Fwd: Nethesis 6.6 beta1

75 views
Skip to first unread message

Alessio Fattorini

unread,
Feb 15, 2015, 10:58:10 AM2/15/15
to neths...@googlegroups.com

I forward this e-mail from Todd
There are some issues To test and reproduce.
Alessio

On Feb 5, 2015, at 23:19, Todd Firkins <toddf...@hotmail.com> wrote:
  1. Soon after the installation was complete, I began adding hosts (Gateway/Firewall Objects/Hosts) and I noticed an error message at the top of the screen (in red letters) that complained "orange (DMZ) zone undefined". I have 3 NIC cards in my server, and one of them had been assigned to Orange DMZ, but it is not being used at this time. I changed the NIC assignment to Blue(Guest) and the problem went away.EmojiFeature request: Wouldn't it be cool if you could import hosts right off of the DHCP server page, instead of having to manually type them all in?!
  2. On the dashboard, the IP address is blank for the RED NIC. (MODEM).
     
     
  3. Shorewall seemed to crash when I was submitting new profiles  (Gateway/Web content filter) . But the error would go away if I simply pressed submit again. Probably a normal behavior.
  4. From the dashboard, under apps, if I click Collectd Graph Panel I get blocked. All other applications work.
 
 


Not much for beta 1 !


Another feature request: In my situation, when the software was being installed on a system that was already hardware configured as a gateway, it would be nice if the installer made the MAC address of the detected NIC cards visible. It was not obvious that I just had to press Alt + F2 for a terminal, and use ifconfig -a to determine this.  


I am really enjoying trying to figure out all the new data analysis tools provided by NTOP! Thanks!



Subject: Re: Nethesis 6.6 beta1
From: alessio....@nethesis.it
Date: Thu, 5 Feb 2015 20:50:16 +0100
To: toddf...@hotmail.com

Hi Todd,
Welcome on NSteam,
This is the best place to speak about it, eventually we'll ask you to fill some bugs ;-)
Tell us, which are the problems?
Alessio

Sent from Blue Mail

On Feb 5, 2015, at 19:56, Todd Firkins <toddf...@hotmail.com> wrote:
I successfully installed Nethesis 6.6 Beta1 on a box that had Zentyal 4.0 running on it. I observed a few small bugs. Where is the best place to give feedback on installation experience?
 
Nethesis 6.6 is very good!




Todd Firkins

unread,
Feb 16, 2015, 10:25:54 PM2/16/15
to neths...@googlegroups.com
Hello this is Todd, I wanted to point out that the problem on point 4. was because I had "block access to websites using IP address"  selected in the filter that I had applied to the host group my PC is in. I simply unchecked this option and I have full access to all applications.

Giacomo Sanchietti

unread,
Feb 17, 2015, 3:26:48 AM2/17/15
to neths...@googlegroups.com
Hi,

> 1. Soon after the installation was complete, I began adding hosts
> (Gateway/Firewall Objects/Hosts) and I noticed an error message
> at the top of the screen (in red letters) that complained
> "orange (DMZ) zone undefined". I have 3 NIC cards in my server,
> and one of them had been assigned to Orange DMZ, but it is not
> being used at this time. I changed the NIC assignment to
> Blue(Guest) and the problem went away.

this is quite strange.
If you can reproduce the error, can you post the output of following
commands:
* db networks show
* shorewall check


EmojiFeature request:
> Wouldn't it be cool if you could import hosts right off of the
> DHCP server page, instead of having to manually type them all in?!

You already can.
All hosts defined inside the DHCP reservation page (and hosts page) are
automatically available in the firewall rules page.

> 2. On the dashboard, the IP address is blank for the RED NIC. (MODEM).

Right, because is configured in DHCP. We have a couple of ideas to
improve DHCP on red interfaces, stay tuned :)

> 3. Shorewall seemed to crash when I was submitting new profiles
> (Gateway/Web content filter) . But the error would go away if I
> simply pressed submit again. Probably a normal behavior.

No, it shouldn't be a normal behavior. Probably is related to the error
reported on 1, since the firewall is restarted when the system applies
the content filter rules.


> 4. From the dashboard, under apps, if I click*Collectd Graph
> Panel* I get blocked. All other applications work.

You already fixed this, good :)

> Another feature request: In my situation, when the software was
> being installed on a system that was already hardware configured as
> a gateway, it would be nice if the installer made the MAC address of
> the detected NIC cards visible. It was not obvious that I just had
> to press Alt + F2 for a terminal, and use ifconfig -a to determine
> this.

Where exactly to you need this information? Maybe we have only to
display it in the right position :)

Thank you for your time!


Filippo Carletti

unread,
Feb 17, 2015, 9:54:13 AM2/17/15
to Todd Firkins, neths...@googlegroups.com
> Hello this is Todd, I wanted to point out that the problem on point 4. was
> because I had "block access to websites using IP address" selected in the
> filter that I had applied to the host group my PC is in. I simply unchecked
> this option and I have full access to all applications.

Having "block access to websites using IP address" selected improves
security, I'd leave it enabled.
The problem is that the CGP url is built using the url you entered in
the web browser.
Here, I use https://nethserver.nethesis.it:980 because my DNS (it is
the same nethserver) resolves the name.
Another option is not to use the web proxy to access your nethserver
and this is the default if you used auto-configure through wpad.
Otherwise, I think you need to adjust your browser config.


--
Ciao,
Filippo

Todd Firkins

unread,
Feb 18, 2015, 1:30:05 AM2/18/15
to neths...@googlegroups.com

Giacomo, I will answer your points to the best of my ability.

1. I probably won't be re-installing NethServer 6.6 anytime soon since is is working very well and
has gathered useful data about bandwidth consumption that I want to keep in place. If I do re-install, I
will take note, now that I know the commands you suggest.

Regarding importing hosts off of the DHCP server page, I was not using the firewall rules page, I
was using the firewall objects page to add hosts so I could create host groups.

2. OK
3. OK

4. I took Filippo Carletti's advise and used the FQDN I configured in NethServer, instead of using the IP address.
I re-activated "block access to websites using IP address" in the filter I have applied to the network I'm on, and it works.
I have access to all applications.

Regarding displaying MAC addresses during installation. As I indicated, the PC I am using fore the Nethesis Gateway was already wired into the network
infrastructure, so the NICS have roles already "wired in". I didn't know which NIC was given what name (eth0,eth1), so if the installation program could
display the MAC address along with the NIC name it would make it easier. Or, I could just label my NIC cards with the MAC address in advance, like
I probably should. The screen grabs below is where this would be convenient.

Todd Firkins

unread,
Feb 18, 2015, 1:47:06 AM2/18/15
to neths...@googlegroups.com, todd.f...@gmail.com
Filippo, I took your advise and used the FQDN I configured in the gateway instead of the IP address and it works.
I should have thought of that! I re-activated "block access to websites using IP address" on the filter that is applied to
the host group I'm in, and I still have access to all Nethserver applications.

However, it did cause a problem with my son, who was having his game software update function blocked. I watched
the httpd_access.log an I could see that the update servers were using IP addresses without a domain name, and were being blocked.
The game software is a "Steam" client, Call of Duty Advanced Warfare.
Maybe the client is poorly written and has IP addresses baked into it's code?

Thanks for your feedback.

Giacomo Sanchietti

unread,
Feb 18, 2015, 3:33:31 AM2/18/15
to neths...@googlegroups.com

> Regarding displaying MAC addresses during installation. As I indicated,
> the PC I am using fore the Nethesis Gateway was already wired into the
> network
> infrastructure, so the NICS have roles already "wired in". I didn't know
> which NIC was given what name (eth0,eth1), so if the installation
> program could
> display the MAC address along with the NIC name it would make it easier.

Excellent idea!

Right in time for the RC1: http://dev.nethserver.org/issues/3047



Filippo Carletti

unread,
Feb 18, 2015, 5:36:10 AM2/18/15
to Todd Firkins, neths...@googlegroups.com
> has gathered useful data about bandwidth consumption that I want to keep in place.

I'd like to add bandwidth information to backup-data. I've filed in issue:
http://dev.nethserver.org/issues/3001


--
Ciao,
Filippo

Filippo Carletti

unread,
Feb 18, 2015, 9:01:41 AM2/18/15
to Todd Firkins, neths...@googlegroups.com
> I should have thought of that! I re-activated "block access to websites
> using IP address" on the filter that is applied to
...
> However, it did cause a problem with my son, who was having his game
> software update function blocked. I watched
> the httpd_access.log an I could see that the update servers were using IP
> addresses without a domain name, and were being blocked.
> The game software is a "Steam" client, Call of Duty Advanced Warfare.
> Maybe the client is poorly written and has IP addresses baked into it's
> code?

You're probably right, the IP address could be hardcoded into the game.
Knowing the IP is safe, I suggest that you whitelist it (Global
whitelist in the first tab of the web filter).

--
Ciao,
Filippo

Todd Firkins

unread,
Feb 18, 2015, 10:29:10 PM2/18/15
to neths...@googlegroups.com, todd.f...@gmail.com
Filippo, I have another question regarding Nethserver 6.6 beta1. Immediately after the installation was complete, I ran an external port scan on my public IP and noticed that the following ports were reported as open: 25,80,110,143,443,465,587,980,993,995

This was easy to correct with Security/Network Services. Is this by design?

Filippo Carletti

unread,
Feb 19, 2015, 4:03:07 AM2/19/15
to Todd Firkins, neths...@googlegroups.com
> after the installation was complete, I ran an external port scan on my
> public IP and noticed that the following ports were reported as open:
> 25,80,110,143,443,465,587,980,993,995
>
> This was easy to correct with Security/Network Services. Is this by design?

It is partially by design and partially because of services/modules
you installed and the way they were configured.
I notice that the ssh port is missing. The remaining open ports is
related to the mail server and to the fact that you enabled insecure
connections.

The sysadmin is expected to review the default configuration.
6.6rc1 (coming in a few days) introduces a todo list that guides the
admin through some checks.

I really appreciate this kind of questions, please feel free to add
your comments about default security of NethServer.


--
Ciao,
Filippo

Giacomo Sanchietti

unread,
Feb 19, 2015, 8:14:15 AM2/19/15
to neths...@googlegroups.com
> This was easy to correct with Security/Network Services. Is this by design?

Yes, all listed ports belong to services designed to be exposed on
public networks.

But if you wish, you can change the behavior from "Network service"
page: just simply change the access option from "public" to "private".

Giacomo



Todd Firkins

unread,
Feb 22, 2015, 11:23:39 PM2/22/15
to neths...@googlegroups.com, todd.f...@gmail.com


Filippo, how can I tell if the IPS is working? When I look at the IPS application, it always shows the same log begin (Dec 31st) and log end date (Jan 1st).

Thanks!

Giacomo Sanchietti

unread,
Feb 23, 2015, 2:33:02 AM2/23/15
to neths...@googlegroups.com
> Filippo, how can I tell if the IPS is working? When I look at the IPS
> application, it always shows the same log begin (Dec 31st) and log end
> date (Jan 1st).

It seems it's not running.

Can you try to start the process from the shell:
service snort start

Then, look into /var/log/messages and check if there is any error.

Giacomo

Filippo Carletti

unread,
Feb 23, 2015, 4:59:18 AM2/23/15
to Todd Firkins, neths...@googlegroups.com
> Filippo, how can I tell if the IPS is working? When I look at the IPS application, it always shows the same log begin (Dec 31st) and log end date (Jan 1st).

In the past, I had problems with snort that was not starting because
of some enabled rules. I had to use a template-custom, see this old
thread:
https://groups.google.com/forum/#!topic/nethserver/RDdla50J_fQ

/var/log/messages should have details on the error.

--
Ciao,
Filippo

Todd Firkins

unread,
Feb 23, 2015, 11:44:11 PM2/23/15
to neths...@googlegroups.com
Giacomo, I can see snort is running, ps -ef | grep snort

snort    18722 18718  0 20:09 ?        00:00:00 sshd: admin@pts/0
snort    18723 18722  0 20:09 pts/0    00:00:00 -bash
root     18956     1  1 20:11 ?        00:00:10 /usr/sbin/snort -q -A fast -N -d -D -u snort -g snort -c /etc/snort/snort.conf -Q
root     20070 18778  0 20:26 pts/0    00:00:00 grep snort


or

[root@lan init.d]# ./snortd status from /etc/init.d/
snort (pid 18956) is running...

When I use service snortd stop, start, it appears to work, and a huge number of log entries appear in /var/log/messages from snort and esmith.

When I select the IPS application from NethServer 6.6 Beta1, the log start and stop time is always the same.

The only logs I see in NethServer 6.6 Beta1 are:

Administration/Log viewer    >    /var/log/snort/alert

and it contains nothing.

Bug?

Todd Firkins

unread,
Feb 24, 2015, 12:34:25 AM2/24/15
to neths...@googlegroups.com
A huge number of log entries that don't appear to be errors, I should have said. Let me know if you want me to attach the /var/log/messages file.

Filippo Carletti

unread,
Feb 24, 2015, 4:04:29 PM2/24/15
to Todd Firkins, neths...@googlegroups.com
> Administration/Log viewer > /var/log/snort/alert
>
> and it contains nothing.

I think that the system has not generated alerts.
What configuration are you using? Connectivity has really few rules,
hard to trigger.
Security has more rules, it should trigger some alerts.
I can share my custom config, it's heavy, with over 12000 rules.


--
Ciao,
Filippo

Filippo Carletti

unread,
Feb 26, 2015, 11:05:36 AM2/26/15
to Todd Firkins, neths...@googlegroups.com
An nmap scan wouldn't trigger snort alerts. It's a port scan (empty
network packets), while snort does deep inspection of packet content.
To test snort is working you could follow a guide on the net.
A common test is the icmp rule. Add the following line at the bottom
of /etc/snort/rules/snort.rules:

alert icmp any any -> any any (msg: "ICMP Packet found";)

Then reload rules:
kill -HUP $(cat /var/run/snort_.pid)

Test with a ping packet, you should see an alert in
/var/log/snort/alert (and the dashboard).


--
Ciao,
Filippo

Todd Firkins

unread,
Mar 1, 2015, 11:43:32 PM3/1/15
to neths...@googlegroups.com, todd.f...@gmail.com
I am observing a strange behavior in NethServer 6.6 beta 1. I have created several host groups used to control about 20 hosts. For some reason, the host list now shows only about 10 hosts, but when I go into each host group, I see the hosts that should be in each host group. If I try to re-create a host that is missing from the host list, but visible in a host group, the server complains that the host already exists. I wonder why the host list does not contain all hosts?

Davide Principi

unread,
Mar 2, 2015, 3:41:45 AM3/2/15
to Todd Firkins, neths...@googlegroups.com
Hi Todd,

On Sun, 2015-03-01 at 20:43 -0800, Todd Firkins wrote:
> I wonder why the host list does not contain all hosts?

thank you for reporting this: it may be a bug, I'll investigate!

--
Davide Principi

#davidep | @davideprincipi | GPG 0x5651EA71


Todd Firkins

unread,
Mar 2, 2015, 1:43:10 PM3/2/15
to neths...@googlegroups.com, todd.f...@gmail.com

Another interesting phenomena regarding Nethserver 6.6 beta1.  I have discovered that the antivirus program blocks two of my favorite music sites:

www.radioparadise.com
www.somafm.com

When I turn off the antivirus scanner, they work fine.

I tried adding the domain names to the content filter whitelist, and also to the proxy servers "sites without proxy" tab, but only switching off the antivirus program worked.

Is there a whitelist for the antivirus scanner, or some kind of exception list?

PS. Several other streaming sites work fine with antivirus turned on (Mixcloud, Pandora, Youtube, etc..) so it must be the streaming method that these site use that cause the interruption.

Thanks!

Filippo Carletti

unread,
Mar 2, 2015, 6:40:12 PM3/2/15
to Todd Firkins, neths...@googlegroups.com
> I tried adding the domain names to the content filter whitelist, and also to
> the proxy servers "sites without proxy" tab, but only switching off the
> antivirus program worked.

This is strange. If you add a "site without proxy" the antivirus is
bypassed completely.
I've reproduced the problem, it's not the antivirus, but the proxy set
to transparent.
If I bypass ice.somafm.com (216.129.114.89) the stream works and I can
listen to music.
I searched the net about squid and icy, it should work with squid
radioparadise is trickier, it has multiple host that need to be bypassed.
I'd prefer to make it work through squid. I searched their forum, but
I found no mentions of squid proxy problems.
Do you know more about audio streaming and proxies?


--
Ciao,
Filippo

Todd Firkins

unread,
Mar 2, 2015, 11:53:12 PM3/2/15
to neths...@googlegroups.com, todd.f...@gmail.com
Filippo, thanks for taking the time to reproduce the problem.

On my system, the proxy is set to transparent. With the anti-virus on, the two stations I mentioned will not play. With anti-virus switched off, they both begin playing the instant I click the play button in the pop-up web player or, with an alternate direct server link. I wrote to Rusty Hodge, one of the DJ's  (actually, the founding DJ)   at SOMAFM and in his reply he stated that anti-virus and streams are a common problem.

That of course proves nothing.

To answer your question, I do not know "more" about audio streaming and proxies, probably "less". I was hoping to use NethServer to help me figure out where the problem was by "following" various log files while clicking on play. I used the CentOS EPEL repository to install a program called multitail. I could then SSH into the NethServer and follow several log files at once, but it was difficult to determine where the source of the interruption was.  multitail /var/log/firewall.log /var/log/squid/access.log   /var/log/blah....

For now, I'm just reading the man pages for clamd and clamd.conf to see if there is someway to tell clamd to not scan streams.

Since you seem convinced its a problem with the proxy, I also searched for "squid and icy" and got nothing but weird pictures of seafood.
Shows I really do know "less"!

Thanks again for exploring the problem.



From: ru...@somafm.com
Subject: Re: new popup player
Date: Mon, 2 Mar 2015 12:39:41 -0800
To: toddf...@hotmail.com

Antivirus things on routers always mess with our streams... I should have mentioned that as well. Thanks for letting me know,

cheers
rusty

On Mar 1, 2015, at 10:48 PM, Todd Firkins <toddf...@hotmail.com> wrote:

Rusty, thanks for the reply. The problem was on my end. Emoji I just migrated to a new proxy/gateway called NethServer. I finally figured out that it was the anitvirus program that is an optional package on the gateway that was causing the grief. I turned it off and SOMAFM is flawless.

Sorry to bug you!


Subject: Re: new popup player
From: ru...@somafm.com
Date: Sun, 1 Mar 2015 16:25:41 -0800
To: toddf...@hotmail.com

Try using the icecast servers:


And let me know if that works in VLC for you.

PS- Some but not all streams yet have a superior 128l AAC feed:


PPS- what bugs you about the popup player?

On Mar 1, 2015, at 4:15 PM, Todd Firkins <toddf...@hotmail.com> wrote:

The new popup player is driving me nuts. I am behind a proxy server, but I have SOMAFM.com in a whitelist, and in a list of sites not to be proxied. The only stream I can get to work with VLC is http://voxsc1.somafm.com:9002 and it’s not even listed on your direct server link page (or at least I didn’t see it).
 
Right now I’m using Windows 7 with Firefox 36  or VLC, which I prefer because of the nice graphical equalizer. I also run several Linux distributions, which also always worked with the old popup player, and VLC.
 
Puzzling. Perhaps this is a problem on my end, but I can listen to Mixcloud, Pandora, HBR1 and others OK.
 
I am also having problems with radioparadise.com, but that stream does eventually start, but it can take up to 5 minutes to start playing.
 
Thanks in advance for any suggestions you may have.
 
Oh, is the old popup player still available?
Reply all
Reply to author
Forward
0 new messages