nrw.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Wir sind eine freundliche Mastodon Instanz aus Nordrhein-Westfalen. Ob NRW'ler oder NRW-Sympathifanten, jeder ist hier willkommen.

Serverstatistik:

2,8 Tsd.
aktive Profile

#linuxnetworking

0 Beiträge0 Beteiligte0 Beiträge heute
Thomas Liske<p>Das Wetter ist hier so lala: statt eines schönen Landregens ist alles nur grau bewölkt 🤪 … also gute Gelegenheit meinen CLT Vortrag nachzuarbeiten:</p><p>Ihr findet neben der Aufzeichnung jetzt auch die Folien als PDF: <a href="https://chemnitzer.linux-tage.de/2025/de/programm/beitrag/306" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">chemnitzer.linux-tage.de/2025/</span><span class="invisible">de/programm/beitrag/306</span></a></p><p>Wer sich für die Demos interessiert findet hier die Quellen für das Ansible Deployment: <a href="https://codeberg.org/liske/clt2025-liske-firewalls" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/liske/clt2025-lis</span><span class="invisible">ke-firewalls</span></a></p><p>(Bei <span class="h-card" translate="no"><a href="https://mastodon.social/@clt_news" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>clt_news</span></a></span> ist wohl auch schlechtes Wetter, die Folien wurden innerhalb von 15min verlinkt 😅 - Danke! 🙏 )</p><p><a href="https://ibh.social/tags/clt2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>clt2025</span></a> <a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a></p>
Thomas Liske<p><a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a> 1.13.4 was released:<br><a href="https://codeberg.org/liske/ifstate/releases/tag/1.13.4" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/liske/ifstate/rel</span><span class="invisible">eases/tag/1.13.4</span></a></p><p>(already available in <span class="h-card" translate="no"><a href="https://fosstodon.org/@alpinelinux" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>alpinelinux</span></a></span> edge + 3.21 + 3.20 + 3.19 and in <span class="h-card" translate="no"><a href="https://c3d2.social/@m4rc3l" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>m4rc3l</span></a></span>'s Nix flake <a href="https://codeberg.org/m4rc3l/ifstate.nix" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/m4rc3l/ifstate.ni</span><span class="invisible">x</span></a>)</p><p>This maintenance release includes a single fix for the configuration of sysctl settings. The bug prevented ifstate from changing more than a single sysctl setting at a time. 🤦 </p><p><a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a></p>
Thomas Liske<p>Mein Vortrag von den <a href="https://ibh.social/tags/clt2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>clt2025</span></a> ist schon als Aufzeichnung verfügbar: <a href="https://media.ccc.de/v/clt25-306-firewalls-mandantenfahig-redundant-deklarativ" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">media.ccc.de/v/clt25-306-firew</span><span class="invisible">alls-mandantenfahig-redundant-deklarativ</span></a></p><p>Vielen Dank an alle die zugeschaut haben/es sich ggf. noch anschauen werden. Ich hoffe es hat euch ein paar neue Einblicke gegeben. Mir hat es wieder sehr viel Spaß gemacht. 🤗 </p><p>Und großen Dank an das Team der <span class="h-card" translate="no"><a href="https://mastodon.social/@clt_news" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>clt_news</span></a></span> und das <span class="h-card" translate="no"><a href="https://chaos.social/@c3voc" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>c3voc</span></a></span> 🙏 </p><p><a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a> <a href="https://ibh.social/tags/nftables" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nftables</span></a></p>
OSTechNix<p>How To Check And Secure Open Ports In Linux <a href="https://floss.social/tags/Linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linuxnetworking</span></a> <a href="https://floss.social/tags/Linuxsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linuxsecurity</span></a> <a href="https://floss.social/tags/Linuxadmin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linuxadmin</span></a> <a href="https://floss.social/tags/Linuxhowto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linuxhowto</span></a> <a href="https://floss.social/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://floss.social/tags/netstat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>netstat</span></a> <a href="https://floss.social/tags/ss" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ss</span></a> <a href="https://floss.social/tags/firewalld" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>firewalld</span></a> <a href="https://floss.social/tags/iptables" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iptables</span></a> <a href="https://floss.social/tags/nmap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nmap</span></a> <a href="https://floss.social/tags/lsof" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lsof</span></a> <br><a href="https://ostechnix.com/check-and-secure-open-ports-in-linux/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ostechnix.com/check-and-secure</span><span class="invisible">-open-ports-in-linux/</span></a></p>
Thomas Liske<p>I wonder how DSA network interfaces can be distinguished reliable. The port interfaces can be easily identified by the phys_port_name IFLA, but what is about the master interfaces?</p><p>I've access to a SoC which has a `dsa` and `eth0` interface (besides 4 port ifaces). Both have the same driver, the same businfo and the same mac address. How can they be distinguished at all, even if they have been renamed or moved into a netns?</p><p>Any ideas?</p><p><a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a> <a href="https://ibh.social/tags/DSA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DSA</span></a> <a href="https://ibh.social/tags/netlink" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>netlink</span></a> <a href="https://ibh.social/tags/iproute2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iproute2</span></a></p>
Thomas Liske<p><a href="https://ibh.social/tags/TIL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TIL</span></a> sysctl net.ipv4.conf.all.promote_secondaries</p><p>When enabled (it is not by default) one can remove the primary (read: first assigned) ipv4 address of an interface w/o removing all other assigned ipv4 addresses. This may help when you need to renumber remotely…<br> (…and do not have some declarative network configuration tool like <a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a> ;-)</p><p><a href="https://sysctl-explorer.net/net/ipv4/promote_secondaries/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">sysctl-explorer.net/net/ipv4/p</span><span class="invisible">romote_secondaries/</span></a></p><p><a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://ibh.social/tags/IPLegacyProblem" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IPLegacyProblem</span></a></p>
Kadin<p>Am I correct in thinking that <a href="https://mastodon.sdf.org/tags/Ubuntu" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ubuntu</span></a>'s default networking configuration, for a non-server install, uses both <a href="https://mastodon.sdf.org/tags/NetworkManager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetworkManager</span></a> for network configuration management and <a href="https://mastodon.sdf.org/tags/Systemd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Systemd</span></a> Resolved as a local stub DNS resolver?</p><p>Because that's how my workstation apparently works, and I don't remember doing anything to configure it that way explicitly.</p><p>And what an unholy fucking mess.</p><p><a href="https://mastodon.sdf.org/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.sdf.org/tags/LinuxNetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LinuxNetworking</span></a></p>
Thomas Liske<p><a href="https://ibh.social/tags/TIL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TIL</span></a> routes on Linux can have two different netlink attributes (NLA) for the next-hop: RTA_GATEWAY and RTA_VIA. The latter is set when a NLRI from another address family is used, only.</p><p>(And luckily nobody uses net-tools anymore: the old route command just ignores the RTA_VIA NLA and the route looks like a connected one 🤷)</p><p>…</p><p><a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://ibh.social/tags/routing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>routing</span></a> <a href="https://ibh.social/tags/netlink" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>netlink</span></a></p>
Dresden Internet Exchange<p>We've just published our latest article in our "IXP from Scratch" series on <span class="h-card" translate="no"><a href="https://mastodon.social/@ripencc" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ripencc</span></a></span> Labs! Dive into how we designed the network and security infrastructure at DD-IX. From choosing MicroVMs (<span class="h-card" translate="no"><a href="https://c3d2.social/@astro" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>astro</span></a></span>) on <span class="h-card" translate="no"><a href="https://chaos.social/@nixos_org" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nixos_org</span></a></span> and <span class="h-card" translate="no"><a href="https://fosstodon.org/@alpinelinux" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>alpinelinux</span></a></span> to navigating the challenges of IPv6-only networks. Learn about our services and the thought process behind each decision.</p><p><a href="https://labs.ripe.net/author/liske/ixp-from-scratch-network-and-security-design/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">labs.ripe.net/author/liske/ixp</span><span class="invisible">-from-scratch-network-and-security-design/</span></a></p><p><a href="https://dresden.network/tags/Networking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Networking</span></a> <a href="https://dresden.network/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://dresden.network/tags/IXP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IXP</span></a> <a href="https://dresden.network/tags/IPv6" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IPv6</span></a> <a href="https://dresden.network/tags/DDIX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DDIX</span></a> <a href="https://dresden.network/tags/Dresden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dresden</span></a> <a href="https://dresden.network/tags/LinuxNetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LinuxNetworking</span></a> <a href="https://dresden.network/tags/AlpineLinux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlpineLinux</span></a> <a href="https://dresden.network/tags/NixOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NixOS</span></a></p>
OSTechNix<p>Disable IPv6 in Linux: A Step-by-Step Guide <a href="https://floss.social/tags/ipv6" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ipv6</span></a> <a href="https://floss.social/tags/internetprotocol" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>internetprotocol</span></a> <a href="https://floss.social/tags/disableipv6" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disableipv6</span></a> <a href="https://floss.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://floss.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://floss.social/tags/linuxadmin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxadmin</span></a> <a href="https://floss.social/tags/linuxcommands" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxcommands</span></a> <a href="https://floss.social/tags/linuxhowto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxhowto</span></a> <br><a href="https://ostechnix.com/disable-ipv6-in-linux/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ostechnix.com/disable-ipv6-in-</span><span class="invisible">linux/</span></a></p>
Thomas Liske<p>ifstate 1.9.0 has been released:<br><a href="https://github.com/liske/ifstate/releases/tag/1.9.0" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/liske/ifstate/relea</span><span class="invisible">ses/tag/1.9.0</span></a></p><p>This version adds netns superpowers! 💪 </p><p>All features can now be used in network namespaces and the master and link options got netns support. For example, it is now possible to attach (|ip|mac)vlan sub-interfaces across network namespace boundaries.</p><p><a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a> <a href="https://ibh.social/tags/release" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>release</span></a> <a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a></p>
Elias Probst<p>Giving up for today trying to get <a href="https://mastodon.social/tags/8021x" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>8021x</span></a> (via ethernet, only using credentials, no certificates) working on <a href="https://mastodon.social/tags/NixOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NixOS</span></a> using <a href="https://mastodon.social/tags/wpa_suplicant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wpa_suplicant</span></a> and <a href="https://mastodon.social/tags/NetworkManager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetworkManager</span></a> authing against a <a href="https://mastodon.social/tags/UniFi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UniFi</span></a> infrastructure...</p><p>The debug output from both, NetworkManager, and (especially) wpa_supplicant is quite useless in this regard, as it focuses on technical mumble-jumble that might be useful to someone knees-deep into <a href="https://mastodon.social/tags/RADIUS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RADIUS</span></a>, but helps zero when it comes to a regular admin trying to get this working.</p><p><a href="https://mastodon.social/tags/LinuxNetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LinuxNetworking</span></a></p>
Thomas Liske<p>ifstate 1.8.1 has been released:<br><a href="https://github.com/liske/ifstate/releases/tag/1.8.1" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/liske/ifstate/relea</span><span class="invisible">ses/tag/1.8.1</span></a></p><p>This release contains many (critical) bugfixes. I had two recent incidents where routers booted without a network config due to these bugs in ifstate 😖 </p><p><a href="https://ibh.social/tags/ifstate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ifstate</span></a> <a href="https://ibh.social/tags/release" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>release</span></a> <a href="https://ibh.social/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> <a href="https://ibh.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a></p>
Chris<p>Anyone out there have <a href="https://fosstodon.org/tags/networking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>networking</span></a> experience on <a href="https://fosstodon.org/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> machines. Needing to get <a href="https://fosstodon.org/tags/RockyLinux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RockyLinux</span></a> talking to a windows domain controller and mount an smb share... or looking for other <a href="https://fosstodon.org/tags/linuxnetworking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linuxnetworking</span></a> solutions/suggestions.</p>