Monday, August 06, 2007

DNS Master Slave config - Errors on slave

I have been getting errors like
"dumping master file: sl/tmp-XXXX5il3sQ: open: permission denied"
in my /var/log/messages

Finally found out that the named user is having permission issues on the slave server. When I pointed the named files to slaves/ everything went well.

Ex:
zone "example.net" {
type slave;
file "slaves/example.net";
masters { 192.168.1.1; };
};

Access Windows Network share in Fedora

I found out that smbmount and mount -t smbfs do not work anymore on Fedora.

But now you can use cifs (The Common Internet File System) to do the same as before

mount -t cifs //1.2.3.4/share /mnt/somedirectory

Refer to man mount.cifs for more options

Access NTFS Partitions on Fedora Core (5 and above)

This article is referenced here


Windows uses a different filesystem (NTFS) to store files. In order for Fedora to read that filesystem, you require NTFS support in your kernel. You can either recompile your kernel for NTFS read support -OR- obtain the proper kernel module.

To setup NTFS access you must (1) install NTFS support, (2) check how many partitions you have, (3) create mount points, (4) mount partitions, and (5) update fstab to mount at next boot.

1. Install NTFS Support

[user@localhost ~]$ sudo yum install fuse fuse-libs ntfs-3g ntfsprogs ntfsprogs-gnomevfs

No kernel version checking is required, so long as you are using a stock Fedora kernel.

2. Check Your Partitions

Use fdisk to list partitions. Most ATA hard drives will be /dev/hda. Drives may also show up as /dev/hdb, /dev/sda depending on your configuration.

[user@localhost ~]$ sudo /sbin/fdisk -lu /dev/hda | grep NTFS
/dev/hda1 * 63 33559784 16779861 7 HPFS/NTFS
/dev/hda2 33559785 67119569 16779892+ 7 HPFS/NTFS
/dev/hda3 67119570 100679354 16779892+ 7 HPFS/NTFS

Usually the first will be a drive "letter": C drive, next D, etc. Hence /dev/hda1 is my C:\ drive used by Windows.

3. Create Mount Points

For every partition in step 2 that you wish to access, you will need a "mount point". A mount point is just a directory. Common directories are: /media/ and /mnt/. Use whichever, but be consistent.

[user@localhost ~]$ cd /media/
[user@localhost media]$ sudo mkdir c_drive d_drive e_drive

You do not have to use these names, if you prefer to create folders such as movies, documents, or winxp, any name will work (without spaces).

4. Mount Partitions

Using NTFS-3G, we can mount the NTFS partition read-write, however it is recommended for novices as read-only. The following mounts and sets the permissions so all users can read the contents of each partition.

[user@localhost ~]$ sudo mount /dev/hda1 /media/c_drive -t ntfs-3g -r -o umask=0222
[user@localhost ~]$ sudo mount /dev/hda2 /media/d_drive -t ntfs-3g -r -o umask=0222
[user@localhost ~]$ sudo mount /dev/hda3 /media/e_drive -t ntfs-3g -r -o umask=0222

Read/Write Access: The above is for read-only access. In order to mount read/write, you must use the -rw -o umask=0000. Example:

[user@localhost ~]$ sudo mount /dev/hda1 /media/c_drive -t ntfs-3g -rw -o umask=0000

HIGHLY RECOMMENDED: Please run man mount to understand what umask= does.

5. Update /etc/fstab

Every time Fedora boots, the partitions must be mounted. To automatically mount, you must edit /etc/fstab.

Open /etc/fstab in an editor: (use nano instead of gedit if you do not have a GUI)

[user@localhost ~]$ sudo gedit /etc/fstab

Add these lines to the END of the file:

/dev/hda1   /media/c_drive     ntfs-3g    ro,defaults,umask=0222 0 0
/dev/hda2 /media/d_drive ntfs-3g ro,defaults,umask=0222 0 0
/dev/hda3 /media/e_drive ntfs-3g ro,defaults,umask=0222 0 0

Read/Write Access: The above is for read-only access. In order to mount read/write, you must use the rw,defaults,umask=0000. Example:

/dev/hda1   /media/c_drive     ntfs-3g    rw,defaults,umask=0000 0 0

Done!

NOTE: SELinux Problems

Users of SELinux will fix Fedora blocks the automounting of ntfs partitions when using NTFS-3G. This is a Fedora/SELinux bug, not NTFS-3G. Some support can be found on the NTFS-3G support page.. However for now users can mount everything when they log in by running:

[user@localhost ~]$ sudo mount -a

NOTE for FAT32 users

If you have FAT32 or FAT16 partitions, instead of ntfs-3g above you can use vfat to mount your partitions. No extra modules or downloads are required, this is built into the kernel. Just replace vfat for every place we have ntfs-3g when mounting and when editting /etc/fstab.

FAT32/FAT16 read and write is supported. If you wish to mount read/write, then use: '-rw' for Step 4. Mounting Partitions, and 'rw,defaults,umask=0000 0 0' for Step 5. Updating /etc/fstab.

Password Broken Sync between Windows 2003 and Linux using SFU after SP2

I had encountered this problem after installing SP2 on our AD (Windows 2003 server). Whenever you change the password in windows, it is not reflecting the change in the attribute "msSFU30Password" and hence the change does not reflect on the Linux systems.

I found a useful article at "http://blogs.msdn.com/sfu/archive/2007/04/27/windows-server-2003-sp2-breaks-sfu.aspx"

  1. Download and extract the hot fix on your system.
  2. Install SFU35-KB913030-X86-ENU.EXE from the extracted files.
    1. Double-click on this file and complete the installation. At the end, the installation will prompt you to reboot the server and this prompt features just the OK button. DO NOT click on it yet.
  3. Open a Command Prompt window, change to the folder where you have the SFU35-KB913030-X86-ENU.EXE file and run this -

    SFU35-KB913030-X86-ENU.exe /x
    This command extracts the files from the hot fix instead of kicking the hot fix installation.
  4. That'll again ask you a folder location where the files from this hot fix should be extracted. Type a path and click on OK.
  5. After extraction is complete, open this new path in Windows Explorer. Open the sfu35eng folder and here you can see all the files this hot fix updates.
  6. Depending upon which component is broken on your system, copy the psxss.exe, psxdll.dll and/or pswdsync.dll files after verifying the version number (it should be 8.0.1969.38) to your %systemroot%\system32 folder.

    Manual update of these drivers is needed since the wrongly replaced drivers have a version number corresponding to Windows Server 2003 R2 which is higher than that of the SFU 3.5 driver versions.
  7. Come back to the hot fix window which is still waiting for you to click on the OK button. Click on OK and let your system reboot.
  8. Everything should be fine now.

Thursday, July 05, 2007

Using tape backup in Linux (DAT40)

Installed an old tape drive (Seagate DAT40 20/40G), finally worked out a math for backing up critical data into multiple tapes. It is taking a long time for the backup to finish, so I decided to upgrade to an LTO1 drive that supports 100GB per tape uncompressed. That might solve the frequent tape changing.

For backing up and verifying the backup (similar to verify data after burning a cd-r) you can use the command
tar -cvpWlf /dev/st0 /home
Where,
c : create a new archive of /home
v : Verbose output
p : Ignore umask when extracting files i.e. preserve permissions on files
W : attempt to verify the archive after writing it
l : stay in local file system when creating an archive
f : Specify /dev/st0 as tape device (file)
/dev/st0: Tape device name.
/home : Directory to backup

I would like to use bzip2 compression prior to backing up to tape, that requires turning off compression on the tape drive itself. To get the current status of compression, run the command
tapeinfo -f /dev/st0

For setting the compression off
mt -f /dev/nst0 defcompression 0

For setting the compression on
mt -f /dev/nst0 defcompression 1

Tuesday, July 03, 2007

Webserver(lighttpd) access log

We have installed lighttpd and made the basic configuration to serve plain html pages and later while setting up vnstat PHP front end, we made changes to enable cgi module and php.

Now let us configure the access logging (just to know who is looking at our website)

First create a place on the USB HDD to hold the log files
mkdir /opt/log/lighttpd

Install the accesslog module
ipkg install lighttpd-mod-accesslog

modify /etc/lighttpd.conf

uncomment server.modules
and the corresponding closing brace (if you did not install PHP)

insert the line
mod_accesslog
before the closing brace

at the end of the file insert the lines
#### Access log
accesslog.filename = "/opt/log/lighttpd/access.log"

restart lighttpd server
/etc/init.d/S80lighttpd stop
/etc/init.d/S80lighttpd start

you will now have the lighttpd access log in /opt/log/lighttpd/access.log

Monday, July 02, 2007

vnstat PHP frontend

The vnstat frontend runs in PHP. We installed lighttpd but did not install php. Now we will install php and make the necessary changes in the lighttpd.conf to run it in cgi mode.

