Troubleshoot DHCP Relay Across VLANs
DHCP clients begin with a broadcast that normally stays inside their VLAN. A relay agent forwards the request to a configured server and supplies client subnet context so the server can select the correct scope. This guide follows that path before changing a live scope.
Example topology: client VLAN 20 uses 10.20.20.0/24, its gateway is 10.20.20.1, and the DHCP server is 10.20.5.10. Use only approved test clients and server addresses.
For the Windows server checks, run PowerShell on the DHCP server or an authorized admin workstation with the DHCP Server PowerShell module (installed with the DHCP role or RSAT DHCP Server Tools) and remote administrative permissions.
Verify the Client Broadcast Domain
Client VLANCheck the access port VLAN, VLAN database, and SVI state. If the SVI is down, resolve the Layer 2 issue before diagnosing relay forwarding.
show vlan briefshow interfaces statusshow ip interface brief | include Vlan20show running-config interface Vlan20❯ View Expected Console Output
interface Vlan20 ip address 10.20.20.1 255.255.255.0 ip helper-address 10.20.5.10
Figure 1: Check the relay address on the client VLAN and confirm a route to the DHCP server.
Verify Relay Destination and Return Reachability
Relay PathConfirm the helper points to the intended server on the client-facing SVI. Verify the relay can route to the server and return traffic can reach the relay address used by the server.
show running-config interface Vlan20show ip route 10.20.5.10ping 10.20.5.10 source Vlan20❯ View Expected Console Output
Success rate is 100 percent (5/5)Match the Scope to the Relayed Subnet
Server ScopeOn the DHCP server or an authorized workstation with RSAT DHCP Server Tools, verify an active scope covers 10.20.20.0/24, has available leases, and supplies router option 10.20.20.1 and the expected DNS servers. Check exclusions and reservations. These commands are read-only; use credentials with remote DHCP administration rights.
Get-DhcpServerv4Scope -ComputerName dhcp01.corp.exampleGet-DhcpServerv4OptionValue -ComputerName dhcp01.corp.example -ScopeId 10.20.20.0Get-DhcpServerv4ScopeStatistics -ComputerName dhcp01.corp.example -ScopeId 10.20.20.0❯ View Expected Console Output
ScopeId : 10.20.20.0State : ActiveRouter : 10.20.20.1Follow Discover, Offer, Request, and Acknowledgment
Packet EvidenceCapture at an approved point near the server and filter for DHCP. If the request reaches the server but no Offer leaves, focus on scope selection and policy. If an Offer leaves but never returns, inspect routing and filtering.
Wireshark display filter:udp.port == 67 || udp.port == 68❯ View Expected Console Output
DHCP Discover -> relay/serverDHCP Offer <- server/relayDHCP Request -> relay/serverDHCP ACK <- server/relay