DHCPv6 ç»å ´
IPv6 ã¢ãã¬ã¹ã®èªåå²ãå½ã¦ã¯ã
- RA ã«ãã stateless
- DHCPv6 ã«ãã statesful
ã®ï¼ã¤ãããã®ã¯ãIPv6 ã®è§£èª¬ã«ã¯å¿ ãç»å ´ããæåãªè©±ã§ããã§ãDHCPv6 ã使ã£ã¦ stateful 㪠IPv6 ã¢ãã¬ã¹ã®å²ãå½ã¦ãããå ´åãRA ã® M ãã©ã°ã¨ O ãã©ã°ãè¨å®ããäºããæ§ã ãªè§£èª¬ã§ç»å ´ãã¾ããã¡ãªã¿ã« M ãã©ã°ãO ãã©ã°ã®ããããã®æå³ã¯ã
- M ãã©ã°
- Management ã® M ã§ãã¢ãã¬ã¹ã管çï¼Managementï¼ããäºãæå³ããã
- O ãã©ã°
- Other ã® O ã§ãã¢ãã¬ã¹ä»¥å¤ã®æ å ±ï¼DNS ãµã¼ãã®ã¢ãã¬ã¹çï¼ãæä¾ããäºãæå³ããã
ã§ãå®éã«ã¢ãã¬ã¹ã管çããããã¢ãã¬ã¹ä»¥å¤ã®æ å ±ãæä¾ããã®ã DHCPv6 ãµã¼ããã¨ããäºã«ãªãã¾ããRA ãåä¿¡ãããã¹ãã¯ãåä¿¡ãã RA ã®æ å ±ã§ M ãã©ã°ã on ã«ãªã£ã¦ããããDHCPv6 ãµã¼ãããã¢ãã¬ã¹ã®å²ãå½ã¦ãåãããO ãã©ã°ã on ã ã£ãããDHCPv6 ãã DNS ãµã¼ãã®ã¢ãã¬ã¹çãåå¾ãããã¨ããæåããããã¨ã«ãªãã¾ã*1ã
ã§ããã®ã¨ãã«ãµã¨æ°ã«ãªã£ãã®ã¯ã前回ã®æ®µéã§ã¯ãã«ã¼ã¿ã® RA ã«ã°ãã¼ãã«ãªã¢ãã¬ã¹ã®ãã¬ãã£ãã¯ã¹ã¨ ULA ã®ãã¬ãã£ãã¯ã¹ãåºåããæ§ã«è¨å®ãã¦ãã¾ãããåé¡ã«ãªã£ãã®ã¯ã
- ã°ãã¼ãã«ãªã¢ãã¬ã¹ã¯ä¸æã¢ãã¬ã¹ã使ãã
- ULA ã¯ä¸æã¢ãã¬ã¹ã使ããªãã
ã¨ãï¼ã¤ã®ãã¬ãã£ãã¯ã¹ã§éãããªã·ã¼ã§ã¢ãã¬ã¹ãå²ãå½ã¦ãããã¨ãããã¨ã§ãããã§ãã°ãã¼ãã«ãªã¢ãã¬ã¹ã¯ä»ã¾ã§éãã§ãããULA ã®ãã¬ãã£ãã¯ã¹ã ããDHCPv6 ã§ã³ã³ããã¼ã«ã§ããªãããã¨ããçºæ³ã ã£ãã®ã§ãããã«ã¼ã¿ã®ããã¥ã¢ã«ãã©ãèªãã§ããå ã® M ãã©ã°ãO ãã©ã°ããã¬ãã£ãã¯ã¹æ¯ã«è¨å®ã§ãã¾ããã
å®éã«ãRA ã®ãã±ããããã£ããã£ãã¦ã¿ãã¨ãä¸ã¤ã® RA ã®ä¸ã«ï¼ã¤ã®ãã¬ãã£ãã¯ã¹æ å ±ããããM ãã©ã°ãO ãã©ã°ã¯ããã®ãã¬ãã£ãã¯ã¹æ å ±ã®å¤å´ã«ããã®ã§ãRA ã®ä»æ§ã¨ãã¦ããã¬ãã£ãã¯ã¹æ¯ã«ãããã®ãã©ã°ã使ãåããäºãã§ããªããã¨ãåããã¾ããã
ã§ããããããªãã®ã§ã
- M ãã©ã°ãO ãã©ã°ã on ã«ããã
- ã ãã©ãåºåããï¼ã¤ã®ãã¬ãã£ãã¯ã¹ã®ãã¡ãDHCPv6 ãµã¼ããæä¾ãã¦ããã®ã¯çæ¹ï¼å½ç¶ãULA ã®ãã¬ãã£ãã¯ã¹ï¼ã
- çµæãULA ã®æ¹ã¯ DHCPv6 ããå²ãå½ã¦ããããã©ãã°ãã¼ãã«ãªæ¹ã¯ã仿¹ãªããèªåæ§æã¢ãã¬ã¹ã«ãªãã
ã¨ããæåãæå¾ ããããããã¾ããã
å®éã«è¨å®ãã¦ã¿ã
å®éã«ãM ãã©ã°ãO ãã©ã°ã on ã«ãã NVR500 ã®è¨å®ã¯ããããªæãã«ãªãã¾ã*2ã
ipv6 prefix 1 dhcp-prefix@lan2::/64 ipv6 prefix 2 fdfe:dcba:9876:5432::/64 ipv6 lan1 address dhcp-prefix@lan2::1/64 ipv6 lan1 address fdfe:dcba:9876:5432::1/64 ipv6 lan1 rtadv send 1 2 m_flag=on o_flag=on
ååã¨ã®éãã¯ãm_flag=on o_flag=onããä»ãã¦ããé¨åã§ãã
DHCPv6 ãµã¼ãã®æ¹ã¯ãããã¡ãµã¼ãã® CentOS ã§åããã¾ããã/etc/dhcp/dhcpd6.conf ã®ä¸»ãªå 容ã¯ä¸è¨ã®éãã§ãã
# T2, the delay before Rebind (if Renews failed) # (default is 3/4 preferred lifetime) # (set to 2 hours) option dhcp-rebinding-time 7200; # Enable RFC 5007 support (same than for DHCPv4) allow leasequery; # Global definitions for name server address(es) and domain search list option dhcp6.name-servers fdfe:dcba:9876:5432::35; option dhcp6.domain-search "july.example.com"; # Set preference to 255 (maximum) in order to avoid waiting for # additional servers when there is only one ##option dhcp6.preference 255; # Server side command to enable rapid-commit (2 packet exchange) ##option dhcp6.rapid-commit; # The delay before information-request refresh # (minimum is 10 minutes, maximum one day, default is to not refresh) # (set to 6 hours) option dhcp6.info-refresh-time 21600; # The path of the lease file dhcpv6-lease-file-name "/var/lib/dhcpd/dhcpd6.leases"; # The subnet where the server is attached # (i.e., the server has an address in this subnet) subnet6 fdfe:dcba:9876:5432::/64 { # Two addresses available to clients # (the third client should get NoAddrsAvail) range6 fdfe:dcba:9876:5432::1:1 fdfe:dcba:9876:5432::1:ffff; }
CentOS Ver 6.5 ã«å«ã¾ãã dhcp ããã±ã¼ã¸ã§ã¯ã/usr/share/doc/dhcp-4.1.1/dhcpd6.conf.sample ã¨ãããµã³ãã«ãã¡ã¤ã«*3ãããã®ã§ããããåèã«ã㦠/etc/dhcp/dhcpd6.conf ã使ãã¾ããã
ãã¤ã³ãã«ãªãã®ã¯ãã¾ãã
- option dhcp6.name-servers
- option dhcp6.domain-search
ã§ãããã§ DHCPv6 ã§æ¸¡ã DNS ãµã¼ãã¨ãã¡ã¤ã³åãå®ç¾©ãã¦ãã¾ããRA ã§ O ãã©ã°ã on ã«ããæã«ãã¯ã©ã¤ã¢ã³ãã«æ¸¡ãããæ å ±ã§ãã
ãã¨ã¯ã
- subnet6 fdfe:dcba:9876:5432::/64 { ã
ã®é¨åã§ãããã§ãDHCPv6 ã§å²ãå½ã¦ãã¢ãã¬ã¹ã®ç¯å²ãæå®ãã¾ããRA ã§ M ãã©ã° on ã«ãã¦ããã¨ãsubnet6 ã§æå®ããã¦ãããã¬ãã£ãã¯ã¹ã¨ RA ãåºåãããã¬ãã£ãã¯ã¹ã§ä¸è´ããç©ãããã°ãDHCPv6 ããã¢ãã¬ã¹ãå²ãå½ã¦ããããã¨ã«ãªãã¯ãã§ãã
çµæã¯ããã¨ä¸æ©
