<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Scott, Use cli to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766232#M178827</link>
    <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use cli to configure captures:&lt;/P&gt;&lt;P&gt;&amp;nbsp;cap capi interface inside match udp an an eq bootpc&lt;BR /&gt;&amp;nbsp;cap capi interface inside match udp an an eq bootps&lt;/P&gt;&lt;P&gt;Export captures using:&lt;/P&gt;&lt;P&gt;https://asaIP/capture/capi/pcap&lt;/P&gt;&lt;P&gt;Note: http server should be enabled on the ASA.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; After exporting caputre, disable captures using: no cap capi&lt;/P&gt;&lt;P&gt;ASA is sending the client id as:&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;aaaa.bbbb.cccc when client id is configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;If there nothing specified then client id is seen as: &amp;nbsp;cisco-aaaa.bbbb.cccc-outside-HOSTNAME.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; I am using another ASA as a dhcp server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Sep 2015 13:20:10 GMT</pubDate>
    <dc:creator>Rishabh Seth</dc:creator>
    <dc:date>2015-09-17T13:20:10Z</dc:date>
    <item>
      <title>ASA Client-ID and DHCP question</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766227#M178822</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have an ASA whose Outside interface is obtaining DHCP IP &amp;amp; Default Gateway. &amp;nbsp;When I look at the DHCP Client Lease Information I see: Client-ID: cisco-xxxx.xxxx.xxxx-outside-HOSTNAME where x=MAC and HOSTNAME=configured ASA hostname.&lt;/P&gt;&lt;P&gt;I am trying to change this to a standard MAC response response only. &amp;nbsp;I have the following configuration:&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;mac-address aaaa.bbbb.cccc&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;dhcp-client client-id interface outside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;But I am still sending the same Client-ID.&lt;/P&gt;&lt;P&gt;Any ideas how to make this feature work? &amp;nbsp;I understand the "cisco-xxx..." Client-ID is default with ASA's, but I also understand you can change it...&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766227#M178822</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2019-03-12T06:36:11Z</dc:date>
    </item>
    <item>
      <title>Hi Scott,This command seems</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766228#M178823</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;This command seems to work fine on 9.5.1 version, what version are you using on your ASA?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 10:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766228#M178823</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-16T10:48:15Z</dc:date>
    </item>
    <item>
      <title>Apologies,ASA 5505 running 9</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766229#M178824</link>
      <description>&lt;P&gt;Apologies,&lt;/P&gt;&lt;P&gt;ASA 5505 running 9.1(6)8&lt;/P&gt;&lt;P&gt;The latest software I see posted is 9.2.4. &amp;nbsp;Are you running the new X series for 9.5.1?&lt;/P&gt;&lt;P&gt;I'll try upgrading to 9.2.4.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 11:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766229#M178824</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2015-09-17T11:17:07Z</dc:date>
    </item>
    <item>
      <title>Hi Scott,The mac address is</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766230#M178825</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;The mac address is sent to the DHCP server with&amp;nbsp;dhcp-client client-id interface &amp;lt;int-name&amp;gt; command on version 9.1(6)8 as well.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; You can confirm if the ASA is sending the MAC address as the clinet id, by applying capture on the ASA for dhcp traffic and view the capture in wireshark and verify the client id in the packet.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Probably you should check the dhcp server as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What device is used as the dhcp server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 12:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766230#M178825</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-17T12:46:45Z</dc:date>
    </item>
    <item>
      <title>Hi Seth,What is the best way</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766231#M178826</link>
