2004-02-14 19:06:39 +01:00
|
|
|
<?xml version="1.0" encoding="UTF-8"?>
|
2008-07-07 22:22:09 +02:00
|
|
|
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.4//EN"
|
|
|
|
"http://www.oasis-open.org/docbook/xml/4.4/docbookx.dtd">
|
2004-02-14 19:06:39 +01:00
|
|
|
<article>
|
|
|
|
<!--$Id$-->
|
|
|
|
|
|
|
|
<articleinfo>
|
|
|
|
<title>DHCP</title>
|
|
|
|
|
|
|
|
<authorgroup>
|
|
|
|
<author>
|
|
|
|
<firstname>Tom</firstname>
|
|
|
|
|
|
|
|
<surname>Eastep</surname>
|
|
|
|
</author>
|
|
|
|
</authorgroup>
|
|
|
|
|
2006-07-07 03:04:16 +02:00
|
|
|
<pubdate><?dbtimestamp format="Y/m/d"?></pubdate>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<copyright>
|
|
|
|
<year>2001</year>
|
|
|
|
|
|
|
|
<year>2002</year>
|
|
|
|
|
|
|
|
<year>2004</year>
|
|
|
|
|
2005-11-29 22:19:48 +01:00
|
|
|
<year>2005</year>
|
|
|
|
|
2010-01-12 16:55:58 +01:00
|
|
|
<year>2010</year>
|
|
|
|
|
2004-02-14 19:06:39 +01:00
|
|
|
<holder>Thomas M. Eastep</holder>
|
|
|
|
</copyright>
|
|
|
|
|
|
|
|
<legalnotice>
|
|
|
|
<para>Permission is granted to copy, distribute and/or modify this
|
|
|
|
document under the terms of the GNU Free Documentation License, Version
|
|
|
|
1.2 or any later version published by the Free Software Foundation; with
|
|
|
|
no Invariant Sections, with no Front-Cover, and with no Back-Cover
|
|
|
|
Texts. A copy of the license is included in the section entitled
|
2005-10-22 19:37:38 +02:00
|
|
|
<quote><ulink url="GnuCopyright.htm">GNU Free Documentation
|
|
|
|
License</ulink></quote>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</legalnotice>
|
|
|
|
</articleinfo>
|
|
|
|
|
|
|
|
<note>
|
|
|
|
<para>For most operations, DHCP software interfaces to the Linux IP stack
|
|
|
|
at a level below Netfilter. Hence, Netfilter (and therefore Shorewall)
|
|
|
|
cannot be used effectively to police DHCP. The <quote>dhcp</quote>
|
|
|
|
interface option described in this article allows for Netfilter to stay
|
2005-10-22 19:37:38 +02:00
|
|
|
out of DHCP's way for those operations that can be controlled by Netfilter
|
|
|
|
and prevents unwanted logging of DHCP-related traffic by
|
2004-02-14 19:06:39 +01:00
|
|
|
Shorewall-generated Netfilter logging rules.</para>
|
|
|
|
</note>
|
|
|
|
|
2007-06-28 17:09:37 +02:00
|
|
|
<section id="Firewall">
|
2004-02-14 19:06:39 +01:00
|
|
|
<title>If you want to Run a DHCP Server on your firewall</title>
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
<listitem>
|
|
|
|
<para>Specify the <quote>dhcp</quote> option on each interface to be
|
|
|
|
served by your server in the <filename><ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html">/etc/shorewall/interfaces</ulink></filename>
|
2004-02-14 19:06:39 +01:00
|
|
|
file. This will generate rules that will allow DHCP to and from your
|
|
|
|
firewall system.</para>
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>When starting <quote>dhcpd</quote>, you need to list those
|
|
|
|
interfaces on the run line. On a RedHat system, this is done by
|
|
|
|
modifying <filename>/etc/sysconfig/dhcpd</filename>.</para>
|
|
|
|
</listitem>
|
2006-10-06 22:16:38 +02:00
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>If you set 'ping-check' true in your
|
2016-01-14 17:56:19 +01:00
|
|
|
<filename>/etc/dhcp/dhcpd.conf</filename> file then you will want to
|
|
|
|
<ulink url="ping.html">accept 'ping'</ulink> from your firewall to the
|
|
|
|
zone(s) served by the firewall's DHCP server.</para>
|
2006-10-06 22:16:38 +02:00
|
|
|
</listitem>
|
2004-02-14 19:06:39 +01:00
|
|
|
</itemizedlist>
|
|
|
|
</section>
|
|
|
|
|
2007-06-28 17:09:37 +02:00
|
|
|
<section id="Client">
|
2004-02-14 19:06:39 +01:00
|
|
|
<title>If a Firewall Interface gets its IP Address via DHCP</title>
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
<listitem>
|
|
|
|
<para>Specify the <quote>dhcp</quote> option for this interface in the
|
2005-10-22 19:37:38 +02:00
|
|
|
<ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html"><filename>/etc/shorewall/interfaces</filename></ulink>
|
2010-01-12 16:55:58 +01:00
|
|
|
file. This will generate rules that will allow DHCP to and from your
|
|
|
|
firewall system.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>If you know that the dynamic address is always going to be in
|
2005-10-22 19:37:38 +02:00
|
|
|
the same subnet, you can specify the subnet address in the interface's
|
|
|
|
entry in the <ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html"><filename>/etc/shorewall/interfaces</filename></ulink>
|
2004-02-14 19:06:39 +01:00
|
|
|
file.</para>
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
2005-10-22 19:37:38 +02:00
|
|
|
<para>If you don't know the subnet address in advance, you should
|
|
|
|
specify <quote>detect</quote> for the interface's subnet address in
|
|
|
|
the <ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html"><filename>/etc/shorewall/interfaces</filename></ulink>
|
2004-02-14 19:06:39 +01:00
|
|
|
file and start Shorewall after the interface has started.</para>
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>In the event that the subnet address might change while
|
2016-04-14 02:36:56 +02:00
|
|
|
Shorewall is started, you need to arrange for a <command>shorewall
|
|
|
|
reload</command> command to be executed when a new dynamic IP address
|
2005-10-22 19:37:38 +02:00
|
|
|
gets assigned to the interface. Check your DHCP client's
|
2004-02-14 19:06:39 +01:00
|
|
|
documentation.</para>
|
|
|
|
</listitem>
|
2006-10-06 22:16:38 +02:00
|
|
|
|
|
|
|
<listitem>
|
2013-02-15 19:33:20 +01:00
|
|
|
<para>It is a good idea to <ulink url="ping.html">accept
|
|
|
|
'ping'</ulink> on any interface that gets its IP address via DHCP.
|
|
|
|
That way, if the DHCP server is configured with 'ping-check' true, you
|
|
|
|
won't be blocking its 'ping' requests.</para>
|
2006-10-06 22:16:38 +02:00
|
|
|
</listitem>
|
2004-02-14 19:06:39 +01:00
|
|
|
</itemizedlist>
|
|
|
|
</section>
|
2005-11-29 22:19:48 +01:00
|
|
|
|
2007-06-28 17:09:37 +02:00
|
|
|
<section id="Bridge">
|
2005-11-29 22:19:48 +01:00
|
|
|
<title>If you wish to pass DHCP requests and responses through a
|
|
|
|
bridge</title>
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
<listitem>
|
|
|
|
<para>Specify the <quote>dhcp</quote> option for the bridge interface
|
|
|
|
in the <ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html"><filename>/etc/shorewall/interfaces</filename></ulink>
|
2010-01-12 16:55:58 +01:00
|
|
|
file. This will generate rules that will allow DHCP to and from your
|
|
|
|
firewall system as well as through the bridge.</para>
|
2005-11-29 22:19:48 +01:00
|
|
|
</listitem>
|
|
|
|
</itemizedlist>
|
|
|
|
</section>
|
2006-10-06 22:16:38 +02:00
|
|
|
|
2007-06-28 17:09:37 +02:00
|
|
|
<section id="Relay">
|
2006-10-06 22:16:38 +02:00
|
|
|
<title>Running dhcrelay on the firewall</title>
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
<listitem>
|
|
|
|
<para>Specify the "dhcp" option (in <filename><ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html">/etc/shorewall/interfaces</ulink></filename>)
|
2006-10-06 22:16:38 +02:00
|
|
|
on the interface facing the DHCP server and on the interfaces to be
|
|
|
|
relayed.</para>
|
|
|
|
</listitem>
|
|
|
|
|
2010-01-12 16:55:58 +01:00
|
|
|
<listitem>
|
2010-01-12 18:12:29 +01:00
|
|
|
<para>Allow UDP ports 67 and 68 ("67:68") between the client zone and
|
|
|
|
the server zone:</para>
|
|
|
|
|
2016-02-18 00:58:37 +01:00
|
|
|
<programlisting>#ACTION SOURCE DEST PROTO DPORT
|
2010-01-12 18:12:29 +01:00
|
|
|
ACCEPT ZONEA ZONEB udp 67:68
|
|
|
|
ACCEPT ZONEB ZONEA udp 67:68</programlisting>
|
2010-12-01 20:37:40 +01:00
|
|
|
|
|
|
|
<para>Alternatively, use the DHCPfwd macro:</para>
|
|
|
|
|
2016-02-18 00:58:37 +01:00
|
|
|
<programlisting>#ACTION SOURCE DEST PROTO DPORT
|
2010-12-01 20:39:48 +01:00
|
|
|
DHCPfwd(ACCEPT) ZONEA ZONEB</programlisting>
|
2010-01-12 16:55:58 +01:00
|
|
|
</listitem>
|
|
|
|
|
2006-10-06 22:16:38 +02:00
|
|
|
<listitem>
|
|
|
|
<para>If the server is configured with 'ping-check' true, then you
|
2013-02-15 19:33:20 +01:00
|
|
|
must <ulink url="ping.html">allow 'ping'</ulink> from the server's
|
|
|
|
zone to the zone(s) served by dhcrelay.</para>
|
2006-10-06 22:16:38 +02:00
|
|
|
</listitem>
|
|
|
|
</itemizedlist>
|
|
|
|
</section>
|
2008-07-04 17:11:51 +02:00
|
|
|
</article>
|