97¹ú¼Ê

¹¤³§ÑÐѧ Ø­ 97¹ú¼ÊÍøÂçÊý×Ö»¯ÖÇÄܹ¤³§¡°ºÚ¿Æ¼¼¡±´ó½ÒÃØ
Ô¤Ô¼Ö±²¥
ÀÖÏíÓªÒµ°ü¹Ü·þÎñ Ø­ ÊØ»¤Ò½ÁÆÓªÒµÒ»Á¬ÎȹÌ
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

DHCP SnoopingÔõÑùÊÂÇé

DHCP Snooping×÷ÎªÍ¨Ñ¶ÍøÂç¶þ²ãÇå¾²ÌØÕ÷ £¬Äܹ»ÏÔÖøÌáÉýÍøÂçÇå¾²ÐÔÄÜ¡£±¾ÎĽ«Ê×ÏÈÏÈÈÝDHCPµÄÊÂÇéÀú³Ì £¬È»ºóͨ¹ýÁ½Öֵ䷶DHCP¹¥»÷°¸ÀýÀ´ËµÃ÷DHCP SnoopingµÄ»ù±¾ÊÂÇéÔ­ÀíÒÔ¼°ÔõÑù±ÜÃâÍøÂç¹¥»÷¡£

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    Ðû²¼Ê±¼ä£º2022-12-28

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µã»÷Á¿£º

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÎÒÏë̸ÂÛ

1 ʲôÊÇDHCP Snooping
DHCP SnoopingÒ²½ÐDHCP¿ú̽ £¬ÊÇÒ»ÖÖ³£Ó¦ÓÃÔÚ¶þ²ã½ÓÈë×°±¸µÄDHCPÇ徲ЭÒé £¬Ëüͨ¹ý¼àÌýDHCP±¨ÎÄÀ´×èµ²¾ÖÓòÍøÖв»Õýµ±µÄDHCPÁ÷Á¿ £¬´Ó¶ø±ÜÃâDHCP¹¥»÷ £¬ÌáÉýÍøÂçÇå¾²¡£°²ÅÅÁËDHCP SnoopingµÄ×°±¸Äܹ»ÊµÏÖÒÔÏÂÐж¯£º
¡ñ ¹ýÂ˲»ÊÜÐŶ˿ڵÄDHCPÓ¦´ð±¨ÎÄ£»
¡ñ ¹¹½¨ºÍά»¤DHCP Snooping°ó¶¨±í £¬ÆäÖаüÀ¨Óû§»ñÈ¡µ½µÄIPÐÅÏ¢ÒÔ¼°Óû§MACµØÖ·¡¢VID¡¢PORTºÍ×âԼʱ¼äµÈÐÅÏ¢£»
¡ñ ͨ¹ýÓëARP¼ì²â¹¦Ð§»òARP Check¹¦Ð§ÅäºÏʹÓà £¬¿ÉÒÔ½øÒ»²½ÊµÏÖ¿ØÖÆÓû§Õýµ±Ê¹ÓÃIPµØÖ·µÄÄ¿µÄ¡£
                                                                          
2 DHCP SnoopingÔõÑùÊÂÇé

2.1   DHCPÊÂÇéÔ­Àí

ÔÚÏÈÈÝDHCP SnoopingÔõÑùÊÂÇé֮ǰ £¬ÏȼòҪ˵Ã÷DHCPµÄÊÂÇé»úÖÆ¡£
DHCPÊÇÒ»¸ö±»ÆÕ±éÓ¦Óõġ¢Îª¾ÖÓòÍøÄÚÖ÷ÎÞа̬·ÖÅÉIPµØÖ·µÈÖ÷ÒªÐÅÏ¢µÄЭÒé¡£Ò»´ÎDHCPЭÒé½»»¥¿ÉÒÔ¼òÆÓ¹éÄÉ×ÛºÏΪÈçÏÂ4¸ö°ì·¨£º
(1) DHCP¿Í»§¶Ëͨ¹ý¹ã²¥DHCP Discover±¨ÎÄÀ´Ïò¾ÖÓòÍøÄÚµÄDHCP·þÎñÆ÷ÇëÇó·þÎñ¡£
(2) DHCP·þÎñÆ÷ƾ֤×ÔÉíÉèÖõÄIPµØÖ·³Ø¡¢ÏìÓ¦µÄ×ÓÍøÑÚÂëºÍÍø¹ØµÈÐÅÏ¢ £¬Í¨¹ýDHCP Offer±¨ÎÄÓ¦´ð¿Í»§¶Ë¡£
(3) Èô½ÓÊÜDHCP Offer±¨ÎÄÖеÄÉèÖà £¬DHCP¿Í»§¶ËÔò¹ã²¥DHCP Request±¨ÎÄÒÔͨ¸æDHCP·þÎñÆ÷ºÍ¾ÖÓòÍøÄÚÆäËûÖ÷»úÆäÉúЧµÄIPµØÖ·¡£
(4) ×îºó £¬·þÎñÆ÷½«»áÓ¦´ðDHCP ACK±¨Îĸø¿Í»§¶Ë¾ÙÐÐ×îÖÕÈ·ÈÏ¡£
Èçͼ2-1ÖÐ £¬Í¨¹ýDHCPЭÒé½»»¥ £¬¿Í»§¶Ë´ÓDHCPµØÖ·³ØÖÐ×âÓÃÁËIPµØÖ·10.0.0.11/24 £¬²¢µÃÖª¾ÖÓòÍøÄÚÍø¹ØµØÖ·Îª10.0.0.1¡£ÄÇô £¬¿Í»§¶ËºóÐøµÄIPÊý¾Ý½«·¢ÍùÍø¹Ø10.0.0.1ʵÏÖÓë¹ãÓòÍøµÄͨѶ¡£
ͼ2-1 DHCPЭÒéÔ­ÀíʾÒâͼ
DHCPЭÒéÔ­ÀíʾÒâͼ
                                                                                        

