系统初始化
vim /etc/ssh/sshd_config
PermitRootLogin yes
PasswordAuthentication yes
cat /etc/NetworkManager/system-connections/enp6s18.nmconnection
防火墙
sudo systemctl status firewalld
firewall-cmd --permanent --list-all
sudo firewall-cmd --permanent --add-port=6443/tcp # virtual network flannel
sudo firewall-cmd --permanent --add-port=4172/tcp # PCoIP SG port
sudo firewall-cmd --permanent --add-port=4172/udp # PCoIP SG port
sudo firewall-cmd --permanent --zone=trusted --add-source=10.42.0.0/16 # This subnet is for the pods
sudo firewall-cmd --permanent --zone=trusted --add-source=10.43.0.0/16 # This subnet is for the services
sudo firewall-cmd --reload
系统优化
vim /etc/fstab
swap分区#
swapoff -a //已有的交换器关闭
Connector安装
tar xzvf anyware-connector-offline_24.10.06-1_el9_linux.tar.gz
./install.sh
Manager配置Connector
初始化安装
export token=
/usr/local/bin/anyware-connector configure \
--manager-url 'https://192.168.18.51/' \
--token $token \
--domain 'labtest2025.local' \
--accept-policies \
--enable-ad-sync=false \
--ldaps-insecure \
--manager-insecure \
--debug
同步域控数据
sudo /usr/local/bin/anyware-connector configure \
--enable-ad-sync=true --sa-user usr_sync --sa-password 'Hc@2025' \
--computers-dn 'CN=Computers,DC=labtest2025,DC=local' --users-dn 'CN=Users,DC=labtest2025,DC=local' \
--domain-controller winad-1040.labtest2025.local \
--ldaps-insecure=true \
--manager-insecure \
--debug
WAN网关启用
sudo /usr/local/bin/anyware-connector configure \
--enable-security-gateway=true --external-pcoip-ip 192.168.18.50 \
--manager-insecure --ldaps-insecure=true --self-signed --accept-policies \
--debug
添加LLS
/usr/local/bin/anyware-connector configure \
--local-license-server-url http://192.168.10.57:7070/request \
--debug
如上命令的综合
/usr/local/bin/anyware-connector configure \
--manager-url 'https://192.168.18.51/' \
--token $token \
--domain 'labtest2025.local' \
--enable-ad-sync=true --sa-user usr_sync --sa-password 'Hc@2025' \
--computers-dn 'CN=Computers,DC=labtest2025,DC=local' --users-dn 'CN=Users,DC=labtest2025,DC=local' \
--domain-controller winad-1040.labtest2025.local \
--local-license-server-url http://192.168.10.57:7070/request \
--enable-security-gateway=true --external-pcoip-ip 192.168.18.53 \
--manager-insecure --ldaps-insecure=true --self-signed --accept-policies \
--debug \
--clear
DC证书打开LDAPS
sudo /usr/local/bin/anyware-connector configure \
--ldaps-ca-cert '/root/dc-cert1040.pem' \
--ldaps-insecure=false \
--debug
/usr/local/bin/anyware-connector configure \
--domain 'labtest2025.local' \
--ldaps-ca-cert '/root/dc-cert1040.pem' \
--debug
运维
/usr/local/bin/anyware-connector diagnose --support-bundle
/usr/local/bin/anyware-connector diagnose --health