Solved

Cisco VPN 3000 Concentrator & Windows DHCP Server

Posted on 2004-08-14
2
697 Views
Last Modified: 2012-08-14
My company has two full class C IP address blocks.  The first is reserved exclusively for our primary corporate office.  The second block is split up amongst our several satellite offices.  There are several subnets unused in this second block.

We have a Cisco VPN 3000 Concentrator for providing remote access.  At the moment, the concentrator just relays DHCP requests to our DHCP server in our primary office and they get addresses that are in that first class C block for our primary office.  This is not desirable; I would much rather have the remote access clients get IP addresses from a leftover subnet within that second block of addresses.

I've tried doing this by just using the internally configurable IP Pool functionality in the Concentrator, but the problem with this is that I can't figure out how to give the clients an appropriate subnet mask for that little subnet that I'd use for only VPN clients.  They get the standard classful mask, which means that they won't be able to reach other clients within that second class C block of addresses.  --- If someone can tell me how to specify an appropriate subnet mask, that would work.

Otherwise, I'd like to just have the same setup with the Concentrator relaying DHCP requests to our DHCP server, but I'd like the DHCP server to give out addresses from a different scope as the "primary office" range of addresses.  Is it somehow possible to configure a Windows 2000 Server DHCP server to give out these subnet addresses only to requests originating at the VPN concentrator?

Thanks!
0
Comment
Question by:titan6400
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 400 total points
ID: 11802867
What version OS are you running on the VPN3000? The latest version 4.1.5 has an option to set a subnet mask on the IP address pool.
0
 

Expert Comment

by:troubleu2
ID: 11812915
Are you asking to have the 3005 provide DHCP to then entire office here: "won't be able to reach other clients within that second class C block of addresses?"
If not, why do remote clients require access to other remote clients?

For remote access, each group of users can receive different DHCP scopes. Under Group settings -> General -> The DHCP Network Scope.
Configuration | System | Servers | DHCP screen...Enter the IP sub-network
Enter 0.0.0.0 for the default; by default, the DHCP server assigns addresses to the IP sub-network of the VPN Concentrator's private interface.


If the Windows DHCP server is relaying IP's to these scopes, you filter for group (location).
IAS could also be used to provide DHCP groups - likely with greater ease then the 3005.

HTHs

0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Wifi(LAN) GW being picked up 2 45
Enterasys QoS setup 2 57
Radius Debug Error 16 60
How can I measure the quality of my Internet access? 2 32
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now