DHCP (Dynamic Host Configuration Protocol) assigns clients an IP address, Subnet Mask, Gateway, and DNS addresses. In a environment this is critical: if the client receives an incorrect DNS, it simply won't find the and won't be able to join the Domain or log in.
The DORA Process
הלקוח ללא כתובת IP משדר Discover ב־Broadcast. שרת ה־DHCP, שמאושר (Authorized) ב־Active Directory, מחזיר Offer עם כתובת פנויה. הלקוח שולח Request על ההצעה, והשרת מסיים ב־Acknowledge עם Lease לזמן מוגדר. יחד עם ה־ACK מגיעות Options: 003 שער ברירת מחדל, 006 שרתי DNS פנימיים, ו־015 שם ה־DNS Domain.
- Discover — the client broadcasts and looks for a DHCP server.
- Offer — the server offers an available IP address.
- Request — the client formally requests the offer.
- Acknowledge — the server confirms and grants a Lease for a set time.
DHCP Authorization in AD
A Windows-based DHCP server that is part of the must be Authorized in . The server checks the NetServices object in the Configuration Partition, and if it isn't authorized — the DHCP service simply won't assign addresses. This is a basic protection mechanism against unapproved servers.
Scope and Options
- Scope — the range of addresses the server is allowed to assign on a given network.
- Exclusion Range — addresses reserved for servers and network equipment.
- Reservation — a fixed address for a client based on its MAC address.
- Option 003 — Default Gateway.
- Option 006 — DNS Servers (must point to the internal DC/DNS).
- Option 015 — DNS Name, for example lab.local.
Dynamic DNS Updates
DHCP can update A and PTR records in DNS on behalf of the client. In an environment, it's recommended to configure dedicated Credentials (a regular service account, not a Admin) for performing the updates, and to enable Secure Dynamic Updates on the DNS zone so only the record owner can change them.
לאחר סיום DORA וקבלת Lease, שרת ה־DHCP פונה לשרת ה־DNS שרץ על ה־Domain Controller בזון AD-Integrated ומעדכן עבור הלקוח רשומת A (למשל PC01 לכתובת 10.0.0.25) ורשומת PTR בזון ההפוכה. העדכון מתבצע עם DHCP Credentials — חשבון שירות רגיל ולא Domain Admin — ובזון מופעל Secure Dynamic Updates כך שרק בעל הרשומה יכול לשנות אותה. הגדרת DNS חיצוני ב־Option 006 שוברת את איתור ה־Domain Controller דרך רשומות SRV.