Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - Remon

Pages: [1]
1
Hi, How could I (and using which mas? file) change the settings of the Web Server module to listen on _both_ port 80 and also port 8016 ?
I need this for a special piece of client sw, but I do not want to lose the normal listening port.


2
Installation and Upgrades / Change the LDAP dc hostname and domainname
« on: January 17, 2012, 12:09:54 am »
After installing I found out my LDAP dc settings used were the DHCP local domain settings in my router (linked to the Eth0 external nic).
But the server is going to be placed elsewhere where the use of 'domainname' is not really nice to see.
How can I alter this value after the server has been build? And is there any way to avoid this in the future at install?

Code: [Select]
LDAP information
Base DN: dc=servername,dc=domainname,dc=nl
Root DN: cn=ebox,dc=servername,dc=domainname,dc=nl
Users DN: ou=Users,dc=servername,dc=domainname,dc=nl
Groups DN: ou=Groups,dc=servername,dc=domainname,dc=nl

thx

3
Although subscribing to the zentyal cloud can be done OK, I cannot get it online.
In the dashboard it states that the VPN failed and the log tells more. The machine is a install of zentyal 2.2 with filesharing and the cloud client. All updates of modules and system applied.

I already tried removing all modules, rebooting and reinstalling them. What to try ?

Quote
Tue Jan 10 09:57:41 2012 OpenVPN 2.1.0 x86_64-pc-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [MH] [PF_INET6] [eurephia] built on Jul 20 2010
Tue Jan 10 09:57:41 2012 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Tue Jan 10 09:57:41 2012 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Jan 10 09:57:41 2012 WARNING: file '/etc/openvpn/R_D_SRVS_5ac349a8d.conf.d/certificateKey' is group or others accessible
Tue Jan 10 09:57:41 2012 /usr/bin/openssl-vulnkey -q -b 1024 -m <modulus omitted>
Tue Jan 10 09:57:42 2012 LZO compression initialized
Tue Jan 10 09:57:42 2012 Control Channel MTU parms [ L:1576 D:140 EF:40 EB:0 ET:0 EL:0 ]
Tue Jan 10 09:57:42 2012 Data Channel MTU parms [ L:1576 D:1450 EF:44 EB:135 ET:32 EL:0 AF:3/1 ]
Tue Jan 10 09:57:42 2012 Local Options hash (VER=V4): '31fdf004'
Tue Jan 10 09:57:42 2012 Expected Remote Options hash (VER=V4): '3e6d1056'
Tue Jan 10 09:57:42 2012 Attempting to establish TCP connection with [AF_INET]92.243.6.103:443 [nonblock]
Tue Jan 10 09:57:43 2012 TCP connection established with [AF_INET]92.243.6.103:443
Tue Jan 10 09:57:43 2012 Socket Buffers: R=[87380->131072] S=[16384->131072]
Tue Jan 10 09:57:43 2012 TCPv4_CLIENT link local: [undef]
Tue Jan 10 09:57:43 2012 TCPv4_CLIENT link remote: [AF_INET]92.243.6.103:443
Tue Jan 10 09:57:43 2012 TLS: Initial packet from [AF_INET]92.243.6.103:443, sid=5dd88df2 47083951
Tue Jan 10 09:57:43 2012 VERIFY OK: depth=1, /C=ES/ST=Nation/L=Nowhere/O=ebox-controlcenter.com/CN=Certification_Authority_Certificate
Tue Jan 10 09:57:43 2012 VERIFY OK: depth=0, /C=ES/ST=Nation/L=Nowhere/O=ebox-controlcenter.com/CN=vpn3.cloud.zentyal.com
Tue Jan 10 09:57:44 2012 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Tue Jan 10 09:57:44 2012 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Jan 10 09:57:44 2012 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Tue Jan 10 09:57:44 2012 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Jan 10 09:57:44 2012 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Jan 10 09:57:44 2012 [vpn3.cloud.zentyal.com] Peer Connection Initiated with [AF_INET]92.243.6.103:443
Tue Jan 10 09:57:46 2012 SENT CONTROL [vpn3.cloud.zentyal.com]: 'PUSH_REQUEST' (status=1)
Tue Jan 10 09:57:46 2012 AUTH: Received AUTH_FAILED control message
Tue Jan 10 09:57:46 2012 TCP/UDP: Closing socket
Tue Jan 10 09:57:46 2012 SIGTERM[soft,auth-failure] received, process exiting




4
I installed the server (zentyal 2.2) with a single NIC in a small network.1 that supplies IP's via DHCP. The server gets an IP OK and sets up the default gateway OK as well. The DNS entry under network also is set during the assignment.

I noticed when I took the server to another network.2 and connected it then it did get and except another ip address from the dhcp server there of another range as well, and the gatway as well. But the DNS server was not replaced by the correct one of the other server, it still had the DNS entry supplied by network 1.
I've been able to reproduce this now in 2 new servers.

Is this a known issue for anyone, or should I make a bug ticket in trac?

5
Could anybody elaborate how the gateway proxy is supposed to work, or point me to the error in my setup or expectations?

-I have a normal WAN gateway by DHCP, gateway = 10.20.0.1
-With this all setup I can surf the web from my zentyal server and get software updates with apt-get and the software maintenance
-I have setup a http proxy on the WAN side of my network network  on 10.20.0.33  port 8080  , so its positioned in the DMZ.
-Proxy test was OK: If i hard set in firefox on the server the proxy manual I see traffic on my proxy so its operational and reachable from the zentyal box

I now define this proxy in the Gateway section and Save

-> The proxy settings in FF on the box are set to normal again and I can goto internet BUT this is not via the proxy I see
-> I can nolonger get software updates with apt-get and the software maintenance, Access is denied
-> I so totally no attempt to address the external proxy in the proxy logs (high verbose and connection logging on).

I tried as http proxy and as socks4/5 proxy but as the system does not seem to try to open an connection is has no effect.

I checked the EXPORT settings, and as should, the proxy is listed there.
declare -x http_proxy="http://user:user@10.20.0.33:8080/"

6
Installation and Upgrades / 4 gateways, 2 not allowed to surf on. How?
« on: December 08, 2011, 11:55:42 pm »
I try to configure this situation.

There are 4 gateways defined, with nr4 being the default gateway with the highest preference as well.
1=GPRS router
2=WIFI client router
3=ADSL-Slow
4=Fiber-Highspeed

The intention is that only the ADSL+FIBER gateways allow HTTP traffic to go through.
The other 2, GPRS and WIFI may not be used to carry http trafic over.  Reason is that if both adsl + fiber connections fail then the limited bandwidth offered on 1&2 is reserved for a vpn control link & email.

I tried a testsetup with 2 gateways defined, gw1 one operational to internet, and gw2 nr 2 to a network address in use but not routing to internet causing a dead end.
Then I defined a gateway loadbalance rule that states the http traffic from the zentyal box as source should go over gw2, then I saved.

Result: The gw2 is detected 'dead' by the wan failover events, and is disabled. But when I start browsing on the zentyal box the traffic is not stopped and obviously goes out via gw1.

I would have expected the rules to block the http traffic. But the WAN check (that i need for normal failover) disables the trafficbalance rules for that gateway.


Any help to set this up is most welcome, should else firewall rule be required? The documentation points to QoS (traffic shaping?) to pick this up, but  how to block a traffic service in total via an appointed gateway/eth card ?



7
Installation and Upgrades / save the startup resolution in 2.2
« on: December 08, 2011, 11:04:13 pm »
Maybe this is specific to my hardware, but its really annoying..

Every time I reboot the screen resolution is 800x600, then I set to to 1024x768 and its fine until i reboot again.
How can I make this permanent?


8
Installation and Upgrades / How to add PHP support to the webmodule?
« on: December 04, 2011, 11:03:41 am »
Could someone tell me the advsed method to add PHP support to the general web server module?
Is there a central config gui option, or file?  Or should I really just apt-get it on top (what is the right packahe for Zerntyal 2.2 ?)

(PS: I do not want to install zarafa to get it as dependency package)
Thanks

9
The default behaviour for the VNC access to the VMs is by a port 5900 and up +1 for each VM in addition to  Zentyal automatically generates random passwords.

But where can I read these generates random passwords?

Pages: [1]