๐ฅ️ Windows DHCP Server ๅฎๆดๆถ่จญๆๅ:่ง่ฒๅฎ่ฃ、Scopes ่จญๅฎ、็ง็จ็ฎก็ๅฐ PowerShell ่ชๅๅ
Windows DHCP(Dynamic Host Configuration Protocol)ๆฏไผๆฅญๅ ง้จๆๅธธ่ฆ็ๅบ็ค็ถฒ่ทฏๆๅไนไธ,ๆไพ่ชๅๅ้ IP、Subnet Mask、Gateway、DNS ็ญ็ถฒ่ทฏๅๆธ。 ๆฌๆๆด็ไธๅฅไผๆฅญ็ดๅฎๆดๆต็จ:่ง่ฒๅฎ่ฃ、Scopes ๅปบ็ฝฎ、Reservations、Options、ๆๆฌ(Authorized),ๆๅพๅฐไฝฟ็จ PowerShell ้ฒ่ก่ชๅๅๆน้้จ็ฝฒ。
ไธ、DHCP Server ๆถๆง่้ไฝๆต็จ
DHCP Server ็ๅบๆฌๆต็จๅ ๅซ:
- Client → DHCPDISCOVER(ๅฐๆพไผบๆๅจ)
- Server → DHCPOFFER(ๆๅบๅฏ็ง็จ IP)
- Client → DHCPREQUEST(่ฆๆฑไฝฟ็จ่ฉฒ IP)
- Server → DHCPACK(็ขบ่ช็ง็จ)
Windows DHCP ้็ญๅพ AD ๆๆฌ(Authorized)ๅพๆ่ฝๆๅ็ถฒๅๅ ง็ Client,้ฟๅ Rogue DHCP ๅบ็พ。
ไบ、ๅฎ่ฃ DHCP Server(GUI)
- ้ๅ Server Manager → Add Roles and Features
- ้ธๆ「DHCP Server」
- ๅฎๆๅฎ่ฃๅพๆ「Complete DHCP Configuration」
- ้ธๆ่ฆๆๆฌ(Authorize)็ Domain Account
ไธ、ไฝฟ็จ PowerShell ๅฎ่ฃ DHCP Server(ๆจ่ฆ)
# ๅฎ่ฃ DHCP Server
Install-WindowsFeature -Name 'DHCP' -IncludeManagementTools
# ๅจ็ถฒๅไธญๆๆฌ DHCP ๆๅ
Add-DhcpServerInDC -DnsName "DHCP01.domain.local" -IpAddress "10.0.0.10"
ๅ、ๅปบ็ซ IPv4 Scope(GUI)
- ้ๅ DHCP ็ฎก็ๅทฅๅ ท dhcpmgmt.msc
- ๅณ้ต IPv4 → New Scope
- ๅกซๅฏซๅ็จฑ(ไพๅฆ:Office-10.0.10.x)
- ่จญๅฎ Start / End IP(ไพ:10.0.10.50–10.0.10.200)
- Subnet Mask:255.255.255.0
- ๆฐๅข Gateways、DNS、Router、Option 003/006
ไบ、ไฝฟ็จ PowerShell ๅปบ็ซ Scope(่ชๅๅ)
# ๅปบ็ซ Scope
Add-DhcpServerv4Scope -Name "Office-Network" -StartRange 10.0.10.50 `
-EndRange 10.0.10.200 -SubnetMask 255.255.255.0 -State Active
# ่จญๅฎ Gateway
Set-DhcpServerv4OptionValue -ScopeId 10.0.10.0 -Router 10.0.10.1
# ่จญๅฎ DNS
Set-DhcpServerv4OptionValue -ScopeId 10.0.10.0 -DnsServer 10.0.10.5,10.0.10.6
ๅ ญ、Reservations(ไปฅ MAC ็ถๅฎๅบๅฎ IP)
ไผๆฅญๅธธไฝฟ็จ Reservation ็ถๅฎไผบๆๅจ、IPCam、Printer、POS ็ญ่จญๅ。
Add-DhcpServerv4Reservation `
-ScopeId 10.0.10.0 `
-IPAddress 10.0.10.99 `
-ClientId "00-11-22-33-44-55" `
-Description "Storage Server"
ไธ、DHCP Options ๅฎๆด้ ็ฝฎ(003、006、015、066 ็ญ)
| Option | ๅ่ฝ |
|---|---|
| 003 | Default Gateway |
| 006 | DNS Server |
| 015 | DNS Domain Name |
| 066 | TFTP Server(PXE Boot ็จ) |
| 067 | PXE Loader ๆชๆก(ไพๅฆ wdsmgfw.efi) |
ไฝฟ็จ PowerShell ่จญๅฎ DHCP Options
# ่จญๅฎๆๆ Scope ๅ
ฑไบซ็ๅ
จๅ Options
Set-DhcpServerv4OptionValue -DnsDomain "domain.local"
# ่จญๅฎๅๅฅ Scope ็ Options
Set-DhcpServerv4OptionValue -ScopeId 10.0.10.0 -Router 10.0.10.1
ๅ ซ、DHCP ็ง็จ็ฎก็(ๆฅ่ฉข / ้ๆพ / ๅช้ค)
ๆฅ่ฉขๆๆ็ง็จ(Active Leases)
Get-DhcpServerv4Lease -ScopeId 10.0.10.0
้ๆพๆๅฎ็ง็จ
Remove-DhcpServerv4Lease -ScopeId 10.0.10.0 -IPAddress 10.0.10.88
ไน、DHCP Failover ้ซๅฏ็จ(2 ๅฐ DHCP HA)
ๅ ฉๅฐ DHCP Server ๅฏ็ตๆ:Load Balance ๆ Hot Standby。
Add-DhcpServerv4Failover `
-Name "DHCP-HA" `
-PartnerServer "DHCP02.domain.local" `
-ScopeId 10.0.10.0 `
-LoadBalancePercent 50
ๅ、ๅฏๅบ/ๅฏๅ ฅ DHCP ่จญๅฎ(ไผบๆๅจ็งป่ฝๅฟ ๅ)
ๅฏๅบ DHCP ่จญๅฎ
Export-DhcpServer -ComputerName DHCP01 -File "C:\dhcp-backup.xml"
ๅฏๅ ฅๅฐๆฐไผบๆๅจ
Import-DhcpServer -ComputerName DHCP02 -File "C:\dhcp-backup.xml" -BackupPath "C:\Backup" -Leases
๐ ็ต่ช
DHCP ๆฏไผๆฅญๅ ง็ถฒๆๅบ็คๅปๆ้่ฆ็่ชๅๅๆๅไนไธ。้้ GUI ๆนๅผ่ฝๅฟซ้ๅฎๆไธ่ฌๅปบ็ฝฎ,่ PowerShell ๅๆไพๅฏ้่ค、ๅฏ็งป่ฝ、ๅฏๅไปฝ็ไผๆฅญ่ชๅๅ้จ็ฝฒๆต็จ。 ็ก่ซๆฏไธ่ฌไฝฟ็จ、่ทจ VLAN ็ฎก็、ๆ HA ้ซๅฏ็จๆถๆง,้ฝ่ฝ้้ๆฌๆๆนๆณๅฎๆดๅปบ็ฝฎ่็ฎก็。
๐ ๅปถไผธ้ฑ่ฎ
- Windows Update ๆทฑๅบฆ่งฃๆ:USOClient、WAAS、WSUS ่ก็บๅทฎ็ฐ
- WSUS Client ๅผทๅถๅๅ ฑๆๅทง(COM+SYSTEM+PsExec)
- Windows PE ๅฎๆดๆๅ(ๆถๆง็ฏ)
— WWFandy・Windows Server ้จ็ฝฒ็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