²©¿Íͳ¼ÆÐÅÏ¢

51ctoÍÆ¼ö²©¿Í
Óû§Ãû£ºCTO_LiuJinFeng
ÎÄÕÂÊý£º92
ÆÀÂÛÊý£º690
·ÃÎÊÁ¿£º104707
ÎÞÓDZңº3907
²©¿Í»ý·Ö£º9010
²©¿ÍµÈ¼¶£º9
×¢²áÈÕÆÚ£º2009-03-26

F5 ÅäÖÃÊÖ²á -F5 BIG-IP 10.1-2-ÅäÖÃ-»ù±¾²ÎÊý
2012-01-31 20:59:56
Ô­´´×÷Æ·£¬ÔÊÐí×ªÔØ£¬×ªÔØÊ±ÇëÎñ±ØÒÔ³¬Á´½ÓÐÎʽ±êÃ÷ÎÄÕ ԭʼ³ö´¦ ¡¢×÷ÕßÐÅÏ¢ºÍ±¾ÉùÃ÷¡£·ñÔò½«×·¾¿·¨ÂÉÔðÈΡ£http://dynamic.blog.51cto.com/711418/769888

                                                                 F5 ÅäÖÃÊÖ²á

F5 BIG-IP 10.1-2-ÅäÖÃ

-»ù±¾²ÎÊý

 

ͳһ¹µÍ¨(Öйú)ÓÐÏÞ¹«Ë¾

2012-01-31

 

 

ǰÑÔ£º

ÓÐÈ˸øÎÒ˵,¼¤»îÁ˽ÓÏÂÀ´Òª×öʲô?

ÄÇôÎÒÃÇÏÖÔÚ¿ªÊ¼×ö¼¤»îºóµÄÊÂÎñ¡£

µ«ÊÇÇëÏÈ¿´:

ÄãÒ²¿ÉÒÔÓµÓÐF5

http://dynamic.blog.51cto.com/711418/767161

F5 ÅäÖÃÊÖ²á -F5 BIG-IP 10.1-1-¼¤»î

http://dynamic.blog.51cto.com/711418/769081

Èç¹ûÉÏÃæÁ½¸öÎÄÕÂû¿´¹ý£¬Çë±ðÏòÏÂÃæ¿´¡£¿´ÁËÄãÒ²²»ÖªµÀÈçºÎÀ´µÄ¡£

ÇмÇ!

±¾ÎĽéÉÜ:

ÅäÖÃ-»ù±¾²ÎÊý

1. ÅäÖùÜÀí½Ó¿Ú-IP

Ç°ÃæÎÄÕÂÖÐûÌáµ½ÈçºÎÅäÖÃIP,ÏÖÔÚ¿ªÊ¼À´ÅäÖá£

怬-F5

clip_image002

Ñ¡Ôñ-System-Õ¹¿ª:

clip_image004

Ñ¡Ôñ-Platform

clip_image006

ĬÈÏ-Automatic(DHCP),²ÎÕÕÎÒÃÇǰÆÚ¹æ»®£¬Ñ¡Ôñ-Manual,ÉèÖÃ-IP:

clip_image008

Ìîд.ºì¿òÖеĶ«Î÷¡£

Ñ¡Ôñ-Update

clip_image010

怬-F5

clip_image012

Log in

clip_image014

Hostname :F5-BIGIP-10-1-1.uc-cn.net

IP Address:192.168.1.245

¼ÆËã»úÃûºÍ¹ÜÀíIPÅäÖÃÍê±Ï¡£

ͬÀí:

ÅäÖÃ- F5-BIGIP-10-1-2

Hostname :F5-BIGIP-10-1-2.uc-cn.net

IP Address:192.168.0.245

clip_image016

Update

clip_image018

怬-F5

clip_image020

clip_image022

2. µÇ¼-¹ÜÀí½çÃæ

clip_image024

clip_image026

clip_image028

3. ¼¤»î-License

²ÎÕÕ:

F5 ÅäÖÃÊÖ²á -F5 BIG-IP 10.1-1-¼¤»î

http://dynamic.blog.51cto.com/711418/769081

4. ÅäÖÃ-ϵͳ-ÊôÐÔ

Ñ¡Ôñ-System-Platform- Configuration

clip_image030

clip_image032

²ÎÕÕ:

²ÎÊýÃû

ÈçºÎÀí½â……

ÈçºÎÉèÖÃ……

Host Name

Ö÷»úÃû£¬ÓÃÀ´±êʶF5ϵͳ×ÔÉí¡£

˵Ã÷

¸ºÔؾùºâÆ÷Ë«»úϵͳµÄÖ÷»úÃû±ØÐ벻ͬ£¬·ñÔòÔÚË«»úͬ²½Ê±»á²úÉú´íÎó£¬Ò²¿ÉÄܵ¼ÖÂLicense±»ÆÆ»µ¡£

