How to Configure DHCP Server on Cisco Switch and Reserve IP Addresses
What is DHCP?
DHCP stands for Dynamic Host Configuration Protocol. It is a network protocol that automatically assigns IP addresses and other network parameters — such as subnet mask, default gateway, and DNS server — to devices on a network. Without DHCP, every device would need to be manually configured with a unique IP address, which quickly becomes unmanageable as the network grows.
Cisco switches and routers can act as a DHCP server directly, removing the need for a dedicated server in small to medium-sized networks.
How DHCP Works — The DORA Process
Every time a device joins the network and requests an IP address, it goes through a four-step exchange with the DHCP server known as the DORA process:
- Discover: The client broadcasts a DHCPDISCOVER message across the network to locate any available DHCP server.
- Offer: The DHCP server responds with a DHCPOFFER message containing an available IP address and configuration parameters.
- Request: The client replies with a DHCPREQUEST message, formally requesting the offered IP address.
- Acknowledge: The server confirms the lease by sending a DHCPACK message. The client applies the IP configuration and joins the network.
This process repeats when a device restarts or when the IP lease expires. The lease duration is configurable — shorter leases reclaim addresses faster in dynamic environments, while longer leases reduce DHCP traffic overhead.
Configure DHCP Server on a Cisco Switch
The configuration involves three parts: excluding addresses that should never be assigned dynamically (such as the gateway and any reserved IPs), creating the DHCP pool that defines the address range and options, and optionally setting a lease duration.
Step 1 — Exclude Addresses from Dynamic Assignment
Before creating the DHCP pool, exclude the IP addresses you do not want DHCP to hand out automatically. This typically includes the default gateway, network devices, printers, servers, and any address you plan to reserve for a specific device.
SW01(config)# ip dhcp excluded-address 192.168.1.1 192.168.1.10
This excludes the range 192.168.1.1 through 192.168.1.10. Addresses outside this range will be available for dynamic assignment. You can add multiple exclusion statements if needed.
Step 2 — Create the DHCP Pool
Define the DHCP pool with the network range, default gateway, and DNS server:
SW01(config)# ip dhcp pool LAN-POOL SW01(dhcp-config)# network 192.168.1.0 255.255.255.0 SW01(dhcp-config)# default-router 192.168.1.1 SW01(dhcp-config)# dns-server 8.8.8.8 SW01(dhcp-config)# lease 7 SW01(dhcp-config)# end
The lease 7 command sets the IP lease duration to 7 days. You can also specify hours and minutes using lease <days> <hours> <minutes>, or use lease infinite for a permanent lease.
Full Configuration
SW01# configure terminal SW01(config)# ip dhcp excluded-address 192.168.1.1 192.168.1.10 SW01(config)# ip dhcp pool LAN-POOL SW01(dhcp-config)# network 192.168.1.0 255.255.255.0 SW01(dhcp-config)# default-router 192.168.1.1 SW01(dhcp-config)# dns-server 8.8.8.8 SW01(dhcp-config)# lease 7 SW01(dhcp-config)# end SW01# write memory
Verify DHCP Operation
After configuration, use show ip dhcp binding to confirm that the server is handing out addresses to clients:
SW01# show ip dhcp binding
Bindings from all pools not associated with VRF:
IP address Client-ID/ Lease expiration Type State Interface
Hardware address/
User name
192.168.1.11 0050.7966.6801 Jul 08 2025 09:00 AM Automatic Active GigabitEthernet0/1
192.168.1.12 0050.7966.6802 Jul 08 2025 09:00 AM Automatic Active GigabitEthernet0/2
192.168.1.13 0050.7966.6803 Jul 08 2025 09:00 AM Automatic Active GigabitEthernet0/3
Each line shows the assigned IP, the client's hardware address (MAC), the lease expiry time, and the type (Automatic for dynamically assigned addresses). Additional useful verification commands:
SW01# show ip dhcp pool ! View pool statistics and address usage SW01# show ip dhcp conflict ! Check for any IP conflicts detected by the server
DHCP IP Reservation — Assign a Fixed IP to a Specific Device
DHCP IP reservation (also called a static DHCP binding or DHCP reservation) allows you to permanently assign a specific IP address to a device based on its MAC address. The device still goes through the normal DORA process, but the DHCP server always returns the same IP address for that particular MAC — giving you the convenience of DHCP with the predictability of a static IP.
This is ideal for devices that need a consistent IP address — such as printers, servers, IP cameras, or access points — without having to configure static IPs on each device individually.
How client-identifier Works
Cisco DHCP reservations use the client-identifier to identify a device. The client-identifier is derived from the device's MAC address with a prefix of 01 added at the beginning, which represents the Ethernet hardware type.
For example, if a device has a MAC address of 00:50:79:66:68:02, the client-identifier is:
0100.5079.6668.02
The format breakdown is: 01 (Ethernet type prefix) + MAC address with dots every four characters. You can find the MAC address of a device from the show ip dhcp binding output, ARP table, or from the device itself.
The client-identifier must include the 01 prefix. Without it, the reservation will not match the client and the device will receive a dynamic address instead.
