ÆÐÅ¶Ææ½º´Â ¼³Ä¡Çϱ⠻ó´çÈ÷ ¾î·Á¿î ½Ã½ºÅÛÀ̳ª ½Ã°£ ÅõÀÚ ´ëºñ °¡Ä¡´Â ¶Ù¾î³ª´Ù. ÀÌ ½Ã½ºÅÛÀº À¯Àú°¡ ¼±È£ÇÏ´Â ¾î¶² OS ȯ°æÀ̳ª µð¹ÙÀ̽º¿Íµµ ±ÃÇÕÀÌ Àß ¸ÂÀ¸¸ç, ´Ù¾çÇϸ鼵µ ¾ÈÀüÇÑ ±â´ÉµéÀ» Áö³æ´Ù.
ÀÌ Áß Çϳª°¡ À¥±â¹ÝÀÇ admin ÅøÀ̶ó´Â °ÍÀÌ´Ù. ÆÐÅ¶Ææ½º¸¦ ¼³Ä¡Çϴµ¥ ¿ä±¸ »çÇ×ÀÌ ²Ï ¸¹À¸¸ç, Ä¿¸Çµå ¶óÀÎÀ» ÅëÇØ Çڵ鸵 ÇØ¾ß ÇÏ´Â °Íµµ ¸¹´Ù. ÇÏÁö¸¸, Çѹø ¼³Ä¡¸¦ ÇÏ°í ³ª¸é, À¥±â¹ÝÀÇ ÅøÀ» ÅëÇØ ¾ÆÁÖ ½±°Ô ¿î¿µ ÇÒ ¼ö ÀÖ´Ù.
ȯ°æ
ÀÌ ±Û¿¡¼´Â ¿ìºÐÅõ ¼¹ö 6.06¿¡¼ÀÇ ÆÐÅ¶Ææ½º À¥GUI¿¡ ´ëÇØ ¼³¸íÇÏ·Á°í ÇÑ´Ù. ÀÌ ¼ÒÇÁÆ®¿þ¾î »ç¿ë¿¡ ÀÖ¾î ÁÁÀº Á¡Àº ¿ä±¸ »çÇ×ÀÌ ¸¹Áö ¾Ê´Ù´Â °ÍÀÌ´Ù. ½ÇÁ¦·Î, AMD 2075MHz ÇÁ·Î¼¼½º¿¡ 512 MB RAM, SSH¸¸ Áö¿øµÇ¸é µÈ´Ù.
ÆÐÅ¶Ææ½º GUI¸¦ ÅëÇØ admin°èÁ¤À¸·Î ·Î±× Çϴµ¥, ¾ÆÀÌÆùÀ» ÀÌ¿ëÇØµµ »ó°ü¾ø´Ù. µû¶ó¼, ¾î¶² OS¸¦ »ç¿ëÇÏ´ø, À¥±â¹ÝÀÇ GUI »ç¿ë¿¡´Â ¹®Á¦µÉ °ÍÀÌ ¾ø´Ù.
½ÃÀÛÇϱâ
óÀ½À¸·Î ÇØ¾ß ÇÒ ÀÏÀº À¥ºê¶ó¿ìÀú¸¦ ¿°í https://IP_OF_PacketFence_SERVER:1443 ÁÖ¼Ò¸¦ Ä¡¸é ´ë½Ãº¸µå ȸéÀÌ <±×¸²1>°ú °°ÀÌ ³ªÅ¸³´Ù.
<±×¸²1>
´ë½Ãº¸µå¸¦ ÅëÇØ admin À¯Àú ³×ÀÓ ¹× ÆÐ½º¿öµå¸¦ ³Ö°í ·Î±×ÀÎ ÇÏ¸é µÈ´Ù. ´ëºÎºÐ À¯Àú³×ÀÓÀº adminÀ¸·Î ÇÑ´Ù.
GUI¸¦ º¸¸é ¸î °³ÀÇ ÅÇÀ» º¼ ¼ö ÀÖÀ¸¸ç, ÅÇÀÇ ¾Æ·§ºÎºÐÀº ´ëºÎºÐ ¸®Æ÷ÆÃ °ü·Ã ÇÑ °ÍÀ̸ç, ÅÇÀÇ ÀÂÊ ¿Àº ½ÇÁ¦ ¿î¿µ¿¡ °ü·Ã ÇÑ °ÍµéÀÌ´Ù.
ÇöÀç±îÁö ¾×Ƽºê ¸®Æ÷Æ®¿¡ °üÇÑ ¹ö±×°¡ ÀÖ´Ù. ¸¸¾à ¸®Æ÷Æ®¿¡¼ ¾×Ƽºê¸¦ ¼±ÅÃÇÏ¸é ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÉ °ÍÀÌ´Ù.
Error: Problems executing 'PFCMD report active '
DBD::mysql::st execute failed: Unknown column 'n.dhcp_fingerprint' in 'on clause' at /usr/local/pf/lib/pf/db.pm line 96.
Can't use string ("0") as a HASH ref while "strict refs" in use at /usr/local/pf/bin/pfcmd line 653.
ÀÌ ¹®Á¦´Â MySQL 5ÀÇ Á¶ÀκκÐÀÇ º¯°æÀ» ¾î¶»°Ô Çߴ°¡ ¶§¹®¿¡ ¹ß»ýÇÑ´Ù. ÀÌ ¹®Á¦´Â 1.6.4°¡ ¸±¸®½º µÇ¸é ÇØ°á µÉ °Í °°´Ù. µû¶ó¼ ±×¶§±îÁö´Â ¾×Ƽºê ¸®Æ÷Æ® ºÎºÐÀº ½ºÅµ ÇØ¾ß ÇÑ´Ù.
´ë½Ãº¸µå·Î ´Ù½Ã µ¹¾Æ°¡¼, À©µµ¿ì â¿¡ Áß¿äÇÑ Á¤º¸¸¦ º¸°Ô µÉ °ÍÀÌ´Ù.
-Disk Usage: ÆÐÅ¶Ææ½º ¼¹ö¿¡ ÀÖ´Â µð½ºÅ© »ç¿ë·®
-Memory Usage: ÆÐÅ¶Ææ½º ¼¹ö»ó¿¡¼ÀÇ ¸Þ¸ð¸® »ç¿ë·®.
-CPU Load:
-Recent Violations: ÆÐÅ¶Ææ½º¿¡ µû¸¥ ³×Æ®¿öÅ©»ó¿¡ ¹ß»ýÇß´ø ¸ðµç ÃÖ½Å Ä§ÇØ.
-Recent Registrations: ½Ã½ºÅÛ»ó¿¡¼ ¹ß»ýÇß´ø ¸ðµç µð¹ÙÀ̽ºÀÇ ·¹Áö½ºÆ®·¹À̼Ç(³ëÆ®: ÀÌ ºÎºÐÀº admin¿¡ ÀÇÇØ ¹ß»ýÇÑ °ÍÀÌ ¾Æ´Ï¶ó Ãʱâ À¯Àú µî·Ï½Ã ¹ß»ýÇÑ °ÍÀÓ.)
´ë½Ãº¸µå´Â À¯Àú¿¡ ¸Â°Ô Ä¿½ºÆ®¸¶ÀÌ¡ ÇÒ ¼ö ÀÖ°í, Ç¥ÁØ ´ë½Ãº¸µå´Â À¯Àú°¡ ¿øÇÏ´Â ¸ðµç Á¤º¸¸¦ Á¦°ø ÇÏÁö´Â ¾Ê´Â´Ù. ´ë½Ãº¸µå¸¦ Ä¿½ºÆ®¸¶ÀÌ¡ Çϱâ À§Çؼ´Â ¾ÆÀÌÄÜÀ» »ç¿ëÇÏ¿© º¯°æ Çϰųª ¸®Æ÷Æ®¸¦ Ãß°¡ ÇÒ ¼ö ÀÖ´Ù.
<±×¸²2>
<±×¸²3>
´ë½Ãº¸µå ±¸¼ºÀ» À§¿Í °°ÀÌ ÇÏ°í ³ª¸é, Sumit Query¸¦ ¼±ÅÃÇϸé, ¿øÇÏ´Â ´ë½Ãº¸µå°¡ µÈ´Ù. ¹°·Ð, ½ÇÁ¦·Î Â÷ÀÌÁ¡À» º¸±â Àü¿¡ ¸î °¡Áö Åë°èºÎºÐÀÌ ÆË¾÷ÀÌ ½ÃÀÛµÉ ¶§±îÁö ±â´Ù·Á¾ß ÇÑ´Ù.
Repostitory: History
´ë½Ãº¸µåÀÇ ¸®Æ÷Æ® ºÎºÐÀ¸·Î °¡º¸ÀÚ. ÀÌ ¼½¼ÇÀº À¯¿ëÇÑ Á¤º¸¸¦ ¸¹ÀÌ Á¦°ø Çϴµ¥ ±×¸²4¸¦ ÂüÁ¶Ç϶ó.
<±×¸²4>
ƯÁ¤ IP³ª MAC¾îµå·¹½º¿Í ÇÔ²² ¾×Ƽºê ¸®½ºÆ®¸¦ º¸°í ½Í´Ù°í °¡Á¤Çϸé, History ¸µÅ©¸¦ ¼±ÅÃÇϰí, IP³ª MAC¾îµå·¹½º¸¦ ÃÄ ³ÖÀ¸¸é º¼ ¼ö ÀÖ´Ù. ±×¸²5¸¦ ÂüÁ¶ Ç϶ó.
<±×¸²5>
Query History¸¦ ¼±ÅÃÇϸé, IP³ª MAC¾îµå·¹½ºÀÇ ¾×Ƽºê »óÅ¿´´ø ¸®Æ÷Æ®¸¦ º¼ ¼ö ÀÖ´Ù. ºÒÇàÇϰԵµ, ¸®Æ÷Æ® µÇ´Â µ¥ÀÌÅÍ´Â ¾×ƼºñƼ¿¡ ´ëÇÑ Æ¯Á¤ ½Ã°£¿¡ ¸®Æ÷Æ®¸¦ º¼ ¶§¸¸ À¯¿ëÇÏ´Ù.
±×¸²6¿¡¼ º¸´Â °Íó·³, ¸®Æ÷Æ® µÈ µ¥ÀÌÅÍ´Â MAC ¾îµå·¹¼, IP¾îµå·¹½º, Start Time, End TimeÀ» º¸¿©ÁØ´Ù. ¾×ƼºñƼ ŸÀÔÀº ºÒÇàÇϰԵµ ¾Ë ¼ö°¡ ¾ø´Ù.
<±×¸²6>
¸®Æ÷Æ®: Inactive
ÇÑ °¡Áö ÁÁÀº ±â´ÉÀº Inactive ¸®Æ÷Æ®ÀÌ´Ù. ³×Æ®¿öÅ©»óÀÇ µî·ÏµÇÁö ¾ÊÀº °¢°¢ÀÇ MAC¾îµå·¹½º ¸®½ºÆ®°¡ ³ªÅ¸³ª´Â °ÍÀ» ¼±ÅÃÇÏ¸é µÈ´Ù. <±×¸²7>À» ÂüÁ¶Ç϶ó.
<±×¸² 7>
History¸®Æ÷Æ®¿¡¼ ¾ò´Â Á¤º¸»Ó¸¸ ¾Æ´Ï¶ó, ºê¶ó¿ìÀú¿¡ µû¸¥ Á¤º¸, OSŸÀÔ, DHCP¶óÀ̼¾½º ¹× ARP¸®Æ÷Æ®¸¦ º¼ ¼ö ÀÖ´Ù.
Person
PersonÅÇÀº NAC»ó¿¡ ÀÖ´Â ¾îµå¹Î À¯Àú¸¦ Á¶Á¤ÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ÀÎÁõ(authentication)°ú Çò°¥¸®Áö ¾Ê±â¸¦ ¹Ù¶õ´Ù. AutenticationÀº ÀÌ ºÎºÐ°ú´Â ¾Æ¹« »ó°üÀÌ ¾ø´Ù. ¿©±â¼ PersonºÎºÐÀº ¾îµå¹ÎÀÇ ÀÛ¾÷À» ´õ¿í ½±°Ô ÇØÁÖ´Â °Í»ÓÀÌ´Ù.
½Ã½ºÅÛ »óÀÇ µð¹ÙÀ̽º¿¡ °áÇÕµÈ »ç¶÷ Ãß°¡, ÆíÁý ¶Ç´Â Áö¿ì±â¸¦ ÇÒ ¼ö ÀÖ´Ù. µû¶ó¼ MAC ¾îµå·¹½º¿¡ ¹«¾ùÀÌ ÀÖ´ÂÁö¸¦ ±â¾ïÇÏ´Â ´ë½Å¿¡, ¾î¶² À¯Àú°¡ ¾î¶² ºÎ¼¿¡ ¼ÓÇØ ÀÖ´ÂÁö, ½Ã½ºÅÛ¿¡ À¯Àú¸¦ Ãß°¡ Çϰí, ±×µéÀÇ À̸§°ú ÁÖ¼Ò¸¦ ÇÒ´çÇÏ´Â °ÍÀÌ´Ù.
<±×¸² 8>
<±×¸² 9>
Nodes
ÆÐÅ¶Ææ½º¿¡¼ÀÇ ³ëµå´Â ±âº»ÀûÀ¸·Î µð¹ÙÀ̽º¸¦ ÀÇ¹Ì ÇÑ´Ù. µð¹ÙÀ̽º´Â PC ÇÁ¸°ÅÍ, ¶ó¿ìÅÍ ¶Ç´Â Çãºêµî MAC¾îµå·¹½º¸¦ °¡Áö°í ÀÖ´Â µð¹ÙÀ̽º¸¦ ¸»ÇÑ´Ù. Node ÅÇÀ» ´©¸£¸é, ³×Æ®¿öÅ©»ó¿¡ Á¢¼Ó µÇ¾î ÀÖ´Â ¸ðµç µð¹ÙÀ̽º ¸®½ºÆ®¸¦ º¼ ¼ö ÀÖ´Ù.
<±×¸² 10>
¿¹¸¦ µé¾î, IP ¾îµå·¹½º 192.168.1.24°¡ ´©±º°¡¿¡ ¼ÓÇØ ÀÖ°í, ³ëµå ¸®½ºÆÃ¿¡ ±× »ç¶÷ÀÇ À̸§À» Ãß°¡ ÇÏ°í ½Í´Ù°í ÇÏÀÚ. ¹®Á¦´Â ³ëµå ¸®½ºÆÃÀº MAC¾îµå·¹½º¸¸ º¸¿© Áشٴ °ÍÀÌ´Ù. ÀÌ ¹®Á¦ÀÇ ÇØ°áÃ¥Àº °£´ÜÇÏ´Ù. Reports·Î °¡¼, History¸¦ ¼±ÅÃÇϰí, IP¾îµå·¹½º¸¦ ³Ö°í, Query History¸¦ ¼±ÅÃÇÏ¸é µÈ´Ù. ±×·¯¸é ¸®Æ÷Æ®¿¡ IP¾îµå·¹½º¿Í °áÇÕµÈ MAC¾îµå·¹½º¸¦ ¸®½ºÆ® ÇÒ °ÍÀÌ´Ù. MAC¾îµå·¹½º Áú¹®¿¡ ´ëÀÀÇÏ´Â Edit¹öưÀ» ´©¸£¸é ÆíÁý ȸéÀ» º¼ ¼ö ÀÖ´Ù.
<±×¸² 11>
Administration
ÀÌÁ¦ admin ÅøÀÇ ¸¹Àº ÀÛ¾÷À» µé¿©´Ù º¸ÀÚ. AdministrationÅÇÀ» ¼±ÅÃÇÏ¸é ¸¹Àº ¼ºêÅÇÀ» º¼ ¼ö ÀÖ´Ù.
" Configuration: ÀÌ ¼ºêÅÇ¿¡¼´Â ¸¹Àº ½Ã½ºÅÛÀÇ configurationÀ» º¼ ¼ö ÀÖ´Ù..
" Services: ÆÐŶ¼ºñ½ºÀÇ ½ÃÀÛ°ú Áß´ÜÀ» ÇÒ ¼ö ÀÖ´Ù.
" Add User
" UI Options.
" Remediation
" Instructions
Alerting
" Wins Server: Address of Wins server.
" E-mail Address: Address of administrator.
" SMTP Server: Outgoing mail server for system.
" Admin netbiosname: Netbios name of the PacketFence server.
" Log: Log file to be used for violations.
ARP
" DHCP Timeout: Hours and Minutes of ARP timeout.
" Clean Shutdown: Enable or disable.
" Interval: Seconds.
" Strobe: Enable or disable.
" GW Timeout: Enable or disable.
" ARP Timeout: Enable or disable.
" Heartbeat: Seconds.
" Stuffing: Enable or disable.
Database
" Username: Database username.
" Password: Database password.,
" Port: Port for database use.
" Host: Database host.
DHCP
" Registered lease: Hours.
" Unregistered lease time: Minutes.
" Isolation lease time: Minutes.
Expire
" Iplog: Days.
" Node: Days.
General
" Logo: Location of system logo.
" Caching: Enabled or disabled.
" Domain: Domain name.
" Dnsservers: Location of DNS servers.
" Hostname: Hostname of PacketFence server.
" Dhcpservers: Location of DHCP servers.
Interface
" IP address: IP of PacketFence server.
" Gateway: Gateway for PacketFence server.
" Type: Internal, Managed, or Monitored.
" Mask: Netmask of PacketFence server.
Logging
" Level: 0-8
" Priority: Debug, info, notice, warning, warn (same as warning), err, error (same as err), crit, alert, emerg, or panic (same as emerg).
" Facility: Auth, authpriv, cron, daemon, ftp, kern, lpr, mail, mark, news, security (same as auth), syslog, user, uucp, or local0 through local7.
Network
" Rogueinterval: 1-10.
" Named: Enabled or disbled.
" Scan: Enabled or disabled.
" Nat: Enabled or disabled.
" DHCP detector: Enabled or disabled.
" Mode: Passive or Inline.
" DHCP: Enabled or disabled.
Passthroughs
" Symantec Scanner: URL
" PacketFence: IP addresses of devices allowed to pass through system.
Ports
" Admin: Administration port
" Open: Open ports.
" Allowed: Ports allowed for use.
" Redirect: Ports that are redirected.
" Listeners: IMAP or POP3.
Proxies
" Stinger.exe: Address of stinger.exe
Registration
" Expire Window: Days
" Detection: Enabled or disabled.
" Range: IP address range for registration.
" Registration: Enabled or disabled.
" Skip reminder: Days
" Immediate: Enabled or disabled.
" Expire deadline: Date.
" Auth: Local, ldap, mysql, radius, or harvard.
" Expire Session: Days
" Skip Mode: Window, Deadline, Disabled.
" Isolation: Enabled.
" Queuesize: Integer
" Expire Mode: Window, deadline, session, or disabled.
" AUP: Enabled or disabled.
" Complete Message: Enabled or disabled.
" Redirect URL: Address for redirection.
" Skip Deadline: Date.
" Skip Window: Seconds, minutes, hours, days, weeks.
" Button Text: Text to appear on registration button.
" Maxnodes: Maximum number of nodes allowed.
Scan
" Pass: Type of data to pass
" SSL: Enabled or disabled.
" Live TIDS: Plug in IDs allowed to live on the system.
" User: User allowed to scan.
" Port: Port number for scanning.
" Registration: Enabled or disabled.
" Host: Address of scanning host.
Services
" Named: Location of named executable.
" DHCPD: Location of dhcpd executable.
" HTTP: Location of apache executable.
" Pfredirect: Location of pfredirect executable.
" Pfdetect: Location of pfdetect executable.
" Pfmon: Location of pfmon executable.
" Snort: location of snort executable.
Trapping
" Isolation: Enabled or disabled.
" Testing: Enabled or disabled.
" Detection: Enabled or disabled.
" Blacklist: Location of blacklist.
" Range: IP range of trapping.
" Whitelist: Enabled or disabled.
" Trapping Registration: Enabled or disabled.
" Redirect URL: URL for trapping redirection.
" Immediate: Enabled or disabled.
" Redirtimer: Seconds
" Passthrough: IP tables or proxy.