Thursday, October 27, 2011

Linux command to get hardware and system information

Copy and paste the script given below , save on your linux box and then give execute permission . You have to run this script AS ROOT USER

#!/bin/bash

#########################################################################
# #
# Get System Information #
# By Suvabrata Mukherjee #
#Linux command to get hardware info
#########################################################################

echo "System Report" > report.txt
echo "##########################################################################" >> report.txt
echo "HostName" >> report.txt
hostname >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "OS Version" >> report.txt
cat /etc/issue.net >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "Total Memory in GB" >> report.txt
echo `free -g | head -n 2 | tail -n 1 | awk '{print $2}'` >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "Total number of processors" >> report.txt
echo `cat /proc/cpuinfo | grep processor | wc -l` >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "Processor Make " >> report.txt
echo `cat /proc/cpuinfo | grep 'model name' | head -1` >> report.txt
#Linux command to get hardware info
echo "----------------------------------------------------------" >> report.txt
echo "HardDisk Details :" >> report.txt
echo "Number of Harddisk" >> report.txt
echo `/sbin/fdisk -l | grep Disk | wc -l` >> report.txt
echo `/sbin/fdisk -l | grep Disk` >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "Ip Addresses:" >> report.txt
echo `/sbin/ifconfig | grep 'inet addr' | awk '{print $2}'| cut -c6-25` >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "Number of Ethernet Cards" >> report.txt
echo `/sbin/lspci | grep -i ethernet | wc -l` >> report.txt
echo "----------------------------------------------------------" >> report.txt
echo "Server Model and Serial" >> report.txt
echo `/usr/sbin/dmidecode -t system | grep Manufacturer` >> report.txt
echo `/usr/sbin/dmidecode -t system | grep 'Product Name'` >> report.txt
echo ` /usr/sbin/dmidecode -t system | grep 'Serial Number'` >> report.txt
echo "----------------------------------------------------------" >> report.txt
#Linux command to get hardware information
echo "Total DIMM Module available" >> report.txt
echo ` /usr/sbin/dmidecode -t 17 | grep 'Size' | wc -l` >> report.txt
echo "Total DIMM Module free" >> report.txt
echo ` /usr/sbin/dmidecode -t 17 | grep 'Size: No Module Installed' | wc -l` >> report.txt
echo "----------------------------------------------------------" >> report.txt

cat report.txt

# End of Linux command to get hardware information

Thursday, January 28, 2010

vicidial campaign set caller id

To set vicidial campaign set caller id just edit vicidial_extensions.conf
find your outbound dialing pattern and route

for example
##################### USA Calling ###########################
exten => _1XXXXXXXXXX,1,AGI(AGI(agi://127.0.0.1:4577/call_log)
exten => _1XXXXXXXXXX,2,Set(CALLERID(all)=122222222XX <122222222XX>)
exten => _1XXXXXXXXXX,4,Dial(sip/${EXTEN}@sip-provider,30,WtTo)
exten => _1XXXXXXXXXX,5,Hangup
####################################

Wednesday, January 27, 2010

Monitoring MySql replication

This is a sample script to monitor mysql replication
This script should have both master and slave server authentication details

#!/usr/bin/perl -w

use Mysql;
$ENV{MYSQL_UNIX_PORT} = "/tmp/mysql.sock";
# MYSQL CONFIG VARIABLES
$host = "localhost";
$database = "DB-NAME";
$user = "DB-USER";
$pw = "DB-PASS";
$host_master = "192.168.75.70";
$database_master = "DB-NAME";
$user_master = "Monitor";
$pw_master = "DB-PASS";

# PERL MYSQL CONNECT()
$connect = Mysql->connect($host, $database, $user, $pw);

# DEFINE A MySQL QUERY
$myquery = "show slave status";

# EXECUTE THE QUERY FUNCTION
$execute = $connect->query($myquery);
## Tag : Monitoring MySql replication
# FETCHROW ARRAY

@results = $execute->fetchrow();
if ( $results[11] eq "No" || $results[10] eq "No" )
{
open(SENDMAIL, "|/usr/lib/sendmail -oi -t -odq")
or die "Can't fork for sendmail: $!\n";
print SENDMAIL <<"EOF";
From: Monitor
To: Administrator
Cc: Administrator
Subject: DB-NAME DB Replication failed on slave
DB-NAME DB Replication failed
Error No -- $results[18]
Error Details --
Error -- $results[19]
EOF
close(SENDMAIL) or warn "sendmail didn't close nicely";
}
else
{
print "Db replication is good";
}
$connect2 = Mysql->connect($host_master, $database_master, $user_master, $pw_master);
$myquery2 = "show master status";
## Tag : Monitoring MySql replication
# EXECUTE THE QUERY FUNCTION
$execute2 = $connect2->query($myquery2);

# FETCHROW ARRAY

@results2 = $execute2->fetchrow();
if ( $results2[0] eq $results[5] )
{
print "DB in sync";
## Tag : Monitoring MySql replication
}
else
{
open(SENDMAIL, "|/usr/lib/sendmail -oi -t -odq")
or die "Can't fork for sendmail: $!\n";
print SENDMAIL <<"EOF";
From: Monitor
To: Administrator
Cc: Administrator
Subject: DB-NAME DB Replication not in Sync
DB-NAME DB Replication is not in Sync
Master Log File is $results2[0]
where in slave log file is $results[5]
EOF
close(SENDMAIL) or warn "sendmail didn't close nicely";
}


## Tag : Monitoring MySql replication

Friday, June 5, 2009

Creating a self signed certificate for apache - A very quick HowTo

1. generate a private key ( Tag - self signed certificate for apache)
openssl genrsa -des3 -out yourdomain.com.key 1024

2. Generate CSR ( Tag - self signed certificate for apache)
openssl req -new -key yourdomain.com.key -out yourdomain.com.csr

Now enter all details as shown below 

Country Name (2 letter code) [GB]:IN
State or Province Name (full name) [Berkshire]:WB
Locality Name (eg, city) [Newbury]:Kolkata
Organization Name (eg, company) [My Company Ltd]:ABC Co
Organizational Unit Name (eg, section) []:Information Technology
Common Name (eg, your name or your server's hostname) []:www.yourdomain.com
Email Address []:admin@yourdomain.com
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:


3. Remove passphrase ( Tag - self signed certificate for apache)
cp yourdomain.com.key yourdomain.com.key.orig
openssl rsa -in yourdomain.com.key.orig -out yourdomain.com.key

4. generate certificate  ( Tag - self signed certificate for apache)
openssl x509 -req -days 730 -in yourdomain.com.csr -signkey yourdomain.com.key -out yourdomain.com.crt

5. Copy required files
cp server.crt /etc/apache2/conf/ssl.crt
cp server.key /etc/apache2/conf/ssl.key

6: Configuring SSL In Apache( Tag - self signed certificate for apache)

User the SSL Vhosts or in main configuration file 
put 
--------------------------------------------------------------
SSLEngine on
SSLCertificateFile /etc/apache2/conf/ssl.crt
SSLCertificateKeyFile /etc/apache2/conf/ssl.key
SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown
CustomLog logs/ssl_request_log \
   "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
--------------------------------------------------------------
7: Restart Apache ( Tag - self signed certificate for apache)

/etc/init.d/apache2 stop
/etc/init.d/apache2 stop

You are done , now test :)

Thursday, June 4, 2009

Rsync backup - a quick HowTo

This is a quick HowTo for taking backup using rsync utility.
Rsync utility is an open sourec tool used for incremental backup.

Man page of rsync describes all options for rsync utility.

Here we show you some simple command for incremental backup using rsync.

For example we have two Linux servers server1 and server2 and we want to take
incremental backup of server1 "/data" directory to server2 "/backup/data".
In order to do this rsync utility must be installed in both of the servers.

Steps:

1. login to server2 and create the backup directory /backup/data (Tag - Rsync backup)
2. now run the following command from server2  (Tag - Rsync backup)
rsync -avz -e ssh user@server1:/data/ /backup/data/  ( this will fetch files fromm server1 and store it to local(server2) /backup/data)    (Tag - Rsync backup)
3. This will prompt for user password (ssh) - server1    (Tag - Rsync backup)
5. After providing password for user rsync will start syncing files.
6. Once this is done , you can see all files under /data in server1 are also in /backup/data/ in server2              (Tag - Rsync backup)
7. Now to schedule this backup process , you can use cron .   (Tag - Rsync backup)

If you don't want to provide password each time , you can setup password less ssh 
between these two servers.   (Tag - Rsync backup)

