Shunze ¾Ç¶é > ·j´M > ·j´Mµ²ªG «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]

§@ªÌ ¤å³¹
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nAPIÀ³¥Î½d¨ÒÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦b¨¾¤î¡§¼É¤O²q´ú±b±K¡¨¤W¡A¥Ñ©óXG¥u¬O¶i¦ærouting¡A±N³s½u»Ý¨DÂ൹«áºÝªºserver¡A
©Ò¥HXG¥»¨­¨Ã¤£ª¾¹D¨C¦¸³s½u©Ò¿é¤Jªº±b¸¹/±K½X¬O§_¥¿½T¡H
¦ÛµM¤]´NµLªk¿ì¨ì¡§¿é¤J¿ù»~±b±K´X¦¸«á¡A«ÊÂê´c·NIP¡¨³o¼Ëªº¤u§@...

¦ý°²³]«áºÝ¥D¾÷¥i¥H¥D°ÊÂ^¨ú¡§¿é¤J¿ù»~¦¸¼Æ¹L¦hªºIP¸ê°T¡¨,
¨ºXG¯à§_¥D°Ê¥h«ÊÂê³o¼Ëªº´c·NIP³s½u¡H

µª®×¬O¥i¥Hªº¡I
XG´£¨ÑAPI¥\¯à¡AÅý«áºÝ¥D¾÷¥i¥H³z¹LXML®æ¦¡¡A±N­nªý¾×ªºIPª«¥óª½±µ¦bXG¤¤«Ø¥ß¡C
§Ú­Ì¥u­n¦b¨¾¤õÀð³W«h¤¤¡A¹w¥ý«Ø¦nªý¾×³W«h¡A
¦A¥Ñ«áºÝ¥D¾÷¥hºûo­Óblock IP²M³æ©Î¸s²Õ¡A´N¥i¥H¹ê²{³o¼Ëªº»Ý¨D¡C


¨Ï¥ÎAPI¥\¯à®É¡A½Ð¥ý½T»{°õ¦æªººÞ²z­û±b¸¹¬O§_¨ã¦³ª«¥óªº¼g¤JÅv­­¡C



µM«á¦A©óAPI Configuration¤¤©ñ¦æ«áºÝ¥D¾÷ªº¨Ï¥ÎÅv­­¡A



³o¼Ë´N«áºÝ¥D¾÷´N¥i¥H¨Ï¥ÎºÞ²z­ûÅv­­±b¸¹¨Ó°õ¦æAPI¥\¯à¤F¡ã


­º¥ý¡A§Ú­Ì¥i¥H³z¹L¥H¤U«ü¥O¨Ó¬d¬ÝIPª«¥ó²M³æ»P®æ¦¡¡C

https://XG_IP/webconsole/APIController?reqxml=<Request><Login><Username>admin_account</Username><Password>P@ssw0rd</Password></Login><Get><IPHost><Name></Name><IPFamily></IPFamily><HostType></HostType><IPAddress></IPAddress></IPHost></Get></Request>


­Y§Ú­Ì­n¨ú±oBlock_IP³o­ÓIP Listª«¥óªº¤º®e¡A¥i³z¹L¥H¤U«ü¥O¡C
https://XG_IP/webconsole/APIController?reqxml=<Request><Login><Username>admin_account</Username><Password>P@ssw0rd</Password></Login><Get><IPHost><Filter><key name="Name" criteria="like">Block_IP</key></Filter></IPHost></Get></Request>


­YBlock_IP³o­ÓIP Listª«¥ó¤£¦s¦b¡A§Ú­Ì¥i¥H³z¹L¥H¤U«ü¥O¨Ó«Ø¥ß¡C
https://XG_IP/webconsole/APIController?reqxml=<Request><Login><Username>admin_account</Username><Password>P@ssw0rd</Password></Login><Set operation="add"><IPHost><Name>Block_IP</Name><IPFamily>IPv4</IPFamily><HostType>IPList</HostType><ListOfIPAddresses>199.199.199.199</ListOfIPAddresses></IPHost></Set></Request>


­YBlock_IP³o­ÓIP Listª«¥ó¤w¦s¦b¡A§Ú­Ì¥i¥H³z¹L¥H¤U«ü¥O¥h§ó·s¥¦ªºIP¤º®e¡C
https://XG_IP/webconsole/APIController?reqxml=<Request><Login><Username>admin_account</Username><Password>P@ssw0rd</Password></Login><Set operation="update"><IPHost><Name>Block_IP</Name><IPFamily>IPv4</IPFamily><HostType>IPList</HostType><ListOfIPAddresses>199.199.199.199</ListOfIPAddresses></IPHost></Set></Request>


­n§R°£Block_IP³o­Ó¯S©wIP Listª«¥ó¡A«h¥i³z¹L¥H¤U«ü¥O¡C
https://XG_IP/webconsole/APIController?reqxml=<Request><Login><Username>admin_account</Username><Password>P@ssw0rd</Password></Login><Remove><IPHost><Name>Block_IP</Name><IPFamily>IPv4</IPFamily><HostType>IPList</HostType></IPHost></Remove></Request>


­Y§Ú­Ì¤£·Q¥ÎIP Listª«¥ó¨ÓºÞ²z¡A·Q­n³z¹LIP¸s²Õªº¤è¦¡¨ÓºÞ²z¡A
±N­n³Q«ÊÂꪺIPª«¥óª½±µ¥[¨ìBlock_IP_Group¸s²Õ¤¤¡A¥i¥H³z¹L¥H¤U«ü¥O¨Ó«Ø¥ßÁõÄÝ©ó¸s²ÕªºIPª«¥ó¡C
https://XG_IP/webconsole/APIController?reqxml=<Request><Login><Username>admin_account</Username><Password>P@ssw0rd</Password></Login><Set operation="add"><IPHost><Name>Test_IP</Name><IPFamily>IPv4</IPFamily><HostType>IP</HostType><HostGroupList><HostGroup>Block_IP_Group</HostGroup></HostGroupList><IPAddress>199.199.199.199</IPAddress></IPHost></Set></Request>



¦³¤F¥H¤W´X­Ósample«ü¥O«á¡A
¦b«áºÝ¥D¾÷¤W¡A§Ú­Ì´N¥i¥H³z¹Lcurl(linux¥D¾÷)©Îpowershell(Windows¥D¾÷)©óXG¤Wª½±µ«Ø¥ß«ÊÂꪫ¥ó¤F¡ã


°Ñ¦Ò¸ê®Æ
How to use the API



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2020-09-11, 12:11 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n§ó·s¸É¥RÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¤W¤å½d¨Ò¬°LAN to DMZªºUDP flood³]©w¡A
¦pªG¬O­n¨¾Å@¨Ó¦ÛWAN to DMZªºTCP flood¤S¸Ó¦p¦ó³]©w©O¡H

¥Ñ©ó¨Ó¦ÛWANºÝªº¥~³¡IP¬OµLªkª½±µ³s¨ì¦ì¦bXG¤º³¡ªºServer¡A
³oÃþ³s½u»Ý¨D¥²»Ý³z¹LXGªºbusiness application rule¶i¦æDNATÂà§}«á¤~¯à¿ì¨ì¡A
¦]¦¹³]©wWAN to DMZªºflood¨¾Å@®É¡AÁöµM³Ì²×¥Øªº¬O¤º³¡ServerªºµêÀÀIP¡A
¦ý¦b³]©w®É¡AÁÙ¬O­n§â¥Ø¼ÐIP³]©w¬°XG¤Wmappingµ¹¤º³¡Serverªº¥~³¡IP¡C

¨Ò¦pXG¤WªºWAN°t¸m¤F¤@­Ó¥~³¡IP 123.123.123.1¡A
¨Ã§â³o­ÓIPªºTCP 8080 port¾É¦V¤º³¡web server 172.16.16.1¡C
¨º§Ú­Ì­n¹ï³o¥xweb server¶i¦æTCP flood¨¾Å@®É¡A
´N¸Ó¶i¦æ¦p¤Uªº°t¸m¡C

system dos-config add dos-policy policy-name SYN-Flood_over_200 SYN-Flood 200 pps per-src
system dos-config add dos-rule rule-name W2D_TCP_8080 src-zone WAN dstip 123.123.123.1 netmask 255.255.255.255 protocol tcp dport 8080 dos-policy SYN-Flood_over_200


¥H¤W«ü¥O¦b°Ñ·Ó¤W­zªº»¡©ú«á¡A¥Ø¼ÐIPªº¿ï¾Ü¨S¦³¤Ó¤j°ÝÃD¡A
¤ñ¸û¦³°ÝÃDªº·|¬O¡A¬°¤°»ò§Ú­Ì­n¾×ªº©ú©ú´N¬OTCPªºflood¡A¦ý¦bdos-policy¤¤ªº³]©w«o¬OSYN-Flood¡H

³o¬OXG¤W¤ñ¸û¦Q¸Þªº¦a¤è...
¦b dos-config ¤¤ªºflood°Ñ¼Æ¥u¦³SYN-Flood¡A¨S¦³TCP-Flood¡F
¦Ó¦b dos-rule «o¤Ï¹L¨Ó¡Aprotocolªº°Ñ¼Æ¥u¦³tcp¡A¨S¦³syn¡I¡H
©Ò¥H¦bTCP floodªº¨¾Å@¤W¡A¥u¯à¨Ï¥Î³o¼Ëªº°t·f°t³]©w¤F...



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2020-09-11, 12:07 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n­«³]admin±K½XÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦b¶´Å骩¥»17.5¤§«e¡A
­n­«³]admin±K½X¥u¯à¥Îconsole½u±µµÛ¡AµM«á¦b¶}¾÷®É«ö¤UEnterÁä¡A¿ï¾Ü¶i¤JSFLoader¨Ó¹F¦¨¡C









¦b¶´Å骩¥»17.5¤§«á¡A­ì¼t¼W¥[¤F¤@­Ó·sªº¤è¦¡¡A
¤@¼Ë¥Îconsole½u±µµÛ¡AµM«á¦b¿é¤Jadmin±K½X®É¡Aª½±µ¿é¤JRESET¶i¤J¯S®íªº¥\¯à¿ï³æ¡C

µn¤J«á·|µo²{17.5ªº¿ï³æ¦h¥X¤F 4 ªº¥\¯à¿ï¶µ¡A´£¨ÑºÞ²zªÌ­«³]admin±K½X¡C
­«³]«áªºadmin±b¸¹±K½X¬°admin¡A
½Ðµn¤JWebUI«á¦A¥hÅܧ󬰩ҭnªº±K½X¡C



17.5¤§«e(¦p¤U¹Ï)¡A´N¥u¦³¤T­Ó¿ï¶µ¡A¨S¦³­«³]admin±K½Xªº·s¥\¯à¡C




°Ñ¦Ò¸ê®Æ
How to reset the admin password



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2020-02-12, 10:55 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n³z¹LIPsec VPN±N¤À¤½¥q¬y¶q¥þ³¡¾É¦VÁ`¤½¥q¡A©Ç©Çªº¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

«È¤á¦³»Ý­n¡A­n±N¤À¤½¥q¬y¶q³z¹LIPsec VPN¥þ³¡¾É¦VÁ`¤½¥q¡A
µM«á²Î¤@¦bÁ`¤½¥q°µºô­¶±±ºÞ¡C

IPsec VPN¦ê¦n¤F¡A¦ý¤À¤½¥quser¹ï¥~«o¦³¨Ç©Ç©Çªº¡H
¦³¨Çºô¯¸¥´¤£¶}¡BLine¥u¯à³q¸Ü¡AµLªk¶Ç°e±µ¦¬°T®§¡H
³o¬O«ç»ò¦^¨Æ¡H



­ì¨Ó³o¬O¤@­Ó©MTCP³]©w«Ê¥]©Ò±aªº¸ê®Æ¤W­­MSS (maximum segment size)¦³Ãöªº°ÝÃD¡C
MSSªº¹w³]¤j¤p¬O1460¡A¦b³o¼Ë¥þ¾É¦VÁ`¤½¥qªºÀô¹Ò¤¤¡A
«Ê¥]¦b¤À¤½¥q¸g¹LIPsec¦A¦¸«Ê¸Ë«á¡A´N¦³¥i¯à¶W¹L1460ªº¤¹³\¤j¤p¡A¦Ó¾É­P³¡¤Àºô¯¸»PÀ³¥Î³nÅéµLªk¥¿±`¶}±Ò¡C

­ì¼t«Øij­×§ïªº¤j¤p¬°1300¡A
§Ú°O±o¦b¤§«eªº¬Y¨Çª©¥»XG¡A¥i¥Hª½±µ¦bWANªºinterface³]©w¤¤¥h­×§ïMSSªº¤j¤p¡C



¦ý¦b³o­Ó³Ì·sªº17.5.9 MR-9ª©¶´Å餤¡A
­×§ï³o­Ó³]©w¬OµL®Äªº¡Aª¬ªpµLªk±Æ°£¡I
¥²»Ý¦b¤À¤½¥qªºXG¤¤¡A©óadvanced shell¤¤¥Hiptables«ü¥O¨Ó³]©wMSSªº¤j¤p¬°1300¡C

iptables -t mangle -I POSTROUTING -s 192.168.2.0/24 -d 0.0.0.0/0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1300;
iptables -t mangle -I POSTROUTING -s 0.0.0.0/0 -d 192.168.2.0/24 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1300;


¬d¸ßiptables«ü¥O³]©wµ²ªG¦p¤U¡C
iptables -L -t mangle | grep TCPMSS


¤£¹L³o­Ó«ü¥O¤£¬O¥Ã¤[©Êªº¡A­«¶}¾÷«á´N¥¢®Ä¤F¡C
¬°¤FÅý¥¦¥Ã¤[©Êªºªº¥Í®Ä¡A¥i¥H§â¥¦¼g¦b customization_application_startup.sh ¤¤¡A
¬yµ{¦p¤U¡C
mount -o remount,rw /
vi /scripts/system/clientpref/customization_application_startup.sh
mount -o remount,ro /


§¹¦¨«áªº customization_application_startup.sh À³¸Ó¦³¦p¤Uªº¤º®e¡C
#!/bin/sh
iptables -t mangle -I POSTROUTING -s 192.168.2.0/24 -d 0.0.0.0/0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1300;
iptables -t mangle -I POSTROUTING -s 0.0.0.0/0 -d 192.168.2.0/24 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1300;
exit 0;


¸g¹L¥H¤Wªº½Õ¾ã«á¡A¤À¤½¥q³z¹LÁ`¤½¥q³s¥~ªº©_©Ç°ÝÃDÁ`ºâ¬O¤@Á|±Æ°£¤F¡ã



°Ñ¦Ò¸ê®Æ
How to set the MSS value for remote network(s)
IPSec VPN - Path MTU
TCP maximum segment size ¬O¤°»ò¥H¤Î¬O¦p¦ó¨M©wªº



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2020-01-03, 13:55 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nBridge Mode¤U©Ò¦³ºô­¶³£¥´¤£¶}¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¦P¨Æ¦b¨Ï¥Îbridge mode°µPoC®É¹J¨ì¤F¤@­Ó©_©Çªº°ÝÃD¡A
·í±Ò¥ÎWeb Filter®É¡A©Ò¦³ºô­¶³£¥´¤£¶}¡A
§Y«K¬O¿ï¾ÜAllow All¤]¤@¼Ë¡I

¦ý§ï¬°none®É¡A©Ò¦³ºô­¶«o³£¥i¥H¥¿±`¶}±Ò¤F¡I
³o¬O«ç»ò¦^¨Æ¡H


­ì¨Ó¦³¨S¦³±Ò¥Îweb filter¦b«Ê¥]ªº³B²z¤W¦³«Ü¤jªº¤£¦P¡A
·í¿ï¾Ü¬°none®É¡AXG¤£¶i¦æ¹LÂo¡A«Ê¥]ª½±µ¸g¥Ñ¾ô±µ°t¹ï°e¨ì¥t¥~¤@ºÝ¡C

¦ý¿ï¾Ü¨ä¥¦web filter®É¡AXG·|¥Hproxyªº¬[ºc¨Ó³B²z«Ê¥]¡A
«Ê¥]·|¥ý°±¯d¦bXG¤W¡AµM«á¥ÑXG¤ñ¹ïpattern¡A§P©w³o­Ó«Ê¥]¸Ó¾×¡AÁÙ¬O©ñ¡H

³o®É­YXG¥»¨­µLªk§ó·spattern¡A¨º»ò¦bÀˬd®É´N·|¥X¤F°ÝÃD¡AµLªk§PÂ_¸Ó¾×ÁÙ¬O¸Ó©ñ¡H
µM«á´N³y¦¨¤F±Ò¥Îweb filter«á¡A©Ò¦³ºô­¶µLªk¶}±Òªºª¬ªp¡I

¦P¨Æªº³o­Ó®×¨Ò¡A¬O¦]¬°Àô¹Ò¤¤¦³¨â­Órouting³]³Æ-¬J¦³¨¾¤õÀð»PCore Switch¡A¦ÓXG´N§¨¦b¨â­Ó³]³Æ¤§¶¡¡C
¦b³o­Ó®×¨Ò¤¤¡AXGªºgateway«ü¦V¬J¦³¨¾¤õÀð»PCore Switch³£¥i¥H³s¥~¡A©Ò¥H¤]¨S¦³·Q¨ì·|¬Ogatewayªº°ÝÃD¡C

ª½¨ì«á¨Óµo²{ÁöµMgateway«ü¦V¬J¦³¨¾¤õÀð¥i¥H³q¡A
¦ýXGªºlicense sync»Ppattern update³£·|¥¢±Ñ¡A¤~µo²{¬O³o­Ó°ÝÃD¡C
¦b±Ngateway§ï«ü¦VCore Switch«á¡A°ÝÃDÁ`ºâ¶¶§Q±Æ°£¡C

¦Ü©óÀô¹Ò¤¤ªºgateway¨s³º¬O­n«ü¦V¬J¦³¨¾¤õÀðÁÙ¬OCore Switch¡H
³o­n¬ÝÀô¹Ò¬[ºc¦Ó©w¡C
¤£¹L¤@­Ó²³æªº´ú¸Õ¤èªk´N¬O¥h¸Õlicense sync»Ppattern update¡A
¦¨¥\¤F¡A´N¬O¹ïªº¡F¿ù¤F¡A´N§ï¦¨¥t¤@­Ó§a¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-12-25, 15:35 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nSSLVPNµLªk³sµ²Alias IPªºªA°È¡HÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

«È¤á¤Ï¬M¤@­Ó°ÝÃD¡A³z¹LSSLVPN³s¤½¥q«á¡A
VPN userµLªk¦A³z¹LXG WANºÝªºalias IP³s¦^¤º³¡¥D¾÷ªA°È¡A
§Y«K¦b¬J¦³ªºW2L business application rule¤¤¡A©ó¨Ó·½°Ï°ì¦A¥[¤JVPN¤]¤£¦æ...

³o­Ó°ÝÃD¦b´ú¸Õ«á¡A½T¹ê¦p¦¹¡I
¥Htraceroute¥h°l踪¡Aµo²{¥u¦³¼·¤JªºWAN¤¶­±IP¥i¥H°l踪¨ì¡A
¨ä¥¦alias IP³£§¹¥þ¨S¦³¦^À³¡A
³o¹ê¦b¤Ó©Ç¤F¡I


³Ì«á¶¶¤lµo²{¡A°£¤F¤W­zbusiness application rule¤¤¨Ó·½ºÝ»Ý¥[¤JVPN°Ï°ì¥~¡A
Áٻݭn¦bSSLVPNªº³]©w¤¤¡A±Nalias IP¥[¤J¡§¤¹³\ªººô¸ô¸ê·½¡¨¤¤¡A³o¼Ë¤~¯à¸Ñ¨M¦¹°ÝÃD¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-10-28, 16:21 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nNo LAN to LAN loopback ruleÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Cyberoam¦b«Ø¥ßVirtual HostªA°È®É¡A
·|«Ü¶K¤ßªºÀ°ºÞ²zªÌ¦Û°Ê«Ø¥ßLAN to LANªº loopback ³W«h¡A
Åý¤º³¡user¤]¯à³z¹L¦¹Virtual Hostªº¥~³¡IP¡A³s¨ì¶}³qªA°Èªº¤º³¡¥D¾÷¡C
¶¶¤l»{¬°³oÂI¬OCyberoamÀu©óSophos XGªº¤@­Ó¦a¤è¡C

¦ý©_©Çªº¬O¡A«È¤áªºCyberoam¦b«Ø¥ßVirtual Host®É¡A
«o¤£·|¥D°Ê«Ø¥ßloopback³W«h¡AºÞ²zªÌ¥²¤â°Ê¸É¤W³oºØ³W«h¡C

³o°ÝÃD¥H«e¦b«³·ç®É¹J¨ì¹L¤@¦¸¡A
¦ý¤Ï¥¿³£¥i¥H¤â°Ê¸É«Øloopback³W«h¡A¥B«È¤á¨S¦³¤Ï¬M¡A©Ò¥H´N¤£¤F¤F¤§...


³Ìªñ·s±µÄ²ªº«È¤á¤S¹J¨ì¤F¬Û¦P°ÝÃD¡A
³o¦¸¡A¶¶¤l¶}¤Fcase¡A·Q¨ì©ú½Tª¾¹D¦p¦ó¥h³B²z³o°ÝÃD¡I

¶}case«á¡A¸g­ì¼t¬d¬ÝÅçÃÒ¡A³o°ÝÃD¥i³z¹L²ÕºAÀÉÁÙ­ì¨ì¨ä¥¦³]³Æ¡A¦Ó­«²{¦¹°ÝÃD¡A
¤]´N¬O»¡¡A³o°ÝÃD¤£¬OµwÅé¤Wªº°ÝÃD¡A¦Ó¬O²ÕºA¤Wªº°ÝÃD¡C

¤§©Ò¥H²£¥Í¦¹°ÝÃD¡A¬O¦]¬°Cyberoam databaseùتºNATªí®æ¤¤¡A
¹w³]­È¦³¶Ã½X©Ò­P¡C

¤£¹L«Ü¿ò¾Ñªº¬O¡A¸Ñ¨M¤è¦¡­ì¼t¨Ã¨S¦³³zº|¡A
¥B±j½Õ¥u¯à¦bLANºÝ¥HSSH³s¤J­×¥¿¡C
¦Ó§Ú¨Ã¤£¦b«È¤áºÝ²{³õ¡A©Ò¥H¨S¬Ý¨ì­ì¼t¬O³z¹L­þ¨Ç«ü¥O³s¤J­×¥¿...

¦]¦¹³Ì«á§ÚÁÙ¬O¤£ª¾¹D¸Ó¦p¦ó­×¥¿¦¹°ÝÃD¡A
­Y¤£©¯¹J¨ì¦¹°ÝÃD®É¡AÁÙ¬O¥u¯à¶}case½Ð­ì¼t¨ó§U³B²z¤F¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-10-16, 14:40 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡n³z¹LÁp¨¾ªý¤îL2¼h¯Åªº¯f¬rÂX´²Åã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¨¾¬r³nÅé»P¨¾¤õÀðÁp¨¾¡A¬OSophos¦b¨ÖÁʤFCyberoam«áªº¥D­n²£«~¶D¨D¡C

«Ê¥]¦b¸g¹LSophos XG routing«á¡A¥i¥Hª½±µ³z¹L¨¾¤õÀð³W«h¡A¨Óªý¤î¤¤¬r¹q¸£ªº¾î¦VÂX´²¡C





¦ýL2¼h¯Å¡A¤£¸g¹LSophos XGªºÁa¦VÂX´²¡ASophos¤S¬O¦p¦ó¶i¦æ¨¾¿m©O¡H



«Ü©úÅ㪺¡A¥Ñ©óL2¼h¯Åªº«Ê¥]ª½±µ´N¦b¥æ´«¾¹¤W¥æ´«±¼¤F¡A
©Ò¥HµLªk³z¹L¨¾¤õÀð¨Ó¨¾¿m¡A
­n¨¾¿mL2¼h¯ÅªºÁa¦VÂX´²¡A¥u¯à³z¹L¨¾¬r³nÅé¨Ó¶i¦æ¡C

­n°µ¨ìÁa¦VÂX´²ªº¨¾¿m¡ASophos¦bSophos Central¤W´£¨Ñ¤F¥H¤U¨â¶µ³]©w¡C

  • ©Úµ´¨Ó¦Û¤¤¬r¹q¸£ªº³s½u



    ±Ò¥Î³o¶µ³]©w«á¡A¤¤¬rªº¹q¸£´NµLªk¦A»P±zªº¹q¸£¶i¦æÁpô¡C

    ³o¶µ³]©w¬O¦bSophos Central¤¤ Global Settings ùØ General °Ï¶ô¤Uªº Reject Network Connections ¤¤³]©w¡C



  • ¤¤¬r¹q¸£ªº¦Û§Ú¹jÂ÷



    ±Ò¥Î³o¶µ³]©w«á¡A¤¤¬rªº¹q¸£·|³QSophos Central¦Û°Ê¹jÂ÷¡A
    °£¤F´X­Ó­×¥¿¤¤¬rª¬ºAªº¥²­nºô¯¸¥~¡A¨ä¥¦IP¡BFQDN³£·|³QSophos Central¸T¤î³sµ²¡A¨Ó¹F¨ì«OÅ@®ÄªG¡C

    ³o¶µ³]©w¬O¦bSophos Central¤¤ Endpoint Protection ùØ Police ¤¤ªº Threat Protection ¤¤³]©w¡C
¡@

·f°tSophos Central»PSophos XG¶i¦æÁp¨¾«á¡A
¤£½×¾î¦V©ÎÁa¦Vªº¯f¬rÂX´²¡A³£¦bÁp¨¾¾÷¨î¤U¦h¤F¤@¼h«OÅ@¡ã


¦³«È¤á¦b°Ý¡AL2¨¾¤îÂX´²¾÷¨î¡A¤@©w­n¦³XG¨¾¤õÀð°Ñ»P¦b¨ä¤¤¶Ü¡H
¯à§_²¤¹LXG¡Aª½±µ³z¹LCentral¦VºÝÂIAgent³qª¾¡A¶i¦Ó¹F¨ìÁa¦Vªº¨¾¿m®ÄªG¡H

µª®×¬O¤£¦æ...
­ì¼t KB ¤¤¦³´£¨ì¡A³o­Ó¾÷¨î¬O¥Ñ¨¾¤õÀð¨Óshare¦³°ÝÃDªººÝÂIºô¥d¡A
©Ò¥H»Ý­n¨¾¤õÀð©~¤¤¶Ç»¼¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-09-23, 12:34 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nWifi RoamingÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

Sophos XGªºWifi Roaming¤@ª½¹¡¨ü¥Î¤á½èºÃ¨ä¥\¯à¡A
¦³¤£¤Ö¥Î¤á¦b Community ¤¤¤Ï¬M¡A¤â¾÷¥²»ÝÂ_½u¦A³s½u¤~·|¤Á¨ì¥t¤@­Ó°T¸¹¸û±jªºAP¡C
­Y¯uªº»Ý­nÂ_½u¦A³s½u¤~·|¤Á´«AP¡A¨ºÁÙ¥sWifi Roaming¶Ü¡H


Wifi Roaming 802.11r¬O»Ý­n¦bµL½u³]³Æ»P¥Î¤áºÝ¨âÃä³£¤ä´©ªº±¡ªp¤U¡A¤~¯à¶¶§Q¹B§@ªº¡C

Sophos¤W­n±Ò¥ÎWifi Roaming¡A«Ü²³æ¡A¥u­n±Ò¥Î¡§Fast Transition¡¨§Y¥i¡A
¤£¹L­n¯à¬Ý¨ì¡§Fast Transition¡¨¿ï¶µ¡A¥[±Kªº³¡¤À¥²»Ý¿ï¾ÜWPA2¥H¤Wªº¡§AES¡¨¤~¦æ¡C



¦bXG¤W¦¨¥\±Ò¥Î¡§Fast Transition¡¨«á¡A±µµÛ´N¬O¥Î¤áºÝªº°ÝÃD¤F¡C


¦b¤@¯ëªº»{ª¾¤W¡A§Ú­Ì³£¥H¬°¥Î¤áºÝ³]³Æ¦b¦P®É¤ä´©2.4G»P5Gªº±¡ªp¤U¡A
¶Ç¿é¯à¤O¸û¦nªº5G·|Àu¥ý¨Ï¥Î¡I

µM¦Ó¨Æ¹ê¤W¤£¬O¦p¦¹¡A
¥HWindows¹q¸£¨Ó»¡¡A¬Y¨Çª©¥»ªºÅX°Êµ{¦¡¡A¹w³]¨Ã¤£·|¥H5G¬°Àu¥ý¦Ò¶q¡A
Windows¹q¸£·|¥H2.4G¥hÁpµ²AP¡C

¦Ó¦b2.4G°T¸¹²[»\½d³ò¬O5Gªº¤@­¿ªº±¡ªp¤U¡A
©Î³\user¥H¬°¦b¦æ¶i®É¡A°T¸¹¤w¸g«Ü®z¤F¡AÀ³¸Ó¤Á´«¨ì¥t¤@ÁûAP¥h¡C



¦ý¹ê»Ú¤W¥H2.4Gªº²[»\½d³ò¨Ó¬Ý¡AuserÁÙ¦b¨¬°÷±j«×ªº°T¸¹½d³ò¤º¡A¨Ã¤£·|¤Á´«¨ì¥t¤@ÁûAP¥h¡C



UserÁÙ¬O¥²»Ý­nÃö±¼µL½u¡AµM«á¦A­«·s¶}±ÒµL½u¡A¤~¯à³s¨ì°T¸¹¸û±jªº¥t¤@­ÓAP¡C
³y¦¨user»{¬°Wifi Roaming¥u¬O¾»ÀY¡A¨S¦³§@¥Î¡I


¦]¦¹¶¶¤l«Øij¡A¦bµL½uÀô¹Ò¤¤§G«Ø¨¬°÷¦hªºAPªº±¡ªp¤U¡A
°È¥²½T»{Windows¹q¸£ªºWifi³]©w¬O¥H5G¬°Àu¥ý¿ï¾Ü¡C(iOS 11¥H«á¡A¹w³]¤w¸g¬O¥H5G¬°Àu¥ý¤F¡A¦ýAndroidªº³¡¤À¶¶¤l´N¬d¤£¨ì¤F...)



©Î¬O°®¯Ü¿W¥ß5GªºµL½uºô¸ô¡A¤£­n±N2.4G»P5G²V¥Î¡A³y¦¨¨Ï¥ÎªÌ»~¥Î¨ì2.4Gªº§xÂZ¡C
¦pªGı±o¦b¤Á´«¤WÁÙ¬O¤£°÷¥D°Ê¡A¬Æ¦Ü¥i¥H¦Ò¼{½Õ°ªº©¹Cªº¿n·¥«×¡C




¶¶¤l¦b±j¨î¨Ï¥Î5Gªº±¡ªp¤U¡A¹ê»Ú¶i¦æSophos XGªºWifi Roaming´ú¸Õ¡A
´ú¸Õµ²ªGµo²{¡A¥Hping¨ÓÆ[¹îªº¸Ü¡A¦bAP¤Á´«®É¡Aping³Ì¦h¥u·|±¼¤@­Ó¡A¥BLineªº³q¸Ü¨Ã¤£·|Â_¡C

Sophos XGªºWifi Roaming¡A¨ä¹ê¤]¨S¦³¨º»ò¤£³ô°Ú¡ã



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-08-16, 11:14 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2370

shunze Â÷½u
¡m¤À¨É¡nSIPÀô¹Ò°Ñ¼Æ½Õ¾ãÅã¥Ü¥DÃD ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¤µ¤Ñ¦b°Q½×°Ï¤¤¬Ý¨ì¤@½g¦³ÃöSIPªºÀô¹Ò°Ñ¼Æ½Õ¾ã¡A
­ì¨Ó°£¤F system system_modules sip unload ¥~¡AÁÙ¦³¥H¤U´X­Ó°Ñ¼Æ¥i¥H½Õ®Õ¡C

set advanced-firewall udp-timeout-stream 150

¹w³]®É¶¡¬O60¬í¡A©ñ¤j¨ì150¬í¡A¦³§U©ó´î¤ÖVoIPÀô¹Ò¤UUDP timeoutªº¾÷·|¡C

set ips sip_preproc disable

³z¹L¥H¤W«ü¥O¡A¥i¥H¦bIPSªº«Ê¥]¤¤¡A°±¥Î¹ï©óSIPªº¹w¥ý¸ü¤J¼Ò²Õ¡A´î¤Ö¤@¨Ç¤zÂZ¡A¹w³]¬Oenable¡C

set vpn conn-remove-tunnel-up disable

¦bSite to Site VPNÀô¹Ò¤¤¡A¤£·|¦]VPN tunnel-up¡A¦Óflush SIP³s½u¡A¹w³]¬Oenable¡C
¤ñ¸û¯S§Oªº¬O¡A³o­Ó«ü¥OµLªk¥HtabÁä¦Û°Ê±a¥X/Åã¥Ü«áÄò°Ñ¼Æ¡I


°Ñ¦Ò¸ê®Æ
VoIP calls may drop or encounter poor quality



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2019-07-22, 12:13 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
¸õ¨ì:
Åã¥Ü±q 41 ¨ì 50 ¦b©Ò¦³ªº 2070 ­Óµ²ªG¤¤.  «123456789...»

Powered by: Burning Board 1.1.1 2001 WoltLab GbR