Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Static DHCP IP to Mac-address reservation in ASA

Hi,

I am finding it difficult to suggest my management for replacing the present Netscreen firewall which ASA as it does the static dhcp ip to mac-address mapping.

Is there any facility where ASA does static DHCP IP to Mac-address reservation in ASA.

I have seen some notes on cisco which states the utilisation of option 61 to specify the client identifier as we do in Cisco routers How can I use this in ASA with DHCPD option.

Can anyone help me doing this and send me a sample configuration if this can be done using ASA.

Regards,

Krissh

24 REPLIES
Bronze

Re: Static DHCP IP to Mac-address reservation in ASA

static dhcp ip to mac-address mapping is not supported in ASA.The listt of features supported by ASA is present in the URL given below:

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/specs.html

The below Url gives the firewall mode guide for the ASA.

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/fwmode.html

New Member

Re: Static DHCP IP to Mac-address reservation in ASA

Actually, you can:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080a7afb2.shtml

The above configuration sample includes both ASDM and CLI config.

Regards,

DL......Please rate the post if it was useful.

New Member

Static DHCP IP to Mac-address reservation in ASA

Hello.

You can't. Your document is about " how to assign static IP address for user who uses VPN" , not how to bind specific IP address from DHCP pool, to the specific MAC address.

New Member

Static DHCP IP to Mac-address reservation in ASA

I was looking around for the same answer when I found what could be a work around.  You can create a static arp entry that should allow the device to get the same IP address everytime. 

You can do this in the ASDM under Device Management -> Advanced -> Arp -> Arp Static Table

Or from the CLI:

arp INSIDE 1.1.1.1 01ac.ac54.dc88

New Member

Static DHCP IP to Mac-address reservation in ASA

Hi!

Does it really works for you? Why ASA should look to the ARP table, when the client is sending DHCP request?

Cisco Employee

Static DHCP IP to Mac-address reservation in ASA

This functionality is currently not supported on the ASA. There is no known way to implement this functionality (The static ARP idea doesn't work, I just tried it in the lab).

An enhancement bug has been filed requesting this support:

CSCsw72963 ASA local address pools should support DHCP reservations/assignments

New Member

I know this post is 3 years

I know this post is 3 years old but has this been included on a recent software version update for the ASA?

Bronze

Nope, still not supported in

Nope, still not supported in 9.2(4), 9.3(3) , 9.4(2), or 9.5(1).  The best work-around IMO is use DHCP relay.  

Considering it's already taken them this long, I have no problem betting $100 that it will never happen.  

New Member

Hi, 

Hi, 

This is the topology.

Users are connecting via AnyConnect VPN and are getting authorized with ISE and AD. Windows DHCP Server is giving dynamically IP addreses. The customer wants to assign static MAC-IP binding in the DHCP Server so they can use the firewall to filter based on the VPN IP addresses.

Internet  ----- ASA ------ LAN --- ISE and Windows DHCP Server.

Can you provide more information how can I assign MAC-IP binding in a Windows DHCP Server through AnyConnect VPN and ISE.

Would it work by just configuring the DHCP relay on the ASA?

Thanks.

New Member

https://bst.cloudapps.cisco

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCsw72963/

does show an update:

Last Modified: Sep 7,2016
Status: Fixed
Severity: 6 Enhancement
will the feature become available in some future releases? - in which versions?
- Marcus
New Member

The detail and config on

The detail and config on using a IPAM type name server using static reservations (and options) is still not crystal clear.  My .org has over 400 mac reservations configured on the DNS ip server.  Are we missing something?

New Member

Cisco are you fking kidding

Cisco are you fking kidding me with this?  Unable to create DHCP reservations?  Come on......

New Member

@Cisco You should be

@Cisco You should be embarrassed about this. How is this still not supported?

Cisco Employee

We absolutely have not

We absolutely have not forgotten about this feature. Stay tuned.

New Member

Configuring DHCP Reservations

Configuring DHCP Reservations for VPN users terminating on ASA 5540 | VPN | Cisco Support Community

We would like to know the solution to this MAC reservation issue? Federal Gov. and compliance network scenarios require this. This is related to this bug also. https://bst.cloudapps.cisco.com/bugsearch/bug/CSCsw72963/?referring_site=bugquickviewredir

My company has purchased 2 ASA 5525-x machines to run remote client vpn services.  We should be able set this. We just asked are premier cisco partner  if there will help us when implementing our ISE project, they have declined. Why is ASA so different then IOS/WLC ?

Posted by u Jay Johnston Cisco 4 years ago

This functionality is currently not supported on the ASA. There is no known way to implement this functionality (The static ARP idea doesn't work, I just tried it in the lab).

An enhancement bug has been filed requesting this support:

CSCsw72963 ASA local address pools should support DHCP reservations/assignments

Is there a remote DHCP workaround? What is the workaround to use IOS or a VPN concentrator ? 

New Member

So what has happened in the

So what has happened in the four years since this shortcoming was pointed out?

New Member

Staying tuned is all fine and

Staying tuned is all fine and good for those who aren't trying to operate a business.  I just had my business partner shell out for three ASAs thinking they'd be adequate, now I find out I can't reserve IPs.  Any update?

-m

New Member

Re: Staying tuned is all fine and

Adding a static ARP entry actually creates an issue as the ASA will not be able to reserve the IP.  When the ASA assigns the supposedly reserved IP address to another device, you will end up with ARP collision. 

Received ARP request collision from 192.168.5.6/aaaa.aaaa.aaaa on interface Inside with existing ARP entry 192.168.5.6/xxxx.xxxx.xxxx

 

 

 

New Member

Re: We absolutely have not

Another YEAR later - perhaps you can update the bugs report at least?  Very disappointed in Cisco, and will never recommend their products again.

New Member

Has someone forgotten about this feature? We are staying tuned.

Still looking for a solution to this problem.

New Member
New Member

What about this?

What about this?

https://www.youtube.com/watch?v=GDwERO0e3zU

 

Bronze

That shows adding a static 

That shows adding a static  ARP entry.  See the post from Jay Johnston below

New Member

Hi all,

Hi all,

Static ARP didn't work on my ASA 5505 with asa924-20-k8.bin (9.2(4)20) even though the command was entered, shows in config, and reboot performed... No success.

This person said he did Static ARP on his 5505 with command alias at the end.

https://cyruslab.net/2014/07/09/adding-static-arp-to-asa5505/

I tried this, cleared ARP, rebooted... No success.

This does look like a bug/flaw on at least the 5505. Online documentations shows it as a feature and ASDM leads you to believe it works as well.

http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/bridgarp.html

http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/about.html

I guess one way to implement the Static ARP / DHCP Reservation on a device where it does work and configure DHCP Relay (if that works!) on the ASA. The feature is available even on old Linksys Wirless G routers that came out in 2003... this does not make you look good Cisco!

-Jason

48890
Views
33
Helpful
24
Replies
CreatePlease to create content