Cisco Systems IP Helper-address & ICMP port unreachable

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
IP Helper-address & ICMP port unreachable traust 07-27-06
Posted by traust on July 27, 2006, 11:17 am
Please log in for more thread options
Hi,

I am confguring a 6500 with IP helper-address.. done it before on
5500's thousands of times.. no bother.. except this 6500 is sending an
ICMP port unreachable to my DHCP server on the Offer!!!??

Why?

I thought if it caches the helper bootp request it should recognise the
offer coming back!?

It is some funky ARP inspection thing (I switched it all off)..

Its a base config with secondaries on both interfaces (Vlan 2 & Vlan 3)
and a helper address... thats it!


Any ideas?!


Posted by Martin Bilgrav on July 27, 2006, 2:42 pm
Please log in for more thread options

> Hi,
>
> I am confguring a 6500 with IP helper-address.. done it before on
> 5500's thousands of times.. no bother.. except this 6500 is sending an
> ICMP port unreachable to my DHCP server on the Offer!!!??
>
> Why?
>

do you run proxy ARP ?
Does all your SVI's have the ip helper command ? (Interface Vlan 1,
Interface vlan 2 etc)
Are there any ACL's ?

> I thought if it caches the helper bootp request it should recognise the
> offer coming back!?
>
> It is some funky ARP inspection thing (I switched it all off)..
>
> Its a base config with secondaries on both interfaces (Vlan 2 & Vlan 3)
> and a helper address... thats it!

Can you drop the config snip-let ?
Do you mean standby=secondaries or IP ?
HTH
Martin
>
>
> Any ideas?!
>



Posted by traust on July 28, 2006, 5:28 am
Please log in for more thread options
Hi.. Yes secondaries.. many of them...

I have come a lot further.. I notice that the relay helper is pushing
the requests forward with Src and St prt set at 67 but my server is
replying back on 68... hence the port unreachable..

But it still leaves me the quetion that in the field is this still
going to be a problem... will I have to PAT the replies in these
instances.. does anyone know a good DHCP server that reponds
correctly?!

Found this excellent link..
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a00800f0804.shtml

but it still doesnt tell you the solution..


Posted by Martin Bilgrav on July 29, 2006, 3:45 pm
Please log in for more thread options

> Hi.. Yes secondaries.. many of them...
>
> I have come a lot further.. I notice that the relay helper is pushing
> the requests forward with Src and St prt set at 67 but my server is
> replying back on 68... hence the port unreachable..
>
Well, some DHCP servers will respond on udp/67 with reply on udp/67 or
udp/68
It is a setup/config problem at your DHCP server.


> But it still leaves me the quetion that in the field is this still
> going to be a problem... will I have to PAT the replies in these
> instances.. does anyone know a good DHCP server that reponds
> correctly?!
>
> Found this excellent link..
>
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a00800f0804.shtml
>
> but it still doesnt tell you the solution..
>



Posted by Martin Bilgrav on July 29, 2006, 3:50 pm
Please log in for more thread options

> Hi.. Yes secondaries.. many of them...
>
> I have come a lot further.. I notice that the relay helper is pushing
> the requests forward with Src and St prt set at 67 but my server is
> replying back on 68... hence the port unreachable..
>
Are you, by any chance, setting an IP helper on an interface that is in the
same subnet as the DHCP server ?

> But it still leaves me the quetion that in the field is this still
> going to be a problem... will I have to PAT the replies in these
> instances.. does anyone know a good DHCP server that reponds
> correctly?!
>
> Found this excellent link..
>
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a00800f0804.shtml
>
> but it still doesnt tell you the solution..
>



Similar ThreadsPosted
IP Helper-address & ICMP port unreachable July 27, 2006, 11:17 am
Pings and PIX messages 302020: Built ICMP - 302021: Teardown ICMP Lots of them.... May 1, 2006, 2:40 pm
email notification for unreachable switch February 26, 2007, 3:54 pm
IP SLA - ICMP June 5, 2008, 3:55 am
icmp weirdness - PIX 501 (does any really mean any??) September 23, 2005, 10:12 am
timestamp ICMP ? April 16, 2006, 11:45 pm
ICMP pinging. October 3, 2006, 7:22 am
PIX 501 - allow icmp out but deny everything else out November 18, 2006, 1:49 am
PIX 6.3.4 - I have question on a VPN setup & ICMP August 26, 2005, 11:08 am
PIX7.x/ASA and icmp redirects April 19, 2006, 12:30 am
ICMP access list October 9, 2006, 10:55 am
Cisco icmp problems April 13, 2007, 12:32 pm
ICMP Redirect Query? February 24, 2008, 4:44 pm
ASA, static, icmp and inspect FTP August 22, 2008, 5:11 am
icmp type 11 cause pix to deny traffic July 27, 2005, 12:16 pm