VPN
Click on the red underlined text to get to the source
... security gateway, they
are not described in this document. The mechanisms described here
work best when the VPN is implemented using a virtual interface.
...
... interface, in order to enable the DHCP server to
differentiate VPN from non-VPN requests. The chaddr field of the
DHCPDISCOVER ...
... DHCP server to
differentiate VPN from non-VPN requests. The chaddr field of the
DHCPDISCOVER MUST include an identifier ...
... NAI concatenated with an interface number. Assuming that
the user is only connected to the VPN at one location, this will
be unique on the subnet as well as persistent across reboots.
...
... appropriate tunnel endpoint. Note that this is particularly
undesirable in large VPN servers where the resulting state will be
substantial.
...
... DHCPINFORM, DHCPDECLINE, and DHCPRELEASE
messages will use the newly established VPN SA. Similarly, all DHCP
messages subsequently sent by the DHCPv4 server ...
