1-3
Cisco ASA Series CLI Configuration Guide
 
Chapter 1      Configuring DHCP
  Configuring a DHCP Server
• For multiple context mode, you cannot enable DHCP relay service on an interface that is used by 
more than one context.
• The DHCP relay service is not available in transparent firewall mode. An ASA in transparent 
firewall mode only allows ARP traffic through; all other traffic requires an access list. To allow 
DHCP requests and replies through the ASA in transparent firewall mode, you must configure two 
access lists: one that allows DCHP requests from the inside interface to the outside, and one that 
allows the replies from the server in the other direction.
• When the DHCP relay service is enabled and more than one DHCP relay server is defined, the ASA 
forwards client requests to each defined DHCP relay server. Replies from the servers are also 
forwarded to the client until the client DHCP relay binding is removed. The binding is removed 
when the ASA receives any of the following DHCP messages: ACK, NACK, or decline.
• You cannot enable DHCP relay service on an interface running as a DHCP proxy service. You must 
remove the VPN DHCP configuration first or an error message appears. This error occurs if both 
DHCP relay and DHCP proxy services are enabled. Make sure that either the DHCP relay or DHCP 
proxy service is enabled, but not both. 
Firewall Mode Guidelines
Supported in routed firewall mode.
Not supported in transparent firewall mode.
Context Mode Guidelines
Supported in single and multiple context mode.
Failover Guidelines
Supports Active/Active and Active/Standby failover.
IPv6 Guidelines
Supports IPv6.
Configuring a DHCP Server
This section describes how to configure a DHCP server provided by the ASA and includes the following 
topics:
• Enabling the DHCP Server, page 1-4
• Configuring DHCP Options, page 1-5
• Using Cisco IP Phones with a DHCP Server, page 1-6