Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » pix 501 and dhcp on the outside interface issue
Search Topic:
Uniqs:
206
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Config] CISCO IOS images »
« [HELP] Cisco 2621xm  
AuthorAll Replies


devicemanage
Premium
join:2002-03-16
Chalfont, PA
·Comcast
·Vonage
·Verizon FIOS

pix 501 and dhcp on the outside interface issue

I have a pix 501 on my residential fios, outside interface set to dhcp, fios in bridge mode. Puts the public ip on my outside interface of the pix. Inside interface is a 10.1.1.1 - next is my router cisco 2611xm outside is 10.1.1.2 and inside is 192.168.100.1 - the 2611 is my dhcp server handing out 192.168.100.x - but for some reason now, i noticed that the outside interface of the pix is picking up a 192.168.100.x address. How can this be? Is there a way I can block dhcp from getting out into the 10x network?
--
»www.devicemanager.net

ladino

join:2001-02-24
USA
Confirm that the mac-address listed listed in the router's assigned DHCP bind pool is that of the PIX. If it is, create an ACL to deny UDP bootpc/bootps on the routers outside interface.


devicemanage
Premium
join:2002-03-16
Chalfont, PA
·Comcast
·Vonage
·Verizon FIOS

Thanks for the reply!

I do not have any pix ip's/mac's in the routers dhcp bindings as the pix is on a completely different subnet (its between my isp's ip and the outside of the 2611xm). Yet the dhcp makes it to the outside of the pix. This makes me nuts but either way the acl should be all that I need?
--
»www.devicemanager.net

ladino

join:2001-02-24
USA

Is this your topology

LAN------(192.168.100.1) 2611XM (10.1.1.2)-------(10.1.1.1) PIX (DHCP)----ISP

Is there a switch between the PIX & the router?
When the PIX gets this 192. address, can LAN clients STILL browse the internet?
Could it be that your ISP is giving out that private IP address in question?


devicemanage
Premium
join:2002-03-16
Chalfont, PA
·Comcast
·Vonage
·Verizon FIOS

Actually made a typo the 192.168.100.1 should be 251 but no biggie. There isn't a switch between the router and the pix.

When the pix gets the 192 addy on the outside we can not browse the net - i dont think that address is coming from my isp as it comes from my dhcp pool which is a pretty specific range.

If I create the acl on the outside of the 2611 - that should do the trick no? Currently the router is only in the equation for the dhcp service and we have battery backup on everything. But in the event the pix should go down, i need to power down the router so the pix can grab the addy from isp, then bring the router online.
--
»www.devicemanager.net

ladino

join:2001-02-24
USA
Yes, the ACL on the 2611 should do the trick


devicemanage
Premium
join:2002-03-16
Chalfont, PA
thank you!
-
Forums » Equipment Support » Hardware By Brand » Cisco[Config] CISCO IOS images »
« [HELP] Cisco 2621xm  


Tuesday, 15-Dec 04:22:28 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [143] Verizon Kindly Forgives Kid's $21,917 3G Bandwidth Bill
· [103] Google To Sell Phone Directly To Consumers
· [73] TiVO Tries To Figure Out Where It Fits
· [55] Faster Verizon DSL Service Will Burn Your House Down
· [47] NY Times: AT&T 3G Network Is Secretly Awesome
· [30] Rural Broadband User? You're Screwed
· [26] Can Satire Take Down AT&T's 3G Network?
· [24] Sweden First To Get LTE Service
· [6] Monday Evening Links
· [1] Monday Morning Links
Most people now reading
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· Official Mediacom Email Discussion Thread [Mediacom]
· personal check etiquette [General Questions]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Lady Deathwhisper Strategy - 3.3 Live [World of Warcraft]
· ICC strats [World of Warcraft]
· What VOIP changes did you make in 2009? [VOIP Tech Chat]
· how to get money back when ripped off [General Questions]