Shunze ¾Ç¶é > ·j´M > ·j´Mµ²ªG «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]

§@ªÌ ¤å³¹
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nWebUI TLS 1.0/1.1­·ÀI°ÝÃDÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Ãö©óCaptive Portal 8090 Port TLS1.0, 1.1ªº­·ÀI°ÝÃD¡A
°£¤F¥i¥H¦bDevice Access¤¤ª½±µÃö³¬ªA°È¥~¡A
¦b¶´Å骩¥»17.5.12«á¡A¥i¥H³z¹Lconsole¤U¹F¥H¤U«ü¥OÃö³¬TLS1.0¡C

set http_proxy captive_portal_tlsv1_0 on/off

¦b18.5¥H«á¡A¦A¦h¤FTLS1.1ª©¥»Ãö³¬«ü¥O¡C
set http_proxy captive_portal_tlsv1_1 on/off


¬d¬Ý³]©w«ü¥O¦p¤U¡C
show http_proxy





♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2025-02-06, 09:30 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nHA to HAÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

«È¤á¶R¤F¦h¥xSophos¨¾¤õÀð¡A¨Ã±N¨ä¤¤¥|¥x¥H¨â²ÕA/SªºHA¨Ó¦ê±µ¡A¥H´Á¦b¸ó¼Ó¼hªº±ø¥ó¤U¡AÁÙ¯àºû«ùHAªº°ª¥i¥Î©Ê¡C



¨º»ò°ÝÃD¨Ó¤F¡A¨C¥x³]³Æªº¨â±ø¦ê±µ½u¨s³º¬O­n¥ÎLACPÁÙ¬OLAGªº¤è¦¡²Õ¦¨¸s²Õ©O¡H


¨ä¹ê¤£½×¬OLACP©ÎLAG¡A¥¦³£¬O¥Hºô¥dªºµwÅ骬ªp¨Ó§PÂ_ºô¥dmeber¬O¦nÁÙ¬OÃa¡C
¥HLACP¨Ó»¡¡A¥¦¬O¥HActive/Activeªº¤è¦¡¨Ó¹B§@¡A



©Ò¥H­Y¥HLACP¨Ó¦ê±µ4¥x¨¾¤õÀð¡A¨º»ò¹ï¥ô¦ó¤@¥xPrimary node¦Ó¨¥¡A
¥¦¹ï±µªº¨â±iºô¥d³£¦³¦^À³¡A³£¬O¦nªº¡A
¥¦¦b¶Ç°e®É´N·|³z¹L¨â±iºô¥d¥h°µload sharing¡A¥H´£°ªºô¸ô³t«×¡C

µM¦Ó¹ïºÝªº¹ê»Ú±¡§Î«o¬O¥u¦³¤@¥x¦b¥¿±`¹B§@(A/S HAª¬ºA¤U)¡A
¾É­P¤F¥u¦³¤@¥bªº«Ê¥]·|³q¡A¥t¤@¥b¥¢±Ñ¡A³y¦¨¨¾¤õÀð¹B§@¤Wªº²§±`¡I


¨º»ò§ï¦¨Active/StandbyªºLAG¤£´N¦n¤F¡H
LAG member¤¤¥u¦³¤@±ø·|¹B§@¡A³o¼Ë¤£´N¨S¦³°ÝÃD¡ã



²z½×¤W¬O¦p¦¹¡A
¦ý«È¤á¦bMA©Î¶´Åé¤É®É«á¡A«o¤Sµo²{¤£·|³qªºª¬ªp¡I
»Ý­n¦bLAGªº¶i¶¥³]©w¤¤¡A«ü©w¡§¥D­n¤¶­±¡¨¨ì¥Ø«e³s±µªº¤¶­±¤~·|³q¡A
¤£¹L¤@¥¹HA failovder«á¡A¤S¤£³q¤F¡I³o¬O«ç»ò¦^¨Æ¡H


¶¶¤l²q´ú¬OMA/¶´Åé¤É¯Å«á¡A¨âºÝ¨¾¤õÀ𪺽u¸ô¬O¦P¤@®É¶¡±µ¤W¡A
¦ÓLAG¯Âºé´Nºô¥d¤¶­±ªºup/down¨Ó§PÂ_­þ¤@±i¬Oactive¡A­þ¤@±i¤S¬Ostandby¡A
¦Ó¦b³o­Ó·í¤U¡A§PÂ_¥ý«áªº®É¶¡®t¡A³y¦¨¤FLAGªºactiveºô¥dµLªk¹ï¦b¥¿½Tªº¹ïºÝºô¥d¤W¡A§¹¦¨³q¸ô¡C




