<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DHCP relay Cisco ASA to PIX535 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790777#M963937</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to use the DHCP relay service on a Cisco 5505 ASA connected trough a VPN IP_Sec site-to-site tunnel with a PIX 535. We set up te configuration as discribed in the documantation. From de remote site the ASA 5505 we can ping de DCHP servers on the remote site so the VPN tunnel is up. A DCHP request seems to be forwarded to the relay server but does not enter the VPN tunnel. There is no DHCP traffic in the tunnel on de local and remote site. We permitted all IP traffic in the tunnel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a configuration example with DHCP relay and IPSEC site-to site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:06:00 GMT</pubDate>
    <dc:creator>nijholt</dc:creator>
    <dc:date>2019-03-11T11:06:00Z</dc:date>
    <item>
      <title>DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790777#M963937</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to use the DHCP relay service on a Cisco 5505 ASA connected trough a VPN IP_Sec site-to-site tunnel with a PIX 535. We set up te configuration as discribed in the documantation. From de remote site the ASA 5505 we can ping de DCHP servers on the remote site so the VPN tunnel is up. A DCHP request seems to be forwarded to the relay server but does not enter the VPN tunnel. There is no DHCP traffic in the tunnel on de local and remote site. We permitted all IP traffic in the tunnel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a configuration example with DHCP relay and IPSEC site-to site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790777#M963937</guid>
      <dc:creator>nijholt</dc:creator>
      <dc:date>2019-03-11T11:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790778#M963939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should check if the outside IP of the Pix is in the interesting traffic and in the nat0 configuration. This is required for dhcp relays to work. Also on the client side device you need to configure dhcp relay with the physical IP of the DHCP server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 13:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790778#M963939</guid>
      <dc:creator>amritpatek</dc:creator>
      <dc:date>2007-09-10T13:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790779#M963940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nijholt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you solve this problem? I have a similar configuration to the one you describe and require DHCP services from a server only available through a L2L tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2007 12:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790779#M963940</guid>
      <dc:creator>james.smith</dc:creator>
      <dc:date>2007-09-27T12:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790780#M963941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also interested if this is possible because we have a centralized dhcp server and want to extend this to remote offices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2007 18:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790780#M963941</guid>
      <dc:creator>vanoverschelde</dc:creator>
      <dc:date>2007-10-22T18:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790781#M963942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update to this?&lt;/P&gt;&lt;P&gt;(also interested)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jun 2008 08:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790781#M963942</guid>
      <dc:creator>gerdpleyer</dc:creator>
      <dc:date>2008-06-27T08:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790782#M963943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone ever gotten this to work? I've got a case open with Cisco TAC and they say it will, but the on&lt;/P&gt;&lt;P&gt;ly doc they have is for DHCP from a client on one interface of a PIX/ASA to a DHCP server on another interface of the same firewall. I haven't yet seen any information or examples on getting it to work across a Site-to-Site VPN between firewalls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Oct 2010 12:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790782#M963943</guid>
      <dc:creator>momeara</dc:creator>
      <dc:date>2010-10-12T12:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790783#M963944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi ,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman","serif";}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;The following example configuration would be helpful in this scenario:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-family: monospace; white-space: pre;"&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt;Consider a scenario wherein we need to configure PIX as a DHCP relay so that clients &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt; behind&amp;nbsp; the PIX could get IP addresses from &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-family: monospace; white-space: pre;"&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt;a DHCP server which is behind a headend &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt;ASA. The ASA and the&amp;nbsp; PIX are the VPN terminating devices. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt; &lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt;Brief topology:&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 10pt; font-family: arial, helvetica, sans-serif; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Remote Site 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote site2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;clients---PIX &amp;lt;--&amp;gt; &lt;IP sec="" tunnel=""&gt; ASA----DHCP server&lt;/IP&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;To resolve the issue, we need to use DHCP relay configuration on the PIX which is as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraph"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Pix(config)# dhcprelay server &lt;IP address="" of="" dhcp="" server=""&gt;outside&lt;/IP&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Pix(config)# dhcprelay enable inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;--We need to add two more entries in the crypto access-list for DHCP request and reply to traverse over the Ipsec tunnel, along with the usual crypto acls for local and remote subnets.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1.&amp;nbsp; An entry with source ip as the outside interface of the PIX and the destination ip as the IP address of the DHCP server which is on the other end.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2.&amp;nbsp; Another entry with source ip as the ip of the client interface of the PIX and the destination as the ip addres of the DHCP server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraph"&gt;&lt;SPAN style="font-size: 10pt;"&gt;The first entry is for the DHCP request to go over the tunnel, the second entry is for the DHCP reply which is sent to the client interface and not the outside interface of the PIX. It is very important to note that &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt; "&gt;the DHCP Server will reply to the address of the interface through which the DHCP Discover message came.&lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt; Also, at the ASA end, it has to be made sure that the traffic from the DHCP server to the client interface of the PIX is excluded from being natted by the ASA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;The DHCP message exchange is elaborated in the diagram attached with the post&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;(Here the ASA is acting as the DHCP relay agent.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;It should be working fine with the above configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Let me know if this helps,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Rudresh V&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 16:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790783#M963944</guid>
      <dc:creator>Rudresh Veerappaji</dc:creator>
      <dc:date>2010-10-13T16:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790784#M963945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rudresh,&lt;/P&gt;&lt;P&gt;Great detail.&amp;nbsp; Please consider publishing this as a support forum document.&amp;nbsp; I tried to google search "dhcp relay site to site vpn"&amp;nbsp; and other combinations but came out empty handed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 16:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790784#M963945</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-10-13T16:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay Cisco ASA to PIX535</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790785#M963946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have to do this tomorrow, so please let me know if I have this correctly. Thanks.&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;EM style="Courier New&amp;quot;: ; font-size: 10pt; font-family: &amp;quot; "&gt;Central site dhcp server over site-to-site vpn to branch dhcp clients&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-size: 8pt; font-family: &amp;quot; "&gt;Branch Site Requirements&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap permit ip branch lan to central lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap permit udp 67,68 branch-outside to dhcp-server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap permit udp 67,68 branch-inside to dhcp-server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap traffic must be nat exempted&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap traffic must be in crypto map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-size: 8pt; font-family: &amp;quot; "&gt;Central Site Requirements&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap permit ip central lan to branch lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap permit udp 67,68 dhcp-server to branch-inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap permit udp 67,68 dhcp-server to branch-outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap traffic must be nat exempted&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;acl outside_1_cryptomap traffic must be in crypto map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;EM style="Courier New&amp;quot;: ; font-size: 8pt; font-family: &amp;quot; "&gt;Commands v8.3 (omitting site-to-site vpn commands)&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-size: 8pt; font-family: &amp;quot; "&gt;Branch Site ASA&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;object network dhcp-server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;BR /&gt; object network asa-inside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;BR /&gt; object network asa-outside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;object-group service dhcp-services udp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq bootpc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq bootps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;dhcprelay server object dhcp-server outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;dhcprelay enable inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;dhcprelay setroute inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;dhcprelay timeout 90&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list outside_1_cryptomap extended permit udp object asa-outside object dhcp-server object-group dhcp-services &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list outside_1_cryptomap extended permit udp object asa-inside &lt;SPAN&gt; &lt;/SPAN&gt;object dhcp-server object-group dhcp-services&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-size: 8pt; font-family: &amp;quot; "&gt;Cental Site ASA&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;object network dhcp-server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;BR /&gt; object network branch-asa-inside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;BR /&gt; object network branch-asa-outside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;object-group service dhcp-services udp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq bootpc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq bootps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list outside_1_cryptomap extended permit udp object dhcp-server object branch-asa-outside object-group dhcp-services&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list outside_1_cryptomap extended permit udp object dhcp-server object branch-asa-inside &lt;SPAN&gt; &lt;/SPAN&gt;object-group dhcp-services&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 14:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-relay-cisco-asa-to-pix535/m-p/790785#M963946</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2010-12-27T14:39:38Z</dc:date>
    </item>
  </channel>
</rss>

