/srv/irclogs.ubuntu.com/2010/12/31/#ubuntu-server.txt

=== WinstonSmith_ is now known as WinstonSmith
quentusrex_Anyone know how to create a cd that will boot and auto start ssh server?02:07
quentusrex_I have a headless server that I need to boot without a keyboard or monitor, that would allow me to ssh into it once it has started.02:07
Smaughey all i can't seem to get exim4 to work02:42
Smaugi configured it as per https://help.ubuntu.com/8.04/serverguide/C/exim4.html02:42
Smaugand then i typed02:42
Smaug>  /usr/sbin/exim -i address@domain.tld02:43
Smaug>  message02:43
Smaug>  CTRL+D02:43
Smaugas i was instructed to in the man page02:43
Smaugand nothing occurs02:43
Smaugor at least no email sent02:43
Smaugany help people can offer?02:43
Smaug(exim4 is a sendmail replacement)02:43
Turlis there any ubuntu sysadmin (from canonical) in here?03:22
The_Tickdoubt it03:22
patdk-wkisn't that what the payed support option is for?03:24
Turlpatdk-wk: I don't need support03:25
TurlI just want to tell them popcon.ubuntu.com is broken03:25
SpamapSTurl: working fine for me03:30
TurlSpamapS: yeah, the website is up&running, but it's been like 10 days without refreshing its information03:33
Smaugi have trouble beleiving no one ehre knows aobut exim03:33
Smaugcome on03:33
patdk-wkonly sendmail and postfix03:33
Smaugbut ubuntu *comes with* exim03:33
Smaugfor me03:33
Smaugand not sendmail03:33
patdk-wkcomes with postfix by default03:34
Smaugmine doesn't03:34
Smaugor at least doesn't have a man for postfix03:34
Smaug8.0403:34
patdk-wkprobably cause you didn't install postfix :)03:34
Smaugok so I should install postfix and come back03:35
Smaugis what you are advising?03:35
The_Tickumm03:35
The_Tickthere's a channel03:35
patdk-wknope :)03:35
The_Tickcalled #exim03:35
SpamapSTurl: right.. most of canonical is on holiday this week so it will most likely get looked at on Monday.03:35
patdk-wkI'm saying I can't help you with exim :)03:35
The_Tickpatdk-wk: zomg03:35
patdk-wkcause I dunno exim at all03:35
SmaugThe_Tick: it is dead.  i came here b/c i thought it was a standard enough sort of program03:35
The_TickSmaug: most people don't use exim03:36
Smaugpatdk-wk: fair enough03:36
The_Tickexcept for spammers03:36
SmaugThe_Tick: huh03:36
Smaugit came with my ubuntu03:36
Smaugwhy03:36
The_Tickso what?03:36
Smaugwould this occur03:36
The_Tickapt is so hard to use03:36
Smaugi thought i might as well use it03:36
The_Tickpeople couldn't possible install the mta they want03:36
The_Tickwell then maybe you should ask your question03:36
Smaug:)03:36
Smaugokay okay03:36
The_Tickand if anyone knows03:37
The_Tickthey'll speak up03:37
The_Tickotherwise don't berate the channel03:37
TurlSpamapS: right, I just emailed some ubuntu/canonical guys so I guess this will be looked at someday03:37
SmaugThe_Tick: i apologize to all for my berations03:37
Smaugyou are all my friends03:37
SmaugThe_Tick: (already asked my question an hour ago)03:37
Smauganyway03:37
Smaugwhat about03:38
Smaug"What MTA should I use?"03:38
Smaugi don't want anything fancy03:38
Smaugstandard03:38
Smaugsimple03:38
Smaugeasy03:38
Smaugworks03:38
Smaugsince exim seems to be a dead end support wise03:38
Smaugthis 2nd question of mine is an easy one to answer03:39
The_Tickyou're asking people the week between christmas and new years03:40
The_Tickand expect an irc channel to be alive03:40
The_Tickyou're hilarious03:40
The_Tickyou should use the mta you are most comfortable with03:40
SmaugThe_Tick: oh right03:40
SmaugThe_Tick: never used an mta before03:40
The_Tickwell then have you read any documentation?03:41
* Smaug does not celebrate christmas and has no plans for new years. no hatin03:41
The_Tickmost people do03:41
The_TickI'm just at work because I ran out of vacation03:41
Smaugi know. the former is my choice but the latter is just bad luck. :(03:42
Smauganywayz.  thanks for you being here.03:42
SmaugThe_Tick: i have.  I read instructions on how to03:42
The_Tickread any man pages?03:42
Smaugset up and configure exim, and the exim man page03:42
The_Tickok, good03:42
The_Tickany errors?03:42
Smaugnope. no errors03:42
Smaugjust doesn't send mail. :)03:42
The_Tickok, then you have it wrong most likely03:42
The_Ticksee if it's listening03:42
The_Tickif not, that's a good indication of the first problem03:42
Smaughow should I check that?03:43
The_Ticknetstat :)03:44
The_Tickyou'll need some switches03:44
The_Tickman netstat to find out which ones03:44
The_Tickbut it's likely netstat -na03:44
The_Tickthen you could grep for the right port03:45
=== root is now known as Guest71713
=== Guest71713 is now known as computerwiz_222
The_Tickyou aren't a computerwiz if you're ircing as root :P03:47
Smaugso, exim is not listening (at least nothing called "exim" is listening that I can see.  i do have a saslauthd listening03:47
computerwiz_222lol03:47
computerwiz_222that is my problem :P03:47
Smaugcia.com?03:47
computerwiz_222oh yes03:47
The_TickSmaug: and not cia.gov03:47
computerwiz_222lol03:47
patdk-wkthe_tick, and you aren't a scriptkiddie if you haven't hacked his root irc yet :)03:47
computerwiz_222alright.. i need some help actually03:48
The_Tickpatdk-wk: ya, I'd be someone who isn't interested03:48
computerwiz_222i am running 10.04 ubuntu server03:48
The_Tickthat's your first problem03:48
The_Tickinstall windows 2000 advanced edition03:48
computerwiz_222i've been running it for about 2 years.. and i know that irssi as root is a bad idea lol03:48
computerwiz_222but.. i'm stuck here03:48
Smaughow can you have been running 10.04 for 2 years03:48
The_Ticksome hosting company?03:48
computerwiz_222we..03:48
computerwiz_222ubuntu server in general03:49
The_TickSmaug: you can update the os03:49
computerwiz_222i like to keep current, you know03:49
computerwiz_222anyway03:49
computerwiz_222so.. i had one of my 1.5TB hard drives die on me today in my RAID array03:49
SmaugThe_Tick: indeed.  also, responded to your inquiry about the netstat03:49
The_TickSmaug: I'm not going to hand hold you here03:49
The_TickSmaug: you need to learn the ropes03:50
Smaugcan you point me towards some links at least?03:50
The_Tickanything I point you to would be something I found on googl03:50
The_Tickgoogle03:50
computerwiz_222i had to rewrite my fstab file because it had became corrupted for some reason03:50
computerwiz_222so i rewrote it, it works fine, but everytime i reboot it's corrupted03:50
computerwiz_222any ideas?03:50
computerwiz_222like.. mount -a is fine, no errors03:50
Smaugalright then tell me what I should search for at least.  when this problem comes up, what sort of things should be thinking about?  what do I need to learn?03:50
Smaugi know to check out error logs if a program has them03:51
Smaugi appreciate the time you've spent so far The_Tick03:51
Delerium_Smaug: First, do you understand how MTA / mails works?03:52
computerwiz_222does anyone have any ideas? My problem boils down to this.. everytime I restart, my fstab becomes corrupted03:52
The_Tickcomputerwiz_222: I've heard of this on clusters, can't remember what the problem is03:53
computerwiz_222The_Tick: I've been fighting with it for a while, and google is not much help on the issue03:53
The_Tickya, I remember those things03:54
The_TickI worked at a startup and we had this problem03:54
The_Tickbut the ceo fixed it03:54
The_Tickit was somethinga bout a version of cluster software03:54
The_Tickand some other crap03:54
computerwiz_222hmm...03:54
The_Ticksorry, I'm not being very helpful03:54
The_Tickit's been about 2 years03:54
computerwiz_222oh no, i appreciate anything you can say about the issue03:54
The_Tickmay not even be the same thing03:55
The_Tickbut I remember fstab getting corrupted03:55
The_Tickmount working03:55
The_Tickand it being a software raid03:55
The_Tickya, that's all I remember03:55
SmaugDelerium_: only at the most basic level03:55
Smaugi'm only trying to send mail03:55
The_Tickyou don't need an mta to do that03:56
computerwiz_222this is a pretty stock 10.04 server, with 4 hard drives (2 mirrored copies)03:56
The_Tickyou just need an mua03:56
computerwiz_222anyway.. i better go, i cringe running everything as root03:56
The_Ticklol03:56
computerwiz_222it goes against the fibre of my being :P03:56
computerwiz_222cya03:56
The_Tickcomputerwiz_222: errors?03:56
computerwiz_222errors03:56
The_Tickin dmesg or anything03:56
The_Tickbefore you go03:56
computerwiz_222hmm03:56
SmaugThe_Tick: ty03:56
The_Tickthat's where I'd start03:56
computerwiz_222alright03:57
SmaugThe_Tick: that is helpful advice03:57
computerwiz_222i'll check it out03:57
The_TickSmaug: dmesg was for computerwiz_22203:57
computerwiz_222thanks, i'm sure i'll be back, and running irssi in screen next time03:57
computerwiz_222cya03:57
The_Ticklol03:57
The_Ticklater03:57
Delerium_Smaug: if you only want to send mail, I guess you can use your ISP provider SMTP as the relay04:01
Smaugok04:02
Delerium_Never used exim but check this: https://wiki.archlinux.org/index.php/Exim_with_a_remote_SMTP_server04:03
The_Tickthe problem is the isp probably knows more04:03
The_Tickand doesn't allow relay04:04
Delerium_Depend of ISP I guess... mine work just fine04:04
Delerium_I use it to send mail from my home server04:04
computerwiz_222The_Tick: Hey, so I solved my problem -- I had been using "defaults" for the options for mounting my data partition *headbash*04:15
The_Tickhaha04:15
The_Tickwhat I said got you thinking?04:15
computerwiz_222The_Tick: yeah, tbh.. sometimes i just need the moral support that #ubuntu-server gives haha04:16
The_Tickya man04:16
The_Tickhalf the time you stare at it too long04:16
computerwiz_222getting frustrated at annoying fstab issues will cause me to do stupid things like run irssi as root04:16
computerwiz_222exactlyu04:16
The_Tickand then someone says something, not even related04:16
computerwiz_222pretty much lol04:17
The_Tickseen the tv show house?04:17
computerwiz_222yeah, but i'm not a religious watcher or anything04:17
The_Tickyou know the moment when someone says something stupid04:18
The_Tickthen he gets a look in his eye04:18
The_Tickand dashes off?04:18
The_Tickthat's that moment :D04:18
computerwiz_222lol yep04:18
computerwiz_222it's frustrating.. this past fall, I designed a point-of-sale system for a company I work for, entirely based on Ubuntu04:18
computerwiz_222when something like this happens, it makes me want to toss my home server out onto the street because I *should* know how to fix it :P04:19
computerwiz_222anyway, just thought you might like to know the solution.. pretty simple04:19
The_Tickyea04:19
The_Ticknot bad04:19
The_Tickmakes me think that there is a need for a "proper configuration scanner" utility04:20
computerwiz_222python scripts anyone? lol04:20
The_Tickthat scans for all hardware and then the software configurations and generates a report04:20
computerwiz_222oh that would be a deadly script :P04:20
The_Tickyea04:20
computerwiz_222anyway, i can finally try streaming to my new android tablet04:21
The_Tickoh crap04:21
The_TickI get off work at midnight04:21
computerwiz_222the server has been off for about 2 days out of sheer holiday laziness04:21
The_Tickfuck04:21
computerwiz_222thanks for your help, ttyl04:21
dschuettwhat does everyone use for a packet sniffer on ubuntu server?04:39
sabgentontcpdump04:40
sabgenton tcpdump -i eth004:40
sabgentoneg04:40
The_Tickdschuett: wireshark is likely the defacto gui04:41
sabgentontcpdump alone will run the default nick04:41
sabgentonyes wire shark if you have grafics04:41
sabgentonwhich ubuntu-server doesn't have by default04:42
sabgentonI have a wlan0 nic and an eth0 nic04:43
sabgentonI'm trying to make wlan0 my wan and nat eth0 to it04:43
sabgentonit doesn't work for ages and then just starts working04:43
sabgentonrestarting the computer start the proccess all over again04:44
StrangeCharmi'm trying to ssh to a machine whose key has changed. how can i override ssh's complain and connect to the machine anyway, saving the new key?04:44
sabgentonits  very weird I feel something is wrong with the distro to do this04:44
qman__StrangeCharm, remove the offending key from your ~/.ssh/known_hosts04:44
sabgentonor the ath5k driver04:45
qman__it tells you which line the key is on in the error04:45
sabgentonkernell updates haven't fixed this for me04:45
StrangeCharmqman__, there isn't a command line instruction for 'ignore this' ?04:45
qman__not that I'm aware of04:45
dschuettsabgenton: tcpdump works fine, but what i am noticing is that it is getting flooded with ssh packets since i am shh into the server that i am running tcpdump on. Like it literally floods the screen with packets???04:48
sabgentonyou can grep out the ssh stuff04:49
sabgentonbut you have to use -l04:49
sabgentonit turns off tcpdumps buffering04:49
sabgentonbuffering stuffs up pipes04:49
qman__don't use grep04:49
sabgentonit's  a pain in bash04:49
qman__use tcpdump's built in filtering04:49
sabgentonqman__: -l04:50
sabgentonturns it off04:50
sabgentonwell buffering anyway04:50
qman__not needed04:50
qman__tcpdump has a built in filtering system designed at choosing the packets you want to see04:50
sabgentonoh04:50
qman__based on ip, interface, port, etc04:50
sabgentonqman__: example04:50
sabgentonssh04:50
sabgentonport 2204:50
sabgenton?04:51
qman__tcpdump -i eth0 port ! 2204:51
qman__would filter out ssh traffic04:51
sabgentoncool04:51
StrangeCharmqman__, is there a command for 'remove line number # from this text file' ?04:51
qman__http://danielmiessler.com/study/tcpdump/04:51
sabgentonI  did like tcpdump -li eth0  |grep -v 2204:51
sabgentondschuett: ignore me qman__  is way cooler :)04:52
sabgenton-e gives you some good info too04:52
sabgentonforget what04:52
qman__StrangeCharm, I'm sure it's possible but I don't know off the top of my head, I just use vi04:53
dschuettthanks guys!04:53
StrangeCharmqman__, surely, you mean emacs04:54
qman__no, I mean vi04:54
qman__use what you know, and I know vi04:56
sabgentonqman__: so an ip would be host ! 10.1.1.504:56
sabgenton?04:56
qman__sabgenton, the ! means not04:57
qman__so if you wanted to see all traffic except ssh, you'd use port ! 2204:57
sabgentonyeah would that exculed that IP I mean04:57
qman__but to see all traffic to a host, you'd use dst 10.1.1.504:57
sabgentonqman__: to see all traffic but 10.1.1.5 would you do  host ! 10.1.1.504:58
sabgenton?04:58
qman__I don't know if "host" works, but yet04:58
qman__yes*04:58
qman__src and dst work04:58
sabgentonah04:59
sabgentonhost might be both I think04:59
sabgentoncould be wrong04:59
qman__you can combine with && and ||04:59
sabgenton?04:59
qman__criteria04:59
qman__the words "and" and "or" also work05:00
qman__dst ! 10.1.1.5 && port ! 2205:00
StrangeCharmqman__, i just of course to the religious wars of old05:00
sabgentonI though bash would  see port as the next command05:01
StrangeCharmmy server currently gets its ip via dhcp. how can i give it a static ip assignment which will survive a reboot?05:01
qman__StrangeCharm, I know all about them, and I still choose vi05:01
qman__I much rather its multi press control key style than modifiers05:01
StrangeCharmqman__, it makes no difference to me which editor you use, i was just pulling your leg05:02
qman__sabgenton, no, that doesn't get interpreted by bash, it's all in a row as part of tcpdump's args05:02
qman__if you use & or | it will, though05:03
qman__that's why it uses the double form05:03
qman__StrangeCharm, configure it in /etc/network/interfaces05:03
qman__see man interfaces for details on how05:03
sabgentonok but like cd someware && echo foo05:03
sabgentonis two differnet things05:03
sabgenton like cd someware ; echo foo ;05:03
StrangeCharmqman__, wonderful05:04
qman__sabgenton, yes, but in this case, it all gets interpreted by tcpdump05:04
qman__some kind of voodoo or whathaveyou05:04
sabgentoninteresting05:04
* sabgenton shakes05:04
qman__I am not a programmer, so I couldn't tell you exactly what it does05:04
qman__but I'm sure someone can05:04
sabgentonhas any one had nat issues with the orriganal ubuntu server lts05:04
sabgenton10.0405:05
qman__the original LTS is 6.0605:05
sabgentonyou get wada mean05:05
sabgentonbefore the point release05:05
qman__I upgraded my router straight to .105:06
qman__due mostly to procrastination05:06
qman__first thing to check05:06
sabgentonI might try the new ubuntu just to see if my problem will fix05:06
qman__cat /proc/sys/net/ipv4/ip_forward05:06
qman__should be 1 for a router, 0 for all others05:07
sabgentonqman u name it I checked it05:07
sabgentonits 1 promise05:07
qman__and you have iptables set up to masquerade?05:08
sabgentonnat works affter leaving the computer on for a very long time05:08
sabgentonwhich is totaly werid05:08
qman__well, that narrows the scope of the problem slightly05:08
qman__do you have networkmanager in any incarnation installed? if so, remove it05:09
qman__it causes all sorts of bizarre issues with manual configurations05:09
StrangeCharmqman__, how do i apply those changes? can i just put the connection down then up again?05:10
qman__StrangeCharm, sudo service networking restart05:10
sabgentonqman__: is there one by default?05:10
sabgentonother wise no05:10
qman__though sometimes dhclient keeps running in the background messing things up05:10
qman__so check to make sure it's killed off afterward05:10
StrangeCharmqman__, well, this could be entertaining, since i'm sshing to the machine05:11
qman__sabgenton, not out of the box, but some packages recommend it, and ubuntu installs recommends by default05:11
sabgentonqman__: list some?05:11
qman__too many to list05:11
sabgentonI haven't installed much so dont' think so05:11
StrangeCharmqman__, it complains that "restart: unknown instance"05:12
qman__best way to check is `dpkg -l | grep -i networkmanager05:12
qman__`05:12
qman__StrangeCharm, upstart lost track of it apparently05:12
sabgentonno results05:12
qman__I run into that a lot05:12
qman__rebooting fixes it, but that can be problematic05:13
StrangeCharmcan i just use an init.d script?05:13
sabgentonqman__: do you think theres any chance of the wifi driver refusing netfilter wanting to nat?05:13
qman__sabgenton, probably not05:13
qman__sabgenton, more likely is that the wifi network is not reporting as up properly and activating the nat05:13
qman__how are you activating your nat script?05:14
sabgentonshorewall05:14
qman__StrangeCharm, I don't know if network still exists in init.d05:14
qman__you can try it05:14
StrangeCharmqman__, i did, to rapturous success05:15
qman__sabgenton, well, I don't know anything about how shorewall works, so I can't really tell you whether that's the problem or not05:15
qman__nothing against it, I just don't know what it does under the hood05:16
sabgentonqman__: it just basicly types in iptable commands for you05:16
sabgentonit doesn't really run as a dameon at all05:16
qman__yes, but the key here is when it runs them05:16
qman__boot time, if-up.d, dhclient-exit-hooks.d, or elsewhere05:16
Patrickdkonly when manually told to, or via startup script05:17
Patrickdkunless you have shorewall-init installed then I think it will do it via if-up.d also05:17
sabgentoniptables -L -v looks good acording to #shorewall05:17
sabgentonok I guess I should do some manual iptables commands05:17
Patrickdkshorewall-init doesn't exist in ubuntu yet, so :)05:17
sabgentonPatrickdk: what does that do:?05:18
qman__well, your nat needs to be flushed and re-applied each time you get a new DHCP lease in order for things to work smoothly05:18
Patrickdkit restarts shorewall each time a nic comes online05:18
qman__if-up.d is the best place05:18
PatrickdkI think05:18
sabgentonPatrickdk: who cares I can just shorewall restart right?05:18
PatrickdkI also think it sets a default iptables policy on boot too, basically all locked down, till everything is up, and shorewall starts05:19
Patrickdkyep05:19
Patrickdkassuming you don't use dhcp05:19
sabgentonqman__: if you type shorewall clear it removes all the tables it made05:20
sabgentonthen just run shorewall start again05:20
sabgentonputs em back new05:20
sabgentonthat will flush reaply nat05:20
Patrickdkthe rules, it won't flush nat05:21
qman__yes, but (if you use DHCP) it must be done every time there is a new lease05:21
Patrickdkas in conntrack/...05:21
sabgentonPatrickdk: shorewall clear && shorewall start05:21
sabgenton?05:22
qman__though that would manifest as a working network breaking at regular intervals05:22
sabgentonthat will fush nat?05:22
qman__you seem to have the reverse problem05:22
qman__indicating that something else is wrong05:22
sabgentonI mean it removes it completely05:22
sabgentonPatrickdk: ?05:22
sabgentonremoves then installs again05:22
Patrickdkshorewall clear only removes iptables rules05:22
Patrickdkit does nothing about connection tracking tables and other things05:22
sabgentonnot nat?05:22
sabgentonoh05:22
Patrickdkit just says not to use nat anymore05:22
Patrickdkit doesn't *flush* nat05:22
sabgentonok but didn't it set up nat?05:23
sabgentonok wait05:23
Patrickdkyou don't setup nat, you make a iptables rule that says to use it :)05:23
sabgentonso when you flush nat that doesn't have to be configured to nat apartcicular thing?05:23
sabgentonok05:23
sabgentonso yes05:23
Patrickdkif your conntrack is broken before you clear iptables, it will be broken afterwards too05:24
Patrickdkbut normally you can't really break it05:25
sabgentonqman__: ok mabye your on to somting pardon me05:25
Patrickdkunless you are really trying to05:25
sabgentonhow do I flush nat?05:25
PatrickdkI think you have to install the conntrackd util05:25
sabgentonI manually run dhclient well after the computer starts05:25
sabgentoncould this be my problem?05:25
qman__yes05:25
Patrickdkheh, configure it with a static ip :) be done with it :)05:25
qman__configure /etc/network/interfaces correctly05:26
qman__and don't ever run dhcliet manually05:26
sabgenton:(05:26
sabgentonyeah but you learn more05:26
qman__if you need to refresh, ifup/ifdown or service network restart05:26
sabgentonlike your tcpdump guide :P05:26
qman__dhclient is one of those programs that lingers in the background05:26
sabgenton(like I'm painfully learning now :P)05:27
qman__messing with things long after you're done05:27
sabgentonqman__: "if-up.d is the best place"05:28
qman__dhclient should only ever be run manually on a non-configured or disabled interface05:28
sabgentonfor what?05:28
qman__for your firewall script05:28
sabgentonoh like some iptables lines?05:29
sabgentonor stick shorewall in there05:29
sabgentonI think the interface does start disabled nonconfiged05:30
sabgentonI run wpa_suplicant then dhclient05:30
sabgentonby hand05:30
Patrickdkand run shorewall start after those?05:30
Patrickdkor shorewall restart05:30
qman__you should probably place a script which contains "shorewall clean && shorewall start" in /etc/network/if-up.d/05:31
Patrickdkno clean needed, just shorewall restart05:31
Patrickdkclean basically means, disable firewall05:31
qman__as long as it's smart enough to clear out old rules first05:31
Patrickdkit's smarter than that, it loads them in the correct order to not kill existing connections :)05:32
Patrickdkand clear out the old rules05:32
qman__I write mine myself, so they always start with iptables -F, -t F, -X, etc05:32
sabgentongee I'm tring to take in all this dhcp stuff05:33
qman__er, -t nat -F05:33
Patrickdkqman, ya, that is how I did it for years, I gave up about a year ago or so, my firewalls started getting way too complex05:33
qman__my current one reads port forwards from a human-readable list in /etc05:34
Patrickdkmine is managing interactions of over 14 different interfaces05:34
qman__hah, that's pretty complex05:34
Patrickdkit's over 2000 iptables lines05:34
qman__mine only has four05:34
Patrickdkya, basic nat firewalls are easy enough by hand :)05:35
Patrickdkjust accouting for changes and bad interactions when it gets bigger is just too much work05:35
qman__I bet, keeping track of that many without some sort of visual aid would be difficult05:36
qman__four interfaces, that is, not lines :)05:37
qman__I know a simple two-interface nat can be done in four lines05:37
Patrickdkya, my 3 and 4 interfaces by hand I used was about 80 or so iptables lines05:38
Patrickdkbut then, that is mostly dnat/snat stuff05:38
Patrickdkhmm, system happier, gave it one more drive spindle to play with :)05:38
Patrickdk8 drives in my workstation now :(05:39
qman__heh05:39
Patrickdkwd re4 are freaking fast :)05:40
Patrickdknot as good as sas, but close05:40
qman__not too many toys to play with here, working with next to nothing budget05:40
PatrickdkI'm attempting to build my replacement server, old one needs to die, 10years old almost05:41
qman__but every once in a while I get something new, got a new WAP to set up05:41
Patrickdkdual 1.4ghz p3, 4gig ram and 8 146g 15k scsi drives05:41
qman__nicer than most of mine05:42
Patrickdknew system looks to be a dual quad 2.5ghz 48gig ram, 8 300g sas 15k and probably throw some ssd's in there also05:42
qman__my web server is a P4 1.4 desktop05:42
Patrickdkmine can't do webserving :(05:43
Patrickdkhad to put the database on another server so it could handle the load05:43
qman__monthly hits here are in the 1000-range05:44
qman__not exactly high demand, just enough to put off most freebie hosts05:44
Patrickdkdamn, I hit my own systems up more than 1000 times a month :)05:44
qman__and wanting to implement an online reservation system makes hosting it myself more attractive05:44
qman__I may be working with old junk, but most if it's old enough junk that it's unlikely to fail05:46
qman__built before computers were throw away items :)05:47
patdk-lapheh, except for capacitors, they have fixed life spans :(05:47
patdk-lapbut old enough, it's before the bad knockoff ones where used :)05:48
qman__yeah05:48
qman__file server is a prime example, system drive is a 4GB quantum fireball, it outlasted two SATA disk arrays in the same system05:49
patdk-lapya, I have some 8gig ide's that where still working perfectly good05:49
patdk-lapretired it, cause I don't have a computer with ide anymore05:50
patdk-lapI have a 4x8 shelf full of ide/scsi/fc disks05:50
patdk-lapall just old and small capacity, still work, but too slow for my usage05:50
sabgentonqman__: so why doe nat care about dhcp?06:11
sabgentonwhen it is flushed06:11
sabgentonI thought dhcp just gave an ip adress same as if you did it static06:11
qman__sabgenton, it doesn't, but when a DHCP lease expires, and you get a new address, your interface goes down and up06:11
qman__and your previous nat configuration based on the previous address will no longer work06:12
sabgentonoh is that all06:12
qman__so it needs to be reloaded06:12
sabgentonwell my ip hasn't changed at all so then this is not the isuse06:12
sabgentonit gets the same ip back06:12
sabgentonand has done for the last ever06:13
sabgentonbesides restarting the computer would flush nat right?06:13
qman__yes06:13
sabgentonand when i restarted it last it picked up the same ip06:13
qman__as I said, this is not likely the problem you're experiencing, since this problem would manifest as a working connection breaking periodically06:13
sabgentonhm unless nat was configed for no ip?06:13
sabgentonthat maybe?06:13
sabgentonon boot there will be no ip on the card i think06:14
qman__your firewall will need to be run after the network is up06:14
sabgentonqman__: so will the nat tables be done to no ip?06:14
sabgentonqman__: Im still confused06:24
sabgentonif turn the box on there is no nic on wlan006:25
sabgentonno ip I mean06:25
sabgentonis there a nat configured to no ip06:25
sabgentonI'm tring to understand what nat is if I have no iptables up06:25
sabgentonwhen I  run dhclient is nat someware set with the found ip06:26
sabgentonI thought it was when i run iptables  or in my case shorewall06:26
sabgenton(after that)06:27
qman__it is06:29
qman__if you attempt to configure nat while the interface is down, it won't work06:29
sabgenton well I'll try and set it all up in interfaces06:33
sabgentonI think i tryed  and gave up06:34
sabgentondoing everything there06:34
sabgentonjust didn't the non-distro independent way06:34
sabgentonstill feel it won't solve my problem06:34
patdk-lapI say, forget dhcp06:36
patdk-lapjust setup everything in /etc/network/interfaces using static ip06:36
sabgentonyeah it's just on a wifi card and its confusing06:36
sabgentonpatdk-lap: Is there anything I can run to monitor when it just starts working?06:40
sabgentonI don't know what I'd be looking for but06:40
patdk-lapfor basic stuff like that I use:06:44
patdk-laphmm, paste broken :(06:44
patdk-lapgoogle: watchping06:44
=== squishy is now known as SquishyNotHere
_Techie_i have just setup a third IC in my server and am unable to figure out why i cant get one of my interfaces thats attatched to my internal network working correctly08:00
_Techie_if i have eth3 as my external interface, and eth1 and eth0 as my LAN interfaces, can they both have the same ip, or do i need to implement a bridge of some sort, i dont need cross talk betweet eth0 and eth1 yet08:02
_Techie_i currently have eth1 working fine, but eth0 doesnt seem t be workin coprrectly08:03
_Techie_okay, let me re word things a bit, is there anything special i need to do when setting up a point to point connection between ubuntu-server and a windows machine when using a patch cable and no switch/router?08:16
gobbeyou cannot have same ip in two interfaces without bonding08:18
gobbeif they are attached to same network08:19
gobbe_Techie_: no, there's no special things when using patch cable between two computers08:19
gobbeso what do you want to do and what is not working08:19
_Techie_well i had 2 NIC's in my machine before, one for net and the other for LAN08:20
_Techie_worked fine08:20
_Techie_added a new NIC in, now totalling 308:20
gobbeyes08:21
_Techie_ive shifted the configurations aroud to the new interfaces08:21
_Techie_cloned my routing rules t the new interface08:21
gobbecan you ping from windows-machine to ubuntu?08:21
_Techie_and one of my LAN interfaces is still not functioning properly08:21
_Techie_no, i cant ping from windows to anything08:22
gobbeso what is configuration in ubuntu at this interface?08:22
_Techie_however everything attatched to the other interface is fine08:22
gobbe_Techie_: /sbin/ifconfig08:22
gobbeand pass that to pastebin08:22
_Techie_mind if i ue srunge intead?08:23
_Techie_sprunge?08:23
gobbeok08:23
gobbejust somewhere else than direct paste here :D08:24
_Techie_http://sprunge.us/QNhh08:24
_Techie_the only differences between eth0 and eth1, is eth0 is a gigabit direct cable to my pc08:24
gobbewell, there's problem08:24
gobbelike i told08:24
gobbeyou cannot have same ip in two interfaces08:25
gobbeyou need to change eth0 or eth108:25
_Techie_would i have to change the gateway address in my DHCP server aswell?08:26
_Techie_i know its a pretty dumb question, but id rather look like a noob than have to do things twice08:26
gobbei don't know what do you try to do?08:27
gobbebe able to access internet from windows-machine?08:27
_Techie_at this point in time08:27
_Techie_i have a networked printer which will call for bridging at a later time08:28
_Techie_but getting basic functionality is what i want at the moment08:28
gobbewell, you just change other interface IP and do NAT in your ubuntu08:28
gobbeipforward + nat08:28
gobbethat's it08:28
_Techie_i flicked eth0's ip up by one and still no luck08:30
gobbewindows-machine is not able to ping?08:31
_Techie_nup, no pinging08:31
_Techie_what abot bridging the two interfaces?08:31
gobbe_Techie_: so what is IP's now?08:31
_Techie_its at 192.168.10.208:31
gobbeno, you need to change whole network08:32
gobbesorry, wait08:32
gobbewhat is IP in windows-machine?08:32
_Techie_192.168.10.5008:32
gobbechange ubuntu to 192.168.11.1 or something and windows to same subnet08:32
gobbei believe that there's still problems with returning packets08:33
_Techie_http://sprunge.us/SKQR08:34
_Techie_well, taht works08:34
gobbeyep08:34
gobbeand if you need to connect to internet, check out ip forwarding and NAT08:35
gobbethere's good manual for that08:35
_Techie_okay, so now that things are functioning, i needa set up a bridge between the two08:35
_Techie_ive already setup NAT through iptables08:35
gobbehttps://help.ubuntu.com/community/Router'08:35
gobbe- '-mark08:35
_Techie_its a server machine i built awhile back, so everything is already setup08:35
_Techie_the only thing new is the interface eth308:36
_Techie_do you know how to set up a bridge between two interfaces?08:36
gobbewhat kind of bridge?08:39
_Techie_well, im able to modify my dhcp server so that it gives my machine a ip on 192.168.11.X08:41
_Techie_however i have a networked printer attatched to the other interface @ 192.168.10.9008:41
_Techie_oh08:41
_Techie_dw08:41
_Techie_doesnt seem to be a problem08:41
gobbeyep, it should not be if you have ip forwarding08:41
_Techie_thanks for your help gobbe08:51
gobbenp09:28
sabgentondoes crontab mynewcronfile11:30
sabgentonerror check11:31
sabgentonor do you have to crontab -e for that11:31
gobbesabgenton: yes it does11:40
sabgentonok so you don't have to use -e11:44
sabgentonto be safe11:44
uvirtbot`New bug: #695944 in apache2 (main) "update apache2 in lucid or backport some features?" [Undecided,New] https://launchpad.net/bugs/69594412:07
sabgentonwhen a user runs crontab -e where is it installed to?12:08
sabgentonthe new cron file12:08
gobbeyep12:24
sabgentonwoop12:24
gobbe/var/spool/cron/crontabs12:25
uvirtbot`New bug: #695968 in krb5 (main) "kerberized telnetd is not working (Error: All terminal ports in use.)" [Undecided,New] https://launchpad.net/bugs/69596812:26
screen-xHi all, which is the recommended slapd configuration method in 10.04, slapd.conf or cn=config?13:37
thewrathi used that a while ago i think i used slapd.conf13:38
thewrathbut wait for a person who has used it more than what I have13:38
screen-xthewrath: Yeah, I was using slapd.conf in 8.04, but I recently installed a 10.04 server, which defaulted to cn=config which I don't really understand yet.13:38
=== viezerd- is now known as viezerd
pmatulisscreen-x: ubuntu uses cn=config now14:04
screen-xpmatulis: ok, so I should invest time and learn to set it up. I was confused as the debconf stuff didn't prompt for a root password, so I couldn't bind with an ldap browser in order to configure cn=config.14:05
pmatulisscreen-x: yes, this is the standard now, best to get onboard14:06
screen-xok, I've got a few articles to read, I'll have a go. Thanks pmatulis14:07
=== deegee_ is now known as deegee
lieuwe[49ft]is it possible to have an ip whitelist for a specific port?15:51
lieuwe[49ft]also, is it possible to stdin/stdout to/from an upstart job? i need to be able to do some server commands15:57
FrenkHey people. I just set up my new server and I want to test how snorby and iptable works. Can you do me a favour and scan 88.198.57.242 (nmap or whatever you like). I dont need the result, just want to see how the server reacts! Would be really kind!16:39
AndyGraybealwoh, sorby i never heard of that.. is it something to do with snort?16:41
AndyGraybealsnorby16:42
Frenko mean snort >D16:42
FrenkI did some configurations and as I dont have a Botnet I kindly ask you to do it.16:43
AndyGraybealhow did you get snorby froom snort on the keyboard!  lols16:43
FrenkAndyGraybeal: snorby was what i looked for - a ruby application for snort16:44
AndyGraybealaaah16:45
AndyGraybeali nmap a few times to the ip16:45
AndyGraybeali don't kno whow to do anythign too creative16:45
Frenknmap is great16:45
AndyGraybealdid your computer respond appropriatly to my nmaps?16:48
Frenklets see >D16:48
Frenknope -(16:49
FrenkAndyGraybeal: could you run just like this: nmap -T4 -A -v -PE -PS22,25,80 -PA21,23,80,3389 88.198.57.24216:58
=== SquishyNotHere is now known as squishy
nailoraon a fresh install i get the following warning over and over again: "perl: warning: Setting locale failed. perl: warning: Please check that your locale settings: ..." running "sudo locale-gen en_US.UTF-8" fixes it. however i think this is just a workaround. what would be a proper fix?17:11
=== Hero_of_Mordor is now known as mordor_away
=== mordor_away is now known as mordor_gone
RoyKhi all. anyone here that knows some decent backup software that will allow me to backup remote windows machines to an ubuntu or solaris or something?18:04
Nafallobackuppc?18:04
RoyKah18:04
RoyKdidn't know that one18:05
Nafallohmm. is it still in main even?18:05
Nafallo!info backuppc18:05
ubottubackuppc (source: backuppc): high-performance, enterprise-grade system for backing up PCs. In component main, is optional. Version 3.1.0-9ubuntu2 (maverick), package size 548 kB, installed size 2376 kB18:05
Nafallo\o/18:05
compdocclonezilla18:07
RoyKclonezilla doesn't look like a good solution over time (with incremental backups etc)18:10
thewrath?18:11
compdocyeah, its good for monthly images18:12
RoyKI don't really need that - just data backup18:12
compdocbackula sounds good, but seems a bear to set up18:13
compdoctheres another Ive heard of but havent tried: remastersys18:14
RoyKI'm running bacula at work with some 100TB storage units, and it works well, but not for clients behind nat - bacula works with a director contacting the clients (file agents), which then contacts the storage agent, and with clients behind nat, it'll require port forwarding for this to work, something I don't want18:16
=== KB1JWQ is now known as Corey
FreezingCold_How do I run ZNC as nobody?19:32
e_t_If I delete /etc/udev/rules.d/70-persistent-net.rules, will the file be regenerated. or will I be left without network interfaces?19:33
=== mordor_gone is now known as Hero_of_Mordor
RoyKe_t_: it'll be regenerated19:54
RoyKe_t_ phone home...19:55
=== Hero_of_Mordor is now known as mordor_is_gone
cn1209is there a free gui to manage cron jobs. I want to setup a cron that will ssh into another server and run a command. I can do this the old fashion way but would like to setup a GUI. Any ideas or addons?20:33
RoyKcn1209: doing it from the commandline would be quite easy20:37
RoyK!webmin20:37
ubottuwebmin is no longer supported in Debian and Ubuntu. It is not compatible with the way that Ubuntu packages handle configuration files, and is likely to cause unexpected issues with your system.20:37
cn1209RoyK: Understood. But I would like management tool for someone else to manage.20:37
cn1209ubottu: Cpanel might do the job but I'm looking for something free / open source.20:38
ubottuError: I am only a bot, please don't think I'm intelligent :)20:38
cn1209lol20:38
RoyK!ebox20:38
ubottuebox is a web-based GUI interface for administering a server. It is designed to work with Ubuntu/Debian style configuration management. See https://help.ubuntu.com/community/eBox20:38
RoyKubottu: no, webmin is no longer supported in Debian and Ubuntu. It is not compatible with the way that Ubuntu packages handle configuration  files, and is likely to cause unexpected issues with your system20:39
RoyKubottu: no, webmin is no longer supported in Debian and Ubuntu. It is not compatible with the way that Ubuntu packages handle configuration  files, and is likely to cause unexpected issues with your system, see ebox20:39
RoyKubottu: no, webmin is no longer supported in Debian and Ubuntu. It is not compatible with the way that Ubuntu packages handle configuration  files, and is likely to cause unexpected issues with your system, see ebox20:39
cn1209RoyK: The entire purpose is to ssh into my esxi box an run a backup command. Just want to be able to manage it. I'm looking into ebox. I'll see if that's what I'm looking for. Thanks20:42
RoyKcn1209: I'd suggest using the commandline - stuff like webmin or ebox somehow simplifies things, but learning the real stuff takes you longer20:45
