Jump to content


Photo

Mgmt IP address with DHCP over WAN?

DHCP Management IP Address NG Firewall F380 WAN ISP

  • Please log in to reply
2 replies to this topic

#1 Jonathan Klein

Jonathan Klein
  • Members
  • 34 posts

Posted 26 May 2015 - 12:50 PM

I am configuring an NG F380 for one of our remote offices. We plan to have it get its IP address via DHCP from the ISP over the WAN.

 

Do I still need to configure a Management IP Address for the NG? If so, does it have to be a part of the ISP's subnet?

 

Thanks,

 

Jonathan



#2 Bartek Moczulski

Bartek Moczulski
  • Barracuda Team Members
  • 102 posts
  • LocationEMEA

Posted 27 May 2015 - 02:44 AM

You've got few ways to make it work:

1. if you use Control Centre - you just need to configure VIP and you will manage your box using VIP. MIP can be set to anything on the loopback as it will not be relevant in this case

2. assign MIP to anything in your local branch office LAN and access your box over VPN. This is recommended from security perspective, but if something goes wrong and your VPN server in branch office dies - you lose access

3. assign MIP to loopback and use a DNAT rule in forwarding firewall to redirect TCP 807 with destination DHCP IP to your loopback IP. AFAIR this rule should be already in your default ruleset. It is a good idea to restrict this rule to specific source IP (the one you will be connecting from) - this will act as a management ACL. Also, if you redirect only port 807 remember to enable "SPoE" feature in NGadmin settings.



#3 Matthias Maschler

Matthias Maschler
  • Barracuda Team Members
  • 106 posts
  • LocationInnsbruck

Posted 27 May 2015 - 03:02 AM

Here are a few how-to's that may help you with the configuration of the different approaches when you're not running a NG Control Center: