<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD RA VPN - DHCP Server configuration not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/5297865#M1121280</link>
    <description>&lt;P&gt;In our case, it turns out the Microsoft DHCP server requires the VPN appliance to be authorized.&amp;nbsp; Otherwise the Microsoft DHCP server will consider the FTD appliance a rogue relay and ignore requests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;More info at&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-subnet-options" target="_blank"&gt;https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-subnet-options&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jun 2025 16:27:26 GMT</pubDate>
    <dc:creator>Alfredo_1</dc:creator>
    <dc:date>2025-06-09T16:27:26Z</dc:date>
    <item>
      <title>FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4007398#M934312</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I have a problem with RA VPN DHCP configuration. VPN users get IP address from the local pool just fine, but when I try to use my Windows Server 2012 R2 DHCP server, i get the following errors and it always falls back to local pool:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IPAA: Session=0x0000e000, &lt;SPAN class="dash-highlighter"&gt;DHCP&lt;/SPAN&gt; request attempt 1 failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IPAA: Session=0x0000e000, &lt;/SPAN&gt;&lt;SPAN class="dash-highlighter"&gt;DHCP&lt;/SPAN&gt;&lt;SPAN&gt; configured, request failed for tunnel-group 'DefaultWEBVPNGroup'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank"&gt;IPAA: Session=0x0000e000, Client assigned 172.16.10.13 from local pool VPN_user&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank"&gt;IPAA: Session=0x0000e000, Local pool request succeeded for tunnel-group 'DefaultWEBVPNGroup'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the Windows Server side I cannot see any logs pointing to this, so I guess the request never reaches the server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now, what I have done as per following the documentations I could find:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- Defined DHCP -server address (172.16.0.20) in the Connection Profile&lt;/P&gt;&lt;P&gt;- Defined the Address Pools (172.16.10.10-172.16.10.150) in Connection Profile and Group Policy&lt;/P&gt;&lt;P&gt;- Defined a DHCP Network Scope (172.16.10.0) in Group Policy and in the Windows Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like the FTD cannot find the DHCP server, but my DHCP Relay settings are working just fine for the same server. Any advice? Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4007398#M934312</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-02-21T17:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4007855#M934313</link>
      <description>Hi,&lt;BR /&gt;I recently setup FTD RAVPN (v6.4.5) with DHCP and it worked first time without issue, so special configuration that I can recall. Which FTD version are you running?&lt;BR /&gt;&lt;BR /&gt;To troubleshoot run a packet capture on the server end and see if the DHCP server receives the DHCP "discover" packet from the FTD. Enable DHCP debugging on the FTD (debug dhcprelay error|event|packet) - and check to see if the DHCP request was even made. Upload the debug output for review if necessary.</description>
      <pubDate>Tue, 07 Jan 2020 22:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4007855#M934313</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-01-07T22:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4007954#M934314</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running the latest version 6.5.0.2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enabled debugging for error, event and packet but connecting the VPN client does not produce any debug log entries. I can see other dhcp relay debug logs just fine. Again I just get the same error in the logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank"&gt;IPAA: Session=0x00020000, DHCP request attempt 1 failed&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank"&gt;IPAA: Session=0x00020000, DHCP configured, request failed for tunnel-group 'DefaultWEBVPNGroup'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 07:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4007954#M934314</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-01-08T07:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4011747#M934315</link>
      <description>&lt;P&gt;Any advice on what to do next? It seems like the FTD is not making the dhcp request at all for the RA VPN. Although in the log I can find "DHCP Configured".&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 10:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4011747#M934315</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-01-15T10:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4014910#M934316</link>
      <description>Do you have a route on your core switch for the RAVPN subnet pointing to the FTD?&lt;BR /&gt;Did you run a packet capture on the DHCP server? Did you see any DHCP Discover packets from the FTD IP address?</description>
      <pubDate>Mon, 20 Jan 2020 21:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4014910#M934316</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-01-20T21:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4015083#M934317</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the routing is done in the FTD device, I only have layer 2 switches. On the FTD I only have the default route atm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet capture on the DHCP server doesn't show any traffic originating from the FTD IP.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 07:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4015083#M934317</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-01-21T07:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4038777#M1067203</link>
      <description>&lt;P&gt;Where you ever able to solve this?&amp;nbsp; I have the same problem.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 18:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4038777#M1067203</guid>
      <dc:creator>mhidde</dc:creator>
      <dc:date>2020-03-02T18:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4038860#M1067208</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Following the correct steps and running a stable version, will make it work. Here'a document to guide you:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200475-Configure-DHCP-Server-Relay-on-FTD-Using.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200475-Configure-DHCP-Server-Relay-on-FTD-Using.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 21:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4038860#M1067208</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-02T21:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4039030#M1067221</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Unfortunately I couldn't make it work. I have followed every step in the configuration guides, both DHCP and Remote Access VPN. DHCP relay works for my interfaces just fine, but for the RA VPN it will not work no matter what I do.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 05:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4039030#M1067221</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-03-03T05:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4039711#M1067269</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;See if you're hitting this bug:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo12057/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo12057/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Do you have the hot fix applied? Or try using 6.5.0.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 22:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4039711#M1067269</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-03T22:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4039907#M1067280</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks. I'm not sure if it's this bug or not, as my DHCP relay debug did not output anything. But I'll try installing 6.5.0.4 some time soon and investigate further after that. I'm currently running 6.5.0.2.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 05:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4039907#M1067280</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-03-04T05:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4040024#M1067296</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; If you have to postpone the upgrade, open a TAC case. Looking forward to know what your problem is, as it clearly looks like the FTD does not even initiate sending the DHCP packet to the DHCP server, so the relay function seem to be dead in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4040024#M1067296</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-04T09:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4075148#M1069552</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Firepower 2130 with FTD 6.6.0 I got the same issue. Same issue with DHCP server:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 0.000000 10.45.30.2 10.52.10.8 DHCP 590 DHCP Discover - Transaction ID 0x8c9cf9a&lt;BR /&gt;2 0.000565 10.52.10.8 10.44.96.20 DHCP 342 DHCP Offer - Transaction ID 0x8c9cf9a&lt;BR /&gt;3 2.988343 10.45.30.2 10.52.10.8 DHCP 590 DHCP Discover - Transaction ID 0x8c9cf9a&lt;BR /&gt;4 2.988740 10.52.10.8 10.44.96.20 DHCP 342 DHCP Offer - Transaction ID 0x8c9cf9a&lt;BR /&gt;5 6.988328 10.45.30.2 10.52.10.8 DHCP 590 DHCP Discover - Transaction ID 0x8c9cf9a&lt;BR /&gt;6 6.988770 10.52.10.8 10.44.96.20 DHCP 342 DHCP Offer - Transaction ID 0x8c9cf9a&lt;BR /&gt;7 11.990678 10.45.30.2 10.52.10.8 DHCP 590 DHCP Discover - Transaction ID 0x8c9cf9a&lt;BR /&gt;8 11.991105 10.52.10.8 10.44.96.20 DHCP 342 DHCP Offer - Transaction ID 0x8c9cf9a&lt;BR /&gt;9 17.988328 10.45.30.2 10.52.10.8 DHCP 590 DHCP Discover - Transaction ID 0x8c9cf9a&lt;BR /&gt;10 17.988679 10.52.10.8 10.44.96.20 DHCP 342 DHCP Offer - Transaction ID 0x8c9cf9a&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 20:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4075148#M1069552</guid>
      <dc:creator>doukkalli</dc:creator>
      <dc:date>2020-04-27T20:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4075331#M1069555</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently upgraded to 6.5.0.4 and it did not solve the problem. I suppose I'll have to open a TAC case.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 05:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4075331#M1069555</guid>
      <dc:creator>Elpakko</dc:creator>
      <dc:date>2020-04-28T05:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4075361#M1069557</link>
      <description>&lt;P&gt;Based on my capture I noted that FTD send DHCP request to DHCP server using the IP address assigned to the VPN as configured in the DHCP Scope.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case I will check if my DHCP server has the correct route to the IP address configured in the DHCP scope.&lt;/P&gt;&lt;P&gt;I will try this way. I hope we can solve the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 06:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/4075361#M1069557</guid>
      <dc:creator>doukkalli</dc:creator>
      <dc:date>2020-04-28T06:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN - DHCP Server configuration not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/5297865#M1121280</link>
      <description>&lt;P&gt;In our case, it turns out the Microsoft DHCP server requires the VPN appliance to be authorized.&amp;nbsp; Otherwise the Microsoft DHCP server will consider the FTD appliance a rogue relay and ignore requests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;More info at&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-subnet-options" target="_blank"&gt;https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-subnet-options&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jun 2025 16:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-dhcp-server-configuration-not-working/m-p/5297865#M1121280</guid>
      <dc:creator>Alfredo_1</dc:creator>
      <dc:date>2025-06-09T16:27:26Z</dc:date>
    </item>
  </channel>
</rss>