[ȡֵ·¶Î§]

l ±ØÐë·ûºÏDNSÓòÃû±ê×¼¡£

l Ö÷»ú²¿·ÖÒÔ×Öĸ¿ªÍ·ÇÒ²»ÉÙÓÚ2λµÄ×Ö·û´®¡£

[ʾÀý]

l Ö÷»úΪ£ºljxc-3600-1

l ±¸»úΪ£ºljxc-3600-2

High availability

¿ÉÓÃģʽ£¬°üÀ¨£º

l Single Device£ºµ¥»úģʽ

l Redundant Pair£ºË«»úģʽ

[ÅäÖÃÖµ]

Redundant Pair

Unit ID

Ë«»úϵͳÖУ¬Ö÷±¸µÄ»ú±êʶ·û¡£

˵Ã÷

´ËÅäÖÃÏîÔÚ“High availability”ÅäÖÃΪ“Redundant Pair”ʱ²ÅÏÔʾ¡£

[ÈçºÎÉèÖÃ]

µ¥»÷ÏÂÀ­Áбí¿òÑ¡Ôñ¡£

[ʾÀý]

l Ö÷»úΪ2¡£

l ±¸»úΪ1¡£

Root Account

ʹÓÃrootÓû§Í¨¹ýÃüÁîÐеǼ¸ºÔؾùºâÆ÷ʱµÄÃÜÂë¡£

˵Ã÷

Ë«»úϵͳµÄÖ÷±¸»úrootÃÜÂë±ØÐë±£³ÖÒ»Ö¡£

[ȡֵ·¶Î§]

³¤¶È´óÓÚ6ÇÒ²»³¬¹ý32λµÄ×Ö·û´®¡£

Çø·Ö´óСд£¬½¨ÒéÃÜÂëÖаüº¬´óд¡¢Ð¡Ð´×ÖĸºÍÊý×Ö¡£

[ʾÀý]

root

Admin Account

ʹÓÃAdminÓû§Í¨¹ýWebÒ³ÃæµÇ¼¸ºÔؾùºâÆ÷ʱµÄÃÜÂë¡£

[ȡֵ·¶Î§]

³¤¶È´óÓÚ6ÇÒ²»³¬¹ý32λµÄ×Ö·û´®¡£

Çø·Ö´óСд£¬½¨ÒéÃÜÂëÖаüº¬´óд¡¢Ð¡Ð´×ÖĸºÍÊý×Ö¡£

[ʾÀý]

admin

Ñ¡Ôñ-¸üÐÂ

ͬÀí:

ÅäÖõÚ2̨F5

clip_image034

Ñ¡Ôñ-¸üÐÂ

Ñ¡Ôñ- System - Gerneral Properties

Device-General

clip_image036

Local Traffic –Gerneral

clip_image038

ͬÀí:

¶Ô.µÚ2̨½øÐÐÏàͬ²Ù×÷¡£ÓëÉÏÁ½Í¼Ò»Ñù¡£²»×ö½ØÍ¼½éÉÜ¡£

5. µ÷Õû-ϵͳʱ¼ä

°²×°-SecureCRT & FX(ÖÕ¶Ë·ÂÕæÆ÷)V6.5.3 Build 490

clip_image040

´ò¿ª-SecureCRT

clip_image042

È¡Ïû

clip_image044

Ñ¡Ôñ-ÔÚ±êǩҳÖÐн¨Á¬½Ó

clip_image046

Ñ¡Ôñ-н¨»á»°

clip_image048

Ñ¡Ôñ-ÏÂÒ»²½

clip_image050

Ñ¡Ôñ-ÏÂÒ»²½

clip_image052

Ñ¡Ôñ-ÏÂÒ»²½

clip_image054

Ñ¡Ôñ-Íê³É¡£

clip_image056

Ñ¡Ôñ-Á¬½Ó

clip_image058

Ñ¡Ôñ-Ö»½ÓÊÜÒ»´Î(O)

