ServerSetupFedora22: Difference between revisions
Jump to navigation
Jump to search
No edit summary |
No edit summary |
||
Line 8: | Line 8: | ||
# Install fail2ban | # Install fail2ban | ||
# yum remove unneeded software | # yum remove unneeded software | ||
# yum update<br><br> | # yum update | ||
# Enable SElinux<br><br> | |||
# Configure GRUB serial console redirection | # Configure GRUB serial console redirection | ||
# Configure kdump for system panics | # Configure kdump for system panics | ||
Line 18: | Line 20: | ||
# Configure syslog for network client writes | # Configure syslog for network client writes | ||
## Add UDP 514 to IPTables<br><br> | ## Add UDP 514 to IPTables<br><br> | ||
# Mount raid array | # Mount raid array | ||
# Configure md alerts | # Configure md alerts | ||
Line 40: | Line 43: | ||
# Configure logwatch | # Configure logwatch | ||
# Setup clamav virus protection for Samba and weekly scan<br><br> | # Setup clamav virus protection for Samba and weekly scan<br><br> | ||
# Setup cron jobs | # Setup cron jobs | ||
## Keep anacron from waking me up at night! # vi /etc/anacrontab // START_HOURS_RANGE<br><br> | ## Keep anacron from waking me up at night! # vi /etc/anacrontab // START_HOURS_RANGE<br><br> | ||
Line 52: | Line 56: | ||
# Configure webdav for tomboy notes / foxit marks | # Configure webdav for tomboy notes / foxit marks | ||
# Configure mod_auth_pam for httpd authentication<br><br> | # Configure mod_auth_pam for httpd authentication<br><br> | ||
# ^ Verify all log files in /var/log are not giving any errors or notifications | # ^ Verify all log files in /var/log are not giving any errors or notifications | ||
# ^ Check logs for whats growing! | # ^ Check logs for whats growing! | ||
:* ls -alR /var/log | grep ^- | awk {'print $5" "$8'} | sort -k 2| sort -n | :* ls -alR /var/log | grep ^- | awk {'print $5" "$8'} | sort -k 2| sort -n |
Revision as of 02:51, 24 July 2011
# yum install man screen lm_sensors wget rsync fail2ban mailx sendmail-cf \ nut clamav clamav-update nfs-utils strace smartmontools logwatch etckeeper \ OpenIPMI ipmitool php-pecl-apc.x86_64
- Install etckeeper
- Disable root login via ssh
- Enable sudo
- Install fail2ban
- yum remove unneeded software
- yum update
- Enable SElinux
- Configure GRUB serial console redirection
- Configure kdump for system panics
- Append kernel grub.conf crashkernel=128M for F14
- /etc/sysctl.conf :: kernel.sysrq =1
- Configure NUT for UPS alerts
- Configure Time Server for local network access
- Add UDP 123 to IPTables
- Configure syslog for network client writes
- Add UDP 514 to IPTables
- Add UDP 514 to IPTables
- Mount raid array
- Configure md alerts
- Enable NFS
- Add TCP 2049 to IPTables
- Disable NFSv2/3 /etc/sysconfig/nfs
- $ service rpcbind start ; chkconfig rpcbind on
- $ service nfslock start ; chkconfig nfslock on
- $ service nfs start ; chkconfig nfs on
- Enable samba
- Add TCP port 139/445 to IPTables
- Enable iSCSI
- ^ Configure bacula and web interface
- Setup mail relay
- $ echo drew > /root/.forward
- echo "andrew: drew" >> /etc/aliases; newaliases
- echo "root: drew" >> /etc/aliases; newaliases
- Remove 127.0.0.1 /etc/mail/sendmail.mc
- Add TCP port 25 to IPTables
- Configure smartd to monitor hard drives
- ^ Configure thermal alerts for server
- Configure logwatch
- Setup clamav virus protection for Samba and weekly scan
- Setup cron jobs
- Keep anacron from waking me up at night! # vi /etc/anacrontab // START_HOURS_RANGE
- Keep anacron from waking me up at night! # vi /etc/anacrontab // START_HOURS_RANGE
- ^ Configure Snort passive IDS
- ^ Transparent Proxy with Squid for bandwidth utilization tally
- Upload firmware for tv tuner card
- Setup mythtv
- Configure MythWeb
- Force http to https redirection
- Add TCP port 443 to IPTables
- Configure MediaWiki
- Configure webdav for tomboy notes / foxit marks
- Configure mod_auth_pam for httpd authentication
- ^ Verify all log files in /var/log are not giving any errors or notifications
- ^ Check logs for whats growing!
- ls -alR /var/log | grep ^- | awk {'print $5" "$8'} | sort -k 2| sort -n