DHCP Scope Calculator
Size a DHCP pool from device count and churn, choose a lease time that balances address reuse against broadcast load, and see when the scope will exhaust.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Lease time governs how fast addresses return
An address is unavailable for the whole lease duration after a device leaves, whether or not it is still there. A guest network with an eight day lease and heavy turnover exhausts a /24 within a day, because every visitor who connected for five minutes holds an address for the rest of the week. A two hour lease on the same network returns addresses quickly enough that a small pool serves many times its size in visitors. On a stable office network the reverse applies: long leases reduce renewal traffic and mean devices keep the same address across a reboot.
Renewal happens at half the lease, not at the end
A client attempts renewal at fifty percent of the lease duration and again at 87.5 percent, so a two hour lease produces a renewal from every device every hour. On a large network that is a meaningful amount of broadcast traffic and load on the DHCP server. It also means a server outage is survivable for half a lease period before anything loses its address, which is an argument for longer leases on infrastructure networks.
Reserve the ends of the range
Static addresses for routers, switches, printers and servers should sit outside the dynamic pool, conventionally at the low end, with the pool starting above them. Overlapping the two produces an address conflict that appears intermittently, only when the DHCP server happens to hand out an address already in static use, and it is one of the harder faults to diagnose because it works most of the time.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
What lease time should I use?
Eight days is a common default for stable office networks and is far too long for anything with turnover. Guest wifi wants one to four hours, a conference network one hour, and a stable server VLAN can use weeks. Match it to how quickly addresses need to return.
When does a client renew its lease?
At 50 percent of the lease duration, and again at 87.5 percent if the first attempt failed. That means a short lease multiplies renewal traffic, and it also means a DHCP server can be down for half a lease period before any device loses its address.
How much of a subnet can I use for the pool?
Everything except the network address, the broadcast address, the gateway and any static assignments. Keeping statics in a reserved block at the low end and starting the pool above them avoids conflicts that appear only intermittently.
What happens when a scope is exhausted?
New devices get no address and fail to connect, while existing ones keep working, so the fault looks like a problem affecting only new arrivals. Shortening the lease is the fastest mitigation because it returns abandoned addresses sooner.
Should I use DHCP reservations or static configuration?
Reservations, generally: the address is managed centrally, appears in the DHCP records, and changing the subnet does not mean visiting every device. Configure statically only where the device must work when DHCP does not, such as the DHCP server itself.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter your device count and turnover rate to size the pool and choose a lease duration.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.