97¹ú¼Ê

¹¤³§ÑÐѧ Ø­ 97¹ú¼ÊÍøÂçÊý×Ö»¯ÖÇÄܹ¤³§¡°ºÚ¿Æ¼¼¡±´ó½ÒÃØ
Ô¤Ô¼Ö±²¥
ÀÖÏíÓªÒµ°ü¹Ü·þÎñ Ø­ ÊØ»¤Ò½ÁÆÓªÒµÒ»Á¬ÎȹÌ
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

¡¾¾­µä°¸Àý¡¿Íø¹Øweb½çÃæµÇ¼ʧ°Ü

Ðû²¼Ê±¼ä£º2024-06-07
µã»÷Á¿£º1092

Ò»¡¢Õ÷ÏóÐÎò

×°±¸ÓÐËÄÖֵǼ·½·¨SSH / TELNET / CONSOLE / WEB
·ºÆðÒÔϹÊÕÏ£ºWEB½çÃæÎÞ·¨µÇ¼

¶þ¡¢×éÍøÍØÆË
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

Èý¡¢¿ÉÄÜÔµ¹ÊÔ­ÓÉ

1¡¢control-planeեȡµÇ¼ÉèÖã¬ACL¹ýÂËÏÞÖÆ£¬VTYÏß³ÌÕ¼Âú

2¡¢NGINXÀú³Ìɥʧ

ËÄ¡¢´¦Öóͷ£°ì·¨

°ì·¨1¡¢ÅŲéµÇ¼²ÎÊýÉèÖ㨵ØÖ·¡¢¶Ë¿Ú£©

1¡¢µÇ¼µØÖ·¹ýʧ

  a. consoleÏߵǼ¿ÉÒÔÉó²é½Ó¿ÚµØÖ·£¬ÏêϸÏÂÁîΪshow ip interface brief
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÈçÉÏÏÖÔÚ2¿ÚΪÄÚÍø¿Ú£¬7¿ÚΪÍâÍø¿ÚµØÖ·£¬¿ÉÒÔͨ¹ýÕâÁ½¸ö½Ó¿ÚµÇ¼װ±¸£¬ÍâÍøÓû§Ö»ÄÜͨ¹ýÍâÍø¿ÚµØÖ·µÇ¼װ±¸

2¡¢µÇ¼¶Ë¿Ú¹ýʧ

ÏÂÁîÐпÉÒÔͨ¹ýshow web-serviceÈ·¶¨µÇ¼¶Ë¿Ú
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

HttpsµÄ¶Ë¿ÚºÅĬÈÏÊÇ4430£¬ÐèÒªÐÞ¸ÄÖ»ÄÜÔÚÏÂÁîÐÐÏÂÐ޸ģ¬ÏêϸÏÂÁîΪ£ºip http secure-port ¶Ë¿Ú
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

Ð޸ĺó¿ÉÒÔʹÓÃж˿ڵǼhttps

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 


°ì·¨2¡¢ÅŲé×°±¸ÉÏÇå¾²ÏÞÖÆ£¬Õ¥È¡µÇ¼£¬ACL¹ýÂË

1¡¢ÍâµØ·À¹¥»÷ÉèÖÃեȡwebµÇ¼µÇ¼µÈ²Ù×÷

¡¾±¸×¢¡¿

¶ÔÓ¦ÏÂÁîΪ£º  

control-plane

security deny lan-web-----եȡÄÚÍøwebµÇ¼װ±¸

security deny wan-web-----եȡÍâÍøwebµÇ¼װ±¸

2¡¢ ÔÚ½Ó¿ÚŲÓûòip session filterŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP

  a. ½Ó¿Ú»á¼ûÁбíϵÄŲÓã¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 b. Ip session filter Á÷¹ýÂ˲Ù×÷£¬È«¾ÖŲÓã¬È«¾ÖÉúЧ£¬ÐèÒª¼ì²éACLÓÐûÓзÅͨ¶ÔÓ¦µÄ¶Ë¿Ú»òIP
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

c¡¢Line vtyÏÂŲÓõÄACLûÓзÅͨ¶ÔÓ¦µÄÍø¶Î»á¼û×°±¸£¬µ¼ÖÂÎÞ·¨telnet
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
  ËùŲÓõÄACL161ÐèÒª·ÅͨµÇ¼װ±¸µÄ¶Ë¿Ú»òIPµØÖ·
  Ïêϸ·¾¶£ºÇå¾²—ACL»á¼ûÁбí

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

  ÉèÖÃÍ꣬ÏÂÁîÐжÔӦϷ¢µÄÏÂÁîÈçÏ£º

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

°ì·¨3¡¢ÅŲéÓ³É䵼ֵǼ¶Ë¿Ú±»Õ¼ÓÃ

ÏêϸÉèÖÃÈçÏ£º
ÄÚÍø·þÎñÆ÷Ó³ÉäʱӳÉäµ½×°±¸µÇ¼¶Ë¿ÚºÃ±È˵80¡¢4430£¬»òÕßÊÇÉèÖÃÁËÕû»úÓ³ÉäÓ³Éäµ½½Ó¿ÚÉÏ£¬µ¼ÖÂ×°±¸µÇ¼¶Ë¿Ú±»Õ¼Ó㬻ᵼÖÂ×°±¸ÎÞ·¨µÇ¼£¬

1¡¢¶Ë¿ÚÓ³ÉäÉèÖÃ

¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static tcp 192.168.1.10 80 172.18.161.111 80

2.¡¢Õû»úÓ³ÉäÉèÖÃ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

¶ÔÓ¦ÏÂÁîÈçÏ£ºip nat inside source static 192.168.1.10 172.18.161.111 permit-inside

¡¾½â¾öÒªÁì¡¿£º½«ÍâÍøÓ³Éä¶Ë¿Ú80»òÕß4430Ó³ÉäΪ1080»òÕß14430µÈ¶Ë¿Ú£¬×èÖ¹¶Ë¿ÚÕ¼ÓÃÎÊÌâ¡£

°ì·¨4¡¢ÅŲé¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö

¶àÌõÍâÍøÏßµÄÇéÐÎÏÂûÓпªÆôÔ´½øÔ´³ö£¬µ¼ÖÂÍâÍø»á¼ûµ½×°±¸µÄÊý¾ÝÁ÷·ºÆð´Ó½Ó¿Ú7½øÀ´¿ÉÊÇ´Ó½Ó¿Ú6³öÈ¥ÁË¡£

ÒÔÊÇÔÚÍâÍø¿ÚÐèÒª¿ªÆôÔ´½øÔ´³ö£¬Ïêϸ·¾¶ÈçÏ£ºÍøÂç—½Ó¿ÚÉèÖ×¶ÔÓ¦½Ó¿ÚϹ´Ñ¡Ô´½øÔ´³ö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

¶ÔÓ¦µÄÏÂÁîÈçÏ£º

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

°ì·¨5¡¢ÅŲé·þÎñÊÇ·ñÆôÓûòÕßÊÇ·ñ±£´æweb°ü 

1¡¢µÇ¼·þÎñûÓпªÆô£¬ÏêϸÏÂÁîΪ£ºweb·þÎñÊÇ·ñ¿ªÆôshow web-service

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

2¡¢Éó²é¶Ë¿ÚÊÇ·ñÕý³£¼àÌý

£¨1£©Show tcp connect £¬LISTEN´ú±í¼àÌý״̬ÊôÓÚÕý³£×´Ì¬

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

Show cpu | in nginx £¬NGINXÀú³ÌÕ¼ÓýÏС£¬ÊôÓÚÕý³£Õ÷Ïó

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

δ·âshell³¡¾°Ï£º

Run-system-shell

ps aux | grep nginx

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·âshell³¡¾°Ï£¬Éó²éÀú³Ì

Debug support

execute diagnose-cmd ps –ef nginx

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

£¨2£©ÈôÀú³Ì²»±£´æ£¬ÐèÒªÖØÆôÀú³Ì¿´ÏÂÊÇ·ñÕý³£

Run-system-shell

/etc/rc.d/init.d/nginx start ÖØÆônginxÀú³Ì

/etc/rc.d/init.d/lnsp start  ÖØÆôphpÀú³Ì

·âshell³¡¾°ÏÂ

Debug su

execute diagnose-cmd process nginx stop

execute diagnose-cmd process nginx start

£¨3£©ÈônginxµÄÀú³Ìcpu¸ß

µ¼ÖÂwebµÇ¼²»ÉÏ£¬tcp connectÏÔʾÐÂÅþÁ¬¶¼syn_rev£¬×¥°üÏÔʾegûÓлذü

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

½â¾öÒªÁ죺

  1. show cpu | in nginx È·¶¨nginx½ø³ÌÐòÁкÅ

  2. ɱµôÀú³Ì£¬²»Ó°ÏìÆäËûʹÓã¬Ö»Ó°Ïìweb

  debug su

  execute diagnose-cmd kill ÐòÁкÅ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

  3. KillÀú³Ìºó£¬ÐèÒªÊÖ¶¯ÖØÆôÀú³Ì

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

½â¾ö¼Æ»®£º

  1. ÔöÌí°²ÅÅ·À»¤£¬Ö»ÔÊÐí¹ÜÀíÔ±µÇ¼web

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

  2. µÍ·åÆÚÏÂÔØ×îа汾¡£

Îå¡¢ÐÅÏ¢ÍøÂç

sh ver

sh run

sh web-service

sh cpu | in nginx

sh int usage

sh ver all

sh tcp connect

sh memory

sh cpu | ex 0.00

sh log rev

show int usage

sh envir

sh ip fpm sta

debug su

execute diagnose-cmd fdisk

execute diagnose-cmd mount

exit

Áù¡¢×ܽáÓ뽨Òé

1¡¢ÐÂ×°±¸µÄĬÈϵǼ½Ó¿ÚΪGI0/0½Ó¿Ú£¬¹ÜÀíµØÖ·Îª192.168.1.1£¬µçÄÔÐèÒªÉèÖÃÏàÍ¬Íø¶Î²Å»ªµÇ¼¡£

2¡¢×°±¸Ä¬ÈÏեȡwan¿ÚµÇ¼£¬ÐèÒª×¢ÖØ¡£

3¡¢ÈôÊǼì²éWEB¹¦Ð§¶¼Õý³££¬ÈÔÈ»ÎÞ·¨µÇ¼£¬¿ÉÒԲο¼ÉÏÊö°ì·¨ÖØÆôwebÀú³Ì²âÊÔÏ¡£


¡¾Ôö²¹¡¿Èçδ½â¾ö»òÐèÒªÏàʶ¸ü¶àÏêÇ飬¿Éµã»÷ÊÛºóÉÁµçÍþÙÐÐ×Éѯ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù£¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