diff --git a/roles/firewall/tasks/main.yml b/roles/firewall/tasks/main.yml index 8309a42..f9ad212 100644 --- a/roles/firewall/tasks/main.yml +++ b/roles/firewall/tasks/main.yml @@ -48,10 +48,12 @@ tags: template -- name: "Template the tsgconf/app_l7_proto_id.conf" +- name: "Template the conf/capture_packet_plug.conf.j2" template: - src: "{{ role_path }}/templates/app_l7_proto_id.conf.j2" - dest: /home/mesasoft/sapp_run/tsgconf/app_l7_proto_id.conf + src: "{{ role_path }}/templates/capture_packet_plug.conf.j2" + dest: /home/mesasoft/sapp_run/conf/capture_packet_plug.conf + tags: template + - name: "Template the /home/mesasoft/sapp_run/plug/business/tsg_conn_sketch/tsg_conn_sketch.inf" template: diff --git a/roles/firewall/templates/capture_packet_plug.conf.j2 b/roles/firewall/templates/capture_packet_plug.conf.j2 new file mode 100644 index 0000000..292357e --- /dev/null +++ b/roles/firewall/templates/capture_packet_plug.conf.j2 @@ -0,0 +1,26 @@ +[MAAT] +MAAT_MODE=2 +#EFFECTIVE_FLAG= +STAT_SWITCH=1 +PERF_SWITCH=1 +TABLE_INFO=conf/capture_packet_tableinfo.conf +STAT_FILE=capture_packet_maat.status +EFFECT_INTERVAL_S=1 +REDIS_IP={{ maat_redis_server.address }} +REDIS_PORT_NUM={{ maat_redis_server.port_num }} +REDIS_PORT={{ maat_redis_server.port }} +REDIS_INDEX={{ maat_redis_server.db }} +JSON_CFG_FILE=conf/capture_packet_maat.json +INC_CFG_DIR=capture_packet_rule/inc/index/ +FULL_CFG_DIR=capture_packet_rule/full/index/ +EFFECTIVE_RANGE_FILE=/opt/tsg/etc/tsg_device_tag.json +ACCEPT_TAGS={"tags":[{"tag":"data_center","value":"{{ data_center }}"}]} + +[LOG] +NIC_NAME=enp130s2f3 +BROKER_LIST={{ log_kafkabrokers.address | join(",") }} +FIELD_FILE=conf/capture_packet_log_field.conf + +[SYSTEM] +LOG_LEVEL=30 +LOG_PATH=./tsglog/capture_packet_plug/capture_packet \ No newline at end of file diff --git a/roles/firewall/templates/maat.conf.j2 b/roles/firewall/templates/maat.conf.j2 index baa29f6..3b81054 100644 --- a/roles/firewall/templates/maat.conf.j2 +++ b/roles/firewall/templates/maat.conf.j2 @@ -32,5 +32,37 @@ INC_CFG_DIR=tsgrule/inc/index/ FULL_CFG_DIR=tsgrule/full/index/ EFFECTIVE_RANGE_FILE=/opt/tsg/etc/tsg_device_tag.json +[APP_SIGNATURE_MAAT] +MAAT_MODE=2 +STAT_SWITCH=1 +PERF_SWITCH=1 +TABLE_INFO=tsgconf/app_sketch_tableinfo.conf +STAT_FILE=app_sketch_maat.status +EFFECT_INTERVAL_S=1 +REDIS_IP={{ maat_redis_server.address }} +REDIS_PORT_NUM={{ maat_redis_server.port_num }} +REDIS_PORT={{ maat_redis_server.port }} +REDIS_INDEX={{ maat_redis_server.db }} +JSON_CFG_FILE=tsgconf/app_sketch_maat.json +INC_CFG_DIR=tsgrule/inc/index/ +FULL_CFG_DIR=tsgrule/full/index/ +EFFECTIVE_RANGE_FILE=/opt/tsg/etc/tsg_device_tag.json + +[CAPTURE] +MAAT_MODE=2 +STAT_SWITCH=1 +PERF_SWITCH=1 +TABLE_INFO=tsgconf/app_sketch_tableinfo.conf +STAT_FILE=app_sketch_maat.status +EFFECT_INTERVAL_S=1 +REDIS_IP={{ maat_redis_server.address }} +REDIS_PORT_NUM={{ maat_redis_server.port_num }} +REDIS_PORT={{ maat_redis_server.port }} +REDIS_INDEX={{ maat_redis_server.db }} +JSON_CFG_FILE=tsgconf/app_sketch_maat.json +INC_CFG_DIR=tsgrule/inc/index/ +FULL_CFG_DIR=tsgrule/full/index/ +EFFECTIVE_RANGE_FILE=/opt/tsg/etc/tsg_device_tag.json + [MAAT] ACCEPT_TAGS={"tags":[{"tag":"data_center","value":"{{ data_center }}"}]} diff --git a/roles/firewall/templates/main.conf.j2 b/roles/firewall/templates/main.conf.j2 index 6112ff3..99aa03b 100644 --- a/roles/firewall/templates/main.conf.j2 +++ b/roles/firewall/templates/main.conf.j2 @@ -80,10 +80,24 @@ live_intervals_time = 30 [HOS_CONF] hos_serverip="{{ firewall.hos_serverip }}" hos_serverport={{ firewall.hos_serverport }} -hos_accesskeyid="{{ firewall.hos_accesskeyid }}" -hos_secretkey="{{ firewall.hos_secretkey }}" -hos_poolsize={{ firewall.hos_poolsize }} -hos_thread_sum={{ firewall.hos_thread_sum }} -hos_cache_size={{ firewall.hos_cache_size }} -hos_fs2_serverip="{{ firewall.hos_fs2_serverip }}" -hos_fs2_serverport={{ firewall.hos_fs2_serverport }} +hos_accesskeyid="default" +hos_secretkey="default" +hos_poolsize=100 +hos_thread_sum=32 +hos_cache_size=102400 +hos_fs2_serverip="127.0.0.1" +hos_fs2_serverport=10086 + +[APP_SKETCH_LOCAL] +LOG_LEVEL=10 +LOG_PATH="./tsglog/app_sketch_local/app_sketch_local" + +[APP_SKETCH_FEEDBACK] +QOS=1 +PUBLISH_TOPIC="APP_SIGNATURE_ID" +#CLIENT_ID= +BROKER_IP="{{ firewall.APP_SKETCH_BROKER_IP }}" +BROKER_PORT="{{ firewall.APP_SKETCH_BROKER_PORT }}" + +[APP_PROTO_ENGINE] +license_path=/data/app_proto_engine/license \ No newline at end of file diff --git a/roles/mrzcpd/templates/traffic_mirror/mrglobal.conf.traffic_mirror.j2 b/roles/mrzcpd/templates/traffic_mirror/mrglobal.conf.traffic_mirror.j2 index 1e31f2a..03c5edd 100644 --- a/roles/mrzcpd/templates/traffic_mirror/mrglobal.conf.traffic_mirror.j2 +++ b/roles/mrzcpd/templates/traffic_mirror/mrglobal.conf.traffic_mirror.j2 @@ -1,5 +1,5 @@ [device] -device={{ data_incoming_nic_list | join(",") }},vxlan_user,vxlan_fwd +device={{ data_incoming_nic_list | join(",") }} sz_tunnel=8192 sz_buffer=0 diff --git a/roles/sapp/templates/conflist.inf.j2 b/roles/sapp/templates/conflist.inf.j2 index 87cdee7..900440d 100644 --- a/roles/sapp/templates/conflist.inf.j2 +++ b/roles/sapp/templates/conflist.inf.j2 @@ -1,4 +1,5 @@ [platform] +./plug/platform/app_proto_identify/app_proto_identify.inf ./plug/platform/tsg_master/tsg_master.inf [protocol] @@ -15,6 +16,7 @@ [business] ./plug/business/tsg_conn_sketch/tsg_conn_sketch.inf +./plug/business/capture_packet_plug/capture_packet_plug.inf ./plug/business/fw_ssl_plug/fw_ssl_plug.inf ./plug/business/fw_http_plug/fw_http_plug.inf ./plug/business/fw_dns_plug/fw_dns_plug.inf @@ -23,4 +25,5 @@ ./plug/business/fw_quic_plug/fw_quic_plug.inf ./plug/business/fw_voip_plug/fw_voip_plug.inf ./plug/business/conn_telemetry/conn_telemetry.inf +./plug/business/app_sketch_local/app_sketch_local.inf ./plug/business/gtp_signaling_plug/gtp_signaling_plug.inf \ No newline at end of file