Password Less SSH -- quick HowTo

Password less ssh:
This is a quick HowTo for setting up password less ssh.
For example we have two servers server1 and server2 and 
two users user1 in server1 and user2 in server2
Now from server 1 we want tgo password less ssh to server2 
For this we need to follow a few steps 

1. login to as user1 to server1 
2. run "ssh-key-gen -t rsa" from command prompt 
it will provide following out put

Generating public/private rsa key pair.
Enter file in which to save the key (/home/user1/.ssh/id_rsa):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/user1/.ssh/id_rsa.
Your public key has been saved in /home/user1/.ssh/id_rsa.pub.
The key fingerprint is:
f6:61:a8:27:35:cf:4c:6d:13:22:70:cf:4c:c8:a0:23 user1@server1

Now you have private key at /home/user1/.ssh/id_rsa and
public key at /home/user1/.ssh/id_rsa.pub

3. Now we need to copy the content of /home/user1/.ssh/id_rsa.pub file to server2

4. login to server2 using user2 user

5. cd .ssh/

6. copy the entire content of /home/user1/.ssh/id_rsa.pub from server1 and put into authorized_keys
   i.e /home/user2/.ssh/authorized_keys of server2

7. If you already have authorized_keys file with some other keys , then just append to it.

8. Now you can ssh as user1@server to user2@server2 without being promted for password.

Wednesday, June 3, 2009

Nagios Temperature Monitoring

I have written a short nagios plugin for Nagios Temperature Monitoring .
This plugin will work on linux and it will use "mbmon" system utility to trace the system temperature.

Please check that "/usr/bin/mbmon" commad runs successfully in your system.
else install mobmon utility 
-------------Perl Script for Nagios Temperature Monitoring----
#! /usr/bin/perl -w
## Nagios-NRPE check Temperature Status
# Developed by Polo


$result="";
$error=0;
if ($status = `sudo /usr/bin/mbmon -c1 -T 7`)
{
@status = split(/\n/,$status);
$numlines = @status;
$count=0;
while ( $count < $numlines )
{
if ( $status[$count] > 60 )
{
$error = $error +1;
#$result=$result.','.$status[$count];
}
$result=$result.','.$status[$count];
$count++;
}
if ($error > 0)
{
$output= 'TEMPRATURE CRITICAL Status:'.$result."\n";
print $output;
exit 2;
}
else
{
$output= 'TEMPRATURE OK Status:'.$result."\n";
print $output;
exit 0;
}
}
else
{
exit 3;
}

NFS Cluster setup - a Quick HowTo

This is a quick HowTo for NFS Cluster setup.

Required setup (NFS Cluster setup - a Quick HowTo):
(This requirement is as per our assumpsion , you can customise it further as per requirement)
Server1: Debain Linux installed with NFS server and client package with one private ip address
Server2:                               --- same ------

One virtual ip address for fail over.

/data/share partition will be mirrored by DRBD.

Proposed partitions for each NFS servers.

/dev/md0 -- 500 MB /boot (primary, ext3, Bootable flag: on)
/dev/md1 -- 10000 MB / (logical, ext3)
/dev/md2 - Double of RAM swap (logical)
/dev/md3 -- 200 MB un mounted (logical, ext3) (will contain DRBD's meta data) 
/dev/md4 -- 100 GB un mounted (logical, ext3) (will contain the /data/sharedirectory)


Steps (NFS Cluster setup - a Quick HowTo):

After Linux installation 

1. Check all partitions are ok and /dev/md3 and /dev/md4 are un mounted.(Tag - NFS Cluster setup)
2. Install NTP and update time in both servers 
3. Install NF Server - apt-get install nfs-kernel-server. (Tag - NFS Cluster setup)
4. Remove from auto boot 
update-rc.d -f nfs-kernel-server remove (Tag - NFS Cluster setup)
update-rc.d -f nfs-common remove  (Tag - NFS Cluster setup)

5. Edit /etc/exports  (Tag - NFS Cluster setup)
Put /data/share 192.168.1.0/255.255.255.0(rw,no_root_squash,no_all_squash,sync)
6. Install DRBD on both servers (Tag - NFS Cluster setup)
apt-get install kernel-headers-2.6.8-2-386 drbd0.7-module-source drbd0.7-utils
cd /usr/src/  (Tag - NFS Cluster setup)
tar xvfz drbd0.7.tar.gz
cd modules/drbd/drbd
make
make install  (Tag - NFS Cluster setup)

7. Configure on both servers (NFS Cluster setup - a Quick HowTo) (Tag - NFS Cluster setup)

Edit /etc/drbd.conf (Tag - NFS Cluster setup)

resource r0 {

 protocol C;
 incon-degr-cmd "halt -f";

 startup {
    degr-wfc-timeout 120;    # 2 minutes.
  }

  disk {
    on-io-error   detach;
  }

  net {

  }

  syncer {

    rate 10M;

    group 1;

    al-extents 257;
  }

 on server1 {                
   device     /dev/drbd0;       
   disk       /dev/md4;         
   address    192.168.1.xx:7788; 
   meta-disk  /dev/md3[0];      
  }

 on server2 {                
   device    /dev/drbd0;        
   disk      /dev/md4;          
   address   192.168.1.xx:7788; 
   meta-disk /dev/md3[0];       
  }

}



modprobe drbd
drbdadm up all
cat /proc/drbd


11. server1/server2 (NFS Cluster setup - a Quick HowTo): (Tag - NFS Cluster setup)
mkdir /data
server1:
mount -t ext3 /dev/drbd0 /data
mv /var/lib/nfs/ /data/
ln -s /data/nfs/ /var/lib/nfs
mkdir /data/share
umount /data
server2:
rm -fr /var/lib/nfs/
ln -s /data/nfs/ /var/lib/nfs

12. Install and configure Heartbeat (Tag - NFS Cluster setup)
apt-get install heartbeat
edit /etc/heartbeat/ha.cf
logfacility     local0
keepalive 2
#deadtime 30 # USE THIS!!!
deadtime 10
bcast   eth0
node server1 server2

 
edit /etc/heartbeat/haresources   (Tag - NFS Cluster setup)
server1  IPaddr::192.168.1.xx/24/eth0 drbddisk::r0 Filesystem::/dev/drbd0::/data::ext3 nfs-kernel-server

/etc/heartbeat/authkeys    (Tag - NFS Cluster setup)
auth 3
3 md5 somerandomstring

chmod 600 /etc/heartbeat/authkeys  (Tag - NFS Cluster setup)
/etc/init.d/drbd start
/etc/init.d/heartbeat start

Thursday, May 28, 2009

linux network configuration - A Quick Howto

Linux Network configuration files .


One of the linux network configuration part is to setup DNS , to do this you need to edit 
/etc/resolv.conf  -- DNS Configuration in linux

-----
search yourdomain.com
nameserver xxx.xxx.xxx.xxx
nameserver xxx.xxx.xxx.xxx
-----

Secondly you might need to edit the host file 

/etc/hosts
---
127.0.0.1       localhost
---

For fedora and redhat , you can use an easy GUI tool for linux network configuration .
command : /usr/sbin/system-config-network 

After running this command you can simply select the interface to edit and configure 

Also from text mode you can configure linux networking using ifconfig tool like 
/sbin/ifconfig eth0 192.168.75.50 netmask 255.255.255.0 broadcast 192.168.75.255
For debian 
Just edit /etc/network/interfaces 
and put like
-------------------------
# The loopback network interface 
auto lo iface lo inet loopback  
# The primary network interface allow-hotplug eth0 iface eth0 inet static         address 192.168.75.50         netmask 255.255.255.0         network 192.168.75.0         broadcast 192.168.75.255 
----------------------

save and exit , then restart network service ussuing command "/etc/init.d/network restart".

For alias ip configuration just follow the smae steps except assign ip address in virtual interface like eth1:1 , eth1:2..etc.



How to copy a disk - Linux

Here are the steps which shows
How to copy a disk over network .

Copy a disk over network , target machine enter following command:

"nc" utility and "dd" are used to copy a disk over network
nc -l -p 6565 | gzip –dfc | dd of=/dev/hdb

And on source machine.

dd if=/dev/hda | gzip –cf | nc 192.168.75.21 6565

Tuesday, December 9, 2008

Quick Setup SVN with Apache2 on Linux


Step 1. Install Apache2 , if not already installed. (apache2,SVN,Linux)
Step 2. Install libapache2-svn, subversion ,subversion-tools(apache2,SVN,Linux)
If you are using debian try "apt-get install libapache2-svn subversion subversion-tools" or in Redhat/Fedora
try "yum install install libapache2-svn subversion subversion-tools".(apache2,SVN,Linux)
Step 3. Create SVN Repo Directory(apache2,SVN,Linux)
as root user(apache2,SVN,Linux)
mkdir /src (apache2,SVN,Linux)
chown -R ApacheUser /src (apache2,SVN,Linux)
svnadmin create /src/trunk (apache2,SVN,Linux)
Step 3. Now create apache config , put this config (apache2,SVN,Linux)
Under Location directive: (apache2,SVN,Linux)

DAV svn (apache2,SVN,Linux)
SVNPath /src/trunk (apache2,SVN,Linux)
AuthType Basic (apache2,SVN,Linux)
AuthName "SVN Authentication" (apache2,SVN,Linux)
AuthUserFile /etc/apache2/.svn.passwd (apache2,SVN,Linux)
Require valid-user (apache2,SVN,Linux)

Restart apache (apache2,SVN,Linux)

Step 4. Create SVN user (apache2,SVN,Linux)
htpasswd -c -m /etc/apache2/.svn.passwd user
You can add more user later

Step 5. Test you installation (apache2,SVN,Linux)
Open in your browser
http://yourservername/src/trunk

Step 6. If all set then import your files to this SVN Repo (apache2,SVN,Linux)
svn --username user import http://yourservername/src/trunk -m "First Import"

Apache rewrite with cookie value set

Using Apache redirect rule, you can redirect a specific request to another url setting cookie value. (Apache rewrite with cookie)
This will redirect any specific request and sets client cookie with defined values. (Apache rewrite with cookie)

For Example:
RewriteRule ^/abc/ff/(.+) http://www.somedomain.com/abc.php?code=$1 (Apache rewrite with cookie) [CO=DemoCookie:$1:.somedomain.com:100:/]

This will redirect
http://www.somedomain.com/abc/ff/123

to

http://www.somedomain.com/abc.php?code=123

and set cookie at client browser with name DemoCookie , value 123, domain somedomain.com and time set 100. (Apache rewrite with cookie)

Wednesday, December 3, 2008

New features in MySql 5.1

There are several new features added to MySql 5.1 .

Some important items are given below :

1. Table partitioning and sub-portioning as well .
2. FAST execution for ALTER TABLE .
3. Task Scheduler - CREATE EVENT Statement to add task , a good use for DB maintenance activities

Apache Modsecurity with GeoIP blocking country specific traffic

Modsecurity + GeoIP

ModSecurity is a web application firewall that can work either embedded or as a reverse proxy.
It provides protection from a range of attacks against web applications and allows for HTTP
traffic monitoring, logging and real-time analysis.

Requirements:[
To install modsecurity with geop support we need following packages [
1.ModSecurity v2.5 or greater ( Download from http://www.modsecurity.org/)[
2.mod_geoip2 ( Download from http://www.maxmind.com/)[
3.GeoIP-1.4 or greater ( Download from http://www.maxmind.com/) [
Additionaly we need apxs to compile apache modules.
Apache unique_id_module and libxml2 must be installed in the system.
Download GeoLiteCity.dat database file from http://www.maxmind.com/ and place it in
/usr/share/

After installing all these packages, include four files under tour apache configuration directory and include them under main config file (httpd.conf)

1. mod-security.load
LoadFile /usr/local/lib/libxml2.X[[BR]]
LoadModule security2_module /usr/local/lib/apache2/mod_security2.so[[BR]][[BR]]

2. mod_sec.conf[
SecRuleEngine On[
Include //*.conf

3. mod_geoip.load[
LoadModule geoip_module //mod_geoip.so

4. mod_geoip.conf

GeoIPEnable On
GeoIPDBFile /usr//share/GeoLiteCity.dat


Now for modsecurity configuration files visit http://www.gotroot.com/ [[BR]]
A complete set of configuration files can be downloaded from http://downloads.prometheus-group.com/delayed/rules/modsec-2.5-free-latest.tar.gz
Extract all files and move them to // depending on application security
level and available system resource. Including all rule files may slowdown the apache server

Create a file name geo_ip_rules.conf under //
and put for example
SecGeoLookupDb /usr/share/GeoLiteCity.dat
SecRule REMOTE_ADDR "@geoLookup" "chain,drop,msg:'COUNTRY IP address'
SecRule GEO:COUNTRY_CODE "@streq " "t:none"

This configuration will block all ipaddress from mentioned country.
As per requirement we can change this country code.

After all these installation and configuration we need to restart the apache server to take effect.

We can monitor the apache error.log for mod geoip ip address blocking.

Apache DOS Attack

Prevent DOS attacks, specially for your Apache web server is not very easy !! or really easy

Mod-Evasive is the most common solution to this problem , but it seems for user feedback that it does not work properly or very difficult to configure as per your server need.

Another very helpful solution is (D)Dos-Deflate script which is really effective .
A lot of people are using it to prevent their sites from DOS attacks .

http://deflate.medialayer.com/

Quick InnoDB Tuning Guide

InnoDB performance depends on a list of things including your hard drive speed and raid controller performance .

In brief there are some major tuning directives , which can improve InnoDB performance.

1. innodb_log_flush_at_trx_commit - If you set it to 0 , InnoDB does not flush each commit to Disk rather it would flush after ter one second , If you are running non financial site and can afford to loss 1-2 seconds data loss incase of failure , this trick will work good

2. innodb_flush_method -- the default method work well for innodb

3. Check if the version of mysql is tested against your operating system.

Also you need to set
innodb_buffer_pool_size
innodb_additional_mem_pool_size
innodb_thread_concurrency
innodb_log_file_size
innodb_log_buffer_size
innodb_flush_log_at_trx_commit
innodb_file_per_table

options as per your database server hardware environment and need to tune it perfectly for optimize innodb performance.

Please don't tests these options on your production environment , unless you are 100% sure about your changes and after effects

Quick Setup -- NRPE for NAGIOS in debian

You can use a simple script for this .
Please change this script as per your environment .

This script is for debian users only , Others can use it after some modification.
(Setup NRPE NAGIOS)
########################################
# NRPE INSTALLATION (Setup NRPE NAGIOS ) (Setup NRPE NAGIOS)
########################################
useradd nagios
groupadd nagios
apt-get -y install xinetd make openssl libssl-dev g++ gcc
wget http://osdn.dl.sourceforge.net/sourcefo ... 4.6.tar.gz
tar xzf nagios-plugins-1.4.6.tar.gz
cd nagios-plugins-1.4.6
./configure
make
make install
chown -R nagios.nagios /usr/local/nagios/
cd ..
wget http://osdn.dl.sourceforge.net/sourcefo ... 2.8.tar.gz
tar xzf nrpe-2.8.tar.gz
cd nrpe-2.8
./configure
make all
make install-plugin
make install-daemon
make install-daemon-config
make install-xinetd
`sed -i 's/127.0.0.1//g' /etc/xinetd.d/nrpe`
cd ..
########################
## edit your nrpe.cfg file if required
(Setup NRPE NAGIOS)
########################

chown -R nagios.nagios /usr/local/nagios/
echo "nrpe 5666/tcp #nrpe" >> /etc/services
/etc/init.d/xinetd restart

(Setup NRPE NAGIOS)

A very quick howto about Linux LVM

First identify the disk part where you want to setup LVM
Secondly you need to install LVM package in your system.

Assuming here
1. /dev/sda10 - disk partition
2. Disk space is 200G
3. mount point is /home

Now follow the commands
pvcreate /dev/sda10
pvscan

vgscan


Create a volume group
vgcreate -s 16M vol_grp_1 /dev/sda10

vgdisplay

lvcreate -l 200G -n lv_1 vol_grp_1
lvdisplay


mke2fs -j /dev/vol_grp_1/lv_1

mount /dev/vol_grp_1/lv_1 /home

add to /etc/fstab

/dev/vol_grp_1/lv_1 /home ext3 defaults 0 2

Quick Setup APF firewall

in your server command prompt
** You need to have iptables installed in your server **

wget http://www.r-fx.ca/downloads/apf-current.tar.gz
tar zxf apf-current.tar.gz
cd apf-x
./install.sh
edit /etc/apf/conf.apf

IFACE_IN="xxx"
IFACE_OUT="xxx" -- replace xxx with internet exposed interface

IFACE_TRUSTED="yyy" -- -- replace xxx with internal network where firewall not applicable ( if available ) .

change
# Common inbound (ingress) TCP ports
IG_TCP_CPORTS="22,80,4443" --- mention the ports that you want to keep open in external interface .

A lot of other directives are there to manipulate your config .

Only basic configs are mentioned here .

then start apf " apf -s" andf test your firewall

If all set just set DEVEL_MODE="0" in conf.apf then
stop apf " apf -f"
and start "apf -s"
:)