Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #178680 > unrolled thread
| Started by | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| First post | 2017-03-11 16:20 +0100 |
| Last post | 2017-03-19 11:40 +0100 |
| Articles | 20 on this page of 45 — 18 participants |
Back to article view | Back to linux.debian.user
Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-11 16:20 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-11 22:10 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-13 14:00 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:00 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-17 11:50 +0100
Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-17 19:50 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-18 06:20 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 11:50 +0100
Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 11:50 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-22 13:20 +0100
Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-22 13:30 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:30 +0100
Re: Guide(s?) to backup philosophies <tomas@tuxteam.de> - 2017-03-23 11:10 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 13:10 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 04:00 +0100
Re: Guide(s?) to backup philosophies Dan Purgert <dan@djph.net> - 2017-03-23 10:40 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-23 20:10 +0100
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 14:10 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 23:20 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Nathan Dorfman <ndorf@rtfm.net> - 2017-04-01 11:00 +0200
should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) cbannister@slingshot.co.nz - 2017-03-31 14:10 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 14:20 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Brian <ad44@cityscape.co.uk> - 2017-03-31 15:20 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) <tomas@tuxteam.de> - 2017-03-31 15:30 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:30 +0200
Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) Dominik George <nik@naturalnet.de> - 2017-03-31 15:50 +0200
Re: Guide(s?) to backup philosophies Glenn English <ghe2001@gmail.com> - 2017-03-14 19:00 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 19:20 +0100
Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:20 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-14 21:40 +0100
Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 13:30 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-15 14:10 +0100
Re: Guide(s?) to backup philosophies "Martin McCormick" <martin.m@suddenlink.net> - 2017-03-15 14:30 +0100
Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 16:40 +0100
Re: Guide(s?) to backup philosophies Stefan Monnier <monnier@iro.umontreal.ca> - 2017-03-15 21:50 +0100
Re: Guide(s?) to backup philosophies songbird <songbird@anthive.com> - 2017-03-16 23:50 +0100
Re: Guide(s?) to backup philosophies Miles Fidelman <mfidelman@meetinghouse.net> - 2017-03-14 20:10 +0100
Re: Guide(s?) to backup philosophies Joe <joe@jretrading.com> - 2017-03-11 23:30 +0100
Re: Guide(s?) to backup philosophies Jonathan Dowland <jmtd@debian.org> - 2017-03-15 13:30 +0100
Re: Guide(s?) to backup philosophies Dan Ritter <dsr@randomstring.org> - 2017-03-13 15:20 +0100
Re: Guide(s?) to backup philosophies David Christensen <dpchrist@holgerdanske.com> - 2017-03-14 05:10 +0100
Re: Guide(s?) to backup philosophies Richard Owlett <rowlett@cloud85.net> - 2017-03-14 15:50 +0100
Re: Guide(s?) to backup philosophies Merlin Büge <toni@bluenox07.de> - 2017-03-14 19:50 +0100
Re: Guide(s?) to backup philosophies DdB <debianlist@potentially-spam.de-bruyn.de> - 2017-03-19 11:40 +0100
Page 1 of 3 [1] 2 3 Next page →
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2017-03-11 16:20 +0100 |
| Subject | Guide(s?) to backup philosophies |
| Message-ID | <tjQYh-4AT-7@gated-at.bofh.it> |
I've been good about telling others that backups are a good idea. Guess who hadn't and then crashed his system and spent hours putting things back together ;< In the past individual projects ended up on individual flash drives as I was frequently using different machines. I now have some reliable hardware and a large internal hard drive. I have one partition that might be called a "production" environment, i.e. fairly stable and has the most valuable content. A second partition hosts my experiments - I've a project to create an optimal install. The third is the target of those experimental installs whose content doesn't rate explicit backups. The scripts for creating those installs being on the second partition. I've vague ideas of what backup pattern(s) I might follow. I'm looking for reading materials that might trigger "I hadn't thought of that" moments. Suggestions? TIA
[toc] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2017-03-11 22:10 +0100 |
| Message-ID | <tjWr0-8sd-17@gated-at.bofh.it> |
| In reply to | #178680 |
On 03/11/2017 07:10 AM, Richard Owlett wrote: > I've been good about telling others that backups are a good idea. > Guess who hadn't and then crashed his system and spent hours putting > things back together ;< > > In the past individual projects ended up on individual flash drives as I > was frequently using different machines. I now have some reliable > hardware and a large internal hard drive. > > I have one partition that might be called a "production" environment, > i.e. fairly stable and has the most valuable content. > A second partition hosts my experiments - I've a project to create an > optimal install. The third is the target of those experimental installs > whose content doesn't rate explicit backups. The scripts for creating > those installs being on the second partition. > > I've vague ideas of what backup pattern(s) I might follow. > I'm looking for reading materials that might trigger "I hadn't thought > of that" moments. > > Suggestions? [1] is a decent overview: http://shop.oreilly.com/product/9780596102463.do After that, it's a matter of what systems you have, what tools you pick, and how to best utilize them. David References: [1] W. Curtis Preston, 2007, "Backup & Recovery Inexpensive Backup Solutions for Open Systems", O'Reilly Media, ISBN: 978-0-596-10246-3
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-13 14:00 +0100 |
| Message-ID | <tkxJU-Fd-21@gated-at.bofh.it> |
| In reply to | #178692 |
David Christensen wrote: > On 03/11/2017 07:10 AM, Richard Owlett wrote: >> I've vague ideas of what backup pattern(s) I might follow. >> I'm looking for reading materials that might trigger "I hadn't thought >> of that" moments. >> >> Suggestions? > > [1] is a decent overview: > > http://shop.oreilly.com/product/9780596102463.do > > [1] W. Curtis Preston, 2007, "Backup & Recovery Inexpensive Backup > Solutions for Open Systems", O'Reilly Media, ISBN: 978-0-596-10246-3 I can only agree that O'Reilly books are well worth the price of admission. As for the backup schemes / plans (which I can only assume are in that book, as I've not personally read it yet), I favor a 3-2-1 setup. - 3 copies (original, backup, backup of the backup) - 2 mediums (HDD & something else - right now optical ... though I really need to change that) - 1 offiite Don't forget that "if you don't have a tested backup, you don't have a backup." Currently, the system here is - every PC has a cronjob backing up $HOME to a central "server" (read - repurposed PC with decent WD drives), just an rsync script that runs daily. - /path/to/backups/$user/Documents/ is tar'd weekly and burned to disc. - discs are copied, and taken to parents' place. "Rolling Updates" are performed there (as the CD case / binder thing (see: [1]) is already full, take oldest set of discs, replace with the newest, repeat til full again, then start over at the beginning). [1] https://images-na.ssl-images-amazon.com/images/G/01/aplusautomation/vendorimages/b54c252f-3608-4565-814d-ab4ce301675c.jpg._CB317952912__SL300__.jpg -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2017-03-14 05:00 +0100 |
| Message-ID | <tkLMR-2GV-3@gated-at.bofh.it> |
| In reply to | #178755 |
On 03/13/2017 05:38 AM, Dan Purgert wrote: > Currently, the system here is > > - every PC has a cronjob backing up $HOME to a central "server" (read - > repurposed PC with decent WD drives), just an rsync script that runs > daily. Don't forget security: 1. With a "push" arrangement (e.g. each workstation backs up itself to the server) -- if a workstation gets compromised, the backups are at risk. 2. With a "pull" arrangement (e.g. the server backs up all the workstations) -- if a workstation gets compromised, the backups should be safe (and might have clues about the intrusion). Additionally, the backup server can be completely firewalled (e.g. no open ports). I prefer the latter. David
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-17 11:50 +0100 |
| Message-ID | <tlXCi-535-7@gated-at.bofh.it> |
| In reply to | #178810 |
David Christensen wrote: > On 03/13/2017 05:38 AM, Dan Purgert wrote: >> Currently, the system here is >> >> - every PC has a cronjob backing up $HOME to a central "server" (read - >> repurposed PC with decent WD drives), just an rsync script that runs >> daily. > > Don't forget security: > > 1. With a "push" arrangement (e.g. each workstation backs up itself to > the server) -- if a workstation gets compromised, the backups are at risk. > > 2. With a "pull" arrangement (e.g. the server backs up all the > workstations) -- if a workstation gets compromised, the backups should > be safe (and might have clues about the intrusion). Additionally, the > backup server can be completely firewalled (e.g. no open ports). Since the PCs are laptops, they're not always here, so I was never able to figure out how to get pull to work with the condition that we were on vacation (or the laptops were otherwise "not home"). Though, yeah, the stuff that's statically here (desktop, server, etc.) are rsync-by-pull. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | Glenn English <ghe2001@gmail.com> |
|---|---|
| Date | 2017-03-17 19:50 +0100 |
| Message-ID | <tm56O-2jb-21@gated-at.bofh.it> |
| In reply to | #178948 |
On Fri, Mar 17, 2017 at 4:31 AM, Dan Purgert <dan@djph.net> wrote: > David Christensen wrote: >> On 03/13/2017 05:38 AM, Dan Purgert wrote: >>> Currently, the system here is >>> >>> - every PC has a cronjob backing up $HOME to a central "server" (read - >>> repurposed PC with decent WD drives), just an rsync script that runs >>> daily. >> >> Don't forget security: >> >> 1. With a "push" arrangement (e.g. each workstation backs up itself to >> the server) -- if a workstation gets compromised, the backups are at risk. >> >> 2. With a "pull" arrangement (e.g. the server backs up all the >> workstations) -- if a workstation gets compromised, the backups should >> be safe (and might have clues about the intrusion). Additionally, the >> backup server can be completely firewalled (e.g. no open ports). > > Since the PCs are laptops, they're not always here, so I was never able > to figure out how to get pull to work with the condition that we were on > vacation (or the laptops were otherwise "not home"). Amanda and tape, but hopefully useful with other programs Amanda's hard core pull -- there's a server on the LAN that does all the LAN and DMZ backing up. Part of Amanda's configuration is a list of things around the network to back up. To deal with wandering laptops, I have a shell script that looks around to find out what's there and creates a modified version of that list just before Amanda runs. Anything that doesn't respond to a ping doesn't get backed up. -- Glenn English
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2017-03-18 06:20 +0100 |
| Message-ID | <tmeWt-1mc-1@gated-at.bofh.it> |
| In reply to | #178948 |
On 03/17/2017 03:31 AM, Dan Purgert wrote:
> David Christensen wrote:
>> On 03/13/2017 05:38 AM, Dan Purgert wrote:
>>> Currently, the system here is
>>>
>>> - every PC has a cronjob backing up $HOME to a central "server" (read -
>>> repurposed PC with decent WD drives), just an rsync script that runs
>>> daily.
>>
>> Don't forget security:
>>
>> 1. With a "push" arrangement (e.g. each workstation backs up itself to
>> the server) -- if a workstation gets compromised, the backups are at risk.
>>
>> 2. With a "pull" arrangement (e.g. the server backs up all the
>> workstations) -- if a workstation gets compromised, the backups should
>> be safe (and might have clues about the intrusion). Additionally, the
>> backup server can be completely firewalled (e.g. no open ports).
I should clarify that:
"The backup server can be firewalled with no incoming ports and
outgoing ports limited to SSH and other required ports".
I still need to figure out the "other required outgoing ports".
Suggestions and comments are welcome.
> Since the PCs are laptops, they're not always here, so I was never able
> to figure out how to get pull to work with the condition that we were on
> vacation (or the laptops were otherwise "not home").
>
> Though, yeah, the stuff that's statically here (desktop, server, etc.)
> are rsync-by-pull.
I haven't dealt with the "roaming laptop on the Internet" use-case yet,
but I do have a desire to solve it. My idea has been, and remains, for
the backup server to poll for a "job file" on the laptop, and to execute
it when found (once; idempotent). This implies a network connection
between the backup server and the laptop. OpenVPN is a technology that
might be able to facilitate this.
David
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-22 11:50 +0100 |
| Message-ID | <tnM02-11I-27@gated-at.bofh.it> |
| In reply to | #178985 |
David Christensen wrote: > On 03/17/2017 03:31 AM, Dan Purgert wrote: >> David Christensen wrote: >>> On 03/13/2017 05:38 AM, Dan Purgert wrote: >>> [...] > > I should clarify that: > > "The backup server can be firewalled with no incoming ports and > outgoing ports limited to SSH and other required ports". > > > I still need to figure out the "other required outgoing ports". > Suggestions and comments are welcome. Unfortunately, pretty much "all ephemeral ports", if the server is running things that initiate connections. Some programs allow you to specify what ports they're connecting from, but not all. > > >> Since the PCs are laptops, they're not always here, so I was never able >> to figure out how to get pull to work with the condition that we were on >> vacation (or the laptops were otherwise "not home"). >> >> Though, yeah, the stuff that's statically here (desktop, server, etc.) >> are rsync-by-pull. > > I haven't dealt with the "roaming laptop on the Internet" use-case yet, > but I do have a desire to solve it. My idea has been, and remains, for > the backup server to poll for a "job file" on the laptop, and to execute > it when found (once; idempotent). This implies a network connection > between the backup server and the laptop. OpenVPN is a technology that > might be able to facilitate this. VPN could work, but SSH into a jumpbox works just as well. The push script checks /etc/resolv.conf for the local domain, if it's mine, then backup to the backup-server directly. If it's not mine, backup "critical files" to the jumpbox (which, in turn is backed up to the backup-server). It's quite a bit smaller than the full backups that're performed at home - just $HOME/vacation. SSH with key-auth only is plenty secure, and so far has never been one of those things that've been blocked at a hotel. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-22 11:50 +0100 |
| Message-ID | <tnM03-11I-37@gated-at.bofh.it> |
| In reply to | #179148 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote: > David Christensen wrote: > > On 03/17/2017 03:31 AM, Dan Purgert wrote: > >> David Christensen wrote: > >>> On 03/13/2017 05:38 AM, Dan Purgert wrote: > >>> [...] > > > > I should clarify that: > > > > "The backup server can be firewalled with no incoming ports and > > outgoing ports limited to SSH and other required ports". > > > > > > I still need to figure out the "other required outgoing ports". > > Suggestions and comments are welcome. > > Unfortunately, pretty much "all ephemeral ports", if the server is > running things that initiate connections. Some programs allow you to > specify what ports they're connecting from, but not all. That's what ESTABLISHED is for, in firewall jargon (you accept packets belonging to an established TCP connection). Regards - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAljSVc0ACgkQBcgs9XrR2kZuzgCfXXa+qKx7HKM4z89EOuC0mWbK GiMAnij6QBoehTW2rE7gzAckchaifmdS =RbGU -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-22 13:20 +0100 |
| Message-ID | <tnNp8-2fJ-13@gated-at.bofh.it> |
| In reply to | #179150 |
<tomas@tuxteam.de> wrote: > > On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote: >> David Christensen wrote: >> > On 03/17/2017 03:31 AM, Dan Purgert wrote: >> >> David Christensen wrote: >> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote: >> >>> [...] >> > >> > I should clarify that: >> > >> > "The backup server can be firewalled with no incoming ports and >> > outgoing ports limited to SSH and other required ports". >> > >> > >> > I still need to figure out the "other required outgoing ports". >> > Suggestions and comments are welcome. >> >> Unfortunately, pretty much "all ephemeral ports", if the server is >> running things that initiate connections. Some programs allow you to >> specify what ports they're connecting from, but not all. > > That's what ESTABLISHED is for, in firewall jargon (you accept packets > belonging to an established TCP connection). > You're not gonna have any ESTABLISHED connections in your firewall if you're _initiating_ the connection. ;) if my firewall has the following rules: - default drop - rule 10 accept established the command: rsync (whatever switches) user@remote-host:/path/to/files/ /local/ Will fail to connect to remote-host, as the rsync command is not connecting across a previously established link. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-22 13:30 +0100 |
| Message-ID | <tnNyN-2kr-1@gated-at.bofh.it> |
| In reply to | #179154 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Mar 22, 2017 at 11:57:44AM -0000, Dan Purgert wrote: > <tomas@tuxteam.de> wrote: > > > > On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote: > >> David Christensen wrote: > >> > On 03/17/2017 03:31 AM, Dan Purgert wrote: > >> >> David Christensen wrote: > >> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote: > >> >>> [...] > >> > > >> > I should clarify that: > >> > > >> > "The backup server can be firewalled with no incoming ports and > >> > outgoing ports limited to SSH and other required ports". > >> > > >> > > >> > I still need to figure out the "other required outgoing ports". > >> > Suggestions and comments are welcome. > >> > >> Unfortunately, pretty much "all ephemeral ports", if the server is > >> running things that initiate connections. Some programs allow you to > >> specify what ports they're connecting from, but not all. > > > > That's what ESTABLISHED is for, in firewall jargon (you accept packets > > belonging to an established TCP connection). > > > > You're not gonna have any ESTABLISHED connections in your firewall if > you're _initiating_ the connection. ;) > > if my firewall has the following rules: > - default drop > - rule 10 accept established > > the command: > rsync (whatever switches) user@remote-host:/path/to/files/ /local/ > > Will fail to connect to remote-host, as the rsync command is not > connecting across a previously established link. You're holding it wrong :) Remote-host has to allow connections (from wherever, perhaps only from the backup host) *to* its port 22. The ESTABLISHED is for rsync's "other leg". - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAljSa/wACgkQBcgs9XrR2kbrjwCeNwPfsjE3wFnfWm/pQJGlLc+j SwwAnAtDVJZiH34L3jLTi45dlFz8PPcK =ue1R -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-23 10:30 +0100 |
| Message-ID | <to7ea-eW-25@gated-at.bofh.it> |
| In reply to | #179155 |
<tomas@tuxteam.de> wrote: > > On Wed, Mar 22, 2017 at 11:57:44AM -0000, Dan Purgert wrote: >> <tomas@tuxteam.de> wrote: >> > >> > On Wed, Mar 22, 2017 at 10:35:13AM -0000, Dan Purgert wrote: >> >> David Christensen wrote: >> >> > On 03/17/2017 03:31 AM, Dan Purgert wrote: >> >> >> David Christensen wrote: >> >> >>> On 03/13/2017 05:38 AM, Dan Purgert wrote: >> >> >>> [...] >> >> > >> >> > I should clarify that: >> >> > >> >> > "The backup server can be firewalled with no incoming ports and >> >> > outgoing ports limited to SSH and other required ports". >> >> > >> >> > >> >> > I still need to figure out the "other required outgoing ports". >> >> > Suggestions and comments are welcome. >> >> >> >> Unfortunately, pretty much "all ephemeral ports", if the server is >> >> running things that initiate connections. Some programs allow you to >> >> specify what ports they're connecting from, but not all. >> > >> > That's what ESTABLISHED is for, in firewall jargon (you accept packets >> > belonging to an established TCP connection). >> > >> >> You're not gonna have any ESTABLISHED connections in your firewall if >> you're _initiating_ the connection. ;) >> >> if my firewall has the following rules: >> - default drop >> - rule 10 accept established >> >> the command: >> rsync (whatever switches) user@remote-host:/path/to/files/ /local/ >> >> Will fail to connect to remote-host, as the rsync command is not >> connecting across a previously established link. > > You're holding it wrong :) > > Remote-host has to allow connections (from wherever, perhaps only > from the backup host) *to* its port 22. The ESTABLISHED is for > rsync's "other leg". You do realize that the thread of discussion you hopped onto was specifically talking about if the "server box" was _initiating_ connections, right? Of course if the server is simply responding to incoming requests, "accept established" would let the responses back out. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-23 11:10 +0100 |
| Message-ID | <to7QR-Io-11@gated-at.bofh.it> |
| In reply to | #179180 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, Mar 23, 2017 at 09:14:47AM -0000, Dan Purgert wrote: > <tomas@tuxteam.de> wrote: [...] > > You're holding it wrong :) [on a second reading this might come across as unpolite: sorry if that's the case] [...] > You do realize that the thread of discussion you hopped onto was > specifically talking about if the "server box" was _initiating_ > connections, right? Sorry. Role confusion. I usually don't think of "boxes" (or programs) as client or servers -- so "server" was associated with SSH server. Regards - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEUEARECAAYFAljTnn0ACgkQBcgs9XrR2kZ5twCfcD8fqMhRmeRkk08N3GSeMxXP YfYAlRloRn7d3Zz4yg21Y2LXAb2W+hs= =1yRT -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-23 13:10 +0100 |
| Message-ID | <to9IZ-21Y-11@gated-at.bofh.it> |
| In reply to | #179184 |
<tomas@tuxteam.de> wrote: > > On Thu, Mar 23, 2017 at 09:14:47AM -0000, Dan Purgert wrote: >> <tomas@tuxteam.de> wrote: > > [...] > >> > You're holding it wrong :) > > [on a second reading this might come across as unpolite: sorry if > that's the case] No worries, I don't use iDevices. > > [...] > >> You do realize that the thread of discussion you hopped onto was >> specifically talking about if the "server box" was _initiating_ >> connections, right? > > Sorry. Role confusion. I usually don't think of "boxes" (or programs) > as client or servers -- so "server" was associated with SSH server. > That explains it :) -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2017-03-23 04:00 +0100 |
| Message-ID | <to18J-49M-5@gated-at.bofh.it> |
| In reply to | #179148 |
On 03/22/2017 03:35 AM, Dan Purgert wrote: > David Christensen wrote: >> On 03/17/2017 03:31 AM, Dan Purgert wrote: >>> David Christensen wrote: >>>> On 03/13/2017 05:38 AM, Dan Purgert wrote: >>>> [...] >> >> I should clarify that: >> >> "The backup server can be firewalled with no incoming ports and >> outgoing ports limited to SSH and other required ports". >> >> >> I still need to figure out the "other required outgoing ports". >> Suggestions and comments are welcome. > > Unfortunately, pretty much "all ephemeral ports", if the server is > running things that initiate connections. Some programs allow you to > specify what ports they're connecting from, but not all. I run ntpd on all my machines. So, ports 123/tcp and 123/udp need to be open for ongoing connections: 2017-03-22 19:30:03 dpchrist@jesse ~ $ grep ^ntp /etc/services ntp 123/tcp ntp 123/udp # Network Time Protocol >>> Since the PCs are laptops, they're not always here, so I was never able >>> to figure out how to get pull to work with the condition that we were on >>> vacation (or the laptops were otherwise "not home"). >>> >>> Though, yeah, the stuff that's statically here (desktop, server, etc.) >>> are rsync-by-pull. >> >> I haven't dealt with the "roaming laptop on the Internet" use-case yet, >> but I do have a desire to solve it. My idea has been, and remains, for >> the backup server to poll for a "job file" on the laptop, and to execute >> it when found (once; idempotent). This implies a network connection >> between the backup server and the laptop. OpenVPN is a technology that >> might be able to facilitate this. > > VPN could work, but SSH into a jumpbox works just as well. > > The push script checks /etc/resolv.conf for the local domain, if it's > mine, then backup to the backup-server directly. > > If it's not mine, backup "critical files" to the jumpbox (which, in turn > is backed up to the backup-server). It's quite a bit smaller than the > full backups that're performed at home - just $HOME/vacation. So, you have a static IP (or dynamic DNS) for your home Internet connection, you have your home gateway configured to allow incoming SSH connections and direct them to an internal host "jumpbox", and your laptop has a backup script that detects whether the laptop is on your LAN or on the Internet. If on the LAN, the backup script exits and waits for the backup server to pull a complete backup. If on the Internet, the backup script pushes critical files over SSH to a receiving directory on "jumpbox" (?). > SSH with key-auth only is plenty secure, and so far has never been one > of those things that've been blocked at a hotel. I have recently been studying up on SSH, both STFW and: https://www.michaelwlucas.com/tools/ssh SSH user keys with passphrases, disabling PasswordAuthentication, and ssh-agent/ssh-add are all good practices. David
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2017-03-23 10:40 +0100 |
| Message-ID | <to7nP-jM-7@gated-at.bofh.it> |
| In reply to | #179175 |
David Christensen wrote: > On 03/22/2017 03:35 AM, Dan Purgert wrote: >> David Christensen wrote: >>> On 03/17/2017 03:31 AM, Dan Purgert wrote: >>>> David Christensen wrote: >>>>> On 03/13/2017 05:38 AM, Dan Purgert wrote: >>>>> [...] >>> >>> I should clarify that: >>> >>> "The backup server can be firewalled with no incoming ports and >>> outgoing ports limited to SSH and other required ports". >>> >>> >>> I still need to figure out the "other required outgoing ports". >>> Suggestions and comments are welcome. >> >> Unfortunately, pretty much "all ephemeral ports", if the server is >> running things that initiate connections. Some programs allow you to >> specify what ports they're connecting from, but not all. > > I run ntpd on all my machines. So, ports 123/tcp and 123/udp need to be > open for ongoing connections: Good point, that :). I was just making a comment about "other required outgoing ports" (as many things just use an ephemeral port to initiate a connection, rather than a defined port, as with ntp). > [...] >> VPN could work, but SSH into a jumpbox works just as well. >> >> The push script checks /etc/resolv.conf for the local domain, if it's >> mine, then backup to the backup-server directly. >> >> If it's not mine, backup "critical files" to the jumpbox (which, in turn >> is backed up to the backup-server). It's quite a bit smaller than the >> full backups that're performed at home - just $HOME/vacation. > > So, you have a static IP (or dynamic DNS) for your home Internet > connection, you have your home gateway configured to allow incoming SSH > connections and direct them to an internal host "jumpbox", and your > laptop has a backup script that detects whether the laptop is on your > LAN or on the Internet. If on the LAN, the backup script exits and > waits for the backup server to pull a complete backup. If on the > Internet, the backup script pushes critical files over SSH to a > receiving directory on "jumpbox" (?). Close enough - the script on the laptops just switches between "rsync everything to backup-server, because you're at home" and "rsync only the 'vacation' folder to jumpbox, because you're not" -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2017-03-23 20:10 +0100 |
| Message-ID | <toghs-6GO-11@gated-at.bofh.it> |
| In reply to | #179181 |
On 03/23/2017 02:22 AM, Dan Purgert wrote: > David Christensen wrote: >> On 03/22/2017 03:35 AM, Dan Purgert wrote: >>> David Christensen wrote: >>>> On 03/17/2017 03:31 AM, Dan Purgert wrote: >>>>> David Christensen wrote: >>>>>> On 03/13/2017 05:38 AM, Dan Purgert wrote: >>>>>> [...] >>>> >>>> I should clarify that: >>>> >>>> "The backup server can be firewalled with no incoming ports and >>>> outgoing ports limited to SSH and other required ports". >>>> >>>> >>>> I still need to figure out the "other required outgoing ports". >>>> Suggestions and comments are welcome. >>> >>> Unfortunately, pretty much "all ephemeral ports", if the server is >>> running things that initiate connections. Some programs allow you to >>> specify what ports they're connecting from, but not all. >> >> I run ntpd on all my machines. So, ports 123/tcp and 123/udp need to be >> open for ongoing connections: > > Good point, that :). I was just making a comment about "other required > outgoing ports" (as many things just use an ephemeral port to initiate a > connection, rather than a defined port, as with ntp). At this point, I have only implemented incoming firewalling on all of my computers. But, I do want to implement outgoing firewalling on the backup server. Figuring it out will be interesting. >> [...] >>> VPN could work, but SSH into a jumpbox works just as well. >>> >>> The push script checks /etc/resolv.conf for the local domain, if it's >>> mine, then backup to the backup-server directly. >>> >>> If it's not mine, backup "critical files" to the jumpbox (which, in turn >>> is backed up to the backup-server). It's quite a bit smaller than the >>> full backups that're performed at home - just $HOME/vacation. >> >> So, you have a static IP (or dynamic DNS) for your home Internet >> connection, you have your home gateway configured to allow incoming SSH >> connections and direct them to an internal host "jumpbox", and your >> laptop has a backup script that detects whether the laptop is on your >> LAN or on the Internet. If on the LAN, the backup script exits and >> waits for the backup server to pull a complete backup. If on the >> Internet, the backup script pushes critical files over SSH to a >> receiving directory on "jumpbox" (?). > > Close enough - the script on the laptops just switches between "rsync > everything to backup-server, because you're at home" and "rsync only the > 'vacation' folder to jumpbox, because you're not" So, your computers push backups to the backup server. I feel safer if the backup server pulls backups and all incoming ports are closed. David
[toc] | [prev] | [next] | [standalone]
| From | Dominik George <nik@naturalnet.de> |
|---|---|
| Date | 2017-03-31 14:10 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <tr3xn-4rg-5@gated-at.bofh.it> |
| In reply to | #178810 |
>My understanding is that if there are no services listening on a port >then >it cannot be accessed. Well, if nothing is listening on a port, then something can start doing so unconditionally. That's how w^Hsomeone rooted Dreamhost. -nik
[toc] | [prev] | [next] | [standalone]
| From | Dominik George <nik@naturalnet.de> |
|---|---|
| Date | 2017-03-31 23:20 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <trc7D-1vo-3@gated-at.bofh.it> |
| In reply to | #179633 |
> On Fri, Mar 31, 2017 at 02:07:54PM +0200, Dominik George wrote: > > That's how w^Hsomeone rooted Dreamhost. > > Are you referring to the 2012 incident, or something more recent? > > I thought the former was an issue with lax filesystem permissions. (This is getting somewhat OT; if you want to discuss that further, maybe choose private conversation or another mailing list… I only intended to provide a scenario that was not made up.) Something less recent, from late 2010. The thing I described was reported only to the company themselves, who still failed to fix the root issue for several years. After their administrators and CEO (funnily enough, it was his webhosting account that had the vulnerable PHP application I was talking about…) had ignored the issue for more than a year, $someone dropped a note in the Chaos Communication Congress' wiki. What exactly this note was used for and what it was not used for is beyond my knowledge. -nik -- PGP-Fingerprint: 3C9D 54A4 7575 C026 FB17 FD26 B79A 3C16 A0C4 F296 Dominik George · Hundeshagenstr. 26 · 53225 Bonn Mobile: +49-1520-1981389 · https://www.dominik-george.de/ Teckids e.V. · FrOSCon e.V. Fellowship of the FSFE · Piratenpartei Deutschland Opencaching Deutschland e.V. · Debian Maintainer LPIC-3 Linux Enterprise Professional (Security)
[toc] | [prev] | [next] | [standalone]
| From | Nathan Dorfman <ndorf@rtfm.net> |
|---|---|
| Date | 2017-04-01 11:00 +0200 |
| Subject | Re: should I firewall an open port which isn't used? (was ... Re: Guide(s?) to backup philosophies) |
| Message-ID | <trc7D-1vo-5@gated-at.bofh.it> |
| In reply to | #179633 |
On Fri, Mar 31, 2017 at 02:07:54PM +0200, Dominik George wrote: > That's how w^Hsomeone rooted Dreamhost. Are you referring to the 2012 incident, or something more recent? I thought the former was an issue with lax filesystem permissions. -nd.
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web