<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bitlocker Network Unlock in SDA Environment in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364990#M4307</link>
    <description>&lt;P&gt;bc since DHCP DISCOVER reached out to EN's AnycastGW with L2-switching &amp;amp; where "ip dhcp snooping" is natively configured to insert information option where else apart of EN configuration can u see&amp;nbsp;"ip dhcp snooping vlan USER-VLAN" applicable?&lt;/P&gt;</description>
    <pubDate>Sat, 24 Jan 2026 18:34:11 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2026-01-24T18:34:11Z</dc:date>
    <item>
      <title>Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360645#M4269</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;My organization was testing Bitlocker Network Unlock in our SDA environment and was running into issues. I was curious if anyone else has setup network unlock in their SDA environment. I'm pretty sure the reason we are having issues is because the BOOTP request from the client is not getting tagged with option 82. I can see the BOOTP reply from the WDS server to the client but it never reaches the client which is making me think it is arriving on the border node and not going any further since option 82 is not being inserted in the BOOTP packet and it is using the SVI IP of the edge node which also exists on the border node. The DHCP packets are getting option 82 just not the BOOTP packets. If anyone has managed to get network unlock to work, were there any configurations you had to do other than setting the IP helper addresses and setting the port in low-impact mode with a pre-auth ACL?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 17:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360645#M4269</guid>
      <dc:creator>barryjm</dc:creator>
      <dc:date>2026-01-12T17:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360696#M4270</link>
      <description>&lt;P&gt;Hej&lt;BR /&gt;i've just got the hint that&amp;nbsp;The core of the problem is that BitLocker Network Unlock's third packet is a BOOTP request that lacks DHCP Option 53 resulting in edge node doesnt insert option 82 into it. but it would be damn cruel if it's true.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 20:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360696#M4270</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-12T20:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360701#M4271</link>
      <description>&lt;P&gt;Yeah that's what I'm thinking too but wasn't 100% sure so I was curious if anyone else has gotten it to work in their environment. We did also open a case with TAC as well and are giving them the pcaps we have taken so we hopefully get a confirmation if that is the issue or not.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 21:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360701#M4271</guid>
      <dc:creator>barryjm</dc:creator>
      <dc:date>2026-01-12T21:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360703#M4272</link>
      <description>&lt;P&gt;please keep tread updated &amp;amp; good luck in resolving the issue&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 21:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5360703#M4272</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-12T21:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364886#M4302</link>
      <description>&lt;P&gt;Can you provide the SR number of the TAC case you have opened?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 06:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364886#M4302</guid>
      <dc:creator>Kris Pellens</dc:creator>
      <dc:date>2026-01-24T06:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364944#M4303</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1912546"&gt;@barryjm&lt;/a&gt;&amp;nbsp;Can you try enabling, at port level, in the path between client and BOOTP server,&amp;nbsp;&lt;STRONG&gt;ip dhcp&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;snooping trust&lt;/STRONG&gt;&amp;nbsp;? See if it works?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 13:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364944#M4303</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-24T13:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364945#M4304</link>
      <description>&lt;P&gt;this is enabled by default on EN's user-facing VLANs. Having it somewhere on the routed way beyond Site's BN, honestly, makes few sense from my pov.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 13:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364945#M4304</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-24T13:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364949#M4305</link>
      <description>&lt;P&gt;is the SDA deployment with ISE integration with 802.1x ?&lt;/P&gt;
&lt;P&gt;check this post :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/802-1x-and-bitlocker-network-unlock/m-p/4671727" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/802-1x-and-bitlocker-network-unlock/m-p/4671727&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-with-bitlocker-network-unlock/td-p/4467087" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-with-bitlocker-network-unlock/td-p/4467087&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 13:40:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364949#M4305</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-01-24T13:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364970#M4306</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;Why so? I meant, if not clear, on the layer 2 path, up until the DHCP Relay.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 15:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364970#M4306</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-24T15:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364990#M4307</link>
      <description>&lt;P&gt;bc since DHCP DISCOVER reached out to EN's AnycastGW with L2-switching &amp;amp; where "ip dhcp snooping" is natively configured to insert information option where else apart of EN configuration can u see&amp;nbsp;"ip dhcp snooping vlan USER-VLAN" applicable?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 18:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364990#M4307</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-24T18:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364991#M4308</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;The problem is with the BOOTP process, right, not with DHCP. Enabling the layer 2 path as DHCP snooping trusted, maybe there's not gonna be an intent to insert OPTION 82 which is not supported for BOOTP (this is the problem we're trying to solve per my understanding).&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 18:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364991#M4308</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-24T18:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364992#M4309</link>
