Cisco 851 router won't get/give DHCP address with firewall on

Posted on 2009-02-17
Last Modified: 2013-11-16
With the help of someone here I've mostly gotten our Cisco 851 router going, but I still have one issue.   If I enable my access-lists, our Cisco 851 router will not obtain a DHCP address from our service provider, nor will it successfully give out any DHCP addresses to local clients.    All I need to do to make both of these work is to remove the "ip access-list 105 in" and "ip access-list 102 in" lines from FastEthernet4 and Vlan1 respectively.   But then of course I don't have a firewall.  

For reference, we have a simple setup with simple requirements -- internet is provided via a cable modem and we just want to have basic firewall features (i.e. any connections initiated from the inside gets out, no connections initiated from the outside get in).   Only exceptions are whatever may be required for typical internet usage.  

I've attached my current config, but the relevent access-lists are below:

access-list 102 permit tcp any
access-list 102 permit udp any
access-list 102 permit icmp any
access-list 102 deny   ip any any log
access-list 105 permit icmp any any
access-list 105 deny   ip any any log

Surely I must be missing something since enabling the access lists prevents the router from getting or giving out DHCP addresses, but what could it be?   Note that when this problem occurs, "show log" does not reveal the answer, to me anyway.  :)  

Thanks so much for any and all assistance!  
Question by:izgoblin
    LVL 43

    Accepted Solution

    Add this:

    access-list 102 permit udp any any eq bootps

    access-list 105 permit udp any eq bootps any

    Author Closing Comment

    Thanks - that did it and I learned something else in the process.  :)  

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
    Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    9 Experts available now in Live!

    Get 1:1 Help Now