Categories

Bluetrait
        Bluetrait
                Bluetrait
                    Coding
                    Geek
                    General
                    Videos
                    Solar
                    Coding
                    Geek
                    General
                    Coding
                        PHP
                        Bluetrait
                        PHP
                        Bluetrait
                        WordPress
                            Plugins
                        PHP
                        Bluetrait (Program)
                    Geek
                        Juniper
                        Cisco
                        IBM N2200 8363
                        PCs
                        Spam
                        IPv6
                        Apple
                        NetScreen
                        Internet
                    General
                        Uni

Mon, 08 Jan 2007 10:30 PM

Seagate Drives

Michael Dale
I had another Seagate drive die on me. I'm not going to be buying that brand from now on, pity I thought they were pretty good.


Any recommendations?

Wed, 03 Jan 2007 3:33 PM

Bluetrait Wish List

Michael Dale
Things I'd like to add:
  • gettext

  • better plugin support (add_task, update checker, bluetrait version checking)

  • categories

  • upgrades to event management

  • upgrades to spam system

  • full UTF-8

  • per-user time zone support

  • caching

  • faster/smaller


Fri, 29 Dec 2006 12:25 PM

Laptop

Michael Dale
Got my laptop back. Much quicker than expected!

Looks like they've replaced the keyboard, the whole top of the laptop and the battery! Awesome.

Wed, 27 Dec 2006 5:05 PM

Reminder for when I move again...

Michael Dale
Details I need to update:
  • Three (Mobile)

  • UTS

  • ING

  • Commonwealth Bank

  • Joker.com (Domains)

  • License

  • Atomic

  • MLC (Super)

  • Electoral Roll

  • Anything else!?!


Tue, 26 Dec 2006 8:52 PM

Macbook Battery

Michael Dale
Looks like the battery on my Macbook has died. I'm going to take it in tomorrow to get replaced.
Dead Macbook battery

Sat, 23 Dec 2006 10:38 PM

Setting up the Secondary IP option on a netscreen with a PPPoE connection.

Michael Dale
The following howto will show you how to setup an extra subnet connected to a Netscreen.

Background Info:
  1. Static IP address (202.129.82.126) on ethernet3

  2. /30 Subnet (202.129.82.192/30)

  3. 10.0.0.0/22 Internal Network on ethernet1

  4. Netscreen 5GT running ScreenOS 5.4.0r2 in Dual Untrust mode

  5. PPPoE connection

  6. Router address on 10.0.0.254


Adding an extra subnet gives us the option to run servers on separate IP addresses and bypass the Netscreen's limitation of range port forwarding.


Now what I've done for our connection is attach the extra subnet to our trust interface, the plan being that both the internal network (10.0.0.0) and the new subnet (202.129.82.192/30) can talk to each other.


Another issue is that that the 10.0.0.0 network needs to have a nat'ed connection, while the new subnet needs to be routed. All this is possible on the same interface with a few policy changes.

So Lets start. Please note that process will break your internet connection until all steps have been done.

1) Make sure that your external WAN interface is set to Route mode. This will break your current nat until we fix the policies.

This option can be found in:

Network > Interfaces > ethernet3 (name may be different) -> Edit
WAN Route Mode

2) Now go to your internal LAN interface and check that it too is in route mode and that "Block Intra-Subnet Traffic" is off (allowing the internal interface to pass traffic back out the same interface (i.e. 10.0.0.0 -> 202.129.82.192)

Network > Interfaces > ethernet1 (name may be different) -> Edit
LAN Route Mode

3) Add your Subnet on the internal interface

Network > Interfaces > ethernet1 (name may be different) -> Edit -> Secondary IP
Adding Second Subnet

4) Now we'll setup a policy so that any traffic from 10.0.0.0/22 gets nat'ed out of our static IP address

Policies -> From Trust to Untrust. The source address will be your internal network, destination address will be ANY and so will the service.
10.0.0.0 Nat Policy

5) Click advanced and check "Source Translation", then click okay.
Source Translation

6) Now we'll setup a policy so that our new subnet can talk to the world.

In Policies -> From Trust to Untrust create a basic subnet any rule (of course you can restrict things if you'd like). You don't need "Source Translation" on this one.
Subnet to ANY

7) Now to create a rule to allow traffic in to our new subnet

In Policies -> From Untrust to Trust create a basic any subnet rule (of course you can restrict things if you'd like). You don't need "Source Translation" on this one.
ANY to subnet

8) The last step is to allow traffic from the new subnet to talk to the internal network (this is an optional step).

In Policies -> From Trust to Trust. Source address being your new subnet and destination address is your local network.
Subnet to LOCAL network


Somethings I've noticed with this setup.
  1. You can still use VIPs on your main static ip address (202.129.82.126), so that gives you another IP to play with.

  2. The internal netscreen interface works on the network address for the /30 (i.e. 202.129.82.192) giving us two ip addresses that we can use for servers instead of just one.


Sat, 23 Dec 2006 8:45 PM

Back on the air

Michael Dale
We've successfully moved! This new place is pretty awesome, great kitchen and a dishwasher! :)


iinet adsl2+ was connected this morning. We've got the business pack so we currently have one static ip address plus a /30, something we couldn't do cheaply with internode (it would have cost an $100/month with node).


We're hoping to upgrade the current /30 to a /29 (8 IP addresses) later next week (for an extra $64/year).


I've got the netscreen setup so that the /30 works seamlessly with our internal 10.0.0.0/22 network including broadcast traffic (itunes sharing for the win).


So once the cabling is done we'll move the servers back here (about mid jan I would say).

Wed, 20 Dec 2006 7:26 PM

Moving

Michael Dale
The guys are moving tomorrow.


Our new address is 30 Wardell Rd Petersham 2049.


This website and anything else hosted here will be offline sometime early Friday while I move the servers to work and update the DNS.


Temporary IP Addresses:


Mail Server: 203.27.228.200

Web/DNS Server: 203.27.228.201

Mon, 11 Dec 2006 8:18 PM

Photos of our possible new house

Michael Dale
Photos of our possible new house. I don't really like the colours, but other than that it seems nice.

Tue, 05 Dec 2006 7:23 PM

Moving :(

Michael Dale
Looks like the owners of the house want to move back in.


So it looks like we're house hunting again.


We moved in here almost a year ago