This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DHCP service offering DHCP packets on other interface...

I have a network setup with the main LAN on interface eth2 with a DHCP server on the network, and a separate wireless LAN on eth3 with the UTM offering DHCP for that interface. The only thing attached to that IF is a Wireless AP (Not sophos). For some reason, the UTM is offering DHCP addresses on the eth2 IF conflicting with the main LAN DHCP server. This causes issues since the traffic in the WLAN subnet is not allowed to talk to the LAN subnet in the firewall rules, which is working, but people that should be on LAN are not getting LAN IPs all the time.

Any ideas? Thanks.



This thread was automatically locked due to age.
Parents
  • You do have different subnets on both interfaces do you?


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

Reply
  • You do have different subnets on both interfaces do you?


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

Children
  • The two interfaces have separate subnets. The only thing on the interface that has the DHCP server from the firewall being used is a wifi access point for public use. So, there can't be any network loops between the interfaces and the subnets are separate on each interface.

  • Is the wifi access point "requesting" the "wrong" ip-address for the guest connected to it?

    If this is the case I think you should configure your guest wifi as a VLAN and make sure this VLAN is also configured on UTM. That way your wireless clients will be logically divided from the DHCP server and shouldn't be able to get an address from this server.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • wifi guests connecting to that AP get the correct addresses.