      <description>&lt;P&gt;Hi Seth,&lt;/P&gt;&lt;P&gt;What is the best way to setup this type of capture on the ASA as far as sequence of events? &amp;nbsp;I'm assuming since I'm coming from the Inside interface, I should:&lt;/P&gt;&lt;P&gt;1: remove "ip address dhcp setroute"&lt;BR /&gt;2:&amp;nbsp;shutdown Gi0/0 (Outside)&lt;BR /&gt;3: setup packet capture via wizard&lt;BR /&gt;4: add "ip address dhcp setroute" to Gi0/0&lt;BR /&gt;5: no shutdown Gi0/0&lt;/P&gt;&lt;P&gt;Also, just to clarify with your configuration: &amp;nbsp;Which Client-ID format is your ASA sending?&lt;BR /&gt;1: &amp;nbsp;cisco-aaaa.bbbb.cccc-outside-HOSTNAME&lt;BR /&gt;or&lt;BR /&gt;2: &amp;nbsp;aaaa.bbbb.cccc&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal is to achieve option 2. &amp;nbsp;My understanding is that if I set the "mac-address" option on Gi0/0 followed by "dhcp-client client-id interface outside" in global, option 2 should be the result.&lt;/P&gt;&lt;P&gt;Thanks again for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: &amp;nbsp;Also, I believe the DHCP server is Windows 2008, but not 100%&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 13:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766231#M178826</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2015-09-17T13:13:17Z</dc:date>
    </item>
    <item>
      <title>Hi Scott, Use cli to</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766232#M178827</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use cli to configure captures:&lt;/P&gt;&lt;P&gt;&amp;nbsp;cap capi interface inside match udp an an eq bootpc&lt;BR /&gt;&amp;nbsp;cap capi interface inside match udp an an eq bootps&lt;/P&gt;&lt;P&gt;Export captures using:&lt;/P&gt;&lt;P&gt;https://asaIP/capture/capi/pcap&lt;/P&gt;&lt;P&gt;Note: http server should be enabled on the ASA.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; After exporting caputre, disable captures using: no cap capi&lt;/P&gt;&lt;P&gt;ASA is sending the client id as:&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;aaaa.bbbb.cccc when client id is configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;If there nothing specified then client id is seen as: &amp;nbsp;cisco-aaaa.bbbb.cccc-outside-HOSTNAME.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; I am using another ASA as a dhcp server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 13:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766232#M178827</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-17T13:20:10Z</dc:date>
    </item>
    <item>
      <title>Hi Seth,Thanks for these CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766233#M178828</link>
      <description>&lt;P&gt;Hi Seth,&lt;/P&gt;&lt;P&gt;Thanks for these CLI instructions. &amp;nbsp;Very cool and didn't know about the simplicity of the CLI and URL.&lt;/P&gt;&lt;P&gt;I ended up having to Shut/No Shut Gi0/0 (Outside) in order to produce a DHCP Request. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Within the DHCP Request I see:&lt;BR /&gt;Option 61: Client Identifier&lt;BR /&gt;&amp;nbsp;&amp;nbsp;Client MAC address: Transiti_aa:bb:cc (aa:aa:bb:bb:cc:cc)&lt;BR /&gt;Option 12: Host Name&lt;BR /&gt;&amp;nbsp;&amp;nbsp;Host Name: &amp;nbsp;My-Device-Hostname&lt;/P&gt;&lt;P&gt;Along with other standard DHCP options. &amp;nbsp;These are the two I see as most relevant.&lt;/P&gt;&lt;P&gt;Yet when I open up ASDM, go to Monitoring, DHCP, DHCP Client Leasing Information, I still see the same "cisco-aa.bb...." Client-ID as before.&lt;/P&gt;&lt;P&gt;Could this be because I merely shut/noshut Gi0/0 and didn't give it enough time to timeout the lease? &amp;nbsp;Any idea on how to force the DHCP Server to renew (assuming this is the issue)?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 15:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766233#M178828</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2015-09-17T15:58:44Z</dc:date>
    </item>
    <item>
      <title>Hi Scott, &gt;&gt; Client ID that</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766234#M178829</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Client ID that you see on the ASDM under client-lease information is something&amp;nbsp;local to ASA and not being sent to the other device.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; What other device will see is decided in the interface configuration where you can specify the mac address to be used for client-id. Default option is&amp;nbsp;&lt;SPAN style="font-size: 14.4px; line-height: normal;"&gt;Client-ID: cisco-xxxx.xxxx.xxxx-outside-HOSTNAME but one can change it to only MAC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; From the captures it is clear that your dhcp server will be getting only MAC address as the client-id identifier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;Don't forget to mark correct answer, if your queries are answered.!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 17:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766234#M178829</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-09-17T17:06:09Z</dc:date>
    </item>
    <item>
      <title>Hi Seth,Thank you for</title>
      <link>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766235#M178830</link>
      <description>&lt;P&gt;Hi Seth,&lt;/P&gt;&lt;P&gt;Thank you for clarifying that what I see in ASDM isn't exactly what is being sent to DHCP Server. &amp;nbsp;I wish they would fix/change this!&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 17:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-client-id-and-dhcp-question/m-p/2766235#M178830</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2015-09-17T17:28:18Z</dc:date>
    </item>
  </channel>
</rss>