¡i¸Ñ¨M¤è¦¡¦p¤U¡j

  1. ¥ý±N¨âºÝªºAuxiliary node³£¤U½u¡A
    ÅýPrimary node¥HStandaloneªº¨¤¦â¹B§@¡D



    ¦b³o±ø¥ó¤U¡A¥Ñ©óAuxiliary node¤£¦b¡A¨âºÝ¶Õ¥²±N¥¿½Tªººô¥d¼Ð°O¬°active§¹¦¨³s½u¡C

  2. ºô¸ô³q¤F«á¡A§â¤@¥xAuxiliary node¤W½u¡A«ì´_HA²ÕºA¡C



  3. ³Ì«á¦A§â¥t¤@¥xAuxiliary node¤W½u¡A«ì´_¨âºÝªºHA²ÕºA¡C



  4. ¥Ñ©óLAG memberºô¥d¤w¥¿½Tªº¼Ð°O¤Factive/standbyªº¨¤¦â¡A
    ¦b¨ä¤¤¤@²ÕHAµo¥Ífailover«á¡APrimary node·|Åܦ¨failed¨¤¦âµu¼ÈÂ÷½u¡A¦ÓAuxiliary node«h±µ¤âÅܦ¨Primary node¡A
    ³o®É¦]¬°failed¨¤¦âÂ÷½u¡Aºô¥d¥¢Áp¡A¦Ó±µ¤âªºPrimary nodeºô¥d¥¿±`¹B§@¡A
    ©Ò¥H·|IJµo¹ïºÝLAG member¤¤ªºactive/standby¨¤¦â¹ï½Õ¡A¦Ó»P·sªºPrimary node«Ø¥ß³s½u¡F¤Ï¤§¥çµM¡ã

©Ò¥H°ÝÃDªº®Ö¤ß¨Ã¤£¬O«ü©w¡§¥D­n¤¶­±¡¨³o¥ó¨Æ¡A
¦Ó¬OLAG member¯à§_¦b²Ä¤@®É¶¡»P¹ïºÝ«Ø¥ß¥¿½TªºÃö«Y¡C
­YÃö«Y«Ø¥ß¿ù»~¡A½Ð¨Ì·Ó¤W­z¤è¦¡¡AÅýLAGªºmember¯à¦¨¥\ªº¸ò¹ïºÝ«Ø¥ß¥¿½Tªº¨¤¦âÃö«Y¡C
«ü©w¡§¥D­n¤¶­±¡¨³o¥ó¨Æ¡A´N«O¯d¹w³]­È§Y¥i¡A¤£»Ý­n°Ê¥¦¡C

¸g«È¤á¤ÏÂЦh¦¸¤Á´«¨¾¤õÀð´ú¸Õ¡AÅçÃÒLAG memberªºÃö«Y¡A
¨âºÝºô¸ô³£¯à¶¶§Qªº¦bÂ_¤@­Ópingªº±¡ªp¤U¶¶§Q³s½u¡A²§±`ª¬ªp±Æ°£¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2025-01-20, 17:38 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nFtp-bounce attack°T®§Åã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

«È¤á¦b¤º³¡¬[³]¦nPassive FTP server«á¡A¤]§âftpbounce-prevention°Ñ¼Æ¥Ñcontrol§ï¬°data¤F¡A
FTP server¬Ý°_¨Ó¥i¥H¥¿±`¨Ï¥Î¡A
¦ý¦blog¤¤¡A«oÁ`¬O¦ñÀHµÛ Ftp-bounce attack ªº¿ù»~°T®§¡A
³o¥¿±`¶Ü¡H



¦b¶}caseµ¹­ì¼t«á¡A­ì¼t¤]¤£©ú¥Õ¬°¦ó·|¦p¦¹¡H
¦bÂà¥æ¶}µo¹Î¶¤¤ÀªR«á¡Aµo²{passive FTPªº³s½uµo°_¦æ¬°´N¸òFTP bounce attack¤@¼Ë¡A
©Ò¥HSFOS·|Åã¥Ü¥X¤@­Ó¹ïÀ³ªº§ðÀ»log¡C
¦ý³o¬O§_¬°§ðÀ»¨Æ¥ó¡AÁÙ¬O­n¥ÑºÞ²zªÌ¨Ó°µ§PÂ_...

­Y­n°±¤î¦¹Äµ§i°T®§¡ASophos´£¨Ñ¨âºØ¤è¦¡¡C
1. ©óadvanced shell¤¤¿é¤J¥H¤U«ü¥O¡A¦ý«ü¥O·|¦b­«¶}¾÷«á¥¢®Ä¡A»Ý©ó¨C¦¸­«¶}¾÷«á¦A¿é¤J¤@¦¸¡C

echo Y > /sys/module/nf_conntrack_ftp/parameters/loose


2. ©óadvanced shell¤¤¿é¤J¥H¤U«ü¥O¡A¥ý±¾¸üºÏ°Ï¡A±N«ü¥O¼g¦b¶}¾÷ºÏºÐ¡AÅýµ{¦¡©ó­«¶}¾÷«á¥D°Ê¦A°õ¦æ¤@¦¸«ü¥O¡C
¦ý¦¹¤èªk·|¦b¤É¯Å¶´Åé«á¥¢®Ä¡A¤É¯Å¶´Åé«á»Ý¦A°õ¦æ¤@¦¸¡C
mount -no remount, rw /
echo "echo Y > /sys/module/nf_conntrack_ftp/parameters/loose" >> /etc/sysinit_original


³z¹L¥H¤Wªº³B²z¤è¦¡¡AÁ`ºâ¥i¥HÅý³o­Ó°T®§¤£¦A¥X²{¤F¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2025-01-08, 17:29 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nAPIÀ³¥Î½d¨Ò¤§2-¤j¶q¿é¤JFQDNÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦³«È¤á¦b°Ý¡A±¡¸ê³æ¦ìµ¹ªº´c·NFQDN²M³æ¡ASophos¦³¨S¦³¿ìªk§å¦¸¶×¤J¡H

¶¶¤l¥J²Ó¥h¬d¤F¤@¤U¡ASFOS³£¤w¸g¨ì21ª©¤F¡A¦ýSophosÁÙ¬O¨S¦³³o­Ó¥\¯à...
¤£¹L¦³¦n¤ßªº¨Ï¥ÎªÌ´£¨Ñ¤F¦Û»sªºAPI script¡A¥i¥H³z¹LAPI¤j¶q¿é¤JIP»PFQDNª«¥ó¡A³sµ²¦p¤U¡C
Automated load of object through API from CSV!

³o­Óscript¶¶¤l¬Ý¤F¤@¤U¡Aµo²{¥¦¥u­nµy·L­×§ï¤@¤U¡A´N¥i¥H§¹¬ü²Å¦X«È¤á»Ý¨D¡I

­n­×§ï­þ¨Ç¤º®e©O¡H
­º¥ý¡AFQDN¸òIPª«¥ó¤£¤@¼Ë¡AIP¦³IP list¥i¥Î¡A¥i¥H¥H¤@­ÓIP listª«¥ó¦¬®e¦h­ÓIP¡A¨Ã®M¥Î¦b¨¾¤õÀð³W«h¤§¤¤Â²³æºÞ²z¡F
¦ýFQDN¨S¦³FQDN listª«¥ó¡A¨C¤@­ÓFQDN³£¬O¤@­Ó¿W¥ßª«¥ó¡A­Y­n±N¤j¶qªºFQDN¦C¤J©Úµ´²M³æ¡A¹ïºÞ²zªÌ¦Ó¨¥±N¬O¤@µ§¤£¤pªº­t¾á¡C

¤£¹LÁöµMFQDN¨S¦³FQDN list¥i¥Î¡A¦ý§Ú­Ì¥i¥H³z¹LFQDN group¨Ó¹F¦¨Ãþ¦ü»Ý¨D¡A
§â³o¨ÇFQDN¥[¨ìFQDN group¤§¤¤¡A´N¥i¥H¦b¨¾¤õÀð³W«h¤§¤¤¥HFQDN group¨Ó¶i¦æºÞ²z¡C

¦A¨Ó´N¬O¶×¤JªºFQDNÁöµM¥i¥H¥[¤W«eºó¦r¦ê¨ÓÃѧO»PºÞ²z¡A
¦ýscript¤¤ªº¤º®e¬O¼g¦ºªº¡A¶¶¤l§â¥¦Åܦ¨¤@­ÓÅܼơAÅý¨Ï¥ÎªÌ¨Ì»Ý¨D¥h½Õ¾ã¡C

°ò©ó¥H¤Wªº»Ý¨D¡A¶¶¤l­×§ï¤Fscript¤º®e¡A
Åý¥¦¥¦¥i¥H¨Ì»Ý¨D¥ý«Ø¥ßFQDN Group¡AÅýÀH«áªºFQDNª«¥ó¦b«Ø¥ß®Éª½±µÂkÄݦb³o­ÓFQDN Group¤§¤¤¡A
¤§«á­n®M¥Î¦b¨¾¤õÀð³W«h®É´N²³æ¦h¤F¡Aª½±µ®M¥Î³o­ÓGroupª«¥ó§Y¥i¡C

# Variables you need to adjust for your environment
# -------------------------------------------------
$_FIREWALL_IP = "192.168.1.210"
$_FIREWALL_PORT = "4444"
$_API_USER = "admin"
$_API_PASSWORD = 'correcthorsebatterystaple'
$_WORK_FOLDER = "D:\test\"
$_DATA_FILE_NAME = "ips.txt"
$_ADD_PREFIXES_TO_OBJECTS = "Yes"
$_FQDN_Prefix = "Bulk_"
$_ADD_FQDN_GROUP = "FQDN_G_Test"


# Main functions
# --------------

# ¶¶¤l¼W¥[FQDN¸s²Õ§PÂ_
if ($_ADD_FQDN_GROUP -ne "")
    {
    $_API_QUERY_URL = "https://$($_FIREWALL_IP):$($_FIREWALL_PORT)/webconsole/APIController?reqxml=<Request><Login><UserName>$($_API_USER)</UserName><Password>$($_CODIFIED_API_PASSWORD)</Password></Login><Get><FQDNHostGroup><Filter><key name='Name' criteria='='>$($_ADD_FQDN_GROUP)</key></Filter></FQDNHostGroup></Get></Request>"    
    $_API_QUERY_RESULT = Invoke-WebRequest -Uri "$_API_QUERY_URL"
    [xml] $_API_QUERY_RESULT_PARSED = $_API_QUERY_RESULT.Content

    #FQDN GROUPª«¥ó¤£¦s¦b®É,«Ø¥ßFQDNª«¥ó
if ($_API_QUERY_RESULT_PARSED.Response.FQDNHostGroup.Status -eq "No. of records Zero.")
{    
        $_API_QUERY_URL = "https://$($_FIREWALL_IP):$($_FIREWALL_PORT)/webconsole/APIController?reqxml=<Request><Login><UserName>$($_API_USER)</UserName><Password>$($_CODIFIED_API_PASSWORD)</Password></Login><Set><FQDNHostGroup><Name>$($_ADD_FQDN_GROUP)</Name></FQDNHostGroup></Set></Request>"

        $_API_QUERY_RESULT = Invoke-WebRequest -Uri "$_API_QUERY_URL"
        [xml] $_API_QUERY_RESULT_PARSED = $_API_QUERY_RESULT.Content
        Write-Host "[INFO] Create FQDN Group object $($_ADD_FQDN_GROUP)"
        }
        
    $_ADD_FQDN_GROUP = "<FQDNHostGroupList><FQDNHostGroup>" + $_ADD_FQDN_GROUP + "</FQDNHostGroup></FQDNHostGroupList>"
    }            
    
    
    # For FQDN item
    # --------------
    if ($_OPERATION -eq "FQDN_Mode")
     {
        $_API_QUERY_URL = "https://$($_FIREWALL_IP):$($_FIREWALL_PORT)/webconsole/APIController?reqxml=<Request><Login><UserName>$($_API_USER)</UserName><Password>$($_CODIFIED_API_PASSWORD)</Password></Login><Set><FQDNHost><Name>$($_CODIFIED_ITEM_NAME)</Name><FQDN>$($_SECOND_FIELD)</FQDN>$($_ADD_FQDN_GROUP)</FQDNHost></Set></Request>"
        $_TYPE_OBJECT = "FQDN"        
     }


µM«á§å¦¸«Ø¥ßªºFQDNª«¥óªº«eºó¦r¦ê¤]¥i¥H¦Û­q¡A¥u­n­×§ï¹ïÀ³ªº°Ñ¼Æ§Y¥i¡C

$_ADD_PREFIXES_TO_OBJECTS = "Yes"
$_FQDN_Prefix = "Bulk_"


# Prefix for name of object
    # -------------------------

if ($_ADD_PREFIXES_TO_OBJECTS -eq "Yes")
{
if ($_OPERATION -eq "FQDN_Mode")
{
$_ITEM_NAME = $_FQDN_Prefix + $_ITEM_NAME
} else {
if ($_THIRD_FIELD -eq "255.255.255.255")
{
$_ITEM_NAME = "HOST_" + $_ITEM_NAME
} else {
$_ITEM_NAME = "NET_" + $_ITEM_NAME
}
}
}


§¹¾ãªºscript´N¦bªþ¥[Àɮפ§¤¤(¸ÑÀ£±K½XSophos)¡A¦³»Ý­nªºªB¤Í½Ð¦Û¦æ¨ú¥Î¡ã





shunze ¤W¶ÇªºÀÉ®×
Sophos_API.zip (5 KB, ¤w¸g³Q¤U¸ü 75 ¦¸)


♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-12-27, 17:35 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nÂÂXG°h¦ì¡AÂà¥Í¬°AP ControllerÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XG¨t¦C¦b2025¦~3¤ë©³Eol¡A
«áÄò±µ¤âªº²£«~¬°Sophos XGS¨t¦C¨¾¤õÀð¡C
¹ïÀ³ªº21ª©SFOS¶´Åé¤]§¹¥þ©ß¶}XG¥]µö¡A¥þ¤ß¹ïÀ³XGSªºµwÅé³W®æ¡A¥H¼·´§§ó¦nªº®Ä¯à¡ã

µM¦ÓªºlegacyµL½uAP¦Û18.5ª©¶´Åé«á¡A¤w¤£³QSFOS¤ä´©¡A
«È¤á¦bÁʤJ·sªºXGS¨¾¤õÀð«á¡AªºAP´N¥u¯à»{©R¡AÀH¤§©ß±ó¶Ü¡H
Legacy AP series support on SFOS version...S series models

¨ä¹ê¥u­n§âªºXG«O¯d¦b18.5¥H«eªºª©¥»¡AÂà¥Í¬°AP controller¨¤¦â¡A´N¥i¥H¬°ÂÂAPÄò©R¤F¡C


  • ­º¥ý¡A¥Ñ©óXGªº¨¤¦â¤w³QXGS¨ú¥N¡A©Ò¥H§Ú­Ì­nµ¹XG¤@­Ó·sªº¤ººôIP¡AÅý¥¦¤£·|¸òXGSµo¥Í½Ä¬ð¡C
  • µM«á°±¥ÎXGSªºwireless protection¡AÅýÂÂAP¤£·|³QXGSÄd¨ì¡A¨¾Ãª¥¦¸òXG³ø¨ì¡C
  • ±µµÛ¦bDHCPªº³]©w¤¤¡A¼W¥[¤@­Ó234¿ï¶µ(¦¹¿ï¶µ¹ïÀ³AP³ø¨ì¥ÎªºMagic IP)¡A
    ÅýAP³z¹LDHCP®³¨ìIP«á¡Aª¾¹D¥¦­n¥hÂÂXG³ø¨ì¡A¦Ó¤£¬O¹w³]ªºMagic IP 1.2.3.4¡A
    ³o¼Ë´N§¹¦¨XGÂà¥Í¬°AP Controllerªº³]©w¤F¡ã


¬[ºc¥Ü·N¹Ï¦p¤U¡C



¦b¦¹¬[ºc¤U¡A¬£µoIPªºXGS»Ý¦bconsole¤¤¼W¥[DHCP 234¿ï¶µ°Ñ¼Æ¡A«ü¥O¦p¤U¡C
system dhcp dhcp-options add optioncode 234 optionname dhcp_magic_ip optiontype ipaddress
system dhcp dhcp-options binding add dhcpname [DHCP²ÕºA¦WºÙ] optionname dhcp_magic_ip(234) value 10.1.1.253

³o¼ËµL½uAP¦b®³¨ìIP«á¡A´Nª¾¹D­n¥h¸òXGªº10.1.1.253³ø¨ì¡A¦Ó¤£¬O¹w³]ªº1.2.3.4¡C

¥t¥~¥Ñ©óXG¤¤ªºµL½uµêÀÀºô¬q192.168.99.0/24»P192.168.101.0/24¥~ÀYªºXGS¨Ã¤£»{ÃÑ¡A
©Ò¥H­n¦bXGS¤¤¼W¥[ÀRºA¸ô¥Ñ¡AÅýXGSª¾¹D³o¨â­Óºô¬q­n©¹XGªº10.1.1.253°e¡C

192.168.99.0/24 -> 10.1.1.253
192.168.101.0/24 -> 10.1.1.253


XG¥»¨­¤]­n¼W¥[¤@µ§¹w³]¸ô¥Ñ¡A±N©Ò¦³¬y¶q©¹XGS°e¡A
³o¼ËXG¥»¨­»PµêÀÀ¥X¨ÓªºµL½uºô¬q¤~¯à³s¥~¡C

0.0.0.0/0 -> 10.1.1.254


¦Ó¾ô±µ¨ì¤ººôªºµL½uºô¬q¡A¨ädefault gateway°Ñ·Ó¤ººôªº³]©w¡A·|¬OXGS¦Ó¤£¬OXG¡A
³o¼Ë¥i¥HÁ×§K±¼¸ô¥Ñ¤£¹ïºÙªº°ÝÃD¡C

³Ì«á¡A³o¼Ëªº¬[ºc·|¥X²{¤@­Ó¼ç¦bªº°ÝÃD¡A
­Y¥ÑXGµêÀÀ¥X¨ÓªºµL½uºô¬q¦³³s¨ì¤ººôªº»Ý¨D®É¡A
·|¦bXGS¤W¥X²{¥u¦³³æ¦V¸ô¥Ñ³q¹Lªºª¬ªp¡A³oºØ¤£¦w¥þªº¸ô¥Ñ·|³QXGS«ÊÂê¡C



¸Ñ¨Mªº¤èªk¤]«Ü²³æ¡A¦]¬°¥u¦³³æ¦V¸ô¥Ñ·|¸g¹LXGS¡A©Ò¥H¤]¥u¯à¦bXGSªºconsole¤¤¼W¥[bypass³]©w¡A
²¤¹L³o¨â¬qªº«Ê¥]Àˬd¡C

set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.99.0 source_netmask 255.255.255.0 dest_network 10.1.1.0 dest_netmask 255.255.255.0
set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.101.0 source_netmask 255.255.255.0 dest_network 10.1.1.0 dest_netmask 255.255.255.0
set advanced-firewall bypass-stateful-firewall-config add source_network 10.1.1.0 source_netmask 255.255.255.0 dest_network 192.168.99.0 dest_netmask 255.255.255.0
set advanced-firewall bypass-stateful-firewall-config add source_network 10.1.1.0 source_netmask 255.255.255.0 dest_network 192.168.101.0 dest_netmask 255.255.255.0


¥Ñ©óXGS²¤¹L¤F³o¨Çºô¬qªº«Ê¥]Àˬd¡A­Y­n¶i¦æ±ø¥óµ¥¬ÛÃö¹LÂo³]©w¡A
´N¥u¯à¦bXG¤W°µ¡A¦Ó¤£¬OXGS¤F...

³z¹L¥H¤Wªº³]©w¡A´N¯à§â´«¤U¨ÓªºXG·í¦¨AP controller¡AÅý¤£³Q¤ä´©ªºlegacy AP¯àÄ~Äò¨Ï¥Î¤F¡ã
¤£¹LXG±N¦b2025¦~3¤ë©³EoL¡A¤§«á±N¨S¦³«O©T¡A
¤@¥¹Ãa¤F¡A³s±a¤W­±ªºlegacy AP³£µLªkÄò©R¨Ï¥Î¡A­nÂà¥Í¬°AP Controller«e¤]½Ð¯d·N³o­Ó­·ÀI³á¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-12-25, 13:58 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nChrome¨SÁn­µ¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

³Ìªñ«Ü°gYoutube¤Wªº¿ûµ^¡B¤p´£µ^ªº§Ö°{¼v¤ù¡ã

¬Q¤Ñ¥ÎChrome¬ÝYoutube¼v¤ù®É¡A¬ðµM±µ¨ìLineªº¹q¸Ü¡C
±µ¹q¸Ü®É¡AYoutube¼v¤ùªºÁn­µ¦Û°ÊÅܤp¡A¥HÁ×§K¤zÂZ»y­µ³q¸Ü¡F
¦ý¹q¸ÜÁ¿§¹«á¡AµL½×«ç»ò½Õ­µ¶q¡A³£¨S¦³¿ìªk«ì´_ChromeªºÁn­µ...

¸ÕµÛ¥h½Õ¾ã¦UºØ­µ¶q¡AµLªk«ì´_Án­µ¡C
¸Õ¹L­«¶}¾÷¡A¨S¦³§ïµ½¡C
­µ¶q´ú¸Õ»P¼·©ñ¥»¾÷­µÀÉ¡B¼v¤ù¡AÁn­µ³£¥¿±`¡A«Ü©úÅ㪺¬OChrome³Q®ø­µ¤F...

§ä¤F¦n¤[¡A³Ì«á²×©ó§ä¨ìWin10­n¦b­þùذw¹ïÀ³¥Îµ{¦¡½Õ¾ã­µ¶q¤F¡I







¥H¤W¤À¨Éµ¹¤j®a¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-12-05, 23:30 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡n¥~©ß²Ä¤T¤èlog severÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XG/S­n±Nlog¥~©ß¨ì²Ä¤T¤èlog server¨ä¹ê«Ü²³æ¡A
¥u­n¦b CONFIGURE / System services / Log settings ¤¤±N²Ä¤T¤èlog serverªºIP, portµ¥¸ê°T¥[¤J¡C
(¤@¯ëlog server¨Ï¥Îªºport¬O514¡C)



µM«á¦A¿ï¾Ü»Ý­n¥~©ßlogÃþ§O§Y¥i¡C



¤£¹L¦b³z¹L¥H¤W³]©w«á¡A©Î³\§A·|µo²{¬°¤°»ò¦³®É­Ô³o¼Ëªº³]©w¥i¥H¥~©ß¦¨¥\¡A
¦ý¦b¥t¥~¤@¥x³]©w«o¤S¤£¦æ¡H¡H

¨ä¹ê¤W­zªº³]©wÁÙ¦³¤@­Ó­«ÂI¡A
¨º´N¬OSophos¨¾¤õÀðªºlog¨Æ¥ó¦bSeverity level¤¤¬OÄÝ©óinformation(¸ê°T)¼h¯Å¡A
Severity¥²»Ý¬Oinformation(¸ê°T)©Î§ó°ªªºdebug(°»¿ù)¡AFirewallªºlog¤~·|¥~©ß¨ì²Ä¤T¤èlogserver.



­Y¿ï¾Ü¤F¨ä¥¦¼h¯Å¡A§A·|µo²{§A­nªº ¨¾¤õÀðlog§¹¥þ¤£·|©ß¥X¥h¡C


¥t¥~¡A¦b¥~©ßªº°»¿ù¤W¡A§Ú­Ì¥i¥H¦badvanced shell¤¤¡A¿é¤J¥H¤U«ü¥O(³q°Tport¬°514)¨Ó¶i¦æÆ[¹î¡C

tcpdump -nie any port 514




¥H§ÚªºLAB¬°¨Ò¡A§Úªº²Ä¤T¤èLogserver IP¬O10.1.1.136¡C
¦btcpdumpªºÆ[¹î¤¤¡A´N·|¬Ý¨ìXG¥»¨­IP 127.0.0.1¹ï10.1.1.136ªº514«Ê¥]¡C
­Y±Nseverity§ï¬°notification¡A«h¬Ý¤£¨ì¹ï10.1.1.136ªº¥ô¦ó«Ê¥]¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-11-28, 11:42 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡n20ª©«á¡AXG©Úµ´¬õºñª©SSLVPNªº¨Ï¥ÎÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bSophos¤j¤O±À°Ê¦Û®a¶}µoªºSophos Connect³nÅé«á¡A
²×©ó¦b20ª©¡AXG¥¿¦¡©Úµ´¶Ç²Î¬õºñª©SSLVPN³nÅ骺¨Ï¥Î¡A
±j­¢¨Ï¥ÎªÌ§ï¥ÎSophos Connect©Î¬O²Ä¤T¤èªºOpenVPN³nÅé¡C
(¶¶¤l´ú¸Õ¹LOpenVPNÁÙ¬O¥i¥H¦¨¥\³s½u¨ì20ª©ªºXG¡C)



https://community.sophos.com/sophos-xg-f...s-now-available

°£¤F±j­¢¨Ï¥ÎSophos Connect¥~¡ASophosÁÙ§âVPN¥\¯à¦ÛUser Portal¤¤¤ÀÂ÷¡A
¦h¤F¤@­ÓVPN portalÅý¨Ï¥ÎªÌ¤U¸ü³nÅé»P­Ó¤H²ÕºA¡C



¤]¦h¤@­ÓPort¸¹µ¹VPN Portal¨Ó¨Ï¥Î¡C



ºÞ²zªÌ¦b¤Éª©®É¡A½Ð¯d·N³o¶µ§ïÅܳá¡ã




♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-11-22, 14:32 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
¡m¤À¨É¡nSSD firmware updateÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XGS applianceªº¬Y¤@§åµwÅé¦]±Ä¥Î¤F¬Y¤@«¬¸¹ªºSSD¡A³y¦¨¤F¨t²Î¤Wªº¤£Ã­©w¡C
°£¤F¶}case½Ð­ì¼t³B²z¥~¡A±q20ª©ªº¶´Åé¶}©l¡A¤]·|¥D°Ê¦bWebUI¤¤´£¿ôºÞ²zªÌ­n§ó·s¶´Åé¡C





§ó·s¶´Å骺¤è¦¡«Ü²³æ¡A¦ý­n¦bconsole¤U¶i¦æ¡C
¶i¤Jconsole«á¿é¤J system ssd show¡A
´N¥i¥H¥Ñ¦^À³°T®§¨Ó§PÂ_³o¥x³]³Æ»Ý¤£»Ý­n¶i¦æSSDªº¶´Åé§ó·s¡C



­Y»Ý­n§ó·s¡A½Ð¿é¤J system ssd update ¨Ó¶i¦æ§ó·s¡C



§ó·s¶´Å骺®É¶¡¬ù¬°5¤ÀÄÁ¥ª¥k¡A
¶¶¤l§ó·s¹L¨â¥x³]³Æ¡A¤p«¬¸¹ªºXGS136¦b§ó·s§¹·|Ãö¾÷¡A»Ý­n¤â°Ê¶}¾÷¡F
¦Ó¤j«¬¸¹ªºXGS2300«h·|¦Û°Ê­«¶}¾÷¡A§¹¦¨§ó·s¡C
¥Ñ©ó¦³¤£¦Pªºµ²ªG¡A¦]¦¹§ó·s®É¤H³Ì¦nÁÙ¬O¦b²{³õ¡A
­Y¹L¤F¤­¤ÀÄÁÁÙ¨S¦³¥ô¦ó¦^À³¡A½Ð¦b²{³õ½T»{¤@¤U³]³Æ¬O§_³QÃö¾÷¡A¦Ó¤£¬O­«¶}¾÷¡C

§ó·s«á¦A¥hÀˬdSSD¡A·|µo²{¶´Åé¤w¬O³Ì·sª©¡A¤£»Ý­n¶i¦æ¨ä¥¦°Ê§@¤F¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-08-07, 17:47 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2387

shunze Â÷½u
SD-WAN Connection GroupsÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos Central¤¤ªºSD-WAN Connection Groups¨ä¹ê´N¬O§â¦h¥x¨¾¤õÀð¥Hroute baseªºsite to site VPN¦ê°_¨Ó¡A
µM«á³z¹Lpolicy route¥h¾É³q¥»¦a»P»·ºÝªº¤À¨Éºô¬q¡C

¥H¤U¶¶¤l¥H¨â¥x¨¾¤õÀ𬰨ҡA¤@¨B¨B¾Þ§@¡A¬Ý¬Ý¦¹¥\¯à¦p¦ó³z¹LºëÆF§âroute base site to site VPN«Ø°_¨Ó¡C
­º¥ý¡A§Ú­Ì«Ø¥ß¤@­ÓConnection group¡C



µM«á§â¥Ø¼Ðªº¨â¥x¨¾¤õÀð¥[¤J¦¹group¡C



²Ä¤G¨B¡A´N¬O§âsite to site VPN¤¤­n¤À¨Éµ¹¹ïºÝªº¸ê·½¥[¤J¡C





¨â¥x¨¾¤õÀð­n¤À¨Éªººô¬q¸ê·½³£¥[¤J«á¡A«ö¤U¤@¨B¡C



¨ì²Ä¤T¨BConfigure Networks¡A·|´£¥ÜÁÙ¨S¦³¥»¦a¸ê·½¡C



®i¶}«á¡A³v¤@§â¨â¥x¨¾¤õÀ𪺥»¦a¸ê·½¥[¤J¡C



¥»¦a¸ê·½¥]¥»¦aªººô¬q»P¥Î¨Ó¼·±µªºWAN Port¡C



¨â¥x¸ê·½³£¥[¤J«á¡A«ö¤U§¹¦¨¡C





§¹¦¨«á»Ý­nµ¹¥¦¤@ÂI®É¶¡¡A±N²ÕºA³¡¸p¨ì¨â¥x¨¾¤õÀ𤤡C



³¡¸p§¹¦¨¡A¨â²Õªºª¬ºA·|Åã¥Üºñ¿O¡C



¨ì¦aºÝ¨¾¤õÀð¥h¬Ý¡A·|µo²{¦¹ºëÆF¤w¦¨¥\«Ø¥ß¤@±øtunnel baseªºSite to site VPN¡C



¨Ã¦b¹ïÀ³ªºWAN port¤W¡A«Ø¥ß¤@­ÓVPN tunnelªº¤¶­±IP¡C



¦P®É¥H¦¹IP«Ø¥ß¤F¤@­Ógateway¡C



¨Ã¥H³]©wªº¥»¦aºô毁»P¹ïºÝ¤À¨Éªººô¬q³z¹Lpolicy route«Ø¥ß¤F«ü¦V³W«h¡C



³z¹L³o¼Ëªº¥Ü½d¡A§Ú­Ì¥i¥H²M·¡¬Ý¨ìSD-WAN Connection Groups½T¹ê´N¬O§â¦h¥x¨¾¤õÀð¡A
¥Hroute baseªºsite to site VPN¦ê°_¨Óªº¤@­ÓºëÆF¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-08-05, 18:07 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
¸õ¨ì:
Åã¥Ü±q 1 ¨ì 10 ¦b©Ò¦³ªº 2584 ­Óµ²ªG¤¤.  12345...»

Powered by: Burning Board 1.1.1 2001 WoltLab GbR