ELASTIX
INSTALLATION
Info3W
Table des matires
[Link] a partir du CD.................................................................................................2
1.1. Si RAID Matriel ou Sans Raid.................................................................................................................................2
[Link] RAID logiciel (RAID 1).............................................................................................................................................2
[Link] /boot.........................................................................................................................................................................2
[Link] Swap........................................................................................................................................................................3
[Link] donnes...................................................................................................................................................................3
[Link] Keyboard Francais.........................................................................................4
[Link] Rseau........................................................................................................4
[Link]...............................................................................................................................................................4
[Link] statique Interne.......................................................................................................................................................4
[Link] DHCP......................................................................................................................................................................4
[Link] PPOE en eth1...................................................................................................................................................4
[Link] configuration..........................................................................................................................................................4
[Link] Email...........................................................................................................5
[Link] context..................................................................................................................5
[Link].............................................................................................................................5
[Link].....................................................................................................................................................................5
[Link]....................................................................................................................................................................6
[Link] augmenter la verbosit? .......................................................................................................................................7
[Link] voir les bannissements en cours? ........................................................................................................................7
[Link] mettre fin un bannissement non-termin? ........................................................................................................7
Coordonnes:
INFO3W
ZI LE CHIMPY
BP 40040
67 134 SCHIRMECK CEDEX
tl: [Link].73
Version du 04 fvrier 2009
Info3W
1. Installation a partir du CD
1.1.
Si RAID Matriel ou Sans Raid
tout laiss par dfaut
1.2. Si RAID logiciel (RAID 1)
Booter CD
cran d'accueil: saisir "advanced"
Choisir francais latin9
Choisir "CUSTOM" pour les disques
3 partitions: (utiliser TAB et FLECHE pour naviguer)
1.2.1. Partition /boot
File system Type: Software Raid
Allowable Drives: SDA (dselectionner SDB)
Size: 512
Cocher Forcer a tre une partition primaire : sinon il ne booteras jamais !
File system Type: Software Raid
Allowable Drives: SDB (dselectionner SDA)
Size: 512
Cocher Forcer a tre une partition primaire : sinon il ne booteras jamais !
Select RAID
Mount point: /boot
File System Type: ext3
Raid Level: RAID1
Raid members: sda1 and sdb1. Its already selected. Leave them alone!
Info3W
Elastix Installation
2/7
Info3W
1.2.2. Partition Swap
Highlight free space under SDA (first disk) using arrow keys and select NEW using tab.
On the new screen select using only tab and space:
File system Type: Software Raid
Allowable Drives: SDA (unselect SDB using space)
Size: 2048
Force to be a primary partition: DONT select this!
Step2
The same procedure for SDB but with one difference
Allowable Drives: SDB (unselect SDA)
Step 3
Select RAID
Mount point: nothing!
File System Type: swap
Raid Level: RAID1
Raid members: sda2 and sdb2. Its already selected. Leave them alone!
1.2.3. Partition donnes
Step 1
Highlight free space under SDA (first disk) using arrow keys and select NEW using tab.
On the new screen select using only tab and space:
File system Type: Software Raid
Allowable Drives: SDA (unselect SDB using space)
Size: type the number you wrote down or just toggle the option Use all available
space if you have identical disks
Force to be a primary partition: DONT select this!
Step2
The same procedure for SDB but with one difference
Allowable Drives: SDB (unselect SDA)
Step 3
Select RAID
Mount point: /
File System Type: ext3
Raid Level: RAID1
Raid members: sda3 and sdb3. Its already selected. Leave them alone!
Info3W
Elastix Installation
3/7
Info3W
2. Changement Keyboard Francais
system-config-keyboard
et choisir francais latin 9
3. Configuration Rseau
3.1. Configuration
Vi /etc/[Link]
mettre [Link]=1
prendre en compte la modif: sysctl -p
verifier: cat /proc/sys/net/ipv4/ip_forward
3.2. IP statique Interne
vi /etc/sysconfig/network-scripts/ifcfg-eth0
DEVICE=eth0
ONBOOT=yes
BOOTPROTO=static
IPADDR=[Link]
NETMASK=[Link]
3.3. IP DHCP
vi /etc/sysconfig/network-scripts/ifcfg-eth0
DEVICE=eth0
BOOTPROTO=dhcp
ONBOOT=yes
3.4. ADSL PPOE en eth1
wget [Link]
tar xvf [Link]
cd rp-pppoe-3.10
./go
3.5. Fin configuration
/etc/init.d/network restart
Info3W
Elastix Installation
4/7
Info3W
4. Configuration Email
vi /etc/postfix/[Link]
Mettre relayhost=IP
vi /etc/[Link]
mettre bonne adresse email pour problme RAID
5. Module context
cd /var/www/html/admin/modules
wget [Link]
format=raw
mv [Link]?format=raw [Link]
tar -xzvf [Link]
rm -f [Link]
Module PBX/ unemebeddefreepbx
(passe admin,admin)
module et install custom context
6. Scurit
6.1. Shorewall
yum install gamin-python
wget [Link]
wget [Link]
wget [Link]
rpm -i [Link] [Link] [Link]
Info3W
Elastix Installation
5/7
Info3W
vi /etc/shorewall/masq
eth1 eth0 (eth0 est interne)
vi /etc/shorewall/rules
ACCEPT net
ACCEPT net
$FW
$FW
udp
udp
5060
10001:20000
vi /etc/shorwall/zones
fw
firewall
net
ipv4
loc
ipv4
vi /etc/shorewall/policy
loc $FW
ACCEPT
$FW loc
ACCEPT
$FW net
ACCEPT
net $FW
DROP
loc net
DROP
all
all
DROP
net all
DROP
vi /etc/shorewall/interfaces
net
eth1 routeback
loc
eth0 routeback
vi /etc/shorewall/[Link]
startup a YES
/etc/init.d/shorewall restart
6.2. FailToBan
wget [Link]
rpm -i [Link]
vi /etc/fail2ban/action.d/[Link]
dest = MON_EMAIL
/etc/init.d/fail2ban restart
Info3W
Elastix Installation
6/7
Info3W
6.2.1. Comment augmenter la verbosit?
Pour rendre Fail2ban plus bavard, vous pouvez utiliser l'option -vvv avec fail2banclient et fail2ban (seulement pour la version 0.6.x).
Paramtrez loglevel 4 dans /etc/fail2ban/[Link] (seulement pour les versions
> 0.6.x).
6.2.2. Comment voir les bannissements en cours?
avec la commande iptables iptables -L
6.2.3. Comment mettre fin un bannissement non-termin?
Il suffit d'utiliser la commande :
1. pour les connexions ftp
iptables -D fail2ban-proftpd -s <IP> -j DROP
1. pour les connexions ssh
iptables -D fail2ban-ssh -s <IP> -j DROP
en remplacant <IP> par l'ip bannie.
Info3W
Elastix Installation
7/7