Re: [rlug] Eroare cacti

2006-05-08 Fir de Conversatie Dragos Chiriac

sin wrote:

fh wrote:
  

On 5/6/06, Dragos CHIRIAC [EMAIL PROTECTED] wrote:


fh wrote:
  

De unde ar trebui sa provina eroarea din /var/log/apache2/error.log
cand acceses http://localhost/cacti

[Sat May 06 20:23:02 2006] [notice] Apache/2.0.55 (Debian)
PHP/5.1.2-1+b1 mod_apreq2-20051231/2.5.7 mod_perl/2.0.2 Perl/v5.8.8
configured -- resuming normal operations


esti sigur ca nu incarci de dou ori mysql.so in php.ini (ala folosit de
apache that is) ?
da si tu un strace -ff daca nu e de la asta. (desi imi aduc aminte ca am
comis-o si eu odata si parca tot d-astea cu segfault zicea).
  

Da, in /etc/php5/apache2/php.ini era de doua ori
extension=mysql.so
Dupa ce am comentat-o si am restartat apache-ul , dar se da aceiasi eroare.
strace -ff pe care thread/proces al apache-ului ?



ii zici lu apache (din minte):

startservers 1
maxservers 1
spareservers 0
maxspareservers 0


apache stop ; apache start

si dupa aia strace -v -f -p pidul_procesului parinte

(la pstree o sa vezi doar 2 apache-uri, dintre care unu e parent,
alalalt copilu)

  

eh, io gandeam mai pervers

  -ff If  the  -o  filename option is in effect, each pro-
  cesses trace is written to filename.pid where pid is
  the numeric process id of each process.

dup-aia gasesti fisieru in v-un fel sau altu

___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


[rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
Masina: P4 2.6Ghz, 1Gram, 2 placi de retea (rtl8139too)

Problema se pune in felul urmator.

Aceasta masina pe langa faptul ca da net la vreo 15 oameni, mai face si
alte lucruri. Unul dintre ele este ca pe el descarc torrenti.
Dupa cum se stie, torrenti mananca banda la greu!

Treaba este ca in momentul in care descarc ceva pe el, imediat apar loss-uri.

De ce se intampla treaba asta? Sunt indreptatit sa intreb chestia asta,
pentru ca pana acum cu toate ca descarca cu 9m/s nu facea figuri d'astea,
ci doar incarca procesorul la greu. In momentul de fata daca descarca si
cu 1-2m/s s-a terminat cu smecheria.

Cand descarca cu... nu stiu... 7m/s... mtr in server am 80-90% loss.
Repet, treaba asta nu s-a intamplat pana acum.

Ce poate sa fie?

Multumesc!

___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Samareanu Florin

On Mon, 8 May 2006, Ionut EANA wrote:


Masina: P4 2.6Ghz, 1Gram, 2 placi de retea (rtl8139too)



Cand descarca cu... nu stiu... 7m/s... mtr in server am 80-90% loss.
Repet, treaba asta nu s-a intamplat pana acum.


dmesg baraie ceva? /var/log/messages zice ceva?



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


[rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie IuliaN
  Incerc sa pun mrtg-ul sa faca niste poze cu trafic(n-am mai facut), si
nu-mi afiseaza nimic(mai exact arata ca si cum traficul e zero)!
Folosesc Kubuntu!

#/etc/mrtg:
# Global configuration
WorkDir: /var/www/mrtg
WriteExpires: Yes

Title[^]: Traffic Analysis for

# 128K leased line
# 
#Title[leased]: a 128K leased line
#PageTop[leased]: H1Our 128K link to the outside world/H1
#Target[leased]: 1:[EMAIL PROTECTED]
#MaxBytes[leased]: 16000

Title[eth]: br0 eth
Target[eth]: 1:[EMAIL PROTECTED]
MaxBytes[eth]: 300
Options[eth]: bits,growright

Title[2eth]: 2 br0
Target[2eth]: 2:[EMAIL PROTECTED]
MaxBytes[2eth]: 300
Options[2eth]: bits,growright


/etc/snmp/snmpd.conf

com2sec localro  default public

group MyROSystem v1localro
group MyROSystem v2c   localro
group MyROSystem usm   localro

group MyROGroup v1 readonly
group MyROGroup v2creadonly
group MyROGroup usmreadonly
group MyRWGroup v1 readwrite
group MyRWGroup v2creadwrite
group MyRWGroup usmreadwrite

view allincluded  .1   80
view system included  .iso.org.dod.internet.mgmt.mib-2.system

access MyROSystem  any   noauthexact  system none   none
access MyROGroup   any   noauthexact  allnone   none
access MyRWGroup   any   noauthexact  allallnone
-


env LANG=C /usr/bin/mrtg /etc/mrtg.cfg
SNMP Error:
Received SNMP response with error code
  error status: noSuchName
  index 2 (OID: 1.3.6.1.2.1.2.2.1.16.1)
SNMPv1_Session (remote host: 192.168.0.55 [192.168.0.55].161)
  community: public
 request ID: 108926461
PDU bufsize: 8000 bytes
timeout: 2s
retries: 5
backoff: 1)
 at /usr/share/perl5/SNMP_util.pm line 490
SNMPGET Problem for ifInOctets.1 ifOutOctets.1 sysUptime sysName on
[EMAIL PROTECTED]::v4only
 at /usr/bin/mrtg line 1925
SNMP Error:
no response received
SNMPv1_Session (remote host: 192.168.0.2 [192.168.0.2].161)
  community: public
 request ID: 592489591
PDU bufsize: 8000 bytes
timeout: 2s
retries: 5
backoff: 1)
 at /usr/share/perl5/SNMP_util.pm line 490
SNMPGET Problem for ifInOctets.2 ifOutOctets.2 sysUptime sysName on
[EMAIL PROTECTED]::v4only
 at /usr/bin/mrtg line 1925
WARNING: skipping because at least the query for ifInOctets.2 on 
192.168.0.2 did not succeed
WARNING: no data for ifInOctetsifOutOctets:[EMAIL PROTECTED] Skipping
further queries for Host 192.168.0.2 in this round.
ERROR: Target[eth][_IN_] ' $target-[0]{$mode} ' did not eval into defined
data
ERROR: Target[eth][_OUT_] ' $target-[0]{$mode} ' did not eval into
defined data
ERROR: Target[2eth][_IN_] ' $target-[1]{$mode} ' did not eval into
defined data
ERROR: Target[2eth][_OUT_] ' $target-[1]{$mode} ' did not eval into
defined data


  Multumesc


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie egl


- Original Message - 
From: IuliaN [EMAIL PROTECTED]

To: Romanian Linux Users Group rlug@lists.lug.ro
Sent: Monday, May 08, 2006 10:53 AM
Subject: [rlug] mrtg on Kubuntu


 Incerc sa pun mrtg-ul sa faca niste poze cu trafic(n-am mai facut), 
si

nu-mi afiseaza nimic(mai exact arata ca si cum traficul e zero)!
Folosesc Kubuntu!

#/etc/mrtg:
# Global configuration
WorkDir: /var/www/mrtg
WriteExpires: Yes

Title[^]: Traffic Analysis for

# 128K leased line
# 
#Title[leased]: a 128K leased line
#PageTop[leased]: H1Our 128K link to the outside world/H1
#Target[leased]: 1:[EMAIL PROTECTED]
#MaxBytes[leased]: 16000

Title[eth]: br0 eth
Target[eth]: 1:[EMAIL PROTECTED]
MaxBytes[eth]: 300
Options[eth]: bits,growright

Title[2eth]: 2 br0
Target[2eth]: 2:[EMAIL PROTECTED]
MaxBytes[2eth]: 300
Options[2eth]: bits,growright


/etc/snmp/snmpd.conf

com2sec localro  default public

group MyROSystem v1localro
group MyROSystem v2c   localro
group MyROSystem usm   localro

group MyROGroup v1 readonly
group MyROGroup v2creadonly
group MyROGroup usmreadonly
group MyRWGroup v1 readwrite
group MyRWGroup v2creadwrite
group MyRWGroup usmreadwrite

view allincluded  .1   80
view system included  .iso.org.dod.internet.mgmt.mib-2.system

access MyROSystem  any   noauthexact  system none   none
access MyROGroup   any   noauthexact  allnone   none
access MyRWGroup   any   noauthexact  allallnone
-


env LANG=C /usr/bin/mrtg /etc/mrtg.cfg
SNMP Error:
Received SNMP response with error code
 error status: noSuchName
 index 2 (OID: 1.3.6.1.2.1.2.2.1.16.1)
SNMPv1_Session (remote host: 192.168.0.55 [192.168.0.55].161)
 community: public
request ID: 108926461
   PDU bufsize: 8000 bytes
   timeout: 2s
   retries: 5
   backoff: 1)
at /usr/share/perl5/SNMP_util.pm line 490
SNMPGET Problem for ifInOctets.1 ifOutOctets.1 sysUptime sysName on
[EMAIL PROTECTED]::v4only
at /usr/bin/mrtg line 1925
SNMP Error:
no response received
SNMPv1_Session (remote host: 192.168.0.2 [192.168.0.2].161)
 community: public
request ID: 592489591
   PDU bufsize: 8000 bytes
   timeout: 2s
   retries: 5
   backoff: 1)
at /usr/share/perl5/SNMP_util.pm line 490
SNMPGET Problem for ifInOctets.2 ifOutOctets.2 sysUptime sysName on
[EMAIL PROTECTED]::v4only
at /usr/bin/mrtg line 1925
WARNING: skipping because at least the query for ifInOctets.2 on
192.168.0.2 did not succeed
WARNING: no data for ifInOctetsifOutOctets:[EMAIL PROTECTED] 
Skipping

further queries for Host 192.168.0.2 in this round.
ERROR: Target[eth][_IN_] ' $target-[0]{$mode} ' did not eval into 
defined

data
ERROR: Target[eth][_OUT_] ' $target-[0]{$mode} ' did not eval into
defined data
ERROR: Target[2eth][_IN_] ' $target-[1]{$mode} ' did not eval into
defined data
ERROR: Target[2eth][_OUT_] ' $target-[1]{$mode} ' did not eval into
defined data


 Multumesc



cauta linia (in snmpd.conf)
#viewrwview  included 
interfaces.ifTable.ifEntry.ifAdminStatus

scoate commentu si restarteaza snmpd




___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie IuliaN

 - Original Message -
 From: IuliaN [EMAIL PROTECTED]
 To: Romanian Linux Users Group rlug@lists.lug.ro
 Sent: Monday, May 08, 2006 10:53 AM
 Subject: [rlug] mrtg on Kubuntu


  Incerc sa pun mrtg-ul sa faca niste poze cu trafic(n-am mai facut),
 si
 nu-mi afiseaza nimic(mai exact arata ca si cum traficul e zero)!
 Folosesc Kubuntu!

 #/etc/mrtg:
 # Global configuration
 WorkDir: /var/www/mrtg
 WriteExpires: Yes

 Title[^]: Traffic Analysis for

 # 128K leased line
 # 
 #Title[leased]: a 128K leased line
 #PageTop[leased]: H1Our 128K link to the outside world/H1
 #Target[leased]: 1:[EMAIL PROTECTED]
 #MaxBytes[leased]: 16000

 Title[eth]: br0 eth
 Target[eth]: 1:[EMAIL PROTECTED]
 MaxBytes[eth]: 300
 Options[eth]: bits,growright

 Title[2eth]: 2 br0
 Target[2eth]: 2:[EMAIL PROTECTED]
 MaxBytes[2eth]: 300
 Options[2eth]: bits,growright
 

 /etc/snmp/snmpd.conf

 com2sec localro  default public

 group MyROSystem v1localro
 group MyROSystem v2c   localro
 group MyROSystem usm   localro

 group MyROGroup v1 readonly
 group MyROGroup v2creadonly
 group MyROGroup usmreadonly
 group MyRWGroup v1 readwrite
 group MyRWGroup v2creadwrite
 group MyRWGroup usmreadwrite

 view allincluded  .1   80
 view system included  .iso.org.dod.internet.mgmt.mib-2.system

 access MyROSystem  any   noauthexact  system none   none
 access MyROGroup   any   noauthexact  allnone   none
 access MyRWGroup   any   noauthexact  allallnone
 -


 env LANG=C /usr/bin/mrtg /etc/mrtg.cfg
 SNMP Error:
 Received SNMP response with error code
  error status: noSuchName
  index 2 (OID: 1.3.6.1.2.1.2.2.1.16.1)
 SNMPv1_Session (remote host: 192.168.0.55 [192.168.0.55].161)
  community: public
 request ID: 108926461
PDU bufsize: 8000 bytes
timeout: 2s
retries: 5
backoff: 1)
 at /usr/share/perl5/SNMP_util.pm line 490
 SNMPGET Problem for ifInOctets.1 ifOutOctets.1 sysUptime sysName on
 [EMAIL PROTECTED]::v4only
 at /usr/bin/mrtg line 1925
 SNMP Error:
 no response received
 SNMPv1_Session (remote host: 192.168.0.2 [192.168.0.2].161)
  community: public
 request ID: 592489591
PDU bufsize: 8000 bytes
timeout: 2s
retries: 5
backoff: 1)
 at /usr/share/perl5/SNMP_util.pm line 490
 SNMPGET Problem for ifInOctets.2 ifOutOctets.2 sysUptime sysName on
 [EMAIL PROTECTED]::v4only
 at /usr/bin/mrtg line 1925
 WARNING: skipping because at least the query for ifInOctets.2 on
 192.168.0.2 did not succeed
 WARNING: no data for ifInOctetsifOutOctets:[EMAIL PROTECTED]
 Skipping
 further queries for Host 192.168.0.2 in this round.
 ERROR: Target[eth][_IN_] ' $target-[0]{$mode} ' did not eval into
 defined
 data
 ERROR: Target[eth][_OUT_] ' $target-[0]{$mode} ' did not eval into
 defined data
 ERROR: Target[2eth][_IN_] ' $target-[1]{$mode} ' did not eval into
 defined data
 ERROR: Target[2eth][_OUT_] ' $target-[1]{$mode} ' did not eval into
 defined data


  Multumesc


  cauta linia (in snmpd.conf)
  #viewrwview  included
 interfaces.ifTable.ifEntry.ifAdminStatus
  scoate commentu si restarteaza snmpd

in conf-ul de snmpd nu am asa ceva, am adaugat linia de care povestesti tu
in snmpd.conf, restartat daemonul in cauza ...si ...la fel..aceeeasi
eroare!




 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug




___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
Nu zice nimic!

Ultimile linii in /var/log/messages
May  8 09:15:30 localhost -- MARK --
May  8 09:35:30 localhost -- MARK --
May  8 09:55:30 localhost -- MARK --
May  8 10:15:31 localhost -- MARK --
May  8 10:35:31 localhost -- MARK --
May  8 10:55:31 localhost -- MARK --
May  8 11:15:31 localhost -- MARK --
May  8 11:35:32 localhost -- MARK --
May  8 11:55:32 localhost -- MARK --
May  8 12:15:32 localhost -- MARK --

In rest nimic neobisnuit...

 On Mon, 8 May 2006, Ionut EANA wrote:

 Masina: P4 2.6Ghz, 1Gram, 2 placi de retea (rtl8139too)

 Cand descarca cu... nu stiu... 7m/s... mtr in server am 80-90% loss.
 Repet, treaba asta nu s-a intamplat pana acum.

 dmesg baraie ceva? /var/log/messages zice ceva?



 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie Alex
On Monday 08 May 2006 11:53, IuliaN wrote:
   Incerc sa pun mrtg-ul sa faca niste poze cu trafic(n-am mai facut), si
 nu-mi afiseaza nimic(mai exact arata ca si cum traficul e zero)!
 Folosesc Kubuntu!

Vad ca ai mai multe erori ... Uite aici un howto care e ok (ai tot ce trebuie 
ca sa o iei de la zero).

http://www.siliconvalleyccie.com/linux-hn/mrtg.htm

http://www.siliconvalleyccie.com/linux-hn/mrtg-advanced.htm

Alex


 #/etc/mrtg:
 # Global configuration
 WorkDir: /var/www/mrtg
 WriteExpires: Yes

 Title[^]: Traffic Analysis for

 # 128K leased line
 # 
 #Title[leased]: a 128K leased line
 #PageTop[leased]: H1Our 128K link to the outside world/H1
 #Target[leased]: 1:[EMAIL PROTECTED]
 #MaxBytes[leased]: 16000

 Title[eth]: br0 eth
 Target[eth]: 1:[EMAIL PROTECTED]
 MaxBytes[eth]: 300
 Options[eth]: bits,growright

 Title[2eth]: 2 br0
 Target[2eth]: 2:[EMAIL PROTECTED]
 MaxBytes[2eth]: 300
 Options[2eth]: bits,growright
 

 /etc/snmp/snmpd.conf

 com2sec localro  default public

 group MyROSystem v1localro
 group MyROSystem v2c   localro
 group MyROSystem usm   localro

 group MyROGroup v1 readonly
 group MyROGroup v2creadonly
 group MyROGroup usmreadonly
 group MyRWGroup v1 readwrite
 group MyRWGroup v2creadwrite
 group MyRWGroup usmreadwrite

 view allincluded  .1   80
 view system included  .iso.org.dod.internet.mgmt.mib-2.system

 access MyROSystem  any   noauthexact  system none   none
 access MyROGroup   any   noauthexact  allnone   none
 access MyRWGroup   any   noauthexact  allallnone
 -


 env LANG=C /usr/bin/mrtg /etc/mrtg.cfg
 SNMP Error:
 Received SNMP response with error code
   error status: noSuchName
   index 2 (OID: 1.3.6.1.2.1.2.2.1.16.1)
 SNMPv1_Session (remote host: 192.168.0.55 [192.168.0.55].161)
   community: public
  request ID: 108926461
 PDU bufsize: 8000 bytes
 timeout: 2s
 retries: 5
 backoff: 1)
  at /usr/share/perl5/SNMP_util.pm line 490
 SNMPGET Problem for ifInOctets.1 ifOutOctets.1 sysUptime sysName on
 [EMAIL PROTECTED]::v4only
  at /usr/bin/mrtg line 1925
 SNMP Error:
 no response received
 SNMPv1_Session (remote host: 192.168.0.2 [192.168.0.2].161)
   community: public
  request ID: 592489591
 PDU bufsize: 8000 bytes
 timeout: 2s
 retries: 5
 backoff: 1)
  at /usr/share/perl5/SNMP_util.pm line 490
 SNMPGET Problem for ifInOctets.2 ifOutOctets.2 sysUptime sysName on
 [EMAIL PROTECTED]::v4only
  at /usr/bin/mrtg line 1925
 WARNING: skipping because at least the query for ifInOctets.2 on
 192.168.0.2 did not succeed
 WARNING: no data for ifInOctetsifOutOctets:[EMAIL PROTECTED] Skipping
 further queries for Host 192.168.0.2 in this round.
 ERROR: Target[eth][_IN_] ' $target-[0]{$mode} ' did not eval into defined
 data
 ERROR: Target[eth][_OUT_] ' $target-[0]{$mode} ' did not eval into
 defined data
 ERROR: Target[2eth][_IN_] ' $target-[1]{$mode} ' did not eval into
 defined data
 ERROR: Target[2eth][_OUT_] ' $target-[1]{$mode} ' did not eval into
 defined data


   Multumesc


 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug

___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Dan Dragomir
On Monday 08 May 2006 11:22, Ionut EANA wrote:

cred ca pachetele icmp sunt tratate cu prioritate diferita, iar cand banda e 
incarcata, ele iau un drop... dar nu as putea sa iti spun exact si la ce 
nivel... daca lossul ar fi la toate pachetele, nici nu ai mai avea viteze de 
ordinul M/s

 Masina: P4 2.6Ghz, 1Gram, 2 placi de retea (rtl8139too)

 Problema se pune in felul urmator.

 Aceasta masina pe langa faptul ca da net la vreo 15 oameni, mai face si
 alte lucruri. Unul dintre ele este ca pe el descarc torrenti.
 Dupa cum se stie, torrenti mananca banda la greu!

 Treaba este ca in momentul in care descarc ceva pe el, imediat apar
 loss-uri.

 De ce se intampla treaba asta? Sunt indreptatit sa intreb chestia asta,
 pentru ca pana acum cu toate ca descarca cu 9m/s nu facea figuri d'astea,
 ci doar incarca procesorul la greu. In momentul de fata daca descarca si
 cu 1-2m/s s-a terminat cu smecheria.

 Cand descarca cu... nu stiu... 7m/s... mtr in server am 80-90% loss.
 Repet, treaba asta nu s-a intamplat pana acum.

 Ce poate sa fie?

 Multumesc!

 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug

-- 
Dan Dragomir
+40724009169

___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Constantin Gavrilescu

Cam pe la 05/08/2006 12:23 PM, Ionut EANA scrise:

Nu zice nimic!

Ultimile linii in /var/log/messages
May  8 09:15:30 localhost -- MARK --
May  8 09:35:30 localhost -- MARK --
  


Vezi ce zice si in:
/var/log/kern.log
sau in
/var/log/kernel/*.log

--
They say money can't buy happiness? Look at the smile on my face... ear to ear, 
baby!


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie egl
- Original Message - 
From: IuliaN [EMAIL PROTECTED]
To: egl [EMAIL PROTECTED]; Romanian Linux Users Group 
rlug@lists.lug.ro

Sent: Monday, May 08, 2006 11:23 AM
Subject: Re: [rlug] mrtg on Kubuntu



 cauta linia (in snmpd.conf)
 #viewrwview  included
interfaces.ifTable.ifEntry.ifAdminStatus
 scoate commentu si restarteaza snmpd


in conf-ul de snmpd nu am asa ceva, am adaugat linia de care 
povestesti tu

in snmpd.conf, restartat daemonul in cauza ...si ...la fel..aceeeasi
eroare!




se pare ca nu ai acces la OID-ul 
interfaces.ifTable.ifTable.ifEntry.ifDescr.

vezi pe ce interfete asculta snmpd.
verifica ce rezultat intoarce snmpwalk -v2c -c public localhost 
interfaces.ifTable.ifTable.ifEntry.ifDescr (case sensitive),
daca-ti listeaza interfetele configureaza mrtg sa faca cererile pe 
localhost




___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Constantin Gavrilescu

Cam pe la 05/08/2006 12:45 PM, Dan Dragomir scrise:

On Monday 08 May 2006 11:22, Ionut EANA wrote:

cred ca pachetele icmp sunt tratate cu prioritate diferita, iar cand banda e 
incarcata, ele iau un drop... dar nu as putea sa iti spun exact si la ce 
nivel... daca lossul ar fi la toate pachetele, nici nu ai mai avea viteze de 
ordinul M/s
  


Nu e o prioritate diferita. Imagineaza-ti o autostrada foarte 
aglomerata, plina cu tiruri. Pachetele tale icmp sunt niste matizuri 
printre tirurile imense. La trecerea pe un pod e Hulk care da cu masini 
in sant, pentru ca n-au loc pe pod toate. Acum, chiar daca se pierd 
cateva tiruri, marfa tot se transporta si cea mai mare parte din sosea e 
acoperita de tiruri.



--
They say money can't buy happiness? Look at the smile on my face... ear to ear, 
baby!


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
 Cam pe la 05/08/2006 12:23 PM, Ionut EANA scrise:
 Nu zice nimic!

 Ultimile linii in /var/log/messages
 May  8 09:15:30 localhost -- MARK --
 May  8 09:35:30 localhost -- MARK --


 Vezi ce zice si in:
 /var/log/kern.log
 sau in
 /var/log/kernel/*.log


May  7 08:54:06 localhost kernel: HTB: quantum of class 10001 is big.
Consider r2q change.
May  7 08:54:07 localhost kernel: HTB: quantum of class 10101 is small.
Consider r2q change.
May  7 08:54:07 localhost kernel: HTB: quantum of class 10102 is small.
Consider r2q change.
May  7 08:54:07 localhost kernel: HTB: quantum of class 10103 is small.
Consider r2q change.
May  7 08:54:07 localhost kernel: HTB: quantum of class 10104 is small.
Consider r2q change.
May  7 08:54:07 localhost kernel: HTB: quantum of class 10105 is small.
Consider r2q change.
May  7 08:54:07 localhost kernel: HTB: quantum of class 10106 is small.
Consider r2q change.
May  7 08:54:07 localhost kernel: u32 classifier
May  7 08:54:07 localhost kernel: Perfomance counters on
May  7 08:54:07 localhost kernel: input device check on
May  7 08:54:07 localhost kernel: Actions configured
May  7 08:54:08 localhost kernel: HTB: quantum of class 10001 is big.
Consider r2q change.
May  7 08:54:08 localhost kernel: HTB: quantum of class 10101 is small.
Consider r2q change.
May  7 08:54:08 localhost kernel: HTB: quantum of class 10102 is small.
Consider r2q change.
May  7 08:54:08 localhost kernel: HTB: quantum of class 10103 is small.
Consider r2q change.
May  7 08:54:08 localhost kernel: HTB: quantum of class 10104 is small.
Consider r2q change.
May  7 08:54:08 localhost kernel: HTB: quantum of class 10105 is small.
Consider r2q change.
May  7 08:54:08 localhost kernel: HTB: quantum of class 10106 is small.
Consider r2q change.

Asta s-a intamplat ieri. Am oprit htb, am oprit firewall (adica nu le-am
mai dat net, nici mie chiar) si nu au mai aparut mesajele astea, dar in
schimb problema a ramas!

Dar am spus! Inainte a mers perfect! Fara nici un fel de modificare,
problema asta a aparut aparent din senin. Incep sa ma gandesc din ce in ce
mai serios sa nu fie vreo problema hardware! Exista oare posibilitatea sa
se fi dus vreo placa de retea? Poate chiar aia de interfata externa?

 --
 They say money can't buy happiness? Look at the smile on my face... ear to
 ear, baby!


 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Samareanu Florin

On Mon, 8 May 2006, Ionut EANA wrote:


Dar am spus! Inainte a mers perfect! Fara nici un fel de modificare,
problema asta a aparut aparent din senin. Incep sa ma gandesc din ce in ce
mai serios sa nu fie vreo problema hardware! Exista oare posibilitatea sa
se fi dus vreo placa de retea? Poate chiar aia de interfata externa?


--
sigur nu cea externa. pentru ca traficul intre tine si server nu trece 
prin interfata spre provider.




___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
 On Mon, 8 May 2006, Ionut EANA wrote:

 Dar am spus! Inainte a mers perfect! Fara nici un fel de modificare,
 problema asta a aparut aparent din senin. Incep sa ma gandesc din ce in
 ce
 mai serios sa nu fie vreo problema hardware! Exista oare posibilitatea
 sa
 se fi dus vreo placa de retea? Poate chiar aia de interfata externa?

 --
 sigur nu cea externa. pentru ca traficul intre tine si server nu trece
 prin interfata spre provider.



Eu descarc direct pe server! Nu pe workstation! Acesta este motivul pentru
care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
Defectarea placii de retea?


 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Samareanu Florin

On Mon, 8 May 2006, Ionut EANA wrote:


On Mon, 8 May 2006, Ionut EANA wrote:



Eu descarc direct pe server! Nu pe workstation! Acesta este motivul pentru
care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
Defectarea placii de retea?





nu cumva te limiteaza providerul?
ia da un mtr in timp ce downloadezi si da paste aici.



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie George-Cristian Bîrzan
On Mon, 2006-05-08 at 13:20 +0300, Ionut EANA wrote:
 
 Eu descarc direct pe server! Nu pe workstation! Acesta este motivul
 pentru
 care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
 Defectarea placii de retea? 

vmstat 1 5 in timp ce downloadezi ce zice?

-- 
George-Cristian Bîrzan


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
 On Mon, 8 May 2006, Ionut EANA wrote:

 On Mon, 8 May 2006, Ionut EANA wrote:


 Eu descarc direct pe server! Nu pe workstation! Acesta este motivul
 pentru
 care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
 Defectarea placii de retea?



 nu cumva te limiteaza providerul?
 ia da un mtr in timp ce downloadezi si da paste aici.


mtr in server:
 Host 
Loss%   Snt   Last   Avg  Best 
Wrst StDev
 1. 86.106.192.1  
12.2%   1470.3   0.4   0.2 
12.8   1.3

vmstat 1 5
procs ---memory-- ---swap-- -io --system--
cpu
 r  b   swpd   free   buff  cache   si   sobibo   incs us sy
id wa
 1  0  0 147324  77716 512864008163   36 2  1  2
96  1
 0  0  0 145836  77716 51490400 4 0 1825   530 14  5
80  1
 0  0  0 143584  77720 51721200  1280 0 1729   946 12  4
79  5
 0  0  0 142592  77720 51823200 0 0 2509  1402 14  4
82  0
 0  0  0 142608  77720 51823200 0  7412 1336   366  7  4
63 26

acum descarca cu 850k/s putini la seed :((
oricum cu cat creste da pe spate mai rau...

avand in vedere ca la noi sunt mai multi provideri (ines, evolva, rds)
mtr ines.ro
 Host 
Loss%   Snt   Last   Avg  Best 
Wrst StDev
 1. 86.106.192.1  
18.5%270.6   0.9   0.2  
7.6   1.7
 2. 172.16.0.2
15.4%270.3   0.4   0.3  
0.8   0.1
 3. VLAN-800.NVC-CORE.iNES.RO 
22.2%271.6   1.5   1.0  
2.9   0.4
 4. VLAN-006.B-CORE-1.iNES.RO 
20.0%261.8   2.2   1.5  
6.9   1.2
 5. Webgate1.iNES.RO  
20.0%261.8   2.0   1.3  
2.5   0.3

mtr rdsnet.ro
 Host 
Loss%   Snt   Last   Avg  Best 
Wrst StDev
 1. 86.106.192.1  
13.3%300.3   0.7   0.2  
7.6   1.5
 2. 172.16.0.4
 3.4%300.5   1.1   0.4  
7.7   1.9
 3. 82-76-67-1.rdsnet.ro  
13.3%301.4   1.8   1.1  
4.3   0.6
 4. 82-76-241-246.rdsnet.ro   
13.3%301.9   1.7   1.3  
2.4   0.2
 5. www.rdsnet.ro 
 7.1%292.4   1.9   1.1  
7.8   1.3


mtr evolva.ro
 Host 
Loss%   Snt   Last   Avg  Best 
Wrst StDev
 1. 86.106.192.1  
18.2%110.2   0.3   0.2  
0.6   0.1
 2. 172.16.0.3
27.3%110.4   0.6   0.3  
1.3   0.3
 3. bbTnrt-fe1032-v3132-wirednet.b.evolvatelecom.net  
22.2%101.5   1.6   0.8  
3.3   0.8
 4. bbDcbl-ge306-v21-bbTnrt.b.evolvatelecom.net   
70.0%102.7   1.8   1.1  
2.7   0.9
 5. evolva.ro 
10.0%101.0   1.4   0.7  
3.3   0.8





 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
 On Mon, 8 May 2006, Ionut EANA wrote:

 On Mon, 8 May 2006, Ionut EANA wrote:


 Eu descarc direct pe server! Nu pe workstation! Acesta este motivul
 pentru
 care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
 Defectarea placii de retea?



 nu cumva te limiteaza providerul?
 ia da un mtr in timp ce downloadezi si da paste aici.


Nu sunt limitat de provider... Am vorbit chiar cu providerul! Si m-a
asigurat ca nu m-a limitat.


 mtr in server:
  Host
 Loss%   Snt   Last   Avg  Best
 Wrst StDev
  1. 86.106.192.1
 12.2%   1470.3   0.4   0.2
 12.8   1.3

 vmstat 1 5
 procs ---memory-- ---swap-- -io --system--
 cpu
  r  b   swpd   free   buff  cache   si   sobibo   incs us sy
 id wa
  1  0  0 147324  77716 512864008163   36 2  1  2
 96  1
  0  0  0 145836  77716 51490400 4 0 1825   530 14  5
 80  1
  0  0  0 143584  77720 51721200  1280 0 1729   946 12  4
 79  5
  0  0  0 142592  77720 51823200 0 0 2509  1402 14  4
 82  0
  0  0  0 142608  77720 51823200 0  7412 1336   366  7  4
 63 26

 acum descarca cu 850k/s putini la seed :((
 oricum cu cat creste da pe spate mai rau...

 avand in vedere ca la noi sunt mai multi provideri (ines, evolva, rds)
 mtr ines.ro
  Host
 Loss%   Snt   Last   Avg  Best
 Wrst StDev
  1. 86.106.192.1
 18.5%270.6   0.9   0.2
 7.6   1.7
  2. 172.16.0.2
 15.4%270.3   0.4   0.3
 0.8   0.1
  3. VLAN-800.NVC-CORE.iNES.RO
 22.2%271.6   1.5   1.0
 2.9   0.4
  4. VLAN-006.B-CORE-1.iNES.RO
 20.0%261.8   2.2   1.5
 6.9   1.2
  5. Webgate1.iNES.RO
 20.0%261.8   2.0   1.3
 2.5   0.3

 mtr rdsnet.ro
  Host
 Loss%   Snt   Last   Avg  Best
 Wrst StDev
  1. 86.106.192.1
 13.3%300.3   0.7   0.2
 7.6   1.5
  2. 172.16.0.4
  3.4%300.5   1.1   0.4
 7.7   1.9
  3. 82-76-67-1.rdsnet.ro
 13.3%301.4   1.8   1.1
 4.3   0.6
  4. 82-76-241-246.rdsnet.ro
 13.3%301.9   1.7   1.3
 2.4   0.2
  5. www.rdsnet.ro
  7.1%292.4   1.9   1.1
 7.8   1.3


 mtr evolva.ro
  Host
 Loss%   Snt   Last   Avg  Best
 Wrst StDev
  1. 86.106.192.1
 18.2%110.2   0.3   0.2
 0.6   0.1
  2. 172.16.0.3
 27.3%110.4   0.6   0.3
 1.3   0.3
  3. bbTnrt-fe1032-v3132-wirednet.b.evolvatelecom.net
 22.2%101.5   1.6   0.8
 3.3   0.8
  4. bbDcbl-ge306-v21-bbTnrt.b.evolvatelecom.net
 70.0%102.7   1.8   1.1
 2.7   0.9
  5. evolva.ro
 10.0%101.0   1.4   0.7
 3.3   0.8





 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie arny

Ionut EANA wrote:

Eu descarc direct pe server! Nu pe workstation! Acesta este motivul pentru
care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
Defectarea placii de retea?


Vezi un ifconfig eth0 si daca ai ceva de genul
RX packets:41124 errors:24 dropped:56 overruns:0 frame:0
    

TX packets:2146 errors:34 dropped:23 overruns:0 carrier:0
^
atunci e cam pb de placa de retea.



--
Besides, I think Slackware sounds better than Microsoft, don't you? - 
Patrick Volkerding


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie Ionut EANA
 Ionut EANA wrote:
 Eu descarc direct pe server! Nu pe workstation! Acesta este motivul
 pentru
 care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
 Defectarea placii de retea?

 Vezi un ifconfig eth0 si daca ai ceva de genul
 RX packets:41124 errors:24 dropped:56 overruns:0 frame:0


 TX packets:2146 errors:34 dropped:23 overruns:0 carrier:0
  ^
 atunci e cam pb de placa de retea.


ifconfig eth0

  RX packets:147782899 errors:2 dropped:15 overruns:1 frame:0
  TX packets:136707610 errors:0 dropped:0 overruns:0 carrier:0
  collisions:0 txqueuelen:1000
  RX bytes:1100170388 (1.0 GiB)  TX bytes:1394921841 (1.2 GiB)
  Interrupt:16 Base address:0xd000

doua erori si 15 dropuite... placa sa fie?



 --
 Besides, I think Slackware sounds better than Microsoft, don't you? -
 Patrick Volkerding

 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug



___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Loss!

2006-05-08 Fir de Conversatie arny

Ionut EANA wrote:

Ionut EANA wrote:

Eu descarc direct pe server! Nu pe workstation! Acesta este motivul
pentru
care zic cea externa... Pana la urma asta ar putea fi o posibilitate?
Defectarea placii de retea?

Vezi un ifconfig eth0 si daca ai ceva de genul
RX packets:41124 errors:24 dropped:56 overruns:0 frame:0
 

TX packets:2146 errors:34 dropped:23 overruns:0 carrier:0
 ^
atunci e cam pb de placa de retea.



ifconfig eth0

  RX packets:147782899 errors:2 dropped:15 overruns:1 frame:0
  TX packets:136707610 errors:0 dropped:0 overruns:0 carrier:0
  collisions:0 txqueuelen:1000
  RX bytes:1100170388 (1.0 GiB)  TX bytes:1394921841 (1.2 GiB)
  Interrupt:16 Base address:0xd000

doua erori si 15 dropuite... placa sa fie?


Mai mult ca sigur ca e, poti sa pui alta sa vezi cum merge cu ea.



--
Besides, I think Slackware sounds better than Microsoft, don't you? - 
Patrick Volkerding


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


[rlug] iptables expire

2006-05-08 Fir de Conversatie Mihai Nanu

Salut la toata lista,

Am si o mica problema cu $SUBJ
Se da:
   kernel 2.6.16.14
   patch-o-matic (latest version)
   iptables-1.3.5

am pus patch-ul de expire si totul merge bine pana cand sa imi faca remove
la regula :-s

iptables -nL

Chain INPUT (policy ACCEPT)
target prot opt source   destination
ACCEPT all  --  0.0.0.0/00.0.0.0/0   expires in -4s


MN
___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


[rlug] Module

2006-05-08 Fir de Conversatie Teo

Salut,

imi cer scuze pt intrebarea poate prea banala, insa sunt incepator.
Am luate de la http://the-devil.dnsalias.net/home/extremist scriptul
acela de securitate, si, rulandu-l primesc:
FATAL: Module ip_nat not found.
FATAL: Module ipt_TTL not found.
FATAL: Module x_tables not found.
FATAL: Module xt_limit not found.
FATAL: Module xt_state not found.
FATAL: Module xt_tcpudp not found.

ipt_psd module not found... portscan detection match rules not used!

logging invalid packets...

adding open port -21 tcp...
ipt_connlimit module not found... tcp connections limit rules not used!
ipt_TTL module not found... ttl value not set!

Cum pot sa incarc acele module?

# uname -a
Linux www 2.6.4-52-default #1 Wed Apr 7 02:08:30 UTC 2004 i686 athlon
i386 GNU/Linux

SuSE Linux 9.1

Si inca o intrebare: Cand incerc sa schimb parola de root, stringul
care reprezinta parola, este trunchiat la 8 caractere. Cum pot
modifica acel nr. (8)?

Multumesc!

___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie Alex
On Monday 08 May 2006 13:46, IuliaN wrote:
  On Monday 08 May 2006 11:53, IuliaN wrote:
Incerc sa pun mrtg-ul sa faca niste poze cu trafic(n-am mai facut), si
  nu-mi afiseaza nimic(mai exact arata ca si cum traficul e zero)!
  Folosesc Kubuntu!
 
  Vad ca ai mai multe erori ... Uite aici un howto care e ok (ai tot ce
  trebuie
  ca sa o iei de la zero).
 
  http://www.siliconvalleyccie.com/linux-hn/mrtg.htm

   Acelasi rezultat cu indicatiile de aici(copy / paste .. si modificat
 community in public fata de ce era acolo)!


Pe routerul tau (nu mai stiu exact adresa sa de ip, dar sa luam ca ex ip-ul 
192.168.0.55)

mv /etc/snmp/snmpd.conf /etc/snmp/snmpd.conf.orig

si apoi pune in /etc/snmp/snmpd.conf
rocommunity public

dai apoi un restart la snmpd

dupa care vezi daca mai ai erori la interogarea via snmpwalk (de pe o statie 
din retea)

snmpwalk -v 1 -c public 192.168.0.55 system

daca merge ok, treci mai departe cu fisierele de configurare mrtg. Daca nu 
merge, atunci vezi sa sa nu ai firewall-ul activat.

Dai un:
/usr/bin/cfgmaker --output=/etc/mrtg/router1.cfg --global 
'workdir: /var/www/mrtg' -ifref=ip --global 'options[_]: growright,bits' 
[EMAIL PROTECTED]

exact ca in link-ul pe care ti l-am dat.

Daca in acest caz, treaba incepe sa functioneze, atunci incepi sa stringi 
surubul si te intorci la snmpd.conf  firewall, unde dupa parerea mea este 
problema!

Alex


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] mrtg on Kubuntu

2006-05-08 Fir de Conversatie IuliaN
  Si aparu si primul bat pe graficul meu!

Title[eth]: br0 eth
Target[eth]: 1:[EMAIL PROTECTED]
MaxBytes[eth]: 300
Options[eth]: bits,growright

 Pe masina in cauza nu am FIREWALL (e in LAN)! La interogarea snmpwalk -v
1 -c public 192.168.0.55 system cat si pe localhost nu dadea erori nici
inainte!

 On Monday 08 May 2006 13:46, IuliaN wrote:
  On Monday 08 May 2006 11:53, IuliaN wrote:
Incerc sa pun mrtg-ul sa faca niste poze cu trafic(n-am mai facut),
 si
  nu-mi afiseaza nimic(mai exact arata ca si cum traficul e zero)!
  Folosesc Kubuntu!
 
  Vad ca ai mai multe erori ... Uite aici un howto care e ok (ai tot ce
  trebuie
  ca sa o iei de la zero).
 
  http://www.siliconvalleyccie.com/linux-hn/mrtg.htm

   Acelasi rezultat cu indicatiile de aici(copy / paste .. si modificat
 community in public fata de ce era acolo)!


 Pe routerul tau (nu mai stiu exact adresa sa de ip, dar sa luam ca ex
 ip-ul
 192.168.0.55)

 mv /etc/snmp/snmpd.conf /etc/snmp/snmpd.conf.orig

 si apoi pune in /etc/snmp/snmpd.conf
 rocommunity public

 dai apoi un restart la snmpd

 dupa care vezi daca mai ai erori la interogarea via snmpwalk (de pe o
 statie
 din retea)

 snmpwalk -v 1 -c public 192.168.0.55 system

 daca merge ok, treci mai departe cu fisierele de configurare mrtg. Daca nu
 merge, atunci vezi sa sa nu ai firewall-ul activat.

 Dai un:
 /usr/bin/cfgmaker --output=/etc/mrtg/router1.cfg --global
 'workdir: /var/www/mrtg' -ifref=ip --global 'options[_]: growright,bits'
 [EMAIL PROTECTED]

 exact ca in link-ul pe care ti l-am dat.

 Daca in acest caz, treaba incepe sa functioneze, atunci incepi sa stringi
 surubul si te intorci la snmpd.conf  firewall, unde dupa parerea mea
 este
 problema!

 Alex


 ___
 RLUG mailing list
 RLUG@lists.lug.ro
 http://lists.lug.ro/mailman/listinfo/rlug




___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


[rlug] Iptables

2006-05-08 Fir de Conversatie George Calian
As vrea sa imi spuneti daca firewall-ul pe care l-am configurat eu este 
sigur.eth1 este in LAN;eth0 este interfata internet.
   
  -A INPUT -s 192.168.1.0/255.255.255.0 -i eth1 -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -m state --state NEW -j DROP
-A FORWARD -o eth0 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -d 192.168.1.0/255.255.255.0 -o eth1 -j ACCEPT
-A OUTPUT -o eth0 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
   
  Vreau sa stiu daca regula -A INPUT -i eth0 -m state --state NEW -j DROP imi 
ofera protectie si ma tine la distanta de relele din afara.
   
  Merci frumos!


-
Yahoo! Messenger with Voice. Make PC-to-Phone Calls to the US (and 30+ 
countries) for 2¢/min or less.

-
Yahoo! Mail goes everywhere you do.  Get it on your phone.
___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


Re: [rlug] Iptables

2006-05-08 Fir de Conversatie Ratiu Petru

On 5/8/06, George Calian [EMAIL PROTECTED] wrote:

As vrea sa imi spuneti daca firewall-ul pe care l-am configurat eu este 
sigur.eth1 este in LAN;eth0 este interfata internet.


Arata decent, dar: nu ai spus ce politici ai pe chainuri, regulile din
OUTPUT sunt cam degeaba, nu ai nat, fereste-te pe viitor sa mai dai
paste pe lista la scripturi si sa intrebi ce nu e in regula cu ele, si
de rele la modul generic nu te scapa decat Doamne-Doamne, Rusty face
niste miracole limitate ca amploare.

Petre.

___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug


RE: [rlug] Iptables

2006-05-08 Fir de Conversatie Ionut BOLDIZSAR
   Vreau sa stiu daca regula -A INPUT -i eth0 -m state --state NEW -j DROP
 imi ofera protectie si ma tine la distanta de relele din afara.
 
   Merci frumos!

Vezi ca protectia e un concept cu un grad mare de relativism (vezi
exemplul celebru al fabricii de preservative care produce si biberoane pe
aceasi linie de productie).

Din mailul tau rezulta ca singurul lucru care iti ofera tie protectie e
firewall-ul. Acum, iptables e un firewall *bun*. Foarte bun, chiar. Dar de
asemenea, iptables sties a se uite la layerele 3/4. Cam atat. Nothing more,
nothing less. Nu vreau sa par paranoic, dar in zilele astea, atacurile la
layer 3/4 sunt cam obsolete. Mai in voga par atacurile la nivele mai inalte
din modelul OSI, iar la asemenea atacuri, iptables (ca si majoritatea altor
firewall-uri) este inutil.

Acum, tu ai cerut aici o analiza a ruleset-ului tau si un verdict. Daca o sa
te culci pe urechea dreapta in baza faptului ca vei primi calificative de la
bine in sus *strict* pentru acel ruleset, o sa ai o problema. Mai de vreme
sau mai tarziu, *sigur* o sa ai o problema.

Nu ma mai lungesc inutil, ai deja un firewall-ruleset bun, poti deja sa
treci la layer 5-7. Vezi de-un antivirus, vezi de-un IDS/IPS, vezi de o
strategie de patch management. Relele de afara au nature si origini
complexe, asta nu inseamna ca nu o sa ai rele si inauntru. Principalul
rau dinauntru e factorul uman, iar aici o sa-ti fie mai greu sa scrii
vreun ruleset...

Regards,

//ionut


___
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug