Define virtual IP addresses for VPN clients

You can use assign the VPN client an IP address in the VPN, independent of the address the VPN client computer uses in its local network.

Before you begin

To use virtual IP addresses for VPN clients:
  • You can use the internal DHCP server to provide IP addresses to the VPN client Virtual Adapter only if you use Single Firewalls as VPN gateways.
  • The users must use a VPN client that has a Virtual Adapter feature. The Forcepoint VPN Client always has this feature installed and active.

The virtual IP address is only used in communications through the VPN tunnels. The VPN gateway gets the IP address and network settings of the VPN client from the DHCP server and forwards the information to the VPN client.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Right-click the Engine, then select Edit Single Engine.
  2. Browse to VPN > VPN Client.
  3. From the DHCP Mode drop-down list, select Relay.
  4. From the Interface or Interface for DHCP Relay drop-down list, select the source address for the DHCP packets when querying the DHCP server (the interface toward the DHCP server).
  5. Click Add, then select the DHCP server element that assigns IP addresses for the VPN clients.
  6. (Optional) From the Add Information drop-down list, select what VPN Client user information is added to the Remote ID option field in the DHCP Request packets.
    • Add User information — VPN Client user information (in the form user@domain) is automatically added to the Remote ID option field in the DHCP Request packets.
    • Add Group information — VPN Client user information (in the form group@domain) is automatically added to the Remote ID option field in the DHCP Request packets.
    Your DHCP server must support the DHCP Relay Agent Information option to use this information. Depending on your DHCP server configuration, this information can be used as a basis for IP address selection.
  7. (Optional) Select Restrict Virtual Address Ranges, then enter the IP address range in the field on the right.
  8. (Optional) Configure the Engine to act as a proxy for the VPN client’s ARP requests.
    1. Select Proxy ARP.
    2. In the field on the right, enter the IP address range for proxy ARP.
    Note: The Proxy ARP option might be required for a working VPN depending on your network configuration.
  9. Click Save and Refresh.
    Note: You must restrict the local DHCP service to the VPN client virtual IP address use. For details, refer section Restrict the local DHCP service.