Tampilkan postingan dengan label Install. Tampilkan semua postingan
Tampilkan postingan dengan label Install. Tampilkan semua postingan

Selasa, 21 Juni 2011

Install and Configure OpenVPN Server on Linux

The VPN is very often critical to working within a company. With working from home being such a popular draw to many industries, it is still necessary to be able to access company folders and hardware that exists within the LAN. When outside of that LAN, one of the best ways to gain that access is with the help of a VPN. Many VPN solutions are costly, and/or challenging to set up and manage. Fortunately, for the open source/Linux community, there is a solution that is actually quite simple to set up, configure, and manage. OpenVPN is that solution and here you will learn how to set up the server end of that system.


The VPN is very often critical to working within a company. With working from home being such a popular draw to many industries, it is still necessary to be able to access company folders and hardware that exists within the LAN. When outside of that LAN, one of the best ways to gain that access is with the help of a VPN. Many VPN solutions are costly, and/or challenging to set up and manage. Fortunately, for the open source/Linux community, there is a solution that is actually quite simple to set up, configure, and manage. OpenVPN is that solution and here you will learn how to set up the server end of that system.


I will be setting OpenVPN up on a Ubuntu 11.04, using Public Key Infrastructure with a bridged Ethernet interface. This setup allows for the quickest route to getting OpenVPN up and running, while maintaining a modicum of security.


The first step (outside of having the operating system installed) is to install the necessary packages. Since I will installing on Ubunutu, the installation is fairly straightforward:

Open up a terminal window.Run sudo apt-get install openvpn to install the OpenVPN package.Type the sudo password and hit Enter.Accept any dependencies.

There is only one package left to install — the package that allows the enabling of bridged networking. Setting up the bridge is simple, once you know how. But before the interface can be configured to handle bridged networking, a single package must be installed. Do the following:

Install the necessary package with the command sudo apt-get install bridge-utils.Edit the /etc/network/interfaces file to reflect the necessary changes (see below).Restart networking with the command sudo /etc/init.d/networking restart .

Open up the /etc/network/interfaces file and make the necessary that apply to your networking interface, based on the sample below:

auto loiface lo inet loopbackauto br0iface br0 inet static address 192.168.100.10 network 192.168.100.0 netmask 255.255.255.0 broadcast 192.168.100.255 gateway 192.168.100.1 bridge_ports eth0 bridge_fd 9 bridge_hello 2 bridge_maxage 12 bridge_stp off

Make sure to configure the bridge section (shown above) to match the correct information for your network. Save that file and restart networking. Now it's time to start configuring the VPN server.


The OpenVPN server will rely on certificate authority for security. Those certificates must first be created and then placed in the proper directories. To do this, follow these steps:

Create a new directory with the command sudo mkdir /etc/openvpn/easy-rsa/.Copy the necessary files with the command sudo cp -r /usr/share/doc/openvpn/examples/easy-rsa/2.0/* /etc/openvpn/easy-rsa/.Change the ownership of the newly copied directory with the command sudo chown -R $USER /etc/openvpn/easy-rsa/.Edit the file /etc/openvpn/easy-rsa/vars and change the variables listed below.

The variables to edit are:

export KEY_COUNTRY="US"export KEY_PROVINCE="KY"export KEY_CITY="Louisville"export KEY_ORG="Monkeypantz"export KEY_EMAIL=" This e-mail address is being protected from spambots. You need JavaScript enabled to view it "

Once the file has been edited and saved, we'll run several commands must be entered in order to create the certificates:

cd /etc/openvpn/easy-rsa/source vars./clean-all./build-dh./pkitool --initca./pkitool --server servercd keyssudo openvpn --genkey --secret ta.keysudo cp server.crt server.key ca.crt dh1024.pem ta.key /etc/openvpn/

The clients will need to have certificates in order to authenticate to the server. To create these certificates, do the following:

cd /etc/openvpn/easy-rsa/source vars./pkitool hostname

Here the hostname is the actual hostname of the machine that will be connecting to the VPN.


Now, certificates will have to be created for each host needing to connecting to the VPN. Once the certificates have been created, they will need to be copied to the respective clients. The files that must be copied are:

/etc/openvpn/ca.crt/etc/openvpn/ta.key/etc/openvpn/easy-rsa/keys/hostname.crt (Where hostname is the hostname of the client)./etc/openvpn/easy-rsa/keys/hostname.key (Where hostname is the hostname of the client).

Copy the above using a secure method, making sure they are copied to the /etc/openvpn directory.


It is time to configure the actual VPN server. The first step is to copy a sample configuration file to work with. This is done with the command sudo cp /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gz /etc/openvpn/. Now decompress the server.conf.gz file with the command sudo gzip -d /etc/openvpn/server.conf.gz. The configuration options to edit are in this file. Open server.conf up in a text editor (with administrative privileges) and edit the following options:

local 192.168.100.10dev tap0up "/etc/openvpn/up.sh br0"down "/etc/openvpn/down.sh br0"server-bridge 192.168.100.101 255.255.255.0 192.168.100.105 192.168.100.200push "route 192.168.100.1 255.255.255.0"push "dhcp-option DNS 192.168.100.201"push "dhcp-option DOMAIN example.com"tls-auth ta.key 0 # This file is secretuser nobodygroup nogroup

If you're unsure of any of the options, here:

The local address is the IP address of the bridged interface.The server-bridge is needed in the case of a bridged interface.The server will push out the IP address range of 192.168.100.105-200 to clients.The push directives are options sent to clients.

Before the VPN is started (or restarted) a couple of scripts will be necessary to add the tap interface to the bridge (If bridged networking is not being used, these scripts are not necessary.) These scripts will then be used by the executable for OpenVPN. The scripts are /etc/openvpn/up.sh and /etc/openvpn/down.sh.

#!/bin/sh#This is /etc/openvpn/up.shBR=$1DEV=$2MTU=$3/sbin/ifconfig $DEV mtu $MTU promisc up/usr/sbin/brctl addif $BR $DEV#!/bin/sh#This is/etc/openvpn/down.shBR=$1DEV=$2/usr/sbin/brctl delif $BR $DEV/sbin/ifconfig $DEV down

Both of the scripts will need to be executable, which is done with the chmod command:

sudo chmod 755 /etc/openvpn/down.shsudo chmod 755 /etc/openvpn/up.sh

Finally, restart OpenVPN with the command sudo /etc/init.d/openvpn restart. The VPN server is now ready to accept connections from clients (the topic of my next tutorial.)


One thing that is a must for a VPN is that the machine hosting the VPN has to be accessible to the outside world — assuming users are coming in from the outside world. This can be done by either giving the server an external IP address or by routing traffic from the outside in with NAT rules (which can be accomplished in various ways). It will also be critical to employ best security practices (especially if the server has an external IP address) to prevent any unwanted traffic or users from getting into the server.


View the original article here

Jumat, 10 Juni 2011

Install corkscrew on MacOSX

Rabu, 01 Juni 2011

How To Install A (Canon) Printer On Debian And Debian-Like Systems

This tutorial will cover how to install the well-known CUPS printing system, and optionally tell you how to have your Canon printer work. There are extra details about where to find Canon drivers and how to install the "Print to PDF" feature.

If you didn't check any option at the Debian network installation, you will need to download and install a few packages.

Run the following command as root:

# apt-get install cups cups-client "foomatic-db*"

This will install CUPS and download a database of printer drivers.

As the Debian distribution installs a secure Linux system on your computer, most of the permissions involved by installing packages are "opt-in". This means you have to explicitly grant permission to users so that they can print.

This is done by adding them to the lpadmin group:

# adduser YOUR_NORMAL_ACCOUNT lpadmin

Power on and plug your printer, and then browse to http://localhost:631/

Go to the Administration tab and click Add printer. At that point you will be required to type your normal user and password (not root).

CUPS will look for printers available on the network or attached to your computer.

Choose your printer in the Local printers section.

Fill the form if you want to, then see if your printer driver is in the list.
NB: Your exact model number is probably not in the list, however if you've got a 3030 printer, the 3000 driver is the one you need.

If you don't find your printer in the list, either the driver just doesn't exist for non-Windows OS / Mac OS, or it is proprietary (non-free).

If you bought a Brother or HP printer, you're lucky because all of their current printers are provided with an opensource driver. Install the hplip package for Hewlett Packard printers.

You can't find Canon drivers on non-free repositories. You have to go to the Canon website and download them.

Go to www.canon.com, select your country and language, then go to the Support page, find your printer (in category "Printer" or "Multifunction").
Choose "Linux" as your operating system. Let the language setting as it is. (Because maybe the drivers could be hidden if the included manual doesn't exist in your language).

Download that UFR II driver file.

You'll end up with a zip file / archive.

Open your Terminal again, change to your Downloads directory, and unzip that file:

$ unzip *ufr2*.zip

The unzipped directory is the language you choose, e.g. "english" or "italiano". cd to that directory, then open the "driver" directory corresponding to your architecture (32 or 64 bits), and finally open the RPM folder.

As you may know, RPM is the "Red Hat Package Manager", but Debian uses APT. RPM files have the ".rpm" extension and Debian packages get a ".deb" extension.

So, we will have to convert them.

For that purpose, install a program called alien. And I'd advice to install fakeroot as well. (Fakeroot allows you to work on Debian packaging without root privileges, which are not needed until the installation part.)

# apt-get install alien fakeroot

Then convert the packages:

 $ fakeroot alien --to-deb *.rpm

Finally you can now install them as usual:

# dpkg -i *.deb

Reload the "Add printer" page on the CUPS web interface, and this time you should be able to find your printer model in the list. (You can also press "Choose another ...." and go back to "Canon" again.)

You should not need to restart cups, but if you want to, just to be sure, do the following as root:

# service cups restart

VoilĂ  ! You've successfully installed your printer!

Here is a trick that could be helpful. If you're using an application that doesn't provide an "Export to PDF" function, you can simply print as normally and select a special "PDF printer."

