sudo apt update && sudo apt upgrade isc-dhcp-server)。chmod 640 /etc/dhcp/dhcpd.conf; chown root:dhcpd /etc/dhcp/dhcpd.conf;chmod 640 /var/lib/dhcp/dhcpd.leases; chown dhcpd:dhcpd /var/lib/dhcp/dhcpd.leases。INTERFACESv4="eth0";在 RHEL/CentOS 可设置 DHCPDARGS=eth0。authoritative;。dhcpd.conf 加入 option log-facility local7;,并在 rsyslog 配置 local7.* /var/log/dhcpd.log,便于审计与取证。ping-check on; ping-timeout 2;,降低地址冲突与误配置风险。default-lease-time 与 max-lease-time,例如 default-lease-time 600; max-lease-time 7200;(高安全/访客网段可适当缩短)。host 声明绑定 MAC–IP,既便于访问控制,也减少地址欺骗空间。authoritative;
option log-facility local7;
subnet 192.168.1.0 netmask 255.255.255.0 {
range 192.168.1.100 192.168.1.200;
option routers 192.168.1.1;
option subnet-mask 255.255.255.0;
option domain-name-servers 8.8.8.8, 8.8.4.4;
default-lease-time 600;
max-lease-time 7200;
ping-check on;
ping-timeout 2;
# 关键主机静态绑定(示例)
host important-client {
hardware ethernet 00:1a:2b:3c:4d:5e;
fixed-address 192.168.1.100;
}
}
local7.* /var/log/dhcpd.log 并重启日志服务,确保 DHCP 事件完整落盘。