¥Í¥Ã¥È¥ï¡¼¥¯¥¹¥Ú¥·¥ã¥ê¥¹¥È»î¸³¤Î²áµîÌä¡ÊH25ǯ½©NW¸á¸åµÌä2¡Ë¤Ç¤Ï¡¢°Ê²¼¤Îµ½Ò¤¬¤¢¤ë¡£
¥¹¥Ì¡¼¥Ô¥ó¥°¤È¤Ï¡¤¡Ö¤Î¤¾¤¸«¤¹¤ë¡×¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£¤Ä¤Þ¤ê¡¢DHCP¤Î¥Ñ¥±¥Ã¥È¤ò¤Î¤¾¤¸«¤·¡¢ÉÔÀµ¤ÊÄÌ¿®¤ò¥Ö¥í¥Ã¥¯¤·¤Þ¤¹¡£¶ñÂÎŪ¤Ë¡¢º£²ó¤ÎDHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤Îµ¡Ç½¤Ï°Ê²¼¤Ç¤¹¡£
Àµµ¬¤ÎDHCP¥µ¡¼¥Ð¤òÀܳ¤¹¤ë¥Ý¡¼¥È¤ò»ØÄꤹ¤ëµ¡Ç½
»ØÄꤷ¤¿¥Ý¡¼¥È°Ê³°¤ËDHCP¥µ¡¼¥Ð¤òÀܳ¤·¤Æ¤â¡¢DHCP¤Îʧ¤¤½Ð¤·¤ò¤µ¤»¤Þ¤»¤ó¡£¤â¤·¡¢»ØÄꤷ¤¿¥Ý¡¼¥È°Ê³°¤«¤éDHCP OFFER¤äDHCP ACK¤¬ÆÏ¤¤¤¿¤È¤·¤Æ¤â¡¢¤½¤Î¥Õ¥ì¡¼¥à¤òSW¤¬ÇË´þ¤·¤Þ¤¹¡£
Àµµ¬¤ÎDHCP¥µ¡¼¥Ð¤«¤éIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¤¿PC¤À¤±¤òÄÌ¿®¤µ¤»¤ëµ¡Ç½
DHCP¤Î¥Ñ¥±¥Ã¥È¤ò¥¹¥Ì¡¼¥Ô¥ó¥°¤·¡¢Àµµ¬¤ÎDHCP¤«¤éIP¥¢¥É¥ì¥¹¤òʧ¤¤½Ð¤µ¤ì¤¿PC¤À¤±¤òÄ̲ᤵ¤»¤Þ¤¹¡£PC¤ÎÆÃÄê¤ÏMAC¥¢¥É¥ì¥¹¤Ç¹Ô¤¤¤Þ¤¹¡£¤µ¤é¤Ë¤Ï¡¤ÍøÍѼԤ¬¾¡¼ê¤Ë¸ÇÄêIP¥¢¥É¥ì¥¹¤ò³äÅö¤Æ¤¿PC¤ÎÄÌ¿®¤âµñÈݤ·¤Þ¤¹¡£

Catalyst¤Ç¤ÎDHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤ÎÀßÄê¤ò¾Ò²ð¤·¤Þ¤¹¡£
¾¯¤·Ê䤷¤Þ¤¹¡£¡¤ÎÀßÄê¤Ï¡¢DHCP¥µ¡¼¥Ð¤òÀܳ¤¹¤ë24È֥ݡ¼¥È¤òtrust¡Ê¿®Íꤵ¤ì¤¿¡Ë¤È¤·¤ÆÀßÄꤷ¤Þ¤¹¡£¤³¤ÎÀßÄê¤ò¤·¤Ê¤¤¥Ý¡¼¥È¤Ïuntrust¡Ê¿®ÍѤµ¤ì¤Ê¤¤¡Ë¤È¤¤¤¦ÀßÄê¤Ë¤Ê¤ê¡¢DHCP¥µ¡¼¥Ð¤òÀܳ¤·¤Æ¤âDHCP¤Î¥Õ¥ì¡¼¥à¤¬ÇË´þ¤µ¤ì¤Þ¤¹¡£
¢¤ÎÀßÄê¤Ï¡¢DHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤ËIP Source Guard¤òÉղ䷤Ƥ¤¤Þ¤¹¡£1È֥ݡ¼¥È¤Ç¤Ï¡¢Àµµ¬¤ÎüËö°Ê³°¤«¤é¤ÎÄÌ¿®¤òµñÈݤ·¤Þ¤¹¡£¡Överify¡×¤È¤Ï¡ÖÀµ¤·¤¤¤«¤É¤¦¤«¤ò³Î¤«¤á¤ë¡×¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£
L2SWµÚ¤ÓSW¤¬¤â¤ÄDHCP¥¹¥Ì¡¼¥Ô¥ó¥°µ¡Ç½¤ò»ÈÍѤ¹¤ë¡£¤³¤Îµ¡Ç½¤Ë¤è¤Ã¤Æ¡¤L2SWµÚ¤ÓSW¤Ï¡¤Àµµ¬¤ÎDHCP¥µ¡¼¥Ð¤ÈüËö´Ö¤ÇÄÌ¿®¤µ¤ì¤ëDHCP¥á¥Ã¥»¡¼¥¸¤ò¡¤Ä̲᤹¤ë¥Ý¡¼¥È¤Î¾ì½ê¤ò´Þ¤á¤Æ´Æ»ë¤¹¤ë¡£¤µ¤é¤Ë¡¤Àµµ¬¤ÎDHCP¥µ¡¼¥Ð¤«¤éIP¥¢¥É¥ì¥¹¤ò³ä¤êÅö¤Æ¤é¤ì¤¿Ã¼Ëö¤À¤±¤¬ÄÌ¿®¤Ç¤¤ë¤è¤¦¤Ë¡¤¥Ý¡¼¥È¤Î¥Õ¥£¥ë¥¿¤ò¼«Æ°À©¸æ¤¹¤ë¡£ |
¥¹¥Ì¡¼¥Ô¥ó¥°¤È¤Ï¡¤¡Ö¤Î¤¾¤¸«¤¹¤ë¡×¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£¤Ä¤Þ¤ê¡¢DHCP¤Î¥Ñ¥±¥Ã¥È¤ò¤Î¤¾¤¸«¤·¡¢ÉÔÀµ¤ÊÄÌ¿®¤ò¥Ö¥í¥Ã¥¯¤·¤Þ¤¹¡£¶ñÂÎŪ¤Ë¡¢º£²ó¤ÎDHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤Îµ¡Ç½¤Ï°Ê²¼¤Ç¤¹¡£

