<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA DHCP server problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140575#M360278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Wrong forum, post in "Security - Firewalling". You can move your posting with the Actions panel on the right.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Sep 2013 19:47:41 GMT</pubDate>
    <dc:creator>paolo bevilacqua</dc:creator>
    <dc:date>2013-09-20T19:47:41Z</dc:date>
    <item>
      <title>ASA DHCP server problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140573#M360276</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for an excellent forum!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a wierd problem with 3 ASA 5505s... They are set up on a small lan to serve as dhcp server, very flat straight forward setup - single vlan with a couple of phones printers pcs and such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now. When the lease time runs out for lets say one of the ip phones (specifically a 7912) everything stops. Or if the sw port it is connected to is reset it is unable to recover. With cdp i can see that it maintains its old ip add, and i can see the dhcp conversation with the asa (debug dhcpd packet 255 and dhcp debug event 255).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to get it back up is to clear the specific lease on the asa and reset the sw port again. Then it gets a new ip and i can access it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a debug output from the ASA. To me it looks like it just keeps requesting the address but for some unexplained reason it never starts using it. I'm wondering if that delayed ACK seen in the debug output is the cause!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've set the lease time to what 14 days or so for the scope and made sure every client renewed so i have some time to dig into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But any help is much appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** SNIP ** &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DHCPD: Server msg received, fip=ANY, fport=0 on inside interface&lt;/P&gt;&lt;P&gt;DHCPD: DHCPREQUEST received from client 0100.137f.ed76.b2.&lt;/P&gt;&lt;P&gt;DHCPD: Extracting client address from the message&lt;/P&gt;&lt;P&gt;DHCPD: State = DHCPS_REBOOTING&lt;/P&gt;&lt;P&gt;DHCPD: Client 0100.137f.ed76.b2 specified it's address 10.101.50.172&lt;/P&gt;&lt;P&gt;DHCPD: Client is on the correct network&lt;/P&gt;&lt;P&gt;DHCPD: Client accepted our offer&lt;/P&gt;&lt;P&gt;DHCPD: Client and server agree on address 10.101.50.172&lt;/P&gt;&lt;P&gt;DHCPD: Renewing client 0100.137f.ed76.b2 lease&lt;/P&gt;&lt;P&gt;DHCPD: Client lease can be renewed&lt;/P&gt;&lt;P&gt;DHCPD: adding option 15&lt;/P&gt;&lt;P&gt;DHCPD: adding option 150&lt;/P&gt;&lt;P&gt;DHCPD: adding option 161&lt;/P&gt;&lt;P&gt;DHCPD: adding option 162&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 15&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 150&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 161&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 162&lt;/P&gt;&lt;P&gt;DHCPD: ACK is being delayed and will be sent later&lt;/P&gt;&lt;P&gt;DHCPD: Server msg received, fip=ANY, fport=0 on inside interface&lt;/P&gt;&lt;P&gt;DHCPD: DHCPDISCOVER received from client 0100.137f.ed76.b2 on interface inside.&lt;/P&gt;&lt;P&gt;DHCPD: Sending DHCPOFFER to client 0100.137f.ed76.b2 (10.101.50.172).&lt;/P&gt;&lt;P&gt;DHCPD: adding option 15&lt;/P&gt;&lt;P&gt;DHCPD: adding option 150&lt;/P&gt;&lt;P&gt;DHCPD: adding option 161&lt;/P&gt;&lt;P&gt;DHCPD: adding option 162&lt;/P&gt;&lt;P&gt;DHCPD: client requests option 150.&lt;/P&gt;&lt;P&gt;DHCPD: copy option 150 (length = 4) to outgoing message.&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DHCPD: Total # of raw options copied to outgoing DHCP message is 1.&lt;/P&gt;&lt;P&gt;DHCPD: broadcasting BOOTREPLY to client 0013.7fed.76b2.&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 15&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 150&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 161&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 162&lt;/P&gt;&lt;P&gt;DHCPD: Server msg received, fip=ANY, fport=0 on inside interface&lt;/P&gt;&lt;P&gt;DHCPD: DHCPREQUEST received from client 0100.137f.ed76.b2.&lt;/P&gt;&lt;P&gt;DHCPD: Extracting client address from the message&lt;/P&gt;&lt;P&gt;DHCPD: State = DHCPS_REBOOTING&lt;/P&gt;&lt;P&gt;DHCPD: State = DHCPS_REQUESTING&lt;/P&gt;&lt;P&gt;DHCPD: Client 0100.137f.ed76.b2 specified it's address 10.101.50.172&lt;/P&gt;&lt;P&gt;DHCPD: Client is on the correct network&lt;/P&gt;&lt;P&gt;DHCPD: Client accepted our offer&lt;/P&gt;&lt;P&gt;DHCPD: Client and server agree on address 10.101.50.172&lt;/P&gt;&lt;P&gt;DHCPD: Renewing client 0100.137f.ed76.b2 lease&lt;/P&gt;&lt;P&gt;DHCPD: Client lease can be renewed&lt;/P&gt;&lt;P&gt;DHCPD: adding option 15&lt;/P&gt;&lt;P&gt;DHCPD: adding option 150&lt;/P&gt;&lt;P&gt;DHCPD: adding option 161&lt;/P&gt;&lt;P&gt;DHCPD: adding option 162&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 15&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 150&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 161&lt;/P&gt;&lt;P&gt;DHCPD: deleting option 162&lt;/P&gt;&lt;P&gt;DHCPD: ACK is being delayed and will be sent later&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** SNIP **&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140573#M360276</guid>
      <dc:creator>Geminorum_cco</dc:creator>
      <dc:date>2019-03-12T01:13:41Z</dc:date>
    </item>
    <item>
      <title>ASA DHCP server problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140574#M360277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; We are seeing the the same thing on an ASA5505. The initial discover gets a response, but the request during a client renew, gets a ACK being delayed and will be sent later message.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 19:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140574#M360277</guid>
      <dc:creator>s-mvasquez</dc:creator>
      <dc:date>2013-09-20T19:41:39Z</dc:date>
    </item>
    <item>
      <title>ASA DHCP server problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140575#M360278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Wrong forum, post in "Security - Firewalling". You can move your posting with the Actions panel on the right.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 19:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-server-problems/m-p/2140575#M360278</guid>
      <dc:creator>paolo bevilacqua</dc:creator>
      <dc:date>2013-09-20T19:47:41Z</dc:date>
    </item>
  </channel>
</rss>

