About Me

My photo
Hi Friends, I am Sandeep CC and some people know me as System Administrator. I have started my professional career from 2008. I have been working as System Administrator on Linux Server and Windows Client. I am here to share my Knowledge in which I have experienced and which I have come across till now, It could be help to you people. In case anything wrong or any improvements in my post steps, Please comment to the post, Feel free to contact me by posting comments on this blog. Thanks and Regards, Sandeep CC

Tuesday, December 30, 2014

Configure Wine on Redhat Linux / CentOS

                                  Configure Wine on Redhat Linux / CentOS




Introduction: Wine is one interface to install Windows application on Linux platform. There are many people who has doubt about running windows application (exp: Microsoft Office, .Net Framework or VLC/Teamviwer ) kind application, for that Wine is best way to install, Here We are covering how to configure / install wine 1.7 on CentOS 6.5 and how to run exe on it.


Requirement: (Need some services to be run)
1. Wine Binary Files (To Download Click Here )
2. Yum Server (Need to install some dependency by Yum , To know how to configure Yum Click Here )

Configuration:

Install Dependency before starting wine configuration

[root@proxy2 ~]#yum groupinstall 'Development Tools'

[root@proxy2 ~]#yum install libX11-devel freetype-devel zlib-devel libxcb-devel

Once all dependency installation get over move with wine configuration.

[root@proxy2 ~]#cd /usr/src (Download file from net in this location or its your choice where you feel to keep downloaded file)

[root@proxy2 src]wget  http://prdownloads.sourceforge.net/wine/wine-1.7.31.tar.bz2 (Download file by using wget command)

[root@proxy2 src]tar xjf wine-1.7.31.tar.bz2 (Unzip the directory by using tar command)

[root@proxy2 src]cd wine-1.7.31/ (change the directory  wine directory)

[root@proxy2 wine-1.7.31]./configure (Run the configure script file, this will take more than 20-30 min)

[root@proxy2 wine-1.7.31]make (Run the make command, this will take more than 45 min)

[root@proxy2 wine-1.7.31]make install (Run the make & install command, this will take more than 45 min)

How to use wine for exe:
 Take any exe file copy in to your linux machine -- > Right click --> Load this file with wine program --> click Next (same as per your requirement to install)

Note: Once Wine configuration over, when you load 1st time any exe with wine its takes more time to load, while running 1st time any exe it will do basic configuration itself, so in this 1st time it will configure mono & gecko installer. For mono configuration it will take long time to download and configure sometime it wont configure correctly in that case you manually have to download and configure, Mono is required for to use .Net applications.


Thanks & Regards,
Sandeep CC


Thursday, March 13, 2014

Configure Roundcube webmail on CentOS 6.5 / Redhat Linux

Configure Roundcube webmail on CentOS 6.5 / Redhat Linux


Introduction:  Roundcube is interface for webmail sever, which offers more features & user-friendly like  send-receive mails, calenders, marking, folder, adressbook and much more,  roundcube can be installed/configure on any OS platform (windows, linux, mac etc...). This required some basic configurations which we are going to discuss...I feel roundcube is better than squirrelmail to use/access mails (Its depend on people's choice )...for squirrelmail configuration Click Here

Requirement: (Need some service's to be run, installation steps given below links)
1. Roundcube binary files
2. Webserver (httpd) (Click Here)
3. Mysql (mysqld) (Click Here)
4. Php  (httpd) (Click Here)
5. Dovecot & Sendmail (Click Here)
6. DNS (Click Here)

Downloads:
Roundcube binary files: (Download) or (Download)

Basic Setup:
Setup host name and ip address (static), we must required to configure httpd, mysqld, dovecot, sendmail & named service's (for configuration of this service's, provided links above). modify below files(before modifying any files take a backup copy for your safer side),

1. Host name : /etc/sysconfig/network
[root@mailsvr ~]# cat /etc/sysconfig/network
NETWORKING=yes
HOSTNAME=mailsvr.com
[root@mailsvr ~]#

2. IP : /etc/sysconfig/network-scripts/ifcfg-eth0 (You can add eth1 as public static IP for access from internet)
[root@mailsvr ~]# cat /etc/sysconfig/network-scripts/ifcfg-eth0
DEVICE=eth0
BOOTPROTO=none
HWADDR=MACID
#IPV6INIT="yes"
#NM_CONTROLLED="yes"
ONBOOT=yes
TYPE=Ethernet
IPADDR=192.168.5.1
NETMASK=255.255.255.0
GATEWAY=192.168.5.1
DNS1=192.168.5.1
IPV6INIT=no
USERCTL=no
[root@mailsvr ~]#

3. cat /etc/resolv.conf
[root@mailsvr ~]# cat /etc/resolv.conf
# Generated by NetworkManager
search com
nameserver 192.168.5.1
nameserver static public dns provided by ISP

4. cat /etc/hosts
[root@mailsvr ~]# cat /etc/hosts (do not remove localhost ip name)
127.0.0.1       localhost.localdomain   localhost.localdomain   localhost4      localhost4.localdomain4 localhost
::1     localhost.localdomain   localhost.localdomain   localhost6      localhost6.localdomain6 localhost
192.168.5.1      mailsvr.com         mail
[root@mailsvr ~]#

5. create users by using useradd passwd commands

6. Make necessary changes in dovecot files cd /etc/dovecot/ & cd /etc/dovecot/conf.d/ directory files (Dovecot config files are different in rhel/centos 5/6 and rhel/centos 6/6.5 versions...

7. Firewall/iptables disable, SElinux disable, to work on iptables open port no - 80, 443, 143, 25

Create Database:
[root@mailsvr ~]# mysql -u root -p
Enter password:

mysql> CREATE DATABASE roundcubemail;
Query OK, 1 row affected (0.01 sec)

mysql> GRANT ALL PRIVILEGES ON roundcubemail.* TO roundcubemail@localhost IDENTIFIED BY 'roundcubemail123';
Query OK, 0 rows affected (0.00 sec)

mysql> flush privileges;
Query OK, 0 rows affected (0.00 sec)

mysql> exit
Bye

Installation of Roundcube:

Extract downloaded roundcube directory
[root@mailsvr Downloads]# tar -xvf roundcubemail-0.9.5.tar.gz

Move Extracted directory to /var/www/html
[root@mailsvr Downloads]# mv roundcubemail-0.9.5 /var/www/html

Change Directory Name (Keep name as we can access easily in web browser Exp: http://localhost/mails)

[root@mailsvr Downloads]# cd /var/www/html/
[root@mailsvr html]# mv roundcubemail-0.9.5 mails

Set Permission for /tmp & /logs directory (Better to change all directory and sub directory ownership by root:apache , its optional , actually not required to change , its just for troubleshooting issue if it is not working)

[root@mailsvr mails]# chown -R apache:apache temp/
[root@mailsvr mails]# chown -R apache:apache logs/

[root@mailsvr mails]# ls -ltr |egrep "logs|temp"
drwxr-xr-x  2 apache  apache  4096 Feb 26 12:58 temp
drwxr-xr-x  2 apache  apache  4096 Feb 26 12:58 logs
[root@mailsvr mails]#

Now open browser in server, give  http://localhost/mails/installer or http://192.168.5.1/mails/installer , There you will find 3 setup pages on top, you must need to complete 1st page then only you can go with 2nd page then 3rd last page. Keep in mind you must need to give created mysql db and pass correctly, Give all correct information, after 1st page compilation you have to download 2 files(2 files screen shot has given below) and keep that files in /var/www/html/mails/config/ path then continue on 3rd page (if you wont copy this file in particular path then you may get error for 3rd page). given below screen shot of 3 pages by modifying/adjusting...

Page-1
Installer Page - 1





Page -2

Installer Page - 2


Page -3
Installer Page - 3

Note: At the end of this configuration you must need to remove/move installer directory from /.../mails/ and move to somewhere. /.../mails/config/main.inc.php files as given below...

[root@mailsvr mails]# mv installer/ /home/
[root@mailsvr mails]# cd config/
[root@mailsvr config]# vi main.inc.php
$rcmail_config['enable_installer'] = false; -----------------> by default its true make it false.

after removing and disabling this installer option check it again in browser by giving same url http://192.168.5.1/mails/installer it should not work, final intention is our webmail server should not hack or access/modify by someone else who is not authorize person to touch this server, it should give error link below image.

After removing /installer/ directory
After disable installer option,
before removing /installer/ directory














Now your roundcube has configured completely, now you can access this webmail server by giving ip/name in browser http://192.168.5.1/mails , user name - password created in server


Mail Server in browser
User logged in
Thanks and Regards,
Sandeep CC

Thursday, February 20, 2014

Configure OwnCloud Server on CenteOS 6.5 / RHEL-5.3

Configure OwnCloud Server on CenteOS 6.5 / Redhat-5.3

owncloud is free open sorce software you can install in windows linux machine's, Make own shareing server, we can access any our file from anywhere in the world, software's are available for windows/unix/mac server and client, we can synchronize our file's from desktop mobile to server and download from server in any device's (Internet connection required for synchronize) , we can share our personal files,folders,calender,contacts(addressbook) etc... We have done owncloud setup in CentOS 6.5 server and using in windows/linux desktop & android mobiles...Lets see how to configure owncloud...


Requirement: owncloud binary file's,  Linux OS (We used CentOS 6.5), Apache(httpd), Mysql, Php (php-mysql php-json php-xml php-mbstring php-zip php-gd curl php-curl php-pdo) (LAMP), Client exe (optional), root user to configure all steps...

Downloads: Need to download owncloud binary file's, php almost all packages available in OS DVD till we need to downlaod some packages, given link downside...

owncloud -  download
php-mbstring (download for centos 6.5) - download
client exe (for windows/linux/mac desktop's) - download
android app - download

Basic Setup: Change system name as you need, give static IP (You can give dual IP, 1) Local IP for accessing internal 2) Direct public IP for access external), add DNS in /etc/resolv.conf file (for access this server from outside network)...

Disable SElinux & Firewall (iptables) for temp, you need to work this by firewall then enable port no 80 & 443 in iptables file...


LAMP Configuration:

Apache (httpd) Setup Steps -  ClickHere
Mysql Setup Steps - ClickHere
Php Setup Steps - ClickHere

Create Database: Create one database name on ownclouddb with user-ownclouduser password-myownpassword...

[root@owncloudsvr ~]# mysql -u root -p
Enter password:
mysql> CREATE DATABASE ownclouddb;
Query OK, 1 row affected (0.03 sec)
mysql>

mysql> GRANT ALL ON ownclouddb.* TO ownclouduser@localhost IDENTIFIED BY 'myownpassword';
Query OK, 0 rows affected (0.00 sec)
mysql>

mysql> flush privileges;
Query OK, 0 rows affected (0.00 sec)
mysql>

mysql> exit
Bye
[root@owncloudsvr ~]#

Owncloud Setup: After downloading owncloud binary file from given link move that whole folder to /var/www/html/ directory...

[root@owncloudsvr ~]# cd Downloads/
[root@owncloudsvr Downloads]# mv owncloud/ /var/www/html/
[root@owncloudsvr Downloads]#

[root@owncloudsvr Downloads]# cd /var/www/html/
[root@owncloudsvr html]# ls -ltr
total 4
drwxr-xr-x. 12 nobody 65534 4096 Dec 15 01:18 owncloud

(change ownership for owncloud directory user and group as apache)
[root@owncloudsvr html]# chown -R apache:apache owncloud/
[root@owncloudsvr html]#

[root@owncloudsvr html]# cd owncloud/
[root@owncloudsvr owncloud]#

(give full permission for config directory under owcloud directory)
[root@owncloudsvr owncloud]# chmod 777 config/
[root@owncloudsvr owncloud]#

(modify httpd.conf file under /etc/httpd/conf/ directory - before making changes take present file as backup for your safety purpose)
[root@owncloudsvr config]# cd /etc/httpd/conf
[root@owncloudsvr conf]# cp httpd.conf httpd.conf.org
[root@owncloudsvr conf]#
[root@owncloudsvr conf]# vi httpd.conf

    Options FollowSymLinks
    AllowOverride All -------------------------------------------------> None to All

[root@owncloudsvr conf]#

Start Service's:  Start mysqld and httpd service...
[root@owncloudsvr conf]# service mysqld restart
Stopping mysqld:                                           [  OK  ]
Starting mysqld:                                           [  OK  ]
[root@owncloudsvr conf]# service httpd restart
Stopping httpd:                                            [OK]
Starting httpd: httpd: apr_sockaddr_info_get() failed for owncloudsvr
httpd: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1 for ServerName
                                                           [  OK  ]
[root@owncloudsvr conf]#

Now your owncloud server is ready, Try to open website by using url: http://ip/owncloud OR http://servername/owncloud anywhere in mobile or client desktop etc... 1st time it will ask for finishup stage

1st time log on root user with server password, then inside root user you can create multiple user's with password, you can give diskspace for particular user for particular GB...You can install client exe on your linux/windows/mac desktop (download client exe from given above link) & you can synchronize your client desktop with your owncloud server (upload download files, calender, addressbook etc... )...


Thanks and Regards,
Sandeep CC



Wednesday, October 30, 2013

YUM CONFIGURATION & INSTALLATION ON REDHAT LINUX

YUM CONFIGURATION & INSTALLATION ON REDHAT LINUX

Requirements:
1. Need to copy all linux rpm packages in one directory (if you have ftp/httpd then copy /var/www/html or /var/ftp/pub direcotry, also you can keep anywhere in your linux box but you can't use this server for other linux clients for yum installation...)

2. Need to install createrepo rpm on server side...

3. yum packages (This package will installed default)

Copy All RPM to your linux location:
keep RHEL DVD in dvd rom and copy /Server directory to your selected location, In my server its running httpd service and vsftpd service so I am keep all copied file under httpd location /var/www/html/yumpack/

[root@proxy1 RHEL5]# cp -R Server/ /var/www/html/yumpack/
[root@proxy1 RHEL5]#
[root@proxy1 Server]# pwd
/var/www/html/yumpack/Server
[root@proxy1 Server]#

Installation of createrepo rpm:
[root@proxy1 Server]# rpm -ivh createrepo-0.4.11-3.el5.noarch.rpm
warning: createrepo-0.4.11-3.el5.noarch.rpm: Header V3 DSA signature: NOKEY, key ID 37017186
Preparing...                ########################################### [100%]
   1:createrepo             ########################################### [100%]
[root@proxy1 Server]#

Copy comps-rhel5-server-core.xml file to /var/www/html/yumpack/Server location from /var/www/html/yumpack/Server/repodata/

[root@proxy1 Server]# cd repodata/
[root@proxy1 repodata]# ls -ltr
total 10144
-rw-r--r-- 1 root root    1139 Oct 29 17:33 TRANS.TBL
-rw-r--r-- 1 root root 1010906 Oct 29 17:33 comps-rhel5-server-core.xml
-rw-r--r-- 1 root root 2400291 Oct 29 17:33 filelists.xml.gz
-rw-r--r-- 1 root root    1314 Oct 29 17:33 repomd.xml
-rw-r--r-- 1 root root  733418 Oct 29 17:33 primary.xml.gz
-rw-r--r-- 1 root root 6199888 Oct 29 17:33 other.xml.gz
[root@proxy1 repodata]#

[root@proxy1 repodata]# cp comps-rhel5-server-core.xml /var/www/html/yumpack/Server/
[root@proxy1 repodata]# cd ..
[root@proxy1 Server]#

[root@proxy1 Server]# ls -ltr |grep comp
-rw-r--r-- 1 root root    79270 Oct 29 17:33 compat-dapl-utils-2.0.13-4.el5.i386.rpm
-rw-r--r-- 1 root root  1010906 Oct 29 17:43 comps-rhel5-server-core.xml
[root@proxy1 Server]#

compat-dapl-utils-2.0.13-4.el5.i386.rpm this file content all rpm updates, that we have to update with group with that directory, follow below steps...
[root@proxy1 Server]# createrepo -vg comps-rhel5-server-core.xml /var/www/html/yumpack/Server/
1/2255
...
2254/2255 - esc-1.0.0-39.el5.i386.rpm
2255/2255 - xml-common-0.6.3-18.noarch.rpm
Saving Primary metadata
Saving file lists metadata
Saving other metadata
[root@proxy1 Server]#

In this file updation it will update all /Server rpm packs, see above it has updated 2255/2255 packages

Modify /etc/yum.repos.d/rhel-debuginfo.repo file (This steps you can do in server as well as in client machine)
[root@proxy1 Server]# cd /etc/yum.repos.d/
[root@proxy1 yum.repos.d]#
Keep original file copy for your safety purpose
[root@proxy1 yum.repos.d]# ls -ltr
total 8
-rw-r--r-- 1 root root 254 Dec 16  2008 rhel-debuginfo.repo
[root@proxy1 yum.repos.d]# cp rhel-debuginfo.repo rhel-debuginfo.repo.org
[root@proxy1 yum.repos.d]#

[root@proxy1 yum.repos.d]# vi rhel-debuginfo.repo
[my_Server]
name=my_Yum_Server
baseurl=http://172.16.4.205:9542/yumpack/Server/
enabled=1
gpgcheck=0

###clear yum cache### (This step need to do only in server side)

[root@proxy1 yum.repos.d]# yum clean all
Loaded plugins: rhnplugin, security
Cleaning up Everything
[root@proxy1 yum.repos.d]#

###update the yum####  (This step need to do only in server side)
[root@proxy1 yum.repos.d]# yum update
Loaded plugins: rhnplugin, security
This system is not registered with RHN.
RHN support will be disabled.
my_Server                                                                                                        | 1.1 kB    
00:00    
primary.xml.gz                                                                                                         | 791
kB     00:00    
my_Server                                                2255/2255
Skipping security plugin, no data
Setting up Update Process
No Packages marked for Update
[root@proxy1 yum.repos.d]#

###Test Yum Working or not (This step you can check with Server or client [if client /etc/yum.repos.d/rhel-debuginfo.repo modified])

[root@proxy1 ~]# yum install nfs-utils
Loaded plugins: rhnplugin, security
This system is not registered with RHN.
RHN support will be disabled.
Setting up Install Process
Parsing package install arguments
Resolving Dependencies
--> Running transaction check
---> Package nfs-utils.i386 1:1.0.9-40.el5 set to be updated
--> Processing Dependency: nfs-utils-lib >= 1.0.8-2 for package: nfs-utils
--> Processing Dependency: librpcsecgss.so.2 for package: nfs-utils
--> Processing Dependency: libnfsidmap.so.0 for package: nfs-utils
--> Running transaction check
---> Package nfs-utils-lib.i386 0:1.0.8-7.2.z2 set to be updated
--> Finished Dependency Resolution
Dependencies Resolved
=============================================================================================================================
 Package                            Arch                      Version                              Repository                
           Size
=============================================================================================================================
Installing:
 nfs-utils                          i386                      1:1.0.9-40.el5                       my_Server                 
    380 k
Installing for dependencies:
 nfs-utils-lib                      i386                      1.0.8-7.2.z2                         my_Server                 
     55 k
Transaction Summary
=============================================================================================================================
Install      2 Package(s)        
Update       0 Package(s)        
Remove       0 Package(s)        
Total download size: 434 k
Is this ok [y/N]: yes
Downloading Packages:
(1/2): nfs-utils-lib-1.0.8-7.2.z2.i386.rpm                                                                             |  55
kB     00:00    
(2/2): nfs-utils-1.0.9-40.el5.i386.rpm                                                                                 | 380
kB     00:00    
----------------------------------------------------------------------------------------------------------------------------
Total                                                                                                         3.7 MB/s | 434
kB     00:00    
Running rpm_check_debug
Running Transaction Test
Finished Transaction Test
Transaction Test Succeeded
Running Transaction
  Installing     : nfs-utils-lib                                     [1/2]
  Installing     : nfs-utils                                         [2/2]
Installed: nfs-utils.i386 1:1.0.9-40.el5
Dependency Installed: nfs-utils-lib.i386 0:1.0.8-7.2.z2
Complete!
[root@proxy1 ~]#

Thanks and Regards,
Sandeep CC

Wednesday, October 23, 2013

Install & Configure VNCSERVER on REDHAT LINUX-5


INSTALLATION & CONFIGURATION OF VNCSERVER ON REDHAT LINUX


Requirement: VNCSERVER package (server end) & Client version for client side...

INSTALL PACKAGE:

[root@proxy2 ~]# rpm -ivh vnc-server-4.1.1-10.1.0.0.1.i386.rpm
Preparing...                ########################################### [100%]
        package vnc-server-4.1.2-9.el5 (which is newer than vnc-server-4.1.1-10.1.0.0.1) is already installed
        file /etc/rc.d/init.d/vncserver from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /etc/sysconfig/vncservers from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/bin/Xvnc from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/bin/vncconfig from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/bin/vncpasswd from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/bin/vncserver from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/bin/x0vncserver from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/share/man/man1/vncserver.1.gz from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
        file /usr/share/vnc/classes/vncviewer.jar from install of vnc-server-4.1.1-10.1.0.0.1 conflicts with file from package vnc-server-4.1.2-9.el5
[root@proxy2 ~]#

ADD ONE USER FOR VNCSERVER (For security purpose don't use root user)
[root@proxy2 ~]# useradd vncserver

GO TO VNCSERVER USER (ALSO YOU CAN CREATE PASSWORD FOR LOCAL USERLOGIN BY USING "PASSWD USERNAME" COMMAND)
[root@proxy2 ~]# su -l vncserver

CREATE VNC SERVER PASSWORD FOR CREATED USER (this password is must required for remote login)
[vncserver@proxy2 root]$ vncpasswd
Password:
Verify:
[vncserver@proxy2 root]$

ALLOW CREATED USER TO VNCSERVER (Uncomment last 2 lines & give user session , like 1st user '1:myuser')
[root@proxy2 ~]# cd /etc/sysconfig/
[root@proxy2 sysconfig]# ls -ltr |grep vncser
-rw-r--r-- 1 root root   847 Jan 15  2007 vncservers
[root@proxy2 sysconfig]# cp vncservers vncservers.org
[root@proxy2 sysconfig]#
[root@proxy2 sysconfig]# vi vncservers
# The VNCSERVERS variable is a list of display:user pairs.
#
# Uncomment the lines below to start a VNC server on display :2
# as my 'myusername' (adjust this to your own).  You will also
# need to set a VNC password; run 'man vncpasswd' to see how
# to do that.
#
# DO NOT RUN THIS SERVICE if your local area network is
# untrusted!  For a secure way of using VNC, see
# .
# Use "-nolisten tcp" to prevent X connections to your VNC server via TCP.
# Use "-nohttpd" to prevent web-based VNC clients connecting.
# Use "-localhost" to prevent remote VNC clients connecting except when
# doing so through a secure tunnel.  See the "-via" option in the
# `man vncviewer' manual page.
# VNCSERVERS="2:myusername"
# VNCSERVERARGS[2]="-geometry 800x600 -nolisten tcp -nohttpd -localhost"
VNCSERVERS="1:vncserver" ------------------------------------------------------> ADD CREATED USER HERE
VNCSERVERARGS[1]="-geometry 1600x1200" ----------------------------------------> GIVE REQUIRED RESULATION TO VIEW

"vncservers" 23L, 911C written

#####MAKE ON VNCSERVER WHILE BOOTING SERVER#####
[root@proxy2 ~]# chkconfig --list |grep vncserver
vncserver       0:off   1:off   2:off   3:off   4:off   5:off   6:off
[root@proxy2 ~]# chkconfig --level 35 vncserver on
[root@proxy2 ~]# chkconfig --list |grep vncserver
vncserver       0:off   1:off   2:off   3:on    4:off   5:on    6:off
[root@eduproxy2 ~]#
[root@proxy2 sysconfig]#

##########SERVICE START############
[root@proxy2 sysconfig]# service vncserver start
Starting VNC server: 1:vncserver xauth:  creating new authority file /home/vncserver/.Xauthority
xauth: (stdin):1:  bad display name "proxy2.com:1" in "add" command
New 'proxy2.com:1 (vncserver)' desktop is proxy2.com:1
Creating default startup script /home/vncserver/.vnc/xstartup
Starting applications specified in /home/vncserver/.vnc/xstartup
Log file is /home/vncserver/.vnc/proxy2.com:1.log
                                                           [  OK  ]
[root@proxy2 sysconfig]#

### Go to Client machine###
Note: We can install vnc client version in any OS, I have installed and tried in XP platform...also we can open this vnc server on any java updated browser, you can see 2 steps also below...

Step-1: With VNC Client exe...




Step-2: Open in any java updated browser with default port 5801



Monday, September 23, 2013

SPLIT INTERNET SPEED/BANDWIDTH IN SQUID REDHAT LINUX-5

        Split Internet Speed/Bandwidth Limit on Squid REDHAT LINUX -5

Requirements :
1. Squid Installed and configured on Linux Machine.

2. --enable-delay-pools (This is mandatory, To check its enabled or not)
[[root@proxy1 ~]# squid -v
Squid Cache: Version 2.6.STABLE21
configure options:  '--build=i686-redhat-linux-gnu' '--host=i686-redhat-linux-gnu' '--target=i386-redhat-linux-gnu' '--program-prefix=' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--includedir=/usr/include' '--libdir=/usr/lib' '--libexecdir=/usr/libexec' '--sharedstatedir=/usr/com' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--exec_prefix=/usr' '--bindir=/usr/sbin' '--libexecdir=/usr/lib/squid' '--localstatedir=/var' '--datadir=/usr/share' '--sysconfdir=/etc/squid' '--enable-epoll' '--enable-snmp' '--enable-removal-policies=heap,lru' '--enable-storeio=aufs,coss,diskd,null,ufs' '--enable-ssl' '--with-openssl=/usr/kerberos' '--enable-delay-pools' '--enable-linux-netfilter' '--with-pthreads' '--enable-ntlm-auth-helpers=SMB,fakeauth' '--enable-external-acl-helpers=ip_user,ldap_group,unix_group,wbinfo_group' '--enable-auth=basic,digest,ntlm' '--enable-digest-auth-helpers=password' '--with-winbind-auth-challenge' '--enable-useragent-log' '--enable-referer-log' '--disable-dependency-tracking' '--enable-cachemgr-hostname=localhost' '--enable-underscores' '--enable-basic-auth-helpers=LDAP,MSNT,NCSA,PAM,SMB,YP,getpwnam,multi-domain-NTLM,SASL' '--enable-cache-digests' '--enable-ident-lookups' '--with-large-files' '--enable-follow-x-forwarded-for' '--enable-wccpv2' '--enable-fd-config' '--with-maxfd=16384' 'build_alias=i686-redhat-linux-gnu' 'host_alias=i686-redhat-linux-gnu' 'target_alias=i386-redhat-linux-gnu' 'CFLAGS=-D_FORTIFY_SOURCE=2 -fPIE -Os -g -pipe -fsigned-char' 'LDFLAGS=-pie'
[root@proxy1 ~]#]


3. Check internet is working fine in client side..

4. As per your requirement make different groups...

Scenario : I have installed Squid in RHEL-5 and given internet access to 172.16.4.X subnet... We have Lease line 4Mbps line. I have made 4 groups for different speed limit. This group can access internet speed max what we have assigned speed limit...
Group-1 : 172.16.4.1 to 172.16.4.51 (Unlimited Speed) /etc/squid/unlimited.txt
Group-2 : 172.16.4.51 to 172.16.4.100 (1Mbps) /etc/squid/our_1.5mbps.txt
Group-1 : 172.16.4.101 to 172.16.4.150 (1.5Mbps) /etc/squid/our_1mbps.txt
Group-1 : 172.16.4.151 to 172.16.4.240 (512Kbps) /etc/squid/our_512kbps.txt

Modify : /etc/squid/squid.conf file (Before modification take one backup copy for your safer side...) and enter given dalay_pools details after ACL entries...For group IP entries create 4 files in /etc/squid/ by speed limit as given above names...


##INTERNET SPEED LIMIT###
#Internet Speed Limit Define
acl all src 0.0.0.0/0.0.0.0 ##(Here you can define your Network)
acl unlimited src "/etc/squid/unlimited.txt"
acl our_1.5mbps src "/etc/squid/our_1.5mbps.txt"
acl our_1mbps src "/etc/squid/our_1mbps.txt"
acl our_512kbps src "/etc/squid/our_512kbps.txt"
http_access allow unlimited
http_access allow our_1.5mbps
http_access allow our_1mbps
http_access allow our_512kbps
http_access deny all
delay_pools 4
delay_class 1 2
delay_access 1 allow unlimited
delay_access 1 deny all
delay_parameters 1 -1/-1 -1/-1

delay_class 2 2
delay_access 2 allow our_1.5mbps
delay_access 2 deny all
delay_parameters 2 -1/-1 196608/196608

delay_class 3 2
delay_access 3 allow our_1mbps
delay_access 3 deny all
delay_parameters 3 -1/-1 131072/131072

delay_class 4 2
delay_access 4 allow our_512kbps
delay_access 4 deny all
delay_parameters 4 -1/-1 65536/65536

Save file and Restart Squid Service..

Above given details is 4 pools entry's... Here we have used dalay_class 2 for all 4 pools, as we have allowed dalay_parameters 4 65536/65536 (its in bytes for 512kbps) user can get max speed 512kbps only...as per your requirement you can change with speed limit...


Thanks and Regards,
Sandeep CC

Friday, August 16, 2013

Install/Configure Webmin Web-Based Access Tools on REDHAT LINUX

Install & Configure Webmin on Redhat Linux Server


Webmin is a web-based interface for system administration for Unix. Using any modern web browser, you can setup/create user accounts, you can start stop the services, you can ssh/remote login for command mod,  file sharing and much more. Webmin is one graphical/browsable easy simple access tool...I like this tool too much.... Lets see how to install webmin and how to use this simple tool...

Requirements:
1. Webmin RPM (Here we have used webmin-1.590-1.noarch.rpm version)

Installation:
[root@proxy2 home]# rpm -ivh webmin-1.590-1.noarch.rpm
warning: webmin-1.590-1.noarch.rpm: Header V3 DSA signature: NOKEY, key ID 11f63c51
Preparing...                ########################################### [100%]
Operating system is Redhat Enterprise Linux
   1:webmin                 ########################################### [100%]
Webmin install complete. You can now login to http://proxy2:10000/
as root with your root password.
[root@proxy2 home]#

Change Default Port No:

By default webmin gives 10000 port no, for your security purpose you can change port no to anything... Here i am changing 9543 port no...File is available in /etc/webmin/ (Before modification with original file take one backup copy for your safety purpose...)

[root@proxy2 webmin]# cp miniserv.conf miniserv.conf.org
[root@proxy2 webmin]#
[root@proxy2 webmin]# vi miniserv.conf
port=9543
Start/Stop/Status Webmin Service:
[root@proxy2 webmin]# service webmin status
Webmin (pid 13830) is running
[root@proxy2 webmin]# service webmin stop
Stopping Webmin server in /usr/libexec/webmin
[root@proxy2 webmin]# service webmin start
[root@proxy2 webmin]#

Create User By Webmin Tool: 


Created User Logins & Permission:

Tuesday, October 16, 2012

CONFIGURE ROUTER ON REDHAT LINUX-5/6 (SHOREWALL)

Shorewall Configuration On Redhat-5/6

Requirements:
1. Public Network
2. LAN Network
3. Linux Server (Required 3 NIC PORT)

4. Shorewall Package (Download Latest Shorewall Package and Install)

Here My Office Concepts:

I have configured Router by using Shorewall 3rd Party Tools,

Example:
ISP: 10.10.10.10 (Public)
LAN1: 172.16.4.1 - 172.16.4.254

LAN2: 192.168.4.1 - 192.168.4.10 (Public)

Scenario:
From ISP we have got one lease line (10.10.10.10) with 10 IP's Free, if we route to main lease IP then only we can use remaining 10 IP's as public IP anywhere in network, So here total now becanme 3 Network's 1. Main Public Network 2. Depended Public Network 3. Local Area Network, This 3 network also need to access ping each other network...

===================================================================

Installation:
[root@router home]# rpm -ivh shorewall-4.4.7-1.noarch.rpm
Preparing...                ########################################### [100%]
   1:shorewall              ########################################### [100%]
[root@router home]#

Sysctl.conf File Modification: IP Forwarding
[root@router etc]# cp sysctl.conf sysctl.conf.org
[root@router etc]# vi sysctl.conf
# Controls IP packet forwarding
net.ipv4.ip_forward = 1
(default it was 0 make it 1)

Basic Network & IP OF NETWORKS:
1. Public: 10.10.10.10 net eth0
2. Public + Private: 192.168.4.1 dmz eth2
3. Local: 172.16.4.1 loc eth1

Host Name
[root@router ~]# cat /etc/sysconfig/network
NETWORKING=yes
NETWORKING_IPV6=yes
HOSTNAME=edurouter.xyz.com

Put ISP DNS in resolv.conf file[root@router ~]# cat /etc/resolv.conf
; generated by /sbin/dhclient-script
#search localdomain
nameserver IPS DNS IP
nameserver IPS DNS IP

[root@router ~]#
Setup IP
[root@router ~]# ifconfig
eth0      Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX
          inet addr:10.10.10.10  Bcast:xx.xx.xx.xx  Mask:255.255.255.0
          inet6 addr: fa80::x11:58ff:feyc:5fa7/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:111447029 errors:0 dropped:0 overruns:0 frame:0
          TX packets:99925403 errors:0 dropped:0 overruns:0 carrier:0
          collisions:573853 txqueuelen:1000
          RX bytes:4184601542 (3.8 GiB)  TX bytes:1685430657 (1.5 GiB)
          Interrupt:193 Base address:0x2400

eth1      Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX 
          inet addr:172.16.4.1  Bcast:172.16.4.255  Mask:255.255.255.0
          inet6 addr: fe81::2z0:9llff:fe14322:7979/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:3227980 errors:0 dropped:0 overruns:0 frame:0
          TX packets:17165972 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:323716456 (308.7 MiB)  TX bytes:669689826 (638.6 MiB)
          Base address:0xecc0 Memory:fe100000-fe120000

eth2      Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX 
          inet addr:192.168.4.1  Bcast:192.168.4.255  Mask:255.255.255.0
          inet6 addr: f3e80::2a1fg0:7bff:fe4bs:b47/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:106119080 errors:0 dropped:0 overruns:0 frame:0
          TX packets:94155429 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:2329561954 (2.1 GiB)  TX bytes:3487500317 (3.2 GiB)
          Interrupt:201 Base address:0x4000

lo        Link encap:Local Loopback 
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:2934 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2934 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:11665575 (11.1 MiB)  TX bytes:11665575 (11.1 MiB)

[root@router ~]#


Configuration of Shorewall files: (Before modifiying take original file backup for your safety purpose)

Zone File (Introduce your Zone with IP Version)
[root@router etc]# cd /etc/shorewall[root@router shorewall]# cp zones zones.org
[root@router shorewall]# vi zones

###############################################################################
#ZONE    TYPE        OPTIONS        IN            OUT
#                    OPTIONS            OPTIONS
fw    firewall
net    ipv4
loc    ipv4
dmz    ipv4
[root@router shorewall]#

==========================================================================================================================
interfaces Interfaces File (Introduce your zones to Ethernet)
[root@router shorewall]# cp interfaces interfaces.org
[root@router shorewall]# vi interfaces

###############################################################################
#ZONE   INTERFACE       BROADCAST       OPTIONS
net     eth3    detect  routeback
loc     eth1    detect  tcpflags,routeback
net     eth2    detect  tcpflags,routeback
~                                                  

===========================================================================================================================
Policy File (Give Permissions to zones to accepts each other)
[root@router shorewall]# cp policy policy.org
[root@router shorewall]# vi policy


loc     dmz     ACCEPT
loc     fw      ACCEPT
fw      loc     ACCEPT
fw      dmz     ACCEPT
#dmz    loc     ACCEPT
# If you want open access to the Internet from your Firewall
# remove the comment from the following line.
fw              net             ACCEPT
net             all             DROP            info
# THE FOLLOWING POLICY MUST BE LAST
all             all             REJECT          info

============================================================================================================================
Masq
[root@router shorewall]# cp masq masq.org
[root@router shorewall]# vi masq

###############################################################################
#INTERFACE              SOURCE          ADDRESS         PROTO   PORT(S) IPSEC   MARK    USER/
#                                                                                       GROUP
eth3                    eth1
eth2                    eth1

==============================================================================================================================
Rules (Give your own company rules, open port for your required services)
[root@router shorewall]# cp rules rules.org
[root@router shorewall]# vi rules

#       Accept DNS connections from the firewall to the Internet
#
ACCEPT          fw              net             tcp     53
ACCEPT          fw              net             udp     53
#
#
#       Accept SSH connections from the local network to the firewall and DMZ
#
ACCEPT          loc             fw              tcp     22
ACCEPT          loc             dmz             tcp     22
#
#       DMZ DNS access to the Internet
#
ACCEPT          dmz             net             tcp     53
ACCEPT          dmz             net             udp     53

ACCEPT          loc             net             tcp     53
ACCEPT          loc             net             udp     53

ACCEPT          loc             fw              tcp     53
ACCEPT          loc             fw              udp     53

ACCEPT          dmz             fw              tcp     53
ACCEPT          dmz             fw              udp     53

ACCEPT          loc             net             udp     123
ACCEPT          loc             fw              udp     4242 # Ntop
#
#       Make ping work bi-directionally between the dmz, net, Firewall and local zone
#       (assumes that the loc-> net policy is ACCEPT).
#
ACCEPT          net             fw              icmp    8
ACCEPT          loc             fw              icmp    8
ACCEPT          dmz             fw              icmp    8
ACCEPT          loc             dmz             icmp    8
#
#ACCEPT         vpn             dmz             icmp    8
#ACCEPT         dmz             vpn             icmp    8
#
ACCEPT          dmz             loc             icmp    8
ACCEPT          dmz             net             icmp    8
ACCEPT          fw              net             icmp
ACCEPT          fw              loc             icmp
ACCEPT          fw              dmz             icmp
ACCEPT          net             dmz             icmp    8       # Only with Proxy ARP and
ACCEPT          net             loc             icmp    8       # static NAT
ACCEPT          loc             net             icmp

# additional rules (Router: July 14, 2012)
ACCEPT          loc                     net             tcp
#
#       DMZ to net access rules
#
ACCEPT          loc                     fw              tcp
#
# remote Desktop
ACCEPT        fw        net        tcp    3389
ACCEPT        net        loc        tcp    3389
ACCEPT        net        dmz        tcp    3389
ACCEPT        loc        dmz        tcp    3389
ACCEPT        dmz        loc        tcp    3389

#FTP
ACCEPT        net        fw        tcp    21
ACCEPT        net        fw        udp    21
ACCEPT          net             fw              tcp     20
ACCEPT          net             fw              udp     20
ACCEPT        net        loc        tcp    21
ACCEPT          net             loc             udp     21
ACCEPT          net             loc             tcp     20
ACCEPT          net             loc             udp     20

======================================================================================================================================
Shorewall.conf file (Check your config file should like below)
[root@router shorewall]# cp shorewall.conf shorewall.conf.org
[root@router shorewall]# vi shorewall.conf

#                      S T A R T U P   E N A B L E D
###############################################################################
STARTUP_ENABLED=Yes ------------------------> Default is no, make it yes
###############################################################################
#                             V E R B O S I T Y
###############################################################################
VERBOSITY=0 -------------------------------------> Default is 1, make it 0
###############################################################################
#                              L O G G I N G
###############################################################################
LOGFILE=/var/log/messages
STARTUP_LOG=/var/log/shorewall-init.log
LOG_VERBOSITY=1 ------------------------> Default is 2, Make it 1
LOGFORMAT="Shorewall:%s:%s:"
LOGTAGONLY=No
LOGRATE=
LOGBURST=
LOGALLNEW=
BLACKLIST_LOGLEVEL=
MACLIST_LOG_LEVEL=info
TCP_FLAGS_LOG_LEVEL=info
SMURF_LOG_LEVEL=info
LOG_MARTIANS=No ----------------------------> Default is Yes, Make it No
======================================================================================================================================
Keep Always On Shorewall Service:
[root@router shorewall]# chkconfig shorewall --levels 235 on
[root@router shorewall]#

Start Shorewall Service:
[root@router shorewall]# service shorewall start
Starting shorewall:                          [  OK  ] [root@router shorewall]#

Now try to ping each other from all 3 networks....

Thanks and Regards,
Sandeep CC