DHCP
DORA hands a host with no address a lease, a gateway and DNS servers, and relays carry it across subnets. It opens every 'from boot to browsing' question and every rogue-server story.
on this pageshowhide
explore
- DORA Exchange6 questions
- Leases and Renewal5 questions
- Scopes and Reservations5 questions
- DHCP Options4 questions
- Relay Agents5 questions
- DHCPv66 questions
- Rogue Servers and Snooping6 questions
questions
page 2 of 2When no DHCP server answers a client's DHCPDISCOVER, how does RFC 2131 say the client should time its retransmissions, and why randomise them?
basics
~20 sOnly the client retransmits, using a randomised exponential back-off. RFC 2131 suggests gaps of about 4 s, then 8 s, doubling to a 64 s cap, each ±1 s, so clients that start together do not retry in lockstep.
Every DHCPv4 client on a relayed branch subnet extends its lease only at about 87.5%, never at 50%; what in the renewal path explains it?
basics
~20 sA DHCPv4 T1 renewal is unicast from the client straight to the server, bypassing the relay; when that path is blocked, renewals fail and the lease is only extended by the T2 rebinding broadcast, which the relay does forward.
In DHCP Option 82, what do the circuit-ID and remote-ID sub-options carry, and how does a server use them though the client never sees them?
basics
~20 sThe relay agent adds DHCP Option 82: sub-option 1, Agent Circuit ID, names the arrival port or circuit; sub-option 2, Agent Remote ID, names the remote end. The server matches and logs them and echoes the option, which the relay strips.
Why can a DHCPv4 reservation keyed on a laptop's MAC address fail to match, and when should it be keyed on the client identifier instead?
basics
~20 sRFC 2131 makes the server identify a client by its client identifier option when one is sent, using the MAC in chaddr only otherwise; RFC 4361 clients send a DUID-based identifier, so a MAC reservation may not match.
What do DHCPv6-Shield (RFC 7610) and SAVI-DHCP (RFC 7513) each standardise, and why must DHCPv6-Shield parse the whole IPv6 header chain?
basics
~20 sDHCPv6-Shield (RFC 7610, BCP 199) drops DHCPv6 server messages on ports not allowed for a server or relay; SAVI-DHCP (RFC 7513) binds DHCP-assigned addresses to ports to filter forged sources. Shield parses the full chain because extension headers can hide UDP.
When a DHCP snooping switch inserts Option 82 but leaves giaddr at zero, why can the upstream relay agent discard the client's request?
basics
~20 sRFC 3046 tells a relay agent to discard a packet from an untrusted circuit that has giaddr zero but already carries Option 82. A snooping switch that inserts Option 82 without setting giaddr produces exactly that, so the relay must trust that circuit.
How does a DHCPv6 relay agent carry a client's Solicit to a server on another subnet, and how does the server tell which link the client is on?
basics
~20 sThe relay wraps the client's message unchanged in a Relay-forward, recording a global address of the client's link in link-address and the client's source in peer-address. The server picks the link from link-address and answers in a Relay-reply.
showing 31–37 of 37