cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
593
Views
0
Helpful
1
Replies

Nexus 5500 and ASA DHCP Relay not Working

Tiago Nunes
Level 1
Level 1

Hi everyone

 

I'm having a problem with deploying a Nexus 5596 in a costumer's network

 

We have 2 Nexus 5500, connected, through VPC to a Cisco 5585X which owns the default gateways for all the networks. The Nexus has only a SVI in the VLAN 50 for in-band management 

 

The problem is that, if we connect a user in the VLAN 50 (the same one that is configured for Nexus management) that user doesn't get an IP Address from the DHCP Server located in a different VLAN

 

Here's a simplified network diagram

 

 

As far as i could understand, the Nexus MUST relay all the DHCP packets from the VLAN's in which it has configured SVI's (i've tried to remove the SVI's from the Nexus and everything worked just as fine as it works in the other 20 something VLAN's in which I don't have SVI's ).

However, the ASA doesn't relay packets that have already been relayed from another device. So, we must have reached a dead end...or am I picturing this wrong and there is a way to achieve the goal of getting DHCP in the VLAN 50? Hope so...

 

Here is the dhcp config configuration in both nexus. I've also tried every possible combination for the dhcp global commands ( dhcp relay information and sub-option)

 

NEXUS-A(config)# show running-config dhcp 

!Command: show running-config dhcp
!Time: Thu Nov 13 16:55:35 2014

version 6.0(2)N2(5a)
feature dhcp

ip dhcp snooping
service dhcp
ip dhcp relay

 

interface Vlan50

  ip dhcp relay address 192.168.24.1 <--- DHCP Server
  ip dhcp relay address 192.168.4.255 <---- Broadcast address for VLAN50
  ip dhcp relay address 192.168.4.250 <---- ASA address for VLAN50 and also the default gateway for this VLAN
  ip dhcp relay subnet-broadcast

interface port-channel1
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel2
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel3
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel4
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel5
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel6
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel7
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel8
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel9
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel10
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel11
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel12
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel13
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel14
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel15
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel400
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel401
  ip dhcp snooping trust
  ip arp inspection trust

interface port-channel1000
  ip dhcp snooping trust
  ip arp inspection trust

interface Ethernet1/25
  ip dhcp snooping trust
  ip arp inspection trust
ip dhcp snooping vlan 1-1000

 

Thank you very much


Regards

1 Reply 1

Tiago Nunes
Level 1
Level 1

This was a bug CSCut21777

It's now fixed

Known Fixed Releases: (9)
7.0(7)N1(1)
7.0(7)ZN(0.108)
7.1(1)ZN(0.105)
7.1(2)N1(0.527)
7.1(2)N1(1)
7.2(1)N1(0.246)
7.2(1)N1(1)
7.2(1)ZN(0.12)
7.3(0)N1(1)
https://tools.cisco.com/bugsearch/bug/CSCut21777/?reffering_site=dumpcr
Review Cisco Networking products for a $25 gift card