<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FTD DHCP relay on FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773504#M1028768</link>
    <description>Hello,&lt;BR /&gt;&lt;BR /&gt;I already have the relay configured. But I do not have the set route checked as the DHCP gives out the default gw&lt;BR /&gt;</description>
    <pubDate>Sat, 05 Jan 2019 16:09:48 GMT</pubDate>
    <dc:creator>Poliberte</dc:creator>
    <dc:date>2019-01-05T16:09:48Z</dc:date>
    <item>
      <title>Cisco FTD DHCP relay on FMC</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773319#M1028764</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently stuck with an issue with DHCP relay&amp;nbsp; not working on cisco FTD over site-to-site VPN and hoping you can assist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a setup which looks like this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN----&amp;gt;FTD1 ---&amp;gt;VPN--&amp;gt;&amp;gt;FTD2--&amp;gt;CORE--&amp;gt; DHCP subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FTD1 is configured for DHCP relay and is also the GW for the LAN. I have DHCP listening on FTD1 on the LAN and the relay gong out my WAN interface. My no nat is working and I have wide open rules for the access policy. However, the firewall drops the packet per packet tracer.&amp;nbsp; I'm thinking that my issue is because when the firewall repackages the DHCP broadcast to unicast using the LAN interface. I know that the ASA didn't allow traffic through it, to another interface. Is that the issue i'm experiencing here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x2b587aaf44c0, priority=501, domain=permit, deny=true&lt;BR /&gt;hits=25, user_data=0x7, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=10.0.82.1, mask=255.255.255.255, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=v448, output_ifc=any&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773319#M1028764</guid>
      <dc:creator>Poliberte</dc:creator>
      <dc:date>2020-02-21T16:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD DHCP relay on FMC</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773416#M1028766</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Try configuring DHCP relay agent and external DHCP server and see.&lt;/P&gt;
&lt;H3 id="toc-hId-1182468318"&gt;Configure the DHCP Relay Agent&lt;/H3&gt;
&lt;P&gt;Navigate to&lt;STRONG&gt;Devices &amp;gt; Device Management&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;edit&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;button&amp;nbsp;of&amp;nbsp;the FTD appliance. Navigate to&lt;STRONG&gt;DHCP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;DHCP Relay&lt;/STRONG&gt;&amp;nbsp;option.&amp;nbsp;&lt;/SPAN&gt;Click the&amp;nbsp;&lt;STRONG&gt;Add&amp;nbsp;&lt;/STRONG&gt;button.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Interface:&amp;nbsp;&lt;/STRONG&gt;Specify the interface from the drop-down list where interface listens for the client request. DHCP client should connect&amp;nbsp;directly to this interface for IP address request.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Enable DHCP Relay:&amp;nbsp;&lt;/STRONG&gt;Enable the checkbox&amp;nbsp;to enable the DHCP relay service.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Set Route:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Enable the check box to set the interface IP address as the default gateway.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline"&gt;&lt;A class="show-image-alone" title="Related image, diagram or screenshot." href="https://www.cisco.com/c/dam/en/us/support/docs/security/firepower-ngfw/200475-Configure-DHCP-Server-Relay-on-FTD-Using-05.png" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/support/docs/security/firepower-ngfw/200475-Configure-DHCP-Server-Relay-on-FTD-Using-05.png" border="0" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Click the&amp;nbsp;&lt;STRONG&gt;OK&amp;nbsp;&lt;/STRONG&gt;button to save the DHCP relay agent configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A class="auto_toc_anchor" name="anc11" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H3 id="toc-hId--1369688643"&gt;Configure External DHCP Server&lt;/H3&gt;
&lt;P&gt;You need to specify the IP address of external DHCP server where client request is&amp;nbsp; forwarded.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To specify the DHCP server, navigate to&amp;nbsp;&lt;STRONG&gt;DHCP Server&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server: &amp;nbsp;&lt;/STRONG&gt;Specify the IP address of DHCP server.&amp;nbsp;&lt;SPAN&gt;Either you can select the network object from the drop-down list or click the&amp;nbsp;&lt;STRONG&gt;plus (+)&lt;/STRONG&gt;&amp;nbsp;icon and create a network object for DHCP server.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Interface&lt;/STRONG&gt;: Specify the interface where DHCP server connects.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline"&gt;&lt;A class="show-image-alone" title="Related image, diagram or screenshot." href="https://www.cisco.com/c/dam/en/us/support/docs/security/firepower-ngfw/200475-Configure-DHCP-Server-Relay-on-FTD-Using-06.png" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/support/docs/security/firepower-ngfw/200475-Configure-DHCP-Server-Relay-on-FTD-Using-06.png" border="0" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to save the configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Click the&amp;nbsp;&lt;STRONG&gt;Save&amp;nbsp;&lt;/STRONG&gt;button to save the platform setting.&amp;nbsp;Navigate to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Deploy&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;option, select the FTD appliance where you want to apply the changes &amp;amp; click the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Deploy&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;button to start deployment of platform&amp;nbsp;&lt;/SPAN&gt;setting&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abheesh&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jan 2019 10:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773416#M1028766</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-01-05T10:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD DHCP relay on FMC</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773504#M1028768</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;I already have the relay configured. But I do not have the set route checked as the DHCP gives out the default gw&lt;BR /&gt;</description>
      <pubDate>Sat, 05 Jan 2019 16:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773504#M1028768</guid>
      <dc:creator>Poliberte</dc:creator>
      <dc:date>2019-01-05T16:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD DHCP relay on FMC</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773821#M1028770</link>
      <description>&lt;P&gt;Ok, so my issue was because I'm an idiot :).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I fat fingered one of my network objects which had an impact on my access policies, NAT, and interesting traffic for the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 01:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-dhcp-relay-on-fmc/m-p/3773821#M1028770</guid>
      <dc:creator>Poliberte</dc:creator>
      <dc:date>2019-01-07T01:46:46Z</dc:date>
    </item>
  </channel>
</rss>

