Jump to content
Main menu
Main menu
move to sidebar
hide
Navigation
Main page
Recent changes
Random page
Help about MediaWiki
TetraWiki
Search
Search
Appearance
Create account
Log in
Personal tools
Create account
Log in
Pages for logged out editors
learn more
Contributions
Talk
Editing
GSTN - Directory services DNS PRINT DHCP
Page
Discussion
English
Read
Edit
View history
Tools
Tools
move to sidebar
hide
Actions
Read
Edit
View history
General
What links here
Related changes
Special pages
Page information
Appearance
move to sidebar
hide
Warning:
You are not logged in. Your IP address will be publicly visible if you make any edits. If you
log in
or
create an account
, your edits will be attributed to your username, along with other benefits.
Anti-spam check. Do
not
fill this in!
[[category:GSTN]] # '''Directory Services, DNS, PRINT and DHCP''' <div style="color:#00000a;"></div># ## '''Integrated Components''' The following components will be used for building up the Integrated Environment.* '''BIND (Berkeley Internet Name Domain)''' is an implementation of the DNS protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System, including: ** Domain Name System server ** Domain Name System resolver library ** Tools for managing and verifying the proper operation of the DNS server Some of the important features of BIND9 are DNS Security (DNSSEC, TSIG), IPv6, DNS Protocol Enhancements (IXFR, DDNS, DNS Notify, EDNS0), Views, Multiprocessor Support, Replications, Zone updates and an Improved Portability Architecture. Below is the print screen of packages used to implement BIND: [[Image:GSTNDIRECTORY1.png]]* '''ISC (Internet Systems Consortium) DHCP''' is open source software that implements the Dynamic Host Configuration Protocol for connection to an IP network. It is production-grade software that offers a complete solution for implementing DHCP servers, relay agents, and clients for small local networks to large enterprises. ISC DHCP solution supports both IPv4 and IPv6, and is suitable for use in high-volume and high-reliability applications. '''(Due to design change DHCP has been configured on different server in HA.)'''* '''Directory and policy''' - '''Samba 4'''.X is a milestone release that brings Active Directory functionality to the open source SMB/CIFS (Server Message Block/Common Internet File System) file and print server. Samba 4.X can serve as an Active Directory Domain Controller, provide DNS services, handle Kerberos-based authentication, and administer group policy. The Samba 4.X Domain Controller can even be managed using the native Windows Active Directory admin tools. Supports DC and ADC . Command to check kerberos '''''klist get host/%computername%''''' Below print screen for kerberose ticket for a windows10 client.[[Image:GSTNDIRECTORY2.png]] Windows Active Directory admin tool to manage users and computers. [[Image:GSTNDIRECTORY3.png]] Administer group policy using Group policy management tool. Domain Controller management using the native Windows Active Directory admin tools: DNS management tool. [[Image:GSTNDIRECTORY6.png]] * '''Common UNIX Printing System (CUPS)'''. This printing system is a freely available, portable printing layer which has become the new standard for printing in most Linux distribution. CUPS manages print jobs and queues and provides network printing using the standard Internet Printing Protocol (IPP), while offering support for a very large range of printers, from dot-matrix to laser and many in between. CUPS also supports Post Script Printer Description (PPD) and auto-detection of network printers, and features a simple web-based configuration and administration tool. <div style="margin-left:1.27cm;margin-right:0cm;"></div> <div style="margin-left:1.27cm;margin-right:0cm;"></div> <div style="margin-left:1.27cm;margin-right:0cm;"></div> CUPS web interface to manage printers. [[Image:GSTNDIRECTORY7.png]] Print jobs and queues management. [[Image:GSTNDIRECTORY8.png]] <div style="margin-left:1.27cm;margin-right:0cm;"></div> CUPS allows to create a new or modify an existing printer in such a way that there is a user-based access-control in place. [[Image:GSTNDIRECTORY9.png]] '''Print server High Availability.''' We have configured Print server on HA. Cluster IPV4 is 172.18.101.33 and IPV6 is 2404:a800:1000:d:7800::21 for print server. We have configured one cluster named as PRINTER having two nodes and one resource. To manage cluster open web GUI link '''https://gdprinter.gstn.local:2224.''' [[Image:GSTNDIRECTORY10.png]] Cluster nodes: Cluster Resource:[[Image:GSTNDIRECTORY11.png]] [[Image:GSTNDIRECTORY12.png]] Checking cluster status from command line: Run ''“pcs status”'' [[Image:GSTNDIRECTORY13.png]] Start the cluster using pcs command. “–all” will start the cluster on all the configured nodes. ''<nowiki># pcs cluster start --all</nowiki>'' Stopping cluster.[[Image:GSTNDIRECTORY14.png]] ''<nowiki># pcs cluster stop all</nowiki>'' [[Image:GSTNDIRECTORY15.png]]# ## '''Server Sizing / Considerations''' <div style="color:#00000a;"></div> <div style="color:#00000a;"></div> {| style="border-spacing:0;width:18.352cm;" |- | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''ServerName''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''OS''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''Role''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''vRAM''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''vCPU''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''HDD [GB]''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''VLANID''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''IP4/IP6 Address''' | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''Subnet''' | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | '''Gateway''' |- | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GD9103 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | RHEL | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | DNS, Print , Directory <nowiki>#1</nowiki> | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 16 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 4 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | OS-200 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 101 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.101.14/2404:a800:1000:d:7800::e | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 255.255.255.0/69 | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.101.1 |- | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GD9104 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | RHEL | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | DNS, Directory #2 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 16 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 4 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | OS-200 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 101 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.101.15/2404:a800:1000:d:7800::f | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 255.255.255.0/69 | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.101.1 |- | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GDPRINTER | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | RHEL | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | Print | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 16 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 4 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | OS-200 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 101 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.101.33/2404:a800:1000:d:7800::21 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 255.255.255.0/69 | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.101.1 |- | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | |- |} # ## '''DNS Structure at GSTN''' As there will be Linux AD implemented via SAMBA4, DNS which is Bind9 will be additionally installed and integrated with SAMBA4 implementation. The DNS setup and records will be managed by DNS MMC Snap-In tool on windows as shown below.[[Image:GSTNDIRECTORY16.png]] Adding new records, Updating existing records, Deleting, Changing zone properties, Defining Zone Replication Scope, Reverse Lookup Zone, Dynamic Update etc will be created and deployed via Window's DNS MMC Snap-in tool from Windows Management Machine placed in management zone. [[Image:GSTNDIRECTORY17.png]] The DNS can also be managed via Linux CLI. An Separate DNS zone for Servers at GSTN is created for having name based resolution for inter communications. Bind9 with Master – Slave replication is designed for GSTN. The Slave will reside on ADC and replicated. Both IPV4 and IPV6 as dual stack will be activated and populated. We have created an additional zone named as '''gstn.org.in '''for mail server. [[Image:GSTNDIRECTORY18.png]] # ## ### '''Conditional Forwarding''' A '''forwarder''' is a '''Domain Name System''' ('''DNS''') server on a network that is used to forward '''DNS''' queries for external '''DNS''' names to '''DNS''' servers outside that network. You can also configure your server to forward queries according to specific domain names using '''conditional forwarders. ''' '''Bind9 '''supports forwarders and conditional forwarding .Conditional forwarders are not implemented yet on Samba integrated DNS management Snap-In . That means any conditional forwarders will be implemented via CLI. [[Image:GSTNDIRECTORY19.png]] # ## ### '''Round robin DNS''' Round Robin DNS is a technique of load distribution, load balancing, or fault-tolerance provisioning multiple, redundant Internet Protocol service hosts, e.g., Web server, FTP servers, by managing the Domain Name System's (DNS) responses to address requests from client computers according to an appropriate statistical model. Bind9 support Round robin (RR) for long . Both IPV4 and IPv6 is supported over round robin principle. The records are output as per rrset-order .'''rrset-order''' defines the order in which multiple records of the same type are returned. This works for any record type in which the records are similar not just A or AAAA RRs and covers results in the ANSWER SECTION and the ADDITIONAL SECTION. The default is cyclic (round-robin).# ## {{anchor|RefHeading1213241649886}} '''DHCP Structure at GSTN (DHCP has been covered in different document )''' DHCP will be configured on IPV4 and IPV6 both as dual stack. Dedicated 2 VMs are allocated for High Availability. Following are the details of suggested DHCP environment* Enablement of both dhcpd and dhcpv6d Services for ipv4 and ipv6 respectively[[Image:GSTNDIRECTORY20.png]] * Only Desktop / Laptop User based VLAN and IP Telephone Devices VLAN to be included in scoping of DHCP. * Scope ID 176 to be configured for scope of IP Telephony devices. * Switches will be activated as DHCP relay agent to forward the different VLAN Traffic for DHCP server. * Both Ipv4 and Ipv6 scopes will be defined. Ipv6 will be preferred over ipv4. * As there will be around 200 devices which might increase up to four hundred, the lease period suggested for 8 hours. * High Availability is inbuilt feature of ISC DHCP. It will configured as primary and secondary server in active / passive mode or fail-over mode * The Leases databases is file type and can be backup and restored. * DHCP with dynamic DNS updates to ensure the tight integration of DNS with DHCP * 13/14 VLANS would be present for different Type of User. Each VLAN would have a scope name and a particular VLAN type defined. <div style="margin-left:1.27cm;margin-right:0cm;">DHCP Range is as follows :</div> {| style="border-spacing:0;width:16.614cm;" |- ! align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | S.No ! align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | VLAN ID ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | FW-MZ- VLAN NAME ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | Description ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | Network ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | Gateway ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | Mask ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | Host Start Range ! style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | IPV6 Network/Gateway ! style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | DHCP Range |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 1 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 2 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GNDEL-VoIP | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | VOIP PHONE - "String Option 176" | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.2.0/24 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.2.1 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.0 255.255.255.0] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.16.11 to 172.18.16.254 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:172.18.16.51%20-%20172.18 172.18.16.51 - 172.18.16.240] |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 2 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 3 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GSTN-VC | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | VIDEO-CONFERENCE | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.3.0/27 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.3.1 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.224 255.255.255.224] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.3.11 to 172.18.3.30 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | NA |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 3 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 33 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GNDEL-SEC-SYSTEM | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | SECURITY SYSTEM | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.3.32/27 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.3.33 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.224 255.255.255.224] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:172.18.3.%2036 172.18.3. 36 to 172.18.3.62] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.3.41 to 172.18.3.62 |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 4 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 4 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GNDEL-TPV | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GSTN- TP VENDOR | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.4.0/24 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.4.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.0 255.255.255.0] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:172.18.4.254 172.18.4.11 to 172.18.4.254] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:172.18.4.240 172.18.4.51 to 172.18.4.240] |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 5 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 5 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GNDEL-USER | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | GSTN-USERs | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.5.0/24 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 172.18.5.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.0 255.255.255.0] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:172.18.5.254 172.18.5.11 to 172.18.5.254] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:172.18.5.240 172.18.5.51 to 172.18.5.240] |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 6 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 6 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GNDEL-IT | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GSTN-IT | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.6.0/26 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.6.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.192 255.255.255.192] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.6.11 to 172.18.6.62 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.6.21 to 172.18.6.62 |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 7 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 7 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GNDEL-HR | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GSTN-HR | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.7.0/27 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.7.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.224 255.255.255.224] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.7.11 to 172.18.7.30 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.7.11 to 172.18.7.30 |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 8 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 8 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GNDEL-FINANCE | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GSTN-FINANCE | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.8.0/27 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.8.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.224 255.255.255.224] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.8.11 to 172.18.8.30 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.8.11 to 172.18.8.30 |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 9 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 9 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GENDEL-WIFI-AP | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | WIFI-MGMT-VLAN(CNTRLR+APS) | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.9.0/26 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.9.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.192 255.255.255.192] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.9.11 to 172.18.9.62 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | NA |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 10 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 10 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GNDEL-WIFI-DC | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GSTN-DC GSTN-WIFI(AD-AUTH) | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.10.0/24 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.10.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.0 255.255.255.0] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.10.11 to 172.18.10.254 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.10.51 to 172.18.10.240 |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 11 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 11 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GNDEL-WIFI(MAC-AUTH) | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GSTN-INTERNET | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.11.0/24 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.11.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.0 255.255.255.0] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.11.11 to 172.18.11.254 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.11.51 to 172.18.11.240 |- | align=center style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;color:#000000;" | 12 | align=center style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 12 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GNDEL-WIFI(GUEST USER) | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | GSTN-GUEST | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.12.0/24 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.12.0 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | [callto:255.255.255.0 255.255.255.0] | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.12.11 to 172.18.12.254 | style="background-color:#ffffff;border-top:0.5pt solid #000000;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:none;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | ISP-GUA(Global Unique Adress) | style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.191cm;padding-right:0.191cm;" | 172.18.12.51 to 172.18.12.240 |- |} IPv6 – IP Range will be provided/Shared by ISP. == DHCP HA Configuration: == == The Servers: == <div style="color:#00000a;">Primary IP address: 172.18.101.12</div> <div style="color:#00000a;">Secondary IP address: 172.18.101.13</div> '''How HA is working?''' <div style="color:#00000a;">With DHCP failover, DHCPv4 scopes can be replicated from a primary DHCP server to a secondary DHCP server, enabling redundancy and load balancing of DHCP services.</div> <div style="color:#00000a;">Both server are configured in HA. Given below the configuration file of both DHCP servers. They communicate on port number 519 and 520 as defined in dhcpd.conf file.</div> '''Primary DHCP server:''' <div style="color:#00000a;"><nowiki># Failover specific configurations</nowiki></div> ''[root@gd9101 ~]# cat /etc/dhcp/dhcpd.conf'' <div style="color:#00000a;">ddns-update-style none;</div> <div style="color:#00000a;">one-lease-per-client true;</div> <div style="color:#00000a;">option domain-name "gstn.local";</div> <div style="color:#00000a;">option domain-name-servers 172.18.101.14, 172.18.101.15;</div> <div style="color:#00000a;">default-lease-time 28800;</div> <div style="color:#00000a;">max-lease-time 288000;</div> <div style="color:#00000a;">lease-file-name "/var/log/dhcpd/dhcpd.leases";</div> <div style="color:#00000a;">authoritative;</div> <div style="color:#00000a;">log-facility local5;</div> <div style="color:#00000a;">option option-242 code 242 = string;</div> <div style="color:#00000a;">failover peer "dhcp" {</div> <div style="color:#00000a;">primary;</div> <div style="color:#00000a;">address 172.18.101.12;</div> <div style="color:#00000a;">port 519;</div> <div style="color:#00000a;">peer address 172.18.101.13;</div> <div style="color:#00000a;">peer port 520;</div> <div style="color:#00000a;">max-response-delay 60;</div> <div style="color:#00000a;">max-unacked-updates 10;</div> <div style="color:#00000a;">mclt 600;</div> <div style="color:#00000a;">split 128;</div> <div style="color:#00000a;">load balance max seconds 3;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">include "/etc/dhcpd.master";</div> <div style="color:#00000a;"><nowiki>==============================================================</nowiki></div> '''Secondary Server:''' <div style="color:#00000a;"><nowiki># Failover specific configurations</nowiki></div> ''[root@gd9102 ~]# cat /etc/dhcp/dhcpd.conf'' <div style="color:#00000a;">ddns-update-style none;</div> <div style="color:#00000a;">one-lease-per-client true;</div> <div style="color:#00000a;">option domain-name "gstn.local";</div> <div style="color:#00000a;">option domain-name-servers 172.18.101.14, 172.18.101.15;</div> <div style="color:#00000a;">default-lease-time 28800;</div> <div style="color:#00000a;">max-lease-time 288000;</div> <div style="color:#00000a;">lease-file-name "/var/log/dhcpd/dhcpd.leases";</div> <div style="color:#00000a;">authoritative;</div> <div style="color:#00000a;">log-facility local5;</div> <div style="color:#00000a;">option option-242 code 242 = string;</div> <div style="color:#00000a;">failover peer "dhcp" {</div> <div style="color:#00000a;">secondary;</div> <div style="color:#00000a;">address 172.18.101.13;</div> <div style="color:#00000a;">port 520;</div> <div style="color:#00000a;">peer address 172.18.101.12;</div> <div style="color:#00000a;">peer port 519;</div> <div style="color:#00000a;">max-response-delay 60;</div> <div style="color:#00000a;">max-unacked-updates 10;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">include "/etc/dhcpd.master";</div> <div style="color:#00000a;"><nowiki>=============================================================</nowiki></div> <div style="color:#00000a;">When two DHCP servers are configured for failover, they will share scope information, including all active leases. This enables both DHCP servers to provide leases to the same subnet for load balancing or redundancy purposes. Scope settings are replicated when you first configure DHCP failover, and can be replicated again later if configuration changes are made. </div> <div style="color:#00000a;">To take advantage of failover, we need to create a pool. We have created pools in '''"/etc/dhcpd.master"''' on both servers as shown below:</div> '''Primary Server:''' <div style="color:#00000a;">Output of "'''/etc/dhcpd.master'''"</div> <div style="color:#00000a;">subnet 172.18.101.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.101.216 172.18.101.217;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.101.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">shared-network data {</div> <div style="color:#00000a;">subnet 172.18.5.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool { </div> <div style="color:#00000a;">failover peer "dhcp"; </div> <div style="color:#00000a;">range 172.18.5.51 172.18.5.240;</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">option routers 172.18.5.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.5.255;</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">shared-network voice {</div> <div style="color:#00000a;">subnet 172.18.2.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool { </div> <div style="color:#00000a;">failover peer "dhcp"; </div> <div style="color:#00000a;">range 172.18.2.51 172.18.2.240;</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">option routers 172.18.2.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.2.255;</div> <div style="color:#00000a;">option option-242 "MCIPADD=172.18.102.16,MCPORT=1719,HTTPSRVR=172.18.102.16";</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.3.32 netmask 255.255.255.224 { </div> <div style="color:#00000a;">pool { </div> <div style="color:#00000a;">failover peer "dhcp"; </div> <div style="color:#00000a;">range 172.18.3.41 172.18.3.62; </div> <div style="color:#00000a;">deny dynamic bootp clients; </div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">option routers 172.18.3.33;</div> <div style="color:#00000a;">option broadcast-address 172.18.3.63;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.4.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.4.51 172.18.4.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.4.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.4.255;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.6.0 netmask 255.255.255.192 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.6.21 172.18.6.62;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.6.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.6.63;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.7.0 netmask 255.255.255.224 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.7.11 172.18.7.30;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.7.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.7.31;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.8.0 netmask 255.255.255.224 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.8.11 172.18.8.30;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.8.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.8.31;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.10.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.10.51 172.18.10.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.10.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.10.255;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.11.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.11.51 172.18.11.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.11.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.11.255;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.12.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">option broadcast-address 172.18.12.255;</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.12.51 172.18.12.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.12.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">shared-network gd-soft {</div> <div style="color:#00000a;">subnet 172.18.16.0 netmask 255.255.255.192 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.16.11 172.18.16.62;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.16.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.16.63;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.20.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">option broadcast-address 172.18.20.255;</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.20.51 172.18.20.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.20.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.21.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">option broadcast-address 172.18.21.255;</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.21.51 172.18.21.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.21.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"><nowiki>=================================================================== </nowiki></div> <div style="color:#00000a;">'''Seconday Server''':</div> <div style="color:#00000a;">Output of "/etc/dhcpd.master"</div> <div style="color:#00000a;">subnet 172.18.101.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.101.216 172.18.101.217;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.101.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">shared-network data {</div> <div style="color:#00000a;">subnet 172.18.5.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool { </div> <div style="color:#00000a;">failover peer "dhcp"; </div> <div style="color:#00000a;">range 172.18.5.51 172.18.5.240;</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">option routers 172.18.5.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.5.255;</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;"></div> <div style="color:#00000a;">shared-network voice {</div> <div style="color:#00000a;">subnet 172.18.2.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool { </div> <div style="color:#00000a;">failover peer "dhcp"; </div> <div style="color:#00000a;">range 172.18.2.51 172.18.2.240;</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">option routers 172.18.2.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.2.255;</div> <div style="color:#00000a;">option option-242 "MCIPADD=172.18.102.16,MCPORT=1719,HTTPSRVR=172.18.102.16";</div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.3.32 netmask 255.255.255.224 { </div> <div style="color:#00000a;">pool { </div> <div style="color:#00000a;">failover peer "dhcp"; </div> <div style="color:#00000a;">range 172.18.3.41 172.18.3.62; </div> <div style="color:#00000a;">deny dynamic bootp clients; </div> <div style="color:#00000a;">} </div> <div style="color:#00000a;">option routers 172.18.3.33;</div> <div style="color:#00000a;">option broadcast-address 172.18.3.63;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.4.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.4.51 172.18.4.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.4.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.4.255;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.6.0 netmask 255.255.255.192 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.6.21 172.18.6.62;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.6.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.6.63;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.7.0 netmask 255.255.255.224 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.7.11 172.18.7.30;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.7.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.7.31;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.8.0 netmask 255.255.255.224 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.8.11 172.18.8.30;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.8.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.8.31;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.10.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.10.51 172.18.10.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.10.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.10.255;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.11.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.11.51 172.18.11.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.11.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.11.255;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.12.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">option broadcast-address 172.18.12.255;</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.12.51 172.18.12.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.12.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">shared-network gd-soft {</div> <div style="color:#00000a;">subnet 172.18.16.0 netmask 255.255.255.192 {</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.16.11 172.18.16.62;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.16.1;</div> <div style="color:#00000a;">option broadcast-address 172.18.16.63;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet 172.18.20.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">option broadcast-address 172.18.20.255;</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.20.51 172.18.20.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.20.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;"></div> <div style="color:#00000a;">subnet 172.18.21.0 netmask 255.255.255.0 {</div> <div style="color:#00000a;">option broadcast-address 172.18.21.255;</div> <div style="color:#00000a;">pool {</div> <div style="color:#00000a;">failover peer "dhcp";</div> <div style="color:#00000a;">range 172.18.21.51 172.18.21.240;</div> <div style="color:#00000a;">deny dynamic bootp clients;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">option routers 172.18.21.1;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;"></div> <div style="color:#00000a;"><nowiki>=====================================================================</nowiki></div> <div style="color:#00000a;">'''DHCP6 Configuration in HA''':</div> <div style="color:#00000a;">In DHCPv6, the half of ipv6 range is given in Primary server and rest half of the ipv6 range is given in secondary server.</div> <div style="color:#00000a;">For example:</div> <div style="color:#00000a;">IPv6 range on primary server for below range is from </div> <div style="color:#00000a;">range6 2404:a800:1000:d:2000::b 2404:a800:1000:d:2000::85</div> <div style="color:#00000a;">and on secondary server it is from</div> <div style="color:#00000a;">range6 2404:a800:1000:d:2000::88 2404:a800:1000:d:2000::100</div> <div style="color:#00000a;">'''Primary Server''': </div> <div style="color:#00000a;">DHCPv6 configuration file:</div> ''vi /etc/dhcp/dhcpd6.conf'' <div style="color:#00000a;"></div> <div style="color:#00000a;">default-lease-time 28800;</div> <div style="color:#00000a;">preferred-lifetime 28800;</div> <div style="color:#00000a;">option dhcp-renewal-time 3600;</div> <div style="color:#00000a;">option dhcp-rebinding-time 7200;</div> <div style="color:#00000a;">allow leasequery;</div> <div style="color:#00000a;">option dhcp6.name-servers 2404:a800:1000:d:7800::e, 2404:a800:1000:d:7800::f;</div> <div style="color:#00000a;">option dhcp6.domain-search "gstn.local";</div> <div style="color:#00000a;"><nowiki>##option dhcp6.preference 255;</nowiki></div> <div style="color:#00000a;"><nowiki>##option dhcp6.rapid-commit;</nowiki></div> <div style="color:#00000a;">option dhcp6.info-refresh-time 2160;</div> <div style="color:#00000a;">dhcpv6-lease-file-name "/var/lib/dhcpd/dhcpd6.leases";</div> <div style="color:#00000a;">subnet6 2404:a800:1000:d:7800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:7800::90 2404:a800:1000:d:7800::91;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:2000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:2000::b 2404:a800:1000:d:2000::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:0800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:800::b 2404:a800:1000:d:800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:1800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:1800::b 2404:a800:1000:d:1800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:2800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:2800::b 2404:a800:1000:d:2800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:3000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:3000::b 2404:a800:1000:d:3000::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:3800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:3800::b 2404:a800:1000:d:3800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:4800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:4800::b 2404:a800:1000:d:4800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:5000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:5000::b 2404:a800:1000:d:5000::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:5800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:5800::b 2404:a800:1000:d:5800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:6000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:6000::b 2404:a800:1000:d:6000::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:6800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:6800::b 2404:a800:1000:d:6800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:b800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:b800::b 2404:a800:1000:d:b800::85;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">'''Secondary Server''':</div> <div style="color:#00000a;">DHCPv6 configuration file:</div> ''vi /etc/dhcp/dhcpd6.conf'' <div style="color:#00000a;">default-lease-time 28800;</div> <div style="color:#00000a;">preferred-lifetime 28800;</div> <div style="color:#00000a;">option dhcp-renewal-time 3600;</div> <div style="color:#00000a;">option dhcp-rebinding-time 7200;</div> <div style="color:#00000a;">allow leasequery;</div> <div style="color:#00000a;">option dhcp6.name-servers 2404:a800:1000:d:7800::e, 2404:a800:1000:d:7800::f;</div> <div style="color:#00000a;">option dhcp6.domain-search "gstn.local";</div> <div style="color:#00000a;"><nowiki>##option dhcp6.preference 255;</nowiki></div> <div style="color:#00000a;"><nowiki>##option dhcp6.rapid-commit;</nowiki></div> <div style="color:#00000a;">option dhcp6.info-refresh-time 2160;</div> <div style="color:#00000a;">dhcpv6-lease-file-name "/var/lib/dhcpd/dhcpd6.leases";</div> <div style="color:#00000a;">subnet6 2404:a800:1000:d:7800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:7800::92 2404:a800:1000:d:7800::93;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:2000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:2000::88 2404:a800:1000:d:2000::98;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:0800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:800::88 2404:a800:1000:d:800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:1800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:1800::88 2404:a800:1000:d:1800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:2800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:2800::88 2404:a800:1000:d:2800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:3000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:3000::88 2404:a800:1000:d:3000::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:3800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:3800::88 2404:a800:1000:d:3800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:4800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:4800::88 2404:a800:1000:d:4800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:5000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:5000::88 2404:a800:1000:d:5000::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:5800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:5800::88 2404:a800:1000:d:5800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;"></div> <div style="color:#00000a;"></div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:6000::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:6000::88 2404:a800:1000:d:6000::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:6800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:6800::88 2404:a800:1000:d:6800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">subnet6 2404:a800:1000:000d:b800::/69 {</div> <div style="color:#00000a;">range6 2404:a800:1000:d:b800::88 2404:a800:1000:d:b800::100;</div> <div style="color:#00000a;">}</div> <div style="color:#00000a;">In HA, DHCP servers are in continuos syncronization with each other. You can get it from /var/log/messages file of DHCP server.</div> # ## '''Active Directory via SAMBA4''' Samba AD DC Features* LDAP * Kerberos * X.500 complaint * Windows Domain Controller * Centralized Identity Management Server * Authentication * Authorization * SMB / SMB2 / CIFS * Windows machines join AD natively * Ipv4 and Ipv6 ready * SSL over TCP as the Transporting Protocol ( [https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_(LDAPS)_on_a_Samba_AD_DC https://wiki.samba.org/index.php/Configuring_LDAP_over_SSL_%28LDAPS%29_on_a_Samba_AD_DC] ) * 7 FSMO roles ** PDC Emulator ** RID Master ** Schema Master ** Domain Naming Master ** Infrastructure Master ** Domain DNS Zone Master role ** Forest DNS Zone Master role At GSTN , AD and ADC will be implemented# ## ### '''Forest and Domain design''' Considering the Need of GSTN , there is no need to have Multi forest or Multi domain . There will be a single forest with a single domain as “GSTN.local” . Environment will have one domain controller in a domain and additional domain controllers to the domain is added to improve the availability and reliability of network services. Adding additional domain controllers can help provide fault tolerance, balance the load of existing domain controllers, and provide additional infrastructure support to sites. More than one domain controller in a domain makes it possible for the domain to continue to function if a domain controller fails or must be disconnected. Multiple domain controllers can also improve performance by making it easier for clients to connect to a domain controller when logging on to the network. [[Image:GSTNDIRECTORY21.png]] <div style="color:#00000a;"></div> Distribution of FSMO roles for Active Directory DC and Addition DC will be Active Directory DC* ** PDC Emulator ** RID Master ** Schema Master ** Domain Naming Master ** Infrastructure Master ** Domain DNS Zone Master role ** Forest DNS Zone Master role Below screen shot shows the 7 fsmo roles on PDC. [[Image:GSTNDIRECTORY22.png]] There is no FSMO roles on ADC. In case of DC failure the ADC needs to be promoted as DC .# ## ### '''Time Synchronization''' Time synchronization design and setup are very important for an Active Directory environment. This is because time synchronization issues lead to Kerberos authentication failures once the maximum tolerance for computer clock synchronization (By default is five (5) minutes) is exceeded. We have 2 NTP servers running on RHEL for the time synchronization purpose . Active directory will update time or synchronize time from these NTP servers. NTP configuration done on PDC as in below screen shot. [[Image:GSTNDIRECTORY23.png]] We have created NTP policy, all client computers will sync the time from AD only. [[Image:GSTNDIRECTORY24.png]] # ## ### '''AD Group Policies''' Group Policy The guiding principle for Group Policy design is OU design and IT administrative model and together they form the below benefits* To enable delegation of administration * To scope the application of Group Policy Objects While designing the group policy the required consideration from key stake holders and best practices are consulted. Group Policy settings are passed from parent containers down to child containers. This means that a policy that is applied to a parent container applies to all the containers including users and computers that are below the parent containers in the Active directory tree hierarchy. However if you specifically assign a group policy for a child container that contradicts the parent container policy, the child container’s policy overrides the parent group policy. If policies are not contradictory, both are implemented. Group Policies are processed in the following order: * Local Group policy * Site Group Policy * Domain Group Policy * Organizational unit Group Policy [[Image:GSTNDIRECTORY25.png]] We are selecting No Override option at GSTN so that child containers cannot override any policy setting set by higher level GPO. This option is not turned on by default and must be turned on in each GPO where it’s wanted. In Addition with Default Domain and Domain Controller policy will apply set of CIS (Center for Internet Security) recommended policy for Active Directory like Account, Audit, Security, Interactive Login, Event Log Settings, Network Services, Network Access, User Account Control etc for GSTN. <span style="background-color:#ffff00;">Please Note the AD Based policies will only be Applicable for Windows based environments and its components. These policies will not be applicable any of Linux environment and its components</span>.# ## ### '''Accounts Policy''' Account policies control password restrictions and account lockouts and help protecting the system from unauthorized access. Account policies apply to all user accounts at the same time locally or domain-wide, depend on the scope where the policy is defined. {| style="border-spacing:0;width:14.605cm;" |- style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Account Policy |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Account lockout threshold' to '7 invalid logon attempt(s)' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Account lockout duration' to '10 or more minute(s)' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Reset account lockout counter after' to '10 minute(s)' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Minimum password length' to '8 or more character(s)' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Enforce password history' to '24 or more password(s) |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Password must meet complexity requirements' to 'Enabled' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Store passwords using reversible encryption' to 'Disabled |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Minimum password age' to '1 or more day(s)' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Set 'Maximum password age' to '30 or fewer days' |- |} Below screen shot is showing password policy which has been defined. <div style="margin-left:0cm;margin-right:0cm;">[[Image:GSTNDIRECTORY26.png]]</div># ## ### {{anchor|RefHeading2653241649886}} '''Audit Policy''' Auditing enhancements in Active Directory support the needs of IT Admins of Windows environments who are responsible for implementing, maintaining, and monitoring the ongoing security of an organization's Windows related physical and information assets. These settings can help administrators to get answers of following: Who is accessing our assets? What assets are they accessing? When and where did they access them? How did they obtain access? '''Advanced Audit Policies ''' {| style="border-spacing:0;width:14.605cm;" |- style="background-color:#ffffff;border:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || '''Account Management''' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit Computer Account Management “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit User Account Management “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || '''Logon/Logoff''' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit Account Lockout “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit User / Device Claims “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit logoff “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit Logon “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit Other Logon/Logoff Events “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || '''Policy Change''' |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit Audit Policy Change “Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || Audit Authentication Policy Change Success” |- style="background-color:#ffffff;border-top:none;border-bottom:0.5pt solid #000000;border-left:0.5pt solid #000000;border-right:0.5pt solid #000000;padding-top:0cm;padding-bottom:0cm;padding-left:0.182cm;padding-right:0.191cm;" || |- |} [[Image:GSTNDIRECTORY27.png]] <div style="color:#00000a;">'''SAMBA SECONDARY DOMAIN CONTROLLER'''</div> <div style="color:#00000a;">With a Primary Domain Controller (PDC) on the network it is best to have a Backup Domain Controller (BDC) as well. This will allow clients to authenticate in case the PDC becomes unavailable. Adding further DCs, will provide failure safety, high availability and load balancing. </div> [[Image:GSTNDIRECTORY28.png]] '''Rsysnc based SysVol replication.''' Samba AD currently doesn't provide support for SysVol replication. To achive this important feature in a Multi-DC environment, until it's implemented, workarounds are necessary to keep it in sync. This HowTo provides a basic workaround solution based on rsync. This tool is unidirectional, this means files can only be transferred in one direction. That's why for rsync-based SysVol replication, you have to choose one DC on which you do all modifications like GPO edits, logon script changes, etc. A good choice for this "master" host is the one that contains the FSMO roles. All other DC's retrieve the changes from this host, this is because modifications on them are overwritten when syncing. '''1. Setup SysVol replication:''' a. Install rsync on the pdc by runing below command. <nowiki># yum install rsync</nowiki> Open '''/etc/rsyncd.conf '''file and make below entries. [SysVol] path = /usr/local/samba/var/locks/sysvol/ comment = Samba Sysvol Share uid = root gid = root read only = yes auth users = sysvol-replication secrets file = /usr/local/samba/etc/rsyncd.secret Create a file '''/usr/local/samba/etc/rsyncd.secret'''. ''<nowiki># vi /usr/local/samba/etc/rsyncd.secret</nowiki>'' Make below entry in '''rsyncd.secret''' file. sysvol-replication:Pa$$w0rD and set 600 permission on this file. <nowiki>#</nowiki>'' chmod 600 /usr/local/samba/etc/rsyncd.secret'' Restart rsyncd services. ''<nowiki># systemctl restart rsyncd.service</nowiki>'' Setup on secondary Domain Controller a. Install rsync on the adc by runing below command. ''<nowiki># yum install rsync</nowiki>'' Create a password file /usr/local/samba/etc/rsync-sysvol.secret. ''<nowiki># vi /usr/local/samba/etc/rsync-sysvol.secret</nowiki>'' Fill it with the password you set on the PDC for the sysvol-replication rsync account. ''Pa$$w0rD'' Set 600 permission on this file and restart rsync service. ''<nowiki># chmod 600 /usr/local/samba/etc/rsyncd.secret</nowiki>'' ''<nowiki># systemctl restart rsyncd.service</nowiki>'' For replicating the SysVol folder, run the following command (--dry-run means that no modifications are actually made): ''<nowiki># /usr/bin/rsync --dry-run -XAavz --delete-after --password-file=/usr/local/samba/etc/rsync-sysvol.secret rsync://sysvol-replication@172.18.101.14/SysVol/ /usr/local/samba/var/locks/sysvol/</nowiki>'' If everything looks sane, run the command without the --dry-run option and let rsync do the replication. To automate synchronisation, run the command via cron. ''<nowiki># */2 * * * * /usr/bin/rsync -XAavz --delete-after --password-file=/usr/local/samba/etc/rsync-sysvol.secret rsync://sysvol-replication@172.18.101.14/SysVol/ /usr/local/samba/var/locks/sysvol/</nowiki>'' [[Image:GSTNDIRECTORY29.png]] = Demote a Samba AD DC = <div style="margin-left:0cm;margin-right:0cm;">Whenever a Domain Controller needs to be removed from your domain, for what ever reason, you will have to demote it.</div> = Demote a working Domain Controller. = <div style="margin-left:0cm;margin-right:0cm;">Follow this section if your DC is accessible and working. </div>* <div style="margin-left:1.247cm;margin-right:0cm;">Log into the DC you want to demote. </div> * <div style="margin-left:1.247cm;margin-right:0cm;">Verify that the DC is not the last one remaining in the domain! </div> * <div style="margin-left:1.247cm;margin-right:0cm;">Make sure this DC does not contain any [https://wiki.samba.org/index.php/Flexible_Single-Master_Operations_(FSMO)_roles FSMO role]: </div> <div style="color:#00000a;"></div> <div style="color:#00000a;">To check FSMO roles hit below command.</div> ''<nowiki># /usr/local/samba/bin/samba-tool fsmo show</nowiki>'' == Transferring a FSMO Role == * <div style="margin-left:1.247cm;margin-right:0cm;">Log on to the DC, that should be the new owner of the role you want to transfer. </div> * <div style="margin-left:1.247cm;margin-right:0cm;">Transfer the role to the DC, by executing the following command: </div> ''<nowiki># /usr/local/samba/bin/samba-tool fsmo transfer --role=all</nowiki>'' Ensure that the role was transferred ('samba-tool fsmo show'). [[Image:GSTNDIRECTORY30.png]] '''Demote the DC: ''' <div style="color:#00000a;">Run below command to demote dc.</div> ''<nowiki># /usr/local/samba/bin/samba-tool domain demote -Uadministrator</nowiki>'' <div style="color:#00000a;">Using spdc.gstntest.com as partner server for the demotion</div> <div style="color:#00000a;">Password for [GSTNTEST\administrator]:</div> <div style="color:#00000a;">Desactivating inbound replication</div> <div style="color:#00000a;">Asking partner server spdc.gstntest.com to synchronize from us</div> <div style="color:#00000a;">Changing userControl and container</div> <div style="color:#00000a;">Demote successfull</div> '''Demote a DC that isn't accessible any more''' <div style="color:#00000a;">Follow this section if your DC is not accessible any more - e. g. by hardware failure - and it surely will never come back into the network. </div> <div style="color:#00000a;">Run the following command on one of the remaining, working Domain Controllers: </div> <div style="color:#00000a;"><nowiki>#</nowiki>'' /usr/local/samba/bin/samba-tool domain demote –remove-other-dead-server=sadc''</div> = Verifying that nothing was left = The following steps are done on a Windows computer having [https://wiki.samba.org/index.php/Installing_RSAT RSAT installed]. '''Warning: The following are just cleanup steps, if something was left after a demote! It's not a replacement for the demote process itself!''' : <div style="margin-left:1.247cm;margin-right:0cm;">Open „Active Directory Users and Computers“ </div> : <div style="margin-left:2.247cm;margin-right:0cm;">Go to the container „Domain Controllers“ and verify that the demoted DC was removed. If not, remove the account manually. This would also cleanup metadata. </div> = Seizing FSMO Roles = = Difference of Transferring and Seizing FSMO Roles = Whenever it's possible, you should transfer FSMO roles and do not seize them! Transferring is the recommended and cleaner way. But it requires that the DC, which currently owns the role you want to transfer, is still working and connected to the network. Transferring makes the old DC know that it does not own the role(s) any more. If the DC is broken (e. g. hardware defect) and will never come back again, then you can seize the role on a remaining DC. It is very important that the old DC will never be connected to the network again, if it is connected again, this will cause conflicts and lead to an inconsistent AD. This is because the old DC will not notice the change and still feel responsible for tasks related to the role. = How to Handle Situations Where a DC with FSMO Roles Is Offline = There are three situations to distinguish: 1. The downtime is planned and the DC will come back soon (reboot, hardware replacement, etc.): <div style="margin-left:1cm;margin-right:0cm;">In this case, you have to decide, to temporarily transfer the roles to a different DC or be aware of the effects during the downtime. </div> 2. The DC should be demoted: <div style="margin-left:1cm;margin-right:0cm;">Transfer the roles to a different DC, before you demote. </div> 3. The DC is offline because of a problem: <div style="margin-left:1cm;margin-right:0cm;">1. Don't panic! </div> <div style="margin-left:1cm;margin-right:0cm;">2. Depending on the kind of role(s) that were on the DC, the consequences may be different. Make sure that you find out which roles are affected and what it means for your forest. See [https://wiki.samba.org/index.php/Transfering_/_seizing_FSMO_roles#The_seven_FSMO_roles The seven FSMO roles]. </div> <div style="margin-left:1cm;margin-right:0cm;">3. Try repairing the broken DC and connect it to the network again. But never restore it from a backup, if at least one DC in the domain is still working. The replication could mix up your directory! </div> <div style="margin-left:1cm;margin-right:0cm;">4. If there is no chance to get the DC back again, seize the roles on a remaining DC and [https://wiki.samba.org/index.php/Demote_a_Samba_AD_DC demote the broken one]. </div> <div style="color:#00000a;">To check FSMO roles hit below command.</div> ''<nowiki># /usr/local/samba/bin/samba-tool fsmo show</nowiki>'' == Seizing a FSMO Role == * <div style="margin-left:1.247cm;margin-right:0cm;">Log on to the DC, that should be the new owner of the role you want to transfer. </div> * <div style="margin-left:1.247cm;margin-right:0cm;">Seize the role to the current DC, by executing the following command: </div> ''<nowiki># /usr/local/samba/bin/samba-tool fsmo seize --role=all</nowiki>'' Attempting transfer... Transfer unsuccessful, seizing... FSMO seize of '...' role successful* <div style="margin-left:1.247cm;margin-right:0cm;">Ensure that the role was transferred ('samba-tool fsmo show'). </div> * <div style="margin-left:1.247cm;margin-right:0cm;">Make sure, that the old DC is never connected to the network again! </div> # ## '''SAMBA integrated CUPS ( Print Server )'''[[Image:GSTNDIRECTORY31.png]] A print server accepts print jobs from network computers, queues them locally and then sends them to the appropriate printers. As well as having domain and file service capabilities, Samba can also act as a MS Windows compatible print server. While Samba provides the interface to Windows/SMB machines, CUPS or LDP is used by Samba to send print jobs to the devices. CUPS provides a mechanism that allows print jobs to be sent to printers in a standard fashion. The print-data goes to a scheduler which sends jobs to a filter system that converts the print job into a format the printer will understand. The filter system then passes the data on to a backend—a special filter that sends print data to a device or network connection. The system makes extensive use of PostScript and rasterization of data to convert the data into a format suitable for the destination printer. The CUPS scheduler implements Internet Printing Protocol (IPP) over HTTP/1.1. A helper application (cups-lpd) converts Line Printer Daemon protocol (LPD) requests to IPP. The scheduler also provides a web-based interface for managing print jobs, the configuration of the server, and for documentation about CUPS itself. CUPS can process a variety of data formats on the print server. It converts the print-job data into the final language/format of the printer via a series of filters. It uses MIME types for identifying file formats. The backends are the ways in which CUPS sends data to printers. There are several backends available for CUPS: parallel, serial, and USB ports, cups-pdf PDF Virtual Printing, as well as network backends that operate via the IPP, JetDirect (AppSocket), Line Printer Daemon ("LPD"), and SMB protocols. CUPS integrated with SAMBA supports multiple end user operating systems – e.g. Linux all flavors (Desktop OS and Server OS, Windows 7 and higher, Windows server 2003 and higher, Mac OS. == SMB.CONF Configuration. == '''To integrated '''CUPS with samba i m'''ade below entries in smb.conf.''' [[Image:GSTNDIRECTORY32.png]] '''CUPS web-based administration interface''' On all platforms, CUPS has a web-based administration interface that runs on port 631. It particularly helps the need to monitor print jobs and add print queues and printers remotely. This interface is with an enhanced administration interface that allows users to add, modify, delete, configure, and control classes, jobs, and printers. It Supports reports/ monitoring, Auditing and tracking of print queues . It will also do the centralized allocation /DE-allocation of Network printers to the users. [[Image:GSTNDIRECTORY33.png]] '''CUPS quotas''' CUPS supports page and size-based '''quotas''' for each printer. The quotas are tracked individually for each user, but a single set of limits applies to all users for a particular printer. CUPS '''logsevery page''' that is printed on a system to the ''page_log'' file. Page logging is only available for drivers that provide page accounting information, typically all PostScript and CUPS raster devices. Raw queues and queues using third-party solutions such as Foomatic generally do not have useful page accounting information available. Structure at GSTN : The HP Laserjet Pro M202dw printers act as print servers and authenticate against the Samba AD. Quota can be deploye only from command line. Below are the commands to deploy quota: '''<nowiki># lpadmin -p ProLaserJet -o job-quota-period=604800 -o job-k-limit=1024 </nowiki>''' This sets a limit of a file size of 1 MB (added-up) for each user on the existing printer "''ProLaserJet''" during one week. '''<nowiki># lpadmin -p ProLaserJet -o job-quota-period=604800 -o job-page-limit=100 </nowiki>''' This sets a limit of 100 pages (added-up) for each user on the existing printer "''ProLaserJet''" during one week. '''<nowiki># lpadmin -p ProLaserJet -o job-quota-period=604800 -o job-k-limit=1024 -o job-page-limit=100 </nowiki>''' >>A day is 60x60x24=86400, a week is 60x60x24x7=604800, and a month is 60x60x24x30=2592000 seconds.) This sets a combined limit of 1 MB (added-up) and 100 pages (added-up) for each user of existing printer "''ProLaserJet''" during one week. Whichever limit is reached first will take effect. <div style="color:#00000a;">[[Image:|top]]</div>
Summary:
Please note that all contributions to TetraWiki may be edited, altered, or removed by other contributors. If you do not want your writing to be edited mercilessly, then do not submit it here.
You are also promising us that you wrote this yourself, or copied it from a public domain or similar free resource (see
TetraWiki:Copyrights
for details).
Do not submit copyrighted work without permission!
Cancel
Editing help
(opens in new window)
Template used on this page:
Template:Anchor
(
edit
)