Solved

DHCP Errors post firewall replacement

Posted on 2013-06-28
6
276 Views
Last Modified: 2013-07-11
Hi

Ideas why i am seeing bad ip addresses in the dhcp servers at our 2nd site?

We have replaced a like for like cisco asa 5505 firewall.

Ideas?
0
Comment
Question by:CHI-LTD
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39284727
0
 
LVL 17

Accepted Solution

by:
TimotiSt earned 250 total points
ID: 39284792
Configuration and firmware version are the same?
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39284840
This hasn't been setup by us, but our managed provider.

I think they copied the config from the old firewall and uploaded.  
Firmware, is newer, i think.
0
Are Your IoT Devices Out to Get You?

IoT business is booming, with manufacturers connecting any and every “thing” to the Internet. But as pressure grows to release new products faster and faster, we’re all left to wonder: is security a priority? Join our webinar on June 29th for the answer.

 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 250 total points
ID: 39284941
If they simply copied config, there might be default config left behind. By default the ASA's have a dhcp server configured so that you can plug in on initial boot and use the ASDM. If a simple copy paste was done, it's unlikely that there was any commands in place to remove the default DHCP server configuration. This could mean that many of your clients are receiving an IP from the firewall, and some from the server. Since the server knows nothing about the firewalls leases, all it can do is reactively mark IP's as BAD_ADDRESS meaning that it's a bad address to hand out via DHCP because a device is already using the address. Have your managed provider check if the ASA is handing out an IP it's not supposed to.

The other check you can do would be to stop the DHCP server service, and try to obtain an IP. If you do you will also see which IP is the DHCP server which can't be your server.
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39289722
Ok, they have removed all dhcp rules settings on the firewall but we are still getting all ips in the scope being taken up with bad ip address...

Clients now not picking up ips...
0
 
LVL 1

Author Closing Comment

by:CHI-LTD
ID: 39317085
Was a leftover dhcp rule and another setting (can't find link now) that caused this.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question