Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] access-list, dhcp
Search Topic:
Uniqs:
275
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Config] PIX best practices »
« Cisco PIX OS 7.0  
AuthorAll Replies

lonebandit

join:2001-12-01
Oak Creek, WI
reply to Phraxos
Re: [Config] access-list, dhcp

I probably know what I need to add there...one or both of these:

bootps 67/udp BOOTP/DHCP server
bootpc 68/udp BOOTP/DHCP client

I just wanted an opinion about this. And I guess I got it.

-JD

Phraxos
Premium
join:2004-06-12
UK


1 edit
reply to lonebandit
The way to fix these sorts of problems is to have a deny ip any any log at the end of the ACL. You trigure the problem behaviour and check the log sh log and you will see what is being blocked.

Usually you can nail it in two minutes.

BTW it is good practice to have that line anyway at the end of the ACLs then you can always have a quick look at the log to check for suspicious behaviour.

[Edit] I could just tell you what you need for DHCP but I'm a heartless bastard and this way you will learn so much more

lonebandit

join:2001-12-01
Oak Creek, WI
reply to thebajaguy
yea...I figured something like this should be needed....but wasnt sure.
So I am on the right track

-JD

thebajaguy
Premium
join:2006-01-06
Oaklyn, NJ
reply to lonebandit
I dug back into the discussions and saw a note about UDP port 67 being DHCP related communications. I didn't confirm it with another source, so I'd suggest you check it out further.

lonebandit

join:2001-12-01
Oak Creek, WI
·AT&T U-Verse

I am running a 2801 router and enabled the DHCP server for my LAN... it's working well...but I had a question...

I use an access-list on my fas0/0 (lan side) and different access-lists on my fas0/1 (wan side).

My current applied access list on fas0/0:
interface FastEthernet0/0
description INSIDE LAN
ip access-group to-internet in

and the list looks like this:
ip access-list extended to-internet
deny tcp any any range 135 139
deny udp any any range 135 netbios-ss
permit ip 192.168.1.0 0.0.0.255 any

...this configuration seems to BLOCK dhcp client requests into the interface.

So I changed this list as follows:
ip access-list extended to-internet
deny tcp any any range 135 139
deny udp any any range 135 netbios-ss
permit ip any

..this now permits the clients to obtain a DHCP address....but I was wondering if there could be a better way to do this....

Any comments WILL be appreciated.

-JD
Forums » Equipment Support » Hardware By Brand » Cisco[Config] PIX best practices »
« Cisco PIX OS 7.0  


Thursday, 26-Nov 03:13:08 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [105] New AT&T Ad Campaign Hits Back At Verizon
· [101] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [63] TiVo Sees Record Customer Losses
· [48] In-Flight Internet Headed For Bumpy Landing?
· [34] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [30] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Shutting of Electricity Temporarily (up to 1 yr) to Save $$$ [Home Repair & Improvement]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· [DVR] DCX3400 - 30 Second Skip Forward [Comcast Cable TV]
· Reasons #137/#138 to Love Windows Home Server [Microsoft Help]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]