ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ืžื” ืœืขืฉื•ืช ืื ื›ื•ื—ื• ืฉืœ ืฉืจืช ืื—ื“ ืื™ื ื• ืžืกืคื™ืง ืœืขื™ื‘ื•ื“ ื›ืœ ื”ื‘ืงืฉื•ืช, ื•ื™ืฆืจืŸ ื”ืชื•ื›ื ื” ืื™ื ื• ืžืกืคืง ืื™ื–ื•ืŸ ืขื•ืžืกื™ื? ื™ืฉื ืŸ ืืคืฉืจื•ื™ื•ืช ืจื‘ื•ืช, ื”ื—ืœ ืžืจื›ื™ืฉืช ืžืื–ืŸ ืขื•ืžืกื™ื ื•ืขื“ ื”ื’ื‘ืœืช ืžืกืคืจ ื”ื‘ืงืฉื•ืช. ืžื™ ืžื”ื ื ื›ื•ืŸ ื—ื™ื™ื‘ ืœื”ื™ืงื‘ืข ืœืคื™ ื”ืžืฆื‘, ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ืชื ืื™ื ื”ืงื™ื™ืžื™ื. ื‘ืžืืžืจ ื–ื” ื ืกืคืจ ืœื›ื ืžื” ืชื•ื›ืœื• ืœืขืฉื•ืช ืื ื”ืชืงืฆื™ื‘ ืฉืœื›ื ืžื•ื’ื‘ืœ ื•ื™ืฉ ืœื›ื ืฉืจืช ื—ื™ื ืžื™.

ื›ืžืขืจื›ืช ืฉืขื‘ื•ืจื” ื”ื™ื” ืฆื•ืจืš ืœื”ืคื—ื™ืช ืืช ื”ืขื•ืžืก ืขืœ ืื—ื“ ื”ืฉืจืชื™ื, ื‘ื—ืจื ื• ื‘-DLP (ืžืขืจื›ืช ืœืžื ื™ืขืช ื“ืœื™ืคืช ืžื™ื“ืข) ืžื‘ื™ืช InfoWatch. ืžืืคื™ื™ืŸ ืฉืœ ื”ื™ื™ืฉื•ื ื”ื™ื” ืžื™ืงื•ื ืคื•ื ืงืฆื™ื™ืช ื”ืื™ื–ื•ืŸ ื‘ืื—ื“ ืžืฉืจืชื™ ื”"ืงืจื‘".

ืื—ืช ื”ื‘ืขื™ื•ืช ืฉื ืชืงืœื ื• ื‘ื”ืŸ ื”ื™ื™ืชื” ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžืงื•ืจ NAT (SNAT). ืžื“ื•ืข ื”ื™ื” ืฆื•ืจืš ื‘ื›ืš ื•ื›ื™ืฆื“ ื ืคืชืจื” ื”ื‘ืขื™ื”, ื ืชืืจ ื‘ื”ืžืฉืš.

ืื– ื‘ืชื—ื™ืœื” ื”ืชืจืฉื™ื ื”ืœื•ื’ื™ ืฉืœ ื”ืžืขืจื›ืช ื”ืงื™ื™ืžืช ื ืจืื” ื›ืš:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ืชืขื‘ื•ืจืช ICAP, SMTP, ืื™ืจื•ืขื™ื ืžืžื—ืฉื‘ื™ ืžืฉืชืžืฉ ืขื•ื‘ื“ื• ื‘ืฉืจืช Traffic Monitor (TM). ื™ื—ื“ ืขื ื–ืืช, ืฉืจืช ืžืกื“ ื”ื ืชื•ื ื™ื ื”ืชืžื•ื“ื“ ื‘ืงืœื•ืช ืขื ื”ืขื•ืžืก ืœืื—ืจ ืขื™ื‘ื•ื“ ืื™ืจื•ืขื™ื ื‘-TM, ืืš ื”ืขื•ืžืก ืขืœ ื”-TM ืขืฆืžื• ื”ื™ื” ื›ื‘ื“. ื–ื” ื”ื™ื” ื‘ืจื•ืจ ืžื”ื•ืคืขืช ืชื•ืจ ื”ื•ื“ืขื•ืช ื‘ืฉืจืช Device Monitor (DM), ื›ืžื• ื’ื ืžืขื•ืžืก ื”ืžืขื‘ื“ ื•ื”ื–ื™ื›ืจื•ืŸ ื‘-TM.

ื‘ืžื‘ื˜ ืจืืฉื•ืŸ, ืื ื ื•ืกื™ืฃ ืฉืจืช TM ื ื•ืกืฃ ืœืกื›ื™ืžื” ื–ื•, ื ื™ืชืŸ ื™ื”ื™ื” ืœื”ื—ืœื™ืฃ ืืœื™ื• ICAP ืื• DM, ืืš ื”ื—ืœื˜ื ื• ืœื ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ื” ื–ื•, ืžื›ื™ื•ื•ืŸ ืฉืกื•ื‘ืœื ื•ืช ื”ืชืงืœื•ืช ื”ื•ืคื—ืชื”.

ืชื™ืื•ืจ ื”ืคืชืจื•ืŸ

ื‘ืชื”ืœื™ืš ื—ื™ืคื•ืฉ ืื—ืจ ืคืชืจื•ืŸ ืžืชืื™ื, ื”ืกืชืคืงื ื• ื‘ืชื•ื›ื ื” ื”ืžื•ืคืฆืช ื‘ื—ื•ืคืฉื™ื•ืช ื›ืœ ื”ื–ืžืŸ ืขื LVS. ื›ื™ Keepalived ืคื•ืชืจ ืืช ื”ื‘ืขื™ื” ืฉืœ ื™ืฆื™ืจืช ืืฉื›ื•ืœ failover ื•ื™ื›ื•ืœ ื’ื ืœื ื”ืœ ืืช ืื™ื–ื•ืŸ LVS.

ืžื” ืฉืจืฆื™ื ื• ืœื”ืฉื™ื’ (ืœื”ืคื—ื™ืช ืืช ื”ืขื•ืžืก ืขืœ TM ื•ืœืฉืžื•ืจ ืขืœ ื”ืจืžื” ื”ื ื•ื›ื—ื™ืช ืฉืœ ืกื•ื‘ืœื ื•ืช ืชืงืœื•ืช) ื”ื™ื” ืฆืจื™ืš ืœืขื‘ื•ื“ ืœืคื™ ื”ืชื•ื›ื ื™ืช ื”ื‘ืื”:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื›ืฉื‘ื“ืงื• ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช, ื”ืชื‘ืจืจ ืฉืžื›ืœื•ืœ RedHat ื”ืžื•ืชืื ืื™ืฉื™ืช ื”ืžื•ืชืงืŸ ืขืœ ื”ืฉืจืชื™ื ืื™ื ื• ืชื•ืžืš ื‘-SNAT. ื‘ืžืงืจื” ืฉืœื ื•, ืชื›ื ื ื• ืœื”ืฉืชืžืฉ ื‘-SNAT ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉืžื ื•ืช ื ื›ื ืกื•ืช ื•ืชื’ื•ื‘ื•ืช ืืœื™ื”ืŸ ื™ื™ืฉืœื—ื• ืžืื•ืชื” ื›ืชื•ื‘ืช IP, ืื—ืจืช ื ืงื‘ืœ ืืช ื”ืชืžื•ื ื” ื”ื‘ืื”:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื–ื” ืœื ืžืงื•ื‘ืœ. ืœื“ื•ื’ืžื”, ืฉืจืช ืคืจื•ืงืกื™, ืœืื—ืจ ืฉืฉืœื— ืžื ื•ืช ืœื›ืชื•ื‘ืช IP ื•ื™ืจื˜ื•ืืœื™ืช (VIP), ื™ืฆืคื” ืœืชื’ื•ื‘ื” ืž-VIP, ืืš ื‘ืžืงืจื” ื–ื” ื”ื™ื ืชื’ื™ืข ืž-IP2 ืขื‘ื•ืจ ื”ืคืขืœื•ืช ืฉื ืฉืœื—ื•ืช ืœื’ื™ื‘ื•ื™. ื ืžืฆื ืคืชืจื•ืŸ: ื”ื™ื” ืฆื•ืจืš ืœื™ืฆื•ืจ ื˜ื‘ืœืช ื ื™ืชื•ื‘ ื ื•ืกืคืช ื‘ื’ื™ื‘ื•ื™ ื•ืœื—ื‘ืจ ืฉื ื™ ืฉืจืชื™ TM ืขื ืจืฉืช ื ืคืจื“ืช, ื›ืคื™ ืฉืžื•ืฆื’ ืœื”ืœืŸ:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื”ื’ื“ืจื•ืช

ื ื™ื™ืฉื ืกื›ืžื” ืฉืœ ืฉื ื™ ืฉืจืชื™ื ืขื ืฉื™ืจื•ืชื™ ICAP, SMTP, TCP 9100 ื•ืžืื–ืŸ ืขื•ืžืกื™ื ืžื•ืชืงืŸ ืขืœ ืื—ื“ ืžื”ื.

ื™ืฉ ืœื ื• ืฉื ื™ ืฉืจืชื™ RHEL6, ืฉืžื”ื ื”ื•ืกืจื• ื”ืžืื’ืจื™ื ื”ืกื˜ื ื“ืจื˜ื™ื™ื ื•ื›ืžื” ื—ื‘ื™ืœื•ืช.

ืฉื™ืจื•ืชื™ื ืฉืื ื• ืฆืจื™ื›ื™ื ืœืื–ืŸ:

โ€ข ICAP โ€“ tcp 1344;

โ€ข SMTP โ€“ tcp 25.

ืฉื™ืจื•ืช ื”ืขื‘ืจืช ืชื ื•ืขื” ืž-DM โ€“ tcp 9100.

ืจืืฉื™ืช, ืขืœื™ื ื• ืœืชื›ื ืŸ ืืช ื”ืจืฉืช.

ื›ืชื•ื‘ืช IP ื•ื™ืจื˜ื•ืืœื™ืช (VIP):

โ€ข IP: 10.20.20.105.

ืฉืจืช TM6_1:

โ€ข IP ื—ื™ืฆื•ื ื™: 10.20.20.101;

โ€ข IP ืคื ื™ืžื™: 192.168.1.101.

ืฉืจืช TM6_2:

โ€ข IP ื—ื™ืฆื•ื ื™: 10.20.20.102;

โ€ข IP ืคื ื™ืžื™: 192.168.1.102.

ืœืื—ืจ ืžื›ืŸ ืื ื• ืžืืคืฉืจื™ื ื”ืขื‘ืจืช IP ื‘ืฉื ื™ ืฉืจืชื™ TM. ื›ื™ืฆื“ ืœืขืฉื•ืช ื–ืืช ืžืชื•ืืจ ื‘-RedHat ื›ืืŸ.

ืื ื—ื ื• ืžื—ืœื™ื˜ื™ื ืื™ื–ื” ืžื”ืฉืจืชื™ื ื™ื”ื™ื• ืœื ื• ื”ื•ื ื”ืจืืฉื™ ื•ืื™ื–ื” ืžื”ืฉืจืชื™ื ื™ื”ื™ื” ื”ื’ื™ื‘ื•ื™. ืชืŸ ืœืžืืกื˜ืจ ืœื”ื™ื•ืช TM6_1, ื”ื’ื™ื‘ื•ื™ ื™ื”ื™ื” TM6_2.

ื‘ื’ื™ื‘ื•ื™ ืื ื• ื™ื•ืฆืจื™ื ื˜ื‘ืœืช ื ื™ืชื•ื‘ ื—ื“ืฉื” ืฉืœ ืื™ื–ื•ืŸ ื•ื›ืœืœื™ ื ื™ืชื•ื‘:

[root@tm6_2 ~]echo 101 balancer >> /etc/iproute2/rt_tables
[root@tm6_2 ~]ip rule add from 192.168.1.102 table balancer
[root@tm6_2 ~]ip route add default via 192.168.1.101 table balancer

ื”ืคืงื•ื“ื•ืช ืฉืœืขื™ืœ ืคื•ืขืœื•ืช ืขื“ ืฉื”ืžืขืจื›ืช ืžื•ืคืขืœืช ืžื—ื“ืฉ. ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉื”ืžืกืœื•ืœื™ื ื™ื™ืฉืžืจื• ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ, ืชื•ื›ืœ ืœื”ื–ื™ืŸ ืื•ืชื /etc/rc.d/rc.local, ืื‘ืœ ืขื“ื™ืฃ ื“ืจืš ืงื•ื‘ืฅ ื”ื”ื’ื“ืจื•ืช /etc/sysconfig/network-scripts/route-eth1 (ื”ืขืจื”: ื›ืืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืชื—ื‘ื™ืจ ืฉื•ื ื”).

ื”ืชืงืŸ ืืช Keepalive ื‘ืฉื ื™ ืฉืจืชื™ ื”-TM. ื”ืฉืชืžืฉื ื• ื‘-rpmfind.net ื›ืžืงื•ืจ ื”ื”ืคืฆื”:

[root@tm6_1 ~]#yum install https://rpmfind.net/linux/centos/6.10/os/x86_64/Packages/keepalived-1.2.13-5.el6_6.x86_64.rpm

ื‘ื”ื’ื“ืจื•ืช Keepalive, ืื ื• ืžืงืฆื™ื ืืช ืื—ื“ ื”ืฉืจืชื™ื ื›ืžืืกื˜ืจ, ืืช ื”ืฉื ื™ ื›ื’ื™ื‘ื•ื™. ืœืื—ืจ ืžื›ืŸ ื”ื’ื“ืจื ื• VIP ื•ืฉื™ืจื•ืชื™ื ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื. ืงื•ื‘ืฅ ื”ื”ื’ื“ืจื•ืช ื ืžืฆื ื‘ื“ืจืš ื›ืœืœ ื›ืืŸ: /etc/keepalived/keepalived.conf.

ื”ื’ื“ืจื•ืช ืขื‘ื•ืจ TM1 Server

vrrp_sync_group VG1 { 
   group { 
      VI_1 
   } 
} 
vrrp_instance VI_1 { 
        state MASTER 
        interface eth0 

        lvs_sync_daemon_inteface eth0 
        virtual_router_id 51 
        priority 151 
        advert_int 1 
        authentication { 
                auth_type PASS 
                auth_pass example 
        } 

        virtual_ipaddress { 
                10.20.20.105 
        } 
}

virtual_server 10.20.20.105 1344 {
    delay_loop 6
    lb_algo wrr 
    lb_kind NAT
    protocol TCP

    real_server 192.168.1.101 1344 {
        weight 1
        TCP_CHECK { 
                connect_timeout 3 
            connect_port 1344
        nb_get_retry 3
        delay_before_retry 3
        }
    }

    real_server 192.168.1.102 1344 {
        weight 1
        TCP_CHECK { 
                connect_timeout 3 
            connect_port 1344
        nb_get_retry 3
        delay_before_retry 3
        }
    }
}

virtual_server 10.20.20.105 25 {
    delay_loop 6
    lb_algo wrr 
    lb_kind NAT
    protocol TCP

    real_server 192.168.1.101 25 {
        weight 1
        TCP_CHECK { 
                connect_timeout 3 
            connect_port 25
        nb_get_retry 3
        delay_before_retry 3
        }
    }

    real_server 192.168.1.102 25 {
        weight 1
        TCP_CHECK { 
                connect_timeout 3 
            connect_port 25
        nb_get_retry 3
        delay_before_retry 3
        }
    }
}

virtual_server 10.20.20.105 9100 {
    delay_loop 6
    lb_algo wrr 
    lb_kind NAT
    protocol TCP

    real_server 192.168.1.101 9100 {
        weight 1
        TCP_CHECK { 
                connect_timeout 3 
            connect_port 9100
        nb_get_retry 3
        delay_before_retry 3
        }
    }

    real_server 192.168.1.102 9100 {
        weight 1
        TCP_CHECK { 
                connect_timeout 3 
            connect_port 9100
        nb_get_retry 3
        delay_before_retry 3
        }
    }
}

ื”ื’ื“ืจื•ืช ืขื‘ื•ืจ TM2 Server

vrrp_sync_group VG1 { 
   group { 
      VI_1 
   } 
} 
vrrp_instance VI_1 { 
        state BACKUP 
        interface eth0 

        lvs_sync_daemon_inteface eth0 
        virtual_router_id 51 
        priority 100 
        advert_int 1 
        authentication { 
                auth_type PASS 
                auth_pass example 
        } 

        virtual_ipaddress { 
                10.20.20.105 
        } 
}

ืื ื• ืžืชืงื™ื ื™ื LVS ืขืœ ื”ืžืืกื˜ืจ, ืฉื™ืื–ืŸ ืืช ื”ืชืขื‘ื•ืจื”. ื–ื” ืœื ื”ื’ื™ื•ื ื™ ืœื”ืชืงื™ืŸ ืื™ื–ื•ืŸ ืขื‘ื•ืจ ื”ืฉืจืช ื”ืฉื ื™, ืžื›ื™ื•ื•ืŸ ืฉื™ืฉ ืœื ื• ืจืง ืฉื ื™ ืฉืจืชื™ื ื‘ืชืฆื•ืจื”.

[root@tm6_1 ~]##yum install https://rpmfind.net/linux/centos/6.10/os/x86_64/Packages/ipvsadm-1.26-4.el6.x86_64.rpm

ื”ืื™ื–ื•ืŸ ื™ื ื•ื”ืœ ืขืœ ื™ื“ื™ keepalved, ืฉื›ื‘ืจ ื”ื’ื“ืจื ื•.

ื›ื“ื™ ืœื”ืฉืœื™ื ืืช ื”ืชืžื•ื ื”, ื‘ื•ืื• ื ื•ืกื™ืฃ Keepalved ืœื”ืคืขืœื” ืื•ื˜ื•ืžื˜ื™ืช ื‘ืฉื ื™ ื”ืฉืจืชื™ื:

[root@tm6_1 ~]#chkconfig keepalived on

ืžืกืงื ื”

ื‘ื•ื“ืง ืืช ื”ืชื•ืฆืื•ืช

ื‘ื•ืื• ื ืจื™ืฅ Keepalive ื‘ืฉื ื™ ื”ืฉืจืชื™ื:

service keepalived start

ื‘ื“ื™ืงืช ื”ื–ืžื™ื ื•ืช ืฉืœ ื›ืชื•ื‘ืช ื•ื™ืจื˜ื•ืืœื™ืช VRRP

ื‘ื•ืื• ื ื•ื•ื“ื ืฉื”-VIP ื ืžืฆื ื‘ืžืืกื˜ืจ:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื•ืื™ืŸ VIP ื‘ื’ื™ื‘ื•ื™:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื‘ืืžืฆืขื•ืช ืคืงื•ื“ืช ping, ื ื‘ื“ื•ืง ืืช ื–ืžื™ื ื•ืช ื”-VIP:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื›ืขืช ืืชื” ื™ื›ื•ืœ ืœื›ื‘ื•ืช ืืช ืžืืกื˜ืจ ื•ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” ืฉื•ื‘ ping.

ื”ืชื•ืฆืื” ืฆืจื™ื›ื” ืœื”ื™ืฉืืจ ื–ื”ื”, ื•ื‘ื’ื™ื‘ื•ื™ ื ืจืื” VIP:

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ื‘ื“ื™ืงืช ืื™ื–ื•ืŸ ืฉื™ืจื•ืช

ื ื™ืงื— ืœื“ื•ื’ืžื SMTP. ื‘ื•ืื• ื ืฉื™ืง ืฉื ื™ ื—ื™ื‘ื•ืจื™ื ืœ-10.20.20.105 ื‘ื• ื–ืžื ื™ืช:

telnet 10.20.20.105 25

ื‘-master ืื ื—ื ื• ืืžื•ืจื™ื ืœืจืื•ืช ืฉืฉื ื™ ื”ื—ื™ื‘ื•ืจื™ื ืคืขื™ืœื™ื ื•ืžื—ื•ื‘ืจื™ื ืœืฉืจืชื™ื ืฉื•ื ื™ื:

[root@tm6_1 ~]#watch ipvsadm โ€“Ln

ื”ื’ื“ืจืช ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘-InfoWatch Traffic Monitor

ืœืคื™ื›ืš, ื”ื˜ืžืขื ื• ืชืฆื•ืจื” ืกื•ื‘ืœื ื™ืช ืœืชืงืœื•ืช ืฉืœ ืฉื™ืจื•ืชื™ TM ืขืœ ื™ื“ื™ ื”ืชืงื ืช ืื™ื–ื•ืŸ ื‘ืื—ื“ ืžืฉืจืชื™ ื”-TM. ืขื‘ื•ืจ ื”ืžืขืจื›ืช ืฉืœื ื•, ื–ื” ื”ืคื—ื™ืช ืืช ื”ืขื•ืžืก ืขืœ TM ื‘ื—ืฆื™, ืžื” ืฉืืคืฉืจ ืœืคืชื•ืจ ืืช ื‘ืขื™ื™ืช ื”ื™ืขื“ืจ ืงื ื” ืžื™ื“ื” ืื•ืคืงื™ ื‘ืืžืฆืขื•ืช ื”ืžืขืจื›ืช.

ื‘ืจื•ื‘ ื”ืžืงืจื™ื ืคืชืจื•ืŸ ื–ื” ืžื™ื•ืฉื ื‘ืžื”ื™ืจื•ืช ื•ืœืœื ืขืœื•ื™ื•ืช ื ื•ืกืคื•ืช, ืืš ืœืขื™ืชื™ื ื™ืฉื ืŸ ืžืกืคืจ ืžื’ื‘ืœื•ืช ื•ืงืฉื™ื™ื ื‘ืชืฆื•ืจื”, ืœืžืฉืœ ื‘ืขืช ืื™ื–ื•ืŸ ืชืขื‘ื•ืจืช UDP.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”