• Lomin Security
    • Location
    • NAICS and SIC Codes
    • Press
      • Lomin Quick Facts
      • Press Releases
  • Blog
  • SIM CD
    • SIM CD History
    • SIM CD Forums
    • SIM CD Downloads
    • OSSIM
    • CentOS on SIMCD
  • Services
    • Software Development
      • Security Applications
      • Open Source Solutions
      • System Integration
    • IA Consultants
    • IA Training
      • IDS Analyst Training
    • Staffing
  • Job Opportunities
  • Online Store
  • Contact Us
    • Lomin Security Email List

A Computer Network Defense Company

Developing ideas with the strength & courage to defend.

Feed
  • Site Navigation

    • Lomin Security
    • Blog
    • SIM CD
    • Services
    • Job Opportunities
    • Online Store
    • Contact Us
  • Email Subscription





    Emails managed with Mad Mimi

  • m0n0wall 1.2 Is Not Upgrading

    By: jminto

    No comments

    A A

    M0n0wall is a terrific firewall setup. It is a highly recommended replacement for netgear or Linksys routers with their proprietary/esoteric interfaces. M0n0wall has an easy to use web interface with concise help on how to program its various settings. Recently, however, I experienced an interesting problem.

    M0n0wall is built to work on a dual nic embedded device.  M0n0wall comes standard with a number of fabulous utilities (from m0n0wall features):

    • wireless support (access point with PRISM-II/2.5/3 cards, BSS/IBSS with other cards including Cisco)
    • captive portal
    • 802.1Q VLAN support
    • stateful packet filtering
      • block/pass rules
      • logging
    • NAT/PAT (including 1:1)
    • DHCP client, PPPoE, PPTP and Telstra BigPond Cable support on the WAN interface
    • IPsec VPN tunnels (IKE; with support for hardware crypto cards, mobile clients and certificates)
    • PPTP VPN (with RADIUS server support)
    • static routes
    • DHCP server and relay
    • caching DNS forwarder
    • DynDNS client and RFC 2136 DNS updater
    • SNMP agent
    • traffic shaper
    • SVG-based traffic grapher
    • firmware upgrade through the web browser
    • Wake on LAN client
    • configuration backup/restore
    • host/network aliases

    Sounds great, but where do I get one? You may roll your own embedded system or purchase one from a few different vendors. Logic Supply is a great place to purchase a m0n0wall systems pre-configured for use. They feature mini-ITX systems. Their physical and electrical footprint is very small. You can find their m0n0wall systems here below, where the cheapest is around $300.00:

    http://www.logicsupply.com/categories/firewall_systems

    defend Yourself maillist!!!

    Signup for the Lomin Security MailList to receive exclusive Network Defense content.

     





    Emails managed with Mad Mimi

     [padlock button]

    Interesting Problem

    Recently, I had to upgrade a m0n0wall system from version 1.2 to version 1.3. The upgrade appeared to work, but it did not. There was no clue of failure from the console or the web interface. Each update would reveal firmware 1.2 still installed.

    Did I mention that m0n0wall was great?

    It is great, m0n0wall does use a syslog daemon. Configure it to send logfiles to central log repository. If you don’t have one – install a virtual machine to collect them or use some sort of wacky windows/eventlog/syslog/snarfer. An interesting message was found after m0n0wall was configured to forward its logfiles:

    Mar 15 10:10:05 10.0.0.1 /kernel: pid 217 (php), uid 0 on /ftmp: file system full

    That was the key bit of information I needed. df –h on the m0n0wall revealed that there was indeed not enough room on its file system for the new image. So the upgrade would blissfully fail and only alert the failure via syslog.

    After a bit of research, this email was found:

    http://m0n0.ch/wall/list/showmsg.php?id=341/38

    It was not the exact problem, but sure enough, it solved everything. Essentially, you have to babystep the upgrade. There is not enough room on the old file system for the latest version of m0n0wall. Upgrading incrementally allowed the system to accept the newer versions.

    Thank you m0n0wall!!

    Related posts:

    1. Ntop 3.310 and FreeBSD 8.0
    2. OpenBSD dos2unix

    CND, CNO

    BSD, firewall, FreeBSD, m0n0wall, System Administration

     

    Leave a Reply

    Click here to cancel reply.

    CAPTCHA Image
    CAPTCHA Audio
    Refresh Image

© Copyright 2005-2010 Lomin LLC. All rights reserved. Privacy Policy. Disclaimer.