Solved

DHCP Relay agent on Vlan

Posted on 2010-11-14
8
1,154 Views
Last Modified: 2012-05-10
Hi,

I have a topology as follows:

Router (Relevant sub interfaces for the vlan's  AND dhcp server for each vlan's network)  

CONNECTED TO

Switch(With Multiple VLAN's AND 2 trunks: 1 for AP and 1 for the router))

CONNECTED TO

Access Point (Cisco Aironet, broadcasting multiple SSID's, each assigned to a specific vlan).

Now if I add another vlan (example vlan 66) and want to host the dhcp server for that vlan somewhere else.

How can I tell the AP to send the dhcp requests coming on ssid of vlan 66 and switch ports of vlan 66 to a specific IP and not the router?

Will I still have a sub interface for vlan 66 on the router so clients on vlan 66 can talk to clients on other vlans?

Thanks


How

0
Comment
Question by:masdf123
  • 3
  • 2
  • 2
8 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 334 total points
Comment Utility
Yes, you will need a L3 subinterface on the router.
As long as the other DHCP server is connected to a VLAN66 access port and you do not setup DHCP on the router, the clients should get IP addresses no problem. Nothing else to configure.
0
 
LVL 1

Author Comment

by:masdf123
Comment Utility
so how does it work exactly?

When it doesn't find a dhcp server for that network (the sub interfaces network) it would automatically go to the other dhcp server?

How do I enable L3 on a sub interface?
0
 
LVL 7

Assisted Solution

by:joelvp
joelvp earned 166 total points
Comment Utility
You create a vlan interface on the router and use the ip helper-address command

So let's assume you're DHCP server has ip address 1.1.1.1 and the subnet for vlan 66 is 192.168.66.0/24

You will create a DHCP scope for subnet 192.168.66.0/24 on the DHCP server (1.1.1.1)

Then on the router, you can instruct the router to relay DHCP messages to this DHCP server for this specific vlan

interface vlan66
ip address 192.168.66.x 255.255.255.0
ip helper-address 1.1.1.1

By the way: by creating a vlan interface (as above) you in essence enable L3 on a subinterface (in switching terminology a subinterface would be called a vlan)

I think this is what you need?

0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 334 total points
Comment Utility
If the DHCP server is in the same subnet as VLAN66, and connected to a switch port in static access vlan 66, there is nothing else to do because a VLAN is a broadcast domain.

If the DHCP server is on a different network, and has a scope for the 66 vlan subnet, then you use ip helper-address on the Vlan66 subinterface to act as a relay.

The L3 interface is the sub-interface with an IP address. This sub-interface IP would be configured as the default-router in the DHCP scope.
0
 
LVL 1

Author Comment

by:masdf123
Comment Utility
Thanks guys this clarify my question.
0
 
LVL 1

Author Comment

by:masdf123
Comment Utility
Another question I had was if a person gives himself a static and connect to the vlan 66 switchport...he would have access to the network. Basically vlan 66 has a cilli hotspot with free radius backwnd which also acts as a dhcp server. So after user authenticates chilli spot would replace the client gateway to the ip of vlan 66 sub interface.

So how can I prevent users from statically assigning an ip and connect straight to vlan66.
0
 
LVL 7

Expert Comment

by:joelvp
Comment Utility
you would need a cisco switch and use a feature called dhcp snooping in combination with ip source guard (ip verify source), but this seems a new question to me, doesn't it?
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now