Showing posts with label network. Show all posts

Configuration initiale de Forefront TMG 2010

Forefront TMG



Configuration initiale de Forefront TMG 2010 :





 ________________________________________


Follow us on Facebook


Follow us on Google+


________________________________________




Forefront TMG



Cliquer sur Configure network settings 









Forefront TMG

Cliquer sur Next











Forefront TMG

Sélectionner le modèle de déploiement “Single network adapter”. 

Cliquer sur Next







Forefront TMG
Dans mon cas, la configuration IP était obtenue via DHCP. En production, vu que c’est un serveur, je recommande très fortement l’usage de paramètres IP fixes. Cliquer sur Next




Forefront TMG

Cliquer sur Finish











Forefront TMG


Cliquer sur Configure system settings









Forefront TMG

Ici il est possible de changer le nom du serveur ou son appartenance à un domaine ou groupe de travail. Dans mon cas, la machine est dans un workgroup. Cliquer sur Next



Forefront TMG

Cliquer sur Finish












Cliquer sur Define deployment options












Cliquer sur Next












Sélectionner Use the Microsoft Update Service to check for updates.

 Cliquer sur Next







Ici sélectionner les modes de licences de la protection NIS, de l’antivirus HTTP et du filtrage d’URL. Cliquer sur Next







Choisir ici le mode d’installation des mises à jour (signature antivirus HTTP, signatures NIS) ainsi que le comportement des réponses du NIS. Cliquer sur Next





Choisir ici si vous souhaitez participer au Customer Improvement Program. 

Cliquer sur Next







Choisir ici le niveau de remontée d’informations auprès de Microsoft. Cliquer sur Next.









Cliquer sur Finish













Cliquer sur Close


Maintenant on passe au paramétrage des règles d’accès Web










Configuration des règles d’accès Web







Cliquer sur Next












Sélectionner l’option proposée par défaut. Cliquer sur Next









Il est possible de modifier la liste des catégories à bloquer. Cliquer sur Next









Par défaut, il est proposé d’analyser (antivirus http) l’ensemble des contenus Web.

Cliquer sur Next.





Choisir ici si vous souhaitez faire de l’inspection sélectionner L’option proposée par défaut. Attention cependant : cette fonctionnalité nécessite d’utiliser un certificat “trusté” par les postes clients (ce qui peut nécessiter le déploiement sur les postes clients du certificat utilisé sur TMG).


Il est possible de notifier les utilisateurs de la présence de l’inspection SSL (c’est nécessaire légalement dans certains pays). Attention pour faire la notification, il faut déployer et utiliser le client pare-feu Forefront TMG sur les postes clients.
Cliquer sur Next


Dans mon cas, le certificat utilisé pour l’inspection HTTPS est un certificat auto-généré que je vais déployer sur mes postes clients. Exporter le certificat sous la forme d’un fichier.
Cliquer sur Next.



Définir ici la taille du fichier de cache du proxy. Cliquer sur Next.






Cliquer sur Finish pour terminer l’assistant de création des règles d’accès Web.








Le serveur est fonctionnel.

Sharing disks with NFS network

   

Sharing disks with NFS network

 ________________________________________

Follow us on Facebook

Follow us on Google+

________________________________________

 

 Introduction


NFS (Network File System) is a protocol used to mount network disks. This protocol is based on the client / server principle has been developed by Sun Microsystems in 1984. It can be used to exchange data between Linux, Mac or Windows. One of its advantages is that it manages file permissions.


Installing NFS


On Fedora, normally the tools for setting up a network via nfs are installed. You can check it with the command:

$ Rpm-qi nfs-utils

If you get back a message like: "The nfs-utils is not installed", you can install nfs-utils with the command:

# Yum install nfs-utils


Configuring NFS


Before starting the configuration, you must know the IP addresses of your client and server machines. You can get the address of each machine using the command:

$ / Sbin / ifconfig
 



Server-side


You must edit the file / etc / exports and add a line like:

/ path / to / shared @ _ip_client (rw) @ _ip_client2 (rw)

For example, if you want to share your / home / user and the client has the address 192.168.0.23, you would add the line: / home / user 192.168.0.23 (rw) Then it'll just restart the NFS server with the command:

# Service nfs start

Since Fedora 16, systemd uses NFS, it should run it with the command:

# Systemctl start nfs-server.service

If you want the service to be active in the launch of Fedora:
 

 

Client-side configuration


First you need to create a folder that will contain the shared / mnt or / media for example. Then you can mount the file directly with the command:

# Mount-t nfs @ _ip_serveur :/ path / to / share / mnt / share

It is also possible to mount at boot time, for this simply edit the file / etc / fstab and add a line like:

@ _ip_serveur :/ path / to / share / mnt / share nfs auto, user, rw 0 0

Once this change is made, you can mount all partitions in fstab by typing the command:

# Mount-a

You can use showmount to list information for mounting an NFS server:

$ Showmount-e <IP_du_serveur_NFS>

Some security

 

Configuring the firewall


Default portmap ports dynamically defined using NFS and transmits them to client port 2049, which makes the configuration of firewall. For simplicity, it is preferable to set the ports to allow our firewall enabled. You can either use the graphical tool, system-config-nfs or edit the file / etc / sysconfig / nfs manually so that it has the following parameters:

LOCKD_TCPPORT = 32803
LOCKD_UDPPORT = 32769
MOUNTD_PORT = 892
STATD_PORT = 662

Then, modify the configuration by fire so that your open its ports

# System-config-firewall

Ports are open:

2049 (nfs) tcp / upd
111 tcp / upd
32803 tcp / udp
32769 tcp / udp
892 tcp / udp
662 tcp / udp

By default, only the ports 2049, 111 and MOUNTD_PORT are used. The other match Diversent NFS server option.

Finally, you must restart the NFS service changes to take into account:

# / Etc / init.d / nfs restart

If you want to start the NFS server startup, use:

# Chkconfig nfs on
# Chkconfig rpcbind on

(adjust if you enable nfslock etc.).
 

Secure your Wireless Network

 

 Secure your Wireless Network :

 ________________________________________

Follow us on Facebook

Follow us on Google+

________________________________________

To secure your wireless network is an essential step to prevent a malicious user to use your wireless network. Here are the steps to follow.

Change the user password of your wireless router :

 

 Access the configuration utility of your router is secured with a username and a password. This page is accessed by typing the IP address of your router in your internet browser (eg 192.168.1.1). The first step in securing your new wireless network is to change the password by going to the option to change it.


Define your network name (SSID) :




Any WiFi network has a name: the SSID (Service Set IDentifier). The second step is to change the name and hide at the sight of malicious users. In the configuration utility of your router, change the default SSID name in avoiding it is too simple.Désactivez then broadcast SSID name of your wireless network by checking the corresponding box, so that n 'not appear in the list of possible connections of your neighbors.


Enable encryption on your network (security key) :


 


Before using your wireless network, it is useful to encrypt it with a digital key to not allow access only to users with it. Two types of data encryption currently exist: WEP (Wired Equivalent Privacy) and WPA (Wi-Fi Protected Access). If your router and your wireless adapters support it, you should opt for WPA encryption key with "pre-shared". However, if your hardware does not support WPA, then select WEP. The manipulation is simple because the digital encryption is created from a sentence you must enter a minimum 5-letter word or phrase in the text box and the router will generate different codes. Do not forget to note (one is enough) because they will be used to connect each computer on the network.


MAC address filtering :




Devices (PC or PDA) connected to a wireless network have a network card fitted with a specific address: MAC address (regardless of it, a computer is defined by its IP address). In the configuration utility of your router, you must activate the filter option and enter the MAC addresses of each of your devices. Thus, only these devices (known on the network by MAC address) can access the network.

Configure machines WiFi :



For each machine that can connect to the network, you need to specify the information listed above. After researching your wireless network, you must change the SSID to match the one you specified for the router. Then enter the numeric key encryption that was specified in the configuration utility of the router. This done, your device should connect to the router and the Internet.


Enable File Sharing :





To share files between computers and devices connected Wifi, you need to enable file sharing. The process of sharing in Windows XP is simple. Select << Control Panel >>, then << Network Connections >> and then click Create a home network or a corporate network. Then select This computer connects to the Internet through another computer on my home network or through a residential gateway. The connection wizard will detect your Internet connection.

To share a folder in Windows XP, right click on the file in question, and choose <<Sharing and Security>> and select the Share this folder option. To then access all shared folders from any machine on the network, click Start then My Network Places.

The technique is the same to a network printer: On the computer to which the printer is directly connected, go to the Start menu and then click Printers and Faxes, then right-click on the installed printer, and select Share.