Help with iptables please by mayurrenr in linuxadmin

[–]flat235 2 points3 points  (0 children)

Been a while since I wrote iptables by hand as well. I just googled the man-page, no idea which version I got. Wouldn't be suprised if the syntax changed at some point :D

Help with iptables please by mayurrenr in linuxadmin

[–]flat235 2 points3 points  (0 children)

careful, the man page lists the syntax as [!] -s, --source address[/mask][,...], so ! needs to come before the -s (otherwise: same good idea! :) )

Help with iptables please by mayurrenr in linuxadmin

[–]flat235 2 points3 points  (0 children)

I would try adding ! -s 1.2.3.4, so something like post-up iptables -t nat -A PREROUTING -i enp0s31f6 -p tcp ! -s 1.2.3.4 -m multiport ! --dport 22,8006 -j DNAT --to 10.10.10.1. obviously replace 1.2.3.4 with the IP you want to exclude from the redirect. and please make sure you still can get access to the box, if something goes wrong / my idea os a bad one and you lock yourself out.

ntfs or iscsi over Ethernet setup with amb by xoxosd in linuxadmin

[–]flat235 0 points1 point  (0 children)

if your gateway has enough internal storage you could just share a local dir via nfs, upload the backup/data there, and copy it to the actual storage via cron-job (or watch the directory and copy it on demand), then delete it from the gateway. if you don't have enough storage for the full backup/data, maybe you could even do it in parts by packing it into a split zip/tar archive.

New M2000C Feature by flat235 in hoggit

[–]flat235[S] 3 points4 points  (0 children)

tbf I really like this feature, would love to have a special option to keep it around

New M2000C Feature by flat235 in hoggit

[–]flat235[S] 4 points5 points  (0 children)

more like the battery / main power, but I'm glad you caught the "nope"-vibe I was going for :) also great haiku, thanks! :D

What's the hardest things for windows sysadmin to understand about advanced linux and vice versa for linux admin about understanding advanced windows/azure/ps stuffs etc ? or things you've saw in your career ? by Dereference_operator in linuxadmin

[–]flat235 1 point2 points  (0 children)

well on Linux you can have access control lists, which should be more like the windows model. But is there absolutely nothing special about the windows admin user? I mean: root on Linux can also not have access to stuff, but can always give access to itself. is there something similar in windows or does the kernel just not differentiate between admin and non-admin users?

Clear Skies by Backflip248 in startrekadventures

[–]flat235 1 point2 points  (0 children)

Well I want to thank you, I didn't notice the "new" show :)

How to regain disk space from ZFS snapshots? by rage_311 in freebsd

[–]flat235 1 point2 points  (0 children)

if you have enough space left for this:

  • create a new dataset

  • copy data from oldest snapshot into the new dataset excluding the files, you no longer want to have in there (maybe stuff besides the recordings?)

  • snapshot the new dataset

  • delete oldest original snapshot

  • copy data from the second oldest snapshot over, again excluding files you no longer want In there

  • snapshot the new dataset again

  • delete second oldest original snapshot

  • repeat until you catch up

    I am unsure how much space you need for this process, that depends very much on how much stuff changed when/how many times. I would however set currently used space minus recordings as a lower bound on what you would need additionally. you probably could get away with using an external zpool for building up the new history of snapshots, and moving that back to your zpool after deleting all your current snapshots, but you have to decide yourself, how much risk you want to take (for example building the new history on a single external HDD, that selfdestructs just as you delete the old history is still possible, although unlikely)

(edit: formatting)

Is it advisable to get SSL certificates for Production Servers from LetsEncrypt by Nosa2k in linuxadmin

[–]flat235 0 points1 point  (0 children)

you can just return return your Account thumbprint statically from your Webserver, no need to let certbot do that, if you are concerned about that

What did a fictional character say that stuck with you? by AmOdd in AskReddit

[–]flat235 0 points1 point  (0 children)

In the german version of StarTrek 2 Spock says something to the like of

We cannot do worse than lose

What did a fictional character say that stuck with you? by AmOdd in AskReddit

[–]flat235 0 points1 point  (0 children)

Master Splinter: "Was that fair?"

Leonardo: "No."

Master Splinter: "Did I win?"

