01-24-2007 04:28 AM - edited 03-05-2019 01:57 PM
Hi,
I have setup my 2811 router to act as a dhcp server.
However, I dont see any request come into the router.
I have several access list setup, but I dont think they may be causing the problem.
My Config is :
Fa 0/0.1 is 10.1.1.7
service dhcp is enabled
ip dhcp pool 1
network 10.1.1.0 255.255.255.0
domain-name xx.com
dns-server 10.1.1.2 192.168.30.50
default-router 10.1.1.7
netbios-node-type h-node
Any ideas what may be preventing this ?
Thanks
Solved! Go to Solution.
01-24-2007 07:58 AM
Shahed
Looking at the config parts that you posted I do not see any obvious problems. The inbound access list on the interface does permit UDP packets with source address 0.0.0.0 so this should allow the DHCP request into the router. If you hard code an IP address on one of the PCs that is attempting DHCP (perhaps 10.1.1.160) can the PC ping the router address of 10.1.1.7? This will demonstrate whether there is a problem with basic connectivity.
I suspect that the problem may be in the switch and the configuration of trunking. Can you tell us some things about the switch and its trunking. Most especially it is important to know what VLAN these PCs are in and which VLAN is configured as the native VLAN.
HTH
Rick
01-24-2007 04:43 AM
Hi ,
Where is the DHCP server located. If it in another segment,You have to use " ip-helper " address commnad under the sub-interface to direct the DHCP broadcast as unicast to the DHCP server.
Please paste the router config and we will help you on teh problme if it doesnot work.
HTH,Please rate if it does.
-amit singh
01-24-2007 07:05 AM
Hi Amit,
Sorry for posting this twice :-(
The router itself is the DHCP server, so I dont need ip helper-address
The IP address of the router is 10.1.1.7 on Fa 0/0.1, and the network for DHCP is 10.1.1.0
I also tried this on Fa0/1, which is on another subnet, and DHCP worked fine for clients connected to that interface.
This leads me to believe that DHCP does not work on SUB-INTERFACES ????
Relavant extract of Config is
no ip dhcp use vrf connected
no ip dhcp conflict logging
ip dhcp excluded-address 10.1.1.1 10.1.1.150
!
!
ip dhcp pool havant
network 10.1.1.0 255.255.255.0
default-router 10.1.1.7
domain-name xx
dns-server 10.1.1.2 192.168.30.50
interface FastEthernet0/0.1
description $FW_INSIDE$
encapsulation dot1Q 1 native
ip address 10.1.1.7 255.255.255.0
ip access-group 104 in
ip access-group 150 out
no ip redirects
ip nat inside
ip virtual-reassembly
no snmp trap link-status
end
access-list 104 permit udp host 0.0.0.0 any
access-list 104 remark auto generated by SDM firewall configuration
access-list 104 remark SDM_ACL Category=1
access-list 104 deny ip 10.1.6.0 0.0.0.255 any
access-list 104 deny ip 81.xx.xx.xx 0.0.0.15 any log
access-list 104 deny ip 10.1.3.0 0.0.0.255 any
access-list 104 deny ip host 255.255.255.255 any
access-list 104 deny ip 127.0.0.0 0.255.255.255 any
access-list 104 permit ip any any
01-24-2007 07:58 AM
Shahed
Looking at the config parts that you posted I do not see any obvious problems. The inbound access list on the interface does permit UDP packets with source address 0.0.0.0 so this should allow the DHCP request into the router. If you hard code an IP address on one of the PCs that is attempting DHCP (perhaps 10.1.1.160) can the PC ping the router address of 10.1.1.7? This will demonstrate whether there is a problem with basic connectivity.
I suspect that the problem may be in the switch and the configuration of trunking. Can you tell us some things about the switch and its trunking. Most especially it is important to know what VLAN these PCs are in and which VLAN is configured as the native VLAN.
HTH
Rick
01-24-2007 08:08 AM
Thanks Rick,
It turned out to be a problem with the Switch.
The routers are connected to a Cat500 Express,
and the PC are on a 2950.
Both have a dot1q trunk with all vlans allowed.
When I added ip dhcp snooping trust to the switchport on which 10.1.1.7 is connected, it worked !!
Thanks
01-24-2007 08:41 AM
Shahed
I am glad that you were able to get this solved and that my suggestion was helpful.
Thank you for posting back to the forum indicating that the problem was solved (and for the rating). It makes the forum more useful when people can read about a problem and know that a solution was found and can read what the solution was.
I encourage you to continue your participation in the forum.
HTH
Rick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide