DHCP Based IP Address Assignment and Management for GlobalProtect
DHCP Based IP Address Assignment and Management for GlobalProtect
Where Can I Use This?
What Do I Need?
GlobalProtect Subscription License
PAN-OS 11.2 (or a later PAN-OS version)
GlobalProtect app 6.0.8, 6.2.1 or later versions
GlobalProtect endpoints running on Windows, macOS, Android, iOS,
and Linux
Starting from PAN-OS
11.2.1, the DHCP Based IP Address Assignment feature is supported for both
VM-Series virtual firewall and hardware next-generation firewall
platforms.
DHCP Based IP Address Assignment feature in PAN OS 11.2.0 release is
supported for VM-Series Virtual Firewalls only. The feature is not supported for
hardware next-generation firewall platforms.
You can now configure a DHCP server profile on the GlobalProtect gateway to use DHCP
server for managing and assigning IP addresses for the endpoints connected remotely
through the GlobalProtect app. Users who are using enterprise DHCP servers can enable
this feature for centralized IP management and IP address assignments.
When you configure a DHCP server profile on the GlobalProtect gateway and upon
successful communication between the gateway and the DHCP server, the gateway obtains
DHCP IP addresses from a DHCP member server. The GlobalProtect gateway then assigns the
IP addresses as the tunnel IP for the endpoints that are remotely connected through the
GlobalProtect app. Firstyou configure a DHCP server profile on the GlobalProtect
gateway. After successful communication between the gateway and the DHCP server, the
gateway obtains DHCP IP addresses from a DHCP member server. Then the GlobalProtect
gateway assigns the IP addresses as the tunnel IP for the endpoints that are remotely
connected through the GlobalProtect app.
When the GlobalProtect gateway assigns the DHCP IP addresses to the endpoints, you can
configure their DHCP server to create Dynamic DNS ( Address and Pointer Record) records
for the GlobalProtect connected users. DDNS are useful for endpoint admins to do
troubleshooting on the GlobalProtect connected remote user endpoints. The IP addresses
get registered to the DDNS server only when you configure IP Address Management (IPAM)
on Windows server, DDNS server, or on the Infoblox server.
When you create a DHCP profile on the firewall and
enable the DHCP server on the GlobalProtect gateway, the gateway uses the
DHCP server to manage and assign the IP addresses for the endpoints instead of assigning
the IP addresses from the gateway’s private IP pool. If the DHCP server fails to respond
to the gateway within the set communication timeout and retry time period, the gateway
falls back to the private Static IP pool for the allocation of IP addresses for the
endpoints.
The DHCP-based IP address assignment feature is only supported for IPv4 address
assignment and not for IPv6.
Configuring a static IP pool on the GlobalProtect gateway is optional when you
configure a DHCP-based IP address assignment feature.