π₯οΈ Domain Controller - FSociety.pt
Servidor Central de Identidade e AutenticaΓ§Γ£o
DocumentaΓ§Γ£o completa do Domain Controller da infraestrutura FSociety.pt, incluindo Samba AD DC, DNS, DHCP, Kerberos, FreeRADIUS e CrowdSec.
| Campo |
Valor |
| Hostname |
dc.fsociety.pt |
| EndereΓ§o IP |
192.168.1.10 |
| Sistema Operativo |
Ubuntu 24.04.3 LTS (Noble Numbat) |
| Kernel |
6.8.0-88-generic |
| VirtualizaΓ§Γ£o |
KVM (Proxmox VE) |
| RAM |
1.4 GB |
| Disco |
24 GB |
| Zona de Rede |
LAN (192.168.1.0/24) |
ποΈ Arquitetura de ServiΓ§os
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β dc.fsociety.pt (192.168.1.10) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ β
β β SAMBA AD β β DNS β β DHCP β β
β β DC β β (Integrado) β β Server β β
β β β β β β β β
β β β’ LDAP β β β’ Zonas AD β β β’ Pool IPs β β
β β β’ Kerberos β β β’ PTR β β β’ Reservas β β
β β β’ GPO β β β’ SRV β β β’ Options β β
β ββββββββ¬βββββββ ββββββββ¬βββββββ βββββββββββββββ β
β β β β
β βΌ βΌ β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β AUTENTICAΓΓO CENTRALIZADA β β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ€ β
β β β β
β β βββββββββββββ βββββββββββββ βββββββββββββ β β
β β β Kerberos β β LDAP β β RADIUS β β β
β β β (KDC) β β (389/636)β β(1812/1813)β β β
β β βββββββββββββ βββββββββββββ βββββββββββββ β β
β β β β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ β
β β CrowdSec β β Shares β β Netdata β β
β β IDS β β SMB β β Monitoring β β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ β
β β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
π Γndice da DocumentaΓ§Γ£o
π ServiΓ§os e Portas
| Porta |
Protocolo |
ServiΓ§o |
DescriΓ§Γ£o |
| 53 |
TCP/UDP |
DNS |
ResoluΓ§Γ£o de nomes (Samba interno) |
| 67 |
UDP |
DHCP |
AtribuiΓ§Γ£o dinΓ’mica de IPs |
| 88 |
TCP/UDP |
Kerberos |
AutenticaΓ§Γ£o de tickets |
| 135 |
TCP |
RPC |
Remote Procedure Call |
| 137-138 |
UDP |
NetBIOS |
ServiΓ§o de nomes NetBIOS |
| 139 |
TCP |
NetBIOS |
SessΓ΅es NetBIOS |
| 389 |
TCP/UDP |
LDAP |
DirectΓ³rio nΓ£o cifrado |
| 445 |
TCP |
SMB |
Partilhas de ficheiros |
| 464 |
TCP/UDP |
Kpasswd |
AlteraΓ§Γ£o de passwords Kerberos |
| 636 |
TCP |
LDAPS |
DirectΓ³rio cifrado (TLS) |
| 1812 |
UDP |
RADIUS Auth |
AutenticaΓ§Γ£o RADIUS |
| 1813 |
UDP |
RADIUS Acct |
Accounting RADIUS |
| 3268 |
TCP |
Global Catalog |
CatΓ‘logo global LDAP |
| 3269 |
TCP |
Global Catalog SSL |
CatΓ‘logo global LDAPS |
π IntegraΓ§Γ΅es
O Domain Controller integra-se com todos os serviΓ§os da infraestrutura:
βββββββββββββββββββ
β dc.fsociety.pt β
β 192.168.1.10 β
ββββββββββ¬βββββββββ
β
βββββββββββββββββββββββββββΌββββββββββββββββββββββββββ
β β β
βΌ βΌ βΌ
βββββββββββββββββ βββββββββββββββββ βββββββββββββββββ
β Mailcow β β Nextcloud β β pfSense β
β (LDAP Auth) β β (LDAP Auth) β β (RADIUS/VPN) β
β 10.0.0.40 β β 192.168.1.40 β β 192.168.1.1 β
βββββββββββββββββ βββββββββββββββββ βββββββββββββββββ
| ServiΓ§o |
Tipo de IntegraΓ§Γ£o |
Porta Utilizada |
| Mailcow |
LDAP (autenticaΓ§Γ£o email) |
636 (LDAPS) |
| Nextcloud |
LDAP (utilizadores/grupos) |
636 (LDAPS) |
| pfSense OpenVPN |
RADIUS β LDAP |
1812 |
| EstaΓ§Γ΅es Windows |
Domain Join |
389, 445, 88 |
π₯ Estrutura Organizacional (AD)
Organizational Units (OUs)
DC=fsociety,DC=pt
βββ OU=FSociety
β βββ OU=TI
β βββ OU=RH
β βββ OU=Comercial
β βββ OU=Financeiro
β βββ OU=Grupos
β βββ OU=Computadores
βββ OU=Service Accounts
βββ OU=Domain Controllers
βββ CN=Users (built-in)
Grupos de SeguranΓ§a
| Grupo |
FunΓ§Γ£o |
Membros |
| GRP_TI |
Departamento TI |
Administradores de sistemas |
| GRP_RH |
Recursos Humanos |
Equipa de RH |
| GRP_Comercial |
Departamento Comercial |
Equipa de vendas |
| GRP_Financeiro |
Departamento Financeiro |
Contabilidade |
| GRP_Gestores |
GestΓ£o |
Diretores e gestores |
| GRP_VPN_Users |
Acesso VPN |
Utilizadores com acesso remoto |
π MΓ©tricas de SeguranΓ§a (CrowdSec)
| MΓ©trica |
Valor |
| VersΓ£o CrowdSec |
v1.7.3 |
| Bouncer Ativo |
cs-firewall-bouncer v0.0.34 |
| IPs na Blocklist (CAPI) |
16.19k |
| Collections Ativas |
linux, mysql, postfix, smb, sshd |
| Campo |
InformaΓ§Γ£o |
| InstituiΓ§Γ£o |
ESTG - Instituto PolitΓ©cnico do Porto |
| Unidade Curricular |
AdministraΓ§Γ£o de Sistemas II |
| Ano Letivo |
2025/2026 |
| Autores |
Ryan Barbosa, Hugo Correia, Igor AraΓΊjo |
π LicenΓ§a
Este projeto estΓ‘ licenciado sob a MIT License.
**[β¬
οΈ Voltar Γ DocumentaΓ§Γ£o Principal](/fsociety-infrastructure/)** | **[PrΓ³ximo: InstalaΓ§Γ£o Ubuntu β‘οΈ](/fsociety-infrastructure/04-domain-controller/01-instalacao-ubuntu.html)**
Γltima atualizaΓ§Γ£o: Dezembro 2025