附录:EVPN 多宿主交换矩阵中的 DHCP 中继示例
以下是在具有以下配置的 EVPN 多宿主虚拟网关交换矩阵中测试 DHCP 中继的实验室设计示例:
- 交换矩阵类型 = EVPN 多宿主。
- 配置叠加环路池 = 不适用(静态 IRB IP 地址用作网关 IP 地址)
- WAN 路由器集成 = 此测试时尚未执行。
- DHCP 服务器位置 = 通过虚拟服务块功能与交换矩阵集成。
- DHCP 服务器可访问性 = 分配给相同 VRF 的不同 VLAN 之间的交换矩阵内。
- 使用的第三方 DHCP 服务器 = 作为 VM 的 Microsoft Windows 2022 DHCP 服务器。
添加附加服务器交换机只是因为在虚拟机中安装 Microsoft Windows 2022 时,LACP 捆绑不可用于“团队”接口。因此,这是在这两个世界之间进行翻译的更好选择。

为了简而言之,下面显示的配置示例仅显示与 DHCP 中继集成相关的配置。完整的工作流程可以从已经发布的可用 JVD 和扩展中推断出来。
您可以通过导入下面的 JSON 来重复使用我们提供的交换机模板,以加快此配置的进度:
{
"ntp_servers": [],
"dns_servers": [
"8.8.8.8",
"9.9.9.9"
],
"dns_suffix": [],
"additional_config_cmds": [],
"networks": {
"vlan1099": {
"vlan_id": 1099,
"subnet": "10.99.99.0/24"
},
"vlan1091": {
"vlan_id": "1091",
"subnet": "10.91.91.0/24",
"subnet6": ""
}
},
"port_usages": {
"vlan1099": {
"mode": "access",
"disabled": false,
"port_network": "vlan1099",
"voip_network": null,
"stp_edge": false,
"all_networks": false,
"networks": null,
"port_auth": null,
"speed": "auto",
"duplex": "auto",
"mac_limit": 0,
"persist_mac": false,
"poe_disabled": false,
"enable_qos": false,
"storm_control": {},
"mtu": 9014,
"description": "",
"disable_autoneg": false
},
"vlan1091": {
"disabled": false,
"mode": "access",
"port_network": "vlan1091",
"voip_network": null,
"stp_edge": false,
"stp_p2p": false,
"stp_no_root_port": false,
"mac_auth_protocol": null,
"all_networks": false,
"networks": null,
"port_auth": null,
"allow_multiple_supplicants": null,
"enable_mac_auth": null,
"mac_auth_only": null,
"guest_network": null,
"bypass_auth_when_server_down": null,
"dynamic_vlan_networks": null,
"speed": "auto",
"duplex": "auto",
"mac_limit": 0,
"persist_mac": false,
"poe_disabled": false,
"enable_qos": false,
"storm_control": {},
"mtu": 9014,
"description": "",
"disable_autoneg": false
},
"dynamic": {
"mode": "dynamic",
"reset_default_when": "link_down",
"rules": []
}
},
"switch_matching": {
"enable": true,
"rules": [
{
"name": "core",
"port_config": {
"ge-0/0/5": {
"usage": "vlan1091",
"dynamic_usage": null,
"critical": false,
"description": "",
"no_local_overwrite": true,
"aggregated": true,
"ae_disable_lacp": false,
"ae_lacp_force_up": false,
"ae_lacp_slow": false,
"ae_idx": 1,
"esilag": true
}
},
"additional_config_cmds": [
"set groups top routing-instances customera forwarding-options dhcp-relay forward-only",
"set groups top routing-instances customera forwarding-options dhcp-relay group vlan1099 relay-option-82 circuit-id vlan-id-only",
"set groups top routing-instances customera forwarding-options dhcp-relay group vlan1099 relay-option-82 server-id-override",
"",
""
],
"oob_ip_config": {
"type": "dhcp",
"use_mgmt_vrf": false
},
"ip_config": {
"type": "dhcp",
"network": "default"
},
"port_mirroring": {},
"match_name[0:4]": "core"
}
]
},
"switch_mgmt": {
"config_revert_timer": 10,
"root_password": "juniper123",
"protect_re": {
"enabled": false
},
"tacacs": {
"enabled": false
}
},
"radius_config": {
"auth_servers": [],
"acct_servers": [],
"auth_servers_timeout": 5,
"auth_servers_retries": 3,
"fast_dot1x_timers": false,
"acct_interim_interval": 0,
"auth_server_selection": "ordered",
"coa_enabled": false,
"coa_port": ""
},
"vrf_config": {
"enabled": false
},
"remote_syslog": {
"enabled": false
},
"snmp_config": {
"enabled": false
},
"dhcp_snooping": {
"enabled": false
},
"acl_policies": [],
"mist_nac": {
"enabled": true,
"network": null
},
"disabled_system_defined_port_usages": [],
"bgp_config": null,
"routing_policies": {},
"port_mirroring": {},
"name": "DHCPLab1"
}
园区交换矩阵对话配置
在园区交换矩阵对话配置中,配置非常重要:
- 正确的交换矩阵类型 = EVPN 多宿主
- 虚拟网关 v4 MAC 地址 = 已启用(这使得调试更容易,因为并非所有 VLAN 都使用全局 MAC 地址)。

在下一个窗格中将交换机分配为折叠核心和接入交换机。
然后,在“网络”交换矩阵对话框中,从交换机模板导入两个 VLAN。
- 第一个 VLAN(需要租赁的桌面客户端将在这里):
- 名称 = vlan1099
- VLAN ID = 1099
- IPv4 子网 = 10.99.99.0/24
- IPv4 虚拟网关 = 10.99.99.1
- 第二个 VLAN(您的 DHCP 服务器将在这里):
- 名称 = vlan1091
- VLAN ID = 1091
- IPv4 子网 = 10.91.91.0/24
- IPv4 虚拟网关 = 10.91.91.1
然后,将它们添加到单个 VRF:
- VRF 配置 = 启用
- VRF:
- 姓名 = customera
- 网络 = vlan1099 和 vlan1091
查看示例:

还要添加 DHCP 中继信息:
- DHCP 中继 = 启用
- VLAN 1099:
- 网络 = vlan1099
- DHCP 服务器 = 10.91.91.42


确保始终使用此对话框在所有园区交换矩阵设计中配置 DHCP 中继。
完成剩余的对话,以便瞻博网络 Mist 云推送配置以设置交换矩阵。
接入交换机配置
我们的 Desktop1 客户端通过以下端口配置连接到 Access1 交换机上的 ge-0/0/3 接口:

根据此配置,瞻博网络 Mist 云会在此交换矩阵中 VRF 所在的两台塌缩核心层交换机上配置以下 Junos OS 配置。
set groups top routing-instances customera instance-type vrf
set groups top routing-instances customera interface irb.1091
set groups top routing-instances customera interface irb.1099
set groups top routing-instances customera forwarding-options dhcp-relay server-group vlan1099 10.91.91.42
set groups top routing-instances customera forwarding-options dhcp-relay group vlan1099 interface irb.1099
set groups top routing-instances customera forwarding-options dhcp-relay group vlan1099 active-server-group vlan1099
set groups top routing-instances customera route-distinguisher 172.16.254.1:101
set groups top routing-instances customera vrf-target target:65000:101
set groups top routing-instances customera vrf-table-label
set groups top routing-instances customera routing-options auto-export
创建本文档时,并未创建解决方案架构章节中介绍的 Junos OS 中的所有选项。因此,我们在每台塌缩核心层交换机上手动添加了以下附加 Junos OS 配置,以便在测试的各种 DHCP 服务器上获得最佳体验。

set groups top routing-instances customera forwarding-options dhcp-relay forward-only set groups top routing-instances customera forwarding-options dhcp-relay group vlan1099 relay-option-82 circuit-id vlan-id-only set groups top routing-instances customera forwarding-options dhcp-relay group vlan1099 relay-option-82 server-id-override
DHCP 服务器集成
我们决定在交换矩阵和 DHCP 服务器(虚拟机)之间放置一个交换机。当服务器是虚拟机时,Microsoft Windows 不支持使用 LACP。但是,我们在交换矩阵端执行此操作,因此我们使用交换机作为一种转换元素。另一个优点是,对于 VM,我们有一个包含所有消息的单个接口,这使得调试更容易。
在两台塌缩核心层交换机上,您可以配置:
- 端口 ID = ge-0/0/5
- 配置文件 = vlan1091
- 端口聚合 = 启用
- AE 指数 = 1
- ESI-LAG = 启用

