VPSと組み合わせてなんかできるかな。
stone (前編):
'via Blog this'
2014年6月26日木曜日
VPSと自前プロキシサーバのすすめ - Eyes, JAPAN Blog
VPSと自前プロキシサーバのすすめ - Eyes, JAPAN Blog:
123systemsのVPSが2台余っている。
1台を申し込むと、キャンペーンでメモリー256Mが年間8$とかで案内をしてくれるので、メモリー2G 1台(本契約)と256M×1台が検証用であります。
ServerManiaはマインクラフト用にSSD-CashedVPS メモリー2Gを1台年間56$で借りています。
※現在は寄付を頂いて40$程追加オプションでメモリー4Gにしています。
'via Blog this'
123systemsのVPSが2台余っている。
1台を申し込むと、キャンペーンでメモリー256Mが年間8$とかで案内をしてくれるので、メモリー2G 1台(本契約)と256M×1台が検証用であります。
ServerManiaはマインクラフト用にSSD-CashedVPS メモリー2Gを1台年間56$で借りています。
※現在は寄付を頂いて40$程追加オプションでメモリー4Gにしています。
'via Blog this'
2014年6月25日水曜日
故郷納税(ふるさと納税) 寄付控除について
完全ガイド 100%得をする「ふるさと納税」生活 金森 重樹 を読みました。
この本は、所得税、県民税数百万払っている人の話なので、あっそうとしかならないのですが、自分に当てはめると年収500万~600万で寄付控除が25000円程あったので、
1万円2口、5000円1口、計3口の寄付を行いました。
人気の米20キロは人気で売り切れだったので、父の故郷の淡路島の町で米10キロ(1万円寄付)と鳥取でハム(1万円寄付)とアイスクリーム(5000円)をやってみました。
毎年、確定申告はFXやらなんやらでやっているので、確定申告は苦にはなりませんが。
実質、25000円-2000円=23000円が寄付控除で帰ってくる計算になります。
今住んでいる岡山市は寄付特典がない。寄付受け付ける気はないんだなぁと思います。倉敷はあるんだけどね。
同じ税金を払うならば、地方が元気になってくれればいいなぁと思います。
Cacti のパスワード変更
Cactiでパスワードを忘れた場合の備考録(パスワード変更)
#mysql -u root -p
mysql>user databasename;
mysql>update user_auth set password=MD5('test') where username='admin'
ユーザー adminのパスワードがtestに変更されるので、ログインしてからパスワードを変更する。
#mysql -u root -p
mysql>user databasename;
mysql>update user_auth set password=MD5('test') where username='admin'
ユーザー adminのパスワードがtestに変更されるので、ログインしてからパスワードを変更する。
2014年6月13日金曜日
RTXシリーズ RTX1100/RTX1200 でのIPSECパススルー
RTXシリーズでのIPSECパススルー
条件:フレッツ光ネクストでPPPOEでインターネットに接続し、LANのPCから外部に対してIPSECを接続する。
インターネットからLANに対してのFilterが必要
ESPはプロトコル番号50番だがお客さんの指定でTCP50も追加
ほか、AHやもろもろも追加
RouterA# show config
# RTX1100 Rev.8.03.24 (Thu Oct 27 11:06:13 2005)
# MAC Address :
# Memory 32Mbytes, 3LAN, 1BRI
# main: RTX1100 ver=e0
login password *
administrator password *
security class 1 on on
console character sjis
console lines 24
console prompt RouterA
ip route default gateway pp 1
ip lan1 address 192.168.100.1/24
pp select 1
pp always-on on
pppoe use lan2
pppoe auto disconnect off
pp auth accept pap chap
pp auth myname xxxxx@fip.plala.or.jp xxx-xxx-xxx
ppp lcp mru on 1454
ppp ipcp ipaddress on
ppp ipcp msext on
ppp ccp type none
ip pp address xxx.xxx.xxx.x/32
ip pp mtu 1454
ip pp secure filter in 1 2 3 4 5 10 11 12 20 21 22 23 24 25 30 31 32 33 34 35
ip pp secure filter out 20 21 22 23 24 25 50 51 52 99
ip pp nat descriptor 1
pp enable 1
ip filter 1 pass xxx.xxx.xxx.xxx 192.168.100.1 tcp * telnet
ip filter 2 pass * 192.168.100.0/24 udp 500 *
ip filter 3 pass * 192.168.100.0/24 udp 4500 *
ip filter 4 pass * 192.168.100.0/24 udp 51 *
ip filter 5 pass * 192.168.100.0/24 udp 50 *
ip filter 10 reject 10.0.0.0/8 * * * *
ip filter 11 reject 172.16.0.0/12 * * * *
ip filter 12 reject 192.168.0.0/16 * * * *
ip filter 20 reject * * udp,tcp 135 *
ip filter 21 reject * * udp,tcp * 135
ip filter 22 reject * * udp,tcp netbios_ns-netbios_ssn *
ip filter 23 reject * * udp,tcp * netbios_ns-netbios_ssn
ip filter 24 reject * * udp,tcp 445 *
ip filter 25 reject * * udp,tcp * 445
ip filter 30 pass * * icmp * *
ip filter 31 pass * * established * *
ip filter 32 pass * * tcp * ident
ip filter 33 pass * * tcp ftpdata *
ip filter 34 pass * * udp domain *
ip filter 35 pass * * udp * 33434-33500
ip filter 50 reject * 10.0.0.0/8 * * *
ip filter 51 reject * 172.16.0.0/12 * * *
ip filter 52 reject * 192.168.0.0/16 * * *
ip filter 99 pass * * * * *
nat descriptor type 1 masquerade
nat descriptor masquerade static 1 1 192.168.100.1 udp 500
nat descriptor masquerade static 1 2 192.168.100.1 esp
nat descriptor masquerade static 1 3 192.168.100.1 udp 51
nat descriptor masquerade static 1 4 192.168.100.1 tcp 50
nat descriptor masquerade static 1 5 192.168.100.1 tcp telnet
dhcp service server
dhcp scope 1 192.168.100.10-192.168.100.64/24
dns server xxx.xxx.xxx.1 xxx.xxx.xxx.9
dns server pp 1
dns private address spoof on
schedule at 1 */* 12:00 * ntpdate ntp1.xxx.or.jp
条件:フレッツ光ネクストでPPPOEでインターネットに接続し、LANのPCから外部に対してIPSECを接続する。
インターネットからLANに対してのFilterが必要
ESPはプロトコル番号50番だがお客さんの指定でTCP50も追加
ほか、AHやもろもろも追加
RouterA# show config
# RTX1100 Rev.8.03.24 (Thu Oct 27 11:06:13 2005)
# MAC Address :
# Memory 32Mbytes, 3LAN, 1BRI
# main: RTX1100 ver=e0
login password *
administrator password *
security class 1 on on
console character sjis
console lines 24
console prompt RouterA
ip route default gateway pp 1
ip lan1 address 192.168.100.1/24
pp select 1
pp always-on on
pppoe use lan2
pppoe auto disconnect off
pp auth accept pap chap
pp auth myname xxxxx@fip.plala.or.jp xxx-xxx-xxx
ppp lcp mru on 1454
ppp ipcp ipaddress on
ppp ipcp msext on
ppp ccp type none
ip pp address xxx.xxx.xxx.x/32
ip pp mtu 1454
ip pp secure filter in 1 2 3 4 5 10 11 12 20 21 22 23 24 25 30 31 32 33 34 35
ip pp secure filter out 20 21 22 23 24 25 50 51 52 99
ip pp nat descriptor 1
pp enable 1
ip filter 1 pass xxx.xxx.xxx.xxx 192.168.100.1 tcp * telnet
ip filter 2 pass * 192.168.100.0/24 udp 500 *
ip filter 3 pass * 192.168.100.0/24 udp 4500 *
ip filter 4 pass * 192.168.100.0/24 udp 51 *
ip filter 5 pass * 192.168.100.0/24 udp 50 *
ip filter 10 reject 10.0.0.0/8 * * * *
ip filter 11 reject 172.16.0.0/12 * * * *
ip filter 12 reject 192.168.0.0/16 * * * *
ip filter 20 reject * * udp,tcp 135 *
ip filter 21 reject * * udp,tcp * 135
ip filter 22 reject * * udp,tcp netbios_ns-netbios_ssn *
ip filter 23 reject * * udp,tcp * netbios_ns-netbios_ssn
ip filter 24 reject * * udp,tcp 445 *
ip filter 25 reject * * udp,tcp * 445
ip filter 30 pass * * icmp * *
ip filter 31 pass * * established * *
ip filter 32 pass * * tcp * ident
ip filter 33 pass * * tcp ftpdata *
ip filter 34 pass * * udp domain *
ip filter 35 pass * * udp * 33434-33500
ip filter 50 reject * 10.0.0.0/8 * * *
ip filter 51 reject * 172.16.0.0/12 * * *
ip filter 52 reject * 192.168.0.0/16 * * *
ip filter 99 pass * * * * *
nat descriptor type 1 masquerade
nat descriptor masquerade static 1 1 192.168.100.1 udp 500
nat descriptor masquerade static 1 2 192.168.100.1 esp
nat descriptor masquerade static 1 3 192.168.100.1 udp 51
nat descriptor masquerade static 1 4 192.168.100.1 tcp 50
nat descriptor masquerade static 1 5 192.168.100.1 tcp telnet
dhcp service server
dhcp scope 1 192.168.100.10-192.168.100.64/24
dns server xxx.xxx.xxx.1 xxx.xxx.xxx.9
dns server pp 1
dns private address spoof on
schedule at 1 */* 12:00 * ntpdate ntp1.xxx.or.jp
2014年5月13日火曜日
Cisco1812J mac-address-table staticがコンフィグに表示されない。
ルーターの交換でコンフィグを移設していたが、以下のコマンドが入るが、コンフィグに表示されない。
「mac-address-table static 0200.0099.xxxx interface FastEthernet2 vlan 100」
コンフィグをDIFFにかけてもこの部分だけが欠落している。
⇒原因
指定しているVLAN100がVLAN DATABASEに登録されていなかった。
Router#vlan data
Router(vlan)#vlan 100
Router(vlan)#show
VLAN ISL Id: 1
Name: default
Media Type: Ethernet
VLAN 802.10 Id: 100001
State: Operational
MTU: 1500
Translational Bridged VLAN: 1002
Translational Bridged VLAN: 1003
VLAN ISL Id: 100
Name: VLAN0100
Media Type: Ethernet
VLAN 802.10 Id: 100100
State: Operational
MTU: 1500
VLANを登録して再度、コマンドをたたくと、表示されるようになった。
「mac-address-table static 0200.0099.xxxx interface FastEthernet2 vlan 100」
コンフィグをDIFFにかけてもこの部分だけが欠落している。
⇒原因
指定しているVLAN100がVLAN DATABASEに登録されていなかった。
Router#vlan data
Router(vlan)#vlan 100
Router(vlan)#show
VLAN ISL Id: 1
Name: default
Media Type: Ethernet
VLAN 802.10 Id: 100001
State: Operational
MTU: 1500
Translational Bridged VLAN: 1002
Translational Bridged VLAN: 1003
VLAN ISL Id: 100
Name: VLAN0100
Media Type: Ethernet
VLAN 802.10 Id: 100100
State: Operational
MTU: 1500
VLANを登録して再度、コマンドをたたくと、表示されるようになった。
登録:
投稿 (Atom)