diagnsose sys session filter src
diagnose sys session list | grep policy_id
diagnose sys session filter dport 5060
show | grep -f Red\ server
diagnose ip addres lists
jueves, 7 de mayo de 2020
domingo, 3 de mayo de 2020
INSPECCIÓN AVANZADA DE FLUJO DE TRÁFICO
INSPECCIÓN AVANZADA DE FLUJO DE TRÁFICO
diagnose debug disable
diagnose debug flow trace stop
diagnose debug flow filter clear
diagnose debug flow show function-name disable
diagnose debug flow show iprope disable
diagnose debug reset 4
diagnose debug flow filter dadd 8.8.8.8
diagnose debug flow filter sadd 10.212.134.200
diagnose debug flow show console enable
diagnose debug console timestamp enable
diagnose debug enable
diagnose debug flow trace start 30
diagnose debug disable
diagnose debug flow trace stop
diagnose debug flow filter clear
diagnose debug flow show function-name disable
diagnose debug flow show iprope disable
diagnose debug reset 4
diagnose debug flow filter dadd 8.8.8.8
diagnose debug flow filter sadd 10.212.134.200
diagnose debug flow show console enable
diagnose debug console timestamp enable
diagnose debug enable
diagnose debug flow trace start 30
sábado, 2 de mayo de 2020
Fortigate SIP
https://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-voip-guide/ALG.htm
https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-voip-guide/ALG.htm
https://kb.fortinet.com/kb/documentLink.do?externalID=FD38920
Fortigate maneja dos métodos para controlar las sesione SIP
The SIP session helper
config system settings
set default-voip-alg-mode kernel-helper-based
set sip-helper enable
end
show system session-helper
.
.
.
edit 13
set name sip
set port 5060
set protocol 17
next
Use the following command to set the debug level for the SIP session helper. Different debug masks display different levels of detail about SIP session helper activity.
diagnose sys sip debug-mask <debug_mask_int>
Use the following command to display the current list of SIP dialogs being processed by the SIP session help. You can also use the
clear option to delete all active SIP dialogs being processed by the SIP session helper.
diagnose sys sip dialog {clear | list}
Use the following command to display the current list of SIP NAT address mapping tables being used by the SIP session helper.
diagnose sys sip mapping list
Use the following command to display the current SIP session helper activity including information about the SIP dialogs, mappings, and other SIP session help counts. This command can be useful to get an overview of what the SIP session helper is currently doing.
diagnose sys sip status
The SIP session helper is disabled by default and must be enabled for the SIP session helper to process VoIP traffic
The SIP ALG
config system settings
set default-voip-alg-mode proxy-based
set sip-helper disable
end
config voip profile |
edit "default" |
set comment "Default VoIP profile." |
next |
By default all SIP traffic is processed by the SIP ALG. If the policy that accepts the SIP traffic includes a VoIP profile, the SIP traffic is processed by that profile. If the policy does not include a SIP profile the SIP traffic is processed by the SIP ALG using the default VoIP profile.
Use the following command to list all active SIP calls being processed by the SIP ALG. You can also use the
clear option to delete all active SIP calls being processed by the SIP ALG, the idle option to list idle SIP calls, and the invite option to list SIP invite transactions.
diagnose sys sip-proxy calls {clear | list | idle | invite}
Use the following commands to employ filters to display specific information about the SIP ALG and the session that it is processing. You can build up a filter by including a number of options such as source address, VoIP profile, policy, and so on.
diagnose sys sip-proxy filter <filter_options>
diagnose sys sip-proxy log-filter <filter_options>
Use the following command to display the active SIP rate limiting meters and their current settings.
diagnose sys sip-proxy meters list
Use the following command to display status information about the SIP sessions being processed by the SIP ALG. You can also clear all SIP ALG statistics.
diagnose sys sip-proxy stats {clear | list}
Conflicts between the SIP ALG and the session helper
------------
diagnose sys sip status
dialogs: max=32768, used=0
mappings: used=0
dialog hash by ID: size=2048, used=0, depth=0
dialog hash by RTP: size=2048, used=0, depth=0
mapping hash: size=2048, used=0, depth=0
count0: 0
count1: 0
count2: 0
count3: 0
count4: 0
This command output shows that the session helper is not processing SIP sessions because all of the used and count fields are 0. If any of these fields contains non-zero values then the SIP session helper may be processing SIP sessions.
diagnose sys sip-proxy stats list
The RTP port number is included in the
m= part of the SDP profile. In the example above, the SIP INVITE message includes RTP port number is 49170 so the RTCP port number would be 49171. In the SIP response message the RTP port number is 3456 so the RTCP port number would be 3457.
Debug:
diagnose debug disablediagnose debug resetdiagnose debug application sip -1diagnose debug enable
Use following commands to display status information about the SIP sessions being processed by the SIP ALG.
Clear all SIP ALG statistics.
diagnose sys sip-proxy calls listdiagnose sys sip-proxy stats {clear | list}diagnose sys sip-proxy statsdiagnose sys sip statusdiagnose sys sip dialog listdiagnose sys sip mapping list
-
diagnose debug application sip
| 1 | Configuration changes, mainly addition/deletion/modification of virtual domains. |
| 2 | TCP connection accepts or connects, redirect creation. |
| 4 | Create or delete a session. |
| 16 | Any IO read or write. |
| 32 | An ASCII dump of all data read or written. |
| 64 | Include HEX dump in the above output. |
| 128 | Any activity related to the use of the FortiCarrier dynamic profile feature to determine the correct profile-group to use. |
| 256 | Log summary of interesting fields in a SIP call. |
| 1024 | Any activity related to SIP geo-redundancy. |
| 2048 | Any activity related to HA syncing of SIP calls. |
miércoles, 11 de julio de 2018
Notas de HA en Fortigate
Validar si el cluster esta sincronizado
diagnose sys ha checksum cluster
diagnose sys ha checksum recalculate
execute ha synchronice star ==> este comando lo utilizo en la unidad de backup para sincronizar la configuración de la unidad primaria a la secundaria.
##################################
########### HA_PRIMARY ###########
##################################
config system global
set hostname Primary_FortiGate
end
config system ha
set mode a-p
set group-name My-HA-Cluster
set password
set priority 250
set override enable
set hbdev ha1 50 ha2 50
end
#################################
########### HA_BACKUP ###########
#################################
execute factoryreset
config system global
set hostname Backup_FortiGate
end
config system ha
set mode a-p
set group-name My-HA-Cluster
set password
set priority 50
set hbdev ha1 50 ha2 50
end
#########################################################################
########### Checking cluster operation and disabling override ###########
#########################################################################
diag sys ha cluster-csum
config system ha
set override disable
end
OVERRIDE funciona como un premt , el primario siempre seria el primario en condiciones normales.
///////////
diagnose sys ha reset-uptime
//////////
martes, 10 de julio de 2018
Buscar en Fortinet
show full-configuration | grep -f
este comando nos sirve para encontrar un elemento en la configuración de nuestro firewall mostrándonos la sección completa, por ejemplo si buscamos una ip nos muestra que esta en un firewall address y sus atributos.
sh full-configuration | grep -f 10.10.10.10
config firewall address
edit "direccion_ip"
set type ipmask
set comment ''
set visibility enable
set associated-interface ''
set color 0
set allow-routing disable
set subnet 10.10.10.10 255.255.255.255 <---
next
end
viernes, 16 de junio de 2017
jueves, 20 de abril de 2017
Sincronizar un nodo a cluster
En ocaciones se requiriere realizar el cambio de un firewall en un cluster por diferentes razones, la principal por daño en alguno de estos. para poder sincronizar la configuración inicialmente pensé que copiar la misma en el nodo nuevo seria la forma adecuada sin embargo con apoyo de un amigo me mostró como era la manera indicada de realizar el procedimiento minimizando problemas en este.
Inicialmente el nodo nuevo debe ser actualizado a la versión que tenga el nodo activo.
Para adelantar lo requerido validamos en el nodo activo el numero que se le asigno al cluster id, y no es por defecto debemos validarlo, esto lo hacemos con el siguiente comando:
UUUUU@XXXX> show chassis cluster status
Monitor Failure codes:
CS Cold Sync monitoring FL Fabric Connection monitoring
GR GRES monitoring HW Hardware monitoring
IF Interface monitoring IP IP monitoring
LB Loopback monitoring MB Mbuf monitoring
NH Nexthop monitoring NP NPC monitoring
SP SPU monitoring SM Schedule monitoring
######Cluster ID: 3#####
Node Priority Status Preempt Manual Monitor-failures
En este momento podemos continuar con el nodo nuevo asi:
-Borramos la configuración
root# delete
This will delete the entire configuration
Delete everything under this level? [yes,no] (no) yes
-Configuramos una contraseña de root
root# set system root-authentication plain-text-password
New password:
Retype new password:
- Guardamos la configuración
root# commit
-Salimos del modo de configuración
root# exit
Exiting configuration mode
root>
-Configuramos el id del cluster y en numero del nodo que vamos a reemplazar.
root> set chassis cluster cluster-id 3 node 1
warning: A reboot is required for chassis cluster to be enabled
- Apagamos el firewall, realizamos la conexión del cableado de red , al finalizar y estar seguros del cableado procedemos a encender el firewall.
Validamos el estado del cluster para el RD de sincronizacion entre los firewall, generalmente el Redundancy group 0 , una vez el cluster esta sincronizado primario y secundario en modo de configuración hacemos un commit full y listo!!! Y tenemos la configuraracion en en los dos nodos.
Suscribirse a:
Entradas
(
Atom
)
