+7 (916) 741 5495
support@netams.com

                         english   

 

service processor


processor NeTAMS, .

lookup-delay XXXX
, processor NetUnit, . , "" , . .
XXX - , 30.

flow-lifetime XXXX
RAW . , . , , .
XXX - , 300.

policy [oid OID] name NAME [no] target TARGET [bw { speed in speed out | speed } ]
, , (NetUnit) .
oid OID - ,
name NAME - (2-8 )
hidden - HTML ( target layer7-detect)
target TARGET - , .
target no, TARGET .
  • bw { speed in speed out | speed } - / fw . , fw DROP. , .
    speed ; K M . in out, . , (. ). ! , NeTAMS HAVE_BW. : make distclean && FLAGS=-DHAVE_BW make

    (target) . . :
    • proto XX - /etc/protocols
    • tos XX - TOS IP
    • port [s|d|b]num [s|d|b]num ... - TCP UDP . - , .
      s(ource) - SRC , d(estination) - DST , b(oth) - SRC DST.
      ( ) - 10. .
      : target proto tcp port 25 SMTP (), target proto tcp port s80:82 s8080 (), -.
    • as [s|d|b]num [s|d|b]num ... - AS. AS - , .
      s(ource) - AS , d(estination) - AS , b(oth) - SRC AS DST AS.
      AS - 10, .
      ( 3.3.0(2266))
    • vlan N1 [ N2 ] ... , VLAN- N, data-source libpcap
    • ds N1 [ N2 ] ... , data-source N
    • units oid XXXX , ( IP ) NetUnit XXXX
    • file YYYY , ( IP ) YYYY
      :
      A.B.C.D /N A.B.C.D /MASK A.B.C.D/N A.B.C.D/MASK
      :
            A.B.C.D - , 10.1.1.0
            MASK - (255.255.255.0)
            N - , 24 (255.255.255.0). .
    • addr addr ... - ip .
    • ifindex [s|d|b]num [s|d|b]num ... - () . netflow .
    • ingress|egress - netflow . netflow v9 .
    • policy-or [!]{NAME|OID} ... [!]{NAME|OID} - , . ! .
    • policy-and [!]{NAME|OID} ... [!]{NAME|OID} - , . ! .
    • time timespec - , timespec. , : (24- ), :
      target time 9-18
      target time 00:40-21:30
    • day dayspec - , , dayspec. , , :
      target day Mon-Fri
      target day Sun

    default { acct-policy | fw-policy } NAME|OID ... NAME|OID
    | .

    restrict all {drop|pass} local {drop|pass}
    , fw-policy
    all - ( ip- src/dst)
    local - , ,
    drop -
    pass -
    restrict all drop local pass , , src/dst IP- //, . , / "" . restrict local drop fw-policy. acct-policy fw-policy, no-local-pass, .. restrict all restrict local.

    auto-assign A.B.C.D E.F.G.H
    , A.B.C.D E.F.G.H IP- . :
    unit {host|user} name XXX ip auto
    auto-assign user host, IP- , ( ). , - "" , .
    . IP auto-assign.

    auto-units N type {host|user} naming {by-dns| prefix1 PPP |prefix2 QQQ} [group GROUPNAME]
    , , . DNS, IP-.
    • N - auto-units
    • type host type user -
    • naming - :
            by-dns - DNS,
      , IP .
            prefix1 PPP - , PPP
            prefix2 QQQ - , QQQ
    • group GROUPNAME - ()( 17 2004).

    unit {host|group|cluster|net|user} [oid OID] name NAME parameters [parent GROUP] [no-local-pass] [email addr] [password passwd] [description "any describing words"] [mac "XX:XX:XX:XX:XX:XX"] [sys-XXXX] [bw { speed in speed out | speed } ] [nodefault] [ap-nodefault] [fp-nodefault] [acct-policy [!][%]p_name [p_name] ...] [fw-policy [!][%]p_name [p_name] ... ] [ds-list 1,2,3...] [auto-units X]
    (NetUnit) .
    • :
      host - , IP
      group - ( )
      cluster - ip- ()
      net - ,
      user - , ip
    • oid OID - ,
    • name NAME - (2-8 )
    • parameters - :
      : ip A.B.C.D -
      :
      : ip A.B.C.D [ip A.B.C.E [..]] -
      : ip A.B.C.D mask E.F.G.H -
      : ip A.B.C.D -
    • parent GROUP [GROUP1 [..]] -
    • no-local-pass - ip-, , , restrict all, restrict local ( )
    • email addr -
    • password passwd - . (unit user), , htaccess yes html.
    • description "any describing words" - , ( ).
    • mac "XX:XX:XX:XX:XX:XX" - Ethernet- (MAC-) USER HOST. (mac-control ...) RADIUS-.
    • sys-{allow|deny}-XXX - .. " ", :
      sys-allow - ,
      sys-deny - ,
      sys-{deny|allow}-ACTION - | ACTION(auth, block, login, money, quota, mac)
      .
      sys-deny-OID - OID
      sys-allow-OID - OID
    • bw { speed in speed out | speed } - / . speed ; K M . in out, . fw- (. ). ! , NeTAMS HAVE_BW. : make distclen && FLAGS=-DHAVE_BW make
    • nodefault, ap-nodefault, fp-nodefault - , , (, acct-policy fw-policy, )
    • acct-policy [!][%]p_name -
      ! - ( ), !all-icmp, / , .. -ICMP .
      % - acct-policy, , , .
    • fw-policy [!][%]p_name -
      netams 3.1.xx, 3.2.xx 3.3.xx build 2117:
      ! - ( ), !all-icmp, / , .. -ICMP .
      % - fw-policy, , / .
      netams 3.3.xx build 2117, 3.3.0-release :
      , . . ( target... bw XX). [!][%] , .
      " " .
    • ds-list no,[no,no,...] - ,
    • auto-units X - auto-units processor, . net. .
    
    
    access-script path
    , . , data-source ip-filter, .
    path -
    :
    access-script "/usr/home/anton/script.pl"
    :
    #!/usr/bin/perl -w
    print shift, " ", shift, " ", shift, " ", shift, "\n";
    
    - processor :
        (DENY|ALLOW)
        _(OID)
        IP(IP)
        (QUOTA|LOGIN|...)


  • [an error occurred while processing this directive]