> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Windows DHCP

> Capturing Windows DHCP servers with server options, scopes, reservations and leases—with credentials of your own or under the gateway's service account.

The *Windows DHCP* scan module captures Windows DHCP servers with server
options, scopes, scope options, reservations and active leases. It requires a
connected [gateway](/docs/en/scan/gateway-install).

## Captured data

Each DHCP server becomes an asset of the type *DHCP*. The detail page groups
the data as follows:

| Group | Content |
| - | - |
| IPv4 Settings | configured network adapters, high availability, policies, classes, option definitions, server options, filter settings |
| IPv4 Scopes | scopes, superscopes, multicast scopes |
| IPv4 Scope Exclusions | exclusions per scope and multicast scope |
| IPv4 Server Statistics | server statistics, occupancy of superscopes and scopes |

How the detail page of the type is structured is described in
[Directory and Network Services](/docs/en/assets/directory-services).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries the columns *Server Name* and *Credentials*. *Server Name*
takes one DHCP server per row, as an address or hostname; the column does not
accept an address range.

*Search DHCP Servers* fills in the servers from Active Directory instead: the
dialog asks for the *Domain* and credentials and adds the DHCP servers
authorized in Active Directory as rows.

The *Credentials* column may stay empty. The scan then runs under the
gateway's service account, and that account needs the rights listed under
[Permissions](#permissions). An entry in *Credentials for all targets* applies
to every row without an assignment of its own.

## Prerequisites

The scan connects to the DHCP servers over WMI and queries the DHCP data
through PowerShell.

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| NetBIOS Name Service, NetBIOS Datagram Service | 137, 138 | UDP |
| NetBIOS Session Service, SMB / CIFS over TCP | 139, 445 | TCP |
| RPC, dynamic ports | 49152–65535 | TCP/UDP |

### Permissions

* On the DHCP servers, local administrator rights are sufficient.
* Enter the account with the domain: `DOMAIN\user` or `user@domain.local`.

### Network requirements

* The firewall allows the ports above.
* The DHCP servers have:
  * .NET Framework 4.6.1 or later,
  * PowerShell 3 or later, allowed to run,
  * the PowerShell module for DHCP,
  * access to `C:\Windows\Temp` and to the `IPC$` share.

Scan DHCP servers the gateway cannot reach directly on the server with the
`Discovery-DHCP.exe` scan script—see
[Scanning by Script](/docs/en/scan/scan-by-script).

## Common issues

| Symptom | Cause | Resolution |
| - | - | - |
| *Search DHCP Servers* lists old DHCP servers that are no longer in use. | The servers are still authorized in Active Directory. | Revoke the authorization of the old servers; they no longer appear afterwards. |

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). You capture the DNS servers of
the same domain with [Windows DNS](/docs/en/scan/dns).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.