Solved

DHCP Errors post firewall replacement

Posted on 2013-06-28
6
275 Views
Last Modified: 2013-07-11
Hi

Ideas why i am seeing bad ip addresses in the dhcp servers at our 2nd site?

We have replaced a like for like cisco asa 5505 firewall.

Ideas?
0
Comment
Question by:CHI-LTD
  • 4
6 Comments
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39284727
0
 
LVL 17

Accepted Solution

by:
TimotiSt earned 250 total points
ID: 39284792
Configuration and firmware version are the same?
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39284840
This hasn't been setup by us, but our managed provider.

I think they copied the config from the old firewall and uploaded.  
Firmware, is newer, i think.
0
Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

 
LVL 20

Assisted Solution

by:rauenpc
rauenpc earned 250 total points
ID: 39284941
If they simply copied config, there might be default config left behind. By default the ASA's have a dhcp server configured so that you can plug in on initial boot and use the ASDM. If a simple copy paste was done, it's unlikely that there was any commands in place to remove the default DHCP server configuration. This could mean that many of your clients are receiving an IP from the firewall, and some from the server. Since the server knows nothing about the firewalls leases, all it can do is reactively mark IP's as BAD_ADDRESS meaning that it's a bad address to hand out via DHCP because a device is already using the address. Have your managed provider check if the ASA is handing out an IP it's not supposed to.

The other check you can do would be to stop the DHCP server service, and try to obtain an IP. If you do you will also see which IP is the DHCP server which can't be your server.
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 39289722
Ok, they have removed all dhcp rules settings on the firewall but we are still getting all ips in the scope being taken up with bad ip address...

Clients now not picking up ips...
0
 
LVL 1

Author Closing Comment

by:CHI-LTD
ID: 39317085
Was a leftover dhcp rule and another setting (can't find link now) that caused this.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ip igmp join-group 8 73
Cisco Edge Routers for BGP 6 95
Upgrading from Sonicwall Tz210 6 37
CISCO wireless controller & AP 2 40
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question