[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

DHCP Superscope Assigning Wrong Address to Clients Windows Server 2003

Posted on 2008-02-04
10
Medium Priority
?
5,386 Views
Last Modified: 2011-12-06
Hi,
I have a Windows 2003 network switched using a collapsed core design with a Cisco 3560 as the core switch and standard 3com or Netgear non managed swithces at the edge. The network is divided into several VLANS (192.168.4.0/24, 192.168.5.0/24, 192.168.6.0/23, 192.168.8.0/24). The 3560 is configured to route traffic between the networks and this works perfectly. All servers are on the 8.0/24 network, all DHCP clients are located on the other networks. There ia a DHCP server on the 8.0/24 network configured with a superscope encompassing scopes for the 4.0/24, 5.0/24 and 6.0/23 subnets. Each VLAN interface on the 3560 is configured with an ip-helper address entry (DHCP relay agent) that points to the DHCP server. DHCP usually works fine. However if a user on the 5.0/24 network takes his laptop to a room on the 6.0/24 network the laptop will usually pick up an address from the 5.0/24 subnet which means that he can't access the network because he is plugged into an interface on the core switch with a 6.0/23 ip address. The only way that I can get a client to pick up the correct address reliably when it is moving between subnets is to disable all scopes other that the one which I want. This is causing us big problems. I'm usually pretty ok with networking but this one has me stumped. Can anyone out there help?

Thanks

Kirsty
0
Comment
Question by:KirstyP
  • 3
  • 3
  • 3
  • +1
10 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 20814280
I'm sure it has to do with the fact that you are using a superscope in DHCP versus 3 individual scopes for the 3 subnets.  I bet if you removed the superscope the problem would disappear.
0
 

Author Comment

by:KirstyP
ID: 20814875
Thanks, I know that It should work if I set up 3 seperate scopes on different servers and point the respective helper addresess to them. However why doesn't it work with a superscope? This is what a supescope is designed to do - it looks at the originating subnet in the GIADDR field and assigns the appropriate address - so why doesn't it work?

Kirsty
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 20814891
It's my understanding that a superscope is used in a scenario where you have multiple logical subnets on the same physical segment.  You have 3 logical subnets on 3 physical segments.
0
[Webinar] Improve your customer journey

A positive customer journey is important in attracting and retaining business. To improve this experience, you can use Google Maps APIs to increase checkout conversions, boost user engagement, and optimize order fulfillment. Learn how in this webinar presented by Dito.

 

Author Comment

by:KirstyP
ID: 20815118
Yes that's true but In the MS implementation superscopes are also designed to support logical subnets on different physical segments. I am currently looking at an MS press book describing how to set up a superscope on a DHCP server physically seperated from the multinets by a router. Which is exactly the set up that I have. I would just like to know why it doesn't work - why does the DHCP server not take notice of the GIADDR info passed by the ip-helper address? I think I might just set up 3 seperate DHCP servers and have done with it.

Kirsty
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 20815696
It may be because the lease is still active and since it is a superscope, it deems it okay to reissue the same IP.  Do they get the same IP when moving?  You could try adding the 002 option to your scopes (Release DHCP lease on shutdown) to see if that helps.  Otherwise, I would simply not use a superscope and see if that resolves it.
0
 
LVL 2

Expert Comment

by:Stevexpress
ID: 20817406
I agree with JFederick29.
I looks like your setup correctly to me.  I would say its giving it the same address from the wrong scope because the lease on that MAC address is not up.  

Let us know if it is resolving the same IP when you more from one scope to another.
0
 
LVL 2

Expert Comment

by:Stevexpress
ID: 20817807
Perhaps this will be of some use

Perhaps you considered the possibility of placing multiple DHCP
Servers on the same physical segment to solve the problem of
issuing IP address for multiple network IDs. Let's take a look at
what might happen here.

We have two DHCP Servers, DHCP-1 and DHCP-2. The DHCP Servers
contain scopes that include all addresses for the following
network IDs:

DHCP-1 192.168.1.0/24
DCHP-2 192.168.2.0/24

Now imagine that a DHCP client with IP address 192.168.1.10 needs
to renew its IP address. When the client sends out its
DHCPRequest message to renew its address, that request is
broadcast to the entire segment. Therefore, either DHCP Server
can receive the message. If DHCP-2 receives the message, it will
check the network ID on the request and compare that with the
network ID on its local interface and find that the source
network ID is different from its own network ID. Since these are
different, DHCP-2 will look for a member scope in a superscope
that can service this request. Since there is no superscope to
service the request, DCHP-2 will send a NACK to the client.

After receiving the NACK, the DHCP client then has to begin the
discovery process from the beginning and send out a DHCPDiscovery
packet. Let's say that DHCP-2 is the first to respond to the
DHCPDiscover packet, and assigns the clients the IP address of
192.168.2.15. Hey look at that! The client is now a located on a
different network ID. And what's really rich is that the whole
thing could start all over again, and the DHCP client could end
up on network ID 192.168.1.0/24 again.
0
 
LVL 2

Accepted Solution

by:
Stevexpress earned 2000 total points
ID: 20817824
The Solution

The solution is to configure superscopes on both DHCP Servers,
and then exclude all the addresses on one of the scopes. For
example:

DHCP-1
Superscope
192.168.1.1-192.168.1.254
192.168.2.1-192.168.2.254
Exclude:
192.168.2.1-192.168.2.254

DHCP-2
Superscope
192.168.1.1-192.168.1.254
192.168.2.1-192.168.2.254
Exclude:
192.168.1.1-192.168.1.254

With this configuration, what happens to the DHCP client that
tries to renew its IP address, 192.168.1.10?

If DHCP-2 receives the DHCPRequest message, rather than sending a
NACK, it will just ignore the message, because it does have a
scope for the client's network ID, but just doesn't have any
addresses available because they've all been excluded. The client
will try again, and perhaps again, and sooner or later will
contact DHCP-1 and renew its IP address. The key here is that
when you configure the scope for network ID 192.168.1.0/24 and
then exclude all the addresses in the scope and make it part of
the superscope, DHCP-2 will ignore requests from clients from
that network ID.
0
 

Author Closing Comment

by:KirstyP
ID: 31427761
Thanks guys. I tried the 002 option but it still didn't work. I therefore went with the suggestion of stevexpreess and set up several DHCP servers, each with a superscope with all addresses excluded apart from the scope that I want that server to assign. I then pointed the ip helper-address from each VLAN to its respective DHCP server. It works perfectly. Sorry for the delay in getting back to you all and thanks for all your help guys.
0
 

Expert Comment

by:tiaconis
ID: 35013895
Hi, all I wanted to point out an alternative solution.  To those who plan to have double digit subnets, having a separate DHCP server for each would defeat the whole ease of management that dhcp relaying offers.  The alternative solution is to separate each scope outside of the superscope so that they are peers of the superscope.  Now, i can jump from one network to the next without getting stuck with the ip from the first network.  I hope this helps the rest of you multi network admins out there.  
0

Featured Post

Receive 1:1 tech help

Solve your biggest tech problems alongside global tech experts with 1:1 help.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Measuring Server's processing rate with a simple powershell command. The differences in processing rate also was recorded in different use-cases, when a server in free and busy states.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
There may be issues when you are trying to access Outlook or send & receive emails or due to Outlook crash which leads to corrupt or damaged PST file. To eliminate the corruption from your PST file, you need to repair the corrupt Outlook PST file. U…

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question