Thursday, December 1, 2011

Wireshark lab DHCP


1. UDP
2. The port numbers are the same.
3. 00:22:15:96:cb:13
4. Option: (t=53,l=1) DHCP Message Type = DHCP Discover
5. The first transaction number is 0xdec5ef20. The second is  0xdec5ef20. ID's are used so the server can tell the difference between a requests.
6.

 The client and server use the address 255.255.255.255 as the desination address. The server uses the computers actual IP address as the source, and the client uses 0.0.0.0.
7. 10.33.147.254
8. The IP address is 10.33.147.254, and the message says Option: (t=53,l=1) DHCP Message Type = DHCP Offer.
9. There is no relay used because 0.0.0.0 is the address.
10. A router shows the client what the gateway is. The subnet mask line shows the client which subnet mask it is.
11. The host requests the IP address. 10.33.147.254 in my experiment.
12. Lease time is the amount of time a DHCP gives an IP address. In my experiment, it is 1 day.
13. The DHCP message cancels the IP address that is given to it by the server. The server does not send an achknowlegement. If the release message is dropped, then the server must wait until the lease time is up before that address can be used again.
14. Yes, there are ARP packets. This is done to make sure that the IP addresses are not already in use.

No comments:

Post a Comment