Link to home
Start Free TrialLog in
Avatar of Andrew N. Kowtalo
Andrew N. Kowtalo

asked on

Sophos Red 15 not assigning DHCP addresses to target

Would anyone by chance know why a Sophos Red 15 will not assign DHCP addresses to a device after we assign a range to it?

Does the Sophos need to be setup as a DHCP host?  The reason for this is we are attempting to setup pixie booting for imaging machines however the machine cannot pickup an address from the network due to the fact the Sophos will not assign it.   Is there somewhere in the UTM we need to provision this Sophos to act as a DHCP server?

Avatar of Bembi
Bembi
Flag of Germany image

Hello,
I guess you should put some general network rules into account. 
Sure, to provide a DHCP server, you have to configure and activate it on the  device.
But this doesn't neccessarily mean, that the client takes it. 
DHCP is a very low level service and if a client ask for a dhcp service, it take any servive it can find. Or better said, the first which responds. 
Due to this, the basic rule is to have only one dhcp service inside a network segment to make sure, that all of the clients are using the same service. Also dhcp packages may pass routers. 
If you have more than one dhcp service, you have to split them into two network segments and block the dhcp traffic between the two segments. In this case, only one dhcp exists in each segement and only the reachable dhcp service can respond.      

Do other devices behind the RED get an IP address?

The RED itself can't be the DHCP-Server, but the Sophos Firewall where the RED is connected to can.

You have to configure the DHCP Server and DHCP Options within Sophos Firewall.

You may use the Sophos Firewall as DHCP-Relay too.  

Used many times ... it works.

Avatar of Andrew N. Kowtalo
Andrew N. Kowtalo

ASKER

Dirk do you remember how to set this up

Do you use SG(UTM) or XG/XGS-Firewall?

we use the web utm
ASKER CERTIFIED SOLUTION
Avatar of Dirk Kotte
Dirk Kotte
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I will give this a try