We help IT Professionals succeed at work.

Cisco 851 router won't get/give DHCP address with firewall on

izgoblin
izgoblin asked
on
Medium Priority
723 Views
Last Modified: 2013-11-16
Hello,
With the help of someone here I've mostly gotten our Cisco 851 router going, but I still have one issue.   If I enable my access-lists, our Cisco 851 router will not obtain a DHCP address from our service provider, nor will it successfully give out any DHCP addresses to local clients.    All I need to do to make both of these work is to remove the "ip access-list 105 in" and "ip access-list 102 in" lines from FastEthernet4 and Vlan1 respectively.   But then of course I don't have a firewall.  

For reference, we have a simple setup with simple requirements -- internet is provided via a cable modem and we just want to have basic firewall features (i.e. any connections initiated from the inside gets out, no connections initiated from the outside get in).   Only exceptions are whatever may be required for typical internet usage.  

I've attached my current config, but the relevent access-lists are below:

access-list 102 permit tcp 192.168.1.0 0.0.0.255 any
access-list 102 permit udp 192.168.1.0 0.0.0.255 any
access-list 102 permit icmp 192.168.1.0 0.0.0.255 any
access-list 102 deny   ip any any log
access-list 105 permit icmp any any
access-list 105 deny   ip any any log

Surely I must be missing something since enabling the access lists prevents the router from getting or giving out DHCP addresses, but what could it be?   Note that when this problem occurs, "show log" does not reveal the answer, to me anyway.  :)  

Thanks so much for any and all assistance!  
ms-config-0217.txt
Comment
Watch Question

Top Expert 2009
Commented:
Add this:

access-list 102 permit udp any any eq bootps

access-list 105 permit udp any eq bootps any

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts

Author

Commented:
Thanks - that did it and I learned something else in the process.  :)  
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.