Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| en:dpi:dpi_components:platform:dpi_install:start [2023/03/13 15:44] – edrudichgmailcom | en:dpi:dpi_components:platform:dpi_install:start [2023/09/04 09:48] (current) – removed elena.krasnobryzh | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== 2 Stingray Service Gateway implementation ====== | ||
| - | {{indexmenu_n> | ||
| - | ===== Migrating from CentOS 8.x to VEOS 8.x ===== | ||
| - | <note important> | ||
| - | ** The transition to the new version of the OS is planned as a regular update (without reinstallation), | ||
| - | The transition to VEOS 8.6 (VAS Experts OS) will be phased in: | ||
| - | - **January 2021** - Switching to the VAS Experts repository at the end of the release of patches for CentOS 8.5, does not require reinstalling the current CentOS packages | ||
| - | - **[[https:// | ||
| - | - Creating a distribution kit for the initial installation of the OS - **April 2023**, but for now the initial installation is performed from the CentOS 8.5 installation disk and the subsequent switching of the repository | ||
| - | |||
| - | If you received a ready-made system from us, then immediately refer to the [[en: | ||
| - | Otherwise, you need to independently install the VEOS 8 operating system on your server and provide us with remote SSH access and root rights to install and initially configure the platform. | ||
| - | After completing the work, remote access can be closed. | ||
| - | |||
| - | ===== 2.1 Preparing the server and installing CentOS 8.x ===== | ||
| - | - Before rack-mounting the server, make sure it meets [[en: | ||
| - | - Install the latest version of CentOS 8.x using the link: **[[https:// | ||
| - | * When partitioning a disk: | ||
| - | < | ||
| - | the rest of the space can be allocated for the /var directory | ||
| - | The Stingray SG partition does not use swap, but it may be required for system tasks, so 4GB can be allocated </ | ||
| - | * Disable Hyper-threading in BIOS | ||
| - | |||
| - | ===== 2.2 Pre-configuring CentOS 8.x ===== | ||
| - | |||
| - | - Create a **vasexpertsmnt** user: < | ||
| - | - Set a **complex** password for the user **vasexpertsmnt**: | ||
| - | - Save the password for **vasexpertsmnt**. | ||
| - | - Set permission for users of the wheel group to use all commands on behalf of all users, for this you need to add to /// | ||
| - | - To provide remote access via SSH and set restrictions on valid IP addresses from the list: < | ||
| - | < | ||
| - | iptables -A INPUT -m conntrack --ctstate RELATED, ESTABLISHED -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 45.151.108.0/ | ||
| - | iptables -A INPUT -p tcp -s 94.140.198.64/ | ||
| - | iptables -A INPUT -p tcp -s 78.140.234.98 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 193.218.143.187 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 93.100.47.212 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 93.100.73.160 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 77.247.170.134 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 91.197.172.2 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 46.243.181.242 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp -s 93.159.236.11 -m tcp --dport 22 -j ACCEPT | ||
| - | iptables -A INPUT -p tcp --dport 22 -j DROP | ||
| - | service iptables save | ||
| - | </ | ||
| - | |||
| - | If you are using firewalld: | ||
| - | < | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --permanent --zone = public --add-rich-rule = 'rule family = " | ||
| - | firewall-cmd --reload | ||
| - | firewall-cmd --zone = public --remove-service = ssh --permanent | ||
| - | </ | ||
| - | **!Save your settings as the server will be rebooted during installation!** \\ | ||
| - | \\ | ||
| - | |||
| - | After making sure that remote access via SSH is provided, send to [[en: | ||
| - | |||
| - | |||
| - | < | ||
| - | The initial setup of the DPI platform is carried out by engineers [[en: | ||
| - | </ | ||
| - | <note warning> | ||
| - | Do not update the operating system kernel until the system is activated [[en: | ||
| - | this may cause the network card driver to fail (([[en: | ||
| - | </ | ||
| - | |||
| - | <note tip> Further settings are made depending on which components you plan to use, their descriptions are presented in [[en: | ||