Mostrando las entradas con la etiqueta networking. Mostrar todas las entradas
Mostrando las entradas con la etiqueta networking. Mostrar todas las entradas

viernes, 20 de noviembre de 2009

Securing Network Services with FreeBSD Jails

In this article by Christer Edwards, we will explore FreeBSD Jails. FreeBSD Jails are a kernel-level security mechanism which allows you to safely segregate processes within a sandbox environment. Jails are commonly used to secure production network services like DNS or Email by restricting what a process can access. In the case of a malicious attack on one service, all other Jailed processes would remain secure. FreeBSD Jails securely limits, in an administratively simple way, the amount of damage an attacker can do to a server.


jueves, 23 de julio de 2009

RANCID on FreeBSD

RANCID is an application that allows you to track changes to network devices using a CVS tree. It will email you any changes made at scheduled intervals.

I’m going to implement RANCID on a FreeBSD box at work to track changes to my Cisco network devices. I’ve tested these directions on FreeBSD 6.3 and 7.2 and they should work on FreeBSD in general.


(more...)

sábado, 27 de junio de 2009

Finding out what httpd a website uses

Have you ever wanted to know what httpd a website is using but didn’t know how? this tutorial will be able to show you.


jueves, 29 de enero de 2009

IPsec VPN and NAT

At work we run a number of IPsec VPN tunnels to peers all over the world and we have always been concerned about possible RFC1918 address space collisions between our network and one of the other companies - it is surprising how often administrators keep the default 192.168.0.0/24 network! To the best of our knowledge on OpenBSD there was no good technical solution to the problem, and migrating the whole partner network to a unique address space is often politically unacceptable or too expensive.

(more...)

lunes, 8 de diciembre de 2008

OpenVPN - creating a routed VPN

"In this article, I will show you how I created a routed VPN using OpenVPN. In this network, multiple clients can attach to the server, each of which has access to the network attached to the server. Each client can also contact any other client, subject to firewall rules.

In my case, I wanted a way for all my servers (on the internet, in data centers) to contact my CVS repository behind my firewall at home. Given that home has a dynamic IP address, it complicates matters. A VPN solves this issue and provides several benefits."

OpenVPN - getting it running

"This article is about OpenVPN, a full-featured open source SSL VPN solution. I first started using OpenVPN in December 2006. That is nearly two years ago. I took some notes but I never published anything until today. My original use for OpenVPN was easy access to my home network while away from home. For this is was wonderful. Being able to ssh "directly" to my machines, cvsup, etc, was very convenient."

Creating your own Certificate Authority

"In this article, I write about creating your own Certificate Authority (CA) and generating certificates and keys for an OpenVPN server and multiple clients. It is based around the the OpenVPN How To and the README provided with that package.

There is an abundance of material for creating a CA. Why bother? I bother because getting this right is easy. It's easy if you know the goals and how to accomplish them. However, getting there is often trial and error. I don't want to do the error bit the next time I need to do this. The added bonus is neither do you. You can use these steps."

lunes, 15 de septiembre de 2008

Build up a powerful network analyzer ( Cacti ) on FreeBSD

Sometimes you need to use powerful analyzer to detect network traffic.
Cacti is a best choice for you.

sábado, 13 de septiembre de 2008

Port-Forwarding With rinetd On Debian Etch

"This article shows how you can do port-forwarding with rinetd on Debian Etch. rinetd allows you to forward ports from one system to another. This useful if you have moved your web sites to a new server with a different IP address. Of course, you have modified your DNS records, but it can take a few days until DNS changes become effective, and that is where rinetd comes into play. If clients still use the old DNS records, rinetd can redirect them to the new server. With rinetd, you do not have to fiddle with iptables rules."

(more...)

jueves, 4 de septiembre de 2008

Quick Guide to FreeBSD hostap for FreeBSD 8

"I have a need to setup an access point. Many of the discussions on the web include all kinds of extra goodies that one normally sets up with the access point. But I just needed an access point: no dhcp, bridging, etc. Here's how I did it."


sábado, 23 de agosto de 2008

Setting Up Squid on FreeBSD

Squid is web caching and conserving badwidth application. With Squid, we will reduce the traffic 30% or more from normal usage (without squid) and enhance respone time. In here, i will use squid 2.7.STABLE3.

(more...)

viernes, 25 de julio de 2008

Installing A FreeBSD 7.0 DNS Server With BIND

As FreeBSD is known as one of the most stable and reliable operating systems, I decided to publish some useful articles for it, mixing it with services we need on daily bases.

This tutorial
shows how to set up a FreeBSD based server that offers DNS services. This tutorial is written for the 64-bit version of FreeBSD, but should apply to the 32-bit version.

jueves, 24 de julio de 2008

Build your own NAS with FreeNAS (video)

"This video from Revison3 explains the theory behind NAS and shows how to set up a FreeNAS server."

(more...)

Quick Guide to FreeBSD hostap for FreeBSD 8

"I have a need to setup an access point. Many of the discussions on the web include all kinds of extra goodies that one normally sets up with the
access point. But I just needed an access point: no dhcp, bridging, etc. Here's how I did it."

lunes, 30 de junio de 2008

Create Your Own Web Server With BIND And Apache On CentOS 5

This tutorial explains how you can run your own web server on CentOS 5 with the help of Apache and the BIND name server.

Encrypted Traffic No Longer Safe From Throttling

"New research could allow ISPs to selectively block or slow down your encrypted traffic even if they cannot snoop on your transmitted data. Italian researchers have found a way to categorize the type of traffic that is hidden inside an encrypted SSH session to around 90% accuracy. They are achieving this by analyzing packet sizes and inter-packet intervals instead of looking at the content itself."

(more...)

sábado, 28 de junio de 2008

Configure a professional firewall using pfSense

The guide will take you through the setup of the pfSense firewall with one WAN interface, one LAN interface and one Opt1-WiFi Interface.

This guide was written for Linksys, Netgear, and D-link users with no firewall or router experience. No experience is needed with FreeBSD or GNU/Linux to install and run pfSense. When you are finished, management of pfSense will be from a web interface just like any of the SOHO firewall/router appliances.

Add multiple IP’s to a server

I will try to explain in here an easy way to add a lot of IP’s to a server without having to add every one of them manually but of course this works if IP’s are part of same classes.

viernes, 27 de junio de 2008

Monitor your Network for Free with Nagios

I recently met with an international telephone company who is using an open source monitoring tool called Nagios to keep tabs on their international VoIP network. Having reviewed several small network monitoring options, including Servers Alive and Jumpnode's Pulse product, I decided to dive into Nagios to see how feasible it is to deploy this full featured network monitoring tool for the small network environment.

(more...)

Nipper - The Network Infrastructure Parser

Nipper enables network administrators, security professionals and auditors to quickly produce reports on key network infrastructure devices.

The report can include a detailed security audit of the device settings or be a configuration report, the output is customisable. Nipper supports a wide variety of devices from different manufacturers such as Cisco, Nokia, Juniper, CheckPoint and Nortel.

(more...)