Configuring Dhcp Relay Services - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Chapter 10
Configuring DHCP, DDNS, and WCCP Services

Configuring DHCP Relay Services

A DHCP relay agent allows the security appliance to forward DHCP requests from clients to a router
connected to a different interface.
The following restrictions apply to the use of the DHCP relay agent:
DHCP Relay services are not available in transparent firewall mode. A security appliance in transparent
Note
firewall mode only allows ARP traffic through; all other traffic requires an access list. To allow DHCP
requests and replies through the security appliance in transparent mode, you need to configure two
access lists, one that allows DCHP requests from the inside interface to the outside, and one that allows
the replies from the server in the other direction.
To enable DHCP relay, perform the following steps:
To set the IP address of a DHCP server on a different interface from the DHCP client, enter the following
Step 1
command:
hostname(config)# dhcprelay server ip_address if_name
You can use this command up to 4 times to identify up to 4 servers.
To enable DHCP relay on the interface connected to the clients, enter the following command:
Step 2
hostname(config)# dhcprelay enable interface
(Optional) To set the number of seconds allowed for relay address negotiation, enter the following
Step 3
command:
OL-10088-01
To provide information for DHCP requests that include an option number as specified in RFC-2132,
enter the following command:
hostname(config)# dhcpd option number value
To provide the IP address or name of a TFTP server for option 66, enter the following command:
hostname(config)# dhcpd option 66 ascii server_name
To provide the IP address or names of one or two TFTP servers for option 150, enter the following
command:
hostname(config)# dhcpd option 150 ip server_ip1 [server_ip2]
The server_ip1 is the IP address or name of the primary TFTP server while server_ip2 is the
IP address or name of the secondary TFTP server. A maximum of two TFTP servers can be
identified using option 150.
To set the default route, enter the following command:
hostname(config)# dhcpd option 3 ip router_ip1
The relay agent cannot be enabled if the DHCP server feature is also enabled.
Clients must be directly connected to the security appliance and cannot send requests through
another relay agent or a router.
For multiple context mode, you cannot enable DHCP relay on an interface that is used by more than
one context.
Cisco Security Appliance Command Line Configuration Guide
Configuring DHCP Relay Services
10-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents