Networking-Blog

My WordPress Blog

LINUX DANGUARDIAN FILTER GROUPS

cat /etc/dansguardian/danguardianf1.conf

groupname = ‘Office‘
# Content filtering files location
bannedphraselist = ‘/etc/dansguardian/bannedphraselist’
weightedphraselist = ‘/etc/dansguardian/weightedphraselist’
exceptionphraselist = ‘/etc/dansguardian/exceptionphraselist’
bannedsitelist = ‘/etc/dansguardian/bannedsitelist’
greysitelist = ‘/etc/dansguardian/greysitelist’
exceptionsitelist = ‘/etc/dansguardian/exceptionsitelist’
bannedurllist = ‘/etc/dansguardian/bannedurllist’
greyurllist = ‘/etc/dansguardian/greyurllist’
exceptionurllist = ‘/etc/dansguardian/exceptionurllist’
bannedregexpurllist = ‘/etc/dansguardian/bannedregexpurllist’
bannedextensionlist = ‘/etc/dansguardian/bannedextensionlist’
bannedmimetypelist = ‘/etc/dansguardian/bannedmimetypelist’
picsfile = ‘/etc/dansguardian/pics’
contentregexplist = ‘/etc/dansguardian/contentregexplist’
!
!

Filtergroup List :
cat /etc/dansguardian/filtergroupslist

#Filter Group 1
#
85.234.69.48=filter1
85.234.69.49=filter1
85.234.69.51=filter1
85.234.69.54=filter1
85.234.69.61=filter1

!
!


Allowed Sites :

cat /etc/danguardian/exceptionsitelist

gwaliagroup.net
gwaliabackup.net
gwaliahelp.com
gotoassist.com
gwaliagroup.com
gwalia.com
speedtester.bt.com
217.35.209.142
217.32.105.42
britishredcross.org
sheltercymru.org.uk
swanseagov.uk
learningpool.com

!
!

####################################################

cat /etc/dansguardian/danguardianf2.conf

groupname = ‘Public‘
# Content filtering files location
bannedphraselist = ‘/etc/dansguardian/public/bannedphraselist’
weightedphraselist = ‘/etc/dansguardian/public/weightedphraselist’
exceptionphraselist = ‘/etc/dansguardian/public/exceptionphraselist’
bannedsitelist = ‘/etc/dansguardian/public/bannedsitelist’
greysitelist = ‘/etc/dansguardian/public/greysitelist’
exceptionsitelist = ‘/etc/dansguardian/public/exceptionsitelist’
bannedurllist = ‘/etc/dansguardian/public/bannedurllist’
greyurllist = ‘/etc/dansguardian/public/greyurllist’
exceptionurllist = ‘/etc/dansguardian/public/exceptionurllist’
bannedregexpurllist = ‘/etc/dansguardian/public/bannedregexpurllist’
bannedextensionlist = ‘/etc/dansguardian/public/bannedextensionlist’
bannedmimetypelist = ‘/etc/dansguardian/public/bannedmimetypelist’
picsfile = ‘/etc/dansguardian/public/pics’
contentregexplist = ‘/etc/dansguardian/public/contentregexplist’

!
!

Filtergroup List :

cat /etc/dansguardian/filtergroupslist

#Filter Group 2
#
85.234.69.52=filter2
85.234.69.53=filter2

Allowed Sites :

cat /etc/danguardian/public/exceptionsitelist

gwaliagroup.net
gwaliabackup.net
gwaliahelp.com
gotoassist.com
gwaliagroup.com
gwalia.com
learningpool.com

DANSGUARDIAN BLOCK ONLINE STREAMING

Config File squid configuration in /etc/squid/squid.conf

Edit File in squid.conf above line in ACL Zone.
################## ACL for Radio / Video Stream ##################
acl StreamingRequest1 req_mime_type -i ^video/x-ms-asf$
acl StreamingRequest2 req_mime_type -i ^application/vnd.ms.wms-hdr.asfv1$
acl StreamingRequest3 req_mime_type -i ^application/x-mms-framed$
acl StreamingRequest4 req_mime_type -i ^audio/x-pn-realaudio$
acl StreamingReply1 rep_mime_type -i ^video/x-ms-asf$
acl StreamingReply2 rep_mime_type -i ^application/vnd.ms.wms-hdr.asfv1$
acl StreamingReply3 rep_mime_type -i ^application/x-mms-framed$
acl StreamingReply4 rep_mime_type -i ^audio/x-pn-realaudio$

################## ACL for Radio / Video Stream ##################

Edit File in squid.conf above line in http_access Zone.
#################### Rules to block Radio / Video Stream ###########
http_access deny StreamingRequest1 all
http_access deny StreamingRequest2 all
http_access deny StreamingRequest3 all
http_access deny StreamingRequest4 all

http_reply_access deny StreamingReply1 all
http_reply_access deny StreamingReply2 all
http_reply_access deny StreamingReply3 all
http_reply_access deny StreamingReply4 all
#################### Rules to block Radio / Video Stream ############

Config File Dansguardian : /etc/dansguadian/
banned MIME types : bannedmimetypelist

Default List :

audio/mpeg
audio/x-mpeg
audio/x-pn-realaudio
audio/x-wav
video/mpeg
video/x-mpeg2
video/acorn-replay
video/quicktime
video/x-msvideo
video/msvideo
application/gzip
application/x-gzip
#application/zip
application/compress
application/x-compress
application/java-vm

Added Ones :

video :

video/flv
video/quicktime
video/x-quicktime

Audio :

audio/midi
audio/x-midi
audio/mod
audio/x-mod
audio/mpeg3
audio/x-mpeg3
audio/mpeg-url
audio/x-mpeg-url
audio/mpeg2
audio/x-mpeg2
audio/basic
audio/x-basic
audio/wav
audio/x-wav
audio/aiff
audio/x-aiff
audio/prs.sid
audio/x-ogg:
audio/x-pn-realaudio-plugin

Complete List :

# banned MIME types

audio/mpeg
audio/x-mpeg
audio/midi
audio/x-midi
audio/mod
audio/x-mod
audio/mpeg3
audio/x-mpeg3
audio/mpeg-url
audio/x-mpeg-url
audio/basic
audio/x-basic
audio/wav
audio/x-wav
audio/aiff
audio/x-aiff
audio/prs.sid
audio/x-ogg:
audio/x-pn-realaudio-plugin
audio/x-pn-realaudio
audio/x-wav
video/mpeg
video/x-mpeg2
video/acorn-replay
video/quicktime
video/x-msvideo
video/msvideo
application/gzip
application/x-gzip
#application/zip
application/compress
application/x-compress
application/java-vm

Linux VM Zyxel Router Ipsec Config

conn <<SITE-NAME>>
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left=80.74.16.239
leftnexthop=<<LOCAL_DEFAULT_GATEWAY_ADDRESS>>
leftsubnet=10.20.0.0/16
right=<<REMOTE_SITE_WAN_IP_ADDRESS>>
rightnexthop=<<REMOTE_DEFAULT_GATEWAY_ADDRESS>>
rightsubnet=<<LAN-SUBNET>><<MASK>>
rightsourceip=<<REMOTE_SITE_WAN_NaTTed_IP_ADDRESS>>
keyingtries=3
pfs=no
rekey=yes
auto=start
keyexchange=ike
ikelifetime=24h
keylife=24h
dpdaction=restart
dpddelay=30
dpdtimeout=120

eq :

conn cvs232
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left=80.74.16.239
leftnexthop=80.74.16.60
leftsubnet=10.20.0.0/16
right=85.234.66.231
rightnexthop=85.234.65.79
rightsubnet=10.20.55.64/27
rightsourceip=85.234.66.231
keyingtries=3
pfs=no
rekey=yes
auto=start
keyexchange=ike
ikelifetime=24h
keylife=24h
dpdaction=restart
dpddelay=30
dpdtimeout=120

LINUX Cisco Router Telnet Script

#!/usr/bin/expect

set timeout 100
spawn
telnet xxx.xx.x.xx
expect “Username: ”
send “aaaar”
expect “Password: ”
send “bbbbr”
expect “*#”
send “conf tr”
expect “*#”
send “ip ftp username ftpuserr”
expect “*#”
send “ip ftp password ftppassr”
expect “*#”
send “exitr”
expect “*#”
send “copy ftp: disk0:r”
expect “*? ”
send “yyy.yy.yy.yr”
expect “*? ”
send “a.jpgr”
expect “*? ”
send “a.jpgr”
expect “*]”
send “r”
expect “*]”
send “r”
expect “*#”
send “exit”
exit

Save script and setup executable permission on it :
$ chmod +x router.exp

!
!

e.g :

eval spawn “telnet $ip”
expect “^Login:”

send “$usernamen”
expect “Password:”
send “$passwordn”
expect “prompt> ”
send “configure terminaln”
expect “prompt> ”
send “interface fa0/0n”

Linux Iptables Web-Redirect 8080

PREROUTING CHAIN :

sudo iptables -t nat -I PREROUTING 20 -s 85.234.70.18/32 -p tcp -m tcp –dport 80 -j
REDIRECT –to-ports 8080

IF DATA IS FOR FIREWALL : It will hit the INPUT chain.

INPUT CHAIN :

sudo iptables -I INPUT -p tcp -m tcp –dport 81 -j Content_Filter
sudo iptables -I INPUT -p tcp -m tcp –dport 8080 -j Content_Filter

CONTENT_FILTER CHAIN :

sudo iptables -I Content_Filter 3 -s 85.234.70.18/32 -j ACCEPT

FORWARD CHAIN :

sudo iptables -I FORWARD 17 -s 85.234.70.18/32 -j ACCEPT

Remote Site incoming traffic to be naTTed using  eth2 public ip address :

POSTROUTING CHAIN :

sudo iptables -t nat -I POSTROUTING 6 -o eth2 -s 85.234.70.18/32 -j SNAT –to 85.234.65.46

MessageLabs Email Filtering

List of MessageLabs Public Ip Address Ranges :

Subnet IP Subnet Mask
216.82.240.0 255.255.240.0     /20 216.82.240.0 – 216.82.255.255
67.219.240.0 255.255.240.0     /20 67.219.240.0 – 67.219.255.255
85.158.136.0 255.255.248.0     /21 85.158.136.0 – 85.158.143.255
95.131.104.0 255.255.248.0     /21 95.131.104.0 – 95.131.111.255
46.226.48.0 255.255.248.0      /21 46.226.48.0 – 46.226.55.255
117.120.16.0 255.255.248.0     /21 117.120.16.0 – 117.120.23.255
193.109.254.0 255.255.254.0  /23 193.109.254.0 – 193.109.255.255
194.106.220.0 255.255.254.0  /23 194.106.220.0 – 194.106.221.255
195.245.230.0 255.255.254.0  /23 195.245.230.0 – 195.245.231.255

Linux Iptables Firewall Rules :

Create a Chain :

sudo iptables -t nat -N messagelabs

!

Create a PREROUTING rule to forward port 25 to “messagelabs” chain :

sudo iptables -t nat -I PREROUTING 11 -d 195.99.136.99/32 -p tcp -m tcp –dport 25 -j messagelabs

!
Create rules in messagelabs chain to DNAT port 25 Traffic to internal host :
sudo iptables -t nat -I messagelabs 1 -s 216.82.240.0/20 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 67.219.240.0/20 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 85.158.136.0/21 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 95.131.104.0/21 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 46.226.48.0/21 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 117.120.16.0/21 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 193.109.254.0/23 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 194.106.220.0/23 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
sudo iptables -t nat -I messagelabs 1 -s 195.245.230.0/23 -p tcp -m tcp –dport 25 -j DNAT –to 172.31.10.12:25
!
!
Next Chain down the line that will be accessed is the FORWARD chain :
This will FORWARD traffic to the POSTROUTING chain where it will locally break-out to the internet.
!
sudo iptables -I FORWARD 1 -d 172.31.10.12/32 -p tcp -m tcp –dport 25 -j ACCEPT
!
!
Final chain to be accessed is the POSTROUTING chain,
where traffic is SNATed to a particular interface
:
!
sudo iptables -t nat -I POSTROUTING 5 -o eth1 -s 172.31.10.12 -j SNAT –to 195.99.136.99

Booting Ubuntu From Grub Rescue

I have XP on another partition and it fails to load now.
When i start my machine I get the grub rescue command prompt.
!
Solution
:
!
Boot from live Cd. Open a terminal and enter :


grub-install

or

After booting the live CD, you have to bring up a terminal window in that go to the Applications,
Accessories, and then to Terminal, and then you got to verify what partitions you have by typing :

$sudo fdisk -l

In this your going to see two partitions, with the first being the MS Windows (NTFS)
partition
and the second being your Linux installation, And then when you will proceed:

$sudo grub
grub> root (hd0,1)
grub> setup (hd0)
grub> quit

If everything is going well, you should be able to reboot, remove the CD and boot into Ubuntu.
You can also make the adjustment by
/boot/grub/grub.cfg once in Ubuntu,
so that at boot time you can get the either of the operating system
.

Alternatively :

grub-install –root-directory /boot /dev/hda “hda = ubuntu partition, eg : sda9“


!
!
The update-grub command is used to generate and update the /boot/grub/grub.cfg.
This will update grub file with Bootable partition finding.

I have a working solution currently successful on Ubuntu Natty v 11.10

Run the grub-setup command, inserting the -d option and specifying the path to the /boot/grub directory of the operating system you’re trying to fix,

sudo grub-setup -d /media/disk/boot/grub /dev/sda

The -d option tells GRUB to use files from the specified directory.

Please substitute the word ‘disk’ with the name of your own mount point.

The ‘/dev/sda‘ part tells grub-setup to install GRUB to MBR in the first hard disk, which is called ‘/dev/sda‘.

You may use the same command to install GRUB in any other disks in your computer by replacing the /dev/sda part of the command with /dev/sdb or /dev/sdc and so on.

– If the command fails with feedback about not being able to access a device.map file, you might need to try again and specify the exact device.
map file to use with the -m option.

grub-setup -d /media/04bbbd00-d0c4-4b5b-99e2-d9ca0259a1d2/boot/grub /dev/sda

sudo mount /dev/sda4 /mnt
sudo mount /dev/sda4 /mnt/boot
sudo grub-install –root-directory=/mnt /dev/sda

Linux VSFtpd

Adding New Users To vsftpd

Tutorial that can explain how to add new users to vftpd.
!
#edit /etc/vsftpd.conf or /opt/etc/vsftpd.conf
!
Open the vsftpd.conf file and search for chroot_list_enable=YES
Make sure it is YES.
!
Do the same for the following variables :
chroot_list_file=/etc/vsftpd.chroot_list or /opt/etc/vsftpd.chroot_list
chroot_list_enable=YES
!
Save and close the file
!
!
Create vsftpd.chroot_list in /etc/ or /opt/etc/

nano /etc/vsftpd.chroot_list
!

Add the username you want to export to ftp.

The user must already be a system user with a valid passwd.
You must be able to find /home/,
If the user you want to add is not a system user then create
that user first before editing the above file
.
!
useradd username
passwd password

This will populate user in the /etc/passwd file :

ftpuser:x:1001:1001:::/home/salman:/bin/bash
!
What we want to do here is point the user “ftpuser” to ftp home directory like this below :

ftpuser:x:1001:1001::/media/Multimedia/Multimedia:/bin/bash
!
!

Restart the vsftpd server using /etc/init.d/vsftpd restart or service vsftpd restart

Now you can log into ftp using the new user.

EG : vsftpd.conf :

ftpd_banner: Prints a welcome message when someone connects to the server.
listen: If enabled, vsftpd will run in standalone mode.
xferlog_enable: If enabled, a log file will store detailed uploads and downloads.
xferlog_file=/var/log/vsftpd.log:  You may override where the log file goes if you like. The default is shown.
xferlog_std_format=YES: Log file in standard ftpd xferlog format. Note that the default log file location is /var/log/xferlog in this case.
connect_from_port_20: Controls PORT data connections use port 20 on the server machine.
idle_session_timeout=600: You may change the default value for timing out an idle session.
data_connection_timeout=120:
You may change the default value for timing out a data connection.
hide_ids: If enabled, all user and group information in directory listings will be displayed as “ftp”.
max_client: Sets the maximum number of clients allowed to be connected.
max_per_ip: Sets the maximum number of clients allowed to be connected from the same IP address.
max_login_fails: After this many login failures, the session is killed.
anon_root: Sets the directory which vsftpd will try to change into when an anonymous user logs in.
anonymous_enable: Enables or disables anonymous access. Use with caution.
anon_upload_enable: If enabled, anonymous users will be permitted to upload files.
anon_mkdir_write_enable: If enabled, anonymous users will be permitted to create new folders.
However, for this option to work, your server needs to have the option anonymous upload enabled and
the ftp *NIX user must write permissions on the parent directory.

nano /etc/vsftpd.conf :

listen=YES
listen_port=21
anonymous_enable=No
local_enable=YES
write_enable=NO
dirmessage_enable=YES
xferlog_enable=YES
connect_from_port_20=YES
xferlog_file=/var/log/vsftpd.log
xferlog_std_format=YES
idle_session_timeout=600
data_connection_timeout=120
ftpd_banner=Welcome to Comms-Networks FTP service.
chroot_local_user=YES
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd.chroot_list
pasv_enable=YES
pasv_promiscuous=YES
pasv_min_port=40000
pasv_max_port=40010
pasv_address=192.168.2.4
hide_ids=YES
max_clients=4
max_per_ip=2
max_login_fails=3
local_max_rate=128000

Centralizing Logins with TACACS+

Configuring TACACS+ can be a bit of a challenge if you have never done it before.
But once you understand the format of the config file its really pretty simple
.

Here’s a sample tacacs+ config :

# Encryption key is the same key you configure in your router
# ENCYPTION KEY:
	key = password

# You will want to log access to a file. Set that file here
# Remember to rotate the log, it will grow over time.
# write accounting to:
	accounting file = accounting.log

#########################################
###############Users#####################
#########################################

### without "login = " need to authenticate through radius or local:

	user 	= tom 		{ member = itnetwork }
	user 	= dick		{ member = itnetwork }
	user 	= harry		{ member = itnetwork }

	user	= backup-user	{ member = show } # show profile for only doing backups

################################
##########Groups################
################################

group = itnetwork {
		# IT-Network Engineers
        login = file passwords.db

		service	= exec {
			default attribute = permit
			priv-lvl = 15
		}

cmd = show {
                permit .*
                }
cmd = enable {
                permit .*
                }
#################################################
# The remainder edited for breavity

In the above sample config there are basically three sections.  The top section of the config is
where you define the encryption key that allows your routers and switches to authenticate to
your tacacs+ server.

The next section is the users section.  This is where you define the user names , which group they
are a member of, and where the password is kept.  In this example we are using a file called
passwords.db that contains these passwords.

Finally is the group section.  This is where you define the commands that can be executed by
this group. Users can belong to multiple groups.  Commands can be permitted or denied which
allows for an amazing amount of control over what users and groups can do on your network devices.

While TAC+ runs on the server, enter this command on the server to see the entries that go into the
accounting file:

tail -f /var/log/tac.log

For more advanced features check out Cisco Secure ACS Server.

The entire tacacs+ package can be downloaded here. It contains the entire tac.cfg file