update mac to 13.3, problem is still there
Beiträge von Readbook
-
-
any ideas?
Am I the only, who using smb with updated Macos?
-
My SMB share working perfectly fine, until I didn't upgrade my macbook to Ventura.
Afrer this update I can't copy folder with file to SMB due permission error.
If I create folder manually all process complete without issue.
I found some info:
"
MacOS Ventura is compounding SMB2_FLUSH | SMB_CLOSE which is new behavior. Samba rejects this cancelling the in-flight AIO fsync() request via io_uring, and in some error cases closing the ring_fd which kills subsequent AIO"
Can I fix this in latest OMV? 6.3.2-1 (Shaitan)
1.I try to fix this in macbook, setting client SMB version to 2, no luck.
2. Try use option strict sync = no , no luck.
Here is info about fix in another nas platform:
SMB Permission Issues on macOS VenturaWhen trying to write files to my SMB shares with macOS Ventura, I keep getting permission issues. If I use the Finder the write hangs for a minute before…www.truenas.com -
Ok, here here
I try add 3 default from this post, It didn't help.
I still can connect to server(from non-local internet host) via ssh and :9000 with active reject rules (from screen on 1st massage).
-
OK do a google search for openmediavault firewall and you'll find some information on how to set it up
what's the point in your post?
I googled and configured it according to forum posts, my screenshots show that the simplest rules don't work.
-
-
No, I need to use it without router and need some simple rule (block all, except few services)
-
any adwice?
-
Hi!
I want add some secure to my nas, but when i was testing firewall he just didn't work.
I try to reject or block some ports (for example 9000 for portainer or 22 for ssh) but I still can connect and use them.
Here is my GUI is in attachment. I try use blunk IP, !1.1.1.1 and 0.0.0.0-255.255.255.255 didn't help.
Here is my iptables:
I have one docker, that using 140 and 189 port
# Generated by xtables-save v1.8.2 on Mon Oct 26 11:44:39 2020
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:DOCKER - [0:0]
-A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
-A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
-A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 9000 -j MASQUERADE
-A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 8000 -j MASQUERADE
-A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
-A DOCKER -i docker0 -j RETURN
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 9000 -j DNAT --to-destination 172.17.0.2:9000
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 8000 -j DNAT --to-destination 172.17.0.2:8000
COMMIT
# Completed on Mon Oct 26 11:44:39 2020
# Generated by xtables-save v1.8.2 on Mon Oct 26 11:44:39 2020
*filter
:INPUT ACCEPT [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
:DOCKER - [0:0]
:DOCKER-ISOLATION-STAGE-1 - [0:0]
:DOCKER-ISOLATION-STAGE-2 - [0:0]
:DOCKER-USER - [0:0]
-A INPUT -p tcp -m tcp --sport 140 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 289 -j ACCEPT
-A INPUT -p udp -m udp --sport 289 -j ACCEPT
-A INPUT -p tcp -m iprange --src-range 0.0.0.0-255.255.255.255 -m tcp --sport 9000 --dport 9000 -m iprange --dst-range 0.0.0.0-255.255.255.255 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -p tcp -m tcp --sport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 22 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -p udp -m udp --sport 22 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -j DOCKER-USER
-A FORWARD -j DOCKER-ISOLATION-STAGE-1
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o docker0 -j DOCKER
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
-A FORWARD -i docker0 -o docker0 -j ACCEPT
-A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
-A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8000 -j ACCEPT
-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -j RETURN
-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -j RETURN
-A DOCKER-USER -j RETURN
COMMIT
# Completed on Mon Oct 26 11:44:39 2020
What should I do for working firewell?
Thanks
-
Hi!
I buy cheap 16gb optane for system disk usage.
Before main nas migration, I just try it on fresh intallation on another machine.
When I choose optane as destanation disk in OMV5.3.9 I have this error:
Failed to partition the selected disk.
This probably happened because the selected disk or free space is too small to be automarically partitioned.
In doc I find this:
- System Drive: min. 4 GiB capacity (but more than the capacity of the RAM)
I have 16gb ram on both machine.
So question is: can I use 16gb Optane(14.4 actual size) as a main drive for OMV5.3.9 ?
I understand, that my main server will migrate via gpart/clonezilla/dd and avoid this issue. But it will work stable after that?(