cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
11376
Views
0
Helpful
7
Replies

Cisco ASA 5510 dhcp

tinhnho123
Level 2
Level 2

Hello,

I'd like to create dhcp server pool on ASA 5510. I was wondering how big is the DHCP scope that Cisco ASA 5510 can support? Are there any ASA models which can support up to subnet mask \22 for DHCP scope?

Thanks.

7 Replies 7

alejands
Level 1
Level 1

Hello,

On the ASA5510  DHCP pool range is limited to 256 addresses.

Let me know if this helps you.

Hi Bro!

Yes, there's a limit in terms of the DHCP scope you can enable in a Cisco ASA FW 5510 model. It's limited to /24 subnet only. In addition, there are some other limitations with regards to this subject, which shouldn’t worry you too much. Please kindly refer to this URL for further details http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/dhcp.html

FW01(config)# dhcpd address 172.29.0.1-172.29.255.254 inside

Warning, DHCP pool range is limited to 256 addresses, set address range as: 172.29.0.1-172.29.1.0

Moving forward, to meet your requirements, I would propose that you look into an external DHCP Server option e.g. Cisco Network Registrar v7.2, if you've the budget. Good luck bro!!

P/S: If you find this comment useful, please do rate it nicely :-)

Warm regards,
Ramraj Sivagnanam Sivajanam

Just curiosity that I can't have more than 256 hosts even with ASA 5520 or higher model?

Plus, what does Cisco mean by 10 users and/or unlimited users license?

Thanks.

Hi Bro

I tested on my lab's Cisco ASA 5540, and it still says "DHCP pool range is limited to 256 addresses". I guess Alejandro Sanchez statement below is correct after all :-)

Meanwhile, I get lots of questions pertaining to the user licenses pertaining to Cisco ASA 5505. This model offers 3 types of User Licenses namely 10 users, 50 users and UL (unrestricted license). The meaning of user license here basically refers to concurrent source IP addresses that can communicate between Internal (inside) network and Internet (outside) interface.

Hence, for a 10 user license, only 10 concurrent internal hosts (IP addresses) can access the internet, at a given time. The same applies for 50 users (only 50 concurrent IP addresses can access the Internet). For UL license, there is no such restriction.

Part Number                  Part Description                                                      Pricing (Estimation ONLY)

ASA5505-SW-10           ASA 5505 10 User software license                           FREE

ASA5505-SW-50           ASA 5505 50 User software license                           USD 250

ASA5505-SW-UL           ASA 5505 Unlimited User (UL) software license          USD 400

Cisco ASA 5510 on its' own doesn't have these 3 types of User Licenses though, unless you're talking about AIP-SSM and CSC-SSM modules :-) For further details on this, you can refer to http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80402e88.html

Just for you information, the user licensing has also has an effect on the maximum number of IP addresses that can be assigned by the Cisco ASA FW (acting as a DHCP server to the internal hosts. For a 10-user license, the max number of DHCP clients on the internal network is 32. For 50-user license, the max number of DHCP clients is 128.

P/S: If you think this comment is helpful, please do rate it nicely :-)

Warm regards,
Ramraj Sivagnanam Sivajanam

Hello,

All ASAs the max that supports are 254 addresses on the DHCP pool per interface.

You will not be able to give more than that addresses.

You can have a pool of 254 address on each configure interface.

Let me know if you have any other questions

Thanks guys. As you said above, if I wanted to go with /22 subnet mask it's better to have windows/linux setup as DHCP server and ASA 5505 (with unlimited users) as firewall?

Hi Bro

Yes, your statement is correct. Happy shopping :-)

Warm regards,
Ramraj Sivagnanam Sivajanam
Review Cisco Networking for a $25 gift card