»ØÄꤷ¤¿¥Ý¡¼¥È°Ê³°¤ËDHCP¥µ¡¼¥Ð¤òÀܳ¤·¤Æ¤â¡¢DHCP¤Îʧ¤¤½Ð¤·¤ò¤µ¤»¤Þ¤»¤ó¡£¤â¤·¡¢»ØÄꤷ¤¿¥Ý¡¼¥È°Ê³°¤«¤éDHCP OFFER¤äDHCP ACK¤¬ÆÏ¤¤¤¿¤È¤·¤Æ¤â¡¢¤½¤Î¥Õ¥ì¡¼¥à¤òSW¤¬ÇË´þ¤·¤Þ¤¹¡£

DHCP¤Î¥Ñ¥±¥Ã¥È¤ò¥¹¥Ì¡¼¥Ô¥ó¥°¤·¡¢Àµµ¬¤ÎDHCP¤«¤éIP¥¢¥É¥ì¥¹¤òʧ¤¤½Ð¤µ¤ì¤¿PC¤À¤±¤òÄ̲ᤵ¤»¤Þ¤¹¡£PC¤ÎÆÃÄê¤ÏMAC¥¢¥É¥ì¥¹¤Ç¹Ô¤¤¤Þ¤¹¡£¤µ¤é¤Ë¤Ï¡¤ÍøÍѼԤ¬¾¡¼ê¤Ë¸ÇÄêIP¥¢¥É¥ì¥¹¤ò³äÅö¤Æ¤¿PC¤ÎÄÌ¿®¤âµñÈݤ·¤Þ¤¹¡£

Catalyst¤Ç¤ÎDHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤ÎÀßÄê¤ò¾Ò²ð¤·¤Þ¤¹¡£
SW(config)# ip dhcp snooping ¡¡¢«DHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤ò͸ú²½ SW(config)# ip dhcp snooping vlan 10¡¡¢«DHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤ò͸ú¤Ë¤¹¤ëVLAN¤ò»ØÄê SW(config)# interface fastethernet0/24¡¡¢«¾åµ¡¤ÎÀßÄê SW(config-if)# ip dhcp snooping trust¡¡¡¡¢«¡¡¡¡¡· SW(config)# interface fastethernet0/1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¢«¾åµ¢¤ÎÀßÄê SW(config-if)# ip verify source port-security¡¡¡¡¡¡¢«¡¡¡¡¡¡¡¡¡· |
¢¤ÎÀßÄê¤Ï¡¢DHCP¥¹¥Ì¡¼¥Ô¥ó¥°¤ËIP Source Guard¤òÉղ䷤Ƥ¤¤Þ¤¹¡£1È֥ݡ¼¥È¤Ç¤Ï¡¢Àµµ¬¤ÎüËö°Ê³°¤«¤é¤ÎÄÌ¿®¤òµñÈݤ·¤Þ¤¹¡£¡Överify¡×¤È¤Ï¡ÖÀµ¤·¤¤¤«¤É¤¦¤«¤ò³Î¤«¤á¤ë¡×¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£
Copyright (C) 2011¡Á nw.seeeko.com ¥Í¥Ã¥È¥ï¡¼¥¯¥¹¥Ú¥·¥ã¥ê¥¹¥È - ¤»¡¼¤³¤Î¤Ä¤ë¤® -