Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178680 > unrolled thread

Guide(s?) to backup philosophies

Started byRichard Owlett <rowlett@cloud85.net>
First post2017-03-11 16:20 +0100
Last post2017-03-19 11:40 +0100
Articles 20 on this page of 45 — 18 participants

Back to article view | Back to linux.debian.user


Contents

  Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-11 16:20 +0100
    Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-11 22:10 +0100
      Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-13 14:00 +0100
        Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:00 +0100
          Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-17 11:50 +0100
            Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-17 19:50 +0100
            Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-18 06:20 +0100
              Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 11:50 +0100
                Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 11:50 +0100
                  Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 13:20 +0100
                    Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 13:30 +0100
                      Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:30 +0100
                        Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-23 11:10 +0100
                          Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 13:10 +0100
                Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 04:00 +0100
                  Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:40 +0100
                    Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 20:10 +0100
          Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 14:10 +0200
            Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 23:20 +0200
            Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) Nathan Dorfman <ndorf@rtfm.net> - 2017-04-01 11:00 +0200
          should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) cbannister@slingshot.co.nz - 2017-03-31 14:10 +0200
            Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 14:20 +0200
              Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) Brian <ad44@cityscape.co.uk> - 2017-03-31 15:20 +0200
                Re: should I firewall an open port which isn't used? (was ... Re:  Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 15:30 +0200
                Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:30 +0200
                  Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:50 +0200
        Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-14 19:00 +0100
          Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 19:20 +0100
            Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:20 +0100
              Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 21:40 +0100
                Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 13:30 +0100
                  Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-15 14:10 +0100
                    Re: Guide(s?) to backup philosophies "Martin McCormick" <martin.m@suddenlink.net> - 2017-03-15 14:30 +0100
                    Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
                  Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
                  Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 21:50 +0100
                    Re: Guide(s?) to backup philosophies songbird <songbird@anthive.com> - 2017-03-16 23:50 +0100
          Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:10 +0100
    Re: Guide(s?) to backup philosophies Joe <joe@jretrading.com> - 2017-03-11 23:30 +0100
      Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 13:30 +0100
    Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-13 15:20 +0100
      Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:10 +0100
      Re: Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-14 15:50 +0100
    Re: Guide(s?) to backup philosophies Merlin Büge <toni@bluenox07.de> - 2017-03-14 19:50 +0100
    Re: Guide(s?) to backup philosophies DdB <debianlist@potentially-spam.de-bruyn.de> - 2017-03-19 11:40 +0100

Page 1 of 3  [1] 2 3  Next page →


#178680 — Guide(s?) to backup philosophies

FromRichard Owlett <rowlett@cloud85.net>
Date2017-03-11 16:20 +0100
SubjectGuide(s?) to backup philosophies
Message-ID<tjQYh-4AT-7@gated-at.bofh.it>
I've been good about telling others that backups are a good idea.
Guess who hadn't and then crashed his system and spent hours putting 
things back together ;<

In the past individual projects ended up on individual flash drives as I 
was frequently using different machines. I now have some reliable 
hardware and a large internal hard drive.

I have one partition that might be called a "production" environment, 
i.e. fairly stable and has the most valuable content.
A second partition hosts my experiments - I've a project to create an 
optimal install. The third is the target of those experimental installs 
whose content doesn't rate explicit backups. The scripts for creating 
those installs being on the second partition.

I've vague ideas of what backup pattern(s) I might follow.
I'm looking for reading materials that might trigger "I hadn't thought 
of that" moments.

Suggestions?
TIA

[toc] | [next] | [standalone]


#178692

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2017-03-11 22:10 +0100
Message-ID<tjWr0-8sd-17@gated-at.bofh.it>
In reply to#178680
On 03/11/2017 07:10 AM, Richard Owlett wrote:
> I've been good about telling others that backups are a good idea.
> Guess who hadn't and then crashed his system and spent hours putting
> things back together ;<
>
> In the past individual projects ended up on individual flash drives as I
> was frequently using different machines. I now have some reliable
> hardware and a large internal hard drive.
>
> I have one partition that might be called a "production" environment,
> i.e. fairly stable and has the most valuable content.
> A second partition hosts my experiments - I've a project to create an
> optimal install. The third is the target of those experimental installs
> whose content doesn't rate explicit backups. The scripts for creating
> those installs being on the second partition.
>
> I've vague ideas of what backup pattern(s) I might follow.
> I'm looking for reading materials that might trigger "I hadn't thought
> of that" moments.
>
> Suggestions?

[1] is a decent overview:

http://shop.oreilly.com/product/9780596102463.do


After that, it's a matter of what systems you have, what tools you pick, 
and how to best utilize them.


David



References:

[1] W. Curtis Preston, 2007, "Backup & Recovery Inexpensive Backup 
Solutions for Open Systems", O'Reilly Media, ISBN: 978-0-596-10246-3

[toc] | [prev] | [next] | [standalone]


#178755

FromDan Purgert <dan@djph.net>
Date2017-03-13 14:00 +0100
Message-ID<tkxJU-Fd-21@gated-at.bofh.it>
In reply to#178692
David Christensen wrote:
> On 03/11/2017 07:10 AM, Richard Owlett wrote:
>> I've vague ideas of what backup pattern(s) I might follow.
>> I'm looking for reading materials that might trigger "I hadn't thought
>> of that" moments.
>>
>> Suggestions?
>
> [1] is a decent overview:
>
> http://shop.oreilly.com/product/9780596102463.do
>
> [1] W. Curtis Preston, 2007, "Backup & Recovery Inexpensive Backup 
> Solutions for Open Systems", O'Reilly Media, ISBN: 978-0-596-10246-3

I can only agree that O'Reilly books are well worth the price of
admission.  

As for the backup schemes / plans (which I can only assume are in that
book, as I've not personally read it yet), I favor a 3-2-1 setup.

 - 3 copies (original, backup, backup of the backup)
 - 2 mediums (HDD & something else - right now optical ... though I
   really need to change that)
 - 1 offiite

Don't forget that "if you don't have a tested backup, you don't have
a backup."

Currently, the system here is

 - every PC has a cronjob backing up $HOME to a central "server" (read -
   repurposed PC with decent WD drives), just an rsync script that runs
   daily.
 - /path/to/backups/$user/Documents/ is tar'd weekly and burned to disc.
 - discs are copied, and taken to parents' place.  "Rolling Updates" are
   performed there (as the CD case / binder thing (see: [1]) is already
   full, take oldest set of discs, replace with the newest, repeat til
   full again, then start over at the beginning).



[1]
https://images-na.ssl-images-amazon.com/images/G/01/aplusautomation/vendorimages/b54c252f-3608-4565-814d-ab4ce301675c.jpg._CB317952912__SL300__.jpg

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#178810

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2017-03-14 05:00 +0100
Message-ID<tkLMR-2GV-3@gated-at.bofh.it>
In reply to#178755
On 03/13/2017 05:38 AM, Dan Purgert wrote:
> Currently, the system here is
>
>  - every PC has a cronjob backing up $HOME to a central "server" (read -
>    repurposed PC with decent WD drives), just an rsync script that runs
>    daily.

Don't forget security:

1.  With a "push" arrangement (e.g. each workstation backs up itself to 
the server) -- if a workstation gets compromised, the backups are at risk.

2.  With a "pull" arrangement (e.g. the server backs up all the 
workstations) -- if a workstation gets compromised, the backups should 
be safe (and might have clues about the intrusion).  Additionally, the 
backup server can be completely firewalled (e.g. no open ports).


I prefer the latter.


David

[toc] | [prev] | [next] | [standalone]


#178948

FromDan Purgert <dan@djph.net>
Date2017-03-17 11:50 +0100
Message-ID<tlXCi-535-7@gated-at.bofh.it>
In reply to#178810
David Christensen wrote:
> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>> Currently, the system here is
>>
>>  - every PC has a cronjob backing up $HOME to a central "server" (read -
>>    repurposed PC with decent WD drives), just an rsync script that runs
>>    daily.
>
> Don't forget security:
>
> 1.  With a "push" arrangement (e.g. each workstation backs up itself to 
> the server) -- if a workstation gets compromised, the backups are at risk.
>
> 2.  With a "pull" arrangement (e.g. the server backs up all the 
> workstations) -- if a workstation gets compromised, the backups should 
> be safe (and might have clues about the intrusion).  Additionally, the 
> backup server can be completely firewalled (e.g. no open ports).

Since the PCs are laptops, they're not always here, so I was never able
to figure out how to get pull to work with the condition that we were on
vacation (or the laptops were otherwise "not home").

Though, yeah, the stuff that's statically here (desktop, server, etc.)
are rsync-by-pull.

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#178971

FromGlenn English <ghe2001@gmail.com>
Date2017-03-17 19:50 +0100
Message-ID<tm56O-2jb-21@gated-at.bofh.it>
In reply to#178948
On Fri, Mar 17, 2017 at 4:31 AM, Dan Purgert <dan@djph.net> wrote:
> David Christensen wrote:
>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>> Currently, the system here is
>>>
>>>  - every PC has a cronjob backing up $HOME to a central "server" (read -
>>>    repurposed PC with decent WD drives), just an rsync script that runs
>>>    daily.
>>
>> Don't forget security:
>>
>> 1.  With a "push" arrangement (e.g. each workstation backs up itself to
>> the server) -- if a workstation gets compromised, the backups are at risk.
>>
>> 2.  With a "pull" arrangement (e.g. the server backs up all the
>> workstations) -- if a workstation gets compromised, the backups should
>> be safe (and might have clues about the intrusion).  Additionally, the
>> backup server can be completely firewalled (e.g. no open ports).
>
> Since the PCs are laptops, they're not always here, so I was never able
> to figure out how to get pull to work with the condition that we were on
> vacation (or the laptops were otherwise "not home").

Amanda and tape, but hopefully useful with other programs

Amanda's hard core pull -- there's a server on the LAN that does all
the LAN and DMZ backing up. Part of Amanda's configuration is a list
of things around the network to back up. To deal with wandering
laptops, I have a shell script that looks around to find out what's
there and creates a modified version of that list just before Amanda
runs. Anything that doesn't respond to a ping doesn't get backed up.

--
Glenn English

[toc] | [prev] | [next] | [standalone]


#178985

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2017-03-18 06:20 +0100
Message-ID<tmeWt-1mc-1@gated-at.bofh.it>
In reply to#178948
On 03/17/2017 03:31 AM, Dan Purgert wrote:
> David Christensen wrote:
>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>> Currently, the system here is
>>>
>>>  - every PC has a cronjob backing up $HOME to a central "server" (read -
>>>    repurposed PC with decent WD drives), just an rsync script that runs
>>>    daily.
>>
>> Don't forget security:
>>
>> 1.  With a "push" arrangement (e.g. each workstation backs up itself to
>> the server) -- if a workstation gets compromised, the backups are at risk.
>>
>> 2.  With a "pull" arrangement (e.g. the server backs up all the
>> workstations) -- if a workstation gets compromised, the backups should
>> be safe (and might have clues about the intrusion).  Additionally, the
>> backup server can be completely firewalled (e.g. no open ports).

I should clarify that:

     "The backup server can be firewalled with no incoming ports and
     outgoing ports limited to SSH and other required ports".


I still need to figure out the "other required outgoing ports". 
Suggestions and comments are welcome.


> Since the PCs are laptops, they're not always here, so I was never able
> to figure out how to get pull to work with the condition that we were on
> vacation (or the laptops were otherwise "not home").
>
> Though, yeah, the stuff that's statically here (desktop, server, etc.)
> are rsync-by-pull.

I haven't dealt with the "roaming laptop on the Internet" use-case yet, 
but I do have a desire to solve it.  My idea has been, and remains, for 
the backup server to poll for a "job file" on the laptop, and to execute 
it when found (once; idempotent).  This implies a network connection 
between the backup server and the laptop.  OpenVPN is a technology that 
might be able to facilitate this.


David

[toc] | [prev] | [next] | [standalone]


#179148

FromDan Purgert <dan@djph.net>
Date2017-03-22 11:50 +0100
Message-ID<tnM02-11I-27@gated-at.bofh.it>
In reply to#178985
David Christensen wrote:
> On 03/17/2017 03:31 AM, Dan Purgert wrote:
>> David Christensen wrote:
>>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>> [...]
>
> I should clarify that:
>
>      "The backup server can be firewalled with no incoming ports and
>      outgoing ports limited to SSH and other required ports".
>
>
> I still need to figure out the "other required outgoing ports". 
> Suggestions and comments are welcome.

Unfortunately, pretty much "all ephemeral ports", if the server is
running things that initiate connections.  Some programs allow you to
specify what ports they're connecting from, but not all.

>
>
>> Since the PCs are laptops, they're not always here, so I was never able
>> to figure out how to get pull to work with the condition that we were on
>> vacation (or the laptops were otherwise "not home").
>>
>> Though, yeah, the stuff that's statically here (desktop, server, etc.)
>> are rsync-by-pull.
>
> I haven't dealt with the "roaming laptop on the Internet" use-case yet, 
> but I do have a desire to solve it.  My idea has been, and remains, for 
> the backup server to poll for a "job file" on the laptop, and to execute 
> it when found (once; idempotent).  This implies a network connection 
> between the backup server and the laptop.  OpenVPN is a technology that 
> might be able to facilitate this.

VPN could work, but SSH into a jumpbox works just as well. 

The push script checks /etc/resolv.conf for the local domain, if it's
mine, then backup to the backup-server directly.

If it's not mine, backup "critical files" to the jumpbox (which, in turn
is backed up to the backup-server). It's quite a bit smaller than the
full backups that're performed at home - just $HOME/vacation.

SSH with key-auth only is plenty secure, and so far has never been one
of those things that've been blocked at a hotel.


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#179150

From<tomas@tuxteam.de>
Date2017-03-22 11:50 +0100
Message-ID<tnM03-11I-37@gated-at.bofh.it>
In reply to#179148
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote:
> David Christensen wrote:
> > On 03/17/2017 03:31 AM, Dan Purgert wrote:
> >> David Christensen wrote:
> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
> >>> [...]
> >
> > I should clarify that:
> >
> >      "The backup server can be firewalled with no incoming ports and
> >      outgoing ports limited to SSH and other required ports".
> >
> >
> > I still need to figure out the "other required outgoing ports". 
> > Suggestions and comments are welcome.
> 
> Unfortunately, pretty much "all ephemeral ports", if the server is
> running things that initiate connections.  Some programs allow you to
> specify what ports they're connecting from, but not all.

That's what ESTABLISHED is for, in firewall jargon (you accept packets
belonging to an established TCP connection).

Regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAljSVc0ACgkQBcgs9XrR2kZuzgCfXXa+qKx7HKM4z89EOuC0mWbK
GiMAnij6QBoehTW2rE7gzAckchaifmdS
=RbGU
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#179154

FromDan Purgert <dan@djph.net>
Date2017-03-22 13:20 +0100
Message-ID<tnNp8-2fJ-13@gated-at.bofh.it>
In reply to#179150
<tomas@tuxteam.de> wrote:
>
> On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote:
>> David Christensen wrote:
>> > On 03/17/2017 03:31 AM, Dan Purgert wrote:
>> >> David Christensen wrote:
>> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>> >>> [...]
>> >
>> > I should clarify that:
>> >
>> >      "The backup server can be firewalled with no incoming ports and
>> >      outgoing ports limited to SSH and other required ports".
>> >
>> >
>> > I still need to figure out the "other required outgoing ports". 
>> > Suggestions and comments are welcome.
>> 
>> Unfortunately, pretty much "all ephemeral ports", if the server is
>> running things that initiate connections.  Some programs allow you to
>> specify what ports they're connecting from, but not all.
>
> That's what ESTABLISHED is for, in firewall jargon (you accept packets
> belonging to an established TCP connection).
>

You're not gonna have any ESTABLISHED connections in your firewall if
you're _initiating_ the connection. ;)

if my firewall has the following rules:
 - default drop
 - rule 10 accept established

the command:
rsync (whatever switches) user@remote-host:/path/to/files/ /local/

Will fail to connect to remote-host, as the rsync command is not
connecting across a previously established link. 

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#179155

From<tomas@tuxteam.de>
Date2017-03-22 13:30 +0100
Message-ID<tnNyN-2kr-1@gated-at.bofh.it>
In reply to#179154
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Mar 22, 2017 at 11:57:44AM -0000, Dan Purgert wrote:
> <tomas@tuxteam.de> wrote:
> >
> > On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote:
> >> David Christensen wrote:
> >> > On 03/17/2017 03:31 AM, Dan Purgert wrote:
> >> >> David Christensen wrote:
> >> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
> >> >>> [...]
> >> >
> >> > I should clarify that:
> >> >
> >> >      "The backup server can be firewalled with no incoming ports and
> >> >      outgoing ports limited to SSH and other required ports".
> >> >
> >> >
> >> > I still need to figure out the "other required outgoing ports". 
> >> > Suggestions and comments are welcome.
> >> 
> >> Unfortunately, pretty much "all ephemeral ports", if the server is
> >> running things that initiate connections.  Some programs allow you to
> >> specify what ports they're connecting from, but not all.
> >
> > That's what ESTABLISHED is for, in firewall jargon (you accept packets
> > belonging to an established TCP connection).
> >
> 
> You're not gonna have any ESTABLISHED connections in your firewall if
> you're _initiating_ the connection. ;)
> 
> if my firewall has the following rules:
>  - default drop
>  - rule 10 accept established
> 
> the command:
> rsync (whatever switches) user@remote-host:/path/to/files/ /local/
> 
> Will fail to connect to remote-host, as the rsync command is not
> connecting across a previously established link. 

You're holding it wrong :)

Remote-host has to allow connections (from wherever, perhaps only
from the backup host) *to* its port 22. The ESTABLISHED is for
rsync's "other leg".

- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAljSa/wACgkQBcgs9XrR2kbrjwCeNwPfsjE3wFnfWm/pQJGlLc+j
SwwAnAtDVJZiH34L3jLTi45dlFz8PPcK
=ue1R
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#179180

FromDan Purgert <dan@djph.net>
Date2017-03-23 10:30 +0100
Message-ID<to7ea-eW-25@gated-at.bofh.it>
In reply to#179155
<tomas@tuxteam.de> wrote:
>
> On Wed, Mar 22, 2017 at 11:57:44AM -0000, Dan Purgert wrote:
>> <tomas@tuxteam.de> wrote:
>> >
>> > On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote:
>> >> David Christensen wrote:
>> >> > On 03/17/2017 03:31 AM, Dan Purgert wrote:
>> >> >> David Christensen wrote:
>> >> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>> >> >>> [...]
>> >> >
>> >> > I should clarify that:
>> >> >
>> >> >      "The backup server can be firewalled with no incoming ports and
>> >> >      outgoing ports limited to SSH and other required ports".
>> >> >
>> >> >
>> >> > I still need to figure out the "other required outgoing ports". 
>> >> > Suggestions and comments are welcome.
>> >> 
>> >> Unfortunately, pretty much "all ephemeral ports", if the server is
>> >> running things that initiate connections.  Some programs allow you to
>> >> specify what ports they're connecting from, but not all.
>> >
>> > That's what ESTABLISHED is for, in firewall jargon (you accept packets
>> > belonging to an established TCP connection).
>> >
>> 
>> You're not gonna have any ESTABLISHED connections in your firewall if
>> you're _initiating_ the connection. ;)
>> 
>> if my firewall has the following rules:
>>  - default drop
>>  - rule 10 accept established
>> 
>> the command:
>> rsync (whatever switches) user@remote-host:/path/to/files/ /local/
>> 
>> Will fail to connect to remote-host, as the rsync command is not
>> connecting across a previously established link. 
>
> You're holding it wrong :)
>
> Remote-host has to allow connections (from wherever, perhaps only
> from the backup host) *to* its port 22. The ESTABLISHED is for
> rsync's "other leg".

You do realize that the thread of discussion you hopped onto was
specifically talking about if the "server box" was _initiating_
connections, right?

Of course if the server is simply responding to incoming requests,
"accept established" would let the responses back out.


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#179184

From<tomas@tuxteam.de>
Date2017-03-23 11:10 +0100
Message-ID<to7QR-Io-11@gated-at.bofh.it>
In reply to#179180
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, Mar 23, 2017 at 09:14:47AM -0000, Dan Purgert wrote:
> <tomas@tuxteam.de> wrote:

[...]

> > You're holding it wrong :)

[on a second reading this might come across as unpolite: sorry if
that's the case]

[...]

> You do realize that the thread of discussion you hopped onto was
> specifically talking about if the "server box" was _initiating_
> connections, right?

Sorry. Role confusion. I usually don't think of "boxes" (or programs)
as client or servers -- so "server" was associated with SSH server.

Regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEUEARECAAYFAljTnn0ACgkQBcgs9XrR2kZ5twCfcD8fqMhRmeRkk08N3GSeMxXP
YfYAlRloRn7d3Zz4yg21Y2LXAb2W+hs=
=1yRT
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#179190

FromDan Purgert <dan@djph.net>
Date2017-03-23 13:10 +0100
Message-ID<to9IZ-21Y-11@gated-at.bofh.it>
In reply to#179184
<tomas@tuxteam.de> wrote:
>
> On Thu, Mar 23, 2017 at 09:14:47AM -0000, Dan Purgert wrote:
>> <tomas@tuxteam.de> wrote:
>
> [...]
>
>> > You're holding it wrong :)
>
> [on a second reading this might come across as unpolite: sorry if
> that's the case]

No worries, I don't use iDevices.

>
> [...]
>
>> You do realize that the thread of discussion you hopped onto was
>> specifically talking about if the "server box" was _initiating_
>> connections, right?
>
> Sorry. Role confusion. I usually don't think of "boxes" (or programs)
> as client or servers -- so "server" was associated with SSH server.
>

That explains it :)

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#179175

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2017-03-23 04:00 +0100
Message-ID<to18J-49M-5@gated-at.bofh.it>
In reply to#179148
On 03/22/2017 03:35 AM, Dan Purgert wrote:
> David Christensen wrote:
>> On 03/17/2017 03:31 AM, Dan Purgert wrote:
>>> David Christensen wrote:
>>>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>>> [...]
>>
>> I should clarify that:
>>
>>      "The backup server can be firewalled with no incoming ports and
>>      outgoing ports limited to SSH and other required ports".
>>
>>
>> I still need to figure out the "other required outgoing ports".
>> Suggestions and comments are welcome.
>
> Unfortunately, pretty much "all ephemeral ports", if the server is
> running things that initiate connections.  Some programs allow you to
> specify what ports they're connecting from, but not all.

I run ntpd on all my machines.  So, ports 123/tcp and 123/udp need to be 
open for ongoing connections:

2017-03-22 19:30:03 dpchrist@jesse ~
$ grep ^ntp /etc/services
ntp		123/tcp
ntp		123/udp				# Network Time Protocol


>>> Since the PCs are laptops, they're not always here, so I was never able
>>> to figure out how to get pull to work with the condition that we were on
>>> vacation (or the laptops were otherwise "not home").
>>>
>>> Though, yeah, the stuff that's statically here (desktop, server, etc.)
>>> are rsync-by-pull.
>>
>> I haven't dealt with the "roaming laptop on the Internet" use-case yet,
>> but I do have a desire to solve it.  My idea has been, and remains, for
>> the backup server to poll for a "job file" on the laptop, and to execute
>> it when found (once; idempotent).  This implies a network connection
>> between the backup server and the laptop.  OpenVPN is a technology that
>> might be able to facilitate this.
>
> VPN could work, but SSH into a jumpbox works just as well.
>
> The push script checks /etc/resolv.conf for the local domain, if it's
> mine, then backup to the backup-server directly.
>
> If it's not mine, backup "critical files" to the jumpbox (which, in turn
> is backed up to the backup-server). It's quite a bit smaller than the
> full backups that're performed at home - just $HOME/vacation.

