1Session at a glance
Objectives
- Name the four settings in a lease and say what breaks when each one is missing.
- Describe the four-message exchange and say why two of the messages are broadcast.
- Explain why a DHCP failure produces symptoms hours later.
- Choose between a reservation and a static address, with a reason.
- Name the order a Windows machine resolves a name in, and use that order to place a fault.
Before the session
ipconfig /allalready run on the demo machine, with the lease times visible.- A site open in the UniFi console at a network's settings, with the address range, lease time and DNS (Domain Name System) servers on screen, and a device with a reservation already located.
- A real internal name and a public name chosen for the
nslookupdemo. - Everyone at a machine with a command prompt, and the Learner Guide open.
| Time | Block | What happens |
|---|---|---|
| 0:00 | Open | A server that failed at nine, and the first ticket about it at four. |
| 0:04 | Concept | What a lease contains (4), the four-message exchange (4), leases and renewal (4), reservations and second servers (5), how a name is resolved (4), records and time to live (3). |
| 0:28 | Show | Live: ipconfig /all read in full, the same settings from the console side, a reservation, then nslookup against an internal and a public name. |
| 0:37 | Do | Everyone reads their own lease, works out their renewal time, and runs both lookups. |
| 0:49 | Check | Seven questions. |
| 0:56 | Close | The work before session 06, and what that session covers. |
The block that changes how people work tickets is leases and renewal, because it is the one that explains a delayed symptom, and the open is built on it. If the room is behind, cut the record types to A, CNAME and MX and let the Learner Guide carry the rest. Do not cut the resolution order: the last two check questions are unanswerable without it.
Menu names in the UniFi console move between versions. Confirm the paths in the version the site is running before the session rather than in front of the room.
2Open (0:00, 4 minutes)
A server fails at nine in the morning. Nobody calls. It is still failed at eleven and nobody calls. At four in the afternoon one person cannot get on the network, then two more, then five, and by the next morning half the building is down. Every one of those people reports it as their own problem with their own machine, and none of them is wrong. What failed at nine was the service that hands out addresses, and the seven-hour gap between the cause and the first ticket is not a mystery. It is a setting, and you can read it off any machine in ten seconds.
- Do not explain the lease yet. Leave the seven hours hanging and come back to it in the third concept block.
- Say what the hour buys: two services that between them sit behind a large share of faults reported as something else, and both are readable from one command.
3Concept (0:04, 24 minutes)
What a lease contains (4 min)
- Four settings: address, mask, gateway, DNS servers. Walk the table in section 2 of the Learner Guide and give the failure for each rather than just the name.
- Spend the time on the last two, side by side. No gateway means the local network works and nothing beyond it does. No DNS server means addresses work and names do not.
- Then the point of putting them together: a user describes both of those with the same words. The way you separate them is to ask them to reach something by address instead of by name. Say that out loud as the takeaway of the block.
The four-message exchange (4 min)
- Start with the awkward condition, because it explains the design: the device has no address, so it cannot send to anyone in particular and has nothing to send from.
- Walk the four: Discover, Offer, Request, Acknowledge. Broadcast, answer, broadcast, confirm.
- Ask the room why the third message is broadcast rather than sent straight back to the server that offered. Give them a moment before answering: so that any other server that also offered hears the decline and can put that address back.
- Then the two consequences, both of which show up on tickets. The device needs no configuration to find the server. And a broadcast does not cross a router: if a VLAN's own DHCP server lives on a different VLAN (VLAN means virtual local area network), the router has to be set to pass those requests along. When that is missing, one VLAN gets nothing and every other VLAN is fine.
Leases and renewal (4 min)
- Lease length is set on the network. The device tries to renew at the halfway point, and when the server answers, the clock resets and nothing visible happens.
- Then what happens when it does not answer: the device keeps the address and keeps trying, and only gives it up when the lease actually ends.
- Now pay off the open, on the board, with the eight-hour lease. Nine, the server fails and every machine already has a valid lease. One in the afternoon, renewals start failing and nothing visible happens. Late afternoon onwards, machines drop off one at a time as each reaches the end of its own lease. Say the line: the lease length is the delay between the cause and the symptom.
