将物理设备审核与 Azure Stack Hub 数据中心集成Integrate physical device auditing with your Azure Stack Hub datacenter

Azure Stack Hub 中的所有物理设备(例如基板管理控制器 (BMC) 和网络交换机)都会发出审核日志。All physical devices in Azure Stack Hub, like the baseboard management controllers (BMCs) and network switches, emit audit logs. 可以将审核日志集成到整体审核解决方案中。You can integrate the audit logs into your overall auditing solution. 由于设备因不同的 Azure Stack Hub OEM 硬件供应商而异,所以请联系你的供应商来获取有关审核集成的文档。Since the devices vary across the different Azure Stack Hub OEM hardware vendors, contact your vendor for the documentation on auditing integration. 以下各部分提供了有关 Azure Stack Hub 中的物理设备审核的一些常规信息。The sections below provide some general information for physical device auditing in Azure Stack Hub.

物理设备访问审核Physical device access auditing

Azure Stack Hub 中的所有物理设备都支持使用 TACACS 或 RADIUS。All physical devices in Azure Stack Hub support the use of TACACS or RADIUS. 支持包括访问基板管理控制器 (BMC) 和网络交换机。Support includes access to the baseboard management controller (BMC) and network switches.

Azure Stack Hub 解决方案在推出时并未内置 RADIUS 或 TACACS。Azure Stack Hub solutions don't ship with either RADIUS or TACACS built-in. 但是,经验证,这些解决方案支持使用市面上现有的 RADIUS 或 TACACS 解决方案。However, the solutions have been validated to support the use of existing RADIUS or TACACS solutions available in the market.

对于 RADIUS,只有 MSCHAPv2 经过了验证。For RADIUS only, MSCHAPv2 was validated. 它代表使用 RADIUS 的最安全实现。This represents the most secure implementation using RADIUS. 请咨询 OEM 硬件供应商,在 Azure Stack Hub 解决方案包含的设备中启用 TACAS 或 RADIUS。Consult with your OEM hardware vendor to enable TACAS or RADIUS in the devices included with your Azure Stack Hub solution.

网络设备的 Syslog 转发Syslog forwarding for network devices

Azure Stack Hub 中的所有物理网络设备都支持 syslog 消息。All physical networking devices in Azure Stack Hub support syslog messages. Azure Stack Hub 解决方案未随 syslog 服务器一起提供。Azure Stack Hub solutions don't ship with a syslog server. 但是,经验证,这些设备支持将消息发送到市面上现有的 syslog 解决方案。However, the devices have been validated to support sending messages to existing syslog solutions available in the market.

Syslog 目标地址是针对部署所收集的可选参数,但也可以在部署后添加此参数。The syslog destination address is an optional parameter collected for deployment, but it can also be added post deployment. 要在网络设备上配置 syslog 转发,请咨询你的 OEM 硬件供应商。Consult with your OEM hardware vendor to configure syslog forwarding on your networking devices.

后续步骤Next steps

服务策略Servicing policy