cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4159
Views
0
Helpful
4
Replies

Can a ASA 5520 assign multiple DHCP scopes?

scottbob09
Level 1
Level 1

I am setting up a ASA to be a VPN box/router to connect to a remote hub site. This end has a few vlans/IP networks associated with it and the network is not flat. Can I use subinterfaces to somehow make the ASA give out addresses on 3 different IP networks (and dhcp pools) on this end of the tunnel? I was at first thinking I could trunk in the 2 vlans that are "nearby" and handle those that way, but the 3rd _routed_ network on the other side of campus may be more difficult. I know how IP helpers work, but I guess I'm not entirely sure how to make the ASA realize what network the DHCP_request if coming from and which pool to assign it out of.

Scott

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

Scott

You can have multiple pools but the clients must be on a directly attached network so the trunked 2 vlans would be fine but not the 3rd routed network.

Also even though you can have multiple IP pools, settings such as DNS server, domain name etc. are configured globally altho this may not be an issue for you -

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1058874

Jon

View solution in original post

4 Replies 4

Jon Marshall
Hall of Fame
Hall of Fame

Scott

You can have multiple pools but the clients must be on a directly attached network so the trunked 2 vlans would be fine but not the 3rd routed network.

Also even though you can have multiple IP pools, settings such as DNS server, domain name etc. are configured globally altho this may not be an issue for you -

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1058874

Jon

Right....

So the router (option 3) would be a problem.

humph

Yes it would.

Not ideal but for the 3rd network could you not just use the router to hand out IP's.

Jon

Yeah I was just thinking I could use the 6509 up there to hand them out. Not something we typically do, but it could be just fine. Of course since there is just going to be 1 phone and 1 PC piggybacked up there, I can just do static and KISS. :)

Scott

Review Cisco Networking products for a $25 gift card