Category: Linux

  • Custom firmware for Asus RT-AC66U

    Merlin has a custom Asuswrt firmware for the RT-AC66U router which can be found at its new home at http://www.mediafire.com/asuswrt-merlin/#

    With this firmware Merlin adds some needed feature that Asus lefted out see below.

    Using IPv6 can be a pain without a firewall between you and the world. This is one of the reasons I like Merlin’s version of the firmware,
    You can create a file /jffs/scripts/firewall-start on the router to run a custom firewall rules at start up.

    Here’s an example of what that file would look like for IPv6 6in4 tunnel with ip6tables:

    ip6tables -A INPUT -j DROP
    ip6tables -I FORWARD 2 -m state --state RELATED,ESTABLISHED -j ACCEPT

    # Allowed inbound rules here, such as this one:
    ip6tables -I FORWARD 2 -p tcp -m state --state NEW -i v6in4 --dport 22-j ACCEPT

    ip6tables -A FORWARD -i v6in4 -o br0 -p all -j DROP
    ip6tables -A FORWARD -i br0 -o any -p all -j ACCEPT
    ip6tables -A FORWARD -i br0 -o v6in4 -p all -j ACCEPT
    ip6tables -A FORWARD -i any -o br0 -p all -j ACCEPT
    ip6tables -A FORWARD -j DROP

     

    Here is a list of features that Asuswrt-merlin brings over the original firmware:
    System:
       – Based on the 3.0.0.4.246 source release from Asus
       – Various bugfixes (like the crash on VPN/NAT Loopback access of LAN devices)
       – Persistent JFFS partition
       – User scripts that run on specific events
       – Cron jobs
       – Customized config files for router services
       – LED control – put your Dark Knight in Stealth Mode by turning off all LEDs
    Disk sharing:
       – Act as a Master Browser
       – Act as a WINS server
       – Optionally use shorter share names (folder name only)
       – Disk spindown after user-configurable inactivity timeout
    Networking:
       – WakeOnLan web interface (with user-entered preset targets)
       – SSHD
       – Allows tweaking TCP/UDP connection tracking timeouts
       – CIFS client support (for mounting remote SMB share on the router)
       – Layer7 iptables matching
       – User-defined options for WAN DHCP queries (required by some ISPs)
       – Improved NAT loopback (based on code from phuzi0n from the DD-WRT forums)
       – Dual WAN support (both failover and load
         balancing supported) (EXPERIMENTAL) (RT-N66U, RT-AC66U)
       – OpenVPN client and server, based on code originally written by
         Keith Moyer for Tomato and reused with his permission. (RT-N66U, RT-AC66U)
       – Option to control Spanning-Tree Protocol support.
    Web interface:
       – Clicking on the MAC address of an unidentified client will do a lookup in
         the OUI database (ported from DD-WRT).
       – Optionally save traffic stats to disk (USB or JFFS partition)
       – Display monthly traffic reports
       – Display active/tracked network connections
       – Name field on the DHCP reservation list and Wireless ACL list
       – System info summary page
       – Wireless client IP, hostname, rate and rssi on the Wireless Log page
       – Wifi icon reports the state of both radios
    Thank you Merlin for your hard work in creating this firmware.
  • Using Google Authenticator on Ubuntu for SSH

    Run:

    $ apt-get update
    $ apt-get -yy install gcc mercurial libpam0g-dev git
    $ git clone https://code.google.com/p/google-authenticator/
    $ cd google-authenticator/libpam
    $ make install

    Edit /etc/ssh/sshd_config file and change the ChallengeResponseAuthentication from no to yes

    edit /etc/pam.d/common-auth so it looks like

    # here are the per-package modules (the "Primary" block)
    auth required pam_google_authenticator.so
    auth [success=1 default=ignore] pam_unix.so nullok_secure
    # here's the fallback if no module succeeds

    Run google-authenticator as the user you want to use two factor authentication on.
    Paste the generated URL into your browser and a QRCode will be generated.
    Scan the QR code with the Google Authenticator app on your iPhone.
    Reboot the server and test.

  • Protecting SSH from brute force attacks via iptables

    Put the following in /etc/sysconf/iptables and /etc/sysconf/ip6tables:

    -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --set --name SSH
    -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 5 --rttl --name SSH -j DROP
    -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT

    restart iptables
    /bin/systemctl restart iptables.service
    /bin/systemctl restart ip6tables.service

  • Clearing cached memory on Linux system

    The Linux OS the tends keep Cached memory because the it decides that the Cached memory is being used and is needed which can lead to memory issues and slow do your system.

    To fix this problem you can force the system to free up the stored Cached memory.

    Create a script called /usr/local/bin/clearcache.sh with the following two lines:
    #!/bin/sh
    sync; echo 3 > /proc/sys/vm/drop_caches

    run “crontab -e” and add the following line:
    0 * * * * /usr/local/bin/clearcache.sh
    Also make the script executable by running “chmod +x /usr/local/bin/clearcache.sh”

    This should clear the Cached memory every hour.

  • Windows 7 as a Samba File Server for Linux machines

    If you get the this error message “mount error(12): Cannot allocate memory” while trying to mount a Windows SMB to a linux box.

    You need to configure Windows to act as a file server and it will allocate the resources needed.

    Change the registry key HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory ManagementLargeSystemCache  to ‘1′

    and Change HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLanmanServerParametersSize  to ‘3′

    once you have done that do a reboot and try mounting the Samba drive again.

     

  • VMWare Workstation 8 Server

    Recently I have started using VMWare Workstation 8, this is really cool and seem to function better than VirtualBox.
    If you setup a virtual machine and set it to be shared, you can make it boot up with the Windows OS, hence this could be a headless sever hosting a Linux OS.
    You will need to log in as the Administrator to set permission to allow your own user account to use the shared VMware server. Once you have done that you can make any virtual machine boot up as a shared virtual machine without having to be logged in to Windows.

  • Running a Ubuntu server on VirtualBox

    I created a virtual Ubuntu server on my Windows HTPC box using VirtualBox and VBoxVmService. This is a great setup as I can have a HTPC that’s always on with a Ubuntu server running on top.

    The Zbox is very energy efficient, quiet and small. This uses the AMD APU chip which is a all-in-one CPU/GPU combo.

    My setup is:

    • Zotac Zbox AD02
    • 8GB DDR3
    • 500GB WD HDD 7200k rpm
    • Windows 7 ultimate

    Installation was easy, I just installed VirtualBox, create a VM using the ISO from Ubuntu (make sure you install/enable SSH or NoMachine for remote access to the headless server), and then setup the VM to run as a service with VBoxVmService.

     

    http://vboxvmservice.sourceforge.net/

    https://www.virtualbox.org/

  • Nagios

    I Nagios is a wonderful tool to monitor your network devices.

     

    Nagios is a powerful monitoring system that enables organizations to identify and resolve IT infrastructure problems before they affect critical business processes.

    Designed with scalability and flexibility in mind, Nagios gives you the peace of mind that comes from knowing your organization’s business processes won’t be affected by unknown outages.

    Nagios is a powerful tool that provides you with instant awareness of your organization’s mission-critical IT infrastructure. Nagios allows you to detect and repair problems and mitigate future issues before they affect end-users and customers.

  • kmod-Nvidia and Centos 6

    Centos 6 comes with the nouveau which doesn’t work very well for my needs and the Nvidia driver works better. So heres the step to install kmod-nvidia as root.

    1. run “rpm -Uvh http://elrepo.org/elrepo-release-6-4.el6.elrepo.noarch.rpm”
    2. run “yum install kmod-nvidia nvidia-x11-drv nvidia-x11-drv-32bit”
    3. reboot the system

    You may need to black list the nouveau driver if that does not work.
    Edit the /boot/grub/menu.lst and append the following to the end of the kernel line:
    rdblacklist=nouveau

  • AirPrint and Ubuntu 11.10

    In Ubuntu 11.10, setting up AirPrint is easy.

    1. Have a Standard install of Ubuntu Desktop 11.10.
    2. Go into the CUPS interface and make sure “Share published printers connected to this system” is enabled on the server settings.
    3. On the Printer Properties, make sure the Shared checkbox is check on the Policies tab.
    4. If you have a firewall running, make sure you allow the needed ports (one of the is port 631).
    5. Restart CUPS “/etc/init.d/cups restart” or reboot the computer
    6. Make sure you iPhone/iPad is on the same network
    7. On your iPhone/iPad, go into Safari, print, and search for printers. Your new printer should be in there.