I-PacketFence - Isistimu Yokulawula Ukufinyelela Kwenethiwekhi Yomthombo Ovulekile

IphaketheFence

Muva nje I-Inverse imemezele ukukhishwa kwenguqulo 8.2 yePacketFence. Kubo bonke labo bafundi abangazi noma abangakezwa ngePacketFence singakusho lokho Lesi yisixazululo sokuthobela inethiwekhi ngokuphelele (i-GPL v2) ngokuphelele.

Es inketho ekahle impela lapho uzama ukuhlanganisa ubuchwepheshe obuhlukile bokuvikela kwimishini yokugcina, njenge-antivirus, ukusingathwa kokungena ngaphakathi, imibiko yokuba sengozini, uhlelo lomsebenzisi noma lokufakazela ubuqiniso nokuqinisa ukuphepha kwenethiwekhi yokufinyelela.

IPacketFence ingasetshenziselwa ukuvikela kahle womabili amanethiwekhi amancane kanye namanethiwekhi amakhulu kakhulu ahlukahlukene.

Futhin Singasebenzisa i-ejenti, bavumela amasheke wokuthobela, ukucushwa nokuningi izindawo zokugcina ezixhunywe kunethiwekhi yakho. I-PacketFence ingaqinisekisa ukuthi ama-ejenti (noma amaklayenti) afakiwe phakathi nenqubo yokubhalisa bese exhumeka uxhumano ngalunye olusha

Phakathi kwezici eziyinhloko zokuqapha nokulawula zohlelo esizitholayo:

  • Ukuphathwa kwe-VLAN okuguqukayo nokulawulwa kokufinyelela okususelwa endimeni
  • Ukufinyelela kwezivakashi: letha idivayisi yakho (BYOD)
  • Amaphrofayli wePortal
  • Izinhlobo eziningi zokudlwengula ezakhelwe ngaphakathi
  • Ukubhaliswa okuzenzakalelayo
  • Ukusekelwa kwe-PKI ne-EAP-TLS
  • Ukuphelelwa yisikhathi
  • Ukuphathwa Kwedivayisi
  • Ukuhlanganiswa komlilo
  • Ukubalwa komkhawulokudonsa
  • Amadivayisi enethiwekhi entantayo
  • Ukuqinisekisa okuguqukayo
  • Ukuhlanganiswa kweMicrosoft Active Directory
  • Amanethiwekhi ajwayelekile
  • Ukuthunyelwa kancane kancane
  • I-Hardware ehambisanayo

Lapho singagqamisa khona lokho ngo-Pi-acketFence sinikezwa ithuba lokuqapha amadivayisi axhunywe kunethiwekhi nokuphatha ukuhlala kwawo kuwo lapho singabeka khona isikhathi sakho kunethiwekhi, inani lebhendi elizosetshenziswa, sisebenzisa izinqubomgomo ze-Firewall.

IPacketFence yisixazululo esingaxakeki esisebenza nenqwaba yamadivayisi wenethiwekhi (anentambo noma angenantambo) njenge-3Com, Aerohive, Brocade, Cisco, Dell / Force10, Enterasys, Extreme Networks, Huawei, Intel, Meru Network, Mojo Networks, Motorola , Netgear, Nortel / Avaya, Ruckus, Ubiquiti, Xirrus, nokuningi.

Uhlobo olusha lwe-Update 8.2

Lokhu kukhishwa okusha kokuvuselelwa kuletha ezinye izici ezintsha, kepha ikakhulukazi ukulungiswa okuningi.

Yize esa "minor", le nguqulo engu-8.2 iyisibuyekezo esikhulu, siletha okungeziwe nokuthuthuka okuningi.

Ezingxenyeni ezintsha ezingagqanyiswa, singathola umthombo omusha wokufakazela ubuqiniso lapho kungasungulwa khona «iphasiwedi yosuku» kanye nokuqinisekiswa kwe- "Web Mojo".

Ngokwengeziwe, ukusekelwa kwamaqoqo eseva atholakala kuma-Layer 3 amaningi naku-Voice over IP amanethiwekhi kanye nama-ACL alandekayo wenkinobho yenethiwekhi ye-Aruba 5400 engeziwe.

Okokugcina, onjiniyela bacela ukuthi bazi ukuthi ukuqinisekiswa kwe-mac wired ne-ethernet-noeap kuhlanganisiwe.

Kulungiswe iziphazamisi: landa imethadatha ye-SAML kuphekhi yokuphatha, izindaba ezahlukahlukene ze-pfdhcp zilungisiwe, "i-DNS" izinzuzo ezingamanga zisusiwe, nabanye abambalwa.

Ekugcineni, Ohlwini lokuthuthuka olutholakala ngale nguqulo 8.2, singagqamisa:

  • Ukuthuthuka kweskripthi sesondlo (amathuba amasha wokubhakwa kweGolang, ukuqala kabusha kweRsyslog).
  • Ukuhlelwa kabusha kwemithetho ye-IPtables.
  • Usebenzisa i-MySQL backend yezinketho ze-pfdhcp.
  • Ushintsho lwenziwe kusuka ku-4 Gio kuye ku-18 Eio (exbioctet) yebhalansi yomkhawulokudonsa omkhulu.
  • Izihlungi zokushintsha inethiwekhi manje zingasetshenziswa esikhundleni semodyuli yokushintsha eyenziwe ngesikhathi sokuxhumeka kweRadius.
  • Ukubanjwa okuthuthukile kwamaphutha wokumiswa kufayela le-pfdetect.conf lokumisa.
  • Izibalo ze-HAProxy manje sezi / var / run ezinamagama acacile.
  • I-Pfdns manje isebenzisa umtapo wezincwadi ojwayelekile we-Golang.
  • Kungezwe ukusekelwa kweCoA kokushintshwa kwenethiwekhi kweMeraki.
  • Ukuhlunga okuthuthukile kwamaphrofayela wokuxhuma kuyathuthukiswa.
  • Ukungeza umsebenzi wokuhlola kusistimu yokuxwayisa ye-SMTP.

Ungayifaka kanjani iPacketFence kuLinux?

Uhlelo lokusebenza isinikeza izifaki ezimbili zokusatshalaliswa okwehlukile kweLinux, eyodwa ngefomethi ye-deb futhi eyodwa ngefomethi ye-rpm kulesi sixhumanisi.

Kuko konke ukusatshalaliswa singasebenzisa ikhodi yomthombo futhi sihlanganise uhlelo lokusebenza.


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.