<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Configuration on Michael’s Domain</title><link>https://jeltsch.org/en/tags/configuration/</link><description>Recent content in Configuration on Michael’s Domain</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright © 2002 - 2026 Michael Jeltsch.</copyright><lastBuildDate>Fri, 24 Jul 2026 00:18:18 +0300</lastBuildDate><atom:link href="https://jeltsch.org/en/tags/configuration/index.xml" rel="self" type="application/rss+xml"/><item><title>Grub2</title><link>https://jeltsch.org/en/grub2/</link><pubDate>Mon, 19 Oct 2020 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/grub2/</guid><description>&lt;p&gt;Grub2 has been the default boot loader for Ubuntu for more then 10 years now. Its configuration file is nowadays /boot/grub/grub.cfg, but you MUST NOT edit /boot/grub/grub.cfg in order to modify the Grub boot menu. Instead, you need to add your own entries to the file /etc/grub.d/40_custom. Some general preferences are also set in the the file /etc/default/grub and any file under /etc/default/grub.d/.&lt;/p&gt;</description></item><item><title>OpenVPN server on pfsense and client on Ubuntu 16.04</title><link>https://jeltsch.org/en/openvpn_server_on_pfsense_and_client_on_ubuntu_16_04/</link><pubDate>Fri, 02 Nov 2018 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/openvpn_server_on_pfsense_and_client_on_ubuntu_16_04/</guid><description>&lt;p&gt;I have been setting up an 
 &lt;a href="https://openvpn.net" target="_blank" rel="noopener noreferrer nofollow"&gt;OpenVPN&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 server on my 
 &lt;a href="https://www.netgate.com/solutions/pfsense/sg-3100.html" target="_blank" rel="noopener noreferrer nofollow"&gt;Netgate SG-3100 router&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. I hope this makes syncronizing backups to a physically separate location easier. There are many walkthroughs to set up an OpenVPN server on a 
 &lt;a href="https://www.pfsense.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;pfsense router&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 and that works nicely. However, I am using 
 &lt;a href="https://blog.ubuntu.com/desktop" target="_blank" rel="noopener noreferrer nofollow"&gt;Ubuntu&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 16.04 at work and setting up the client requires a bit more than doing the same on MacOS or Windows. On Ubuntu, it is mandatory to update DNS information manually after establishing the VPN tunnel if you have opted for the setting to route all internet traffic originating from the client through the VPN server. If you do no update the DNA resolver information on the Ubuntu client, you can access the the VPN-internal network (in my case 10.0.0.0/24), but you cannot use hostnames. E.g. ping 
 &lt;a href="https://www.google.com" target="_blank" rel="noopener noreferrer nofollow"&gt;www.google.com&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 will fail, but ping 172.217.21.164 will succeed. Similarly, your browser will not find any URLs. And browsing with IP-addresses (&amp;ldquo;http://172.217.21.164&amp;rdquo;) is not very practical.The default configuration on Ubuntu does not allow for this update of the DNS resolver to happen automatically for security reasons. There is a script included in the 
 &lt;a href="https://packages.ubuntu.com/search?keywords=openvpn" target="_blank" rel="noopener noreferrer nofollow"&gt;Ubuntu package of openvpn&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 that updates this information (/etc/openvpn/update-resolv-conf). But in order for this to work one needs to&lt;/p&gt;</description></item><item><title>Managing OpenVPN with Network Manger</title><link>https://jeltsch.org/en/managing_openvpn_with_network_manger/</link><pubDate>Thu, 05 Nov 2015 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/managing_openvpn_with_network_manger/</guid><description>&lt;p&gt;I just switched back from MacOSX to Ubuntu for work. Mostly for financial reasons. We need more computers at work and a really good PC laptop is just half as expensive as a MacbookPro or iMac. Today I wanted to connect from home to the University&amp;rsquo;s VPN network and I had a look at the instructions provided by the university.As usually, documentation was virtually absent and what was available was wrong. And exclusively in Finnish (
 &lt;a href="http://www.helsinki.fi/helpdesk/ohjeet/tietoliikenne_ja_etakaytto/yhteydet_yliopiston_ulkopuolelta/vpn_ubuntu-asennus.html%29" target="_blank" rel="noopener noreferrer nofollow"&gt;http://www.helsinki.fi/helpdesk/ohjeet/tietoliikenne_ja_etakaytto/yhteydet_yliopiston_ulkopuolelta/vpn_ubuntu-asennus.html)&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. From the image (Hardy Heron) it is clear that this page has not been updated for about at least 6 years (Hardy Heron was realased in the beginning of 2008).So what do you do if you downloaded and extracted the hy-vpn-config.tar.gz file from 
