Shunze ¾Ç¶é > ·j´M > ·j´Mµ²ªG «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]

§@ªÌ ¤å³¹
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nNo reportÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

XGªºHD¦³¤Á¤@¶ô¤À³Î°Ï°µ¬°report¦s©ñªÅ¶¡¡A
·íreportªÅ¶¡¨Ï¥Î²v¶W¹L80%¡AXGªºreport´NµLªkÅã¥Ü¤º®e¡C

­ì¼t¦³¤@­ÓKB¥i¥HÅýºÞ²zªÌ¨Ì·ÓKB¤¤ªº»¡©ú¡A§R°£Â¸ê®Æ¥HÄÀ©ñreportªÅ¶¡¡A¨Ó«ì´_reportªº¥¿±`¨Ï¥Î¡C
Troubleshoot on-box reporting issues

¦ý³Ìªñ´X­Ó«È¤á¹J¨ì³o°ÝÃD®É¡A«oµo²{¨ÌKB¾Þ§@report¤À³Î°Ï¨Ï¥Î²v¤w­°¨ì2,30%¡A
µM¦ÓreportÁÙ¬OµLªkÅã¥Ü...

¶}caseµ¹­ì¼t«á¡A­ì¼tªí¥ÜÁÙ­n­«±Ò¥H¤U4­ÓªA°È¤~¯àÅýreport¥¿±`Åã¥Ü¡C
tomcat, apache, reportdb, garner

service <ªA°È¦WºÙ>:restart -ds nosync



¦³¹J¨ìreportµLªkÅã¥ÜªºªB¤Í¤£§«­«±Ò³o4­ÓªA°È¸Õ¸Õ



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2023-04-19, 17:54 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nMTA mode¦Q¸Þªºpolicy³]©wÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bSophos XG email protectionªºMTA³]©w¤¤¡A¦³¤Àinbound»Poutbound¨â­Ó¤£¦P¤è¦Vªº³B²zÅÞ¿è¡C
Inbound¬O«ümail flow¤¤¦¬¥óªÌdomain»Pprotected domain¬Û²Å®É¡A©Ò¶i¦æªº¶l¥ó³B²z¡A
¤@¯ë¨Ó»¡¡A´N¬O¥~³¡mail server°e«H¨ì°µ¬°spam¹h¹DªºXG®É¡AXG¶i¦æ¤F¶l¥ó±½´y«á¡A¦A±Hµ¹¤º³¡¯u¥¿ªºmail server¡C

Outbound«h¬O«ümail flow¤¤±H¥óªÌdomain»Pprotected domain¬Û²Å®É¡A©Ò¶i¦æªº¶l¥ó³B²z¡A
¤@¯ë¨Ó»¡¡A´N¬O¤º³¡mail server¨ì°e«H®É¡A¥ý°e¨ìXG°µ¶l¥ó±½´y¡A¦A¥ÑXG©¹¥~°e«È¤áªºmail server¡C
¦ÓXG¤¤¡§¶l¥ó¥[±K¡¨³o­Ó¥\¯à¡A¥u¯à¹ïÀ³¨ìoutbound³o­Ó¤è¦V¡C

¨º¶¶¤l´N¦n©_¤F¡AMTA modeªº¡§SMTP route & scan policy¡¨¤@­Ódomain¥u¯à¹ïÀ³¤@±øpolicy¡A
­Y¤@­Ódomain¦P®É­n°µinbound»Poutbound¨â­Ó¤è¦Vªº¸Ü¡A
¨º­n«ç»ò°µ¡H

·|³o¼Ë°Ý¥D­n¬OXG¦b¦¬¨ì¶l¥ó«á¡Ainbound¡Boutbound¨â­Ó¤è¦Vªºrouting¦³«Ü¤jªº¤£¦P¡A
inbound¶l¥ó¦b³B²z§¹«á¡A·|©¹¤º³¡ªºmail server°e¡A
©Ò¥Hroute by­n¿ï¤º³¡ªºmail server¡C



Outboundªº³¡¤À¡A«h¬O¦bXG³B²z¹L«á¡A©¹¥~³¡¯u¹êªºmail server°e¡A
©Ò¥Hroute by­n¿ïMX¡A³z¹LDNSªº¸ÑªR¡A¨Ó§ä¥X¥Ø¼Ðdomainªºmail server¡C



¦b¤@­Ódomain¥u¯à«Ø¤@±øpolicy«e´£¤U¡A
¦P¤@±øpolicy«ç»ò¥i¯à¹ïinbound/outbound¨â­Ó¤è¦V°µ¤£¦Pªºrouting¡H



¦Ópolicy¤¤ªºprotected domain¦b¹ïÀ³inbound®É¡A«üªº¬O¦¬¥óªÌdomain¡A
¦boutbound®É¡A«üªº¤S¬O±H¥óªÌdomain¡A

«ç»ò¦P¼Ëªºpolicy¤@¤U¤l¬O¹ïÀ³¦¬¥óªÌdomain¡A¤@¤U¤l¤SÅܦ¨±H¥óªÌdomain¡H
¨âªÌ§¹¥þ¬O¬Û¤Ïªº­C¡I
SophosªºMTA¯uªº¬OÅý§Ú¶WÀY¤j¡I


¦b¶}caseµ¹­ì¼t¡A©¹¨Ó©P±Û¼Æ¤Ñ«á¡A­ì¼tÁ`µ¹¥Xº¡·Nªºµª®×¤F(case ID: 06166848)¡C
­ì¨ÓMTA modeªº¡§SMTP route & scan policy¡¨½T¹ê¹ïÀ³¨ìinbound»Poutbound¨â­Ó¤è¦V¡A
·í¦¬¥óªÌdomain»Ppolicy¤¤protected domain¬Û²Å®É¡A³o±øpolicy°µªº´N¬Oinbound¤è¦Vªº³B²z¡F
¤Ï¤§·í±H¥óªÌdomain»Pprotected domain¬Û²Å®É¡A³o±øpolicy°µªº´N¬Ooutbound¤è¦Vªº³B²z¡C
MTAªºpolicy·|¥D°Ê®Ú¾Ú¦¬¥óªÌ»P±H¥óªÌdomain¨Ó°µ¤Á´«¡I

¨º¸U¤@¦¬¥óªÌ»P±H¥óªÌ³£¬O¬Û¦Pdomain®É¡AMTA¤S·|«ç»ò§PÂ_¡H
³o®É¦¬¥óªÌ·|¦³¸û°ªªºÀu¥ýÅv¡A¦]¦¹¶i¦æªº·|¬Oinbound¤è¦Vªº¶l¥ó³B²z¡C


±q­ì¼t¦^ÂШӬݡAÁöµM¸Ñ¨M¤F¦P¤@­Ódomain«ç»ò·|¤@¤U«ü¦V¦¬¥óªÌ¡A¤@¤U¤l¤S«ü¦V±H¥óªÌªº§x´b¡A
¦ý½T»{in/outbound¤è¦V«áªºroute by«ü¦VÁÙ¬O«Ü¦³°ÝÃD¡C

¦]¬°policyªº¤º®e¦b«Ø¥ß«á¡Aµ¥¦P¬O¼g¦ºªº¡A
route by­Y«ü¦V¤º³¡mail server¡A¥u­n®M¥Î³opolicy¡A¤£½×in/outbound³£¬O¾É¦V¤º³¡mail server¡F
route by­Y«ü¦VMX¸ÑªR¡A®M¥Î³opolicyªºin/outbound³£·|³z¹LDNSªºMX record¨Ó°µ¸ÑªR¡A
³o¤£¬O©Ç©Çªº¡H¡H¡H


¹ïÀ³¨ì¤@¶}©lªº°ÝÃD¡A
¦P¤@­Ódomain¡A¥i¥H¦P®É°µinbound»Poutbound¨â­Ó¤è¦Vªº¶l¥ó³B²z¶Ü¡H

¦bSophos¤£»{¬°³o¬O­Ó°ÝÃD¡A¤]¤£¥´ºâ§âin/outbound°µ­Ó¤À©î³B²z¡A
µw¬O­n§âin/outbound¨â­Ó¤è¦Vªºmail flow¥H¦P¤@±øpolicy¨Ó³B²z¡A
§Ú»{¬°¬O¦³­·ÀIªº¡C
¦]¬°¥¦¯uªº²V²c¤£²M¡I



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2023-03-07, 15:55 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nrouting defer (-51):retry time not reachedÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

³Ìªñ«È¤á¹J¨ì¤@­Ó©_©Çªº°ÝÃD¡A·íXG¥H¤º«ØªºMTA±H«H®É¡AÁ`·|¥d¦bMail Spool¤¤¡A
«D±o­n¦bMail Spool¤¤¤Ä¿ï¥d¦íªº¶l¥ó¡A«ö¤Uretry¡A
µM«á...
¥d¦íªº¶l¥ó´N¯à¦¨¥\°e¥X¤F¡I¡I

¶l¥ó¥d¦íªº¿ù»~°T®§¦p¤U¡C

routing defer (-51) DT=0.000s:retry time not reached


©ó¦¹ª¬ºA¤U¡A§Y«Kµ¥¤F´X¤Ñ¡A¥d¦íªº¶l¥óÁÙ¬O¤£·|°e¥X¡F
©Çªº¬O«ö¤Uretry¡A¥d¦íªº¶l¥ó¥ß°¨´N°e¥X¥h¤F...

§Y¨Ï§R°£Mail Spool¤¤©Ò¦³¥d¦íªº¶l¥ó¡AµM«á¦A´ú¤@¦¸¡Aµ²ªGÁÙ¬O¤@¼Ë...
³o¨ì©³¬O«ç»ò¤@¦^¨Æ°Ú¡H


¶}caseµ¹­ì¼t³B²z¤]¨S¥Î¡A©ì¤F´X¤ÑÁÙ¬O¨S¦³¶i«×¡C
³Ì«á¦b°Q½×°Ï¤¤µo²{¤@½g¦³®Äªº³B²z¤èªk¡C

¸Ó¤åªº§@ªÌµo²{¡AXG°µ¬°MTA®É¡A¨Ã¤£¬O³z¹LsmtpdªA°È¡A¦Ó¬OeximªA°È¡C
¦ÓeximªA°È¥d¦í®É¡A´N¥²»Ý³z¹L¥H¤Uadvanced shell«ü¥O¡A²MªÅ¥d¦íªº¶l¥ó¤~¯à®Ú¥»¸Ñ¨M°ÝÃD¡C
# service smtpd:stop -ds nosync
200 OK
# exim -bp | awk '{print $3}' | while IFS= read -r line; do
> exim -Mrm $line
> done
¤U§¹done«á¡A´N·|ªáÂI®É¶¡¥h§R°£¥d¦íªº¶l¥ó¡C
# rm /sdisk/spool/output/db/*
# service smtpd:start -ds nosync
200 OK


²M°£exim¥d¦íªº¶l¥ó«á¡AXGªºMTAªGµM¯à°÷¦¨¥\ªº±H«H¥X¥h¤F¡ã


PS.
¶}caseµ¹­ì¼t¡A­ì¼tsupport«á¨Ó´£¥Xªº¸Ñ¨M¤è¦¡¦p¤U¡A¤@¨Ö´£¨Ñµ¹¤j®a°Ñ¦Ò¡C
rm -rf /var/spool/output/db/retry*


°Ñ¦Ò¸ê®Æ
MTA troubleshooting guide



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2023-02-10, 17:08 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n18ª©«áªº¸ô¥ÑÀu¥ý¶¶§ÇÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦b17ª©«e¦hWANªº±¡¹Ò¤U¡A¹ï¥~­n¨«­þ­ÓWAN¡H
¥i¥Hª½±µ¦b¨¾¤õÀð³W«h¤¤«ü©w¡A¬Û·íª½Ä±¤è«K¡ã

¦ý¦b18ª©«á¡ANAT»P¨¾¤õ³W«h¤À©î¶}¨Ó¡A
¹ï¥~­n±q­þ­ÓWAN¥X¥hÅܪº³Â·Ð¦h¤F...

­n±q­þ­ÓWAN¥X¥h¡A18ª©«á¥u¯à¦bpolicy routing¤¤ÃB¥~¥h©w¸q¡C
¨º»òpolicy route¡Avpn route¸òstatic route¤TºØ¸ô¥ÑªºÀu¥ý¶¶§Ç¡A¦b18ª©¤¤¤S¦³¤°»òÅܤƩO¡H


¦bXG¤¤¡A¥i³z¹L¥H¤U«ü¥O©óconsole³]©wstatic route¡AVPN»Ppolicy routeªºÀu¥ý¶¶§Ç¡C

system route_precedence set static vpn sdwan_policyroute

17ª©¹w³]ªºÀu¥ý¶¶§Ç¬°policyroute vpn static¡A
18ª©«á¹w³]ªºÀu¥ý¶¶§Ç«h§ï¬°static sdwan_policyroute vpn¡C

°ÝÃD¨Ó¤F¡A18ª©¤¤¹w³]ªº¸ô¥ÑÀu¥ý¶¶§Ç¬O§_²Å¦X¤@¯ë±¡¹Ò¡H


¶¶¤l»{¬°¡A¦b¥u¦³¤@±øWAN¡A¥B¨S¦³site to site VPNªº±¡¹Ò¤U¡A
ºû«ù¹w³]³]©w¬OOKªº¡A²¦³ºÀô¹Ò³æ¯Â¡C

¦ý­Y¦³¦h±øWAN¡A¤º³¡ºô¸ô©Î¥D¾÷·|¨Ì¤£¦P»Ý¨D³z¹L¹ïÀ³ªºWAN³s¥~¡A¥B¦³site to site VPNªº±¡¹Ò¤U¡A
³o¹w³]ªº¸ô¥Ñ¶¶§Ç¬O­n»Ý­n½Õ¾ãªº¡C

¦b¦³site to site VPNªº±¡¹Ò¤U¡AVPN tunnel¨âºÝºô¬qªº³q¾É³Ì¬°­«­n¡A
©Ò¥HVPN­n³]©w¬°³ÌÀu¥ý¡C

­Y¤º³¡¦³¨ä¥¦router¨Ó³q¾É¨ì¤º³¡¨ä¥¦ºô¬q¡A¦Ópolicy route¥u¬O¥Î¨Ó«ü©w¹ï­n¨«ªºWAN¡A
¨º»òstatic routeªºÀu¥ýÅv­n¤j©ópolicy route¡A
¤£µM¥h¨ì¤º³¡¨ä¥¦ºô¬qªº¸ô¥Ñ·|³Qpolicy route·m¨«¦Ó±q«ü©wªº¥~ºô¥X¥h¡C

Á`µ²¨Ó»¡¡A¶¶¤l«Øij18ª©«áªº¸ô¥ÑÀu¥ý¶¶§Ç¥i½Õ¾ã¬°vpn static sdwan_policyroute¡A
³o¼ËªºÀu¥ý¶¶§Ç¤ñ¸û²Å¦X¤j³¡¤Àªº±¡¹Ò¡C


PS.
17ª©´N¨S¦³³o¨Ç§xÂZ¡ASophos¯uªº¬O¦b·h¿j¯{¸}¡I
¤£ª¾¹D·|¤£·|¦³¤@¤Ñ¡A¤S§âNAT¸òFirewall rule¸j¦b¤@°_¤F...



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2023-01-31, 17:33 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nProxy mode¤UXGµo¥X¹L´Á¾ÌÃÒÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

«È¤á©óProxy mode¤U¡A¥X²{¤FXGµo¥X¹L´Á¾ÌÃÒµ¹¥~³¡¯u¹ê¯¸¥xªº°ÝÃD¡C
¥Ñ©ó¾ÌÃÒ¹L´Á¡A¥Î¤áºÝªºÂsÄý¾¹µLªk¦¨¥\ÂsÄý¥~³¡¯¸¥x¡C



ºô¸ô¤W¬d¨ì³o¬O¤@­Óbug(NC-100078/NC-100265)¡A
¥i¥H³z¹L²M°£ /var/certcache/ ¥Ø¿ý¤Uªº¾ÌÃÒ§Ö¨ú¡D¨Ó¸Ñ¨M¦¹°ÝÃD¡C
¦ý¤S¤£«Øij§R¥ú¦¹¥Ø¿ý¤Uªº©Ò¦³§Ö¨ú¡A©Ò¥H§Ú´N¶}¤Fcase¸ß°Ý­ì¼t¡C

­ì¼tµ¹¤F¥H¤Uadvanced shellªº«ü¥O¡A
³z¹L¥H¤U«ü¥O¨Ó²M°£§Ö¨ú¡A¦A­«±Òweb proxyªA°È¨Ó±Æ°£¦¹¾ÌÃÒ¹L´Á°ÝÃD¡C

touch /var/certcache/.clear_all_certs_on_reload
service -ds nosync awarrenhttp:restart


¸g«È¤á´ú¸Õ«á¡A°ÝÃD¶¶§Q±Æ°£¡I
¶¶¤l¯d¤U¦¹µ§°O¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2023-01-09, 10:55 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nXG³s¤£¤W¤F¡A«ç»ò¿ì¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XG¦bV18ª©«á°µ¤F«Ü¤jªºÅÜ­²¡A
NAT³W«h¦Û­ì¥»¨¾¤õÀð³W«h¤À©î«á¡A³y¦¨«Ü¦h³W«h³]©w¤Wªº°ÝÃD¡A
¬Æ¦Ü¦³´X­Ó«È¤á¦]¬°NAT³W«hªº¿ù»~°t¸m¡A¦Ó¾É­PXGªº¥¢Áp¡I

­ì¥»§Ú¥H¬°¦b³o±¡ªp¤U¡A¥u¯à«ì´_¥X¼t¹w³]­È¡AµM«á¦A§â³Æ¥÷ªº²ÕºAÀɭ˦^¥h¡C
(³o®É­Ô§A´Nª¾¹D²ÕºA³Æ¥÷±K½X»PSSMKªº­«­n©Ê¤F§a!)

¤£¹L¬Q¤Ñ«È¤áÅý§Úª¾¹D¤F¥t¤@ºØ§ó¦³®Ä²vªº°µªk - enable appliance_access¡C


¨ä¹êconsole¤Uªº³o­Ó«ü¥O¡A§Ú¦b¤@¶}©l±µÄ²Sophos XG®É´Nª¾¹D¤F¡C

system appliance_access enable


§Úª¾¹D³o«ü¥O¦b°õ¦æ«á¡A¥i¥HµLµøDevice Access¤¤ªº³]©w¡A
ª½±µ©ñ¦æ¤¶­±IPªº³s¤JÅv­­¡C

¦ý³o«ü¥O enable «á¡A·|¥á±ó©Ò¦³¥~¥X¨ìinternetªº¬y¶q¡A
©Ò¥H¦b¥¿±`¹B§@±¡ªp¤U¡Aappliance_access¬O­n«O«ù¦bdisable³o­Óª¬ºAªº¡C


§Ú¥H¬°V18ª©«á¡A¿ù»~ªºNAT³W«h·|«ùÄò¦bXG¤¤¹B§@µo»Ã¡A
§Y«K¬O enable appliance_access¡A¤]µLÀÙ©ó¨Æ...

¦ý«È¤áÅý§Úª¾¹D§Y«K¦b¿ù»~ªºNAT³W«h§@¥Î¤U¡A
ÁÙ¬O¯à³z¹L enable appliance_access ¨Ó©ñ¦æ¤¶­±IPªº³s¤J¯à¤O¡A¶i¦Ó¥h­×´_¿ù»~ªºNAT³W«h¡A
§¹¦¨«á¦A±Nappliance_access disable§Y¥i¡C
³o¯u¬O«Ü­«­nªº¤@­Ó¸ê°T°Ú¡I


¥H¤U¶¶¤l³v¤@¸Ñ»¡¡A¦b¿ù»~ªºNAT³W«h§@¥Î¤U¡A¦p¦ó«ì´_XGªº¥¿±`¨Ï¥Î¡C
  1. ­º¥ý§ä¨ì¤@±øconsole½u¨Ó¸òXGªºCOM port¹ï±µ¡C
    ¦pªG¨S¦³ºD¥Îªºconsole½u©ÎÁ{®É§ä¤£¨ìconsole½u¡A
    XGªº°t¥ó²°ùئ³¤@±øMicro-USB½u¡A³o±ø½u´N¥i¥Hª½±µ¸òXGªºMicro-USB port¹ï±µ¡A
    µM«á¥Ñ¹q¸£¼ÒÀÀ¥XCOM port¨Ó¨Ï¥Î¡C







  2. Console½u¹ï±µ¦n«á¡A±µµÛ¶}±Òputty³nÅé¡C
    ³s½u³t«×ªº³¡¤À¡A½Ð³]©w¬°38400¡A¦Ó¤£¬O¹w³]ªº9600³á¡ã



  3. ¦¨¥\³s½u«á¡A½Ð¿é¤Jadminªº±K½X¨Ó¶i¦æµn¤J¡C
    ¥Ñ©óconsole¥u¤¹³\admin³o­Ó¯S®í±b¸¹µn¤J¡A
    ¦]¦¹¡A³s½u¦¨¥\«á¡A¬J¤£»Ý­n¡B¤]¤£¤¹³\³z¹L¨ä¥¦±b¸¹µn¤J¡C
    ½Ðª½±µ¿é¤Jadminªº±K½X¨Ó¶i¦æµn¤J¡C

  4. ¦¨¥\¥Hadmin±b¸¹µn¤J«á¡A¿ï4¶i¤JDevice Console¡C



    µM«á¦A¿é¤J¥H¤U«ü¥O¡A«ì´_XG LANºÝWebUIµn¤J¥\¯à¡C
    system appliance_access enable


  5. ­×¥¿©Î°±¥Î¿ù»~ªºNAT³W«h«á¡A°O±o¦A³z¹L¥H¤U«ü¥O«ì´_XGªºrouting¥\¯à¡C
    system appliance_access disable



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2022-11-25, 15:03 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n´ª¥XATP¨Æ¥ó¤¤¯u¥¿ªº³s½uclientÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

SophosªºATP¼Ò²Õ¯à¦btraffic³z¹LXG°µrouting®É¡A§Y®Éªº¹LÂoÄdªý¦³®`³s½u¡A
¦ý¦bºô°ìÀô¹Ò¤¤¡A³ÌÀYµhªº´N¬ODNS Clientªº¸ÑªR°ÝÃD¡C

ÁöµM´c·NdomainªºDNS¸ÑªR³QXGªºATPÄd¤U¨Ó¤F¡A
¤£¹Lºô°ì¤¤clientªºDNS¬O«ü¦V¤º³¡ªºDNS Server¡A
·íclient±ý³s¨ì´c·Ndomain®É¡A²Ä¤@¨BªºDNS¸ÑªR¤u§@·|¥æµ¹¤º³¡DNS Server¨Ó¶i¦æ¡A
¤º³¡DNS Server¨S¦³´c·NdomainªºIP¹ïÀ³¸ê°T¡A¦]¦¹·|¦A¦V¤W¼hDNS¥D¾÷­n¨D¸ÑªR¡A
¥H¦Ü©óATPÄdºI¨Æ¥ó¤¤¡AÄdªº¨Ó·½IP©¹©¹³£¬O¤º³¡ªºDNS Server¡A¦Ó¤£¬Oª½¥¿ªºDNS Client...

§ä¤£¥X¨Ó¯u¥¿¦³°ÝÃDªºDNS Client¡A¤£¬ODNS Server¤]¤£¬OATPªº°ÝÃD¡A
¥¦­Ì³£¥¿±`ªº°õ¦æ¥æ¥Iªº¤u§@¡D³o¬Oºô°ìÀô¹Ò¬[ºc¤Uªº­­¨î¡C
¨º»ò¦b³o¼Ëªº¬[ºc¤U¡A¦³¨S¦³¿ìªk´ª¥X¯u¥¿ªºDNS Client©O¡H


¶¶¤l·Q¨ì¤F¤@­Ó°µªk¡A¤£¹L¥¦»Ý­nDNS Serverªº°t¦X¡C
¬JµMDNS¸ÑªR¤u§@¬O¥Ñ¤º³¡ªºDNS Server¨Ó¶i¦æ¡A¨º»ò§Ú­Ì´Nª½±µ¦bDNS Server¤W«Ø¥ß¤@µ§¸ÓdomainªºIP¹ïÀ³record¡A
¨Ò¦p±N´c·Ndomain msdnupdate.com ¹ïÀ³¨ì 10.199.199.2 ³o­Ó¨S¦b¨Ï¥ÎªºIP¡C
¦p¦ó³]©w¡HWindowsªºDNS¥D¾÷¥i¥H°Ñ¦Ò ³o¤@½g ªº°µªk¡C

µM«á¦bXG¤W±Ò¥Î¤@­Ó¶¢¸m¤¶­±¡A°t¸m¤@­Ózone»P³o­Ó°²IP¦Pºô¬qªºIP¡A¨Ò¦p 10.199.199.1/29¡A
±µµÛ³]©w¤º³¡¨ì³o­Ózone(©ÎIP)ªºªý¾×³W«h¡A¨Ã¤Ä¿ïlog°O¿ý¡A
³o¼Ë·í¤º³¡¹q¸£±ý³s¨ì³o­Ó´c·Ndomain®É¡ADNS Server´N·|«ü¦V³o­Ó°²IP¡A
¦Ó¹q¸£¨Ì·ÓDNS¸ÑªR¥X¨Óªºµ²ªG¡A³z¹LXG routing­n³s¨ì³o­Ó°²IP®É¡A´N·|³QXG¤Wªºªý¾×³W«h©Ò°O¿ý¤U¨Ó¡A
§Ú­Ì¥u­n¥h¬d¬Ýlog¡A´N¥i¥H²M·¡ª¾¹D¦³­þ¨Ç¤º³¡IP¸Õ¹Ï³s¨ì³o­Ó´c·Ndomain¡A´ª¥X¯u¥¿ªºDNS client¡I

¬°¤FÁקK³s½u³QATP©ÒÄdºI¡A³]©w§¹¦¨«á¡A
½Ð±N³o­Ó´c·Ndomain¥[¨ìATPªºexception¤¤¡A°µ¨Ò¥~©ñ¦æ¡A¥Ñ³]©wªý¾×³W«h¨Ó¶i¦æÄdªý¡C


³o­Ó¤èªk¦b¹ê°µ¤W¦³´X­Ó­«ÂI­nª`·N¡C

  1. ¸jIPªººô¥d¥²»Ý¬°upª¬ºA¡A²³æ¨Ó»¡´N¬O³o±iºô¥d¥²»Ý±µ¤Wswitch¡A
    ³o¼Ë¤¶­±¸ô¥Ñ¤~·|¹B§@¡A¾É¦V°²IPªº¬y¦V¤~·|routing¨ì³o­Ó¤¶­±¡A¶i¦Ó³Q¨¾¤õÀð³W«hªý¾×¦Ó¯d¤U°O¿ý¡C
    ­Y¥u¬O³]©w¦nIP¸ê°T¡A¦ýºô¥d¤¶­±¬°down¡A«h¤¶­±routing¤£·|¥Í®Ä¡C

    ºô¥d¤¶­±¥i¥H¬O¤@¯ëºô¥d¡BVLAN©Î¬OAlias IP¡A
    ­Y¨Ï¥ÎAlias IP¨Ó³]©w¡A¨º«ÊÂê°O¿ýªº¨¾¤õÀð³W«h»Ý¤p¤ß©w¸q¡A¥H§K³s±a¾×±¼©Ò¦³¥¿±`¬y¶q¡C

  2. ¥Î¨Ó¸É§ìDNS Client IPªº¨¾¤õÀð³W«h¥²»Ý¬Oªý¾×Ãþ«¬¡A
    ­Y±Ä¥Î©ñ¦æ³W«h¡A«h¸Óºô¥d¤¶­±¥²»Ý¯uªº±µ¨ì¤@¥x³]©w°²IPªº¥D¾÷¤~·|¯d¤U°O¿ý¡A
    ¤j¤jªº¼W¥[½ÆÂø«×¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2022-09-20, 14:14 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n³q¦æ¶O¶BÄFÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

5/7¤@¦­¡A¶¶¤l¦¬¨ì¤F¤@«Ê³q¦æ¶O§Y±N¨ì´ÁªºÂ²°T³qª¾¡A
­n¶¶¤l¥ß§Y³z¹L²°T¤¤ªº³sµ²¡A¤U¸üAPP¨Ó½u¤Wú¶O¡C



¶¶¤lªºETC¬OÀx­È¦Û°Ê¦©Ãºªº¡A¦L¶H¤¤ÁÙ¦³¿ú°Ú¡I
³o­Ó29¤¸ªº¶O¥Î¡A¬O§_·N¨ýµÛ¶¶¤lETCùرb¤áùؤw¨S¿ú¤F¡H

³z¹Lºô¸ô¬d¸ß«á¡A
±b¤áùØÁÙ¦³¤C¦Ê¦h¤¸°Ú¡I
¨º»ò³o­Ó³sµ²¬O¤°»ò¡H¡H

½Æ»s³sµ²«á¡Aµo²{¥¦·|¤U¸ü¤@­ÓapkÀÉ¡A
¤@¯ë¨Ó»¡¡A©x¤èªºAPP·|¥s§A¨ì¥«¶°¥h¤U¸ü¡A
©ñ¦b¥«¶°¤WªºAPP°ò¥»¤W¤]³£¸g¹L¤FApple©ÎGoogleªºÅçÃÒ¡A
¦w¥þ©Ê¼h°ò¥»¤W¤ñ¸û¨S¦³°ÝÃD¡C

³o­Ó¥suser¦Û¤v¤U¸üapkÀɨӦw¸Ëªº¡A­·ÀI«Ü°ª¡I
¦A¥[¤W¶¶¤l±b¤áùØ©ú©ú¦³¿ú¡A«o¸ò§A»¡¶O¥Î¥¼Ãº¡A©úÅ㦳°­¡I
§ó¶Bªº¬O¨ì´Á¤é´N¬O²°Tµo°e·í¤é¡AÂ\©ú¤F­n§Q¥Î¨Ï¥ÎªÌ¾á¤ß¹L´Á»@´Úªº¤ß²z¡A
¨Ó¶BÄF¨Ï¥ÎªÌ¤W¤Ä¡A¯u¬O¥i´c°Ú¡I



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2022-05-09, 10:35 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nSSLVPN«È¤áºÝ³nÅéEoL¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos¤½§i¡A°ò©óOpen VPNªºSSLVPN¥Î¤áºÝ³nÅé(¬õ½t¿Oª©)±N©ó2022¦~1¤ë31¤éEoL¡C



­ì¥»¤w¤U¸ü¦w¸Ëªº¬õºñ¿Oª©SSLVPN³nÅé¥i¥HÄ~Äò¥¿±`¨Ï¥Î¡A
¦ý«áÄò¦bUser Portal¤W´£¨ÑªºVPN¼·±µ³nÅé¡A±N·|¥ÑSophos Connect¨Ó¨ú¥N¡C




³o·N¿×µÛSophos¦bWindows¤W©ñ±ó¤FOpen VPN³o­Ó¤½ª©³nÅé¡A
§ï±À¦Û®a¶}µo¥i¦P®É¤ä´©IPsec VPNªºSophos Connect³nÅé¡C
¦ý¦b¨ä¥¦¨t²Î¤W¡A¨Ò¦pMac¡A¦æ°Ê¸Ë¸m¤W­Ë¬O¨S¦³Sophos Connectªº¹ïÀ³¤è®×¡A
©Ò¥HÁÙ¬O­n¾aOpen VPN¡C

´«¦¨Sophos Connect¹ïWindows User¨Ó»¡¦³¤°»ò¼vÅT¡H

  1. Sophos Connect¤£¤ä´©Win7¡A©Ò¥H­Y§AÁÙ¬OWin7ªº¨Ï¥ÎªÌ¡AÁÙ¬O«O¯d§Aªº¬õºñ¿Oª©³nÅé¡C
    ¤£µM´N¥h¤U¸ü¤½ª©ªºOpen VPN¨Ó¨Ï¥Î§a¡C

  2. Sophos Connect¤£¤ä´©¦h±b¸¹¤Á´«¡C
    ¬õºñ¿Oª©ªº³nÅé¤ä´©¦h±b¸¹²ÕºA¶×¤J¡A
    ¦P¤@­Ó¼·±µIP¦b¶×¤J¦h­Ó²ÕºA«á¡A±z¥i¥H¦Û¥Ñ¤Á´«­n¥Î­þ­Ó±b¸¹¨Ó¶i¦æSSLVPNªº¼·±µ¡C



    ¦ýSophos Connect¤£¦æ¡I
    ¤@­Ó¥Øªº¦aIP¥u¯à¦³¤@­Ó²ÕºAÀÉ¡C

  3. ¦w¸ËSophos Connect«á¡A¨Ï¥ÎªÌ²ÕºAªº¨ú±oµLªk³z¹LUser PortalªºDownload Configuration for Windows¨Ó¦w¸Ë¡A
    ¥²»Ý³z¹LDownload Configuration for Other OSs¨Ó¤U¸ü²ÕºAÀÉ¡A



    µM«á¦A¥ÑSophos Connect¶×¤Jovpn®æ¦¡ªº²ÕºAÀÉ¡C


¨ä¥¦´N¨S¦³¤Ó¤j®t§O¤F¡A²¦³º¥¦¬O¤@­Ó¼·³qªº´C¤¶¡A¹ïÀ³ªº¨Ï¥ÎÅv­­ÁÙ¬O¦bXG¤W±±¨î¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2022-02-18, 17:11 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nV18ªºDirect Proxy³]©wÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦bV18¤§«á¡ASophos§â­ì¥»ÁôÂêº0¸¹ªý¾×³W«h±j¨îÅã¥Ü¤F¡I
¦Ó³o±ø³W«h¦bDirect Proxyªº¨Ï¥Î¤W¤S·|³y¦¨¤°»ò¼vÅT¡H
´NÅý¶¶¤l¨Ó¹ê´ú¬Ý¬Ý¡C



¸g¹ê»Ú´ú¸Õ¡A±N¥i¥¿±`¹B§@ªºV17 Direct Proxy¤É¯Å¨ìV18«á¡A
­ì¥»user¥i¥H¥¿±`¶}±Òªººô­¶¡A²{¦b³£¥´¤£¶}¤F¡I



­ì¦]´N¸òV17ª©¤@¼Ë¡A·í²M³æ³Ì«á¦³¤@±øªý¾×http/httpsªº³W«h®É¡A
´N¥²»Ý¦b³oªý¾×³W«hªº«e­±¡A¥[¤W¤@±ø®M¥ÎDeny AllªºWeb filterªºhttp/https©ñ¦æ³W«h¡A
§_«h©Ò¦³ºô­¶³£±NµLªk¥¿±`¶}±Ò¡I





¦b¹w³]ªý¾×³W«h«e¡A¥[¤WDeny All Web filterªºhttp/https©ñ¦æ³W«h«á¡Aºô­¶´N¥i¥H¥¿±`¶}±Ò¤F¡A
¤£¶È¥i¥H¨Ì·ÓProxy³W«h¤¤ªºWeb filter¨Ó¶i¦æºô­¶±±ºÞ¡A
¦Ó¥Blog¤¤¡A¤]¥i¥H¬Ý¨ìProxyªºWeb filter log°O¿ý¡C



¦ÓºÝÂI¨S¦³±¾¤Wproxy¡A´NµLªk¥´¶}©Ò¦³ºô­¶¡C



°ò¥»¤WV18ªºDirect proxyªº³]©w´N¨S¦³¤Ó¤j°ÝÃD¤F¡C
(°£¤F¨º­Ó¾ã­Ó¥Ø¼Ðºô¬qµLªk¦bweb exception¤¤©ñ¦æªº°ÝÃDµLªk¸Ñ¨M¥H¥~...)


°Ñ¦Ò¸ê®Æ
Resolve issues related to web proxy when...l rule is added



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2022-01-25, 16:31 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
¸õ¨ì:
Åã¥Ü±q 21 ¨ì 30 ¦b©Ò¦³ªº 2070 ­Óµ²ªG¤¤.  «1234567...»

Powered by: Burning Board 1.1.1 2001 WoltLab GbR