Aug 22

OpenVPN between pfSense and Mikrotik

Reading time: 3 – 5 minutes

vpn-pfsense-mikrotik-schemaAssuming previous scenario I’m going to describe the required configurations on pfSense and Mikrotik. Certifcate creation is not part of the scope of this document, if you are not familiar about how to do that it’s a good idea to use the pfSense certificate manager to do it. My last advice is take care with certificates 90% of problems that I found in my life when I was working on VPNs are because of that. Take your time to check it before spend your time playing with other configurations.

In that scenario pfSense will play the role of the VPN server and Mikrotik will be the client, so I’m going to start describing pfSense configurations.

Create OpenVPN server on proper section:

pfsense-openvpn-server

 

Important things to take in account when you set up the parameters are socket has to be a TCP socket in my case I decided to use port 1201:

pfsense-openvpn-server-configNext settings on the same place are about local network and tunnel IP addresses, this is required to create proper routing rules on the server and the client.

pfsense-openvpn-server-config2

 

Last part to configure on this sections is extremly simple, only take care to unmark everything and check “address pool” setting.

pfsense-openvpn-server-config3

 

Remember to open that port on Firewall rules.

pfsense-firewall-rules

 

A VPN user is required to authenticate the process, just go to “User Management” inside the “System” menu:

pfsense-user-manager-oriol

 

pfSense is configured, now it’s time to set-up the OpenVPN client on Mikrotik using Winbox. Remember to import the certificates:

certificates-mikrotik

 

Click on “PPP” this on the left menu:

ppp-mikrotik

 

Add an OVPN Client connection using the “+” button, the parameters for that connection are:

ppp-interface

 

Another required thing to define on “PPP” is the profile, click on the tab “Profile” and using the button with symbol “+” create a new profile like that:

ppp-profile

 

Everything is ready, now it’s time to check if the connection is OK. First go to the OVPN client on Mikrotik, remember this is on “PPP” menu option and inside tab “Interfaces”. Clicking on the interface you’ll see the status details. If it’s disconnect going to pfSense or Mikrotik logs you can see the negotiation details.

Remember usually the problem is with your certificates, but first of all you have to ensure that the negotiation tries to start.

Enjoy it and good luck.

 

Aug 15

Sniffing on Mikrotik and streaming in real-time to Wireshark

Reading time: 2 – 2 minutes

When you have a Mikrotik in any point of your network and you want to launch a sniffer for debugging or troubleshooting, a part from original RouterOS tools, you can stream captured traffic in real-time to Wireshark and inspect packets there.

The idea is exactly the same like I explained on the entry: Sniffing traffic in a Linux box and streaming in real-time to Wireshark on Windows.

Mikrotik configuration using the web interface is like that:

mikrotik-config

We assume 10.2.0.44 is the IP address of the Wireshark box, ensure that you don’t block UDP traffic on port 37008 because the stream from Mikrotik uses that target port. And define your own filters.

About Wireshark configuration is really simple, just set up the filter to allow only traffic from sniffing stream and select the network interface where traffic comes.

wireshark-config

Previous captures allow us to debug DNS queries to Google DNS service, this is the result when you click to the icon marked with a red circle on previous screen capture.

wireshark-traffic

Aug 01

Extracting private and public keys from a p12 file

Reading time: < 1 minute PKCS#12 is a container for storing many cryptography objects as a single file. It is commonly used to bundle a private key with its X.509 certificate or to bundle all the members of a chain of trust. This is a fast and simple summary about how to extract your keys from those kind of files:

#Private key:
openssl pkcs12 -in file_name.p12 -nocerts -out private.key
#Certificates:
openssl pkcs12 -in file_name.p12 -clcerts -nokeys -out public.crt

Recurrently I have to access to a usuful guide about those kind of openssl parameters, let me refer that guide:

The Most Common OpenSSL Commands (local copy)

Jul 27

Mikrotik as a PPTP server for Android

Reading time: 4 – 6 minutes

Two years ago I installed a Mikrotik Cloud Switch and lately I stoped my pfSense and I started using that switch as my network router, firewall and also as a switch. RouterOS is really powerful and allows to do a lot of things with that hardware. One of those things is set-up a VPN server based on PPTP. This is not the most secure way to create VPNs but usually the only requirement is a little bit of security on top of an IP over IP service that allows us to use local service when we’re in remote. In my case I have a lot of services in my LAN and I need some of them when I’m out of home specially I need to use them from my mobile phone.

Next steps describe how I set-up a PPTP server on my Mikrotik server allowing my Android 6 device (Huawei Mate 8) to connect to my home services through the VPN. Bellow you have a simple schema representing the schenario of the solution:

architecture

I’m only going to describe steps from the web console, of course, all those steps can be done using Winbox or the command line. To be honest I’m not used to RouterOS CLI but I think it’s not difficult to figure out the CLI commands to get the same result.

First step is set-up a pool of IP addresses to be assigned to the tunnel endpoints.

01-ip-pool

02-ip-pool

Thanks to an ARP proxy those IP addresses will be available like local IPs, this is transparent for the VPN configuration.

00-arp-proxy

configuration of connection profile is done inside “Profiles” tab:

05-profiles

first of all create a new profile called “default-encription”:

061-profiles

and another profile called “pptp-profile”:

06-profiles

“Secrets” tab is where you have to manage users, in my case only two users are created:

07-secrets

configuration details about my user are:

08-secrets

Inside PPP menu there is a button with a label “PPTP server” click there…

03-pptp-server

… and copy next settings:

04-pptp-server

Don’t forget to check that your PPTP port is accessible from your public IP address. Remember it’s 1703/TCP.

Android configuration is simple, first of all go to “settings” icon. Look for a “More” section bellow network options, and you’ll find VPN managment. Add a new connection, define a name, the type and the IP address and leave the rest by default. After that when you come back to VPN list you’ll find your new VPN in the list, click there and just set-up your PPTP credentials.

android

If you have some trouble the only thing that you can do is go to Mikrotik logs or start sniffing to figure out where is the problem. I had to do some tests before it was working but in the end everything was so simple like I explained here.

Good luck and enjoy it.

Thanks to next blog entries to inspire me:

 

 

Jun 06

Remove old kernels when there is no space in /boot

Reading time: 1 – 2 minutes

The first step is get some space in the partition “/boot” because without that it’s impossible to do anything.

So go to /boot and remove some “initrd” files as they are the biggest ones. A few of them will be enough.

After that a good point is to ensure there is no partial installation pending to finish:

apt-get -f install

Now it’s a good idea to purge all kernels except the running one:

dpkg -l 'linux-*' | sed '/^ii/!d;/'"$(uname -r | sed "s/\(.*\)-\([^0-9]\+\)/\1/")"'/d;s/^[^ ]* [^ ]* \([^ ]*\).*/\1/;/[0-9]/!d' | xargs sudo apt-get -y purge

To avoid that in future before filling the partition, it’s a good idea to install and run periodically: purge-old-kernels. Installation and example of use are:

# installation
apt-get install bikeshed
# keep three old kernels:
purge-old-kernels --keep 3
# if you want to put that in the crontab use that command
purge-old-kernels --keep 3 -qy

If you’re a Grub user don’t forget to run:

update-grub2

Personally I have a nightmare with that problem and Ubuntu, especially with version 12.04 which is installed in a lot of servers that I manage. I repeated the previous process a lot of times and in the end, I decided to document it because I always have to go to Google and find the proper steps to solve that problem.

Jun 05

Protecting your email with MXGuarddog

Reading time: 2 – 2 minutes

mxguarddogAfter using VMWare ESXi for a long time as a Hypervisor for my virtual servers I decided to stop paying OVH for that service and I migrated my virtual machines to VPS servers on OVH. At the end of the day only two VPS with a cost of 3€/month are enough and I can stop a 50€/month dedicated server.

The biggest challenge that I had to solve was migrate mail server to a new server. So far today I was using pfSense a firewall for my virtual servers. They were in a virtual network; pfSense anti-spam services and mail forwarding were enough to receive “cleaned” mail in my private mail server with Postfix and Dovecot.

New configuration is just a cheap VPS (1xCPU+2GB RAM+10GB SSD) with Ubuntu 16.04 and also with Postfix and Dovecot. But I decided to rent the anti-spam, anti-malware and anti-virus service to MX Guarddog. I discovered that service just surfing on the big G. Only 0.25 cents per account per month it’s a very good price and it does all the things that I need and much more. Configuration is really simple if you know what you are doing. They have a very good and simple control panel to manage the service. This is the perfect service to get what I need.

In the control panel you can do all that you need, manage mail accounts and domains. View quarantined mails and all required configurations and tests to validate everything is ready and also maintain white and black lists. We’ll see during next days if the service gets the quality that I expect, I hope I have found a very good and cheap resource.

Apr 12

Sniffing traffic in a Linux box and streaming in real-time to Wireshark on Windows

Reading time: 1 – 2 minutes

Sniffing and inspect complex protocols on “tcpdump” is usually painful. Of course, “tcpflow” is a very useful tool but is not always enough to sniff in a console. Wireshark is always a better option when it’s time to debug and troubleshooting communication problems.

But it’s not always easy to plug a Network TAP where you want to sniff. If at that point we have a Linux box with “ssh” and “tcpdump”. An interesting option is stream sniffed traffic to another box with Wireshark and dissect packet octets in their layers, fields, etc.

When Wireshark box is based on Windows you need “plink.exe“, and you can do thinks like that:

plink.exe -ssh -pw LINUX_BOX_PASSWORD root@LINUX_BOX_IP "tcpdump -n -i INTERFACE_TO_SNIFF -s 0 -w - not port 22" | "%PATH_TO_WIRESHARK\Wireshark.exe" -k -i -

Next you have a screenshot with a real life example of that:

tcpdump_streams_to_wireshark_secure

Apr 09

MacBook Air battery explossion

Reading time: 2 – 2 minutes

Two months ago I went to get my “Mac Book Air mid2011 version” and found that:

The batteries had exploded! It is curious bacause I have laptops saved for many years, one would say it has almost 20 years. Obviously the battery lasts very little but has never exploited. It is incredible that a brand that cares the quality of its product as Apple and a product that was the best in its class 5 years ago; today without more than being on a shelf it has exploded from one day to the other.

In Apple store didn’t want to know about the problem because it is out of guarantee; luckly it wasn’t my daily laptop and after buying a new battery in ebay I have changed the battery for les than 50€ and the laptop keeps running.

bateria-apple

I don’t know if anybody else suffered that experience but IMHO Apple has failed and I’m very disappointed with their reaction with my issue with the product. I know it’s not on guarantee but I paid close to 1.700€ on a Laptop less than 5 years ago and I don’t expect that. Clearly this is a manufacturing problem with the battery. I have to recognize once again that Apple has very good quality products, or not, but day after day their customer support is being worst.

Just a final note my actual laptop is a Toshiba, I’m not proud of it but it works quite good so far today is for far more powerful than current MacBook Air with the same weight amd I don’t have to carry a lot of connectors and cables because everything is embedded, included the 4G modem.

Feb 12

X files: mouse pointer starts moving by itself

Reading time: 2 – 3 minutes

It seems a jog but it’s true, after buying my Toshiba Portégé Z30-A-180 PT243 I was so proud about the performance and laptop features. By default it was running a Windows 7 and after some months of using mouse pointer started moving drawing a diagonal in the screen there wasn’t a stela just a diagonal movement and during that automatic movement there were no way to get mouse control. New Toshiba laptops has a touchpad and a trackpoint a none of them was responding while that happened. Because that only happens time to time I didn’t pay attention to the problem.

Toshiba Portégé - Trackpoint and Touchpad

Last Christmas holidays I updated the laptop to Windows 10, and I was very happy to see how 99.9% of applications and configurations was maintained and running perfectly. But after some weeks mouse pointer movements return to my life, some times very often and some times less usual. But one afternoon I was totally desperate with that issue and I decided to look it up on Google. I found a thread on Toshiba support forum where more people was talking about the same issue. Proposed solutions are not perfect but helpful for me, they talk about a static electricity problem that affects trackpoint and the best option is disable it to forget the problem. Luckly I don’t use trackpoint because for me touchpad is more confortable and disable trackpoint is good enough solution in my case.

So if you have automatic mouse movements in Toshiba Portégé Z30 disable the trackpoint, don’t forget that Toshiba refers to that device as a Accupoint. Below you have a capture of the instructions to do that:

Disable Accupoint II

Disable Accupoint

I hope this blog entry has been so helpful as it has been for me.

Jan 10

El meu 2015

Reading time: 8 – 12 minutes

Re-editant l’article que vaig escriure per tancar l’any passat aquest any també he volgut fer un resum del que ha donat de si el 2015. Per desgràcia els compromisos personals i familiars no m’han permès publicar-lo fins a principis del 2016, tot i que jo sóc dels que pensa que més val tard que mai. He tancat un nou any on he fet més coses de les que hem pensava i quan m’he posat a rellegir les meves notes diaries, setmanals, mensuals, semestrals i anuals he al·lucinat.

A nivell personal i familiar, de nou he tingut moltíssimes oportunitats pel creixement personal. Moltíssimes ocasions on m’he hagut de sobreposar per aixecar-me i tornar a creixer un cop rera d’un altre. La millor notícia de l’any és que estem esperant el Roc. El que ha de ser el germà del Pol i que ha de neixer durant el mes de Febrer. Aquesta boníssima notícia eclipsa qualsevol altre tema i ha fet de pal de paller al voltant del qual s’han desenvolupat moltíssimes decisions durant l’any.

L’any 2015 va començar amb una bona notícia el mes de febrer perquè tornavem a estar embarassats. Però a finals de març un avortament ens va fer tornar a canviar els plans i la il·lusió es va tornar a esvaïr. Per tal de trencar una mica amb aquest amarg event ens varem escapar durant una setmaneta cap a terres del sur. Varem visitar “Puerto Banús” (Marbella), Puerto de la Duquesa, Tarifa i Gibraltar. Després d’haver passat per la història del Pol això no era res, però de nou apel·lava a la nostre fortalesa emocional. En moments com aquest és quan hem sento infinitament orgullós d’estar amb una persona tan excepcional com l’Estefania. No només ens varem aixecar sinó que ara com ús dic estem apunt de donar la benvinguda al germanet del Pol, en Roc.

Per aquestes mateixes dates la meva avia de Sant Sadurní, la Carmeta, també ens va dir adéu. Era l’últim avi que hem quedava viu. Per desgràcia ja feia una colla de mesos que anava perdent la serenitat. Per si no fos poc la meva mare i el meu germà també durant els primers 5 mesos de l’any van haver de superar temes de salut rellevants. Per sort, en ambdós casos només van ser ensurts. Curiosament per aquestes dates és sempre quan es concentren esdeveniments emocionalment més importants per la família. Coincidint a més amb l’aniversari de la mort del meu pare, la història del Pol, els 12 anys del meu accident de cotxe, el tercer aniversari del nostre casament i la cel·lebració dels meus 38 anys.

També per aquestes dates varem fer una nova escapada amb els “cunyis” (Sarai i Àlex); aquest cop a la costa brava. Concretament a Calella de Palafrugell. Un d’aquests racons que per molts cops que visitis mai et canses de tornar a visitar. No ens oblidem tampoc la caminada que varem fer l’Estefania i jo per celebrar el seu aniversari, junt amb la romeria de Torrelavit, l’Anna i el Carles ens varem arribar fins a Montserrat a peu. Tot un desafiament per nosaltres.

Per desgràcia aquest any no he pogut disfrutar tan del tennis com és habitual en mi els últims anys. Una epicondilitis m’ha tingut uns quatre mesos patint sense poder disfrutar d’aquest esport que tan m’agrada. Per sort he pogut seguir amb l’spinning i també he començat a anar a la pisicina. A finals d’any degut a compromisos professionals i també els personals que ja coneixeu he hagut de deixar l’spinning aprofitant que ja podia tornar a jugar a tennis. Així doncs, s’ha acabat l’any amb alguns quilets extres que cauran ben aviat a la que reprengui la meva activitat esportiva i professional.

De nou hem continuat invertint en la casa, no tan fort com l’any passat perquè ens haviem de recuperar una miqueta però si que hem instal·lat un descalcificador a la casa, un grup d’osmosis a la cuina, hem fet una nova habitació a l’estudi, hem renovat l’WC del pis de d’alt, hem posat una nova pergola pel cotxe i nova teulada a la caseta de fusta del jardí. El millor de tot plegat és que personalment he participat força en l’execució d’aquestes d’algunes d’aquestes tasques.

Degut a l’embaraç del Roc aquest any les vacances han estat força diferents de l’habitual. Primer de tot varem fer una petita escapadeta a Puigcerdà durant un cap de setmana i després una setmaneta a Roses, bàsicament per descansar i disfrutar de la platja a més de poder estar junts com a parella. Ja que degut a la feina he passat un estiu força ocupat. Aprofitant les vacances a Roses també ens varem acostar fins a Empuria Brava per provar el Windoor que m’havia regalat l’Estefania per l’aniversari.

A nivell de creixement personal, aquest any hem tingut un creixement important a M2M Cloud Factory i ens hem començat a consolidar com a empresa, producte i amb grans i bons clients; tot això m’ha fet evolucionar moltíssim perquè l’excés de feina i l’altíssima demanda que ha tingut la feina sobre la meva energia ha estat esgotador. A més grans persones de l’empresa ens han deixat; com ara el Marc i el Pau i això encara ha augmentat més l’exigència. Però al final tot passa per algo i sempre hi ha lectures positives a tots els esdeveniments.

Tot i amb això he pogut incorporar tres noves formacions al meu currículum, un parell de cursos de comptabilitat. Un d’introducció i l’altre d’anàlisis de balanços. Però el que realment m’ha fet creixer personalment ha estat el de Management 3.0. Un curs increible, on no només se m’han obert les portes a una nova forma de fer les coses sinó també uns contactes boníssims i la possibilitat de col·laborar dins del meu departament amb un advisor excepcional, el Gabri.

Les meves rutines matutines, fent meditació a primera hora del matí; les preguntes per enfocar el dia i després fer-ne balanç i molts d’altres exercicis que heredo de la PNL, el mindfulness i d’altres disciplines m’han anat acompanyant durant tot l’any. Estic molt content del nivell de fidelitat que tinc amb totes aquestes pràctiques i sovint n’agraeixo els beneficis.

Gràcies a l’Horizon 2020 que varem guanyar l’any passat a M2MCF ens hem pogut centrar en crear un nou producte el MIIMETIQ LITE que veurà la llum ben aviat, a més d’haver creat una nova solució basada en les Smart Glasses. Mentre treiem noves versions del “framework”. Tot plegat ha tingut força repercusió a la prensa. Personalment hem van fer una entrevista al diari Ara referent a aquests temes: L’Internet de les coses: un futur a la punta dels dits.

Professionalment també he pogut tancar finalment el projecte Empowering. Més de dos anys de projecte al costat del Xavi i la gent del BEE group (CIMNE). Finalment el meu contracte va espirar el mes de setembre i vaig poder posar punt i final a aquest projecte de Big Data tan interessant i al que li desitjo el millor. A més com a consultor de l’empresa IUL, conjuntament amb l’Adrià com a part de l’equip de Nakima també hem pogut crear un parell de productes en un temps rècord i amb una orientació tecnològica molt ben enfocada cap al IoT.

Tot plegat m’ha permès tocar força tecnologies tot i que moltes d’elles ja les coneixia. Voldria destacar-ne algunes: OpenWRT, Raspbery PI, Rancher, Ambari, NodeJS, NodeRED, ESP8266, IrDA, RF, etc. Finalment també he aprofitat per canviar de portàtil i he jubilat el Mac Book Air que tenia. Tot i ser un i7 amb 4G de RAM i 256GB de SSD, el seu rendiment és ridicul al costat del Toshiba Portégé que amb el i7 de dos cossos, 16GB de RAM i 500GB d’SSD vola. Comentar que li vaig canviar el disc mSATA que portava de serie perquè no podia ser de més de 256GB. A més aquest nou portàtil té tots els ports que hem calen integrats, fins hi tot un mòdem 4G. Cosa que hem permet no haver d’anar pel món amb la maleta plena de cables.

Abans de tancar aquest resum anual afegir que aquest any he donat tres conferències. L’Àlex i la gent de la UPC van tornar a confiar amb mi perquè a inicis d’any fes de nou una conferència per la gent del FIB Alumni, aquest cop sobre la meva SmartHome. Arran d’aquesta conferència en Marc organitzador del IoT meetup de Barcelona em va demanar que la repetís en anglès per la gent del meetup. Finalment a la Garrotxa Camp també van voler que la tornés a fer.

També gràcies al Josep Maria la gent de l’Ara van voler fer-me una entrevista a tota pàgina que va sortir el dia de la diada. Sincerament hem va agradar força com van resumir la meva vida professional sense entrar en detalls. Obviament es van deixar mil coses però fer un article sobre la meva vida professional no és senzill i crec que ho van aconseguir prou bé. A més arran d’aquest article al butlletí de la gent gran de Torrelavit també hem van voler entrevistar, cosa que hem va fer molta il·lusió.

Un altre any plè de grans events, oportunitats i emocions profundes viscudes a flor de pell. Un any que varem acomiadar amb l’Àlex i Sarai (els “cunyis”) a Benifaió amb un sopar excel·lent i de forma relaxada. Abraçant aquest 2016 plè d’esperances, il·lusió i amb moltíssimes ganes de viure i estimar. Des del cor i els braços oberts de nou: GRÀCIES!!!