Posts

Showing posts with the label Computer Network

Sharing OpenVPN connection in Windows 11 with other connections

Open "Control Panel" (by typing "Control Panel" in the Windows search bar and select it). Select "Network and Internet" -> "Network and Sharing Center" -> "Change adapter settings". Right click on the "Local Area Connection" with description similar to "TAP-Windows Adapter V9 for OpenVPN Connect". Under the "Sharing" tab, check "Allow other network users to connect through this computer's Internet connection". In the pull-down menu, select the network that is allowed. Done.

Set up a OpenVPN access server with free resources on Oracle Cloud Infrastructure

Image
A easier approach of setting the whole thing up https://blogs.oracle.com/developers/post/launching-your-own-free-private-vpn-in-the-oracle-cloud#:~:text=Launching%20Your%20Own%20Free%20Private%20VPN%20In%20The,5%20Testing%20The%20VPN%20...%206%20Summary%20 Apply for a free Oracle Cloud free tier Sign up at https://www.oracle.com/cloud/free/ When asked to select a region, pick up that states "always free". After you sign up, sign in at https://www.oracle.com/cloud/sign-in.html Create a new virtual machine instance After log in, click on the hamburger icon on the top left. Then select "Compute" -> "Instances". Click on the "Create Instance" button. In the subsequent screen, name the virtual machine, select an image (recommend: Ubuntu 16.04), select a shape (select a always free one if needed), upload your ssh public key. Then click the "Create" button to create the VM. In the next page, wait until you see the publ...

TCP congestion windows

TCP congestion window: Where in tcpdump to look for window size and scale https://osqa-ask.wireshark.org/questions/27648/how-can-i-get-congestion-window-from-traces https://support.citrix.com/article/CTX113656 https://networklessons.com/cisco/ccie-routing-switching-written/tcp-window-size-scaling iperf and TCP window size https://kb.wisc.edu/uwsysnet/41705 General tcpdump info https://hackertarget.com/tcpdump-examples/ https://www.comparitech.com/net-admin/how-to-use-wireshark/

MTU

There is kind of a work around to detect MTU problems with TCP using ICMP as a base: http://en.wikipedia.org/wiki/Path_MTU_Discovery PMTU. The caveats are: it doesn't work with UDP, and some scenarios with ICMP being blocked or old operating systems, and some interoperability/network topology situation The problem comes when you want to send more data over this connection - lets say you wanted to send 3000 bytes: your computer would split this up based on your MTU - in this case, two packets of 1500 bytes each, and send them to your ADSL modem which would then split them up so that it can fulfill its MTU. Now your 3000 byte data has been fragmented into four packets: two with a payload of 1492 bytes and two with a payload of 8 bytes. This is obviously inefficient, we really only need three packets to send this data. Had your computer been configured with the correct MTU for the network, it would have sent this as three packets in the first place (two 1492 byte...

Network issue resources

ntpdate[24246]: no server suitable for synchronization found http://askubuntu.com/questions/429306/ntpdate-no-server-suitable-for-synchronization-found http://serverfault.com/questions/277375/ntpdate-d-server-dropped-strata-too-high Juniper specific issues With Juniper: https://kb.juniper.net/InfoCenter/index?page=content&id=KB15756&actp=search Set date/time in Juniper: http://www.juniper.net/documentation/en_US/junos/topics/task/operational/junos-time-date-setting.html NTP setup in Juniper: http://www.juniper.net/documentation/en_US/junos/topics/task/configuration/network-time-protocol-configuring.html NTP debugging with Juniper: https://kb.juniper.net/InfoCenter/index?page=content&id=KB15756&actp=search Juniper LAG creation error: xSTP configuration disallowed on interface http://www.juniperforum.com/index.php?topic=27731.0

iptables pocket reference

iptables -L lists all rules  iptables -S [chain] shows the commands that build the rules of the chain. iptables -D [rule index or rule details] deletes a particular chain. NAT iptables -L -t nat lists all NAT rules. Replace source private IP to a public one, then when reply comes back, replace the associated destination public IP back to the private one. iptables -t nat -A POSTROUTING -s 192.168.128.4 -j SNAT --to-source 10.247.65.43 iptables -t nat -A PREROUTNG -d 10.247.65.43/32 -j DNAT --to-destination 192.168.128.4 Replacing rules iptables -R INPUT 1 -p tcp -s 192.168.0.0/24 --dport 80 -j ACCEPT Save modified iptables service iptables save Reference Reference 2

Use squid to track http requests of machines in your LAN

The key is to set up a squid server on a Linux machine, and then have other machines use that squid server as the network proxy. Procedures (for squid installed on Ubuntu) sudo apt-get install squid3 Edit /etc/squid/squid.conf . Make sure you have uncomment the following acl lines: acl localhost src 127.0.0.1/32 acl localnet src 192.168.2.0/24 (Replace 192.168.2.0/24 with the subnet of your LAN)  Make sure you have uncomment the following http_access lines: http_access allow localnet http_access allow localhost service squid restart . By default the server uses port 3128. Set other machines to use that squid3 server as the network proxy. Browse /var/log/squid/access.log to check the http requests. To make your proxy server cache nothing, follow the instruction at here . For instance, add the following line in /etc/squid/squid.conf . cache deny all

Network for VM under proxy environment

Use bridge networking mode rather than the default NAT. Then the VM is like an additional machine in the local network, and its proxy setting can be configured as any other machine in the network. Reference