{"id":2181,"date":"2019-10-28T09:16:51","date_gmt":"2019-10-28T06:16:51","guid":{"rendered":"https:\/\/vasexperts-ru.hst11.itglobal.com\/blog\/%d0%b1%d0%b5%d0%b7-%d1%80%d1%83%d0%b1%d1%80%d0%b8%d0%ba%d0%b8\/integration-ms-active-directory\/"},"modified":"2025-08-11T14:14:08","modified_gmt":"2025-08-11T11:14:08","slug":"integration-ms-active-directory","status":"publish","type":"post","link":"https:\/\/vasexperts.com\/br\/blog\/dpi\/integration-ms-active-directory\/","title":{"rendered":"Utiliza\u00e7\u00e3o do DPI em redes corporativas: integra\u00e7\u00e3o com o Microsoft Active Directory"},"content":{"rendered":"Uma de nossas atualiza\u00e7\u00f5es recentes \u00e9 a integra\u00e7\u00e3o com o Microsoft Active Directory, \u00fatil para o uso do <a href=\"\/br\/solutions\/dpi-based-bras\/\">DPI em redes corporativas<\/a>. Ao organizar uma rede corporativa, \u00e9 necess\u00e1rio analisar e controlar como os funcion\u00e1rios utilizam os recursos da Internet durante o hor\u00e1rio de trabalho. A plataforma DPI \u00e9 utilizada para:\r\n<ol>\r\n \t<li>restri\u00e7\u00e3o de acesso a redes sociais e mensageiros para determinados grupos de usu\u00e1rios<\/li>\r\n \t<li>monitoramento de tr\u00e1fego e an\u00e1lise de conex\u00e3o \u2013 para evitar vazamento de informa\u00e7\u00f5es confidenciais, ataques DDoS e detec\u00e7\u00e3o de BotNet<\/li>\r\n \t<li>cumprimento de requisitos legais \u2013 restri\u00e7\u00e3o de acesso ao registro de recursos proibidos.<\/li>\r\n<\/ol>\r\nVamos ver como conectar o MS AD e o Stingray Service Gateway, criar listas negras e restringir o acesso de funcion\u00e1rios a aplicativos.\r\n\r\n<h2>Esquema de intera\u00e7\u00e3o<\/h2>\r\n<a href=\"\/wp-content\/uploads\/2019\/10\/msad.svg\"><noscript><img decoding=\"async\" src=\"\/wp-content\/uploads\/2019\/10\/msad.svg\" alt=\"Diagram of Stingray Service Gateway\" width=\"100%\" height=\"auto\" class=\"alignnone wp-image-3515 size-full\"><\/noscript><img decoding=\"async\" src=\"\/wp-content\/uploads\/2019\/10\/msad.svg\" alt=\"Diagram of Stingray Service Gateway\" width=\"100%\" height=\"auto\" class=\"alignnone wp-image-3515 size-full lazyload\" data-src=\"\/wp-content\/uploads\/2019\/10\/msad.svg\"><\/a>\r\n\r\nO DPI \u00e9 instalado em linha e garante a passagem de todo o tr\u00e1fego de entrada e sa\u00edda. O local de instala\u00e7\u00e3o \u00e9 determinado com base nas caracter\u00edsticas da rede: recomenda-se instal\u00e1-lo na frente de um roteador de borda ou dispositivo que implemente NAT.\r\n\r\n\u00c9 importante visualizar os endere\u00e7os IP reais dos clientes e aplicar pol\u00edticas diretamente a esses IPs. Se voc\u00ea precisar implementar NAT, isso tamb\u00e9m \u00e9 poss\u00edvel nas vers\u00f5es BRAS e Complete da plataforma Stingray. <a href=\"\/br\/blog\/bras\/new-licenses-bras-free-qoe-option-vas-cloud\/\">Detalhes do Licenciamento<\/a>\r\n\r\n<h2>O que \u00e9 necess\u00e1rio para integra\u00e7\u00e3o com o MS AD?<\/h2>\r\nO Stingray Service Gateway suporta mecanismos de autoriza\u00e7\u00e3o nos modos L2 (DHCP, ARP, PPPoE) e L3 (IPoE), utilizados com sucesso em redes de acesso de banda larga. Por exemplo, prop\u00f5e-se utilizar o modo IPoE como o mais simples e r\u00e1pido de configurar. O DPI neste esquema \u00e9 muito f\u00e1cil de escalar e executar bypass usando placas ou um segundo servidor com uma licen\u00e7a de backup.\r\n\r\nO esquema envolve:\r\n<ol>\r\n \t<li>   <strong>  Controlador de dom\u00ednio do Microsoft Active Directory.   <\/strong>   Autentica o assinante e transmite dados sobre o endere\u00e7o IP, nome de usu\u00e1rio e grupo emitidos para o servidor Radius.<\/li>\r\n \t<li>   <strong>  Servidor Radius.   <\/strong>   Acumula informa\u00e7\u00f5es do MS AD e responde \u00e0s solicita\u00e7\u00f5es Radius do DPI.<\/li>\r\n \t<li>   <strong>  Stingray Service Gateway.   <\/strong>   Possui perfis pr\u00e9-configurados de listas negras e brancas, perfis de policiamento para bloqueio por protocolos e aplicativos. Gera solicita\u00e7\u00f5es ao servidor Radius no primeiro pacote do assinante.<\/li>\r\n<\/ol>\r\n<h2>Atribui\u00e7\u00e3o de perfis<\/h2>\r\nAp\u00f3s a autoriza\u00e7\u00e3o no MS AD, as informa\u00e7\u00f5es do assinante s\u00e3o enviadas ao servidor Radius. Quando o assinante faz a primeira solicita\u00e7\u00e3o, a plataforma DPI gera uma solicita\u00e7\u00e3o de aceita\u00e7\u00e3o com o endere\u00e7o IP do assinante. Com base na informa\u00e7\u00e3o de que esse IP pertence a um assinante e grupo espec\u00edficos, o servidor Radius gera uma solicita\u00e7\u00e3o de aceita\u00e7\u00e3o de acesso com os atributos. Os atributos podem incluir:\r\n<ol>\r\n\t<li>Nome do perfil da lista de bloqueios<\/li>\r\n\t<li>Nome do perfil da lista de permiss\u00f5es<\/li>\r\n\t<li>Nome do perfil de policiamento<\/li>\r\n\t<li>Nome do pool NAT<\/li>\r\n\t<li>Ativa\u00e7\u00e3o do servi\u00e7o de coleta de estat\u00edsticas de assinantes<\/li>\r\n\t<li>Ativa\u00e7\u00e3o do servi\u00e7o de notifica\u00e7\u00e3o<\/li>\r\n\t<li>Ativa\u00e7\u00e3o do servi\u00e7o de incorpora\u00e7\u00e3o de banners para recursos HTTP.<\/li>\r\n<\/ol>\r\nAp\u00f3s receber os dados, o Stingray Service Gateway aplica restri\u00e7\u00f5es por um per\u00edodo igual ao Tempo Limite da Sess\u00e3o (por exemplo, 600 segundos). Ap\u00f3s esse per\u00edodo, a solicita\u00e7\u00e3o de autoriza\u00e7\u00e3o do IP ao servidor Radius \u00e9 repetida.\r\n\r\n<noscript><img decoding=\"async\" src=\"\/wp-content\/uploads\/2020\/07\/sczenarij-ms-ad-1077x1024-1.png\" alt=\"MS AD Script\" width=\"100%\" class=\"alignnone size-large wp-image-1801\"><\/noscript><img decoding=\"async\" src=\"\/wp-content\/uploads\/2020\/07\/sczenarij-ms-ad-1077x1024-1.png\" alt=\"MS AD Script\" width=\"100%\" class=\"alignnone size-large wp-image-1801 lazyload\" data-src=\"\/wp-content\/uploads\/2020\/07\/sczenarij-ms-ad-1077x1024-1.png\">\r\n\r\nSe o servidor Radius n\u00e3o tiver informa\u00e7\u00f5es sobre o IP solicitado, uma resposta Access-Reject ser\u00e1 gerada com os perfis padr\u00e3o:\r\n<ul>\r\n \t<li>nome do perfil da lista de permiss\u00f5es<\/li>\r\n \t<li>nome do perfil de policiamento.<\/li>\r\n<\/ul>\r\nNesse caso, o assinante ser\u00e1 redirecionado para o Portal Cativo na pr\u00f3xima solicita\u00e7\u00e3o HTTP e limitado pelos protocolos de troca dispon\u00edveis.\r\n<h2>Estat\u00edsticas de assinantes<\/h2>\r\nPara facilitar a configura\u00e7\u00e3o, h\u00e1 uma Interface Gr\u00e1fica do Usu\u00e1rio que ajuda a criar e gerenciar perfis, rastrear servi\u00e7os atribu\u00eddos e status de autoriza\u00e7\u00e3o.\r\n\r\nO Stingray Service Gateway permite analisar o Clickstream e o Full Netflow, que s\u00e3o coletados no <a href=\"\/br\/products\/qoe-analytics\/\">m\u00f3dulo Quality of Experience<\/a>. O administrador da rede tem as seguintes op\u00e7\u00f5es:\r\n<ul>\r\n \t<li>um coletor de estat\u00edsticas NetFlow com suporte para reexporta\u00e7\u00e3o<\/li>\r\n \t<li>suporte de API para integra\u00e7\u00e3o com sistemas externos<\/li>\r\n \t<li>visualiza\u00e7\u00e3o de estat\u00edsticas completas do NetFlow e do ClickStream<\/li>\r\n \t<li>relat\u00f3rios integrados de TOP baseado em Full NetFlow: RTT alto, por volume de tr\u00e1fego, por n\u00famero de novas solicita\u00e7\u00f5es, por protocolos de aplica\u00e7\u00e3o, por AS, por AS de assinantes, por switches de acesso e agrega\u00e7\u00e3o<\/li>\r\n \t<li>relat\u00f3rios TOPs baseados em ClickStream integrados: URLs, hosts, assinantes, dispositivos, recursos de IP<\/li>\r\n \t<li>exporta\u00e7\u00e3o de relat\u00f3rios usando os formatos *.xlsx, .*csv, *.pdf e *.png<\/li>\r\n \t<li>relat\u00f3rios sobre categorias de recursos da web, atualizando a lista de categorias<\/li>\r\n \t<li>relat\u00f3rios completos de NetFlow e ClickStream com informa\u00e7\u00f5es detalhadas por usu\u00e1rio<\/li>\r\n \t<li>configura\u00e7\u00e3o de gatilhos e a\u00e7\u00f5es em eventos, envio de relat\u00f3rios por e-mail<\/li>\r\n \t<li>detec\u00e7\u00e3o de DDoS e BotNet.<\/li>\r\n<\/ul>\r\n\r\n[product id=\u201d108\u2033]","protected":false},"excerpt":{"rendered":"<p>Uma de nossas atualiza\u00e7\u00f5es recentes \u00e9 a integra\u00e7\u00e3o com o Microsoft Active Directory, que \u00e9 \u00fatil para usar o DPI em redes corporativas.<\/p>\n","protected":false},"author":1,"featured_media":3131,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51,55],"tags":[],"class_list":["post-2181","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dpi","category-functionality"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>(English) VASExperts<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/\",\"url\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/\",\"name\":\"[:en]Integration with Microsoft Active Directory for using DPI in corporate networks[:es]Integraci\u00f3n con Microsoft Active Directory para usar DPI en redes corporativas[:fr]Int\u00e9gration avec Microsoft Active Directory pour l'utilisation de DPI dans les r\u00e9seaux d'entreprise[:br]Integra\u00e7\u00e3o com o Microsoft Active Directory para uso de DPI em redes corporativas\",\"isPartOf\":{\"@id\":\"https:\/\/vasexperts.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#primaryimage\"},\"thumbnailUrl\":\"\/wp-content\/uploads\/2019\/10\/corporate-networks-management.jpg\",\"datePublished\":\"2019-10-28T06:16:51+00:00\",\"dateModified\":\"2025-08-11T11:14:08+00:00\",\"author\":{\"@id\":\"https:\/\/vasexperts.com\/#\/schema\/person\/da05c9a6f023e1596cae221d4037bea5\"},\"description\":\"[:en]One of our recent updates is integration with MicroSoft Active Directory which is useful for DPI usage in corporate networks[:es]Una de nuestras actualizaciones recientes es la integraci\u00f3n con MicroSoft Active Directory, que es \u00fatil para el uso de DPI en redes corporativas.[:fr]Une de nos r\u00e9centes mises \u00e0 jour est l'int\u00e9gration avec MicroSoft Active Directory qui est utile pour l'utilisation du DPI dans les r\u00e9seaux d'entreprise[:br]Uma de nossas atualiza\u00e7\u00f5es recentes \u00e9 a integra\u00e7\u00e3o com o Microsoft Active Directory, que \u00e9 \u00fatil para uso de DPI em redes corporativas\",\"breadcrumb\":{\"@id\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#breadcrumb\"},\"inLanguage\":\"br-PT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"br-PT\",\"@id\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#primaryimage\",\"url\":\"\/wp-content\/uploads\/2019\/10\/corporate-networks-management.jpg\",\"contentUrl\":\"\/wp-content\/uploads\/2019\/10\/corporate-networks-management.jpg\",\"width\":1800,\"height\":1201,\"caption\":\"corporate networks management\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\",\"item\":\"https:\/\/vasexperts.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Use of DPI in corporate networks: integration with Microsoft Active Directory\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vasexperts.com\/#website\",\"url\":\"https:\/\/vasexperts.com\/\",\"name\":\"ITGLOBAL.COM\",\"description\":\"(English) VASExperts\",\"inLanguage\":\"br-PT\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/vasexperts.com\/#\/schema\/person\/da05c9a6f023e1596cae221d4037bea5\",\"name\":\"ivan.kuzin\",\"sameAs\":[\"https:\/\/vasexperts-ru.hst11.itglobal.com\"],\"url\":\"https:\/\/vasexperts.com\/br\/blog\/author\/ivan-kuzin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"(English) VASExperts","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/","url":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/","name":"[:en]Integration with Microsoft Active Directory for using DPI in corporate networks[:es]Integraci\u00f3n con Microsoft Active Directory para usar DPI en redes corporativas[:fr]Int\u00e9gration avec Microsoft Active Directory pour l'utilisation de DPI dans les r\u00e9seaux d'entreprise[:br]Integra\u00e7\u00e3o com o Microsoft Active Directory para uso de DPI em redes corporativas","isPartOf":{"@id":"https:\/\/vasexperts.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#primaryimage"},"image":{"@id":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#primaryimage"},"thumbnailUrl":"\/wp-content\/uploads\/2019\/10\/corporate-networks-management.jpg","datePublished":"2019-10-28T06:16:51+00:00","dateModified":"2025-08-11T11:14:08+00:00","author":{"@id":"https:\/\/vasexperts.com\/#\/schema\/person\/da05c9a6f023e1596cae221d4037bea5"},"description":"[:en]One of our recent updates is integration with MicroSoft Active Directory which is useful for DPI usage in corporate networks[:es]Una de nuestras actualizaciones recientes es la integraci\u00f3n con MicroSoft Active Directory, que es \u00fatil para el uso de DPI en redes corporativas.[:fr]Une de nos r\u00e9centes mises \u00e0 jour est l'int\u00e9gration avec MicroSoft Active Directory qui est utile pour l'utilisation du DPI dans les r\u00e9seaux d'entreprise[:br]Uma de nossas atualiza\u00e7\u00f5es recentes \u00e9 a integra\u00e7\u00e3o com o Microsoft Active Directory, que \u00e9 \u00fatil para uso de DPI em redes corporativas","breadcrumb":{"@id":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#breadcrumb"},"inLanguage":"br-PT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/"]}]},{"@type":"ImageObject","inLanguage":"br-PT","@id":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#primaryimage","url":"\/wp-content\/uploads\/2019\/10\/corporate-networks-management.jpg","contentUrl":"\/wp-content\/uploads\/2019\/10\/corporate-networks-management.jpg","width":1800,"height":1201,"caption":"corporate networks management"},{"@type":"BreadcrumbList","@id":"https:\/\/vasexperts.com\/blog\/dpi\/integration-ms-active-directory\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430","item":"https:\/\/vasexperts.com\/"},{"@type":"ListItem","position":2,"name":"Use of DPI in corporate networks: integration with Microsoft Active Directory"}]},{"@type":"WebSite","@id":"https:\/\/vasexperts.com\/#website","url":"https:\/\/vasexperts.com\/","name":"ITGLOBAL.COM","description":"(English) VASExperts","inLanguage":"br-PT"},{"@type":"Person","@id":"https:\/\/vasexperts.com\/#\/schema\/person\/da05c9a6f023e1596cae221d4037bea5","name":"ivan.kuzin","sameAs":["https:\/\/vasexperts-ru.hst11.itglobal.com"],"url":"https:\/\/vasexperts.com\/br\/blog\/author\/ivan-kuzin\/"}]}},"_links":{"self":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts\/2181"}],"collection":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/comments?post=2181"}],"version-history":[{"count":10,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts\/2181\/revisions"}],"predecessor-version":[{"id":12921,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/posts\/2181\/revisions\/12921"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/media\/3131"}],"wp:attachment":[{"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/media?parent=2181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/categories?post=2181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vasexperts.com\/br\/wp-json\/wp\/v2\/tags?post=2181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}