-

  • (11)

 - e-mail

 

 -

 -

 -

 -

 LiveInternet.ru:
: 05.09.2005
:
:
: 1055

:


, 11 2010 . 13:34 +
. , , , . . , , , , " ". - . () . () . - . -, . . - ר. -, ,, . " "- .
, .

.
- netams . , . , .
- , .

3.4. - fw-policy, netams-3.3.5, . - nawt.2.6 3.4.1 cgi "" .
mysql apache.
! 3.4.1rc2 . u fw-policy

, . ipfw

divert natd from any to any via interface
allow all from any to any
deny all from any to any.

libcap - . - netams netams.org
, netams-3.4.1rc2 :

http://www.netams.com/files/netams-3.4.1rc2.tar.gz


3.4.1rc1

#cd /usr/ports/net-mgmt/netams
#make install clean







libpcpap libpcap.

#cd /usr/ports/net/libpcap
#make install clean



!
/etc/rc.conf
daemon_name_enable="YES"

netams_enable="YES"

.

language ru
user oid 030262 name admin real-name "Admin" crypted $1$$HpXmjtul/3i1.bf.B27bU. email root@localhost permit all

. crypted

#services configuration

service server 0
login local
listen 20000
max-conn 6

service processor
lookup-delay 5
flow-lifetime 2
policy oid 08D7E7 name ip target proto ip
restrict all drop local pass


. . service server , , ,, .
( 20000)

service processor. , :

lookup-delay XXXX

, processor NetUnit, . , "" , . .
XXX - , 30.

86 delay 5 .


flow-lifetime XXXX

RAW . , . , , .
XXX - , 300.
lookup-delay XXXX

, processor NetUnit, . , "" , . .
XXX - , 30.
, 2 . .


policy oid 08D7E7 name ip target proto ip

- , . OID , , .. .

! oid , netams , .

ip ip .


restrict all {drop|pass} local {drop|pass}

, fw-policy
all - ( ip- src/dst)
local - , ,
drop -
pass -
restrict all drop local pass , , src/dst IP- //, . , / "" . restrict local drop fw-policy. acct-policy fw-policy, no-local-pass, .. restrict all restrict local.



. , .

, . - mac ( , , . )


unit group oid 08EA6D name LAN
unit host oid 0AD6A9 name server ip 192.168.9.1 parent LAN acct-policy ip
unit user oid 04D535 name HOST1 ip 192.168.9.2 parent LAN acct-policy ip
unit user oid 0E8592 name HOST2 ip 192.168.9.5 parent LAN acct-policy ip
unit user oid 0C14C4 name HOST3 ip 192.168.9.7 parent LAN acct-policy ip
unit user oid 06941D name HOST4 ip 192.168.9.8 parent LAN acct-policy ip
unit user oid 0E9C62 name HOST5 ip 192.168.9.10 parent LAN acct-policy ip
unit user oid 0B915E name HOST6 ip 192.168.9.11 parent LAN acct-policy ip
unit user oid 0023E6 name HOST7 ip 192.168.9.12 parent LAN acct-policy ip
unit user oid 073899 name HOST8 ip 192.168.9.20 parent LAN acct-policy ip
unit user oid 083230 name HOST9 ip 192.168.9.32 parent LAN acct-policy ip

- "user" , "" "". -OID' , OID, .
. , LAN.
acct-policy ip - . . acct-policy ip,
default acct-policy ip( , ).


service storage 1
type mysql
user netams
password ***
dbname netams
accept all

. , , . accept all . .


service data-source 1
type libpcap
source fxp0

.FXP0 - . libpcap . libcpap - . , , .


service data-source 1
type ip-traffic
source divert 199
rule 9000 "ip from 192.168.0.0/24 to any out xmit fxp0"
rule 11000 "ip from any to 192.168.0.0/24 in via fxp0"


divert natd from any to any via interface 9000 11000
199 , . FXP0 .



- monitor.
, . , 3.4.x 3.3.5
3.4.

enable
configure terminal
service monitor
monitor unit oid/name



service html
path /usr/local/www/stat
run 10sec
url http://192.168.9.1/stat
client-pages all
account-pages none

service scheduler
oid 08FFFF time 10sec action "html"



. . - quota. _ _ .
policy oid 013ECF name msgs target proto tcp port 25 110 5190

Service quota 0
storage 1
policy ip
block-policy msgs^M
notify soft owner
notify hard owner
notify return owner
, , Service Storage

. OID', .

Admintool, . :

telnet localhost 21000 ( )
enable
configure terminal
service quota
set OID/NAME active


set OID/NAME block-policy [ fw-policy, ] day [ ] in/out/both week [ ] in/out/both month [ ] in/out/both




- HOST/OID, , - ip, fw-policy, msgs. ip - 300 . K M G.
: , fw-policy msgs, .. 110 25 5190.


, . show config ( ). " ", .. . -

policy oid #### name NAME

, - .
, /usr/local/www/stat ( 3.4.1 /usr/local/www/netams)

( ) , layer7. , -DLAYER7-FILTER. - , .
Data Source

layer7-detect urls



policy hidden name urls target layer7-detect

hidden , html
acct-policy urls
, default acct-policy , default acct-policy urls.

! , url . proxy.


, , :

http://www.controlstyle.ru/products/web/text/namonitor/
nawt 2.6.0 ( 3.4.) 2.5.0 3.3.5
netams.com php .
nawt-2.5.0 ( 3.3.5) http://netamsadmin.sourceforge.net/nawt/nawt-2.0.5b.tar.gz
nawt-2.6.0 ( 3.4.0) http://netamsadmin.sourceforge.net/nawt/nawt-2.0.6.tar.gz
http://www.it2k.ru/projects/netams-front/


libpcap, netflow divert. -, .

..., netams transparent proxy. . :

01300 divert 199 ip from not 192.168.0.0/24 to any via em0
09000 divert 199 ip from 192.168.0.0/24 to any out xmit fxp0
09100 divert 199 ip from 192.168.254.0/24 to any out xmit fxp0
09500 fwd 127.0.0.1,3128 tcp from 192.168.0.0/24 to not 192.168.0.254 dst-port 80,3128,8080,8101,8108 via fxp0
09600 fwd 127.0.0.1,3128 tcp from 192.168.0.0/21 to not 192.168.0.254 dst-port 80,3128,8080,8101,8108 via fxp0
10000 divert 8668 ip from any to any via fxp0
11000 divert 199 ip from any to 192.168.0.0/24 in via fxp0



upd: netams-front
, . . Tmetr- 2 .
, .
:  

: [1] []
 

:
: 

: ( )

:

  URL