Cisco Firewall :: Can Configure 3560 To Listen To Relayed DHCP Requests

Apr 18, 2013

I'll start out with the fact I work mostly with Wi-Fi and not a lot in the security realm... If I plug my workstation into the 3560, my wired client adapter can get an IP address.  But the WLAN adapter will not when associated to WLAN.Usually this is not a problem since you may only have two access points on the controller and a dozen or so hosts.  In my case, however, I want to put a few of the ports on the 3560 into the same VLAN as the WLAN on the 2106 so I can give them the same guest access as the WLAN.  The hosts plugged into the 3560 get an IP address without issue from the ASA.  When I disable dhcp proxy, the WLAN clients get an IP address, but then the APs cannot get an IP address from the internal DHCP server on the WLAN controller, and  cease to function when rebooted since they cannot get to the controller without an IP address.
 
Any way to configure the ASA to accept the modified DHCP packets from the WLAN controller?  It appears to me that the ASA is not able to accept DHCP relayed packets.

View 21 Replies


ADVERTISEMENT

Cisco Switching/Routing :: Configure 3560 To Force Client To Get IP By DHCP Relay Server?

Jul 30, 2012

How to configure cisco 3560 to force the client only can get ip by dhcp-relay server ?
 
The company i am working in has 5 vlans which have been set an lay-3 switch(3560), uses the dhcp-relay server .(in svi configuration: ip helper-address X.X.X.X) well , that works ok~
 
Now , I got my problem: I need to force the client only can get ip by dhcp-relay server, that means if anyone set static IP manunally , he can't really access to anywhere (to provent anyone set static IP with malignancy )
 
I know if a h3c router , how to set this configuration n svi configuration : dhcp relay security address-check enable )
the how to configure on a cisco 3560 ?

View 1 Replies View Related

Cisco Firewall :: Configure IOS IPS On Catalyst 3560?

Mar 18, 2012

is it possible to configure an IOS Firewall IPS on a Catalyst 3560? Which IOS version would I need if it were possible?

View 3 Replies View Related

Cisco Wireless :: How To Forward DHCP Requests Through 1140N AP

Oct 30, 2012

We have an 1140N AP connected to a switch and our "network partner" controls the router and will hand out DHCP and do the NAT for this WLAN.  How can I configure the AP to forward DCHP requests through.
 
I have WPA2 PSK (TKIP) setup and the client is able to authenticate however we fail to get an address.  In this case the Ethernet interface was left alone so it has the default config and it gets a DHCP address fine.  How can I configure this AP to enable the rest of the WiFI clients to get an IP?

View 6 Replies View Related

Cisco Wireless :: AP 1242AG Passing DHCP Requests

Jun 10, 2010

I have 2 1242AG APs setup with one SSID and no vlans configured.  The APs are connected to a switch along with my DHCP server.  Clients are able to connect to the SSID but are unable to get an IP from the server.  Clients can plug into the switch and get an IP.  If I configure a static IP on the wireless card, the client works fine.
 
Is there something I'm missing on the AP to allow DHCP requests to pass through? IPhelper?
 
Here is the AP info: AIR-AP1242AG-A-K9  12.4(21a)JA1

View 7 Replies View Related

D-Link DAP-1522 :: DHCP Requests Thorough DAP Units?

Dec 7, 2011

I am trying out a DAP-1513 unit but there is no forum section for this? My question seems to be general and might cover the other models also.  Do the DHCP request, from the attached LAN devices on the DAP, get pass to the DHCP "server?"  

View 6 Replies View Related

Cisco Switching/Routing :: ESW-520-24P Not Passing DHCP Requests From AP1141

Dec 14, 2011

Cisco Small Business Switch POE ESW-520-24P with a Wireless Access Point Cisco Aironet AP1141. Both the devices are upgraded to the latest firmware.

 Connected to the ESW-520-24P is a Windows 2008 SBS 2011 with DCHP and Domain Controller. Along with the server I have a number of wired computers connected to the switch which do not have any issues and connect to the DHCP server without any problems.

 When connecting two wireless devices to the AP1141, they get the IP address and DHCP from the server; but when connecting other devices apart the first two they will fail to connect to the DHCP server and do not get any IP Address. They manage to connect to the Wireless access point but they cannot contact the DHCP server.

