Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

How to deploy DHCP server in production environment

2025-02-02 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >

Share

Shulou(Shulou.com)06/01 Report--

This article mainly introduces "how to deploy the DHCP server in the production environment". In the daily operation, I believe that many people have doubts about how to deploy the DHCP server in the production environment. The editor consulted all kinds of materials and sorted out the simple and easy-to-use operation methods. I hope it will be helpful to answer the doubts about "how to deploy the DHCP server in the production environment". Next, please follow the editor to study!

DHCP servers and DNS servers are the most common basic network services in a production network, so let's take a look at how to deploy DHCP servers in a production environment.

I. Theory

DHCP, the dynamic host configuration protocol, is a service used to provide IP address to the client. The working process of the client to obtain the IP address is divided into four parts.

1. Discover: the client sends a broadcast to find the DHCP server, because this is a broadcast packet, which can be received by all hosts on the same network segment, but only the DHCP server will respond.

2. Offer: the response message of the DHCP server to the client. Some manufacturers use broadcast and some use unicast. In this message, the DHCP server has responded to the client, your IP address, mask and other DHCP Option.

3. Request: after receiving the Offer message, the client will send broadcast information to the whole network again with the options provided by the Offer message.

4. ACK: the server sends a confirmation message and the IP address has been assigned to the client.

By grabbing the bag, we found two points:

1. The port monitored by the server is port 67, and the port monitored by the client is port 68.

two。 The discover and request messages sent by the client are broadcast messages and cannot pass through the router.

2. How to send DHCP packets to DHCP servers across network segments

In production networks, in order to reduce broadcast domains, we usually deploy VLAN on layer 3 switches so that faults can be isolated. However, there will be problems in deploying DHCP in this case, because DHCP's broadcast packets cannot cross the three-layer network. This introduces a new technology, called DHCP relay, which means that the DHCP broadcast message sent by the client will be transferred to a unicast and sent to the DHCP server, so that the DHCP client can communicate with the server normally.

The configuration of the trunk is generally configured under the VLAN interface of the layer 3 switch, that is, the trunk is configured at the user gateway. The following configuration is the configuration of the Huawei switch, which is called on the Cisco switch and the ip helper-address XXX.XXX.XXX.XXX is configured under the VLAN interface.

# configuration of DHCP Relay

Dhcp enable

Dhcp server group DHCP_group

Dhcp-server 192.168.100.253 0

Interface Vlanif20

Ip address 192.168.20.254 255.255.255.0

Dhcp select relay

Dhcp relay server-select DHCP_group

DHCP relay capture packet: after the relay, the user's broadcast packet is converted into a unicast packet to be sent.

III. DHCP server deployment

In the current network, there are generally two situations in which DHCP servers are deployed, one is deployed on layer 3 switches, and the other is deployed on servers. It is easy to deploy on the switch, but later maintenance is a little troublesome, especially when you need to save the user's DHCP database, Huawei seems to need to enter a command after the switch restart to restore the original DHCP database. Deployment on the server is more powerful and the management is more intuitive. Let's give a brief description of the two situations.

(1) deployment on the switch

If DHCP is deployed on a switch, there is generally no need for trunking, and broadcasts sent by clients can be propagated to the DHCP server.

Dhcp enable

Ip pool vlan10 # name the address pool

Gateway of gateway-list 192.168.10.254 # address pool

Network segment and mask of network 192.168.10.0 mask 255.255.255.0 # address pool

Static-bind ip-address 192.168.10.100 mac-address 5489-987b-3e04 # IP address binding

Excluded-ip-address 192.168.10.200 192.168.10.253 # excluded address field

Dns-list 8.8.8.8 # DNS Server

Interface Vlanif10

Ip address 192.168.10.254 255.255.255.0

Dhcp select global # means that users under this VLAN look for DHCP servers from the global address pool, and there is also a simpler one, called dhcp select interface.

(2) deployment on the server

The case here is the deployment of a DHCP server from a Windows server. There are two points to note: 1. Each VLAN is configured with a scope 2. 0. Options common to all scopes can be configured as server options, such as the address of the DNS server can be placed on the server option, while options that need to be configured separately for each VLAN are configured as scope options, such as gateways.

1. On the Windows server, through the server manager, add a role and check the role of the DHCP server to install.

two。 After the installation is complete, open the DHCP management tool and create a scope.

Lease term: if the company needs to assign different Internet access rights to different IP addresses, my approach is to set the IP lease for the wired network to 30 days and the wireless network segment to 2 hours.

Summary: for deploying DHCP server through Windows in production environment, you need to be familiar with the configuration of switch and Windows.

At this point, the study on "how to deploy a DHCP server in a production environment" is over. I hope to be able to solve your doubts. The collocation of theory and practice can better help you learn, go and try it! If you want to continue to learn more related knowledge, please continue to follow the website, the editor will continue to work hard to bring you more practical articles!

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Network Security

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report