Networking-Blog

My WordPress Blog

How to enable USB-Serial Port adapter (RS-232) in Ubuntu Linux

How to enable USB-Serial port adapter in Ubuntu Linux :

First plug in the USB-Serial Port adaptor to one of your USB port.
Wait for a couple of second, then run “dmesg”. You should see these message at
the end of dmesg output.


usb 1-1: new full speed USB device using uhci_and address 2
usb 1-1: configuration #1 chosen from 1 choice

After that, unplug the device and type “lsusb”. You will see a list of output similar to this.

Bus 003 Device 001: ID 0000:0000
Bus 002 Device 007: ID 03f0:4f11 Hewlett-Packard
Bus 002 Device 006: ID 05e3:1205 Genesys Logic, Inc. Afilias Optical Mouse H3003
Bus 002 Device 004: ID 15d9:0a33

Plug in the USB-Serial Port converter back, and run “lsusb” again, and you shall
see an additional line, like this.
Bus 003 Device 001: ID 0000:0000
Bus 002 Device 007: ID 03f0:4f11 Hewlett-Packard
Bus 001 Device 002: ID 4348:5523 — — — (notice the additional line!)
Bus 002 Device 006: ID 05e3:1205 Genesys Logic, Inc. Afilias Optical Mouse H3003
Bus 002 Device 004: ID 15d9:0a33

Now we know the vendor id and the product id of the USB-Serial Port converter, this will enable us to load the linux kernel module “usbserial” to activate the device, like this :


sudo modprobe usbserial vendor=0x4348 product=0x5523

Run “dmesg” again and you shall see lines similar like this :

usbserial_generic 1-1:1.0: generic converter detected
usb 1-1: generic converter now attached to ttyUSB0
usbcore: registered new interface driver usbserial_generic

As you can see, the new serial port device is mapped to /dev/ttyUSB0.
You can instruct Ubuntu to load this module automatically by include the line :
“usbserial vendor=0×4348 product=0×5523″
inside “/etc/modules” file.

How To Change Gnome Keyring Password?

1, Click on Places, Home Folder.
2. You will then need to hit Control+H on your keyboard to view hidden files.
(By the way, if you want to always view hidden files, you can click on Edit, Preferences
and click the box in front of Show hidden and backup files.)
3. Browse to the folder called .gnome2, and then to the folder called keyrings.
Inside it is a file called default.keyring.
4. Delete it and the next time you enter a site or mount with a password, it’ll ask for a
keyring password, and then you can set a new one.

Linux Iptables Port Forward

PREROUTING rule so that traffic coming to a particular public IP port is routed to your internal machine.

DNAT the traffic to your internal machine
Internal machine FILTER rules should not block the incoming traffic .

sudo iptables -t nat -I PREROUTING 1 -d 85.234.65.57 -p tcp -m multiport –dports 80,443
-j DNAT –to 10.20.0.13
!
sudo iptables -I FORWARD 33 -d 10.20.0.13 -p tcp -m multiport –dports 80,443 -j ACCEPT
sudo iptables -I FORWARD -m state –state RELATED,ESTABLISHED -j ACCEPT

RELATED,ESTABLISHED will take care of any return packets.
Accept packets to webservers (http and https) in the FORWARD chain.

Create additional chain within FORWARD chain to jump to another chain.
This configuration is organizing chain to required service or naming ACL.

Create a chain :
sudo iptables -N ahdb_network
Create FORWARD rule to jump to ahdb_network :
sudo iptables -I FORWARD 1 -s 128.0.0.0/8 -d 128.0.0.0/8 -j ahdb_network
sudo iptables -I FORWARD 1 -s 128.0.0.0/8 -d 10.0.0.0/16 -j ahdb_network
sudo iptables -I FORWARD 1 -s 10.0.0.0/16 -d 128.0.0.0/8 -j ahdb_network
ahdb_network Chain :
sudo iptables -I ahdb_network 1 -s 128.0.0.0/8 -d 128.0.0.0/8 -j ACCEPT
sudo iptables -I ahdb_network 2 -s 128.10.0.0/16 -d 10.0.0.0/16 -j ACCEPT
sudo iptables -I ahdb_network 3 -s 128.20.0.0/16 -d 10.0.0.0/16 -j ACCEPT
sudo iptables -I ahdb_network 4 -s 10.0.0.0/16 -d 128.10.0.0/16 -j ACCEPT
sudo iptables -I ahdb_network 5 -s 10.0.0.0/16 -d 128.20.0.0/16 -j ACCEPT
Intersite VPN Connectivity :

iptables -I FORWARD 63 -o eth0 -s 10.20.0.0/16 -d 10.20.21.1/32 -p tcp -m tcp
--dport 3389 -j Priory_Vets_Group
!
iptables -I FORWARD 64 -o eth0 -s 10.20.21.1/32 -d 10.20.0.0/16 -p tcp -m tcp
--sport 3389 -j Priory_Vets_Group
!
iptables -I Priory_Vets_Group 1 -d 10.20.0.0/16 -j ACCEPT
iptables -I Priory_Vets_Group 2 -d 10.20.21.1/32 -j ACCEPT

Linux Iptables Established Traffic

# Example /etc/sysconfig/iptables configuration file
#
# Turn on traffic filtering
*filter

# Set default policies
:INPUT DROP [1:44]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [27040:2493902]

# Accept all traffic from the loopback interface.
-A INPUT -i lo -j ACCEPT

# Accept legitimate responses to traffic we generate.
iptables -I INPUT -m state –state RELATED,ESTABLISHED -j ACCEPT
iptables -I INPUT 11 -m state –state RELATED,ESTABLISHED -j ACCEPT
iptables -I OUTPUT 11 -m state –state RELATED,ESTABLISHED -j ACCEPT
iptables -I public_in 11 -m state –state RELATED,ESTABLISHED -j ACCEPT

!
# Forward all legitimate responses to forwarded traffic.
# iptables -I FORWARD -m state –state RELATED,ESTABLISHED -j ACCEPT
!
# Allow inbound DNS responses from our ISPs DNS servers.
# Change these to the IP addresses of your ISPs DNS servers.
iptables -I INPUT -s 0.0.0.0 -i eth0 -p udp -m state –state ESTABLISHED -m udp –sport 53 -j ACCEPT
iptables -I INPUT -s 0.0.0.0 -i eth0 -p tcp -m tcp –sport 53 -m state –state ESTABLISHED -j ACCEPT
iptables -I INPUT -s 1.1.1.1 -i eth0 -p udp -m state –state ESTABLISHED -m udp –sport 53 -j ACCEPT
iptables -I INPUT -s 1.1.1.1 -i eth0 -p tcp -m tcp –sport 53 -m state –state ESTABLISHED -j ACCEPT

!
# Allow inbound DHCP from the Local wireless network (note: not from 10.0.0/8)
# Change this to the network allocated for your use.
iptables -I INPUT -s 10.1.2.0/255.255.255.0 -i wlan0 -p udp –dport 67:68 –sport 67:68 -j ACCEPT
!
# Allow inbound FTP from the entire wireless network.
iptables -I INPUT -d 10.1.2.0/255.255.255.0 -p tcp -m tcp –dport 21 -j ACCEPT
iptables -I INPUT -d 10.1.2.1 -p udp -m state –state NEW,ESTABLISHED -m udp –dport 21 -j ACCEPT

!
# Allow all related traffic to/from non-privileged ports.
iptables -I INPUT -p tcp -m tcp –sport 1024:65535 –dport 1024:65535 -m state –state RELATED,ESTABLISHED -j ACCEPT

Linux Iptables Active / Passive FTP

Active FTP

From the server-side firewall’s standpoint, to support active mode FTP the following
communication channels need to be opened
:

* FTP server’s port 21 from anywhere (Client initiates connection)
* FTP server’s port 21 to ports > 1024 (Server responds to client’s control port)
* FTP server’s port 20 to ports > 1024 (Server initiates data connection to client’s data port)
* FTP server’s port 20 from ports > 1024 (Client sends ACKs to server’s data port)

Active FTP

The sequence of events for active FTP is:

1. Your client connects to the FTP server by establishing an FTP control connection to
port 21 of the server
. Your commands such as ‘ls’ and ‘get’ are sent over this connection.

2. Whenever the client requests data over the control connection, the server initiates data
transfer connections back to the client. The source port of these data transfer connections is always
port 20 on the server, and the destination port is a high port (greater than 1024) on the client
.

3. Thus the ls listing that you asked for comes back over the port 20 to high port connection,
not the port 21 control connection
.

FTP active mode therefore transfers data in a counter intuitive way to the TCP standard,
as it selects port 20 as it’s source port (not a random high port that’s greater than 1024) and
connects back to the client on a random high port that has been pre-negotiated on the
port 21 control connection.

Active FTP may fail in cases where the client is protected from the Internet via many to one
NAT (masquerading)
. This is because the firewall will not know which of the many servers behind it
should receive the return connection
.

Passive FTP

Passive FTP works differently:

1. Your client connects to the FTP server by establishing an FTP control connection to port 21
of the server. Your commands such as ls and get are sent over that connection
.

2. Whenever the client requests data over the control connection, the client initiates the data transfer
connections to the server. The source port of these data transfer connections is always a high port on
the client with a destination port of a high port on the server
.

Passive FTP should be viewed as the server never making an active attempt to connect to the client
for
FTP data transfers. Because client always initiates the required connections,

Passive FTP works better for clients protected by a firewall.

The main problem with active mode FTP actually falls on the client side.
The
FTP client doesn’t make the actual connection to the data port of the server–it
simply tells the server what port it is listening on and the server connects back to the
specified port on the client
.

From the client side firewall this appears to be an outside system initiating a connection
to an internal client–something that is usually blocked
.

Linux Iptables Commands :

iptables -A INPUT -p tcp –dport ftp -j ACCEPT
iptables -A INPUT -p tcp –dport ftp-data -j ACCEPT
iptables
-A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp –sport ftp -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp –sport ftp-data -j ACCEPT

or

/sbin/modprobe ip_conntrack_ftp
iptables -A INPUT -p TCP -i eth0 –dport 21 -m state –state NEW -j ACCEPT
iptables
-A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT
iptables
-A OUTPUT -m state –state ESTABLISHED,RELATED -j ACCEPT

Summary

The following chart should help admins remember how each FTP mode works:

Active FTP :
command : client >1024 -> server 21
data    : client >1024 <- server 20

Passive FTP :
command : client >1024 -> server 21
data    : client >1024 -> server >1024

As Windows defaults to active FTP, and Linux defaults to passive,
you'll  probably have to accommodate both forms when deciding upon
a security  policy for your FTP server.

Client Protected by a Firewall Problem.

Typically firewalls don't allow incoming connection at all, which
frequently blocks active FTP from functioning. Active FTP connections
appears to work when the client initiates an outbound connection to the
server on port 21.

The connection then appears to hang,, how ever, as soon as you use the
ls,dir, or get commands. The reason is that the firewall is blocking the
return traffic connection from the server to the client (from port 20
on the server to a high port on the client).

If a firewall allows all outbound connections to the internet,
then passive FTP clients behind a firewall will usually work correctly as
the clients initiate all the FTP connections.

Linux Server Commands

Linux / Unix Command: uname

* -a, –all
print all information, in the following order:
* -s, –kernel-name
print the kernel name
* -n, –nodename
print the network node hostname
* -r, –kernel-release
print the kernel release
* -v, –kernel-version
print the kernel version
* -m, –machine
print the machine hardware name
* –p, –processor
print the processor type
* -i, –hardware-platform
print the hardware platform
* -o, –operating-system
print the operating system

* uname -m returns the machine architecture i.e. i386 for Intel/AMD platforms.
* uname -p returns the processor architecture i.e. i686 for Intel/AMD platforms
.
* uname -i (if implemented) returns the actual hardware platform i.e model number or such like
.

cat /etc/issue = returns Linux release

To Find Out How Long The System Has Been Running :

uptime

Sample outputs:

21:54:11 up 13 days,  4:29,  1 user,  load average: 0.21, 0.21, 0.12

The uptime command gives a one line display of the following information.

The current time (21:54:11) The uptime command gives a one line display of the following information
How long the system has been running (up 13 days)
How many users are currently logged on (1 user)
The system load averages for the past 1, 5, and 15 minutes (0.21, 0.21, 0.12)

Linux Set Date and Time From a Command Prompt :

Use the following syntax to set new data and time:
date –set=”STRING”

For example, set new data to 2 Oct 2006 18:00:00, type the following command as root user:

date -s “2 OCT 2006 18:00:00″
or
date –set=”2 OCT 2006 18:00:00”

You can also simplify format using following syntax:

date +%Y%m%d -s “20081128”

Linux Set Time
To set time use the following syntax:

date +%T -s “10:13:13”

Where,

* 10: Hour (hh)
* 13: Minute (mm)
* 30: Second (ss)

Use %p locale’s equivalent of either AM or PM, enter:

date +%T%p -s “6:10:30AM”
date +%T%p -s “12:10:30PM”

Do check and sync hardware clock with:

hwclock –show
hwclock –systohc
clock
date

How many users are currently logged on Server :

w

This is the same information contained in the header line displayed by the w and top commands: (user).

Top provides an ongoing look at processor activity in real time.

top

Start top ignoring any idle or zombie processes

-H
Show all threads.

-b
Batch mode. Useful for sending output from top to other programs or to a file. In this mode,
top will not accept command line input. It runs until it produces the number of iterations requested
with the n option or until killed. Output is plain text suitable for display on a dumb terminal
.

My Favorite updates every second
top -d 1

Batch mode. Useful for sending output from top to other programs or to a file. In this mode,
top will not accept command line input. It runs until it produces the number of iterations requested
with the n option or until killed. Output is plain text suitable for display on a dumb terminal.

Using Bash History

Before you begin typing your command, type ctrl-r. This will put you into history search mode
(actually, reverse incremental history search mode).

Now when you begin typing, the most recent command matching what you’ve typed so far will
appear on the line with a cursor at the start of the match.
(Try playing around with this feature; there are a few interesting behaviors in there.)

If you really are uncertain of the history or if you know you could be searching back through
many similar commands for one of particular interest, then you can use this more brute-force method.

Type the following command to get a list of all related commands with their history numbers:

history | grep -i “<search string>”

Once you’ve found the command you want, you can execute it specifically by its number using the
following built-in history expansion command:

<history number>

To clear bash history :

history -c

A common and convenient way of using ps to obtain much more complete information about the
processes currently on the system is to use the following
:

ps -aux | less

An alternative set of options for viewing all the processes running on a system is :

ps -ef | less

The processes shown by ps can be limited to those belonging to any given user by piping
the output through grep, a filter that is used for searching text. For example, processes belonging
to a user with a username adam can be displayed with the following
:

ps -ef | grep adam

The free command provides information about unused and used memory and swap space on
any computer running Linux or another Unix-like operating system
.

The basic syntax of free is

free [options]

Several options are available to change the unit of display for free from its default kilobytes,
including -b for bytes, -m for megabytes and -g for gigabytes. Of these, -m is usually the most useful.
Thus, for example, to show all of the data in megabytes, the following would be used
:

free -m  -g for gigabytes

The -t option instructs free to additionally display a fourth line of data containing the totals
for physical memory and swap space
.

This scrolling output can be terminated by simultaneously pressing the CONTROL and c keys.
Thus, for example, the following would provide new data every five seconds and display the
output in megabits
:

free -ms 5

to display memory utilization every two seconds, the following would be used:

watch free

which highlights changes in output, and its -n option followed by the number one to increase the
frequency of reports to one per second as follows
:

watch -n 1 -d free

More detailed information about total memory and current memory usage can be obtained by reading
the proc/meminfo file directly. This can be accomplished, for example, with the cat command
(which is commonly used to read text files) as follows
:

cat /proc/meminfo

Linux Dmesg



The dmesg command is used to write the kernel messages in Linux and other
Unix-like
operating systems to standard output (which by default is the display screen).

A kernel is the core of an operating system. It is the first part of the operating system
hat is loaded into memory when a computer boots up (i.e., starts up), and it controls virtually
everything on a system.

The numerous messages generated by the kernel that appear on the display
screen as a computer boots up show the hardware devices that the kernel detects
and indicate whether it is able to configure them.

dmesg obtains its data by reading the kernel ring buffer. A buffer is a portion of a
computer’s memory that is set aside as a temporary holding place for data that is being sent
to or received from an external device, such as a hard disk drive (HDD), printer or keyboard.

A ring buffer is a buffer of fixed size for which any new data added to it overwrites the oldest data in it.

dmesg can be very useful when troubleshooting or just trying to obtain information about the
hardware on a system
. Its basic syntax is

dmesg [options]

Invoking dmesg without any of its options (which are rarely used) causes it to write all the
kernel messages to standard output.

This usually produces far too many lines to fit into the display screen all at once,
and thus only the final messages are visible
.

However, the output can be redirected to the less command through the use of a pipe
(designated by the vertical bar character),

thereby allowing the startup messages to be viewed one screenful at a time:

dmesg | less

less allows the output to be moved forward one screenful at a time by pressing the
SPACE
bar, backward by pressing the b key and removed by pressing the q key.

(The more command could have been used here instead of the less command; however,
less is newer than more and has additional functions, including the ability to return to
previous pages of the output.)

When a user encounters a problem with the system, it can be convenient to write the
output of dmesg to a file and then send that file by e-mail to a system administrator or
other knowledgeable person for assistance.

For example, the output could be redirected to a file named boot_messages using the
output redirection operator

(designated by a rightward facing angle bracket) as follows:

dmesg > boot_messages

The -i option can be used to tell grep to ignore the case (i.e., lower case or upper case) of the
letters in the string. For example, the following command
:
lists all references to USB (universal serial bus) devices in the kernel messages
:

dmesg | grep -i usb

And the following tells dmesg to show all serial ports (which are represented by the string tty):

dmesg | grep -i tty

The dmesg and grep combination can also be used to show how much
physical memory
(i.e., RAM) is available on the system:

dmesg | grep -i memory

The following command checks to confirm that the HDD(s) is running in
DMA (direct memory access) mode:

dmesg | grep -i dma

The output of dmesg is maintained in the log file /var/log/dmesg, and it can thus also be
easily viewed by reading that file with a text editor, such as vi or gedit, or with a command
such as cat, e.g.,

cat /var/log/dmesg | less

NAT Public Ip address Over VPN

On Cisco Configuration :

NAT statements added for external addresses
:

ip nat inside source list NAT interface FastEthernet4 overload
!
ip access-list extended NAT
permit udp host 194.62.42.150 host 213.123.196.140 eq 50561
permit udp host 194.62.42.150 host 213.123.197.21 eq 50561

!
VPN match statement to include Public_Ip UDP flow NAT traffic :
!
VPN access-list for VPN Traffic :

ip access-list extended VPN
remark LAN_TO_LAN
permit ip local_lan_subnet/mask remote_lan_subnet/mask
remark Access_To_PUBLIC_IP_OVER_VPN
permit udp host local_lan_ip host 194.72.93.118

VPN Peer terminating devices is a Linux BOX :

Route updated on Linux Box to forward NAT Public Ip traffic over VPN to remote site HQ.

sudo ip route add 194.72.93.118 via 10.200.0.1 dev eth1 proto zebra equalize

Linux Box Iptables Firewall site_to_site chain updated to allow traffic source
from Public_Ip over VPN
:

sudo iptables -I  site_to_site -s 194.72.93.118 -j ACCEPT
sudo iptables -I  site_to_site -s 194.72.93.119 -j ACCEPT

Packet Processing In iptables

Figure 14-1 Iptables Packet Flow Diagram

Iptables.gif

You need to specify the table and the chain for each firewall rule you create.
There is an exception: Most rules are related to filtering, so iptables assumes that any
chain that’s defined without an associated table will be a part of the filter table.
The filter table is therefore the default.

To help make this clearer, take a look at the way packets are handled by iptables.

In Figure 14.1 a TCP packet from the Internet arrives at the firewall’s interface
on Network A to create a data connection.

The packet is first examined by your rules in the mangle table’s PREROUTING chain,
if any. It is then inspected by the rules in the nat table’s PREROUTING chain to see
whether the packet requires DNAT.

It is then routed.

If the packet is destined for a protected network, then it is filtered by the rules in the
FORWARD chain of the filter table and, if necessary, the packet undergoes SNAT in the
POSTROUTING chain before arriving at Network B. When the destination server
decides to reply, the packet undergoes the same sequence of steps.

Both the FORWARD and POSTROUTING chains may be configured to implement
quality of service (QoS) features. in their mangle tables, but this is not usually done
in SOHO environments.

If the packet is destined for the firewall itself, then it passes through the
mangle table
of the INPUT chain, if configured, before being filtered by the rules in
the INPUT chain of the filter table before. If it successfully passes these tests then it is
processed by the intended application on the firewall.

At some point, the firewall needs to reply. This reply is routed and inspected by the
rules in the OUTPUT chain of the mangle table, if any. Next, the rules in the OUTPUT
chain of the nat table determine whether DNAT is required and the rules in the OUTPUT
chain of the filter table are then inspected to help restrict unauthorized packets.
Finally, before the packet is sent back to the Internet, SNAT and QoS mangling is done
by the POSTROUTING chain

Table 14-1 Processing For Packets Routed By The Firewall

Queue Type Queue Function Packet Transformation Chain in Queue Chain Function
Filter Packet filtering
FORWARD
Filters packets to servers
accessible by another NIC
on the firewall
.
INPUT
Filters packets destined to the
firewall
.
OUTPUT
Filters packets originating
from the firewall.
Nat Network Address Translation
PREROUTING
Address translation occurs
before routing. Facilitates the transformation of the destination
IP address to be compatible with the firewall’s routing table.
Used with NAT of the destination
IP address, also known as destination NAT or DNAT
.
POSTROUTING
Address translation occurs after
routing. This implies that there
was no need to modify the
destination IP address of the packet
as in pre-routing. Used with NAT
of the source IP address using either
one-to-one or many-to-one NAT.
This is known as source NAT,
or SNAT
.
OUTPUT
Network address translation for
packets generated by the firewall.
(Rarely used in SOHO environments
)
Mangle TCP header modification
PREROUTING
POSTROUTING
OUTPUT
INPUT
FORWARD
Modification of the TCP packet
quality of service bits before routing occurs.
(Rarely used in SOHO environments)

Linux – Tcpdump within an ipsec vpn packet

sudo tcpdump -i eth0 -E 3des-cbc:l6h7s4vavpn icmp
this command will let you see all packets coming within the ipsec vpn tunnel of a
network interface


/sbin/iptables –L
this command lists your firewall active rules

tcpdump –i eth0
this command will let you see all packets coming into or out of a network interface,
works on ipsec interfaces as well. Many filter options available

tail –n x /var/log/messages
will display the last x lines of the system log.

ipsec auto –status
This command to get status report from running system. Displays Pluto’s state.
It Includes the list of connections which are currently “added” to Pluto’s internal database;
lists state objects reflecting ISAKMP and IPsec SAs being negotiated or installed.


ipsec look
This command provides brief ipsec status information

ipsec barf
This command provides copious amounts of debugging info for ipsec.

netstat –rn
This command displays your current routing table (in memory)

netstat –an
This command displays your current active ports and their state. Ie: If your firewall is listening on a
certain port or connected on a certain port