Back to Course
Week 8 Practical

NZSE Campus: Subnetting with DHCP

Design the campus subnets, build a router-on-a-stick, and hand out IP addresses automatically with DHCP

🌐 Introduction to Networks 🛠️ Packet Tracer 👤 Reza Farashahi

The NZSE campus is growing. The IT team needs to split the campus network into separate segments — one for the Library, one for the Computer Labs, one for Administration, one for Academic Staff, one for the Student Wi-Fi, and one for the Servers / Data Centre. Keeping every device on one flat network would flood it with broadcast traffic and let student Wi-Fi devices reach sensitive admin and server systems.

Subnetting divides one large Class B network into smaller department segments, each with its own broadcast domain — this reduces congestion, improves security, and makes faults easier to locate. But assigning a static IP to every laptop, PC and phone on campus by hand is impossible. That is where DHCP (Dynamic Host Configuration Protocol) comes in: the router hands out IP addresses, subnet masks, gateways and DNS servers automatically as devices connect.

In this practical you will subnet the Class B network 172.20.0.0/16, provision it for future growth, and map six subnets to six campus departments. Then you will build the network in Packet Tracer using VLANs and a router-on-a-stick, configure a DHCP pool for every department, and watch each PC receive its address automatically. Finally you will verify everything with ipconfig and ping.

📝 Task 1 — Subnet Calculation

The IT team has assigned NZSE the Class B network:

Step 1 — Determine bits to borrow

We need 6 subnets now, but the design rule says provision for up to 16. How many host bits must you borrow to create at least 16 subnets?

Why design for growth? If we borrowed only 3 bits we would get exactly 8 subnets — enough for today, but the moment NZSE adds a 9th department we would have to re-address the entire campus. Borrowing 4 bits gives 16 subnets: we use 6 now and keep 10 in reserve.

Step 2 — New subnet mask

Step 3 — Hosts per subnet

Work out the following from the /20 subnet mask:

QuestionYour Answer
Remaining host bits
Total addresses per subnet (2?)
Usable hosts per subnet (2? − 2)

Step 4 — Block size

Step 5 — Complete the department subnet table

Fill in the details for the 6 subnets in use. Each row already shows which department the subnet belongs to.

Subnet Department Network Address First Usable Host Last Usable Host Broadcast Address
1 Library
2 Computer Labs
3 Administration
4 Academic Staff
5 Student Wi-Fi
6 Servers
Reference — gateways you will use later: By convention the first usable host (.1) of each subnet becomes the router gateway for that department: Library 172.20.0.1, Computer Labs 172.20.16.1, Administration 172.20.32.1, Academic Staff 172.20.48.1, Student Wi-Fi 172.20.64.1, Servers 172.20.80.1.

📦 Task 2 — Build the Topology in Packet Tracer

Create the following network in Packet Tracer. We will use a Router-on-a-Stick design: one physical cable carries traffic for all six departments using VLANs (Virtual LANs).

What is a VLAN? A VLAN lets you split one physical switch into multiple isolated virtual networks. Devices in different VLANs cannot communicate directly — they need a router, just like separate physical networks. Each VLAN represents one campus department.

Equipment

Cabling

  1. Place the Router at the top of the workspace.
  2. Place the Switch below the router.
  3. Connect the router GigabitEthernet0/0 to the switch GigabitEthernet0/1 using a Copper Straight-Through cable (this becomes the trunk).
  4. Connect each end device (FastEthernet0) to the switch using Copper Straight-Through cables:
    • Library: PC-Lib-1 → Fa0/1  |  PC-Lib-2 → Fa0/2
    • Computer Labs: PC-Lab-1 → Fa0/3  |  PC-Lab-2 → Fa0/4
    • Administration: PC-Admin-1 → Fa0/5  |  PC-Admin-2 → Fa0/6
    • Academic Staff: PC-Staff-1 → Fa0/7  |  PC-Staff-2 → Fa0/8
    • Student Wi-Fi: PC-Guest-1 → Fa0/9  |  PC-Guest-2 → Fa0/10
    • Servers: DNS-Server → Fa0/11
Tip: Rename each device (click it → Config tab → Display Name) to match the labels above. Grouping each department in its own column keeps the diagram easy to read.

🔧 Task 3 — Configure the Switch

Click on the Switch, go to the CLI tab, and paste the following configuration. This creates 6 VLANs (one per department), assigns the device ports to the correct VLAN, and sets up a trunk link to the router.

Part A — Enter privileged mode & global configuration

enable
configure terminal
hostname CampusSwitch

Part B — Create VLANs

We create 6 VLANs — one for each department. A VLAN (Virtual LAN) logically separates ports on the same physical switch into isolated networks. Devices in the Student Wi-Fi VLAN cannot talk to devices in the Servers VLAN without going through the router, just as if they were on completely separate switches.

vlan 10
 name Library
vlan 20
 name Computer_Labs
vlan 30
 name Administration
vlan 40
 name Academic_Staff
vlan 50
 name Student_WiFi
vlan 60
 name Servers

Part C — Assign ports to VLANs (access mode)

Each department's devices plug into specific switch ports. We put those ports in access mode and assign them to the correct VLAN. An access port belongs to exactly one VLAN and strips the VLAN tag before sending frames to the device (the PC never knows it is on a VLAN).

interface range FastEthernet0/1-2
 switchport mode access
 switchport access vlan 10
!
interface range FastEthernet0/3-4
 switchport mode access
 switchport access vlan 20
!
interface range FastEthernet0/5-6
 switchport mode access
 switchport access vlan 30
!
interface range FastEthernet0/7-8
 switchport mode access
 switchport access vlan 40
!
interface range FastEthernet0/9-10
 switchport mode access
 switchport access vlan 50
!
interface FastEthernet0/11
 switchport mode access
 switchport access vlan 60

Part D — Configure the trunk link to the router

The uplink from the switch to the router must carry traffic for all 6 VLANs over a single cable. We set this port to trunk mode. A trunk port tags every outgoing frame with its VLAN ID (using the 802.1Q standard) so the router knows which department the frame belongs to.

interface GigabitEthernet0/1
 switchport mode trunk

Part E — Save the configuration

end
write memory
Access vs Trunk summary: An access port carries traffic for a single VLAN (connects to PCs and servers). A trunk port carries traffic for all VLANs over one cable (connects to the router). Without the trunk, the router would need a separate physical cable for every department.

🖧 Task 4 — Configure the Router (Gateways)

Click on the Router, go to the CLI tab, and enter the following. This creates 6 sub-interfaces on a single physical port — one per department — each acting as the default gateway for its subnet.

Part A — Enter privileged mode & bring up the physical interface

enable
configure terminal
hostname CampusRouter
!
interface GigabitEthernet0/0
 no shutdown

Part B — Create sub-interfaces (one per department)

A sub-interface is a logical division of a physical interface. The router uses sub-interfaces to handle traffic from different VLANs on the same physical cable — this is the “router-on-a-stick” design. Each sub-interface needs an 802.1Q encapsulation (which VLAN tag to match) and an IP address (the gateway for that department).

interface GigabitEthernet0/0.10
 encapsulation dot1Q 10
 ip address 172.20.0.1 255.255.240.0
!
interface GigabitEthernet0/0.20
 encapsulation dot1Q 20
 ip address 172.20.16.1 255.255.240.0
!
interface GigabitEthernet0/0.30
 encapsulation dot1Q 30
 ip address 172.20.32.1 255.255.240.0
!
interface GigabitEthernet0/0.40
 encapsulation dot1Q 40
 ip address 172.20.48.1 255.255.240.0
!
interface GigabitEthernet0/0.50
 encapsulation dot1Q 50
 ip address 172.20.64.1 255.255.240.0
!
interface GigabitEthernet0/0.60
 encapsulation dot1Q 60
 ip address 172.20.80.1 255.255.240.0
Note the /20 mask everywhere: every sub-interface uses 255.255.240.0, because each department is a /20 subnet. Only the network portion (the 3rd octet: 0, 16, 32, 48, 64, 80) changes between departments.
Do not save yet! Stay in configuration mode — in the next task we will add the DHCP configuration on this same router before saving.

📮 Task 5 — Configure DHCP on the Router

Instead of typing a static IP into every PC on campus, we let the router hand out addresses automatically. When a PC set to DHCP powers on, it broadcasts a request; the router replies with an IP address, subnet mask, default gateway and DNS server for that department.

What is DHCP? The Dynamic Host Configuration Protocol follows a four-step exchange — Discover → Offer → Request → Acknowledge (“DORA”). The client broadcasts a Discover, the DHCP server (our router) sends an Offer, the client sends a Request for that offer, and the server sends an Acknowledge to lease the address. Because the router already has a gateway on every VLAN, it can serve DHCP for all six departments.

Part A — Reserve addresses that must stay static

Some addresses must never be handed out to random devices: the gateway (.1) and a small block reserved for printers, access points and other fixed infrastructure. We exclude the first 10 addresses of each user subnet.

ip dhcp excluded-address 172.20.0.1 172.20.0.10
ip dhcp excluded-address 172.20.16.1 172.20.16.10
ip dhcp excluded-address 172.20.32.1 172.20.32.10
ip dhcp excluded-address 172.20.48.1 172.20.48.10
ip dhcp excluded-address 172.20.64.1 172.20.64.10

Part B — Create a DHCP pool for each department

Each pool defines the subnet to lease from, the gateway to advertise, and the DNS server. The DNS server lives in the Servers VLAN at 172.20.80.10.

ip dhcp pool LIBRARY
 network 172.20.0.0 255.255.240.0
 default-router 172.20.0.1
 dns-server 172.20.80.10
!
ip dhcp pool COMPUTER_LABS
 network 172.20.16.0 255.255.240.0
 default-router 172.20.16.1
 dns-server 172.20.80.10
!
ip dhcp pool ADMINISTRATION
 network 172.20.32.0 255.255.240.0
 default-router 172.20.32.1
 dns-server 172.20.80.10
!
ip dhcp pool ACADEMIC_STAFF
 network 172.20.48.0 255.255.240.0
 default-router 172.20.48.1
 dns-server 172.20.80.10
!
ip dhcp pool STUDENT_WIFI
 network 172.20.64.0 255.255.240.0
 default-router 172.20.64.1
 dns-server 172.20.80.10
How does the router pick the right pool? A DHCP Discover arrives on a sub-interface (e.g. GigE0/0.40 for Academic Staff). The router looks at that sub-interface's IP (172.20.48.1 / a /20) and matches it to the pool whose network statement covers it — the ACADEMIC_STAFF pool. That is why the pool networks must line up exactly with your sub-interface subnets.

Part C — Save the configuration

end
write memory

🔢 Task 6 — Configure the End Devices

Part A — The Server (static)

The campus server must keep a fixed address so clients (and the DHCP dns-server line) can always find it. Click DNS-Server → Desktop tab → IP Configuration → select Static and enter:

SettingValue
IPv4 Address172.20.80.10
Subnet Mask255.255.240.0
Default Gateway172.20.80.1
DNS Server172.20.80.10

Part B — The PCs (automatic via DHCP)

Every client PC gets its address automatically. For each of the 10 PCs:

  1. Click the PC → Desktop tab → IP Configuration.
  2. Select DHCP (instead of Static).
  3. Wait a moment — you should see “DHCP request successful” and the fields fill in automatically.
  4. Close the window and repeat for all 10 PCs.
What to expect: Because we excluded the first 10 addresses, the first PC in each department receives .11, the second .12, and so on. For example the two Library PCs should get 172.20.0.11 and 172.20.0.12, each with mask 255.255.240.0 and gateway 172.20.0.1.
If a PC shows 169.254.x.x or “DHCP request failed”: that is an APIPA address, meaning the PC could not reach the DHCP server. Check that the switch port is in the right VLAN (show vlan brief), the trunk is up, and the matching router sub-interface and DHCP pool exist.

📡 Task 7 — Verify Connectivity

A — Confirm the DHCP lease on a PC

Open the Command Prompt on PC-Lib-1 and run:

ipconfig /all

Confirm the PC received an address in the Library subnet (e.g. 172.20.0.11), mask 255.255.240.0, gateway 172.20.0.1, and DNS 172.20.80.10.

B — Ping within the same department

From PC-Lib-1, ping PC-Lib-2 (same VLAN):

ping 172.20.0.12

This should succeed immediately — both PCs are in the same VLAN and do not need the router.

C — Ping across departments

  1. Library → Administration: from PC-Lib-1 ping 172.20.32.11
  2. Academic Staff → Student Wi-Fi: from PC-Staff-1 ping 172.20.64.11
  3. Any PC → the Server: ping 172.20.80.10

This traffic goes: PC → Switch → Router (routes between VLANs) → Switch → destination. All pings should return successful replies.

D — Verify DHCP on the router

On the router CLI, run:

show ip dhcp binding
show ip dhcp pool
show ip interface brief
Troubleshooting: If a ping fails:
  • Run ipconfig on the PC — confirm it holds a DHCP address, not 169.254.x.x
  • Verify the PC is connected to the correct switch port and VLAN (show vlan brief)
  • Confirm the trunk is up and the router sub-interfaces are up/up (show ip interface brief)
  • Check the DHCP pool's default-router matches the sub-interface IP for that VLAN

💬 Reflection Questions

  1. Why did we borrow 4 bits (provision for 16 subnets) instead of exactly 3 bits for our 6 departments?
  2. Why do we ip dhcp excluded-address the first 10 addresses of each subnet before creating the pool?
  3. Why is the campus Server given a static IP instead of using DHCP like the PCs?
  4. A student's laptop connects in the Library and gets 172.20.0.11, then moves to the Computer Labs. Will it keep the same IP address? Explain what happens.
  5. How does the router decide which DHCP pool to answer from when a request arrives on VLAN 40?
  6. Each /20 department can hold 4094 hosts, but Administration has only 30 devices. Is a /20 an efficient size for it? What could you do differently?
  7. What would happen to the PCs if the default-router line was missing from a DHCP pool?

📋 Summary

In this practical you have:

Tip: Save your Packet Tracer file — you may extend this network in future practicals (for example, adding an ACL so Student Wi-Fi cannot reach the Servers VLAN).