config system dhcp server

Configure DHCP servers.

config system dhcp server

Description: Configure DHCP servers.

edit <id>

set status [disable|enable]

set lease-time {integer}

set mac-acl-default-action [assign|block]

set forticlient-on-net-status [disable|enable]

set dns-service [local|default|...]

set dns-server1 {ipv4-address}

set dns-server2 {ipv4-address}

set dns-server3 {ipv4-address}

set dns-server4 {ipv4-address}

set wifi-ac-service [specify|local]

set wifi-ac1 {ipv4-address}

set wifi-ac2 {ipv4-address}

set wifi-ac3 {ipv4-address}

set ntp-service [local|default|...]

set ntp-server1 {ipv4-address}

set ntp-server2 {ipv4-address}

set ntp-server3 {ipv4-address}

set domain {string}

set wins-server1 {ipv4-address}

set wins-server2 {ipv4-address}

set default-gateway {ipv4-address}

set next-server {ipv4-address}

set netmask {ipv4-netmask}

set interface {string}

config ip-range

Description: DHCP IP range configuration.

edit <id>

set start-ip {ipv4-address}

set end-ip {ipv4-address}

next

end

set timezone-option [disable|default|...]

set timezone [01|02|...]

set tftp-server <tftp-server1>, <tftp-server2>, ...

set filename {string}

config options

Description: DHCP options.

edit <id>

set code {integer}

set type [hex|string|...]

set value {string}

set ip {user}

next

end

set server-type [regular|ipsec]

set ip-mode [range|usrgrp]

set conflicted-ip-timeout {integer}

set ipsec-lease-hold {integer}

set auto-configuration [disable|enable]

set dhcp-settings-from-fortiipam [disable|enable]

set auto-managed-status [disable|enable]

set ddns-update [disable|enable]

set ddns-update-override [disable|enable]

set ddns-server-ip {ipv4-address}

set ddns-zone {string}

set ddns-auth [disable|tsig]

set ddns-keyname {string}

set ddns-key {user}

set ddns-ttl {integer}

set vci-match [disable|enable]

set vci-string <vci-string1>, <vci-string2>, ...

config exclude-range

Description: Exclude one or more ranges of IP addresses from being assigned to clients.

edit <id>

set start-ip {ipv4-address}

set end-ip {ipv4-address}

next

end

config reserved-address

Description: Options for the DHCP server to assign IP settings to specific MAC addresses.

edit <id>

set type [mac|option82]

set ip {ipv4-address}

set mac {mac-address}

set action [assign|block|...]

set circuit-id-type [hex|string]

set circuit-id {string}

set remote-id-type [hex|string]

set remote-id {string}

set description {var-string}

next

end

next

end

config system dhcp server

Parameter

Description

Type

Size

Default

status

Enable/disable this DHCP configuration.

option

-

enable

Option

Description

disable

Do not use this DHCP server configuration.

enable

Use this DHCP server configuration.

lease-time

Lease time in seconds, 0 means unlimited.

integer

Minimum value: 300 Maximum value: 8640000

604800

mac-acl-default-action

MAC access control default action (allow or block assigning IP settings).

option

-

assign

Option

Description

assign

Allow the DHCP server to assign IP settings to clients on the MAC access control list.

block

Block the DHCP server from assigning IP settings to clients on the MAC access control list.

forticlient-on-net-status

Enable/disable FortiClient-On-Net service for this DHCP server.

option

-

enable

Option

Description

disable

Disable FortiClient On-Net Status.

enable

Enable FortiClient On-Net Status.

dns-service

Options for assigning DNS servers to DHCP clients.

option

-

specify

Option

Description

local

IP address of the interface the DHCP server is added to becomes the client's DNS server IP address.

default

Clients are assigned the FortiGate's configured DNS servers.

specify

Specify up to 3 DNS servers in the DHCP server configuration.

dns-server1

DNS server 1.

ipv4-address

Not Specified

0.0.0.0

dns-server2

DNS server 2.

ipv4-address

Not Specified

0.0.0.0

dns-server3

DNS server 3.

ipv4-address

Not Specified

0.0.0.0

dns-server4

DNS server 4.

ipv4-address

Not Specified

0.0.0.0

wifi-ac-service

Options for assigning WiFi Access Controllers to DHCP clients

option

-

specify

Option

Description

specify

Specify up to 3 WiFi Access Controllers in the DHCP server configuration.

local

IP address of the interface the DHCP server is added to becomes the client's WiFi Access Controller IP address.

wifi-ac1

WiFi Access Controller 1 IP address (DHCP option 138, RFC 5417).

ipv4-address

Not Specified

0.0.0.0

wifi-ac2

WiFi Access Controller 2 IP address (DHCP option 138, RFC 5417).

ipv4-address

Not Specified

0.0.0.0

wifi-ac3

WiFi Access Controller 3 IP address (DHCP option 138, RFC 5417).

ipv4-address

Not Specified

0.0.0.0

ntp-service

Options for assigning Network Time Protocol (NTP) servers to DHCP clients.

option

-

specify

Option

Description

local

IP address of the interface the DHCP server is added to becomes the client's NTP server IP address.

default

Clients are assigned the FortiGate's configured NTP servers.

specify

Specify up to 3 NTP servers in the DHCP server configuration.

ntp-server1

NTP server 1.

ipv4-address

Not Specified

0.0.0.0

ntp-server2

NTP server 2.

ipv4-address

Not Specified

0.0.0.0

ntp-server3

NTP server 3.

ipv4-address

Not Specified

0.0.0.0

domain

Domain name suffix for the IP addresses that the DHCP server assigns to clients.

string

Maximum length: 35

wins-server1

WINS server 1.

ipv4-address

Not Specified

0.0.0.0

wins-server2

WINS server 2.

ipv4-address

Not Specified

0.0.0.0

default-gateway

Default gateway IP address assigned by the DHCP server.

ipv4-address

Not Specified

0.0.0.0

next-server

IP address of a server (for example, a TFTP sever) that DHCP clients can download a boot file from.

ipv4-address

Not Specified

0.0.0.0

netmask

Netmask assigned by the DHCP server.

ipv4-netmask

Not Specified

0.0.0.0

interface

DHCP server can assign IP configurations to clients connected to this interface.

string

Maximum length: 15

timezone-option

Options for the DHCP server to set the client's time zone.

option

-

disable

Option

Description

disable

Do not set the client's time zone.

default

Clients are assigned the FortiGate's configured time zone.

specify

Specify the time zone to be assigned to DHCP clients.

timezone

Select the time zone to be assigned to DHCP clients.

option

-

00

Option

Description

01

(GMT-11:00) Midway Island, Samoa

02

(GMT-10:00) Hawaii

03

(GMT-9:00) Alaska

04

(GMT-8:00) Pacific Time (US & Canada)

05

(GMT-7:00) Arizona

81

(GMT-7:00) Baja California Sur, Chihuahua

06

(GMT-7:00) Mountain Time (US & Canada)

07

(GMT-6:00) Central America

08

(GMT-6:00) Central Time (US & Canada)

09

(GMT-6:00) Mexico City

10