In article , Christian Winter wrote: :Yes, seems Cisco is behaving like all the other manufacturers :here, trying to keep functionality low to urge users to step up. :If the implementation was clean the pix would allow to set "private" :dhcp option values and not try to be smart and interfere with it.
Then the PIX would have to be able to parse all of the possible DHCP option formats, including knowing which ones were strings, which were IPs, which are a mix, which are lists of values...
Even if you look at IOS you will find that Cisco does not implement sophisticated DHCP services: by the time you need those additions then you would generally put a different device on the net to act as the server.
:> I suggest you have that "different router" handle the DHCP instead of :> the PIX. The PIX is not intended to be a sophisticated DHCP server.
:The problem is this router is not under our control, so the only :simple solution (without changing or adding hardware) would be to :use a dhcp server on the "outside" interface.
So add hardware? You can probably find someone willing to literally
-give- you a Pentium 2 133 or 266 MHz; that and linux or BSD would give you full control.
:Seems we'll have to :bite into the sour apple and buy an upgrade to 6.3 to get dhcprelay :functionality.
I suggest you review the PIX Security Advisories. Your 6.2(2) is quite out of date, and you are entitled to a free upgrade to at least
6.2(5). If I recall correctly, someone mentioned that they had been able to get a free upgrade from 6.2 to 6.3 by pointing to a documented security problem that had not been fixed in 6.2. Once you are in 6.3, you are entitled to free upgrades to 6.3(4) due to security problems. The latest 6.3 is 6.3(5), which is a bugfix release, not a security release, so you might only be able to get to 6.3(4) for free.