<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="http://marcheimann.de/wiki/lib/exe/css.php?s=feed" type="text/css"?>
<rss version="2.0">
    <channel xmlns:g="http://base.google.com/ns/1.0">
        <title>Marc's Linux-Wiki (Gentoo, Debian) linux:allgemein:netzwerk</title>
        <description></description>
        <link>http://marcheimann.de/wiki/</link>
        <lastBuildDate>Thu, 09 Apr 2026 23:49:17 +0000</lastBuildDate>
        <generator>FeedCreator 1.8</generator>
        <image>
            <url>http://marcheimann.de/wiki/lib/tpl/dokuwiki/images/favicon.ico</url>
            <title>Marc's Linux-Wiki (Gentoo, Debian)</title>
            <link>http://marcheimann.de/wiki/</link>
        </image>
        <item>
            <title>linux:allgemein:netzwerk:fail2ban</title>
            <link>http://marcheimann.de/wiki/doku.php?id=linux:allgemein:netzwerk:fail2ban&amp;rev=1373398995&amp;do=diff</link>
            <description>&lt;pre&gt;
@@ -1 +1,24 @@
+ ====== fail2ban ======
+ Bans IP that make too many password failures
  
+ ===== Kernel =====
+   * Folgende Module müssen aktiviert sein:
+ 
+   [*] Networking support  ---&amp;gt; 
+     Networking options  ---&amp;gt;
+       [*] Network packet filtering framework (Netfilter)  ---&amp;gt;
+         Core Netfilter Configuration  ---&amp;gt;
+           [M] Netfilter Xtables support (required for ip_tables)
+    
+   [*] Networking support  ---&amp;gt; 
+     Networking options  ---&amp;gt;
+       [*] Network packet filtering framework (Netfilter)  ---&amp;gt;
+         Core Netfilter Configuration  ---&amp;gt;
+           IP: Netfilter Configuration  ---&amp;gt;
+             &amp;lt;M&amp;gt; IP tables support (required for filtering/masq/NAT)
+             &amp;lt;M&amp;gt;   &amp;quot;addrtype&amp;quot; address type match support
+             &amp;lt;M&amp;gt;   Packet filtering 
+             &amp;lt;M&amp;gt;     REJECT target support 
+   
+   
+   

&lt;/pre&gt;</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>linux:allgemein:netzwerk</category>
            <pubDate>Tue, 09 Jul 2013 21:43:15 +0000</pubDate>
        </item>
        <item>
            <title>linux:allgemein:netzwerk:networkmanager</title>
            <link>http://marcheimann.de/wiki/doku.php?id=linux:allgemein:netzwerk:networkmanager&amp;rev=1373398995&amp;do=diff</link>
            <description>&lt;pre&gt;
@@ -3,9 +3,130 @@
  Network configuration and management in an easy way. Desktop environment independent.
  
  ===== Konfiguration =====
  
-   * Konfiguration funktionierend mit networkmanager und nm-applet in Version 0.8.2. Pre-0.9 funktioniert bis dato (0.8.2-r10) nicht
+   * Konfiguration funktionierend mit networkmanager und nm-applet in Version 0.9 (Die Konfiguration der 0.8-er Reihe funktioniert wegen einiger API-Änderungen nicht und muss angepasst werden):
+ 
+ &amp;lt;file - /etc/dbus-1/system.d/NetworkManager.conf&amp;gt;
+ &amp;lt;!DOCTYPE busconfig PUBLIC
+  &amp;quot;-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN&amp;quot;
+  &amp;quot;http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd&amp;quot;&amp;gt;
+ &amp;lt;busconfig&amp;gt;
+         &amp;lt;policy user=&amp;quot;root&amp;quot;&amp;gt;
+                 &amp;lt;allow own=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+                 &amp;lt;allow own=&amp;quot;org.freedesktop.NetworkManager.Settings&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager.Settings&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.PPP&amp;quot;/&amp;gt;
+ 
+ 		&amp;lt;allow send_interface=&amp;quot;org.freedesktop.NetworkManager.SecretAgent&amp;quot;/&amp;gt;
+         &amp;lt;/policy&amp;gt;
+         &amp;lt;policy at_console=&amp;quot;true&amp;quot;&amp;gt;
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.DBus.Introspectable&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.DBus.Properties&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.AccessPoint&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Connection.Active&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Device.Cdma&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Device.Wired&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Device.Gsm&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Device.Serial&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Device.Wireless&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Device&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.DHCP4Config&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.IP4Config&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.VPN.Connection&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+ 		       send_interface=&amp;quot;org.freedesktop.NetworkManager.AgentManager&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;SetLogging&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;Sleep&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;sleep&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;wake&amp;quot;/&amp;gt;
+         &amp;lt;/policy&amp;gt;
+         &amp;lt;policy group=&amp;quot;plugdev&amp;quot;&amp;gt;
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                       send_interface=&amp;quot;org.freedesktop.NetworkManager.PPP&amp;quot;/&amp;gt;
+         &amp;lt;/policy&amp;gt;
+         &amp;lt;policy context=&amp;quot;default&amp;quot;&amp;gt;
+                 &amp;lt;deny own=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.Settings&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;allow send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager.AgentManager&amp;quot;/&amp;gt;
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;SetLogging&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;Sleep&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;sleep&amp;quot;/&amp;gt;
+ 
+                 &amp;lt;deny send_destination=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_interface=&amp;quot;org.freedesktop.NetworkManager&amp;quot;
+                        send_member=&amp;quot;wake&amp;quot;/&amp;gt;
+ 
+         &amp;lt;/policy&amp;gt;
+ 
+         &amp;lt;limit name=&amp;quot;max_replies_per_connection&amp;quot;&amp;gt;512&amp;lt;/limit&amp;gt;
+ &amp;lt;/busconfig&amp;gt;
+ &amp;lt;/file&amp;gt;
+ 
+   * Konfiguration funktionierend mit networkmanager und nm-applet in Version 0.8.2.
  
  &amp;lt;file - /etc/dbus-1/system.d/NetworkManager.conf&amp;gt;
  &amp;lt;!DOCTYPE busconfig PUBLIC
   &amp;quot;-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN&amp;quot;

&lt;/pre&gt;</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>linux:allgemein:netzwerk</category>
            <pubDate>Tue, 09 Jul 2013 21:43:15 +0000</pubDate>
        </item>
        <item>
            <title>linux:allgemein:netzwerk:openssh</title>
            <link>http://marcheimann.de/wiki/doku.php?id=linux:allgemein:netzwerk:openssh&amp;rev=1373398995&amp;do=diff</link>
            <description>&lt;pre&gt;
@@ -1 +1,23 @@
+ ====== openssh ======
  
+ Port of OpenBSD&amp;#039;s free SSH release.
+ 
+ ===== ssh =====
+ 
+   * Einloggen auf entferntem Rechner (Server)
+ 
+   $ ssh -p SERVERPORT SERVER-BENUTZERNAME@SERVER-IP
+ 
+ ===== scp =====
+ 
+ SCP wird benutzt, um Dateien über das SSH-Protokol zu transferieren
+ 
+ 
+   * Datei &amp;quot;senden&amp;quot;:
+   
+   $ scp -P SERVER-PORT QUELLDATEI SERVER-IP:SERVERORT
+ 
+ 
+   * Datei &amp;quot;holen&amp;quot;:
+   
+   $ scp -P SERVER-PORT SERVER-IP:SERVERORT ZIELDATEI

&lt;/pre&gt;</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>linux:allgemein:netzwerk</category>
            <pubDate>Tue, 09 Jul 2013 21:43:15 +0000</pubDate>
        </item>
        <item>
            <title>linux:allgemein:netzwerk:samba</title>
            <link>http://marcheimann.de/wiki/doku.php?id=linux:allgemein:netzwerk:samba&amp;rev=1577990900&amp;do=diff</link>
            <description>&lt;pre&gt;
@@ -28,9 +28,9 @@
  vorhandene User, die auf diesen Ordner Zugriff haben sollen, der Gruppe hinzufügen
  
    # gpasswd -a marc scanner
  
- Verzeichnis anlegen und einrichten:
+ Verzeichnis anlegen und einrichten: permission 1770 verhindert, dass eigene Dateien von anderen berechtigten gelöscht werden können. Fall gewünscht, 0770 (ohne sticky bit) verwenden!
  
    # mkdir scanner
    # chmod 1770 scanner
    # chgrp scanner scanner

&lt;/pre&gt;</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>linux:allgemein:netzwerk</category>
            <pubDate>Thu, 02 Jan 2020 19:48:20 +0000</pubDate>
        </item>
        <item>
            <title>linux:allgemein:netzwerk:vsftpd</title>
            <link>http://marcheimann.de/wiki/doku.php?id=linux:allgemein:netzwerk:vsftpd&amp;rev=1373398994&amp;do=diff</link>
            <description>&lt;pre&gt;
@@ -1 +1,110 @@
+ ====== vsftpd ======
+ 
+ Very Secure FTP Daemon written with speed, size and security in mind
+ 
+ ===== Konfiguration =====
+ 
+   * Minimale Konfiguration für Zugriff aus dem lokalen LAN wie auch aus dem Internet.
+   * Ein Benutzer &amp;quot;ftpsecure&amp;quot; muss vorher angelegt werden, damit vsftpd als unpriviliegierter Benutzer laufen kann.
+   * Alle lokalen Benutzer können sich mit Lese- und Schreibzugriff anmelden
+   * anonymer Zugriff nur lesend
+ 
+ &amp;lt;file - vsftpd.conf&amp;gt;
+ # Allow anonymous FTP? (Beware - allowed by default if you comment this out).
+ anonymous_enable=YES
+  
+ # Uncomment this to allow local users to log in.
+ local_enable=YES
+  
+ # Uncomment this to enable any form of FTP write command.
+ write_enable=YES
+  
+ # Default umask for local users is 077. You may wish to change this to 022,
+ # if your users expect that (022 is used by most other ftpd&amp;#039;s)
+ local_umask=022
+  
+ # Uncomment this to allow the anonymous FTP user to upload files. This only
+ # has an effect if the above global write enable is activated. Also, you will
+ # obviously need to create a directory writable by the FTP user.
+ #anon_upload_enable=YES
+  
+ # Uncomment this if you want the anonymous FTP user to be able to create
+ # new directories.
+ #anon_mkdir_write_enable=YES
+  
+ # Activate directory messages - messages given to remote users when they
+ # go into a certain directory.
+ dirmessage_enable=YES
+  
+ # Activate logging of uploads/downloads.
+ xferlog_enable=YES
+  
+ # Make sure PORT transfer connections originate from port 20 (ftp-data).
+ connect_from_port_20=YES
+  
+ # If you want, you can arrange for uploaded anonymous files to be owned by
+ # a different user. Note! Using &amp;quot;root&amp;quot; for uploaded files is not
+ # recommended!
+ #chown_uploads=YES
+ #chown_username=whoever
+ 
+ # You may override where the log file goes if you like. The default is shown
+ # below.
+ #xferlog_file=/var/log/vsftpd.log
+  
+ # If you want, you can have your log file in standard ftpd xferlog format.
+ # Note that the default log file location is /var/log/xferlog in this case.
+ #xferlog_std_format=YES
+  
+ # You may change the default value for timing out an idle session.
+ #idle_session_timeout=600
+  
+ # You may change the default value for timing out a data connection.
+ #data_connection_timeout=120
+  
+ # It is recommended that you define on your system a unique user which the
+ # ftp server can use as a totally isolated and unprivileged user.
+ nopriv_user=ftpsecure
+  
+ # Enable this and the server will recognise asynchronous ABOR requests. Not
+ # recommended for security (the code is non-trivial). Not enabling it,
+ # however, may confuse older FTP clients.
+ #async_abor_enable=YES
+  
+ # By default the server will pretend to allow ASCII mode but in fact ignore
+ # the request. Turn on the below options to have the server actually do ASCII
+ # mangling on files when in ASCII mode.
+ # Beware that on some FTP servers, ASCII support allows a denial of service
+ # attack (DoS) via the command &amp;quot;SIZE /big/file&amp;quot; in ASCII mode. vsftpd
+ # predicted this attack and has always been safe, reporting the size of the
+ # raw file.
+ # ASCII mangling is a horrible feature of the protocol.
+ #ascii_upload_enable=YES
+ #ascii_download_enable=YES
+  
+ # You may specify a file of disallowed anonymous e-mail addresses. Apparently
+ # useful for combatting certain DoS attacks.
+ #deny_email_enable=YES
+ # (default follows)
+ #banned_email_file=/etc/vsftpd/banned_emails
+  
+ # You may specify an explicit list of local users to chroot() to their home
+ # directory. If chroot_local_user is YES, then this list becomes a list of
+ # users to NOT chroot().
+ chroot_local_user=YES
+ #chroot_list_enable=YES
+ # (default follows)
+ #chroot_list_file=/etc/vsftpd/chroot_list
+  
+ # You may activate the &amp;quot;-R&amp;quot; option to the builtin ls. This is disabled by
+ # default to avoid remote users being able to cause excessive I/O on large
+ # sites. However, some broken FTP clients such as &amp;quot;ncftp&amp;quot; and &amp;quot;mirror&amp;quot; assume
+ # the presence of the &amp;quot;-R&amp;quot; option, so there is a strong case for enabling it.
+ #ls_recurse_enable=YES
+  
+ # When &amp;quot;listen&amp;quot; directive is enabled, vsftpd runs in standalone mode and
+ # listens on IPv4 sockets. This directive cannot be used in conjunction
+ # with the listen_ipv6 directive.
+ listen=YES
+ &amp;lt;/file&amp;gt;
  

&lt;/pre&gt;</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>linux:allgemein:netzwerk</category>
            <pubDate>Tue, 09 Jul 2013 21:43:14 +0000</pubDate>
        </item>
        <item>
            <title>linux:allgemein:netzwerk:wicd</title>
            <link>http://marcheimann.de/wiki/doku.php?id=linux:allgemein:netzwerk:wicd&amp;rev=1373398994&amp;do=diff</link>
            <description>&lt;pre&gt;
@@ -1 +1,48 @@
+ ====== wicd ======
+ 
+ ===== Installation =====
+ 
+ 
+   * Remove all net.* initscripts (except for net.lo) from all runlevels
+ 
+   * Add these scripts to the RC_PLUG_SERVICES line in /etc/conf.d/rc. (For example, RC_PLUG_SERVICES=&amp;quot;!net.eth0 !net.wlan0&amp;quot;)
+ 
+   # rc-update add wicd boot
+ 
+   * Starten:
+ 
+   $ wicd-client
+ 
+ 
+ ===== Tuning =====
+ 
+ 
+ Lastly, the wicd init.d script needs to be updated to include dbus and hald as dependencies otherwise the wireless card may not be found. So go into /etc/init.d/wicd and add them:
+ 
+ 
+   #!/sbin/runscript
+   # Copyright 1999-2006 Gentoo Foundation
+   # Distributed under the terms of the GNU General Public License v2
+   
+   opts=&amp;quot;start stop restart&amp;quot;
+   
+   WICD_DAEMON=/usr/sbin/wicd
+   WICD_PIDFILE=/var/run/wicd/wicd.pid
+   
+   depend() {
+           need dbus
+           need hald
+   }
+   
+   start() {
+           ebegin &amp;quot;Starting wicd daemon&amp;quot;
+           &amp;quot;${WICD_DAEMON}&amp;quot; &amp;gt;/dev/null 2&amp;gt;&amp;amp;1
+           eend $?
+   }
+   
+   stop() {
+           ebegin &amp;quot;Stopping wicd daemon&amp;quot;
+           start-stop-daemon --stop --pidfile &amp;quot;${WICD_PIDFILE}&amp;quot;
+           eend $?
+   }
  

&lt;/pre&gt;</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>linux:allgemein:netzwerk</category>
            <pubDate>Tue, 09 Jul 2013 21:43:14 +0000</pubDate>
        </item>
    </channel>
</rss>
