免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1730 | 回复: 0
打印 上一主题 下一主题

Linux系统上DHCP服务器的配置 . [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2011-11-23 16:03 |只看该作者 |倒序浏览
Linux系统上DHCP服务器的配置 .








一、DHCP的工作流程

(1) DHCP服务器发现阶段。DHCP客户机向广播地址255.255.255.255发送DHCPDiscover消息。

(2) DHCP服务器响应阶段。DHCP服务器从尚未出租的IP地址池中选择一个分配给DHCP客户机,向DHCP客户机发送一个包含出租的IP地址和其他设置的DHCPoffer提供信息。

(3) IP地址选择阶段。DHCP客户机选择某个DHCP服务器提供的IP地址,以广播方式回答一个DHCPrequest请求信息.

(4) IP地址确认阶段。服务器回应包含它所提供的IP地址和其他设置的DHCPack确认信息。然后客户机将其与TCP/IP协议与网卡绑定。

(5) 客户机重新登录。再次发送前次分配的IP地址的DHCPRequest请求请求信息,DHCP服务器检查是否可以继续让客户机使用,然后发回DHCPack确认信息或者DHCPnck否认信息。如果IP已不能用,客户机需从(1)开始重新申请。

(6) 更新租约。IP地址租借期限到了,如果DHCP客户机要延长其租约,必须更新。DHCP客户机启动时和IP租约期限过一半时,都会向服务器发送更新期IP租约的信息。




二、DHCP服务器配置文件

路径在/etc/dhcp/dhcpd.conf。下面是一个配置文件的例子:
  1. view plaincopy to clipboardprint?
  2. 01.<span style="font-size:16px;"># dhcpd.conf  
  3. 02.#  
  4. 03.# Sample configuration file for ISC dhcpd  
  5. 04.#  
  6. 05.  
  7. 06.# option definitions common to all supported networks...  
  8. 07.option domain-name "example.org";  
  9. 08.option domain-name-servers ns1.example.org, ns2.example.org;  
  10. 09.  
  11. 10.default-lease-time 600;  
  12. 11.max-lease-time 7200;  
  13. 12.  
  14. 13.# Use this to enble / disable dynamic dns updates globally.  
  15. 14.#ddns-update-style none;  
  16. 15.  
  17. 16.# If this DHCP server is the official DHCP server for the local  
  18. 17.# network, the authoritative directive should be uncommented.  
  19. 18.#authoritative;  
  20. 19.  
  21. 20.# Use this to send dhcp log messages to a different log file (you also  
  22. 21.# have to hack syslog.conf to complete the redirection).  
  23. 22.log-facility local7;  
  24. 23.  
  25. 24.# No service will be given on this subnet, but declaring it helps the   
  26. 25.# DHCP server to understand the network topology.  
  27. 26.  
  28. 27.subnet 10.152.187.0 netmask 255.255.255.0 {  
  29. 28.}  
  30. 29.  
  31. 30.# This is a very basic subnet declaration.  
  32. 31.  
  33. 32.subnet 10.254.239.0 netmask 255.255.255.224 {  
  34. 33.  range 10.254.239.10 10.254.239.20;  
  35. 34.  option routers rtr-239-0-1.example.org, rtr-239-0-2.example.org;  
  36. 35.}  
  37. 36.  
  38. 37.# This declaration allows BOOTP clients to get dynamic addresses,  
  39. 38.# which we don't really recommend.  
  40. 39.  
  41. 40.subnet 10.254.239.32 netmask 255.255.255.224 {  
  42. 41.  range dynamic-bootp 10.254.239.40 10.254.239.60;  
  43. 42.  option broadcast-address 10.254.239.31;  
  44. 43.  option routers rtr-239-32-1.example.org;  
  45. 44.}  
  46. 45.  
  47. 46.# A slightly different configuration for an internal subnet.  
  48. 47.subnet 10.5.5.0 netmask 255.255.255.224 {  
  49. 48.  range 10.5.5.26 10.5.5.30;  
  50. 49.  option domain-name-servers ns1.internal.example.org;  
  51. 50.  option domain-name "internal.example.org";  
  52. 51.  option routers 10.5.5.1;  
  53. 52.  option broadcast-address 10.5.5.31;  
  54. 53.  default-lease-time 600;  
  55. 54.  max-lease-time 7200;  
  56. 55.}  
  57. 56.  
  58. 57.# Hosts which require special configuration options can be listed in  
  59. 58.# host statements.   If no address is specified, the address will be  
  60. 59.# allocated dynamically (if possible), but the host-specific information  
  61. 60.# will still come from the host declaration.  
  62. 61.  
  63. 62.host passacaglia {  
  64. 63.  hardware ethernet 0:0:c0:5d:bd:95;  
  65. 64.  filename "vmunix.passacaglia";  
  66. 65.  server-name "toccata.fugue.com";  
  67. 66.}  
  68. 67.  
  69. 68.# Fixed IP addresses can also be specified for hosts.   These addresses  
  70. 69.# should not also be listed as being available for dynamic assignment.  
  71. 70.# Hosts for which fixed IP addresses have been specified can boot using  
  72. 71.# BOOTP or DHCP.   Hosts for which no fixed address is specified can only  
  73. 72.# be booted with DHCP, unless there is an address range on the subnet  
  74. 73.# to which a BOOTP client is connected which has the dynamic-bootp flag  
  75. 74.# set.  
  76. 75.host fantasia {  
  77. 76.  hardware ethernet 08:00:07:26:c0:a5;  
  78. 77.  fixed-address fantasia.fugue.com;  
  79. 78.}  
  80. 79.  
  81. 80.# You can declare a class of clients and then do address allocation  
  82. 81.# based on that.   The example below shows a case where all clients  
  83. 82.# in a certain class get addresses on the 10.17.224/24 subnet, and all  
  84. 83.# other clients get addresses on the 10.0.29/24 subnet.  
  85. 84.  
  86. 85.class "foo" {  
  87. 86.  match if substring (option vendor-class-identifier, 0, 4) = "SUNW";  
  88. 87.}  
  89. 88.  
  90. 89.shared-network 224-29 {  
  91. 90.  subnet 10.17.224.0 netmask 255.255.255.0 {  
  92. 91.    option routers rtr-224.example.org;  
  93. 92.  }  
  94. 93.  subnet 10.0.29.0 netmask 255.255.255.0 {  
  95. 94.    option routers rtr-29.example.org;  
  96. 95.  }  
  97. 96.  pool {  
  98. 97.    allow members of "foo";  
  99. 98.    range 10.17.224.10 10.17.224.250;  
  100. 99.  }  
  101. 100.  pool {  
  102. 101.    deny members of "foo";  
  103. 102.    range 10.0.29.10 10.0.29.230;  
  104. 103.  }  
  105. 104.}  
  106. 105.</span>  
  107. <span style="font-size:16px;"># dhcpd.conf
  108. #
  109. # Sample configuration file for ISC dhcpd
  110. #

  111. # option definitions common to all supported networks...
  112. option domain-name "example.org";
  113. option domain-name-servers ns1.example.org, ns2.example.org;

  114. default-lease-time 600;
  115. max-lease-time 7200;

  116. # Use this to enble / disable dynamic dns updates globally.
  117. #ddns-update-style none;

  118. # If this DHCP server is the official DHCP server for the local
  119. # network, the authoritative directive should be uncommented.
  120. #authoritative;

  121. # Use this to send dhcp log messages to a different log file (you also
  122. # have to hack syslog.conf to complete the redirection).
  123. log-facility local7;

  124. # No service will be given on this subnet, but declaring it helps the
  125. # DHCP server to understand the network topology.

  126. subnet 10.152.187.0 netmask 255.255.255.0 {
  127. }

  128. # This is a very basic subnet declaration.

  129. subnet 10.254.239.0 netmask 255.255.255.224 {
  130.   range 10.254.239.10 10.254.239.20;
  131.   option routers rtr-239-0-1.example.org, rtr-239-0-2.example.org;
  132. }

  133. # This declaration allows BOOTP clients to get dynamic addresses,
  134. # which we don't really recommend.

  135. subnet 10.254.239.32 netmask 255.255.255.224 {
  136.   range dynamic-bootp 10.254.239.40 10.254.239.60;
  137.   option broadcast-address 10.254.239.31;
  138.   option routers rtr-239-32-1.example.org;
  139. }

  140. # A slightly different configuration for an internal subnet.
  141. subnet 10.5.5.0 netmask 255.255.255.224 {
  142.   range 10.5.5.26 10.5.5.30;
  143.   option domain-name-servers ns1.internal.example.org;
  144.   option domain-name "internal.example.org";
  145.   option routers 10.5.5.1;
  146.   option broadcast-address 10.5.5.31;
  147.   default-lease-time 600;
  148.   max-lease-time 7200;
  149. }

  150. # Hosts which require special configuration options can be listed in
  151. # host statements.   If no address is specified, the address will be
  152. # allocated dynamically (if possible), but the host-specific information
  153. # will still come from the host declaration.

  154. host passacaglia {
  155.   hardware ethernet 0:0:c0:5d:bd:95;
  156.   filename "vmunix.passacaglia";
  157.   server-name "toccata.fugue.com";
  158. }

  159. # Fixed IP addresses can also be specified for hosts.   These addresses
  160. # should not also be listed as being available for dynamic assignment.
  161. # Hosts for which fixed IP addresses have been specified can boot using
  162. # BOOTP or DHCP.   Hosts for which no fixed address is specified can only
  163. # be booted with DHCP, unless there is an address range on the subnet
  164. # to which a BOOTP client is connected which has the dynamic-bootp flag
  165. # set.
  166. host fantasia {
  167.   hardware ethernet 08:00:07:26:c0:a5;
  168.   fixed-address fantasia.fugue.com;
  169. }

  170. # You can declare a class of clients and then do address allocation
  171. # based on that.   The example below shows a case where all clients
  172. # in a certain class get addresses on the 10.17.224/24 subnet, and all
  173. # other clients get addresses on the 10.0.29/24 subnet.

  174. class "foo" {
  175.   match if substring (option vendor-class-identifier, 0, 4) = "SUNW";
  176. }

  177. shared-network 224-29 {
  178.   subnet 10.17.224.0 netmask 255.255.255.0 {
  179.     option routers rtr-224.example.org;
  180.   }
  181.   subnet 10.0.29.0 netmask 255.255.255.0 {
  182.     option routers rtr-29.example.org;
  183.   }
  184.   pool {
  185.     allow members of "foo";
  186.     range 10.17.224.10 10.17.224.250;
  187.   }
  188.   pool {
  189.     deny members of "foo";
  190.     range 10.0.29.10 10.0.29.230;
  191.   }
  192. }
  193. </span>
复制代码
DHCP配置文件通常包括3部分:declarations, parameters, options。
declarations:描述网络的布局;描述客户;提供客户的地址。

parameters:表明如何执行任务,是否要执行任务,或将哪些网络配置选项发送给客户。

option:配置DHCP可选参数。

常用声明:

shared-network 告知DHCP服务器是否为一些子网络分享相同网络

subnet 描述一个IP是否属于子网

range 提供动态分配IP地址的起始和结束范围

host 为特定的主机提供网络参数

group 为一组参数提供声明

常用参数:

ddns-update-style 配置DHCP-DNS互动更新模式

default-lease-time 指定默认租赁时间的长度,单位为秒

max-lease-time 指定最大租赁时间长度,单位为秒

hardware 指定网卡接口类型和MAC地址

server-name 告知DHCP客户服务器名称

fixed-address 为客户端指定一个固定的IP地址

常用选项:

domain-name 为客户端指定域名

domain-name-servers为客户端指明DNS服务器IP地址

host-name 为客户端指明主机名称

routers 为客户端指明默认网关

broadcast-address 为客户端设定广播地址

subnet-mask 为客户端设定子网掩码

ntp-server 为客户端设定格林威治时间的偏移时间,单位为秒




下面是一个DHCPv6的配置文件的例子:
  1. view plaincopy to clipboardprint?
  2. 01.# Server configuration file example for DHCPv6  
  3. 02.# From the file used for TAHI tests.  
  4. 03.  
  5. 04.# IPv6 address valid lifetime  
  6. 05.#  (at the end the address is no longer usable by the client)  
  7. 06.#  (set to 30 days, the usual IPv6 default)  
  8. 07.default-lease-time 2592000;  
  9. 08.  
  10. 09.# IPv6 address preferred lifetime  
  11. 10.#  (at the end the address is deprecated, i.e., the client should use  
  12. 11.#   other addresses for new connections)  
  13. 12.#  (set to 7 days, the  usual IPv6 default)  
  14. 13.preferred-lifetime 604800;  
  15. 14.  
  16. 15.# T1, the delay before Renew  
  17. 16.#  (default is 1/2 preferred lifetime)  
  18. 17.#  (set to 1 hour)  
  19. 18.option dhcp-renewal-time 3600;  
  20. 19.  
  21. 20.# T2, the delay before Rebind (if Renews failed)  
  22. 21.#  (default is 3/4 preferred lifetime)  
  23. 22.#  (set to 2 hours)  
  24. 23.option dhcp-rebinding-time 7200;  
  25. 24.  
  26. 25.# Enable RFC 5007 support (same than for DHCPv4)  
  27. 26.allow leasequery;  
  28. 27.  
  29. 28.# Global definitions for name server address(es) and domain search list  
  30. 29.option dhcp6.name-servers 3ffe:501:ffff:100:200:ff:fe00:3f3e;  
  31. 30.option dhcp6.domain-search "test.example.com","example.com";  
  32. 31.  
  33. 32.# Set preference to 255 (maximum) in order to avoid waiting for  
  34. 33.# additional servers when there is only one  
  35. 34.##option dhcp6.preference 255;  
  36. 35.  
  37. 36.# Server side command to enable rapid-commit (2 packet exchange)  
  38. 37.##option dhcp6.rapid-commit;  
  39. 38.  
  40. 39.# The delay before information-request refresh  
  41. 40.#  (minimum is 10 minutes, maximum one day, default is to not refresh)  
  42. 41.#  (set to 6 hours)  
  43. 42.option dhcp6.info-refresh-time 21600;  
  44. 43.  
  45. 44.# The path of the lease file  
  46. 45.dhcpv6-lease-file-name "/usr/local/var/db/dhcpd6.leases";  
  47. 46.  
  48. 47.# Static definition (must be global)  
  49. 48.host myclient {  
  50. 49.    # The entry is looked up by this  
  51. 50.    host-identifier option  
  52. 51.        dhcp6.client-id 00:01:00:01:00:04:93:e0:00:00:00:00:a2:a2;  
  53. 52.  
  54. 53.    # A fixed address  
  55. 54.    fixed-address6 3ffe:501:ffff:100::1234;  
  56. 55.  
  57. 56.    # A fixed prefix  
  58. 57.    fixed-prefix6 3ffe:501:ffff:101::/64;  
  59. 58.  
  60. 59.    # Override of the global definitions,  
  61. 60.    # works only when a resource (address or prefix) is assigned  
  62. 61.    option dhcp6.name-servers 3ffe:501:ffff:100:200:ff:fe00:4f4e;  
  63. 62.  
  64. 63.    # For debug (to see when the entry statements are executed)  
  65. 64.    #  (log "sol" when a matching Solicitation is received)  
  66. 65.    ##if packet(0,1) = 1 { log(debug,"sol"); }  
  67. 66.}  
  68. 67.  
  69. 68.# The subnet where the server is attached  
  70. 69.#  (i.e., the server has an address in this subnet)  
  71. 70.subnet6 3ffe:501:ffff:100::/64 {  
  72. 71.    # Two addresses available to clients  
  73. 72.    #  (the third client should get NoAddrsAvail)  
  74. 73.    range6 3ffe:501:ffff:100::10 3ffe:501:ffff:100::11;  
  75. 74.  
  76. 75.    # Use the whole /64 prefix for temporary addresses  
  77. 76.    #  (i.e., direct application of RFC 4941)  
  78. 77.    range6 3ffe:501:ffff:100:: temporary;  
  79. 78.  
  80. 79.    # Some /64 prefixes available for Prefix Delegation (RFC 3633)  
  81. 80.    prefix6 3ffe:501:ffff:100:: 3ffe:501:ffff:111:: /64;  
  82. 81.}  
  83. 82.  
  84. 83.# A second subnet behind a relay agent  
  85. 84.subnet6 3ffe:501:ffff:101::/64 {  
  86. 85.    range6 3ffe:501:ffff:101::10 3ffe:501:ffff:101::11;  
  87. 86.  
  88. 87.    # Override of the global definitions,  
  89. 88.    # works only when a resource (address or prefix) is assigned  
  90. 89.    option dhcp6.name-servers 3ffe:501:ffff:101:200:ff:fe00:3f3e;  
  91. 90.  
  92. 91.}  
  93. 92.  
  94. 93.# A third subnet behind a relay agent chain  
  95. 94.subnet6 3ffe:501:ffff:102::/64 {  
  96. 95.    range6 3ffe:501:ffff:102::10 3ffe:501:ffff:102::11;  
  97. 96.}  
复制代码
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP