|
With the development of the Internet , almost everyone has to use network resources needs, but the premise is to obtain an IP address. In a small LAN, you can use manual configuration for the network address or host configuration parameters , but due to the popularity of portable computers , Internet users have a lot of dynamic, static configuration approach is no longer applicable , the Dynamic Host Configuration Protocol (Dynamic Host Configuration Protocol, DHCP) appears to solve this problem, it can be more rational and efficient allocation of network resources , network users to adapt to the growing and increasingly complex network environment. Papers from the basic concept of the DHCP protocol and a DHCP security issues , this paper introduces the basic principles of the DHCP and eliminate security threats to network security technology used for the realization of security DHCPv4 relay has laid a theoretical foundation. Then analyzes the DHCP system functions to be achieved , the use of top-down , layer by layer decomposition approach to design , gives the DHCP system and external relationships between modules , and the DHCP system for modular decomposition , based on this proposed one kind DHCPv4 relay security implementations , including packet parsing solutions , option 82 of the treatment program , the safety relay program , focusing on the DHCPv4 relay user address entries management solutions and security entries solutions . Finally, the paper presents a system for the DHCPv4 relay test ideas , methods, and test networking analysis of problems encountered during testing , and gives a solution. Test results show that the DHCPv4 relay support request packets and response packets forwarding processing option 82 support , support for user address entries management, support configuration and display of relevant information , to shield illegal client's request , with a certain security, to achieve the desired goals, and to work with other vendors' equipment to work with a wide range of applications.
|