<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - DHCP relay not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349754#M1031348</link>
    <description>&lt;P&gt;Thanks for the reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see you have a pretty up to date OS running on the firewall.&lt;/P&gt;
&lt;P&gt;What I would do&lt;/P&gt;
&lt;P&gt;1. Open a TAC case if possible&lt;/P&gt;
&lt;P&gt;2. No matter no1 option, I would review&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;EM&gt;show conn, show cpu, show memory.&amp;nbsp;&lt;/EM&gt;Even better if you have all these three resources graphed out on a daily base usage. Next I would&amp;nbsp;&lt;STRONG&gt;retest&amp;nbsp;&lt;/STRONG&gt;DHCP relay service on the least busy&amp;nbsp;&lt;EM&gt;period of the day&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Last but not least since this is not working for you currently, I would clean up one of the two DHCP servers from config. Maybe this&amp;nbsp;&lt;EM&gt;will make things easier for&amp;nbsp;&lt;/EM&gt;your busy firewall.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2018 10:47:51 GMT</pubDate>
    <dc:creator>Florin Barhala</dc:creator>
    <dc:date>2018-03-16T10:47:51Z</dc:date>
    <item>
      <title>ASA - DHCP relay not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348583#M1031341</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm having an issue with DHCP relay on my ASA.&lt;/P&gt;
&lt;P&gt;My clients are in a DMZ and my DHCP server is behind the inside interface.&lt;/P&gt;
&lt;P&gt;DHCPrelay is configured correctly, but clients are not getting an IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After troubleshooting, I'm under the impression that the problem is that packets sourced from the ASA (which DHCPrelay does) are getting dropped.&lt;/P&gt;
&lt;P&gt;When doing a packet trace with source IP the IP address of the ASA's DMZ interface to the DHCP server, the packet is dropped, eventhough I have an explicit rule allowing this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All examples I run in to with regards to DHCPrelay on ASA, are always with clients on the inside and DHCP server on the DMZ/outside; being the packet going from a higher security level to a lower one. In my case, it is the opposite.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone that can help?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dario&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348583#M1031341</guid>
      <dc:creator>dario.didio</dc:creator>
      <dc:date>2020-02-21T15:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA sourced packets dropped</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348589#M1031342</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check wether&lt;STRONG&gt; any&lt;/STRONG&gt; of the items discussed in this thread can be helpfull to you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://supportforums.cisco.com/t5/firewalling/dhcp-relay-on-asa-5505-to-windows-dhcp-server-not-working/td-p/2764667" target="_blank"&gt;https://supportforums.cisco.com/t5/firewalling/dhcp-relay-on-asa-5505-to-windows-dhcp-server-not-working/td-p/2764667&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 16:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348589#M1031342</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2018-03-14T16:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA sourced packets dropped</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348593#M1031343</link>
      <description>Hi,&lt;BR /&gt;thanks for the answer, much appreciated!&lt;BR /&gt;unfortunately, it doesn't solve my problem and I cannot move the DHCP functionality to my ASA, it needs to be relayed.&lt;BR /&gt;Thanks,&lt;BR /&gt;Dario</description>
      <pubDate>Wed, 14 Mar 2018 16:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348593#M1031343</guid>
      <dc:creator>dario.didio</dc:creator>
      <dc:date>2018-03-14T16:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA sourced packets dropped</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348595#M1031344</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I understand, but the article just discusses &lt;STRONG&gt;that&lt;/STRONG&gt; '&lt;FONT color="#0000FF"&gt;only'&lt;/FONT&gt; (!).&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 16:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3348595#M1031344</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2018-03-14T16:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DHCP relay not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349121#M1031345</link>
      <description>&lt;P&gt;After some more digging, I found in the ASP drops that the ASA is dropping DHCP related messages, coming from our internal server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 4: 13:08:04.482991&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 5: 13:08:04.531039&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 6: 13:08:04.731407&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 314 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 7: 13:08:05.176550&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 8: 13:08:05.809528&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 9: 13:08:06.231524&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 314 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 10: 13:08:06.481450&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 314 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 11: 13:08:06.887878&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 12: 13:08:07.590927&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 13: 13:08:07.718361&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 14: 13:08:08.017790&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 15: 13:08:08.531192&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.x.x.67 &amp;gt; 255.255.255.255.68:&amp;nbsp; udp 318 Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reason is 'flow denied due to resource limitation'.&lt;/P&gt;
&lt;P&gt;According to this page: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/show_asp_drop/show_asp_drop.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/show_asp_drop/show_asp_drop.html&lt;/A&gt;&lt;/P&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231811" target="_blank"&gt;&lt;/A&gt;Name: unable-to-create-flow&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231812" target="_blank"&gt;&lt;/A&gt;Flow denied due to resource limitation:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231813" target="_blank"&gt;&lt;/A&gt; This counter is incremented and the packet is dropped when flow creation fails due to a system resource limitation. The resource limit may be either:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231814" target="_blank"&gt;&lt;/A&gt; 1) system memory&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231815" target="_blank"&gt;&lt;/A&gt; 2) packet block extension memory&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231816" target="_blank"&gt;&lt;/A&gt; 3) system connection limit&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231817" target="_blank"&gt;&lt;/A&gt; Causes 1 and 2 will occur simultaneously with flow drop reason "No memory to complete flow".&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231818" target="_blank"&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231819" target="_blank"&gt;&lt;/A&gt;Recommendation:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231820" target="_blank"&gt;&lt;/A&gt; - Observe if free system memory is low.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231821" target="_blank"&gt;&lt;/A&gt; - Observe if flow drop reason "No memory to complete flow" occurs.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231822" target="_blank"&gt;&lt;/A&gt; - Observe if connection count reaches the system connection limit with the command "show resource usage".&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231823" target="_blank"&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231824" target="_blank"&gt;&lt;/A&gt;Syslogs:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;&lt;A name="pgfId-231825" target="_blank"&gt;&lt;/A&gt; None&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;&lt;SPAN&gt;None of the above are applicable to us. Could this be a bug? We're running version 9.1(7)23 on an 5510 platform with 1GB memory.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Mar 2018 12:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349121#M1031345</guid>
      <dc:creator>dario.didio</dc:creator>
      <dc:date>2018-03-15T12:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DHCP relay not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349176#M1031346</link>
      <description>Quick questions:&lt;BR /&gt;1. Can you share the output of "show run dhcprelay"&lt;BR /&gt;2. What command did you use to see these drops?&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Thu, 15 Mar 2018 13:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349176#M1031346</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-15T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DHCP relay not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349260#M1031347</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;1. Output of show run dhcprelay:&lt;BR /&gt;dhcprelay server x.x.x.x inside&lt;BR /&gt;dhcprelay server x.x.x.x inside&lt;BR /&gt;dhcprelay enable DMZ-1&lt;BR /&gt;dhcprelay enable DMZ-2&lt;BR /&gt;dhcprelay enable DMZ-3&lt;BR /&gt;dhcprelay enable DMZ-4&lt;BR /&gt;dhcprelay enable DMZ-5&lt;BR /&gt;dhcprelay timeout 90&lt;BR /&gt;&lt;BR /&gt;2. I created a capture using 'capture cap type asp-drop all'&lt;BR /&gt;</description>
      <pubDate>Thu, 15 Mar 2018 14:44:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349260#M1031347</guid>
      <dc:creator>dario.didio</dc:creator>
      <dc:date>2018-03-15T14:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DHCP relay not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349754#M1031348</link>
      <description>&lt;P&gt;Thanks for the reply!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see you have a pretty up to date OS running on the firewall.&lt;/P&gt;
&lt;P&gt;What I would do&lt;/P&gt;
&lt;P&gt;1. Open a TAC case if possible&lt;/P&gt;
&lt;P&gt;2. No matter no1 option, I would review&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;EM&gt;show conn, show cpu, show memory.&amp;nbsp;&lt;/EM&gt;Even better if you have all these three resources graphed out on a daily base usage. Next I would&amp;nbsp;&lt;STRONG&gt;retest&amp;nbsp;&lt;/STRONG&gt;DHCP relay service on the least busy&amp;nbsp;&lt;EM&gt;period of the day&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Last but not least since this is not working for you currently, I would clean up one of the two DHCP servers from config. Maybe this&amp;nbsp;&lt;EM&gt;will make things easier for&amp;nbsp;&lt;/EM&gt;your busy firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 10:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-relay-not-working/m-p/3349754#M1031348</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-16T10:47:51Z</dc:date>
    </item>
  </channel>
</rss>

