DHCP and DNS perform different but connected jobs. DHCP gives a device the network settings required for communication, while DNS translates names such as www.example.com into IP addresses that devices can use.
A laptop normally uses DHCP first to obtain its address, subnet mask, default gateway and DNS server addresses. It can then send DNS queries when a user opens a website or connects to another named service.
What Is the Difference Between DHCP and DNS?
DHCP automatically supplies IP configuration to clients. DNS maps domain and host names to records, including IPv4 and IPv6 addresses.
| Feature | DHCP | DNS |
|---|---|---|
| Full name | Dynamic Host Configuration Protocol | Domain Name System |
| Main purpose | Assign network settings | Resolve names and other DNS records |
| Common server ports | UDP 67 for server, UDP 68 for client | UDP 53 and TCP 53 |
| Typical client result | IP address, mask, gateway and DNS servers | An IP address or another DNS record |
| Uses broadcasts? | Initial IPv4 exchange usually does | Normal DNS queries are usually unicast |
| Information lifetime | Controlled by a DHCP lease | Controlled by the DNS record's TTL |
DHCP does not resolve website names, and DNS does not normally assign client addresses. A DHCP server can, however, tell clients which DNS servers and DNS search domain they should use.
How Does DHCP Assign an IPv4 Address?
DHCP commonly uses a four-message process called DORA: Discover, Offer, Request and Acknowledgement. The first messages are broadcasts because a new client does not yet have a usable IP configuration or know the server's address.
DHCP DORA diagram in words
Imagine a new laptop connected to an access switch:
Laptop Access switch DHCP server
| | |
|-- DHCPDISCOVER -->|---- broadcast ---->|
|<-- DHCPOFFER -----|<--------------------|
|-- DHCPREQUEST --->|-------------------->|
|<-- DHCPACK -------|<--------------------|
|
| Client configures the offered addressThe messages perform these functions:
- DHCPDISCOVER: The client searches for available DHCP servers. It normally sends from
0.0.0.0:68to255.255.255.255:67. - DHCPOFFER: A server proposes an address and configuration options.
- DHCPREQUEST: The client identifies the selected offer and requests that address. Broadcasting this message also informs other servers that their offers were not selected.
- DHCPACK: The selected server confirms the lease and options. The client can then configure its interface.
The acknowledgement may include the subnet mask, default gateway, DNS server addresses, domain name and lease duration. DHCP options identify these values; for example, option 3 supplies routers and option 6 supplies DNS servers.
Before using an address, some clients perform duplicate address detection using ARP. If a conflict is detected, the client can reject the address and restart the process.
Understanding Ethernet broadcasts also helps explain why the initial request remains within its local VLAN. See how switching handles frames and broadcasts for the Layer 2 background.
What Happens When a DHCP Lease Expires?
A DHCP address is leased rather than permanently assigned. The client attempts to renew before the lease ends so that normal users rarely notice the process.
By default, clients generally begin unicast renewal at T1, which is 50% of the lease duration. If renewal fails, they usually enter rebinding at T2, 87.5% of the lease, and broadcast a request that any suitable server can answer. Servers can provide different T1 and T2 values.
If the lease fully expires without renewal, the client must stop using the address. It returns to the initial DHCP process to obtain valid configuration.
A DHCP reservation differs from a manually configured static address. A reservation makes the DHCP server consistently offer a particular address to a client identifier or MAC address, while still centrally delivering options such as DNS servers.
How Does DHCP Work Across Routers and VLANs?
Routers do not normally forward local broadcasts, so a client cannot directly discover a DHCP server in another subnet. A DHCP relay receives the local broadcast and forwards it as a unicast packet to the configured server.
Diagram in words:
VLAN 10 client --broadcast--> VLAN 10 gateway/relay
|
| unicast relay message
v
Central DHCP serverThe relay adds gateway information, commonly through the giaddr field. The server uses that information to select the correct address pool for the client's subnet, then returns the response through the relay.
On Cisco IOS, configure the relay on the Layer 3 interface that receives client broadcasts:
interface GigabitEthernet0/1
description VLAN 10 gateway
ip address 192.168.10.1 255.255.255.0
ip helper-address 10.20.30.10
no shutdownThe ip helper-address command forwards selected UDP services, including DHCP, rather than every broadcast. The relay interface must have IP connectivity to the server, and the server must have a scope for 192.168.10.0/24.
