12-31-2019 02:26 PM - edited 02-21-2020 11:12 AM
I have 12 scopes. I need to use ms dhcp server to dole out IP addresses who have entered the ISE via anyconnect.
Solved! Go to Solution.
01-01-2020 12:35 PM
Hi
See below for ASA documentation on configuring VPN tunnel groups to use DHCP rather than local scopes:
I ran into an issue with using DHCP for AnyConnect clients a while back due to CSCsq84250 - the DHCP server I needed to use was on the ASA Inside interface (Inside was also used to terminate Anyconnect sessions using locally configured scopes)
hth
Andy
12-31-2019 07:02 PM - edited 12-31-2019 07:11 PM
Hi,
If you are referring to Anyconnect VPN terminating on the ASA then for 12 different scopes, you need 12 different tunnel group and group-policies each with different dhcp scope. Refer to below example for reference:
For ASA Software Code:
tunnel-group Group1 general-attributes
dhcp-server subnet-selection
default-group-policy-test test1
!
tunnel-group Group2 general-attributes
dhcp-server subnet-selection
default-group-policy-test test2
!
group-policy test1 attributes
dhcp-network-scope 192.168.1.0 (any IP from the dhcp pool)
!
group-policy test2 attributes
dhcp-network-scope 192.168.2.0 (any IP from the dhcp pool)
01-01-2020 12:35 PM
Hi
See below for ASA documentation on configuring VPN tunnel groups to use DHCP rather than local scopes:
I ran into an issue with using DHCP for AnyConnect clients a while back due to CSCsq84250 - the DHCP server I needed to use was on the ASA Inside interface (Inside was also used to terminate Anyconnect sessions using locally configured scopes)
hth
Andy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide