Wednesday, September 21, 2011

Installing a centralized syslog

Remember that I told you about this guide? So here it is. Basically, it explains step by step how to install Adiscon LogAnalyzer in an Ubuntu box. Let me know if something's not clear enough:


The Prep:

Before we dive into setting up any of this we need to do a little prep work. If you are going to be looking at these logs in a web browser then it might be good if the time stamps you are seeing reflect the appropriate timezone.

Monday, September 19, 2011

Terminal Services Gateway

We were looking for some solution where we can centralize every RDP session coming from outside (especially for vendor access), and we ended up with 2 choices: Citrix or Terminal Services Gateway (now known as Remote Desktop Services Gateway). Considering we already have licenses for Terminal Services, we are taking the latter. If you don't know what it is, here's a brief explanation.

Windows Server Terminal Services uses Remote Desktop Protocol (RDP) to enable the connections from clients to the terminal server, which uses port 3389. If you need to access a terminal server from outside the internal network (intranet), you have two options for doing so. You can either enable port 3389 through your firewall to specific servers (which isn’t a good idea), or, more commonly, clients connect to the corporate network via VPN, which can then enable the RDP session in a secure manner.

Friday, September 16, 2011

vSphere Syslog Collector

I was trying to find a way to create a syslog server where I could centralize all my ESX hosts' logs. I was between options (like Kiwi, phpsyslog-ng, etc.) when I decided to do it with Adiscon LogAnalyzer, which is a free and opensource solution. I'll post a guide for its installation in another post (because I actually installed it successfully all the way).

When I was about to add the ESX hosts to my sources list in the syslog server, I found out that vSphere 5 contains a new feature called VMware Syslog Collector, and since we'll be migrating to that version in a few weeks, makes no sense to move on with my LogAnalyzer.

Thursday, September 15, 2011

UDP reference

You have to remember diferences between TCP and UDP. Here's a quick definition of UDP:

UDP is the User Datagram Protocol. It is used to send individual packets across an IP network, in an unreliable fashion. This means that successful, error-free delivery of a message is not guaranteed.

So remember that UDP is not reliable but it's fast! Examples of protocols that use UDP are TFTP, DNS (it can use TCP too!), DHCP, SNMP, RCP, NFS.

If you're really interested in its standard and how it's defined, you should definitely read the RCF doc here:

RFC 768 - User Datagram Protocol


And finally a couple of jokes:

"A UDP packet walks into a bar, no one acknowledges him.
A TCP packet walks into a bar twice because no one acknowledged him the first time."

"The best thing about UDP jokes is i don’t care if you get it or not."