To run php in cgi mode, install mod_cgi for lighttpd
ipkg install lighttpd-mod-cgi

Now install php and gd for php
ipkg -d opt install php5 php5-cgi php5-mod-gd (dep. libgd, libjpeg, libpng)
the following files will be installed
/opt/etc/php.ini
/opt/usr/bin/php
/opt/usr/lib/php/gd.so
/opt/usr/lib/libgd.so.2.0.0
/opt/usr/lib/libgd.so.2
/opt/usr/lib/libjpeg.so.62.0.0
/opt/usr/lib/libjpeg.so.62
/opt/usr/lib/libpng.so.3.0.0
/opt/usr/lib/libpng12.so.0.0.0
/opt/usr/lib/libpng.so.3
/opt/usr/lib/libpng12.so.0

create symbolic link for php.ini file (by default cgi version of php looks for php.ini in /etc)
ln -s /opt/etc/php.ini /etc/php.ini

To enable mod_cgi in lighttpd, edit vi /etc/lighttpd.conf
uncomment server.modules, the corresponding closing brace and uncomment the line
"mod_cgi",

under #### CGI module add the line
cgi.assign = ( ".php" => "/opt/usr/bin/php" )

for running the php scripts when you hit a directory, index.php needs to be added to index-file.names. For that change the line
index-file.names = ( "index.html", "default.html", "index.htm", "default.htm" )
to
index-file.names = ( "index.html", "default.html", "index.htm", "default.htm", "index.php" )

To enable GD extension in PHP, edit /opt/etc/php.ini, uncomment the line
extension=gd.so

Because we have installed the GD module in a non-standard location, change the line
; Directory in which the loadable extensions (modules) reside.
extension_dir = "/usr/lib/php"
to
; Directory in which the loadable extensions (modules) reside.
extension_dir = "/opt/usr/lib/php"

Restart lighttpd service
/etc/init.d/S80lighttpd stop
/etc/init.d/S80lighttpd start


download the vnstat PHP frontend from here, extract the files to the directory vnstat and copy that to your lighttpd document root

edit config.php under the vnstat PHP frontend directory and change the interfaces as shown below
$iface_list = array('eth0', 'eth1', 'eth2', 'br0');

$iface_title['eth0'] = 'Internal';
$iface_title['eth1'] = 'Internet';
$iface_title['eth2'] = 'eth2';
$iface_title['br0'] = 'Bridge';

also change the vnstat_bin variable to point to the vnstat executable for data collection by the script
$vnstat_bin = '/usr/bin/vnstat';

Now visit your web page at http:/192.168.1.1/vnstat/ for the GUI.

vnstat - network traffic monitor for Linux

install vnstat
ipkg install vnstat

When running vnstat to update the statistics, it will create the stats database in /var/lib/vnstat (/var is in the /tmp directory that is lost after a reboot). If you are using a USB harddrive, you can map that to /opt/lib. To make the mapping automatically at every reboot create a file /etc/init.d/S98vnstatlib paste the lines below

#!/bin/sh

ln -s /opt/lib /var/lib

Now to create the initial text database for the appropriate interfaces you need to run
vnstat -u -i eth0
vnstat -u -i eth1
vnstat -u -i eth2
vnstat -u -i br0

To collect the stats you will have to update the databases regularly by running "vnstat -u" using cron.

enable cron in web interface System -> Cron

create a file /etc/crontabs/root and run the command (it will update the vnstat database every 5 minutes)
echo "*/5 * * * * if [ -x /usr/bin/vnstat ] && [ `ls /var/lib/vnstat/ | wc -l` -ge 1 ]; then /usr/bin/vnstat -u; fi " >> /etc/crontabs/root

restart cron to commit the changes made to the crontab files
/etc/init.d/S60cron restart

Monday, June 25, 2007

PPTP on OpenWrt

PPTP Configuration

install pptpd (dep. ppp, kmod-crypto, kmod-mppe, kmod-ppp)

exit /etc/ppp/options.pptpd
Change the IP from 172.36.0.1 to your LAN IP of the router
and enable proxyarp

in /etc/ppp/chap-secrets
insert a line
username pptp-server password 192.168.xxx.xxx (IP Address of the client)

Add the following lines to /etc/firewall.user
### Allow PPTP control connections from WAN
iptables -t nat -A prerouting_wan -p tcp --dport 1723 -j ACCEPT
iptables -A input_wan -p tcp --dport 1723 -j ACCEPT
### Allow GRE protocol (used by PPTP data stream)
iptables -A output_rule -p 47 -j ACCEPT
iptables -A input_wan -p 47 -j ACCEPT

### VPN Section
# allow VPN clients to talk to LAN clients
iptables -A forwarding_rule -s 192.168.42.0/24 -d 192.168.42.0/24 -j ACCEPT
# allow VPN connections to get out WAN interface (to internet)
iptables -A forwarding_rule -i ppp+ -o vlan1 -j ACCEPT

and restart firewall

DynDNS for OpenWrt

DynDNS Configuration
for hosting your own domain go to www.zoneedit.com and create a free account that can support upto 5 domains
you would have to follow the procedure to change the authortative DNS with your domain registrar.

In OpeWrt you can install ez-ipupdate using
ipkg install ez-ipupdate
Go to the web interface and configure DynDns

/etc/init.d/S52ez-ipupdate start

Samba/rsync/sftp on OpenWrt

File transfer (from OpenWrt Flash and USB HDD)
  • openssh-sftp-server to/from windows machines via winscp
    • ipkg install openssh-sftp-server
  • rsync to/from linux machines
    • ipkg install rsync (dep. libopt)
  • samba to/from any machine
    • ipkg install samba-server (dep. samba-common, libgcc)
Samba Configuration
configure samba to share the USB HDD
/etc/samba/smb.conf
[windows]
comment = windows share
path = /mnt/windows
browseable = yes
public = yes
writeable = yes

[linux]
comment = linux share (opt)
path = /opt
browseable = yes
public = yes
writeable = yes


after installing everything! I still have 2.3M to spare because of the USB HDD
/dev/mtdblock/4 6.1M 3.8M 2.3M 63% /jffs

Asterisk on OpenWrt

Asterisk Installation
ipkg -d opt install asterisk (dep. libncurses)
ln -s /opt/etc/asterisk /etc/asterisk
ln -s /opt/usr/lib/asterisk /usr/lib/asterisk
ln -s /opt/usr/lib/libncurses.so.5 /usr/lib/libncurses.so.5
ln -s /opt/usr/lib/libncurses.so.5.2 /usr/lib/libncurses.so.5.2
ln -s /opt/usr/sbin/asterisk /usr/sbin/asterisk

configure your asterisk

load the following modules
res_indications.so
app_cut.so
pbx_functions.so

configure the firewall to allow IAX2 on 4569 UDP
### Open IAX port to WAN
iptables -t nat -A prerouting_wan -p udp --dport 4569 -j ACCEPT
iptables -A input_wan -p udp --dport 4569 -j ACCEPT

Web Server (lighttpd) on OpenWrt

Web Server Installation & Configuration
lighttpd (dep. libpcre, libpthread, libsqlite3, libxml2, zlib)
ipkg install http://downloads.openwrt.org/backports/rc6/lighttpd_1.4.11-1_mipsel.ipk
lighttpd.conf

Edit /etc/lighttpd.conf
modify server.document-root to point it to /opt/www
uncomment server.port = 81

add a file /opt/www/index.html with "It Works!"


Create a file /etc/init.d/S80lighttpd
#!/bin/sh

BINDIR=/usr/sbin/
BIN=lighttpd
DEFAULT=/etc/default/$BIN
LOG_D=/var/log/$BIN
RUN_D=/var/run
PID_F=$RUN_D/$BIN.pid
[ -f $DEFAULT ] && . $DEFAULT

case $1 in
start)
mkdir -p $LOG_D
mkdir -p $RUN_D
${BINDIR}${BIN} $OPTIONS
;;
stop)
[ -f $PID_F ] && kill $(cat $PID_F)
;;
*)
echo "usage: $0 (start|stop)"
exit 1
esac

exit $?

chmod +x /etc/init.d/S80lighttpd

For Port forwarding from port 80 to 81 (Running Web server on port 81 for external website along with the configuration Web UI on port 80)
  • iptables-mod-nat (dep. kmod-ipt-net)

insert the following lines in /etc/firewall.user
iptables -t nat -A prerouting_wan -p tcp --dport 80 -j REDIRECT --to-port 81
iptables -A input_wan -p tcp --dport 81 -j ACCEPT

Start the lighttpd service and test it.

Installing Applications on USB HDD

Using HDD for additional Application Install
before installing asterisk point the installation directory to /opt


edit /etc/ipkg.conf and enter the line
dest opt /opt
before the existing line
dest ram /tmp


from now on to install a software
ipkg -d opt

also
Packages installed to /opt have their executables in /opt/usr/bin and /opt/bin and since this is not part of the default path, they have to be called with full path.
To get rid of this unwanted "feature" change the PATH line of /etc/profiles to something like :
export PATH=/bin:/sbin:/usr/bin:/usr/sbin:/opt/bin:/opt/sbin:/opt/usr/bin:/opt/usr/sbin

Installing libs in /opt
People that have tried installing libs to /opt knows that this causes problems.
The reason is, that OpenWRT as default is only looking in /lib and /usr/lib for libs, and not in /opt/usr/lib .

