# Windows DHCP Failover Between Two Servers: Reliable Setup

Source: https://srvscripts.com/guides/windows-dhcp-failover/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

A single DHCP server takes the whole network with it a few hours after it dies, once leases start expiring. Windows Server has had built-in DHCP failover since 2012, and it is far more practical than the old split-scope arrangement: both servers share the full scope, leases replicate between them, and clients keep the same address whichever server answers. The steps apply to Windows Server 2019, 2022 and 2025 and to IPv4 scopes.

In short: Install the DHCP role on the second server and authorise it, then on the server that already holds the scopes run Add-DhcpServerv4Failover -ComputerName dhcp01 -PartnerServer dhcp02 -Name “HQ-Failover” -ScopeId 10.10.0.0…

**Short answer:** Install the DHCP role on the second server and authorise it, then on the server that already holds the scopes run `Add-DhcpServerv4Failover -ComputerName dhcp01 -PartnerServer dhcp02 -Name "HQ-Failover" -ScopeId 10.10.0.0 -LoadBalancePercent 50 -SharedSecret "long-random-string" -MaxClientLeadTime 01:00:00 -AutoStateTransition $true -StateSwitchInterval 00:10:00`, or use the DHCP console’s Configure Failover wizard. Choose Load balance for two servers on the same LAN and Hot standby for a remote backup; after any scope change run `Invoke-DhcpServerv4FailoverReplication` and confirm both servers show the relationship as Normal.

## Prepare the second server

Install and authorise the role on the partner, and make sure both servers are members of the same domain, run the same OS version or one release apart, and have accurate time:

```
Install-WindowsFeature DHCP -IncludeManagementTools
Add-DhcpServerInDC -DnsName dhcp02.corp.example.com -IPAddress 10.10.0.22
Add-DhcpServerSecurityGroup
Restart-Service DHCPServer
Get-DhcpServerInDC
```

Do not create scopes on the second server by hand; the failover relationship copies them. Open TCP 647 (the failover protocol port) between the two servers and allow UDP 67 and 68 from clients and relays to both. On the routers or layer-3 switches, add the second server to every `ip helper-address` list, otherwise the partner never sees a discover.

## Choose the mode

- Load balance: both servers answer, splitting the client population by a hash of the MAC address according to the percentage you set. Best for two servers in the same site. Leases are replicated as they are issued.

- Hot standby: the active server issues every lease and the standby only answers when the active one has been unreachable for longer than the state switchover interval. Best when the partner sits in another site or is a general-purpose server you do not want handling normal DHCP load. Reserve a small percentage of addresses (5 percent by default) for the standby to use in the communication-interrupted state.

The Maximum Client Lead Time (MCLT) is the extra time a server may extend a lease beyond what its partner knows; one hour is a sensible default and also governs how long a server waits before taking over the whole pool. Enable automatic state switchover so a dead partner is declared without an administrator’s intervention.

## Create the relationship

From the server that currently owns the scopes:

```
Add-DhcpServerv4Failover -ComputerName dhcp01.corp.example.com `
  -PartnerServer dhcp02.corp.example.com -Name "HQ-Failover" `
  -ScopeId 10.10.0.0, 10.20.0.0 -LoadBalancePercent 50 `
  -MaxClientLeadTime 01:00:00 -AutoStateTransition $true -StateSwitchInterval 00:10:00 `
  -SharedSecret "use-a-long-random-string-here"
```

For hot standby, replace the load balance parameter with `-ServerRole Active -ReservePercent 5`. In the console the same wizard is under the server node » IPv4 » right-click » Configure Failover, where you select scopes, the partner, the mode and the shared secret, which enables message authentication between the servers. Existing leases, reservations, options and policies are copied to the partner during creation. A single relationship can cover every scope on the server; create separate relationships only when different scopes need different modes.

## Keep scopes in sync afterwards

Failover replicates leases automatically but not configuration. After adding a reservation, changing an option or adjusting the range, push the change to the partner:

```
Invoke-DhcpServerv4FailoverReplication -ComputerName dhcp01 -Name "HQ-Failover" -Force
Get-DhcpServerv4Failover -ComputerName dhcp01 | Select-Object Name, Mode, State, PartnerServer
Get-DhcpServerv4Failover -ComputerName dhcp02 | Select-Object Name, Mode, State, PartnerServer
```

Both servers should report State as Normal. “CommunicationInterrupted” means the partner is unreachable on TCP 647; “PartnerDown” means the interval elapsed and one server has taken over the full pool. A server that comes back after an outage returns to Normal automatically, but if you rebuilt it from scratch, remove and recreate the relationship. Back up the configuration on both servers with `Export-DhcpServer -File C:\Backup\dhcp.xml -Leases` on a schedule, because the built-in hourly backup is not off-box. If a DHCP server’s own address changes, recreate the failover relationship afterwards; the steps in [change a domain controller’s IP address](/guides/change-domain-controller-ip-address/) cover that sequence.

## Verify

Stop the DHCP service on the primary and renew a client lease:

```
Stop-Service DHCPServer -ComputerName dhcp01
ipconfig /release
ipconfig /renew
ipconfig /all | findstr "DHCP Server"
```

The client should obtain a lease from the partner’s address within seconds in load balance mode, or after the state switchover interval in hot standby mode. Start the service again and confirm the state returns to Normal on both partners, then check Applications and Services Logs » Microsoft » Windows » DHCP-Server » Operational for the failover events (Event ID 20291 to 20299) that describe state transitions. A common pitfall is a shared secret typed differently on each server when created through the console on separate occasions; the relationship then shows as configured but never leaves CommunicationInterrupted, and the fix is to delete and recreate it.

## Windows DHCP failover at a glance

**Official documentation:** [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Raise the AD forest and domain functional level safely](https://srvscripts.com/guides/raise-ad-functional-level/) · [Deploy printers with Group Policy Preferences](https://srvscripts.com/guides/deploy-printers-group-policy/) · [Block USB storage devices with Group Policy and Intune](https://srvscripts.com/guides/block-usb-storage-group-policy-intune/).

## Frequently asked questions

### Does DHCP failover also replicate reservations and scope options?

Reservations, options, policies and exclusions are copied when the relationship is created and each time you run a replication, but they are not synchronised automatically after a change, so run `Invoke-DhcpServerv4FailoverReplication` whenever you edit a scope.

### How long does it take for the partner to take over when the primary fails?

In load balance mode clients on the failed server’s half of the hash are answered by the partner after a short delay of a few seconds, and after the state switchover interval (10 minutes by default) plus the MCLT the surviving server takes over the entire address pool.

### Can I undo DHCP failover and go back to a single server?

Yes; run `Remove-DhcpServerv4Failover -Name "HQ-Failover"` on either server, which removes the relationship and deletes the scopes from the partner while leaving them intact on the server where you run the command.
