- I-WMI iyindlela eyinhloko yokuqapha imishini Windowskuyilapho i-SNMP isanda kakhulu kumaphrinta, kuma-electronics enethiwekhi, nakumadivayisi amaningi asemaphethelweni.
- I-SNMP ithembele kuma-ejenti, ama-MIB, nama-OID futhi isebenzisa kakhulu amachweba e-UDP 161 no-162 emibuzweni engahambisani, izithiyo, kanye nemibiko.
- Inhlanganisela ye-WMI (ngokufanele nge-WinRM) kanye ne-SNMP, ehlungiwe kahle yizicishamlilo, ivumela ukutholakala nokulawulwa kwamaphrinta nezinsizakalo ngaphandle kwama-ejenti aqinile.
- Ukusetha imiphakathi evikelekile, ukukhawulela ama-IP agunyaziwe, kanye nokuhlanza ukucushwa okudala kuvimbela ithrafikhi ye-SNMP engafuneki futhi kuqinisa ukuphepha kwenethiwekhi iyonke.
Kunoma iyiphi inethiwekhi engathí sina kangako, Thola amaphrinta avulekile, amaseva, nama-port Akuyona "into eyengeziwe," kubalulekile uma ufuna ukuthula kwengqondo. Phakathi kwezinqubomgomo zokuphepha, ukuhlolwa kwamabhuku, kanye nokuphrinta kwabasebenzisi kunoma yini ene-toner, udinga ukwazi ukuthi yini ekuphrinta yakho, ukuthi ikuphi, nokuthi isebenza kanjani.
Izindaba ezinhle ukuthi akudingeki uvuselele isondo: I-WMI ezindaweni ze-Windows kanye ne-SNMP cishe kunoma iyiphi idivayisi yenethiwekhi Bakunika konke okudingayo uma wazi ukuthi ungawasebenzisa kanjani. Icebo liwukuqonda ukuthi ubuchwepheshe ngabunye bunikeza ini, ukuthi yimaphi amachweba ahilelekile, ukuthi konke kuhambisana kanjani nama-firewall, nokuthi iyini imiphumela yokusebenza kanye nokuphepha.
Ukubuka Konke: Ama-ejenti, i-WMI, i-SNMP, nezinye izindlela zokuqapha
Uma sikhuluma ngokuqapha imishini kanye namaphrintaEmpeleni, sikhuluma ngokukhetha "isiteshi" lapho ithuluzi lokuqapha lizokhipha khona ulwazi yedivayisi. Ngokubanzi, lezi zinketho zikhona kumanethiwekhi ezinkampani:
1. I-ejenti efakiwe kudivayisi
Amapulatifomu amaningi okuqapha afaka i-ejenti yawo ye-Windows, Linux noma ngisho nezinhlelo zokusebenza ezithile. Ifakwa kukhompyutha ngayinye, futhi i-ejenti iqoqa amamethrikhi (i-CPU, i-RAM, amadiski, izinsizakalo, njll.) bese izithumela kuseva yokuqapha.
- Inzuzo: ukufinyelela okuningiliziwe kakhulu kudatha yesistimu, ngisho nangale kwalokho okunikezwa yi-WMI noma i-SNMP.
- UkuhlehlaKudingeka isetshenziswe, inakekelwe, ibuyekezwe, futhi ihlolwe ukuqinisekisa ukuthi ayibi inkinga yokusebenza noma yokuphepha.
2. I-WMI (Ithuluzi Lokuphatha iWindows)
Ezweni le-Windows, i-WMI iyindinganiso. Ikuvumela ukuthi uthole ulwazi oluningiliziwe kakhulu mayelana hardwareisofthiwe, izinqubo, izinsizakalo, ukusebenza futhi ngisho nokulungisa izici ezithile zesistimu. Konke lokhu kwenziwa ngamakilasi e-WMI afinyeleleka kude.
- Sebenzisa ngokuzenzakalelayo I-RPC phezu kwe-TCP, kanye nembobo engu-135/TCP njengomnikezeli bese kuba yimbobo enamandla aphezulu (49152-65535) uma ingakhawulelwe.
- Ezimweni eziningi isetshenziswa futhi ku- I-WinRM (HTTP 5985 / HTTPS 5986) ukugwema ukubhekana nobubanzi bezimbobo ze-RPC ezivulekile.
3. I-SNMP (Iphrothokholi Yokuphathwa Kwenethiwekhi Elula)
I-SNMP iyiphrothokholi yesicelo ejwayelekile, echazwe kuma-RFC amaningana (1157, 1901-1908, 3411-3418, phakathi kwabanye), futhi iyingxenye ye-TCP/IP stack. Lulimi oluvamile lwe- ama-router, amaswishi, ama-firewall, amaphrinta, i-NAS, i-UPS, izinto zokuphepha futhi nakumaseva amaningi.
- Imibuzo yokufunda/yokubhala kanye nemisebenzi evame ukusetshenziswa Idatha ye-PDU161.
- Izaziso ezingavumelani (izingibe nolwazi) zihamba nge Idatha ye-PDU162.
- Amandla ayo atholakala ekuhlanganisweni kwe Ama-ejenti e-SNMP + MIB + OID.
4. ssh
Ezinhlelweni zohlobo UNIX (i-Linux, i-BSD, njll.), amathuluzi amaningi akhetha ukuxhuma nge I-SSH (TCP 22) ukwenza imiyalo bese uhlaziya umphumela. Lokhu kuyindlela ehlukile uma i-SNMP ingatholakali noma uma kudingeka ukulawula okungcono ngaphandle kokufaka ama-ejenti engeziwe.
5. Ama-API kanye nezinsizakalo zewebhu
Abakhiqizi abaningi ngokwengeziwe baveza izilinganiso zabo ngokusebenzisa Ama-REST API, i-SOAP noma izinsizakalo zewebhuKuyindlela evamile yokuqapha izinhlelo zokusebenza zesimanje, izixazululo zamafu, noma izinto zikagesi ezithile lapho i-SNMP/WMI ingalingani kahle noma ingaphumeleli khona.
Isincomo esisheshayo: ukuthi yini ongayisebenzisa kuhlobo ngalunye lwemishini

Una umhlahlandlela Okusebenza kumanethiwekhi amaningi ezinkampani yilokhu okulandelayo:
- Ama-Windows PC: beka phambili I-WMI (noma i-WMI nge-WinRM) uma kuqhathaniswa nama-ejenti akho, ngaphandle kokuthi udinga ukuqapha okuthuthukisiwe kakhulu kwezinhlelo zokusebenza eziveza idatha kuphela ngaleyo ejenti.
- Amaseva e-Linux/UNIX kanye nezindawo zokusebenza: isebenzisa ssh noma i-ejenti elula. I-SNMP nayo ingenzeka, kodwa ivame ukwehluleka ekuhlinzekeni ngemininingwane yesistimu.
- Ama-elekthronikhi enethiwekhi (amaswishi, ama-router, i-AP, ama-firewall): SNMP Kuyindlela yemvelo. Ngokuvamile ayikho enye indlela ejwayelekile.
- Amaphrinta namadivayisi “asemaphethelweni” (I-NAS, i-UPS, ihadiwe ethile): cishe njalo SNMP.
- Izinhlelo zokusebenza nezinsizakalo zesimanje: uma umenzi enikeza API Iphoyisa, sebenzisa kuqala.
I-Los ama-ejenti ezindlu Zishiye njengohlelo lokusekelayo, uma ungenayo i-WMI, i-SSH, i-SNMP, noma ama-API ahlanganisa izidingo zakho. Ngokuvamile zenza kube nzima ukuthunyelwa, ukulungiswa, kanye nokuqina kokuphepha.
Indlela i-SNMP esebenza ngayo ngaphakathi: abaphathi, ama-ejenti, ama-MIB, nama-OID

Ukuze uthole amaphrinta nama-port usebenzisa i-SNMP, okokuqala udinga ukuqonda ukuthi ulwazi luhlelwe kanjani. I-SNMP isekelwe ezinsikeni ezintathu: Umphathi we-SNMP, amadivayisi aphethwe (ama-ejenti) kanye ne-MIB/OID.
Umphathi we-SNMP (i-NMS)
Yingxenye ephakathi: ikhonsoli noma iseva eqhuba Uhlelo Lokuphathwa KwenethiwekhiYiyo ethumela izicelo (GET, GETNEXT, GETBULK, SET) kuma-ejenti futhi ithole izimpendulo, izithiyo kanye nolwazi.
- Hlola ama-ejenti ngezikhathi ezithile ukuze uthole izibalo.
- Icubungula amanani, isebenzisa imingcele, ikhiqiza izexwayiso namagrafu.
- Ungabhalela ama-OID athile (ama-SET) uma ukuphepha kukuvumela, yize empeleni kunconywa ukuthi usebenze cishe njalo kwimodi yokubhala. ukufunda kuphela (RO).
Amadivayisi aphethwe kanye nama-ejenti e-SNMP
Ngamunye routerIswishi, iphrinta, noma iseva ofuna ukuyiqapha isebenza I-ejenti ye-SNMPLo menzeli:
- Iqoqa izibalo zendawo kuhadiwe, inethiwekhi, imigqa yokuphrinta, izinga lokushisa, njll.
- Iveza lolu lwazi ngokwezincazelo eziqukethwe kuma-MIB ayo.
- Ingakhiqiza izicupho ukuya ku-NMS lapho kwenzeka okuthile (isb., ukuminyana kwephepha, ukuwa kwesixhumi, izinga lokushisa elingaphezulu).
- Kungasebenza ngisho nanjengo ummeleli kumadivayisi angenayo i-SNMP yomdabu.
I-MIB (Isizinda Solwazi Lokuphatha)
Kalula nje, i-MIB “isichazamazwi” esichaza yiziphi iziguquguquko ezingabuzwa futhi ngayiphi ifomethiYifayela lombhalo (ngokuvamile elibhalwe ku-ASN.1) elichaza:
- Igama elingokomfanekiso lento.
- Uhlobo lwedatha (INTEGER, OCTET STRING, COUNTER, Gauge, TimeTicks...).
- Ukufinyelela (ukufunda kuphela, ukufunda-ukubhala).
- Incazelo yokusebenza.
- Ubudlelwano obuhambisana nezigaba nezinye izinto.
Kukhona ama-MIB ajwayelekile (isibonelo) I-IF-MIB, i-IP-MIB, i-SNMPv2-MIB) kanye nama-MIB aqondene nomkhiqizi (i-Cisco, i-HP, i-Xerox, i-Synology, njll.). Lawa ma-MIB azimele yiwo akuvumela ukuthi udlulele ngale kwe-generic, isibonelo, Buka izinga le-toner noma amakhasi aphrintiwe emodeli ethile iphrinta.
I-OID (Isihlonzi Sento)
Into ngayinye echazwe ku-MIB ihlotshaniswa ne- I-OID, ukulandelana kwezinombolo okuhlukaniswe yizikhathi, isibonelo:
- 1.3.6.1.2.1.1.3.0 -> i-sysUpTime.
- 1.3.6.1.2.1.1.5.0 -> i-sysName (igama ledivayisi).
- 1.3.6.1.2.1.1.4.0 -> sysXhumana.
Ama-OID ahlelwe ngendlela isakhiwo somuthi, lapho:
- 1.3.6.1.2.1 ihambisana ne-MIB ejwayelekile (mib-2).
- 1.3.6.1.4.1 igatsha le- amabhizinisiOkusho ukuthi, ama-MIB abakhiqizi.
Isibonelo esijwayelekile se-OID yobunikazi be-Synology NAS kungaba into efana nale: 1.3.6.1.4.1.6574.5okuhlobene nolwazi lwe-disk SMART, kuyilapho i-Cisco OID ingalenga kuyo 1.3.6.1.4.1.9.
Amachweba e-SNMP, imisebenzi eyisisekelo, kanye nezinguqulo zephrothokholi

Ukuze ukuqapha kwe-SNMP kusebenze, kudingeka ucace kakhulu ngalokho amachweba ahilelekile kanye nemodeli yokuxhumanaNgaphandle kwalokho, i-firewall iba yisitha sakho esikhulu kunazo zonke.
Amachweba ajwayelekile e-SNMP
- Idatha ye-PDU161Imibuzo kanye nemisebenzi evamile (GET, GETNEXT, GETBULK, SET). I-NMS ithumela izicelo kumenzeli kuleyo port.
- Idatha ye-PDU162: uyabamba futhi anikeze ulwazi. Kulokhu i-agent iqala ukuxhumana neseva yokuqapha.
Nakuba i-TCP ingasetshenziswa ne-SNMP kwezinye izimo, Ukuqaliswa okujwayelekile nokusabalele kakhulu yi-UDPLokhu kunemiphumela: kukhona imali encane yokukhokha, kodwa futhi akukho siqinisekiso sokulethwa. Yingakho izinhlelo zokuqapha zivame ukuphinda imibuzo uma zingatholi mpendulo.
Imisebenzi ebaluleke kakhulu ye-SNMP
- TholaI-NMS icela inani le-OID eyodwa noma ngaphezulu ezithile.
- I-GETNEXT: kufana ne-GET, kodwa kucela i-OID elandelayo kuhlu lwemisebenzi, ewusizo kakhulu ekuphindaphindeni amathebula.
- I-GETBULK: yethulwe ku-SNMPv2, eyenzelwe ukulanda ngempumelelo amabhlogo amakhulu edatha (amathebula wonke).
- SETUmphathi ubhala inani kumenzeli. Linamandla kodwa liyingozi, yingakho cishe wonke amanethiwekhi amakhulu egwema ukudalula i-SET noma ukuyikhawulela ngangokunokwenzeka.
- UGIBE: umlayezo ongahambisani nesikhathi othunyelwa yi-ejenti ku-NMS lapho kwenzeka umcimbi (isb., iphrinta ephuma ephepheni, isixhumanisi phansi).
- INFORM: kufana nogibe, kodwa ngokuqinisekiswa kokwamukelwa yi-NMS.
Izinguqulo ze-SNMP kanye nokuphepha
Ngokomlando, i-SNMP idlule ezinguqulweni eziningana, kanye nezinguquko ikakhulukazi endaweni yezokuphepha:
- I-SNMPv1 (RFC1155, 1156, 1157). Imodeli elula kakhulu, ukuphepha okusekelwe "kuchungechunge lomphakathi", ngaphandle kokubethela.
- I-SNMPv2cInguqulo ebuyekeziwe enokuthuthukiswa kokusebenza (i-GETBULK, izinhlobo ezintsha, njll.), kodwa igcina uhlelo olufanayo lokuphepha olusekelwe emphakathini. Yilona esetshenziswa kakhulu ekusebenzeni.
- I-SNMPv3. ngena ukufakazela ubuqiniso nokubethelangezokuphepha ezisekelwe kumsebenzisi (i-USM) kanye namamodeli okufinyelela aqinile. Kuphephile kakhulu, kodwa futhi kuyinkimbinkimbi kakhulu ukuyilungiselela futhi kungase kufake imali eyengeziwe.
Ukuze kube lula, amanethiwekhi amaningi asasebenzisa I-SNMPv2c kumodi yokufunda kuphela (RO) nemiphakathi eyinkimbinkimbi kanye nohlu lokulawula ukufinyelela kumadivayisi. Uma udinga ukulandela izinqubomgomo zokuphepha eziqinile, kuyalulekwa ukuhlela ukuthuthela endaweni ethile ngezigaba. v3.
I-WMI ngokujula: Amachweba, i-RPC, kanye ne-WinRM
Ezindaweni ze-Windows, i-WMI iyithuluzi elisetshenziswa kakhulu lokukhipha ulwazi lwesistimu ngaphandle kokufaka ama-ejenti engeziwe. Kodwa ezingeni lenethiwekhi, I-WMI incike ku-RPC Futhi lokho kunemiphumela ku-firewall.
Amachweba ahilelekile ku-WMI yakudala
- I-TCP 135: ichweba lase I-RPC Endpoint MapperYindawo yokuqala yokungena; ngayo iklayenti lixoxisana ngokuthi yiliphi ichweba eliguqukayo elizosetshenziswa ucingo olulandelayo.
- Amachweba aphezulu e-TCP aguquguqukayo: ngokuvamile 49152-65535 Ezinhlelweni zesimanje, iseshini yangempela ye-WMI/DCOM isungulwa lapho.
Uma uhlukanisa kakhulu inethiwekhi futhi uhlunga amachweba, lokhu kusho ukuthi inkingaUkuvula ububanzi obuphelele 49152-65535 phakathi kwezingxenye ngokuvamile akwamukeleki ngokombono wokuphepha.
Okunye: I-WMI nge-WinRM
Ukuze kugwenywe lokhu kugcwala kwamachweba ashukumisayo, iMicrosoft inikeza ithuba lokuveza i-WMI ngaphezulu Ukuphathwa kwe-WS nge-WinRM:
- HTTP e el Puerto 5985 / TCP.
- I-HTTPS e el Puerto 5986 / TCP.
Ngale ndlela, ungakhawulela ukuxhumana kwe-WMI kumachweba achazwe kahle kanye lula ukulawula ku-firewall, ngaphezu kokwengeza ukubethela uma usebenzisa i-HTTPS. Kuyindlela ekhethwayo yokuqapha kwe-Windows yesimanje kanye namathuluzi okuphatha kude.
I-WMI + Active Directory kanye nezinye izinsizakalo
Akufanele kukhohlwe ukuthi imisebenzi eminingi yokuphatha kude ihlobene ne-WMI, I-PowerShell Ukulawula kude noma ukukhushulwa kwabalawuli besizinda ngokwabo nakho kusebenzisa:
- I-LDAP (389/TCP kanye ne-UDP), I-LDAPS (636/TCP).
- I-SMB (445/TCP) yamapayipi aqanjwe ngamagama.
- Amachweba e-RPC asebenza isikhathi esifushane aphezulu ezinsizakalo ezincikene ezahlukene (i-DFS, ukukopishwa kwamafayela, i-Netlogon, njll.).
Uma uvala ngokuphelele inethiwekhi ye-Windows, kubalulekile ukubuyekeza ithebula elibanzi le- amachweba esevisi yesistimu Inqubomgomo ye-Microsoft iwukugwema ukunqamula izingxenye ezibalulekile (i-Kerberos, i-DNS, ishejuli ye-Windows, ukukopishwa kwe-AD, njll.).
Ukuthola amaphrinta namachweba nge-SNMP: indlela ewusizo
Ake sigxile konke lokhu ecaleni elisithakazelisa kakhulu: Thola amaphrinta kunethiwekhi bese uqonda ukuthi yimaphi amachweba asebenzayo usebenzisa i-SNMP.
1. Sebenzisa futhi ulungiselele i-SNMP kumaphrinta
Kumaphrinta amaningi esimanje aphakathi nendawo, i-SNMP ivulwa ngokuzenzakalelayo noma ivulwa kusukela ku-interface yewebhu yedivayisi:
- Ichaza a Umphakathi wokufunda we-SNMP (Ungalisebenzisi igama elithi “umphakathi” ezimweni ezibucayi zebhizinisi).
- Uma kungenzeka, ikhawulela ukufinyelela kwe-SNMP ekhelini le-IP noma i-subnet yeseva yakho yokuqapha.
- Gcwalisa amasimu e- i-sysLocation y sysXhumana ukuze ngikwazi ukuwahlela kamuva (ihhovisi, igumbi, phansi, i-imeyili yokusekela, njll.).
2. Hlola kusuka kuseva yokuqapha usebenzisa i-snmpwalk
Kumphathi we-Linux noma okufanayo namathuluzi e-Net-SNMP afakiwe, ungasebenzisa:
snmpwalk -v2c -c UMPHAKATHI WAKHO 192.168.xx
Uma ukucushwa kunembile, uzobona umbukiso uhlu olude lwe-OID namanani: igama lesistimu, indawo, inani lezindawo zokusebenzelana, izibalo zenethiwekhi, izibali zekhasi, amazinga e-toner (uma enikezwe umenzi kuma-MIB akhe ayimfihlo), njll.
Ukuhlola i-OID ethile kuphela (isibonelo, i-sysName):
snmpwalk -v2c -c UMPHAKATHI WAKHO 192.168.xx SNMPv2-MIB::sysName.0
3. Thola amachweba e-SNMP "kadoti" kanye nethrafikhi
Icala elivamile kakhulu kumanethiwekhi anomlando ukuthola Iseva yokuphrinta yeWindows eqhubeka nokuzama ukuxhumana nge-SNMP namaphrinta angasekho noma ashintshe ama-subnet.
- Amachweba ephrinta e-TCP/IP ku-Windows angaba nawo I-SNMP inikwe amandla ngokuzenzakalela.
- Uma leyo seva izama ukwenza imibuzo ye-SNMP kuma-IP amadala njalo ngemizuzwana embalwa, uzobona amaphakheji amaningi avinjiwe ku-firewall yakho (isibonelo, i-FortiGate), konke kuqondiswe kumakheli e-UDP 161 angasasebenzi kunethiwekhi.
Isixazululo silula kanje: Khubaza i-SNMP kulawo machweba okuphrinta noma uhlanze amachweba angasetshenziswanga. Ngaphambi kokususa noma yini, kuyalulekwa ukuqinisekisa ukuthi azikho ngempela imisebenzi ehlobene nokuthi iphrinta ehambisanayo ayiseyona ingxenye yengqalasizinda.
4. Ukusetshenziswa kwe-MIB yomkhiqizi kwedatha ethuthukisiwe
Uma ufuna ukuya ngale kokuthi "kuvuliwe noma kuvaliwe" futhi ukuqapha isimo samaphrinta (imigqeni, ama-jam, i-toner, amathreyi ephepha), kuzodingeka:
- Landa ifayela le- Ama-MIB aqondene nomkhiqizi (Xerox, HP, Canon, njll.), evame ukutholakala ku-portal yabo yokusekela.
- Zilayishe kuthuluzi lakho le-SNMP noma kusiphequluli se-MIB.
- Thola ama-OID ahlobene ne-metric ngayinye (isb., inani lamakhasi aphrintiwe, isikhathi sokuphila esingasetshenziswa, amakhodi amaphutha).
Ngalokho uzokwazi ukwakha amagrafu kanye nezaziso ezixwayisa abasebenzisi lapho iphrinta iphelelwa iphepha, lapho i-toner iku-5%, noma lapho ikhawunta ikhuphuka ngendlela engavamile, okuvimbela ukumangala kubasebenzisi.
I-SNMP, ukuphepha, kanye nemikhuba emihle yokulungiselela
I-SNMP inamandla amakhulu, kodwa uma ingalawulwa iba yi- isihluziAmaphuzu athile abalulekile okugwema ukuzidubula onyaweni:
- Sebenzisa njalo imiphakathi eyenzelwe wenaungalokothi “ube sobala”/“okwangasese”.
- Nciphisa ukufinyelela ku- Ama-IP athile noma ama-subnet kusetshenziswa ama-ACL kuma-router, amaswishi noma ku-daemon ye-SNMP uqobo (i-Linux, i-Windows, i-ESXi, njll.).
- Noma nini lapho kungenzeka, hlala imodi yokufunda (RO)Gwema i-SET ekukhiqizweni ngaphandle kwasezimweni ezilawulwa kakhulu.
- Uma indawo okuyo idinga lokho, cabanga ukusebenzisa I-SNMPv3 ngokuqinisekiswa nokubethela, okungenani kwemishini ebalulekile.
- Idokhumenti Iyini i-MIB ne-OID? Uyawasebenzisa kanye nalokho akushoyo, ukuze abanye abaphathi bakwazi ukuwagcina.
