Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - cyberstudio

Pages: [1] 2 3 ... 5
1
Installation and Upgrades / Re: I keep getting squid errors
« on: January 23, 2015, 10:39:05 pm »
I was trying to clean the squid cache to see if that helps.

I was using these commands:
Quote
sudo /etc/init.d/zentyal squid stop
sudo rm -rf /var/spool/squid3/*
sudo squid3 -z
sudo /etc/init.d/zentyal squid start

When i run the bold one i get the following output:

Quote
server-gw01:/etc/init.d$ sudo squid3 -z
2015/01/23 17:33:56| WARNING: (B) '127.0.0.0/8' is a subnetwork of (A) '127.0.0.0/8'
2015/01/23 17:33:56| WARNING: because of this '127.0.0.0/8' is ignored to keep splay tree searching predictable
2015/01/23 17:33:56| WARNING: You should probably remove '127.0.0.0/8' from the ACL named 'to_localhost'
2015/01/23 17:33:56| WARNING: (B) '::1' is a subnetwork of (A) '::1'
2015/01/23 17:33:56| WARNING: because of this '::1' is ignored to keep splay tree searching predictable
2015/01/23 17:33:56| WARNING: You should probably remove '::1' from the ACL named 'to_localhost'
inabima@inabima-gw01:/etc/init.d$ 2015/01/23 17:34:06 kid1| WARNING: (B) '127.0.0.0/8' is a subnetwork of (A) '127.0.0.0/8'
2015/01/23 17:34:06 kid1| WARNING: because of this '127.0.0.0/8' is ignored to keep splay tree searching predictable
2015/01/23 17:34:06 kid1| WARNING: You should probably remove '127.0.0.0/8' from the ACL named 'to_localhost'
2015/01/23 17:34:06 kid1| WARNING: (B) '::1' is a subnetwork of (A) '::1'
2015/01/23 17:34:06 kid1| WARNING: because of this '::1' is ignored to keep splay tree searching predictable
2015/01/23 17:34:06 kid1| WARNING: You should probably remove '::1' from the ACL named 'to_localhost'
2015/01/23 17:34:16 kid1| Creating missing swap directories
2015/01/23 17:34:16 kid1| No cache_dir stores are configured.

Is anything wrong there? that part of "No cache_dir stores are configured" seems wrong to me

2
Installation and Upgrades / I keep getting squid errors
« on: January 22, 2015, 02:56:56 pm »
Hi guys!

From like a month ago im getting constant and random squid errors. Sometimes you're browsing normally and then you get this error:
Quote
This cache is in the process of shutting down and can not service your request at this time. Please retry your request again soon.

or this one:
Quote
Zero Sized Reply

Squid did not receive any data for this request.

or this one:
Quote
Read Error

The system returned: (104) Connection reset by peer

An error condition occurred while reading data from the network. Please retry your request.

When that happens, i keep pressing F5 (refresh) and i keep getting errors (One of those, randomly) until suddenly the request works and the page loads normally. Sometimes you need to press F5 10 times or so.

If you're browsing on 5 tabs, you may get the problem on one of them, while you can continue browsing on the other 4.

Im running a transparent proxy, with the checkbox "ad blocking" checked, my cache size is 8192mb
looking at my cache.log, i can see huuuuundreds and hundreds of:
Quote
ERROR: No forward-proxy ports configured.
i don't know if that is related or not.

My squid.conf is:
Quote
http_port 0.0.0.0:3128 intercept

visible_hostname (frontal)inabima-gw01.inabimasd.local
coredump_dir /var/spool/squid3
cache_effective_user proxy
cache_effective_group proxy
access_log /var/log/squid3/access.log squid
cache_log /var/log/squid3/cache.log
cache_store_log /var/log/squid3/store.log

pid_filename /var/run/squid3.pid


cache_peer 127.0.0.1 parent 3129 0 no-query proxy-only login=*:nopassword

auth_param basic realm Zentyal HTTP proxy
auth_param basic program /usr/lib/squid3/basic_ldap_auth -v3 -b DC=inabimasd,DC=local -f "(&(samAccountName=%s)(objectclass=user))" -p 3268 -D CN=zentyal-squid-inabima-gw01,CN=Users,DC=inabimasd,DC=local -w AYbgZYC6HWEjFvTe7Gdd -P
external_acl_type ldapgroup  ipv4 %LOGIN /usr/lib/squid3/ext_ldap_group_acl -v3 -b DC=inabimasd,DC=local   -p 3268 -D CN=zentyal-squid-inabima-gw01,CN=Users,DC=inabimasd,DC=local -w AYbgZYC6HWEjFvTe7Gdd -P -F "(&(samAccountName=%s)(objectclass=user))" -f  "(&(samAccountName=%g)(objectclass=group)(member=%u))"


