You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell切换凭据后执行DHCP故障转移复制命令失败求助

DHCP故障转移复制权限问题解决方案

问题说明

脚本可正常在主DHCP服务器(DHCPprimary.net)遍历作用域并设置租期,但执行Invoke-DhcpServerv4FailoverReplication命令时失败,报错显示无法访问备用DHCP服务器(DHCPSecondary.net)。核心原因是凭据无法在服务器间跳转——该命令需要访问故障转移伙伴服务器,但当前会话的权限无法传递到目标服务器。

报错信息

Failed to get superscope information on DHCP server
DHCPSecondary.net.
+ CategoryInfo          : PermissionDenied: (DHCPSecondary.net:root/Microsoft/...overReplication)
[Invoke-DhcpServerv4FailoverReplication], CimException
+ FullyQualifiedErrorId : WIN32 5,Invoke-DhcpServerv4FailoverReplication
+ PSComputerName        : DHCPSecondary.net

原始脚本

$destinationServer = "DHCPprimary.net"
$Credentials = Get-Credential -Message "Enter credentials"

$Sessionnew = New-PSSession -Credential $Credentials -ComputerName $destinationServer

$sourcedata = Invoke-Command -Session $Sessionnew -AsJob {
   
$UserLeaseDuration = "2.00:00:00"
$GuestLeaseDuration = "0.02:00:00"
$ServerLeaseDuration = "7.00:00:00"


$scopeList = Get-DhcpServerv4Scope 
foreach ($scope in $scopeList){
    switch -regex ($scope.name) 
    {
    "WIFI-CORP" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId  -LeaseDuration $UserLeaseDuration}
    "Wired" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId  -LeaseDuration $UserLeaseDuration}
    "Server" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId  -LeaseDuration $ServerLeaseDuration}
    Default {write-host ($scope.name)}
    }

    Invoke-DhcpServerv4FailoverReplication -scope $scope.ScopeId  -Force
}
    
} 

Receive-Job -Job $sourcedata -Wait -AutoRemoveJob

解决方法

方法1:启用Kerberos约束委派(域环境推荐)

  1. 在Active Directory用户和计算机中,找到主DHCP服务器(DHCPprimary.net)的计算机账户
  2. 右键属性 → 「委派」选项卡,选择「信任此计算机来委派指定的服务」
  3. 添加备用DHCP服务器(DHCPSecondary.net)的「DHCP Server」服务和「WMI」服务(对应CIM访问权限)
  4. 保存设置后,重启主DHCP服务器的DHCP服务,再重新运行脚本

方法2:使用CredSSP认证传递凭据

如果无法修改AD委派设置,可采用CredSSP方式传递跨服务器凭据:

  1. 在本地客户端以管理员权限执行:
Enable-WSManCredSSP -Role Client -DelegateComputer DHCPprimary.net
  1. 在主DHCP服务器以管理员权限执行:
Enable-WSManCredSSP -Role Server
  1. 修改脚本中创建PSSession的命令,指定CredSSP认证:
$Sessionnew = New-PSSession -Credential $Credentials -ComputerName $destinationServer -Authentication CredSSP
  1. 重新运行脚本即可

方法3:直接在备用服务器触发复制

调整脚本逻辑,分别连接主/备用服务器,在备用服务器上执行复制命令:

$destinationServer = "DHCPprimary.net"
$secondaryServer = "DHCPSecondary.net"
$Credentials = Get-Credential -Message "Enter credentials"

# 连接主服务器修改租期
$primarySession = New-PSSession -Credential $Credentials -ComputerName $destinationServer
Invoke-Command -Session $primarySession -AsJob {
    $UserLeaseDuration = "2.00:00:00"
    $ServerLeaseDuration = "7.00:00:00"

    $scopeList = Get-DhcpServerv4Scope 
    foreach ($scope in $scopeList){
        switch -regex ($scope.name) 
        {
        "WIFI-CORP" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId  -LeaseDuration $UserLeaseDuration}
        "Wired" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId  -LeaseDuration $UserLeaseDuration}
        "Server" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId  -LeaseDuration $ServerLeaseDuration}
        Default {write-host ($scope.name)}
        }
    }
} | Receive-Job -Wait -AutoRemoveJob

# 连接备用服务器执行复制
$secondarySession = New-PSSession -Credential $Credentials -ComputerName $secondaryServer
Invoke-Command -Session $secondarySession -AsJob {
    $scopeList = Get-DhcpServerv4Scope 
    foreach ($scope in $scopeList){
        Invoke-DhcpServerv4FailoverReplication -ScopeId $scope.ScopeId -Force
    }
} | Receive-Job -Wait -AutoRemoveJob

Remove-PSSession $primarySession, $secondarySession

内容的提问来源于stack exchange,提问作者DevilWAH

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 07:47:03