So, was working on a Nagios event handler to issue a NAT clear command to a Cisco router (half-baked IPSec VPN box issues, fail) and even though I had configured all of the rcmd stuff properly in IOS and locked it down to just the Nagios server for access it still didn't work. On the server side, when I issued the command I would get a single line of output:
No free VTYs.
So, I went back to the router and turned on 'debug ip tcp rcmd' and noticed that the rsh authentication (if you can call it that) was working but after accepting the command from the rsh client (router sends 'OK' to client), the router followed by immediately sending '
All of my default VTYs are setup with 'transport input ssh' because I don't use telnet where I have the choice to use SSH. I changed that to 'transport input rlogin ssh' and no luck. Finally, I changed it to 'transport input ssh telnet' and bingo, the rcmd was working like a champ. I removed the telnet option for my main access lines and defined a new line, telnet only, with a much more restrictive access-class limited to the server running Nagios.
Tuesday, December 7, 2010
No free VTYs
Wednesday, May 12, 2010
Migrating IPPlan from 4.92a to 6.00BETA2
I performed this for two IP network repositories that I manage and it worked out ok. The paths and such are relative to the FreeBSD platform from which this runs, therefore you may have to tweak if you've made the mistake of using something other than FreeBSD. Some steps, such as step 1, may not be necessary for you, so check your extensions.ini beforehand as you may already have support for gmp.
- rebuild php extensions with GNU MP support and enable it in /usr/local/etc/php/extensions.ini
- unpack source
- cp config.php config.php.orig
- patch config.php from patch file in /usr/ports/net-mgmt/ipplan/files/
- fix user name, password, db type, and db name in config.php
- fix user name, password, db type, and db name in contrib/db-migrate.php
- create new ipplanv6 db via phpMyAdmin with same permissions as ipplan db
- visit http://site/ipplanv6/admin/install.php, choosing "new installation" and "run the sql now"
#zlib support compiled into php #output to webrowser will be compressed for quicker loading of pages if web browser supports compression The database schema was created - you can now create users and groups after loggin in with the admin user specified in the config.php file Click here to access the administration page
- visit http://site/ipplanv6/contrib/db-migrate.php which will import all data from the ipplan db into the new ipplanv6 db
Migrating table grp Migrating table users [snip] Migrating table fwdzonerec
- via phpMyAdmin, check the ipplanv6.version table and you should see version (or schema) '23'
That's about it. Other than the fiasco with building the GNU MP extension for PHP, which I won't go into here, it was pretty painless and doing it twice helped me clean up these notes which will hopefully help you.
This is a big step forward for IPPlan and I am stoked to see IPv6 support. It's been on my wish list for a *very* long time and while I have contributed patches to the project in the past, I simply didn't have the spare time to do the IPv6 integration. I had been planning to resurrect the old Perl code for FreeIPdb that I worked on with a couple guys from Global Crossing, but now that IPPlan supports IPv6, I think that FreeIPdb will really die (at least for me).
Finally, if you are using IPPlan and it's useful to you and/or your business then *PLEASE* contribute to the project. Thank you!
Posted by
Mike Oliver, KT2T
at
16:43
0
comments
Thursday, September 10, 2009
tcpdump can't find /dev/bpf
Setting up new router/firewall and during testing had this issue:
# tcpdump -n -e -tttt -vv -i pflog0 |
Turns out that the tcpdump package for FreeBSD 7.2 that I had installed, version 3.9.7, was the cause of the problem. Weird part is that the base tcpdump is 3.9.8 -- newer than the packaged port! Weird indeed.
Anyway, deinstalled the package and now the base tcpdump has no problem connecting to the pflog0 interface for real-time pflog examination.
# which tcpdump |
Live and learn...
Posted by
Mike Oliver, KT2T
at
11:31
0
comments
Tuesday, August 25, 2009
Modifying a FreeBSD release ISO for headless booting
Ok, here are the commands. I will come back later to add context, too many irons in the fire right this minute...
# mkdir /bigdisk/iso |
No trailing slash on the rsync destination is significant. The following two commands are equivalent:
rsync -av /bigdisk/iso/ /bigdisk/iso_headless
rsync -av /bigdisk/iso/* /bigdisk/iso_headless/
# rsync -av /bigdisk/iso/ /bigdisk/iso_headless |
Note that I did attempt the following, which failed:
echo "/boot/loader -h" > /bigdisk/iso_headless/boot.config
# echo 'console="comconsole"' >> /bigdisk/iso_headless/boot/loader.conf |
Set whatever speed you want here. I had some cheap, old CDRs and they needed burn slowly. I have plenty to keep me busy while it's burning...
# cdrecord speed=2 dev=1,0,0 /bigdisk/7.2-RELEASE-i386-disc1_HEADLESS.iso |
That's all for now, please enjoy responsibly.
Wednesday, August 19, 2009
Retrieve ARP table from Cisco router, parse, spew
I had a colleague in need of an automated way to retrieve the ARP table from a lot of Cisco routers and format the output in a spreadsheet. Another colleague suggested using an Expect script, which is definitely cool because I love using Expect (seriously, it's a Swiss Army knife), but I wanted to take it a different direction. I looked up the SNMP MIB to retrieve the ARP table and then parsed the input to provide a two-column output consisting of the IP address and MAC address, one pair per line.
Here is the script:
snmpwalk -t 60 -v 1 -c MYCOMMSTRING routerhostname .1.3.6.1.2.1.4.22.1.2 | \ |
Notice that there are two mid-string sed matches, each with a 'g' matching command. The reason that this command needs to be listed twice is that a single iteration of 'g' doesn't mean global, it means to match up to two addresses within the stream. Since some of the MAC addresses I was dealing with were beyond that, such as "0:d:ed:c:7:5e", just using a single mid-string pattern with 'g' left me with "00:0d:ed:0c:7:5e" (note the :7: instead of the desired :07:). Adding the second iteration of mid-string matching fixed this issue by enabling matching of a third and fourth mid-string single-digit. I learned something new about sed, and learning something new is a good thing.
Posted by
Mike Oliver, KT2T
at
00:26
1 comments
Labels: arp, awk, cisco, ip address, mac address, router, sed, snmp
Saturday, August 8, 2009
FreeBSD 7.2 on my Samsung NC10-14GB
Everything working well so far. To get X working I read a lot of forums and ML archives. To get the 915resolution tool, from ports, working with the 945GME chipset in this netbook, I had to patch a couple of files...
# diff -ruN 915resolution.c.orig 915resolution.c |
...and this one...
# diff -ruN chipset_info.txt.orig chipset_info.txt |
More to come later, but I will leave you with this:
# kldstat |
Have fun!
Friday, June 19, 2009
Rant: There, fixed that for ya...
I am so sick and tired of people who think they are so clever to reply to someone else on a mailing list, EDITING SOMEONE ELSE'S WORDS, and then covering with the oh-so-bright "There, fixed that for you." comment. Hello jackass, why don't you form an intelligent reply and submit that to the list and refrain from editing quoted text from someone else. If I happen to jump straight into a message in some archive via a Google search or such and I see a quoted message then I don't REALLY know what the quoted message was if some super-smart guy decides to "fix" someone else's quote, do I?
Please, if you have taken up this bad habit, give some thought to quitting. It isn't nearly as witty as you believe it is.
Posted by
Mike Oliver, KT2T
at
08:42
0
comments
