Jump to:navigation, search
Wiki





notempty
Dieser Artikel bezieht sich auf eine nicht mehr aktuelle Version!

notempty
Der Artikel für die neueste Version steht hier

notempty
Zu diesem Artikel gibt es bereits eine neuere Version, die sich allerdings auf eine Reseller-Preview bezieht










































De.png
En.png
Fr.png






Global settings of IPSec with DHCP
Last adaption: 06.2023 (12.2.4)
New:
  • Note that only either a server or an interface may be specified.
notempty
This article refers to a Resellerpreview
Access: UTM-IP:Port or UTM-URL:Port
Port as configured at Network / Appliance Settings / Webserver
Default-Port: 11115
i.e.: https://utm.ttt-point.de:11115
Default: https://192.168.175.1:11115
→ VPN →IPSecTab Global


Preparations
An IP address range for the network of the selected interface must be available on the DHCP server.

On the UTM, this is configured under → Network →Network ConfigurationTab DHCP Pools.
Further setup instructions in the Wiki article on DHCP.


IPSec DHCP settings
Caption Value Description UTM 12.4.1 IPSec Global-en.png
Dialog for the global DHCP settings of IPSec clients
DHCP-Server: 192.168.222.1 Sets a DHCP server address to be used. It can also be a unicast address. For example, to be used with remote DHCP servers that can only be reached via routed networks.
  • Note: Only a server or an interface may be defined!
  • DHCP-Interface: LAN3 Specifies an interface through which DHCP requests from the client are forwarded as a broadcast. If applicable the names of the pools configured under → Network →Network ConfigurationTab DHCP Pools and belonging to a network configured on the interface are displayed.
    Static DHCP identity: Off For On, a static DHCP client identity and MAC address is generated for each client from its IPSec identity (e.g., certificate DN, EAP identity) to allow static IP addresses to be assigned by the server.
    Save and restart Saves the settings and restarts the IPSec service

    notempty

    This will interrupt all existing IPSec connections