ãœãŒã¹ããŒã¿
- 1C Enterprise 8ã¯ã©ã€ã¢ã³ããµãŒããŒããŒãžã§ã³ã
- Enterprise 1CãµãŒããŒã¯ãWindows Server 2003ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«åºã¥ããŠå±éãããŸãã
- 1C Enterpriseã¯ãWindows Server 2003ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«åºã¥ããŠå±éãããå°çšã®MS SQLãµãŒããŒã䜿çšããŸãã
- 1Cãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã¯ãWindows Server 2003ã«åºã¥ããŠå±éãããã¿ãŒããã«ãµãŒããŒãä»ããŠå®è¡ãããŸãã
- ãã¹ãŠã®ãµãŒããŒã¯åããããã¯ãŒã¯ã»ã°ã¡ã³ãã«ãããActive Directoryãã¡ã€ã³ã«åºã¥ããŠå±éãããŸãã
ã»ãã¥ãªãã£ã®è åš
ã»ãã¥ãªãã£ã®è åšãç¹å®ããããã«ãæ¢åã®ãããã¯ãŒã¯ã«ãã©ãã£ãã¯ãããŒå³ãäœæããŸãã
å³1.ãœãŒã¹ãã©ãã£ãã¯ãããŒ
ã€ã©ã¹ãããŒã
- ãLDAPããšã¯ã1ã€ã®ããŒãã§ã¯ãªããéåäœãæå³ããŸãã Active Directoryã§äœ¿çšãããããŒããšãããã³ã«ã«ã€ããŠã¯ããã€ã¯ããœãããµããŒãæè¡æ
å ±ã®èšäºãMicrosoft Windows Serverã·ã¹ãã ã®ãµãŒãã¹ãšãããã¯ãŒã¯ããŒããã§èª¬æãããŠããŸãã ã¿ãŒããã«ãµãŒããŒããã¡ã€ã³ã³ã³ãããŒã©ã«èŠæ±ãããã®ã«å¿ããŠããããã¯ç°ãªãã»ããã«ãªããŸãã ãã®èšäºã§ã¯ã次ã®ããŒããšãããã³ã«ã®ã»ããã䜿çšããŸãã
枯 ãããã³ã« äºå® 88 UDP Kerberos ãã®ããŒãã¯ãlsass.exeïŒããŒã«ã«ã»ãã¥ãªãã£æ©é¢ãµãŒãã¹ïŒããã»ã¹ããªãã¹ã³ããŸãã 135 TCP RPC 139 TCP NetBIOSã»ãã·ã§ã³ãµãŒãã¹ 389 TCP / UDP ãã¡ã€ã³ã³ã³ãããŒã©ãŒãã±ãŒã¿ãŒ 445 TCP SMB 1025 TCP lsass.exeããã»ã¹ã«ãã£ãŠäœ¿çšãããŸãã 詳现ã¯ãã¡ã ã - ICMP ICMPã¯ããŸããŸãªæ å ±ãååŸããããã«äœ¿çšãããããããã®ãããã³ã«ã®ãã±ããã¯ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®æ¹åã«èªç±ã«ééããå¿ èŠããããŸãã
ãã®ãªã¹ãã¯ããã¡ã€ã³ã§ã®æ¿èªãšnetlogonã¹ã¯ãªããã®å®è¡ã«ååã§ãã - ãSMBããšã¯ãSMBãããã³ã«ãä»ãããã¡ã€ã«äº€æãå®è£ ãããŠããããŒãã»ãããæå³ããŸãã ãã®ããŒãã»ããã¯ãLDAPãã»ããã®ãµãã»ããã§ããã説æã®ããã«ããã«ç€ºãããŠããŸãã
- ãRDPããšã¯ãRDPæ¥ç¶ãæå³ããŸãã ããŒã3389ïŒ3390ããã®ããã«äœ¿çšãããŸãïŒ2ã€ã以äžã«èª¬æããçç±ïŒã
- ã1Cãã¯ã1Cã¯ã©ã€ã¢ã³ãããµãŒããŒãšé£æºããããã«å¿ èŠãªããŒããæå³ããŸãã ãããã¯ãããŒã1541ã1560ïŒ1591ã§ãïŒããŒãã«é¢ããæ å ±ã¯ãã1CïŒEnterprise 8.2-Client-server version Administrator GuideãããååŸããŸããïŒã
- ãMS SQLããšã¯ãMS SQLãµãŒããŒãæäœããããã®ããŒããæå³ããŸãïŒããã©ã«ãã§ã¯ããŒã1433ïŒã
ç§ãã¡ã¯äœãæã£ãŠããŸãïŒ
- Windows Server 2003ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ã¯ã1Cããã³MS SQLãšã¯é¢ä¿ã®ãªãè匱æ§ããããŸããããããã®è匱æ§ã䜿çšããæ»æã¯ããããã®ã¢ããªã±ãŒã·ã§ã³ã®ããŒã¿ãå¶åŸ¡ããã®ã«åœ¹ç«ã¡ãŸãã
- ãŠãŒã¶ãŒã¯ãSMBãããã³ã«ã䜿çšããŠããªã¢ãŒãã»ãã·ã§ã³ãããããã¯ãŒã¯ã³ã³ãã¥ãŒã¿ãŒã«ãã¡ã€ã«ã転éã§ããŸãã
- ãããã¯ãŒã¯äžã«åºããããŸããŸãªãŠã€ã«ã¹ãã»ãã¥ãªãã£ãªã¹ã¯ããããããŸãã
- ãŠãŒã¶ãŒã¯ãµãŒããŒãšåããããã¯ãŒã¯ã»ã°ã¡ã³ãã«ãããããç¹ã«è³¢ããŠãŒã¶ãŒã¯MS SQLããã³1CããŒããä»ããŠãŠãŒã¶ãŒã«æ¥ç¶ãè©Šã¿ãããšãã§ããŸãã
ã¿ã¹ã¯
- ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®è匱æ§ã®ãªã¹ã¯ãæå°éã«æããŸãã
- SMBãããã³ã«ãä»ããŠã¿ãŒããã«ãµãŒããŒãããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«ãã¡ã€ã«ã転éã§ããªãããã«ããã
- 1Cããã³MS SQLãµãŒããŒãžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã®å¯èœæ§ãæé€ããããã
- RDPãããã³ã«ã䜿çšããŠã³ã³ãã¥ãŒã¿ãŒã«ãã¡ã€ã«ã転éã§ãããŠãŒã¶ãŒã®æ°ãæå°éã«ããŸãã
å®è£ èŠä»¶
1C EnterpriseãªãœãŒã¹ã®ã·ã³ãã«ããšäœ¿ãããããæäŸããããã
解決ç
å¿ èŠãªãã©ãã£ãã¯ãããŒã®ãã©ãã£ãã¯ãã¿ãŒã³ãäœæããŸãã
å³2.å¿ èŠãªãã©ãã£ãã¯ãããŒ
ã芧ã®ãšããã1Cãå®å šã«æ©èœããããã«ã¯ããã»ã©å¿ èŠãããŸããã
ããœã³ã³ | çºä¿¡æ¥ç¶ | çä¿¡æ¥ç¶ |
AD DC | äžèŠ | ãããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒ |
ãµãŒããŒ1C | DBãµãŒããŒ1C | ã¿ãŒããã«ãµãŒã㌠|
DBãµãŒããŒ1C | äžèŠ | ãµãŒããŒ1C |
ã¿ãŒããã«ãµãŒã㌠| ãµãŒããŒ1C | ãŠãŒã¶ãŒ |
ãã®è¡šã¯ããããã¯ãŒã¯ã3ã€ã®ã»ã°ã¡ã³ãã«åå²ã§ããããšã瀺ããŠããŸãã
- ããµãŒããŒ1Cã+ãããŒã¿ããŒã¹ãµãŒããŒ1Cãã
- ãã¿ãŒããã«ãµãŒããŒãã
- ããŠãŒã¶ãŒã+ãAD DCãã
次ã«ãã æ å ±æè¡ã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ ãã®çšèªã䜿çšããŸãã ãããã¯ãŒã¯ã»ãã¥ãªãã£ãŸãŒãã³ã° ãïŒ
æäœãŸãŒã³ïŒOZïŒã¯ãã»ãšãã©ã®ãŠãŒã¶ãŒã·ã¹ãã ãšãµãŒããŒãé 眮ãããŠããæ¥åžžæäœã®æšæºç°å¢ã§ãã æ©å¯æ å ±ã¯ããã§åŠçã§ããŸããã倧éã®æ©å¯æ å ±ã®ä¿åãéèŠãªã¢ããªã±ãŒã·ã§ã³ã«ã¯é©ããŠããŸããã
å¶éãŸãŒã³ïŒRZïŒ-éèŠãªãµãŒãã¹ãŸãã¯å€§èŠæš¡ãªæ©å¯æ å ±ã®ãããã¯ãŒã¯ã«å¶åŸ¡ããããããã¯ãŒã¯ç°å¢ãæäŸããŸãã
ã¿ã¹ã¯1ã3ãå®è¡ããããã«ããããã¯ãŒã¯ãããã€ãã®ãŸãŒã³ã«åå²ããŸãã
- RZ1C-ããµãŒããŒ1Cãããã³ãããŒã¿ããŒã¹ãµãŒããŒ1Cãã¯ãã®ãŸãŒã³ã«å ¥ããŸãã
- RZTS-ã¿ãŒããã«ãµãŒããŒã¯ãã®ãŸãŒã³ã«å ¥ããŸãã
- OZ-ãã¡ã€ã³ã³ã³ãããŒã©ãŒãAD DCããšãŠãŒã¶ãŒããã®ãŸãŒã³ã«å ¥ããŸãã
å¿ èŠãªã«ãŒã«ãå°å ¥ããã«ãŒã¿ãŒã«ãããã©ãã£ãã¯ã®ééãèŠå¶ããŸãã
å³3.ãããã¯ãŒã¯ãŸãŒãã³ã°ã¹ããŒã
åé¡4ã解決ããããã«ã次ã®ããšãè¡ããŸãã
- åã¿ãŒããã«ãµãŒããŒã§ãæšæºæ¥ç¶ã«å ããŠæ°ããæ¥ç¶ãäœæããããŒã3390ã§åäœããŸãã
- ãã¹ãŠã®ãŠãŒã¶ãŒã«ããŒã3389ãžã®æ¥ç¶ãèš±å¯ããããŒã3390ã®TerminalDiskã°ã«ãŒãã®ãŠãŒã¶ãŒã®ã¿ã«èš±å¯ããŸãã
- ã¿ãŒããã«ãµãŒããŒã®æ¥ç¶ã®ããããã£ã§ãã¯ã©ã€ã¢ã³ããããŒã3389ã§ããŒã«ã«ãã©ã€ãã«æ¥ç¶ããæ©èœãç¡å¹ã«ããããŒã3390ã§ããŒã«ã«ãã©ã€ãã®æ¥ç¶ãæå¹ã«ããŸãã
ãããã£ãŠãããŒã«ã«ãã©ã€ãã®ç¹å®ã®ãŠãŒã¶ãŒãžã®æ¥ç¶ã®ã¿ãèš±å¯ã§ããŸãã
å®è£
ã«ãŒãã£ã³ã°
ãã®èšäºã§ã¯ãGNU / Linuxãã¡ããªãŒã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãæèŒãã3ã€ã®ãããã¯ãŒã¯ã«ãŒããæèŒããã³ã³ãã¥ãŒã¿ãŒãã«ãŒã¿ãŒãšããŠäœ¿çšããŸãã ã«ãŒãã£ã³ã°ãœãããŠã§ã¢-Iptablesã iptablesæ§æã¹ã¯ãªããã以äžã«ç€ºããŸãã
#!/bin/sh echo 1 > /proc/sys/net/ipv4/ip_forward OZ=192.168.0.0/24 RZTS=192.168.2.0/24 RZ1C=192.168.1.0/24 ADDC=192.168.0.1 # iptables âF iptables âX iptables â-flush # iptables âP INPUT DROP iptables âP OUTPUT DROP iptables âP FORWARD DROP # ESTABLISHED RELATED TCP UDP iptables âA FORWARD âp tcp âm state --state ESTABLISHED,RELATED âj ACCEPT iptables âA FORWARD âp udp âm state --state ESTABLISHED,RELATED âj ACCEPT # RDP OZ->RZTS iptables âA FORWARD --src $OZ --dst $RZTS âp tcp --dport 3389:3390 âj ACCEPT # DNS- RZTS->ADDC, RZ1C->ADDC iptables -A FORWARD â-src $RZTS --dst $ADDC -p udp --dport 53 -j ACCEPT iptables âA FORWARD --src $RZ1C â-dst $ADDC âp udp --dport 53 âj ACCEPT # Active Directory iptables âA FORWARD --src $RZTS --dst $ADDC âp udp --dport 88 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp udp --dport 88 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $ADDC âp tcp --dport 135 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp tcp --dport 135 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $ADDC âp tcp --dport 139 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp tcp --dport 139 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $ADDC âp tcp --dport 389 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp tcp --dport 389 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $ADDC âp udp --dport 389 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp udp --dport 389 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $ADDC âp tcp --dport 445 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp tcp --dport 445 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $ADDC âp tcp --dport 1025 âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp tcp --dport 1025 âj ACCEPT # 1 iptables âA FORWARD --src $RZTS --dst $RZ1C âp tcp --dport 1541 âj ACCEPT iptables âA FORWARD --src $RZTS --dst $RZ1C âp tcp --dport 1560:1591 âj ACCEPT # , iptables âA FORWARD --src $RZTS --dst $ADDC âp icmp âj ACCEPT iptables âA FORWARD --src $RZ1C --dst $ADDC âp icmp âj ACCEPT iptables âA FORWARD --src $OZ --dst $ADDC âp icmp âj ACCEPT # REJECT iptables âA FORWARD âj REJECT # REJECT iptables âA INPUT âj REJECT
ã¹ã¯ãªããããŒã
DROPã¢ã¯ã·ã§ã³ã¯åã«ãã±ãããããããããããiptablesã¯ãã®ååšããå¿ãããŸãã ãç Žæ£ãããããã±ããã¯ã移åãå®å šã«åæ¢ããŸãã ACCEPTã¢ã¯ã·ã§ã³ã®å Žåã®ããã«ããããã¯ä»ã®ããŒãã«ã«è»¢éãããŸããã ãµãŒããŒåŽãšã¯ã©ã€ã¢ã³ãåŽã®äž¡æ¹ã§éããããŠããªãããããããœã±ãããæ®ãããšãã§ããããããã®ã¢ã¯ã·ã§ã³ã¯ãã€ãã¹ã®çµæãããããå¯èœæ§ãããããšãèŠããŠããå¿ èŠããããŸããæåã®ä¿è·æ¹æ³ã¯ãç¹ã«ããŒãã¹ãã£ã³ããä¿è·ããå Žåã«REJECTã¢ã¯ã·ã§ã³ã䜿çšããããšã§ãïŒ Iptablesãã¥ãŒããªã¢ã« ïŒã
HASPããŒãã¿ãŒããã«ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠããããã©ã€ã»ã³ã¹ãããŒãžã£ãŒãå¥ã®ãããã¯ãŒã¯ã«ããå Žåãããã€ãã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸãã
- UDPãã±ãããšTCPãã±ããããåæ¹åã®License_ Server <-> Client_1Cã§ããŒã475ã®ã«ãŒã¿ãŒãééã§ããããã«ããŸãã
iptables âA FORWARD --src _ --dst _ âp udp --dport 475 âj ACCEPT
iptables âA FORWARD --src _ --dst _ âp tcp --dport 475 âj ACCEPT
iptables âA FORWARD â-src _ --dst _ âp udp --sport 475 âj ACCEPT
iptables âA FORWARD â-src _ --dst _ âp tcp --sport 475 âj ACCEPT
- nethasp.iniãã¡ã€ã«ã§ã©ã€ã»ã³ã¹ãµãŒããŒã®ã¢ãã¬ã¹ãæå®ããŸãïŒããã°ã©ã ã®å®è¡å¯èœãã¡ã€ã«ãšåããã£ã¬ã¯ããªã«é
眮ããå¿
èŠããããŸãïŒã
--------------------- nethasp.ini-------------------------------
[NH_COMMON]
NH_TCPIP = Enabled
...
[NH_TCPIP]
NH_SERVER_ADDR = 168.192.1.10 // ip- , .
NH_TCPIP_METHOD = TCP
NH_USE_BROADCAST = Disabled
---------------------------------------------------------------
ã¯ã©ã€ã¢ã³ãããŒã«ã«ãã©ã€ãã®ãããã³ã°
ããžã¥ã¢ã«ãŠã£ã¶ãŒãã䜿çšããŠãã¿ãŒããã«ãµãŒããŒã«æ°ãããªã¹ãã³ã°ããŒããè¿œå ããããšã¯ã§ããŸããããã®ããããããã®æ¥ç¶ã¯ãç°ãªãã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã¯ç°ãªããããã³ã«ã䜿çšããŠã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãã
å³4.æ¢åã®ãã©ã¡ãŒã¿ãŒã䜿çšããŠæ°ããæ¥ç¶ãäœæããããšãã
ãã ãããã®ã·ããªãªã¯é©ããŠããŸããã
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\_
æ¥ç¶ã®ååã¯ãRDP-Tcpãã§ããããã®æ å ±ã¯ã¬ãžã¹ããªããŒ
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\_
ä¿åãããŸã
æ°ããæ¥ç¶ãäœæããã«ã¯ã以äžãè¡ãå¿ èŠããããŸãã
- æå®ãããã¬ãžã¹ããªãã©ã³ãã* .regæ¡åŒµåãæã€ãã¡ã€ã«ã«ãšã¯ã¹ããŒãããŸãã
- ãã®ãã¡ã€ã«ãããã¹ããšãã£ã¿ãŒã§éããŸãã
- ãšã¯ã¹ããŒããã¡ã€ã«
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\_
ãHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\_2
- ãšã¯ã¹ããŒããã¡ã€ã«ã§PortNumberè¡ãèŠã€ããŠãæ°å€ã0xd3eïŒ10é²æ³ã§ã¯3390ãä»ã®ãã®ã䜿çšã§ããŸããïŒã«å€æŽããŸãã
- çµæã®ãã¡ã€ã«ãã¬ãžã¹ããªã«ã€ã³ããŒãããŸãã
説æããæäœã®åŸã
TerminalDisk
ã°ã«ãŒããäœæããããŒã«ã«ãã£ã¹ã¯ã®ãããã³ã°ãä¿¡é ŒãããŠãŒã¶ãŒãè¿œå ããŸãã
次ã«ãæ°ããæ¥ç¶ã®ããããã£ã§ã
TerminalDisk
ã°ã«ãŒãã®ã¿ãããã«æ¥ç¶ããŠããŒã«ã«ãã£ã¹ã¯ã®ãããã³ã°ãèš±å¯ããå€ãæ¥ç¶ã®ããããã£ã§ãã£ã¹ã¯ãšã¯ãªããããŒãã®ãããã³ã°ãç¡å¹ã«ããããšã瀺ããŸãã
ãããã«
å°æ¥çã«ã¯ãäŸµå ¥æ€ç¥ã·ã¹ãã ãå°å ¥ããããšã§ã¹ããŒã ã匷åã§ããŸãã
以äžã§ãã 誰ãããã®è³æã圹ç«ã€ãšæãããšãé¡ã£ãŠããŸãã ãããããé¡ãããŸãã
ãœãŒã¹
- æ å ±æè¡ã»ãã¥ãªãã£ã¬ã€ãã©ã€ã³ïŒITSG-38ïŒ-ãããã¯ãŒã¯ã»ãã¥ãªãã£ãŸãŒãã³ã°ïŒãŸãŒã³å ã®ãµãŒãã¹ã®é 眮ã«é¢ããèšèšäžã®èæ ®äºé ïŒ-http://www.cse-cst.gc.ca/its-sti/publications/itsg-csti/itsg38- eng.html
- Microsoft WindowsãµãŒããŒã·ã¹ãã ã®ãµãŒãã¹ãšãããã¯ãŒã¯ããŒã-http://support.microsoft.com/kb/832017
- Active Directoryã¬ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ãšã¯ã©ã€ã¢ã³ãRPCãã©ãã£ãã¯ãç¹å®ã®ããŒãã«å¶éãã-http ://support.microsoft.com/kb/224196/en-us
- iptablesã¬ã€ãïŒIptablesãã¥ãŒããªã¢ã«1.1.19ïŒ-http : //www.opennet.ru/docs/RUS/iptables/
- æ°ããRDPãªã¹ãã³ã°ããŒããWindows 2000/2003ã¿ãŒããã«ãµãŒããŒã«è¿œå ããã«ã¯ã©ãããã°ããã§ããïŒ -http://www.petri.co.il/add_a_new_rdp_listening_port_to_terminal_server.htm
- 1CïŒãšã³ã¿ãŒãã©ã€ãº8.2ã ã¯ã©ã€ã¢ã³ããµãŒããŒãªãã·ã§ã³ã 管çè ã¬ã€ã
- 1C HASPã䜿çšããéã®äžè¬çãªåé¡-http: //itunion.com.ua/article.php? id = 39