<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="ru">
	<id>https://noname.com.ua/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Dhcp_relay</id>
	<title>Dhcp relay - История изменений</title>
	<link rel="self" type="application/atom+xml" href="https://noname.com.ua/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Dhcp_relay"/>
	<link rel="alternate" type="text/html" href="https://noname.com.ua/mediawiki/index.php?title=Dhcp_relay&amp;action=history"/>
	<updated>2026-05-14T18:28:39Z</updated>
	<subtitle>История изменений этой страницы в вики</subtitle>
	<generator>MediaWiki 1.36.1</generator>
	<entry>
		<id>https://noname.com.ua/mediawiki/index.php?title=Dhcp_relay&amp;diff=12175&amp;oldid=prev</id>
		<title>Sirmax в 07:00, 30 октября 2023</title>
		<link rel="alternate" type="text/html" href="https://noname.com.ua/mediawiki/index.php?title=Dhcp_relay&amp;diff=12175&amp;oldid=prev"/>
		<updated>2023-10-30T07:00:44Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;ru&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Предыдущая&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Версия 07:00, 30 октября 2023&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Строка 1:&lt;/td&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Строка 1:&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Категория:Linux]]&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;+&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Категория:Networking]]&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;PRE&amp;gt;&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;PRE&amp;gt;&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Gloeiende Oliebollen. I wanted to DHCP relay discovers MSGs off only ‘one’ specific device in my home network somewhere to the DHCP server on the other side of a GRE tunnel. Off course this is not really logical but that’s besides this post.&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&amp;#160;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Gloeiende Oliebollen. I wanted to DHCP relay discovers MSGs off only ‘one’ specific device in my home network somewhere to the DHCP server on the other side of a GRE tunnel. Off course this is not really logical but that’s besides this post.&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Sirmax</name></author>
	</entry>
	<entry>
		<id>https://noname.com.ua/mediawiki/index.php?title=Dhcp_relay&amp;diff=6646&amp;oldid=prev</id>
		<title>Sirmax: Новая: &lt;PRE&gt; Gloeiende Oliebollen. I wanted to DHCP relay discovers MSGs off only ‘one’ specific device in my home network somewhere to the DHCP server on the other side of a GRE tunnel. Of...</title>
		<link rel="alternate" type="text/html" href="https://noname.com.ua/mediawiki/index.php?title=Dhcp_relay&amp;diff=6646&amp;oldid=prev"/>
		<updated>2014-11-28T10:54:38Z</updated>

		<summary type="html">&lt;p&gt;Новая: &amp;lt;PRE&amp;gt; Gloeiende Oliebollen. I wanted to DHCP relay discovers MSGs off only ‘one’ specific device in my home network somewhere to the DHCP server on the other side of a GRE tunnel. Of...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Новая страница&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;PRE&amp;gt;&lt;br /&gt;
Gloeiende Oliebollen. I wanted to DHCP relay discovers MSGs off only ‘one’ specific device in my home network somewhere to the DHCP server on the other side of a GRE tunnel. Off course this is not really logical but that’s besides this post.&lt;br /&gt;
&lt;br /&gt;
I installed ISC DHCP “yum install dhcp-4.1.1″. This packages comes with the ISC dhcrelay client which I figured to do the relaying. The Idea was to block all broadcast traffic designed for port 67 on this machine, and only to allow the specific MAC address.&lt;br /&gt;
&lt;br /&gt;
When this was setup, I noticed all the local DHCP discovers/MAC’s passing the filter and thought I made a mistake. I did some troubleshooting and started with blocking individual MAC’s. This is normally an easy task by doing:”-A INPUT -m mac –mac-source 00:02:02:41:d0:77 -j DROP” and checking the hit counter of IPtables.&lt;br /&gt;
&lt;br /&gt;
My Tunnel/VPN Server: IPTV / 10.0.0.253&lt;br /&gt;
My test server with relay agent and IPtables MAC filter: centos-test1 / 10.0.0.101&lt;br /&gt;
&lt;br /&gt;
#It get's three hits, It works!:&lt;br /&gt;
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)&lt;br /&gt;
pkts bytes target prot opt in out source destination&lt;br /&gt;
3 1728 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:02:02:41:D0:77&lt;br /&gt;
&lt;br /&gt;
You will think that everything is okay now…. NO it isn’t!&lt;br /&gt;
&lt;br /&gt;
# Still request being picked up and relayed:&lt;br /&gt;
[root@centos-test1 ~]# dhcrelay -d -i eth0 10.0.0.253&lt;br /&gt;
Internet Systems Consortium DHCP Relay Agent 4.1.1-P1&lt;br /&gt;
Copyright 2004-2010 Internet Systems Consortium.&lt;br /&gt;
All rights reserved.&lt;br /&gt;
For info, please visit https://www.isc.org/software/dhcp/&lt;br /&gt;
Listening on LPF/eth0/52:54:00:05:b0:a4&lt;br /&gt;
Sending on LPF/eth0/52:54:00:05:b0:a4&lt;br /&gt;
Sending on Socket/fallback&lt;br /&gt;
&lt;br /&gt;
Forwarded BOOTREQUEST for 00:02:02:41:d0:77 to 10.0.0.253&lt;br /&gt;
Forwarded BOOTREQUEST for 00:02:02:41:d0:77 to 10.0.0.253&lt;br /&gt;
&lt;br /&gt;
# And tcpdump output:&lt;br /&gt;
21:20:23.596458 IP 0.0.0.0.68 &amp;gt; 255.255.255.255.67: BOOTP/DHCP, Request from 00:02:02:41:d0:77, length 548&lt;br /&gt;
21:20:23.596597 IP 10.0.0.101.67 &amp;gt; 10.0.0.253.67: BOOTP/DHCP, Request from 00:02:02:41:d0:77, length 548&lt;br /&gt;
&lt;br /&gt;
I spend considerable time figuring this one out. Even thought about a bug in iptables. But it appears that ISC dhcrelay client hooks it-self before the IPtables in the IP stack. It explains why the (DROP) counter is increasing while the packets are being relayed too.&lt;br /&gt;
&lt;br /&gt;
After searching the internet I found:&lt;br /&gt;
Per Mark Andrews of isc.org:&lt;br /&gt;
&amp;quot;DHCP uses packet filters and these tie into the IP stack before the&lt;br /&gt;
firewall.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
I decided to go with Kelly’s “DHCP Helper” (wget http://www.thekelleys.org.uk/dhcp-helper/dhcp-helper-1.1.tar.gz), did an make, make install. Fired it up. Added again the line:”IPtables -I INPUT -m mac –mac-source 00:02:02:41:D0:77 -p udp –dport 67 -j DROP” and the problem disappeared:&lt;br /&gt;
&lt;br /&gt;
21:35:23.036248 IP 0.0.0.0.68 &amp;gt; 255.255.255.255.67: BOOTP/DHCP, Request from 00:02:02:41:d0:77, length 548&lt;br /&gt;
21:35:39.064687 IP 0.0.0.0.68 &amp;gt; 255.255.255.255.67: BOOTP/DHCP, Request from 00:02:02:41:d0:77, length 548&lt;br /&gt;
&lt;br /&gt;
Life can be good!&lt;br /&gt;
&amp;lt;/PRE&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sirmax</name></author>
	</entry>
</feed>