How Do You Configure a Cisco IOS DHCP Server?
A Cisco router or multilayer switch can provide DHCP in a lab or smaller network. Create exclusions for infrastructure addresses, define a pool and specify the client options.
This example reserves addresses .1 through .20 and leases the remaining pool addresses for seven days:
ip dhcp excluded-address 192.168.10.1 192.168.10.20
ip dhcp pool USERS
network 192.168.10.0 255.255.255.0
default-router 192.168.10.1
dns-server 192.168.50.10 1.1.1.1
domain-name lab.example
lease 7
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
no shutdownThe network command identifies the pool's subnet; it does not configure an interface. The default-router value should normally be the gateway reachable by clients in that subnet.
Useful verification commands are:
show ip dhcp pool
show ip dhcp binding
show ip dhcp conflict
show ip dhcp server statistics
show running-config | section dhcpshow ip dhcp pool displays utilisation and available addresses. show ip dhcp binding maps leased addresses to client identifiers and lease expiration times, while show ip dhcp conflict identifies addresses removed from allocation because of detected conflicts.
A Cisco interface acting as a DHCP client can be configured with:
interface GigabitEthernet0/0
ip address dhcp
no shutdownThese configurations and packet flows are useful practical exercises in a structured CCNA course, where DHCP is studied with VLANs, routing and network services.
How Does DNS Resolve a Domain Name?
DNS uses a distributed hierarchy instead of one server containing every name. A client normally asks a recursive resolver, which returns a cached answer or queries other DNS servers on the client's behalf.
Suppose a client needs the IPv4 address for www.example.com:
Application
|
v
Operating-system stub resolver
|
v
Recursive DNS resolver
|-- asks a root server where .com is served
|-- asks a .com TLD server where example.com is served
|-- asks example.com's authoritative server for www
v
Returns the answer to the client and caches itThe root and top-level domain servers usually provide referrals rather than the final host address. The authoritative server stores the zone data and supplies the requested record. If the recursive resolver already has an unexpired cached answer, it can respond without repeating the complete hierarchy.
The time to live, or TTL, states how long a record may be cached. A lower TTL allows changes to be noticed sooner but can increase query volume; a higher TTL reduces repeated lookups but keeps old answers cached longer.
Common DNS record types
| Record | Purpose | Example use |
|---|---|---|
| A | Maps a name to an IPv4 address | Web server at 192.0.2.20 |
| AAAA | Maps a name to an IPv6 address | Web server at 2001:db8::20 |
| CNAME | Creates an alias for another name | portal points to a canonical host |
| MX | Identifies mail exchangers | Domain email delivery |
| NS | Identifies authoritative name servers | Delegating a DNS zone |
| PTR | Maps an address back to a name | Reverse DNS lookup |
| TXT | Stores text data | Domain verification or email policies |
| SOA | Describes zone authority and timers | Zone administration |
Most standard queries use UDP port 53. DNS can use TCP port 53 for operations such as zone transfers and when a response requires TCP; modern implementations may also retry over TCP after receiving a truncated UDP response. Encrypted DNS methods, including DNS over HTTPS and DNS over TLS, use different transports and can affect packet-level troubleshooting.
How Do DHCP and DNS Work Together?
DHCP gives the client a DNS resolver address, and the client sends name queries to that resolver. Both services must work for a typical device to reach an internet service by name.
Consider this sequence:
- A laptop receives
192.168.10.25/24from DHCP. - It also receives gateway
192.168.10.1and DNS server192.168.50.10. - The user opens
intranet.lab.example. - The laptop queries
192.168.50.10for the name. - DNS returns
192.168.60.20. - The laptop checks its subnet, recognises that the destination is remote and sends the packet to its default gateway.
This distinction is important during fault isolation. If a client can ping an IP address but not a hostname, its address and routing may be functional while DNS has failed. If it has no valid address, gateway or route, DNS queries may never reach the resolver.
In managed environments, a DHCP server may also coordinate dynamic DNS updates. The exact behaviour depends on the DHCP and DNS platforms, update permissions and security policy; receiving a DHCP lease does not automatically guarantee that a DNS record will be created.
