বৃহস্পতিবার, ২৮ মার্চ, ২০১৩

URL Redirection, SquidGuard, Squint, Sqstat


URL Redirection by squid.conf  :
-----------------------------------------------------
If I want to redirect URL telnet.com.bd to bol-online.com then edit squid.conf file by following information where 172.30.5.0/24 is src network and redirection for src network.
acl mynet src 172.30.5.0/24
acl badsites dstdomain .telnet.com.bd
deny_info http://bol-online.com mynet
http_reply_access deny badsites mynet
then save the squid.conf file and restart squid daemon. Then try by any browser and put telnet.com.bd to address bar output will be bol-online.com

SquidGuard (Web Filter plugin as URL Redirector used to use blacklists)
--------------------------------------------------------------------------------------------

1.       Install squidguard by Apt-get install squidguard
2.    Install blacklists by wget -c http://www.shallalist.de/Downloads/shallalist.tar.gz
3.    Extract shallalist.tar.gz
4.    Copy your required blacklists sush as porn by cp –avr BL/porn /var/lib/squidguard/db/
5.    Create databases from text files by squidGuard –b –C /var/lib/squidguard/db/porn/domains and squidGuard –b –C /var/lib/squidguard/db/porn/urls
6.    Set the permission for read by squid by chown proxy.proxy –R /var/lib/squidguard/db/
7.    Edit squid.conf file by adding url_rewrite_program /usr/bin/squidGuard
8.    Edit /etc/squid/squidGuard.conf file by adding
dest porn {
       domainlist      porn/domains
      
urllist         porn/urls
}
9.    And update acl section by
acl  {
    default {
              pass  !porn all
 redirect http://
}
           }

10. Reload squid by /etc/init.d/squid reload
11. Verify squid and squidGuard loading by viewing log tail -f /var/log/squid3/cache.log
12.  Verify configuration by echo "http://DOMAIN-NAME-HERE / - - GET" | squidGuard –d or browing restricted site from local.
13. Simply add additional restricted site by same as no 8 and 9 step and creating file , db file etc.


Squint (Squid log analyzer and viewer) installation:
--------------------------------------------------------------------

Prerequisites: Squid proxy server, apach2, php5.
 Download squint.tar.gz from internet.
Extract squint.tar.gz
Enter squint directory
cp squint.pl squint.cron.sh /usr/local/bin
cd /usr/local/bin
vim squint.cron.sh
edit to HTTPDCONF=/etc/apache2/apache.conf
execute “squint.cron.sh init” command
execute “squint.cron.sh all” command
edit crontab file and replace Monday to “1” without quote in the line weekly.
Then browse http:// server ip>/squint

Sqstat (To view realtime active user connections):
-----------------------------------------------------------------


prerequisites:
Active PHP Module in Apache:  a2enmod fcgid

apt-get install libapache2-mod-fcgid php5-cgi
extract sqstat-1.20.tar.gz
cp –r sqstat-1.20 /var/www/
cd /var/www/sqstat-1.20
then rename config.inc.php.defaults to config.inc.php
then edit config.inc.php put DEFINE(“SQSTAT_SHOWLEN”,100);
Make sure chachemgr protocol is allowed from localhost.
Browse http:// server ip>/sqstat-1.20/sqstat.php

সোমবার, ২১ জানুয়ারি, ২০১৩

BGP AFI and SAFI


When BGP peers set up their session between them, they send an OPEN message possibly containing optional parameters.
One optional parameter is capabilities. Possible capabilities are Multiprotocol extensions, route refresh, outbound route filtering (ORF), and so on. When the BGP peers exchange the Multiprotocol extension capability, they exchange AFI and SAFI numbers and thus identify what the other BGP speaker is capable of.
IPv6 in BGP is implementated via Multi-Protocol BGP (MPBGP) (RFC 2283), as is MPLS and VPN’s through two new attributes: MP_UNREACH_NLRI and MP_REACH_NLRI. The first two values in these two attributes contain the Address Family Identifier (AFI) and the Subsequent Address Family Identifier (SAFI).
AFI
Meaning
1
IPv4
2
IPv6
.
SAFI
Meaning
1
Unicast
2
Multicast
3
Unicast and multicast
4
MPLS Label
128
MPLS-labeled VPN
If BGP is carrying IPv4 traffic, AFI equals 1, SAFI equals 1 for Unicast, or SAFI equals 4 for MPLS.
If BGP is carrying IPv6 traffic, AFI equals 2, SAFI equals 1 for Unicast, and SAFI equals 2 for multicast.
This is best seen during BGP session negotiation by using the “debug bgp all” command. Obviously use this command with caution and not on full-feed internet peerings.


In the above output you can clearly see these two BGP peers are capable of supporting IPv4 and IPv6 with Unicast and MPLS/VPN’s, along with Route-Refresh.

মঙ্গলবার, ৩ জুলাই, ২০১২

BGP Attributes


BGP Attributes

BGP attribute is a metric used to describe the
Characteristics of a BGP path. Attributes are contained in update messages passed between BGP peers for advertise routers.

BGP attributes are divided into two types -

a) Well Known         
b) Optional

Well Known attributes are divided into two types -

a) Mandatory           
b) Discretionary

** Mandatory attributes are -

a) AS Path     
b) Next Hop      
c) Origin

** Origin attributes divided into three types -

a) Internal(i)    
b) External(e)  
c) Incomplete(?)

** Discretionary attributes are -

a) Local Preference        
b) Atomic Aggregate

Optional attributes are divided into two types -

a) Transitive               
b) Non Transitive

** Transitive attributes are divided into two types -

a) Aggregator               
b) Community

** Community attributes are -

a) No-export
b) No advertise
c) Internet
d) Local AS.

** Non transitive attributes are -

a) MED (Multi Exit Discriminator).
b) Originator
d) Cluster ID.