Protocol · DHCP

DHCP PCAP Analysis

by My Network Consultant

From capture to clarity—find missing offers, NAKs, relay issues, and pool exhaustion with AI-powered insights.

Layer 7 (Application) Related: IP, UDP, ICMP, DNS Ports: 67/68 UDP (DHCPv4), 546/547 UDP (DHCPv6) DHCPv4 & DHCPv6

Overview

The Dynamic Host Configuration Protocol (DHCP) assigns IP configuration to endpoints. In IPv4, the classic DORA sequence is Discover → Offer → Request → ACK (or NAK). In IPv6, common messages are SARR: Solicit → Advertise → Request → Reply (plus Renew/Rebind/Confirm). From a PCAP/PCAPNG you can spot missing OFFERs, conflicting servers, NAK reasons, relay (giaddr/Option 82) issues, scope mismatches, T1/T2 timer problems, and pool exhaustion.

  • What you’ll see: per-client timelines (DORA/SARR), multiple-offer detection, NAKs, lease timers (T1/T2), relay (giaddr) and Option 82, option values (router/DNS/domain), pool exhaustion hints
  • Best for: NOC troubleshooting, enterprise rollout/changes, campus/Wi-Fi onboarding, incident response
  • Works with: IP clients, DHCP relays, DNS integration

What to look for

  • No address assignment: DISCOVERs without OFFERs → filtering, relay failure, or pool exhaustion
  • Multiple OFFERs: conflicting/rogue servers handing different scopes or options
  • NAKs: wrong subnet, stale/conflicting lease, reservation mismatch (watch Option 54 Server ID)
  • Relay problems: missing/incorrect giaddr, Option 82 anomalies, or blocked helper path
  • Option mismatches: wrong default gateway (Opt 3), DNS servers (Opt 6), domain/search (Opt 15), lease time (Opt 51)
  • Lease timing: abnormal T1/T2 causing frequent renewals or outages
  • DHCPv6 specifics: SOLICIT/ADVERTISE loops, missing REPLY, relay-forward/relay-reply issues; consider RA/SLAAC flags

Capture tips

  • Capture on the client VLAN and at the gateway/relay to localize where DORA/SARR fails.
  • Include ICMP/ICMPv6 alongside DHCP—PMTUD or RA issues can affect DHCP reachability.
  • Disable NIC offloads (LRO/GRO/TSO/checksum) on capture interfaces to keep headers and timing accurate.
  • For wireless/campus, capture at the controller/AP switch to see Option 82/circuit IDs.
  • Keep a focused window that reproduces the issue (fits within the 10 MB demo limit).

Example walkthrough

  1. Browse to DHCP and the client MAC/IP if known.
  2. Follow the DORA/SARR sequence per client; note missing OFFER/ACK or repeated retries.
  3. Check for multiple OFFERs and compare Option 54 (Server Identifier) and gateway/DNS options.
  4. Inspect giaddr/Option 82 and verify the scope matches the client VLAN/subnet.
  5. Confirm T1/T2 and lease time; look for premature renewals or failures.
  6. Export a concise report (timeline, options, server sources) and attach it to your ticket.

DHCP FAQ

Look for multiple OFFERs to the same client from different servers or with different Option 54 values. Our views highlight unknown sources and conflicting options.

They didn’t get an OFFER/ACK. Check VLAN/ACLs, relay reachability, and pool capacity. We show exactly where the sequence fails.

The server rejected the request: wrong subnet, conflicting lease, or reservation mismatch. Renew or correct the scope/reservation, then retry.

Relays tag where the request came from so the server picks the right scope. Misconfigurations or blocked helper paths cause missing offers or wrong addresses.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.