HP VPN Server Appliance sa3110/sa3150/sa3400/sa3450 and sa3000 Series VPN Manager - Release 6.8.2 Release Notes
Release 6.8.2 Release Notes
21
Specifically, the range should not overlap any of the Client-
IP addresses specified in the ACL.
Configuration of Both DHCP and Static IP
Addresses on One Tunnel
The VPN Manager allows you to configure both DHCP and
static Client-IP addresses on the same remote-use tunnel,
but should not since this configuration is not supported.
You can, however, configure either multiple static Client-IP
address entries or multiple DHCP entries (as long as you
enter the DHCP gateway’s IP address), but not a
combination of these.
DHCP Server of Client-IP Addresses
To successfully use the VPN device as a DHCP server or
forwarder for a VPN Client, the client-IP address assigned
must fall within one of the subnets on a red interface so
that the VPN device can return an appropriate subnet mask
and DHCP server.
For example:
remote-group test
client-ip 10.20.1.17 2
assigns two IP addresses to the group test, 10.20.1.17 and
10.20.1.18.
To service DHCP requests, a red interface could be
configured as follows:
int e 0
mode red
ip address 10.20.1.1 255.255.255.240
ip address 10.20.1.19 255.255.255.240 secondary
The secondary address 10.20.1.19 is the address/mask that
is used when responding to VPN Client DHCP requests.










