<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 1010 VLAN and DHCP issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987194#M935153</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I recently got a Firepower 1010 for my home lab and was testing the VLAN interface feature that I previously used on my old&amp;nbsp; ASA 5505.&lt;/P&gt;&lt;P&gt;I used my 5505 as a DHCP server on the Inside network and had the DHCP server enabled on my Inside VLAN interface.&lt;/P&gt;&lt;P&gt;I was trying to setup the 1010 the same way, but I only had the option to select a routed interface and not a VLAN interface.&lt;/P&gt;&lt;P&gt;Anyone know if it suppose to be possible to use a VLAN interface for DHCP on the 1010?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:42:41 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2020-02-21T17:42:41Z</dc:date>
    <item>
      <title>Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987194#M935153</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I recently got a Firepower 1010 for my home lab and was testing the VLAN interface feature that I previously used on my old&amp;nbsp; ASA 5505.&lt;/P&gt;&lt;P&gt;I used my 5505 as a DHCP server on the Inside network and had the DHCP server enabled on my Inside VLAN interface.&lt;/P&gt;&lt;P&gt;I was trying to setup the 1010 the same way, but I only had the option to select a routed interface and not a VLAN interface.&lt;/P&gt;&lt;P&gt;Anyone know if it suppose to be possible to use a VLAN interface for DHCP on the 1010?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987194#M935153</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2020-02-21T17:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987645#M935154</link>
      <description>&lt;P&gt;Can you post a sample configuration of this from your 5505 so we can fully understand what you are trying to configure?&lt;/P&gt;
&lt;P&gt;Also, is your plan to run ASA or FTD on your 1010?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 03:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987645#M935154</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2019-11-22T03:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987837#M935155</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for answering. I am planing to run the FTD software.&lt;/P&gt;&lt;P&gt;Here is the relevant config from my ASA 5505 that I want to replicate on my 1010.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;BR /&gt;nameif INSIDE&lt;BR /&gt;security-level 100&lt;BR /&gt;allow-ssc-mgmt&lt;BR /&gt;ip address 10.46.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 10.46.0.225-10.46.0.254 INSIDE&lt;BR /&gt;dhcpd enable INSIDE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 12:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/3987837#M935155</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2019-11-22T12:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4005332#M935156</link>
      <description>&lt;P&gt;The VLAN interface is a routed interface on the ASA 5505, it just has multiple physical interfaces attached to it. So what you are describing is consistent across the two firewalls. DHCP is always enabled on a layer 3 interface.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2020 15:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4005332#M935156</guid>
      <dc:creator>dddd2</dc:creator>
      <dc:date>2020-01-01T15:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4021638#M935157</link>
      <description>&lt;P&gt;This is not true. The problem with DHCP on the VLAN interface takes place to be. The interface VLAN does not appear in the list when adding a server. Firepower 1010 version 6.5.0.2&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 12:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4021638#M935157</guid>
      <dc:creator>Sergii Storozhchuk</dc:creator>
      <dc:date>2020-01-31T12:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4022446#M935158</link>
      <description>&lt;P&gt;I can assure you a VLAN interface &lt;EM&gt;is&lt;/EM&gt; a routed interface on an ASA5505. This is evidenced by the fact that you apply IP addresses to the VLAN interface on that platform. This, by definition, makes the VLAN interface a routed/layer 3 interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your belief that a VLAN interface on an ASA 5505 is not a routed interface may stem from the fact that a VLAN is a layer 2 mechanism that separates a single broadcast domain into smaller broadcast domains. However, once you create a VLAN interface that for that VLAN, that creates a routable, layer 3 interface for that VLAN which you can then use for DHCP functionality.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As all physical interfaces on an ASA5505 are switched, layer 2 interfaces, the platform utilises VLAN interfaces to route between two different subnets. It is no different to using SVI interfaces on a layer 3 capable switch. Though most, if not all, layer 3 capable switches also allow you to assign an IP address directly to a physical switch port, turning it in to a routed port, the ASA5505 does not support this and must use VLAN interfaces as routed ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 00:13:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4022446#M935158</guid>
      <dc:creator>dddd2</dc:creator>
      <dc:date>2020-02-03T00:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4022588#M935159</link>
