Enabling the DHCP Server

The security appliance can act as a DHCP server. DHCP is a protocol that supplies network settings to hosts including the host IP address, the default gateway, and a DNS server.

Note The security appliance DHCP server does not support BOOTP requests.

In multiple context mode, you cannot enable the DHCP server or DHCP relay on an interface that is used by more than one context.

You can configure a DHCP server on each interface of the security appliance. Each interface can have its own pool of addresses to draw from. However the other DHCP settings, such as DNS servers, domain name, options, ping timeout, and WINS servers, are configured globally and used by the DHCP server on all interfaces.

You cannot configure a DHCP client or DHCP Relay services on an interface on which the server is enabled. Additionally, DHCP clients must be directly connected to the interface on which the server is enabled.

To enable the DHCP server on a given security appliance interface, perform the following steps:

Step 1 Create a DHCP address pool. Enter the following command to define the address pool:

hostname(config)# dhcpd address ip_address-ip_address interface_name

The security appliance assigns a client one of the addresses from this pool to use for a given length of time. These addresses are the local, untranslated addresses for the directly connected network.

The address pool must be on the same subnet as the security appliance interface.

Step 2 (Optional) To specify the IP address(es) of the DNS server(s) the client will use, enter the following command:

hostname(config)# dhcpd dns dns1 [dns2]

You can specify up to two DNS servers.

Step 3 (Optional) To specify the IP address(es) of the WINS server(s) the client will use, enter the following command:

hostname(config)# dhcpd wins wins1 [wins2]

You can specify up to two WINS servers. Step 4 (Optional) To change the lease length to be granted to the client, enter the following command:

hostname(config)# dhcpd lease lease_length

This lease equals the amount of time (in seconds) the client can use its allocated IP address before the lease expires. Enter a value between 0 to 1,048,575. The default value is 3600 seconds.

Step 5 (Optional) To configure the domain name the client uses, enter the following command:

hostname(config)# dhcpd domain domain_name

Step 6 (Optional) To configure the DHCP ping timeout value, enter the following command:

hostname(config)# dhcpd ping_timeout milliseconds

To avoid address conflicts, the security appliance sends two ICMP ping packets to an address before assigning that address to a DHCP client. This command specifies the timeout value for those packets.

Step 7

(Transparent Firewall Mode) Define a default gateway. To define the default gateway that is sent to

DHCP clients, enter the following command.

hostname(config)# dhcpd option 3 ip gateway_ip

If you do not use the DHCP option 3 to define the default gateway, DHCP clients use the IP address of

the management interface. The management interface does not route traffic.

Step B

To enable the DHCP daemon within the security appliance to listen for DHCP client requests on the

enabled interface, enter the following command:

hostname(config)# dhcpd enable interface_name

For example, to assign the range 10.0.1.101 to 10.0.1.110 to hosts connected to the inside interface, enter

the following commands:

hostname(config)# dhcpd address 10.0.1.101-10.0.1.110 inside

hostname(config)# dhcpd dns 209.165.201.2 209.165.202.129

hostname(config)# dhcpd wins 209.165.201.5

hostname(config)# dhcpd lease 3000

hostname(config)# dhcpd domain example.com

hostname(config)# dhcpd enable inside

Configuring

DHCP Options

You can configure the security appliance to send information for the DHCP options listed in RFC 2132.

The DHCP options fall into one of three categories:

• Options that return an IP address.

• Options that return a text string.

• Options that return a hexadecimal value.

The security appliance supports all three categories of DHCP options. To configure a DHCP option, do

one of the following:

• To configure a DHCP option that returns one or two IP addresses, enter the following command:

hostname(config)# dhcpd option code ip addr_1 [addr_2]

• To configure a DHCP option that returns a text string, enter the following command:

hostname(config)# dhcpd option code ascii text

• To configure a DHCP option that returns a hexadecimal value, enter the following command:

hostname(config)# dhcpd option code hex value

X

Note

The security appliance does not verify that the option type and value that you provide match the expected

type and value for the option code as defined in RFC 2132. For example, you can enter the dhcpd option

46 ascii hello command and the security appliance accepts the configuration although option 46 is

defined in RFC 2132 as expecting a single-digit, hexadecimal value. For more information about the

option codes and their associated types and expected values, refer to RFC 2132.

Table 10-1 shows the DHCP options that are not supported by the dhcpd option command.

Table 10-1 Unsupported DHCP Options

Option Code

Description

0

DHCPOPT_PAD

1

HCPOPT_SUBNET_MASK

12

DHCPOPT_HOST_NAME

50

DHCPOPT_REQUESTED_ADDRESS

51

DHCPOPT_LEASE_TIME

52

DHCPOPT_OPTION_OVERLOAD

53

DHCPOPT_MESSAGE_TYPE

54

DHCPOPT_SERVER_IDENTIFIER

58

DHCPOPT_RENEWAL_TIME

59

DHCPOPT_REBINDING_TIME

61

DHCPOPT_CLIENT_IDENTIFIER

67

DHCPOPT_BOOT_FILE_NAME

82

DHCPOPT_RELAY_INFORMATION

255

DHCPOPT_END

Specific options, DHCP option 3, 66, and 150, are used to configure Cisco IP Phones. See the "Using Cisco IP Phones with a DHCP Server" section on page 10-4 topic for more information about configuring those options.

Continue reading here: Configuring DHCP Relay Services

Was this article helpful?

0 0