So, you have a static IP (or dynamic DNS) for your home Internet 
connection, you have your home gateway configured to allow incoming SSH 
connections and direct them to an internal host "jumpbox", and your 
laptop has a backup script that detects whether the laptop is on your 
LAN or on the Internet.  If on the LAN, the backup script exits and 
waits for the backup server to pull a complete backup.  If on the 
Internet, the backup script pushes critical files over SSH to a 
receiving directory on "jumpbox" (?).


> SSH with key-auth only is plenty secure, and so far has never been one
> of those things that've been blocked at a hotel.

I have recently been studying up on SSH, both STFW and:

https://www.michaelwlucas.com/tools/ssh


SSH user keys with passphrases, disabling PasswordAuthentication, and 
ssh-agent/ssh-add are all good practices.


David

[toc] | [prev] | [next] | [standalone]


#179181

FromDan Purgert <dan@djph.net>
Date2017-03-23 10:40 +0100
Message-ID<to7nP-jM-7@gated-at.bofh.it>
In reply to#179175
David Christensen wrote:
> On 03/22/2017 03:35 AM, Dan Purgert wrote:
>> David Christensen wrote:
>>> On 03/17/2017 03:31 AM, Dan Purgert wrote:
>>>> David Christensen wrote:
>>>>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>>>> [...]
>>>
>>> I should clarify that:
>>>
>>>      "The backup server can be firewalled with no incoming ports and
>>>      outgoing ports limited to SSH and other required ports".
>>>
>>>
>>> I still need to figure out the "other required outgoing ports".
>>> Suggestions and comments are welcome.
>>
>> Unfortunately, pretty much "all ephemeral ports", if the server is
>> running things that initiate connections.  Some programs allow you to
>> specify what ports they're connecting from, but not all.
>
> I run ntpd on all my machines.  So, ports 123/tcp and 123/udp need to be 
> open for ongoing connections:

Good point, that :).  I was just making a comment about "other required
outgoing ports" (as many things just use an ephemeral port to initiate a
connection, rather than a defined port, as with ntp).

> [...]
>> VPN could work, but SSH into a jumpbox works just as well.
>>
>> The push script checks /etc/resolv.conf for the local domain, if it's
>> mine, then backup to the backup-server directly.
>>
>> If it's not mine, backup "critical files" to the jumpbox (which, in turn
>> is backed up to the backup-server). It's quite a bit smaller than the
>> full backups that're performed at home - just $HOME/vacation.
>
> So, you have a static IP (or dynamic DNS) for your home Internet 
> connection, you have your home gateway configured to allow incoming SSH 
> connections and direct them to an internal host "jumpbox", and your 
> laptop has a backup script that detects whether the laptop is on your 
> LAN or on the Internet.  If on the LAN, the backup script exits and 
> waits for the backup server to pull a complete backup.  If on the 
> Internet, the backup script pushes critical files over SSH to a 
> receiving directory on "jumpbox" (?).

Close enough - the script on the laptops just switches between "rsync
everything to backup-server, because you're at home" and "rsync only the
'vacation' folder to jumpbox, because you're not"



-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#179213

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2017-03-23 20:10 +0100
Message-ID<toghs-6GO-11@gated-at.bofh.it>
In reply to#179181
On 03/23/2017 02:22 AM, Dan Purgert wrote:
> David Christensen wrote:
>> On 03/22/2017 03:35 AM, Dan Purgert wrote:
>>> David Christensen wrote:
>>>> On 03/17/2017 03:31 AM, Dan Purgert wrote:
>>>>> David Christensen wrote:
>>>>>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>>>>> [...]
>>>>
>>>> I should clarify that:
>>>>
>>>>      "The backup server can be firewalled with no incoming ports and
>>>>      outgoing ports limited to SSH and other required ports".
>>>>
>>>>
>>>> I still need to figure out the "other required outgoing ports".
>>>> Suggestions and comments are welcome.
>>>
>>> Unfortunately, pretty much "all ephemeral ports", if the server is
>>> running things that initiate connections.  Some programs allow you to
>>> specify what ports they're connecting from, but not all.
>>
>> I run ntpd on all my machines.  So, ports 123/tcp and 123/udp need to be
>> open for ongoing connections:
>
> Good point, that :).  I was just making a comment about "other required
> outgoing ports" (as many things just use an ephemeral port to initiate a
> connection, rather than a defined port, as with ntp).

At this point, I have only implemented incoming firewalling on all of my 
computers.  But, I do want to implement outgoing firewalling on the 
backup server.  Figuring it out will be interesting.


>> [...]
>>> VPN could work, but SSH into a jumpbox works just as well.
>>>
>>> The push script checks /etc/resolv.conf for the local domain, if it's
>>> mine, then backup to the backup-server directly.
>>>
>>> If it's not mine, backup "critical files" to the jumpbox (which, in turn
>>> is backed up to the backup-server). It's quite a bit smaller than the
>>> full backups that're performed at home - just $HOME/vacation.
>>
>> So, you have a static IP (or dynamic DNS) for your home Internet
>> connection, you have your home gateway configured to allow incoming SSH
>> connections and direct them to an internal host "jumpbox", and your
>> laptop has a backup script that detects whether the laptop is on your
>> LAN or on the Internet.  If on the LAN, the backup script exits and
>> waits for the backup server to pull a complete backup.  If on the
>> Internet, the backup script pushes critical files over SSH to a
>> receiving directory on "jumpbox" (?).
>
> Close enough - the script on the laptops just switches between "rsync
> everything to backup-server, because you're at home" and "rsync only the
> 'vacation' folder to jumpbox, because you're not"

So, your computers push backups to the backup server.  I feel safer if 
the backup server pulls backups and all incoming ports are closed.


David

[toc] | [prev] | [next] | [standalone]


#179633 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

FromDominik George <nik@naturalnet.de>
Date2017-03-31 14:10 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<tr3xn-4rg-5@gated-at.bofh.it>
In reply to#178810
>My understanding is that if there are no services listening on a port
>then
>it cannot be accessed.

Well, if nothing is listening on a port, then something can start doing so unconditionally.

That's how w^Hsomeone rooted Dreamhost.

-nik

[toc] | [prev] | [next] | [standalone]


#179665 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

FromDominik George <nik@naturalnet.de>
Date2017-03-31 23:20 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<trc7D-1vo-3@gated-at.bofh.it>
In reply to#179633
> On Fri, Mar 31, 2017 at 02:07:54PM +0200, Dominik George wrote:
> > That's how w^Hsomeone rooted Dreamhost.
> 
> Are you referring to the 2012 incident, or something more recent?
> 
> I thought the former was an issue with lax filesystem permissions.

(This is getting somewhat OT; if you want to discuss that further, maybe
choose private conversation or another mailing list… I only intended to
provide a scenario that was not made up.)

Something less recent, from late 2010.

The thing I described was reported only to the company themselves, who
still failed to fix the root issue for several years.

After their administrators and CEO (funnily enough, it was his
webhosting account that had the vulnerable PHP application I was talking
about…) had ignored the issue for more than a year, $someone dropped a
note in the Chaos Communication Congress' wiki. What exactly this note
was used for and what it was not used for is beyond my knowledge.

-nik

-- 
PGP-Fingerprint: 3C9D 54A4 7575 C026 FB17  FD26 B79A 3C16 A0C4 F296

Dominik George · Hundeshagenstr. 26 · 53225 Bonn
Mobile: +49-1520-1981389 · https://www.dominik-george.de/

Teckids e.V. · FrOSCon e.V.
Fellowship of the FSFE · Piratenpartei Deutschland
Opencaching Deutschland e.V. · Debian Maintainer

LPIC-3 Linux Enterprise Professional (Security)

[toc] | [prev] | [next] | [standalone]


#179676 — Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)

FromNathan Dorfman <ndorf@rtfm.net>
Date2017-04-01 11:00 +0200
SubjectRe: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies)
Message-ID<trc7D-1vo-5@gated-at.bofh.it>
In reply to#179633
On Fri, Mar 31, 2017 at 02:07:54PM +0200, Dominik George wrote:
> That's how w^Hsomeone rooted Dreamhost.

Are you referring to the 2012 incident, or something more recent?

I thought the former was an issue with lax filesystem permissions.

-nd.

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web