<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi cofee &amp; johnlloyd, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948178#M144706</link>
    <description>&lt;P&gt;Hi cofee &amp;amp; johnlloyd,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is example my simple network connection, I have ;-&lt;/P&gt;
&lt;P&gt;1- DHCP Server &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; firewall &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; switch &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; client = &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Failed.&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I also try configure my router as a dhcp server and it's working fine.&lt;/P&gt;
&lt;P&gt;2- Router ( dhcp enable) &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; firewall &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; switch &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; client = &lt;SPAN style="color: #00ff00;"&gt;&lt;STRONG&gt;Successful.&amp;nbsp;&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The configuration works when my router as a dhcp server. Problem become when I change to use my DHCP server only.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Firewall Configuration;-&lt;/P&gt;
&lt;P&gt;- dhcprelay server 202.100.1.3 SERVER_DMZ&lt;/P&gt;
&lt;P&gt;- dhcprelay enable inside&lt;/P&gt;
&lt;P&gt;- dhcprelay setroute inside&lt;/P&gt;
&lt;P&gt;- dhcprelay timeout 90&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Switch configuration;-&lt;/P&gt;
&lt;P&gt;- &lt;STRONG&gt;&lt;SPAN style="color: #333300;"&gt;switchport mode access / default configure.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;-no vlan&lt;/P&gt;
&lt;P&gt;-no trunk&lt;/P&gt;</description>
    <pubDate>Fri, 25 Nov 2016 10:10:06 GMT</pubDate>
    <dc:creator>azrex_22</dc:creator>
    <dc:date>2016-11-25T10:10:06Z</dc:date>
    <item>
      <title>ASA 5516-X dhcprelay not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948173#M144666</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have an issue with my ASA FW is not working for dhcprelay. I try to configure just for a basic or simple network setup but it's failed,my client cannot get the ip from server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;DHCP server --&amp;gt; ASA Firewall --&amp;gt; Switch --&amp;gt; Client&lt;/P&gt;
&lt;P&gt;#&lt;STRONG&gt;Server Ip - 202.100.1.3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;#&lt;STRONG&gt;Ip dhcp - 192.168.100.1/24&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is example of my ASA configuration.&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;&amp;nbsp;nameif &lt;STRONG&gt;inside&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 192.168.100.254 255.255.255.0 &lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;&amp;nbsp;nameif &lt;STRONG&gt;SERVER_DMZ&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 202.100.1.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;dhcprelay server 202.100.1.3 &lt;STRONG&gt;SERVER_DMZ&lt;/STRONG&gt;&lt;BR /&gt;dhcprelay enable &lt;STRONG&gt;inside&lt;/STRONG&gt;&lt;BR /&gt;dhcprelay setroute&lt;STRONG&gt; inside&lt;/STRONG&gt;&lt;BR /&gt;dhcprelay timeout 90&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948173#M144666</guid>
      <dc:creator>azrex_22</dc:creator>
      <dc:date>2019-03-12T08:34:43Z</dc:date>
    </item>
    <item>
      <title>Hi Azrex,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948174#M144677</link>
      <description>&lt;P&gt;Hi Azrex,&lt;/P&gt;
&lt;P&gt;Did you test connectivity between your inside and dmz network? Also what makes you think the firewall is the problem ?are you certain that dhcp packets are making to the firewall by debugging dhcp packets on the firewall?&lt;/P&gt;
&lt;P&gt;i am not sure how your switch is configured, but if you are using svi for the client subnet on the switch is it configured with dhcp relay?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;config on the firewall that you sent seems to be fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 03:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948174#M144677</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2016-11-24T03:11:17Z</dc:date>
    </item>
    <item>
      <title>Hi cofee,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948175#M144692</link>
      <description>&lt;P&gt;Hi cofee,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am not to expert in this network environment however I'm glad to learn from you and all professional person in here.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I already test my connectivity between inside and dmz, However could you please explain to me about&amp;nbsp; the&amp;nbsp;&lt;STRONG&gt;test connectivity between inside and dmz &lt;/STRONG&gt;more&lt;STRONG&gt; &lt;/STRONG&gt;detail because maybe I forgot some step during the troubleshoot.&lt;/P&gt;
&lt;P&gt;My switch only configure &lt;STRONG&gt;switch port mode access, &lt;/STRONG&gt;there is any configuration I need to add or change it?.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 04:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948175#M144692</guid>
      <dc:creator>azrex_22</dc:creator>
      <dc:date>2016-11-24T04:12:37Z</dc:date>
    </item>
    <item>
      <title>Hello Azrex,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948176#M144698</link>
      <description>&lt;P&gt;Hello Azrex,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I meant by testing connectivity between inside and dmz if you are able to reach the DMZ environment from your inside network for&amp;nbsp; example ping/telnet/ssh so we know that connectivity is not an issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please check or answer following things:&lt;/P&gt;
&lt;P&gt;a) switchport your end host is connected is it in the right vlan?&lt;/P&gt;
