skip to content

DHCP

DORA hands a host with no address a lease, a gateway and DNS servers, and relays carry it across subnets. It opens every 'from boot to browsing' question and every rogue-server story.

on this pageshow

explore

questions

page 2 of 2

When no DHCP server answers a client's DHCPDISCOVER, how does RFC 2131 say the client should time its retransmissions, and why randomise them?

level: middleimportance: nice to knowfreq 10%

basics

~20 s

Only the client retransmits, using a randomised exponential back-off. RFC 2131 suggests gaps of about 4 s, then 8 s, doubling to a 64 s cap, each ±1 s, so clients that start together do not retry in lockstep.

open as a page

Every DHCPv4 client on a relayed branch subnet extends its lease only at about 87.5%, never at 50%; what in the renewal path explains it?

level: seniorimportance: nice to knowfreq 10%

basics

~20 s

A DHCPv4 T1 renewal is unicast from the client straight to the server, bypassing the relay; when that path is blocked, renewals fail and the lease is only extended by the T2 rebinding broadcast, which the relay does forward.

open as a page

In DHCP Option 82, what do the circuit-ID and remote-ID sub-options carry, and how does a server use them though the client never sees them?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

The relay agent adds DHCP Option 82: sub-option 1, Agent Circuit ID, names the arrival port or circuit; sub-option 2, Agent Remote ID, names the remote end. The server matches and logs them and echoes the option, which the relay strips.

open as a page

Why can a DHCPv4 reservation keyed on a laptop's MAC address fail to match, and when should it be keyed on the client identifier instead?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

RFC 2131 makes the server identify a client by its client identifier option when one is sent, using the MAC in chaddr only otherwise; RFC 4361 clients send a DUID-based identifier, so a MAC reservation may not match.

open as a page

What do DHCPv6-Shield (RFC 7610) and SAVI-DHCP (RFC 7513) each standardise, and why must DHCPv6-Shield parse the whole IPv6 header chain?

level: seniorimportance: nice to knowfreq 8%

basics

~20 s

DHCPv6-Shield (RFC 7610, BCP 199) drops DHCPv6 server messages on ports not allowed for a server or relay; SAVI-DHCP (RFC 7513) binds DHCP-assigned addresses to ports to filter forged sources. Shield parses the full chain because extension headers can hide UDP.

open as a page

When a DHCP snooping switch inserts Option 82 but leaves giaddr at zero, why can the upstream relay agent discard the client's request?

level: seniorimportance: nice to knowfreq 9%

basics

~20 s

RFC 3046 tells a relay agent to discard a packet from an untrusted circuit that has giaddr zero but already carries Option 82. A snooping switch that inserts Option 82 without setting giaddr produces exactly that, so the relay must trust that circuit.

open as a page

How does a DHCPv6 relay agent carry a client's Solicit to a server on another subnet, and how does the server tell which link the client is on?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

The relay wraps the client's message unchanged in a Relay-forward, recording a global address of the client's link in link-address and the client's source in peer-address. The server picks the link from link-address and answers in a Relay-reply.

open as a page

showing 31–37 of 37