#arpnetworks/ 2015-02-06,Fri

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)

WhoWhatWhen
***dwarren has quit IRC (Read error: Connection reset by peer) [01:51]
........................... (idle for 2h11mn)
toeshred has quit IRC (Ping timeout: 265 seconds)
toeshred has joined #arpnetworks
[04:02]
jbergstroem has quit IRC (Ping timeout: 250 seconds)
jbergstroem has joined #arpnetworks
mjp has quit IRC (Read error: Connection reset by peer)
carvite_ has joined #arpnetworks
mjp has joined #arpnetworks
jpalmer has quit IRC (*.net *.split)
twobithacker has quit IRC (*.net *.split)
sjackso has quit IRC (*.net *.split)
Hien_ has quit IRC (*.net *.split)
carvite has quit IRC (*.net *.split)
carvite_ has quit IRC (Changing host)
carvite_ has joined #arpnetworks
carvite_ is now known as carvite
jpalmer has joined #arpnetworks
twobithacker has joined #arpnetworks
sjackso has joined #arpnetworks
Hien_ has joined #arpnetworks
[04:09]
.... (idle for 16mn)
dj_goku_ has quit IRC (Read error: Connection reset by peer)
dj_goku has joined #arpnetworks
[04:37]
.... (idle for 15mn)
dwarren has joined #arpnetworks [04:52]
.................................................. (idle for 4h8mn)
SpeedBus has quit IRC (Ping timeout: 245 seconds)
SpeedBus has joined #arpnetworks
[09:00]
......................................... (idle for 3h22mn)
mnathani has quit IRC (Ping timeout: 264 seconds)
mnathani has joined #arpnetworks
[12:23]
.............. (idle for 1h5mn)
dj_goku_ has joined #arpnetworks
dj_goku has quit IRC (Read error: No route to host)
[13:31]
dj_goku_ has quit IRC (Read error: Connection reset by peer) [13:42]
dj_goku has joined #arpnetworks
dj_goku has quit IRC (Changing host)
dj_goku has joined #arpnetworks
[13:47]
...... (idle for 25mn)
qbit has quit IRC (Quit: leaving) [14:12]
....... (idle for 32mn)
qbit has joined #arpnetworks
qbit is now known as Guest28144
Guest28144 is now known as qbit
[14:44]
......... (idle for 40mn)
mercutiodoes anyone know of an ipv6 netmask validator?
ie to make sure you're not screwing up syntax.
[15:27]
brycecmercutio: like http://www.gestioip.net/cgi-bin/subnet_calculator.cgi ? [15:34]
mercutioahh yeah like that
it's not quite as nice as the netmask command i usually use for ipv4 just to check :)
in the end i used openbgpd to validate it :)
[15:43]
brycecit was simply the first google result for "ipcalc ipv6" :P (Also, I've used their IP address management stuff before) [15:44]
mercutiothe extra :: etc gets confusing. [15:44]
brycecthere's an extra :: ? [15:44]
mercutioit /loked/ right [15:45]
brycecShouldn't there be at most 1 [15:45]
mercutionah
shortened form.
this is a /127 that i'm doing.
[15:45]
brycecRight. In shortened form there can only be 1 instance of :: [15:45]
mercutioyeah
there only is one
[15:45]
brycecSo where's the extra? [15:45]
mercutiowell over ipv4 it's "extra" [15:45]
brycecah [15:46]
mercutioi just get paranoid of making mistakes so like to check [15:47]
brycecThat's fine. i was just confused by "the extra ::" (because to me, there's 1, and any more are extra. I don't compare it to ipv4) [15:49]
***medum has joined #arpnetworks [15:49]
mercutioYeah, I'm still kind of rusty on IPV6.
i'd be fine if it only went up to /32 :)
but the long addresses by sight still are a bit.. disorientating.
apparently someone had asked about netmask gaining ipv6 support in 2000.
and someone asked for an update last year.
it's a pretty nifty program for ipv4.. you can just do things like netmask -r 192.168.13.76/29
or such
and it'll show you the range of ip addresses that covers.
[15:56]
brycecipcalc does the same thing [16:01]
mercutiooh [16:01]
brycecAnd has seen an update more recently than 5 years ago [16:01]
mercutiowith ipv6 support? [16:01]
brycecno idea offhand
Looks like no, at least on my install
[16:01]
mercutiothe help doesn't suggest ipv6
well ipv4 hasn't changed, so don't relaly need updates.
[16:02]
bryceclooks like sipcalc has superseded ipcalc and supports ipv6 [16:03]
mercutiosipcalc sounds like it might
haha
[16:03]
brycec(yep, confirmed ipv6 in sipcalc) [16:03]
mercutiosweet, this looks good
yeah
i tried it.
[16:04]
........... (idle for 50mn)
***RandalSchwartz has joined #arpnetworks [16:54]
RandalSchwartzanyone up for a ZFS question? [16:54]
mercutioyeah sure [16:55]
RandalSchwartzso... I use send/recv to clone a snapshot from zroot to pool/zroot (on a different disk)
what steps do I have to take to make it boot off the second disk, and mount pool/zroot as /
[16:55]
mercutiooh i haven't done much with freebsd zfs root [16:56]
RandalSchwartzsomething in bootconf? [16:56]
mercutiobut i think as long as the bootloader understands it shoudl be find
you probably have to use zfs set mountpoint=/ on it
[16:56]
RandalSchwartzvfs.root.mountfrom="zfs:zroot"
probably need to edit that too
[16:56]
mercutiohttps://wiki.freebsd.org/RootOnZFS
hmm
[16:57]
RandalSchwartzdo I need to promote the snapshot so it becomes the live fs
I haven't done that before
[16:57]
mercutioyou'll need to clone the snapshot
so usually you make a snapshot on the sender, set the receiver to readonly
[16:57]
RandalSchwartzyes... the tool does that
zxfer
[16:57]
mercutioand keep updating the snapshot on the receiver using diffs, then when you wnat to promote it, you clone frmo the snapshot to a real file system [16:57]
RandalSchwartzahh. clone... that was the word I was missing I guess [16:58]
mercutioit sounds like freebsd doesn't use the zfs automount stuff
and uses /etc/fstab instead.
and that vfs.root.mountfrom is probably what you want.
yeah so you can take any snapshot, create a clone from it, and access it like a normal filesystem.
[16:58]
RandalSchwartzHmm. Maybe I should rehearse this in a VM. :) [17:00]
mercutioseems like a good idea [17:01]
RandalSchwartzand the selected boot drive is out-of-band right?
this is a dedi system at arp
[17:01]
mercutioi'm not sure [17:02]
RandalSchwartzok [17:02]
mercutioi would just split the boot pool from the data pool.
and just haev a fully functional second pool
on another machine
[17:03]
RandalSchwartztoo late for that. :) [17:03]
mercutioheh [17:04]
RandalSchwartzwe're trying to migrate from hard to ssd [17:04]
mercutioyeah. [17:04]
RandalSchwartzcurrently mirror hard... using zxfer to push data over. that worked well. [17:04]
mercutiowithout doing another install
how big is your root
[17:04]
RandalSchwartzthat's personal! [17:04]
mercutioyou can mirror to ssd if it's big enough
so mirror hard-disk to ssd
[17:04]
RandalSchwartzcan't set up mirror after the fact [17:05]
mercutioyou can [17:05]
RandalSchwartzalready have mirror hard1 hard2 [17:05]
mercutioif it's small enough existing
you can unmirror
or just remove drive / fail it
[17:05]
RandalSchwartzhards are 768, ssd is 512
so it wouldn't accept the mirror
[17:06]
mercutioi had to do that when migrating my zfs array at home
yeah
[17:06]
RandalSchwartzso I have to resort to this send/recv dance
all for about 100G of data. :)
[17:06]
mercutioi'd normally opt for another system install
on a second machine
[17:06]
RandalSchwartz"if I put it in a jail..." [17:07]
mercutiobut that's why i don't migrate from hard-disk to ssd
yeah if you'd made your root smaller..
[17:07]
RandalSchwartzhard to do that now :) [17:07]
mercutiowhen you do your ssd short stroke it
you can always expand it later.
[17:07]
RandalSchwartzinteresting thought [17:07]
mercutioit's a good habit to be in if you're using much less data
so like with a 512gb ssd, with 100gb of data you may decide to only do 200gb on each drive
but leave partition space there
[17:08]
RandalSchwartzhmm. looks like you *can* "mirror down"
... https://blogs.oracle.com/mock/entry/how_to_shrink_a_mirrored
[17:09]
mercutioyeah.
oh
i don't know if you can
i think that was added after the fork.
[17:11]
RandalSchwartzugh [17:11]
mercutioi've been finding with ssd's raidz works better than mirrored. [17:12]
RandalSchwartzsays blog entry 2010
but I'd need 3 ssds then
[17:12]
mercutioyou've got so many iops, and write speed goes up.
yeah.
[17:12]
RandalSchwartzwe've been in this conversation before :) [17:12]
mercutiooh [17:12]
RandalSchwartzOh, I could split each ssd into two [17:12]
mercutiooh yeah you can't have more than 2. [17:12]
RandalSchwartzand make it a 4-way raidz [17:12]
mercutiouhh [17:13]
RandalSchwartzor 3 with a spair
spare
[17:13]
mercutiothat wouldn't give you redundancy [17:13]
RandalSchwartzoh - because ssd fail is taking two drives at once
and double fail is bad
[17:13]
mercutioanyway, with linux i've found it really easy to migrate.
i don't actually think it'll be that complicated.
i would check out the freebsd zfs root documentation for before it was in the installer.
s/for/from/
[17:14]
BryceBot<mercutio> i would check out the freebsd zfs root documentation from befrome it was in the installer. [17:14]
mercutiohaha
i didn't have /g
i think there's just two key components, the bootloader, and the initial config as it comes up
[17:14]
RandalSchwartzyeah, the latter being /boot/loader.conf
or something like that
where I found the zfs:zpool thing
[17:17]
mercutiohttps://calomel.org/zfs_freebsd_root_install.html
does this help?
that site is terrible
hmm zfs set bootfs?
https://wiki.freebsd.org/RootOnZFS/GPTZFSBoot/9.0-RELEASE
this may be better
[17:21]
RandalSchwartzbetter in what sense
ahh.. that's the one I have bookmarked.
[17:30]
mercutiook [17:31]
RandalSchwartzok - gonna wander into ##freebsd to see if they know what I need [17:31]
mercutiogood idea [17:32]
................ (idle for 1h18mn)
mnathani_sipcalc 0.0.0.0/0 >> Addresses in network - 4294967295
Usable range - 0.0.0.1 - 255.255.255.254
[18:50]
brycecChecks out by my math. [18:56]
............ (idle for 57mn)
mnathani_I wonder how many bytes it would take to store a compressed text file containing one ipv6 address per line and do that for all possible ipv6 addresses [19:53]
mercutioa lot
oh compressed.
there's actually special compression algorithams for things like that
[20:04]
or do you mean human readable compression? [20:13]
..... (idle for 23mn)
ip addresses are predictableish
which reminds me, http://blog.edgecast.com/post/110230974176/being-good-stewards-of-the-internet
[20:36]
anisfarhanaand until now i still dont understand how to use the sipcalc even with lots of reading.
Stupid is always stupid i guess.
[20:38]
mercutioanisfarhana: sipcalc 192.168.13.13/29 will show something like
etwork range - 192.168.13.8 - 192.168.13.15
Usable range - 192.168.13.9 - 192.168.13.14
so if you have a /29 subnet that you want to place, you can figure out where a nice multiple of 8 is
you can always do it on your own too.
curiously it doesn't seem to like legacy subnets. netmask does.
err legacy netmasks
[20:38]
anisfarhanaYes i actually know that part.
As i u always use sipcalc to trace out youtube ip address blocks.
and blocked it in firewall until many of staff at office complained they are not able to use Google.
[20:41]
mercutioyoutube is probably easier to block in dns.
and you can block alternative dns providers.
it shares infrastructure too close to google search.
[20:43]
anisfarhanaInteresting...
So what you just said, https for youtube counts too?
I have no problem blocking youtube.com
But i do have problem to block https://www.youtube.com
[20:47]
mercutiohttp or https can be blocked just by dns
unless anyone knows the ip addresses to go to
[20:49]
anisfarhanaAnd now even worst, our staff use Google Chrome and it use HTML5 player for youtube. [20:49]
mercutiowhat dns cache are you using? [20:49]
anisfarhanaI do blocked youtube by using squid too, the mime for *media player*
anisfarhana blinks
[20:50]
mercutiothat wont' help https unless you force people to use proxy [20:50]
***brycec is now known as regex [20:50]
anisfarhanamercutio: Can you simplify your question again? [20:50]
***regex is now known as brycec [20:50]
anisfarhanaI am not RandalSchwartz :P
Well, I use tranparent proxy at office though
[20:50]
mercutioare you using unbound or bind or dnsmasq or what as a local resolver?
transparent proxies don't work with https
[20:52]
anisfarhanaOkey..I dont know what to say now.
Your question is just..very geeky to me.
[20:52]
***pyvpx has quit IRC (Remote host closed the connection) [20:52]
mercutiowell in /etc/resolv.conf.. there's a nameserver... do you have your own local one?
or are you just using your isp's resolver?
[20:53]
brycecIt's a geeky channel... [20:53]
anisfarhanaBut i use squid in firewall. Firewall ---> proxy server (local ip address) ---> Internet
I am using Google DNS.
[20:53]
mercutiodo you have a cache in front of that?
or do you just hand out google dns to desktops?
[20:53]
anisfarhanaDesktop --> DHCP server (use google dns) ---> Firewall (also google dns) [20:55]
mercutiodoes the dhcp server have local dns cache?
like dnsmasq can do dns as well as dhcp
[20:55]
anisfarhanaIt is just normal dhcp server in wondows. [20:55]
mercutioisc dhcp server doesn't.
oh
[20:55]
brycecin other words, a "dns forwarder" [20:55]
anisfarhanaOpen the range for each VLANs. [20:55]
mercutiowindows :/
do you run squid on windows?
[20:55]
anisfarhanaThat is only i know to setup dhcp server.
Debian
[20:56]
mercutiodnsmasq is pretty easy [20:56]
anisfarhanaI use ipcop for firewall. [20:56]
mercutioand does dns too
and makes it easy to point domain names somewhere else
[20:56]
m0undswhoa, ipcop? haven't heard that name in years [20:56]
mercutioand it publishes dhcp names to dns. [20:56]
anisfarhanaInteresting... [20:57]
mercutioipcop?
did i miss osmethingZ?
err something
[20:57]
anisfarhanam0unds: It works, I have at least 4 ipcops running like charm now. [20:57]
m0undsanisfarhana: is it still actively developed? i had no idea it was still around [20:57]
anisfarhanaWhy bother with those expensive appliance while ipcop can do that? [20:57]
mercutiocos there's pfsense now? :") [20:57]
anisfarhanam0unds: afaik yes sir. [20:57]
brycecbecause there's better AND free
mercutio: ++
Also m0n0wall
[20:58]
anisfarhanaIts not about free, why you wanna spend lots of money while you can use opensource for the same mission? [20:58]
mercutioanisfarhana: he was just saying there are better alternatives that are also free. [20:58]
anisfarhanaBetter use that money and donate to people like mercutio here. [20:58]
brycecm0n0wall and pfSense are both free, open-source, etc [20:59]
m0undsyea, i compared ipcop to m0n0wall in 03 or so, and decided on m0n0wall because i liked bsd better [20:59]
anisfarhanaAh yes..well..again..sorry if i said anything wrong. my engrish is not good. [20:59]
m0undsran it on an old hp proliant server until i couldn't bear the noise anymore and built something newer (in like 04 or 05) [21:00]
anisfarhanamercutio: I am googling about dnsmasq atm [21:00]
mercutioi used to use an old openbsd box as a router [21:00]
brycecI ran m0n0wall for years, both at home and for work. Then there came pfSense and I used that at home and work, and still do use it at home. (Before m0n0wall, I used ipcop too) [21:00]
mercutioat home, with like 16mb of ram [21:01]
anisfarhanaI wish i can flirt with those ipcops dev
lol
[21:01]
mercutioit looks like ipcop is still in development. [21:01]
anisfarhanaYes it is :)
I am glad the ipcop is still alive..
And founder of #ipcop channel usually here, don't see him recently.
mercutio: Ohhh dnsmasq + dhcp together in 1 place.
[21:02]
mercutioyeah it does dns and dhcp
simple config
[21:05]
anisfarhanaI think dnsmasq is something like dns + AD server for windows? [21:05]
mercutiohas a few nice things like being able to just stick extra dns names in /etc/hosts.
i reckon for small setups it's the simplest/easiest solution
[21:05]
anisfarhanaand dnsmasq actually can *block* any website i want, even on https? [21:06]
mercutioit can block the dns name to ip mapping [21:06]
brycecAnd it's easy to configure it to deny any DNS request matching a domain, such as blocking youtube.com [21:06]
mercutioor renumber it [21:06]
brycec^ Which is how we got to this point. [21:06]
anisfarhanaSigh [21:06]
mercutioi'd recommend renumbering it to an ip with a web server on it that says it's blocked. [21:06]
anisfarhanaI do aware about dnsmasq before, but i don't bother to find out what it is.
Does a person like me can configure / setup it?
[21:07]
mercutioyes.
if you can configure squid you can configure dnsmasq.
[21:07]
anisfarhanaWith no stress, less downtime, and no overnight at office?
I don't configure squid myself 100%
[21:08]
mercutiowell the biggest complication is if you have a mix or static and dhcp addresses on the same subnet [21:08]
anisfarhanaErrr engrish error again. [21:08]
mercutioand just making sure you don't clash new ip address allocations over the top of existing static allocations. [21:08]
anisfarhanaI don't configure the squid server 100% before, somebody help me for it. [21:09]
mercutiowell the only way to learn is by doing
maybe configure it at home first?
i'm using it at home myself.
[21:09]
anisfarhanaI do have spare machine at office, at least with 1 public ip address on it. [21:10]
mercutiodhcp is disruptive :) [21:10]
brycecI was too, as part of pfSense (but have just switched to Unbound) [21:10]
anisfarhanaIf i have mix/static/dhcp addresses on the same subnet? [21:10]
mercutiohttps://wiki.debian.org/HowTo/dnsmasq
this looks like a way to say the important things easy
[21:11]
anisfarhanaOk by looking at the url given, I need another server for that. [21:11]
mercutiojust run it on your squid server
you could setup dns first
[21:11]
anisfarhanaBut squid server is more to front end. [21:12]
mercutioand setup your dhcp server to give out the dns cache's ip. [21:12]
anisfarhanacurrent windows server that i use for dhcp server, able to do that? [21:12]
mercutioshould be able to [21:13]
anisfarhanaOk thats great. [21:13]
mercutioi've never done dhcp on windows. [21:13]
anisfarhanaIt is easy.
That is why i use it.
[21:13]
mercutiohttp://forums.petri.com/showthread.php?t=55350 [21:14]
anisfarhanaI will use any OS that could give more easy solution based on my minimal knowledge.
Wow
Interesting.
I believe 006 DNS Servers i put for the windows box at office is 8.8.8.8/8.8.4.4
So basically, just replace that google dns, to my dnsmasq?
[21:14]
mercutioyeah
and then dnsmasq can use 8.8.8.8/8.8.4.4
although i'd recommend not using google dns primary and secondary.
the chances of both going down at once is increased.
and google dns's performance can be kind of variable. i don't know what it's like there.
[21:16]
anisfarhanaIt is good so far. [21:18]
mercutioi'm assuming google's dns is in singapore.
but i think they send their requests from taiwan or soemthing
[21:18]
anisfarhanaMany people use gDNS to run away from blocked website by our gov. [21:18]
mercutioheh
opendns may be another option
or ultradns
[21:18]
anisfarhanaSlow.
Based on ping compared to gdns
[21:19]
mercutioyou can set dnsmasq to query multiple dns in parallel
and take the first answer it gets.
ping isn't everything
google ping is like 24 msec from here
[21:19]
anisfarhanaYes this dnsmasq is interesting [21:19]
mercutiobut it's more than 24msec slower on average.
there's a cool program called namebench which lets you benchmark dns servers.
the problem with google here is that even though the server is close, all the requests come from ages away.
[21:19]
anisfarhanaI am aware of that. namebench even recommended to use gdns before. [21:20]
mercutiohmm [21:20]
anisfarhanaBut that is less important.
The more important thing is, how to fight our staff at office.
mercutio: Can i trial and error do the dnsmaqs by using the vps first? and change one of DHCP ip range at office, point it to the public vps?
[21:21]
mercutiodon't run dnsmasq on vpos
vps
[21:23]
anisfarhanaEven for testing purposes? [21:24]
mercutiowell i mean you can, but you'd have to be very careful with firewalling it. [21:24]
anisfarhanaFirewalling the vps or ? [21:24]
mercutioyou really don't want to run an open dns.
if you're behind a firewall it's safer.
yeah
unbound is better for acl support
[21:24]
anisfarhanaWell, i always can format the vps after that with 1 single click only. [21:25]
mercutioand not being open
well it's more there are constant dns attacks happenign these days
and evn if you shut it off they'll continue
so if you have open dns for 5 minutes
and they find it
[21:25]
brycecMartial arts? "The more important thing is, how to fight our staff at office." [21:26]
mercutioyou'll get 24 hours or something of dns attacks
i dunno how long it is exactly
probably longer
[21:26]
BryceBotThat's what she said!! [21:26]
anisfarhanaI am wondering why some people outside want to *attack* me for that. [21:27]
mercutioit's dns amplification attacks
basically they query a really long record from you with a fake ip address of who they want to attack
and you send a much bigger response than you receive
so like if you type host -t any google.com
you'll get a big long response
but it's a pretty short query
so they send to you at 50 megabit
[21:27]
anisfarhanaWell, i do have you to strike back. I can get brycec support if needed. [21:28]
mercutioand you respond with 200 megabit [21:28]
brycecWhat? don't involve me [21:29]
mercutiowell what i'm saying is that if you're open at all they can keep hitting you
and so be careful to block port 53 on firewall
before even trying such software.
b ut it's probably easier to do it on a lan behind firewall
[21:29]
brycecThrough bugs/security holes, attackers can "hijack" your server (dns and ntp are popular choices) to DDOS a third target. it's not personal, anisfarhana [21:30]
anisfarhanabrycec: "Never run from the battlefield without fighting" - anisfarhana [21:30]
brycecExcept the Internet is all about defense [21:30]
anisfarhanamercutio: Then i must try it over the weekend.
brycec / mercutio : I was kidding though about the strike back.
[21:31]
mercutioanisfarhana: the thing is if you're open for even a moment when they're checking for open relays [21:32]
anisfarhanamercutio: Installing dnsmasq on live server (squid server) is quite risky. [21:32]
mercutiothey'll send attack traffic your way later and you can't stop it
and they don't know it's not still open
because they're pretending to be their victim's ip.
yeah thats' why i said do it at home
if you're behind nat with no dmz with no internet ip it's safer.
[21:32]
anisfarhanaBut the *network setup* is not same like in office. [21:33]
mercutiowith ferm you can have something like: proto tcp dport 53 REJECT;
proto udp dport 53 REJECT;
i thought you just wanted to test youtube blocking?
[21:33]
anisfarhanaYou are telling about blocking port 53, I even don't know whether i do block 53 or not at office right now.
Duhhh
I can feel the stress now.
[21:33]
mercutiomaybe just use unbound. [21:34]
anisfarhanamercutio: Sir, maybe i should explain to you first about the current network topology at my office. [21:34]
mercutiolocal-zone: "youtube.com" redirect
local-data: "youtube.com A 127.0.0.1"
you should be able to have something ilke that in unbound.
[21:35]
brycecmercutio: ++ [21:35]
anisfarhanaMaybe something can make this dnsmaqs not working on current network setup.
mercutio: How about VM a linux in that windows dhcp server?
[21:35]
mercutiowith unbound you have acl's like: access-control: 127.0.0.0/8 allow
well if you're happy with your current dhcp server, then unbound may be the easier way to go
[21:36]
anisfarhanaand dnsmasq will not interfere with our current firewall + squid? [21:37]
mercutioand then you can stick it on the squid box [21:37]
anisfarhanaIf i am brave enough to take a risk on it.
Otherwise, i will use spare machine first for it.
[21:38]
mercutiowell doing dhcp as well is more disruptive than just dns. [21:38]
anisfarhanaI am happy so far with my dhcp current dhcp server, its about 5 years now and still running like charm.
Well its windows, so I am not worry about kernel panic.
or shellshock things you know.
[21:38]
brycec(Windows can kernel panic. Its kernel panics tend to be coloured blue.) [21:40]
mercutiowell we don't really do windows in here. [21:40]
brycecYou don't say!?! :P [21:40]
anisfarhanabrycec: Sir, with high respect to you, and to mercutio , and also to the arpnetworks, that windows not even give me single bsod until now. I am not saying that windows is good. But what i like said before, with my limited knowledge, I just use *any* that will give me less headache and problems.
Hate to see the conversation, or hates about windows vs linux. Its 2015 now.
And do not ignore me just because i use only 1 single windows at office for dhcp server.
:/
[21:42]
brycecThis isn't Windows vs. Linux, anisfarhana. It was a statement that ARP Networks is known as a *nix VPS host. This is a *nix-leaning crowd in here. [21:43]
anisfarhanaanisfarhana nods
Sorry for that. Sorry #arpnetworks
My bad.
I am talking about it since nobody speaking about arpnetworks or nix related here..thats all.
Again, sorry.
[21:44]
mercutiowell ok back to your original issue. [21:45]
***dj_goku has quit IRC (Ping timeout: 256 seconds) [21:45]
mercutiounbound is pretty easy to setup, and can do acl's to only allow certain ip's to access dns.
which makes it safer to use on an internet facing host.
[21:45]
anisfarhanaWait mercutio, maybe we can speak about this in private or another channel? [21:46]
mercutiothe config is slightly more verbose, but for the essentials it's not relaly harder.
well you know how to change the dhcp server.
[21:46]
brycecYou're free to talk about it in here
Nobody's complaining
[21:46]
mercutioso it's just unbound config. [21:46]
anisfarhanaThanks.
mercutio: Change as in, that 006 in win dhcp server?
The url given by you before?
[21:46]
mercutiounbound is one of the most popular dns resolvers that came out of nowhere.
to being in lots of places. including arp iirc.
anis: yeah.
but it still works ok on small setups.
[21:47]
anisfarhanafrom gdns to my-setup-dnsmasq, and my-setup-dnsmaqs use gdns right? [21:48]
mercutiogo to unbound not dnsmasq,
less likely to break things :)
it's a bit simpler to use google dns upstream from dnsmasq than unbound
[21:48]
anisfarhanaI thought unbound is the local IP address i use for dnsmasq server. Or I am wrong here? [21:49]
mercutioname: "."
forward-addr: 8.8.8.8
forward-first: yes
you need something like that in the config to use google dns from unbound
nah unbound is an alternate dns resolver
https://unbound.net/
[21:49]
anisfarhanaOk ok, this is more confusing now.
Stop first mercutio.
[21:50]
mercutiohttp://npr.me.uk/unbound.html
if you must you can run it on windows too
[21:52]
anisfarhanaSo unbound and dnsmaqs, are different?
I need both of it?
[21:53]
mercutioyou need either
but unbound is safer to not be open dns
unbound can also be graphed in cacti if you're into that kind of thing
[21:54]
......... (idle for 42mn)
***dj_goku has joined #arpnetworks
dj_goku has quit IRC (Changing host)
dj_goku has joined #arpnetworks
[22:37]

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)