      <description>&lt;P&gt;solution for UEFI boot requests in non-SDA env. as it DOESNT require information option unlike to how SDA does for Fabric DHCP.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 18:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5364992#M4309</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-24T18:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365001#M4310</link>
      <description>&lt;P&gt;problem is exactly in EN doesnt insert opt 82 in the BOOTP request packet during dhcp snooping while it does it for regular DHCP packet. this is what BU &amp;amp; developers must resolve, not community.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 20:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365001#M4310</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-24T20:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365008#M4311</link>
      <description>&lt;P&gt;Yeah from the packet captures we can see that the normal DHCP traffic 0.0.0.0 -&amp;gt; 255.255.255.255 hits the SVI of the edge node which has the helper address so the switch now sends the packet to the helper address with the source IP as the SVI IP and also where the switch will input option 82 into the packet. The DHCP process continues and assigns the client the IP address x.x.x.x. After the client has an IP it sends out the BOOTP request which is x.x.x.x -&amp;gt; 255.255.255.255 also with udp port 67. The broadcast hits the SVI of the edge node again and forwards it with the helper address once again which gets rid of the client IP of x.x.x.x and replaces it with the SVI IP address but does not insert option 82 this time so when the return traffic comes back to the fabric at the border node it hits the IP of the LISP interface on the border node and since there is no option 82 in the original BOOTP request, the packet does not get routed further. We suspect it does not insert option 82 into the BOOTP request since it does not contain option 53 like the DHCP request does, since the client already has been assigned an IP address by this point, although that has not been confirmed to be the case yet. Cisco is currently reviewing the information we have sent them and our customer has also opened a ticket with Microsoft.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 22:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365008#M4311</guid>
      <dc:creator>barryjm</dc:creator>
      <dc:date>2026-01-24T22:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365009#M4312</link>
      <description>&lt;P&gt;Unfortunately I cannot since the case contains information that our customer has determined to be sensitive. I will keep this thread updated with any results or determinations that we get back from Cisco or Microsoft though.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 22:20:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365009#M4312</guid>
      <dc:creator>barryjm</dc:creator>
      <dc:date>2026-01-24T22:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365064#M4313</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;Yes, I've misunderstood where the problem lies.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 11:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365064#M4313</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-25T11:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365065#M4314</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1912546"&gt;@barryjm&lt;/a&gt;&amp;nbsp;If you figure it with TAC, would be great to present if there's a WA that can be done on Cisco side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Meanwhile, not sure if the following could work / override the built-in SDA requirements, however I would give it a try. Either globally disable the verification of Option 82 being inserted in BOOTP Reply via command&amp;nbsp;&lt;STRONG&gt;no ip dhcp relay information check&amp;nbsp;&lt;/STRONG&gt;(this would affect all SVI's), either do it at the SVI level via command&amp;nbsp;&lt;STRONG&gt;ip dhcp relay information check-reply none&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 11:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365065#M4314</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-25T11:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365240#M4315</link>
      <description>&lt;P&gt;Dear barryjm,&lt;/P&gt;&lt;P&gt;Can you at least provide:&lt;BR /&gt;- the date/time you have opened the case?&lt;BR /&gt;- Cisco's team working on the case?&lt;BR /&gt;- the description of the case?&lt;/P&gt;&lt;P&gt;We've opened today case&amp;nbsp;SR 700334461 with description: Bitlocker Network Unlock in SDA Environment not working.&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 14:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365240#M4315</guid>
      <dc:creator>Kris Pellens</dc:creator>
      <dc:date>2026-01-26T14:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365521#M4316</link>
      <description>&lt;P&gt;Answer from Cisco TAC:&lt;/P&gt;&lt;P&gt;Unfortunately, the BOOTP protocol does not support the option 82.&lt;/P&gt;&lt;P&gt;This is the reason why the Fabric Edge is not inserting this option in the packet.&lt;/P&gt;&lt;P&gt;A colleague from the BU is the one who filed the following document explaining the lack of support:&lt;/P&gt;&lt;P&gt;Doc Bug: BOOTP protocol not supported in SDA fabric&lt;BR /&gt;CSCwh46171&lt;BR /&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh46171" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh46171&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Given the BOOTP protocol does not support the option 82, when the reply arrives to the border, the packet is dropped given there is no information on where to send this packet to. This is the process followed by the DHCP Offer packet.&lt;/P&gt;&lt;P&gt;The same issue was observed on several other cases with versions 17.6.x, 17.9.x and 17.12.x. So this situation has been observed repeatedly, due to the lack of support of the option 82 and thereby, the colleague from the BU filed the document, for awareness.&lt;/P&gt;&lt;P&gt;From the Cisco side there is no software image or workaround to address the issue.&lt;/P&gt;&lt;P&gt;Please let me know if you have any questions or comments.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 13:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365521#M4316</guid>
      <dc:creator>Kris Pellens</dc:creator>
      <dc:date>2026-01-27T13:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker Network Unlock in SDA Environment</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365527#M4317</link>
      <description>&lt;P&gt;That is very unfortunate. Thank you for the update. Our case is still open and the ECN HTTS team is scheduling a call with us to discuss it but it sounds like we will end up getting the same answer. If I hear anything different I will definitely update this thread. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 13:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/bitlocker-network-unlock-in-sda-environment/m-p/5365527#M4317</guid>
      <dc:creator>barryjm</dc:creator>
      <dc:date>2026-01-27T13:30:11Z</dc:date>
    </item>
  </channel>
</rss>