Ku-Windows Server, khumbula ukuthi Isevisi ye-SNMP:
- Ayifakwanga ngokuzenzakalelayo; isici kumele sengezwe (nge-GUI, i-PowerShell noma amakhono okuzikhethela).
- Ilungiselelwe kakhulu kusukela kumathebhu Ukuphepha y Umenzeli yesevisi: imiphakathi eyamukelekile, ababungazi lapho kuvunyelwe khona amaphakheji, ukuxhumana, indawo, kanye nezinsizakalo eziqashwe.
Ku-Linux, ifayela eliyisihluthulelo livame ukuba /etc/snmp/snmpd.conflapho ungachaza khona imibono, imiphakathi, kanye neziqondiso zokulalela, isibonelo ukuvumela umphakathi owodwa ochaziwe kanye nokukhawulela umbono ku .1 (isihlahla sonke) noma izingxenye ezithile.
Ukuxhumanisa i-WMI, i-SNMP, kanye nezingodo zomlilo kumanethiwekhi ahlukene
Ezinkampanini ezine-VLAN eziningi, ama-DMZ, kanye nezindawo ezihlungiwe kakhulu, inselele akuyona nje ukuqapha, kodwa empeleni ukuqapha. ngaphandle kokuvula ingxenye yendawo yonke yamachwebaYilapho imithetho ye-WMI, i-SNMP, kanye ne-firewall idinga ukuhlanganiswa kahle.
Ezinye izimiso ezisebenza kahle:
- para Amafasitela angaphakathi: yenza I-WinRM (5985/5986) futhi ikhawulela i-WMI yakudala nge-RPC kuphela ezigabeni ezilawulwa kakhulu.
- para imishini yenethiwekhi namaphrinta: kuvulwa kuphela I-UDP 161/162 ukuya nokubuya kuma-IP amaseva akho okuqapha.
- Hlanganisa ukuqapha ngakunye i-NMS evikelwe kahle esikhundleni sokuba nemithombo eminingi yemibuzo ehlakazekile.
- Hlola ithebula le- Amachweba esevisi ye-Windows Server ukuqinisekisa ukuthi i-AD, i-DNS, i-Kerberos, i-DFS, i-Netlogon, njll. isakwazi ukuxhumana ngemva kokuqina.
Uma usuvele une-firewall logging enqatshelwe ithrafikhi, kuwumqondo omuhle lokho. hlaziya izingodo Ukufuna amaphethini e-SNMP avinjiwe (noma i-WMI nge-RPC) ahambisana namadivayisi angalungiselelwe kahle, amaphrinta angekho, noma amaseva asakholelwa ukuthi kunama-subnet aphelelwe yisikhathi. Ukuhlanza lokhu kunciphisa umsindo wangemuva futhi kukusindise emithethweni engadingekile.
Ekugcineni, hlanganisa kahle I-WMI ku-Windows kanye ne-SNMP yakho konke okunyeNgenqubomgomo ecacile yembobo kanye nomphakathi, ikunikeza umbono onemininingwane eminingi wamaphrinta, amaseva, amaswishi, kanye nezinhlelo zokusebenza, ngaphandle kokudida inethiwekhi ngama-ejenti asindayo noma ukushiya i-firewall ivulekile. Kuyindlela enengqondo kakhulu yokugcina umkhondo wokuthi ubani ophrintayo, usuka kuphi, futhi udlula kumaphi amambobo, ngaphandle kokuhlanya njalo lapho kuhlolwa noma udinga ukubuyekeza ukuphepha kwengqalasizinda.
Umbhali oshisekayo ngomhlaba wamabhayithi nobuchwepheshe ngokujwayelekile. Ngiyathanda ukwabelana ngolwazi lwami ngokubhala, futhi yilokho engizokwenza kule bhulogi, ngikubonise zonke izinto ezithakazelisayo kakhulu ngamagajethi, isofthiwe, ihadiwe, izitayela zobuchwepheshe, nokuningi. Inhloso yami ukukusiza ukuthi uzulazule emhlabeni wedijithali ngendlela elula nejabulisayo.