Shunze ¾Ç¶é > ·j´M > ·j´Mµ²ªG «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]

§@ªÌ ¤å³¹
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¡m¤À¨É¡nAPIÀ³¥Î½d¨Ò¤§2-¤j¶q¿é¤JFQDNÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦³«È¤á¦b°Ý¡A±¡¸ê³æ¦ìµ¹ªº´c·NFQDN²M³æ¡ASophos¦³¨S¦³¿ìªk§å¦¸¶×¤J¡H

¶¶¤l¥J²Ó¥h¬d¤F¤@¤U¡ASFOS³£¤w¸g¨ì21ª©¤F¡A¦ýSophosÁÙ¬O¨S¦³³o­Ó¥\¯à...
¤£¹L¦³¦n¤ßªº¨Ï¥ÎªÌ´£¨Ñ¤F¦Û»sªºAPI script¡A¥i¥H³z¹LAPI¤j¶q¿é¤JIP»PFQDNª«¥ó¡A³sµ²¦p¤U¡C
Automated load of object through API from CSV!

³o­Óscript¶¶¤l¬Ý¤F¤@¤U¡Aµo²{¥¦¥u­nµy·L­×§ï¤@¤U¡A´N¥i¥H§¹¬ü²Å¦X«È¤á»Ý¨D¡I

­n­×§ï­þ¨Ç¤º®e©O¡H
­º¥ý¡AFQDN¸òIPª«¥ó¤£¤@¼Ë¡AIP¦³IP list¥i¥Î¡A¥i¥H¥H¤@­ÓIP listª«¥ó¦¬®e¦h­ÓIP¡A¨Ã®M¥Î¦b¨¾¤õÀð³W«h¤§¤¤Â²³æºÞ²z¡F
¦ýFQDN¨S¦³FQDN listª«¥ó¡A¨C¤@­ÓFQDN³£¬O¤@­Ó¿W¥ßª«¥ó¡A­Y­n±N¤j¶qªºFQDN¦C¤J©Úµ´²M³æ¡A¹ïºÞ²zªÌ¦Ó¨¥±N¬O¤@µ§¤£¤pªº­t¾á¡C

¤£¹LÁöµMFQDN¨S¦³FQDN list¥i¥Î¡A¦ý§Ú­Ì¥i¥H³z¹LFQDN group¨Ó¹F¦¨Ãþ¦ü»Ý¨D¡A
§â³o¨ÇFQDN¥[¨ìFQDN group¤§¤¤¡A´N¥i¥H¦b¨¾¤õÀð³W«h¤§¤¤¥HFQDN group¨Ó¶i¦æºÞ²z¡C

¦A¨Ó´N¬O¶×¤JªºFQDNÁöµM¥i¥H¥[¤W«eºó¦r¦ê¨ÓÃѧO»PºÞ²z¡A
¦ýscript¤¤ªº¤º®e¬O¼g¦ºªº¡A¶¶¤l§â¥¦Åܦ¨¤@­ÓÅܼơAÅý¨Ï¥ÎªÌ¨Ì»Ý¨D¥h½Õ¾ã¡C

°ò©ó¥H¤Wªº»Ý¨D¡A¶¶¤l­×§ï¤Fscript¤º®e¡A
Åý¥¦¥¦¥i¥H¨Ì»Ý¨D¥ý«Ø¥ßFQDN Group¡AÅýÀH«áªºFQDNª«¥ó¦b«Ø¥ß®Éª½±µÂkÄݦb³o­ÓFQDN Group¤§¤¤¡A
¤§«á­n®M¥Î¦b¨¾¤õÀð³W«h®É´N²³æ¦h¤F¡Aª½±µ®M¥Î³o­ÓGroupª«¥ó§Y¥i¡C

# Variables you need to adjust for your environment
# -------------------------------------------------
$_FIREWALL_IP = "192.168.1.210"
$_FIREWALL_PORT = "4444"
$_API_USER = "admin"
$_API_PASSWORD = 'correcthorsebatterystaple'
$_WORK_FOLDER = "D:\test\"
$_DATA_FILE_NAME = "ips.txt"
$_ADD_PREFIXES_TO_OBJECTS = "Yes"
$_FQDN_Prefix = "Bulk_"
$_ADD_FQDN_GROUP = "FQDN_G_Test"


# Main functions
# --------------

# ¶¶¤l¼W¥[FQDN¸s²Õ§PÂ_
if ($_ADD_FQDN_GROUP -ne "")
    {
    $_API_QUERY_URL = "https://$($_FIREWALL_IP):$($_FIREWALL_PORT)/webconsole/APIController?reqxml=<Request><Login><UserName>$($_API_USER)</UserName><Password>$($_CODIFIED_API_PASSWORD)</Password></Login><Get><FQDNHostGroup><Filter><key name='Name' criteria='='>$($_ADD_FQDN_GROUP)</key></Filter></FQDNHostGroup></Get></Request>"    
    $_API_QUERY_RESULT = Invoke-WebRequest -Uri "$_API_QUERY_URL"
    [xml] $_API_QUERY_RESULT_PARSED = $_API_QUERY_RESULT.Content

    #FQDN GROUPª«¥ó¤£¦s¦b®É,«Ø¥ßFQDNª«¥ó
if ($_API_QUERY_RESULT_PARSED.Response.FQDNHostGroup.Status -eq "No. of records Zero.")
{    
        $_API_QUERY_URL = "https://$($_FIREWALL_IP):$($_FIREWALL_PORT)/webconsole/APIController?reqxml=<Request><Login><UserName>$($_API_USER)</UserName><Password>$($_CODIFIED_API_PASSWORD)</Password></Login><Set><FQDNHostGroup><Name>$($_ADD_FQDN_GROUP)</Name></FQDNHostGroup></Set></Request>"

        $_API_QUERY_RESULT = Invoke-WebRequest -Uri "$_API_QUERY_URL"
        [xml] $_API_QUERY_RESULT_PARSED = $_API_QUERY_RESULT.Content
        Write-Host "[INFO] Create FQDN Group object $($_ADD_FQDN_GROUP)"
        }
        
    $_ADD_FQDN_GROUP = "<FQDNHostGroupList><FQDNHostGroup>" + $_ADD_FQDN_GROUP + "</FQDNHostGroup></FQDNHostGroupList>"
    }            
    
    
    # For FQDN item
    # --------------
    if ($_OPERATION -eq "FQDN_Mode")
     {
        $_API_QUERY_URL = "https://$($_FIREWALL_IP):$($_FIREWALL_PORT)/webconsole/APIController?reqxml=<Request><Login><UserName>$($_API_USER)</UserName><Password>$($_CODIFIED_API_PASSWORD)</Password></Login><Set><FQDNHost><Name>$($_CODIFIED_ITEM_NAME)</Name><FQDN>$($_SECOND_FIELD)</FQDN>$($_ADD_FQDN_GROUP)</FQDNHost></Set></Request>"
        $_TYPE_OBJECT = "FQDN"        
     }


µM«á§å¦¸«Ø¥ßªºFQDNª«¥óªº«eºó¦r¦ê¤]¥i¥H¦Û­q¡A¥u­n­×§ï¹ïÀ³ªº°Ñ¼Æ§Y¥i¡C

$_ADD_PREFIXES_TO_OBJECTS = "Yes"
$_FQDN_Prefix = "Bulk_"


# Prefix for name of object
    # -------------------------

if ($_ADD_PREFIXES_TO_OBJECTS -eq "Yes")
{
if ($_OPERATION -eq "FQDN_Mode")
{
$_ITEM_NAME = $_FQDN_Prefix + $_ITEM_NAME
} else {
if ($_THIRD_FIELD -eq "255.255.255.255")
{
$_ITEM_NAME = "HOST_" + $_ITEM_NAME
} else {
$_ITEM_NAME = "NET_" + $_ITEM_NAME
}
}
}


§¹¾ãªºscript´N¦bªþ¥[Àɮפ§¤¤(¸ÑÀ£±K½XSophos)¡A¦³»Ý­nªºªB¤Í½Ð¦Û¦æ¨ú¥Î¡ã





shunze ¤W¶ÇªºÀÉ®×
Sophos_API.zip (5 KB, ¤w¸g³Q¤U¸ü 142 ¦¸)


♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-12-27, 17:35 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¡m¤À¨É¡nÂÂXG°h¦ì¡AÂà¥Í¬°AP ControllerÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XG¨t¦C¦b2025¦~3¤ë©³Eol¡A
«áÄò±µ¤âªº²£«~¬°Sophos XGS¨t¦C¨¾¤õÀð¡C
¹ïÀ³ªº21ª©SFOS¶´Åé¤]§¹¥þ©ß¶}XG¥]µö¡A¥þ¤ß¹ïÀ³XGSªºµwÅé³W®æ¡A¥H¼·´§§ó¦nªº®Ä¯à¡ã

µM¦ÓªºlegacyµL½uAP¦Û18.5ª©¶´Åé«á¡A¤w¤£³QSFOS¤ä´©¡A
«È¤á¦bÁʤJ·sªºXGS¨¾¤õÀð«á¡AªºAP´N¥u¯à»{©R¡AÀH¤§©ß±ó¶Ü¡H
Legacy AP series support on SFOS version...S series models

¨ä¹ê¥u­n§âªºXG«O¯d¦b18.5¥H«eªºª©¥»¡AÂà¥Í¬°AP controller¨¤¦â¡A´N¥i¥H¬°ÂÂAPÄò©R¤F¡C


  • ­º¥ý¡A¥Ñ©óXGªº¨¤¦â¤w³QXGS¨ú¥N¡A©Ò¥H§Ú­Ì­nµ¹XG¤@­Ó·sªº¤ººôIP¡AÅý¥¦¤£·|¸òXGSµo¥Í½Ä¬ð¡C
  • µM«á°±¥ÎXGSªºwireless protection¡AÅýÂÂAP¤£·|³QXGSÄd¨ì¡A¨¾Ãª¥¦¸òXG³ø¨ì¡C
  • ±µµÛ¦bDHCPªº³]©w¤¤¡A¼W¥[¤@­Ó234¿ï¶µ(¦¹¿ï¶µ¹ïÀ³AP³ø¨ì¥ÎªºMagic IP)¡A
    ÅýAP³z¹LDHCP®³¨ìIP«á¡Aª¾¹D¥¦­n¥hÂÂXG³ø¨ì¡A¦Ó¤£¬O¹w³]ªºMagic IP 1.2.3.4¡A
    ³o¼Ë´N§¹¦¨XGÂà¥Í¬°AP Controllerªº³]©w¤F¡ã


¬[ºc¥Ü·N¹Ï¦p¤U¡C



¦b¦¹¬[ºc¤U¡A¬£µoIPªºXGS»Ý¦bconsole¤¤¼W¥[DHCP 234¿ï¶µ°Ñ¼Æ¡A«ü¥O¦p¤U¡C
system dhcp dhcp-options add optioncode 234 optionname dhcp_magic_ip optiontype ipaddress
system dhcp dhcp-options binding add dhcpname [DHCP²ÕºA¦WºÙ] optionname dhcp_magic_ip(234) value 10.1.1.253

³o¼ËµL½uAP¦b®³¨ìIP«á¡A´Nª¾¹D­n¥h¸òXGªº10.1.1.253³ø¨ì¡A¦Ó¤£¬O¹w³]ªº1.2.3.4¡C

¥t¥~¥Ñ©óXG¤¤ªºµL½uµêÀÀºô¬q192.168.99.0/24»P192.168.101.0/24¥~ÀYªºXGS¨Ã¤£»{ÃÑ¡A
©Ò¥H­n¦bXGS¤¤¼W¥[ÀRºA¸ô¥Ñ¡AÅýXGSª¾¹D³o¨â­Óºô¬q­n©¹XGªº10.1.1.253°e¡C

192.168.99.0/24 -> 10.1.1.253
192.168.101.0/24 -> 10.1.1.253


XG¥»¨­¤]­n¼W¥[¤@µ§¹w³]¸ô¥Ñ¡A±N©Ò¦³¬y¶q©¹XGS°e¡A
³o¼ËXG¥»¨­»PµêÀÀ¥X¨ÓªºµL½uºô¬q¤~¯à³s¥~¡C

0.0.0.0/0 -> 10.1.1.254


¦Ó¾ô±µ¨ì¤ººôªºµL½uºô¬q¡A¨ädefault gateway°Ñ·Ó¤ººôªº³]©w¡A·|¬OXGS¦Ó¤£¬OXG¡A
³o¼Ë¥i¥HÁ×§K±¼¸ô¥Ñ¤£¹ïºÙªº°ÝÃD¡C

³Ì«á¡A³o¼Ëªº¬[ºc·|¥X²{¤@­Ó¼ç¦bªº°ÝÃD¡A
­Y¥ÑXGµêÀÀ¥X¨ÓªºµL½uºô¬q¦³³s¨ì¤ººôªº»Ý¨D®É¡A
·|¦bXGS¤W¥X²{¥u¦³³æ¦V¸ô¥Ñ³q¹Lªºª¬ªp¡A³oºØ¤£¦w¥þªº¸ô¥Ñ·|³QXGS«ÊÂê¡C



¸Ñ¨Mªº¤èªk¤]«Ü²³æ¡A¦]¬°¥u¦³³æ¦V¸ô¥Ñ·|¸g¹LXGS¡A©Ò¥H¤]¥u¯à¦bXGSªºconsole¤¤¼W¥[bypass³]©w¡A
²¤¹L³o¨â¬qªº«Ê¥]Àˬd¡C

set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.99.0 source_netmask 255.255.255.0 dest_network 10.1.1.0 dest_netmask 255.255.255.0
set advanced-firewall bypass-stateful-firewall-config add source_network 192.168.101.0 source_netmask 255.255.255.0 dest_network 10.1.1.0 dest_netmask 255.255.255.0
set advanced-firewall bypass-stateful-firewall-config add source_network 10.1.1.0 source_netmask 255.255.255.0 dest_network 192.168.99.0 dest_netmask 255.255.255.0
set advanced-firewall bypass-stateful-firewall-config add source_network 10.1.1.0 source_netmask 255.255.255.0 dest_network 192.168.101.0 dest_netmask 255.255.255.0


¥Ñ©óXGS²¤¹L¤F³o¨Çºô¬qªº«Ê¥]Àˬd¡A­Y­n¶i¦æ±ø¥óµ¥¬ÛÃö¹LÂo³]©w¡A
´N¥u¯à¦bXG¤W°µ¡A¦Ó¤£¬OXGS¤F...

³z¹L¥H¤Wªº³]©w¡A´N¯à§â´«¤U¨ÓªºXG·í¦¨AP controller¡AÅý¤£³Q¤ä´©ªºlegacy AP¯àÄ~Äò¨Ï¥Î¤F¡ã
¤£¹LXG±N¦b2025¦~3¤ë©³EoL¡A¤§«á±N¨S¦³«O©T¡A
¤@¥¹Ãa¤F¡A³s±a¤W­±ªºlegacy AP³£µLªkÄò©R¨Ï¥Î¡A­nÂà¥Í¬°AP Controller«e¤]½Ð¯d·N³o­Ó­·ÀI³á¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-12-25, 13:58 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¡m¤À¨É¡nChrome¨SÁn­µ¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

³Ìªñ«Ü°gYoutube¤Wªº¿ûµ^¡B¤p´£µ^ªº§Ö°{¼v¤ù¡ã

¬Q¤Ñ¥ÎChrome¬ÝYoutube¼v¤ù®É¡A¬ðµM±µ¨ìLineªº¹q¸Ü¡C
±µ¹q¸Ü®É¡AYoutube¼v¤ùªºÁn­µ¦Û°ÊÅܤp¡A¥HÁ×§K¤zÂZ»y­µ³q¸Ü¡F
¦ý¹q¸ÜÁ¿§¹«á¡AµL½×«ç»ò½Õ­µ¶q¡A³£¨S¦³¿ìªk«ì´_ChromeªºÁn­µ...

¸ÕµÛ¥h½Õ¾ã¦UºØ­µ¶q¡AµLªk«ì´_Án­µ¡C
¸Õ¹L­«¶}¾÷¡A¨S¦³§ïµ½¡C
­µ¶q´ú¸Õ»P¼·©ñ¥»¾÷­µÀÉ¡B¼v¤ù¡AÁn­µ³£¥¿±`¡A«Ü©úÅ㪺¬OChrome³Q®ø­µ¤F...

§ä¤F¦n¤[¡A³Ì«á²×©ó§ä¨ìWin10­n¦b­þùذw¹ïÀ³¥Îµ{¦¡½Õ¾ã­µ¶q¤F¡I







¥H¤W¤À¨Éµ¹¤j®a¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-12-05, 23:30 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¡m¤À¨É¡n¥~©ß²Ä¤T¤èlog severÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XG/S­n±Nlog¥~©ß¨ì²Ä¤T¤èlog server¨ä¹ê«Ü²³æ¡A
¥u­n¦b CONFIGURE / System services / Log settings ¤¤±N²Ä¤T¤èlog serverªºIP, portµ¥¸ê°T¥[¤J¡C
(¤@¯ëlog server¨Ï¥Îªºport¬O514¡C)



µM«á¦A¿ï¾Ü»Ý­n¥~©ßlogÃþ§O§Y¥i¡C



¤£¹L¦b³z¹L¥H¤W³]©w«á¡A©Î³\§A·|µo²{¬°¤°»ò¦³®É­Ô³o¼Ëªº³]©w¥i¥H¥~©ß¦¨¥\¡A
¦ý¦b¥t¥~¤@¥x³]©w«o¤S¤£¦æ¡H¡H

¨ä¹ê¤W­zªº³]©wÁÙ¦³¤@­Ó­«ÂI¡A
¨º´N¬OSophos¨¾¤õÀðªºlog¨Æ¥ó¦bSeverity level¤¤¬OÄÝ©óinformation(¸ê°T)¼h¯Å¡A
Severity¥²»Ý¬Oinformation(¸ê°T)©Î§ó°ªªºdebug(°»¿ù)¡AFirewallªºlog¤~·|¥~©ß¨ì²Ä¤T¤èlogserver.



­Y¿ï¾Ü¤F¨ä¥¦¼h¯Å¡A§A·|µo²{§A­nªº ¨¾¤õÀðlog§¹¥þ¤£·|©ß¥X¥h¡C


¥t¥~¡A¦b¥~©ßªº°»¿ù¤W¡A§Ú­Ì¥i¥H¦badvanced shell¤¤¡A¿é¤J¥H¤U«ü¥O(³q°Tport¬°514)¨Ó¶i¦æÆ[¹î¡C

tcpdump -nie any port 514




¥H§ÚªºLAB¬°¨Ò¡A§Úªº²Ä¤T¤èLogserver IP¬O10.1.1.136¡C
¦btcpdumpªºÆ[¹î¤¤¡A´N·|¬Ý¨ìXG¥»¨­IP 127.0.0.1¹ï10.1.1.136ªº514«Ê¥]¡C
­Y±Nseverity§ï¬°notification¡A«h¬Ý¤£¨ì¹ï10.1.1.136ªº¥ô¦ó«Ê¥]¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-11-28, 11:42 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¡m¤À¨É¡n20ª©«á¡AXG©Úµ´¬õºñª©SSLVPNªº¨Ï¥ÎÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bSophos¤j¤O±À°Ê¦Û®a¶}µoªºSophos Connect³nÅé«á¡A
²×©ó¦b20ª©¡AXG¥¿¦¡©Úµ´¶Ç²Î¬õºñª©SSLVPN³nÅ骺¨Ï¥Î¡A
±j­¢¨Ï¥ÎªÌ§ï¥ÎSophos Connect©Î¬O²Ä¤T¤èªºOpenVPN³nÅé¡C
(¶¶¤l´ú¸Õ¹LOpenVPNÁÙ¬O¥i¥H¦¨¥\³s½u¨ì20ª©ªºXG¡C)



https://community.sophos.com/sophos-xg-f...s-now-available

°£¤F±j­¢¨Ï¥ÎSophos Connect¥~¡ASophosÁÙ§âVPN¥\¯à¦ÛUser Portal¤¤¤ÀÂ÷¡A
¦h¤F¤@­ÓVPN portalÅý¨Ï¥ÎªÌ¤U¸ü³nÅé»P­Ó¤H²ÕºA¡C



¤]¦h¤@­ÓPort¸¹µ¹VPN Portal¨Ó¨Ï¥Î¡C



ºÞ²zªÌ¦b¤Éª©®É¡A½Ð¯d·N³o¶µ§ïÅܳá¡ã




♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-11-22, 14:32 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¡m¤À¨É¡nSSD firmware updateÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XGS applianceªº¬Y¤@§åµwÅé¦]±Ä¥Î¤F¬Y¤@«¬¸¹ªºSSD¡A³y¦¨¤F¨t²Î¤Wªº¤£Ã­©w¡C
°£¤F¶}case½Ð­ì¼t³B²z¥~¡A±q20ª©ªº¶´Åé¶}©l¡A¤]·|¥D°Ê¦bWebUI¤¤´£¿ôºÞ²zªÌ­n§ó·s¶´Åé¡C





§ó·s¶´Å骺¤è¦¡«Ü²³æ¡A¦ý­n¦bconsole¤U¶i¦æ¡C
¶i¤Jconsole«á¿é¤J system ssd show¡A
´N¥i¥H¥Ñ¦^À³°T®§¨Ó§PÂ_³o¥x³]³Æ»Ý¤£»Ý­n¶i¦æSSDªº¶´Åé§ó·s¡C



­Y»Ý­n§ó·s¡A½Ð¿é¤J system ssd update ¨Ó¶i¦æ§ó·s¡C



§ó·s¶´Å骺®É¶¡¬ù¬°5¤ÀÄÁ¥ª¥k¡A
¶¶¤l§ó·s¹L¨â¥x³]³Æ¡A¤p«¬¸¹ªºXGS136¦b§ó·s§¹·|Ãö¾÷¡A»Ý­n¤â°Ê¶}¾÷¡F
¦Ó¤j«¬¸¹ªºXGS2300«h·|¦Û°Ê­«¶}¾÷¡A§¹¦¨§ó·s¡C
¥Ñ©ó¦³¤£¦Pªºµ²ªG¡A¦]¦¹§ó·s®É¤H³Ì¦nÁÙ¬O¦b²{³õ¡A
­Y¹L¤F¤­¤ÀÄÁÁÙ¨S¦³¥ô¦ó¦^À³¡A½Ð¦b²{³õ½T»{¤@¤U³]³Æ¬O§_³QÃö¾÷¡A¦Ó¤£¬O­«¶}¾÷¡C

§ó·s«á¦A¥hÀˬdSSD¡A·|µo²{¶´Åé¤w¬O³Ì·sª©¡A¤£»Ý­n¶i¦æ¨ä¥¦°Ê§@¤F¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-08-07, 17:47 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
SD-WAN Connection GroupsÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos Central¤¤ªºSD-WAN Connection Groups¨ä¹ê´N¬O§â¦h¥x¨¾¤õÀð¥Hroute baseªºsite to site VPN¦ê°_¨Ó¡A
µM«á³z¹Lpolicy route¥h¾É³q¥»¦a»P»·ºÝªº¤À¨Éºô¬q¡C

¥H¤U¶¶¤l¥H¨â¥x¨¾¤õÀ𬰨ҡA¤@¨B¨B¾Þ§@¡A¬Ý¬Ý¦¹¥\¯à¦p¦ó³z¹LºëÆF§âroute base site to site VPN«Ø°_¨Ó¡C
­º¥ý¡A§Ú­Ì«Ø¥ß¤@­ÓConnection group¡C



µM«á§â¥Ø¼Ðªº¨â¥x¨¾¤õÀð¥[¤J¦¹group¡C



²Ä¤G¨B¡A´N¬O§âsite to site VPN¤¤­n¤À¨Éµ¹¹ïºÝªº¸ê·½¥[¤J¡C





¨â¥x¨¾¤õÀð­n¤À¨Éªººô¬q¸ê·½³£¥[¤J«á¡A«ö¤U¤@¨B¡C



¨ì²Ä¤T¨BConfigure Networks¡A·|´£¥ÜÁÙ¨S¦³¥»¦a¸ê·½¡C



®i¶}«á¡A³v¤@§â¨â¥x¨¾¤õÀ𪺥»¦a¸ê·½¥[¤J¡C



¥»¦a¸ê·½¥]¥»¦aªººô¬q»P¥Î¨Ó¼·±µªºWAN Port¡C



¨â¥x¸ê·½³£¥[¤J«á¡A«ö¤U§¹¦¨¡C





§¹¦¨«á»Ý­nµ¹¥¦¤@ÂI®É¶¡¡A±N²ÕºA³¡¸p¨ì¨â¥x¨¾¤õÀ𤤡C



³¡¸p§¹¦¨¡A¨â²Õªºª¬ºA·|Åã¥Üºñ¿O¡C



¨ì¦aºÝ¨¾¤õÀð¥h¬Ý¡A·|µo²{¦¹ºëÆF¤w¦¨¥\«Ø¥ß¤@±øtunnel baseªºSite to site VPN¡C



¨Ã¦b¹ïÀ³ªºWAN port¤W¡A«Ø¥ß¤@­ÓVPN tunnelªº¤¶­±IP¡C



¦P®É¥H¦¹IP«Ø¥ß¤F¤@­Ógateway¡C



¨Ã¥H³]©wªº¥»¦aºô毁»P¹ïºÝ¤À¨Éªººô¬q³z¹Lpolicy route«Ø¥ß¤F«ü¦V³W«h¡C



³z¹L³o¼Ëªº¥Ü½d¡A§Ú­Ì¥i¥H²M·¡¬Ý¨ìSD-WAN Connection Groups½T¹ê´N¬O§â¦h¥x¨¾¤õÀð¡A
¥Hroute baseªºsite to site VPN¦ê°_¨Óªº¤@­ÓºëÆF¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-08-05, 18:07 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¶l¥óĵ¥Ü¾÷¨îÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¶l¥óĵ¥Ü¾÷¨î¬O«È¤á«Ü¦b·Nªº¤@­Ó¥\¯à¡A
²¦³º³£¤w¸g¦bSophos Central¶°¤¤±±ºÞ¤F¡A©Ò¦³¨¾¤õÀ𪺪¬ºA¤]À³¸Ó­n¥D°Ê³qª¾¡C

¦bFirewall Management¤¤¦³¤T­Ó©w¸q¦nªºÄµ¥ÜÀW²v²ÕºA¡A
¥i¥H¨Ì·Ó»Ý¨D§â¨¾¤õÅé­ÓÅé©Ô¨ì¹ïÀ³ªº²ÕºA¤¤¡C

Defaultªº¹w³]¨C¤K¤p®Éµo°e¤@¦¸¡Dª¬ªp­Y¥¼±Æ°£¡A«h·|¦b¤K¤p®É«á¦Aµo¤@¦¸¡C



Verbose«h¬O¸û±K¶°ªº¡A¨C¤@¤p®É´Nµo°e¤@¦¸¡C



¦ÓSilent«h¬O¤@¤Ñ¥u·|µo°e¤@¦¸¡C




¶l¥óµo°eÀW²v©w¸q¦n¤F¡A¨º­þ¨Ç¤H¤S·|¦¬¨ì¶l¥ó³qª¾©O¡H
¹w³]¬O©Ò¦³Administrators¦¨­û³£·|¦¬¨ì«H¡A
¦pªG­n½Õ¾ã¡A¥i¥H¦b General Settings ¤¤ªº Configure email alerts ¶i¦æ½Õ¾ã¡C



¦b Adminstrators ­¶­±¤¤¡A±z¥i¥H½Õ¾ãAdministrators¦¨­ûªº±µ¦¬ª¬ºA¡C



­Y¦³¥~³¡«H½c»Ý­n¦¬¨ì«H¡A¥i¥H¦bDistribution lists¤¤¡A±N¶l¥ó«H½c¥[¤J¡C



±z¥i¥H¦bFrequency¤¤¨ÌÄY­«©Ê¡B²£«~»PÃþ§O¨Ó½Õ¾ãµo°eÀW²v¡C







¯S§O»¡©ú¤@¤U¡A¸ò¨¾¤õÀð¦³ÃöªºÃþ§O¬°Security¡BSystem health¡BConnectivity»PGeneral³o¥|­ÓÃþ§O¡A
³o¥|­ÓÃþ§O¹ïÀ³ªº§¹¾ã¨Æ¥ó¡A½Ð°Ñ¦Ò¥H¤U³sµ²¡C
Firewall alerts


¥t¥~¤]¥i¥H¦Û¦æ³]©w±ø¥ó¡A¨Ó¨M©w­þ¨Ç¤H­n¦¬¨ì­þ¨ÇÃþ§OªºÄµ¥Ü«H¥ó¡C
¦ý¤@¥¹«Ø¥ß Custom rules «á¡A¹w³]¡§©Ò¦³Administrators¦¨­û³£·|¦¬¨ì³qª¾«H¡¨³o­Ó°Ê§@±N·|°±¥Î¡A
©Ò¦³­n¦¬¨ì«HªºAdministrators³£­n¦³¹ïÀ³ªº Custom rules ¤~·|IJµoĵ¥Ü³qª¾¾÷¨î¡I



«Ø¥ß Custom rules ªº²Ä¤@¨B¡A´N¬O¿ï¾Üadmin¨¤¦â»P¦¨­û¡C





Admin¿ï¦n«á¡A±µµÛ¿ï»Ý­n¦¬¨ì³qª¾ªº¥~³¡«H½c(¦pªG¦³ªº¸Ü)¡C



±µµÛ¿ï¾Ü­n¦¬¨ìªºÄµ¥Ü«H¥óÃþ§O±ø¥ó¡C






¡ô³oÃä°O±o§â¸ò¨¾¤õÀð¦³Ãöªº¥|­ÓÃþ§OSecurity¡BSystem health¡BConnectivity»PGeneral³£¿ï°_¨Ó³á¡ã

§¹¦¨«á¡A«ö¤USaveÀx¦s¡C



¦pªG¦³¹ïÀ³ªº¨Æ¥óµo¥Íªº¸Ü¡A¦¬¥ó¤Hªº«H½c´N·|¦¬¨ì¨Ó¦ÛSophos Centralªº³qª¾«H¥ó¡C




¦pªG¦bCustom rulen«Ø¥ß«á¡A¤S§ârule¤¤ªºadmin±b¸¹°±¥Î¡A¤£¦¬³qª¾«H¡C



«h¸ÓCustom rule·|¦]¬°¦¬«H±b¸¹¦³°ÝÃD¦Ó³Q±j­¢°±¥Î¡C



ÂI¶}³W«h¡A¥i¥H¬d¬Ý¨äª¬ºA¡A¥H¥»¨Ò¨Ó»¡¡A¦]¬°¹ïÀ³ªº±b¸¹³Q°±¥Î¡A©Ò¥H¥X²{±b¸¹¤£¦s¦bªº¿ù»~¡C



³o¼Ëªº¿ù»~¥²»Ý¥h½s¿è¦¹³W«h¡Aª½¨ì­×¥¿¿ù»~«á¡A³W«h¤~¯à¦A¦¸¹B§@¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-07-31, 16:01 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
³øªí¥\¯àÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos Central¤Wªº³øªí¸ê®Æ¤º®e»P¨¾¤õÀð±ÂÅv¦³ª½±µÃö«Y¡C
Base license¥u¦³«O¯d7¤Ñªº¸ê®Æ¶q¡A
¦³Central Orchestration(¨ó§@) license«h¥i«O¯d30¤Ñªº¸ê®Æ¡A
­Y­n«O¯d¤@¦~ªº¸ê®Æ¡A»Ý­n¦³Central Firewall Reporting Advanced¿W¥ß±ÂÅv¡C



¦p¦ó½T»{¨¾¤õÀð©Ò¾Ö¦³ªº³øªí±ÂÅv¡H
¥i¥H¦b­Ó§Oªº¨¾¤õÀ𤤪½±µ½T»{¸Ó¨¾¤õÀð¾Ö¦³ªº±ÂÅvºØÃþ¡C
¥H§Ú­Ì¤½¥qªº¨¾¤õÀ𬰨ҡA§Ú­Ì¤½¥q¾Ö¦³ªº¬OXstream Protection bundle±ÂÅv¡AùØ­±¥]§t¤FCentral Orchestration±ÂÅv¡A



¦]¬°¦³Central Orchestration±ÂÅv¡A©Ò¥H³o¥x¨¾¤õÀð¥i¥H¦bSophos Central¤¤¬d¸ßªñ30¤Ñ¤ºªº¸ê®Æ¡C



­Y¥u¦³¤@¯ë§K¶O±ÂÅvªº¨¾¤õÀð¡A´N¥u¯à¬d¸ß7¤Ñ¤ºªº³øªí¸ê®Æ¡D



¥t¥~¦³Central Orchestration±ÂÅvªº¨¾¤õÀð¡A¦b³øªí¤¤´N¥i¥H²Õ¦Xªº¤è¦¡¡A¤@¦¸¿ï¾Ü¦h¥x¨¾¤õÀð¡C
³z¹L¦h¥x¨¾¤õÀ𪺳øªí¿é¥X¡A¥i¥HºîÆ[¨ä¶¡ªº®t²§¡C



¦ý¨S¦³Central Orchestration±ÂÅvªº¨¾¤õÀð¡A¨ä§Ç¸¹«e·|¦³¤@­Ó i ²Å¸¹¡A
´£¥Ü±z¦h¥x³øªíªº¿é¥X¥u´£¨Ñµ¹¦³¶i¶¥±ÂÅvªº¨¾¤õÀð¡C
Multi-device reporting is only available with the Advanced license.



¦Ü©ó´£¨Ñªº³øªí¤º®e¡Aª½±µ¤WSophos CentralªH¬Ý¤ñ¸û§¹¾ã¡C



¦ý¤ñ¸û¦³·N«äªº¬O¡ALog viewer¤]¥X²{¦b¨ä¤¤¡C



¦Ó¥B¥i¥H¬d¸ß¹L¥h´Á¶¡ªºlog°O¿ý¡A
¤£¹³¦aºÝ¥u¯à¬d²{¦b®É¶¡©¹«e±Àªº¤@¬q®É¶¡¸ê®Æ(¦Ó¦aºÝªº³o­Ó´Á¶¡ÁÙ¤£©T©w)...
³oºâ¬O­ÓÅý¤H²´·ú¤@«Gªº¥\¯à¡I


¡ô¨Ò¦p§Ú¥i¥H¬d¸ß«e30¤Ñªºlog°O¿ý¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-07-31, 15:19 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2394

shunze Â÷½u
¶³ºÝ»P¦aºÝªº½Ä¬ð´ú¸ÕÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦b¨¾¤õÀð¯Ç¤JSophos Central²Î¤@¶°¤¤±±ºÞ«á¡A
§Ú·Q³ÌÅý¤H¾á¤ßªº¬O¶³ºÝGroup»P¦aºÝªº³W«h©Îª«¥óµo¥Í½Ä¬ð®É¡A·|«ç»ò³B²z¡H

¥ý¨Ó´ú¸Õ¨¾¤õÀð³W«h
§Ú­Ì¥ý©ó¦aºÝ«Ø¥ß¤@±ø¦W¬°test1ªºVPN to WAN¡AÀu¥ý¶¶§Ç³Ì§Cªº¨¾¤õÀð³W«h¡C



¦aºÝ³W«h«Ø¥ß«á¡A§Ú­Ì¦b©óGroup¤¤«Ø¥ß¤@±ø¬Û¦P¦WºÙ¡A¦ý¤º®e¤£¦PªºDMZ to WAN¸m³»³W«h¡C



¬d¬ÝTasks Queue¡A§Ú­Ì·|µo²{³W«h¤w¦P¨B¦¨¥\ªº¼g¤J¦aºÝ¡C



¦ý©ó¦aºÝ¬d¬Ý¡AÁöµM¦aºÝ³W«h¤º®e³QGroup³W«hÂл\¹L¥h¡A¦ýÀu¥ý¶¶§Ç«h«o¨S¦³¸òµÛÅܧó¡C
³o³¡¤À¦³¨Ç©Ç©Çªº...



±µµÛ´ú¸Õ¥D¾÷ª«¥ó
§Ú­Ì¥ý©ó¦aºÝ«Ø¥ß¤@­Ó¦W¬°shunzeªº1.1.1.1/32 hostª«¥ó¡C



¦A©óGroup¤¤«Ø¥ß¤@­Ó¦WºÙ¬Û¦P¡A¦ý¤º®e¤£¦Pªº1.0.0.0/24ºô¬qª«¥ó¡C



´ú¸Õµo²{¡A¥Ñ©ó¬J¦³ªº¦WºÙª«¥ó¤w¦s¦b¡A©Ò¥HµLªk¦¨¥\¶i¦æ¦P¨B¡I
¹ï©ó³o¼Ëªºª¬ªp¡A§Ú­Ì¦³¨â­Ó¿ï¾Ü¡A¤@­Ó¬O¦A¸Õ¤@¦¸¡A¥t¤@­Ó¬O²¤¹L¦¹°Ê§@¡C



¦pªG¤£ºÞ³o½Ä¬ðªºª¬ªp¡A«ùÄò¶i¦æ¨ä¥¦Åܧó¡A·|µo²{«áÄòªº°Ê§@³£·|¥d¦í¡AµLªk¶i¦æ¡I





­n¹À²¤¹L¦¹½Ä¬ð°Ê§@¡A­n¹À±Æ°£½Ä¬ðªº°ÝÃD¡A«áÄòªº°Ê§@¤~¦³¿ìªkÄ~Äò¶i¦æ¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!


2024-07-31, 14:48 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
¸õ¨ì:
Åã¥Ü±q 11 ¨ì 20 ¦b©Ò¦³ªº 2591 ­Óµ²ªG¤¤.  «123456...»

Powered by: Burning Board 1.1.1 2001 WoltLab GbR