<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.thomas-krenn.com/en/wikiEN/index.php?title=Special:NewPages&amp;feed=atom&amp;xortex=yes</id>
	<title>Thomas-Krenn-Wiki - New pages [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.thomas-krenn.com/en/wikiEN/index.php?title=Special:NewPages&amp;feed=atom&amp;xortex=yes"/>
	<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Special:NewPages"/>
	<updated>2026-08-14T03:14:19Z</updated>
	<subtitle>From Thomas-Krenn-Wiki</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OPNsense_plugins</id>
		<title>OPNsense plugins</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OPNsense_plugins"/>
		<updated>2026-08-11T07:12:58Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The functions of the Open Source firewall OPNsense can be extended by multiple &amp;#039;&amp;#039;&amp;#039;plugins&amp;#039;&amp;#039;&amp;#039;.  The following table shows the plugins available with the corresponding version numbers (OPNsense version 25.1.1):  {| class=&amp;quot;wikitable&amp;quot; !Plugin !Version !Description |- |os-acme-client |4.11 |ACME Client |- |os-apcupsd |1.2_3 |APCUPSD - APC UPS daemon |- |os-beats |1 |Send logs, network, metrics and heartbeat to Elasticsearch |- |os-bind |1.34_2 |BIND domain name service |-...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The functions of the Open Source firewall [[OPNsense]] can be extended by multiple &amp;#039;&amp;#039;&amp;#039;plugins&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
The following table shows the plugins available with the corresponding version numbers (OPNsense version 25.1.1):&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Plugin&lt;br /&gt;
!Version&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|os-acme-client&lt;br /&gt;
|4.11&lt;br /&gt;
|ACME Client&lt;br /&gt;
|-&lt;br /&gt;
|os-apcupsd&lt;br /&gt;
|1.2_3&lt;br /&gt;
|APCUPSD - APC UPS daemon&lt;br /&gt;
|-&lt;br /&gt;
|os-beats&lt;br /&gt;
|1&lt;br /&gt;
|Send logs, network, metrics and heartbeat to Elasticsearch&lt;br /&gt;
|-&lt;br /&gt;
|os-bind&lt;br /&gt;
|1.34_2&lt;br /&gt;
|BIND domain name service&lt;br /&gt;
|-&lt;br /&gt;
|os-c-icap&lt;br /&gt;
|1.9&lt;br /&gt;
|c-icap connects the web proxy with a virus scanner&lt;br /&gt;
|-&lt;br /&gt;
|os-cache&lt;br /&gt;
|1.0_1&lt;br /&gt;
|Webserver cache&lt;br /&gt;
|-&lt;br /&gt;
|os-caddy&lt;br /&gt;
|2.0.4_2&lt;br /&gt;
|Modern Reverse Proxy with Automatic HTTPS, Dynamic DNS and Layer4 Routing&lt;br /&gt;
|-&lt;br /&gt;
|os-chrony&lt;br /&gt;
|1.5_3&lt;br /&gt;
|Chrony time synchronisation&lt;br /&gt;
|-&lt;br /&gt;
|os-clamav&lt;br /&gt;
|1.8.1&lt;br /&gt;
|Antivirus engine for detecting malicious threats&lt;br /&gt;
|-&lt;br /&gt;
|os-collectd&lt;br /&gt;
|1.4_1&lt;br /&gt;
|Collect system and application performance metrics periodically&lt;br /&gt;
|-&lt;br /&gt;
|os-cpu-microcode-amd&lt;br /&gt;
|1.1&lt;br /&gt;
|AMD CPU microcode updates&lt;br /&gt;
|-&lt;br /&gt;
|os-cpu-microcode-intel&lt;br /&gt;
|1.1&lt;br /&gt;
|Intel CPU microcode updates&lt;br /&gt;
|-&lt;br /&gt;
|os-crowdsec&lt;br /&gt;
|1.0.12&lt;br /&gt;
|Lightweight and collaborative security engine&lt;br /&gt;
|-&lt;br /&gt;
|os-ddclient&lt;br /&gt;
|1.28&lt;br /&gt;
|Dynamic DNS client&lt;br /&gt;
|-&lt;br /&gt;
|os-debug&lt;br /&gt;
|1.7&lt;br /&gt;
|Debugging Tools&lt;br /&gt;
|-&lt;br /&gt;
|os-dec-hw&lt;br /&gt;
|1.1_3&lt;br /&gt;
|Deciso hardware specific information&lt;br /&gt;
|-&lt;br /&gt;
|os-dmidecode&lt;br /&gt;
|1.2&lt;br /&gt;
|Display hardware information on the dashboard&lt;br /&gt;
|-&lt;br /&gt;
|os-dnscrypt-proxy&lt;br /&gt;
|1.16&lt;br /&gt;
|Flexible DNS proxy supporting DNSCrypt and DoH&lt;br /&gt;
|-&lt;br /&gt;
|os-etpro-telemetry&lt;br /&gt;
|1.8&lt;br /&gt;
|ET Pro Telemetry Edition&lt;br /&gt;
|-&lt;br /&gt;
|os-freeradius&lt;br /&gt;
|1.9.28_1&lt;br /&gt;
|RADIUS Authentication, Authorization and Accounting Server&lt;br /&gt;
|-&lt;br /&gt;
|os-frr&lt;br /&gt;
|1.49&lt;br /&gt;
|The FRRouting Protocol Suite&lt;br /&gt;
|-&lt;br /&gt;
|os-ftp-proxy&lt;br /&gt;
|1.0_4&lt;br /&gt;
|Control ftp-proxy processes&lt;br /&gt;
|-&lt;br /&gt;
|os-gdrive-backup&lt;br /&gt;
|1&lt;br /&gt;
|Backup configurations using Google Drive&lt;br /&gt;
|-&lt;br /&gt;
|os-git-backup&lt;br /&gt;
|1.1_1&lt;br /&gt;
|Track config changes using git&lt;br /&gt;
|-&lt;br /&gt;
|os-google-cloud-sdk&lt;br /&gt;
|1.0_1&lt;br /&gt;
|Google Cloud SDK&lt;br /&gt;
|-&lt;br /&gt;
|os-grid_example&lt;br /&gt;
|1.1&lt;br /&gt;
|A sample framework application&lt;br /&gt;
|-&lt;br /&gt;
|os-haproxy&lt;br /&gt;
|4.6_1&lt;br /&gt;
|Reliable, high performance TCP/HTTP load balancer&lt;br /&gt;
|-&lt;br /&gt;
|os-helloworld&lt;br /&gt;
|1.4_1&lt;br /&gt;
|A sample framework application&lt;br /&gt;
|-&lt;br /&gt;
|os-hw-probe&lt;br /&gt;
|1.0_1&lt;br /&gt;
|Collect hardware diagnostics&lt;br /&gt;
|-&lt;br /&gt;
|os-igmp-proxy&lt;br /&gt;
|1.5_6&lt;br /&gt;
|IGMP-Proxy Service&lt;br /&gt;
|-&lt;br /&gt;
|os-intrusion-detection-content-et-open&lt;br /&gt;
|1.0.2_2&lt;br /&gt;
|IDS Proofpoint full ET open ruleset complementary subset for ET Pro Telemetry edition&lt;br /&gt;
|-&lt;br /&gt;
|os-intrusion-detection-content-et-pro&lt;br /&gt;
|1.0.2_1&lt;br /&gt;
|IDS Proofpoint ET Pro ruleset (needs a valid subscription)&lt;br /&gt;
|-&lt;br /&gt;
|os-intrusion-detection-content-ptopen&lt;br /&gt;
|1&lt;br /&gt;
|IDS Positive Technologies ESC ruleset&lt;br /&gt;
|-&lt;br /&gt;
|os-intrusion-detection-content-snort-vrt&lt;br /&gt;
|1.2&lt;br /&gt;
|IDS Snort VRT ruleset (needs registration or subscription)&lt;br /&gt;
|-&lt;br /&gt;
|os-iperf&lt;br /&gt;
|1.0_2&lt;br /&gt;
|Connection speed tester&lt;br /&gt;
|-&lt;br /&gt;
|os-lcdproc-sdeclcd&lt;br /&gt;
|1.1_1&lt;br /&gt;
|LCDProc for SDEC LCD devices&lt;br /&gt;
|-&lt;br /&gt;
|os-lldpd&lt;br /&gt;
|1.2&lt;br /&gt;
|LLDP allows you to know exactly on which port is a server&lt;br /&gt;
|-&lt;br /&gt;
|os-maltrail&lt;br /&gt;
|1.10_1&lt;br /&gt;
|Malicious traffic detection system&lt;br /&gt;
|-&lt;br /&gt;
|os-mdns-repeater&lt;br /&gt;
|1.2&lt;br /&gt;
|Proxy multicast DNS between networks&lt;br /&gt;
|-&lt;br /&gt;
|os-munin-node&lt;br /&gt;
|1.1_1&lt;br /&gt;
|Munin monitoring agent&lt;br /&gt;
|-&lt;br /&gt;
|os-ndp-proxy-go&lt;br /&gt;
|1.1&lt;br /&gt;
|IPv6 Neighbor Discovery Protocol (NDP) Proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-ndproxy&lt;br /&gt;
|1.1&lt;br /&gt;
|Neighbor Discovery Proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-net-snmp&lt;br /&gt;
|1.6&lt;br /&gt;
|Net-SNMP is a daemon for the SNMP protocol&lt;br /&gt;
|-&lt;br /&gt;
|os-netbird&lt;br /&gt;
|1.1&lt;br /&gt;
|Peer-to-peer VPN that seamlessly connects your devices&lt;br /&gt;
|-&lt;br /&gt;
|os-netdata&lt;br /&gt;
|1.2_1&lt;br /&gt;
|Real-time performance monitoring&lt;br /&gt;
|-&lt;br /&gt;
|os-nextcloud-backup&lt;br /&gt;
|1.0_1&lt;br /&gt;
|Track config changes using NextCloud&lt;br /&gt;
|-&lt;br /&gt;
|os-nginx&lt;br /&gt;
|1.35_4&lt;br /&gt;
|Nginx HTTP server and reverse proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-node_exporter&lt;br /&gt;
|1.2&lt;br /&gt;
|Prometheus exporter for machine metrics&lt;br /&gt;
|-&lt;br /&gt;
|os-nrpe&lt;br /&gt;
|1.1_1&lt;br /&gt;
|Execute nagios plugins&lt;br /&gt;
|-&lt;br /&gt;
|os-ntopng&lt;br /&gt;
|1.3&lt;br /&gt;
|Traffic Analysis and Flow Collection&lt;br /&gt;
|-&lt;br /&gt;
|os-nut&lt;br /&gt;
|1.9_1&lt;br /&gt;
|Network UPS Tools&lt;br /&gt;
|-&lt;br /&gt;
|os-openconnect&lt;br /&gt;
|1.4.6&lt;br /&gt;
|OpenConnect Client&lt;br /&gt;
|-&lt;br /&gt;
|os-openvpn-legacy&lt;br /&gt;
|1&lt;br /&gt;
|OpenVPN legacy support&lt;br /&gt;
|-&lt;br /&gt;
|os-OPNProxy&lt;br /&gt;
|1.0.5_4&lt;br /&gt;
|OPNsense proxy additions&lt;br /&gt;
|-&lt;br /&gt;
|os-postfix&lt;br /&gt;
|1.24&lt;br /&gt;
|SMTP mail relay&lt;br /&gt;
|-&lt;br /&gt;
|os-puppet-agent&lt;br /&gt;
|1.2&lt;br /&gt;
|Manage Puppet Agent&lt;br /&gt;
|-&lt;br /&gt;
|os-qemu-guest-agent&lt;br /&gt;
|1.3&lt;br /&gt;
|QEMU Guest Agent for OPNsense&lt;br /&gt;
|-&lt;br /&gt;
|os-radsecproxy&lt;br /&gt;
|1.1&lt;br /&gt;
|RADIUS proxy provides both RADIUS UDP and TCP/TLS (RadSec) transport&lt;br /&gt;
|-&lt;br /&gt;
|os-realtek-re&lt;br /&gt;
|1&lt;br /&gt;
|Realtek re(4) vendor driver&lt;br /&gt;
|-&lt;br /&gt;
|os-redis&lt;br /&gt;
|1.1_3&lt;br /&gt;
|Redis DB&lt;br /&gt;
|-&lt;br /&gt;
|os-relayd&lt;br /&gt;
|2.9_2&lt;br /&gt;
|Relayd Load Balancer&lt;br /&gt;
|-&lt;br /&gt;
|os-rfc2136&lt;br /&gt;
|1.9_4&lt;br /&gt;
|RFC-2136 Support&lt;br /&gt;
|-&lt;br /&gt;
|os-rspamd&lt;br /&gt;
|1.13_2&lt;br /&gt;
|Protect your network from spam&lt;br /&gt;
|-&lt;br /&gt;
|os-sftp-backup&lt;br /&gt;
|1.1_2&lt;br /&gt;
|Backup configurations using SFTP&lt;br /&gt;
|-&lt;br /&gt;
|os-shadowsocks&lt;br /&gt;
|1.3&lt;br /&gt;
|Secure socks5 proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-siproxd&lt;br /&gt;
|1.3_3&lt;br /&gt;
|Siproxd is a proxy daemon for the SIP protocol&lt;br /&gt;
|-&lt;br /&gt;
|os-smart&lt;br /&gt;
|2.4&lt;br /&gt;
|SMART tools&lt;br /&gt;
|-&lt;br /&gt;
|os-squid&lt;br /&gt;
|1.4&lt;br /&gt;
|Squid is a caching proxy for the web&lt;br /&gt;
|-&lt;br /&gt;
|os-sslh&lt;br /&gt;
|1.0_1&lt;br /&gt;
|sslh configuration front-end&lt;br /&gt;
|-&lt;br /&gt;
|os-strongswan-legacy&lt;br /&gt;
|1&lt;br /&gt;
|IPsec legacy support&lt;br /&gt;
|-&lt;br /&gt;
|os-stunnel&lt;br /&gt;
|1.0.6_1&lt;br /&gt;
|Stunnel TLS proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-sunnyvalley&lt;br /&gt;
|1.5_1&lt;br /&gt;
|Vendor Repository for Zenarmor (Enterprise Security Modules - NGFW, SSE, SASE, f.k.a Sensei)&lt;br /&gt;
|-&lt;br /&gt;
|os-tailscale&lt;br /&gt;
|1.3&lt;br /&gt;
|VPN mesh securely connecting clients using WireGuard&lt;br /&gt;
|-&lt;br /&gt;
|os-tayga&lt;br /&gt;
|1.3&lt;br /&gt;
|Tayga NAT64&lt;br /&gt;
|-&lt;br /&gt;
|os-telegraf&lt;br /&gt;
|1.12.13&lt;br /&gt;
|Agent for collecting metrics and data&lt;br /&gt;
|-&lt;br /&gt;
|os-tftp&lt;br /&gt;
|1&lt;br /&gt;
|TFTP server&lt;br /&gt;
|-&lt;br /&gt;
|os-theme-advanced&lt;br /&gt;
|1.1&lt;br /&gt;
|Theme based on AdvancedTomato GUI&lt;br /&gt;
|-&lt;br /&gt;
|os-theme-cicada&lt;br /&gt;
|1.4&lt;br /&gt;
|The cicada theme - dark grey onyx&lt;br /&gt;
|-&lt;br /&gt;
|os-theme-flexcolor&lt;br /&gt;
|1&lt;br /&gt;
|Theme with 3 different color schemes: black as default, light and dark-light&lt;br /&gt;
|-&lt;br /&gt;
|os-theme-rebellion&lt;br /&gt;
|1.9.3&lt;br /&gt;
|A suitably dark theme&lt;br /&gt;
|-&lt;br /&gt;
|os-theme-tukan&lt;br /&gt;
|1.3&lt;br /&gt;
|The tukan theme - blue/white&lt;br /&gt;
|-&lt;br /&gt;
|os-theme-vicuna&lt;br /&gt;
|1.5&lt;br /&gt;
|The vicuna theme - blue sapphire&lt;br /&gt;
|-&lt;br /&gt;
|os-tinc&lt;br /&gt;
|1.7_4&lt;br /&gt;
|Tinc VPN&lt;br /&gt;
|-&lt;br /&gt;
|os-tor&lt;br /&gt;
|1.1&lt;br /&gt;
|The Onion Router&lt;br /&gt;
|-&lt;br /&gt;
|os-turnserver&lt;br /&gt;
|1.1&lt;br /&gt;
|The coturn STUN/TURN Server&lt;br /&gt;
|-&lt;br /&gt;
|os-udpbroadcastrelay&lt;br /&gt;
|1.0_5&lt;br /&gt;
|Control udpbroadcastrelay processes&lt;br /&gt;
|-&lt;br /&gt;
|os-upnp&lt;br /&gt;
|1.8&lt;br /&gt;
|UPnP IGD &amp;amp; PCP/NAT-PMP Service&lt;br /&gt;
|-&lt;br /&gt;
|os-virtualbox&lt;br /&gt;
|1.0_1&lt;br /&gt;
|VirtualBox guest additions&lt;br /&gt;
|-&lt;br /&gt;
|os-vmware&lt;br /&gt;
|1.5_1&lt;br /&gt;
|VMware tools&lt;br /&gt;
|-&lt;br /&gt;
|os-vnstat&lt;br /&gt;
|1.3_1&lt;br /&gt;
|Network traffic monitor&lt;br /&gt;
|-&lt;br /&gt;
|os-wazuh-agent&lt;br /&gt;
|1.2_3&lt;br /&gt;
|Agent for the open source security platform Wazuh&lt;br /&gt;
|-&lt;br /&gt;
|os-wol&lt;br /&gt;
|2.5_3&lt;br /&gt;
|Wake on LAN Service&lt;br /&gt;
|-&lt;br /&gt;
|os-xen&lt;br /&gt;
|1.2_1&lt;br /&gt;
|Xen guest utilities&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix6-agent&lt;br /&gt;
|1.18&lt;br /&gt;
|Zabbix monitoring agent&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix6-proxy&lt;br /&gt;
|1.16&lt;br /&gt;
|Zabbix monitoring proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix7-agent&lt;br /&gt;
|1.18&lt;br /&gt;
|Zabbix monitoring agent&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix7-proxy&lt;br /&gt;
|1.16&lt;br /&gt;
|Zabbix monitoring proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix72-agent&lt;br /&gt;
|1.18&lt;br /&gt;
|Zabbix monitoring agent&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix72-proxy&lt;br /&gt;
|1.16&lt;br /&gt;
|Zabbix monitoring proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix74-agent&lt;br /&gt;
|1.18&lt;br /&gt;
|Zabbix monitoring agent&lt;br /&gt;
|-&lt;br /&gt;
|os-zabbix74-proxy&lt;br /&gt;
|1.16&lt;br /&gt;
|Zabbix monitoring proxy&lt;br /&gt;
|-&lt;br /&gt;
|os-zerotier&lt;br /&gt;
|1.3.2_6&lt;br /&gt;
|Virtual Networks That Just Work&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:OPNsense]]&lt;br /&gt;
[[Category:Review 2025 Q3]]&lt;br /&gt;
[[de:OPNsense Plugins]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Update_VMware_ESXi</id>
		<title>Update VMware ESXi</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Update_VMware_ESXi"/>
		<updated>2026-08-06T10:45:03Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Updates for VMware ESXi can be easily installed via the command line, even for the free version of the ESXi hypervisor. In this example, we explain how to install updates via command line using [[VMware ESXi 6.7]].&amp;lt;ref&amp;gt;[https://kb.vmware.com/articleview?docid=2008939 “esxcli software vib” commands to patch an ESXi 5.x/6.x host] (kb.vmware.com, VMware Knowledge Base Article 2008939)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Download updates == &lt;br /&gt;
In the following knowledge base article about VMware, you will find information on how to download the updates that are currently available for your system:&lt;br /&gt;
* https://kb.vmware.com/s/article/1021623&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:ESXi-6.7-Update-01-Downloads.png|Download available updates from VMware.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Load updates to EXSi host ==&lt;br /&gt;
In the next step, load the updates to the ESXi host. This is, for example, possible by using the datastore browser in the vSphere web client.&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:ESXi-6.7-Update-02-Web-Client.png|Open datastore browser.&lt;br /&gt;
File:ESXi-6.7-Update-03-New-Directory.png|Create new directory. &lt;br /&gt;
File:ESXi-6.7-Update-04-Upload.png|Click on upload and select files. &lt;br /&gt;
File:ESXi-6.7-Update-05-Files.png|Files have been uploaded. &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Install updates on the command line ==&lt;br /&gt;
Activate the SSH shell in the web client, stop or migrate all virtual machines and put the host into maintenance mode:&lt;br /&gt;
 [root@localhost:~] vim-cmd hostsvc/maintenance_mode_enter&lt;br /&gt;
&lt;br /&gt;
Next, install the updates on the esxcli command as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@localhost:~] esxcli software vib update -d /vmfs/volumes/datastore1/updates/ESXi670-201806001.zip&lt;br /&gt;
Installation Result&lt;br /&gt;
   Message: The update completed successfully, but the system needs to be rebooted for the changes to be effective.&lt;br /&gt;
   Reboot Required: true&lt;br /&gt;
   VIBs Installed: VMware_bootbank_cpu-microcode_6.7.0-0.14.8941472, VMware_bootbank_esx-base_6.7.0-0.14.8941472, VMware_bootbank_vsan_6.7.0-0.14.8941472, VMware_bootbank_vsanhealth_6.7.0-0.14.8941472, VMware_locker_tools-light_10.2.1.8267844-8941472&lt;br /&gt;
   VIBs Removed: VMware_bootbank_cpu-microcode_6.7.0-0.0.8169922, VMware_bootbank_esx-base_6.7.0-0.0.8169922, VMware_bootbank_vsan_6.7.0-0.0.8169922, VMware_bootbank_vsanhealth_6.7.0-0.0.8169922, VMware_locker_tools-light_10.2.0.7253323-8169922&lt;br /&gt;
   VIBs Skipped: VMW_bootbank_ata-libata-92_3.00.9.2-16vmw.670.0.0.8169922, VMW_bootbank_ata-pata-amd_0.3.10-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-atiixp_0.4.6-4vmw.670.0.0.8169922, VMW_bootbank_ata-pata-cmd64x_0.2.5-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-hpt3x2n_0.3.4-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-pdc2027x_1.0-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-serverworks_0.4.3-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-sil680_0.4.8-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-via_0.3.3-2vmw.670.0.0.8169922, VMW_bootbank_block-cciss_3.6.14-10vmw.670.0.0.8169922, VMW_bootbank_bnxtnet_20.6.101.7-11vmw.670.0.0.8169922, VMW_bootbank_brcmfcoe_11.4.1078.0-8vmw.670.0.0.8169922, VMW_bootbank_char-random_1.0-3vmw.670.0.0.8169922, VMW_bootbank_ehci-ehci-hcd_1.0-4vmw.670.0.0.8169922, VMW_bootbank_elxiscsi_11.4.1174.0-2vmw.670.0.0.8169922, VMW_bootbank_elxnet_11.4.1094.0-5vmw.670.0.0.8169922, VMW_bootbank_hid-hid_1.0-3vmw.670.0.0.8169922, VMW_bootbank_i40en_1.3.1-18vmw.670.0.0.8169922, VMW_bootbank_iavmd_1.2.0.1011-2vmw.670.0.0.8169922, VMW_bootbank_igbn_0.1.0.0-15vmw.670.0.0.8169922, VMW_bootbank_ima-qla4xxx_2.02.18-1vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-devintf_39.1-4vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-msghandler_39.1-4vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-si-drv_39.1-4vmw.670.0.0.8169922, VMW_bootbank_iser_1.0.0.0-1vmw.670.0.0.8169922, VMW_bootbank_ixgben_1.4.1-11vmw.670.0.0.8169922, VMW_bootbank_lpfc_11.4.33.1-6vmw.670.0.0.8169922, VMW_bootbank_lpnic_11.4.59.0-1vmw.670.0.0.8169922, VMW_bootbank_lsi-mr3_7.702.13.00-4vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt2_20.00.04.00-4vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt35_03.00.01.00-10vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt3_16.00.01.00-1vmw.670.0.0.8169922, VMW_bootbank_misc-cnic-register_1.78.75.v60.7-1vmw.670.0.0.8169922, VMW_bootbank_misc-drivers_6.7.0-0.0.8169922, VMW_bootbank_mtip32xx-native_3.9.6-1vmw.670.0.0.8169922, VMW_bootbank_ne1000_0.8.3-4vmw.670.0.0.8169922, VMW_bootbank_nenic_1.0.11.0-1vmw.670.0.0.8169922, VMW_bootbank_net-bnx2_2.2.4f.v60.10-2vmw.670.0.0.8169922, VMW_bootbank_net-bnx2x_1.78.80.v60.12-2vmw.670.0.0.8169922, VMW_bootbank_net-cdc-ether_1.0-3vmw.670.0.0.8169922, VMW_bootbank_net-cnic_1.78.76.v60.13-2vmw.670.0.0.8169922, VMW_bootbank_net-e1000_8.0.3.1-5vmw.670.0.0.8169922, VMW_bootbank_net-e1000e_3.2.2.1-2vmw.670.0.0.8169922, VMW_bootbank_net-enic_2.1.2.38-2vmw.670.0.0.8169922, VMW_bootbank_net-fcoe_1.0.29.9.3-7vmw.670.0.0.8169922, VMW_bootbank_net-forcedeth_0.61-2vmw.670.0.0.8169922, VMW_bootbank_net-igb_5.0.5.1.1-5vmw.670.0.0.8169922, VMW_bootbank_net-ixgbe_3.7.13.7.14iov-20vmw.670.0.0.8169922, VMW_bootbank_net-libfcoe-92_1.0.24.9.4-8vmw.670.0.0.8169922, VMW_bootbank_net-mlx4-core_1.9.7.0-1vmw.670.0.0.8169922, VMW_bootbank_net-mlx4-en_1.9.7.0-1vmw.670.0.0.8169922, VMW_bootbank_net-nx-nic_5.0.621-5vmw.670.0.0.8169922, VMW_bootbank_net-tg3_3.131d.v60.4-2vmw.670.0.0.8169922, VMW_bootbank_net-usbnet_1.0-3vmw.670.0.0.8169922, VMW_bootbank_net-vmxnet3_1.1.3.0-3vmw.670.0.0.8169922, VMW_bootbank_nhpsa_2.0.22-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-core_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-en_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-rdma_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx5-core_4.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx5-rdma_4.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_ntg3_4.1.3.0-1vmw.670.0.0.8169922, VMW_bootbank_nvme_1.2.1.34-1vmw.670.0.0.8169922, VMW_bootbank_nvmxnet3-ens_2.0.0.21-1vmw.670.0.0.8169922, VMW_bootbank_nvmxnet3_2.0.0.27-1vmw.670.0.0.8169922, VMW_bootbank_ohci-usb-ohci_1.0-3vmw.670.0.0.8169922, VMW_bootbank_pvscsi_0.1-2vmw.670.0.0.8169922, VMW_bootbank_qcnic_1.0.2.0.4-1vmw.670.0.0.8169922, VMW_bootbank_qedentv_2.0.6.4-8vmw.670.0.0.8169922, VMW_bootbank_qfle3_1.0.50.11-9vmw.670.0.0.8169922, VMW_bootbank_qfle3f_1.0.25.0.2-14vmw.670.0.0.8169922, VMW_bootbank_qfle3i_1.0.2.3.9-3vmw.670.0.0.8169922, VMW_bootbank_qflge_1.1.0.11-1vmw.670.0.0.8169922, VMW_bootbank_sata-ahci_3.0-26vmw.670.0.0.8169922, VMW_bootbank_sata-ata-piix_2.12-10vmw.670.0.0.8169922, VMW_bootbank_sata-sata-nv_3.5-4vmw.670.0.0.8169922, VMW_bootbank_sata-sata-promise_2.12-3vmw.670.0.0.8169922, VMW_bootbank_sata-sata-sil24_1.1-1vmw.670.0.0.8169922, VMW_bootbank_sata-sata-sil_2.3-4vmw.670.0.0.8169922, VMW_bootbank_sata-sata-svw_2.3-3vmw.670.0.0.8169922, VMW_bootbank_scsi-aacraid_1.1.5.1-9vmw.670.0.0.8169922, VMW_bootbank_scsi-adp94xx_1.0.8.12-6vmw.670.0.0.8169922, VMW_bootbank_scsi-aic79xx_3.1-6vmw.670.0.0.8169922, VMW_bootbank_scsi-bnx2fc_1.78.78.v60.8-1vmw.670.0.0.8169922, VMW_bootbank_scsi-bnx2i_2.78.76.v60.8-1vmw.670.0.0.8169922, VMW_bootbank_scsi-fnic_1.5.0.45-3vmw.670.0.0.8169922, VMW_bootbank_scsi-hpsa_6.0.0.84-3vmw.670.0.0.8169922, VMW_bootbank_scsi-ips_7.12.05-4vmw.670.0.0.8169922, VMW_bootbank_scsi-iscsi-linux-92_1.0.0.2-3vmw.670.0.0.8169922, VMW_bootbank_scsi-libfc-92_1.0.40.9.3-5vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid-mbox_2.20.5.1-6vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid-sas_6.603.55.00-2vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid2_2.00.4-9vmw.670.0.0.8169922, VMW_bootbank_scsi-mpt2sas_19.00.00.00-2vmw.670.0.0.8169922, VMW_bootbank_scsi-mptsas_4.23.01.00-10vmw.670.0.0.8169922, VMW_bootbank_scsi-mptspi_4.23.01.00-10vmw.670.0.0.8169922, VMW_bootbank_scsi-qla4xxx_5.01.03.2-7vmw.670.0.0.8169922, VMW_bootbank_shim-iscsi-linux-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-iscsi-linux-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libata-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libata-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfc-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfc-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfcoe-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfcoe-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-3-0_6.7.0-0.0.8169922, VMW_bootbank_smartpqi_1.0.1.553-10vmw.670.0.0.8169922, VMW_bootbank_uhci-usb-uhci_1.0-3vmw.670.0.0.8169922, VMW_bootbank_usb-storage-usb-storage_1.0-3vmw.670.0.0.8169922, VMW_bootbank_usbcore-usb_1.0-3vmw.670.0.0.8169922, VMW_bootbank_vmkata_0.1-1vmw.670.0.0.8169922, VMW_bootbank_vmkfcoe_1.0.0.0-1vmw.670.0.0.8169922, VMW_bootbank_vmkplexer-vmkplexer_6.7.0-0.0.8169922, VMW_bootbank_vmkusb_0.1-1vmw.670.0.0.8169922, VMW_bootbank_vmw-ahci_1.2.0-6vmw.670.0.0.8169922, VMW_bootbank_xhci-xhci_1.0-3vmw.670.0.0.8169922, VMware_bootbank_elx-esx-libelxima.so_11.4.1184.0-0.0.8169922, VMware_bootbank_esx-dvfilter-generic-fastpath_6.7.0-0.0.8169922, VMware_bootbank_esx-ui_1.25.0-7872652, VMware_bootbank_esx-xserver_6.7.0-0.0.8169922, VMware_bootbank_lsu-hp-hpsa-plugin_2.0.0-13vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-lsi-mr3-plugin_1.0.0-12vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-lsi-msgpt3-plugin_1.0.0-8vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-megaraid-sas-plugin_1.0.0-9vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-mpt2sas-plugin_2.0.0-7vmw.670.0.0.8169922, VMware_bootbank_native-misc-drivers_6.7.0-0.0.8169922, VMware_bootbank_qlnativefc_3.0.1.0-5vmw.670.0.0.8169922, VMware_bootbank_rste_2.0.2.0088-7vmw.670.0.0.8169922, VMware_bootbank_vmware-esx-esxcli-nvme-plugin_1.2.0.32-0.0.8169922&lt;br /&gt;
[root@localhost:~] esxcli software vib update -d /vmfs/volumes/datastore1/updates/ESXi670-201807001.zip&lt;br /&gt;
Installation Result&lt;br /&gt;
   Message: The update completed successfully, but the system needs to be rebooted for the changes to be effective.&lt;br /&gt;
   Reboot Required: true&lt;br /&gt;
   VIBs Installed: VMW_bootbank_qedentv_2.0.6.4-10vmw.670.0.17.9214924, VMware_bootbank_esx-base_6.7.0-0.17.9214924, VMware_bootbank_vsan_6.7.0-0.17.9214924, VMware_bootbank_vsanhealth_6.7.0-0.17.9214924&lt;br /&gt;
   VIBs Removed: VMW_bootbank_qedentv_2.0.6.4-8vmw.670.0.0.8169922, VMware_bootbank_esx-base_6.7.0-0.14.8941472, VMware_bootbank_vsan_6.7.0-0.14.8941472, VMware_bootbank_vsanhealth_6.7.0-0.14.8941472&lt;br /&gt;
   VIBs Skipped: VMW_bootbank_ata-libata-92_3.00.9.2-16vmw.670.0.0.8169922, VMW_bootbank_ata-pata-amd_0.3.10-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-atiixp_0.4.6-4vmw.670.0.0.8169922, VMW_bootbank_ata-pata-cmd64x_0.2.5-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-hpt3x2n_0.3.4-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-pdc2027x_1.0-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-serverworks_0.4.3-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-sil680_0.4.8-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-via_0.3.3-2vmw.670.0.0.8169922, VMW_bootbank_block-cciss_3.6.14-10vmw.670.0.0.8169922, VMW_bootbank_bnxtnet_20.6.101.7-11vmw.670.0.0.8169922, VMW_bootbank_brcmfcoe_11.4.1078.0-8vmw.670.0.0.8169922, VMW_bootbank_char-random_1.0-3vmw.670.0.0.8169922, VMW_bootbank_ehci-ehci-hcd_1.0-4vmw.670.0.0.8169922, VMW_bootbank_elxiscsi_11.4.1174.0-2vmw.670.0.0.8169922, VMW_bootbank_elxnet_11.4.1094.0-5vmw.670.0.0.8169922, VMW_bootbank_hid-hid_1.0-3vmw.670.0.0.8169922, VMW_bootbank_i40en_1.3.1-18vmw.670.0.0.8169922, VMW_bootbank_iavmd_1.2.0.1011-2vmw.670.0.0.8169922, VMW_bootbank_igbn_0.1.0.0-15vmw.670.0.0.8169922, VMW_bootbank_ima-qla4xxx_2.02.18-1vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-devintf_39.1-4vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-msghandler_39.1-4vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-si-drv_39.1-4vmw.670.0.0.8169922, VMW_bootbank_iser_1.0.0.0-1vmw.670.0.0.8169922, VMW_bootbank_ixgben_1.4.1-11vmw.670.0.0.8169922, VMW_bootbank_lpfc_11.4.33.1-6vmw.670.0.0.8169922, VMW_bootbank_lpnic_11.4.59.0-1vmw.670.0.0.8169922, VMW_bootbank_lsi-mr3_7.702.13.00-4vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt2_20.00.04.00-4vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt35_03.00.01.00-10vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt3_16.00.01.00-1vmw.670.0.0.8169922, VMW_bootbank_misc-cnic-register_1.78.75.v60.7-1vmw.670.0.0.8169922, VMW_bootbank_misc-drivers_6.7.0-0.0.8169922, VMW_bootbank_mtip32xx-native_3.9.6-1vmw.670.0.0.8169922, VMW_bootbank_ne1000_0.8.3-4vmw.670.0.0.8169922, VMW_bootbank_nenic_1.0.11.0-1vmw.670.0.0.8169922, VMW_bootbank_net-bnx2_2.2.4f.v60.10-2vmw.670.0.0.8169922, VMW_bootbank_net-bnx2x_1.78.80.v60.12-2vmw.670.0.0.8169922, VMW_bootbank_net-cdc-ether_1.0-3vmw.670.0.0.8169922, VMW_bootbank_net-cnic_1.78.76.v60.13-2vmw.670.0.0.8169922, VMW_bootbank_net-e1000_8.0.3.1-5vmw.670.0.0.8169922, VMW_bootbank_net-e1000e_3.2.2.1-2vmw.670.0.0.8169922, VMW_bootbank_net-enic_2.1.2.38-2vmw.670.0.0.8169922, VMW_bootbank_net-fcoe_1.0.29.9.3-7vmw.670.0.0.8169922, VMW_bootbank_net-forcedeth_0.61-2vmw.670.0.0.8169922, VMW_bootbank_net-igb_5.0.5.1.1-5vmw.670.0.0.8169922, VMW_bootbank_net-ixgbe_3.7.13.7.14iov-20vmw.670.0.0.8169922, VMW_bootbank_net-libfcoe-92_1.0.24.9.4-8vmw.670.0.0.8169922, VMW_bootbank_net-mlx4-core_1.9.7.0-1vmw.670.0.0.8169922, VMW_bootbank_net-mlx4-en_1.9.7.0-1vmw.670.0.0.8169922, VMW_bootbank_net-nx-nic_5.0.621-5vmw.670.0.0.8169922, VMW_bootbank_net-tg3_3.131d.v60.4-2vmw.670.0.0.8169922, VMW_bootbank_net-usbnet_1.0-3vmw.670.0.0.8169922, VMW_bootbank_net-vmxnet3_1.1.3.0-3vmw.670.0.0.8169922, VMW_bootbank_nhpsa_2.0.22-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-core_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-en_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-rdma_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx5-core_4.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx5-rdma_4.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_ntg3_4.1.3.0-1vmw.670.0.0.8169922, VMW_bootbank_nvme_1.2.1.34-1vmw.670.0.0.8169922, VMW_bootbank_nvmxnet3-ens_2.0.0.21-1vmw.670.0.0.8169922, VMW_bootbank_nvmxnet3_2.0.0.27-1vmw.670.0.0.8169922, VMW_bootbank_ohci-usb-ohci_1.0-3vmw.670.0.0.8169922, VMW_bootbank_pvscsi_0.1-2vmw.670.0.0.8169922, VMW_bootbank_qcnic_1.0.2.0.4-1vmw.670.0.0.8169922, VMW_bootbank_qfle3_1.0.50.11-9vmw.670.0.0.8169922, VMW_bootbank_qfle3f_1.0.25.0.2-14vmw.670.0.0.8169922, VMW_bootbank_qfle3i_1.0.2.3.9-3vmw.670.0.0.8169922, VMW_bootbank_qflge_1.1.0.11-1vmw.670.0.0.8169922, VMW_bootbank_sata-ahci_3.0-26vmw.670.0.0.8169922, VMW_bootbank_sata-ata-piix_2.12-10vmw.670.0.0.8169922, VMW_bootbank_sata-sata-nv_3.5-4vmw.670.0.0.8169922, VMW_bootbank_sata-sata-promise_2.12-3vmw.670.0.0.8169922, VMW_bootbank_sata-sata-sil24_1.1-1vmw.670.0.0.8169922, VMW_bootbank_sata-sata-sil_2.3-4vmw.670.0.0.8169922, VMW_bootbank_sata-sata-svw_2.3-3vmw.670.0.0.8169922, VMW_bootbank_scsi-aacraid_1.1.5.1-9vmw.670.0.0.8169922, VMW_bootbank_scsi-adp94xx_1.0.8.12-6vmw.670.0.0.8169922, VMW_bootbank_scsi-aic79xx_3.1-6vmw.670.0.0.8169922, VMW_bootbank_scsi-bnx2fc_1.78.78.v60.8-1vmw.670.0.0.8169922, VMW_bootbank_scsi-bnx2i_2.78.76.v60.8-1vmw.670.0.0.8169922, VMW_bootbank_scsi-fnic_1.5.0.45-3vmw.670.0.0.8169922, VMW_bootbank_scsi-hpsa_6.0.0.84-3vmw.670.0.0.8169922, VMW_bootbank_scsi-ips_7.12.05-4vmw.670.0.0.8169922, VMW_bootbank_scsi-iscsi-linux-92_1.0.0.2-3vmw.670.0.0.8169922, VMW_bootbank_scsi-libfc-92_1.0.40.9.3-5vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid-mbox_2.20.5.1-6vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid-sas_6.603.55.00-2vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid2_2.00.4-9vmw.670.0.0.8169922, VMW_bootbank_scsi-mpt2sas_19.00.00.00-2vmw.670.0.0.8169922, VMW_bootbank_scsi-mptsas_4.23.01.00-10vmw.670.0.0.8169922, VMW_bootbank_scsi-mptspi_4.23.01.00-10vmw.670.0.0.8169922, VMW_bootbank_scsi-qla4xxx_5.01.03.2-7vmw.670.0.0.8169922, VMW_bootbank_shim-iscsi-linux-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-iscsi-linux-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libata-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libata-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfc-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfc-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfcoe-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfcoe-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-3-0_6.7.0-0.0.8169922, VMW_bootbank_smartpqi_1.0.1.553-10vmw.670.0.0.8169922, VMW_bootbank_uhci-usb-uhci_1.0-3vmw.670.0.0.8169922, VMW_bootbank_usb-storage-usb-storage_1.0-3vmw.670.0.0.8169922, VMW_bootbank_usbcore-usb_1.0-3vmw.670.0.0.8169922, VMW_bootbank_vmkata_0.1-1vmw.670.0.0.8169922, VMW_bootbank_vmkfcoe_1.0.0.0-1vmw.670.0.0.8169922, VMW_bootbank_vmkplexer-vmkplexer_6.7.0-0.0.8169922, VMW_bootbank_vmkusb_0.1-1vmw.670.0.0.8169922, VMW_bootbank_vmw-ahci_1.2.0-6vmw.670.0.0.8169922, VMW_bootbank_xhci-xhci_1.0-3vmw.670.0.0.8169922, VMware_bootbank_cpu-microcode_6.7.0-0.14.8941472, VMware_bootbank_elx-esx-libelxima.so_11.4.1184.0-0.0.8169922, VMware_bootbank_esx-dvfilter-generic-fastpath_6.7.0-0.0.8169922, VMware_bootbank_esx-ui_1.25.0-7872652, VMware_bootbank_esx-xserver_6.7.0-0.0.8169922, VMware_bootbank_lsu-hp-hpsa-plugin_2.0.0-13vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-lsi-mr3-plugin_1.0.0-12vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-lsi-msgpt3-plugin_1.0.0-8vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-megaraid-sas-plugin_1.0.0-9vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-mpt2sas-plugin_2.0.0-7vmw.670.0.0.8169922, VMware_bootbank_native-misc-drivers_6.7.0-0.0.8169922, VMware_bootbank_qlnativefc_3.0.1.0-5vmw.670.0.0.8169922, VMware_bootbank_rste_2.0.2.0088-7vmw.670.0.0.8169922, VMware_bootbank_vmware-esx-esxcli-nvme-plugin_1.2.0.32-0.0.8169922, VMware_locker_tools-light_10.2.1.8267844-8941472&lt;br /&gt;
[root@localhost:~] esxcli software vib update -d /vmfs/volumes/datastore1/updates/ESXi670-201808001.zip&lt;br /&gt;
Installation Result&lt;br /&gt;
   Message: The update completed successfully, but the system needs to be rebooted for the changes to be effective.&lt;br /&gt;
   Reboot Required: true&lt;br /&gt;
   VIBs Installed: VMware_bootbank_cpu-microcode_6.7.0-0.20.9484548, VMware_bootbank_esx-base_6.7.0-0.20.9484548, VMware_bootbank_esx-ui_1.25.1-9210161, VMware_bootbank_vsan_6.7.0-0.20.9484548, VMware_bootbank_vsanhealth_6.7.0-0.20.9484548&lt;br /&gt;
   VIBs Removed: VMware_bootbank_cpu-microcode_6.7.0-0.14.8941472, VMware_bootbank_esx-base_6.7.0-0.17.9214924, VMware_bootbank_esx-ui_1.25.0-7872652, VMware_bootbank_vsan_6.7.0-0.17.9214924, VMware_bootbank_vsanhealth_6.7.0-0.17.9214924&lt;br /&gt;
   VIBs Skipped: VMW_bootbank_ata-libata-92_3.00.9.2-16vmw.670.0.0.8169922, VMW_bootbank_ata-pata-amd_0.3.10-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-atiixp_0.4.6-4vmw.670.0.0.8169922, VMW_bootbank_ata-pata-cmd64x_0.2.5-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-hpt3x2n_0.3.4-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-pdc2027x_1.0-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-serverworks_0.4.3-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-sil680_0.4.8-3vmw.670.0.0.8169922, VMW_bootbank_ata-pata-via_0.3.3-2vmw.670.0.0.8169922, VMW_bootbank_block-cciss_3.6.14-10vmw.670.0.0.8169922, VMW_bootbank_bnxtnet_20.6.101.7-11vmw.670.0.0.8169922, VMW_bootbank_brcmfcoe_11.4.1078.0-8vmw.670.0.0.8169922, VMW_bootbank_char-random_1.0-3vmw.670.0.0.8169922, VMW_bootbank_ehci-ehci-hcd_1.0-4vmw.670.0.0.8169922, VMW_bootbank_elxiscsi_11.4.1174.0-2vmw.670.0.0.8169922, VMW_bootbank_elxnet_11.4.1094.0-5vmw.670.0.0.8169922, VMW_bootbank_hid-hid_1.0-3vmw.670.0.0.8169922, VMW_bootbank_i40en_1.3.1-18vmw.670.0.0.8169922, VMW_bootbank_iavmd_1.2.0.1011-2vmw.670.0.0.8169922, VMW_bootbank_igbn_0.1.0.0-15vmw.670.0.0.8169922, VMW_bootbank_ima-qla4xxx_2.02.18-1vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-devintf_39.1-4vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-msghandler_39.1-4vmw.670.0.0.8169922, VMW_bootbank_ipmi-ipmi-si-drv_39.1-4vmw.670.0.0.8169922, VMW_bootbank_iser_1.0.0.0-1vmw.670.0.0.8169922, VMW_bootbank_ixgben_1.4.1-11vmw.670.0.0.8169922, VMW_bootbank_lpfc_11.4.33.1-6vmw.670.0.0.8169922, VMW_bootbank_lpnic_11.4.59.0-1vmw.670.0.0.8169922, VMW_bootbank_lsi-mr3_7.702.13.00-4vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt2_20.00.04.00-4vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt35_03.00.01.00-10vmw.670.0.0.8169922, VMW_bootbank_lsi-msgpt3_16.00.01.00-1vmw.670.0.0.8169922, VMW_bootbank_misc-cnic-register_1.78.75.v60.7-1vmw.670.0.0.8169922, VMW_bootbank_misc-drivers_6.7.0-0.0.8169922, VMW_bootbank_mtip32xx-native_3.9.6-1vmw.670.0.0.8169922, VMW_bootbank_ne1000_0.8.3-4vmw.670.0.0.8169922, VMW_bootbank_nenic_1.0.11.0-1vmw.670.0.0.8169922, VMW_bootbank_net-bnx2_2.2.4f.v60.10-2vmw.670.0.0.8169922, VMW_bootbank_net-bnx2x_1.78.80.v60.12-2vmw.670.0.0.8169922, VMW_bootbank_net-cdc-ether_1.0-3vmw.670.0.0.8169922, VMW_bootbank_net-cnic_1.78.76.v60.13-2vmw.670.0.0.8169922, VMW_bootbank_net-e1000_8.0.3.1-5vmw.670.0.0.8169922, VMW_bootbank_net-e1000e_3.2.2.1-2vmw.670.0.0.8169922, VMW_bootbank_net-enic_2.1.2.38-2vmw.670.0.0.8169922, VMW_bootbank_net-fcoe_1.0.29.9.3-7vmw.670.0.0.8169922, VMW_bootbank_net-forcedeth_0.61-2vmw.670.0.0.8169922, VMW_bootbank_net-igb_5.0.5.1.1-5vmw.670.0.0.8169922, VMW_bootbank_net-ixgbe_3.7.13.7.14iov-20vmw.670.0.0.8169922, VMW_bootbank_net-libfcoe-92_1.0.24.9.4-8vmw.670.0.0.8169922, VMW_bootbank_net-mlx4-core_1.9.7.0-1vmw.670.0.0.8169922, VMW_bootbank_net-mlx4-en_1.9.7.0-1vmw.670.0.0.8169922, VMW_bootbank_net-nx-nic_5.0.621-5vmw.670.0.0.8169922, VMW_bootbank_net-tg3_3.131d.v60.4-2vmw.670.0.0.8169922, VMW_bootbank_net-usbnet_1.0-3vmw.670.0.0.8169922, VMW_bootbank_net-vmxnet3_1.1.3.0-3vmw.670.0.0.8169922, VMW_bootbank_nhpsa_2.0.22-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-core_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-en_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx4-rdma_3.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx5-core_4.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_nmlx5-rdma_4.17.9.12-1vmw.670.0.0.8169922, VMW_bootbank_ntg3_4.1.3.0-1vmw.670.0.0.8169922, VMW_bootbank_nvme_1.2.1.34-1vmw.670.0.0.8169922, VMW_bootbank_nvmxnet3-ens_2.0.0.21-1vmw.670.0.0.8169922, VMW_bootbank_nvmxnet3_2.0.0.27-1vmw.670.0.0.8169922, VMW_bootbank_ohci-usb-ohci_1.0-3vmw.670.0.0.8169922, VMW_bootbank_pvscsi_0.1-2vmw.670.0.0.8169922, VMW_bootbank_qcnic_1.0.2.0.4-1vmw.670.0.0.8169922, VMW_bootbank_qedentv_2.0.6.4-10vmw.670.0.17.9214924, VMW_bootbank_qfle3_1.0.50.11-9vmw.670.0.0.8169922, VMW_bootbank_qfle3f_1.0.25.0.2-14vmw.670.0.0.8169922, VMW_bootbank_qfle3i_1.0.2.3.9-3vmw.670.0.0.8169922, VMW_bootbank_qflge_1.1.0.11-1vmw.670.0.0.8169922, VMW_bootbank_sata-ahci_3.0-26vmw.670.0.0.8169922, VMW_bootbank_sata-ata-piix_2.12-10vmw.670.0.0.8169922, VMW_bootbank_sata-sata-nv_3.5-4vmw.670.0.0.8169922, VMW_bootbank_sata-sata-promise_2.12-3vmw.670.0.0.8169922, VMW_bootbank_sata-sata-sil24_1.1-1vmw.670.0.0.8169922, VMW_bootbank_sata-sata-sil_2.3-4vmw.670.0.0.8169922, VMW_bootbank_sata-sata-svw_2.3-3vmw.670.0.0.8169922, VMW_bootbank_scsi-aacraid_1.1.5.1-9vmw.670.0.0.8169922, VMW_bootbank_scsi-adp94xx_1.0.8.12-6vmw.670.0.0.8169922, VMW_bootbank_scsi-aic79xx_3.1-6vmw.670.0.0.8169922, VMW_bootbank_scsi-bnx2fc_1.78.78.v60.8-1vmw.670.0.0.8169922, VMW_bootbank_scsi-bnx2i_2.78.76.v60.8-1vmw.670.0.0.8169922, VMW_bootbank_scsi-fnic_1.5.0.45-3vmw.670.0.0.8169922, VMW_bootbank_scsi-hpsa_6.0.0.84-3vmw.670.0.0.8169922, VMW_bootbank_scsi-ips_7.12.05-4vmw.670.0.0.8169922, VMW_bootbank_scsi-iscsi-linux-92_1.0.0.2-3vmw.670.0.0.8169922, VMW_bootbank_scsi-libfc-92_1.0.40.9.3-5vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid-mbox_2.20.5.1-6vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid-sas_6.603.55.00-2vmw.670.0.0.8169922, VMW_bootbank_scsi-megaraid2_2.00.4-9vmw.670.0.0.8169922, VMW_bootbank_scsi-mpt2sas_19.00.00.00-2vmw.670.0.0.8169922, VMW_bootbank_scsi-mptsas_4.23.01.00-10vmw.670.0.0.8169922, VMW_bootbank_scsi-mptspi_4.23.01.00-10vmw.670.0.0.8169922, VMW_bootbank_scsi-qla4xxx_5.01.03.2-7vmw.670.0.0.8169922, VMW_bootbank_shim-iscsi-linux-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-iscsi-linux-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libata-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libata-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfc-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfc-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfcoe-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-libfcoe-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-1-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-2-0_6.7.0-0.0.8169922, VMW_bootbank_shim-vmklinux-9-2-3-0_6.7.0-0.0.8169922, VMW_bootbank_smartpqi_1.0.1.553-10vmw.670.0.0.8169922, VMW_bootbank_uhci-usb-uhci_1.0-3vmw.670.0.0.8169922, VMW_bootbank_usb-storage-usb-storage_1.0-3vmw.670.0.0.8169922, VMW_bootbank_usbcore-usb_1.0-3vmw.670.0.0.8169922, VMW_bootbank_vmkata_0.1-1vmw.670.0.0.8169922, VMW_bootbank_vmkfcoe_1.0.0.0-1vmw.670.0.0.8169922, VMW_bootbank_vmkplexer-vmkplexer_6.7.0-0.0.8169922, VMW_bootbank_vmkusb_0.1-1vmw.670.0.0.8169922, VMW_bootbank_vmw-ahci_1.2.0-6vmw.670.0.0.8169922, VMW_bootbank_xhci-xhci_1.0-3vmw.670.0.0.8169922, VMware_bootbank_elx-esx-libelxima.so_11.4.1184.0-0.0.8169922, VMware_bootbank_esx-dvfilter-generic-fastpath_6.7.0-0.0.8169922, VMware_bootbank_esx-xserver_6.7.0-0.0.8169922, VMware_bootbank_lsu-hp-hpsa-plugin_2.0.0-13vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-lsi-mr3-plugin_1.0.0-12vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-lsi-msgpt3-plugin_1.0.0-8vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-megaraid-sas-plugin_1.0.0-9vmw.670.0.0.8169922, VMware_bootbank_lsu-lsi-mpt2sas-plugin_2.0.0-7vmw.670.0.0.8169922, VMware_bootbank_native-misc-drivers_6.7.0-0.0.8169922, VMware_bootbank_qlnativefc_3.0.1.0-5vmw.670.0.0.8169922, VMware_bootbank_rste_2.0.2.0088-7vmw.670.0.0.8169922, VMware_bootbank_vmware-esx-esxcli-nvme-plugin_1.2.0.32-0.0.8169922, VMware_locker_tools-light_10.2.1.8267844-8941472&lt;br /&gt;
[root@localhost:~]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Verify updates ==&lt;br /&gt;
You can also use esxcli to verify the versions that were just installed:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@localhost:~] esxcli software vib list&lt;br /&gt;
Name                           Version                               Vendor  Acceptance Level  Install Date&lt;br /&gt;
-----------------------------  ------------------------------------  ------  ----------------  ------------&lt;br /&gt;
ata-libata-92                  3.00.9.2-16vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-amd                   0.3.10-3vmw.670.0.0.8169922           VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-atiixp                0.4.6-4vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-cmd64x                0.2.5-3vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-hpt3x2n               0.3.4-3vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-pdc2027x              1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-serverworks           0.4.3-3vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-sil680                0.4.8-3vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ata-pata-via                   0.3.3-2vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
block-cciss                    3.6.14-10vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
bnxtnet                        20.6.101.7-11vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
brcmfcoe                       11.4.1078.0-8vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
char-random                    1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ehci-ehci-hcd                  1.0-4vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
elxiscsi                       11.4.1174.0-2vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
elxnet                         11.4.1094.0-5vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
hid-hid                        1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
i40en                          1.3.1-18vmw.670.0.0.8169922           VMW     VMwareCertified   2018-08-27&lt;br /&gt;
iavmd                          1.2.0.1011-2vmw.670.0.0.8169922       VMW     VMwareCertified   2018-08-27&lt;br /&gt;
igbn                           0.1.0.0-15vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ima-qla4xxx                    2.02.18-1vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ipmi-ipmi-devintf              39.1-4vmw.670.0.0.8169922             VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ipmi-ipmi-msghandler           39.1-4vmw.670.0.0.8169922             VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ipmi-ipmi-si-drv               39.1-4vmw.670.0.0.8169922             VMW     VMwareCertified   2018-08-27&lt;br /&gt;
iser                           1.0.0.0-1vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ixgben                         1.4.1-11vmw.670.0.0.8169922           VMW     VMwareCertified   2018-08-27&lt;br /&gt;
lpfc                           11.4.33.1-6vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
lpnic                          11.4.59.0-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
lsi-mr3                        7.702.13.00-4vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
lsi-msgpt2                     20.00.04.00-4vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
lsi-msgpt35                    03.00.01.00-10vmw.670.0.0.8169922     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
lsi-msgpt3                     16.00.01.00-1vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
misc-cnic-register             1.78.75.v60.7-1vmw.670.0.0.8169922    VMW     VMwareCertified   2018-08-27&lt;br /&gt;
misc-drivers                   6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
mtip32xx-native                3.9.6-1vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ne1000                         0.8.3-4vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nenic                          1.0.11.0-1vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-bnx2                       2.2.4f.v60.10-2vmw.670.0.0.8169922    VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-bnx2x                      1.78.80.v60.12-2vmw.670.0.0.8169922   VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-cdc-ether                  1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-cnic                       1.78.76.v60.13-2vmw.670.0.0.8169922   VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-e1000                      8.0.3.1-5vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-e1000e                     3.2.2.1-2vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-enic                       2.1.2.38-2vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-fcoe                       1.0.29.9.3-7vmw.670.0.0.8169922       VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-forcedeth                  0.61-2vmw.670.0.0.8169922             VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-igb                        5.0.5.1.1-5vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-ixgbe                      3.7.13.7.14iov-20vmw.670.0.0.8169922  VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-libfcoe-92                 1.0.24.9.4-8vmw.670.0.0.8169922       VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-mlx4-core                  1.9.7.0-1vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-mlx4-en                    1.9.7.0-1vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-nx-nic                     5.0.621-5vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-tg3                        3.131d.v60.4-2vmw.670.0.0.8169922     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-usbnet                     1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
net-vmxnet3                    1.1.3.0-3vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nhpsa                          2.0.22-1vmw.670.0.0.8169922           VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nmlx4-core                     3.17.9.12-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nmlx4-en                       3.17.9.12-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nmlx4-rdma                     3.17.9.12-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nmlx5-core                     4.17.9.12-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nmlx5-rdma                     4.17.9.12-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ntg3                           4.1.3.0-1vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nvme                           1.2.1.34-1vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nvmxnet3-ens                   2.0.0.21-1vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
nvmxnet3                       2.0.0.27-1vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
ohci-usb-ohci                  1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
pvscsi                         0.1-2vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
qcnic                          1.0.2.0.4-1vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
qedentv                        2.0.6.4-8vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
qfle3                          1.0.50.11-9vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
qfle3f                         1.0.25.0.2-14vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
qfle3i                         1.0.2.3.9-3vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
qflge                          1.1.0.11-1vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-ahci                      3.0-26vmw.670.0.0.8169922             VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-ata-piix                  2.12-10vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-sata-nv                   3.5-4vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-sata-promise              2.12-3vmw.670.0.0.8169922             VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-sata-sil24                1.1-1vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-sata-sil                  2.3-4vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
sata-sata-svw                  2.3-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-aacraid                   1.1.5.1-9vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-adp94xx                   1.0.8.12-6vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-aic79xx                   3.1-6vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-bnx2fc                    1.78.78.v60.8-1vmw.670.0.0.8169922    VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-bnx2i                     2.78.76.v60.8-1vmw.670.0.0.8169922    VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-fnic                      1.5.0.45-3vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-hpsa                      6.0.0.84-3vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-ips                       7.12.05-4vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-iscsi-linux-92            1.0.0.2-3vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-libfc-92                  1.0.40.9.3-5vmw.670.0.0.8169922       VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-megaraid-mbox             2.20.5.1-6vmw.670.0.0.8169922         VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-megaraid-sas              6.603.55.00-2vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-megaraid2                 2.00.4-9vmw.670.0.0.8169922           VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-mpt2sas                   19.00.00.00-2vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-mptsas                    4.23.01.00-10vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-mptspi                    4.23.01.00-10vmw.670.0.0.8169922      VMW     VMwareCertified   2018-08-27&lt;br /&gt;
scsi-qla4xxx                   5.01.03.2-7vmw.670.0.0.8169922        VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-iscsi-linux-9-2-1-0       6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-iscsi-linux-9-2-2-0       6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-libata-9-2-1-0            6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-libata-9-2-2-0            6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-libfc-9-2-1-0             6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-libfc-9-2-2-0             6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-libfcoe-9-2-1-0           6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-libfcoe-9-2-2-0           6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-vmklinux-9-2-1-0          6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-vmklinux-9-2-2-0          6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
shim-vmklinux-9-2-3-0          6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
smartpqi                       1.0.1.553-10vmw.670.0.0.8169922       VMW     VMwareCertified   2018-08-27&lt;br /&gt;
uhci-usb-uhci                  1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
usb-storage-usb-storage        1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
usbcore-usb                    1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
vmkata                         0.1-1vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
vmkfcoe                        1.0.0.0-1vmw.670.0.0.8169922          VMW     VMwareCertified   2018-08-27&lt;br /&gt;
vmkplexer-vmkplexer            6.7.0-0.0.8169922                     VMW     VMwareCertified   2018-08-27&lt;br /&gt;
vmkusb                         0.1-1vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
vmw-ahci                       1.2.0-6vmw.670.0.0.8169922            VMW     VMwareCertified   2018-08-27&lt;br /&gt;
xhci-xhci                      1.0-3vmw.670.0.0.8169922              VMW     VMwareCertified   2018-08-27&lt;br /&gt;
cpu-microcode                  6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
elx-esx-libelxima.so           11.4.1184.0-0.0.8169922               VMware  VMwareCertified   2018-08-27&lt;br /&gt;
esx-base                       6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
esx-dvfilter-generic-fastpath  6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
esx-ui                         1.25.0-7872652                        VMware  VMwareCertified   2018-08-27&lt;br /&gt;
esx-xserver                    6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
lsu-hp-hpsa-plugin             2.0.0-13vmw.670.0.0.8169922           VMware  VMwareCertified   2018-08-27&lt;br /&gt;
lsu-lsi-lsi-mr3-plugin         1.0.0-12vmw.670.0.0.8169922           VMware  VMwareCertified   2018-08-27&lt;br /&gt;
lsu-lsi-lsi-msgpt3-plugin      1.0.0-8vmw.670.0.0.8169922            VMware  VMwareCertified   2018-08-27&lt;br /&gt;
lsu-lsi-megaraid-sas-plugin    1.0.0-9vmw.670.0.0.8169922            VMware  VMwareCertified   2018-08-27&lt;br /&gt;
lsu-lsi-mpt2sas-plugin         2.0.0-7vmw.670.0.0.8169922            VMware  VMwareCertified   2018-08-27&lt;br /&gt;
native-misc-drivers            6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
qlnativefc                     3.0.1.0-5vmw.670.0.0.8169922          VMware  VMwareCertified   2018-08-27&lt;br /&gt;
rste                           2.0.2.0088-7vmw.670.0.0.8169922       VMware  VMwareCertified   2018-08-27&lt;br /&gt;
vmware-esx-esxcli-nvme-plugin  1.2.0.32-0.0.8169922                  VMware  VMwareCertified   2018-08-27&lt;br /&gt;
vsan                           6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
vsanhealth                     6.7.0-0.0.8169922                     VMware  VMwareCertified   2018-08-27&lt;br /&gt;
tools-light                    10.2.1.8267844-8941472                VMware  VMwareCertified   2018-08-27&lt;br /&gt;
[root@localhost:~]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Perform reboot and exit maintenance mode ==&lt;br /&gt;
Now, perform the reboot:&lt;br /&gt;
 [root@localhost:~] reboot&lt;br /&gt;
&lt;br /&gt;
After the reboot, exit maintenance mode:&lt;br /&gt;
 [root@localhost:~] vim-cmd hostsvc/maintenance_mode_exit&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:VMware vSphere 6.7]]&lt;br /&gt;
[[de:VMware ESXi updaten]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/IPMI_configuration_for_Supermicro_systems</id>
		<title>IPMI configuration for Supermicro systems</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/IPMI_configuration_for_Supermicro_systems"/>
		<updated>2026-08-06T09:30:00Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes tools for the configuration of IPMI modules for Supermicro systems. Alternatively, the ipmitool can also be used if the server is operated on Linux (see also IPMI Configuration under Linux using ipmitool).  == IPnMAC ==  With this tool (on Linux IPMICFG, see below), it is possible to set the IP address and the MAC address locally on the server. It must be taken into consideration that the correct MAC...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes tools for the configuration of IPMI modules for Supermicro systems. Alternatively, the ipmitool can also be used if the server is operated on Linux (see also [[Configuring IPMI under Linux using ipmitool|IPMI Configuration under Linux using ipmitool]]).&lt;br /&gt;
&lt;br /&gt;
== IPnMAC ==&lt;br /&gt;
&lt;br /&gt;
With this tool (on Linux IPMICFG, see below), it is possible to set the IP address and the MAC address locally on the server. It must be taken into consideration that the correct MAC address is already preconfigured.&lt;br /&gt;
&lt;br /&gt;
== XGICFG ==&lt;br /&gt;
&lt;br /&gt;
With the XGICFG tool (for DOS), diverse network parameters can be locally set for the IPMI module on the server. The possible options are listed in the following:&lt;br /&gt;
&lt;br /&gt;
 -m          Show IP and MAC&lt;br /&gt;
 -m IP       Set IP (format :###.###.###.###)&lt;br /&gt;
 -k          Show Subnet Mask&lt;br /&gt;
 -k Mask     Set Subnet Mask (format :###.###.###.###)&lt;br /&gt;
 -dhcp on    Enable the DHCP&lt;br /&gt;
 -dhcp off   Disable the DHCP&lt;br /&gt;
 -g          Show Gateway IP&lt;br /&gt;
 -g IP       Set Gateway IP (format :###.###.###.###)&lt;br /&gt;
&lt;br /&gt;
== IPMICFG ==&lt;br /&gt;
&lt;br /&gt;
IPMICFG allows the local configuration of multiple IPMI settings and is available for the following operating systems:&lt;br /&gt;
* Windows (In addition to the command-line program IPMICFG, it also includes the graphical &amp;#039;&amp;#039;IPMI Configuration Utility&amp;#039;&amp;#039;)&lt;br /&gt;
* Linux&lt;br /&gt;
* DOS&lt;br /&gt;
&lt;br /&gt;
Detailed information on IPMICFG: [[IPMI configuration for Supermicro servers with ipmicfg]]&lt;br /&gt;
&lt;br /&gt;
== IPMI view ==&lt;br /&gt;
[[Supermicro IPMI View]] also allows the IPMI configuration of Supermicro systems. For the access via IPMI view, however, a working IP address for IPMI must have been set up beforehand.&lt;br /&gt;
&lt;br /&gt;
== psetup ==&lt;br /&gt;
IPMI modules, that are based on the Raritan KIRA chip (such as the IPMI module for X7 motherboards), can also be configured by using psetup: [[Raritan KIRA basierendes Remote Management mit psetup konfigurieren|Configuration of Raritan KIRA based Remote Management with psetup]].&lt;br /&gt;
&lt;br /&gt;
== IPMI configuration via BIOS ==&lt;br /&gt;
&lt;br /&gt;
For the new Supermicro motherboards (X8/X9/H8 series), the configuration of the IPMI module is possible via mainboard BIOS: [[Supermicro IPMI Configuration through BIOS or Web Interface]]&lt;br /&gt;
&lt;br /&gt;
== Weblinks ==&lt;br /&gt;
&lt;br /&gt;
[https://www.thomas-krenn.com/redx/tools/mb_download.php/mid.x426274344b6e4f5a6365383d/SW_IPMICfg-Utility-Windows_1.5_110420.zip Download IPMI Config-Tool for Windows]&lt;br /&gt;
&lt;br /&gt;
[https://www.thomas-krenn.com/redx/tools/mb_download.php/mid.x4146352f4e6338477669733d/IPMICFG-DOS_v1.25_100106_1.zip Download IPMI Config-Tool for DOS]&lt;br /&gt;
&lt;br /&gt;
[https://www.thomas-krenn.com/redx/tools/mb_download.php/mid.x77383743655052663377773d/SW_IPMICFG-Linux_v1.37_20110429.zip Download IPMI Config-Tool for Linux]&lt;br /&gt;
&lt;br /&gt;
[ftp://ftp.supermicro.com/CDR-0010_2.10_IPMI_Server_Managment/ Content IPMI CD]&lt;br /&gt;
&lt;br /&gt;
[ftp://ftp.supermicro.com/CDR-0010_2.10_IPMI_Server_Managment/IPMI_Solution/ IPMI-View]&lt;br /&gt;
&lt;br /&gt;
[ftp://ftp.supermicro.com/CDR-0010_2.10_IPMI_Server_Managment/Manuals IPMI Documentation]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IPMI]]&lt;br /&gt;
[[pl:Konfiguracja IPMI w systemach Supermicro]]&lt;br /&gt;
[[de:IPMI Konfiguration für Supermicro Systeme]]&lt;br /&gt;
{{Aranzinger}}&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Software_tools_for_IPMI_at_a_glance</id>
		<title>Software tools for IPMI at a glance</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Software_tools_for_IPMI_at_a_glance"/>
		<updated>2026-08-06T05:51:48Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Manufacturer specific toolsy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For [[IPMI Basics|IPMI]], there are multiple software tools for different purposes and operating systems. In the following, there is an overview of useful &amp;#039;&amp;#039;&amp;#039;IPMI tools&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Linux ==&lt;br /&gt;
&lt;br /&gt;
=== IPMItool ===&lt;br /&gt;
[http://ipmitool.sourceforge.net/ IPMItool] is already included in multiple Linux distributions.&lt;br /&gt;
&lt;br /&gt;
You can now communicate with IPMItool in two different ways with IPMI BMC&amp;#039;s:&lt;br /&gt;
* via network by using a so-called LAN channel. In this case, only IPMItool is required.&lt;br /&gt;
* locally via a system interface to the BMC of the computer on which you are currently using IPMItool. In this case, the IPMI device driver from OpenIPMI is required (see below).&lt;br /&gt;
&lt;br /&gt;
Originally, IPMItool was often bundled with OpenIPMI in packages provided by distributions. However, since these are independent software tools, IPMItool is now usually provided as a standalone package.&amp;lt;ref&amp;gt;[https://bugzilla.redhat.com/show_bug.cgi?id=466762 Bug 466762  - Review Request: ipmitool - Utility for IPMI control  ] (bugzilla.redhat.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
More information on the IPMItool in Thomas-Krenn-Wiki:&lt;br /&gt;
* [[IPMI Konfiguration unter Linux mittels ipmitool|Configuring IPMI under Linux using ipmitool]]&lt;br /&gt;
* [[Ipmitool zur Remotesteuerung von Servern nutzen|Using Ipmitool to Remotely Control Servers]]&lt;br /&gt;
* [[Ipmitool zur Sensorabfrage von Servern nutzen|Using Ipmitool to Check Server Sensors]]&lt;br /&gt;
&lt;br /&gt;
=== OpenIPMI ===&lt;br /&gt;
[http://openipmi.sourceforge.net/ OpenIPMI] consists of two parts:&lt;br /&gt;
* an IPMI device driver for the Linux kernel&lt;br /&gt;
* a user-level library that provides a higher abstraction of IPMI&lt;br /&gt;
&lt;br /&gt;
Updates from OpenIPMI in RHEL:&lt;br /&gt;
* [http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.4/html/Technical_Notes/OpenIPMI.html OpenIPMI updates in RHEL 5.4]&lt;br /&gt;
* [http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.5.b1/html/Technical_Notes/ch01.html#OpenIPMI OpenIPMI updates in RHEL 5.5]&lt;br /&gt;
&lt;br /&gt;
More information on OpenIPMI in Thomas-Krenn-Wiki:&lt;br /&gt;
* [[IPMI Analyse mit openipmish|IPMI analysis with openipmish]]&lt;br /&gt;
&lt;br /&gt;
=== FreeIPMI ===&lt;br /&gt;
[[FreeIPMI]], just like IPMItool, allows IPMI queries both over the network and locally via a system interface. FreeIPMI, however, requires &amp;#039;&amp;#039;&amp;#039;no IPMI device driver&amp;#039;&amp;#039;&amp;#039;. The required code for the access via system interface is already included in FreeIPMI. It is not possible to run the OpenIPMI device driver and FreeIPMI at the same time.&lt;br /&gt;
&lt;br /&gt;
FreeIPMI is specifically designed to meet the requirements of large computer clusters (HPC). At Thomas-Krenn, we use FreeIPMI at [[IPMI Sensor Monitoring Plugin]] (v2 and v3) for Nagios/Icinga.&lt;br /&gt;
&lt;br /&gt;
FreeIPMI is included in RHEL 5 as Technology Preview.&amp;lt;ref&amp;gt;http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5/html/Release_Notes/sect-Release_Notes-Technology_Previews.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== IPMIutil ===&lt;br /&gt;
[http://ipmiutil.sourceforge.net/ IPMIutil] is another tool in the IPMI environment. In addition to Linux, it is also available for Windows, Solaris, BSD, and EFI. More details can be found in the [http://ipmiutil.sourceforge.net/docs/ipmisw-compare.htm comparison table of IPMIutil]. &lt;br /&gt;
&lt;br /&gt;
IPMIutil is included in Fedora 14.&amp;lt;ref&amp;gt;http://fedoraproject.org/wiki/Features/ipmiutil&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Windows ==&lt;br /&gt;
&lt;br /&gt;
=== Microsoft IPMI provider ===&lt;br /&gt;
The Microsoft IPMI provider is not an independent tool. Instead, as a WMI provider, it allows other tools to access IPMI BMC information.&lt;br /&gt;
&lt;br /&gt;
More information at Microsoft:&lt;br /&gt;
* [http://msdn.microsoft.com/en-us/library/aa391402%28VS.85%29.aspx IPMI Provider (Windows)] (http://msdn.microsoft.com)&lt;br /&gt;
&lt;br /&gt;
=== IPMIutil for Windows ===&lt;br /&gt;
(see [[#IPMIutil]]) &lt;br /&gt;
&lt;br /&gt;
== iPhone ==&lt;br /&gt;
[[file:IPhone-IPMI-touch-01.png|right|thumb|300px|IPMI touch on the iPhone]]&lt;br /&gt;
There are two IPMI apps for the iphone by [http://www.yellowkompressor.com/ www.yellowkompressor.com]&lt;br /&gt;
* [http://www.yellowkompressor.com/ipmi-touch/ipmi-touch/ IPMI touch] (subject to a fee), [http://itunes.apple.com/app/ipmi-touch/id325614107 IPMI touch in the AppStore]&lt;br /&gt;
* [http://www.yellowkompressor.com/ipmi-touch/ipmi-light/ IPMI light] (free of charge), [http://itunes.apple.com/app/ipmi-light/id325610519 IPMI light in the AppStore]&lt;br /&gt;
&lt;br /&gt;
== Manufacturer-specific tools ==&lt;br /&gt;
&lt;br /&gt;
=== Supermicro tools ===&lt;br /&gt;
See [[IPMI Konfiguration für Supermicro Systeme|IPMI configuration for Supermicro systems]].&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:IPMI]]&lt;br /&gt;
[[pl:Przegląd narzędzi programowych IPMI]]&lt;br /&gt;
[[de:Softwaretools für IPMI im Überblick]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Terraform_with_Proxmox_VE_tutorial</id>
		<title>Terraform with Proxmox VE tutorial</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Terraform_with_Proxmox_VE_tutorial"/>
		<updated>2026-08-05T05:48:16Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article is about the first use of Terraform with Proxmox VE. You will receive all the necessary information beginning with the installation of Terraform to the first deployment of a Proxmox resource (VM).  == Overview == Once setup is complete, the basic workflow in Terraform with Proxmox VE is as follows: # &amp;#039;&amp;#039;&amp;#039;Install Terraform&amp;#039;&amp;#039;&amp;#039; # &amp;#039;&amp;#039;&amp;#039;Create Proxmox API-Token:&amp;#039;&amp;#039;&amp;#039; for Terraform to access Proxmox VE  # &amp;#039;&amp;#039;&amp;#039;Create Terraform Provider:&amp;#039;&amp;#039;&amp;#039; Communicates Terraform that...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article is about the first use of Terraform with [[Proxmox VE]]. You will receive all the necessary information beginning with the installation of Terraform to the first deployment of a Proxmox resource (VM).&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
Once setup is complete, the basic workflow in Terraform with Proxmox VE is as follows:&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Install Terraform&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Create Proxmox API-Token:&amp;#039;&amp;#039;&amp;#039; for Terraform to access Proxmox VE &lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Create Terraform Provider:&amp;#039;&amp;#039;&amp;#039; Communicates Terraform that Proxmox VE is the deployment target &lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Create Cloud-Init-Image:&amp;#039;&amp;#039;&amp;#039; For a simple and completed deployment including IP addresses &lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Create or modify Terraform resources&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Terraform Init:&amp;#039;&amp;#039;&amp;#039; Terraform tests the connection to the provider &lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Terraform Plan:&amp;#039;&amp;#039;&amp;#039; Terraform displays the planned changes &lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Terraform Apply:&amp;#039;&amp;#039;&amp;#039; Terraform displays/modifies the resources&lt;br /&gt;
&lt;br /&gt;
== Terraform installation ==&lt;br /&gt;
=== Terraform installation ===&lt;br /&gt;
&lt;br /&gt;
A Debian 12 container has been created and Terraform has been installed with the following commands:&amp;lt;ref&amp;gt;[https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli Terraform Installation] (developer.hashicorp.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt install curl unzip &amp;amp;&amp;amp;&lt;br /&gt;
curl -O https://releases.hashicorp.com/terraform/1.5.3/terraform_1.5.3_linux_amd64.zip &amp;amp;&amp;amp;&lt;br /&gt;
unzip terraform_1.5.3_linux_amd64.zip&lt;br /&gt;
mv terraform /usr/local/bin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Creation of API token in PVE ===&lt;br /&gt;
&lt;br /&gt;
First, an API token must be created in Proxmox VE. This can be made on datacenter level at &amp;lt;code&amp;gt;Permissions -&amp;gt; API-Tokens -&amp;gt; Add&amp;lt;/code&amp;gt;. It is important that &amp;lt;code&amp;gt;Privilege Separation&amp;lt;/code&amp;gt; is set to &amp;lt;code&amp;gt;No&amp;lt;/code&amp;gt; for this functional test, or that you do not check the box when creating the API token. Please make a copy of the API key after you create it, as you will not be able to view it again later. In our case, this results in the following credentials:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;root@pam!terraform2&lt;br /&gt;
b057aea1-a092-49c3-b530-a53fd9e6fccc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Terraform configuration ==&lt;br /&gt;
=== Creating Terraform provider ===&lt;br /&gt;
&lt;br /&gt;
So that Terraform knows, that it should use Proxmox as provider, a &amp;lt;code&amp;gt;provider.tf&amp;lt;/code&amp;gt;-file must be created:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;touch provider.tf &lt;br /&gt;
nano provider.tf&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
terraform {&lt;br /&gt;
&lt;br /&gt;
        required_providers {&lt;br /&gt;
                proxmox = {&lt;br /&gt;
                        source = &amp;quot;telmate/proxmox&amp;quot;&lt;br /&gt;
                        version = &amp;quot;2.9.14&amp;quot;&lt;br /&gt;
                }&lt;br /&gt;
        }&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
variable &amp;quot;proxmox_api_url&amp;quot; {&lt;br /&gt;
        type = string&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
variable &amp;quot;proxmox_api_token_id&amp;quot; {&lt;br /&gt;
        type = string&lt;br /&gt;
        sensitive = true&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
variable &amp;quot;proxmox_api_token_secret&amp;quot; {&lt;br /&gt;
        type =  string&lt;br /&gt;
        sensitive = true&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
provider &amp;quot;proxmox&amp;quot; {&lt;br /&gt;
&lt;br /&gt;
        pm_api_url= var.proxmox_api_url&lt;br /&gt;
        pm_api_token_id = var.proxmox_api_token_id&lt;br /&gt;
        pm_api_token_secret = var.proxmox_api_token_secret&lt;br /&gt;
        pm_tls_insecure = true&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enter API credentials ===&lt;br /&gt;
&lt;br /&gt;
In addition, Terraform must now authenticate with Proxmox VE using the API user and API key. Here, the configuration file  &amp;lt;code&amp;gt;credentials.auto.tfvars&amp;lt;/code&amp;gt; can be used and adapted to the environment:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
touch credentials.auto.tfvars&lt;br /&gt;
nano credentials.auto.tfvars&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
proxmox_api_url = &amp;quot;https://10.2.1.130:8006/api2/json&amp;quot;&lt;br /&gt;
proxmox_api_token_id = &amp;quot;root@pam!terraform2&amp;quot;&lt;br /&gt;
proxmox_api_token_secret = &amp;quot;b057aea1-a092-49c3-b530-a53fd9e6fccc&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cloudinit under Proxmox VE ==&lt;br /&gt;
Since using cloud images makes sense in Terraform, here is a quick look at how to create and modify one. For this, an Ubuntu image is downloaded &amp;#039;&amp;#039;&amp;#039;on the Proxmox hypervisor&amp;#039;&amp;#039;&amp;#039; and the package &amp;lt;code&amp;gt;libguestfs-tools&amp;lt;/code&amp;gt; is installed, which is required to make adjustments in the cloud image.&amp;lt;ref&amp;gt;[https://libguestfs.org/virt-customize.1.html virt-customize - Customize a virtual machine] (libguestfs.org)&amp;lt;/ref&amp;gt; &lt;br /&gt;
Details for the creation of Cloud-Init-Templates can be found in the article  [[Cloud Init Templates in Proxmox VE - Quickstart]]&lt;br /&gt;
&lt;br /&gt;
=== Virt-Customize ===&lt;br /&gt;
The Virt-Customize tool is quite extensive and is also able to perform the following option:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
--run SCRIPT&lt;br /&gt;
--touch FILE&lt;br /&gt;
--firstboot SCRIPT&lt;br /&gt;
--mkdir DIR&lt;br /&gt;
--move SOURCE:DEST&lt;br /&gt;
--install PKG,PKG&lt;br /&gt;
--firstboot-install PKG,PKG&lt;br /&gt;
--append-line FILE:LINE&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Overview in Proxmox VE ==&lt;br /&gt;
The templates are prepared  and you can now use these templates to deploy as many VMs as you like. In the following example, there are 4 VMs that are ready to run immediately, including IP configuration, hostname, etc. To achieve this, 3 additional resource files were created with the names &amp;lt;code&amp;gt;srv_demo_2.tf&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;srv_demo_3.tf&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;srv_demo_4.tf&amp;lt;/code&amp;gt; and adapted to our needs.&lt;br /&gt;
&lt;br /&gt;
[[file:Proxmox Terraform.png|Terraform-Container and both templates (9000) and (9001)|frameless|without]]&lt;br /&gt;
&lt;br /&gt;
== Terraform Workflow ==&lt;br /&gt;
=== Terraform Init ===&lt;br /&gt;
&lt;br /&gt;
After this, it can be tested if Terraform can access the Proxmox host via API. For this, &amp;lt;code&amp;gt;terraform init&amp;lt;/code&amp;gt; is used:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;root@js-terraform-01:~# terraform init&lt;br /&gt;
&lt;br /&gt;
Initializing the backend...&lt;br /&gt;
&lt;br /&gt;
Initializing provider plugins...&lt;br /&gt;
- Reusing previous version of telmate/proxmox from the dependency lock file&lt;br /&gt;
- Using previously-installed telmate/proxmox v2.9.14&lt;br /&gt;
&lt;br /&gt;
Terraform has been successfully initialized!&lt;br /&gt;
&lt;br /&gt;
You may now begin working with Terraform. Try running &amp;quot;terraform plan&amp;quot; to see&lt;br /&gt;
any changes that are required for your infrastructure. All Terraform commands&lt;br /&gt;
should now work.&lt;br /&gt;
&lt;br /&gt;
If you ever set or change modules or backend configuration for Terraform,&lt;br /&gt;
rerun this command to reinitialize your working directory. If you forget, other&lt;br /&gt;
commands will detect it and remind you to do so if necessary.&lt;br /&gt;
root@js-terraform-01:~# &amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create Terraform resource ===&lt;br /&gt;
&lt;br /&gt;
The goal of Terraform is, simply put, to be able to provision individual resources on various hypervisors (in this case with Proxmox VE). For this, Terraform configuration files are created, which describe what the resource to be provisioned should look like. Here is an example of the &amp;lt;code&amp;gt;srvdemo1.tf&amp;lt;/code&amp;gt; file. We will be using a clone, so we need the VM template &amp;lt;code&amp;gt;ubuntu2204-ci&amp;lt;/code&amp;gt;, which will later be created using a cloud image.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
touch srvdemo1.tf&lt;br /&gt;
nano srvdemo1.tf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;resource &amp;quot;proxmox_vm_qemu&amp;quot; &amp;quot;srv_demo_1&amp;quot; {&lt;br /&gt;
        name = &amp;quot;srv-demo-1&amp;quot;&lt;br /&gt;
        desc = &amp;quot;Ubuntu-Server&amp;quot;&lt;br /&gt;
        target_node = &amp;quot;PMX4&amp;quot;&lt;br /&gt;
        sshkeys = &amp;quot;ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj8ipwPHVSI/yvERzILBD52zL1jj6Ja3ptWlVhR0WK6ElBekwKL314Sps79xAitJb&amp;gt;&lt;br /&gt;
        agent = 1&lt;br /&gt;
        clone = &amp;quot;ubuntu2204-ci&amp;quot;&lt;br /&gt;
        qemu_os = &amp;quot;l26&amp;quot;&lt;br /&gt;
        # this l26 is a small l like linux&lt;br /&gt;
        cores = 2&lt;br /&gt;
        sockets = 1&lt;br /&gt;
        cpu = &amp;quot;host&amp;quot;&lt;br /&gt;
        memory = 8096&lt;br /&gt;
        scsihw = &amp;quot;virtio-scsi-pci&amp;quot;&lt;br /&gt;
&lt;br /&gt;
        vga {&lt;br /&gt;
                type = &amp;quot;std&amp;quot;&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        disk {&lt;br /&gt;
                storage = &amp;quot;vm_nvme&amp;quot;&lt;br /&gt;
                type = &amp;quot;scsi&amp;quot;&lt;br /&gt;
                size = &amp;quot;83212M&amp;quot;&lt;br /&gt;
                discard = &amp;quot;on&amp;quot;&lt;br /&gt;
                ssd = &amp;quot;1&amp;quot;&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        network {&lt;br /&gt;
                bridge = &amp;quot;vmbr0&amp;quot;&lt;br /&gt;
                model = &amp;quot;virtio&amp;quot;&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        ## must match the template&lt;br /&gt;
&lt;br /&gt;
        os_type = &amp;quot;cloud-init&amp;quot;&lt;br /&gt;
        ipconfig0 = &amp;quot;ip=dhcp&amp;quot;&lt;br /&gt;
        nameserver = &amp;quot;192.168.110.61&amp;quot;&lt;br /&gt;
        ciuser = &amp;quot;tk&amp;quot;&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A VM is created, including IP configuration. In addition, a cloud image is used, which you can also customize to suit your own needs.&lt;br /&gt;
&lt;br /&gt;
=== Terraform plan ===&lt;br /&gt;
&lt;br /&gt;
With &amp;lt;code&amp;gt; terraform plan &amp;lt;/code&amp;gt;, you can use Terraform to provision the VM. This means that no resources are created yet. The configuration file and the connection to the provider are tested and validated.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;root@js-terraform-01:~# terraform plan&lt;br /&gt;
  + create&lt;br /&gt;
&lt;br /&gt;
Terraform will perform the following actions:&lt;br /&gt;
&lt;br /&gt;
  # proxmox_vm_qemu.srv_demo_1 will be created&lt;br /&gt;
  + resource &amp;quot;proxmox_vm_qemu&amp;quot; &amp;quot;srv_demo_1&amp;quot; {&lt;br /&gt;
      + additional_wait           = 5&lt;br /&gt;
      + agent                     = 1&lt;br /&gt;
      + automatic_reboot          = true&lt;br /&gt;
      + balloon                   = 0&lt;br /&gt;
      + bios                      = &amp;quot;seabios&amp;quot;&lt;br /&gt;
      + boot                      = (known after apply)&lt;br /&gt;
      + bootdisk                  = (known after apply)&lt;br /&gt;
      + ciuser                    = &amp;quot;tk&amp;quot;&lt;br /&gt;
      + clone                     = &amp;quot;ubuntu2204-ci&amp;quot;&lt;br /&gt;
      + clone_wait                = 10&lt;br /&gt;
      + cores                     = 2&lt;br /&gt;
      + cpu                       = &amp;quot;host&amp;quot;&lt;br /&gt;
      + default_ipv4_address      = (known after apply)&lt;br /&gt;
      + define_connection_info    = true&lt;br /&gt;
      + desc                      = &amp;quot;Ubuntu-Server&amp;quot;&lt;br /&gt;
      + force_create              = false&lt;br /&gt;
      + full_clone                = true&lt;br /&gt;
      + guest_agent_ready_timeout = 100&lt;br /&gt;
      + hotplug                   = &amp;quot;network,disk,usb&amp;quot;&lt;br /&gt;
      + id                        = (known after apply)&lt;br /&gt;
      + ipconfig0                 = &amp;quot;ip=dhcp&amp;quot;&lt;br /&gt;
      + kvm                       = true&lt;br /&gt;
      + memory                    = 8096&lt;br /&gt;
      + name                      = &amp;quot;srv-demo-1&amp;quot;&lt;br /&gt;
      + nameserver                = &amp;quot;192.168.110.61&amp;quot;&lt;br /&gt;
      + onboot                    = false&lt;br /&gt;
      + oncreate                  = true&lt;br /&gt;
      + os_type                   = &amp;quot;cloud-init&amp;quot;&lt;br /&gt;
      + preprovision              = true&lt;br /&gt;
      + reboot_required           = (known after apply)&lt;br /&gt;
      + scsihw                    = &amp;quot;virtio-scsi-pci&amp;quot;&lt;br /&gt;
      + searchdomain              = (known after apply)&lt;br /&gt;
      + sockets                   = 1&lt;br /&gt;
      + ssh_host                  = (known after apply)&lt;br /&gt;
      + ssh_port                  = (known after apply)&lt;br /&gt;
      + sshkeys                   = &amp;quot;ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj8ipwPHVSI/yvERzILBD52zL1jj6JaSKoN1t1ftXEKbp+cuwZPUWykvSaR13ptWlVhR0WK6ElBekwKL314Sps79xAitJbbD35yDuMVtLUK/Bo+j2ehuWWmFZMwi1UKsPgCzF/YarsX12aCIS2Gyyf2NnscgOGlQKIdcgtfO23Xz18yxQxmFuRFVbFscd7gghRoQWsoKKwldbCKS8JEbXE8Mrb5mA7XD1C4dQLMnFvoJUvx3UqZinQHc20lWjqlZIOZ0uxRz6ssVFoCn+bKKNdf43JEnwPhcxQC2vGmKWunojNsXCifdx16fvd/wegXrdL8uw2oWUAvNsjCIUYCFn+VOn5JXEAxlXCAUNN9Z9H6/64QhwTjAXibwzB8Yj2+mGqd2ODy9ZIs+nzqxsmITA8+ayaEigZngol54f6vafmQzRHrM6Zn768UEYqEGb2LgYtI/0eTClO+E0HAPVfwpRwy6T1MhmIY8otSizE3PN3pg+fcyxv9oyMnxVsYCpspzE= root@js-terraform-01&amp;gt;&amp;quot;&lt;br /&gt;
      + tablet                    = true&lt;br /&gt;
      + target_node               = &amp;quot;PMX4&amp;quot;&lt;br /&gt;
      + unused_disk               = (known after apply)&lt;br /&gt;
      + vcpus                     = 0&lt;br /&gt;
      + vlan                      = -1&lt;br /&gt;
      + vmid                      = (known after apply)&lt;br /&gt;
&lt;br /&gt;
      + disk {&lt;br /&gt;
          + backup             = true&lt;br /&gt;
          + cache              = &amp;quot;none&amp;quot;&lt;br /&gt;
          + discard            = &amp;quot;on&amp;quot;&lt;br /&gt;
          + file               = (known after apply)&lt;br /&gt;
          + format             = (known after apply)&lt;br /&gt;
          + iops               = 0&lt;br /&gt;
          + iops_max           = 0&lt;br /&gt;
          + iops_max_length    = 0&lt;br /&gt;
          + iops_rd            = 0&lt;br /&gt;
          + iops_rd_max        = 0&lt;br /&gt;
          + iops_rd_max_length = 0&lt;br /&gt;
          + iops_wr            = 0&lt;br /&gt;
          + iops_wr_max        = 0&lt;br /&gt;
          + iops_wr_max_length = 0&lt;br /&gt;
          + iothread           = 0&lt;br /&gt;
          + mbps               = 0&lt;br /&gt;
          + mbps_rd            = 0&lt;br /&gt;
          + mbps_rd_max        = 0&lt;br /&gt;
          + mbps_wr            = 0&lt;br /&gt;
          + mbps_wr_max        = 0&lt;br /&gt;
          + media              = (known after apply)&lt;br /&gt;
          + replicate          = 0&lt;br /&gt;
          + size               = &amp;quot;83212M&amp;quot;&lt;br /&gt;
          + slot               = (known after apply)&lt;br /&gt;
          + ssd                = 1&lt;br /&gt;
          + storage            = &amp;quot;vm_nvme&amp;quot;&lt;br /&gt;
          + storage_type       = (known after apply)&lt;br /&gt;
          + type               = &amp;quot;scsi&amp;quot;&lt;br /&gt;
          + volume             = (known after apply)&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
      + network {&lt;br /&gt;
          + bridge    = &amp;quot;vmbr0&amp;quot;&lt;br /&gt;
          + firewall  = false&lt;br /&gt;
          + link_down = false&lt;br /&gt;
          + macaddr   = (known after apply)&lt;br /&gt;
          + model     = &amp;quot;virtio&amp;quot;&lt;br /&gt;
          + queues    = (known after apply)&lt;br /&gt;
          + rate      = (known after apply)&lt;br /&gt;
          + tag       = -1&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
      + vga {&lt;br /&gt;
          + type = &amp;quot;std&amp;quot;&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Terraform Apply ===&lt;br /&gt;
&lt;br /&gt;
You can then create the resources using &amp;lt;code&amp;gt;terraform apply &amp;lt;/code&amp;gt;. Confirm with &amp;lt;code&amp;gt;yes&amp;lt;/code&amp;gt;, and then (in this case, 4 VMs) will be deployed. The output has been shortened for clarity, so that only the complete output of &amp;lt;code&amp;gt;srv_demo_1&amp;lt;/code&amp;gt; is displayed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;root@js-terraform-01:~# terraform apply&lt;br /&gt;
&lt;br /&gt;
Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols:&lt;br /&gt;
  + create&lt;br /&gt;
&lt;br /&gt;
Terraform will perform the following actions:&lt;br /&gt;
&lt;br /&gt;
  # proxmox_vm_qemu.srv_demo_1 will be created&lt;br /&gt;
  + resource &amp;quot;proxmox_vm_qemu&amp;quot; &amp;quot;srv_demo_1&amp;quot; {&lt;br /&gt;
      + additional_wait           = 5&lt;br /&gt;
      + agent                     = 1&lt;br /&gt;
      + automatic_reboot          = true&lt;br /&gt;
      + balloon                   = 0&lt;br /&gt;
      + bios                      = &amp;quot;seabios&amp;quot;&lt;br /&gt;
      + boot                      = (known after apply)&lt;br /&gt;
      + bootdisk                  = (known after apply)&lt;br /&gt;
      + ciuser                    = &amp;quot;tk&amp;quot;&lt;br /&gt;
      + clone                     = &amp;quot;ubuntu2204-ci&amp;quot;&lt;br /&gt;
      + clone_wait                = 10&lt;br /&gt;
      + cores                     = 2&lt;br /&gt;
      + cpu                       = &amp;quot;host&amp;quot;&lt;br /&gt;
      + default_ipv4_address      = (known after apply)&lt;br /&gt;
      + define_connection_info    = true&lt;br /&gt;
      + desc                      = &amp;quot;Ubuntu-Server&amp;quot;&lt;br /&gt;
      + force_create              = false&lt;br /&gt;
      + full_clone                = true&lt;br /&gt;
      + guest_agent_ready_timeout = 100&lt;br /&gt;
      + hotplug                   = &amp;quot;network,disk,usb&amp;quot;&lt;br /&gt;
      + id                        = (known after apply)&lt;br /&gt;
      + ipconfig0                 = &amp;quot;ip=dhcp&amp;quot;&lt;br /&gt;
      + kvm                       = true&lt;br /&gt;
      + memory                    = 8096&lt;br /&gt;
      + name                      = &amp;quot;srv-demo-1&amp;quot;&lt;br /&gt;
      + nameserver                = &amp;quot;192.168.110.61&amp;quot;&lt;br /&gt;
      + onboot                    = false&lt;br /&gt;
      + oncreate                  = true&lt;br /&gt;
      + os_type                   = &amp;quot;cloud-init&amp;quot;&lt;br /&gt;
      + preprovision              = true&lt;br /&gt;
      + reboot_required           = (known after apply)&lt;br /&gt;
      + scsihw                    = &amp;quot;virtio-scsi-pci&amp;quot;&lt;br /&gt;
      + searchdomain              = (known after apply)&lt;br /&gt;
      + sockets                   = 1&lt;br /&gt;
      + ssh_host                  = (known after apply)&lt;br /&gt;
      + ssh_port                  = (known after apply)&lt;br /&gt;
      + sshkeys                   = &amp;quot;ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj8ipwPHVSI/yvERzILBD52zL1jj6JaSKoN1t1ftXEKbp+cuwZPUWykvSaR13ptWlVhR0WK6ElBekwKL314Sps79xAitJbbD35yDuMVtLUK/Bo+j2ehuWWmFZMwi1UKsPgCzF/YarsX12aCIS2Gyyf2NnscgOGlQKIdcgtfO23Xz18yxQxmFuRFVbFscd7gghRoQWsoKKwldbCKS8JEbXE8Mrb5mA7XD1C4dQLMnFvoJUv= root@js-terraform-01&amp;gt;&amp;quot;&lt;br /&gt;
      + tablet                    = true&lt;br /&gt;
      + target_node               = &amp;quot;PMX4&amp;quot;&lt;br /&gt;
      + unused_disk               = (known after apply)&lt;br /&gt;
      + vcpus                     = 0&lt;br /&gt;
      + vlan                      = -1&lt;br /&gt;
      + vmid                      = (known after apply)&lt;br /&gt;
&lt;br /&gt;
      + disk {&lt;br /&gt;
          + backup             = true&lt;br /&gt;
          + cache              = &amp;quot;none&amp;quot;&lt;br /&gt;
          + discard            = &amp;quot;on&amp;quot;&lt;br /&gt;
          + file               = (known after apply)&lt;br /&gt;
          + format             = (known after apply)&lt;br /&gt;
          + iops               = 0&lt;br /&gt;
          + iops_max           = 0&lt;br /&gt;
          + iops_max_length    = 0&lt;br /&gt;
          + iops_rd            = 0&lt;br /&gt;
          + iops_rd_max        = 0&lt;br /&gt;
          + iops_rd_max_length = 0&lt;br /&gt;
          + iops_wr            = 0&lt;br /&gt;
          + iops_wr_max        = 0&lt;br /&gt;
          + iops_wr_max_length = 0&lt;br /&gt;
          + iothread           = 0&lt;br /&gt;
          + mbps               = 0&lt;br /&gt;
          + mbps_rd            = 0&lt;br /&gt;
          + mbps_rd_max        = 0&lt;br /&gt;
          + mbps_wr            = 0&lt;br /&gt;
          + mbps_wr_max        = 0&lt;br /&gt;
          + media              = (known after apply)&lt;br /&gt;
          + replicate          = 0&lt;br /&gt;
          + size               = &amp;quot;83212M&amp;quot;&lt;br /&gt;
          + slot               = (known after apply)&lt;br /&gt;
          + ssd                = 1&lt;br /&gt;
          + storage            = &amp;quot;vm_nvme&amp;quot;&lt;br /&gt;
          + storage_type       = (known after apply)&lt;br /&gt;
          + type               = &amp;quot;scsi&amp;quot;&lt;br /&gt;
          + volume             = (known after apply)&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
      + network {&lt;br /&gt;
          + bridge    = &amp;quot;vmbr0&amp;quot;&lt;br /&gt;
          + firewall  = false&lt;br /&gt;
          + link_down = false&lt;br /&gt;
          + macaddr   = (known after apply)&lt;br /&gt;
          + model     = &amp;quot;virtio&amp;quot;&lt;br /&gt;
          + queues    = (known after apply)&lt;br /&gt;
          + rate      = (known after apply)&lt;br /&gt;
          + tag       = -1&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
      + vga {&lt;br /&gt;
          + type = &amp;quot;std&amp;quot;&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  # proxmox_vm_qemu.srv_demo_2 will be created&lt;br /&gt;
  # proxmox_vm_qemu.srv_demo_3 will be created&lt;br /&gt;
  # proxmox_vm_qemu.srv_demo_4 will be created&lt;br /&gt;
 &lt;br /&gt;
Plan: 4 to add, 0 to change, 0 to destroy.&lt;br /&gt;
&lt;br /&gt;
Do you want to perform these actions?&lt;br /&gt;
  Terraform will perform the actions described above.&lt;br /&gt;
  Only &amp;#039;yes&amp;#039; will be accepted to approve.&lt;br /&gt;
&lt;br /&gt;
  Enter a value: yes&lt;br /&gt;
&lt;br /&gt;
proxmox_vm_qemu.srv_demo_4: Creating...&lt;br /&gt;
proxmox_vm_qemu.srv_demo_2: Creating...&lt;br /&gt;
proxmox_vm_qemu.srv_demo_3: Creating...&lt;br /&gt;
proxmox_vm_qemu.srv_demo_1: Creating...&lt;br /&gt;
...&lt;br /&gt;
proxmox_vm_qemu.srv_demo_4: Creation complete after 39s [id=PMX4/qemu/103]&lt;br /&gt;
proxmox_vm_qemu.srv_demo_3: Creation complete after 47s [id=PMX4/qemu/101]&lt;br /&gt;
proxmox_vm_qemu.srv_demo_1: Creation complete after 49s [id=PMX4/qemu/102]&lt;br /&gt;
proxmox_vm_qemu.srv_demo_2: Creation complete after 53s [id=PMX4/qemu/104]&lt;br /&gt;
&lt;br /&gt;
Apply complete! Resources: 4 added, 0 changed, 0 destroyed.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
[[file:Proxmox Terraform Apply.png|without|small|650x650px|Terraform allocates Proxmox VMs]]&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://www.youtube.com/watch?v=dvyeoDBUtsU&amp;amp; YouTube video on Proxmox Automation with Terraform]: Live-Demo on using and configuring Terraform in Proxmox VE&lt;br /&gt;
* [https://registry.terraform.io/providers/Telmate/proxmox/latest Proxmox Terraform Provider]: Terraform-Provider Docs (Telmate/proxmox)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:VMs/Containers]]&lt;br /&gt;
[[de:Terraform mit Proxmox VE Tutorial]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/IPMI/BMC_Security_Vulnerability_in_Older_Implementations</id>
		<title>IPMI/BMC Security Vulnerability in Older Implementations</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/IPMI/BMC_Security_Vulnerability_in_Older_Implementations"/>
		<updated>2026-07-31T09:05:42Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Sources */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Introduction ==&lt;br /&gt;
In July 2025, attention was once again drawn to a vulnerability that has been known for many years in various implementations of the Intelligent Platform Management Interface (IPMI) and the underlying Baseboard Management Controllers (BMCs). Security researchers have identified numerous management interfaces that are available via Internet, which remain vulnerable to an attack on the authentication mechanism.&lt;br /&gt;
&lt;br /&gt;
The vulnerability allows, with certain requirements, to read out password hashes from user accounts. After that, they can be analyzed offline or attacked via brute force or dictionary attacks. As IPMI operates independently of the installed operating system and provides extensive administrative functions, a successful compromise poses a significant security risk.&lt;br /&gt;
&lt;br /&gt;
== Background == &lt;br /&gt;
IPMI is a standardized management interface for administrating servers. The implementation is made via Baseboard Management Controller (BMC), which operates independently from the operating system. Administrators can also&lt;br /&gt;
&lt;br /&gt;
* switch on and switch off servers&lt;br /&gt;
* monitor the system condition&lt;br /&gt;
* update firmware&lt;br /&gt;
* perform console access as well as&lt;br /&gt;
* remote installations&lt;br /&gt;
&lt;br /&gt;
As these functions are also available when the operating system is switched off or does not function, the BMC possesses multiple authorizations and should be extra protected.&lt;br /&gt;
&lt;br /&gt;
== Description of vulnerability ==&lt;br /&gt;
The affected vulnerability concerns the authentication mechanism, which are older than IMPI-2.0 implementations. An attacker can send special prepared authentication requests and can therefore receive hash values from user passwords without successful authentication.&lt;br /&gt;
&lt;br /&gt;
Next, the hash values can be analyzed offline. Depending on the password quality, an attacker could use this to determine the actual login data. After successful login, the attacker gets access to all management functions of the BMC.&lt;br /&gt;
&lt;br /&gt;
The vulnerability itself does not allow direct access to the operating system, but it can allow the complete remote access to the server. &lt;br /&gt;
&lt;br /&gt;
== Affected systems ==&lt;br /&gt;
In general, servers whose BMC firmware implements the vulnerable authentication mechanism and whose IPMI interface is accessible from untrusted networks may be affected.&lt;br /&gt;
&lt;br /&gt;
The following are particularly relevant:&lt;br /&gt;
&lt;br /&gt;
* older server platforms&lt;br /&gt;
* not updated BMC firmware&lt;br /&gt;
* IPMI interfaces accessible from the public network&lt;br /&gt;
* systems with weak or reused passwords&lt;br /&gt;
&lt;br /&gt;
Whether a specific system is affected depends on the manufacturer, firmware version, and configuration.&lt;br /&gt;
&lt;br /&gt;
== Potential impact ==&lt;br /&gt;
A successful utilization may have the following consequences:&lt;br /&gt;
&lt;br /&gt;
* disclosure of password hashes&lt;br /&gt;
* offline attacks on user passwords&lt;br /&gt;
* complete access on the BMC&lt;br /&gt;
* remote console access&lt;br /&gt;
* turning systems on and off&lt;br /&gt;
* integration of virtual installation medium &lt;br /&gt;
* change of firmware configuration&lt;br /&gt;
* bypassing Operating System Security Mechanisms&lt;br /&gt;
&lt;br /&gt;
As the BMC operates independently of the host system, a lot of these opportunities remain in place even if the actual operating system is switched off.&lt;br /&gt;
&lt;br /&gt;
== Verification of the own infrastructure ==&lt;br /&gt;
Administrators should check&lt;br /&gt;
&lt;br /&gt;
* if IPMI interfaces are publicly available &lt;br /&gt;
* which firmware version is used&lt;br /&gt;
* if safety updates are available &lt;br /&gt;
* which user accounts are available&lt;br /&gt;
* if strong passwords should be used&lt;br /&gt;
* which networks should have access to the BMC.&lt;br /&gt;
&lt;br /&gt;
In addition, it is recommended to monitor the firewall rulesas well as the management networks on a regular basis.&lt;br /&gt;
&lt;br /&gt;
== Protective measures ==&lt;br /&gt;
The following measures are recommended to protect the system:&lt;br /&gt;
&lt;br /&gt;
* install latest BMC-firmware&lt;br /&gt;
* make IPMI accessible exclusively via internal management networks&lt;br /&gt;
* avoid public accessibility&lt;br /&gt;
* use strong individual passwords&lt;br /&gt;
* remove unused user accounts&lt;br /&gt;
* replace standard passwords&lt;br /&gt;
* restrict management accesses on confidential administrators&lt;br /&gt;
* use VPN or Jump Hosts for the remote access, if possible&lt;br /&gt;
&lt;br /&gt;
== Firmware updates ==&lt;br /&gt;
Multiple server manufacturers provide updated firmware versions that fix known vulnerabilities or implement additional protective measures. The respective release notes should be controlled before an update and the update is performed in accordance with the manufacturer&amp;#039;s recommendations.&lt;br /&gt;
&lt;br /&gt;
=== Updates for Thomas-Krenn products ===&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;Thomas-Krenn download area&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The versions in the download area have been tested by us to guarantee the stability and compatiblity of our systems. &lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you can get it at the respective manufacturer. &lt;br /&gt;
&lt;br /&gt;
== Conclusion == &lt;br /&gt;
The renewed attention for this vulnerability, that has been known for years, shows that management interfaces continue to be a frequently underestimated target for attacks. Independent from the age of the vulnerability, public available BMC or IPMI interfaces should be verified on a regular basis, operted with the latest firmware and available via secured management networks only.&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.thomas-krenn.com/de/wikiDE/index.php?title=IPMI_Sicherheitsupdates&amp;amp;xtxsearchselecthit=1 Thomas-Krenn Wiki: IPMI Safety Updates]&lt;br /&gt;
* [https://www.heise.de/news/Server-Fernwartung-24-650-Server-fuer-20-Jahre-alte-Luecke-anfaellig-11382232.html Remote Server Maintenance – 24.650 Server vulnerable for 20 year old vulnerability] (heise.de, July 2026)&lt;br /&gt;
* [https://www.golem.de/news/passwort-hashes-auslesbar-20-jahre-alte-bmc-luecke-gefaehrdet-ueber-24-000-server-2607-211397.html Passwort-Hashes readable – 20 year old BMC vulnerability puts more than 24,000 servers at risk]  (golem.de, July 2026)&lt;br /&gt;
&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Server Hardware]]&lt;br /&gt;
[[de:IPMI/BMC-Sicherheitslücke in älteren Implementierungen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Copy-on-Write_principle_in_ZFS</id>
		<title>Copy-on-Write principle in ZFS</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Copy-on-Write_principle_in_ZFS"/>
		<updated>2026-07-30T07:44:00Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Copy-on-Write&amp;#039;&amp;#039;&amp;#039; is an optimization principle of data processing in which changes are not made directly to the existing data set, but are always written to a new copy. As the cornerstone of the [[ZFS Basics|ZFS]] file system&amp;#039;s storage strategy, CoW, in combination with transaction groups, ensures that an interrupted write operation can never result in an inconsistent file system. This is why ZFS stands out from classic file systems that overwrite the data completely. &lt;br /&gt;
&lt;br /&gt;
== Copy-on-Write principle ==&lt;br /&gt;
For write operations based on the CoW principle, &amp;#039;&amp;#039;&amp;#039;data blocks are not overwritten when changes are made&amp;#039;&amp;#039;&amp;#039;. Instead, new data blocks are written with the changes, and the old data blocks are simply overwritten. To receive the consistency of the data, CoW works with a reference system that is also known as &amp;#039;&amp;#039;Hash-Tree&amp;#039;&amp;#039; (or &amp;#039;&amp;#039;Merkle-Tree&amp;#039;&amp;#039;)&amp;lt;ref&amp;gt;[https://en.wikipedia.org/wiki/Merkle_tree Merkle Tree] (en.wikipedia.org, 2026)&amp;lt;/ref&amp;gt;. With the help of this system it is ensured that errors in data integrity can be noticed all time. &lt;br /&gt;
&lt;br /&gt;
=== The tree structure ===&lt;br /&gt;
[[File:Zfs-merkletree.png|alt=Image 1: A simple Hash-tree.|thumb|1st image: A simple hash tree]]&lt;br /&gt;
In the first image, a simplified view of a hash tree is represented:&lt;br /&gt;
&lt;br /&gt;
* At the endpoints of the trees, that are also called &amp;#039;&amp;#039;leaves&amp;#039;&amp;#039;, the data blocks can be found.&lt;br /&gt;
* The nodes above, &amp;#039;&amp;#039;inner nodes&amp;#039;&amp;#039; or &amp;#039;&amp;#039;branches&amp;#039;&amp;#039;, include &amp;#039;&amp;#039;block pointers&amp;#039;&amp;#039;. Every of these &amp;#039;&amp;#039;pointers&amp;#039;&amp;#039; includes information on the underlying blocks, for example the physical location of the data, the size of blocks as well as the number of the transaction group (&amp;#039;&amp;#039;Birth-TXG&amp;#039;&amp;#039;), in which the block has been written to. The most important information, however, is the &amp;#039;&amp;#039;&amp;#039;check sum&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
* At the top level, the &amp;#039;&amp;#039;uberblock&amp;#039;&amp;#039; is located. This value is unique within a &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt; and is recalculated after every write operation. It includes the check sum from which can be used to verify all data contained in &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Application in transaction groups ===&lt;br /&gt;
ZFS stores the data in so-called &amp;#039;&amp;#039;transaction groups (txg)&amp;#039;&amp;#039; in the RAM of the system. After a determined timeline, the default setting is 5 seconds, or when enough data has been collected, all changes collected in the transaction group are committed simultaneously&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
With this procedure, it is ensured that an inconsistent data set is excluded by an interrupted writing process.&lt;br /&gt;
&lt;br /&gt;
Either the &amp;#039;&amp;#039;txg&amp;#039;&amp;#039; is committed:  Then a new &amp;quot;uberblock&amp;quot; was created, and the file system is now consistent. &lt;br /&gt;
&lt;br /&gt;
Or the &amp;#039;&amp;#039;txg&amp;#039;&amp;#039; has not been committed: In that case, the old &amp;quot;uberblock&amp;quot; is considered current, and the file system is also consistent (just older).&lt;br /&gt;
&lt;br /&gt;
== The writing process ==&lt;br /&gt;
[[File:Zfs-CoW.png|alt=|thumb|2nd image: After a writing process, the replaced blocks are released. The unchanged blocks remain untouched&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/Basic%20Concepts/Copy-on-write.html#transaction-groups Copy-on-Write in the OpenZFS Documentation] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;.]]&lt;br /&gt;
In the second image, the condition of the file system can be seen with Copy-on-Write after a writing process. The following steps have contributed to this result:&lt;br /&gt;
&lt;br /&gt;
# A change makes it necessary to replace the data in the block &amp;lt;code&amp;gt;D4&amp;lt;/code&amp;gt; &lt;br /&gt;
# A new block &amp;lt;code&amp;gt;D4&amp;#039;&amp;lt;/code&amp;gt; is created that includes the new data&lt;br /&gt;
# The new block should be included into the &amp;#039;&amp;#039;Hash&amp;#039;&amp;#039;-tree. For this, it is necessary to form a new &amp;lt;code&amp;gt;inode2&amp;lt;/code&amp;gt;, which is described with &amp;lt;code&amp;gt;inode2&amp;#039;&amp;lt;/code&amp;gt; here. This step is necessary, as the checksum must be recalculated for all parent nodes&lt;br /&gt;
# As described in step 3, &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;uberblock&amp;lt;/code&amp;gt; are also recreated&lt;br /&gt;
# The &amp;#039;&amp;#039;inner nodes&amp;#039;&amp;#039; are reconnected with the unchanged nodes and the check sums are reformed. The new data blocks are now integrated&lt;br /&gt;
&lt;br /&gt;
With the integration of the new data block, the old data block &amp;lt;code&amp;gt;D4&amp;lt;/code&amp;gt; was replaced and released, just like all parent nodes. As long as there is no &amp;#039;&amp;#039;snapshot&amp;#039;&amp;#039; that references the old block, it can be reused for future write operations.&lt;br /&gt;
&lt;br /&gt;
== Consequences of CoW-strategy ==&lt;br /&gt;
CoW gives rise to some of ZFS&amp;#039;s most important features as a logical consequence. However, this also highlights some of ZFS&amp;#039;s weaknesses. These are listed as advantages and disadvantages in the following.&lt;br /&gt;
&lt;br /&gt;
=== Advantages ===&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[[ZFS Snapshots|Snapshots]]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; –  in other words, snapshots of a system&amp;#039;s state - &amp;#039;&amp;#039;&amp;#039;can be simply created by CoW&amp;#039;&amp;#039;&amp;#039;. All you need to do is reference and freeze the &amp;quot;uberblock&amp;quot; and its underlying nodes and blocks.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Clones&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;can be also simply created&amp;#039;&amp;#039;&amp;#039;, as simple references can be used here as well. &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Incremental Duplication&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;is exactly&amp;#039;&amp;#039;&amp;#039;, as every block knows, in which transaction group it has been created. This allows ZFS to jump directly to the changed sections when comparing two snapshots, rather than checking each file individually.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Data corruption&amp;#039;&amp;#039; is traceable and often repairable&amp;#039;&amp;#039;&amp;#039;. Damaged blocks can be identified by verifying the check sums. If the file system has been built redundant, no damaged block can be recreated in most cases.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;lt;code&amp;gt;fsck&amp;lt;/code&amp;gt;&amp;#039;&amp;#039; is obsolete&amp;#039;&amp;#039;&amp;#039;, as CoW always ensures a consistant pool.&lt;br /&gt;
&lt;br /&gt;
=== Disadvantages ===&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Fragmentation&amp;#039;&amp;#039;&amp;#039; occurs&amp;#039;&amp;#039;.&amp;#039;&amp;#039; Every change is written into new blocks. As a result, even files that were originally written sequentially become fragmented. The fuller &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt; gets, the more difficult it gets to find sufficiently contiguous blocks for sequential writing processes.&lt;br /&gt;
* Free storage space is required at all times, because even during deletion operations, the blocks that were used are not deleted; instead, new nodes and blocks must be created.&lt;br /&gt;
* If only parts of a data set must be changed, it can be slow independent of the &amp;lt;code&amp;gt;recordsize&amp;lt;/code&amp;gt;, as the whole data set must be read. For a data set with &amp;lt;code&amp;gt;recordsize=128k&amp;lt;/code&amp;gt; in which 8 KB are to be modified, 128 KB must be read, 8 KB must be modified in memory, and the result must then be written back as a new 128-KB record.&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
[https://www.heise.de/select/ix/2017/2/1486040905020105 ZFS, Part 1: Concepts and basics from Michael Plura] (heise.de, 2017)&lt;br /&gt;
&lt;br /&gt;
[https://www.linux-magazin.de/ausgaben/2026/06/openzfs-2-4/ The Time Machine in Kernel Space: ZFS-Workflows on Ubuntu 24.04] (linux-magazin.de, 2026)&lt;br /&gt;
&lt;br /&gt;
[https://web.archive.org/web/20060428092023/http://www.sun.com/2004-0914/feature/ &amp;quot;ZFS: The last word in file systems.&amp;quot; by Jeff Bonwick] (web.archive.org, 2026)&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Sbohn}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[de:Copy-on-Write Prinzip in ZFS]]&lt;br /&gt;
[[Category:Storage]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Onboard_RAID_on_Supermicro_X12_Motherboards</id>
		<title>Onboard RAID on Supermicro X12 Motherboards</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Onboard_RAID_on_Supermicro_X12_Motherboards"/>
		<updated>2026-07-29T05:37:28Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article is about the topic Onboard RAID on X12 Supermicro [[:Category:Motherboards|Motherboards]]. It is explained how to create, administrate and delete a [[RAID]] in the BIOS. It also explains how Distributed PPL and Journaling Mode are used to counteract the [[RAID Write Hole]].&lt;br /&gt;
&lt;br /&gt;
== Setup ==&lt;br /&gt;
In the following, it is explained how to create an Onboard RAID in the BIOS of your motherboard and which modes you need to be aware of. &lt;br /&gt;
&lt;br /&gt;
=== Create RAID in the BIOS ===&lt;br /&gt;
&lt;br /&gt;
To create a RAID in the BIOS, you must first enter the BIOS. You can do this by pressing the &amp;quot;Del&amp;quot; key several times during the boot process.&lt;br /&gt;
The following images describe how to create a simple RAID 5 array. Please note that with the onboard RAID controller on Supermicro X12 motherboards, only RAID 0, 1, 5, and 10 can be created.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Advanced-Reiter.png|Use the arrow keys to navigate to the tab &amp;#039;&amp;#039;&amp;#039;Advanced&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:SATA and RSTe Configuration.png|Use the arrow keys to navigate to &amp;#039;&amp;#039;&amp;#039;SATA And RSTe Configuration&amp;#039;&amp;#039;&amp;#039; access this menu by clicking on &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:AHCI-Einstellung.png|Select the &amp;#039;&amp;#039;&amp;#039;SATA Mode Selection&amp;#039;&amp;#039;&amp;#039; option and change the mode from &amp;#039;&amp;#039;&amp;#039;AHCI&amp;#039;&amp;#039;&amp;#039; to &amp;#039;&amp;#039;&amp;#039;Intel RSTe Premium with Intel Optane System Acceleration.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
File:Controller im BIOS.png|Navigate back to the tab &amp;#039;&amp;#039;&amp;#039;Advanced&amp;#039;&amp;#039;&amp;#039;. Here, the  &amp;#039;&amp;#039;&amp;#039;Intel(R) VROC SATA Controller&amp;#039;&amp;#039;&amp;#039; is displayed. You can now configure this by pressing &amp;#039;&amp;#039;&amp;#039;Enter.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
File:Save changes and reset.png|Now use the arrow keys to navigate to the &amp;#039;&amp;#039;&amp;#039;Save &amp;amp; Exit&amp;#039;&amp;#039;&amp;#039; tab and select &amp;#039;&amp;#039;&amp;#039;Save Changes and Reset.&amp;#039;&amp;#039;&amp;#039; This will save your changes and restart the system. Enter the BIOS again during the restart..&lt;br /&gt;
File:Controller-BIOS.png|Navigate back to &amp;#039;&amp;#039;&amp;#039;Advanced&amp;#039;&amp;#039;&amp;#039; and select the onboard RAID controller. Here you will see the &amp;#039;&amp;#039;&amp;#039;Create RAID Volume&amp;#039;&amp;#039;&amp;#039; option, as well as the ports, names, and capacities of the connected storage devices. To create a RAID, select the &amp;#039;&amp;#039;&amp;#039;Create RAID Volume&amp;#039;&amp;#039;&amp;#039; option.&lt;br /&gt;
File:CreateRAIDvolume.png|This menu is used to create the RAID. Enter the desired &amp;#039;&amp;#039;&amp;#039;name&amp;#039;&amp;#039;&amp;#039; in the Name field. Under RAID Level, select the desired RAID level. In the &amp;#039;&amp;#039;&amp;#039;Select Disks&amp;#039;&amp;#039;&amp;#039; submenu, you can select the disks that will be part of the RAID array. &amp;#039;&amp;#039;&amp;#039;Strip Size&amp;#039;&amp;#039;&amp;#039; specifies the block size. Under &amp;#039;&amp;#039;&amp;#039;Capacity&amp;#039;&amp;#039;&amp;#039;, you can select the capacity. However, this field is filled in automatically once you have selected the disks. Then select &amp;#039;&amp;#039;&amp;#039;Create Volume&amp;#039;&amp;#039;&amp;#039; to create the RAID.&lt;br /&gt;
File:RAID übersicht.png|The RAID you created is now displayed under &amp;#039;&amp;#039;&amp;#039;RAID Volumes&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Delete RAID ===&lt;br /&gt;
&lt;br /&gt;
To delete a RAID, use the arrow keys to navigate back to the &amp;quot;Advanced&amp;quot; tab, then to the &amp;quot;[[Intel VROC (SATA RAID)|Intel(R) VROC]] SATA Controller&amp;quot; subitem. Now press Enter to access the controller menu. Then select the RAID you want to delete and press Enter again.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:RAID übersicht.png| Here, you can select the RAID you want to delete by clicking on &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:RAID Löschen.png|To delete the RAID, select the &amp;#039;&amp;#039;&amp;#039;Delete&amp;#039;&amp;#039;&amp;#039; option here.&lt;br /&gt;
File:RAID löschen Bestätigung.png|Confirm the deletion by selecting &amp;#039;&amp;#039;&amp;#039;Yes. Please note that all data on the deleted storage device will be lost after deletion. Therefore, please delete the RAID only if you are certain that you no longer need the data.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== RAID mode for parity RAID ===  &lt;br /&gt;
&lt;br /&gt;
The X12 series of Supermicro motherboards offers two different modes for configuring a RAID array with parity data. The explanation and configuration of the modes can be found in the following two paragraphs.&lt;br /&gt;
An advantage provide, however, both modes: With parity-based RAIDs (in the case of onboard RAIDs on X12 motherboards, this is limited to RAID 5), data is not lost if a power outage and a RAID drive failure occur simultaneously.&lt;br /&gt;
&lt;br /&gt;
==== Distributed PPL ====&lt;br /&gt;
&lt;br /&gt;
In the &amp;#039;&amp;#039;&amp;#039;Distributed PPL&amp;#039;&amp;#039;&amp;#039; version, the so-called &amp;#039;&amp;#039;&amp;#039;RAID Write Hole journal&amp;#039;&amp;#039;&amp;#039; is stored on all disks in the RAID array. This provides full protection against the RAID write hole, but there is a performance degradation during write-intensive tasks.&lt;br /&gt;
This kind of RAID can be easily created by selecting RAID 5 when creating the RAID and changing the &amp;#039;&amp;#039;&amp;#039;RWH Policy&amp;#039;&amp;#039;&amp;#039; from &amp;quot;Disable&amp;quot; to &amp;quot;Distributed PPL&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:1 Modus wählen.png|Here you can select the mode &amp;#039;&amp;#039;&amp;#039;Distributed PPL&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Journaling Mode ====&lt;br /&gt;
&lt;br /&gt;
In this variant, the &amp;#039;&amp;#039;&amp;#039;RAID Write Hole journal&amp;#039;&amp;#039;&amp;#039; is stored on an extra hard drive. This hard drive can only be used for this purpose. The data carrier is also &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; included in the RAID array. If you want to create a RAID 5 in &amp;#039;&amp;#039;&amp;#039;Journaling Mode&amp;#039;&amp;#039;&amp;#039;, instead of the usual three storage devices, four are required, since only the &amp;#039;&amp;#039;&amp;#039;RAID Write Hole journal&amp;#039;&amp;#039;&amp;#039; is stored on the fourth one. The performance degradation for write-intensive tasks depends on the performance of the storage device on which the RAID W/H journal is stored. However, the write speed is usually &amp;#039;&amp;#039;&amp;#039;faster&amp;#039;&amp;#039;&amp;#039; than in distributed mode. The journaling hard drive must be at least as large as the smallest hard drive in the RAID array.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Platte wählen.png|Select a hard drive on which the RAID W/H journal should be stored, and press &amp;#039;&amp;#039;&amp;#039;Enter.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
File:Markieren.png|Navigate to &amp;#039;&amp;#039;&amp;#039;Mark as Journaling Drive&amp;#039;&amp;#039;&amp;#039; and press &amp;#039;&amp;#039;&amp;#039;Enter&amp;#039;&amp;#039;&amp;#039;. Confirm the message that appears by selecting &amp;#039;&amp;#039;&amp;#039;Yes&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:RAIDerstellen.png|You can now create the RAID. Select RAID Level 5, then select the desired hard drives. You cannot select the hard drive marked as the journaling drive, as it is not part of the RAID array. Under &amp;#039;&amp;#039;&amp;#039;RWH Policy&amp;#039;&amp;#039;&amp;#039;, select &amp;#039;&amp;#039;&amp;#039;Journaling Drive&amp;#039;&amp;#039;&amp;#039;, and under &amp;#039;&amp;#039;&amp;#039;Select RWH Journaling Drive&amp;#039;&amp;#039;&amp;#039;, select the hard drive you previously designated as the journaling drive.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To stop configuring the hard drive as a spare drive, follow the steps described above, but this time select &amp;#039;&amp;#039;&amp;#039;Reset to non-RAID&amp;#039;&amp;#039;&amp;#039; instead of &amp;#039;&amp;#039;&amp;#039;Mark as Spare&amp;#039;&amp;#039;&amp;#039; and confirm by pressing Enter.&lt;br /&gt;
&lt;br /&gt;
== Administration ==&lt;br /&gt;
In the following, it is explained which options you have to administrate your Onboard RAID and how to remove hard drives from the RAID array.&lt;br /&gt;
&lt;br /&gt;
=== Configuration spare plate ===&lt;br /&gt;
&lt;br /&gt;
To administrate a RAID that has already been created, you have the opportunity to configure hard drives as &amp;#039;&amp;#039;&amp;#039;spare plates&amp;#039;&amp;#039;&amp;#039;. A spare plate is a hard drive, which is initially not in operation and takes over if a hard drive in the RAID array fails. The following series of images describes how this works.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Spare-Platte wählen.png|Select a desired hard drive to configure it as spare plate.&lt;br /&gt;
File:Spare-Markieren.png|Select &amp;#039;&amp;#039;&amp;#039;Mark as Spare&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:3 Bestätigen.png|Confirm the designation of the spare plate with &amp;#039;&amp;#039;&amp;#039;Yes&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The steps described must be performed that the hard drive is not configured as spare plate. However, select &amp;#039;&amp;#039;&amp;#039;Reset to non-RAID&amp;#039;&amp;#039;&amp;#039; instead of &amp;#039;&amp;#039;&amp;#039;Mark as Spare&amp;#039;&amp;#039;&amp;#039; and confirm with Enter.&lt;br /&gt;
&lt;br /&gt;
=== Remove hard drives from RAID array ===&lt;br /&gt;
&lt;br /&gt;
If you have too many hard drives in your RAID array and you want to delete one, perform the following steps. For this example, a RAID 5 array with 4 hard drives was created although 3 would be enough.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:RAIDwählen.png|Select the RAID array from which you want to remove the hard drive. &lt;br /&gt;
File:PlatteWählen.png|Select now the data carrier that should be removed from the RAID array.&lt;br /&gt;
File:ResetToNonRaid.png|Select here the option &amp;#039;&amp;#039;&amp;#039;Reset to non-RAID&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:Bestätigen.png|Confirm the removal by selecting &amp;#039;&amp;#039;&amp;#039;Yes&amp;#039;&amp;#039;&amp;#039; and pressing Enter. &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After a hard drive has been removed, the RAID is in &amp;#039;&amp;#039;&amp;#039;Degraded&amp;#039;&amp;#039;&amp;#039; mode. This means that the RAID still functions but no longer in optimal condition. Normally, this mode occurs, when the hard drive fails unexpectedly. In this case, it is recommended to change it and to start a rebuild.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:RaidWählen.png|Select the RAID, in which you want to start  the rebuild. &lt;br /&gt;
File:RebuildWählen.png|Select the option &amp;#039;&amp;#039;&amp;#039;Rebuild&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:RebuildPlatteWählen.png|Select the hard drive with which you want to start the rebuild. &lt;br /&gt;
File:RebuildBestätigen.png|Confirm with &amp;#039;&amp;#039;&amp;#039;Yes&amp;#039;&amp;#039;&amp;#039;, to start the rebuild.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Change RWH policy ===&lt;br /&gt;
&lt;br /&gt;
The above described &amp;#039;&amp;#039;&amp;#039;RWH Policy&amp;#039;&amp;#039;&amp;#039; can also be changed afterwards. To do this, go back to the &amp;#039;&amp;#039;&amp;#039;Controller BIOS&amp;#039;&amp;#039;&amp;#039; and select the desired RAID. Next, select the desired mode under the &amp;#039;&amp;#039;&amp;#039;RWH Policy&amp;#039;&amp;#039;&amp;#039; option.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Policy ändern.png|Here, you can change the desired mode. &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{tbiebl}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:RAID Controllers]]&lt;br /&gt;
[[de:Onboard RAID auf Supermicro X12 Mainboards]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Remove_a_Proxmox_node_from_the_cluster_and_add_it_again</id>
		<title>Remove a Proxmox node from the cluster and add it again</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Remove_a_Proxmox_node_from_the_cluster_and_add_it_again"/>
		<updated>2026-07-24T05:45:30Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article shows how to remove a node from a [https://www.thomas-krenn.com/de/wiki/Proxmox_VE?xtxsearchselecthit=1 Proxmox] Ceph cluster and, if necessary, add it back.  == Requirements ==  *  There must be no VMs or containers on the node to be removed. Therefore, it is recommended that you migrate them to another node beforehand (see the &amp;quot;Preparation&amp;quot; section for more information). * Please note that your cluster has enough free storage space to distribute the data o...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article shows how to remove a node from a [https://www.thomas-krenn.com/de/wiki/Proxmox_VE?xtxsearchselecthit=1 Proxmox] Ceph cluster and, if necessary, add it back.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
*  There must be no VMs or containers on the node to be removed. Therefore, it is recommended that you migrate them to another node beforehand (see the &amp;quot;Preparation&amp;quot; section for more information).&lt;br /&gt;
* Please note that your cluster has enough free storage space to distribute the data onto the remaining nodes&lt;br /&gt;
&lt;br /&gt;
== Preparations ==&lt;br /&gt;
===Migration of VMs &amp;amp; containers===&lt;br /&gt;
&lt;br /&gt;
Migrate all virtual machines and containers on any server. &amp;lt;gallery&amp;gt;&lt;br /&gt;
File:1 Migrate.png|Right-click the VM or container, then click &amp;#039;&amp;#039;&amp;#039;[Migrate]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:Bulk Migrate.png|Alternatively, you can also use the &amp;#039;&amp;#039;&amp;#039;[Bulk Migrate]&amp;#039;&amp;#039;&amp;#039; by right clicking on the node to migrate several at once. &lt;br /&gt;
File:2 Migrate.png|In this window, select the node to which the VM or CT should be migrated.&lt;br /&gt;
File:3 Migrate.png|In the following, click on &amp;#039;&amp;#039;&amp;#039;[Migrate]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:4 Migrate.png|The VM is migrated to the selected node.&lt;br /&gt;
File:5 Migrate.png|The VM/CT is now assigned in the overview to another node. Repeat this procedure until all VMs and containers are migrated. &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Delete OSDs ===&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:1 OSD löschen.png|Select &amp;#039;&amp;#039;&amp;#039;[Ceph] --&amp;gt; [OSD]&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
File:2 OSD löschen.png|Select an OSD of the node and click in the upper right corner on &amp;#039;&amp;#039;&amp;#039;[Out]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:3 OSD löschen.png|In the following, select the same OSD and click on &amp;#039;&amp;#039;&amp;#039;[Stop]&amp;#039;&amp;#039;&amp;#039; this time&amp;#039;&amp;#039;&amp;#039;.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
File:4 OSD löschen.png|The OSD should now be displayed as down/out.&lt;br /&gt;
File:5 OSD löschen.png|Now select the OSD again and choose &amp;#039;&amp;#039;&amp;#039;[More]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[Destroy]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[Remove]&amp;#039;&amp;#039;&amp;#039;. This will completely delete the OSD. Repeat this process for the remaining OSDs.&lt;br /&gt;
File:6 OSD löschen.png|After deleting the OSDs, the desired node should look like this.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Delete Monitor, Manager, MetaDataServer Daemons ===&lt;br /&gt;
To avoid later complications when creating different daemons, it is recommended to delete it before the node is removed. Please follow these steps:&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Proxmox Monitor löschen.png|In the overview, click on &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[Monitor]&amp;#039;&amp;#039;&amp;#039; and select the monitor that should be deleted. Next, click on &amp;#039;&amp;#039;&amp;#039;[Destroy]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:Proxmox Manager löschen.png|Follow the same order for the managers as well.&lt;br /&gt;
File:Proxmox MetaDataServer löschen.png|In the websurface, click on &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[CephFS]&amp;#039;&amp;#039;&amp;#039; and select the MetaDataServer. Next, click on &amp;#039;&amp;#039;&amp;#039;[Destroy]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Reading out name ===&lt;br /&gt;
Find the name of your node either in the GUI under the &amp;quot;Server View&amp;quot; or use these command in the CLI: &amp;#039;&amp;#039;&amp;quot;pvecm nodes&amp;quot;.&amp;#039;&amp;#039;The name of the server is required in the following step.&lt;br /&gt;
 root@PMX1:~# pvecm nodes&lt;br /&gt;
 &lt;br /&gt;
 Membership information&lt;br /&gt;
 ----------------------&lt;br /&gt;
     Nodeid      Votes Name&lt;br /&gt;
          1          1 &amp;#039;&amp;#039;&amp;#039;PMX1&amp;#039;&amp;#039;&amp;#039; (local)&lt;br /&gt;
          2          1 PMX2&lt;br /&gt;
          3          1 PMX3&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Remove cluster node==&lt;br /&gt;
First, connect using the IP address of another node to prevent the connection from being lost during removal. Next, you have to shut down the node that should be removed. Please make sure that the node does not turn back on (for example with Wake-On-LAN).&lt;br /&gt;
&lt;br /&gt;
In the following, you can enter the following command to remove the node from the cluster. Use the CLI of any other node for that. &lt;br /&gt;
 root@PMX2:~# pvecm delnode PMX1&lt;br /&gt;
 Killing node 1&lt;br /&gt;
 root@PMX2:~# &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Reinstallation &amp;amp; configuration of node==&lt;br /&gt;
&lt;br /&gt;
Now, it is important to know that the node can not be simply added back to the cluster, as a complete reinstallation must be performed. However, the previous configuration can also be used. Please note that the same PVE version is used as in the cluster. If you want to use another hardware, make sure that it is identical with the hardware of the remaining cluster nodes. &lt;br /&gt;
&lt;br /&gt;
Now, you can start the configuration of your new system. For this, the configuration of the network and the editing of the host entries is necessary. Helpful tips for the configuration can be found in the following documentation: [https://pve.proxmox.com/pve-docs/chapter-sysadmin.html Proxmox Dokumentation]&lt;br /&gt;
&lt;br /&gt;
== Cluster Join ==&lt;br /&gt;
Next, the node can be readded to the cluster.&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:1 Proxmox Cluster join.png|Connect to the cluster that should be joined by the node and go to &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[Cluster]&amp;#039;&amp;#039;&amp;#039; and click on &amp;#039;&amp;#039;&amp;#039;[Join Information]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:2 Proxmox Cluster join.png|Here, you can copy the Join information with a click on &amp;#039;&amp;#039;&amp;#039;[Copy Information].&amp;#039;&amp;#039;&amp;#039; After this, switch to the node that should be added. &lt;br /&gt;
File:3 Proxmox Cluster join.png|Here, go to &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[Cluster]&amp;#039;&amp;#039;&amp;#039; and click on &amp;#039;&amp;#039;&amp;#039;[Join Cluster]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:4 Proxmox Cluster join.png|Under &amp;#039;&amp;#039;&amp;#039;[Information]&amp;#039;&amp;#039;&amp;#039;, paste the Join information you copied earlier. You will also need the password and Link0 and Link1. These should be configured to match the cluster.&lt;br /&gt;
File:5 Proxmox Cluster join.png|Now, the node is added to the cluster. &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Ceph installation and configuration ==&lt;br /&gt;
The last step for the integration of a node into the cluster is the installation and configuration of Ceph on the newly added server.&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:1 Ceph Installation.png|Select the new node and click on &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; and perform the installation. &lt;br /&gt;
File:2 Ceph Installation.png|The configuration should be automatically applied to the other nodes.&lt;br /&gt;
File:3 Ceph Installation.png|Next, go to &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[Monitor]&amp;#039;&amp;#039;&amp;#039; click &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039; and recreate the monitor. &lt;br /&gt;
File:4 Ceph Installation.png|For the manager service, click on &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:5 Ceph Installation.png|To recreate the MDS, select &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; --&amp;gt; &amp;#039;&amp;#039;&amp;#039;[CephFS]&amp;#039;&amp;#039;&amp;#039; and click &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:6 Ceph Installation.png|Finally, you must create the OSDs under &amp;#039;&amp;#039;&amp;#039;[Ceph] --&amp;gt; [OSD].&amp;#039;&amp;#039;&amp;#039; You must use the same device class as you did for the other nodes.&lt;br /&gt;
File:7 Ceph Installation.png|The OSDs after creating them. &lt;br /&gt;
File:8 Ceph Installation.png|Ceph still needs some time to redistribute all the data. This may take a while.&lt;br /&gt;
File:9 Ceph Installation.png|After a short wait, everything should be back to normal.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Npauli}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Proxmox Administration]]&lt;br /&gt;
[[de:Proxmox Node aus Cluster entfernen und erneut hinzufügen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Windows_Server_Core_Licensing</id>
		<title>Windows Server Core Licensing</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Windows_Server_Core_Licensing"/>
		<updated>2026-07-23T11:36:39Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Windows Server Access Licenses(CAL) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Since &amp;#039;&amp;#039;&amp;#039;[[Windows Server 2016 Editionsunterschiede|Windows Server 2016]]&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;Microsoft&amp;#039;&amp;#039;&amp;#039; relies on &amp;#039;&amp;#039;&amp;#039;core licensing&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
In this article, all important information, that is required for the &amp;#039;&amp;#039;&amp;#039;licensing of Windows Server&amp;#039;&amp;#039;&amp;#039;, is included.&lt;br /&gt;
&lt;br /&gt;
It is possible to test the latest server version up to 180 days for free.&lt;br /&gt;
&lt;br /&gt;
A corresponding download can be found in [https://www.microsoft.com/de-de/evalcenter Microsoft Evaluation Center].&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;{{#widget:Imagebox-left|link={{#tklink:type=sitex|id=18135|linkonly=1}}|image=/de/wikiDE/images/9/99/WindowsServer2025-shoplink.png|text=Click here for our Microsoft software in the Thomas-Krenn online shop|campaign=Windows Server 2025 edition differences}} {{#widget:SitexBox|link={{#tklink:type=sitex|id=18135|linkonly=1}}|text=Click here for our Microsoft software in the Thomas-Krenn online shop|campaign=Windows Server 2025 edition differences}}&lt;br /&gt;
&lt;br /&gt;
==Windows Server licensing==&lt;br /&gt;
Since Windows server 2016, it must be distinguished between Essentials and Standard/Datacenter . Every system running a Windows Server instance must be licensed, whether it is physical or virtualized.&lt;br /&gt;
&lt;br /&gt;
===Windows Server Essentials===&lt;br /&gt;
For the Essentials Edition, the licensing model remains &amp;quot;per CPU / per server&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Essentials still has the limitation that a maximum of two CPUs may be installed.&lt;br /&gt;
&lt;br /&gt;
An Essentials license includes two CPUs. Therefore, only one Essentials license needs to be assigned per server.&lt;br /&gt;
&lt;br /&gt;
===Windows Server Standard and Datacenter===&lt;br /&gt;
For the Standard and Datacenter Edition, a &amp;#039;&amp;#039;&amp;#039;core licensing&amp;#039;&amp;#039;&amp;#039; is required. It must be noted how much active, physical kernels possesses a CPU.&lt;br /&gt;
&lt;br /&gt;
To obtain two virtual licenses for the Standard Edition and unlimited licenses for the Datacenter Edition, the following three rules must be observed:&lt;br /&gt;
&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Rule #1:&amp;#039;&amp;#039;&amp;#039; Every physical &amp;#039;&amp;#039;&amp;#039;processor&amp;#039;&amp;#039;&amp;#039; is scored based on &amp;#039;&amp;#039;&amp;#039;at least 8 cores&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Rule #2:&amp;#039;&amp;#039;&amp;#039; Every physical &amp;#039;&amp;#039;&amp;#039;server&amp;#039;&amp;#039;&amp;#039; is scored based on &amp;#039;&amp;#039;&amp;#039;at least 16 cores&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Rule #3:&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;All physical and active cores&amp;#039;&amp;#039;&amp;#039; must be licensed in accordance with Rule #1 and Rule #2&lt;br /&gt;
&lt;br /&gt;
If you want to increase virtualization rights for the Standard Edition, you must double the number of licenses for 4 VMs, triple them for 6 VMs, quadruple them for 8 VMs, and so on. &lt;br /&gt;
&lt;br /&gt;
==== Basis and additional licenses ====&lt;br /&gt;
There are so-called basis licenses and additional licenses. The basis licenses are available with 16 or 24 cores. Additional licenses are available with 2, 4 or 16 cores.&lt;br /&gt;
&lt;br /&gt;
The following chart shows that additional licenses are required only when there are 4 or more CPUs or more than 8 cores.&lt;br /&gt;
&lt;br /&gt;
[[file:Windows Server 2016 Core-Lizenzierung.png |900px]]&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;You are still unsure? No problem!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
In the [https://www.thomas-krenn.com/de/index.html Thomas-Krenn online shop], you do not need to worry about the core licensing yourself.&lt;br /&gt;
&lt;br /&gt;
Our online configurator automatically calculates the correct number of licenses, so that your new Windows server system is licensed correctly.&lt;br /&gt;
&lt;br /&gt;
If you have questions on the licensing, do not hesitate to contact us.&lt;br /&gt;
&lt;br /&gt;
==Software assurance==&lt;br /&gt;
Of course, you can also purchase software assurance for the new server operating system.&lt;br /&gt;
&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Did you know? Software assurance for OEM!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
: Within 90 days, you can buy a software assurance for your OEM Windows Server license&lt;br /&gt;
: An OEM license becomes a volume license when combined with software assurance. You have the same advantages as a volume license customer.&lt;br /&gt;
: Even after the SA expires, the OEM license remains a volume license, so you will continue to benefit from it.&lt;br /&gt;
&lt;br /&gt;
Benefits you can enjoy through software assurance:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;License mobility&amp;#039;&amp;#039;&amp;#039; - all 90 days right of reassignment of the license &lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;free upgrade to a new version of Windows Server&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
*Windows Virtual Desktop access licenses (VDA)&lt;br /&gt;
*and more...&amp;lt;ref&amp;gt;[https://download.microsoft.com/download/0/0/3/0039f316-45cf-4083-aa6e-c35da9d25c1b/sa_interactivebenefitschart.pdf Software Assurance] (www.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Windows Server Access Licenses(CAL)==&lt;br /&gt;
Windows Server Access Licenses - &amp;#039;&amp;#039;&amp;#039;CAL&amp;#039;&amp;#039;&amp;#039;s (&amp;#039;&amp;#039;&amp;#039;C&amp;#039;&amp;#039;&amp;#039;lient &amp;#039;&amp;#039;&amp;#039;A&amp;#039;&amp;#039;&amp;#039;ccess &amp;#039;&amp;#039;&amp;#039;L&amp;#039;&amp;#039;&amp;#039;icence) - are required for the access on systems with Windows Server operating system:&lt;br /&gt;
&lt;br /&gt;
For every user &amp;#039;&amp;#039;&amp;#039;or&amp;#039;&amp;#039;&amp;#039; every device, you require a CAL. If the user or the device accesses a Windows Server via remote desktop, a RDS-CAL is &amp;#039;&amp;#039;&amp;#039;required&amp;#039;&amp;#039;&amp;#039; additionally. &lt;br /&gt;
&lt;br /&gt;
CAL is tied to the &amp;#039;&amp;#039;&amp;#039;latest version&amp;#039;&amp;#039;&amp;#039; of Windows Server, which means that to license a user&amp;#039;s access to a Windows Server 2025, you need a Windows Server 2025 User CAL for that user.&lt;br /&gt;
&lt;br /&gt;
In this scenario, you must not use an older Windows Server CAL!&lt;br /&gt;
&lt;br /&gt;
All important information about the topic access licenses/CALs, can be found directly at Microsoft&amp;lt;ref&amp;gt;[https://www.microsoft.com/de-de/Licensing/produktlizenzierung/client-access-license.aspx Server-Access-License – Client Access License, CAL] (www.microsoft.com)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Did you know? There are OEM-CALs!&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;Every OEM-CAL (Windows-Server-CAL and RDS-CAL) allows the access on every Windows server, regardless of the manufacturer, regardless of whether the Windows Server was licensed through OEM or volume licensing.&lt;br /&gt;
&lt;br /&gt;
You can purchase additional OEM CALs at any time in the Thomas-Krenn online shop: &amp;lt;tklink type=sitex id=18135/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Downgrade right==&lt;br /&gt;
Every Windows Server license includes an &amp;#039;&amp;#039;&amp;#039;unlimited downgrade right&amp;#039;&amp;#039;&amp;#039;, whether OEM or volume licenses.&lt;br /&gt;
&lt;br /&gt;
With your Windows Server license, you have the right to install all underlying Windows Server versions and editions.&lt;br /&gt;
&lt;br /&gt;
With a Windows Server 2025 Standard license, for example, you may install Windows Server 2016 Standard or Windows Server 2019 Essentials, but not, for example, Windows Server 2019 Datacenter.&lt;br /&gt;
&lt;br /&gt;
To exercise this downgrade right, all you need is an installation medium as well as an installation product key (Windows key) of the operating system that should be installed.&lt;br /&gt;
&lt;br /&gt;
There are so-called &amp;#039;&amp;#039;&amp;#039;downgrade kits&amp;#039;&amp;#039;&amp;#039; that include these installation mediums as well as product keys. You can also purchase these directly from Thomas-Krenn.&lt;br /&gt;
&lt;br /&gt;
All important information on the downgrade topic can be found at Microsoft&amp;lt;ref&amp;gt; 	&lt;br /&gt;
[https://www.microsoft.com/OEM/de/licensing/sblicensing/Pages/downgrade_rights.aspx#fbid=APiJYEBPjyu Information on downgrade rights]  (www.microsoft.com)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
*[https://www.microsoft.com/licensing/guidance/Windows-Server-2025 Microsoft Licence Guide] (www.microsoft.com)&lt;br /&gt;
*[https://www.microsoft.com/en-us/cloud-platform/windows-server Windows Server] (EN) (www.microsoft.com)&lt;br /&gt;
*&amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;18135&amp;quot;&amp;gt;Windows Server 2025 Pricing Information&lt;br /&gt;
&amp;lt;/tklink&amp;gt; (www.thomas-krenn.com)&lt;br /&gt;
*[[Windows Server 2025 Editionsunterschiede|Windows Server 2025 Differences Between Editions]]  (www.wiki.thomas-krenn.com)&lt;br /&gt;
*[https://www.thomas-krenn.com/de/tkmag/webinare/windows-server-2025-lizenzierung-und-editionen/ Thomas-Krenn Webinar on Windows Server 2025 Licensing]] (www.thomas-krenn.com)&lt;br /&gt;
&lt;br /&gt;
{{aoberneder}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[pl:Model licencjonowania w oparciu o rdzenie w Windows Server 2016]]&lt;br /&gt;
[[de:Windows Server Core-Lizenzierung]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows Server 2019]]&lt;br /&gt;
[[Category:Windows Server 2022]]&lt;br /&gt;
[[Category:Windows Server 2025]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Administration_of_RAID_with_MDADM</id>
		<title>Administration of RAID with MDADM</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Administration_of_RAID_with_MDADM"/>
		<updated>2026-07-23T07:14:17Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;This article includes the general procedure of creating and administrating an array with MDADM.&amp;#039;&amp;#039;&amp;#039;  MDAMD (multiple disk administration) is a program that helps with the administration of a Software RAID in Linux. With this program, RAID-arrays can be created, configured, monitored and deleted. MDADM is released as free software under the GNU General Public License (GPL).  MDADM creates so-called multiple devices (short MD) from different block devices (such as an ent...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;This article includes the general procedure of creating and administrating an array with MDADM.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
MDAMD (multiple disk administration) is a program that helps with the administration of a Software RAID in Linux.&lt;br /&gt;
With this program, RAID-arrays can be created, configured, monitored and deleted.&lt;br /&gt;
MDADM is released as free software under the GNU General Public License (GPL).&lt;br /&gt;
&lt;br /&gt;
MDADM creates so-called multiple devices (short MD) from different block devices (such as an entire hard drive, a single partition, or a USB flash drive)&lt;br /&gt;
&lt;br /&gt;
MDADM is a practical software RAID solution that can be actively developed. &lt;br /&gt;
It allows simultaneous, parallel access to all disks.&lt;br /&gt;
In addition, the arrays created are hardware-independent, which significantly enhances data security.&lt;br /&gt;
&lt;br /&gt;
== Possible RAID levels ==&lt;br /&gt;
&lt;br /&gt;
*Linear: Chaining of multiple parities &lt;br /&gt;
*Multipath: No RAID, but mapping of a file on two different paths on the same partition (mirroring). &lt;br /&gt;
*Faulty: Emulates a faulty RAID system for test cases. &lt;br /&gt;
*Level 0 (Block Level Striping): Chaining multiple small block devices together to form one large one.&lt;br /&gt;
*Level 1 (Mirror): Mirroring of a disk &lt;br /&gt;
*Level 4: Like level 0, but with an additional device for parity bit (increased reliability). &lt;br /&gt;
*Level 5: Like level 4, the parity bits are distributed across all devices.&lt;br /&gt;
*Level 6: However, like level 5, it uses two independent parity bits per segment (increased reliability).&lt;br /&gt;
*Level 10: Combination of level 0 and 1. &lt;br /&gt;
&lt;br /&gt;
== Installation of mdadm ==&lt;br /&gt;
&lt;br /&gt;
If RAID was not set up during the Linux installation, you must install the mdadm package from the repositories.&lt;br /&gt;
&amp;lt;pre&amp;gt;:~$ sudo aptitude install mdadm&amp;lt;/pre&amp;gt;&lt;br /&gt;
After the installation, there are no further steps required for the configuration and the tool can be used. &lt;br /&gt;
&lt;br /&gt;
== Commands for configuration and administration == &lt;br /&gt;
&lt;br /&gt;
=== Basic syntax === &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mdadm [mode] &amp;lt;raiddevice&amp;gt; [options] &amp;lt;component-devices&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create array === &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mdadm --create /dev/md/&amp;lt;Label&amp;gt; --level=&amp;lt;RAID-Level&amp;gt; --raid-devices=&amp;lt;number of physical partitions in the array&amp;gt; /dev/sdX1 /dev/sdY1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Parameter:&lt;br /&gt;
* &amp;lt;code&amp;gt;--create&amp;lt;/code&amp;gt; An optional parameter can be specified to set a label for the RAID. For example: &amp;lt;code&amp;gt;/dev/md/md_1&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;--level=&amp;lt;/code&amp;gt;: Specifies the desired RAID level. Valid entries are  &amp;lt;code&amp;gt;linear, raid0, 0, stripe, raid1, 1, mirror, raid4, 4, raid5, 5, raid6, 6, raid10, 10, multipath, mp, faulty, container&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;--raid-devices=&amp;lt;/code&amp;gt;: Specifies the number of physical partitions in the software RAID. In addition, the individual partitions must be stated. For example: &amp;lt;code&amp;gt;--raid-devices=2 /dev/sda2 /dev/sdb3&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== RAID 0 with MDADM ====&lt;br /&gt;
To create a RAID 0 (Block Level Striping) array, at least 2 partitions are required. They should be the same size and located on different physical hard drives. &lt;br /&gt;
The RAID 0 array can be initialized with the following command: &amp;lt;code&amp;gt;mdadm --create /dev/md/&amp;lt;Label&amp;gt; --level=0 --raid-devices=&amp;lt;Anzahl&amp;gt; /dev/sdX1 /dev/sdY1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example (2 physical hard drives):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:~# mdadm --create /dev/md/md_test --level=0 --raid-devices=2 /dev/sdb1 /dev/sdc1 &lt;br /&gt;
mdadm: Defaulting to version 1.2 metadata&lt;br /&gt;
mdadm: array /dev/md/md_test started.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== RAID 1 with MDADM ====&lt;br /&gt;
To create a RAID 1 (Block Level Mirroring) array, at least two physical partitions are required. They should be the same size and located on different physical hard drives.&lt;br /&gt;
The RAID 1 array can be initialized with the following command: &amp;lt;code&amp;gt;mdadm --create /dev/md/&amp;lt;Label&amp;gt; --level=1 --raid-devices=&amp;lt;number&amp;gt; /dev/sdX1 /dev/sdY1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example (2 physical hard drives):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/dev# mdadm --create /dev/md/md_test --level=1 --raid-devices=2 /dev/sdb1 /dev/sdc1 &lt;br /&gt;
mdadm: Note: this array has metadata at the start and&lt;br /&gt;
    may not be suitable as a boot device.  If you plan to&lt;br /&gt;
    store &amp;#039;/boot&amp;#039; on this device please ensure that&lt;br /&gt;
    your boot-loader understands md/v1.x metadata, or use&lt;br /&gt;
    --metadata=0.90 &lt;br /&gt;
Continue creating array? yes&lt;br /&gt;
mdadm: Defaulting to version 1.2 metadata&lt;br /&gt;
mdadm: array /dev/md/md_test started.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Delete array ===&lt;br /&gt;
To remove a RAID array, the array must be unmounted (&amp;lt;code&amp;gt;umount&amp;lt;/code&amp;gt;) and the command &amp;lt;code&amp;gt; mdadm --stop /dev/md/&amp;lt;name of RAID&amp;gt;&amp;lt;/code&amp;gt; must be called up. Although this unmounts the array from the system, the RAID array remains physically in place.&lt;br /&gt;
&lt;br /&gt;
To remove the array, the superblock of every hard drive, which determines the hard drive/partition as RAID-device, must be set to 0. This can be performed with the command &amp;lt;code&amp;gt; mdadm --zero-superblock /dev/&amp;lt;physical partition&amp;gt;&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/dev# umount -l /mnt/test&lt;br /&gt;
root@swraid:/dev# mdadm --stop /dev/md/md_test&lt;br /&gt;
mdadm: stopped /dev/md/md_test&lt;br /&gt;
root@swraid:/dev# mdadm --zero-superblock /dev/sdb1&lt;br /&gt;
root@swraid:/dev# mdadm --zero-superblock /dev/sdc1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Listing arrays/partitions ===&lt;br /&gt;
RAID-arrays can be listed with two kinds of commands. &amp;lt;code&amp;gt;--detail&amp;lt;/code&amp;gt; refers to a completely active array, while &amp;lt;code&amp;gt;--examine&amp;lt;/code&amp;gt; refers to the individual physical devices in a RAID array.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/mnt/test# mdadm --examine --brief --scan  --config=partitions&lt;br /&gt;
ARRAY /dev/md/md_test metadata=1.2 UUID=81c1d8e5:27f6f8b9:9cdc99e6:9d92a1cf name=swraid:md_test&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
This command can also be abbreviated with &amp;lt;code&amp;gt;-Ebsc partitions&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/dev/md# mdadm --detail /dev/md/md_test &lt;br /&gt;
/dev/md/md_test:&lt;br /&gt;
        Version : 1.2&lt;br /&gt;
  Creation Time : Fri Jul  5 09:14:36 2013&lt;br /&gt;
     Raid Level : raid0&lt;br /&gt;
     Array Size : 16776192 (16.00 GiB 17.18 GB)&lt;br /&gt;
   Raid Devices : 2&lt;br /&gt;
  Total Devices : 2&lt;br /&gt;
    Persistence : Superblock is persistent&lt;br /&gt;
&lt;br /&gt;
    Update Time : Fri Jul  5 09:14:36 2013&lt;br /&gt;
          State : clean &lt;br /&gt;
 Active Devices : 2&lt;br /&gt;
Working Devices : 2&lt;br /&gt;
 Failed Devices : 0&lt;br /&gt;
  Spare Devices : 0&lt;br /&gt;
&lt;br /&gt;
     Chunk Size : 512K&lt;br /&gt;
&lt;br /&gt;
           Name : swraid:md_test  (local to host swraid)&lt;br /&gt;
           UUID : 81c1d8e5:27f6f8b9:9cdc99e6:9d92a1cf&lt;br /&gt;
         Events : 0&lt;br /&gt;
&lt;br /&gt;
    Number   Major   Minor   RaidDevice State&lt;br /&gt;
       0       8       17        0      active sync   /dev/sdb1&lt;br /&gt;
       1       8       33        1      active sync   /dev/sdc1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Hotspare ===&lt;br /&gt;
Hotspare hard drives/partitions are hard drives/partitions that are not normally used. These are used when one of the active hard drives or partitions in the RAID array has an error or is defective. If no hot spare disk is defined in a software RAID, the rebuild of a failed RAID array must be started manually. If a Hotspare is available, it is automatically started with the rebuild. A Hotspare hard drive can be added with the command &amp;lt;code&amp;gt; mdadm --add /dev/md/&amp;lt;RAID-name&amp;gt; /dev/sdX1&amp;lt;/code&amp;gt;, where the first parameter is the name of the RAID array and the second is the name of the hard drive to be added. If a Hotspare hard drive should be removed from the RAID array, the command &amp;lt;code&amp;gt;mdadm --remove /dev/md/&amp;lt;RAID-name&amp;gt; /dev/sdX1&amp;lt;/code&amp;gt; must be called up. Here, the first parameter is the name of the RAID array, and the second is the name of the hot spare hard drive.&lt;br /&gt;
&lt;br /&gt;
=== Rebuild ===&lt;br /&gt;
If a partition or hard drive has a defect (software or hardware), the RAID array must be rebuilt. To do this, the defect device must be removed from the RAID. The command &amp;lt;code&amp;gt;mdadm --manage /dev/md/&amp;lt;RAID-name&amp;gt; -r /dev/sdX1&amp;lt;/code&amp;gt; is required for this. The first parameter refers to the RAID array. The second to the defect device. If there is no Hotspare hard drive available, a new hard drive must be partitioned. It is important that the new hard drive has the same partition as the defect one. The tools &amp;lt;code&amp;gt;fdisk /dev/sdX&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;cfdisk /dev/sdX1&amp;lt;/code&amp;gt; as well as &amp;lt;code&amp;gt;parted /dev/sdX1&amp;lt;/code&amp;gt; help with the partition of a hard drive. &lt;br /&gt;
If the new hard drive is partitioned correctly, it can be added to the RAID array. This can be made with &amp;lt;code&amp;gt;mdadm --manage /dev/md/&amp;lt;RAID-Name&amp;gt; -a /dev/sdX1&amp;lt;/code&amp;gt;. If no errors occurred during this process, you can begin the actual rebuild. For this, the new partition must be set to &amp;quot;faulty&amp;quot; in the RAID array: &amp;lt;code&amp;gt;mdadm --manage --set-faulty /dev/md/&amp;lt;RAID-name&amp;gt; /dev/sdX1&amp;lt;/code&amp;gt;. This triggers the rebuild of the RAID array.&lt;br /&gt;
With &amp;lt;code&amp;gt;watch cat /proc/mdstat&amp;lt;/code&amp;gt;, the progress of the rebuild can be tracked. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Every 2.0s: cat /proc/mdstat                                                         Fri Jul  5 09:59:16 2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
root@swraid:/dev# watch cat /proc/mdstat &lt;br /&gt;
Personalities : [raid0] [raid1]&lt;br /&gt;
md127 : active raid1 sdc1[1] sdb1[0]&lt;br /&gt;
      8384448 blocks super 1.2 [2/2] [UU]&lt;br /&gt;
      [==============&amp;gt;......]  check = 74.7% (6267520/8384448) finish=0.1min speed=202178K/sec&lt;br /&gt;
&lt;br /&gt;
unused devices: &amp;lt;none&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
As soon as the rebuild of the RAID compound has been completed, the partition must be removed from the RAID array and added again to remove the status &amp;quot;faulty&amp;quot;. &amp;lt;code&amp;gt; mdadm --manage /dev/md/&amp;lt;RAID-name&amp;gt; -r /dev/sdX1&amp;lt;/code&amp;gt; for removing and &amp;lt;code&amp;gt;mdadm --manage /dev/md/&amp;lt;RAID-name&amp;gt; -a /dev/sdX1&amp;lt;/code&amp;gt; for adding. &lt;br /&gt;
With the command &amp;lt;code&amp;gt;mdadm --detail /dev/md/&amp;lt;RAID-name&amp;gt; &amp;lt;/code&amp;gt;, the status of the RAID array can be verified again. This should now have the &amp;#039;&amp;#039;&amp;#039;State: clean&amp;#039;&amp;#039;&amp;#039; status.&lt;br /&gt;
&lt;br /&gt;
=== Set up email address for array monitoring ===&lt;br /&gt;
&lt;br /&gt;
To receive an email notification in the event of a failure, you can enter the desired email address in the mdadm configuration file (&amp;lt;code&amp;gt;/etc/mdadm/mdadm.conf&amp;lt;/code&amp;gt;) under &amp;lt;code&amp;gt;MAILADDR root&amp;lt;/code&amp;gt; instead of &amp;#039;&amp;#039;root&amp;#039;&amp;#039;.&lt;br /&gt;
For this, an email service (&amp;lt;code&amp;gt;postfix, exim, ...&amp;lt;/code&amp;gt;) must be configured on the system.&lt;br /&gt;
Open &amp;#039;&amp;#039;&amp;#039;/etc/mdadm/mdadm.conf&amp;#039;&amp;#039;&amp;#039; with an editor and edit the following line:&lt;br /&gt;
&lt;br /&gt;
Instead of &amp;lt;code&amp;gt;MAILADDR root&amp;lt;/code&amp;gt;, enter an email address such as &amp;lt;code&amp;gt;MAILADDR email@example.com&amp;lt;/code&amp;gt; and save it.&lt;br /&gt;
&lt;br /&gt;
=== Verify array ===&lt;br /&gt;
The tool &amp;lt;code&amp;gt;checkarray&amp;lt;/code&amp;gt; is required to conduct continuous monitoring. This can be added to the list of Cronjobs with &amp;lt;code&amp;gt;crontab -e&amp;lt;/code&amp;gt;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/mdadm/checkarray --cron --all --quiet&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Sstrassner}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Software RAID]]&lt;br /&gt;
[[de:Software RAID mit MDADM verwalten]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/IPMI_configuration_for_Supermicro_servers_with_ipmicfg</id>
		<title>IPMI configuration for Supermicro servers with ipmicfg</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/IPMI_configuration_for_Supermicro_servers_with_ipmicfg"/>
		<updated>2026-07-22T12:18:28Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes the tool ipmicfg for Supermicro systems. Alternatively, when the server is operated on Linux, the ipmitool (see article [[Configuring IPMI under Linux using ipmitool|Configuring IPMI on Linux using ipmitool]]) or [[FreeIPMI]] can also be used. Older systems could be also interesting for the tools IPnMAC and XGICFG. Information can be found in the article [[IPMI_Konfiguration_f%C3%BCr_Supermicro_Systeme|IPMI Configuration for Supermicro Systems]]&lt;br /&gt;
&lt;br /&gt;
If there are problems with the configuration, it may be because the required modules have not been loaded. Please take the following article into consideration: [[IPMI Init Script für Debian|IPMI Init Script for Debian]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Basic configuration ==&lt;br /&gt;
[[file:Supermicro-IPMICFG-Windows-version-1.03-Build-110420.png|thumb|right|250px|Screenshot ipmicfg.exe on Windows]]&lt;br /&gt;
IPMICFG version 1.02 (Build 120820) provides the following options:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@test:~# ./ipmicfg-linux.x86_64.static &lt;br /&gt;
&lt;br /&gt;
IPMICFG Version 1.14.3 (Build 130725)&lt;br /&gt;
Copyright 2013 Super Micro Computer, Inc.&lt;br /&gt;
Usage: IPMICFG params (Example: IPMICFG -m 192.168.1.123)&lt;br /&gt;
  -m                    Show IP and MAC.&lt;br /&gt;
  -m IP                 Set IP (format: ###.###.###.###).&lt;br /&gt;
  -a MAC                Set MAC (format: ##:##:##:##:##:##).&lt;br /&gt;
  -k                    Show Subnet Mask.&lt;br /&gt;
  -k Mask               Set Subnet Mask (format: ###.###.###.###).&lt;br /&gt;
  -dhcp                 Get the DHCP status.&lt;br /&gt;
  -dhcp on              Enable the DHCP.&lt;br /&gt;
  -dhcp off             Disable the DHCP.&lt;br /&gt;
  -g                    Show Gateway IP.&lt;br /&gt;
  -g IP                 Set Gateway IP (format: ###.###.###.###).&lt;br /&gt;
  -r                    BMC cold reset.&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -garp on              Enable the Gratuitous ARP.&lt;br /&gt;
  -garp off             Disable the Gratuitous ARP.&lt;br /&gt;
  -fd                   Reset to the factory default.&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -fdl                  Reset to the factory default. (Clean LAN)&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -fde                  Reset to the factory default. (Clean FRU &amp;amp; LAN)&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -ver                  Get Firmware revision.&lt;br /&gt;
  -vlan                 Get VLAN status.&lt;br /&gt;
  -vlan on &amp;lt;VLANtag&amp;gt;    Enable the VLAN and set the VLAN tag.&lt;br /&gt;
                        If VLANtag is not given it uses previously saved value.&lt;br /&gt;
  -vlan off             Disable the VLAN.&lt;br /&gt;
  -selftest             Checking and reporting on the basic health of BMC.&lt;br /&gt;
  -raw                  Send a RAW IPMI request and print response.&lt;br /&gt;
                        Format: NetFn Cmd [Data1 ... DataN]&lt;br /&gt;
  -fru info             Show FRU inventory area Info.&lt;br /&gt;
  -fru list             Show all FRU values.&lt;br /&gt;
  -fru cthelp           Show chassis type code.&lt;br /&gt;
  -fru help             Show help of FRU Write.&lt;br /&gt;
  -fru &amp;lt;Field&amp;gt;          Show FRU field value.&lt;br /&gt;
  -fru &amp;lt;Field&amp;gt; &amp;lt;Value&amp;gt;  Write FRU.&lt;br /&gt;
  -fru 1m               Update FRU Product Manufacturer from DMITable.&lt;br /&gt;
  -fru 1p               Update FRU Product Prodcut Name from DMITable.&lt;br /&gt;
  -fru 1s               Update FRU Product S/N from DMITable.&lt;br /&gt;
  -fru 2m               Update FRU Board Manufacturer from DMITable.&lt;br /&gt;
  -fru 2p               Update FRU Board Product Name from DMITable.&lt;br /&gt;
  -fru 2s               Update FRU Board S/N from DMITable.&lt;br /&gt;
  -fru 3s               Update FRU Chassis S/N from DMITable.&lt;br /&gt;
  -fru backup &amp;lt;file&amp;gt;    Backup FRU to file &amp;lt;Binary format&amp;gt;.&lt;br /&gt;
  -fru restore &amp;lt;file&amp;gt;   Restore FRU from file &amp;lt;Binary format&amp;gt;.&lt;br /&gt;
  -fru tbackup &amp;lt;file&amp;gt;   Backup FRU to file &amp;lt;Text format&amp;gt;.&lt;br /&gt;
  -fru trestore &amp;lt;file&amp;gt;  Restore FRU from file &amp;lt;Text format&amp;gt;.&lt;br /&gt;
  -fru ver &amp;lt;V1&amp;gt; &amp;lt;V2&amp;gt;    Get/Set FRU version. (V1 V2 are BCD format)&lt;br /&gt;
  -sel info             Show SEL info.&lt;br /&gt;
  -sel list             Show SEL records.&lt;br /&gt;
  -sel del              Delete all SEL records.&lt;br /&gt;
  -sel raw              Show SEL raw data.&lt;br /&gt;
  -sdr                  Show SDR records and reading.&lt;br /&gt;
  -sdr del &amp;lt;SDR ID&amp;gt;     Delete SDR record.&lt;br /&gt;
  -sdr ver &amp;lt;V1&amp;gt; &amp;lt;V2&amp;gt;    Get/Set SDR version. (V1 V2 are BCD format)&lt;br /&gt;
  -nm nmsdr             Display NM SDR.&lt;br /&gt;
  -nm seltime           Get SEL time.&lt;br /&gt;
  -nm deviceid          Get ME Device ID.&lt;br /&gt;
  -nm reset             Reboots ME.&lt;br /&gt;
  -nm reset2default     Force ME reset to Default.&lt;br /&gt;
  -nm updatemode        Force ME to Update Mode.&lt;br /&gt;
  -nm selftest          Get Self Test Results.&lt;br /&gt;
  -nm listimagesinfo    List ME Images information.&lt;br /&gt;
  -nm oemgetpower       OEM Power command for ME.&lt;br /&gt;
  -nm oemgettemp        OEM Temp. command for ME.&lt;br /&gt;
  -nm pstate            Get Max allowed CPU P-State.&lt;br /&gt;
  -nm tstate            Get Max allowed CPU T-State.&lt;br /&gt;
  -nm cpumemtemp        Get CPU/Memory temperature.&lt;br /&gt;
  -nm hostcpudata       Get host CPU data.&lt;br /&gt;
  -fan                  Get Fan Mode.&lt;br /&gt;
  -fan &amp;lt;mode&amp;gt;           Set Fan Mode.&lt;br /&gt;
  -pminfo               Power supply PMBus health.&lt;br /&gt;
  -psfruinfo            Power supply FRU health.&lt;br /&gt;
  -psbbpinfo            Battery backup power status.&lt;br /&gt;
  -autodischarge &amp;lt;module&amp;gt; &amp;lt;day&amp;gt;   Set auto discharge by days.&lt;br /&gt;
  -discharge &amp;lt;module&amp;gt;   Manually discharge battery.&lt;br /&gt;
  -user list            List user privilege information.&lt;br /&gt;
  -user help            Show user privilege code.&lt;br /&gt;
  -user add &amp;lt;user id&amp;gt; &amp;lt;user name&amp;gt; &amp;lt;password&amp;gt; &amp;lt;privilege&amp;gt;&lt;br /&gt;
                        Add user.&lt;br /&gt;
  -user del &amp;lt;user id&amp;gt;   Delete user.&lt;br /&gt;
  -user level &amp;lt;user id&amp;gt; &amp;lt;privilege&amp;gt;  Update user privilege.&lt;br /&gt;
  -user setpwd &amp;lt;user id&amp;gt; &amp;lt;password&amp;gt;  Update user password.&lt;br /&gt;
  -conf upload &amp;lt;file&amp;gt; &amp;lt;option&amp;gt;       Upload IPMI configuration form binary file.&lt;br /&gt;
                        option: -p | Bypass warning message.&lt;br /&gt;
  -conf download &amp;lt;file&amp;gt;              Download IPMI configuration to binary file.&lt;br /&gt;
  -conf tupload &amp;lt;file&amp;gt; &amp;lt;option&amp;gt;      Upload IPMI configuration from text file.&lt;br /&gt;
                        option: -p | Bypass warning message.&lt;br /&gt;
  -conf tdownload &amp;lt;file&amp;gt;             Download IPMI configuration to text file.&lt;br /&gt;
  -clrint               Clear chassis intrusion.&lt;br /&gt;
root@test:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To configure the IPMI module for the first time, it is necessary to state the IP address through which the IPMI module should be accessible.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -m ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, the IPMI module is available via web interface.&lt;br /&gt;
&lt;br /&gt;
== Factory default settings ==&lt;br /&gt;
To set the IPMI module on the default settings, please enter&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -fd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please note that all settings, including all users, are deleted. Furthermore, the DHCP server is switched on after reset.&lt;br /&gt;
&lt;br /&gt;
== Problems with Offset Sensor Readings ==&lt;br /&gt;
Under certain circumstances, some sensor readings may be incorrect or may not be read at all.&lt;br /&gt;
To solve the issue, the following steps must be performed:&lt;br /&gt;
&lt;br /&gt;
[[Correcting Faulty IPMI Sensors by Fully Initializing the IPMI Module]]&lt;br /&gt;
&lt;br /&gt;
== Command reference ==&lt;br /&gt;
=== Display IP and MAC address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -m&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set IP address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -m ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MAC address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -a ##:##:##:##:##:##&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Display Subnet mask ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Subnet mask ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -k ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Switch on DHCP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -dhcp on&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Switch off DHCP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -dhcp off&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Display Gateway IP address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -g&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Gateway IP address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -g ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== BMC Cold Reset ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -r&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Recreate default settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -fd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable the Gratuitous ARP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -garp on&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable the Gratuitous ARP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -garp off&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Download ipmicfg ==&lt;br /&gt;
&lt;br /&gt;
If the ipmicfg is not yet installed on the system, it can be downloaded via  [https://www.thomas-krenn.com/de/download.html Thomas-Krenn download area]. For this, select the specific mainboard.&lt;br /&gt;
&lt;br /&gt;
At Supermicro, it is available here:&lt;br /&gt;
* ftp://ftp.supermicro.com/utility/IPMICFG/&lt;br /&gt;
&lt;br /&gt;
{{Bbayer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:IPMI]]&lt;br /&gt;
[[de:IPMI Konfiguration für Supermicro Server mittels ipmicfg]]&lt;br /&gt;
[[pl:Konfiguracja IPMI w serwerach Supermicro za pomocą ipmicfg]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/ZFS_basics</id>
		<title>ZFS basics</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/ZFS_basics"/>
		<updated>2026-07-22T09:28:13Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;ZFS&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;Pseudo-acronym&amp;#039;&amp;#039;, short for &amp;#039;&amp;#039;Zettabyte File System&amp;#039;&amp;#039;) is a &amp;#039;&amp;#039;&amp;#039;file system&amp;#039;&amp;#039;&amp;#039; that has been originally developed by Sun Microsystems for the operating system Solaris. The OpenZFS project develops an Open-Source variant&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/index.html OpenZFS Documentation] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;. ZFS distinguishes itself from other file systems through its focus on data integrity, storage capacity, and the management...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;ZFS&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;Pseudo-acronym&amp;#039;&amp;#039;, short for &amp;#039;&amp;#039;Zettabyte File System&amp;#039;&amp;#039;) is a &amp;#039;&amp;#039;&amp;#039;file system&amp;#039;&amp;#039;&amp;#039; that has been originally developed by Sun Microsystems for the operating system Solaris. The OpenZFS project develops an Open-Source variant&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/index.html OpenZFS Documentation] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;. ZFS distinguishes itself from other file systems through its focus on data integrity, storage capacity, and the management of physical drives within a logical device pool. &lt;br /&gt;
&lt;br /&gt;
== Basic function == &lt;br /&gt;
The main focus of ZFS is on &amp;#039;&amp;#039;&amp;#039;data integrity&amp;#039;&amp;#039;&amp;#039;. To ensure this data integrity, ZFS relies on a &amp;#039;&amp;#039;&amp;#039;transactional&amp;#039;&amp;#039;&amp;#039; approach. This means that writing processes are always completely performed or never&amp;lt;ref&amp;gt;[https://docs.oracle.com/cd/E19120-01/open.solaris/817-2271/gaypi/index.html Transactional Semantics] (docs.oracle.com, 2026)&amp;lt;/ref&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
A simple, asynchron writing process collects or buffers data for a determined period in a so-called &amp;#039;&amp;#039;&amp;#039;transaction group (TXG)&amp;#039;&amp;#039;&amp;#039; in the RAM of the system. After this period, the changes are transferred to permanent storage. This completes the transaction.&lt;br /&gt;
&lt;br /&gt;
To ensure data consistency when following this procedure, ZFS uses a &amp;#039;&amp;#039;&amp;#039;[[Copy-on-Write (COW)|Copy-on-Write (CoW)]]&amp;#039;&amp;#039;&amp;#039; strategy. During a write operation, no blocks are overwritten. Instead, the blocks, with the corresponding changes, are copied to a different location. The old blocks remain intact, but the file system points to the new blocks. If the old blocks are not referenced anymore (for example from [[ZFS Snapshots|Snapshots]]), they may be overwritten during future write operations.&lt;br /&gt;
&lt;br /&gt;
== Setup ==&lt;br /&gt;
[[File:Zfs-storage_stack.png|alt=Abb. 1: A simplified, illustrative representation of the ZFS storage stack|thumb|Image 1: A simplified, illustrative representation of the ZFS storage stack.]]&lt;br /&gt;
To understand the function of ZFS, its building blocks must be understood. &lt;br /&gt;
&lt;br /&gt;
Three levels form the structure of the ZFS storage stack&amp;lt;ref&amp;gt;[https://openzfs.org/wiki/System_Administration &amp;quot;System Administration&amp;quot; in openzfs Wiki] (openzfs.org, 2026)&amp;lt;/ref&amp;gt; (see image 1): The lowest level are the &amp;#039;&amp;#039;&amp;#039;physical data carriers&amp;#039;&amp;#039;&amp;#039;. These are grouped together in logical units within a storage pool called &amp;#039;&amp;#039;&amp;#039;&amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt;&amp;#039;&amp;#039;&amp;#039;. Logical objects are provided for the operating system via &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt;. In addition to the &amp;#039;&amp;#039;&amp;#039;datasets&amp;#039;&amp;#039;&amp;#039;, that correspond to classic file systems, there are also &amp;#039;&amp;#039;&amp;#039;metadata&amp;#039;&amp;#039;&amp;#039; such as snapshots and bookmarks. &lt;br /&gt;
&lt;br /&gt;
{| {{Prettytable}} cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;margin: 1em 1em 1em 0; background: #f9f9f9; border: 1px #a0a0a0 solid; border-collapse: collapse; &amp;quot; rules=&amp;quot;all&amp;quot;&lt;br /&gt;
|The hardware level is not further explained in this article. If you require consulting on an efficient and performant design of a ZFS infrastructure, do not hesitate to contact us: [https://www.thomas-krenn.com/de/unternehmen/kontakt-tk/thomas-krenn-ansprechpartner/slide.presales Contact persons]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
Furthermore, the &amp;#039;&amp;#039;Adaptive Replacement Cache (ARC)&amp;#039;&amp;#039; and the &amp;#039;&amp;#039;ZFS Intent Log (ZIL)&amp;#039;&amp;#039; are also important elements for the function of ZFS.&lt;br /&gt;
&lt;br /&gt;
=== zpool ===&lt;br /&gt;
The &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt; is a virtual storage pool that is formed by so-called &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt; (&amp;#039;&amp;#039;Virtual Devices&amp;#039;&amp;#039; in brief). ZFS can administrate multiple &amp;lt;code&amp;gt;zpools&amp;lt;/code&amp;gt;. The individual &amp;lt;code&amp;gt;zpools&amp;lt;/code&amp;gt; are independent from each other and must be administrated separately. &lt;br /&gt;
&lt;br /&gt;
==== vdev ==== &lt;br /&gt;
A &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is a logical data carrier within a &amp;lt;code&amp;gt;zpools&amp;lt;/code&amp;gt; that is created by a physical data carrier or a fusion of multiple physical data carriers. It can be formed by the following entities:&lt;br /&gt;
&lt;br /&gt;
* physical data carrier&lt;br /&gt;
* data carrier arrays (for example RAID)&lt;br /&gt;
* partitions&lt;br /&gt;
&lt;br /&gt;
In productive environments, a &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is usually created by individual physical data carriers.&lt;br /&gt;
&lt;br /&gt;
It is also possible to form a &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; out of files. This is an exceptional case and is only recommended for testing purposes. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Storage&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt; are provided for data storage. ZFS provides different redundancy levels for storage &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt;&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/man/master/7/zfsconcepts.7.html zfsconcepts.7] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
* Single (simple data carrier)&lt;br /&gt;
* Mirror (mirrored data carrier)&lt;br /&gt;
* RAIDZ-1/2/3 (data storage network with 1/2/3 parities)&lt;br /&gt;
* [[ZFS dRAID Grundlagen und Einrichtung|dRAID]]&lt;br /&gt;
&lt;br /&gt;
In addition, there are further &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt; for special use:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Spare&amp;#039;&amp;#039;&amp;#039;: Is used for the failure of a physical data carrier from a storage &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; used for recovery (resilvering)&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Cache&amp;#039;&amp;#039;&amp;#039;: The read buffer, also known as L2ARC &amp;#039;&amp;#039;(Level 2 Adaptive Replacement Cache),&amp;#039;&amp;#039; is an extension of the &amp;#039;&amp;#039;[[Benutzer:Sbohn/Spielwiese5#ARC|ARC]]&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;  &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Log&amp;#039;&amp;#039;&amp;#039;: The so-called &amp;#039;&amp;#039;SLOG&amp;#039;&amp;#039; &amp;#039;&amp;#039;(Separate Intent Log)&amp;#039;&amp;#039; &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is responsible for caching during synchronous write operations. It is the relocation of &amp;#039;&amp;#039;[[Benutzer:Sbohn/Spielwiese5#ZIL|ZIL]] (ZFS Intent Log)&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Dedup&amp;#039;&amp;#039;&amp;#039;: This &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is used for storing the &amp;#039;&amp;#039;Deduplication Table (DDT)&amp;#039;&amp;#039; for deduplicate in the &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt; &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Special&amp;#039;&amp;#039;&amp;#039;: A&amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is used for storing metadata and optionally small data blocks. &amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;It also stores the DDT if there is no dedicated &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; for it.&lt;br /&gt;
&lt;br /&gt;
=== Datasets ===&lt;br /&gt;
A dataset forms the upper level of the ZFS Storage Stack. The following datasets can be formed with ZFS:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;ZVOL:&amp;#039;&amp;#039;&amp;#039; The &amp;#039;&amp;#039;ZFS Volume&amp;#039;&amp;#039; is a virtual block device &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;File system:&amp;#039;&amp;#039;&amp;#039; ZFS-native file systems can be set up&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Clone:&amp;#039;&amp;#039;&amp;#039; A standalone, writable copy of a ZFS snapshot&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZVOLs can be used to insert regular file systems on operating system layers. &lt;br /&gt;
&lt;br /&gt;
=== Meta data ===&lt;br /&gt;
In addition to data sets, there are further logical objects in ZFS:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Snapshot:&amp;#039;&amp;#039;&amp;#039; A snapshot is a momentary representation of a system&amp;#039;s state. The blocks described at the time of the snapshot are immutable (&amp;#039;&amp;#039;immutable&amp;#039;&amp;#039;) and remain in place at least until the snapshot and its references are deleted&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Bookmark:&amp;#039;&amp;#039;&amp;#039; A bookmark is a read-only copy of the filesystem or a volume. They are tied to snapshots and are retained even if the snapshot is deleted&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ARC and ZIL ==&lt;br /&gt;
In addition to the storage stack, there are two other important modules for using ZFS efficiently.&lt;br /&gt;
&lt;br /&gt;
=== ARC ===&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;#039;Adaptive Replacement Cache&amp;#039;&amp;#039; &amp;#039;&amp;#039;(ARC)&amp;#039;&amp;#039; is the reading buffer of ZFS. It is formed in the RAM of the host system&amp;lt;ref name=&amp;quot;:2&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/Performance%20and%20Tuning/Workload%20Tuning.html#adaptive-replacement-cache Adaptive Replacement Cache] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;.   &lt;br /&gt;
&lt;br /&gt;
The general task of the ARC is to provide blocks for fast reading processes. For this, the ARC builds lists about buffered entries&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;. The ARC distinguishes from &amp;#039;&amp;#039;most recent&amp;#039;&amp;#039; (&amp;#039;&amp;#039;MRU - Most Recently Used&amp;#039;&amp;#039;) blocks and &amp;#039;&amp;#039;frequently&amp;#039;&amp;#039; (&amp;#039;&amp;#039;MFU - Most Frequently Used&amp;#039;&amp;#039;) used blocks. Therefore, the ARC is faster as commonly used read buffers that only keep MRU in the buffer&amp;lt;ref&amp;gt;[https://github.com/openzfs/zfs/blob/master/module/zfs/arc.c OpenZFS ARC Source Code] (github.com/openzfs, 2026)&amp;lt;/ref&amp;gt;.   &lt;br /&gt;
&lt;br /&gt;
==== L2ARC ====&lt;br /&gt;
The &amp;#039;&amp;#039;Level 2 ARC (L2ARC)&amp;#039;&amp;#039; is formed in the permanent storage (NVMe preferred)&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;. If data is evicted from the ARC, ZFS can store it in the L2ARC and access it during subsequent read operations.&lt;br /&gt;
&lt;br /&gt;
=== ZIL ===&lt;br /&gt;
The &amp;#039;&amp;#039;ZFS Intent Log (ZIL)&amp;#039;&amp;#039; is a temporary cache that is used for synchron writing processes.&lt;br /&gt;
&lt;br /&gt;
The ZIL is not a cache in the strict sense: During a synchronous write operation, the data is written simultaneously to a transaction group (in RAM) and to the ZIL (on physical storage media)&amp;lt;ref&amp;gt;[https://github.com/openzfs/zfs/blob/master/module/zfs/zil.c OpenZFS ZIL Source Code] (github.com/openzfs, 2026)&amp;lt;/ref&amp;gt;. As soon as the data from the transaction group has been fully written to the &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt;, the data is rejected in the ZIL. The ZIL is responsible for data integrity even in the event of system failures. Because data must be written to permanent storage, which is slow compared to RAM, synchronous write operations are less efficient.&lt;br /&gt;
&lt;br /&gt;
==== SLOG ====&lt;br /&gt;
The &amp;#039;&amp;#039;Separate Intent Log (SLOG)&amp;#039;&amp;#039; outsources &amp;#039;&amp;#039;ZIL&amp;#039;&amp;#039;-blocks to a separate &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://openzfs.github.io/openzfs-docs/Performance%20and%20Tuning/Workload%20Tuning.html#synchronous-i-o OpenZFS - Synchron Writing Process]  (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;. This is useful, when the data carriers used for the SLOG have a higher writing performance.&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
Official documentation: [https://openzfs.github.io/openzfs-docs/index.html OpenZFS Documentation]&lt;br /&gt;
&lt;br /&gt;
Basic article: [https://arstechnica.com/information-technology/2020/05/zfs-101-understanding-zfs-storage-and-performance/ ZFS 101—Understanding ZFS storage and performance]&lt;br /&gt;
&lt;br /&gt;
Synchron/Asynchron writing processes: [https://jrs-s.net/2019/05/02/zfs-sync-async-zil-slog/ ZFS sync/async + ZIL/SLOG, explained]&lt;br /&gt;
&lt;br /&gt;
TrueNAS article on ZIL and SLOG: [https://www.truenas.com/blog/zfs-zil-and-slog-demystified/ The ZFS ZIL and SLOG Demystified]&lt;br /&gt;
&lt;br /&gt;
ZFS on Linux: https://zfsonlinux.org/&lt;br /&gt;
&lt;br /&gt;
Aaron Toponce about ZFS: [https://web.archive.org/web/20230904234829/https://pthree.org/2012/04/17/install-zfs-on-debian-gnulinux/ ZFS Administration]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Sbohn}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Storage]]&lt;br /&gt;
[[Category:Review 2027 Q3]]&lt;br /&gt;
[[de:ZFS Grundlagen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OPNsense_network_card_driver</id>
		<title>OPNsense network card driver</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OPNsense_network_card_driver"/>
		<updated>2026-07-21T11:26:59Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;OPNsense contains drivers for numerous network cards. This Wiki article shows, &amp;#039;&amp;#039;&amp;#039;which drivers are used for which network card&amp;#039;&amp;#039;&amp;#039;. Some drivers must be activated manually. Information on this topic can be found in the article Activation of OPNsense Chelsio Mellanox Broadcom network card driver.  == Driver versions == {| class=&amp;quot;wikitable&amp;quot; |+ ! rowspan=&amp;quot;2&amp;quot; |Driver !Supported network chips/cards  !Driver version in OPNsense 26.7 !Driver version in OPNsense 26.1 !Dr...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[OPNsense]] contains drivers for numerous network cards. This Wiki article shows, &amp;#039;&amp;#039;&amp;#039;which drivers are used for which network card&amp;#039;&amp;#039;&amp;#039;. Some drivers must be activated manually. Information on this topic can be found in the article [[Activation of OPNsense Chelsio Mellanox Broadcom network card driver]].&lt;br /&gt;
&lt;br /&gt;
== Driver versions ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
! rowspan=&amp;quot;2&amp;quot; |Driver&lt;br /&gt;
!Supported network chips/cards &lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 26.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 26.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 25.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 25.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 24.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 24.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 23.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 23.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 22.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 22.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 21.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 21.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 20.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in [[OPNsense]] 20.1&lt;br /&gt;
|-&lt;br /&gt;
!Kernel version&lt;br /&gt;
!FreeBSD 15.1-RELEASE&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |FreeBSD 14.3-RELEASE&lt;br /&gt;
!FreeBSD 14.2-RELEASE&lt;br /&gt;
!FreeBSD 14.1-RELEASE&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |FreeBSD 13.2-RELEASE&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |FreeBSD 13.1-RELEASE&lt;br /&gt;
!FreeBSD 13.0-STABLE&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; |FreeBSD 12.1&lt;br /&gt;
![[FreeBSD]] 11.2&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=bge&amp;amp;sektion=4&amp;amp;format=html bge]&lt;br /&gt;
|&lt;br /&gt;
* Broadcom 1Gbit, for example:&lt;br /&gt;
** H12SSL-i - BCM5720&lt;br /&gt;
** H12SSW-iN - BCM5720&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=bnxt&amp;amp;sektion=4&amp;amp;format=html bnxt]&lt;br /&gt;
|&lt;br /&gt;
* Broadcom 10GBit, for example:&lt;br /&gt;
** H12SSL-NT/CT - BCM57416&lt;br /&gt;
** H12SSW-NT - BCM57416&lt;br /&gt;
** P210TP - BCM57416&lt;br /&gt;
*Broadcom 25GBit,for example:&lt;br /&gt;
** X12SPZ-SPLN6F - BCM57414&lt;br /&gt;
** P225P - BCM57414&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |230.0.133.0 (via iflib, driver is activated automatically)&amp;lt;ref&amp;gt;[Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; for a system with a built-in Broadcom P225P network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 230.0.133.0&lt;br /&gt;
dev.bnxt.0.%iommu: rid=0x8100&lt;br /&gt;
dev.bnxt.0.%parent: pci6&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d7 subvendor=0x14e4 subdevice=0x1402 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:129:0:0&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.20.0.1 (via iflib, &amp;#039;&amp;#039;&amp;#039;driver is now activated automatically&amp;#039;&amp;#039;&amp;#039;)&amp;lt;ref&amp;gt;[Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; for a system with a built-in Broadcom P225P network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 2.20.0.1&lt;br /&gt;
dev.bnxt.0.%domain: 0&lt;br /&gt;
dev.bnxt.0.%parent: pci6&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d7 subvendor=0x14e4 subdevice=0x1402 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:24:0:0 handle=\_SB_.PC01.BR1A.H000&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
dev.bnxt.0.%desc: Broadcom BCM57414 NetXtreme-E 10Gb/25Gb Ethernet&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.20.0.1 (via iflib)&amp;lt;ref name=&amp;quot;:5&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a system with a Supermicro H13SSL-NT motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 2.20.0.1&lt;br /&gt;
dev.bnxt.0.%domain: 0&lt;br /&gt;
dev.bnxt.0.%parent: pci1&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d8 subvendor=0x15d9 subdevice=0x16d8 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:195:0:0&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |1.0.0.2 (via iflib)&amp;lt;ref name=&amp;quot;:2&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 1.0.0.2&lt;br /&gt;
dev.bnxt.0.%parent: pci2&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d7 subvendor=0x14e4 subdevice=0x1402 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:194:0:0&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
dev.bnxt.0.%desc: Broadcom BCM57414 NetXtreme-E 10Gb/25Gb Ethernet&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=cxgbe&amp;amp;sektion=4&amp;amp;format=html cxgbe]&lt;br /&gt;
|&lt;br /&gt;
* Chelsio T4/T5/T6&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=em&amp;amp;sektion=4&amp;amp;format=html em]&lt;br /&gt;
|&lt;br /&gt;
* Intel I219&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; rowspan=&amp;quot;2&amp;quot; |7.6.1-k (via iflib)&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a LES compact 4L with I210:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igb.0.iflib.driver_version: 7.6.1-k&lt;br /&gt;
dev.igb.0.%parent: pci1&lt;br /&gt;
dev.igb.0.%pnpinfo: vendor=0x8086 device=0x157b subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igb.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP01.PXSX&lt;br /&gt;
dev.igb.0.%driver: igb&lt;br /&gt;
dev.igb.0.%desc: Intel(R) PRO/1000 PCI-Express Network Driver&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|7.6.1-k&lt;br /&gt;
|-&lt;br /&gt;
|igb&lt;br /&gt;
|&lt;br /&gt;
* Intel I210&lt;br /&gt;
* Intel I211&lt;br /&gt;
* Intel I350&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |2.5.28-fbsd (via iflib)&amp;lt;ref name=&amp;quot;:7&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a LES compact 4L:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igb.0.iflib.driver_version: 2.5.28-fbsd&lt;br /&gt;
dev.igb.0.%iommu: rid=0x100&lt;br /&gt;
dev.igb.0.%parent: pci1&lt;br /&gt;
dev.igb.0.%pnpinfo: vendor=0x8086 device=0x157b subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igb.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP01.PXSX&lt;br /&gt;
dev.igb.0.%driver: igb&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |2.5.19-fbsd (via iflib)&amp;lt;ref name=&amp;quot;:6&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on an &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;20785&amp;quot;&amp;gt;Edge 4L&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igb.0.iflib.driver_version: 2.5.19-fbsd&lt;br /&gt;
dev.igb.0.%parent: pci1&lt;br /&gt;
dev.igb.0.%pnpinfo: vendor=0x8086 device=0x1533 subvendor=0xffff subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igb.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP03.PXSX&lt;br /&gt;
dev.igb.0.%driver: igb&lt;br /&gt;
dev.igb.0.%desc: Intel(R) I210 (Copper)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |7.6.1-k (via iflib)&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&lt;br /&gt;
|2.5.3-k&lt;br /&gt;
|-&lt;br /&gt;
|igc&lt;br /&gt;
|&lt;br /&gt;
* Intel I225-V&lt;br /&gt;
* Intel I225-LM&lt;br /&gt;
* Intel I226-V&lt;br /&gt;
| colspan=&amp;quot;5&amp;quot; |1 (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.igc.0.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a  &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;20700&amp;quot;&amp;gt;LES v4&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igc.0.iflib.driver_version: 1&lt;br /&gt;
dev.igc.0.%parent: pci1&lt;br /&gt;
dev.igc.0.%pnpinfo: vendor=0x8086 device=0x15f3 subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igc.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PC00.RP01.PXSX&lt;br /&gt;
dev.igc.0.%driver: igc&lt;br /&gt;
dev.igc.0.%desc: Intel(R) Ethernet Controller I225-V&lt;br /&gt;
dev.igc.%parent:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.igc.0.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;21011&amp;quot;&amp;gt;LES plus v4&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igc.0.iflib.driver_version: 1&lt;br /&gt;
dev.igc.0.%parent: pci2&lt;br /&gt;
dev.igc.0.%pnpinfo: vendor=0x8086 device=0x125c subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igc.0.%location: slot=0 function=0 dbsf=pci0:2:0:0 handle=\_SB_.PC00.RP05.PXSX&lt;br /&gt;
dev.igc.0.%driver: igc&lt;br /&gt;
dev.igc.0.%desc: Intel(R) Ethernet Controller I226-V&lt;br /&gt;
dev.igc.%parent:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;5&amp;quot; |1 (via iflib)&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.igc.0.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;20159&amp;quot;&amp;gt;LES network 6L&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igc.0.iflib.driver_version: 1&lt;br /&gt;
dev.igc.0.%parent: pci1&lt;br /&gt;
dev.igc.0.%pnpinfo: vendor=0x8086 device=0x15f3 subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igc.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP05.PXSX&lt;br /&gt;
dev.igc.0.%driver: igc&lt;br /&gt;
dev.igc.0.%desc: Intel(R) Ethernet Controller I225-V&lt;br /&gt;
dev.igc.%parent:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |(not supported)&lt;br /&gt;
|-&lt;br /&gt;
|ix&lt;br /&gt;
|&lt;br /&gt;
* Intel X520&lt;br /&gt;
* Intel X550&lt;br /&gt;
* Intel E610&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; |5.0.1-k(via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with a Kontron K3881-C motherboard and E610 interfaces:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 5.0.1-k&lt;br /&gt;
dev.ix.0.%iommu: rid=0x700&lt;br /&gt;
dev.ix.0.%parent: pci6&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x57b0 subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:7:0:0 handle=\_SB_.PC00.RP09.PXSX&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
dev.ix.0.%desc: Intel(R) E610 (10 GbE)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|5.0.1-k(via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with X520 (82599ES) interfaces:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 5.0.1-k&lt;br /&gt;
dev.ix.0.%iommu: rid=0x200&lt;br /&gt;
dev.ix.0.%parent: pci2&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x10fb subvendor=0xffff subdevice=0xffff class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:2:0:0 handle=\_SB_.PC00.RP01.PXSX&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
dev.ix.0.%desc: Intel(R) X520 82599ES (SFI/SFP+)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|4.0.1-k (via iflib)&amp;lt;ref name=&amp;quot;:4&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with Supermicro X12SPi-TF motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 4.0.1-k&lt;br /&gt;
dev.ix.0.%domain: 0&lt;br /&gt;
dev.ix.0.%parent: pci1&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x1563 subvendor=0x15d9 subdevice=0x1563 class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PC00.RP01.D033&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|4.0.1-k (via iflib)&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|4.0.1-k (via iflib)&amp;lt;ref name=&amp;quot;:3&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with Supermicro X10SDV-TP8F motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 4.0.1-k&lt;br /&gt;
dev.ix.0.%parent: pci5&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x15ac subvendor=0x15d9 subdevice=0x15ac class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:4:0:0 handle=\_SB_.PCI0.BR2C.H000&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
dev.ix.0.%desc: Intel(R) X552 (SFP+)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|3.2.12-k ? (was on OPNsense 18.7)&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=ixl&amp;amp;sektion=4&amp;amp;format=html ixl]&lt;br /&gt;
|&lt;br /&gt;
* Intel X700 Series&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with Advantech FWA-3034:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%iommu: rid=0x200&lt;br /&gt;
dev.ixl.0.%parent: pci2&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x1572 subvendor=0x13fe subdevice=0x303d class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:2:0:0 handle=\_SB_.PC00.PEG0.PEGP&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a system with Asus P13R-M/10G-2T motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%iommu: rid=0x300&lt;br /&gt;
dev.ixl.0.%parent: pci3&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x15ff subvendor=0x1043 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:3:0:0 handle=\_SB_.PC00.RP13.PXSX&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a system that has a built-in Intel X710-T4 network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%domain: 0&lt;br /&gt;
dev.ixl.0.%parent: pci8&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x15ff subvendor=0x8086 subdevice=0x0001 class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:81:0:0 handle=\_SB_.PC02.BR2A.H000&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
dev.ixl.0.%desc: Intel(R) Ethernet Controller X710 for 10GBASE-T - 2.3.3-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a system featuring an Asus P12R-M/10G-2T motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%parent: pci3&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x15ff subvendor=0x1043 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:3:0:0 handle=\_SB_.PC00.RP09.D073&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
dev.ixl.0.%desc: Intel(R) Ethernet Controller X710 for 10GBASE-T - 2.3.3-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.3.1-k (via iflib)&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; |2.1.0-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a Supermicro AOC-STG-i4S network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.1.0-k&lt;br /&gt;
dev.ixl.0.%parent: pci20&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x1572 subvendor=0x15d9 subdevice=0x087e class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:65:0:0&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
dev.ixl.0.%desc: Intel(R) Ethernet Controller X710 for 10GbE SFP+ - 2.1.0-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|1.9.9-k ?&lt;br /&gt;
|-&lt;br /&gt;
|ice&lt;br /&gt;
|&lt;br /&gt;
* Intel E800 Series&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |1.43.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with Advantech FWA-3034:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.0.iflib.driver_version: 1.43.3-k&lt;br /&gt;
dev.ice.0.%iommu: rid=0x100&lt;br /&gt;
dev.ice.0.%parent: pci1&lt;br /&gt;
dev.ice.0.%pnpinfo: vendor=0x8086 device=0x1593 subvendor=0x13fe subdevice=0x2060 class=0x020000&lt;br /&gt;
dev.ice.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PC00.PEG1.PEGP&lt;br /&gt;
dev.ice.0.%driver: ice&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|1.39.13-k (via iflib)&amp;lt;ref&amp;gt;Read out via  &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a system that has a built-in Intel E810-XXVDA2 network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.0.iflib.driver_version: 1.39.13-k&lt;br /&gt;
dev.ice.0.%domain: 0&lt;br /&gt;
dev.ice.0.%parent: pci10&lt;br /&gt;
dev.ice.0.%pnpinfo: vendor=0x8086 device=0x159b subvendor=0x8086 subdevice=0x0003 class=0x020000&lt;br /&gt;
dev.ice.0.%location: slot=0 function=0 dbsf=pci0:138:0:0 handle=\_SB_.PC04.BR4A.H000&lt;br /&gt;
dev.ice.0.%driver: ice&lt;br /&gt;
dev.ice.0.%desc: Intel(R) Ethernet Network Adapter E810-XXV-2 - 1.39.13-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|1.37.11-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;root@OPNsense:~ # sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt;on a system with Supermicro X12SDV-4C-SP6F motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.0.iflib.driver_version: 1.37.11-k&lt;br /&gt;
dev.ice.0.%domain: 0&lt;br /&gt;
dev.ice.0.%parent: pci8&lt;br /&gt;
dev.ice.0.%pnpinfo: vendor=0x8086 device=0x124d subvendor=0x15d9 subdevice=0x124d class=0x020000&lt;br /&gt;
dev.ice.0.%location: slot=0 function=0 dbsf=pci0:244:0:0 handle=\_SB_.PC02.VP2A.CPM0&lt;br /&gt;
dev.ice.0.%driver: ice&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|1.34.2-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;root@OPNsense:~ # sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a system with Supermicro X12SDV-4C-SP6F motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.1.iflib.driver_version: 1.34.2-k&lt;br /&gt;
dev.ice.1.%domain: 0&lt;br /&gt;
dev.ice.1.%parent: pci8&lt;br /&gt;
dev.ice.1.%pnpinfo: vendor=0x8086 device=0x124d subvendor=0x15d9 subdevice=0x124d class=0x020000&lt;br /&gt;
dev.ice.1.%location: slot=0 function=2 dbsf=pci0:244:0:2 handle=\_SB_.PC02.VP2A.D077&lt;br /&gt;
dev.ice.1.%driver: ice&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |(not supported)&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=mlx4en&amp;amp;sektion=4&amp;amp;format=html mlx4en]&lt;br /&gt;
|&lt;br /&gt;
* Mellanox ConnectX-4&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=mlx5en&amp;amp;sektion=4&amp;amp;format=html mlx5en]&lt;br /&gt;
|&lt;br /&gt;
* Mellanox ConnectX-5&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|re&lt;br /&gt;
|&lt;br /&gt;
* Realtek&lt;br /&gt;
| colspan=&amp;quot;14&amp;quot; |See [[Realtek NICs in OPNsense]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== iflib ==&lt;br /&gt;
Iflib is a framework for network interface drivers for FreeBSD. It has been developed to remove standard codeblocks (boilerplates) that are often required for modern network interface devices. This should allow driver developers to focus on the specific code required for their hardware.&amp;lt;ref&amp;gt;[https://www.freebsd.org/cgi/man.cgi?query=iflib&amp;amp;sektion=4&amp;amp;apropos=0&amp;amp;manpath=FreeBSD+12.2-RELEASE+and+Ports iflib Manpage] (www.freebsd.org)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Iflib was launched in the fall of 2017 and provides a standardized set of functions for implementing network drivers. iflib currently supports most Intel drivers and cards from Broadcom NetExtreme family.&amp;lt;ref&amp;gt;[https://www.youtube.com/watch?v=FuNgy8Ag4DE Sam Gwydir: Improving netdump hardware support and performance with iflib - BSDCan 2018] (youtube.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The idea behind iflib was to reduce the redundant code in different NIC drivers to standardize certain kernel interface functions. Most, but not all, NIC drivers have been rewritten by the manufacturers to support the iflib API. The new library handles tasks such as connecting Netmap devices to relieve the manufacturers&amp;#039; driver developers of this burden.&lt;br /&gt;
&lt;br /&gt;
The use of iflib in FreeBSD means that the driver versions have changed. The version that can be seen in the current FreeBSD kernels is the iflib version of the driver and this version number usually does not match the latest version of the driver listed on the manufacturer&amp;#039;s website. Some manufacturers provide an iflib version of their FreeBSD driver for newer kernel versions and an older, non-iflib version for older kernels. And the real catch is that, for some NIC drivers, the version number that appears to be newer and higher is actually older code than what might be included in a non-iflib version.&amp;lt;ref&amp;gt;[https://forum.netgate.com/topic/155324/any-one-know-which-intel-ix-driver-for-x520-card-is-in-the-actual-kernel/4?_=1620296660376&amp;amp;lang=de Any one know which Intel ix driver for x520 card is in the actual kernel?] (forum.netgate.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IPS support ==&lt;br /&gt;
An overview, which drivers are supported by IPS, is shown in the following spreadsheet:&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1RVj8K3XOzWi-Bkjq6hUxWudu7Cxd8FFTqjLiBMzZWEM/edit#gid=0 netmap(4) on OPNsense] (docs.google.com/spreadsheets)&lt;br /&gt;
&lt;br /&gt;
Information on ixl driver netmap support:&lt;br /&gt;
* [https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=230465#c30 ixl: not working in netmap mode (Comment #30)] (bugs.freebsd.org) &amp;lt;cite&amp;gt;I&amp;#039;m not surprised this works, because ixl in FreeBSD 12.x is implemented through iflib, and netmap in this case uses iflib to access the hw (and iflib must work, otherwise you would not be able to use an ixl NIC using the traditional networking tools and applications).&amp;lt;/cite&amp;gt;&lt;br /&gt;
&lt;br /&gt;
More information:&lt;br /&gt;
* [https://www.thomas-krenn.com/de/tkmag/allgemein/opnsense-webinar-intrusion-detection-pro-und-contra/ OPNsense Webinar: Intrusion Detection – Pro and Contra] (TKmag, 16.06.2020)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:OPNsense]]&lt;br /&gt;
[[de:OPNsense Netzwerkkarten-Treiber]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Installation_of_Open_WebUI_with_Ollama</id>
		<title>Installation of Open WebUI with Ollama</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Installation_of_Open_WebUI_with_Ollama"/>
		<updated>2026-07-20T12:37:05Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Open WebUI&amp;#039;&amp;#039;&amp;#039; provides a browser-based user interface for local KI-models. In connection with Ollama, user can select models and use them via webbrowser.   This article shows the installation of Open WebUI as docker container. Ollama is operated natively on the same Ubuntu server.  &amp;lt;!-- Add after testing: * Used Ubuntu-Version: * Used Open-WebUI-Version: * Used Ollama-Version: * Used Docker-Version: * Used Testhardware: --&amp;gt;  == Requirements ==  These instructions are...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Open WebUI&amp;#039;&amp;#039;&amp;#039; provides a browser-based user interface for local KI-models. In connection with Ollama, user can select models and use them via webbrowser. &lt;br /&gt;
&lt;br /&gt;
This article shows the installation of Open WebUI as docker container. Ollama is operated natively on the same Ubuntu server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Add after testing:&lt;br /&gt;
* Used Ubuntu-Version:&lt;br /&gt;
* Used Open-WebUI-Version:&lt;br /&gt;
* Used Ollama-Version:&lt;br /&gt;
* Used Docker-Version:&lt;br /&gt;
* Used Testhardware:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
These instructions are designed for Ubuntu server 24.04 LTS. The following components must already be installed:&lt;br /&gt;
&lt;br /&gt;
* Ollama in accordance with the article [[Installation of Ollama]]&lt;br /&gt;
* Docker in accordance with the article [[Docker Installation under Ubuntu 24.04]]&lt;br /&gt;
* At least one locally installed Ollama model&lt;br /&gt;
* User with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;-rights&lt;br /&gt;
* Free TCP-Port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Ollama service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl status ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the connection is successful, a JSON response containing the installed models is returned.&lt;br /&gt;
&lt;br /&gt;
If no model is available, download, for example, &amp;lt;code&amp;gt;gemma3:4b&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama pull gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the docker installation:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker version&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Install WebUI ==&lt;br /&gt;
&lt;br /&gt;
Open WebUI runs in a docker container. As Ollama is natively installed on the same server, the container with the host network is started.&lt;br /&gt;
&lt;br /&gt;
Start WebUI:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker run -d \&lt;br /&gt;
  --network=host \&lt;br /&gt;
  -v open-webui:/app/backend/data \&lt;br /&gt;
  -e OLLAMA_BASE_URL=http://127.0.0.1:11434 \&lt;br /&gt;
  --name open-webui \&lt;br /&gt;
  --restart always \&lt;br /&gt;
  ghcr.io/open-webui/open-webui:main&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Docker volume &amp;lt;code&amp;gt;open-webui&amp;lt;/code&amp;gt; stores user accounts, settings and chat histories permanently.&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;main&amp;lt;/code&amp;gt; tag refers to the current version. For the productive operation, a fixed version number should be used after the test has been successful.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Before publishing, change to a stable version after testing:&lt;br /&gt;
ghcr.io/open-webui/open-webui:vX.Y.Z&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the container status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker ps --filter name=open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If necessary, view the startup logs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker logs --tail=100 open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Open web interface ==&lt;br /&gt;
&lt;br /&gt;
Open the following address in a browser:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;http://&amp;amp;lt;IP-DES-SERVERS&amp;amp;gt;:8080&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first user account created on a new installation is granted administrator privileges.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 2: Registration page for Open WebUI --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Screenshot 3: Homepage after first login --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Log in and select &amp;lt;code&amp;gt;gemma3:4b&amp;lt;/code&amp;gt; from the model selection.&lt;br /&gt;
&lt;br /&gt;
Send, for example, the following request:&lt;br /&gt;
&lt;br /&gt;
:Explain the difference between RAID 5 und RAID 6.&lt;br /&gt;
&lt;br /&gt;
If the model responds, the connection between Open WebUI and Ollama functions.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 4: Erste erfolgreiche Antwort in Open WebUI --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Check Ollama connection ==&lt;br /&gt;
&lt;br /&gt;
If no models are displayed, open the following in Open WebUI:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Admin Panel &amp;amp;gt; Settings &amp;amp;gt; Connections&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Ollama address should point to the following URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;http://127.0.0.1:11434&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In addition, check the Ubuntu server:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl http://127.0.0.1:11434/api/tags&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As Open WebUI is started with &amp;lt;code&amp;gt;--network=host&amp;lt;/code&amp;gt;, the container can use the local Ollama address directly.&lt;br /&gt;
&lt;br /&gt;
== Update Open WebUI ==&lt;br /&gt;
&lt;br /&gt;
Load the current container image:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker pull ghcr.io/open-webui/open-webui:main&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Stop and remove the previous container:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker stop open-webui&lt;br /&gt;
sudo docker rm open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, restart Open WebUI:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker run -d \&lt;br /&gt;
  --network=host \&lt;br /&gt;
  -v open-webui:/app/backend/data \&lt;br /&gt;
  -e OLLAMA_BASE_URL=http://127.0.0.1:11434 \&lt;br /&gt;
  --name open-webui \&lt;br /&gt;
  --restart always \&lt;br /&gt;
  ghcr.io/open-webui/open-webui:main&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The data in the docker volume &amp;lt;code&amp;gt;open-webui&amp;lt;/code&amp;gt; is retained.&lt;br /&gt;
&lt;br /&gt;
== Secure access ==&lt;br /&gt;
&lt;br /&gt;
Open WebUI uses user accounts. Nevertheless, port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt; should not be accessible from the Internet without protection. &lt;br /&gt;
&lt;br /&gt;
A VPN or a reverse proxy with HTTPS is recommended for the access from the Internet. For a reverse proxy, WebSockets support must be enabled.&lt;br /&gt;
&lt;br /&gt;
For purely internal use, access can be restricted to the local network using UFW:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ufw allow from 192.168.1.0/24 to any port 8080 proto tcp&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Adapt the subnet to your own environment:&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== Websurface is not available ===&lt;br /&gt;
&lt;br /&gt;
Check the container status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker ps -a --filter name=open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
View the logs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker logs open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify, if port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt; is already used:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ss -tulpn | grep 8080&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== No models are displayed ===&lt;br /&gt;
&lt;br /&gt;
Check the installed Ollama models:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ls&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check Ollama API:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl http://127.0.0.1:11434/api/tags&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart both services if necessary:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo systemctl restart ollama&lt;br /&gt;
sudo docker restart open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Page is not displayed correctly after an update ===&lt;br /&gt;
&lt;br /&gt;
Open the web interface in a private browser window to test it. If it works there, delete the cache and the website data for the Open-WebUI-address.&lt;br /&gt;
&lt;br /&gt;
== Deinstallation ==&lt;br /&gt;
&lt;br /&gt;
Stop and remove the container:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker stop open-webui&lt;br /&gt;
sudo docker rm open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The stored data remains in the Docker volume for the time being.&lt;br /&gt;
&lt;br /&gt;
Remove the volume to delete all Open-WebUI-data completely:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker volume rm open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; User accounts, settings and chat histories are completely deleted.&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://docs.openwebui.com/getting-started/quick-start/ Open WebUI Documentation – Quick Start] (en)&lt;br /&gt;
* [https://docs.openwebui.com/getting-started/quick-start/connect-a-provider/starting-with-ollama/ Open WebUI Documentation – Ollama] (en)&lt;br /&gt;
* [https://docs.openwebui.com/troubleshooting/connection-error/ Open WebUI Documentation – Connection Errors] (en)&lt;br /&gt;
* [https://www.thomas-krenn.com/de/wiki/Docker_Installation_unter_Ubuntu_24.04 Docker Installation on Ubuntu 24.04]&lt;br /&gt;
* [https://docs.ollama.com/api/introduction Ollama Documentation – API Introduction] (en)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Artificial Intelligence]]&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[Category:Docker]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Activation_of_NVIDIA_vGPU_for_RDS_Sessions_on_Windows_Server</id>
		<title>Activation of NVIDIA vGPU for RDS Sessions on Windows Server</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Activation_of_NVIDIA_vGPU_for_RDS_Sessions_on_Windows_Server"/>
		<updated>2026-07-20T10:28:32Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;On Windows Server, applications within an RDS session may not use the assigned NVIDIA vGPU. Instead, Windows uses Microsoft Basic Render Driver by default. As a result, DirectX-based 3D applications, in particular, cannot access the GPU.   This article shows how to activate NVIDIA vGPU for RDS-sessions.  &amp;lt;!-- Add after testing: * Windows-Server-Version: * NVIDIA-vGPU-Version: * vGPU-Profile: * Hypervisor: --&amp;gt;  == Requirements == The NVIDIA vGPU must be assigned to the vi...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On Windows Server, applications within an RDS session may not use the assigned NVIDIA vGPU. Instead, Windows uses Microsoft Basic Render Driver by default. As a result, DirectX-based 3D applications, in particular, cannot access the GPU. &lt;br /&gt;
&lt;br /&gt;
This article shows how to activate NVIDIA vGPU for RDS-sessions.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Add after testing:&lt;br /&gt;
* Windows-Server-Version:&lt;br /&gt;
* NVIDIA-vGPU-Version:&lt;br /&gt;
* vGPU-Profile:&lt;br /&gt;
* Hypervisor:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
The NVIDIA vGPU must be assigned to the virtual machine and the suitable guest driver must be installed.&lt;br /&gt;
&lt;br /&gt;
Check first if Windows recognizes the vGPU:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;nvidia-smi&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The command should display the assigned GPU and the graphics memory available. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 1: Ausgabe von nvidia-smi --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Enable Group Policy ==&lt;br /&gt;
&lt;br /&gt;
Open the dialogue &amp;lt;code&amp;gt;Execute&amp;lt;/code&amp;gt; via &amp;lt;code&amp;gt;Windows-Key+ R&amp;lt;/code&amp;gt; and start:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;gpedit.msc&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Navigate to:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Computer-Configuration &amp;amp;gt; Administrative Templates&amp;amp;gt; Windows-Components&amp;amp;gt; Remotedesktopservices &amp;amp;gt; Remotedesktop-Session-Host &amp;amp;gt; Remote-Session-Environment&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 2: Pfad im Gruppenrichtlinien-Editor --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Activate the guideline:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Hardware graphics adapter for all remotedesktopservices-sessions&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The English name is:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Use the hardware default graphics adapter for all Remote Desktop Services Sessions&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 3: Aktivierte Gruppenrichtlinie --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, restart Windows-Server-VM.&lt;br /&gt;
&lt;br /&gt;
== Check GPU-use ==&lt;br /&gt;
&lt;br /&gt;
Re-establish an RDS connection and launch an application that uses GPU acceleration.&lt;br /&gt;
&lt;br /&gt;
Check the utilization in the Task-Manager:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Performance &amp;amp;gt; GPU&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, you can execute the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;nvidia-smi&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a GPU still does not appear, check the NVIDIA vGPU guest driver, the assigned vGPU profile, and the licensing.&lt;br /&gt;
&lt;br /&gt;
== Background ==&lt;br /&gt;
&lt;br /&gt;
NVIDIA describes this behaviour for all supported Windows Server guest operating systems. The default settings uses Microsoft Basic Render Driver, as Software Rendering can be more efficient for simple 2D-applications.&lt;br /&gt;
DirectX-based 3D-applications cannot, however, access the GPU.&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://docs.nvidia.com/vgpu/19.0/known-issues/bug-no-id-no-gpu-utilization-windows-server-guests.html NVIDIA vGPU Documentation – RDS sessions do not use the GPU with Microsoft Windows Server as guest OS] (en)&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Windows]]&lt;br /&gt;
[[Category:Virtual Desktop Infrastructure (VDI)]]&lt;br /&gt;
[[de:NVIDIA vGPU für RDS-Sitzungen unter Windows Server aktivieren]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_July_2026</id>
		<title>Supermicro BMC Security Advisories July 2026</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_July_2026"/>
		<updated>2026-07-20T05:49:48Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In &amp;#039;&amp;#039;&amp;#039;July 2026&amp;#039;&amp;#039;&amp;#039;, Supermicro published security advisories regarding the BMC-firmware of its mainboards. This security vulnerability requires a &amp;#039;&amp;#039;&amp;#039;firmware update&amp;#039;&amp;#039;&amp;#039;. &lt;br /&gt;
&lt;br /&gt;
In this article, you will find information on this security advisory and where to find updates on Thomas-Krenn products.&lt;br /&gt;
&lt;br /&gt;
== Security advisories ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |CVE&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Risk potential&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Description&lt;br /&gt;
|-&lt;br /&gt;
|align=&amp;quot;center&amp;quot;  | CVE-2026-3821&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | High 8.8&lt;br /&gt;
| align=&amp;quot;left&amp;quot; | &amp;#039;&amp;#039;&amp;#039;&amp;lt;u&amp;gt;Execution of arbitrary code&amp;lt;/u&amp;gt;&amp;#039;&amp;#039;&amp;#039; (The SMASH-services of Supermicro (SMC) show a security vulnerability that allows the execution of an arbitrary code. An authorized attacker can exploit SMASH input functions to compromise data integrity or launch a denial-of-service (DoS) attack against the BMC.)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Updates for Thomas-Krenn products ==&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;download area of Thomas-Krenn&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The updates in the download area have been tested by us to guarantee the stability and compatibility of our systems.&lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you can get it at [https://www.asus.com/de/support/download-center/ Asus] or [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro].&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://www.supermicro.com/en/support/security_BMC_IPMI_Jul_2026 Vulnerabilities in Supermicro BMC Firmware, July 2026]&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Server Hardware]]&lt;br /&gt;
[[de:Supermicro BMC Sicherheitshinweise Juli 2026]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Installation_of_Ollama</id>
		<title>Installation of Ollama</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Installation_of_Ollama"/>
		<updated>2026-07-17T07:38:13Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Ollama&amp;#039;&amp;#039;&amp;#039; allows the local operation of Large Language Models (LLMs) on a Linux server. The models run on the own hardware and can be used via command line or HTTP-API.&lt;br /&gt;
&lt;br /&gt;
This article presents the native installation of Ollama on an Ubuntu server. As an example, a small model is downloaded and tested by using the local command line as well as the local API.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Add the following information after testing:&lt;br /&gt;
* Ubuntu-Version used:&lt;br /&gt;
* Ollama-Version used:&lt;br /&gt;
* Testhardware used:&lt;br /&gt;
* GPU used:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
These instructions are designed for Ubuntu Server 24.04 LTS. The installation normally functions on an Ubuntu Server LTS and 22.04 LTS, too. For GPU-systems should be verified if a suitable driver is available for the used Ubuntu version in advance. &lt;br /&gt;
&lt;br /&gt;
The following resources are recommended for initial testing:&lt;br /&gt;
&lt;br /&gt;
* user with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;-rights&lt;br /&gt;
* at least 8 GB RAM&lt;br /&gt;
* at least 20 GB storage available&lt;br /&gt;
* Internet access for installation and model download &lt;br /&gt;
* optional for a supported NVIDIA or AMD-GPU&lt;br /&gt;
&lt;br /&gt;
Verify the intalled Ubuntu version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;cat /etc/os-release&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install &amp;lt;code&amp;gt;curl&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo apt install -y curl&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Install Ollama == &lt;br /&gt;
Execute the official installation script:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl -fsSL https://ollama.com/install.sh | sh&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 1: Output of Ollama installation script --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, verify the installed version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama -v&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The installation script sets up a systemd-service. Check its status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl status ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The service should be displayed with the &amp;lt;code&amp;gt;active (running)&amp;lt;/code&amp;gt; state.&lt;br /&gt;
&lt;br /&gt;
If the service is not started, it can be activated manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl enable --now ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Start initial model ==&lt;br /&gt;
&lt;br /&gt;
In this example, &amp;lt;code&amp;gt;gemma3:4b&amp;lt;/code&amp;gt; is used. The model requires approximately 2.2 GB storage for the download and is suitable for the initial function test.&lt;br /&gt;
&lt;br /&gt;
Start the model:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama run gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ollama automatically downloads the model the first time it is runned. It may take a few minutes depending on the Internet connection.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 2: Download and start of gemma3:4b --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, enter the following query, for example:&lt;br /&gt;
&lt;br /&gt;
:Explain the difference between RAID 5 and RAID 6.&lt;br /&gt;
&lt;br /&gt;
Finish the session with:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;/bye&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Display the installed models:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ls&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Verify GPU-usage == &lt;br /&gt;
&lt;br /&gt;
Ollama automatically uses a supported GPU if the required driver is installed.&lt;br /&gt;
&lt;br /&gt;
Start the model and open the second SSH-session:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama run gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the current version there:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ps&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The column &amp;lt;code&amp;gt;PROCESSOR&amp;lt;/code&amp;gt; displays if the model is executed on the CPU, GPU or on both.&lt;br /&gt;
&lt;br /&gt;
With an NVIDIA GPU, you can also check the utilization:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;nvidia-smi&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If there is no supported GPU available, Ollama executes the model via CPU and RAM. Response times are generally longer in such cases.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 3: Output from ollama ps and optionally nvidia-smi --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Check Ollama-API == &lt;br /&gt;
&lt;br /&gt;
Ollama provides a local HTTP-API on port &amp;lt;code&amp;gt;11434&amp;lt;/code&amp;gt; by default. &lt;br /&gt;
&lt;br /&gt;
Display the models available via API:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl http://127.0.0.1:11434/api/tags&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the connection is successful, a JSON response containing the installed models is returned.&lt;br /&gt;
&lt;br /&gt;
The local API is, for example, used by Open WebUI, n8n and own applications.&lt;br /&gt;
&lt;br /&gt;
== Optional: Acces from the local network == &lt;br /&gt;
&lt;br /&gt;
By default, Ollama only listens on &amp;lt;code&amp;gt;127.0.0.1&amp;lt;/code&amp;gt;. If another system should access the API in the local network, the Bind address must be adjusted.&lt;br /&gt;
&lt;br /&gt;
Open the systemd extension:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl edit ollama.service&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;ini&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;[Service]&lt;br /&gt;
Environment=&amp;quot;OLLAMA_HOST=0.0.0.0:11434&amp;quot;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Apply changes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo systemctl daemon-reload&lt;br /&gt;
sudo systemctl restart ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, verify the port:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ss -tulpn | grep 11434&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By default, the Ollama API does not have its own user authentication for locally run models. Port &amp;lt;code&amp;gt;11434&amp;lt;/code&amp;gt; should therefore only be released for reuqired systems and should not be directly available from the Internet.&lt;br /&gt;
&lt;br /&gt;
Here is an example for the release of an internal subnet with UFW:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ufw allow from 192.168.1.0/24 to any port 11434 proto tcp&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Customize the subnet to suit your own environment.&lt;br /&gt;
&lt;br /&gt;
Further Ollama environment variables can be added in the same systemd-extension. All &amp;lt;code&amp;gt;Environment=&amp;quot;...&amp;quot;&amp;lt;/code&amp;gt; lines are entered together under a &amp;lt;code&amp;gt;[Service]&amp;lt;/code&amp;gt; block.&lt;br /&gt;
&lt;br /&gt;
== Update Ollama ==&lt;br /&gt;
&lt;br /&gt;
On Linux, Ollama is updated by running the installation script again:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl -fsSL https://ollama.com/install.sh | sh&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Models that have already been downloaded will remain.&lt;br /&gt;
&lt;br /&gt;
After that, check the version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama -v&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== Ollama-service does not run ===&lt;br /&gt;
&lt;br /&gt;
Verify the service status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl status ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Display the most recent log entries:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo journalctl -e -u ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Model does not start ===&lt;br /&gt;
&lt;br /&gt;
Check the available storage space:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;df -h&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Display the installed models:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ls&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If necessary, download the model again:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama pull gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Port 11434 is not available ===&lt;br /&gt;
&lt;br /&gt;
Check if Ollama listens on the port:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ss -tulpn | grep 11434&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart the service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl restart ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://docs.ollama.com/linux Ollama Documentation – Linux] (en)&lt;br /&gt;
* [https://docs.ollama.com/quickstart Ollama Documentation – Quickstart] (en)&lt;br /&gt;
* [https://docs.ollama.com/api/introduction Ollama Documentation – API Introduction] (en)&lt;br /&gt;
* [https://docs.ollama.com/faq Ollama Documentation – FAQ] (en)&lt;br /&gt;
* [https://ollama.com/library/gemma3:4b Ollama Model Library – Gemma 3 4B] (en)&lt;br /&gt;
* [https://ubuntu.com/about/release-cycle Ubuntu Release Cycle] (en)&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Artificial Intelligence]]&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de: Ollama installieren]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Failed_to_fetch_enterprise.proxmox.com_401_Unauthorized</id>
		<title>Failed to fetch enterprise.proxmox.com 401 Unauthorized</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Failed_to_fetch_enterprise.proxmox.com_401_Unauthorized"/>
		<updated>2026-07-16T12:53:03Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;Proxmox Server Solutions GmbH from Vienna provides two package repositories for Proxmox VE: &amp;#039;&amp;#039;&amp;#039;Proxmox VE Enterprise Repository&amp;#039;&amp;#039;&amp;#039; (subject to a fee, recommended for productive use) and &amp;#039;&amp;#039;&amp;#039;Proxmox VE No-Subscription Repository&amp;#039;&amp;#039;&amp;#039; (free of charge, recommended for testing purposes). After Installation of Proxmox VE, the following error message appears when trying to install updates: &amp;#039;&amp;#039;&amp;#039;&amp;lt;nowiki&amp;gt;Failed to fetch https://enterprise.proxmox.com/debian/pve/dists/buster/I...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Proxmox Server Solutions GmbH from Vienna provides two package repositories for [[Proxmox VE]]: &amp;#039;&amp;#039;&amp;#039;Proxmox VE Enterprise Repository&amp;#039;&amp;#039;&amp;#039; (subject to a fee, recommended for productive use) and &amp;#039;&amp;#039;&amp;#039;Proxmox VE No-Subscription Repository&amp;#039;&amp;#039;&amp;#039; (free of charge, recommended for testing purposes). After [[Installation of Proxmox VE]], the following error message appears when trying to install updates: &amp;#039;&amp;#039;&amp;#039;&amp;lt;nowiki&amp;gt;Failed to fetch https://enterprise.proxmox.com/debian/pve/dists/buster/InRelease 401 Unauthorized&amp;lt;/nowiki&amp;gt;&amp;#039;&amp;#039;&amp;#039;. This article shows how to solve this error by either setting up a paid subscription to the Enterprise Repository or, alternatively, using the free No-Subscription Repository. &lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
[[File:Proxmox_8_Updates_Refresh_Error.png|thumb|right|After the installation, Proxmox VE displays the following error message when trying to install the updates. The access to &amp;#039;&amp;#039;&amp;#039;Proxmox VE Enterprise Repository&amp;#039;&amp;#039;&amp;#039; can be unlocked with a subscription key. Alternatively, the &amp;#039;&amp;#039;&amp;#039;Proxmox VE No-Subscription Repository&amp;#039;&amp;#039;&amp;#039; is available for testing purposes.]] After the installation of Proxmox VE, the following message appears without further configuration when trying to install updates:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Header&lt;br /&gt;
Proxmox&lt;br /&gt;
Virtual Environment 8.1.3&lt;br /&gt;
Node &amp;#039;pve&amp;#039;&lt;br /&gt;
Show details&lt;br /&gt;
Logs&lt;br /&gt;
()&lt;br /&gt;
starting apt-get update&lt;br /&gt;
Get:1 http://security.debian.org bookworm-security InRelease [48.0 kB]&lt;br /&gt;
[...]&lt;br /&gt;
Get:9 http://ftp.at.debian.org/debian bookworm/main Translation-en [6109 kB]&lt;br /&gt;
Err:10 https://enterprise.proxmox.com/debian/ceph-quincy bookworm InRelease&lt;br /&gt;
  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
Err:11 https://enterprise.proxmox.com/debian/pve bookworm InRelease&lt;br /&gt;
  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
Get:12 http://ftp.at.debian.org/debian bookworm/contrib amd64 Packages [54.1 kB]&lt;br /&gt;
Get:13 http://ftp.at.debian.org/debian bookworm/contrib Translation-en [48.7 kB]&lt;br /&gt;
Get:14 http://ftp.at.debian.org/debian bookworm-updates/main amd64 Packages [12.7 kB]&lt;br /&gt;
Get:15 http://ftp.at.debian.org/debian bookworm-updates/main Translation-en [13.8 kB]&lt;br /&gt;
Reading package lists...&lt;br /&gt;
E: Failed to fetch https://enterprise.proxmox.com/debian/ceph-quincy/dists/bookworm/InRelease  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
E: The repository &amp;#039;https://enterprise.proxmox.com/debian/ceph-quincy bookworm InRelease&amp;#039; is not signed.&lt;br /&gt;
E: Failed to fetch https://enterprise.proxmox.com/debian/pve/dists/bookworm/InRelease  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
E: The repository &amp;#039;https://enterprise.proxmox.com/debian/pve bookworm InRelease&amp;#039; is not signed.&lt;br /&gt;
TASK ERROR: command &amp;#039;apt-get update&amp;#039; failed: exit code 100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Solution 1: Proxmox VE Enterprise Repository == &lt;br /&gt;
This is the default, stable and recommended repository that is available for all users of Proxmox VE subcriptions. It contains the most stable packages and is suitable for production use. The pve-enterprise Repository is activated by default (/etc/apt/sources.list.d/pve-enterprise.list).&lt;br /&gt;
&lt;br /&gt;
Information on the subscriptions available can be found in the article [[Proxmox VE Support-Subscriptions]].&lt;br /&gt;
&lt;br /&gt;
== Solution 2: Proxmox VE No-Subscription Repository == &lt;br /&gt;
This is the repository that is recommended for testing and non-production purposes. The included packages are not as intensively tested and validated as those from the Proxmox VE Enterprise Repository. There is no subscription key required for the access on the pve-no-subscription Repository.&lt;br /&gt;
&lt;br /&gt;
The following settings must be selected in /etc/apt/sources.list for using the No-Subscription Repository:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
deb http://ftp.at.debian.org/debian bookworm main contrib&lt;br /&gt;
deb http://ftp.at.debian.org/debian bookworm-updates main contrib&lt;br /&gt;
&lt;br /&gt;
# PVE pve-no-subscription repository provided by proxmox.com,&lt;br /&gt;
# NOT recommended for production use&lt;br /&gt;
deb http://download.proxmox.com/debian/pve bookworm pve-no-subscription&lt;br /&gt;
&lt;br /&gt;
# security updates&lt;br /&gt;
deb http://security.debian.org bookworm-security main contrib&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Note: So that the message &amp;quot;failed to fetch&amp;quot; disappears permanently, you must comment out the respective repository listed in each file by adding a &amp;quot;#&amp;quot; before it in the following two files:&lt;br /&gt;
* /etc/apt/sources.list.d/pve-enterprise.list:&lt;br /&gt;
*: &amp;lt;pre&amp;gt;# deb https://enterprise.proxmox.com/debian/pve bookworm pve-enterprise&amp;lt;/pre&amp;gt;&lt;br /&gt;
* /etc/apt/sources.list.d/ceph.list:&lt;br /&gt;
*: &amp;lt;pre&amp;gt;# deb https://enterprise.proxmox.com/debian/ceph-quincy bookworm enterprise&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://pve.proxmox.com/wiki/Package_Repositories Package Repositories] (pve.proxmox.com/wiki)&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Proxmox Troubleshooting]]&lt;br /&gt;
[[de:Failed to fetch enterprise.proxmox.com 401 Unauthorized]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Synology_UC3400_Metadata-Overflow</id>
		<title>Synology UC3400 Metadata-Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Synology_UC3400_Metadata-Overflow"/>
		<updated>2026-07-15T12:03:11Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;right On the Synology UC3400, a very high number of metadata objects (&amp;gt;10 million) leads to a critical condition in combination with migrations and snapshot load that may cause CPU and RAM overloads and cause migrations to fail.   This article describes symptoms and provides possible solutions.  == Initial situation == The UC3400 administrates SAN and LUN structures with the help of a internal metadata database. When there is...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[file:UC3400_Front.png|frameless|322x322px|right]]&lt;br /&gt;
On the Synology UC3400, a very high number of metadata objects (&amp;gt;10 million) leads to a critical condition in combination with migrations and snapshot load that may cause CPU and RAM overloads and cause migrations to fail. &lt;br /&gt;
&lt;br /&gt;
This article describes symptoms and provides possible solutions.&lt;br /&gt;
&lt;br /&gt;
== Initial situation ==&lt;br /&gt;
The UC3400 administrates SAN and LUN structures with the help of a internal metadata database. When there is a very large number of objects, the metadata can grow significantly. In addition, long snapshot chains, numerous copy-on-write operations, and the simultaneous processing of I/O and metadata accesses lead to increased system load. &lt;br /&gt;
&lt;br /&gt;
The situation becomes particularly critical when there is a high number of snapshots, long operation hours without reorganisation, the migration of more extensive LUNs or the high rates of changes within a short time. &lt;br /&gt;
&lt;br /&gt;
== Problem description ==&lt;br /&gt;
When there are more than &amp;#039;&amp;#039;&amp;#039;approximately 10 million metadata objects&amp;#039;&amp;#039;&amp;#039;, a significant system overload occurs on the UC3400. This condition is often referred to as &amp;#039;&amp;#039;&amp;#039;Metadata overflow&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
Possible symptoms are:&lt;br /&gt;
&lt;br /&gt;
* CPU-/RAM-load permanently close to 100%&lt;br /&gt;
* migrations are canceled or &amp;quot;timeouted&amp;quot;&lt;br /&gt;
* system reacts very slowly&lt;br /&gt;
* storage and snapshot operations block each other&lt;br /&gt;
* SAN-services fail temporarily &lt;br /&gt;
* risk for inconsistent LUN conditions increases &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;The following applies to the Synology UC3400:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
* &amp;lt; 5 million objects → stable&lt;br /&gt;
* 5–10 million objects → marginal&lt;br /&gt;
* 10 million objects → critical (overflow risk)&lt;br /&gt;
* 50 milion objects → can only be operated effectively with significant optimization&lt;br /&gt;
&lt;br /&gt;
== &amp;#039;&amp;#039;&amp;#039;Immediate measures&amp;#039;&amp;#039;&amp;#039; ==&lt;br /&gt;
The following measures can be implemented to restore operational capability quickly:&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; These measures are intended solely as temporary workarounds and do not constitute a long-term solution for production operations. &lt;br /&gt;
* stop migration&lt;br /&gt;
* reduce snapshot load&lt;br /&gt;
* restart services (only in maintenance window)&lt;br /&gt;
&lt;br /&gt;
== &amp;#039;&amp;#039;&amp;#039;Recommended solution strategy&amp;#039;&amp;#039;&amp;#039; ==&lt;br /&gt;
The most sustainable solution is a reorganization of the LUN-structure and a migration into smaller, clearly separated units.&lt;br /&gt;
&lt;br /&gt;
=== Create new LUN ===&lt;br /&gt;
The most stable method is:&lt;br /&gt;
&lt;br /&gt;
# create new LUN&lt;br /&gt;
# transmit data via storage migration or backup restore&lt;br /&gt;
# delete old LUN&lt;br /&gt;
&lt;br /&gt;
As a result, all old metadata will be deleted completely.&lt;br /&gt;
&lt;br /&gt;
=== Alternative: Metadata-Rebuild ===&lt;br /&gt;
{| {{Prettytable}} cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;margin: 1em 1em 1em 0; background: #f9f9f9; border: 1px #a0a0a0 solid; border-collapse: collapse; &amp;quot; rules=&amp;quot;all&amp;quot;&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Note: A Metadata-Rebuild should be only performed if there is a current and functional backup of all relevant data!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This risky procedure is intended solely as a last resort for recovery after all other diagnostic and repair measures have been proven unsuccessful.&lt;br /&gt;
&lt;br /&gt;
Only with complete backup:&lt;br /&gt;
&lt;br /&gt;
* metadata structure is deleted and recreated&lt;br /&gt;
* risk of iSCSI-Mapping losses&lt;br /&gt;
* only recommended for emergencies&lt;br /&gt;
== Prevention == &lt;br /&gt;
To avoid the above mentioned problems, the following measures can be implemented:&lt;br /&gt;
* limit snapshot number&lt;br /&gt;
* LUN-recreation for long durations on a regular basis&lt;br /&gt;
* unload metadata regularly &lt;br /&gt;
* divide migrations in smaller sessions&lt;br /&gt;
* monitoring of CPU / RAM and SAN metadata load &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Recommendation:&amp;#039;&amp;#039;&amp;#039; When migrating large amounts of data, you should involve Synology Support early on. This way, they can assist with the data migration if needed, and you will receive recommendations on best practices to minimize risks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Wsuess}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Storage]]&lt;br /&gt;
[[de:Synology UC3400 Metadaten-Overflow]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/IPMI_BMC_reset_for_IPMI_problems</id>
		<title>IPMI BMC reset for IPMI problems</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/IPMI_BMC_reset_for_IPMI_problems"/>
		<updated>2026-07-09T11:34:27Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If there are any problems with IPMI or Remote Management Webinterface, the BMC (Baseboard Management Controller) can be &amp;#039;&amp;#039;&amp;#039;restartet&amp;#039;&amp;#039;&amp;#039; using the &amp;#039;&amp;#039;&amp;#039;IPMItool&amp;#039;&amp;#039;&amp;#039;. In this example, it is explained how to restart the BMC in Linux with ipmitool.&lt;br /&gt;
&lt;br /&gt;
== IPMI BMC reset via ipmitool (remote) ==&lt;br /&gt;
If the server does not run on Linux, ipmitool can be executed on a Linux computer to restart the BMC of another server by using its IPMI IP address.&lt;br /&gt;
&lt;br /&gt;
The command for the reset of the module on the server  10.0.0.1 (default user and pw) is as follows:&lt;br /&gt;
 ipmitool mc reset cold -I lan -H 10.0.0.1 -U admin -P password  &lt;br /&gt;
&lt;br /&gt;
The last parameter is optional. It is prompted for the password if it has not been entered yet.  Communication between the ipmitool on the Linux system and the IPMI BMC of the server takes place via UDP port 623.&lt;br /&gt;
&lt;br /&gt;
== IPMI BMC reset via ipmitool (local) ==&lt;br /&gt;
If Linux is installed on the server itself, BMC can be reset locally (with root rights):&lt;br /&gt;
 ipmitool mc reset cold&lt;br /&gt;
&lt;br /&gt;
== Alternative: Turn off server == &lt;br /&gt;
If the described procedure does not function with a reset via IPMI command, there is always the possibility to shut down the server and to turn off the power for 30 seconds then. To do this, the server must be disconnected completely from the power supply. This procedure also leads to a reset of the BMC.&lt;br /&gt;
&lt;br /&gt;
== Recreate default settings ==&lt;br /&gt;
If you also want to recreate default settings, you can use the ipmicfg tool for Supermicro-based systems (see also [[IPMICFG#Recreation of default settings]]).&lt;br /&gt;
&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Remote Management]]&lt;br /&gt;
[[de:IPMI BMC reset bei IPMI Problemen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Windows_Server_2025:_Differences_between_editions</id>
		<title>Windows Server 2025: Differences between editions</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Windows_Server_2025:_Differences_between_editions"/>
		<updated>2026-07-09T07:41:43Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;Microsoft  Windows Server 2025 is an operating system of the Windows series and the successor of  Windows Server 2022.  This article presents the differences between Windows Server 2025 editions. Pricing information on Windows Server 2025 can be found in the Thomas-Krenn online shop at &amp;lt;tklink type=sitex id=18135/&amp;gt;. For Windows Server 2025, Microsoft is now adopting the same approach it used for Window...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Microsoft [[:Category:Windows Server 2025 | Windows Server 2025]] is an operating system of the Windows series and the successor of [[:Category:Windows Server 2022 | Windows Server 2022]].&lt;br /&gt;
&lt;br /&gt;
This article presents the differences between Windows Server 2025 editions. Pricing information on Windows Server 2025 can be found in the Thomas-Krenn online shop at &amp;lt;tklink type=sitex id=18135/&amp;gt;. For Windows Server 2025, Microsoft is now adopting the same approach it used for Windows Server 2019 and Windows Server 2022, which is a &amp;#039;&amp;#039;&amp;#039;Core Licensing&amp;#039;&amp;#039;&amp;#039;. Information on this new licensing model can be found in the article [[Windows Server Core-Lizenzierung|Windows Server Core Licensing]].&lt;br /&gt;
&lt;br /&gt;
== Editions ==&lt;br /&gt;
Microsoft Windows Server 2025 is available in four different editions:&lt;br /&gt;
* Essentials&lt;br /&gt;
* Standard&lt;br /&gt;
* Datacenter&lt;br /&gt;
*Datacenter Azure Edition&lt;br /&gt;
&lt;br /&gt;
These four editions are suitable for the following application areas:&lt;br /&gt;
{| {{Prettytable}} width=&amp;quot;1000px&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! Edition|| Suitable for... || Virtualization rights || Access licenses || CPU limit &lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Essentials&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| small companies with basic IT needs; very small IT department or no IT department of their own&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| Installation: 1 physical &amp;#039;&amp;#039;&amp;#039;or&amp;#039;&amp;#039;&amp;#039; 1 virtual *&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| no CALs required (limited to 25 users / 50 devices)&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| max. 1 CPU, max. 10 cores&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Standard&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| for all companies that require extended features and virtualize to a lesser extent &lt;br /&gt;
|align=&amp;quot;center&amp;quot;| 2 virtual Windows Server machines&amp;lt;sup&amp;gt;**&amp;lt;/sup&amp;gt;&lt;br /&gt;
| rowspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; | CALs required&amp;lt;sup&amp;gt;***&amp;lt;/sup&amp;gt;&lt;br /&gt;
|align=&amp;quot;center&amp;quot; rowspan=&amp;quot;2&amp;quot;| unlimited cores&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Datacenter&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| for all companies with high IT workload needs and with a high number of virtual systems &lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | An unlimited number of virtual Windows Server machines&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Datacenter Azure Edition&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| small companies with basic IT needs; very small IT department or no IT department on their own  &lt;br /&gt;
|align=&amp;quot;center&amp;quot;| 2,048 logical processors &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
:&amp;lt;sup&amp;gt;(*) The Windows Server Essentials license allows an installation of a physical and virtual Essentials Server if the physical server only provides the Hyper-V role for the virtualization of the Essentials Server.&amp;lt;ref&amp;gt;[https://www.microsoft.com/licensing/terms/productoffering/WindowsServerStandardDatacenterEssentials/OL#UseRights Windows Server Standard, Datacenter, and Essentials] (EN) (www.microsoft.com/licensing/terms)&amp;lt;/ref&amp;gt;&amp;lt;/sup&amp;gt;&lt;br /&gt;
:&amp;lt;sup&amp;gt;(**) The Windows Server Standard Edition License allows 2 OSEs (operating system environments) if all physical cores are licensed.&amp;lt;/sup&amp;gt;&lt;br /&gt;
:&amp;lt;sup&amp;gt;(***) CALs are required for every user or for every device, which accesses a server directly or indirectly. Detailed information on this topic can be found on the Microsoft website. &amp;lt;ref&amp;gt;[https://www.microsoft.com/en-us/licensing/product-licensing/client-access-license Client Access Licenses and Management Licenses] (EN) (www.microsoft.com)&amp;lt;/ref&amp;gt;&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minimum hardware requirements for Windows Server 2025 ==&lt;br /&gt;
The following table presents the official minimum requirements for Windows Server 2025.&amp;lt;ref&amp;gt;[https://learn.microsoft.com/de-de/windows-server/get-started/hardware-requirements?tabs=cpu&amp;amp;pivots=windows-server-2025 Windows Server 2025 - Hardware Requirements] (DE) (www.learn.microsoft.com)&amp;lt;/ref&amp;gt; The actual requirements are dependent on the system configuration and on the installed applications and features.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;margin: 1em 1em 1em 0; background: #f9f9f9; border: 1px #a0a0a0 solid; border-collapse: collapse; &amp;quot; rules=&amp;quot;all&amp;quot; width=&amp;quot;650px&amp;quot; cellspacing=&amp;quot;0&amp;quot; {{Prettytable}}&lt;br /&gt;
|- |- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! Description || Minimum requirements&lt;br /&gt;
|-&lt;br /&gt;
|Processor architecture || x64&lt;br /&gt;
|-&lt;br /&gt;
|Processor speed || 1,4 GHz&lt;br /&gt;
|-&lt;br /&gt;
|Storage (RAM) || 512 MB&amp;lt;sup&amp;gt;*&amp;lt;/sup&amp;gt; (recommended: ECC or similar technologies)&lt;br /&gt;
|-&lt;br /&gt;
|Hard drive storage space || 32 GB&amp;lt;sup&amp;gt;**&amp;lt;/sup&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Network card || 1x Ethernet with a minimum throughput in the 1 GBit/s-range&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
:&amp;lt;sup&amp;gt;(*) 2GB for server with &amp;quot;desktop view&amp;quot;.&amp;lt;/sup&amp;gt;&lt;br /&gt;
:&amp;lt;sup&amp;gt;(**) Computer with more than 16 GB RAM require larger storage space for paging, hibernation, and backup files.&amp;lt;/sup&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== What is new in Windows Server 2025 ==&lt;br /&gt;
In Windows Server 2022, the list of the new features is relatively short. Microsoft focuses on the new operating system Azure Stack HCI with new features. &lt;br /&gt;
&lt;br /&gt;
We can look forward to the following new features in Windows Server 2025:&amp;lt;ref&amp;gt;[https://learn.microsoft.com/de-de/windows-server/get-started/whats-new-windows-server-2025 Windows Server 2025 - News] (DE) (www.learn.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Hotpatching&lt;br /&gt;
* TLS 1.3&lt;br /&gt;
* Improved Active Directory&lt;br /&gt;
* Optimized and improved performance for virtual machines and containers&lt;br /&gt;
* Improved administration&lt;br /&gt;
&lt;br /&gt;
== Removed or not further developed features in Windows Server 2025 ==&lt;br /&gt;
In Windows Server 2025, there are few features that were not further developed or that were removed from Windows Server 2025.&lt;br /&gt;
&lt;br /&gt;
The following features will no longer be included in Windows Server 2025:&amp;lt;ref&amp;gt;[https://learn.microsoft.com/de-de/windows-server/get-started/removed-deprecated-features-windows-server-2025 Windows Server 2025 - Removed Features] (DE) (www.learn.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 * IIS 6 administration console(Web-Lgcy-Mgmt-Console)&lt;br /&gt;
* NTLMv1&lt;br /&gt;
* WordPad&lt;br /&gt;
* SMTP-Server&lt;br /&gt;
* Windows PowerShell 2.0 Engine&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{bbayer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Windows Server 2025]]&lt;br /&gt;
[[de:Windows Server 2025 Editionsunterschiede]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/How_to:_Install_Nextcloud_with_an_NFS_data_directory</id>
		<title>How to: Install Nextcloud with an NFS data directory</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/How_to:_Install_Nextcloud_with_an_NFS_data_directory"/>
		<updated>2026-07-09T07:09:37Z</updated>

		<summary type="html">&lt;p&gt;Smueller: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes how to install Nextcloud Server on Ubuntu 26.04 LTS. Apache with PHP-FPM is used as the web server, while MariaDB provides the required database.&lt;br /&gt;
&lt;br /&gt;
The actual Nextcloud user data is stored on an NFS-mounted storage system. The NFS storage is used as the primary Nextcloud data directory and is not integrated through the Nextcloud “External Storage” app.&lt;br /&gt;
&lt;br /&gt;
This guide uses the following example values:&lt;br /&gt;
&lt;br /&gt;
* Nextcloud address: &amp;lt;code&amp;gt;cloud.example.com&amp;lt;/code&amp;gt;&lt;br /&gt;
* NFS server: &amp;lt;code&amp;gt;nfs.example.com&amp;lt;/code&amp;gt;&lt;br /&gt;
* NFS export: &amp;lt;code&amp;gt;/nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Local NFS mount point: &amp;lt;code&amp;gt;/srv/nextcloud-data&amp;lt;/code&amp;gt;&lt;br /&gt;
* Nextcloud directory: &amp;lt;code&amp;gt;/var/www/nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database name: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database user: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Adjust these values to match your environment.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; In this setup, the NFS storage is part of the primary Nextcloud storage. If the NFS server is unavailable, the Nextcloud data directory will also be unavailable.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
The following components are required for this guide:&lt;br /&gt;
&lt;br /&gt;
* Ubuntu Server 26.04 LTS, 64-bit&lt;br /&gt;
* Apache 2.4&lt;br /&gt;
* PHP 8.5 with PHP-FPM&lt;br /&gt;
* MariaDB 11.8&lt;br /&gt;
* Redis&lt;br /&gt;
* An accessible NFSv4 export&lt;br /&gt;
* A DNS record for the Nextcloud domain&lt;br /&gt;
* TCP ports 80 and 443 must be reachable&lt;br /&gt;
&lt;br /&gt;
For a small installation, the following resources can be used as an example:&lt;br /&gt;
&lt;br /&gt;
* 4 vCPUs&lt;br /&gt;
* 4 GiB RAM&lt;br /&gt;
* At least 20 GiB of local storage for the operating system, Nextcloud application, database and logs&lt;br /&gt;
* Separate storage for the Nextcloud data directory&lt;br /&gt;
&lt;br /&gt;
The actual resource requirements depend on factors such as the number of users, installed apps, number of files and concurrent access.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important:&amp;#039;&amp;#039;&amp;#039; NFS storage does not replace a backup. A complete backup must include at least the Nextcloud data directory, the MariaDB database and the Nextcloud configuration.&lt;br /&gt;
&lt;br /&gt;
== Preparing the system ==&lt;br /&gt;
&lt;br /&gt;
The following commands are executed as the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; user.&lt;br /&gt;
&lt;br /&gt;
First update the operating system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
apt full-upgrade -y&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a new kernel was installed, restart the system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
reboot&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then verify the installed Ubuntu version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat /etc/os-release&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should contain the following information, among other values:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
VERSION_ID=&amp;quot;26.04&amp;quot;&lt;br /&gt;
VERSION_CODENAME=resolute&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Installing the required packages ==&lt;br /&gt;
&lt;br /&gt;
Install Apache, MariaDB, PHP 8.5, Redis and the required PHP extensions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt install -y \&lt;br /&gt;
    apache2 \&lt;br /&gt;
    mariadb-server \&lt;br /&gt;
    php8.5-fpm \&lt;br /&gt;
    php8.5-cli \&lt;br /&gt;
    php8.5-common \&lt;br /&gt;
    php8.5-curl \&lt;br /&gt;
    php8.5-gd \&lt;br /&gt;
    php8.5-gmp \&lt;br /&gt;
    php8.5-imagick \&lt;br /&gt;
    php8.5-intl \&lt;br /&gt;
    php8.5-mbstring \&lt;br /&gt;
    php8.5-mysql \&lt;br /&gt;
    php8.5-xml \&lt;br /&gt;
    php8.5-zip \&lt;br /&gt;
    php8.5-bcmath \&lt;br /&gt;
    php8.5-bz2 \&lt;br /&gt;
    php8.5-apcu \&lt;br /&gt;
    php8.5-redis \&lt;br /&gt;
    redis-server \&lt;br /&gt;
    nfs-common \&lt;br /&gt;
    cron \&lt;br /&gt;
    bzip2 \&lt;br /&gt;
    wget&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable and start the required services:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl enable --now \&lt;br /&gt;
    apache2 \&lt;br /&gt;
    mariadb \&lt;br /&gt;
    php8.5-fpm \&lt;br /&gt;
    redis-server \&lt;br /&gt;
    cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the installed PHP version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 --version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should begin with &amp;lt;code&amp;gt;PHP 8.5&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The loaded PHP modules can be checked with the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 -m&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following modules should be present, among others:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apcu&lt;br /&gt;
curl&lt;br /&gt;
dom&lt;br /&gt;
fileinfo&lt;br /&gt;
gd&lt;br /&gt;
gmp&lt;br /&gt;
imagick&lt;br /&gt;
intl&lt;br /&gt;
mbstring&lt;br /&gt;
mysqli&lt;br /&gt;
openssl&lt;br /&gt;
pdo_mysql&lt;br /&gt;
redis&lt;br /&gt;
SimpleXML&lt;br /&gt;
xml&lt;br /&gt;
xmlreader&lt;br /&gt;
xmlwriter&lt;br /&gt;
zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring PHP 8.5 ==&lt;br /&gt;
&lt;br /&gt;
Nextcloud requires suitable PHP settings for both PHP-FPM and command-line PHP calls.&lt;br /&gt;
&lt;br /&gt;
=== Configuring PHP-FPM ===&lt;br /&gt;
&lt;br /&gt;
Create a dedicated PHP configuration file for Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/php/8.5/fpm/conf.d/99-nextcloud.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
memory_limit = 512M&lt;br /&gt;
upload_max_filesize = 10G&lt;br /&gt;
post_max_size = 10G&lt;br /&gt;
max_execution_time = 3600&lt;br /&gt;
max_input_time = 3600&lt;br /&gt;
output_buffering = 0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The values for &amp;lt;code&amp;gt;upload_max_filesize&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;post_max_size&amp;lt;/code&amp;gt; determine the maximum file size that can be uploaded through the web interface. Adjust these values to suit your environment if required.&lt;br /&gt;
&lt;br /&gt;
=== Configuring PHP CLI ===&lt;br /&gt;
&lt;br /&gt;
The PHP command-line interface is used for cron jobs, maintenance tasks and the Nextcloud updater.&lt;br /&gt;
&lt;br /&gt;
Create the following configuration file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/php/8.5/cli/conf.d/99-nextcloud.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
memory_limit = 512M&lt;br /&gt;
apc.enable_cli = 1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 --ini&lt;br /&gt;
php8.5 -i | grep -E &amp;#039;memory_limit|apc.enable_cli&amp;#039;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart PHP-FPM:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the service status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Setting up the NFS data directory ==&lt;br /&gt;
&lt;br /&gt;
=== Creating the mount point ===&lt;br /&gt;
&lt;br /&gt;
Create the local mount point:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkdir -p /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuring the NFS mount ===&lt;br /&gt;
&lt;br /&gt;
Add the following line to &amp;lt;code&amp;gt;/etc/fstab&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nfs.example.com:/nextcloud /srv/nextcloud-data nfs4 rw,hard,_netdev,x-systemd.automount 0 0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Adjust the NFS server and export path to match your environment.&lt;br /&gt;
&lt;br /&gt;
Reload the systemd configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl daemon-reload&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Access the mount point to trigger the automatic mount:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ls -la /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, the mount can be triggered manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mount /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify that the NFS file system has been mounted:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
findmnt /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
TARGET                  SOURCE                         FSTYPE OPTIONS&lt;br /&gt;
/srv/nextcloud-data     nfs.example.com:/nextcloud    nfs4   rw,relatime,...&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Only continue with the installation if &amp;lt;code&amp;gt;/srv/nextcloud-data&amp;lt;/code&amp;gt; is actually mounted as an NFS file system.&lt;br /&gt;
&lt;br /&gt;
=== Setting permissions ===&lt;br /&gt;
&lt;br /&gt;
Apache and PHP-FPM run as the &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt; user by default on Ubuntu.&lt;br /&gt;
&lt;br /&gt;
Check its UID and GID:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
id www-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By default, Ubuntu uses UID and GID &amp;lt;code&amp;gt;33&amp;lt;/code&amp;gt; for &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The NFS directory must allow the &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt; user to write to it. If NFS &amp;lt;code&amp;gt;root_squash&amp;lt;/code&amp;gt; is enabled, ownership usually cannot be changed from the Nextcloud server. In this case, set the permissions directly on the NFS server.&lt;br /&gt;
&lt;br /&gt;
Example on the NFS server:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chown -R 33:33 /path/to/export/nextcloud&lt;br /&gt;
chmod 0750 /path/to/export/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then perform a write test on the Nextcloud server as the &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt; user:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data touch /srv/nextcloud-data/.write-test&lt;br /&gt;
sudo -u www-data rm /srv/nextcloud-data/.write-test&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If this test fails, correct the NFS export settings, UID/GID mapping or file system permissions before continuing.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The data directory should be used exclusively by Nextcloud. Files should not be modified directly on the NFS share in parallel.&lt;br /&gt;
&lt;br /&gt;
=== Making Apache and PHP-FPM depend on the NFS mount ===&lt;br /&gt;
&lt;br /&gt;
To prevent the relevant services from starting without the data directory being available, systemd dependencies can be configured.&lt;br /&gt;
&lt;br /&gt;
First create a dependency for Apache:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl edit apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[Unit]&lt;br /&gt;
RequiresMountsFor=/srv/nextcloud-data&lt;br /&gt;
Wants=network-online.target&lt;br /&gt;
After=network-online.target&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then create the corresponding dependency for PHP-FPM:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl edit php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration there as well:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[Unit]&lt;br /&gt;
RequiresMountsFor=/srv/nextcloud-data&lt;br /&gt;
Wants=network-online.target&lt;br /&gt;
After=network-online.target&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Reload the systemd configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl daemon-reload&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the configured dependencies:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl cat apache2&lt;br /&gt;
systemctl cat php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring MariaDB ==&lt;br /&gt;
&lt;br /&gt;
=== Setting the transaction isolation level ===&lt;br /&gt;
&lt;br /&gt;
Nextcloud requires the &amp;lt;code&amp;gt;READ-COMMITTED&amp;lt;/code&amp;gt; transaction isolation level for MySQL or MariaDB.&lt;br /&gt;
&lt;br /&gt;
Create the following configuration file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/mysql/mariadb.conf.d/99-nextcloud.cnf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[mysqld]&lt;br /&gt;
transaction-isolation = READ-COMMITTED&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If MariaDB binary logging is enabled, the &amp;lt;code&amp;gt;ROW&amp;lt;/code&amp;gt; format must also be used:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[mysqld]&lt;br /&gt;
transaction-isolation = READ-COMMITTED&lt;br /&gt;
binlog_format = ROW&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart MariaDB:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart mariadb&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the configured transaction isolation level:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mariadb -e &amp;quot;SHOW VARIABLES LIKE &amp;#039;transaction_isolation&amp;#039;;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should contain the following value:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
READ-COMMITTED&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Creating the database and user ===&lt;br /&gt;
&lt;br /&gt;
Open the MariaDB console:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mariadb&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Create the database and a database user that can only connect locally:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CREATE DATABASE nextcloud&lt;br /&gt;
    CHARACTER SET utf8mb4&lt;br /&gt;
    COLLATE utf8mb4_general_ci;&lt;br /&gt;
&lt;br /&gt;
CREATE USER &amp;#039;nextcloud&amp;#039;@&amp;#039;localhost&amp;#039;&lt;br /&gt;
    IDENTIFIED BY &amp;#039;SECURE-DATABASE-PASSWORD&amp;#039;;&lt;br /&gt;
&lt;br /&gt;
GRANT ALL PRIVILEGES&lt;br /&gt;
    ON nextcloud.*&lt;br /&gt;
    TO &amp;#039;nextcloud&amp;#039;@&amp;#039;localhost&amp;#039;;&lt;br /&gt;
&lt;br /&gt;
FLUSH PRIVILEGES;&lt;br /&gt;
EXIT;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Replace &amp;lt;code&amp;gt;SECURE-DATABASE-PASSWORD&amp;lt;/code&amp;gt; with a long, random password used exclusively for this database.&lt;br /&gt;
&lt;br /&gt;
Because MariaDB and Nextcloud are installed on the same server, the user is deliberately restricted to &amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Test the login:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mariadb -u nextcloud -p -h localhost nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exit the MariaDB console afterwards:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
EXIT;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Installing Nextcloud ==&lt;br /&gt;
&lt;br /&gt;
At the time this article was created, Nextcloud &amp;lt;code&amp;gt;34.0.1&amp;lt;/code&amp;gt; was the current stable version.&lt;br /&gt;
&lt;br /&gt;
Before performing a later installation, check whether a newer version is available within the supported Nextcloud release branch.&lt;br /&gt;
&lt;br /&gt;
Download the Nextcloud archive and the corresponding SHA-256 checksum:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cd /tmp&lt;br /&gt;
&lt;br /&gt;
NEXTCLOUD_VERSION=&amp;quot;34.0.1&amp;quot;&lt;br /&gt;
&lt;br /&gt;
wget https://download.nextcloud.com/server/releases/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2&lt;br /&gt;
wget https://download.nextcloud.com/server/releases/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2.sha256&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the integrity of the archive:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sha256sum -c nextcloud-${NEXTCLOUD_VERSION}.tar.bz2.sha256&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output must contain &amp;lt;code&amp;gt;OK&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nextcloud-34.0.1.tar.bz2: OK&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Extract Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tar -xjf nextcloud-${NEXTCLOUD_VERSION}.tar.bz2&lt;br /&gt;
mv nextcloud /var/www/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set the owner:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chown -R www-data:www-data /var/www/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the permissions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ls -ld /var/www/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After a successful installation, the downloaded archive files can optionally be removed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
rm -f /tmp/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2&lt;br /&gt;
rm -f /tmp/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2.sha256&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring Apache with PHP-FPM ==&lt;br /&gt;
&lt;br /&gt;
This guide uses a dedicated subdomain for Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cloud.example.com&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable the required Apache modules:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2enmod \&lt;br /&gt;
    proxy_fcgi \&lt;br /&gt;
    setenvif \&lt;br /&gt;
    rewrite \&lt;br /&gt;
    headers \&lt;br /&gt;
    env \&lt;br /&gt;
    dir \&lt;br /&gt;
    mime \&lt;br /&gt;
    ssl \&lt;br /&gt;
    http2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable the PHP 8.5 FPM configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2enconf php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Create the Apache configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/apache2/sites-available/nextcloud.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;VirtualHost *:80&amp;gt;&lt;br /&gt;
    ServerName cloud.example.com&lt;br /&gt;
    DocumentRoot /var/www/nextcloud&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;Directory /var/www/nextcloud/&amp;gt;&lt;br /&gt;
        Require all granted&lt;br /&gt;
        AllowOverride All&lt;br /&gt;
        Options FollowSymLinks&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;IfModule mod_dav.c&amp;gt;&lt;br /&gt;
            Dav off&lt;br /&gt;
        &amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        SetEnv HOME /var/www/nextcloud&lt;br /&gt;
        SetEnv HTTP_HOME /var/www/nextcloud&lt;br /&gt;
    &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    ErrorLog ${APACHE_LOG_DIR}/nextcloud-error.log&lt;br /&gt;
    CustomLog ${APACHE_LOG_DIR}/nextcloud-access.log combined&lt;br /&gt;
&amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Replace &amp;lt;code&amp;gt;cloud.example.com&amp;lt;/code&amp;gt; with the actual DNS name of the Nextcloud installation.&lt;br /&gt;
&lt;br /&gt;
Enable the Nextcloud site:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2ensite nextcloud.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the default Apache site is no longer required, it can be disabled:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2dissite 000-default.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Apache configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apache2ctl configtest&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the configuration is valid, the following output is displayed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Syntax OK&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart Apache and PHP-FPM:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart php8.5-fpm&lt;br /&gt;
systemctl restart apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check both services:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
systemctl status apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring the firewall ==&lt;br /&gt;
&lt;br /&gt;
This step is only required if UFW is used on the server.&lt;br /&gt;
&lt;br /&gt;
Before making changes, ensure that SSH remains allowed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ufw allow OpenSSH&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Allow HTTP and HTTPS:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ufw allow &amp;#039;Apache Full&amp;#039;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the rules:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ufw status&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To                         Action      From&lt;br /&gt;
--                         ------      ----&lt;br /&gt;
OpenSSH                    ALLOW       Anywhere&lt;br /&gt;
Apache Full                ALLOW       Anywhere&lt;br /&gt;
OpenSSH (v6)               ALLOW       Anywhere (v6)&lt;br /&gt;
Apache Full (v6)           ALLOW       Anywhere (v6)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Setting up HTTPS ==&lt;br /&gt;
&lt;br /&gt;
Nextcloud should only be accessible over HTTPS on production systems.&lt;br /&gt;
&lt;br /&gt;
The following requirements apply for a publicly trusted certificate:&lt;br /&gt;
&lt;br /&gt;
* The domain points to the Nextcloud server.&lt;br /&gt;
* TCP port 80 is reachable for certificate validation.&lt;br /&gt;
* TCP port 443 is reachable for subsequent HTTPS access.&lt;br /&gt;
&lt;br /&gt;
Install Certbot and the Apache plugin:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt install -y certbot python3-certbot-apache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Request the certificate:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
certbot --apache --redirect -d cloud.example.com&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Certbot configures the certificate and redirects HTTP requests to HTTPS.&lt;br /&gt;
&lt;br /&gt;
Test automatic certificate renewal:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
certbot renew --dry-run&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Certbot timer:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status certbot.timer&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a reverse proxy or load balancer is already placed in front of Nextcloud, TLS termination can alternatively take place there. In that case, the Nextcloud settings for trusted proxies and forwarded headers must also be configured correctly.&lt;br /&gt;
&lt;br /&gt;
Self-signed certificates should only be used in isolated internal environments where the certificate can be added as trusted on all clients.&lt;br /&gt;
&lt;br /&gt;
== Completing the installation in the browser ==&lt;br /&gt;
&lt;br /&gt;
Open the Nextcloud domain in a browser:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
https://cloud.example.com/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enter the following information in the installation dialog.&lt;br /&gt;
&lt;br /&gt;
=== Administrator account ===&lt;br /&gt;
&lt;br /&gt;
Create an administrator account with a secure password used exclusively for Nextcloud.&lt;br /&gt;
&lt;br /&gt;
=== Data directory ===&lt;br /&gt;
&lt;br /&gt;
Use the following path as the data directory:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Database ===&lt;br /&gt;
&lt;br /&gt;
Select MariaDB or MySQL and use the following values:&lt;br /&gt;
&lt;br /&gt;
* Database user: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database password: the password defined previously&lt;br /&gt;
* Database name: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database host: &amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then start the installation.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:003-Admin-Erstellen.png|Create an administrator account with a secure password.&lt;br /&gt;
File:004-Speicherort-Festlegen.png|Use the previously mounted NFS share as the data directory.&lt;br /&gt;
File:Datenbank-hinzufügen.png|Enter the credentials for the local MariaDB database.&lt;br /&gt;
File:006-Finish.png|After a successful installation, the Nextcloud dashboard is displayed.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring background jobs ==&lt;br /&gt;
&lt;br /&gt;
Nextcloud requires background jobs to be executed regularly. Cron should be used for server installations.&lt;br /&gt;
&lt;br /&gt;
Create the following cron file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/cron.d/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
*/5 * * * * www-data /usr/bin/php8.5 -f /var/www/nextcloud/cron.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set the correct file permissions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chmod 0644 /etc/cron.d/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable cron mode in Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ background:cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart the cron service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the entry:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat /etc/cron.d/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test the cron job manually once:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 -f /var/www/nextcloud/cron.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The status of the background jobs can later be checked in Nextcloud under “Administration settings” → “Basic settings”.&lt;br /&gt;
&lt;br /&gt;
== Configuring APCu and Redis ==&lt;br /&gt;
&lt;br /&gt;
APCu is used for the local application cache. Redis handles transactional file locking and can also be used as a distributed cache.&lt;br /&gt;
&lt;br /&gt;
Open the Nextcloud configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /var/www/nextcloud/config/config.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following entries inside the &amp;lt;code&amp;gt;$CONFIG&amp;lt;/code&amp;gt; array:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;#039;memcache.local&amp;#039; =&amp;gt; &amp;#039;\OC\Memcache\APCu&amp;#039;,&lt;br /&gt;
&amp;#039;memcache.distributed&amp;#039; =&amp;gt; &amp;#039;\OC\Memcache\Redis&amp;#039;,&lt;br /&gt;
&amp;#039;memcache.locking&amp;#039; =&amp;gt; &amp;#039;\OC\Memcache\Redis&amp;#039;,&lt;br /&gt;
&lt;br /&gt;
&amp;#039;redis&amp;#039; =&amp;gt; [&lt;br /&gt;
    &amp;#039;host&amp;#039; =&amp;gt; &amp;#039;127.0.0.1&amp;#039;,&lt;br /&gt;
    &amp;#039;port&amp;#039; =&amp;gt; 6379,&lt;br /&gt;
    &amp;#039;timeout&amp;#039; =&amp;gt; 0.0,&lt;br /&gt;
],&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ensure that all entries are placed inside the existing &amp;lt;code&amp;gt;$CONFIG&amp;lt;/code&amp;gt; array and that preceding entries are separated correctly with commas.&lt;br /&gt;
&lt;br /&gt;
Restart PHP-FPM and Apache:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart php8.5-fpm&lt;br /&gt;
systemctl restart apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Redis service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status redis-server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test the connection:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
redis-cli ping&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The expected response is:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
PONG&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Enabling pretty URLs ==&lt;br /&gt;
&lt;br /&gt;
Pretty URLs remove the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; component from Nextcloud URLs.&lt;br /&gt;
&lt;br /&gt;
First set the complete Nextcloud URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set overwrite.cli.url \&lt;br /&gt;
    --value=&amp;quot;https://cloud.example.com&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then set the rewrite base:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set htaccess.RewriteBase \&lt;br /&gt;
    --value=&amp;quot;/&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Update the Nextcloud &amp;lt;code&amp;gt;.htaccess&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 \&lt;br /&gt;
    /var/www/nextcloud/occ maintenance:update:htaccess&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Reload Apache:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl reload apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nextcloud URLs should now be displayed without &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Verifying the installation ==&lt;br /&gt;
&lt;br /&gt;
First check the Nextcloud status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ status&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A successful installation returns information similar to the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
installed: true&lt;br /&gt;
maintenance: false&lt;br /&gt;
needsDbUpgrade: false&lt;br /&gt;
version: 34.0.1.0&lt;br /&gt;
versionstring: 34.0.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Also check the relevant services:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status apache2&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
systemctl status mariadb&lt;br /&gt;
systemctl status redis-server&lt;br /&gt;
systemctl status cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the NFS mount again:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
findmnt /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify that Nextcloud can still write to the data directory:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data touch /srv/nextcloud-data/.write-test&lt;br /&gt;
sudo -u www-data rm /srv/nextcloud-data/.write-test&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Nextcloud configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 \&lt;br /&gt;
    /var/www/nextcloud/occ config:list system&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Finally, open “Administration settings” → “Overview” in Nextcloud. Missing PHP modules, cache issues, failed background jobs and other configuration problems are displayed there.&lt;br /&gt;
&lt;br /&gt;
== Optional configurations ==&lt;br /&gt;
&lt;br /&gt;
=== Setting the default phone region ===&lt;br /&gt;
&lt;br /&gt;
If phone numbers without an international country code are used in Nextcloud, a default region can be configured.&lt;br /&gt;
&lt;br /&gt;
For Germany, use:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set default_phone_region \&lt;br /&gt;
    --value=&amp;quot;DE&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuring the maintenance window ===&lt;br /&gt;
&lt;br /&gt;
Nextcloud can run resource-intensive daily background jobs preferentially during a maintenance window.&lt;br /&gt;
&lt;br /&gt;
The following example sets the start of the maintenance window to 01:00 UTC:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set maintenance_window_start \&lt;br /&gt;
    --type=integer \&lt;br /&gt;
    --value=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Running available repairs ===&lt;br /&gt;
&lt;br /&gt;
After updates or configuration changes, the Nextcloud repair routines can be executed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 \&lt;br /&gt;
    /var/www/nextcloud/occ maintenance:repair&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Operational notes ==&lt;br /&gt;
&lt;br /&gt;
At least the following points should be considered for ongoing operation:&lt;br /&gt;
&lt;br /&gt;
* Install security updates regularly&lt;br /&gt;
* Update Nextcloud and installed apps regularly&lt;br /&gt;
* Back up the MariaDB database&lt;br /&gt;
* Back up the NFS data directory&lt;br /&gt;
* Back up &amp;lt;code&amp;gt;/var/www/nextcloud/config&amp;lt;/code&amp;gt;&lt;br /&gt;
* Monitor NFS availability&lt;br /&gt;
* Monitor local disk space&lt;br /&gt;
* Monitor Apache, PHP-FPM, MariaDB and Redis&lt;br /&gt;
* Check the Nextcloud administration overview regularly&lt;br /&gt;
* Check background jobs regularly&lt;br /&gt;
* Test restoring from existing backups&lt;br /&gt;
&lt;br /&gt;
Relevant log files include:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/var/log/apache2/nextcloud-error.log&lt;br /&gt;
/var/log/apache2/nextcloud-access.log&lt;br /&gt;
/var/log/php8.5-fpm.log&lt;br /&gt;
/srv/nextcloud-data/nextcloud.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The systemd logs can also be displayed with the following commands:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
journalctl -u apache2&lt;br /&gt;
journalctl -u php8.5-fpm&lt;br /&gt;
journalctl -u mariadb&lt;br /&gt;
journalctl -u redis-server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Displaying the Nextcloud version ===&lt;br /&gt;
&lt;br /&gt;
The currently installed Nextcloud version can be checked at any time:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ status&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Displaying the PHP version ===&lt;br /&gt;
&lt;br /&gt;
The command-line PHP version can be checked as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 --version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The PHP-FPM version used by Apache can be checked through the service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Smueller}}&lt;br /&gt;
[[Category:Server Software]]&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Nextcloud Installation mit NFS-Mount (HowTo)]]&lt;/div&gt;</summary>
		<author><name>Smueller</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Linux_network_analysis_with_traceroute</id>
		<title>Linux network analysis with traceroute</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Linux_network_analysis_with_traceroute"/>
		<updated>2026-07-08T11:45:40Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Linux tool &amp;#039;&amp;#039;&amp;#039;traceroute&amp;#039;&amp;#039;&amp;#039; provides a lot of possibilities to trace the path of network packets through a network or the Internet to a specific host. This article provides an overview of the function of [http://de.wikipedia.org/wiki/Traceroute traceroute]. Furthermore, we present interesting option parameters for traceroute. In addition to traceroute, [[Linux Netzwerk Analyse mit mtr|mtr]] is also interesting. It combines the functionality of traceroute and ping. &lt;br /&gt;
&lt;br /&gt;
== Function == &lt;br /&gt;
&lt;br /&gt;
Traceroute traces the path of network packets to a specific host. To do this, traceroute modifies the time-to-live (TTL) field of the IP protocol. By using small TTL values, traceroute attempts to elicit ICMP TIME_EXCEEDED responses from the individual routers. The only required parameter for traceroute is the host to which the path is to be traced.&lt;br /&gt;
&lt;br /&gt;
To identify the individual hops (routers) along the path from the current computer to the desired host, traceroute proceeds as follows:&lt;br /&gt;
# First, it sends an IP packet with TTL=1. As a result, the first router (the default gateway) discards the packet and sends back an ICMP TIME_EXCEEDED response.&lt;br /&gt;
# Now traceroute sends additional packets, incrementing the TTL by 1 each time. With the second packet (TTL=2), the packet first passes through the default gateway to the next router on the path to the host. Since the default gateway decrements the TTL by 1 when forwarding the packet, the packet arrives at the second router with a TTL of 1. This router discards the packet and sends an ICMP TIME_EXCEEDED response back to the original computer. The process works similarly with TTL=3 at the third router, TTL=4 at the fourth router, and so on.&lt;br /&gt;
# If an IP packet with a sufficiently high TTL eventually reaches the destination host, the host responds with an ICMP &amp;quot;port unreachable&amp;quot; message.&lt;br /&gt;
&lt;br /&gt;
== Methods of testing packets == &lt;br /&gt;
&lt;br /&gt;
For the IP test packets sent, different protocols can be used. These options allow you to send test packets even with restrictive firewall configurations. In addition, this method lets you track the exact path used by a specific protocol (in case packets are routed differently depending on the protocol at some point along the path).&lt;br /&gt;
&lt;br /&gt;
=== UDP (default) ===&lt;br /&gt;
&lt;br /&gt;
In the default configuration, UDP datagrams are used as IP test packets. An &amp;#039;unlikely&amp;#039; port is used for this purpose. The starting port is set to 33434 and is incremented by 1 for each subsequent test packet.&lt;br /&gt;
&lt;br /&gt;
This method can be used by any user and does not require root rights.&lt;br /&gt;
&lt;br /&gt;
Example (the first three hops were anonymized):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@tpw ~]# traceroute www.google.com&lt;br /&gt;
traceroute to www.google.com (209.85.129.147), 30 hops max, 60 byte packets&lt;br /&gt;
 1  XXX (XXX)  1.929 ms  1.982 ms  2.141 ms&lt;br /&gt;
 2  XXX (XXX)  3.795 ms  3.769 ms  3.751 ms&lt;br /&gt;
 3  XXX (XXX)  5.673 ms  5.650 ms  5.634 ms&lt;br /&gt;
 4  iix12-aux11.highway.telekom.at (195.3.70.206)  21.027 ms 195.3.118.50 (195.3.118.50)  21.025 ms  21.328 ms&lt;br /&gt;
 5  72.14.198.241 (72.14.198.241)  21.436 ms  21.406 ms  21.401 ms&lt;br /&gt;
 6  209.85.255.176 (209.85.255.176)  21.497 ms 209.85.255.178 (209.85.255.178)  23.380 ms  23.300 ms&lt;br /&gt;
 7  72.14.232.165 (72.14.232.165)  23.301 ms  21.613 ms 72.14.232.201 (72.14.232.201)  21.661 ms&lt;br /&gt;
 8  72.14.239.170 (72.14.239.170)  21.678 ms 72.14.233.210 (72.14.233.210)  34.381 ms  34.365 ms&lt;br /&gt;
 9  fk-in-f147.1e100.net (209.85.129.147)  19.659 ms  19.280 ms  19.291 ms&lt;br /&gt;
[root@tpw ~]# &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== ICMP (-I) ===&lt;br /&gt;
&lt;br /&gt;
This method uses ICMP echo requests (&amp;#039;Ping&amp;#039;) for testing.&lt;br /&gt;
&lt;br /&gt;
This method requires superuser-rights.&lt;br /&gt;
&lt;br /&gt;
Example (the first three hops were anonymized):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@tpw ~]# traceroute -I www.google.com&lt;br /&gt;
traceroute to www.google.com (209.85.129.147), 30 hops max, 60 byte packets&lt;br /&gt;
 1  XXX (XXX)  1.948 ms  2.022 ms  2.202 ms&lt;br /&gt;
 2  XXX (XXX)  3.915 ms  3.918 ms  3.929 ms&lt;br /&gt;
 3  XXX (XXX)  5.870 ms  5.876 ms  5.889 ms&lt;br /&gt;
 4  iix12-aux11.highway.telekom.at (195.3.70.206)  17.967 ms  19.781 ms  19.784 ms&lt;br /&gt;
 5  72.14.198.241 (72.14.198.241)  19.869 ms  19.867 ms  19.915 ms&lt;br /&gt;
 6  209.85.255.178 (209.85.255.178)  20.044 ms  19.502 ms  19.470 ms&lt;br /&gt;
 7  72.14.232.201 (72.14.232.201)  19.529 ms  19.523 ms 72.14.232.203 (72.14.232.203)  19.532 ms&lt;br /&gt;
 8  72.14.233.210 (72.14.233.210)  27.065 ms  34.198 ms  34.165 ms&lt;br /&gt;
 9  fk-in-f147.1e100.net (209.85.129.147)  18.249 ms  19.352 ms  17.936 ms&lt;br /&gt;
[root@tpw ~]# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== TCP (-T) ===&lt;br /&gt;
&lt;br /&gt;
This method uses a fix TCP port (port 80 is default). With the option -p, another destination port can be also selected (for example -p 25  to check the path to a mail server). This also allows you to get past firewalls that do not let through UDP datagrams or ICMP messages, for example.&lt;br /&gt;
&lt;br /&gt;
This method uses the &amp;quot;half-open technique&amp;quot;. This means that the target applications (for example a web server if the test packets are sent to port 80) do not see the test packets. Normally, a TCP SYN packet is simply sent. If no application is listening on that port on the target host, a TCP RESET is simply returned. However, if an application is listening on that port on the destination host, the destination host sends back a TCP SYN+ACK. Traceroute then responds with a TCP RESET (instead of accepting the connection with a TCP ACK). In this way, the TCP session is discarded without the application on the destination host noticing anything.&lt;br /&gt;
&lt;br /&gt;
This method requires superuser-rights.&lt;br /&gt;
&lt;br /&gt;
Example (the first three hops were anonymized):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@tpw ~]# traceroute -T -p 80 www.google.com&lt;br /&gt;
traceroute to www.google.com (209.85.129.147), 30 hops max, 60 byte packets&lt;br /&gt;
 1  XXX (XXX)  3.187 ms  3.165 ms  3.142 ms&lt;br /&gt;
 2  XXX (XXX)  4.502 ms  4.486 ms  4.478 ms&lt;br /&gt;
 3  XXX (XXX)  6.409 ms  6.394 ms  6.365 ms&lt;br /&gt;
 4  195.3.118.50 (195.3.118.50)  22.834 ms  22.828 ms iix12-aux11.highway.telekom.at (195.3.70.206)  22.822 ms&lt;br /&gt;
 5  72.14.198.241 (72.14.198.241)  22.848 ms  22.827 ms  22.803 ms&lt;br /&gt;
 6  209.85.255.178 (209.85.255.178)  22.822 ms 209.85.255.176 (209.85.255.176)  20.884 ms 209.85.255.178 (209.85.255.178)  20.880 ms&lt;br /&gt;
 7  72.14.232.165 (72.14.232.165)  20.916 ms  19.753 ms 72.14.232.203 (72.14.232.203)  19.744 ms&lt;br /&gt;
 8  72.14.233.210 (72.14.233.210)  33.508 ms 72.14.233.206 (72.14.233.206)  21.713 ms  21.655 ms&lt;br /&gt;
 9  * * *&lt;br /&gt;
10  * * *&lt;br /&gt;
11  * * *&lt;br /&gt;
12  * * *&lt;br /&gt;
13  * * *&lt;br /&gt;
14  * * *&lt;br /&gt;
15  fk-in-f147.1e100.net (209.85.129.147)  19.678 ms  19.715 ms  19.728 ms&lt;br /&gt;
[root@tpw ~]#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== UDP (-U) ===&lt;br /&gt;
&lt;br /&gt;
This method uses a fix UDP port (port 53 is default). It is also used to bypass firewalls.&lt;br /&gt;
&lt;br /&gt;
Unlike the TCP method, an application on the destination host receives these UDP datagrams if it is listening on the corresponding port. This can confuse the application in question. In most cases, the application will not send a response (so traceroute does not see a final hop in the trace).&lt;br /&gt;
&lt;br /&gt;
This method can be used by any user and does not require root rights).&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* Manpage of traceroute&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Networking]][[Category:Linux Performance]]&lt;br /&gt;
[[pl:Analiza sieci w Linuksie z traceroute]]&lt;br /&gt;
[[de:Linux Netzwerk Analyse mit traceroute]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/How_to_set_up_VLAN_in_OPNsense</id>
		<title>How to set up VLAN in OPNsense</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/How_to_set_up_VLAN_in_OPNsense"/>
		<updated>2026-07-08T08:03:12Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Virtual Local Area Networks&amp;#039;&amp;#039;&amp;#039; -  VLANs - are an important tool for the network infrastructure, particularly in environments with firewall solutions such as OPNsense. They allow to divide a physical network into multiple logical networks, which improves security and organization. This article describes how to set up VLANs in OPNsense 25.1.  == Assign VLAN == First, a &amp;#039;&amp;#039;&amp;#039;VLAN-ID between 1 and 4094&amp;#039;&amp;#039;&amp;#039; is assigned to an interface. The ID 4095 is reser...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Virtual Local Area Networks&amp;#039;&amp;#039;&amp;#039; -  [[VLAN Basics|VLANs]] - are an important tool for the network infrastructure, particularly in environments with firewall solutions such as [[OPNsense]]. They allow to divide a physical network into multiple logical networks, which improves security and organization. This article describes how to set up VLANs in OPNsense 25.1.&lt;br /&gt;
&lt;br /&gt;
== Assign VLAN ==&lt;br /&gt;
First, a &amp;#039;&amp;#039;&amp;#039;VLAN-ID between 1 and 4094&amp;#039;&amp;#039;&amp;#039; is assigned to an interface. The ID 4095 is reserved, as in all VLAN networks.&amp;lt;ref name=IEEE802.1Q&amp;gt;[http://www.microhowto.info/tutorials/802.1q.html#idp28880 IEEE 802.1Q VLAN] &amp;lt;cite&amp;gt;&amp;quot;Each 802.1Q VLAN is identified by a 12-bit integer called a VID (VLAN Identifier) in the range 1 to 4094 inclusive. The values 0 and 4095 are reserved and should not be used.&amp;quot;&amp;lt;/cite&amp;gt;&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-001.png|Go to &amp;#039;&amp;#039;&amp;#039;Interfaces ‣ Devices ‣ VLAN&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-002.png|Here, click on the &amp;#039;&amp;#039;&amp;#039;+&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-003.png|Assign the desired &amp;#039;&amp;#039;&amp;#039;Interface&amp;#039;&amp;#039;&amp;#039; as well as the &amp;#039;&amp;#039;&amp;#039;VLAN-ID&amp;#039;&amp;#039;&amp;#039;, in this example &amp;#039;&amp;#039;&amp;#039;10&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-004.png|Click on &amp;#039;&amp;#039;&amp;#039;Apply&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It is also possible to use an interface as [[VLAN#Tagged VLANs|Trunk]] by simply assigning a second VLAN with a different ID to the same interface.&lt;br /&gt;
&lt;br /&gt;
== Create interface ==&lt;br /&gt;
The following screenshots demonstrate the process of adding a network interface:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-005.png|In the webinterface, navigate to &amp;#039;&amp;#039;&amp;#039;Interfaces&amp;#039;&amp;#039;&amp;#039; ‣ &amp;#039;&amp;#039;&amp;#039;Assignments&amp;#039;&amp;#039;&amp;#039; and select the new VLAN in the section &amp;#039;&amp;#039;&amp;#039;Assign a new interface.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-006.png|State a description and click on &amp;#039;&amp;#039;&amp;#039;Add&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-007.png|The new VLAN was added as new interface &amp;#039;&amp;#039;&amp;#039;Lab&amp;#039;&amp;#039;&amp;#039; in this example. Click on &amp;#039;&amp;#039;&amp;#039;Save&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In Thomas-Krenn-Wiki, you will find information on how to [[OPNsense add interface|add an OPNsense interface]].&lt;br /&gt;
&lt;br /&gt;
== Assign IP address ==&lt;br /&gt;
Here, an IP address is assigned to the added interface. There are several options available, such as automatic address assignment using DHCP or manual configuration of a static IP address (Static IPv4). In this example, a static address assignment with the IP-address &amp;#039;&amp;#039;&amp;#039;192.168.10.1/24&amp;#039;&amp;#039;&amp;#039; is used.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-008.png|Click on the menu item &amp;#039;&amp;#039;&amp;#039;Assignments&amp;#039;&amp;#039;&amp;#039; ‣ &amp;#039;&amp;#039;&amp;#039;Interfaces&amp;#039;&amp;#039;&amp;#039; on the previously created VLAN interface. &lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-009.png|Activate it with the help of the option &amp;#039;&amp;#039;&amp;#039;Enable Interface&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-010.png|Go to the menu item &amp;#039;&amp;#039;&amp;#039;IPv4 Configuration Type&amp;#039;&amp;#039;&amp;#039; after activation of the interface and select one of the &amp;#039;&amp;#039;&amp;#039;options&amp;#039;&amp;#039;&amp;#039; described earlier.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-011.png|If you selected the &amp;#039;&amp;#039;&amp;#039;Static IPv4&amp;#039;&amp;#039;&amp;#039; option, scroll down to the &amp;#039;&amp;#039;&amp;#039;Static IPv4 configuration&amp;#039;&amp;#039;&amp;#039; section. State the static IPv4 address as well as the subnet. After that, click on &amp;#039;&amp;#039;&amp;#039;Save&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-012.png|Store the configuration with &amp;#039;&amp;#039;&amp;#039;Apply changes.&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Firewall rules ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; By default, all incoming connections on this interface are blocked. To change this, you must create rules to control and secure data traffic for the VLAN you created.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-013.png|Go to the &amp;#039;&amp;#039;&amp;#039;Firewall&amp;#039;&amp;#039;&amp;#039; menu and click on &amp;#039;&amp;#039;&amp;#039;Rules&amp;#039;&amp;#039;&amp;#039; to create rules here.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{ederr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:OPNsense]]&lt;br /&gt;
[[de:VLAN einrichten unter OPNsense]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Network_configuration_Ubuntu_-_Netplan</id>
		<title>Network configuration Ubuntu - Netplan</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Network_configuration_Ubuntu_-_Netplan"/>
		<updated>2026-07-08T06:07:19Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Aranzinger moved page Network configuration - Netplan to Network configuration Ubuntu - Netplan&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the current version of [[Ubuntu]] Server, Ubuntu 18.04 (Bionic Beaver), the network configuration can no longer be set in the file &amp;lt;code&amp;gt;/etc/network/interfaces&amp;lt;/code&amp;gt; in a default installation. Since Ubuntu 17.10, there is [http://manpages.ubuntu.com/manpages/bionic/man5/netplan.5.html Netplan], which is a new option to configure network interfaces. The network configuration is stored in .yaml-files. In addition to changes to the configuration of the network interfaces, there are also new configurations regarding the hostname. &lt;br /&gt;
&lt;br /&gt;
== Network configuration (static) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo rm /etc/netplan/50-cloud-init.yaml &lt;br /&gt;
sudo touch /etc/netplan/01-ens160.yaml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The content of the file in a static network configuration should look as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
network:&lt;br /&gt;
 version: 2&lt;br /&gt;
 renderer: networkd&lt;br /&gt;
 ethernets:&lt;br /&gt;
   ens160:&lt;br /&gt;
     dhcp4: no&lt;br /&gt;
     dhcp6: no&lt;br /&gt;
     addresses: [10.2.2.123/24]&lt;br /&gt;
     gateway4: 10.2.2.1&lt;br /&gt;
     nameservers:&lt;br /&gt;
       addresses: [192.168.110.50]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, the network configuration can be activated:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt; sudo netplan apply&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; Please use spaces for indentation in this file and do not use tabs.&lt;br /&gt;
&lt;br /&gt;
== Change hostname ==&lt;br /&gt;
In Ubuntu 18.04, it is no longer enough to set the hostname via &amp;lt;code&amp;gt;/etc/hostname&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;hostnamectl&amp;lt;/code&amp;gt;. After a reboot of the server, the hostname would be lost again, as it has not been stored. In the following, it is explained how to permanently set the host name:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;nano /etc/cloud/cloud.cfg&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This will cause the set+update hostname module to not operate (if true)&lt;br /&gt;
preserve_hostname: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Here, the value preserve_hostname must be set from false to true.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This will cause the set+update hostname module to not operate (if true)&lt;br /&gt;
preserve_hostname: true&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, the hostname can be set permanently using the following commands:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo nano /etc/hostname &lt;br /&gt;
sudo hostnamectl set-hostname web-01&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network configuration (other) == &lt;br /&gt;
For other network configurations, such as DHCP, Bonds, WLAN etc., you will find corresponding notes on the [https://netplan.io/examples netplan.io] website.&lt;br /&gt;
&lt;br /&gt;
{{Jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Netzwerk-Konfiguration Ubuntu - Netplan]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/NVMe-CLI</id>
		<title>NVMe-CLI</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/NVMe-CLI"/>
		<updated>2026-07-07T11:07:10Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The &amp;#039;&amp;#039;&amp;#039;NVMe Command Line Interface&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;NVMe-CLI&amp;#039;&amp;#039;&amp;#039;) provides multiple &amp;#039;&amp;#039;&amp;#039;functions on querying and configuring NVMe SSDs&amp;#039;&amp;#039;&amp;#039; on Linux and FreeBSD. In this article, we explain how to install NVMe-CLI and which funtions NVMe-CLI offers.   == Version information == In the Linux distributions, the following versions of NVMe-CLI are included: {| class=&amp;quot;wikitable&amp;quot; |+ ! colspan=&amp;quot;2&amp;quot; |Linux distribution !NVMe-CLI version |- | rowspan=&amp;quot;3&amp;quot; |Debian GNU/Linux |1...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;NVMe Command Line Interface&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;NVMe-CLI&amp;#039;&amp;#039;&amp;#039;) provides multiple &amp;#039;&amp;#039;&amp;#039;functions on querying and configuring [[NVMe]] [[SSD]]s&amp;#039;&amp;#039;&amp;#039; on [[Linux]] and [[FreeBSD]]. In this article, we explain how to install NVMe-CLI and which funtions NVMe-CLI offers. &lt;br /&gt;
&lt;br /&gt;
== Version information ==&lt;br /&gt;
In the Linux distributions, the following versions of NVMe-CLI are included:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Linux distribution&lt;br /&gt;
!NVMe-CLI version&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;3&amp;quot; |[[Debian GNU/Linux]]&lt;br /&gt;
|12.0 (Bookworm)&lt;br /&gt;
|nvme-cli [https://packages.debian.org/bookworm/nvme-cli 2.3]&lt;br /&gt;
|-&lt;br /&gt;
|11.0 (Bullseye)&lt;br /&gt;
|nvme-cli [https://packages.debian.org/bullseye/nvme-cli 1.12]&lt;br /&gt;
|-&lt;br /&gt;
|10.0 (Buster)&lt;br /&gt;
|nvme-cli [https://packages.debian.org/buster/nvme-cli 1.7]&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; |[[Ubuntu]]&lt;br /&gt;
|22.04 LTS&lt;br /&gt;
|nvme-cli [https://packages.ubuntu.com/jammy/nvme-cli 1.16]&lt;br /&gt;
|-&lt;br /&gt;
|20.04 LTS&lt;br /&gt;
|nvme-cli [https://packages.ubuntu.com/focal/nvme-cli 1.9]&lt;br /&gt;
|-&lt;br /&gt;
|[[Proxmox VE]]&lt;br /&gt;
|7.x&lt;br /&gt;
|nvme-cli 1.12&lt;br /&gt;
|}&lt;br /&gt;
Changelog (in part):&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!NVMe-CLI version&lt;br /&gt;
!Release date&lt;br /&gt;
!Changes&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.1-rc0 v2.1-rc0]&lt;br /&gt;
|14.07.2022&lt;br /&gt;
|new solidigm plugin&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0 v2.0]&lt;br /&gt;
|08.04.2022&lt;br /&gt;
|first release of nvme-cli 2&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc7 v2.0-rc7]&lt;br /&gt;
|18.03.2022&lt;br /&gt;
|add transcend, virtium plugin commands&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc6 v2.0-rc6]&lt;br /&gt;
|11.03.2022&lt;br /&gt;
|cmds-main: Add intel plugin commands&lt;br /&gt;
cmds-plugins: Add huawei plugin commands&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc4 v2.0-rc4]&lt;br /&gt;
|22.02.2022&lt;br /&gt;
|Micron and NetApp plugin got a few fixes&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc3 v2.0-rc3]&lt;br /&gt;
|11.02.2022&lt;br /&gt;
|update wdc plugin version to 1.16.3&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc0 v2.0-rc0]&lt;br /&gt;
|14.01.2022&lt;br /&gt;
|code base of nvme-cli has been splitted into a nvme-cli and libnvme&lt;br /&gt;
a lot&amp;#039;s of cleanups and refactoring&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NVMe-CLI installation ==&lt;br /&gt;
NVMe-CLI is installed via apt on [[Debian]] and [[Ubuntu]]:&lt;br /&gt;
 apt install nvme-cli&lt;br /&gt;
&lt;br /&gt;
On [[FreeBSD]], the installation works as follows:&lt;br /&gt;
 pkg install nvme-cli&lt;br /&gt;
&lt;br /&gt;
== NVMe-CLI function overview ==&lt;br /&gt;
&lt;br /&gt;
=== nvme help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  list                      List all NVMe devices and namespaces on machine&lt;br /&gt;
  list-subsys               List nvme subsystems&lt;br /&gt;
  id-ctrl                   Send NVMe Identify Controller&lt;br /&gt;
  id-ns                     Send NVMe Identify Namespace, display structure&lt;br /&gt;
  id-ns-granularity         Send NVMe Identify Namespace Granularity List, display structure&lt;br /&gt;
  list-ns                   Send NVMe Identify List, display structure&lt;br /&gt;
  list-ctrl                 Send NVMe Identify Controller List, display structure&lt;br /&gt;
  nvm-id-ctrl               Send NVMe Identify Controller NVM Command Set, display structure&lt;br /&gt;
  primary-ctrl-caps         Send NVMe Identify Primary Controller Capabilities&lt;br /&gt;
  list-secondary            List Secondary Controllers associated with a Primary Controller&lt;br /&gt;
  cmdset-ind-id-ns          I/O Command Set Independent Identify Namespace&lt;br /&gt;
  ns-descs                  Send NVMe Namespace Descriptor List, display structure&lt;br /&gt;
  id-nvmset                 Send NVMe Identify NVM Set List, display structure&lt;br /&gt;
  id-uuid                   Send NVMe Identify UUID List, display structure&lt;br /&gt;
  id-iocs                   Send NVMe Identify I/O Command Set, display structure&lt;br /&gt;
  id-domain                 Send NVMe Identify Domain List, display structure&lt;br /&gt;
  list-endgrp               Send NVMe Identify Endurance Group List, display structure&lt;br /&gt;
  create-ns                 Creates a namespace with the provided parameters&lt;br /&gt;
  delete-ns                 Deletes a namespace from the controller&lt;br /&gt;
  attach-ns                 Attaches a namespace to requested controller(s)&lt;br /&gt;
  detach-ns                 Detaches a namespace from requested controller(s)&lt;br /&gt;
  get-ns-id                 Retrieve the namespace ID of opened block device&lt;br /&gt;
  get-log                   Generic NVMe get log, returns log in raw format&lt;br /&gt;
  telemetry-log             Retrieve FW Telemetry log write to file&lt;br /&gt;
  fw-log                    Retrieve FW Log, show it&lt;br /&gt;
  changed-ns-list-log       Retrieve Changed Namespace List, show it&lt;br /&gt;
  smart-log                 Retrieve SMART Log, show it&lt;br /&gt;
  ana-log                   Retrieve ANA Log, show it&lt;br /&gt;
  error-log                 Retrieve Error Log, show it&lt;br /&gt;
  effects-log               Retrieve Command Effects Log, show it&lt;br /&gt;
  endurance-log             Retrieve Endurance Group Log, show it&lt;br /&gt;
  predictable-lat-log       Retrieve Predictable Latency per Nvmset Log, show it&lt;br /&gt;
  pred-lat-event-agg-log    Retrieve Predictable Latency Event Aggregate Log, show it&lt;br /&gt;
  persistent-event-log      Retrieve Presistent Event Log, show it&lt;br /&gt;
  endurance-event-agg-log   Retrieve Endurance Group Event Aggregate Log, show it&lt;br /&gt;
  lba-status-log            Retrieve LBA Status Information Log, show it&lt;br /&gt;
  resv-notif-log            Retrieve Reservation Notification Log, show it&lt;br /&gt;
  boot-part-log             Retrieve Boot Partition Log, show it&lt;br /&gt;
  get-feature               Get feature and show the resulting value&lt;br /&gt;
  device-self-test          Perform the necessary tests to observe the performance&lt;br /&gt;
  self-test-log             Retrieve the SELF-TEST Log, show it&lt;br /&gt;
  supported-log-pages       Retrieve the Supported Log pages details, show it&lt;br /&gt;
  set-feature               Set a feature and show the resulting value&lt;br /&gt;
  set-property              Set a property and show the resulting value&lt;br /&gt;
  get-property              Get a property and show the resulting value&lt;br /&gt;
  format                    Format namespace with new block format&lt;br /&gt;
  fw-commit                 Verify and commit firmware to a specific slot (fw-activate in old version &amp;lt; 1.2)&lt;br /&gt;
  fw-download               Download new firmware&lt;br /&gt;
  admin-passthru            Submit an arbitrary admin command, return results&lt;br /&gt;
  io-passthru               Submit an arbitrary IO command, return results&lt;br /&gt;
  security-send             Submit a Security Send command, return results&lt;br /&gt;
  security-recv             Submit a Security Receive command, return results&lt;br /&gt;
  get-lba-status            Submit a Get LBA Status command, return results&lt;br /&gt;
  capacity-mgmt             Submit Capacity Management Command, return results&lt;br /&gt;
  resv-acquire              Submit a Reservation Acquire, return results&lt;br /&gt;
  resv-register             Submit a Reservation Register, return results&lt;br /&gt;
  resv-release              Submit a Reservation Release, return results&lt;br /&gt;
  resv-report               Submit a Reservation Report, return results&lt;br /&gt;
  dsm                       Submit a Data Set Management command, return results&lt;br /&gt;
  copy                      Submit a Simple Copy command, return results&lt;br /&gt;
  flush                     Submit a Flush command, return results&lt;br /&gt;
  compare                   Submit a Compare command, return results&lt;br /&gt;
  read                      Submit a read command, return results&lt;br /&gt;
  write                     Submit a write command, return results&lt;br /&gt;
  write-zeroes              Submit a write zeroes command, return results&lt;br /&gt;
  write-uncor               Submit a write uncorrectable command, return results&lt;br /&gt;
  verify                    Submit a verify command, return results&lt;br /&gt;
  sanitize                  Submit a sanitize command&lt;br /&gt;
  sanitize-log              Retrieve sanitize log, show it&lt;br /&gt;
  reset                     Resets the controller&lt;br /&gt;
  subsystem-reset           Resets the subsystem&lt;br /&gt;
  ns-rescan                 Rescans the NVME namespaces&lt;br /&gt;
  show-regs                 Shows the controller registers or properties. Requires character device&lt;br /&gt;
  discover                  Discover NVMeoF subsystems&lt;br /&gt;
  connect-all               Discover and Connect to NVMeoF subsystems&lt;br /&gt;
  connect                   Connect to NVMeoF subsystem&lt;br /&gt;
  disconnect                Disconnect from NVMeoF subsystem&lt;br /&gt;
  disconnect-all            Disconnect from all connected NVMeoF subsystems&lt;br /&gt;
  gen-hostnqn               Generate NVMeoF host NQN&lt;br /&gt;
  show-hostnqn              Show NVMeoF host NQN&lt;br /&gt;
  dir-receive               Submit a Directive Receive command, return results&lt;br /&gt;
  dir-send                  Submit a Directive Send command, return results&lt;br /&gt;
  virt-mgmt                 Manage Flexible Resources between Primary and Secondary Controller&lt;br /&gt;
  rpmb                      Replay Protection Memory Block commands&lt;br /&gt;
  fid-support-effects-log   Submit Feature ID Support and Effects Log, Return result&lt;br /&gt;
  lockdown                  Submit a Lockdown command,return result&lt;br /&gt;
  version                   Shows the program version&lt;br /&gt;
  help                      Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&lt;br /&gt;
The following are all installed plugin extensions:&lt;br /&gt;
  ymtc            Ymtc vendor specific extensions&lt;br /&gt;
  nvidia          NVIDIA vendor specific extensions&lt;br /&gt;
  zns             Zoned Namespace Command Set&lt;br /&gt;
  transcend       Transcend vendor specific extensions&lt;br /&gt;
  sfx             ScaleFlux vendor specific extensions&lt;br /&gt;
  dera            Dera vendor specific extensions&lt;br /&gt;
  shannon         Shannon vendor specific extensions&lt;br /&gt;
  virtium         Virtium vendor specific extensions&lt;br /&gt;
  seagate         Seagate vendor specific extensions&lt;br /&gt;
  micron          Micron vendor specific extensions&lt;br /&gt;
  toshiba         Toshiba NVME plugin&lt;br /&gt;
  netapp          NetApp vendor specific extensions&lt;br /&gt;
  huawei          Huawei vendor specific extensions&lt;br /&gt;
  wdc             Western Digital vendor specific extensions&lt;br /&gt;
  memblaze        Memblaze vendor specific extensions&lt;br /&gt;
  lnvm            LightNVM specific extensions&lt;br /&gt;
  amzn            Amazon vendor specific extensions&lt;br /&gt;
  intel           Intel vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme &amp;lt;plugin&amp;gt; help&amp;#039; for more information on a plugin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme micron help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme micron help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme micron &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Micron vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  select-download                  Selective Firmware Download&lt;br /&gt;
  vs-temperature-stats             Retrieve Micron temperature statistics&lt;br /&gt;
  vs-pcie-stats                    Retrieve Micron PCIe error stats&lt;br /&gt;
  clear-pcie-correctable-errors    Clear correctable PCIe errors&lt;br /&gt;
  vs-internal-log                  Retrieve Micron logs&lt;br /&gt;
  vs-telemetry-controller-option   Enable/Disable controller telemetry log generation&lt;br /&gt;
  vs-nand-stats                    Retrieve NAND Stats&lt;br /&gt;
  vs-drive-info                    Retrieve Drive information&lt;br /&gt;
  plugin-version                   Display plugin version info&lt;br /&gt;
  cloud-SSD-plugin-version         Display plugin version info&lt;br /&gt;
  log-page-directory               Retrieve log page directory&lt;br /&gt;
  vs-fw-activate-history           Display FW activation history&lt;br /&gt;
  vs-error-reason-identifier       Retrieve Error reason&lt;br /&gt;
  vs-smart-add-log                 Retrieve extended SMART data&lt;br /&gt;
  clear-fw-activate-history        Clear FW activation history&lt;br /&gt;
  vs-smbus-option                  Enable/Disable SMBUS on the drive&lt;br /&gt;
  version                          Shows the program version&lt;br /&gt;
  help                             Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme micron help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme toshiba help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme toshiba help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme toshiba &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Toshiba NVME plugin&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  vs-smart-add-log                Extended SMART information&lt;br /&gt;
  vs-internal-log                 Get Internal Log&lt;br /&gt;
  clear-pcie-correctable-errors   Clear PCIe correctable error count&lt;br /&gt;
  version                         Shows the program version&lt;br /&gt;
  help                            Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme toshiba help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme wdc help ===&lt;br /&gt;
The following commands are provided for WDC SSDs (details on &amp;#039;drive-resize&amp;#039; can be found in [[Drive-Resize von Western Digital NVME SSDs|Drive-Resize of Western Digital NVME SSDs]]):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme wdc help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme wdc &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Western Digital vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  cap-diag                         WDC Capture-Diagnostics&lt;br /&gt;
  drive-log                        WDC Drive Log&lt;br /&gt;
  get-crash-dump                   WDC Crash Dump&lt;br /&gt;
  get-pfail-dump                   WDC Pfail Dump&lt;br /&gt;
  id-ctrl                          WDC identify controller&lt;br /&gt;
  purge                            WDC Purge&lt;br /&gt;
  purge-monitor                    WDC Purge Monitor&lt;br /&gt;
  vs-internal-log                  WDC Internal Firmware Log&lt;br /&gt;
  vs-nand-stats                    WDC NAND Statistics&lt;br /&gt;
  vs-smart-add-log                 WDC Additional Smart Log&lt;br /&gt;
  clear-pcie-correctable-errors    WDC Clear PCIe Correctable Error Count&lt;br /&gt;
  drive-essentials                 WDC Drive Essentials&lt;br /&gt;
  get-drive-status                 WDC Get Drive Status&lt;br /&gt;
  clear-assert-dump                WDC Clear Assert Dump&lt;br /&gt;
  drive-resize                     WDC Drive Resize&lt;br /&gt;
  vs-fw-activate-history           WDC Get FW Activate History&lt;br /&gt;
  clear-fw-activate-history        WDC Clear FW Activate History&lt;br /&gt;
  enc-get-log                      WDC Get Enclosure Log&lt;br /&gt;
  vs-telemetry-controller-option   WDC Enable/Disable Controller Initiated Telemetry Log&lt;br /&gt;
  vs-error-reason-identifier       WDC Telemetry Reason Identifier&lt;br /&gt;
  log-page-directory               WDC Get Log Page Directory&lt;br /&gt;
  namespace-resize                 WDC NamespaceDrive Resize&lt;br /&gt;
  vs-drive-info                    WDC Get Drive Info&lt;br /&gt;
  vs-temperature-stats             WDC Get Temperature Stats&lt;br /&gt;
  capabilities                     WDC Device Capabilities&lt;br /&gt;
  cloud-SSD-plugin-version         WDC Cloud SSD Plugin Version&lt;br /&gt;
  vs-pcie-stats                    WDC VS PCIE Statistics&lt;br /&gt;
  get-latency-monitor-log          WDC Get Latency Monitor Log Page&lt;br /&gt;
  version                          Shows the program version&lt;br /&gt;
  help                             Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme wdc help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme intel help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme intel help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme intel &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Intel vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  id-ctrl                 Send NVMe Identify Controller&lt;br /&gt;
  internal-log            Retrieve Intel internal firmware log, save it&lt;br /&gt;
  lat-stats               Retrieve Intel IO Latency Statistics log, show it&lt;br /&gt;
  set-bucket-thresholds   Set Latency Stats Bucket Values, save it&lt;br /&gt;
  lat-stats-tracking      Enable and disable Latency Statistics logging.&lt;br /&gt;
  market-name             Retrieve Intel Marketing Name log, show it&lt;br /&gt;
  smart-log-add           Retrieve Intel SMART Log, show it&lt;br /&gt;
  temp-stats              Retrieve Intel Temperature Statistics log, show it&lt;br /&gt;
  version                 Shows the program version&lt;br /&gt;
  help                    Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme intel help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== NVMe-CLI examples ==&lt;br /&gt;
The following examples were collected on an Ubuntu 22.04 system with an ATP M.2 NVMe SSD.&lt;br /&gt;
&lt;br /&gt;
=== nvme list ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme list&lt;br /&gt;
Node                  SN                   Model                                    Namespace Usage                      Format           FW Rev&lt;br /&gt;
--------------------- -------------------- ---------------------------------------- --------- -------------------------- ---------------- --------&lt;br /&gt;
/dev/nvme0n1          20040089-000002      ATP NVMe M.2 2280 SSD                    1           5,08  GB / 120,03  GB    512   B +  0 B   42A0S79A&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme list-subsys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme list-subsys&lt;br /&gt;
nvme-subsys0 - NQN=nqn.2014.08.org.nvmexpress:1db21db220040089-000002     ATP NVMe M.2 2280 SSD&lt;br /&gt;
\&lt;br /&gt;
 +- nvme0 pcie 0000:01:00.0 live&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the following, you will find the output of a [[Proxmox VE]] 7.x system with four [[Western Digital SN640 TCG U.2 NVMe SSDs]]:&lt;br /&gt;
 root@pmx01:~# nvme list-subsys&lt;br /&gt;
nvme-subsys0 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B7800000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme0 pcie 0000:84:00.0 live&lt;br /&gt;
nvme-subsys1 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B0000000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme1 pcie 0000:85:00.0 live&lt;br /&gt;
nvme-subsys2 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B7000000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme2 pcie 0000:86:00.0 live&lt;br /&gt;
nvme-subsys3 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B4000000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme3 pcie 0000:87:00.0 live&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme smart-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme smart-log /dev/nvme0n1&lt;br /&gt;
Smart Log for NVME device:nvme0n1 namespace-id:ffffffff&lt;br /&gt;
critical_warning                        : 0&lt;br /&gt;
temperature                             : 38 C (311 Kelvin)&lt;br /&gt;
available_spare                         : 100%&lt;br /&gt;
available_spare_threshold               : 10%&lt;br /&gt;
percentage_used                         : 0%&lt;br /&gt;
endurance group critical warning summary: 0&lt;br /&gt;
data_units_read                         : 314.978&lt;br /&gt;
data_units_written                      : 197.916&lt;br /&gt;
host_read_commands                      : 1.739.034&lt;br /&gt;
host_write_commands                     : 2.384.025&lt;br /&gt;
controller_busy_time                    : 46&lt;br /&gt;
power_cycles                            : 106&lt;br /&gt;
power_on_hours                          : 68&lt;br /&gt;
unsafe_shutdowns                        : 59&lt;br /&gt;
media_errors                            : 0&lt;br /&gt;
num_err_log_entries                     : 0&lt;br /&gt;
Warning Temperature Time                : 0&lt;br /&gt;
Critical Composite Temperature Time     : 0&lt;br /&gt;
Temperature Sensor 1           : 27 C (300 Kelvin)&lt;br /&gt;
Temperature Sensor 2           : 38 C (311 Kelvin)&lt;br /&gt;
Thermal Management T1 Trans Count       : 0&lt;br /&gt;
Thermal Management T2 Trans Count       : 0&lt;br /&gt;
Thermal Management T1 Total Time        : 0&lt;br /&gt;
Thermal Management T2 Total Time        : 0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme fw-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme fw-log /dev/nvme0n1&lt;br /&gt;
Firmware Log for device:nvme0n1&lt;br /&gt;
afi  : 0x11&lt;br /&gt;
frs1 : 42A0S79A&lt;br /&gt;
frs2 : 42A0S79A&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme error-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme error-log /dev/nvme0n1&lt;br /&gt;
Error Log Entries for device:nvme0n1 entries:64&lt;br /&gt;
.................&lt;br /&gt;
 Entry[ 0]&lt;br /&gt;
.................&lt;br /&gt;
error_count     : 0&lt;br /&gt;
sqid            : 0&lt;br /&gt;
cmdid           : 0&lt;br /&gt;
status_field    : 0(SUCCESS: The command completed successfully)&lt;br /&gt;
phase_tag       : 0&lt;br /&gt;
parm_err_loc    : 0&lt;br /&gt;
lba             : 0&lt;br /&gt;
nsid            : 0&lt;br /&gt;
vs              : 0&lt;br /&gt;
trtype          : The transport type is not indicated or the error is not transport related.&lt;br /&gt;
cs              : 0&lt;br /&gt;
trtype_spec_info: 0&lt;br /&gt;
[...]&lt;br /&gt;
.................&lt;br /&gt;
 Entry[63]&lt;br /&gt;
.................&lt;br /&gt;
error_count     : 0&lt;br /&gt;
sqid            : 0&lt;br /&gt;
cmdid           : 0&lt;br /&gt;
status_field    : 0(SUCCESS: The command completed successfully)&lt;br /&gt;
phase_tag       : 0&lt;br /&gt;
parm_err_loc    : 0&lt;br /&gt;
lba             : 0&lt;br /&gt;
nsid            : 0&lt;br /&gt;
vs              : 0&lt;br /&gt;
trtype          : The transport type is not indicated or the error is not transport related.&lt;br /&gt;
cs              : 0&lt;br /&gt;
trtype_spec_info: 0&lt;br /&gt;
.................&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme effects-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme effects-log /dev/nvme0n1&lt;br /&gt;
Admin Command Set&lt;br /&gt;
ACS0     [Delete I/O Submission Queue     ] 00000001&lt;br /&gt;
ACS1     [Create I/O Submission Queue     ] 00000001&lt;br /&gt;
ACS2     [Get Log Page                    ] 00000001&lt;br /&gt;
ACS4     [Delete I/O Completion Queue     ] 00000001&lt;br /&gt;
ACS5     [Create I/O Completion Queue     ] 00000001&lt;br /&gt;
ACS6     [Identify                        ] 00000001&lt;br /&gt;
ACS8     [Abort                           ] 00000001&lt;br /&gt;
ACS9     [Set Features                    ] 00000001&lt;br /&gt;
ACS10    [Get Features                    ] 00000001&lt;br /&gt;
ACS12    [Asynchronous Event Request      ] 00000001&lt;br /&gt;
ACS16    [Firmware Commit                 ] 00000011&lt;br /&gt;
ACS17    [Firmware Image Download         ] 00000001&lt;br /&gt;
ACS20    [Device Self-test                ] 00000001&lt;br /&gt;
ACS128   [Format NVM                      ] 00010003&lt;br /&gt;
ACS129   [Security Send                   ] 00000003&lt;br /&gt;
ACS130   [Security Receive                ] 00000001&lt;br /&gt;
ACS132   [Sanitize                        ] 00010003&lt;br /&gt;
ACS192   [Unknown                         ] 00000017&lt;br /&gt;
ACS193   [Unknown                         ] 00000017&lt;br /&gt;
ACS194   [Unknown                         ] 00000001&lt;br /&gt;
ACS224   [Unknown                         ] 00000001&lt;br /&gt;
ACS228   [Unknown                         ] 00000001&lt;br /&gt;
ACS229   [Unknown                         ] 00000001&lt;br /&gt;
ACS230   [Unknown                         ] 00000001&lt;br /&gt;
&lt;br /&gt;
NVM Command Set&lt;br /&gt;
IOCS0    [Flush                           ] 00000003&lt;br /&gt;
IOCS1    [Write                           ] 00000003&lt;br /&gt;
IOCS2    [Read                            ] 00000001&lt;br /&gt;
IOCS4    [Write Uncorrectable             ] 00000003&lt;br /&gt;
IOCS5    [Compare                         ] 00000001&lt;br /&gt;
IOCS8    [Write Zeroes                    ] 00000003&lt;br /&gt;
IOCS9    [Dataset Management              ] 00000003&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://github.com/linux-nvme/nvme-cli nvme-cli] (github.com/linux-nvme)&lt;br /&gt;
* [https://nvmexpress.org/open-source-nvme-management-utility-nvme-command-line-interface-nvme-cli/ Open Source NVMe™ Management Utility – NVMe Command Line Interface (NVMe-CLI)] (nvmexpress.org, 25.02.2020)&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSDs]]&lt;br /&gt;
[[de:NVMe-CLI]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/EFI_shell_USB_drive</id>
		<title>EFI shell USB drive</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/EFI_shell_USB_drive"/>
		<updated>2026-07-03T05:28:16Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The &amp;#039;&amp;#039;&amp;#039;EFI shell&amp;#039;&amp;#039;&amp;#039; allows to run EFI applications, such as tools for updating the BIOS or the firmware of network cards or RAID controllers. In a lot of systems, an EFI shell is already included in the BIOS. If an integrated EFI shell is missing, an USB drive with EFI shell can be used as an alternative.   == Create USB stick with EFI shell == The following steps must be performed, to create an USB drive with EFI shell: # Format USB stick with &amp;#039;&amp;#039;&amp;#039;FAT32&amp;#039;&amp;#039;&amp;#039;  # Create &amp;#039;&amp;#039;&amp;#039;/...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;EFI shell&amp;#039;&amp;#039;&amp;#039; allows to run EFI applications, such as tools for updating the BIOS or the firmware of network cards or RAID controllers. In a lot of systems, an EFI shell is already included in the BIOS. If an integrated EFI shell is missing, an USB drive with EFI shell can be used as an alternative. &lt;br /&gt;
&lt;br /&gt;
== Create USB stick with EFI shell ==&lt;br /&gt;
The following steps must be performed, to create an USB drive with EFI shell:&lt;br /&gt;
# Format USB stick with &amp;#039;&amp;#039;&amp;#039;FAT32&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
# Create &amp;#039;&amp;#039;&amp;#039;/efi/boot&amp;#039;&amp;#039;&amp;#039; directory on USB drive&lt;br /&gt;
# Download UEFI shell (&amp;#039;&amp;#039;&amp;#039;Shell.efi&amp;#039;&amp;#039;&amp;#039;) and store it in the /efi/boot/ directory on the USB drive: &lt;br /&gt;
#*https://github.com/tianocore/edk2/blob/edk2-stable201903/ShellBinPkg/UefiShell/X64/Shell.efi (includes UEFI interactive shell v2.2)&lt;br /&gt;
# Rename Shell.efi to &amp;#039;&amp;#039;&amp;#039;Bootx64.efi&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
&lt;br /&gt;
== Test UEFI shell ==&lt;br /&gt;
Next, you can boot from this USB stick and use the EFI shell:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:BIOS-Boot-Override-USB-Pen-Drive.jpg|Boot into the BIOS and, under &amp;#039;&amp;#039;&amp;#039;Save &amp;amp; Exit&amp;#039;&amp;#039;&amp;#039; in the &amp;#039;&amp;#039;&amp;#039;Boot Override&amp;#039;&amp;#039;&amp;#039; section&amp;#039;&amp;#039;&amp;#039;,&amp;#039;&amp;#039;&amp;#039; select the UEFI entry for the USB drive you created. (&amp;#039;&amp;#039;&amp;#039;UEFI: Lexar USB Flash Drive ...&amp;#039;&amp;#039;&amp;#039; in this example).&lt;br /&gt;
File:EFI-Shell-v2.2.jpg|The EFI shell is started.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
&lt;br /&gt;
[[Category:UEFI]]&lt;br /&gt;
[[de:EFI Shell USB Stick]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Grafana_installation_and_configuration_on_Ubuntu_server_18.04_LTS</id>
		<title>Grafana installation and configuration on Ubuntu server 18.04 LTS</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Grafana_installation_and_configuration_on_Ubuntu_server_18.04_LTS"/>
		<updated>2026-07-01T09:27:26Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Grafana&amp;#039;&amp;#039;&amp;#039; is a webbased open source frontend for virtualizing metrics and for alerting when thresholds are exceeded. Grafana &amp;#039;&amp;#039;&amp;#039;supports numerous data sources&amp;#039;&amp;#039;&amp;#039;, for example Time Series databases such as InfluxDB, Graphite or Prometheus, log files via Elasticsearch and SQL data bases. Pre-defined dashboards are available through a marketplace.&amp;lt;ref&amp;gt;[https://grafana.com/grafana/dashboards Grafana Dashboards] (grafana.com)&amp;lt;/ref&amp;gt; This aticle explains the &amp;#039;&amp;#039;&amp;#039;installa...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Grafana&amp;#039;&amp;#039;&amp;#039; is a webbased open source frontend for virtualizing metrics and for alerting when thresholds are exceeded. Grafana &amp;#039;&amp;#039;&amp;#039;supports numerous data sources&amp;#039;&amp;#039;&amp;#039;, for example Time Series databases such as [[InfluxDB]], Graphite or Prometheus, log files via Elasticsearch and SQL data bases. Pre-defined dashboards are available through a marketplace.&amp;lt;ref&amp;gt;[https://grafana.com/grafana/dashboards Grafana Dashboards] (grafana.com)&amp;lt;/ref&amp;gt; This aticle explains the &amp;#039;&amp;#039;&amp;#039;installation of Grafana&amp;#039;&amp;#039;&amp;#039; in version 6.6.2 on &amp;#039;&amp;#039;&amp;#039;[[Ubuntu]] 18.04 LTS&amp;#039;&amp;#039;&amp;#039; as well as the &amp;#039;&amp;#039;&amp;#039;connection of a InfluxDB database as a data source&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
[[File:OPNsense-Grafana-Dashboard.png|thumb|right|Grafana dashboard with InfluxDB as datasource for monitoring a [[OPNsense]] firewall]]&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Grafana can be easily installed using Ubuntu&amp;#039;s built-in package manager.&amp;lt;ref&amp;gt;[https://grafana.com/docs/grafana/latest/installation/debian/ Install on Debian or Ubuntu] (grafana.com)&amp;lt;/ref&amp;gt; The following paragraphs show how to install Grafana on Ubuntu. Information about the installation on Windows, MAC and other Linux distributions can be found in the Grafana download area.&amp;lt;ref&amp;gt;[https://grafana.com/grafana/download Download Grafana] (grafana.com)&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Add package sources ===&lt;br /&gt;
Since Grafana is not included in the official package repositories, the Grafana repository can be added as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt install -y apt-transport-https&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt install -y software-properties-common wget&lt;br /&gt;
tk@monitoringlesv2:~$ wget -q -O - https://packages.grafana.com/gpg.key | sudo apt-key add -&lt;br /&gt;
tk@monitoringlesv2:~$ sudo add-apt-repository &amp;quot;deb https://packages.grafana.com/oss/deb stable main&amp;quot;&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Install Grafana and activate Systemd daemon ===&lt;br /&gt;
After the package sources have been added, Grafana can be installed and the SystemD-service can be started and activated for Grafana:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt install grafana&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl daemon-reload&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl enable grafana-server&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl start grafana-server&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl status grafana-server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configure Grafana ==&lt;br /&gt;
The configuration is made via Grafana webinterface.&amp;lt;ref&amp;gt;[https://grafana.com/docs/grafana/latest/guides/getting_started/ Getting started] (grafana.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
To proceed with the remaining configuration steps, launch a browser of your choice.&lt;br /&gt;
&lt;br /&gt;
* Webinterface: http://&amp;lt;IP-des-Grafana-Servers&amp;gt;:3000&lt;br /&gt;
* Username: admin&lt;br /&gt;
* Password: admin&lt;br /&gt;
&lt;br /&gt;
=== Login to webinterface ===&lt;br /&gt;
Log in with the username &amp;quot;admin&amp;quot; and the password &amp;quot;admin&amp;quot;:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-001.png|Grafana login&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-002.png|Log in to the web interface using the username &amp;quot;admin&amp;quot; and password &amp;quot;admin&amp;quot;.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-003.png|A prompt to change your password appears.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Add datasource ===&lt;br /&gt;
This paragraph shows how to connect an InfluxDB as datasource to Grafana:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-004.png|After logging in to the web interface, you will see the following screen. Click on &amp;#039;&amp;#039;Add data source&amp;#039;&amp;#039;.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-005.png|Click &amp;#039;&amp;#039;Select&amp;#039;&amp;#039; in the InfluxDB row.  &lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-006.png|Assign a name to the data source, specify the path to InfluxDB, and select the database you want to connect to. Click &amp;#039;&amp;#039;Save &amp;amp; Test&amp;#039;&amp;#039;.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-007.png|If the message &amp;#039;&amp;#039;&amp;#039;Data source is working&amp;#039;&amp;#039;&amp;#039; appears, the connection from InfluxDB to Grafana was successful.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-008.png|Click &amp;#039;&amp;#039;Back&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Import dashboard ===&lt;br /&gt;
Pre-defined Grafana dashboards can be easily imported:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-009.png|Switch to the menu option Dashboards → Home.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-010.png|Go to Create → Import, to import a dashboard. &lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-011.png|Search for a suitable dashboard on Grafana and enter the URL or dashboard ID here.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-012.png|Depending on the dashboard, adjust a few more variables and then click &amp;#039;&amp;#039;Import&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[Category:Monitoring]]&lt;br /&gt;
[[pl:Instalacja i konfiguracja oprogramowania Grafana w Ubuntu Server 18.04 LTS]]&lt;br /&gt;
[[de:Grafana Installation und Konfiguration unter Ubuntu Server 18.04 LTS]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Upload_own_Ubuntu_packages_to_reprepro_repository</id>
		<title>Upload own Ubuntu packages to reprepro repository</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Upload_own_Ubuntu_packages_to_reprepro_repository"/>
		<updated>2026-07-01T05:30:30Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;In the following article, it is explained &amp;#039;&amp;#039;&amp;#039;how to upload&amp;#039;&amp;#039;&amp;#039; your own Ubuntu packages to a &amp;#039;&amp;#039;&amp;#039;reprepro&amp;#039;&amp;#039;&amp;#039; repository. The packages are transferred in a folder on the repository server with &amp;#039;&amp;#039;&amp;#039;dupload&amp;#039;&amp;#039;&amp;#039; via scp and processed there via an inoticoming job from reprepro. In the examples shown, the client is running Ubuntu 12.10, and the server is running &amp;#039;&amp;#039;&amp;#039;Ubuntu 12.04.2&amp;#039;&amp;#039;&amp;#039; with kernel 3.2.0-38-generic.   In the article Create Own apt repository using reprepro on Ubuntu...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the following article, it is explained &amp;#039;&amp;#039;&amp;#039;how to upload&amp;#039;&amp;#039;&amp;#039; your own Ubuntu packages to a &amp;#039;&amp;#039;&amp;#039;reprepro&amp;#039;&amp;#039;&amp;#039; repository. The packages are transferred in a folder on the repository server with &amp;#039;&amp;#039;&amp;#039;dupload&amp;#039;&amp;#039;&amp;#039; via scp and processed there via an inoticoming job from reprepro. In the examples shown, the client is running Ubuntu 12.10, and the server is running &amp;#039;&amp;#039;&amp;#039;Ubuntu 12.04.2&amp;#039;&amp;#039;&amp;#039; with kernel 3.2.0-38-generic. &lt;br /&gt;
&lt;br /&gt;
In the article [[Create Own apt repository using reprepro on Ubuntu]], it is explained how to generate an own reprepro repository.&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
=== On the repository server === &lt;br /&gt;
&amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[http://manpages.ubuntu.com/manpages/lucid/man1/inoticoming.1.html inoticoming Ubuntu-package] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; triggered actions, when files are added to a folder.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ sudo apt-get install inoticoming&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== On the client ===&lt;br /&gt;
&amp;lt;code&amp;gt;dupload&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[http://packages.ubuntu.com/precise/dupload dupload Ubuntu-package] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; loads the Ubuntu packages from the repository server that is monitored by inoticoming.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ sudo apt-get install dupload&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
=== On the server ===&lt;br /&gt;
The configuration file &amp;lt;code&amp;gt;incoming&amp;lt;/code&amp;gt; sets the rules and folders for uploads of new packages into the reprepro repository. The configuration file &amp;lt;code&amp;gt;incoming&amp;lt;/code&amp;gt; is located in the &amp;lt;code&amp;gt;/conf&amp;lt;/code&amp;gt; folder of the used reprepro repos.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ vi packages/conf/incoming&lt;br /&gt;
Name: incoming&lt;br /&gt;
IncomingDir: /home/repository/incoming&lt;br /&gt;
Allow: precise&lt;br /&gt;
Cleanup: on_deny on_error&lt;br /&gt;
Tempdir: /home/repository/incoming_tmp&lt;br /&gt;
LogDir: /home/repository/incoming_log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The &amp;lt;code&amp;gt;incoming&amp;lt;/code&amp;gt; rule is called by &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; via &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ inoticoming --logfile /home/repository/incoming_log/upload.log /home/repository/incoming/ \&lt;br /&gt;
&amp;gt; --stderr-to-log --stdout-to-log --suffix &amp;#039;.changes&amp;#039; \&lt;br /&gt;
&amp;gt; reprepro --waitforlock 100 processincoming incoming {} \;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Make sure that &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; runs under the same user account that manages the repository and uploads the packages. This ensures that the files and folders can be created and have the correct permissions.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ ps -u repository&lt;br /&gt;
  PID TTY          TIME CMD&lt;br /&gt;
[...]&lt;br /&gt;
 3098 ?        00:00:00 inoticoming&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== On the client ===&lt;br /&gt;
First, an SSH key is transmitted to the server for authentication:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ ssh-copy-id -i .ssh/key_rsa.pub repository@192.168.56.102&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The dupload-configuration specifies how the packages are loaded into the rep: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ vi .dupload.conf&lt;br /&gt;
package config;&lt;br /&gt;
$default_host = &amp;quot;tkpack&amp;quot;;&lt;br /&gt;
$cfg{&amp;#039;tkpack&amp;#039;} = {&lt;br /&gt;
        fqdn =&amp;gt; &amp;quot;192.168.56.102&amp;quot;,&lt;br /&gt;
        method =&amp;gt; &amp;quot;scp&amp;quot;,&lt;br /&gt;
        login =&amp;gt; &amp;quot;repository&amp;quot;,&lt;br /&gt;
        incoming =&amp;gt; &amp;quot;/home/repository/incoming/&amp;quot;,&lt;br /&gt;
        # files pass on to dinstall which sends emails itself&lt;br /&gt;
        dinstall_runs =&amp;gt; 1,&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Upload packages to repository == &lt;br /&gt;
You can then use &amp;lt;code&amp;gt;dupload&amp;lt;/code&amp;gt; to upload a package to the repo &amp;#039;&amp;#039;&amp;#039;from the client&amp;#039;&amp;#039;&amp;#039; (in this case, without sending notification emails):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ dupload -f --nomail -t tkpack tkmon_0.0.1-1_amd64.changes&lt;br /&gt;
dupload warning: mail options disabled, can&amp;#039;t run `/usr/sbin/sendmail&amp;#039;: No such file or directory&lt;br /&gt;
dupload note: no announcement will be sent.&lt;br /&gt;
Uploading (scp) to 192.168.56.102:/home/repository/incoming/&lt;br /&gt;
[ job tkmon_0.0.1-1_amd64 from tkmon_0.0.1-1_amd64.changes&lt;br /&gt;
 tkmon_0.0.1-1.dsc, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1-1.debian.tar.gz, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1.orig.tar.gz, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1-1_all.deb, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1-1_amd64.changes ok ]&lt;br /&gt;
Uploading (scp) to tkpack (192.168.56.102)&lt;br /&gt;
[ Uploading job tkmon_0.0.1-1_amd64&lt;br /&gt;
 tkmon_0.0.1-1.dsc 0.8 kB, ok (0 s, 0.81 kB/s)&lt;br /&gt;
 tkmon_0.0.1-1.debian.tar.gz 6.1 kB, ok (0 s, 6.07 kB/s)&lt;br /&gt;
 tkmon_0.0.1.orig.tar.gz 720.0 kB, ok (1 s, 720.00 kB/s)&lt;br /&gt;
 tkmon_0.0.1-1_all.deb 701.7 kB, ok (1 s, 701.66 kB/s)&lt;br /&gt;
 tkmon_0.0.1-1_amd64.changes 1.4 kB, ok (0 s, 1.43 kB/s) ]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;On the server&amp;#039;&amp;#039;&amp;#039;, &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; loads the packages with reprepro into the repository:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~/incoming_log$ cat upload.log &lt;br /&gt;
Will call action reprepro for: tkmon_0.0.1-1_amd64.changes&lt;br /&gt;
Exporting indices...&lt;br /&gt;
:~/incoming_log$ reprepro list precise &lt;br /&gt;
precise|main|i386: tkmon 0.0.1-1&lt;br /&gt;
precise|main|amd64: tkmon 0.0.1-1&lt;br /&gt;
precise|main|source: tkmon 0.0.1-1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
The following error occurs when using the upload method &amp;lt;code&amp;gt;scpb&amp;lt;/code&amp;gt;, which is actually recommended in the dupload man page:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1.dsc&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1.debian.tar.gz&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1.orig.tar.gz&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1_all.deb&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1_amd64.changes&amp;#039;: No such file or directory&lt;br /&gt;
dupload fatal error: ssh -x -l repository 192.168.56.102 &amp;#039;cd /home/repository/incoming/;chmod 0644 tkmon_0.0.1-1.dsc tkmon_0.0.1-1.debian.tar.gz tkmon_0.0.1.orig.tar.gz tkmon_0.0.1-1_all.deb tkmon_0.0.1-1_amd64.changes ;&amp;#039; failed&lt;br /&gt;
 at /usr/bin/dupload line 662&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
This error occurs because &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; is processing the uploaded packages too quickly. The packages have already been moved to the repository by &amp;lt;code&amp;gt;reprepro&amp;lt;/code&amp;gt;, so &amp;lt;code&amp;gt;dupload&amp;lt;/code&amp;gt; can no longer perform a &amp;lt;code&amp;gt;chmod&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Workaround ===&lt;br /&gt;
The right permissions can be set with preupload-hook before the upload. This also allows you to upload using &amp;lt;code&amp;gt;scpb&amp;lt;/code&amp;gt;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
$preupload{&amp;#039;file&amp;#039;} = &amp;#039;chmod 644 %1&amp;#039;,&lt;br /&gt;
$preupload{&amp;#039;deb&amp;#039;} = &amp;#039;chmod 644 %1&amp;#039;,&lt;br /&gt;
$cfg{&amp;#039;tkpack&amp;#039;} = {&lt;br /&gt;
        fqdn =&amp;gt; &amp;quot;192.168.56.102&amp;quot;,&lt;br /&gt;
        method =&amp;gt; &amp;quot;scpb&amp;quot;,&lt;br /&gt;
        login =&amp;gt; &amp;quot;repository&amp;quot;,&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Eigene Ubuntu-Pakete in reprepro Repository hochladen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Linux_file_systems</id>
		<title>Linux file systems</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Linux_file_systems"/>
		<updated>2026-06-30T10:37:36Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;There are numerous &amp;#039;&amp;#039;&amp;#039;file systems&amp;#039;&amp;#039;&amp;#039; for different application purposes. This article includes excerpts highlighting particularly relevant file systems that are also included in the Linux Storage Stack Diagram.  Further file systems are mentioned in the documentation of the Linux kernel.&amp;lt;ref&amp;gt;[https://www.kernel.org/doc/html/latest/filesystems/ Filesystems in the Linux kernel] (www.kernel.org)&amp;lt;/ref&amp;gt;  == File systems for storing data ==  ==...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;There are numerous &amp;#039;&amp;#039;&amp;#039;file systems&amp;#039;&amp;#039;&amp;#039; for different application purposes. This article includes excerpts highlighting particularly relevant file systems that are also included in the [[Linux Storage Stack Diagram|Linux Storage Stack Diagram]]. &lt;br /&gt;
Further file systems are mentioned in the documentation of the Linux kernel.&amp;lt;ref&amp;gt;[https://www.kernel.org/doc/html/latest/filesystems/ Filesystems in the Linux kernel] (www.kernel.org)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== File systems for storing data ==&lt;br /&gt;
&lt;br /&gt;
=== Block-based file systems ===&lt;br /&gt;
The following list displays block-based file systems:&lt;br /&gt;
* [https://docs.kernel.org/filesystems/btrfs.html btrfs] - Copy-on-write file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ext2.html ext2] - New version of extended file system.&lt;br /&gt;
* [https://docs.kernel.org/admin-guide/ext4.html ext4] - An enhanced version of the journal-based ext3 file system with support for large file systems (64-bit).&lt;br /&gt;
* [https://www.kernel.org/doc/html/latest/filesystems/f2fs.html f2fs] - A file system that uses NAND flash storage devices and is based on a log-structured file system (LFS).&lt;br /&gt;
* [https://docs.kernel.org/filesystems/gfs2.html gfs2] - Cluster file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/isofs.html iso9660] - Read-only file system for optical data carrier (CD-ROM, DVD-ROM, Blu-ray Disc etc.).&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ntfs3.html ntfs3] - A fully functional read/write driver for NTFS up to version 3.1.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ocfs2-online-filecheck.html ocfs2] - (Oracle Cluster File System 2) cluster file system from Oracle.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/squashfs.html squashfs] - Comprimized, read-only file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/vfat.html vfat] - File system for Microsoft operating systems. &lt;br /&gt;
* [https://docs.kernel.org/admin-guide/xfs.html xfs] - Journaling file system for Unix-like operating systems developed by Silicon Graphics (SGI) &lt;br /&gt;
&lt;br /&gt;
More details can be found in the article [[Block-based Linux file systems]].&lt;br /&gt;
&lt;br /&gt;
=== Network FS ===&lt;br /&gt;
* ceph&lt;br /&gt;
* coda&lt;br /&gt;
* nfs&lt;br /&gt;
* smbfs&lt;br /&gt;
&lt;br /&gt;
=== Stackable FS ===&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ecryptfs.html ecryptfs] - (Enterprise Cryptographic Filesystem) POSIX-compliant cryptographic stacked file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/overlayfs.html overlayfs] - An overlay file system that provides a writable file system on top of another (usually read-only) file system (often used for live CDs).&lt;br /&gt;
&lt;br /&gt;
=== Raw Flash FS ===&lt;br /&gt;
* jffs2&lt;br /&gt;
* ubifs&lt;br /&gt;
&lt;br /&gt;
== More file systems ==&lt;br /&gt;
&lt;br /&gt;
=== Pseudo FS ===&lt;br /&gt;
* futexfs&lt;br /&gt;
* pipefs&lt;br /&gt;
* [https://docs.kernel.org/filesystems/proc.html proc] - (process filesystem) serves as an interface to internal data structures in the kernel. It can be used to obtain information about the system and to change certain kernel parameters at runtime (sysctl).&lt;br /&gt;
* [https://docs.kernel.org/filesystems/sysfs.html sysfs] - RAM-based file system that was originally based on ramfs. It provides the ability to export kernel data structures, their attributes, and the relationships between them to user space.&lt;br /&gt;
* usbfs&lt;br /&gt;
&lt;br /&gt;
=== Special Purpose FS ===&lt;br /&gt;
* devtmpfs&lt;br /&gt;
* ramfs&lt;br /&gt;
* tmpfs&lt;br /&gt;
&lt;br /&gt;
== Einzelnachweise ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category: Linux Basics]]&lt;br /&gt;
[[de:Linux Dateisysteme]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/FSCK_Best_Practices</id>
		<title>FSCK Best Practices</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/FSCK_Best_Practices"/>
		<updated>2026-06-30T08:14:53Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;File system checks (FSCK) verify the consistency of &amp;#039;&amp;#039;&amp;#039;file systems&amp;#039;&amp;#039;&amp;#039;. Generally, a check of journaling file systems such as Ext3, [[Ext4]], or [[XFS]] is performed quickly, since the metadata journal ensures consistency. Nevertheless, there may be situations in which a file system becomes corrupted and must be &amp;#039;&amp;#039;&amp;#039;fixed&amp;#039;&amp;#039;&amp;#039;. A &amp;#039;&amp;#039;&amp;#039;regular FSCK&amp;#039;&amp;#039;&amp;#039; is &amp;#039;&amp;#039;&amp;#039;recommended&amp;#039;&amp;#039;&amp;#039; on server systems to prevent file system problems. &lt;br /&gt;
&lt;br /&gt;
== Periodic check on Ubuntu ==&lt;br /&gt;
Ubuntu has deactivated the periodical file system check (FSCK) with the release of [[Ubuntu]] 12.04 Precise.&amp;lt;ref name=&amp;quot;e2fsprogs&amp;quot;&amp;gt;[https://bugs.launchpad.net/ubuntu/+source/e2fsprogs/+bug/1083985 fsck routine checks on boot are disabled] (launchpad.net)&amp;lt;/ref&amp;gt;&lt;br /&gt;
* Up through Ubuntu 12.04, FSCK was run at regular intervals during system boot. For this, &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt; were set on certain values when generating the file system:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo tune2fs -l /dev/sda1 | egrep -i &amp;quot;mount count|Check interval|Last|Next&amp;quot;&lt;br /&gt;
Mount count:              2&lt;br /&gt;
Maximum mount count:      39&lt;br /&gt;
Last checked:             Mon Jun 29 20:23:44 2015&lt;br /&gt;
Check interval:           15552000 (6 months)&lt;br /&gt;
Next check after:         Sat Dec 26 19:23:44 2015&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Starting on April 12, you will see the following output: a value of -1 for &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt; and a value of 0 for &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt; disable periodic FSCK:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo tune2fs -l /dev/sda1 | egrep -i &amp;quot;mount count|Check interval|Last|Next&amp;quot;&lt;br /&gt;
Last mounted on:          /&lt;br /&gt;
Mount count:              80&lt;br /&gt;
Maximum mount count:      -1&lt;br /&gt;
Last checked:             Fri Jul 18 21:27:32 2014&lt;br /&gt;
Check interval:           0 (&amp;lt;none&amp;gt;)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint:&amp;#039;&amp;#039;&amp;#039; In server environments, it is generally recommended to verify file systems on a regular basis. Further information can be also found in:&lt;br /&gt;
* [https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Storage_Administration_Guide/ch-fsck.html#fsck-best-practices FSCK Best Practices] (redhat.com)&lt;br /&gt;
* [https://access.redhat.com/solutions/39682 Is it advisable to disable filesystem checks?] (redhat.com)&lt;br /&gt;
&lt;br /&gt;
== Enable periodic FSCK == &lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; In some cases, it may be advisable to perform an FSCK manually rather than on a scheduled basis on server systems.  For larger file systems, an FSCK can take quite a while. If a reboot causes the mount count to reach its limit or if you exceed the interval between checks, an FSCK will be performed during boot, during which the server will be unavailable! When performing the FSCK manually, you determine when it runs.&lt;br /&gt;
&lt;br /&gt;
The use of [[LVM basics|LVM]] also allows to dismiss the FSCK on a snapshot. The downtime of the productive file system can be limited to a minimum with that. See also [[#Filesystem check with LVM Snapshot]].&lt;br /&gt;
&lt;br /&gt;
=== Requirement fstab ===&lt;br /&gt;
In fstab, the &amp;#039;&amp;#039;pass&amp;#039;&amp;#039;, or &amp;#039;&amp;#039;fs_passno&amp;#039;&amp;#039;, field must be set right for the periodic check.&amp;lt;ref&amp;gt;[http://linux.die.net/man/5/fstab fstab man Page]&amp;lt;/ref&amp;gt;&lt;br /&gt;
The default value for the root filesystem is 1. It is best to set other filesystems to 2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo vi /etc/fstab&lt;br /&gt;
# / was on /dev/sda1 during installation&lt;br /&gt;
UUID=410ffeb7-f200-4d44-9517-d1b0926bd574 /               ext4    errors=remount-ro 0       1&lt;br /&gt;
# /home was on /dev/sda2 during installation&lt;br /&gt;
UUID=30995b90-3348-4de3-905b-593f7e2de487 /home           ext4    defaults        0       2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure settings ===&lt;br /&gt;
To enable periodic FSCK at boot time, adjust the values &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt; with tune2fs:&lt;br /&gt;
# &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt;: Number of mount-processes on which the file system is verified automatically.&lt;br /&gt;
# &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt;: Maximum time elapsed between two checks.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo tune2fs -c 60 /dev/sda1&lt;br /&gt;
tune2fs 1.42.9 (4-Feb-2014)&lt;br /&gt;
Setting maximal mount count to 60&lt;br /&gt;
$ sudo tune2fs -i 30d /dev/sda1&lt;br /&gt;
tune2fs 1.42.9 (4-Feb-2014)&lt;br /&gt;
Setting interval between checks to 2592000 seconds&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Force FSCK when booting ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint:&amp;#039;&amp;#039;&amp;#039; The settings of the &amp;#039;&amp;#039;pass&amp;#039;&amp;#039;, or also &amp;#039;&amp;#039;fs_passno&amp;#039;&amp;#039;, field ( see [[#Requirement fstab]]) are ignored during a forced FSCK! All file systems listed in fstab are verified.&lt;br /&gt;
&lt;br /&gt;
Up through Ubuntu version 15.10, it was possible to force an FSCK on the next reboot by creating the file /forcefsck. The next boot would then run an FSCK:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo touch /forcefsck&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
From Ubuntu 16.04, this is possible via the following kernel boot parameter (that can be set in the Grub configuration):&amp;lt;ref&amp;gt;[https://ubuntuforums.org/showthread.php?t=2326230&amp;amp;p=13496775#post13496775 forcefsck not working] (ubuntuforums.org, 30.05.2016)&amp;lt;/ref&amp;gt;&lt;br /&gt;
 fsck.mode=force&lt;br /&gt;
&lt;br /&gt;
=== Auto repair ===&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; The following option triggers an auto-repair when errors occur. Automatic error correction is not always desirable or practical in every situation!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo vi /etc/default/rcS&lt;br /&gt;
[...]&lt;br /&gt;
# automatically repair filesystems with inconsistencies during boot&lt;br /&gt;
FSCKFIX=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Standard settings for new file systems ==&lt;br /&gt;
The standard settings for new created file systems can be made in the &amp;#039;&amp;#039;mke2fs.conf&amp;#039;&amp;#039; file. The periodical check of file systems is deactivated via default. To activate it, set &amp;#039;&amp;#039;enable_periodic_fsck&amp;#039;&amp;#039; to 1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo vi /etc/mke2fs.conf&lt;br /&gt;
[defaults]&lt;br /&gt;
        base_features = sparse_super,filetype,resize_inode,dir_index,ext_attr&lt;br /&gt;
        default_mntopts = acl,user_xattr&lt;br /&gt;
        enable_periodic_fsck = 1&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
As a result, the FSCK is set up automatically for new file systems:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo mkfs.ext4 /dev/loop0&lt;br /&gt;
[...]&lt;br /&gt;
This filesystem will be automatically checked every 23 mounts or&lt;br /&gt;
180 days, whichever comes first.  Use tune2fs -c or -i to override.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Manual file system check ==&lt;br /&gt;
A manual file system check for ext4 can be started with fsck.ext4 from the e2fsprogs package.&amp;lt;ref&amp;gt;[http://packages.ubuntu.com/trusty/e2fsprogs Package e2fsprogs] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; The name of the other tools, for example for XFS, can be found in the article [[Linux file systems]]. &lt;br /&gt;
&lt;br /&gt;
Ideally, a FSCK is not only started on mounted file systems. The following is located in the manpage:&amp;lt;ref&amp;gt;[http://linux.die.net/man/8/e2fsck e2fsck man Page] (linux.die.net)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Note that, in general, it is not safe to run e2fsck on mounted filesystems.  The only exception is if the -n option is specified,  and  -c, -l, or -L options are not specified.   However, even if it is safe to do so, the results printed by e2fsck are not valid if the filesystem is mounted.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the file system is currently in a &amp;#039;&amp;#039;clean&amp;#039;&amp;#039; state, the FSCK must be started with &amp;#039;&amp;#039;-f&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo fsck.ext4  /dev/loop0&lt;br /&gt;
e2fsck 1.42.9 (4-Feb-2014)&lt;br /&gt;
/dev/loop0: clean, 11/7680 files, 2370/30720 blocks&lt;br /&gt;
$ sudo fsck.ext4 -f /dev/loop0&lt;br /&gt;
e2fsck 1.42.9 (4-Feb-2014)&lt;br /&gt;
Pass 1: Checking inodes, blocks, and sizes&lt;br /&gt;
Pass 2: Checking directory structure&lt;br /&gt;
Pass 3: Checking directory connectivity&lt;br /&gt;
Pass 4: Checking reference counts&lt;br /&gt;
Pass 5: Checking group summary information&lt;br /&gt;
/dev/loop0: 11/7680 files (9.1% non-contiguous), 2370/30720 blocks&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Not interactive filesystem check ===&lt;br /&gt;
The option &amp;#039;&amp;#039;-n&amp;#039;&amp;#039; performs a FSCK in read-only mode and assumes &amp;#039;&amp;#039;No&amp;#039;&amp;#039; as the answer to any question that may arise.  The option is therefore suitable for not starting an FSCK interactively, for example regularly and automatized via cron job. Please note that the file system must not be mounted in this case.&lt;br /&gt;
&lt;br /&gt;
== Filesystem check with LVM snapshot ==&lt;br /&gt;
Using LVM allows you to perform file system checks using a snapshot. This means the device being checked does not need to be unmounted for the duration of the check. It is sufficient to unmount the file system being checked in order to create the snapshot. Theoretically, an LVM snapshot of a mounted file system would also be possible. However, the snapshot is only clean and truly consistent if the logical volume is not mounted.&lt;br /&gt;
&lt;br /&gt;
This method for a FSCK using an LVM snapshot is also recommended by Theodore Ts&amp;#039;o in Mailing List Posts.&amp;lt;ref name=&amp;quot;e2fsprogs&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;periodicfsck&amp;quot;&amp;gt;[https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773267 Provide a means to query fsck whether it would run a routine check] (debian.org)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The &amp;#039;&amp;#039;lazy&amp;#039;&amp;#039; option can be helpful if users are currently working with the file system. With a lazy unmount, file system resources are released when they are no longer in use by users. You can also use &amp;#039;&amp;#039;lsof&amp;#039;&amp;#039; beforehand to check whether a file system is currently still in use. In the following example, unmounting is not possible because a user is still in the directory:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# lsof | grep -i mnt&lt;br /&gt;
bash       6963            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
lsof      14456            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
grep      14457            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
lsof      14458            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
# umount /mnt&lt;br /&gt;
umount: /mnt: device is busy.&lt;br /&gt;
        (In some cases useful info about processes that use&lt;br /&gt;
         the device is found by lsof(8) or fuser(1))&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; The snapshot must not fill up during the FSCK. Therefore, when creating the snapshot, make sure to choose an appropriate size! In this case, a snapshot size of 20 gigabytes was selected.&lt;br /&gt;
&lt;br /&gt;
The following commands must be used for creating the snapshot and for starting the FSCK:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# umount -l /dev/vg00/data&lt;br /&gt;
# lvcreate -s -n data_snap -L 20G /dev/vg00/data&lt;br /&gt;
# mount /dev/vg00/data /mnt/&lt;br /&gt;
# fsck.ext4 -f /dev/vg00/data_snap&lt;br /&gt;
# lvremove -f /dev/vg00/data_snap&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The advantage of LVM is that the file system can be remounted immediately after the snapshot is created.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Basics]]&lt;br /&gt;
[[de:FSCK Best Practices]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/VMware_Contract_ID</id>
		<title>VMware Contract ID</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/VMware_Contract_ID"/>
		<updated>2026-06-30T05:37:18Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;For the renewal of an existing or soon-to-expire VMware support &amp;amp; subscription contract, the &amp;#039;&amp;#039;&amp;#039;Support Contract ID&amp;#039;&amp;#039;&amp;#039; of the product is required.  This information can be found in your [https://support.broadcom.com/ Broadcom Support Portal] in &amp;#039;&amp;#039;&amp;#039;MyEntitlements.&amp;#039;&amp;#039;&amp;#039;  &amp;lt;gallery width=&amp;quot;1024&amp;quot; height=&amp;quot;820&amp;quot; showcarousel=&amp;quot;false&amp;quot; slideinfozoneopacity=&amp;quot;0.95&amp;quot;&amp;gt; file:Vmware support id 1.png|Select &amp;#039;&amp;#039;&amp;#039;My Entitlements&amp;#039;&amp;#039;&amp;#039; file:Vmware support id 2.png|Select your &amp;#039;&amp;#039;&amp;#039;Site ID&amp;#039;&amp;#039;&amp;#039; , then &amp;#039;&amp;#039;...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the renewal of an existing or soon-to-expire VMware support &amp;amp; subscription contract, the &amp;#039;&amp;#039;&amp;#039;Support Contract ID&amp;#039;&amp;#039;&amp;#039; of the product is required.&lt;br /&gt;
&lt;br /&gt;
This information can be found in your [https://support.broadcom.com/ Broadcom Support Portal] in &amp;#039;&amp;#039;&amp;#039;MyEntitlements.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery width=&amp;quot;1024&amp;quot; height=&amp;quot;820&amp;quot; showcarousel=&amp;quot;false&amp;quot; slideinfozoneopacity=&amp;quot;0.95&amp;quot;&amp;gt;&lt;br /&gt;
file:Vmware support id 1.png|Select &amp;#039;&amp;#039;&amp;#039;My Entitlements&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
file:Vmware support id 2.png|Select your &amp;#039;&amp;#039;&amp;#039;Site ID&amp;#039;&amp;#039;&amp;#039; , then &amp;#039;&amp;#039;&amp;#039;Entitlement Details&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;Contract Details&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
file:Vmware support id 3.png|You will find the required &amp;#039;&amp;#039;&amp;#039;Contract Number&amp;#039;&amp;#039;&amp;#039; in the left column.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Npauli}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:VMware vSphere 8.0]]&lt;br /&gt;
[[de:VMware Contract ID]]&lt;br /&gt;
[[pl:Przedłużenie wsparcia producenta oraz subskrypcji produktów VMware - VMware Contract ID]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Upgrade_Linux_Mint_Debian_Edition</id>
		<title>Upgrade Linux Mint Debian Edition</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Upgrade_Linux_Mint_Debian_Edition"/>
		<updated>2026-06-29T11:52:39Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;An installation of &amp;#039;&amp;#039;&amp;#039;Linux Mint Debian Edition&amp;#039;&amp;#039;&amp;#039; (LMDE) can be updated to a newer version once it is released. In this example, we present the upgrade from LMDE 6 to LMDE 7.   == Preparation ==  To prepare, the updatetool mintupgrade must be installed:&amp;lt;ref&amp;gt;[https://blog.linuxmint.com/?p=4923 How to upgrade to LMDE 7] (blog.linuxmint.com, 14.10.2025)&amp;lt;/ref&amp;gt;  apt update  apt install mintupgrade  &amp;#039;&amp;#039;&amp;#039;Important note - create backup:&amp;#039;&amp;#039;&amp;#039; Before you continue, we recommend t...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An installation of &amp;#039;&amp;#039;&amp;#039;[[Linux]] Mint Debian Edition&amp;#039;&amp;#039;&amp;#039; (LMDE) can be updated to a newer version once it is released. In this example, we present the upgrade from LMDE 6 to LMDE 7. &lt;br /&gt;
&lt;br /&gt;
== Preparation == &lt;br /&gt;
To prepare, the updatetool mintupgrade must be installed:&amp;lt;ref&amp;gt;[https://blog.linuxmint.com/?p=4923 How to upgrade to LMDE 7] (blog.linuxmint.com, 14.10.2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
 apt update&lt;br /&gt;
 apt install mintupgrade&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important note - create backup:&amp;#039;&amp;#039;&amp;#039; Before you continue, we recommend to create a recent backup of your data.&lt;br /&gt;
&lt;br /&gt;
== Perform update ==&lt;br /&gt;
Next, start the updatetool:&lt;br /&gt;
 sudo mintupgrade&lt;br /&gt;
&lt;br /&gt;
The following screenshots display the individual steps of the upgrade process:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:LMDE-7-Upgrade-01.png&lt;br /&gt;
File:LMDE-7-Upgrade-02.png&lt;br /&gt;
File:LMDE-7-Upgrade-03.png&lt;br /&gt;
File:LMDE-7-Upgrade-08.png&lt;br /&gt;
File:LMDE-7-Upgrade-09.png&lt;br /&gt;
File:LMDE-7-Upgrade-10.png&lt;br /&gt;
File:LMDE-7-Upgrade-11.png&lt;br /&gt;
File:LMDE-7-Upgrade-12.png&lt;br /&gt;
File:LMDE-7-Upgrade-13.png&lt;br /&gt;
File:LMDE-7-Upgrade-14.png&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cancel and restart upgrade ==&lt;br /&gt;
After this, remove the updatetool and restart the system:&lt;br /&gt;
&lt;br /&gt;
 apt remove mintupgrade&lt;br /&gt;
 sudo reboot&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Mint]]&lt;br /&gt;
[[de:Upgrade Linux Mint Debian Edition]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Installation_of_N8n</id>
		<title>Installation of N8n</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Installation_of_N8n"/>
		<updated>2026-06-19T06:10:54Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;n8n&amp;#039;&amp;#039;&amp;#039; is a performant open-source platform for automatizing workflows. In contrast to cloud services such as Zapier or Make.com, n8n enables self-hostet operation, which allows you to maintain full control over your data, workflows, and costs. &lt;br /&gt;
&lt;br /&gt;
This article describes four different self-contained methods (&amp;quot;paths&amp;quot;) to install n8n on a local Linux server. Select the path that fits best to your use case and follow the steps from beginning to end. &lt;br /&gt;
&lt;br /&gt;
== Requirements == &lt;br /&gt;
=== General requirements (for all methods) ===&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Server:&amp;#039;&amp;#039;&amp;#039; A physical server or a virtual machine. &lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Resources:&amp;#039;&amp;#039;&amp;#039; At least 1 vCPU and 2 GB RAM. 2+ vCPUs and 4+ GB RAM are recommended for productive use.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;User rights:&amp;#039;&amp;#039;&amp;#039; You will require a user with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;-rights.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;System updates:&amp;#039;&amp;#039;&amp;#039; It is recommended to update the system in advance:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo apt update &amp;amp;&amp;amp; sudo apt upgrade -y&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Specific software (depending on the path) ===&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;For path 1 &amp;amp; 2 (Docker / Docker Compose):&amp;#039;&amp;#039;&amp;#039; Install the docker engine and the compose plugin via the &amp;#039;&amp;#039;&amp;#039;official docker repositories&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo apt-get remove docker docker-engine docker.io containerd runc &amp;amp;&amp;amp; sudo apt-get autoremove -y&lt;br /&gt;
# 2. Set up Repository and install docker&lt;br /&gt;
sudo apt-get update &amp;amp;&amp;amp; sudo apt-get install -y ca-certificates curl&lt;br /&gt;
sudo install -m 0755 -d /etc/apt/keyrings&lt;br /&gt;
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg&lt;br /&gt;
echo &amp;quot;deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(. /etc/os-release &amp;amp;&amp;amp; echo &amp;quot;$VERSION_CODENAME&amp;quot;) stable&amp;quot; | sudo tee /etc/apt/sources.list.d/docker.list &amp;gt; /dev/null&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin&lt;br /&gt;
# 3. Set permissions (crucial!)&lt;br /&gt;
sudo usermod -aG docker $USER&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important:&amp;#039;&amp;#039;&amp;#039; So that docker permissions work, you have to &amp;#039;&amp;#039;&amp;#039;log out and log in&amp;#039;&amp;#039;&amp;#039; or execute the command &amp;lt;code&amp;gt;newgrp docker&amp;lt;/code&amp;gt; in your current shell. &lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;For path 3 (npm):&amp;#039;&amp;#039;&amp;#039; Install Node.js (v18+) and the package manager npm.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -&lt;br /&gt;
sudo apt-get install -y nodejs&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;For path 4 (Proxmox):&amp;#039;&amp;#039;&amp;#039; A functional Proxmox VE installation is required.&lt;br /&gt;
&lt;br /&gt;
== Installation paths ==&lt;br /&gt;
&lt;br /&gt;
=== Path 1: Docker (fast &amp;amp; simple for tests) ===&lt;br /&gt;
This method is ideal to test n8n fast and uncomplicated.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Create data directory&amp;#039;&amp;#039;&amp;#039; This steps avoids permission issues in the container.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkdir -p ~/.n8n&lt;br /&gt;
sudo chown -R $USER:$USER ~/.n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Start container&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
docker run -d --rm --name n8n -p 5678:5678 -v ~/.n8n:/home/node/.n8n n8nio/n8n:latest&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
n8n is available on &amp;lt;code&amp;gt;http://&amp;lt;Ihre-Server-IP&amp;gt;:5678&amp;lt;/code&amp;gt;. You will see a security warning about &amp;quot;secure cookie&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Resolve access issue&amp;#039;&amp;#039;&amp;#039; You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; Stop the old container (&amp;lt;code&amp;gt;docker stop n8n&amp;lt;/code&amp;gt;) and restart it with additional environment variable.&lt;br /&gt;
This is only suitable for localhost testing!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
docker run -d --rm --name n8n -p 5678:5678 -v ~/.n8n:/home/node/.n8n -e &amp;quot;N8N_SECURE_COOKIE=false&amp;quot; n8nio/n8n:latest&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach using Reverse Proxy (recommended):&amp;#039;&amp;#039;&amp;#039; Set up a reverse proxy to run n8n over HTTPS using a domain.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
=== Path 2: Docker Compose (recommended for productive use) ===&lt;br /&gt;
This method is a robust method and ideal for long-term use, as it clearly divides the data base and n8n.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Create project directory and configuration file&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkdir -p ~/n8n-produktiv&lt;br /&gt;
cd ~/n8n-produktiv&lt;br /&gt;
nano docker-compose.yml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Add content for &amp;lt;code&amp;gt;docker-compose.yml&amp;lt;/code&amp;gt;&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Replace the placeholders for the passwords.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
services:&lt;br /&gt;
  n8n:&lt;br /&gt;
    image: n8nio/n8n:latest&lt;br /&gt;
    ports:&lt;br /&gt;
      - &amp;quot;5678:5678&amp;quot;&lt;br /&gt;
    restart: always&lt;br /&gt;
    environment:&lt;br /&gt;
      - DB_TYPE=postgresdb&lt;br /&gt;
      - DB_POSTGRESDB_HOST=postgres&lt;br /&gt;
      - DB_POSTGRESDB_PORT=5432&lt;br /&gt;
      - DB_POSTGRESDB_DATABASE=n8n&lt;br /&gt;
      - DB_POSTGRESDB_USER=n8n&lt;br /&gt;
      - DB_POSTGRESDB_PASSWORD=IHR_N8N_DB_PASSWORT&lt;br /&gt;
      - GENERIC_TIMEZONE=Europe/Berlin&lt;br /&gt;
    volumes:&lt;br /&gt;
      - n8n_data:/home/node/.n8n&lt;br /&gt;
    depends_on:&lt;br /&gt;
      - postgres&lt;br /&gt;
  postgres:&lt;br /&gt;
    image: postgres:14&lt;br /&gt;
    restart: always&lt;br /&gt;
    environment:&lt;br /&gt;
      - POSTGRES_USER=n8n&lt;br /&gt;
      - POSTGRES_PASSWORD=IHR_N8N_DB_PASSWORT&lt;br /&gt;
      - POSTGRES_DB=n8n&lt;br /&gt;
    volumes:&lt;br /&gt;
      - postgres_data:/var/lib/postgresql/data&lt;br /&gt;
volumes:&lt;br /&gt;
  n8n_data:&lt;br /&gt;
  postgres_data:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Start container&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
docker compose up -d&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
As the port is only connected to 127.0.0.1, n8n is not directly accessible from outside. This is intentional. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 4: Enable access&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; Change the port assignment in the &amp;lt;code&amp;gt;docker-compose.yml&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;&amp;quot;5678:5678&amp;quot;&amp;lt;/code&amp;gt; and add to the &amp;lt;code&amp;gt;environment&amp;lt;/code&amp;gt;-block in n8n the line &amp;lt;code&amp;gt;- N8N_SECURE_COOKIE=false&amp;lt;/code&amp;gt;. Restart with &amp;lt;code&amp;gt;docker compose up -d&amp;lt;/code&amp;gt;.&lt;br /&gt;
This is only suitable for LAN-only test without external accessibility!&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach using Reverse Proxy (recommended): &amp;#039;&amp;#039;&amp;#039;Set up a Reverse Proxy, that forwards the traffic to &amp;lt;code&amp;gt;127.0.0.1:5678&amp;lt;/code&amp;gt;.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
=== Path 3: npm (for developers) ===&lt;br /&gt;
This method installs n8n directly on the host system.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Install n8n globally&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
The global installation requires administrator rights.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo npm install -g n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Start n8n&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Execute the command as normal user.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
n8n is now available on &amp;lt;code&amp;gt;http://&amp;amp;#x3C;Your&amp;lt;nowiki/&amp;gt;-Server-IP&amp;gt;:5678&amp;lt;/code&amp;gt; and displays a safety warning. Terminate the process with &amp;lt;code&amp;gt;Strg+C&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Resolve access issue&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; Start n8n with a preceding environment variable.&lt;br /&gt;
Please note that this is only suitable for localhost tests!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
N8N_SECURE_COOKIE=false n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach with Reverse Proxy (recommended): &amp;#039;&amp;#039;&amp;#039;Let n8n run in the background (for example with &amp;lt;code&amp;gt;pm2&amp;lt;/code&amp;gt; oder &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt;) and set up a Reverse Proxy in front of it.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
=== Path 4: Proxmox Helper Scripts (LXC) ===&lt;br /&gt;
This method creates a dedicated, lean Linux container for n8n. &lt;br /&gt;
&lt;br /&gt;
Attention: We do not recommend this for productive use!&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Execute installation script&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Execute this command on the &amp;#039;&amp;#039;&amp;#039;Proxmox-Host&amp;#039;&amp;#039;&amp;#039; shell and follow the interactive dialogue.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
bash -c &amp;quot;$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/ct/n8n.sh)&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Test access&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
After the installation, the script outputs the IP address of the container. n8n is available on &amp;lt;code&amp;gt;http://&amp;lt;IP-des-LXC-Containers&amp;gt;:5678&amp;lt;/code&amp;gt; and displays the safety warning.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Resolve access issue&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; The environment variable must be configured directly in the container.&lt;br /&gt;
This is only suitable for LAN-tests without external availability!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# 1. Verbinden Sie sich mit der Shell des n8n-Containers&lt;br /&gt;
ssh root@&amp;lt;IP-des-LXC-Containers&amp;gt;&lt;br /&gt;
# 2. Öffnen Sie die systemd-Service-Datei&lt;br /&gt;
nano /etc/systemd/system/n8n.service&lt;br /&gt;
# 3. Fügen Sie unter dem Abschnitt [Service] folgende Zeile hinzu:&lt;br /&gt;
Environment=&amp;quot;N8N_SECURE_COOKIE=false&amp;quot;&lt;br /&gt;
# 4. Speichern, schließen und die Dienste neu laden/starten&lt;br /&gt;
systemctl daemon-reload &amp;amp;&amp;amp; systemctl restart n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach with Reverse Proxy (recommended):&amp;#039;&amp;#039;&amp;#039; Set up a Reverse Proxy on another server or in another container that forwards the traffic to &amp;lt;code&amp;gt;http://&amp;lt;IP-des-LXC-Containers&amp;gt;:5678&amp;lt;/code&amp;gt;.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
* [https://docs.n8n.io/hosting/self-hosted/ n8n Documentation – Self‑Hosted] (en)&lt;br /&gt;
* [https://github.com/n8n-io/n8n n8n auf GitHub] (en)&lt;br /&gt;
* [https://tteck.github.io/Proxmox/ Proxmox VE Helper-Scripts von tteck] (en)&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Automation]]&lt;br /&gt;
[[Category:Artificial Intelligence]]&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[Category:VMs/Containers]]&lt;br /&gt;
[[de:N8n installieren]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Creation_of_Proxmox_HA_cluster</id>
		<title>Creation of Proxmox HA cluster</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Creation_of_Proxmox_HA_cluster"/>
		<updated>2026-06-18T10:12:06Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes the configuration of a &amp;#039;&amp;#039;&amp;#039;High Availability Cluster&amp;#039;&amp;#039;&amp;#039; or &amp;#039;&amp;#039;&amp;#039;HA Cluster&amp;#039;&amp;#039;&amp;#039; using three servers with &amp;#039;&amp;#039;&amp;#039;Proxmox&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;VE&amp;#039;&amp;#039;&amp;#039; 8.2.2. In this example, Ceph is configured within the cluster as the data storage.  ==Requirements for High Availability== Before configuring the HA cluster, it must be verified if all requirements are fulfilled: *3 server systems identical in design  * all nodes must be located in the same system * date and time must be sy...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes the configuration of a &amp;#039;&amp;#039;&amp;#039;High Availability Cluster&amp;#039;&amp;#039;&amp;#039; or &amp;#039;&amp;#039;&amp;#039;HA Cluster&amp;#039;&amp;#039;&amp;#039; using three servers with &amp;#039;&amp;#039;&amp;#039;Proxmox&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;VE&amp;#039;&amp;#039;&amp;#039; 8.2.2. In this example, [[Ceph]] is configured within the cluster as the data storage.&lt;br /&gt;
&lt;br /&gt;
==Requirements for High Availability==&lt;br /&gt;
Before configuring the HA cluster, it must be verified if all requirements are fulfilled:&lt;br /&gt;
*3 server systems identical in design &lt;br /&gt;
* all nodes must be located in the same system&lt;br /&gt;
* date and time must be synchronized (NTP)&lt;br /&gt;
* SSH must be released for SSH on port 22&lt;br /&gt;
&lt;br /&gt;
==Installation and configuration==&lt;br /&gt;
First, Proxmox must be installed on all 3 nodes. Please make sure that you have entered the correct host name and IP configuration.&lt;br /&gt;
&lt;br /&gt;
=== Network configuration === &lt;br /&gt;
After that, the network configuration of all nodes must be made. The following steps must be executed after the installation has been successful:&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:Initiale Netzwerkkonfiguration.png|First, select the host name and click on &amp;#039;&amp;#039;&amp;#039;[Network]&amp;#039;&amp;#039;&amp;#039;. Next, you will see the initial network configuration, which can be adjusted according to your requirements. &lt;br /&gt;
file:Netzwerkkonfiguration PVE.png|After that, the changes are applied by clicking on &amp;#039;&amp;#039;&amp;#039;[Apply]&amp;#039;&amp;#039;&amp;#039;. This process must be repeated on the remaining nodes.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, the network configuration can be verified with a ping test. You can also test the ping with jumbo frames, if configured. The following command would test this with an MTU configured to 9000 bytes:&amp;lt;pre&amp;gt;&lt;br /&gt;
ping -M do -s 8972 [IP-Adresse]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Create Proxmox VE cluster===&lt;br /&gt;
The following steps must be executed to create the cluster:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:Create PVE Cluster.png|Go to &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[Cluster]&amp;#039;&amp;#039;&amp;#039; and click on &amp;#039;&amp;#039;&amp;#039;[Create Cluster]&amp;#039;&amp;#039;&amp;#039;. Now, a pop-up appears where a   &amp;#039;&amp;#039;&amp;#039;Clustername&amp;#039;&amp;#039;&amp;#039; and the &amp;#039;&amp;#039;&amp;#039;Network&amp;#039;&amp;#039;&amp;#039; are entered for the PVE-cluster. By clicking on  &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039; , the cluster is created. &lt;br /&gt;
file:PVE Cluster Join Information .png|Now you can copy the join information by selecting the &amp;#039;&amp;#039;&amp;#039;[Join Information]&amp;#039;&amp;#039;&amp;#039; option and clicking &amp;#039;&amp;#039;&amp;#039;[Copy Information]&amp;#039;&amp;#039;&amp;#039;. This step is required for adding the remaining nodes.  &lt;br /&gt;
file:PVE Cluster Join.png|To add the remaining nodes to the cluster, connect to their GUI and under &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[Cluster]&amp;#039;&amp;#039;&amp;#039;, click &amp;#039;&amp;#039;&amp;#039;[Join Cluster]&amp;#039;&amp;#039;&amp;#039;. After that, the join information, the password and the network can be entered. By clicking on &amp;#039;&amp;#039;&amp;#039;[Join &amp;#039;Clustername&amp;#039;],&amp;#039;&amp;#039;&amp;#039; the host is added. Repeat this process for the remaining servers. &lt;br /&gt;
file:PVE Cluster Final.png|The overview should look similar to this.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint for a cluster with a lot of nodes:&amp;#039;&amp;#039;&amp;#039; For clusters with a large number of nodes (25 or more), enter all nodes in the local hosts file on each cluster node. Otherwise, it may come to high network traffic and stability problems.&lt;br /&gt;
&lt;br /&gt;
===Add Ceph storage===&lt;br /&gt;
To create a Ceph storage for storing all data, the following steps must be performed:&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:1 Ceph Installation.png|Select a node here and click on &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;[Install Ceph]&amp;#039;&amp;#039;&amp;#039; to start the installation.&lt;br /&gt;
file:Ceph Network.png|After the installation has been completed, the &amp;#039;&amp;#039;&amp;#039;Ceph-Network&amp;#039;&amp;#039;&amp;#039; can be stated. In addition, you can also set the number of &amp;#039;&amp;#039;&amp;#039;replicates&amp;#039;&amp;#039;&amp;#039; here. Click on &amp;#039;&amp;#039;&amp;#039;[Next]&amp;#039;&amp;#039;&amp;#039; to complete the configuration. This process is repeated for all nodes.  &lt;br /&gt;
file:Ceph MON MGR.png|Next, some services must be configured for Ceph.  The first are the monitoring and management services. For this, click &amp;#039;&amp;#039;&amp;#039;[Ceph],&amp;#039;&amp;#039;&amp;#039; then  &amp;#039;&amp;#039;&amp;#039;[Monitor]&amp;#039;&amp;#039;&amp;#039; and then &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039; in Monitor and Manager. In this example, one service is created per host. &lt;br /&gt;
file:Ceph MON MGR done.png|The result should look similar to this image.&lt;br /&gt;
file:Disk Wipe GPT.png|The HDDs/SSDs/NVMes must be prepared for the creation of the OSDs.  To do this, delete them under &amp;#039;&amp;#039;&amp;#039;[Disks]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[Wipe Disk]&amp;#039;&amp;#039;&amp;#039; and initialize them with GPT &amp;#039;&amp;#039;&amp;#039;[Initialize Disk with GPT]&amp;#039;&amp;#039;&amp;#039;. Repeat this with all data carriers. &lt;br /&gt;
file:Ceph OSD.png|Now, you can create the OSDs under  &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[OSD]&amp;#039;&amp;#039;&amp;#039; by clicking on &amp;#039;&amp;#039;&amp;#039;[Create: OSD].&amp;#039;&amp;#039;&amp;#039; Select the disk and a device class and confirm it by clicking on &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039;. This must be repeated for all data carriers. &lt;br /&gt;
file:MDS Erstellung.png|After creating the OSD, a Meta Data server can be created under &amp;#039;&amp;#039;&amp;#039;[CephFS].&amp;#039;&amp;#039;&amp;#039; These are required for CephFS. For this, click on  &amp;#039;&amp;#039;&amp;#039;[Create].&amp;#039;&amp;#039;&amp;#039; In this example, a MDS host is created per host&amp;#039;&amp;#039;&amp;#039;.&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
file:CephFS.png|You can now create CephFS by clicking &amp;#039;&amp;#039;&amp;#039;[Create CephFS]&amp;#039;&amp;#039;&amp;#039;. You can use the default values here.&lt;br /&gt;
file:Ceph Pool erstellen.png|Finally, a pool must be created to store all data from the VMs/CTs. For this, switch to  &amp;#039;&amp;#039;&amp;#039;[Pools]&amp;#039;&amp;#039;&amp;#039; and click &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039;. Next, you must assign a pool name; you can also set a &amp;#039;&amp;#039;&amp;#039;target ratio&amp;#039;&amp;#039;&amp;#039; of &amp;#039;&amp;#039;&amp;#039;0.9&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
file:Ceph Health Status.png|Finally, you can check the Ceph dashboard, and everything should be showing as Healthy.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Configuration High Availability ===&lt;br /&gt;
Now you can create the required virtual machines and containers on the cluster. To take advantage of the cluster&amp;#039;s high availability, it is essential that the configured VMs/CTs are added to the HA. To set this up, follow the steps below:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:Add VM to HA.png|Go to &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; and click on &amp;#039;&amp;#039;&amp;#039;[HA]&amp;#039;&amp;#039;&amp;#039;. You can now add the VM to HA by clicking &amp;#039;&amp;#039;&amp;#039;[Add]&amp;#039;&amp;#039;&amp;#039;. To do so, enter the VM ID and a request state, then confirm by clicking &amp;#039;&amp;#039;&amp;#039;[Add]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After all steps have been executed, the cluster is functional and your virtual instance is highly available.&lt;br /&gt;
&lt;br /&gt;
{{Npauli}}&lt;br /&gt;
{{Tlindinger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Proxmox Administration]]&lt;br /&gt;
[[de:Proxmox HA Cluster erstellen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/LVM_basic_configuration</id>
		<title>LVM basic configuration</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/LVM_basic_configuration"/>
		<updated>2026-06-18T07:09:52Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the following article, the &amp;#039;&amp;#039;&amp;#039;basic configuration&amp;#039;&amp;#039;&amp;#039; of LVs is explained. The used system is a &amp;#039;&amp;#039;&amp;#039;Ubuntu Server 10.4&amp;#039;&amp;#039;&amp;#039; with the 2.6.32-24 kernel and the LVM-version 2.02.54(1) (2009-10-26). In the following, it is explained how to create &amp;#039;&amp;#039;&amp;#039;partitions&amp;#039;&amp;#039;&amp;#039; of &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Physical Volumes&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (PVs), a &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Volume Group&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (VG) and the &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Logical Volumes&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (LVs) built on top of them.&lt;br /&gt;
&lt;br /&gt;
==Creating partitions== &lt;br /&gt;
First, the partitions for the PVs are created. The following points must be taken into account:&lt;br /&gt;
&lt;br /&gt;
*[[Partition Alignment]]&lt;br /&gt;
**Switch display to sectors (Switch &amp;quot;-u&amp;quot;)&lt;br /&gt;
**switch off DOS-compatible mode (Switch &amp;quot;-c&amp;quot;)&lt;br /&gt;
*for later LVM management&lt;br /&gt;
**switch system ID of partition to &amp;quot;8e&amp;quot; (Switch &amp;quot;-t&amp;quot; bei fdisk)&lt;br /&gt;
After the changes, the partition table looks as follows: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:/home/tktest# fdisk -lu&lt;br /&gt;
&lt;br /&gt;
Disk /dev/sda: 5368 MB, 5368709120 bytes&lt;br /&gt;
255 heads, 63 sectors/track, 652 cylinders, total 10485760 sectors&lt;br /&gt;
Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;br /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;br /&gt;
Disk identifier: 0x00051afd&lt;br /&gt;
&lt;br /&gt;
   Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;
/dev/sda1   *        2048     9920511     4959232   83  Linux&lt;br /&gt;
Partition 1 does not end on cylinder boundary.&lt;br /&gt;
/dev/sda2         9922558    10483711      280577    5  Extended&lt;br /&gt;
Partition 2 does not end on cylinder boundary.&lt;br /&gt;
/dev/sda5         9922560    10483711      280576   82  Linux swap / Solaris&lt;br /&gt;
&lt;br /&gt;
Disk /dev/sdb: 2147 MB, 2147483648 bytes&lt;br /&gt;
22 heads, 16 sectors/track, 11915 cylinders, total 4194304 sectors&lt;br /&gt;
Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;br /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;br /&gt;
Disk identifier: 0x1673663d&lt;br /&gt;
&lt;br /&gt;
   Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;
/dev/sdb1            2048     4194303     2096128   8e  Linux LVM&lt;br /&gt;
&lt;br /&gt;
Disk /dev/sdc: 2147 MB, 2147483648 bytes&lt;br /&gt;
22 heads, 16 sectors/track, 11915 cylinders, total 4194304 sectors&lt;br /&gt;
Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;br /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;br /&gt;
Disk identifier: 0xbd277faf&lt;br /&gt;
&lt;br /&gt;
   Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;
/dev/sdc1            2048     4194303     2096128   8e  Linux LVM&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Preparation of PVs==&lt;br /&gt;
PVs also include meta data for the administration of volumes (see also [[LVM basics]]). 255 sectors (á 512 byte) are created for the meta data by default. Among other things, a meta data area that is too small can result in, for example, the inability to create snapshots anymore: [[Fix LVM VG vgname metadata too large for circular buffer]]. Therefore, it will make sense to configure a larger meta data area. If you want to enlargen your meta data area, the parameter &amp;quot;--metadatasize&amp;quot; must be added to the command &amp;quot;pvcreate&amp;quot; and then select the desired size at:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
--metadatasize size&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After that, the partitions are initialized as PV.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvcreate /dev/sdb1 &lt;br /&gt;
  Physical volume &amp;quot;/dev/sdb1&amp;quot; successfully created&lt;br /&gt;
root@ubuntu:~# pvcreate /dev/sdc1 &lt;br /&gt;
  Physical volume &amp;quot;/dev/sdc1&amp;quot; successfully created&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The commands &amp;quot;pvs&amp;quot; and &amp;quot;pvdisplay&amp;quot; offer a variety of possibilities to display the current status of the PVs. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvs&lt;br /&gt;
  PV         VG   Fmt  Attr PSize PFree&lt;br /&gt;
  /dev/sdb1       lvm2 --   2.00g 2.00g&lt;br /&gt;
  /dev/sdc1       lvm2 --   2.00g 2.00g&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Creating a VG==&lt;br /&gt;
The PVs, that have been created before, are now summarized to a VG.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# vgcreate vg00 /dev/sdb1 /dev/sdc1 &lt;br /&gt;
  Volume group &amp;quot;vg00&amp;quot; successfully created&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The  &amp;quot;pvdisplay&amp;quot; now shows that a VG was created with the PVs:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvdisplay &lt;br /&gt;
  --- Physical volume ---&lt;br /&gt;
  PV Name               /dev/sdb1&lt;br /&gt;
  VG Name               vg00&lt;br /&gt;
  PV Size               2.00 GiB / not usable 3.00 MiB&lt;br /&gt;
  Allocatable           yes &lt;br /&gt;
  PE Size               4.00 MiB&lt;br /&gt;
  Total PE              511&lt;br /&gt;
  Free PE               511&lt;br /&gt;
  Allocated PE          0&lt;br /&gt;
  PV UUID               fl9ipM-bhhQ-V46G-2iH3-R3yZ-9DsN-JbRmY9&lt;br /&gt;
   &lt;br /&gt;
  --- Physical volume ---&lt;br /&gt;
  PV Name               /dev/sdc1&lt;br /&gt;
  VG Name               vg00&lt;br /&gt;
  PV Size               2.00 GiB / not usable 3.00 MiB&lt;br /&gt;
  Allocatable           yes &lt;br /&gt;
  PE Size               4.00 MiB&lt;br /&gt;
  Total PE              511&lt;br /&gt;
  Free PE               511&lt;br /&gt;
  Allocated PE          0&lt;br /&gt;
  PV UUID               d1iY5L-ac3F-W5Sz-zyaE-uaT3-f66r-I3831o&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
vgdisplay also shows information on VG: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# vgdisplay &lt;br /&gt;
  --- Volume group ---&lt;br /&gt;
  VG Name               vg00&lt;br /&gt;
  System ID             &lt;br /&gt;
  Format                lvm2&lt;br /&gt;
  Metadata Areas        2&lt;br /&gt;
  Metadata Sequence No  1&lt;br /&gt;
  VG Access             read/write&lt;br /&gt;
  VG Status             resizable&lt;br /&gt;
  MAX LV                0&lt;br /&gt;
  Cur LV                0&lt;br /&gt;
  Open LV               0&lt;br /&gt;
  Max PV                0&lt;br /&gt;
  Cur PV                2&lt;br /&gt;
  Act PV                2&lt;br /&gt;
  VG Size               3.99 GiB&lt;br /&gt;
  PE Size               4.00 MiB&lt;br /&gt;
  Total PE              1022&lt;br /&gt;
  Alloc PE / Size       0 / 0   &lt;br /&gt;
  Free  PE / Size       1022 / 3.99 GiB&lt;br /&gt;
  VG UUID               YTEj9f-9LCT-EOP5-JBEA-YHSz-c0R1-TMzVmy&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
What stands out here is, that the PE size is 4.00 MiB. Since the lvm2-format, the number of PEs is not limited anymore. According to the Man page of vgcreate, a high number of PEs can slow down the tools. However, the number of pEs does not have influence on the I/O-performance of the Logical Volumes. If you want to change the PE-size, add the parameter to &amp;quot;vgcreate&amp;quot;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
-s, --physicalextentsize PhysicalExtentSize&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Creating LVs==&lt;br /&gt;
&lt;br /&gt;
There are different possibilities to specify the size of the LV to be created. However, all LVs require the parameter &amp;quot;-l&amp;quot; or &amp;quot;-L&amp;quot;.&lt;br /&gt;
*size specification in, for example, Gigabyte: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lvcreate -n data -L1G vg00&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
*Percentage of available storage in the VG:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lvcreate -n data -l100%VG vg00&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
*Percentage of free storage in the VG: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lvcreate -n data -l100%FREE vg00&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The example in progress is continued by dividing the VG into two equally sized LVs:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# lvcreate -n data -l50%VG vg00&lt;br /&gt;
  Logical volume &amp;quot;data&amp;quot; created&lt;br /&gt;
root@ubuntu:~# lvcreate -n data1 -l100%FREE vg00&lt;br /&gt;
  Logical volume &amp;quot;data1&amp;quot; created&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, the status of the Logical Volume can be taken into consideration:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# lvdisplay &lt;br /&gt;
  --- Logical volume ---&lt;br /&gt;
  LV Name                /dev/vg00/data&lt;br /&gt;
  VG Name                vg00&lt;br /&gt;
  LV UUID                S1btrq-zQZQ-h9oU-2VE6-UNoT-hkqB-Fpv7pG&lt;br /&gt;
  LV Write Access        read/write&lt;br /&gt;
  LV Status              available&lt;br /&gt;
  # open                 0&lt;br /&gt;
  LV Size                2.00 GiB&lt;br /&gt;
  Current LE             511&lt;br /&gt;
  Segments               1&lt;br /&gt;
  Allocation             inherit&lt;br /&gt;
  Read ahead sectors     auto&lt;br /&gt;
  - currently set to     256&lt;br /&gt;
  Block device           252:0&lt;br /&gt;
   &lt;br /&gt;
  --- Logical volume ---&lt;br /&gt;
  LV Name                /dev/vg00/data1&lt;br /&gt;
  VG Name                vg00&lt;br /&gt;
  LV UUID                Syaml9-d1Ax-RYTs-tSZy-vEyq-yzqW-VoOddZ&lt;br /&gt;
  LV Write Access        read/write&lt;br /&gt;
  LV Status              available&lt;br /&gt;
  # open                 0&lt;br /&gt;
  LV Size                2.00 GiB&lt;br /&gt;
  Current LE             511&lt;br /&gt;
  Segments               1&lt;br /&gt;
  Allocation             inherit&lt;br /&gt;
  Read ahead sectors     auto&lt;br /&gt;
  - currently set to     256&lt;br /&gt;
  Block device           252:1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Creating file system== &lt;br /&gt;
Now, the LVs can be formatted with a file system and mounted afterwards:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkfs.ext4 /dev/vg00/data&lt;br /&gt;
mkdir data&lt;br /&gt;
mount /dev/vg00/data data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Removing LV==&lt;br /&gt;
If a LV should be removed, it can be removed via lvremove command:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# lvremove /dev/vg00/data_snap &lt;br /&gt;
  Do you really want to remove active logical volume data_snap? [y/n]: y  &lt;br /&gt;
  Logical volume &amp;quot;data_snap&amp;quot; successfully removed &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The LV data_snap does no longer appear as an LV. However, the underlying partition is still listed as a PV:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
  --- Physical volume ---   &lt;br /&gt;
PV Name               /dev/sde1   &lt;br /&gt;
VG Name               vg00   &lt;br /&gt;
PV Size               2.00 GiB / not usable 3.00 MiB   &lt;br /&gt;
Allocatable           yes    &lt;br /&gt;
PE Size               4.00 MiB   &lt;br /&gt;
Total PE              511   &lt;br /&gt;
Free PE               511   &lt;br /&gt;
Allocated PE          0   &lt;br /&gt;
PV UUID               lKEW15-1YHu-dikC-S0Pm-72UJ-UMPg-fgiW0Y&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
If the partition should be released completely, the PV must be removed from the VG first:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# vgreduce vg00 /dev/sde1   &lt;br /&gt;
  Removed &amp;quot;/dev/sde1&amp;quot; from volume group &amp;quot;vg00&amp;quot;&lt;br /&gt;
root@ubuntu:~# pvdisplay&lt;br /&gt;
 &amp;quot;/dev/sde1&amp;quot; is a new physical volume of &amp;quot;2.00 GiB&amp;quot;  &lt;br /&gt;
 --- NEW Physical volume ---&lt;br /&gt;
   PV Name               /dev/sde1&lt;br /&gt;
   VG Name                 &lt;br /&gt;
   PV Size               2.00 GiB&lt;br /&gt;
   Allocatable           NO&lt;br /&gt;
   PE Size               0&lt;br /&gt;
   Total PE              0 &lt;br /&gt;
   Free PE               0&lt;br /&gt;
   Allocated PE          0&lt;br /&gt;
   PV UUID               lKEW15-1YHu-dikC-S0Pm-72UJ-UMPg-fgiW0Y &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, the PV can be also deleted completely to reformat, for example, the hard drive:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvremove /dev/sde1&lt;br /&gt;
  Labels on physical volume &amp;quot;/dev/sde1&amp;quot; successfully wiped&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:LVM]]&lt;br /&gt;
[[de:LVM Grundkonfiguration]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Linux_performance_analysis_in_60_seconds</id>
		<title>Linux performance analysis in 60 seconds</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Linux_performance_analysis_in_60_seconds"/>
		<updated>2026-06-17T13:17:30Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;When a critical &amp;#039;&amp;#039;&amp;#039;performance issue&amp;#039;&amp;#039;&amp;#039; arises on a [[Linux]] server, there is often little time to analyze the problem in detail. Brendan Gregg, computer performance analyst and kernel engineer, describes in a blog posting and in a video, &amp;#039;&amp;#039;&amp;#039;which Linux commands he uses for the performance analysis in the first 60 seconds&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Commands for performance analysis == &lt;br /&gt;
The following commands are recommended by Brendan Gregg:&amp;lt;ref&amp;gt;[http://techblog.netflix.com/2015/11/linux-performance-analysis-in-60s.html Linux Performance Analysis in 60,000 Milliseconds] (techblog.netflix.com, 30.11.2015)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
uptime&lt;br /&gt;
dmesg | tail&lt;br /&gt;
vmstat 1&lt;br /&gt;
mpstat -P ALL 1&lt;br /&gt;
pidstat 1&lt;br /&gt;
iostat -xz 1&lt;br /&gt;
free -m&lt;br /&gt;
sar -n DEV 1&lt;br /&gt;
sar -n TCP,ETCP 1&lt;br /&gt;
top&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
More information on these commands can be found in the following articles:&lt;br /&gt;
* vmstat: [[Linux Performance Measurements using vmstat]]&lt;br /&gt;
* mpstat: [[Linux CPU performance measurements with mpstat]]&lt;br /&gt;
* iostat: [[Linux I/O Performance measurements with iostat]]&lt;br /&gt;
* free: [[Linux Page Cache Basics]]&lt;br /&gt;
* sar: [[Collect and report Linux System Activity Information with sar]]&lt;br /&gt;
* top: [[Linux-tool top]]&lt;br /&gt;
&lt;br /&gt;
== Video ==&lt;br /&gt;
In this video, Brendan Gregg shows how to execute these commands in 60 seconds:&amp;lt;ref&amp;gt;[http://www.brendangregg.com/blog/2015-12-03/linux-perf-60s-video.html Linux Performance Analysis in 60s (video)] (www.brendangregg.com/blog, 03.12.2015)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#widget:YouTube|id=ZdVpKx6Wmc8}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Performance]]&lt;br /&gt;
[[de:Linux Performance Analyse in 60 Sekunden]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Docker_basics_-_the_most_important_terms</id>
		<title>Docker basics - the most important terms</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Docker_basics_-_the_most_important_terms"/>
		<updated>2026-06-17T12:17:57Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article provides an introduction in Docker and shows useful terms, which can be useful when using Docker and Docker containers:  &amp;lt;pre&amp;gt; # Start container docker container run &amp;lt;IMAGENAME&amp;gt; starts a container based on an image (Example: checkmk/check-mk-raw:2.2.0-latest)   # List containers (active) docker ps displays a list of all containers that are currently active   # List containers (all)  docker ps -all displays all containers on the system including those that ha...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article provides an introduction in Docker and shows useful terms, which can be useful when using Docker and Docker containers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Start container&lt;br /&gt;
docker container run &amp;lt;IMAGENAME&amp;gt; starts a container based on an image (Example: checkmk/check-mk-raw:2.2.0-latest) &lt;br /&gt;
&lt;br /&gt;
# List containers (active)&lt;br /&gt;
docker ps displays a list of all containers that are currently active &lt;br /&gt;
&lt;br /&gt;
# List containers (all) &lt;br /&gt;
docker ps -all displays all containers on the system including those that have been stopped. &lt;br /&gt;
&lt;br /&gt;
# Stop container &lt;br /&gt;
docker stop &amp;lt;CONTAINER-NAME&amp;gt; stops a container &lt;br /&gt;
&lt;br /&gt;
# Reboot container&lt;br /&gt;
docker restart &amp;lt;CONTAINER-NAME&amp;gt; restarts a Docker container &lt;br /&gt;
&lt;br /&gt;
# Delete container&lt;br /&gt;
docker remove &amp;lt;CONTAINER-NAME&amp;gt; deletes a container &lt;br /&gt;
&lt;br /&gt;
# Display container volume &lt;br /&gt;
docker volume ls displays all created container volumes &lt;br /&gt;
&lt;br /&gt;
# Delete container volume &lt;br /&gt;
docker volume rm &amp;lt;VOLUME-NAME&amp;gt; - deletes a named volume &lt;br /&gt;
&lt;br /&gt;
# Execute container shell command in container&lt;br /&gt;
docker exec &amp;lt;CONTAINER-NAME&amp;gt; &amp;lt;COMMAND&amp;gt; executes the command and displays the output on its own terminal (locally)&lt;br /&gt;
&lt;br /&gt;
# Open the interactive full shell in the container (interactive terminal) &lt;br /&gt;
docker exec -it &amp;lt;CONTAINER-NAME&amp;gt; bash&lt;br /&gt;
&lt;br /&gt;
# Display container logs: &lt;br /&gt;
docker container logs &amp;lt;CONTAINER-NAME&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[de:Docker Grundlagen - die wichtigsten Befehle]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Measuring_TCP_and_UDP_Network_Performance_with_iperf</id>
		<title>Measuring TCP and UDP Network Performance with iperf</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Measuring_TCP_and_UDP_Network_Performance_with_iperf"/>
		<updated>2026-06-17T08:44:44Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;iperf&amp;#039;&amp;#039;&amp;#039;, the open-source tool, allows to measure the maximum TCP and UDP network bandwidth. It is an alternative for netperf&amp;lt;ref&amp;gt;[http://www.netperf.org/ Netperf] (www.netperf.org)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Iperf is already included in the Debian and Ubuntu repository, which means that an installation is easy possible via &amp;lt;code&amp;gt;apt-get install iperf&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
For RHEL and CentOS, the package is available in the EPEL&amp;lt;ref&amp;gt;[http://dl.fedoraproject.org/pub/epel/6/x86_64/repoview/iperf.html IPerf Paket aus EPEL Repository] (download.fedora.redhat.com)&amp;lt;/ref&amp;gt; repository.&lt;br /&gt;
&lt;br /&gt;
Alternatively, the source code can be downloaded from the IPerf website &amp;lt;ref&amp;gt;[http://sourceforge.net/projects/iperf/files/ IPerf] (sourceforge.net)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Use ==&lt;br /&gt;
Iperf works according to the client-sever model, which means that the iperf daemon must be started first on a server and then connects to the iperf client. Client and server are included in the same binary. When entering the IP address for the client, be sure to select the one associated with the network interface you want to test.&lt;br /&gt;
&lt;br /&gt;
=== Measure TCP performance ===&lt;br /&gt;
In this case, the TCP performance of a 1 GBit network card is measured.&lt;br /&gt;
&lt;br /&gt;
Server1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server1 ~]# iperf -s&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Server listening on TCP port 5001&lt;br /&gt;
TCP window size: 85.3 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  4] local 192.168.255.1 port 5001 connected with 192.168.255.2 port 39838&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth&lt;br /&gt;
[  4]  0.0-10.0 sec  1.10 GBytes   941 Mbits/sec&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Server2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server2 ~]# iperf -c 192.168.255.1&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Client connecting to 192.168.255.1, TCP port 5001&lt;br /&gt;
TCP window size: 16.0 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  3] local 192.168.255.2 port 39838 connected with 192.168.255.1 port 5001&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth&lt;br /&gt;
[  3]  0.0-10.0 sec  1.10 GBytes   944 Mbits/sec&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Measure UDP performance ===&lt;br /&gt;
The UDP performance is measured on the same system. In this case, the used bandwidth (-b) must be stated. The default here is only 1 MBit per second. &lt;br /&gt;
&lt;br /&gt;
Server1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server1 ~]# iperf -s -u&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Server listening on UDP port 5001&lt;br /&gt;
Receiving 1470 byte datagrams&lt;br /&gt;
UDP buffer size:  126 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  3] local 192.168.255.1 port 5001 connected with 192.168.255.2 port 40612&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth        Jitter   Lost/Total Datagrams&lt;br /&gt;
[  3]  0.0-10.0 sec   889 MBytes   746 Mbits/sec   0.065 ms  621/634707 (0.098%)&lt;br /&gt;
[  3]  0.0-10.0 sec  1 datagrams received out-of-order&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Server2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server2 ~]# iperf -c 192.168.255.1 -u -b 1000M&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Client connecting to 192.168.255.1, UDP port 5001&lt;br /&gt;
Sending 1470 byte datagrams&lt;br /&gt;
UDP buffer size:  126 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  3] local 192.168.255.2 port 40612 connected with 192.168.255.1 port 5001&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth&lt;br /&gt;
[  3]  0.0-10.0 sec   890 MBytes   746 Mbits/sec&lt;br /&gt;
[  3] Sent 634708 datagrams&lt;br /&gt;
[  3] Server Report:&lt;br /&gt;
[  3]  0.0-10.0 sec   889 MBytes   746 Mbits/sec   0.065 ms  621/634707 (0.098%)&lt;br /&gt;
[  3]  0.0-10.0 sec  1 datagrams received out-of-order&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Hints for 10G/40G tests ==&lt;br /&gt;
When testing 40 Gbit/s connections, it is possible that an individual CPU-core can become a bottleneck. In this case, it is recommended that several parallel tests are operated on different ports.&lt;br /&gt;
&lt;br /&gt;
More information on this topic can be found, for example, on the following pages:&lt;br /&gt;
* [https://fasterdata.es.net/host-tuning/linux/100g-tuning/ 40G/100G Tuning] (fasterdata.es.net)&lt;br /&gt;
* [https://fasterdata.es.net/performance-testing/network-troubleshooting-tools/iperf/multi-stream-iperf3/ iperf3 at 40Gbps and above] (fasterdata.es.net)&lt;br /&gt;
* [https://calomel.org/network_performance.html Network Tuning and Performance: a simple guide to enhancing network speeds] (calomel.org)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Networking]]&lt;br /&gt;
[[Category:Linux Performance]]&lt;br /&gt;
[[de:TCP und UDP Netzwerk Performance mit iperf messen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Permanently_Change_the_Root_Data_Directory_in_Docker</id>
		<title>Permanently Change the Root Data Directory in Docker</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Permanently_Change_the_Root_Data_Directory_in_Docker"/>
		<updated>2026-06-17T05:40:20Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article explains how to permanently switch the default root data directory &amp;lt;code&amp;gt;/var/lib/docker/&amp;lt;/code&amp;gt; to a different directory.  == Background information ==  The &amp;lt;code&amp;gt;/var/lib/docker&amp;lt;/code&amp;gt; directory stores all images, volumes from Docker and can grow significantly depending on how many containers are used. The directory is structured as follows:&amp;lt;pre&amp;gt; root@js-checkmk-02:/var/lib/docker# ls buildkit  containers  engine-id  image  network  overlay2  plugins  runt...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article explains how to permanently switch the default root data directory &amp;lt;code&amp;gt;/var/lib/docker/&amp;lt;/code&amp;gt; to a different directory.&lt;br /&gt;
&lt;br /&gt;
== Background information == &lt;br /&gt;
The &amp;lt;code&amp;gt;/var/lib/docker&amp;lt;/code&amp;gt; directory stores all images, volumes from Docker and can grow significantly depending on how many containers are used. The directory is structured as follows:&amp;lt;pre&amp;gt;&lt;br /&gt;
root@js-checkmk-02:/var/lib/docker# ls&lt;br /&gt;
buildkit  containers  engine-id  image  network  overlay2  plugins  runtimes  swarm  tmp  volumes&amp;lt;/pre&amp;gt; You can see that it is used if you, for example, verify the status with df -h:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;root@js-checkmk-02:/var/lib/docker# df -h&lt;br /&gt;
Filesystem      Size  Used Avail Use% Mounted on&lt;br /&gt;
udev            3.9G     0  3.9G   0% /dev&lt;br /&gt;
tmpfs           794M  684K  794M   1% /run&lt;br /&gt;
/dev/sda1        47G  3.8G   41G   9% /&lt;br /&gt;
tmpfs           3.9G     0  3.9G   0% /dev/shm&lt;br /&gt;
tmpfs           5.0M     0  5.0M   0% /run/lock&lt;br /&gt;
/dev/sda15      124M   12M  113M  10% /boot/efi&lt;br /&gt;
tmpfs           794M     0  794M   0% /run/user/0&lt;br /&gt;
tmpfs           794M     0  794M   0% /run/user/1000&lt;br /&gt;
overlay          47G  3.8G   41G   9% /var/lib/docker/overlay2/a6a4203cef42815c7187f584436e5eb9dff385e3ca9c92d597a38806b9dc255d/merged&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
First, &amp;lt;code&amp;gt;docker&amp;lt;/code&amp;gt; must be stopped, which has immediately influence on all active containers. In addition, we install the tool &amp;lt;code&amp;gt;rsync&amp;lt;/code&amp;gt;.&amp;lt;pre&amp;gt;&lt;br /&gt;
root@js-checkmk-02:/# systemctl stop docker &amp;amp;&amp;amp; apt install rsync&lt;br /&gt;
&amp;lt;/pre&amp;gt;After this, it must be communicated to Docker where to find the new data root:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;# Create directory if it has not been created yet&lt;br /&gt;
root@js-checkmk-02:/# mkdir -p /root/docker/root&lt;br /&gt;
&lt;br /&gt;
# Daemon-Datei anlegen in /etc/docker&lt;br /&gt;
root@js-checkmk-02:/# nano /etc/docker/daemon.json&lt;br /&gt;
&lt;br /&gt;
# Please add the following into the file, then adjust your path and store it. In this example, we change it to /root/docker/root&lt;br /&gt;
&lt;br /&gt;
{&lt;br /&gt;
   &amp;quot;data-root&amp;quot;: &amp;quot;/root/docker/root&amp;quot;&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;Next, the whole content of the old docker-root-directory is copied into the new data-root-directory and then the old &amp;lt;code&amp;gt;/var/lib/docker&amp;lt;/code&amp;gt; directory is renamed to &amp;lt;code&amp;gt;/var/lib/docker.old&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;rsync -aP /var/lib/docker/ &amp;quot;/root/docker/root&amp;quot;&lt;br /&gt;
cp -rp /var/lib/docker/* &amp;quot;/root/docker/root&amp;quot;&lt;br /&gt;
mv /var/lib/docker /var/lib/docker.old&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After that, Docker can be restarted and it should be verified if all containers still function:&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl start docker&lt;br /&gt;
&amp;lt;/pre&amp;gt;If everything functions, the old data-root-directory can be deleted:&amp;lt;pre&amp;gt;&lt;br /&gt;
rm -rf /var/lib/docker.old&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[de:Root Data Directory in Docker dauerhaft ändern]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Checkmk_RAW_Edition_-_Docker_Container_Installation</id>
		<title>Checkmk RAW Edition - Docker Container Installation</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Checkmk_RAW_Edition_-_Docker_Container_Installation"/>
		<updated>2026-06-16T11:51:57Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;These instructions show how to install and start the free RAW-edition on a Debian server.  == Installation == The installation of Docker on a server is a requirement (see Docker installation on Debian 12).  == Container (custom parameter) == Please note: We will provide the default password shortly so that you can log in right away. Otherwise, you may have trouble logging in. Please note that you have to change the following parameters:  * &amp;lt;code&amp;gt;-p 8006:5000&amp;lt;/cod...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;These instructions show how to install and start the free RAW-edition on a [[Debian]] server.&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
The installation of Docker on a server is a requirement (see [[Docker installation on Debian 12]]).&lt;br /&gt;
&lt;br /&gt;
== Container (custom parameter) ==&lt;br /&gt;
Please note: We will provide the default password shortly so that you can log in right away. Otherwise, you may have trouble logging in. Please note that you have to change the following parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;-p 8006:5000&amp;lt;/code&amp;gt; (This is the port for accessing the Web-UI, default is usually 8080:5000)&lt;br /&gt;
* &amp;lt;code&amp;gt;-p 8007:8000&amp;lt;/code&amp;gt; (This is the port for the agent communication, default is usually 8000:8000)&lt;br /&gt;
* &amp;lt;code&amp;gt;-e CMK_PASSWORD=&amp;#039;relation&amp;#039;&amp;lt;/code&amp;gt; (The password for the Web-UI user cmkadmin is set here)&lt;br /&gt;
* &amp;lt;code&amp;gt;-e MAIL_RELAY_HOST=&amp;#039;mail.thomas-krenn.com&amp;#039;&amp;lt;/code&amp;gt; (Please state your mail server if it can be used as relay host) &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
root@js-checkmk-02:/home/tk#  docker container run -dit -p 8006:5000 -p 8007:8000 --tmpfs /opt/omd/sites/cmk/tmp:uid=1000,gid=1000 -v monitoring:/omd/sites --name monitoring -v /etc/localtime:/etc/localtime:ro -e CMK_PASSWORD=&amp;#039;relation&amp;#039; -e MAIL_RELAY_HOST=&amp;#039;mail.thomas-krenn.com&amp;#039; --restart always checkmk/check-mk-raw:2.2.0-latest&lt;br /&gt;
&lt;br /&gt;
Unable to find image &amp;#039;checkmk/check-mk-raw:2.2.0-latest&amp;#039; locally&lt;br /&gt;
2.2.0-latest: Pulling from checkmk/check-mk-raw&lt;br /&gt;
125a6e411906: Pull complete&lt;br /&gt;
1a8b24f9c661: Pull complete&lt;br /&gt;
e005a80d7504: Pull complete&lt;br /&gt;
727db143e9a5: Pull complete&lt;br /&gt;
1c9d1984857d: Pull complete&lt;br /&gt;
6261e32c9473: Pull complete&lt;br /&gt;
Digest: sha256:c75927b694b02fbd748c48f1aa9469964f3c003757ebbd01c17e21daaeb08b20&lt;br /&gt;
Status: Downloaded newer image for checkmk/check-mk-raw:2.2.0-latest&lt;br /&gt;
23a12948f6b3d3a8bb0ed1808a9e4aef6f4183509c14b34de8b84175e7a12a00&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It is searched for the container image online, which will be downloaded. After that, the container will start immediately. You can verify with &amp;lt;code&amp;gt;docker ps&amp;lt;/code&amp;gt;  if everything has functioned:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@js-checkmk-01:~# docker ps&lt;br /&gt;
CONTAINER ID   IMAGE                               COMMAND                  CREATED          STATUS                             PORTS                                                                                            NAMES&lt;br /&gt;
756a5156e143   checkmk/check-mk-raw:2.2.0-latest   &amp;quot;/docker-entrypoint.…&amp;quot;   29 seconds ago   Up 28 seconds (health: starting)   6557/tcp, 0.0.0.0:8000-&amp;gt;8000/tcp, :::8000-&amp;gt;8000/tcp, 0.0.0.0:8080-&amp;gt;5000/tcp, :::8080-&amp;gt;5000/tcp   monitoring&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Webinterface ==&lt;br /&gt;
You can test the Web-UI with &amp;lt;code&amp;gt;http://IP-DES-DOCKER-SERVERS:8006&amp;lt;/code&amp;gt;. Here, we used custom port 8006.&lt;br /&gt;
&lt;br /&gt;
== Login data ==&lt;br /&gt;
You can log in using the following data in the login screen. Please note that the password is the one you set when you first started the container!&lt;br /&gt;
&lt;br /&gt;
* User: cmkadmin&lt;br /&gt;
* Password: relation&lt;br /&gt;
&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[Category:Monitoring]]&lt;br /&gt;
[[de:Checkmk RAW Edition - Docker Container Installation]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Proxmox_Backup_Server_No_Subscription_Update_Repository</id>
		<title>Proxmox Backup Server No Subscription Update Repository</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Proxmox_Backup_Server_No_Subscription_Update_Repository"/>
		<updated>2026-06-16T09:08:21Z</updated>

		<summary type="html">&lt;p&gt;Smueller: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Proxmox Backup Server]] provides different package repositories for installing updates. For production systems, Thomas-Krenn.AG recommends using a [[Proxmox Backup Server Support Subscriptions|Proxmox Backup Server Subscription]].&lt;br /&gt;
&lt;br /&gt;
A valid subscription provides access to the extensively tested Enterprise Repository. Depending on the selected subscription level, technical support from Proxmox is also included. Purchasing a subscription also supports the continuous development of Proxmox Backup Server.&lt;br /&gt;
&lt;br /&gt;
For test and development environments, the publicly available No-Subscription Repository can be used instead. It contains newer packages that have not yet undergone the same extensive testing and validation process as the packages in the Enterprise Repository. Therefore, the No-Subscription Repository is not recommended for production systems.&lt;br /&gt;
&lt;br /&gt;
== Error message without a valid subscription ==&lt;br /&gt;
&lt;br /&gt;
After a default installation, the Enterprise Repository is enabled. If no valid subscription is configured, updating the package lists may result in an error similar to the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Err: https://enterprise.proxmox.com/debian/pbs trixie InRelease&lt;br /&gt;
  401 Unauthorized&lt;br /&gt;
E: Failed to fetch https://enterprise.proxmox.com/debian/pbs/dists/trixie/InRelease&lt;br /&gt;
E: The repository &amp;#039;https://enterprise.proxmox.com/debian/pbs trixie InRelease&amp;#039; is not signed.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this case, the Enterprise Repository must be disabled and the No-Subscription Repository must be configured.&lt;br /&gt;
&lt;br /&gt;
The following configuration applies to Proxmox Backup Server 4.x based on Debian 13 “Trixie”.&lt;br /&gt;
&lt;br /&gt;
== Disable the Enterprise Repository ==&lt;br /&gt;
&lt;br /&gt;
By default, the Enterprise Repository is configured in the following file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/etc/apt/sources.list.d/pbs-enterprise.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The file can be opened using an editor such as &amp;lt;code&amp;gt;nano&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/apt/sources.list.d/pbs-enterprise.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The default repository configuration looks similar to the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: https://enterprise.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-enterprise&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To disable the Enterprise Repository, add the following line:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Enabled: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The complete file should then look as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: https://enterprise.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-enterprise&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
Enabled: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, the repository file can be removed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
rm /etc/apt/sources.list.d/pbs-enterprise.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disabling the repository configuration is generally preferable, as it can easily be enabled again later.&lt;br /&gt;
&lt;br /&gt;
== Configure the No-Subscription Repository ==&lt;br /&gt;
&lt;br /&gt;
Create or edit the following file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/apt/sources.list.d/proxmox.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: http://download.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-no-subscription&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, the file can be created directly from the command line:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat &amp;gt; /etc/apt/sources.list.d/proxmox.sources &amp;lt;&amp;lt; &amp;#039;EOF&amp;#039;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: http://download.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-no-subscription&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Verify the repository configuration ==&lt;br /&gt;
&lt;br /&gt;
Update the package lists:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The configured package repositories can be checked using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt policy&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should include the No-Subscription Repository for Debian 13 “Trixie”. The Enterprise Repository should no longer be queried.&lt;br /&gt;
&lt;br /&gt;
The system can then be updated:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
apt full-upgrade&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After kernel updates or other system-level updates, the Proxmox Backup Server should be restarted:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
reboot&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Check for outdated repository files ==&lt;br /&gt;
&lt;br /&gt;
After upgrading from Proxmox Backup Server 3 to Proxmox Backup Server 4, repository entries for Debian 12 “Bookworm” may still be present.&lt;br /&gt;
&lt;br /&gt;
All configured repository files can be checked using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
grep -R --line-number --extended-regexp \&lt;br /&gt;
  &amp;#039;bookworm|trixie|enterprise\.proxmox|download\.proxmox&amp;#039; \&lt;br /&gt;
  /etc/apt/sources.list \&lt;br /&gt;
  /etc/apt/sources.list.d/ 2&amp;gt;/dev/null&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Outdated entries containing &amp;lt;code&amp;gt;bookworm&amp;lt;/code&amp;gt; must be removed or disabled. Repository entries for different Debian releases must not be mixed.&lt;br /&gt;
&lt;br /&gt;
{{Smueller}}&lt;br /&gt;
[[Category:Proxmox Backupserver]]&lt;br /&gt;
[[de:Proxmox Backup Server No Subscription Update Repository]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Secure_SSH_login_with_2_factor_authentication</id>
		<title>Secure SSH login with 2 factor authentication</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Secure_SSH_login_with_2_factor_authentication"/>
		<updated>2026-06-11T10:08:07Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A SSH shell belongs to the essential management tools on Linux based servers. This shell is already well covered by using certificate based login methods only and by deactivating root logins.&lt;br /&gt;
Furthermore, an additional registration step can be added, for example a one-time password, with a second factor. This further enhances security, as a successful login now relies on something you have (the certificate) and something you know (the one-time password). This article shows how to secure &amp;#039;&amp;#039;&amp;#039;the SSH login with Google Authenticator as second factor&amp;#039;&amp;#039;&amp;#039; on an &amp;#039;&amp;#039;&amp;#039;Ubuntu Server 18.04 LTS&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Preparatory measures == &lt;br /&gt;
First, configure certificate-based authentication on your Ubuntu Server 18.04 LTS system using a [[OpenSSH Public Key Authentifizierung unter Ubuntu|OpenSSH Public Key]].&lt;br /&gt;
&lt;br /&gt;
== libpam-google-authenticator ==&lt;br /&gt;
The following paragraph provides an insight into the Google Authenticator PAM-module and shows the installation and configuration. &lt;br /&gt;
&lt;br /&gt;
=== Integration ===&lt;br /&gt;
The two-factor authentication is connected as PAM module ((Pluggable Authentication Module) to the operating system. &lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
The installation of the PAM module from Google Authenticator can be made on Debian and Ubuntu via apt. It is contained in the official package sources.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;$ sudo apt install libpam-google-authenticator&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compatibility ===&lt;br /&gt;
The authentication via PAM module is compatible with a variety of system services. A lot of steps can therefore be further secured using Google Authenticator. The list command applied to the /etc/pam.d/ directory returns the services and tools currently supported in a base installation of Ubuntu 18.04 LTS Server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ ls -m /etc/pam.d/&lt;br /&gt;
atd, chfn, chpasswd, chsh, common-account, common-auth, common-password,&lt;br /&gt;
common-session, common-session-noninteractive, cron, login, newusers, other,&lt;br /&gt;
passwd, polkit-1, runuser, runuser-l, sshd, su, sudo, systemd-user, vmtoolsd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
After the PAM module has been installed, it can be presented, initialized and configured as follows:&lt;br /&gt;
&lt;br /&gt;
# Execute Google Authenticator on the console:&lt;br /&gt;
#: $ google-authenticator&lt;br /&gt;
# Do you want authentication tokens to be time-based (y/n)&lt;br /&gt;
#: y, this is used to generate TOTP tokens (time-based one-time password)&lt;br /&gt;
#: n, this generates HOTP tokens (counter-based one-time passwords)&lt;br /&gt;
#: In this case, the TOTP method is used&lt;br /&gt;
# Now, a QR-code is displayed on the SSH-console &lt;br /&gt;
#: Scan this code with a compatible app on your smartphone&lt;br /&gt;
#: Copy and store the keys listed below safely. &lt;br /&gt;
#: With the &amp;#039;&amp;#039;emergency scratch codes,&amp;#039;&amp;#039; the login can be performed without OTP  &lt;br /&gt;
# Update the &amp;#039;&amp;#039;.google_authenticator&amp;#039;&amp;#039; file with this information.&lt;br /&gt;
#: For this, type &amp;#039;&amp;#039;y&amp;#039;&amp;#039;.&lt;br /&gt;
# Confirm all other questions with &amp;#039;&amp;#039;y&amp;#039;&amp;#039; or with &amp;#039;&amp;#039;n&amp;#039;&amp;#039; if you want to use different settings.&lt;br /&gt;
&lt;br /&gt;
== Integration into SSH-login ==&lt;br /&gt;
The Google Authenticator PAM module is fully configured. Now, these services, such as the SSH daemon, can be adjusted to enable a two-factor authentication through it. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important hint:&amp;#039;&amp;#039;&amp;#039; If the following configuration is made via SSH session, be sure to keep the current session open and test it in parallel with a second session. If the SSH daemon is misconfigured, you will no longer be able to log in.&lt;br /&gt;
&lt;br /&gt;
=== Adjustments in /etc/pam.d/sshd ===&lt;br /&gt;
Open the /etc/pam.d/sshd file with an editor. Comment out the line &amp;#039;&amp;#039;@include common-&amp;#039;&amp;#039;auth and add the line for Google Authenticator below it. Store and close the file afterwards.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
# Standard Un*x authentication.&lt;br /&gt;
#@include common-auth&lt;br /&gt;
[...]&lt;br /&gt;
# Google Authenticator&lt;br /&gt;
auth required pam_google_authenticator.so&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Adjust sshd_config ===&lt;br /&gt;
In the configuration file &amp;#039;&amp;#039;/etc/ssh/sshd_config&amp;#039;&amp;#039;, you can now set &amp;#039;&amp;#039;&amp;#039;ChallengeResponseAuthentication&amp;#039;&amp;#039;&amp;#039; to &amp;#039;&amp;#039;yes&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
# Change to yes to enable challenge-response passwords (beware issues with&lt;br /&gt;
# some PAM modules and threads)&lt;br /&gt;
ChallengeResponseAuthentication yes&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Also, check that UsePAM is set to yes and add the following line below it: &amp;#039;&amp;#039;&amp;#039;AuthenticationMethods&amp;#039;&amp;#039;&amp;#039;. In this example, an authentication is accepted via public key and one-time password.&amp;lt;ref&amp;gt;[http://manpages.ubuntu.com/manpages/bionic/man5/sshd_config.5.html sshd_config — OpenSSH SSH daemon configuration file] (manpages.ubuntu.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
UsePAM yes&lt;br /&gt;
AuthenticationMethods publickey,keyboard-interactive&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Restart SSH daemon === &lt;br /&gt;
Now, you can restart the SSH daemon to activate the configuration.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;$ sudo systemctl restart sshd.service&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Login process ===&lt;br /&gt;
The following screenshots show the login process of an SSH shell with activated two-factor authentication by Google Authenticator.&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Bionic-SSH-Login-01.png|Start the SSH session.  You will now be asked for the time-based one-time password. Open your app and enter the six-digit numeric code.&lt;br /&gt;
File:Ubuntu-Bionic-SSH-Login-02.png|After entering TOTP, the login is made on the Ubuntu server 18.04 LTS system.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:SSH-Login mit 2-Faktor-Authentifizierung absichern]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Restrict_executable_SSH-commands_via_authorized_keys</id>
		<title>Restrict executable SSH-commands via authorized keys</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Restrict_executable_SSH-commands_via_authorized_keys"/>
		<updated>2026-06-11T07:56:38Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot; The &amp;#039;&amp;#039;&amp;#039;OpenSSH&amp;#039;&amp;#039;&amp;#039; secure shell server allows a secure and encrypted remote access on Linux and Unix systems. On the server side, the &amp;#039;&amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039;&amp;#039; file in the &amp;#039;&amp;#039;.ssh&amp;#039;&amp;#039; folder is primarily used for configuring a SSH public key authentication under Ubuntu. Normally, a user is granted &amp;#039;&amp;#039;&amp;#039;full access&amp;#039;&amp;#039;&amp;#039; on the system, on which the authentication was set up. In some cases, such as automatized backup processes, it is useful that the access is restricted to just a...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;OpenSSH&amp;#039;&amp;#039;&amp;#039; secure shell server allows a secure and encrypted remote access on Linux and Unix systems. On the server side, the &amp;#039;&amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039;&amp;#039; file in the &amp;#039;&amp;#039;.ssh&amp;#039;&amp;#039; folder is primarily used for configuring a [[SSH public key authentication under Ubuntu]]. Normally, a user is granted &amp;#039;&amp;#039;&amp;#039;full access&amp;#039;&amp;#039;&amp;#039; on the system, on which the authentication was set up. In some cases, such as automatized backup processes, it is useful that the access is restricted to just a few, or even just a single &amp;#039;&amp;#039;&amp;#039;command&amp;#039;&amp;#039;&amp;#039;. The successful configuration steps are explained in this article.&lt;br /&gt;
&lt;br /&gt;
== Purpose == &lt;br /&gt;
The restriction of executable commands via SSH is mainly used for automatized backups. The dedicated backup users mostly have a private key without key phrase to execute automated backups. On the backup destination server, the public key of the user is added to the &amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039; file so that this user can connect without entering a password. &lt;br /&gt;
&lt;br /&gt;
Strictly speaking, from this point on, the user would actually have full access to the backup server, even though, for example, the &amp;quot;rsync&amp;quot; command is always used. &lt;br /&gt;
&lt;br /&gt;
A command restriction for the user avoids that if the private key is compromised, the backup server is automatically compromised as well. As the user is restricted to a command in the &amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039; file, it is not allowed to execute another command or to establish a terminal session via SSH.&lt;br /&gt;
&lt;br /&gt;
== Restrict to a single command in authorized_keys ==&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;/~/.ssh/authorized_keys&amp;#039;&amp;#039;&amp;#039; file contains the public key of the user that is allowed to connect. (see also [[SSH public key authentication under Ubuntu]]):&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ cat .ssh/authorized_keys &lt;br /&gt;
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCj98R[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
To restrict the user to a single command, the parameter &amp;#039;&amp;#039;&amp;#039;command=&amp;#039;&amp;#039;&amp;#039; is entered before the key. After that, whenever an attempt is made to establish an SSH connection, only this command will be executed, even if, for example, a different command was provided.&amp;lt;ref name=&amp;quot;sshdef&amp;quot;&amp;gt;[http://oreilly.com/catalog/sshtdg/chapter/ch08.html Per-Account Server Configuration] (oreilly.com)&amp;lt;/ref&amp;gt; In the following example, the user &amp;#039;&amp;#039;dailybackup&amp;#039;&amp;#039; is restricted to the &amp;#039;&amp;#039;date&amp;#039;&amp;#039; command for demonstration purposes.&lt;br /&gt;
For this, the &amp;#039;&amp;#039;command=date&amp;#039;&amp;#039; parameter is defined on the SSH-server:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ cat .ssh/authorized_keys &lt;br /&gt;
command=&amp;quot;date&amp;quot; ssh-rsa AAAA[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
From the client computer that connects to the server via SSH, the only command the user can then execute is &amp;#039;&amp;#039;date&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ ssh dailybackup@192.168.56.105&lt;br /&gt;
Wed Apr 30 14:46:53 CEST 2014&lt;br /&gt;
Connection to 192.168.56.105 closed.&lt;br /&gt;
:~$ ssh dailybackup@192.168.56.105 &amp;quot;tail /etc/passwd&amp;quot;&lt;br /&gt;
Wed Apr 30 14:47:02 CEST 2014&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Analyse executed command on SSH-server ==&lt;br /&gt;
The analysis, which command must be entered in &amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039;, is made easier by the environment variable &amp;#039;&amp;#039;$SSH_ORIGINAL_COMMAND&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
command=&amp;quot;/bin/echo You invoked: $SSH_ORIGINAL_COMMAND&amp;quot; ssh-rsa AAAAB[..]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
When a command is issued from the client, the command executed on the server is then displayed for analysis purposes:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ ssh dailybackup@192.168.56.105 tail /etc/passwd&lt;br /&gt;
You invoked: tail /etc/passwd&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Some commands, for example &amp;#039;&amp;#039;rsync&amp;#039;&amp;#039;, lead to an error message when used with the above &amp;#039;&amp;#039;command&amp;#039;&amp;#039;. By taking a roundabout route using a script on the SSH server, the command, that was executed, can be also accessed: &amp;lt;ref name=&amp;quot;sshdef&amp;quot; /&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ vi logssh.sh&lt;br /&gt;
#!/bin/sh&lt;br /&gt;
if [ -n &amp;quot;$SSH_ORIGINAL_COMMAND&amp;quot; ]&lt;br /&gt;
then&lt;br /&gt;
  echo &amp;quot;`/bin/date`: $SSH_ORIGINAL_COMMAND&amp;quot; &amp;gt;&amp;gt; $HOME/ssh-command-log&lt;br /&gt;
  exec $SSH_ORIGINAL_COMMAND&lt;br /&gt;
fi&lt;br /&gt;
:~$ vi .ssh/authorized_keys&lt;br /&gt;
command=&amp;quot;/home/dailybackup/logssh.sh&amp;quot; ssh-rsa AAAAB3N[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The client then calls up rsync: &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~/tmp$ rsync -avz test.txt dailybackup@192.168.56.105:/home/dailybackup&lt;br /&gt;
sending incremental file list&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The command executed via SSH appears in the log file on the SSH server. This command can be used again via &amp;#039;&amp;#039;command=&amp;#039;&amp;#039; for restrictions:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ cat ssh-command-log &lt;br /&gt;
Wed Apr 30 15:10:54 CEST 2014: rsync --server -vlogDtprze.iLsf . /home/dailybackup&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint:&amp;#039;&amp;#039;&amp;#039; For problems with output redirection, &amp;lt;code&amp;gt;exec&amp;lt;/code&amp;gt; can be used instead of &amp;lt;code&amp;gt;eval&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Restrict multiple commands in authorized_keys ==&lt;br /&gt;
In general, it is possible via additional scripts to allow multiple commands for a key pair.&lt;br /&gt;
&lt;br /&gt;
However, for maximum security, it is easier to generate a private key pair for every desired command and to safe the corresponding command.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:Ausführbare SSH-Kommandos per authorized keys einschränken]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OpenSSH_public_key_authentication_fails</id>
		<title>OpenSSH public key authentication fails</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OpenSSH_public_key_authentication_fails"/>
		<updated>2026-06-11T06:25:36Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes how to resolve issues with SSH authentication using public key authentication. In the article SSH key login, it is explained how to set up public key authentication in general.    == Server-side problems ==  In most cases, the reason why public key authentication is not working can be found in the file and directory permissions. The home directory on the server as well as the sub-directory .ssh is not allowed to have writing right...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes how to resolve issues with SSH authentication using public key authentication. In the article [[SSH Key Login|SSH key login]], it is explained how to set up public key authentication in general.  &lt;br /&gt;
&lt;br /&gt;
== Server-side problems == &lt;br /&gt;
In most cases, the reason why public key authentication is not working can be found in the file and directory permissions. The home directory on the server as well as the sub-directory .ssh is not allowed to have writing rights for group and other. Furthermore, the file &amp;lt;code&amp;gt;authorized_keys&amp;lt;/code&amp;gt; must be accessible only to the owner. &lt;br /&gt;
&lt;br /&gt;
To set the rights correctly, log in to the server with the user for whom the SSH authentication should function.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chmod go-w $HOME $HOME/.ssh&lt;br /&gt;
chmod 600 $HOME/.ssh/authorized_keys&lt;br /&gt;
chown `whoami` $HOME/.ssh/authorized_keys&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If this is not possible, you can alternatively deactivate the right verification of the server. The following option must be entered in the &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt; file:&lt;br /&gt;
 StrictModes no&lt;br /&gt;
&lt;br /&gt;
Another error source can be the wrong settings in &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt;. Here is an extract of options that can influence the public key authentication:&lt;br /&gt;
* AuthorizedKeysFile&lt;br /&gt;
* PreferredAuthentications&lt;br /&gt;
* PubkeyAuthentication&lt;br /&gt;
&lt;br /&gt;
More settings can be found in the &amp;#039;&amp;#039;&amp;#039;man sshd_config&amp;#039;&amp;#039;&amp;#039; manpage.&lt;br /&gt;
&lt;br /&gt;
== Client-sided problems == &lt;br /&gt;
Alternatively, there may still be issues on the client side, that is, on the computer from which the SSH connection is initiated.&lt;br /&gt;
&lt;br /&gt;
If the file rights are set open for the private key, the following error message is displayed by the SSH client:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @&lt;br /&gt;
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;
Permissions 0777 for &amp;#039;xyz&amp;#039; are too open.&lt;br /&gt;
It is recommended that your private key files are NOT accessible by others.&lt;br /&gt;
This private key will be ignored.&lt;br /&gt;
bad permissions: ignore key: xyz&lt;br /&gt;
Permission denied (publickey,gssapi-with-mic).&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this case, the private key is ignored. Set the rights correctly using the following command: &lt;br /&gt;
 chmod 600 $HOME/.ssh/&amp;lt;Keyname&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Another possible error source could be a wrong setting in &amp;lt;code&amp;gt;.ssh/config&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;/etc/ssh/ssh_config&amp;lt;/code&amp;gt;. An excerpt of possible options that may affect public key authentication, can be found here:&lt;br /&gt;
* PreferredAuthentications&lt;br /&gt;
* PubkeyAuthentication&lt;br /&gt;
&lt;br /&gt;
All settings can be found in the &amp;#039;&amp;#039;&amp;#039;man ssh_config&amp;#039;&amp;#039;&amp;#039; manpage.&lt;br /&gt;
&lt;br /&gt;
== Sources: == &lt;br /&gt;
* http://www.openssh.org/faq.html#3.14&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:OpenSSH Public Key Authentication schlägt fehl]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/AMD_Security_Vulnerabilities_-_June_2026</id>
		<title>AMD Security Vulnerabilities - June 2026</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/AMD_Security_Vulnerabilities_-_June_2026"/>
		<updated>2026-06-10T12:16:49Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;On &amp;#039;&amp;#039;&amp;#039;June 9th, 2026&amp;#039;&amp;#039;&amp;#039;, AMD published the security bulletins &amp;#039;&amp;#039;&amp;#039;AMD-SB-3039&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3039.html ASP non-Coherent Memory Access – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; and &amp;#039;&amp;#039;&amp;#039;AMD-SB-9025&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9025.html AMD uProf Vulnerabilities – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; for security vulnerabili...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On &amp;#039;&amp;#039;&amp;#039;June 9th, 2026&amp;#039;&amp;#039;&amp;#039;, AMD published the security bulletins &amp;#039;&amp;#039;&amp;#039;AMD-SB-3039&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3039.html ASP non-Coherent Memory Access – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; and &amp;#039;&amp;#039;&amp;#039;AMD-SB-9025&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9025.html AMD uProf Vulnerabilities – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; for security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
== Information ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;AMD-SB-3039&amp;#039;&amp;#039;&amp;#039;: This is a malicious hypervisor that can undermine the integrity protection mechanisms of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP), by forcing AMD Security Processor (ASP) to work with the system storage without cache coherence. According to the publication, system settings controlled by the hypervisor enable the reconfiguration of the interaction between the storage requirements of the ASP and the CPU-cache. By disabling coherence, the ASP can read stale data from the DRAM when copying pages and updating the associated metadata, causing the guest to lose the most recent updates in the CPU cache. This could potentially undermine the integrity warranties of the SEV-SNP for guests and could cause data corruption.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;AMD-SB-9025&amp;#039;&amp;#039;&amp;#039;: The vulnerability could allow a local attacker with user privileges to write to memory assigned by the kernel. AMD confirms that the issue occurs because from the driver creating a shared-section object with a NULL security descriptor and exposing kernel pointers in shared memory, which could allow an attacker to write to kernel-allocated memory and potentially cause a system crash or a denial-of-service condition.  &lt;br /&gt;
&lt;br /&gt;
== Affected systems ==&lt;br /&gt;
&lt;br /&gt;
Here is a table listing the affected processors. &lt;br /&gt;
&lt;br /&gt;
===== AMD EPYC™ Processors =====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|Product&lt;br /&gt;
|Mitigation&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ 8004 Series Processors&lt;br /&gt;
|GenoaPI&lt;br /&gt;
1.0.0.H&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ 9004 Series Processors&lt;br /&gt;
|GenoaPI&lt;br /&gt;
1.0.0.H&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ 9005 Series Processors&lt;br /&gt;
|TurinPI&lt;br /&gt;
&lt;br /&gt;
1.0.0.8&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 8004 Series Processors&lt;br /&gt;
|EmbGenoaPI-SP5&lt;br /&gt;
&lt;br /&gt;
1.0.0.D&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 9004 Series Processors&lt;br /&gt;
&lt;br /&gt;
(formerly codenamed &amp;quot;Genoa&amp;quot;)&lt;br /&gt;
|EmbGenoaPI-SP5&lt;br /&gt;
&lt;br /&gt;
1.0.0.D&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 9004 Series Processors&lt;br /&gt;
&lt;br /&gt;
(formerly codenamed &amp;quot;Bergamo&amp;quot;)&lt;br /&gt;
|EmbGenoaPI-SP5&lt;br /&gt;
&lt;br /&gt;
1.0.0.D&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 9005 Series Processors&lt;br /&gt;
|EmbeddedTurinPI_SP5&lt;br /&gt;
&lt;br /&gt;
1004&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |CVE&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |CVSS Score&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |[https://www.cve.org/CVERecord?id=CVE-2026-54509 CVE-2025-54509]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |4.0 (Medium)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |[https://www.cve.org/CVERecord?id=CVE-2026-0466 CVE-2026-0466]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |6.8 (Medium)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |[https://www.cve.org/CVERecord?id=CVE-2026-28237 CVE-2026-28237]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |6.8 (Medium)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In the following, there is an extract of this table in which all Supermicro mainboards are included that are offered by Thomas-Krenn:&amp;lt;ref&amp;gt;[https://www.supermicro.com/en/support/security_AMD-SB-3027 AMD Security Bulletin AMD-SB-3027, January 2027] (www.supermicro.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!AMD motherboard &lt;br /&gt;
! align=&amp;quot;center&amp;quot; |&amp;#039;&amp;#039;&amp;#039;BIOS version&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |H13SSW&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |3.8&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |H13SSL-N/NT&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |3.8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Updates for Thomas-Krenn products ===&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;download area of Thomas-Krenn&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The updates in the download area have been tested by us to guarantee the stability and compatibility of our systems. &lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you can get it at &lt;br /&gt;
[https://www.asus.com/de/support/download-center/ Asus], [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro] or [https://www.gigabyte.com/de/Support/Consumer/Download Gigabyte]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information == &lt;br /&gt;
* [https://www.supermicro.com/en/support/security_AMD-SB-3027 AMD Security Bulletin AMD-SB-3039] (supermicro.com, Juni 2026)&lt;br /&gt;
&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:AMD Safety Information]]&lt;br /&gt;
[[de:AMD Sicherheitslücken - Juni 2026]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Slow_SSH_login_due_to_DNS_timeout</id>
		<title>Slow SSH login due to DNS timeout</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Slow_SSH_login_due_to_DNS_timeout"/>
		<updated>2026-06-10T08:52:47Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes solutions for when an &amp;#039;&amp;#039;&amp;#039;SSH login is slow&amp;#039;&amp;#039;&amp;#039;.  ==Problem== It takes approximately 10 seconds when you log in to a Linux system via SSH until the password prompt appears. After this, the SSH session functions completely normal.  ==Background==  The SSH server tries to make a reverse DNS lookup for the IP from which the SSH connection is established. If there is no functioning configured DNS (for example a wrong registered IP for the DNS server in /...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes solutions for when an &amp;#039;&amp;#039;&amp;#039;SSH login is slow&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
==Problem==&lt;br /&gt;
It takes approximately 10 seconds when you log in to a Linux system via SSH until the password prompt appears. After this, the SSH session functions completely normal.&lt;br /&gt;
&lt;br /&gt;
==Background== &lt;br /&gt;
The SSH server tries to make a reverse DNS lookup for the IP from which the SSH connection is established. If there is no functioning configured DNS (for example a wrong registered IP for the DNS server in /etc/resolv.conf), it takes 10 seconds until the timeout is reached for the reverse DNS lookup. Then, the password prompt appears. &lt;br /&gt;
&lt;br /&gt;
In the following, information on the use of &amp;lt;code&amp;gt;ssh -v&amp;lt;/code&amp;gt; (verbose mode) is listed:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[admin@tpw admin]$ ssh -v root@192.168.1.154&lt;br /&gt;
OpenSSH_5.1p1, OpenSSL 0.9.8g 19 Oct 2007&lt;br /&gt;
debug1: Reading configuration data /etc/ssh/ssh_config&lt;br /&gt;
debug1: Applying options for *&lt;br /&gt;
debug1: Connecting to 192.168.1.154 [192.168.1.154] port 22.&lt;br /&gt;
debug1: Connection established.&lt;br /&gt;
debug1: identity file /home/admin/.ssh/identity type -1&lt;br /&gt;
debug1: identity file /home/admin/.ssh/id_rsa type -1&lt;br /&gt;
debug1: identity file /home/admin/.ssh/id_dsa type -1&lt;br /&gt;
debug1: Remote protocol version 2.0, remote software version OpenSSH_5.1p1 Debian-5&lt;br /&gt;
debug1: match: OpenSSH_5.1p1 Debian-5 pat OpenSSH*&lt;br /&gt;
debug1: Enabling compatibility mode for protocol 2.0&lt;br /&gt;
debug1: Local version string SSH-2.0-OpenSSH_5.1&lt;br /&gt;
debug1: SSH2_MSG_KEXINIT sent&lt;br /&gt;
debug1: SSH2_MSG_KEXINIT received&lt;br /&gt;
debug1: kex: server-&amp;gt;client aes128-cbc hmac-md5 none&lt;br /&gt;
debug1: kex: client-&amp;gt;server aes128-cbc hmac-md5 none&lt;br /&gt;
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024&amp;lt;1024&amp;lt;8192) sent&lt;br /&gt;
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP&lt;br /&gt;
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent&lt;br /&gt;
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY&lt;br /&gt;
debug1: Host &amp;#039;192.168.1.154&amp;#039; is known and matches the RSA host key.&lt;br /&gt;
debug1: Found key in /home/admin/.ssh/known_hosts:153&lt;br /&gt;
debug1: ssh_rsa_verify: signature correct&lt;br /&gt;
debug1: SSH2_MSG_NEWKEYS sent&lt;br /&gt;
debug1: expecting SSH2_MSG_NEWKEYS&lt;br /&gt;
debug1: SSH2_MSG_NEWKEYS received&lt;br /&gt;
debug1: SSH2_MSG_SERVICE_REQUEST sent&lt;br /&gt;
debug1: SSH2_MSG_SERVICE_ACCEPT received&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, it takes ten minutes until it continues:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
debug1: Authentications that can continue: publickey,password&lt;br /&gt;
debug1: Next authentication method: publickey&lt;br /&gt;
debug1: Trying private key: /home/admin/.ssh/identity&lt;br /&gt;
debug1: Trying private key: /home/admin/.ssh/id_rsa&lt;br /&gt;
debug1: Trying private key: /home/admin/.ssh/id_dsa&lt;br /&gt;
debug1: Next authentication method: password&lt;br /&gt;
root@192.168.1.154&amp;#039;s password: &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After entering the password, it continues:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
debug1: Authentication succeeded (password).&lt;br /&gt;
debug1: channel 0: new [client-session]&lt;br /&gt;
debug1: Requesting no-more-sessions@openssh.com&lt;br /&gt;
debug1: Entering interactive session.&lt;br /&gt;
debug1: Sending environment.&lt;br /&gt;
debug1: Sending env LANG = en_US.utf8&lt;br /&gt;
Linux debian5 2.6.9-023stab048.6-smp #1 SMP Mon Nov 17 18:41:14 MSK 2008 x86_64&lt;br /&gt;
&lt;br /&gt;
The programs included with the Debian GNU/Linux system are free software;&lt;br /&gt;
the exact distribution terms for each program are described in the&lt;br /&gt;
individual files in /usr/share/doc/*/copyright.&lt;br /&gt;
&lt;br /&gt;
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent&lt;br /&gt;
permitted by applicable law.&lt;br /&gt;
Last login: Wed Jun 17 13:20:19 2009 from 192.168.1.52&lt;br /&gt;
debian5:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Solution==&lt;br /&gt;
On the target system, either add the IP address of the computer from which the connection is being established to /etc/hosts, or make sure that the DNS configuration on the target system is working properly.&lt;br /&gt;
&lt;br /&gt;
===Enter IP in /etc/hosts===&lt;br /&gt;
The IP can be, for example, entered in /etc/hosts as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@debian5:/# echo &amp;quot;192.168.1.52 laptop&amp;quot; &amp;gt;&amp;gt; /etc/hosts&lt;br /&gt;
root@debian5:/# cat /etc/hosts&lt;br /&gt;
127.0.0.1  debian5 localhost localhost.localdomain&lt;br /&gt;
&lt;br /&gt;
::1     localhost ip6-localhost ip6-loopback&lt;br /&gt;
fe00::0 ip6-localnet&lt;br /&gt;
ff00::0 ip6-mcastprefix&lt;br /&gt;
ff02::1 ip6-allnodes&lt;br /&gt;
ff02::2 ip6-allrouters&lt;br /&gt;
ff02::3 ip6-allhosts&lt;br /&gt;
192.168.1.52 laptop&lt;br /&gt;
root@debian5:/# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Verify DNS configuration===&lt;br /&gt;
In the example, an incorrect DNS server was configured on the Debian 5 target system. The configuration was corected as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@debian5:/# cat /etc/resolv.conf &lt;br /&gt;
nameserver 10.10.18.1&lt;br /&gt;
root@debian5:/# echo &amp;quot;nameserver 192.168.1.254&amp;quot; &amp;gt; /etc/resolv.conf&lt;br /&gt;
root@debian5:/# cat /etc/resolv.conf &lt;br /&gt;
nameserver 192.168.1.254&lt;br /&gt;
root@debian5:/# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==More information==&lt;br /&gt;
* [http://www.macosxhints.com/article.php?story=20050329185832952 macosxhints.com: A possible fix for slow SSH connections ]&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[pl:Logowanie przez ssh powolne przez DNS Timeout]]&lt;br /&gt;
[[de:SSH Login langsam durch DNS Timeout]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OpenSSH_configuration</id>
		<title>OpenSSH configuration</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OpenSSH_configuration"/>
		<updated>2026-06-10T06:30:22Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The following configuration describes advanced OpenSSH configurations that can be expaned as needed. If you have more interesting contents, kindly send us a message.  An overview of all server-side SSH configuration options can be found in the manpage of sshd_config.  man sshd_config  === Conditional configuration with &amp;quot;Match&amp;quot; === &amp;quot;Match&amp;quot;, the configuration option, allows a global configuration (for example in &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt;) to ove...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The following configuration describes advanced OpenSSH configurations that can be expaned as needed. If you have more interesting contents, kindly send us a [[Special:contact|message]].&lt;br /&gt;
&lt;br /&gt;
An overview of all server-side SSH configuration options can be found in the manpage of sshd_config.&lt;br /&gt;
 man sshd_config&lt;br /&gt;
&lt;br /&gt;
=== Conditional configuration with &amp;quot;Match&amp;quot; ===&lt;br /&gt;
&amp;quot;Match&amp;quot;, the configuration option, allows a global configuration (for example in &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt;) to overwrite one that is conditional. The following conditions are possible:&lt;br /&gt;
* User&lt;br /&gt;
* Group&lt;br /&gt;
* Host&lt;br /&gt;
* Address[&lt;br /&gt;
&lt;br /&gt;
Here is an example for a configuration in /etc/ssh/sshd_config:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
PasswordAuthentication no&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
Match User admin&lt;br /&gt;
        PasswordAuthentication yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this case, the password authentication is deactivated globally. However, it was subsequently enabled for the &amp;quot;admin&amp;quot; user using a MATCH statement.&lt;br /&gt;
&lt;br /&gt;
In general, &amp;quot;Match&amp;quot; is only for one option allowed:&lt;br /&gt;
&lt;br /&gt;
AllowAgentForwarding, AllowTcpForwarding, Banner, ChrootDirectory, ForceCommand, GatewayPorts, GSSAPIAuthentication, HostbasedAuthentication, KbdInteractiveAuthentication, KerberosAuthentication, MaxAuthTries, MaxSessions, PasswordAuthentication, PermitEmptyPasswords, PermitOpen, PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication, RSAAuthentication, X11DisplayOffset, X11Forwarding und X11UseLocalHost&lt;br /&gt;
&lt;br /&gt;
=== VPN with OpenSSH ===&lt;br /&gt;
OpenSSH offers from version 4.3 the opportunity to set up a VPN tunnel. This creates a tun device on both the local and remote sides. As soon as it has been configured, the VPN can be used.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;uml-utilities&amp;quot; package must be installed in advance on Ubuntu/Debian. This comes with the &amp;#039;&amp;#039;&amp;#039;tunctl&amp;#039;&amp;#039;&amp;#039; binary.&lt;br /&gt;
&lt;br /&gt;
The SSH sever configuration &amp;#039;&amp;#039;&amp;#039;sshd_config&amp;#039;&amp;#039;&amp;#039; must be expanded by the following options:&lt;br /&gt;
 PermitRootLogin yes&lt;br /&gt;
 PermitTunnel yes&lt;br /&gt;
&lt;br /&gt;
A tunnel can be set up with the option &amp;#039;&amp;#039;&amp;#039;&amp;quot;-w&amp;quot;&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
 ssh -w 0:0 1.2.3.4&lt;br /&gt;
&lt;br /&gt;
After this, a &amp;quot;tun0&amp;quot; interface should be visible on both sides. An IP address must then be assigned to it.&lt;br /&gt;
&lt;br /&gt;
You may need to enable IP forwarding.&lt;br /&gt;
 echo 1 &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
&lt;br /&gt;
For long-term VPN use, we recommend the use of [[OpenVPN with Pre-shared Key|OpenVPN]], which is much easier to configure and automate.&lt;br /&gt;
&lt;br /&gt;
More information can be found here: https://help.ubuntu.com/community/SSH_VPN&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:OpenSSH Konfiguration]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Samba-server_basics</id>
		<title>Samba-server basics</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Samba-server_basics"/>
		<updated>2026-06-09T11:35:50Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;A &amp;#039;&amp;#039;&amp;#039;Samba-Server&amp;#039;&amp;#039;&amp;#039; helps with the integration of &amp;#039;&amp;#039;&amp;#039;Windows- and Unix/Linux computers&amp;#039;&amp;#039;&amp;#039;.&amp;lt;ref&amp;gt;[http://www.oreilly.de/german/freebooks/samba2ger/ch01.html#936841 Samba, 2. Auflage] www.oreilly.de&amp;lt;/ref&amp;gt; &amp;#039;&amp;#039;&amp;#039;Files&amp;#039;&amp;#039;&amp;#039; can be, for example, exchanged or &amp;#039;&amp;#039;&amp;#039;printers&amp;#039;&amp;#039;&amp;#039; can be shared. The name Samba comes from the SMB protocol (&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Server Message Block&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;), which is used for network-based data exchange on Windows. These days, people are increasingly referring to the &amp;quot;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Co...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A &amp;#039;&amp;#039;&amp;#039;Samba-Server&amp;#039;&amp;#039;&amp;#039; helps with the integration of &amp;#039;&amp;#039;&amp;#039;Windows- and Unix/Linux computers&amp;#039;&amp;#039;&amp;#039;.&amp;lt;ref&amp;gt;[http://www.oreilly.de/german/freebooks/samba2ger/ch01.html#936841 Samba, 2. Auflage] www.oreilly.de&amp;lt;/ref&amp;gt; &amp;#039;&amp;#039;&amp;#039;Files&amp;#039;&amp;#039;&amp;#039; can be, for example, exchanged or &amp;#039;&amp;#039;&amp;#039;printers&amp;#039;&amp;#039;&amp;#039; can be shared. The name Samba comes from the SMB protocol (&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Server Message Block&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;), which is used for network-based data exchange on Windows. These days, people are increasingly referring to the &amp;quot;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Common Internet File System&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;quot; (CIFS) instead of SMB. CIFS is a further development of SMB and was developed by Microsoft.&amp;lt;ref&amp;gt;[http://msdn.microsoft.com/en-us/library/aa365233%28v=vs.85%29.aspx SMB and CIFS overview] (msdn.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A free online book by O&amp;#039;Reilly provides detailed information about Samba/CIFS in German. It is available at [http://www.oreilly.de/german/freebooks/samba2ger/ Oreilly Samba 2nd edition]. Furthermore, the Samba community provides a detailed documentation about Samba: [https://help.ubuntu.com/community/Samba Samba Community]. This article presents the basics of working with a Samba server that is set up on &amp;#039;&amp;#039;&amp;#039;Ubuntu 10.04 LTS&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
== Server ==&lt;br /&gt;
=== Installation ===&lt;br /&gt;
The Samba package &amp;lt;ref&amp;gt;[http://packages.ubuntu.com/lucid/samba Samba Package] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; is installed on the server so that a file and print server can be set up. &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
apt-get install samba&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuration === &lt;br /&gt;
The central configuration file is located at&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo vi /etc/samba/smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The corresponding man page provides a range of information on how to configure the Samba server using this file:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
man smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The file is divided into several parts. The global section ([global]) includes basic settings that may be followed by other sections on the release of resources.&lt;br /&gt;
&lt;br /&gt;
As the first step in the configuration, comment out the following line in the &amp;quot;Authentication&amp;quot; section:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# &amp;quot;security = user&amp;quot; is always a good idea. This will require a Unix account&lt;br /&gt;
# in this server for every user accessing the server. See&lt;br /&gt;
# /usr/share/doc/samba-doc/htmldocs/Samba3-HOWTO/ServerType.html&lt;br /&gt;
# in the samba-doc package for details.&lt;br /&gt;
   security = user&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Due to these security measures, an existing user account on the server is required to access the Samba shares.&amp;lt;ref&amp;gt;[https://help.ubuntu.com/10.04/serverguide/C/samba-fileprint-security.html Samba Security] (help.ubuntu.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Network interfaces ====&lt;br /&gt;
If your server possesses multiple network interfaces, it may be that the smb-server is connected to the wrong interface. To do this, the line &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
interfaces = 192.168.1.1/24&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
can be added to the &amp;quot;[global]&amp;quot; area of smb.conf. In this example, the SMB server listens on the address range in the 192.168.1.1/24 network.&amp;lt;ref&amp;gt;http://tldp.org/HOWTO/SMB-HOWTO-6.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Add smb password ====&lt;br /&gt;
The following command creates a smb-password for the existing user &amp;quot;smbuser&amp;quot;. It is important that this step is performed for an existing user, as every smb-user needs a valid account on the server. The password you set can be used later to access the SMB share:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo smbpasswd -a smbuser&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
As the smb-password does not have to comply with the password of the actual account, it can definitely time-consuming to administrate different passwords. On Ubuntu, the &amp;quot;libpam-smbpass&amp;quot; package exists, which can be used to keep Linux and smb passwords synchronized. &lt;br /&gt;
&lt;br /&gt;
So that the changes are effective, the server must reload the configuration:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo service smbd reload&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Zuvor können die modifizierten Einstellungen auch auf ihre Korrektheit geprüft werden:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
testparm /etc/samba/smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Add a resource ===&lt;br /&gt;
In the following configuration example, the home directories of the smb-users are released. In the first step, a new resource is added to the &amp;quot;smb.conf&amp;quot; file:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo vi /etc/samba/smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The following paragraph is commented out:  &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Un-comment the following (and tweak the other settings below to suit)&lt;br /&gt;
# to enable the default home directory shares.  This will share each&lt;br /&gt;
# user&amp;#039;s home directory as \\server\username&lt;br /&gt;
[homes]&lt;br /&gt;
   comment = Home Directories&lt;br /&gt;
   browseable = yes&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Now, the home-directories are available for all users, which means that the users can access each other´s directories (provided, of course, that an SMB password has been set and the user therefore has access to the SMB server). The parameter &amp;quot;browseable&amp;quot; allows Windows users to browse the Samba share using Windows Explorer.&lt;br /&gt;
To be more restrictive with home directories, the following line can be commented out:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# By default, \\server\username shares can be connected to by anyone&lt;br /&gt;
# with access to the samba server.  Un-comment the following parameter&lt;br /&gt;
# to make sure that only &amp;quot;username&amp;quot; can connect to \\server\username&lt;br /&gt;
# This might need tweaking when using external authentication schemes&lt;br /&gt;
   valid users = %S&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Then, for example, the user &amp;quot;tktest&amp;quot; will no longer be able to access the home directory of &amp;quot;smbuser&amp;quot; (from clients perspective):&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mount -t smbfs //192.168.56.101/smbuser /media/ -o username=tktest&lt;br /&gt;
Password: &lt;br /&gt;
mount error(13): Permission denied&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Further security measures are presented, for example, on  [https://help.ubuntu.com/10.04/serverguide/C/samba-fileprint-security.html Samba Security] (help.ubuntu.com) or [http://samba.org/samba/docs/man/Samba-HOWTO-Collection/securing-samba.html Securing samba] (samba.org).&lt;br /&gt;
&lt;br /&gt;
== Client ==&lt;br /&gt;
=== Installation ===&lt;br /&gt;
The following package is required for the access on the smb-server on the client:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo apt-get install smbfs smbclient&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
With the smbclient, an initial connection test can be started:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
smbclient -U smbuser -L 192.168.56.101&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Mounting of smb share === &lt;br /&gt;
With the mount command, the smb directory can be integrated locally:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mount -t cifs //192.168.56.101/smbuser /media/ -o username=smbuser&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
After this command, the smb-directory will be accessible at &amp;quot;/media/&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Samba-Server Grundlagen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_June_2026</id>
		<title>Supermicro BMC Security Advisories June 2026</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_June_2026"/>
		<updated>2026-06-09T05:30:51Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;In &amp;#039;&amp;#039;&amp;#039;June 2026&amp;#039;&amp;#039;&amp;#039;, Supermicro published security advisories for the BMC-firmware of its mainboards. This security vulnerability requires a &amp;#039;&amp;#039;&amp;#039;firmware update&amp;#039;&amp;#039;&amp;#039;.   In this article, you will find information on this security advisory and where to find updates on Thomas-Krenn products.  == Security advisories == {| class=&amp;quot;wikitable&amp;quot; |- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot; ! align=&amp;quot;center&amp;quot; |CVE ! align=&amp;quot;center&amp;quot; |Risk potential: ! align=&amp;quot;center&amp;quot; |Title  |-...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In &amp;#039;&amp;#039;&amp;#039;June 2026&amp;#039;&amp;#039;&amp;#039;, Supermicro published security advisories for the BMC-firmware of its mainboards. This security vulnerability requires a &amp;#039;&amp;#039;&amp;#039;firmware update&amp;#039;&amp;#039;&amp;#039;. &lt;br /&gt;
&lt;br /&gt;
In this article, you will find information on this security advisory and where to find updates on Thomas-Krenn products.&lt;br /&gt;
&lt;br /&gt;
== Security advisories ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |CVE&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Risk potential:&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Title &lt;br /&gt;
|-&lt;br /&gt;
|align=&amp;quot;center&amp;quot; | [https://www.cve.org/CVERecord?id=CVE-2026-3820 CVE-2026-3820]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | 7.2 (high)&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &amp;#039;&amp;#039;&amp;#039;&amp;lt;u&amp;gt;Command-Injection&amp;lt;/u&amp;gt;&amp;#039;&amp;#039;&amp;#039; (The security vulnerability allows an attacker to get administrator rights and to manipulate the SMTP service configuration. This could cause the system to execute unintended commands when calling processes)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Updates for Thomas-Krenn products ==&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;download area of Thomas-Krenn&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The updates in the download are have been tested by us to guarantee the stability and compatibility of our systems.&lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you will find it at [https://www.asus.com/de/support/download-center/ Asus] or [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro].&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://www.supermicro.com/en/support/security_BMC_IPMI_Jun_2026 Vulnerabilities in Supermicro BMC firmware, June 2026]&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category: Server Hardware]]&lt;br /&gt;
[[de:Supermicro BMC Sicherheitshinweise Juni 2026]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
</feed>