You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7 DHCP服务器无法响应UEFI PXE DISCOVER请求

CentOS 7 DHCP服务器无法响应UEFI PXE DISCOVER请求

我正在尝试把CentOS 7服务器配置成支持UEFI的PXE DHCP服务器,已经对dhcpd.conf做了好几次修改,但都没看到效果。

当前dhcpd.conf配置

allow booting;

allow bootp;

max-lease-time 120;

default-lease-time 120;

option domain-name "domain.tld";

option domain-name-servers 192.168.1.9, 192.168.1.10;

option space pxe;

option pxe.magic code 208 = string;

option pxe.configfile code 209 = text;

option pxe.pathprefix code 210 = text;

option pxe.reboottime code 211 = unsigned integer 32;

option pxe.mtftp-ip code 1 = ip-address;

option pxe.mtftp-cport code 2 = unsigned integer 16;

option pxe.mtftp-sport code 3 = unsigned integer 16;

option pxe.mtftp-tmout code 4 = unsigned integer 8;

option pxe.mtftp-delay code 5 = unsigned integer 8;

option pxe.discovery-control code 6 = unsigned integer 8;

option pxe.discovery-mcast-addr code 7 = ip-address;

option architecture-type code 93 = unsigned integer 16;

class "pxe" {

match if substring (option vendor-class-identifier, 0, 9) = "PXEClient";

option vendor-class-identifier "PXEClient";

vendor-option-space pxe;

option pxe.mtftp-ip 0.0.0.0;

if option architecture-type = 00:07 {

filename "shim.efi";

} else {

filename "pxelinux/pxelinux.0";

}

}

subnet 192.168.1.0 netmask 255.255.255.0 {

not authoritative;

}

# PXE Network

########################################################################

subnet 172.16.10.0 netmask 255.255.255.0 {

authoritative;

allow unknown-clients;

next-server 172.16.10.3;

option routers 172.16.10.1;

option broadcast-address 172.16.10.255;

pool {

range dynamic-bootp 172.16.10.10 172.16.10.49;

allow members of "pxe";

}

pool {

range 172.16.10.50 172.16.10.99;

allow members of "pxe";

}

pool {

range 172.16.10.100 172.16.10.149;

}

}

host dev2 {

hardware ethernet ec:f4:bb:d8:59:9f;

option host-name "dev2.domain.tld";

}

host dev1 {

hardware ethernet ec:f4:bb:bf:c8:e7;

option host-name "dev1.domain.tld";

}

手动启动DHCP服务器的日志

我手动启动服务器查看日志,输出如下:

[root@kickstart dhcp]# /usr/sbin/dhcpd -f -cf /etc/dhcp/dhcpd.conf -user dhcpd -group dhcpd --no-pid -4 -d eth1

Internet Systems Consortium DHCP Server 4.2.5

Copyright 2004-2013 Internet Systems Consortium.

All rights reserved.

For info, please visit https://www.isc.org/software/dhcp/

Not searching LDAP since ldap-server, ldap-port and ldap-base-dn were not specified in the config file

Wrote 0 class decls to leases file.

Wrote 0 deleted host decls to leases file.

Wrote 0 new dynamic host decls to leases file.

Wrote 0 leases to leases file.

Listening on LPF/eth1/52:54:00:fa:4d:fc/172.16.10.0/24

Sending on   LPF/eth1/52:54:00:fa:4d:fc/172.16.10.0/24

Sending on   Socket/fallback/fallback-net

抓包分析结果

我在服务器上做了数据包捕获,能看到DHCP DISCOVER包进来,但服务器始终没有响应:

$tcpdump -vvvvvvvvvvvvvvvvvvvvv -ttttt -i eth1

00:37:05.338983 IP (tos 0x0, ttl 64, id 43032, offset 0, flags [none], proto UDP (17), length 375)

0.0.0.0.bootpc > 255.255.255.255.bootps: [udp sum ok] BOOTP/DHCP, Request from ec:f4:bb:d8:59:9f (oui Unknown), length 347, xid 0x777a345e, secs 12, Flags [Broadcast] (0x8000)

Client-Ethernet-Address ec:f4:bb:d8:59:9f (oui Unknown)

Vendor-rfc1048 Extensions

Magic Cookie 0x63825363

DHCP-Message Option 53, length 1: Discover

MSZ Option 57, length 2: 1464

Parameter-Request Option 55, length 35:

Subnet-Mask, Time-Zone, Default-Gateway, Time-Server

IEN-Name-Server, Domain-Name-Server, Hostname, BS

Domain-Name, RP, EP, RSZ

TTL, BR, YD, YS

NTP, Vendor-Option, Requested-IP, Lease-Time

Server-ID, RN, RB, Vendor-Class

TFTP, BF, GUID, Option 128

Option 129, Option 130, Option 131, Option 132

Option 133, Option 134, Option 135

GUID Option 97, length 17: 0.68.69.76.76.84.0.16.57.128.75.180.192.79.67.52.50

NDI Option 94, length 3: 1.3.16

ARCH Option 93, length 2: 7

Vendor-Class Option 60, length 32: "PXEClient:Arch:00007:UNDI:003016"

END Option 255, length 0

系统相关信息

网络配置

$ip addr

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1

link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00

inet 127.0.0.1/8 scope host lo

valid_lft forever preferred_lft forever

2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000

link/ether 52:54:00:59:e9:5d brd ff:ff:ff:ff:ff:ff

inet 192.168.1.203/24 brd 192.168.1.255 scope global eth0

valid_lft forever preferred_lft forever

3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000

link/ether 52:54:00:fa:4d:fc brd ff:ff:ff:ff:ff:ff

inet 172.16.10.3/24 brd 172.16.10.255 scope global eth1

valid_lft forever preferred_lft forever

SELinux状态

$ sestatus

SELinux status:                 enabled

SELinuxfs mount:                /sys/fs/selinux

SELinux root directory:         /etc/selinux

Loaded policy name:             targeted

Current mode:                   permissive

Mode from config file:          enforcing

Policy MLS status:              enabled

Policy deny_unknown status:     allowed

Max kernel policy version:      28

防火墙状态

$ firewall-cmd --state

not running

DHCP进程监听情况

$ netstat -nap | grep dhcp

udp        0      0 0.0.0.0:67              0.0.0.0:*                           21050/dhcpd

udp        0      0 0.0.0.0:67              0.0.0.0:*                           17697/dhcpd

udp        0      0 0.0.0.0:67              0.0.0.0:*                           15042/dhcpd

raw        0      0 0.0.0.0:1               0.0.0.0:*               7           21050/dhcpd

raw        0      0 0.0.0.0:1               0.0.0.0:*               7           17697/dhcpd

raw        0      0 0.0.0.0:1               0.0.0.0:*               7           15042/dhcpd

unix  2      [ ]         DGRAM                    94586    15042/dhcpd

unix  2      [ ]         DGRAM                    107361   17697/dhcpd

unix  2      [ ]         DGRAM                    110207   21050/dhcpd

iptables规则

$ iptables-save

<bash>$

环境说明

这个PXE服务器是运行在CentOS 7宿主机上的KVM/QEMU虚拟机,宿主机上em1绑定到br1,em2绑定到br2,em3绑定到br3,em4绑定到br4,每个网卡都连接到对应VLAN的交换机;虚拟机的eth0连接br1,eth1连接br4。PXE客户端是物理服务器,和DHCP服务器之间有多个交换机。

更新情况

我更新了上面的配置后,在同网段配置了一个标准Linux客户端,它能正常获取租约,所以问题应该出在UEFI PXE客户端本身。这里有一份单次请求的抓包内容(base64编码)。

备注:内容来源于stack exchange,提问作者Justin Killen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 16:02:46