Linux DHCP服务器安全加固清单
一 基础加固
二 配置与访问控制
三 交换机与二层防护
四 监控审计与维护
五 快速配置示例
option log-facility local7;
default-lease-time 600;
max-lease-time 7200;
subnet 192.168.1.0 netmask 255.255.255.0 {
range 192.168.1.100 192.168.1.200;
option routers 192.168.1.1;
option subnet-mask 255.255.255.0;
option domain-name-servers 8.8.8.8, 8.8.4.4;
ping-check on;
ping-timeout 2;
host important-client {
hardware ethernet 00:1a:2b:3c:4d:5e;
fixed-address 192.168.1.100;
}
}