Configure IP addresses for VPN clients

You can assign IP addresses to remote access VPN users by using IP address pools. You can source these IP addresses from a AAA server, a DHCP server, or local IP address pools. If you select multiple sources, addresses are assigned in this order: AAA server, DHCP server, and then local IP address pools. IP address pools defined in a connection profile are used only when no pools are defined in the associated group policy or in the default group policy DfltGrpPolicy.

Before you begin

Note

When you configure both a DHCP server and a local IP address pool for address assignment, automatic fallback to the local pool (if the DHCP server is unavailable) works only for SSL-based remote access VPN connections.

For IPsec-based remote access VPN connections, this fallback may not complete in time if the DHCP server is unreachable, which can cause the connection to fail.

To avoid connection issues with IPsec-based remote access VPN, do one of the following:

  • Make sure the DHCP server is reachable, or

  • Use only a local IP address pool for address assignment.

Procedure


Step 1

Choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy.

Step 3

Click the edit icon next to the connection profile.

Step 4

Click the Client Address Assignment tab.

Step 5

Click + next to Address Pools:

  1. Click + next to Address Pools to add IP address pools.

    Note
    If you share a remote access VPN policy among multiple Firewall Threat Defense devices, the devices use the same address pool. Assign a unique address pool to each device using device-level object overrides. Unique address pools prevent overlapping IP addresses when devices do not use NAT.
  2. Select IPv4 or IPv6.

  3. In the Address Pools dialog box, choose the IP address pools.

  4. Click + next to Available Pools to add a new IPv4 or IPv6 address pool.

    When you configure an IPv4 address pool, provide a starting and ending IP address. When you configure an IPv6 address pool, enter a number within the range 1 to 16384 in the Number of Addresses field.

  5. Check the Allow Overrides check box to avoid conflicts with IP addresses when objects are shared across many devices. For more information, see Configure address pools.

  6. Click OK.

    If you plan to edit the IP address pools, perform these steps during a maintenance window:

    1. Unassign the device from the remote access VPN policy.

    2. Select the device and click Deploy.

      This deployment removes all the remote access VPN configurations from the device and ends the remote access VPN sessions. Users must reconnect because the sessions are not reestablished.

    3. Click the edit icon next to the IP address pools. Update other remote access VPN configurations, if required, on the Cloud-Delivered Firewall Management Center.

    4. Assign the device to the updated remote access VPN policy.

    5. Deploy the configurations on the device.

      The remote access VPN clients can connect to the device after the maintenance window.

Step 6

Click + next to DHCP Servers to add DHCP servers for address assignment.

Note
You can use only IPv4 addresses for DHCP servers.
  1. Choose the server from the object list.

  2. Click Add

  3. Click + to configure a DHCP server as a network object.

  4. Click OK.

Step 7

Click Save.


What to do next

To define the IP address assignment policy, click the Advanced tab, and from the left pane, choose Address Assignment Policy.