cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
986
Views
0
Helpful
3
Replies

Cisco ASA VPN DHCP through Cisco ASA Firewall.

raun.williams
Level 3
Level 3

Hello all!

Quick question.  I have an ASA5520 (8.2) acting as a VPN server with the correct configuration to request a DCHP address on behalf the VPN Client.  However, This ASAVPN is connected to a vpn-dmz on my other ASA5520 (8.0) that is our main firewall.  I can see the request coming through the DMZ and to the inside interface of the ASAFIREWALL and out.  The DHCP Server responds and sends it back to x.x.x.0.   I did not originally have dhcp relay setup on the ASAFIREWALL as I had upd 67 open, thinking it would just allow it back through with out issue.  Any idea how to go about getting this to work correctly?                  

Thanks,

Raun

1 Accepted Solution

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Raun,

Please check the following link from one of the Cisco engineers.

It will help you on this

https://supportforums.cisco.com/community/netpro/security/firewall/blog/2011/01/07/asa-pix-dhcp-relay-through-vpn-tunnel

Any other question..Sure...Just remember to rate all of my answers.

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Raun,

Please check the following link from one of the Cisco engineers.

It will help you on this

https://supportforums.cisco.com/community/netpro/security/firewall/blog/2011/01/07/asa-pix-dhcp-relay-through-vpn-tunnel

Any other question..Sure...Just remember to rate all of my answers.

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hey Julio

Thanks for the response.  I was actually able to get my situation working with out any static translations.  However, that document is very useful for ANOTHER project in the works, so correct answer anyways!

Hello Raun,

Great to hear that Can you share how you resolve it so future users can learn from your case?

Regards,

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC