<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I have the same problem, and in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957744#M937023</link>
    <description>&lt;P&gt;I have the same problem, and I agree that a "fixup" option in the ASA would be useful.&lt;/P&gt;&lt;P&gt;However, I found that one solution was to use a special DHCP option 54 (Server Identifier) for the particular DHCP scope. This allows the server to masquerade behind the WAN address, and thus enables the DHCP client to communicate with&amp;nbsp;the DHCP server via unicast.&lt;/P&gt;&lt;P&gt;Hope this helps someone other than me.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Dec 2014 10:48:10 GMT</pubDate>
    <dc:creator>simon</dc:creator>
    <dc:date>2014-12-30T10:48:10Z</dc:date>
    <item>
      <title>ASA + DHCP Server behind NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957742#M937016</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a fixup in ASA  that allows to run a DHCP server inside a NATed ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the scenario;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Windows DHCP server on the inside&lt;/P&gt;&lt;P&gt;-DHCP client on the oustide&lt;/P&gt;&lt;P&gt;-The DHCP server is translated on the outside&lt;/P&gt;&lt;P&gt;-ip helper-address pointing to the translated IP address of the server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we observe is the following;&lt;/P&gt;&lt;P&gt;When the DHCP broadcast occurs , the DHCP request is forwarded to the helper address and&lt;/P&gt;&lt;P&gt;the server leases an IP address . In the offer the server also includes it's own (real) IP&lt;/P&gt;&lt;P&gt;address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the clients have an IP ,  but when it tries to renew, it makes a unicast DHCP call&lt;/P&gt;&lt;P&gt;(udp 67) to the server  using the real IP of the server , so the renew fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i would like to know if there is a fixup in the ASA , that would change the DHCP server&lt;/P&gt;&lt;P&gt;IP address for it's translated value  in the DHCP offer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, is  there an equivalent of the dns reply modification , but for DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;something like;&lt;/P&gt;&lt;P&gt;static (inside,outside) 209.165.201.10 10.1.3.14 netmask 255.255.255.255 dhcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957742#M937016</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2019-03-11T12:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA + DHCP Server behind NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957743#M937018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have a look at this this Cisco ASA 5500 Series Adaptive Security Appliances Configuration guide. For your setups.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/ps6120/tsd_products_support_configure.html" target="_blank"&gt;http://cisco.com/en/US/products/ps6120/tsd_products_support_configure.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2008 21:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957743#M937018</guid>
      <dc:creator>owillins</dc:creator>
      <dc:date>2008-06-05T21:22:50Z</dc:date>
    </item>
    <item>
      <title>I have the same problem, and</title>
      <link>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957744#M937023</link>
      <description>&lt;P&gt;I have the same problem, and I agree that a "fixup" option in the ASA would be useful.&lt;/P&gt;&lt;P&gt;However, I found that one solution was to use a special DHCP option 54 (Server Identifier) for the particular DHCP scope. This allows the server to masquerade behind the WAN address, and thus enables the DHCP client to communicate with&amp;nbsp;the DHCP server via unicast.&lt;/P&gt;&lt;P&gt;Hope this helps someone other than me.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 10:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dhcp-server-behind-nat/m-p/957744#M937023</guid>
      <dc:creator>simon</dc:creator>
      <dc:date>2014-12-30T10:48:10Z</dc:date>
    </item>
  </channel>
</rss>

