Runbook 03 — DHCP and IP Addressing Troubleshooting
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook | 03 |
| Runbook Name | DHCP and IP Addressing Troubleshooting |
| Track | CompTIA Network+ |
| Type | Network Operations Runbook |
| Primary Role | Network Technician / Network Administrator |
| Difficulty | Intermediate |
| Use Case | IPv4 addressing and DHCP configuration incidents |
| Primary Tools | ipconfig, ip, arp, ping, DHCP Server Console, Router CLI, Wireshark, Syslog, SNMP |
| Primary Technologies | IPv4, DHCP, DHCP Relay, Subnetting, ARP, VLANs |
| Outcome | Identify, isolate, remediate, verify, escalate, and document IP addressing failures |
Runbook Objective: Provide a consistent operational procedure for investigating endpoint IPv4 and DHCP incidents by validating the client, VLAN, address assignment process, DHCP scope, relay path, lease database, gateway configuration, duplicate-address conditions, and DHCP packet flow before implementing controlled corrective actions.
When to Use This Runbook
Section titled “When to Use This Runbook”Use this runbook when users report:
"I have no network."
"My computer has a 169.254 address."
"I connected to the network but cannot reach anything."
"My IP address is wrong."
"I can reach local systems but not remote networks."
"New devices cannot obtain addresses."
"Some users receive addresses while others do not."
"The DHCP scope is full."
"Clients are receiving the wrong gateway."
"Clients are receiving the wrong DNS server."
"Connectivity is intermittent because of duplicate IP addresses."Typical incidents include:
-
DHCP server unavailable
-
DHCP scope inactive
-
scope exhaustion
-
missing DHCP relay
-
incorrect relay destination
-
incorrect DHCP scope
-
wrong subnet mask
-
wrong default gateway
-
wrong DNS option
-
incorrect static address
-
duplicate IP address
-
reservation problems
-
lease problems
-
incorrect VLAN
-
DHCP packets blocked by firewall
-
rogue DHCP server
-
DORA failure
1. Understand the DHCP Path
Section titled “1. Understand the DHCP Path”A normal local DHCP process looks like:
CLIENT01 ↓DHCP Discover ↓Local VLAN ↓DHCP Server ↓DHCP Offer ↓DHCP Request ↓DHCP ACKIf the DHCP server is on another subnet:
CLIENT01 ↓DHCP Broadcast ↓VLAN Gateway ↓DHCP Relay ↓DHCP Server ↓Correct Scope ↓Lease ReturnedFor DHCP to succeed, all of the following must work:
Physical Connectivity
Correct VLAN
DHCP Client
Broadcast Path
DHCP Relay
Routing
DHCP Server
Correct Scope
Available Lease
Correct DHCP Options2. Troubleshooting Principle
Section titled “2. Troubleshooting Principle”Follow:
Symptom ↓Scope ↓Client Configuration ↓VLAN ↓DHCP Exchange ↓Relay ↓Server ↓Scope ↓Lease ↓Options ↓Root Cause ↓Remediation ↓VerificationDo not begin by:
Restarting Every DHCP Server
Deleting All Leases
Expanding the Scope Randomly
Disabling Firewalls
Assigning Static Addresses to EveryoneThese actions can hide the underlying fault.
3. Record the Incident
Section titled “3. Record the Incident”Document:
Incident ID:
Date:
Time:
Reported By:
Affected Users:
Affected VLAN:
Affected Subnet:
DHCP Server:
Business Impact:
Recent Changes:Example:
Incident ID:INC-DHCP-3051
Affected:Sales Department
VLAN:20
Network:10.10.20.0/24
Problem:New laptops cannot obtain an IPv4 address.
Impact:18 users affected.4. Define the Exact Symptom
Section titled “4. Define the Exact Symptom”Avoid:
DHCP is broken.Prefer:
Clients in VLAN 20 receive 169.254.x.x addresses.
Existing clients with active leases remain operational.This distinction immediately provides evidence.
5. Determine Scope
Section titled “5. Determine Scope”Ask:
One Client?
Several Clients?
All New Clients?
One VLAN?
Several VLANs?
One Site?
All Sites?
Wired Only?
Wireless Only?Create:
| Test | Result |
|---|---|
| Existing client in affected VLAN | |
| New client in affected VLAN | |
| Client in another VLAN | |
| Static-address test client | |
| DHCP server reachable |
6. Check Recent Changes
Section titled “6. Check Recent Changes”Review:
DHCP Scope Changes
VLAN Changes
DHCP Relay Changes
Router Configuration
Firewall Changes
Server Updates
DHCP Server Restart
New Reservations
Scope Resize
Network RenumberingRecord any relevant change ID and timestamp.
7. Check the Endpoint First
Section titled “7. Check the Endpoint First”Windows:
ipconfig /allLinux:
ip addrRecord:
IPv4 Address:
Subnet Mask / Prefix:
Default Gateway:
DHCP Enabled:
DHCP Server:
DNS Server:
Lease Obtained:
Lease Expires:8. Identify APIPA
Section titled “8. Identify APIPA”If Windows displays:
169.254.x.xthis is:
APIPAIt strongly suggests the client did not obtain its intended DHCP configuration.
Remember:
APIPA=Symptomnot:
Root Cause9. Check Whether DHCP Is Enabled
Section titled “9. Check Whether DHCP Is Enabled”Windows:
ipconfig /allLook for:
DHCP Enabled:YesIf:
Nothe endpoint may be using static configuration.
10. Check for Incorrect Static Addressing
Section titled “10. Check for Incorrect Static Addressing”Suppose the expected network is:
10.10.20.0/24but the client is configured:
10.10.10.50/24Root cause may be:
Incorrect Static IPnot DHCP.
11. Validate the Client Subnet
Section titled “11. Validate the Client Subnet”Compare:
Expected VLAN:20
Expected Network:10.10.20.0/24
Actual Address:10.10.20.125/24or identify any mismatch.
12. Validate the Subnet Mask
Section titled “12. Validate the Subnet Mask”Expected:
255.255.255.0but actual:
255.255.0.0can cause incorrect local/remote forwarding decisions.
Record:
Expected Mask:
Actual Mask:13. Validate the Default Gateway
Section titled “13. Validate the Default Gateway”Example:
Client:10.10.20.125/24
Expected Gateway:10.10.20.1Incorrect:
10.10.10.1can allow a valid-looking IP while remote communication fails.
14. Test the Client Stack
Section titled “14. Test the Client Stack”Windows:
ping 127.0.0.1Then:
ping <CLIENT-IP>Verify the local TCP/IP stack before moving upstream.
15. Test the Gateway
Section titled “15. Test the Gateway”Run:
ping <DEFAULT-GATEWAY>If a valid DHCP address exists but gateway access fails, investigate:
VLAN
Gateway Interface
ARP
Switching
Incorrect DHCP Gateway Option16. Check ARP
Section titled “16. Check ARP”Windows:
arp -aLinux:
ip neighVerify the gateway resolves to a MAC address.
17. Verify VLAN Membership
Section titled “17. Verify VLAN Membership”A client can fail DHCP because it is connected to the wrong VLAN.
On the switch:
show vlan briefThen:
show interfaces <interface> switchportVerify:
Expected VLAN=Actual VLAN18. Recognize Wrong-VLAN DHCP Symptoms
Section titled “18. Recognize Wrong-VLAN DHCP Symptoms”Expected client network:
10.10.20.0/24Client receives:
10.10.40.110/24This may indicate:
Wrong Access VLAN
Wrong SSID-to-VLAN Mapping
Wrong DHCP Scope Selection19. Release the DHCP Lease
Section titled “19. Release the DHCP Lease”Windows:
ipconfig /releaseLinux behavior depends on the DHCP client implementation.
Use the appropriate client command for the platform.
20. Renew the DHCP Lease
Section titled “20. Renew the DHCP Lease”Windows:
ipconfig /renewRecord:
Renewal:SUCCESS / FAILURE
Assigned Address:
Gateway:
DNS:
DHCP Server:21. Understand DORA
Section titled “21. Understand DORA”The normal initial DHCPv4 exchange is:
Discover ↓Offer ↓Request ↓AcknowledgmentRemember:
DORA22. Capture DHCP Traffic
Section titled “22. Capture DHCP Traffic”Start Wireshark on the affected client network.
Filter:
dhcpor:
bootpThen perform a release/renew.
23. Identify DHCP Discover
Section titled “23. Identify DHCP Discover”Look for:
DHCP DiscoverRecord:
Client MAC:
Transaction ID:
Source IP:
Destination IP:
Source Port:
Destination Port:24. DHCP Ports
Section titled “24. DHCP Ports”Remember:
UDP 67=DHCP ServerUDP 68=DHCP Client25. Decision Point — No Discover
Section titled “25. Decision Point — No Discover”If the client sends no DHCP Discover:
Investigate ClientCheck:
DHCP Enabled?
NIC Operational?
Correct Interface?
OS DHCP Client Service?
Static Configuration?26. Decision Point — Discover but No Offer
Section titled “26. Decision Point — Discover but No Offer”If you see:
Discover
Discover
Discoverbut no:
Offerinvestigate:
DHCP Server
Scope
VLAN
Relay
Routing
Firewall
Available AddressesThis is one of the most useful DHCP fault-isolation patterns.
27. Decision Point — Offer but No Request
Section titled “27. Decision Point — Offer but No Request”If:
Discover↓Offerappears, but the client never sends a Request, investigate:
Client DHCP Behavior
Invalid Offer
Duplicate Detection
Competing DHCP Servers
Client Configuration28. Decision Point — Request but No ACK
Section titled “28. Decision Point — Request but No ACK”If:
Discover
Offer
Requestappears but there is no ACK, investigate:
DHCP Server
Lease Allocation
Server Policy
Network Path
Firewall29. Identify DHCP NAK
Section titled “29. Identify DHCP NAK”A DHCP server may respond with:
DHCP NAKwhich indicates the requested configuration is not valid in the server’s current context.
Investigate:
Old Lease
Moved VLAN
Invalid Address
Scope Change
Client Rebinding30. Check the DHCP Server
Section titled “30. Check the DHCP Server”Verify the DHCP service is:
RunningLinux example:
systemctl status <dhcp-service>Windows Server:
Verify DHCP Server Serviceand server health.
31. Verify Server IP Configuration
Section titled “31. Verify Server IP Configuration”A DHCP server should normally have stable addressing.
Check:
Static IP
Subnet Mask
Default Gateway
RoutingA DHCP server with incorrect addressing may be unable to respond correctly.
32. Verify DHCP Scope Exists
Section titled “32. Verify DHCP Scope Exists”For client network:
10.10.20.0/24verify a matching scope exists.
Example:
Scope:10.10.20.0/24
Pool:10.10.20.100–10.10.20.20033. Verify the Scope Is Active
Section titled “33. Verify the Scope Is Active”A correctly defined but inactive scope cannot serve clients.
Check:
Scope State:ACTIVE34. Verify Address Pool
Section titled “34. Verify Address Pool”Check:
Start Address:
End Address:
Subnet Mask:
Available Addresses:35. Check for Scope Exhaustion
Section titled “35. Check for Scope Exhaustion”Suppose:
Pool:10.10.20.100–10.10.20.149and:
Available Addresses:0New clients cannot obtain leases.
36. Scope Exhaustion Symptoms
Section titled “36. Scope Exhaustion Symptoms”Typical behavior:
Existing Clients:Working
New Clients:FailingThis is an important clue.
37. Investigate Lease Utilization
Section titled “37. Investigate Lease Utilization”Review:
Total Addresses
Active Leases
Available Addresses
Reservations
Exclusions
Expired LeasesCreate:
| Metric | Value |
|---|---|
| Pool size | |
| Active leases | |
| Reservations | |
| Exclusions | |
| Available |
38. Understand Exclusions
Section titled “38. Understand Exclusions”Ensure critical infrastructure addresses are excluded from dynamic allocation.
Examples:
Gateway
Servers
Switches
Printers
Access PointsIncorrect exclusions can reduce pool capacity or create conflicts.
39. Review Lease Duration
Section titled “39. Review Lease Duration”Very long lease duration in a high-turnover environment may reduce address availability.
Very short leases may increase DHCP activity.
Check:
Lease Duration:and compare with operational requirements.
40. Check Reservations
Section titled “40. Check Reservations”Verify:
MAC / Client Identifier
Reserved Address
Correct Scope
Reservation StateIncorrect reservations may cause predictable-address problems.
41. Check DHCP Options
Section titled “41. Check DHCP Options”Validate:
Subnet Mask
Default Gateway
DNS Servers
Domain Name
Lease DurationA DHCP lease can be successfully assigned while containing incorrect options.
42. Wrong Gateway Scenario
Section titled “42. Wrong Gateway Scenario”Client receives:
IP:10.10.20.120
Mask:255.255.255.0
Gateway:10.10.20.254but actual gateway is:
10.10.20.1Symptoms:
Local Communication:WORKS
Remote Communication:FAILS43. Wrong DNS Scenario
Section titled “43. Wrong DNS Scenario”Client receives correct IP and gateway but:
DNS:10.10.20.99where no DNS service exists.
Symptoms:
IP Connectivity:WORKS
Hostname Resolution:FAILSThe DHCP service is functioning—but distributing incorrect configuration.
44. Check DHCP Relay
Section titled “44. Check DHCP Relay”If DHCP server is on another network, verify the relay.
Conceptually:
CLIENT VLAN 20 ↓10.10.20.1 ↓DHCP Relay ↓10.10.30.53DHCP Server45. Verify Relay Destination
Section titled “45. Verify Relay Destination”Cisco-like example:
show running-config interface <client-gateway-interface>Look for the equivalent of:
ip helper-address 10.10.30.5346. Decision Point — Missing Relay
Section titled “46. Decision Point — Missing Relay”If:
Local VLAN Clients:No DHCPwhile the DHCP server is remote and no relay exists:
Root Cause:DHCP Broadcast Cannot Reach Server47. Decision Point — Wrong Relay Address
Section titled “47. Decision Point — Wrong Relay Address”Expected:
10.10.30.53Configured:
10.10.30.99DHCP requests are relayed to the wrong system.
48. Verify Router Can Reach DHCP Server
Section titled “48. Verify Router Can Reach DHCP Server”From the relay device:
ping 10.10.30.53or equivalent.
Relay configuration alone is not enough.
The relay needs normal Layer 3 reachability.
49. Verify DHCP Server Return Routing
Section titled “49. Verify DHCP Server Return Routing”Ensure the DHCP server can return traffic toward the relay/client networks.
Check:
Default Gateway
Routing Table
Firewall50. Check Firewalls
Section titled “50. Check Firewalls”Verify required DHCP communication is permitted.
Relevant traffic includes:
UDP 67
UDP 68and any relay path between network devices and the server.
51. Check for Multiple DHCP Servers
Section titled “51. Check for Multiple DHCP Servers”Wireshark may show:
DHCP Discover ↓Offer from Server A
Offer from Server BUnexpected offers may indicate:
Rogue DHCP Server
Misconfigured Backup DHCP Server
Overlapping DHCP Services52. Rogue DHCP Symptoms
Section titled “52. Rogue DHCP Symptoms”Clients may receive:
Wrong Gateway
Wrong DNS
Wrong Subnet
Unexpected Address Rangewhile other clients appear normal.
53. Identify DHCP Server from the Client
Section titled “53. Identify DHCP Server from the Client”Windows:
ipconfig /allRecord:
DHCP Server:Compare with the approved server inventory.
54. Check Duplicate IP Address Symptoms
Section titled “54. Check Duplicate IP Address Symptoms”Possible signs include:
Intermittent Connectivity
Duplicate Address Warning
ARP Changes
Connections Going to Wrong Host
Unexpected Disconnects55. Investigate Duplicate IPs
Section titled “55. Investigate Duplicate IPs”Windows:
arp -aLinux:
ip neighCompare MAC mappings over time.
56. Verify Static Addresses Are Outside Dynamic Pool
Section titled “56. Verify Static Addresses Are Outside Dynamic Pool”Example bad design:
SERVER01:10.10.20.120Staticwhile DHCP pool includes:
10.10.20.100–200This creates conflict risk.
57. Create an Addressing Standard
Section titled “57. Create an Addressing Standard”Example:
10.10.20.1–49Infrastructure
10.10.20.50–99Reservations
10.10.20.100–200Dynamic DHCP
10.10.20.201–254Future / ReservedThe exact model can vary, but the separation should be intentional.
58. Check Lease State
Section titled “58. Check Lease State”On the DHCP server, inspect:
Client MAC
Leased IP
Lease Start
Lease Expiration
Hostname
Reservation Status59. Troubleshoot Client Unable to Renew
Section titled “59. Troubleshoot Client Unable to Renew”If the client already has an address but renewal fails:
Existing Connectivitymay continue temporarilyuntil the lease reaches later stages or expires.
Investigate:
DHCP Server Reachability
Server Health
Relay
Firewall
Scope60. Understand T1 and T2
Section titled “60. Understand T1 and T2”At a high level:
T1→ Renewal attempt with original DHCP serverT2→ Rebinding attempt using available DHCP serversThis can explain why DHCP failures sometimes appear delayed.
61. Troubleshoot a Moved Client
Section titled “61. Troubleshoot a Moved Client”A client moved from:
VLAN 10to:
VLAN 20may temporarily retain stale configuration.
Release/renew the lease and verify the client obtains an address valid for VLAN 20.
62. Check Wireless DHCP
Section titled “62. Check Wireless DHCP”Wireless path:
Client ↓SSID ↓AP ↓VLAN Mapping ↓AP Trunk ↓Gateway ↓DHCP Relay ↓DHCP ServerIf association works but DHCP fails, investigate this entire path.
63. Wireless APIPA Scenario
Section titled “63. Wireless APIPA Scenario”Client shows:
SSID:GHC-CORP
Status:Connected
IPv4:169.254.30.15This tells you:
Association:Likely Working
DHCP:FailingDo not immediately troubleshoot the WPA password.
64. Verify SSID-to-VLAN Mapping
Section titled “64. Verify SSID-to-VLAN Mapping”Example:
GHC-CORP→ VLAN 50If incorrectly mapped:
GHC-CORP→ VLAN 60clients may receive guest-network addresses.
65. Build the DHCP Theory Matrix
Section titled “65. Build the DHCP Theory Matrix”| Theory | Evidence For | Evidence Against | Test | Result |
|---|---|---|---|---|
| Client DHCP disabled | ||||
| Wrong VLAN | ||||
| DHCP service down | ||||
| Scope inactive | ||||
| Scope exhausted | ||||
| Missing relay | ||||
| Wrong relay address | ||||
| Firewall block | ||||
| Wrong DHCP options | ||||
| Rogue DHCP server | ||||
| Duplicate IP |
66. Fault Isolation Example 1
Section titled “66. Fault Isolation Example 1”Observation:
CLIENT01:169.254.x.xWireshark:
DiscoverDiscoverDiscoverGateway configuration:
No DHCP relayDHCP server:
Located on another subnetRoot cause:
Missing DHCP Relay67. Fault Isolation Example 2
Section titled “67. Fault Isolation Example 2”Observation:
Existing clients work.
New clients fail DHCP.Server:
RunningScope:
Active
Available addresses:0Root cause:
DHCP Scope Exhaustion68. Fault Isolation Example 3
Section titled “68. Fault Isolation Example 3”Client:
10.10.20.120/24Gateway:
10.10.20.254Expected gateway:
10.10.20.1Root cause:
Incorrect DHCP Router/Gateway Option69. Fault Isolation Example 4
Section titled “69. Fault Isolation Example 4”Clients receive:
10.10.99.xExpected:
10.10.20.xInvestigate:
Wrong VLAN
Rogue DHCP
Incorrect Scope
Relay Selection70. Create the Root Cause Statement
Section titled “70. Create the Root Cause Statement”Avoid:
DHCP problem.Use:
New VLAN 20 clients failed to receive IPv4 configurationbecause the DHCP relay statement was removed from theVLAN 20 gateway during a router configuration change.
Existing clients remained operational because theirprevious DHCP leases had not yet expired.This explains:
What Failed
Why
Who Was Affected
Why Some Users Still Worked71. Plan the Corrective Action
Section titled “71. Plan the Corrective Action”Before remediation:
Current State:
Expected State:
Proposed Change:
Affected Scope:
Risk:
Rollback Plan:
Approval Required:72. Implement the Minimum Required Change
Section titled “72. Implement the Minimum Required Change”Examples:
Restore Correct DHCP Relayor:
Correct DHCP Optionor:
Expand Approved DHCP PoolDo not automatically restart every DHCP service.
73. Scope Exhaustion Remediation
Section titled “73. Scope Exhaustion Remediation”Depending on root cause, remediation may include:
Expand Pool
Reclaim Expired Leases
Remove Invalid Reservations
Adjust Lease Duration
Increase Subnet CapacitySubnet expansion should follow approved network design and change control.
74. Wrong DHCP Option Remediation
Section titled “74. Wrong DHCP Option Remediation”Correct only the incorrect option.
Example:
Gateway:10.10.20.254change to:
10.10.20.1Then force a test client to obtain new configuration.
75. Verify Client Renewal
Section titled “75. Verify Client Renewal”Run:
ipconfig /releaseipconfig /renewipconfig /allConfirm:
Correct Address
Correct Mask
Correct Gateway
Correct DNS
Correct DHCP Server76. Verify Gateway Connectivity
Section titled “76. Verify Gateway Connectivity”Run:
ping <DEFAULT-GATEWAY>Expected:
SUCCESS77. Verify Remote Connectivity
Section titled “77. Verify Remote Connectivity”Run:
ping <REMOTE-IP>Then validate required applications.
78. Verify DNS
Section titled “78. Verify DNS”Run:
nslookup <internal-hostname>This confirms the DHCP-provided DNS configuration is usable.
79. Verify Multiple Clients
Section titled “79. Verify Multiple Clients”Do not test only one endpoint when multiple users were affected.
Use:
CLIENT01
CLIENT02
CLIENT03Verify independent leases.
80. Verify DHCP Server Lease Database
Section titled “80. Verify DHCP Server Lease Database”Confirm new leases appear with:
Correct Client
Correct Address
Correct Scope
Expected Lease Duration81. Verify DORA
Section titled “81. Verify DORA”Capture a fresh lease acquisition.
Expected:
Discover↓Offer↓Request↓ACK82. Compare Before and After
Section titled “82. Compare Before and After”Use:
| Test | Before | After |
|---|---|---|
| IP address | ||
| Subnet mask | ||
| Gateway | ||
| DNS | ||
| DHCP server | ||
| Gateway ping | ||
| Remote connectivity | ||
| DNS query |
83. Verify Monitoring
Section titled “83. Verify Monitoring”Check:
DHCP Server Availability
Scope Utilization
Address Pool Capacity
Relay/Gateway Availability
Packet Loss
Related Alerts84. Review Syslog
Section titled “84. Review Syslog”Search for:
DHCP Server Events
Relay Changes
Interface Changes
VLAN Changes
Configuration ChangesCorrelate timestamps with the incident.
85. Build an Incident Timeline
Section titled “85. Build an Incident Timeline”Example:
| Time | Event | Source |
|---|---|---|
| 09:00 | Router configuration changed | Syslog |
| 09:05 | New client DHCP failures begin | Service Desk |
| 09:10 | APIPA alert reported | Support |
| 09:18 | Missing relay identified | Technician |
| 09:23 | Relay restored | Change Record |
| 09:24 | DHCP Offer observed | Wireshark |
| 09:25 | Clients receive leases | Validation |
86. Escalation Criteria
Section titled “86. Escalation Criteria”Escalate when:
-
DHCP server is unavailable and managed by another team
-
address-space redesign is required
-
subnet exhaustion requires architecture changes
-
duplicate DHCP servers cannot be identified safely
-
rogue DHCP activity is suspected
-
DHCP database corruption is suspected
-
production failover configuration requires specialist intervention
-
routing or firewall changes exceed your authority
-
incident may involve malicious network activity
87. Rogue DHCP Escalation
Section titled “87. Rogue DHCP Escalation”If an unauthorized DHCP server is suspected, treat it as both:
Network Incident+Security IncidentPreserve:
Packet Capture
Server Identifier
MAC Address
Switch Port
Timestamps
Affected Clientsbefore remediation where possible.
88. Prepare an Escalation Package
Section titled “88. Prepare an Escalation Package”Include:
Incident ID
Affected VLAN
Affected Scope
Affected Clients
Client IP Configuration
DHCP Server
Scope Status
Lease Utilization
Packet Capture
DORA Stage Where Failure Occurs
Relay Configuration
Firewall/Routing Findings
Changes Already Made89. Example Escalation
Section titled “89. Example Escalation”INC-DHCP-3051
New VLAN 20 clients cannot obtain DHCP leases.
Clients successfully transmit DHCP Discover frames.
No DHCP Offer is observed.
The VLAN 20 gateway contains the correct relay destination10.10.30.53.
RTR01 can reach 10.10.30.53.
DHCP server is online, but VLAN 20 scope reports zeroavailable addresses.
Existing leased clients remain functional.
No scope changes made because subnet expansion requiresNetwork Engineering approval.90. DHCP Troubleshooting Decision Tree
Section titled “90. DHCP Troubleshooting Decision Tree”Client Has Wrong / No IP ↓DHCP Enabled? ┌───┴───┐ NO YES ↓ ↓ Static Valid VLAN? Config ┌───┴───┐ NO YES ↓ ↓ VLAN Discover Sent? ┌───┴───┐ NO YES ↓ ↓ Client Offer Received? ┌───┴───┐ NO YES ↓ ↓ Server/Relay Request Sent? ┌───┴───┐ NO YES ↓ ↓ Client ACK Received? ┌───┴───┐ NO YES ↓ ↓ Server/Policy Options Correct? ┌───┴───┐ NO YES ↓ ↓ DHCP Opts Validate91. APIPA Decision Tree
Section titled “91. APIPA Decision Tree”169.254.x.x ↓Physical Link Up? ↓Correct VLAN? ↓DHCP Enabled? ↓Discover Sent? ↓Offer Received? ↓Relay Present? ↓DHCP Server Reachable? ↓Scope Active? ↓Addresses Available?92. Wrong Address Decision Tree
Section titled “92. Wrong Address Decision Tree”Client Received Address ↓Correct Subnet? ┌───┴───┐ NO YES ↓ ↓Wrong VLAN Correct Gateway?Wrong Scope ┌───┴───┐Rogue DHCP NO YES ↓ ↓ DHCP Option Correct DNS? ┌───┴───┐ NO YES ↓ ↓ DHCP Option Validate93. Quick Command Reference — Windows
Section titled “93. Quick Command Reference — Windows”ipconfig /allipconfig /releaseipconfig /renewping <gateway>arp -aroute printnslookup <hostname>94. Quick Command Reference — Linux
Section titled “94. Quick Command Reference — Linux”ip addrip routeip neighping <gateway>resolvectl statusUse the appropriate DHCP client controls for the Linux distribution.
95. Quick Switch Reference
Section titled “95. Quick Switch Reference”show interfaces statusshow vlan briefshow interfaces <interface> switchportshow interfaces trunk96. Quick Router Reference
Section titled “96. Quick Router Reference”show ip interface briefshow ip routeshow running-configCheck the relevant client-facing gateway interface for DHCP relay configuration.
97. Wireshark Quick Reference
Section titled “97. Wireshark Quick Reference”| Investigation | Filter |
|---|---|
| DHCP | dhcp |
| BOOTP/DHCP fallback | bootp |
| DHCP server port | udp.port == 67 |
| DHCP client port | udp.port == 68 |
| ARP | arp |
| ICMP | icmp |
98. Common DHCP Problems
Section titled “98. Common DHCP Problems”| Problem | Typical Symptom |
|---|---|
| DHCP disabled on client | Static/no automatic lease |
| DHCP server down | No Offer |
| Scope inactive | No leases |
| Scope exhausted | Existing clients work, new clients fail |
| Missing relay | Remote VLAN clients fail |
| Wrong relay target | Requests sent to wrong server |
| Wrong VLAN | Client receives wrong network/no lease |
| Wrong gateway option | Local works, remote fails |
| Wrong DNS option | IP works, names fail |
| Wrong subnet mask | Incorrect local/remote behavior |
| Rogue DHCP | Unexpected gateway/DNS/network |
| Duplicate IP | Intermittent connectivity |
| Static address inside pool | Conflict risk |
| Wrong reservation | Device gets unexpected address |
99. Operational Checklist
Section titled “99. Operational Checklist”Incident Intake
Section titled “Incident Intake”-
Incident ID created
-
Exact symptom documented
-
Scope identified
-
Business impact determined
-
Recent changes reviewed
Endpoint
Section titled “Endpoint”-
Physical connectivity verified
-
DHCP enabled
-
IP address checked
-
APIPA checked
-
Subnet mask checked
-
Gateway checked
-
DNS checked
-
DHCP server identified
-
Correct switch port identified
-
Correct VLAN verified
-
Wireless VLAN mapping checked where applicable
-
Trunk path verified where required
DHCP Exchange
Section titled “DHCP Exchange”-
Discover observed
-
Offer observed
-
Request observed
-
ACK observed
-
NAK checked where relevant
-
Transaction documented
DHCP Server
Section titled “DHCP Server”-
Service running
-
Server reachable
-
Scope exists
-
Scope active
-
Pool correct
-
Available addresses checked
-
Lease duration reviewed
-
Reservations reviewed
-
Exclusions reviewed
DHCP Options
Section titled “DHCP Options”-
Subnet mask correct
-
Gateway correct
-
DNS server correct
-
Domain settings correct where used
DHCP Relay
Section titled “DHCP Relay”-
Remote DHCP requirement identified
-
Relay configured
-
Relay destination correct
-
Router can reach DHCP server
-
Return route verified
-
UDP 67/68 permitted
Address Conflicts
Section titled “Address Conflicts”-
Duplicate IP considered
-
Static/DHCP overlap checked
-
ARP entries reviewed
-
Rogue DHCP considered
Remediation
Section titled “Remediation”-
Root cause identified
-
Current configuration documented
-
Proposed change documented
-
Risk assessed
-
Rollback considered
-
Minimum required change implemented
Verification
Section titled “Verification”-
Lease renewed
-
Correct IP obtained
-
Correct mask obtained
-
Correct gateway obtained
-
Correct DNS obtained
-
Gateway reachable
-
Remote network reachable
-
DNS working
-
Multiple clients validated
-
Lease appears on server
-
Monitoring returned to normal
Closure
Section titled “Closure”-
Root cause documented
-
Corrective action documented
-
Preventive recommendation documented
-
Affected users confirmed recovery
-
Incident closed
100. Incident Documentation Template
Section titled “100. Incident Documentation Template”# DHCP and IP Addressing Incident
## Incident Information
Incident ID:
Date:
Start Time:
Resolution Time:
Severity:
## Business Impact
## Affected Users
## Affected VLAN
## Affected Subnet
## Reported Symptoms
## Incident Scope
## Recent Changes
## Client Configuration
IP Address:
Subnet Mask:
Default Gateway:
DNS:
DHCP Enabled:
DHCP Server:
Lease Information:
## VLAN Validation
## DHCP Packet Analysis
### Discover
### Offer
### Request
### ACK / NAK
## DHCP Server Investigation
Server:
Scope:
Scope State:
Pool:
Available Addresses:
Lease Duration:
Reservations:
Exclusions:
## DHCP Relay Investigation
Gateway:
Relay Target:
Routing:
Firewall:
## DHCP Options
Subnet Mask:
Gateway:
DNS:
## Duplicate Address Investigation
## Root Cause
## Corrective Action
## Verification
## Monitoring Status
## Preventive Recommendation
## Escalation
## Final Status
RESOLVED / ESCALATED101. Preventive Recommendations
Section titled “101. Preventive Recommendations”Depending on the incident, consider:
DHCP Scope Utilization Monitoring
Capacity Alerts
Configuration Backups
DHCP Failover
Address Management
IPAM
Standardized Lease Durations
Reservation Documentation
Static/Dynamic Range Separation
Relay Configuration Monitoring
Rogue DHCP Detection
Change Control102. Example Preventive Action — Scope Exhaustion
Section titled “102. Example Preventive Action — Scope Exhaustion”Instead of:
Monitor DHCP better.write:
Generate a warning when VLAN 20 DHCP scope utilizationreaches 80% and a critical alert when utilization reaches90%, allowing capacity remediation before new clientsfail to obtain leases.103. Example Preventive Action — Relay Failure
Section titled “103. Example Preventive Action — Relay Failure”Use:
Include DHCP relay statements in automated routerconfiguration backups and post-change validation for allclient VLAN gateway interfaces.104. Example Preventive Action — Duplicate IP
Section titled “104. Example Preventive Action — Duplicate IP”Use:
Maintain separate documented static, reserved, anddynamic address ranges and validate that manuallyconfigured infrastructure addresses never overlap withactive DHCP pools.105. Runbook Success Criteria
Section titled “105. Runbook Success Criteria”The runbook is successfully completed when:
DHCP Client=Correctly ConfiguredDHCP Exchange=SuccessfulScope=Available and CorrectRelay=OperationalIP Address=CorrectGateway=CorrectDNS=CorrectConnectivity=Validatedand:
Root Cause=DocumentedRunbook Review
Section titled “Runbook Review”DHCP troubleshooting should not stop at:
Client has 169.254.x.x.That only tells you:
Expected IPv4 ConfigurationWas Not ObtainedThe real investigation asks:
Did the client request an address? ↓Did the request reach the server? ↓Did the server have the correct scope? ↓Was an address available? ↓Did the server send an Offer? ↓Did the client Request it? ↓Did the server ACK it? ↓Were the DHCP options correct? ↓Can the client actually use the resulting configuration?Likewise:
Valid IP Addressdoes not automatically mean:
Valid Network Configurationbecause the client can still receive:
Wrong Subnet Mask
Wrong Gateway
Wrong DNS
Wrong VLAN
Wrong DHCP ServerThe professional operational workflow is:
Client ↓VLAN ↓DHCP Request ↓Relay ↓DHCP Server ↓Scope ↓Lease ↓Options ↓Gateway ↓DNS ↓ApplicationThe objective of DHCP troubleshooting is not simply to obtain an IP address. It is to prove that the client received the correct network configuration from the correct DHCP infrastructure, can use that configuration successfully, and that the underlying cause of the failure has been identified and documented.
What’s Next?
Section titled “What’s Next?”Runbook 04 — DNS Troubleshooting
Section titled “Runbook 04 — DNS Troubleshooting”The next runbook focuses on enterprise name-resolution incidents involving:
-
incorrect DNS server configuration
-
DNS server unavailability
-
missing DNS records
-
incorrect A and AAAA records
-
PTR failures
-
CNAME problems
-
DNS timeouts
-
NXDOMAIN responses
-
stale DNS cache
-
incorrect hosts-file entries
-
DNS suffix problems
-
DNS forwarders
-
UDP/TCP port 53
-
firewall filtering
-
DNS packet analysis
-
DNS service failures
-
remediation and verification
The operational progression becomes:
IP Address Assignment ↓Gateway Connectivity ↓DNS Client Configuration ↓DNS Query ↓Resolver ↓Authoritative Data ↓Name Resolution ↓Application Connectivity➡️ Next: Runbook 04 — DNS Troubleshooting