Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
en:dpi:dpi_components:platform:dpi_install:start [2021/12/20 13:58] – kuligina | en:dpi:dpi_components:platform:dpi_install:start [2023/09/04 09:48] (current) – removed elena.krasnobryzh | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== 2 Stingray Service Gateway implementation ====== | ||
- | {{indexmenu_n> | ||
- | ===== Migrating from CentOS 8.x to VEOS 8.x ===== | ||
- | <note important> | ||
- | ** The transition to the new version of the OS is planned as a regular update (without reinstallation), | ||
- | The transition to VEOS 8.6 (VAS Experts OS) will be phased in: | ||
- | - **January 2021** - Switching to the VAS Experts repository at the end of the release of patches for CentOS 8.5, does not require reinstalling the current CentOS packages | ||
- | - **[[https:// | ||
- | - Creating a distribution kit for the initial installation of the OS - ** the deadline will be determined in 2022 **, but for now the initial installation is performed from the CentOS 8.5 installation disk and the subsequent switching of the repository | ||
- | |||
- | If you received a ready-made system from us, then immediately refer to the [[en: | ||
- | Otherwise, you need to independently install the VEOS 8 operating system on your server and provide us with remote SSH access and root rights to install and initially configure the platform. | ||
- | After completing the work, remote access can be closed. | ||
- | |||
- | ===== 2.1 Preparing the server and installing CentOS 8.x ===== | ||
- | - Before rack-mounting the server, make sure it meets [[en: | ||
- | - Install the latest version of CentOS 8.x using the link: **[[http:// | ||
- | * When partitioning a disk: | ||
- | < | ||
- | the rest of the space can be allocated for the /var directory | ||
- | The Stingray SG partition does not use swap, but it may be required for system tasks, so 4GB can be allocated </ | ||
- | * Disable Hyper-threading in BIOS | ||
- | |||
- | ===== 2.2 Pre-configuring CentOS 8.x ===== | ||
- | |||
- | - Create a **vasexpertsmnt** user: < | ||
- | - Set a **complex** password for the user **vasexpertsmnt**: | ||
- | - Save the password for **vasexpertsmnt**. | ||
- | - Set permission for users of the wheel group to use all commands on behalf of all users, for this you need to add to /// | ||
- | - To provide remote access via SSH and set restrictions on valid IP addresses from the list: < | ||
- | < | ||
- | iptables -A INPUT -m conntrack --ctstate RELATED, ESTABLISHED -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 45.151.108.0/ | ||
- | iptables -A INPUT -p tcp -s 94.140.198.64/ | ||
- | iptables -A INPUT -p tcp -s 78.140.234.98 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 193.218.143.187 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 93.100.47.212 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 93.100.73.160 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 77.247.170.134 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 91.197.172.2 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 46.243.181.242 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp -s 93.159.236.11 -m tcp --dport 22 -j ACCEPT | ||
- | iptables -A INPUT -p tcp --dport 22 -j DROP | ||
- | service iptables save | ||
- | </ | ||
- | |||
- | If you are using firewalld: | ||
- | < | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
- | firewall-cmd --reload | ||
- | firewall-cmd --zone = public --remove-service = ssh --permanent | ||
- | </ | ||
- | **!Save your settings as the server will be rebooted during installation!** \\ | ||
- | \\ | ||
- | |||
- | After making sure that remote access via SSH is provided, send to [[en: | ||
- | |||
- | |||
- | < | ||
- | The initial setup of the DPI platform is carried out by engineers [[en: | ||
- | </ | ||
- | <note warning> | ||
- | Do not update the operating system kernel until the system is activated [[en: | ||
- | this may cause the network card driver to fail (([[en: | ||
- | </ | ||
- | |||
- | <note tip> Further settings are made depending on which components you plan to use, their descriptions are presented in [[en: |