Configure a DHCP server on the Windows server or on the Infoblox server
Focus
Focus
GlobalProtect

Configure a DHCP server on the Windows server or on the Infoblox server

Table of Contents

Configure a DHCP server on the Windows server or on the Infoblox server

Configure a DHCP server on the Windows server or on the Infoblox server
Where Can I Use This?What Do I Need?
  • NGFW (managed by Panorama)
  • GlobalProtect Subscription License
  • PAN-OS 11.2 (or a later PAN-OS version)
  • GlobalProtect app 6.0.8, 6.2.1 or later versions
  • GlobalProtect endpoints running on Windows, macOS, Android, iOS, and Linux
You can configure a DHCP server on the Windows server or on the Infoblox server

Configure DHCP Server on the Windows Server

Server on the Windows Server
  1. Log into Microsoft Server Manager.
    For the latest information on configuring DHCP server, refer to the Microsoft documentation
  2. On the Microsoft Server Manager Dashboard, select Add roles and features.
  3. On the Before you begin screen, click Next.
  4. Select the installation type and click Next.
  5. Select the destination server from the Server Pool area and click Next.
  6. Select the Server Roles and click Next.
  7. Select features and click Next.
  8. Click Tools and select DHCP.
  9. Select IPv4 and right-click and select the New Scope option.
  10. Click Next on the New Scope Wizard.
  11. Enter the range of IP addresses the new scope will use to distribute.
    The range of DHCP IP pool address pool you configure in the DHCP server should match the management interface IP addresses in the GlobalProtect gateway. If you configure DHCP IP addresses incorrectly on the DHCP server, the traffic will not flow as expected.
  12. (Optional) Enter the range of IP addresses that you want to exclude and will not be distributed by the server.
  13. Configure DHCP options and click Next.
  14. Click Next on the Domain Name and DNS server window.
  15. The new scope of IP addresses is added under IPv4. Right-click on the new scope and select Add to SuperScope.
  16. The added IP addresses will be displayed under the Connections tab on the GlobalProtect app.

Configure DHCP Policy on the New Scope

  1. Under Scope, click on the Policy and select New Policy.
  2. Enter the policy name and description.
  3. Click Addto add the circuit ID as part of the policy rule.
  4. Select Context as Relay Agent Information and Operator as Equals.
  5. Select Agent Circuit ID and enter the Circuit ID of the GlobalProtect from the firewall (NetworkGlobalProtectGlobalProtect Gateway<globalprotect-gateway-config>AgentClient IP PoolDHCP Server Circuit ID.)
  6. Click OK.
  7. Add the IP Address range of the scope in the policy and click Next.
  8. Click Next again and then click Finish to save the configurations.

Configure DHCP Server on the Infoblox Server

Configure DHCP Server on the Infoblox Server
For the latest information on configuring DHCP server, refer to the Infoblox documentation such as DHCP server on the Infoblox server.
  1. Log into the Infoblox Grid Manager.
  2. Click Add Networks to add a new network.
  3. Ensure that DHCP and DNS are enabled and running on the GRID.
  4. Click Add under Toolbar to add IPv4 network.
  5. Click Next to add IPv4 Network.
  6. Add the network IP address and click Next.
  7. Add Infoblox members.
  8. After adding the member, click Next.
  9. (Optional) Modify the default Lease time and click Next.
  10. Click Next.
  11. Restart the service to reflect the configurations added for the new network.
  12. To add Shared Network, go to DHCPNetworksShared Networks.
  13. Create all your networks under one Shared Network.
  14. Click on the shared network to add a range of IP addresses.
  15. Click on range to add range of IP addresses and click Next.
  16. Click Next to add other details and proceed until the restart screen appears. Restart Grid to reflect the new configurations added.
  17. After adding the IPv4 ranges, the IP addresses within the range will be displayed under the Shared Networks tab. Click Edit to edit the details.
  18. (Optional)Enter the range of IP addresses you want to exclude from the range. Click the Add sign to add the Exclusion Ranges .
  19. Click Save & Close.
  20. You can leave the exclusion range empty if you do not want to exclude any IP addresses.
  21. Click Next to proceed and enter the details such as grid member, schedule change, and so on, until you finally Save and Close the configurations.
  22. After creating the DHCP configuration, you can create filters with Gateway Name.
  23. You can view the relay agent details of the GlobalProtect gateway.