Networking-Blog

My WordPress Blog

LINUX FSTAB

#  — This file has been automaticly generated by ntfs-config —
#
# <file system> <mount point>   <type>  <options>       <dump>  <pass>

proc /proc proc defaults 0 0
# Entry for /dev/sda8 :
UUID=d91d3807-8653-49b7-b281-608c07cbb14b / ext2 errors=remount-ro 0 1
# Entry for /dev/sda7 :
UUID=e92a8a7c-37aa-4264-b568-dddf79d41718 none swap sw 0 0
/dev/scd0 /media/cdrom0 udf,iso9660 user,noauto,exec,utf8 0 0
/dev/fd0 /media/floppy0 auto rw,user,noauto,exec,utf8 0 0
/dev/sdb1 /media/BackupDrive ntfs 0 0
/dev/sda5 /media/Multimedia ntfs-3g defaults,locale=en_GB.UTF-8 0 0

LINUX – Log Messages

Catalogue :

sudo cat  var/log/messages | grep 10.20.239.17 | less
sudo cat var/log/messages | grep vpn.log
sudo cat var/log/messages
sudo cat var/log/radius/radius.log

Monitor Live Logs:

sudo tail -f  var/log/messages | grep 10.20.239.17 | less
sudo tail -f var/log/messages | grep vpn.log
sudo tail -f var/log/messages
sudo tail -f /var/log/radius/radius.log

Linux Vpn Restarter Script

sudo vi ./root/scripts/vpn_restarter.pl (script)

#!/usr/bin/perl -w

use strict;
use Net::Ping;
use Expect;

# Disable Expect output
$Expect::Log_Stdout = 0;

my $company = “CVS”;
my $sitelist = “/root/scripts/cvs_sites“;
my $timeout = 15;

my ($lanip, $result, $site, $type, $wanip) = “”;
my @sites = “”;

# This sub will ping hosts and send a text message if the host is down
sub ping {
my $ip = shift;
my $host = shift;
my $net = shift;
my $maxtries = 5;       # Total pings
my $count = $maxtries;
my $success = 0;
my $p = Net::Ping->new(“icmp”,2);
if ( $net eq “LAN” ) {
$p->bind(‘10.20.254.254’);
} else {
$p->bind(‘80.74.16.239’);
}
while ( $count > 0 ) {
if ($p->ping($ip)) {
#print “$host – $ip – ping successn”;
$success+=1;
} else {
#print “$host – $ip – ping failedn”;
}
$count–;
}

# Calculate success percentage
my $percent = ((100/$maxtries)*$success);

# If pings are >80% successful host is up
if ( $percent >= 80 ) {
#print “$success/$maxtries pings to $host ($ip) were successfuln”;
return “Success”;
} else {
my $fail = $maxtries – $success;
#print “$fail/$maxtries pings to $host ($ip) failedn”;
return “Fail”;
}
}
print “$company VPN Restartern”;
open(SITES, “< $sitelist”) or die “Unable to open $sitelist”;
@sites = <SITES>;
close(SITES);

foreach (@sites) {
chomp;
($site, $lanip, $wanip) = split(/,/);

print “$site: “;
$result = ping($lanip, $site, “LAN”);
if ( $result eq “Fail” ) {
print “VPN down. “;
$result = ping($wanip, $site, “WAN”);
if ( $result eq “Success” ) {
print “WAN link up, Restarting VPN… “;
system(“/usr/sbin/ipsec auto –replace $site > /dev/null 2>&1”);
sleep 2;

my $exp = new Expect;
$exp->raw_pty(1);
$exp->spawn(“telnet”, $wanip) or die “Unable to spawn telnet: $!n”;

$exp->expect($timeout, “Password: “);
$exp->send(“FireStormn”);

my $regex = ‘Main.*Menu’;
$exp->expect($timeout,
[ “>”,
sub {
my $self = shift;
$self->send(“exitr”);
$type = “nomenu”;
}],
[ “$regex”, sub { my $self = shift; $self->send(“99r”); $type = “menu”; }]);

if ( $type eq “” ) {
$type = “Cisco”;
system(“/usr/sbin/ipsec auto –up $site > /dev/null 2>&1”);
} else {
system(“./zyxel_$type.exp $wanip > /dev/null 2>&1”);
}

print “Donen”;
} else {
print “WAN link downn”;
}
} else {
print “VPN upn”;
}

sudo ./root/scripts/vpn_checker.pl (script)

#!/usr/bin/perl

# vpn_checker.pl
# —–
# Version: 1.2
# Author: Darren Bradley
# Last Edit: 27/08/2008

# Restart IPSEC when Pluto is not running/hung

$piddir = “/var/run/pluto”;
$date = `date +%Y/%m/%d-%H:%M`;

print “n#### $date”.”IPSEC auto-restart scriptn—–n”;

print “Pluto is running…”;
$status = `/usr/sbin/ipsec auto –status 2>&1`;

if ( $status  =~ /^whack:/ ) {
print “NOnRestarting IPSEC…”;
# Stop IPSEC
system( “/etc/init.d/ipsec stop > /dev/null 2>&1” );

# Remove any reference to previous process
system( “rm -f $piddir/*.pid” );

# Start IPSEC
system( “/etc/init.d/ipsec start > /dev/null 2>&1” );
# Allow time for ipsec to initialise
sleep 15;
print “DONEn”;
} else {
print “YESn* No need for restart *n”;
}

print “n”;

$running = `ps aux | grep -v grep | grep vpn_restarter.pl`;

if ( $running ne “” ) {
print “VPN restarter already runningn”;
exit 0;
} else {
print “Running VPN restarter…n”;
system( “/root/scripts/vpn_restarter.pl” );
}

$date = `date +%Y/%m/%d-%H:%M`;
print “DONEn#### $daten”;
~
run script command :
sudo ./root/scripts/vpn_checker.pl

check site vpn status :
sudo less /var/log/vpn.log

edit vpn site list. this file is called for when vpn restarter script above is run :
sudo vi /root/scripts/cvs_sites

file structure of cvs_sites

cvs151,10.20.70.62,85.234.11.151
cvs161,10.20.4.100,85.234.11.161
cvs162,10.20.45.30,85.234.11.162
cvs163,10.20.45.94,85.234.11.163
cvs164,10.20.45.62,85.234.11.164
cvs167,10.20.250.14,85.234.11.167
cvs168,10.20.182.30,85.234.66.168

sudo crontab -l
A cron job is a process that is automatically run at whatever time you set it to run.
This can be each day, each hour of every day, every 5 minutes of every hour of every day.

Linux MTU Size Pings

Pinging with MTU packet Size.

ping -s 1438 85.234.75.1

PING 85.234.75.1 (85.234.75.1) 1438(1466) bytes of data.
1446 bytes from 85.234.75.1: icmp_seq=1 ttl=84 time=87.5 ms
1446 bytes from 85.234.75.1: icmp_seq=2 ttl=84 time=144 ms
1446 bytes from 85.234.75.1: icmp_seq=3 ttl=84 time=87.9 ms
1446 bytes from 85.234.75.1: icmp_seq=4 ttl=84 time=111 ms
!
Ping MTU packet Size with no Fragmentation of Packet.

ping -M dont -s 1472 85.234.75.2
PING 85.234.75.2 (85.234.75.2) 1472(1500) bytes of data.
1480 bytes from 85.234.75.2: icmp_seq=1 ttl=239 time=90.9 ms
1480 bytes from 85.234.75.2: icmp_seq=2 ttl=239 time=91.0 ms
1480 bytes from 85.234.75.2: icmp_seq=3 ttl=239 time=89.3 ms
1480 bytes from 85.234.75.2: icmp_seq=4 ttl=239 time=92.1 ms

Linux – Dansguardian Content Filter

sudo vi /etc/danguardian/bannedphraselist

.Include</etc/dansguardian/phraselists/pornography/banned>
.Include</etc/dansguardian/phraselists/illegaldrugs/banned>
.Include</etc/dansguardian/phraselists/gambling/banned>

# The following banned phraselists are included in the default DG distribution.

.Include</etc/dansguardian/phraselists/pornography/banned>
.Include</etc/dansguardian/phraselists/pornography/banned_portuguese>
.Include</etc/dansguardian/phraselists/illegaldrugs/banned>
.Include</etc/dansguardian/phraselists/gambling/banned>
.Include</etc/dansguardian/phraselists/gambling/banned_portuguese>
#.Include</etc/dansguardian/phraselists/googlesearches/banned>
#.Include</etc/dansguardian/phraselists/intolerance/banned_portuguese>
.Include</etc/dansguardian/phraselists/badwords/weighted

sudo vi /etc/danguardian/phraselists/gambling/weighted

#
# Phraselists to block gambling sites
#

#listcategory: “Gambling”

< bet >,<poker><40>
< betting ><30>
< blackjack ><30>
< casino ><30>
< casinon ><30>
< casinos ><30>
< gamblers ><30>
< gambling ><30>
< jackpot ><20>
< jackpott ><20>
< kasino><30>
< kasinon ><30>
< loto ><30>
< lotteri ><30>
< lotterier ><30>
< lotteries ><20>
< lottery ><30>
< lotto ><30>
< prispott ><20>
< roulette ><30>
< snake eyes ><20>
< snakeeyes ><20>
< sports book ><10>
< sportsbook ><10>
< totalisator ><30>
< video poker ><30>
< wagering ><50>
< wager ><30>
<card room><10>
<green card lottery><30>
<greencard lottery><30>
<poker>,<online><50>
<poker>,<tournament><50>
<poker>,<virtual><50>
<videopoker><30>
<virtual casino><30>
<virtual vegas><30>
<virtualcasino><30>

Linux Ipsec VPN Dynamic IP

Fully qualified domain name in DNS of the right-hand side VPN device,
which is preceded by an @ sign. If DNS isn’t set up for the IP addresses,
remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail
.

conn comms27
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms27.commsgroup.ww
rightsubnet=10.10.37.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear
type=transport

ipsec.secrets config :
%any 85.234.65.53 : PSK “commsr3m0t3”
@comms30.commsgroup.ww 85.234.65.53 : PSK “commsr3m0t3”

Table 35-1 Parameters of the /etc/ipsec.conf file

Parameter Description
Left Internet IP address of the left-hand side VPN device.
Leftsubnet The network protected by the left-hand side VPN device.
Leftid Fully qualified domain name in DNS of the left-hand side VPN device, which is preceded by an “@” sign. If DNS is set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Leftrsasigkey The entire left RSA sig public key for the left-hand side VPN device. This can be obtained by using the ipsec showhostkey --left command.
Leftnexthop The next hop router from the left-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.
Right Internet IP address of the right-hand side VPN device.
Rightsubnet The network protected by the right-hand side VPN device.
Rightid Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign. If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Rightrsasigkey The entire right RSA sig public key for the right-hand side VPN device. This can be obtained by using the ipsec showhostkey --right command.
Rightnexthop The next hop router from the right-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.

IPTables: SNAT

Flags:

-A Append
-I Insert

Example using the append flag:

sudo iptables -t nat -A POSTROUTING -o eth0 -d 1.2.3.4 -j SNAT –to-source 5.6.7.8
!
sudo iptables -t nat -I hml -s 172.20.6.99 -j SNAT –to-source 10.94.43.10

Example using the insert flag:

iptables -t nat -I POSTROUTING 17 -o eth0 -d 1.2.3.4 -j SNAT –to-source 5.6.7.8

Delete a Rule:
sudo iptables -t nat -D hml
sudo iptables -t nat -D POSTROUTING
sudo iptables -t nat -D PREROUTING

Linux: vi Editor

To Get Into and Out Of vi

To Start vi

To use vi on a file, type in vi filename. If the file named filename exists, then the first page (or screen) of the file will be displayed; if the file does not exist, then an empty file and screen are created into which you may enter text.
* vi filename edit filename starting at line 1
vi -r filename recover filename that was being edited when system crashed

To Exit vi

Usually the new or modified file is saved when you leave vi. However, it is also possible to quit vi without saving the file.
Note: The cursor moves to bottom of screen whenever a colon (:) is typed. This type of command is completed by hitting the <Return> (or <Enter>) key.
* 😡<Return> quit vi, writing out modified file to file named in original invocation
:wq<Return> quit vi, writing out modified file to file named in original invocation
:q<Return> quit (or exit) vi
* :q!<Return> quit vi even though latest changes have not been saved for this vi call

Deleting Text

The following commands allow you to delete text.
* x delete single character under cursor
Nx delete N characters, starting with character under cursor
dw delete the single word beginning with character under cursor
dNw delete N words beginning with character under cursor;
e.g., d5w deletes 5 words
D delete the remainder of the line, starting with current cursor position
* dd delete entire current line
Ndd or dNd delete N lines, beginning with the current line;
e.g., 5dd deletes 5 lines

Cutting and Pasting Text

The following commands allow you to copy and paste text.
yy copy (yank, cut) the current line into the buffer
Nyy or yNy copy (yank, cut) the next N lines, including the current line, into the buffer
p put (paste) the line(s) in the buffer into the text after the current line