When you connect a laptop to a network, it needs an IP address and a few other settings before it can communicate properly. DHCP (Dynamic Host Configuration Protocol) supplies those settings automatically, so nobody has to configure every device by hand.
Why DHCP exists
To use an IP network fully, every device needs four settings: an IP address, a subnet mask, a default gateway and a DNS server. Typing these into every laptop, phone and printer by hand is slow, and people make mistakes: two devices end up with the same address, or a typo in the gateway cuts a PC off from the internet. Phones and laptops also move between networks all day, and each network needs different settings.
DHCP solves all of these problems. One server holds the correct settings for the network and hands them out on request. Addresses are only lent, so when a visitor leaves, their address goes back into the pool for someone else. This happens every time you join a Wi-Fi network at home, at work or in a café.
What DHCP gives a device
Here is an example for a small office using the network 192.168.10.0/24:
| Setting | Example | What it's for |
|---|---|---|
| IP address | 192.168.10.100 | The device's address on the network |
| Subnet mask | 255.255.255.0 | Tells the device which destinations are local |
| Default gateway | 192.168.10.1 | The router used to reach other networks |
| DNS server | 192.168.10.2 | Translates names into IP addresses |
| Lease time | 8 hours | How long the assignment is valid |
The server sends these values as DHCP options. Common ones are option 1 (subnet mask), option 3 (router, meaning the default gateway) and option 6 (DNS servers). In this example, 192.168.10.2 runs both DHCP and DNS, but they can just as easily be separate devices.
💡 In simple terms: DHCP is like checking into a hotel. You don't bring your own room number. The front desk gives you one for the length of your stay (the lease) and tells you everything else you need, such as where the exit is (the gateway).
Who's involved
| Component | Job |
|---|---|
| DHCP client | Asks for settings, for example a laptop or phone. Almost every device is a DHCP client by default. |
| DHCP server | Hands out addresses and settings from a pool. At home this is the home router; in an office it is often a server or the router. |
| Scope / pool | The range of addresses the server may lend for one subnet, plus the settings that go with it |
| Lease | The loan of one address to one client, for a set time |
| Switch | Carries the messages within the VLAN |
| DHCP relay | Forwards DHCP messages to a server on another subnet |
On a home network, all of this is in one box: the home router is the default gateway, the DHCP server and usually a DNS forwarder too.
Watch it: getting an address (DORA)
Getting an address is a four-message exchange, remembered as DORA: Discover → Offer → Request → Acknowledge. In simple terms:
- Discover (client): "I'm new here and have no address. Is there a DHCP server?" Sent as a broadcast, because the client doesn't know who the server is.
- Offer (server): "You can have 192.168.10.100, with this mask, gateway and DNS server, for 8 hours."
- Request (client): "Yes, please. I'll take the offer from that server." This is still a broadcast, so any other server that made an offer knows it wasn't chosen.
- Acknowledge (server): "Done. The address is yours for 8 hours." The client then configures itself.
All four messages travel in UDP datagrams. Select any message to see its addresses and ports.
- IP:
- 192.168.10.100
- Mask:
- 255.255.255.0
- Gateway:
- 192.168.10.1
- DNS:
- 192.168.10.2
- Lease:
- 8 hours
* The Offer and ACK can be broadcast or unicast, depending on the client's state and broadcast flag.
Ports and addresses
DHCP runs over UDP: the server listens on UDP 67, and the client listens on UDP 68.
| Message | Source IP | Destination IP | UDP ports |
|---|---|---|---|
| Discover | 0.0.0.0 | 255.255.255.255 | 68 → 67 |
| Offer | Server IP | Broadcast or offered address | 67 → 68 |
| Request (first time) | 0.0.0.0 | 255.255.255.255 | 68 → 67 |
| ACK | Server IP | Broadcast or assigned address | 67 → 68 |
0.0.0.0 means "I don't have an address yet". 255.255.255.255 is the limited broadcast address: it reaches every device in the local broadcast domain and is never forwarded by routers. Later, when the client renews its lease, it uses its own assigned address as the source.
Pools, exclusions and reservations
| Term | Meaning | Office example |
|---|---|---|
| Pool (scope in Windows Server) | Addresses and settings for one subnet | .100 to .200 |
| Lease | A time-limited assignment | 8 hours |
| Exclusion | An address the server must not hand out | .150, set manually on a device |
| Reservation | An address kept for one particular client | The printer always gets .120 |
A device with a reservation still uses DHCP, while a static address is typed into the device itself. Plan exclusions so that manually set addresses never overlap with the addresses DHCP hands out.
Keeping the address: renewal, rebinding and expiry
A client doesn't wait for its lease to run out. It tries to renew the lease well before then:
0 h · lease startsThe client has a 8-hour lease. Nothing to do yet.
| Stage | What the client does | How |
|---|---|---|
| T1 · renewing (50%) | Asks the original server to extend the lease | Unicast DHCPREQUEST |
| T2 · rebinding (87.5%) | Asks any available server to extend it | Broadcast DHCPREQUEST |
| Expiry (100%) | Stops using the address | Starts DORA again |
A successful renewal needs only a Request and an ACK, not all four DORA messages. A client that restarts can also ask for its previous address back.
DHCP server on another subnet: relay
Organisations often run one central DHCP server for many VLANs. But routers don't forward the client's broadcast. Instead, the router interface facing the clients acts as a DHCP relay: it receives the broadcast and forwards it to the server as a normal unicast packet.
