Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

DHCP for Logical Systems

Understanding DHCP Support for Logical Systems

Starting in Junos OS Release 18.4R1, a logical system supports the DHCP client feature to learn IP addresses for interfaces assigned to the logical systems. Additionally, starting in Junos OS Release 18.4R1, logical systems support the DHCP relay feature. A DHCP relay agent forwards DHCP requests and responses between the DHCP client and the DHCP server.

A DHCP server allocates IP addresses and provides IP configuration settings such as the DNS server and default gateway to client hosts on a subnet served by an interface of a logical system. The DHCP allows network administrators centrally manage a pool of IP addresses among hosts and automate the assignment of IP addresses in a network within a logical system. An IP address is leased to a host for a limited time period, allowing the DHCP server to share a limited IP addresses among a group of hosts that do not require permanent IP addresses.

An interface of an SRX Series Firewall operating as a DHCP client receives the TCP or IP settings and the IP address from an external DHCP server.

An SRX Series Firewall operating as a DHCP relay agent for logical systems forwards incoming requests from the DHCP clients to a specified DHCP server. The client requests pass through interfaces on the logical systems.

Minimum DHCPv6 Relay Agent Configuration for Logical Systems

The following example describes the minimum configuration required to configure an SRX Series Firewall as a DHCPv6 relay agent for the logical system.

Before you begin determine the following:

  • The DHCPv6 relay group and the DHCP active server-group for logical system.

  1. Configure an interface with an IPv6 address for the logical system.
  2. Specify the name of the server-group and add the IP address for the DHCP servers belonging to the same group.
  3. Specify the name of the active server group.
  4. Create a DHCP relay group that includes at least one interface for the logical system.
  5. Confirm your configuration by entering the show logical-systems LSYS1 command.
Note:

To configure the DHCP relay agent in a routing instance for the logical system, configure the dhcp-relay statement in the edit logical-systems LSYS1 routing-instances R1 hierarchy level.

Example: Configuring the DHCPv6 Client for Logical Systems

This example shows how to configure an SRX Series Firewall as a DHCPv6 client for the logical systems.

Requirements

This example uses the following hardware and software components:

  • An SRX Series Firewall

  • Junos OS Release 18.4R1

Before you begin:

  • Read the Understanding DHCP Support for Logical Systems to understand how and where this procedure fits in the overall support for DHCP.

    No special configuration beyond device initialization is required before configuring this feature.

Overview

In this example, the primary administrator configures an SRX Series Firewall as a DHCPv6 client for a logical system.

The DHCPv6 client for a logical system includes the following features:

  • Identity association for non-temporary addresses (IA_NA)

  • Identity association for prefix delegation (IA_PD)

  • Autoconfig or stateful mode

  • DHCP unique identifier (DUID)

Configuration

CLI Quick Configuration

To quickly configure this example, copy the following commands, paste them into a text file, remove any line breaks, change any details necessary to match your network configuration, copy and paste the commands into the CLI at the [edit] hierarchy level, and then enter commit from configuration mode.

Configuring DHCPv6 Client in a Logical System

Procedure

Step-by-Step Procedure

The following example requires you to navigate various levels in the configuration hierarchy. For instructions on how to do that, see Using the CLI Editor in Configuration Mode in the Junos OS CLI User Guide.

  1. Configure the security zones to permit traffic for a logical system.

  2. Create a routing instance and assign the routing instance type for a logical system.

  3. Specify the interface name for the routing instance.

  4. Configure the DHCPv6 client type. The client type can be autoconfig or stateful for the logical system.

    • To enable the DHCPv6 auto configuration mode, configure the client type as autoconfig.

    • For stateful address assignment, configure the client type as stateful.

  5. Specify the identity association type.

    • To configure identity association for nontemporary address (IA_NA) assignment, specify the client-ia type as ia-na.

    • To configure identity association for prefix delegation (IA_PD), specify the client-ia-type as ia-pd.

