republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] access-list, dhcp
Search Topic:
Uniqs:
264
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Config] PIX best practices »
« Cisco PIX OS 7.0  
AuthorAll Replies

lonebandit

join:2001-12-01
Oak Creek, WI
·AT&T U-Verse

[Config] access-list, dhcp

I am running a 2801 router and enabled the DHCP server for my LAN... it's working well...but I had a question...

I use an access-list on my fas0/0 (lan side) and different access-lists on my fas0/1 (wan side).

My current applied access list on fas0/0:
interface FastEthernet0/0
description INSIDE LAN
ip access-group to-internet in

and the list looks like this:
ip access-list extended to-internet
deny tcp any any range 135 139
deny udp any any range 135 netbios-ss
permit ip 192.168.1.0 0.0.0.255 any

...this configuration seems to BLOCK dhcp client requests into the interface.

So I changed this list as follows:
ip access-list extended to-internet
deny tcp any any range 135 139
deny udp any any range 135 netbios-ss
permit ip any

..this now permits the clients to obtain a DHCP address....but I was wondering if there could be a better way to do this....

Any comments WILL be appreciated.

-JD

thebajaguy
Premium
join:2006-01-06
Oaklyn, NJ
I dug back into the discussions and saw a note about UDP port 67 being DHCP related communications. I didn't confirm it with another source, so I'd suggest you check it out further.

lonebandit

join:2001-12-01
Oak Creek, WI
yea...I figured something like this should be needed....but wasnt sure.
So I am on the right track

-JD

Phraxos
Premium
join:2004-06-12
UK


1 edit
The way to fix these sorts of problems is to have a deny ip any any log at the end of the ACL. You trigure the problem behaviour and check the log sh log and you will see what is being blocked.

Usually you can nail it in two minutes.

BTW it is good practice to have that line anyway at the end of the ACLs then you can always have a quick look at the log to check for suspicious behaviour.

[Edit] I could just tell you what you need for DHCP but I'm a heartless bastard and this way you will learn so much more

lonebandit

join:2001-12-01
Oak Creek, WI
I probably know what I need to add there...one or both of these:

bootps 67/udp BOOTP/DHCP server
bootpc 68/udp BOOTP/DHCP client

I just wanted an opinion about this. And I guess I got it.

-JD
Forums » Equipment Support » Hardware By Brand » Cisco[Config] PIX best practices »
« Cisco PIX OS 7.0  


Sunday, 08-Nov 16:59:27 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [156] Cable Uncapper Faces Criminal Charges
· [140] AT&T Sues Verizon Over 3G Ads
· [112] Why Run Fiber When You Can Run Ads That Pretend You Do?
· [108] Comcast Is Simply Getting Huge
· [92] Apple Cooking Up New $30 A Month TV Service?
· [82] Bits Of ACTA Agreement Leaking Out
· [80] Will 'Three Strikes' Come To The United States?
· [78] Verizon To Double Smartphone ETFs?
· [76] Verizon: Droid Tethering Will Cost $30 Extra
· [73] Comcast, NBC Deal Almost Complete
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [NFL] Week 9 Games Thread [Sports Chat]
· Please Help, I think my computer is being monitored [Security]
· Hit and run [General Questions]
· NO ONE knows what's wrong with my line! [TekSavvy]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· The real men who stare at goats [56k Lookout (Broadband Heavy)]
· Security Software Updates - 08 Nov 2009 [Security]