DHCP scope, lease, reservation and relay
How a DHCP server is scoped to a subnet, how leases and reservations decide which address a client gets, and how a relay agent lets one server serve other segments.

A DHCP server answers only for the subnets it has been told to serve. Three server-side settings decide what a client receives: the scope (the pool and the subnet it covers), the lease (how long the address is lent), and an optional reservation (one address bound to one client). When the server is not on the client’s Layer 2 segment, a relay agent forwards the request and tells the server which subnet the client belongs to.
The model: three choices and one bridge
Read the subject through one frame. The server must decide which subnet to allocate from (scope), how long (lease) and to whom (reservation); these are local decisions taken on the server. Reaching a client on another segment needs a second device, because a DHCP broadcast stops at a router — that is what relay provides.
client ── broadcast ──► relay agent (sets giaddr = client subnet) ── unicast ──► DHCP server
▲ │
└──────── reply, option 82 stripped ◄────────────────┘
server-side choices: scope (which subnet) · lease (how long) · reservation (to whom)
Terms
- Scope / address pool — the subnet (
network) the server serves and the range of addresses it may allocate there. - Lease — the time for which an address is granted; the client renews before it expires.
- Reservation (manual binding) — one address tied to one client identity, so that client always receives the same address.
- Relay agent — the device that forwards DHCP between segments.
giaddr— the relay agent’s address facing the client; the server reads the client’s subnet from it.- Option 82 — the relay agent information option of RFC 3046.
How it works, step by step
- The scope picks the subnet. The server allocates from the pool whose
networkmatches the subnet the request arrived on: the receiving interface’s subnet whengiaddris 0, or thegiaddraddress when the request was relayed (RFC 2131, §4.3.1). A pool whosenetworkdoes not match cannot serve that client. - The lease sets the duration. The server returns a lease time in option 51. The client renews at T1, half the lease, by unicast to the server that issued it; if that fails it rebinds at T2, seven-eighths of the lease, by broadcast to any server (RFC 2131, §4.4.5; the timers travel in options 58 and 59, RFC 2132).
- A reservation pins one address. Allocation normally honours an existing binding or a valid requested address (RFC 2131, §4.3.1). A reservation overrides that for one client by binding one address to its identity — the client identifier (option 61, RFC 2132) or its hardware address.
- The relay bridges the segments. A router on the client’s segment forwards the broadcast to the server as a unicast message and sets
giaddrto its own incoming interface address (RFC 2131, §4.3.1). The server sends its reply togiaddr, and the relay forwards it to the client. - Option 82 carries the port identity. A relay may insert the Relay Agent Information option with a circuit ID and a remote ID; the server can use it for allocation policy and must echo it back unchanged, and the relay removes it before the reply reaches the client (RFC 3046, §2.1–2.2).
On Cisco IOS XE
An address pool and a reservation. ip dhcp excluded-address is global configuration, not part of the pool, and each reservation is its own single-host pool:
ip dhcp excluded-address 10.10.10.1 10.10.10.62
!
ip dhcp pool LAN
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
dns-server 208.67.222.222
lease 0 6
!
ip dhcp pool PRINTER
host 10.10.10.50 255.255.255.0
client-identifier 0100.1122.3344.55
Relay is enabled per interface; ip helper-address both forwards the broadcast and makes the router set giaddr:
interface GigabitEthernet0/0/0
ip helper-address 10.20.30.40
Option 82 insertion is off by default and is turned on explicitly; the reforwarding policy decides what happens to a packet that already carries relay information:
ip dhcp relay information option
ip dhcp relay information policy replace
Warning. ip helper-address, an edit to a live pool, clear ip dhcp binding and no service dhcp all affect clients in production: they can interrupt renewal or force re-addressing. Apply them in a change window and verify afterwards.
To check the result without guessing, show ip dhcp pool reports, per pool, the subnet and the totals of leased and excluded addresses; show ip dhcp binding lists each active address with its client identity and expiry; show ip dhcp conflict lists addresses the server has marked as in use by another device.
Limits and a common error
DHCP carries no authentication (RFC 2131, §7): a rogue server or a rogue relay can hand out wrong addresses or the wrong gateway, and relay only narrows that gap because the relay-to-server path is assumed trusted (RFC 3046, §5). Option 82 is not a security control on its own.
The common error is the reservation identity. Match client-identifier when the client sends option 61 — many Cisco clients do, with the MAC prefixed by the media type 01 — and hardware-address otherwise. Match the wrong one and the reservation silently never applies, so the device keeps taking a dynamic address. A lease that is too long holds addresses after a client leaves; lease infinite never returns the address to the pool.
Level and prerequisites
L2 — operational. It assumes the L1 sheet DNS and DHCP: names, addresses and automatic configuration, which covers the DORA exchange and the lease concept; this sheet does not repeat them. Configuration examples are Cisco IOS XE; the concepts are portable, the syntax is not.
Where to go next
- Networking — the area this sheet belongs to.
References
- RFC 2131 — Dynamic Host Configuration Protocol (Mar 1997); address allocation and subnet selection, §4.3.1; relay and
giaddrforwarding, §4.3.1; lease renewal timers T1/T2, §4.4.5; security, §7. - RFC 2132 — DHCP Options and BOOTP Vendor Extensions (Mar 1997); lease time (option 51), §9.2; renewal T1 (58), §9.11; rebinding T2 (59), §9.12; client identifier (61), §9.14.
- RFC 3046 — DHCP Relay Agent Information Option (Jan 2001); agent and server operation, §2.1–2.2; security considerations, §5.
- RFC 3527 — Link Selection sub-option for the Relay Agent Information Option (Apr 2003) — consulted for the split of the
giaddrroles; no body claim rests on it. - RFC 5010 — DHCPv4 Relay Agent Flags Suboption (Sep 2007) — consulted for relay-agent flag handling; no body claim rests on it.
- Cisco — IP Addressing Configuration Guide, Cisco IOS XE 17.x: “Configuring the Cisco IOS XE DHCP Server”. Address pools (
ip dhcp pool,network,default-router,dns-server,lease), excluded addresses, manual bindings (host,client-identifier,hardware-address), verification commands. - Cisco — IP Addressing: DHCP Configuration Guide, Cisco IOS XE 16.12.x: “Configuring the Cisco IOS XE DHCP Relay Agent”. Relay agent behaviour, packet forwarding address, Relay Agent Information option.
- Cisco — Cisco IOS IP Addressing Services Command Reference:
ip dhcp relay information option,option-insert,policy,trust-all,trusted. - Cisco — support document “Operate a Robust IOS XE DHCP Server”. General pool, excluded addresses, lease, fixed bindings, ping-check,
show ip dhcp poolfields.