<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 6500 DHCP ISSUE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835505#M490771</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This question was in the Switching section but I moved it into the Firewall section seeing as this is an access-list issue. Any help would be greatly appreciated thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Dec 2011 15:08:45 GMT</pubDate>
    <dc:creator>John Apricena</dc:creator>
    <dc:date>2011-12-20T15:08:45Z</dc:date>
    <item>
      <title>6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835501#M490764</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an issue do DHCP from the 6500, and was hoping someone cant help. So, I tried to setup DHCP from the FWSM to the clients and this worked fine with giving out the IP, however the gateway for devices on the inside is supposed to be the 6500, not the FWSM, which is why the clinets wouldn't get out to the internet. Do I need to set up DHCP relay on the FWSM or does anyone know the way I can setup DHCP on the 6500 to give out IP's to the clients. Again just to reiterate, when I setup DHCP on the FWSM the clinets get the IP's but do not get out to the internet and when I setup DHCP on the 6500 the clients do not get an IP. Also I know tghis is a dhcp issue becasue when I assign a static address on the network the clients get out fine. Thanks in advance for the help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;6500 Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;ip dhcp pool TEST&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;&amp;nbsp;&amp;nbsp; network 1.1.1.0 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;&amp;nbsp;&amp;nbsp; default-router 1.1.1.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; dns-server x.x.x.x y.y.y.y&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FWSM Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;FWSM/TEST# show run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif outside9&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan203&lt;/P&gt;&lt;P&gt; nameif inside9&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt; ip address 1.1.1.4 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;access-list INSIDE1_IN extended permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;global (outside1) 1 x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; "&gt;nat (inside1) 1 1.1.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-group INSIDE1_IN in interface inside1&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; "&gt;route outside1 0.0.0.0 0.0.0.0 1.1.1.1 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM/TEST#&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835501#M490764</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2019-03-11T22:03:46Z</dc:date>
    </item>
    <item>
      <title>6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835502#M490766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also this is the error I get in the logs of the FWSM. The pool stats at 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Deny inbound udp src outside9:1.1.1.2/67 dst inside9:1.1.1.100/68&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 19:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835502#M490766</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-12-19T19:26:46Z</dc:date>
    </item>
    <item>
      <title>6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835503#M490768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you post your topology.&lt;/P&gt;&lt;P&gt;The DHCP reply from the server is blocked on the FWSM : &lt;STRONG&gt;Deny inbound udp src outside9:1.1.1.2/67 dst inside9:1.1.1.100/68&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 19:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835503#M490768</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-12-19T19:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: 6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835504#M490770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your quick response. I attached a Diagram of the layout. Just to let you know this is an FWSM with many virtual contexts and most including this one that are Transparent. I understand that I need an access-list on both ends to specifiy so the FWSM opens it, I am just having issue because the FWSM sees this as unsual traffic and the access-list needs to be on-point to work. Thank you for the response and I'll look forward to hearing back from you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 21:00:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835504#M490770</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-12-19T21:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: 6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835505#M490771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This question was in the Switching section but I moved it into the Firewall section seeing as this is an access-list issue. Any help would be greatly appreciated thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Dec 2011 15:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835505#M490771</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-12-20T15:08:45Z</dc:date>
    </item>
    <item>
      <title>6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835506#M490773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've never implemented transparent firewall but I'll do some research and if I find out something I'll let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Dec 2011 15:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835506#M490773</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-12-20T15:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: 6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835507#M490775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You Alain, I will look forward to hearing back from you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Dec 2011 15:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835507#M490775</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-12-20T15:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: 6500 DHCP ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835508#M490777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there anyone that can provide some insight to this? I have tried multiple sequences of access-lists and nothing seems to work. I continue to get the same error in the logs. Thank You in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2011 16:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6500-dhcp-issue/m-p/1835508#M490777</guid>
      <dc:creator>John Apricena</dc:creator>
      <dc:date>2011-12-22T16:07:57Z</dc:date>
    </item>
  </channel>
</rss>

