1The two services behind most faults
This is your copy to keep. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.
Two services do work that nobody notices until they stop. DHCP (Dynamic Host Configuration Protocol) hands a device its addressing when it joins a network. DNS (Domain Name System) turns a name into an address so a person never has to type one.
They are worth an hour together because between them they produce a large share of faults that get reported as something else. A machine with no address is reported as a broken network port. A name that will not resolve is reported as an application being down. Neither report names the cause, and both are found in minutes once you know what each service is supposed to do.
The addresses and names on this page are an example written for training. They are not a client network. The example site's staff network is 192.168.10.0/24 with the gateway at 192.168.10.1.
2What DHCP hands out
A device joining a network needs four things before it can do anything, and DHCP supplies all four in one exchange. Each set of settings DHCP hands out is called a lease, because the device holds them for a fixed period rather than permanently, and the range of addresses available to hand out is called the scope.
| Setting | Example | What breaks without it |
|---|---|---|
| IP address | 192.168.10.115 | Nothing works. The device has no identity on the network |
| Subnet mask | 255.255.255.0 | The device cannot tell which machines are its neighbors, so it sends local traffic to the router and remote traffic nowhere |
| Default gateway | 192.168.10.1 | The local network works and nothing beyond it does, including the internet |
| DNS servers | 192.168.10.10 | Addresses work, names do not. Everything appears broken to a user, and everything is reachable by address |
Read the last two rows together. They are two different faults that a user describes with the same words, and the way you separate them is to ask for an address rather than a name. That is the whole reason this table is worth learning.
3How a device gets a lease
The exchange is four messages, and it has an awkward starting condition: the device has no address yet, so it cannot send to anyone in particular and has nothing to send from.
It solves that with a broadcast, a message addressed to every device on the local network at once. A port is a number that says which program on a machine the data is for, and the exchange uses two of them: 67 for the server and 68 for the client.
- Discover. The device broadcasts "is there a DHCP server here", from port 68, with no source address of its own.
- Offer. A server answers with an address it is willing to give, along with the mask, gateway and DNS servers.
- Request. The device broadcasts that it is accepting that offer. It broadcasts rather than replying directly so that any other server that also made an offer hears that its offer was declined and can put that address back.
- Acknowledge. The server confirms, and the lease starts.
Two consequences come straight out of that being a broadcast. The device does not need to be told where the server is, which is why a machine gets an address with nothing configured. And the request only reaches servers on its own VLAN, meaning its own virtual local area network, because a broadcast does not cross a router. A network whose DHCP server is somewhere else needs the router configured to pass those requests along, and when that configuration is missing the symptom is one VLAN where nothing gets an address while every other VLAN is fine.
4Leases, and what happens when one expires
A lease has a length, set on the network. The device does not wait for it to run out. It tries to renew at the halfway point, and if the server answers, the clock resets and nothing visible happens. That is why a lease can be renewed hundreds of times without anybody noticing.
If the server does not answer at the halfway point, the device keeps using the address and keeps trying. It only gives the address up when the lease actually expires, at which point it has nothing and asks again from the start.
That behavior explains a fault that otherwise makes no sense. Take a DHCP server that failed at nine in the morning on a network with an eight-hour lease. Nobody notices at nine, because every machine already has a valid lease. Nobody notices at one in the afternoon when renewals start failing, because the machines keep using what they have. What happens is that machines begin dropping off one at a time from late afternoon onwards, as each one reaches the end of its own lease, and each user reports it as their own individual problem. The lease length is the delay between the cause and the symptom.
A device that ends up with no lease and no answer gives itself an address starting
169.254. That is not a usable address, and it reaches nothing. It is a signal, and what
it signals is that the machine asked and nothing answered.
5Reservations against static addresses
Some devices should always be at the same address: printers, servers, cameras, anything other machines are configured to reach by address. There are two ways to do that and they are not equally good.
A static address
Typed into the device itself. The device now knows nothing about the network's plan, and the network knows nothing about the device.
If somebody later changes the subnet or the gateway, this device is wrong and stays wrong. If the address is inside the range DHCP hands out, the server can give the same address to something else and both devices break in a way that looks like neither of them is reliable.
A reservation
Configured on the DHCP server: this hardware address always gets this IP address. The device is still asking normally and still being answered normally.
It always gets the same address, the server knows the address is taken so it cannot hand it out twice, and a change to the gateway or the DNS servers reaches this device with everything else.
The rule that follows: use a reservation wherever the device supports asking for an address at all. Keep static addresses for the equipment that has to work before any server does, which in practice means the gateway and the switches themselves.
Either way, the fixed addresses and the range DHCP hands out must not overlap. That is why a site addressing scheme divides each network into a range reserved for fixed addresses and a separate range for automatic ones.
6A second DHCP server nobody meant to install
Most consumer routers run a DHCP server and have it on by default. Plug one into a client network to use its wireless, or as a spare switch, and there are now two servers offering addresses on the same network.
Whichever answers first wins, so the damage is random. Some devices get correct addressing from the real server. Others get an address from a different range entirely, with a gateway pointing at a device that cannot route anywhere. The symptom is a site where some machines work and some do not, with no pattern, changing every time a machine reconnects.
Two things find it. The first is reading the addressing on a machine that is failing:
ipconfig /all names the server that answered, and if that address is not the one in the
documentation, you have both the cause and the address of the offending device. The second is the
switch, which can be told to accept DHCP offers from one address only and to block the rest, a
setting the vendor calls DHCP Guarding. It needs the trusted server's address, and it requires the
site's switches to be managed.
7What DNS does
DNS turns a name into an address. Nothing on the network routes on names, so this has to happen before any connection is made, which is why a DNS fault stops everything while the network underneath is healthy.
A Windows machine answers a name in a fixed order, and it stops at the first answer it gets.
- Its own cache. Answers it received recently are held in memory. No traffic leaves the machine.
- The hosts file. A local text file of name-to-address entries, normally empty. Anything in it overrides everything below.
- Its configured DNS server, the one DHCP handed it. At a site with its own server, that is the internal one, which knows the internal names.
- That server's forwarders. For a name it does not hold, the internal server asks a public resolver and passes the answer back.
The order is the diagnosis. A name that resolves on one machine and not another points at step 1 or 2 on the failing machine. A name that fails everywhere internally points at step 3. An internal name that resolves and a public one that does not points at step 4.
8The record types, and why a change takes a while to land
| Type | What it holds | Where it matters |
|---|---|---|
| A | A name and its IPv4 address | The ordinary one. Nearly every lookup ends at an A record |
| AAAA | A name and its IPv6 address | Returned alongside A records. A machine may prefer it, which matters when IPv6 is half configured |
| CNAME | A name that points at another name | Aliases. The lookup then has to resolve the second name too |
| MX | Where mail for this domain goes | Mail delivery. Wrong or missing, and mail stops while the website is fine |
| TXT | Free text, used for verification and mail policy | Domain verification and the records that say who may send mail as this domain |
| PTR | An address and the name it belongs to, the reverse of an A record | Logs that show names, and mail servers checking who is connecting |
| SRV | Which server provides a named service, and on which port | How a domain-joined machine finds its domain controllers |
Every record carries a TTL (time to live), a number of seconds saying how long anyone may keep the answer before asking again. It is the reason a change does not take effect immediately: everything that already asked is entitled to keep using the old answer until its copy expires.
Work an example. A record with a TTL of 3,600 seconds is one hour. Change the address at noon and a machine that looked it up at 11:55 keeps the old answer until 12:55. During that hour, the record is genuinely correct at the source and genuinely wrong on that machine, and both are true at once. This is why a planned change gets its TTL lowered the day before, so the window is minutes rather than hours.
On the machine in front of you, ipconfig /flushdns clears the local cache and forces
a fresh lookup. That fixes the one machine you are sitting at and nothing else, which is worth being
clear about before reporting a problem as solved.
9The four faults you will actually see
| Reported as | Actually | What confirms it |
|---|---|---|
| "My network port is broken" | No DHCP answer. The machine has a 169.254 address | ipconfig /all. If others on the same VLAN are fine, look at the port and the VLAN. If nobody on that VLAN has an address, look at the server and at whether requests are being passed across the router |
| "Some people are fine and some are not" | A second DHCP server answering | ipconfig /all on a failing machine, reading which server answered and whether the address range matches the documentation |
| "Everything is down" | Name resolution failing while the network is healthy | Reaching something by address while the same thing by name fails. Then nslookup to see which server is answering and what it says |
| "It works for me and not for her" | A stale cached answer, or an entry in the hosts file on one machine | The hosts file first, since it overrides everything, then ipconfig /flushdns and try again |
One case deserves naming because it produces faults that make no sense otherwise. A domain-joined machine must use the internal DNS server, because the records that tell it where its domain controllers are exist only there. Set such a machine to a public resolver and it will browse the internet perfectly while failing to sign in, failing to find file shares, and failing to apply policy. Everything the user tests works, and everything the business needs does not. A public resolver on a domain-joined machine is always wrong, however well the internet appears to be working.
10Practice on your own machine
- Run
ipconfig /all. Write down your address, mask, gateway, DNS servers, the DHCP server that answered, and your lease start and end times. - Work out your lease length from the start and end times, and say when your machine will next try to renew.
- Run
nslookupagainst an internal name and a public one. Note which server answered each and whether the answer is marked as coming from a cache. - Run
ipconfig /displaydnsand find an entry with a TTL counting down. Run it again a minute later and confirm the number has fallen. - In the UniFi console, open a network's settings and find its address range, its lease time and the DNS servers it hands out. Confirm they match what your machine received.
- Find a device with a reservation in the console. Note its hardware address and the address reserved for it, and confirm that address sits outside the automatic range.
11Check for understanding
Name the four settings a device receives in a lease, and say what specifically breaks if the gateway is missing but the other three are correct.
Why does a device broadcast its acceptance of an offer rather than replying directly to the server that made it?
A DHCP server fails at nine in the morning on a network with an eight-hour lease. Describe what the day looks like from the service desk, and why.
A printer needs a permanent address. Give the reason a reservation is better than typing an address into the printer, and name the one category of device that should still have an address typed in.
A user can reach a file server by its IP address but not by its name. Everyone else can reach it by name. Where do you look, in what order, and why is the order what it is?
A record's address was changed at noon and the TTL is 3,600 seconds. A machine says the old address at 12:30. Is something broken? What would you do, and what would that fix?
A laptop browses the internet perfectly but cannot sign in to the domain, reach file shares, or pick up policy. Its DNS server is set to a public resolver. Explain why the internet works and the rest does not.
12Before the next session
- Do the practice steps in section 10 and bring your lease length and renewal time worked out.
- Be able to say the four-message exchange in order and what each message does.
- Read the Network+ companion, chapter 2, common protocols and ports, and chapter 11, the DHCP and name resolution sections.
Next session. 06 - Firewalls and NAT, meaning network address translation. What a firewall decides and in what order, why a reply gets back in without a rule, and what translation does to a packet.
13Glossary
- DHCP
- Dynamic Host Configuration Protocol. Hands a device its address, mask, gateway and DNS servers when it joins a network.
- Lease
- A set of DHCP settings granted for a fixed period rather than permanently.
- Scope
- The range of addresses a DHCP server may hand out on a network.
- Reservation
- An entry on the DHCP server pairing one hardware address with one IP address, so that device always gets the same one.
- Static address
- An address typed into the device itself, with the network unaware of it.
- Broadcast
- A message addressed to every device on the local network at once. It does not cross a router.
- Port
- A number saying which program on a machine the data is for. DHCP uses 67 for the server and 68 for the client.
- DHCP Guarding
- A switch setting that accepts DHCP offers only from a named address and blocks the rest.
- APIPA
- The 169.254 address a machine gives itself when it asked for a lease and nothing answered.
- DNS
- Domain Name System. Turns a name into an address.
- Resolver
- The server a machine asks to turn a name into an address.
- Forwarder
- The server an internal DNS server asks for names it does not hold itself.
- Hosts file
- A local text file of name-to-address entries that overrides every other source on that machine.
- TTL
- Time to live. The number of seconds an answer may be kept before it must be asked for again.
- A record
- A name and its IPv4 address.
- CNAME
- A name that points at another name.
- MX record
- The record saying where mail for a domain is delivered.
- PTR record
- An address and the name it belongs to. The reverse of an A record.
- SRV record
- A record naming which server provides a service and on which port. How a domain-joined machine finds its domain controllers.
14Sources
- Internet Engineering Task Force, RFC 2131, Dynamic Host Configuration Protocol, for the four-message exchange, leases and renewal at the halfway point.
- Internet Engineering Task Force, RFC 1035, Domain Names, Implementation and Specification, for record types and time to live.
- Internet Engineering Task Force, RFC 3927, Dynamic Configuration of IPv4 Link-Local Addresses, for the 169.254 range.
- Ubiquiti, UniFi DHCP Server, for what the server supplies and where it is enabled.
- Ubiquiti, Duplicate IP Addresses and Rogue DHCP Servers, for DHCP Guarding and its requirement for managed switches.
- Ubiquiti, UniFi DNS Troubleshooting Guide.
- Microsoft Learn, DNS troubleshooting guidance, for client resolution behavior on Windows.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 2 and chapter 11.