Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

A kọwalarị ihe atụ ụfọdụ nke ịhazi WiFi ụlọọrụ. N'ebe a, m ga-akọwa otú m si tinye ihe ngwọta dị otú ahụ na nsogbu ndị m zutere mgbe ejikọtara na ngwaọrụ dị iche iche. Anyị ga-eji LDAP dị ugbu a yana ndị ọrụ guzosiri ike, wụnye FreeRadius wee hazie WPA2-Enterprise na njikwa Ubnt. Ihe niile dị ka ọ dị mfe. Ka ahụ…

Obere maka usoro EAP

Tupu anyị amalite ọrụ ahụ, anyị kwesịrị ikpebi ụzọ nyocha anyị ga-eji na ngwọta anyị.

Site na Wikipedia:

EAP bụ usoro nyocha nke a na-ejikarị na netwọk ikuku yana njikọ nrụtụ aka ruo n'isi. Ebu ụzọ kọwaa usoro a na RFC 3748 wee kwalite ya na RFC 5247.
A na-eji EAP họrọ usoro nyocha, igodo nyefe, na hazie igodo ndị ahụ site na plugins akpọrọ ụzọ EAP. Enwere ọtụtụ ụzọ EAP, nke akọwapụtara na EAP n'onwe ya yana nke ndị na-ere ahịa wepụtara. EAP anaghị akọwa oyi akwa njikọ, ọ na-akọwa naanị usoro ozi. Protocol ọ bụla na-eji EAP nwere usoro mkpuchi mkpuchi ozi EAP nke ya.

Usoro n'onwe ha:

  • LEAP bụ protocol nwe nke CISCO mebere. Achọpụtara adịghị ike. Ugbu a akwadoghị maka ojiji
  • EAP-TLS kwadoro nke ọma n'etiti ndị na-ere ikuku. Ọ bụ protocol echekwara n'ihi na ọ bụ onye ga-anọchi ụkpụrụ SSL. Ịtọlite ​​onye ahịa dị nnọọ mgbagwoju anya. Ị chọrọ asambodo onye ahịa na mgbakwunye na paswọọdụ. Na-akwado na ọtụtụ usoro
  • EAP-TTLS - akwadoro n'ọtụtụ sistemụ, na-enye nchekwa dị mma site na iji asambodo PKI naanị na sava nyocha.
  • EAP-MD5 bụ ọkọlọtọ mepere emepe ọzọ. Na-enye obere nchekwa. N'adịghị ike, anaghị akwado nkwenye otu na ọgbọ isi
  • EAP-IKEv2 - dabere na Internet Key Exchange Protocol mbipute 2. Na-enye nkwenye otu na nhazi igodo nnọkọ n'etiti onye ahịa na nkesa.
  • PEAP bụ ngwọta nkwonkwo n'etiti CISCO, Microsoft na RSA Security dị ka ọkọlọtọ mepere emepe. A na-enweta ya na ngwaahịa, na-enye ezigbo nchekwa. Yiri EAP-TTLS, na-achọ naanị asambodo akụkụ nkesa
  • PEAPv0/EAP-MSCHAPv2 - Mgbe EAP-TLS gasịrị, nke a bụ ọkọlọtọ nke abụọ a na-ejikarị n'ụwa. Mmekọrịta ndị ahịa na nkesa na Microsoft, Cisco, Apple, Linux
  • PEAPv1/EAP-GTC - Cisco mepụtara dị ka ihe ọzọ na PEAPv0/EAP-MSCHAPv2. Anaghị echekwa data nyocha n'ụzọ ọ bụla. akwadoghị na Windows OS
  • EAP-FAST bụ usoro Cisco mepụtara iji dozie adịghị ike nke LEAP. Na-eji nzere nnweta echedoro (PAC). Emechachabeghị ya

N'ime ụdị dịgasị iche iche a, nhọrọ ahụ ka na-adịghị mma. Usoro nyocha chọrọ: ezigbo nchekwa, nkwado na ngwaọrụ niile (Windows 10, macOS, Linux, Android, iOS) na, n'ezie, ọ dị mfe karị. Ya mere, nhọrọ ahụ dabara na EAP-TTLS na njikọ PAP protocol.
Ajụjụ nwere ike ibilite - gịnị kpatara eji PAP? E kwuwerị, ọ na-ebufe okwuntughe na ederede doro anya?

Ee nke ahụ ziri ezi. Nkwukọrịta n'etiti FreeRadius na FreeIPA ga-ewere ọnọdụ dịka nke a. Na ọnọdụ debug, ị nwere ike soro otu esi ezipụ aha njirimara na paswọọdụ. Ee, hapụ ha ka ha laa, naanị gị nwere ohere na sava FreeRadius.

Ị nwere ike ịgụkwu gbasara otu EAP-TTLS si arụ ọrụ ebe a

FreeRADIUS

Anyị ga-ebuli FreeRadius na CentOS 7.6. Ọ dịghị ihe mgbagwoju anya ebe a, anyị na-etinye ya na mbụ ụzọ.

yum install freeradius freeradius-utils freeradius-ldap -y

N'ime ngwugwu ahụ, arụnyere ụdị 3.0.13. Enwere ike iwere nke ikpeazụ na https://freeradius.org/

Mgbe nke a gasịrị, FreeRadius na-arụ ọrụ. Ị nwere ike mebie ahịrị na /etc/raddb/users

steve   Cleartext-Password := "testing"

Malite n'ime ihe nkesa na ọnọdụ nbipu

freeradius -X

Ma mee njikọ ule site na localhost

radtest steve testing 127.0.0.1 1812 testing123

Anyị nwetara azịza Nweta nnabata-Nabata Id 115 sitere na 127.0.0.1:1812 ruo 127.0.0.1:56081 ogologo 20, ọ pụtara na ihe niile dị mma. Gaba n'ihu.

Ijikọ modul ldap.

ln -s /etc/raddb/mods-available/ldap /etc/raddb/mods-enabled/ldap

Anyị ga-agbanwekwa ya ozugbo. Anyị chọrọ FreeRadius ka anyị nwee ike ịnweta FreeIPA

mods-enyere/ldap

ldap {
server="ldap://ldap.server.com"
port=636
start_tls=yes
identity="uid=admin,cn=users,dc=server,dc=com"
password=**********
base_dn="cn=users,dc=server,dc=com"
set_auth_type=yes
...
user {
base_dn="${..base_dn}"
filter="(uid=%{%{Stripped-User-Name}:-%{User-Name}})"
}
...

Malitegharịa ihe nkesa radius wee lelee mmekọrịta nke ndị ọrụ LDAP:

radtest user_ldap password_ldap localhost 1812 testing123

Na-edezi eap in mods-enyere/eap
N'ebe a, anyị ga-agbakwunye ihe atụ abụọ nke eap. Ha ga-adị iche naanị na asambodo na igodo. Aga m akọwa ihe kpatara nke a ji bụrụ eziokwu n'okpuru.

mods-enyere/eap

eap eap-client {                                                                                                                                                                                                                           default_eap_type = ttls                                                                                                                                                                                                                 timer_expire = 60                                                                                                                                                                                                                       ignore_unknown_eap_types = no                                                                                                                                                                                                          cisco_accounting_username_bug = no                                                                                                                                                                                                      max_sessions = ${max_requests}
           tls-config tls-common {
           private_key_file = ${certdir}/fisrt.key
           certificate_file = ${certdir}/first.crt
           dh_file = ${certdir}/dh
           ca_path = ${cadir}
           cipher_list = "HIGH"
           cipher_server_preference = no
           ecdh_curve = "prime256v1"
           check_crl = no
           }
                                                                                                                                                                                                                                                                                                                                                                                                                                                 
           ttls {
           tls = tls-common
           default_eap_type = md5
           copy_request_to_tunnel = no
           use_tunneled_reply = yes
           virtual_server = "inner-tunnel"
           }
}
eap eap-guest {
default_eap_type = ttls                                                                                                                                                                                                                 timer_expire = 60                                                                                                                                                                                                                       ignore_unknown_eap_types = no                                                                                                                                                                                                          cisco_accounting_username_bug = no                                                                                                                                                                                                      max_sessions = ${max_requests}
           tls-config tls-common {
           private_key_passwotd=blablabla
           private_key_file = ${certdir}/server.key
           certificate_file = ${certdir}/server.crt
           dh_file = ${certdir}/dh
           ca_path = ${cadir}
           cipher_list = "HIGH"
           cipher_server_preference = no
           ecdh_curve = "prime256v1"
           check_crl = no
           }
                                                                                                                                                                                                                                                                                                                                                                                                                                                 
           ttls {
           tls = tls-common
           default_eap_type = md5
           copy_request_to_tunnel = no
           use_tunneled_reply = yes
           virtual_server = "inner-tunnel"
           }
}

Ọzọ anyị dezie enyere saịtị/ndabere. Enwere m mmasị na inye ikike ma kwado ngalaba.

enyere saịtị/ndabere

authorize {
  filter_username
  preprocess
  if (&User-Name == "guest") {
   eap-guest {
       ok = return
   }
  }
  elsif (&User-Name == "client") {
    eap-client {
       ok = return 
    }
  }
  else {
    eap-guest {
       ok = return
    }
  }
  ldap
  if ((ok || updated) && User-Password) {
    update {
        control:Auth-Type := ldap
    }
  }
  expiration
  logintime
  pap
  }

authenticate {
  Auth-Type LDAP {
    ldap
  }
  Auth-Type eap-guest {
    eap-guest
  }
  Auth-Type eap-client {
    eap-client
  }
  pap
}

Na ngalaba ikike anyị na-ewepụ modulu niile anyị na-achọghị. Anyị na-ahapụ naanị ldap. Tinye nkwenye ndị ahịa site na aha njirimara. Nke a bụ ya mere anyị ji gbakwunye ihe atụ abụọ nke eap n'elu.

Multi EAPNke bụ eziokwu bụ na mgbe ị na-ejikọta ụfọdụ ngwaọrụ anyị ga-eji asambodo usoro ma kọwaa ngalaba. Anyị nwere asambodo na igodo sitere na ikike asambodo ntụkwasị obi. Onwe m, n'uche nke m, usoro njikọ a dị mfe karịa ịtụba asambodo ejiri aka ya na ngwaọrụ ọ bụla. Mana ọbụlagodi na-enweghị asambodo ejiri aka ya bịanye aka, ọ ka agaghị ekwe omume ịpụ. Ngwaọrụ Samsung na gam akporo =<ụdị 6 amaghị ka esi eji asambodo sistemụ. Ya mere, anyị na-emepụta ihe atụ dị iche iche nke eap-leest maka ha nwere asambodo ejiri aka ya bịanye aka na ya. Maka ngwaọrụ ndị ọzọ niile anyị ga-eji eap-client nwere asambodo ntụkwasị obi. A na-ekpebi aha njirimara site na mpaghara amaghị mgbe ị na-ejikọta ngwaọrụ. Naanị ụkpụrụ 3 ka anabatara: ọbịa, onye ahịa na ubi efu. A na-atụfu ihe niile fọdụrụ. Enwere ike ịhazi nke a na atumatu. Aga m enye ihe atụ obere oge ma emechaa.

Ka anyị dezie ikike wee chọpụta ngalaba n'ime saịtị-enyere/n'ime-ọwara

saịtị-enyere/n'ime-ọwara

authorize {
  filter_username
  filter_inner_identity
  update control {
   &Proxy-To-Realm := LOCAL
  }
  ldap
  if ((ok || updated) && User-Password) {
    update {
        control:Auth-Type := ldap
    }
  }
  expiration
  digest
  logintime
  pap
  }

authenticate {
  Auth-Type eap-guest {
    eap-guest
  }
  Auth-Type eap-client {
    eap-client
  }
  Auth-Type PAP {
    pap
  }
  ldap
}

Na-esote, ị ga-ezipụta na atumatu aha nke enwere ike iji maka nbanye na-amaghị aha. Na-edezi policy.d/filter.

Ịkwesịrị ịchọta ahịrị ndị yiri nke a:

if (&outer.request:User-Name !~ /^(anon|@)/) {
  update request {
    Module-Failure-Message = "User-Name is not anonymized"
  }
  reject
}

Na n'okpuru elsif tinye ụkpụrụ ndị dị mkpa:

elsif (&outer.request:User-Name !~ /^(guest|client|@)/) {
  update request {
    Module-Failure-Message = "User-Name is not anonymized"
  }
  reject
}

Ugbu a, anyị kwesịrị ịkwaga na ndekọ asambodo. N'ebe a, anyị kwesịrị itinye igodo na asambodo sitere na ikike asambodo ntụkwasị obi, nke anyị nweburu, yana anyị kwesịrị iwepụta asambodo ejiri aka ya bịa maka eap-lest.

Ịgbanwe paramita dị na faịlụ ahụ ca.cnf.

ca.cnf


...
default_days = 3650
default_md = sha256
...
input_password = blablabla
output_password = blablabla
...
countryName = RU
stateOrProvinceNmae = State
localityNmae = City
organizationName = NONAME
emailAddress = [email protected]
commonName = "CA FreeRadius"

Anyị na-ede otu ụkpụrụ na faịlụ ahụ nkesa.cnf. Anyị na-agbanwe naanị
aha nkịtị:

nkesa.cnf


...
default_days = 3650
default_md = sha256
...
input_password = blablabla
output_password = blablabla
...
countryName = RU
stateOrProvinceNmae = State
localityNmae = City
organizationName = NONAME
emailAddress = [email protected]
commonName = "Server Certificate FreeRadius"

Anyị na-emepụta:

make

Njikere. natara nkesa.crt и ihe nkesa.key Anyị edebanyelarị aha n'elu na eap-leest.

Ma n'ikpeazụ, ka anyị tinye ebe nnweta anyị na faịlụ ahụ ahịa.conf. Enwere m 7 n'ime ha. Ka ị ghara itinye isi ihe ọ bụla iche iche, anyị ga-edebanye aha naanị netwọk ebe ha dị (ebe m nweta dị na VLAN dị iche).

client APs {
ipaddr = 192.168.100.0/24
password = password_AP
}

Onye njikwa Ubiquiti

Anyị na-ebuli netwọk dị iche na njikwa. Ka ọ bụrụ 192.168.2.0/24
Gaa na ntọala -> profaịlụ. Ka anyị mepụta nke ọhụrụ:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Anyị na-edepụta adreesị na ọdụ ụgbọ mmiri nke ihe nkesa radius na paswọọdụ e dere na faịlụ ahụ clients.conf:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Mepụta aha netwọk ikuku ọhụrụ. Họrọ WPA-EAP (Enterprise) dị ka usoro nyocha wee kọwapụta profaịlụ radius emepụtara:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Anyị na-echekwa ihe niile, tinye ya ma gaa n'ihu.

Ịtọlite ​​​​ndị ahịa

Ka anyị malite na akụkụ kacha sie ike!

Windows 10

Ihe isi ike na-agbada na eziokwu ahụ bụ na Windows amabeghị ka esi jikọọ na WiFi ụlọ ọrụ na ngalaba. Ya mere, anyị ga-eji aka bulite akwụkwọ anyị na ụlọ ahịa akwụkwọ ntụkwasị obi. N'ebe a, ị nwere ike iji nke ejiri aka ya bịanyere aka na ya ma ọ bụ nke sitere na ikike asambodo. M ga-eji nke abụọ.

Ọzọ ịkwesịrị ịmepụta njikọ ọhụrụ. Iji mee nke a, gaa na Ntọala netwọkụ na ịntanetị -> Network and Sharing Center -> Mepụta na hazie njikọ ọhụrụ ma ọ bụ netwọkụ:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Anyị jiri aka tinye aha netwọkụ wee gbanwee ụdị nchekwa. Wee pịa gbanwee ntọala njikọ na na Nche taabụ, họrọ njirimara netwọk - EAP-TTLS.

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Gaa na ntọala, tọọ nzuzo nke nyocha - ahịa. Dị ka ikike asambodo ntụkwasị obi, họrọ asambodo anyị gbakwunyere, lelee igbe “Enyela onye ọrụ oku ma ọ bụrụ na enweghị ike ịnye ihe nkesa ikike” wee họrọ usoro nyocha - paswọọdụ plaintext (PAP).

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Na-esote, gaa na paramita ndị ọzọ wee lelee igbe "Kpepụta ọnọdụ nyocha." Họrọ "Nnwale njirimara" wee pịa chekwaa nzere. Ebe ị ga-achọ itinye username_ldap na paswọọdụ_ldap

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Anyị na-echekwa, tinye, mechie ihe niile. Ị nwere ike jikọọ na netwọk ọhụrụ.

Linux

M nwalere na Ubuntu 18.04, 18.10, Fedora 29, 30.

Mbụ, budata asambodo maka onwe gị. Ahụbeghị m na Linux ma ọ ga-ekwe omume iji asambodo sistemụ ma ọ bụ na enwere ụlọ ahịa dị otú ahụ ma ọlị.

Anyị ga-ejikọta site na ngalaba. Ya mere, anyị chọrọ asambodo sitere n'aka ikike asambodo nke esi zụta asambodo anyị.

A na-eme njikọ niile n'otu windo. Họrọ netwọk anyị:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

amaghị aha - onye ahịa
ngalaba - ngalaba nke e nyere akwụkwọ ikike

android

na-abụghị Samsung

Site na ụdị 7, mgbe ị na-ejikọ WiFi, ịnwere ike iji asambodo sistemụ site na ịkọwa naanị ngalaba:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

ngalaba - ngalaba nke e nyere akwụkwọ ikike
amaghị aha - onye ahịa

Samsung

Dịka m dere n'elu, ngwaọrụ Samsung amaghị ka esi eji asambodo sistemụ mgbe ị na-ejikọ WiFi, ha enweghịkwa ike ijikọ site na ngalaba. Ya mere, ịkwesịrị iji aka tinye akwụkwọ mgbọrọgwụ nke ikike asambodo (ca.pem, were ya na sava Radius). Nke a bụ ebe a ga-eji aka nke aka ya mee ihe.

Budata asambodo na ngwaọrụ gị wee wụnye ya.

Ịwụnye asambodoỤlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

N'okwu a, ị ga-achọ ịtọ ụkpụrụ mkpọghe ihuenyo, koodu PIN ma ọ bụ paswọọdụ, ma ọ bụrụ na edobebeghị ya:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Egosiri m nhọrọ dị mgbagwoju anya maka ịwụnye asambodo. N'ọtụtụ ngwaọrụ, pịa naanị asambodo ebudatara.

Mgbe arụnyere asambodo, ị nwere ike ịga n'ihu na njikọ ahụ:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

asambodo - gosi nke ị rụnyere
onye na-amaghị aha - ọbịa

MacOS

Ngwa Apple nwere ike jikọọ na EAP-TLS site na igbe ahụ, mana ị ka kwesịrị ịnye ha asambodo. Iji kọwapụta usoro njikọ dị iche, ịkwesịrị iji Apple Configurator 2. N'ihi ya, ịkwesịrị ibu ụzọ budata ya na Mac gị, mepụta profaịlụ ọhụrụ wee gbakwunye ntọala WiFi niile dị mkpa.

Njikọta AppleỤlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

N'ebe a, anyị na-egosi aha netwọk anyị
Ụdị nchekwa - WPA2 Enterprise
Ụdị EAP anabatara - TTLS
Aha njirimara na okwuntughe - hapụ efu
Nyocha ime ime - PAP
Mpụta Identity - ahịa

Taabụ ntụkwasị obi. N'ebe a, anyị na-egosi ngalaba anyị

Ha niile. Enwere ike ịchekwa profaịlụ, bịanye aka ma kesaa ya na ngwaọrụ

Mgbe profaịlụ dị njikere, ịkwesịrị ibudata ya na Mac gị wee wụnye ya. N'oge usoro nrụnye, ị ga-achọ ezipụta usernmae_ldap na paswọọdụ_ldap nke onye ọrụ:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

iOS

Usoro a dị ka macOS. Ịkwesịrị iji profaịlụ (ị nwere ike iji otu ihe ahụ maka macOS. Lee n'elu maka otu esi emepụta profaịlụ na Apple Configurator).

Budata profaịlụ, wụnye, tinye nzere, jikọọ:

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ụlọ ọrụ WiFi. FreeRadius + FreeIPA + Ubiquiti

Ọ gwụla. Anyị melite sava Radius, mekọrịta ya na FreeIPA, wee gwa Ubiquiti ohere iji WPA2-EAP.

Ajụjụ enwere ike

Na: otu esi ebufe profaịlụ / asambodo na onye ọrụ?

BANYERE: Ana m echekwa asambodo/profaịlụ niile na FTP site na ịnweta site na webụ. Edobere m netwọk ndị ọbịa nwere oke ọsọ na ịnweta naanị ịntanetị, ewezuga FTP.
Nyocha na-adị ụbọchị 2, mgbe nke ahụ gasịrị, a na-emegharị ya ma hapụ onye ahịa na-enweghị ịntanetị. Nke ahụ. Mgbe onye ọrụ chọrọ ijikọ na WiFi, ọ na-ebu ụzọ jikọọ na netwọk ndị ọbịa, banye na FTP, budata asambodo ma ọ bụ profaịlụ ọ chọrọ, tinye ha, wee nwee ike jikọọ na netwọk ụlọ ọrụ.

Na: gịnị kpatara na ị gaghị eji atụmatụ MSCHAPv2 mee ihe? ọ ka mma!

BANYERE: Nke mbu, atụmatụ a na-arụ ọrụ nke ọma na NPS (Windows Network Policy System), na mmejuputa anyị, ọ dị mkpa ịhazi LDAP (FreeIpa) yana chekwaa hashes paswọọdụ na sava ahụ. Tinye. Ọ dịghị mma ịme ntọala, n'ihi na nke a nwere ike ibute nsogbu dị iche iche na mmekọrịta nke usoro ultrasound. Nke abuo, hash bụ MD4, yabụ na ọ naghị agbakwunye nchekwa dị ukwuu

Na: Ọ ga-ekwe omume iji adreesị mac nye ngwaọrụ ikike?

BANYERE: Mba, nke a adịghị mma, onye na-awakpo nwere ike imebi adreesị MAC, na ọbụna karịa, akwadoghị ikike site na adreesị MAC n'ọtụtụ ngwaọrụ.

Na: Gịnị kpatara iji asambodo ndị a niile? ị nwere ike jikọọ na-enweghị ha

BANYERE: A na-eji asambodo iji nye ihe nkesa ikike. Ndị ahụ. Mgbe ị na-ejikọta, ngwaọrụ na-enyocha ma ọ bụ ihe nkesa nwere ike ịtụkwasị obi ma ọ bụ na ọ bụghị. Ọ bụrụ otu a, mgbe ahụ nyocha na-aga n'ihu; ọ bụrụ na ọ bụghị, njikọ ahụ na-emechi. Ị nwere ike jikọọ na-enweghị asambodo, ma ọ bụrụ na onye na-awakpo ma ọ bụ onye agbata obi na-edozi ihe nkesa radius na ebe ịnweta otu aha dị ka nke anyị n'ụlọ, ọ nwere ike igbochi nzere onye ọrụ (echefula na a na-ebufe ya na ederede doro anya) . Mgbe ejiri asambodo, onye iro ga-ahụ na ndekọ ya naanị Aha njirimara anyị - onye ọbịa ma ọ bụ onye ahịa yana ụdị njehie - Asambodo CA amabeghị.

ntakịrị ihe gbasara macOSDịka, na macOS, a na-emeghachi sistemụ ahụ site na ịntanetị. Na mgbake mode, Mac ga-jikọọ na WiFi, na ọ bụghị ụlọ ọrụ anyị WiFi ma ọ bụ ọbịa netwọk ga-arụ ọrụ ebe a. Onwe m, etinyere m netwọkụ ọzọ, WPA2-PSK na-emebu, zoro ezo, naanị maka ọrụ teknụzụ. Ma ọ bụ ị nwekwara ike ịmepụta draịvụ USB bootable na sistemụ ahụ tupu oge eruo. Ma ọ bụrụ na Mac gị bụ mgbe 2015 gasịrị, ị ga-achọkwa ihe nkwụnye ọkụ maka draịvụ a)

isi: www.habr.com

Tinye a comment