顯示具有 網路 標籤的文章。 顯示所有文章
顯示具有 網路 標籤的文章。 顯示所有文章

2026年10月5日 星期一

BreeBSD Bridge 筆記

ifconfig bridge create name vmbr0
ifconfig vmbr0 addm igb0
ifconfig vmbr0 up

sysrc cloned_interfaces+="bridge0"
sysrc ifconfig_bridge0_name="vmbr0"
sysrc ifconfig_vmbr0="addm igb0 up"

ifconfig vmbr0
ifconfig vmbr0 deletem igb0
ifconfig vmbr0 down
ifconfig vmbr0 destroy

sysrc cloned_interfaces-="bridge0"
sysrc -x ifconfig_bridge0_name
sysrc -x ifconfig_vmbr0

2026年9月14日 星期一

Apache2 設定編碼方式

編輯  /etc/apache2/conf-available/charset.conf 加入
AddDefaultCharset UTF-8

編輯 .htaccess
AddDefaultCharset UTF-8
AddType 'text/html; charset=UTF-8' .html .htm
AddType 'application/json; charset=UTF-8' .json




2026年8月25日 星期二

LEAF Shorewall NAT LOOPBACK 範例

編輯 /etc/shorewall/interfaces 增加 routeback
net             eth0                    dhcp
loc             eth1                    dhcp,routeback

編輯 /etc/shorewall/nat
100.109.54.55   eth0            192.168.9.55    Yes             No

編輯/etc/shorewall/snat
MASQUERADE     192.168.9.0/24 eth1 

編輯  /etc/shorewall/rules
SSH(ACCEPT)     net:100.109.54.0/24  loc:192.168.9.55
#DNAT       net      loc:192.168.9.55:22   tcp     22   -   100.109.54.55
#DNAT       loc      loc:192.168.9.55      tcp     22   -   100.109.54.55

Nginx Reverse Proxy 設定範例

 server {
 listen 80 ;
 listen [::]:80 ;

    server_name 192.168.26.162;
    set $backend_librenms "http://192.168.255.1";
    location / {
        # 注意:目標網址結尾「不要」加斜線 /
        # 這樣存取 /ipam/xxx 時,會自動轉發至 http://hostname2/ipam/xxx
        proxy_pass $backend_librenms;
        # 傳送原始請求標頭
        proxy_set_header Host $http_host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # 處理後端發出的 301/302 重導向(將 hostname2 替換為 hostname1)
        proxy_redirect $backend_librenms $http_host;

        # 停用快取與調整超時限制(適合 phpIPAM / NetBox 等管理工具)
        proxy_buffering off;
        proxy_read_timeout 90;
    }

    set $backend_ipam "http://192.168.255.2";
    location /ipam {
        # 注意:目標網址結尾「不要」加斜線 /
        # 這樣存取 /ipam/xxx 時,會自動轉發至 http://hostname2/ipam/xxx
        proxy_pass $backend_ipam;

        # 傳送原始請求標頭
        proxy_set_header Host $http_host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # 處理後端發出的 301/302 重導向(將 hostname2 替換為 hostname1)
        proxy_redirect $backend_ipam $http_host;

        # 停用快取與調整超時限制(適合 phpIPAM / NetBox 等管理工具)
        proxy_buffering off;
        proxy_read_timeout 90;
    }
}

2026年7月28日 星期二

IDs assigned but not accepted

#Nginx 設定
http {
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
ssl_session_tickets on;
}

測試
openssl s_client -connect host:443 -reconnect -state

HSTS(Strict Transport Security)

#Nginx 設定
server {
    listen 443 ssl http2;
    server_name example.com;
    # 啟用 HSTS(建議維持至少 1 年 = 31536000 秒)
    # includeSubDomains: 套用至所有子網域
    # preload: 允許加入瀏覽器預載清單
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
}

#Apache2 設定
<VirtualHost *:443>
    ServerName example.com   
    # 啟用 HSTS
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
</VirtualHost>

測試
chrome://net-internals/#hsts
curl -I https://127.0.0.1
Plaintext
HTTP/2 200
...
strict-transport-security: max-age=31536000; includeSubDomains; preload
...

Qualys SSL Labs(權威檢測)
網址:https://www.ssllabs.com/ssltest/

HSTS Preload 狀態檢查
網址:https://hstspreload.org/

2026年7月17日 星期五

IPMI 網路 dhcp 重新取得 IP

 ipmitool lan set 1 ipsrc static && ipmitool lan set 1 ipsrc dhcp

2026年6月16日 星期二

Linux 使用 tc 將 eth0 封包 mirror 至eth1

清除 eth1 IP 設定混雜模式
sudo ip addr flush dev eth1
sudo ip link set dev eth1 up
sudo ip link set dev eth1 promisc on

設定 tc eth0 進入規則
sudo tc qdisc add dev eth0 handle ffff: ingress
sudo tc filter add dev eth0 parent ffff: protocol all u32 match u32 0 0 action mirred egress mirror dev eth1

設定 tc eth0 流出規則
sudo tc qdisc add dev eth0 root handle 1: prio
sudo tc filter add dev eth0 parent 1: protocol all u32 match u32 0 0 action mirred egress mirror dev eth1

檢查 tc 規則
sudo tc filter show dev eth0 ingress
sudo tc filter show dev eth0 parent 1:

刪除 tc 規則
sudo tc qdisc del dev eth0 handle ffff: ingress
sudo tc qdisc del dev eth0 root

關閉 eth1 的混雜模式
sudo ip link set dev eth1 promisc off

相關 module 
 ifb act_mirred

2026年6月12日 星期五

wireguard 日誌記錄

 #!/bin/bash
LOG_FILE=/home/WGlog/202606
TIMESTAMP=$(date "+%Y-%m-%d %H:%M:%S")

echo "=== Log entry at $TIMESTAMP ===" >> $LOG_FILE
# 抓取介面、Peer ID、端點 IP 以及最後交握時間

wg show all dump | awk 'NF>1 {print TIMESTAMP, $1, $2, $4, $5}' TIMESTAMP="$TIMESTAMP" >>$LOG_FILE

echo "" >> $LOG_FILE

LEAF設定 WireGuard

編輯 leaf.cfg加入
wireguard

編輯 /etc/modules 加入
wireguard

編輯  /etc/shorewall/interfaces 加入
wg0    wg0     tcpflags,nosmurfs,routefilter,routeback

編輯  /etc/shorewall/zones 加入
wg0             ipv4

編輯 /etc/shorewall/rules 加入
ACCEPT    net                     fw      UDP 51820
ACCEPT    wg0:192.168.226.1       wg0     TCP 22
ACCEPT    wg0     wg0:192.168.226.1       TCP 4119,4120,4122,22
DROP         wg0                     wg0     all
Ping(ACCEPT)    wg0                     fw

產生 設定檔
#!/bin/sh
nodenum=20

spri=$(wg genkey); spub=$(echo $spri|wg pubkey)

# wireguard server
Endpoint=192.168.228.2:51820

# configure file
wg0conf=wg0.conf-
client=client.conf-

:>${client}
cat <<EOF0 >$wg0conf
#pri=${spri}
#pub=${spub}
[Interface]
Address = 192.168.226.253/24
ListenPort = 51820
PrivateKey = ${spri}

EOF0

for i in `seq 1 $nodenum`;do
pri=$(wg genkey); pub=$(echo $pri|wg pubkey)

cat <<EOF >>$client
## node $i ##############################################
[Interface]
PrivateKey = ${pri}
Address = 192.168.226.${i}/24

[Peer]
PublicKey = $spub
AllowedIPs = 192.168.226.0/24
Endpoint = ${Endpoint}
PersistentKeepalive = 25

EOF

cat <<EOF0 >>$wg0conf
## node $i ##############################################
[Peer]
PublicKey = ${pub}
AllowedIPs = 192.168.226.$i/32

EOF0

done

2026年5月13日 星期三

Debian13 使用 pptp

apt install pptp-linux
apt install network-manager-pptp-gnome

2026年4月7日 星期二

Debian 13 更改網路卡別名

編輯  /etc/systemd/network/10-eth1.link

[Match]
MACAddress=00:11:22:33:44:55

[Link]
Name=eth1

方法二 UDEV設定方式
編輯 /etc/udev/rules.d/10-rename-it.rules
SUBSYSTEM=="net", ACTION=="add", ATTR{address}=="00:11:22:33:44:55", NAME="eth1"
Debian 網路命名規則通常在開機 initramfs 階段就決定,須更新 initramfs
update-initramfs -u

2026年3月25日 星期三

Shorewall Hairpin NAT 或 NAT Loopback 設定方式

fw  eth0:192.168.119.253/24
ap  eth2:192.168.119.231/24:3142

編輯 /etc/shorewall/interfaces
增加 內網介面  routeback 選項( Shorewall 會丟棄在同一個介面「進又出」的封包)
loc             eth2                    dhcp,routeback

編輯 /etc/shorewall/snat  (偽裝來源,讓伺服器以為是「防火牆」在找它)
SNAT(192.168.119.253)   192.168.119.0/24 eth2 tcp 3142 -

編輯/etc/shoreall/rule (定義轉發:當內網存取fw ,目標轉向伺服器)
DNAT:NFLOG(4) loc    loc:192.168.119.231 tcp 3142 - -

2026年3月9日 星期一

取代 netstat-nat 指令

[ -f /proc/net/nf_conntrack ]&& cat  /proc/net/nf_conntrack
[ -f /proc/net/ip_conntrack ]&& cat /proc/net/ip_conntrack

相關模組
nf_conntrack
ip_conntrack (2.6.24 核心之前)

查詢目前連線數:
cat /proc/sys/net/netfilter/nf_conntrack_count

查看連線數上限:
sysctl net.netfilter.nf_conntrack_max

Dnsmasq DNS 查詢增加黑名單

 #!/bin/sh
# adblockMY.sh 

urls="donate.ssl.xmrig.com "

conf=/etc/dnsmasq.d/adblockMY.conf
for url in $urls;do echo server=/${url}/;done >${conf};

/etc/init.d/dnsmasq restart
leaf119x# 

Dnsmasq DNS 查詢增加黑名單 (pgl.yoyo.org)

#!/bin/sh
# adblock.sh

url=https://pgl.yoyo.org/as/serverlist.php?hostformat=dnsmasq-server;showintro=0
conf=/etc/dnsmasq.d/adblock.conf
tmp=${conf}.tmp

wget --no-check-certificate "${url}" -q -O ${tmp}
[ $? -gt 0 ]&&exit $?;

cat ${tmp}|grep server= >${conf} 
[ -f "${tmp}" ]&&rm ${tmp};
dnsmasq -C ${conf} --test && /etc/init.d/dnsmasq restart || rm ${conf}; 

Dnsmasq DNS 查詢增加黑名單 (filter.futa.gg)

 #!/bin/sh
# adblockFutaGuard.sh 
# https://github.com/FutaGuard/LowTechFilter?tab=readme-ov-file

#
urls="https://filter.futa.gg/hosts_domains.txt"
urls="$urls https://filter.futa.gg/TW165_domains.txt"
urls="$urls https://filter.futa.gg/TWNIC-RPZ_domains.txt"
urls="$urls https://filter.futa.gg/nofarm_domains.txt"
urls="$urls https://filter.futa.gg/nrd/past-01day_domains.txt"

for url in $urls;do
conf=/etc/dnsmasq.d/adblock$(basename $url|awk -F . '{print $1}').conf
tmp=${conf}.tmp
wget --no-check-certificate "${url}" -q -O ${tmp}
[ $? -gt 0 ]&& { [ -f "${tmp}" ]&&rm ${tmp}; continue; };                                                

cat ${tmp}|awk '{print "server=/"$1"/"}' >${conf}
[ -f "${tmp}" ]&&rm $tmp;
dnsmasq -C ${conf} --test || rm ${conf};
done

/etc/init.d/dnsmasq restart; 

2026年2月6日 星期五

2026年1月6日 星期二

NFS Client 錯誤訊息

open pipe file /run/rpc_pipefs/nfs/blocklayout failed: No such file or directory

停用不必要的 pNFS 服務,一般的 NFS 掛載(非高效能並行檔案系統),關閉這個報錯的服務,不會影響正常的 NFS 掛載

systemctl stop nfs-blkmap
systemctl disable nfs-blkmap
systemctl mask nfs-blkmap

Quanta IX8D 摘要

Quanta IX8D - 48x25G SFP 8x100G QSFP, Runtime Code 22.06, Linux 4.14.4, 2017.11.00.12
Machine Type   Quanta IX8D - 48x25G SFP 8x100G QSFP
Machine Model  IX8D
Software Version 22.06
Manufacturer Name QSMC
Software Storage mSATA
Operating System Linux 4.14.4
Network Processing Device BCM56873_A0

sudo qnos-console (admin / password)
/etc/debian_version
buster/sid

連線設定
Bps/Par/Bits       : 115200 8N1                                |
Hardware Flow Control : No                                        |
Software Flow Control : No