Hello. I have one public AP at my work so people could get internet connectivity with their mobile devices or laptops. I have WPA2 Personal wireless security configured with a shared key. Although that is way not the best solution.
I could be using WPA2 Enterprise, but then there would be problems with connecting, so the best method in my opinion is web based authentication. I havent found about that much here in the forums, so I'm asking.
Are there any wireless routers/AP's which could be easily configured to work with Zentyal radius server and provide web-based authentication to users? I tried that with an old router with dd-wrt and chillispot, but I wasn't lucky.
I'm sure that there are people who have done that, because public wifi is just a very important thing to implement.

Installation and Upgrades / HTTP Proxy slow when higher load
« on: November 05, 2013, 05:23:12 pm »
I have traveled across this forum and commented on different discussions about problems with slowness with squid+dansguardian setup. I think my issue is a bit different.
Slow proxy. Mostly when 5+ clients are highly using the internet. Sometimes the inital requests are slow, takes 1-3sec to load (sometimes loads well), but when using proxy alone its pretty smooth, but still sometimes have tiny delays.
Without proxy its fine, DNS is working smooth. Even with proxy on it resolves DNS fine, the delays are usually on html/text documents.
In short what I have currently:
Intel Xeon CPU E3-1220 V2 3.10GHz
1TB 7200RPM HDD (hdparm -t shows ~140MB/s)
2 Gigabit ethernet ports
Zentyal 3.0.25 with HTTP Proxy (Cache and Filter) 3.0.14
File sharing, domain controller, webserver, NTP, VPN, Antivirus for samba
At one time there are 10-40 clients which are using internet.
I use the proxy as transparent proxy with filtering (bigblacklist with few categories enabled) for 2 network segments and non-filtered traffic for all other connections. I have modified configuration, because the default config was pretty slow to me.
Config files:
I have also modified dansguardian stub to fix forwarding loop issue described here,18388.0.html
I have assigned 40GB to squid cache, but its under the main system drive (I have only one drive in my server). Can that really be the bottleneck? The CPU load is low when proxy is used. And RAM usage is fine, no swapping occurs according to system stats and what squidclient says.
Also sometimes I get
Code: [Select]
WARNING - Queue congestion in my cache.log.
Also the filedescriptor count is fine and its always under the limit 65536.
I have Zentyal logging off for HTTP proxy.
The cache fs is reiserfs mounted with noatime and notail options. I recently switched from aufs to diskd caching method, but it didn't make any changes.
Maybe any ideas I can try? Meanwhile I will disable the transparent proxy and configure only for some devices.

Installation and Upgrades / Transparent proxy excemptions
« on: October 27, 2013, 09:51:53 am »
Hi. This should be easy to answer, but I couldn't stop thinking how this might work actually, so I did post here.
For unknown reason I am unable to install any Java updates trough transparent proxy, altrough offline installer does well. To fix this maybe I could bypass proxy for whole or domain, but will this work if I add transparent proxy excemption? Will this work for all subdomains of

Installation and Upgrades / Access to Zentyal API via PHP
« on: September 24, 2013, 09:55:51 am »
Hi. I have custom made PHP application to add new users, currently I'm typing them by hand into the Zentyal administration panel. It would be awesome and time-saving to automatically add them into the Zentyal server. I'm not familiar to perl, but probably would manage to write a tiny script based on what can be found on the internet. The problem would be launching that perl script (which uses zentyal api) with passed parameters (userame, password, name, surname) from PHP. Maybe anyone has done something like that?
Thanks in advance!

Installation and Upgrades / Can't delete empty GPO
« on: September 03, 2013, 05:57:01 pm »
Hi. So the problem is that I cant delete one empty GPO. This started after I added a new GPO and added a few computers in it, then removed the computers and tried to get rid of the gpo and now I cant.
Code: [Select]
admins@server:~$ sudo samba-tool gpo del {6AC1786C-016F-11D2-945F-00C04FB984F9}
ldb_wrap open of secrets.ldb
GENSEC backend 'gssapi_spnego' registered
GENSEC backend 'gssapi_krb5' registered
GENSEC backend 'gssapi_krb5_sasl' registered
GENSEC backend 'schannel' registered
GENSEC backend 'spnego' registered
GENSEC backend 'ntlmssp' registered
GENSEC backend 'krb5' registered
GENSEC backend 'fake_gssapi_krb5' registered
ERROR(ldb): uncaught exception - LDAP error 53 LDAP_UNWILLING_TO_PERFORM -  <00002035: objectclass: Cannot delete CN=User,CN={6AC1786C-016F-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=gnvg,DC=lan, it isn't permitted!> <>
  File "/opt/samba4/lib/python2.7/site-packages/samba/netcmd/", line 175, in _run
    return*args, **kwargs)
  File "/opt/samba4/lib/python2.7/site-packages/samba/netcmd/", line 1083, in run
    self.samdb.delete(ldb.Dn(self.samdb, "CN=User,%s" % str(gpo_dn)))
When trying to delete it via Windows RSAT utilities, it shows that server is unwilling to process the request.
Can I fix this manually? Thanks!

Installation and Upgrades / Logging stops after some time
« on: August 22, 2013, 10:16:54 am »
Hi. I had a problem like this in 2.2. It seems that after a day of usage, the logging stops, but Zentyal log service seems to be started. After restarting log service, it starts to work, but the period between that time is lost in the logs. It usually happens in somewhere between ~8 o'clock in the morning. Then no more logs are shown in the log section for any module.
Anyone getting this?
I'm using 3.0.25 as a gateway

Installation and Upgrades / Getting Zentyal 3.0 UPS module to work.
« on: August 07, 2013, 06:40:26 pm »
Hi. I got Orvaldi 620GE UPS and it should be compatible with upsmon and Linux in general (as nuts support all ups upsmart did , then it still should be supported), thats what the manufactuers homepage says about this specific model. It has 1 RS232 port and the Zentyal server also has 1 RS232 port. I have the RS232 wire hooked up and configured the UPS module like this:

And the error message is Error: Driver not connected and there are broadcasts in terminal that orvaldi@server is offline.
Sorry for posting in the wrong section before.  :D Also today I had very fancy behavior when changing UPS driver, I set it to genericups and as soon as nuts start - the server starts to shut down. The recovery console helped this time (removed /etc/init.d/nuts).
I don't know much about rs232 ports in Linux so maybe there is something i'm doing wrong or a fix or a way to look. In near future we are planning to buy a new UPS, maybe someone can share of what UPS works best with zentyal?
Thanks. :)

Hi. I mentioned this in a other thread, but I have a problem with VPN. Recently we bought a new server to our office and I started preconfiguring it. Some days ago I brought it to our office and plugged in, did basic ip config and it works very well and I have a lot of services running with no problems. Altrough there is now a little problem with VPN.
When I set a port which is not 1194/udp (default openvpn port) the VPN seems to work (clients are able to connect from the internet), but with 1194 set the traffic of my internal interface (eth1) stops (clients of eth1 cant access anything) and there is no access to VPN. After messing up with it now the internal network works (!) with port set to 1194/udp, but there seems still to be a problem with firewall as far as I can tell.
When I set the port to 1194 and do
Code: [Select]
sudo iptables -L | grep 1194then it outputs nothing, when I set the port to 1195 for example then
Code: [Select]
sudo iptables -L | grep 1195outputs the firewall rule. When I was preconfiguring the server at home, the VPN worked trough 1195 with no problems.

The problem is that our ISP has a firewall and allows to the internet only HTTP traffic over port 80/443 and VPN traffic over 1194. I have to deal with ISP in order to properly forward the new port (lets say 1195), which is a mess so I would prefer to get the old 1194 working.  :) Anyway it should have worked by default, but somehow it doesnt.
Anyways I'm having a pretty great expirience with Zentyal 3.0 and I am pretty impressed of all the new features it has. Also tried the transparent proxy thing which was unplanned and it is very responsive and hope it will be stable, because I had issues with squid in Zentyal 2.2, had to increase some url stuff (cant remember now) to make it not to hang when the usage was high.

Hello everyone! :) We have purchased a new more powerful server to our office and would like to get rid of router which routes all internet traffic. We want server to act as router.
I will try to describe the main current network structure here, hope you will understand:

                                                  [ALL OTHER WORKSTATIONS]

We would like to get rid of the router and directy put the cable coming from internet modem into eth0. So that would be the external network interface. eth1 would create internal network and it would look like this (sorry for the interesting diagrams ;D ):

                                                                               [ALL OTHER WORKSTATIONS]

I tried installing zentyal by selecting all gateway components and configuring eth0 as external with static ip's (provided by ISP) and configuring eth1 as static internal and assigning and netmask to it. After doing that I was able to access all  allowed Zentyal services from internal network (by connecting my laptop and manually assigning and zentyal DNS to it - just to test the internal network), BUT had no internet connection! I was able to ping and ping, the Windows network status also said that there is internet connectivity, but no pages could be opened except Zentyal administration page (
I also tried enabling transparent proxy, then very very slow traffic started to come trough (and then I broke something, so I'll try to reinstall it and try again), but I would like just to reroute the internet traffic to eth0 to eth1 with no proxy (I use non-transparent proxy for other reasons). What am I doing wrong? Also didn't get why the traffic was so slow with transparent proxy enabled (opening web page in 5-10 seconds)

The main point is get internet connection to work in internal networks by just rerouting it. The server has 2 network adapters, eth0 and eth1. If I cant do this then I'll have to stick with a router which tends to hang 1-2 times a month. I would also like the monitoring options I can get if I use Zentyal as router.


