<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help to allow traffic through firewall to DHCP server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265287#M348230</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help, It's realy helpful to clear my query.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jun 2013 05:08:55 GMT</pubDate>
    <dc:creator>suryakant.chavan</dc:creator>
    <dc:date>2013-06-13T05:08:55Z</dc:date>
    <item>
      <title>Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265281#M348224</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My setup is as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inside host--&amp;gt; ASA1--Outside interface- layer_ 2_Switch1--outside interface--&amp;gt; ASA2--inside interface-DHCP SERVER.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want that inside host should get ip from subnet 192.168.10.0 /24. This ip pool is configured in DHCP server (ip 172.16.10.1) which is connected to ASA2. There is no routing issue as we are able to ping DHCP srever 172.16.10.1 from ASA1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pl's help me , to do config needed on&amp;nbsp; ASA1 and ASA2 , so that host connected to ASA1 inside interface can get ip from DHCP srever. We have configured 192.168.10.1 /24 to ASA1 inside interface which will be gateway to inside host of ASA1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ,&lt;/P&gt;&lt;P&gt;Surya&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265281#M348224</guid>
      <dc:creator>suryakant.chavan</dc:creator>
      <dc:date>2019-03-12T01:56:25Z</dc:date>
    </item>
    <item>
      <title>Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265282#M348225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since broadcast traffic wont pass a L3 point in the network means that you will need to configure DHCP Relay on the ASA1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would be something like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dhcprelay server 172.16.10.1 outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dhcprelay enable inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I would imagine that you need ACL rules on the ASA2 to permit the traffic sent by the ASA1 firewall as its relaying the DHCP messages from the hosts behind ASA1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 07:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265282#M348225</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-12T07:16:49Z</dc:date>
    </item>
    <item>
      <title>Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265283#M348226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Appreciate your quick repy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What traffic I should allow from ASA2 firewall oustside interface access-list.&lt;/P&gt;&lt;P&gt;Can you pl's help me to construct acl. Our destination is DHCP server 172.16.10.1 , but what I should mention as source&amp;nbsp; and DHCP ports .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Surya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 07:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265283#M348226</guid>
      <dc:creator>suryakant.chavan</dc:creator>
      <dc:date>2013-06-12T07:31:35Z</dc:date>
    </item>
    <item>
      <title>Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265284#M348227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume the source should be ASA1 outside interface ip address and destination is what you configured as the relay server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port should be UDP 67 and 68.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this is not difficult to validate if you enable logging on ASA2, you can check via sh logging | i server ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Yao&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 07:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265284#M348227</guid>
      <dc:creator>XIE YAO</dc:creator>
      <dc:date>2013-06-12T07:43:55Z</dc:date>
    </item>
    <item>
      <title>Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265285#M348228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi XIE,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Presently I do not have access to ASA firewall.&lt;/P&gt;&lt;P&gt;Also I have read one document which mentioned as " &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;Clients must be directly connected to the security appliance and cannot send requests&lt;/P&gt;&lt;P&gt;through another relay agent or a router." Can you help me to understand what it mean.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Surya&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 09:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265285#M348228</guid>
      <dc:creator>suryakant.chavan</dc:creator>
      <dc:date>2013-06-12T09:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265286#M348229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first ASA that is connected to the host network will do the relying of the messages so they are directly connected as the document suggests that is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ONLY the first ASA will relay the DHCP messages to the server. The traffic from the host initially to the first ASA is broadcast traffic that the first ASA will then convert to a unicast traffic directly to the server. The second ASA just needs to allow the DHCP related UDP traffic between the the DHCP server and the other ASA/hosts so that the DHCP process can finish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So from the perspective of the second ASA it will just see UDP traffic and doesnt need any DHCP related configuration to relay that traffic between the endpoints. Just the ACLs allowing the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 09:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265286#M348229</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-12T09:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Need help to allow traffic through firewall to DHCP server</title>
      <link>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265287#M348230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help, It's realy helpful to clear my query.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 05:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-to-allow-traffic-through-firewall-to-dhcp-server/m-p/2265287#M348230</guid>
      <dc:creator>suryakant.chavan</dc:creator>
      <dc:date>2013-06-13T05:08:55Z</dc:date>
    </item>
  </channel>
</rss>