- Close with 169.254, restated as a signal rather than an address: it means the machine asked and nothing answered.
Reservations, and second servers (5 min)
- Reservation against static, as two ways to get the same outcome. Static is typed into the device; the device knows nothing about the network's plan and the network knows nothing about the device.
- Give the two failures that follow from static: a subnet or gateway change leaves that device wrong, and an address inside the automatic range can be handed to something else, which reads as two devices that both work unreliably.
- Then the rule: reservations wherever the device can ask for an address, static only for equipment that has to work before any server does, meaning the gateway and the switches.
- Move to the second server. Most consumer routers run one and have it on by default, so somebody plugging one in for its wireless has just put a second server on the network.
- Say why the damage is random: whichever answers first wins, so some machines are correct and some are not, and it changes every time a machine reconnects.
- Then the two ways to find it: read which server answered on a failing machine, and the switch setting that accepts offers from one address only, which the vendor calls DHCP Guarding and which needs managed switches.
How a name is resolved (4 min)
- Say what DNS is for in one line, and why the failure is so total: nothing on the network routes on names, so this happens before any connection exists.
- Walk the four steps in order, and say that the machine stops at the first answer: own cache, hosts file, configured server, that server's forwarders.
- Then turn the order into the diagnosis, which is the reason to teach it at all. Fails on one machine only, look at the first two. Fails everywhere internally, look at the third. Internal names fine and public names failing, look at the fourth.
Records and time to live (3 min)
- A record and CNAME briefly, then MX with its consequence, because it is the one that produces a whole class of ticket: wrong or missing and mail stops while the website is fine.
- Name SRV and why it matters here: it is how a domain-joined machine finds its domain controllers, which sets up the last check question.
- Then time to live, worked rather than defined. TTL 3,600 is one hour. Change the address at noon, and a machine that looked it up at 11:55 keeps the old answer until 12:55. The record is correct at the source and wrong on that machine at the same time, and both are true.
- Finish with the practical pair: lower the TTL the day before a planned change, and
ipconfig /flushdnsfixes the one machine in front of you and nothing else.
4Show (0:28, 9 minutes)
- Read
ipconfig /allin full. Address, mask, gateway, DNS servers, the DHCP server that answered, and the lease start and end. Point at each as you name it. - Do the lease arithmetic out loud. Subtract start from end to get the lease length, halve it, add it to the start, and say when this machine will next try to renew. This is the open, on a real machine.
- Cross to the console. Open that network's settings and show the same numbers from the other side: the address range, the lease time, the DNS servers handed out. They are the same facts from two directions.
- Show a reservation. Point at the hardware address, the address reserved for it, and the fact that the address sits outside the automatic range. Say what would happen if it did not.
- Then
nslookup. Run it against an internal name and a public one. Read out which server answered each and whether the answer is marked as non-authoritative, meaning it came from a cache rather than from the server that owns the record.
5Do (0:37, 12 minutes)
- Their own lease.
ipconfig /all. Write down all six values, work out the lease length, and work out the renewal time. - Both lookups.
nslookupagainst an internal name and a public one. Write down which server answered each. - Watch a cache expire.
ipconfig /displaydns, find an entry with a time to live counting down, wait a minute, run it again and confirm the number fell. - Place a fault. Give the room three symptoms out loud and have them name which step of the resolution order they would check first: a name that works for one person and not another, a name nothing internal can resolve, and internal names working while public ones fail.
The habit to break is flushing the cache as a first move. It is a fine test and a poor fix: it changes one machine, and if the problem was on the server it will be back within the hour. Make anyone who reaches for it say what they expect it to prove before they run it.
6Check (0:49, 7 minutes)
Name the four settings a device receives in a lease, and say what specifically breaks if the gateway is missing but the other three are correct.
AnswerAddress, subnet mask, default gateway, DNS servers. Without the gateway the machine still reaches everything on its own network, because it delivers those directly, and reaches nothing beyond it, including the internet and every other VLAN at the site.
Why does a device broadcast its acceptance of an offer rather than replying directly to the server that made it?
AnswerSo that any other server that also made an offer hears that its offer was declined and can return that address to its pool. A direct reply would leave those addresses held for nothing.
A DHCP server fails at nine in the morning on a network with an eight-hour lease. Describe what the day looks like from the service desk, and why.
AnswerNothing at nine, because every machine already holds a valid lease. Nothing at one in the afternoon, when renewals begin failing, because the machines keep using what they have. From late afternoon, machines start dropping off one at a time as each reaches the end of its own lease, each reported as an individual problem with an individual machine. The lease length is the gap between the cause and the first ticket.
A printer needs a permanent address. Give the reason a reservation is better than typing an address into the printer, and name the one category of device that should still have an address typed in.
AnswerWith a reservation the server knows the address is taken, so it cannot hand the same one to something else, and a later change to the gateway or the DNS servers reaches the printer along with everything else. A typed address leaves the printer wrong after any such change, and invisible to the server. Type an address only into equipment that has to work before any server does, which means the gateway and the switches.
A user can reach a file server by its IP address but not by its name. Everyone else can reach it by name. Where do you look, in what order, and why is the order what it is?
AnswerThe hosts file on that machine first, then its cache. The order follows the order the machine resolves in, because it stops at the first answer it gets and the hosts file overrides everything below it. Everyone else working proves the server and the record are fine, which is what puts the fault on this machine.
A record's address was changed at noon and the TTL is 3,600 seconds. A machine says the old address at 12:30. Is something broken? What would you do, and what would that fix?
AnswerNothing is broken. A TTL of 3,600 seconds is one hour, so a machine that looked the name up before noon is entitled to keep the old answer until its copy expires.
ipconfig /flushdnson that machine forces a fresh lookup and fixes that machine only.The obvious answer is that the change did not take. It did. The record is correct at the source and stale on that machine at the same time, and both are true until the hour is up. The real fix is upstream of the incident: lower the TTL the day before a planned change so the window is minutes.
A laptop browses the internet perfectly but cannot sign in to the domain, reach file shares, or pick up policy. Its DNS server is set to a public resolver. Explain why the internet works and the rest does not.
AnswerA public resolver knows public names, so browsing works normally. The records that tell a domain-joined machine where its domain controllers are exist only on the internal DNS server, so the machine cannot find them and everything that depends on the domain fails.
The obvious answer is that the DNS setting cannot be the problem, because name resolution is clearly working. It is working for the half of the names that do not matter here. A public resolver on a domain-joined machine is always wrong, however well the internet appears to be running.
7Close (0:56, 4 minutes)
Work before the next session
- The practice steps in section 10 of the Learner Guide, with the lease length and renewal time worked out and brought along.
- The four-message exchange, in order, said from memory with what each message does.
- The Network+ companion, chapter 2, common protocols and ports, and chapter 11, the DHCP and name resolution sections.
Next session
06 - Firewalls and NAT, meaning network address translation. What a firewall decides and in what order, why a reply gets back in without a rule for it, and what translation does to a packet on the way out.
Open items to settle
- Whether DHCP Guarding is enabled at the sites with managed switches, and if not, whether that becomes a piece of work.
- Whether any site has devices with typed addresses that should be reservations, which the console demo may surface.
- Whether lowering a record's time to live before a planned change is written down anywhere, or is currently something people remember.
8Sources
- Internet Engineering Task Force, RFC 2131, Dynamic Host Configuration Protocol, for the four-message exchange, leases and renewal at the halfway point.
- Internet Engineering Task Force, RFC 1035, Domain Names, Implementation and Specification, for record types and time to live.
- Internet Engineering Task Force, RFC 3927, Dynamic Configuration of IPv4 Link-Local Addresses, for the 169.254 range.
- Ubiquiti, UniFi DHCP Server, for what the server supplies and where it is enabled.
- Ubiquiti, Duplicate IP Addresses and Rogue DHCP Servers, for DHCP Guarding and its requirement for managed switches.
- Ubiquiti, UniFi DNS Troubleshooting Guide.
- Microsoft Learn, DNS troubleshooting guidance, for client resolution behavior on Windows.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 2 and chapter 11.
9After the session
| Delivered on | |
| Attendance | |
| What landed | |
| What did not | |
| Changes for next time | |
| Backlog items created |