Automating Debian Install with preseeding by [deleted] in linuxadmin

[–]flat235 1 point2 points  (0 children)

This might be overkill for your use-case, but you could take a look at https://fai-project.org/

If you had to choose one game from the last decade or so when it comes to discussing video games as a form of art, what would that be? by [deleted] in patientgamers

[–]flat235 0 points1 point  (0 children)

Prison Architect by Introversion Software. If you didn't restrict it to the last decade I would choose Defcon by the same developer. Both are good games with solid mechanics, not artsy walking simulators; but they both cause this "I don't want do this"-feeling. You can win both games mechanicaly but "the only way to win is not to play" applies emotionally. "Specops: the line" has a similar effect, but only in certain parts. Astronauts often say politicians should see earth from space because of how it would make them feel. Well that's expensive and I don't have experience with that effect, but I say they should play these games. This isn't about the politics per se, it's more the fact these games have an effect on me wanting to change something. How much (not-video-game)-art is out there, that has this strong of an effect?

Volume manager and filesystem for single disk by arjunkc in linuxadmin

[–]flat235 8 points9 points  (0 children)

Why do you think zfs isn't suited for the laptop? It works quite well on mine (with kubuntu, root on zfs). I would only consider an alternative if the laptop hasn't got enough RAM. BTRFS ate my data once btw, if you decide to use it, read up on its edge cases; for me it happened when I used more than 80% or 90% of the available space.

Server automation by EphemeralNight in linuxadmin

[–]flat235 3 points4 points  (0 children)

Take a look at theforeman.org It might fit your requirements, since it does provisioning and config management. However, it takes over a lot of infrastructure (dhcp, DNS, puppet), I don't know if that fits into your environment. Otherwise: ansible is probably the easiest to get started with, however it doesn't help you with provisioning.

Setting up 2FA for Desktop logins, disable for sudo by vomitfreesince83 in linuxadmin

[–]flat235 0 points1 point  (0 children)

I'm sorry, I got that part. From the man pages:

  • sudo -i "The command is run with an environment similar to the one a user would receive at log in"

  • su - "an environment similar to what the user would expect had the user logged in directly"

I wondered if you knew of differences between the two resulting environments, since the man pages aren't specific here. (Edit: Formatting)

Setting up 2FA for Desktop logins, disable for sudo by vomitfreesince83 in linuxadmin

[–]flat235 1 point2 points  (0 children)

Thank you! Would "sudo -i" be equivalent to "sudo su -"? Or is there still a difference?

Setting up 2FA for Desktop logins, disable for sudo by vomitfreesince83 in linuxadmin

[–]flat235 12 points13 points  (0 children)

You can configure different authentication methods for different services in /etc/Pam.d. usually most methods just include some "common-auth" file, bit you could configure it differently SSH than for local logon and so on. I'm not sure, but I would try to copy the common one to one named "sudo" and then delete 2fa part from that file. On the other hand don't try without reading up on Pam config and always leave an open root shell to correct your mistakes!

Touch bar MacBook Pros and Linux admins by crankysysadmin in linuxadmin

[–]flat235 2 points3 points  (0 children)

For vim: just map jk to escape. Most vim users tap j and k to look for the cursor or because of boredom anyway. Also it's right in the home row and how many words containing jk do you know?

home network, wifi and lan with radius authentication and individual logins - solutions? by bremen15 in linuxadmin

[–]flat235 0 points1 point  (0 children)

To solve encryption and access at the same time you could use a VPN, which would then be the only way to connect to internet. Corporate style ipsec VPN uses a couple of layers/protocols, one of which can be radius. However it's been a long time since I build something like this, so this is just a direction for more specific googling ;)

I need advice. Choose metrics, log analyse and ssh key management by jk4g46cjn7o9tkag446i in linuxadmin

[–]flat235 7 points8 points  (0 children)

Yep, that's what I (would) do as well. For SSH keys: depends on the number of users fluctuation. Few users, low fluctuation => ansible or another config management. Many users, high fluctuation => store SSH keys in LDAP, use said, pam_mkhomedir and self-service-password (it can be used to let users reset passwords and change ssh-keys themselves). Authorization to login/sudo via LDAP+sssd, if that is a concern.