Peak security
Peak security
This is a joke, I didn't really lock myself out
Peak security
This is a joke, I didn't really lock myself out
even worse. I regularly have to get up out of my chair and go down 2 stairs.
Also this took a while to find, but : https://sourceforge.net/p/shorewall/svn/HEAD/tree/branches/4.2/Samples/one-interface/shorewall.conf
ADMINISABSENTMINDED=Yes
Is an actual setting in the config for the (now apparently unmaintained) Shorewall Firewall software/tool for linux.
If I remember correctly, it always checks on firewall rule changes if there is an active connection on port 22, and adds a special rule at the end to maintain that connection.
They don't build them like they used to anymore.
They don't build them like they used to anymore.
Well if we did, the way it works would be by telling a chatbot to enable ssh on port 22 at the end.
Doing this is a right of passage.
Believe it or not, "rite" is the, uh, right, word here.
Real servers have lights out management and management networks.
I'd rather plug in a screen with VGA than deal with HPE iLO 4
Serial terminal servers (sometimes called terminal console servers) are a thing for a reason.
I keep a Windows 2008 w Java 6 VM on ice for administering old Java console shit like that.
The VM is unsafe as hell. Completely virgin unpatched. The only protection is that I don't give it a gateway or dns, and I shut it down when its not in use.
And it works. Old Java shit can still be used.
To be honest, HPE iLO 6 isn't too bad, if you're using the GUI. It's the API that remains really broken in many places.
Networking noob here, what, pray tell, is HPE iLO4... or do I want to even know?
Edit: Never mind. Found it. HP... shudders
Sounds like an issue draling with .NET or JRC console.
Are you on the nosz up to date firmware?
Before you make a change, do this in a screen-session:
sleep 300 && iptables-restore old_fw_rules.bak
Almost the same thing happened to me. I accidentally fucked up the internet connection in my home while in Japan, and I had to video call my mom to have her fix it. It was a pain for both of us, but thankfully it went rather smoothly. Thank you mom!
Do you mind explaining the details? I’m trying to learn as much as possible!
Most corporate network devices like Cisco will reset their config to the one written in memory when they lose power.
So in that case, just unplug and replug them to restore to previous config.
Just make sure you write your new config to memory or it will reset when there is ever a power failure.
So I connected through ssh back home to fiddle with the router settings, and in the PPPoE settings (where you set a pair of username and password that your router sends to the ISP such that the ISP knows you and knows what IP to assign to you) I made a typo, and apparently that instantly killed the internet connection at home and also for me. I had to call my mom to instruct her to fix the typo in the username. TBH I don't know that much about PPPoE either, I only do it so that the ISP assigns us the same IP address every time.
What's really fun is hearing "oh shit" from the UPS maintenance tech followed by darkness and silence.
Classic.
Love Hetzner. If something like that were to happen to me they can hook up a remote console accessible through their web interface.
Many hosting providers have a remote console feature.
Console
Fuck, that is really good wordplay.
Don't practically all commercial hosting providers provide remote console access?
This seems a combo of an extremely newb mistake in an extremely unusual scenario - worthy of Gru I guess.
Physical, on premises servers are still a thing.
Yes, I also used to run an "on premise" server - in my kitchen, not 500km away. I sometimes might need to admin it remotely, but never critical setup work.
And the meme makes it sound like they have to drive there specifically to fix it, like nobody is actually living nearby.
They should have a remote console like Dell RAC or HP iLO
Yeah, all the ones I've used had remote access
Since that happens to the best of us, I envision writing a wrapper script around {n,}pfctl that asks for confirmation upon detecting that you're logged in via ssh through a specific port AND detecting that the new rules would block that port.
VMware does this with its virtual networking. If a change takes it offline, it automatically rolls it back. It can be frustrating at times, but mostly its saved my ass.
Meraki does this as well. If you change anything that might disconnect the uplink or the port you are connected to, it gives you a pop-up warning before it commits.
Most secure box is the one that does nothing.
That the slrpnk.net admins in the picture?
This is the NetAdmin's problem. And he's got 3 ways to get into the datacenter, so he goddamn well better have an answer that doesn't involve airfare. Worst case, he's gotta use remote hands, but that would be embarrassing, and I'd not let him forget it. Nobody forgives me when I screw up a server cluster, so he gets no latitude when he takes a datacenter offline.
Does it actually happen to people? All servers I worked with both had a back door (or two), and someone at the data centre (during work hours at least) you could contact in an emergency.
I guess some smaller companies might have simpler setups they self-host
Most data centers have some kind of service where you can request a KVM to be connected to the server. It's not instant as an actual human has to do so but a lot sooner than another human driving long distance. I guess in this case, it's a mid size company that is big enough to have multiple locations yet small enough to still manage to use on-premise infra instead of data centers.
iptables default DENY and flush the rules. Done by at least two people I know (then me) at the same company. Led to them moving the servers in-house and virtualizing some services to connect to the hypervisor. It does happen though.
I try to remember to always open two SSH connections when altering iptables or the ssh config - just in case
I'll always be grateful for the firewalls like OpenWRT that will automatically revert any changes if you don't log back in after a few minutes (at least on the web interface). I'm not proud of how many times that's saved me.
this sounds like something chip from sales would do
It's gray on the bottom.
Hello Derek you fucking idiot
This is precisely the problem that deploy-rs solves!
Rescue mode with networking, mount drive, make changes and reboot.
i feel that. Hetzner support has a special place in my heart
That is why I always put any:any for ssh on all my firewalls!
Lol.
Just tailscale it and this will never happen again.
(Set the whole interface of tailscale0 as a trusted network)
Happened to me once. Had a little Pi at my parent's house and that was a nice excuse to visit them.
Except when you get there and don’t want to talk or do all the meeting and greeting until you know the server still works.
Relevant XKCD