Nhanganyaya
Kugadzirisa zvivakwa zvehofisi uye kuendesa nzvimbo nyowani dzekushandira idambudziko rakakura kumakambani emarudzi ese nemasaizi. Sarudzo yakanakisa yepurojekiti nyowani kuhaya zviwanikwa mugore uye kutenga marezinesi anogona kushandiswa zvese kubva kune anopa uye mune yako wega data data. Imwe mhinduro yechiitiko ichi ndeye , iyo inokutendera iwe kuti ugadzire chikuva chekubatana uye kutaurirana kwemakambani ebhizinesi mune yegore nharaunda uye pane yayo pachayo.

Mhinduro iyi yakagadzirirwa mahofisi ehukuru hwese uye ine zviitiko zviviri zvikuru zvekuisa: seti yeseva imwe chete inosvika mabhokisi etsamba anosvika 3000 uye zvinodiwa zvekushivirira zvikanganiso zvishoma, nepo seti yemaseva akawanda ichitsigira mashandiro akavimbika uye anopindura emakumi kana mazana ezviuru emabhokisi etsamba. Muzviitiko zvese, mushandisi anowana tsamba, magwaro, uye mameseji kuburikidza newebhu imwe chete kubva padesktop inoshandisa chero sisitimu yekushandisa, pasina kuisa kana kugadzirisa software yekuwedzera, kana kuburikidza nemapurogiramu enharembozha e iOS ne AndroidUnogona kushandisa macustomer anozivikanwa eOutlook neThunderbird.
Kuendesa chirongwa ichi, Zextras shamwari - yakasarudza Yandex.Cloud nekuti mavakirwo ayo akafanana neAWS uye inotsigira S3 inowirirana chengetedzo, iyo inoderedza mutengo wekuchengetedza mavhoriyamu makuru etsamba, mameseji uye zvinyorwa uye kuwedzera kukanganisa kushivirira kwemhinduro.
Munzvimbo yeYandex.Cloud, maturusi ekutanga emuchina wekushandisa anoshandiswa kuisa imwe-server uye virtual network manejimendi kugona . Kune akawanda-server kuisirwa, kuwedzera kune yakatsanangurwa maturusi, zvinodikanwa kushandisa matekinoroji , kana zvichidikanwa (zvichienderana nehuwandu hwehurongwa) - zvakare , uye network balancer .
S3-inoenderana chinhu kuchengetedza inogona kushandiswa mune ese maviri ekuisa sarudzo, uye zvakare inogona kubatanidzwa kune masisitimu akaiswa pane-nzvimbo kune inodhura-inoshanda uye kukanganisa-kushivirira kuchengetedza mail server data muYandex.Cloud.
Kuisirwa-sevha-sevha, zvichienderana nehuwandu hwevashandisi uye / kana mabhokisi etsamba, zvinotevera zvinodikanwa: kune iyo huru server 4-12 vCPU, 8-64 GB vRAM (yakatarwa vCPU uye vRAM kukosha zvinoenderana nehuwandu hwemabhokisi etsamba uye mutoro chaiwo), ingangoita 80 GB yedhisiki nzvimbo yeanoshanda system uye maapplication, madhisiki ekuwedzera, dhisiki nzvimbo, nezvimwewo. zvichienderana nenhamba uye avhareji saizi yemabhokisi eemail uye ayo anogona kuchinja zvine simba panguva yekushanda kwehurongwa; kune anobatsira maDocs maseva: 2-4 vCPU, 2-16 GB vRAM, 16 GB yedhisiki nzvimbo (yakatarwa zviwanikwa kukosha uye huwandu hwemaseva zvinoenderana nemutoro chaiwo); a TURN/STUN server inogonawo kudiwa (zvainoda sevhavha yakaparadzana uye zviwanikwa zvinoenderana nemutoro chaiwo). Nekumisikidzwa kwema-multi-server, iyo nhamba uye chinangwa chebasa chairo muchina uye zviwanikwa zvakapihwa kwavari zvinotemerwa mumwe nemumwe zvichienderana nezvinodiwa nemushandisi.
Chinangwa chechinyorwa
Tsanangudzo yekutumirwa muYandex.Cloud nharaunda yeZextras Suite zvigadzirwa zvichibva paZimbra mail server mune imwe-server yekumisikidza sarudzo. Iyo inokonzeresa yekuisa inogona kushandiswa munzvimbo yekugadzira (vane ruzivo vashandisi vanogona kugadzira inodiwa marongero uye kuwedzera zviwanikwa).
Iyo Zextras Suite/Zimbra system inosanganisira:
- zimbra - email yekambani ine kugona kugovera mabhokisi eemail, makarenda uye mazita ekufonera (mabhuku ekero).
- Zextras Docs - yakavakirwa-muhofisi suite yakavakirwa paLibreOffice pamhepo yekugadzira uye nekubatana nemagwaro, matafura, mharidzo.
- Zextras Drive - Yega faira kuchengetedza iyo inokutendera iwe kugadzirisa, kuchengeta uye kugovera mafaera uye maforodha nevamwe vashandisi.
- Zextras Chikwata - mutumwa ane tsigiro yekuteerera uye vhidhiyo musangano. Idzi shanduro dziripo iTeam Basic, iyo inobvumira chete 1: 1 kutaurirana, uye Team Pro, iyo inotsigira akawanda-mushandisi makonferensi, chiteshi, kugovana skrini, kugovana faira, uye zvimwe zvinhu.
- Zextras Mobile - Tsigiro yemidziyo mbozha kuburikidza neExchange ActiveSync yekuwiriranisa tsamba nenharembozha ine MDM (Mobile Chishandiso Management) mabasa. Inokubvumira kushandisa Microsoft Outlook semutengi wetsamba.
- Zextras Admin -kuitwa kweakawanda-maroja sisitimu manejimendi pamwe nenhume yevatariri kutonga mapoka evatengi uye makirasi ebasa.
- Zextras Backup -yakazara-kutenderera data backup uye kudzoreredza munguva chaiyo
- Zextras Powerstore - Hierarchical chengetedzo yemeseti system zvinhu zvine rutsigiro rwemakirasi ekugadzirisa data, nekugona kuchengetedza data munharaunda kana mukuchengetedza kwegore kweS3 architecture, kusanganisira Yandex Object Storage.
Kana kuiswa kwapera, mushandisi anogamuchira sisitimu inoshanda muYandex.Cloud nharaunda.
Mitemo nezvirambidzo
- Disk nzvimbo yekugoverwa kwemabhokisi emabhokisi, indexes uye mamwe marudzi e data haana kutsanangurwa, nokuti Zextras Powerstore inotsigira marudzi akasiyana ekuchengetedza. Rudzi uye saizi yekuchengetera zvinoenderana nemabasa uye system paramita. Kana zvichidikanwa, izvi zvinogona kuitwa gare gare munzira yekushandura yakatsanangurwa yekumisikidza kuita inobereka.
- Kurerutsa kuisirwa, kushandiswa kwemaneja-inotungamirwa DNS server kugadzirisa mukati (asiri eruzhinji) mazita emazita haatariswe; iyo yakajairwa Yandex.Cloud DNS server inoshandiswa. Kana ichishandiswa munzvimbo yekugadzira, zvinokurudzirwa kushandisa sevha yeDNS, iyo inogona kunge yatove muhurongwa hwekambani.
- Zvinofungidzirwa kuti account muYandex.Cloud ine default settings inoshandiswa (kunyanya, kana uchipinda mu "Console" yebasa, pane chete dhairekitori (mune "Available clouds" list pasi pezita rekusagadzika). Vashandisi vanoziva nezvekushanda muYandex.Cloud vanogona, pakusarudza kwavo, kugadzira dhairekitori yakasiyana yechiratidzo chekuedza, kana kushandisa imwe iripo.
- Mushandisi anofanira kunge aine yeruzhinji DNS zone kwaanofanirwa kuwana manejimendi.
- Mushandisi anofanirwa kuwana dhairekitori muYandex.Cloud Console ine ingangoita "editor" basa (iyo "Cloud Owner" ine kodzero dzese dzinodiwa nekusarudzika; pane nhungamiro yekupa mukana kune gore kune vamwe vashandisi: , , )
- Chinyorwa chino hachitsananguri kuiswa kwemushandisi X.509 zvitupa zvinoshandiswa kuchengetedza network kufambiswa neTLS michina. Pakupedzwa kwekuiswa, zvitupa zvekuzvisainira zvichashandiswa, izvo zvinobvumira kushandisa mabhurawuza kuwana iyo yakaiswa system. Vanowanzo ratidza chiziviso chekuti sevha haina chitupa chinobatika, asi inobvumidza iwe kuti uenderere mberi uchishanda. Usati waisa zvitupa zvakasimbiswa nemidziyo yemutengi (yakasainwa neveruzhinji uye/kana yemakambani zvitupa zvitupa), zvikumbiro zvenharembozha zvinogona kusashanda neiyo yakaiswa system. Naizvozvo, kuisirwa zvitupa izvi munzvimbo yekugadzira kwakakosha uye kunoitwa mushure mekupedza bvunzo zvinoenderana nehurongwa hwekuchengetedza makambani.
Tsanangudzo yekumisikidzwa kweZextras/Zimbra system mune "single-server" vhezheni
1. Kugadzirira kwekutanga
Usati watanga kuiswa, unofanirwa kuve nechokwadi:
a) Kuita shanduko kune yeruzhinji DNS zone (kugadzira A rekodhi yeZimbra server uye MX rekodhi yeakatsigirwa tsamba domain).
b) Kumisikidza chaiyo network network muYandex.Cloud.
Nekudaro, mushure mekuita shanduko kuDNS zone, zvinotora nguva kuti shanduko idzi dziparadzire, asi, kune rumwe rutivi, haugone kugadzira A-rekodhi usingazive iyo IP kero yakabatana nayo.
Naizvozvo, zviito zvinoitwa munhevedzano inotevera:
1. Sevha kero yeruzhinji IP muYandex.Cloud
1.1 MuYandex.Cloud Console (kana zvichidikanwa, sarudza dhairekitori mu "makore aripo"), enda kuchikamu cheVirtual Private Cloud, iyo IP kero chikamu, wobva wadzvanya bhatani re "Reserve kero", sarudza yaunoda kuwanikwa nzvimbo (kana kubvumirana nemutengo wakatarwa; iyi inowanikwa nzvimbo inofanirwa kushandiswa kune zvese zvimwe zviitiko muYandex. bhokisi rinovhura, kana uchida, unogona, asi hazvina basa, sarudza "DDoS dziviriro" sarudzo, uye tinya "Reserve" bhatani (ona zvakare ).

Mushure mekuvhara dialog, iyo rondedzero yeIP kero ichange iine static IP kero yakagoverwa nehurongwa, iyo inogona kukopwa uye kushandiswa munhanho inotevera.

1.2 Mu "zvakananga" DNS zone, gadzira A-rekodhi yeZimbra server inongedza kune yakambogoverwa IP kero, A-rekodhi yeiyo TURN server inonongedza kune imwecheteyo IP kero, uye MX-rekodhi kune inotsigirwa tsamba domain. Mumuenzaniso wedu, idzi dzichava mail.testmail.svzcloud.ru (Zimbra server), turn.testmail.svzcloud.ru (TURN server), uye testmail.svzcloud.ru (mail domain), maererano.
1.3 MuYandex.Cloud, munzvimbo yakasarudzwa inowanikwa ye subnet ichashandiswa kuendesa mashini chaiwo, ita kuti NAT iende kuInternet.
Kuti uite izvi, muchikamu cheVirtual Private Cloud, chikamu che "Cloud network", sarudza iyo yakakodzera Cloud network (nekudaro, chete default network inowanikwa ipapo), sarudza yakakodzera nzvimbo yekuwanikwa mairi uye muzvirongwa zvayo, sarudza chinhu "Gonesa NAT kuInternet".

Mamiriro acho achachinja mune runyorwa rwe subnets:

Kuti uwane rumwe ruzivo, ona zvinyorwa: и .
2. Kugadzira virtual machines
2.1. Kugadzira muchina chaiwo weZimbra
Kuenzanisa kwezviito:
2.1.1 MuYandex.Cloud Console, enda kuchikamu cheCompute Cloud, chikamu Virtual Machines, tinya bhatani Gadzira VM (kuti uwane rumwe ruzivo nezve kugadzira VM, ona. ).

2.1.2 Pano iwe unofanirwa kutsanangura:
- Zita - zvekupokana (maererano nefomati inotsigirwa neYandex.Cloud)
- Inowanikwa nzvimbo - inofanirwa kuenderana neyakambosarudzwa kune chaiyo network.
- Mu "Mifananidzo Yeveruzhinji" sarudza Ubuntu 18.04 lts
- Mumadhisiki, isa bhutsu dhisiki yeinenge 80 GB. Nezvinangwa zvekuyedza, rudzi rweHDD rwakakwana (uye zvakare nekushandisa zvine pundutso, chero mamwe marudzi e data achiendeswa kune SSD disks). Kana zvichidikanwa, mamwe madhisiki anogona kuwedzerwa mushure mekugadzira iyo VM.
Mu "computing resources" tsanangura:
- vCPU: kwete pasi pe4.
- Yakavimbiswa vCPU share: ingangoita 50% panguva yekuitwa kwezviito zvinotsanangurwa muchinyorwa, mushure mekuiswa kwapera, inogona kuderedzwa kana zvichidikanwa.
- RAM: 8GB inokurudzirwa.
- Subnet: Sarudza iyo subnet iyo NAT kuInternet yakagoneswa panguva yekutanga-yekugadzirira chikamu.
- Kero yeruzhinji: Sarudza kubva pane iyo IP kero yakamboshandiswa kugadzira iyo A rekodhi muDNS.
- Mushandisi: sekufunga kwako, asi zvakasiyana nemushandisi wekutanga uye nemaakaundi esystem Linux.
- Izvo zvinodikanwa kuseta yeruzhinji SSH kiyi.
→
Onawo 1 kushanda. Kugadzira makiyi eSSH mune openssh uye putty uye kushandura makiyi kubva putty kune openssh fomati.
2.1.3 Kana iyo setup yapera, tinya "Gadzira VM".
2.2. Kugadzira Virtual Machine yeZextras Docs
Kuenzanisa kwezviito:
2.2.1 MuYandex.Cloud Console, enda kuchikamu cheCompute Cloud, chikamu Virtual Machines, tinya bhatani Gadzira VM (kuti uwane rumwe ruzivo nezve kugadzira VM, ona. ).

2.2.2 Pano iwe unofanirwa kutsanangura:
- Zita - zvekupokana (maererano nefomati inotsigirwa neYandex.Cloud)
- Inowanikwa nzvimbo - inofanirwa kuenderana neyakambosarudzwa kune chaiyo network.
- Mu "Mifananidzo Yeveruzhinji" sarudza Ubuntu 18.04 lts
- Mumadhisiki, isa bhutsu dhisiki yeinenge 80 GB. Nezvinangwa zvekuyedza, rudzi rweHDD rwakakwana (uye zvakare nekushandisa zvine pundutso, chero mamwe marudzi e data achiendeswa kune SSD disks). Kana zvichidikanwa, mamwe madhisiki anogona kuwedzerwa mushure mekugadzira iyo VM.
Mu "computing resources" tsanangura:
- vCPU: kwete pasi pe2.
- Yakavimbiswa vCPU share: ingangoita 50% panguva yekuitwa kwezviito zvinotsanangurwa muchinyorwa, mushure mekuiswa kwapera, inogona kuderedzwa kana zvichidikanwa.
- RAM: kwete pasi pe2GB.
- Subnet: Sarudza iyo subnet iyo NAT kuInternet yakagoneswa panguva yekutanga-yekugadzirira chikamu.
- Kero yeruzhinji: hapana kero (muchina uyu haudi kuwana kubva kuInternet, kungobuda chete kubva muchina uyu kuenda kuInternet, iyo inopihwa ne "NAT kuInternet" sarudzo ye subnet inoshandiswa).
- Mushandisi: sekufunga kwako, asi zvakasiyana nemushandisi wekutanga uye nemaakaundi esystem Linux.
- Izvo zvinodikanwa kutsanangura kiyi yeruzhinji (yakavhurika) SSH kiyi, inogona kunge yakafanana neyeZimbra sevha, kana iwe unogona kugadzira yakaparadzana kiyi peya, sezvo yakavanzika kiyi yeZextras Docs server ichada kuiswa paZimbra server disk.
Onawo Appendikisi 1. Kugadzira makiyi eSSH mune openssh uye putty uye kushandura makiyi kubva ku putty kuenda ku openssh fomati.
2.2.3 Kana iyo setup yapera, tinya "Gadzira VM".
2.3 Iwo akagadzirwa chaiwo michina ichave iripo mune rondedzero yemachina chaiwo, uko chimiro chavo uye IP kero dzinoshandiswa, zveveruzhinji nemukati, zvinoratidzwa, pakati pezvimwe zvinhu. Ruzivo nezve IP kero ichadikanwa mune anotevera ekuisa matanho.

3. Kugadzirira Zimbra server yekuisa
3.1 Kuisa zvigadziriso
Iwe unofanirwa kupinda muZimbra server pane yayo yeruzhinji IP kero uchishandisa yako yaunofarira ssh mutengi ine yakavanzika ssh kiyi uye zita rekushandisa rawakatsanangura paunenge uchigadzira chaiwo muchina.
Mushure mekupinda mukati, shandisa mirairo inotevera:
sudo apt update
sudo apt upgrade
(kana uchiita murairo wekupedzisira, pindura "y" kumubvunzo wekuti une chokwadi chekuisa rondedzero yakarongwa yezvigadziriso)
Mushure mekuisa zvigadziriso, unogona (asi haufanirwe) kumhanya murairo:
sudo apt autoremove
Uye pakupera kwenhanho, ita murairo
sudo shutdown –r now
3.2 Kuwedzera kuiswa kwemaapplication
Iwe unofanirwa kuisa iyo NTP mutengi kuwiriranisa iyo system nguva uye iyo skrini yekushandisa nemurairo unotevera:
sudo apt install ntp screen
(kana uchimhanyisa murairo wekupedzisira, pindura "y" kumubvunzo uchibvunza kana uine chokwadi chekuti unoda kuisa iyo inosanganisirwa rondedzero yemapakeji)
Iwe unogona zvakare kuisa zvimwe zvinoshandiswa kuitira kuti maneja zvive nyore. Semuenzaniso, Midnight Commander inogona kuiswa nemurairo:
sudo apt install mc
3.3. Kuchinja masisitimu ehurongwa
3.3.1 Mufaira /etc/cloud/cloud.cfg.d/95-yandex-cloud.cfg shandura kukosha kweparameter maneja_etc_hosts c zvechokwadi pamusoro venhema.
Cherechedza: mupepeti wekugadzirisa iyi faira inofanira kushandiswa nemidzi yekodzero yemushandisi, semuenzaniso, "sudo vi /etc/cloud/cloud.cfg.d/95-yandex-cloud.cfg” kana kana iyo mc package yakaiswa, unogona kushandisa murairo “sudo mceedit /etc/cloud/cloud.cfg.d/95-yandex-cloud.cfg»
3.3.2 Edit / etc / maoko sezvinotevera, kutsiva kero mumutsara unotsanangura FQDN yemuiti kubva 127.0.0.1 nekero yemukati yeIP ye server iyi, uye zita kubva pazita rakazara mu .internal zone nezita reruzhinji re server rataurwa kare muA-rekodhi renzvimbo yeDNS, uye kushandura zita remukosi pfupi zvichienderana neredhiyo reDNS rinosiyana nerevoruzhinji reDNS).
Semuenzaniso, kwatiri isu faira remauto rakaita seizvi:

Mushure mekugadzirisa zvakaratidzika seizvi:

Cherechedza: mupepeti wekugadzirisa iyi faira inofanira kushandiswa nemidzi yekodzero yemushandisi, semuenzaniso, "sudo vi /etc/hosts” kana kana iyo mc package yakaiswa, unogona kushandisa murairo “sudo mceedit /etc/hosts»
3.4 Seta password yemushandisi
Izvi zvinodikanwa nekuti firewall ichagadziriswa gare gare, uye kana paine matambudziko nayo ikamuka, kana mushandisi aine password, zvinokwanisika kupinda mukati meiyo chaiyo muchina uchishandisa serial console kubva kuYandex.Cloud web console uye kudzima firewall uye / kana kugadzirisa kukanganisa. Paunenge uchigadzira muchina chaiwo, mushandisi haana password, uye saka kuwana kunogoneka chete kuburikidza neSSH uchishandisa kiyi yekusimbisa.
Kuti uise password, unofanirwa kumhanya murairo:
sudo passwd <имя пользователя>
Semuenzaniso, kwatiri ichava murairo "sudo passwd mushandisi".
4. Kuisa Zimbra neZextras Suite
4.1. Kudhaunirodha Zimbra uye Zextras Suite kugovera
4.1.1 Kurodha kugovera kweZimbra
Kuenzanisa kwezviito:
1) Enda kuURL uchishandisa browser yako uye zadza fomu racho. Iwe uchagamuchira email ine zvinongedzo zvekurodha Zimbra kune akasiyana OS.
2) Sarudza vhezheni iripo yekugoverwa kwepuratifomu Ubuntu 18.04 LTS uye kopi link yacho
3) Dhawunirodha kugovera kweZimbra kuZimbra server uye kuiburitsa. Kuti uite izvi, mumusangano we ssh pane zimbra server, shandisa mirairo
cd ~
mkdir zimbra
cd zimbra
wget <url, скопированный на предыдущем шаге>
tar –zxf <имя скачанного файла>
(mumuenzaniso wedu ndi“tar –zxf zcs-9.0.0_OSE_UBUNTU18_yazvino-zextras.tgz")
4.1.2 Kurodha kugovera kweZextras Suite
Kuenzanisa kwezviito:
1) Enda kuURL uchishandisa browser yako
2) Zadza fomu nekuisa data rinodiwa uye tinya bhatani re "DOWNLOAD ZVINO".

3) Peji yekudhawunirodha ichavhurwa.

Kune ma URL maviri atinofarira: rimwe riri pamusoro peji reZextras Suite pachayo, iro ratichada ikozvino, uye rimwe riri pasi muDocs Server block ye Ubuntu 18.04 LTS, iyo ichadiwa gare gare kuti iiswe Zextras Docs paVM yeDocs.
4) Dhawunirodha kugovera kweZextras Suite kuZimbra server uye kuiburitsa. Kuti uite izvi, muchikamu che ssh pane zimbra server, ita mirairo
cd ~
mkdir zimbra
cd zimbra
(kana dhairekitori razvino risati rachinja mushure menhanho yapfuura, mirairo iri pamusoro haidi kuurayiwa)
wget http://download.zextras.com/zextras_suite-latest.tgz
tar –zxf zextras_suite-latest.tgz
4.2. Kuiswa kweZimbra
Kuenzanisa kwezviito
1) Enda kudhairekitori uko mafaera akaburitswa mudanho 4.1.1 (unogona kuiona uchishandisa iyo ls command uri mu ~/zimbra dhairekitori).
Mumuenzaniso wedu zvichave:
cd ~/zimbra/zcs-9.0.0_OSE_UBUNTU18_latest-zextras/zimbra-installer
2) Mhanya iyo Zimbra yekuisa nemirairo
sudo ./install.sh
3) Kupindura mibvunzo yekuisa
Unogona kupindura mibvunzo yemugadziri ne "y" (inoenderana ne "hongu"), "n" (inoenderana ne "kwete"), kana kusiya mazano emugadziri asina kuchinjwa (inopa sarudzo nekuaratidza mumabhuraketi akaenzana, semuenzaniso, "[Y]" kana "[N]".
Unobvumirana here nemitemo yechibvumirano cherezinesi resoftware? - Ehe.
Shandisa Zimbra's package repository? - nekusingaperi (hongu).
"Isa zimbra-ldap?","Isa zimbra-logger?","Isa zimbra-mta?” – nekusingaperi (hongu).
Isa zimbra-dnscache? - kwete (iyo inoshanda sisitimu ine yayo caching DNS server inogoneswa nekusarudzika, saka iyi package ichapokana nayo nekuda kwemadoko anoshandiswa).
Isa zimbra-snmp? - nesarudzo, unogona kusiya iyo yakasarudzika sarudzo (hongu), haugone kuisa iyi package. Mumuenzaniso wedu, sarudzo yakasara yasara.
"Isa zimbra-chitoro?","Isa zimbra-apache?","Isa zimbra-spell?","Isa zimbra-memcached?","Isa zimbra-proxy?” – nekusingaperi (hongu).
Isa zimbra-snmp? - kwete (iyo package haina kunyatso kutsigirwa uye inotsiviwa neZextras Drive).
Isa zimbra-imapd? - nekusarudzika (kwete).
Isa zimbra-chat? - kwete (inoshanda yakatsiviwa neZextras Team)
Mushure mezvo mugadziri anozobvunza kana kuenderera mberi nekuisirwa?

Tinopindura "hongu" kana tikakwanisa kuenderera mberi, kana tikasadaro tinopindura "kwete" uye tinowana mukana wekuchinja mhinduro dzemibvunzo yakabvunzwa kare.
Mushure mekunge mabvuma kuenderera mberi, mugadziri anoisa mapakeji.
4.) Kupindura mibvunzo kubva kune yekutanga configurator
4.1) Sezvo mumuenzaniso wedu zita reDNS revhavha yetsamba (zita reA-rekodhi) uye zita reiyo inotsigirwa tsamba domain (iyo MX-rekodhi zita) zvakasiyana, mugadziri anoratidza yambiro uye anopa kudoma zita reiyo inotsigirwa mail domain. Isu tinobvumirana nekupihwa kwayo uye tinoisa zita reMX-rekodhi. Mumuenzaniso wedu, zvinoita seizvi:

Ongorora: unogona kutsanangura inotsigirwa tsamba domain yakasiyana kubva kune server zita kunyangwe paine MX rekodhi ine zita rimwechete rezita reseva.
4.2) Iyo configurator inoratidza iyo huru menyu.

Tinoda kuisa password yeZimbra administrator (menu item 6 mumuenzaniso wedu), pasina izvo hazvibviri kuenderera mberi nekugadzirisa, uye shandura zimbra-proxy setting (menu chinhu 8 mumuenzaniso wedu; kana zvichidiwa, iyi sarudzo inogona kuchinjwa mushure mekuisa).
4.3) Kuchinja zimbra-chitoro marongero
Mune configurator kukurumidza, isa iyo menyu chinhu nhamba uye tinya Enter. Iwe uchasvika kune yekuchengetedza setup menyu:

uko mukukoka kwemugadziri isu tinoisa nhamba yeiyo Admin Password menyu chinhu (mumuenzaniso wedu, 4), tinya Enter, mushure meiyo iyo configurator inopa isina kurongeka inogadzirwa password, iyo iwe yaunogona kubvumirana nayo (uchiirangarira) kana kupinda yako. Muzviitiko zvese izvi, unofanirwa kudzvanya Enter kumagumo, mushure mezvo chiratidzo chekumirira mushandisi chinobviswa kubva ku "Admin Password" chinhu:

Isu tinodzokera kune yakapfuura menyu (tinobvumirana nechikumbiro chemugadziri).
4.4) Kuchinja zimbra-proxy marongero
Nekufananidza nenhanho yapfuura, mumenyu huru, sarudza nhamba yechinhu "zimbra-proxy" uye uiise mukugadzirisa kukurumidza.

Mune iyo Proxy yekumisikidza menyu inovhura, sarudza iyo nhamba yechinhu "Proxy server modhi" uye isa iyo mune yekumisikidza kukurumidza.

Iyo configurator ichakukurudzira kuti usarudze imwe yemamodhi, isa "redirect" mukukasira kwayo uye tinya Enter.
Mushure meizvozvo, tinodzokera kumenyu huru (tinobvumirana nechikumbiro chemugadziri).
4.5) Kutangisa configuration
Kuti utange kurongeka, isa "a" mune yekumisikidza kukurumidza. Mushure meizvozvo, ichabvunza kana kuchengetedza iyo yakapinda kumisikidzwa kufaira (iyo inogona kushandiswa kuisirwazve) - unogona kubvumirana neyakagadzika kupihwa, kana kuchengetedza kwaitwa - inobvunza kuti ndeipi faira yekuchengetedza iyo gadziriso (iwe unogona zvakare kubvumirana neiyo default kupa kana isa rako rezita refaira).

Panguva ino, iwe unogona kuramba kuenderera mberi uye kuita shanduko kugadziriso nekugamuchira mhinduro yakasarudzika kumubvunzo wekuti "Sitimu ichagadziriswa - enderera?".
Kuti utange kuisirwa, unofanirwa kupindura "Hongu" kumubvunzo uyu, mushure meizvozvo iyo configurator ichaisa iyo yakambopinda marongero kwenguva yakati.
4.6) Kupedzisa kuiswa kweZimbra
Asati apedza, mugadziri anobvunza kana kuzivisa Zimbra nezve kuisirwa. Unogona kubvumirana neiyo default kupa kana kuramba (mhinduro "Kwete") ziviso.
Mushure mezvo mugadziri anoenderera mberi nekuita mashandiro ekupedzisira kwenguva yakati uye acharatidza chiziviso nezve kupedzwa kwegadziriro yegadziriro ine zano rekudzvanya chero kiyi yekubuda muinstall.

4.3. Kuisa Zextras Suite
Kuti uwane rumwe ruzivo nezve kuisa Zextras Suite, ona .
Kuenzanisa kwezviito:
1) Enda kudhairekitori uko mafaera akaburitswa mudanho 4.1.2 (unogona kuiona uchishandisa iyo ls command uri mu ~/zimbra dhairekitori).
Mumuenzaniso wedu zvichave:
cd ~/zimbra/zextras_suite
2) Mhanya iyo Zextras Suite yekuisa nemurairo
sudo ./install.sh all
3) Kupindura mibvunzo yekuisa
Iyo installer inoshanda nenzira yakafanana neyeZimbra installer, kunze kwekushayikwa kwemugadziri. Unogona kupindura mibvunzo yemugadziri ne "y" (inoenderana ne "hongu"), "n" (inoenderana ne "kwete"), kana kusiya mazano emugadziri asina kuchinjwa (inopa sarudzo nekuaratidza mumabhuraketi akaenzana, semuenzaniso, "[Y]" kana "[N]".
Kuti utange maitiro ekuisa, unofanirwa kupindura "hongu" kumibvunzo inotevera munhevedzano:
Unobvumirana here nemitemo yechibvumirano cherezinesi resoftware?
Unoshuvira here kuti Zextras Suite idhawunirodhe, isa nekusimudzira ZAL Library?
Mushure mezvo chiziviso chichaonekwa chichikumbira kuti udzvanye Enter kuti uenderere mberi:

Mushure mekudzvanya Enter, iyo yekumisikidza ichatanga, dzimwe nguva ichikanganiswa nemibvunzo, iyo, zvisinei, isu tinopindura nekubvumirana neyakagadzika zvirevo ("hongu"), zvinoti:
Zextras Suite Core zvino ichaiswa. Proceed?
Unoshuvira kumisa Zimbra Webhu Chikumbiro (bhokisi retsamba)?
Iyo Zextras Suite Zimlet yave kuiswa. Proceed?
Chikamu chekupedzisira chekuisa chisati chatanga, chiziviso chicharatidzwa nezve kukosha kwekugadzirisa iyo DOS sefa ine zano rekudzvanya Enter kuti uenderere mberi. Mushure mekudzvanya Enter, chikamu chekupedzisira chekuisa chinotanga, pakupera, chiziviso chekupedzisira chinoratidzwa uye mugadziri anopedzisa basa rayo.

4.4. Kwekutanga kugadzirisa kwezvigadziriso uye tsananguro yeLDAP yekumisikidza paramita
1) Zvose zvinotevera zviito zvinoitwa pasi pemushandisi we zimbra. Kuti uite izvi, unofanirwa kumhanya murairo
sudo su - zimbra
2) Chinja iyo DOS mafirita marongero nemurairo
zmprov mcf zimbraHttpDosFilterMaxRequestsPerSec 150
3) Kuti uise Zextras Docs, iwe unozoda ruzivo nezve mamwe Zimbra kumisikidzwa paramita. Kuti uite izvi, unogona kumhanya murairo:
zmlocalconfig –s | grep ldap
Mumuenzaniso wedu, ruzivo runotevera rucharatidzwa:

Kuti uenderere mberi uchada ldap_url, zimbra_ldap_password (uye zimbra_ldap_userdn, kunyange zvazvo Zextras Docs installer inowanzoita fungidziro chaiyo pamusoro pezita rekushandisa reLDAP).
4) Buda se zimbra nekumhanyisa rairo
kubuda
5. Kugadzirira Docs server kuti igadzirwe
5.1. Kurodha SSH Yakavanzika Kiyi kuZimbra Server uye Login kune Docs Server
Zvakakosha kuisa paZimbra server kiyi yakavanzika yeSSH key pair, iyo yeruzhinji kiyi yakashandiswa mudanho 2.2.2 p.2.2 pakugadzira iyo Docs virtual muchina. Inogona kuiswa kune sevha kuburikidza neSSH (semuenzaniso, kuburikidza ne sftp) kana kunamirwa kuburikidza ne clipboard (kana kugona kweSSH mutengi uye nharaunda yayo yekuuraya ichibvumira).
Isu tinofungidzira kuti kiyi yepachivande yakaiswa mufaira ~/.ssh/docs.key uye mushandisi anoshandiswa kupinda muZimbra server ndiye muridzi wayo (kana kurodha/kugadzirwa kwefaira iyi kwakaitwa pasi pemushandisi uyu, akabva angove muridzi wayo).
Iwe unofanirwa kuita murairo kamwe chete:
chmod 600 ~/.ssh/docs.key
Mune ramangwana, kuti upinde kuDocs server, unofanirwa kuita zvinotevera zvinotevedzana zvezviito:
1) Pinda kuZimbra server
2) Ita murairo
ssh -i ~/.ssh/docs.key user@<внутренний ip-адрес сервера Docs>
Apo kukosha <mukati IP kero yeDocs server> inogona kuwanikwa mu "Yandex.Cloud Console", semuenzaniso, sezvakaratidzwa mup.2.3.
5.2. Kuisa zvigadziriso
Mushure mekupinda muDocs server, ita mirairo yakafanana neiyo yeZimbra server:
sudo apt update
sudo apt upgrade
(kana uchiita murairo wekupedzisira, pindura "y" kumubvunzo wekuti une chokwadi chekuisa rondedzero yakarongwa yezvigadziriso)
Mushure mekuisa zvigadziriso, unogona (asi haufanirwe) kumhanya murairo:
sudo apt autoremove
Uye pakupera kwenhanho, ita murairo
sudo shutdown –r now
5.3. Kuwedzera kuiswa kwemaapplication
Iwe unofanirwa kuisa mutengi weNTP kuwiriranisa iyo system nguva uye skrini yekushandisa, yakafanana nechiito chimwechete cheZimbra server, nemurairo unotevera:
sudo apt install ntp screen
(kana uchimhanyisa murairo wekupedzisira, pindura "y" kumubvunzo uchibvunza kana uine chokwadi chekuti unoda kuisa iyo inosanganisirwa rondedzero yemapakeji)
Iwe unogona zvakare kuisa zvimwe zvinoshandiswa kuitira kuti maneja zvive nyore. Semuenzaniso, Midnight Commander inogona kuiswa nemurairo:
sudo apt install mc
5.4. Kuchinja masisitimu ehurongwa
5.4.1. Mufaira /etc/cloud/cloud.cfg.d/95-yandex-cloud.cfg, sezvakangoita sevhavha yeZimbra, shandura kukosha kwemanage_etc_hosts parameter kubva pachokwadi kuenda kunhema.
Cherechedza: mupepeti wekugadzirisa iyi faira inofanira kushandiswa nemidzi yekodzero yemushandisi, semuenzaniso, "sudo vi /etc/cloud/cloud.cfg.d/95-yandex-cloud.cfg” kana kana iyo mc package yakaiswa, unogona kushandisa murairo “sudo mceedit /etc/cloud/cloud.cfg.d/95-yandex-cloud.cfg»
5.4.2. Rongedza /etc/hosts uye wedzera iyo yeruzhinji FQDN yeZimbra server, asi neiyo yemukati IP kero yakapihwa neYandex.Cloud. Kana iwe uine maneja-anodzora mukati meDNS sevha inoshandiswa nemashini chaiwo (semuenzaniso munharaunda yekugadzira) uye inokwanisa kugadzirisa veruzhinji FQDN yeZimbra server kune yemukati IP kero kana uchigamuchira chikumbiro kubva kune yemukati network (yezvikumbiro kubva paInternet, iyo FQDN yeZimbra sevha inofanirwa kugadziriswa kune yeruzhinji IP kero, uye iyo TURN kero, kusanganisira kero yemukati, iyo yemukati sevha inogadziriswa nguva dzose, iyo IP kero inofanirwa kuve yagadziriswa. hazvidiwi.
Semuenzaniso, kwatiri isu faira remauto rakaita seizvi:

Mushure mekugadzirisa zvakaratidzika seizvi:

Cherechedza: mupepeti wekugadzirisa iyi faira inofanira kushandiswa nemidzi yekodzero yemushandisi, semuenzaniso, "sudo vi /etc/hosts” kana kana iyo mc package yakaiswa, unogona kushandisa murairo “sudo mceedit /etc/hosts»
6. Kuisa Zextras Docs
6.1. Pinda kuDocs server
Maitiro ekupinda muDocs server anotsanangurwa muchikamu 5.1.
6.2. Kudhaunirodha kugovera Zextras Docs
Kuenzanisa kwezviito:
1) Kubva papeji rakabva kudhawunirodha kugoverwa kweZextras Suite muchikamu 4.1.2. Kudhawunirodha kugoverwa kweZextras Suite (mudanho rechitatu), kopi URL yekuunganidza maDocs e Ubuntu 18.04 LTS (kana isina kukopwa kare).
2) Dhawunirodha kugovera kweZextras Suite kuZimbra server uye kuiburitsa. Kuti uite izvi, muchikamu che ssh pane zimbra server, ita mirairo
cd ~
mkdir zimbra
cd zimbra
wget <URL со страницы скачивания>
(kwedu murairo "wget" unoitwa ")
tar –zxf <имя скачанного файла>
(mune yedu nyaya, murairo wekuti "tar –zxf zextras-docs-" waitwaubuntu18.tgz»)
6.3. Kuisa Zextras Docs
Kuti uwane rumwe ruzivo nezve kuisa nekugadzirisa Zextras Docs, ona: .
Kuenzanisa kwezviito:
1) Enda kudhairekitori uko mafaera akaburitswa mudanho 4.1.1 (unogona kuiona uchishandisa iyo ls command uri mu ~/zimbra dhairekitori).
Mumuenzaniso wedu zvichave:
cd ~/zimbra/zextras-docs-installer
2) Mhanya iyo Zextras Docs yekuisa nemurairo
sudo ./install.sh
3) Kupindura mibvunzo yekuisa
Unogona kupindura mibvunzo yemugadziri ne "y" (inoenderana ne "hongu"), "n" (inoenderana ne "kwete"), kana kusiya mazano emugadziri asina kuchinjwa (inopa sarudzo nekuaratidza mumabhuraketi akaenzana, semuenzaniso, "[Y]" kana "[N]").
Sisitimu ichagadziridzwa, ungade kuenderera? - tinobvuma sarudzo yakasarudzika ("hongu").
Mushure meizvi, kuisirwa kwezvinotsamira kunotanga: mugadziri acharatidza kuti ndeapi mapakeji aanoda kuisa uye okumbira kusimbiswa kwekuiswa kwawo. Muzviitiko zvese, bvumirana nemazano ekutanga.
Somuenzaniso, anogona kubvunza, ".python2.7 haina kuwanikwa. Unoda kuiisa here?»,«python-ldap haina kuwanikwa. Unoda kuiisa?»nezvimwewo.
Mushure mekuisa mapakeji ese anodiwa, mugadziri anokumbira mvumo yekuisa Zextras Docs:
Unoda kuisa Zextras DOCS? - tinobvuma sarudzo yakasarudzika ("hongu").
Mushure mezvo, kwenguva yakati, mapakeji akaiswa, chaizvo, Zextras Docs, uye shanduko kumibvunzo yekumisikidza inoitika.
4) Kupindura mibvunzo configurator
Iyo configurator inokumbira zvigadziriso zvigadziriso, uye mukupindura, hunhu hunowanikwa munhanho 3 mundima 4.4. Yekutanga tuning yezvirongwa uye tsananguro yeLDAP yekumisikidza paramita inoiswa.
Mumuenzaniso wedu, marongero anotaridzika seizvi:

5) Kuzadza kuisirwa kweZextras Docs
Mushure mekupindura mibvunzo yemugadziri, mugadziri anopedzisa dhizaini yemunharaunda uye anonyoresa sevhisi yakaiswa pane huru Zimbra server yakaiswa kare.
Nekuisirwa-sevha-sevha, izvi zvinowanzokwana, asi mune dzimwe nguva (kana magwaro asingazovhurike muDocs mune yewebhu mutengi paDrive tebhu) zvingave zvakakosha kuita chiito chinosungirwa kuisirwa-sevha yakawanda - mumuenzaniso wedu, pane huru Zimbra server, zvichave zvakakosha kuita mirairo kubva pasi pemushandisi weZimbra. /opt/zimbra/libexec/zmproxyconfgen и zmproxyctl restart.
7. Kugadzwa kwekutanga kweZimbra neZextras Suite (kunze kweChikwata)
7.1. Kutanga kupinda kune administrator console
Pinda mubrowser uchishandisa URL: https:// :7071
Kana uchida, unogona kupinda pawebhu mutengi paURL: https://
Paunenge uchipinda mukati, mabhurawuza anoratidza yambiro nezve isina chengetedzo yekubatanidza nekuda kwekutadza kuona chitupa. Iwe unofanirwa kupindura kubrowser nemvumo yako kuenda kune saiti kunyangwe yambiro iyi. Izvi zvinokonzerwa nekuti mushure mekuiswa, chitupa che X.509 chakazvisainira chinoshandiswa pakubatanidza TLS, izvo zvinogona kuzotsiviwa (mukushandisa zvinobudirira - zvinofanirwa) kutsiviwa nechitupa chekutengesa kana chimwe chitupa chinozivikanwa nemabhurawuza anoshandiswa.
Mune fomu rechokwadi, isa zita rekushandisa mufomati admin@<yako inotsigirwa mail domain> uye Zimbra administrator password yakataurwa panguva yekuiswa kweZimbra server mudanho 4.3 mu clause 4.2.
Mumuenzaniso wedu zvinotaridzika seizvi:
Administrator console:

Webhu mutengi:

Cherekedza 1 Kana iwe ukasatsanangudza tsamba inotsigirwa inotsigirwa paunenge uchipinda mune admin console kana webhu mutengi, vashandisi vanozosimbisa neiyo mail domain yakagadzirwa panguva yekumisikidzwa kweZimbra server. Mushure mekuisa, iyi ndiyo yega inotsigirwa mail domain iripo pane ino server, asi mamwe matsamba etsamba anogona kuwedzerwa panguva yekushanda kwehurongwa, uyezve kunyatsotsanangura domain iri muzita remushandisi zvine basa.
Cherekedza 2 Paunopinda mutengi yewebhu, browser yako inogona kukumbira mvumo yekuratidza zviziviso kubva pane saiti. Iwe unofanirwa kubvuma kugamuchira zviziviso kubva kune ino saiti.
Cherekedza 3 Mushure mekupinda muAdmin Console, unogona kuziviswa nezve chero Admin mameseji, kazhinji zviyeuchidzo zvekugadzirisa Zextras Backup uye/kana kutenga rezinesi reZextras rezinesi reyedzo risati rapera. Zviito izvi zvinogona kuitwa gare gare, saka mameseji aripo panguva yekupinda anogona kufuratirwa uye/kana kumakwa sekuverengwa muZextras menyu: Zextras Notification.

Cherekedza 4 Izvo zvakanyanya kukosha kuziva kuti mune sevhavha mamiriro ekutarisa iyo Docs sevhisi sevhisi inoratidzwa se "isipo" kunyangwe Docs muwebhu mutengi ari kushanda nemazvo:

Ichi chikamu cheyedzo vhezheni uye chinogona kugadziriswa chete mushure mekutenga rezinesi uye kubata rutsigiro.
7.2. Kuendesa Zextras Suite Zvikamu
MuZextras: Core menyu, unofanirwa kudzvanya bhatani rekuti "Wedzera" kune ese mazamu auri kuda kushandisa.

Kana uchitumira zimlets, bhokisi rebhokisi rinoonekwa rine mhedzisiro yekushanda sezvinotevera:

Mumuenzaniso wedu, ese Zextras Suite zimlets anoiswa, mushure meiyo Zextras: Core fomu ichaita seizvi:

7.3. Kuchinja magadzirirwo ekuwana
7.3.1. Kuchinja magadzirirwo enyika
Mune Zvirongwa: Menyu yepasi rose, Proxy server submenu, shandura zvinotevera paramita:
Webhu proxy mode: redirect
Gonesa console kutonga proxy server: tarisa bhokisi.
Zvadaro, muchikamu chepamusoro chepamusoro chefomu, tinya "Save".
Mumuenzaniso wedu, mushure mekuchinja kwaitwa, fomu rinotaridzika seizvi:

7.3.2. Shanduko kune huru Zimbra server marongero
Mumenu Settings: Servers: <zita reZimbra server>, submenu Proxy server, shandura zvinotevera paramita:
Webhu proxy mode: tinya "Reset to default" bhatani (ukoshi pachahwo hauzoshanduke, sezvo hwakanga hwatoiswa panguva yekuiswa). Gonesa iyo proxy server yekutonga koni: tarisa kuti cheki bhokisi rakatariswa (iyo yakasarudzika kukosha inofanira kunge yaiswa, kana zvisiri, unogona kudzvanya bhatani re "Reset to default" uye / kana kurimisa nemaoko). Wobva wadzvanya "Save" muchikamu chepamusoro chekurudyi chefomu.
Mumuenzaniso wedu, mushure mekuchinja kwaitwa, fomu rinotaridzika seizvi:

Cherechedza: (Kutangazve kunogona kudiwa kana kupinda pachiteshi ichi kusashanda)
7.4. Kupinda kutsva kune admin console
Pinda kune admin console mubrowser yako uchishandisa URL: https:// :9071
Mune ramangwana, shandisa URL iyi kupinda.
Ongorora: yekumisikidza imwe-server, shanduko yakaitwa munhanho yapfuura kazhinji inokwana, asi mune dzimwe nguva (kana iyo server peji isina kuratidzwa paunenge uchipinda pane yakatsanangurwa URL), ungangoda kuita chiito chinosungirwa kuisirwa-sevha yakawanda - mumuenzaniso wedu, pane huru Zimbra server, iwe uchafanirwa kuita mirairo pasi pemushandisi weZimbra. /opt/zimbra/libexec/zmproxyconfgen и zmproxyctl restart.
7.5. Kugadzirisa iyo default COS
MuSetup: Kirasi yeSevhisi menyu, sarudza iyo COS inonzi "default".
Mune "Sarudzo" submenu, bvisa iyo "Portfolio" basa, wobva wadzvanya "Chengetedza" kumusoro kumusoro kurudyi kwefomu.
Mumuenzaniso wedu, mushure mekugadzirisa, fomu inotaridzika seizvi:

Zvinokurudzirwawo kutarisa bhokisi rekuti "Gonesa faira uye kugovera folda" kuseta muDrive submenu, wobva wadzvanya "Chengetedza" kumusoro kurudyi kwefomu.
Mumuenzaniso wedu, mushure mekugadzirisa, fomu inotaridzika seizvi:

Munzvimbo yekuyedza, mukirasi imwechete sevhisi, unogona kugonesa Team Pro kushanda nekugonesa bhokisi rekutarisa rine zita rimwechete muChikwata submenu, mushure meiyo fomu yekuseta ichataridzika seizvi:

Iine Team Pro maficha akaremara, vashandisi vanongowana mukana weTimu Basic maficha.
Ndapota cherechedza kuti Zextras Team Pro ine rezinesi yakazvimiririra yeZextras Suite, ichibvumira kuti itengerwe nhamba diki yemabhokisi etsamba pane Zextras Suite pachayo; Team Basic maficha anosanganisirwa muZextras Suite rezinesi. Naizvozvo, kana ichishandiswa munzvimbo yekugadzira, zvingave zvakafanira kugadzira yakaparadzana sevhisi kirasi yevashandisi veTimu Pro, iyo inosanganisira akakodzera maficha.
7.6. Firewall setup
Inodiwa kune huru Zimbra server:
a) Bvumira kupinda kubva paInternet kuenda kumadoko ssh, http/https, imap/imaps, pop3/pop3s, smtp (main port uye mamwe madoko ekushandiswa nevatengi vetsamba) uye manejimendi console port.
b) Bvumira zvese zvinongedzo kubva kune yemukati network (iyo NAT kuInternet yakagoneswa mudanho 1.3 muchinhu 1).
Iko hakuna chikonzero chekugadzirisa firewall yeZextras Docs server, sezvo isingasviki kubva paInternet.
Kuti uite izvi, iwe unofanirwa kuita zvinotevera kutevedzana kwezviito:
1) Pinda kune iyo text console ye main Zimbra server. Paunenge uchipinda mukati neSSH, iwe unofanirwa kumhanyisa "screen" kuraira kuti udzivise kukanganisa kwekuita kwekuraira kana iyo yekubatanidza kune server yarasika kwenguva pfupi nekuda kwekuchinja kwe firewall marongero.
2) Ita mirairo
sudo ufw allow 22,25,80,110,143,443,465,587,993,995,9071/tcp
sudo ufw allow from <адрес_вашей_сети>/<длина CIDR маски>
sudo ufw enable
Mumuenzaniso wedu zvinotaridzika seizvi:

7.7. Kutarisa kuwana kune webhu mutengi uye admin console
Kuti utarise kushanda kwefirewall, unogona kuenda kune inotevera URL mubrowser yako
Admin console: https:// :9071
Webhu mutengi: http:// (inotungamira otomatiki ku https:// ichaitika )
Panguva imwecheteyo, uchishandisa imwe nzira URL https:// :7071 Iyo administrator console haifanirwe kuvhura.
Mutengi wewebhu mumuenzaniso wedu anotaridzika seizvi:

Ongorora: Kana iwe ukasaina kune wewebhu mutengi, browser yako inogona kukumbira mvumo yekuratidza zviziviso kubva pasaiti. Iwe unofanirwa kubvuma kugamuchira zviziviso kubva kune ino saiti.
8. Kupa odhiyo nevhidhiyo musangano muZextras Team
8.1. General information
Matanho anotevera haadiwe kana vatengi vese veZextras Team vachidyidzana pasina kushandisa NAT (apo kupindirana neZimbra server pachayo kunogona kuitwa uchishandisa NAT, i.e. kusavapo kweNAT pakati pevatengi kwakakosha), kana kana chete text messenger inoshandiswa.
Kuve nechokwadi chekudyidzana pakati pevatengi muodhiyo uye vhidhiyo musangano musangano:
a) Iwe unofanirwa kuisa kana kushandisa iripo TURN server.
b) Sezvo TURN server inowanzovawo nekushanda kweSTUN server, inokurudzirwa kuishandisa mune iyi simba zvakare (seimwe nzira, mavhareji ehurumende STUN anogona kushandiswa, asi STUN kushanda kwega kazhinji hakuna kukwana).
Munzvimbo yekugadzira, nekuda kwekuremerwa kwakakwira, zvinokurudzirwa kufambisa iyo TURN server kune yakaparadzana virtual muchina. Yekuyedza uye/kana kuremerwa, iyo TURN sevha inogona kusanganiswa neiyo huru Zimbra server.
Muenzaniso wedu unoratidza maitiro ekuisa TURN server pane huru Zimbra server. Kuisa TURN pane imwe sevha yakafanana, kunze kwekuti matanho ekuisa nekugadzirisa iyo TURN software inoitwa pane TURN server, uye matanho ekugadzirisa Zimbra server kuti ishandise anoitwa pane huru Zimbra server.
8.2. Kuisa TURN server
Wakambopinda mukati kuburikidza neSSH kune huru Zimbra server, ita murairo
sudo apt install resiprocate-turn-server
8.3. Kugadzira TURN server
Ongorora: Mupepeti wekugadzirisa ese anotevera ekugadzirisa mafaera anofanirwa kumhanyirwa nemidzi yemushandisi kodzero, semuenzaniso, "sudo vi /etc/reTurn/reTurnServer.config” kana kana iyo mc package yakaiswa, unogona kushandisa murairo “sudo mceedit /etc/reTurn/reTurnServer.config»
Kugadzirwa kwemushandisi kwakareruka
Kurerutsa kusikwa uye kugadzirisa bvunzo yekubatanidza kune TURN server, isu tichadzima kushandiswa kwemapassword ane hashed muTURN server mushandisi database. Munzvimbo yekugadzira, zvinokurudzirwa kushandisa hashed passwords; munyaya iyi, password hashes kwavari inofanira kugadzirwa maererano nemirayiridzo iri mumafaira /etc/reTurn/reTurnServer.config uye /etc/reTurn/users.txt.
Kuenzanisa kwezviito:
1) Rongedza iyo faira /etc/reTurn/reTurnServer.config
Chinja kukosha kwe "UserDatabaseHashedPasswords" parameter kubva pa "chokwadi" kuenda ku "nhema".
2) Rongedza faira /etc/reTurn/users.txt
Rondedzera zita rekushandisa, password, realm (zvisingabvumirwe, zvisingashandiswe pakumisikidza kubatana kweZimbra) uye isa mamiriro eakaunti kuti "ZVINOGONESA".
Mumuenzaniso wedu, faira pakutanga yaitaridzika seizvi:

Mushure mekugadzirisa zvakaratidzika seizvi:

3) Kushandisa configuration
Ita murairo
sudo systemctl restart resiprocate-turn-server
8.4. Kugadzira firewall yeTURN server
Panguva ino, mitemo yekuwedzera firewall inotangwa iyo inodiwa kuti TURN server ishande. Izvo zvinodikanwa kubvumidza kupinda kune hombe chiteshi pane iyo sevha inogashira zvikumbiro, uye kune ine simba renji rezviteshi rinoshandiswa nesevha kuronga midhiya midhiya.
Zviteshi zvinotsanangurwa mufaira /etc/reTurn/reTurnServer.config, kwatiri isu ndeizvi:

и

Kuti umise mitemo ye firewall, unofanirwa kumhanyisa mirairo inotevera
sudo ufw allow 3478,49152:65535/udp
sudo ufw allow 3478,49152:65535/tcp
8.5. Kugadzirisa Zimbra Kushandisa TURN Server
Nekugadzirisa, iyo FQDN yeTURN server yakagadzirwa munhanho 1.2 yechinhu 1 inoshandiswa, uye inofanirwa kugadziriswa nemaseva eDNS kune imwecheteyo yeruzhinji IP kero kune zvese zvikumbiro kubva paInternet uye zvikumbiro kubva kukero dzemukati.
Wona marongero ezvino ekubatanidza e "zxsuite timu iceServer get" ichimhanya semushandisi zimbra.
Kuti uwane rumwe ruzivo nezve kumisikidza kushandiswa kwesevha yeTURN, ona chikamu "Kumisikidza Zextras Chikwata chekushandisa TURN server" mukati .
Kuti ugadzirise, unofanirwa kumhanyisa inotevera mirairo pane Zimbra server:
sudo su - zimbra
zxsuite team iceServer add stun:<FQDN вашего сервера TURN>:3478?transport=udp
zxsuite team iceServer add turn:<FQDN вашего сервера TURN>:3478?transport=udp credential <пароль> username <имя пользователя>
zxsuite team iceServer add stun:<FQDN вашего сервера TURN>:3478?transport=tcp
zxsuite team iceServer add turn:<FQDN вашего сервера TURN>:3478?transport=tcp credential <пароль> username <имя пользователя>
zxsuite team iceServer add stun:<FQDN вашего сервера TURN>:3478
logout
Iwo <username> uye <password> kukosha ndiro zita rekushandisa uye password tsika dzakatsanangurwa mudanho 2 re clause 8.3, zvichiteerana.
Mumuenzaniso wedu zvinotaridzika seizvi:

9. Kubvumira tsamba kupfuura nepakati peSmTP protocol
Maererano ne , muYandex.Cloud, traffic inobuda kuenda kuTCP port 25 paInternet uye kuYandex Compute Cloud virtual machines inogara yakavharwa kana ichipinda kuburikidza neruzhinji IP kero. Izvi hazvikutadzise kutarisa kugamuchirwa kwetsamba kune inotsigirwa tsamba domain inotumirwa kubva kune imwe mail server, asi zvinokutadzisa kutumira tsamba kunze kweZimbra server.
Zvinyorwa zvinoti Yandex.Cloud inogona kuvhura TCP port 25 pakukumbira kutsigira, kana ukaita , uye inochengetedza kodzero yekuvhara chiteshi zvakare kana mitemo ikatyorwa. Kuti uvhure chiteshi, unofanirwa kubata Yandex.Cloud rutsigiro.
Kushanda
Kugadzira makiyi eSSH mune openssh uye putty uye kushandura makiyi kubva putty kune openssh fomati
1. Kugadzira Key Pair dzeSSH
В Windows Kushandisa Putty: Mhanya murairo we puttygen.exe wobva wadzvanya bhatani rekuti “Gadzira”.
В Linux: ita murairo
ssh-keygen
2. Kushandura makiyi kubva ku putty kuenda ku openssh fomati
В Windows:
Kuenzanisa kwezviito:
- Mhanya iyo puttygen.exe chirongwa.
- Rodha kiyi yakavanzika muppk fomati uchishandisa menyu chinhu Faira → Rodha yakavanzika kiyi.
- Isa kodhi (passphrase) kana ichidikanwa pakiyi iyi.
- Kiyi yeruzhinji muOpenSSH fomati inoratidzwa muputtygen ine chinyorwa "Public kiyi yekunamira muOpenSSH authorized_keys file field"
- Kutumira kunze kiyi yakavanzika kune OpenSSH fomati, sarudza Shanduko → Export OpenSSH kiyi kubva kumenyu huru
- Sevha kiyi yakavanzika kufaira idzva.
В Linux
1. Isa iyo PuTTY chishandiso package:
в Ubuntu:
sudo apt-get install putty-tools
в Debian-kugoverwa kwakafanana:
apt-get install putty-tools
muzvikamu zveRPM zvichibva pa yum (CentOS nevamwe):
yum install putty
2. Kushandura kiyi yakavanzika, ita murairo:
puttygen <key.ppk> -O private-openssh -o <key_openssh>
3. Kugadzira kiyi yeruzhinji (kana zvichidikanwa):
puttygen <key.ppk> -O public-openssh -o <key_openssh.pub>
mugumisiro
Mushure mekuisa zvinoenderana nekurudziro, mushandisi anogashira Zimbra mail server yakagadziriswa muYandex.Cloud infrastructure neZextras yekuwedzera yekutaurirana kwemakambani uye kubatana kwegwaro. Izvo zvigadziriso zvinogadzirwa nezvimwe zvirambidzo zvenzvimbo yekuyedza, asi hazvina kuoma kuendesa kuiswa kune yekugadzira maitiro uye kuwedzera sarudzo dzekushandisa iyo Yandex.Cloud chinhu chekuchengetedza uye nezvimwe. Pamibvunzo pamusoro pekuendesa uye kushandiswa kwemhinduro, taura nemudiwa weZextras - kana vamiririri .
Pamibvunzo yese ine chekuita neZextras Suite, unogona kubata Zextras Representative Ekaterina Triandafilidi neemail katerina@zextras.com
Source: www.habr.com
