<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Firewall &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Sun, 27 Jul 2025 11:24:52 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>Juniper SRX Firewall Junos 備份及還原步驟</title>
		<link>https://ailog.tw/lifelog/2024/05/13/junos-bak-restore/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 13 May 2024 15:17:18 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Junos]]></category>
		<category><![CDATA[restore]]></category>
		<category><![CDATA[SRX]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17512</guid>

					<description><![CDATA[小編有好多年沒遇到Juniper的防火牆了，就隨手紀錄一下，分享給有需要的網友們。 本篇要介紹的是Junipe &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2024/05/13/junos-bak-restore/" class="more-link">閱讀全文<span class="screen-reader-text">〈Juniper SRX Firewall Junos 備份及還原步驟〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva;">小編有好多年沒遇到Juniper的防火牆了，就隨手紀錄一下，分享給有需要的網友們。</span></p>
<p><span style="font-family: verdana, geneva;">本篇要介紹的是Juniper SRX 防火牆備份及還原Junos的方法。</span></p>
<p><span style="font-family: verdana, geneva;"><span id="more-17512"></span></span></p>
<p><span style="color: #0000ff;"><strong><span style="font-family: verdana, geneva;">[備份Junos]</span></strong></span><br />
<span style="font-family: verdana, geneva;">(1)、準備一個比防火牆內建空間大的隨身碟(建議16GB)</span><br />
<span style="font-family: verdana, geneva;">(2)、將隨身碟格式化成FAT32格式</span><br />
<span style="font-family: verdana, geneva;">(3)、將隨身碟插入要備份系統(韌體)的SRX防火牆設備上</span><br />
<span style="font-family: verdana, geneva;">(4)、透過下方指令進行系統(韌體)備份</span><br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">request system snapshot media usb</span></pre>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-17518 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-01.png" alt="" width="688" height="217" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-01.png 688w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-01-300x95.png 300w" sizes="(max-width: 688px) 100vw, 688px" /></p>
<p>檢查備份是否有成功<br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">show system snapshot media usb</span></pre>
<p><img decoding="async" class="alignnone wp-image-17519 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-02.png" alt="" width="623" height="247" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-02.png 623w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-02-300x119.png 300w" sizes="(max-width: 623px) 100vw, 623px" /></p>
<p>&nbsp;</p>
<p><span style="color: #0000ff;"><strong><span style="font-family: verdana, geneva;">[還原Junos]</span></strong></span><br />
<span style="font-family: verdana, geneva;">(1)、將備份好的USB隨身碟插入要還原系統(韌體)的防火牆<br />
(2)、檢查系統是否可以順利讀取到USB隨身碟<br />
</span><span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">show system snapshot media usb</span></pre>
<p><img decoding="async" class="alignnone wp-image-17519 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-02.png" alt="" width="623" height="247" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-02.png 623w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-02-300x119.png 300w" sizes="(max-width: 623px) 100vw, 623px" /></p>
<p><span style="font-family: verdana, geneva;"><br />
(3)、指令系統改由USB隨身碟進行系統開機<br />
</span><span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">request system reboot media usb
<span style="color: #000000;">Reboot the system ? [yes,no] (no)</span> yes
</span></pre>
<p><span style="font-family: verdana, geneva;"><img decoding="async" class="alignnone wp-image-17521 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-03.png" alt="" width="544" height="239" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-03.png 544w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-03-300x132.png 300w" sizes="(max-width: 544px) 100vw, 544px" /></span></p>
<p><span style="font-family: verdana, geneva;"><br />
(4)、確認系統已是透過USB隨身碟進行開機</span><br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">show system storage partitions</span></pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17522 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-04.png" alt="" width="555" height="333" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-04.png 555w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-04-300x180.png 300w" sizes="auto, (max-width: 555px) 100vw, 555px" /></p>
<p><span style="font-family: verdana, geneva;">(5)、再將目前運作的系統備份至防火牆內建的儲存空間</span><br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">show system storage partitions</span></pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17523 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-05.png" alt="" width="722" height="358" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-05.png 722w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-05-300x149.png 300w" sizes="auto, (max-width: 722px) 100vw, 722px" /></p>
<p><span style="font-family: verdana, geneva;"><br />
(6)、查看系統(韌體)備份是否有成功</span><br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">show system snapshot media internal</span></pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17524 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-06.png" alt="" width="674" height="212" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-06.png 674w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-06-300x94.png 300w" sizes="auto, (max-width: 674px) 100vw, 674px" /></p>
<p><span style="font-family: verdana, geneva;"><br />
(7)、設定防火牆改由內建的儲存空間開機</span><br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>root&gt; <span style="color: #ff0000;">request system reboot media internal</span>
Reboot the system ? [yes,no] (no) <span style="color: #ff0000;">yes</span></pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17525 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-07.png" alt="" width="535" height="256" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-07.png 535w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-07-300x144.png 300w" sizes="auto, (max-width: 535px) 100vw, 535px" /><br />
<span style="color: #ff0000;">※當風扇運作很大聲的時候代表設備已重新開機，將插在設備上的隨身碟拔掉。</span></p>
<p><span style="font-family: verdana, geneva;"><br />
(8)、確認系統已是透過防火牆設備的內建空間進行開機<br />
※當防火牆系統可以順利開機，且版本跟USB隨身碟一致，代表系統(韌體)已還原成功。</span><br />
<span style="font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone wp-image-17526 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-08.png" alt="" width="583" height="215" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-08.png 583w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/junos-bak-restore-08-300x111.png 300w" sizes="auto, (max-width: 583px) 100vw, 583px" /></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Juniper SRX 防火牆基礎設定</title>
		<link>https://ailog.tw/lifelog/2024/05/05/juniper-srx-%e9%98%b2%e7%81%ab%e7%89%86%e5%9f%ba%e7%a4%8e%e8%a8%ad%e5%ae%9a/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 05 May 2024 11:26:54 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[SRX]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17458</guid>

					<description><![CDATA[小編有好多年沒遇到Juniper的防火牆了，就隨手紀錄一下，分享給有需要的網友們。 本篇要介紹的是Junipe &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2024/05/05/juniper-srx-%e9%98%b2%e7%81%ab%e7%89%86%e5%9f%ba%e7%a4%8e%e8%a8%ad%e5%ae%9a/" class="more-link">閱讀全文<span class="screen-reader-text">〈Juniper SRX 防火牆基礎設定〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>小編有好多年沒遇到Juniper的防火牆了，就隨手紀錄一下，分享給有需要的網友們。</p>
<p>本篇要介紹的是Juniper SRX 防火牆基礎設定。</p>
<p><span id="more-17458"></span></p>
<p><span style="color: #3366ff;"><strong>[環境說明]</strong></span><br />
<span style="font-family: verdana, geneva;">Juniper SRX設備型號：Juniper SRX320</span><br />
<span style="font-family: verdana, geneva;">韌體版本：18.4R3-S4.2<br />
WAN端IP設定方式：採用固定IP</span></p>
<p><span style="color: #3366ff;"><strong>[硬體介面說明]</strong></span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17462 size-large" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-1024x312.png" alt="" width="525" height="160" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-1024x312.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-300x91.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-768x234.png 768w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01.png 1409w" sizes="auto, (max-width: 525px) 100vw, 525px" /></p>
<p><span style="font-family: verdana, geneva;">5號介面為網路介面：ge-0/0/0~ge-0/0/5</span><br />
<span style="font-family: verdana, geneva;">ge-0/0/1~ge-0/0/5預設為vlan-trust介面，預設IP為192.168.1.1/24並具有DHCP服務會動發送192.168.1.X的網段IP。</span></p>
<p><span style="color: #3366ff;"><strong>[步驟01]、設定root密碼</strong></span><br />
預設初始值root密碼為空值，因此要先設定root的密碼，否則無法套用設定值。<br />
該步驟建議透過console進行設定會比較快速。<br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>set system root-authentication plain-text-password
commit</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17476 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-1-1.png" alt="" width="574" height="248" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-1-1.png 574w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-01-1-1-300x130.png 300w" sizes="auto, (max-width: 574px) 100vw, 574px" /></p>
<p><strong><span style="font-family: verdana, geneva; color: #3366ff;">[步驟02]、登入防火牆</span></strong><br />
<span style="font-family: verdana, geneva;">(1)、電腦網路卡設定為自動取得IP，並接到Juniper SRX320的ge-0/0/1。<br />
(2)、電腦端透過瀏覽器登入https://192.168.1.1<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17463 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-02.png" alt="" width="590" height="452" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-02.png 590w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-02-300x230.png 300w" sizes="auto, (max-width: 590px) 100vw, 590px" /></span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="color: #3366ff;">[步驟03]、選擇網路環境模式</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17477 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-03.png" alt="" width="801" height="484" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-03.png 801w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-03-300x181.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-03-768x464.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva;"><span style="color: #3366ff;"><strong>[步驟04]、開始透過精靈模式設定防火牆</strong></span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17478 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-04.png" alt="" width="987" height="365" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-04.png 987w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-04-300x111.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-04-768x284.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva;"><span style="color: #3366ff;"><strong>[步驟05]、設定「hostname」及「password」</strong></span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17479 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-05.png" alt="" width="952" height="466" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-05.png 952w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-05-300x147.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-05-768x376.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="color: #3366ff;">[步驟06]、設定「管理Port」IP資訊、「預設閘道」及管理Port可以提供的存取服務</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17480 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-06.png" alt="" width="973" height="632" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-06.png 973w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-06-300x195.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-06-768x499.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><strong><span style="font-family: verdana, geneva; color: #3366ff;">[步驟07]、設定「wan介面Port」、「IP」、「DNS」等資訊</span></strong><span style="font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone wp-image-17488 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-07.png" alt="" width="973" height="704" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-07.png 973w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-07-300x217.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-07-768x556.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="color: #3366ff;">[步驟08]、依據環境需求設定「系統時間及時區」</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17481 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-08.png" alt="" width="975" height="408" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-08.png 975w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-08-300x126.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-08-768x321.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="color: #3366ff;">[步驟09]、如系統有需要多個帳號管理，可以在此步驟新增帳號</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17482 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-09.png" alt="" width="982" height="437" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-09.png 982w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-09-300x134.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-09-768x342.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="color: #3366ff;">[步驟10]、確定設定無誤後，點選「OK」套用設定</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17484 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-10.png" alt="" width="950" height="542" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-10.png 950w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-10-300x171.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-10-768x438.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><strong><span style="font-family: verdana, geneva; color: #3366ff;">[步驟11]、套用設定成功的畫面</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17487 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-11.png" alt="" width="964" height="219" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-11.png 964w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-11-300x68.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-11-768x174.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="color: #3366ff;">[步驟12]、測試PC端是否可以上網</span></strong><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17489 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-12.png" alt="" width="494" height="141" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-12.png 494w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/bconfig-12-300x86.png 300w" sizes="auto, (max-width: 494px) 100vw, 494px" /><br />
</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Juniper SRX Firewall重置root密碼</title>
		<link>https://ailog.tw/lifelog/2024/05/05/juniper-resetpw/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 05 May 2024 08:11:22 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[reset password]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[SRX]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17443</guid>

					<description><![CDATA[小編有好多年沒遇到Juniper的防火牆了，就隨手紀錄一下，分享給有需要的網友們。 本篇要介紹的是如何rese &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2024/05/05/juniper-resetpw/" class="more-link">閱讀全文<span class="screen-reader-text">〈Juniper SRX Firewall重置root密碼〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>小編有好多年沒遇到Juniper的防火牆了，就隨手紀錄一下，分享給有需要的網友們。</p>
<p>本篇要介紹的是如何reset JunOS(Junos OS)的root密碼，透過該方式重新設定密碼，原本的設定檔案並不會消失，請放心服用。</p>
<p><span id="more-17443"></span></p>
<p><span style="font-family: verdana, geneva;">[步驟一]：進入「loader」模式<br />
透過console模式在開機過程：</span><br />
<span style="font-family: verdana, geneva;">看到「<span style="color: #ff0000;">Hit [Enter] to boot immediately, or space bar for command prompt</span>」就趕快按下空白按鍵，接著就可以看到「loader&gt;」的等待畫面</span><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17444 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-01.png" alt="" width="669" height="274" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-01.png 669w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-01-300x123.png 300w" sizes="auto, (max-width: 669px) 100vw, 669px" /></p>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva;">[步驟二]：進入「單人模式」<br />
指令語法：</span></p>
<pre>boot -s</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17447 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-02.png" alt="" width="627" height="320" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-02.png 627w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-02-300x153.png 300w" sizes="auto, (max-width: 627px) 100vw, 627px" /></p>
<p>&nbsp;</p>
<p><span style="font-family: verdana, geneva;">[步驟三]：進入「還原模式」<br />
</span><span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>recovery</pre>
<p><span style="font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone wp-image-17448 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-03.png" alt="" width="955" height="209" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-03.png 955w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-03-300x66.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-03-768x168.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p>&nbsp;</p>
<p>[步驟四]：進入「設定模式」<br />
<span style="font-family: verdana, geneva;">指令語法：</span></p>
<pre>configure</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17451 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-04.png" alt="" width="427" height="211" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-04.png 427w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-04-300x148.png 300w" sizes="auto, (max-width: 427px) 100vw, 427px" /></p>
<p>&nbsp;</p>
<p>[步驟五]：重新設定密碼<br />
<span style="font-family: verdana, geneva; font-size: 1rem;">指令語法：</span></p>
<pre>set system root-authentication plain-text-password</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17452 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-05.png" alt="" width="561" height="193" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-05.png 561w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-05-300x103.png 300w" sizes="auto, (max-width: 561px) 100vw, 561px" /><br />
<span style="color: #ff0000;">※過程會要求輸入新的root密碼</span></p>
<p>&nbsp;</p>
<p>[步驟六]：確認設定<br />
<span style="font-family: verdana, geneva; font-size: 1rem;">指令語法：</span></p>
<pre>commit</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17454 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-07.png" alt="" width="526" height="253" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-07.png 526w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-07-300x144.png 300w" sizes="auto, (max-width: 526px) 100vw, 526px" /></p>
<p>[步驟七]：離開設定模式並重新開機<br />
<span style="font-family: verdana, geneva; font-size: 1rem;">指令語法：</span></p>
<pre>exit</pre>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-17453 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-06.png" alt="" width="271" height="159" /><br />
※連續輸入兩次exit後，即可離開設定模式，並且重新開機。</p>
<p>[步驟八]：使用新的root密碼登入設備<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-17456 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-08.png" alt="" width="493" height="243" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-08.png 493w, https://ailog.tw/lifelog/wp-content/uploads/2024/05/resetpw-08-300x148.png 300w" sizes="auto, (max-width: 493px) 100vw, 493px" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>讓Pfsense防火牆也有判別國家IP(GEO IP)的能力</title>
		<link>https://ailog.tw/lifelog/2023/08/13/pfsense-country-ip/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 13 Aug 2023 14:25:07 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[country IP]]></category>
		<category><![CDATA[GEO IP]]></category>
		<category><![CDATA[國家IP]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=16517</guid>

					<description><![CDATA[使用過新世代防火牆設備的夥伴們一定知道，這些設備均有判別國家IP來源(GEO IP)的功能，但Pfsense這 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2023/08/13/pfsense-country-ip/" class="more-link">閱讀全文<span class="screen-reader-text">〈讓Pfsense防火牆也有判別國家IP(GEO IP)的能力〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 18px;">使用過新世代防火牆設備的夥伴們一定知道，這些設備均有判別國家IP來源(GEO IP)的功能，但Pfsense這一套軟體式防火牆似乎還沒內建(Opnsense倒是已有內建這樣的功能)，因此小編今天要來介紹如何讓pfsense擁有過濾來源國別IP的能力。</span></p>
<p><span style="font-size: 18px;"><span id="more-16517"></span></span></p>
<p><span style="color: #0000ff; font-size: 18px;"><strong>一、情境</strong></span><br />
<span style="font-family: verdana, geneva; font-size: 18px;">Pfsense：2.2.4-RELEASE</span></p>
<p><span style="font-size: 18px;"><strong><span style="color: #0000ff;">二、IP情資來源</span></strong></span><br />
<span style="font-size: 18px;">官網</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://github.com/herrbischoff">https://github.com/herrbischoff</a></span></p>
<p><span style="font-size: 18px;">國家IP專案頁面：</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://github.com/herrbischoff/country-ip-blocks/tree/master/ipv4">https://github.com/herrbischoff/country-ip-blocks/tree/master/ipv4</a></span></p>
<p><span style="font-size: 18px;">舉例幾個範例國別的連結：</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;">[Japan]</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/jp.cidr">https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/jp.cidr</a></span></p>
<p><span style="font-family: verdana, geneva; font-size: 18px;">[Taiwan]</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><a href="https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/tw.cidr">https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/tw.cidr</a></span></p>
<p><span style="font-size: 18px;"><strong>三、Pfsense設定國別IP清單</strong></span><br />
<span style="font-size: 18px;">01、點選「Firewall」→「Aliases」</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16518 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip01.png" alt="" width="195" height="231" /></span></p>
<p><span style="font-size: 18px;">02、點選「URLs」頁面</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16519 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip02.png" alt="" width="707" height="260" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip02.png 707w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip02-300x110.png 300w" sizes="auto, (max-width: 707px) 100vw, 707px" /></span></p>
<p><span style="font-size: 18px;">03、輸入設定值</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><span style="color: #ff0000;">Name：</span><br />
輸入可識別的名稱<br />
</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><span style="color: #ff0000;">Description：</span><br />
輸入註解名稱<br />
</span><br />
<span style="font-family: verdana, geneva; font-size: 18px;"><span style="color: #ff0000;">Type：</span><br />
選擇URL Table (IPs)<br />
</span><br />
<span style="font-size: 18px;"><span style="font-family: verdana, geneva;"><span style="color: #ff0000;">在「URL Table (IPs)」欄位輸入參考網址所取得的url：</span><br />
</span>https://raw.githubusercontent.com/herrbischoff/country-ip-blocks/master/ipv4/tw.cidr</span></p>
<p><span style="color: #ff0000; font-size: 18px;">Update Freq. (days)：</span><br />
<span style="font-size: 18px;">選擇資料來源的更新頻率(以天為單位)</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16520 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip03.png" alt="" width="592" height="465" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip03.png 592w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip03-300x236.png 300w" sizes="auto, (max-width: 592px) 100vw, 592px" /></span></p>
<p><span style="font-size: 18px;">04、資料確認無誤的話，點選「Apply Changes」套用設定</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16522 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04.png" alt="" width="897" height="252" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04.png 897w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04-300x84.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip04-768x216.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 18px;">05、接著到「Firewall」→「Rules」或「NAT」</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-16523" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip05.png" alt="" width="210" height="288" /></span></p>
<p><span style="font-size: 18px;">06、在Source欄位，將「Type」選擇「Single host or alias」，在「Address」欄位輸入先前Aliases步驟所新增的物件名稱</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16524 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06.png" alt="" width="834" height="660" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06.png 834w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06-300x237.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip06-768x608.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 18px;">07、防火牆規則設定完畢的狀態</span><br />
<span style="font-size: 18px;"><img loading="lazy" decoding="async" class="alignnone wp-image-16526 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07.png" alt="" width="1336" height="261" srcset="https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07.png 1336w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07-300x59.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07-1024x200.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2023/08/pfsense-country-ip07-768x150.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FortiGate防火牆-設備產品生命週期(2022-10-15更新)</title>
		<link>https://ailog.tw/lifelog/2022/10/15/fortigate-life-cycle2022/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 15 Oct 2022 09:22:11 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[EOO]]></category>
		<category><![CDATA[EOS]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[保固]]></category>
		<category><![CDATA[停產]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13946</guid>

					<description><![CDATA[Product Life Cycle就是設備產品生命週期，選購資訊產品時應該要注意一下這個資訊，避免購買到即將 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/10/15/fortigate-life-cycle2022/" class="more-link">閱讀全文<span class="screen-reader-text">〈FortiGate防火牆-設備產品生命週期(2022-10-15更新)〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p class="gray"><span style="font-size: 12pt;">Product Life Cycle就是設備產品生命週期，選購資訊產品時應該要注意一下這個資訊，避免購買到即將停止服務或更新的產品，尤其是資安設備(小編就吃過一次虧&#8230;.買完隔年就EOS了&gt;&lt;)。</span></p>
<p><span id="more-13946"></span></p>
<p>EOO(End of Order Date)：<br />
中止接受訂單日期，不過這是原廠的日期，通常SI或代理商會把日期往前推，避免遇到無法出貨的狀況。</p>
<p>LSED(Last Service Extension Date)：<br />
最後服務展延日期，指的是如果有購買維護合約這是日期是最後可以下單的日期，且購買的延伸保固服務日期不得超過EOS日期。</p>
<p>EOS(End of Support Date)：<br />
產品服務中止日期，也就是宣告這個產品的中止了，如果遇到設備故障或有Bug，那就只能重新採購新產品而無法得到相關服務了。</p>
<p>FortiGate防火牆設備產品生命週期(2022-10-15更新)<br />
※如資訊有誤以原廠資訊為主</p>
<table width="756">
<tbody>
<tr>
<td width="316"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate產品型號</span></strong></td>
<td width="147"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">可接受訂單日期</span></strong></td>
<td width="182"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">訂閱服務最後日期</span></strong></td>
<td width="111"><strong><span style="font-size: 10pt; font-family: verdana, geneva;">中止服務日期</span></strong></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-60D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-09-23</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-09-23</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-09-23</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-60E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-12-29</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-12-29</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-12-29</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-70D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2017-07-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-07-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-07-16</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-80D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-04-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-04-16</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-04-16</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-80E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-08-17</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-90D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-10-14</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-10-14</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-10-14</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-90E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2020-04-15</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2024-04-15</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-04-15</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-100D</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2018-07-26</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2022-07-26</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2023-07-26</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-100E</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2021-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2025-08-17</span></td>
<td><span style="font-family: verdana, geneva; font-size: 10pt;">2026-08-17</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-200D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-05-22</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-05-22</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-05-22</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-300D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-10-11</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-10-11</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-10-11</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-300E</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2021-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2025-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2026-07-15</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-500D</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2018-05-08</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2022-05-08</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2023-05-08</span></td>
</tr>
<tr>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">FortiGate-500E</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2021-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2025-07-15</span></td>
<td><span style="font-size: 10pt; font-family: verdana, geneva;">2026-07-15</span></td>
</tr>
</tbody>
</table>
<p>原廠產品生命週期查詢網頁(需要登入帳號才可查詢)<br />
<a href="https://support.fortinet.com/Information/ProductLifeCycle.aspx">https://support.fortinet.com/Information/ProductLifeCycle.aspx</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>VMware Esxi host Server啟動防火牆</title>
		<link>https://ailog.tw/lifelog/2022/08/29/esxi-fw/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Mon, 29 Aug 2022 04:27:20 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[ESXi Server]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<category><![CDATA[防火牆]]></category>
		<category><![CDATA[零信任]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13353</guid>

					<description><![CDATA[近年來Zero Trust議題逐漸被重視，防範的惡意連結不在只有公司外部對內的連線，內部網路的連線應該也要有適 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/08/29/esxi-fw/" class="more-link">閱讀全文<span class="screen-reader-text">〈VMware Esxi host Server啟動防火牆〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">近年來Zero Trust議題逐漸被重視，防範的惡意連結不在只有公司外部對內的連線，內部網路的連線應該也要有適當的管制，避免有惡意行為的跳板機從內部網路發動攻擊。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">小編今天要來介紹如何啟動VMware Esxi Host Server的內建防火牆，以確保管理服務只有被授權的IP存取。<span id="more-13353"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">環境：VMware Esxi 7.0.2</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">Set01、確認防火牆狀態</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">指令：</span></p>
<pre><span style="font-size: 16px;">esxcli network firewall get</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><br />
<img loading="lazy" decoding="async" class="alignnone wp-image-13364 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-01.png" alt="" width="411" height="64" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-01.png 411w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-01-300x47.png 300w" sizes="auto, (max-width: 411px) 100vw, 411px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">Set02、啟動防火牆</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">指令：</span></p>
<pre><span style="font-size: 16px;">esxcli network firewall set --enabled true</span></pre>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13365 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-02.png" alt="" width="473" height="102" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-02.png 473w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-02-300x65.png 300w" sizes="auto, (max-width: 473px) 100vw, 473px" /><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">Set03、設定服務可連線的IP</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(a).點選ESXi主機左方選單的「網路」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13366 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-03.png" alt="" width="237" height="248" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(b).點選右邊畫面的「防火牆規則」頁面，接著搜尋要設定防火牆的服務(本範例是設定443Port的Web管理畫面連線)，透過選取確認要設定的服務，接著點選「編輯設定」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13367 " src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04.png" alt="" width="802" height="267" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04.png 893w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04-300x100.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-04-768x255.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(c).點選「僅允許從下列的網路連線」，輸入要放行的IP，完成IP輸入後點選「確定」套用設定。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13368 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-05.png" alt="" width="450" height="342" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-05.png 450w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-05-300x228.png 300w" sizes="auto, (max-width: 450px) 100vw, 450px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(d).最後檢查該服務的防火牆規則是否有「啟用」， 滑鼠指著要確認的服務，接著按下滑鼠右鍵，如果有看見「啟用」選項，就點選「啟用」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">如果看見「停用」，代表防火牆規則已啟用無須變更設定。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13369 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06.png" alt="" width="773" height="158" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06.png 773w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06-300x61.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-06-768x157.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">補充說明：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">如果防火牆規則有誤設定，導致無法連入VMware ESXi主機，此時需要到實體Server機的Console面前設定ESXi Server啟動「Troubleshooting Options」。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13371 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-07.png" alt="" width="629" height="401" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-07.png 629w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-07-300x191.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">選擇「Enable ESXi Shell」</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-13372 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-08.png" alt="" width="499" height="156" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-08.png 499w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/esxi-fw-08-300x94.png 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">接著在鍵盤輸入「Ctrl」+「Alt」+「F1」，切換到本機的Console命令提示畫面，通過管理者帳號密碼驗證後，接著透過指令將防火牆關閉，即可重新連線ESXi Server並重新設定防火牆規則。</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">關閉防火牆</span><span style="font-family: verdana, geneva; font-size: 14pt;">指令：</span></p>
<pre><span style="font-size: 16px;">esxcli network firewall set --enabled false</span></pre>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-系統線上版本更新</title>
		<link>https://ailog.tw/lifelog/2021/05/29/pfsense-online-update/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 29 May 2021 10:11:51 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[online update]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[更新]]></category>
		<category><![CDATA[線上更新]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-系統線上版本更新]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8551</guid>

					<description><![CDATA[本篇要介紹的是Pfsense系統線上版本更新，快跟著小編一起來了解吧! 01、登入系統後點選「System」→ &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/29/pfsense-online-update/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-系統線上版本更新〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">本篇要介紹的是Pfsense系統線上版本更新，快跟著小編一起來了解吧!<span id="more-8551"></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">01、登入系統後點選「<span style="color: #ff0000;">System</span>」→「<span style="color: #ff0000;">Update</span>」<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8554" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-01.png" alt="" width="357" height="368" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-01.png 357w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-01-291x300.png 291w" sizes="auto, (max-width: 357px) 100vw, 357px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">02、點選「Confirm」進行系統更新</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">※由下圖畫面可得知，目前系統的版本為「<span style="color: #ff0000;">2.4.5_1</span>」，可更新的版本為「<span style="color: #ff0000;">2.5.1</span>」<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8555" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-02.png" alt="" width="607" height="365" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-02.png 607w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-02-300x180.png 300w" sizes="auto, (max-width: 607px) 100vw, 607px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">03、下圖為系統更新過程畫面，畫面上有提示更新過程會耗費數分鐘，並請<span style="color: #ff0000;">勿關閉視畫面窗或重新整理該視窗畫面</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8556" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03.png" alt="" width="949" height="360" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03.png 949w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03-300x114.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-03-768x291.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">04、該畫面表示系統正在做背景更新，請稍後。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8557" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-04.png" alt="" width="635" height="139" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-04.png 635w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-04-300x66.png 300w" sizes="auto, (max-width: 635px) 100vw, 635px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">如果此時到Pfsense系統的Console畫面可以看到正在努力的跑更新中。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8558" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-05.png" alt="" width="501" height="147" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-05.png 501w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-05-300x88.png 300w" sizes="auto, (max-width: 501px) 100vw, 501px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">04、當畫面自動變更為系統登入畫面時，代表系統已順利更新完畢。</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8559" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-06.png" alt="" width="329" height="435" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-06.png 329w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-06-227x300.png 227w" sizes="auto, (max-width: 329px) 100vw, 329px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">05、登入系統後確認版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">※下圖為順利完成更新至<span style="color: #ff0000;">2.5.1</span>的畫面</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8560" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-07.png" alt="" width="470" height="428" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-07.png 470w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/pfsense-update-07-300x273.png 300w" sizes="auto, (max-width: 470px) 100vw, 470px" /></span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-網路介面設定</title>
		<link>https://ailog.tw/lifelog/2021/05/23/interface-config/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 23 May 2021 14:50:19 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[config]]></category>
		<category><![CDATA[DHCP]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[NAT]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[WAN]]></category>
		<category><![CDATA[設定介面IP]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-網路介面設定]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8422</guid>

					<description><![CDATA[上一篇已經介紹過Pfsense的系統安裝，本篇要介紹的是網路介面的IP設定，快跟著小編一起來了解吧! 假設情境 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/23/interface-config/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-網路介面設定〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">上一篇已經介紹過<a href="https://ailog.tw/lifelog/2021/05/22/pfsense-install/">Pfsense的系統安裝</a>，本篇要介紹的是網路介面的IP設定，快跟著小編一起來了解吧!<span id="more-8422"></span></span></p>
<p><span style="font-size: 14pt;">假設情境網路架構圖</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8442" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense000.png" alt="" width="531" height="366" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense000.png 531w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense000-300x207.png 300w" sizes="auto, (max-width: 531px) 100vw, 531px" /></span></p>
<p><span style="font-size: 14pt;">01、第一次開機時畫面，此時詢問是否設定VLAN，輸入「<span style="color: #ff0000;">n</span>」後按下Enter</span><br />
<span style="font-size: 14pt;">※注意畫面中的資訊，系統有偵測到兩張網路卡分別為「<span style="color: #ff0000;">hn0</span>」及「<span style="color: #ff0000;">hn1</span>」，該資訊下一步驟設定會使用到</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8397" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense012.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense012.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense012-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">02、接著設定WAN端(外部網路)的網路卡介面代號，輸入系統畫面上偵測到的網路卡代號，哪一張做為WAN端網路卡都沒關係，但網路線別接錯就好，這一個介面通常是連接到外端設備，例如：ATUR(小烏龜設備)。<br />
本範例採用<span style="color: #ff0000;">hn0</span>當作WAN網路介面，因此輸入「<span style="color: #ff0000;">hn0</span>」後按下Enter繼續設定步驟。</span><br />
<span style="color: #ff0000; font-size: 14pt;">※不同的網路卡晶片會有不同的網路卡代號，請自行變更為相對應的設定值，勿直接跟著本範例輸入hn0</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8398" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense013.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense013.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense013-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">03、接著設定LAN端(內部網路)的網路卡介面代號，輸入系統畫面上偵測到的網路卡代號，這一個介面通常是連接到內部的設備，例如：Switch或Wifi AP設備上。<br />
本範例採用<span style="color: #ff0000;">hn1</span>當作WAN網路介面，因此輸入「<span style="color: #ff0000;">hn1</span>」後按下Enter繼續設定步驟。<br />
<span style="color: #ff0000;">※不同的網路卡晶片會有不同的網路卡代號，請自行變更為相對應的設定值，勿直接跟著本範例輸入hn1</span></span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8399" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense014.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense014.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense014-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">04、再次確認網路卡相關配置，沒問題後輸入「<span style="color: #ff0000;">y</span>」後按下Enter繼續</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8400" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense015.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense015.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense015-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">05、該畫面為登入系統後的Console主選單畫面。<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8402" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense016.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense016.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense016-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /><br />
各項功能如下：<br />
<span style="font-family: verdana, geneva;">0)、登入(透過SSH登入時使用)</span><br />
<span style="font-family: verdana, geneva;">1)、定義網路介面卡</span><br />
<span style="font-family: verdana, geneva;">2)、設定網路介面的IP</span><br />
<span style="font-family: verdana, geneva;">3)、重置網頁設定的密碼</span><br />
<span style="font-family: verdana, geneva;">4)、還原為原廠/出廠設定值</span><br />
<span style="font-family: verdana, geneva;">5)、重開機</span><br />
<span style="font-family: verdana, geneva;">6)、關機</span><br />
<span style="font-family: verdana, geneva;">7)、ping測試其他電腦</span><br />
<span style="font-family: verdana, geneva;">8)、進入Shell命令提示字元模式</span><br />
<span style="font-family: verdana, geneva;">9)、執行Pf客製TOP</span><br />
<span style="font-family: verdana, geneva;">10)、過濾log</span><br />
<span style="font-family: verdana, geneva;">11)、重新啟動網頁設定</span><br />
<span style="font-family: verdana, geneva;">12)、執行PHP命令及pfSense工具</span><br />
<span style="font-family: verdana, geneva;">13)、在命令提示字元下更新系統</span><br />
<span style="font-family: verdana, geneva;">14)、啟動SSH服務</span><br />
<span style="font-family: verdana, geneva;">15)、恢復近期的設定值</span><br />
<span style="font-family: verdana, geneva;">16)、重新啟動PHP-FPM</span><br />
</span></p>
<p><span style="font-size: 14pt;">06、輸入「<span style="color: #ff0000;">2</span>」後按下Enter，進行網路介面IP設定</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8401" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense017.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense017.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense017-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">07、輸入「<span style="color: #ff0000;">2</span>」後按下Enter，設定LAN的網路介面IP</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8403" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense018.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense018.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense018-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">08、輸入LAN網路介面所配置的IP，本範例輸入「<span style="color: #ff0000;">192.168.168.254</span>」後按下Enter繼續設定<br />
<span style="color: #ff0000;">※192.168.168.254為本範例情境LAN網路介面所配置的IP，請自行變更為實際狀況所需的LAN(內部網路)介面IP，勿直接跟著本範例輸入</span></span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8405" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense019.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense019.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense019-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">09、以CIDR格式輸入LAN網路介面所配置的子遮罩，本範例輸入「<span style="color: #ff0000;">24</span>」後按下Enter繼續設定<br />
<span style="color: #ff0000;">※24為本範例情境的子遮罩，請自行變更為實際狀況所需的LAN(內部網路)介面IP，勿直接跟著本範例輸入<br />
</span>CIDR數字所代表的子遮罩</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">24 = 255.255.255.0 (通常居家環境都是選這個)</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">25 = 255.255.255.128</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">26 = 255.255.255.192</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">27 = 255.255.255.224</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">28 = 255.255.255.240</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">29 = 255.255.255.248</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">30 = 255.255.255.252</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">31 = 255.255.255.254</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">32 = 255.255.255.255</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8404" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense020.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense020.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense020-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">10、輸入LAN(內部網路)的gateway閘道IP，直接按下Enter略過設定，之後有需要在web介面再進行設定</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8406" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense021.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense021.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense021-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">11、輸入LAN(內部網路)的IPv6 IP，直接按下Enter略過設定，之後有需要在web介面再進行設定</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8407" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense022.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense022.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense022-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">12、詢問是否設定內部網路的DHCP自動配發IP服務，輸入「<span style="color: #ff0000;">y</span>」後按下Enter繼續設定<br />
<span style="color: #ff0000;">※內部網路是否需要啟動DHCP服務，請自行依據實際狀況進行設定，勿直接跟著本範例，通常內部網路只會啟動一個DHCP服務，如果您的內部網路已有DHCP服務，就不該再啟動另一台DHCP服務避免IP配發衝突的狀況。</span></span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8408" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense023.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense023.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense023-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">13、輸入DHCP服務發放IP區間的起始值，本範例輸入「<span style="color: #ff0000;">192.168.168.1</span>」，該範圍可以依據實際狀況上去設定範圍</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8409" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense024.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense024.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense024-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">14、輸入DHCP服務發放IP區間的結束值，本範例輸入「<span style="color: #ff0000;">192.168.168.10</span>」，該範圍可以依據實際狀況上去設定範圍</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8410" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense025.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense025.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense025-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">15、輸入「<span style="color: #ff0000;">y</span>」套用LAN網路介面的新IP</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8411" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense026.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense026.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense026-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">16、提示LAN網路介面新IP已生效，可以透過瀏覽器連線該IP進行系統登入，按下「<span style="color: #ff0000;">enter</span>」後可以返回Console功能選單畫面。</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8412" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense027.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense027.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense027-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">17、到該步驟已完成LAN內部網路介面IP的設定，並提供內部網路DHCP服務自動派送 192.168.168.1~10區間的IP</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8413" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense028.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense028.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense028-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">18、到網路架構圖的PC端，驗證是否有自動取得IP<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8445" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-01.png" alt="" width="516" height="149" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-01.png 516w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-01-300x87.png 300w" sizes="auto, (max-width: 516px) 100vw, 516px" /><br />
</span></p>
<p><span style="font-size: 14pt;">19、測試PC端透過ping測試是否可以連線到Pfsense的Lan段IP</span><br />
<span style="font-size: 14pt;">ping 192.168.168.254</span><br />
<span style="color: #ff0000; font-size: 14pt;">※192.168.168.254為本範例Pfsense的Lan端IP，請自行變更為實際狀況的IP進行測試。</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8446" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-02.png" alt="" width="415" height="129" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-02.png 415w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-02-300x93.png 300w" sizes="auto, (max-width: 415px) 100vw, 415px" /></span></p>
<p>20、透過瀏覽器登入pfsense系統，推薦使用Google Chrome或Firefox瀏覽器<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8448" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-03.png" alt="" width="346" height="157" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-03.png 346w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-03-300x136.png 300w" sizes="auto, (max-width: 346px) 100vw, 346px" /></p>
<p>21、輸入預設的帳號密碼登入pfsense系統<br />
預設帳號：admin<br />
預設密碼：pfsense<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8449" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-04.png" alt="" width="350" height="254" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-04.png 350w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-04-300x218.png 300w" sizes="auto, (max-width: 350px) 100vw, 350px" /></p>
<p>22、變更管理者密碼<br />
(1)、登入後系統上方的功能選單下，會有變更管理者密碼的提示，點選「Change the password in the User Manager」變更密碼。<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8450" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05.png" alt="" width="834" height="122" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05.png 834w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05-300x44.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-05-768x112.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>(2)、輸入admin帳號新的密碼<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8456" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-06.png" alt="" width="611" height="173" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-06.png 611w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-06-300x85.png 300w" sizes="auto, (max-width: 611px) 100vw, 611px" /></p>
<p>(3)、點選最下方的「SAVE」進行密碼變更儲存<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8457" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-07.png" alt="" width="355" height="134" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-07.png 355w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-07-300x113.png 300w" sizes="auto, (max-width: 355px) 100vw, 355px" /></p>
<p>23、變更WAN介面卡IP<br />
(1)、點選「Interfaces」→「WAN」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8458" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-08.png" alt="" width="252" height="177" /></p>
<p>(2)、設定WAN網路介面為固定IP方式<br />
a.確認「EnableInterface」有勾選<br />
b.將「IPv4 Configuration Type」選項變更為「Static IPv4」<br />
c.將「IPv6 Configuration Type」選項變更為「None」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8459" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-09.png" alt="" width="543" height="238" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-09.png 543w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-09-300x131.png 300w" sizes="auto, (max-width: 543px) 100vw, 543px" /><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8461" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-10.png" alt="" width="559" height="246" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-10.png 559w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-10-300x132.png 300w" sizes="auto, (max-width: 559px) 100vw, 559px" /></p>
<p>(3)、在下方「Static IPv4 Configuration」區域設定WAN網路介面的固定IP資訊<br />
a.在「IPv4 Address」欄位輸入「192.192.205.205」，後方「/」下拉選項選擇「24」<br />
b.點選「IPv4 Upstream gateway」後方的「Add a new gateway」新增WAN端得預設閘道IP<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8462" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11.png" alt="" width="864" height="178" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11.png 864w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11-300x62.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-11-768x158.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>(4)、在「Gateway IPv4」欄位輸入本範例的WAN預設閘道IP「192.192.205.254」，並點選「Add」完成新增步驟<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8463" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-12.png" alt="" width="328" height="317" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-12.png 328w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-12-300x290.png 300w" sizes="auto, (max-width: 328px) 100vw, 328px" /></p>
<p>(5)、確認「IPv4 Upstream gateway」欄位有順利完成設定<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8464" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13.png" alt="" width="832" height="134" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13.png 832w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13-300x48.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-13-768x124.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>(6)、在該設定頁面最下方點選「Save」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8465" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-14.png" alt="" width="292" height="325" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-14.png 292w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-14-270x300.png 270w" sizes="auto, (max-width: 292px) 100vw, 292px" /></p>
<p>(7)、在該設定頁面最上方點選選「<span style="color: #ff0000;">Apply Changes</span>」完成設定<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8466" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-15.png" alt="" width="594" height="111" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-15.png 594w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-15-300x56.png 300w" sizes="auto, (max-width: 594px) 100vw, 594px" /></p>
<p>24、設定DNS<br />
(1)、點選「System」→「General Setup」<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8468" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-16.png" alt="" width="346" height="157" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-16.png 346w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-16-300x136.png 300w" sizes="auto, (max-width: 346px) 100vw, 346px" /></p>
<p>(2)、在「DNS Server Settings」新增一組DNS資訊。<br />
在DNS Servers後方依序輸入「168.95.1.1」、「Hinet」、選擇「WAN端的預設閘道」，並點選「Add DNS Server」新增次要DNS設定<br />
<span style="color: #ff0000;">※該設定並非固定值，請自行依據實際的狀況輸入主要DNS資訊</span><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8469" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-17.png" alt="" width="618" height="350" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-17.png 618w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-17-300x170.png 300w" sizes="auto, (max-width: 618px) 100vw, 618px" /></p>
<p>(3)、在新增的欄位後方依序輸入「8.8.8.8」、「google」、選擇「WAN端的預設閘道」<br />
<span style="color: #ff0000;">※該設定並非固定值，請自行依據實際的狀況輸入次要DNS資訊</span><br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8470" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-18.png" alt="" width="728" height="133" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-18.png 728w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-18-300x55.png 300w" sizes="auto, (max-width: 728px) 100vw, 728px" /></p>
<p>(4)、在該頁面的最下方點選「Save」，進行DNS設定存檔<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8471" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-19.png" alt="" width="551" height="196" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-19.png 551w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-19-300x107.png 300w" sizes="auto, (max-width: 551px) 100vw, 551px" /></p>
<p>(5)、看見「The changes have been applied successfully.」代表DNS設定已順利完成變更<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8472" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-20.png" alt="" width="329" height="122" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-20.png 329w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense-config-20-300x111.png 300w" sizes="auto, (max-width: 329px) 100vw, 329px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>跟小編一起學-Pfsense防火牆-系統安裝</title>
		<link>https://ailog.tw/lifelog/2021/05/22/pfsense-install/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 22 May 2021 14:38:54 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[install]]></category>
		<category><![CDATA[iso]]></category>
		<category><![CDATA[Pfsense]]></category>
		<category><![CDATA[光碟開機]]></category>
		<category><![CDATA[安裝]]></category>
		<category><![CDATA[跟小編一起學-Pfsense防火牆-系統安裝]]></category>
		<category><![CDATA[防火牆]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8370</guid>

					<description><![CDATA[Pfsense是一套開源免費版軟體式防火牆，以FreeBSD系統為核心，可以安裝在X86的硬體上，當然安裝在一 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/22/pfsense-install/" class="more-link">閱讀全文<span class="screen-reader-text">〈跟小編一起學-Pfsense防火牆-系統安裝〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt;">Pfsense是一套開源免費版軟體式防火牆，以FreeBSD系統為核心，可以安裝在X86的硬體上，當然安裝在一般的PC也是沒問題，擁有相當良好的硬體移轉特性，因此很適合中小企業/家庭/社區使用，小編使用該軟體也有相當久的時間了，表現相當的傑出、也相當的穩定，推薦給大家試試看。<span id="more-8370"></span></span></p>
<p><span style="font-size: 14pt;">官網：</span><br />
<span style="font-size: 14pt;"><a href="https://www.pfsense.org/">https://www.pfsense.org/</a></span></p>
<p><span style="font-size: 14pt;">軟體下載快速連結：</span><br />
<span style="font-size: 14pt;"><a href="https://www.pfsense.org/download/">https://www.pfsense.org/download/</a></span></p>
<p><span style="font-size: 14pt;">適合安裝的平台(無論是實體機或是虛擬機，均需要準備<span style="color: #ff0000;">兩張網路卡</span>)：</span><br />
<span style="font-size: 14pt;">個人電腦(PC)、伺服器硬體(HP、Dell、Lenovo等Server)、VMware ESXi、Microsoft Hyper-V、Linux KVM</span></p>
<p><span style="font-size: 14pt;">小編為何會特別說該系統的「硬體移轉特性」十分的良好，是因為如果時體機硬體發生故障時，將系統移轉到其他硬體後，只要可以順利開機、網路卡可以被pfsense識別的到，接著重新定義LAN(內部網路介面)及WAN(外部網路介面)的網路卡就可以恢復服務瞜。</span></p>
<p><span style="font-size: 14pt;">小編最近忙翻了，詞窮&#8230;&#8230;廢話不多說，趕快開始。</span></p>
<p><span style="font-size: 14pt;">01、連線到官網，點選「Download」切換到軟體下載頁面<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8373" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001.png" alt="" width="779" height="175" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001.png 779w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001-300x67.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense001-768x173.png 768w" sizes="auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-size: 14pt;">02、小編安裝時最新的版本是2.4.5，安裝平台選擇「<span style="color: #ff0000;">AMD64</span>」即是64位元的系統，安裝媒體選擇<span style="color: #ff0000;">ISO</span>檔案格式，下載來源就採用預設不特別挑選了。</span><br />
<span style="font-size: 14pt;">※該ISO檔下載後即可安裝在X86的硬體平台上</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8374" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense002.png" alt="" width="524" height="378" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense002.png 524w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense002-300x216.png 300w" sizes="auto, (max-width: 524px) 100vw, 524px" /></span></p>
<p><span style="font-size: 14pt;">03、選擇光碟開機後的安裝歡迎畫面</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8376" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense003.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense003.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense003-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">04、按下「Accept」繼續安裝步驟</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8378" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense004.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense004.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense004-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">05、用鍵盤上下按鍵挑選「<span style="color: #ff0000;">Install</span>」選項，並用鍵盤Tab鍵切換到「<span style="color: #ff0000;">OK</span>」後，按下鍵盤「Enter」繼續<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8379" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense005.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense005.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense005-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">06、鍵盤設定不變更，採用預設值「<span style="color: #ff0000;">default keymap</span>」，並用鍵盤Tab鍵切換到「<span style="color: #ff0000;">Select</span>」後，按下鍵盤「Enter」繼續<img loading="lazy" decoding="async" class="alignnone size-full wp-image-8381" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense006.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense006.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense006-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">07、磁碟格式選擇，採用預設的「Auto (UFS)」選項，並用鍵盤Tab鍵切換到「<span style="color: #ff0000;">OK</span>」後，按下鍵盤「Enter」繼續</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone wp-image-8388 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense007.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense007.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense007-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">08、開始安裝的過程畫面</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8386" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense008.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense008.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense008-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">09、等待系統安裝的過程畫面</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8394" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense009.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense009.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense009-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">10、詢問是否有要手動設定系統，用鍵盤Tab鍵切換到「<span style="color: #ff0000;">No</span>」後，按下鍵盤「Enter」繼續</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8395" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense010.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense010.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense010-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt;">11、用鍵盤Tab鍵切換到「<span style="color: #ff0000;">Reboot</span>」，按下鍵盤「Enter」後會進行重新開機，並完成Pfsense安裝步驟。</span><br />
<span style="font-size: 14pt;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-8396" src="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense011.png" alt="" width="640" height="400" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense011.png 640w, https://ailog.tw/lifelog/wp-content/uploads/2021/05/Pfsense011-300x188.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></span></p>
<p><span style="font-size: 14pt; color: #ff0000;"><span style="color: #000000;">※下一單元</span><br />
<span style="color: #000000;">跟小編一起學-Pfsense防火牆-網路介面設定</span><br />
<a href="https://ailog.tw/lifelog/2021/05/23/interface-config/"><span style="color: #000000;">https://ailog.tw/lifelog/2021/05/23/interface-config/</span></a><br />
</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Ubuntu 18 防火牆簡易設定</title>
		<link>https://ailog.tw/lifelog/2020/01/11/ubuntu-firewall/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 11 Jan 2020 09:42:27 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Ubuntu 18]]></category>
		<category><![CDATA[ufw]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=2311</guid>

					<description><![CDATA[Ubuntu也是架設Server常用的Linux作業系統，快跟著小編一起來了解如何設定內建的防火牆軟體吧! [ &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2020/01/11/ubuntu-firewall/" class="more-link">閱讀全文<span class="screen-reader-text">〈Ubuntu 18 防火牆簡易設定〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>Ubuntu也是架設Server常用的Linux作業系統，快跟著小編一起來了解如何設定內建的防火牆軟體吧!<span id="more-2311"></span></p>
<p>[1]、安裝防火牆軟體(一般來說預設都是有安裝的)<br />
sudo apt-get install ufw<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2322" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-000.png" alt="" width="434" height="73" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-000.png 434w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-000-300x50.png 300w" sizes="auto, (max-width: 434px) 100vw, 434px" /></p>
<p>[2]、不限制IP來源的狀況下開放服務Port<br />
sudo ufw allow ssh<br />
sudo ufw allow http<br />
sudo ufw allow https<br />
sudo ufw allow 5432<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2312" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-001.png" alt="" width="399" height="241" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-001.png 399w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-001-300x181.png 300w" sizes="auto, (max-width: 399px) 100vw, 399px" /></p>
<p>[3]、限制來源IP並允許任何Port<br />
sudo ufw allow from 192.168.0.1/32<br />
sudo ufw allow from 192.168.1.200/32<br />
sudo ufw allow from 192.168.3.11/32<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2313" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-002.png" alt="" width="558" height="137" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-002.png 558w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-002-300x74.png 300w" sizes="auto, (max-width: 558px) 100vw, 558px" /></p>
<p>[4]、限制來源IP並允許特定Port<br />
sudo ufw allow from 192.168.33.55 to any port 22<br />
sudo ufw allow from 192.168.7.5 to any port 80<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2320" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-008.png" alt="" width="675" height="96" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-008.png 675w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-008-300x43.png 300w" sizes="auto, (max-width: 675px) 100vw, 675px" /></p>
<p>[5]、啟動防火牆<br />
sudo ufw enable<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2314" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-003.png" alt="" width="415" height="116" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-003.png 415w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-003-300x84.png 300w" sizes="auto, (max-width: 415px) 100vw, 415px" /></p>
<p>[6]、關閉防火牆<br />
sudo ufw disable<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2321" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-010.png" alt="" width="496" height="66" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-010.png 496w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-010-300x40.png 300w" sizes="auto, (max-width: 496px) 100vw, 496px" /></p>
<p>[7]、查看防火牆設定狀態<br />
sudo ufw status<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2315" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-004.png" alt="" width="534" height="299" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-004.png 534w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-004-300x168.png 300w" sizes="auto, (max-width: 534px) 100vw, 534px" /></p>
<p>帶出防火牆設定狀態並帶出編號的指令<br />
sudo ufw status numbered<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2316" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-005.png" alt="" width="580" height="298" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-005.png 580w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-005-300x154.png 300w" sizes="auto, (max-width: 580px) 100vw, 580px" /></p>
<p>[8]、刪除防火牆第3條規則<br />
sudo ufw delete 3<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2317" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-006.png" alt="" width="364" height="119" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-006.png 364w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-006-300x98.png 300w" sizes="auto, (max-width: 364px) 100vw, 364px" /></p>
<p>[9]、刪除所有防火牆設定<br />
sudo ufw reset<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-2318" src="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-007.png" alt="" width="727" height="167" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-007.png 727w, https://ailog.tw/lifelog/wp-content/uploads/2020/01/Ubuntu-FW-007-300x69.png 300w" sizes="auto, (max-width: 727px) 100vw, 727px" /></p>
<p>[10]、防火牆預設規則是封鎖還是放行設定(其實就是正向表列跟負向表列的用途)<br />
10.1、設定為預設放行<br />
sudo ufw default allow<br />
備註說明：使用在負向表列的情境，規則中都是設定「拒絕連線」的條列，不在規則定義的，通通都是「允許」。</p>
<p>10.2、設定為預設封鎖<br />
sudo ufw default deny<br />
備註說明：使用在正向表列的情境，規則中都是設定「允許」連線的條列，不在規則定義的，通通都是「拒絕連線」。</p>
<p>[11]、訪火牆設定規則補充<br />
上述的所有防火牆規則設定只要有「allow」跟「deny」的地方都可以互換，就看情境的需求是什麼，這個就讓大家自己動動腦搂!</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
