Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

DHCP logging

Hello all,

Is it possible to enable logging to check dhcp stats? I have 252 bindings limit on an asa and would to know if there was a way to get the information of the maximum bindings at any given time on an asa. Also, if there has been a rejected request for an IP address due to the limit being reached?

Thanks,

Arun

5 REPLIES
VIP Green

DHCP logging

I don't believe that the ASA has a DHCP logging specifically for DHCP.  You could set your logging to informational and then each time a client requests and receives and address, or is rejected for that matter, it will be logged.

the down side is that you need to filter the log to get the output you want.

--

Please rate all helpful posts.

-- Please remember to rate and select a correct answer
New Member

DHCP logging

Hello Marius,

Could you provide me with an example on how it would look? I mean a screenshot of the log message?

Thanks,

Arun

VIP Green

DHCP logging

It would look something like this:

%ASA-5-111008: User 'enable_15' executed the 'logging buffered informational' command.

%ASA-5-111010: User 'enable_15', running 'CLI' from IP 0.0.0.0, executed 'logging buffered informational'

%ASA-6-302015: Built inbound UDP connection 1 for inside:0.0.0.0/68 (0.0.0.0/68) to identity:255.255.255.255/67 (255.255.255.255/67)

%ASA-6-302015: Built outbound UDP connection 2 for inside:255.255.255.255/68 (255.255.255.255/68) to identity:10.10.10.1/67 (10.10.10.1/67)

%ASA-6-604103: DHCP daemon interface inside:  address granted 0063.6973.636f.2d63.3230.302e.3064.6638.2e30.3030.302d.4661.302f.30 (10.10.10.10)

%ASA-6-302020: Built outbound ICMP connection for faddr 10.10.10.10/0 gaddr 10.10.10.1/4388 laddr 10.10.10.1/4388

%ASA-6-302021: Teardown ICMP connection for faddr 10.10.10.10/0 gaddr 10.10.10.1/4388 laddr 10.10.10.1/4388

--

Please rate all helpful posts

-- Please remember to rate and select a correct answer
VIP Green

DHCP logging

Although this isn't a log, you can get a good overview of how many addresses have been handed out and/or rejected:

ciscoasa(config)# show dhcpd statistics

DHCP UDP Unreachable Errors: 0

DHCP Other UDP Errors: 0

Address pools        1

Automatic bindings   1

Expired bindings     0

Malformed messages   0

Message              Received

BOOTREQUEST          0

DHCPDISCOVER         1

DHCPREQUEST          1

DHCPDECLINE          0

DHCPRELEASE          0

DHCPINFORM           0

Message              Sent

BOOTREPLY            0

DHCPOFFER            1

DHCPACK              1

DHCPNAK              0

-- Please remember to rate and select a correct answer
Silver

DHCP logging

I would check with SNMP/MIBs on the ASA, but logs don't actually send reports.

Value our effort and rate the assistance!
376
Views
0
Helpful
5
Replies