- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2013 10:40 AM - edited 03-07-2019 04:58 PM
Hi,
Why the clients in vlan 30 cannot get ip from DHCP (192.168.1.3 and 4) when the ACL is applied to the vlan 30? When the ACL is removed clients can get ip from dhcp.
Thanks
10 permit ip 192.168.3.0 0.0.0.255 host 192.168.1.3
20 permit ip 192.168.3.0 0.0.0.255 host 192.168.1.4
80 permit tcp host 192.168.3.21 eq 3389 host 192.168.1.1
90 permit tcp host 192.168.3.21 host 192.168.1.1 range 2221 2222
100 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
110 deny ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
120 permit ip 192.168.3.0 0.0.0.255 any
interface Vlan30
ip address 192.168.3.253 255.255.255.0
ip access-group 130 in
ip helper-address 192.168.1.3
ip helper-address 192.168.1.4
Solved! Go to Solution.
- Labels:
-
Other Switching
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2013 12:19 PM
You should add a line for the client's initial DHCP DISCOVERs, e.g.:
5 permit udp host 0.0.0.0 host 255.255.255.255 eq bootps
HTH
Rolf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2013 10:53 AM
Hi ,
Can u check the Access List group number which u assigned on vlan interface.
interface Vlan30
ip address 192.168.3.253 255.255.255.0
ip access-group 130 in
ip helper-address 192.168.1.3
ip helper-address 192.168.1.4
I did not see any access list 130??
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2013 11:50 AM
This is the extended ACL 130.
ip access-list extended 130
10 permit ip 192.168.3.0 0.0.0.255 host 192.168.1.3
20 permit ip 192.168.3.0 0.0.0.255 host 192.168.1.4
80 permit tcp host 192.168.3.21 eq 3389 host 192.168.1.1
90 permit tcp host 192.168.3.21 host 192.168.1.1 range 2221 2222
100 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
110 deny ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
120 permit ip 192.168.3.0 0.0.0.255 any

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2013 12:18 PM
Does the vlan svi that has the ip address of 192.168.1.x have an acl applied as well? Maybe it's not allowing the return traffic....
HTH,
John
*** Please rate all useful posts ***
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-08-2013 12:19 PM
You should add a line for the client's initial DHCP DISCOVERs, e.g.:
5 permit udp host 0.0.0.0 host 255.255.255.255 eq bootps
HTH
Rolf
