Restrict the local DHCP service to the VPN client virtual IP address use.
Steps
-
Create the following Expression Network element "Node-internal" (negation of the built-in Zone element):
-
Open the Engine cPP Template for editing.
-
Before the Automatic Rules Insert Point, add the following rule:
Source: NOT Node-internal
Destination: $$ Valid DHCP Servers for Mobile VPN clients, DHCP Broadcast Destination
Service: BOOTPS (UDP)
Action: Discard
-
Save the template policy.
-
Refresh the policies of all firewalls involved in the VPN to activate the new configuration.