<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>防火牆 &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/%E9%98%B2%E7%81%AB%E7%89%86/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Sun, 27 Jul 2025 11:24:52 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>讓Pfsense防火牆也有判別國家IP(GEO IP)的能力</title>
		<link>https://ailog.tw/lifelog/2023/08/13/pfsense-country-ip/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 13 Aug 2023 14:25:07 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[country IP]]></category>
		<category><![CDATA[GEO IP]]></category>
		<category><![CDATA[國家IP]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=16517</guid>

					<description><![CDATA[使用過新世代防火牆設備的夥伴們一定知道，這些設備均有判別國家IP來源(GEO IP)的功能，但Pfsense這 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2023/08/13/pfsense-country-ip/" class="more-link">閱讀全文<span class="screen-reader-text">〈讓Pfsense防火牆也有判別國家IP(GEO IP)的能力〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 18px;">使用過新世代防火牆設備的夥伴們一定知道，這些設備均有判別國家IP來源(GEO IP)的功能，但Pfsense這一套軟體式防火牆似乎還沒內建(Opnsense倒是已有內建這樣的功能)，因此小編今天要來介紹如何讓pfsense擁有過濾來源國別IP的能力。</span></p>
<p><span style="font-size: 18px;"><span id="more-16517"></span></span></p>
<p><span style="color: #0000ff; font-size: 18px;"><strong>一、情境</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 18px;">Pfsense：2.2.4-RELEASE</span></p>
<p><span style="font-size: 18px;"><strong><span style="color: #0000ff;">二、IP情資來源</span></strong></span><br />
<span style="font-size: 18px;">官網</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://github.com/herrbischoff">https://github.com/herrbischoff</a></span></p>
<p><span style="font-size: 18px;">國家IP專案頁面：</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://github.com/herrbischoff/country-ip-blocks/tree/master/ipv4">https://github.com/herrbischoff/country-ip-blocks/tree/master/ipv4</a></span></p>
<p><span style="font-size: 18px;">舉例幾個範例國別的連結：</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;">[Japan]</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/jp.cidr">https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/jp.cidr</a></span></p>
<p><span style="font-family: verdana, geneva; font-size: 18px;">[Taiwan]</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/tw.cidr">https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/tw.cidr</a></span></p>
<p><span style="font-size: 18px;"><strong>三、Pfsense設定國別IP清單</strong></span><br />
<span style="font-size: 18px;">01、點選「Firewall」→「Aliases」</span><br />
<span style="font-size: 18px;"><img decoding="async" class="alignnone wp-image-16518 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip01.png" alt="" width="195" height="231" /></span></p>
<p><span style="font-size: 18px;">02、點選「URLs」頁面</span><br />
<span style="font-size: 18px;"><img fetchpriority="high" decoding="async" class="alignnone wp-image-16519 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip02.png" alt="" width="707" height="260" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip02.png 707w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip02-300x110.png 300w" sizes="(max-width: 707px) 100vw, 707px" /></span></p>
<p><span style="font-size: 18px;">03、輸入設定值</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><span style="color: #ff0000;">Name：</span><br />
輸入可識別的名稱<br />
</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><span style="color: #ff0000;">Description：</span><br />
輸入註解名稱<br />
</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><span style="color: #ff0000;">Type：</span><br />
選擇URL Table (IPs)<br />
</span><br />
<span style="font-size: 18px;"><span style="font-family: verdana, geneva;"><span style="color: #ff0000;">在「URL Table (IPs)」欄位輸入參考網址所取得的url：</span><br />
</span>https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/tw.cidr</span></p>
<p><span style="color: #ff0000; font-size: 18px;">Update Freq. (days)：</span><br />
<span style="font-size: 18px;">選擇資料來源的更新頻率(以天為單位)</span><br />
<span style="font-size: 18px;"><img decoding="async" class="alignnone wp-image-16520 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip03.png" alt="" width="592" height="465" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip03.png 592w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip03-300x236.png 300w" sizes="(max-width: 592px) 100vw, 592px" /></span></p>
<p><span style="font-size: 18px;">04、資料確認無誤的話，點選「Apply Changes」套用設定</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16522 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04.png" alt="" width="897" height="252" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04.png 897w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04-300x84.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04-768x216.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 18px;">05、接著到「Firewall」→「Rules」或「NAT」</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-16523" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip05.png" alt="" width="210" height="288" /></span></p>
<p><span style="font-size: 18px;">06、在Source欄位，將「Type」選擇「Single host or alias」，在「Address」欄位輸入先前Aliases步驟所新增的物件名稱</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16524 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06.png" alt="" width="834" height="660" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06.png 834w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06-300x237.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06-768x608.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 18px;">07、防火牆規則設定完畢的狀態</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16526 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07.png" alt="" width="1336" height="261" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07.png 1336w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07-300x59.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07-1024x200.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07-768x150.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Linux透過firewalld指令設定防火牆規則</title>
		<link>https://ailog.tw/lifelog/2023/03/28/linux-firewalld/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 28 Mar 2023 06:05:06 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[FIREWALL-CMD]]></category>
		<category><![CDATA[firewalld]]></category>
		<category><![CDATA[Oracle Linux]]></category>
		<category><![CDATA[Red Hat]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=15379</guid>

					<description><![CDATA[在CentOS 7 / Oracle Linux 7 / Red Hat7版本開始內建了firewalld這個 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2023/03/28/linux-firewalld/" class="more-link">閱讀全文<span class="screen-reader-text">〈Linux透過firewalld指令設定防火牆規則〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">在CentOS 7 / Oracle Linux 7 / Red Hat7版本開始內建了firewalld這個防火牆管理的指令，比過往的Iptables使用上更為簡單，快來了解如何設定吧!</span></p>
<p><span id="more-15379"></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>一、停止iptables服務</strong></span><br />
(1)、暫停iptables功能：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl stop iptables
</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、停用iptables功能：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl mask iptables</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
<span style="color: #0000ff;"><strong>二、安裝firewalld套件</strong></span><br />
(1)、安裝firewalld套件：<br />
</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">sudo yum install firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、設定開機自動執行firewalld：<br />
</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl enable firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、檢查 firewalld 服務狀態：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl status firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、啟動 firewalld 服務：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl start firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(5)、停止 firewalld 服務：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">systemctl stop firewalld</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(6)、重新啟動 firewalld 服務：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">service firewalld restart</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(7)、重新載入 firewalld 設定：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --reload</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong><br />
三、查詢設定狀態</strong></span><br />
(1)、查詢現有區域：<br />
</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-zones</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、查詢「public」區域的設定：</span></p>
<pre><span style="font-size: 12pt; font-family: verdana, geneva;">firewall-cmd --zone=public --list-all</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、查詢「public」的永久設定值：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --list-all --permanent</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、查詢目前預設的區域：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-default-zone</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(5)、更改 firewalld 的預設區域為「office」：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --set-default-zone=office</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(6)、查詢各個網路介面所屬的區域：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-active-zones</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(7)、更改網路卡所屬的區域：<br />
將ens160網路卡<span style="color: #ff0000;">永久</span>設定為public區域的範例語法如下：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">sudo firewall-cmd --permanent --zone=public --change-interface=ens160</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(8)、查詢系統內建服務名稱：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-services</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(9)、查詢防火牆目前所有規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --list-all</span></pre>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>四、設定防火牆規則</strong></span><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(1)、查詢各個網路介面所屬的區域：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --get-active-zones</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、在public區域中「新增」<span style="color: #00ff00;">暫時</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --add-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、在public區域中「新增」<span style="color: #ff0000;">永久</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --permanent --add-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、在public區域中「新增」<span style="color: #ff0000;">永久</span>開放TCP 8080 Port規則：</span></p>
<pre><span style="font-size: 12pt; font-family: verdana, geneva;">firewall-cmd --zone=public --permanent --add-port=8080/tcp</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、在public區域中「新增」<span style="color: #ff0000;">永久</span>開放192.168.6.111這個IP可以連線mysql(3306)服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --add-rich-rule 'rule family="ipv4" source address="192.168.6.111/32" service name="mysql" accept' --permanent</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(6)、在public區域中「新增」<span style="color: #ff0000;">永久<span style="color: #000000;">阻擋192.168.6.222這個IP連線的規則</span></span>：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --add-rich-rule 'rule family="ipv4" source address="192.168.6.222/32" reject' --permanent</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong><br />
五、移除防火牆規則</strong></span><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(1)、在public區域中「刪除」<span style="color: #ff0000;">暫時</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --remove-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(2)、在public區域中「刪除」<span style="color: #ff0000;">永久</span>開放https服務規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --permanent --remove-service=https</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(3)、在public區域中「刪除」<span style="color: #ff0000;">永久</span>開放TCP 8080 Port</span><span style="font-family: verdana, geneva; font-size: 14pt;">規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --permanent --remove-port=8080/tcp</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
(4)、在public</span><span style="font-family: verdana, geneva; font-size: 14pt;">區域中「刪除」特定永久開放</span><span style="font-family: verdana, geneva; font-size: 14pt;">規則：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">firewall-cmd --zone=public --remove-rich-rule 'rule family="ipv4" source address="192.168.6.111/32" service name="mysql" accept' --permanent</span></pre>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="color: #0000ff;"><strong>六、查看系統內建服務樣板</strong></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(1)、查看系統預設防火牆服務樣板：</span></p>
<pre><span style="font-family: verdana, geneva; font-size: 12pt;">ls /usr/lib/firewalld/services</span></pre>
<p>※如無適合的樣板，可以透過既有的樣板產生一個客製化的設定</p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、建立客製化防火牆服務</span><span style="font-family: verdana, geneva; font-size: 14pt;">樣板：</span></p>
<pre>cd /usr/lib/firewalld/services
cp mysql.xml oracle.xml
vim oracle.xml</pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-16440 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/03/linux-firewalld-6-02.png" alt="" width="637" height="154" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/03/linux-firewalld-6-02.png 637w, https://ailog.tw/lifelog/wp-content/uploads/2023/03/linux-firewalld-6-02-300x73.png 300w" sizes="auto, (max-width: 637px) 100vw, 637px" /></span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate防火牆-設備產品生命週期(2022-10-15更新)</title>
		<link>https://ailog.tw/lifelog/2022/10/15/fortigate-life-cycle2022/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 15 Oct 2022 09:22:11 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[EOO]]></category>
		<category><![CDATA[EOS]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[保固]]></category>
		<category><![CDATA[停產]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13946</guid>

					<description><![CDATA[Product Life Cycle就是設備產品生命週期，選購資訊產品時應該要注意一下這個資訊，避免購買到即將 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/10/15/fortigate-life-cycle2022/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate防火牆-設備產品生命週期(2022-10-15更新)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p class="gray"><span style="font-size: 12pt;">Product Life Cycle就是設備產品生命週期，選購資訊產品時應該要注意一下這個資訊，避免購買到即將停止服務或更新的產品，尤其是資安設備(小編就吃過一次虧&#8230;.買完隔年就EOS了&gt;&lt;)。</span></p>
<p><span id="more-13946"></span></p>
<p>EOO(End of Order Date)：<br />
中止接受訂單日期，不過這是原廠的日期，通常SI或代理商會把日期往前推，避免遇到無法出貨的狀況。</p>
<p>LSED(Last Service Extension Date)：<br />
最後服務展延日期，指的是如果有購買維護合約這是日期是最後可以下單的日期，且購買的延伸保固服務日期不得超過EOS日期。</p>
<p>EOS(End of Support Date)：<br />
產品服務中止日期，也就是宣告這個產品的中止了，如果遇到設備故障或有Bug，那就只能重新採購新產品而無法得到相關服務了。</p>
<p>FortiGate防火牆設備產品生命週期(2022-10-15更新)<br />
※如資訊有誤以原廠資訊為主</p>
<table width="756">
<tbody>
<tr>
<td width="316"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate產品型號</span></strong></td>
<td width="147"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">可接受訂單日期</span></strong></td>
<td width="182"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">訂閱服務最後日期</span></strong></td>
<td width="111"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">中止服務日期</span></strong></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-60D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-09-23</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-09-23</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-09-23</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-60E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-12-29</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-12-29</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-12-29</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-70D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2017-07-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-07-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-07-16</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-80D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-04-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-04-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-04-16</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-80E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-08-17</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-90D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-10-14</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-10-14</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-10-14</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-90E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2020-04-15</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2024-04-15</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-04-15</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-100D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-07-26</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-07-26</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-07-26</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-100E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-08-17</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-200D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-05-22</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-05-22</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-05-22</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-300D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-10-11</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-10-11</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-10-11</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-300E</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2021-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2025-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2026-07-15</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-500D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-05-08</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-05-08</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-05-08</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-500E</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2021-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2025-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2026-07-15</span></td>
</tr>
</tbody>
</table>
<p>原廠產品生命週期查詢網頁(需要登入帳號才可查詢)<br />
<a href="https://support.fortinet.com/Information/ProductLifeCycle.aspx">https://support.fortinet.com/Information/ProductLifeCycle.aspx</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>VMware Esxi host Server啟動防火牆</title>
		<link>https://ailog.tw/lifelog/2022/08/29/esxi-fw/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 29 Aug 2022 04:27:20 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[ESXi Server]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<category><![CDATA[防火牆]]></category>
		<category><![CDATA[零信任]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13353</guid>

					<description><![CDATA[近年來Zero Trust議題逐漸被重視，防範的惡意連結不在只有公司外部對內的連線，內部網路的連線應該也要有適 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/08/29/esxi-fw/" class="more-link">閱讀全文<span class="screen-reader-text">〈VMware Esxi host Server啟動防火牆〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">近年來Zero Trust議題逐漸被重視，防範的惡意連結不在只有公司外部對內的連線，內部網路的連線應該也要有適當的管制，避免有惡意行為的跳板機從內部網路發動攻擊。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">小編今天要來介紹如何啟動VMware Esxi Host Server的內建防火牆，以確保管理服務只有被授權的IP存取。<span id="more-13353"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">環境：VMware Esxi 7.0.2</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">Set01、確認防火牆狀態</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">指令：</span></p>
<pre><span style="font-size: 16px;">esxcli network firewall get</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13364 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-01.png" alt="" width="411" height="64" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-01.png 411w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-01-300x47.png 300w" sizes="auto, (max-width: 411px) 100vw, 411px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">Set02、啟動防火牆</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">指令：</span></p>
<pre><span style="font-size: 16px;">esxcli network firewall set --enabled true</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13365 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-02.png" alt="" width="473" height="102" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-02.png 473w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-02-300x65.png 300w" sizes="auto, (max-width: 473px) 100vw, 473px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">Set03、設定服務可連線的IP</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(a).點選ESXi主機左方選單的「網路」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13366 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-03.png" alt="" width="237" height="248" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(b).點選右邊畫面的「防火牆規則」頁面，接著搜尋要設定防火牆的服務(本範例是設定443Port的Web管理畫面連線)，透過選取確認要設定的服務，接著點選「編輯設定」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13367 " src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04.png" alt="" width="802" height="267" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04.png 893w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04-300x100.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04-768x255.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(c).點選「僅允許從下列的網路連線」，輸入要放行的IP，完成IP輸入後點選「確定」套用設定。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13368 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-05.png" alt="" width="450" height="342" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-05.png 450w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-05-300x228.png 300w" sizes="auto, (max-width: 450px) 100vw, 450px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(d).最後檢查該服務的防火牆規則是否有「啟用」， 滑鼠指著要確認的服務，接著按下滑鼠右鍵，如果有看見「啟用」選項，就點選「啟用」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">如果看見「停用」，代表防火牆規則已啟用無須變更設定。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13369 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06.png" alt="" width="773" height="158" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06.png 773w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06-300x61.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06-768x157.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">補充說明：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">如果防火牆規則有誤設定，導致無法連入VMware ESXi主機，此時需要到實體Server機的Console面前設定ESXi Server啟動「Troubleshooting Options」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13371 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-07.png" alt="" width="629" height="401" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-07.png 629w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-07-300x191.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">選擇「Enable ESXi Shell」</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13372 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-08.png" alt="" width="499" height="156" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-08.png 499w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-08-300x94.png 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">接著在鍵盤輸入「Ctrl」+「Alt」+「F1」，切換到本機的Console命令提示畫面，通過管理者帳號密碼驗證後，接著透過指令將防火牆關閉，即可重新連線ESXi Server並重新設定防火牆規則。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">關閉防火牆</span><span style="font-family: verdana, geneva; font-size: 14pt;">指令：</span></p>
<pre><span style="font-size: 16px;">esxcli network firewall set --enabled false</span></pre>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fortinet於2022年7月發布CVE-2021-43072修補</title>
		<link>https://ailog.tw/lifelog/2022/07/20/fortinet-cve-2021-43072/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Wed, 20 Jul 2022 03:34:17 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE-2021-43072]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[FortiOS]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13102</guid>

					<description><![CDATA[資安設備大廠Fortinet於2022年7月發布CVE-2021-43072修補，管理者們趕緊手刀快速更新吧。 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/07/20/fortinet-cve-2021-43072/" class="more-link">閱讀全文<span class="screen-reader-text">〈Fortinet於2022年7月發布CVE-2021-43072修補〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">資安設備大廠Fortinet於2022年7月發布CVE-2021-43072修補，管理者們趕緊手刀快速更新吧。<span id="more-13102"></span></span></p>
<p><strong><span style="font-size: 14pt; font-family: verdana, geneva;">[官方公告網址]</span></strong><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://www.fortiguard.com/psirt/FG-IR-21-206">https://www.fortiguard.com/psirt/FG-IR-21-206</a></span></p>
<p><strong><span style="font-size: 14pt; font-family: verdana, geneva;">[受到CVE-2021-43072影響的產品]</span></strong><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 5.6.0 through 5.6.11</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 6.0.0 through 6.0.11</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 6.2.0 through 6.2.9</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 6.4.0 through 6.4.7</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 7.0.0 through 7.0.2</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 5.6.0 through 5.6.11</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 6.0.0 through 6.0.11</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 6.2.0 through 6.2.9</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 6.4.0 through 6.4.7</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 7.0.0 through 7.0.2</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 6.0.0 through 6.0.14</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 6.2.0 through 6.2.10</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 6.4.0 through 6.4.8</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 7.0.0 through 7.0.5</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 1.0.0 through 1.0.7</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 1.1.0 through 1.1.6</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 1.2.0 through 1.2.13</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 2.0.0 through 2.0.8</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 7.0.0 through 7.0.3</span></p>
<p><strong><span style="font-size: 14pt; font-family: verdana, geneva;">[官方建議更新版本]</span></strong><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 7.0.3 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiManager version 6.4.8 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 7.0.3 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiAnalyzer version 6.4.8 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 7.0.4 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiProxy version 2.0.9 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 7.2.0 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 7.0.6 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 6.4.9 或以上版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">FortiOS version 6.2.11 或以上版本</span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-設定虛擬伺服器通訊埠轉發(virtual ip)</title>
		<link>https://ailog.tw/lifelog/2021/06/02/pfsense-vip/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Wed, 02 Jun 2021 13:47:44 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[NAT]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[VIP]]></category>
		<category><![CDATA[virtual ip]]></category>
		<category><![CDATA[虛擬伺服器]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-設定虛擬伺服器通訊埠轉發(virtual ip)]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8906</guid>

					<description><![CDATA[本篇要介紹的是Pfsense系統如何設定虛擬伺服器通訊埠轉發(virtual ip)，就是如何把內網的伺服器設 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/06/02/pfsense-vip/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-設定虛擬伺服器通訊埠轉發(virtual ip)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">本篇要介紹的是Pfsense系統如何設定虛擬伺服器通訊埠轉發(virtual ip)，就是如何把內網的伺服器設定開放至網際網路，快跟著小編一起來了解吧!<span id="more-8906"></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">假設情境網路架構圖<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8909" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-01.png" alt="" width="512" height="442" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-01.png 512w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-01-300x259.png 300w" sizes="auto, (max-width: 512px) 100vw, 512px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;"><strong>[情境架構說明]</strong></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">Pfsense防火牆的內部網路有一台Web Server 提供80 Port的服務，IP為192.168.168.100，本範例要設定防火牆讓外部網路可以存取這一台Web Server的80Port服務。</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;"><strong>[防火牆設定步驟]<br />
</strong>01、登入Pfsense防火牆系統<br />
http://192.168.168.254<br />
※192.168.168.254為本範例的內部介面IP，請自行變更為相對應的IP<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8912" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-02.png" alt="" width="329" height="230" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-02.png 329w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-02-300x210.png 300w" sizes="auto, (max-width: 329px) 100vw, 329px" /><br />
</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">02、設定NAT規則</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">點選「<span style="color: #ff0000;">Firewall</span>」 → 「<span style="color: #ff0000;">NAT</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8914" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-03.png" alt="" width="344" height="175" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-03.png 344w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-03-300x153.png 300w" sizes="auto, (max-width: 344px) 100vw, 344px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">03、點選「<span style="color: #ff0000;">Port Forward</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8916" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-04.png" alt="" width="353" height="140" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-04.png 353w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-04-300x119.png 300w" sizes="auto, (max-width: 353px) 100vw, 353px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">04、點選「<span style="color: #ff0000;">Add</span>」新增NAT設定規則</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8917" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-05.png" alt="" width="402" height="169" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-05.png 402w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-05-300x126.png 300w" sizes="auto, (max-width: 402px) 100vw, 402px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">05、設定NAT設定規則</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(a)、Interface：選擇「<span style="color: #ff0000;">WAN</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(b)、Address Family：選擇「<span style="color: #ff0000;">IPv4</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(c)、Protocol：選擇「<span style="color: #ff0000;">TCP</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8918" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-06.png" alt="" width="347" height="356" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-06.png 347w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-06-292x300.png 292w" sizes="auto, (max-width: 347px) 100vw, 347px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(d)、Destination：選擇「<span style="color: #ff0000;">WAN Address</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(e)、Destination port：選擇「<span style="color: #ff0000;">HTTP</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(f)、Redirect target IP：選擇「<span style="color: #ff0000;">Single host</span>」並輸入「<span style="color: #ff0000;">192.168.168.100</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(g)、Redirect target port：選擇「<span style="color: #ff0000;">HTTP</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8920" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-07.png" alt="" width="786" height="369" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-07.png 786w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-07-300x141.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-07-768x361.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(h)、Description：填寫可以識別這一條NAT規則的敘述文字</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(i)、Filter rule association：選擇「<span style="color: #ff0000;">Add associated filter rule</span>」進行自動設定對應的防火牆放行規則</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(j)、最後點選「<span style="color: #ff0000;">Save</span>」完成NAT規則新增。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8922" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-08.png" alt="" width="347" height="346" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-08.png 347w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-08-300x300.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-08-150x150.png 150w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-08-100x100.png 100w" sizes="auto, (max-width: 347px) 100vw, 347px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(k)、點選「<span style="color: #ff0000;">Apply Changes</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8923" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-09.png" alt="" width="887" height="165" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-09.png 887w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-09-300x56.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-09-768x143.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(l)、點選「<span style="color: #ff0000;">Firewall</span>」 → 「<span style="color: #ff0000;">Rules</span>」</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8924" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-10.png" alt="" width="189" height="281" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(m)、點選「<span style="color: #ff0000;">WAN</span>」，即可看見剛剛自動新增的防火牆規則</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8925" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-11.png" alt="" width="948" height="284" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-11.png 948w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-11-300x90.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-11-768x230.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(n)、連線Pfsense防火牆80 Port，即可看見剛剛內部網路192.168.168.100的IIS Web Server。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8926" src="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-12.png" alt="" width="409" height="336" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-12.png 409w, https://ailog.tw/lifelog/wp-content/uploads/2021/06/pfsense-vip-12-300x246.png 300w" sizes="auto, (max-width: 409px) 100vw, 409px" /></span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-系統線上版本更新</title>
		<link>https://ailog.tw/lifelog/2021/05/29/pfsense-online-update/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 29 May 2021 10:11:51 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[online update]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[更新]]></category>
		<category><![CDATA[線上更新]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-系統線上版本更新]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8551</guid>

					<description><![CDATA[本篇要介紹的是Pfsense系統線上版本更新，快跟著小編一起來了解吧! 01、登入系統後點選「System」→ &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/29/pfsense-online-update/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-系統線上版本更新〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">本篇要介紹的是Pfsense系統線上版本更新，快跟著小編一起來了解吧!<span id="more-8551"></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">01、登入系統後點選「<span style="color: #ff0000;">System</span>」→「<span style="color: #ff0000;">Update</span>」<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8554" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-01.png" alt="" width="357" height="368" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-01.png 357w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-01-291x300.png 291w" sizes="auto, (max-width: 357px) 100vw, 357px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">02、點選「Confirm」進行系統更新</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">※由下圖畫面可得知，目前系統的版本為「<span style="color: #ff0000;">2.4.5_1</span>」，可更新的版本為「<span style="color: #ff0000;">2.5.1</span>」<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8555" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-02.png" alt="" width="607" height="365" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-02.png 607w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-02-300x180.png 300w" sizes="auto, (max-width: 607px) 100vw, 607px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">03、下圖為系統更新過程畫面，畫面上有提示更新過程會耗費數分鐘，並請<span style="color: #ff0000;">勿關閉視畫面窗或重新整理該視窗畫面</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8556" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03.png" alt="" width="949" height="360" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03.png 949w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03-300x114.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03-768x291.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">04、該畫面表示系統正在做背景更新，請稍後。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8557" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-04.png" alt="" width="635" height="139" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-04.png 635w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-04-300x66.png 300w" sizes="auto, (max-width: 635px) 100vw, 635px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">如果此時到Pfsense系統的Console畫面可以看到正在努力的跑更新中。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8558" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-05.png" alt="" width="501" height="147" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-05.png 501w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-05-300x88.png 300w" sizes="auto, (max-width: 501px) 100vw, 501px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">04、當畫面自動變更為系統登入畫面時，代表系統已順利更新完畢。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8559" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-06.png" alt="" width="329" height="435" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-06.png 329w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-06-227x300.png 227w" sizes="auto, (max-width: 329px) 100vw, 329px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">05、登入系統後確認版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">※下圖為順利完成更新至<span style="color: #ff0000;">2.5.1</span>的畫面</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8560" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-07.png" alt="" width="470" height="428" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-07.png 470w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-07-300x273.png 300w" sizes="auto, (max-width: 470px) 100vw, 470px" /></span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-網路介面設定</title>
		<link>https://ailog.tw/lifelog/2021/05/23/interface-config/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 23 May 2021 14:50:19 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[config]]></category>
		<category><![CDATA[DHCP]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[NAT]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[WAN]]></category>
		<category><![CDATA[設定介面IP]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-網路介面設定]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8422</guid>

					<description><![CDATA[上一篇已經介紹過Pfsense的系統安裝，本篇要介紹的是網路介面的IP設定，快跟著小編一起來了解吧! 假設情境 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/23/interface-config/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-網路介面設定〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">上一篇已經介紹過<a href="https://ailog.tw/lifelog/2021/05/22/pfsense-install/">Pfsense的系統安裝</a>，本篇要介紹的是網路介面的IP設定，快跟著小編一起來了解吧!<span id="more-8422"></span></span></p>
<p><span style="font-size: 14pt;">假設情境網路架構圖</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8442" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense000.png" alt="" width="531" height="366" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense000.png 531w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense000-300x207.png 300w" sizes="auto, (max-width: 531px) 100vw, 531px" /></span></p>
<p><span style="font-size: 14pt;">01、第一次開機時畫面，此時詢問是否設定VLAN，輸入「<span style="color: #ff0000;">n</span>」後按下Enter</span><br />
<span style="font-size: 14pt;">※注意畫面中的資訊，系統有偵測到兩張網路卡分別為「<span style="color: #ff0000;">hn0</span>」及「<span style="color: #ff0000;">hn1</span>」，該資訊下一步驟設定會使用到</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8397" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense012.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense012.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense012-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">02、接著設定WAN端(外部網路)的網路卡介面代號，輸入系統畫面上偵測到的網路卡代號，哪一張做為WAN端網路卡都沒關係，但網路線別接錯就好，這一個介面通常是連接到外端設備，例如：ATUR(小烏龜設備)。<br />
本範例採用<span style="color: #ff0000;">hn0</span>當作WAN網路介面，因此輸入「<span style="color: #ff0000;">hn0</span>」後按下Enter繼續設定步驟。</span><br />
<span style="color: #ff0000; font-size: 14pt;">※不同的網路卡晶片會有不同的網路卡代號，請自行變更為相對應的設定值，勿直接跟著本範例輸入hn0</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8398" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense013.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense013.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense013-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">03、接著設定LAN端(內部網路)的網路卡介面代號，輸入系統畫面上偵測到的網路卡代號，這一個介面通常是連接到內部的設備，例如：Switch或Wifi AP設備上。<br />
本範例採用<span style="color: #ff0000;">hn1</span>當作WAN網路介面，因此輸入「<span style="color: #ff0000;">hn1</span>」後按下Enter繼續設定步驟。<br />
<span style="color: #ff0000;">※不同的網路卡晶片會有不同的網路卡代號，請自行變更為相對應的設定值，勿直接跟著本範例輸入hn1</span></span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8399" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense014.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense014.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense014-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">04、再次確認網路卡相關配置，沒問題後輸入「<span style="color: #ff0000;">y</span>」後按下Enter繼續</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8400" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense015.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense015.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense015-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">05、該畫面為登入系統後的Console主選單畫面。<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8402" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense016.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense016.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense016-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /><br />
各項功能如下：<br />
<span style="font-family: verdana, geneva;">0)、登入(透過SSH登入時使用)</span><br />
<span style="font-family: verdana, geneva;">1)、定義網路介面卡</span><br />
<span style="font-family: verdana, geneva;">2)、設定網路介面的IP</span><br />
<span style="font-family: verdana, geneva;">3)、重置網頁設定的密碼</span><br />
<span style="font-family: verdana, geneva;">4)、還原為原廠/出廠設定值</span><br />
<span style="font-family: verdana, geneva;">5)、重開機</span><br />
<span style="font-family: verdana, geneva;">6)、關機</span><br />
<span style="font-family: verdana, geneva;">7)、ping測試其他電腦</span><br />
<span style="font-family: verdana, geneva;">8)、進入Shell命令提示字元模式</span><br />
<span style="font-family: verdana, geneva;">9)、執行Pf客製TOP</span><br />
<span style="font-family: verdana, geneva;">10)、過濾log</span><br />
<span style="font-family: verdana, geneva;">11)、重新啟動網頁設定</span><br />
<span style="font-family: verdana, geneva;">12)、執行PHP命令及pfSense工具</span><br />
<span style="font-family: verdana, geneva;">13)、在命令提示字元下更新系統</span><br />
<span style="font-family: verdana, geneva;">14)、啟動SSH服務</span><br />
<span style="font-family: verdana, geneva;">15)、恢復近期的設定值</span><br />
<span style="font-family: verdana, geneva;">16)、重新啟動PHP-FPM</span><br />
</span></p>
<p><span style="font-size: 14pt;">06、輸入「<span style="color: #ff0000;">2</span>」後按下Enter，進行網路介面IP設定</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8401" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense017.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense017.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense017-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">07、輸入「<span style="color: #ff0000;">2</span>」後按下Enter，設定LAN的網路介面IP</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8403" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense018.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense018.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense018-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">08、輸入LAN網路介面所配置的IP，本範例輸入「<span style="color: #ff0000;">192.168.168.254</span>」後按下Enter繼續設定<br />
<span style="color: #ff0000;">※192.168.168.254為本範例情境LAN網路介面所配置的IP，請自行變更為實際狀況所需的LAN(內部網路)介面IP，勿直接跟著本範例輸入</span></span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8405" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense019.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense019.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense019-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">09、以CIDR格式輸入LAN網路介面所配置的子遮罩，本範例輸入「<span style="color: #ff0000;">24</span>」後按下Enter繼續設定<br />
<span style="color: #ff0000;">※24為本範例情境的子遮罩，請自行變更為實際狀況所需的LAN(內部網路)介面IP，勿直接跟著本範例輸入<br />
</span>CIDR數字所代表的子遮罩</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">24 = 255.255.255.0 (通常居家環境都是選這個)</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">25 = 255.255.255.128</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">26 = 255.255.255.192</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">27 = 255.255.255.224</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">28 = 255.255.255.240</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">29 = 255.255.255.248</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">30 = 255.255.255.252</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">31 = 255.255.255.254</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">32 = 255.255.255.255</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8404" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense020.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense020.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense020-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">10、輸入LAN(內部網路)的gateway閘道IP，直接按下Enter略過設定，之後有需要在web介面再進行設定</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8406" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense021.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense021.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense021-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">11、輸入LAN(內部網路)的IPv6 IP，直接按下Enter略過設定，之後有需要在web介面再進行設定</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8407" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense022.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense022.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense022-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">12、詢問是否設定內部網路的DHCP自動配發IP服務，輸入「<span style="color: #ff0000;">y</span>」後按下Enter繼續設定<br />
