
4-21
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 4 Using PIX Firewall in SOHO Networks
Using DHCP Relay
Note With PIX Firewall Version 6.2 and lower, the DHCP server can only be enabled on the inside interface
and therefore can only respond to DHCP option 150 and 66 requests from Cisco IP Phones or other
network devices on the internal network. With PIX
Firewall Version 6.3 and higher, the DHCP server
can be enabled on any interface and with as many instances as required.
Using DHCP Relay
PIX Firewall Version 6.3 provides a DHCP relay agent. This allows the PIX Firewall to assist in dynamic
configuration of IP device hosts on any Ethernet interface. Acting as a DHCP relay agent, when the
PIX
Firewall receives a request from a host on an interface, it forwards the request to a user-configured
DHCP server on another interface.
With previous versions of PIX Firewall, hosts on the inside interfaces must be statically configured or
use addresses provided by the PIX
Firewall DHCP Server.
The following restrictions apply to the use of the DHCP relay agent:
• The relay agent accepts and responds to client requests on any interface.
• The relay agent cannot be enabled if the PIX Firewall DHCP server is enabled.
• The relay agent will forward requests if IPSec is configured. VPN negotiations will be initiated if a
tunnel does not exist.
• Clients must be directly connected to the PIX Firewall and cannot send requests through another
relay agent or a router.
• DHCP relay will not work in client mode.
Note Some type of NAT must be specified to allows forwarding of a DHCP release message from a client to
a DHCP server.
Use the following command to enable the DHCP relay agent:
[no] dhcprelay enable interface
Replace interface with the name of the interface connected to the DHCP clients.
Use the following command to configure a DHCP server address for the relay agent:
[no] dhcprelay server dhcp_server_ip server_ifc
Replace dhcp_server_ip with the IP address of the DHCP server. Replace server_ifc with the interface
connected to the DHCP server. You can use this command to identify up to four servers.
By default, the default gateway used by the DHCP server is configured on the DHCP server. To specify
the default gateway to be used by the DHCP server in the PIX Firewall configuration, enter the following
command:
[no] dhcprelay setroute client_ifc
Replace client_ifc with the PIX Firewall interface to be used as the default gateway by DHCP clients for
reaching the DHCP server.
To set the timeout, use the following command:
[no] dhcprelay timeout seconds
Commentaires sur ces manuels