资源描述
单击此处编辑母版标题样式,单击此处编辑母版文本样式,第二级,第三级,第四级,第五级,*,*,中国农业银行,中国农业银行,中国农业银行,单击此处编辑母版标题样式,单击此处编辑母版文本样式,第二级,第三级,第四级,第五级,利用,DHCP,自动指派,IP,地址,本章要点,主机,IP,地址的设置,DHCP,的运行原理,DHCP,服务器配置,DHCP,中继代理程序,主机,IP,地址的设置,手工,TCP/IP,配置,自动,TCP/IP,配置,在每个客户端手工输入,IP,地址,可能会输入错误的或无效的,IP,地址,错误的,IP,地址可能导致网络问题,对于这类问题,很难跟踪,.,管理一个频繁移动的网络时会增加管理开销,IP,地址自动分配给每个客户端,确保每个客户端总是得到正确得配置信息,消除了网络问题的一个常见的问题来源,客户机自动反映网络变化、物理变化,无需人工干预,DHCP,的运行原理,Non-DHCP Client,DHCP Client,DHCP Client,DHCP Server,DHCP Database,IP Address1,IP Address2,IP Address3,.,.,.,IP Address,N,IP Address2,IP Address1,DHCP,租约的生成过程(,1,),1,请求,IP,租约,3,选择,IP,租约,2,提供,IP,租约,4,确定,IP,租约,DHCP,的生成过程(,2,),DHCP,客户端广播一个,DHCPDISCOVER,数据包,1,DHCP,服务器广播一个,DHCPOFFER,数据包,2,DHCP,客户端广播一个,DHCPREQUEST,数据包,3,DHCP,服务器,1,广播一个,DHCPACK,数据包,4,DHCP,客户端,DHCP,服务器,1,DHCP,服务器,2,DHCP,的生成过程(,3,),DHCP,客户机发送完,DHCPDISCOVER,消息后,如果未能接受到,DHCPOFFER,它就会重试,4,次,(,相隔,2,4,8,16s,加上一个,0,到,1000ms,之间的随机数,),如果,DHCP,客户机经过努力仍未获得任何有效的,IP,地址,将使用备用配置。,每隔分钟,该客户机都继续尝试寻找,DHCP,服务器,如果有某个,DHCP,服务器成为可用,客户机将接受到合法的,IP,地址。,使用抓包工具查看,DHCP,租约生成过程,Demo,DHCP,租约的更新过程(,1,),DHCPREQUEST,源,IP,地址,= 192.168.0.77,目标,IP,地址,= 192.168.0.108,请求的,IP,地址,= 192.168.0.77,硬件地址,= 08004.,DHCPACK,源,IP,地址,= 192.168.0.108,目标,IP,地址,= 192.168.0.77,提供的,IP,地址,= 192.168.0.77,客户端的硬件地址,= 08004.,子网掩码,= 255.255.255.0,租借期限,= 8 days,服务器标示符,= 192.168.0.108,DHCP,选项:路由器,= 192.168.0.1,DHCP Client,DHCP Server,DHCP,租约的更新过程(,2,),DHCP Client,DHCP Server1,DHCP,客户端发送一个,DHCPREQUEST,数据包,1,DHCP,服务器,1,发送一个,DHCPACK,数据包,2,租约时间过去,50%,时,租约时间过去,87.5%,时,租约时间到达,100%,如果客户端在租约时间过去,50%,时更新失败,,DHCP,客户端继续使用,直到租约时间到达,87.5%,时再次启动更新,如果客户端更新租约失败,在时间到达,87.5%,时,,DHCP,客户端利用,DHCPDISCOVER,广播包向任何服务器更新租约。,DHCP Server2,DHCP,租约的更新过程(,3,),DHCP,客户机在它们的租约期限已过去,50%,,自动尝试更新租约。如果,DHCP,服务器可用,那么将更新。如果,DHCP,服务器不可用,客户机将继续使用它的当前配置。,当租约期限过去,87.5%,,发出广播再次更新租约。此时,,DHCP,客户机接受任何,DHCP,服务器发出的租约。,如果租约已经到期,(,100%,),,客户机必须立即停止使用当前的,IP,地址。然后,DHCP,客户机开始新的,DHCP,租约过程,尝试租用新的,IP,地址。,DHCP,租约的更新过程(,4,),人工更新租约,如果你需要立即更新,DHCP,配置信息,你可以使用人工方式更新,IP,租约。,ipconfig /release,ipconfig /renew,配置客户端,DHCP,服务器的授权,为了防止用户随意安装,DHCP,服务器,必须经过授权才可以为,DHCP,客户端提供服务,(,采用授权机制,域用户没经授权有可能也能提供服务,),只有在,AD,环境中,,DHCP,服务器才可以被授权;在,AD,环境中,,DHCP,服务器必须被授权。,只有,Enterprise Admins,组的成员才有权限授权。,独立服务器(未授权的)首先查看子网内有没有被授权的服务器,只有当确认子网内没有被授权的服务器时,才可以出租,IP,地址给,DHCP,客户端。,为,DHCP,服务授权,Domain,Controller,Active,Directory,DHCP Client,DHCP Server1 checks with the domain controller to obtain a list of authorized DHCP servers,Unauthorized,Does not service DHCP requests,Authorized,Services DHCP requests,DHCP Server1,DHCP Server2,If DHCP Server1 finds its IP address on the list, the service starts and supports DHCP clients,DHCP Server2 checks with the,domain controller to obtain a list of,authorized DHCP servers,If DHCP Server2 does not find its IP address on the list, the service does not start and support DHCP clients,DHCP client receives IP address,from authorized DHCP Server1,DHCP client receives IP address,from authorized DHCP Server1,Domain,Controller,Active,Directory,DHCP Client,Unauthorized,Does not service DHCP requests,Authorized,Services DHCP requests,DHCP Server1,DHCP Server2,DHCP authorization,is the process of registering the DHCP Server service in the Active Directory domain to support DHCP clients,DHCP,服务器的安装,创建作用域,管理作用域,配置,DHCP,服务器,添加作用域,Demo,为客户端保留,IP,地址,配置,DHCP,选项(,1,),保留客户端级别,服务器级别,作用域级别,类级别,DHCP,选项的级别,配置,DHCP,选项(,2,),配置,DHCP,选项(,3,),配置,DHCP,类别选项,DHCP,中继代理,当,DHCP,客户机与,DHCP,服务器不在同一网段时的解决方案:,每个网段安装一台,DHCP,服务器,使用符合,RFC1542,规范的路由器,使用中继代理,DHCP,中继代理是如何工作的?,Router,Non-RFC 1542 Compliant,Client1,DHCP Relay Agent,Client2,DHCP Server,Client3,Client1 broadcasts a DHCPDISCOVER packet,1,Relay agent forwards the DHCPDISCOVER message to the DHCP server,2,Server sends a DHCPOFFER message to the DHCP relay agent,3,Relay agent broadcasts the DHCPOFFER packet,4,Client1 broadcasts a DHCPREQUEST packet,5,Relay agent forwards the DHCPREQUEST message to the DHCP server,6,Server sends a DHCPACK message to the DHCP relay agent,7,Relay agent broadcasts the DHCPACK packet,8,如何使用,DHCP,中继代理跃点计数?,The,hop count threshold,is the number of routers that the packet can be transmitted through before being discarded,DHCP Relay Agent 2,DHCP Server,Hop Count = 2,DHCP Relay Agent 1,如何使用,DHCP,中继代理的启动阀值?,DHCP Server 2,DHCP Server 3,DHCP Relay Agent,Boot Threshold,= 10 seconds,Local DHCP Server,DHCP Server 2,DHCP Server 3,DHCP Relay Agent,Boot Threshold,= 10 seconds,Local DHCP Server,The,boot threshold,is the length of time in seconds that the DHCP Relay Agent will wait for a local DHCP server to respond to client requests before forwarding the request,配置,DHCP,中继代理,Demo,
展开阅读全文