ç§ãå€åããŠããäŒç€Ÿã§ã¯ããã¹ãŠã®åºèãšçŽ500ã®åºèãIPãã¬ãã©ããŒã«ç§»è»¢ããããšã決å®ãããŸããã äžå€®ããã³å°æ¹ã®ãªãã£ã¹ã¯ãããã«é·ãéãããœããã¯ã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããŠããŸãã ã»ã³ãã©ã«ãªãã£ã¹ã§ã¯KX-NS1000ã§ãå°åã§ã¯äž»ã«KX-NS500ã§ãã
ããããã¹ãã¢ãIPãã¬ãã©ããŒã«è»¢éããããã«ãã¢ã¹ã¿ãªã¹ã¯ã䜿çšããããšã決å®ãããŸããã
mysqlãšé£æºããbashã¹ã¯ãªããã䜿çšããŠãã¢ã¹ã¿ãªã¹ã¯ããããžã§ãã³ã°ããå®è£
ããæ¹æ³ãAsterisk RealTimeãdhcpãtftpãæ§æããæ¹æ³ãããã³Cyscoããhttpsããããžã§ãã³ã°ãè¡ãããã®ssl蚌ææžãçæããã³çœ²åããããã»ã¹ã«èå³ãããå Žåã¯ãcat ïŒ
次ã®èšäºã¯ãã¢ã¹ã¿ãªã¹ã¯ãšéä¿¡ããããã®KX-NS1000ããã³KX-NS500ã®ã»ããã¢ããã«ã€ããŠå°ã説æããŠããŸãã
åç
§æ¡ä»¶ïŒ
- èªåæ§æã§ã¯ãã²ãŒããŠã§ã€ãšã¢ã¹ã¿ãªã¹ã¯èªäœã®äž¡æ¹ã®æ§æã«ããã人éã®é¢äžãå®å
šã«æé€ããå¿
èŠããããŸãã èšå®ããã»ã¹ã«ã¯ãç¹å®ã®é»è©±çªå·ãžã®ã²ãŒããŠã§ã€ããŒãã®ããã€ã³ããã®ã¿ãå«ããå¿
èŠããããŸãã
- ã»ããã¢ããã¯åäžã®Webã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠè¡ãå¿
èŠããããŸã
- ãã€ã§ããã²ãŒããŠã§ã€ãåé€ããããé»è©±çªå·ãããã²ãŒããŠã§ã€ããå¥ã®ã²ãŒããŠã§ã€ã«è»¢éããããã²ãŒããŠã§ã€ã®ããŒããåå²ãåœãŠãããã§ããŸãã
- ãµããŒããããŠããæ©åšã®ãªã¹ããå±éããæ©èœ
é³å£°ã²ãŒããŠã§ã€ã®éžæïŒã²ãŒããŠã§ã€ãéžæããéã®äž»ãªåºæºã¯ãèªåæ§æã®æ£ããæäœã§ããã å€ãã®ã²ãŒããŠã§ã€ããããããèšå®ããå¿
èŠããããŸãã ãã€ã§ããã²ãŒããŠã§ã€ã«é害ãçºçããæ°ããã²ãŒããŠã§ã€ã代ããã«ãªãããããã«æªãããšã«ãã²ãŒããŠã§ã€ã1ã€ã®ã¹ãã¢ããå¥ã®ã¹ãã¢ã«ç§»åããã²ãŒããŠã§ã€ã®å
éšé»è©±çªå·ãŸãã¯äœ¿çšãããããŒãçªå·ãå€ããå ŽåããããŸãã
åœç¶ãæ°ãæé
ããã¹ãã·ã§ããã®
ããŠã¹ã§ãã¹ãŠã®ã²ãŒããŠã§ã€ããã¹ãããã³ãŒããã¯ããããã€ããŒãããã³QoSãã©ã¡ãŒã¿ãŒãšæŠããå¢çã²ãŒããŠã§ã€ãã»ããã¢ããããŸããã
ElteksãšCiscoããããã€ãã®ã²ãŒããŠã§ã€ãéžæããŸããã
** EltexïŒ**
é·æ-çŽ æŽãããOpenWRTã§ã圌ãè¯ãã²ãŒããŠã§ã€ã圌ããã§ããå€ãã®ããšã
ãã®çŽ æŽããããŒãã®çã®æå³è£œé å
ã¯ãOpenWRTã©ã€ã»ã³ã¹ã§å¿
èŠãªãã©ã€ããŒã®ãœãŒã¹ãã¢ããããŒãããªããããç¬èªã®ããŒãžã§ã³ã®ãã¡ãŒã ãŠã§ã¢ãã¢ã»ã³ãã«ãããããµãŒãããŒãã£ã®ããã±ãŒãžãã€ã³ã¹ããŒã«ãããããããšã¯ã§ããŸããã
çæïŒéåžžã«äžäŸ¿ãªèªåæ§æãããšãã°ããã¹ãŠã®ã²ãŒããŠã§ã€ã«å¯ŸããŠ1ã€ã®å
±éãã¡ã€ã«ãäœæããåã
ã®èšå®ãå¥ã
ã®ãã¡ã€ã«ã«å
¥ããããšã¯ã§ããŸããã
ç°ãªããã¡ãŒã ãŠã§ã¢ããŒãžã§ã³ã§ã¯ãã²ãŒããŠã§ã€ã¯ç°ãªãæ¹æ³ã§æ§æãã¡ã€ã«ãèŠæ±ããŸãã ã©ããã§ãã±ã·ã¯ãããèåããç¹ã§æžãããŠããŸãã 8ããŒãã®TAU-8.IPã¯ãtftpãµãŒããŒã®ã«ãŒãããã®ã¿æ§æãã¡ã€ã«ããã«ããŸãã ãã®ããããããã®ã²ãŒããŠã§ã€ã®å®å
šèªåæ§æã¯æ©èœããŸããã§ãããã²ãŒããŠã§ã€ã®WEBã€ã³ã¿ãŒãã§ãŒã¹ã«ç§»åããŠãtftpãµãŒããŒãžã®ãã¹ãæå®ããå¿
èŠããããŸãã ããã«ãTAU-2M.IPã¯ãã¡ã€ã«ãžã®ãã¹å
ã®å€æ°ãå®å
šã«ç解ããŸãã
tftp://10.0.15.9/Eltex/$PN/config/$MA.tar.gz
ããã¯ãéäžã§ã²ãŒããŠã§ã€ã®MACã¢ãã¬ã¹ãæžã蟌ãå¿
èŠãããTAU-8.IPã«ã€ããŠã¯èšããŸããã
WEBã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯ãæ§æåŸã«èªå調æŽã«ãããã®ãã¹ã®çæãè¿œå ãããŸããã DHCPãµãŒããŒã®43ãªãã·ã§ã³ã«ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒãæå®ãããšãããããæ©èœããããšã¯ååã«ç解ããŠããŸããããã®ãªãã·ã§ã³ã¯å¿ããã§ãã
**ã·ã¹ã³**
ãã©ã¹-çŽ æŽãããã²ãŒããŠã§ã€ã§ãããèªåæ§æã®çŽ æŽãããã·ã¹ãã ãåããã以åã®ä»äºãå§ããŸããã
çæïŒQOSèšå®ãªãã
ãã®çµæãSPA112ã䜿çšããããšã«ããŸããã éåžžã«ããããå€æãæäŸãããããã«ã»ãŒãã¹ãŠã®å Žæã§ã·ã¹ã³ã®æ©åšã䜿çšããŠããŸãã
æ§æãã¡ã€ã«ãäœæããããã®ã¡ã«ããºã
Asteriskã¯mysqlããŒã¿ããŒã¹å
ã®sipãŠãŒã¶ãŒã®ãªã¹ããååŸããŸãããã®ã¡ã«ããºã ã¯
Asterisk RealTimeãšåŒã°ããŸãã ããã«ãããAsteriskã«sip.confãŸãã¯users.confãåèªã¿èŸŒã¿ãããããšãªããSIPã¯ã©ã€ã¢ã³ãã®ã¢ã«ãŠã³ãããã®å Žã§äœæ/åé€/ç·šéã§ããŸãã
Asteriskãsipã¢ã«ãŠã³ãã
ååŸããããŒãã«ã¯ã
sip_users ããšåŒã°ããAsterisk RealTimeã¡ã«ããºã ã®ã»ãŒæšæºã§ãã
ãŠãŒã¶ãŒãé³å£°ã²ãŒããŠã§ã€ãSIPã¢ã«ãŠã³ãã«ãã€ã³ãããããŒãã«ã¯ããredaction_gateway_and_phoneãããã³ãgateway_and_phone_infoããšåŒã°ããŸãã
redaction_gateway_and_phoneSQL圢åŒã§ããŠã³ããŒããã-ãmacã-ãããŒã²ãŒããŠã§ã€ã¢ãã¬ã¹
-ãååã-sipãŠãŒã¶ãŒåã¯åãé»è©±çªå·ã§ã
-ãport_idã-VoIpã²ãŒããŠã§ã€ã®ç©çããŒãçªå·ã ããªãã¡ãã¢ããã°é»è©±ãæ¥ç¶ãããããŒã
-ãå®éã-æ§æãã¡ã€ã«ãšsip_usersããŒãã«ã®ãšã³ããªãäœæ/äžæžããããã©ããã瀺ããã©ã°
ãããŠãè¿œå ãç·šéã®æ¥ä»ïŒ
-ãããŒã¿ã-ã¬ã³ãŒãã®äœæ/ç·šéã®æ¥ä»ãèªåçã«è¿œå ãããŸã
gateway_and_phone_infoSQL圢åŒã§ããŠã³ããŒãããgateway_and_phone_infoã¯ãæ§æãããŠããã²ãŒããŠã§ã€ã«é¢ããæ
å ±ãè¿œå ããããã«å¿
èŠã§ãããŸããã²ãŒããŠã§ã€ã®å Žæãã¹ãã¢IDçªå·ãããã³æ§æ/ç·šéãã人ã®ADããã®ã¢ã«ãŠã³ãåã瀺ããŸãã
-ãå°åã-çºä¿¡é話ãã©ã®å°åããçºä¿¡ãããŠããããå€æããã®ã«äŸ¿å©ã§ãïŒè©³çŽ°ã¯ä»¥äžãåç
§ïŒã
-ãã¢ãã«ã-ã²ãŒããŠã§ã€ã¢ãã«ããã¹ãŠã®ã¢ãã«ã¯å¥ã®ããŒãã«ã«ä¿åãããŸã
-ãcfuã-åºèèå¥çªå·
-ãå°åã-ã²ãŒããŠã§ã€ãé
眮ãããŠããå°åãã€ãŸã åžãæãªã©
-"last_modified"-WEBã€ã³ã¿ãŒãã§ãŒã¹ã«å
¥ãåã«ãApacheã¯åå/ãã¹ãèŠæ±ããADã®ã°ã«ãŒãã§ç¢ºèªããŸãã
-ãmacã-ãããŒ
å¿
èŠã«å¿ããŠãäž¡æ¹ã®ããŒãã«ã1ã€ã«çµåã§ããŸãã 1ã€ã®ããŒãã«ã«åããã£ãŒã«ããæã€å€§éã®ã¬ã³ãŒããäœæãããªãããã«ãããããåå²ããŸããã
ã€ãŸããæåã®ããŒãã«ã¯sip_usersããŒãã«ã«è¿œå ããã¢ã«ãŠã³ãã説æãã2çªç®ã®ããŒãã«ã§ã¯ã²ãŒããŠã§ã€ã®ã©ã®ã¢ãã«ãæ§æãããã©ãã«é
眮ããããã説æããŸãã
ã²ãŒããŠã§ã€æ§æã®å
šäœçãªããžãã¯ã¯ããŠãŒã¶ãŒãé³å£°ã²ãŒããŠã§ã€ã®MACã¢ãã¬ã¹ã䜿çšããããŒãçªå·ãç®çã®é»è©±çªå·ãäž¡æ¹ã®ããŒãã«ã«å
¥åããããWebã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠå
¥åããããšã§ãã2ã€ã®ã¹ã¯ãªãããsip_usersããŒãã«ã«å¯Ÿå¿ãããšã³ããªãäœæããæ§æãçæããŸããã¡ã€ã«ã ãããã£ãŠãåæã«ãæå®ãããMACã¢ãã¬ã¹ãæã€éçã«å¯ŸããŠããµãŒããŒã®tftpãã£ã¬ã¯ããªã«ããã¢ã¹ã¿ãªã¹ã¯ãšå¯Ÿå¿ããæ§æãã¡ã€ã«ã«å¯ŸããŠsipã¢ã«ãŠã³ããäœæãããŸãã
ããŒã¿ããŒã¹åŠçããžãã¯ãšæ§æãã¡ã€ã«äœæããžãã¯ã¯ã2ã€ã®éšåã«åãããŠããŸãã ãããã¯äºãã«ç¬ç«ããŠãããæ°ããã¹ã¯ãªãããäœæããããšã«ãããä»ã®ã²ãŒããŠã§ã€/é»è©±ã®èªåãã¥ãŒãã³ã°ãäœæã§ããŸãã
ã¹ã¯ãªãã
AutoProvision_all.sh
ã¯ãããŒã¿ããŒã¹ã®
AutoProvision_all.sh
ãæ
åœããŸãã æåã«ãã¹ã¯ãªããã¯
gateway_and_phone
ããŒãã«ãããŒãªã³ã°ããŠã
gateway_and_phone
ã¢ãã¬ã¹ãš
actual
ãã£ãŒã«ãã«
No
ãã©ã°ãæã€ãšã³ããªã
gateway_and_phone
ãŸãã ã€ãŸãã1ã€ã®ã¢ã«ãŠã³ãã1ã€ã®é³å£°ã²ãŒããŠã§ã€ïŒãŸãã¯VoIp-phoneïŒã«å¯ŸããŠæ§æãããã¢ã¹ã¿ãªã¹ã¯ã®èŠ³ç¹ãããAã¢ã«ãŠã³ããé¢é£ããªãã²ãŒããŠã§ã€/é»è©±ãèŠã€ããŸãã 次ã«ãã¹ã¯ãªããã¯
actual
ãã£ãŒã«ãã®ãã©ã°ã[
No
ãã[
Yes
ã«å€æŽããåã¬ã³ãŒãã®ããŒã¿ã亀äºã«è¡šç€ºãããšåæã«ã
sip_users
ããŒãã«ã«ãšã³ããªãäœæããŸãã
次ã«ãã¹ã¯ãªããã¯
gateway_and_phone_info
ããŒãã«ãããŒãªã³ã°ããŠã
actual
ãã£ãŒã«ãã«
No
ãã©ã°ã
No
ã
gateway_and_phone_info
ã¢ãã¬ã¹ãéè€ããŠãããšã³ããªã
gateway_and_phone_info
ãŸãã ã€ãŸãã1ã€ã®é³å£°ã²ãŒããŠã§ã€ïŒãŸãã¯VoIp-phoneïŒã§è€æ°ã®ã¢ã«ãŠã³ããæ§æãããã¢ã¹ã¿ãªã¹ã¯ã®èŠ³ç¹ãããAã¢ã«ãŠã³ããé¢é£ããªãã²ãŒããŠã§ã€/é»è©±ãèŠã€ããŸãã ãŸãããã©ã°ãå€æŽããã¬ã³ãŒããäœæããŠããŒã¿ã衚瀺ããŸãã
åºåã§ãã¹ã¯ãªããã¯æ¬¡ã®åœ¢åŒã®è¡ãçæããŸãïŒduplicate_flag
; MACã¢ãã¬ã¹ ãŠãŒã¶ãŒå port_number ãã¹ã¯ãŒã
äŸãã°ïŒ
duble;00da55b729e8;8888;1;2DJKjH3XTx1osjI1
no_duble;00da55b729e8;8888;1;d5xfDwKG3UNdywgY
ãã¹ã¯ãŒãã¯ãå¥ã®passGen.shã¹ã¯ãªããã«ãã£ãŠçæãããŸãã
2çªç®ã®ã¹ã¯ãªããã¯ãgen_prov.shããšåŒã°ããŸãã ãAutoProvision_all.shããèµ·åãããã¹ãŠã®ã¬ã³ãŒãã®ãªã¹ããåãåããSPA112ãTAU2-2M.IPãããã³TAU-8.IPã®æ§æãã¡ã€ã«ãçæããŸãã Eltexesã«ãšã£ãŠæ®å¿µãªããšã«ãåã
ã®ããŒãã®æ§æãã€ãŸã ãã¹ãŠã®ããŒãããããã§æ§æãããããã¯WEBã€ã³ã¿ãŒãã§ãŒã¹ã§ãã§ãã¯ãããŸãã
ãã®ã¹ã¯ãªããã¯ãPAP2T-naãSPA8000ãããã³çè«çã«ã¯Ciscoããã³Linksysã®é³å£°ã²ãŒããŠã§ã€çšã®ãã¡ã€ã«ã®çæã«ãé©ããŠããŸãã
TAU8ã䜿çšãããšã¬ã¬ã³ããªãœãªã¥ãŒã·ã§ã³ã§ã¯ãããŸããããã¹ããµã€ã¯ã«ãèŠæ±ããŸãã äžèšã§æžããããã«ãTAU-8.IPã¯ãæ§æãã¡ã€ã«ãžã®ãã¹ãæžã蟌ãããšã«ãããã³ã§æ§æããå¿
èŠããããŸãã 2ã€ã®ããŒãTAU-2M.IPããã³ãã«ã§æ§æããå¿
èŠããããŸãããããã¯DHCPãµãŒããŒã§150ããã³66ã®ãªãã·ã§ã³ãæ§æããã43ã®ãªãã·ã§ã³ãæ§æãããŠããªãããã§ãã