To make libs work from /opt you need to add the following line to /etc/profile :
export LD_LIBRARY_PATH=/lib:/usr/lib:/opt/usr/lib:/opt/lib

Making services installed to /opt start at system boot time
In order to get stuff in /opt/etc/init.d/ startet at boot-time I have created the script S98optfiles and placed it in /etc/init.d
#!/bin/sh
#
# /opt/etc/init.d/ script
#

i=0
while [ $i -le 30 ]
do
if [ -d /opt/etc/init.d ]
then
for i in /opt/etc/init.d/S*; do
$i start 2>&1
done | logger -s -p 6 -t '' &
break
fi

sleep 1
i=`expr $i + 1`
done

USB Memory/HDD support on OpenWrt

USB HDD/Memory Stick support
  • kmod-usb2 - Kernel driver for USB2 controllers
  • kmod-vfat - Kernel modules for VFAT filesystem support
  • kmod-usb-storage - Kernel modules for USB storage support
  • kmod-ext3 - Kernel modules for EXT3 filesystem support
  • kmod-usb-core - Kernel Support for USB
"ipkg install kmod-usb2 kmod-usb-storage kmod-vfat kmod-ext3"


Configuring USB HDD Mount Points
mkdir /mnt/windows
mkdir /opt

vi /etc/hotplug.d/usb/01-mount
comment everythig under mount_storage() and umount_storage()
and insert
mount /dev/scsi/host0/bus0/target0/lun0/part1 /mnt/windows
mount /dev/scsi/host0/bus0/target0/lun0/part2 /opt
under mount_storage()

and

umount /mnt/windows
umount /opt
under umount_storage()

Make the following partitions on a USB HDD
  1. FAT32
  2. ext3
Connect the USB HDD to the router and
reboot at this point to get the usb drivers up and access the HDD

The partitions will be mounted at /mnt/windows and /opt

NTP and DCHP on OpenWrt

NTP Configuration
For NTP (install client)
"ipkg install ntpclient"

  • nvram set ntp_server=0.pool.ntp.org;nvram set time_zone="PST8PDT";nvram commit;echo "PST8PDT" > /etc/TZ; /usr/sbin/ntpclient -c 1 -d -s -h 0.pool.ntp.org
Configure DHCP Server Param

For DHCP lease time
nvram set dhcp_lease=43200 (for 12hours)
nvram commit

WPA Security on OpenWrt

WPA Security
To turn on WPA security you would have to install

* nas - Proprietary Broadcom WPA Authenticator/Supplicant
* wl - Proprietary Broadcom utility for setting wireless driver parameters
* wpa-supplicant - WPA Supplicant with support for WPA and WPA2

dep. libopenssl (0.9.8d-2)

easy way to install them are thru ssh with the command
"ipkg install nas wl wpa-supplicant"

Webif^2 on OpenWrt

To enhance your OpenWrt experience I would prefer to install Webif2
go to
http://x-wrt.org/ and scroll down to method2 (you need to have active internet connection) and select stable version


the router will automatically restart after installation

Now you will have a fabulous interface and lots of options

Wednesday, April 11, 2007

OpenWRT on Linksys WRTSL54GS v1.1

Just got my hands on a Linksys WRTSL54GS v1.1. It was $99 + tax at local Frys Electronics.

Downloaded latest OpenWRT (WhiteRussian 0.9)

Installation is pretty simple. Just go to the web interface at http://192.168.1.1 and go to Administration -> Firmware Upgrade

Browse... for the downloaded OpenWRT image and hit Upgrade

Took about 45s to display the "Upgrade is successful." confirmation page.
Give if about 2-3 minutes to format the filesystem and install the new image.

Click continue on the router upgrade page.

At this point you may or may not have access to the router from either web browser or telnet.
You might have to repair your LAN connection (by visiting Control Panel -> Network Connections).

If you still have issues bringing up the web interface, restart the router, release and renew the IP address of the local machine.

Once you get into the web interface and click any link on the page, you will be prompted to change/set the root password. You will be using this to login thru SSH or Web Browser. You will not have access to the router if you forget the password.


Now go to System -> Installed Software (You will be prompted to enter the login ID and password)

You can install and try out a variety of applications from here.

More posts to follow discussing all the cool applications that you can run using OpenWrt and to completely utilize your routers HorsePower.