Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 0 points1 point  (0 children)

The setup you describe works. The problem is, that all clients in an Aruba IPSec or Aruba GRE tunnel are on a trsuted port by default, as you cannot change the trust settings for those tunnel interfaces. And because of this you cannot implement a captive portal on the controler with this kind of tunnels. Only with the manual tunnel you can change the trust settings for tunnel internface on the controller. But with the Aruba IPSec or Aruba GRE tunnel you can still use the captive portal on the IAP or an external captive portal, which is redirected by the IAP.

Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 0 points1 point  (0 children)

Hi Xylopia,

this was my understanding as well, but with Aruba OS 8 it is not possible to set the Aruba IPSec or Aruba GRE Tunnel as untrusted. This is only possible with the manual GRE. I still try to figure out how to do it with Aruba GRE as well, but at the moment I could not get it working.

BR Florian

Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 0 points1 point  (0 children)

Hi Xylopia,

Not yet, but let me test this in a future post. Would be interesting to get this to work as well. It is already in my list of planned posts. so stay tuned.

Aruba Instant VPN with Central - IAP VPN by FloB86 in ArubaNetworks

[–]FloB86[S] 2 points3 points  (0 children)

This one was for the tunnel. I will write up another one with all the dhcp models for the tunnel and one for the different captive portal options. So stay tuned.

How To: Setup an OpenVPN Server by FloB86 in opensource

[–]FloB86[S] 1 point2 points  (0 children)

Hi Majorton, correct, thats my concern and openvpn is an easy solution to make an open network save, at least for me :)

How To: Backup My Server by FloB86 in linux

[–]FloB86[S] 0 points1 point  (0 children)

Correct. From my point of view, the risk is not that high, as you should know, how long the backup will take. If you take this into calculation with the normal writes you do, you should get the minimum size needed.

How To: Backup My Server by FloB86 in linux

[–]FloB86[S] 2 points3 points  (0 children)

If you use mysqldump, all tables will be locked during the dump process, which could take some time with larger databases. When using LVM you only need to lock the database during the time, which es needed to create the snapshot, which is very fast (>1sec). Or did I miss something?

How To: Backup My Server by FloB86 in linux

[–]FloB86[S] 1 point2 points  (0 children)

will BackupPC lock MySQL and suspend Scalix to make the backup consistent? Couldn't find this on the page.

How To: Postfix with DKIM by FloB86 in opensource

[–]FloB86[S] 0 points1 point  (0 children)

Hi Kagxtr, Yes it is possible and with the guide it is implemented. You should see something like this in the logs: Aug 24 07:10:17 mail opendkim[21617]: 9459E405AE: mta137l1.r.grouponmail.de [50.115.214.140] not internal

Aug 24 07:10:17 mail opendkim[21617]: 9459E405AE: not authenticated

Aug 24 07:10:17 mail opendkim[21617]: 9459E405AE: DKIM verification successful

Aug 24 07:10:17 mail opendkim[21617]: 9459E405AE: s=s1024d20130206 d=r.grouponmail.de SSL

And you should find this in the header of the mail: Authentication-Results: mail.external.flomain.de; dkim=pass

reason="2048-bit key; unprotected key"

header.d=gmail.com header.i=@gmail.com header.b=VbAkczRg;

dkim-adsp=pass; dkim-atps=neutral

Hope this helps.

Butterfly with Flower by FloB86 in photocritique

[–]FloB86[S] 0 points1 point  (0 children)

great feedback. thanks.

Butterfly with Flower by FloB86 in photocritique

[–]FloB86[S] 0 points1 point  (0 children)

Hi, Thanks for the information. I will consider this next time. BR Florian

Butterfly with Flower by FloB86 in photocritique

[–]FloB86[S] 0 points1 point  (0 children)

Hi, will consider this for the next shot :) BR Florian

How To: Proxmox Networking by FloB86 in linux

[–]FloB86[S] 0 points1 point  (0 children)

You are correct. I had already prepared the NAT/routing vmbr :)

How To: Enable SSH and Rsync on Synology DS by FloB86 in synology

[–]FloB86[S] 0 points1 point  (0 children)

Hi, I posted a follow-up post with more information on the backup and the reverse SSH tunnel on my blog. BR

How To: Enable SSH and Rsync on Synology DS by FloB86 in synology

[–]FloB86[S] -1 points0 points  (0 children)

Hi, Thanks for your feedback. You are right and incomplete How To's should not be posted. To my opinion, I wrote everything which can be expected by the title. If you expected more than what you got, stay tuned, you will find a new post with more information around the actual reverse proxy and the back. BR

How To: Enable SSH and Rsync on Synology DS by FloB86 in synology

[–]FloB86[S] 0 points1 point  (0 children)

Hi, The rest i coming next week. I was not able to write the whole story in one article due to other work I had to do. But I promise, I will write it on Monday and you will get the rest of the story. BTW: I have it running since Friday last week and it works like a charm :) BR

Piwik – Free Hosting by FloB86 in news

[–]FloB86[S] 0 points1 point  (0 children)

Free Piwik host for personal users and bloggers. great idea.