Configuring The DHCP Relay Agent On ISA Server 2004
Configuring The DHCP Relay Agent On ISA Server 2004
Page 1 of 4
TechNet Home > Products & Technologies > Servers > ISA Server TechCenter Home > ISA Server 2004 > Technical Library > Planning, Deployment, and Integration
On This Page Overview Creating DHCP Rules Ordering DHCP Request Rules
Overview
There may be some configurations in which you want to install Microsoft Internet Security and Acceleration (ISA) Server 2004 on a Dynamic Host Configuration Protocol (DHCP) relay agent server. This document addresses issues you may encounter when configuring such a scenario.
Top of page
A rule to allow the DHCP request from the network in which DHCP clients are situated to the Local Host network. (The DHCP relay agent acts as a DHCP server for the DHCP clients.) A rule to allow the DHCP reply from the Local Host network to the network in which DHCP clients are situated. (The DHCP relay agent acts as a DHCP server for the DHCP clients.) A rule to allow the DHCP relay agent to communicate with DHCP servers, as follows:
Create a DHCP protocol definition. Create a computer set for DHCP servers. Create a rule from the Local Host network to DHCP servers.
2.
3. 4. 5.
6. 7.
http://www.microsoft.com/technet/isa/2004/plan/isadhcprelay.mspx?pf=true
22. 1. 2007
Page 2 of 4
then click Next. 8. 9. In the Access Rule Destinations page, click Add. In Add Network Entities, in the Networks section, click Local Host. Click Add, click Close, and then click Next. In the User Sets page, All Users is selected by default. Click Next, and then click Finish.
10.
Allow the DHCP (Reply) Protocol from the Local Host Network
In this procedure, the DHCP clients are located in the Internal network. To allow the DHCP (reply) protocol, do the following: 1. In the Firewall Policy node of ISA Server Management, right-click Firewall Policy, point to New, and then click Access Rule. In the New Access Rule Wizard, type a name for the rule. For example: Allow DHCP Replies. Then, click Next. In the Rule Action page, click Allow. Then, click Next. In the Protocols page, in This rule applies to, select Selected protocols. Then, click Add. In Add Protocols, in the All Protocols section, click DHCP (reply). Click Add, click Close, and then click Next. In the Access Rule Sources page, click Add. In Add Network Entities, in the Networks section, click Local Host. Click Add, click Close, and then click Next. In the Access Rule Destinations page, click Add. In Add Network Entities, in the Networks section, click Internal. Click Add, click Close, and then click Next. In the User Sets page, All Users is selected by default. Click Next, and then click Finish.
2.
3. 4. 5.
6. 7.
8. 9.
10.
5. 6.
Click OK, and then click Next. On the Secondary Connections page, click Next, and then click Finish to complete the wizard.
http://www.microsoft.com/technet/isa/2004/plan/isadhcprelay.mspx?pf=true
22. 1. 2007
Page 3 of 4
9.
5.
Click OK to close the New Computer Set Rule Element dialog box. Click Apply to apply the changes.
Allow the DHCP Relay Agent (Local Host Network) to DHCP Servers
To allow the DHCP relay agent to communicate with the DHCP server, do the following: 1. In the Firewall Policy node of ISA Server Management, right-click Firewall Policy, point to New, and then click Access Rule. In the New Access Rule Wizard, type a name for the rule (for example Allow DHCP Relay Agent). Then, click Next. In the Rule Action page, click Allow. Then, click Next. In the Protocols page, in This rule applies to, click Selected protocols. Then, click Add. In Add Protocols, in the User-Defined section, click DHCPRelay, which is the protocol that you created earlier. Click Add, click Close, and then click Next. In the Access Rule Sources page, click Add. In Add Network Entities, in the Networks section, click Local Host. Click Add, click Close, and then click Next. In the Access Rule Destinations page, click Add. In Add Network Entities, in the Computer Sets section, click DHCP_Servers, which is the computer set that you created earlier. Click Add, click Close, and then click Next. In the User Sets page, All Users is selected by default. Click Next, and then click Finish. Click Apply to apply the changes.
2.
3. 4. 5.
6. 7.
8. 9.
10. 11.
Top of page
http://www.microsoft.com/technet/isa/2004/plan/isadhcprelay.mspx?pf=true
22. 1. 2007
Page 4 of 4
criterion. Note that if there are other criteria in the rule that do not match a DHCP request, there is no conflict. To avoid conflict, ensure that the rule you have configured to allow DHCP requests is higher in the rule order than any other rule that uses name resolution that may match the DHCP request. This principle is shown in the following example. This rule will not work:
Deny all protocols from www.attack.com Allow DHCP requests from internal to local host
This rule will work: Deny HTTP protocol from www.attack.com Allow DHCP requests from internal to local host
This rule will work: Allow DHCP requests from internal to local host Deny all protocols from www.attack.com
Top of page
Manage Your Profile 2007 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks | Privacy Statement
http://www.microsoft.com/technet/isa/2004/plan/isadhcprelay.mspx?pf=true
22. 1. 2007