【正文】
務(wù)器級(jí)和作用域級(jí)的信息 DHCP Server DHCP審核日志 DHCP 審核日志是服務(wù)器相關(guān)的日志,比如,什么時(shí)間 DHCP服務(wù)啟動(dòng)和停止;什么時(shí)間 DHCP服務(wù)器被授權(quán) ; 或者 IP 地址釋放、重新獲得、重新釋放,或者拒絕的情況 DHCP審核日志工作過(guò)程 3. 結(jié)束每日審核日志 2. DHCP 檢查磁盤空間 1. DHCP 打開(kāi)每天的日志 DHCP服務(wù)器開(kāi)始寫入日志,用一個(gè)頭信息表示日志已經(jīng)開(kāi)始記錄 定期執(zhí)行磁盤檢查,以確保服務(wù)器磁盤空間的可用性以及當(dāng)前審核日志文件不會(huì)變得太長(zhǎng)或日志文件增長(zhǎng)不會(huì)太快 服務(wù)器關(guān)閉現(xiàn)有日志并移動(dòng)到用于本周后一天的日志文件 審核日志每天都收集 DHCP服務(wù)器的事件,把它們寫入日志文件中 12:00 am DHCP審核日志 使用性能計(jì)數(shù)器監(jiān)控 DHCP服務(wù)器 性能計(jì)數(shù)器 What to look for after a baseline is established Packets received/second Monitor for sudden increases or decreases which could reflect problems on the work Requests/second Monitor for sudden increases or decreases which could reflect problems on the work Active queue length Monitor for increases both sudden and gradual which could reflect increased load or decreased server capacity Duplicates dropped/second Monitor for any activity which could indicate that more than one request is being transmitted on behalf of clients 配置 DHCP安全性 ? 限制非法客戶機(jī)獲得 IP地址租約 ? 限制非授權(quán)的服務(wù)器提供 IP地址租約 ? 限制 DHCP管理員數(shù)目 ? 實(shí)現(xiàn) DHCP數(shù)據(jù)庫(kù)安全性 限制非法客戶機(jī)獲得 IP地址租約 To restrict an unauthorized user from obtaining a lease: 確保非授權(quán)的用戶和網(wǎng)絡(luò)之間沒(méi)有物理連接 在網(wǎng)絡(luò)中每一臺(tái) DHCP服務(wù)器上起用審核日志 定期檢查審核日志 啟用 限制非授權(quán)的服務(wù)器提供 IP地址租約 To restrict an unauthorized, nonMicrosoft DHCP server from leasing IP addresses: Ensure that unauthorized persons do not have physical or wireless access to your work Microsoft DHCP Server Only DHCP servers running Windows 2022 or Windows Server 2022 can be authorized in Active Directory Unauthorized, nonMicrosoft DHCP Server NonMicrosoft DHCP server software does not include the authorization feature that is included in Windows 2022 and Windows Server 2022 限制 DHCP管理員數(shù)目 To restrict who can administer the DHCP service: Restrict the membership of the DHCP Administrators group to the minimum number of users necessary to administer the service If there are users who need readonly access to the DHCP console, then add them to the DHCP Users group instead of the DHCP Administrators group DHCP Users group Have readonly DHCP console access to the server DHCP Administrators group Can view and modify any data about the DHCP server 實(shí)現(xiàn) DHCP數(shù)據(jù)庫(kù)安全性 To further secure the DHCP database: Consider changing the default permissions of the DHCP folder Provide only the minimum permissions required to users to enable them to perform their task Provide Read permissions to users responsible for analyzing DHCP server log files Remove Authenticated Users and Power Users to minimize access to the files in the DHCP folder 小 結(jié) ? 動(dòng)態(tài) IP地址的優(yōu)點(diǎn)主要是可減少 IP地址和IP參數(shù)管理的工作量 、 提高 IP地址的利用率 。在左側(cè)控制臺(tái)樹(shù)中雙擊DHCP服務(wù)器,在展開(kāi)的樹(shù)中雙擊作用域,然后單擊“ 地址租約 ” 選項(xiàng),將能夠看到從當(dāng)前 DHCP服務(wù)器的當(dāng)前作用域中租用 IP地址的租約 。 保留特定的 IP地址 ?配置超級(jí)作用域 ? 超級(jí)作用域是運(yùn)行 Windows Server 2022的 DHCP服務(wù)器的一種管理功能,當(dāng) DHCP服務(wù)器上有多個(gè)作用域時(shí),就可組成超級(jí)作用域,作為單個(gè)實(shí)體來(lái)管理。 授權(quán) DHCP服務(wù)器 ?創(chuàng)建 DHCP作用域 ?DHCP服務(wù)器是為了自動(dòng)分配 IP地址而配置的,因此必須具有相應(yīng)可分配的、有效的 IP地址。如果網(wǎng)絡(luò)中的DHCP服務(wù)器都是正確配置的,則網(wǎng)絡(luò)將能夠正常運(yùn)行。 安裝 DHCP服務(wù)器 ?( 8)在 “ 域名稱和 DNS服務(wù)器 ” 對(duì)話框中設(shè)置域名稱和 DNS服務(wù)器的 IP地址。 ? 3. DHCP服務(wù)器必須要擁有一組有效的 IP地址,以便自動(dòng)分配給客戶端。在這一階段, DHCP客戶機(jī)接受任何 DHCP服務(wù)器發(fā)出的租約。 第 3章