ãã¹ãŠã®ã¹ã¯ãªããã¯
/etc/asterisk/scripts
ãã£ã¬ã¯ããªã«ãããŸããåãå Žæã«ãã²ãŒããŠã§ã€ã®æ§æãã¡ã€ã«ãã³ãã¬ãŒããé
眮ããã
ãã³ãã¬ãŒã ããã£ã¬ã¯ããªãäœæããå¿
èŠããããŸãããŸããTAU-8.IPã«ã¯ãã£ã¬ã¯ããªããªãŒããããŸãã ãã®ã²ãŒããŠã§ã€ã«ã¯ããã€ãã®èšå®ãã¡ã€ã«ãããããããããç¬èªã®ãã£ã¬ã¯ããªã«ããããã®ãããã³å
šäœã1ã€ã®ã¢ãŒã«ã€ãã«åéãããŸãã
gen_prov.shã¯ãã¯ã©ãŠã³äžã§1åããšã«å®è¡ãããŸãã
ããã«äœ¿çšå¯èœãªSPA112ã²ãŒããŠã§ã€ã¯ãHTTPSãµãŒããŒããæ§æãã¡ã€ã«ãããŠã³ããŒãããããšããããããµãŒããŒã«ã¯å®éã®SSL蚌ææžãå¿
èŠã§ãã
SSL蚌ææžã®èŠæ±ãçæããæ¹æ³ã«ã€ããŠ
㯠ã
ããã§è©³ãã説æããŸããèªã¿ã«ããå Žåã¯ã
ããã§ãã¹ãŠã説æããŸãã
1.ããŒã1åçæããä¿åããŸãã
openssl genrsa -out server.key 2048
2.蚌ææžèŠæ±ãã¡ã€ã«ãçæããŸãã
openssl req -new -key srv-shop-aster.key -out srv-shop-aster.csr -subj "/C=RU/ST=Novosibirskaya Oblast/L=Kolcovo/O=Roga_and_Kopita_Company Ltd./OU=IT Department/CN=srv-shop-aster/emailAddress=admin_user@RogKop.ru/"
3.ãµãŒããŒãã¡ã€ã«srv-shop-aster.csrãåé€ããŸãããã¡ãããäžè¬çã«ãã¡ã€ã«ãserver_name.csrããšã¯ç°ãªãååã«ãªããŸã
4.
蚌ææžã«çœ²åãã
ãµãŒãã¹ã«è¡ãã補åã蚌ææžã®æå¹æéãéžæããã蚌ææžèŠæ±ã«çœ²åããã¿ã³ãã¯ãªãã¯ããŠçœ²åãããã§ã«çœ²åããã蚌ææžããã£ã¹ã¯ã«ä¿åããŸãã ãšããã§ãCisco Webãµã€ãã§ç»é²ããå¿
èŠããããŸãã
5. Apacheã§HTTPSãèšå®ããŸãã
ããã«ããæžãããŠã
ãŸã ã
蚌ææžããããããŒã¯ãã£ã¬ã¯ããª
/etc/apache2/ssl/
ãã¡ã€ã«
/etc/apache2/sites-enabled/default-ssl.conf
ããã蚌ææžãšããŒãžã®ãã¹ãç»é²ãããŠããŸãã
SSLCertificateFile /etc/apache2/ssl/srv-shop-aster.crt
SSLCertificateKeyFile /etc/apache2/ssl/srv-shop-aster.key
ãããŠãå»æ¢ãããSSLv2ãããã³ã«ã®äœ¿çšãçŠæ¢ããŸããã§ããã ïŒSSLProtocol all -SSLv2
é©åãªãã£ã¬ã¯ããªã«çœ²åæžã¿èšŒææžä»ãã®ããŒãå
¥ããŠãApacheãåèµ·åããããšãå¿ããªãã§ãã ããã
次ã®èšäºã§ã¯ãKX-NS1000ãšã¢ã¹ã¿ãªã¹ã¯ãåéã«ããæ¹æ³ãWEBã€ã³ã¿ãŒãã§ãŒã¹ã«ã€ããŠãã«ãŒã¿ãŒã§ã®DHCPã®èšå®ã«ã€ããŠèª¬æããŸãã