1. Discover · Broadcast on VLAN 10 · UDP 68 → 67
Is there a DHCP server out there?
The relay writes its client-facing address into the giaddr (gateway IP address) field. That is how the server knows which pool to use: a giaddr of 192.168.10.1 means "use the 192.168.10.0/24 pool". The server replies to the relay, not straight to the client.
Checking DHCP on a Windows client
ipconfig /all| Field | What to look for |
|---|---|
| DHCP Enabled | Yes |
| IPv4 Address | An address in the expected subnet |
| Subnet Mask | The right mask |
| Default Gateway | The right router |
| DHCP Server | The server you expect |
| DNS Servers | The DNS addresses you expect |
| Lease Obtained / Expires | When the lease started and when it ends |
To ask for a fresh lease:
ipconfig /release
ipconfig /renew/release gives the current address back to the server, and /renew starts a new request. Run ipconfig /all again afterwards: if the IPv4 address is still 169.254.x.x, no DHCP server answered.
When DHCP fails
| Symptom | Likely cause | Check first |
|---|---|---|
| No lease at all | Server down or pool exhausted | The DHCP service, free addresses in the pool |
| Only one VLAN fails | Relay or VLAN problem | VLAN assignment, helper address |
| Address from the wrong subnet | Wrong VLAN or an unexpected server | The switch port's VLAN, which server answered |
| Local works, remote doesn't | Gateway or routing | The gateway option, routes |
| IP addresses work, names don't | DNS | The DNS option, whether the DNS server is reachable |
| Discover seen, no Offer | Path or server problem | Relay, routing, ACLs, server |
These are clues, not proof. Follow the four messages and find where the exchange stops.
⚠️ A Windows device that gets no answer gives itself a 169.254.x.x address (APIPA, Automatic Private IP Addressing). macOS does the same. Seeing 169.254 almost always means "DHCP didn't work". The address allows only limited local communication, with no gateway and no internet.
DHCP security: snooping
A rogue DHCP server (a home router plugged into the office network by mistake, or an attacker) can hand clients the wrong gateway or DNS server. DHCP snooping on the switch blocks DHCP server replies from ports that shouldn't send them:
| Port | Setting |
|---|---|
| Towards the real DHCP server (or relay) | Trusted |
| To user devices | Untrusted |
Trusted ports must follow the real path to the server. If you get this wrong, the switch blocks legitimate replies too.
Practice: predict what happens
The office DHCP server is switched off. A Windows laptop joins the network. What happens?
Every address in the pool .100 – .200 is leased. A new phone joins. What happens?
One central DHCP server serves VLAN 10 and VLAN 30. VLAN 10's router interface has ip helper-address configured, but VLAN 30's doesn't. What happens?
A client has the correct IP address, mask and gateway. It can ping 8.8.8.8, but websites won't load by name. What is the most likely cause?
Common mistakes
- Setting a static address inside the DHCP pool. The server doesn't know the address is taken and may lease it to another device, causing an address conflict. Exclude it from the pool or use a reservation.
- Configuring ip helper-address on the wrong interface. The helper must be on the interface that receives the client broadcasts, not the one facing the server.
- Treating a 169.254.x.x address as a DNS or internet problem. It means the device never got a DHCP lease, so start with DHCP: the server, the pool, the relay and the VLAN.
- A DHCP address doesn't guarantee internet access; the gateway and DNS still have to be right.
- The DHCP server, default gateway and DNS server can all be different devices.
- DHCPREQUEST is broadcast when first choosing an offer, but unicast when renewing at T1.
- Routers don't forward the client's broadcast; a relay (
ip helper-address) does. - A reservation is handed out by DHCP; a static address is set on the device.
Going further: DHCP on a Cisco router (CCNA)
This section is CCNA level: it shows how the ideas above are configured on a Cisco router. You don't need it to understand how DHCP works, so you can skip it on a first read.
Router as the DHCP server
Here the router is both the default gateway and the DHCP server, and a separate DNS server is at 192.168.10.2. Interface names vary by device.
configure terminal
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
no shutdown
exit
ip dhcp excluded-address 192.168.10.1 192.168.10.99
ip dhcp excluded-address 192.168.10.201 192.168.10.254
ip dhcp pool OFFICE
network 192.168.10.0 255.255.255.0
default-router 192.168.10.1
dns-server 192.168.10.2
lease 0 8
exit
end| Command | What it does |
|---|---|
ip dhcp excluded-address | Keeps a range out of the pool |
ip dhcp pool OFFICE | Creates a pool named OFFICE |
network | The subnet the pool serves |
default-router | The gateway handed to clients (option 3) |
dns-server | The DNS server handed to clients (option 6) |
lease 0 8 | Lease of 0 days, 8 hours |
The two exclusions leave .100 to .200 for clients. Note that dns-server only advertises a DNS server to clients; it doesn't create one.
Check it with:
show ip dhcp bindingLists the addresses the router has leased, and to which client.
Router as a relay
If the server is at 192.168.20.10 instead, configure the helper address on the interface that receives the client broadcasts:
configure terminal
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
ip helper-address 192.168.20.10
no shutdown
exit
endThe remote server still needs a pool for 192.168.10.0/24, and routing must work between the relay and the server. By default, ip helper-address also forwards a few other UDP broadcasts, so it isn't strictly a DHCP-only command.