IT271 Networking and System Administration

Networking and System AdministrationUnit 612 min read

DNS & DHCP: Services, Protocols & Real-World Networking

Unit 6 of Networking and System Administration covers DNS (Domain Name System) and DHCP (Dynamic Host Configuration Protocol), explaining how they resolve human-readable domain names to IP addresses, automate IP assignment, and ensure seamless network communication. This note includes definitions, packet formats, proto

Core Concepts: DNS and DHCP Defined

DNS (Domain Name System)

DNS translates human-readable domain names (e.g., esewa.com.np) into machine-readable IP addresses (e.g., 103.102.128.100). Without DNS, users would need to remember IP addresses for every website.

How DNS Works

  1. Hierarchical Structure: DNS uses a distributed database of name servers (root, TLD, authoritative, and recursive resolvers).
  2. DNS Query Process:
    • A user types esewa.com.np in a browser.
    • The local resolver (ISP’s DNS server) checks its cache.
    • If not found, it queries the root DNS server → TLD server (.np) → authoritative server for esewa.com.np.
    • The authoritative server returns the IP address (103.102.128.100).
    • The resolver caches the result and returns it to the user.
sequenceDiagram
    participant User
    participant LocalResolver
    participant RootDNS
    participant TLD
    participant AuthoritativeDNS
    User->>LocalResolver: Query: esewa.com.np
    LocalResolver->>RootDNS: Query (.)
    RootDNS->>TLD: Query (.np)
    TLD->>AuthoritativeDNS: Query (esewa.com.np)
    AuthoritativeDNS-->>TLD: IP: 103.102.128.100
    TLD-->>RootDNS: IP: 103.102.128.100
    RootDNS-->>LocalResolver: IP: 103.102.128.100
    LocalResolver-->>User: IP: 103.102.128.100

DNS Record Types

Record Type Purpose Example
A Maps domain to IPv4 address esewa.com.np → 103.102.128.100
AAAA Maps domain to IPv6 address google.com → 2607:f8b0:4009...
MX Mail exchange server esewa.com.np → mail.esewa.com
CNAME Alias for another domain www.esewa.com → esewa.com.np
NS Nameserver for a domain esewa.com.np → ns1.esewa.com
TXT Text records (e.g., SPF, DKIM) esewa.com.np → "v=spf1..."
08162431Name32 bitsType16 bitsClass16 bitsTTL32 bitsRD Length16 bitsRD Data16 bits
DNS Resource Record (RR) format (simplified)

In the Real World

  1. eSewa (Nepal):

    • Uses DNS to resolve esewa.com.np to its server IP, ensuring users can access payment services without memorizing IPs.
    • Relies on MX records to route emails (e.g., transaction confirmations) to the correct mail server.
  2. Google (Global):

    • Anycast routing with DNS: When you type google.com, DNS returns the IP of the nearest Google data center (e.g., Mumbai for Nepal users), reducing latency.
    • Uses DNSSEC (DNS Security Extensions) to prevent spoofing attacks on google.com.
  3. NTC (Nepal Telecom):

    • DHCP assigns dynamic IPs to home broadband users. When you connect, NTC’s DHCP server automatically provides:
      • IP address (e.g., 192.168.1.100),
      • Subnet mask (255.255.255.0),
      • Default gateway (192.168.1.1),
      • DNS server (8.8.8.8 or 103.102.128.100).
    • Worked Example: If your NTC router’s DHCP pool is 192.168.1.100–200, and 5 devices are connected, the first device gets 192.168.1.100, the second 192.168.1.101, etc.

DHCP (Dynamic Host Configuration Protocol)

DHCP automates IP assignment, reducing manual configuration errors and enabling devices to join networks dynamically.

How DHCP Works

  1. DHCP Discovery: A device (e.g., your laptop) broadcasts a DHCP DISCOVER message to the network.
  2. DHCP Offer: A DHCP server responds with a DHCP OFFER (e.g., IP 192.168.1.100, lease time 24h).
  3. DHCP Request: The device accepts the offer with a DHCP REQUEST.
  4. DHCP Acknowledgment: The server confirms with DHCP ACK and assigns the IP.
DHCP DISCOVER (Broadcast)DHCP OFFER (192.168.1.100)DHCP REQUESTDHCP ACKClientDHCP Server
DHCP 4-way handshake (Discovery, Offer, Request, Acknowledgment)

DHCP Message Format

0                   1                   2                   3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|     op (1=BOOTREQUEST, 2=BOOTREPLY)    |   htype (1=Ethernet)   |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|   hlen (6 for Ethernet) |   hops (0) |       xid (transaction ID) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|   secs |   flags |       ciaddr (client IP, 0 if none)       |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                    yiaddr (your IP)                    |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                    siaddr (next server IP)              |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                    giaddr (relay agent IP)              |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                          client MAC address                   |
|                                                               |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                          server MAC address                   |
|                                                               |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                          options (e.g., lease time, DNS)      |
|                                                               |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
059118177235op8 bitshtype8 bitshlen8 bitshops8 bitsxid32 bitssecs16 bitsflags16 bitsciaddr32 bitsyiaddr32 bitssiaddr32 bitsgiaddr32 bitschaddr16 bitspadding10 bitsoptions66 bits
DHCP Message Header (236 bytes total)

DHCP Lease Management

  • Lease Time: Duration an IP is assigned (e.g., 24h). After expiry, the device renews via DHCP REQUEST.
  • Scope: Range of IPs a DHCP server can assign (e.g., 192.168.1.100–200).
  • Exclusion Range: IPs reserved for static assignments (e.g., 192.168.1.1 for the router).

DNS vs. DHCP: Key Differences

Feature DNS DHCP
Purpose Translates names to IPs Assigns IPs to devices
Protocol UDP (port 53) UDP (port 67/68)
Message Type Queries/Responses (A, MX, etc.) DISCOVER, OFFER, REQUEST, ACK
Persistence Static (unless TTL expires) Dynamic (lease-based)
Example Use esewa.com.np → 103.102.128.100 Assigns 192.168.1.100 to your laptop

DNS and DHCP in Action: A Worked Example

Scenario: You open daraz.com.np on your home network (NTC broadband).

  1. DNS Resolution:

    • Your browser queries the local resolver (8.8.8.8 or NTC’s DNS).
    • The resolver checks its cache. If not found, it queries:
      • Root DNS → .np TLD → daraz.com.np authoritative server.
    • The authoritative server returns daraz.com.np → 103.102.128.50.
    • Your browser connects to 103.102.128.50.
  2. DHCP Assignment:

    • Your laptop sends a DHCP DISCOVER broadcast.
    • NTC’s DHCP server responds with:
      • IP: 192.168.1.150,
      • Subnet mask: 255.255.255.0,
      • Gateway: 192.168.1.1,
      • DNS: 103.102.128.100.
    • Your laptop uses these settings to communicate with daraz.com.np.

DNS and DHCP Configuration (Linux Example)

Configuring a DNS Server (BIND)

  1. Install BIND:
    sudo apt install bind9
    
  2. Edit /etc/bind/named.conf.local:
    zone "esewa.com.np" {
        type master;
        file "/etc/bind/db.esewa.com.np";
    };
    
  3. Create /etc/bind/db.esewa.com.np:
    $TTL 86400
    @       IN  SOA     ns1.esewa.com.np. admin.esewa.com.np. (
                    2023100101 ; Serial
                    3600       ; Refresh
                    1800       ; Retry
                    604800     ; Expire
                    86400 )    ; Minimum TTL
    
    @       IN  NS      ns1.esewa.com.np.
    @       IN  A       103.102.128.100
    www     IN  CNAME   esewa.com.np.
    mail    IN  MX  10  mail.esewa.com.np.
    

Configuring DHCP Server (ISC DHCP)

  1. Install DHCP:
    sudo apt install isc-dhcp-server
    
  2. Edit /etc/dhcp/dhcpd.conf:
    subnet 192.168.1.0 netmask 255.255.255.0 {
        range 192.168.1.100 192.168.1.200;
        option routers 192.168.1.1;
        option domain-name-servers 103.102.128.100, 8.8.8.8;
        default-lease-time 24h;
        max-lease-time 72h;
    }
    

Advanced Topics

DNS Caching and Propagation

  • Local Cache: Resolvers cache DNS records (TTL = Time To Live). For example, if google.com has a TTL of 300s, your resolver won’t query again until 5 minutes.
  • Propagation Delay: When DNS records change (e.g., esewa.com.np moves to a new IP), it takes time (up to 48h) for all caches to update. This is why websites may be unreachable temporarily during migrations.

DHCP Relay Agent

In large networks (e.g., a university campus), DHCP servers may not be on the same subnet as clients. A DHCP relay agent forwards DHCP DISCOVER messages to the DHCP server and returns DHCP OFFER messages to clients.

DHCP DISCOVER (Broadcast)DHCP DISCOVER (Unicast)DHCP OFFERDHCP OFFERClientSubnetRelayAgentServerSubnetClientDHCPServer
DHCP Relay Agent forwarding across subnets

DNSSEC (DNS Security Extensions)

DNSSEC adds digital signatures to DNS records to prevent spoofing. For example:

  • A google.com DNS record includes a signature signed by Google’s private key.
  • Resolvers verify the signature using Google’s public key (distributed via DNSKEY records).
  • If the signature is invalid, the resolver rejects the response (e.g., "DNSSEC validation failed").

Common DNS and DHCP Issues and Solutions

Issue Cause Solution
DNS resolution fails Incorrect DNS server IP Set correct DNS (e.g., 8.8.8.8 or NTC’s)
DHCP IP not assigned DHCP server offline Restart DHCP service or check server
IP conflict Two devices with same IP Release/renew IP (ipconfig /release)
Slow DNS lookups Cached stale records Clear cache (ipconfig /flushdns)
DHCP lease not renewed Lease expired Manually renew (dhclient -r && dhclient)

Exam Tip

  1. DNS Hierarchy: Always draw the DNS query flow (root → TLD → authoritative) in exams. Use the sequence diagram above as a template.
  2. DHCP Process: Memorize the 4-step handshake (DISCOVER, OFFER, REQUEST, ACK). Examiners often ask to trace a DHCP assignment.
  3. Record Types: Know the purpose of A, AAAA, MX, CNAME, NS, TXT. For example:
    • "Why does mail.google.com resolve to an IP?" → MX record.
    • "How does www.esewa.com point to esewa.com.np?" → CNAME record.
  4. Configuration: Be ready to write minimal BIND or DHCP config snippets (e.g., defining a zone or subnet).
  5. Real-World Scenarios: Expect questions like:
    • "Explain how NTC assigns IPs to home users using DHCP."
    • "Trace the DNS lookup for khalti.com starting from your laptop."
  6. Troubleshooting: Practice diagnosing issues like:
    • "A user cannot access daraz.com.np. The ping works but the browser fails. What could be wrong?" → DNS issue (e.g., HOSTS file override or ISP DNS blocking).

Based on the TU BITM syllabus for Networking and System Administration (IT271), unit 6.

Discussion

Loading…