In order to do that, you have to install the "cups-pdf" package:

# apt-get install cups-pdf

Your "PDF printed" documents will be put in a folder called "PDF" in your home directory, i.e. ~/PDF/

You may have to create this directory yourself if you have issues with the cups PDF printer.

The CUPS web user interface is the place to go whether you need to manage your printers and printing jobs, and find the reasons of printing issues. You can pause or cancel a job and even re-print a document.

Note you have to modify your /etc/cups/cupsd.conf configuration file if you want the interface to be accessible from other computers in your network.



View the original article here

Senin, 30 Mei 2011

Cover Thumbnailer - How to install in Ubuntu Linux

Cover Thumbnailer is a small Python script which displays music/video album covers in Nautilus in place of ordinary icons of folders, preview of pictures in a folder and more.

It is similar to what you see in Microsoft Windows 7 where the folder shows a preview of the pictures contained in it.

This is for Ubuntu users running v 9.10 Karmic, v 10.04 Lucid and v 10.10 Maverick .

Open your terminal and enter the following set of commands :

$ sudo add-apt-repository ppa:flozz/flozz$ sudo apt-get update$ sudo apt-get install cover-thumbnailer
Once Cover Thumbnailer has been installed, you will have to restart Nautilus by running the following command. $ nautilus -q
Now the specified folders containing music files will display the respective album cover / mosaic of covers.

If you are using another Linux distribution, you can download the source code from the Cover Thumbnailer website, compile it, and install it on your machine.

Cover Thumbnailer program will store a cache of cropped images of albums in a  hidden folder named .thumbnails/ in your home directory. The .thumbnails/ directory is a cache directory created by GNOME when you browse through your folders in Nautilus. It contains thumbnail pictures of images you have previously viewed.

And when you visit a particular music folder, the thumbnail of the respective album is shown on top of the folder.


You can access the Cover Thumbnailer preferences via GNOME Menu > System > Preferences > Cover Thumbnailer. Here you can specify more folders that can avail of Cover Thumbnailer's services and set many other options such as clearing the thumbnail cache and more.


Here is how the folders looks after you install cover thumbnailer program in Ubuntu. Cover Thumbnailer in action in Nautilus

View the original article here

Kamis, 26 Mei 2011

How To Install VMware Tools On pfsense (FreeBSD)

This tutorial shows how to install VMware Tools onto pfsense v1.2.3 which is operated by the FreeBSD OS. It took me days to figure out how to do it, especially with lack of a complete guide in the Internet.

To install such a system you will need the following:

Download the pfsense VMware appliance here: http://doc.pfsense.org/index.php/VMwareAppliance
Download and Install:
1. VMware vCenter Converter Standalone Client
2. VMware vSphere Client
(How to download and install, please follow other guides)

Do not just upload the pfsense*.vmx or vmdk into the vmware datastore, use vCenter Converter instead, otherwise your pfsense-VM won't boot after you create snapshot. And I suppose you have configured the pfsense-VM, and successfully made an Internet connection.

First, we need to install "perl" and "compat6x-i386" onto the system prior VMware Tools installation, just like other linux. But there are many catches through the path... and this guide solved all these and goes straight to the result.

--> press "8" and go to the Shell of pfsense.

We need to update the FTP path for pkg_add command, otherwise the package won't fetch (coz the pfsense FreeBSD is not so updated to FreeBSD FTP)!

setenv PACKAGEROOT "ftp://ftp.freebsd.org"

setenv PACKAGESITE "ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.4-release/Latest/"

Start installing packages:

pkg_add -v -r perl

pkg_add -v -r compat6x-i386

Go to VMware vsphere client, and start "Install VMware Tools" onto the pfsense-VM, as usual, we need to mount the CD-ROM in order to get the VMware Tools executable.

First, we create some tmp folders first for VMware Tools:

cd /

mkdir tmp2

mkdir tmpp

Mounting the CD-ROM to tmp2:

mount_cd9660 /dev/acd0 /tmp2

cd /tmp2

Copy the VMware Tools to tmpp, then extract the package:

cp vmware-freebsd-tools.tar.gz /tmpp

cd /tmpp

tar -zxvf vmware-freebsd-tools.tar.gz

cd vmware-tools-distrib/

Then, here is the catch, before executing the installation, we need to link the compat6x files to the proper directory for VMware Tools to find, otherwise it just doesn't work!

ln -s /usr/local/lib/compat/libm.so.4 /lib

ln -s /usr/local/lib/compat/libc.so.6 /lib

ln -s /usr/local/lib/compat/libthr.so.2 /lib

Then, start the installation, make sure you are under /vmware-tools-distrib.

chmod +x vmware-install.pl bin/vmware-config-tools.pl bin/vmware-uninstall-tools.pl

./vmware-install.pl

As usual, keep pressing "Enter", and it should work with "Enjoy" message. If so, start cleaning up and reboot:

cd /

rm -r /tmpp/

rmdir tmpp

shutdown -r now

If you get a "You are under attack" note along the way, it properly is due to the mounted CD-ROM drive, if so, press "Ctrl+Alt+Insert" to reboot the VM and start over. After all these, you should have an "OK" message in VMware vsphere client.

So, enjoy!



View the original article here