02-02-2022 10:37 PM
Hello,
I would like to configure for Cisco Anyconnect DHCP Address Assignment from Windows DHCP Server. I Use this Manuals (https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215854-configure-anyconnect-vpn-client-on-ftd.pdf), but nothing works.
Are there any additional steps?
02-02-2022 11:05 PM
@Irakli Gvishiani can you provide screenshot of what you've configured please?
02-02-2022 11:10 PM
I Get this error
Also I have added DHCP Relay Configuration on my core switch as it showed in manuals.
02-02-2022 11:56 PM
Is the object "obj_DHCP_Scope101" from the same network that is configured on your DHCP server?
Does the DHCP server recieve the DHCP requests?
Is the FTD also the default gateway or is this a dedicated VPN concentrator?
02-03-2022 12:37 AM
1 - Yes, obj_DHCP_Scope101 = 192.168.101.0 (Host), on the DHCP Server I created DHCP Pool 192.168.101.0/24
2 - As I discovered, no
3 - Yes, FTD is a default gateway, but Subnet 10.54.213.0/24 is not terminated on FTD, it terminated on Core Switch, Which is connected to FTD.
02-03-2022 12:54 AM
@Irakli Gvishiani udner the Connection Profile navigate to Advanced > Address Assignment Policy is Use DHCP selected?
02-03-2022 01:01 AM
Yes, this option is selected
02-03-2022 01:36 AM
@Irakli Gvishiani I assume the FTD can communicate (ping) the DHCP server(s)? Can you run a packet capture on the FTD itself and capture traffic to/from the DHCP server? Post the output here for review.
02-03-2022 02:29 AM - edited 02-03-2022 03:26 AM
Yes, FTD has access to the DHCP Server.
Also I run Wireshark on the DHCP server, but it doesn't receive any DHCP requests from FTD
02-03-2022 09:17 AM
I follow comment between you and Mr.Rob,
and finally you mention that the DHCP Server is connect to Core not directly to FTD so please config the IP helper in Core interface connect to FTD and check again.
02-03-2022 10:53 AM
I added this command, but still not works
02-03-2022 11:28 AM
@Irakli Gvishiani can you provide the output of "show route" from the FTD and "show ip route" from the directly connected core switch please.
02-03-2022 11:40 AM - edited 02-03-2022 11:40 AM
as Mr.Rob mention check the return DHCP from Core to FTD.
02-03-2022 10:42 PM
02-04-2022 03:05 AM
@Irakli Gvishiani I tested this in my lab using FMC/FTD v7 earlier it worked as expected. What version of FMC/FTD are you running?
From the CLI of the FTD, run system support diagnostics-cli and configure the following capture, this will capture traffic to/from the DHCP server.
capture CAPI interface INSIDE match ip any host <DHCP SERVER>
capture CAPI interface INSIDE match ip host <DHCP SERVER> any
Login to AnyConnect to try and get an IP address, from the FTD CLI use the command show capture CAPI provide the output for review.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide