<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD dhcp relay (7.2.5) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140241#M1114013</link>
    <description>&lt;P&gt;And the PNGs:&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2024 18:53:40 GMT</pubDate>
    <dc:creator>Ditter</dc:creator>
    <dc:date>2024-07-04T18:53:40Z</dc:date>
    <item>
      <title>FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140240#M1114012</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;&lt;P&gt;a little bit confused about configuring the equivalent of command "ip helper address" in FMC.&lt;/P&gt;&lt;P&gt;My topology is like this:&lt;/P&gt;&lt;P&gt;&amp;lt;---Inside-dhcp-clients_vlan100----&amp;gt; FTD &amp;lt;--outside interface_vlan_27--&amp;gt; 6500 &amp;lt;-- SVI where the DHCP SERVER lives&amp;nbsp; --&amp;gt;&lt;/P&gt;&lt;P&gt;What i want is the DHCP clients that are in different VLANs in FTD to be able to get their IP address from the remote DHCP server.&lt;/P&gt;&lt;P&gt;The FTD is also a DHCP server for an additional VLAN.&lt;/P&gt;&lt;P&gt;For example the dhcp clients reside in vlan 100 in FTD. The DHCP server (192.168.65.7) is reachable via OSPF from the FTD outside interface which is vlan 27.&lt;/P&gt;&lt;P&gt;What i tried to configure is in the png attached:&lt;/P&gt;&lt;P&gt;The problem is that i can not save any change as i get the error message you see in the png.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ditter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 18:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140240#M1114012</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-04T18:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140241#M1114013</link>
      <description>&lt;P&gt;And the PNGs:&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 18:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140241#M1114013</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-04T18:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140243#M1114014</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/655758"&gt;@Ditter&lt;/a&gt; that is not possible, as per the guide:&lt;/P&gt;
&lt;P&gt;"You cannot configure both a DHCP server and &lt;SPAN class="searchMark primary"&gt;DHCP relay&lt;/SPAN&gt; on the same device, even if you want to enable them on different interfaces; you can only configure one type of service."&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/interfaces-settings-dhcp-ddns.html?bookSearch=true#task_F1FFF15591C148119AE2FDB8837E7C36" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/interfaces-settings-dhcp-ddns.html?bookSearch=true#task_F1FFF15591C148119AE2FDB8837E7C36&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You will have to use the same DHCP server for all VLANS, whether its the FTD itself or a remote DHCP server via the relay.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 18:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140243#M1114014</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-04T18:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140249#M1114016</link>
      <description>&lt;P&gt;can not make 6500 do relay for some VLAN and make FTD server for other VLAN ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 19:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140249#M1114016</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-04T19:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140256#M1114017</link>
      <description>&lt;P&gt;Hi MHM Cisco World,&lt;/P&gt;&lt;P&gt;but the dhcp clients are on vlans that are in the inside zone of the FTD and the DHCP linux server is behind the 6500, shouldn;t i configure the dhcp relay function on the FTD itself?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 19:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140256#M1114017</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-04T19:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140260#M1114018</link>
      <description>&lt;P&gt;I will give it a try tomorrow and let you know&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 19:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140260#M1114018</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-04T19:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140262#M1114020</link>
      <description>&lt;P&gt;Inside and outside connect to to 6500 then it connect FTD&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Inside use vlan 100 and outside use different vlan.&lt;/P&gt;
&lt;P&gt;What I suggest is add svi in 6500 vlan 100 with ip helper.&lt;/P&gt;
&lt;P&gt;That my suggestion.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 19:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140262#M1114020</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-04T19:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140264#M1114021</link>
      <description>&lt;P&gt;To be honest' if this my network I will config FTD as dhcp relay for all vlan' ftd dhcp server missing many features.&lt;/P&gt;
&lt;P&gt;So if you can make ftd relay the dhcp for all vlan that is so so better&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Goodluck friend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 19:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140264#M1114021</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-04T19:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140496#M1114025</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply,&amp;nbsp; that is what i intend to do.&lt;/P&gt;&lt;P&gt;The dhcpd server running on linux is feature rich and i think&amp;nbsp; does not compare with the FTD dhcp service.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 07:30:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5140496#M1114025</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-05T07:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141121#M1114065</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just letting you know that the DHCP relay agent worked OK, the clients get their IP address from the linux DHCPd.&lt;/P&gt;&lt;P&gt;One problem i found is that the option82 is not sent to the DHCP server and that is a problem as the information carried by option 82 is very useful.&lt;/P&gt;&lt;P&gt;Googling it i found the following:&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvx10377?rfs=qvred" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCvx10377?rfs=qvred&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Running&amp;nbsp; 7.2.5.1 (Build 29).&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Ditter.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 17:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141121#M1114065</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-07T17:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141122#M1114066</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/655758"&gt;@Ditter&lt;/a&gt; that bug does not have a workaround, so perhaps Flexconfig won't work. You could attempt to configure the ASA CLI command (as per your link) via Flexconfig and see if that works.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa920/configuration/general/asa-920-general-config/basic-dhcp-ddns.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa920/configuration/general/asa-920-general-config/basic-dhcp-ddns.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Other than that, use a helper-address on a switch if possible.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 17:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141122#M1114066</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-07T17:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141125#M1114067</link>
      <description>&lt;P&gt;Never done asa cli commands via flexconfig. I will try by first looking at the documentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the second option you suggested , i do not know how it can be done if the switch does not have&amp;nbsp; L3 interfaces on all DHCP vlans?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 17:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141125#M1114067</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-07T17:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141127#M1114068</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/655758"&gt;@Ditter&lt;/a&gt; if using Flexconfig you just create a Flexconfig object and use the ASA command, assign this object to the FTD. If that command is not supported it will likely tell you it is blacklisted.&lt;/P&gt;
&lt;P&gt;If that Flexconfig option does not work, the only other option I can think of is using the helper-address. Any reason why you cannot define SVI on the switches for your VLANs? What model of switch do you have?&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 18:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141127#M1114068</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-07T18:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141129#M1114069</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thanks Rob,&amp;nbsp; i went through the documentation and tried the command&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;dhcprelay information&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;trust-all&amp;nbsp; ,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;i do not know if i did everything correctly , i got a pop-up command not supported or something similar.&amp;nbsp; Then i went through the FTD documentation , i noticed that in releases next to 7.2.5 , the command is supported. I will most probably try the upgrade.&amp;nbsp; As far as the second option is concerned i have 50 switches and around 30 Vlans , so it does not seem so scalable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Ditter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 18:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141129#M1114069</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-07T18:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141130#M1114070</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/655758"&gt;@Ditter&lt;/a&gt; looks like that DHCP option 82 command is available&amp;nbsp;natively in the FMC GUI from 7.2.6 or 7.4.1.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/roadmap/management-center-new-features-by-release.html#c_new-features-fmc-726__ph_dhcp_flexconfig" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/roadmap/management-center-new-features-by-release.html#c_new-features-fmc-726__ph_dhcp_flexconfig&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;7.2.6 was quickly removed due to a bug, so if you wish to remain on 7.2.x upgrade to 7.2.7/7.2.8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 18:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141130#M1114070</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-07T18:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD dhcp relay (7.2.5)</title>
      <link>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141135#M1114072</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thanks , i am currently upgrading to 7.2.8.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 19:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-dhcp-relay-7-2-5/m-p/5141135#M1114072</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2024-07-07T19:37:10Z</dc:date>
    </item>
  </channel>
</rss>

