Enabling the DHCP Server
The security appliance can act as a DHCP server. DHCP is a protocol that supplies network settings to hosts including the host IP address, the default gateway, and a DNS server.
Note The security appliance DHCP server does not support BOOTP requests.
In multiple context mode, you cannot enable the DHCP server or DHCP relay on an interface that is used by more than one context.
You can configure a DHCP server on each interface of the security appliance. Each interface can have its own pool of addresses to draw from. However the other DHCP settings, such as DNS servers, domain name, options, ping timeout, and WINS servers, are configured globally and used by the DHCP server on all interfaces.
You cannot configure a DHCP client or DHCP Relay services on an interface on which the server is enabled. Additionally, DHCP clients must be directly connected to the interface on which the server is enabled.
To enable the DHCP server on a given security appliance interface, perform the following steps:
Step 1 Create a DHCP address pool. Enter the following command to define the address pool:
hostname(config)# dhcpd address ip_address-ip_address interface_name
The security appliance assigns a client one of the addresses from this pool to use for a given length of time. These addresses are the local, untranslated addresses for the directly connected network.
The address pool must be on the same subnet as the security appliance interface.
Step 2 (Optional) To specify the IP address(es) of the DNS server(s) the client will use, enter the following command:
hostname(config)# dhcpd dns dns1 [dns2]
You can specify up to two DNS servers.
Step 3 (Optional) To specify the IP address(es) of the WINS server(s) the client will use, enter the following command:
hostname(config)# dhcpd wins wins1 [wins2]
You can specify up to two WINS servers. Step 4 (Optional) To change the lease length to be granted to the client, enter the following command:
hostname(config)# dhcpd lease lease_length
This lease equals the amount of time (in seconds) the client can use its allocated IP address before the lease expires. Enter a value between 0 to 1,048,575. The default value is 3600 seconds.
Step 5 (Optional) To configure the domain name the client uses, enter the following command:
hostname(config)# dhcpd domain domain_name
Step 6 (Optional) To configure the DHCP ping timeout value, enter the following command:
hostname(config)# dhcpd ping_timeout milliseconds
To avoid address conflicts, the security appliance sends two ICMP ping packets to an address before assigning that address to a DHCP client. This command specifies the timeout value for those packets.
|
Step 7 |
(Transparent Firewall Mode) Define a default gateway. To define the default gateway that is sent to |
|
DHCP clients, enter the following command. |
|
|
hostname(config)# dhcpd option 3 ip gateway_ip |
|
|
If you do not use the DHCP option 3 to define the default gateway, DHCP clients use the IP address of |
|
|
the management interface. The management interface does not route traffic. |
|
|
Step B |
To enable the DHCP daemon within the security appliance to listen for DHCP client requests on the |
|
enabled interface, enter the following command: |
|
|
hostname(config)# dhcpd enable interface_name |
|
|
For example, to assign the range 10.0.1.101 to 10.0.1.110 to hosts connected to the inside interface, enter |
|
|
the following commands: |
|
|
hostname(config)# dhcpd address 10.0.1.101-10.0.1.110 inside |
|
|
hostname(config)# dhcpd dns 209.165.201.2 209.165.202.129 |
|
|
hostname(config)# dhcpd wins 209.165.201.5 |
|
|
hostname(config)# dhcpd lease 3000 |
|
|
hostname(config)# dhcpd domain example.com |
|
|
hostname(config)# dhcpd enable inside |
|
|
Configuring |
DHCP Options |
|
You can configure the security appliance to send information for the DHCP options listed in RFC 2132. |
|
|
The DHCP options fall into one of three categories: |
|
|
• Options that return an IP address. |
|
|
• Options that return a text string. |
|
|
• Options that return a hexadecimal value. |
|
|
The security appliance supports all three categories of DHCP options. To configure a DHCP option, do |
|
|
one of the following: |
|
|
• To configure a DHCP option that returns one or two IP addresses, enter the following command: |
|
|
hostname(config)# dhcpd option code ip addr_1 [addr_2] |
|
|
• To configure a DHCP option that returns a text string, enter the following command: |
|
|
hostname(config)# dhcpd option code ascii text |
|
|
• To configure a DHCP option that returns a hexadecimal value, enter the following command: |
|
|
hostname(config)# dhcpd option code hex value |
|
|
X |
|
|
Note |
The security appliance does not verify that the option type and value that you provide match the expected |
|
type and value for the option code as defined in RFC 2132. For example, you can enter the dhcpd option |
|
|
46 ascii hello command and the security appliance accepts the configuration although option 46 is |
|
|
defined in RFC 2132 as expecting a single-digit, hexadecimal value. For more information about the |
|
|
option codes and their associated types and expected values, refer to RFC 2132. |
|
|
Table 10-1 shows the DHCP options that are not supported by the dhcpd option command. |
|
Option Code |
Description |
|
0 |
DHCPOPT_PAD |
|
1 |
HCPOPT_SUBNET_MASK |
|
12 |
DHCPOPT_HOST_NAME |
|
50 |
DHCPOPT_REQUESTED_ADDRESS |
|
51 |
DHCPOPT_LEASE_TIME |
|
52 |
DHCPOPT_OPTION_OVERLOAD |
|
53 |
DHCPOPT_MESSAGE_TYPE |
|
54 |
DHCPOPT_SERVER_IDENTIFIER |
|
58 |
DHCPOPT_RENEWAL_TIME |
|
59 |
DHCPOPT_REBINDING_TIME |
|
61 |
DHCPOPT_CLIENT_IDENTIFIER |
|
67 |
DHCPOPT_BOOT_FILE_NAME |
|
82 |
DHCPOPT_RELAY_INFORMATION |
|
255 |
DHCPOPT_END |
Specific options, DHCP option 3, 66, and 150, are used to configure Cisco IP Phones. See the "Using Cisco IP Phones with a DHCP Server" section on page 10-4 topic for more information about configuring those options.
Continue reading here: Configuring DHCP Relay Services
Was this article helpful?