Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

DHCP Relay agent on Vlan

Posted on 2010-11-14
8
Medium Priority
?
1,183 Views
Last Modified: 2012-05-10
Hi,

I have a topology as follows:

Router (Relevant sub interfaces for the vlan's  AND dhcp server for each vlan's network)  

CONNECTED TO

Switch(With Multiple VLAN's AND 2 trunks: 1 for AP and 1 for the router))

CONNECTED TO

Access Point (Cisco Aironet, broadcasting multiple SSID's, each assigned to a specific vlan).

Now if I add another vlan (example vlan 66) and want to host the dhcp server for that vlan somewhere else.

How can I tell the AP to send the dhcp requests coming on ssid of vlan 66 and switch ports of vlan 66 to a specific IP and not the router?

Will I still have a sub interface for vlan 66 on the router so clients on vlan 66 can talk to clients on other vlans?

Thanks


How

0
Comment
Question by:masdf123
  • 3
  • 2
  • 2
7 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 1336 total points
ID: 34133710
Yes, you will need a L3 subinterface on the router.
As long as the other DHCP server is connected to a VLAN66 access port and you do not setup DHCP on the router, the clients should get IP addresses no problem. Nothing else to configure.
0
 
LVL 1

Author Comment

by:masdf123
ID: 34133716
so how does it work exactly?

When it doesn't find a dhcp server for that network (the sub interfaces network) it would automatically go to the other dhcp server?

How do I enable L3 on a sub interface?
0
 
LVL 7

Assisted Solution

by:joelvp
joelvp earned 664 total points
ID: 34133926
You create a vlan interface on the router and use the ip helper-address command

So let's assume you're DHCP server has ip address 1.1.1.1 and the subnet for vlan 66 is 192.168.66.0/24

You will create a DHCP scope for subnet 192.168.66.0/24 on the DHCP server (1.1.1.1)

Then on the router, you can instruct the router to relay DHCP messages to this DHCP server for this specific vlan

interface vlan66
ip address 192.168.66.x 255.255.255.0
ip helper-address 1.1.1.1

By the way: by creating a vlan interface (as above) you in essence enable L3 on a subinterface (in switching terminology a subinterface would be called a vlan)

I think this is what you need?

0
NEW Veeam Backup for Microsoft Office 365 1.5

With Office 365, it’s your data and your responsibility to protect it. NEW Veeam Backup for Microsoft Office 365 eliminates the risk of losing access to your Office 365 data.

 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 1336 total points
ID: 34135698
If the DHCP server is in the same subnet as VLAN66, and connected to a switch port in static access vlan 66, there is nothing else to do because a VLAN is a broadcast domain.

If the DHCP server is on a different network, and has a scope for the 66 vlan subnet, then you use ip helper-address on the Vlan66 subinterface to act as a relay.

The L3 interface is the sub-interface with an IP address. This sub-interface IP would be configured as the default-router in the DHCP scope.
0
 
LVL 1

Author Comment

by:masdf123
ID: 34135770
Thanks guys this clarify my question.
0
 
LVL 1

Author Comment

by:masdf123
ID: 34136246
Another question I had was if a person gives himself a static and connect to the vlan 66 switchport...he would have access to the network. Basically vlan 66 has a cilli hotspot with free radius backwnd which also acts as a dhcp server. So after user authenticates chilli spot would replace the client gateway to the ip of vlan 66 sub interface.

So how can I prevent users from statically assigning an ip and connect straight to vlan66.
0
 
LVL 7

Expert Comment

by:joelvp
ID: 34141539
you would need a cisco switch and use a feature called dhcp snooping in combination with ip source guard (ip verify source), but this seems a new question to me, doesn't it?
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question