So after a bit of research and tons of failed attempts, I've discovered that the olives really don't like multicast. Some people have had used a patch to enable it for OSPF on earlier versions of JunOS, but there's nothing for later versions (since these run fine), although MSDP and PIM still don't work.
I had heard about people using gre tunnels, and can confirm that this works. Olives only let you have one of each type of tunnel (due to there being no PIC's installed) so I used an ipip tunnel to connect two routers, got PIM and MSDP working, then gre tunnels to my two ubuntu boxes (as per http://knol.google.com/k/juniper-hacks/gre-tunnel-between-a-linux-host-and/1xqkuq3r2h459/43#).
I can see the routes filling up the MSDP table, dbeacon seems to sense get some sort of communication, but it still looks like multicast traffic isn't being routed properly.... at least it's getting across all the links now
Thursday, June 30, 2011
Friday, June 17, 2011
JunOS Router testbed part 2
My topology has since become quite complicated, so I thought it would be best to draw a picture:
The fourth olive (meant to branch off like olive2 and olive3 with a separate AS number, tap interface and Ubuntu virtual machine) has been left out for simplicity at this stage. The main problem with my original design was that layer 3 separation wasn't enough - multicast skips routers at layer 2 - so I needed to give each box its own tap interface. To go with the diagram, here's the config from olive1 and olive2 (olive3 is basically the same as olive2 - this is an exercise for the reader)Olive 1:
interfaces {
em0 {
unit 0 {
family inet {
address 192.168.2.1/24;
address 192.168.11.1/24;
address 10.1.1.198/8;
}
}
}
lo0 {
unit 0 {
family inet {
address 1.1.1.1/32;
}
}
}
}
routing-options {
autonomous-system 65000;
}
protocols {
bgp {
local-as 65000;
group branch1 {
type external;
export to-branch1;
peer-as 65001;
neighbor 192.168.2.2;
}
group branch2 {
type external;
export to-branch;
peer-as 65002;
neighbor 192.168.2.3;
}
group branch3 {
type external;
export to-branch;
peer-as 65003;
neighbor 192.168.2.4;
}
}
rip {
group gateway {
export gateway-rip;
neighbor em0.0;
}
}
}
policy-options {
policy-statement gateway-rip {
from protocol [ direct bgp ];
then accept;
}
policy-statement to-branch {
from protocol [ direct local ospf bgp static rip ];
then accept;
}
}
Olive 2:
interfaces {
em0 {
unit 0 {
family inet {
address 192.168.2.2/24;
}
}
}
em1 {
unit 0 {
family inet {
address 192.168.12.1/24;
}
}
}
lo0 {
unit 0 {
family inet {
address 1.1.1.2/32;
}
}
}
}
routing-options {
autonomous-system 65001;
}
protocols {
bgp {
local-as 65001;
group olive {
type external;
export to-branch1;
peer-as 65000;
neighbor 192.168.2.1;
}
}
}
policy-options {
policy-statement to-branch1 {
from protocol [ direct local ospf bgp ];
then accept;
}
}
And here's a show route from olive 2
inet.0: 12 destinations, 13 routes (12 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both
0.0.0.0/0 *[BGP/170] 00:31:58, MED 3, localpref 100
AS path: 65000 I
> to 192.168.2.1 via em0.0
1.1.1.1/32 *[BGP/170] 00:31:58, localpref 100
AS path: 65000 I
> to 192.168.2.1 via em0.0
1.1.1.2/32 *[Direct/0] 00:32:02
> via lo0.0
1.1.1.3/32 *[BGP/170] 00:25:00, localpref 100, from 192.168.2.1
AS path: 65000 65002 I
> to 192.168.2.3 via em0.0
10.0.0.0/8 *[BGP/170] 00:31:58, localpref 100
AS path: 65000 I
> to 192.168.2.1 via em0.0
192.168.2.0/24 *[Direct/0] 00:32:02
> via em0.0
[BGP/170] 00:31:58, localpref 100
AS path: 65000 I
> to 192.168.2.1 via em0.0
192.168.2.2/32 *[Local/0] 00:32:02
Local via em0.0
192.168.11.0/24 *[BGP/170] 00:31:58, localpref 100
AS path: 65000 I
> to 192.168.2.1 via em0.0
192.168.12.0/24 *[Direct/0] 00:31:09
> via em1.0
192.168.12.1/32 *[Local/0] 00:31:09
Local via em1.0
192.168.13.0/24 *[BGP/170] 00:25:00, localpref 100, from 192.168.2.1
AS path: 65000 65002 I
> to 192.168.2.3 via em0.0
218.101.61.124/32 *[BGP/170] 00:31:58, MED 2, localpref 100
AS path: 65000 I
> to 192.168.2.1 via em0.0
It's all going well so far - putting each subnet on a different tap interface stops them cheating and using layer 2 for multicast, so now I can start getting PIM-SM set up (IPv4 only for starters)
Router testbed with JunOS olive on Virtualbox
I did an SRX course earlier in the week and we got to use Olive virtual machines to play with what we had learned. I'd tried making my own but got into trouble when actually installing the package, so I took a copy of this olive (8.3) and tried to get it to work at home. The first results were less than ideal - they would run fine without crashing, but setting addresses had to be done on the commandline with ifconfig rather than in the interfaces stanza. Not only this, but routing was totally broken - not even OSPF would work!
I had read that JunOS 9 didn't suffer from this, and tonight I acquired a copy of JunOS 9.6. The upgrade went smoothly (needed a force as the leftover diskspace wasn't enough, but it installed fine) and it automatically picked up the addresses from the interfaces stanza. OSPF worked fine between 4 of them, so the next thing was to use BGP to set up a basic layer 3 topology with 3 routers all with a single peering with the router in the middle.
If you've done JunOS BGP before then you'll know this is trivial - I made my life easier by making the export policy take routes from direct, local and bgp (which means readvertising happens automatically). The point of this testbed was simply to check my connectivity.
It did all work in the end, and now I'm on to part two - testing out multicast. The plan is to get a couple of virtual interfaces on a real machine, set up multicast between the routers, and have each virtual interface on a subnet owned by a different router. They're all connected to the same bridged interface which means the layer 2 topology has everything effectively hanging off the same switch, so this will be successful if I can get multicasts happening between the different subnets. This is somewhat trivial though, and the next step is to get IPv6 connectivity and testbed IPv6 multicast - if it works, then I'll put up some detailed instructions of all the ins and outs!
I had read that JunOS 9 didn't suffer from this, and tonight I acquired a copy of JunOS 9.6. The upgrade went smoothly (needed a force as the leftover diskspace wasn't enough, but it installed fine) and it automatically picked up the addresses from the interfaces stanza. OSPF worked fine between 4 of them, so the next thing was to use BGP to set up a basic layer 3 topology with 3 routers all with a single peering with the router in the middle.
If you've done JunOS BGP before then you'll know this is trivial - I made my life easier by making the export policy take routes from direct, local and bgp (which means readvertising happens automatically). The point of this testbed was simply to check my connectivity.
It did all work in the end, and now I'm on to part two - testing out multicast. The plan is to get a couple of virtual interfaces on a real machine, set up multicast between the routers, and have each virtual interface on a subnet owned by a different router. They're all connected to the same bridged interface which means the layer 2 topology has everything effectively hanging off the same switch, so this will be successful if I can get multicasts happening between the different subnets. This is somewhat trivial though, and the next step is to get IPv6 connectivity and testbed IPv6 multicast - if it works, then I'll put up some detailed instructions of all the ins and outs!
Sunday, May 15, 2011
Tuntap - going down the rabbit hole
Firstly I'd like to begin by apologising if the title makes this sound at all interesting - it drove me completely fucking crazy for most of last week. The issue I had was a packet capture probe which would stream the data elsewhere, but I didn't have the luxury of being able to cache the gigabytes of data it was putting out every minute. I tried using netflow with ntop (since I'd had absolutely no experience with flow analysers) and this gave me a good start, but there was pretty much nothing I could do to manipulate the data apart from a few hall of fame style charts.
The next step was to try snort and set up some rules based on ip ranges (a step ahead of ntop in netflow mode) and then run it through snortalog to make it a bit easier to view, but snort doesn't take data directly from a single port. I tried to dump it from netcat into a named pipe, but snort doesn't read "special" files... The next option was to start playing around with tap interfaces.
The tap and tun interfaces are virtual NICs which you can apparently send data directly to. I had no luck getting this to work - my tap0 didn't give me a /dev/tap0 file to pipe to, so I ended up back at square one... almost. The final key was using tcpreplay to replay from the named pipe to tap0, and then attaching snort to it. It ended up working, but being asynchronous, snort ended up missing half the packets since the system was busy trying to pipe data to this virtual interface that nobody else could read from...
And in the end? We all lived happily ever after. I found the tcpdump filter I wanted, set up tshark to read from the named pipe, and it's all working, all thanks to the almost unusable tuntap interfaces.
The next step was to try snort and set up some rules based on ip ranges (a step ahead of ntop in netflow mode) and then run it through snortalog to make it a bit easier to view, but snort doesn't take data directly from a single port. I tried to dump it from netcat into a named pipe, but snort doesn't read "special" files... The next option was to start playing around with tap interfaces.
The tap and tun interfaces are virtual NICs which you can apparently send data directly to. I had no luck getting this to work - my tap0 didn't give me a /dev/tap0 file to pipe to, so I ended up back at square one... almost. The final key was using tcpreplay to replay from the named pipe to tap0, and then attaching snort to it. It ended up working, but being asynchronous, snort ended up missing half the packets since the system was busy trying to pipe data to this virtual interface that nobody else could read from...
And in the end? We all lived happily ever after. I found the tcpdump filter I wanted, set up tshark to read from the named pipe, and it's all working, all thanks to the almost unusable tuntap interfaces.
Monday, May 9, 2011
Two part network authentication
We've just changed to using two part authentication for google at work, and it seems to do the job well - unintrusive, unless you lose your phone. The idea is simple - retain your current password, but use a second one-time password which is generated by an app on your phone. When you first set it up, you paste a massive password into your phone if you're unlucky enough to not have an iPhone 3GS or higher (with a camera capable of reading the barcode on the screen). This acts as the seed for a random number generator, which is combined with the current time to the nearest minute to generate one-time passwords that can only be predicted if both sides have their time synchronised and share the same password.
This is cool in itself, but after a conversation with one of my colleagues I thought it would be cool to extend it, and combine it with the concept of port knocking.
Port knocking, for those who don't know, is at worst another layer of security through obscurity, but at best is another channel for confirming knowledge of shared secrets. Normal firewalls try to make it difficult for potential hackers by detecting when they scan for open ports (which correspond to network services) and then not confirming or denying whether or not any of the ports are open. Port knocking goes further, by making all ports appear closed, unless the IP attempting to connect to a service has recently queried a list of ports in the correct order (a sort of secret knock if you like).
A traditional port knock is a predictable sequence, which can be easily inspected by routers along the way. To add a further layer of security, setting the TCP sequence number to the value of a hash of the packet combined with a shared secret - thus ensuring a port knock from one IP can't be replayed later from another.
But what if we want to make the sequence itself unpredictable? If we restrict ourself to just 256 ports, and make our port knock sequence 16 ports long, then we can convert the output from a cryptographic hash into a sequence of ports to query. Sharing a secret in advance, and salting this with the current time to the nearest minute allows us to create per-session portknocks. And the icing on the cake? Add the IP to the time as a second salt, allowing the client to perform the portknock in plain sight, and then be allowed access to a totally hidden port.
OR..... we could just use IPSEC AH
Port knocking, for those who don't know, is at worst another layer of security through obscurity, but at best is another channel for confirming knowledge of shared secrets. Normal firewalls try to make it difficult for potential hackers by detecting when they scan for open ports (which correspond to network services) and then not confirming or denying whether or not any of the ports are open. Port knocking goes further, by making all ports appear closed, unless the IP attempting to connect to a service has recently queried a list of ports in the correct order (a sort of secret knock if you like).
A traditional port knock is a predictable sequence, which can be easily inspected by routers along the way. To add a further layer of security, setting the TCP sequence number to the value of a hash of the packet combined with a shared secret - thus ensuring a port knock from one IP can't be replayed later from another.
But what if we want to make the sequence itself unpredictable? If we restrict ourself to just 256 ports, and make our port knock sequence 16 ports long, then we can convert the output from a cryptographic hash into a sequence of ports to query. Sharing a secret in advance, and salting this with the current time to the nearest minute allows us to create per-session portknocks. And the icing on the cake? Add the IP to the time as a second salt, allowing the client to perform the portknock in plain sight, and then be allowed access to a totally hidden port.
OR..... we could just use IPSEC AH
Saturday, April 9, 2011
Server upgrade: day 2
After deleting a few packages that had been installed from the ubuntu stream and were causing major issues, the upgrade somewhat took care of itself. TFTPD-HPA isn't incredibly happy at the moment, but I'll sort that out next time I feel the need to PXE boot anything (there may be a tutorial on exactly how I got BartPE to PXE boot, which would be just a mix of all the information that is already floating around on the internets).
I've already got a working config for the WIDE DHCPv6, so migrating to the ISC version wasn't going to be too difficult - fortunately I found a sweet tutorial which made life easier. Once I'd got my new config set up, all that needed to be changed was /etc/init.d/dhcp with a couple of extra lines
echo -n "Starting DHCPv6 server: "
start-stop-daemon --start --pidfile $DHCPD6PID \
--exec /usr/sbin/dhcpd -- -q -6 -cf /etc/dhcp/dhcpd6.conf $INTERFACES
sleep 2
if [ -f "$DHCPD6PID" ] && ps h `cat "$DHCPD6PID"` >/dev/null; then
echo "dhcpd6."
else
echo "dhcpd6 failed to start - check syslog for diagnostics."
fi
I've already got a working config for the WIDE DHCPv6, so migrating to the ISC version wasn't going to be too difficult - fortunately I found a sweet tutorial which made life easier. Once I'd got my new config set up, all that needed to be changed was /etc/init.d/dhcp with a couple of extra lines
echo -n "Starting DHCPv6 server: "
start-stop-daemon --start --pidfile $DHCPD6PID \
--exec /usr/sbin/dhcpd -- -q -6 -cf /etc/dhcp/dhcpd6.conf $INTERFACES
sleep 2
if [ -f "$DHCPD6PID" ] && ps h `cat "$DHCPD6PID"` >/dev/null; then
echo "dhcpd6."
else
echo "dhcpd6 failed to start - check syslog for diagnostics."
fi
It hasn't crashed yet, and I'm hoping that it will be a bit more resilient than the WIDE package. I'll let you know how my testing goes with all my different operating systems here!
Friday, April 8, 2011
Nagios, DHCPv6, and migrating Debian servers
Migrating debian
I convinced myself I'd keep this updated after I started work, but this was assuming that I'd still have time to play with my server alongside having a real job and trying to maintain some sort of social life. I did however end up a little bit tipsy last Thursday, which prompted me to start migrating my server from it's original 8GB home to the 250GB drive that has been there for the last two years under the name of /usr/bigdisk for obvious reasons.
My first hurdle was underestimating how long it takes to copy 8GB over IDE on an old pentium 4 (on a side note, describing a pentium 4 as old still makes me feel like a bit of a dinosaur given i vividly remember my first 586) so after having unscrewed my case and plugged in the CD-ROM without electrocuting myself, and booting up backtrack (version 2, because 4 is on a dvd, and 3 was a bit shit), I started what I thought was a sensible cp /mnt/sda1 /mnt/sdc2
Fast forward an hour and a half, and ignoring the part where I converted the original partition to ext2 (by deleting the journal) and shrunk it which took about half an hour by itself (and is already adequately documented everywhere else on the internet) and created the new partition (total of 10 seconds work), I got to the stage where I installed grub (after a chroot to /mnt/sdc2 because bt2 only has LILO) and was ready for a reboot, only to find that half of my stuff wouldn't work because EVERYTHING was 755 to root.
This was about the time I decided it was good to go to bed, since I had to get up for work in less than five hours. The next day I did the procedure all over again, except with the help of the -a switch to the cp command (keeps permissions and timestamps the same - don't leave home without it), made sure to set up fstab, set the partitions back to ext3, and set up grub to use the correct partitions. Finally, everything booted, and I was good to go.
Why did I migrate? The drive was only 95% full, and I thought maybe that was why my wide-dhcpv6-server was crashing... but this wasn't the case in the end.
DHCPv6
I'd not had any problems with wide-dhcpv6-server until recently, so I figured a nearly-full hard drive was why it seemed to crash for no reason every second day. This wasn't the case however, and my research showed that the WIDE DHCPv6 project stopped about three years ago. It turns out that the official ISC DHCP server incorporates both now (although they need to run in separate instances), but to install this, I needed to upgrade to squeeze, so once all 2.4GB of packages come down, I'll let you know how this goes for me.
Nagios
We use this at work to keep an eye on the network, and after writing a plugin to report on light levels on SFP's I decided it made sense to install it at home. This helped me track the DHCPv6 problem, but also made it easier to see the moment anything went wrong. It's only a simple setup at the moment, with periodic pings to google through my IPv4 and IPv6 gateways, and checks on the HTTP and DHCP servers, but already I feel like I have a way closer eye on the health of my server.
I convinced myself I'd keep this updated after I started work, but this was assuming that I'd still have time to play with my server alongside having a real job and trying to maintain some sort of social life. I did however end up a little bit tipsy last Thursday, which prompted me to start migrating my server from it's original 8GB home to the 250GB drive that has been there for the last two years under the name of /usr/bigdisk for obvious reasons.
My first hurdle was underestimating how long it takes to copy 8GB over IDE on an old pentium 4 (on a side note, describing a pentium 4 as old still makes me feel like a bit of a dinosaur given i vividly remember my first 586) so after having unscrewed my case and plugged in the CD-ROM without electrocuting myself, and booting up backtrack (version 2, because 4 is on a dvd, and 3 was a bit shit), I started what I thought was a sensible cp /mnt/sda1 /mnt/sdc2
Fast forward an hour and a half, and ignoring the part where I converted the original partition to ext2 (by deleting the journal) and shrunk it which took about half an hour by itself (and is already adequately documented everywhere else on the internet) and created the new partition (total of 10 seconds work), I got to the stage where I installed grub (after a chroot to /mnt/sdc2 because bt2 only has LILO) and was ready for a reboot, only to find that half of my stuff wouldn't work because EVERYTHING was 755 to root.
This was about the time I decided it was good to go to bed, since I had to get up for work in less than five hours. The next day I did the procedure all over again, except with the help of the -a switch to the cp command (keeps permissions and timestamps the same - don't leave home without it), made sure to set up fstab, set the partitions back to ext3, and set up grub to use the correct partitions. Finally, everything booted, and I was good to go.
Why did I migrate? The drive was only 95% full, and I thought maybe that was why my wide-dhcpv6-server was crashing... but this wasn't the case in the end.
DHCPv6
I'd not had any problems with wide-dhcpv6-server until recently, so I figured a nearly-full hard drive was why it seemed to crash for no reason every second day. This wasn't the case however, and my research showed that the WIDE DHCPv6 project stopped about three years ago. It turns out that the official ISC DHCP server incorporates both now (although they need to run in separate instances), but to install this, I needed to upgrade to squeeze, so once all 2.4GB of packages come down, I'll let you know how this goes for me.
Nagios
We use this at work to keep an eye on the network, and after writing a plugin to report on light levels on SFP's I decided it made sense to install it at home. This helped me track the DHCPv6 problem, but also made it easier to see the moment anything went wrong. It's only a simple setup at the moment, with periodic pings to google through my IPv4 and IPv6 gateways, and checks on the HTTP and DHCP servers, but already I feel like I have a way closer eye on the health of my server.
Subscribe to:
Posts (Atom)
