<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using ASA as DHCP server for multiple vlans in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651368#M589639</link>
    <description>&lt;P&gt;i have a requirement to use an ASA as the DHCP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are.....If I have multiple vlans behind the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 - Can I use the ASA with sub interfaces as the default gateway for each of these vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 - Can I use the DHCP server feature on the ASA to assign ip addresses to each of the clients on each of the vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So vlan 10 subnet would be 192.168.10.0 /24 DHCP scope would be 192.168.10.10 - 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 20 subnet would be 192.168.20.0 /24 DHCP scope would be 192.168.20.10 - 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I can use the ASA as a dhcp server, just not sure if it can assign different scopes to different VLAN clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:04:27 GMT</pubDate>
    <dc:creator>dclee</dc:creator>
    <dc:date>2019-03-11T20:04:27Z</dc:date>
    <item>
      <title>Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651368#M589639</link>
      <description>&lt;P&gt;i have a requirement to use an ASA as the DHCP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are.....If I have multiple vlans behind the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 - Can I use the ASA with sub interfaces as the default gateway for each of these vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 - Can I use the DHCP server feature on the ASA to assign ip addresses to each of the clients on each of the vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So vlan 10 subnet would be 192.168.10.0 /24 DHCP scope would be 192.168.10.10 - 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 20 subnet would be 192.168.20.0 /24 DHCP scope would be 192.168.20.10 - 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I can use the ASA as a dhcp server, just not sure if it can assign different scopes to different VLAN clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651368#M589639</guid>
      <dc:creator>dclee</dc:creator>
      <dc:date>2019-03-11T20:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651369#M589640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure a DHCP server on each interface of the ASA (I assume this also means subinterfaces however I haven't tried it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind the license restrictions also (ASA 5505):&lt;BR /&gt;For a 10-user license, the max. DHCP clients is 32. For 50 users, the max. is 128. For unlimited users, the max. is 250, which is the max. for other models.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the ASA only assigns IPs to directly connected subnets... meaning it won't assign IPs to hosts that are 1 or more layer 3 hops away (on a different subnet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 19:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651369#M589640</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-10T19:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651370#M589641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks it does help. I'll have to set it up in the lab and verify that I can indeed setup&lt;/P&gt;&lt;P&gt;a DHCP server per sub interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 20:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651370#M589641</guid>
      <dc:creator>dclee</dc:creator>
      <dc:date>2011-03-10T20:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651371#M589642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave ,&amp;nbsp; as Federico have indicated&amp;nbsp; you can use DHCP when using subinterfaces. DHCP services are&amp;nbsp; bound to nameif&amp;nbsp; rather than the interface/subinterface, so regardles wether you use actual physical or logical subinterface you use the interface nameif to activate DHCP services when working with dhcp command syntax.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Exmaple ; using your IP scheme.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;lets assume you will&amp;nbsp; use physical&amp;nbsp; e0/2 for your trunk and work your subinterfaces and DHCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/2.10&lt;BR /&gt;vlan 10&lt;BR /&gt;nameif DMZ10&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface Ethernet0/2.20&lt;BR /&gt;vlan 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;nameif DMZ20 &lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.20.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;dhcpd address 192.168.10.10-192.168.10.254 DMZ10&lt;BR /&gt;dhcpd dns x.x.x.x&amp;nbsp; y.y.y.y interface DMZ10&lt;BR /&gt;dhcpd enable DMZ10&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;dhcpd address 192.168.20.10-192.168.20.254 DMZ20&lt;BR /&gt;dhcpd dns h.h.h.h&amp;nbsp; z.z.z.z interface DM20&lt;BR /&gt;dhcpd enable DMZ20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some references &lt;BR /&gt;&lt;A href="http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/d2.html#wp1948446"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/d2.html#wp1948446&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 22:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651371#M589642</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2011-03-10T22:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651372#M589643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info, got it up and running in the lab &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 21:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651372#M589643</guid>
      <dc:creator>dclee</dc:creator>
      <dc:date>2011-03-11T21:32:58Z</dc:date>
    </item>
    <item>
      <title>Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651373#M589644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I got in same situation with Dave and tried to apply your nameif on other interface but found out that I could not do it with the ASA based 10 license, got the error message&lt;/P&gt;&lt;P&gt;ERROR: This license does not allow configuring more than 2 interfaces with&lt;/P&gt;&lt;P&gt;nameif and without a "no forward" command on this interface or on 1 interface(s)&lt;/P&gt;&lt;P&gt;with nameif already configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; just want to share that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2012 21:44:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651373#M589644</guid>
      <dc:creator>vinlata2007</dc:creator>
      <dc:date>2012-01-13T21:44:03Z</dc:date>
    </item>
    <item>
      <title>Using ASA as DHCP server for multiple vlans</title>
      <link>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651374#M589645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue you are getting is related to a license restriction on your ASA 5505 where with a base license you only have 2 unrestricted interface, in this case I think you already have vlan 1 as inside and vlan2 as outside, and you want to use a dhcp server on a different vlan. The problem is again you have a restricted license. so the 3 vlan can be configured but just passing traffic to one interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need the following to make it work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet 0/2&lt;/P&gt;&lt;P&gt;no forward interface vlan 1&lt;/P&gt;&lt;P&gt;nameif dmz&lt;/P&gt;&lt;P&gt;ip address x.x.x.x&lt;/P&gt;&lt;P&gt;security level #&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can give it a try .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2012 22:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-asa-as-dhcp-server-for-multiple-vlans/m-p/1651374#M589645</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-13T22:51:17Z</dc:date>
    </item>
  </channel>
</rss>

