Friday, November 8, 2013

Hal-Hal Yang Harus Dilakukan Oleh Seorang System Administrator

Seorang system administrator mempunyai tanggung jawab yang cukup besar didalam sebuah perusahaan, semua data yang berkaitan dengan perusahaan tersebut menjadi tanggung jawab yang harus benar-benar dijaga oleh seorang system administrator. Dalam pengelolaan data-data tersebut mereka harus mengamankannya dari dari kerusakan file, kehilangan file, atau kerusakan yang disebabkan oleh pihak luar. Tidak ada orang yang langsung menguasai sesuatu secara langsung dan instant, semuanya akan menjalani proses-proses yang cukup panjang, jadi jika anda adalah seorang system administrator yang baru saja menginjakkan kaki dibidang infrastruktur sistem, jangan pernah berkecil hati atau minder karena anda seorang pemula. Percayalah, waktu akan membawa anda pada pengalaman yang luar biasa jika anda bisa memanfaatkannya. Dengan dibuatnya tulisan ini, mungkin akan menambahkan wawasan anda mengenai tugas-tugas penting yang harus dilakukan oleh seorang system administrator.

[ Monitoring Performance Server ]
Jangan perdulikan anda berada di instansi yang kecil, sedang, atau besar. Hal ini tetap harus diperhatikan, jangan sampai tidak! Karena jika performance server kita tidak stabil, maka dalam hitungan detik saja anda dapat memberikan kerugian pada perusahaan. Dan ketika user meng-complain kita, rasanya tidak enak didengar. Jadi monitoring performance server itu harus selalu pantau, Malah kalau bisa saya sarankan anda selalu mobile. Buatlah tool kecil yang bisa mengintegrasikan server-server dengan gadget anda. Mengingat perkembangan gadget yang semakin canggih belakangan ini, rasanya hal itu sudah sangat memungkinkan, tidak perlu yang bagus-bagus, buat saja yang sederhana. Asalkan SNMP server dapat berfungsi baik ketika salah satu server mengalami penurunan performance atau down. Jika anda bukan seorang developer dan malas seperti saya, anda juga bisa menggunakan monitoring tools yang sudah ada seperti misalnya Zenoss, openNMS, The Dude, Observium, atau yang lainnya. Dan jangan lupa untuk menginstall service sendmail didalam server monitoring anda, ini cukup membantu ketika server anda mengalami penurunan performance atau bahkan down, maka fitur-fitur pada tools tadi akan mengirimkan email kepada anda secara langsung. Biasanya error alert pada server ada tingkatannya, dari warning sampai critical warning. Jangan sampai anda mendapatkan notifikasi critical warning karena berarti kondisinya benar-benar gawat. Dengan tools tadi anda bukan hanya bisa memonitoring server tetapi juga perangkat-perangkat jaringan yang aktif seperti switch, router, dan access point. Tapi itu juga jika memang perangkat-perangkat tersebut mempunyai fitur SNMP.

[ Backup Data ]
Jangan besar kepala hanya karena anda handal mengendalikan performance server, baik itu dari segi pengaturan performance ataupun pengelolaan data, backup data tetap harus ada! Kita bahkan tidak tau apa yang akan terjadi dalam satu detik kemudian, jadi lebih baik mencegah daripada mengatasi. Dalam melakukan backup data sebaiknya dilakukan dalam beberapa metode sekaligus. Buatlah jadwal backup otomatis dengan tujuan yang berbeda. Saya pribadi membackup data-data server setiap hari, dari backup-backup harian tadi saya akan mem-burning setiap minggu. Boros memang, tapi rasanya worth it lah. Selain itu, buatlah sebuah server backup DRC (Disaster Recovery Center). Seperti yang tadi saya katakan, kita tidak tau apa yang akan terjadi satu detik kemudian, bencana alam atau kebakaran mungkin saja terjadi dan merobohkan gedung kantor anda. Dan saat itu terjadi, kita memiliki backup ditempat lain. Ya! DRC tidak boleh berada didalam gedung yang sama dengan gedung kantor kita, dikhawatirkan karena jika terjadi kehancuran pada gedung kantor utama dan mengakibatkan server kita rusak berat, maka kita mempunyai backup data secara utuh ditempat lain.

[ Keamanan. Jangan Membuka Port Yang Tidak Dipakai Oleh Aplikasi ]
Bicara mengenai kemanan tentunya kita tau akan bermain dengan firewall. Cara memasang firewall di server itu ada beberapa metode, anda bisa memakai metode drop all allow some atau allow all drop some. Sebelumnya saya pernah menjelaskan mengenai firewall secara detail di artikel ini, silahkan disimak jika anda belum pernah membacanya. Menurut saya pribadi membuka terlalu banyak port server itu adalah riskan. Sangat rentan sekali oleh serangan hacker. Jaringan itu luas, ada banyak watak yang bermacam-macam di setiap user nya. Tentu saja kita tidak menginginkan server-server kita kesurupan orang-orang yang tidak bertanggung jawab. Saya pribadi hanya membuka port-port yang memang dipakai oleh aplikasi, jika tidak untuk apa saya buka? Akses ssh pun saya rubah, saya segan membiarkan port ssh menggunakan port default. Jika server anda memakai system operasi linux, cara mengganti port ssh di linux juga sudah saya jelaskan di artikel sebelumnya. Dan juga, saya tidak membiarkan siapapun masuk selain orang-orang dengan IP address tertentu yang sudah saya patenkan dengan mac address nya di router.

Saya rasa masih banyak hal-hal yang harus dilakukan oleh seorang system administrator, tulisan kecil ini hanya gambaran secara global saja. Mungkin dilain kesempatan saya akan jelaskan lebih mendetail lagi. Semoga dapat menambah wawasan kepada anda.

Semoga bermanfaat,
Salam penguin! :)



Monday, November 4, 2013

How to extend home wifi signal using Coke Can for free (with realtime data log)



    I'm living in a two storey house and I always have problem with my wireless connection whenever I'm working upstairs.There is a way we can enhance our home wireless router range with some small can coke hack. In this post I'll be sharing how to do this trick.

   I will use the exact same location for my laptop for this purpose and will share the wireless reading from my machine. In Linux, we can see our wireless signal strength by using "watch" command. "watch" execute program periodically and will give output on the screen.By default it will give 2 sec return time interval.  we can change this using command below .



watch --internal 0.5 cat /proc/net/wireless         #returning 0.5 sec time interval

   My home is using Netgear Wifi router and with this project,I'm using Aztech WL230USB Wireless card


Below are the things that you need to do this trick,


                                          Figure 1: Item needed for this trick

1. A can
2. Scissor
3 .knife
4.Glove

Skill level : primary school :-)

Steps

1. Clean the can
2. Cut the bottom of the can
                                            Figure 2 : Coke can without bottom

3. Cut 3/4  vertically from sideways on top of the can (make sure the can tio is facing upward)

4. Use scissor to cut the can. Stretch the can open

                                                Figure 3 : Stretch the can


5. plug out the tip of the can
6. Install it to your modem.
                                         Figure 4 : Install the can to your router


7. Check your machine and  re direct the coke can to face  the location that you want the range to be at . The final position of the router in my house  is as below.

                                      Figure 5 : My final router setting
 

This is my machine  final reading  with current wireless router  setting.


                                   Figure 6: My   Wireless signal quality reading


we can also use "iwconfig"  command to get our machine wireless reading.

watch  --interval 0.5 iwconfig wlan0


Figure 7 :My Wireless signal quality reading 



Read Previous:How to make Torrent or any file to work in Firefox
Read Next : How to check your Wireless card supported interface mode

Saturday, November 2, 2013

Cara Mengamankan PhpMyAdmin Dengan SSL Mode HTTPS Di Linux Ubuntu

Bonjour! Server database adalah sebuah area yang sangat sensitif, dimana tidak bisa sembarang orang dapat mengaksesnya atau mengambil data didalamnya, apalagi jika mempunyai niat yang tidak baik. Semua itu harus dijauhkan dari server database karena akibatnya akan sangat fatal. Ada banyak metode yang bisa dilakukan oleh seorang system administrator.

Seperti yang kita ketahui bahwa PhpMyAdmin adalah salah satu media konsol database yang memudahkan pekerjaan kita daripada harus mengakses database menggunakan CLI. Namun terkadang resiko kesalahan bisa lebih besar ketika kita mengotak-atik database dengan konsol CLI daripada ketika kita mengaksesnya dengan PhpMyAdmin. Lalu pertanyaannya adalah, apakah kita yakin jika PhpMyAdmin kita buka maka server kita aman? Tentu tidak! Sebelumnya saya pernah membahas mengenai beberapa metode pengamanan PhpMyAdmin di linux. Sebenarnya dengan cara yang saya tulis di artikel tersebut sudah cukup aman, namun jika boleh saya jujur itu masih kurang aman. Karena didalam artikel saya tersebut PhpMyAdmin masih diakses dengan HTTP Mode. Itu artinya Sniffing masih mempunyai kemungkinan untuk dilakukan bukan? Tentu kita tidak mau server database kita di obrak-abrik oleh para hacker. Dengan ditulisnya artikel ini saya akan memberikan tutorial tentang bagaimana caranya mengamankan PhpMyAdmin dengan SSL Mode HTTPS di Linux. Metode ini saya praktekan dengan VM Ubuntu Server, bagi anda yang memakai distro linux lainnya sepertinya tidak akan berbeda terlalu jauh. Jika anda belum menginstall PhpMyAdmin di server anda, silahkan install terlebih dahulu, jika anda belum mengetahui cara install PhpMyAdmin di Linux anda bisa mengikuti langkah-langkahnya di artikel saya sebelumnya.

Baiklah kita mulai, saya memberikan IP Address 192.168.1.1 pada VM saya. Langkah pertama yang akan kita lakukan adalah kita memberikan autentikasi sebelum mengakses halaman login PhpMyAdmin. Hal ini sangat saya rekomendasikan untuk anda lakukan demi mengamankan PhpMyAdmin anda. Cara memberikan autentikasi pada PhpMyAdmin adalah :

Buka file /etc/phpmyadmin/apache2.conf. Lalu cari text "DirectoryIndex index.php". Lalu tambahkan line dibawahnya "AllowOverride All".
<Directory /usr/share/phpmyadmin>
Options FollowSymLinks
DirectoryIndex index.php
AllowOverride All
. . .

membuat file .htaccess pada folder /usr/share/phpmyadmin/. Masukkan script dibawah ini :
AuthType Basic
AuthName "Restricted Files"
AuthUserFile /etc/phpmyadmin/.htpasswd
Require valid-user

Script diatas akan mengarahkan user pada autentikasi sebelum mengakses halaman login PhpMyAdmin. Username dan password yang digunakan untuk autentikasi tersebut berbeda dengan username dan password yang dipakai untuk mengakses MySQL via CLI atau via PhpMyAdmin. File username dan password untuk autentikasi ini akan disimpan di folder /etc/phpmyadmin/.htpasswd. Selanjutnya yang akan kita lakukan adalah membuat username dan password untuk autentikasi. Ketikkan perintah ini di server atau VM anda :
sudo htpasswd -c /etc/phpmyadmin/.htpasswd user_name
Setelah anda menekan enter untuk perintah tersebut, anda akan disuruh membuat password untuk user tersebut. Perintah ini akan membuat sebuah user untuk autentikasi sebelum mengakses halaman login PhpMyAdmin dan file tersebut akan disimpan pada file /etc/phpmyadmin/.htpasswd. Untuk mengujinya silahkan restart service apache anda.
sudo service apache2 restart
Maka seharusnya anda mendapatkan tampilan seperti ini :

Autentikasi sebelum mengakses login page PhpMyAdmin

Selanjutnya adalah kita akan memaksa PhpMyAdmin diakses melalui HTTPS, bukan HTTP. Ini bertujuan supaya setiap transaksi data antara kita dan server tersebut di enkripsi. Jadi tidak ada kesempatan bagi para hacker untuk melakukan sniffing. Cara mengkonfigurasi HTTPS SSL Mode di Linux sebenarnya sudah saya bahas diartikel sebelumnya. Tapi daripada ribet, saya akan menuliskan ulang diartikel ini. Cara konfigurasi PhpMyAdmin dengan HTTPS SSL Mode, pertama, lakukan dua perintah dibawah ini pada server anda :
sudo a2enmod ssl
sudo service apache2 restart

Lalu buatlah direktori untuk menyimpan file certificate SSL, dan buatlah cert dan key dengan perintah ini :
sudo mkdir /etc/apache2/ssl
sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/apache2/ssl/apache.key -out /etc/apache2/ssl/apache.crt

Perintah diatas akan membuat file certificate yang berlaku untuk 365 hari atau 1 tahun dengan enkripsi 2048 bit. Lalu kedua file tersebut akan disimpan didalam folder /etc/apache2/ssl. Setelah anda menekan enter untuk perintah tersebut, anda harus mengisi pertanyaan-pertanyaan yang tampil seperti dibawah, isilah dengan benar.
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:ID
State or Province Name (full name) [Some-State]:West Java
Locality Name (eg, city) []:Bandung
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Apocalypsix Inc
Organizational Unit Name (eg, section) []:IT Dept
Common Name (e.g. server FQDN or YOUR name) []:apocalypsix.com
Email Address []:webmaster@apocalypsix.com

Setelah membuat file certificate dan key kita tambahkan NameVirtualHost :443 didalam file /etc/apache2/ports.conf. Lalu selanjutnya adalah mengkonfigurasi file site default-ssl di folder /etc/apache2/default-ssl. Masukkan lokasi apache.key dan apache.cert yang kita buat sebelumnya. Cari dan rubah line tersebut sesuai path masing-masing.
SSLEngine on
SSLCertificateFile /etc/apache2/ssl/apache.crt
SSLCertificateKeyFile /etc/apache2/ssl/apache.key

Tutup dan save. Lalu selanjutnya adalah memaksa PhpMyAdmin diakses melalui HTTPS. Masukkan script dibawah ini kedalam file /etc/phpmyadmin/config.inc.php. Simpan script ini di line paling bawah.
$cfg['ForceSSL'] = true;

Simpan dan Tutup file. Lalu aktifkan site default-ssl
sudo a2ensite default-ssl
sudo service apache2 restart

Untuk melihat hasilnya anda bisa coba dengan memanggil phpmyadmin.
192.168.1.1/phpmyadmin

Pertama anda akan melihat tampilan seperti dibawah ini. Masukkan username dan password yang kita buat tadi.
Autentikasi sebelum login page PhpMyAdmin

Lalu setelah anda login akan tampil halaman seperti ini :
Security warning SSL
Dan akhirnya anda akan melihat login page PhpMyAdmin :
Login Page PhpMyAdmin
Login dengan username dan password mysql anda.
PhpMyAdmin

Dan sekarang server database anda sudah lebih aman dari sebelumnya. Cara mengamankan PhpMyAdmin dengan SSL Mode HTTPS di linux tidak sulit bukan. Semoga artikel ini membantu anda.

Semoga bermanfaat,
Salam penguin! :)

Thursday, October 31, 2013

How to make Torrent or any file to work with Firefox (Ubuntu 12.04)

   
 Whenever we click a file to download using Torrent client,  Torrent will use   ".magnet"  protocol to communicate with it's peers in the network. The idea of this  protocol is using the content cryptographic hash value of the file rather than of it's location. This protocol  use metadata content to be located by our machine.

