-

  • (11)

 - e-mail

 

 -

 -

 -

 LiveInternet.ru:
: 05.09.2005
:
:
: 1055

:

(0)

, 11 2010 . 13:34 +
. , , , . . , , , , " ". - . () . () . - . -, . . - ר. -, ,, . " "- .
, .

.
- netams . , . , .
- , .

3.4. - fw-policy, netams-3.3.5, . - nawt.2.6 3.4.1 cgi "" .
mysql apache.
! 3.4.1rc2 . u fw-policy

, . ipfw

divert natd from any to any via interface
allow all from any to any
deny all from any to any.

libcap - . - netams netams.org
, netams-3.4.1rc2 :

http://www.netams.com/files/netams-3.4.1rc2.tar.gz


3.4.1rc1

#cd /usr/ports/net-mgmt/netams
#make install clean







libpcpap libpcap.

#cd /usr/ports/net/libpcap
#make install clean



!
/etc/rc.conf
daemon_name_enable="YES"

netams_enable="YES"

.

language ru
user oid 030262 name admin real-name "Admin" crypted $1$$HpXmjtul/3i1.bf.B27bU. email root@localhost permit all

. crypted

#services configuration

service server 0
login local
listen 20000
max-conn 6

service processor
lookup-delay 5
flow-lifetime 2
policy oid 08D7E7 name ip target proto ip
restrict all drop local pass


. . service server , , ,, .
( 20000)

service processor. , :

lookup-delay XXXX

, processor NetUnit, . , "" , . .
XXX - , 30.

86 delay 5 .


flow-lifetime XXXX

RAW . , . , , .
XXX - , 300.
lookup-delay XXXX

, processor NetUnit, . , "" , . .
XXX - , 30.
, 2 . .


policy oid 08D7E7 name ip target proto ip

- , . OID , , .. .

! oid , netams , .

ip ip .


restrict all {drop|pass} local {drop|pass}

, fw-policy
all - ( ip- src/dst)
local - , ,
drop -
pass -
restrict all drop local pass , , src/dst IP- //, . , / "" . restrict local drop fw-policy. acct-policy fw-policy, no-local-pass, .. restrict all restrict local.



. , .

, . - mac ( , , . )


unit group oid 08EA6D name LAN
unit host oid 0AD6A9 name server ip 192.168.9.1 parent LAN acct-policy ip
unit user oid 04D535 name HOST1 ip 192.168.9.2 parent LAN acct-policy ip
unit user oid 0E8592 name HOST2 ip 192.168.9.5 parent LAN acct-policy ip
unit user oid 0C14C4 name HOST3 ip 192.168.9.7 parent LAN acct-policy ip
unit user oid 06941D name HOST4 ip 192.168.9.8 parent LAN acct-policy ip
unit user oid 0E9C62 name HOST5 ip 192.168.9.10 parent LAN acct-policy ip
unit user oid 0B915E name HOST6 ip 192.168.9.11 parent LAN acct-policy ip
unit user oid 0023E6 name HOST7 ip 192.168.9.12 parent LAN acct-policy ip
unit user oid 073899 name HOST8 ip 192.168.9.20 parent LAN acct-policy ip
unit user oid 083230 name HOST9 ip 192.168.9.32 parent LAN acct-policy ip

- "user" , "" "". -OID' , OID, .
. , LAN.
acct-policy ip - . . acct-policy ip,
default acct-policy ip( , ).


service storage 1
type mysql
user netams
password ***
dbname netams
accept all

. , , . accept all . .


service data-source 1
type libpcap
source fxp0

.FXP0 - . libpcap . libcpap - . , , .


service data-source 1
type ip-traffic
source divert 199
rule 9000 "ip from 192.168.0.0/24 to any out xmit fxp0"
rule 11000 "ip from any to 192.168.0.0/24 in via fxp0"


divert natd from any to any via interface 9000 11000
199 , . FXP0 .



- monitor.
, . , 3.4.x 3.3.5
3.4.

enable
configure terminal
service monitor
monitor unit oid/name



service html
path /usr/local/www/stat
run 10sec
url http://192.168.9.1/stat
client-pages all
account-pages none

service scheduler
oid 08FFFF time 10sec action "html"



. . - quota. _ _ .
policy oid 013ECF name msgs target proto tcp port 25 110 5190

Service quota 0
storage 1
policy ip
block-policy msgs^M
notify soft owner
notify hard owner
notify return owner
, , Service Storage

. OID', .

Admintool, . :

telnet localhost 21000 ( )
enable
configure terminal
service quota
set OID/NAME active


set OID/NAME block-policy [ fw-policy, ] day [ ] in/out/both week [ ] in/out/both month [ ] in/out/both




- HOST/OID, , - ip, fw-policy, msgs. ip - 300 . K M G.
: , fw-policy msgs, .. 110 25 5190.


, . show config ( ). " ", .. . -

policy oid #### name NAME

, - .
, /usr/local/www/stat ( 3.4.1 /usr/local/www/netams)

( ) , layer7. , -DLAYER7-FILTER. - , .
Data Source

layer7-detect urls



policy hidden name urls target layer7-detect

hidden , html
acct-policy urls
, default acct-policy , default acct-policy urls.

! , url . proxy.


, , :

http://www.controlstyle.ru/products/web/text/namonitor/
nawt 2.6.0 ( 3.4.) 2.5.0 3.3.5
netams.com php .
nawt-2.5.0 ( 3.3.5) http://netamsadmin.sourceforge.net/nawt/nawt-2.0.5b.tar.gz
nawt-2.6.0 ( 3.4.0) http://netamsadmin.sourceforge.net/nawt/nawt-2.0.6.tar.gz
http://www.it2k.ru/projects/netams-front/


libpcap, netflow divert. -, .

..., netams transparent proxy. . :

01300 divert 199 ip from not 192.168.0.0/24 to any via em0
09000 divert 199 ip from 192.168.0.0/24 to any out xmit fxp0
09100 divert 199 ip from 192.168.254.0/24 to any out xmit fxp0
09500 fwd 127.0.0.1,3128 tcp from 192.168.0.0/24 to not 192.168.0.254 dst-port 80,3128,8080,8101,8108 via fxp0
09600 fwd 127.0.0.1,3128 tcp from 192.168.0.0/21 to not 192.168.0.254 dst-port 80,3128,8080,8101,8108 via fxp0
10000 divert 8668 ip from any to any via fxp0
11000 divert 199 ip from any to 192.168.0.0/24 in via fxp0



upd: netams-front
, . . Tmetr- 2 .
, .

:  
(0)

, sql .

, 10 2009 . 15:35 +
- mysql. , . 2 :
1)
2) , .
, . , . - - - , . . , . .

UPD: 0, . 6 10 . , __ , .

:  
(8)

.

, 06 2009 . 22:23 +
. . 1 . - . - -. 1,5 . . , 2 ( ). - " ", " ", " ". . .. , . "www slow ,www fast" . . -. . real-time . squid2mysql . , . awk' , . - - awk, , - . , , . - .
, .

 (699x518, 306Kb)
 (699x518, 186Kb)
 (699x518, 308Kb)

, . :)
-. .


. . nissin mr.moto . . . . 23 . , , .

:  
(2)

.

, 18 2009 . 02:19 +
. - . timesheet' . , , sql . . -. . -. , , - . , - , , , . . . , " ". . . , .
. , . - 3.4.2, , mysql51, . .


. , . . . , , , . , . - . - - , . . . .. - , ,, , , , . ,, . - - , - . . " " .
. , , 20 . - , . 20 . , , , . , . , 20 . , - , . - ? - , . , , - . ? . - . " ". , . , - . . - , , "", , - .

:  
(0)

.

, 16 2009 . 13:11 +

:  
(0)

, 29 2009 . 23:34 +
- -. () . -

:  
(0)

.

, 13 2008 . 20:50 +
. ( ) - fw-policy. . , . . .

:  
(0)

.

, 13 2008 . 12:13 +
( ) :
fw-policy , , . -( ). , fw-policy. fw-policy , . ! % . , , - . , - 80% . . , - . . . . , .

:  
(2)

.

, 05 2008 . 21:08 +
, ( ) -. , class-netams-client.php : . , . () . - - . !

:  
(0)

.

, 30 2008 . 18:06 +
. . - . - . , . , .

:  
(2)

, 21 2008 . 15:06 +
+. . - , , . . . - -. - . .

( ), ( )

-



account-policy fw-policy

, .

. . -. , ! 66 . , . . .

.
MONTH in: 112.392M, hardquota 1.000G ratio 11% -> [+]
"! !!!!!"

upd: - - . " "

- . - .

, 66, 85 . , .

upd: , netams . , , , .

:  
(0)

, 07 2008 . 22:36 +
netams-front. - "MAC-" monitor unit oid zzz
- "", .
- , fw-policy. , fw-policy . - , fw-policy ( , , description), , . , ,, . . , , . - . , :)

:  
(2)

.

, 14 2008 . 17:35 +
- -.

. . . . . . :
1. .
2. .
. . !
:
1.
"MONTH in: 926.270M, hardquota 2.000G ratio 45% -> [+]"
": "
.

2. . 70% .

3. . .

4. - .

:  
(0)

, 02 2008 . 21:10 +
- 3.4.12.
.... - fw-policy. -netamsfront . - . - . 3.4.. " " , , . . , . , . . "" .

. , .

:  

 : [1]