Converting a MAC Address to client-identifier
If you have a MAC address in the standard format, here is how to convert it:
MAC address: 00:50:79:66:68:02 (or 00-50-79-66-68-02) Remove separators: 005079666802 Add 01 prefix: 01005079666802 Cisco format: 0100.5079.6668.02
Configuration — Single Reservation
Each reservation requires its own DHCP pool. The pool uses host instead of network to define a single IP address:
SW01(config)# ip dhcp pool RESERVATION-PRINTER SW01(dhcp-config)# host 192.168.1.20 255.255.255.0 SW01(dhcp-config)# client-identifier 0100.5079.6668.02 SW01(dhcp-config)# client-name OFFICE-PRINTER SW01(dhcp-config)# end
The reserved IP address (192.168.1.20 in this example) must also be in the excluded range defined by ip dhcp excluded-address. If it is not excluded, the DHCP server may hand that address out to another device before the reservation is used, causing an IP conflict.
Configuration — Multiple Reservations
For multiple devices, create a separate pool for each reservation. Here is a complete configuration example with a dynamic pool and three reservations:
SW01# configure terminal ! Reservation for Office Printer SW01(config)# ip dhcp pool RESERVATION-PRINTER SW01(dhcp-config)# host 192.168.1.20 255.255.255.0 SW01(dhcp-config)# client-identifier 0100.5079.6668.02 SW01(dhcp-config)# client-name OFFICE-PRINTER ! Reservation for PC-01 SW01(config)# ip dhcp pool RESERVATION-PC-01 SW01(dhcp-config)# host 192.168.1.21 255.255.255.0 SW01(dhcp-config)# client-identifier 0100.5079.6668.03 SW01(dhcp-config)# client-name PC-01 ! Reservation for PC-02 SW01(config)# ip dhcp pool RESERVATION-PC-02 SW01(dhcp-config)# host 192.168.1.22 255.255.255.0 SW01(dhcp-config)# client-identifier 0100.5079.6668.04 SW01(dhcp-config)# client-name PC-02 SW01(dhcp-config)# end SW01# write memory
Verify DHCP Reservations
Use show ip dhcp binding to confirm reservations are active. Reserved entries show as Manual type with an Infinite lease — unlike dynamic assignments which show Automatic with an expiry time:
SW01# show ip dhcp binding
Bindings from all pools not associated with VRF:
IP address Client-ID/ Lease expiration Type State Interface
Hardware address/
User name
192.168.1.11 0050.7966.6801 Jul 08 2025 09:00 AM Automatic Active GigabitEthernet0/1
192.168.1.20 0100.5079.6668.02 Infinite Manual Active Unknown
192.168.1.21 0100.5079.6668.03 Infinite Manual Active Unknown
192.168.1.22 0100.5079.6668.04 Infinite Manual Active Unknown
The key indicators that a reservation is correctly configured:
- Type: Manual — confirms this is a static reservation, not a dynamic assignment
- Lease expiration: Infinite — reserved IPs never expire
- State: Active — the binding is in use; it shows Inactive if the device has not yet requested an IP
You can also view the pool configuration to confirm all reservations are saved correctly:
SW01# show ip dhcp pool Pool RESERVATION-PRINTER : Utilization mark (high/low) : 100 / 0 Subnet size (first/next) : 0 / 0 Total addresses : 1 Leased addresses : 1 Pending event : none 1 subnet is currently in the pool: Current index IP address range Leased/Excluded/Total 192.168.1.20 192.168.1.20 - 192.168.1.20 1 / 0 / 1
A reservation showing Leased: 1 confirms the device is actively using the reserved IP address.
Troubleshooting DHCP Reservations
-
Device receives a random IP instead of the reserved one — The client-identifier does not match. Double-check the MAC address of the device and ensure the identifier is formatted correctly with the
01prefix and dots every four characters (e.g.,0100.5079.6668.02). -
IP conflict on the reserved address — The reserved IP is not in the excluded-address range. Add an explicit exclusion:
ip dhcp excluded-address 192.168.1.20. Without this, the dynamic pool may assign that address to another device before the reserved device requests it. - State shows Inactive — The device has not yet sent a DHCP request. This is normal if the device has not been connected or has not renewed its lease. Once the device requests an IP, the state will change to Active.
-
Reservation not matching on Windows clients — Some Windows versions send a DHCP client-identifier based on the hostname rather than the MAC address. In this case, use the
hardware-addresscommand instead ofclient-identifier:SW01(dhcp-config)# hardware-address 0050.7966.6802
-
Changes not taking effect after editing a pool — Clear the existing binding and force the device to renew:
clear ip dhcp binding 192.168.1.20. Then release and renew the IP on the client side.
Summary
Configuring a Cisco switch or router as a DHCP server eliminates the need for manual IP assignment across the network. Adding DHCP reservations on top of that gives you the best of both worlds — devices join the network automatically through DHCP, but critical devices always receive the same predictable IP address every time.
The key points to remember:
- Always exclude reserved IPs and gateway addresses from the dynamic pool using
ip dhcp excluded-address - Each DHCP reservation requires its own pool using
hostinstead ofnetwork - The
client-identifieris the device MAC address with an01prefix in Cisco dotted format - Reserved bindings appear as Manual / Infinite in
show ip dhcp binding - If a client does not match, check the client-identifier format first — it is the most common cause of reservation failures
Proper use of DHCP reservations removes the maintenance burden of managing static IPs on individual devices while keeping your address plan predictable and conflict-free.