DHCP pools on ASA 5510/5520

Unanswered Question
May 8th, 2008
User Badges:

Hi. I cant seem to figure out how to have a dhcp pool for inside users that is a different subnet than what the inside interface is.

For example, inside interface is but I want dhcp pool to be Honestly, this is for a customer and I dont know his reasoning behind it, so I cant address that.

I read this document: http://cisco.com/en/US/docs/security/asa/asa71/configuration/guide/ip.html

And it didnt tell me I could or couldnt do it. Am I just missing something?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
JORGE RODRIGUEZ Thu, 05/08/2008 - 13:31
User Badges:
  • Green, 3000 points or more


The way it works at least as I understand it is if a physical interface ip in your scenario is DHCP can be enable in the interface to provide dhcp services for that particular network, that said, if your client wants to have another network routed within the firewall in the case of and have dhcp services it would have to be in a different interface.

The question for you would be does your client already have a subnet with somewhere in the network and wants firewall to be dhcp server for that subnet? if this is the case you cannot create a pool in firewall off the interface to be a different network other than to be within the network.

If your client wants to create another inside network to be routed in the firewall with you could create subinterfaces and use 802.1q trunking, so you could have say as inside1 for sub.interface name with security 100 and another subinterface named inside2 with IP with same sec level of 100 as inside1, then you can have dhcp enabled on the two subinterfaces to service IPs on each subnet.

Now forget all above for a minute, if your client just wanst to change dhcp pool to be then the inside interface ip address have to coinside with dhcp pool so your inside interface must change to then create dhcp pool on interface.

hope this makes sence



mx Fri, 05/09/2008 - 03:19
User Badges:

Thank you Jorge. So it looks like we are on the same page with this. I understand I can have a DHCP pool PER INTERFACE and can be on different subnets, just not different subnets on the same interface. Ill have a conference call with the client at 1:30 to see his reasoning.

Thanks for the verification.


JORGE RODRIGUEZ Fri, 05/09/2008 - 06:07
User Badges:
  • Green, 3000 points or more

Bob, you are welcome.

Indeed, it would be helpful to understand your clients requirements as well as to understand its topology on both firewalls asa5510/asa5520 to see what options there could be based on accurate provided information and be able to assist you better.




This Discussion