Skip to content

DHCP

Summary

  • DHCP (Dynamic Host Configuration Protocol) automatically assigns an IP address — plus a subnet mask, default gateway, DNS servers, and other configuration — to a device joining a network, so nothing has to be configured by hand.
  • It works through a four-message exchange known by the acronym DORA: Discover, Offer, Request, Acknowledge.
  • The assignment isn't permanent — it's a time-limited lease, which the client has to periodically renew or risk losing.

The DORA Process

A device with no IP address yet can't unicast anything — it doesn't have an address to send from. So the entire initial exchange happens over broadcast, using the default route-less, address-less state every device starts in:

  1. Discover — the client broadcasts a DHCPDISCOVER, essentially asking "is there a DHCP server out there?" — sent to the broadcast address 255.255.255.255 since the client has no IP of its own yet to receive a unicast reply
  2. Offer — any DHCP server that hears the Discover responds with a DHCPOFFER, proposing a specific IP address and lease terms
  3. Request — the client broadcasts a DHCPREQUEST, explicitly accepting one particular offer — broadcast rather than unicast, so that other servers that also made offers know their offers weren't chosen and can release those addresses back into their pool
  4. Acknowledge — the chosen server confirms with a DHCPACK, finalizing the lease; the client now has a usable IP address and can start normal communication

The DORA Process

Renewal skips straight to Request/Acknowledge

Once a client already has an address, renewing an existing lease doesn't repeat the full DORA cycle — it just sends a unicast DHCPREQUEST directly to the server it got the lease from, and gets a DHCPACK back. Full DORA only happens on a genuinely fresh start (or if that direct renewal fails).

DHCP Options

Beyond just an IP address, a DHCP exchange carries a whole set of options — additional configuration fields the server can hand the client in the same Offer/Ack messages:

Option Number Purpose
Subnet Mask 1 The subnet mask for the assigned address
Router 3 The default gateway
Domain Name Server 6 One or more DNS servers to use
Domain Name 15 The local domain name
Requested IP Address 50 Client → server: "I'd like this specific address again" (used on renewal/re-request)
IP Address Lease Time 51 How long the lease is valid for, in seconds
DHCP Message Type 53 Which DORA message this is (Discover/Offer/Request/Ack, etc.)
Server Identifier 54 Identifies which DHCP server sent this message
Client Identifier 61 How the client identifies itself to the server (often its MAC address)

Common DHCP Options

The Lease Lifecycle

A DHCP lease isn't just "valid" or "expired" — it moves through renewal checkpoints, each a fraction of the total lease time:

  • T1 (50% of lease time) — the client attempts to renew directly with the server that issued the lease (unicast)
  • T2 (87.5% of lease time) — if T1's renewal attempt got no response, the client broadcasts instead, willing to accept a renewal from any DHCP server, not just the original one
  • Expiration (100% of lease time) — if neither renewal attempt succeeded, the lease is no longer valid and the client must start over with a fresh DORA exchange

DHCP Lease Renewal Timeline (T1 / T2 / Expiration)

A device can lose its address mid-session

If a client is offline (asleep, out of range) through T1, T2, and expiration, it comes back with an IP address it's no longer actually entitled to — the next thing it does is try to renew, and if that specific address is no longer available, it has to accept a different one entirely.

DHCPv6

IPv6 complicates the picture, because SLAAC already lets a device configure its own address without any DHCP server at all. DHCPv6 still exists, in two different modes:

  • Stateful DHCPv6 — the server actually assigns and tracks specific addresses, much like DHCPv4
  • Stateless DHCPv6 — the device gets its address via SLAAC, but still queries a DHCPv6 server only for additional configuration (DNS servers, domain search list) that SLAAC's router advertisements don't carry

Inspecting and Managing DHCP on Linux

# Request/renew a lease on demand
sudo dhclient eth0

# Release a currently held lease
sudo dhclient -r eth0

# View the current lease details (path varies by distro/client)
cat /var/lib/dhcp/dhclient.leases

# Watch DHCP traffic live
sudo tcpdump -i eth0 port 67 or port 68

Ports 67 and 68

DHCP runs over UDP: the server listens on port 67, and the client listens on port 68 — this is exactly why a tcpdump filter on those two ports catches the whole DORA exchange.

Useful Resources