{"id":440,"date":"2019-11-01T13:25:38","date_gmt":"2019-11-01T05:25:38","guid":{"rendered":"https:\/\/rol801.com\/wordpress\/?p=440"},"modified":"2019-11-23T13:33:58","modified_gmt":"2019-11-23T05:33:58","slug":"freenas-rsync-over-ssh-to-synology-setup","status":"publish","type":"post","link":"https:\/\/rol801.com\/wordpress\/?p=440","title":{"rendered":"FreeNAS (Rsync over SSH) to Synology Setup"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"452\" data-permalink=\"https:\/\/rol801.com\/wordpress\/?attachment_id=452\" data-orig-file=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/FreeNAS.jpg?fit=224%2C224&amp;ssl=1\" data-orig-size=\"224,224\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FreeNAS\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/FreeNAS.jpg?fit=224%2C224&amp;ssl=1\" class=\"alignleft  wp-image-452\" src=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/FreeNAS.jpg?resize=102%2C102&#038;ssl=1\" alt=\"\" width=\"102\" height=\"102\" srcset=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/FreeNAS.jpg?w=224&amp;ssl=1 224w, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/FreeNAS.jpg?resize=150%2C150&amp;ssl=1 150w\" sizes=\"auto, (max-width: 102px) 85vw, 102px\" \/><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"454\" data-permalink=\"https:\/\/rol801.com\/wordpress\/?attachment_id=454\" data-orig-file=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/SSH.png?fit=225%2C225&amp;ssl=1\" data-orig-size=\"225,225\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"SSH\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/SSH.png?fit=225%2C225&amp;ssl=1\" class=\"alignleft  wp-image-454\" src=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/SSH.png?resize=94%2C94&#038;ssl=1\" alt=\"\" width=\"94\" height=\"94\" srcset=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/SSH.png?w=225&amp;ssl=1 225w, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/SSH.png?resize=150%2C150&amp;ssl=1 150w\" sizes=\"auto, (max-width: 94px) 85vw, 94px\" \/> \u00a0<img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"453\" data-permalink=\"https:\/\/rol801.com\/wordpress\/?attachment_id=453\" data-orig-file=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/Synology.png?fit=445%2C113&amp;ssl=1\" data-orig-size=\"445,113\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Synology\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/Synology.png?fit=445%2C113&amp;ssl=1\" class=\"alignleft  wp-image-453\" src=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/Synology.png?resize=287%2C73&#038;ssl=1\" alt=\"\" width=\"287\" height=\"73\" srcset=\"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/Synology.png?w=445&amp;ssl=1 445w, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2019\/11\/Synology.png?resize=300%2C76&amp;ssl=1 300w\" sizes=\"auto, (max-width: 287px) 85vw, 287px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Data \u5099\u4efd\u597d\u7dca\u8981\uff01<\/p>\n<p>\u81ea\u5f9eOffice \u7528FreeNAS keep Source \u4ee5\u9ece\uff0c\u90fd\u4fc2\u7528USB HDD \u7d93PC \u884cSyncBackPro \u505aSchedule Backup (\u96d6\u7136\u91cd\u6709\u7b2c\u4e09\u5957Backup\u53bb\u53e6\u4e00\u96bbSynology\uff09<\/p>\n<p>Reference site \u597d\u6709\u7528\uff0c\u4f46\u6709\u4e00\u6a23\u4fc2\u5165\u9762\u7121\u63d0\uff0c\u4f46\u81ea\u5df1\u53c8\u958b\u982d\u7121\u641e\u6e05\u695a\u5605\u3002\u5c31\u4fc2FreeNAS \u5605 \u300ersync\u300f service-account \u5605Primary Group \u8981\u4fc2 Wheel\uff0cPrimary Group \u4fc2\u81ea\u5df1\u540d\u6216\u5176\u4ed6\u3002Rsync task\u90fd\u5514\u6703\u884c\u5f97\u8d77\u3002<\/p>\n<p>SSH Keygen \u5514\u4fc2\u592a\u96e3\uff0c\u6700\u7dca\u8981\u641e\u6e05\u695a\u908a\u90e8\u6a5f\u53bb\u908a\u90e8\u6a5f(Source&gt;Target)<\/p>\n<p>Genkey \u7cfb\u4fc2Source\u6a5fgen\uff0c\u4e4b\u5f8c\u6284id_rsa.pub\u53bbTargetMachine ~\/.ssh\u5165\u9762\uff0c\u540c\u57cb &#8220;authorized_key&#8221; \u5169\u500bfile\u3002Permission 711<\/p>\n<p>\u4fc2Synology\u5165\u9762enable Rsync\u5514\u592a\u8907\u96dc\uff0c\u4f46\u4fc2\u552f\u4e00\u4ee4\u6211\u518d\u4f0f\u5605\u4f4d\u4fc2, Synology Rsync Service-Account\u9700\u8981\u4fc2Admin Group Member\u3002\u5514\u4fc2\u5572\u8a71FreeNAS\u7528SSHconnect\u53bbSynology\u7cfb\u6703\u7167\u554fPassword\u3002<\/p>\n<p>\u5982\u7121\u7279\u5225\u554f\u984c\u5c31\u53ef\u4ee5Trial Run\u3002\u3002\u4f46\u4fc2\u592a\u591aData\u53bb\u6284\uff0c\u7d50\u679c 1.3T Data\u7cfb\u7528\u63a5\u8fd1\u5169\u661f\u671f\u5b8c\u6210\u3002<\/p>\n<p>\u984d\u5916\u5c31\u4fc2FreeNAS\u5605Rsync\u7cfb\u6703unlimit bandwidth\u53bb\u505aSync\u3002\u6240\u4ee5\u8981control\u00a0task \u7528\u5e7e\u591abandwidth\u3002\u518d\u4e4b\u5f8c\u4fc2\u843d\u8fd4\u500blogfile\uff0c\u7b49\u53ef\u7121\u7747task\u6709\u7121\u554f\u984c<\/p>\n<p>My setup<\/p>\n<p>&#8211;bwlimit=1800 -vv &#8211;log-file=\/path for log\/rsync.log<\/p>\n<p>&nbsp;<\/p>\n<p>Credit: Reference Article<\/p>\n<p>FreeNAS Rsync setup<\/p>\n<p><a href=\"https:\/\/www.mattwall.co.uk\/2016\/04\/03\/rsync-to-synology-from-freenas.html\">https:\/\/www.mattwall.co.uk\/2016\/04\/03\/rsync-to-synology-from-freenas.html<\/a><\/p>\n<p>Synology Rsync setup<\/p>\n<p><a href=\"https:\/\/www.synology.com\/en-global\/knowledgebase\/DSM\/help\/DSM\/AdminCenter\/file_rsync\">https:\/\/www.synology.com\/en-global\/knowledgebase\/DSM\/help\/DSM\/AdminCenter\/file_rsync<\/a><\/p>\n<p>Synology SSH Public Key<\/p>\n<p><a href=\"https:\/\/www.synology.com\/en-global\/knowledgebase\/DSM\/tutorial\/Management\/How_to_log_in_to_DSM_with_key_pairs_as_admin_or_root_permission_via_SSH_on_computers\">https:\/\/www.synology.com\/en-global\/knowledgebase\/DSM\/tutorial\/Management\/How_to_log_in_to_DSM_with_key_pairs_as_admin_or_root_permission_via_SSH_on_computers<\/a><\/p>\n<p>SSH Keygen<\/p>\n<p><a href=\"https:\/\/www.ssh.com\/ssh\/keygen\/\">https:\/\/www.ssh.com\/ssh\/keygen\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 &nbsp; &nbsp; Data \u5099\u4efd\u597d\u7dca\u8981\uff01 \u81ea\u5f9eOffice \u7528FreeNAS keep Source \u4ee5\u9ece\uff0c\u90fd\u4fc2\u7528USB HDD \u7d93PC \u884cSyncBackPro \u505aSchedule Backup (\u96d6\u7136\u91cd\u6709\u7b2c\u4e09\u5957Backup\u53bb\u53e6\u4e00\u96bbSynology\uff09 Reference site \u597d\u6709\u7528\uff0c\u4f46\u6709\u4e00\u6a23\u4fc2\u5165\u9762\u7121\u63d0\uff0c\u4f46\u81ea\u5df1\u53c8\u958b\u982d\u7121\u641e\u6e05\u695a\u5605\u3002\u5c31\u4fc2FreeNAS \u5605 \u300ersync\u300f service-account \u5605Primary Group \u8981\u4fc2 Wheel\uff0cPrimary Group \u4fc2\u81ea\u5df1\u540d\u6216\u5176\u4ed6\u3002Rsync task\u90fd\u5514\u6703\u884c\u5f97\u8d77\u3002 SSH Keygen \u5514\u4fc2\u592a\u96e3\uff0c\u6700\u7dca\u8981\u641e\u6e05\u695a\u908a\u90e8\u6a5f\u53bb\u908a\u90e8\u6a5f(Source&gt;Target) Genkey \u7cfb\u4fc2Source\u6a5fgen\uff0c\u4e4b\u5f8c\u6284id_rsa.pub\u53bbTargetMachine ~\/.ssh\u5165\u9762\uff0c\u540c\u57cb &#8220;authorized_key&#8221; \u5169\u500bfile\u3002Permission 711 \u4fc2Synology\u5165\u9762enable Rsync\u5514\u592a\u8907\u96dc\uff0c\u4f46\u4fc2\u552f\u4e00\u4ee4\u6211\u518d\u4f0f\u5605\u4f4d\u4fc2, Synology Rsync Service-Account\u9700\u8981\u4fc2Admin Group Member\u3002\u5514\u4fc2\u5572\u8a71FreeNAS\u7528SSHconnect\u53bbSynology\u7cfb\u6703\u7167\u554fPassword\u3002 \u5982\u7121\u7279\u5225\u554f\u984c\u5c31\u53ef\u4ee5Trial Run\u3002\u3002\u4f46\u4fc2\u592a\u591aData\u53bb\u6284\uff0c\u7d50\u679c 1.3T Data\u7cfb\u7528\u63a5\u8fd1\u5169\u661f\u671f\u5b8c\u6210\u3002 \u984d\u5916\u5c31\u4fc2FreeNAS\u5605Rsync\u7cfb\u6703unlimit bandwidth\u53bb\u505aSync\u3002\u6240\u4ee5\u8981control\u00a0task \u7528\u5e7e\u591abandwidth\u3002\u518d\u4e4b\u5f8c\u4fc2\u843d\u8fd4\u500blogfile\uff0c\u7b49\u53ef\u7121\u7747task\u6709\u7121\u554f\u984c My setup &#8211;bwlimit=1800 &hellip; <a href=\"https:\/\/rol801.com\/wordpress\/?p=440\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;FreeNAS (Rsync over SSH) to Synology Setup&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[2],"tags":[],"class_list":["post-440","post","type-post","status-publish","format-standard","hentry","category-it"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p71O8A-76","jetpack-related-posts":[{"id":365,"url":"https:\/\/rol801.com\/wordpress\/?p=365","url_meta":{"origin":440,"position":0},"title":"iOS Supervised Device \u7528 Global HTTP Proxy Profile \u51fa\u73feMDM Device Check-In Activity \u5931\u8e64\u4e8b\u4ef6","author":"rol801","date":"July 28, 2018","format":false,"excerpt":"\u00a0 \u00a0 \u00a0 \u00a0 \u7e8c\u4e0a\u4e00\u500bPost\u3002 pFSense\u52a0Squid Proxy\u5df2\u7d93Config \u597d\u3002Proxy Pac\u4ea6\u5df2\u7d93\u653e\u4fc2Web Server\u3002\u4fc2PC Browser\u53ef\u4ee5\u9806\u5229\u7528\u5230Proxy\uff0c\u6e96\u5099\u5de5\u4f5c\u5b8c\u6210\u3002 \u4fc2Apple Community\u5165\u9762\u6435\u5230\u4e00\u500b\u5e7e\u597d\u5605Discussion AppProxy Provider vs Global Proxy \u4ee5\u81ea\u5df1\u7406\u89e3\uff0cAppProxyProvider \u4fc2 MDM Vendor \u5605App Gateway\u6216\u8005\u4fc2\u6211\u54cb\u8b1bMDM\u5605PreApp VPN Gateway\uff0c\u7b49\u540cMobileIron \u5605 Sentry \u81ea\u5df1\u5605\u63a8\u65b7\u540c\u4e0b\u9762\u5462\u6bb5Message\u5dee\u5514\u591a To start, I want to be clear about one thing: App proxy providers and the global HTTP proxy are very different\u2026","rel":"","context":"In &quot;iOS&quot;","block_context":{"text":"iOS","link":"https:\/\/rol801.com\/wordpress\/?cat=15"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2018\/07\/Squid_Software_Logo.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":306,"url":"https:\/\/rol801.com\/wordpress\/?p=306","url_meta":{"origin":440,"position":1},"title":"Kerberos Double Hop Setup \u5099\u5fd8","author":"rol801","date":"April 7, 2018","format":false,"excerpt":"\u00a0 \u00a0 \u00a0 \u00a0 Kerberos -\u00a0\u5c0d\u65bc\u81ea\u5df1\u569f\u8b1b\u53eb\u505a\u5e38\u7528\uff0c\u4f46\u4fc2\u6709\u6642\u5019\u90fd\u6703\u5fd8\u8a18\u4e00\u5572\u7279\u5225\u5605Implementation \u65b9\u6cd5\u3002Double Hop \u6b63\u6b63\u4fc2\u81ea\u5df1\u6703\u5fd8\u8a18\u5605\u4e00\u7a2e\u3002 \u5148\u8b1b\u54a9\u4fc2 Single Hop \uff0f Double Hop\u3002 \u00a0 \u9867\u540d\u601d\u7fa9 Single Hop > \u5e73\u5e38 \u5e38\u7528\u5605\u5ea6\u6cd5\uff0c\u597d\u4f3cShare Point\u5481 Double Hop > \u540cSingle Hop \u5605\u5225\u5c31\u4fc2\u6703\u518d\u7528Kerberos\u53bbConnect \u53e6\u4e00\u500bSource\u3002 \uff08\u6ce8\u610f\uff1a\u4fc2\u5169\u6b21Kerberos\uff0c\u6211\u6703\u5e38\u5e38\u5fd8\u8a18\u5605\u5c31\u4fc2\u7b2c\u4e8c\u5c64\u7121\u7528Kerberos\u5605\u99c1\u6cd5\u800cFail Error 401) \u4e0b\u9762\u7b2c\u4e00\u689dReference URL \u4fc2\u975e\u5e38\u6e05\u6670Setup Guide\u3002 \u800c\u5e38\u7528Kerberos Hop\u4fc2 IIS Virtual Directory\u6307\u4fc2 UNC Path \u81ea\u5df1\u559c\u6b61\u7528\u5605\u65b9\u6cd5\u540cArticle \u8b1b\u5605\u6709\u5572\u5514\u540c \u5230\u6cd5\u5982\u4e0b - IIS WebSite\u2026","rel":"","context":"In &quot;IT&quot;","block_context":{"text":"IT","link":"https:\/\/rol801.com\/wordpress\/?cat=2"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2018\/04\/Kerberos_DoubleHop.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2018\/04\/Kerberos_DoubleHop.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2018\/04\/Kerberos_DoubleHop.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":93,"url":"https:\/\/rol801.com\/wordpress\/?p=93","url_meta":{"origin":440,"position":2},"title":"Postfix incoming\/outgoing mail routing \u5be6\u4f5c","author":"rol801","date":"February 17, 2016","format":false,"excerpt":"\u00a0 \u73a9\u81ea\u5df1\u96bbDomain Linux server\u5481\u591a\u5e74.\u5f9e\u4f86\u90fd\u7121\u9ede\u8ad7\u8981\u591a\u6a5f\u9eceform Infra. \u54e9\u500b\u661f\u671f\u7d42\u65bc\u51fa\u73fe \u9700\u8981prepare Zimbra \u800c\u6709\u5462\u500b\u505a\u6cd5\u5605\u9700\u8981\u3002 \u7686\u56e0\u5514\u60f3\u6d6a\u8cbb N\u5e74\u524d\u8d77\u843d\u5605 CentOS server. \u4f5c\u70baSMTP gateway \u4ea6\u5514\u9700\u8981\u518dreg DNS Record. Outbound SMTP relay \u505a\u5f97\u591a\u3002 \u4f46\u4fc2Inbound\u7d55\u5c0d\u4fc2\u7b2c\u4e00\u6b21\u3002 \u904e\u7a0b\u6574\u8db3\u4e00\u65e5\uff0c\u4f46\u4fc2\u660e\u767d\u4e4b\u5f8c\u7d55\u5c0d\u53ef\u4ee5\u518d\u8ad7\u5f97\u66f4\u8907\u96dc\u3002 \u57fa\u672c\u9700\u6c42\u3002\u3002 \u540c\u4e00Domain\u4e0b\uff0c\u9ece\u7dcaZimbra email\u5605email\u6703\u7d93\u820aserver(Gateway) route\uff08relay)\u5165\uff0c\u00a0 Outbound \u540c\u6a23 relay \u51fa\u3002 \u4f46\u4fc2\u552f\u4e00exception.\u56e0\u70ba\u820aServer\u5df2\u6709\u81ea\u5df1account\u7528\u7dca\uff0c\u9700\u8981keep\u4f4f\u5514\u53ef\u4ee5\u6bd4account\u5605email \u90fdroute\u8d70\u3002 \u9996\u5148\u8981\u4fc2 postfix \u65e2config \/ect\/postfix\/main.cf,\u00a0 \u52a0\u5462\u53e5 \"transport_maps = hash:\/etc\/postfix\/transport\" \u4e4b\u5f8c\u6232\u8089\uff0c\u4fc2 \/etc\/postfix\/transport \u5165\u9762\u6700\u4f4e, \u52a0\u4ee5\u4e0b \u81ea\u5df1\u8981\u7559\u4f4f\u5514route\u5605email address , \u63a5\u4f4f\u4fc2\u81ea\u5df1\u6a5f\u5668\u6536\u2026","rel":"","context":"In &quot;IT&quot;","block_context":{"text":"IT","link":"https:\/\/rol801.com\/wordpress\/?cat=2"},"img":{"alt_text":"Integrations-Postfix-340x216","src":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/02\/Integrations-Postfix-340x216.png?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":134,"url":"https:\/\/rol801.com\/wordpress\/?p=134","url_meta":{"origin":440,"position":3},"title":"\u521d\u8a66SAML\u5927\u96c6\u6703 &#8230;..  1.OKTA 2.Sales Force 3.ADFS","author":"rol801","date":"October 15, 2016","format":false,"excerpt":"\u00a0 \u7d55\u5c0d\u4fc2\u65b0\u6311\u6230 !!!!! SAML\u00a0\u00a0\u00a0\u00a0\u00a0 \u4e00\u76f4\u4fc2\u4ee5\u5f80\u5514\u591a\u6562\u53bb\u6382\u5605\u91ce\u3002\u76f8\u6bd4Kerberos\uff0cSAML\u6709\u81ea\u5df1\u89ba\u5f97\u597d\u96e3\u7747\u5605XML (Recursive xml\uff09\u3002\u8ad7\u8d77\u90fd\u6015\u6015\u3002\u6015\u6015\u3002 \u57fa\u5982\u569f\u7dca\u597d\u9ad8\u6a5f\u6703\u8981\u7528\u540c\u81ea\u5df1\u5605\u672a\u96e8\u7da2\u7e46\uff0c\u6c7a\u5b9a\u653e\u624b\u7747\u7747\u4f62...... \u7b2c\u4e00\u4fc2\u6435\u7528\u5605IdP\uff08Identity Provider) \u540cSP(Service Provider) \u96d6\u7136\u5df2\u7d93\u6709ADFS\u4fc2\u5230\u53ef\u7528\uff0c \u4f46\u4fc2ADFS\u5514\u4fc2\u5462\u500b\u4eca\u6b21Buildup\u6700\u521d\u6703\u7528\u5605\u3002 SalesForce\u5df2\u77e5\u5605\u4fc2\u5927\u8def\u5605Service Provider\u3002\u3002 Production \u8981\u9322\u7121\u53ef\u80fd\u3002\u4f46\u4fc2Developer Edition\u4fc2\u5169\u500bUser\u514d\u8cbb \uff0c\u672a\u6435\u5230\u6709\u7121Support\u3002 \u8d85\u5b64\u5bd2\u3002\u3002\u3002\u3002 \u5df2IdP\u4fc2\u6435\u5605\u7576\u4e2d\u7747\u5230OKTA\u3002\u3002 \u4f62\u5c0d\u6bd4\u597d\u5572\u3002 \u4e09\u500bApp\uff0c\u4e00\u767e\u500bUser\u4fc2\u6c38\u4e45\u514d\u8cbb\uff0c\u4ea6\u6709Support\u3002 \u597d\u5572 \u597d\u3002\u3002\u3002 \u6e96\u5099\u5b8c\u6210\u3002\u3002 \u958b\u5de5 \u5927\u81f3\u4e0a\u5605Concept AD \u4fc2Identity\u00a0 Source\uff0c \u6700\u521d\u4ee4\u81ea\u5df1\u4e82\u5605\u4fc2\u9ede\u958bOKTA\u5605UserID. \u56e0\u70ba\u4fc2\u672a\u5b89OKTA Agent\u540cAD link\u57cb\u4e4b\u524d\u3002 OKTA \u81ea\u5df1\u5605user account\u90fd\u4fc2\u7528\u540c\u4e00\u500bdomain suffix. Password \u4e00\u6a23\u6703\u96e3\u53bb\u78ba\u5b9a\u3002 \u4f46\u4fc2\u767c\u73fe\u7576\u5b89\u5b8cOKTA Agent match \u597duser\u4e4b\u5f8c\u3002 \u4fc2\u5f97\u8fd4AD password. \u5373\u4fc2\u5514\u9700\u8981\u6435account \u505alocal\u2026","rel":"","context":"In &quot;ADFS&quot;","block_context":{"text":"ADFS","link":"https:\/\/rol801.com\/wordpress\/?cat=13"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/10\/ADFSSalesforceConfig.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/10\/ADFSSalesforceConfig.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/10\/ADFSSalesforceConfig.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/10\/ADFSSalesforceConfig.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/10\/ADFSSalesforceConfig.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":71,"url":"https:\/\/rol801.com\/wordpress\/?p=71","url_meta":{"origin":440,"position":4},"title":"ADFS 3.0 -> MFA Setup Configuration","author":"rol801","date":"January 6, 2016","format":false,"excerpt":"\u00a0 \u00a0 \u00a0 \u00a0 \u57fa\u65bc\u88abM\uff04 \u6311\u6a5f\u8a71\u73a9 ADFS \u8981\u7528 On-Premises MFA \u5148\u5920\u597d\u3002 \uff08\u5f80\u5f8c\u5c31\u4fc2\u554f M\uff04\u9ede\u89e3 Cloud MFA \u505a\u5514\u5230Intranet IP by pass MFA) \u7528\u6700\u7c21\u55ae\u5605\u65b9\u6cd5\u4fc2 MFA server \u5b89\u4fc2 ADFS \u540c\u4e00\u90e8\u5e7e\u3002 \u5b89\u88dd\u540c\u5927\u90e8\u5206configure \u4ee5\u4e0b\u9762URL\u70ba\u597d\uff0c \u6bd4Microsoft Official Article \u66f4\u65b9\u4fbf Reference https:\/\/4sysops.com\/archives\/azure-multi-factor-authentication-part-7-securing-ad-fs\/ \u4f46\u4fc2\uff0c\u8981\u63d0\u53ca MFA User Portal\u6703\u7121\u795e\u795e\u9ed0\u7dda login \u5514\u5230\uff0c \u751a\u81f3\u5f71\u97ff\u5230\u4e00\u822c\u7528\u5605ADFS \u721bpage\u3002\u4fc2\u5b89\u88dd\u9014\u4e2dReboot Server\u591a\u7684\u4e8b....... \u6700\u5f8c\u6700\u7d93\u5178\u5605\u4fc2Microsoft \u5605 article \u932f\u8aa4\u52c1\u591a\u3002 PowerShell Commmand \u81ea\u5df1\u780c\u4f46\u4fc2\u7528\u9ece\u5305Parameter\u2026","rel":"","context":"In &quot;ADFS&quot;","block_context":{"text":"ADFS","link":"https:\/\/rol801.com\/wordpress\/?cat=13"},"img":{"alt_text":"mfa_thumb","src":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2016\/01\/mfa_thumb-300x179.png?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":293,"url":"https:\/\/rol801.com\/wordpress\/?p=293","url_meta":{"origin":440,"position":5},"title":"My ADFS Claims Rules Journey \u2013 Part 3 &#8211; Final","author":"rol801","date":"February 28, 2018","format":false,"excerpt":"\u00a0 \u00a0 \u7d42\u65bc\u6709\u6642\u9593\u5fc3\u60c5\u5beb\u57cb\u6700\u5f8c\u5462Part\u3002 \u7e7cPart 2\u3002 \u7d93\u904e\u4e0d\u65b7Try on Error\u8a66Claims Rules\u4e4b\u5f8c\u3002 \u5ee0\u5605\u4ee5\u4e0b\u5462\u500bArticle\u53e6\u6211\u653e\u68c4Claims Rules\u53bb\u505aRestriction\u5605\u8ad7\u6cd5\u3002\u5c0d\u65bcActiveSync\u569f\u8b1b\uff0c\u4f3c\u4e4e\u7528Modern Auth\u4fc2\u524b\u6b7bClaim Rule\u3002 \u4ee5\u4e0b \u5e7e\u985e\u578b\u5605\u505a\u6cd5\u53ef\u4ee5\u53d6\u66ffUnauthorize ActiveSync device access \u7b2c\u4e00\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u7528MDM Vendor\u5605Identity Management Software - \u76f8\u5c0d\u96e3\u5ea6\u4fc2\u6700\u9ad8\uff0c\u56e0\u70ba\u591a\u7528SAML\uff0c \u9700\u8981\u6709Deploy SAML\u5605\u7d93\u9a57\u3002\u800cInfrasture\u5165\u9762\u5605\u914d\u7f6e\u5df2\u7d93\u5514\u4fc2\u666e\u901aCompany\u6703\u6295\u8cc7 \u7b2c\u4e8c\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Deploy Certificate Authentication\u3002\u96e3\u5ea6\u540c\u7b2c\u4e00\u7a2e\u505a\u6cd5\u4e0d\u9051\u591a\u8b93\u3002\u9700\u8981Deploy\/ Maintain Internal CA \/ NDES \/PKI infrastructure\u540c\u6a23\u5514\u5bb9\u6613 \u7b2c\u4e09\u00a0 \u00a0\u2026","rel":"","context":"In &quot;ADFS&quot;","block_context":{"text":"ADFS","link":"https:\/\/rol801.com\/wordpress\/?cat=13"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2015\/12\/adfs-logo.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2015\/12\/adfs-logo.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/rol801.com\/wordpress\/wp-content\/uploads\/2015\/12\/adfs-logo.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=440"}],"version-history":[{"count":6,"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/440\/revisions"}],"predecessor-version":[{"id":455,"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/440\/revisions\/455"}],"wp:attachment":[{"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rol801.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}