  6. Configure the DHCPv6 client identifier by specifying the DHCP unique identifier (DUID) type for the logical system. The following DUID type is supported:

    • Link layer address (duid-ll)

  7. Specify the DHCPv6 client requested option as dns-server for the logical system.

  8. Configure the router advertisement.

Results

  • From configuration mode, confirm your configuration by entering the show logical-systems LSYS1 command. If the output does not display the intended configuration, repeat the configuration instructions in this example to correct it.

  • From configuration mode, confirm your configuration by entering the show protocols command. If the output does not display the intended configuration, repeat the configuration instructions in this example to correct it.

If you are done configuring the device, enter commit from configuration mode.

Verification

To confirm that the configuration is working properly, perform these tasks:

Verifying the DHCPv6 Client for Logical Systems

Purpose

Verify that the DHCPv6 client information is configured.

Action

From the operational mode, enter the show dhcpv6 client binding logical-systems LSYS1 command.

Meaning

The output displays the address binding information for the logical system.

Verifying the DHCPv6 Client Binding for Logical Systems

Purpose

Verify that the DHCPv6 client binding information is configured.

Action

From the operational mode, enter the show dhcpv6 client binding detail logical-systems LSYS1 command.

Meaning

The output displays the detailed client binding information for the logical system.

Verifying the DHCPv6 Client Statistics for Logical Systems

Purpose

Verify that the DHCPv6 client statistics information is configured.

Action

From the operational mode, enter the show dhcpv6 client statistics logical-systems LSYS1 command.

Meaning

The output displays the information about the number of packets discarded, the number of messages received and the number of messages sent by the DHCP client for the logical system.

Example: Configuring the DHCPv6 Server Options for Logical Systems

This example shows how to configure DHCPv6 server options on SRX Series Firewalls for the logical system.

Requirements

This example uses the following hardware and software components:

  • An SRX Series Firewall

  • Junos OS Release 18.4R1

Before you begin determine the following:

  • The IPv6 address pool range and the IPv6 prefix for logical systems.

Overview

In this example, you set a default client limit as 200 for all DHCPv6 groups. You then create a group called my-group that contains at least one interface. In this case, the interface is ge-0/0/2.0. You set a range of interfaces using the upto command and set a custom client limit as 200 for group my-group that overrides the default limit. Finally, you configure interface ge-0/0/2.0 with IPv6 address 2001:db8::1/64 and set router advertisement for interface ge-0/0/2.0.

Configuration

CLI Quick Configuration

To quickly configure this example, copy the following commands, paste them into a text file, remove any line breaks, change any details necessary to match your network configuration, copy and paste the commands into the CLI at the [edit] hierarchy level, and then enter commit from configuration mode.

Procedure

Step-by-Step Procedure

The following example requires you to navigate various levels in the configuration hierarchy. For instructions on how to do that, see Using the CLI Editor in Configuration Mode in the Junos OS CLI User Guide.

To configure the DHCPv6 server options for logical systems:

  1. Configure a DHCP local server.

  2. Set a default limit for all DHCPv6 groups.

  3. Specify a group name and interface.

  4. Configure an interface with an IPv6 address.

  5. Configure an address-pool and specify the IPv6 family.

  6. Configure the IPv6 prefix, the range name, and the IPv6 range for the DHCPv6 clients

  7. Configure the DHCPv6 attribute for the maximum lease time.

  8. Configure the user-defined option.

  9. Configure the router advertisement for the interface.

Results

From configuration mode, confirm your configuration by entering the show logical-systems LSYS1 command. If the output does not display the intended configuration, repeat the configuration instructions in this example to correct it.

If you are done configuring the device, enter commit from configuration mode.

Verification

To confirm that the configuration is working properly, perform these tasks:

Verifying the DHCPv6 Local Server Configuration

Purpose

Displays the address bindings in the client table on the extended DHCPv6 local server.

Action

From operational mode, enter the show dhcpv6 server binding summary command to display the address bindings in the client table on the DHCPv6 local server.

Meaning

The output displays the information about the DHCPv6 local server address binding summary.