¶¯Ì¬Ö÷»úÅäÖÃÐÒ飨DHCP£©×÷ÎªÍøÂç¹ÜÀíÖеÄÖØÒª×é³É²¿·Ö£¬°çÑÝ×ÅÎªÍøÂçÉ豸×Ô¶¯·ÖÅäIPµØÖ·¡¢×ÓÍøÑÚÂ롢ĬÈÏÍø¹Ø¼°DNS·þÎñÆ÷µØÖ·µÈ¹Ø¼üÍøÂçÅäÖÃÐÅÏ¢µÄ½ÇÉ«
È»¶ø£¬Î´¾ÊÚȨ»òÅäÖò»µ±µÄDHCP·þÎñÆ÷¿ÉÄܵ¼ÖÂIPµØÖ·³åÍ»¡¢ÍøÂçÐÔÄÜϽµÄËÖÁ°²È«Â©¶´
Òò´Ë£¬ÕýÈ·ÊÚȨDHCP·þÎñÆ÷£¬²»½öÊÇÈ·±£ÍøÂç˳³©ÔËÐеĻù´¡£¬¸üÊǹ¹½¨°²È«ÍøÂç»·¾³µÄ±ØÒª²½Öè
±¾ÎĽ«ÉîÈë̽ÌÖÊÚȨDHCP·þÎñÆ÷µÄÖØÒªÐÔ¡¢ÊµÊ©·½·¨ÒÔ¼°ÈçºÎͨ¹ýÊÚȨ»úÖÆÌáÉýÍøÂçµÄÕûÌåЧÄÜÓ밲ȫÐÔ
Ò»¡¢DHCP·þÎñÆ÷ÊÚȨµÄÖØÒªÐÔ 1.±ÜÃâIPµØÖ·³åÍ»£ºÔÚÒ»¸öÍøÂçÖУ¬Èç¹û´æÔÚ¶à¸öδ¾ÊÚȨµÄDHCP·þÎñÆ÷£¬ËüÃÇ¿ÉÄÜ»áÏòÍ¬Ò»ÍøÂçÄÚµÄÉ豸·ÖÅäÖØµþµÄIPµØÖ·£¬µ¼ÖÂIP³åÍ»£¬Ê¹µÃÉ豸ÎÞ·¨Õý³£Í¨ÐÅ£¬Ó°ÏìÍøÂçµÄÎȶ¨ÐԺͿÉÓÃÐÔ
2.ÔöÇ¿ÍøÂ簲ȫÐÔ£ºÎ´¾ÊÚȨµÄDHCP·þÎñÆ÷¿ÉÄܳÉÎªÍøÂç¹¥»÷ÕßµÄÌø°å£¬Í¨¹ýαÔìDHCPÏìÓ¦£¬Ïò¿Í»§¶ËÉ豸·Ö·¢´íÎóµÄÍøÂçÅäÖÃÐÅÏ¢£¬ÈçÖ¸Ïò¶ñÒâDNS·þÎñÆ÷µÄµØÖ·£¬´Ó¶øÊµÊ©ÖмäÈ˹¥»÷£¨MITM£©»òDNS½Ù³Ö£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖØ¶¨ÏòÓû§ÖÁµöÓãÍøÕ¾
3.ÌáÉýÍøÂç¹ÜÀíЧÂÊ£ºÍ¨¹ýÊÚȨDHCP·þÎñÆ÷£¬ÍøÂç¹ÜÀíÔ±¿ÉÒÔ¼¯ÖйÜÀíIPµØÖ··ÖÅä²ßÂÔ£¬È·±£×ÊÔ´µÄºÏÀí·ÖÅäÓëÀûÓã¬Í¬Ê±±ãÓÚ×·×ÙºÍ¼à¿ØÍøÂçÉ豸µÄ״̬£¬Ìá¸ß¹ÊÕÏÅŲéÓëÏìÓ¦ËÙ¶È
4.·ûºÏºÏ¹æÐÔÒªÇó£ºÐí¶àÐÐÒµ±ê×¼ºÍ·¨¹æÒªÇóÆóÒµ¶ÔÆäÍøÂç»ù´¡ÉèʩʵʩÑϸñµÄ·ÃÎÊ¿ØÖƺÍÉ󼯻úÖÆ£¬ÊÚȨDHCP·þÎñÆ÷ÊÇÂú×ãÕâЩºÏ¹æÐÔÒªÇóµÄ¹Ø¼üÒ»»·
¶þ¡¢ÈçºÎÊÚȨDHCP·þÎñÆ÷ ÊÚȨDHCP·þÎñÆ÷µÄ·½·¨ÒòÍøÂç¼Ü¹¹ºÍʹÓõļ¼ÊõÕ»¶øÒ죬µ«Í¨³£°üÀ¨ÒÔϼ¸¸öºËÐIJ½Ö裺 1.Ñ¡Ôñ²¢²¿ÊðºÏÊʵÄDHCP·þÎñÆ÷Èí¼þ£º¸ù¾ÝÍøÂç¹æÄ£ºÍÐèÇó£¬Ñ¡ÔñºÏÊʵÄDHCP·þÎñÆ÷Èí¼þ£¬ÈçMicrosoftµÄDHCP·þÎñ£¨¼¯³ÉÓÚWindows Server£©¡¢ISC DHCP·þÎñÆ÷£¨ÊÊÓÃÓÚLinux»·¾³£©»òµÚÈý·½½â¾ö·½°¸
È·±£Èí¼þ°æ±¾×îУ¬ÒÔ»ñÈ¡×îÐµİ²È«²¹¶¡ºÍ¹¦ÄܸüÐÂ
2.ÅäÖÃDHCP·þÎñÆ÷£º°²×°Íê³Éºó£¬Ðè¶ÔDHCP·þÎñÆ÷½øÐлù±¾ÅäÖ㬰üÀ¨ÉèÖÃ×÷ÓÃÓò£¨¶¨ÒåIPµØÖ·³Ø£©¡¢×ÓÍøÑÚÂ롢ĬÈÏÍø¹Ø¡¢DNS·þÎñÆ÷µØÖ·µÈ
´ËÍ⣬»¹ÐèÅäÖÃDHCP×âÔ¼ÆÚÏÞ¡¢ÈÕÖ¾¼Ç¼¼¶±ðµÈ²ÎÊý£¬ÒÔÂú×ãÍøÂç¹ÜÀíµÄÐèÇó
3.ʵʩ·ÃÎÊ¿ØÖÆ£ºÈ·±£Ö»ÓÐÊÚȨµÄ¹ÜÀíÔ±Äܹ»·ÃÎʺÍÐÞ¸ÄDHCP·þÎñÆ÷µÄÅäÖÃ
Õâ¿ÉÒÔͨ¹ý²Ù×÷ϵͳ¼¶±ðµÄÓû§È¨ÏÞ¹ÜÀí¡¢·À»ðǽ¹æÔòÒÔ¼°DHCP·þÎñÆ÷Èí¼þ×ÔÉíµÄ·ÃÎÊ¿ØÖÆÁÐ±í£¨ACL£©À´ÊµÏÖ
4.ʹÓÃDHCPÖмÌ/´úÀí£¨ÈçÓбØÒª£©£ºÔÚ´óÐÍ»ò¸´ÔÓÍøÂçÖУ¬DHCP·þÎñÆ÷¿ÉÄÜÎÞ·¨Ö±½Ó½ÓÊÕµ½ËùÓпͻ§¶ËµÄÇëÇó
´Ëʱ£¬ÐèÅäÖÃDHCPÖмÌ/´úÀí£¬½«¿Í»§¶ËµÄÇëÇóת·¢ÖÁÖ¸¶¨µÄDHCP·þÎñÆ÷£¬²¢È·±£ÕâЩÖмÌ/´úÀíÒ²ÊǾ¹ýÊÚȨµÄ
5.ÑéÖ¤ÓëÊÚȨ»úÖÆ£º¶ÔÓÚÖ§³ÖDHCPv6µÄÍøÂ磬¿ÉÒÔÀûÓÃDHCPv6µÄÈÏÖ¤»úÖÆ£¨ÈçDHCPv6-Authenticate£©À´ÔöÇ¿°²È«ÐÔ£¬È·±£Ö»Óо¹ýÈÏÖ¤µÄDHCP·þÎñÆ÷²ÅÄÜÌṩ·þÎñ
¶ÔÓÚDHCPv4£¬ËäÈ»±ê×¼ÐÒé±¾Éí²»Ö§³ÖÈÏÖ¤£¬µ«¿ÉÒÔͨ¹ýÍøÂç¼Ü¹¹Éè¼ÆºÍ°²È«²ßÂÔÀ´¼ä½ÓʵÏÖÀàËÆÐ§¹û£¬ÈçʹÓÃVLAN¸ôÀë¡¢IPSec¼ÓÃܵÈ
6.¶¨ÆÚÉó¼ÆÓë¼à¿Ø£º½¨Á¢¶¨ÆÚÉó¼ÆDHCP·þÎñÆ÷ÅäÖúÍÈÕÖ¾µÄ»úÖÆ£¬¼°Ê±·¢ÏÖ²¢¾ÀÕýÅäÖôíÎó»òDZÔڵݲȫ·çÏÕ
ͬʱ£¬ÀûÓÃÍøÂç¼à¿Ø¹¤¾ßʵʱ¸ú×ÙDHCP»î¶¯£¬¶ÔÒì³£ÐÐΪ½øÐÐÔ¤¾¯ºÍÏìÓ¦
Èý¡¢Í¨¹ýÊÚȨDHCP·þÎñÆ÷ÌáÉýÍøÂçЧÄÜÓ밲ȫÐÔ 1.ÓÅ»¯×ÊÔ´·ÖÅ䣺ͨ¹ý¼¯ÖйÜÀíºÍÖÇÄÜ·ÖÅäIPµØÖ·£¬ÊÚȨDHCP·þÎñÆ÷ÄÜÓÐЧ±ÜÃâIPµØÖ·À˷ѺͳåÍ»£¬Ìá¸ßÍøÂç×ÊÔ´µÄÀûÓÃÂÊ
2.ÔöÇ¿ÍøÂç¿É¼ûÐÔ£ºÊÚȨDHCP·þÎñÆ÷¼Ç¼µÄÍøÂç»î¶¯ÈÕÖ¾£¬ÎªÍøÂç¹ÜÀíÔ±ÌṩÁ˷ḻµÄÊý¾ÝÖ§³Ö£¬ÓÐÖúÓÚ¿ìËÙ¶¨Î»ÍøÂçÎÊÌ⣬ÓÅ»¯ÍøÂçÐÔÄÜ
3.´Ù½øºÏ¹æÐÔ£ºÍ¨¹ýÑϸñµÄ·ÃÎÊ¿ØÖƺÍÉ󼯻úÖÆ£¬ÊÚȨDHCP·þÎñÆ÷ÓÐÖúÓÚÆóÒµÂú×ãÐÐÒµ±ê×¼ºÍ·¨¹æÒªÇ󣬽µµÍ·¨ÂÉ·çÏÕ
4.ÌáÉý°²È«ÐÔ£º½áºÏ·À»ðǽ¡¢ÈëÇÖ¼ì²âϵͳ£¨IDS£©¡¢°²È«Ê¼þÐÅÏ¢¹ÜÀí£¨SIEM£©µÈ°²È«×é¼þ£¬ÊÚȨDHCP·þÎñÆ÷Äܹ»¹¹½¨¶à²ã´ÎµÄ·ÀÓùÌåϵ£¬ÓÐЧµÖÓùÍøÂç¹¥»÷
5.Ö§³ÖÁé»îµÄÍøÂçÀ©Õ¹£ºËæ×ÅÆóÒµÒµÎñµÄÔö³¤£¬ÍøÂç¹æÄ£²»¶ÏÀ©´ó
ÊÚȨDHCP·þÎñÆ÷Äܹ»ÇáËÉÊÊÓ¦ÕâÖֱ仯£¬Í¨¹ý¶¯Ì¬µ÷ÕûIPµØÖ·³Ø¡¢Ìí