BolеKwiminyaka emibini edlulileyo, sabhala ukuba wonke umlawuli we-Check Point kungekudala ujongene nomcimbi wokuhlaziya inguqulelo entsha. Kule
Njengoko uyazi, kukho iinketho ze-2 zokuphumeza i-Check Point: I-Standalone kunye ne-Distributed, oko kukuthi, ngaphandle komncedisi wokulawula ozinikeleyo kunye nozinikeleyo. Ukhetho oluSasazo lunconywa kakhulu ngenxa yezizathu ezininzi:
-
umthwalo kwimithombo yesango iyancitshiswa;
-
Awunayo ishedyuli yogcino lwefestile ukuze usebenze kumncedisi wolawulo;
-
ukusebenza okwaneleyo kwe-SmartEvent, kuba akunakwenzeka ukuba isebenze kwi-Standalone version;
-
Kucetyiswa kakhulu ukwakha iqela lamasango kuqwalaselo oluSasazo.
Ukunikezelwa kwazo zonke iinzuzo zokucwangciswa koSasazo, siya kuqwalasela ukuphuculwa kweseva yolawulo kunye nesango lokhuseleko ngokwahlukileyo.
Uhlaziyo lweSeva yoLawulo loKhuseleko (SMS).
Kukho iindlela ezi-2 zokuhlaziya iSMS:
-
ngeCPUSE (ngeGaia Portal)
-
usebenzisa iZixhobo zokuFudukela (ufakelo olucocekileyo luyafuneka - ukufakela okutsha)
Ukuhlaziya usebenzisa i-CPUSE akukhuthazwa ngabalingane be-Check Point njengoko ayiyi kuhlaziya inkqubo yefayile yakho kunye ne-kernel. Nangona kunjalo, le ndlela ayifuni ukufuduka kwemigaqo-nkqubo kwaye ikhawuleza kakhulu kwaye ilula kunendlela yesibini.
Ukufakela okucocekileyo kunye nokufuduka kwemigaqo-nkqubo kusetyenziswa iziXhobo zokuFudukela yindlela ecetyiswayo. Ukongeza kwinkqubo entsha yefayile kunye ne-OS kernel, kaninzi kwenzeka ukuba i-database ye-SMS ivaliwe, kwaye ukufakela okucocekileyo kulo mbandela kuyisisombululo esihle kakhulu sokongeza isantya kumncedisi.
1) Inyathelo lokuqala kulo naluphi na uhlaziyo kukudala i-backups kunye ne-snapshots. Ukuba unomncedisi wolawulo womzimba, ke ugcino kufuneka lwenziwe kwi-intanethi ye-Gaia Portal web. Yiya kwisithuba Ukugcinwa > Ugcino lweNkqubo > Ugcino. Okulandelayo, ukhankanya indawo yokugcina i-backup. Oku kunokuba yi-SCP, i-FTP, iseva ye-TFTP, okanye ekuhlaleni kwisixhobo, kodwa ke kuya kufuneka ulayishe le backup kwiseva okanye ikhompyuter kamva.
Umzobo 1. Ukudala i-backup kwi-Gaia Portal
2) Okulandelayo kufuneka uthathe i-snapshot kwithebhu Ugcino → Ulawulo lwesifinyezo → Entsha. Umahluko phakathi kwee-backups kunye ne-snapshots kukuba ii-snapshots zigcina ulwazi oluninzi, kuquka zonke ii-hotfixes ezifakiweyo. Nangona kunjalo, kungcono ukwenza zombini.
Ukuba umncedisi wakho wolawulo ufakwe njengomatshini wenyani, ngoko kuyacetyiswa ukuba wenze ugcino lomatshini wenyani usebenzisa izixhobo ezakhelwe ngaphakathi zehypervisor. Ikhawuleza kwaye ithembekile.
Umzobo 2. Ukudala i-snapshot kwi-Gaia Portal
3) Gcina ukucwangciswa kwesixhobo kwiGaia Portal. Unokwenza umfanekiso weskrini zonke iisetingi iithebhu ezikwiGaia Portal, okanye ngenisa umyalelo osuka kwiClish gcina uqwalaselo . Okulandelayo, thatha ifayile kwiPC yakho usebenzisa iWinSCP okanye omnye umxhasi.
Umzobo 3. Ukugcina uqwalaselo kwifayile yombhalo)
Qaphela:: ukuba iWinSCP ayikuvumeli ukudibanisa, tshintsha iqokobhe lomsebenzisi ukuya kwi /bin/bash nokuba kujongano lwewebhu kwi Abasebenzisi tab, okanye ngokungenisa umyalelo. chsh –s /bin/bash .
Ukuhlaziya nge-CPUSE
4) Amanyathelo okuqala ama-3 anyanzelekileyo naluphi na ukhetho lokuhlaziya. Ukuba uthatha isigqibo sokuthatha indlela elula yokuhlaziya, ngoko kwi-interface yewebhu yiya kwithebhu Uphuculo (CPUSE) > Isimo kunye neZenzo > Iinguqulelo ezinkulu > Khangela iNqaku R80.40 Gaia Fresh Install and Upgrade. Cofa ekunene kolu hlaziyo kwaye ukhethe Umqinisekisi. Inkqubo yokuqinisekisa iya kuqala imizuzu embalwa, emva koko uya kubona umyalezo ukuba isixhobo sinokuhlaziywa. Ukuba ubona iimpazamo, kufuneka zilungiswe.
Umzobo 4. Hlaziya nge-CPUSE
5) Hlaziya kwinguqu yamva nje ye-CDT (iSixhobo sokuThunyelwa esiPhakathi) - isixhobo esisebenza kwiseva yolawulo kwaye ikuvumela ukuba ufake uhlaziyo, iipakethi zenkonzo, ulawule ii-backups, i-snapshots, izikripthi kunye nokunye okuninzi. Uguqulelo lwe-CDT oluphelelwe lixesha lunokubangela iingxaki ngohlaziyo. Unokuyikhuphela i-CDT apha
I-6) Emva kokubeka i-archive ekhutshelweyo kwi-SMS nakweyiphi na i-directory nge-WinSCP, qhagamshela nge-SSH kwi-SMS kwaye ufake imodi yengcali. Makhe ndikukhumbuze ukuba umsebenzisi weWinSCP kufuneka abe neqokobhe / ibin / ibash!
7) Faka imiyalelo:
cd/somepathtoCDT/
tar -zxvf .tgz
rpm -Uhv —force CPcdt-00-00.i386.rpm
Umzobo 5. Ukufakela iSixhobo sokuThunyelwa esiPhakathi (CDT)
8) Inyathelo elilandelayo kukufakela umfanekiso we-R80.40. Cofa ekunene kuhlaziyo Ukukhuphela, ngoko Faka. Gcina ukhumbule ukuba uhlaziyo luya kuthatha imizuzu ye-20-30 kwaye iseva yokulawula ayiyi kufumaneka ixesha elithile. Ngoko ke, kunengqiqo ukuvumelana kwifestile yenkonzo.
I-9) Zonke iilayisensi kunye nemigaqo-nkqubo yokhuseleko zigcinwe, ngoko ngokulandelayo kufuneka ukhuphele entsha
10) Qhagamshela kwi-SMS entsha SmartConsole kwaye usete imigaqo-nkqubo yokhuseleko. Iqhosha Faka iPolisi kwikona ephezulu ngasekhohlo.
11) I-SMS yakho ihlaziywe, emva koko kufuneka ufake i-hotfix yamva nje. Kwithebhu Uphuculo (CPUSE) > Ubume kunye neZenzo > Ulungiso olushushu nqakraza kwi ekunene iqhosha le mouse Umqinisekisike Faka uHlaziyo. Isixhobo sizakuziqalisa ngokwaso emva kokufaka uhlaziyo.
Umzobo 6. Ukufaka i-hotfix yamva nje nge-CPUSE
Ukuhlaziya ngeMigration Tools
4) Okokuqala, kufuneka uhlaziye kuguqulelo lwamva nje lweCDT - amanqaku 5, 6, 7 ukusuka kwicandelo. "Hlaziya usebenzisa i-CPUSE."
5) Faka iphakheji yeZixhobo zokufuduka ezifunekayo ukufuduka imigaqo-nkqubo ukusuka kumncedisi wolawulo. Ngokutsho koku
6) Okulandelayo kujongano lwewebhu yeSMS yiya kwithebhu Uphuculo (CPUSE)> Isimo kunye neZenzo> Ngenisa iPakeji> Khangela> Khetha ifayile ekhutshelweyo> Ngenisa.
Umzobo 7. Ukungenisa izixhobo zokufuduka ngaphandle
7) Ukusuka kwimowudi yobuchwephesha kwiSMS, khangela ukuba iphakheji yeZixhobo zokuFudukela ifakwe kusetyenziswa umyalelo (imveliso yomyalelo kufuneka ihambelane nenombolo egameni leZixhobo zoKufuduka):
cpprod_util CPPROD_GetValue CPupgrade-tools-R80.40 BuildNumber 1
Umzobo 8. Ukuqinisekisa ukufakwa kweZixhobo zokuFudukela
8) Yiya kwi- $FWDIR/iincwadi zeempendulo kwi-server yolawulo:
cd $FWDIR/scripts
9) Qhuba umqinisekisi wokuphucula kwangaphambili usebenzisa umyalelo (ukuba kukho iimpazamo, zilungise phambi kwamanyathelo angakumbi):
./migrate_server qinisekisa -v R80.40
Qaphela:: ukuba ubona impazamo "Ayiphumelelanga ukufumana iphakheji yoPhuculo lweZixhobo", kodwa ukhangele ukuba uvimba uthathwe ngaphandle ngempumelelo (bona inqaku lesi-4), sebenzisa umyalelo:
./migrate_server qinisekisa -v R80.40 -skip_upgrade_tools_check
Umzobo 9. Ukuqhuba iskripthi sokuqinisekisa
10) Thumela iinkqubo zokhuseleko usebenzisa umyalelo:
./migrate_server export -v R80.40 //.tgz
Umzobo 10. Ukuthunyelwa ngaphandle komgaqo-nkqubo wokhuseleko
Qaphela:: ukuba ubona impazamo "Ayiphumelelanga ukufumana iphakheji yoPhuculo lweZixhobo", kodwa ukhangele ukuba indawo yokugcina ithathwe ngaphandle ngempumelelo (inyathelo 7), sebenzisa umyalelo:
./migrate_server export -skip_upgrade_tools_check -v R80.40 //.tgz
11) Bala i-MD5 hash sum kwaye ugcine imveliso yomyalelo:
md5sum //.tgz
Umzobo 11. Ukubala i-MD5 hash sum
12) Ukusebenzisa iWinSCP, hambisa le fayile kwikhompyuter yakho.
13) Faka umyalelo df-h kwaye uzigcinele ipesenti yabalawuli ngokusekelwe kwisithuba esithathiweyo.
Umfanekiso 12. Ipesenti yabalawuli ngeSMS nganye
14.1) Kwimeko apho uneSMS yokwenyani
14.1.1) Ukusebenzisa
14.1.2) Ndincoma ukulungiselela ubuncinane i-2 bootable flash drives, kuba kwenzeka ukuba i-flash drive ayisoloko ifundeka.
14.1.3) Njengomlawuli kwikhompyuter yakho, sebenzisa ISOmorphic.exe. Kwinqanaba loku-1, khetha umfanekiso okhutshelweyo weGaia R80.40, kwinqanaba lesi-4 i-flash drive. Guqula amanqaku 2 kunye nesi-3 akukho sidingo!
Umzobo 13. Ukudala i-USB flash drive ebhuthayo
14.1.4) Khetha into "Faka ngokuzenzekelayo ngaphandle kokuqinisekisa" kwaye kubalulekile ukukhankanya imodeli yomncedisi wakho wolawulo. Kwimeko yeSMS, kufuneka ukhethe umgca 3 okanye 4.
Umzobo 14. Ukukhetha imodeli yesixhobo ukwenza i-bootable USB flash drive
14.1.5) Emva koko, cima i-upline, faka i-flash drive kwi-port ye-USB, qhagamshela intambo ye-console nge-COM port kwisixhobo kwaye uvule i-SMS. Inkqubo yokuhlohla yenzeka ngokuzenzekelayo. Idilesi ye-IP ehlala ikho - 192.168.1.1/24, kunye nolwazi lokungena ulawulo / admin.
14.1.6) Isinyathelo esilandelayo kukuqhagamshela kwi-intanethi yewebhu kwi-Gaia Portal (idilesi ehlala ikho
14.2) Kwimeko apho uneSMS ebonakalayo
14.2.1) Ngaphantsi kweemeko kufuneka ucime i-SMS endala; yenza umatshini omtsha wenyani kunye nezixhobo ezifanayo (CPU, RAM, HDD) kunye nedilesi ye-IP efanayo. Ngendlela, unokongeza i-RAM kunye ne-HDD, ekubeni i-R80.40 inguqulo ifuna kancinci. Ukuze ugweme iingxabano zedilesi ye-IP, cima i-SMS endala kwaye uqale ukufaka entsha.
14.2.2) Ngexesha lofakelo lweGaia, qwalasela idilesi ye-IP yangoku kwaye ukhethe i-directory / ingcambu indawo eyaneleyo. Ipesenti yezalathisi onazo kufuneka zibe malunga sinda, sebenzisa imveliso df-h.
15) Ngexesha lokukhetha uhlobo lofakelo “Uhlobo loFakelo” khetha ukhetho lokuqala, kuba kusenokwenzeka ukuba awunayo iMDS (Multi-Domain Server). Ukuba i-MDS, ngoko ulawule imimandla emininzi evela kumaziko eSMS ahlukeneyo ngexesha elinye. Kule meko, kufuneka ukhethe ukhetho lwesibini.
Umzobo 15. Ukukhetha uhlobo lofakelo lweGaia
I-16) Inqaku elibaluleke kakhulu elingenakulungiswa ngaphandle kokufaka kwakhona kukhetho lwequmrhu. Kufuneka ukhethe Ulawulo loKhuseleko kwaye cinezela Okulandelayo. Yonke enye into yenzekile.
Umzobo 16. Ukukhetha uhlobo lwequmrhu xa ufaka iGaia
17) Nje ukuba isixhobo siqale kabusha, qhagamshela kwi-intanethi usebenzisa
18) Dlulisa izicwangciso ukusuka kwiscreenshots kuzo zonke iithebhu zeGaia Portal apho into iqwalaselwe, okanye sebenzisa umyalelo osuka kwiclish. uqwalaselo lomthwalo .txt. Le fayile yoqwalaselo kufuneka ifakwe kuqala kwiSMS.
Qaphela:: Ngenxa yokuba i-OS intsha, iWinSCP ayiyi kukuvumela ukuba uqhagamshele njengomlawuli, tshintsha iqokobhe lomsebenzisi ukuya kwi/bin/bash nokuba kujongano lwewebhu kwi Abasebenzisi tab, okanye ngokungenisa umyalelo. chsh –s /bin/bash okanye wenze umsebenzisi omtsha.
19) Layisha ifayile ngemigaqo-nkqubo ethunyelwa ngaphandle ukusuka kumncedisi omdala wolawulo ukuya kulo naliphi na ulawulo. Emva koko uye kwikhonsoli kwimowudi yeengcali kwaye ujonge ukuba isixa se-MD5 hash sihambelana nangaphambili. Ngaphandle koko, ukuthunyelwa kufuneka kwenziwe kwakhona:
ndingu md5 //.tgz
20) Phinda inyathelo lesi-6 kwaye ufake iZixhobo zokuPhucula kwiSMS entsha kwiGaia Portal kwithebhu. Uphuculo (CPUSE) > Ubume kunye nezenzo.
21) Faka umyalelo kwimo yengcali:
./migrate_server import -v R80.40 -skip_upgrade_tools_check //.tgz
Umzobo 17. Ukungenisa umgaqo-nkqubo wokhuseleko kwi-SMS entsha
22) Yenza iinkonzo zisebenze ngomyalelo cpstart.
23) Khuphela entsha
Umfanekiso 18. Ukujonga iilayisensi ezifakiweyo
24) Misela umgaqo-nkqubo wokhuseleko kwisango okanye kwiqela - Faka iPolisi.
Uhlaziyo lweSango loKhuseleko (SG).
