Recent Questions - Server Fault |
- Zabbix proxy under error "failed to update local proxy configuration copy"
- I just transfered domain name and now within my .htaccess file I have two codes which seem the same should one be deleted?
- iptables: why are outgoing connections working even though no rules allow it
- Water Vapor inside the Camera Lens of the phone [closed]
- Website domain not working with www but working without www
- DNS Godday for mail and AWS for rest
- How forward only all UDP traffic to OpenVPN tunX interface?
- How to redirect user if direct access image files by browser? [nginx]
- docker health check for disk space not working as intended
- 403 in nginx when accessing a directory
- Unable to connect GCP SQL Instance from GKE cluster
- my emr cluster is being terminated with error after the status is being set to starting
- Nginx websocket reverse proxy remove location
- Local devices aren't reachable via VPN
- mongodb 3.2 cluster database compatibility to mongodb 5.0
- Group Policy Management about:security_mmc
- Problems with setting up bonding on Netplan (Ubuntu server 18.04)
- Percona-Server-shared my.cnf file conflicts with file from package mysql-community-server-5.5
- Domain admin can't edit GPOs on DC
- Painfully slow network when routed through Windows 2012 R2
- Domain shared folder with user restricted subfolders
- Trying to ChrootDirectory an SFTP user to their home directory
- Use Openswan / IPSec on Ubuntu server to connect to existing Openswan VPN - NAT broken
- PHP-FPM with Nginx not Working on port 80
- S/MIME icon missing from OWA
- Windows Server 2008 ARP Cache Poisioning
- Wake on Lan (WOL) stopped working
- Cannot Access new Sharepoint 2013 Collection
- Nginx dynamic upstream configuration / routing
| Zabbix proxy under error "failed to update local proxy configuration copy" Posted: 16 Jan 2022 03:53 AM PST This morning I've installed a Zabbix Proxy on an host and I've seen this message in the error log Moreover I've inspected the What's going on? Updated: My Zabbix server has version 4.0.4 and my Zabbix Proxy has version 5.0.8. |
| Posted: 16 Jan 2022 03:53 AM PST and this one |
| iptables: why are outgoing connections working even though no rules allow it Posted: 16 Jan 2022 03:25 AM PST The INPUT and OUTPUT chain policies are set to DROP. Very few rules allowing only specific traffic between directly cable-connected devices. However, if I temporarily add a cable that goes to the router, why can I initiate outgoing connections and receive answers, like do I have noticed that if I add Secondary question: Is there any risk in using those easy to recognize IP addresses between my internally and directly cable-connected devices? Could packets leak, because those are valid public addresses? |
| Water Vapor inside the Camera Lens of the phone [closed] Posted: 16 Jan 2022 01:08 AM PST Does anyone have the same problem with me? There is water vapor inside the camera lens of my phone. What should I do? Does anyone try to put their phone in the rice bag and can this method worked? |
| Website domain not working with www but working without www Posted: 16 Jan 2022 12:28 AM PST My website is working without www but it is not working with www. I have also added CNAME with www.example.com but still it did not work. and I have also duplicate the entry for the zone's root - e.g., copy the IP address, make a new RR set of type A at 'www', and paste the IP address. But still it is not working. I am using Netlify for hosting. |
| DNS Godday for mail and AWS for rest Posted: 16 Jan 2022 12:35 AM PST I have a Goddady hosting account but for some of my websites I would like to host them in AWS S3. My question is how to set DNS entries in Route53 so that I keep web traffic served from S3 but I point email traffic to Goddady? Thank you |
| How forward only all UDP traffic to OpenVPN tunX interface? Posted: 16 Jan 2022 12:05 AM PST I have client with tun0 interface and tunnel network 10.0.8.0/24 (server IP 10.0.8.1, i can ping this address from client side), i want forward only UDP traffic to that interface, how i can do it? |
| How to redirect user if direct access image files by browser? [nginx] Posted: 16 Jan 2022 01:31 AM PST How do I redirect if a user tries to direct access image files in browser only? I want to keep the ability to embed images with
to
This is my nginx conf Code isn't working cause it's going to |
| docker health check for disk space not working as intended Posted: 16 Jan 2022 02:42 AM PST I've got an nginx container which ends up with a full disk after it's been running for about 10 days. So if a new version of the app isn't released, errors start to occur that look like; This happened over the Christmas break so I thought the ideal situation here is to have the container health check ensure that there is free disk space. I thought I had achieved that with this container setup (but clearly not); How should I check for disk space in the health check? |
| 403 in nginx when accessing a directory Posted: 16 Jan 2022 01:47 AM PST I made a very simple server to test how a URL with folder behaves in nginx. Nginx is running in docker (nginx:latest image). Nginx runs user and this structure: Now I have this issue: I expect to see "Test" when I access |
