Firewall Threat Defense devices support IPv4 and IPv6 address assignment policies for remote access VPN clients. This policy applies to all connection profiles of the remote access policy. If you configure multiple address assignment methods, the device attempts each method in sequence until it finds an IP address.
Before you begin
Ensure that you have configured a remote access VPN policy.
Procedure
Step 1 | Choose . |
Step 2 | Click the edit icon next to the remote access VPN policy. |
Step 3 | Click the Advanced tab. |
Step 4 | In the left pane, click Address Assignment Policy. |
Step 5 | In IPv4 Policy, configure these parameters:
-
Check the Use authorization server check box to retrieve IP addresses from an external authorization server on a per-user basis. Use this method when the authorization server has IP addresses configured. This address assignment policy supports only RADIUS servers, not AD or LDAP servers.
-
Check the Use DHCP check box to retrieve IP addresses from a DHCP server configured in a connection profile. You can also define the range of IP addresses by configuring the DHCP network scope in the group policy.
-
Check the Use an internal address pool check box to retrieve IP addresses from internally configured address pools.
Create IP address pools using objects, choose and configure them in the connection profile.
-
In the Allow reuse of IP address field, enter the delay time (in minutes) before an IP address is reassigned to the pool after being released. A delay prevents issues that you could experience due to rapid IP address reassignment. The default delay is zero minutes, and the range is 0 to 480 minutes.
|
Step 6 | In IPv6 Policy, check the Use authorization server and Use an internal address pool check boxes, as required. |
Step 7 | Click Save. |