&lt;P&gt;b) Do you have an SVI configured for that VLAN on your core switch and is it configured for dhcp relay?&lt;/P&gt;
&lt;P&gt;for example -&lt;/P&gt;
&lt;P&gt;Int vlan 2&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;ip helper-address &lt;STRONG&gt;202.100.1.3&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;But I am not sure how your network looks like. Let us know if you are using your firewall inside&amp;nbsp;interface as the default gateway for the client or is there a multilayer core switch on the inside network that client is using for default gateway. Can you draw your network and share it? Also is it just one client that's not getting address from the DHCP server or is it all the end hosts connected to inside network having the same issue?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;The other thing you can do is look at the firewalls logs and debug commands on the asa:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;debug dhcprelay&lt;/STRONG&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;So after you initiate the debug command on the ASA, reboot the PC you are working on and when it comes back up it will broadcast DHCPDISCOVER packet. So your job will be to look at the firewall and see if it's getting those packets and what is it doing with them. Logs and debugging on the asa will give you a lot of information. If you don't see anything on the ASA then problem might be something internal like between the switch and end host.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;STRONG&gt;Let me know if you have any questions.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 12:04:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948176#M144698</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2016-11-24T12:04:53Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948177#M144704</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;your &lt;STRONG&gt;inside&lt;/STRONG&gt; has a lower security-level 0 while &lt;STRONG&gt;SERVER_DMZ&lt;/STRONG&gt; has higher (100), which means you'll need to explicitly create ACL/allow DHCP relay ports from &lt;STRONG&gt;inside&lt;/STRONG&gt; (untrusted) to &lt;STRONG&gt;SERVER_DMZ &lt;/STRONG&gt;(trusted).&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 13:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948177#M144704</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-11-24T13:38:32Z</dc:date>
    </item>
    <item>
      <title>Hi cofee &amp; johnlloyd,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948178#M144706</link>
      <description>&lt;P&gt;Hi cofee &amp;amp; johnlloyd,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is example my simple network connection, I have ;-&lt;/P&gt;
&lt;P&gt;1- DHCP Server &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; firewall &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; switch &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; client = &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Failed.&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I also try configure my router as a dhcp server and it's working fine.&lt;/P&gt;
&lt;P&gt;2- Router ( dhcp enable) &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; firewall &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; switch &lt;STRONG&gt;--&amp;gt;&lt;/STRONG&gt; client = &lt;SPAN style="color: #00ff00;"&gt;&lt;STRONG&gt;Successful.&amp;nbsp;&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The configuration works when my router as a dhcp server. Problem become when I change to use my DHCP server only.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Firewall Configuration;-&lt;/P&gt;
&lt;P&gt;- dhcprelay server 202.100.1.3 SERVER_DMZ&lt;/P&gt;
&lt;P&gt;- dhcprelay enable inside&lt;/P&gt;
&lt;P&gt;- dhcprelay setroute inside&lt;/P&gt;
&lt;P&gt;- dhcprelay timeout 90&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Switch configuration;-&lt;/P&gt;
&lt;P&gt;- &lt;STRONG&gt;&lt;SPAN style="color: #333300;"&gt;switchport mode access / default configure.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;-no vlan&lt;/P&gt;
&lt;P&gt;-no trunk&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 10:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948178#M144706</guid>
      <dc:creator>azrex_22</dc:creator>
      <dc:date>2016-11-25T10:10:06Z</dc:date>
    </item>
    <item>
      <title>Do this with the set up that</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948179#M144708</link>
      <description>&lt;P dir="ltr"&gt;Do this with the set up that's failing:&lt;/P&gt;
&lt;P&gt;directly connect the client with DHCP server and see if it successfully pulls an ip, if not than you know there is something wrong with the configuration on your DHCP server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The set up that works the only thing you changed was the DHCP server itself, you didn't mention making any other changes. You can rule out client/switch/firewall&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 12:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948179#M144708</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2016-11-25T12:28:14Z</dc:date>
    </item>
    <item>
      <title>Hi Cofee,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948180#M144712</link>
      <description>&lt;P&gt;Hi Cofee,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I also tested with directly connect from DHCP server to client and it's okay.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;DHCP server --&amp;gt; switch --&amp;gt; client = OK.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I don't know what need to do anymore..just like my brain freeze for this part.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 02:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-dhcprelay-not-working/m-p/2948180#M144712</guid>
      <dc:creator>azrex_22</dc:creator>
      <dc:date>2016-11-28T02:58:30Z</dc:date>
    </item>
  </channel>
</rss>

