<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems in Cisco</title>
<link>http://www.dslreports.com/forum/r20931986</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 03:29:58 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 03:29:58 EDT</lastBuildDate>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,21009007</link>
<description><![CDATA[<A HREF="/useremail/u/1327804"><b>mr_dirt</b></A> : <div class="bquote"><small>said by  hoover87 <A HREF="/useremail/u/1574525"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>You may want to try the latest 124-15.XZ code as it usually has more bug fixes than the mainline releases.<br></div>12.4(15)XZ was released before 12.4(20)T, at a time when the infrastructure under (20)T FW was still in development.  You'll have bigger problems than DHCP not working if you load (15)XZ (CSCsm15782).<br><br>Marko, sorry I haven't replied.  I've had my hands full.  Give me a little time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21009007</guid>
<pubDate>Tue, 26 Aug 2008 11:55:56 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,21008463</link>
<description><![CDATA[<A HREF="/useremail/u/1574525"><b>hoover87</b></A> : You may want to try the latest 124-15.XZ code as it usually has more bug fixes than the mainline releases.<br><small>--<br>&raquo;<A HREF="http://www.ketchumits.com" >www.ketchumits.com</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21008463</guid>
<pubDate>Tue, 26 Aug 2008 10:07:53 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,21007786</link>
<description><![CDATA[<A HREF="/useremail/u/797898"><b>mocah</b></A> : I was testing config over a weekend. Unfortunately I still did not find solution how to allow DHCP traffic.<br>Firewall is reporting following:<br><textarea name="code" class="text" cols=50 rows=10>FW-6-LOG_SUMMARY: 3 packets were dropped from 0.0.0.0:68 =&gt; 255.255.255.255:67 (target:class)-(LAN2Self:class-default)&#012;</textarea><!--end code block--><br>Also I noticed that ARP table is not showing clients with dynamic IP addres, only static ones.<br><br>Thank you and kind regards,M<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21007786</guid>
<pubDate>Tue, 26 Aug 2008 03:56:41 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20938078</link>
<description><![CDATA[<A HREF="/useremail/u/797898"><b>mocah</b></A> : I have the same problem on Cisco 871. Because the config on Cisco 871 is simpler I will post that config:<br><br><textarea name="code" class="text" cols=50 rows=10>C871#sh run&#012;Building configuration...&#012; &#012;Current configuration : 8659 bytes&#012;!&#012;version 12.4&#012;no service pad&#012;service tcp-keepalives-in&#012;service tcp-keepalives-out&#012;service timestamps debug datetime msec localtime show-timezone&#012;service timestamps log datetime msec localtime show-timezone&#012;service password-encryption&#012;service sequence-numbers&#012;!&#012;hostname C871&#012;!&#012;boot-start-marker&#012;boot-end-marker&#012;!&#012;security authentication failure rate 2 log&#012;security passwords min-length 10&#012;logging message-counter syslog&#012;no logging console&#012;enable secret 5 $&#012;!&#012;aaa new-model&#012;!&#012;!&#012;!&#012;!&#012;aaa session-id common&#012;clock timezone CET 1&#012;clock summer-time CET recurring last Sun Mar 2:00 last Sun Oct 3:00&#012;!&#012;crypto pki trustpoint TP-self-signed-2100979184&#012; enrollment selfsigned&#012; subject-name cn=IOS-Self-Signed-Certificate-2100979184&#012; revocation-check none&#012; rsakeypair TP-self-signed-2100979184&#012;!&#012;!