IntermediatePublished 2026-07-02
Lab 9: Centralized DHCP for Two Departments via Relay
Bundle lab
Build a central DHCP service on an IOS-XE router and service two branch departments across a routed hop via DHCP relay. Configure two DHCP pools (SALES and SUPPORT) with proper options and excluded ranges on the HQ server, and enable ip helper-address on both branch LAN interfaces so clients obtain leases from the correct pool. Verify leases and bindings using Linux and IOS show commands, and confirm return-path reachability with prebuilt static routes.
Learning objectives
- Design two DHCP pools on a centralized IOS-XE router with correct scope, default-gateway, DNS, domain-name, lease, and excluded addresses
- Enable and verify DHCP relay (ip helper-address) on multiple branch interfaces toward the central server
- Confirm dynamic leases on Linux clients without relying on hard-coded host addresses
- Use IOS show commands to validate pools and bindings and ensure the return path via static routes
- Troubleshoot common relay and scoping mistakes (missing helper, wrong pool network, over-excluded ranges, bad default-router)
Troubleshooting focus
- If a client has no IP, check the correct ip helper-address on the branch interface and the routing path to 10.70.0.1.
- If the client gets an IP but cannot reach the server, review the static routes on DHCP-SRV back to 10.71.10.0/24 and 10.71.20.0/24.
- If a client pulls an unexpected network, verify the pool network masks match the actual LAN subnets.
- If no leases are issued, ensure pools are not fully excluded and that service dhcp is enabled.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.