| Unable to connect GCP SQL Instance from GKE cluster Posted: 16 Jan 2022 01:54 AM PST I have created a vpc-native cluster and I am trying to connect from a pod inside the cluster to a postgres SQL instance with a private IP. I am testing using a basic telnet 5432 command. The connection works fine when I try it from a GCE instance that is in the same VPC. All connectivity tests in GCP are giving me green light so it seems to be a k8s issue. Here is my cluster: Here is how I am testing the connectivity: Here is my network config in terraform: I have already checked the following documentation and articles, but nothing helps: Any help is greatly appreciated ! |
| my emr cluster is being terminated with error after the status is being set to starting Posted: 16 Jan 2022 12:05 AM PST Hi when I create EMR cluster. The status says it is being created but after 58 minutes it throws in error saying I was following the AWS documentation on how to create EMR cluster Create EMR cluster on AWS(Picture from the documentation attached) where did i go wrong? I want to successfully create EMR cluster and attach Jupiter notebook to the cluster. Is there a documentation to successfully create a cluster and make the cluster to run without being terminated after 58 Minutes Please suggest me what has to be done. Thankyou. |
| Nginx websocket reverse proxy remove location Posted: 16 Jan 2022 01:50 AM PST Trying to set up an nginx https reverse proxy to home assistant, this works: But I would like to access it from a non-root url like Any Ideas how I can get this to work? |
| Local devices aren't reachable via VPN Posted: 16 Jan 2022 12:56 AM PST I have a VPN configured on a router (router model is bintec be.ip plus). VPN Connections are successfully established by the clients using IKEv2 (router is reachable via DynDNS). Router's local ip address is 192.168.73.1. One of the local device's ip address is 192.168.73.150. The problem is: sometimes the devices in the local network cannot be reached by the VPN clients. E.g. a ping fails: The router itself is always reachable by the clients: And the local device is always reachable by the router: As it only sometimes fails I doubt it's a firewall issue. As the ping packets from the router to the device succeeds I doubt it's a local network issue. I suspect some kind of routing issue but have absolutely no idea how to proceed with the problem. Any ideas how to investigate further? |
| mongodb 3.2 cluster database compatibility to mongodb 5.0 Posted: 16 Jan 2022 01:59 AM PST We have a mongodb 3.2 production cluster that we need to upgrade to mongodb 5.0. Instead of upgrading in place, we are considering creating a new mongodb 5.0 cluster, export the DB from 3.2, and import the DB into the mongodb 5.0 cluster. Will there be any issues with upgrading this way? What we are uncertain about is whether the database format has changed from version 3.2 to 5.0, and whether the database format conversion is only done during the upgrades from 3.2 -> 3.4 -> 3.6 -> ... Thanks in advance. |
| Group Policy Management about:security_mmc Posted: 16 Jan 2022 01:40 AM PST In Group Policy Management, when I click on an existing GPO, I get an Internet Explorer Enhanced Security Configuration messaged that "about:security_mmc.exe" is not a trusted site. It happens every time I click a different GPO. I read to add this to the trusted site list, which I did. I confirmed it is in the policy when I do gpresult. But I'm still getting this message. Anything else I need to do so this doesn't keep popping up? |
| Problems with setting up bonding on Netplan (Ubuntu server 18.04) Posted: 16 Jan 2022 03:07 AM PST I have a dual port network card that I want to bond both ports and balance the traffic between ports. I want 1 static IP address. I used to ubuntu 16.04 and this worked fine. Im now trying to set up the same thing in netplan and am struggling. My config is below... |
| Percona-Server-shared my.cnf file conflicts with file from package mysql-community-server-5.5 Posted: 16 Jan 2022 01:01 AM PST I'm trying to install Percona Toolkit on the server where there is already
I got the following error:
My setup is:
|
| Domain admin can't edit GPOs on DC Posted: 16 Jan 2022 02:04 AM PST I have come across a weird situation. We have 3 domain controllers, 2 Server 2008 R2 & 1 Server 2008, in our single domain environment. When I login to one of the DCs, let's say DC1, with my domain admin account and access Group Policy Management Console (GPMC), I can't edit any GPOs, and also I can see inaccessible next to few GPOs applied to the domain. However, with the same domain admin, when I access GPMC on another DC, I can see all the GPOs applied to the domain and I can also edit all the GPOs. I have also noticed that under the problematic DC,DC1, I cannot see 2 GPOs at all under the Group Policy Objects node on GPMC. Whereas, I can see them on the other two DCs. I have done a lot of research on this, but so far no luck! Please help! |
