Transparent DHCP Proxy

Hi,

I plan to remove my Orange Livebox (Fiber link) with a Fortinet Firewall and a GPON by LEOX LXT-01G-D but my FortiGate firewall (like most of Security device) cannot send all required options needed by Orange for authentication :

  • DHCP v4 request need to be done using CoS set to 6 (DSCP 48) with custom options 60,61, 77 and 90
  • DHCP v6 sollicit need to be done using CoS set to 6 (DSCP 48) with custom options 11, 15, 16 and 17

I would like to use a sort of black box running OpenWRT in transparent mode inserted between the GPON and the Firewall injecting on the fly for each DHCP v4 request and for each DHCP v6 sollicit the missing required options and setting the CoS to 6 (DSCP 48)

Is it possible to achieve a such box ?
If yes what could be the main architecture ?

Many thanks in advance.
Nicolas

Imaginable, yes.
Reasonably easy, no.