 &lt;a href="https://ohjelmistojakelu.helsinki.fi?First" target="_blank" rel="noopener noreferrer nofollow"&gt;https://ohjelmistojakelu.helsinki.fi?First&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 you need to install a plugin for the Network Manager: &lt;code&gt;sudo apt-get install network-manager-openvpn network-manager-openvon-gnome&lt;/code&gt;. Then you go to the Network Manager via the icon in the menu bar on the top right of your Desktop. Below all the available wireless networks, there is an entry &amp;ldquo;VPN Connections&amp;rdquo;. Follow &amp;ldquo;VPN Connections&amp;rdquo; -&amp;gt; &amp;ldquo;Configure VPN&amp;rdquo; -&amp;gt; &amp;ldquo;Add&amp;rdquo; -&amp;gt; &amp;ldquo;Import a saved VPN configuration&amp;rdquo; -&amp;gt; &amp;ldquo;Create&amp;rdquo;. Then select the &amp;ldquo;openvpn.conf&amp;rdquo; from the downloaded and extracted files. After that, fill in the rest of the dialog box: User name, Password. For the CA Certificate, select the &amp;ldquo;HY-vpn-CA.pem&amp;rdquo; file from the downloaded files (you should have put it first somewhere safe, e.g. to &amp;ldquo;/etc/openvpn&amp;rdquo;).One problem that people are complaining about is the fact that the import does not honor the &amp;ldquo;redirect-gateway def1&amp;rdquo; directive and as a consequence you won&amp;rsquo;t be able to connect anywhere (I guess this is due to the Network Manager using dnsmasq and dnsmasq is apparently not smart enough to realize that it should send the queries somewhere else now). That&amp;rsquo;s why people are complaining that Network Manager doesn&amp;rsquo;t work to route all traffic via the VPN network. The box that you need to uncheck for this to work is well hidden: It&amp;rsquo;s in the connection editor dialog under the IPv4 Settings tab -&amp;gt; Routes (at the bottom right) -&amp;gt; &amp;ldquo;Use this connection only for resources on its network&amp;rdquo;. Why on earth do they have to call it in a way that nobody understands its meaning? Why not to call it &amp;ldquo;Do not route all traffic through this VPN connection&amp;rdquo;? I also had to check the box that said &amp;ldquo;Ignore automatically obtained routes&amp;rdquo;, although I don&amp;rsquo;t know why…As usual, setting up the OpenVPN sucks and the important tunneling back of VPN traffic needed to be added manually on the OpenVPN server:&lt;code&gt;iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE&lt;/code&gt;I did it by making an additional file called openvpn2 in the /etc/network/if-up.d/ directory with the following content:&lt;code&gt;#!/bin/shiptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE&lt;/code&gt;Of course you can still start and stop the VPN via the command line. However, since systemd, the password entry is not straightforward. When you execute &lt;code&gt;sudo systemctl start openvpn.service&lt;/code&gt; you need to execute (e.g. in another terminal) &lt;code&gt;sudo systemd-tty-ask-password-agent&lt;/code&gt; and enter your password there. That&amp;rsquo;s clearly a kludge until they get a decent password agent…&lt;/p&gt;</description></item><item><title>NFS shares &amp; automount</title><link>https://jeltsch.org/en/nfs_shares_automount/</link><pubDate>Wed, 04 Apr 2007 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/nfs_shares_automount/</guid><description>&lt;p&gt;On each computer on the network there is an NFS server running, starting at bootup (edit the runlevel to enable that). In Suse Linux, NFS shares can be configured in YAST (NFS server configuration) or directly in /etc/exports file. Don&amp;rsquo;t configure the remote root to act as local root! Shares should be configured to be accessed only from the local network 192.168.0.0/24 or 192.168.0.0/255.255.255.0. &lt;code&gt;/media/downloads/ 192.168.0.0/255.255.255.0(root_squash,sync)&lt;/code&gt;UIDs have to be the same on all computers for the permissions to work properly. In case they are different you can change them in YAST. After the changes files and directories will have the old user id set as the owner, so you&amp;rsquo;ll have to change the owner globally: &lt;code&gt;chown -R --from=1001 marzena /&lt;/code&gt; Change also permissions for hidden files in the home directory: &lt;code&gt;/home/marzena chown -R --from=1001 marzena .[a-zA-Z0-9]*&lt;/code&gt;NFS shares are accessed by other computers with automount, not configured in /etc/fstab!&lt;/p&gt;</description></item></channel></rss>