Solved

DHCP Errors post firewall replacement

Posted on 2013-06-28
6
272 Views
Last Modified: 2013-07-11
Hi

Ideas why i am seeing bad ip addresses in the dhcp servers at our 2nd site?

We have replaced a like for like cisco asa 5505 firewall.

Ideas?
0
Comment
Question by:CHI-LTD
  • 4
6 Comments
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39284727
0
 
LVL 17

Accepted Solution

by:
TimotiSt earned 250 total points
ID: 39284792
Configuration and firmware version are the same?
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39284840
This hasn't been setup by us, but our managed provider.

I think they copied the config from the old firewall and uploaded.  
Firmware, is newer, i think.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 250 total points
ID: 39284941
If they simply copied config, there might be default config left behind. By default the ASA's have a dhcp server configured so that you can plug in on initial boot and use the ASDM. If a simple copy paste was done, it's unlikely that there was any commands in place to remove the default DHCP server configuration. This could mean that many of your clients are receiving an IP from the firewall, and some from the server. Since the server knows nothing about the firewalls leases, all it can do is reactively mark IP's as BAD_ADDRESS meaning that it's a bad address to hand out via DHCP because a device is already using the address. Have your managed provider check if the ASA is handing out an IP it's not supposed to.

The other check you can do would be to stop the DHCP server service, and try to obtain an IP. If you do you will also see which IP is the DHCP server which can't be your server.
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39289722
Ok, they have removed all dhcp rules settings on the firewall but we are still getting all ips in the scope being taken up with bad ip address...

Clients now not picking up ips...
0
 
LVL 1

Author Closing Comment

by:CHI-LTD
ID: 39317085
Was a leftover dhcp rule and another setting (can't find link now) that caused this.
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
I designed this idea while studying technology in the classroom.  This is a semester long project.  Students are asked to take photographs on a specific topic which they find meaningful, it can be a place or situation such as travel or homelessness.…
Need to grow your business through quality cloud solutions? With everything required to build a cloud platform and solution, you may feel like the distance between you and the cloud is quite long. Help is here. Spend some time learning about the Con…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now