Skip to main content
The Windows DHCP scan module captures Windows DHCP servers with server options, scopes, scope options, reservations and active leases. It requires a connected gateway.

Captured data

Each DHCP server becomes an asset of the type DHCP. The detail page groups the data as follows: How the detail page of the type is structured is described in Directory and Network Services.

Setting up the job

The wizard follows the standard path Basics › Targets › Schedule › Summary—see Creating a Scan Job. The Targets step is what sets this module apart. Each row carries the columns Server Name and Credentials. Server Name takes one DHCP server per row, as an address or hostname; the column does not accept an address range. Search DHCP Servers fills in the servers from Active Directory instead: the dialog asks for the Domain and credentials and adds the DHCP servers authorized in Active Directory as rows. The Credentials column may stay empty. The scan then runs under the gateway’s service account, and that account needs the rights listed under Permissions. An entry in Credentials for all targets applies to every row without an assignment of its own.

Prerequisites

The scan connects to the DHCP servers over WMI and queries the DHCP data through PowerShell.

Ports and protocols

Permissions

  • On the DHCP servers, local administrator rights are sufficient.
  • Enter the account with the domain: DOMAIN\user or user@domain.local.

Network requirements

  • The firewall allows the ports above.
  • The DHCP servers have:
    • .NET Framework 4.6.1 or later,
    • PowerShell 3 or later, allowed to run,
    • the PowerShell module for DHCP,
    • access to C:\Windows\Temp and to the IPC$ share.
Scan DHCP servers the gateway cannot reach directly on the server with the Discovery-DHCP.exe scan script—see Scanning by Script.

Common issues

After it is created, the job appears among the jobs; how you watch and adjust it is in Managing Jobs. You capture the DNS servers of the same domain with Windows DNS.