2.2   DHCP Snooping±ÜÃâ·þÎñÓÕÆ­¹¥»÷

ÓÉÓÚDHCP Discover/RequestÊǹ㲥±¨ÎÄ £¬ÈôÊǾÖÓòÍøÖмÓÈëÁ˹¥»÷Õß £¬ÄÇôËü±ã¿ÉÒÔ»ñÈ¡µ½ÍøÂçÄÚÿһ̨Ö÷»úµÄDHCPÇëÇóÐÅÏ¢¡£Í¨¹ýÐÞ¸ÄIPµØÖ·»òÕßÍø¹ØµÈÐÅϢαÔìDHCP Offer/ACK±¨ÎÄÓ¦´ðÖ÷»ú £¬À´µÖ´ïʹÓû§ÎÞ·¨ÉÏÍø»òÕßÇÔÈ¡Óû§ÐÅÏ¢µÄÄ¿µÄ £¬ÕâÖÖ¹¥»÷·½·¨±»³ÆÎªDHCP·þÎñÓÕÆ­¹¥»÷¡£Èçͼ2-2 £¬¹¥»÷ÕßΪÁ˽ػñ¾ÖÓòÍøÄÚÓû§µÄÁ÷Á¿ £¬½«×Ô¼ºÍâµØµÄIPµØÖ·10.0.0.2×÷ΪÐéÎ±Íø¹ØµØÖ· £¬²»·¨Ó¦´ð¿Í»§¶ËµÄDHCPÇëÇ󡣺óÐø £¬¿Í»§¶ËµÄIPÊý¾Ý°ü½«»á·¢ÍùÐéÎ±Íø¹Ø £¬Ôì³ÉÐÅϢй¶¡£ÈôÊǹ¥»÷ÕßÔڽػñÁ÷Á¿µÄͬʱ¶ÔÕæÊµÍø¹ØºÍ¿Í»§¶ËÖ®¼äµÄÊý¾Ý¾ÙÐÐת·¢ £¬ÄÇÃ´ÍøÂçÄÚÊܵ½¹¥»÷µÄÖ÷»ú½«¸ÐÊܲ»µ½¶ÏÍøµÈÍøÂçÒì³£ £¬Òþ²ØÐÔ¼«Ç¿¡£
ͼ2-2 DHCPÓÕÆ­¹¥»÷ʾÒâͼ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
                                                                                          
ÔÚ×°±¸ÉÏ¿ªÆôDHCP Snooping¹¦Ð§ £¬°ÑÅþÁ¬¿ÉÐÅ·þÎñÆ÷µÄ¶Ë¿ÚÉèÖÃΪTrust¿Ú £¬ÆäÓà½ÔΪUntrust¿Ú £¬DHCP SnoopingÄܹ»ÓÐÓõıÜÃâÉÏÎÄËùÊöµÄDHCP·þÎñÓÕÆ­¹¥»÷¡£Èçͼ2-3 £¬ÔÚDevice AÉÏ¿ªÆôDHCP Snooping¹¦Ð§ £¬Ö»ÓзþÎñÆ÷µÄDHCP Offer/ACK±¨ÎÄÄܹ»Í¨¹ýTrust¿ÚËÍ´ï¿Í»§¶Ë £¬¹¥»÷Õß×°±¸ÓÉÓÚÅþÁ¬ÔÚUntrust¿ÚÉÏ £¬Æä·¢Ë͵IJ»·¨DHCP Offer/ACK±¨ÎĽ«²»ÔÊÐíͨ¹ý £¬´Ó¶ø°ü¹Ü¿Í»§¶ËÄܹ»»ñµÃ׼ȷµÄÍøÂçÉèÖà £¬×èÖ¹ÁËÐÅϢй¶¡£
ͼ2-3 DHCP Snooping±ÜÃâDHCPÓÕÆ­¹¥»÷ʾÒâͼ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
                                                                                             

2.3   DHCP Snooping±ÜÃâαÔ챨ÎĹ¥»÷

³ýÁË·ÂðDHCP·þÎñÆ÷ £¬¹¥»÷Õß»¹ÄÜ·ÂðDHCP¿Í»§¶Ë¶ÔDHCP·þÎñÆ÷Ìᳫ¹¥»÷¡£Èçͼ2-4 £¬¹¥»÷Õßͨ¹ý²»·¨½Ø»ñDHCP¿Í»§¶ËÔÚ¾ÖÓòÍøÄڹ㲥µÄDHCP Discover±¨ÎÄ»ñÈ¡ÆäMACµØÖ· £¬´Ó¶ø·ÂðMACαÔì²î±ðµÄDHCP¿Í»§¶ËÏòDHCP·þÎñÆ÷´ó×Ú·¢ËͲ»·¨ÇëÇó±¨ÎÄ £¬Ê¹µÃDHCP·þÎñÆ÷µÄIPµØÖ·³Ø±»ÏûºÄ £¬ÉõÖÁÇÀ¶áÍøÂçÄÚÕýµ±¿Í»§¶ËµÄIPµØÖ·¡£Ò»µ©·þÎñÆ÷µÄIPµØÖ·³Ø±»²»·¨ÇëÇóºÄ¿Õ £¬ÍøÂçÄ򵀮äËûÕýµ±Ö÷»ú½«ÓÉÓÚÎÞ·¨Í¨¹ýDHCP»ñµÃIPµØÖ·¶ø¶ÏÍø¡£ÕâÖÖ¹¥»÷·½·¨±»³ÆÎªÎ±ÔìDHCP±¨ÎĹ¥»÷ £¬Ò²ÊÇÒ»Öֵ䷶µÄDoS¹¥»÷¡£
ͼ2-4 αÔìDHCP±¨ÎĹ¥»÷ʾÒâͼ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
                                                                            
³ýÁ˹ýÂËUntrust¿ÚµÄ²»·¨DHCPÓ¦´ð±¨ÎÄ £¬DHCP Snoopingͨ¹ý½øÒ»²½Î¬»¤DHCP°ó¶¨±íÏîÀ´±ÜÃâαÔ챨ÎĹ¥»÷¡£DHCP°ó¶¨±íÏîͨ¹ý¿ú̽Õýµ±DHCP±¨ÎÄÀ´¶Ô¿Í»§¶ËµÄMACµØÖ·¡¢IPµØÖ·×âÆÚ¡¢½Ó¿ÚºÅºÍVLANÐÅÏ¢µÈ½¨ÉèÆð¹ØÁª²¢ÇÒά»¤ £¬´Ó¶ø¶ÔºóÐøDHCP¿Í»§¶ËÇëÇó±¨ÎľÙÐйýÂË¡£Èçͼ2-5 £¬ÔÚDevice AÉϰ²ÅÅDHCP Snooping¹¦Ð§²¢½«Óë¿Í»§¶ËÖ÷»úÏàÁ¬µÄ½Ó¿ÚÉèÖÃΪUntrust¿Ú¡£ÄÇô £¬ËùÓÐͨ¹ýUntrust¿ÚµÄDHCPÇëÇó±¨ÎĽ«»áÊ×ÏȾÙÐÐDHCP°ó¶¨±íÏîÆ¥Åä¡£ÓÉÓÚ¹¥»÷ÕßαÔìµÄ±¨ÎÄÓëDevice AÉÏά»¤µÄ°ó¶¨±íÎÞ·¨Æ¥Åä £¬Î±Ô챨ÎĽ«»á±»ÑïÆú £¬´Ó¶øÓÐÓÃ×èÖ¹ÁËÕâÀ๥»÷¡£
ͼ2-5 DHCP Snooping±ÜÃâαÔìDHCP±¨ÎĹ¥»÷ʾÒâͼ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
                                                                                            
3 ½áÓï
DHCP Snooping×÷ΪDHCPÇå¾²ÌØÕ÷ £¬³ýÁËÄÜͨ¹ý¶ÔUntrust¿Ú²»·¨DHCPÁ÷Á¿µÄ×èµ²ÒÔ¼°°ó¶¨±íµÄά»¤À´±ÜÃâDHCP·þÎñÓÕÆ­¹¥»÷ºÍαÔìDHCP±¨ÎĹ¥»÷Íâ £¬»¹ÄÜͨ¹ýÓëARPЭÒéÁª¶¯±ÜÃâARPÈëÇÖ¡£ÓÉÓÚDHCPЭÒéÓ¦ÓÃÆÕ±é £¬ÎªÌáÉýÍøÂçÇå¾²ÐÔÄÜ £¬ÔÚÓû§½ÓÈë²ã°²ÅÅÖ§³ÖDHCP SnoopingÌØÕ÷µÄ×°±¸ÊÇÊ®·ÖÐëÒªµÄ¡£
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

µãÔÞ

¸ü¶àÊÖÒÕ²©ÎÄ

ÈκÎÐèÒª £¬ÇëÁªÏµ97¹ú¼Ê

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌâ £¿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù £¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£© £¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£© £¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Òé £¿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌâ £¬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