sábado, 10 de janeiro de 2015

FORTIGATE - COMANDOS ÚTEIS

Verificar o consumo de CPU
FORTIGATE# get system performance top
Run Time:  2 days, 4 hours and 44 minutes
2U, 2S, 96I; 1843T, 1415F, 153KF
           authd       74      S       8.6     0.9
          newcli     3364      R       2.8     0.7
       ipsengine     3182      S <     0.0     4.1
         pyfcgid     3319      S       0.0     1.5
         pyfcgid     3318      S       0.0     1.5
     proxyworker       56      S       0.0     1.4
          httpsd      114      S       0.0     1.4
          httpsd      117      S       0.0     1.2
         pyfcgid     3316      S       0.0     1.2
         pyfcgid     3317      S       0.0     1.1
         cmdbsvr       36      S       0.0     1.1
         miglogd       42      S       0.0     1.1
          httpsd       44      S       0.0     0.8
          httpsd      113      S       0.0     0.8
            iked       78      S       0.0     0.8
          newcli     3350      S       0.0     0.7
           fgfmd      100      S       0.0     0.7
         src-vis       84      S       0.0     0.7
          fcnacd       75      S       0.0     0.7
          cw_acd      101      S       0.0     0.6


Verificação de Tráfego
FORTIGATE# get system performance firewall statistics
getting traffic statistics...
Browsing: 10014170 packets, 7688174225 bytes
DNS: 228686 packets, 22137858 bytes
E-Mail: 2657460 packets, 1255411117 bytes
FTP: 0 packets, 0 bytes
Gaming: 0 packets, 0 bytes
IM: 0 packets, 0 bytes
Newsgroups: 0 packets, 0 bytes
P2P: 0 packets, 0 bytes
Streaming: 0 packets, 0 bytes
TFTP: 0 packets, 0 bytes
VoIP: 0 packets, 0 bytes
Generic TCP: 20329044 packets, 13913188326 bytes
Generic UDP: 444630 packets, 127355536 bytes
Generic ICMP: 379816 packets, 25450000 bytes
Generic IP: 161589 packets, 5231988 bytes


Verificação de Status 
FORTIGATE# get system status
Version: XX
Virus-DB: 23.00580
Extended DB: 22.00839
IPS-DB: 5.00593
IPS-ETDB: 0.00000
Serial-Number: FORTIGATE
Botnet DB: x.xxxx
BIOS version: 04000023
System Part-Number: xxxx-xx
Log hard disk: Available
Internal Switch mode: switch
Hostname: ADONAI
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: XX
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: disable
Current HA mode: standalone
Branch point: 271
Release Version Information: GA
System time: XX


Verificar a configuração das interfaces físicas 
FORTIGATE # get system interface physical
== [onboard]
        ==[dmz]
                mode: dhcp
                ip: 192.168.25.103 255.255.255.0
                ipv6: ::/0
                status: up
                speed: 1000Mbps (Duplex: full)
        ==[internal]
                mode: static
                ip: 10.0.0.254 255.0.0.0
                ipv6: ::/0
                status: up
                speed: 1000Mbps (Duplex: full)
        ==[wan1]
                mode: pppoe
                ip: 179.15.44.83 255.255.255.255
                ipv6: ::/0
                status: up
                speed: 1000Mbps (Duplex: full)
        ==[wan2]
                mode: dhcp
                ip: 211.1.11.7 255.255.254.0
                ipv6: ::/0
                status: up
                speed: 1000Mbps (Duplex: full)
        ==[modem]
                mode: pppoe
                ip: 0.0.0.0 0.0.0.0
                ipv6: ::/0
                status: down
                speed: n/a
Checar a tabela ARP
FORTIGATE# get system arp
Address           Age(min)   Hardware Addr      Interface
200.000.00.00     92         00:01:5c:71:84:46 wan2
10.0.0.11         0          00:25:11:b4:92:54 internal
10.0.0.14         0          c8:9c:dc:c7:a9:4d internal
10.0.0.20         0          18:a9:9b:fb:db:8d internal
10.0.0.21         0          e0:69:95:20:d4:d2 internal
10.0.0.29         0          10:78:d2:ba:dd:8e internal
10.0.0.32         0          00:24:8c:a2:b6:59 internal
10.0.0.38         9          00:01:01:01:33:34 internal
10.0.0.39         0          00:25:22:4f:c9:31 internal
10.0.0.41         0          00:14:2a:7e:99:a4 internal
10.0.0.51         0          00:1e:c9:1b:0f:12 internal
10.0.0.52         0          d8:9d:67:e2:52:db internal
10.0.0.58         11         00:15:5d:28:89:02 internal
10.0.0.79         0          bc:5f:f4:cb:ed:50 internal
10.0.0.96         0          c8:9c:dc:0d:8f:83 internal
10.0.0.104        13         00:1f:e2:33:fb:5f internal
10.0.0.117        0          00:25:22:3a:12:bd internal
10.0.0.118        0          44:87:fc:b1:d3:d1 internal
10.0.0.119        0          00:26:18:96:5c:f6 internal
10.0.0.121        0          c8:9c:dc:ce:bf:59 internal
10.0.0.122        0          c8:9c:dc:ce:bf:1a internal
10.0.0.135        0          e0:69:95:20:d9:6c internal
10.0.0.155        0          a4:ba:db:04:87:50 internal
10.0.0.166        1          00:1f:e2:32:a4:17 internal
10.0.0.176        1          00:15:5d:28:89:01 internal
10.0.0.192        0          bc:ee:7b:21:ef:5b internal
10.0.0.199        0          78:45:c4:ff:bf:ac internal
10.0.0.250        2          90:02:a9:b5:3f:33 internal
192.168.25.1      0          68:15:90:fc:66:16 dmz



Checar a tabela de roteamento
FORTIGATE# get router info routing-table all
Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP
       O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
       * - candidate default
S*      0.0.0.0/0 [1/0] via 187.100.231.2, ppp1
C       10.0.0.0/8 is directly connected, internal
C       169.254.1.1/32 is directly connected, PPTPVPN_0
                       is directly connected, PPTPVPN_0
C       XXX.XXX.XXX.XXX/32 is directly connected, ppp1
C        XXX.XXX.XXX.XXX/32 is directly connected, ppp1
S       192.168.2.1/32 [1/0] is directly connected, PPTPVPN_0
C       192.168.25.0/24 is directly connected, dmz
C       XXX.XXX.XXX.XXX/23 is directly connected, wan2

x

domingo, 30 de novembro de 2014

OCS Inventory no CentOS 7

Preparando o servidor 

yum update -y
yum install -y httpd httpd-devel mod_perl mod_php mod_ssl php-gd php-mysql php-mbstring php perl perl-XML-Simple perl-Compress-Zlib perl-DBI perl-DBD-MySQL  perl-Net-IP perl-SOAP-Lite perl-Apache-DBI perl-Apache2-SOAP perl-XML-Entities

Inicie o WebServer

systemctl start httpd.service
systemctl enable httpd.service

Adicione o repositorio do MariaDB

cd /etc/yum.repos.d/
vim MariaDB.repo

Adicione o conteúdo abaixo no arquivo e salve o arquivo Mariadb.repo

# MariaDB 10.0 CentOS repository list - created 2014-11-30 22:51 UTC
# http://mariadb.org/mariadb/repositories/
[mariadb]
name = MariaDB
baseurl = http://yum.mariadb.org/10.0/centos7-amd64
gpgkey=https://yum.mariadb.org/RPM-GPG-KEY-MariaDB
gpgcheck=1

 Agora faça a instalação do MariaDB

sudo yum install MariaDB-server MariaDB-client

Fonte: Maria DB

Inicie o Banco de Dados

/etc/init.d/mysql start

 Execute o instalação segura do Mysql e atribui a senha para root

 /usr/bin/mysql_secure_installation


NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MariaDB
      SERVERS IN PRODUCTION USE!  PLEASE READ EACH STEP CAREFULLY!

In order to log into MariaDB to secure it, we'll need the current
password for the root user.  If you've just installed MariaDB, and
you haven't set the root password yet, the password will be blank,
so you should just press enter here.

Enter current password for root (enter for none): <--ENTER
OK, successfully used password, moving on...

Setting the root password ensures that nobody can log into the MariaDB
root user without the proper authorisation.

Set root password? [Y/n] 
New password: <--yourmariadbpassword
Re-enter new password: <--yourmariadbpassword
Password updated successfully!
Reloading privilege tables..
 ... Success!


By default, a MariaDB installation has an anonymous user, allowing anyone
to log into MariaDB without having to have a user account created for
them.  This is intended only for testing, and to make the installation
go a bit smoother.  You should remove them before moving into a
production environment.

Remove anonymous users? [Y/n] <--ENTER
 ... Success!

Normally, root should only be allowed to connect from 'localhost'.  This
ensures that someone cannot guess at the root password from the network.

Disallow root login remotely? [Y/n] <--ENTER
 ... Success!

By default, MariaDB comes with a database named 'test' that anyone can
access.  This is also intended only for testing, and should be removed
before moving into a production environment.

Remove test database and access to it? [Y/n] <--ENTER
 - Dropping test database...
 ... Success!
 - Removing privileges on test database...
 ... Success!

Reloading the privilege tables will ensure that all changes made so far
will take effect immediately.

Reload privilege tables now? [Y/n] <--ENTER
 ... Success!

Cleaning up...

All done!  If you've completed all of the above steps, your MariaDB
installation should now be secure.

Thanks for using MariaDB!

Opcional: Caso deseje criar a base de dados agora, segue abaixo o procedimento, porém é possivel criar na durante a instalação do OCS.
Fazendo essa configuração agora quando acessar o OCS será necessário somente dar input das informações de conexão com o banco de dados.

# mysql -u root -p
    
  CREATE DATABASE ocs;
  GRANT ALL PRIVILEGES ON ocs.* to ocs@localhost IDENTIFIED BY 'suasenha';
  FLUSH PRIVILEGES;
  QUIT

Habilitando o Remi no CentOs 7

wget http://rpms.famillecollet.com/enterprise/remi-release-7.rpm 
sudo rpm -Uvh remi-release-7*.rpm
sudo yum --enablerepo=remi install php-tcpdf

Acesse /etc/yum.repos.d/remi.repo em [remi] modifique enable=0 para enable-1 para ativar o repositorio.
Abaixo como [remi] deve ficar.

[remi]
name=Les RPM de remi pour Enterprise Linux 7 - $basearch
#baseurl=http://rpms.famillecollet.com/enterprise/7/remi/$basearch/
mirrorlist=http://rpms.famillecollet.com/enterprise/7/remi/mirror
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-remi
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-remi
failovermethod=priority

Verifique se o repositorio está funcionando.

yum repolist

Caso deseje desabilitar futuramento o repositorio abaixo comando utilize o comando abaixo.

yum repolist disabled

Instalação do OCS NG através do Yum utilizando o Remi

yum --enablerepo=remi install ocsinventory

Libera acesso http e https 

firewall-cmd --permanent --zone=public --add-service=http 
firewall-cmd --permanent --zone=public --add-service=https
firewall-cmd --reload

Altere no php.ini o tamanho maximo de post e upload

vim /etc/php.ini
post_max_size = 200M
upload_max_filesize = 200M

Concluindo a instalação remova o arquivo install.php do diretorio /usr/share/ocsinventory-reports/ocsreports

cd /usr/share/ocsinventory-reports/ocsreports
rm install.php


Acesse a URL para configurar o OCS http://ipdoservidor/ocsreports