&#012;crypto pki certificate chain TP-self-signed-2100979184&#012; certificate self-signed 01&#012;  30820248 308201B1 A0030201 02020101 300D0609 2A864886 F70D0101 04050030&#012;  5BAA36E2 2F597053 33C8C451&#012;        quit&#012;dot11 syslog&#012;no ip source-route&#012;!&#012;!&#012;no ip dhcp use vrf connected&#012;no ip dhcp conflict logging&#012;ip dhcp excluded-address 192.168.1.1 192.168.1.5&#012;!&#012;ip dhcp pool VLAN1&#012;   import all&#012;   network 192.168.1.0 255.255.255.0&#012;   default-router 192.168.1.1&#012;   dns-server xxx.xxx.xxx.13 xxx.xxx.xxx.23&#012;   lease 7 7 7&#012;!&#012;!&#012;ip cef&#012;no ip bootp server&#012;no ip domain lookup&#012;ip domain name koli.net&#012;ip port-map http port tcp 8080&#012;login block-for 305 attempts 2 within 100&#012;!&#012;no ipv6 cef&#012;multilink bundle-name authenticated&#012;!&#012;password encryption aes&#012;!&#012;!&#012;username mogul privilege 15 secret 5 $1$xpjH$q&#012; &#012;!&#012;!&#012;!&#012;archive&#012; log config&#012;  hidekeys&#012;!&#012;!&#012;ip ssh authentication-retries 2&#012;ip ssh logging events&#012;ip ssh version 2&#012;!&#012;class-map type inspect match-any p2p-cmap&#012; match protocol bittorrent&#012; match protocol bittorrent signature&#012;class-map type inspect match-any Internet-cmap&#012; match protocol http&#012; match protocol https&#012; match protocol ssh&#012; match protocol ftp&#012; match protocol ftps&#012; match protocol icmp&#012; match protocol pop3s&#012; match protocol bittorrent&#012; match protocol bittorrent signature&#012;class-map type inspect match-any ISPtraffic&#012; match protocol dns&#012; match protocol pop3&#012; match protocol smtp extended&#012; match protocol ntp&#012;class-map type inspect match-all ISPtraffic-cmap&#012; match access-group name ISPtraffic&#012; match class-map ISPtraffic&#012;class-map type inspect match-all PING-cmap&#012; match access-group name ICMP&#012;class-map type inspect match-all TIME-cmap&#012; match access-group name TIME&#012;class-map type inspect match-all RouterManagement-cmap&#012; match access-group name RouterManagement&#012;class-map type inspect match-all DHCP-cmap&#012; match access-group name DHCP&#012;class-map type inspect match-all SSHaccess-cmap&#012; match access-group name SSHaccess&#012;!&#012;!&#012;policy-map type inspect Inside2Router-pmap&#012; class type inspect RouterManagement-cmap&#012;  inspect&#012; class type inspect PING-cmap&#012;  inspect&#012; class type inspect DHCP-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;policy-map type inspect Router2Inside-pmap&#012; class type inspect RouterManagement-cmap&#012;  inspect&#012; class type inspect PING-cmap&#012;  inspect&#012; class type inspect DHCP-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;policy-map type inspect Outside2Router-pmap&#012; class type inspect SSHaccess-cmap&#012;  inspect&#012; class type inspect PING-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;policy-map type inspect Router2Outside-pmap&#012; class type inspect SSHaccess-cmap&#012;  inspect&#012; class type inspect PING-cmap&#012;  inspect&#012; class type inspect TIME-cmap&#012;  inspect&#012;policy-map type inspect Inside2Outside-pmap&#012; class type inspect Internet-cmap&#012;  inspect&#012; class type inspect ISPtraffic-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;policy-map type inspect Outside2Inside-pmap&#012; class type inspect p2p-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;!