Introduction to DHCP

IP addresses can be configured statically or dynamically. Normally we configure static IP addresses on network devices like routers, switches, firewalls and servers while we dynamically assign IP addresses to computers, laptops, tablets, smartphones etc. The dynamic method uses DHCP (Dynamic Host Configuration Protocol) and in this short lesson I want to show you how it works.

Let’s take a look at the following picture:

dhcp topology

On the left side we have a computer without IP address. On the right side there’s a DHCP server configured with static IP address This DHCP server will supply an IP address to our computer, this is how it works:

dhcp discover

The computer will send a DHCP discover message. This is a broadcast because it doesn’t have an IP address and it doesn’t know if there is a DHCP server on the network. Of course in our scenario we do have a DHCP server so it will respond to this broadcast as following:

dhcp offer

The DHCP server will respond with a DHCP offer message which contains an IP address for the computer (we have to configure the DHCP server to define which IP addresses we want to give). If we want we can also assign a default gateway and DNS server(s) to the computer. The computer will respond to this information:

dhcp request

The computer will send a DHCP Request in response to the DHCP offer message, asking nicely if it’s OK to use the information that it has received. Our DHCP server will respond to this as following:

The DHCP server will respond with a DHCP ACK message to tell the computer it’s OK to use this information. Now you have an idea what DHCP is like, let’s take a closer look at the packages in wireshark:

Wireshark DHCP capture

Above you see the 4 DHCP packets in wireshark. If you want to capture this yourself you need to filter on bootp messages since DHCP uses the bootstrap protocol. In the DHCP discover message you can see that the computer has no IP address ( and is broadcasting this to IP address The DHCP offer is from our DHCP server (

wireshark DHCP discover capture

Above you see the DHCP discover message. First of all you see the source MAC address of the computer and the destination MAC address is FF:FF:FF:FF:FF:FF (broadcast). It doesn’t have an IP address ( DHCP uses the bootstrap protocol and you can see the source port (68) and destination port (67). Now let’s take a closer look at the DHCP offer:

We're Sorry, Full Content Access is for Members Only...

If you like to keep on reading, Become a Member Now! Here is why:

  • Learn any CCNA, CCNP and CCIE R&S Topic. Explained As Simple As Possible.
  • Try for Just $1. The Best Dollar You’ve Ever Spent on Your Cisco Career!
  • Full Access to our 791 Lessons. More Lessons Added Every Week!
  • Content created by Rene Molenaar (CCIE #41726)

1646 Sign Ups in the last 30 days

100% Satisfaction Guaranteed!
You may cancel your monthly membership at any time.
No Questions Asked!

Tags: ,

Forum Replies

  1. great explanation…thanx Rene

  2. Awesome work Rene …appreciate it !!

  3. Rene,

    More one time, thanks for good explanation!!!


  4. JOb well done to explain this in simple way, yet offer a good level of detail.

  5. Hi Rene,

    From the wireshark capture I understand that all the DHCP (Discover, Offer, Request and Ack) messages are layer 2 and layer 3 broadcast messages.

    Why is it so?

    I read somtime back (Request and Ack) messages. can be unicast message . Is it possible ?

    Could you please explain how to configure it?



68 more replies! Ask a question or join the discussion by visiting our Community Forum