Anyone Make an Off the Shelf DHCP Proxy NAT / Firewall?

Anyone Make an Off the Shelf DHCP Proxy NAT / Firewall?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Anyone Make an Off the Shelf DHCP Proxy NAT / Firewall? Will 12-30-2005
Posted by Will on December 30, 2005, 3:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm looking for a commodity small LAN firewall / NAT box that would support
a DHCP proxy feature on its *external* interface, and then send those DHCP
requests to a specific host behind the arp.

My application is that I have a Windows 2003 domain controller that I would
like to have act as a DHCP server for the computers in its domain. The
clients would be in front of a firewall / NAT and the domain controller
would be behind the firwall / NAT. I want to find an NAT that would
present a DHCP proxy on its external interface and send those requests to
the domain controller.

The existing firewall we have in place supports DHCP proxy only in a weak
way. It also requires adding some additional software to the firewall that
I don't particularly want running on the firewall. So I would run the DHCP
proxy as a bypass to the existing firewall, just for DHCP only. No other
traffic besides DHCP would go in or out of the new firewall.

I see that Netopia's Cayman 3500 series supports a DHCP relay from
*internal* machines to an outside DHCP server. Unfortunately, that's the
opposite of what I need, unless I am ready to turn the firewall 180 degrees
around and make the clients the internal network and the domain controller
the external. That would require some very iffy configuration to make
secure, if it could be done. My preference is to find a similar
off-the-shelf product that already incorporate DHCP proxy as I describe it.
I would prefer to not have to install UNIX and do anything custom. Due to
time limitations, off the shelf is what I need.

Does this product exist?

--
Will



Posted by Somebody. on December 30, 2005, 5:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> I'm looking for a commodity small LAN firewall / NAT box that would
> support
> a DHCP proxy feature on its *external* interface, and then send those DHCP
> requests to a specific host behind the arp.
>
> My application is that I have a Windows 2003 domain controller that I
> would
> like to have act as a DHCP server for the computers in its domain. The
> clients would be in front of a firewall / NAT and the domain controller
> would be behind the firwall / NAT. I want to find an NAT that would
> present a DHCP proxy on its external interface and send those requests to
> the domain controller.
>
> The existing firewall we have in place supports DHCP proxy only in a weak
> way. It also requires adding some additional software to the firewall
> that
> I don't particularly want running on the firewall. So I would run the
> DHCP
> proxy as a bypass to the existing firewall, just for DHCP only. No other
> traffic besides DHCP would go in or out of the new firewall.
>
> I see that Netopia's Cayman 3500 series supports a DHCP relay from
> *internal* machines to an outside DHCP server. Unfortunately, that's the
> opposite of what I need, unless I am ready to turn the firewall 180
> degrees
> around and make the clients the internal network and the domain controller
> the external. That would require some very iffy configuration to make
> secure, if it could be done. My preference is to find a similar
> off-the-shelf product that already incorporate DHCP proxy as I describe
> it.
> I would prefer to not have to install UNIX and do anything custom. Due
> to
> time limitations, off the shelf is what I need.
>
> Does this product exist?

www.fortigate.com

-Russ.



Posted by Somebody. on December 30, 2005, 5:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> I'm looking for a commodity small LAN firewall / NAT box that would
> support
> a DHCP proxy feature on its *external* interface, and then send those DHCP
> requests to a specific host behind the arp.
>
>
> Does this product exist?

My bad -- not fortigate.com...


http://www.fortinet.com

:-(

-Russ.



Posted by Volker Birk on December 31, 2005, 7:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> I'm looking for a commodity small LAN firewall / NAT box that would support
> a DHCP proxy feature on its *external* interface, and then send those DHCP
> requests to a specific host behind the arp.
> My application is that I have a Windows 2003 domain controller that I would
> like to have act as a DHCP server for the computers in its domain. The
> clients would be in front of a firewall / NAT and the domain controller
> would be behind the firwall / NAT. I want to find an NAT that would
> present a DHCP proxy on its external interface and send those requests to
> the domain controller.

This is not a good idea. Better use a VPN.

Yours,
VB.
--
Ein vision statement ist in aller Regel planfreies Gelalle einer Horde
realitätsferner Spinner.
        Dietz Pröpper in d.a.s.r

Posted by E. on December 31, 2005, 5:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Will wrote:
> I'm looking for a commodity small LAN firewall / NAT box that would support
> a DHCP proxy feature on its *external* interface, and then send those DHCP
> requests to a specific host behind the arp.
>
> My application is that I have a Windows 2003 domain controller that I would
> like to have act as a DHCP server for the computers in its domain. The
> clients would be in front of a firewall / NAT and the domain controller
> would be behind the firwall / NAT. I want to find an NAT that would
> present a DHCP proxy on its external interface and send those requests to
> the domain controller.
>
> The existing firewall we have in place supports DHCP proxy only in a weak
> way. It also requires adding some additional software to the firewall that
> I don't particularly want running on the firewall. So I would run the DHCP
> proxy as a bypass to the existing firewall, just for DHCP only. No other
> traffic besides DHCP would go in or out of the new firewall.
>
> I see that Netopia's Cayman 3500 series supports a DHCP relay from
> *internal* machines to an outside DHCP server. Unfortunately, that's the
> opposite of what I need, unless I am ready to turn the firewall 180 degrees
> around and make the clients the internal network and the domain controller
> the external. That would require some very iffy configuration to make
> secure, if it could be done. My preference is to find a similar
> off-the-shelf product that already incorporate DHCP proxy as I describe it.
> I would prefer to not have to install UNIX and do anything custom. Due to
> time limitations, off the shelf is what I need.
>
> Does this product exist?
>

Why are you trying to do things this way? If they are domain clients why
not stick them on the same subnet?
E.

Similar ThreadsPosted
How can I make sure I use Zonealarm not Microsoft firewall October 31, 2005, 5:58 am
DMZ & DHCP September 26, 2005, 9:35 am
netscreen 5XP DHCP December 10, 2004, 4:35 am
Turn off dhcp? March 30, 2005, 10:30 am
PIX 501 dhcp client February 7, 2007, 11:25 am
DHCP server August 4, 2008, 11:20 am
lost DHCP connection July 15, 2005, 8:41 pm
DHCP lease question January 15, 2006, 6:12 am
CheckPoint Problem on DHCP July 7, 2006, 1:08 am
Certain DHCP Broadcasts being dropped?!? February 12, 2007, 12:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy