Astaro Security Gateway V8.300 Released

1.大家最关注的,翻墙,防止DNS被劫持。
正常请求一个被劫持的域名,当然是劫持没商量了
Sam@Bra:~$ dig hen.bao.li
Sam@Bra:~$ dig hen.bao.li
; <<>> DiG 9.6.0-APPLE-P2 <<>> hen.bao.li
;hen.bao.li. IN A
hen.bao.li. 85697 IN A
然后再看用了Google Public DNS后,照样劫持你没商量
Sam@Bra:~$ dig @ hen.bao.li
;; MSG SIZE  rcvd: 54

我们看看国外机器得出的真实结果
; <<>> DiG 9.3.4-P1 <<>> @ hen.bao.li
可以看到,此路不通。想靠换国外DNS来翻墙的可以醒醒了。
2.解析速度快

Google Public DNS解析速度是挺快的,但OpenDNS就未必了

Sam@Bra:~$ dig @ www.dnspod.com
; <<>> DiG 9.6.0-APPLE-P2 <<>> @ www.dnspod.com
;; QUESTION SECTION: ;www.dnspod.com. IN A
3.最重要的问题,访问网站真的快吗?
相信不少人一定记得之前QQ用户出现过一次"免费出国",当然,现在这个情况也会出现在用了OpenDNS和Google Public DNS用户的身上。
大家都知道中国特色的互联网,南北分家,互访速度巨慢无比,网站的维护人员绞尽脑汁的想办法解决互联互通的问题,加速大家的网站访问速度。
网站加速访问有好几种办法,有钱的大公司就用BGP AnyCast,但并不是人人都做得起(有自己的IP段,做一次BGP广播X-XX万,要达到最佳访问效果必须要做N次BGP广播,最后费用有可能达到 XXX万)。没钱的公司就只能用智能DNS了,包括自建的DNS,或者直接用DNSPod这样的现成方案,其实原理都一样。
智能DNS其实并不是太智能,它靠的预先分配好几个区域,然后根据用户请求的IP来判断用户属于哪个区域,之后返回对应区域的服务器IP。正常情况下,用户在国内上网,用的是ISP自动分配的DNS,用户域名解析请求发给ISP的DNS,ISP的DNS又发给DNSPod这样的域名授权DNS。 DNSPod这时候拿到的IP地址基本是ISP的DNS地址,所以很方便的就能判断出用户所在的区域,并把结果返回给用户。
但如果这个时候,用户用的是OpenDNS或者Google Public DNS,因为这些服务器的IP地址是在国外,并且N多老外都在用,智能DNS就不好判断该怎么返回了。返回国外的IP,影响国内用户的访问速度。
  如果返回国内的IP,影响到其他老外的访问速度。并且如果返回国内的IP,那么该到底返回电信还是网通的IP呢?用户属于哪个省份?无从判断。那么最后只能人多决定人少,返回国外的服务器IP。
本来想找几个典型例子的,但找了一圈回来,发现国内的大公司在这上面烧钱可是一点都不心痛,全部是BGP。要么就是不搭理国外用户,没针对国外用户单独进行解析,一概解析到电信的服务器去。
拿Google来当例子吧。我是网通用户,使用网通自带的DNS,解析www.google.com得到以下结果

Sam@Bra:~$ dig www.google.com
;; ANSWER SECTION:
www.google.com. 48102 IN CNAME www.l.google.com.
www.l.google.com. 300 IN A
如果我用了OpenDNS的话,那么我得到下面的结果

Sam@Bra:~$ dig @ www.google.com
;; ANSWER SECTION:
http://www.google.com.        30    IN    CNAME    google.navigation.opendns.com.
ping一下得出的IP地址,看看速度,其实并不快

Sam@Bra:~$ ping PING ( 56 data bytes
64 bytes from icmp_seq=0 ttl=51 time=213.828 ms
64 bytes from icmp_seq=1 ttl=51 time=213.779 ms
64 bytes from icmp_seq=2 ttl=51 time=214.716 ms
^C
--- ping statistics ---
3 packets transmitted, 3 packets received, 0.0% packet loss
我们可以再看看kaixin001.com的,如果我是网通用户,用了OpenDNS或者Google Public DNS,那么我会被解析到kaixin001的电信IP去。当然,kaixin001的电信机房线路很好,网通用户访问其实影响不大。
我网通DNS直接解析

Sam@Bra:~$ dig kaixin001.com
;; ANSWER SECTION:
kaixin001.com.        120    IN    A
kaixin001.com.        120    IN    A
kaixin001.com.        120    IN    A
kaixin001.com.        120    IN    A
kaixin001.com.        120    IN    A
kaixin001.com.        120    IN    A
Sam@Bra:~$ dig @ kaixin001.com ......
;; ANSWER SECTION:
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A
kaixin001.com. 60 IN A

中小网站就没这么幸运了。中小网站没有太多的钱去买昂贵的BGP线路,只能用很低廉的智能DNS方案,比如我们经常去找字幕的射手网
; p' v) G6 [0 E! c% J' U; @- h
网通直接查询,可以得到网通服务器的IP
Sam@Bra:~$ dig shooter.cn ......
;; ANSWER SECTION:
shooter.cn. 800 IN A

网通套用OpenDNS进行查询,得到的是射手在国外服务器的IP
Sam@Bra:~$ dig @ shooter.cn ......
shooter.cn. 750 IN A
这样,你就"被出国"了。用了OpenDNS或者Google Public DNS后,你访问的将是一个速度并不快的射手网。

国内类似射手网这样的中小网站有几十万甚至上百万,不少游戏运营商也采用这样的方案。虽然他们不一定有国外的服务器,但如果你被解析到并不属于自己网络的服务器上,访问速度或多或少都会受到影响。所以,如果你最近访问网站速度有所下降,或者玩游戏的时候经常掉线,那么你就该把DNS给换回来了。

How to uninstall Sophos Endpoint Security & Control from the command line or with a batch file
Article ID: 109668
58 customers rated this article 4.4 out of 6
This article explains how to uninstall Sophos endpoint security software via a batch script or command line.

The instructions explain what to do on one computer however once the batch file has been created you can run it on any number of computers and if the same components are found they will be removed.
This article does not troubleshoot errors or problems when uninstalling and is intended for guidance on correctly removing endpoint software with a Windows batch script.  Other articles document how to resolve corrupt or broken installations (e.g., Troubleshooting and resolving problematic Sophos endpoint upgrade and uninstall issues).
The instructions below have limited testing and are therefore provided 'as is' and without full support.  You must fully test the batch file created on a test system before using in your production environment.
Read this article
Do not run batch file uninstalls on the Sophos management server, message relay servers, or computers running server-side components such as Sophos Update Manager (SUM), Sophos PureMessage, etc.
If you encounter a problem when running your script we recommend you test uninstalling the components manually with Add/Remove Programs to ensure the normal method works correctly before troubleshooting further or contacting technical support.2 K& F4 ]0 A/ ?/ B) d
Note: Different product version may have different uninstall strings and hence this can mean the script does not uninstall components as expected.
( P# v  J- E/ ^/ y1 ~6 FWe do not accept responsibility for any loss of data resulting from following these instructions.. M# \" Y4 b. I* A! J- H% }' b' ^, R" R. V
Known to apply to the following Sophos product(s) and version(s), D( }" o# Z6 h8 ^5 \

% g6 G( s" j  l. ISophos Endpoint Security and Control
; I( r7 W  Z) ]8 V% r1 @Sophos Endpoint Security
; M0 c% h. T! O) tWhat To Do
5 X/ g* ?, L' z& f$ ?. d& |You need to collect all the required uninstall strings from a typical endpoint computer (so you get the correct commands), copy them into a new text file (one per line), save the file as a .bat extension (batch file) and fully test it works as desired.
Note: If enabled, the Sophos Tamper Protection policy must be disabled on the endpoints involved before attempting to uninstall any component of Sophos Endpoint Security and Control.  See article 119175 for more information.
: ]8 q0 r1 q9 f+ n% q) L. b! jGather the uninstall commands
On an endpoint computer open the registry editor (Start | Run | Type: regedit.exe | Press return).
. V' N) \2 O: x1 w1 tClick through the list and locate the first Sophos component you need to uninstall.
Copy the string into a text editor.6 u- f* @7 I% W
( G- N- [9 T- ~4 PWindows installer parameters
# K" g1 m( Z$ q5 p8 R2 }& \
- g% D7 D4 ]! f# v7 P  n1 c* QThe uninstall strings copied from the registry may contain MSIEXEC.exe parameters or you may want to add your own parameters to control what the end user sees on screen and how the computer behaves.  For example the uninstall string for Sophos Anti-Virus v10 is:
MsiExec.exe /X {9ACB414D-9347-40B6-A453-5EFB2DB59DFA}
But can be modified so that the uninstall is silent:5 U' t& r5 u! q) c- c
MsiExec.exe /X {9ACB414D-9347-40B6-A453-5EFB2DB59DFA} /qn
  A, R. _# [. jOr to suppress a reboot (A restart is normally required for Sophos Client Firewall and Sophos Anti-Virus) so that you may perform it at a later time:7 ]! x6 p& J* r1 N

0 V$ H$ E1 {( i; s9 \It is advisable to create a log file (a separate file is needed for each component) as part of this process for each component being removed to help facilitate troubleshooting should an issue arise:
MsiExec.exe /X{9ACB414D-9347-40B6-A453-5EFB2DB59DFA} /qn REBOOT=SUPPRESS /L*v %windir%\\Temp\\Uninstall_SAV9-10_Log.txt
* E3 S  V/ `' x4 a. O/ qIf you need further information on Windows Installer (MSIEXEC.exe) and associated parameters we recommend you consult up to date Microsoft documentation.
Create a batch file% P! d2 f' s% u8 `, h
Prior to uninstalling the endpoint components, you should stop the Sophos AutoUpdate Service to prevent a potential update of the endpoint software during the removal.  A command line such as the following can be used.& D! t& J1 c- W* e& R

: M+ B: S1 o+ L0 \% c4 F7 h; _net stop &quot;Sophos AutoUpdate Service&quot;4 y3 b/ |7 @# t: A6 K: M$ Y

% \9 V6 A# {# R7 u$ p) D+ _
Sophos Patch Agent
$ G$ W2 l* X$ f7 e- s% GSophos Remote Management System
Sophos Anti-Virus
Then save the file and change the file extension from .txt to .bat
