{"id":349,"date":"2022-03-29T15:30:37","date_gmt":"2022-03-29T12:30:37","guid":{"rendered":"http:\/\/yusufziyagulec.com\/blog\/?p=349"},"modified":"2022-05-18T15:58:57","modified_gmt":"2022-05-18T12:58:57","slug":"vcenter-7-esx-syslog-konfigurasyounu-ve-firewall-ruleset-tanimi","status":"publish","type":"post","link":"https:\/\/yusufziyagulec.com\/blog\/vcenter-7-esx-syslog-konfigurasyounu-ve-firewall-ruleset-tanimi\/","title":{"rendered":"vCenter 7 &#038; ESX Syslog Konfig\u00fcrasyounu ve Firewall Ruleset Tan\u0131m\u0131"},"content":{"rendered":"<p>vCenter 7 ve ESX&#8217;lerde Syslog tan\u0131m\u0131 yapmak i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar izlenir:<\/p>\n<p><strong>vCenter<\/strong><\/p>\n<p>VAMI ara y\u00fcz\u00fcnden yap\u0131l\u0131r. Standart olarak eri\u015fim https:\/\/&lt;vCenter IP&gt;:5480<\/p>\n<p>Sol men\u00fcde Syslog se\u00e7ene\u011fine t\u0131klayarak Syslog sunucunun IP&#8217;si ve haberle\u015fme portu tan\u0131mlan\u0131r.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-352\" src=\"http:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2.png\" alt=\"\" width=\"1338\" height=\"276\" srcset=\"https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2.png 1338w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-300x62.png 300w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-1024x211.png 1024w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-768x158.png 768w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-500x103.png 500w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-150x31.png 150w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-1200x248.png 1200w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-400x83.png 400w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-800x165.png 800w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog2-200x41.png 200w\" sizes=\"auto, (max-width: 1338px) 100vw, 1338px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-350\" src=\"http:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1.png\" alt=\"\" width=\"973\" height=\"549\" srcset=\"https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1.png 973w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-300x169.png 300w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-768x433.png 768w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-500x282.png 500w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-150x85.png 150w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-400x226.png 400w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-800x451.png 800w, https:\/\/yusufziyagulec.com\/blog\/wp-content\/uploads\/2022\/03\/syslog1-200x113.png 200w\" sizes=\"auto, (max-width: 973px) 100vw, 973px\" \/><\/p>\n<p><strong>ESXi<\/strong><\/p>\n<p>ESXi Syslog konfig\u00fcrasyonu vCenter veya ESX \u00fczerinden yap\u0131labilir. vCenter \u00fczerinden konfig\u00fcrasyonu yapmak i\u00e7in:<\/p>\n<p>\u0130lgili ESX host&#8217;ta Configure &#8211;&gt; Advanced System Settings &#8211;&gt; Syslog.global.logHost parametresi uygun \u015fekilde d\u00fczenlenir. \u00d6rn:<\/p>\n<p>tcp:\/\/10.0.0.120:514<\/p>\n<p>E\u011fer standart bir Syslog port tan\u0131m\u0131 (UDP 514) mevcutsa ESX loglar\u0131 Syslog sunucusuna akmaya ba\u015flayacakt\u0131r. Ancak g\u00fcvenlik nedeniyle syslog ileti\u015fim portu network katman\u0131nda de\u011fi\u015ftirilmi\u015fse, ESX firewall ayarlar\u0131nda yeni bir kural setiyle konfig\u00fcrasyon yapmak gerekir:<\/p>\n<p>Standart olan UDP 514 portunu TCP 6530 olarak de\u011fi\u015ftirildi\u011fini varsayal\u0131m. ESX&#8217;lere bu firewall kural setini eklemek i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar izlenir:<\/p>\n<p>1- SyslogFirewallConfig.xml isminde bir dosya olu\u015fturulup dosya bir edit\u00f6rle a\u015fa\u011f\u0131daki \u015fekilde d\u00fczenlenir:<\/p>\n<p><em><strong>&lt;ConfigRoot&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;service&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;id&gt;ServiceName&lt;\/id&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;rule id=&#8217;0000&#8242;&gt;outbound&lt;\/direction&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;protocol&gt;tcp&lt;\/protocol&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;porttype&gt;dst&lt;\/porttype&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;port&gt;6530&lt;\/port&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;\/rule&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;enabled&gt;true&lt;\/enabled&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;required&gt;false&lt;\/required&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;\/service&gt;<\/strong><\/em><br \/>\n<em><strong>&lt;\/ConfigRoot&gt;<\/strong><\/em><\/p>\n<p>2- SyslogFirewallConfig.xml dosyas\u0131 WinSCP gibi bir uygulama yard\u0131m\u0131yla her bir ESX hosttaki a\u015fa\u011f\u0131daki alana kopyalan\u0131r:<\/p>\n<p>\/etc\/vmware\/firewall\/<\/p>\n<p>3- Yeni kural setinin aktif olmas\u0131 i\u00e7in ESX hostlarda a\u015fa\u011f\u0131daki komut \u00e7al\u0131\u015ft\u0131r\u0131l\u0131r:<\/p>\n<p>#esxcli network firewall refresh<\/p>\n<p>4- Yeni kural seti aktif oldu\u011funda loglar Syslog sunucusuna akmaya ba\u015flayacakt\u0131r. Yeni kural seti -e\u011fer do\u011fru \u015fekilde tan\u0131mland\u0131ysa- a\u015fa\u011f\u0131daki ekrandan g\u00f6r\u00fcnt\u00fclenebilir:<\/p>\n<p>ESX &#8211;&gt; Configure &#8211;&gt; Firewall &#8211;&gt; Outgoing<\/p>\n<p>Ekledi\u011finiz kural halen g\u00f6r\u00fcnt\u00fclenemiyorsa a\u015fa\u011f\u0131daki komutlar\u0131 \u00e7al\u0131\u015ft\u0131rabilirsiniz:<\/p>\n<p><strong><em>esxcli network firewall set &#8211;enabled false<\/em><\/strong><br \/>\n<strong><em>esxcli network firewall unload<\/em><\/strong><br \/>\n<strong><em>esxcli network firewall load<\/em><\/strong><br \/>\n<strong><em>esxcli network firewall set &#8211;enabled true<\/em><\/strong><br \/>\n<strong><em>esxcli network firewall refresh<\/em><\/strong><\/p>\n<p><img class=\"aligncenter size-full wp-image-343\" alt=\"\" \/><img class=\"aligncenter size-full wp-image-343\" alt=\"\" \/><\/p>\n<p><strong>Referanslar<\/strong><\/p>\n<p>&#8211; <a href=\"https:\/\/kb.vmware.com\/s\/article\/2005304\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/kb.vmware.com\/s\/article\/2005304<\/a><br \/>\n&#8211; <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/7.0\/com.vmware.vsphere.monitoring.doc\/GUID-9633A961-A5C3-4658-B099-B81E0512DC21.html\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/docs.vmware.com\/en\/VMware-vSphere\/7.0\/com.vmware.vsphere.monitoring.doc\/GUID-9633A961-A5C3-4658-B099-B81E0512DC21.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>vCenter 7 ve ESX&#8217;lerde Syslog tan\u0131m\u0131 yapmak i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar izlenir: vCenter VAMI ara y\u00fcz\u00fcnden yap\u0131l\u0131r. Standart olarak eri\u015fim https:\/\/&lt;vCenter IP&gt;:5480 Sol men\u00fcde Syslog se\u00e7ene\u011fine t\u0131klayarak Syslog sunucunun IP&#8217;si ve haberle\u015fme portu tan\u0131mlan\u0131r. ESXi ESXi Syslog konfig\u00fcrasyonu vCenter veya ESX \u00fczerinden yap\u0131labilir. vCenter \u00fczerinden konfig\u00fcrasyonu yapmak i\u00e7in: \u0130lgili ESX host&#8217;ta Configure &#8211;&gt; Advanced System Settings&#8230; <a class=\"more-link\" href=\"https:\/\/yusufziyagulec.com\/blog\/vcenter-7-esx-syslog-konfigurasyounu-ve-firewall-ruleset-tanimi\/\">Continue reading <span class=\"meta-nav\">&#8594;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43],"tags":[137,9],"class_list":["post-349","post","type-post","status-publish","format-standard","hentry","category-vmware-2","tag-syslog","tag-vcenter"],"_links":{"self":[{"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/posts\/349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/comments?post=349"}],"version-history":[{"count":5,"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/posts\/349\/revisions"}],"predecessor-version":[{"id":379,"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/posts\/349\/revisions\/379"}],"wp:attachment":[{"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/media?parent=349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/categories?post=349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yusufziyagulec.com\/blog\/wp-json\/wp\/v2\/tags?post=349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}