在交换矩阵和 DHCP 服务器之间的交换机上,添加一个简单的 LAG 配置,如下所示:
- 端口 ID = ge-0/0/1-2
- 接口 = L2 接口
- 配置文件 = vlan1091
- 端口聚合 = 启用
- LACP = 已启用
- LACP 强制上行 = 禁用
- LACP 周期性减慢 = 已禁用
- AE 指数 = 1

然后,通往 DHCP 服务器的单个接口:
- 端口 ID = ge-0/0/0
- 接口 = L2 接口
- 配置文件 = vlan1091

检查 DHCP 服务器本身
我们假设您已安装 Microsoft Windows 2022 Server 版本,并应用了上一章中的配置示例 附录:用于测试的 Microsoft DHCP 服务器配置示例。完成此操作后,您需要检查与交换矩阵的连接,以确保服务器收到中继消息。在我们的例子中,服务器有多个用于引导它的接口:
PS C:\Users\Administrator> ipconfig
Windows IP Configuration
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::7d5a:47ae:2892:3d88%5
IPv4 Address. . . . . . . . . . . : 192.168.10.200
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
Ethernet adapter Ethernet 2:
Connection-specific DNS Suffix . :
IPv4 Address. . . . . . . . . . . : 10.91.91.42
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.91.91.1
# ping the VGA of this subnet
PS C:\Users\Administrator> ping 10.91.91.1
Pinging 10.91.91.1 with 32 bytes of data:
Reply from 10.91.91.1: bytes=32 time=1ms TTL=64
Reply from 10.91.91.1: bytes=32 time=1ms TTL=64
Reply from 10.91.91.1: bytes=32 time=1ms TTL=64
Reply from 10.91.91.1: bytes=32 time=1ms TTL=64
Ping statistics for 10.91.91.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 1ms, Average = 1ms
# ping desktop1 client who should have a static IP-Address now
PS C:\Users\Administrator> ping 10.99.99.99
Pinging 10.99.99.99 with 32 bytes of data:
Reply from 10.99.99.99: bytes=32 time=2ms TTL=63
Reply from 10.99.99.99: bytes=32 time=2ms TTL=63
Reply from 10.99.99.99: bytes=32 time=2ms TTL=63
Reply from 10.99.99.99: bytes=32 time=1ms TTL=63
Ping statistics for 10.99.99.99:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms
验证服务器是否正在侦听 IP 地址 10.91.91.42:

使用有线客户端进行最终测试
要完成安装,请使用有线客户端执行最终测试。我们客户端的初始状态是分配了一个静态 IP 地址,可以与互联网通信:
root@desktop1:~# ifconfig ens5
ens5: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 10.99.99.99 netmask 255.255.255.0 broadcast 10.99.99.255
inet6 fe80::5054:ff:feae:1e5b prefixlen 64 scopeid 0x20<link>
ether 52:54:00:ae:1e:5b txqueuelen 1000 (Ethernet)
RX packets 142 bytes 10653 (10.6 KB)
RX errors 0 dropped 51 overruns 0 frame 0
TX packets 158 bytes 14096 (14.0 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
# do ping the VGA shared GW IP
root@desktop1:~# ping -c3 10.99.99.1
PING 10.99.99.1 (10.99.99.1) 56(84) bytes of data.
64 bytes from 10.99.99.1: icmp_seq=1 ttl=64 time=0.785 ms
64 bytes from 10.99.99.1: icmp_seq=2 ttl=64 time=1.03 ms
64 bytes from 10.99.99.1: icmp_seq=3 ttl=64 time=1.19 ms
--- 10.99.99.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 0.785/1.003/1.193/0.167 ms
# we ping the static IP of the one collapsed core switch
root@desktop1:~# ping -c3 10.99.99.2
PING 10.99.99.2 (10.99.99.2) 56(84) bytes of data.
64 bytes from 10.99.99.2: icmp_seq=1 ttl=64 time=0.766 ms
64 bytes from 10.99.99.2: icmp_seq=2 ttl=64 time=0.959 ms
64 bytes from 10.99.99.2: icmp_seq=3 ttl=64 time=0.824 ms
--- 10.99.99.2 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 0.766/0.849/0.959/0.080 ms
# we ping the static IP of the other collapsed core switch
root@desktop1:~# ping -c3 10.99.99.3
PING 10.99.99.3 (10.99.99.3) 56(84) bytes of data.
64 bytes from 10.99.99.3: icmp_seq=1 ttl=64 time=2.91 ms
64 bytes from 10.99.99.3: icmp_seq=2 ttl=64 time=1.35 ms
64 bytes from 10.99.99.3: icmp_seq=3 ttl=64 time=1.43 ms
--- 10.99.99.3 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2004ms
rtt min/avg/max/mdev = 1.354/1.897/2.912/0.718 ms
# we review the ARP-cache for the 3 MAC-Addresses
root@desktop1:~# arp -an
? (10.99.99.3) at 2c:6b:f5:f8:9b:f0 [ether] on ens5
? (10.99.99.2) at 2c:6b:f5:ac:da:f0 [ether] on ens5
? (10.99.99.1) at 00:00:5e:e4:04:4b [ether] on ens5
# we try to test connectivity towards DHCP server
# Server must allow ICMP Ping which is not a default
root@desktop1:~# ping -c3 10.91.91.42
PING 10.91.91.42 (10.91.91.42) 56(84) bytes of data.
64 bytes from 10.91.91.42: icmp_seq=1 ttl=127 time=2.35 ms
64 bytes from 10.91.91.42: icmp_seq=2 ttl=127 time=2.32 ms
64 bytes from 10.91.91.42: icmp_seq=3 ttl=127 time=2.51 ms
--- 10.91.91.42 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 2.322/2.392/2.506/0.081 ms
我们可以在瞻博网络 Mist 门户的有线客户端概述中查看该客户端及其 IP 地址:

接下来,我们取消配置静态 IP 地址,并尝试获取 DHCP 租约。以下附加配置可确保客户端丢失静态配置和 DHCP 租约的任何先前知识。然后,我们在前台启动 DHCP 客户端以查看更多调试消息:
root@desktop1:~# ifconfig ens5 0.0.0.0 up root@desktop1:~# pkill dhclient root@desktop1:~# rm -f /var/lib/dhcp/*.leases root@desktop1:~# dhclient -v ens5 Internet Systems Consortium DHCP Client 4.4.1 Copyright 2004-2018 Internet Systems Consortium. All rights reserved. For info, please visit https://www.isc.org/software/dhcp/ Listening on LPF/ens5/52:54:00:ae:1e:5b Sending on LPF/ens5/52:54:00:ae:1e:5b Sending on Socket/fallback DHCPDISCOVER on ens5 to 255.255.255.255 port 67 interval 3 (xid=0x8599fa19) DHCPOFFER of 10.99.99.63 from 10.99.99.3 DHCPREQUEST for 10.99.99.63 on ens5 to 255.255.255.255 port 67 (xid=0x19fa9985) DHCPACK of 10.99.99.63 from 10.99.99.3 (xid=0x8599fa19) bound to 10.99.99.63 -- renewal in 304223 seconds.
一段时间后(取决于本地 ARP 老化),此更改将显示在有线客户端概述中:

打开 DHCP 管理器时,您还可以在 DHCP 服务器上查看租约讲义,如下所示:

下面是我们的客户端现在出现在 DHCP 服务器租约数据库中的示例:

DHCP 租约讲义的示例跟踪
下面是 DHCP 租约讲义的完整序列,其中查看始发有线客户端和 DHCP 服务器端从交换矩阵的中继代理获取转发的消息。这是通过 tcpdump 同时捕获的。
我们在客户端上启动跟踪,通过广播向交换矩阵中继代理发送发现消息:
10:14:30.770921 52:54:00:ae:1e:5b > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: (tos 0x10, ttl 128, id 0, offset 0, flags [none], proto UDP (17), length 328)
0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 52:54:00:ae:1e:5b, length 300, xid 0xb7d35449, Flags [none]
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Discover
Hostname Option 12, length 8: "desktop1"
Parameter-Request Option 55, length 13:
Subnet-Mask, BR, Time-Zone, Default-Gateway
Domain-Name, Domain-Name-Server, Option 119, Hostname
Netbios-Name-Server, Netbios-Scope, MTU, Classless-Static-Route
NTP
现在,我们查看到达DHCP服务器的中继消息,其中包含来自交换矩阵中继代理的嵌入式信息,如网关IP和选项82:
10:14:30.772605 2c:6b:f5:f8:9b:f0 > 52:54:00:73:46:1c, ethertype IPv4 (0x0800), length 394: (tos 0x0, ttl 64, id 19866, offset 0, flags [none], proto UDP (17), length 380)
10.99.99.3.67 > 10.91.91.42.67: BOOTP/DHCP, Request from 52:54:00:ae:1e:5b, length 352, xid 0xb7d35449, Flags [none]
Gateway-IP 10.99.99.3
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Discover
Hostname Option 12, length 8: "desktop1"
Parameter-Request Option 55, length 13:
Subnet-Mask, BR, Time-Zone, Default-Gateway
Domain-Name, Domain-Name-Server, Option 119, Hostname
Netbios-Name-Server, Netbios-Scope, MTU, Classless-Static-Route
NTP
Agent-Information Option 82, length 50:
Circuit-ID SubOption 1, length 4: 1099
Unknown SubOption 5, length 4:
0x0000: 0a63 6303
Unknown SubOption 11, length 4:
0x0000: 0a63 6303
Unknown SubOption 9, length 30:
0x0000: 0000 0a4c 1904 1749 5242 2d69 7262 2e31
0x0010: 3039 393a 7674 6570 2e33 3237 3639
DHCP 服务器响应交换矩阵中继代理,并提供给客户端的报价:
10:14:30.773018 52:54:00:73:46:1c > 00:00:5e:e4:04:43, ethertype IPv4 (0x0800), length 384: (tos 0x0, ttl 128, id 47992, offset 0, flags [none], proto UDP (17), length 370)
10.91.91.42.67 > 10.99.99.3.67: BOOTP/DHCP, Reply, length 342, xid 0xb7d35449, Flags [none]
Your-IP 10.99.99.63
Server-IP 10.91.91.42
Gateway-IP 10.99.99.3
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Offer
Subnet-Mask Option 1, length 4: 255.255.255.0
RN Option 58, length 4: 345600
RB Option 59, length 4: 604800
Lease-Time Option 51, length 4: 691200
Server-ID Option 54, length 4: 10.99.99.3
Default-Gateway Option 3, length 4: 10.99.99.1
Domain-Name-Server Option 6, length 8: 8.8.8.8,9.9.9.9
Agent-Information Option 82, length 50:
Circuit-ID SubOption 1, length 4: 1099
Unknown SubOption 5, length 4:
0x0000: 0a63 6303
Unknown SubOption 11, length 4:
0x0000: 0a63 6303
Unknown SubOption 9, length 30:
0x0000: 0000 0a4c 1904 1749 5242 2d69 7262 2e31
0x0010: 3039 393a 7674 6570 2e33 3237 3639
交换矩阵中继代理会过滤掉部分信息(如选项 82),并将产品/服务作为第 2 层单播转发给客户端:
10:14:30.774479 2c:6b:f5:f8:9b:f0 > 52:54:00:ae:1e:5b, ethertype IPv4 (0x0800), length 332: (tos 0x0, ttl 64, id 19869, offset 0, flags [none], proto UDP (17), length 318)
10.99.99.3.67 > 10.99.99.63.68: BOOTP/DHCP, Reply, length 290, xid 0xb7d35449, Flags [none]
Your-IP 10.99.99.63
Server-IP 10.91.91.42
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Offer
Subnet-Mask Option 1, length 4: 255.255.255.0
RN Option 58, length 4: 345600
RB Option 59, length 4: 604800
Lease-Time Option 51, length 4: 691200
Server-ID Option 54, length 4: 10.99.99.3
Default-Gateway Option 3, length 4: 10.99.99.1
Domain-Name-Server Option 6, length 8: 8.8.8.8,9.9.9.9
根据之前收到的报价,客户端现在通过广播向交换矩阵中继代理发送请求消息:
