PreChecklist (์„ค์น˜ ๋ฐ ์ž‘์—… ์ „ ์‚ฌ์ „ ํ™˜๊ฒฝ ์š”๊ตฌ ์‚ฌํ•ญ)

PreChecklist (์„ค์น˜ ๋ฐ ์ž‘์—… ์ „ ์‚ฌ์ „ ํ™˜๊ฒฝ ์š”๊ตฌ ์‚ฌํ•ญ)

ย 


  1. RoRo ์„œ๋ฒ„ ์ค€๋น„ ๋ฐ ์‚ฌ์ „ ์š”๊ตฌ์‚ฌํ•ญ ์„ค์ •

  2. ๋Œ€์ƒ ์„œ๋ฒ„(Inventory Server) ์ค€๋น„ ๋ฐ ์‚ฌ์ „ ์š”๊ตฌ์‚ฌํ•ญ ์„ค์ • - ์ ‘๊ทผ๊ถŒํ•œ ๋ฐ ๋„คํŠธ์›Œํฌ ์„ค์ •
    * Discovered Server ๋ฐœ๊ฒฌ์‹œ ์ถ”๊ฐ€ ๋ถ„์„์„ ์œ„ํ•œ ์ ‘์†๊ถŒํ•œ ํš๋“ (์ดˆ๊ธฐ ์ธ๋ฒคํ† ๋ฆฌ ๋Œ€์ƒ์—์„œ ๋ˆ„๋ฝ๋œ ์„œ๋ฒ„๋กœ RoRo์—์„œ ๋ฐœ๊ฒฌํ–ˆ๋‹ค๋Š” ์˜๋ฏธ๋กœ Discovered Server๋ผ๊ณ  ํ•จ)

  3. ์ž‘์—…์ž PC ์ค€๋น„ ๋ฐ ์‚ฌ์ „ ์š”๊ตฌ์‚ฌํ•ญ ์„ค์ •

  4. ๋ฐฉํ™”๋ฒฝ ํ•ด์ œ List

  5. RoRo์—์„œ ์ œ๊ณตํ•˜๋Š” inventory template (RoRo-Inventory-Template.xls) ์ž‘์„ฑ

    1. Template์„ ์ด์šฉํ•˜์—ฌ bulk upload ์ง„ํ–‰ํ•จ. (์ˆ˜๋™์œผ๋กœ 1๊ฐœ ์„œ๋ฒ„ ๋‹จ์œ„๋กœ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ์Œ.)

    2. Service sheet (ํ•„์ˆ˜ ์ž…๋ ฅ) : Service Code, Service Name, Business Category Code, Business Category, Migration Y/N

      • ์—…๋ฌด์„œ๋น„์Šค๋ช…์„ ๋งํ•˜๋ฉฐ, ์—†๋Š” ๊ฒฝ์šฐ์—๋Š” default service (service code = SERV-001)๋กœ ๋“ฑ๋ก๋จ.

    3. Server sheet (ํ•„์ˆ˜ ์ž…๋ ฅ) : Inventory Code, Server_Name, IP Address, Port(SSH/Winrm), Username, Password, Windows Y/N, su Y/N, Monitoring Y/N

    4. Database assessment ์ง„ํ–‰์˜ ๊ฒฝ์šฐ database sheet ์ถ”๊ฐ€ ์ž‘์„ฑ

      • Database sheet (ํ•„์ˆ˜ ์ž…๋ ฅ) : Server Inventory Code, Inventory Code(of Database), Database Name, Database Service Name, Port, Username, Password, JDBC URL, Engine Name


#1. RoRo ์„œ๋ฒ„ ์ค€๋น„ ๋ฐ ์‚ฌ์ „ ์š”๊ตฌ์‚ฌํ•ญ ์„ค์ •

์ž‘์—…

RoRo Server

์™„๋ฃŒ (Y/N)

์ž‘์—…

RoRo Server

์™„๋ฃŒ (Y/N)

๊ถŒ์žฅ์‚ฌ์–‘ ๋ฐ ์šด์˜ํ™˜๊ฒฝ

CPU - 4 Core

ย 

Memory - 8GB

ย 

HDD - 30GB + a (Assessment ๋ฐ์ดํ„ฐ ๋ฐ Migration ์ด๋ฏธ์ง€ ์ €์žฅ์†Œ)

์˜ˆ. Assessment ์˜ ๊ฒฝ์šฐ : ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ „์ฒด ์šฉ๋Ÿ‰ ๋ณด๋‹ค ํฐ ์‚ฌ์ด์ฆˆ ํ•„์š” (์‚ฌ๋ก€. 500GB ~ 1TB) Migration ์˜ ๊ฒฝ์šฐ : as-is ์„œ๋ฒ„์˜ ์šฉ๋Ÿ‰ ๋ณด๋‹ค ํฐ ์‚ฌ์ด์ฆˆ ํ•„์š”

ย 

OS - CentOS 7 +

ย 

JDK 11 +

java -version ๋ช…๋ น์„ ์‹คํ–‰ํ•˜์—ฌ java ๋ช…๋ น์„ ์ฐพ์„ ์ˆ˜ ์—†๊ฑฐ๋‚˜ ๋ฒ„์ „์ด ๋‚ฎ์€ ๊ฒฝ์šฐ ๋‹ค์Œ๊ณผ ๊ฐ™์ด java ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๊ณ  ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. (JRE ์„ค์น˜ ์‹œ ์ผ๋ถ€ ๊ธฐ๋Šฅ์— ์ œํ•œ์ด ์ƒ๊ธธ ์ˆ˜ ์žˆ์–ด JDK ์„ค์น˜๋ฅผ ์ถ”์ฒœํ•ฉ๋‹ˆ๋‹ค.) ]$ sudo yum install -y java-11-openjdk-devel

ย 

system package

Python 2.7

ย 

ssh

ย 

rsync

ย 

epel

ย 

sshpass

ย 

RoRo repository - DBMS

Maria DB 10.6 ์ด์ƒ ๋ฒ„์ „์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

  • ํ…Œ์ด๋ธ” ๋ฐ ์ปฌ๋Ÿผ์˜ ๋Œ€์†Œ๋ฌธ์ž ๊ตฌ๋ถ„์„ ํ•˜์ง€ ์•Š์œผ๋ฉฐ, ํƒ€์ž„์กด์„ UTC๋กœ ์„ค์ •ํ•˜๊ธฐ ์œ„ํ•ด /etc/my.cnf ํŒŒ์ผ์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

# # This group is read both both by the client and the server # use it for options that affect everything # [client-server] # # include all files from the config directory # !includedir /etc/my.cnf.d [mariadb] lower_case_table_names = 1 default_time_zone = '+9:00'
  • ์„ค์ • ํ™•์ธ

]$ mysqladmin variables -uroot -p | grep -i lower_case_table_names Enter password: | lower_case_table_names | 1

ย 

Network

Unix/Linux : SSH (์ฐธ๊ณ - default 22)

ย 

  • Playce RoRo์—์„œ Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ SSH ์ ‘์†์ด ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

  • Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ SSH ์ ‘์† ์‹œ ํŒจ์Šค์›Œ๋“œ ๋˜๋Š” ํ‚คํŒŒ์ผ์„ ์ด์šฉํ•œ ๋กœ๊ทธ์ธ์ด ๊ฐ€๋Šฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

  • Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ SSH ์ ‘์† ํ›„ ํŒจ์Šค์›Œ๋“œ ํ™•์ธ ์—†์ด sudo ๋ช…๋ น์ด ์‹คํ–‰ ๊ฐ€๋Šฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

  • ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ๋Œ€์ƒ AWS, GCP ๋“ฑ์˜ CSP(Cloud Service Provider)์— ๋„คํŠธ์›Œํฌ๋กœ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.ย 

ย 

  • cf. SSH ํ†ต์‹  ๋ฐ ์ ‘์† ์„ค์ • ํ™•์ธ

]$ ssh rorouser@Bserver_ip -p ssh_port Bserver_ip]$ sudo vi /etc/sudoers -- ์ •์ƒ์—ฌ๋ถ€ ํ™•์ธ

ย 

  • Windows ์„œ๋ฒ„ ๋‚ด์˜ Application ๋ถ„์„์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ Windows์—์„œ RoRo ์„œ๋ฒ„๋กœ์˜ SSH ์ ‘์†์ด ๊ฐ€๋Šฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

Windows : Winrm (์ฐธ๊ณ - default 5985)

ย 

  • Playce RoRo์—์„œ Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ winrm์ ‘์†์ด ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • Windows Server ์˜ ๋ฐฉํ™”๋ฒฝ ์„ค์ •์—์„œ ํ•ด์ œ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

Rehost migration

RoRo Server์˜ /etc/mke2fs.conf ํŒŒ์ผ์˜ ์„ค์ •์— ๋”ฐ๋ผ Rehost Migration์ด ์‹คํŒจํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์•„๋ž˜ ์„ค์ •๊ณผ ๊ฐ™์ด [fs_types] ๋‚ด ext4์˜ features ์ธ์ž ์ค‘ 64bit๋ฅผ ์‚ญ์ œํ•˜๊ณ , auto_64-bit_support = 1 ๋ฅผ ์ถ”๊ฐ€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

[defaults] ... skip ... [fs_types] ... skip ... ext4 = { features = has_journal,extent,huge_file,flex_bg,metadata_csum,dir_nlink,extra_isize auto_64-bit_support = 1 inode_size = 256 } ... skip ...

ย 

Subscription Key

Trial, Enterprise๋กœ ๊ตฌ๋ถ„ํ•˜์—ฌ Subscription Key ๋ฐœ๊ธ‰

  • Enterprise(์ •์‹ํ‚ค) - RoRo ์„ค์น˜ ์ดํ›„ signature ๋ช…๋ น ์ˆ˜ํ–‰ ํ›„ ๊ฒฐ๊ณผ ๊ฐ’์„ sales์—๊ฒŒ ์ „๋‹ฌํ•œ ํ›„ ๋ฐœ๊ธ‰

  • Trial - ๊ธฐ๊ฐ„๊ณผ ์ธ๋ฒคํ† ๋ฆฌ ๋“ฑ๋ก ๊ฐ€๋Šฅํ•œ VM์˜ ์ˆ˜๋Ÿ‰์— ์ œ์•ฝ

ย 

๊ธฐํƒ€

์ฐธ๊ณ , tar ๋˜๋Š” unzip ํŒจํ‚ค์ง€๊ฐ€ ์„ค์น˜๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜์—ฌ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

]$ sudo yum install -y tar ]$ sudo yum install -y unzip

ย 

ย 

#2. ๋Œ€์ƒ ์„œ๋ฒ„(Inventory Server) ์ค€๋น„ ๋ฐ ์‚ฌ์ „ ์š”๊ตฌ์‚ฌํ•ญ ์„ค์ • - ์ ‘๊ทผ๊ถŒํ•œ ๋ฐ ๋„คํŠธ์›Œํฌ ์„ค์ •

์ž‘์—…

Inventory Server (Unix/Linux Server)

์™„๋ฃŒ (Y/N)

์ž‘์—…

Inventory Server (Unix/Linux Server)

์™„๋ฃŒ (Y/N)

ํ•„์ˆ˜ ์„ค์น˜ ํ•ญ๋ชฉ

ssh

ย 

sudo (unix)

ย 

rsync **** ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜์„ ์œ„ํ•ด ํ•„์š”ํ•จ

ย 

roro ์ž‘์—… ๊ณ„์ • ์ƒ์„ฑ ๋ฐ ๊ถŒํ•œ ์„ค์ •
(sudo ๋ช…๋ น์ด ์‹คํ–‰ ๊ฐ€๋Šฅํ•˜๋„๋ก ์„ค์ • - ๋“ฑ๋ก๋  ์‚ฌ์šฉ์ž ๊ณ„์ •์ด root๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ)

3๊ฐ€์ง€ ๋ฐฉ๋ฒ• ์ค‘ ์„ ํƒํ•˜์—ฌ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

  • #1. ๋“ฑ๋ก๋  ์‚ฌ์šฉ์ž ๊ณ„์ •์ด root๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ /etc/sudoers ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. (ํŒจ์Šค์›Œ๋“œ์—†์ด sudo(super user do) ๋ช…๋ น ์‹คํ–‰ ๊ฐ€๋Šฅํ† ๋ก)

  • #2. root ๊ณ„์ •์œผ๋กœ ์ง์ ‘ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

  • #3. ๋“ฑ๋ก๋œ ์‚ฌ์šฉ์ž ๊ณ„์ •์œผ๋กœ ์ง„ํ–‰ํ•˜๋ฉฐ, root ๋กœ su(switch user) ํ•˜์—ฌ ์ง„ํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

ย 

Middleware/java-application ๋ถ„์„์„ ์œ„ํ•ด์„œ๋Š” root ๊ถŒํ•œ ๋˜๋Š” ํ•ด๋‹น application ์ˆ˜ํ–‰ ๊ถŒํ•œ์˜ user ์ ‘์† ์ •๋ณด๊ฐ€ ํ•„์š”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
(solution path ์˜ ํด๋” ๊ถŒํ•œ์ด 700/600 ์ธ ๊ฒฝ์šฐ, ssh&su ์ง„ํ–‰์œผ๋กœ๋Š” ๊ถŒํ•œ์ด ๋ถ€์กฑ์œผ๋กœ ๋ถ„์„์ด ๋ถˆ๊ฐ€)

ย 

Database Assessment๋ฅผ ์œ„ํ•ด์„œ๋Š” RoRo DB User Name์ด ๋ฐ˜๋“œ์‹œ DBA๊ถŒํ•œ ์ด์ƒ์œผ๋กœ ์„ค์ • ๋˜์–ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์€ ๊ฒฝ์šฐ๋Š” DBA User ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

์ƒ๊ธฐ ์œ„์˜ #1์˜ ๊ฒฝ์šฐ์— ๋Œ€ํ•œ ์„ค๋ช…์ž…๋‹ˆ๋‹ค.

๋“ฑ๋ก๋  ์‚ฌ์šฉ์ž ๊ณ„์ •์ด root๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ /etc/sudoers ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ํ•ด๋‹น ์‚ฌ์šฉ์ž ๋˜๋Š” ๊ทธ๋ฃน์ด ํŒจ์Šค์›Œ๋“œ ์—†์ด sudo ๋ช…๋ น ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•˜๋„๋ก ์•„๋ž˜์™€ ๊ฐ™์ด ์ถ”๊ฐ€๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • โ€œDefaults requirettyโ€ ์˜ต์…˜์ด ํ™œ์„ฑํ™” ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ ์ฃผ์„ ์ฒ˜๋ฆฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. (OS ๋ฒ„์ „์— ๋”ฐ๋ผ ์˜ต์…˜์ด ์กด์žฌํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.)

vim /etc/sudoers # Disable "ssh hostname sudo <cmd>", because it will show the password in clear. # You have to run "ssh -t hostname sudo <cmd>". # #Defaults requiretty ...... ## Same thing without a password # %wheel ALL=(ALL) NOPASSWD: ALL roro ALL=(ALL) NOPASSWD: ALL

ย 

Network

Unix/Linux : SSH (์ฐธ๊ณ - default 22)

ย 

  • Playce RoRo์—์„œ Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ SSH์ ‘์†์ด ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ SSH ์ ‘์† ์‹œ ํŒจ์Šค์›Œ๋“œ ๋˜๋Š” ํ‚คํŒŒ์ผ์„ ์ด์šฉํ•œ ๋กœ๊ทธ์ธ์ด ๊ฐ€๋Šฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • Inventory์— ๋“ฑ๋ก ๋œ ์„œ๋ฒ„๋กœ SSH ์ ‘์† ํ›„ ํŒจ์Šค์›Œ๋“œ ํ™•์ธ ์—†์ด sudo ๋ช…๋ น์ด ์‹คํ–‰ ๊ฐ€๋Šฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • Server Assessment ์‹œ netstat, arp๋“ฑ์˜ ๋ช…๋ น์–ด๊ฐ€ ์‹คํ–‰๋˜์ง€ ์•Š์„ ๊ฒฝ์šฐ ์•„๋ž˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•ด์„œ ์„ค์น˜ ํ›„ ์ง„ํ–‰ํ•˜๋Š” ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

# CentOS/Rhel yum -y install net-tools # Debian sudo apt install net-tools

ย 

์ž‘์—…

Inventory Server (Windows Server)

์™„๋ฃŒ (Y/N)

์ž‘์—…

Inventory Server (Windows Server)

์™„๋ฃŒ (Y/N)

ํ•„์ˆ˜์„ค์น˜ ํ•ญ๋ชฉ

PowerShell Version 1.0 ~ 5.1

  • Window Server 2008์˜ ๊ฒฝ์šฐ Component ํ™œ์šฉ Optional ํ•˜๊ฒŒ ์„ค์น˜ํ•˜์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ย 

pscp (SFTP Client) ์„ค์น˜

ย 

roro ์ž‘์—… ๊ณ„์ • ์ƒ์„ฑ ๋ฐ ๊ถŒํ•œ ์„ค์ •

(Local) Administrators ๊ถŒํ•œ ๋ถ€์—ฌ ํ•„์š”

ย 

Network (Firewall)

WinRM์—์„œ ๊ธฐ๋ณธ์œผ๋กœ ์“ฐ๋Š” Port๋Š” 5985์ด๋‹ค.

  • ๋ฐฉํ™”๋ฒฝ ์„ค์ •์—์„œ InBound Port 5985๋ฅผ ์ถ”๊ฐ€ํ•œ๋‹ค.

  • ๋ณ„๋„์˜ OutBound ์„ค์ •์„ ๊ด€๋ฆฌํ•œ๋‹ค๋ฉด RoRo ์„œ๋ฒ„์˜ SSH ํฌํŠธ๋กœ ์ ‘์†์ด ๊ฐ€๋Šฅํ•˜๋„๋ก ์„ค์ •์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

ย 

WinRM ์„ค์ •

(Power Shell : ๊ด€๋ฆฌ์ž ๋ชจ๋“œ)

Basic ์ธ์ฆ ๋ฐฉ๋ฒ• ์ถ”๊ฐ€ ๋ฐ ์„ค์ •.

# WinRM ์„œ๋น„์Šค ํ™œ์„ฑํ™” winrm qc # Basic ์ธ์ฆ ๋ฐฉ๋ฒ• ์ถ”๊ฐ€. (RoRo์—์„œ Basic ์ธ์ฆ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•œ๋‹ค.) winrm set winrm/config/service/Auth '@{Basic="true"}' # AllowUnencrypted ์„ค์ • (์•”ํ˜ธํ™” ๋˜์ง€์•Š๋Š” ๋ฐ์ดํ„ฐ์˜ ์ „์†ก์„ ํ—ˆ์šฉ). winrm set winrm/config/service '@{AllowUnencrypted="true"}' # Shell์˜ ์ž์‹ ํ”„๋กœ์„ธ์Šค๋ฅผ ํฌํ•จํ•˜์—ฌ ํ• ๋‹น๋œ ์ตœ๋Œ€ ๋ฉ”๋ชจ๋ฆฌ ์–‘ ์„ค์ • (๊ธฐ๋ณธ๊ฐ’ : 1024) # ๊ธฐ๋ณธ๊ฐ’ ๋ณด๋‹ค ์ž‘์€ ๊ฐ’์œผ๋กœ ์„ค์ •๋œ ๊ฒฝ์šฐ ์ œ๋Œ€๋กœ ๋™์ž‘ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Œ. winrm set winrm/config/winrs '@{MaxMemoryPerShellMB="1024"}'

ย 

Trust Host์ถ”๊ฐ€

# TrustedHosts ์— RoRo ์„œ๋ฒ„ ๋“ฑ๋ก. # ๋ฐฉํ™”๋ฒฝ๊ณผ ๊ด€๊ณ„์—†์ด RoRo ์„œ๋ฒ„์™€์˜ ํ†ต์‹ ์„ ์œ„ํ•ด ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ํ˜ธ์ŠคํŠธ๋กœ ๋“ฑ๋ก์„ ํ•œ๋‹ค. # ๊ธฐ์กด์— ์„ค์ •๋˜์–ด ์žˆ๋Š” Host๊ฐ€ ์žˆ๋‹ค๋ฉด Overwrite๋ฅผ ํ•œ๋‹ค. Set-Item wsman:\localhost\Client\TrustedHosts RoRo์„œ๋ฒ„IP # TrustedHosts ๋ชฉ๋ก ๋ณด๊ธฐ Get-Item wsman:\localhost\Client\TrustedHosts ---------------------------------------------------------- ์˜ˆ์‹œ) # TrustedHosts์— ๋ชจ๋“  ์ปดํ“จํ„ฐ๋ฅผ ์ถ”๊ฐ€๋ฐฉ๋ฒ• Set-Item wsman:\localhost\Client\TrustedHosts -value * ์˜ˆ์‹œ) # TrustedHosts์— ํŠน์ • ๋„๋ฉ”์ธ/IP ์ปดํ“จํ„ฐ๋ฅผ ์ถ”๊ฐ€๋ฐฉ๋ฒ• Set-Item wsman:\localhost\Client\TrustedHosts test.domain.com Set-Item wsman:\localhost\Client\TrustedHosts *.domain.com Set-Item wsman:\localhost\Client\TrustedHosts 192.168.5.111 *** ์ด๋ฏธ ๋“ฑ๋กํ•œ ํ˜ธ์ŠคํŠธ๊ฐ€ ์žˆ๋‹ค๋ฉด ๊ธฐ์กด ์ •์˜๋œ ํ˜ธ์ŠคํŠธ์— Add ํ•ด์„œ ๋“ฑ๋ก์„ ํ•œ๋‹ค. *** ์˜ˆ์‹œ) PS> Get-Item wsman:\localhost\Client\TrustedHosts WSManConfig: Microsoft.WSMan.Management\WSMan::localhost\Client Type Name SourceOfValue Value ---- ---- ------------- ----- System.String TrustedHosts test.domain.com PS> Set-Item wsman:\localhost\Client\TrustedHosts 'test.domain.com,RoRo์„œ๋ฒ„IP'

ย 

  • Session ๋ณ€๊ฒฝ - ์ ‘์† ์œ ์ € ๋ฐ Shell ์œ ์ €์ˆ˜ Limit ๋ณ€๊ฒฝ.

winrm set winrm/config/winrs '@{MaxConcurrentUsers="20"}' winrm set winrm/config/winrs '@{MaxShellsPerUser="20"}'

ย 

WinRM์˜ ์„ค์ • ํ™˜๊ฒฝ ๋ณด๊ธฐ

winrm get winrm/config

ย 

WinRM ์„œ๋น„์Šค Restart (ํ•„์š” ์‹œ)

restart-service winrm

ย 

ย 

ย 

** Windows 2008 (Powershell 1.0์„ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ.)ย 

์ž‘์—…

Inventory Server

ย 

์ž‘์—…

Inventory Server

ย 

PowerShell ์„ค์น˜.

๊ธฐ๋ณธ์ ์œผ๋กœ ์„ค์น˜๋˜์–ด ์žˆ์ง€๋Š” ์•Š์ง€๋งŒ Windows Server 2008์˜ ํ‘œ์ค€ ๊ธฐ๋Šฅ์œผ๋กœ ํฌํ•จ. (Version :1.0)
๊ด€๋ฆฌ์ž ๊ถŒํ•œ์œผ๋กœ ๋ช…๋ น์–ด ํ”„๋กฌํ”„ํŠธ๋ฅผ ์‹คํ–‰ํ•œ ๋’ค ์„ค์น˜๋ฅผ ํ•œ๋‹ค. (์„œ๋ฒ„์— ๋”ฐ๋ผ์„œ ์˜ค๋ž˜ ๊ฑธ๋ฆด ์ˆ˜ ์žˆ๋‹ค.)

C:\> servermanagercmd -install powershell

ย 

ย 

WinRM ์„ค์ •

Session

Basic ์ธ์ฆ ๋ฐฉ๋ฒ• ์ถ”๊ฐ€ ๋ฐ ์„ค์ •.

# WinRM ์„œ๋น„์Šค ํ™œ์„ฑํ™” winrm quickconfig # Basic ์ธ์ฆ ๋ฐฉ๋ฒ• ์ถ”๊ฐ€. (RoRo์—์„œ Basic ์ธ์ฆ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•œ๋‹ค.) winrm set winrm/config/service/Auth '@{Basic="true"}' # AllowUnencrypted ์„ค์ • (์•”ํ˜ธํ™” ๋˜์ง€์•Š๋Š” ๋ฐ์ดํ„ฐ์˜ ์ „์†ก์„ ํ—ˆ์šฉ). winrm set winrm/config/service '@{AllowUnencrypted="true"}' # Shell์˜ ์ž์‹ ํ”„๋กœ์„ธ์Šค๋ฅผ ํฌํ•จํ•˜์—ฌ ํ• ๋‹น๋œ ์ตœ๋Œ€ ๋ฉ”๋ชจ๋ฆฌ ์–‘ ์„ค์ • (๊ธฐ๋ณธ๊ฐ’ : 1024) # ๊ธฐ๋ณธ๊ฐ’ ๋ณด๋‹ค ์ž‘์€ ๊ฐ’์œผ๋กœ ์„ค์ •๋œ ๊ฒฝ์šฐ ์ œ๋Œ€๋กœ ๋™์ž‘ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Œ. winrm set winrm/config/winrs '@{MaxMemoryPerShellMB="1024"}'

ย 

ย 

WinRM Default Listener Port ํ™•์ธ

# Port ํ™•์ธ. # ๊ธฐ๋ณธ Port๊ฐ€ 80์œผ๋กœ ์„ค์ •๋˜์–ด ์žˆ๋Š”๊ฑธ ์•Œ ์ˆ˜์žˆ๋‹ค. winrm enumerate winrm/config/listener

WinRM Port ๋ณ€๊ฒฝ.

# Port ๋ณ€๊ฒฝ. winrm set winrm/config/listener?Address=*+Transport=HTTP '@{Port="5985"}'

ย 

ย 

  • Session ๋ณ€๊ฒฝ - ์ ‘์† ์œ ์ € ๋ฐ Shell ์œ ์ €์ˆ˜ Limit ๋ณ€๊ฒฝ.

winrm set winrm/config/winrs '@{MaxConcurrentUsers="20"}' winrm set winrm/config/winrs '@{MaxShellsPerUser="20"}'

ย 

ย 

  • Trust Host์ถ”๊ฐ€

    # TrustedHosts ์— RoRo ์„œ๋ฒ„ ๋“ฑ๋ก. # ๋ฐฉํ™”๋ฒฝ๊ณผ ๊ด€๊ณ„์—†์ด RoRo ์„œ๋ฒ„์™€์˜ ํ†ต์‹ ์„ ์œ„ํ•ด ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ํ˜ธ์ŠคํŠธ๋กœ ๋“ฑ๋ก์„ ํ•œ๋‹ค. winrm set winrm/config/client '@{TrustedHosts="RoRo์„œ๋ฒ„IP"}'

    ย 

    WinRM ์„œ๋น„์Šค Restart (ํ•„์š” ์‹œ)

    restart-service winrm

ย 

ย 

WinRM ์ธ์ฆ ๋น„ํ™œ์„ฑํ™”, TrustedHosts ๋“ฑ๋กํ•ด์ œ, ์„œ๋น„์Šค ์ข…๋ฃŒ ๋ฐ ๋น„ํ™œ์„ฑํ™”, ๋ฐฉํ™”๋ฒฝ ์ˆ˜์ •

์ž‘์—…

Inventory Server

ย 

์ž‘์—…

Inventory Server

ย 

Basic ์ธ์ฆ ์ œ๊ฑฐ

๊ธฐ์กด Basic Auth ์œ ํ˜•์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋‹ค๋ฉด ์‹คํ–‰ํ•  ํ•„์š”๊ฐ€ ์—†๋‹ค.

winrm set winrm/config/service/Auth '@{Basic="false"}'

ย 

ย 

ย 

TrustedHosts ์ œ๊ฑฐ.

ย 

1. ๋จผ์ € ๊ธฐ์กด์˜ TrustedHosts๋ฅผ ํ™•์ธ์„ ํ•ด์„œ ๋ชฉ๋ก์„ ํ™•์ธํ•œ๋‹ค. - winrm get winrm/config/client 2. ๊ทธ๋ฆฌ๊ณ  ๋‹ค์‹œ ์žฌ ์ •์˜๋ฅผ ํ•œ๋‹ค. (์‹ ๋ขฐํ•˜๊ณ ์ž ํ•˜๋Š” ์„œ๋ฒ„ IP๋งŒ ๋“ฑ๋ก) winrm set winrm/config/client '@{TrustedHosts="ServerIP ๋ชฉ๋ก"}' Example) PS> winrm set winrm/config/client '@{TrustedHosts="server1,127.0.0.1"}' 3. ๋ชจ๋“  Hosts๋ฅผ ์‚ญ์ œํ• ๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•œ๋‹ค. winrm set winrm/config/client '@{TrustedHosts=""}'

ย 

Example)

ย 

ย 

ย 

ย 

์„œ๋น„์Šค ์ค‘์ง€ ๋ฐ Disabled

  • # ํ˜„์žฌ ์„œ๋น„์Šค๋ฅผ Stopํ•œ๋‹ค. Stop-Service winrm # ์œˆ๋„์šฐ ์‹œ์ž‘ ์‹œ ์„œ๋น„์Šค๊ฐ€ ์‹œ์ž‘๋˜์ง€ ์•Š๋„๋ก Disabled ํ•œ๋‹ค. (Disabled๋ฅผ ํ•  ๊ฒฝ์šฐ Start๊ฐ€ ๋˜์ง€ ์•Š๋Š”๋‹ค.) Set-Service winrm -StartupType Disabled

ย 

Firewall

  • ๋ฐฉํ™”๋ฒฝ์—์„œ WinRM ์„œ๋น„์Šค๋ฅผ ์œ„ํ•ด ์˜คํ”ˆ ์‹œ์ผœ๋‘์—ˆ๋˜ InBound 5985 Port๋ฅผ ์ œ๊ฑฐํ•œ๋‹ค.

ย 

ย 

#3. ์ž‘์—…์ž PC ์ค€๋น„ ๋ฐ ์‚ฌ์ „ ์š”๊ตฌ์‚ฌํ•ญ ์„ค์ •

์ž‘์—…

Windows PC

์™„๋ฃŒ (Y/N)

์ž‘์—…

Windows PC

์™„๋ฃŒ (Y/N)

ํ•„์ˆ˜ ์†Œํ”„ํŠธ์›จ์–ด

Chrome ์ตœ์‹ ๋ฒ„์ „, (IE 11๋ฒ„์ „ ์ง€์› ์˜ˆ์ •)

ย 

Export/Import Data File์„ ์œ„ํ•ด Microsoft Excel 2013 ์ด์ƒ

ย 

  • IE 11์˜ ๊ฒฝ์šฐ ์›ํ™œํ•œ ๋™์ž‘์€ ๋ณด์žฅ๋˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์œผ๋ฉฐ ์ตœ์ ํ™” ์ง„ํ–‰ ์ž‘์—…์„ ์ง„ํ–‰์ค‘์ž…๋‹ˆ๋‹ค.

ย 

Network

HTTP - 8080

๋ธŒ๋ผ์šฐ์ €์—์„œ http://$ROROSERVER_IP:8080 ๋ฅผ ์ ‘์†ํ•˜์—ฌ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

ย 

์‹œ์Šคํ…œ์— firewall๊ฐ€ active ์ƒํƒœ๋กœ ๋ธŒ๋ผ์šฐ์ € ์ ‘์†์ด ๋ถˆ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ, ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ 8080 ํฌํŠธ์˜ ์ ‘์†์„ ํ—ˆ์šฉํ•œ๋‹ค.

]$ sudo firewall-cmd --add-port=8080/tcp --permanent ]$ sudo systemctl reload firewalld

ย 

(Optional)

DBํด๋ผ์ด์–ธํŠธ ํˆด ์„ค์น˜ & ์ ‘๊ทผ ๊ถŒํ•œ ํ•„์š”

  • ํ•ด๋‹น PC์—์„œ RoRo ์„œ๋ฒ„์˜ ๋ ˆํŒŒ์ง€ํ† ๋ฆฌ DB(maria/mysql)์— ์ ‘์†ํ•˜์—ฌ assessment data ์ถ”์ถœ

ย 

ย 

๋ฐฉํ™”๋ฒฝ ํ•ด์ œ List

์ถœ๋ฐœ์ง€

๋ชฉ์ ์ง€

ํฌํŠธ

๋ฐฉํ–ฅ

์šฉ๋„

ํ•„์ˆ˜/์˜ต์…˜

์ถœ๋ฐœ์ง€

๋ชฉ์ ์ง€

ํฌํŠธ

๋ฐฉํ–ฅ

์šฉ๋„

ํ•„์ˆ˜/์˜ต์…˜

Windows PC
(์ž‘์—…์ž)

RoRo ์„œ๋ฒ„

8080 (HTTP)

๋‹จ๋ฐฉํ–ฅ

์›น๋ธŒ๋ผ์šฐ์ €(Chrome)์œผ๋กœ RoRo ๊ด€๋ฆฌํ™”๋ฉด ์ ‘์†, Assessment ๋ฐ Migration ์ง„ํ–‰

ํ•„์ˆ˜

RoRo ์„œ๋ฒ„

22 (SSH)

๋‹จ๋ฐฉํ–ฅ

Putty, SecureCRT, Xshell ๋“ฑ์œผ๋กœ RoRo ์„œ๋ฒ„๋กœ ์ ‘์†, ์„ค์น˜ ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง ์ง„ํ–‰

ํ•„์ˆ˜

๋Œ€์ƒ์„œ๋ฒ„ (Inventory - Unix/Linux Server)

22 (SSH)

๋‹จ๋ฐฉํ–ฅ

๋„คํŠธ์›Œํฌ ๋ฐ ์ ‘๊ทผ๊ถŒํ•œ ๋“ฑ ์„ค์ • ๋ฐ ํ™•์ธ

-

๋Œ€์ƒ์„œ๋ฒ„ (Inventory - Windows Server)

3389 (RDP)

๋‹จ๋ฐฉํ–ฅ

Powershell(๊ด€๋ฆฌ์ž๋ชจ๋“œ)์„ ์ด์šฉํ•œ Winrm ์„ค์ • ๋ฐ ํ™•์ธ

-

RoRo ์„œ๋ฒ„

๋Œ€์ƒ์„œ๋ฒ„ (Inventory - Unix/Linux Server)

22 (SSH)

๋‹จ๋ฐฉํ–ฅ

๋Œ€์ƒ์„œ๋ฒ„์— ๋Œ€ํ•œ Assessment ์ˆ˜ํ–‰ (Agentless)

ํ•„์ˆ˜

๋Œ€์ƒ์„œ๋ฒ„ (Inventory - Windows Server)

5985(WINRM)

๋‹จ๋ฐฉํ–ฅ

๋Œ€์ƒ์„œ๋ฒ„์— ๋Œ€ํ•œ Assessment ์ˆ˜ํ–‰ (Agentless)

ํ•„์ˆ˜

๋Œ€์ƒ์„œ๋ฒ„ (Inventory - Windows Server)

RoRo ์„œ๋ฒ„

22 (SSH)

๋‹จ๋ฐฉํ–ฅ

Windows ์„œ๋ฒ„ ๋‚ด์˜ Application Assessment

ํ•„์ˆ˜