ãã®ç¶æ ã§ PC ãèµ·åããã¨ã
- ã°ãã¼ãã«ãªã¢ãã¬ã¹ã¯ãRA ã«ããèªåæ§æã¢ãã¬ã¹ã
- ULA ã®ã¢ãã¬ã¹ã¯ãDHCPv6 ãµã¼ããå²ãå½ã¦ãã¢ãã¬ã¹ã
ã¨ãªãäºã確èªã§ãã¾ãããã¨ããããäºå®å¤ã®äºãä¸ã¤ããã¾ããã
ã°ãã¼ãã«ãªã¢ãã¬ã¹ã«é¢ãã¦ã¯çã£ãã¨ãããRA ã ãã®æã¨ä½ãå¤ããããã¾ãããã¨ããããULA ã¯ã
- DHCPv6 ããå²ãå½ã¦ãããã¢ãã¬ã¹
- ULA ã®ãã¬ãã£ãã¯ã¹ãæã¤ä¸æã¢ãã¬ã¹
ã®ï¼ã¤ã®ã¢ãã¬ã¹ãå²ãå½ã¦ããã¾ãããååè¦ã¤ãã£ãåé¡ã¯ã
- 䏿ã¢ãã¬ã¹ã¯ããã¤ããã㯠DNS ã®å¯¾è±¡å¤
- ã½ã¼ã¹ã¢ãã¬ã¹ã¨ãã¦ä¸æã¢ãã¬ã¹ã使ãããã¨ãDNS ä¸ã«ã¯åå¨ããªããã¹ãããã®æ¥ç¶ã«ãªãã
- Windows ã§ Linux ã® Kerberos èªè¨¼ã使ã£ã¦ããã¨ãhost ããªã³ã·ãã«ã®åé¡ãããã®ã§ãããã§ã¯é½åãæªãã
ã¨ããåé¡ã§ããDHCPv6 ã使ã£ã¦ããULA ã®ä¸æã¢ãã¬ã¹ã使ãããã®ã§ããã°ãåé¡ã¯è§£æ±ºãã¾ããã
調ã¹ãã¨ãWindows ã§ããããããIPv6 ã®ä¸æã¢ãã¬ã¹ã使ããªããã¨ããæ¹æ³ãæ¨å¥¨ãã¦ããè¨äºãè¦ããã¾ãã
ä¸è¨ã® Technet ãã©ã¼ã©ã ã§ã®è©±ã¯ Windows 8 ã§ã®è©±ã§ãããWindows 7 ã 㨠netsh ã³ãã³ãã§è¨å®ã§ããããã§ãã
http://www.ipnet-lab.jp/post/2012/04/12/ipv6-ra-privacyaddress-disable.aspx
ããããããã ã¨ã°ãã¼ãã«ãªã¢ãã¬ã¹ã§ã䏿ã¢ãã¬ã¹ãä»ããªããªã£ã¦ãã¾ãã¾ãã
å ã® Technet ãã©ã¼ã©ã ã§ã®åçã«ã¯
Windows Vista / Windows Server 2008 以éã® OS ã¯ãã¹ãã¼ãã¬ã¹ RA ç°å¢ã«ç½®ãããã¨ãIPv6 ã¢ãã¬ã¹ãèªåæ§æãããã©ã«ã ON ã«ãªã£ã¦ãã¾ãã®ã§ãæåã§ IPv6 ã¢ãã¬ã¹ãè¨å®ãã¦ããRA ã§èªåæ§æããã IPv6 ã¢ãã¬ã¹ãä»ãã¦ãã¾ãã¾ãã
ã¨ããã¾ããDHCPv6 ã§ã¢ãã¬ã¹ãæãåºããããã¬ãã£ãã¯ã¹ã¯ stateful ã§ã¯ãªãã®ãï¼ ã¨æãã®ã§ãããå®éã«ã¯ä¸æã¢ãã¬ã¹ãä»ãã¦ãã¾ãã¾ãã
ããããã©ããããã®ã... ã¨ãããã¨ã§æ¬¡åã«ç¶ãã¾ãã
*1:O ãã©ã°ã ã on ã§ããã°ãã¢ãã¬ã¹èªä½ã¯ RA ã«å«ã¾ãããã¬ãã£ãã¯ã¹ããèªåæ§æã§ãDNS ãµã¼ãã®ã¢ãã¬ã¹ç㯠DHCPv6 ãµã¼ãããåãåããã¨ãããã¨ã«ãªãã¾ãããã®éï¼ã¢ãã¬ã¹ã¯ DHCPv6 ã ãã©ãDNS ãµã¼ãçã¯æåè¨å®ããã¨ããIPv4 ã¾ããï¼ã«ããã±ã¼ã¹ã¯ãã»ã¨ãã©ç¡ãããªã
*2:ååããå¼ãç¶ããULA ã®ãã¬ãã£ãã¯ã¹ã fdfe:dcba:9876:5432::/64 ã¨ãã¦ãã¾ã
*3:ãã®ãµã³ãã«ãã¡ã¤ã«ããããããISC ã®ãªãªã¸ãã«ããã±ã¼ã¸ã«å«ã¾ãã¦ããç©ããã®ã¾ã¾åé²ãããã®ã ã¨æãã¾ãããRHEL / CentOS ã§ SELinux ãæå¹ã«ãã¦ããå ´åãdhcpv6-lease-file-name ã®æå®ããµã³ãã«ãã夿´ããªãã¨ããªã¼ã¹ç¶æ ãåºåãããã¡ã¤ã«ã®æ¸ãè¾¼ã¿ã«å¤±æããã¯ãã§ãã/var/lib/dhcpd ã®ä¸ã«è¨å®ããã°ãSELinux æå¹ã§åé¡ããã¾ããã