å°ãé²ãã§ãDHCPãªã¬ãŒãã©ã®ããã«æ©èœããããæãåºããŸãã ãããŒããã£ã¹ãèŠæ±ïŒæ§æãããŠããVLANïŒãã€ã³ã¿ãŒã»ããããL3ã§ã©ããããŠãæå®ãããDHCPãµãŒããŒãžã®ãŠããã£ã¹ãã«éä¿¡ããŸãã ãŸããoption82ãäœãããããæãåºãããšã¯äžå¿ èŠã§ã¯ãããŸããã DHCPãã±ããã«2ã€ã®è¿œå ãã©ã¡ãŒã¿ãŒãè¿œå ããŸãã
DHCP-Relay-Circuit-Id-èŠæ±ã®éä¿¡å ã®ããŒãçªå·ã
DHCP-Relay-Remote-Id-ïŒããã©ã«ãã§ïŒèŠæ±ã®éä¿¡å ã®ã¹ã€ããã®ãã¯ãã¢ãã¬ã¹ã
ãã®ãªãã·ã§ã³ãããã±ãŒãžã«å®è£ ããæ¹æ³ã«ã€ããŠã説æããããšæããŸãDlinkæ©åšã«ã¯2ã€ã®æ¹æ³ããããŸãã
dhcp_relay-Option82ãè¿œå ããäžèšã®ããã«ããããL3ã§ã©ããããæå®ãããDHCPãµãŒããŒã«ãŠããã£ã¹ããéä¿¡ããŸãã
dhcp_local_relayïŒDHCPã¹ããŒãã³ã°ïŒ-Option82ã®ã¿ãè¿œå ãããããŒããã£ã¹ããã±ãããããã«è»¢éããŸãã
ãããã¯ããå°ãå€ããŸãã å®éãdhlink_local_relayã³ã³ã¹ãã©ã¯ãã¯DlinkããŒããŠã§ã¢ã§ã®ã¿èŠã€ãããŸããã ä»ã®ã¡ãŒã«ãŒããã®ãããªçŽ æŽããããªãã·ã§ã³ãå®è£ ããªãã£ãã®ã¯ãªãã ãããïŒ ããã¯çµå±ãå®è£ ãããŠãããé·ãéã§ãã DHCPã¹ããŒãã³ã°ãšåŒã°ããŸãã
ãããã誰ãã質åãããã§ãããïŒããªããããŒããã£ã¹ããã©ãã£ãã¯ãåãé€ãã¹ããªã®ãïŒã å®éãå®éã«ã¯ãããšãã°é·éšã®çµæãšããŠã¹ã€ããã«é害ãçºçãããšã«ãŒããçºçãããããŒããã£ã¹ãã¹ããŒã ã«ã€ãªãããããªçŸè±¡ã«é »ç¹ã«ééããŸããã ãã¡ããããæ³åã®ãšãããIPv4ã§1ã€ã®ãããŒããã£ã¹ããã©ãã£ãã¯ãåãé€ãããšã¯ã§ããŸãããããã¯ARPãã©ãã£ãã¯ã§ãã 圌ã¯ãMAC-IPããŒãã«ã®äœæãæ åœããŠããŸãã ãã¡ããããããç¡å¹ã«ããŠãæåã§ããŒãã«ã«èšå ¥ããããšãã§ããŸãã ããããç§ã¯ããã«ãã£ãŠåŒãèµ·ããããäžäŸ¿ãéçARPããŒãã«ã®é åããã¹ãŠç¡å¹ã«ããããšãæããŠããŸãã
ãã¹ãŠã®èšäºã¯ãDHCPã¯ã©ã€ã¢ã³ããšDHCPãµãŒããŒãç°ãªããµããããäžã«ååšããå¯èœæ§ãããããšã瀺ããŠããŸã-ããã¯æ£ãããããŸããã 以äžã«å³ã瀺ããŸãã
次ã«ãæ§æã®äŸã瀺ããŸãã
DLINK DES-3200
config vlan default delete 1-10 ïŒããã©ã«ãVLANãããã¹ãŠã®ããŒããåé€ VLAN VLAN7ã¿ã°7ãäœæããŸã ïŒDHCPãµãŒããŒãé 眮ãããŠããVLANãäœæããŸã config vlan VLAN7 add 9-10ã®ã¿ã°ä»ã ïŒã¿ã°ä»ãããŒã9ããã³10ãããã«è¿œå ããŸãïŒãããã€ããŒã®æ¹åãèŠãŠãã ããïŒ VLAN VLAN10ã¿ã°10ãäœæããŸã ïŒãµãã¹ã¯ã©ã€ããŒãããVLAN 10ãäœæããŸã config vlan VLAN10 add tags 9 -10 ïŒã¿ã°ä»ãããŒã9ããã³10ãè¿œå ããŸã config vlan VLAN10 add untagged 1-8 ïŒããã«ã¿ã°ãªãããŒã1-8ãè¿œå ïŒãµãã¹ã¯ã©ã€ããŒããŒãïŒ config ipif System ipaddress 10.90.90.90/8 ïŒã¹ã€ããã®IPã¢ãã¬ã¹ãèšå®ããŸã config ipif System vlan VLAN7 ïŒVLAN7ã«ãã³ã°ã¢ããããŸã dhcp_relayãæå¹ã«ãã ïŒãªãã·ã§ã³ãæå¹å config dhcp_relay option_82ããªã·ãŒã®çœ®ãæã ïŒããã±ãŒãžå ã®æ å ±ãæ¢ã«ååšããå Žåã¯ã眮ãæããŸã config dhcp_relay option_82 remote_id default ïŒããã©ã«ãèšå®ãä¿åããã ãïŒãããŒïŒ config dhcp_relay option_82 circuit_id default ïŒããã©ã«ãèšå®ïŒããŒãçªå·ïŒãä¿åããã ã config dhcp_relay add vlanid 10 10.90.90.92 ïŒVLAN10ã®ãã¹ãŠã®ãã©ãã£ãã¯ã¯ã€ã³ã¿ãŒã»ãããããã¢ãã¬ã¹10.90.90.92ã®DHCPãµãŒããŒã«éä¿¡ãããŸã iprouteã®ããã©ã«ã10.90.90.92ãäœæããŸã ïŒããã©ã«ãã«ãŒããäœæããŸãããã®äŸã§ã¯ãäœãå¿ èŠãã¯ããããŸãããã颚氎
config isc-dhcp-serverïŒisc-dhcpd-4.2.4ïŒon
Linux big-A75F-M2 3.13.0-24-genericïŒ47-Ubuntu SMP Fri May 2 23:30:00 UTC 2014 x86_64 x86_64 x86_64 GNU / LinuxïŒ
$ sudo apt-get install vlan-tools isc-dhcp-server
$ sudo vconfig add eth0 7
$ sudo ifconfig eth0.7 10.90.90.92/8
ïŒVLAN7ãäœæããDHCPãµãŒããŒãæã€ã¢ãã¬ã¹10.90.90.92/8ãå²ãåœãŠãŸã
ããŒã«ã«ã¢ãã¬ã¹10.90.90.92; ïŒçè«çã«ã¯ãããã¯çèŽçšã®ãœã±ããã®äœæå Žæã瀺ãå¿ èŠããããŸãããå®éã«ã¯ãã®ãªãã·ã§ã³ã¯åæ©çãªãã®ã§ããããšã«æ°ä»ããŸãããç§ã¯ãããå€æŽããããšããŠäœãå€ãã£ãŠããªãããšãã³ã¡ã³ãããŸããããFeng Shuiã«ãããš:) äžè¬ã«ããµãŒããŒã¯ãã¹ãŠã®æ瀺ããåãåºããããµããããã»ã¯ã·ã§ã³ã§èª¬æãããŠãããµããããã«åé¡ãããIPã€ã³ã¿ãŒãã§ãŒã¹ã§èªåçã«ãã³ã°ã¢ããããŸãã ååšããå Žåagent.circuit-id { logïŒinfoãconcatïŒ "Lease for"ãbinary-to-asciiïŒ10ã8ã "ã"ãleased-addressïŒãã ãrawãªãã·ã§ã³82æ å ±ã¯CIDïŒãããã€ããªããASCIIïŒ10ã8ããããããªãã·ã§ã³agent.circuit-idïŒããAIDïŒãã binary-to-asciiïŒ16ã8ã "ã"ããªãã·ã§ã³agent.remote-idïŒïŒïŒ; } ïŒããã¯ããªãã·ã§ã³82ãæ€åºãããå Žåããã°ãã¡ã€ã«ã«ãšã³ããªãåºåããã ãã§ã ãµãããã10.0.0.0ããããã¹ã¯255.0.0.0 { ããŒã«{ ç¯å²10.0.0.155; } } ïŒãµãããããšããŒã«ãèšå®ãã
ãã¡ãããããã¯ã¹ã¿ã³ãã¢ãã³ã®èšå®ã«ãããŸããããç§ãã¡ã«ãšã£ãŠæãéèŠãªããšã¯ããã®ä»çµã¿ãç解ããããšã§ãã ããã§ããç§ã¯option82ãšdhcp_local_relayïŒdhcpã¹ããŒãã³ã°ïŒã³ã³ã¹ãã©ã¯ããåãã課éã·ã¹ãã ãããããµãŒããŒãšããŠpostgresããŒã¿ããŒã¹ããéžæãããperlã®IPã¢ãã¬ã¹ã§freeradius2ã䜿çšããŠãããšèšããŸãã ããããããã¯ãã§ã«ãã®èšäºã®ç¯å²å€ã§ãã
ãµãŒããŒã®ãããã·ã³ã§ã次ãå®è¡ããŸãã
$ sudo tcpdump -i eth0.7 -e -n -t
ãããŠã次ã®ãããªãã®ãèŠãå ŽåïŒ
c0ïŒa0ïŒbbïŒ48ïŒe5ïŒb0> 00ïŒ15ïŒ17ïŒdbïŒe3ïŒe0 ãethertype IPv4ïŒ0x0800ïŒãé·ã345ïŒ 10.90.90.90.68> 10.90.90.92.67 ïŒBOOTP / DHCPããªã¯ãšã¹ã48ïŒ5bïŒ39ïŒ43ïŒ78ããïŒe5ãé·ã303
ã€ãŸãããããŒããã£ã¹ãã¯ãããŸãããã€ãŸãããã¹ãŠãé 調ã«é²ãã§ãããDHCPãµãŒããŒãèµ·åãããšãã§ãã
åããŠã次ã®è¡ãå ¥åããŠéå§ããããšããå§ãããŸãã
$ sudo dhcpd
ãã®åŸããšã©ãŒãããå Žåã¯ããã«ãã¹ãŠè¡šç€ºããããã©ãŒã ã®èšé²ãå¿ èŠã§ãã
LPF / eth0.7 / 00ã§ã®ãªãã¹ã³ïŒ15ïŒ17ïŒdbïŒe3ïŒe0 / 10.0.0.0 / 8
LPF / eth0.7 / 00ã§éä¿¡ïŒ15ïŒ17ïŒdbïŒe3ïŒe0 / 10.0.0.0 / 8
念ã®ãããæ°ç§åŸã«ç¢ºèªã§ããŸãã
$ pgrep dhcpd
ããã»ã¹ã®UIDãè¿ãå¿ èŠããããŸããäœãåºåãããªãå Žåã¯ãæ§æã確èªããŠãã ããã
ãªããã®ãããªãã§ãã¯ãå¿ èŠãªã®ã§ããïŒ ãµãŒããŒãèµ·åããæ°ç§éã¡ã¢ãªã«ãã³ã°ã¢ããããŠã¯ã©ãã·ã¥ããå ŽåãèŠããŠããŸãã ãããŠãç§ã¯ç¡é§ã«IPã¢ãã¬ã¹ãååŸããããšããŸããã
ãã¹ãŠãããŸããã£ãå Žåããã°ã«æ¬¡ã®ãããªãã®ããããŸãã
12æ2æ¥20:36:17 big-A75F-M2 dhcpdïŒ48ïŒ5bïŒ39ïŒ43ïŒ78ãã10.0.0.155ã®DHCPREQUEST 10.90.90.90çµç±ã§e5ïŒbig-1001PXïŒ
12æ2æ¥20:36:17 big-A75F-M2 dhcpdïŒ10.0.0.155ãã48ïŒ5bã®DHCPACKïŒ39ïŒ43ïŒ78ïŒ10.90.90.90çµç±ã®e5ïŒbig-1001PXïŒ
12æ2æ¥20:38:06 big-A75F-M2 dhcpdïŒ10.0.0.155ã®rawãªãã·ã§ã³82æ å ±ã®ãªãŒã¹ã¯CIDïŒ0.4.0.10.0.3 AIDïŒ 0.6.c0.a0.bb.48.e5.b0
ä»ãéåžžã«éèŠãªããšã¯ãã©ãã«ãæžãããŠããŸããããå®éšçã«å°éããŸããã ã¹ã€ããã®IPã¢ãã¬ã¹ã¯ãå å ¥è ã«çºè¡ãããã¢ãã¬ã¹ãšåããµããããäžã«ãªããã°ãªããŸãã ã ä»ã®çµã¿åããã§ã¯ãDlink DES-3200ãã³ãã«ïŒããŒãPROMããŒãžã§ã³ïŒãã«ã4.00.002ãã¡ãŒã ãŠã§ã¢ããŒãžã§ã³ïŒãã«ã4.04.004ããŒããŠã§ã¢ããŒãžã§ã³ïŒC1ïŒââãšisc-dhcp-server 4.2.4ãåäœãããããšã¯ã§ããŸããã§ããã
ãããŠããŸã 倧ããªããŒãã¹ã¯ãããŸããããããŒããã£ã¹ãã§æ»ãªãªãããšã§ãã Dlink DES-3200 C1ã®æ§æïŒ
config safeguard_engine state enable config safeguard_engine䜿çšçã®äžæ90äžé30ç¶æ ã®æå¹å ïŒããã¯ããã»ããµã®éè² è·ä¿è·ã§ã configãã©ãã£ãã¯å¶åŸ¡1-8ãããŒããã£ã¹ãã€ããŒãã«ãã«ããã£ã¹ãã€ããŒãã«ãŠããã£ã¹ãç¡å¹ã¢ã¯ã·ã§ã³ãããããããå€ d 64ã«ãŠã³ãããŠã³5 time_interval 5 ïŒããã«ããã顧客ãçæããè€æ°ã®ãããŒããã£ã¹ãããããªããæããŸã ã«ãŒãæ€åºãæå¹ã«ãã config loopdetect ports 1-8 state enable config loopdetect recover_timer 1200 interval 10ã¢ãŒãããŒãããŒã¹ ïŒãããŠãã«ãŒããæ¢ã«åœ¢æãããŠããå Žåãããã¯ã«ãŒãããä¿åãããŸã
ãã®èšäºã¯ã¯ããŒã³ã§ã¯ãªããä»ã®äººã®èšäºãããªãèªèº«ã®èšèã§æžãçŽãããšãããã®ã§ããããŸããã 以äžã¯ãåæ§ã®åºçç©ãšããããšã®éãã®ãªã¹ãã§ãã ç§ã®èšäºã§ã¯ããããã¯ãŒã¯ããDHCPãµãŒããŒãåãåºãããšããã®ã§ã¯ãªããæ¿èªæ¹æ³ãšããŠãã®èšèšã䜿çšããããšã«çŠç¹ãåœãŠãŸããã
-xgu.ru/wiki/%D0%9E%D0%BF%D1%86%D0%B8%D1%8F_82_DHCP-ããã«ãšã©ãŒãããããããèŠã€ããã®ã«å€ãã®æéãè²»ãããŸããã äžèšã«ã€ããŠæžããŸããïŒã¹ã€ããã®IPã¢ãã¬ã¹ã¯ããµãã¹ã¯ã©ã€ããŒã«äžããããã¢ãã¬ã¹ãšåããµããããäžã«ããå¿ èŠããããŸããä»ã®çµã¿åããã§ã¯ãDlink DES-3200ãã³ãã«ãåäœãããããšã¯ã§ããŸããã§ããïŒããŒãPROMããŒãžã§ã³ïŒãã«ã4.00.002ãã¡ãŒã ãŠã§ã¢ããŒãžã§ã³ïŒãã«ã4.04.004ããŒããŠã§ã¢ããŒãžã§ã³ïŒC1ïŒââããã³isc-dhcp-server 4.2.4ãïŒ ;
habrahabr.ru/post/143846-ããã§dhcpã¯ãããã¯ãŒã¯å€ã«ç§»åãããŸãã
www.dlink.ru/ru/faq/62/228.html-ããã§ãdhcpã¯ãããã¯ãŒã¯å€ã«ç§»åãããŸãã