Sections:
Overview:
Use Case Scenarios:
DORA DHCP Process
The D.O.R.A acronym in DHCP refers to the DHCP steps used by a client to obtain an IP address and other configuration settings from a DHCP server.
Discover
Offer
Request
Acknowledge
Cisco DHCP Features
A Cisco Router has the ability to function and run as a full DHCP server implementation that assigns and manages IP addresses from specified address pools to DHCP clients.
Cisco devices can support the following roles and features:
DHCP Server
Routers and certain layer 3 switches can operate as a DHCP server and maintain a pool of IP addresses to assign to DHCP clients. This feature can be a cost effective option for small office or home office networks with a small amount of clients. While Cisco routers can provide basic DHCP server functionality, they may lack some advanced features offered by dedicated DHCP servers for medium to large sized networks.
DHCP Client
By using a Cisco router or layer 3 switch as a DHCP client, the device will receive its IP address and other network configuration details dynamically from another DHCP server on the network. This case is common for scenarios in which the Cisco device is at the edge of the network connecting to an ISP (Internet Service Provider) however not suited for cases in which you require services like remote access or Site to site VPNs. Static IP address assignments will be better suited for VPN services.
DHCP Relay Agent
A DHCP Relay agent is a feature in which a device forwards DHCP messages between DHCP clients and a DHCP server when they are located on different networks. The relay agent acts as an intermediary, helping DHCP clients obtain IP addresses when the server is not on same local network. Cisco routers and certain layer 3 switch devices are capable of using the relay feature.
DHCP Snooping
DHCP snooping is a security feature that is configured and implemented on Cisco and other vendor switches that helps protect a network from malicious DHCP servers. DHCP Snooping ensures that only authorized DHCP servers are allowed to assign IP addresses to clients.
DAI Dynamic ARP Inspection
DAI often paired with DHCP Snooping, is a security feature configured and implemented on Cisco and other vendor switches to protect against ARP spoofing and poison attacks. DAI ensures that only valid ARP requests and responses are allowed on the network to prevent rogue devices from impersonating authorized devices by sending spoofed ARP messages.