Показаны сообщения с ярлыком OpenVZ. Показать все сообщения
Показаны сообщения с ярлыком OpenVZ. Показать все сообщения

среда, 9 января 2013 г.



[Tutorial] OpenVZ - Debian - Zenoss (monitor your world)


openvz-debian-zenoss
Do you have an OpenVZ HN (Host Node) & have no idea what’s happening with your nodes? Well get out of the dark ages & add a Zenoss installation to monitor your VE’s (Virtual Environments). Why did I choose debian when zenoss supports a bunch of distros? Well there are repos for debian/ubuntu (which will auto-setup for the most part), and I’m not a fan of ubuntu. Thus we’ll use debian. The whole setup only takes a few minutes, so lets jump right in…
1) Make a new VE with Debian 5:
# On your HN run:

# Download the debian 5 template
sudo wget -c http://download.openvz.org/template/precreated/debian-5.0-x86_64.tar.gz -o /vz/template/cache/debian-5.0-x86_64.tar.gz

# Create debian VE
sudo vzctl create 1 --ostemplate debian-5.0-x86_64

# Hooray your VE is setup, now move onto configuration >>
2) Set VE options:
# Configure debian VE (naibed-zen is debian backwards with a lil zen added)
# You can enter this all on one line, I just spread it out to make it easier to read
sudo vzctl set 1 
--hostname naibed-zen 
--ipadd  
--searchdomain  
--nameserver "(
separated by spaces)> --vmguarpages $((256 * 4096)) --privvmpages $((256 * 6144)) --swappages $((256 * 1024)) --meminfo none --onboot yes --save #--vmguarpages $((256 * 4096)) # guaranteed memory (4GB) #--privvmpages $((256 * 6144)) # burst memory (6GB) #--swappages $((256 * 1024)) # swap memory #--meminfo none # I was having memory listing issues, and this fixed it
This will configure the empty shell of a VE that we setup & make is more usable:
VEID: (Virtual Environment ID) == 1 in our case, but you can set it to whatever you wantHostname: naibed-zen IP Address: (eg. 192.168.1.2) Search Domain (/etc/resolv.conf): (eg. google.com this is optional)Nameserver(s)* (/etc/resolv.conf): (eg. 192.168.1.1)Guaranteed Memory: (change the last number, 4096 == 4GB) Burst Memory: (change the last number, 6144 == 6GB) Turn on at boot: yes Don’t forget to save: if you don’t –save then your HN won’t remember the settings when rebooted
If I were you I would enter the VE (sudo vzctl enter 1) && test to make sure networking is working… ping google or something, if not, then make sure your HN is setup correctly & that your dns servers are correct
3) Setup Zenoss:
Now that we have our VE all ready to go, lets setup zenoss…
# Enter the VE
sudo vzctl enter 1
echo "deb http://dev.zenoss.org/deb main stable" >> /etc/apt/sources.list
apt-get update
apt-get install zenoss-stack
/etc/init.d/zenoss-stack start
It should look something like this:
$ sudo vzctl enter 2
entered into CT 2
naibed:/# echo "deb http://dev.zenoss.org/deb main stable" >> /etc/apt/sources.list
naibed:/# apt-get update
... updating pkg-database ...

naibed:/# apt-cache search zenoss-stack # just verifying that the repo is correct
zenoss-stack - Zenoss Stack with all requirements.

naibed:/# apt-get install zenoss-stack
Reading package lists... Done
Building dependency tree... Done
The following NEW packages will be installed:
  zenoss-stack
0 upgraded, 1 newly installed, 0 to remove and 14 not upgraded.
Need to get 110MB of archives.
After this operation, 386MB of additional disk space will be used.
WARNING: The following packages cannot be authenticated!
  zenoss-stack
Install these packages without verification [y/N]? Y
Get:1 http://dev.zenoss.org main/stable zenoss-stack 3.0.2-0 [110MB]
Fetched 110MB in 11s (9756kB/s)
Selecting previously deselected package zenoss-stack.
(Reading database ... 23039 files and directories currently installed.)
Unpacking zenoss-stack (from .../zenoss-stack_3.0.2-0_amd64.deb) ...
Setting up zenoss-stack (3.0.2-0) ...

naibed:/# /etc/init.d/zenoss-stack start
nohup: redirecting stderr to stdout
Starting mysqld.bin daemon with databases from /usr/local/zenoss/mysql/data
/usr/local/zenoss/mysql/scripts/ctl.sh : mysql  started at port 3307
Daemon: zeoctl .
daemon process started, pid=2050
Daemon: zopectl .
daemon process started, pid=2061
Daemon: zenhub starting...
Daemon: zenjobs starting...
Daemon: zenping starting...
Daemon: zensyslog starting...
Daemon: zenstatus starting...
Daemon: zenactions starting...
Daemon: zentrap starting...
Daemon: zenmodeler starting...
Daemon: zenperfsnmp starting...
Daemon: zencommand starting...
Daemon: zenprocess starting...
Daemon: zenwin starting...
Daemon: zeneventlog starting...
naibed:/#

# You're done, move onto testing & pat yourself on the back
4) Test & Enjoy:
To test just go to a web browser & enter the IP that you choose for the machine followed by:8080 (eg. 192.168.1.2:8080) If everything went as expected you should be greeted with a zenoss setup pageSuccess

вторник, 30 октября 2012 г.

Установка OpenVPN на Linux (CentOS)


BY NASA,СЕНТЯБРЬ 22ND,2011 (copy)


Ставим openvpn из yum-а или из RPM http://dag.wieers.com/rpm/packages/openvpn/
yum install openvpn lzo-devel
chkconfig openvpn on
Если ставится версия 2.0 то лучше поставить поверх из исходников последнюю версию (2.1 или старше) и переписать бинарник /usr/local/sbin/openvpn ->/usr/sbin/openvpn
На хост машине для контейнера надо разрешить tun-устройства и модули ната для iptables:
vzctl set 900 –save –devnodes net/tun:rw
vzctl stop 900
vzctl set 900 –save –iptables «ip_conntrack iptable_filter iptable_mangle ipt_state iptable_nat ip_nat_ftp ip_conntrack_ftp»
vzctl start 900
Затем подготавливаем папки конфигов:
cp -R /usr/share/openvpn/easy-rsa/2.0 /etc/openvpn/easy-rsa
cd /etc/openvpn/easy-rsa
chmod 777 *
mkdir /etc/openvpn/keys
Для версии 2.2 и старше будет чуть по другому:
cp -R /usr/share/doc/openvpn-2.2.0/easy-rsa /etc/openvpn/easy-rsa
cd /etc/openvpn/easy-rsa/2.0
chmod 777 *
mkdir /etc/openvpn/keys
touch /etc/openvpn/keys/index.txt
echo «01″>/etc/openvpn/keys/serial
в vars-файле в /etc/openvpn/easy-rsa/2.0 заменяем строку:
export KEY_DIR=…
на
export KEY_DIR=/etc/openvpn/keys
Генерируем все сертификаты:
cd /etc/openvpn/easy-rsa
. ./vars
./clean-all
./build-ca
./build-key-server server
./build-dh
openvpn –genkey –secret /etc/openvpn/keys/ta.key
./build-key client1
./build-key client2
В процессе генерации сертификатов можно ничего не вводить. Все оставить по дефолту.
Последняя строчка делается столько раз,сколько надо ключей для клиентов.
Не забыть,что если дата на клиенте меньше чем дата на сервере в момент генерации сертификата – подключение не пройдет.
Включаем роутинг:
echo 1 >/proc/sys/net/ipv4/ip_forward
и правим соотвествующую строчку в sysctl.conf
Конфиг для сервера /etc/openvpn/server.conf:
proto tcp
dev tun
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/server.crt
key /etc/openvpn/keys/server.key
dh /etc/openvpn/keys/dh1024.pem
tls-server
tls-auth /etc/openvpn/keys/ta.key 0
server 10.10.10.0 255.255.255.0
ifconfig-pool-persist /etc/openvpn/ipp.txt
client-to-client
duplicate-cn
keepalive 10 60
ping-timer-rem
comp-lzo
user nobody
group nobody
persist-key
persist-tun
verb 4
mute 10
log /var/log/openvpn/openvpn.log
status /var/log/openvpn/openvpn-status.log
push «dhcp-option DNS 208.67.222.222″
Ставим,включаем и делаем роутинг в iptables:
yum install iptables
# делаем автостарт файрволу
chkconfig iptables on
# правило для нат-а,VE_IP_ADDRESS заменить на IP,который будет у вас «исходящим»для впн-трафика
iptables -t nat -A POSTROUTING -s 10.10.10.0/255.255.255.0 -o venet0 -j SNAT –to-source VE_IP_ADDRESS
# сохраняем правила
/etc/init.d/iptables save
# еще раз смотрим на сохраненные правила и проверяем
iptables -t nat -L
mkdir /var/log/openvpn
chmod 777 /var/log/openvpn
service openvpn start
Конфиг одного клиента (будет работать для Windows XP,Windows Vista и Windows 7):
dev tun
proto tcp
remote vpn.domain.com
client
resolv-retry infinite
redirect-gateway def1
ca ca.crt
cert client1.crt
key client1.key
tls-client
tls-auth ta.key 1
cipher BF-CBC
ns-cert-type server
comp-lzo
persist-key
persist-tun
verb 4
route-metric 1
route-method exe
route-delay 2
Для Windows Vista,Windows 7 запускать клиента надо с админскими правами через батник:
cd c:\vpn\
«c:\program files\openvpn\bin\openvpn.exe»c:\vpn\client1.ovpn
pause
ЗЫ. На хостовой ноде может быть не загружен модуль ядра tun. Тогда:
modprobe tun
modprobe -l |grep tun

Ссылка на сайт