2011年7月5日 星期二

linux dhcp access windows dhcp multidomain

if you dns server is windows base and allow linux client to search multidomin,
please modify windows dhcp server and add option 119.
1.on dhcp global scope add predefined option
2.add a byte array
3.example:abc.com abc.com.tw
add order is ab.com.tw abc.com
0x00 0x77 0x74 0x02 0x6d 0x6f 0x63 0x03 0x63 0x62 0x61 0x03 --> abc.com.tw
0x00 0x6d 0x6f 0x63 0x03 0x63 0x62 0x61 0x03 -->abc.com
ox00 means null termination
0x02 tw two characters
0x03 com three characters
0x0c abc three characters

other setting method,please use optinos 15 to add other domain with space
abc.com abc.com.tw

2011年7月4日 星期一

search mulitdomain

#vim /etc/resolv.conf
domain abc.com.tw
search adc.com ad.adc.com abc.com.tw
nameserver 172.16.1.100
nameserver 172.16.1.110
options ndots:3

it will search multidomain on /etc/resolv.conf

2011年6月29日 星期三

enable apache x-forwarder-for

1.modify /etc/apache2/apache2.conf
add lines in it

LogFormat "%{X-Forwarded-For}i %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" proxy
SetEnvIf X-Forwarded-For "^.*\..*\..*\..*" forwarded
CustomLog "logs/access_log" combined env=!forwarded
CustomLog "logs/access_log" proxy env=forwarded

2.restart apache2 server
#/etc/init.d/apache2 restart

2011年5月31日 星期二

add route in linux

1.add new route
#route add -net 172.16.0.0. netmask 255.255.0.0 gw 172.16.1.1

2.del route
#route del -net 172.16.0.0 netmask 255.255.0.0 gw 172.16.1.1

3.modify default route
#route add -net 0.0.0.0 netmask 0.0.0.0 gw 10.10.10.1

2011年5月23日 星期一

bind chroot setting

1.stop bind9 service
#/etc/init.d/bind9 stop

2.modify /etc/default/bind9 and add -t agrument
#vim /etc/default/bind9
OPTIONS="-u bind -t /var/lib/named"


3.create necessary folder
#mkdir -p /var/lib/named/etc
#mkdir /var/lib/named/dev
#mkdir -p /var/lib/named/var/cache/bind
#mkdir -p /var/lib/named/var/run/bind/run

4.move /etc/bind to /var/lib/name/etc/
#mv /etc/bind /var/lib/named/etc

5.mkdir software link to /etc/bind
#ln -s /var/lib/named/etc/bind /etc/bind

6.mkdir two char device and grant some permission
#mknod /var/lib/named/dev/null c 1 3
#mknod /var/lib/named/dev/random c 1 8
#chmod 666 /var/lib/named/dev/null /var/lib/named/dev/random
#chown -R bind:bind /var/lib/named/var/*
#chown -R bind:bind /var/lib/named/etc/bind

7.create one file to log import message and add one line on it
#vim /etc/rsyslog.d/bind-chroot.conf
$AddUnixListenSocket /var/lib/named/dev/log

8.add some lines on /etc/apparmor.d/usr.sbin.named
#vim /etc/apparmor.d/usr.sbin.named
/var/lib/named/etc/bind/* rw,
/var/lib/named/var/run/bind/run/named.pid w,
/var/lib/named/var/run/bind/named.options r,
/var/lib/named/dev/null rw,
/var/lib/named/dev/random rw,


9.restart rsyslog and bind9 serivice
#/etc/init.d/rsyslog restart
#/etc/init.d/apparmor restart
#/etc/init.d/bind9 start

2011年5月12日 星期四

bind9 enable logging for dns query everything

1.modify /etc/bind/named.conf.options
#vim /etc/bind/named.conf.options

logging{
channel dns_log {
file "/var/log/named/bind.log" versions 3 size 5m;
severity info;
print-time yes;
print-severity yes;
print-category yes;
};
category lame-servers{
null;
};
category default{
dns_log;
};
category xfer-out{
dns_log;
};
category queries{
dns_log;
};
};

2.make a folder name named in /var/log and give bind write permission
#cd /var/log
#mkdir named
#cd named
#touch bind.log
#cd ../..
#chown bind:bind -Rf named/
#chmod 775 -Rf named/

3.restart bind service
#/etc/init.d/bind9 restart

ntp server in taiwan

server 1.tw.pool.ntp.org
server 0.asia.pool.ntp.org
server 2.asia.pool.ntp.org