acl_uses_indirect_client on
acl authorized proxy_auth REQUIRED

acl from_localhost src 127.0.0.0/8 ::1
acl to_localhost dst 127.0.0.0/8 ::1

acl fltr1~ext urlpath_regex -i .mp3$
acl fltr1~mime rep_mime_type -i ^application/java-vm$
acl fltr1~df~dmn33 dstdomain .ascodevida.com
acl fltr1~df~dmn32 dstdomain .mekstream.com
acl fltr1~df~dmn31 dstdomain .mek4.mekstream.com
acl fltr1~df~dmn30 dstdomain .emisoradominicana.net
acl fltr1~df~dmn29 dstdomain .animeflv.net
acl fltr1~df~dmn28 dstdomain .scribd.com
acl fltr1~df~dmn27 dstdomain .canalesdominicano.com
acl fltr1~df~dmn26 dstdomain .telemicro.com.do
acl fltr1~df~dmn25 dstdomain .instagram.com
acl fltr1~df~dmn24 dstdomain .musicatube.net
acl fltr1~df~dmn23 dstdomain .dicelacancion.net
acl fltr1~df~dmn22 dstdomain .genteflow.com
acl fltr1~df~dmn21 dstdomain .paradaurbana.net
acl fltr1~df~dmn20 dstdomain .downflow.net
acl fltr1~df~dmn19 dstdomain .flowactivo.com
acl fltr1~df~dmn18 dstdomain .lomasrankiao.com
acl fltr1~df~dmn17 dstdomain .iexalead.com
acl fltr1~df~dmn16 dstdomain .isearchspace.com
acl fltr1~df~dmn15 dstdomain .nuevaq.net
acl fltr1~df~dmn14 dstdomain .sonicomp3.com
acl fltr1~df~dmn13 dstdomain .fullhumor.com
acl fltr1~df~dmn12 dstdomain .gamerfuzion.com
acl fltr1~df~dmn11 dstdomain .mrhookah.com
acl fltr1~df~dmn10 dstdomain .dhookah.blogspot.com
acl fltr1~df~dmn9 dstdomain .youtubereloaded.com
acl fltr1~df~dmn8 dstdomain .elmismogolpe.com
acl fltr1~df~dmn7 dstdomain .screencast.com
acl fltr1~df~dmn6 dstdomain .ooyala.com
acl fltr1~df~dmn5 dstdomain .jigsawplanet.com
acl fltr1~df~dmn4 dstdomain .intercambiosvirtuales.org
acl fltr1~df~dmn3 dstdomain .figureord.com
acl fltr1~df~dmn2 dstdomain .conquista.91.com
acl fltr1~df~dmn1 dstdomain .91huo.com
acl Dominios~dc~virusinfected~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/virusinfected/domains.squid"
acl Dominios~dc~remote-control~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/remote-control/domains.squid"
acl Dominios~dc~entertainment~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/entertainment/domains.squid"
acl Dominios~dc~sexuality~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/sexuality/domains.squid"
acl Dominios~dc~dating~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/dating/domains.squid"
acl Dominios~dc~mixed_adult~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/mixed_adult/domains.squid"
acl Dominios~dc~audio-video~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/audio-video/domains.squid"
acl Dominios~dc~weapons~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/weapons/domains.squid"
acl Dominios~dc~webmail~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/webmail/domains.squid"
acl Dominios~dc~radio~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/radio/domains.squid"
acl Dominios~dc~manga~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/manga/domains.squid"
acl longAcl~1 dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/instantmessaging/domains.squid"
acl Dominios~dc~hacking~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/hacking/domains.squid"
acl Dominios~dc~gambling~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/gambling/domains.squid"
acl Dominios~dc~filesharing~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/filesharing/domains.squid"
acl Dominios~dc~filehosting~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/filehosting/domains.squid"
acl Dominios~dc~violence~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/violence/domains.squid"
acl Dominios~dc~malware~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/malware/domains.squid"
acl Dominios~dc~social_networks~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/social_networks/domains.squid"
acl Dominios~dc~chat~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/chat/domains.squid"
acl longAcl~2 dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/socialnetworking/domains.squid"
acl Dominios~dc~phishing~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/phishing/domains.squid"
acl Dominios~dc~adult~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/adult/domains.squid"
acl Dominios~dc~proxy~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/proxy/domains.squid"
acl Dominios~dc~onlinegames~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/onlinegames/domains.squid"
acl Dominios~dc~dialers~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/dialers/domains.squid"
acl Dominios~dc~warez~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/warez/domains.squid"
acl Dominios~dc~celebrity~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/celebrity/domains.squid"
acl Dominios~dc~hunting~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/hunting/domains.squid"
acl Dominios~dc~mail~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/mail/domains.squid"
acl Dominios~dc~humor~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/humor/domains.squid"
acl Dominios~dc~games~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/games/domains.squid"
acl Dominios~dc~porn~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/porn/domains.squid"
acl Dominios~dc~drugs~dom dstdomain "/var/lib/zentyal/files/squid/categories/Dominios/blacklists/drugs/domains.squid"

http_access allow to_localhost
follow_x_forwarded_for allow from_localhost
http_access allow from_localhost
forwarded_for on
log_uses_indirect_client on
always_direct allow to_localhost

# force clients to use squid-external
never_direct allow all


##
## ACLs from model rules
##
acl obj~objc1 src 10.0.0.226/32 10.0.0.134/32 10.0.0.88/32 10.0.0.223/32 10.0.0.100/32 10.0.0.224/32 10.0.0.92/32 10.0.0.221/32 10.0.0.222/32 10.0.0.24/32
acl obj~objc1 src 10.0.0.168/32
##
## Access
##

http_access allow  obj~objc1
http_access deny  all fltr1~ext
http_reply_access deny  all fltr1~mime
http_access deny  all fltr1~df~dmn33
http_access deny  all fltr1~df~dmn32
http_access deny  all fltr1~df~dmn31
http_access deny  all fltr1~df~dmn30
http_access deny  all fltr1~df~dmn29
http_access allow  all fltr1~df~dmn28
http_access deny  all fltr1~df~dmn27
http_access deny  all fltr1~df~dmn26
http_access deny  all fltr1~df~dmn25
http_access deny  all fltr1~df~dmn24
http_access deny  all fltr1~df~dmn23
http_access deny  all fltr1~df~dmn22
http_access deny  all fltr1~df~dmn21
http_access deny  all fltr1~df~dmn20
http_access deny  all fltr1~df~dmn19
http_access deny  all fltr1~df~dmn18
http_access deny  all fltr1~df~dmn17
http_access deny  all fltr1~df~dmn16
http_access deny  all fltr1~df~dmn15
http_access deny  all fltr1~df~dmn14
http_access deny  all fltr1~df~dmn13
http_access deny  all fltr1~df~dmn12
http_access deny  all fltr1~df~dmn11
http_access deny  all fltr1~df~dmn10
http_access deny  all fltr1~df~dmn9
http_access deny  all fltr1~df~dmn8
http_access deny  all fltr1~df~dmn7
http_access deny  all fltr1~df~dmn6
http_access deny  all fltr1~df~dmn5
http_access deny  all fltr1~df~dmn4
http_access deny  all fltr1~df~dmn3
http_access deny  all fltr1~df~dmn2
http_access deny  all fltr1~df~dmn1
http_access deny  all Dominios~dc~adult~dom
http_access deny  all Dominios~dc~audio-video~dom
http_access deny  all Dominios~dc~celebrity~dom
http_access deny  all Dominios~dc~chat~dom
http_access deny  all Dominios~dc~dating~dom
http_access deny  all Dominios~dc~dialers~dom
http_access deny  all Dominios~dc~drugs~dom
http_access deny  all Dominios~dc~entertainment~dom
http_access deny  all Dominios~dc~filehosting~dom
http_access deny  all Dominios~dc~filesharing~dom
http_access deny  all Dominios~dc~gambling~dom
http_access deny  all Dominios~dc~games~dom
http_access deny  all Dominios~dc~hacking~dom
http_access deny  all Dominios~dc~humor~dom
http_access deny  all Dominios~dc~hunting~dom
http_access deny  all longAcl~1
http_access deny  all Dominios~dc~mail~dom
http_access deny  all Dominios~dc~malware~dom
http_access deny  all Dominios~dc~manga~dom
http_access deny  all Dominios~dc~mixed_adult~dom
http_access deny  all Dominios~dc~onlinegames~dom
http_access deny  all Dominios~dc~phishing~dom
http_access deny  all Dominios~dc~porn~dom
http_access deny  all Dominios~dc~proxy~dom
http_access deny  all Dominios~dc~radio~dom
http_access deny  all Dominios~dc~remote-control~dom
http_access deny  all Dominios~dc~sexuality~dom
http_access deny  all Dominios~dc~social_networks~dom
http_access deny  all longAcl~2
http_access deny  all Dominios~dc~violence~dom
http_access deny  all Dominios~dc~virusinfected~dom
http_access deny  all Dominios~dc~warez~dom
http_access deny  all Dominios~dc~weapons~dom
http_access deny  all Dominios~dc~webmail~dom
http_access allow  all


##
## Default policy
##
# All acces denied by default if no other allow rule matchs
http_access deny all
# reply access allowed if not denied before
http_reply_access allow all
'

I dont know where to start. ahy help please? thanks!

3
Why do you want it? Its not working anyway...

4
I need to try again to see, but we're still at 3.3.10 so maybe its just the same :(

And no word yet from the official zentyal team.  :-\

5
Ok, en espanol y en ingles :P

Ingles:
Well ruben, if you want to try, be sure to make a FULL backup of your server first (Be sure that you know how to make that backup and how to restore it if you need). Im also running zentyal 3.3. My server is running in a virtual machine, so its very easy for me to take a snapshot before trying, and restoring it if something goes wrong. I have tried 2 times to upgrade, and the upgrade always fails with lots of error inside the log. Lots of people are having problems too, so i wont recommend you to try to upgrade without a full backup in hand.

En espanol:
Bueno ruben, si quieres intentar hacer el upgrade, asegurate de tener un backup COMPLETO antes de hacer cualquier cosa (Asegurate de que sabes hacer el backup, y de que puedes restaurarlo bien en caso de que lo necesites). Yo tambien estoy usando Zentyal 3.3. Mi servidor esta corriendo en una maquina virtual, asi que me resulta bien facil hacer un snapshot y restaurarlo en caso de que algo salga mal. Ya he intentado hacer el uprade dos veces y las dos veces falla. Cuando reviso el log hay bastantes errores. No es solo un caso mio... muchas personas aqui en el foro estan teniendo problemas con el upgrade. asi que si quieres intentarlo... adelante, pero hazlo en horario no laborable, y con un backup a mano.

6
Installation and Upgrades / Re: Need help in Static Route
« on: April 24, 2014, 05:58:23 pm »
You have a server on your internal network, and you want to expose a service to the external network? (a webserver maybe?)

7
Hi guys! There's something that i dont get, and that's my question: Why its Zentyal based on ubuntu, and sometimes not even on the LTS branch?

The upgrade process from 3.3 to 3.4 its a real pain (im not able to upgrade yet... lots of errors), and i think that many of those problems came as a result of the underlying distribution upgrade. As you know, zentyal 3.4 its not just a new zentyal version, but also based on a new ubuntu release, so the upgrade process needs to upgrade the Zentyal packages and also the distribution packages.

I have nothing against ubuntu. What i dont understand is why Zentyal uses Ubuntu 13.10 for Zentyal 3.4? That's madness! Ubuntu 13.10 has his end of life on July 2014! That's a few weeks away already.

The TLS branches seems more suited for Zentyal, Even Centos looks like a better choice.

8
Hi.

I have a production zentyal server (A VM on ESXi). This server was running zentyal 3.2 and was upgraded to zentyal 3.3 without any problems a few months ago. Yesterday i was trying to upgrade to zentyal 3.4, so i made an snapshot prior to trying (and thanks god that i did).

During the automated process i saw multiple errors on the update log, and the last message was "Zentyal upgrade failed. Full log at /var/log/zentyal/upgrade.log." so i had to revert back to my pre-update snapshot.

These where the errors that i got during the update process.

The first one...
Quote
Preparing to replace suricata 1.1.1-1 (using .../suricata_1.4.3-1_amd64.deb) ...
 * NFQUEUE support not found !
 * Please ensure the nfnetlink_queue module is loaded or built in kernel
invoke-rc.d: initscript suricata, action "stop" failed.
dpkg: warning: subprocess old pre-removal script returned error exit status 5
dpkg: trying script from the new package instead ...
 * NFQUEUE support not found !
 * Please ensure the nfnetlink_queue module is loaded or built in kernel
invoke-rc.d: initscript suricata, action "stop" failed.
dpkg: error processing /var/cache/apt/archives/suricata_1.4.3-1_amd64.deb (--unpack):
 subprocess new pre-removal script returned error exit status 5
 * NFQUEUE support not found !
 * Please ensure the nfnetlink_queue module is loaded or built in kernel
invoke-rc.d: initscript suricata, action "start" failed.
dpkg: error while cleaning up:
 subprocess installed post-installation script returned error exit status 5

Another one...
Quote
Errors were encountered while processing:
 /var/cache/apt/archives/suricata_1.4.3-1_amd64.deb
E: Sub-process /usr/bin/dpkg returned an error code (1)

Forcing pending packages installation...

Quote
The following packages will be upgraded:
  suricata
E: Could not open file descriptor -1
E: Prior errors apply to /var/cache/apt/archives/libcgi-emulate-psgi-perl_0.15-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libapache-logformat-compiler-perl_0.12-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libdevel-stacktrace-ashtml-perl_0.11-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libfile-sharedir-perl_1.03-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libfilesys-notify-simple-perl_0.12-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libhash-multivalue-perl_0.12-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libpath-class-perl_0.32-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libyaml-perl_0.84-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libhttp-body-perl_1.17-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libhttp-tiny-perl_0.034-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libmodule-refresh-perl_0.17-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libstream-buffered-perl_0.2-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libtest-requires-perl_0.07-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libtest-sharedfork-perl_0.19-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libtest-tcp-perl_2.00-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libplack-perl_1.0028-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libplack-middleware-reverseproxy-perl_0.14-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libplack-middleware-session-perl_0.14-1_all.deb
E: Prior errors apply to /var/cache/apt/archives/libpgm-5.1-0_5.1.118-1~dfsg-0.1ubuntu1_amd64.deb
E: Prior errors apply to /var/cache/apt/archives/libzmq1_2.2.0+dfsg-4_amd64.deb
E: Prior errors apply to /var/cache/apt/archives/uwsgi-core_1.9.13-4build1_amd64.deb
E: Prior errors apply to /var/cache/apt/archives/uwsgi-plugin-psgi_1.9.13-4build1_amd64.deb
E: Prior errors apply to /var/cache/apt/archives/suricata_1.4.3-1_amd64.deb
E: Prior errors apply to /var/cache/apt/archives/libsoap-transport-http-plack-perl_0.03-1_all.deb
debconf: apt-extracttemplates failed: No such file or directory


Quote
Preparing to replace suricata 1.1.1-1 (using .../suricata_1.4.3-1_amd64.deb) ...
 * NFQUEUE support not found !
 * Please ensure the nfnetlink_queue module is loaded or built in kernel
invoke-rc.d: initscript suricata, action "stop" failed.
dpkg: warning: subprocess old pre-removal script returned error exit status 5
dpkg: trying script from the new package instead ...
 * NFQUEUE support not found !
 * Please ensure the nfnetlink_queue module is loaded or built in kernel
invoke-rc.d: initscript suricata, action "stop" failed.
dpkg: error processing /var/cache/apt/archives/suricata_1.4.3-1_amd64.deb (--unpack):
 subprocess new pre-removal script returned error exit status 5
 * NFQUEUE support not found !
 * Please ensure the nfnetlink_queue module is loaded or built in kernel
invoke-rc.d: initscript suricata, action "start" failed.
dpkg: error while cleaning up:
 subprocess installed post-installation script returned error exit status 5
Processing triggers for man-db ...
Processing triggers for ureadahead ...
Errors were encountered while processing:
 /var/cache/apt/archives/suricata_1.4.3-1_amd64.deb
E: Sub-process /usr/bin/dpkg returned an error code (1)

Quote
dpkg: dependency problems prevent configuration of zentyal-remoteservices:
 zentyal-remoteservices depends on libsoap-transport-http-plack-perl; however:
  Package libsoap-transport-http-plack-perl is not installed.

dpkg: error processing zentyal-remoteservices (--configure):
 dependency problems - leaving unconfigured

Quote
Installing new version of config file /etc/init.d/collectd ...
 * Starting statistics collection and monitoring daemon collectd
   ...fail!

(Maybe not an error?)
Quote
Setting up openvpn (2.3.2-4ubuntu1) ...
 * Restarting virtual private network daemon(s)...
 *   Stopping VPN 'Inabima-central'
   ...done.
 *   Restarting VPN 'Inabima-central'
grep: /etc/openvpn/Inabima-central.conf: No such file or directory
grep: /etc/openvpn/Inabima-central.conf: No such file or directory
grep: /etc/openvpn/Inabima-central.conf: No such file or directory
grep: /etc/openvpn/Inabima-central.conf: No such file or directory

Quote
dpkg: error processing suricata (--configure):
 Package is in a very bad inconsistent state - you should
 reinstall it before attempting configuration.