10:14:30.776566 52:54:00:ae:1e:5b > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: (tos 0x10, ttl 128, id 0, offset 0, flags [none], proto UDP (17), length 328)
0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 52:54:00:ae:1e:5b, length 300, xid 0xb7d35449, Flags [none]
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Request
Server-ID Option 54, length 4: 10.99.99.3
Requested-IP Option 50, length 4: 10.99.99.63
Hostname Option 12, length 8: "desktop1"
Parameter-Request Option 55, length 13:
Subnet-Mask, BR, Time-Zone, Default-Gateway
Domain-Name, Domain-Name-Server, Option 119, Hostname
Netbios-Name-Server, Netbios-Scope, MTU, Classless-Static-Route
NTP
现在,我们查看到达 DHCP 服务器的中继消息,其中包含来自交换矩阵中继代理的嵌入信息,如网关 IP 和选项 82,如之前转发的发现消息:
10:14:30.778142 2c:6b:f5:f8:9b:f0 > 52:54:00:73:46:1c, ethertype IPv4 (0x0800), length 394: (tos 0x0, ttl 64, id 19872, offset 0, flags [none], proto UDP (17), length 380)
10.99.99.3.67 > 10.91.91.42.67: BOOTP/DHCP, Request from 52:54:00:ae:1e:5b, length 352, xid 0xb7d35449, Flags [none]
Gateway-IP 10.99.99.3
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Request
Server-ID Option 54, length 4: 10.99.99.3
Requested-IP Option 50, length 4: 10.99.99.63
Hostname Option 12, length 8: "desktop1"
Parameter-Request Option 55, length 13:
Subnet-Mask, BR, Time-Zone, Default-Gateway
Domain-Name, Domain-Name-Server, Option 119, Hostname
Netbios-Name-Server, Netbios-Scope, MTU, Classless-Static-Route
NTP
Agent-Information Option 82, length 50:
Circuit-ID SubOption 1, length 4: 1099
Unknown SubOption 5, length 4:
0x0000: 0a63 6303
Unknown SubOption 11, length 4:
0x0000: 0a63 6303
Unknown SubOption 9, length 30:
0x0000: 0000 0a4c 1904 1749 5242 2d69 7262 2e31
0x0010: 3039 393a 7674 6570 2e33 3237 3639
DHCP 服务器响应时,会向交换矩阵中继代理发送租约确认:
10:14:30.778534 52:54:00:73:46:1c > 00:00:5e:e4:04:43, ethertype IPv4 (0x0800), length 384: (tos 0x0, ttl 128, id 47993, offset 0, flags [none], proto UDP (17), length 370)
10.91.91.42.67 > 10.99.99.3.67: BOOTP/DHCP, Reply, length 342, xid 0xb7d35449, Flags [none]
Your-IP 10.99.99.63
Gateway-IP 10.99.99.3
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: ACK
RN Option 58, length 4: 345600
RB Option 59, length 4: 604800
Lease-Time Option 51, length 4: 691200
Server-ID Option 54, length 4: 10.99.99.3
Subnet-Mask Option 1, length 4: 255.255.255.0
Default-Gateway Option 3, length 4: 10.99.99.1
Domain-Name-Server Option 6, length 8: 8.8.8.8,9.9.9.9
Agent-Information Option 82, length 50:
Circuit-ID SubOption 1, length 4: 1099
Unknown SubOption 5, length 4:
0x0000: 0a63 6303
Unknown SubOption 11, length 4:
0x0000: 0a63 6303
Unknown SubOption 9, length 30:
0x0000: 0000 0a4c 1904 1749 5242 2d69 7262 2e31
0x0010: 3039 393a 7674 6570 2e33 3237 3639
交换矩阵中继代理会过滤掉部分信息(如选项 82),并将租约确认作为第 2 层单播转发给客户端:
10:14:30.780034 2c:6b:f5:f8:9b:f0 > 52:54:00:ae:1e:5b, ethertype IPv4 (0x0800), length 332: (tos 0x0, ttl 64, id 19875, offset 0, flags [none], proto UDP (17), length 318)
10.99.99.3.67 > 10.99.99.63.68: BOOTP/DHCP, Reply, length 290, xid 0xb7d35449, Flags [none]
Your-IP 10.99.99.63
Client-Ethernet-Address 52:54:00:ae:1e:5b
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: ACK
RN Option 58, length 4: 345600
RB Option 59, length 4: 604800
Lease-Time Option 51, length 4: 691200
Server-ID Option 54, length 4: 10.99.99.3
Subnet-Mask Option 1, length 4: 255.255.255.0
Default-Gateway Option 3, length 4: 10.99.99.1
Domain-Name-Server Option 6, length 8: 8.8.8.8,9.9.9.9