zettelkasten/OneNoteExport/Kommunikationstechnologie/Sharepoint/Infrastruktur/108_Kemp einrichten.md
Ralf Koop 5a108aa2b4 .
2023-08-25 23:29:11 +02:00

8.4 KiB

Kemp einrichten

Dienstag, 23. Oktober 2018

14:05

 

Es muss für jede WebAPP vom Sharepoint eine Rule eingerichtet werden, unter Rule & Checking :

 

 

 

Computergenerierter Alternativtext: Modify Rule mysites spt Rule Name Ru Le Type Match Type Header Field Match String Negation Ignore Case IncLude Host in URL IncLude Query\' in URL Fail On Match Perform If Flag Set Set Flag If Matched mysites_spt Content Matching Regular Expression Host imysites-spti,\_ bkk-mobiloift_de/ (None) v {width="7.479166666666667in" height="3.3125in"}

 

(bkklb001:10.96.65.247) Configuration

https://bkklb-mgmt.bkk-mobiloil.de/

Erfasster Bildschirmausschnitt: 25.10.2018 08:07

 

 

 

Computergenerierter Alternativtext: Modify Rule portal spt Rule Name Ru Le Type Match Type Header Field Match String Negation Ignore Case IncLude Host in URL IncLude Query\' in URL Fail On Match Perform If Flag Set Set Flag If Matched portal_spt Content Matching Regular Expression v Host Ipo rtal-sptv,. bkk-mobiloilk_de/ (None) v {width="7.239583333333333in" height="3.4583333333333335in"}

 

(bkklb001:10.96.65.247) Configuration

https://bkklb-mgmt.bkk-mobiloil.de/

Erfasster Bildschirmausschnitt: 25.10.2018 08:08

 

 

 

 

Computergenerierter Alternativtext: Modify Rule search spt Rule Name Ru Le Type Match Type Header Field Match String Negation Ignore Case IncLude Host in URL IncLude Query\' in URL Fail On Match Perform If Flag Set Set Flag If Matched se arch_spt Content Matching Regular Expression Host isearch-sptk_bkk-mobiloilidei (None) {width="7.041666666666667in" height="3.6875in"}

In der Übersicht sieht das dann so aus :

 

 

Computergenerierter Alternativtext: Root 29126 Root 707 mysi tes_spt porta I_spt se arch_spt Header Modification Rules Name Redirect Root 10706 Redirect Root 12352 Redirect Root 16879 Redirect Root 20153 Reg Ex Reg Ex Reg Ex Reg Ex Reg Ex Rule Type Modify URL Modify URL Modify URL Modify URL Ignore Case Ignore Case Ignore Case Ignore Case Ignore Case Options /mysites-sptx_bkk-mobi Loi LA_de,\' /portaI-spn_bkk-mobiLoi /search-sptNrbkk-mobiLoiLNFde/ Header rv\'S/ rv\'S/ rv\'S/ rv\'S/ Replacement Iowa Iowa Iowa Iowa Modify Modify Modify Modify Modify Operation Modify Modify Modify Modify Delete Delete Delete Delete Delete Delete Delete Delete Delete {width="17.489583333333332in" height="4.239583333333333in"}

 

(bkklb001:10.96.65.247) Configuration

https://bkklb-mgmt.bkk-mobiloil.de/

Erfasster Bildschirmausschnitt: 25.10.2018 08:09

 

 

Einrichten des Virtuellen Services ohne SSL Acceleration :

 

 

Computergenerierter Alternativtext: e-Back Basic Properties Sewice Name ALtemate Address Sewice Type Activate or Deactivate Service Sharepoint T Set Alternate Address HTTP-HTTP/2-HTTPS v {width="7.645833333333333in" height="1.5729166666666667in"}

 

 

Computergenerierter Alternativtext: Standard Options Force L4 Transparency Subnet Originating Requests Persistence Options Scheduling Method Idle Connection Timeout Use Address for Sener NAT Quality of Service Mode: None least connection Set Extra Ports 900 Set ldle Timeout Normal-Service {width="7.6875in" height="2.5104166666666665in"}

 

 

Computergenerierter Alternativtext: SSL Properties SSL Acceleration Enabled: {width="5.447916666666667in" height="0.7395833333333334in"}

 

 

Computergenerierter Alternativtext: Advanced Properties \"Sorry- Sewer Default Gateway Add a Port 80 Redirector VS S-eNice Specific Access Control Port Set D efau lt Gateway Redirection URL: https://%h%s Access Control {width="9.09375in" height="1.3541666666666667in"}

 

 

Computergenerierter Alternativtext: ESP options ESP Ü {width="4.885416666666667in" height="0.7604166666666666in"}

 

 

Computergenerierter Alternativtext: Real Sewers Real Sewer Check Method IP Address (bkksptwebOOI_bkk-mobiLoiLße) None Port Forwarding method Weignt Limit Status Enabled Id 143 {width="14.3125in" height="1.25in"}

 

 

Mit Health Check auf Port 80 IIS Standart website :

 

 

Computergenerierter Alternativtext: Real Sewers Real Sewer Check Method Status Codes Use HTTP/IA HTTP Method Custom Headers Enhanced Options Id IP Address 143 (bkksptwebOOI_bkk-mobiLoiLße) HTTP Protocol Checked Port 80 set URL Set Status Codes Weignt Limit Status Enabled Dis HEAD v Show Headers Port Forwarding method {width="14.583333333333334in" height="2.5729166666666665in"}

 

Der Kemp kann beim Health Check kein SNI nutzen, da wir in dieser Konfiguration kein SSl Acceleration nutzen.

SNI check geht nur wenn wir SSL Reencryption machen..

 

 

C:\\F38C12A5\\DE6F32D8-F5D9-4C62-B413-22AE52B876C4-Dateien\\image012.png{width="4.5in" height="0.625in"}

 

Einrichten des Virtuellen Services mit SSL Acceleration :

 

 

Computergenerierter Alternativtext: Basic Properties Service Name Altem a te Address Se Nice Type Activate or Deactivate Sewice Sharepoint T Set Alternate Add ress HTTP-HTTP,\'2-HTTPS v {width="7.5in" height="1.28125in"}

 

 

Computergenerierter Alternativtext: Standard Options Transparency Subnet Originating Requests Persistence Options ScheduLing Method IdLe Connection Timeout Use Address for Sewer NAT Quality of Sewice DisabLed Mode: None least connection 900 Set ldle Timeout Normal-Service {width="7.229166666666667in" height="2.0729166666666665in"}

 

 

Computergenerierter Alternativtext: SSL Properties SSL Acceleration Supported Protocols Require SNI hostname Certificates Ciphers Client Certificates Reencryption Client Certificate Reencryption SNI Hostname Strict Transport Security Header Enabled: g Reenc•ypt: CITLS1_o uTLS1_1 uTLS12 Ava ilable Certificates Kemp Lbkklb-mgmt.bkk-mobiloil.l OOS Outlook spa Server CA P_s M (BKKSPQAPP001bkk-mobi10il Assigned Certificates SP_Test Lbkksptweb001 \_bkk-mobiloil Manage Certificates Cipher Set BestPractices Assigned Ciphers Modify Cipher Set ECDHE-ECDSA-AES256-GCM-SHA384 DHE-DSS-AES256-GCM-SHA384 ECDHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-SHA384 ECDHE-ECDSA-AES256-SHA384 No Client Certificates required None required portal-spt\_ bkk-mobiloil_de Set SNI Hostname Don\'t add the Strict Transport Security Header {width="10.71875in" height="4.53125in"}

 

 

Computergenerierter Alternativtext: Advanced Properties Content Switching HTTP selection Rules HTTP Header Modifications Response Body Modification Enable HTTP,\'2 Stack Enable Caching Enable Compression Detect Ma Licious Requests Add Header to Request Copy Header in Request Add HTTP Headers \"Sony- Server Not AvaiLabLe Redirection Handling a Port 80 Redirector VS Default Gateway Sewice Specific Access Control Rule Precedence Enabled Show Selection Rules Show Header Rules Disable Show Body Modification Rules Set Header Set He ad ers To Header Legacy Operation(X-Forwarded-For) Port Error Code: Redirect URL: https://%h%s Redirection URL: Set Default Gateway Access Control Set Redirect URL {width="9.583333333333334in" height="4.416666666666667in"}

 

 

 

Computergenerierter Alternativtext: ESP options ESP Ü {width="5.0625in" height="0.8541666666666666in"}

 

 

 

Computergenerierter Alternativtext: Real Sewers Real Sewer Check Method IP Address (bkksptwebOOI_bkk-mobiLoiLße) None Port Forwarding method Weight 1000 Limit Rules Status Enabled Id 143 {width="14.15625in" height="1.125in"}

 

 

 

 

Computergenerierter Alternativtext: Name porta I_spt se arch_spt mysi tes_spt Add Rule RuLe: default Match Type RegEx RegEx RegEx Options Ignore Case Ignore Case Ignore Case Header Pattem „\'portaL-sptX_bkk-mobiIoiBYde/ „\'search-sptx_bkk-mobiloiftrde/ „\'mysites-sp bkk-mobiLoi {width="12.375in" height="2.125in"}

 

Über ADD Rule müssen die Rules hinzugefügt werden !

 

Dann sieht es in der Übersicht folgend aus :

 

 

Computergenerierter Alternativtext: tcp SharePoint T bkksptwebOOI_bkk-mobiLoiLde O Unchecked {width="10.677083333333334in" height="0.6875in"}

 

C:\\F38C12A5\\DE6F32D8-F5D9-4C62-B413-22AE52B876C4-Dateien\\image021.png{width="1.4583333333333333in" height="0.4791666666666667in"}

Content Switching muss aktiviert werden

 

°