Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Eneko Lacunza
You can also setup iptables so that only your fixed IPs are allowed to port 8006 (and ssh port...) On 14/09/14 19:00, ad...@extremeshok.com wrote: You don't need a VPN Follow the guides on my site this will give you a secure and optimized proxmox. Set proxmox admin interface to only listen

Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Guy Plunkett
I would strongly suggest against this or indeed any way to put proxmox directly on the internet. The way I go about this would be to create a private network inside proxmox and host a real firewall system such as pfsense (pfsense.org) to front the internet and then use PPTP or OpenVPN to

Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Eneko Lacunza
Guy, so how do you connect if the Firewall VM is down? :) On 15/09/14 09:43, Guy Plunkett wrote: I would strongly suggest against this or indeed any way to put proxmox directly on the internet. The way I go about this would be to create a private network inside proxmox and host a real

Re: [PVE-User] Internet facing Proxmox

2014-09-15 Thread Guy Plunkett
well yeah that's always a problem. :).. I also use zenoss core (zenoss.org) to monitor my systems. You can easily configure zenoss to monitor the firewall etc, and if it's down, you can have it connect to proxmox and restart it. Cheers, --Guy On 15 Sep 2014, at 08:51, Eneko Lacunza

[PVE-User] Proxmox VE 3.3 released!

2014-09-15 Thread Martin Maurer
Hi all! We just released Proxmox VE 3.3, introducing great new features and security enhancements! Including the new HTML5 Console, http://pve.proxmox.com/wiki/Proxmox_VE_Firewall, http://pve.proxmox.com/wiki/Two-Factor_Authentication, ZFS storage plugin,

Re: [PVE-User] Proxmox VE 3.3 released!

2014-09-15 Thread Gilberto Nunes
PVE Mobile! wow... Nice job 2014-09-15 7:05 GMT-03:00 Martin Maurer mar...@proxmox.com: Hi all! We just released Proxmox VE 3.3, introducing great new features and security enhancements! Including the new HTML5 Console, http://pve.proxmox.com/wiki/Proxmox_VE_Firewall,

Re: [PVE-User] Proxmox VE 3.3 released!

2014-09-15 Thread Gilberto Nunes
Correct me if I wrong, but this TFA works like a token, right? 2014-09-15 8:03 GMT-03:00 Diaolin diao...@diaolin.com: Pve is spectacular TX, Diaolin --- ala fin l'ei sol parole tut sta smania maledeta la se strenge entorn, menudola, e le not l'è le orazion de na cigaia 'mbarlumada da la

[PVE-User] pptp is not secure (war: Internet facing Proxmox)

2014-09-15 Thread Lutz Markus Willek
Hey There, PPTP has always been considered rather week security but a flaw in MSChapv2 indicates it is even less secure than we ever believed. MSChapv2 is the most secure authentication protocol used with PPTP! So PPTP turns to the least secure VPN solution. In Fact PPTP is so insecure, it

Re: [PVE-User] Proxmox VE 3.3 released!

2014-09-15 Thread Hector Suarez Planas
Greetings, Guys. Hi all! We just released Proxmox VE 3.3, introducing great new features and security enhancements! Including the new HTML5 Console, http://pve.proxmox.com/wiki/Proxmox_VE_Firewall, http://pve.proxmox.com/wiki/Two-Factor_Authentication, ZFS storage plugin,

[PVE-User] Two-factor auth

2014-09-15 Thread Gilberto Nunes
Hi I have facing some issues here... I follow this instruction: http://pve.proxmox.com/wiki/Two-Factor_Authentication But I am unable to log in into Proxmox... I used the oauthkeygen and also oauthkeygen root, oauthkeygen root@pam as well but received a Login Failed... In my smartphone. I used

Re: [PVE-User] Two-factor auth

2014-09-15 Thread Gilberto Nunes
Perhaps I need to do a fresh installation??? I just do an upgrade from 3.2 to 3.3 or doesn't matter? 2014-09-15 9:17 GMT-03:00 Gilberto Nunes gilberto.nune...@gmail.com: Hi I have facing some issues here... I follow this instruction: http://pve.proxmox.com/wiki/Two-Factor_Authentication

Re: [PVE-User] Two-factor auth

2014-09-15 Thread Gilberto Nunes
I get this error on syslog: Sep 15 09:25:16 pve01 pvedaemon[3138]: WARNING: Use of uninitialized value $keys in pattern match (m//) at /usr/share/perl5/PVE/AccessControl.pm line 1235. Sep 15 09:25:16 pve01 pvedaemon[3138]: authentication failure; rhost=192.168.1.101 user=gilberto@pve msg=oath

Re: [PVE-User] pptp is not secure (war: Internet facing Proxmox)

2014-09-15 Thread Paul Gray
On 09/15/2014 06:38 AM, Lutz Markus Willek wrote: Hey There, PPTP has always been considered rather week security but a flaw in MSChapv2 indicates it is even less secure than we ever believed. MSChapv2 is the most secure authentication protocol used with PPTP! So PPTP turns to the least

Re: [PVE-User] pptp is not secure (war: Internet facing Proxmox)

2014-09-15 Thread Diaolin
I use softether And it's perfect Diaolin --- ala fin l'ei sol parole tut sta smania maledeta la se strenge entorn, menudola, e le not l'è le orazion de na cigaia 'mbarlumada da la luna Il giorno 14:32 15/set/2014, alle ore 14:32, Paul Gray g...@cs.uni.edu ha scritto: On 09/15/2014 06:38 AM,

Re: [PVE-User] Proxmox VE 3.3 released!

2014-09-15 Thread Angel Docampo
On 15/09/14 12:05, Martin Maurer wrote: Hi all! We just released Proxmox VE 3.3, introducing great new features and security enhancements! Including the new HTML5 Console, http://pve.proxmox.com/wiki/Proxmox_VE_Firewall, http://pve.proxmox.com/wiki/Two-Factor_Authentication, ZFS storage

Re: [PVE-User] Proxmox VE 3.3 released!

2014-09-15 Thread Gilberto Nunes
Iam here trying TFA but doesn't work... Yet! :=( I just upgraded... I will try it with a fresh installation... Let see it 2014-09-15 9:39 GMT-03:00 Angel Docampo adoca...@dltec.net: On 15/09/14 12:05, Martin Maurer wrote: Hi all! We just released Proxmox VE 3.3, introducing great new

Re: [PVE-User] Two-factor auth

2014-09-15 Thread Dietmar Maurer
You added the secret key to the user? From: pve-user [mailto:pve-user-boun...@pve.proxmox.com] On Behalf Of Gilberto Nunes Sent: Montag, 15. September 2014 14:27 To: pve-user@pve.proxmox.com Subject: Re: [PVE-User] Two-factor auth I get this error on syslog: Sep 15 09:25:16 pve01

Re: [PVE-User] Two-factor auth

2014-09-15 Thread Gilberto Nunes
Like this? 2. Add a unique secret (password) to each user - this secret has also to be added to your OATH app on the smartphone of each user. To generate a secret, you can run the following command on your Proxmox VE host: oathkeygen If a user has more secrets, just add all your secrets

Re: [PVE-User] Two-factor auth

2014-09-15 Thread Gilberto Nunes
Or, you meant do it in Key ID's field on Users configuration?? 2014-09-15 9:59 GMT-03:00 Gilberto Nunes gilberto.nune...@gmail.com: Like this? 2. Add a unique secret (password) to each user - this secret has also to be added to your OATH app on the smartphone of each user. To generate a

Re: [PVE-User] Two-factor auth

2014-09-15 Thread Gilberto Nunes
Oh... I figure out... I fill Key ID's and now works as a charm! Just a note: this is not in the how to... Thanks 2014-09-15 10:00 GMT-03:00 Gilberto Nunes gilberto.nune...@gmail.com: Or, you meant do it in Key ID's field on Users configuration?? 2014-09-15 9:59 GMT-03:00 Gilberto Nunes

[PVE-User] Upgrade 3.2 to 3.3

2014-09-15 Thread Joerg Hanebuth
Hello all, some hints howto upgrade a productive system without installing new? Found Upgrade from 2.3 to 3.0 in wiki but I guess the required script won't work. Gruesse / Regards Joerg Hanebuth -- IT-Services - Hamburg

Re: [PVE-User] Upgrade 3.2 to 3.3

2014-09-15 Thread Gilberto Nunes
I think is pretty smoothly... Just maka a backup to externa HD, make new installation and make a restore! Just like that! 2014-09-15 10:51 GMT-03:00 Joerg Hanebuth jo...@im-www.biz: Hello all, some hints howto upgrade a productive system without installing new? Found Upgrade from 2.3

Re: [PVE-User] Upgrade 3.2 to 3.3

2014-09-15 Thread Joerg Hanebuth
Don't know how many systems you have and how big ur systems are, but I got a hand full of running proxmox-systems to upgrade. Most of them are stand-alone, all are productive systems. Hours of downtime and backing up tb's of data is not possible for my customers and me! Gruesse / Regards Joerg

Re: [PVE-User] Upgrade 3.2 to 3.3

2014-09-15 Thread Gilou
Le 15/09/2014 15:51, Joerg Hanebuth a écrit : Hello all, some hints howto upgrade a productive system without installing new? Found Upgrade from 2.3 to 3.0 in wiki but I guess the required script won't work. Stop the VMs, or move them away from the host you want to upgrade, backup the

Re: [PVE-User] Upgrade 3.2 to 3.3

2014-09-15 Thread Joerg Hanebuth
Ty hector, ill give a try tonight ;) posting about the results afterwards! Gruesse / Regards Joerg Hanebuth -- IT-Services - Hamburg e.K. Heinsonweg 59b, 22359, Hamburg Tel. +494079100220 FAX. +494079100223

Re: [PVE-User] Can't get NoVnc

2014-09-15 Thread Lex Rivera
I have exact same issue. Java console works, but novnc gives me same error with exit code 1 On Mon, Sep 15, 2014, at 07:20 AM, Dhaussy Alexandre wrote: No idea ? or should i blame my english ? x) Le 10/09/2014 16:05, Alexandre DHAUSSY a écrit : Hello, I'm getting a timeout when i try to

[PVE-User] Solved AW: Upgrade 3.2 to 3.3

2014-09-15 Thread Joerg Hanebuth
OK :) In preparation to upgrade the way hector told me below I did a apt-update/upgrade on console. No new packages shown in web-gui before! What I get was a full upgrade to 3.3-1 with kernel 2.6.32-32-pve :) All fine - all running - all happy here ;) Gruesse / Regards Joerg Hanebuth

[PVE-User] same here - AW: Can't get NoVnc

2014-09-15 Thread Joerg Hanebuth
Java OK novnc no connection : Connection timed out TASK ERROR: command '/bin/nc -l -p 5900 -w 10 -c '/usr/sbin/qm vncproxy 107 2/dev/null'' failed: exit code 1 Gruesse / Regards Joerg Hanebuth -- IT-Services - Hamburg e.K.

[PVE-User] W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

2014-09-15 Thread Joerg Hanebuth
But whats that? Ver. 3.2-4 Subscription is active At a customers system i got that from apt-update: W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry 'pve-enterprise/binary-i386/Packages' in Release file (Wrong sources.list entry or

Re: [PVE-User] W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

2014-09-15 Thread Alessandro Briosi
Il 15/09/2014 17:34, Joerg Hanebuth ha scritto: But whats that? Ver. 3.2-4 Subscription is active At a customers system i got that from apt-update: W: Failed to fetchhttps://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

Re: [PVE-User] W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

2014-09-15 Thread Joerg Hanebuth
Hallo Alessandro, thnx for fast reply! Have you enabled multiarch on Proxmox? no - not by hand. but dpkg --print-architecture gives amd64 and dpkg --print-foreign-architectures gives i386 Got 150 i386 packages! don't know where it comes from. Perhaps of the installation from

[PVE-User] CLOSE: AW: W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

2014-09-15 Thread Joerg Hanebuth
I guess I found the issue. Fujitsu Servermanager needs some i386 packages. Seems I was unfocused while installing. and finally its not working properly . . . -.- Sorry at LSI ;) Gruesse / Regards Joerg Hanebuth --

Re: [PVE-User] W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

2014-09-15 Thread Alessandro Briosi
Il 15/09/2014 19:05, Joerg Hanebuth ha scritto: Yes - dpkg --remove-architecture i386 but dpkg: error: cannot remove architecture 'i386' currently in use by the database but i guess uninstalling all i386 will mess up my system - i'm afraid;) so I'll have to wait until I have the machine on my

Re: [PVE-User] Upgrade 3.2 to 3.3

2014-09-15 Thread Michael Rasmussen
On Mon, 15 Sep 2014 14:27:22 + Joerg Hanebuth jo...@im-www.biz wrote: Ty hector, ill give a try tonight ;) If you need a quick way to migrate all running VMs and CTs away from a node I have made this little script to do just that. Run without options to see help. # cat

Re: [PVE-User] W: Failed to fetch https://enterprise.proxmox.com/debian/dists/wheezy/Release Unable to find expected entry

2014-09-15 Thread Joerg Hanebuth
Oh yes :) i forgot about . . . Thnx for waking me up ;) Gruesse / Regards Joerg Hanebuth -- IT-Services - Hamburg e.K. Heinsonweg 59b, 22359, Hamburg Tel. +494079100220 FAX. +494079100223 jo...@im-www.biz