Quote
dpkg: dependency problems prevent configuration of zentyal-ips:
 zentyal-ips depends on suricata; however:
  Package suricata is not configured yet.

dpkg: error processing zentyal-ips (--configure):
 dependency problems - leaving unconfigured

Quote
Configuration file `/etc/collectd/collectd.conf'
 ==> Modified (by you or by a script) since installation.
 ==> Package distributor has shipped an updated version.
 ==> Keeping old config file as default.
 * Restarting statistics collection and monitoring daemon collectd
   ...fail!

(Maybe not an error?)
Quote
Installing new version of config file /etc/default/openbsd-inetd ...
 * Stopping internet superserver inetd
   ...done.
 * Not starting internet superserver: no services enabled

Warning
Quote
Installing new version of config file /etc/init.d/ddclient ...
update-rc.d: warning:  stop runlevel arguments (1) do not match ddclient Default-Stop values (0 1 6)

Quote
Setting up dansguardian (2.10.1.1-5) ...
Installing new version of config file /etc/init.d/dansguardian ...
/var/log/dansguardian
 * Starting DansGuardian dansguardian
   ...fail!
invoke-rc.d: initscript dansguardian, action "start" failed.
WARNING: Starting dansguardian failed. Please check your configuration.

Quote
Installing new version of config file /etc/ldap/schema/README ...
  Backing up /etc/ldap/slapd.d in /var/backups/slapd-2.4.28+51~precise1... done.
Not starting slapd: SLAPD_NO_START set in /etc/default/slapd

Quote
econnecting to redis server (1 try)... at /usr/share/perl5/EBox/Config/Redis.pm line 479, <GEN1> line 1.
Reconnecting to redis server (2 try)... at /usr/share/perl5/EBox/Config/Redis.pm line 479, <GEN2> line 1.
Reconnecting to redis server (3 try)... at /usr/share/perl5/EBox/Config/Redis.pm line 479, <GEN3> line 1.
Reconnecting to redis server (4 try)... at /usr/share/perl5/EBox/Config/Redis.pm line 479, <GEN4> line 1.
Redis command 'get remoteservices/conf/RemoteSupportAccess/keys/form' failed: [get] ERR wrong number of arguments for 'get' command,  at /usr/share/perl5/Redis.pm line 513
        Redis::__read_response_r('Redis=HASH(0x46c86f0)', 'get') called at /usr/share/perl5/Redis.pm line 493
        Redis::__read_response('Redis=HASH(0x46c86f0)', 'get') called at /usr/share/perl5/Redis.pm line 256
        Redis::__run_cmd('Redis=HASH(0x46c86f0)', 'get', 0, 0, 0, 'remoteservices/conf/RemoteSupportAccess/keys/form') called at /usr/share/perl5/EBox/Config/Redis.pm line 455
        eval {...} called at /usr/share/perl5/EBox/Config/Redis.pm line 451
        EBox::Config::Redis::_redis_call('EBox::Config::Redis=HASH(0x2dd4bd8)', 'get', 'remoteservices/conf/RemoteSupportAccess/keys/form') called at /usr/share/perl5/EBox/Config/Redis.pm line 126
        EBox::Config::Redis::get('EBox::Config::Redis=HASH(0x2dd4bd8)', 'remoteservices/conf/RemoteSupportAccess/keys/form', undef) called at /usr/share/perl5/EBox/Module/Config.pm line 559
        EBox::Module::Config::get('EBox::RemoteServices=HASH(0x458f8e8)', 'RemoteSupportAccess/keys/form') called at /usr/share/perl5/EBox/Model/DataForm.pm line 207
        EBox::Model::DataForm::_rowStored('EBox::RemoteServices::Model::RemoteSupportAccess=HASH(0x46c8450)') called at /usr/share/perl5/EBox/Model/DataForm.pm line 195
        EBox::Model::DataForm::row('EBox::RemoteServices::Model::RemoteSupportAccess=HASH(0x46c8450)') called at /usr/share/perl5/EBox/Model/DataForm.pm line 650
        EBox::Model::DataForm::AUTOLOAD('EBox::RemoteServices::Model::RemoteSupportAccess=HASH(0x46c8450)') called at /usr/share/perl5/EBox/RemoteServices.pm line 2100
        EBox::RemoteServices::extraSudoerUsers('EBox::RemoteServices=HASH(0x458f8e8)') called at /usr/share/zentyal/sudoers-friendly line 41
dpkg: error processing zentyal-core (--configure):
 subprocess installed post-installation script returned error exit status 255
dpkg: dependency problems prevent configuration of zentyal-services:
 zentyal-services depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-services depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-services (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-antivirus:
 zentyal-antivirus depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-antivirus depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-antivirus (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-monitor:
 zentyal-monitor depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-monitor depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-monitor (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-software:
 zentyal-software depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-software depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-software (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-ntp:
 zentyal-ntp depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-ntp depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-ntp (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-ca:
 zentyal-ca depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-ca depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-ca (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-trafficshaping:
 zentyal-trafficshaping depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-trafficshaping depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-trafficshaping (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-users:
 zentyal-users depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-users depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-users depends on zentyal-ntp; however:
  Package zentyal-ntp is not configured yet.

