Skip to main content
AD Academy
CCNA — Cisco Networking Fundamentals
Beginner12 minLast updated: Topic 5 of 12

Network Services: DHCP, DNS, NAT, and NTP

The services that run every enterprise network — and also every Active Directory environment.

Not read

What you will learn here

  • What DHCP hands out to a computer
  • Why DNS and NTP are critical for AD
  • How NAT connects an internal network to the internet

Worth reading first:Routing: Static, OSPF and Default Route

Without DHCP, DNS, and NTP, an enterprise network simply doesn't work — and in an environment, they are especially critical: fails if the clock deviates by more than 5 minutes.

  • DHCP — distributes IP, Mask, Gateway, and DNS (DORA process).
  • DNS — translates names to addresses; in , also SRV records for locating Controllers.
  • NAT/PAT — translates private addresses to a single public address.
  • NTP — clock synchronization; mandatory for .
! DHCP Relay to the DHCP server in the server farm
Router(config-if)# ip helper-address 192.168.50.10

! NAT/PAT for Internet access
Router(config)# access-list 1 permit 192.168.10.0 0.0.0.255
Router(config)# ip nat inside source list 1 interface gi0/1 overload
Router(config)# interface gi0/0
Router(config-if)# ip nat inside
Router(config)# interface gi0/1
Router(config-if)# ip nat outside

! NTP
Router(config)# ntp server 192.168.50.10
bash
Architecture and Theory — Under the Hood

Network services are the 'transparent' infrastructure: DHCP distributes addresses, DNS translates names, NAT allows internet access, and NTP synchronizes time — without synchronized time, simply won't work.

DHCP DORA:
 Client --Discover(broadcast)--> Server
        <--Offer----------------
        --Request-------------->
        <--Ack------------------  (IP + Mask + GW + DNS + Lease)
text
  • DHCP Relay (ip helper-address): Forwards client Broadcast as Unicast to the server in another VLAN.
  • NAT: Static (1:1), Dynamic (Pool), PAT/Overload — many clients behind one IP by ports.
  • DNS: Recursive Resolver → Root → TLD → Authoritative; TTL determines how long it is cached.
  • NTP: Stratum 0 = atomic clock, each layer adds 1. Deviation above 5 minutes breaks .
Practical Configuration (CLI)
! DHCP on Router
R(config)# ip dhcp excluded-address 192.168.10.1 192.168.10.20
R(config)# ip dhcp pool USERS
R(dhcp-config)# network 192.168.10.0 255.255.255.0
R(dhcp-config)# default-router 192.168.10.1
R(dhcp-config)# dns-server 192.168.10.10
R(dhcp-config)# lease 8

! DHCP Relay
R(config-if)# ip helper-address 192.168.50.10

! PAT (Overload)
R(config)# access-list 1 permit 192.168.10.0 0.0.0.255
R(config)# ip nat inside source list 1 interface gi0/1 overload
R(config)# interface gi0/0
R(config-if)# ip nat inside
R(config)# interface gi0/1
R(config-if)# ip nat outside

! NTP
R(config)# ntp server 192.168.10.10 prefer
bash
Real-world Scenarios in an Organization
  • In an organization with : DHCP and DNS reside on Windows Server, and the router only performs Relay.
  • PAT is the default in every branch — the entire internal network exits through one public IP.
  • Static NAT for a Web/VPN server that needs to be accessible from outside.
  • All network equipment and servers are synchronized to the same NTP source — critical for incident investigation and logs.
Troubleshooting
R# show ip dhcp binding
R# show ip dhcp pool
R# debug ip dhcp server events
R# show ip nat translations
R# clear ip nat translation *
R# show ntp status
R# show ntp associations
bash
  • Client receives 169.254.x.x (APIPA) → Did not reach DHCP: missing helper-address or Pool is full.
  • Has IP but no internet → Check NAT (inside/outside on the correct interfaces) and Default Route.
  • Name does not resolve but ping to IP works → DNS issue, not a network issue.
  • login failures at certain times → Check NTP.
Glossary and Quick Command Line
  • DORA = Discover, Offer, Request, Ack
  • ip helper-address <dhcp-server> — on the client interface
  • ip nat inside / outside — mandatory on both sides
  • Ports: DHCP 67/68, DNS 53, NTP 123

Check yourself

Why is ip helper-address needed?

Which service is critical for Kerberos integrity in AD?

Was this page helpful?