Networking-Blog

My WordPress Blog

LINUX Add Dummy0 Interface

/etc/modprobe.conf (insert last 2 lines)

alias scsi_hostadapter mptbase
alias scsi_hostadapter1 mptspi
alias scsi_hostadapter2 ata_piix
alias eth0 pcnet32
alias eth1 pcnet32
alias dummy0 dummy
options dummy numdummies=1
!
!
info :

eth0 is core
eth1 transit

Preload the dummy network driver on the machine. If this command is successful,
you do not receive any messages from the server
:

modprobe -a dummy

Find the last address in the last usable network range.

/etc/sysconfig/network-scripts/ifcfg-dummy0

DEVICE=dummy0
BOOTPROTO=static
ONBOOT=yes
IPADDR
NETMASK=255.255.0.0


Before we bring up dummy interface. Need to
:

rmmod dummy =  removes dummy modules
modprobe dummy =  re-creates the dummy modules
ifup dummy0 =  bring up dummy0

LINUX GENTOO ADD DUMMY INTERFACE

# /etc/conf.d/net
config_dummy0=(‘10.1.2.100 netmask 255.255.255.255 broadcast 10.1.2.100’)

!

I actually added both forwarded ip addresses and make the dummy interface start up by default

cd /etc/init.d
ln -s net.lo net.dummy0
rc-update add net.dummy0 default

/etc/init.d/dummy0 start

!

I added this to my /etc/sysctl.conf
net.ipv4.conf.all.arp_ignore=1
net.ipv4.conf.eth0.arp_ignore=1
net.ipv4.conf.all.arp_announce=2
net.ipv4.conf.eth0.arp_announce=2

Then refresh the sysctl settings:
sysctl -p

!

Bring up interface :

/etc/init.d/net.dummy0 stop
/etc/init.d/net.dummy0 start

Linux TCP Tuning

To change TCP settings in Linux, add the entries below to the file /etc/sysctl.conf, and then run sysctl -p. The system will also set these values at boot time.

# increase TCP maximum buffer size
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216

# increase Linux autotuning TCP buffer limits
# min, default, and maximum number of bytes to use
net.ipv4.tcp_rmem = 4096 87380 16777216
net.ipv4.tcp_wmem = 4096 65536 16777216

Set the maximum buffer sizes to a value large enough to handle the longest, fastest network link you think that host will encounter (16MB in the example above). Windows does not require any modifications, as the default maximum TCP buffer size (GlobalMaxTcpWindowSize) is not defined. My TCP Tuning Guide web site has information on how to set the maximum buffer size for other OSes.

Tuning TCP for Linux 2.4 and 2.6

NB: Manually adjusting socket buffer sizes with setsockopt() disables autotuning. Application that are optimized for other operating systems may implicitly defeat Linux autotuning.

The following values (which are the defaults for 2.6.17 with more than 1 GByte of memory) would be reasonable for all paths with a 4MB BDP or smaller (you must be root):

	echo 1 > /proc/sys/net/ipv4/tcp_moderate_rcvbuf
       	echo 108544 > /proc/sys/net/core/wmem_max
       	echo 108544 > /proc/sys/net/core/rmem_max
       	echo "4096 87380 4194304" > /proc/sys/net/ipv4/tcp_rmem
       	echo "4096 16384 4194304" > /proc/sys/net/ipv4/tcp_wmem

    
All standard advanced TCP features are on by default. You can check them by: cat /proc/sys/net/ipv4/tcp_timestamps cat /proc/sys/net/ipv4/tcp_window_scaling cat /proc/sys/net/ipv4/tcp_sack Linux supports both /proc and sysctl (using alternate forms of the variable names) Eg. net.core.rmem_max) for inspecting and adjusting network tuning parameters. The following is a useful shortcut for inspecting all tcp parameters: sysctl -a | fgrep tcp To detect network errors and signaling connection problems, You can enable TCP keep alive feature. It will increase signaling bandwidth used, but as bandwidth utilized by signaling channels is low from its nature,the increase should not be significant.Moreover, you can control it using keep alive timeout. The problem is that most system use keep alive timeout of 7200 seconds, which means the system is notified about a dead connection after 2 hours. You probably want this time to be shorter, like one minute or so. On each operating system, the adjustment is done in a different way. After settings all parameters, it's recommended to check whether the feature works correctly - just make a test call and unplug a network cable at either side of the call. Then see if the call terminates after the configured timeout. Here are some hints: Linux systems: Use sysctl -A to get a list of available kernel variables and grep this list for net.ipv4 settings (sysctl -A | grep net.ipv4). There should exist the following variables: - net.ipv4.tcp_keepalive_time - time of connection inactivity after which The first keep alive request is sent - net.ipv4.tcp_keepalive_probes - number of keep alive requests retransmitted before the connection is considered broken - net.ipv4.tcp_keepalive_intvl - time interval between keep alive probes You can manipulate with these settings using the following command: sysctl -w net.ipv4.tcp_keepalive_time=60 net.ipv4.tcp_keepalive_probes=3 net.ipv4.tcp_keepalive_intvl=10 This sample command changes TCP keepalive timeout to 60 seconds with 3 probes, 10 seconds gap between each. With this, your application will detect dead TCP connections after 90 seconds (60 + 10 + 10 + 10).
You can decrease the net.ipv4.netfilter.ip_conntrack_tcp_timeout_established, by half, at least. You can decrease also the following. net.ipv4.netfilter.ip_conntrack_tcp_max_retrans = 3 net.ipv4.netfilter.ip_conntrack_tcp_be_liberal = 0 net.ipv4.netfilter.ip_conntrack_tcp_loose = 1 net.ipv4.netfilter.ip_conntrack_tcp_timeout_max_retrans = 300 net.ipv4.netfilter.ip_conntrack_tcp_timeout_close = 10 net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 120 net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack = 30 net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 60 net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 120 net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 14400 net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv = 60 net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent = 120 sysctl -w net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=14400 (14400 = 4hours)

Linux Iptables Output Chain

sudo iptables -I smtp_out 1 -p tcp -s 10.11.254.250 -d 0.0.0.0/0 –dport 25 -j ACCEPT
sudo iptables -I smtp_out 2 -p tcp -s 10.11.254.251 -d 0.0.0.0/0 –dport 25 -j ACCEPT
sudo iptables -I smtp_out 4 -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 –dport 25 -j LOG
sudo iptables -I smtp_out 4 -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 –dport 25 -j DROP

The below statement will log all deny traffic which needs to be entered before the deny statement.

sudo iptables -I smtp_out 4 -p tcp -s 0.0.0.0/0 -d 0.0.0.0/0 –dport 25 -j LOG

Run this command to see log messages:

sudo cat /var/log/messages | grep DST=25
sudo cat /var/log/messages | grep 217.154.157.250

Linux Password File Conf

nano /etc/passwd

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/bin/sh
bin:x:2:2:bin:/bin:/bin/sh
sys:x:3:3:sys:/dev:/bin/sh
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/bin/sh
man:x:6:12:man:/var/cache/man:/bin/sh
lp:x:7:7:lp:/var/spool/lpd:/bin/sh
mail:x:8:8:mail:/var/mail:/bin/sh
news:x:9:9:news:/var/spool/news:/bin/sh
uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
proxy:x:13:13:proxy:/bin:/bin/sh
www-data:x:33:33:www-data:/var/www:/bin/sh
backup:x:34:34:backup:/var/backups:/bin/sh
list:x:38:38:Mailing List Manager:/var/list:/bin/sh
irc:x:39:39:ircd:/var/run/ircd:/bin/sh
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
libuuid:x:100:101::/var/lib/libuuid:/bin/sh
syslog:x:101:102::/home/syslog:/bin/false
messagebus:x:102:106::/var/run/dbus:/bin/false
hplip:x:103:7:HPLIP system user,,,:/var/run/hplip:/bin/false
avahi-autoipd:x:104:110:Avahi autoip daemon,,,:/var/lib/avahi-autoipd:/bin/false
avahi:x:105:111:Avahi mDNS daemon,,,:/var/run/avahi-daemon:/bin/false
couchdb:x:106:113:CouchDB Administrator,,,:/var/lib/couchdb:/bin/bash
haldaemon:x:107:114:Hardware abstraction layer,,,:/var/run/hald:/bin/false
speech-dispatcher:x:108:29:Speech Dispatcher,,,:/var/run/speech-dispatcher:/bin/sh
kernoops:x:109:65534:Kernel Oops Tracking Daemon,,,:/:/bin/false
saned:x:110:116::/home/saned:/bin/false
pulse:x:111:117:PulseAudio daemon,,,:/var/run/pulse:/bin/false
gdm:x:112:119:Gnome Display Manager:/var/lib/gdm:/bin/false
salman:x:1000:1000:Ash Salman,,,:/home/salman:/bin/bash
xrdp:x:113:121::/var/run/xrdp:/bin/false
sshd:x:114:65534::/var/run/sshd:/usr/sbin/nologin
asalman:x:116:65534::/media/Multimedia/Multimedia:/bin/bash
ftp:x:116:65534::/media/Multimedia/Multimedia:/bin/bash

Linux Samba Share Conf

smbpasswd -a asalman
passwd
nano /etc/samba/smb.conf

[Media]
path = /media/Multimedia/Multimedia
interfaces = lo eth0
bind interfaces only = true
security = share
guest account = nobody
invalid users = root
browseable = yes
read only = no
guest ok = yes
valid users = salman asalman
hosts allow = 127.0.0.1 192.168.2.4 192.168.4.0/28

[Downloads]
path = /media/Multimedia/Downloads
interfaces = lo eth0
bind interfaces only = true
security = share
guest account = nobody
invalid users = root
browseable = yes
read only = no
guest ok = yes
valid users = salman asalman
hosts allow = 127.0.0.1 192.168.2.4 192.168.4.0/28

[Pictures]
path = /media/BackupDrive/FamilyPictures
interfaces = lo eth0
bind interfaces only = true
security = share
guest account = nobody
invalid users = root
browseable = yes
read only = yes
guest ok = yes
valid users = salman asalman

[Share]
path = /media/BackupDrive/Share
interfaces = lo eth0
bind interfaces only = true
security = share
guest account = nobody
invalid users = root
browseable = yes
read only = no
guest ok = yes
valid users = salman asalman
hosts allow = 127.0.0.1 192.168.2.4 192.168.4.0/28

[Games]
path = /media/BackupDrive/Games
interfaces = lo eth0
bind interfaces only = true
security = share
guest account = nobody
invalid users = root
browseable = yes
read only = no
guest ok = yes
valid users = salman asalman
hosts allow = 127.0.0.1 192.168.2.4 192.168.4.0/28

Linux Network Interface

sudo ethtool eth0

This will tell you the properties of the wired config.  If Duplex is showing half, then type:

sudo ethtool -s eth0 autoneg off
sudo ethtool -s eth0 duplex full

This will tell you the properties of the wired config.  If Speed is showing auto, then type:

sudo ethtool -s eth0 speed 100

Finally, type to view final configuration:

sudo ethtool eth0

To set the interface speed, duplex or auto negotiation on Linux system boot up (make settings permanent), you need edit /etc/sysconfig/network-scripts/ifcfg-eth0 file for eth0 interface :

Open the file :

 vi/etc/sysconfig/network-scripts/ifcfg-eth0

Append following line :

ETHTOOL_OPTS=”speed 100 duplex full autoneg off”

Save and close the system. It will set the eth0 device to 100Mbs, full duplex, with the auto negotiation off at boot time.

You can simply restart the networking :

/etc/init.d/network restart

Debian or Ubuntu Linux permanent settings :

Under Debian or Ubuntu Linux just create a script as follows :

vi /etc/init.d/100Mbs

Append following lines :

#!/bin/sh
ETHTOOL=”/usr/sbin/ethtool”
DEV=”eth0″
SPEED=”100 duplex full”
case “$1” in
start)
echo -n “Setting eth0 speed 100 duplex full…”;
$ETHTOOL -s $DEV speed $SPEED;
echo ” done.”;;
stop)
;;
esac
exit 0

Save and close the file. Setup executable permission :

chmod +x /etc/init.d/100Mbs

Now run script when Debian or Ubuntu Linux boots up. Use update-rc.d command install System-V style init script links :

update-rc.d 100Mbs defaults

Reboot the system to take effect or just type scrit name :

/etc/init.d/100Mbs start

For Debian, I think that you just need append the follow line at /etc/network/interfaces file :

post-up ethtool -s eth0 speed 10 duplex half

Iptables Rules

less <filename> (reads a file)
vi <filename> (edits a file)

Local history file(s)

/.bash_history (records the last entries made, so less the file to read it)
/var/lib/iptables/rules-save (records the last entries saved in iptables)

Examples :

iptables -vnL  (lists the iptables ruleset)
iptables -vnL – t nat  (lists the iptables nat tables, i.e PREROUTING,POSTROUTING)

1. Inserts a rule in the INPUT chain at line 5 that allows 10.10.0.0/16 to 1.1.1.1

iptables -I INPUT 5 -s 10.10.0.0/16 -d 1.1.1.1 -j ACCEPT

2. Deletes the above rule :

iptables -D INPUT 5

-A will append the rule to the Chain, rather than insert it
-I will insert the rule to the Chain, rather than append it

3. REDIRECT port 80 traffic to port 8080

iptables -I PREROUTING 9 -t nat -s 1.1.1.1 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

4. Source NAT everything from 1.1.1.1 to go out as 2.2.2.2
iptables -I POSTROUTING 20 -t nat -s 1.1.1.1 -o eth1 -j SNAT –to-source 2.2.2.2

5.  Allows 1.1.1.1  to talk to our ranges and vpn box

iptables -I POSTROUTING 8 -t nat -s 1.1.1.1 -d 83.44.16.6 -j ACCEPT
iptables -I POSTROUTING 12 -t nat -s 1.1.1.1 -d 83.44.16.8/29 -j ACCEPT

6. /etc/init.d/iptables save (saves the changes made to iptables)

7. DNATs, SNATs and ports

-i eth1 (for in port)
-o eth1 (for out port)

–dport <port number> (destination port) –to <ip address> (NAT to an IP)

Examples :

Adds a rule in to POSTROUTING chain, to SNAT everything out of eth0 with a source address of 172.16.26.1 to 83.44.16.6

iptables -I POSTROUTING 6 -t nat -o eth0 -s 172.16.26.1 -j SNAT –to 83.44.16.6

8. Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201

iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp –dport 443 -j DNAT –to 172.16.209.201

9. Adds a rule in the FORWARD chain allowing everything from 10.10.1.2 with a destination tcp port of 25

iptables -I FORWARD -s 10.10.1.2 -p tcp –dport 25 -j ACCEPT