<span style="color: #ff0000;">※內部網路是否需要啟動DHCP服務，請自行依據實際狀況進行設定，勿直接跟著本範例，通常內部網路只會啟動一個DHCP服務，如果您的內部網路已有DHCP服務，就不該再啟動另一台DHCP服務避免IP配發衝突的狀況。</span></span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8408" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense023.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense023.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense023-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">13、輸入DHCP服務發放IP區間的起始值，本範例輸入「<span style="color: #ff0000;">192.168.168.1</span>」，該範圍可以依據實際狀況上去設定範圍</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8409" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense024.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense024.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense024-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">14、輸入DHCP服務發放IP區間的結束值，本範例輸入「<span style="color: #ff0000;">192.168.168.10</span>」，該範圍可以依據實際狀況上去設定範圍</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8410" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense025.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense025.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense025-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">15、輸入「<span style="color: #ff0000;">y</span>」套用LAN網路介面的新IP</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8411" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense026.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense026.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense026-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">16、提示LAN網路介面新IP已生效，可以透過瀏覽器連線該IP進行系統登入，按下「<span style="color: #ff0000;">enter</span>」後可以返回Console功能選單畫面。</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8412" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense027.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense027.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense027-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">17、到該步驟已完成LAN內部網路介面IP的設定，並提供內部網路DHCP服務自動派送 192.168.168.1~10區間的IP</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8413" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense028.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense028.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense028-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">18、到網路架構圖的PC端，驗證是否有自動取得IP<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8445" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-01.png" alt="" width="516" height="149" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-01.png 516w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-01-300x87.png 300w" sizes="auto, (max-width: 516px) 100vw, 516px" /><br />
</span></p>
<p><span style="font-size: 14pt;">19、測試PC端透過ping測試是否可以連線到Pfsense的Lan段IP</span><br />
<span style="font-size: 14pt;">ping 192.168.168.254</span><br />
<span style="color: #ff0000; font-size: 14pt;">※192.168.168.254為本範例Pfsense的Lan端IP，請自行變更為實際狀況的IP進行測試。</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8446" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-02.png" alt="" width="415" height="129" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-02.png 415w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-02-300x93.png 300w" sizes="auto, (max-width: 415px) 100vw, 415px" /></span></p>
<p>20、透過瀏覽器登入pfsense系統，推薦使用Google Chrome或Firefox瀏覽器<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8448" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-03.png" alt="" width="346" height="157" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-03.png 346w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-03-300x136.png 300w" sizes="auto, (max-width: 346px) 100vw, 346px" /></p>
<p>21、輸入預設的帳號密碼登入pfsense系統<br />
預設帳號：admin<br />
預設密碼：pfsense<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8449" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-04.png" alt="" width="350" height="254" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-04.png 350w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-04-300x218.png 300w" sizes="auto, (max-width: 350px) 100vw, 350px" /></p>
<p>22、變更管理者密碼<br />
(1)、登入後系統上方的功能選單下，會有變更管理者密碼的提示，點選「Change the password in the User Manager」變更密碼。<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8450" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05.png" alt="" width="834" height="122" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05.png 834w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05-300x44.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05-768x112.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>(2)、輸入admin帳號新的密碼<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8456" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-06.png" alt="" width="611" height="173" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-06.png 611w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-06-300x85.png 300w" sizes="auto, (max-width: 611px) 100vw, 611px" /></p>
<p>(3)、點選最下方的「SAVE」進行密碼變更儲存<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8457" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-07.png" alt="" width="355" height="134" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-07.png 355w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-07-300x113.png 300w" sizes="auto, (max-width: 355px) 100vw, 355px" /></p>
<p>23、變更WAN介面卡IP<br />
(1)、點選「Interfaces」→「WAN」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8458" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-08.png" alt="" width="252" height="177" /></p>
<p>(2)、設定WAN網路介面為固定IP方式<br />
a.確認「EnableInterface」有勾選<br />
b.將「IPv4 Configuration Type」選項變更為「Static IPv4」<br />
c.將「IPv6 Configuration Type」選項變更為「None」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8459" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-09.png" alt="" width="543" height="238" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-09.png 543w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-09-300x131.png 300w" sizes="auto, (max-width: 543px) 100vw, 543px" /><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8461" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-10.png" alt="" width="559" height="246" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-10.png 559w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-10-300x132.png 300w" sizes="auto, (max-width: 559px) 100vw, 559px" /></p>
<p>(3)、在下方「Static IPv4 Configuration」區域設定WAN網路介面的固定IP資訊<br />
a.在「IPv4 Address」欄位輸入「192.192.205.205」，後方「/」下拉選項選擇「24」<br />
b.點選「IPv4 Upstream gateway」後方的「Add a new gateway」新增WAN端得預設閘道IP<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8462" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11.png" alt="" width="864" height="178" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11.png 864w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11-300x62.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11-768x158.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>(4)、在「Gateway IPv4」欄位輸入本範例的WAN預設閘道IP「192.192.205.254」，並點選「Add」完成新增步驟<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8463" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-12.png" alt="" width="328" height="317" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-12.png 328w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-12-300x290.png 300w" sizes="auto, (max-width: 328px) 100vw, 328px" /></p>
<p>(5)、確認「IPv4 Upstream gateway」欄位有順利完成設定<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8464" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13.png" alt="" width="832" height="134" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13.png 832w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13-300x48.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13-768x124.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>(6)、在該設定頁面最下方點選「Save」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8465" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-14.png" alt="" width="292" height="325" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-14.png 292w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-14-270x300.png 270w" sizes="auto, (max-width: 292px) 100vw, 292px" /></p>
<p>(7)、在該設定頁面最上方點選選「<span style="color: #ff0000;">Apply Changes</span>」完成設定<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8466" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-15.png" alt="" width="594" height="111" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-15.png 594w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-15-300x56.png 300w" sizes="auto, (max-width: 594px) 100vw, 594px" /></p>
<p>24、設定DNS<br />
(1)、點選「System」→「General Setup」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8468" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-16.png" alt="" width="346" height="157" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-16.png 346w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-16-300x136.png 300w" sizes="auto, (max-width: 346px) 100vw, 346px" /></p>
<p>(2)、在「DNS Server Settings」新增一組DNS資訊。<br />
在DNS Servers後方依序輸入「168.95.1.1」、「Hinet」、選擇「WAN端的預設閘道」，並點選「Add DNS Server」新增次要DNS設定<br />
<span style="color: #ff0000;">※該設定並非固定值，請自行依據實際的狀況輸入主要DNS資訊</span><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8469" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-17.png" alt="" width="618" height="350" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-17.png 618w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-17-300x170.png 300w" sizes="auto, (max-width: 618px) 100vw, 618px" /></p>
<p>(3)、在新增的欄位後方依序輸入「8.8.8.8」、「google」、選擇「WAN端的預設閘道」<br />
<span style="color: #ff0000;">※該設定並非固定值，請自行依據實際的狀況輸入次要DNS資訊</span><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8470" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-18.png" alt="" width="728" height="133" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-18.png 728w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-18-300x55.png 300w" sizes="auto, (max-width: 728px) 100vw, 728px" /></p>
<p>(4)、在該頁面的最下方點選「Save」，進行DNS設定存檔<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8471" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-19.png" alt="" width="551" height="196" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-19.png 551w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-19-300x107.png 300w" sizes="auto, (max-width: 551px) 100vw, 551px" /></p>
<p>(5)、看見「The changes have been applied successfully.」代表DNS設定已順利完成變更<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8472" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-20.png" alt="" width="329" height="122" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-20.png 329w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-20-300x111.png 300w" sizes="auto, (max-width: 329px) 100vw, 329px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-系統安裝</title>
		<link>https://ailog.tw/lifelog/2021/05/22/pfsense-install/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 22 May 2021 14:38:54 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[install]]></category>
		<category><![CDATA[iso]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[光碟開機]]></category>
		<category><![CDATA[安裝]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-系統安裝]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8370</guid>

					<description><![CDATA[Pfsense是一套開源免費版軟體式防火牆，以FreeBSD系統為核心，可以安裝在X86的硬體上，當然安裝在一 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/22/pfsense-install/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-系統安裝〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">Pfsense是一套開源免費版軟體式防火牆，以FreeBSD系統為核心，可以安裝在X86的硬體上，當然安裝在一般的PC也是沒問題，擁有相當良好的硬體移轉特性，因此很適合中小企業/家庭/社區使用，小編使用該軟體也有相當久的時間了，表現相當的傑出、也相當的穩定，推薦給大家試試看。<span id="more-8370"></span></span></p>
<p><span style="font-size: 14pt;">官網：</span><br />
<span style="font-size: 14pt;"><a href="https://www.pfsense.org/">https://www.pfsense.org/</a></span></p>
<p><span style="font-size: 14pt;">軟體下載快速連結：</span><br />
<span style="font-size: 14pt;"><a href="https://www.pfsense.org/download/">https://www.pfsense.org/download/</a></span></p>
<p><span style="font-size: 14pt;">適合安裝的平台(無論是實體機或是虛擬機，均需要準備<span style="color: #ff0000;">兩張網路卡</span>)：</span><br />
<span style="font-size: 14pt;">個人電腦(PC)、伺服器硬體(HP、Dell、Lenovo等Server)、VMware ESXi、Microsoft Hyper-V、Linux KVM</span></p>
<p><span style="font-size: 14pt;">小編為何會特別說該系統的「硬體移轉特性」十分的良好，是因為如果時體機硬體發生故障時，將系統移轉到其他硬體後，只要可以順利開機、網路卡可以被pfsense識別的到，接著重新定義LAN(內部網路介面)及WAN(外部網路介面)的網路卡就可以恢復服務瞜。</span></p>
<p><span style="font-size: 14pt;">小編最近忙翻了，詞窮&#8230;&#8230;廢話不多說，趕快開始。</span></p>
<p><span style="font-size: 14pt;">01、連線到官網，點選「Download」切換到軟體下載頁面<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8373" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001.png" alt="" width="779" height="175" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001.png 779w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001-300x67.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001-768x173.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt;">02、小編安裝時最新的版本是2.4.5，安裝平台選擇「<span style="color: #ff0000;">AMD64</span>」即是64位元的系統，安裝媒體選擇<span style="color: #ff0000;">ISO</span>檔案格式，下載來源就採用預設不特別挑選了。</span><br />
<span style="font-size: 14pt;">※該ISO檔下載後即可安裝在X86的硬體平台上</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8374" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense002.png" alt="" width="524" height="378" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense002.png 524w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense002-300x216.png 300w" sizes="auto, (max-width: 524px) 100vw, 524px" /></span></p>
<p><span style="font-size: 14pt;">03、選擇光碟開機後的安裝歡迎畫面</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8376" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense003.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense003.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense003-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">04、按下「Accept」繼續安裝步驟</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8378" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense004.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense004.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense004-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">05、用鍵盤上下按鍵挑選「<span style="color: #ff0000;">Install</span>」選項，並用鍵盤Tab鍵切換到「<span style="color: #ff0000;">OK</span>」後，按下鍵盤「Enter」繼續<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8379" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense005.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense005.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense005-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">06、鍵盤設定不變更，採用預設值「<span style="color: #ff0000;">default keymap</span>」，並用鍵盤Tab鍵切換到「<span style="color: #ff0000;">Select</span>」後，按下鍵盤「Enter」繼續<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8381" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense006.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense006.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense006-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">07、磁碟格式選擇，採用預設的「Auto (UFS)」選項，並用鍵盤Tab鍵切換到「<span style="color: #ff0000;">OK</span>」後，按下鍵盤「Enter」繼續</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-8388 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense007.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense007.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense007-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">08、開始安裝的過程畫面</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8386" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense008.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense008.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense008-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">09、等待系統安裝的過程畫面</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8394" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense009.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense009.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense009-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">10、詢問是否有要手動設定系統，用鍵盤Tab鍵切換到「<span style="color: #ff0000;">No</span>」後，按下鍵盤「Enter」繼續</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8395" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense010.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense010.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense010-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">11、用鍵盤Tab鍵切換到「<span style="color: #ff0000;">Reboot</span>」，按下鍵盤「Enter」後會進行重新開機，並完成Pfsense安裝步驟。</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8396" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense011.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense011.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense011-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt; color: #ff0000;"><span style="color: #000000;">※下一單元</span><br />
<span style="color: #000000;">跟小編一起學-Pfsense防火牆-網路介面設定</span><br />
<a href="https://ailog.tw/lifelog/2021/05/23/interface-config/"><span style="color: #000000;">https://ailog.tw/lifelog/2021/05/23/interface-config/</span></a><br />
</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-FortiGate防火牆-維護管理者帳號</title>
		<link>https://ailog.tw/lifelog/2021/01/04/mgmt-user/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 04 Jan 2021 15:41:00 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[add]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[Create]]></category>
		<category><![CDATA[default login]]></category>
		<category><![CDATA[default password]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[user]]></category>
		<category><![CDATA[建立帳號]]></category>
		<category><![CDATA[新增]]></category>
		<category><![CDATA[管理者]]></category>
		<category><![CDATA[腳色]]></category>
		<category><![CDATA[變更密碼]]></category>
		<category><![CDATA[跟小編一起學-FortiGate防火牆-維護管理者帳號]]></category>
		<category><![CDATA[防火牆]]></category>
		<category><![CDATA[預設密碼]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=5881</guid>

					<description><![CDATA[今天小編要介紹的單元是維護FortiGate防火牆的管理者帳號，小編建議設備連上網路前先變更預設帳號的密碼，避 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/01/04/mgmt-user/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-FortiGate防火牆-維護管理者帳號〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>今天小編要介紹的單元是維護FortiGate防火牆的管理者帳號，小編建議設備連上網路前先變更預設帳號的密碼，避免發生資安事件。<span id="more-5881"></span></p>
<p>在接下來的單元，小編會以比較平易近人的web管理畫面優先介紹，但如果你跟小編一樣是指令控的話，在文章後半段也會介紹如果用指令模式來進行設定。</p>
<p>介紹的內容為<br />
透過web管理畫面：<br />
(1)、變更預設帳號的密碼<br />
(2)、新增管理者帳號</p>
<p>透過Console的Command指令模式：<br />
(1)、變更預設帳號的密碼<br />
(2)、新增管理者帳號</p>
<p><strong><br />
[web管理畫面]<br />
一、變更預設帳號的密碼<br />
</strong>(1)、登入系統<br />
預設帳號為admin，預設密碼為空白(無須輸入)，點選「Login」即可登入。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5823 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg" alt="" width="381" height="235" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08.jpg 381w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/FGT-LOGIN-08-300x185.jpg 300w" sizes="auto, (max-width: 381px) 100vw, 381px" /></p>
<p>(2)、開啟系統管理者帳號畫面<br />
點選左邊功能列的「System」選項，接著點選「Administrators」<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5883 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user001.jpg" alt="" width="249" height="231" /></p>
<p>(3)、查看現有管理者帳號<br />
在系統右邊畫面可以看見目前系統的管理者帳號列表，<br />
選擇「帳號名稱」後，點選上方的「Edit」進入帳號的編輯模式。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5885 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user002.jpg" alt="" width="247" height="120" /></p>
<p>(4)、變更帳號的密碼<br />
進入帳號編輯畫面後，點選後方的「Change Password」即可變更密碼。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5884 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user003.jpg" alt="" width="592" height="233" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user003.jpg 592w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user003-300x118.jpg 300w" sizes="auto, (max-width: 592px) 100vw, 592px" /></p>
<p>(5)、變更密碼<br />
在下圖畫面中，分別在「New Password」及「Confirm Password」後方的空格輸入密碼，最後點選「OK」，即可完成密碼變更的程序。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5887 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user004.jpg" alt="" width="598" height="316" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user004.jpg 598w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user004-300x159.jpg 300w" sizes="auto, (max-width: 598px) 100vw, 598px" /><br />
※變更admin的密碼後系統會立即登入，需要透過剛剛建立的新密碼重新登入系統。</p>
<p><strong>二、新增管理者帳號<br />
</strong>(1)、開啟系統管理者帳號畫面<br />
點選左邊功能列的「System」選項，接著點選「Administrators」<strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5921 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user001-1.jpg" alt="" width="249" height="231" /><br />
</strong></p>
<p>(2)、新增帳號<br />
點選「Create New」後接著點選「Administrator」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5924 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user006.jpg" alt="" width="226" height="113" /></p>
<p>(3)、輸入帳號資訊及定義密碼<br />
在「Username」後方輸入要建立的帳號名稱(本範例採用blackjack為帳號名稱)，接著在「New Password」及「Confirm Password」後方的空格輸入密碼。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5925 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user007.jpg" alt="" width="467" height="232" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user007.jpg 467w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user007-300x149.jpg 300w" sizes="auto, (max-width: 467px) 100vw, 467px" /></p>
<p>(4)、設定帳號權限<br />
在「Administrator Profile」選擇「super_admin」這個管理者腳色權限，最後點選「OK」即可完成帳號新增。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5926 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user008.jpg" alt="" width="702" height="327" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user008.jpg 702w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user008-300x140.jpg 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /></p>
<p>(5)、檢查帳號列表<br />
完成帳號新增後，在管理者帳號列表中應該可以看見剛剛建立的帳號。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5928 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user009.jpg" alt="" width="694" height="160" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user009.jpg 694w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user009-300x69.jpg 300w" sizes="auto, (max-width: 694px) 100vw, 694px" /></p>
<p>[Console的Command指令模式]<br />
<strong>一、變更預設帳號的密碼<br />
</strong>(1)、登入系統<br />
預設帳號為「admin」，輸入完畢後按下Enter。<br />
預設密碼為空白(無須輸入)，直接按下Enter即可登入系統<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5930 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user011.jpg" alt="" width="396" height="102" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user011.jpg 396w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user011-300x77.jpg 300w" sizes="auto, (max-width: 396px) 100vw, 396px" /></p>
<p>(2)、進入系統管理者帳號維護模式<br />
輸入「config system admin」接著按下enter送出指令，即可進入系統管理者帳號維護模式<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5931 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user012.jpg" alt="" width="398" height="69" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user012.jpg 398w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user012-300x52.jpg 300w" sizes="auto, (max-width: 398px) 100vw, 398px" /></p>
<p>(3)、檢查現有管理者帳號<br />
輸入「show」接著按下enter送出指令，可將現在所有管理者帳號列表出來，<br />
由下圖可以發現目前只有「admin」這個帳號，且沒有設定密碼。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5932 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user013.jpg" alt="" width="378" height="178" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user013.jpg 378w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user013-300x141.jpg 300w" sizes="auto, (max-width: 378px) 100vw, 378px" /></p>
<p>(4)、變更admin帳號的密碼<br />
輸入「edit admin」接著按下enter送出指令，即可進入帳號編輯模式，<br />
輸入「set password Password」接著按下enter送出指令，即可將管理者帳號admin的密碼邊更為「Password」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5933 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user014.jpg" alt="" width="509" height="79" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user014.jpg 509w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user014-300x47.jpg 300w" sizes="auto, (max-width: 509px) 100vw, 509px" /></p>
<p>(5)、檢查密碼是否完成設定<br />
輸入「next」並按下enter送出指令，即可離開帳號編輯模式，接著輸入「show」並按下enter送出指令，即可查看帳號狀態。<br />
由下圖可了解到，管理者帳號admin已有順利新增密碼。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5934 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user015.jpg" alt="" width="328" height="239" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user015.jpg 328w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user015-300x219.jpg 300w" sizes="auto, (max-width: 328px) 100vw, 328px" /></p>
<p><strong>二、新增管理者帳號<br />
</strong>(1)、進入系統管理者帳號維護模式<br />
輸入「config system admin」接著按下enter送出指令，即可進入系統管理者帳號維護模式<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5931 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user012.jpg" alt="" width="398" height="69" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user012.jpg 398w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user012-300x52.jpg 300w" sizes="auto, (max-width: 398px) 100vw, 398px" /></p>
<p>(2)、新增帳號<br />
輸入「edit 帳號名稱(本範例為blackjack)」並按下enter送出指令，即可新增帳號並進入帳號編輯模式<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5936 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user016.jpg" alt="" width="442" height="73" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user016.jpg 442w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user016-300x50.jpg 300w" sizes="auto, (max-width: 442px) 100vw, 442px" /></p>
<p>(3)、設定帳號權限及定義密碼<br />
輸入「set accprofile &#8220;super_admin&#8221;」並按下enter送出指令，設定腳色權限為管理者。<br />
輸入「set password Password」並按下enter送出指令，設定密碼為「Password(該密碼為範例，請自行定義密碼)」。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5937 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user017.jpg" alt="" width="603" height="95" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user017.jpg 603w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user017-300x47.jpg 300w" sizes="auto, (max-width: 603px) 100vw, 603px" /></p>
<p>(4)、檢查帳號是否完成設定<br />
輸入「next」並按下enter送出指令，即可離開帳號編輯模式，接著輸入「show」並按下enter送出指令，即可查看帳號狀態。<br />
由下圖可了解到，管理者帳號blackjack已順利新增並設定了密碼。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5939 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user018.jpg" alt="" width="365" height="348" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user018.jpg 365w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user018-300x286.jpg 300w" sizes="auto, (max-width: 365px) 100vw, 365px" /></p>
<p>(5)、離開系統管理者帳號維護模式<br />
輸入「end」並按下enter送出指令，即可系統管理者帳號維護模式。<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-5940 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user019.jpg" alt="" width="327" height="97" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user019.jpg 327w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user019-300x89.jpg 300w" sizes="auto, (max-width: 327px) 100vw, 327px" /></p>
<p>※command line模式設定階層說明：在同一階層設定採用「next」進行下一個設定，離開該階層設定採用「end」指令。<br />
以下圖範例說明：<br />
config system admin → 進入第一層<br />
edit admin → 設定帳號，進入第二層<br />
next → 離開帳號設定，回到第一層<br />
edit blackjack → 設定帳號，進入第二層<br />
next → 離開帳號設定，回到第一層<br />
end →離開第一層<br />
<img loading="lazy" decoding="async" class="alignnone size-medium wp-image-5945" src="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user020-300x244.jpg" alt="" width="300" height="244" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user020-300x244.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/01/mgmt-user020.jpg 431w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
