Настройка мониторинга Microsoft SQL в Zabbix

От РоманZabbix

Содержание  скрыть 

1 Описание окружения

2 Настройка мониторинга Microsoft SQL в Zabbix

3 Проверка

4 Если что-то пошло не так

Законспектирую еще один момент — как выполняется настройка мониторинга Microsoft SQL в Zabbix. Я буду использовать вот этот шаблон, который доступен уже «из коробки».

Описание окружения

Версия сервера Zabbix — Zabbix 6.4.8.

Версия MS SQL сервера — SQL Server 2019 CU 23 (15.0.4335.1).

Имя экземпляра SQL — MSSQLSERVER (экземпляр по умолчанию).

Прослушиваемый TCP-порт — 1433.

Настройка мониторинга Microsoft SQL в Zabbix

Выполним настройку:

1. Сначала я создам отдельного SQL пользователя, от имени которого Zabbix будет подключаться к SQL серверу.

2. Также я включу проверку подлинности Windows и SQL в свойствах SQL сервера.

3. После изменения параметров аутентификации потребуется перезапуск сервиса SQL.

4. Назначьте необходимые разрешения для пользователя:

USE msdb;
CREATE USER zabbix FOR LOGIN zabbix;
GRANT SELECT ON OBJECT::msdb.dbo.sysjobs TO zabbix;
GRANT SELECT ON OBJECT::msdb.dbo.sysjobservers TO zabbix;
GRANT SELECT ON OBJECT::msdb.dbo.sysjobactivity TO zabbix;
GRANT EXECUTE ON OBJECT::msdb.dbo.agent_datetime TO zabbix;
USE master;
GRANT VIEW SERVER STATE TO zabbix;
GRANT VIEW ANY DEFINITION to zabbix;

5. Установить ODBC драйвер. На моем сервере Zabbix установлена ОС Ubunt Server 22.04. Соответственно в моем случае команда по установке ODBC драйвера следующая:

if ! [[ "18.04 20.04 22.04 23.04" == *"$(lsb_release -rs)"* ]];
then
    echo "Ubuntu $(lsb_release -rs) is not currently supported.";
    exit;
fi

curl https://packages.microsoft.com/keys/microsoft.asc | sudo tee /etc/apt/trusted.gpg.d/microsoft.asc

curl https://packages.microsoft.com/config/ubuntu/$(lsb_release -rs)/prod.list | sudo tee /etc/apt/sources.list.d/mssql-release.list

sudo apt-get update
sudo ACCEPT_EULA=Y apt-get install -y msodbcsql18
# optional: for bcp and sqlcmd
sudo ACCEPT_EULA=Y apt-get install -y mssql-tools18
echo 'export PATH="$PATH:/opt/mssql-tools18/bin"' >> ~/.bashrc
source ~/.bashrc
# optional: for unixODBC development headers
sudo apt-get install -y unixodbc-dev

6. Также нужно настроить ODBC подключение.

nano /etc/odbc.ini

Я добавлю следующие параметры подключения:

[SPS01]
Driver = ODBC Driver 18 for SQL Server
Server =  10.10.10.79
Port = 1433
TrustServerCertificate = yes

SPS01 — это имя подключения, которое необходимо будет указать в макросах при настройке шаблона. Можете указать любое. Server — IP-адрес сервера SQL. При необходимости скорректируйте порт для подключения.

7. Теперь соберем весь пазл воедино — добавим хост с MS SQL в Zabbix, привяжем шаблон и скорректируем макросы. Сначала я добавлю хост в мониторинг и привяжу шаблон «MSSQL by ODBC».

8. Затем я скорректирую следующие макросы:

  • {$MSSQL.DSN}
  • {$MSSQL.PASSWORD}
  • {$MSSQL.USER}

9. Сохраните внесенные изменения.

Проверка

Проще всего перейти в раздел с отображением последних полученных данных и выполнить проверку.

Пример успешного сбора данных с сервера MS SQL:

Настройка мониторинга Microsoft SQL в Zabbix завершена.

Если что-то пошло не так

Не всегда решение получается настроить так быстро, как хотелось бы. Такое бывает.

Первое, что я бы проверим — это доступность порта SQL сервера со стороны Zabbix сервера.

nc -zv 10.10.10.79 1433

Пример успешного подключения:

Connection to 10.10.10.79 1433 port [tcp/ms-sql-s] succeeded!

Также можно выполнить проверку подключения через ODBC драйвер напрямую:

isql -v SPS01 zabbix Qwerty123

Пример неудачного подключения:

[28000][unixODBC][Microsoft][ODBC Driver 18 for SQL Server][SQL Server]Login failed for user 'zabbix'.
[ISQL]ERROR: Could not SQLConnect

Пример удачного подключения:

+---------------------------------------+
| Connected!                            |
|                                       |
| sql-statement                         |
| help [tablename]                      |
| quit                                  |
|                                       |
+---------------------------------------+
SQL> 

ZabbixШпаргалки

Cisco Catalyst 9800-CL Cloud Wireless Controller Installation Guide

https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/9800-cloud/installation/b-c9800-cl-install-guide/installing-controller-on-hyperv.html#id_119330

Chapter: Installing the Controller in Microsoft Hyper-V Hypervisor

Chapter Contents

Microsoft Hyper-V Support Information

The Catalyst 9800-CL Cloud Wireless Controller installation on Microsoft Hyper-V requires the manual creation of a VM and installation, using the .iso file.

The following Microsoft Hyper-V features are supported:

  • Snapshot
  • Export
  • Hyper-V Replica

For more information about Microsoft Hyper-V, see the Microsoft documentation.

NoteWhile running Microsoft Hyper-V VM, you may get the following traceback log continuously in the console: "PLATFORM_INFRA-5-IOS_INTR_OVER_LIMIT_HIGH_STIME: IOS thread blocked due to SYSTEM LEVEL ISSUE"To avoid this issue, perform the following steps:Configure the controller in serial mode, using the commands given below.Device# configure terminal Device(config)# platform console serial Device(config)# end Device# reloadRun the following command:PS C:\> Set-VMComPort TestVM 1 \\.\pipe\TestPipeUse Putty in administrative mode to access the console.

Installation Requirements for Microsoft Hyper-V

Before installing the controller on a Microsoft Hyper-V VM, the following must be installed on the host:

  • Hyper-V Manager
  • Failover Cluster Manager
  • Virtual Switch
NoteWe recommended that you create the Virtual Switch prior to creating the VM.

The hardware profiles and the recommended resources are listed in the following table:

SettingsUltra-LowSmallMediumLarge
Minimum Number of vCPUs24610
Minimum Memory6 GB8 GB16 GB32 GB
Required Storage16 GB16 GB16 GB16 GB
Minimum Number of vNICs2222
Maximum Access Points1001,0003,0006,000
Maximum Clients Support1,00010,00032,00064,000

Creating the VM

Perform the following to create the VM:

NoteYou can install the controller on Microsoft Hyper-V using Microsoft Hyper-V Manager or Microsoft System Center VMM.

Procedure


Step 1In Hyper-V Manager, click the host.
Step 2Choose New > Virtual Machine.
Step 3Click Specify Name and Location.Enter the name of the VM.(Optional) Click the checkbox to store the VM in a different location.
Step 4Click Next.
Step 5In the Specify Generation window, specify the generation of the machine to be loaded.Note The choice of Generation 1 or Generation 2 depends on your requirements. Generation 2 supports advance features like boot from Small Computer System Interface (SCSI), secure boot, higher hardware limits, Unified Extensible Firmware Interface (UEFI) BIOS, GUID Partition Table (GPT) partitioning, and so on. If Generation 2 is selected, and the Cisco C9800 IOS image version is below 17.6, unselect the Enable Secure Boot checkbox after the deployment, as the controller does not support secure boot. However, if the Cisco C9800 IOS image version is 17.6 or higher, secure boot is supported. Therefore, when Generation 2 is selected, the Enable Secure Boot option is enabled by default.
Step 6In the Assign Memory window, enter the Startup Memory value.The controller requires 8196 MB for the startup memory.
Step 7Click Next.
Step 8In the Configure Networking window, select a network connection to the virtual switch that was previously created.The network adapter selected in this step will become the first interface for the controller when the VM is launched and the router boots. The other vNICs for the VM are created in the next procedure.
Step 9Click Next.
Step 10In the Connect Virtual Hard Disk Screen window, select the following option:Attach a virtual hard disk later.Note The New Virtual Machine Wizard only supports creating a virtual hard disk using the .vhdx format. The controller requires that the hard disk uses the .vhd format. Create the virtual hard disk after the VM has been created.
Step 11Click Next.The Summary screen is displayed.
Step 12Review the VM settings and click Finish.The new VM is created.

Configuring the VM Settings

Perform the following procedure to configure the VM settings before launching the VM:

Before you begin

Before launching the instance, add the network adapters (as required), disk, and load the .iso image in to the disk drive.

We recommended that you create and use separate network interfaces for Management, Wireless Management and High Availability. In case of HA deployments, create 3 network interfaces and attach the VM to the appropriate networks. For non-HA deployments, create 2 network interfaces.

The creation of management, wireless management and HA networks should be done before launching VM. The IP addressing on these interfaces could be either static or DHCP and should be configured as part of the bootstrap configuration.

The order in which the networks are attached to the interface is important as the first network attached is used for Management, second for Wireless Management (unless configured explicitly) and third for the HA.

Procedure


Step 1In Hyper-V Manager, select the host, and right-click the VM created earlier.
Step 2Choose Settings.
Step 3Specify the number of virtual processors, also known as virtual CPUs (vCPUs) for the VM.
Step 4Under IDE Controller 0, select the Hard Drive.Click the Virtual Hard Disk check box and click New to create a new virtual hard disk.The New Virtual Hard Disk Wizard opens. Click Next.On the Choose Disk Format page, click the VHD check box to create the virtual hard disk using the .vhd format. Click Next.On the Choose Disk Type page, click Fixed Size and Next.Specify the Name and Location for the virtual hard disk. Click Next.On the Configure Disk page, click the option to create a new blank virtual hard disk. For the size, specify 16 GB.Click Next to view the Summary of the virtual hard disk settings.Click Finish to create the new virtual hard disk.When the new hard disk has been created, continue configuring the VM settings with the next step.
Step 5Under IDE Controller1, choose DVD Drive.The DVD Drive screen is displayed.For the Media setting, check the Image File check box, and browse the .iso file downloaded from Cisco.com.
Step 6Click Ok.
Step 7Choose Network Adapter to verify that the network connection to the virtual switch is configured.
Step 8Choose Com 1 to configure the serial port.This port provides access to the controller console.
Step 9Choose Hardware > Add Hardware to add the network interfaces (vNICs) to the VM.Choose Network Adapter and click Add.Microsoft Hyper-V adds the network adapter and highlights that hardware with the status Virtual Switch “Not Connected”.Select a virtual switch in the drop-down menu to place the network adapter into it.Repeat the steps for each vNIC. The controller supports only the HV NETVSC vNIC type. The maximum number of vNICs supported is 8.Note The hot-add of vNICs is not supported with Microsoft Hyper-V, so the network interfaces need to be added before launching the VM.After the controller boots, you can verify vNICs and map them to the interfaces using the show platform software vnic-if interface-mapping command.
Step 10Click BIOS to verify the boot sequence for the VM.The VM should be set to boot from the CD.

Launching the VM to Boot the Controller

Perform the following procedure to launch the VM:

Procedure


Step 1Select the virtual switch.
Step 2Select the VM and click Start.The Hyper-V Manager connects to the VM, and starts the launch process. Once the VM is launched, the controller starts the boot process

Configuring Tagged Ports

The tagged port configuration is done on the host OS. By default, the VLAN tagged packets are dropped at the host OS at the vNIC. To allow these packets through to the controller, set the specific vNIC on the controller as tagged.

NoteIf you use Web UI to create network interfaces, you cannot specify interface names and all the interfaces will be named as Network Adapter. So, using these commands, all the network adapters in the controller can be converted to tagged.

These commands are to be entered in a Power Shell.

Procedure


Step 1To see the list of adapters and assignment, use the following script:Get-VMNetworkAdapter -VMName <C9800-name>Note To rename the adapter name, use the following command:Rename-VMNetworkAdapter -VMName <C9800-name> -Name '<C9800-adapter-name>' -NewName 'Eth1'Here, Eth1 is the adapter name.
Step 2To configure Ethernet1 (data port/management) as Trunk, with Native VLAN id as 0, use the following script:Set-VMNetworkAdapterVlan -VMName “C9800” -VMNetworkAdapterName Eth1 -Trunk -AllowedVlanIdList “1-4000” -NativeVlanId 0
Step 3To configure Ethernet0 (serial port) as access or untagged, use the following script:Set-VMNetworkAdapterVlan -VMName “C9800” -VMNetworkAdapterName Eth0 -Untagged
Step 4Enable MAC address spoofing to allow the trunk port to pass the tagged traffic.To enable MAC address spoofing, perform the following:Select the virtual machine and choose Actions > Settings.Expand Network Adapter and choose Advanced Features.Select Enable MAC Address spoofing.

Creating a Bootstrap Day0 Configuration

Perform the following to create a bootstrap Day 0 configuration in the Linux server:

Procedure


Step 1Create iosxe_config.txt or ovf-env.xml file.
Step 2Create a disk image from this file using the following command:mkisofs -l -o ./c9800_config.iso <configuration_filename>
Step 3Mount the c9800_config.iso as an additional disk during creation of the virtual machine and power on the VM.

delete obsolete 1c clients

$obsolete1c = “{4C070411-F5ED-8D13-1D93-F9B0EEC933C6}”, “{D5E3CEC7-E1D4-4E5D-AEE1-7B0AE6BE4EC9}”, “{9289DD3A-4103-4CBA-BA3E-C82D128170A2}”, “{E464A62A-6564-48FE-BFB1-F0B9D024C91A}”, “{08D67508-5873-468A-9CE9-DADE09BB3F52}”, “{BA6F5BE2-46F2-4B88-86EC-EEC81A54DA63}”, “{A28F6B5C-8581-4C16-8714-D6397789DA5E}”, “{68078560-1146-433D-BC90-5AD7D741860E}”, “{AF996617-CB3A-4670-8AE9-C36FFDD3C41F}”, “{A09609F5-CF09-4118-A75D-A51EA994F708}”, “{70485E78-5A21-42FC-B41B-F850AAA22385}”
$regroot=”HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\”

foreach ($ver in $obsolete1c) {
$registryPath = $regroot + $ver

if (Test-Path -Path $registryPath) {
Write-Host “Registry key ‘$registryPath’ exists.”
Start-Process -FilePath “msiexec.exe” -ArgumentList “/x "$ver” /qn” -Wait -NoNewWindow
Start-Sleep -Seconds 30
} else {
Write-Host “Registry key ‘$registryPath’ does not exist.”
}

}

Public IPs

https://gist.githubusercontent.com/iamwildtuna/7772b7c84a11bf6e1385f23096a73a15/raw/f18bfc6391ea14e0ee92a2145669b2fc4887ca43/gistfile2.txt

Meta (Instagram, Facebook)
// Узлы
157.240.253.174, 157.240.253.172, 157.240.253.167, 157.240.253.63, 157.240.253.32
157.240.252.174, 157.240.252.172, 157.240.252.167, 157.240.252.63, 157.240.252.38
57.144.112.34, 57.144.110.1, 157.240.205.174, 87.245.223.97

// Подсети
213.102.128.0/24
204.15.20.0/22
199.201.0.0/16
185.89.0.0/16
185.60.0.0/16
179.60.0.0/16
173.252.0.0/16
164.163.191.64/26
163.114.0.0/16
163.77.128.0/17
163.70.0.0/16
157.240.0.0/16
147.75.0.0/16
142.250.0.0/15
129.134.0.0/16
103.4.0.0/16
102.221.0.0/16
102.132.0.0/16
99.84.0.0/16
87.245.208.0/24
74.119.0.0/16
69.171.0.0/16
69.63.0.0/16
66.220.0.0/16
45.64.0.0/16
31.13.0.0/16
157.240.0.0/24
157.240.251.0/24
157.240.205.0/24
173.194.10.0/24
77.240.43.0/24
57.144.222.0/24
45.130.4.0/24
57.144.96.0/19
57.144.244.0/24
157.240.201.0/24
31.13.72.0/24
57.144.248.0/24

Twitter
// Узлы и подсети
68.232.32.0/20
199.232.0.0/16
146.75.0.0/16
54.240.186.247
54.192.98.249
65.9.48.253
18.165.126.254
108.156.13.243
13.33.247.243
54.230.216.248
199.59.243.223
18.66.123.241
151.101.0.0/16
18.66.95.249
104.244.40.0/21
108.157.229.247
34.64.0.0/10
18.160.187.253
13.225.15.250
99.86.92.242
13.225.33.247
13.249.5.250
143.204.221.250
104.244.42.0/24
152.199.21.141 // images
93.184.220.70 // images
192.229.233.50 // images
104.18.37.127 // images
172.64.150.129 // images
192.229.220.133 // Videos
199.232.188.158 // Videos
172.66.0.0/24

Telegram
149.154.164.0/22
149.154.160.0/20
91.108.8.0/22
91.108.56.0/22
91.108.4.0/22
95.161.64.0/20

static1.smartbear.co
108.157.214.96
108.157.214.92
108.157.214.73
108.157.214.40
18.165.140.117
18.165.140.75
18.165.140.71
18.165.140.36

cloudfront.net
52.85.49.123
52.85.49.113
52.85.49.35
52.85.49.12

## Kino.pub
94.237.43.28 - API
91.215.42.193 - web
95.129.233.136 - web
5.188.189.95 - web
172.67.218.67 - web
104.21.45.187 - web
54.37.134.16
57.128.212.243
5.199.173.130
5.199.173.153
5.199.173.163
185.42.163.120
57.128.212.242 (mail.kino.pub)
46.166.167.67 Vilnius, Lithuania
46.166.167.66 Vilnius, Lithuania
94.237.111.107 (94-237-111-107.nl-ams1.upcloud.host) North Holland, Netherlands
46.166.167.68 Vilnius, Lithuania
94.237.125.200 (atv.nl-ams1.upcloud.host) North Holland, Netherlands
94.237.43.28 (94-237-43-28.nl-ams1.upcloud.host) North Holland, Netherlands
94.237.42.247 (4dns) North Holland, Netherlands
94.237.41.236 (94-237-41-236.nl-ams1.upcloud.host) North Holland, Netherlands
91.215.42.193 Moscow, Russia
38.180.44.76 Harjumaa, Estonia
18.195.13.249 (ec2-18-195-13-249.eu-central-1.compute.amazonaws.com) Hesse, Germany
139.59.96.213 Singapore
194.67.111.89 (194-67-111-89.cloudvps.regruhosting.ru) Moscow, Russia
194.38.21.208 (rkn-fixer.network) Kyiv City, Ukraine
194.40.243.150 (rkn-fixer.network) Kyiv City, Ukraine
5.252.22.90 (nowarvpn.ru) Hesse, Germany
128.199.54.7 (emmet.io)
45.55.82.131 (livestyle.io)
172.67.195.29 (api.service-kp.com)
104.21.36.147 (api.service-kp.com)
172.66.40.229 cdn4t.store
172.66.43.27 cdn4t.store
172.67.222.159 cdn4t.store
104.21.46.23 cdn4t.store
104.26.13.72 cdn4t.store
104.26.12.72 cdn4t.store
172.67.70.167 cdn4t.store



## YouTube CDN (статика)
74.125.205.0/24
142.251.1.0/24
64.233.161.0/24
64.233.163.0/24
108.177.14.0/24
142.250.150.0/24
173.194.221.0/24
142.250.186.0/24
142.250.74.0/24
142.250.181.0/24
172.217.16.0/24
142.250.184.0/24
142.250.185.0/24
216.58.206.0/24
216.58.212.0/24
74.125.160.0/24
74.125.162.0/24
173.194.1.0/24
188.43.61.0/24
74.125.104.0/24
74.125.99.0/24
74.125.153.0/24
74.125.108.0/24
173.194.10.0/24
157.240.252.0/24
157.240.253.0/24
87.245.216.0/24
172.217.133.0/24
173.194.220.0/24
173.194.6.0/24
74.125.163.0/24
74.125.8.0/24
74.125.13.0/24
74.125.11.0/24
64.233.164.0/24
195.95.178.0/24
173.194.19.0/24
173.194.18.0/24
64.233.184.198
74.125.71.198
173.194.217.0/24
172.217.132.0/24
209.85.226.0/24
74.125.3.0/24
209.85.165.0/24
173.194.24.0/24
173.194.140.0/24
172.217.131.0/24
173.194.7.0/24
173.194.53.0/24
173.194.141.0/24
173.194.57.0/24
74.125.155.0/24
173.194.191.0/24
173.194.56.0/24
173.194.143.0/24
173.194.50.0/24

## hub.docker.com
52.44.227.212
54.156.140.159
44.221.37.199

## medium.com
162.159.152.4
162.159.153.4

## upwork.com
104.18.89.237
104.18.90.237

## socradar.io
188.114.99.229
188.114.99.224
188.114.98.229
188.114.98.224
172.67.74.159
104.26.11.38
104.26.10.38

## www.crowdstrike.com
104.16.180.118
104.16.181.118

# YouTube video cdn
173.194.181.0/24
173.194.176.0/24
74.125.154.0/24
89.113.122.0/24
188.234.138.0/24
188.234.140.0/24
173.194.179.0/24
74.125.162.0/24
173.194.188.0/24
74.125.173.0/24
74.125.153.0/24
74.125.110.0/24
173.194.177.0/24
173.194.180.0/24
173.194.10.0/24
173.194.151.0/24
173.194.178.0/24
173.194.182.0/24
173.194.163.0/24
173.194.2.0/24
173.194.187.0/24
64.233.162.0/24
74.125.131.0/24
74.125.111.0/24
74.125.100.0/24
173.194.73.0/24
108.177.15.0/24
74.125.172.0/24
74.125.156.0/24
173.194.164.0/24
173.194.189.0/24
173.194.160.0/24

// YouTube+
216.58.192.0/19
64.233.160.0/19

# Google Play (могут пересекаться с youtube cdn)
173.194.222.0/24
64.233.165.0/24
209.85.233.0/24

# RuTracker
172.67.182.196
104.21.32.39
104.21.50.150
172.67.163.237

# LostFilmTV
188.114.97.3
172.67.161.94
104.21.9.225
188.114.96.1
188.114.97.1

# Bosch Home Connect
3.120.63.228
18.198.108.65
3.125.230.2
18.185.28.63
18.192.139.211
18.194.52.28
20.33.66.163

# Discord
162.159.130.234
162.159.134.234
162.159.133.234
162.159.135.234
162.159.136.234
162.159.137.232
162.159.135.232
162.159.136.232
162.159.138.232
162.159.128.233
198.244.231.90
162.159.129.233
162.159.130.233
162.159.133.233
162.159.134.233
162.159.135.233
162.159.138.234
162.159.137.234
162.159.134.232
162.159.130.235
162.159.129.235
162.159.129.232
162.159.128.235
162.159.134.232
162.159.130.232
162.159.133.232
162.159.128.232
34.126.226.51

#Discord Голосовые сервера
e/24
64.233.165.94
35.207.188.57
35.207.81.249
35.207.171.222
195.62.89.0/24
66.22.192.0/18
66.22.196.0/24
66.22.197.0/24
66.22.198.0/24
66.22.199.0/24
66.22.216.0/24
66.22.217.0/24
66.22.237.0/24
66.22.238.0/24
66.22.241.0/24
66.22.242.0/24
66.22.244.0/24
64.71.8.96/29
34.0.240.0/24
34.0.241.0/24
34.0.242.0/24
34.0.243.0/24
34.0.244.0/24
34.0.245.0/24
34.0.246.0/24
34.0.247.0/24
34.0.248.0/24
34.0.249.0/24
34.0.250.0/24
34.0.251.0/24
12.129.184.160/29
138.128.136.0/21
162.158.0.0/15
172.64.0.0/13
34.0.0.0/15
34.2.0.0/15
35.192.0.0/12
35.208.0.0/12
5.200.14.128/25
66.22.192.0/18

// ChatGPT
162.159.140.0/24
172.64.150.0/24
104.18.37.0/24
104.18.35.28
104.18.41.241
172.64.152.228
172.64.146.15
188.114.98.0/24
188.114.99.0/24
172.64.155.209
104.18.39.85
172.64.148.171
172.64.155.214
104.18.32.0/24
8.6.112.0/24
8.47.69.0/24

// GitHub Copilot
140.82.121.6
140.82.121.5
140.82.114.22
140.82.114.21
140.82.113.22
140.82.113.21
140.82.112.22
140.82.112.21
20.250.119.64
20.199.39.224
4.225.11.192

// SmartTube
172.105.245.168

// Reddit
151.101.193.140
151.101.129.140
151.101.65.140
151.101.9.140
151.101.1.140
146.75.121.140

// Netflix (Рекомендую направлять через СНГ, там цеыны ниже. Например Казахстан)
54.155.178.5
54.74.73.31
3.251.50.149
54.246.79.9
52.214.181.141
54.170.196.176
54.155.246.232
18.200.8.190
54.73.148.110

// LinkedIn
104.44.0.0/16
108.174.0.0/16
144.2.0.0/16
185.63.140.0/22
13.107.0.0/16
40.74.0.0/15
40.76.0.0/14
52.183.0.0/16
52.224.0.0/16
104.18.0.0/16
142.250.0.0/16
172.217.0.0/16
172.64.0.0/16
74.125.0.0/16
45.42.64.0/24
45.42.66.0/24
103.20.92.0/24

# NoNaMe Club (nnmclub.to)
104.21.17.86
172.67.175.99
104.21.64.1
104.21.16.1
104.21.48.1
104.21.96.1
104.21.80.1
104.21.32.1
104.21.112.1

cub.red (Lampa)
172.67.207.253
117.55.203.183
104.21.69.116
5.61.53.100

NotePad++
92.113.23.0/24
92.113.16.0/24
91.108.123.0/24
77.37.55.0/24
91.108.98.0/24

# Все адреса в виде строк для файла загрузки
route ADD 173.194.187.0 MASK 255.255.255.0 0.0.0.0
route ADD 213.102.128.0 MASK 255.255.255.0 0.0.0.0
route ADD 204.15.20.0 MASK 255.255.252.0 0.0.0.0
route ADD 199.201.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 185.89.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 185.60.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 179.60.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 173.252.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 164.163.191.64 MASK 255.255.255.192 0.0.0.0
route ADD 163.114.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 163.77.128.0 MASK 255.255.128.0 0.0.0.0
route ADD 163.70.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 157.240.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 147.75.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 142.250.0.0 MASK 255.254.0.0 0.0.0.0
route ADD 129.134.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 103.4.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 102.221.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 102.132.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 99.84.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 87.245.208.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.119.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 69.171.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 69.63.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 66.220.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 45.64.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 31.13.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 68.232.32.0 MASK 255.255.240.0 0.0.0.0
route ADD 199.232.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 146.75.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 151.101.0.0 MASK 255.255.0.0 0.0.0.0
route ADD 104.244.40.0 MASK 255.255.248.0 0.0.0.0
route ADD 34.64.0.0 MASK 255.192.0.0 0.0.0.0
route ADD 173.194.181.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.176.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.154.0 MASK 255.255.255.0 0.0.0.0
route ADD 89.113.122.0 MASK 255.255.255.0 0.0.0.0
route ADD 188.234.138.0 MASK 255.255.255.0 0.0.0.0
route ADD 188.234.140.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.179.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.162.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.188.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.173.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.153.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.110.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.177.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.180.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.10.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.151.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.178.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.182.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.163.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.2.0 MASK 255.255.255.0 0.0.0.0
route ADD 157.240.253.174 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.253.172 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.253.167 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.253.63 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.253.32 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.252.174 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.252.172 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.252.167 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.252.63 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.252.38 MASK 255.255.255.255 0.0.0.0
route ADD 54.240.186.247 MASK 255.255.255.255 0.0.0.0
route ADD 54.192.98.249 MASK 255.255.255.255 0.0.0.0
route ADD 65.9.48.253 MASK 255.255.255.255 0.0.0.0
route ADD 18.165.126.254 MASK 255.255.255.255 0.0.0.0
route ADD 108.156.13.243 MASK 255.255.255.255 0.0.0.0
route ADD 13.33.247.243 MASK 255.255.255.255 0.0.0.0
route ADD 54.230.216.248 MASK 255.255.255.255 0.0.0.0
route ADD 199.59.243.223 MASK 255.255.255.255 0.0.0.0
route ADD 18.66.123.241 MASK 255.255.255.255 0.0.0.0
route ADD 18.66.95.249 MASK 255.255.255.255 0.0.0.0
route ADD 18.160.187.253 MASK 255.255.255.255 0.0.0.0
route ADD 13.225.15.250 MASK 255.255.255.255 0.0.0.0
route ADD 99.86.92.242 MASK 255.255.255.255 0.0.0.0
route ADD 13.225.33.247 MASK 255.255.255.255 0.0.0.0
route ADD 13.249.5.250 MASK 255.255.255.255 0.0.0.0
route ADD 108.157.229.247 MASK 255.255.255.255 0.0.0.0
route ADD 143.204.221.250 MASK 255.255.255.255 0.0.0.0
route ADD 152.199.21.141 MASK 255.255.255.255 0.0.0.0
route ADD 93.184.220.70 MASK 255.255.255.255 0.0.0.0
route ADD 192.229.233.50 MASK 255.255.255.255 0.0.0.0
route ADD 192.229.220.133 MASK 255.255.255.255 0.0.0.0
route ADD 108.157.214.96 MASK 255.255.255.255 0.0.0.0
route ADD 108.157.214.92 MASK 255.255.255.255 0.0.0.0
route ADD 108.157.214.73 MASK 255.255.255.255 0.0.0.0
route ADD 108.157.214.40 MASK 255.255.255.255 0.0.0.0
route ADD 18.165.140.117 MASK 255.255.255.255 0.0.0.0
route ADD 18.165.140.75 MASK 255.255.255.255 0.0.0.0
route ADD 18.165.140.71 MASK 255.255.255.255 0.0.0.0
route ADD 18.165.140.36 MASK 255.255.255.255 0.0.0.0
route ADD 52.85.49.123 MASK 255.255.255.255 0.0.0.0
route ADD 52.85.49.113 MASK 255.255.255.255 0.0.0.0
route ADD 52.85.49.35 MASK 255.255.255.255 0.0.0.0
route ADD 52.85.49.12 MASK 255.255.255.255 0.0.0.0
route ADD 52.44.227.212 MASK 255.255.255.255 0.0.0.0
route ADD 54.156.140.159 MASK 255.255.255.255 0.0.0.0
route ADD 44.221.37.199 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.152.4 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.153.4 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.99.229 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.99.224 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.98.229 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.98.224 MASK 255.255.255.255 0.0.0.0
route ADD 172.67.74.159 MASK 255.255.255.255 0.0.0.0
route ADD 104.26.11.38 MASK 255.255.255.255 0.0.0.0
route ADD 104.26.10.38 MASK 255.255.255.255 0.0.0.0
route ADD 173.194.222.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.221.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.233.165.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.233.162.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.250.186.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.250.74.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.250.181.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.217.16.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.250.184.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.250.185.0 MASK 255.255.255.0 0.0.0.0
route ADD 216.58.206.0 MASK 255.255.255.0 0.0.0.0
route ADD 216.58.212.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.205.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.67.182.196 MASK 255.255.255.255 0.0.0.0
route ADD 104.21.32.39 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.97.3 MASK 255.255.255.255 0.0.0.0
route ADD 172.67.161.94 MASK 255.255.255.255 0.0.0.0
route ADD 104.21.9.225 MASK 255.255.255.255 0.0.0.0
route ADD 3.120.63.228 MASK 255.255.255.255 0.0.0.0
route ADD 18.198.108.65 MASK 255.255.255.255 0.0.0.0
route ADD 3.125.230.2 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.0.0 MASK 255.255.255.0 0.0.0.0
route ADD 157.240.251.0 MASK 255.255.255.0 0.0.0.0
route ADD 157.240.205.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.10.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.160.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.162.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.1.0 MASK 255.255.255.0 0.0.0.0
route ADD 188.43.61.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.104.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.99.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.153.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.108.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.10.0 MASK 255.255.255.0 0.0.0.0
route ADD 157.240.252.0 MASK 255.255.255.0 0.0.0.0
route ADD 157.240.253.0 MASK 255.255.255.0 0.0.0.0
route ADD 87.245.216.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.217.133.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.220.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.131.0 MASK 255.255.255.0 0.0.0.0
route ADD 209.85.233.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.6.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.163.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.8.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.111.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.13.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.100.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.11.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.233.161.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.233.164.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.73.0 MASK 255.255.255.0 0.0.0.0
route ADD 108.177.14.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.233.163.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.251.1.0 MASK 255.255.255.0 0.0.0.0
route ADD 142.250.150.0 MASK 255.255.255.0 0.0.0.0
route ADD 162.159.130.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.134.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.133.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.135.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.136.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.137.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.135.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.136.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.138.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.128.233 MASK 255.255.255.255 0.0.0.0
route ADD 198.244.231.90 MASK 255.255.255.255 0.0.0.0
route ADD 5.188.189.95 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.129.233 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.130.233 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.133.233 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.134.233 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.135.233 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.138.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.137.234 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.134.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.130.235 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.129.235 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.129.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.128.235 MASK 255.255.255.255 0.0.0.0
route ADD 64.233.165.94 MASK 255.255.255.255 0.0.0.0
route ADD 35.207.188.57 MASK 255.255.255.255 0.0.0.0
route ADD 35.207.81.249 MASK 255.255.255.255 0.0.0.0
route ADD 35.207.171.222 MASK 255.255.255.255 0.0.0.0
route ADD 66.22.243.0 MASK 255.255.255.0 0.0.0.0
route ADD 54.37.134.16 MASK 255.255.255.255 0.0.0.0
route ADD 57.128.212.243 MASK 255.255.255.255 0.0.0.0
route ADD 5.199.173.130 MASK 255.255.255.255 0.0.0.0
route ADD 5.199.173.153 MASK 255.255.255.255 0.0.0.0
route ADD 5.199.173.163 MASK 255.255.255.255 0.0.0.0
route ADD 185.42.163.120 MASK 255.255.255.255 0.0.0.0
route ADD 57.128.212.242 MASK 255.255.255.255 0.0.0.0
route ADD 46.166.167.67 MASK 255.255.255.255 0.0.0.0
route ADD 46.166.167.66 MASK 255.255.255.255 0.0.0.0
route ADD 94.237.111.107 MASK 255.255.255.255 0.0.0.0
route ADD 46.166.167.68 MASK 255.255.255.255 0.0.0.0
route ADD 94.237.125.200 MASK 255.255.255.255 0.0.0.0
route ADD 94.237.43.28 MASK 255.255.255.255 0.0.0.0
route ADD 94.237.42.247 MASK 255.255.255.255 0.0.0.0
route ADD 94.237.41.236 MASK 255.255.255.255 0.0.0.0
route ADD 91.215.42.193 MASK 255.255.255.255 0.0.0.0
route ADD 38.180.44.76 MASK 255.255.255.255 0.0.0.0
route ADD 18.195.13.249 MASK 255.255.255.255 0.0.0.0
route ADD 139.59.96.213 MASK 255.255.255.255 0.0.0.0
route ADD 194.67.111.89 MASK 255.255.255.255 0.0.0.0
route ADD 194.38.21.208 MASK 255.255.255.255 0.0.0.0
route ADD 194.40.243.150 MASK 255.255.255.255 0.0.0.0
route ADD 5.252.22.90 MASK 255.255.255.255 0.0.0.0
route ADD 128.199.54.7 MASK 255.255.255.255 0.0.0.0
route ADD 45.55.82.131 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.134.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.130.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.133.232 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.128.232 MASK 255.255.255.255 0.0.0.0
route ADD 195.95.178.0 MASK 255.255.255.0 0.0.0.0
route ADD 104.18.37.127 MASK 255.255.255.255 0.0.0.0
route ADD 172.64.150.129 MASK 255.255.255.255 0.0.0.0
route ADD 173.194.19.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.233.184.198 MASK 255.255.255.255 0.0.0.0
route ADD 173.194.18.0 MASK 255.255.255.0 0.0.0.0
route ADD 77.240.43.0 MASK 255.255.255.0 0.0.0.0
route ADD 57.144.112.34 MASK 255.255.255.255 0.0.0.0
route ADD 57.144.110.1 MASK 255.255.255.255 0.0.0.0
route ADD 157.240.205.174 MASK 255.255.255.255 0.0.0.0
route ADD 216.58.192.0 MASK 255.255.224.0 0.0.0.0
route ADD 64.233.160.0 MASK 255.255.224.0 0.0.0.0
route ADD 172.105.245.168 MASK 255.255.255.255 0.0.0.0
route ADD 162.159.140.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.64.150.0 MASK 255.255.255.0 0.0.0.0
route ADD 104.18.37.0 MASK 255.255.255.0 0.0.0.0
route ADD 104.18.35.28 MASK 255.255.255.255 0.0.0.0
route ADD 172.64.152.228 MASK 255.255.255.255 0.0.0.0
route ADD 104.18.41.241 MASK 255.255.255.255 0.0.0.0
route ADD 172.64.146.15 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.98.0 MASK 255.255.255.0 0.0.0.0
route ADD 188.114.99.0 MASK 255.255.255.0 0.0.0.0
route ADD 95.129.233.136 MASK 255.255.255.255 0.0.0.0
route ADD 173.194.217.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.71.198 MASK 255.255.255.255 0.0.0.0
route ADD 199.232.188.158 MASK 255.255.255.255 0.0.0.0
route ADD 104.21.50.150 MASK 255.255.255.255 0.0.0.0
route ADD 172.67.163.237 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.96.1 MASK 255.255.255.255 0.0.0.0
route ADD 188.114.97.1 MASK 255.255.255.255 0.0.0.0
route ADD 104.244.42.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.67.218.67 MASK 255.255.255.255 0.0.0.0
route ADD 104.21.45.187 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.121.6 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.121.5 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.114.22 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.114.21 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.113.22 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.113.21 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.112.22 MASK 255.255.255.255 0.0.0.0
route ADD 140.82.112.21 MASK 255.255.255.255 0.0.0.0
route ADD 20.250.119.64 MASK 255.255.255.255 0.0.0.0
route ADD 20.199.39.224 MASK 255.255.255.255 0.0.0.0
route ADD 4.225.11.192 MASK 255.255.255.255 0.0.0.0
route ADD 104.16.180.118 MASK 255.255.255.255 0.0.0.0
route ADD 104.16.181.118 MASK 255.255.255.255 0.0.0.0
route ADD 172.64.155.209 MASK 255.255.255.255 0.0.0.0
route ADD 104.18.89.237 MASK 255.255.255.255 0.0.0.0
route ADD 104.18.90.237 MASK 255.255.255.255 0.0.0.0
route ADD 18.185.28.63 MASK 255.255.255.255 0.0.0.0
route ADD 18.192.139.211 MASK 255.255.255.255 0.0.0.0
route ADD 18.194.52.28 MASK 255.255.255.255 0.0.0.0
route ADD 20.33.66.163 MASK 255.255.255.255 0.0.0.0
route ADD 34.126.226.51 MASK 255.255.255.255 0.0.0.0
route ADD 104.18.39.85 MASK 255.255.255.255 0.0.0.0
route ADD 108.177.15.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.64.148.171 MASK 255.255.255.255 0.0.0.0
route ADD 172.64.155.214 MASK 255.255.255.255 0.0.0.0
route ADD 104.18.32.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.217.132.0 MASK 255.255.255.0 0.0.0.0
route ADD 209.85.226.0 MASK 255.255.255.0 0.0.0.0
route ADD 195.62.89.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.192.0 MASK 255.255.192.0 0.0.0.0
route ADD 66.22.196.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.197.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.198.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.199.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.216.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.217.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.237.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.238.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.241.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.242.0 MASK 255.255.255.0 0.0.0.0
route ADD 66.22.244.0 MASK 255.255.255.0 0.0.0.0
route ADD 64.71.8.96 MASK 255.255.255.248 0.0.0.0
route ADD 34.0.240.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.241.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.242.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.243.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.244.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.245.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.246.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.247.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.248.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.249.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.250.0 MASK 255.255.255.0 0.0.0.0
route ADD 34.0.251.0 MASK 255.255.255.0 0.0.0.0
route ADD 12.129.184.160 MASK 255.255.255.248 0.0.0.0
route ADD 195.62.89.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.67.195.29 MASK 255.255.255.255 0.0.0.0
route ADD 104.21.36.147 MASK 255.255.255.255 0.0.0.0
route ADD 151.101.193.140 MASK 255.255.255.255 0.0.0.0
route ADD 151.101.129.140 MASK 255.255.255.255 0.0.0.0
route ADD 151.101.65.140 MASK 255.255.255.255 0.0.0.0
route ADD 151.101.9.140 MASK 255.255.255.255 0.0.0.0
route ADD 151.101.1.140 MASK 255.255.255.255 0.0.0.0
route ADD 146.75.121.140 MASK 255.255.255.255 0.0.0.0
route ADD 54.155.178.5 MASK 255.255.255.255 0.0.0.0
route ADD 54.74.73.31 MASK 255.255.255.255 0.0.0.0
route ADD 3.251.50.149 MASK 255.255.255.255 0.0.0.0
route ADD 54.246.79.9 MASK 255.255.255.255 0.0.0.0
route ADD 52.214.181.141 MASK 255.255.255.255 0.0.0.0
route ADD 54.170.196.176 MASK 255.255.255.255 0.0.0.0
route ADD 54.155.246.232 MASK 255.255.255.255 0.0.0.0
route ADD 18.200.8.190 MASK 255.255.255.255 0.0.0.0
route ADD 54.73.148.110 MASK 255.255.255.255 0.0.0.0
route ADD 74.125.172.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.156.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.3.0 MASK 255.255.255.0 0.0.0.0
route ADD 209.85.165.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.24.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.140.0 MASK 255.255.255.0 0.0.0.0
route ADD 172.217.131.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.7.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.53.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.141.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.57.0 MASK 255.255.255.0 0.0.0.0
route ADD 74.125.155.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.191.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.56.0 MASK 255.255.255.0 0.0.0.0
route ADD 173.194.143.0 MASK 255.255.255.0 0.0.0.0
route ADD 57.144.222.0 MASK 255.255.255.0 0.0.0.0
route ADD 45.130.4.0 MASK 255.255.255.0 0.0.0.0
route ADD 87.245.223.97 MASK 255.255.255.255 0.0.0.0
route ADD 57.144.96.0 MASK 255.255.254.0 0.0.0.0
ROUTE ADD 104.44.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 108.174.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 144.2.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 185.63.140.0 MASK 255.255.252.0 0.0.0.0
ROUTE ADD 13.107.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 40.74.0.0 MASK 255.254.0.0 0.0.0.0
ROUTE ADD 40.76.0.0 MASK 255.252.0.0 0.0.0.0
ROUTE ADD 52.183.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 52.224.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 104.18.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 142.250.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 172.217.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 172.64.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 74.125.0.0 MASK 255.255.0.0 0.0.0.0
ROUTE ADD 45.42.64.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 45.42.66.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 103.20.92.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 8.6.112.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 8.47.69.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 172.66.0.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 138.128.136.0 MASK 255.255.248.0 0.0.0.0
ROUTE ADD 162.158.0.0 MASK 255.254.0.0 0.0.0.0
ROUTE ADD 172.64.0.0 MASK 255.248.0.0 0.0.0.0
ROUTE ADD 34.0.0.0 MASK 255.254.0.0 0.0.0.0
ROUTE ADD 34.2.0.0 MASK 255.254.0.0 0.0.0.0
ROUTE ADD 35.192.0.0 MASK 255.240.0.0 0.0.0.0
ROUTE ADD 35.208.0.0 MASK 255.240.0.0 0.0.0.0
ROUTE ADD 5.200.14.128 MASK 255.255.255.128 0.0.0.0
ROUTE ADD 66.22.192.0 MASK 255.255.192.0 0.0.0.0
ROUTE ADD 173.194.50.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 104.21.17.86 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 172.67.175.99 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.64.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.16.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.48.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.96.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.80.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.32.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.112.1 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 173.194.164.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 173.194.189.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 172.67.207.253 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 117.55.203.183 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.69.116 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 5.61.53.100 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 57.144.244.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 172.66.40.229 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 172.66.43.27 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 172.67.222.159 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.21.46.23 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.26.13.72 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 104.26.12.72 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 172.67.70.167 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 92.113.23.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 92.113.16.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 91.108.123.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 77.37.55.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 91.108.98.0 MASK 255.255.255.0 0.0.0.0
ROUTE ADD 173.194.160.0 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 157.240.201.0 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 31.13.72.0 MASK 255.255.255.255 0.0.0.0
ROUTE ADD 57.144.248.0 MASK 255.255.255.255 0.0.0.0

Update opnsense via proxy

vi /usr/local/opnsense/service/conf/configd.conf

HTTP_PROXY=http://our-proxy.com:8080
HTTPS_PROXY=http://our-proxy.com:8080
http_proxy=http://our-proxy.com:8080
https_proxy=http://our-proxy.com:8080
FTP_PROXY=http://our-proxy.com:8080
ftp_proxy=http://our-proxy.com:8080

WinITPro.ru  /  Active Directory  /  Windows Server 2016  /  Ошибка репликации Active Directory: Target Principal Name is Incorrect


Ошибка репликации Active Directory: Target Principal Name is Incorrect

date27.06.2022

user itpro

directory Active DirectoryWindows Server 2016

comments Комментариев пока нет

При попытке ручной репликации данных между контроллерами домена Active Directory в остатке Active Directory Sites and Services (dssite.msc) появилась ошибка:

The following error occurred during the attempt to synchronize naming context from Domain Controller X to Domain Controller Y.
The target principal name is incorrect.
This operation will not continue.
контроллер домена ошибка The target principal name is incorrect

При проверке репликации с помощью repadmin, у одного из DC появляется ошибка:

(2148074274) The target principal name is incorrect.
repadmin (2148074274) The target principal name is incorrect

В журнале событий DC есть такие ошибки:

Source: Security-Kerberos
Event ID: 4

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server DC2. The target name used was cifs/DC2.winitpro.ru. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (winitpro.ru) is different from the client domain (winiptro.ru), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

Event ID 3210:

Failed to authenticate with \\DC, a Windows NT domain controller for domain WINITPRO.

Event ID 5722:

The session setup from the computer 1 failed to authenticate. The name of the account referenced in the security database is 2. The following error occurred:

В первую очередь проверьте:

  1. Доступность проблемного контроллера домена с помощью простого ICMP ping
  2. Проверьте, что на нем доступен порт TCP 445 и опубликованы сетевые папки SysVol и NetLogon;

Если все ОК, значит проблема в том, между контроллерами домена нарушен безопасный канал передачи данных. Проверьте его с помощью PowerShell команды:

Test-ComputerSecureChannel -Verbose

Служба KDC на целевом контроллере домена не может расшифровать тикет Kerberos из-за того, что в ней хранится старый пароль этого контроллера домена.

Чтобы исправить проблему, нужно сбросить этот пароль. Сначала нужно найти текущий контроллер домена с FSMO ролью PDC.

netdom query fsmo |find "PDC"

В нашем примере PDC находится на MSK-DC02. Мы будем исопользовать это имя в команде netdom resetpwd далее.

netdom найти контроллер домена fsmo

Остановите службу Kerberos Key Distribution Center (KDC) на контроллере домена, на котором появляется ошибка “The target principal name is incorrect” и измените тип запуска на Disabled. Можно изменить настройки службы из консоли services.msc или с помощью PowerShell:

Get-Service kdc -ComputerName msk-dc03 | Set-Service –startuptype disabled –passthru

остановить службу KDC

Перезагрузите этот контроллер домена.

Теперь нужно сбросить безопасный канал связи с контроллером домена с ролью PDC:

netdom resetpwd /server:msk-dc02 /userd:winitpro\administrator /passwordd:*

Укажите пароль администратора домена.

Данная команда восстановит доверительные отношения контроллера домена с PDC.

Перезагрузите проблемный DC и запустите службу KDC. Попробуйте запустить репликацию и проверить ошибки.

repadmin /syncall
repadmin /replsum
repadmin /showrepl

Если репликация успешно выполнена, в журнале Directory Service Event Viewerа должно появится событие Event ID 1394:

All Problems preventing updates to the Active Directory Domain Services database have been cleared. New Updates to the Active Directory Domain Services database are succeeding. The Net Logon service has restarted
Event ID 1394 успешная репликация AD

Проверьте состояние вашего домена и контроллеров домена Active Directory согласно этого гайда.

Veeam B&R Access Denied

To disable UAC remote restrictions, follow these steps:

Click Start, click Run, type regedit, and then press ENTER.

Locate and then click the following registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

If the LocalAccountTokenFilterPolicy registry entry doesn't exist, follow these steps:
    On the Edit menu, point to New, and then select DWORD Value.
    Type LocalAccountTokenFilterPolicy, and then press ENTER.

Right-click LocalAccountTokenFilterPolicy, and then select Modify.

In the Value data box, type 1, and then select OK.

Exit Registry Editor.

Force logoff terminal users

Using PowerShell

To log off all user sessions, run the following Powershell cmdlets on the Connection Broker:

PowerShellCopy

$sessions = Get-RDUserSession

foreach($session in $sessions)
{
    Invoke-RDUserLogoff -HostServer $session.HostServer -UnifiedSessionID $session.UnifiedSessionId -Force
}