PowerShell切换凭据后执行DHCP故障转移复制命令失败求助
DHCP故障转移复制权限问题解决方案
问题说明
脚本可正常在主DHCP服务器(DHCPprimary.net)遍历作用域并设置租期,但执行Invoke-DhcpServerv4FailoverReplication命令时失败,报错显示无法访问备用DHCP服务器(DHCPSecondary.net)。核心原因是凭据无法在服务器间跳转——该命令需要访问故障转移伙伴服务器,但当前会话的权限无法传递到目标服务器。
报错信息
Failed to get superscope information on DHCP server DHCPSecondary.net. + CategoryInfo : PermissionDenied: (DHCPSecondary.net:root/Microsoft/...overReplication) [Invoke-DhcpServerv4FailoverReplication], CimException + FullyQualifiedErrorId : WIN32 5,Invoke-DhcpServerv4FailoverReplication + PSComputerName : DHCPSecondary.net
原始脚本
$destinationServer = "DHCPprimary.net" $Credentials = Get-Credential -Message "Enter credentials" $Sessionnew = New-PSSession -Credential $Credentials -ComputerName $destinationServer $sourcedata = Invoke-Command -Session $Sessionnew -AsJob { $UserLeaseDuration = "2.00:00:00" $GuestLeaseDuration = "0.02:00:00" $ServerLeaseDuration = "7.00:00:00" $scopeList = Get-DhcpServerv4Scope foreach ($scope in $scopeList){ switch -regex ($scope.name) { "WIFI-CORP" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId -LeaseDuration $UserLeaseDuration} "Wired" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId -LeaseDuration $UserLeaseDuration} "Server" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId -LeaseDuration $ServerLeaseDuration} Default {write-host ($scope.name)} } Invoke-DhcpServerv4FailoverReplication -scope $scope.ScopeId -Force } } Receive-Job -Job $sourcedata -Wait -AutoRemoveJob
解决方法
方法1:启用Kerberos约束委派(域环境推荐)
- 在Active Directory用户和计算机中,找到主DHCP服务器(DHCPprimary.net)的计算机账户
- 右键属性 → 「委派」选项卡,选择「信任此计算机来委派指定的服务」
- 添加备用DHCP服务器(DHCPSecondary.net)的「DHCP Server」服务和「WMI」服务(对应CIM访问权限)
- 保存设置后,重启主DHCP服务器的DHCP服务,再重新运行脚本
方法2:使用CredSSP认证传递凭据
如果无法修改AD委派设置,可采用CredSSP方式传递跨服务器凭据:
- 在本地客户端以管理员权限执行:
Enable-WSManCredSSP -Role Client -DelegateComputer DHCPprimary.net
- 在主DHCP服务器以管理员权限执行:
Enable-WSManCredSSP -Role Server
- 修改脚本中创建PSSession的命令,指定CredSSP认证:
$Sessionnew = New-PSSession -Credential $Credentials -ComputerName $destinationServer -Authentication CredSSP
- 重新运行脚本即可
方法3:直接在备用服务器触发复制
调整脚本逻辑,分别连接主/备用服务器,在备用服务器上执行复制命令:
$destinationServer = "DHCPprimary.net" $secondaryServer = "DHCPSecondary.net" $Credentials = Get-Credential -Message "Enter credentials" # 连接主服务器修改租期 $primarySession = New-PSSession -Credential $Credentials -ComputerName $destinationServer Invoke-Command -Session $primarySession -AsJob { $UserLeaseDuration = "2.00:00:00" $ServerLeaseDuration = "7.00:00:00" $scopeList = Get-DhcpServerv4Scope foreach ($scope in $scopeList){ switch -regex ($scope.name) { "WIFI-CORP" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId -LeaseDuration $UserLeaseDuration} "Wired" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId -LeaseDuration $UserLeaseDuration} "Server" {Set-DhcpServerv4Scope -ScopeId $scope.ScopeId -LeaseDuration $ServerLeaseDuration} Default {write-host ($scope.name)} } } } | Receive-Job -Wait -AutoRemoveJob # 连接备用服务器执行复制 $secondarySession = New-PSSession -Credential $Credentials -ComputerName $secondaryServer Invoke-Command -Session $secondarySession -AsJob { $scopeList = Get-DhcpServerv4Scope foreach ($scope in $scopeList){ Invoke-DhcpServerv4FailoverReplication -ScopeId $scope.ScopeId -Force } } | Receive-Job -Wait -AutoRemoveJob Remove-PSSession $primarySession, $secondarySession
内容的提问来源于stack exchange,提问作者DevilWAH
相关产品推荐
相关产品推荐

