Mein Provider und Arbeitgeber stellt mir an meinem VDSL Anschluss eine Fritz!Box 7590 zur Verfügung. Diese ist aktuell noch im Router Modus. Die Fritz!Box macht auf deren WAN Seite DHCPv4 und DHCPv6 mit einer öffentlichen IPV4 Adresse und einem /56 IPv6 Prefix. Auf LAN Seite liegt ein privates /24 IPv4 Netz an.
Auf meinem Homeserver virtualisiere ich mit KVM Gäste und LXC Container. Ein wichtiger KVM Guest ist meine OPNSense.
Heute möchte ich darüber berichten, was für ein großartiges Tool wireguard ist. Ich beschreibe hier, was es macht, wie man es konfiguriert und welche Möglichkeiten sich daraus ergeben.
Wireguard wird gerne als das neue, schnelle VPN des Linux Kernels beschrieben. Dabei gibt es aber zwei Probleme. Patches liegen für den mainline Linux Kernel schon seit einiger Zeit vor. Dennoch dauern die Diskussionen um eine Aufnahme weiter an, da wireguard eine neue crypto-api einführen möchte. Zweitens vermuten Menschen unter VPN eine Lösung, die einen Client mit einem Netz oder zwei Netze untereinander verbindet, dies leistet wireguard aber gar nicht von Haus aus.
RANCID monitors a router's (or more generally a device's) configuration, including software and hardware (cards, serial numbers, etc) and uses CVS (Concurrent Version System) or Subversion to maintain history of changes.
RANCID does this by the very simple process summarized as:
- login to each device in the router table (router.db),
- run various commands to get the information that will be saved,
- cook the output; re-format, remove oscillating or incrementing data,
- email any differences (sample) from the previous collection to a mail list,
- and finally commit those changes to the revision control system
Scapy is a powerful interactive packet manipulation program. It is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more. It can easily handle most classical tasks like scanning, tracerouting, probing, unit tests, attacks or network discovery (it can replace hping, 85% of nmap, arpspoof, arp-sk, arping, tcpdump, tethereal, p0f, etc.). It also performs very well at a lot of other specific tasks that most other tools can't handle, like sending invalid frames, injecting your own 802.11 frames, combining technics (VLAN hopping+ARP cache poisoning, VOIP decoding on WEP encrypted channel, ...), etc. See interactive tutorial and the quick demo: an interactive session (some examples may be outdated).
Ostinato is an open-source, cross-platform network packet crafter/traffic generator and analyzer with a friendly GUI. Craft and send packets of several streams with different protocols at different rates. For the full feature list see below.
Ostinato aims to be "Wireshark in Reverse" and become complementary to Wireshark.