private:zakaznici:hpl:infrastruktura
Rozdíly
Zde můžete vidět rozdíly mezi vybranou verzí a aktuální verzí dané stránky.
| Obě strany předchozí revizePředchozí verzeNásledující verze | Předchozí verze | ||
| private:zakaznici:hpl:infrastruktura [2022/09/23 08:10] – [HPLX02] snemec | private:zakaznici:hpl:infrastruktura [2025/01/26 19:14] (aktuální) – [HPLX03] snemec | ||
|---|---|---|---|
| Řádek 1: | Řádek 1: | ||
| + | ====== Griffteam ====== | ||
| + | |||
| + | Veřejná IP: 80.95.100.114 | ||
| + | |||
| + | ===== Servery ===== | ||
| + | |||
| + | ==== Fyzické ==== | ||
| + | |||
| + | ==== HPLX06 ==== | ||
| + | |||
| + | |||
| + | XEN\\ | ||
| + | |||
| + | HPLAPP01 - účetní server - Libor\\ | ||
| + | < | ||
| + | DCGRIFF - řadič domény\\ | ||
| + | |||
| + | |||
| + | < | ||
| + | root@hplx06: | ||
| + | Name ID Mem VCPUs State | ||
| + | Domain-0 | ||
| + | vssql01 | ||
| + | dcgriff | ||
| + | </ | ||
| + | |||
| + | ==== HPLX01 ==== | ||
| + | |||
| + | **ProxMox**\\ | ||
| + | Proxmox URL: https:// | ||
| + | |||
| + | < | ||
| + | root@hplx01:/ | ||
| + | VMID NAME | ||
| + | 100 VSSQL04 | ||
| + | 101 VSSQL03-OLD | ||
| + | 102 VSSQL02 | ||
| + | 103 VSSQL05 | ||
| + | 104 VSSQL01 | ||
| + | 105 VSSQL03 | ||
| + | </ | ||
| + | |||
| + | ==== HPLX02 ==== | ||
| + | |||
| + | **PROXMOX** - Jira, Bamboo, Bitbucket, Confluence\\ | ||
| + | Proxmox URL: https:// | ||
| + | |||
| + | < | ||
| + | root@hplx02: | ||
| + | VMID | ||
| + | 110 running | ||
| + | 111 running | ||
| + | 112 running | ||
| + | 113 running | ||
| + | </ | ||
| + | |||
| + | ==== HPLX03 ==== | ||
| + | |||
| + | Do managementu Raid controlleru z menu po boot systému libovolnou klávesou. Pak přes F8 | ||
| + | |||
| + | XEN | ||
| + | |||
| + | < | ||
| + | root@hplx03: | ||
| + | Name ID Mem VCPUs State | ||
| + | Name ID Mem VCPUs State | ||
| + | Domain-0 | ||
| + | hplapp01 | ||
| + | </ | ||
| + | |||
| + | ==== HPLX05 ==== | ||
| + | |||
| + | XEN | ||
| + | |||
| + | < | ||
| + | root@hplx05: | ||
| + | Name ID Mem VCPUs State | ||
| + | Domain-0 | ||
| + | hplsvn | ||
| + | unifi 2 2048 | ||
| + | bugzilla | ||
| + | </ | ||
| + | ==== Virtuální ==== | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | ====== DHCP ====== | ||
| + | |||
| + | Dhcp službu v lokalitě Jičínská zajištují dva servery v režimu failover. | ||
| + | |||
| + | https:// | ||
| + | |||
| + | Jedná se o servery **hplx03** a **hplx05**. Kde **hplx03** je nastaven jako primární server. | ||
| + | |||
| + | IP rozsah:\\ | ||
| + | < | ||
| + | range 192.168.10.101 192.168.10.160; | ||
| + | range 192.168.10.175 192.168.10.220; | ||
| + | </ | ||
| + | |||
| + | ==== IPSEC Bratislava ==== | ||
| + | |||
| + | Lokální IP: **10.0.49**, | ||
| + | |||
| + | ping 10.0.0.50 interface=bridge | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | ===== UPS ===== | ||
| + | |||
| + | ==== APC 1000VA ==== | ||
| + | |||
| + | Management na HPLX06 | ||
| + | |||
| + | Připojené servery:\\ | ||
| + | * HPLX06 | ||
| + | * HPLX03 | ||
| + | |||
| + | ==== CyberPower 1500VA ==== | ||
| + | |||
| + | https:// | ||
| + | |||
| + | |||
| + | pwrstat -status | ||
| + | |||
| + | pwrstat -config | ||
| + | | ||
| + | < | ||
| + | pwrstat -pwrfail -delay 180 -active on -cmd / | ||
| + | pwrstat -lowbatt -runtime 300 -active off -cmd / | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | root@hplx01:/ | ||
| + | |||
| + | Daemon Configuration: | ||
| + | |||
| + | Alarm .............................................. On | ||
| + | Hibernate .......................................... Off | ||
| + | |||
| + | Action for Power Failure: | ||
| + | |||
| + | Delay time since Power failure ............. 180 sec. | ||
| + | Run script command ......................... On | ||
| + | Path of script command ..................... / | ||
| + | Duration of command running ................ 60 sec. | ||
| + | Enable shutdown system ..................... On | ||
| + | |||
| + | Action for Battery Low: | ||
| + | |||
| + | Remaining runtime threshold ................ 300 sec. | ||
| + | Battery capacity threshold ................. 35 %. | ||
| + | Run script command ......................... Off | ||
| + | Path of command ............................ / | ||
| + | Duration of command running ................ 10 sec. | ||
| + | Enable shutdown system ..................... Off | ||
| + | </ | ||
| + | |||
| + | |||
| + | Management na HPLX01 | ||
| + | |||
| + | Připojené servery:\\ | ||
| + | * HPLX01 | ||
| + | * HPLX02 | ||
| + | * HPLX05 | ||
| + | * Firewall - mail.hpl.cz | ||
| + | * BckServer | ||
| + | |||
| + | |||
| + | ===== WIFI UNIFI ===== | ||
| + | |||
| + | **Unifi controller**\\ | ||
| + | URL: https:// | ||
| + | |||
| + | 2 x AP talire, jeden umisten v chodbe - **APUNIFI01** IP: 192.168.10.12, | ||
| + | |||
| + | |||
| + | {{: | ||
| + | ===== Tiskárna ===== | ||
| + | |||
| + | Konica Minolta Bizhub C227\\ | ||
| + | URL: http:// | ||
| + | |||
| + | |||
| + | ===== Exchange server ===== | ||
| + | |||
| + | **Exchange Server 2013** | ||
| + | |||
| + | Fyzický server HPLX03(HP) | ||
| + | Při změně konfigurace diskového řadiče je potřeba nejdříve po výzvě stisknout libovolnou klávesu(Option Rom) a pak po identifikaci disk řadiče stisknout kl. F8\\ | ||
| + | Pozor, jedná se až o druhou nabídku na stisknutí F8. | ||
| + | |||
| + | |||
| + | |||
| + | ===== How to dump the contents of an IPSec tunnel on StrongSwan with tcpdump | ||
| + | |||
| + | https:// | ||
| + | |||
| + | http:// | ||
| + | |||
| + | |||
| + | tcpdump -i any -nn esp -w / | ||
| + | | ||
| + | |||
| + | | ||
| + | |||
| + | < | ||
| + | ip xfrm state | ||
| + | |||
| + | |||
| + | src 195.168.26.74 dst 80.95.100.114 | ||
| + | proto esp spi 0x3c47750f reqid 16385 mode tunnel | ||
| + | replay-window 32 flag af-unspec | ||
| + | auth-trunc hmac(sha1) 0x69b70f1f2b59fb99b52a1402e1c89df21afe5670 96 | ||
| + | enc cbc(des3_ede) 0xecfe85280f0dcee7839e9aa408e095e2cec179ca07e3e1ed | ||
| + | src 80.95.100.114 dst 195.168.26.74 | ||
| + | proto esp spi 0x773bb618 reqid 16385 mode tunnel | ||
| + | replay-window 32 flag af-unspec | ||
| + | auth-trunc hmac(sha1) 0x87a564781da8c8d0ce72a9b089d30ecc49906232 96 | ||
| + | enc cbc(des3_ede) 0x31877283c645345b0676e8396738086a06dce3732d9512e6 | ||
| + | </ | ||
| + | |||
| + | |||
| + | ==== Dekódování ESP provozu pro WireShark ==== | ||
| + | |||
| + | https:// | ||
| + | |||
| + | < | ||
| + | # This file is automatically generated, DO NOT MODIFY. | ||
| + | " | ||
| + | " | ||
| + | </ | ||
| + | |||
| + | |||
| + | Na obrázku je již dekódovaná komunikace v IPSEC kanálu, hodnoty dosazeny z výstupu příkazu '' | ||
| + | {{: | ||
| + | |||
| + | |||
| + | | ||
| + | | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
