ื”ืคืจื•ื™ืงื˜ ื”ืœื ืžืžื•ืžืฉ ืฉืœื™. ืจืฉืช ืฉืœ 200 ื ืชื‘ื™ MikroTik

ื”ืคืจื•ื™ืงื˜ ื”ืœื ืžืžื•ืžืฉ ืฉืœื™. ืจืฉืช ืฉืœ 200 ื ืชื‘ื™ MikroTik

ืฉืœื•ื ืœื›ื•ืœื. ืžืืžืจ ื–ื” ืžื™ื•ืขื“ ืœืžื™ ืฉื™ืฉ ื‘ืฆื™ ืžื›ืฉื™ืจื™ ืžื™ืงืจื•ื˜ื™ืง ืจื‘ื™ื, ื•ืจื•ืฆื™ื ืœื‘ืฆืข ืื™ื—ื•ื“ ืžื™ืจื‘ื™ ื›ื“ื™ ืœื ืœื”ืชื—ื‘ืจ ืœื›ืœ ืžื›ืฉื™ืจ ื‘ื ืคืจื“. ื‘ืžืืžืจ ื–ื” ืืชืืจ ืคืจื•ื™ืงื˜ ืฉืœืฆืขืจื™ ืœื ื”ื’ื™ืข ืœืชื ืื™ ืœื—ื™ืžื” ืขืงื‘ ื’ื•ืจืžื™ื ืื ื•ืฉื™ื™ื. ื‘ืงื™ืฆื•ืจ: ื™ื•ืชืจ ืž-200 ื ืชื‘ื™ื, ื”ื’ื“ืจื” ืžื”ื™ืจื” ื•ื”ื›ืฉืจืช ืฆื•ื•ืช, ืื™ื—ื•ื“ ืœืคื™ ืื–ื•ืจ, ืกื™ื ื•ืŸ ืจืฉืชื•ืช ื•ืžืืจื—ื™ื ืกืคืฆื™ืคื™ื™ื, ืืคืฉืจื•ืช ืœื”ื•ืกื™ืฃ ื›ืœืœื™ื ื‘ืงืœื•ืช ืœื›ืœ ื”ืžื›ืฉื™ืจื™ื, ืจื™ืฉื•ื ื•ื‘ืงืจืช ื’ื™ืฉื”.

ืžื” ืฉืžืชื•ืืจ ืœื”ืœืŸ ืื™ื ื• ืžืชื™ื™ืžืจ ืœื”ื™ื•ืช ืžืงืจื” ืžื•ื›ืŸ, ืื‘ืœ ืื ื™ ืžืงื•ื•ื” ืฉื”ื•ื ื™ื”ื™ื” ืฉื™ืžื•ืฉื™ ืขื‘ื•ืจืš ื‘ืขืช ืชื›ื ื•ืŸ ื”ืจืฉืชื•ืช ืฉืœืš ื•ืžื–ืขื•ืจ ืฉื’ื™ืื•ืช. ืื•ืœื™ ื›ืžื” ื ืงื•ื“ื•ืช ื•ืคืชืจื•ื ื•ืช ืœื ื ืจืื™ื ืœืš ืœื’ืžืจื™ ื ื›ื•ื ื™ื - ืื ื›ืŸ, ื›ืชื•ื‘ ื‘ืชื’ื•ื‘ื•ืช. ื”ื‘ื™ืงื•ืจืช ื‘ืžืงืจื” ื–ื” ืชื”ื™ื” ื—ื•ื•ื™ื” ืœืื•ืฆืจ ื”ืžืฉื•ืชืฃ. ืœื›ืŸ, ืงื•ืจื, ืชืกืชื›ืœ ืขืœ ื”ื”ืขืจื•ืช, ืื•ืœื™ ื”ืžื—ื‘ืจ ืขืฉื” ื˜ืขื•ืช ื—ืžื•ืจื” - ื”ืงื”ื™ืœื” ืชืขื–ื•ืจ.

ืžืกืคืจ ื”ื ืชื‘ื™ื ื”ื•ื 200-300, ืžืคื•ื–ืจื™ื ื‘ืขืจื™ื ืฉื•ื ื•ืช ืขื ืื™ื›ื•ืช ืฉื•ื ื” ืฉืœ ื—ื™ื‘ื•ืจื™ ืื™ื ื˜ืจื ื˜. ื™ืฉ ืฆื•ืจืš ืœืขืฉื•ืช ื”ื›ืœ ื‘ืฆื•ืจื” ื™ืคื” ื•ื‘ืจื•ืจื” ืœืžื ื”ืœื™ื ื”ืžืงื•ืžื™ื™ื ืื™ืš ื”ื›ืœ ื™ืขื‘ื•ื“.

ืื– ืื™ืคื” ื›ืœ ืคืจื•ื™ืงื˜ ืžืชื—ื™ืœ? ื›ืžื•ื‘ืŸ, ืขื TK.

  1. ืืจื’ื•ืŸ ืชื›ื ื™ืช ืจืฉืช ืœื›ืœ ื”ืกื ื™ืคื™ื ืœืคื™ ื“ืจื™ืฉื•ืช ื”ืœืงื•ื—, ืคื™ืœื•ื— ืจืฉืช (ืž-3 ืขื“ 20 ืจืฉืชื•ืช ื‘ืกื ื™ืคื™ื ื‘ื”ืชืื ืœื›ืžื•ืช ื”ืžื›ืฉื™ืจื™ื).
  2. ื”ื’ื“ืจืช ืžื›ืฉื™ืจื™ื ื‘ื›ืœ ืกื ื™ืฃ. ื‘ื“ื™ืงืช ืžื”ื™ืจื•ืช ื”ืชืคื•ืงื” ื”ืืžื™ืชื™ืช ืฉืœ ื”ืกืคืง ื‘ืชื ืื™ ื”ืคืขืœื” ืฉื•ื ื™ื.
  3. ืืจื’ื•ืŸ ื”ื’ื ืช ื”ืžื›ืฉื™ืจ, ื ื™ื”ื•ืœ ืจืฉื™ืžืช ื”ืœื‘ื ื™ื, ื–ื™ื”ื•ื™ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ื”ืชืงืคื•ืช ืขื ืจืฉื™ืžื” ืฉื—ื•ืจื” ืื•ื˜ื•ืžื˜ื™ืช ืœืคืจืง ื–ืžืŸ ืžืกื•ื™ื, ืžื–ืขื•ืจ ื”ืฉื™ืžื•ืฉ ื‘ืืžืฆืขื™ื ื˜ื›ื ื™ื™ื ืฉื•ื ื™ื ื”ืžืฉืžืฉื™ื ืœื™ื™ืจื˜ ืฉืœื™ื˜ื” ื‘ื’ื™ืฉื” ื•ืžื ื™ืขืช ืฉื™ืจื•ืช.
  4. ืืจื’ื•ืŸ ื—ื™ื‘ื•ืจื™ VPN ืžืื•ื‘ื˜ื—ื™ื ืขื ืกื™ื ื•ืŸ ืจืฉืช ืœืคื™ ื“ืจื™ืฉื•ืช ื”ืœืงื•ื—. ืžื™ื ื™ืžื•ื 3 ื—ื™ื‘ื•ืจื™ VPN ืžื›ืœ ืกื ื™ืฃ ืœืžืจื›ื–.
  5. ื‘ื”ืชื‘ืกืก ืขืœ ื ืงื•ื“ื•ืช 1, 2. ื‘ื—ืจ ืืช ื”ื“ืจื›ื™ื ื”ืื•ืคื˜ื™ืžืœื™ื•ืช ืœื‘ื ื™ื™ืช VPN-ืกื•ื‘ืœื ื™ ืชืงืœื•ืช. ืื ื™ืฉ ื”ืฆื“ืงื” ื ื›ื•ื ื”, ื ื™ืชืŸ ืœื‘ื—ื•ืจ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ื”ื ื™ืชื•ื‘ ื”ื“ื™ื ืžื™ ืขืœ ื™ื“ื™ ื”ืงื‘ืœืŸ.
  6. ืืจื’ื•ืŸ ืชืขื“ื•ืฃ ืชืขื‘ื•ืจื” ืœืคื™ ืคืจื•ื˜ื•ืงื•ืœื™ื, ื™ืฆื™ืื•ืช, ืžืืจื—ื™ื ื•ืฉื™ืจื•ืชื™ื ืกืคืฆื™ืคื™ื™ื ืื—ืจื™ื ื”ืžืฉืžืฉื™ื ืืช ื”ืœืงื•ื—. (VOIP, ืžืืจื—ื™ื ืขื ืฉื™ืจื•ืชื™ื ื—ืฉื•ื‘ื™ื)
  7. ืืจื’ื•ืŸ ื ื™ื˜ื•ืจ ื•ืจื™ืฉื•ื ืื™ืจื•ืขื™ ื ืชื‘ ืœืžืขื ื” ืฉืœ ืฆื•ื•ืช ืชืžื™ื›ื” ื˜ื›ื ื™ืช.

ื›ืคื™ ืฉืื ื• ืžื‘ื™ื ื™ื, ื‘ืžืกืคืจ ืžืงืจื™ื ื”ืžืคืจื˜ ื”ื˜ื›ื ื™ ื ืขืจืš ื‘ื”ืชืื ืœื“ืจื™ืฉื•ืช. ืืช ื”ื“ืจื™ืฉื•ืช ื”ืœืœื• ื’ื™ื‘ืฉืชื™ ื‘ืขืฆืžื™, ืœืื—ืจ ืฉื”ืงืฉื‘ืชื™ ืœื‘ืขื™ื•ืช ื”ืขื™ืงืจื™ื•ืช. ื”ื•ื ื”ื•ื“ื” ื‘ืืคืฉืจื•ืช ืฉืžื™ืฉื”ื• ืื—ืจ ื™ื•ื›ืœ ืœื˜ืคืœ ื‘ื ืงื•ื“ื•ืช ื”ืœืœื•.

ื‘ืื™ืœื• ื›ืœื™ื ื™ืฉืžืฉื• ื›ื“ื™ ืœืขืžื•ื“ ื‘ื“ืจื™ืฉื•ืช ืืœื•:

  1. ืžื—ืกื ื™ืช ELK (ืœืื—ืจ ื–ืžืŸ ืžื”, ื”ืชื‘ืจืจ ืฉื™ื™ืขืฉื” ืฉื™ืžื•ืฉ ื‘-fluentd ื‘ืžืงื•ื logstash).
  2. ืื ืกื™ื‘ืœ. ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ื ื™ื”ื•ืœ ื•ืฉื™ืชื•ืฃ ื”ื’ื™ืฉื”, ื ืฉืชืžืฉ ื‘-AWX.
  3. GITLAB. ืื™ืŸ ืฆื•ืจืš ืœื”ืกื‘ื™ืจ ื›ืืŸ. ืื™ืคื” ื”ื™ื™ื ื• ื‘ืœื™ ื‘ืงืจืช ื’ืจืกืื•ืช ืฉืœ ื”ื”ื’ื“ืจื•ืช ืฉืœื ื•?
  4. ืคื’ื– ื›ื•ื—. ื™ื”ื™ื” ืกืงืจื™ืคื˜ ืคืฉื•ื˜ ืœื“ื•ืจ ื”ืจืืฉื•ื ื™ ืฉืœ ื”ืชืฆื•ืจื”.
  5. ื“ื•ืงื• ื•ื™ืงื™, ืœื›ืชื™ื‘ืช ืชื™ืขื•ื“ ื•ืžื“ืจื™ื›ื™ื. ื‘ืžืงืจื” ื–ื”, ืื ื• ืžืฉืชืžืฉื™ื ื‘-habr.com.
  6. ื”ื ื™ื˜ื•ืจ ื™ืชื‘ืฆืข ื‘ืืžืฆืขื•ืช zabbix. ืœืฉื ื”ื‘ื ื” ื›ืœืœื™ืช ื™ืฉืจื˜ื˜ ื’ื ื“ื™ืื’ืจืžืช ื—ื™ื‘ื•ืจ.

ื ืงื•ื“ื•ืช ื”ืชืงื ื” ืฉืœ EFK

ืœื’ื‘ื™ ื”ื ืงื•ื“ื” ื”ืจืืฉื•ื ื”, ืืชืืจ ืจืง ืืช ื”ืื™ื“ื™ืื•ืœื•ื’ื™ื” ืฉืœืคื™ื” ื™ื™ื‘ื ื• ื”ืžื“ื“ื™ื. ื™ืฉ ื”ืจื‘ื”
ืžืืžืจื™ื ืžืฆื•ื™ื ื™ื ืขืœ ื”ื’ื“ืจื” ื•ืงื‘ืœื” ืฉืœ ื™ื•ืžื ื™ื ืžืžื›ืฉื™ืจื™ื ืฉื‘ื”ื ืคื•ืขืœ mikrotik.

ืืชืขื›ื‘ ืขืœ ื›ืžื” ื ืงื•ื“ื•ืช:

1. ืœืคื™ ื”ืชืจืฉื™ื, ื›ื“ืื™ ืœืฉืงื•ืœ ืงื‘ืœืช ื™ื•ืžื ื™ื ืžืžืงื•ืžื•ืช ืฉื•ื ื™ื ื•ื‘ื™ืฆื™ืื•ืช ืฉื•ื ื•ืช. ืœืฉื ื›ืš ื ืฉืชืžืฉ ื‘ืฆื‘ืจ ื™ื•ืžื ื™ื. ืื ื—ื ื• ื’ื ืจื•ืฆื™ื ืœื™ืฆื•ืจ ื’ืจืคื™ืงื” ืื•ื ื™ื‘ืจืกืœื™ืช ืœื›ืœ ื”ื ืชื‘ื™ื ืขื ื”ื™ื›ื•ืœืช ืœืฉืชืฃ ื’ื™ืฉื”. ืœืื—ืจ ืžื›ืŸ ืื ื• ื‘ื•ื ื™ื ืืช ื”ืื™ื ื“ืงืกื™ื ื‘ืื•ืคืŸ ื”ื‘ื:

ื”ื ื” ื—ืœืง ืžื”ืชืฆื•ืจื” ืขื fluentd ืกื•ื’ elasticsearch
logstash_format true
index_name mikrotiklogs.north
logstash_prefix mikrotiklogs.north
flush_interval 10s
ืžืืจื—ื™ื ืืœืกื˜ื™ืงื”: 9200
ื™ืฆื™ืื” 9200

ื›ืš ื ื•ื›ืœ ืœืฉืœื‘ ื ืชื‘ื™ื ื•ืœืคืœื— ืœืคื™ ื”ืชื•ื›ื ื™ืช - mikrotiklogs.west, mikrotiklogs.south, mikrotiklogs.east. ืœืžื” ืœืขืฉื•ืช ืืช ื–ื” ื›ืœ ื›ืš ืžืกื•ื‘ืš? ืื ื• ืžื‘ื™ื ื™ื ืฉื™ื”ื™ื• ืœื ื• 200 ืžื›ืฉื™ืจื™ื ืื• ื™ื•ืชืจ. ืื™ ืืคืฉืจ ืœืขืงื•ื‘ ืื—ืจ ื”ื›ืœ. ืขื ื’ืจืกื” 6.8 ืฉืœ elasticsearch, ื”ื’ื“ืจื•ืช ืื‘ื˜ื—ื” ื–ืžื™ื ื•ืช ืœื ื• (ืœืœื ืจื›ื™ืฉืช ืจื™ืฉื™ื•ืŸ), ื•ื‘ื›ืš ื ื•ื›ืœ ืœื”ืคื™ืฅ ื–ื›ื•ื™ื•ืช ืฆืคื™ื™ื” ื‘ื™ืŸ ืขื•ื‘ื“ื™ ืชืžื™ื›ื” ื˜ื›ื ื™ืช ืื• ืžื ื”ืœื™ ืžืขืจื›ืช ืžืงื•ืžื™ื™ื.
ื˜ื‘ืœืื•ืช, ื’ืจืคื™ื - ื›ืืŸ ืืชื” ืจืง ืฆืจื™ืš ืœื”ืกื›ื™ื - ืื• ืœื”ืฉืชืžืฉ ื‘ืื•ืชื, ืื• ืฉื›ืœ ืื—ื“ ื™ืขืฉื” ืžื” ืฉื ื•ื— ืœื•.

2. ืขืœ ื™ื“ื™ ืจื™ืฉื•ื. ืื ื ืืคืฉืจ ื›ื ื™ืกื” ืœื›ืœืœื™ ื—ื•ืžืช ื”ืืฉ, ื ื”ืคื•ืš ืืช ื”ืฉืžื•ืช ืœืœื ืจื•ื•ื—ื™ื. ื ื™ืชืŸ ืœืจืื•ืช ืฉื‘ืืžืฆืขื•ืช ืชืฆื•ืจื” ืคืฉื•ื˜ื” ื‘-fluentd, ืื ื• ื™ื›ื•ืœื™ื ืœืกื ืŸ ื ืชื•ื ื™ื ื•ืœื™ืฆื•ืจ ืคืื ืœื™ื ื ื•ื—ื™ื. ื”ืชืžื•ื ื” ืœืžื˜ื” ื”ื™ื ื”ื ืชื‘ ื”ื‘ื™ืชื™ ืฉืœื™.

ื”ืคืจื•ื™ืงื˜ ื”ืœื ืžืžื•ืžืฉ ืฉืœื™. ืจืฉืช ืฉืœ 200 ื ืชื‘ื™ MikroTik

3. ืœืคื™ ืฉื˜ื— ืชืคื•ืก ื•ื™ื•ืœื™ ืขืฅ. ื‘ืžืžื•ืฆืข, ืขื 1000 ื”ื•ื“ืขื•ืช ืœืฉืขื”, ื™ื•ืžื ื™ื ืชื•ืคืกื™ื 2-3 ืžื’ื”-ื‘ื™ื™ื˜ ืœื™ื•ื, ื•ื–ื”, ืืชื” ืžื‘ื™ืŸ, ืœื ื›ืœ ื›ืš ื”ืจื‘ื”. Elasticsearch ื’ืจืกื” 7.5.

ANSIBLE.AWX

ืœืžื–ืœื ื•, ื™ืฉ ืœื ื• ืžื•ื“ื•ืœ ืžื•ื›ืŸ ืœื ืชื‘ื™ื
ืฆื™ื™ื ืชื™ ืœื’ื‘ื™ AWX, ืื‘ืœ ื”ืคืงื•ื“ื•ืช ืœืžื˜ื” ืขื•ืกืงื•ืช ืจืง ื‘-ansible ื‘ืฆื•ืจืชื• ื”ื˜ื”ื•ืจื” - ืื ื™ ื—ื•ืฉื‘ ืฉืœืžื™ ืฉืขื‘ื“ ืขื ansible, ืœื ื™ื”ื™ื• ื‘ืขื™ื•ืช ื‘ืฉื™ืžื•ืฉ ื‘-awx ื“ืจืš ื”-gui.

ืœืžืขืŸ ื”ืืžืช, ืœืคื ื™ ื–ื” ื”ืกืชื›ืœืชื™ ืขืœ ืžื“ืจื™ื›ื™ื ืื—ืจื™ื ืฉื‘ื”ื ื”ื ื”ืฉืชืžืฉื• ื‘-ssh, ื•ืœื›ื•ืœื ื”ื™ื• ื‘ืขื™ื•ืช ืฉื•ื ื•ืช ืขื ื–ืžืŸ ืชื’ื•ื‘ื” ื•ืขื•ื“ ื”ืžื•ืŸ ื‘ืขื™ื•ืช. ืื ื™ ื—ื•ื–ืจ, ื–ื” ืœื ื”ื’ื™ืข ืœืžืื‘ืง ๏Š, ืงื— ืืช ื”ืžื™ื“ืข ื”ื–ื” ื›ื ื™ืกื•ื™ ืฉืœื ื”ื’ื™ืข ืจื—ื•ืง ื™ื•ืชืจ ืžืขืžื“ื” ืฉืœ 20 ื ืชื‘ื™ื.

ืขืœื™ื ื• ืœื”ืฉืชืžืฉ ื‘ืชืขื•ื“ื” ืื• ื‘ื—ืฉื‘ื•ืŸ. ื–ื” ืชืœื•ื™ ื‘ืš ืœื”ื—ืœื™ื˜, ืื ื™ ื‘ืขื“ ืชืขื•ื“ื•ืช. ืื™ื–ื• ื ืงื•ื“ื” ืขื“ื™ื ื” ืœื’ื‘ื™ ื–ื›ื•ื™ื•ืช. ืื ื™ ื ื•ืชืŸ ื–ื›ื•ื™ื•ืช ื›ืชื™ื‘ื” - ืœืคื—ื•ืช "ืื™ืคื•ืก ืชืฆื•ืจื”" ืœื ื™ืขื‘ื•ื“.

ืœื ืืžื•ืจื•ืช ืœื”ื™ื•ืช ื‘ืขื™ื•ืช ื‘ื”ืคืงื”, ื”ืขืชืงื” ื•ื™ื‘ื•ื ืฉืœ ื”ืื™ืฉื•ืจ:

ืจืฉื™ืžืช ืคืงื•ื“ื•ืช ืงืฆืจื”ื‘ืžื—ืฉื‘ ื”ืื™ืฉื™ ืฉืœืš
ssh-keygen -t RSA, ืขื ื” ืขืœ ืฉืืœื•ืช, ืฉืžื•ืจ ืืช ื”ืžืคืชื—.
ื”ืขืชืง ืœ-mikrotik:
ืžืฉืชืžืฉ ssh-keys ื™ื™ื‘ื•ื โ€‹โ€‹public-key-file=id_mtx.pub user=ansible
ืจืืฉื™ืช ืขืœื™ืš ืœื™ืฆื•ืจ ื—ืฉื‘ื•ืŸ ื•ืœื”ืงืฆื•ืช ืœื• ื–ื›ื•ื™ื•ืช.
ื‘ื“ื™ืงืช ื”ื—ื™ื‘ื•ืจ ื‘ืืžืฆืขื•ืช ื”ืื™ืฉื•ืจ
ssh -p 49475 -i /keys/mtx [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]

ื”ืจืฉืžื” vi /etc/ansible/hosts
MT01 ansible_network_os=routeros ansible_ssh_port=49475 ansible_ssh_user= ansible
MT02 ansible_network_os=routeros ansible_ssh_port=49475 ansible_ssh_user= ansible
MT03 ansible_network_os=routeros ansible_ssh_port=49475 ansible_ssh_user= ansible
MT04 ansible_network_os=routeros ansible_ssh_port=49475 ansible_ssh_user= ansible

ื•ื‘ื›ืŸ, ืกืคืจ ืžืฉื—ืง ืœื“ื•ื’ืžื”: - ืฉื: add_work_sites
ืžืืจื—ื™ื: testmt
ืกื“ืจืชื™: 1
ื—ื™ื‘ื•ืจ: network_cli
ืžืฉืชืžืฉ_ืžืจื•ื—ืง: mikrotik.west
ืœืืกื•ืฃ_ืขื•ื‘ื“ื•ืช: ื›ืŸ
ืžืฉื™ืžื•ืช:
- ืฉื: ื”ื•ืกืฃ ืืชืจื™_ืขื‘ื•ื“ื”
routeros_command:
ืคืงื•ื“ื•ืช:
โ€” ืจืฉื™ืžืช ื›ืชื•ื‘ื•ืช ื—ื•ืžืช ืืฉ /ip add address=gov.ru list=work_sites comment=Ticket665436_Ochen_nado
โ€” ืจืฉื™ืžืช ื›ืชื•ื‘ื•ืช ื—ื•ืžืช ืืฉ /ip add address=habr.com list=work_sites comment=for_habr

ื›ืคื™ ืฉืืชื” ื™ื›ื•ืœ ืœืจืื•ืช ืžื”ืชืฆื•ืจื” ืฉืœืขื™ืœ, ื™ืฆื™ืจืช ืกืคืจื™ ืžืฉื—ืง ืžืฉืœืš ืื™ื ื” ืงืฉื”. ื–ื” ืžืกืคื™ืง ื›ื“ื™ ืœืฉืœื•ื˜ ื”ื™ื˜ื‘ ื‘-cli mikrotik. ื‘ื•ืื• ื ื“ืžื™ื™ืŸ ืžืฆื‘ ืฉื‘ื• ืืชื” ืฆืจื™ืš ืœื”ืกื™ืจ ืืช ืจืฉื™ืžืช ื”ื›ืชื•ื‘ื•ืช ืขื ื ืชื•ื ื™ื ืžืกื•ื™ืžื™ื ื‘ื›ืœ ื”ื ืชื‘ื™ื, ืื–:

ืžืฆื ื•ื”ืกืจ/ip firewal address-list remove [find where list="gov.ru"]

ื‘ื›ื•ื•ื ื” ืœื ื›ืœืœืชื™ ื›ืืŸ ืืช ื›ืœ ืจืฉื™ืžืช ื—ื•ืžืช ื”ืืฉ ื›ื™... ื–ื” ื™ื”ื™ื” ืื™ื ื“ื™ื‘ื™ื“ื•ืืœื™ ืขื‘ื•ืจ ื›ืœ ืคืจื•ื™ืงื˜. ืื‘ืœ ื“ื‘ืจ ืื—ื“ ืื ื™ ื™ื›ื•ืœ ืœื•ืžืจ ื‘ื•ื•ื“ืื•ืช, ื”ืฉืชืžืฉ ืจืง ื‘ืจืฉื™ืžืช ื”ื›ืชื•ื‘ื•ืช.

ืœืคื™ GITLAB ื”ื›ืœ ื‘ืจื•ืจ. ืœื ืืชืขื›ื‘ ืขืœ ื”ื ืงื•ื“ื” ื”ื–ื•. ื”ื›ืœ ื™ืคื” ืœืžืฉื™ืžื•ืช ื‘ื•ื“ื“ื•ืช, ืชื‘ื ื™ื•ืช, ืžื˜ืคืœื™ื.

PowerShell

ื™ื”ื™ื• ื›ืืŸ 3 ืงื‘ืฆื™ื. ืœืžื” Powershell? ืืชื” ื™ื›ื•ืœ ืœื‘ื—ื•ืจ ื›ืœ ื›ืœื™ ืœื™ืฆื™ืจืช ื”ื’ื“ืจื•ืช, ืžื” ืฉื ื•ื— ืœืš ื™ื•ืชืจ. ื‘ืžืงืจื” ื–ื”, ืœื›ื•ืœื ื™ืฉ Windows ื‘ืžื—ืฉื‘ ื”ืื™ืฉื™ ืฉืœื•, ืื– ืœืžื” ืœืขืฉื•ืช ืืช ื–ื” ื‘-bash ื›ืืฉืจ powershell ื ื•ื— ื™ื•ืชืจ. ืื™ื–ื” ืžื”ื ื ื•ื— ื™ื•ืชืจ?

ื”ืชืกืจื™ื˜ ืขืฆืžื• (ืคืฉื•ื˜ ื•ืžื•ื‘ืŸ):[cmdletBinding()] Param(
[Parameter(Mandatory=$true)] [string]$EXTERNALIPADDDRESS,
[Parameter(Mandatory=$true)] [string]$EXTERNALIPROUTE,
[Parameter(Mandatory=$true)] [string]$BWorknets,
[Parameter(Mandatory=$true)] [string]$CWorknets,
[Parameter(Mandatory=$true)] [string]$BVoipNets,
[Parameter(Mandatory=$true)] [string]$CVoipNets,
[Parameter(Mandatory=$true)] [string]$CClientss,
[Parameter(Mandatory=$true)] [string]$BVPNWORKs,
[Parameter(Mandatory=$true)] [string]$CVPNWORKs,
[Parameter(Mandatory=$true)] [string]$BVPNCLIENTSs,
[Parameter(Mandatory=$true)] [string]$cVPNCLIENTSs,
[Parameter(Mandatory=$true)] [ืžื—ืจื•ื–ืช]$NAMEROUTER,
[Parameter(Mandatory=$true)] [string]$ServerCertificates,
[Parameter(Mandatory=$true)] [string]$infile,
[Parameter(Mandatory=$true)] [string]$outfile
)

Get-Content $infile | Foreach-Object {$_.Replace("EXTERNIP", $EXTERNALIPADDRESS)} |
Foreach-Object {$_.Replace("EXTROUTE", $EXTERNALIPROUTE)} |
Foreach-Object {$_.Replace("BWorknet", $BWorknets)} |
Foreach-Object {$_.Replace("CWorknet", $CWorknets)} |
Foreach-Object {$_.Replace("BVoipNet", $BVoipNets)} |
Foreach-Object {$_.Replace("CVoipNet", $CVoipNets)} |
Foreach-Object {$_.Replace("CClients", $CClientss)} |
Foreach-Object {$_.Replace("BVPNWORK", $BVPNWORKs)} |
Foreach-Object {$_.Replace("CVPNWORK", $CVPNWORKs)} |
Foreach-Object {$_.Replace("BVPNCLIENTS", $BVPNCLIENTSs)} |
Foreach-Object {$_.Replace("CVPNCLIENTS", $cVPNCLIENTSs)} |
Foreach-Object {$_.Replace("MYNAMERROUTER", $NAMEROUTER)} |
Foreach-Object {$_.Replace("ServerCertificate", $ServerCertificates)} | Set-Content $outfile

ืื ื ืกืœื— ืœื™, ืื ื™ ืœื ื™ื›ื•ืœ ืœืคืจืกื ืืช ื›ืœ ื”ื—ื•ืงื™ื ื›ื™... ื–ื” ืœื ื™ื”ื™ื” ื™ืคื” ื‘ืžื™ื•ื—ื“. ืืชื” ื™ื›ื•ืœ ืœื”ืžืฆื™ื ืืช ื”ื›ืœืœื™ื ื‘ืขืฆืžืš, ื‘ื”ื ื—ื™ื™ืช ืฉื™ื˜ื•ืช ืขื‘ื•ื“ื” ืžื•ืžืœืฆื•ืช.

ืœื“ื•ื’ืžื”, ื”ื ื” ืจืฉื™ืžื” ืฉืœ ืงื™ืฉื•ืจื™ื ืฉืืœื™ื”ื ื”ืœื›ืชื™:wiki.mikrotik.com/wiki/Manual:ืื‘ื˜ื—ืช_ื”ื ืชื‘_ืฉืœืš
wiki.mikrotik.com/wiki/Manual:IP/ื—ื•ืžืช ืืฉ/ืžืกื ืŸ
wiki.mikrotik.com/wiki/Manual:OSPF-ื“ื•ื’ืžืื•ืช
wiki.mikrotik.com/wiki/Drop_port_scanners
wiki.mikrotik.com/wiki/Manual:Winbox
wiki.mikrotik.com/wiki/Manual:Upgrading_RouterOS
wiki.mikrotik.com/wiki/Manual:IP/Fasttrack - ื›ืืŸ ืืชื” ืฆืจื™ืš ืœื“ืขืช ืฉื›ืืฉืจ fasttrack ืžื•ืคืขืœ, ื›ืœืœื™ ืชืขื“ื•ืฃ ื”ืชืขื‘ื•ืจื” ื•ืขื™ืฆื•ื‘ ืœื ื™ืขื‘ื“ื• - ืฉื™ืžื•ืฉื™ ืขื‘ื•ืจ ืžื›ืฉื™ืจื™ื ื—ืœืฉื™ื.

ืกืžืœื™ื ืœืžืฉืชื ื™ื:ื”ืจืฉืชื•ืช ื”ื‘ืื•ืช ื ืœืงื—ื•ืช ื›ื“ื•ื’ืžื”:
ืจืฉืช ืขื•ื‘ื“ืช 192.168.0.0/24
ืจืฉืช VOIP 172.22.4.0/24
ืจืฉืช 10.0.0.0/24 ืขื‘ื•ืจ ืœืงื•ื—ื•ืช ืœืœื ื’ื™ืฉื” ืœืจืฉืช ื”ืžืงื•ืžื™ืช
192.168.255.0/24 ืจืฉืช VPN ืœืกื ื™ืคื™ื ื’ื“ื•ืœื™ื
172.19.255.0/24 ืจืฉืช VPN ืœืงื˜ื ื™ื

ื›ืชื•ื‘ืช ื”ืจืฉืช ืžื•ืจื›ื‘ืช ืž-4 ืžืกืคืจื™ื ืขืฉืจื•ื ื™ื™ื, ื‘ื”ืชืืžื” ABCD, ื”ื”ื—ืœืคื” ืคื•ืขืœืช ืขืœ ืื•ืชื• ืขื™ืงืจื•ืŸ, ืื ื‘ื”ืคืขืœื” ื”ื™ื ืžื‘ืงืฉืช B, ืื– ื–ื” ืื•ืžืจ ืฉืืชื” ืฆืจื™ืš ืœื”ื–ื™ืŸ ืืช ื”ืžืกืคืจ 192.168.0.0 ืขื‘ื•ืจ ื”ืจืฉืช 24/0, ื•ืขื‘ื•ืจ C = 0.
$EXTERNALIPADDDRESS - ื›ืชื•ื‘ืช ื™ื™ืขื•ื“ื™ืช ืžื”ืกืคืง.
$EXTERNALIPROUTE - ืžืกืœื•ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ ืœืจืฉืช 0.0.0.0/0
$BWorknets - ืจืฉืช ืขื‘ื•ื“ื”, ื‘ื“ื•ื’ืžื” ืฉืœื ื• ื™ื”ื™ื• 168
$CWorknets - ืจืฉืช ืขื•ื‘ื“ืช, ื‘ื“ื•ื’ืžื” ืฉืœื ื• ื–ื” ื™ื”ื™ื” 0
$BVoipNets - ืจืฉืช VOIP ื‘ื“ื•ื’ืžื” ืฉืœื ื• ื›ืืŸ 22
$CVoipNets - ืจืฉืช VOIP ื‘ื“ื•ื’ืžื” ืฉืœื ื• ื›ืืŸ 4
$CClientss - ืจืฉืช ืœืœืงื•ื—ื•ืช - ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ื‘ืœื‘ื“, ื‘ืžืงืจื” ืฉืœื ื• ื›ืืŸ 0
$BVPNWORKs - ืจืฉืช VPN ืœืกื ื™ืคื™ื ื’ื“ื•ืœื™ื, ื‘ื“ื•ื’ืžื” ืฉืœื ื• 20
$CVPNWORKs - ืจืฉืช VPN ืœืกื ื™ืคื™ื ื’ื“ื•ืœื™ื, ื‘ื“ื•ื’ืžื” ืฉืœื ื• 255
$BVPNCLIENTS - ืจืฉืช VPN ืœืกื ื™ืคื™ื ืงื˜ื ื™ื, ื›ืœื•ืžืจ 19
$CVPNCLIENTS - ืจืฉืช VPN ืœืกื ื™ืคื™ื ืงื˜ื ื™ื, ื›ืœื•ืžืจ 255
$NAMEROUTER - ืฉื ื”ื ืชื‘
$ServerCertificate - ืฉื ื”ืื™ืฉื•ืจ ืฉื™ื™ื‘ืืช ื‘ืขื‘ืจ
$infile โ€” ืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ืœืงื•ื‘ืฅ ืฉืžืžื ื• ื ืงืจื ืืช ื”ืชืฆื•ืจื”, ืœืžืฉืœ D:config.txt (ืจืฆื•ื™ ื”ื ืชื™ื‘ ื‘ืื ื’ืœื™ืช ืœืœื ืžืจื›ืื•ืช ื•ืจื•ื•ื—ื™ื)
$outfile โ€” ืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ืฉื‘ื• ืœืฉืžื•ืจ ืื•ืชื•, ืœืžืฉืœ D:MT-test.txt

ืฉื™ื ื™ืชื™ ื‘ื›ื•ื•ื ื” ืืช ื”ื›ืชื•ื‘ื•ืช ื‘ื“ื•ื’ืžืื•ืช ืžืกื™ื‘ื•ืช ื‘ืจื•ืจื•ืช.

ืคืกืคืกืชื™ ืืช ื”ื ืงื•ื“ื” ืœื’ื‘ื™ ื–ื™ื”ื•ื™ ื”ืชืงืคื•ืช ื•ื”ืชื ื”ื’ื•ืช ื—ืจื™ื’ื” - ื–ื” ืจืื•ื™ ืœื›ืชื‘ื” ื ืคืจื“ืช. ืื‘ืœ ื›ื“ืื™ ืœืฆื™ื™ืŸ ืฉื‘ืงื˜ื’ื•ืจื™ื” ื–ื• ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืขืจื›ื™ ื ื™ื˜ื•ืจ ืฉืœ ื ืชื•ื ื™ Zabbix + ื ืชื•ื ื™ ืชืœืชืœื™ื ืžืขื•ื‘ื“ื™ื ืž- elasticsearch.

ืœืื™ืœื• ื ืงื•ื“ื•ืช ื›ื“ืื™ ืœืฉื™ื ืœื‘:

  1. ืชื•ื›ื ื™ืช ืจืฉืช. ืขื“ื™ืฃ ืœื—ื‘ืจ ืื•ืชื• ืžื™ื“ ื‘ืฆื•ืจื” ืงืจื™ืื”. ืืงืกืœ ื™ืกืคื™ืง. ืœืฆืขืจื™, ืื ื™ ืจื•ืื” ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืžืื•ื“ ืฉืจืฉืชื•ืช ื‘ื ื•ื™ื•ืช ืœืคื™ ื”ืขื™ืงืจื•ืŸ "ื”ื•ืคื™ืข ืกื ื™ืฃ ื—ื“ืฉ, ื”ื ื” /24 ื‘ืฉื‘ื™ืœืš." ืืฃ ืื—ื“ ืœื ืžื‘ื™ืŸ ื›ืžื” ืžื›ืฉื™ืจื™ื ืฆืคื•ื™ื™ื ื‘ืžื™ืงื•ื ื ืชื•ืŸ ืื• ืื ืชื”ื™ื” ืฆืžื™ื—ื” ื ื•ืกืคืช. ืœืžืฉืœ, ื ืคืชื—ื” ื—ื ื•ืช ืงื˜ื ื” ื‘ื” ื”ื™ื” ื‘ืจื•ืจ ื‘ื”ืชื—ืœื” ืฉื”ืžื›ืฉื™ืจ ืœื ื™ื”ื™ื” ื™ื•ืชืจ ืž-10, ืœืžื” ืœื”ืงืฆื•ืช /24? ืœืกื ื™ืคื™ื ื’ื“ื•ืœื™ื, ืœื”ื™ืคืš, ื”ื ืžืงืฆื™ื /24, ื•ื™ืฉ 500 ืžื›ืฉื™ืจื™ื - ืืชื” ื™ื›ื•ืœ ืคืฉื•ื˜ ืœื”ื•ืกื™ืฃ ืจืฉืช, ืื‘ืœ ืืชื” ืจื•ืฆื” ืœื—ืฉื•ื‘ ืขืœ ื”ื›ืœ ื‘ื‘ืช ืื—ืช.
  2. ื›ืœืœื™ ืกื™ื ื•ืŸ. ืื ื”ืคืจื•ื™ืงื˜ ื™ื ื™ื— ืฉืชื”ื™ื” ื”ืคืจื“ืช ืจืฉืชื•ืช ื•ืคื™ืœื•ื— ืžืงืกื™ืžืœื™. ืฉื™ื˜ื•ืช ืขื‘ื•ื“ื” ืžื•ืžืœืฆื•ืช ืžืฉืชื ื•ืช ืขื ื”ื–ืžืŸ. ื‘ืขื‘ืจ, ืจืฉืช PC ื•ืจืฉืช ืžื“ืคืกื•ืช ื”ื™ื• ืžื—ื•ืœืงื•ืช, ืื‘ืœ ืขื›ืฉื™ื• ื–ื” ื“ื™ ื ื•ืจืžืœื™ ืœื ืœื—ืœืง ืืช ื”ืจืฉืชื•ืช ื”ืœืœื•. ื›ื“ืื™ ืœื”ืฉืชืžืฉ ื‘ืฉื›ืœ ื”ื™ืฉืจ ื•ืœื ืœื™ืฆื•ืจ ืจืฉืชื•ืช ืžืฉื ื” ืจื‘ื•ืช ืฉื‘ื”ืŸ ืื™ืŸ ืฆื•ืจืš ื•ืœื ืœืฉืœื‘ ืืช ื›ืœ ื”ืžื›ืฉื™ืจื™ื ืœืจืฉืช ืื—ืช.
  3. ื”ื’ื“ืจื•ืช "ื–ื”ื•ื‘" ื‘ื›ืœ ื”ื ืชื‘ื™ื. ื”ึธื”ึตืŸ. ืื ื”ื—ืœื˜ืช ืขืœ ืชื•ื›ื ื™ืช. ื›ื“ืื™ ืœื—ื–ื•ืช ื”ื›ืœ ืžื™ื“ ื•ืœื ืกื•ืช ืœื•ื•ื“ื ืฉื›ืœ ื”ื”ื’ื“ืจื•ืช ื–ื”ื•ืช - ืจืง ืจืฉื™ืžืช ื”ื›ืชื•ื‘ื•ืช ื•ื›ืชื•ื‘ื•ืช ื”-IP ืฉื•ื ื•ืช. ืื ืžืชืขื•ืจืจื•ืช ื‘ืขื™ื•ืช, ื–ืžืŸ ืื™ืชื•ืจ ื”ื‘ืื’ื™ื ื™ื”ื™ื” ืงืฆืจ ื™ื•ืชืจ.
  4. ื ื•ืฉืื™ื ืืจื’ื•ื ื™ื™ื ื—ืฉื•ื‘ื™ื ืœื ืคื—ื•ืช ืžืืœื• ื”ื˜ื›ื ื™ื™ื. ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืขื•ื‘ื“ื™ื ืขืฆืœื ื™ื ืžื‘ืฆืขื™ื ืืช ื”ื”ืžืœืฆื•ืช ื”ืœืœื• "ื™ื“ื ื™ืช", ืžื‘ืœื™ ืœื”ืฉืชืžืฉ ื‘ืชืฆื•ืจื•ืช ื•ืชืกืจื™ื˜ื™ื ืžื•ื›ื ื™ื, ืžื” ืฉื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ ืžื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ืžืฉื•ื ืžืงื•ื.

ืขืœ ื™ื“ื™ ื ื™ืชื•ื‘ ื“ื™ื ืžื™. ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-OSPF ืขื ื—ืœื•ืงืช ืื–ื•ืจื™ื. ืื‘ืœ ื–ื” ืกืคืกืœ ืžื‘ื—ืŸ; ื™ื•ืชืจ ืžืขื ื™ื™ืŸ ืœื”ืงื™ื ื“ื‘ืจื™ื ื›ืืœื” ื‘ืชื ืื™ ืœื—ื™ืžื”.

ืื ื™ ืžืงื•ื•ื” ืฉืืฃ ืื—ื“ ืœื ื›ื•ืขืก ืฉืœื ืคืจืกืžืชื™ ืืช ืชืฆื•ืจื•ืช ื”ื ืชื‘. ืื ื™ ื—ื•ืฉื‘ ืฉื”ืงื™ืฉื•ืจื™ื ื™ืกืคื™ืงื•, ื•ืื– ื”ื›ืœ ืชืœื•ื™ ื‘ื“ืจื™ืฉื•ืช. ื•ื›ืžื•ื‘ืŸ ื‘ื“ื™ืงื•ืช, ื™ืฉ ืฆื•ืจืš ื‘ื‘ื“ื™ืงื•ืช ื ื•ืกืคื•ืช.

ืื ื™ ืžืื—ืœ ืœื›ื•ืœื ืœื”ื’ืฉื™ื ืืช ื”ืคืจื•ื™ืงื˜ื™ื ืฉืœื”ื ื‘ืฉื ื” ื”ื—ื“ืฉื”. ืžื™ ื™ืชืŸ ื•ื”ื’ื™ืฉื” ืฉื ื™ืชื ื” ืชื”ื™ื” ืื™ืชืš!!!

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”