View 17 Replies View Related

Cisco Wireless :: 5508 - DHCP Requests Starts Failing

Feb 15, 2013

I have a school with 550 iPads.  We are using two 5508 WLCs sharing the number of APs.  The DHCP server and the default gateway for the network are on the firewall.  The clients are able to get a DCHP.  After some time, maybe about longer than a month, the clients are no longer able to get DCHP addresses.  A reboot of both controllers takes care of this.  Presently we are runing 7.2.110 OS.  I am going to upgrade to the latest 7.4.100, and reload tonight.

View 1 Replies View Related

Cisco Wireless :: WAP200 Not Forwarding DHCP Requests Onto Server

Feb 15, 2012

I have a Linksys WAP200 Wireless-G Access Point problem. It is SW version 2.0.4.0.  I have it configured for a small network and the problem seems to be that it is not forwarding DHCP requests onto my DHCP server.   I know that it is not a SSID or Key issue as when I give my devices static IP addresses, they communicate fine within my system.   The only issue seems to be when the devices make DHCP client requests.   I also know that the problem is not my DHCP server as it has the device's IP / mac addresses in its configuration file and other wired devices are able to communicate with it to get their IP address through DHCP.
 
I have seen that there was talk in some blogs about WAP200 no forwarding DHCP requests and I was hoping that updating the device to the latest release would have resolved the problems.

View 3 Replies View Related

Cisco Wireless :: Two WET200s Bridge Not Passing DHCP Requests

Dec 15, 2010

We have setup a bridge between two of our offices using two WET200's in adhoc mode.   Everything is connected fine and the signal strengh is good.   All traffic pass's over the bridge correctly but DHCP requsts/replys seem to be failing to traverse the bridge.    Our DHCP server is hosted on site A and the computers on site B fail to obtain thiers IP's from the dhcp over the bridge requiring us to use static IP's.Firmware is currently the latest.

View 1 Replies View Related

Cisco Switches :: SG200-18 Fails To Pass DHCP Requests?

May 30, 2013

I have a sg200-18 connected via one of the ports to my ISP's router/modem.  Using an unmanaged switch everything works as expected, but after a few days on my sg200 my two computers fail to get assigned IP's and cannot connect to anything.  I also have a couple printers that seem to have no problems getting their IP's passed through to the router as I can use them fine from my machines when connected to the unmanaged switch.
 
Is there a possibility I don't have my switch setup properly to know that all outgoing data must go to the router, or UDP traffic is being dropped somehow?

View 7 Replies View Related

Cisco Switching/Routing :: 881 - Blocking DHCP Requests Of Windows Clients?

Nov 18, 2012

We've got 5 remote offices with cisco 881 routers, Win Clients behind them and all routers connected via vpn site-to-site to central software router.

Mostly all clients recieve ip addresses from routers in their subnets 192.168.x.024
We have Win DHCP Server in subnet 192.168.181.024
 
The problem is that some of clients,physically sutuated in 192.168.10.024 subnet, recieve ip addresses from Win DHCP server from 192.168.181.024 subnet.
 
Here's part of cisco cfg:
 
interface FastEthernet0
no ip address
!
interface FastEthernet1

[Code].....

View 3 Replies View Related

Cisco Switching/Routing :: 3560x / Block DHCP Requests Over VLANs

Jan 10, 2012

I have two 3560x Catalyst switches setup between two different locations. They link via a PTP line (Layer 2). I have setup Intervlan routing between the switches and that works fine.Each location has a separate subnet and a Windows DHCP server for each subnet.I want to block any DHCP requests to be sent from hosts on one subnet to the DHCP server on the other side (i.e across the PTP link) What is the best method to do this?

View 5 Replies View Related

Cisco Switching/Routing :: 3500XL - Same DHCP Server Serving Requests For 2 VLANs

Jul 18, 2012

I have several Cata 3500XL switches connected to one 1 HP L3 switch which is connected Sonicwall router. Vlan1 has subnet of 10.10.0.0/24 and Microsoft DCHP server lays inside VLAN1.
 
Now i want to add VLAN11  (192.168.10.0/24) as second data VLAN but DHCP requests should go to microsoft DCHP server.
 
This is what i did:
Configured VLAN11 IP on each cisco switch
IP default gateway with IP from other subnet (i guess this is bad since maybe it should be IP of VLAN11 on HP L3 switch?)
Trunk ports are configured to pass everything on cisco switches
On VLAN11  i configured IPhelper IP to be MS DHCP server on each Cisco switch
 
I haven't tested this yet but i have problem in process.I can't ping VLAN11 IPs between switches (i configured VLAN1 and VLAN11 with IP). When client plugs computer to a port that belongs to VLAN11 will i be sure that client will get IP from the 192.168 range or there is possiblity that he gets IP from the management VLAN range?

View 4 Replies View Related

3750 - Craft Helper Addresses So DHCP Requests Go To Proper Server

Dec 15, 2012

Setting up a stand-alone WDS/PXE server.Current we have helper addresses setup to forward the DHCP requests from the different VLAN's to the DHCP server. The WDS/PXE server we are setting up is on its server. How do we craft the helper addresses so DHCP requests go to the proper server hosting DHCP and PXE requests go the WDS server?

Everything I seen on Microsoft Technet, lists using Helper Address as the recommended way, but assume both services are on the same server. Our helper address is as follows on each VLAN interface in router: ip helper-address X.X.X..This is a Cisco 3750.

View 6 Replies View Related

Cisco Firewall :: Can Configure ASA5510 As DHCP Server For LAN

Oct 13, 2011

I am using a fiber optic connection. I want to connect it directly to ASA5510. A WLC2504 will be connected to ASA and one Aironet AP will be deployed at first. (At this moment I am not using any Windows server but in near future I will need to deploy Windows Server 2003 in my corporate network) My questions are:
 
Can I configure ASA as DHCP server for my LAN?

Can I configure WLC as DHCP server for my LAN?

If we can configure both then what is the best practice from above two options? (I am new to Cisco stuff and first time user)

View 1 Replies View Related

Cisco Firewall :: Configure Multiple Dhcp On ASA 5505?

Dec 23, 2011

I want to configure multiple DHCP pool on ASA. that I create like
 
int e0/2
no shut
 
interface Ethernet0/2.10vlan 10nameif inside10security-level 100ip address 192.168.10.1 255.255.255.0
interface Ethernet0/2.20vlan 20       nameif inside20 security-level 100ip address 192.168.20.1 255.255.255.0
dhcpd address 192.168.10.10-192.168.10.254 inside10dhcpd dns x.x.x.x  y.y.y.y interface inside10dhcpd enable inside10
dhcpd address 192.168.20.10-192.168.20.254 inside20dhcpd dns h.h.h.h  z.z.z.z interface inside20dhcpd enable inside20
 
I have following query...
 
1. int e0/2 work as trunk port, is it?  any special confiduration require other than dot1Q?
 
2. How can I configure inside interface?  is it like,

    access-group inside_access_in_1 in interface inside10
    access-group inside_access_in_1 in interface inside10
 
3. How can I configure static NAT ?
 
4. How can i configured inside route?
 
5. How can I configured default NATing?
 
6. On which interface I access ASA? currently using inside interface.

View 5 Replies View Related

Cisco WAN :: Configure 877W Router As Firewall With DHCP Assigned WAN IP

Nov 15, 2010

I'm configuring a Cisco 877 router as my firewall.My WAN IP will be assigned dynamically with DHCP.  I will also get my default route from DHCP.I will need to configure ip inspection and packet filtering.I will need to configure NAT, I will eventually need to also configure a dial-up VPN.

View 7 Replies View Related

Cisco Firewall :: Configure DHCP Server On Inside Interface ASA 5505

May 9, 2012

We've just started with the ASA 5505. We do run a DHCP server on the inside interface, so it is in the same VLAN 1 as all of the clients. However, we cannot get it to work.We can't use DHCP Relay, as the ASA 5505 only allows to relay to DHCP servers in a different subnet.Or do we have to move the DHCP server to a different subnet. If so, how would we configure that scenario?

View 13 Replies View Related

Cisco Firewall :: Ubuntu 10.04 / Firewall Starts Randomly Responding To ARP Requests For Other IPs

Aug 22, 2011

I have my firewall on IP 192.168.0.1 (for example, real IP is a class C address).  I have a web server (Ubuntu 10.04, though this happened before with an 8.04 box as well) on ip 192.168.0.101.  Everything will be functioning fine, and I won't have any issues for a while.  Then, randomly I'll have problems getting to my web server, getting disconnected from SSH sessions.  I go to one of my linux boxes and do an "arping -b 192.168.0.101" and I will get  two responses, one from my firewall and one from the box, as illustrated below.  The only way to correct the issue that I've run into is to reload the firewall, which will then behave properly again until it randomly decides to start answering ARP requests on the other IP again.
 
nwiadmin@vm-test-lx:~$ arping -b if-webdevint4-lxWARNING: interface is ignored: Operation not permittedARPING 192.168.0.101 from 192.168.0.168 eth0Unicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  2.309msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.434msUnicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  2.280msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.377msUnicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  2.129msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.221msUnicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  1.839msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.934msSent 4 probes (4 broadcast(s))Received 8 response(s)
 
Reloaded firewall
 
nwiadmin@vm-test-lx:~$ arping -b if-webdevint4-lxWARNING: interface is ignored: Operation not permittedARPING 192.168.0.101 from 192.168.0.168 eth0Unicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.839msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.935msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.758msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.733msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  9.568msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.931msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.283msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.756msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.070msSent 9 probes (9 broadcast(s))Received 9 response(s)

View 5 Replies View Related

Cisco Switching/Routing :: 3550 - Configure Firewall DHCP Server Through 10.1.1.0 Connection?

Oct 2, 2012

Is there a way to configure a DHCP server for my internal subnet of 192.168.20.1 which is on a 3550 layer 3 switch from my 5505 ASA Firewall.My subnet of 10.1.1.0/30 is connecting my 5505 to 3550. All I'm trying to do is run a DHCP server down to my hosts. The only options on ASA 5505 is
 
dhcpd address 192.168.20.1 - 192.168.20.254 outside or inside, which conflicts with my subnet of 10.1.1.0 used to connect my internal subnet of 192.168.20.1 for the whole network.
 
When I used my router it did not need the (inside, outside) keywords and just an ip helper-address command. How do I configure my my firewall DHCP server to propagate the 192.168.20.0 network through my 10.1.1.0 connection.

View 3 Replies View Related

How To Make Computer Listen To A Single Port

Oct 5, 2011

i want my computer to make connections to only a single port (53 in this case)......how can i do this? i am using a wireless broadband data card. i am using windows 7 ultimate. is there any way to make such settings in my pc and if so how do i set or make the settings so that my computer will only make connections and also listen to the single port 53?

View 9 Replies View Related

D-Link DIR-655 :: Create Firewall Rule To Block All DNS Requests Except To Specific Servers

Mar 3, 2011

Using a DIR-655, does anybody know how to create a firewall rule to block all dns requests except to specific servers?

View 2 Replies View Related

Cisco WAN :: Dhcp No Internet On 3560?

Jun 10, 2011

have a problem with my 3560 Series PC gets a dhcp of the switches but not on the Internet?

View 1 Replies View Related

Cisco LAN :: 3560 - Add Second / Sub DHCP Pool?

Jul 25, 2012

We have the configuration below set up in a 3560 switch (addresses and names modified for privacy). We are running out of dynamic IP’s in the current pool (6.35.159.0 – 6.35.159.255). We have a new set of IP’s that we can use (6.44.56.0 – 6.44.57.255 – an additional 512 addresses). Although I can figure out the commands to add a new dhcp pool, secondary subnet, etc., I’ve never done this before so I’m not sure of everything I need to do. The end result I need is that the 3560 needs to be able to hand out IP addresses from the current and new pool to anything connecting to vlan 300 – our datanet where computers access the Internet. What I need to do as far as modifying the vlan, adding the secondary subnet, defining helper IP’s, gateways, whatever, so that computers connecting via vlan 300 have Internet access via either of the pools?  I have been told that all I need to do is create the pool, but not sure if that is correct...
 
[code]....

View 3 Replies View Related

Cisco WAN :: DIR-655 / How To Dhcp Auto Interface Port 3560

Apr 21, 2013

i have a adsl modem that is sending dhcp reqeust and i want to use that on my cisco switchs 3560 48 ports.i want to use the interface port 0/48 as a WAN connection and i want to use the other interfaceports for DCHP pool.i have an d-link (dir655) router at home and i want to have the same situation on my cisco switch my WAN interface get from a DHCP reqeust an ip adress from  the provider like 10.10.123.44 (for the cisco switch would this interface port gig 0/48)then i want to configere my  LAN as a DHCP pool like 192.168.0.1 (for the cisco switch would this interface port gig 0/1 - 47 .

View 3 Replies View Related

Cisco Switching/Routing :: DHCP Relay On 3560

Apr 12, 2012

Would like to impliment VLAN's on Cisco IOS Software, C3560 Software (C3560-IPSERVICES-M), Version 12.2(25)SEB4...But I need a DHCP Realy to my Windows Based DHCP Server.  How do I enable DHCP Relay on the 3560?

View 8 Replies View Related

Linksys Wireless Router :: AE3500 - Listen Port Stays Always Green

Apr 10, 2013

I recently upgraded my ADSL to a 1Mbps line and I got a new Fritz box(7390) with it and i bought a linksys ae3500 wireless router. I am using Bit comet to download my torrents and my listen port stays at a yellow light. I previously had only the Fritz box 7170 and my listen port was always green.

View 1 Replies View Related

Cisco Switching/Routing :: 1433 - Span Port Configuration To Listen To Specific Traffic Only?

Nov 2, 2011

Is it possible to configure the span(switch port analyzer) port and restrict it to only listen to ingress and egress of TCP/1433 from the source port?

View 2 Replies View Related

Cisco Switching/Routing :: 3560 Implement DHCP Snooping

Oct 12, 2011

I have attempted to implement DHCP snooping and have been having some strange issues. I have 5 3560s taht I use for my edge and when I attempt to implement on all five, the VLAN that houses my voice data appears to no longer be able to recieve DHCP lease renewals so after the 24 expiration all of my phones lose their configs. Once I roll back the changes the voice VLAN comes back. The other VLANs seem to function correctly as theya re able to renew their DHCP addresses.
 
The 3560s tie into each other using GIG Ports 1 & 2 and the top and bottom switches tie into our core switch, a 4507. The config that I use is below, failry simple and straightforward.

4 of the 5 switches feed our general office vlans for voice and data however the 5th switch is there for expansion and not in use. As such I have left the config changes in place on it and have tied myself and a colleague into it and have been operating fine for over a week now. So the config that I use seems sound in theory and should work on the other 4 switches with no issue.

View 14 Replies View Related

Cisco Switching/Routing :: 3560 DHCP In Layer 3 Switch

May 25, 2012

I have made a topology by using one 3560 switch and 2 2950 switches. I have also made 2 vlans name Clients and other Servers and vlan 1 is for anagement purposes. The left 2950 switch is for clients and the right is for servers. Clients is vlan 2 and servers is vlan3 . Now what i want is that my dhcp is should assign ips to clients in vlans 2 provided that servers are in vlan 3. I am also using a border router and i have introduced a default route on the 3560 to the border router.
 
Now when i assign static ips to my clients pc and server dhcp then i can ping between vlans but when i try to assign ip through dhcp then it wont work. Also the default route on the switch to the border router doesnt seem to work. I can ping only the border router when i put a default route on the border router instead of the 3560 switch.

View 3 Replies View Related

Cisco Switching/Routing :: 3560 DHCP Between Switch And Router

Jul 23, 2012

I have a cisco 3560 24PS and its connected to two ADSL broard band routers.one is a personal broadband line using a Billion ADSL broadband router, and the other is a business broardband line using BT's 2wire broadband line.on the Billion routers i have various things attached like a NAS and a printers, both wired connections. then i have laptops and phones that connect over wifi, so its configured to act as a DHCP server
 
the only thing conncted to my 2wire router is my company's laptop (wired or wifi depending on where i'm working from), so again i have it working as a dhcp server.The switch is configured with multiple vlans, with dhcp scopes assigned for each vlan.I have a static route pointing all traffic to my Billion ADSL for internet connectivity.
 
The problem i'm having is that when i turn on the cisco switch, all wifi conected devices loose their conection. only 2 things get it working again, a reboot of the router, or disabling then enabling the DHCP service on the router.upon further analysis i was able to find out that the devices were not able to pick up an address from the router. again i looked deeper into this and i can see the following on logs of my router: [code]
 
so it seems that the router tuns off its DHCP capabilities because it detects that my Cisco switch is running DHCP services. I need to figure out how to keep the billion routers DHCP running when ever the switch is turned on.is there a way of filtering out any DHCP chat from the switch to the router?

View 7 Replies View Related

Cisco Switching/Routing :: 3560 - Basics Of DHCP Snooping

Jan 18, 2013

I am trying to understand the basics of DHCP snooping.  I have a just a 3560 switch and a laptop ( to get a DHCP address) and my DSL router which has a DHCP server running.  On the switch I have enabled "IP DHCP Snooping" and "IP DHCP Snooping VLAN 1" plugged the laptop and DSL router in and the laptop gets and IP address, should it? 

I thought all ports were untrusted by default so the DHCP server should be blocked at offering IP addresses? If I wanted the DHCP server to be allowed to offer IP's I thought I should need to trust the port.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved