Setup n2n-supernode » Historie » Version 3
Jeremias Keihsler, 12.01.2017 09:59
1 | 1 | Jeremias Keihsler | h1. Install n2n-Supernode |
---|---|---|---|
2 | |||
3 | h2. Requirements |
||
4 | |||
5 | To install n2n you will need the following: |
||
6 | * a installed and supported operating system (e.g. CentOS 6.x) |
||
7 | * root-access |
||
8 | * EPEL repository |
||
9 | * a fast internet connection |
||
10 | |||
11 | h2. Preliminary note |
||
12 | |||
13 | most of this is taken from |
||
14 | * [[http://www.ntop.org/products/n2n/]] |
||
15 | * [[https://github.com/lukablurr/n2n_v2_fork/blob/master/doc/multiple-supernodes.pdf]] |
||
16 | * [[http://listgateway.unipi.it/mailman/listinfo/n2n]] |
||
17 | * [[http://listgateway.unipi.it/pipermail/n2n/2009-October/000300.html]] |
||
18 | |||
19 | h2. Install |
||
20 | |||
21 | <pre><code class="bash"> |
||
22 | yum install n2n |
||
23 | </code></pre> |
||
24 | |||
25 | h2. manual testing |
||
26 | |||
27 | h3. starting Supernode |
||
28 | |||
29 | <pre><code class="bash"> |
||
30 | supernode -l 5422 |
||
31 | </code></pre> |
||
32 | |||
33 | h3. setting up firewall |
||
34 | |||
35 | in order to access the supernode from one of the edge-clients the given UDP-port must be accessible from outside. Therefore we need to open the firewall. |
||
36 | <pre><code class="bash"> |
||
37 | system-config-firewall-tui |
||
38 | </code></pre> |
||
39 | |||
40 | h2. running n2n-Supernode as a service |
||
41 | |||
42 | if everything is working as expected we maybe want n2n-Supernode to survive a system-reboot. |
||
43 | |||
44 | The following should work without modification for RHEL/CentOS linux and similar: |
||
45 | |||
46 | Create a folder /etc/n2n and create configuration files (as described below) using following file name format: |
||
47 | |||
48 | <pre><code class="bash"> |
||
49 | mkdir /etc/n2n |
||
50 | </code></pre> |
||
51 | |||
52 | <pre><code class="bash"> |
||
53 | supernode-gw1.example.com |
||
54 | supernode-gw2.example.com |
||
55 | supernode-*.example.com |
||
56 | </code></pre> |
||
57 | |||
58 | The interesting contents of supernode-gw1.example.com would look similar to this: |
||
59 | |||
60 | <pre><code class="bash"> |
||
61 | vim /etc/n2n/supernode-gw1.example.com |
||
62 | </code></pre> |
||
63 | <pre> |
||
64 | # == supernode config values parsed by /etc/rc.d/init.d/edged == |
||
65 | # Read 'man supernode' for details about these values... |
||
66 | # |
||
67 | # Example port number to listen on... |
||
68 | N2N_PORT="8765" |
||
69 | |||
70 | # Verbose or not (-v logs to std out)... |
||
71 | # N2N_OPTS="-v" |
||
72 | N2N_OPTIONS="" |
||
73 | 3 | Jeremias Keihsler | # === end supernode-gw1.example.com config file ================ |
74 | 1 | Jeremias Keihsler | </pre> |
75 | |||
76 | Read comments in the scripts below to make more sense out of how they work. |
||
77 | |||
78 | Here are copies of some scripts that work when used with configuration files as described above: |
||
79 | |||
80 | <pre><code class="bash"> |
||
81 | vim /etc/init.d/supernoded |
||
82 | </code></pre> |
||
83 | <pre> |
||
84 | #!/bin/sh |
||
85 | # $Id: supernoded.init,v 1.9 2009/10/23 12:34:56 |
||
86 | # n2n supernode startup script. |
||
87 | # |
||
88 | # chkconfig: 345 96 26 |
||
89 | # processname: supernode |
||
90 | # pidfile: /var/run/n2n-supernode.pid |
||
91 | # |
||
92 | # short-description: Provides client-to-client VPN access via Internet |
||
93 | # description: This is startup script for n2n 'edge', |
||
94 | # n2n edge + supernode provide internet connection for vpn peers |
||
95 | # |
||
96 | # SEE: |
||
97 | # for more options n2n 'man edge' and 'man supernode' |
||
98 | # |
||
99 | # NOTE: |
||
100 | # Option to enter 'debug' as second var: e.g 'supernode start debug' |
||
101 | # Using grep -w switch searches for whole word reduces ambiguity |
||
102 | # Comment in/out the 'echo' stuff depending if thigs work as expected |
||
103 | # Config files located/named in: /etc/n2n/supernode-your.example.com |
||
104 | # Assumes CentOS linux init scripts located in /etc/rc.d/init.d/ |
||
105 | # |
||
106 | # Created: FOOFORCE RB 2009-10-24 |
||
107 | # License GPL: free to copy, improve and use. |
||
108 | # http://fuji.unipi.it/pipermail/n2n/2009-October/000300.html |
||
109 | 2 | Jeremias Keihsler | # =============================================================== |
110 | 1 | Jeremias Keihsler | |
111 | 2 | Jeremias Keihsler | # ==== main init script variables =============================== |
112 | 1 | Jeremias Keihsler | # Make sure you include path where 'supernode' + sh + tools are installed.. |
113 | # PATH="/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin" |
||
114 | PATH="/sbin:/bin:/usr/sbin:/usr/bin" |
||
115 | |||
116 | # The name + path to the program/daemon... |
||
117 | NAME="supernode" |
||
118 | DAEMON="/usr/sbin/${NAME}" |
||
119 | |||
120 | # Modify $NAME to filter on 'grep -w [s]supernode' - faster than 'grep -v grep'... |
||
121 | GREPNAME=$(echo "[s]${NAME#s}") |
||
122 | |||
123 | # Enable some simple debug messages when running this script... |
||
124 | if [[ "${2}" == "debug" ]]; then |
||
125 | echo "DEBUG: ${GREPNAME}" |
||
126 | fi |
||
127 | |||
128 | PIDFILE="/var/run/supernode.pid" |
||
129 | LOGFILE="/var/log/n2n-${NAME}.log" |
||
130 | STAMP=$(/bin/date +"%d/%b/%Y %H:%M:%S") |
||
131 | |||
132 | # Get the host/domain name to identify local configfile.. |
||
133 | HOST=$(/bin/hostname) |
||
134 | FQDN=$(/bin/hostname -f) |
||
135 | |||
136 | # Initialise configfile variable to empty value... |
||
137 | CONFIGDIR="/etc/n2n" |
||
138 | |||
139 | # Initialise configfile variable to empty value... |
||
140 | CONFIGFILE="" |
||
141 | |||
142 | # Source function library. |
||
143 | . /etc/rc.d/init.d/functions |
||
144 | |||
145 | # Load values from configfile using our local domain name: |
||
146 | # Example: |
||
147 | # Our local FQDN = 'myhost.example.com' |
||
148 | # Our configfile = 'supernode-myhost.example.com' |
||
149 | # |
||
150 | # if [[ "${HOST}" == "" ]]; then |
||
151 | if [[ "${FQDN}" == "" ]]; then |
||
152 | echo " ERROR: Missing ${FQDN} hostname in config file /etc/rc.d/init.d/${NAME}" |
||
153 | exit 1 |
||
154 | else |
||
155 | CONFIGFILE="/etc/n2n/supernode-${FQDN}" |
||
156 | fi |
||
157 | |||
158 | if [[ -f "${CONFIGFILE}" ]]; then |
||
159 | # Get values from local configuration file... |
||
160 | if [[ "${2}" == "debug" ]]; then |
||
161 | echo " Found config file: ${CONFIGFILE}" |
||
162 | fi |
||
163 | . ${CONFIGFILE} |
||
164 | else |
||
165 | echo "ERROR: Missing config file ${CONFIGFILE}" |
||
166 | exit 1 |
||
167 | fi |
||
168 | |||
169 | # See if pid file exists and get pid number... |
||
170 | if [[ -f "${PIDFILE}" ]]; then |
||
171 | CURPID=$(cat ${PIDFILE}) |
||
172 | fi |
||
173 | |||
174 | # Quit if we can't find application... |
||
175 | test -f ${DAEMON} || exit 0 |
||
176 | |||
177 | set -e |
||
178 | |||
179 | # Set any value to enable this script... |
||
180 | # N2N_RUN=1 |
||
181 | # |
||
182 | # test -n "${N2N_RUN}" || exit 0 |
||
183 | |||
184 | # Optionaly change into n2n config directory... |
||
185 | if [[ -d "${CONFIGDIR}" ]]; then |
||
186 | cd ${CONFIGDIR} |
||
187 | fi |
||
188 | 2 | Jeremias Keihsler | # ============================================================== |
189 | 1 | Jeremias Keihsler | # Should not need to change much below here... |
190 | 2 | Jeremias Keihsler | # ==== see how we were called + act accordingly =============== |
191 | 1 | Jeremias Keihsler | |
192 | if [ "${N2N_PORT}" == "" ]; then |
||
193 | N2N_PORT="1304" |
||
194 | echo "No port specified in ${CONFIGFILE} - using default port: ${N2N_PORT}" |
||
195 | fi |
||
196 | |||
197 | case "${1}" in |
||
198 | start) |
||
199 | # echo " ${NAME} ${1} process is ${0} on pid: ${$})..." |
||
200 | echo "${STAMP} start n2n /etc/rc.d/init.d/${NAME}" >> ${LOGFILE} |
||
201 | |||
202 | if [[ -n "${CURPID}" ]]; then |
||
203 | echo " A PID:${CURPID} already exists for ${0}:" |
||
204 | echo " To re-start with current config settings, run '$0 stop' then '$0 start' ..." |
||
205 | else |
||
206 | if [ -d /var/lock/subsys ] ; then |
||
207 | touch /var/lock/subsys/${NAME}; |
||
208 | fi |
||
209 | |||
210 | 2 | Jeremias Keihsler | # ==================================================== |
211 | 1 | Jeremias Keihsler | # All variables read from ${CONFIGFILE}... |
212 | # If variable value not empty then add command-line switch to variable... |
||
213 | if [[ -n "${N2N_PORT}" ]]; then |
||
214 | N2N_PORT="-l ${N2N_PORT}"; |
||
215 | fi |
||
216 | |||
217 | # next line for debug: |
||
218 | if [[ "${2}" == "debug" ]]; then |
||
219 | echo " DEBUG: ${DAEMON} ${N2N_PORT} ${N2N_OPTIONS}" |
||
220 | fi |
||
221 | |||
222 | # Execute the command + switches + values sources from config file... |
||
223 | echo -n $"Starting $NAME: " |
||
224 | ${DAEMON} ${N2N_PORT} ${N2N_OPTIONS} >> ${LOGFILE} & |
||
225 | RETVAL=$? |
||
226 | |||
227 | [ $RETVAL -eq 0 ] && echo_success |
||
228 | [ $RETVAL -ne 0 ] && echo_failure |
||
229 | echo |
||
230 | |||
231 | 2 | Jeremias Keihsler | # ================================================= |
232 | 1 | Jeremias Keihsler | if [[ "${2}" == "debug" ]]; then |
233 | echo " NOTICE: Creating new ${NAME} pidfile - deleting old ${CURPID}..." |
||
234 | fi |
||
235 | |||
236 | rm -f ${PIDFILE} |
||
237 | touch ${PIDFILE} |
||
238 | |||
239 | for PID in $(ps ax | grep -w "${GREPNAME}" | grep -v "(restart|stop|start)" | awk '{ print $1 }'); do |
||
240 | if [[ "${2}" == "debug" ]]; then |
||
241 | echo " Saving into pidfile - new pid: ${PID}" |
||
242 | fi |
||
243 | echo ${PID} >> ${PIDFILE} |
||
244 | done |
||
245 | fi |
||
246 | ;; |
||
247 | stop) |
||
248 | # echo " DEBUG: Searching for at least one live process id..." |
||
249 | PID=$(ps ax | grep -w "${GREPNAME}" | grep -v "(restart|stop|start)" | awk '{ print $1 }') |
||
250 | |||
251 | if [[ "${2}" == "debug" ]]; then |
||
252 | echo " This ${NAME} ${1} init query ${0} is running on pid: ${$}) for ${PID}..." |
||
253 | fi |
||
254 | |||
255 | # echo " ${NAME} ${1} process is ${0} on pid: ${$})..." |
||
256 | echo "${STAMP} stop /etc/rc.d/init.d/${NAME}" >> ${LOGFILE} |
||
257 | |||
258 | # echo " NOTICE: Kill name:${NAME} pid:${pid} before stopping..." |
||
259 | # kill -9 $(cat /var/run/${NAME}_pid) && rm /var/run/${NAME}_pid |
||
260 | |||
261 | # If a pid value found in file or in process id, then kill it... |
||
262 | if [[ -n "${PID}" ]]; then |
||
263 | echo -n $"Stopping ${NAME}: " |
||
264 | # kill -9 $(cat /var/run/${NAME}.pid) && rm /var/run/${NAME}.pid |
||
265 | kill ${PID} |
||
266 | RETVAL=$? |
||
267 | sleep 4s |
||
268 | rm -f ${PIDFILE} |
||
269 | if [ $RETVAL -eq 0 ] ; then |
||
270 | echo_success |
||
271 | echo |
||
272 | else |
||
273 | echo_failure |
||
274 | echo |
||
275 | fi |
||
276 | else |
||
277 | # Else assume stale pid... |
||
278 | if [[ "${2}" == "debug" ]]; then |
||
279 | echo " NOTICE: No current active process ${PID}..." |
||
280 | fi |
||
281 | |||
282 | if [[ -f "${PIDFILE}" ]]; then |
||
283 | rm -f "${PIDFILE}" |
||
284 | fi |
||
285 | fi |
||
286 | |||
287 | # Indiscriminate pid killer... |
||
288 | # for PID in $(ps ax | grep -w ${NAME} | grep -v stop | awk '{ print $1 }'); do |
||
289 | # echo " Killing currently active ${NAME} pid(s): ${PID}" |
||
290 | # # kill -HUP $PID |
||
291 | # kill ${PID} |
||
292 | # done |
||
293 | |||
294 | if [ -f /var/lock/subsys/${NAME} ]; then |
||
295 | if [[ "${2}" == "debug" ]]; then |
||
296 | echo " Removing stale lock..." |
||
297 | fi |
||
298 | rm -f /var/lock/subsys/${NAME} |
||
299 | fi |
||
300 | |||
301 | if [ -f "${PIDFILE}" ]; then |
||
302 | echo " Removing stale pidfile..." |
||
303 | rm -f ${PIDFILE} |
||
304 | fi |
||
305 | ;; |
||
306 | restart) |
||
307 | echo "* Re-start ${NAME}..." |
||
308 | ${0} stop ${2} |
||
309 | |||
310 | # Not a race... |
||
311 | sleep 4s |
||
312 | |||
313 | ${0} start ${2} |
||
314 | ;; |
||
315 | status) |
||
316 | # status ${NAME} |
||
317 | |||
318 | if [[ "${2}" == "debug" ]]; then |
||
319 | echo " This init script ${NAME} ${1} query ${0} is running on pid: ${$})..." |
||
320 | fi |
||
321 | |||
322 | PID=$(ps ax | grep -w "${GREPNAME}" | grep -v status | awk '{ print $1 }') |
||
323 | |||
324 | # If at least one active session then find all... |
||
325 | if [[ -n "${PID}" ]]; then |
||
326 | for PID in $(ps ax | grep -w "${GREPNAME}" | grep -v status | awk '{ print $1 }'); do |
||
327 | if [[ -n "${PID}" ]]; then |
||
328 | echo "${NAME} (pid ${PID}) is running..." |
||
329 | else |
||
330 | echo "${NAME} is stopped" |
||
331 | fi |
||
332 | done |
||
333 | else |
||
334 | echo "${NAME} is stopped" |
||
335 | fi |
||
336 | ;; |
||
337 | *) |
||
338 | echo " Usage: ${0} {start|stop|status|restart|any debug}" >&2 |
||
339 | exit 1 |
||
340 | ;; |
||
341 | esac |
||
342 | exit 0 |
||
343 | 2 | Jeremias Keihsler | # === end supernoded ====================================== |
344 | 1 | Jeremias Keihsler | </pre> |
345 | |||
346 | make init-script executeable |
||
347 | <pre><code class="bash"> |
||
348 | chmod +x /etc/init.d/supernoded |
||
349 | </code></pre> |
||
350 | |||
351 | Using CentOS tools to activate the systemV init scripts: |
||
352 | <pre><code class="bash"> |
||
353 | chkconfig --add supernoded |
||
354 | chkconfig supernoded on |
||
355 | </code></pre> |
||
356 | |||
357 | Command line syntax: |
||
358 | <pre><code class="bash"> |
||
359 | service supernoded [start|stop|restart|any debug] |
||
360 | </code></pre> |
||
361 | For example: |
||
362 | <pre><code class="bash"> |
||
363 | service supernoded restart |
||
364 | </code></pre> |
||
365 | … OR… |
||
366 | <pre><code class="bash"> |
||
367 | service supernoded restart debug |
||
368 | </code></pre> |
||
369 | provides some extra clues. |