randomly(!) assign ip's from dynamic address range

classic Classic list List threaded Threaded
26 messages Options
12
Reply | Threaded
Open this post in threaded view
|

Re: randomly(!) assign ip's from dynamic address range

Niall O'Reilly
On Tue, 09 Jun 2015 09:33:37 +0100,
Simon Hobson wrote:
>
> So in summary :
> A process to add IPs to a list to be changed.
> A process to monitor expiring leases and check them against the list.
> A process to take matches from the previous step and take dummy leases to temporarily "lock" the address.
>
> That would seem to a fairly safe set of operations.

  Depending on "how many spare addresses you have", as you mentioned
  further up.  I'ld suggest also monitoring the balance between locked
  and available addresses.

  Best regards,
  Niall O'Reilly
 
_______________________________________________
dhcp-users mailing list
[hidden email]
https://lists.isc.org/mailman/listinfo/dhcp-users
Reply | Threaded
Open this post in threaded view
|

Re: randomly(!) assign ip's from dynamic address range

Roberto Innocente
In reply to this post by glenn.satchell

Don't forget also rfc 4436 (Detect network attachment)
used in particular by iphones and ipads that are so nice to switch
almost instantaneously from a wifi ap to another (less than 1 second).
This is done (when the lease is still valid) without re-negotiating
anything with the dhcp server and , provided they recognize the mac
address
of the default router, continue to use the old lease address.
 From some checks they remember 4/5 ap.

roberto



On 2015-06-08 17:24, Glenn Satchell wrote:

> Most dhcp clients also store the last address. So even if you configure
> the server to offer different IPs to the client, the client could keep
> asking for the old address and the server would accept that.
>
> regards,
> -glenn
>
> On Tue, June 9, 2015 12:58 am, Bob Harold wrote:
>> A Windows 8 client appears to keep the last IP in the registry in:
>> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{...<Network
>> Adapter>...}\DhcpIPAddress
>>
>> Although many years ago I remember having clients that remembered the
>> last
>> 5 or 10 IP's (in different subnets).
>>
>>
>>
>> --
>> Bob Harold
>> hostmaster, UMnet, ITcom
>> Information and Technology Services (ITS)
>> [hidden email]
>> 734-647-6524 desk
>>
>> On Mon, Jun 8, 2015 at 9:11 AM, Glenn Satchell
>> <[hidden email]>
>> wrote:
>>
>>>
>>> On Mon, June 8, 2015 7:29 pm, Arne Baeumler wrote:
>>> > Hi Simon,
>>> >
>>> > thank you for your reply.
>>> >
>>> > On 2015-06-05 15:05, Simon Hobson wrote:
>>> >> Hmm, that's a variation I don't think we've seen before ;-)
>>> >> What you are seeing is correct operation according to the RFCs - the
>>> >> server is required to keep the address stable as far as is possible,
>>> and
>>> >> that means the client can come back after an arbitrary length of time
>>> >> and as long as the address has not been re-used then the client
>>> *must*
>>> >> get the same address.
>>> >
>>> > Would you please point me to the RFC you are referring to?
>>> > Can't find any requirements for the server to maintain some kind of IP
>>> > history in RFC2131.
>>> >
>>>
>>> I'm looking at https://www.ietf.org/rfc/rfc2131.txt, there are
>>> several
>>> references to this feature within the document. Section 4.3.1 is the
>>> clearest on this, even though it says it "SHOULD" rather than "MUST"
>>> be
>>> done this way.
>>>
>>> 1.6 Design goals
>>>
>>>       o Retain DHCP client configuration across DHCP client reboot.  
>>> A
>>>         DHCP client should, whenever possible, be assigned the same
>>>         configuration parameters (e.g., network address) in response
>>>         to each request,
>>>
>>>       o Retain DHCP client configuration across server reboots, and,
>>>         whenever possible, a DHCP client should be assigned the same
>>>         configuration parameters despite restarts of the DHCP
>>> mechanism,
>>>
>>> 2.2 Dynamic allocation of network addresses
>>>
>>>    The
>>>    allocation mechanism (the collection of DHCP servers) guarantees
>>> not
>>>    to reallocate that address within the requested time and attempts
>>> to
>>>    return the same network address each time the client requests an
>>>    address.
>>>
>>> 4.3.1 DHCPDISCOVER message
>>>
>>>    When a server receives a DHCPDISCOVER message from a client, the
>>>    server chooses a network address for the requesting client.  If no
>>>    address is available, the server may choose to report the problem
>>> to
>>>    the system administrator. If an address is available, the new
>>> address
>>>    SHOULD be chosen as follows:
>>>
>>>       o The client's current address as recorded in the client's
>>> current
>>>         binding, ELSE
>>>
>>>       o The client's previous address as recorded in the client's
>>> (now
>>>         expired or released) binding, if that address is in the
>>> server's
>>>         pool of available addresses and not already allocated, ELSE
>>>
>>>       o The address requested in the 'Requested IP Address' option,
>>> if
>>> that
>>>         address is valid and not already allocated, ELSE
>>>
>>>       o A new address allocated from the server's pool of available
>>>         addresses; the address is selected based on the subnet from
>>> which
>>>         the message was received (if 'giaddr' is 0) or on the address
>>> of
>>>         the relay agent that forwarded the message ('giaddr' when not
>>> 0).
>>>
>>> I hope this helps.
>>>
>>> I realise this doesn't help with your original question :) In terms
>>> of
>>> privacy there is an IPV6 feature that assigns a new IP address each
>>> day.
>>> This is part of the client functionality defined in RFC 4941 "Privacy
>>> Extensions for Stateless Address Autoconfiguration in IPv6" but
>>> doesn't
>>> help with your current IPv4 issue.
>>>
>>> regards,
>>> -glenn
>>>
>>>
>>> _______________________________________________
>>> dhcp-users mailing list
>>> [hidden email]
>>> https://lists.isc.org/mailman/listinfo/dhcp-users
>>>
>> _______________________________________________
>> dhcp-users mailing list
>> [hidden email]
>> https://lists.isc.org/mailman/listinfo/dhcp-users
>
>
> _______________________________________________
> dhcp-users mailing list
> [hidden email]
> https://lists.isc.org/mailman/listinfo/dhcp-users

--
Roberto Innocente - SISSA
[hidden email] - +39 40 3787541
_______________________________________________
dhcp-users mailing list
[hidden email]
https://lists.isc.org/mailman/listinfo/dhcp-users
Reply | Threaded
Open this post in threaded view
|

Re: randomly(!) assign ip's from dynamic address range

Simon Hobson
Roberto Innocente <[hidden email]> wrote:

> Don't forget also rfc 4436 (Detect network attachment)
> used in particular by iphones and ipads that are so nice to switch
> almost instantaneously from a wifi ap to another (less than 1 second).
> This is done (when the lease is still valid) without re-negotiating
> anything with the dhcp server and , provided they recognize the mac address
> of the default router, continue to use the old lease address.

That won't matter (much). The OP has stated that they can't detect users leaving the network anyway, so the only way to determine a client is "down" is to see it's lease expire. Thus the address will only be "locked" when the lease is expired and the client should not be trying to use it. As long as the client returns to the network (even briefly) during the period the address is locked then it'll negotiate a new address with the DHCP server.

The only problem I see is a multihomed device which is "away" for so long that the locking lease expires and so allows the client to get it's old address back.


One thing I didn't see was anything about how clients connect : is this a "all devices go on the network directly" type of thing, or do users have a router on their end and their end devices behind that (and a layer of NAT) ? If the latter then it really doesn't matter what end user devices are used - it's the router that gets the public address.



_______________________________________________
dhcp-users mailing list
[hidden email]
https://lists.isc.org/mailman/listinfo/dhcp-users
Reply | Threaded
Open this post in threaded view
|

Re: randomly(!) assign ip's from dynamic address range

Roberto Innocente
In reply to this post by Arne Baeumler

Are users authenticated via 802.1x
Or in anycase radius ?



On 2015-06-05 15:10, Arne Baeumler wrote:

> Hi dhcp users,
>
> we are running a DHCP Server for about 10k customers with a single isc
> dhcpd (4.2.4p2) process running.
> Our customers do almost ever get the same IP Address assigned when
> sending DHCPDISCOVER.
>
> Lease time is 1200 sec. (20 minutes), pool is 95-97% in use all day.
> Even after 10h offline,
> dhcpd will answer an DHCPDISCOVER with an DHCPOFFER for the same ip
> address as assigned 10h earlier.
>
> Some of our customers would like their ip address to change from time
> to time (e.g. every 24h)
> as they where used to when using PPP.
>
> Is there any way to accomplish this using isc dhcpd?
>
> _______________________________________________
> dhcp-users mailing list
> [hidden email]
> https://lists.isc.org/mailman/listinfo/dhcp-users

--
Roberto Innocente - SISSA
[hidden email] - +39 40 3787541
_______________________________________________
dhcp-users mailing list
[hidden email]
https://lists.isc.org/mailman/listinfo/dhcp-users
Reply | Threaded
Open this post in threaded view
|

Re: randomly(!) assign ip's from dynamic address range

Pepperon92
In reply to this post by Arne Baeumler
Das klingt nach einer stabilen und gut konfigurierten DHCP-Umgebung – bei dieser Anzahl an Clients ist es beeindruckend, dass die Vergabe so zuverlässig funktioniert. Wenn die Kunden fast immer dieselbe IP erhalten, deutet das auf eine konsistente Lease-Verwaltung und vermutlich lange Lease-Zeiten hin. Und apropos Beständigkeit: Wer auch im Alltag auf Verlässlichkeit und Stil setzt, wird mit einem eleganten midi abendkleider nie danebenliegen – klassisch, modern und immer passend.
Reply | Threaded
Open this post in threaded view
|

Re: randomly(!) assign ip's from dynamic address range

wl123456789
In reply to this post by Arne Baeumler
羅斯泰坦凝膠第三代升級版
https://www.kl19.tw/index.php?m=Index&a=order&id=66toN9
笛夢達克羅寧黑寡婦 
https://www.kl19.tw/index.php?m=Index&a=order&id=6tqnta
美國威樂增大膠囊VIGRX PLUS60粒/盒
https://www.kl19.tw/index.php?m=Index&a=order&id=3ze3Ud
女用美國key
https://www.kl19.tw/index.php?m=Index&a=order&id=6lEJHI
德國必邦偉哥 
https://www.kl19.tw/index.php?m=Index&a=order&id=89MAuC
德國黑螞蟻 
https://www.kl19.tw/index.php?m=Index&a=order&id=1GpaMp
美國【MMC】MAXMAN
https://www.kl19.tw/index.php?m=Index&a=order&id=4MifrP GOODMAN陰莖增大丸goodman 
https://www.kl19.tw/index.php?m=Index&a=order&id=2bW5J3
日本原廠滕素金標凹凸防偽16粒/瓶
https://www.kl19.tw/index.php?m=Index&a=order&id=8SlckI
美國黑金
https://www.kl19.tw/index.php?m=Index&a=order&id=7T5EBE
美國保羅V8 
https://www.kl19.tw/index.php?m=Index&a=order&id=6m7YP2
超級必利勁Extra Super Tadarad雙效片
https://www.kl19.tw/index.php?m=Index&a=order&id=8OCCoo
德國拜耳樂威壯
https://www.kl19.tw/index.php?m=Index&a=order&id=73u1bh
印度犀利士TADACIP-20 
https://www.kl19.tw/index.php?m=Index&a=order&id=8DBRmW
美國黃金偉哥Viagra
https://www.kl19.tw/index.php?m=Index&a=order&id=1IAb4h
一想就硬 華佗神丹
https://www.kl19.tw/index.php?m=Index&a=order&id=10qeD2
享硬瑪卡濃縮片
https://www.kl19.tw/index.php?m=Index&a=order&id=3DPMXH
一炮到天亮第八代升級版
https://www.kl19.tw/index.php?m=Index&a=order&id=6Bf14F
液態威而鋼
https://www.kl19.tw/index.php?m=Index&a=order&id=5DqWkk
威而鋼【四粒装】原裝正品 
https://www.kl19.tw/index.php?m=Index&a=order&id=2NUpQN
美國犀利士Cialis原裝進口速效助勃
https://www.kl19.tw/index.php?m=Index&a=order&id=5QtTRq\
超級雙效樂威壯Levifil Super Power
https://www.kl19.tw/index.php?m=Index&a=order&id=8J5HsM
威而鋼viagra藍色小藥丸速效增硬助勃30粒裝 
https://www.kl19.tw/index.php?m=Index&a=order&id=4f8iW9
韓國奇力片 
https://www.kl19.tw/index.php?m=Index&a=order&id=2Q9TRn
正品犀利士20mg30粒瓶裝
https://www.kl19.tw/index.php?m=Index&a=order&id=5GQanr
印度純進口正品必利勁Priligy(POXET-60)口服速效持久藥
https://www.kl19.tw/index.php?m=Index&a=order&id=4vQ3TP
印度樂威壯30粒
https://www.kl19.tw/index.php?m=Index&a=order&id=9M5XzG
德國黑金鋼 
https://www.kl19.tw/index.php?m=Index&a=order&id=8Yt9e8
菱形雙效威而鋼KAMAGRA 
https://www.kl19.tw/index.php?m=Index&a=order&id=2dzQuO
法國綠騎士持久液噴霧劑
https://www.kl19.tw/index.php?m=Index&a=order&id=6uwikD
日本2H2D金尊持久液原裝進口正品不麻木免洗可口交
https://www.kl19.tw/index.php?m=Index&a=order&id=2i96mw
日本黑豹四代持久液
https://www.kl19.tw/index.php?m=Index&a=order&id=4l4ptJ
液態果凍威而鋼MALEGRA7包/盒
12