Professional Documents
Culture Documents
M U
Sau hn 30 nm ra i v khng ngng pht trin, mng Internet mang nhng c im
ni tri m trong chng ta khng ai c th ph nhn, t kh nng lin kt mnh m n
ngun thng tin di do cng nh vn thi gian v tc x l thng tin. Nhng song
song vi nhng u im th mng Internet li cha ng trong n nhng him ha
khn lng.
Hy tng tng mt ngy p tri no , nhng thng tin mt m chng ta c cng
ct giu li b phi by ra trc tt c mi ngi, n b nh cp m ngay chnh bn thn
chng ta cng khng bit l n b ly i! Thng tin mt ca mt con ngi quan
trng, nhng nu n l thng tin mt ca mt cng ty, mt t chc hay cao hn l ca
quc gia? iu g s xy ra khi n b nh cp?
Trong h thng mng Workgroup, thng tin khng c qun l tp trung dn n rt
nhiu bt cp trong vn qun l cng nh kh nng bo ton d liu. V vy trong mt
cng ty nu s dng mng ny chia s thng tin s v cng nguy him, s dng h
thng mng c qun l theo m hnh Domain l iu tt yu. Mt cng ty vn cha
ng rt nhiu thng tin v trong c nhng thng tin mang tnh chin lc cho s pht
trin ca cng ty, vn qun l v bo mt thng tin c t ln hng u. c th
to dng mt h thng thng tin ni b, d dng cho nhn vin s dng, thun tin cho
cng vic qun l cng nh vic trao i thng tin th vic xy dng h thng File Server
l rt cn thit. T thng tin c qun l tp trung v s dng chin lc Backup
Restore hp l trnh tnh trng thng tin b tht thot!
Da trn tnh hnh thc t, nhm chng ti nghin cu v pht trin d n Kho st ,
thit k v trin khai h thng mng cho doanh nghip vi tnh n nh v bo mt cao
tp trung khai khc cc u im ca File Server .
Chng ti tin tng rng, vi n ny, chng ti c th gip cc cng ty qun l, s
dng v bo mt tt thng tin cng ty tn dng tt cng ngh v ph hp vi ngun ti
chnh ca mt cng ty va v nh ang trn pht trin.
Trang 1
Thc Tp Tt Nghip
Thc Tp Tt Nghip
Ni dung chuyn mn cn c :
WSUS
Remote Assistant : dng h tr support t xa khi ngi qun tr t internet
remote v cng ty.
Group policy: account, local, software restriction.
File server: Sharing & NTFS permission, backup & restore.
User & Group: home folder, script (log in).
DHCP.
DNS.
Printer server: ngoi cc cu hnh c bn c thm phn c th s dng printer qua
internet.
RAID
Web, FTP c publish(NAT) ra internet dng RRAS.
Deploy antivirus.
Trang 3
Thc Tp Tt Nghip
Trang 4
Thc Tp Tt Nghip
Trang 5
Thc Tp Tt Nghip
Yu cu
S lng
Server
Server
Modem ADSL
Switch
8 port
Printer
LaserJet
Cable
RJ45-ADC
450 m
Trang 6
Thc Tp Tt Nghip
RRAS, Antivirus: lm chc nng router (Lan-Routing, VPN, NAT), qun l vic
qut virus cho cc antivirus client trn my nhn vin v cp nht cc bn dit virus
mi t internet.
3. Chi ph :
( Gi thnh ti thi im thng 12/2011)
Thit b
Yu cu
S lng
Gi thnh
Tng cng
Server
Server
890 $
4450 $
32 $
32 $
Modem ADSL
Switch
8 port
15 $
30 $
Printer
LaserJet in mng
382 $
1528 $
Cable
RJ45-ADC
450m
85$ /thng
135 $
Tng chi ph linh kin: 5793$ (cha bao gm cc chi ph pht sinh v bn quyn phn
mm)
Tng ng: 121.653.000 ng (t gi USD: 21.000 thng 12/2011)
Trang 7
Thc Tp Tt Nghip
4. ng truyn kt ni :
ng truyn trong mng LAN: s dng cp RJ45 tc 100 Mbps
ng truyn Internet: s dng gi cc MegaOFFICE ca FPT
Tc truy cp Internet ti a Download 3,072 Kbps Upload 640 Kbps
Cam kt v tc truy cp Internet ti thiu Download T 128 Kbps Upload T
128 Kbps.
Trang 8
Thc Tp Tt Nghip
Deseription
Interface
IP
Mack
Modem ADSL
External
192.168.1.113 255.255.255.252
192.168.1.113
DNS ISP
External
192.168.1.114 255.255.255.252
192.168.1.113
DNS ISP
Router
Antivirus
LAN Floor 1
192.168.1.1
LAN Floor 2
192.168.1.65 255.255.255.224
255.255.255.192
DC 1
192.168.1.97
DNS 1
192.168.1.101
192.168.1.98
DHCP 1
DC 2
192.168.1.97
DNS 2
192.168.1.101
192.168.1.98
For wader : ISP
DHCP 2
File Server
192.168.1.97
WSUS Server
192.168.1.101
192.168.1.98
RIS Server
Web Server
192.168.1.97
FTP Server
192.168.1.101
192.168.1.98
Printer Server
Floor 1
Floor 2
LAN_Floor 1
LAN_Floor 2
192.168.1.2
255.255.255.192
192.168.1.62
192.168.1.66
255.255.255.224
192.168.1.94
192.168.1.97
192.168.1.1
192.168.1.98
192.168.1.97
192.168.1.65
192.168.1.98
Trang 9
Thc Tp Tt Nghip
Trang 10
Thc Tp Tt Nghip
Trang 11
Thc Tp Tt Nghip
Group Type
OU
BanGiamDoc
BanGiamDoc
ThuKy
BanGiamDoc
KToan
KeToan
HC-NS
HanhChinhNhanSu
KT-KD
KeHoachKinhDoanh
KThuat
KyThuat
Trang 12
Thc Tp Tt Nghip
2.3.2
S dng thit b lu tr chuyn dng cho vic backup l Tape Driver: Hewlett
Packard StorageWorks DAT 24 (DW069A) DAT Tape Drive DAT, 12 GB, USB 2.0
Interface, Internal Enclosure, 1.5 MBps, For: PC Platforms. Gi: 220$
Chn thi gian backup thch hp tt nht l vo nhng lc vng nhn vin lm vic
nh vo lc ngh tra hoc sau gi lm vic.
S dng cc chin lc restore ph hp nh: Primary, Non-Authoritative,
Anthoritative
2.3.3 Cch thc hin:
a. Backup System State: dng backup li database ca Active Directory. Dng
chng trnh backup NTBACKUP c sn ca Windows tin hnh backup system
state cho h thng.
b. Restore AD: Ty vo cc trng hp khc nhau ca s c Domain Controller ta tin
hnh cc kiu restote database khc nhau
Trng hp 1: Authoritative Restore
Khi chn cch phc hi ny t my DC1 (file backup trn my ny), d liu c
nhn bn (replicate) ngc li t my DC2. Nu mun chn gi li i tng no
c to ra sau thi im backup trn DC1 ta s chy dng lnh NTDSUNTIL gi
li i tng .
Gi s mun gi li user NV-Ktoan01 trn DC1 c to ra sau thi im backup, ta
ln lt chy dng lnh trn cmd nh sau:
NTDSUNTIL
Authoritative Restore
Restore Object cn=NV-Ktoan01,ou=Ktoan,ou=KeToan,dc=tsn,dc=vn
Quit
Trang 13
Thc Tp Tt Nghip
Restart
Trng hp 2: Non-Authoritative Restore
Hnh thc ny s ghi li tnh trng h thng khi tin hnh backup kt hp vi nhng
i tng t my DC bn kia sau khi bn backup c to ra, gi s ta to bn backup
trn DC1 v sau to user NV-Ktoan01 trn DC2. Sau tin hnh restore file
backup. Sau khi restore h thng s bao gm nhng i tng khi backup cng vi
user NV-Ktoan01 c to ra trn DC2 nhn bn qua.
Trng hp 3: Primary Restore
Hnh thc ny s ly trng thi mi nht cho file backup v phc hi li cho DC tin
hnh restore, h thng t ng ng b cho DC khc trn h thng. Ta s dng cch
backup ny khi tc c cc my DC u b mt d liu v mun phc hi li d liu ti
thi im backup.
2.3.4
Thc Tp Tt Nghip
Cn bng ti
Security (dynamic update)
Gim traffic h thng (khng phi transfer m thng tin Dns c replicate chung
voi AD)
3.2 Yu cu nh hng v cch thc hin:
Xy dng 2 DNS primary server m bo tnh sn sng v kh nng chu li. Khi
1 server b s c DNS server cn li s thc hin cc yu cu phn gii ca client.
Xy dng h thng DNS trn server01
Vo control panel ci t Dns service
Cu hnh Primary Zone tch hp AD
Cu hnh Forward lookup zone v Reverse lookup zones
Xy dng DNS trn server02
Ch cn ci t DNS service sau tc c cc d liu s c replicate t my
dns1 qua.
Sau khi cu hnh xong ta s tin hnh kim tra DNS c phn gii ng hay khng
bng lnh nslookup trn CMD . Nu phn gii tt kt thc qu trnh cu hnh v tip
tc xy dng cc dch v khc.
3.3 Tng kt dch v DNS
DNS l mt dch v cc k quan trng trn h thng mng. DNS c th phn gii
ng v c kh nng hot ng n nh, ta cn tin hnh cc bc cu hnh chnh xc
Trang 15
Thc Tp Tt Nghip
Nhc im:
a ch IP c cp s b thay i, khng bo m c mt a ch ring bit cho
mt Client trong mi lc khi Client cn mt a ch IP tnh.
Qu trnh cp pht IP gia DHCP client v DHCP server l tn hiu broadcast nn
khng th i qua c Router.
4.3 Cc yu cu chung khi trin khai dch v DHCP server
Trang 16
Thc Tp Tt Nghip
DHCP Client
Windows XP
DHCP Server
Windows Server 2003
DHCP Server Service c ci t trn Server
cu hnh IP tnh, Subnet Mask v Default Gateway
C Range IP hp l
Trang 17
Thc Tp Tt Nghip
Ch thch:
003
Router
006
DNS Servers
015
Cu hnh Superscope
Backup & Restore DHCP database
Mc ch:
m bo an ton cho database ca DHCP Server
Khc phc nhanh s c xy ra i vi database ca DHCP Server
Cch thc hin:
To ra mt folder cha file backup ca DHCP trn a C:\
Backup d liu ca DHCP Server n folder to sn trn a C:\
Khi Restore s ch ng dn n folder cha file backup to trn a C:\
Nn DHCP database
Mc ch:
Tit kim dung lng lu tr
Cch thc hin:
Trang 18
Thc Tp Tt Nghip
Thc Tp Tt Nghip
Trang 20
Thc Tp Tt Nghip
Trang 21
Thc Tp Tt Nghip
Share
NTFS (advanced)
Users/Group
Public
Full
Travel Folder /
control
Execute file
ThuKy
KToan
Data
Read Attributes
Read Extend
Attributes
Apply onto
subfolders and
files
HC-NS
KT-KD
KThuat
Create Folders /
Append Data
Report
Full
Travel Folder /
control
Execute file
ThuKy
KToan
Data
Create Folders /
Append Data
Read Attributes
subfolders and
files
HC-NS
KT-KD
KThuat
Write Attributes
Application
Full
control
Full control
Trang 22
Thc Tp Tt Nghip
Thc Tp Tt Nghip
Trang 24
Thc Tp Tt Nghip
a. Yu cu v nh hng
Cc yu cu:
nh hng:
Trang 25
Thc Tp Tt Nghip
Backup Differential:
Kiu backup l file backup c to ra gm backup Full ca ngy hm trc v s
thay i ca ngy cn backup
Thi im dng :Thng dng vo cc ngy cn li trong tun tr th 2 v th 7
u im: bakup li bn Full ca ngy hm trc v s thay i ca ngy backup
nn khi restore s nhanh hn incremental
Khuyt im: thi gian backup s lu hn kiu normal nhng thi gian restore
nhanh hn kiu incremental, cn storage ln cha file backup.
b. Cch thc hin:
Tun 1
Tun 2
Tun 3
Th 2: Bnh Thng
Th 2: Kh khng
Th 2: Kh khng
Th 3: Gia Tng
Th 3: Gia Tng
Th 3: Gia Tng
Th 4: Gia Tng
Th 4: Gia Tng
Th 4: Gia Tng
Th 5: Gia Tng
Th 5: Gia Tng
Th 5: Gia Tng
Th 6: Gia Tng
Th 6: Gia Tng
Th 6: Gia Tng
Th 7: Bnh Thng
Th 7: Bnh Thng
Th 7: Bnh Thng
Trang 26
Thc Tp Tt Nghip
vic ngi ch cng m khng t thit lp cho mnh mt h thng sao lu d phng
n gin m khng cn mt qu nhiu cng sc vo vic backup hng ngy, hng gi
(k c khi c chng trnh h tr). a cng hin nay khng cn qu t v qu
sa x, v vy ta cn to cho cng ty mt h thng sao lu d phng c bn (RAID).
S dng Raid gip tng tc truy xut d liu cng nh bo m vic sao lu phc
hi cho a cng h thng mt cch an ton. Ty vo nhu cu ca cng ty ta c th
s dng Raid trn DC, File Server.
Yu cu v nh hng
Yu cu: S dng Raid tng tc truy xut, sao lu an ton v r tin.
nh hng: S dng Raid 5 thc hin.
Thc Tp Tt Nghip
Yu cu khi thit k cu trc chy Web: hot ng nhanh, cp nht kp thi thng
tin cho nhn vin v khch hng.
Vi FTP: gip user c th truy cp trong phm vi mng ni b cng nh t
internet vo
Vi Web: c web ni b v web public cho user v khch hng truy cp.
6.3 Trin khai cc dch v Web v FTP
Ci t IIS Component
To host v alias cho FTP v Web trn DNS server.
Trin khai FTP:
To mt FTP site mi
Cu hnh a ch IP, Port, ng dn n th mc share FTP
Cp quyn cho cc user s dng th mc share FTP, cp quyn Read, Wrire,
Brower cho user trn FTP site.
Trin khai Web:
To Web site mi
Cu hnh a ch IP, Port, ng dn n th mc share web
Cu hnh trang mc nh v cc ng dn dng truy cp web
Cp quyn Read cho user.
Nat port v cu hnh dyndns public FTP v Web:
Vo modem Nat port 80 - ng vi IP: 192.168.1.99 ca web server, Nat port t 20 n
21 - ng vi IP: 192.168.1.99 ca FTP server
Download v cu hnh DynDNS software trn my Web-FTP cp nht a ch IP
ln server min ph ca DynDNS.org (nu c mua IP public v domain th khng cn
phi s dng dch v min ph ca DynDNS.org)
6.4 Tng kt dch v Web v FTP
Trang 28
Thc Tp Tt Nghip
Sau khi Web-FTP c thit lp, thng tin ca cng ty c ph bin rng ri cho
cc nhn vin v khch hng. y l dich v h tr cc k hu ch cho bt c mt
cng ty no m bo s tin dng v tit kim chi ph.
Trang 29
Thc Tp Tt Nghip
Gi thnh r
C th s dng tc c cc loi my in c th in c
Kt ni n gin khng ph thuc vo cu hnh kt ni
n gin d trin khai
Nhc im:
Bt buc my in ni vi PC phi c m lin tc nu tt s nh hng n cc
ngi s dng chung my in trong cng mt phng ban
Tc in n khng cao
Tnh bo mt km
7.2 Trin khai dch v Printer server
a. Trin khai Internet Printing vi Printer server
Ci t dch v Internet Printing trong Control Panel
To my in mng, v tr v a ch printer server v ci t driver cho printer
server
To cc my in logic phn quyn cho cc Group v user khc nhau
To Printing Pool gip h thng khc phc s chm tr khi c qu nhiu yu
cu in
Map my in v my client thng qua trnh duyt internet.
b. Trin khai Local printing
Ci t v cu hnh cho my in cc b trn my tnh c gn my in
Share my in ra cho cc my khc bng ng dn UNC hoc s dng cu lnh
map my in cho tng client. Phn ny s thc hin trong Group Policy.
7.3 Tng kt dch v Printer server
Vi s qun l ca printer server, hot ng n nh - nhanh chng s gip cng vic
in n ca tc c nhn vin thun li hn. Trong m hnh mng ca cng ty
Trang 30
Thc Tp Tt Nghip
Trang 31
Thc Tp Tt Nghip
my member server.
Sau khi ci t v khi ng li h thng, ta tin hnh Unlock cho server v ty chn
cho server l Primary server.
Sau tin hnh trin khai phn mm xung my client (client trn 3 range khc
nhau, range server, range tng 1 v range tng 2)
Trang 32
Thc Tp Tt Nghip
Thc Tp Tt Nghip
Trang 34
Thc Tp Tt Nghip
Microsoft Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise
Edition;Windows Server 2003, Datacenter Edition; or Windows Server 2003, Web
Edition.
* Note:
ci t c WSUS ta cn thc hin ci t mt s chng trnh yu cu cho
WSUS:
1. Ci t IIS
2. Ci t Services Pack
3. Ci t dotNetFX35setup.exe
4. Ci t ReportViewer.exe
5. Cui cng l ci t WSUS ( y h thng chng ta s ci t ver3.0)
9.3 nh hng v trin khai thc hin WSUS
My ch SUS s phn tch cc h iu hnh yu cu cp nht, kim tra cc bn
service pack v cung cp cho my client nhng gi tin cn phi download v ci t
cc phin bn cp nht.
9.3.1 ng b d liu v cung cp cho h thng
Khi bt u vic ng b d liu my ch SUS s truy vn n my ch Windows
Update ca Microsoft hay cc my ch SUS khc trong h thng mng v download
ton b ti nguyn v cc bn v li hay cc service pack cho mi sn phm v ngn
ng m ta cu hnh. Qu trnh ng b d liu s c truyn khong 150 MB
cho phin bn English v 600MB cho mi ngn ng khc.
9.3.2 Thit lp Automated Updates trn my client
Ci t cc cp nht t Automatic Updates ca my client bng vic ci t cc gi
MSI. cung cp cc gi cp nht dng MSI bn c th d dng s dng Group
Trang 35
Thc Tp Tt Nghip
Thc Tp Tt Nghip
Acrobat Reader
Cc phn mm khc cho tng phng ban:
Phong k ton: phn mm k ton
Phng Hnh chnh Nhn s: phn mm qun l nhn s
Phng K hoch kinh doanh: phn mm thit k m hnh Microsoft Visio
Cu hnh GPO p t cc chnh sch khc nh:
T ng khi ng Internet Explore vi trang ch ca cng ty khi user ng nhp
vo mng
Khng nhn thy Properties ca My Documents
Khng nhn thy v khng truy cp c a C trn my Local
Map my in local, map a mng
10.2 Trin khai cc chnh sch t yu cu t ra
S dng cng c Group Policy Management qun l tp trung cc policy c trn
h thng.
Cc ng dng Word, Exel, PowerPoint c qun l trong mt policy chung v trin
khai (lin kt) xung tc c cc OU phng ban.
Cc ng dng phn mm chuyn ngnh, mi phn mm s c cu hnh deploy
trong mt Policy
Thc hin p t cc chnh sch khc: Mi chnh sch c cu hnh trong mt
policy ring.
11. Cc dch v h tr
11.1 Dch v RIS
Trong mt m hnh h thng c nhiu my trm, ci t h iu hnh cho tt c
my trm th i hi ngi qun tr phi mt rt nhiu thi gian ci t cho tng
my. Vi chc nng ci t h iu hnh mt cch t ng qua mng, dch v RIS ra
i ngi qun tr gii quyt vn ny mt cch nhanh chng v c hiu qu.
Trang 37
Thc Tp Tt Nghip
u nhc im ca dch v
u im
Ci t h iu hnh mt cch t ng
My trm ch cn c card mng h tr PXE, khng cn c CD-ROM
Ngi qun tr khi mt cng i ci t trn tng my
C th ci t cho tt c my trm vi mi cu hnh
My trm sau khi ci t xong t ng join domain
Nhc im
Cu hnh phc tp
Thi gian ci t s rt lu nu s lng my trm ln
11.1.3 Yu cu chung khi trin khai dch v
My tnh cha dch v RIS Server phi l thnh vin ca Domain hoc l dch v
RIS Server ny nm trn Domain
Server ci t RIS phi c 2 phn vng khc nhau
Phn vng cha file ci t RIS phi c nh dng NTFS
C DHCP Server c Active trn mng
C DNS phn gii tt trn mng
C mt Windows CD hoc c mt folder share cha cc file ci t
My Client phi h tr PXE boot ROM hoc card mng c h tr boot floppy
11.1.4 nh hng v trin khai dch v
nh hng thc hin
Cc my trm trong h thng c cng cu hnh
Ci t h iu hnh Windows XP Professional cho tt c my trm
Trang 38
Thc Tp Tt Nghip
Trang 39
Thc Tp Tt Nghip
Trang 40
Thc Tp Tt Nghip
Enable Routing and Remote Access v cu hnh chc nng Remote Access (dialup or VPN)
Cu hnh Range IP cho cp cho client khi connect vo mng v hon tt qu trnh
trn cu hnh trn server
c. Cu hnh VPN Client trn my Client ngoi vo:
Trang 41
Thc Tp Tt Nghip
Trang 42
Thc Tp Tt Nghip
Trang 43
Thc Tp Tt Nghip
Tin hnh nhn tin cho vic thit k, lp t v tin thit b t khch hng.
K cc bin bn xc nhn lin quan.
F.
nh gi hiu qu
Sau khi thit k v xy dng h thng ny, nhm 06PBL152 nhn thy rng h
Trang 44
Thc Tp Tt Nghip
KT LUN
i vi mt h thng th lun bo m ng bn yu cu c bn:
Yu cu v bo mt thng tin
Yu cu v kh nng hot ng nhanh nhy
Yu cu v kh nng chng chu vi mi trng h thng
Yu cu v kh nng m rng
Sau khi hon tc qu trnh xy dng v a vo hot ng, trong tng lai khng xa
kh nng cng ty s pht trin v cn thit mt h thng ln mnh v kh nng bo
mt thng tin cao hn na.
T t ra phng php m rng cho h thng l vn cn c cp ti khi bt
tay vo xy dng mt h thng. Ta s chn la nhng thnh phn v cu trc chnh c
kh nng m rng trong tng lai.
Sau y l phng n m rng h thng m nhm 06PBL152 vch ra cho h thng
trn:
Trin khai CA, IP SEC cho h thng bo mt c nng cao hn
Trin khai vpn (ci radious server nu cn chng thc v qun l trong giao tip
VPN) v kt hp vpn ipsec hoc SSL.
Trang 45
Thc Tp Tt Nghip
http://uet.vnu.edu.vn/tltk/Learning/File_PDF/giao_trinh_mang_doanh_nghiep_0313.pdf
ca H Cng Nghip .
http://www.nhatnghe.com/forum/showthread.php?t=92817 Ca trng Nht Ngh
http://giaiphapmang.biz/ Ca Doanh nghip LTC
Cng nhiu ti liu qu gi su tm trong 3 nm qua .
Trang 46