Xen 05 - dom0 - the physical hardware
Xen on Debian 4 Learning · Previous: domU - backup with LVM snapshots · Next: domU - Base (Golden image)
The Slovak original of this document: Xen 05 - dom0 - fyzický HW (slovensky).
|=----------------------------------=[ XEN ]=------------------------------=| +---------------------------------------------------------------------------+ | | | XEN-server dom0 (REAL SERVER HW) | | Debian 4.0 Etch | | | +---------------------------------------------------------------------------+ |=-------------------------------=[ BH 2008 ]=-----------------------------=|
XEN - Server
The steps taken when installing the XEN server for the XEN project.
Note: only the differences from the default configuration are described.Installing the system
The base Debian Linux 4.0 system was installed from the media: debian-40r0-i386-netinst
URL: http://ftp.antik.sk/debian-cd/current/i386/iso-cd/debian-40r1-i386-netinst.isoPartition layout + parameters
# /etc/fstab: static file system information.
#
# <file system> <mount point> <type> <options> <dump> <pass>
proc /proc proc defaults 0 0
/dev/mapper/system_xen-root / ext3 defaults,errors=remount-ro 0 1
/dev/md0 /boot ext3 defaults,nodev,nosuid,noexec 0 2
/dev/mapper/system_xen-tmp /tmp ext3 defaults,nodev,nosuid,noexec 0 2
/dev/mapper/system_xen-usr /usr ext3 defaults,nodev 0 2
/dev/mapper/system_xen-var /var ext3 defaults,nodev,nosuid 0 2
/dev/mapper/system_xen-var--log /var/log ext3 defaults,nodev,nosuid,noexec 0 2
/dev/mapper/system_xen-swap none swap sw 0 0
/dev/scd0 /media/cdrom0 udf,iso9660 user,noauto 0 0
# cat /proc/mdstat
------------------
Personalities : [raid1]
md4 : active raid1 sdc5[0] sdd5[1]
488383872 blocks [2/2] [UU]
md3 : active raid1 sda7[0] sdb7[1]
87779008 blocks [2/2] [UU]
md2 : active raid1 sda6[0] sdb6[1]
48829440 blocks [2/2] [UU]
md1 : active raid1 sda5[0] sdb5[1]
19534912 blocks [2/2] [UU]
md0 : active raid1 sda1[0] sdb1[1]
144448 blocks [2/2] [UU]
# cat /boot/grub/menu.lst
-------------------------
title Xen 3.0.3-1-amd64 / Debian GNU/Linux, kernel 2.6.18-6-xen-amd64
root (hd0,0)
kernel /xen-3.0.3-1-amd64.gz
module /vmlinuz-2.6.18-6-xen-amd64 root=/dev/mapper/system_xen-root ro console=tty0
module /initrd.img-2.6.18-6-xen-amd64
savedefault
title Debian GNU/Linux, kernel 2.6.18-6-amd64
root (hd0,0)
kernel /vmlinuz-2.6.18-6-amd64 root=/dev/mapper/system_xen-root ro
initrd /initrd.img-2.6.18-6-amd64
savedefault
title Debian GNU/Linux, kernel 2.6.18-6-amd64 (single-user mode)
root (hd0,0)
kernel /vmlinuz-2.6.18-6-amd64 root=/dev/mapper/system_xen-root ro single
initrd /initrd.img-2.6.18-6-amd64
savedefaultSetting up the network card
# nano /etc/network/interfaces
------------------------------
# The loopback network interface
auto lo
iface lo inet loopback
# The primary network interface
iface eth0 inet static
address 192.168.254.254
netmask 255.255.255.0
network 192.168.254.0
broadcast 192.168.254.255
gateway 192.168.254.1
dns-nameservers 192.0.2.52 192.0.2.53
------------------------------END->/etc/network/interfacesSetting up the sources for the packaging system
# nano /etc/apt/sources.list
----------------------------
# STABLE
deb http://ftp.sk.debian.org/debian/ etch main
deb-src http://ftp.sk.debian.org/debian/ etch main
# SECURITY
deb http://security.debian.org/ etch/updates main contrib
deb-src http://security.debian.org/ etch/updates main contrib
-------------------------------END->/etc/apt/sources.listInstalling the rest of the software
# apt-get install less
# apt-get install mc
# apt-get install mailx
# apt-get install mutt
# apt-get install syslog-ng
# apt-get install pciutilsInstalling the SSH server (openbsd ssh)
-------------
Install ssh
-------------
# apt-get install ssh
------------
Config ssh
------------
# nano /etc/ssh/sshd_config
---------------------------
ListenAddress 192.168.254.254
PermitRootLogin no
AllowUsers bh skupko firefox
X11Forwarding no
Banner /etc/issue.net
#Subsystem sftp /usr/lib/openssh/sftp-server
---------------------------END->/etc/ssh/sshd_config
--------------
Banner setup
--------------
# nano /etc/issue
-----------------
***************************************************************************
WARNING
This computer system is private property. It may be used only by
authorised users. The privacy of users on this system is not
guaranteed.
Any use of this computer system may be recorded,
monitored, audited, inspected or otherwise checked by the employer,
the owner or the legal authorities.
By using this system the user consents to the recording and monitoring
of their activities in the computer system, and likewise consents to a possible
inspection of their activities in the system by the owner or the legal authorities.
Unauthorised use of the system may lead to disciplinary action by the employer and to
a criminal investigation. By using this system the user confirms that
they are aware of the conditions stated above. If you do not agree with anything
stated above, log out of the system immediately.
****************************************************************************
-----------------END->/etc/issue
# cat /etc/issue > /etc/issue.net
---------------------------------
the same as /etc/issue ;-)Installing a local-only mail server (postfix)
-----------------
Install postfix
-----------------
# apt-get install postfix
-------------------------
Choose the option "Local only"
Mail name: xen
----------------
Config postfix
----------------
# nano /etc/postfix/main.cf
---------------------------
---------------------------END->/etc/postfix/main.cfFirewall configuration
----------------
Firewall rules
----------------
# nano /var/lib/iptables/active
-------------------------------
#
# Iptables Firewall Template
#
# hajzer [at] gmail [dot] com
# 2008
#
#######################
# NAT - POLICY
#######################
*nat
:PREROUTING ACCEPT
:POSTROUTING ACCEPT
:OUTPUT ACCEPT
#======================
# NAT - PREROUTING
#======================
#---
#--- VIRTUAL MACHINES and their services
#---
#--- WWW (443) -> VM.www (443)
#-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 80 -j DNAT --to-destination 10.0.0.2:80
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 443 -j DNAT --to-destination 10.0.0.2:443
#--- SSH (22222) -> VM.www (22)
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22222 -j DNAT --to-destination 10.0.0.2:22
#--- SSH (22223) -> VM.ldap (22), WWW (80) -> VM.ldap
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22223 -j DNAT --to-destination 10.0.0.3:22
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 80 -j DNAT --to-destination 10.0.0.3:80
#--- SSH (22224) -> VM.db (22)
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22224 -j DNAT --to-destination 10.0.0.4:22
#--- SSH (22225) -> VM.jabber (22)
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22225 -j DNAT --to-destination 10.0.0.5:22
#--- SSH (22226) -> VM.mail (22)
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22226 -j DNAT --to-destination 10.0.0.6:22
#--- SSH (22227) -> VM.devel (22)
-A PREROUTING -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22227 -j DNAT --to-destination 10.0.0.100:22
#======================
# NAT - POSTROUTING
#======================
#--- NAT for VMs
-A POSTROUTING -s 10.0.0.0/255.255.255.0 -j SNAT --to-source 192.168.254.254
#======================
# NAT - OUTPUT
#======================
COMMIT
#######################
# MANGLE - POLICY
#######################
*mangle
:PREROUTING ACCEPT
:INPUT ACCEPT
:FORWARD ACCEPT
:OUTPUT ACCEPT
:POSTROUTING ACCEPT
#======================
# MANGLE - PREROUTING
#======================
#======================
# MANGLE - INPUT
#======================
#======================
# MANGLE - FORWARD
#======================
#======================
# MANGLE - OUTPUT
#======================
#======================
# MANGLE - POSTROUTING
#======================
COMMIT
#######################
# FILTER - POLICY
#######################
*filter
:INPUT DROP
:FORWARD DROP
:OUTPUT DROP
#======================
# FILTER - INPUT
#======================
-A INPUT -m state --state INVALID -j LOG --log-prefix "IN_DROP_INVALID: " --log-tcp-options --log-ip-options
-A INPUT -m state --state INVALID -j DROP
#--- Block WINDOWS junk
-A INPUT -p udp --dport 137:138 -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
#--- VM-base -> XEN ping
-A INPUT -s 192.168.253.1 -d 192.168.253.128 -p icmp -m icmp -j ACCEPT
#--- BH -> SSH
-A INPUT -i eth0 -s 192.168.254.0/255.255.255.0 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
#--- BH (home,work,mailhost.provider.example) -> SSH
-A INPUT -i eth0 -s 192.0.2.47 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
-A INPUT -i eth0 -s 192.0.2.27 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
-A INPUT -i eth0 -s 192.0.2.30 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
#--- skupko, firefox -> SSH
-A INPUT -i eth0 -s 192.0.2.35 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
-A INPUT -i eth0 -s 192.0.2.34 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
#--- skupko (mobile) -> SSH
-A INPUT -i eth0 -s 192.0.2.48/255.255.0.0 -d 192.168.254.254 -p tcp -m tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
#---
#--- VIRTUAL MACHINES and their services
#---
-A INPUT -i ! lo -j LOG --log-prefix "IN_DROP: " --log-tcp-options --log-ip-options
#======================
# FILTER - FORWARD
#======================
-A FORWARD -m state --state INVALID -j LOG --log-prefix "FW_DROP_INVALID: " --log-tcp-options --log-ip-options
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
#---
#--- VIRTUAL MACHINES and their services
#---
#--- WWW (80,443) -> VM.www
-A FORWARD -i eth0 -d 10.0.0.2 -p tcp -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
-A FORWARD -i eth0 -d 10.0.0.2 -p tcp -m tcp --sport 1024:65535 --dport 443 -j ACCEPT
#--- NAT for VMs -> DNS, WWW (http,https), FTP, GPG keys (11371)
-A FORWARD -o eth0 -s 10.0.0.0/255.255.255.0 -p udp -m udp --sport 1024:65535 --dport 53 -j ACCEPT
-A FORWARD -o eth0 -s 10.0.0.0/255.255.255.0 -p tcp -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
-A FORWARD -o eth0 -s 10.0.0.0/255.255.255.0 -p tcp -m tcp --sport 1024:65535 --dport 443 -j ACCEPT
-A FORWARD -o eth0 -s 10.0.0.0/255.255.255.0 -p tcp -m tcp --sport 1024:65535 --dport 21 -j ACCEPT
-A FORWARD -o eth0 -s 10.0.0.0/255.255.255.0 -p tcp -m tcp --sport 1024:65535 --dport 11371 -j ACCEPT
#--- BH LAN (SSH) -> VM.www (22) VM.ldap (22,80) VM.db (22) VM.jabber (22) VM.mail (22)
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.2 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.3 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.3 -p tcp -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.4 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.5 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.6 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.168.254.0/255.255.255.0 -d 10.0.0.100 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
#--- BH BigCorp (SSH) -> VM.www (22) VM.ldap (22,80) VM.db (22) VM.jabber (22) VM.mail (22)
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.2 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.3 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.3 -p tcp -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.4 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.5 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.6 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.27 -d 10.0.0.100 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
#--- skupko ANTIK
-A FORWARD -i eth0 -s 192.0.2.34 -d 10.0.0.2 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.34 -d 10.0.0.3 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.34 -d 10.0.0.4 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.34 -d 10.0.0.5 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.34 -d 10.0.0.6 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i eth0 -s 192.0.2.34 -d 10.0.0.100 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
-A FORWARD -i ! lo -j LOG --log-prefix "FW_DROP: " --log-tcp-options --log-ip-options
#======================
# FILTER - OUTPUT
#======================
-A OUTPUT -m state --state INVALID -j LOG --log-prefix "OUT_DROP_INVALID: " --log-tcp-options --log-ip-options
-A OUTPUT -m state --state INVALID -j DROP
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
#--- Dom0 -> vhosts
-A OUTPUT -p tcp -s 10.0.0.129/32 --sport 1024:65535 -d 10.0.0.0/8 -m state --state NEW -j ACCEPT
-A OUTPUT -p tcp -s 10.0.0.130/32 --sport 1024:65535 -d 10.0.0.0/8 -m state --state NEW -j ACCEPT
-A OUTPUT -p tcp -s 10.0.0.131/32 --sport 1024:65535 -d 10.0.0.0/8 -m state --state NEW -j ACCEPT
-A OUTPUT -p tcp -s 10.0.0.132/32 --sport 1024:65535 -d 10.0.0.0/8 -m state --state NEW -j ACCEPT
-A OUTPUT -p tcp -s 10.0.0.133/32 --sport 1024:65535 -d 10.0.0.0/8 -m state --state NEW -j ACCEPT
-A OUTPUT -p tcp -s 10.0.0.227/32 --sport 1024:65535 -d 10.0.0.0/8 -m state --state NEW -j ACCEPT
#--- FW -> NTP
-A OUTPUT -o eth0 -p udp --sport 123 --dport 123 -j ACCEPT
#--- FW -> SSH
-A OUTPUT -o eth0 -p tcp --sport 1024:65535 --dport 22 --syn -m state --state NEW -j ACCEPT
#--- FW -> FTP
-A OUTPUT -o eth0 -p tcp --sport 1024:65535 --dport 21 --syn -m state --state NEW -j ACCEPT
#--- FW -> SMTP
-A OUTPUT -o eth0 -p tcp --sport 1024:65535 --dport 25 --syn -m state --state NEW -j ACCEPT
#--- FW -> WWW (HTTP,HTTPS)
-A OUTPUT -o eth0 -p tcp --sport 1024:65535 --dport 80 --syn -m state --state NEW -j ACCEPT
-A OUTPUT -o eth0 -p tcp --sport 1024:65535 --dport 443 --syn -m state --state NEW -j ACCEPT
#--- FW -> DNS
-A OUTPUT -o eth0 -p udp --sport 1024:65535 --dport 53 -j ACCEPT
#--- FW -> VMs ICMP
-A OUTPUT -s 10.0.0.0/255.0.0.0 -d 10.0.0.0/255.0.0.0 -p icmp -j ACCEPT
-A OUTPUT -o ! lo -j LOG --log-prefix "OUT_DROP: " --log-tcp-options --log-ip-options
COMMIT
-------------------------------END->/var/lib/iptables/active
--------------------------
Firewall - Kernel tuning
--------------------------
# nano /etc/sysctl.conf
-----------------------
# TCP SYN Cookie Protection - ON
net.ipv4.tcp_syncookies = 1
# IP Source Routing - OFF
net.ipv4.conf.all.accept_source_route = 0
# ICMP Redirect Acceptance - OFF
net.ipv4.conf.all.accept_redirects = 0
# IP Spoofing Protection - ON
net.ipv4.conf.all.rp_filter = 1
# Ignoring to ICMP Requests - ON
net.ipv4.icmp_echo_ignore_all = 1
# Ignoring Broadcasts Request - ON
net.ipv4.icmp_echo_ignore_broadcasts = 1
# Bad Error Message Protection - ON
net.ipv4.icmp_ignore_bogus_error_responses = 1
# Logging of Spoofed Packets, Source Routed Packets, Redirect Packets - ON
net.ipv4.conf.all.log_martians = 1
# IPV4 Forwarding
net.ipv4.conf.all.forwarding=1
-----------------------END->/etc/sysctl.confInstalling Bastille linux
------------------
Install bastille
------------------
# apt-get install bastille
-----------------
Config bastille
-----------------
# InteractiveBastille
---------------------
>accept
Q: Would you like to set more restrictive permissions on the administration utilities? [yes]
Q: Would you like to disable SUID status for mount/umount? [yes]
Q: Would you like to disable SUID status for ping? [yes]
Q: Would you like to disable SUID status for at? [Yes]
Q: Would you like to disable SUID status for traceroute? [yes]
Q: Should Bastille disable clear-text r-protocols that use IP-based authentication? [yes]
Q: Would you like to enforce password aging? [no]
Q: Would you like to restrict the use of cron to administrative account? [yes]
Q: Do you want to set the default umask? [yes]
Q: What umask would you like to set for users on the system? [077]
Q: Should we disallow root login on all ttys? [yes]
Q: Would you like to password-protect the GRUB prompt? [yes]
Q: Enter GRUB password, please. [<grub_password>]
Q: Would you like to disable CTRL-ALT-DELETE rebooting? [yes]
Q: Would you like to password protect single-user mode? [yes]
Q: Would you like to set a default-deny on TCP Wrappers and xinetd? [no]
Q: Should Bastille ensure the telnet service does not run on this system? [yes]
Q: Should Bastille ensure inetd's FTP service does not run on this system? [yes]
Q: Would you like to display "Authorized Use" message at log-in time? [no]
Q: Would you like to put limits on system resource usage? [yes]
Q: Should we restrict console access to small group of the user accounts? [yes]
Q: Which accounts should be able to login at console? [root bh skupko firefox]
Q: Would you like to add additional logging? [no]
Q: Would you like to install TMPDIR/TMP scripts? [no]
Q: Would you like to run the packet filtering script? [no]
Q: Are you finished answering the questions, i.e. may we make the changes? [yes]Installing the IDS (Snort)
---------------
Install snort
---------------
# apt-get install snort
-----------------------
Please enter the address range that Snort will listen on [192.168.254.0/24]
# dpkg-reconfigure snort (these parameters can also be set in /etc/snort/snort.debian.conf)
-------------------------------------------------------------------------------------------
When should Snort be started? [boot]
On which interface(s) Snort listen? [eth0]
Please enter the address range that Snort will listen on [192.168.254.0/24]
Should Snort disable promiscuous mode on the interface? [no]
Should Snort's rules testing order be changed to Pass|Alert|Log [yes]
Should daily summaries be sent by e-mail? [yes]
Who should receive the daily statistics mails? [root]
An alert needs to appear more times than this number to be included in the daily statistics [1]
-------------------------------------------------------------------------------------------
The 'oinkmaster' package is used to update the signatures for snort
-------------------------------------------------------------------
# apt-get install oinkmaster
Setting the URL the rules are downloaded from
=============================================
# nano /etc/oinkmaster.conf
---------------------------
url = http://www.snort.org/pub-bin/oinkmaster.cgi/<oinkcode>/snortrules-snapshot-2.3.tar.gz
The directory old rules are backed up into
------------------------------------------
# mkdir /etc/snort/rules-backup
Automatic updating of the rules
-------------------------------
# touch /etc/cron.daily/snort_update
# chmod +x /etc/cron.daily/snort_update
# nano /etc/cron.daily/snort_update
-----------------------------------
#!/bin/bash
/usr/sbin/oinkmaster -C /etc/oinkmaster.conf -o /etc/snort/rules/ -b /etc/snort/rules-backup 2>&1 | mutt -s "SNORT UPDATE: XEN" support@localhost
--------------
Config snort
--------------
# nano /etc/snort/snort.conf
----------------------------
output alert_full: /var/log/snort/alert
preprocessor sfportscan: proto {all} \
memcap { 10000000 } \
sense_level { medium } \
logfile { /var/log/snort/portscan.log }
preprocessor stream4: disable_evasion_alerts detect_scans enforce_state state_protection enable_udp_sessions
--------------
Chroot snort
--------------
Creating the directory structure (the jail)
-------------------------------------------
# mkdir -p /chroot/snort/var/log/snort
# chown snort:snort /chroot/snort/var/log/snort
We edit the file /etc/default/snort
-----------------------------------
# nano /etc/default/snort
-------------------------
PARAMS="-m 027 -D -d -t /chroot/snort"
LOGDIR="/chroot/snort/var/log/snort"
# nano /etc/logrotate.d/snort
-----------------------------
/chroot/snort/var/log/snort/portscan.log /chroot/snort/var/log/snort/alert /chroot/snort/var/log/snort/portscan2.log {
daily
rotate 30
compress
missingok
notifempty
create 0640 snort adm
sharedscripts
postrotate
/etc/init.d/snort restart > /dev/null 2>&1
endscript
}Installing XEN
--------------------
Install XEN 32 bit
--------------------
# apt-get install xen-linux-system-2.6.18-6-xen-686
# apt-get install libc6-xen
# init 6
--------------------
Install XEN 64 bit
--------------------
# xen-linux-system-2.6.18-6-xen-amd64
!!! NOT IMPLEMENTED YET !!!
:-)Monitoring
-------------------------------------------------
Install snortalog (snort and iptables stats)
-------------------------------------------------
# apt-get install libgd-graph-perl
# wget http://jeremy.chartier.free.fr/snortalog/downloads/snortalog/snortalog_v2.4.2.tgz
-------------------------------------------------
Monitoring iptables
-------------------------------------------------
# cat /var/log/iptables.log | /tools/snortalog/snortalog.pl -8 -o /var/log/iptables-sumar.txt -reportCurrent practice (checked 2026-10)
noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.
- Debian 4.0 and the Xen packages: Etch has been end-of-life since 2010 (dates are in the section under the first article), and the
etchandetch/updateslines insources.listno longer deliver updates. On current Debian the dom0 isapt install xen-system-amd64on the standard kernel; the "Install XEN 32 bit" branch withxen-linux-system-2.6.18-6-xen-686andlibc6-xenhas no successor, because Debian 13 ships no i386 kernel and the Xen packages are amd64 only. - Boot loader:
/boot/grub/menu.lstis GRUB Legacy. GRUB 2 generates its configuration, and the Xen entry ("Debian GNU/Linux, with Xen hypervisor") is created when the hypervisor package is installed; do not hand-write thekernel /xen-...gzandmodulelines. - SSH:
PermitRootLogin no,AllowUsers,X11Forwarding noand the banner are still valid as written. OpenSSL on Etch produced predictable keys until the fix of 2008-05-13 (DSA-1571), so every SSH host and user key created on such a system before that date had to be regenerated. DSA keys are not supported at all by the OpenSSH in Debian 13; use Ed25519 keys. - Firewall format: the rule set in
/var/lib/iptables/activeis iptables-restore syntax. nftables is the default framework in Debian since Debian 10 and building new firewalls on iptables is discouraged; the rules belong in/etc/nftables.conf, loaded bynftables.service, and theinetfamily covers IPv4 and IPv6 in one table (the article filters IPv4 only).-m state --stateisct statethere. The file can be converted mechanically, checked, and then merged into/etc/nftables.conf:
$ # iptables-restore-translate -f /var/lib/iptables/active > /root/ruleset.nft $ # nft -c -f /root/ruleset.nft
- Firewall syntax that no longer loads:
-i ! loand-o ! loare rejected by current iptables ("Bad argument"); the negation goes in front of the option:! -i lo. Fix these three LOG rules before translating the file. - SSH to the guests: one DNAT port per guest (22222 to 22227) can be replaced by a jump through dom0, with no forwarding rules:
ssh -J user@dom0 user@10.0.0.2. - sysctl: from Debian 13
systemd-sysctlno longer reads/etc/sysctl.conf. Put the same lines in a file under/etc/sysctl.d/, for example/etc/sysctl.d/local.conf. - Bastille: the
bastillepackage was dropped from Debian testing in 2010 and removed from unstable in 2013; there is nothing toapt-get install. What it did here (SUID bits, umask, cron and console restrictions, boot loader password) is set directly or through configuration management. GRUB 2 stores the password as a hash made withgrub-mkpasswd-pbkdf2. - Snort: Debian stable no longer carries a
snortpackage; the package tracker lists it only for old releases, at 2.9.x. Upstream develops Snort 3, which is configured in Lua (snort.lua); thesnort.conflines shown, includingpreprocessor stream4, do not apply to it. Thesnortrules-snapshot-2.3rule set is long past its end of life. - Snort rule updates:
oinkmasteris replaced by PulledPork (pulledpork3for Snort 3). The article fetches the rules over plainhttp://with the personal oinkcode inside the URL; an oinkcode is a credential and belongs in a root-only configuration file.
Sources: