แสดงบทความที่มีป้ายกำกับ Endian Firewall Community แสดงบทความทั้งหมด
แสดงบทความที่มีป้ายกำกับ Endian Firewall Community แสดงบทความทั้งหมด

1/30/2555

Endian Firewall Community 2.5 ออกแล้วครับ


ออกเวอร์ชั่นปลอดบั๊กแล้วครับ สำหรับ Endian Firewall 2.5 เมื่อปลายธันวาคม 2554 สำหรับการทดสอบ พบว่า น่าใช้กว่าเดิมมาก ทั้งจุดบกพร่องเดิมหลายตัว ก็ได้รับการแก้ไขให้ทำงานได้สมบูรณ์มากขึ้น

สำหรับรายละเอียดของการเพิ่มเติมมาในเวอร์ชั่นนี้ มี

* การจัดการโปรเซสที่เขียนขึ้นใหม่ New process management
การจัดการกระบวนการทั้งในพื้นหลังของระบบที่ได้รับการเขียนขึ้นใหม่ ด้วยเครื่องมือจัดการงานใหม่ของ Endian ทำให้ขั้นตอนการบูตที่ตอนนี้ ใช้เวลาเพียงครึ่งหนึ่งของเวอร์ชั่นก่อนหน้า
  The whole process management in the background of the system has been
  rewritten. With the new Endian Jobs engine the boot procedure now takes
  only half as long as before.

* ทำการปรับเปลี่ยนการจัดการทรัพยากรที่ดีกว่า Improved resource management
การเปลี่ยนแปลงที่สำคัญบางคนได้ทำเพื่อพร็อกซี่ต่างๆและป้องกันไวรัส
การตั้งค่า ส่งผลให้เกือบ 200 เมกะไบต์หน่วยความจำที่ถูกปลดปล่อย
ในระบบการกำหนดค่าอย่างเต็มที่
  Some major changes have been made to various proxy and antivirus
  settings. This resulted in almost 200 Megabytes of memory being freed
  in a fully configured system.

* การแก้ไขข้อผิดพลาด Bugfixes
ความพยายามอย่างมากที่ได้ทำเพื่อสร้างรุ่นเสถียร บนเส้นทางที่ Endian Firewall 2.5 การปรับปรุงขนาดเล็กจำนวนมากได้รับการทำแก้ไขข้อผิดพลาดหลายร้อยจุดที่ได้รับการแก้ไขในเวอร์ชั่นนี้
  Huge efforts have been made to create a stable release. On the road to
  Endian Firewall Community 2.5 many small improvements have been made
  and hundreds of bugs have been fixed.
 
* Trusted timestamping
เอ็นเดียนเวอร์ชั่นนี้สนับสนุนความสามารถ trusted timestamping โดยใช้ OpenTSA นี้
คุณลักษณะที่ช่วยให้เพื่อให้แน่ใจว่าล็อกไฟล์ของคุณไม่ได้ถูกแก้ไข หลังจากที่มันได้ได้รับการเก็บบันทึกไว้แล้ว
  Endian Firewall now supports trusted timestamping using OpenTSA. This
  feature allows you to make sure your log files have not been modified
  after they have been archived.
 
แต่สำหรับกระบวนการ Upgrades จากเวอร์ชั่น Endian Firewall Community 2.4.1 มายัง version 2.5 จะสามารถทำได้ในปลายเดือนมกราคม 2555 นี้ครับ

สำหรับการติดตั้ง Webmin สำหรับเวอร์ชั่น 2.5 นี้ ง่ายกว่าเดิมเยอะมากครับ สามารถ Download webmin เวอร์ชั่นล่าสุด มาติดตั้งได้เลยจาก http://www.webmin.com ซึ่งตอนนี้ เป็น Webmin 1.580 สามารถดาวน์โหลดได้ที่ http://prdownloads.sourceforge.net/webadmin/webmin-1.580-1.noarch.rpm ครับ
ทำการติดตั้งโดยใช้คำสั่ง
rpm -ivh webmin-1.580-1.noarch.rpm
โดยที่ไม่จำเป็นต้องใช้ Endian Firewall Development มาลงก่อนเลยครับ ทำงานได้เลย แต่บางโปรเซส ต้องทำการ กำหนดค่า config ให้ถูกต้องด้วยครับ จึงจะกำหนดจาก webmin ได้ทั้งหมด

12/31/2554

การใช้งาน Endian Firewall Community ตอน การเซ็ตอัพเครือข่าย

Endian Firewall Community เป็น linux security distribution ที่มีฟังก์ชันของระบบการจัดการความปลอดภัยทางเครือข่ายแบบรวม (UTM : Unified Threat Management)  เป็นซอฟต์แวร์ที่ได้ออกแบบมาเพื่อให้จัดการและใช้งานได้ง่าย  โดยมีคุณสมบัติที่ประกอบด้วย Stateful Packet Inspection (SPI) Firewall แอพพลิเคชันพร๊อกซี่สำหรับ HTTP,FTP, POP3,SMTP และ DNS  เครื่องมือในการกลั่นกรองเว็บรวมถึง VPN แบบ OpenVPN และ IPSec  โดยข้อดีหลักของ Endian Firewall Community คือเป็น Open Source ที่สามารถประยุกต์ใช้งานกับเครือของเรา
ความสามารถที่ทางเว็บไซต์ของ EFW (http://www.efw.it) มีดังนี้·      
การสำรองข้อมูล
สามารถบันทึกและกู้คืนผ่าน
USB device   สามารถตั้งเวลาให้มีการสำรองข้อมูลแบบอัตโนมัติและส่งข้อมูลการสำรองที่ผ่านการเข้ารหัสแล้วผ่านทางอีเมล์·      
Dashboard
หน้าเพจหลักจะถูกแทนที่ด้วย
dashboard ซึ่งเป็นสถิติเกี่ยวกับระบบและบริการต่างๆ อันเป็นกราฟแบบ live-graphs สำหรับทราฟฟิกขาเข้าและขาออก·      
ระบบแจ้งเตือนทางอีเมล์
เป็นการส่งอีเมล์โดยอัตโนมัติตามที่ได้กำหนด  เมี่อมีเหตุการณ์ต่างๆ เกิดขึ้น·      
HTTP proxy time based access control
เป็นการควบคุมการเข้าใช้งาน
HTTP Proxy โดยกำหนดช่วงเวลาในการใช้งานได้·      
HTTP proxy with user- and group-based content filtering
เป็นความสามารถในการกำหนดผู้ใช้งานและกลุ่มผู้ใช้งานเพื่อควบคุมการกลั่นกรองการเข้าใช้งานเว็บไซต์
·      
Intrusion Prevention
มีระบบการการป้องการการบุกรุกทางเครือข่ายโดยใช้กฎของ Snort ที่สามารถคอนฟิกได้  ซึ่งสามารถที่จะละทิ้งแพ็กเกตการบุกรุกที่เหมือนกับข้อมูลใน Log ได้·      
Policy routing
สามารถสร้างกฎการจัดเส้นทางโดยยึดถืออินเตอร์เฟส
, MAC Address หรือพอร์ตของแพ็กเกตได้·      
Port forwarding rewrite
การทำ
 Porwarding ในเวอร์ชันก่อน 2.3 สามารถฟอร์เวิร์ดได้เฉพาะ Red zone เท่านั้น แต่ในเวอร์ชันนี้สามารถทำได้จากทุกโซนโดยปราศจากการทำ NAT·      
Quality of Service and Bandwidth Management
การจัดรูปร่างของทราฟฟิก
(Traffic Shaping) ได้ถูกแทนที่ด้วย QoS Module ซึ่งสามารถทำได้โดยใช้ device, classes และ rules·      
SNMP support
สนับสนุน
SNMP แบบพื้นฐาน  ซึ่งการใช้งานต้องทำการ Enable SNMP Server พร้อมป้อนค่าที่เกี่ยวข้อง·      
SMTP proxy web interface rewrite
ได้มีการปรับปรุง
Web Interface ในส่วน SMTP Proxy โดยเน้นการใช้งานที่สะดวก·      
VLAN support (IEEE 802.1Q trunking)
เวอร์ชันนี้สามารถสร้าง
VLANs บนทุก Interface ได้  โดย VLAN Interface สามารถใช้งานเพื่อแบ่งแยกการเชื่อมต่อในโซนเดียวกัน  การเซ็ตอัพเครือข่ายทำได้ด้วยเลือกเมนู System จาก Menu bar ส่วนบนของหน้าจอ แล้วเลือกเมนูย่อย Network configuration ทางด้านซ้ายของหน้าจอ   
การเลือกชนิดของ Red Interfaceเมื่อเราติดตั้ง Endian Firewall Community แล้ว  อินเตอร์เฟสที่เป็น trusted network (เรียกว่า Green Interface) จะถูกเลือกและเซ็ตอัพ   และการเลือก untrusted interface network (เรียกว่า Red Interface) เพื่อเชื่อมต่อไปยังผู้ให้บริการอินเตอร์เน็ต (outside) สามารถใช้งานได้เป็น 7  รูปแบบดังนี้
1.             ETHERNET STATIC
ต้องมีการเซ็ตอัพค่าข้อมูลเครือข่ายของ Ethernet Adapter เช่น IP และ Netmask เป็นแบบ manual  การใช้งานแบบนี้โดยทั่วไปจะเชื่อมต่อ RED Interface กับเราเตอร์โดยใช้สายอีเทอร์เน็ต แบบ crossover
2.               ETHERNET DHCP
เป็นการเซ็ตอัพค่าข้อมูลเครือข่ายของ Ethernet Adapter ให้รับค่าจาก DHCP การใช้งานแบบนี้ใช้สำหรับการเชื่อมต่อ RED Interface กับ cable modem/router หรือ ADSL/ISDN router โดยใช้สายอีเทอร์เน็ตแบบ crossover
3.              PPPoE
เป็นการเชื่อมต่อ Ethernet adapter แบบ crossover เข้ากับ ADSL modem การใช้งานแบบนี้ต้องเซ็ตค่าที่โมเด็มเป็นแบบบริดจ์  และให้เครื่องที่เป็น EFW Community ใช้ PPPoE เชื่อมต่อกับผู้ให้บริการ  ทั้งนี้อย่าสับสนกับการใช้งานผ่าน ADSL modem ที่เป็นแบบ ETHERNET STATIC และ ETHERNET DHCP ซึ่งทั้งสองแบบนี้มีการทำ PPPoE บนตัว Router เอง
4.              ADSL (USB, PCI)
เป็นการใช้งานกับ ADSL modem แบบ USB และ PCI
5.              ISDN
เป็นการใช้งานกับ ISDN adapter
6.              ANALOG/UMTS Modem
เป็นการใช้งานกับระบบอานาล็อก (dial-up) หรือ UMTS (cell-phone) modem
7.              GATEWAY
เป็นการใช้งานกับเครื่องที่ไม่มี RED Interface  การใช้งาน Firewall โดยทั่วไปจะต้องมีสองอินเตอร์เฟสเป็นอย่างน้อย  แต่บางสถานการณ์เราสามารถใช้แค่อินเตอร์เฟสเดียวได้  เช่น  การใช้งานที่ต้องการทำเป็น Firewall อย่างเดียวเท่านั้น  หรืออีกแบบอาจจะใช้ในกรณีที่ BLUE zone ของ EFW ถูกเชื่อมต่อกับ VPN ผ่าน GREEN interface ของ EFW ตัวที่สอง ในสถานการณ์แบบนี้ IP Address ของ Green interface ของ Firewall ตัวที่สอง สามารถถูกใช้เป็น backup uplink บน Firewall ตัวแรก  ซึ่งถ้าเลือกออฟชันนี้จะต้องมีการคอนฟิก default gateway ในภายหลัง

12/30/2554

การติดตั้ง Endian Firewall Community 2.4

ความรู้พื้นฐานเกี่ยวกับไฟล์วอลล์
Firewall คือระบบที่ใช้ป้องกันการบุกรุกจากภายนอกสู้ภายใน และในทางกลับกัน ก็ใช้ป้องจากถายในสู้ภายนอก ด้วยเช่นกัน ในปัจจุบันมีผู้ผลิต Firewall ทั้งที่เป็น Hardware และ Software ทั้งแบบที่นำมาใช้โดยไม่มีค่าใช้จ่าย (Open Source) เช่น Pfsense Firewall ที่พัฒนามากจาก FreeBSD(Unix Base), Endian Firewall Communityที่พัฒนามากจาก Redhath5 (Linux Base) และ แบบที่ต้องจ่ายเงินให้กับผู้จำหน่ายเป็นรายปี อย่างเช่น ISA ของ Microsoft หรือ Firewall ของบริษัท Sophos ซึ่งจำหน่ายทั้งเป็น Hardware และ Software เกี่ยวกับระบบความปลอดภัยทั้งหมด หรือ Endian Firewall ที่เป็น Hardware (Box) ซึ่งมีหลากหลายขนาดให้เลือกใช้งานตามความเหมาะสม หรือเป็น Software ซึ่งคิดราคาตามจำนวนของ User ซึ่งข้อแตกต่างกับที่เป็น Community ก็คือการบริการหลังการขาย การแก้ไขปัญหาต่างๆให้กับลูกค้าอย่างรวดเร็ว และมีปสิธภาพ และยังมี Firewall Client อีกประเภทที่จะถูกติดตั้งมากับระบบปฏิบัติการอย่างเช่น Windows Firewall หรือจะซื้อมาติดตั้งเองอย่างเช่น Nod32 Smart Security ซึ่งเป็น Antivirus ที่รวมเอาคุณสมบัติของ Firewall มารวมเข้าไว้ด้วยกัน
structure.png



การติดตั้ง Endian Firewall Community 2.4
Endian Firewall Community คือ ลีนุกซ์ประเภทหนึ่งที่ออกแบบมาเพื่อความปลอดภัย ซึ่งถูกเปลี่ยนทุกระบบเพื่อมาเป็น อุปกรณ์ทางด้านความปลอดภัยของเครือข่ายด้วยการทำงานแบบ Unified Threat Management (UTM)* ตัวซอฟท์แวร์ถูกออกแบบให้ใช้งานได้ง่าย ง่ายต่อการติดต้ังใช้งานและการจัดการ โดยคุณลักษณะที่เพิ่มเข้ามาได้แก่…
1. Stateful packet inspection firewall**
2. Application-level proxies for various protocols (HTTP, FTP, POP3, SMTP) with Antivirus
support
3. Virus and spamfiltering for email traffic (POP and SMTP)
4. Content filtering of Web traffic
5. VPN solution (based on OpenVPN)
ข้อดีที่สำคัญของ Endian Firewall คือเป็น software แบบ Open source สนับสนุนโดย บริษัท Endian S.r.l.
* Network firewall + E-mail spam filtering + Anti-virus capability + IDS or IPS = UTM
** Stateful packet inspection firewall
ข้อมูลเพิ่มเติมที่ http://www.endian.com/en/community/feature-comparison/
รูปแบบการใช้งานโดยทั่วไปของ Endian Firewall Community
ลักษณะการใช้งานทางเครือข่ายของ Endian Firewall ถ้าใช้เต็มระบบแล้วจะเป็นดังรูปที่ 1 นั่นคือจะประกอบด้วยเครือข่าย 4 เครือข่ายคือ
  1. RED : ซึ่งใช้สำหรับเชื่อมต่อกับเครือข่ายภายนอก (untrusted network หรือ Internet)
  2. GREEN : ซึ่งใช้เชื่อมต่อกับเครือข่ายภายใน (trusted network หรือ Internal)
  3. ORANGE : ซึ่งใช้เชื่อมต่อกับเครือข่ายที่เป็นพื้นที่ของ Server (DMZ)
  4. BLUE : ซึ่งใช้เชื่อมต่อกับเครือข่ายที่เป็นระบบไร้สาย (Access Point)


รูปภาพการทำงานของ Endian แบบเต็มระบบ
Hardware-Requirements
สำหรับเน็ตเวิร์คเล็กๆ 25 user กับ VPN 5 Connections เขาแนะนำ
  • Pentium 3 1000MHZ+
  • 512MB RAM
  • 8 GB Hard Disk
  • 2x 100mb Network Cards
  • Extra cooling fans and good ventilation, as the PC will be operational 24x7x365
สำหรับเน็ตเวิร์คขนาดกลาง 50 users กับ 10 VPN connections เขาแนะนำ
  • Pentium 4 2.8GHZ+
  • 1GB RAM
  • 100 GB Hard Disk
  • 2x 1Gb Network Cards
  • Extra cooling fans and good ventilation, as the PC will be operational 24x7x365

เตรียมการและติดตั้ง

Host เป็น OS:WindowsXP Pro SP3 , CPU:CERARON 3.6 GHZ , HDD:160 , RAM:1GB ,ส่วน Internet ที่ผมใช้เป็น Nokia 2700 Classic + Dtac Internet ลง Nokia PC Suite และเชื่อมต่อ Internet เรียบร้อย
Guest คือ Endian Firewall : 512 RAM , 20GB Hard Disk ,2x 10/100mb Network Cards : Interface1 Bridge กับ Lan ของจริง (ทำเป็น GREEN Interface) Interface2 NAT กับ Host (ทำเป็น RED Interface)
เครื่องโนตบุ๊ค 1 เครื่อง เพื่อใช้คอนฟิก Firewall โดยผ่าน Bowser
ดาวน์โหลดโปรแกรมได้ที่ http://www.endian.com/en/community/download/ เมื่อเรียบร้อยแล้วก็นำไฟล์ iso มาเขียนลงแผ่น cd ให้เรียบร้อยครับ
เริ่มการติดตั้ง
1.ใส่แผ่น Endian เข้าไป โดยตั้ง Bios ให้บูตจาก Cd-Rom เป็นอันดับแรกจะได้ดังรูปด้านล่างครับ

2.โปรแกรมการติดตั้งจะให้เราเลือกจะใช้ภาษาอะไรในการติดตั้ง ผมจะเลือกภาษาอังกฤษนะครับ เลือกแล้วก็กด OK โดยใช้ปุ่ม Tab ในการเลือก

3.โปรแกรมจะแสดงข้อความต้อนรับเพื่อเข้าสู่การติดตั้งโปรแกรมครับ เมื่อขึ้นหน้าต่างนี้มาให้เลือก OK ครับ


4.โปรแกรมจะแจ้งเตือนเราว่า ถ้าเรายืนยันที่จะติดตั้งโปรแกรม ข้อมูลเดิมทีมีอยู่ก็จะหายทั้งหมด ในที่นี้ผมจะยืนยันการติดตั้ง เนื่องจากน HDDไม่มีข้อมูลอะไรสำคัญ ถ้ามีข้อมูลสำคัญควรจะสำรองข้อมูลไว้ก่อนนะครับ ผมเลือก YES และก็ OK

5 .ถ้าเราต้องการที่จะใช้ Terminal ผ่านทาง Serial Port เพื่อเชื่อมต่อกับ Firewall ก็ให้ตอบ YES ครับ แต่ผมจะเข้าคอนฟิก Firewall ผ่านทาง Green Interface ของ Firewall โดยผ่านทาง Browser ครับ เพราะฉนั้นผมจะตอบ NO และก็ OK

6.โปรแกรมจะเริ่มทำการติดตั้ง รอสักพักนะครับ

7.โปรแกรมจะให้เราทำการกำหนด IP address สำหรับ GREEN Interface ผมขอใช้ตามในภาพเลยและกัน ตอบ OK ครับ

8.ขั้นตอนสุดท้ายของการติดตั้ง จะแสดงหน้าจอดังรูป ตอบ OK ครับ

9. เครื่องจะ Reboot ครับ


จบขั้นตอนการติดตั้ง และแผ่น CD ก็จะเด้งออกมาเองครับ





ภาพการ Boot ของ Emdian Firewall Community 2.4





การใช้งาน Endian Firewall Community 2.4

เมื่อติดตั้งเสร็จแล้ว ก็ทำการเช็คสาย Lan ก่อนครับว่าเสียบถูกช่องหรอไม่ สายที่ 1 ก็คือสายทีต่อออกจาก Router ให้เสียบเข้ากับ interface1ครับ (RED Interface) สายที่2 ให้เสียบเข้ากับ interface2 ของ Firewall แล้วอีกด้านก็เสียบเข้ากับ SW ภายในครับ หรือจะเสียบตรงกับเครื่อง Labtop ก่อนก็ได้ เมือเรียบร้อยแล้ว เราก็ตั่ง IP ของเครื่องให้ตรงกับ Firewall 192.168.0.15/24 เครื่องเราก็ตั้งให้เป็น 192.168.0.1/24 ก็ได้ครับ
1.เปิด browser ขึ้นมา แล้วพิมพ์ หมายเลข IP ของgreen Interface คือ https://192.168.0.15:10443

2.ก็จะเข้าสู้หน้า Web ของ Endian หน้าแรกเป็นการต้อนรับของโปรแกรมครับ NEXT

3.เลือกภาษาและเวลาถ้าอยู่ประเทศไทยก็ตามภาพเลย NEXT

4.อ่านข้อตกลงให้เข้าใจ เลือกตรง Checkbox ACCEPT License เพื่อยอมรับเงื่อนไข  NEXT

5.เลือกว่าจะนำไฟล์ Backup มาให้หรือไม่ ในทีนี้ไม่ใช้ไฟล์ Backup ครับ ผมตอบ NO NEXT

6.ใส่Password ของ Admin กับ Root เพื่อเข้าในส่วนของ Web กับ SSH NEXT

7.กำหนดค่า WAN (RED Interface) ก็คือ Interface ที่ต่อกับ Router ผมเลือกรับ DHCP ตามภาพแล้วกันครับ NEXT

8.หน้านี้เป็นการกำหนดค่า Interface ORANGE กับ BLUE แต่ตอนนี้มีแค่ RED กับ GREEN ก็ผ่านไปเลยครับ NEXT

9.ตั่งค่า IP ของ Green Interface ผมเปลียนจาก 192.168.0.15/24 เป็น 192.168.100.254 /24 และ Host เป็น efw ส่วน Domain เป็น pond.local NEXT

10.หน้านี้คลิกเลือก Interface ให้กับ RED Interface NEXT

11.ตั้งค่า DNS ผมลือกรับ Automatic จาก Router ครับ NEXT

12.อันนี้เป็นการตั่งค่า E-mail สำหรับส่งรายงานต่างๆของระบบให้กับผู้ดูแลระบบ ผมไม่ใส่นะครับ NEXT

13.ขั้นตอนสุดท้ายก็ Ok to apply the new configuration ได้เลยครับ NEXT

14. รอซักแป็บแล้วก็ไปตั้งค่า IP ทีเครื่อง PC ของเราให้เป็นวงเดียวกับ Firewall เครื่องของเราก็สามมารถใช้งาน Internet ได้แล้วครับ NEXT

ภาพการตั่งค่า IP Address

15.เปิด Browser ขึ้นมา ใน Address Bar พิมพ์ IP ของ Green Interface ถ้าใช้ Google Chrome จะเป็นดั่งในรูปด้านล่างก็เลือก Proceed anyway ครับ

16.ใส่ Username คือ Admin และ Password ก็ที่ตั้งไว้ตอนแรกครับ



หน้าตา Dashboard ของ Endian Firewall Community 2.4 ครับ

แหล่งที่มา
http://agileware.net/content/endian-firewall-hardware-requirements
http://gotoknow.org/blog/sorn-mit/193375
http://www.asterisk.co.th/endian/index.php
http://www.endian.com/en/community/overview/
http://www.thaiadmin.org/board/index.php?topic=112996.0
http://www.endian.com/fileadmin/documentation/efw-admin-guide/en/index.html
http://www.it-guides.com/index.php/training-a-tutorial/network-system/109-what-is-firewall

12/28/2554

จะติดตั้งลินุกส์ตระกูลต่างๆ จาก USB ได้อย่างไร

ขั้นตอนการติดตั้ง

1. ทำการ Format USB Drive ผ่าน Windows โดยไปที่ My Computer และคลิ๊กขวาที่ USB Drive แล้วคลิ๊ก Format เมื่อมี Prompt ขึ้นมาให้เลือก FAT32 อย่าใช้ NTFS เพราะมันไม่ work
2. ดาวน์โหลดและติดตั้ง 7-Zip ซึ่งเป็นโปรแกรม Open Source ที่ฟรี เหมือนกับ Linux โดยให้ดาวน์โหลดเวอร์ชันล่าสุดมาติดตั้ง
3. ดาวน์โหลด Syslinux ซึ่งเป็น bootloader ที่เราจะใช้ในการสร้าง USB bootable โดยให้ดาวน์โหลดเวอร์ชันล่าสุดที่เป็นไฟล์ zip และแตกไฟล์ไว้ที่ Desktop โดยใช้ 7-Zip ซึ่งจะมีการสร้างโฟลเดอร์ขึ้นมาชื่อว่า syslinux-3.82 ให้ทำการเปลี่ยนชื่อโฟลเดอร์ดังกล่าวเป็น syslinux
4. เปิด command prompt แล้วใช้คำสั่ง
    cd Desktop/syslinux/win32
5. รันคำสั่งต่อไปนี้เพื่อติดตั้ง bootable ไปยัง USB Drive
    syslinux -ma f: (f หมายถึงชื่อ Drive ของ USB)
6. ทำการแตก Linux ISO ด้วยการคลิ๊กขวาที่ ISO File แล้วเลือก 7-Zip แล้วเลือก แยกไฟล์ไปที่ ubuntu-9.04....หรืออื่นๆ
7. มาถึงตอนนี้เราก็มี system ที่เป็น syslinux ติดตั้งไว้แล้วที่ USB Drive และมีโฟลเดอร์ซึ่งอาจจะชื่อว่า ubuntu-9.04.... หรือชื่ออื่น บน Windows Desktop
8. จากนั้นนำไฟล์ทั้่งหมดที่แตกจาก ISO ไฟล์ไปไว้ที่ USB Drive ซึ่งตอนนี้ว่างเปล่า (ให้อยู่ในตำแหน่ง root ไม่ต้องมีโฟลเดอร์เดิม)
    หมายเหตุ สำหรับคนที่มีแผ่น Linux ที่เป็น CD อยู่แล้ว สามารถจะ copy ไฟล์พร้อมโฟลเดอร์ทั้งหมดไปไว้ที่ UDB Drive ได้ โดยไ่ม่ต้องเอาจากไฟล์ที่แตกจาก ISO
9. Move (หรือ copy) ทุกสิ่งจากไฟล์เดอร์ isolinux (กรณีของ IPCop และ Endianอยู่ในโฟลเดอร์ boot/isolinux) ไปยังตำแหน่ง root ของ drive ซึ่งในที่นี้หมายถึง move all the files from F:\isolinux\ into F:\
10. เปลี่ยนชื่อไฟล์ isolinux.cfg เป็น syslinux.cfg
11. ดึง USB Drive ออกจากเครื่อง  และ USB Drive ดังกล่าวพร้อมที่จะนำไปใ้ช้ในการติดตั้งได้แล้ว 

 อีกวิธีง่ายๆเช่นกันครับ

UNetbootin - Homepage and Downloads

Packages: Ubuntu Debian Fedora Suse Arch Gentoo More

Introduction

UNetbootin allows you to create bootable Live USB drives for Ubuntu, Fedora, and other Linux distributions without burning a CD. It runs on Windows, Linux, and Mac OS X. You can either let UNetbootin download one of the many distributions supported out-of-the-box for you, or supply your own Linux .iso file if you've already downloaded one or your preferred distribution isn't on the list.

Requirements

  • Microsoft Windows 2000/XP/Vista/7, or Linux, or Mac OS X 10.5+. Note that resulting USB drives are bootable only on PCs (not on Macs).
  • Internet access for downloading a distro to install, or a pre-downloaded ISO file

Features

UNetbootin can create a bootable Live USB drive, or it can make a "frugal install" on your local hard disk if you don't have a USB drive. It loads distributions either by downloading a ISO (CD image) files for you, or by using an ISO file you've already downloaded.

screenshot
The current version has built-in support for automatically downloading and loading the following distributions, though installing other distributions is also supported:

UNetbootin can also be used to load various system utilities, including:
» See List of Custom UNetbootin Versions and Plugins.
» See Using a UNetbootin Plugin.

Installation & Screenshots

  1. If using Windows, run the file, select an ISO file or a distribution to download, select a target drive (USB Drive or Hard Disk), then reboot once done. If your USB drive doesn't show up, reformat it as FAT32.

    screenshot
  2. If using Linux, make the file executable (using either the command chmod +x ./unetbootin-linux, or going to Properties->Permissions and checking "Execute"), then start the application, you will be prompted for your password to grant the application administrative rights, then the main dialog will appear, where you select a distribution and install target (USB Drive or Hard Disk), then reboot when prompted.

    screenshot

    screenshot

  3. After rebooting, if you created a Live USB drive by selecting "USB Drive" as your install target, press the appropriate button (usually F1, F2, F12, ESC, or backspace) while your computer is starting up to get to your BIOS boot menu and select USB drive as the startup target; otherwise if there's no boot selection option, go to the BIOS setup menu and change the startup order to boot USB by default. Note that Live USB drives are bootable only on PCs (not on Macs). Otherwise, if you did a "frugal install" by selecting "Hard Disk" as your install target, select the UNetbootin entry from the Windows Boot Menu as the system boots up.
» See Live USB Creation Guide.

Removal Instructions (Applicable only to Hard Disk / "frugal installs")

If using Windows, UNetbootin should prompt you to remove it the next time you boot into Windows. Alternatively, you can remove it via Add/Remove Programs in the Control Panel.
If using Linux, re-run the UNetbootin executable (with root priveledges), and press OK when prompted to uninstall.
Removal is only required if you used the "Hard Drive" installation mode; to remove the bootloader from a USB drive, back up its contents and reformat it.
Uninstalling UNetbootin simply removes the UNetbootin entry from your boot menu; if you installed an operating system to a partition using UNetbootin, removing UNetbootin will not remove the OS.
To manually remove a Linux installation, you will have to restore the Windows bootloader using "fixmbr" from a recovery CD, and use Parted Magic to delete the Linux partition and expand the Windows partition.

Installing Other Distributions Using UNetbootin

Download and run UNetbootin, then select the "disk image" option and supply it with an ISO (CD image).

screenshot
UNetbootin doesn't use distribution-specific rules for making your live USB drive, so most Linux ISO files should load correctly using this option. However, not all distributions support booting from USB, and some others require extra boot options or other modifications before they can boot from USB drives, so these ISO files will not work as-is. Also, ISO files for non-Linux operating systems have a different boot mechanism, so don't expect them to work either.

What translations are available, and how can I use them?

A number of translations are included in the latest UNetbootin release. See the Translations Page for the status of each.
If a translation corresponding to your system's native language has already been included into UNetbootin, it should automatically load the corresponding translation. Alternatively, you can force the language to use via the lang=es command-line option, where you substitute es with the the 2-letter ISO 639-1 code for your language.
If you'd like to contribute a translation, please use Launchpad Translations. If you are new to Launchpad, you will first have to join the corresponding Ubuntu Translators group for the language you intend to translate. For information on using the Launchpad Translations system, see the translations help page.
» See UNetbootin Translations

FAQs

How does UNetbootin work, and what does it do?
For the Live USB creation mode, UNetbootin downloads and extracts an ISO file to your USB drive, generates an appropriate syslinux config file, and makes your USB drive bootable using syslinux.
For the Hard Disk / "frugal install" mode, UNetbootin uses a Windows or Linux-based installer to install a small modification to the bootloader (bootmgr and bcdedit on Vista, grldr and boot.ini for NT-based systems, grub.exe and config.sys for Win9x, or GRUB on Linux, uses the bootloader to boot the desired distribution's installer or to load the system utility, no CD required. After the distribution has been installed, or once done using the system utility, the modification to the bootloader is then undone.
» See USB Drive and Hard Disk Install Modes.
» See How UNetbootin Works.
Does it have any spyware, viruses, trojans, or other malware?
No; though some anti-virus products (Kaspersky) raise "Trojan.generic" warnings due to the auto-uninstall feature, these are false positives. Just make sure you obtain UNetbootin from the official downloads page on Sourceforge not some shady third-party source. If you're absolutely paranoid, you can check the source code and compile it yourself.

Certified by Softpedia.com Linux Format Hottest Pick
What is it written in, where's the source code, and how can I compile it?
UNetbootin is written in C++, using the Qt4 toolkit. Source code is available from the source zip package, or from the git repository on Sourceforge, or the bzr repository on Launchpad. The Linux version is compiled using g++, while the Windows version is cross-compiled using mingw32. Both use a statically linked version of qt4 (to eliminate external library dependencies). Executables are compressed using UPX to reduce file size.
» See Compiling UNetbootin.
How can I get my distribution supported by UNetbootin?
First, try loading the ISO file via the diskimage option, and see if that works (because UNetbootin doesn't use distribution-specific rules for creating live USB drives, it should be able to load most Linux ISOs as-is). If the resulting live USB doesn't boot correctly, check your distribution's documentation, and verify that it indeed can be booted from a standard (FAT32-formatted) USB drive. Also ensure that it doesn't need any extra boot options or other modifications to boot from a USB drive. If both of these are correct, you may have found a bug, so file a bug report.
If your distribution's ISO file can already be loaded correctly via the diskimage option, and are trying to get it added to the list of distributions which UNetbootin can download for you, file a bug report and provide a link to the latest release.
How can I create specialized, rebranded, distro-specific releases?
UNetbootin can easily be rebranded and adapted to a specific distribution using either a plugin system, or a series of #define statements, as seen in the unetbootin.h file within the source code. If you are attempting to build a distro-specific version and need additional instructions and details, would like to have your patches merged upstream, or would like to have your custom version added to this list, please file a bug report.
» See UNetbootin Command Line Options.
» See Building a UNetbootin Plugin.
» See Using a UNetbootin Plugin.
» See Building a Custom UNetbootin Version.
» See List of Custom UNetbootin Versions and Plugins.
How can I automate the use of UNetbootin from a script?
» See UNetbootin Command Line Options.
Where can I report bugs, request new features, get help, etc?
If you encounter errors with UNetbootin itself, first try using the version available on this website if you obtained it from a different source (your version may be outdated). If the problem still persists, take note of the version of UNetbootin you're using (it's in the filename if you downloaded it from here), the ISO file you're installing or the distribution you're letting UNetbootin download for you, and the OS you're on (like "Windows 7, 64-bit" or "Ubuntu 10.04, 32-bit"), and ask a question or file a bug report, mentioning the above details. You can also see the Ubuntu Forums (the LiveUSB installation thread or Hard disk installation thread depending on your install mode), or the forum on Boot Land, but only Launchpad (bugs and answers), not the forums, are monitored by developers. However, if it's a distribution or hardware-specific issue, file a bug report against the distribution itself.

License and Credits

UNetbootin was created and written by Arpad and Geza Kovacs (tuxcantfly), contact info. Translators are listed on the translations page. UNetbootin is licensed under the GNU General Public License (GPL) Version 2 or above. Site materials, documentation, screenshots, and logos are licensed as Creative Commons Attribution-Share-Alike 3.0.

12/27/2554

ขั้นตอนในการตั้ง Endian Firewall ให้ update

Now follow these 5 steps to keep your Endian Firewall Community up to date:
  1. เปิดการใช้งาน SSH ที่เจ้า Endianที่ port ที่คุณชอบ ส่วนมากจะใช้ 22 หรือ 2222
  2. ใช้โปรแกรม terminal ที่สามารถใช้งาน SSH เพื่อต่อเข้า Endian ส่วนผมใช้ putty ถนัดมือกว่า
  3. ถ้า Endian Firewall ที่ใช้อยู่ เก่ากว่าเวอร์ชั่น 2.2 ให้ run # rpm -ivh http://updates.endian.org/upgrade.rpm
  4. แล้วสั่งให้อับเกรดโดยใช้ efw-upgrade
    # efw-upgrade
    แล้วมันจะถามว่าต้องการแบบไหน
    Please choose the appropriate channel for your environment and hit [ENTER]:
    1) Production (stable releases) แบบนี้เค้าว่าลองกันมาหลายรอบแล้ว ปัญหาน้อยกว่า
    2) Development (bleeding edge) ใครชอบของใหม่ เลือกตัวนี้เลย ไปตายเอาดาบหน้าครับพี่น้อง
    1
    Please enter your username and hit [ENTER]:
    ให้ใส่ user name ที่ไปแจ้งไว้กับเจ้ากระทรวง แล้วยิงเลย