04 IT support · DHCP · Packet evidence
DHCP failure isolation
A disconnected service lab that traces no-offer, incorrect-option, and competing-server failures through real DORA captures.
Validated result
Each fault was corrected with a clean DORA capture; rollback rebuilt the owned topology before a final clean repeat.- Kea DHCP
- BusyBox udhcpc
- TShark
- Linux namespaces
01 · The support question
What needed to be known?
“Renew the address” does not explain whether the service was absent, the lease options were wrong, or another server answered first. This lab isolates those cases at the packet level.
02 · The build
A controlled path from fault to retest.
- 01
Ran real Kea services and a BusyBox client inside owned namespaces with no default route.
- 02
Captured complete DORA exchanges and preserved decisive frame references.
- 03
Changed one controlled condition at a time: no server, wrong router/DNS, then a competing server.
- 04
Tore down and rebuilt the topology from reviewed configuration for rollback.
03 · What proves it
Evidence tied to the claim.
No offer
The capture remained open beyond the response window after the final Discover before absence was accepted.
Incorrect options
DORA completed, but the offered router and DNS values differed from the reviewed expectation.
Competing server
Two owned servers answered one transaction and the evidence retained which offer the client selected.