04-24-2020 06:50 AM
Hi,
I am using a Cisco Firepower 2130 with FTD code version 6.5.0 for RA VPN using AnyConnect Client 4.x.
I configured my VPN to use a DHCP Server a.b.c.d and DHCP Scope 10.44.96.20-10.44.111.254.
When I use only the VPN Pool (like DHCP scope) AnyConnect client connet immédiately and I can connect to our internal LAN.
When I ise DHCP server in the connection profile and I remove the VPN Pool from Address Pools. I get the following events via FMC:
IPAA: Session=0x00337000, IPv4 address: UTL_ProcIpAddrQEvent DHCP Failed - trying local pool
AnyConnect client took a long long time to get the IP address and connect.
What is the brest practice for use DHCP server for RA VPN ?
What's wrong in my setup ?
Thanks for your help.
04-24-2020 08:51 PM
04-25-2020 02:32 AM
Thanks Francesco.
I have a DHCP and VPN Pool. The IP address assigned to AnyConnect is from the VPN Pool not from DHCP.
I configured, via FMC, the VPN like this:
- I removed the VPN Pool from Connection profile and I kept the DHCP server
- I removed the VPN Pool from Policy and add DHCP scope using an network object with 10.44.96.0 (this scope exist in our DHCP Server)
- In Devices > VPN > Remote Access > RA_VPN > Advanced > Address Assignment Policy > Use DHCP (I kept only this box checked)
Firepower 2130 can ping DHCP server.
When I connect I can see in the VPN Troubleshooting no TCP SVC and I got a message in AnyConnect client indicating that there is No IP.
04-27-2020 11:30 PM
I will close this because I found this thread exposing my issue with DHCP:
04-28-2020 06:51 PM
04-28-2020 10:11 PM
Is your DHCP server on the same subnet as your FTD inside interface?
I've found that it will not work when that is the case.
04-29-2020 12:52 AM
Is your DHCP server on the same subnet as your FTD inside interface?
DHCP is in another VLAN than Inside interface but there is no filtering.
04-29-2020 03:40 PM
04-29-2020 03:55 PM
Yes sure.
I will write a complete setup guide RA VPN with DHCP, Microsoft NPS for Radius and MFA.
I need to santize the document to remove all company private information to avoid any information gathering.
Will keep you updated.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide