Old Tomato
From Nuclear Physics Group Documentation Pages
Jump to navigationJump to searchGeneral Information
Okra is the monitoring server. Uses Cacti to do the monitoring, which currently operates questionably.
Hostnames: okra.unh.edu
, okra.farm.physics.unh.edu
Network Configuration
Currently has ethernet cable to switch, accessing outside world via the VLAN functions of the switch.
/etc/sysconfig/network-scripts/ifcfg-farm
# Realtek|RTL-8169 Gigabit Ethernet HWADDR=00:09:5B:BC:EC:C9 DEVICE=eth0 BOOTPROTO=none IPADDR=10.0.0.246 NETMASK=255.255.255.0 ONBOOT=yes TYPE=Ethernet USERCTL=no PEERDNS=yes IPV6INIT=no
/etc/sysconfig/network-scripts/ifcfg-unh
# UNH network VLAN=yes DEVICE=eth0.2 BOOTPROTO=none BROADCAST=132.177.91.255 IPADDR=132.177.88.73 NETMASK=255.255.252.0 NETWORK=132.177.88.0 ONBOOT=yes REORDER_HDR=no GATEWAY=132.177.88.1 TYPE=Ethernet USERCTL=no PEERDNS=yes IPV6INIT=no
/etc/sysconfig/network-scripts/ifcfg-lo
DEVICE=lo IPADDR=127.0.0.1 NETMASK=255.0.0.0 NETWORK=127.0.0.0 # If you're having problems with gated making 127.0.0.0/8 a martian, # you can change this to something else (255.255.255.255, for example) BROADCAST=127.255.255.255 ONBOOT=yes NAME=loopback
Access Configuration
/etc/security/access.conf
# NPG Config: # Allow direct root logins only from console and einstein + : root : LOCAL einstein.unh.edu einstein.farm.physics.unh.edu lentil.unh.edu lentil.farm.physics.unh.edu # Allow only NPG users and administrators - : ALL EXCEPT npg domain_admins : ALL
Backup Configuration
/etc/rsync-backup.conf
# Backups are 'pull' only. Too bad there isn't a better way to enforce this. read only = yes # Oh for the ability to retain CAP_DAC_READ_SEARCH, and no other. #uid = root # XXX There seems to be an obscure bug with pam_ldap and rsync whereby # getpwnam(3) segfaults when (and only when) archiving /etc. Using a numeric # uid avoids this bug. Only verified on Fedora Core 2. uid = 0 # There's not much point in putting the superuser in a chroot jail # use chroot = yes # This isn't really an effective "lock" per se, since the value is per-module, # but there really ought never be more than one, and it would at least # ensure serialized backups. max connections = 1 [usr_local] path = /usr/local comment = unpackaged software [opt] path = /opt comment = unpackaged software [etc] path = /etc comment = conf files [var] path = /var comment = user and system storage