Showing posts with label VPS. Show all posts
Showing posts with label VPS. Show all posts

How to install OpenVZ inside a Xen VPS

0 comments

This guide should run you through how to install openvz inside centos to get another VPS running inside your main one, we will assume that you’re logged in as root, or logged in as a user and have used ‘su’ or ‘sudo -s’ to become root.
  • Updating the system
If you’re using the CentOS image from scratch you should update the OS first, because there may be some outdated packages.
Quote:-bash-3.2# yum update
Loaded plugins: fastestmirror
Determining fastest mirrors
* addons: mirror.sov.uk.goscomb.net
* base: mirror.sov.uk.goscomb.net
* extras: mirror.sov.uk.goscomb.net
* updates: mirror.as29550.net
addons | 951 B 00:00
base | 2.1 kB 00:00
extras | 2.1 kB 00:00
extras/primary_db | 188 kB 00:00
updates | 1.9 kB 00:00
updates/primary_db | 915 kB 00:00
Setting up Update Process
Resolving Dependencies
–> Running transaction check
—> Package device-mapper-multipath.i386 0:0.4.7-34.el5_5.6 set to be updated
—> Package e2fsprogs.i386 0:1.39-23.el5_5.1 set to be updated
—> Package e2fsprogs-libs.i386 0:1.39-23.el5_5.1 set to be updated
—> Package glibc.i686 0:2.5-49.el5_5.7 set to be updated
—> Package glibc-common.i386 0:2.5-49.el5_5.7 set to be updated
—> Package initscripts.i386 0:8.45.30-3.el5.centos set to be updated
—> Package kernel-xen.i686 0:2.6.18-194.32.1.el5 set to be installed
—> Package kpartx.i386 0:0.4.7-34.el5_5.6 set to be updated
—> Package krb5-libs.i386 0:1.6.1-36.el5_5.6 set to be updated
—> Package libxml2.i386 0:2.6.26-2.1.2.8.el5_5.1 set to be updated
—> Package logrotate.i386 0:3.7.4-9.el5_5.2 set to be updated
—> Package module-init-tools.i386 0:3.3-0.pre3.1.60.el5_5.1 set to be updated
—> Package nss.i386 0:3.12.8-1.el5.centos set to be updated
—> Package openldap.i386 0:2.3.43-12.el5_5.3 set to be updated
—> Package openssl.i686 0:0.9.8e-12.el5_5.7 set to be updated
—> Package pam.i386 0:0.99.6.2-6.el5_5.2 set to be updated
—> Package perl.i386 4:5.8.8-32.el5_5.2 set to be updated
—> Package python.i386 0:2.4.3-27.el5_5.3 set to be updated
—> Package rsyslog.i386 0:3.22.1-3.el5_5.1 set to be updated
extras/filelists_db | 197 kB 00:00
updates/filelists_db | 4.1 MB 00:01
–> Finished Dependency Resolution
–> Running transaction check
—> Package kernel-xen.i686 0:2.6.18-164.el5 set to be erased
–> Finished Dependency Resolution
Dependencies Resolved
================================================================================​================================================================================​===========================================================
Package Arch Version Repository Size
================================================================================​================================================================================​===========================================================
Installing:
kernel-xen i686 2.6.18-194.32.1.el5 updates 18 M
Updating:
device-mapper-multipath i386 0.4.7-34.el5_5.6 updates 2.8 M
e2fsprogs i386 1.39-23.el5_5.1 updates 977 k
e2fsprogs-libs i386 1.39-23.el5_5.1 updates 118 k
glibc i686 2.5-49.el5_5.7 updates 5.3 M
glibc-common i386 2.5-49.el5_5.7 updates 16 M
initscripts i386 8.45.30-3.el5.centos updates 1.6 M
kpartx i386 0.4.7-34.el5_5.6 updates 420 k
krb5-libs i386 1.6.1-36.el5_5.6 updates 663 k
libxml2 i386 2.6.26-2.1.2.8.el5_5.1 updates 795 k
logrotate i386 3.7.4-9.el5_5.2 updates 41 k
module-init-tools i386 3.3-0.pre3.1.60.el5_5.1 updates 426 k
nss i386 3.12.8-1.el5.centos updates 1.1 M
openldap i386 2.3.43-12.el5_5.3 updates 295 k
openssl i686 0.9.8e-12.el5_5.7 updates 1.4 M
pam i386 0.99.6.2-6.el5_5.2 updates 980 k
perl i386 4:5.8.8-32.el5_5.2 updates 12 M
python i386 2.4.3-27.el5_5.3 updates 5.9 M
rsyslog i386 3.22.1-3.el5_5.1 updates 380 k
Removing:
kernel-xen i686 2.6.18-164.el5 installed 43 M
Transaction Summary
================================================================================​================================================================================​===========================================================
Install 1 Package(s)
Upgrade 18 Package(s)
Remove 1 Package(s)
Reinstall 0 Package(s)
Downgrade 0 Package(s)
Total download size: 69 M
Is this ok [y/N]: y
Downloading Packages:
(1/19): logrotate-3.7.4-9.el5_5.2.i386.rpm | 41 kB 00:00
(2/19): e2fsprogs-libs-1.39-23.el5_5.1.i386.rpm | 118 kB 00:00
(3/19): openldap-2.3.43-12.el5_5.3.i386.rpm | 295 kB 00:00
(4/19): rsyslog-3.22.1-3.el5_5.1.i386.rpm | 380 kB 00:00
(5/19): kpartx-0.4.7-34.el5_5.6.i386.rpm | 420 kB 00:00
(6/19): module-init-tools-3.3-0.pre3.1.60.el5_5.1.i386.rpm | 426 kB 00:00
(7/19): krb5-libs-1.6.1-36.el5_5.6.i386.rpm | 663 kB 00:00
(8/19): libxml2-2.6.26-2.1.2.8.el5_5.1.i386.rpm | 795 kB 00:00
(9/19): e2fsprogs-1.39-23.el5_5.1.i386.rpm | 977 kB 00:00
(10/19): pam-0.99.6.2-6.el5_5.2.i386.rpm | 980 kB 00:00
(11/19): nss-3.12.8-1.el5.centos.i386.rpm | 1.1 MB 00:00
(12/19): openssl-0.9.8e-12.el5_5.7.i686.rpm | 1.4 MB 00:00
(13/19): initscripts-8.45.30-3.el5.centos.i386.rpm | 1.6 MB 00:02
(14/19): device-mapper-multipath-0.4.7-34.el5_5.6.i386.rpm | 2.8 MB 00:01
(15/19): glibc-2.5-49.el5_5.7.i686.rpm | 5.3 MB 00:03
(16/19): python-2.4.3-27.el5_5.3.i386.rpm | 5.9 MB 00:03
(17/19): perl-5.8.8-32.el5_5.2.i386.rpm | 12 MB 00:02
(18/19): glibc-common-2.5-49.el5_5.7.i386.rpm | 16 MB 00:05
(19/19): kernel-xen-2.6.18-194.32.1.el5.i686.rpm | 18 MB 00:06
—————————————————————————————————————————————————————————————————————————
Total 2.0 MB/s | 69 MB 00:34
Running rpm_check_debug
Running Transaction Test
Finished Transaction Test
Transaction Test Succeeded
Running Transaction
Updating : glibc-common 1/39
Updating : glibc 2/39
Updating : e2fsprogs-libs 3/39
Updating : module-init-tools 4/39
Updating : krb5-libs 5/39
Updating : openssl 6/39
Updating : e2fsprogs 7/39
Updating : logrotate 8/39
Updating : rsyslog 9/39
Updating : initscripts 10/39
Updating : python 11/39
Updating : openldap 12/39
Updating : pam 13/39
Updating : perl 14/39
Updating : libxml2 15/39
Updating : nss 16/39
Updating : kpartx 17/39
Updating : device-mapper-multipath 18/39
Installing : kernel-xen 19/39
Cleanup : python 20/39
Cleanup : krb5-libs 21/39
Cleanup : openldap 22/39
Cleanup : glibc 23/39
Cleanup : glibc 24/39
Cleanup : pam 25/39
Cleanup : e2fsprogs-libs 26/39
Cleanup : perl 27/39
Cleanup : module-init-tools 28/39
Cleanup : libxml2 29/39
Cleanup : rsyslog 30/39
Cleanup : initscripts 31/39
Cleanup : device-mapper-multipath 32/39
Cleanup : nss 33/39
Cleanup : kpartx 34/39
Cleanup : logrotate 35/39
Cleanup : e2fsprogs 36/39
Cleanup : glibc-common 37/39
Cleanup : openssl 38/39
Cleanup : kernel-xen 39/39
Removed:
kernel-xen.i686 0:2.6.18-164.el5
Installed:
kernel-xen.i686 0:2.6.18-194.32.1.el5
Updated:
device-mapper-multipath.i386 0:0.4.7-34.el5_5.6 e2fsprogs.i386 0:1.39-23.el5_5.1 e2fsprogs-libs.i386 0:1.39-23.el5_5.1 glibc.i686 0:2.5-49.el5_5.7 glibc-common.i386 0:2.5-49.el5_5.7
initscripts.i386 0:8.45.30-3.el5.centos kpartx.i386 0:0.4.7-34.el5_5.6 krb5-libs.i386 0:1.6.1-36.el5_5.6 libxml2.i386 0:2.6.26-2.1.2.8.el5_5.1 logrotate.i386 0:3.7.4-9.el5_5.2
module-init-tools.i386 0:3.3-0.pre3.1.60.el5_5.1 nss.i386 0:3.12.8-1.el5.centos openldap.i386 0:2.3.43-12.el5_5.3 openssl.i686 0:0.9.8e-12.el5_5.7 pam.i386 0:0.99.6.2-6.el5_5.2
perl.i386 4:5.8.8-32.el5_5.2 python.i386 0:2.4.3-27.el5_5.3 rsyslog.i386 0:3.22.1-3.el5_5.1
Complete!
  • Install OpenVZ
    • Edit settings in /etc/sysctl.conf
      Quote:-bash-3.2# nano /etc/sysctl.conf
    • Change the following two options:
      Quote:net.ipv4.ip_forward = 1
      kernel.sysrq = 1
    • Add the section below:
      Quote:net.ipv4.conf.default.proxy_arp = 0
      net.ipv4.conf.all.rp_filter = 1
      net.ipv4.conf.default.send_redirects = 1
      net.ipv4.conf.all.send_redirects = 0
  • Install some additional required packages:
    Quote:yum -y install mkinitrd ed rsync
    Loaded plugins: fastestmirror
    Loading mirror speeds from cached hostfile
    * addons: mirror.sov.uk.goscomb.net
    * base: mirror.sov.uk.goscomb.net
    * extras: mirror.sov.uk.goscomb.net
    * updates: mirror.as29550.net
    Setting up Install Process
    Package mkinitrd-5.1.19.6-61.el5_5.2.i386 already installed and latest version
    Resolving Dependencies
    –> Running transaction check
    —> Package ed.i386 0:0.2-39.el5_2 set to be updated
    —> Package rsync.i386 0:2.6.8-3.1 set to be updated
    –> Finished Dependency Resolution
    Dependencies Resolved
    ================================================================================​================================================================================​===========================================================
    Package Arch Version Repository Size
    ================================================================================​================================================================================​===========================================================
    Installing:
    ed i386 0.2-39.el5_2 base 45 k
    rsync i386 2.6.8-3.1 base 230 k
    Transaction Summary
    ================================================================================​================================================================================​===========================================================
    Install 2 Package(s)
    Upgrade 0 Package(s)
    Total download size: 275 k
    Downloading Packages:
    (1/2): ed-0.2-39.el5_2.i386.rpm | 45 kB 00:00
    (2/2): rsync-2.6.8-3.1.i386.rpm | 230 kB 00:00
    —————————————————————————————————————————————————————————————————————————
    Total 2.6 MB/s | 275 kB 00:00
    Running rpm_check_debug
    Running Transaction Test
    Finished Transaction Test
    Transaction Test Succeeded
    Running Transaction
    Installing : ed 1/2
    Installing : rsync 2/2
    Installed:
    ed.i386 0:0.2-39.el5_2 rsync.i386 0:2.6.8-3.1
    Complete!
  • Download the required kernel:
    Quote:-bash-3.2# wget http://download.openvz.org/kernel/branch…2.i686.rpm
    –2011-01-17 14:32:40– http://download.openvz.org/kernel/branch…2.i686.rpm
    Resolving download.openvz.org… 64.131.90.11
    Connecting to download.openvz.org|64.131.90.11|:80… connected.
    HTTP request sent, awaiting response… 200 OK
    Length: 23863688 (23M) [application/x-rpm]
    Saving to: `ovzkernel-xen-2.6.18-194.26.1.el5.028stab079.2.i686.rpm’
    100%[================================================================================​================================================================================​=================>] 23,863,688 6.62M/s in 4.3s
    2011-01-17 14:32:44 (5.31 MB/s) – `ovzkernel-xen-2.6.18-194.26.1.el5.028stab079.2.i686.rpm’ saved [23863688/23863688]
  • Download OpenVZ utilities:
    Quote:-bash-3.2# wget http://download.openvz.org/utils/vzctl/c…1.i386.rpmhttp://download.openvz.org/utils/vzctl/c…1.i386.rpmhttp://download.openvz.org/utils/vzquota…1.i386.rpm
    –2011-01-17 14:34:06– http://download.openvz.org/utils/vzctl/c…1.i386.rpm
    Resolving download.openvz.org… 64.131.90.11
    Connecting to download.openvz.org|64.131.90.11|:80… connected.
    HTTP request sent, awaiting response… 200 OK
    Length: 159855 (156K) [application/x-rpm]
    Saving to: `vzctl-3.0.25.1-1.i386.rpm’
    100%[================================================================================​================================================================================​=================>] 159,855 398K/s in 0.4s
    2011-01-17 14:34:06 (398 KB/s) – `vzctl-3.0.25.1-1.i386.rpm’ saved [159855/159855]
    –2011-01-17 14:34:06– http://download.openvz.org/utils/vzctl/c…1.i386.rpm
    Connecting to download.openvz.org|64.131.90.11|:80… connected.
    HTTP request sent, awaiting response… 200 OK
    Length: 185781 (181K) [application/x-rpm]
    Saving to: `vzctl-lib-3.0.25.1-1.i386.rpm’
    100%[================================================================================​================================================================================​=================>] 185,781 460K/s in 0.4s
    2011-01-17 14:34:07 (460 KB/s) – `vzctl-lib-3.0.25.1-1.i386.rpm’ saved [185781/185781]
    –2011-01-17 14:34:07– http://download.openvz.org/utils/vzquota…1.i386.rpm
    Connecting to download.openvz.org|64.131.90.11|:80… connected.
    HTTP request sent, awaiting response… 200 OK
    Length: 83539 (82K) [application/x-rpm]
    Saving to: `vzquota-3.0.12-1.i386.rpm’
    100%[================================================================================​================================================================================​=================>] 83,539 261K/s in 0.3s
    2011-01-17 14:34:07 (261 KB/s) – `vzquota-3.0.12-1.i386.rpm’ saved [83539/83539]
    FINISHED –2011-01-17 14:34:07–
    Downloaded: 3 files, 419K in 1.1s (382 KB/s)
  • Install the downloaded packages:
    Quote:-bash-3.2# rpm -ivh ovzkernel-xen-2.6.18-194.26.1.el5.028stab079.2.i686.rpm
    warning: ovzkernel-xen-2.6.18-194.26.1.el5.028stab079.2.i686.rpm: Header V3 DSA signature: NOKEY, key ID a7a1d4b6
    Preparing… ########################################### [100%]
    1:ovzkernel-xen ########################################### [100%]
    Quote:-bash-3.2# rpm -ivh vzquota-* vzctl-*
    warning: vzquota-3.0.12-1.i386.rpm: Header V3 DSA signature: NOKEY, key ID a7a1d4b6
    Preparing… ########################################### [100%]
    1:vzctl-lib ########################################### [ 33%]
    2:vzquota ########################################### [ 67%]
    3:vzctl ########################################### [100%]
  • You’ll need a template for the operating system you’ll install, here is a link to a list of available templates.OpenVZ Templates
  • You should put the template you choose in the /vz/templates/cache folder, here’s an example.
    Quote:-bash-3.2# wget http://download.openvz.org/template/prec…x86.tar.gz -O /vz/template/cache/debian-5.0-x86.tar.gz
    –2011-01-17 14:39:48– http://download.openvz.org/template/prec…x86.tar.gz
    Resolving download.openvz.org… 64.131.90.11
    Connecting to download.openvz.org|64.131.90.11|:80… connected.
    HTTP request sent, awaiting response… 200 OK
    Length: 138639961 (132M) [application/x-gzip]
    Saving to: `/vz/template/cache/debian-5.0-x86.tar.gz’
    100%[================================================================================​================================================================================​=================>] 138,639,961 4.38M/s in 23s
    2011-01-17 14:40:12 (5.68 MB/s) – `/vz/template/cache/debian-5.0-x86.tar.gz’ saved [138639961/138639961]
  • You should then edit your grub (bootloader) config file and change default to 0 to boot the first kernel in the list.
    Quote:-bash-3.2# nano /boot/grub/grub.conf
    default=0
  • Now reboot the system into the new kernel
    Quote:-bash-3.2# reboot
  • Once the system has rebooted you can log back in and we can create our VPS.
  • Create your first VPS
  • You would use this command to create a VPS: vzctl create ID –ostemplate OSTEMPLATE –ipadd IPADDRESS –hostname HOSTNAME
    Quote:-bash-3.2# vzctl create 101 –ostemplate debian-5.0-x86 –ipadd 172.16.0.21 –hostname demosys.allsimple.net
    Creating container private area (debian-5.0-x86)
    Performing postcreate actions
    Container private area was created
  • You may want to set some of the following
    • Set a reasonable disk space limit on the vps
      Quote:-bash-3.2# vzctl set 101 –diskspace 10G –save
    • Set the VPS to start at boot up
      Quote:-bash-3.2# vzctl set 101 –onboot yes –save
    • Set a root password
      Quote:-bash-3.2# vzctl set 101 –userpasswd root:newpassword
    • Setting memory limits, (this is my understanding from a brief read about OpenVZ Memory)
      • privvmpages – Burstable memory
    • Set the above memory limits
      Quote:-bash-3.2# vzctl set 101 –save –privvmpages 128M
      Saved parameters for CT 101
  • Start the VPS
    Quote:-bash-3.2# vzctl start 101
    Starting container …
    Container is mounted
    Adding IP address(es): 172.16.0.21
    Setting CPU units: 1000
    Set hostname: demosys.allsimple.net
    Container start in progress…
  • It looks like the VPS started correct, you can log in directly to the VPS using OpenVZ below:
    Quote:-bash-3.2# vzctl enter 101
    entered into CT 101
    demosys:/# w
    23:13:03 up 1 min, 0 users, load average: 0.05, 0.02, 0.00
    USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
    demosys:/# free -m
    total used free shared buffers cached
    Mem: 128 10 117 0 0 0
    -/+ buffers/cache: 10 117
    Swap: 0 0 0
    demosys:/# exit
    logout
    exited from CT 101
    -bash-3.2#
  • Now you have a VPS running on the IP address 172.16.0.21, you should be able to access it via IP.
    Quote:-bash-3.2# ping -c1 172.16.0.21
    PING 172.16.0.21 (172.16.0.21) 56(84) bytes of data.
    64 bytes from 172.16.0.21: icmp_seq=1 ttl=64 time=0.025 ms
    — 172.16.0.21 ping statistics —
    1 packets transmitted, 1 received, 0% packet loss, time 0ms
    rtt min/avg/max/mdev = 0.025/0.025/0.025/0.000 ms
If you’re using internal IP addresses you would need to use port forwarding or something to access services, I’ve not tested this with public IP’s but I would assume it should work.
Please report any errors, and note that there may be better ways to do some of the OpenVZ configuration above. We don’t regularly use OpenVZ and it seemed a better option for running inside a VPS due to the way it runs.

Install OpenVPN on a Debian/Ubuntu VPS

0 comments


To install issue the following commands logged in as root on your VPS (Refer to this post if you are facing any issues)
wget http://vpsnoc.com/scripts/debian-openvpn.sh
chmod +x debian-openvpn.sh
./debian-openvpn.sh
For any other issues and feedback please e-mail us at support@vpsnoc.com
You may use and modify this script however you see fit, provided that you do not edit the original copyright.
#!/bin/bash
# Quick and dirty OpenVPN install script
# Tested on debian 5.0 32bit, openvz minimal debian OS template
# and Ubuntu 9.04 32 bit minimal, should work on 64bit images as well
# Please submit feedback and questions at support@vpsnoc.com
# John Malkowski vpsnoc.com 01/18/2010
ip=`grep address /etc/network/interfaces | grep -v 127.0.0.1  | awk '{print $2}'`
apt-get update
apt-get install openvpn libssl-dev  openssl
cd /etc/openvpn/
cp -R /usr/share/doc/openvpn/examples/easy-rsa/ /etc/openvpn/
cd /etc/openvpn/easy-rsa/2.0/
chmod +rwx *
. ./vars
./clean-all
source ./vars
echo -e "\n\n\n\n\n\n\n" | ./build-ca
clear
echo "####################################"
echo "Feel free to accept default values"
echo "Wouldn't recommend setting a password here"
echo "Then you'd have to type in the password each time openVPN starts/restarts"
echo "####################################"
./build-key-server server
./build-dh
cp keys/{ca.crt,ca.key,server.crt,server.key,dh1024.pem} /etc/openvpn/

clear
echo "####################################"
echo "Feel free to accept default values"
echo "This is your client key, you may set a password here but it's not required"
echo "####################################"
./build-key client1
cd keys/
client="
client
remote $ip 1194
dev tun
comp-lzo
ca ca.crt
cert client1.crt
key client1.key
route-delay 2
route-method exe
redirect-gateway def1
dhcp-option DNS 10.8.0.1
verb 3"
echo "$client" > $HOSTNAME.ovpn
tar czf keys.tgz ca.crt ca.key client1.crt client1.csr client1.key $HOSTNAME.ovpn
mv keys.tgz /root

opvpn='
dev tun
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
push "route 10.8.0.0 255.255.255.0"
push "redirect-gateway"
comp-lzo
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
group daemon
daemon'
echo "$opvpn" > /etc/openvpn/openvpn.conf
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o venet0 -j MASQUERADE
iptables-save > /etc/iptables.conf
echo "#!/bin/sh" > /etc/network/if-up.d/iptables
echo "iptables-restore < /etc/iptables.conf" >> /etc/network/if-up.d/iptables
chmod +x /etc/network/if-up.d/iptables
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
/etc/init.d/openvpn start
clear
echo "OpenVPN has been installed
Download /root/keys.tgz using winscp or other sftp/scp client such as filezilla
Create a directory named vpn at C:\Program Files\OpenVPN\config\ and untar the content of keys.tgz there
Start openvpn-gui, right click the tray icon go to vpn and click connect
For support/bug reports email us at support@vpsnoc.com"

Setup a VPN server on a CentOS VPS

0 comments

We have made a small and dirty bash script which installs and configures OpenVPN on CentOS 5 32bit. The VPN server’s primary (and only) use is for safe browsing i.e. tunneling all your traffic through your VPS. The script also generates your client configuration file along with the necessary keys for authentication.
Requirements
1. CentOS 5 32bit minimal OS template
2. TUN/TAP device enabled on your VPS
3. iptables NAT support
You will have to open a ticket to request a TUN/TAP device to be enabled on your VPS. If you’re not a customer of ours and your host’s support staff doesn’t know how to do this, you may tell them to execute the following commands on the hardware node where your VPS is hosted.

vzctl stop YOUR_VEID
vzctl set YOUR_VEID --devices c:10:200:rw --save
vzctl set YOUR_VEID --capability net_admin:on --save
vzctl start YOUR_VEID
vzctl exec YOUR_VEID "mkdir -p /dev/net; mknod /dev/net/tun c 10 200; chmod 600 /dev/net/tun"
# iptables support
vzctl stop YOUR_VEID
vzctl set YOUR_VEID --iptables ipt_REJECT --iptables ipt_tos --iptables ipt_TOS --iptables ipt_LOG --iptables ip_conntrack --iptables ipt_limit --iptables ipt_multiport --iptables iptable_filter --iptables iptable_mangle --iptables ipt_TCPMSS --iptables ipt_tcpmss --iptables ipt_ttl --iptables ipt_length --iptables ipt_state --iptables iptable_nat --iptables ip_nat_ftp --save
vzctl start YOUR_VEID

Make sure they will replace ‘YOUR_VEID’ with your VPS’s VEID and you will be ready to roll
Login to your VPS as root and execute the following commands

wget http://vpsnoc.com/scripts/install-openvpn.sh
chmod +x install-openvpn.sh
./install-openvpn.sh

You will be prompted to enter values for your server and client certificate, feel free to accept (hit enter) the default values. Its not recommended to setup a password for your server certificate as you will have to type in the password each time you wish to start/restart the openvpn daemon.
You can however set a password for your client’s certificate since it offers extra level of protection in case your certificate and key files are compromised. You will be prompted for that password each time you connect on your VPS’s VPN.
After the script finished installing openvpn (should be very quick) the client keys and the openvpn clientconfiguration file will be archived in /root/keys.tgz
You may use a sftp/scp client such as winscp or filezilla to download the archive on your computer.
If you already haven’t installed openvpn for windows you may do so now.
You may use winrar or 7zip to extract the content of keys.tgz in C:\Program Files\OpenVPN\config\VPN (create a folder named VPN there)
After you have extracted the files from keys.tgz in the above folder, you may start openvpn-gui from the start menu, right click the tray icon, go to VPN and click connect. After the icon turns green all your traffic will be forwarded through your VPS, no extra configuration on your browser/IM client/email client is required.
If you’re facing issues make sure that your computer clock is synchronized, if so make sure that your VPS’s clock is correct as well. If it’s not you will have to ask your host to sync it.
For any other issues and feedback please e-mail us at support@vpsnoc.com
You may use and modify this script however you see fit, provided that you do not edit the original copyright.

#!/bin/bash
# Quick and dirty OpenVPN install script
# Tested on Centos 5.x 32bit, openvz minimal CentOS OS templates
# Please submit feedback and questions at support@vpsnoc.com
# John Malkowski vpsnoc.com 01/04/2010
ip=`grep IPADDR /etc/sysconfig/network-scripts/ifcfg-venet0:0 | awk -F= '{print $2}'`
wget http://packages.sw.be/rpmforge-release/rpmforge-release-0.3.6-1.el5.rf.i386.rpm
rpm -iv rpmforge-release-0.3.6-1.el5.rf.i386.rpm
rm -rf rpmforge-release-0.3.6-1.el5.rf.i386.rpm
yum -y install openvpn openssl openssl-devel
cd /etc/openvpn/
cp -R /usr/share/doc/openvpn-2.0.9/easy-rsa/ /etc/openvpn/
cd /etc/openvpn/easy-rsa/2.0/
chmod +rwx *
. ../vars
./clean-all
source ./vars
echo -e "\n\n\n\n\n\n\n" | ./build-ca
clear
echo "####################################"
echo "Feel free to accept default values"
echo "Wouldn't recommend setting a password here"
echo "Then you'd have to type in the password each time openVPN starts/restarts"
echo "####################################"
./build-key-server server
./build-dh
cp keys/{ca.crt,ca.key,server.crt,server.key,dh1024.pem} /etc/openvpn/
clear
echo "####################################"
echo "Feel free to accept default values"
echo "This is your client key, you may set a password here but it's not required"
echo "####################################"
./build-key client1
cd keys/
client="
client
remote $ip 1194
dev tun
comp-lzo
ca ca.crt
cert client1.crt
key client1.key
route-delay 2
route-method exe
redirect-gateway def1
dhcp-option DNS 10.8.0.1
verb 3"

echo "$client" > $HOSTNAME.ovpn
tar czf keys.tgz ca.crt ca.key client1.crt client1.csr client1.key $HOSTNAME.ovpn
mv keys.tgz /root
opvpn='
dev tun
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
push "route 10.8.0.0 255.255.255.0"
push "redirect-gateway"
comp-lzo
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
group nobody
daemon'
echo "$opvpn" > /etc/openvpn/openvpn.conf
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o venet0 -j MASQUERADE
iptables-save > /etc/sysconfig/iptables
sed -i 's/eth0/venet0/g' /etc/sysconfig/iptables # dirty vz fix for iptables-save
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
/etc/init.d/openvpn start
clear
echo "OpenVPN has been installed
Download /root/keys.tgz using winscp or other sftp/scp client such as filezilla
Create a directory named vpn at C:\Program Files\OpenVPN\config\ and untar the content of keys.tgz there
Start openvpn-gui, right click the tray icon go to vpn and click connect
For support/bug reports email us at support@vpsnoc.com"

How To CreateHow To Create OpenVZ Virtual Machines (VPS) OpenVZ Virtual Machines (VPS)

1 comments
How do I create OpenVZ virtual machine (VPS) to run CentOS or Debian as VPS?

OpenVZ comes with a template for each VPS or virtual machine. OpenVZ provides templates for all leading Linux distributions. You need to download those templates in order to create a VPS. Visit this page to grab templates for vps.

Download Ubuntu Linux VPS

Type the following commands to download precreated Ubuntu Linux template:
# cd /vz/template/cache
# wget http://download.openvz.org/template/precreated/ubuntu-9.04-x86_64.tar.gz

Download CentOS 64 bit template:
# cd /vz/template/cache
# wget http://download.openvz.org/template/precreated/centos-5-x86_64.tar.gz

Create VPS

Now you’ve download the template for your virtual machine. You can just start a VPS based on the template you have just downloaded, by typing the following commands:  [10 is VPS ID you can use as per your requirement]
vzctl create 10 –ostemplate ubuntu-9.04-x86_64
vzctl set 10 –onboot yes –save

***  Set IP for VPS ***
vzctl set 10 –ipadd 192.168.1.5 –save

*** Set Nameservers IP for VPS ***
vzctl set 10 –nameserver 192.168.1.111 –save
vzctl set 10 –nameserver 192.168.1.111 –save

*** Set Hostname IP for VPS ***
vzctl set 10 –hostname ourlinuxblog.wordpress.com –save

*** Set Disk quota for VPS (10G min [soft] and 11G max hard limit) ***
vzctl set 10 –diskspace 10G:11G –save

*** Okay lets the vps ***
vzctl start 10

***  Set root user password for VPS ***
vzctl exec 10 passwd

vzctl is used to create and set various vps properties such as memory, disk usage and much more. Where,

  • create 10 : Your VPS ID.

  • –ostemplate ubuntu-9.04-x86_64 : VPS template.

  • –config vps.ubuntu: Save configuration.

  • set 10 : Set various option for VPS ID # 10.

  • –onboot yes : Make sure VPS boots automatically after a reboot.

  • –save : Save changes to config file.


Common OpenVZ Admin Tasks

vzctl act as a master tool for various tasks:

How Do I Set VPS Name to ourlinuxblog.wordpress.com ?
# vzctl set 10 –hostname ourlinuxblog.wordpress.com –save

How Do I Set VPS IP Address?
# vzctl set 10 –ipadd 74.86.48.99 –save

How Do I Set VPS DNS Name Servers?
# vzctl set 10 –nameserver 10.0.1.11 –save

How Do I Set Disk Quota?
# vzctl set 10 –diskspace SoftLimitG:HardLimitG –save

# vzctl set 10 –diskspace 10G:12G –save

How Do I Stop / Start / Restart VPS Servers?
# vzctl start 10
# vzctl restart 10
# vzctl stop 10

How Do I Run a Command For VPS?

You can run command as follows
# vzctl exec 10 w
# vzctl exec 10 df
# vzctl exec 10 date
# vzctl exec 10 ps aux

How Do I Login Into VPS Server (container)?
# vzctl enter 10

How Do I Delete VPS?

Type the following command to delete VPS:
# vzctl destroy 10

How to add nameservers from shell

3 comments

Most of the time on cPanel dedicated server we add nameservers from WHM but some time we are not able to access WHM. In that case we can add nameservers from shell by using root login details.


Login in to server as root user and run following commands.

root@server[~]#/scripts/adddns –domain ns1.your_domain.com –ip=174.222.222.1


root@server[~]#/scripts/adddns –domain ns2.your_domain.com –ip=174.222.222.2


You can use your domain name instead of your_domain.com in above command with the respective ips which you want to use for your nameservers.


root@server[~]#service named restart

or

root@server[~]#/etc/init.d/named restart

Looking for a free server load monitoring utility which will email you about the load on the server on a frequent interval ?

0 comments
CRONJOB is the Answer …..

create a cronjob from the uptime command if thats all you need.

crontab -e
* */1 * * * (cd /usr/bin; ./uptime 2>&1 | mail -s “System load” your.email.com)

The above example will email the load and uptime to you every hour. “System load” is the email subject and of course change your email to your real address.

You can mail yourself a report the same way with any command you like such as netstat, ps and top or anything you like.

How to Change Cron Time on VPS cPanel

0 comments

I was trying to change our server cron timings which is usually set at 1AM. But when you change your server time to match your own local time, the Cron activities still continue at 1AM.  So how can you change the cron timing on your VPS Cpanel?


1. Go to WHM >> cPanel >> Manage Plugins


2. Install the cronconfig cPanel plugin which allow users to edit cPanel cron settings/program run times.


cronconfig plugin


3. Now refresh the WHM, you will find the plugin option loaded in the bottom of the left panel.


cron-plugin


4. Set Cron time – WHM >> Plugins >> Configure cPanel Cron Times


cronconfig options


upcp is the program that updates cPanel and it is recommended to run this script once a day. It has, by default, been set to a random time between 9pm and 6am local time. cpbackupcpbackup is the program used to run backups on your server and set by default to run at 1am. However, it is a good idea to set these cron jobs to run at an off peak time of your site.


Setting cron time – Remember the Hour is always set in military time;  Day set to 15 means 15th day of the month; Month is coded as 1=January and 12=December; and weekdays are noted as 0=Sunday and 6=Saturday.


Here is what sample settings mean – Minute = 47; Hour = 1; Day = *; Month = *; Weekday = *. This process would run everyday at 01:47AM.  Have you set you server cron functions at non peak hours?


Go_GrEen^ThiNk_GReeN~LoVE_GreEn - Pushkar

How to Change Cron Time on VPS cPanel

0 comments

I was trying to change our server cron timings which is usually set at 1AM. But when you change your server time to match your own local time, the Cron activities still continue at 1AM.  So how can you change the cron timing on your VPS Cpanel?


1. Go to WHM >> cPanel >> Manage Plugins


2. Install the cronconfig cPanel plugin which allow users to edit cPanel cron settings/program run times.


cronconfig plugin


3. Now refresh the WHM, you will find the plugin option loaded in the bottom of the left panel.


cron-plugin


4. Set Cron time – WHM >> Plugins >> Configure cPanel Cron Times


cronconfig options


upcp is the program that updates cPanel and it is recommended to run this script once a day. It has, by default, been set to a random time between 9pm and 6am local time. cpbackupcpbackup is the program used to run backups on your server and set by default to run at 1am. However, it is a good idea to set these cron jobs to run at an off peak time of your site.


Setting cron time – Remember the Hour is always set in military time;  Day set to 15 means 15th day of the month; Month is coded as 1=January and 12=December; and weekdays are noted as 0=Sunday and 6=Saturday.


Here is what sample settings mean – Minute = 47; Hour = 1; Day = *; Month = *; Weekday = *. This process would run everyday at 01:47AM.  Have you set you server cron functions at non peak hours?


Go_GrEen^ThiNk_GReeN~LoVE_GreEn - Pushkar