cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4807
Views
200
Helpful
31
Replies

Cisco FTD Anyconnect DHCP

Hello,

 

I would like to configure for Cisco Anyconnect DHCP Address Assignment from Windows DHCP Server. I Use this Manuals (https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215854-configure-anyconnect-vpn-client-on-ftd.pdf), but nothing works. 

 

Are there any additional steps? 

31 Replies 31

@Irakli Gvishiani can you provide screenshot of what you've configured please?

dhcp1.PNG

dhcp-2.PNG

 

 

I Get this error

err.PNG

 

Also I have added DHCP Relay Configuration on my core switch as it showed in manuals.

@Irakli Gvishiani

Is the object "obj_DHCP_Scope101" from the same network that is configured on your DHCP server?

Does the DHCP server recieve the DHCP requests?

Is the FTD also the default gateway or is this a dedicated VPN concentrator?

1 - Yes, obj_DHCP_Scope101 = 192.168.101.0 (Host), on the DHCP Server I created DHCP Pool 192.168.101.0/24

2 - As I discovered, no 

3 - Yes, FTD is a default gateway, but Subnet 10.54.213.0/24 is not terminated on FTD, it terminated on Core Switch, Which is connected to FTD. 

@Irakli Gvishiani udner the Connection Profile navigate to Advanced > Address Assignment Policy is Use DHCP selected?

Yes, this option is selected 

@Irakli Gvishiani I assume the FTD can communicate (ping) the DHCP server(s)? Can you run a packet capture on the FTD itself and capture traffic to/from the DHCP server? Post the output here for review.

Yes, FTD has access to the DHCP Server.

 
 

dhcp-3.PNG

Also I run Wireshark on the DHCP server, but it doesn't receive any DHCP requests from FTD 

I follow comment between you and Mr.Rob, 
and finally you mention that the DHCP Server is connect to Core not directly to FTD so please config the IP helper in Core interface connect to FTD and check again.Screen Shot 2022-02-03 at 7.13.50 PM.png

I added this command, but still not works 

@Irakli Gvishiani can you provide the output of "show route" from the FTD and "show ip route" from the directly connected core switch please.

as Mr.Rob mention check the return DHCP from Core to FTD.

 

dhcp-4.PNG

dhcp-5.PNG

dhcp-6.PNG

@Irakli Gvishiani I tested this in my lab using FMC/FTD v7 earlier it worked as expected. What version of FMC/FTD are you running?

 

From the CLI of the FTD, run system support diagnostics-cli and configure the following capture, this will capture traffic to/from the DHCP server.

capture CAPI interface INSIDE match ip any host <DHCP SERVER>
capture CAPI interface INSIDE match ip host <DHCP SERVER> any

Login to AnyConnect to try and get an IP address, from the FTD CLI use the command show capture CAPI provide the output for review.