clip_image060

Ñ¡Ôñ-NO

clip_image062

Ñ¡Ôñ-È·¶¨

clip_image064

ͬÑù-²Ù×÷-192.168.0.245

clip_image066

clip_image068

¼ì²é-ϵͳʱÖÓ

# date

×¢Òâ:ÏÂÃæÏÔʾµÄCST£¬Èç¹ûÄãÒªÐÞ¸Äʱ¼äҪעÒâÊ±Çø¡£<´Ë´¦ÔÝʱ²»ÉèÖÃʱ¼ä!>

clip_image070

clip_image072

×¢Òâ:ʱ¼ä¶¼À´Ô´ÓÚÄãµÄÎïÀí»ú£¬ÒòΪÕâÊÇ2̨VMµÄÐéÄâ»ú¡£

ÆÁÄ»ÏÔʾÀàËÆÈçÏÂÐÅÏ¢£º

clip_image074

Èç¹ûϵͳʱÖÓ¸úµ±Ç°Ê±¼äÓÐÆ«²î£¬ÔòʹÓÃdateÃüÁîÐÞ¸ÄϵͳʱÖÓ¡£

ÃüÁî¸ñʽΪ£ºdate MMDDHHMMYYYY.SS

ÀýÈ磺½«Ê±¼äÐÞ¸ÄΪ2010Äê1ÔÂ25ÈÕ14ʱ24·Ö40Ã루¼ÙÉèʱ¼ä£©

# date 012514242010.40

ÆÁÄ»ÏÔʾÀàËÆÈçÏÂÐÅÏ¢£º

Mon Jan 25 14:24:40 CST 2010

½«Ð޸ı£´æµ½BIOS¡£

# hwclock --systohc

6. ÉèÖÃ-²ßÂÔ-ЭÒé

ÉèÖÃЭÒ鿪·Å²ßÂÔ£¬Ê¹¸ºÔؾùºâÆ÷Äܹ»ÔÊÐíÖ¸¶¨µÄЭÒéͨ¹ý¡£

¼ì²é-ÉèÖÃ

# b base list

clip_image076

clip_image078

È·ÈÏÆÁÄ»Êä³öÖÐÊÇ·ñÓÐÈçÏÂÐÅÏ¢

self allow {

default

tcp ssh

tcp domain

tcp snmp

tcp https

tcp 4353

udp domain

udp snmp

udp efs

udp 1026

udp 4353

proto ospf

}

ÉÏÊöÐÅÏ¢±íʾһЩ»ù±¾µÄЭÒ飬ËüÃǵÄǰºó˳Ðò¿ÉÒÔ²»ÓëÉÏÃæµÄÐÅÏ¢Ò»Ö£¬Ö»Òª¾ß±¸ÕâЩЭÒé¼´¿É¡£

Èç¹ûÓÐÈçϼӴֲ¿·ÖÐÅÏ¢£¬»òÐÅÏ¢ÖÐûÓаüÀ¨ÉÏÊöһЩ»ù±¾Ð­Ò飬ÔòÐèÒª¶ÔÆä½øÐÐÅäÖãº

self allow { default none }

ÔòÖ´ÐÐÒÔÏÂÃüÁʹ¸ºÔؾùºâÆ÷¶Ô»ù±¾Ð­Ò鿪·Å¡£

6.1. ÊäÈë

# b self allow { default tcp ssh tcp https udp efs tcp snmp proto ospf udp domain udp snmp tcp 4353 tcp domain udp 4353 }

6.2. ±£´æÉèÖÃ

# b base save

6.3. Èçͼ

clip_image080

clip_image082

´Ë²½ÖеÄÔÝʱδÌí¼ÓÏëÒªµÄ¶«Î÷£¬²»Ó°Ïì´ó¾Ö£¬¼ÌÐøÏòǰ¡£

6.4. È·ÈÏÐÞ¸ÄÒѾ­³É¹¦

# more /config/bigip_base.conf

Ð޸ijɹ¦ºóbigip_base.confÎļþÖлáÓÐÈçÏÂÐÅÏ¢

self allow {

default

tcp ssh

tcp domain

tcp snmp

tcp https

tcp 4353

udp domain

udp snmp

udp efs

udp 1026

udp 4353

proto ospf

}

clip_image084

clip_image086

×¢Òâ:

·ÇµÃµ½ÏëÒªµÄЧ¹û…

clip_image088

clip_image090

°¦.ûÏëµ½ÐÞ¸ÄȨÏÞÒ²²»ÐÐ!

7. Ö´ÐÐÈçÏÂÃüÁî£¬ÖØÐÂÆô¶¯¸ºÔؾùºâÆ÷

# reboot

 

±¾Îijö×Ô ¡°IT-Standardization¡± ²©¿Í£¬ÇëÎñ±Ø±£Áô´Ë³ö´¦http://dynamic.blog.51cto.com/711418/769888

·ÖÏíÖÁ
¸ü¶à
Ò»¼üÊղأ¬ËæÊ±²é¿´£¬·ÖÏíºÃÓÑ£¡

ÎÄÕÂÆÀÂÛ

 
2012-01-31 21:03:33
±ðµÄÔÙÇëÆÚ´ý....

 

·¢±íÆÀÂÛ            

¡¾¼¼ÊõÃÅÕר¼Ò½âÎö£ºÈí¿¼ÖØµãÄѵ㼰ӦÊÔ¼¼ÇÉ
êÇ  ³Æ£º
µÇ¼  ¿ìËÙ×¢²á
ÑéÖ¤Â룺

Çëµã»÷ºóÊäÈëÑéÖ¤Â벩¿Í¹ý2¼¶£¬ÎÞÐèÌîдÑéÖ¤Âë

ÄÚ  ÈÝ£º