Isango loKhuseleko linokuhlaziywa nge-CPUSE, njengeseva yolawulo, okanye ifakwe kwakhona - ukufakela okutsha. Ukusuka kumava am, kwi-99% yamatyala, wonke umntu ubuyisela iSango loKhuseleko ngenxa yokuba ithatha phantse ixesha elifanayo nokuhlaziya nge-CPUSE, kodwa ufumana i-OS ecocekileyo, ehlaziyiweyo ngaphandle kwezinambuzane.
Ngokufaniswa neSMS, kufuneka uqale wenze i-backup kunye ne-snapshot, kwaye ugcine useto kwi-Gaia Portal. Jonga kumanqaku 1, 2 no-3 kwicandelo "Uhlaziyo lweSeva yoLawulo loKhuseleko".
Ukuhlaziya nge-CPUSE
Ukuhlaziya iSango loKhuseleko nge-CPUSE kuyafana nokuhlaziya iSeva yoLawulo loKhuseleko, ngoko ke nceda ubhekisele ekuqaleni kwenqaku.
Inqaku elibalulekileyo: Uhlaziyo lweSG luyafuna Ukuqalisa kwakhona! Ngoko ke, hlaziya ngexesha lefestile yokulondoloza. Ukuba uneqela, phucula i-node yokwenziwa kuqala, emva koko utshintshe iindima kwaye uphucule enye indawo. Kwimeko yeqela, iifestile zokugcina zinokuphetshwa.
Ukuhlohla inguqulelo entsha ye-OS kwiSango loKhuseleko
1.1) Ukuba une-SG yokwenyani
1.1.1) Ukusebenzisa
1.1.2) Ndincoma ukulungiselela ubuncinane i-2 bootable flash drives, kuba kwenzeka ukuba i-flash drive ayisoloko ifundeka.
1.1.3) Njengomlawuli kwikhompyuter yakho, sebenzisa ISOmorphic.exe. Kwinqanaba loku-1, khetha umfanekiso okhutshelweyo weGaia R80.40, kwinqanaba lesi-4 i-flash drive. Guqula amanqaku 2 kunye nesi-3 akukho sidingo!
Umzobo 19. Ukudala i-USB flash drive ebhuthayo
1.1.4) Khetha into "Faka ngokuzenzekelayo ngaphandle kokuqinisekisa", kwaye kubalulekile ukubonisa imodeli yeSango lakho loKhuseleko - imigca 2 okanye 3. Ukuba le yibhokisi yesanti yomzimba (SandBlast Appliance), uze ukhethe umgca wesi-5.
Umzobo 20. Ukukhetha imodeli yesixhobo ukwenza i-bootable USB flash drive
1.1.5) Emva koko, cima i-upline, faka i-flash drive kwi-port ye-USB, qhagamshela ikhebula le-console nge-COM port kwisixhobo kwaye uvule isango. Inkqubo yokuhlohla yenzeka ngokuzenzekelayo. Idilesi yeIP ehlala ikho - 192.168.1.1/24, kunye nolwazi lokungena ulawulo / admin. Kufuneka uhlaziye kuqala indawo yokwenziwa, emva koko faka ipolisi kuyo, tshintsha iindima kwaye emva koko uhlaziye enye indawo. Uya kufuna kakhulu ifestile yenkonzo.
1.1.6) Isinyathelo esilandelayo kukuxhuma kwi-interface yewebhu kwi-Gaia Portal, apho uhamba khona ekuqalisweni kokuqala kwesixhobo. Ngexesha lokuqalisa ucinezela ngokusisiseko Okulandelayo, kuba phantse zonke iisetingi zinokutshintshwa kwixesha elizayo. Nangona kunjalo, unokutshintsha kwangoko idilesi ye-IP, useto lwe-DNS kunye negama lomninimzi.
1.2) Kwimeko apho une-SG yenyani
1.2.1) Yenza umatshini omtsha we-virtual kunye nezixhobo ezifanayo (CPU, RAM, HDD) okanye ngaphezulu, ekubeni i-R80.40 version ifuna kancinci. Ukuze ugweme ukungqubuzana kweedilesi ze-IP, cima isango elidala kwaye uqale ukufaka entsha kunye nedilesi ye-IP efanayo. I-SG endala inokususwa ngokukhuselekileyo, ekubeni akukho nto ixabisekileyo kuyo, kuba zonke izinto ezibalulekileyo - umgaqo-nkqubo wokhuseleko - zifumaneka kumncedisi wokulawula.
1.2.2) Ngexesha lofakelo lwe-OS, qwalasela idilesi ye-IP yangoku kwaye ukhethe uvimba weefayili / ingcambu indawo eyaneleyo.
3) Xhuma kwisango nge-HTTPS port kwaye uqale inkqubo yokuqalisa. Ngexesha lokukhetha uhlobo lofakelo “Uhlobo loFakelo” khetha ukhetho lokuqala - Isango loKhuseleko kunye/okanye uLawulo loKhuseleko.
Umzobo 21. Ukukhetha uhlobo lofakelo lweGaia
4) Inqaku elibaluleke kakhulu kukhetho lwequmrhu (Iimveliso). Kufuneka ukhethe Ukhuseleko lweSango kwaye, ukuba uneqela, khangela ibhokisi "Iyunithi yinxalenye yeqela, uhlobo: ClusterXL". Ukuba uneqela leVRRP, ke ukhethe olu hlobo, kodwa akunakwenzeka.
Umzobo 22. Ukukhetha uhlobo lwequmrhu xa ufaka iGaia
5) Kwinyathelo elilandelayo, seta igama lokugqitha lexesha elinye le-SIC ukuseka ukuthembana nomncedisi wolawulo. Ukusebenzisa eli gama lokugqithisa, isatifikethi siyenziwa, kwaye umncedisi wolawulo uya kunxibelelana nesango elingaphaya kwendlela yonxibelelwano efihliweyo. Khangela uphawu "Qhagamshela kuLawulo lwakho njengeNkonzo" kufuneka imiselwe ukuba umncedisi wolawulo ubekwe efini. Sisanda kubhala malunga noku
Umzobo 23. Ukudalwa kwe-SIC
6) Qala inkqubo yokuqalisa kwithebhu elandelayo. Nje ukuba isixhobo siqale, qhagamshela kujongano lwewebhu kwaye udlulisele useto ukusuka kwiscreenshots kuzo zonke iithebhu zeGaia Portal apho into iqwalaselwe, okanye sebenzisa umyalelo osuka kwiclish. uqwalaselo lomthwalo .txt. Le fayile yoqwalaselo kufuneka kuqala ifakwe kwisango lokhuseleko.
Qaphela:: Ngenxa yokuba i-OS intsha, iWinSCP ayiyi kukuvumela ukuba uqhagamshele njengomlawuli, tshintsha iqokobhe lomsebenzisi ukuya kwi/bin/bash nokuba kujongano lwewebhu kwi Abasebenzisi tab, okanye ngokungenisa umyalelo. chsh –s /bin/bash okanye yenza umsebenzisi omtsha ngeliqokobhe.
7) Vula
Umzobo 24: Ukuseka intembeko ngesango elitsha lokhuseleko
8) Inguqu yeGaia yento kufuneka itshintshe, ukuba ayitshintshi, yitshintshe ngesandla. Emva koko fakela ipolisi kwisango.
9) KwiGaia Portal, yiya kwithebhu Uphuculo (CPUSE) > Ubume kunye neZenzo > Ulungiso olushushu kwaye ufake i-hotfix yamva nje. Isixhobo siya kungena qalisa kwakhona ngexesha lofakelo!
10) Kwimeko ye-cluster, tshintsha iindima ze-nodes kwaye wenze amanyathelo afanayo kwenye i-node.
isiphelo
Ndizame ukwenza esona sikhokelo sicace kwaye sibanzi sokuphucula ukusuka kwi-R80.20/R80.30 ukuya kwi-R80.40 yangoku, ekubeni kuninzi okutshintshileyo. Inguqulelo
Ngayo nayiphi na imibuzo ungaqhagamshelana nathi. Siya kukuvuyela ukunceda ngohlaziyo olunzima kakhulu kunye namatyala njengenxalenye yenkxaso yethu yobugcisa
umthombo: www.habr.com