Mungkin pernah kita membuat policy di Netenforcer untuk membatasi user menggunakan content, tapi user menggunakan akses internet melalui Proxy Server. Ketika diberlakukannya (enforce) policy itu, ternyata policy itu tidak berjalan seperti yang kita harapkan. Jadi bagaimana ?
Ok kita lihat penjelasan dibawah ini:
Ketika menggunakan proxy server yang dikonfigurasi melalui browser (misalnya Internet Explorer atau lainnya), tidak mungkin untuk mengklasifikasikan trafik proxy HTTP menurut URL, Metode atau Content. Trafik akan diklasifikasikan sebagai HTTP, tetapi tidak ada konten yang dapat diklasifikasikan. Ketika trafik diarahkan melalui Cache Redirector atau perangkat sejenisnya, HTTP proxy diklasifikasikan sebagai trafik HTTP, port tujuan tidak relevan. Inspeksi untuk content dapat didefinisikan pada trafik ini
Jadi jika menggunakan Proxy Server dengan model dimana setingan dilakukan di tiap browser user, maka tidak bisa dilakukan policy seperti yang diinginkan diatas. Kita harus menggunakan Proxy Server dengan model transparant.
Semoga membantu
Silakan copy paste asal diberikan sumber aslinya Indentifikasi Trafik HTTP PROXY di Allot Netenforcero @ finarya.blogspot.com
Pernahkah kamu lupa password root di Allot Netenforcer?
Pada postingan kali ini akan saya terangkan bagaimana merestore password root.
Pertama tama kita harus melakukannya dengan console. Jadi kita perlu kabel rollover dan aplikasi hyperterm. Koneksikan semuanya dengan parameter seperti gambar dibawah ini :
OK.
Jika semua sudah siap kita mulai untuk masuk ke rescue mode.
1.Nyalakan power Netenforcer
2.Ketika kamu sudah melihat LILO message, lakukan salah satu dari berikut ini :
Jika AC-400 series maka kamu tekan TAB dua kali
Jika AC-800 series maka kamu tekan CTRl + TAB
Jika AC-1000 dan AC-2500 series tekan ENTER ketika muncul tulisan "Debugger Disabled. Booting from Compact Flash... Reset NPa and NPb."
3.Untuk semua unit setelah LILO boot ketik r dan tekan ENTER
Catatan : Untuk modelhardware terbaru kemungkinan akan muncul tulisan Pressmfor boot menu.
Pilihlah m untuk melanjutkan
Boot menu:
1 - boot
2 - Rescue boot
Lalu Tekan 2.
4.System sekarang akan masuk ke rescue mode. Login dengan user rootbagabu. dan password
5.Ketik vi /mnt/etc/shadow
6.Ubahlah karakter x menjadi seperti ini root::10219:0:::::
7.Keluar dari vi dan simpan perubahan dengan mengetik menekan ESC dan :wq
8.Reboot netenforcer dengan mengetik reboot.
9.System akan masuk ke normal mode.
10.Login dengan user root ( tanpa password )
11.Untuk memberi password yang baru, ketik passwd dan masukkan password yang kamu kehendaki.
Semoga membantu
Silakan copy paste asal disebutkan sumber aslinya lupa password root di Allot @ finarya.blogspot.com
Terkadang unit Netenforcer tidak dapat me-load sistem ketika unit telah lama dioperasikan tanpa berhenti lalu akibat loss power ataupun ketika dilakukan upgrade atau lainnya yang mengakibatkan unit harus di restart kemudian muncul masalah ini.
Tapi hal ini biasa terjadi karena sistem gagal me-mounting harddisk. Gak usah panik .... ada cara untuk mengembalikan unit tersebut dapat bekerja dengan normal lagi. Dibawah ini step stepnya :
1. Hubungkan unit NE dengan PC menggunakan rollover cable atau kabel console Cisco melalui console port di Netenforcer.
Gambar Rollover Cable
2. Aktipkan aplikasi Hyperterm dengan parameter sebagai berikut :
Gambar Hyperterm
3. Boot Up unit Netenforcer untuk masuk ke Rescue Partition.Hal ini dilakukan secara berbeda bagi tiap perangkat sesuai dengan salah satu dari pilihan berikut:
A. Ketika kamu lihat tampilan LILO, jika unitnya AC-40x tekan tombol TAB dua kali. ( jika unit AC-80x tekan tombol CTRL + BREAK ) . Setelah LILO Boot, ketik r dan tekan ENTER.
B. Ketika kamu melihat BootMenu tekan TAB dua kali untuk ke Rescue Partition:
Bios Version 2.3 List Devices:
Hard DiskInterface ......OK
Network Interface 1.......OK
Network Interface 2.......OK
Network Interface 3.......OK
Boot Menu...
Setelah Boot menu ketik r dan tekan ENTER.
C. Setelah ada tampilantekan m untuk ke boot menu, jangan menekan tombol apapun disini,tunggu sampai terlihatBoot Menu
Ketika terlihat Boot Menutekan tombol TAB dua kali untuk ke rescue partition
Hard DiskInterface ......OK
Network Interface1 ......OK
Network Interface2 ......OK
Network Interface3 ......OK
Tekan' m' untuk ke boot menu
Going to normal boot
Boot Menu...
Setelah Boot menu ketik r dan tekan ENTER.
4. Login:rootpassword:bagabu
5. Setelah log in, kamu perlu mengkonfirmasi partisi yang berlabel /dev/hda2 adalah unmount, karena SW dari NE berjalan dari partisi hda2: silakan ketik df.
Jika Anda melihat label /dev/hda2 silahkan unmount-nya dengan mengetikkan 'umount /dev/hda2'
Jika tidak muncul dengan perintah df, anda dapat melanjutkan ke disk memeriksa dan remount prosedur dengan mengetikkan perintah berikut:
rescue# umount /dev/hda2 rescue# e2fsck /dev/hda2 rescue# mount /dev/hda2 reboot
Jika disk sudah ok pada saat ini, hal itu akan boot secara normal.
Jika tidak, ikuti prosedur di atas untuk boot ke rescue mode sekali lagi, dan lanjutkan ke langkah 6: usaha untuk mengembalikan partisi ke pengaturan default (Factory Default).
6. ketik rescue# cd /usr/local/utils
7. jalankan rescure# ./retToFactoryDef.sh
8. Reboot unit Netenforcer
Contoh tampilan pada Hyperterm:
****************************************************************
A L L O T COMMUNICATIONS - N E T E N F O R C E R
****************************************************************
Bios version 3.0
Device Listing:
Hard Disk Interface ...... OK
Network Interface 1 ...... OK
Network Interface 2 ...... OK
Network Interface 3 ...... OK
tekan 'm' untuk boot menu
Going to normal boot
Boot Menu...
----tekan tombol dua kali untuk masuk ke rescue partition
ALLOT COMMUNICATIONS BOOT MENU
******************************
Available Images: system r
Enter choice: r
----Setelah Boot menu ketik r dan tekan Enter
Loading r... Linux version 2.4.31smp (felix@cruncher) (gcc version 2.95.3 20010315 (release)) #19 Mon Oct 17 11:32:36 IST 2005
BIOS-provided physical RAM map:
BIOS-e801: 0000000000000000 - 000000000009f000 (usable)
BIOS-e801: 0000000000100000 - 000000001ff00000 (usable)
0MB HIGHMEM available.
511MB LOWMEM available.
On node 0 totalpages: 130816
zone(0): 4096 pages.
zone(1): 126720 pages.
zone(2): 0 pages.
DMI not present.
Kernel command line: console=ttyS1,19200 debug root=/dev/hda1
Initializing CPU#0
Detected 851.942 MHz processor.
Console: colour EGA 80x25
Calibrating delay loop... 1697.38 BogoMIPS
Memory: 515204k/523264k available (966k kernel code, 7672k reserved, 271k data, 80k init, 0k highmem)
Dentry cache hash table entries: 65536 (order: 7, 524288 bytes)
Inode cache hash table entries: 32768 (order: 6, 262144 bytes)
Mount cache hash table entries: 512 (order: 0, 4096 bytes)
Buffer cache hash table entries: 32768 (order: 5, 131072 bytes)
Page-cache hash table entries: 131072 (order: 7, 524288 bytes)
CPU: L1 I cache: 16K, L1 D cache: 16K
CPU: L2 cache: 256K
Intel machine check architecture supported.
Intel machine check reporting enabled on CPU#0.
CPU: After generic, caps: 0383f9ff 00000000 00000000 00000000
CPU: Common caps: 0383f9ff 00000000 00000000 00000000
CPU: Intel Pentium III (Coppermine) stepping 0a
Enabling fast FPU save and restore... done.
Enabling unmasked SIMD FPU exception support... done.
Checking 'hlt' instruction... OK.
POSIX conformance testing by UNIFIX
PCI: Using configuration type 1
PCI: Probing PCI hardware
PCI: Probing PCI hardware (bus 00)
Limiting direct PCI/PCI transfers.
Linux NET4.0 for Linux 2.4
Based upon Swansea University Computer Society NET3.039
Initializing RT netlink socket
Starting kswapd
Journalled Block Device driver loaded
Serial driver version 5.05c (2001-07-08) with MANY_PORTS SHARE_IRQ SERIAL_PCI enabled
keyboard: Timeout - AT keyboard not present?(ed)
keyboard: Timeout - AT keyboard not present?(f4)
ttyS00 at 0x03f8 (irq = 4) is a 16550A
ttyS01 at 0x02f8 (irq = 3) is a 16550A
Real Time Clock Driver v1.10f
Intel(R) PRO/1000 Network Driver - version 5.7.6-k1
Copyright (c) 1999-2004 Intel Corporation.
Intel(R) PRO/100 Network Driver - version 2.3.43-k1
Copyright (c) 2004 Intel Corporation
PCI: Setting latency timer of device 00:08.0 to 64
e100: selftest OK.
e100: eth0: Intel(R) PRO/100 Network Connection
Hardware receive checksums disabled
cpu cycle saver enabled
PCI: Setting latency timer of device 00:09.0 to 64
e100: selftest OK.
e100: eth1: Intel(R) PRO/100 Network Connection
Hardware receive checksums disabled
cpu cycle saver enabled
PCI: Setting latency timer of device 00:0a.0 to 64
e100: selftest OK.
e100: eth2: Intel(R) PRO/100 Network Connection
Hardware receive checksums disabled
cpu cycle saver enabled
Uniform Multi-Platform E-IDE driver Revision: 7.00beta4-2.4
ide: Assuming 33MHz system bus speed for PIO modes; override with idebus=xx
PIIX4: IDE controller at PCI slot 00:07.1
PIIX4: chipset revision 1
PIIX4: not 100% native mode: will probe irqs later
ide0: BM-DMA at 0x1000-0x1007, BIOS settings: hda:pio, hdb:pio
ide1: BM-DMA at 0x1008-0x100f, BIOS settings: hdc:pio, hdd:pio
hda: C/H/S=0/0/0 from BIOS ignored
hdb: C/H/S=0/0/0 from BIOS ignored
hda: HDS728080PLAT20, ATA DISK drive
blk: queue c026ea00, I/O limit 4095Mb (mask 0xffffffff)
ide0 at 0x1f0-0x1f7,0x3f6 on irq 14
hda: attached ide-disk driver.
hda: host protected area => 1
hda: 160836480 sectors (82348 MB) w/1719KiB Cache, CHS=10011/255/63, UDMA(33)
Partition check:
hda: hda1 hda2 hda3 hda4
NET4: Linux TCP/IP 1.0 for NET4.0
IP Protocols: ICMP, UDP, TCP
IP: routing cache hash table of 4096 buckets, 32Kbytes
TCP: Hash tables configured (established 32768 bind 32768)
NET4: Unix domain sockets 1.0/SMP for Linux NET4.0.
802.1Q VLAN Support v1.8 Ben Greear All bugs added by David S. Miller VFS: Mounted root (ext2 filesystem) readonly.
Freeing unused kernel memory: 80k freed
serial console detected. Disabling virtual terminals.
console=/dev/console
init started: BusyBox v0.60.3 (2002.08.06-10:57+0000) multi-call binary
Starting pid 8, console /dev/console: '/etc/rc.d/rc.S'
Adding Swap: 128512k swap-space (priority -1)
/etc/rc.d/rc.S: cannot create Testing filesystem status: Read-only file system
Checking root filesystem:
fsck 1.27 (8-Mar-2002)
e2fsck 1.27 (8-Mar-2002)
ext2fs_check_if_mount: No such file or directory while determining whether /dev/hda1 is mounted.
/dev/hda1 has been mounted 24 times without being checked, check forced.
Pass 1: Checking inodes, blocks, and sizes
Blog ini hanya sekedar kumpulan data-data dari apa yang pernah aku lakukan atau copy paste dari blog lain dan juga sebagai media pembelajaran bagi siapa saja yang memerlukan.