Jeff,

> -----Original Message-----
> From: [email protected] [mailto:cisco-nsp-
> [email protected]] On Behalf Of Jeff Kell
> Sent: Thursday, September 02, 2010 10:21 AM
> To: cisco-nsp
> Subject: [c-nsp] Relaying DHCP through small remote VPN (ASA 5505)...
> 
>  Have a remote setup w/ASA 5505... essentially setting up a site-to-site
> tunnel and routing a local inside subnet back to the main campus.  (Default
> inside route part of crypto-map match so all traffic is tunneled).
> 
> Everything is working, but I'm less than excited about the 5505s DHCP
> abilities, would rather have the remote addressing managed by our central
> server.
> 
> If I enable "DHCP relay" on the inside interface, it insists that the DHCP 
> server
> target is "not" on the inside interface.  If I direct it to the outside 
> interface, it
> doesn't go over the tunnel and gets dropped.  If I try to specify the relay
> target on the inside interface, it gives an error that it can't reside on an
> interface where relay is enabled.
> 
> I suspect I need an outside route that also tunnels?
> 

I think you'll need to another line to your interesting traffic ACL for the 
public address of the firewall to inside address of your DHCP server.  Have you 
tried adding 'management-access inside' and see if you still get the DHCP 
target error?

-ryan

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to