      <description>&lt;P&gt;Yes, it works on the ASA5500. I wrote that there is a problem with DHCP on the Layer 3 VLAN interface on Firepower 1010&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 10:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4022588#M935159</guid>
      <dc:creator>Sergii Storozhchuk</dc:creator>
      <dc:date>2020-02-03T10:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4075610#M1069577</link>
      <description>&lt;P&gt;I have the same issue on my FirePower 1010. I cannot select my L3 VLAN interface when enabling the DHCP server. Both FTD and FMC are running version 6.6. See screenshots below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-04-28 at 9.57.31 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73219i34B9964A97ADF053/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-04-28 at 9.57.31 AM.png" alt="Screen Shot 2020-04-28 at 9.57.31 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-04-28 at 9.57.52 AM.png" style="width: 614px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73220i39AB39B040BC0310/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-04-28 at 9.57.52 AM.png" alt="Screen Shot 2020-04-28 at 9.57.52 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 14:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4075610#M1069577</guid>
      <dc:creator>chprewit</dc:creator>
      <dc:date>2020-04-28T14:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4100190#M1070905</link>
      <description>&lt;P&gt;I have the same problem (or similar), with FMCv 6.5.0.4 &amp;amp; FTD 1010 (v.6.5.0.4)&lt;BR /&gt;I wanted to use the ports eth1/7 &amp;amp; eth1/8 to connect 2 access-points (as these ports have PoE option), but I couldn't add the Vlan IDs to the switchport (in FMC GUI it allowed me to configure them, but deployment failed).&lt;BR /&gt;At deployment of the configuration, these were the messages:&lt;/P&gt;&lt;PRE&gt;FMC &amp;gt;&amp;gt; interface Ethernet1/7
FMC &amp;gt;&amp;gt; switchport trunk allowed vlan 5-6
fp1010 &amp;gt;&amp;gt; [info] : Failed to add a switch VLAN 5, a sub-interface E1/3.5 with same vlan-id exists.
ERROR: Failed to add a switch VLAN 6, a sub-interface E1/3.6 with same vlan-id exists.&lt;/PRE&gt;&lt;P&gt;So, I've deleted the sub-interfaces from Ethernet1/3 and created Vlan interfaces (of course, changed also E1/3 to be a switchport in mode trunk for connecting to the rest of the network).&lt;/P&gt;&lt;P&gt;Now deployment works fine, switchport functionality looks ok, BUT:&lt;/P&gt;&lt;P&gt;- DHCP Relay Agent&amp;nbsp; / DHCP Servers definition can't be configured for Vlan interfaces&lt;/P&gt;&lt;P&gt;- OSPF Interface can't be configured for Vlan interfaces&lt;/P&gt;&lt;P&gt;- RIP Passive Interfaces can't be configured for Vlan interfaces&lt;/P&gt;&lt;P&gt;- Multicast Routes or Multicast Boundary Filter can't be configured for Vlan interfaces&lt;/P&gt;&lt;P&gt;Only the physical (sub-) interfaces in routed mode appears in the list, typing the interface name is not working (like the trick with typing "diagnostic" in some older FMC versions)&lt;/P&gt;&lt;P&gt;The behavior is not consistent, as static routes can be configured with Vlan Interfaces &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, as DHCP relay and OSPF are more important than getting 2 additional switchports with PoE, I'm rolling back to using sub-interfaces in routed mode. That was a fun lesson...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 15:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4100190#M1070905</guid>
      <dc:creator>Gabriel Copil</dc:creator>
      <dc:date>2020-06-09T15:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4391641#M1080238</link>
      <description>&lt;P&gt;Did you solve this?&lt;/P&gt;&lt;P&gt;I've hit the same problem on my FMC (6.6.3) with FPR1010 (FTD 6.6.1)&lt;/P&gt;&lt;P&gt;Can't configure a DHCP relay for VLAN interface... absolutely useless product...&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 15:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4391641#M1080238</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2021-04-22T15:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4392271#M1080252</link>
      <description>&lt;P&gt;I managed to hack my way around this using flexconfig, for example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dhcprel&amp;nbsp;enable inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Replace "inside" with the name of your VLAN interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(you can't put "dhcprelay" because it's not a supported command....)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Raised a ticket with my reseller, hopefully will make its way into a TAC case because as far as i'm concerned this is basic functionality that should not be missing..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 16:07:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4392271#M1080252</guid>
      <dc:creator>mhmservice</dc:creator>
      <dc:date>2021-04-23T16:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1010 VLAN and DHCP issues</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4453557#M1083089</link>
      <description>&lt;P&gt;I'm having the exact same problem with FTD/FMC 6.6.4 - I cannot add DHCP server or relay for VLAN interface... something so basic should be available! I'm not impressed with FTD whatsoever as this isn't the first basic configuration item that I've noticed missing from the platform.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 13:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1010-vlan-and-dhcp-issues/m-p/4453557#M1083089</guid>
      <dc:creator>ste.ant</dc:creator>
      <dc:date>2021-08-23T13:58:53Z</dc:date>
    </item>
  </channel>
</rss>