dpkg: error processing zentyal-users (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-jabber:
 zentyal-jabber depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-jabber depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-jabber depends on zentyal-users; however:
  Package zentyal-users is not configured yet.

dpkg: error processing zentyal-jabber (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-objects:
 zentyal-objects depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-objects depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-objects (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-dns:
 zentyal-dns depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-dns depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-dns (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-bwmonitor:
 zentyal-bwmonitor depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-bwmonitor depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.

dpkg: error processing zentyal-bwmonitor (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-firewall:
 zentyal-firewall depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-firewall depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-firewall depends on zentyal-objects; however:
  Package zentyal-objects is not configured yet.
 zentyal-firewall depends on zentyal-services; however:
  Package zentyal-services is not configured yet.

dpkg: error processing zentyal-firewall (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-openvpn:
 zentyal-openvpn depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-openvpn depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-openvpn depends on zentyal-firewall; however:
  Package zentyal-firewall is not configured yet.
 zentyal-openvpn depends on zentyal-ca; however:
  Package zentyal-ca is not configured yet.

dpkg: error processing zentyal-openvpn (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-network:
 zentyal-network depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-network depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-network depends on zentyal-objects; however:
  Package zentyal-objects is not configured yet.
 zentyal-network depends on zentyal-services; however:
  Package zentyal-services is not configured yet.

dpkg: error processing zentyal-network (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-l7-protocols:
 zentyal-l7-protocols depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-l7-protocols depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-l7-protocols depends on zentyal-trafficshaping; however:
  Package zentyal-trafficshaping is not configured yet.

dpkg: error processing zentyal-l7-protocols (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-ipsec:
 zentyal-ipsec depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-ipsec depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-ipsec depends on zentyal-firewall; however:
  Package zentyal-firewall is not configured yet.

dpkg: error processing zentyal-ipsec (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of zentyal-squid:
 zentyal-squid depends on zentyal-core (>= 3.4); however:
  Package zentyal-core is not configured yet.
 zentyal-squid depends on zentyal-core (<< 3.5); however:
  Package zentyal-core is not configured yet.
 zentyal-squid depends on zentyal-firewall; however:
  Package zentyal-firewall is not configured yet.
 zentyal-squid depends on zentyal-users; however:
  Package zentyal-users is not configured yet.

dpkg: error processing zentyal-squid (--configure):
 dependency problems - leaving unconfigured
Processing triggers for libc-bin ...
Processing triggers for ca-certificates ...
Updating certificates in /etc/ssl/certs... 0 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d....done.
Processing triggers for initramfs-tools ...
update-initramfs: Generating /boot/initrd.img-3.8.0-38-generic
Processing triggers for ureadahead ...
Errors were encountered while processing:
 zentyal-remoteservices
 suricata
 zentyal-ips
 zentyal-core
 zentyal-services
 zentyal-antivirus
 zentyal-monitor
 zentyal-software
 zentyal-ntp
 zentyal-ca
 zentyal-trafficshaping
 zentyal-users
 zentyal-jabber
 zentyal-objects
 zentyal-dns
 zentyal-bwmonitor
 zentyal-firewall
 zentyal-openvpn
 zentyal-network
 zentyal-l7-protocols
 zentyal-ipsec
 zentyal-squid

Zentyal upgrade failed. Full log at /var/log/zentyal/upgrade.log.

After all these errors i reverted back to my stable snapshot, and everything is fine, but i cant upgrade to 3.4. To me, this is a bug in the upgrade process because this is a dedicated zentyal box without anything else, so it should work.

Will this upgrade process work? or we are on our own?

9
You don't need to do anything  on the host machine. On your virtual machine you need to add 2 network cards, both set to "Bridget network". You need to set the ip as static on both cards.

When you're installing Zentyal, you need to set one card as external, and another as internal. Your isp router should be on the same network as your external card (For example: 192.168.0.1 for your ISP router, and 192.168.0.2 for your external card), and your client machines and your internal network card should be on another network (For example: 10.0.0.1 for your internal network card on Zentyal, and 10.0.0.X for your clients)

Then, your clients should use the internal Zentyal ip (10.0.0.1 in this example) as their default gateway.

PD: If you run this setup, you should take into account that you wont have internet access util you power on your VM!

Sorry for my bad english

10
Hi!

I have a zentyal server running on my network since 2 years ago (2.2.9) and its running great. But, i want to upgrade from it to the latest stable release (3.0). The problem is, i have  LOTS of OpenVPN users across the globe, and i dont want to issue new certificates, configs etc to them. That will be very disruptive for my time. I dont care if i have to configure the entire server from 0, but i dont want to configure each openvpn client again.

My plan is to install the new zentyal using the same external ip as the old, so my clients can keep their config files without modifications, but, what can i do about the certificates? Im somewhat lost on that part  ???

11
Hi

Yes, you're right. Here we have 3 internet connections, and they're connected to the same switch as the rest of the network (in different ip ranges). Why? Well, zentyal is running on a virtual machine, and the physical machine that host zentyal VM only has one network card. So, in order to connect zentyal with all the 4 networks (Local, internet-1, internet-2, internet-3) i have to connect them on the same switch, on different subnets.

Then, on zentyal, everything goes as usual: one card is market as internal, and the other 3 are external. The problem occurred because, since each card is on the same switch, all of them got the ARP package, and all of them reply to that package, generating 4 answers, each answer with a different mac address. Windows only uses the first answer to arrive and discard the other 3, and sometimes that answer contained the mac address of one of the external cards.

Hope that makes any sense to you xD

Anyway, its solved now, thanks god  ;D

12
FOUND IT!!

the problem is described here:
http://www.embedded-bits.co.uk/2008/multiple-network-gotcha/
http://linux-ip.net/html/ether-arp.html

The problem is not Zentyal's fault, but linux design.

The solution was to add this:
net.ipv4.conf.all.arp_ignore=1
net.ipv4.conf.all.arp_announce=2

on this file:
/etc/sysctl.conf

and restart.

13
ANOTHER UPDATE
Looking at the ARP table on one of the affected machines, i have noticed something VERY strange...

I have a test machine... this is the ARP table of that machine when the internet is working:

Quote
Interface: 10.0.0.123 --- 0xa
  Internet Address      Physical Address              Type
  10.0.0.28              a4-ba-db-ed-07-83          dynamic   
  10.0.0.249            00-50-56-a4-47-8c          dynamic <--------------   
  10.0.0.252            00-24-e8-53-db-f5           dynamic   
  10.0.0.254            00-0c-29-f7-e0-c7           dynamic   
  10.0.0.255            ff-ff-ff-ff-ff-ff                     static   
  224.0.0.252           01-00-5e-00-00-fc           static   
  255.255.255.255       ff-ff-ff-ff-ff-ff                 static   

This is the ARP table of that machine when the internet is not working:

Quote
Interface: 10.0.0.123 --- 0xa
  Internet Address      Physical Address              Type
  10.0.0.28              a4-ba-db-ed-07-83          dynamic   
  10.0.0.249            00-50-56-a4-47-8d          dynamic  <---------------   
  10.0.0.252            00-24-e8-53-db-f5           dynamic   
  10.0.0.254            00-0c-29-f7-e0-c7           dynamic   
  10.0.0.255            ff-ff-ff-ff-ff-ff                     static   
  224.0.0.252           01-00-5e-00-00-fc           static   
  255.255.255.255       ff-ff-ff-ff-ff-ff                 static   

Can you notice the difference?? 10.0.0.249 is my zentyal gateway.

That gateway has 4 ethernet adapters. 1 internal, 3 external. "00-50-56-a4-47-8c" is the mac address of the internal card. "00-50-56-a4-47-8d" is the mac address of the first external card.

For some unknown reason to me, something is making the affected machine point to the wrong zentyal network card.

Yes... i have checked that the card with "00-50-56-a4-47-8d" is marked as external, and "00-50-56-a4-47-8c" is internal.

What can cause that?  :o

14
UPDATE

if i run "tracert www.google.com" on the cmd of the affected machine... the internet starts working again... just like magic, and i can ping the gateway..

But after a while, the problem happens again, and i need to run "Tracert" again

This is a big mistery to me...

Any tip?

15
Installation and Upgrades / Re: Bug? Firewall rules do nothing...
« on: August 03, 2012, 09:15:21 pm »
Object policy do work. At least for web browsing.

By the way, if you know someone on the dev team, please tell them that user defined rules should be of highter priority than those from zentyal services.

Thanks a lot!

Pages: [1] 2 3 ... 5