Avatar of mbudman
mbudman
Flag for Canada asked on

DHCP with multiple subnets -single domain

Hello,

I have two trusted zones on my firewall. Firewall rules / policies allow full communication between the trusted zones. both zones are in the same domain and both zones are physically located in the same building (on different floors).

Each zone has its own domain controller (DC), which is also the DNS server, WINS server and DHCP server.

I would like to implement redundancy with DHCP in case one of the DC's fails.

My  understanding is  that using DHCP relay agent will solve this problem.

What I don't understand is how each zone knows which ip addresses to use.

For instance, zone 1 uses 10.0.0.0 / 255.255.255.0; zone 2 uses 10.0.1.0 / 255.255.255.0

If the Scope of the DC in zone 1 is defined as 10.0.0.100.. .10.0.0.254 / 10.0.1.0..10.0.1.100 and scope of Dc in zone 2 is defined as 10.0.1.100..10.0.1.254 / 10.0.0.0..10.0.0.100, how does the DHCP server know which scope to use in its own zone? What prevents DHCP server from assigning ip addresses from the second zone within its own zone?

Any insight would be appreciated.

Thanks in advance.

Mark


RoutersDHCPNetwork Architecture

Avatar of undefined
Last Comment
mbudman

8/22/2022 - Mon
Craig Beck

The DHCP servers know which scope to assign addresses from using something called the giaddr value.  When a client sends a DHCP request, the router will tell the DHCP server the giaddr (the IP of the interface on the router on which the request was received) so the DHCP server will know to allocate an IP address from that range.
mbudman

ASKER
OK, but what if the DHCP server does not have ot go through the router as in the case when it is giving out ip addresses to the subnet for which it is connected?
ASKER CERTIFIED SOLUTION
Craig Beck

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
mbudman

ASKER
Thanks for your assistance.

Cheers!

Mark
Your help has saved me hundreds of hours of internet surfing.
fblack61