  In this post I'll share how we can solve the problem of Torrent file magnet that can't work  with Firefox. This problem happen because Firefox doesn't recognize the ".magnet" file .Below are the steps taken to resolve this problem:

1. Open  Firefox browser and type "about:config "

2. Search for file "network.protocol-handler.expose.magnet"   this file determine whether our browser know which application need to be open with ".magnet" file type .

3. Right click and choose
"New>boolean> (key in network.protocol-handler.expose.magnet) > false"

4.Make sure the file is configure in our browser.

5. Go to torrent file and click it to open

6. Choose the type of application that you want  to run with ".magnet" file .
 (search for your bittorent client) .

/usr/bin/transmission


    There you go.Your browser should  able to work with torrent file.To know more about what type of application associate with your browser, Go to your browser

Edit>Preference>Application

You should have something like this
 
Application associate with Firefox Browser
                                     
                                     

Wednesday, October 30, 2013

GPON for dummies :Basic Passive Optical Network Concept (Series 2)


Why need to Migrate the network?

     In my previous post, I've described the problem that we have in our traditional DSLAM network which is the contradiction between  Bandwidth vs Distance . It must be highlighted here that our traditional Access Network need to  migrate to IP Base architecture.  This migration is necessary to accommodate the changing of our technology  and to ease the maintenance of the network . A clear Idea can be understand from  below diagram.

Figure 2.1 The Changing of technology and network

                         


    When we connect to  internet  , This is some of the technologies that were use in  the backbone. The migration from traditional network is necessary for us to meet the challenge of future technology expansion and requirement. The world that we  live today is becoming smaller and smaller, although I don't like the idea of absolute globalization, but this technologies might help those in need of learning in area that not even possible for us to travel . Just imagine next time we can have realtime meeting with anyone from around the world from the comfort of our own house.I believe this is essence of technology which should make our life easier .


Active and Passive Optical Network

   Passive Optical Network  (PON) and Active Optical Network (AON)  is a communication type used to transmit data from one point to many connection. In Telecommunication,this is known as point to multiple points  or known as abbreviation  P2MP .

    Fiber optics uses light signal to transmit data to  its destination.In order for data to successfully transmit  to its destination,   There are two main concept for this to happen which is Active Optical Network (AON) and Passive Optical Network (PON) .  AON uses power switching like switch aggregator to manage the signal distribution. PON on the other hand does not include this power switching but uses passive splitter to transmit data to its destination. Power equipment only needed at the starting and end point within the network.We will have a look on PON later in this post.

  Since AON is using switch aggregator, the switch open and closes depending on the signal and direct the incoming and outgoing data to it's destination . The  data transmission using AON is properly deliver.The disadvantage of running AON is it require active power equipment and need at least one aggregator for every 48 subscriber.With this understanding ,the building cost of installing AON in network is extremely expensive and is not a cost effective especially in delivering in large network.

    PON on the other hand does not require electrical power switch .The data transmission uses optical splitter to collect and separate as it moves through the network. PON is more reliable to be install in large scale network because of the low building cost and less maintenance cost as compared to AON.The main disadvantage of PON network is that troubleshooting and isolating the problem might be difficult if there is failure in the network.Diagram below show  a component in PON network

Figure 2.2  Passive Optical Network (PON)
                                                   
                                 

     A PON network consists of Optical Line Terminal (OLT),  Optical Network Unit (ONU), and Passive Optical Splitter (POS) .Optic Line Terminal (OLT) is the equipment at the central office or service provider location while Optic Network Terminal (ONT) is the power equipment in the customer end . The transmission between the splitter is running using Wave Division Multiplexing (WDM) technologies. Figure 2.3 below show a detail information of  a PON Model . 



Figure 2.3   GPON Model


    OLT  is located in service node interface (SNI) while ONT on the other hand is located in User network interface (UNI) in the big picture of PON network . This is so because of the equipment  location in the network. OLT is connected to the upper layer of the network and ONT is at the user end premises  in the network .More on this later in the next chapter. .
                                            
Thats it for now . I'll be discussing more about PON standard  next time. Happy blogging!!

