This document pointing out the Direct RTP media or peer to peer communication of RTP.
I have managed to get Asterisk not to proxy media. I am running Freepbx 2.10.1.9 and Asterisk 1.8.12.0 on CentOS Linux 5.7 (Linux 2.6.18-274.3.1.el15.i686 - 32-bit) in Virtual machine. Directly connected to static IP.
It can be done under below conditions.
--> NAT should be disabled in the FreePBX ( sip.conf, Extension)
--> Network Devices and Phones should support for peer to peer communication (NO NAT)
--> In the extensions recording features should be turned off.
--> Should havedirect internet connection with static IP address
Setting changes in the SIP server, this is should be done via freepbx GUI
1) Application -> Extensions -> 'canreinvite=yes' and 'nat=no'
2) Settings -> Asterix SIP settings -> 'NAT=no' and 'IPconfiguratoin=static IP' and 'Reinvite Behavior=yes'
3) Add below entries to Other SIP Settings
--> 'directrtpsetup=yes' and
--> 'keepalive=yes'
4) Settings -> Advanced Settings -> "SIP canrenivite (directmedia)=yes" and "SIP nat=no"
5) Settings -> General Settings -> "Asterisk Dial command options:" should be empty
I have used tcpdump tool to monitor the communicatoin between server and SIP phones. Then I were albe to recognized the peer to peer communication.
Reference : http://www.dslreports.com/forum/r27852319-Can-I-get-Asterisk-to-not-proxy-media-
Tuesday, August 6, 2013
Friday, June 7, 2013
check_mailq not correctly detecting the mail queue -NRPE plugins
I have added nagios NRPE client to check mail queue in CentOS 6 server and running postfix as mail deamon.
Issue : Eventhough there is mailq in the server nagios showed as Empty mailq.
First I checked the below configuration files in the Mail server
--> /usr/local/nagios/libexec/check_mailq : There you can find a variable called
"$mailq = 'sendmail'; # default". I have changed it to postfix. But it didnt resolve the issue.
--> /usr/local/nagios/libexec/utils.pm : There you can find a varialbe called $PATH_TO_MAILQ = "/usr/bin/mailq";
This is also correct. That can checked by issue /usr/bin/mailq and it will show the actual mailq
--> /usr/local/nagios/etc/nrpe.cfg : There you set check_mailq parameteres
/usr/local/nagios/libexec/check_mailq -w 100 -c 200
Run the below command independantly in the mail server
--> /usr/local/nagios/libexec/check_mailq -w 100 -c 200
But it issues the Mail queue empty though there are several mails in the queue.
Then I issued the above command with the mail deamon option as below
--> /usr/local/nagios/libexec/check_mailq -w 100 -c 200 -M postfix
This will show you the correct mail queue and then I chaged the /usr/local/nagios/etc/nrpe.cfg check_mailq parameter with the -M postfix option.
Issue was sorted.
Note : AS far as I found the postfix does not create mailqueue directory under /var/spool/. It has seperate direcotry in /var/spool/postfix/ which maintain mails in seperate directories such as deferred , bounce , active etc. So this might be the reason the nagion NRPE plugin could not check the mail queue correctly.
Some of the packages cannot updated. Need to take from old packages.
Ubuntu apt-get install propagate error message “ Some of the packages cannot updated. Need to take from old packages. - Ubuntu OS version is old.”
When you get this kind of error message
first you need to backup /etc/apt/souces.list and then follow the
below mention steps.
- vi /etc/apt/sources.list
- Then find the below lines and replace as mention
deb <siteurl> karmic main restricted- replace the <siteurl> with
http://old-releases.ubuntu.com/ubuntu
3.
Once again find
http://security.ubuntu.com/ubuntu
and
replace
with http://old-releases.ubuntu.com/ubuntu 4.
Save the changes and issue the below command. 5.
apt-get
updateThen
install the packages as you wish.Friday, May 17, 2013
SELinux is preventing /sbin/iptables-multi-1.4.7 from read access on the file
Error message :
Check the /var/log/messages to get idea of error
Check the /var/log/messages to get idea of error
=========================================================================
May
12 04:05:40 mail setroubleshoot: SELinux is preventing
/sbin/iptables-multi-1.4.7 from read access on the file . For
complete SELinux messages. run
sealert -l
1a33e373-0b4e-4e1c-8cf7-38636b5acbde
May
12 04:05:40 mail setroubleshoot: SELinux is preventing
/sbin/iptables-multi-1.4.7 from create access on the rawip_socket .
For complete SELinux mes
sages.
run sealert -l c2931169-d03b-4758-92d4-f22275f7f391
May
12 04:05:40 mail setroubleshoot: SELinux is preventing
/sbin/iptables-multi-1.4.7 from create access on the rawip_socket .
For complete SELinux mes
sages.
run sealert -l c2931169-d03b-4758-92d4-f22275f7f391
May
12 04:05:40 mail setroubleshoot: SELinux is preventing
/sbin/iptables-multi-1.4.7 from read access on the file . For
complete SELinux messages. run
sealert -l
1a33e373-0b4e-4e1c-8cf7-38636b5acbde
May
12 04:05:37 mail fail2ban.actions: WARNING [dovecot-pop3imap] Unban
125.19.48.106
May
12 04:05:37 mail fail2ban.actions.action: ERROR iptables -n -L INPUT
| grep -q 'fail2ban-dovecot-pop3imap[ \t]' returned 100
May
12 04:05:37 mail fail2ban.actions.action: ERROR Invariant check
failed. Trying to restore a sane environment
May
12 04:05:37 mail fail2ban.actions.action: ERROR iptables -D INPUT -p
tcp -m multiport --dports pop3,pop3s,imap,imaps -j
fail2ban-dovecot-pop3imap#
012iptables
-F fail2ban-dovecot-pop3imap#012iptables -X fail2ban-dovecot-pop3imap
returned 300
May
12 04:05:37 mail fail2ban.actions.action: ERROR iptables -N
fail2ban-dovecot-pop3imap#012iptables -A fail2ban-dovecot-pop3imap -j
RETURN#012iptabl
es
-I INPUT -p tcp -m multiport --dports pop3,pop3s,imap,imaps -j
fail2ban-dovecot-pop3imap returned 100
May
12 04:05:37 mail fail2ban.actions.action: ERROR iptables -n -L INPUT
| grep -q 'fail2ban-dovecot-pop3imap[ \t]' returned 100
May
12 04:05:37 mail fail2ban.actions.action: CRITICAL Unable to restore
environment
================================================================================
This error propagate with the Selinux, you can run the below command
to get fully idea about selinux error.
sealert -l 1a33e373-0b4e-4e1c-8cf7-38636b5acbde
Check the audit.log file and find below deined messages.
type=AVC
msg=audit(1368773459.619:3055): avc: denied { read } for pid=6627
comm="iptables"
scontext=unconfined_u:system_r:fail2ban_t:s0
tcontext=system_u:object_r:sysctl_modprobe_t:s0 tclass=file
type=AVC
msg=audit(1368773459.620:3056): avc: denied { create } for
pid=6625 comm="iptables"
scontext=unconfined_u:system_r:fail2ban_t:s0
tcontext=unconfined_u:system_r:fail2ban_t:s0 tclass=rawip_socket
type=AVC
msg=audit(1368773459.620:3057): avc: denied { read } for pid=6625
comm="iptables"
scontext=unconfined_u:system_r:fail2ban_t:s0
tcontext=system_u:object_r:sysctl_modprobe_t:s0 tclass=file
type=AVC
msg=audit(1368773459.622:3058): avc: denied { create } for
pid=6629 comm="iptables"
scontext=unconfined_u:system_r:fail2ban_t:s0
tcontext=unconfined_u:system_r:fail2ban_t:s0
Resolution :
Once I check the context of
/sbin/iptables-multi-1.4.7
it will show the incorrect context as below- ls -lZ
/sbin/iptables-multi-1.4.7
output-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /sbin/iptables-multi-1.4.7
Run
the below command to correct the Selinux contextrestorecon -R -v /sbin/
then
run the ls
-lZ
command which show the correct context-rwxr-xr-x. root root system_u:object_r:iptables_exec_t:s0 /sbin/iptables-multi-1.4.7
Then
restart the fail2ban service.Tuesday, May 14, 2013
Samba Server configuration -CentOS 6.3 with SeLinux
You must installs below packages in
order to configure as samba server
yum
install cups-libs samba samba-common
Initially you must allow firewall to
access to samba server. Below ports should be allowed. In my server I
have used iptables as firewall so below rules will allow the samba
from firewall
-A
INPUT -m state --state NEW -m tcp -p tcp -s 192.168.1.0/24 --dport
137 -j ACCEPT
-A
INPUT -m state --state NEW -m tcp -p tcp -s 192.168.1.0/24 --dport
138 -j ACCEPT
-A
INPUT -m state --state NEW -m tcp -p tcp -s 192.168.1.0/24 --dport
139 -j ACCEPT
-A
INPUT -m state --state NEW -m tcp -p tcp -s 192.168.1.0/24 --dport
445 -j ACCEPT
you can restrict by source IP from
better security.
Then you need to concern about SeLinux
values. Since if you not enable boolean value then even home
directory not be able to share.
setsebool -P samba_enable_home_dirs on
setsebool -P samba_domain_controller on
If you want to share files/directories other than home directories or
standard directory. You should label these files/directories as
samba_share_t. For example if you created the directory
/home/fileserver, you can label the directory and its contents with
the chcon tool.
# chcon -R -t samba_share_t /home/fileserver
# chcon -R -t samba_share_t /home/fileserver
To make this label permanent issue the
below commands.
# semanage fcontext -a -t
samba_share_t ’/home/fileserver(/.*)?’
# restorecon -R -v /home/fileserver
# restorecon -R -v /home/fileserver
There are two booleans that you can set
to allow the sharing of standard directories. If you want to share
any standard directory read/only you can set the boolean
samba_export_all_ro.
# setsebool -P samba_export_all_ro 1
This boolean will allow Samba to read every file on the system.Similarly if you want to share all files and directories via Samba, you set the samba_export_all_rw
# setsebool -P samba_export_all_rw 1
This boolean would allow Samba to read and write every file on your system. So a compromised Samba server would be very dangerous.
# setsebool -P samba_export_all_ro 1
This boolean will allow Samba to read every file on the system.Similarly if you want to share all files and directories via Samba, you set the samba_export_all_rw
# setsebool -P samba_export_all_rw 1
This boolean would allow Samba to read and write every file on your system. So a compromised Samba server would be very dangerous.
for more details please refer below
link :
Then you need to configure the smb.conf
file as you want.
I have configured home and other shared
directories and my configuration file should be as below.
[Common]
comment
= All Users
path
= /home/common
valid
users =@users
force
group = users
create
mask = 0765
directory
mask = 0775
writable
= yes
If you need to enable home directories
that users can read and write to it below entry should be included.
[homes] comment = Home Directories browseable = no valid users = %S writable = yes create mask = 0700 directory mask = 0700
Now add the user to the Samba user database:
smbpasswd -a tomFriday, February 15, 2013
Could not load plugin shared object /usr/lib/openvpn/openvpn-auth-ldap.so
When you start openvpn daemon you
will get below error message( If your OpenVPN server integrated with LDAP). It's quite interesting error message.
PLUGIN_INIT: could
not load plugin shared object /usr/lib/openvpn/openvpn-auth-ldap.so:
/usr/lib/openvpn/openvpn-auth-ldap.so: cannot open shared object
file: No such file or directory
I have try to locate
openvpn-auth-ldap.so library file from VPN server. It was located in
/usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so
So simply I have created soft link to
place where openvpn daemon checking above library by issuing below command.
- ln -s /usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so /usr/lib/openvpn/openvpn-auth-ldap.so
Then start the VPN daemon.
Tuesday, February 12, 2013
Open VPN Error TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity) TLS Error: TLS handshake failed
If you getting error message
continuously you should check below things
- Client and Server date/time
- Client Virus guard or Firewall
- Common name of the CA certificate
- Routing entry of the server.conf
Client and server date and time should
be corrected and same. Then If your client machine having virus
guard then you should disable it and should allowed firewall settings
for VPN connection.
If you getting error continuously,
either your CA certificate common name have space such as “Technical
Division” or incorrect routing pushes to client.
Recreate CA certificate and put common
name without space. Then try to connect to VPN server. But if you
failed then checked the server configuration file.
There you must push the route which
does not include the server IP address.
For ex :
My VPN server IP address 192.168.2.30
If you push below route to client then
TLS error will generate
push "route 192.168.2.0
255.255.255.0" This is confusing entry which will generate TLS
error.
You must push route without except
server IP.
Ex: push "route 192.168.2.0
255.255.255.240"
push "route 192.168.2.33
255.255.255.224"
Like wise you should push route
accordingly. But remember not to push route which include server
IP address.
This solution has
resolved TLS handshake failed for me. Server OS is Cent OS 6.3
Subscribe to:
Posts (Atom)