DHCP Snooping¹¦ÄÜÓëʵÀýÏê½â
Ò»¡¢²ÉÓÃDHCP·þÎñµÄ³£¼ûÎÊÌâ
¼ÜÉèDHCP·þÎñÆ÷¿ÉÒÔΪ¿Í»§¶Ë×Ô¶¯·ÖÅäIPµØÖ·¡¢ÑÚÂ롢ĬÈÏÍø¹Ø¡¢DNS·þÎñÆ÷µÈÍøÂç²ÎÊý£¬¼ò»¯ÁËÍøÂçÅäÖã¬Ìá¸ßÁ˹ÜÀíЧÂÊ¡£µ«ÔÚDHCP·þÎñµÄ¹ÜÀíÉÏ´æÔÚһЩÎÊÌ⣬³£¼ûµÄÓУº ¡ñDHCP ServerµÄð³ä
¡ñDHCP ServerµÄDOS¹¥»÷£¬ÈçDHCPºÄ½ß¹¥»÷ ¡ñijЩÓû§Ëæ±ãÖ¸¶¨IPµØÖ·£¬Ôì³ÉIPµØÖ·³åÍ» 1¡¢DHCP ServerµÄð³ä
ÓÉÓÚDHCP·þÎñÆ÷ºÍ¿Í»§¶ËÖ®¼äûÓÐÈÏÖ¤»úÖÆ£¬ËùÒÔÈç¹ûÔÚÍøÂçÉÏËæÒâÌí¼Óһ̨DHCP·þÎñÆ÷£¬Ëü¾Í¿ÉÒÔΪ¿Í»§¶Ë·ÖÅäIPµØÖ·ÒÔ¼°ÆäËûÍøÂç²ÎÊý¡£Ö»ÒªÈøÃDHCP·þÎñÆ÷·ÖÅä´íÎóµÄIPµØÖ·ºÍÆäËûÍøÂç²ÎÊý£¬ÄǾͻá¶ÔÍøÂçÔì³É·Ç³£´óµÄΣº¦¡£ 2¡¢DHCP ServerµÄ¾Ü¾ø·þÎñ¹¥»÷
ͨ³£DHCP·þÎñÆ÷ͨ¹ý¼ì²é¿Í»§¶Ë·¢Ë͵ÄDHCPÇëÇó±¨ÎÄÖеÄCHADDR£¨Ò²¾ÍÊÇClient MAC address£©×Ö¶ÎÀ´ÅжϿͻ§¶ËµÄMACµØÖ·¡£Õý³£Çé¿öϸÃCHADDR×ֶκͷ¢ËÍÇëÇó±¨ÎĵĿͻ§¶ËÕæÊµµÄMACµØÖ·ÊÇÏàͬµÄ¡£¹¥»÷Õß¿ÉÒÔÀûÓÃαÔìMACµÄ·½Ê½·¢ËÍDHCPÇëÇ󣬵«ÕâÖÖ¹¥»÷¿ÉÒÔʹÓÃCisco ½»»»»úµÄ¶Ë¿Ú°²È«ÌØÐÔÀ´·ÀÖ¹¡£¶Ë¿Ú°²È«ÌØÐÔ£¨Port Security£©¿ÉÒÔÏÞÖÆÃ¿¸ö¶Ë¿ÚֻʹÓÃΨһµÄMACµØÖ·¡£µ«ÊÇÈç¹û¹¥»÷Õß²»ÐÞ¸ÄDHCPÇëÇó±¨ÎĵÄÔ´MACµØÖ·£¬¶øÊÇÐÞ¸ÄDHCP±¨ÎÄÖеÄCHADDR×Ö¶ÎÀ´ÊµÊ©¹¥»÷£¬ÄǶ˿ڰ²È«¾Í²»Æð×÷ÓÃÁË¡£ÓÉÓÚDHCP
·þÎñÆ÷ÈÏΪ²»Í¬µÄCHADDRÖµ±íʾÇëÇóÀ´×Ô²»Í¬µÄ¿Í»§¶Ë£¬ËùÒÔ¹¥»÷Õß¿ÉÒÔͨ¹ý´óÁ¿·¢ËÍαÔìCHADDRµÄDHCPÇëÇ󣬵¼ÖÂDHCP·þÎñÆ÷ÉϵĵØÖ·³Ø±»ºÄ¾¡£¬´Ó¶øÎÞ·¨ÎªÆäËûÕý³£Óû§Ìá¹©ÍøÂçµØÖ·£¬ÕâÊÇÒ»ÖÖDHCPºÄ½ß¹¥»÷¡£DHCPºÄ½ß¹¥»÷¿ÉÒÔÊÇ´¿´âµÄDOS¹¥»÷£¬Ò²¿ÉÒÔÓëαÔìµÄDHCP·þÎñÆ÷ÅäºÏʹÓᣵ±Õý³£µÄDHCP·þÎñÆ÷̱»¾Ê±£¬¹¥»÷Õ߾ͿÉÒÔ½¨Á¢Î±ÔìµÄDHCP·þÎñÆ÷À´Îª¾ÖÓòÍøÖеĿͻ§¶ËÌṩµØÖ·£¬Ê¹ËüÃǽ«ÐÅϢת·¢¸ø×¼±¸½ØÈ¡µÄ¶ñÒâ¼ÆËã»ú¡£ÉõÖÁ¼´Ê¹DHCPÇëÇó±¨ÎĵÄÔ´MACµØÖ·ºÍCHADDR×ֶζ¼ÊÇÕýÈ·µÄ£¬µ«ÓÉÓÚDHCPÇëÇó±¨ÎÄÊǹ㲥±¨ÎÄ£¬Èç¹û´óÁ¿·¢Ë͵Ļ°Ò²»áºÄ¾¡ÍøÂç´ø¿í£¬ÐγÉÁíÒ»Ö־ܾø·þÎñ¹¥»÷¡£
3¡¢¿Í»§¶ËËæÒâÖ¸¶¨IPµØÖ·
¿Í»§¶Ë²¢·ÇÒ»¶¨ÒªÊ¹ÓÃDHCP·þÎñ£¬Ëü¿ÉÒÔͨ¹ý¾²Ì¬Ö¸¶¨µÄ·½Ê½À´ÉèÖÃIPµØÖ·¡£Èç¹ûËæ±ãÖ¸¶¨µÄ»°£¬½«»á´ó´óÌá¸ßÍøÂçIPµØÖ·³åÍ»µÄ¿ÉÄÜÐÔ¡£
¶þ¡¢DHCP Snooping¼¼Êõ½éÉÜ
DHCP¼àÌý£¨DHCP Snooping£©ÊÇÒ»ÖÖDHCP°²È«ÌØÐÔ¡£Cisco½»»»»úÖ§³ÖÔÚÿ¸öVLAN»ù´¡ÉÏÆôÓÃDHCP¼àÌýÌØÐÔ¡£Í¨¹ýÕâÖÖÌØÐÔ£¬½»»»»úÄܹ»À¹½ØµÚ¶þ²ãVLANÓòÄÚµÄËùÓÐDHCP±¨ÎÄ¡£ DHCP¼àÌý½«½»»»»ú¶Ë¿Ú»®·ÖΪÁ½Àࣺ
¡ñ·ÇÐÅÈζ˿ڣºÍ¨³£ÎªÁ¬½ÓÖÕ¶ËÉ豸µÄ¶Ë¿Ú£¬ÈçPC£¬ÍøÂç´òÓ¡»úµÈ
¡ñÐÅÈζ˿ڣºÁ¬½ÓºÏ·¨DHCP·þÎñÆ÷µÄ¶Ë¿Ú»òÕßÁ¬½Ó»ã¾Û½»»»»ú
µÄÉÏÐж˿Ú
ͨ¹ý¿ªÆôDHCP¼àÌýÌØÐÔ£¬½»»»»úÏÞÖÆÓû§¶Ë¿Ú£¨·ÇÐÅÈζ˿ڣ©Ö»Äܹ»·¢ËÍDHCPÇëÇ󣬶ªÆúÀ´×ÔÓû§¶Ë¿ÚµÄËùÓÐÆäËüDHCP±¨ÎÄ£¬ÀýÈçDHCP Offer±¨Îĵȡ£¶øÇÒ£¬²¢·ÇËùÓÐÀ´×ÔÓû§¶Ë¿ÚµÄDHCPÇëÇó¶¼±»ÔÊÐíͨ¹ý£¬½»»»»ú»¹»á±È½ÏDHCP ÇëÇó±¨Îĵ썱¨ÎÄÍ·ÀïµÄ£©Ô´MACµØÖ·ºÍ£¨±¨ÎÄÄÚÈÝÀïµÄ£©DHCP¿Í»§»úµÄÓ²¼þµØÖ·£¨¼´CHADDR×ֶΣ©£¬Ö»ÓÐÕâÁ½ÕßÏàͬµÄÇëÇó±¨ÎIJŻᱻת·¢£¬·ñÔò½«±»¶ªÆú¡£ÕâÑù¾Í·ÀÖ¹ÁËDHCPºÄ½ß¹¥»÷¡£
ÐÅÈζ˿ڿÉÒÔ½ÓÊÕËùÓеÄDHCP±¨ÎÄ¡£Í¨¹ýÖ»½«½»»»»úÁ¬½Óµ½ºÏ·¨DHCP·þÎñÆ÷µÄ¶Ë¿ÚÉèÖÃΪÐÅÈζ˿ڣ¬ÆäËû¶Ë¿ÚÉèÖÃΪ·ÇÐÅÈζ˿ڣ¬¾Í¿ÉÒÔ·ÀÖ¹Óû§Î±ÔìDHCP·þÎñÆ÷À´¹¥»÷ÍøÂç¡£DHCP¼àÌýÌØÐÔ»¹¿ÉÒԶԶ˿ڵÄDHCP±¨ÎĽøÐÐÏÞËÙ¡£Í¨¹ýÔÚÿ¸ö·ÇÐÅÈζ˿ÚϽøÐÐÏÞËÙ£¬½«¿ÉÒÔ×èÖ¹ºÏ·¨DHCPÇëÇó±¨ÎĵĹ㲥¹¥»÷¡£
DHCP¼àÌý»¹ÓÐÒ»¸ö·Ç³£ÖØÒªµÄ×÷ÓþÍÊǽ¨Á¢Ò»ÕÅDHCP¼àÌý°ó¶¨±í£¨DHCP Snooping Binding£©¡£Ò»µ©Ò»¸öÁ¬½ÓÔÚ·ÇÐÅÈζ˿ڵĿͻ§¶Ë»ñµÃÒ»¸öºÏ·¨µÄDHCP Offer£¬½»»»»ú¾Í»á×Ô¶¯ÔÚDHCP¼àÌý°ó¶¨±íÀïÌí¼ÓÒ»¸ö°ó¶¨ÌõÄ¿£¬ÄÚÈݰüÀ¨Á˸÷ÇÐÅÈζ˿ڵĿͻ§¶ËIPµØÖ·¡¢MACµØÖ·¡¢¶Ë¿ÚºÅ¡¢VLAN±àºÅ¡¢×âÆÚµÈÐÅÏ¢¡£È磺 Switch#showipdhcp snooping binding MacAddress IpAddress