Cisco – Setting ip helper-address to a broadcast address, bad idea

ciscodhcpnetworking

Info:

  • A number of vlans running on a 16 bit subnet
  • All DHCP servers are on the same subnet (10.1.0.0/16)
  • All switches and routers are Cisco

If I was to set the ip helper-address in our routers/switches to point to 10.1.255.255 would it be a bad idea?

What ramifications would it have on the network (speed, security, etc)?

Best Answer

Yes it is a bad idea.

The Cisco documentation says this, "The helper address can be a specific DHCP server address, or it can be the network address if other DHCP servers are on the destination network segment. Using the network address enables other servers to respond to DHCP requests."

While this will save you work short term, the end result is that any rogue DHCP servers (accidental or malicious) in that /16 will be able to hand addresses to your entire network as well. This doesn't seem like a good trade off to me.

If you are looking to save work, why not re-use the existing DHCP server IPs on the new servers?