DHCP Relay Overwrite
Focus
Focus
Next-Generation Firewall

DHCP Relay Overwrite

Table of Contents

DHCP Relay Overwrite

When acting as a DHCP relay agent, the firewall can replace the subnet mask and default gateway in DHCP messages to redirect client traffic through the firewall.
Where Can I Use This?What Do I Need?
  • NGFW
  • PAN-OS 12.2.2 or a later release
  • One of these licenses when using Strata Cloud Manager
    • Strata Cloud Manager Essentials
    • Strata Cloud Manager Pro
When operating as a standard DHCP relay agent, the Next-Generation Firewall (NGFW) forwards DHCP messages between clients and a DHCP server on a different subnet, passing the server’s assigned IP address, subnet mask, and default gateway to the client unchanged.
The DHCP Relay Overwrite feature allows the firewall to intercept and modify these DHCP server responses. When the firewall relays a DHCP Offer or Acknowledge message to a client, it replaces the original subnet mask and default gateway fields with custom values configured on the relay interface. In cases where server does not give any subnet mask, the configured subnet mask is included in the DHCP responses.
DHCP Interface Configuration Options
In addition to configuring the target DHCP Server IP address per interface, you can now use the DHCP Relay Overwrite enhancement to define the following parameters:
  • Overwrite DHCP Server Response: A toggle to enable or disable the interception and modification of DHCP responses on the interface.
  • Gateway IP: The custom default gateway address that will be sent to the DHCP client.
  • Subnet Mask: The custom subnet mask that will be sent to the DHCP client.
Enable DHCP Relay Overwrite when configuring a DHCP relay agent interface. You configure the overwrite gateway and subnet mask per interface, and the overwrite applies to all DHCP clients that receive addresses through that interface.
DHCP Relay Overwrite supports IPv4 only.