RoyKthat is, it leads to learning more20:45
StrangeCharmhow do i mount a usb disk? i think it's ntfs or fat32, probably ntfs, since it's used by a windows machine, and probably contains large files21:41
RoyKheh - typical newbie idiot - ask a question, part 2 minutes later21:51
Slybootsx3HEhh..22:03
SlybootsIs there a way to tell what sort of RAM I have installed?22:03
Slybootswithout shutting down the machine?22:03
RoyKprtconf?22:03
SlybootsMm.. no such command? and nothing in apt..22:04
RoyKoh22:05
RoyKlshw22:05
RoyKsorry - was thinking about solaris22:05
SlybootsSweet22:08
SlybootsThere is a part-number22:08
SlybootsTF!22:09
SlybootsIt costs more than my new DDR3 ram cost!22:09
qman__of course, DDR3 is the cheapest you can buy22:09
* Slyboots mutters under his breath22:10
SlybootsThe board only takes DDR2 though.. :P22:10
SlybootsPlus Im sure mixing DDR3 and 2 is asking for trouble ;)22:10
qman__the older it is, the more expensive it is22:10
qman__there are exceptions but that's the rule22:10
RoyKSlyboots: mixing DDR3 and DDR2 is asking for trouble indeed22:11
SlybootsAye22:12
SlybootsWell my poor file-server needs more RAM22:12
SlybootsVirtualmachines are pretty demanding22:12
Slyboots16mb free :P22:12
RoyKSlyboots: pastebin free22:13
qman__my file server is running DDR22:13
SlybootsIts in TOP22:13
RoyKSlyboots: still, pastebin free output22:13
SlybootsMem:   1538544k total,  1523360k used,    15184k free,    31788k buffers22:13
SlybootsHardly worth pastebinning a single line22:13
qman__he meant the command `free`22:14
SlybootsActually I could get more out of the system.. 512mb is allocated to video mem that I wont need..22:14
RoyKSlyboots: doesn't say much - linux uses tons of memory for caching22:14
Slybootshttp://pastebin.ca/203530922:14
RoyKso, 400 megs free22:14
qman__yeah22:15
RoyKnot a lot of memory in there22:15
Slyboots2gb stick;l 512mb allocated to Vidram22:15
qman__you're not out of memory yet22:15
SlybootsProbelms is I dont have a monitor so I Cant.. acces s the bios22:15
SlybootsSo hy the hell is virtual machines so slow?22:15
qman__but I have to wonder why a file server has more than ~16MB allocated to video22:15
RoyKSlyboots: increase swappiness22:15
RoyKSlyboots: sysctl vm.swappiness = 10022:15
Slybootsqman__: it used to be a xbmc video center22:15
RoyKthat'll make linux swap out earlier22:16
Slyboots.. isng swapping bad?22:16
RoyKSlyboots: also, the bios settings should allow for less memory overhead from the graphics card22:16
RoyKno, it's not22:16
RoyKswapping is good22:16
SlybootsRoyK: Odds are it does; but.. I dont have a moniotor x.x22:16
SlybootsSo I cant access the bios lol22:16
RoyKswapping out things that aren't in use is good22:17
qman__swapping is good if your disks can keep up22:17
qman__it's bad if they can't22:17
Slybootsnot sure how good my disks are; its a RAID5 array..22:17
RoyKqman__: it's mostly good for dead processes22:17
Slybootsfor my needs its suitable but faster is always better22:17
Slybootshow do you benchmark disks anyway?22:18
SlybootsIn windows there are LOADS of programs for that sort of thing but..22:18
Slybootswith linux server Im a bit lost22:18
qman__for a simple ballpark, hdparm -tT22:18
RoyKSlyboots: a lot of processes allocate memory not needed. this can be swapped out and the memory gained can be used for something useful22:18
qman__if you want some write speed estimates, dd some files22:19
SlybootsWell if it can make the VM's faster all the better22:19
RoyKset swappiness to 10022:19
RoyKtry that22:19
Slyboots/dev/md0: Timing cached reads:   1070 MB in  2.00 seconds = 534.99 MB/sec Timing buffered disk reads:   94 MB in  1.68 seconds =  55.97 MB/sec22:19
Slybootsthat doesnt seem terribly fast22:19
qman__it isn't22:19
RoyKit's decent, but not fast22:19
RoyKhow many drives?22:19
SlybootsEh.. 3?22:19
Slybootsin a RAID5 configuration22:20
SlybootsSegate.. somethings22:20
RoyKnot 5k4 drives?22:20
RoyKthat's asking for trouble22:21
qman__/dev/md0: Timing cached reads:   1598 MB in  2.00 seconds = 799.56 MB/sec Timing buffered disk reads:  432 MB in  3.00 seconds = 143.79 MB/sec22:21
Slyboots.. wait what?22:22
qman__7 disk raid 6, 7200RPM22:22
SlybootsSegate greens22:22
Slybootso.O22:22
Slyboots.. wha?!22:22
qman__oh boy22:22
qman__green drives, that's why22:22
SlybootsThat *cant* be right22:22
qman__anyuway22:22
SlybootsMm.. shit :P Well they work OK for now22:22
qman__while not exactly fast, it's not horrendously slow22:22
qman__it'll work22:23
SlybootsAYe; for file transfers on my need the target machines are going to be the bottlenecks anyway22:23
SlybootsAh windows your busting my fucking balls22:27
Slyboots"Junctino does not support remote locations"22:27
RoyKhm.. getting 1.5GB/s from this system22:28
=== deegee_ is now known as deegee
RoyKhappy new year :)23:08
RoyK1099505336320 bytes (1.1 TB) copied, 727.725 s, 1.5 GB/s23:09
cn1209RoyK: okay. I decided to create a new VM in my ESXi box using Ubuntu and create two cron jobs that will execute the backup script for both servers. I had to create an ssh key. Runs great. Now to create page that will parse the log file that it generates into a nice looking page for management.23:26
Slybootsright.. that all went awfully wrong and show how I lost loads of data23:43
SlybootsMm.. can Rsync copy files as .. mm.. long as the Target destination files are *smaller* than the source?23:47
Slyboots<na Im drawing a total blank here23:55
SlybootsTrying to check if my CPU supports.. hardware virtualation23:55
SlybootsBut its not called HyperV23:55
Slyboots.. is it?23:55

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!