| Painfully slow network when routed through Windows 2012 R2 Posted: 16 Jan 2022 01:01 AM PST I have a Windows 2012 R2 server with two network adapters, on-board 1G one for the LAN and a 100M D-Link 530T connected to the internet. Internet Connection Sharing is set up on the latter. Client machines (Win7, WinXP) on the LAN can access the internet, but speedtest behavior is peculiar. If I choose a close speedtest server with small ping (1-10ms) I get almost full downlink utilization on both clients and server, but if I choose a faraway speedtest server (100ms) the server gets 50-70Mbps of download speed but clients hardly get 1Mbps for TCP traffic (UDP seems unaffected). Upload speed is the same, around 30Mbps on client and server. Every time I reboot the server, clients get the full 50-70Mbps for about 2-3 minutes and then slow down to a crawl. Occasionally this happens without a reboot, too, for no visible reason. I don't see abnormal CPU utilization on the server when speedtest is running. Wireshark captures show a lot of dup acks and retransmissions, Copying files from server to client over SMB, I get full 1Gbps. If I connect a Win7 client straight to the internet, I don't observe any slowdown. An older server on which I had WinXP and the same outward-facing D-Link network adapter, using the same wires, also didn't show such behavior, so network adapters, wires etc. aren't likely to be the problem. Please help, I don't want to install XP on my server again! Here's some things I have tried without success:
|
| Domain shared folder with user restricted subfolders Posted: 15 Jan 2022 11:02 PM PST I have a domain running on a virtual windows server 2012 R2. Another virtual servers hosts our file server. To that end I need a shared folder accessible by all domain users. No problem there. However I would now like to restrict the access to the subfolders, and if possible not list those folders if they do not have access to them. In those subfolders they are allowed to do anything they like. Let me illustrate this: We have domain users Alice and Bob, shared folder Z: with subfolders K, L, M. Alice has access to K and L. Bob has access to L and M. Both should have be able to open Z. Alice sees folders K and L, whereas Bob sees folders L and M. If Alice creates something in L, Bob can remove or modify it. I have been messing around with share access, permissions and access-based enumeration, but so far no combination has got me close to what I need. Any suggestions are welcome. Thanks! My biggest problem is probably: How do you give everybody access to the shared folder, but restrict basically all permissions in that folder at the same time (except for viewing the subfolders they should have access to) |
| Trying to ChrootDirectory an SFTP user to their home directory Posted: 15 Jan 2022 11:02 PM PST I have followed a few examples of how to do this, all of them end up with modifying When I do this, I then once it's restarted, I try to SFTP (with filezilla) but I keep getting If i revert the config back to its original state, i can SFTP fine, but then i can browse any directory. Where I need users only in their home directory My default config has this line in it: Which is what i'm replacing with the above details. I only have access to this machine over ssh, although i do have root access. UPDATE After following sam_pan_mariusz's advice it appears to get further, but now I get UPDATE 2 I have also followed Froggiz's advice and changed my config to this: but I get the original Software cased connection abort I monitor UPDATE 3 - Added sshd_config |
| Use Openswan / IPSec on Ubuntu server to connect to existing Openswan VPN - NAT broken Posted: 16 Jan 2022 12:05 AM PST I have an existing Openswan VPN, all working fairly well with Windows, Mac and Phones. [Office 192.168.0.0/24]---[VPN A.B.C.D]----[Internet]---[Home Routers (NAT), Dynamic IPs]----[Workstations] Now I want to run an offsite backup server and connect it to the same VPN, still with a dynamic IP [Office 192.168.0.0/24]---[VPN A.B.C.D]----[Internet]---[Home Router (NAT), Dynamic IP]----[zfsbackup] IPSec seems to negotiate OK, this is the output on the backup side: However when I try to start the connection in xl2tpd this happens: Running packet capture on the machine at this stage shows that nothing is sent over the wire. Something that concerns me is the log output when connecting. This is the Office side log for a windows connection: This is for the backup server (Same network as windows pc above), note the port 1024 ipsec verify shows that pluto is listening on 500 and 4500. I can't find a way to get IPSec to pass through the correct port number. My programmer's guess is that the port isn't being read in from anywhere and it's defaulting to the first assignable userland port. Note that I can reserve 1024 in advance using nc. Office VPN still gets told to use 1024 rather than say 1025. Pluto doesn't complain that 1024 is already in use. I really hope someone can help - Have spent a few hours on this both searching and tweaking. Office config is as follows: Backup server config is: |
| PHP-FPM with Nginx not Working on port 80 Posted: 15 Jan 2022 10:02 PM PST I am trying out nginx on my Ubuntu 14.04 desktop, I have referred to some basic setup articles and have installed the latest Nginx and PHP-FPM from the apt repository. I have nginx working and can get my html pages displayed on the browser, however when I try to call a .php page it downloads the .php file instead of rendering webpage with .php output. I am using the following server definition in the /etc/nginx/sites-available/default : } However now if I change my server definition to listen on port 8080 instead of 80 then the request is passed to php-fpm and a web page is rendered with the php output : |
| Posted: 16 Jan 2022 02:04 AM PST I'm trying to test S/MIME with OWA (Exchange 2010, Outlook 2010). Now my research has told me that the control must be installed first. So as someone with admin rights, open OWA, click on All Option, then Settings then the S/MIME icon and install the contorl. I also know it has to be done in IE, 32 bit. For myself and another freshly created user, it works fine. The icon is there. But I tested it with a third user, and there is no S/MIME icon. It's missing. The fact it's there for 2 accounts says it's enabled in the Outlook Web App Mailbox policies. I even installed it on my account and it works. There is only the default policy, so it can't be the user is assigned to a policy where it's disabled. He's assigned to the same policy as me in any case. So why do the other accounts have the icon, but the one account doesn't? Without the icon, I can't install the control. |
| Windows Server 2008 ARP Cache Poisioning Posted: 15 Jan 2022 11:06 PM PST Recently ran into a very strange problem. Several applications were having issues communication through our F5 Load-Balancer. When we looked into it we found that the router had an incorrect ARP and MAC-ADDRESS table entry on the Load-Balancer VLAN. Those entries were pointing towards a Windows Server 2008 R2 box instead of the Load-Balancers external interface. Now here is the strange thing. The hardware address in the MAC/ARP table entries did not exist on the Windows 2008 Server but it was very close. The Windows Server was on router interface Gi1/37 (below). The Load-Balancer External Address was 192.168.111.61 and the Windows Server was 192.168.111.125. Two totally different IP addresses in the same /24 subnet. IPConfig on Windows Server MAC Info on Windows Box The ARP and MAC ADDRESS entry in the Router The last 4 bits on the hardware address although similar were not existing physical hardware addresses on the Windows 2008 Server. Logic dictates that the Windows Server had to have performed some sort of incorrect gratuitous ARP in order to poison the ARP and MAC table on the router. Or it was responding to an ARP request for an IP that it didn't own and a MAC ADDRESS that it didn't own. The second we shut down the Windows 2008 interface and cleared the ARP/MAC tables the problem was solved. For the life of me i am unable to understand how this happened (or why). |
| Wake on Lan (WOL) stopped working Posted: 15 Jan 2022 10:59 PM PST My wake on lan stopped working for no apaprent reason. I installed wireshark and from another machine sent a magic packet to the target computer and I could see the packet was coming through. Nothing in the BIOS changes, so |
| Cannot Access new Sharepoint 2013 Collection Posted: 16 Jan 2022 12:05 AM PST I just finished installing SharePoint 2013 on our dev machine. I'm in the CA, and I can create new site collections just fine. Problem is, I cannot access them from any account, including the designated collection admin account. I've been going around and around on this, but nothing seems to work, I just get the "Sorry, this site hasn't been shared with you". Anyone know what I causing this? Logging into the CA works fine under any allowable account, and the security settings match for both IIS sites. Access the site collection security page directly works for some reason (.../_layouts/15/settings.aspx), and if I view the site administrator page my account is even listed! Still no dice on access the actual SP collection though. |
| Nginx dynamic upstream configuration / routing Posted: 16 Jan 2022 03:07 AM PST I was experimenting with dynamic upstream configuration for nginx and cant find any good solution to implement upstream configuration from third-party source like redis or mysql. The idea behind it is to have a single file configuration in primary server and proxy requests to various app servers based on environment conditions. Think of dynamic deployments where you have X servers that are running Y workers on different ports. For instance, i create a new app and deploy. App manager selects a server and then rolls out a worker (Ruby/PHP/Python) and then reports the ip:port to the central database with status "up". At this time when i go to the given url nginx should proxy all requests to the specified ip:port upstream. The whole thing is pretty similar to what heroku does, except this proof-of-concept is not supposed to be production ready, mostly for internal needs. The easiest solution i found was using resolver with ruby-based DNS server. It works, nginx gets the IP address correctly, but the only problem is that you cant define port number for that IP. Second solution (which i havent tried yet) is to roll something else as a proxy server, maybe written in Erlang. In this case we need to use something to serve static content. Any ideas how to implement this in more flexible and stable way? P.S. Some research options: |
| You are subscribed to email updates from Recent Questions - Server Fault. To stop receiving these emails, you may unsubscribe now. | Email delivery powered by Google |
| Google, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | |



No comments:
Post a Comment