<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multi-context FWSM DHCP Relay Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962835#M954379</link>
    <description>&lt;P&gt;I have two FWSM's, one each in redundantly connected 6500's.  The FWSM's are in multi-context routed mode, and active/active failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 3 contexts, Admin, students, labs.  Each context shares interface vlan925 as the connection to the core for routing.  The problem I have is that contexts students and labs each have 20+ interfaces I'm treating as "outside" interfaces, but I want to be able to relay DHCP requests to DHCP servers on the inside which is interface vlan925(the shared interface).  This is not allowed because it's a shared interface.  I cannot use the firewall as the DHCP server according to other requirements.  How can I pass DHCP requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had originally thought to give each context it's own SVI for the inside interface to allow routing to the core, but that doesn't seem to be allowed either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core1(config)#firewall vlan-group 1 900,925&lt;/P&gt;&lt;P&gt;Found svi for vlan 900&lt;/P&gt;&lt;P&gt;Found svi for vlan 925&lt;/P&gt;&lt;P&gt;No more than one svi is allowed, command rejected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:10:53 GMT</pubDate>
    <dc:creator>NotMeHere</dc:creator>
    <dc:date>2019-03-11T12:10:53Z</dc:date>
    <item>
      <title>Multi-context FWSM DHCP Relay Problem</title>
      <link>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962835#M954379</link>
      <description>&lt;P&gt;I have two FWSM's, one each in redundantly connected 6500's.  The FWSM's are in multi-context routed mode, and active/active failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 3 contexts, Admin, students, labs.  Each context shares interface vlan925 as the connection to the core for routing.  The problem I have is that contexts students and labs each have 20+ interfaces I'm treating as "outside" interfaces, but I want to be able to relay DHCP requests to DHCP servers on the inside which is interface vlan925(the shared interface).  This is not allowed because it's a shared interface.  I cannot use the firewall as the DHCP server according to other requirements.  How can I pass DHCP requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had originally thought to give each context it's own SVI for the inside interface to allow routing to the core, but that doesn't seem to be allowed either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core1(config)#firewall vlan-group 1 900,925&lt;/P&gt;&lt;P&gt;Found svi for vlan 900&lt;/P&gt;&lt;P&gt;Found svi for vlan 925&lt;/P&gt;&lt;P&gt;No more than one svi is allowed, command rejected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962835#M954379</guid>
      <dc:creator>NotMeHere</dc:creator>
      <dc:date>2019-03-11T12:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-context FWSM DHCP Relay Problem</title>
      <link>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962836#M954380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default the FWSM will only allow on vlan with an SVI ie. L3 vlan interface, to be allocated to the firewall module. This is a precautionary measure because if you have multiple vlans that have SVI's on the MSFC you could, if you are not careful route "around" the FWSM from one vlan to another thus defeating the purpose of the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if you enter this command on the 6500 switch &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500(config)# firewall multiple-vlan-interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will then allow you to assign more than one SVI. As ling as you are careful with your vlan layout it won't be a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 17:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962836#M954380</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-02-29T17:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-context FWSM DHCP Relay Problem</title>
      <link>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962837#M954381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I think this will fix my problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 19:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962837#M954381</guid>
      <dc:creator>NotMeHere</dc:creator>
      <dc:date>2008-02-29T19:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-context FWSM DHCP Relay Problem</title>
      <link>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962838#M954382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you will still have a problem relaying DHCP from the 20+ VLAN onto the SVI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had hit this problem before. Instead you need to split all the routes back to the core router into seperate Border Vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Mar 2008 20:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962838#M954382</guid>
      <dc:creator>john.mcmanus</dc:creator>
      <dc:date>2008-03-01T20:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-context FWSM DHCP Relay Problem</title>
      <link>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962839#M954383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I should have said was, I assume you are using the Firewall to perform DHCP forwarding?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Mar 2008 21:15:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-context-fwsm-dhcp-relay-problem/m-p/962839#M954383</guid>
      <dc:creator>john.mcmanus</dc:creator>
      <dc:date>2008-03-01T21:15:38Z</dc:date>
    </item>
  </channel>
</rss>

