Cisco SG300-28 (L3) DHCP Relay and DHCP Server running?

I've replaced an edge switch (Catalyst) with a SG300-28 switch and it's in Layer 3 mode.  

We simply have (5) VLANs that the switch handles.  

(4) of the VLANs are set for DHCP Relay to my MS DC.   Those are working great.
but...
The last VLAN is our guest wifi network, and I was hoping to serve out DHCP with a generic DNS from the switch itself.  The guest networks do not need to access the other vlans, it should be self sufficient with just getting it's address from the switch.

I'm receiving an error when I attempt to turn the DHCP server on for the switch because it has the relay setup on the other vlans.  

Am I not able to configure relays on 4 of my vlans and then have the switch server addressing on the final vlan at the same time?

Thanks!
LVL 2
irishmic33Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

JustInCaseCommented:
You can configure DHCP as your other networks just ad ACL to deny traffic to any private address space.
Let's say that your wirelles network is in vlan 26

access-list 100 deny ip any 10.0.0.0 0.255.255.255
access-list 100 deny ip any 172.16.0.0 0.15.255.255
access-list 100 deny ip any 192.168.0.0 0.0.255.255
access-list 100 deny ip any 224.0.0.0 15.255.255.255
access-list 100 permit ip any any

# interface vlan 26
# ip access-group 100 in

This will only forward traffic that has public address space as destination address, rest of traffic will be dropped on VLAN interface.
0
irishmic33Author Commented:
The trouble isn't at the ACL.   But I agree that's a must for security.

My issue is I'm unable to enable the switch's DHCP server option if I have the DHCP Relay assigned on the (4) VLANs.

When I check the "enable" checkbox to engage the DHCP server there is a warning:
"Cannot enable DHCP server when relay is enabled."

8-5-2015-9-08-54-PM.png
0
JustInCaseCommented:
Yes, you can't enable DHCP server while DHCP proxy is in use.
You can either create DHCP pool for that network on DC since you can't enable DHCP server on switch, or disable DHCP relay, enable DHCP server on switch and on VLAN interfaces you can create ip helper-address to point to DC as DHCP server for those 4 VLANs, and then wireless VLAN clients can get IP address from (no ip helper-address on VLAN interface that will point to DC).
0
How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

Benjamin Van DitmarsCommented:
Dont apply an ip address to the vlan. and let the firewall/router do this. also add in youre firewall/router acl's to block traffic from and to youre guest network. then youre secure
0
irishmic33Author Commented:
Sorry for abandoning...
The solutions offered are good, but I just replaced the 300 with my old catalyst.  I couldn't afford further delays.  

In my limited knowledge of the 300 series, it seemed to be a functionality that I couldn't get to work.  I have experience with catalysts (3560) and I was able to get the configuration right on the first try.

Possibly a verbiage issue between the two OS.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
irishmic33Author Commented:
Stated above
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Architecture

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.