Solved

Configure Windows DHCP for Cisco Switch Vlans

Posted on 2014-03-31
6
2,396 Views
Last Modified: 2014-04-07
In most environments nowadays, they use VLANs on Switches.
I would like to know, after creating VLANs , then on Windows DHCP I want to create Scopes for each VLAN. How do DHCP Scopes Map to VLANs, i mean if a workstation is automatically assigned IP 192.168.15.70/24, but the Network cable that connect the workstation to the switch port is going to a port in VLAN 20. I want the third octet of the  IP of the workstation to match the VLAN number. in the Example above the workstation should be connected to Vlan 15

Any help will be very much appreciated.

Thank you
0
Comment
Question by:jskfan
  • 3
  • 2
6 Comments
 
LVL 45

Assisted Solution

by:Craig Beck
Craig Beck earned 334 total points
ID: 39966934
You can create VLAN 20 and configure the IP subnet for that VLAN as 192.168.20.0/24 for example.  That's straight-forward.  Try not to think about DHCP scopes mapping to VLANs - they don't.  All that happens to determine which scope an IP should be allocated from is that the DHCP server checks the value of the giaddr field inside the DHCP request packet and checks to see if it has a scope on the same subnet.  If a scope is present it assigns an address, and if a scope doesn't exist the client gets no address from that server.  If the giaddr field is blank or not present the DHCP server assigns the IP address from the same scope that it's NIC is on.

To put it simply, if your DHCP server has one NIC don't worry about what's going on at your switch.  You would just create scopes for the subnets you have configured.  The only thing that is important is that the DHCP server has a route to each subnet you're assigning an IP address to.

You can also put a dedicated NIC from the DHCP server in each VLAN, but that's not always practical, especially if you have lots of subnets.
0
 

Author Comment

by:jskfan
ID: 39967223
When you plug a workstation into a port in VLAN 20, does that workstation tell DHCP that I am in VLAN 20 and please give me IP address from the scope 192.168.20.0 ?

I am not familiar with giaddr field..
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 334 total points
ID: 39967333
No.  If the DHCP request passes through a router via the IP helper command the address of the router's interface is added to the packet in the giaddr field.

That tells the DHCP server which scope is required.

If no giaddr is present in the DHCP packet the server issues an address from the scope which matches the IP range on the DHCP server interface that the packet was received on.
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 6

Assisted Solution

by:Hassan Besher
Hassan Besher earned 166 total points
ID: 39968402
it depends upon your routing method, if you are using L3 switch you will use IP helper command under vlan interface , if you are using Router on stick design you will have to put IP helper command under router subinterface.

simply IP helper command  will convert DHCP broadcast discover packet into unicast towards your DHCP server and your DHCP server will choose which scoop based upon the source ip address range the request came from.
0
 

Author Comment

by:jskfan
ID: 39972324
OK… IP helper address is the one that knows from which VLAN the client request is coming from and add the info of the VLAN to giaddr field, then windows DHCP server reads giaddr and determine which appropriate scope will hand out IP address from back to the client…

in the case I have  one switch in the LAB with one VLAN only , but multiple DHCP scopes on the windows server , there is no need for IP helper address… in this scenario I believe DHCP server will not hand out and IP address from any scope except if there is one on the same subnet as DHCP server itself is on…….. I could be wrong ???
0
 

Author Closing Comment

by:jskfan
ID: 39983195
Thank you Guys!
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now