How Can You Verify DHCP and DNS from a Client?
Start by checking the assigned address, route and resolver configuration. Then test DNS directly instead of relying only on a browser, which may use caches or encrypted DNS.
Windows commands
ipconfig /all
ipconfig /release
ipconfig /renew
ipconfig /flushdns
nslookup www.example.com
nslookup www.example.com 192.168.50.10In ipconfig /all, check whether DHCP is enabled and verify the IPv4 address, mask, lease times, gateway, DHCP server and DNS servers. The second nslookup command queries a specific resolver, helping separate client configuration problems from server problems.
Linux commands
ip address show
ip route show
resolvectl status
nmcli device show
getent hosts www.example.com
dig www.example.com
dig @192.168.50.10 www.example.com Aip address show confirms interface addressing, and ip route show should reveal a connected route and usually a default route. resolvectl status is useful on systems using systemd-resolved; /etc/resolv.conf may point to a local stub rather than list the upstream resolver directly.
dig displays the response status, answer section, responding server and query time. getent hosts tests name resolution through the operating system's configured Name Service Switch path, which may include sources other than DNS.
A packet capture can confirm whether requests leave and responses return:
sudo tcpdump -ni any '(udp port 67 or udp port 68) or port 53'Run captures only on systems and networks where you have permission. For a broader fault-isolation workflow, follow this layer-by-layer network troubleshooting method.
How Do You Troubleshoot Common DHCP and DNS Failures?
Troubleshoot DHCP before DNS when a client lacks valid network settings. Verify each dependency in order rather than repeatedly renewing the address or changing resolver settings.
Client receives no DHCP address
A Windows address in 169.254.0.0/16 is an Automatic Private IP Addressing result and often indicates that no DHCP lease was obtained. On Linux, the symptoms depend on the network manager and configuration.
Check the following:
- Confirm that the interface and switch port are up.
- Verify that the port belongs to the expected VLAN.
- Confirm the DHCP scope has free addresses.
- Check exclusions, reservations and conflict records.
- For a remote server, verify
ip helper-addresson the client gateway. - Verify routes and access control lists between relay and server.
- Capture traffic to determine whether Discover, Offer, Request and ACK messages appear.
If Discover is visible but no Offer returns, focus on the relay, server, scope and return path. If Offer arrives but the client never sends Request, investigate the client, duplicate-address detection or malformed options.
Client has an address but cannot browse by name
First test the gateway and a known permitted destination by IP. Then inspect the configured DNS server and query it directly with nslookup or dig.
Common causes include an incorrect DHCP option 6 value, an unreachable resolver, blocked UDP or TCP port 53, an absent record, an expired zone, or stale cached data. A NXDOMAIN response means the queried name does not exist according to the responding DNS path; a timeout means no usable response arrived and requires different investigation.
Do not assume that flushing a client cache fixes every DNS problem. It removes locally cached entries but cannot repair an incorrect authoritative record, delegation problem or unreachable server.
What Security Risks Affect DHCP and DNS?
A rogue DHCP server can provide an attacker-controlled gateway or DNS resolver, while DNS manipulation can redirect users to unintended systems. Access controls, monitoring and secure switch features reduce these risks.
DHCP snooping on supported switches can classify trusted server-facing ports and reject unauthorised server messages on untrusted access ports. Its binding table may also support features such as Dynamic ARP Inspection and IP Source Guard, but these features require careful topology-aware configuration.
DNS controls can include restricted zone transfers, protected dynamic updates, resolver access policies, logging and DNSSEC validation where appropriate. DNSSEC helps validate the authenticity and integrity of signed DNS data; it does not encrypt the query contents.
Summary
DHCP supplies an IP address and essential network options through the Discover, Offer, Request and ACK process. DNS then translates names into records, usually through a recursive resolver that uses caching and the DNS hierarchy.
When troubleshooting, verify the physical connection, VLAN, DHCP lease, default route and DNS server in that order. Use Cisco show commands, operating-system tools and authorised packet captures to identify exactly where the exchange stops.
To practise DHCP pools, relay configuration, DNS verification and other routing and switching labs, enquire about upcoming batch details for the Network Rhinos CCNA course.
Reviewed by Network Rhinos networking trainers.