Friday, October 25, 2013

GPON for dummies :Optical Access Network (Series 1)

  Currently I'm living in Australia and there  are a lot of news about the high speed broadband in the newspaper. I believe the company that does it now is NBN Co. For those who don't know what is FTTH,I'll share a little bit of information on this .I'll separate it to different part  to make things easy. In this part, I'll be explaining in general the idea of the term that widely being use and will go into more detail in chapters to come.

Optical Access Network Architecture

  First and foremost,.What is FTTH, FTTN,FTTB, FTTC or what the heck is all this term?All this term belong to Optical Access  Network architecture .This branch of technology is controlled by major Telecommunication company like Huawei ,ZTE, Alcatel-Lucent ,Ericsson-Marconi . 


                                Figure 1.1 Example of Optical Access Architecture

   Previously, our traditional internet connection using Digital Subscriber Line Access Multiplexer (DSLAM)  type of network architecture. DSLAM make use the existing telephone copper to deliver xDSL service. The preferable distance  from the Central Office (CO) to business premise need to be less than  <5km .I will share the details of xDSL technology limitation on different article.For time being  just understand that copper have limitation in term of Bandwidth vs Distance. In other words , DSLAM can't efficiently deliver it's services to those in rural area that is  more than >5 km from the CO .

  To resolve the issue of Bandwidth vs Distance, we have the not so new technology called Passive Optical Network (PON) and Active Optical Network (AON).I will focus on PON in this article and will write more on the differences on future post. As you can see in above photo ,PON technology used fibre optic to extend the long reach of its service to business premises. Thus this help to resolve the  problem that we have in our traditional DSLAM network.

  From the above architecture diagram,  the fiber is split to external plant from Central Office (CO) using Optical Distribution Network (ODN) .ODN  consist of a passive element that split the fiber to the respective architecture scenario. In real world ODN network is what we see  being installed by the contractor physically by digging/trenching or boring at the footpath . Some of the splitter is left inside the pit and from one pit to the next pit is connected by a pipe.The fiber is lay inside this pipe to reach its destination .In layman term the ODN network architecture is also known as pit and pipe architecture .

 The different application between each architecture is describe  as below:

Fiber to the home (FTTH) consist scenario of
1.single family unit  which able to provide a comparatively small number of ports, including  VOIP, 10/100/1000BASE-T, and RF.

Fiber to the building (FTTB)  :consist scenario of
1.Single business unit which able to provide a comparatively small number of ports such as  10/100/1000BASE-T, RF, and DS1/T1/E1 ports


2.Multi-tenant business unit which able to  provide  a comparatively larger number of ports, including  10/100/1000BASE-T, RF and DS1/T1/E1 ports. xDSL technologies


Fiber to the curb/node (FTTC/FTTN) consist scenario of
1.DSLAM/MSAN (Multiple Service Access Node) which able to provide a comparatively larger number of ports, including  10/100/1000BASE-T, RF, xDSL technologies


  The advantage of deploying FTTN network is  it can save considerable amount of money by not installing fibre optic cable to each premise . Rather, the fiber optics cable can just be install from CO to side of neighbourhood road/curb. FTTN can utilize the existing copper telephone network to deliver it's services .The disadvantage of this is, it will limit the network expansion for future growth and there is possibility of copper deteriorate throughout time .Before deploying FTTN a considerable amount of consideration is needed and understanding on the direction that will be taken by the company for future business growth .

  Beside this few example,there are a different number of design that we can do using FTTN network namely point to point, ring and star type of connection. I will update more about this in later post.

Please subscribe to this blog and like my Youtube  channel for more tips and tricks!!


How to add URL in Blekko Search Engine

In this post,I'm going to share How to add URL in Blekko Search Engine.

Steps:

1.You need to register an account with Blekko

2. Click your profile



3.Click create a new tag

4. Add your slashtag (any name)

5.key in your URL/website.

6.click search to add it to your slashtag

7. For adding your own website,type your website’s URL into the section entitled “List websites and slashtags:” and add it under the slashtag