Verificar o consumo de CPU
FORTIGATE# get system performance top
Run Time: 2 days, 4 hours and 44 minutes
2U, 2S, 96I; 1843T, 1415F, 153KF
authd 74 S 8.6 0.9
newcli 3364 R 2.8 0.7
ipsengine 3182 S < 0.0 4.1
pyfcgid 3319 S 0.0 1.5
pyfcgid 3318 S 0.0 1.5
proxyworker 56 S 0.0 1.4
httpsd 114 S 0.0 1.4
httpsd 117 S 0.0 1.2
pyfcgid 3316 S 0.0 1.2
pyfcgid 3317 S 0.0 1.1
cmdbsvr 36 S 0.0 1.1
miglogd 42 S 0.0 1.1
httpsd 44 S 0.0 0.8
httpsd 113 S 0.0 0.8
iked 78 S 0.0 0.8
newcli 3350 S 0.0 0.7
fgfmd 100 S 0.0 0.7
src-vis 84 S 0.0 0.7
fcnacd 75 S 0.0 0.7
cw_acd 101 S 0.0 0.6
Verificação de Tráfego
FORTIGATE# get system performance firewall statistics
getting traffic statistics...
Browsing: 10014170 packets, 7688174225 bytes
DNS: 228686 packets, 22137858 bytes
E-Mail: 2657460 packets, 1255411117 bytes
FTP: 0 packets, 0 bytes
Gaming: 0 packets, 0 bytes
IM: 0 packets, 0 bytes
Newsgroups: 0 packets, 0 bytes
P2P: 0 packets, 0 bytes
Streaming: 0 packets, 0 bytes
TFTP: 0 packets, 0 bytes
VoIP: 0 packets, 0 bytes
Generic TCP: 20329044 packets, 13913188326 bytes
Generic UDP: 444630 packets, 127355536 bytes
Generic ICMP: 379816 packets, 25450000 bytes
Generic IP: 161589 packets, 5231988 bytes
Verificação de Status
FORTIGATE# get system status
Version: XX
Virus-DB: 23.00580
Extended DB: 22.00839
IPS-DB: 5.00593
IPS-ETDB: 0.00000
Serial-Number: FORTIGATE
Botnet DB: x.xxxx
BIOS version: 04000023
System Part-Number: xxxx-xx
Log hard disk: Available
Internal Switch mode: switch
Hostname: ADONAI
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: XX
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: disable
Current HA mode: standalone
Branch point: 271
Release Version Information: GA
System time: XX
Verificar a configuração das interfaces físicas
FORTIGATE # get system interface physical
== [onboard]
==[dmz]
mode: dhcp
ip: 192.168.25.103 255.255.255.0
ipv6: ::/0
status: up
speed: 1000Mbps (Duplex: full)
==[internal]
mode: static
ip: 10.0.0.254 255.0.0.0
ipv6: ::/0
status: up
speed: 1000Mbps (Duplex: full)
==[wan1]
mode: pppoe
ip: 179.15.44.83 255.255.255.255
ipv6: ::/0
status: up
speed: 1000Mbps (Duplex: full)
==[wan2]
mode: dhcp
ip: 211.1.11.7 255.255.254.0
ipv6: ::/0
status: up
speed: 1000Mbps (Duplex: full)
==[modem]
mode: pppoe
ip: 0.0.0.0 0.0.0.0
ipv6: ::/0
status: down
speed: n/a
Checar a tabela ARP
FORTIGATE# get system arp
Address Age(min) Hardware Addr Interface
200.000.00.00 92 00:01:5c:71:84:46 wan2
10.0.0.11 0 00:25:11:b4:92:54 internal
10.0.0.14 0 c8:9c:dc:c7:a9:4d internal
10.0.0.20 0 18:a9:9b:fb:db:8d internal
10.0.0.21 0 e0:69:95:20:d4:d2 internal
10.0.0.29 0 10:78:d2:ba:dd:8e internal
10.0.0.32 0 00:24:8c:a2:b6:59 internal
10.0.0.38 9 00:01:01:01:33:34 internal
10.0.0.39 0 00:25:22:4f:c9:31 internal
10.0.0.41 0 00:14:2a:7e:99:a4 internal
10.0.0.51 0 00:1e:c9:1b:0f:12 internal
10.0.0.52 0 d8:9d:67:e2:52:db internal
10.0.0.58 11 00:15:5d:28:89:02 internal
10.0.0.79 0 bc:5f:f4:cb:ed:50 internal
10.0.0.96 0 c8:9c:dc:0d:8f:83 internal
10.0.0.104 13 00:1f:e2:33:fb:5f internal
10.0.0.117 0 00:25:22:3a:12:bd internal
10.0.0.118 0 44:87:fc:b1:d3:d1 internal
10.0.0.119 0 00:26:18:96:5c:f6 internal
10.0.0.121 0 c8:9c:dc:ce:bf:59 internal
10.0.0.122 0 c8:9c:dc:ce:bf:1a internal
10.0.0.135 0 e0:69:95:20:d9:6c internal
10.0.0.155 0 a4:ba:db:04:87:50 internal
10.0.0.166 1 00:1f:e2:32:a4:17 internal
10.0.0.176 1 00:15:5d:28:89:01 internal
10.0.0.192 0 bc:ee:7b:21:ef:5b internal
10.0.0.199 0 78:45:c4:ff:bf:ac internal
10.0.0.250 2 90:02:a9:b5:3f:33 internal
192.168.25.1 0 68:15:90:fc:66:16 dmz
Checar a tabela de roteamento
FORTIGATE# get router info routing-table all
Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP
O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default
S* 0.0.0.0/0 [1/0] via 187.100.231.2, ppp1
C 10.0.0.0/8 is directly connected, internal
C 169.254.1.1/32 is directly connected, PPTPVPN_0
is directly connected, PPTPVPN_0
C XXX.XXX.XXX.XXX/32 is directly connected, ppp1
C XXX.XXX.XXX.XXX/32 is directly connected, ppp1
S 192.168.2.1/32 [1/0] is directly connected, PPTPVPN_0
C 192.168.25.0/24 is directly connected, dmz
C XXX.XXX.XXX.XXX/23 is directly connected, wan2
x
Preparando o servidor
yum update -y
yum install -y httpd httpd-devel mod_perl mod_php mod_ssl php-gd php-mysql php-mbstring php perl perl-XML-Simple perl-Compress-Zlib perl-DBI perl-DBD-MySQL perl-Net-IP perl-SOAP-Lite perl-Apache-DBI perl-Apache2-SOAP perl-XML-Entities
Inicie o WebServer
systemctl start httpd.service
systemctl enable httpd.service
Adicione o repositorio do MariaDB
cd /etc/yum.repos.d/
vim MariaDB.repo
Adicione o conteúdo abaixo no arquivo e salve o arquivo Mariadb.repo
# MariaDB 10.0 CentOS repository list - created 2014-11-30 22:51 UTC
# http://mariadb.org/mariadb/repositories/
[mariadb]
name = MariaDB
baseurl = http://yum.mariadb.org/10.0/centos7-amd64
gpgkey=https://yum.mariadb.org/RPM-GPG-KEY-MariaDB
gpgcheck=1
Agora faça a instalação do MariaDB
sudo yum install MariaDB-server MariaDB-client
Fonte: Maria DB
Inicie o Banco de Dados
/etc/init.d/mysql start
Execute o instalação segura do Mysql e atribui a senha para root
/usr/bin/mysql_secure_installation
NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MariaDB
SERVERS IN PRODUCTION USE! PLEASE READ EACH STEP CAREFULLY!
In order to log into MariaDB to secure it, we'll need the current
password for the root user. If you've just installed MariaDB, and
you haven't set the root password yet, the password will be blank,
so you should just press enter here.
Enter current password for root (enter for none): <--ENTER
OK, successfully used password, moving on...
Setting the root password ensures that nobody can log into the MariaDB
root user without the proper authorisation.
Set root password? [Y/n]
New password: <--yourmariadbpassword
Re-enter new password: <--yourmariadbpassword
Password updated successfully!
Reloading privilege tables..
... Success!
By default, a MariaDB installation has an anonymous user, allowing anyone
to log into MariaDB without having to have a user account created for
them. This is intended only for testing, and to make the installation
go a bit smoother. You should remove them before moving into a
production environment.
Remove anonymous users? [Y/n] <--ENTER
... Success!
Normally, root should only be allowed to connect from 'localhost'. This
ensures that someone cannot guess at the root password from the network.
Disallow root login remotely? [Y/n] <--ENTER
... Success!
By default, MariaDB comes with a database named 'test' that anyone can
access. This is also intended only for testing, and should be removed
before moving into a production environment.
Remove test database and access to it? [Y/n] <--ENTER
- Dropping test database...
... Success!
- Removing privileges on test database...
... Success!
Reloading the privilege tables will ensure that all changes made so far
will take effect immediately.
Reload privilege tables now? [Y/n] <--ENTER
... Success!
Cleaning up...
All done! If you've completed all of the above steps, your MariaDB
installation should now be secure.
Thanks for using MariaDB!
Opcional: Caso deseje criar a base de dados agora, segue abaixo o procedimento, porém é possivel criar na durante a instalação do OCS.
Fazendo essa configuração agora quando acessar o OCS será necessário somente dar input das informações de conexão com o banco de dados.
# mysql -u root -p
CREATE DATABASE ocs;
GRANT ALL PRIVILEGES ON ocs.* to ocs@localhost IDENTIFIED BY 'suasenha';
FLUSH PRIVILEGES;
QUIT
Habilitando o Remi no CentOs 7
wget http://rpms.famillecollet.com/enterprise/remi-release-7.rpm
sudo rpm -Uvh remi-release-7*.rpm
sudo yum --enablerepo=remi install php-tcpdf
Acesse /etc/yum.repos.d/remi.repo em [remi] modifique enable=0 para enable-1 para ativar o repositorio.
Abaixo como [remi] deve ficar.
[remi]
name=Les RPM de remi pour Enterprise Linux 7 - $basearch
#baseurl=http://rpms.famillecollet.com/enterprise/7/remi/$basearch/
mirrorlist=http://rpms.famillecollet.com/enterprise/7/remi/mirror
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-remi
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-remi
failovermethod=priority
Verifique se o repositorio está funcionando.
yum repolist
Caso deseje desabilitar futuramento o repositorio abaixo comando utilize o comando abaixo.
yum repolist disabled
Instalação do OCS NG através do Yum utilizando o Remi
yum --enablerepo=remi install ocsinventory
Libera acesso http e https
firewall-cmd --permanent --zone=public --add-service=http
firewall-cmd --permanent --zone=public --add-service=https
firewall-cmd --reload
Altere no php.ini o tamanho maximo de post e upload
vim /etc/php.ini
post_max_size = 200M
upload_max_filesize = 200M
Concluindo a instalação remova o arquivo install.php do diretorio /usr/share/ocsinventory-reports/ocsreports
cd /usr/share/ocsinventory-reports/ocsreports
rm install.php
Acesse a URL para configurar o OCS http://ipdoservidor/ocsreports