2015-08-26

BIND (named) server remidiation

Since I virtualised my old failing physical server into a VM, I have found it less and less easy to administer and maintain (read: configuration files).

So, I am looking and spinning up new Debian servers for more specific tasks, network services, games servers, file services etc.

The fist, and most important thing I need to migrate is DNS. That way I can have it simply running in parallel with the old, ready to essentially, stop the service (after making sure DHCP serves out this DNS IP address as well of course!).

Now, here comes the "clever" part or the goals of this approach (or so I thought):

  1. Install named.
  2. Configure it to be a slave for the existing zones
  3. re-configure it to be a master (complete with zone files)

Pretty simple right? Not so much. Well, thanks be to the 'Debian' way of doing things, it was very quick and easy to have a the zones slaved, but when I went to look at the files I was expecting, they where still empty, since I had created empty zone files to begin with.

Some poking around later and I discover that it is transferring the zones fine, but there was an issue with permissions for the zone files, or more specifically, the directory where they lived. A quick chmod -R 0777 /zone/file/directory later and a restart of the service, voila! Except.... something was not right...

The zone files seemed to be in a binary format as file would have me believe they were of type: data

I could have converted them back to plain text using the bind-tool named-compilezone(8) but, I couldn't commit my time to learning how to get the syntax correct for one small job, besides I learned that it is a crazy default in order to get a performance increase, however minuscule that would be given such a small DNS server implementation (for now).

So as per the article "Bind 9.9 – Binary DNS Slave file format" (linked above) or more authoratively as per the Chapter 6. BIND 9 Configuration Reference section of the BIND 9.9 Administrator Reference Manual (ARM) which states (incorrectly):

masterfile-format
Specifies the file format of zone files (see the section called “Additional File Formats”). The default value is text, which is the standard textual representation, except for slave zones, in which the default value is raw. Files in other formats than text are typically expected to be generated by the named-compilezone tool, or dumped by named.

So, knowing this I edited /etc/bind/named.conf.options to include the following:

masterfile-format text;

Perfect. (Just like me ;-) I now have a duplicate of the zones served on the master server, which can, and will soon be decommissioned, not to mention the new servers zones getting a makeover with many many more zones as well as a dynamic-update zone - more to come on this soon.

2015-08-05

Great Success

Finally after weeks, no months of agonising failure though trial and error, I finally managed to get the outcome I desired with my Raspberry Pi 2!



History



A few years back I acquired a Cisco 3560 and quickly realised the potential of vlans and separate subnets for the purposes of testing among other valid reasons, and came to find that the nodes on most of the vlans could not communicate with the outside world (read: internet). It was then that I realised that something was wrong...

Long story short: the Netgear DGND4000 that I own does not route/NAT anything other than its resident subnet and I sure as heck was not going to implement double NAT!




Thanks be to LIbVirt's NAT networking which gave me an interim workaround and helped confirm this.


Getting the necessary bits


NAT issues aside, I began by purchasing a second-hand Netgear DM111P v2 from some random guy on Gumtree. The ADSL Modem in itself wasn't enough because it too, seemed to suffer from the same issue as the DGND4000 did, although admittedly, I didn't put much effort into testing that theory as I wanted a solution not more testing.

I then purchased a Raspberry Pi 2 along with a bunch of accessories. In the meantime (while I was waiting the excessively long shipping time). I did some research on the distributions that are capable of running on the bcm2709-based board and decided with OpenWRT. Yes, I know that I could have used Raspbian but OpenWRT seemed the most logical choice given the fact that it is essentially an internet router anyway, just without the wireless and ADSL modem.

Turns out I made the right choice despite the fact that OpenWRT is still in trunk (RC3 at the time of writing this).

Lastly (after destroying the extremely cheap Rpi2 case) I managed to get an image booted (helps when you use the bcm2709 not the bcm2708 barrier breaker version, thats for the Raspberry Model B!).





Configuration


First of all, this would have gone a lot smother had I have just tested with the USB network adapter I bought along with the Pi, but it didn't get here in time with partial shipping.

I configured the switch with a trunk port with two vlans, one for the LAN side of things (internal link) and another for the WAN or pppoe (public/external/internets) and set the mode appropriately.

NOTE: VLANS and IP addresses have been altered so as to protect the actual configuration used in my network infrastructure. Call me paranoid.


Cisco 3650 partial configuration


!
vlan 20
vlan 69
!
interface Vlan69
 description DMZ/LAN
 ip address 192.168.69.1 255.255.255.248
 no shutdown
!
! no interface defined for WAN because we do not want any L3 traffic
!

interface GigabitEthernet0/2
 description Trunk port for Rpi2 VLAN's: 20, 69
 switchport access vlan 69
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 20,69
 switchport mode trunk
 no shutdown
!
interface GigabitEthernet0/1
 description Link to DM111Pv2 modem (bridged) for PPPoE/L2 traffic
 switchport access vlan 20
 no shutdown
exit
!
ip route 0.0.0.0 0.0.0.0 192.168.69.66
!
end


OpenWRT network configuration


root@OpenWRT# vi /etc/config/network

config interface 'loopback'
        option ifname 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config interface 'lan'
        option proto 'static'
        option delegate '0'
        option _orig_ifname 'eth0'
        option _orig_bridge 'false'
        option ifname 'eth0.69'
        option ipaddr '192.168.69.66'
        option netmask '255.255.255.248'

config route
        option interface 'lan'
        option target '192.168.0.0'
        option netmask '255.255.0.0'
        option gateway '192.168.69.1'

config interface 'WAN'
        option proto 'pppoe'
        option ifname 'eth0.20'
        option delegate '0'
        option username 'myusername'
        option password 'mY$eCr3tP4sSw0rD'


Caveats/Adendums/Extra information


By now you may be wondering, "Why is there no IP addresses or switch virtual interface for vlan 20"? There is no need for it! That, and the fact one might only want traffic to go via one vlan and then the other (remember, this is essentially a router on a stick implementation and we want to separate the vlan's into L3 traffic for one and L2 for the other per requirements).

If you were thinking: "The netmask and destination network IP for the LAN route is wrong!", you would be incorrect. This is a perfectly legitimate summary route. It allows for much easier (read: slack) administration so one does not have to manage multiple static routes for subnets added or removed from the network (short of running a routing protocol) and it has the added benefit of consuming less memory and is a much more flexible approach for this design. Neat huh? I thought so too :-)


Conclusion


Let it be said that although this configuration is very simple, there where many hurdles accompanied by many choice words along the way. The one single most important thing that I kept getting wrong was routing. I had to remember to change the 'gateway of last resort' (Cisco's way of saying default route) on the switch so that all the subnets will route to the internet and the static (summarised) route for traffic to get back into the network from whence they came. That and trying to test this when the internet is depended upon so much by the two people in this household, was frustrating as my change windows where often short and had to be rolled back constantly.

Lastly, I must say that "out-of-the-box" pppoe/nat/routing on OpenWRT worked with like a charm with minimal configuration, however I will need to develop the scenario a little further so I can secure the connection by way of its firewall (read: iptables), but that itself is a beast I have yet to conquer.


2015-08-04

Rasbpberri Pi Internet Connectivity Lab

I have successfully built a lab for testing internet connectivity to the Raspberry Pi 2, by using my phone in a USB tethering configuration.

I followed the majority of the configuration listed in the OpenWRT wiki, except I used the LuCI web configuration instead of the final manual step of using uci to use usb0 as the WAN connection

This will now allow me to test various scenarios including multiple default routes with different metrics as well as testing firewall configurations using OpenWRT running on the Rpi2.

The one gotcha is that I forgot to set the rout back to the internal network for which was previously miss-configured.

I am getting one step closer to having much more control of my internet as well as being able to NET/Route all of my subnets!

2015-07-25

failure to focus

I have confirmed that I can get the Raspberry Pi to connect to the ISP using PPPoE through a VLAN, however, I cannot (or rather my brain cannot) get the OpenWrt to accept traffic other then ICMP to/from the device itself (I probably need to understand iptables or I am overlooking something very simple).

I'm finding it extremely hard to focus and get the networking part of this lab working right now when I don't actually have a lab to do it on and when others in the household rely on internet so much including myself, when I need to refer to something while trying to troubleshoot and find a solution to this 'router-on-a-stick' model of networking to overcome the shortfall of the existing router.

I've also lost my 4Gb micro SD for which I was planning using for building a Bluetooth (A2DP) Audio receiver from the Raspberri Pi which is making me a little less than happy considering they are not as easy to come by due to the size and I will have to spend another $10 (effectively $20 now) in order to get one.

For now, I'm going to go watch something and try again later (including looking for the SD card).

2011-11-20

Google Plus killed the technology blog

This may be the final entry in this and my other blogs.

I managed to painstakingly avoid using Facebook for many years, and instead waited patiently for Google to create it's social networking site, Google Plus (If you have never heard of Google+, I strongly urge you to go back to the rock you have so obviously been living under and/or go read some other non-technical site).

Ever since I have been active on Google+ (since soon after it's initial Beta period), have found it to be absolutely brilliant, if not addictive, and a far better medium to which I can expose my technical knowledge and findings to the masses.

This means that there is little or no time for the blog and I am almost positively confident of using one or more Google+ page(s) to replace this and most probably all of my other blogs.

Thank you Blogger for your great blogging service, but thank you so much more Google plus for finally giveing me what I (and so many other Google fans) wanted.

2011-03-10

mirgating to libata

Since IDE/MFM/RLL is now depreciated, I thought I'd share my experiences of migrating to the newer libsata (SATA prod) drivers in 2.6 kernel.

Since I only have 2 devices on IDE ports (WD 320Gb HDD and a cdrw), there was very little for me to do as I had just about everything spread across both ata and libsata, so I removed all instances of ata, set built-in ATA driver support (since the system boots from IDE - for now) under libsata and enabled what I needed as modules for my SATA JBOD's

The whole thing almost went perfectly as planned (and as documented), except for the following minor irritations:

  1. Forgot to change the real_root option in grub.conf from /dev/hda3 to /dev/sda3 :-P
  2. udev was naming my cdrom to cdrw1/cdrom1

Admittedly, it took my a while figure out that I forgot to change the bootloader for the change in device names, but I quickly worked out how to change the cdrom device name back to default, by editing "/etc/udev/rules.d/70-persistent-cd.rules"

2010-07-13

Xbox 1 savegames on XBOX 360

Since discovered that Burnout 3 and other Xbox 1 titles are now available through XBOX Live! games on demand, I decided to do away with disc swapping and focus my attention on purchasing games for XBOX360 and Xbox Originals online through Live!

Then it dawned on me... What about all the long and painful hours I dedicated to all those Xbox 1 Originals? Do I have to play them all over again including unlocking everything and developing perfect saves etc?

The short answer (more or less from Microsoft) is: No

The Long(er) answer is: Yes, but only with specific hardware, software and some patience (as well as unsigned savegames).


Quite a bit of research later, I discovered that it is theoretically possible as the XBOX 360 has a directory on it's HDD (Partition 3/Compatibility/Xbox1/UDATA to be precise). Besides, how else would it save normally backwards compatible game data?

So after I borrowing a Datel XPort 360 HDD adapter from an awesome friend, I was able to connect the XBOX 360 HDD onto my PC, and read (and also write to) the HDD contents within minutes, all I needed was Xport 360 Software

Next up I deleted my Halo save that I created on the XBOX360 HDD and dragged the Xbox Original savegame folder (ID: 4d530004) onto the XBOX 360 HDD disconnected it and it worked!

I then repeated this with Burnout 3 and tested it, but it failed to load save and shows Unusable in the in-game load menu for the savegam(e). Apparently this is because the savegame(s) are signed with HDD key so it will probably never work for this game *sob*

I decided to proceed with copying all my Xbox Original save games (or at least he ones I care about anyway) onto the XBOX 360 HDD, so I will update this post if and when I have the Games available to test.

2010-06-03

isp faithfulness

I just discovered today that I was being charged by my ISP for a broadband account in a place I used to live in...

I applied for broadband back in 2006 when I was living in Sorrento, but broadband was not available in that area until about 6 months after I left that suburb and cancelled my dial-up. My ISP has been charging me for it ever since!

Luckily for me, my ISP not only cancelled the old unused account, but have also refunded the last 6 months. At least my ISP seems to reward faithful customers...

2009-11-25

xbox360 and WMP11 fail

After about two years of procrastination, I finally got an xbox360 to fulfil my Burnout gaming needs. Before I got the (MW2) bundle, I installed Windows Media Player 11 (using the validation bypass trick). Now sitting here relieved that I finally got media sharing to work, I thought I'd blog about the one simple thing wrong with media sharing:

  1. UNC network paths.
It took almost 2 weeks to find an answer to why my library was not showing up on the xbox360 and the answer lies here.

In summary (for those that don't want to follow that URL for some reason):

"If you want to share files that are not located locally on your machine, Microsoft has chosen to prevent you from sharing content located on network locations (UNC paths) like \\MACHINENAME\sharename"

Luckilly there is an undocumented registry "hack" that will fix this:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Preferences\HME]
“EnableRemoteContentSharing”=dword:00000001

Huge thanks go out to GibStorm for documenting this so well...

2009-08-21

vim + gnupg = password manager

After finding that there are very little native password managers for linux, I decided to see if I could find a way to open my encrypted password file using a console-based editor without putting any plain text onto the disk at all (ie. transparent editing of gnupg encrypted files).

I stumbled onto the vim website (by way a Google search) and found a nice little script (plugin) that does all this for me!

Initially, I had some issues with getting it working but that was mainly due to exporting $GPG_TTY incorrectly :-P

However, as I use screen to manage everthing I do from the one terminal window/ssh session (vim incuded), the plugin works fine but fails to decrypt files when vim is invoked as a new screen.

I suspect that it's attributed to the $GPG_TTY variable, but my knowledge of screen and some other aspects of Linux are limited.

I now use vim + gnupg for my encrypted password file.


UPDATE 21/08/2009 @ 13:15
There seems to be an issue where the the GPG_TTY variable needs to re-exported every time you change to a another screen/pts. I have made myself a workaround, whereby I run a simple script that first exports the variable and then opens vim with the encrypted pwd file, but then vim removes the standard UDLR keybord controlls and falls back to classic vi mode. *sigh*

2009-08-12

iPhone battery fail

My iPhone 3GS seems to be working well but with one small problem. Battery life sux.

The stupid thing lasts anywhere from about ½ a day to about about 1 day, which doesn't seem right at all.

I had also already jailbroken the the thing within the first few weeks of owning it, but since the latest firmware (3.0.1) came out recently, I thought I would update it in the hopes that Apple had silently fixed a possible power issue and to remove any jailbreak packages that could be causing this problem. No luck here folks.

About a week later I discovered that the phone was constantly emitting RF as a cheap set of speakers that I had turned on, would pick up the RF as interference and damn was this phone was being noisy!

After calling the Virgin Mobile iPhone hotline to get some support (which still didn't help mind), I stumbled onto apple's own iPhone battery information page and went through the troubleshooting steps, I seemed to have found the answer! Push mode notification. Turning it off has quietened it and the battery bar has stopped draining quicker than a cold beer in summer.

I am happy the problem is fixed and the battery is still in reasonably good condition, but this begs the question: Why is it on by default?

2009-07-31

10th Annual System Administrator Appreciation Day

Today marks the 10th Annual System Administrator Appreciation Day.

Treat some lonely, unforgiven and/or unloved sysadmin with a gift and/or note of appreciation today and show how much you appreciate the hard work and effort that they do (myself included).

They are usually the same people that make your internets work! so show us some love. Please.





Happy Sysadmin Day!

/respect

2009-07-11

silence isn't golden

Not only did the internal speaker in my my old Nokia 6610i fail not long after I got it, but so too did my Openmoko Neo Freerunner (GTA-02v5) (or so it would seem)!

*Grrr*

I was testing someone else's microphone+earphone's hands-free kit on the 'moko earlier on in the day, which didn't seem to phase the device as it simply didn't work, but after putting my phone on silent a few hours later, the 'moko now has no audio output except from the headphone jack!?!

After re-installing koolu's Android (v1.0_beta7), the thing still refuses to output audio to anything but the external headphone jack and I suspect that it's either the switch pins inside the female jack are stuck or the internal speaker has broken. I am yet to boot it with 0m2008.12 via uSDHC to confirm that it's a hardware fault.

The 'moko certainly has been a very interesting device to toy around with, but it has proved to be quite troublesome, making me want an iPhone 3Gs. If I can't get the audio issue sorted out soon, I will most likely get one. Problem is trying to buy one outright as I fear that no providers will because they all seem to list plans, but fail to give full price or outright purchase details *sigh*.

UPDATE 13/07/2009 @ 15:12
The 'moko now intermittently rings, but the microphone is still muted making calls impossible.


UPDATE 14/07/2009 @ 12:38
I found out from a scumb^H^H^H^H^Hcustomer service person @ Allphones, that Apple are not allowing retailers and telcos to sell the iPhone outright because it's apparently not cost-effective for them to do so.

Lucky for me, I have a friend who is willing to sell me his 16Gb 3G one for the cost of his 3G-s upgrade.


UPDATE 21/07/2009 @ 09:42
I found the link to the Australian Apple store online and I will be using half of my tax return on buying an iPhone. *sniff* Good bye 'moko... You have served me... err... not so well... :P

2009-03-10

internets anew

Thanks to this article I was able to transform my crappy dg632 router into a dumb modem so that I could get better control (including better security) on my internet link.

The only problems I encountered was that I found it difficult to set the router into bridged mode, but finally found the answer here. The documentation on the gentoo wiki differed slightly too, in that the iptables exported variable for the WAN interface should be ppp0 instead of eth1.

Other than that I can now enjoy a properly firewalled, dyndns capable and port-forwarding capable setup at no extra cost.

Now all I need to do is get bind, ldap and openvpn working... having all this free time without a job does have it's benefits...

2009-02-17

kde4

KDE4 finally hit stable in gentoo's portage! *woohoo!* (as of about a month ago :P)

I had to wait a few weeks so that package blocks got sorted out in portage (well, at least now there is only 2 rather than the 4 from last week), which just goes to show that immediately trying to update to anything isn't always a good idea! :P

so now the dell xps is chugging away at building all the kde packages and dependencies (as well as updates from about 4 weeks ago) etc etc and hopefully when I wake up tomorrow I will be greeted with a shiny slick new KDM :)

I really should be updating my diary-blog but I wanted to keep a record of the fact that I have figured out that waiting for sane dependency handling by portage updates is a good thing!

2008-11-29

moar storage

I acquired two more 1Tb HDD's effectively making my current total storage space about 4Tb.

I want to software raid my 1Tb disks, but I need a silent UPS before I can (this system sits in my room, so I don't it waking me or anyone else if the power drops during the night), so my server is going to have to stay JBOD for now *sigh*

I am also contemplating putting Vista (x64) onto my lappy to make it easier for work, but I can't bear to loose my Gentoo/KDE after all the hard work that I have done in getting it functional.

I need to make some hard decisions here...

Also, I will hopefully get around to implementing IPTABLES + bridged mode modem + pppoe on my fileserver soon :)

2008-11-19

Be afraid. Be VERY afraid

Thanks to Senator Conroy, Australia may have to suffer not only internet censorship but very slow internet speeds, due to an old yet unfeasable policy that the government seems determined to force into our homes (and probably businesses too).

I now direct you to http://nocleanfeed.com/ which explains (better than I can at least) what this is, how it affects you and most importantly, what you can do to help prevent it.

No Clean Feed - Stop Internet Censorship in Australia

2008-10-28

OPENMOKO

I have finally been able to purchase a neo freerunner from openmoko!

Due to the current market, the Australian dollar is really low compared to the US Dollar (1 USD = 1.62063 AUD). But I needed a phone real bad and I really, really really wanted this one because of it 99% open (as in open source) nature.

I'm preparing for the arrival of it by purchasing a 16Gb microSDHC card (as well as the fact that I have dfu-util installed from a gentoo overlay from some time ago).

I'm considering putting Debian onto an SD card for uBoot... maybe a little too nerdy but hey, I didn't buy this thing as a fashion accessory :P


UPDATE 13/11/2008 @ 16:01
Today I discovered a nifty hardware feature. The hone can operate without it's battery as long as it's plugged in via it's USB cable!!! See here

Also, I managed to get host USB working the other day too.

Due to the available distributions it's very hard to find one and stick with it as some have feature and/or bugs that other do/don't have. FDOM sounds like it's for me though.

There is nothing this phone can't do (that which I need it to) :D

2008-09-06

bubs is dead

My server (named bubs after the homestarruner character of the same name) died today after a power spike/power outage.

I'm not sure if bubs actually caused the outage, but one thing is for sure: It ain't turning back on.

My initial thoughts are that the power supply was damaged in the surge, but until I can get a reliable unit to test it with, I won't know for sure.

I have an old PSU from a PII computer but I doubt that will work on an amd64-based motherboard.

I just prey that the motherboard is ok becase it's going to get expensive to rebuild with new parts...

Might need to overnight some parts (or at lease a PSU)...


UPDATE 06/09/2008 @ 14:36
Bubs is back online!
Seems that all I should have done is removed it from power for a few minutes, toggle the (PSU) switch, apply power and hit the machines power button.

Also a quick test proved that an old PII/PIII ATX PSU is capable of powering an ASUS A8V board. Who would have thought :P

2008-08-28

Home Network Redesign

I think I may have the motivation to redesign my network for the following reasons:


  • Increased Security: Better Firewall solution
  • Increased Security: Segmented network design, allowing for More control with untrusted hosts such as:

    • internet (DMZ)
    • Wireless and
    • temp hosts (ie. LAN party ^_^).

  • Manageability: Implementing a secure routing protocol (RIP? maybe) may assist with network growth/changes
  • Gloating: Show off my 1337 net skillz to my friends :P


The most important aspect of this is the first point (increased security). It should also allow me to easily create a vpn endpoint onto my server for remote access (from outside the network) and for internet access from the wireless network... *hmmm* radius anyone?

This should help me un-lazy myself and develop (internal) dns zone(s) too...

Hopefully I can have the design done and implemented by the end of next UNI break!

 
Google+