&#012;zone security Private&#012; description LAN&#012;zone security WAN&#012; description WAN&#012;zone security DMZ&#012; description DMZ&#012;zone-pair security Inside2Outside source Private destination WAN&#012; service-policy type inspect Inside2Outside-pmap&#012;zone-pair security Outside2Router source WAN destination self&#012; service-policy type inspect Outside2Router-pmap&#012;zone-pair security Router2Outside source self destination WAN&#012; service-policy type inspect Outside2Router-pmap&#012;zone-pair security Lan2Router source Private destination self&#012; service-policy type inspect Inside2Router-pmap&#012;zone-pair security Router2Lan source self destination Private&#012; service-policy type inspect Router2Inside-pmap&#012;zone-pair security Outside2Inside source WAN destination Private&#012; description Za p2p protocol bittorent&#012; service-policy type inspect Outside2Inside-pmap&#012;!&#012;!&#012;!&#012;interface FastEthernet0&#012;!&#012;interface FastEthernet1&#012;!&#012;interface FastEthernet2&#012;!&#012;interface FastEthernet3&#012;!&#012;interface FastEthernet4&#012; description $ETH-WAN$&#012; no ip address&#012; no ip unreachables&#012; zone-member security WAN&#012; duplex auto&#012; speed auto&#012; pppoe enable group global&#012; pppoe-client dial-pool-number 1&#012;!&#012;interface Vlan1&#012; description Local LAN&#012; ip address 192.168.1.1 255.255.255.0&#012; ip nat inside&#012; ip virtual-reassembly&#012; zone-member security Private&#012; ip tcp adjust-mss 1452&#012;!&#012;interface Dialer1&#012; description IP address xxx.xxx.xxx.xxx&#012; ip address negotiated&#012; no ip unreachables&#012; ip mtu 1492&#012; ip nat outside&#012; ip virtual-reassembly&#012; zone-member security WAN&#012; encapsulation ppp&#012; dialer pool 1&#012; dialer-group 1&#012; no cdp enable&#012; ppp authentication chap callin&#012; ppp chap hostname username12&#012; ppp chap password 7 0118423346756343&#012;!&#012;interface Dialer0&#012; no ip address&#012; no cdp enable&#012;!&#012;ip forward-protocol nd&#012;ip route 0.0.0.0 0.0.0.0 Dialer1&#012;no ip http server&#012;no ip http secure-server&#012;!&#012;!&#012;ip nat inside source list 1 interface Dialer1 overload&#012;ip nat inside source static udp 192.168.1.10 6885 interface Dialer1 6885&#012;ip nat inside source static tcp 192.168.1.10 6881 interface Dialer1 6881&#012;ip nat inside source static tcp 192.168.1.10 6882 interface Dialer1 6882&#012;ip nat inside source static tcp 192.168.1.10 6883 interface Dialer1 6883&#012;ip nat inside source static tcp 192.168.1.10 6884 interface Dialer1 6884&#012;ip nat inside source static tcp 192.168.1.10 6885 interface Dialer1 6885&#012;ip nat inside source static tcp 192.168.1.10 6886 interface Dialer1 6886&#012;ip nat inside source static tcp 192.168.1.10 6887 interface Dialer1 6887&#012;ip nat inside source static tcp 192.168.1.10 6888 interface Dialer1 6888&#012;ip nat inside source static tcp 192.168.1.10 6889 interface Dialer1 6889&#012;!&#012;ip access-list extended DHCP&#012; permit udp any any eq bootps&#012; permit udp any any eq bootpc&#012;ip access-list extended ICMP&#012; permit icmp any any echo&#012; permit icmp any any echo-reply&#012; permit icmp any any traceroute&#012; permit icmp any any host-unreachable&#012; permit icmp any any packet-too-big&#012; deny   icmp any any fragments&#012;ip access-list extended ISPtraffic&#012; permit udp any host xxx.xxx.160.13 eq domain&#012; permit udp any host xxx.xxx.160.23 eq domain&#012; permit tcp any any eq pop3&#012; permit tcp any any eq smtp&#012;ip access-list extended RouterManagement&#012; permit tcp any any eq 22&#012; permit tcp any any eq 443&#012;ip access-list extended SSHaccess&#012; permit tcp any any eq 22&#012;ip access-list extended TIME&#012; permit udp any any eq ntp&#012;!&#012;access-list 1 remark Access List for Dialer 1&#012;access-list 1 permit 192.168.1.0 0.0.0.255&#012;dialer-list 1 protocol ip permit&#012;no cdp run&#012; &#012;!&#012;!&#012;!&#012;!&#012;!&#012;control-plane&#012;!&#012;!&#012;line con 0&#012; no modem enable&#012;line aux 0&#012;line vty 0 4&#012; transport input ssh&#012; transport output ssh&#012;!&#012;scheduler max-task-time 5000&#012;ntp server xxx.xxx.xxx.xxx&#012;end&#012; &#012;C871#&#012; &#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20938078</guid>
<pubDate>Tue, 12 Aug 2008 09:54:09 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20934968</link>
<description><![CDATA[<A HREF="/useremail/u/1327804"><b>mr_dirt</b></A> : Can you post your revised configuration, please?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20934968</guid>
<pubDate>Mon, 11 Aug 2008 17:25:22 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20931986</link>
<description><![CDATA[<A HREF="/useremail/u/797898"><b>mocah</b></A> : I opened (with ACL) ports UDP 67 and 68 to and from Self zone. Unfortunately clients still do not get IP address from server.<br><br>Any other way to allow DHCP traffic from Self zone to "private" one?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20931986</guid>
<pubDate>Mon, 11 Aug 2008 04:46:22 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20806271</link>
<description><![CDATA[<A HREF="/useremail/u/1327804"><b>mr_dirt</b></A> : Thanks for posting your config.  If anything, I suspect that 12.4(20)T fixed a problem that you were relying on being broken.  ;)<br><br>Unless I'm mistaken, your configuration makes no allowance for bootp/dhcp client requests to the router's dhcp server.  In the past, I suspect that dhcp requests were following a code path that didn't call the firewall.  With the changes to the FW (need to locate a doc that describes the changes), the FW gets better control over the various router-local capabilities, including, apparently, the DHCP interaction.<br><br>If you add inspection or pass for the dhcp traffic in one of the class-maps in your 'Vlan2Self-pmap', this should sort this out.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20806271</guid>
<pubDate>Thu, 17 Jul 2008 13:28:02 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20804198</link>
<description><![CDATA[<A HREF="/useremail/u/797898"><b>mocah</b></A> : Here is config:<br><textarea name="code" class="text" cols=50 rows=10> &#012;dot11 syslog&#012;ip source-route&#012;!&#012;!&#012;no ip dhcp use vrf connected&#012;!&#012;ip dhcp pool computers2&#012;   import all&#012;   network 192.168.22.16 255.255.255.240&#012;   default-router 192.168.250.17&#012;   dns-server xxx.xxx.209.77 xxx.xxx.210.77&#012;   domain-name nx.com&#012;   lease 7 7 7&#012;!&#012;!&#012;ip cef&#012;ip domain name C1&#012;ip port-map http port tcp 8080&#012;login block-for 305 attempts 2 within 20&#012;!&#012;no ipv6 cef&#012;multilink bundle-name authenticated&#012;!&#012;!&#012;!&#012;username krenn privilege 15 secret 5 $&#012;!&#012;!&#012;archive&#012; log config&#012;  hidekeys&#012;!&#012;!&#012;ip ssh authentication-retries 2&#012;ip ssh version 2&#012;!&#012;class-map type inspect match-any Management-cmap&#012; match access-group name Management&#012;class-map type inspect match-all Time-cmap&#012; match access-group name TIMEserver&#012; match protocol ntp&#012;class-map type inspect match-any Internet-cmap&#012; match protocol dns&#012; match protocol http&#012; match protocol https&#012; match protocol ssh&#012; match protocol ftp&#012; match protocol pop3&#012; match protocol pop3s&#012; match protocol smtp extended&#012;class-map type inspect match-all ICMP2-cmap&#012; match protocol icmp&#012; match access-group name ICMP&#012;class-map type inspect match-all TIMEaccess-cmap&#012; match access-group name TIMEserver&#012;class-map type inspect match-all ICMP-cmap&#012; match access-group name ICMP&#012;class-map type inspect match-all SSHaccess-cmap&#012; match access-group name SSHaccess&#012;!&#012;!&#012;policy-map type inspect Internet-cmap&#012; class type inspect Time-cmap&#012;  inspect&#012;policy-map type inspect Vlan2Self-pmap&#012; class type inspect SSHaccess-cmap&#012;  inspect&#012; class type inspect ICMP-cmap&#012;  inspect&#012; class type inspect Management-cmap&#012;  inspect&#012; class type inspect TIMEaccess-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;policy-map type inspect Internet-pmap&#012; class type inspect Internet-cmap&#012;  inspect&#012; class type inspect ICMP2-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;policy-map type inspect Outside2Router-pmap&#012; class type inspect SSHaccess-cmap&#012;  inspect&#012; class type inspect ICMP-cmap&#012;  inspect&#012; class class-default&#012;  drop&#012;!&#012;zone security WAN&#012; description WAN FE0&#012;zone security DMZ&#012; description Port to ASA5505 FE1&#012;zone security VLAN1&#012; description Link to Cisco 1712&#012;zone security private&#012; description Link to Computers&#012;zone-pair security Outside2Router source WAN destination self&#012; service-policy type inspect Outside2Router-pmap&#012;zone-pair security Vlan2Self source private destination self&#012; service-policy type inspect Vlan2Self-pmap&#012;zone-pair security Self2Vlan source self destination private&#012; service-policy type inspect Vlan2Self-pmap&#012;zone-pair security Self2Vlan1 source self destination VLAN1&#012; service-policy type inspect Vlan2Self-pmap&#012;zone-pair security Vlan1toSelf source VLAN1 destination self&#012; service-policy type inspect Vlan2Self-pmap&#012;zone-pair security Computers2DMZ source private destination DMZ&#012; service-policy type inspect Internet-pmap&#012;zone-pair security Vlan1-2-DMZ source VLAN1 destination DMZ&#012; service-policy type inspect Internet-pmap&#012;zone-pair security Vlan1-2-Vlan3 source VLAN1 destination private&#012; service-policy type inspect Internet-pmap&#012;zone-pair security Vlan3-2Vlan1 source private destination VLAN1&#012; service-policy type inspect Internet-pmap&#012;zone-pair security DMZ2Self source DMZ destination self&#012; service-policy type inspect Vlan2Self-pmap&#012;zone-pair security Self2DMZ source self destination DMZ&#012; service-policy type inspect Vlan2Self-pmap&#012;zone-pair security Self2outside source self destination WAN&#012; service-policy type inspect Outside2Router-pmap&#012;!&#012;!&#012;!&#012;interface FastEthernet0&#012; description WAN interface&#012; ip address xxx.xxx.xxx.184 255.255.0.0&#012; zone-member security WAN&#012; duplex auto&#012; speed auto&#012;!&#012;interface FastEthernet1&#012; description Link to ASA5505 DMZ&#012; ip address 192.168.24.2 255.255.255.240&#012; zone-member security DMZ&#012; duplex auto&#012; speed auto&#012;!&#012;interface BRI0&#012; no ip address&#012; encapsulation hdlc&#012; shutdown&#012;!&#012;interface FastEthernet2&#012; description Computer link&#012; switchport access vlan 3&#012;!&#012;interface FastEthernet3&#012; description Computer link&#012; switchport access vlan 3&#012;!&#012;interface FastEthernet4&#012; description Computer link&#012; switchport access vlan 3&#012;!&#012;interface FastEthernet5&#012; description Computer link&#012; switchport access vlan 3&#012;!&#012;interface FastEthernet6&#012; description not assignet yet&#012;!&#012;interface FastEthernet7&#012; description not assignet yet&#012;!&#012;interface FastEthernet8&#012; description not assignet yet&#012;!&#012;interface FastEthernet9&#012; description DMZ zone&#012;!&#012;interface Vlan1&#012; description Link to Cisco 1712&#012; ip address 192.168.22.33 255.255.255.252&#012; zone-member security VLAN1&#012;!&#012;interface Vlan3&#012; description Interfaces to Computers&#012; ip address 192.168.22.17 255.255.255.240&#012; zone-member security private&#012;!&#012;ip forward-protocol nd&#012;ip route 0.0.0.0 0.0.0.0 192.168.24.1&#012;no ip http server&#012;no ip http secure-server&#012;!&#012;!&#012;!&#012;ip access-list extended ICMP&#012; permit icmp any any echo&#012; permit icmp any any echo-reply&#012; permit icmp any any traceroute&#012; permit icmp any any host-unreachable&#012;ip access-list extended Management&#012; permit tcp any any eq 443&#012;ip access-list extended SSHaccess&#012; permit tcp any any eq 22&#012;ip access-list extended TIMEserver&#012; permit udp any any eq ntp&#012;!&#012;!&#012;!&#012;!&#012;!&#012;!&#012;!&#012;!&#012;control-plane&#012;!&#012;!&#012;line con 0&#012; exec-timeout 200 0&#012; password 7 0602002F4230FA93&#012;line aux 0&#012;line vty 0 4&#012; transport input ssh&#012; transport output ssh&#012;!&#012;ntp server xxx.xxx.xxx.66&#012;</textarea><!--end code block--><br>I am going to vacation for 14 days so I wont be able to reply.<br><br>Thank you and kind regards,M<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20804198</guid>
<pubDate>Thu, 17 Jul 2008 02:51:39 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20801350</link>
<description><![CDATA[<A HREF="/useremail/u/797898"><b>mocah</b></A> : I have used the same configuration for at least 6 months. The only way that I can use DHCP server from router is if I disable ZBF. Currently I can not access router but I will post config tomorrow.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20801350</guid>
<pubDate>Wed, 16 Jul 2008 16:02:25 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20800573</link>
<description><![CDATA[<A HREF="/useremail/u/1327804"><b>mr_dirt</b></A> : <div class="bquote"><small>said by  mocah <A HREF="/useremail/u/797898"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Hi,<br>After upgrade DHCP server stoped working if Zone Based Firewall is configured on interfaces<br></div>Did the same firewall policy work prior to the upgrade?<br><br>12.4(20)T introduces a new firewall infrastructure, so there are probably a lot of corner cases that aren't fully tested.  It look like you found one.   :p<br><br>Any chance you post the policy-maps, class-maps, and zone-pair configuration between the zone where DHCP fails, and the self zone?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20800573</guid>
<pubDate>Wed, 16 Jul 2008 13:45:35 EDT</pubDate>
</item>

<item>
<title>Re: IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20799308</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : There are probably something on the Zone-Based Firewall configuration that prevent the DHCP mechanism to work. Did you  run packet tracer and troubleshoot further to find out which configuration part that prevent the DHCP mechanism to work?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20799308</guid>
<pubDate>Wed, 16 Jul 2008 09:54:06 EDT</pubDate>
</item>

<item>
<title>IOS 12.4(20) ZBF - DHCP server problems</title>
<link>http://www.dslreports.com/forum/remark,20798575</link>
<description><![CDATA[<A HREF="/useremail/u/797898"><b>mocah</b></A> : Hi,<br><br>recently I have installed new IOS 12.4(20) on Cisco 1812. After upgrade DHCP server stoped working if Zone Based Firewall is configured on interfaces if ZBF is not configured on interfaces than DHCP server is works.<br>Does any body have similar problem?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20798575</guid>
<pubDate>Wed, 16 Jul 2008 03:41:23 EDT</pubDate>
</item>

</channel>
</rss>
