<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.thomas-krenn.com/en/wikiEN/index.php?title=Special:NewPages&amp;feed=atom&amp;xortex=yes</id>
	<title>Thomas-Krenn-Wiki - New pages [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.thomas-krenn.com/en/wikiEN/index.php?title=Special:NewPages&amp;feed=atom&amp;xortex=yes"/>
	<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Special:NewPages"/>
	<updated>2026-07-24T18:07:56Z</updated>
	<subtitle>From Thomas-Krenn-Wiki</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Windows_Server_Core_Licensing</id>
		<title>Windows Server Core Licensing</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Windows_Server_Core_Licensing"/>
		<updated>2026-07-23T11:36:39Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Windows Server Access Licenses(CAL) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Since &amp;#039;&amp;#039;&amp;#039;[[Windows Server 2016 Editionsunterschiede|Windows Server 2016]]&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;Microsoft&amp;#039;&amp;#039;&amp;#039; relies on &amp;#039;&amp;#039;&amp;#039;core licensing&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
In this article, all important information, that is required for the &amp;#039;&amp;#039;&amp;#039;licensing of Windows Server&amp;#039;&amp;#039;&amp;#039;, is included.&lt;br /&gt;
&lt;br /&gt;
It is possible to test the latest server version up to 180 days for free.&lt;br /&gt;
&lt;br /&gt;
A corresponding download can be found in [https://www.microsoft.com/de-de/evalcenter Microsoft Evaluation Center].&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;{{#widget:Imagebox-left|link={{#tklink:type=sitex|id=18135|linkonly=1}}|image=/de/wikiDE/images/9/99/WindowsServer2025-shoplink.png|text=Click here for our Microsoft software in the Thomas-Krenn online shop|campaign=Windows Server 2025 edition differences}} {{#widget:SitexBox|link={{#tklink:type=sitex|id=18135|linkonly=1}}|text=Click here for our Microsoft software in the Thomas-Krenn online shop|campaign=Windows Server 2025 edition differences}}&lt;br /&gt;
&lt;br /&gt;
==Windows Server licensing==&lt;br /&gt;
Since Windows server 2016, it must be distinguished between Essentials and Standard/Datacenter . Every system running a Windows Server instance must be licensed, whether it is physical or virtualized.&lt;br /&gt;
&lt;br /&gt;
===Windows Server Essentials===&lt;br /&gt;
For the Essentials Edition, the licensing model remains &amp;quot;per CPU / per server&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Essentials still has the limitation that a maximum of two CPUs may be installed.&lt;br /&gt;
&lt;br /&gt;
An Essentials license includes two CPUs. Therefore, only one Essentials license needs to be assigned per server.&lt;br /&gt;
&lt;br /&gt;
===Windows Server Standard and Datacenter===&lt;br /&gt;
For the Standard and Datacenter Edition, a &amp;#039;&amp;#039;&amp;#039;core licensing&amp;#039;&amp;#039;&amp;#039; is required. It must be noted how much active, physical kernels possesses a CPU.&lt;br /&gt;
&lt;br /&gt;
To obtain two virtual licenses for the Standard Edition and unlimited licenses for the Datacenter Edition, the following three rules must be observed:&lt;br /&gt;
&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Rule #1:&amp;#039;&amp;#039;&amp;#039; Every physical &amp;#039;&amp;#039;&amp;#039;processor&amp;#039;&amp;#039;&amp;#039; is scored based on &amp;#039;&amp;#039;&amp;#039;at least 8 cores&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Rule #2:&amp;#039;&amp;#039;&amp;#039; Every physical &amp;#039;&amp;#039;&amp;#039;server&amp;#039;&amp;#039;&amp;#039; is scored based on &amp;#039;&amp;#039;&amp;#039;at least 16 cores&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Rule #3:&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;All physical and active cores&amp;#039;&amp;#039;&amp;#039; must be licensed in accordance with Rule #1 and Rule #2&lt;br /&gt;
&lt;br /&gt;
If you want to increase virtualization rights for the Standard Edition, you must double the number of licenses for 4 VMs, triple them for 6 VMs, quadruple them for 8 VMs, and so on. &lt;br /&gt;
&lt;br /&gt;
==== Basis and additional licenses ====&lt;br /&gt;
There are so-called basis licenses and additional licenses. The basis licenses are available with 16 or 24 cores. Additional licenses are available with 2, 4 or 16 cores.&lt;br /&gt;
&lt;br /&gt;
The following chart shows that additional licenses are required only when there are 4 or more CPUs or more than 8 cores.&lt;br /&gt;
&lt;br /&gt;
[[file:Windows Server 2016 Core-Lizenzierung.png |900px]]&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;You are still unsure? No problem!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
In the [https://www.thomas-krenn.com/de/index.html Thomas-Krenn online shop], you do not need to worry about the core licensing yourself.&lt;br /&gt;
&lt;br /&gt;
Our online configurator automatically calculates the correct number of licenses, so that your new Windows server system is licensed correctly.&lt;br /&gt;
&lt;br /&gt;
If you have questions on the licensing, do not hesitate to contact us.&lt;br /&gt;
&lt;br /&gt;
==Software assurance==&lt;br /&gt;
Of course, you can also purchase software assurance for the new server operating system.&lt;br /&gt;
&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Did you know? Software assurance for OEM!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
: Within 90 days, you can buy a software assurance for your OEM Windows Server license&lt;br /&gt;
: An OEM license becomes a volume license when combined with software assurance. You have the same advantages as a volume license customer.&lt;br /&gt;
: Even after the SA expires, the OEM license remains a volume license, so you will continue to benefit from it.&lt;br /&gt;
&lt;br /&gt;
Benefits you can enjoy through software assurance:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;License mobility&amp;#039;&amp;#039;&amp;#039; - all 90 days right of reassignment of the license &lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;free upgrade to a new version of Windows Server&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
*Windows Virtual Desktop access licenses (VDA)&lt;br /&gt;
*and more...&amp;lt;ref&amp;gt;[https://download.microsoft.com/download/0/0/3/0039f316-45cf-4083-aa6e-c35da9d25c1b/sa_interactivebenefitschart.pdf Software Assurance] (www.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Windows Server Access Licenses(CAL)==&lt;br /&gt;
Windows Server Access Licenses - &amp;#039;&amp;#039;&amp;#039;CAL&amp;#039;&amp;#039;&amp;#039;s (&amp;#039;&amp;#039;&amp;#039;C&amp;#039;&amp;#039;&amp;#039;lient &amp;#039;&amp;#039;&amp;#039;A&amp;#039;&amp;#039;&amp;#039;ccess &amp;#039;&amp;#039;&amp;#039;L&amp;#039;&amp;#039;&amp;#039;icence) - are required for the access on systems with Windows Server operating system:&lt;br /&gt;
&lt;br /&gt;
For every user &amp;#039;&amp;#039;&amp;#039;or&amp;#039;&amp;#039;&amp;#039; every device, you require a CAL. If the user or the device accesses a Windows Server via remote desktop, a RDS-CAL is &amp;#039;&amp;#039;&amp;#039;required&amp;#039;&amp;#039;&amp;#039; additionally. &lt;br /&gt;
&lt;br /&gt;
CAL is tied to the &amp;#039;&amp;#039;&amp;#039;latest version&amp;#039;&amp;#039;&amp;#039; of Windows Server, which means that to license a user&amp;#039;s access to a Windows Server 2025, you need a Windows Server 2025 User CAL for that user.&lt;br /&gt;
&lt;br /&gt;
In this scenario, you must not use an older Windows Server CAL!&lt;br /&gt;
&lt;br /&gt;
All important information about the topic access licenses/CALs, can be found directly at Microsoft&amp;lt;ref&amp;gt;[https://www.microsoft.com/de-de/Licensing/produktlizenzierung/client-access-license.aspx Server-Access-License – Client Access License, CAL] (www.microsoft.com)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Did you know? There are OEM-CALs!&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;Every OEM-CAL (Windows-Server-CAL and RDS-CAL) allows the access on every Windows server, regardless of the manufacturer, regardless of whether the Windows Server was licensed through OEM or volume licensing.&lt;br /&gt;
&lt;br /&gt;
You can purchase additional OEM CALs at any time in the Thomas-Krenn online shop: &amp;lt;tklink type=sitex id=18135/&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Downgrade right==&lt;br /&gt;
Every Windows Server license includes an &amp;#039;&amp;#039;&amp;#039;unlimited downgrade right&amp;#039;&amp;#039;&amp;#039;, whether OEM or volume licenses.&lt;br /&gt;
&lt;br /&gt;
With your Windows Server license, you have the right to install all underlying Windows Server versions and editions.&lt;br /&gt;
&lt;br /&gt;
With a Windows Server 2025 Standard license, for example, you may install Windows Server 2016 Standard or Windows Server 2019 Essentials, but not, for example, Windows Server 2019 Datacenter.&lt;br /&gt;
&lt;br /&gt;
To exercise this downgrade right, all you need is an installation medium as well as an installation product key (Windows key) of the operating system that should be installed.&lt;br /&gt;
&lt;br /&gt;
There are so-called &amp;#039;&amp;#039;&amp;#039;downgrade kits&amp;#039;&amp;#039;&amp;#039; that include these installation mediums as well as product keys. You can also purchase these directly from Thomas-Krenn.&lt;br /&gt;
&lt;br /&gt;
All important information on the downgrade topic can be found at Microsoft&amp;lt;ref&amp;gt; 	&lt;br /&gt;
[https://www.microsoft.com/OEM/de/licensing/sblicensing/Pages/downgrade_rights.aspx#fbid=APiJYEBPjyu Information on downgrade rights]  (www.microsoft.com)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
*[https://www.microsoft.com/licensing/guidance/Windows-Server-2025 Microsoft Licence Guide] (www.microsoft.com)&lt;br /&gt;
*[https://www.microsoft.com/en-us/cloud-platform/windows-server Windows Server] (EN) (www.microsoft.com)&lt;br /&gt;
*&amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;18135&amp;quot;&amp;gt;Windows Server 2025 Pricing Information&lt;br /&gt;
&amp;lt;/tklink&amp;gt; (www.thomas-krenn.com)&lt;br /&gt;
*[[Windows Server 2025 Editionsunterschiede|Windows Server 2025 Differences Between Editions]]  (www.wiki.thomas-krenn.com)&lt;br /&gt;
*[https://www.thomas-krenn.com/de/tkmag/webinare/windows-server-2025-lizenzierung-und-editionen/ Thomas-Krenn Webinar on Windows Server 2025 Licensing]] (www.thomas-krenn.com)&lt;br /&gt;
&lt;br /&gt;
{{aoberneder}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[pl:Model licencjonowania w oparciu o rdzenie w Windows Server 2016]]&lt;br /&gt;
[[de:Windows Server Core-Lizenzierung]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows Server 2019]]&lt;br /&gt;
[[Category:Windows Server 2022]]&lt;br /&gt;
[[Category:Windows Server 2025]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Administration_of_RAID_with_MDADM</id>
		<title>Administration of RAID with MDADM</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Administration_of_RAID_with_MDADM"/>
		<updated>2026-07-23T07:14:17Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;This article includes the general procedure of creating and administrating an array with MDADM.&amp;#039;&amp;#039;&amp;#039;  MDAMD (multiple disk administration) is a program that helps with the administration of a Software RAID in Linux. With this program, RAID-arrays can be created, configured, monitored and deleted. MDADM is released as free software under the GNU General Public License (GPL).  MDADM creates so-called multiple devices (short MD) from different block devices (such as an ent...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;This article includes the general procedure of creating and administrating an array with MDADM.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
MDAMD (multiple disk administration) is a program that helps with the administration of a Software RAID in Linux.&lt;br /&gt;
With this program, RAID-arrays can be created, configured, monitored and deleted.&lt;br /&gt;
MDADM is released as free software under the GNU General Public License (GPL).&lt;br /&gt;
&lt;br /&gt;
MDADM creates so-called multiple devices (short MD) from different block devices (such as an entire hard drive, a single partition, or a USB flash drive)&lt;br /&gt;
&lt;br /&gt;
MDADM is a practical software RAID solution that can be actively developed. &lt;br /&gt;
It allows simultaneous, parallel access to all disks.&lt;br /&gt;
In addition, the arrays created are hardware-independent, which significantly enhances data security.&lt;br /&gt;
&lt;br /&gt;
== Possible RAID levels ==&lt;br /&gt;
&lt;br /&gt;
*Linear: Chaining of multiple parities &lt;br /&gt;
*Multipath: No RAID, but mapping of a file on two different paths on the same partition (mirroring). &lt;br /&gt;
*Faulty: Emulates a faulty RAID system for test cases. &lt;br /&gt;
*Level 0 (Block Level Striping): Chaining multiple small block devices together to form one large one.&lt;br /&gt;
*Level 1 (Mirror): Mirroring of a disk &lt;br /&gt;
*Level 4: Like level 0, but with an additional device for parity bit (increased reliability). &lt;br /&gt;
*Level 5: Like level 4, the parity bits are distributed across all devices.&lt;br /&gt;
*Level 6: However, like level 5, it uses two independent parity bits per segment (increased reliability).&lt;br /&gt;
*Level 10: Combination of level 0 and 1. &lt;br /&gt;
&lt;br /&gt;
== Installation of mdadm ==&lt;br /&gt;
&lt;br /&gt;
If RAID was not set up during the Linux installation, you must install the mdadm package from the repositories.&lt;br /&gt;
&amp;lt;pre&amp;gt;:~$ sudo aptitude install mdadm&amp;lt;/pre&amp;gt;&lt;br /&gt;
After the installation, there are no further steps required for the configuration and the tool can be used. &lt;br /&gt;
&lt;br /&gt;
== Commands for configuration and administration == &lt;br /&gt;
&lt;br /&gt;
=== Basic syntax === &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mdadm [mode] &amp;lt;raiddevice&amp;gt; [options] &amp;lt;component-devices&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Create array === &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mdadm --create /dev/md/&amp;lt;Label&amp;gt; --level=&amp;lt;RAID-Level&amp;gt; --raid-devices=&amp;lt;number of physical partitions in the array&amp;gt; /dev/sdX1 /dev/sdY1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Parameter:&lt;br /&gt;
* &amp;lt;code&amp;gt;--create&amp;lt;/code&amp;gt; An optional parameter can be specified to set a label for the RAID. For example: &amp;lt;code&amp;gt;/dev/md/md_1&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;--level=&amp;lt;/code&amp;gt;: Specifies the desired RAID level. Valid entries are  &amp;lt;code&amp;gt;linear, raid0, 0, stripe, raid1, 1, mirror, raid4, 4, raid5, 5, raid6, 6, raid10, 10, multipath, mp, faulty, container&amp;lt;/code&amp;gt;&lt;br /&gt;
* &amp;lt;code&amp;gt;--raid-devices=&amp;lt;/code&amp;gt;: Specifies the number of physical partitions in the software RAID. In addition, the individual partitions must be stated. For example: &amp;lt;code&amp;gt;--raid-devices=2 /dev/sda2 /dev/sdb3&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== RAID 0 with MDADM ====&lt;br /&gt;
To create a RAID 0 (Block Level Striping) array, at least 2 partitions are required. They should be the same size and located on different physical hard drives. &lt;br /&gt;
The RAID 0 array can be initialized with the following command: &amp;lt;code&amp;gt;mdadm --create /dev/md/&amp;lt;Label&amp;gt; --level=0 --raid-devices=&amp;lt;Anzahl&amp;gt; /dev/sdX1 /dev/sdY1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example (2 physical hard drives):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:~# mdadm --create /dev/md/md_test --level=0 --raid-devices=2 /dev/sdb1 /dev/sdc1 &lt;br /&gt;
mdadm: Defaulting to version 1.2 metadata&lt;br /&gt;
mdadm: array /dev/md/md_test started.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== RAID 1 with MDADM ====&lt;br /&gt;
To create a RAID 1 (Block Level Mirroring) array, at least two physical partitions are required. They should be the same size and located on different physical hard drives.&lt;br /&gt;
The RAID 1 array can be initialized with the following command: &amp;lt;code&amp;gt;mdadm --create /dev/md/&amp;lt;Label&amp;gt; --level=1 --raid-devices=&amp;lt;number&amp;gt; /dev/sdX1 /dev/sdY1&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example (2 physical hard drives):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/dev# mdadm --create /dev/md/md_test --level=1 --raid-devices=2 /dev/sdb1 /dev/sdc1 &lt;br /&gt;
mdadm: Note: this array has metadata at the start and&lt;br /&gt;
    may not be suitable as a boot device.  If you plan to&lt;br /&gt;
    store &amp;#039;/boot&amp;#039; on this device please ensure that&lt;br /&gt;
    your boot-loader understands md/v1.x metadata, or use&lt;br /&gt;
    --metadata=0.90 &lt;br /&gt;
Continue creating array? yes&lt;br /&gt;
mdadm: Defaulting to version 1.2 metadata&lt;br /&gt;
mdadm: array /dev/md/md_test started.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Delete array ===&lt;br /&gt;
To remove a RAID array, the array must be unmounted (&amp;lt;code&amp;gt;umount&amp;lt;/code&amp;gt;) and the command &amp;lt;code&amp;gt; mdadm --stop /dev/md/&amp;lt;name of RAID&amp;gt;&amp;lt;/code&amp;gt; must be called up. Although this unmounts the array from the system, the RAID array remains physically in place.&lt;br /&gt;
&lt;br /&gt;
To remove the array, the superblock of every hard drive, which determines the hard drive/partition as RAID-device, must be set to 0. This can be performed with the command &amp;lt;code&amp;gt; mdadm --zero-superblock /dev/&amp;lt;physical partition&amp;gt;&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/dev# umount -l /mnt/test&lt;br /&gt;
root@swraid:/dev# mdadm --stop /dev/md/md_test&lt;br /&gt;
mdadm: stopped /dev/md/md_test&lt;br /&gt;
root@swraid:/dev# mdadm --zero-superblock /dev/sdb1&lt;br /&gt;
root@swraid:/dev# mdadm --zero-superblock /dev/sdc1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Listing arrays/partitions ===&lt;br /&gt;
RAID-arrays can be listed with two kinds of commands. &amp;lt;code&amp;gt;--detail&amp;lt;/code&amp;gt; refers to a completely active array, while &amp;lt;code&amp;gt;--examine&amp;lt;/code&amp;gt; refers to the individual physical devices in a RAID array.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/mnt/test# mdadm --examine --brief --scan  --config=partitions&lt;br /&gt;
ARRAY /dev/md/md_test metadata=1.2 UUID=81c1d8e5:27f6f8b9:9cdc99e6:9d92a1cf name=swraid:md_test&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
This command can also be abbreviated with &amp;lt;code&amp;gt;-Ebsc partitions&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@swraid:/dev/md# mdadm --detail /dev/md/md_test &lt;br /&gt;
/dev/md/md_test:&lt;br /&gt;
        Version : 1.2&lt;br /&gt;
  Creation Time : Fri Jul  5 09:14:36 2013&lt;br /&gt;
     Raid Level : raid0&lt;br /&gt;
     Array Size : 16776192 (16.00 GiB 17.18 GB)&lt;br /&gt;
   Raid Devices : 2&lt;br /&gt;
  Total Devices : 2&lt;br /&gt;
    Persistence : Superblock is persistent&lt;br /&gt;
&lt;br /&gt;
    Update Time : Fri Jul  5 09:14:36 2013&lt;br /&gt;
          State : clean &lt;br /&gt;
 Active Devices : 2&lt;br /&gt;
Working Devices : 2&lt;br /&gt;
 Failed Devices : 0&lt;br /&gt;
  Spare Devices : 0&lt;br /&gt;
&lt;br /&gt;
     Chunk Size : 512K&lt;br /&gt;
&lt;br /&gt;
           Name : swraid:md_test  (local to host swraid)&lt;br /&gt;
           UUID : 81c1d8e5:27f6f8b9:9cdc99e6:9d92a1cf&lt;br /&gt;
         Events : 0&lt;br /&gt;
&lt;br /&gt;
    Number   Major   Minor   RaidDevice State&lt;br /&gt;
       0       8       17        0      active sync   /dev/sdb1&lt;br /&gt;
       1       8       33        1      active sync   /dev/sdc1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Hotspare ===&lt;br /&gt;
Hotspare hard drives/partitions are hard drives/partitions that are not normally used. These are used when one of the active hard drives or partitions in the RAID array has an error or is defective. If no hot spare disk is defined in a software RAID, the rebuild of a failed RAID array must be started manually. If a Hotspare is available, it is automatically started with the rebuild. A Hotspare hard drive can be added with the command &amp;lt;code&amp;gt; mdadm --add /dev/md/&amp;lt;RAID-name&amp;gt; /dev/sdX1&amp;lt;/code&amp;gt;, where the first parameter is the name of the RAID array and the second is the name of the hard drive to be added. If a Hotspare hard drive should be removed from the RAID array, the command &amp;lt;code&amp;gt;mdadm --remove /dev/md/&amp;lt;RAID-name&amp;gt; /dev/sdX1&amp;lt;/code&amp;gt; must be called up. Here, the first parameter is the name of the RAID array, and the second is the name of the hot spare hard drive.&lt;br /&gt;
&lt;br /&gt;
=== Rebuild ===&lt;br /&gt;
If a partition or hard drive has a defect (software or hardware), the RAID array must be rebuilt. To do this, the defect device must be removed from the RAID. The command &amp;lt;code&amp;gt;mdadm --manage /dev/md/&amp;lt;RAID-name&amp;gt; -r /dev/sdX1&amp;lt;/code&amp;gt; is required for this. The first parameter refers to the RAID array. The second to the defect device. If there is no Hotspare hard drive available, a new hard drive must be partitioned. It is important that the new hard drive has the same partition as the defect one. The tools &amp;lt;code&amp;gt;fdisk /dev/sdX&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;cfdisk /dev/sdX1&amp;lt;/code&amp;gt; as well as &amp;lt;code&amp;gt;parted /dev/sdX1&amp;lt;/code&amp;gt; help with the partition of a hard drive. &lt;br /&gt;
If the new hard drive is partitioned correctly, it can be added to the RAID array. This can be made with &amp;lt;code&amp;gt;mdadm --manage /dev/md/&amp;lt;RAID-Name&amp;gt; -a /dev/sdX1&amp;lt;/code&amp;gt;. If no errors occurred during this process, you can begin the actual rebuild. For this, the new partition must be set to &amp;quot;faulty&amp;quot; in the RAID array: &amp;lt;code&amp;gt;mdadm --manage --set-faulty /dev/md/&amp;lt;RAID-name&amp;gt; /dev/sdX1&amp;lt;/code&amp;gt;. This triggers the rebuild of the RAID array.&lt;br /&gt;
With &amp;lt;code&amp;gt;watch cat /proc/mdstat&amp;lt;/code&amp;gt;, the progress of the rebuild can be tracked. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Every 2.0s: cat /proc/mdstat                                                         Fri Jul  5 09:59:16 2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
root@swraid:/dev# watch cat /proc/mdstat &lt;br /&gt;
Personalities : [raid0] [raid1]&lt;br /&gt;
md127 : active raid1 sdc1[1] sdb1[0]&lt;br /&gt;
      8384448 blocks super 1.2 [2/2] [UU]&lt;br /&gt;
      [==============&amp;gt;......]  check = 74.7% (6267520/8384448) finish=0.1min speed=202178K/sec&lt;br /&gt;
&lt;br /&gt;
unused devices: &amp;lt;none&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
As soon as the rebuild of the RAID compound has been completed, the partition must be removed from the RAID array and added again to remove the status &amp;quot;faulty&amp;quot;. &amp;lt;code&amp;gt; mdadm --manage /dev/md/&amp;lt;RAID-name&amp;gt; -r /dev/sdX1&amp;lt;/code&amp;gt; for removing and &amp;lt;code&amp;gt;mdadm --manage /dev/md/&amp;lt;RAID-name&amp;gt; -a /dev/sdX1&amp;lt;/code&amp;gt; for adding. &lt;br /&gt;
With the command &amp;lt;code&amp;gt;mdadm --detail /dev/md/&amp;lt;RAID-name&amp;gt; &amp;lt;/code&amp;gt;, the status of the RAID array can be verified again. This should now have the &amp;#039;&amp;#039;&amp;#039;State: clean&amp;#039;&amp;#039;&amp;#039; status.&lt;br /&gt;
&lt;br /&gt;
=== Set up email address for array monitoring ===&lt;br /&gt;
&lt;br /&gt;
To receive an email notification in the event of a failure, you can enter the desired email address in the mdadm configuration file (&amp;lt;code&amp;gt;/etc/mdadm/mdadm.conf&amp;lt;/code&amp;gt;) under &amp;lt;code&amp;gt;MAILADDR root&amp;lt;/code&amp;gt; instead of &amp;#039;&amp;#039;root&amp;#039;&amp;#039;.&lt;br /&gt;
For this, an email service (&amp;lt;code&amp;gt;postfix, exim, ...&amp;lt;/code&amp;gt;) must be configured on the system.&lt;br /&gt;
Open &amp;#039;&amp;#039;&amp;#039;/etc/mdadm/mdadm.conf&amp;#039;&amp;#039;&amp;#039; with an editor and edit the following line:&lt;br /&gt;
&lt;br /&gt;
Instead of &amp;lt;code&amp;gt;MAILADDR root&amp;lt;/code&amp;gt;, enter an email address such as &amp;lt;code&amp;gt;MAILADDR email@example.com&amp;lt;/code&amp;gt; and save it.&lt;br /&gt;
&lt;br /&gt;
=== Verify array ===&lt;br /&gt;
The tool &amp;lt;code&amp;gt;checkarray&amp;lt;/code&amp;gt; is required to conduct continuous monitoring. This can be added to the list of Cronjobs with &amp;lt;code&amp;gt;crontab -e&amp;lt;/code&amp;gt;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/usr/share/mdadm/checkarray --cron --all --quiet&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Sstrassner}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Software RAID]]&lt;br /&gt;
[[de:Software RAID mit MDADM verwalten]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/IPMI_configuration_for_Supermicro_servers_with_ipmicfg</id>
		<title>IPMI configuration for Supermicro servers with ipmicfg</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/IPMI_configuration_for_Supermicro_servers_with_ipmicfg"/>
		<updated>2026-07-22T12:18:28Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes the tool ipmicfg for Supermicro systems. Alternatively, when the server is operated on Linux, the ipmitool (see article [[Configuring IPMI under Linux using ipmitool|Configuring IPMI on Linux using ipmitool]]) or [[FreeIPMI]] can also be used. Older systems could be also interesting for the tools IPnMAC and XGICFG. Information can be found in the article [[IPMI_Konfiguration_f%C3%BCr_Supermicro_Systeme|IPMI Configuration for Supermicro Systems]]&lt;br /&gt;
&lt;br /&gt;
If there are problems with the configuration, it may be because the required modules have not been loaded. Please take the following article into consideration: [[IPMI Init Script für Debian|IPMI Init Script for Debian]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Basic configuration ==&lt;br /&gt;
[[file:Supermicro-IPMICFG-Windows-version-1.03-Build-110420.png|thumb|right|250px|Screenshot ipmicfg.exe on Windows]]&lt;br /&gt;
IPMICFG version 1.02 (Build 120820) provides the following options:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@test:~# ./ipmicfg-linux.x86_64.static &lt;br /&gt;
&lt;br /&gt;
IPMICFG Version 1.14.3 (Build 130725)&lt;br /&gt;
Copyright 2013 Super Micro Computer, Inc.&lt;br /&gt;
Usage: IPMICFG params (Example: IPMICFG -m 192.168.1.123)&lt;br /&gt;
  -m                    Show IP and MAC.&lt;br /&gt;
  -m IP                 Set IP (format: ###.###.###.###).&lt;br /&gt;
  -a MAC                Set MAC (format: ##:##:##:##:##:##).&lt;br /&gt;
  -k                    Show Subnet Mask.&lt;br /&gt;
  -k Mask               Set Subnet Mask (format: ###.###.###.###).&lt;br /&gt;
  -dhcp                 Get the DHCP status.&lt;br /&gt;
  -dhcp on              Enable the DHCP.&lt;br /&gt;
  -dhcp off             Disable the DHCP.&lt;br /&gt;
  -g                    Show Gateway IP.&lt;br /&gt;
  -g IP                 Set Gateway IP (format: ###.###.###.###).&lt;br /&gt;
  -r                    BMC cold reset.&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -garp on              Enable the Gratuitous ARP.&lt;br /&gt;
  -garp off             Disable the Gratuitous ARP.&lt;br /&gt;
  -fd                   Reset to the factory default.&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -fdl                  Reset to the factory default. (Clean LAN)&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -fde                  Reset to the factory default. (Clean FRU &amp;amp; LAN)&lt;br /&gt;
                        option: -d | Detected IPMI device for BMC reset.&lt;br /&gt;
  -ver                  Get Firmware revision.&lt;br /&gt;
  -vlan                 Get VLAN status.&lt;br /&gt;
  -vlan on &amp;lt;VLANtag&amp;gt;    Enable the VLAN and set the VLAN tag.&lt;br /&gt;
                        If VLANtag is not given it uses previously saved value.&lt;br /&gt;
  -vlan off             Disable the VLAN.&lt;br /&gt;
  -selftest             Checking and reporting on the basic health of BMC.&lt;br /&gt;
  -raw                  Send a RAW IPMI request and print response.&lt;br /&gt;
                        Format: NetFn Cmd [Data1 ... DataN]&lt;br /&gt;
  -fru info             Show FRU inventory area Info.&lt;br /&gt;
  -fru list             Show all FRU values.&lt;br /&gt;
  -fru cthelp           Show chassis type code.&lt;br /&gt;
  -fru help             Show help of FRU Write.&lt;br /&gt;
  -fru &amp;lt;Field&amp;gt;          Show FRU field value.&lt;br /&gt;
  -fru &amp;lt;Field&amp;gt; &amp;lt;Value&amp;gt;  Write FRU.&lt;br /&gt;
  -fru 1m               Update FRU Product Manufacturer from DMITable.&lt;br /&gt;
  -fru 1p               Update FRU Product Prodcut Name from DMITable.&lt;br /&gt;
  -fru 1s               Update FRU Product S/N from DMITable.&lt;br /&gt;
  -fru 2m               Update FRU Board Manufacturer from DMITable.&lt;br /&gt;
  -fru 2p               Update FRU Board Product Name from DMITable.&lt;br /&gt;
  -fru 2s               Update FRU Board S/N from DMITable.&lt;br /&gt;
  -fru 3s               Update FRU Chassis S/N from DMITable.&lt;br /&gt;
  -fru backup &amp;lt;file&amp;gt;    Backup FRU to file &amp;lt;Binary format&amp;gt;.&lt;br /&gt;
  -fru restore &amp;lt;file&amp;gt;   Restore FRU from file &amp;lt;Binary format&amp;gt;.&lt;br /&gt;
  -fru tbackup &amp;lt;file&amp;gt;   Backup FRU to file &amp;lt;Text format&amp;gt;.&lt;br /&gt;
  -fru trestore &amp;lt;file&amp;gt;  Restore FRU from file &amp;lt;Text format&amp;gt;.&lt;br /&gt;
  -fru ver &amp;lt;V1&amp;gt; &amp;lt;V2&amp;gt;    Get/Set FRU version. (V1 V2 are BCD format)&lt;br /&gt;
  -sel info             Show SEL info.&lt;br /&gt;
  -sel list             Show SEL records.&lt;br /&gt;
  -sel del              Delete all SEL records.&lt;br /&gt;
  -sel raw              Show SEL raw data.&lt;br /&gt;
  -sdr                  Show SDR records and reading.&lt;br /&gt;
  -sdr del &amp;lt;SDR ID&amp;gt;     Delete SDR record.&lt;br /&gt;
  -sdr ver &amp;lt;V1&amp;gt; &amp;lt;V2&amp;gt;    Get/Set SDR version. (V1 V2 are BCD format)&lt;br /&gt;
  -nm nmsdr             Display NM SDR.&lt;br /&gt;
  -nm seltime           Get SEL time.&lt;br /&gt;
  -nm deviceid          Get ME Device ID.&lt;br /&gt;
  -nm reset             Reboots ME.&lt;br /&gt;
  -nm reset2default     Force ME reset to Default.&lt;br /&gt;
  -nm updatemode        Force ME to Update Mode.&lt;br /&gt;
  -nm selftest          Get Self Test Results.&lt;br /&gt;
  -nm listimagesinfo    List ME Images information.&lt;br /&gt;
  -nm oemgetpower       OEM Power command for ME.&lt;br /&gt;
  -nm oemgettemp        OEM Temp. command for ME.&lt;br /&gt;
  -nm pstate            Get Max allowed CPU P-State.&lt;br /&gt;
  -nm tstate            Get Max allowed CPU T-State.&lt;br /&gt;
  -nm cpumemtemp        Get CPU/Memory temperature.&lt;br /&gt;
  -nm hostcpudata       Get host CPU data.&lt;br /&gt;
  -fan                  Get Fan Mode.&lt;br /&gt;
  -fan &amp;lt;mode&amp;gt;           Set Fan Mode.&lt;br /&gt;
  -pminfo               Power supply PMBus health.&lt;br /&gt;
  -psfruinfo            Power supply FRU health.&lt;br /&gt;
  -psbbpinfo            Battery backup power status.&lt;br /&gt;
  -autodischarge &amp;lt;module&amp;gt; &amp;lt;day&amp;gt;   Set auto discharge by days.&lt;br /&gt;
  -discharge &amp;lt;module&amp;gt;   Manually discharge battery.&lt;br /&gt;
  -user list            List user privilege information.&lt;br /&gt;
  -user help            Show user privilege code.&lt;br /&gt;
  -user add &amp;lt;user id&amp;gt; &amp;lt;user name&amp;gt; &amp;lt;password&amp;gt; &amp;lt;privilege&amp;gt;&lt;br /&gt;
                        Add user.&lt;br /&gt;
  -user del &amp;lt;user id&amp;gt;   Delete user.&lt;br /&gt;
  -user level &amp;lt;user id&amp;gt; &amp;lt;privilege&amp;gt;  Update user privilege.&lt;br /&gt;
  -user setpwd &amp;lt;user id&amp;gt; &amp;lt;password&amp;gt;  Update user password.&lt;br /&gt;
  -conf upload &amp;lt;file&amp;gt; &amp;lt;option&amp;gt;       Upload IPMI configuration form binary file.&lt;br /&gt;
                        option: -p | Bypass warning message.&lt;br /&gt;
  -conf download &amp;lt;file&amp;gt;              Download IPMI configuration to binary file.&lt;br /&gt;
  -conf tupload &amp;lt;file&amp;gt; &amp;lt;option&amp;gt;      Upload IPMI configuration from text file.&lt;br /&gt;
                        option: -p | Bypass warning message.&lt;br /&gt;
  -conf tdownload &amp;lt;file&amp;gt;             Download IPMI configuration to text file.&lt;br /&gt;
  -clrint               Clear chassis intrusion.&lt;br /&gt;
root@test:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To configure the IPMI module for the first time, it is necessary to state the IP address through which the IPMI module should be accessible.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -m ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, the IPMI module is available via web interface.&lt;br /&gt;
&lt;br /&gt;
== Factory default settings ==&lt;br /&gt;
To set the IPMI module on the default settings, please enter&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -fd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please note that all settings, including all users, are deleted. Furthermore, the DHCP server is switched on after reset.&lt;br /&gt;
&lt;br /&gt;
== Problems with Offset Sensor Readings ==&lt;br /&gt;
Under certain circumstances, some sensor readings may be incorrect or may not be read at all.&lt;br /&gt;
To solve the issue, the following steps must be performed:&lt;br /&gt;
&lt;br /&gt;
[[Correcting Faulty IPMI Sensors by Fully Initializing the IPMI Module]]&lt;br /&gt;
&lt;br /&gt;
== Command reference ==&lt;br /&gt;
=== Display IP and MAC address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -m&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set IP address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -m ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set MAC address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -a ##:##:##:##:##:##&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Display Subnet mask ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Subnet mask ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -k ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Switch on DHCP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -dhcp on&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Switch off DHCP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -dhcp off&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Display Gateway IP address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -g&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Set Gateway IP address ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -g ###.###.###.###&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== BMC Cold Reset ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -r&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Recreate default settings ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -fd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable the Gratuitous ARP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -garp on&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Disable the Gratuitous ARP ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ipmicfg -garp off&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Download ipmicfg ==&lt;br /&gt;
&lt;br /&gt;
If the ipmicfg is not yet installed on the system, it can be downloaded via  [https://www.thomas-krenn.com/de/download.html Thomas-Krenn download area]. For this, select the specific mainboard.&lt;br /&gt;
&lt;br /&gt;
At Supermicro, it is available here:&lt;br /&gt;
* ftp://ftp.supermicro.com/utility/IPMICFG/&lt;br /&gt;
&lt;br /&gt;
{{Bbayer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:IPMI]]&lt;br /&gt;
[[de:IPMI Konfiguration für Supermicro Server mittels ipmicfg]]&lt;br /&gt;
[[pl:Konfiguracja IPMI w serwerach Supermicro za pomocą ipmicfg]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/ZFS_basics</id>
		<title>ZFS basics</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/ZFS_basics"/>
		<updated>2026-07-22T09:28:13Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;ZFS&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;Pseudo-acronym&amp;#039;&amp;#039;, short for &amp;#039;&amp;#039;Zettabyte File System&amp;#039;&amp;#039;) is a &amp;#039;&amp;#039;&amp;#039;file system&amp;#039;&amp;#039;&amp;#039; that has been originally developed by Sun Microsystems for the operating system Solaris. The OpenZFS project develops an Open-Source variant&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/index.html OpenZFS Documentation] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;. ZFS distinguishes itself from other file systems through its focus on data integrity, storage capacity, and the management...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;ZFS&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;Pseudo-acronym&amp;#039;&amp;#039;, short for &amp;#039;&amp;#039;Zettabyte File System&amp;#039;&amp;#039;) is a &amp;#039;&amp;#039;&amp;#039;file system&amp;#039;&amp;#039;&amp;#039; that has been originally developed by Sun Microsystems for the operating system Solaris. The OpenZFS project develops an Open-Source variant&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/index.html OpenZFS Documentation] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;. ZFS distinguishes itself from other file systems through its focus on data integrity, storage capacity, and the management of physical drives within a logical device pool. &lt;br /&gt;
&lt;br /&gt;
== Basic function == &lt;br /&gt;
The main focus of ZFS is on &amp;#039;&amp;#039;&amp;#039;data integrity&amp;#039;&amp;#039;&amp;#039;. To ensure this data integrity, ZFS relies on a &amp;#039;&amp;#039;&amp;#039;transactional&amp;#039;&amp;#039;&amp;#039; approach. This means that writing processes are always completely performed or never&amp;lt;ref&amp;gt;[https://docs.oracle.com/cd/E19120-01/open.solaris/817-2271/gaypi/index.html Transactional Semantics] (docs.oracle.com, 2026)&amp;lt;/ref&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
A simple, asynchron writing process collects or buffers data for a determined period in a so-called &amp;#039;&amp;#039;&amp;#039;transaction group (TXG)&amp;#039;&amp;#039;&amp;#039; in the RAM of the system. After this period, the changes are transferred to permanent storage. This completes the transaction.&lt;br /&gt;
&lt;br /&gt;
To ensure data consistency when following this procedure, ZFS uses a &amp;#039;&amp;#039;&amp;#039;[[Copy-on-Write (COW)|Copy-on-Write (CoW)]]&amp;#039;&amp;#039;&amp;#039; strategy. During a write operation, no blocks are overwritten. Instead, the blocks, with the corresponding changes, are copied to a different location. The old blocks remain intact, but the file system points to the new blocks. If the old blocks are not referenced anymore (for example from [[ZFS Snapshots|Snapshots]]), they may be overwritten during future write operations.&lt;br /&gt;
&lt;br /&gt;
== Setup ==&lt;br /&gt;
[[File:Zfs-storage_stack.png|alt=Abb. 1: A simplified, illustrative representation of the ZFS storage stack|thumb|Image 1: A simplified, illustrative representation of the ZFS storage stack.]]&lt;br /&gt;
To understand the function of ZFS, its building blocks must be understood. &lt;br /&gt;
&lt;br /&gt;
Three levels form the structure of the ZFS storage stack&amp;lt;ref&amp;gt;[https://openzfs.org/wiki/System_Administration &amp;quot;System Administration&amp;quot; in openzfs Wiki] (openzfs.org, 2026)&amp;lt;/ref&amp;gt; (see image 1): The lowest level are the &amp;#039;&amp;#039;&amp;#039;physical data carriers&amp;#039;&amp;#039;&amp;#039;. These are grouped together in logical units within a storage pool called &amp;#039;&amp;#039;&amp;#039;&amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt;&amp;#039;&amp;#039;&amp;#039;. Logical objects are provided for the operating system via &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt;. In addition to the &amp;#039;&amp;#039;&amp;#039;datasets&amp;#039;&amp;#039;&amp;#039;, that correspond to classic file systems, there are also &amp;#039;&amp;#039;&amp;#039;metadata&amp;#039;&amp;#039;&amp;#039; such as snapshots and bookmarks. &lt;br /&gt;
&lt;br /&gt;
{| {{Prettytable}} cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;margin: 1em 1em 1em 0; background: #f9f9f9; border: 1px #a0a0a0 solid; border-collapse: collapse; &amp;quot; rules=&amp;quot;all&amp;quot;&lt;br /&gt;
|The hardware level is not further explained in this article. If you require consulting on an efficient and performant design of a ZFS infrastructure, do not hesitate to contact us: [https://www.thomas-krenn.com/de/unternehmen/kontakt-tk/thomas-krenn-ansprechpartner/slide.presales Contact persons]&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
Furthermore, the &amp;#039;&amp;#039;Adaptive Replacement Cache (ARC)&amp;#039;&amp;#039; and the &amp;#039;&amp;#039;ZFS Intent Log (ZIL)&amp;#039;&amp;#039; are also important elements for the function of ZFS.&lt;br /&gt;
&lt;br /&gt;
=== zpool ===&lt;br /&gt;
The &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt; is a virtual storage pool that is formed by so-called &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt; (&amp;#039;&amp;#039;Virtual Devices&amp;#039;&amp;#039; in brief). ZFS can administrate multiple &amp;lt;code&amp;gt;zpools&amp;lt;/code&amp;gt;. The individual &amp;lt;code&amp;gt;zpools&amp;lt;/code&amp;gt; are independent from each other and must be administrated separately. &lt;br /&gt;
&lt;br /&gt;
==== vdev ==== &lt;br /&gt;
A &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is a logical data carrier within a &amp;lt;code&amp;gt;zpools&amp;lt;/code&amp;gt; that is created by a physical data carrier or a fusion of multiple physical data carriers. It can be formed by the following entities:&lt;br /&gt;
&lt;br /&gt;
* physical data carrier&lt;br /&gt;
* data carrier arrays (for example RAID)&lt;br /&gt;
* partitions&lt;br /&gt;
&lt;br /&gt;
In productive environments, a &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is usually created by individual physical data carriers.&lt;br /&gt;
&lt;br /&gt;
It is also possible to form a &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; out of files. This is an exceptional case and is only recommended for testing purposes. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Storage&amp;#039;&amp;#039;&amp;#039; &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt; are provided for data storage. ZFS provides different redundancy levels for storage &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt;&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/man/master/7/zfsconcepts.7.html zfsconcepts.7] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
* Single (simple data carrier)&lt;br /&gt;
* Mirror (mirrored data carrier)&lt;br /&gt;
* RAIDZ-1/2/3 (data storage network with 1/2/3 parities)&lt;br /&gt;
* [[ZFS dRAID Grundlagen und Einrichtung|dRAID]]&lt;br /&gt;
&lt;br /&gt;
In addition, there are further &amp;lt;code&amp;gt;vdevs&amp;lt;/code&amp;gt; for special use:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Spare&amp;#039;&amp;#039;&amp;#039;: Is used for the failure of a physical data carrier from a storage &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; used for recovery (resilvering)&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Cache&amp;#039;&amp;#039;&amp;#039;: The read buffer, also known as L2ARC &amp;#039;&amp;#039;(Level 2 Adaptive Replacement Cache),&amp;#039;&amp;#039; is an extension of the &amp;#039;&amp;#039;[[Benutzer:Sbohn/Spielwiese5#ARC|ARC]]&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;  &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Log&amp;#039;&amp;#039;&amp;#039;: The so-called &amp;#039;&amp;#039;SLOG&amp;#039;&amp;#039; &amp;#039;&amp;#039;(Separate Intent Log)&amp;#039;&amp;#039; &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is responsible for caching during synchronous write operations. It is the relocation of &amp;#039;&amp;#039;[[Benutzer:Sbohn/Spielwiese5#ZIL|ZIL]] (ZFS Intent Log)&amp;#039;&amp;#039;&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Dedup&amp;#039;&amp;#039;&amp;#039;: This &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is used for storing the &amp;#039;&amp;#039;Deduplication Table (DDT)&amp;#039;&amp;#039; for deduplicate in the &amp;lt;code&amp;gt;zpool&amp;lt;/code&amp;gt; &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Special&amp;#039;&amp;#039;&amp;#039;: A&amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; is used for storing metadata and optionally small data blocks. &amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;It also stores the DDT if there is no dedicated &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt; for it.&lt;br /&gt;
&lt;br /&gt;
=== Datasets ===&lt;br /&gt;
A dataset forms the upper level of the ZFS Storage Stack. The following datasets can be formed with ZFS:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;ZVOL:&amp;#039;&amp;#039;&amp;#039; The &amp;#039;&amp;#039;ZFS Volume&amp;#039;&amp;#039; is a virtual block device &lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;File system:&amp;#039;&amp;#039;&amp;#039; ZFS-native file systems can be set up&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Clone:&amp;#039;&amp;#039;&amp;#039; A standalone, writable copy of a ZFS snapshot&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZVOLs can be used to insert regular file systems on operating system layers. &lt;br /&gt;
&lt;br /&gt;
=== Meta data ===&lt;br /&gt;
In addition to data sets, there are further logical objects in ZFS:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Snapshot:&amp;#039;&amp;#039;&amp;#039; A snapshot is a momentary representation of a system&amp;#039;s state. The blocks described at the time of the snapshot are immutable (&amp;#039;&amp;#039;immutable&amp;#039;&amp;#039;) and remain in place at least until the snapshot and its references are deleted&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Bookmark:&amp;#039;&amp;#039;&amp;#039; A bookmark is a read-only copy of the filesystem or a volume. They are tied to snapshots and are retained even if the snapshot is deleted&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== ARC and ZIL ==&lt;br /&gt;
In addition to the storage stack, there are two other important modules for using ZFS efficiently.&lt;br /&gt;
&lt;br /&gt;
=== ARC ===&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;#039;Adaptive Replacement Cache&amp;#039;&amp;#039; &amp;#039;&amp;#039;(ARC)&amp;#039;&amp;#039; is the reading buffer of ZFS. It is formed in the RAM of the host system&amp;lt;ref name=&amp;quot;:2&amp;quot;&amp;gt;[https://openzfs.github.io/openzfs-docs/Performance%20and%20Tuning/Workload%20Tuning.html#adaptive-replacement-cache Adaptive Replacement Cache] (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;.   &lt;br /&gt;
&lt;br /&gt;
The general task of the ARC is to provide blocks for fast reading processes. For this, the ARC builds lists about buffered entries&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;. The ARC distinguishes from &amp;#039;&amp;#039;most recent&amp;#039;&amp;#039; (&amp;#039;&amp;#039;MRU - Most Recently Used&amp;#039;&amp;#039;) blocks and &amp;#039;&amp;#039;frequently&amp;#039;&amp;#039; (&amp;#039;&amp;#039;MFU - Most Frequently Used&amp;#039;&amp;#039;) used blocks. Therefore, the ARC is faster as commonly used read buffers that only keep MRU in the buffer&amp;lt;ref&amp;gt;[https://github.com/openzfs/zfs/blob/master/module/zfs/arc.c OpenZFS ARC Source Code] (github.com/openzfs, 2026)&amp;lt;/ref&amp;gt;.   &lt;br /&gt;
&lt;br /&gt;
==== L2ARC ====&lt;br /&gt;
The &amp;#039;&amp;#039;Level 2 ARC (L2ARC)&amp;#039;&amp;#039; is formed in the permanent storage (NVMe preferred)&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;. If data is evicted from the ARC, ZFS can store it in the L2ARC and access it during subsequent read operations.&lt;br /&gt;
&lt;br /&gt;
=== ZIL ===&lt;br /&gt;
The &amp;#039;&amp;#039;ZFS Intent Log (ZIL)&amp;#039;&amp;#039; is a temporary cache that is used for synchron writing processes.&lt;br /&gt;
&lt;br /&gt;
The ZIL is not a cache in the strict sense: During a synchronous write operation, the data is written simultaneously to a transaction group (in RAM) and to the ZIL (on physical storage media)&amp;lt;ref&amp;gt;[https://github.com/openzfs/zfs/blob/master/module/zfs/zil.c OpenZFS ZIL Source Code] (github.com/openzfs, 2026)&amp;lt;/ref&amp;gt;. As soon as the data from the transaction group has been fully written to the &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt;, the data is rejected in the ZIL. The ZIL is responsible for data integrity even in the event of system failures. Because data must be written to permanent storage, which is slow compared to RAM, synchronous write operations are less efficient.&lt;br /&gt;
&lt;br /&gt;
==== SLOG ====&lt;br /&gt;
The &amp;#039;&amp;#039;Separate Intent Log (SLOG)&amp;#039;&amp;#039; outsources &amp;#039;&amp;#039;ZIL&amp;#039;&amp;#039;-blocks to a separate &amp;lt;code&amp;gt;vdev&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[https://openzfs.github.io/openzfs-docs/Performance%20and%20Tuning/Workload%20Tuning.html#synchronous-i-o OpenZFS - Synchron Writing Process]  (openzfs.github.io, 2026)&amp;lt;/ref&amp;gt;. This is useful, when the data carriers used for the SLOG have a higher writing performance.&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
Official documentation: [https://openzfs.github.io/openzfs-docs/index.html OpenZFS Documentation]&lt;br /&gt;
&lt;br /&gt;
Basic article: [https://arstechnica.com/information-technology/2020/05/zfs-101-understanding-zfs-storage-and-performance/ ZFS 101—Understanding ZFS storage and performance]&lt;br /&gt;
&lt;br /&gt;
Synchron/Asynchron writing processes: [https://jrs-s.net/2019/05/02/zfs-sync-async-zil-slog/ ZFS sync/async + ZIL/SLOG, explained]&lt;br /&gt;
&lt;br /&gt;
TrueNAS article on ZIL and SLOG: [https://www.truenas.com/blog/zfs-zil-and-slog-demystified/ The ZFS ZIL and SLOG Demystified]&lt;br /&gt;
&lt;br /&gt;
ZFS on Linux: https://zfsonlinux.org/&lt;br /&gt;
&lt;br /&gt;
Aaron Toponce about ZFS: [https://web.archive.org/web/20230904234829/https://pthree.org/2012/04/17/install-zfs-on-debian-gnulinux/ ZFS Administration]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Sbohn}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Storage]]&lt;br /&gt;
[[Category:Review 2027 Q3]]&lt;br /&gt;
[[de:ZFS Grundlagen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OPNsense_network_card_driver</id>
		<title>OPNsense network card driver</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OPNsense_network_card_driver"/>
		<updated>2026-07-21T11:26:59Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;OPNsense contains drivers for numerous network cards. This Wiki article shows, &amp;#039;&amp;#039;&amp;#039;which drivers are used for which network card&amp;#039;&amp;#039;&amp;#039;. Some drivers must be activated manually. Information on this topic can be found in the article Activation of OPNsense Chelsio Mellanox Broadcom network card driver.  == Driver versions == {| class=&amp;quot;wikitable&amp;quot; |+ ! rowspan=&amp;quot;2&amp;quot; |Driver !Supported network chips/cards  !Driver version in OPNsense 26.7 !Driver version in OPNsense 26.1 !Dr...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[OPNsense]] contains drivers for numerous network cards. This Wiki article shows, &amp;#039;&amp;#039;&amp;#039;which drivers are used for which network card&amp;#039;&amp;#039;&amp;#039;. Some drivers must be activated manually. Information on this topic can be found in the article [[Activation of OPNsense Chelsio Mellanox Broadcom network card driver]].&lt;br /&gt;
&lt;br /&gt;
== Driver versions ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
! rowspan=&amp;quot;2&amp;quot; |Driver&lt;br /&gt;
!Supported network chips/cards &lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 26.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 26.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 25.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 25.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 24.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 24.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 23.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 23.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 22.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 22.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 21.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 21.1&lt;br /&gt;
!Driver version&lt;br /&gt;
in OPNsense 20.7&lt;br /&gt;
!Driver version&lt;br /&gt;
in [[OPNsense]] 20.1&lt;br /&gt;
|-&lt;br /&gt;
!Kernel version&lt;br /&gt;
!FreeBSD 15.1-RELEASE&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |FreeBSD 14.3-RELEASE&lt;br /&gt;
!FreeBSD 14.2-RELEASE&lt;br /&gt;
!FreeBSD 14.1-RELEASE&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |FreeBSD 13.2-RELEASE&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |FreeBSD 13.1-RELEASE&lt;br /&gt;
!FreeBSD 13.0-STABLE&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; |FreeBSD 12.1&lt;br /&gt;
![[FreeBSD]] 11.2&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=bge&amp;amp;sektion=4&amp;amp;format=html bge]&lt;br /&gt;
|&lt;br /&gt;
* Broadcom 1Gbit, for example:&lt;br /&gt;
** H12SSL-i - BCM5720&lt;br /&gt;
** H12SSW-iN - BCM5720&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=bnxt&amp;amp;sektion=4&amp;amp;format=html bnxt]&lt;br /&gt;
|&lt;br /&gt;
* Broadcom 10GBit, for example:&lt;br /&gt;
** H12SSL-NT/CT - BCM57416&lt;br /&gt;
** H12SSW-NT - BCM57416&lt;br /&gt;
** P210TP - BCM57416&lt;br /&gt;
*Broadcom 25GBit,for example:&lt;br /&gt;
** X12SPZ-SPLN6F - BCM57414&lt;br /&gt;
** P225P - BCM57414&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |230.0.133.0 (via iflib, driver is activated automatically)&amp;lt;ref&amp;gt;[Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; for a system with a built-in Broadcom P225P network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 230.0.133.0&lt;br /&gt;
dev.bnxt.0.%iommu: rid=0x8100&lt;br /&gt;
dev.bnxt.0.%parent: pci6&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d7 subvendor=0x14e4 subdevice=0x1402 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:129:0:0&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.20.0.1 (via iflib, &amp;#039;&amp;#039;&amp;#039;driver is now activated automatically&amp;#039;&amp;#039;&amp;#039;)&amp;lt;ref&amp;gt;[Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; for a system with a built-in Broadcom P225P network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 2.20.0.1&lt;br /&gt;
dev.bnxt.0.%domain: 0&lt;br /&gt;
dev.bnxt.0.%parent: pci6&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d7 subvendor=0x14e4 subdevice=0x1402 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:24:0:0 handle=\_SB_.PC01.BR1A.H000&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
dev.bnxt.0.%desc: Broadcom BCM57414 NetXtreme-E 10Gb/25Gb Ethernet&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.20.0.1 (via iflib)&amp;lt;ref name=&amp;quot;:5&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a system with a Supermicro H13SSL-NT motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 2.20.0.1&lt;br /&gt;
dev.bnxt.0.%domain: 0&lt;br /&gt;
dev.bnxt.0.%parent: pci1&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d8 subvendor=0x15d9 subdevice=0x16d8 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:195:0:0&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |1.0.0.2 (via iflib)&amp;lt;ref name=&amp;quot;:2&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.bnxt.0.iflib.driver_version: 1.0.0.2&lt;br /&gt;
dev.bnxt.0.%parent: pci2&lt;br /&gt;
dev.bnxt.0.%pnpinfo: vendor=0x14e4 device=0x16d7 subvendor=0x14e4 subdevice=0x1402 class=0x020000&lt;br /&gt;
dev.bnxt.0.%location: slot=0 function=0 dbsf=pci0:194:0:0&lt;br /&gt;
dev.bnxt.0.%driver: bnxt&lt;br /&gt;
dev.bnxt.0.%desc: Broadcom BCM57414 NetXtreme-E 10Gb/25Gb Ethernet&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=cxgbe&amp;amp;sektion=4&amp;amp;format=html cxgbe]&lt;br /&gt;
|&lt;br /&gt;
* Chelsio T4/T5/T6&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=em&amp;amp;sektion=4&amp;amp;format=html em]&lt;br /&gt;
|&lt;br /&gt;
* Intel I219&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; rowspan=&amp;quot;2&amp;quot; |7.6.1-k (via iflib)&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a LES compact 4L with I210:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igb.0.iflib.driver_version: 7.6.1-k&lt;br /&gt;
dev.igb.0.%parent: pci1&lt;br /&gt;
dev.igb.0.%pnpinfo: vendor=0x8086 device=0x157b subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igb.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP01.PXSX&lt;br /&gt;
dev.igb.0.%driver: igb&lt;br /&gt;
dev.igb.0.%desc: Intel(R) PRO/1000 PCI-Express Network Driver&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|7.6.1-k&lt;br /&gt;
|-&lt;br /&gt;
|igb&lt;br /&gt;
|&lt;br /&gt;
* Intel I210&lt;br /&gt;
* Intel I211&lt;br /&gt;
* Intel I350&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |2.5.28-fbsd (via iflib)&amp;lt;ref name=&amp;quot;:7&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a LES compact 4L:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igb.0.iflib.driver_version: 2.5.28-fbsd&lt;br /&gt;
dev.igb.0.%iommu: rid=0x100&lt;br /&gt;
dev.igb.0.%parent: pci1&lt;br /&gt;
dev.igb.0.%pnpinfo: vendor=0x8086 device=0x157b subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igb.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP01.PXSX&lt;br /&gt;
dev.igb.0.%driver: igb&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |2.5.19-fbsd (via iflib)&amp;lt;ref name=&amp;quot;:6&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on an &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;20785&amp;quot;&amp;gt;Edge 4L&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igb.0.iflib.driver_version: 2.5.19-fbsd&lt;br /&gt;
dev.igb.0.%parent: pci1&lt;br /&gt;
dev.igb.0.%pnpinfo: vendor=0x8086 device=0x1533 subvendor=0xffff subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igb.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP03.PXSX&lt;br /&gt;
dev.igb.0.%driver: igb&lt;br /&gt;
dev.igb.0.%desc: Intel(R) I210 (Copper)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |7.6.1-k (via iflib)&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&lt;br /&gt;
|2.5.3-k&lt;br /&gt;
|-&lt;br /&gt;
|igc&lt;br /&gt;
|&lt;br /&gt;
* Intel I225-V&lt;br /&gt;
* Intel I225-LM&lt;br /&gt;
* Intel I226-V&lt;br /&gt;
| colspan=&amp;quot;5&amp;quot; |1 (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.igc.0.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a  &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;20700&amp;quot;&amp;gt;LES v4&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igc.0.iflib.driver_version: 1&lt;br /&gt;
dev.igc.0.%parent: pci1&lt;br /&gt;
dev.igc.0.%pnpinfo: vendor=0x8086 device=0x15f3 subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igc.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PC00.RP01.PXSX&lt;br /&gt;
dev.igc.0.%driver: igc&lt;br /&gt;
dev.igc.0.%desc: Intel(R) Ethernet Controller I225-V&lt;br /&gt;
dev.igc.%parent:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.igc.0.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;21011&amp;quot;&amp;gt;LES plus v4&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igc.0.iflib.driver_version: 1&lt;br /&gt;
dev.igc.0.%parent: pci2&lt;br /&gt;
dev.igc.0.%pnpinfo: vendor=0x8086 device=0x125c subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igc.0.%location: slot=0 function=0 dbsf=pci0:2:0:0 handle=\_SB_.PC00.RP05.PXSX&lt;br /&gt;
dev.igc.0.%driver: igc&lt;br /&gt;
dev.igc.0.%desc: Intel(R) Ethernet Controller I226-V&lt;br /&gt;
dev.igc.%parent:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;5&amp;quot; |1 (via iflib)&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.igc.0.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;20159&amp;quot;&amp;gt;LES network 6L&amp;lt;/tklink&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.igc.0.iflib.driver_version: 1&lt;br /&gt;
dev.igc.0.%parent: pci1&lt;br /&gt;
dev.igc.0.%pnpinfo: vendor=0x8086 device=0x15f3 subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.igc.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PCI0.RP05.PXSX&lt;br /&gt;
dev.igc.0.%driver: igc&lt;br /&gt;
dev.igc.0.%desc: Intel(R) Ethernet Controller I225-V&lt;br /&gt;
dev.igc.%parent:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |(not supported)&lt;br /&gt;
|-&lt;br /&gt;
|ix&lt;br /&gt;
|&lt;br /&gt;
* Intel X520&lt;br /&gt;
* Intel X550&lt;br /&gt;
* Intel E610&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; |5.0.1-k(via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with a Kontron K3881-C motherboard and E610 interfaces:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 5.0.1-k&lt;br /&gt;
dev.ix.0.%iommu: rid=0x700&lt;br /&gt;
dev.ix.0.%parent: pci6&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x57b0 subvendor=0x8086 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:7:0:0 handle=\_SB_.PC00.RP09.PXSX&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
dev.ix.0.%desc: Intel(R) E610 (10 GbE)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|5.0.1-k(via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with X520 (82599ES) interfaces:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 5.0.1-k&lt;br /&gt;
dev.ix.0.%iommu: rid=0x200&lt;br /&gt;
dev.ix.0.%parent: pci2&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x10fb subvendor=0xffff subdevice=0xffff class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:2:0:0 handle=\_SB_.PC00.RP01.PXSX&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
dev.ix.0.%desc: Intel(R) X520 82599ES (SFI/SFP+)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|4.0.1-k (via iflib)&amp;lt;ref name=&amp;quot;:4&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with Supermicro X12SPi-TF motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 4.0.1-k&lt;br /&gt;
dev.ix.0.%domain: 0&lt;br /&gt;
dev.ix.0.%parent: pci1&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x1563 subvendor=0x15d9 subdevice=0x1563 class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PC00.RP01.D033&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|4.0.1-k (via iflib)&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|4.0.1-k (via iflib)&amp;lt;ref name=&amp;quot;:3&amp;quot;&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 6&amp;lt;/code&amp;gt; on a system with Supermicro X10SDV-TP8F motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ix.0.iflib.driver_version: 4.0.1-k&lt;br /&gt;
dev.ix.0.%parent: pci5&lt;br /&gt;
dev.ix.0.%pnpinfo: vendor=0x8086 device=0x15ac subvendor=0x15d9 subdevice=0x15ac class=0x020000&lt;br /&gt;
dev.ix.0.%location: slot=0 function=0 dbsf=pci0:4:0:0 handle=\_SB_.PCI0.BR2C.H000&lt;br /&gt;
dev.ix.0.%driver: ix&lt;br /&gt;
dev.ix.0.%desc: Intel(R) X552 (SFP+)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|3.2.12-k ? (was on OPNsense 18.7)&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=ixl&amp;amp;sektion=4&amp;amp;format=html ixl]&lt;br /&gt;
|&lt;br /&gt;
* Intel X700 Series&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with Advantech FWA-3034:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%iommu: rid=0x200&lt;br /&gt;
dev.ixl.0.%parent: pci2&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x1572 subvendor=0x13fe subdevice=0x303d class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:2:0:0 handle=\_SB_.PC00.PEG0.PEGP&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a system with Asus P13R-M/10G-2T motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%iommu: rid=0x300&lt;br /&gt;
dev.ixl.0.%parent: pci3&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x15ff subvendor=0x1043 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:3:0:0 handle=\_SB_.PC00.RP13.PXSX&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a system that has a built-in Intel X710-T4 network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%domain: 0&lt;br /&gt;
dev.ixl.0.%parent: pci8&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x15ff subvendor=0x8086 subdevice=0x0001 class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:81:0:0 handle=\_SB_.PC02.BR2A.H000&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
dev.ixl.0.%desc: Intel(R) Ethernet Controller X710 for 10GBASE-T - 2.3.3-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.3.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a system featuring an Asus P12R-M/10G-2T motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.3.3-k&lt;br /&gt;
dev.ixl.0.%parent: pci3&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x15ff subvendor=0x1043 subdevice=0x0000 class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:3:0:0 handle=\_SB_.PC00.RP09.D073&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
dev.ixl.0.%desc: Intel(R) Ethernet Controller X710 for 10GBASE-T - 2.3.3-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|2.3.1-k (via iflib)&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; |2.1.0-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a Supermicro AOC-STG-i4S network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ixl.0.iflib.driver_version: 2.1.0-k&lt;br /&gt;
dev.ixl.0.%parent: pci20&lt;br /&gt;
dev.ixl.0.%pnpinfo: vendor=0x8086 device=0x1572 subvendor=0x15d9 subdevice=0x087e class=0x020000&lt;br /&gt;
dev.ixl.0.%location: slot=0 function=0 dbsf=pci0:65:0:0&lt;br /&gt;
dev.ixl.0.%driver: ixl&lt;br /&gt;
dev.ixl.0.%desc: Intel(R) Ethernet Controller X710 for 10GbE SFP+ - 2.1.0-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|1.9.9-k ?&lt;br /&gt;
|-&lt;br /&gt;
|ice&lt;br /&gt;
|&lt;br /&gt;
* Intel E800 Series&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; |1.43.3-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with Advantech FWA-3034:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.0.iflib.driver_version: 1.43.3-k&lt;br /&gt;
dev.ice.0.%iommu: rid=0x100&lt;br /&gt;
dev.ice.0.%parent: pci1&lt;br /&gt;
dev.ice.0.%pnpinfo: vendor=0x8086 device=0x1593 subvendor=0x13fe subdevice=0x2060 class=0x020000&lt;br /&gt;
dev.ice.0.%location: slot=0 function=0 dbsf=pci0:1:0:0 handle=\_SB_.PC00.PEG1.PEGP&lt;br /&gt;
dev.ice.0.%driver: ice&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|1.39.13-k (via iflib)&amp;lt;ref&amp;gt;Read out via  &amp;lt;code&amp;gt;sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; with a system that has a built-in Intel E810-XXVDA2 network card:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.0.iflib.driver_version: 1.39.13-k&lt;br /&gt;
dev.ice.0.%domain: 0&lt;br /&gt;
dev.ice.0.%parent: pci10&lt;br /&gt;
dev.ice.0.%pnpinfo: vendor=0x8086 device=0x159b subvendor=0x8086 subdevice=0x0003 class=0x020000&lt;br /&gt;
dev.ice.0.%location: slot=0 function=0 dbsf=pci0:138:0:0 handle=\_SB_.PC04.BR4A.H000&lt;br /&gt;
dev.ice.0.%driver: ice&lt;br /&gt;
dev.ice.0.%desc: Intel(R) Ethernet Network Adapter E810-XXV-2 - 1.39.13-k&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|1.37.11-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;root@OPNsense:~ # sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt;on a system with Supermicro X12SDV-4C-SP6F motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.0.iflib.driver_version: 1.37.11-k&lt;br /&gt;
dev.ice.0.%domain: 0&lt;br /&gt;
dev.ice.0.%parent: pci8&lt;br /&gt;
dev.ice.0.%pnpinfo: vendor=0x8086 device=0x124d subvendor=0x15d9 subdevice=0x124d class=0x020000&lt;br /&gt;
dev.ice.0.%location: slot=0 function=0 dbsf=pci0:244:0:0 handle=\_SB_.PC02.VP2A.CPM0&lt;br /&gt;
dev.ice.0.%driver: ice&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
|1.34.2-k (via iflib)&amp;lt;ref&amp;gt;Read out via &amp;lt;code&amp;gt;root@OPNsense:~ # sysctl -a | grep -E &amp;#039;dev.*.iflib.driver_version&amp;#039; -A 5&amp;lt;/code&amp;gt; on a system with Supermicro X12SDV-4C-SP6F motherboard:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev.ice.1.iflib.driver_version: 1.34.2-k&lt;br /&gt;
dev.ice.1.%domain: 0&lt;br /&gt;
dev.ice.1.%parent: pci8&lt;br /&gt;
dev.ice.1.%pnpinfo: vendor=0x8086 device=0x124d subvendor=0x15d9 subdevice=0x124d class=0x020000&lt;br /&gt;
dev.ice.1.%location: slot=0 function=2 dbsf=pci0:244:0:2 handle=\_SB_.PC02.VP2A.D077&lt;br /&gt;
dev.ice.1.%driver: ice&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/ref&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; |(not supported)&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=mlx4en&amp;amp;sektion=4&amp;amp;format=html mlx4en]&lt;br /&gt;
|&lt;br /&gt;
* Mellanox ConnectX-4&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.freebsd.org/cgi/man.cgi?query=mlx5en&amp;amp;sektion=4&amp;amp;format=html mlx5en]&lt;br /&gt;
|&lt;br /&gt;
* Mellanox ConnectX-5&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|re&lt;br /&gt;
|&lt;br /&gt;
* Realtek&lt;br /&gt;
| colspan=&amp;quot;14&amp;quot; |See [[Realtek NICs in OPNsense]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== iflib ==&lt;br /&gt;
Iflib is a framework for network interface drivers for FreeBSD. It has been developed to remove standard codeblocks (boilerplates) that are often required for modern network interface devices. This should allow driver developers to focus on the specific code required for their hardware.&amp;lt;ref&amp;gt;[https://www.freebsd.org/cgi/man.cgi?query=iflib&amp;amp;sektion=4&amp;amp;apropos=0&amp;amp;manpath=FreeBSD+12.2-RELEASE+and+Ports iflib Manpage] (www.freebsd.org)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Iflib was launched in the fall of 2017 and provides a standardized set of functions for implementing network drivers. iflib currently supports most Intel drivers and cards from Broadcom NetExtreme family.&amp;lt;ref&amp;gt;[https://www.youtube.com/watch?v=FuNgy8Ag4DE Sam Gwydir: Improving netdump hardware support and performance with iflib - BSDCan 2018] (youtube.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The idea behind iflib was to reduce the redundant code in different NIC drivers to standardize certain kernel interface functions. Most, but not all, NIC drivers have been rewritten by the manufacturers to support the iflib API. The new library handles tasks such as connecting Netmap devices to relieve the manufacturers&amp;#039; driver developers of this burden.&lt;br /&gt;
&lt;br /&gt;
The use of iflib in FreeBSD means that the driver versions have changed. The version that can be seen in the current FreeBSD kernels is the iflib version of the driver and this version number usually does not match the latest version of the driver listed on the manufacturer&amp;#039;s website. Some manufacturers provide an iflib version of their FreeBSD driver for newer kernel versions and an older, non-iflib version for older kernels. And the real catch is that, for some NIC drivers, the version number that appears to be newer and higher is actually older code than what might be included in a non-iflib version.&amp;lt;ref&amp;gt;[https://forum.netgate.com/topic/155324/any-one-know-which-intel-ix-driver-for-x520-card-is-in-the-actual-kernel/4?_=1620296660376&amp;amp;lang=de Any one know which Intel ix driver for x520 card is in the actual kernel?] (forum.netgate.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== IPS support ==&lt;br /&gt;
An overview, which drivers are supported by IPS, is shown in the following spreadsheet:&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1RVj8K3XOzWi-Bkjq6hUxWudu7Cxd8FFTqjLiBMzZWEM/edit#gid=0 netmap(4) on OPNsense] (docs.google.com/spreadsheets)&lt;br /&gt;
&lt;br /&gt;
Information on ixl driver netmap support:&lt;br /&gt;
* [https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=230465#c30 ixl: not working in netmap mode (Comment #30)] (bugs.freebsd.org) &amp;lt;cite&amp;gt;I&amp;#039;m not surprised this works, because ixl in FreeBSD 12.x is implemented through iflib, and netmap in this case uses iflib to access the hw (and iflib must work, otherwise you would not be able to use an ixl NIC using the traditional networking tools and applications).&amp;lt;/cite&amp;gt;&lt;br /&gt;
&lt;br /&gt;
More information:&lt;br /&gt;
* [https://www.thomas-krenn.com/de/tkmag/allgemein/opnsense-webinar-intrusion-detection-pro-und-contra/ OPNsense Webinar: Intrusion Detection – Pro and Contra] (TKmag, 16.06.2020)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:OPNsense]]&lt;br /&gt;
[[de:OPNsense Netzwerkkarten-Treiber]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Installation_of_Open_WebUI_with_Ollama</id>
		<title>Installation of Open WebUI with Ollama</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Installation_of_Open_WebUI_with_Ollama"/>
		<updated>2026-07-20T12:37:05Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Open WebUI&amp;#039;&amp;#039;&amp;#039; provides a browser-based user interface for local KI-models. In connection with Ollama, user can select models and use them via webbrowser.   This article shows the installation of Open WebUI as docker container. Ollama is operated natively on the same Ubuntu server.  &amp;lt;!-- Add after testing: * Used Ubuntu-Version: * Used Open-WebUI-Version: * Used Ollama-Version: * Used Docker-Version: * Used Testhardware: --&amp;gt;  == Requirements ==  These instructions are...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Open WebUI&amp;#039;&amp;#039;&amp;#039; provides a browser-based user interface for local KI-models. In connection with Ollama, user can select models and use them via webbrowser. &lt;br /&gt;
&lt;br /&gt;
This article shows the installation of Open WebUI as docker container. Ollama is operated natively on the same Ubuntu server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Add after testing:&lt;br /&gt;
* Used Ubuntu-Version:&lt;br /&gt;
* Used Open-WebUI-Version:&lt;br /&gt;
* Used Ollama-Version:&lt;br /&gt;
* Used Docker-Version:&lt;br /&gt;
* Used Testhardware:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
These instructions are designed for Ubuntu server 24.04 LTS. The following components must already be installed:&lt;br /&gt;
&lt;br /&gt;
* Ollama in accordance with the article [[Installation of Ollama]]&lt;br /&gt;
* Docker in accordance with the article [[Docker Installation under Ubuntu 24.04]]&lt;br /&gt;
* At least one locally installed Ollama model&lt;br /&gt;
* User with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;-rights&lt;br /&gt;
* Free TCP-Port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Ollama service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl status ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the connection is successful, a JSON response containing the installed models is returned.&lt;br /&gt;
&lt;br /&gt;
If no model is available, download, for example, &amp;lt;code&amp;gt;gemma3:4b&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama pull gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the docker installation:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker version&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Install WebUI ==&lt;br /&gt;
&lt;br /&gt;
Open WebUI runs in a docker container. As Ollama is natively installed on the same server, the container with the host network is started.&lt;br /&gt;
&lt;br /&gt;
Start WebUI:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker run -d \&lt;br /&gt;
  --network=host \&lt;br /&gt;
  -v open-webui:/app/backend/data \&lt;br /&gt;
  -e OLLAMA_BASE_URL=http://127.0.0.1:11434 \&lt;br /&gt;
  --name open-webui \&lt;br /&gt;
  --restart always \&lt;br /&gt;
  ghcr.io/open-webui/open-webui:main&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Docker volume &amp;lt;code&amp;gt;open-webui&amp;lt;/code&amp;gt; stores user accounts, settings and chat histories permanently.&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;main&amp;lt;/code&amp;gt; tag refers to the current version. For the productive operation, a fixed version number should be used after the test has been successful.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Before publishing, change to a stable version after testing:&lt;br /&gt;
ghcr.io/open-webui/open-webui:vX.Y.Z&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the container status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker ps --filter name=open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If necessary, view the startup logs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker logs --tail=100 open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Open web interface ==&lt;br /&gt;
&lt;br /&gt;
Open the following address in a browser:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;http://&amp;amp;lt;IP-DES-SERVERS&amp;amp;gt;:8080&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first user account created on a new installation is granted administrator privileges.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 2: Registration page for Open WebUI --&amp;gt;&lt;br /&gt;
&amp;lt;!-- Screenshot 3: Homepage after first login --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Log in and select &amp;lt;code&amp;gt;gemma3:4b&amp;lt;/code&amp;gt; from the model selection.&lt;br /&gt;
&lt;br /&gt;
Send, for example, the following request:&lt;br /&gt;
&lt;br /&gt;
:Explain the difference between RAID 5 und RAID 6.&lt;br /&gt;
&lt;br /&gt;
If the model responds, the connection between Open WebUI and Ollama functions.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 4: Erste erfolgreiche Antwort in Open WebUI --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Check Ollama connection ==&lt;br /&gt;
&lt;br /&gt;
If no models are displayed, open the following in Open WebUI:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Admin Panel &amp;amp;gt; Settings &amp;amp;gt; Connections&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Ollama address should point to the following URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;http://127.0.0.1:11434&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In addition, check the Ubuntu server:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl http://127.0.0.1:11434/api/tags&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As Open WebUI is started with &amp;lt;code&amp;gt;--network=host&amp;lt;/code&amp;gt;, the container can use the local Ollama address directly.&lt;br /&gt;
&lt;br /&gt;
== Update Open WebUI ==&lt;br /&gt;
&lt;br /&gt;
Load the current container image:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker pull ghcr.io/open-webui/open-webui:main&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Stop and remove the previous container:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker stop open-webui&lt;br /&gt;
sudo docker rm open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, restart Open WebUI:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker run -d \&lt;br /&gt;
  --network=host \&lt;br /&gt;
  -v open-webui:/app/backend/data \&lt;br /&gt;
  -e OLLAMA_BASE_URL=http://127.0.0.1:11434 \&lt;br /&gt;
  --name open-webui \&lt;br /&gt;
  --restart always \&lt;br /&gt;
  ghcr.io/open-webui/open-webui:main&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The data in the docker volume &amp;lt;code&amp;gt;open-webui&amp;lt;/code&amp;gt; is retained.&lt;br /&gt;
&lt;br /&gt;
== Secure access ==&lt;br /&gt;
&lt;br /&gt;
Open WebUI uses user accounts. Nevertheless, port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt; should not be accessible from the Internet without protection. &lt;br /&gt;
&lt;br /&gt;
A VPN or a reverse proxy with HTTPS is recommended for the access from the Internet. For a reverse proxy, WebSockets support must be enabled.&lt;br /&gt;
&lt;br /&gt;
For purely internal use, access can be restricted to the local network using UFW:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ufw allow from 192.168.1.0/24 to any port 8080 proto tcp&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Adapt the subnet to your own environment:&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== Websurface is not available ===&lt;br /&gt;
&lt;br /&gt;
Check the container status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker ps -a --filter name=open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
View the logs:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker logs open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify, if port &amp;lt;code&amp;gt;8080&amp;lt;/code&amp;gt; is already used:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ss -tulpn | grep 8080&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== No models are displayed ===&lt;br /&gt;
&lt;br /&gt;
Check the installed Ollama models:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ls&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check Ollama API:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl http://127.0.0.1:11434/api/tags&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart both services if necessary:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo systemctl restart ollama&lt;br /&gt;
sudo docker restart open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Page is not displayed correctly after an update ===&lt;br /&gt;
&lt;br /&gt;
Open the web interface in a private browser window to test it. If it works there, delete the cache and the website data for the Open-WebUI-address.&lt;br /&gt;
&lt;br /&gt;
== Deinstallation ==&lt;br /&gt;
&lt;br /&gt;
Stop and remove the container:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo docker stop open-webui&lt;br /&gt;
sudo docker rm open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The stored data remains in the Docker volume for the time being.&lt;br /&gt;
&lt;br /&gt;
Remove the volume to delete all Open-WebUI-data completely:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo docker volume rm open-webui&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; User accounts, settings and chat histories are completely deleted.&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://docs.openwebui.com/getting-started/quick-start/ Open WebUI Documentation – Quick Start] (en)&lt;br /&gt;
* [https://docs.openwebui.com/getting-started/quick-start/connect-a-provider/starting-with-ollama/ Open WebUI Documentation – Ollama] (en)&lt;br /&gt;
* [https://docs.openwebui.com/troubleshooting/connection-error/ Open WebUI Documentation – Connection Errors] (en)&lt;br /&gt;
* [https://www.thomas-krenn.com/de/wiki/Docker_Installation_unter_Ubuntu_24.04 Docker Installation on Ubuntu 24.04]&lt;br /&gt;
* [https://docs.ollama.com/api/introduction Ollama Documentation – API Introduction] (en)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Artificial Intelligence]]&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[Category:Docker]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Activation_of_NVIDIA_vGPU_for_RDS_Sessions_on_Windows_Server</id>
		<title>Activation of NVIDIA vGPU for RDS Sessions on Windows Server</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Activation_of_NVIDIA_vGPU_for_RDS_Sessions_on_Windows_Server"/>
		<updated>2026-07-20T10:28:32Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;On Windows Server, applications within an RDS session may not use the assigned NVIDIA vGPU. Instead, Windows uses Microsoft Basic Render Driver by default. As a result, DirectX-based 3D applications, in particular, cannot access the GPU.   This article shows how to activate NVIDIA vGPU for RDS-sessions.  &amp;lt;!-- Add after testing: * Windows-Server-Version: * NVIDIA-vGPU-Version: * vGPU-Profile: * Hypervisor: --&amp;gt;  == Requirements == The NVIDIA vGPU must be assigned to the vi...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On Windows Server, applications within an RDS session may not use the assigned NVIDIA vGPU. Instead, Windows uses Microsoft Basic Render Driver by default. As a result, DirectX-based 3D applications, in particular, cannot access the GPU. &lt;br /&gt;
&lt;br /&gt;
This article shows how to activate NVIDIA vGPU for RDS-sessions.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Add after testing:&lt;br /&gt;
* Windows-Server-Version:&lt;br /&gt;
* NVIDIA-vGPU-Version:&lt;br /&gt;
* vGPU-Profile:&lt;br /&gt;
* Hypervisor:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
The NVIDIA vGPU must be assigned to the virtual machine and the suitable guest driver must be installed.&lt;br /&gt;
&lt;br /&gt;
Check first if Windows recognizes the vGPU:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;nvidia-smi&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The command should display the assigned GPU and the graphics memory available. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 1: Ausgabe von nvidia-smi --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Enable Group Policy ==&lt;br /&gt;
&lt;br /&gt;
Open the dialogue &amp;lt;code&amp;gt;Execute&amp;lt;/code&amp;gt; via &amp;lt;code&amp;gt;Windows-Key+ R&amp;lt;/code&amp;gt; and start:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;gpedit.msc&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Navigate to:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Computer-Configuration &amp;amp;gt; Administrative Templates&amp;amp;gt; Windows-Components&amp;amp;gt; Remotedesktopservices &amp;amp;gt; Remotedesktop-Session-Host &amp;amp;gt; Remote-Session-Environment&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 2: Pfad im Gruppenrichtlinien-Editor --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Activate the guideline:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Hardware graphics adapter for all remotedesktopservices-sessions&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The English name is:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Use the hardware default graphics adapter for all Remote Desktop Services Sessions&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 3: Aktivierte Gruppenrichtlinie --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, restart Windows-Server-VM.&lt;br /&gt;
&lt;br /&gt;
== Check GPU-use ==&lt;br /&gt;
&lt;br /&gt;
Re-establish an RDS connection and launch an application that uses GPU acceleration.&lt;br /&gt;
&lt;br /&gt;
Check the utilization in the Task-Manager:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;Performance &amp;amp;gt; GPU&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, you can execute the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;powershell&amp;quot;&amp;gt;nvidia-smi&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a GPU still does not appear, check the NVIDIA vGPU guest driver, the assigned vGPU profile, and the licensing.&lt;br /&gt;
&lt;br /&gt;
== Background ==&lt;br /&gt;
&lt;br /&gt;
NVIDIA describes this behaviour for all supported Windows Server guest operating systems. The default settings uses Microsoft Basic Render Driver, as Software Rendering can be more efficient for simple 2D-applications.&lt;br /&gt;
DirectX-based 3D-applications cannot, however, access the GPU.&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://docs.nvidia.com/vgpu/19.0/known-issues/bug-no-id-no-gpu-utilization-windows-server-guests.html NVIDIA vGPU Documentation – RDS sessions do not use the GPU with Microsoft Windows Server as guest OS] (en)&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Windows]]&lt;br /&gt;
[[Category:Virtual Desktop Infrastructure (VDI)]]&lt;br /&gt;
[[de:NVIDIA vGPU für RDS-Sitzungen unter Windows Server aktivieren]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_July_2026</id>
		<title>Supermicro BMC Security Advisories July 2026</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_July_2026"/>
		<updated>2026-07-20T05:49:48Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In &amp;#039;&amp;#039;&amp;#039;July 2026&amp;#039;&amp;#039;&amp;#039;, Supermicro published security advisories regarding the BMC-firmware of its mainboards. This security vulnerability requires a &amp;#039;&amp;#039;&amp;#039;firmware update&amp;#039;&amp;#039;&amp;#039;. &lt;br /&gt;
&lt;br /&gt;
In this article, you will find information on this security advisory and where to find updates on Thomas-Krenn products.&lt;br /&gt;
&lt;br /&gt;
== Security advisories ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |CVE&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Risk potential&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Description&lt;br /&gt;
|-&lt;br /&gt;
|align=&amp;quot;center&amp;quot;  | CVE-2026-3821&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | High 8.8&lt;br /&gt;
| align=&amp;quot;left&amp;quot; | &amp;#039;&amp;#039;&amp;#039;&amp;lt;u&amp;gt;Execution of arbitrary code&amp;lt;/u&amp;gt;&amp;#039;&amp;#039;&amp;#039; (The SMASH-services of Supermicro (SMC) show a security vulnerability that allows the execution of an arbitrary code. An authorized attacker can exploit SMASH input functions to compromise data integrity or launch a denial-of-service (DoS) attack against the BMC.)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Updates for Thomas-Krenn products ==&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;download area of Thomas-Krenn&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The updates in the download area have been tested by us to guarantee the stability and compatibility of our systems.&lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you can get it at [https://www.asus.com/de/support/download-center/ Asus] or [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro].&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://www.supermicro.com/en/support/security_BMC_IPMI_Jul_2026 Vulnerabilities in Supermicro BMC Firmware, July 2026]&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Server Hardware]]&lt;br /&gt;
[[de:Supermicro BMC Sicherheitshinweise Juli 2026]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Installation_of_Ollama</id>
		<title>Installation of Ollama</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Installation_of_Ollama"/>
		<updated>2026-07-17T07:38:13Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Ollama&amp;#039;&amp;#039;&amp;#039; allows the local operation of Large Language Models (LLMs) on a Linux server. The models run on the own hardware and can be used via command line or HTTP-API.&lt;br /&gt;
&lt;br /&gt;
This article presents the native installation of Ollama on an Ubuntu server. As an example, a small model is downloaded and tested by using the local command line as well as the local API.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Add the following information after testing:&lt;br /&gt;
* Ubuntu-Version used:&lt;br /&gt;
* Ollama-Version used:&lt;br /&gt;
* Testhardware used:&lt;br /&gt;
* GPU used:&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
These instructions are designed for Ubuntu Server 24.04 LTS. The installation normally functions on an Ubuntu Server LTS and 22.04 LTS, too. For GPU-systems should be verified if a suitable driver is available for the used Ubuntu version in advance. &lt;br /&gt;
&lt;br /&gt;
The following resources are recommended for initial testing:&lt;br /&gt;
&lt;br /&gt;
* user with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;-rights&lt;br /&gt;
* at least 8 GB RAM&lt;br /&gt;
* at least 20 GB storage available&lt;br /&gt;
* Internet access for installation and model download &lt;br /&gt;
* optional for a supported NVIDIA or AMD-GPU&lt;br /&gt;
&lt;br /&gt;
Verify the intalled Ubuntu version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;cat /etc/os-release&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install &amp;lt;code&amp;gt;curl&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo apt install -y curl&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Install Ollama == &lt;br /&gt;
Execute the official installation script:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl -fsSL https://ollama.com/install.sh | sh&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 1: Output of Ollama installation script --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, verify the installed version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama -v&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The installation script sets up a systemd-service. Check its status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl status ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The service should be displayed with the &amp;lt;code&amp;gt;active (running)&amp;lt;/code&amp;gt; state.&lt;br /&gt;
&lt;br /&gt;
If the service is not started, it can be activated manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl enable --now ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Start initial model ==&lt;br /&gt;
&lt;br /&gt;
In this example, &amp;lt;code&amp;gt;gemma3:4b&amp;lt;/code&amp;gt; is used. The model requires approximately 2.2 GB storage for the download and is suitable for the initial function test.&lt;br /&gt;
&lt;br /&gt;
Start the model:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama run gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ollama automatically downloads the model the first time it is runned. It may take a few minutes depending on the Internet connection.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 2: Download and start of gemma3:4b --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, enter the following query, for example:&lt;br /&gt;
&lt;br /&gt;
:Explain the difference between RAID 5 and RAID 6.&lt;br /&gt;
&lt;br /&gt;
Finish the session with:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;/bye&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Display the installed models:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ls&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Verify GPU-usage == &lt;br /&gt;
&lt;br /&gt;
Ollama automatically uses a supported GPU if the required driver is installed.&lt;br /&gt;
&lt;br /&gt;
Start the model and open the second SSH-session:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama run gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the current version there:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ps&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The column &amp;lt;code&amp;gt;PROCESSOR&amp;lt;/code&amp;gt; displays if the model is executed on the CPU, GPU or on both.&lt;br /&gt;
&lt;br /&gt;
With an NVIDIA GPU, you can also check the utilization:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;nvidia-smi&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If there is no supported GPU available, Ollama executes the model via CPU and RAM. Response times are generally longer in such cases.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Screenshot 3: Output from ollama ps and optionally nvidia-smi --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Check Ollama-API == &lt;br /&gt;
&lt;br /&gt;
Ollama provides a local HTTP-API on port &amp;lt;code&amp;gt;11434&amp;lt;/code&amp;gt; by default. &lt;br /&gt;
&lt;br /&gt;
Display the models available via API:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl http://127.0.0.1:11434/api/tags&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the connection is successful, a JSON response containing the installed models is returned.&lt;br /&gt;
&lt;br /&gt;
The local API is, for example, used by Open WebUI, n8n and own applications.&lt;br /&gt;
&lt;br /&gt;
== Optional: Acces from the local network == &lt;br /&gt;
&lt;br /&gt;
By default, Ollama only listens on &amp;lt;code&amp;gt;127.0.0.1&amp;lt;/code&amp;gt;. If another system should access the API in the local network, the Bind address must be adjusted.&lt;br /&gt;
&lt;br /&gt;
Open the systemd extension:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl edit ollama.service&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;ini&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;[Service]&lt;br /&gt;
Environment=&amp;quot;OLLAMA_HOST=0.0.0.0:11434&amp;quot;&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Apply changes:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot; line=&amp;quot;1&amp;quot;&amp;gt;sudo systemctl daemon-reload&lt;br /&gt;
sudo systemctl restart ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, verify the port:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ss -tulpn | grep 11434&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By default, the Ollama API does not have its own user authentication for locally run models. Port &amp;lt;code&amp;gt;11434&amp;lt;/code&amp;gt; should therefore only be released for reuqired systems and should not be directly available from the Internet.&lt;br /&gt;
&lt;br /&gt;
Here is an example for the release of an internal subnet with UFW:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ufw allow from 192.168.1.0/24 to any port 11434 proto tcp&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Customize the subnet to suit your own environment.&lt;br /&gt;
&lt;br /&gt;
Further Ollama environment variables can be added in the same systemd-extension. All &amp;lt;code&amp;gt;Environment=&amp;quot;...&amp;quot;&amp;lt;/code&amp;gt; lines are entered together under a &amp;lt;code&amp;gt;[Service]&amp;lt;/code&amp;gt; block.&lt;br /&gt;
&lt;br /&gt;
== Update Ollama ==&lt;br /&gt;
&lt;br /&gt;
On Linux, Ollama is updated by running the installation script again:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;curl -fsSL https://ollama.com/install.sh | sh&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Models that have already been downloaded will remain.&lt;br /&gt;
&lt;br /&gt;
After that, check the version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama -v&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== Ollama-service does not run ===&lt;br /&gt;
&lt;br /&gt;
Verify the service status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl status ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Display the most recent log entries:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo journalctl -e -u ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Model does not start ===&lt;br /&gt;
&lt;br /&gt;
Check the available storage space:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;df -h&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Display the installed models:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama ls&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If necessary, download the model again:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;ollama pull gemma3:4b&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Port 11434 is not available ===&lt;br /&gt;
&lt;br /&gt;
Check if Ollama listens on the port:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo ss -tulpn | grep 11434&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart the service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;sudo systemctl restart ollama&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* [https://docs.ollama.com/linux Ollama Documentation – Linux] (en)&lt;br /&gt;
* [https://docs.ollama.com/quickstart Ollama Documentation – Quickstart] (en)&lt;br /&gt;
* [https://docs.ollama.com/api/introduction Ollama Documentation – API Introduction] (en)&lt;br /&gt;
* [https://docs.ollama.com/faq Ollama Documentation – FAQ] (en)&lt;br /&gt;
* [https://ollama.com/library/gemma3:4b Ollama Model Library – Gemma 3 4B] (en)&lt;br /&gt;
* [https://ubuntu.com/about/release-cycle Ubuntu Release Cycle] (en)&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Artificial Intelligence]]&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de: Ollama installieren]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Failed_to_fetch_enterprise.proxmox.com_401_Unauthorized</id>
		<title>Failed to fetch enterprise.proxmox.com 401 Unauthorized</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Failed_to_fetch_enterprise.proxmox.com_401_Unauthorized"/>
		<updated>2026-07-16T12:53:03Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;Proxmox Server Solutions GmbH from Vienna provides two package repositories for Proxmox VE: &amp;#039;&amp;#039;&amp;#039;Proxmox VE Enterprise Repository&amp;#039;&amp;#039;&amp;#039; (subject to a fee, recommended for productive use) and &amp;#039;&amp;#039;&amp;#039;Proxmox VE No-Subscription Repository&amp;#039;&amp;#039;&amp;#039; (free of charge, recommended for testing purposes). After Installation of Proxmox VE, the following error message appears when trying to install updates: &amp;#039;&amp;#039;&amp;#039;&amp;lt;nowiki&amp;gt;Failed to fetch https://enterprise.proxmox.com/debian/pve/dists/buster/I...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Proxmox Server Solutions GmbH from Vienna provides two package repositories for [[Proxmox VE]]: &amp;#039;&amp;#039;&amp;#039;Proxmox VE Enterprise Repository&amp;#039;&amp;#039;&amp;#039; (subject to a fee, recommended for productive use) and &amp;#039;&amp;#039;&amp;#039;Proxmox VE No-Subscription Repository&amp;#039;&amp;#039;&amp;#039; (free of charge, recommended for testing purposes). After [[Installation of Proxmox VE]], the following error message appears when trying to install updates: &amp;#039;&amp;#039;&amp;#039;&amp;lt;nowiki&amp;gt;Failed to fetch https://enterprise.proxmox.com/debian/pve/dists/buster/InRelease 401 Unauthorized&amp;lt;/nowiki&amp;gt;&amp;#039;&amp;#039;&amp;#039;. This article shows how to solve this error by either setting up a paid subscription to the Enterprise Repository or, alternatively, using the free No-Subscription Repository. &lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
[[File:Proxmox_8_Updates_Refresh_Error.png|thumb|right|After the installation, Proxmox VE displays the following error message when trying to install the updates. The access to &amp;#039;&amp;#039;&amp;#039;Proxmox VE Enterprise Repository&amp;#039;&amp;#039;&amp;#039; can be unlocked with a subscription key. Alternatively, the &amp;#039;&amp;#039;&amp;#039;Proxmox VE No-Subscription Repository&amp;#039;&amp;#039;&amp;#039; is available for testing purposes.]] After the installation of Proxmox VE, the following message appears without further configuration when trying to install updates:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Header&lt;br /&gt;
Proxmox&lt;br /&gt;
Virtual Environment 8.1.3&lt;br /&gt;
Node &amp;#039;pve&amp;#039;&lt;br /&gt;
Show details&lt;br /&gt;
Logs&lt;br /&gt;
()&lt;br /&gt;
starting apt-get update&lt;br /&gt;
Get:1 http://security.debian.org bookworm-security InRelease [48.0 kB]&lt;br /&gt;
[...]&lt;br /&gt;
Get:9 http://ftp.at.debian.org/debian bookworm/main Translation-en [6109 kB]&lt;br /&gt;
Err:10 https://enterprise.proxmox.com/debian/ceph-quincy bookworm InRelease&lt;br /&gt;
  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
Err:11 https://enterprise.proxmox.com/debian/pve bookworm InRelease&lt;br /&gt;
  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
Get:12 http://ftp.at.debian.org/debian bookworm/contrib amd64 Packages [54.1 kB]&lt;br /&gt;
Get:13 http://ftp.at.debian.org/debian bookworm/contrib Translation-en [48.7 kB]&lt;br /&gt;
Get:14 http://ftp.at.debian.org/debian bookworm-updates/main amd64 Packages [12.7 kB]&lt;br /&gt;
Get:15 http://ftp.at.debian.org/debian bookworm-updates/main Translation-en [13.8 kB]&lt;br /&gt;
Reading package lists...&lt;br /&gt;
E: Failed to fetch https://enterprise.proxmox.com/debian/ceph-quincy/dists/bookworm/InRelease  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
E: The repository &amp;#039;https://enterprise.proxmox.com/debian/ceph-quincy bookworm InRelease&amp;#039; is not signed.&lt;br /&gt;
E: Failed to fetch https://enterprise.proxmox.com/debian/pve/dists/bookworm/InRelease  401  Unauthorized [IP: 212.224.123.70 443]&lt;br /&gt;
E: The repository &amp;#039;https://enterprise.proxmox.com/debian/pve bookworm InRelease&amp;#039; is not signed.&lt;br /&gt;
TASK ERROR: command &amp;#039;apt-get update&amp;#039; failed: exit code 100&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Solution 1: Proxmox VE Enterprise Repository == &lt;br /&gt;
This is the default, stable and recommended repository that is available for all users of Proxmox VE subcriptions. It contains the most stable packages and is suitable for production use. The pve-enterprise Repository is activated by default (/etc/apt/sources.list.d/pve-enterprise.list).&lt;br /&gt;
&lt;br /&gt;
Information on the subscriptions available can be found in the article [[Proxmox VE Support-Subscriptions]].&lt;br /&gt;
&lt;br /&gt;
== Solution 2: Proxmox VE No-Subscription Repository == &lt;br /&gt;
This is the repository that is recommended for testing and non-production purposes. The included packages are not as intensively tested and validated as those from the Proxmox VE Enterprise Repository. There is no subscription key required for the access on the pve-no-subscription Repository.&lt;br /&gt;
&lt;br /&gt;
The following settings must be selected in /etc/apt/sources.list for using the No-Subscription Repository:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
deb http://ftp.at.debian.org/debian bookworm main contrib&lt;br /&gt;
deb http://ftp.at.debian.org/debian bookworm-updates main contrib&lt;br /&gt;
&lt;br /&gt;
# PVE pve-no-subscription repository provided by proxmox.com,&lt;br /&gt;
# NOT recommended for production use&lt;br /&gt;
deb http://download.proxmox.com/debian/pve bookworm pve-no-subscription&lt;br /&gt;
&lt;br /&gt;
# security updates&lt;br /&gt;
deb http://security.debian.org bookworm-security main contrib&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Note: So that the message &amp;quot;failed to fetch&amp;quot; disappears permanently, you must comment out the respective repository listed in each file by adding a &amp;quot;#&amp;quot; before it in the following two files:&lt;br /&gt;
* /etc/apt/sources.list.d/pve-enterprise.list:&lt;br /&gt;
*: &amp;lt;pre&amp;gt;# deb https://enterprise.proxmox.com/debian/pve bookworm pve-enterprise&amp;lt;/pre&amp;gt;&lt;br /&gt;
* /etc/apt/sources.list.d/ceph.list:&lt;br /&gt;
*: &amp;lt;pre&amp;gt;# deb https://enterprise.proxmox.com/debian/ceph-quincy bookworm enterprise&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://pve.proxmox.com/wiki/Package_Repositories Package Repositories] (pve.proxmox.com/wiki)&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Proxmox Troubleshooting]]&lt;br /&gt;
[[de:Failed to fetch enterprise.proxmox.com 401 Unauthorized]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Synology_UC3400_Metadata-Overflow</id>
		<title>Synology UC3400 Metadata-Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Synology_UC3400_Metadata-Overflow"/>
		<updated>2026-07-15T12:03:11Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;right On the Synology UC3400, a very high number of metadata objects (&amp;gt;10 million) leads to a critical condition in combination with migrations and snapshot load that may cause CPU and RAM overloads and cause migrations to fail.   This article describes symptoms and provides possible solutions.  == Initial situation == The UC3400 administrates SAN and LUN structures with the help of a internal metadata database. When there is...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[file:UC3400_Front.png|frameless|322x322px|right]]&lt;br /&gt;
On the Synology UC3400, a very high number of metadata objects (&amp;gt;10 million) leads to a critical condition in combination with migrations and snapshot load that may cause CPU and RAM overloads and cause migrations to fail. &lt;br /&gt;
&lt;br /&gt;
This article describes symptoms and provides possible solutions.&lt;br /&gt;
&lt;br /&gt;
== Initial situation ==&lt;br /&gt;
The UC3400 administrates SAN and LUN structures with the help of a internal metadata database. When there is a very large number of objects, the metadata can grow significantly. In addition, long snapshot chains, numerous copy-on-write operations, and the simultaneous processing of I/O and metadata accesses lead to increased system load. &lt;br /&gt;
&lt;br /&gt;
The situation becomes particularly critical when there is a high number of snapshots, long operation hours without reorganisation, the migration of more extensive LUNs or the high rates of changes within a short time. &lt;br /&gt;
&lt;br /&gt;
== Problem description ==&lt;br /&gt;
When there are more than &amp;#039;&amp;#039;&amp;#039;approximately 10 million metadata objects&amp;#039;&amp;#039;&amp;#039;, a significant system overload occurs on the UC3400. This condition is often referred to as &amp;#039;&amp;#039;&amp;#039;Metadata overflow&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
Possible symptoms are:&lt;br /&gt;
&lt;br /&gt;
* CPU-/RAM-load permanently close to 100%&lt;br /&gt;
* migrations are canceled or &amp;quot;timeouted&amp;quot;&lt;br /&gt;
* system reacts very slowly&lt;br /&gt;
* storage and snapshot operations block each other&lt;br /&gt;
* SAN-services fail temporarily &lt;br /&gt;
* risk for inconsistent LUN conditions increases &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;The following applies to the Synology UC3400:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
* &amp;lt; 5 million objects → stable&lt;br /&gt;
* 5–10 million objects → marginal&lt;br /&gt;
* 10 million objects → critical (overflow risk)&lt;br /&gt;
* 50 milion objects → can only be operated effectively with significant optimization&lt;br /&gt;
&lt;br /&gt;
== &amp;#039;&amp;#039;&amp;#039;Immediate measures&amp;#039;&amp;#039;&amp;#039; ==&lt;br /&gt;
The following measures can be implemented to restore operational capability quickly:&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; These measures are intended solely as temporary workarounds and do not constitute a long-term solution for production operations. &lt;br /&gt;
* stop migration&lt;br /&gt;
* reduce snapshot load&lt;br /&gt;
* restart services (only in maintenance window)&lt;br /&gt;
&lt;br /&gt;
== &amp;#039;&amp;#039;&amp;#039;Recommended solution strategy&amp;#039;&amp;#039;&amp;#039; ==&lt;br /&gt;
The most sustainable solution is a reorganization of the LUN-structure and a migration into smaller, clearly separated units.&lt;br /&gt;
&lt;br /&gt;
=== Create new LUN ===&lt;br /&gt;
The most stable method is:&lt;br /&gt;
&lt;br /&gt;
# create new LUN&lt;br /&gt;
# transmit data via storage migration or backup restore&lt;br /&gt;
# delete old LUN&lt;br /&gt;
&lt;br /&gt;
As a result, all old metadata will be deleted completely.&lt;br /&gt;
&lt;br /&gt;
=== Alternative: Metadata-Rebuild ===&lt;br /&gt;
{| {{Prettytable}} cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;margin: 1em 1em 1em 0; background: #f9f9f9; border: 1px #a0a0a0 solid; border-collapse: collapse; &amp;quot; rules=&amp;quot;all&amp;quot;&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Note: A Metadata-Rebuild should be only performed if there is a current and functional backup of all relevant data!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
This risky procedure is intended solely as a last resort for recovery after all other diagnostic and repair measures have been proven unsuccessful.&lt;br /&gt;
&lt;br /&gt;
Only with complete backup:&lt;br /&gt;
&lt;br /&gt;
* metadata structure is deleted and recreated&lt;br /&gt;
* risk of iSCSI-Mapping losses&lt;br /&gt;
* only recommended for emergencies&lt;br /&gt;
== Prevention == &lt;br /&gt;
To avoid the above mentioned problems, the following measures can be implemented:&lt;br /&gt;
* limit snapshot number&lt;br /&gt;
* LUN-recreation for long durations on a regular basis&lt;br /&gt;
* unload metadata regularly &lt;br /&gt;
* divide migrations in smaller sessions&lt;br /&gt;
* monitoring of CPU / RAM and SAN metadata load &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Recommendation:&amp;#039;&amp;#039;&amp;#039; When migrating large amounts of data, you should involve Synology Support early on. This way, they can assist with the data migration if needed, and you will receive recommendations on best practices to minimize risks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Wsuess}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Storage]]&lt;br /&gt;
[[de:Synology UC3400 Metadaten-Overflow]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/IPMI_BMC_reset_for_IPMI_problems</id>
		<title>IPMI BMC reset for IPMI problems</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/IPMI_BMC_reset_for_IPMI_problems"/>
		<updated>2026-07-09T11:34:27Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If there are any problems with IPMI or Remote Management Webinterface, the BMC (Baseboard Management Controller) can be &amp;#039;&amp;#039;&amp;#039;restartet&amp;#039;&amp;#039;&amp;#039; using the &amp;#039;&amp;#039;&amp;#039;IPMItool&amp;#039;&amp;#039;&amp;#039;. In this example, it is explained how to restart the BMC in Linux with ipmitool.&lt;br /&gt;
&lt;br /&gt;
== IPMI BMC reset via ipmitool (remote) ==&lt;br /&gt;
If the server does not run on Linux, ipmitool can be executed on a Linux computer to restart the BMC of another server by using its IPMI IP address.&lt;br /&gt;
&lt;br /&gt;
The command for the reset of the module on the server  10.0.0.1 (default user and pw) is as follows:&lt;br /&gt;
 ipmitool mc reset cold -I lan -H 10.0.0.1 -U admin -P password  &lt;br /&gt;
&lt;br /&gt;
The last parameter is optional. It is prompted for the password if it has not been entered yet.  Communication between the ipmitool on the Linux system and the IPMI BMC of the server takes place via UDP port 623.&lt;br /&gt;
&lt;br /&gt;
== IPMI BMC reset via ipmitool (local) ==&lt;br /&gt;
If Linux is installed on the server itself, BMC can be reset locally (with root rights):&lt;br /&gt;
 ipmitool mc reset cold&lt;br /&gt;
&lt;br /&gt;
== Alternative: Turn off server == &lt;br /&gt;
If the described procedure does not function with a reset via IPMI command, there is always the possibility to shut down the server and to turn off the power for 30 seconds then. To do this, the server must be disconnected completely from the power supply. This procedure also leads to a reset of the BMC.&lt;br /&gt;
&lt;br /&gt;
== Recreate default settings ==&lt;br /&gt;
If you also want to recreate default settings, you can use the ipmicfg tool for Supermicro-based systems (see also [[IPMICFG#Recreation of default settings]]).&lt;br /&gt;
&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Remote Management]]&lt;br /&gt;
[[de:IPMI BMC reset bei IPMI Problemen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Windows_Server_2025:_Differences_between_editions</id>
		<title>Windows Server 2025: Differences between editions</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Windows_Server_2025:_Differences_between_editions"/>
		<updated>2026-07-09T07:41:43Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;Microsoft  Windows Server 2025 is an operating system of the Windows series and the successor of  Windows Server 2022.  This article presents the differences between Windows Server 2025 editions. Pricing information on Windows Server 2025 can be found in the Thomas-Krenn online shop at &amp;lt;tklink type=sitex id=18135/&amp;gt;. For Windows Server 2025, Microsoft is now adopting the same approach it used for Window...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Microsoft [[:Category:Windows Server 2025 | Windows Server 2025]] is an operating system of the Windows series and the successor of [[:Category:Windows Server 2022 | Windows Server 2022]].&lt;br /&gt;
&lt;br /&gt;
This article presents the differences between Windows Server 2025 editions. Pricing information on Windows Server 2025 can be found in the Thomas-Krenn online shop at &amp;lt;tklink type=sitex id=18135/&amp;gt;. For Windows Server 2025, Microsoft is now adopting the same approach it used for Windows Server 2019 and Windows Server 2022, which is a &amp;#039;&amp;#039;&amp;#039;Core Licensing&amp;#039;&amp;#039;&amp;#039;. Information on this new licensing model can be found in the article [[Windows Server Core-Lizenzierung|Windows Server Core Licensing]].&lt;br /&gt;
&lt;br /&gt;
== Editions ==&lt;br /&gt;
Microsoft Windows Server 2025 is available in four different editions:&lt;br /&gt;
* Essentials&lt;br /&gt;
* Standard&lt;br /&gt;
* Datacenter&lt;br /&gt;
*Datacenter Azure Edition&lt;br /&gt;
&lt;br /&gt;
These four editions are suitable for the following application areas:&lt;br /&gt;
{| {{Prettytable}} width=&amp;quot;1000px&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! Edition|| Suitable for... || Virtualization rights || Access licenses || CPU limit &lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Essentials&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| small companies with basic IT needs; very small IT department or no IT department of their own&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| Installation: 1 physical &amp;#039;&amp;#039;&amp;#039;or&amp;#039;&amp;#039;&amp;#039; 1 virtual *&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| no CALs required (limited to 25 users / 50 devices)&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| max. 1 CPU, max. 10 cores&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Standard&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| for all companies that require extended features and virtualize to a lesser extent &lt;br /&gt;
|align=&amp;quot;center&amp;quot;| 2 virtual Windows Server machines&amp;lt;sup&amp;gt;**&amp;lt;/sup&amp;gt;&lt;br /&gt;
| rowspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; | CALs required&amp;lt;sup&amp;gt;***&amp;lt;/sup&amp;gt;&lt;br /&gt;
|align=&amp;quot;center&amp;quot; rowspan=&amp;quot;2&amp;quot;| unlimited cores&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Datacenter&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| for all companies with high IT workload needs and with a high number of virtual systems &lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | An unlimited number of virtual Windows Server machines&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;Datacenter Azure Edition&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|align=&amp;quot;center&amp;quot;| small companies with basic IT needs; very small IT department or no IT department on their own  &lt;br /&gt;
|align=&amp;quot;center&amp;quot;| 2,048 logical processors &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
:&amp;lt;sup&amp;gt;(*) The Windows Server Essentials license allows an installation of a physical and virtual Essentials Server if the physical server only provides the Hyper-V role for the virtualization of the Essentials Server.&amp;lt;ref&amp;gt;[https://www.microsoft.com/licensing/terms/productoffering/WindowsServerStandardDatacenterEssentials/OL#UseRights Windows Server Standard, Datacenter, and Essentials] (EN) (www.microsoft.com/licensing/terms)&amp;lt;/ref&amp;gt;&amp;lt;/sup&amp;gt;&lt;br /&gt;
:&amp;lt;sup&amp;gt;(**) The Windows Server Standard Edition License allows 2 OSEs (operating system environments) if all physical cores are licensed.&amp;lt;/sup&amp;gt;&lt;br /&gt;
:&amp;lt;sup&amp;gt;(***) CALs are required for every user or for every device, which accesses a server directly or indirectly. Detailed information on this topic can be found on the Microsoft website. &amp;lt;ref&amp;gt;[https://www.microsoft.com/en-us/licensing/product-licensing/client-access-license Client Access Licenses and Management Licenses] (EN) (www.microsoft.com)&amp;lt;/ref&amp;gt;&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minimum hardware requirements for Windows Server 2025 ==&lt;br /&gt;
The following table presents the official minimum requirements for Windows Server 2025.&amp;lt;ref&amp;gt;[https://learn.microsoft.com/de-de/windows-server/get-started/hardware-requirements?tabs=cpu&amp;amp;pivots=windows-server-2025 Windows Server 2025 - Hardware Requirements] (DE) (www.learn.microsoft.com)&amp;lt;/ref&amp;gt; The actual requirements are dependent on the system configuration and on the installed applications and features.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;margin: 1em 1em 1em 0; background: #f9f9f9; border: 1px #a0a0a0 solid; border-collapse: collapse; &amp;quot; rules=&amp;quot;all&amp;quot; width=&amp;quot;650px&amp;quot; cellspacing=&amp;quot;0&amp;quot; {{Prettytable}}&lt;br /&gt;
|- |- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! Description || Minimum requirements&lt;br /&gt;
|-&lt;br /&gt;
|Processor architecture || x64&lt;br /&gt;
|-&lt;br /&gt;
|Processor speed || 1,4 GHz&lt;br /&gt;
|-&lt;br /&gt;
|Storage (RAM) || 512 MB&amp;lt;sup&amp;gt;*&amp;lt;/sup&amp;gt; (recommended: ECC or similar technologies)&lt;br /&gt;
|-&lt;br /&gt;
|Hard drive storage space || 32 GB&amp;lt;sup&amp;gt;**&amp;lt;/sup&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Network card || 1x Ethernet with a minimum throughput in the 1 GBit/s-range&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
:&amp;lt;sup&amp;gt;(*) 2GB for server with &amp;quot;desktop view&amp;quot;.&amp;lt;/sup&amp;gt;&lt;br /&gt;
:&amp;lt;sup&amp;gt;(**) Computer with more than 16 GB RAM require larger storage space for paging, hibernation, and backup files.&amp;lt;/sup&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== What is new in Windows Server 2025 ==&lt;br /&gt;
In Windows Server 2022, the list of the new features is relatively short. Microsoft focuses on the new operating system Azure Stack HCI with new features. &lt;br /&gt;
&lt;br /&gt;
We can look forward to the following new features in Windows Server 2025:&amp;lt;ref&amp;gt;[https://learn.microsoft.com/de-de/windows-server/get-started/whats-new-windows-server-2025 Windows Server 2025 - News] (DE) (www.learn.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Hotpatching&lt;br /&gt;
* TLS 1.3&lt;br /&gt;
* Improved Active Directory&lt;br /&gt;
* Optimized and improved performance for virtual machines and containers&lt;br /&gt;
* Improved administration&lt;br /&gt;
&lt;br /&gt;
== Removed or not further developed features in Windows Server 2025 ==&lt;br /&gt;
In Windows Server 2025, there are few features that were not further developed or that were removed from Windows Server 2025.&lt;br /&gt;
&lt;br /&gt;
The following features will no longer be included in Windows Server 2025:&amp;lt;ref&amp;gt;[https://learn.microsoft.com/de-de/windows-server/get-started/removed-deprecated-features-windows-server-2025 Windows Server 2025 - Removed Features] (DE) (www.learn.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 * IIS 6 administration console(Web-Lgcy-Mgmt-Console)&lt;br /&gt;
* NTLMv1&lt;br /&gt;
* WordPad&lt;br /&gt;
* SMTP-Server&lt;br /&gt;
* Windows PowerShell 2.0 Engine&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{bbayer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Windows Server 2025]]&lt;br /&gt;
[[de:Windows Server 2025 Editionsunterschiede]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/How_to:_Install_Nextcloud_with_an_NFS_data_directory</id>
		<title>How to: Install Nextcloud with an NFS data directory</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/How_to:_Install_Nextcloud_with_an_NFS_data_directory"/>
		<updated>2026-07-09T07:09:37Z</updated>

		<summary type="html">&lt;p&gt;Smueller: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes how to install Nextcloud Server on Ubuntu 26.04 LTS. Apache with PHP-FPM is used as the web server, while MariaDB provides the required database.&lt;br /&gt;
&lt;br /&gt;
The actual Nextcloud user data is stored on an NFS-mounted storage system. The NFS storage is used as the primary Nextcloud data directory and is not integrated through the Nextcloud “External Storage” app.&lt;br /&gt;
&lt;br /&gt;
This guide uses the following example values:&lt;br /&gt;
&lt;br /&gt;
* Nextcloud address: &amp;lt;code&amp;gt;cloud.example.com&amp;lt;/code&amp;gt;&lt;br /&gt;
* NFS server: &amp;lt;code&amp;gt;nfs.example.com&amp;lt;/code&amp;gt;&lt;br /&gt;
* NFS export: &amp;lt;code&amp;gt;/nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Local NFS mount point: &amp;lt;code&amp;gt;/srv/nextcloud-data&amp;lt;/code&amp;gt;&lt;br /&gt;
* Nextcloud directory: &amp;lt;code&amp;gt;/var/www/nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database name: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database user: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Adjust these values to match your environment.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; In this setup, the NFS storage is part of the primary Nextcloud storage. If the NFS server is unavailable, the Nextcloud data directory will also be unavailable.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
The following components are required for this guide:&lt;br /&gt;
&lt;br /&gt;
* Ubuntu Server 26.04 LTS, 64-bit&lt;br /&gt;
* Apache 2.4&lt;br /&gt;
* PHP 8.5 with PHP-FPM&lt;br /&gt;
* MariaDB 11.8&lt;br /&gt;
* Redis&lt;br /&gt;
* An accessible NFSv4 export&lt;br /&gt;
* A DNS record for the Nextcloud domain&lt;br /&gt;
* TCP ports 80 and 443 must be reachable&lt;br /&gt;
&lt;br /&gt;
For a small installation, the following resources can be used as an example:&lt;br /&gt;
&lt;br /&gt;
* 4 vCPUs&lt;br /&gt;
* 4 GiB RAM&lt;br /&gt;
* At least 20 GiB of local storage for the operating system, Nextcloud application, database and logs&lt;br /&gt;
* Separate storage for the Nextcloud data directory&lt;br /&gt;
&lt;br /&gt;
The actual resource requirements depend on factors such as the number of users, installed apps, number of files and concurrent access.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important:&amp;#039;&amp;#039;&amp;#039; NFS storage does not replace a backup. A complete backup must include at least the Nextcloud data directory, the MariaDB database and the Nextcloud configuration.&lt;br /&gt;
&lt;br /&gt;
== Preparing the system ==&lt;br /&gt;
&lt;br /&gt;
The following commands are executed as the &amp;lt;code&amp;gt;root&amp;lt;/code&amp;gt; user.&lt;br /&gt;
&lt;br /&gt;
First update the operating system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
apt full-upgrade -y&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a new kernel was installed, restart the system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
reboot&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then verify the installed Ubuntu version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat /etc/os-release&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should contain the following information, among other values:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
VERSION_ID=&amp;quot;26.04&amp;quot;&lt;br /&gt;
VERSION_CODENAME=resolute&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Installing the required packages ==&lt;br /&gt;
&lt;br /&gt;
Install Apache, MariaDB, PHP 8.5, Redis and the required PHP extensions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt install -y \&lt;br /&gt;
    apache2 \&lt;br /&gt;
    mariadb-server \&lt;br /&gt;
    php8.5-fpm \&lt;br /&gt;
    php8.5-cli \&lt;br /&gt;
    php8.5-common \&lt;br /&gt;
    php8.5-curl \&lt;br /&gt;
    php8.5-gd \&lt;br /&gt;
    php8.5-gmp \&lt;br /&gt;
    php8.5-imagick \&lt;br /&gt;
    php8.5-intl \&lt;br /&gt;
    php8.5-mbstring \&lt;br /&gt;
    php8.5-mysql \&lt;br /&gt;
    php8.5-xml \&lt;br /&gt;
    php8.5-zip \&lt;br /&gt;
    php8.5-bcmath \&lt;br /&gt;
    php8.5-bz2 \&lt;br /&gt;
    php8.5-apcu \&lt;br /&gt;
    php8.5-redis \&lt;br /&gt;
    redis-server \&lt;br /&gt;
    nfs-common \&lt;br /&gt;
    cron \&lt;br /&gt;
    bzip2 \&lt;br /&gt;
    wget&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable and start the required services:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl enable --now \&lt;br /&gt;
    apache2 \&lt;br /&gt;
    mariadb \&lt;br /&gt;
    php8.5-fpm \&lt;br /&gt;
    redis-server \&lt;br /&gt;
    cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the installed PHP version:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 --version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should begin with &amp;lt;code&amp;gt;PHP 8.5&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The loaded PHP modules can be checked with the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 -m&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following modules should be present, among others:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apcu&lt;br /&gt;
curl&lt;br /&gt;
dom&lt;br /&gt;
fileinfo&lt;br /&gt;
gd&lt;br /&gt;
gmp&lt;br /&gt;
imagick&lt;br /&gt;
intl&lt;br /&gt;
mbstring&lt;br /&gt;
mysqli&lt;br /&gt;
openssl&lt;br /&gt;
pdo_mysql&lt;br /&gt;
redis&lt;br /&gt;
SimpleXML&lt;br /&gt;
xml&lt;br /&gt;
xmlreader&lt;br /&gt;
xmlwriter&lt;br /&gt;
zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring PHP 8.5 ==&lt;br /&gt;
&lt;br /&gt;
Nextcloud requires suitable PHP settings for both PHP-FPM and command-line PHP calls.&lt;br /&gt;
&lt;br /&gt;
=== Configuring PHP-FPM ===&lt;br /&gt;
&lt;br /&gt;
Create a dedicated PHP configuration file for Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/php/8.5/fpm/conf.d/99-nextcloud.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
memory_limit = 512M&lt;br /&gt;
upload_max_filesize = 10G&lt;br /&gt;
post_max_size = 10G&lt;br /&gt;
max_execution_time = 3600&lt;br /&gt;
max_input_time = 3600&lt;br /&gt;
output_buffering = 0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The values for &amp;lt;code&amp;gt;upload_max_filesize&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;post_max_size&amp;lt;/code&amp;gt; determine the maximum file size that can be uploaded through the web interface. Adjust these values to suit your environment if required.&lt;br /&gt;
&lt;br /&gt;
=== Configuring PHP CLI ===&lt;br /&gt;
&lt;br /&gt;
The PHP command-line interface is used for cron jobs, maintenance tasks and the Nextcloud updater.&lt;br /&gt;
&lt;br /&gt;
Create the following configuration file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/php/8.5/cli/conf.d/99-nextcloud.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
memory_limit = 512M&lt;br /&gt;
apc.enable_cli = 1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 --ini&lt;br /&gt;
php8.5 -i | grep -E &amp;#039;memory_limit|apc.enable_cli&amp;#039;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart PHP-FPM:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the service status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Setting up the NFS data directory ==&lt;br /&gt;
&lt;br /&gt;
=== Creating the mount point ===&lt;br /&gt;
&lt;br /&gt;
Create the local mount point:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkdir -p /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuring the NFS mount ===&lt;br /&gt;
&lt;br /&gt;
Add the following line to &amp;lt;code&amp;gt;/etc/fstab&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nfs.example.com:/nextcloud /srv/nextcloud-data nfs4 rw,hard,_netdev,x-systemd.automount 0 0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Adjust the NFS server and export path to match your environment.&lt;br /&gt;
&lt;br /&gt;
Reload the systemd configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl daemon-reload&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Access the mount point to trigger the automatic mount:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ls -la /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, the mount can be triggered manually:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mount /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify that the NFS file system has been mounted:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
findmnt /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
TARGET                  SOURCE                         FSTYPE OPTIONS&lt;br /&gt;
/srv/nextcloud-data     nfs.example.com:/nextcloud    nfs4   rw,relatime,...&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Only continue with the installation if &amp;lt;code&amp;gt;/srv/nextcloud-data&amp;lt;/code&amp;gt; is actually mounted as an NFS file system.&lt;br /&gt;
&lt;br /&gt;
=== Setting permissions ===&lt;br /&gt;
&lt;br /&gt;
Apache and PHP-FPM run as the &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt; user by default on Ubuntu.&lt;br /&gt;
&lt;br /&gt;
Check its UID and GID:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
id www-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
By default, Ubuntu uses UID and GID &amp;lt;code&amp;gt;33&amp;lt;/code&amp;gt; for &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
The NFS directory must allow the &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt; user to write to it. If NFS &amp;lt;code&amp;gt;root_squash&amp;lt;/code&amp;gt; is enabled, ownership usually cannot be changed from the Nextcloud server. In this case, set the permissions directly on the NFS server.&lt;br /&gt;
&lt;br /&gt;
Example on the NFS server:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chown -R 33:33 /path/to/export/nextcloud&lt;br /&gt;
chmod 0750 /path/to/export/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then perform a write test on the Nextcloud server as the &amp;lt;code&amp;gt;www-data&amp;lt;/code&amp;gt; user:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data touch /srv/nextcloud-data/.write-test&lt;br /&gt;
sudo -u www-data rm /srv/nextcloud-data/.write-test&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If this test fails, correct the NFS export settings, UID/GID mapping or file system permissions before continuing.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The data directory should be used exclusively by Nextcloud. Files should not be modified directly on the NFS share in parallel.&lt;br /&gt;
&lt;br /&gt;
=== Making Apache and PHP-FPM depend on the NFS mount ===&lt;br /&gt;
&lt;br /&gt;
To prevent the relevant services from starting without the data directory being available, systemd dependencies can be configured.&lt;br /&gt;
&lt;br /&gt;
First create a dependency for Apache:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl edit apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[Unit]&lt;br /&gt;
RequiresMountsFor=/srv/nextcloud-data&lt;br /&gt;
Wants=network-online.target&lt;br /&gt;
After=network-online.target&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then create the corresponding dependency for PHP-FPM:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl edit php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration there as well:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[Unit]&lt;br /&gt;
RequiresMountsFor=/srv/nextcloud-data&lt;br /&gt;
Wants=network-online.target&lt;br /&gt;
After=network-online.target&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Reload the systemd configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl daemon-reload&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the configured dependencies:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl cat apache2&lt;br /&gt;
systemctl cat php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring MariaDB ==&lt;br /&gt;
&lt;br /&gt;
=== Setting the transaction isolation level ===&lt;br /&gt;
&lt;br /&gt;
Nextcloud requires the &amp;lt;code&amp;gt;READ-COMMITTED&amp;lt;/code&amp;gt; transaction isolation level for MySQL or MariaDB.&lt;br /&gt;
&lt;br /&gt;
Create the following configuration file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/mysql/mariadb.conf.d/99-nextcloud.cnf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[mysqld]&lt;br /&gt;
transaction-isolation = READ-COMMITTED&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If MariaDB binary logging is enabled, the &amp;lt;code&amp;gt;ROW&amp;lt;/code&amp;gt; format must also be used:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[mysqld]&lt;br /&gt;
transaction-isolation = READ-COMMITTED&lt;br /&gt;
binlog_format = ROW&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart MariaDB:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart mariadb&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the configured transaction isolation level:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mariadb -e &amp;quot;SHOW VARIABLES LIKE &amp;#039;transaction_isolation&amp;#039;;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should contain the following value:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
READ-COMMITTED&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Creating the database and user ===&lt;br /&gt;
&lt;br /&gt;
Open the MariaDB console:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mariadb&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Create the database and a database user that can only connect locally:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CREATE DATABASE nextcloud&lt;br /&gt;
    CHARACTER SET utf8mb4&lt;br /&gt;
    COLLATE utf8mb4_general_ci;&lt;br /&gt;
&lt;br /&gt;
CREATE USER &amp;#039;nextcloud&amp;#039;@&amp;#039;localhost&amp;#039;&lt;br /&gt;
    IDENTIFIED BY &amp;#039;SECURE-DATABASE-PASSWORD&amp;#039;;&lt;br /&gt;
&lt;br /&gt;
GRANT ALL PRIVILEGES&lt;br /&gt;
    ON nextcloud.*&lt;br /&gt;
    TO &amp;#039;nextcloud&amp;#039;@&amp;#039;localhost&amp;#039;;&lt;br /&gt;
&lt;br /&gt;
FLUSH PRIVILEGES;&lt;br /&gt;
EXIT;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Replace &amp;lt;code&amp;gt;SECURE-DATABASE-PASSWORD&amp;lt;/code&amp;gt; with a long, random password used exclusively for this database.&lt;br /&gt;
&lt;br /&gt;
Because MariaDB and Nextcloud are installed on the same server, the user is deliberately restricted to &amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Test the login:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mariadb -u nextcloud -p -h localhost nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exit the MariaDB console afterwards:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
EXIT;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Installing Nextcloud ==&lt;br /&gt;
&lt;br /&gt;
At the time this article was created, Nextcloud &amp;lt;code&amp;gt;34.0.1&amp;lt;/code&amp;gt; was the current stable version.&lt;br /&gt;
&lt;br /&gt;
Before performing a later installation, check whether a newer version is available within the supported Nextcloud release branch.&lt;br /&gt;
&lt;br /&gt;
Download the Nextcloud archive and the corresponding SHA-256 checksum:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cd /tmp&lt;br /&gt;
&lt;br /&gt;
NEXTCLOUD_VERSION=&amp;quot;34.0.1&amp;quot;&lt;br /&gt;
&lt;br /&gt;
wget https://download.nextcloud.com/server/releases/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2&lt;br /&gt;
wget https://download.nextcloud.com/server/releases/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2.sha256&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the integrity of the archive:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sha256sum -c nextcloud-${NEXTCLOUD_VERSION}.tar.bz2.sha256&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output must contain &amp;lt;code&amp;gt;OK&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nextcloud-34.0.1.tar.bz2: OK&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Extract Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tar -xjf nextcloud-${NEXTCLOUD_VERSION}.tar.bz2&lt;br /&gt;
mv nextcloud /var/www/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set the owner:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chown -R www-data:www-data /var/www/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the permissions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ls -ld /var/www/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After a successful installation, the downloaded archive files can optionally be removed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
rm -f /tmp/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2&lt;br /&gt;
rm -f /tmp/nextcloud-${NEXTCLOUD_VERSION}.tar.bz2.sha256&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring Apache with PHP-FPM ==&lt;br /&gt;
&lt;br /&gt;
This guide uses a dedicated subdomain for Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cloud.example.com&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable the required Apache modules:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2enmod \&lt;br /&gt;
    proxy_fcgi \&lt;br /&gt;
    setenvif \&lt;br /&gt;
    rewrite \&lt;br /&gt;
    headers \&lt;br /&gt;
    env \&lt;br /&gt;
    dir \&lt;br /&gt;
    mime \&lt;br /&gt;
    ssl \&lt;br /&gt;
    http2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable the PHP 8.5 FPM configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2enconf php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Create the Apache configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/apache2/sites-available/nextcloud.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;VirtualHost *:80&amp;gt;&lt;br /&gt;
    ServerName cloud.example.com&lt;br /&gt;
    DocumentRoot /var/www/nextcloud&lt;br /&gt;
&lt;br /&gt;
    &amp;lt;Directory /var/www/nextcloud/&amp;gt;&lt;br /&gt;
        Require all granted&lt;br /&gt;
        AllowOverride All&lt;br /&gt;
        Options FollowSymLinks&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;IfModule mod_dav.c&amp;gt;&lt;br /&gt;
            Dav off&lt;br /&gt;
        &amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        SetEnv HOME /var/www/nextcloud&lt;br /&gt;
        SetEnv HTTP_HOME /var/www/nextcloud&lt;br /&gt;
    &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&lt;br /&gt;
    ErrorLog ${APACHE_LOG_DIR}/nextcloud-error.log&lt;br /&gt;
    CustomLog ${APACHE_LOG_DIR}/nextcloud-access.log combined&lt;br /&gt;
&amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Replace &amp;lt;code&amp;gt;cloud.example.com&amp;lt;/code&amp;gt; with the actual DNS name of the Nextcloud installation.&lt;br /&gt;
&lt;br /&gt;
Enable the Nextcloud site:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2ensite nextcloud.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the default Apache site is no longer required, it can be disabled:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
a2dissite 000-default.conf&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Apache configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apache2ctl configtest&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the configuration is valid, the following output is displayed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Syntax OK&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart Apache and PHP-FPM:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart php8.5-fpm&lt;br /&gt;
systemctl restart apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check both services:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
systemctl status apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring the firewall ==&lt;br /&gt;
&lt;br /&gt;
This step is only required if UFW is used on the server.&lt;br /&gt;
&lt;br /&gt;
Before making changes, ensure that SSH remains allowed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ufw allow OpenSSH&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Allow HTTP and HTTPS:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ufw allow &amp;#039;Apache Full&amp;#039;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the rules:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ufw status&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To                         Action      From&lt;br /&gt;
--                         ------      ----&lt;br /&gt;
OpenSSH                    ALLOW       Anywhere&lt;br /&gt;
Apache Full                ALLOW       Anywhere&lt;br /&gt;
OpenSSH (v6)               ALLOW       Anywhere (v6)&lt;br /&gt;
Apache Full (v6)           ALLOW       Anywhere (v6)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Setting up HTTPS ==&lt;br /&gt;
&lt;br /&gt;
Nextcloud should only be accessible over HTTPS on production systems.&lt;br /&gt;
&lt;br /&gt;
The following requirements apply for a publicly trusted certificate:&lt;br /&gt;
&lt;br /&gt;
* The domain points to the Nextcloud server.&lt;br /&gt;
* TCP port 80 is reachable for certificate validation.&lt;br /&gt;
* TCP port 443 is reachable for subsequent HTTPS access.&lt;br /&gt;
&lt;br /&gt;
Install Certbot and the Apache plugin:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt install -y certbot python3-certbot-apache&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Request the certificate:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
certbot --apache --redirect -d cloud.example.com&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Certbot configures the certificate and redirects HTTP requests to HTTPS.&lt;br /&gt;
&lt;br /&gt;
Test automatic certificate renewal:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
certbot renew --dry-run&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Certbot timer:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status certbot.timer&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If a reverse proxy or load balancer is already placed in front of Nextcloud, TLS termination can alternatively take place there. In that case, the Nextcloud settings for trusted proxies and forwarded headers must also be configured correctly.&lt;br /&gt;
&lt;br /&gt;
Self-signed certificates should only be used in isolated internal environments where the certificate can be added as trusted on all clients.&lt;br /&gt;
&lt;br /&gt;
== Completing the installation in the browser ==&lt;br /&gt;
&lt;br /&gt;
Open the Nextcloud domain in a browser:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
https://cloud.example.com/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enter the following information in the installation dialog.&lt;br /&gt;
&lt;br /&gt;
=== Administrator account ===&lt;br /&gt;
&lt;br /&gt;
Create an administrator account with a secure password used exclusively for Nextcloud.&lt;br /&gt;
&lt;br /&gt;
=== Data directory ===&lt;br /&gt;
&lt;br /&gt;
Use the following path as the data directory:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Database ===&lt;br /&gt;
&lt;br /&gt;
Select MariaDB or MySQL and use the following values:&lt;br /&gt;
&lt;br /&gt;
* Database user: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database password: the password defined previously&lt;br /&gt;
* Database name: &amp;lt;code&amp;gt;nextcloud&amp;lt;/code&amp;gt;&lt;br /&gt;
* Database host: &amp;lt;code&amp;gt;localhost&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then start the installation.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:003-Admin-Erstellen.png|Create an administrator account with a secure password.&lt;br /&gt;
File:004-Speicherort-Festlegen.png|Use the previously mounted NFS share as the data directory.&lt;br /&gt;
File:Datenbank-hinzufügen.png|Enter the credentials for the local MariaDB database.&lt;br /&gt;
File:006-Finish.png|After a successful installation, the Nextcloud dashboard is displayed.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuring background jobs ==&lt;br /&gt;
&lt;br /&gt;
Nextcloud requires background jobs to be executed regularly. Cron should be used for server installations.&lt;br /&gt;
&lt;br /&gt;
Create the following cron file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/cron.d/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
*/5 * * * * www-data /usr/bin/php8.5 -f /var/www/nextcloud/cron.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Set the correct file permissions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chmod 0644 /etc/cron.d/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable cron mode in Nextcloud:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ background:cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart the cron service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the entry:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat /etc/cron.d/nextcloud&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test the cron job manually once:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 -f /var/www/nextcloud/cron.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The status of the background jobs can later be checked in Nextcloud under “Administration settings” → “Basic settings”.&lt;br /&gt;
&lt;br /&gt;
== Configuring APCu and Redis ==&lt;br /&gt;
&lt;br /&gt;
APCu is used for the local application cache. Redis handles transactional file locking and can also be used as a distributed cache.&lt;br /&gt;
&lt;br /&gt;
Open the Nextcloud configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /var/www/nextcloud/config/config.php&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following entries inside the &amp;lt;code&amp;gt;$CONFIG&amp;lt;/code&amp;gt; array:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;#039;memcache.local&amp;#039; =&amp;gt; &amp;#039;\OC\Memcache\APCu&amp;#039;,&lt;br /&gt;
&amp;#039;memcache.distributed&amp;#039; =&amp;gt; &amp;#039;\OC\Memcache\Redis&amp;#039;,&lt;br /&gt;
&amp;#039;memcache.locking&amp;#039; =&amp;gt; &amp;#039;\OC\Memcache\Redis&amp;#039;,&lt;br /&gt;
&lt;br /&gt;
&amp;#039;redis&amp;#039; =&amp;gt; [&lt;br /&gt;
    &amp;#039;host&amp;#039; =&amp;gt; &amp;#039;127.0.0.1&amp;#039;,&lt;br /&gt;
    &amp;#039;port&amp;#039; =&amp;gt; 6379,&lt;br /&gt;
    &amp;#039;timeout&amp;#039; =&amp;gt; 0.0,&lt;br /&gt;
],&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ensure that all entries are placed inside the existing &amp;lt;code&amp;gt;$CONFIG&amp;lt;/code&amp;gt; array and that preceding entries are separated correctly with commas.&lt;br /&gt;
&lt;br /&gt;
Restart PHP-FPM and Apache:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl restart php8.5-fpm&lt;br /&gt;
systemctl restart apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Redis service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status redis-server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Test the connection:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
redis-cli ping&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The expected response is:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
PONG&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Enabling pretty URLs ==&lt;br /&gt;
&lt;br /&gt;
Pretty URLs remove the &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt; component from Nextcloud URLs.&lt;br /&gt;
&lt;br /&gt;
First set the complete Nextcloud URL:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set overwrite.cli.url \&lt;br /&gt;
    --value=&amp;quot;https://cloud.example.com&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Then set the rewrite base:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set htaccess.RewriteBase \&lt;br /&gt;
    --value=&amp;quot;/&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Update the Nextcloud &amp;lt;code&amp;gt;.htaccess&amp;lt;/code&amp;gt; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 \&lt;br /&gt;
    /var/www/nextcloud/occ maintenance:update:htaccess&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Reload Apache:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl reload apache2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nextcloud URLs should now be displayed without &amp;lt;code&amp;gt;index.php&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Verifying the installation ==&lt;br /&gt;
&lt;br /&gt;
First check the Nextcloud status:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ status&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A successful installation returns information similar to the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
installed: true&lt;br /&gt;
maintenance: false&lt;br /&gt;
needsDbUpgrade: false&lt;br /&gt;
version: 34.0.1.0&lt;br /&gt;
versionstring: 34.0.1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Also check the relevant services:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status apache2&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
systemctl status mariadb&lt;br /&gt;
systemctl status redis-server&lt;br /&gt;
systemctl status cron&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the NFS mount again:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
findmnt /srv/nextcloud-data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify that Nextcloud can still write to the data directory:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data touch /srv/nextcloud-data/.write-test&lt;br /&gt;
sudo -u www-data rm /srv/nextcloud-data/.write-test&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Check the Nextcloud configuration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 \&lt;br /&gt;
    /var/www/nextcloud/occ config:list system&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Finally, open “Administration settings” → “Overview” in Nextcloud. Missing PHP modules, cache issues, failed background jobs and other configuration problems are displayed there.&lt;br /&gt;
&lt;br /&gt;
== Optional configurations ==&lt;br /&gt;
&lt;br /&gt;
=== Setting the default phone region ===&lt;br /&gt;
&lt;br /&gt;
If phone numbers without an international country code are used in Nextcloud, a default region can be configured.&lt;br /&gt;
&lt;br /&gt;
For Germany, use:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set default_phone_region \&lt;br /&gt;
    --value=&amp;quot;DE&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuring the maintenance window ===&lt;br /&gt;
&lt;br /&gt;
Nextcloud can run resource-intensive daily background jobs preferentially during a maintenance window.&lt;br /&gt;
&lt;br /&gt;
The following example sets the start of the maintenance window to 01:00 UTC:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ \&lt;br /&gt;
    config:system:set maintenance_window_start \&lt;br /&gt;
    --type=integer \&lt;br /&gt;
    --value=1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Running available repairs ===&lt;br /&gt;
&lt;br /&gt;
After updates or configuration changes, the Nextcloud repair routines can be executed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 \&lt;br /&gt;
    /var/www/nextcloud/occ maintenance:repair&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Operational notes ==&lt;br /&gt;
&lt;br /&gt;
At least the following points should be considered for ongoing operation:&lt;br /&gt;
&lt;br /&gt;
* Install security updates regularly&lt;br /&gt;
* Update Nextcloud and installed apps regularly&lt;br /&gt;
* Back up the MariaDB database&lt;br /&gt;
* Back up the NFS data directory&lt;br /&gt;
* Back up &amp;lt;code&amp;gt;/var/www/nextcloud/config&amp;lt;/code&amp;gt;&lt;br /&gt;
* Monitor NFS availability&lt;br /&gt;
* Monitor local disk space&lt;br /&gt;
* Monitor Apache, PHP-FPM, MariaDB and Redis&lt;br /&gt;
* Check the Nextcloud administration overview regularly&lt;br /&gt;
* Check background jobs regularly&lt;br /&gt;
* Test restoring from existing backups&lt;br /&gt;
&lt;br /&gt;
Relevant log files include:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/var/log/apache2/nextcloud-error.log&lt;br /&gt;
/var/log/apache2/nextcloud-access.log&lt;br /&gt;
/var/log/php8.5-fpm.log&lt;br /&gt;
/srv/nextcloud-data/nextcloud.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The systemd logs can also be displayed with the following commands:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
journalctl -u apache2&lt;br /&gt;
journalctl -u php8.5-fpm&lt;br /&gt;
journalctl -u mariadb&lt;br /&gt;
journalctl -u redis-server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Displaying the Nextcloud version ===&lt;br /&gt;
&lt;br /&gt;
The currently installed Nextcloud version can be checked at any time:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo -u www-data php8.5 /var/www/nextcloud/occ status&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Displaying the PHP version ===&lt;br /&gt;
&lt;br /&gt;
The command-line PHP version can be checked as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
php8.5 --version&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The PHP-FPM version used by Apache can be checked through the service:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl status php8.5-fpm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Smueller}}&lt;br /&gt;
[[Category:Server Software]]&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Nextcloud Installation mit NFS-Mount (HowTo)]]&lt;/div&gt;</summary>
		<author><name>Smueller</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Linux_network_analysis_with_traceroute</id>
		<title>Linux network analysis with traceroute</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Linux_network_analysis_with_traceroute"/>
		<updated>2026-07-08T11:45:40Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Linux tool &amp;#039;&amp;#039;&amp;#039;traceroute&amp;#039;&amp;#039;&amp;#039; provides a lot of possibilities to trace the path of network packets through a network or the Internet to a specific host. This article provides an overview of the function of [http://de.wikipedia.org/wiki/Traceroute traceroute]. Furthermore, we present interesting option parameters for traceroute. In addition to traceroute, [[Linux Netzwerk Analyse mit mtr|mtr]] is also interesting. It combines the functionality of traceroute and ping. &lt;br /&gt;
&lt;br /&gt;
== Function == &lt;br /&gt;
&lt;br /&gt;
Traceroute traces the path of network packets to a specific host. To do this, traceroute modifies the time-to-live (TTL) field of the IP protocol. By using small TTL values, traceroute attempts to elicit ICMP TIME_EXCEEDED responses from the individual routers. The only required parameter for traceroute is the host to which the path is to be traced.&lt;br /&gt;
&lt;br /&gt;
To identify the individual hops (routers) along the path from the current computer to the desired host, traceroute proceeds as follows:&lt;br /&gt;
# First, it sends an IP packet with TTL=1. As a result, the first router (the default gateway) discards the packet and sends back an ICMP TIME_EXCEEDED response.&lt;br /&gt;
# Now traceroute sends additional packets, incrementing the TTL by 1 each time. With the second packet (TTL=2), the packet first passes through the default gateway to the next router on the path to the host. Since the default gateway decrements the TTL by 1 when forwarding the packet, the packet arrives at the second router with a TTL of 1. This router discards the packet and sends an ICMP TIME_EXCEEDED response back to the original computer. The process works similarly with TTL=3 at the third router, TTL=4 at the fourth router, and so on.&lt;br /&gt;
# If an IP packet with a sufficiently high TTL eventually reaches the destination host, the host responds with an ICMP &amp;quot;port unreachable&amp;quot; message.&lt;br /&gt;
&lt;br /&gt;
== Methods of testing packets == &lt;br /&gt;
&lt;br /&gt;
For the IP test packets sent, different protocols can be used. These options allow you to send test packets even with restrictive firewall configurations. In addition, this method lets you track the exact path used by a specific protocol (in case packets are routed differently depending on the protocol at some point along the path).&lt;br /&gt;
&lt;br /&gt;
=== UDP (default) ===&lt;br /&gt;
&lt;br /&gt;
In the default configuration, UDP datagrams are used as IP test packets. An &amp;#039;unlikely&amp;#039; port is used for this purpose. The starting port is set to 33434 and is incremented by 1 for each subsequent test packet.&lt;br /&gt;
&lt;br /&gt;
This method can be used by any user and does not require root rights.&lt;br /&gt;
&lt;br /&gt;
Example (the first three hops were anonymized):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@tpw ~]# traceroute www.google.com&lt;br /&gt;
traceroute to www.google.com (209.85.129.147), 30 hops max, 60 byte packets&lt;br /&gt;
 1  XXX (XXX)  1.929 ms  1.982 ms  2.141 ms&lt;br /&gt;
 2  XXX (XXX)  3.795 ms  3.769 ms  3.751 ms&lt;br /&gt;
 3  XXX (XXX)  5.673 ms  5.650 ms  5.634 ms&lt;br /&gt;
 4  iix12-aux11.highway.telekom.at (195.3.70.206)  21.027 ms 195.3.118.50 (195.3.118.50)  21.025 ms  21.328 ms&lt;br /&gt;
 5  72.14.198.241 (72.14.198.241)  21.436 ms  21.406 ms  21.401 ms&lt;br /&gt;
 6  209.85.255.176 (209.85.255.176)  21.497 ms 209.85.255.178 (209.85.255.178)  23.380 ms  23.300 ms&lt;br /&gt;
 7  72.14.232.165 (72.14.232.165)  23.301 ms  21.613 ms 72.14.232.201 (72.14.232.201)  21.661 ms&lt;br /&gt;
 8  72.14.239.170 (72.14.239.170)  21.678 ms 72.14.233.210 (72.14.233.210)  34.381 ms  34.365 ms&lt;br /&gt;
 9  fk-in-f147.1e100.net (209.85.129.147)  19.659 ms  19.280 ms  19.291 ms&lt;br /&gt;
[root@tpw ~]# &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== ICMP (-I) ===&lt;br /&gt;
&lt;br /&gt;
This method uses ICMP echo requests (&amp;#039;Ping&amp;#039;) for testing.&lt;br /&gt;
&lt;br /&gt;
This method requires superuser-rights.&lt;br /&gt;
&lt;br /&gt;
Example (the first three hops were anonymized):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@tpw ~]# traceroute -I www.google.com&lt;br /&gt;
traceroute to www.google.com (209.85.129.147), 30 hops max, 60 byte packets&lt;br /&gt;
 1  XXX (XXX)  1.948 ms  2.022 ms  2.202 ms&lt;br /&gt;
 2  XXX (XXX)  3.915 ms  3.918 ms  3.929 ms&lt;br /&gt;
 3  XXX (XXX)  5.870 ms  5.876 ms  5.889 ms&lt;br /&gt;
 4  iix12-aux11.highway.telekom.at (195.3.70.206)  17.967 ms  19.781 ms  19.784 ms&lt;br /&gt;
 5  72.14.198.241 (72.14.198.241)  19.869 ms  19.867 ms  19.915 ms&lt;br /&gt;
 6  209.85.255.178 (209.85.255.178)  20.044 ms  19.502 ms  19.470 ms&lt;br /&gt;
 7  72.14.232.201 (72.14.232.201)  19.529 ms  19.523 ms 72.14.232.203 (72.14.232.203)  19.532 ms&lt;br /&gt;
 8  72.14.233.210 (72.14.233.210)  27.065 ms  34.198 ms  34.165 ms&lt;br /&gt;
 9  fk-in-f147.1e100.net (209.85.129.147)  18.249 ms  19.352 ms  17.936 ms&lt;br /&gt;
[root@tpw ~]# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== TCP (-T) ===&lt;br /&gt;
&lt;br /&gt;
This method uses a fix TCP port (port 80 is default). With the option -p, another destination port can be also selected (for example -p 25  to check the path to a mail server). This also allows you to get past firewalls that do not let through UDP datagrams or ICMP messages, for example.&lt;br /&gt;
&lt;br /&gt;
This method uses the &amp;quot;half-open technique&amp;quot;. This means that the target applications (for example a web server if the test packets are sent to port 80) do not see the test packets. Normally, a TCP SYN packet is simply sent. If no application is listening on that port on the target host, a TCP RESET is simply returned. However, if an application is listening on that port on the destination host, the destination host sends back a TCP SYN+ACK. Traceroute then responds with a TCP RESET (instead of accepting the connection with a TCP ACK). In this way, the TCP session is discarded without the application on the destination host noticing anything.&lt;br /&gt;
&lt;br /&gt;
This method requires superuser-rights.&lt;br /&gt;
&lt;br /&gt;
Example (the first three hops were anonymized):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@tpw ~]# traceroute -T -p 80 www.google.com&lt;br /&gt;
traceroute to www.google.com (209.85.129.147), 30 hops max, 60 byte packets&lt;br /&gt;
 1  XXX (XXX)  3.187 ms  3.165 ms  3.142 ms&lt;br /&gt;
 2  XXX (XXX)  4.502 ms  4.486 ms  4.478 ms&lt;br /&gt;
 3  XXX (XXX)  6.409 ms  6.394 ms  6.365 ms&lt;br /&gt;
 4  195.3.118.50 (195.3.118.50)  22.834 ms  22.828 ms iix12-aux11.highway.telekom.at (195.3.70.206)  22.822 ms&lt;br /&gt;
 5  72.14.198.241 (72.14.198.241)  22.848 ms  22.827 ms  22.803 ms&lt;br /&gt;
 6  209.85.255.178 (209.85.255.178)  22.822 ms 209.85.255.176 (209.85.255.176)  20.884 ms 209.85.255.178 (209.85.255.178)  20.880 ms&lt;br /&gt;
 7  72.14.232.165 (72.14.232.165)  20.916 ms  19.753 ms 72.14.232.203 (72.14.232.203)  19.744 ms&lt;br /&gt;
 8  72.14.233.210 (72.14.233.210)  33.508 ms 72.14.233.206 (72.14.233.206)  21.713 ms  21.655 ms&lt;br /&gt;
 9  * * *&lt;br /&gt;
10  * * *&lt;br /&gt;
11  * * *&lt;br /&gt;
12  * * *&lt;br /&gt;
13  * * *&lt;br /&gt;
14  * * *&lt;br /&gt;
15  fk-in-f147.1e100.net (209.85.129.147)  19.678 ms  19.715 ms  19.728 ms&lt;br /&gt;
[root@tpw ~]#&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== UDP (-U) ===&lt;br /&gt;
&lt;br /&gt;
This method uses a fix UDP port (port 53 is default). It is also used to bypass firewalls.&lt;br /&gt;
&lt;br /&gt;
Unlike the TCP method, an application on the destination host receives these UDP datagrams if it is listening on the corresponding port. This can confuse the application in question. In most cases, the application will not send a response (so traceroute does not see a final hop in the trace).&lt;br /&gt;
&lt;br /&gt;
This method can be used by any user and does not require root rights).&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* Manpage of traceroute&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Networking]][[Category:Linux Performance]]&lt;br /&gt;
[[pl:Analiza sieci w Linuksie z traceroute]]&lt;br /&gt;
[[de:Linux Netzwerk Analyse mit traceroute]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/How_to_set_up_VLAN_in_OPNsense</id>
		<title>How to set up VLAN in OPNsense</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/How_to_set_up_VLAN_in_OPNsense"/>
		<updated>2026-07-08T08:03:12Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Virtual Local Area Networks&amp;#039;&amp;#039;&amp;#039; -  VLANs - are an important tool for the network infrastructure, particularly in environments with firewall solutions such as OPNsense. They allow to divide a physical network into multiple logical networks, which improves security and organization. This article describes how to set up VLANs in OPNsense 25.1.  == Assign VLAN == First, a &amp;#039;&amp;#039;&amp;#039;VLAN-ID between 1 and 4094&amp;#039;&amp;#039;&amp;#039; is assigned to an interface. The ID 4095 is reser...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Virtual Local Area Networks&amp;#039;&amp;#039;&amp;#039; -  [[VLAN Basics|VLANs]] - are an important tool for the network infrastructure, particularly in environments with firewall solutions such as [[OPNsense]]. They allow to divide a physical network into multiple logical networks, which improves security and organization. This article describes how to set up VLANs in OPNsense 25.1.&lt;br /&gt;
&lt;br /&gt;
== Assign VLAN ==&lt;br /&gt;
First, a &amp;#039;&amp;#039;&amp;#039;VLAN-ID between 1 and 4094&amp;#039;&amp;#039;&amp;#039; is assigned to an interface. The ID 4095 is reserved, as in all VLAN networks.&amp;lt;ref name=IEEE802.1Q&amp;gt;[http://www.microhowto.info/tutorials/802.1q.html#idp28880 IEEE 802.1Q VLAN] &amp;lt;cite&amp;gt;&amp;quot;Each 802.1Q VLAN is identified by a 12-bit integer called a VID (VLAN Identifier) in the range 1 to 4094 inclusive. The values 0 and 4095 are reserved and should not be used.&amp;quot;&amp;lt;/cite&amp;gt;&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-001.png|Go to &amp;#039;&amp;#039;&amp;#039;Interfaces ‣ Devices ‣ VLAN&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-002.png|Here, click on the &amp;#039;&amp;#039;&amp;#039;+&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-003.png|Assign the desired &amp;#039;&amp;#039;&amp;#039;Interface&amp;#039;&amp;#039;&amp;#039; as well as the &amp;#039;&amp;#039;&amp;#039;VLAN-ID&amp;#039;&amp;#039;&amp;#039;, in this example &amp;#039;&amp;#039;&amp;#039;10&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-004.png|Click on &amp;#039;&amp;#039;&amp;#039;Apply&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It is also possible to use an interface as [[VLAN#Tagged VLANs|Trunk]] by simply assigning a second VLAN with a different ID to the same interface.&lt;br /&gt;
&lt;br /&gt;
== Create interface ==&lt;br /&gt;
The following screenshots demonstrate the process of adding a network interface:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-005.png|In the webinterface, navigate to &amp;#039;&amp;#039;&amp;#039;Interfaces&amp;#039;&amp;#039;&amp;#039; ‣ &amp;#039;&amp;#039;&amp;#039;Assignments&amp;#039;&amp;#039;&amp;#039; and select the new VLAN in the section &amp;#039;&amp;#039;&amp;#039;Assign a new interface.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-006.png|State a description and click on &amp;#039;&amp;#039;&amp;#039;Add&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-007.png|The new VLAN was added as new interface &amp;#039;&amp;#039;&amp;#039;Lab&amp;#039;&amp;#039;&amp;#039; in this example. Click on &amp;#039;&amp;#039;&amp;#039;Save&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In Thomas-Krenn-Wiki, you will find information on how to [[OPNsense add interface|add an OPNsense interface]].&lt;br /&gt;
&lt;br /&gt;
== Assign IP address ==&lt;br /&gt;
Here, an IP address is assigned to the added interface. There are several options available, such as automatic address assignment using DHCP or manual configuration of a static IP address (Static IPv4). In this example, a static address assignment with the IP-address &amp;#039;&amp;#039;&amp;#039;192.168.10.1/24&amp;#039;&amp;#039;&amp;#039; is used.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-008.png|Click on the menu item &amp;#039;&amp;#039;&amp;#039;Assignments&amp;#039;&amp;#039;&amp;#039; ‣ &amp;#039;&amp;#039;&amp;#039;Interfaces&amp;#039;&amp;#039;&amp;#039; on the previously created VLAN interface. &lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-009.png|Activate it with the help of the option &amp;#039;&amp;#039;&amp;#039;Enable Interface&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-010.png|Go to the menu item &amp;#039;&amp;#039;&amp;#039;IPv4 Configuration Type&amp;#039;&amp;#039;&amp;#039; after activation of the interface and select one of the &amp;#039;&amp;#039;&amp;#039;options&amp;#039;&amp;#039;&amp;#039; described earlier.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-011.png|If you selected the &amp;#039;&amp;#039;&amp;#039;Static IPv4&amp;#039;&amp;#039;&amp;#039; option, scroll down to the &amp;#039;&amp;#039;&amp;#039;Static IPv4 configuration&amp;#039;&amp;#039;&amp;#039; section. State the static IPv4 address as well as the subnet. After that, click on &amp;#039;&amp;#039;&amp;#039;Save&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-012.png|Store the configuration with &amp;#039;&amp;#039;&amp;#039;Apply changes.&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Firewall rules ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; By default, all incoming connections on this interface are blocked. To change this, you must create rules to control and secure data traffic for the VLAN you created.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:OPNsense-25.1-vlan-configuration-013.png|Go to the &amp;#039;&amp;#039;&amp;#039;Firewall&amp;#039;&amp;#039;&amp;#039; menu and click on &amp;#039;&amp;#039;&amp;#039;Rules&amp;#039;&amp;#039;&amp;#039; to create rules here.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{ederr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:OPNsense]]&lt;br /&gt;
[[de:VLAN einrichten unter OPNsense]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Network_configuration_Ubuntu_-_Netplan</id>
		<title>Network configuration Ubuntu - Netplan</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Network_configuration_Ubuntu_-_Netplan"/>
		<updated>2026-07-08T06:07:19Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Aranzinger moved page Network configuration - Netplan to Network configuration Ubuntu - Netplan&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the current version of [[Ubuntu]] Server, Ubuntu 18.04 (Bionic Beaver), the network configuration can no longer be set in the file &amp;lt;code&amp;gt;/etc/network/interfaces&amp;lt;/code&amp;gt; in a default installation. Since Ubuntu 17.10, there is [http://manpages.ubuntu.com/manpages/bionic/man5/netplan.5.html Netplan], which is a new option to configure network interfaces. The network configuration is stored in .yaml-files. In addition to changes to the configuration of the network interfaces, there are also new configurations regarding the hostname. &lt;br /&gt;
&lt;br /&gt;
== Network configuration (static) ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo rm /etc/netplan/50-cloud-init.yaml &lt;br /&gt;
sudo touch /etc/netplan/01-ens160.yaml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The content of the file in a static network configuration should look as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
network:&lt;br /&gt;
 version: 2&lt;br /&gt;
 renderer: networkd&lt;br /&gt;
 ethernets:&lt;br /&gt;
   ens160:&lt;br /&gt;
     dhcp4: no&lt;br /&gt;
     dhcp6: no&lt;br /&gt;
     addresses: [10.2.2.123/24]&lt;br /&gt;
     gateway4: 10.2.2.1&lt;br /&gt;
     nameservers:&lt;br /&gt;
       addresses: [192.168.110.50]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, the network configuration can be activated:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt; sudo netplan apply&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; Please use spaces for indentation in this file and do not use tabs.&lt;br /&gt;
&lt;br /&gt;
== Change hostname ==&lt;br /&gt;
In Ubuntu 18.04, it is no longer enough to set the hostname via &amp;lt;code&amp;gt;/etc/hostname&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;hostnamectl&amp;lt;/code&amp;gt;. After a reboot of the server, the hostname would be lost again, as it has not been stored. In the following, it is explained how to permanently set the host name:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;nano /etc/cloud/cloud.cfg&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This will cause the set+update hostname module to not operate (if true)&lt;br /&gt;
preserve_hostname: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Here, the value preserve_hostname must be set from false to true.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This will cause the set+update hostname module to not operate (if true)&lt;br /&gt;
preserve_hostname: true&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that, the hostname can be set permanently using the following commands:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo nano /etc/hostname &lt;br /&gt;
sudo hostnamectl set-hostname web-01&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network configuration (other) == &lt;br /&gt;
For other network configurations, such as DHCP, Bonds, WLAN etc., you will find corresponding notes on the [https://netplan.io/examples netplan.io] website.&lt;br /&gt;
&lt;br /&gt;
{{Jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Netzwerk-Konfiguration Ubuntu - Netplan]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/NVMe-CLI</id>
		<title>NVMe-CLI</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/NVMe-CLI"/>
		<updated>2026-07-07T11:07:10Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The &amp;#039;&amp;#039;&amp;#039;NVMe Command Line Interface&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;NVMe-CLI&amp;#039;&amp;#039;&amp;#039;) provides multiple &amp;#039;&amp;#039;&amp;#039;functions on querying and configuring NVMe SSDs&amp;#039;&amp;#039;&amp;#039; on Linux and FreeBSD. In this article, we explain how to install NVMe-CLI and which funtions NVMe-CLI offers.   == Version information == In the Linux distributions, the following versions of NVMe-CLI are included: {| class=&amp;quot;wikitable&amp;quot; |+ ! colspan=&amp;quot;2&amp;quot; |Linux distribution !NVMe-CLI version |- | rowspan=&amp;quot;3&amp;quot; |Debian GNU/Linux |1...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;NVMe Command Line Interface&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;NVMe-CLI&amp;#039;&amp;#039;&amp;#039;) provides multiple &amp;#039;&amp;#039;&amp;#039;functions on querying and configuring [[NVMe]] [[SSD]]s&amp;#039;&amp;#039;&amp;#039; on [[Linux]] and [[FreeBSD]]. In this article, we explain how to install NVMe-CLI and which funtions NVMe-CLI offers. &lt;br /&gt;
&lt;br /&gt;
== Version information ==&lt;br /&gt;
In the Linux distributions, the following versions of NVMe-CLI are included:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; |Linux distribution&lt;br /&gt;
!NVMe-CLI version&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;3&amp;quot; |[[Debian GNU/Linux]]&lt;br /&gt;
|12.0 (Bookworm)&lt;br /&gt;
|nvme-cli [https://packages.debian.org/bookworm/nvme-cli 2.3]&lt;br /&gt;
|-&lt;br /&gt;
|11.0 (Bullseye)&lt;br /&gt;
|nvme-cli [https://packages.debian.org/bullseye/nvme-cli 1.12]&lt;br /&gt;
|-&lt;br /&gt;
|10.0 (Buster)&lt;br /&gt;
|nvme-cli [https://packages.debian.org/buster/nvme-cli 1.7]&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; |[[Ubuntu]]&lt;br /&gt;
|22.04 LTS&lt;br /&gt;
|nvme-cli [https://packages.ubuntu.com/jammy/nvme-cli 1.16]&lt;br /&gt;
|-&lt;br /&gt;
|20.04 LTS&lt;br /&gt;
|nvme-cli [https://packages.ubuntu.com/focal/nvme-cli 1.9]&lt;br /&gt;
|-&lt;br /&gt;
|[[Proxmox VE]]&lt;br /&gt;
|7.x&lt;br /&gt;
|nvme-cli 1.12&lt;br /&gt;
|}&lt;br /&gt;
Changelog (in part):&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!NVMe-CLI version&lt;br /&gt;
!Release date&lt;br /&gt;
!Changes&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.1-rc0 v2.1-rc0]&lt;br /&gt;
|14.07.2022&lt;br /&gt;
|new solidigm plugin&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0 v2.0]&lt;br /&gt;
|08.04.2022&lt;br /&gt;
|first release of nvme-cli 2&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc7 v2.0-rc7]&lt;br /&gt;
|18.03.2022&lt;br /&gt;
|add transcend, virtium plugin commands&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc6 v2.0-rc6]&lt;br /&gt;
|11.03.2022&lt;br /&gt;
|cmds-main: Add intel plugin commands&lt;br /&gt;
cmds-plugins: Add huawei plugin commands&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc4 v2.0-rc4]&lt;br /&gt;
|22.02.2022&lt;br /&gt;
|Micron and NetApp plugin got a few fixes&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc3 v2.0-rc3]&lt;br /&gt;
|11.02.2022&lt;br /&gt;
|update wdc plugin version to 1.16.3&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/linux-nvme/nvme-cli/releases/tag/v2.0-rc0 v2.0-rc0]&lt;br /&gt;
|14.01.2022&lt;br /&gt;
|code base of nvme-cli has been splitted into a nvme-cli and libnvme&lt;br /&gt;
a lot&amp;#039;s of cleanups and refactoring&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== NVMe-CLI installation ==&lt;br /&gt;
NVMe-CLI is installed via apt on [[Debian]] and [[Ubuntu]]:&lt;br /&gt;
 apt install nvme-cli&lt;br /&gt;
&lt;br /&gt;
On [[FreeBSD]], the installation works as follows:&lt;br /&gt;
 pkg install nvme-cli&lt;br /&gt;
&lt;br /&gt;
== NVMe-CLI function overview ==&lt;br /&gt;
&lt;br /&gt;
=== nvme help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  list                      List all NVMe devices and namespaces on machine&lt;br /&gt;
  list-subsys               List nvme subsystems&lt;br /&gt;
  id-ctrl                   Send NVMe Identify Controller&lt;br /&gt;
  id-ns                     Send NVMe Identify Namespace, display structure&lt;br /&gt;
  id-ns-granularity         Send NVMe Identify Namespace Granularity List, display structure&lt;br /&gt;
  list-ns                   Send NVMe Identify List, display structure&lt;br /&gt;
  list-ctrl                 Send NVMe Identify Controller List, display structure&lt;br /&gt;
  nvm-id-ctrl               Send NVMe Identify Controller NVM Command Set, display structure&lt;br /&gt;
  primary-ctrl-caps         Send NVMe Identify Primary Controller Capabilities&lt;br /&gt;
  list-secondary            List Secondary Controllers associated with a Primary Controller&lt;br /&gt;
  cmdset-ind-id-ns          I/O Command Set Independent Identify Namespace&lt;br /&gt;
  ns-descs                  Send NVMe Namespace Descriptor List, display structure&lt;br /&gt;
  id-nvmset                 Send NVMe Identify NVM Set List, display structure&lt;br /&gt;
  id-uuid                   Send NVMe Identify UUID List, display structure&lt;br /&gt;
  id-iocs                   Send NVMe Identify I/O Command Set, display structure&lt;br /&gt;
  id-domain                 Send NVMe Identify Domain List, display structure&lt;br /&gt;
  list-endgrp               Send NVMe Identify Endurance Group List, display structure&lt;br /&gt;
  create-ns                 Creates a namespace with the provided parameters&lt;br /&gt;
  delete-ns                 Deletes a namespace from the controller&lt;br /&gt;
  attach-ns                 Attaches a namespace to requested controller(s)&lt;br /&gt;
  detach-ns                 Detaches a namespace from requested controller(s)&lt;br /&gt;
  get-ns-id                 Retrieve the namespace ID of opened block device&lt;br /&gt;
  get-log                   Generic NVMe get log, returns log in raw format&lt;br /&gt;
  telemetry-log             Retrieve FW Telemetry log write to file&lt;br /&gt;
  fw-log                    Retrieve FW Log, show it&lt;br /&gt;
  changed-ns-list-log       Retrieve Changed Namespace List, show it&lt;br /&gt;
  smart-log                 Retrieve SMART Log, show it&lt;br /&gt;
  ana-log                   Retrieve ANA Log, show it&lt;br /&gt;
  error-log                 Retrieve Error Log, show it&lt;br /&gt;
  effects-log               Retrieve Command Effects Log, show it&lt;br /&gt;
  endurance-log             Retrieve Endurance Group Log, show it&lt;br /&gt;
  predictable-lat-log       Retrieve Predictable Latency per Nvmset Log, show it&lt;br /&gt;
  pred-lat-event-agg-log    Retrieve Predictable Latency Event Aggregate Log, show it&lt;br /&gt;
  persistent-event-log      Retrieve Presistent Event Log, show it&lt;br /&gt;
  endurance-event-agg-log   Retrieve Endurance Group Event Aggregate Log, show it&lt;br /&gt;
  lba-status-log            Retrieve LBA Status Information Log, show it&lt;br /&gt;
  resv-notif-log            Retrieve Reservation Notification Log, show it&lt;br /&gt;
  boot-part-log             Retrieve Boot Partition Log, show it&lt;br /&gt;
  get-feature               Get feature and show the resulting value&lt;br /&gt;
  device-self-test          Perform the necessary tests to observe the performance&lt;br /&gt;
  self-test-log             Retrieve the SELF-TEST Log, show it&lt;br /&gt;
  supported-log-pages       Retrieve the Supported Log pages details, show it&lt;br /&gt;
  set-feature               Set a feature and show the resulting value&lt;br /&gt;
  set-property              Set a property and show the resulting value&lt;br /&gt;
  get-property              Get a property and show the resulting value&lt;br /&gt;
  format                    Format namespace with new block format&lt;br /&gt;
  fw-commit                 Verify and commit firmware to a specific slot (fw-activate in old version &amp;lt; 1.2)&lt;br /&gt;
  fw-download               Download new firmware&lt;br /&gt;
  admin-passthru            Submit an arbitrary admin command, return results&lt;br /&gt;
  io-passthru               Submit an arbitrary IO command, return results&lt;br /&gt;
  security-send             Submit a Security Send command, return results&lt;br /&gt;
  security-recv             Submit a Security Receive command, return results&lt;br /&gt;
  get-lba-status            Submit a Get LBA Status command, return results&lt;br /&gt;
  capacity-mgmt             Submit Capacity Management Command, return results&lt;br /&gt;
  resv-acquire              Submit a Reservation Acquire, return results&lt;br /&gt;
  resv-register             Submit a Reservation Register, return results&lt;br /&gt;
  resv-release              Submit a Reservation Release, return results&lt;br /&gt;
  resv-report               Submit a Reservation Report, return results&lt;br /&gt;
  dsm                       Submit a Data Set Management command, return results&lt;br /&gt;
  copy                      Submit a Simple Copy command, return results&lt;br /&gt;
  flush                     Submit a Flush command, return results&lt;br /&gt;
  compare                   Submit a Compare command, return results&lt;br /&gt;
  read                      Submit a read command, return results&lt;br /&gt;
  write                     Submit a write command, return results&lt;br /&gt;
  write-zeroes              Submit a write zeroes command, return results&lt;br /&gt;
  write-uncor               Submit a write uncorrectable command, return results&lt;br /&gt;
  verify                    Submit a verify command, return results&lt;br /&gt;
  sanitize                  Submit a sanitize command&lt;br /&gt;
  sanitize-log              Retrieve sanitize log, show it&lt;br /&gt;
  reset                     Resets the controller&lt;br /&gt;
  subsystem-reset           Resets the subsystem&lt;br /&gt;
  ns-rescan                 Rescans the NVME namespaces&lt;br /&gt;
  show-regs                 Shows the controller registers or properties. Requires character device&lt;br /&gt;
  discover                  Discover NVMeoF subsystems&lt;br /&gt;
  connect-all               Discover and Connect to NVMeoF subsystems&lt;br /&gt;
  connect                   Connect to NVMeoF subsystem&lt;br /&gt;
  disconnect                Disconnect from NVMeoF subsystem&lt;br /&gt;
  disconnect-all            Disconnect from all connected NVMeoF subsystems&lt;br /&gt;
  gen-hostnqn               Generate NVMeoF host NQN&lt;br /&gt;
  show-hostnqn              Show NVMeoF host NQN&lt;br /&gt;
  dir-receive               Submit a Directive Receive command, return results&lt;br /&gt;
  dir-send                  Submit a Directive Send command, return results&lt;br /&gt;
  virt-mgmt                 Manage Flexible Resources between Primary and Secondary Controller&lt;br /&gt;
  rpmb                      Replay Protection Memory Block commands&lt;br /&gt;
  fid-support-effects-log   Submit Feature ID Support and Effects Log, Return result&lt;br /&gt;
  lockdown                  Submit a Lockdown command,return result&lt;br /&gt;
  version                   Shows the program version&lt;br /&gt;
  help                      Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&lt;br /&gt;
The following are all installed plugin extensions:&lt;br /&gt;
  ymtc            Ymtc vendor specific extensions&lt;br /&gt;
  nvidia          NVIDIA vendor specific extensions&lt;br /&gt;
  zns             Zoned Namespace Command Set&lt;br /&gt;
  transcend       Transcend vendor specific extensions&lt;br /&gt;
  sfx             ScaleFlux vendor specific extensions&lt;br /&gt;
  dera            Dera vendor specific extensions&lt;br /&gt;
  shannon         Shannon vendor specific extensions&lt;br /&gt;
  virtium         Virtium vendor specific extensions&lt;br /&gt;
  seagate         Seagate vendor specific extensions&lt;br /&gt;
  micron          Micron vendor specific extensions&lt;br /&gt;
  toshiba         Toshiba NVME plugin&lt;br /&gt;
  netapp          NetApp vendor specific extensions&lt;br /&gt;
  huawei          Huawei vendor specific extensions&lt;br /&gt;
  wdc             Western Digital vendor specific extensions&lt;br /&gt;
  memblaze        Memblaze vendor specific extensions&lt;br /&gt;
  lnvm            LightNVM specific extensions&lt;br /&gt;
  amzn            Amazon vendor specific extensions&lt;br /&gt;
  intel           Intel vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme &amp;lt;plugin&amp;gt; help&amp;#039; for more information on a plugin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme micron help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme micron help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme micron &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Micron vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  select-download                  Selective Firmware Download&lt;br /&gt;
  vs-temperature-stats             Retrieve Micron temperature statistics&lt;br /&gt;
  vs-pcie-stats                    Retrieve Micron PCIe error stats&lt;br /&gt;
  clear-pcie-correctable-errors    Clear correctable PCIe errors&lt;br /&gt;
  vs-internal-log                  Retrieve Micron logs&lt;br /&gt;
  vs-telemetry-controller-option   Enable/Disable controller telemetry log generation&lt;br /&gt;
  vs-nand-stats                    Retrieve NAND Stats&lt;br /&gt;
  vs-drive-info                    Retrieve Drive information&lt;br /&gt;
  plugin-version                   Display plugin version info&lt;br /&gt;
  cloud-SSD-plugin-version         Display plugin version info&lt;br /&gt;
  log-page-directory               Retrieve log page directory&lt;br /&gt;
  vs-fw-activate-history           Display FW activation history&lt;br /&gt;
  vs-error-reason-identifier       Retrieve Error reason&lt;br /&gt;
  vs-smart-add-log                 Retrieve extended SMART data&lt;br /&gt;
  clear-fw-activate-history        Clear FW activation history&lt;br /&gt;
  vs-smbus-option                  Enable/Disable SMBUS on the drive&lt;br /&gt;
  version                          Shows the program version&lt;br /&gt;
  help                             Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme micron help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme toshiba help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme toshiba help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme toshiba &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Toshiba NVME plugin&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  vs-smart-add-log                Extended SMART information&lt;br /&gt;
  vs-internal-log                 Get Internal Log&lt;br /&gt;
  clear-pcie-correctable-errors   Clear PCIe correctable error count&lt;br /&gt;
  version                         Shows the program version&lt;br /&gt;
  help                            Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme toshiba help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme wdc help ===&lt;br /&gt;
The following commands are provided for WDC SSDs (details on &amp;#039;drive-resize&amp;#039; can be found in [[Drive-Resize von Western Digital NVME SSDs|Drive-Resize of Western Digital NVME SSDs]]):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme wdc help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme wdc &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Western Digital vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  cap-diag                         WDC Capture-Diagnostics&lt;br /&gt;
  drive-log                        WDC Drive Log&lt;br /&gt;
  get-crash-dump                   WDC Crash Dump&lt;br /&gt;
  get-pfail-dump                   WDC Pfail Dump&lt;br /&gt;
  id-ctrl                          WDC identify controller&lt;br /&gt;
  purge                            WDC Purge&lt;br /&gt;
  purge-monitor                    WDC Purge Monitor&lt;br /&gt;
  vs-internal-log                  WDC Internal Firmware Log&lt;br /&gt;
  vs-nand-stats                    WDC NAND Statistics&lt;br /&gt;
  vs-smart-add-log                 WDC Additional Smart Log&lt;br /&gt;
  clear-pcie-correctable-errors    WDC Clear PCIe Correctable Error Count&lt;br /&gt;
  drive-essentials                 WDC Drive Essentials&lt;br /&gt;
  get-drive-status                 WDC Get Drive Status&lt;br /&gt;
  clear-assert-dump                WDC Clear Assert Dump&lt;br /&gt;
  drive-resize                     WDC Drive Resize&lt;br /&gt;
  vs-fw-activate-history           WDC Get FW Activate History&lt;br /&gt;
  clear-fw-activate-history        WDC Clear FW Activate History&lt;br /&gt;
  enc-get-log                      WDC Get Enclosure Log&lt;br /&gt;
  vs-telemetry-controller-option   WDC Enable/Disable Controller Initiated Telemetry Log&lt;br /&gt;
  vs-error-reason-identifier       WDC Telemetry Reason Identifier&lt;br /&gt;
  log-page-directory               WDC Get Log Page Directory&lt;br /&gt;
  namespace-resize                 WDC NamespaceDrive Resize&lt;br /&gt;
  vs-drive-info                    WDC Get Drive Info&lt;br /&gt;
  vs-temperature-stats             WDC Get Temperature Stats&lt;br /&gt;
  capabilities                     WDC Device Capabilities&lt;br /&gt;
  cloud-SSD-plugin-version         WDC Cloud SSD Plugin Version&lt;br /&gt;
  vs-pcie-stats                    WDC VS PCIE Statistics&lt;br /&gt;
  get-latency-monitor-log          WDC Get Latency Monitor Log Page&lt;br /&gt;
  version                          Shows the program version&lt;br /&gt;
  help                             Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme wdc help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme intel help ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ nvme intel help&lt;br /&gt;
nvme-1.16&lt;br /&gt;
usage: nvme intel &amp;lt;command&amp;gt; [&amp;lt;device&amp;gt;] [&amp;lt;args&amp;gt;]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;lt;device&amp;gt;&amp;#039; may be either an NVMe character device (ex: /dev/nvme0) or an&lt;br /&gt;
nvme block device (ex: /dev/nvme0n1).&lt;br /&gt;
&lt;br /&gt;
Intel vendor specific extensions&lt;br /&gt;
&lt;br /&gt;
The following are all implemented sub-commands:&lt;br /&gt;
  id-ctrl                 Send NVMe Identify Controller&lt;br /&gt;
  internal-log            Retrieve Intel internal firmware log, save it&lt;br /&gt;
  lat-stats               Retrieve Intel IO Latency Statistics log, show it&lt;br /&gt;
  set-bucket-thresholds   Set Latency Stats Bucket Values, save it&lt;br /&gt;
  lat-stats-tracking      Enable and disable Latency Statistics logging.&lt;br /&gt;
  market-name             Retrieve Intel Marketing Name log, show it&lt;br /&gt;
  smart-log-add           Retrieve Intel SMART Log, show it&lt;br /&gt;
  temp-stats              Retrieve Intel Temperature Statistics log, show it&lt;br /&gt;
  version                 Shows the program version&lt;br /&gt;
  help                    Display this help&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;nvme intel help &amp;lt;command&amp;gt;&amp;#039; for more information on a specific command&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== NVMe-CLI examples ==&lt;br /&gt;
The following examples were collected on an Ubuntu 22.04 system with an ATP M.2 NVMe SSD.&lt;br /&gt;
&lt;br /&gt;
=== nvme list ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme list&lt;br /&gt;
Node                  SN                   Model                                    Namespace Usage                      Format           FW Rev&lt;br /&gt;
--------------------- -------------------- ---------------------------------------- --------- -------------------------- ---------------- --------&lt;br /&gt;
/dev/nvme0n1          20040089-000002      ATP NVMe M.2 2280 SSD                    1           5,08  GB / 120,03  GB    512   B +  0 B   42A0S79A&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme list-subsys ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme list-subsys&lt;br /&gt;
nvme-subsys0 - NQN=nqn.2014.08.org.nvmexpress:1db21db220040089-000002     ATP NVMe M.2 2280 SSD&lt;br /&gt;
\&lt;br /&gt;
 +- nvme0 pcie 0000:01:00.0 live&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the following, you will find the output of a [[Proxmox VE]] 7.x system with four [[Western Digital SN640 TCG U.2 NVMe SSDs]]:&lt;br /&gt;
 root@pmx01:~# nvme list-subsys&lt;br /&gt;
nvme-subsys0 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B7800000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme0 pcie 0000:84:00.0 live&lt;br /&gt;
nvme-subsys1 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B0000000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme1 pcie 0000:85:00.0 live&lt;br /&gt;
nvme-subsys2 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B7000000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme2 pcie 0000:86:00.0 live&lt;br /&gt;
nvme-subsys3 - NQN=nqn.2018-01.com.wdc:NGUID:0014EE830220B4000000000000000000&lt;br /&gt;
\&lt;br /&gt;
 +- nvme3 pcie 0000:87:00.0 live&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme smart-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme smart-log /dev/nvme0n1&lt;br /&gt;
Smart Log for NVME device:nvme0n1 namespace-id:ffffffff&lt;br /&gt;
critical_warning                        : 0&lt;br /&gt;
temperature                             : 38 C (311 Kelvin)&lt;br /&gt;
available_spare                         : 100%&lt;br /&gt;
available_spare_threshold               : 10%&lt;br /&gt;
percentage_used                         : 0%&lt;br /&gt;
endurance group critical warning summary: 0&lt;br /&gt;
data_units_read                         : 314.978&lt;br /&gt;
data_units_written                      : 197.916&lt;br /&gt;
host_read_commands                      : 1.739.034&lt;br /&gt;
host_write_commands                     : 2.384.025&lt;br /&gt;
controller_busy_time                    : 46&lt;br /&gt;
power_cycles                            : 106&lt;br /&gt;
power_on_hours                          : 68&lt;br /&gt;
unsafe_shutdowns                        : 59&lt;br /&gt;
media_errors                            : 0&lt;br /&gt;
num_err_log_entries                     : 0&lt;br /&gt;
Warning Temperature Time                : 0&lt;br /&gt;
Critical Composite Temperature Time     : 0&lt;br /&gt;
Temperature Sensor 1           : 27 C (300 Kelvin)&lt;br /&gt;
Temperature Sensor 2           : 38 C (311 Kelvin)&lt;br /&gt;
Thermal Management T1 Trans Count       : 0&lt;br /&gt;
Thermal Management T2 Trans Count       : 0&lt;br /&gt;
Thermal Management T1 Total Time        : 0&lt;br /&gt;
Thermal Management T2 Total Time        : 0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme fw-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme fw-log /dev/nvme0n1&lt;br /&gt;
Firmware Log for device:nvme0n1&lt;br /&gt;
afi  : 0x11&lt;br /&gt;
frs1 : 42A0S79A&lt;br /&gt;
frs2 : 42A0S79A&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme error-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme error-log /dev/nvme0n1&lt;br /&gt;
Error Log Entries for device:nvme0n1 entries:64&lt;br /&gt;
.................&lt;br /&gt;
 Entry[ 0]&lt;br /&gt;
.................&lt;br /&gt;
error_count     : 0&lt;br /&gt;
sqid            : 0&lt;br /&gt;
cmdid           : 0&lt;br /&gt;
status_field    : 0(SUCCESS: The command completed successfully)&lt;br /&gt;
phase_tag       : 0&lt;br /&gt;
parm_err_loc    : 0&lt;br /&gt;
lba             : 0&lt;br /&gt;
nsid            : 0&lt;br /&gt;
vs              : 0&lt;br /&gt;
trtype          : The transport type is not indicated or the error is not transport related.&lt;br /&gt;
cs              : 0&lt;br /&gt;
trtype_spec_info: 0&lt;br /&gt;
[...]&lt;br /&gt;
.................&lt;br /&gt;
 Entry[63]&lt;br /&gt;
.................&lt;br /&gt;
error_count     : 0&lt;br /&gt;
sqid            : 0&lt;br /&gt;
cmdid           : 0&lt;br /&gt;
status_field    : 0(SUCCESS: The command completed successfully)&lt;br /&gt;
phase_tag       : 0&lt;br /&gt;
parm_err_loc    : 0&lt;br /&gt;
lba             : 0&lt;br /&gt;
nsid            : 0&lt;br /&gt;
vs              : 0&lt;br /&gt;
trtype          : The transport type is not indicated or the error is not transport related.&lt;br /&gt;
cs              : 0&lt;br /&gt;
trtype_spec_info: 0&lt;br /&gt;
.................&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== nvme effects-log /dev/nvme0n1 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
test@ubuntu-22-04:~$ sudo nvme effects-log /dev/nvme0n1&lt;br /&gt;
Admin Command Set&lt;br /&gt;
ACS0     [Delete I/O Submission Queue     ] 00000001&lt;br /&gt;
ACS1     [Create I/O Submission Queue     ] 00000001&lt;br /&gt;
ACS2     [Get Log Page                    ] 00000001&lt;br /&gt;
ACS4     [Delete I/O Completion Queue     ] 00000001&lt;br /&gt;
ACS5     [Create I/O Completion Queue     ] 00000001&lt;br /&gt;
ACS6     [Identify                        ] 00000001&lt;br /&gt;
ACS8     [Abort                           ] 00000001&lt;br /&gt;
ACS9     [Set Features                    ] 00000001&lt;br /&gt;
ACS10    [Get Features                    ] 00000001&lt;br /&gt;
ACS12    [Asynchronous Event Request      ] 00000001&lt;br /&gt;
ACS16    [Firmware Commit                 ] 00000011&lt;br /&gt;
ACS17    [Firmware Image Download         ] 00000001&lt;br /&gt;
ACS20    [Device Self-test                ] 00000001&lt;br /&gt;
ACS128   [Format NVM                      ] 00010003&lt;br /&gt;
ACS129   [Security Send                   ] 00000003&lt;br /&gt;
ACS130   [Security Receive                ] 00000001&lt;br /&gt;
ACS132   [Sanitize                        ] 00010003&lt;br /&gt;
ACS192   [Unknown                         ] 00000017&lt;br /&gt;
ACS193   [Unknown                         ] 00000017&lt;br /&gt;
ACS194   [Unknown                         ] 00000001&lt;br /&gt;
ACS224   [Unknown                         ] 00000001&lt;br /&gt;
ACS228   [Unknown                         ] 00000001&lt;br /&gt;
ACS229   [Unknown                         ] 00000001&lt;br /&gt;
ACS230   [Unknown                         ] 00000001&lt;br /&gt;
&lt;br /&gt;
NVM Command Set&lt;br /&gt;
IOCS0    [Flush                           ] 00000003&lt;br /&gt;
IOCS1    [Write                           ] 00000003&lt;br /&gt;
IOCS2    [Read                            ] 00000001&lt;br /&gt;
IOCS4    [Write Uncorrectable             ] 00000003&lt;br /&gt;
IOCS5    [Compare                         ] 00000001&lt;br /&gt;
IOCS8    [Write Zeroes                    ] 00000003&lt;br /&gt;
IOCS9    [Dataset Management              ] 00000003&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://github.com/linux-nvme/nvme-cli nvme-cli] (github.com/linux-nvme)&lt;br /&gt;
* [https://nvmexpress.org/open-source-nvme-management-utility-nvme-command-line-interface-nvme-cli/ Open Source NVMe™ Management Utility – NVMe Command Line Interface (NVMe-CLI)] (nvmexpress.org, 25.02.2020)&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSDs]]&lt;br /&gt;
[[de:NVMe-CLI]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/EFI_shell_USB_drive</id>
		<title>EFI shell USB drive</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/EFI_shell_USB_drive"/>
		<updated>2026-07-03T05:28:16Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The &amp;#039;&amp;#039;&amp;#039;EFI shell&amp;#039;&amp;#039;&amp;#039; allows to run EFI applications, such as tools for updating the BIOS or the firmware of network cards or RAID controllers. In a lot of systems, an EFI shell is already included in the BIOS. If an integrated EFI shell is missing, an USB drive with EFI shell can be used as an alternative.   == Create USB stick with EFI shell == The following steps must be performed, to create an USB drive with EFI shell: # Format USB stick with &amp;#039;&amp;#039;&amp;#039;FAT32&amp;#039;&amp;#039;&amp;#039;  # Create &amp;#039;&amp;#039;&amp;#039;/...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;EFI shell&amp;#039;&amp;#039;&amp;#039; allows to run EFI applications, such as tools for updating the BIOS or the firmware of network cards or RAID controllers. In a lot of systems, an EFI shell is already included in the BIOS. If an integrated EFI shell is missing, an USB drive with EFI shell can be used as an alternative. &lt;br /&gt;
&lt;br /&gt;
== Create USB stick with EFI shell ==&lt;br /&gt;
The following steps must be performed, to create an USB drive with EFI shell:&lt;br /&gt;
# Format USB stick with &amp;#039;&amp;#039;&amp;#039;FAT32&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
# Create &amp;#039;&amp;#039;&amp;#039;/efi/boot&amp;#039;&amp;#039;&amp;#039; directory on USB drive&lt;br /&gt;
# Download UEFI shell (&amp;#039;&amp;#039;&amp;#039;Shell.efi&amp;#039;&amp;#039;&amp;#039;) and store it in the /efi/boot/ directory on the USB drive: &lt;br /&gt;
#*https://github.com/tianocore/edk2/blob/edk2-stable201903/ShellBinPkg/UefiShell/X64/Shell.efi (includes UEFI interactive shell v2.2)&lt;br /&gt;
# Rename Shell.efi to &amp;#039;&amp;#039;&amp;#039;Bootx64.efi&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
&lt;br /&gt;
== Test UEFI shell ==&lt;br /&gt;
Next, you can boot from this USB stick and use the EFI shell:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:BIOS-Boot-Override-USB-Pen-Drive.jpg|Boot into the BIOS and, under &amp;#039;&amp;#039;&amp;#039;Save &amp;amp; Exit&amp;#039;&amp;#039;&amp;#039; in the &amp;#039;&amp;#039;&amp;#039;Boot Override&amp;#039;&amp;#039;&amp;#039; section&amp;#039;&amp;#039;&amp;#039;,&amp;#039;&amp;#039;&amp;#039; select the UEFI entry for the USB drive you created. (&amp;#039;&amp;#039;&amp;#039;UEFI: Lexar USB Flash Drive ...&amp;#039;&amp;#039;&amp;#039; in this example).&lt;br /&gt;
File:EFI-Shell-v2.2.jpg|The EFI shell is started.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
&lt;br /&gt;
[[Category:UEFI]]&lt;br /&gt;
[[de:EFI Shell USB Stick]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Grafana_installation_and_configuration_on_Ubuntu_server_18.04_LTS</id>
		<title>Grafana installation and configuration on Ubuntu server 18.04 LTS</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Grafana_installation_and_configuration_on_Ubuntu_server_18.04_LTS"/>
		<updated>2026-07-01T09:27:26Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Grafana&amp;#039;&amp;#039;&amp;#039; is a webbased open source frontend for virtualizing metrics and for alerting when thresholds are exceeded. Grafana &amp;#039;&amp;#039;&amp;#039;supports numerous data sources&amp;#039;&amp;#039;&amp;#039;, for example Time Series databases such as InfluxDB, Graphite or Prometheus, log files via Elasticsearch and SQL data bases. Pre-defined dashboards are available through a marketplace.&amp;lt;ref&amp;gt;[https://grafana.com/grafana/dashboards Grafana Dashboards] (grafana.com)&amp;lt;/ref&amp;gt; This aticle explains the &amp;#039;&amp;#039;&amp;#039;installa...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Grafana&amp;#039;&amp;#039;&amp;#039; is a webbased open source frontend for virtualizing metrics and for alerting when thresholds are exceeded. Grafana &amp;#039;&amp;#039;&amp;#039;supports numerous data sources&amp;#039;&amp;#039;&amp;#039;, for example Time Series databases such as [[InfluxDB]], Graphite or Prometheus, log files via Elasticsearch and SQL data bases. Pre-defined dashboards are available through a marketplace.&amp;lt;ref&amp;gt;[https://grafana.com/grafana/dashboards Grafana Dashboards] (grafana.com)&amp;lt;/ref&amp;gt; This aticle explains the &amp;#039;&amp;#039;&amp;#039;installation of Grafana&amp;#039;&amp;#039;&amp;#039; in version 6.6.2 on &amp;#039;&amp;#039;&amp;#039;[[Ubuntu]] 18.04 LTS&amp;#039;&amp;#039;&amp;#039; as well as the &amp;#039;&amp;#039;&amp;#039;connection of a InfluxDB database as a data source&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
[[File:OPNsense-Grafana-Dashboard.png|thumb|right|Grafana dashboard with InfluxDB as datasource for monitoring a [[OPNsense]] firewall]]&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Grafana can be easily installed using Ubuntu&amp;#039;s built-in package manager.&amp;lt;ref&amp;gt;[https://grafana.com/docs/grafana/latest/installation/debian/ Install on Debian or Ubuntu] (grafana.com)&amp;lt;/ref&amp;gt; The following paragraphs show how to install Grafana on Ubuntu. Information about the installation on Windows, MAC and other Linux distributions can be found in the Grafana download area.&amp;lt;ref&amp;gt;[https://grafana.com/grafana/download Download Grafana] (grafana.com)&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== Add package sources ===&lt;br /&gt;
Since Grafana is not included in the official package repositories, the Grafana repository can be added as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt install -y apt-transport-https&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt install -y software-properties-common wget&lt;br /&gt;
tk@monitoringlesv2:~$ wget -q -O - https://packages.grafana.com/gpg.key | sudo apt-key add -&lt;br /&gt;
tk@monitoringlesv2:~$ sudo add-apt-repository &amp;quot;deb https://packages.grafana.com/oss/deb stable main&amp;quot;&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Install Grafana and activate Systemd daemon ===&lt;br /&gt;
After the package sources have been added, Grafana can be installed and the SystemD-service can be started and activated for Grafana:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
tk@monitoringlesv2:~$ sudo apt install grafana&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl daemon-reload&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl enable grafana-server&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl start grafana-server&lt;br /&gt;
tk@monitoringlesv2:~$ sudo systemctl status grafana-server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configure Grafana ==&lt;br /&gt;
The configuration is made via Grafana webinterface.&amp;lt;ref&amp;gt;[https://grafana.com/docs/grafana/latest/guides/getting_started/ Getting started] (grafana.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
To proceed with the remaining configuration steps, launch a browser of your choice.&lt;br /&gt;
&lt;br /&gt;
* Webinterface: http://&amp;lt;IP-des-Grafana-Servers&amp;gt;:3000&lt;br /&gt;
* Username: admin&lt;br /&gt;
* Password: admin&lt;br /&gt;
&lt;br /&gt;
=== Login to webinterface ===&lt;br /&gt;
Log in with the username &amp;quot;admin&amp;quot; and the password &amp;quot;admin&amp;quot;:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-001.png|Grafana login&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-002.png|Log in to the web interface using the username &amp;quot;admin&amp;quot; and password &amp;quot;admin&amp;quot;.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-003.png|A prompt to change your password appears.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Add datasource ===&lt;br /&gt;
This paragraph shows how to connect an InfluxDB as datasource to Grafana:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-004.png|After logging in to the web interface, you will see the following screen. Click on &amp;#039;&amp;#039;Add data source&amp;#039;&amp;#039;.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-005.png|Click &amp;#039;&amp;#039;Select&amp;#039;&amp;#039; in the InfluxDB row.  &lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-006.png|Assign a name to the data source, specify the path to InfluxDB, and select the database you want to connect to. Click &amp;#039;&amp;#039;Save &amp;amp; Test&amp;#039;&amp;#039;.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-007.png|If the message &amp;#039;&amp;#039;&amp;#039;Data source is working&amp;#039;&amp;#039;&amp;#039; appears, the connection from InfluxDB to Grafana was successful.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-008.png|Click &amp;#039;&amp;#039;Back&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Import dashboard ===&lt;br /&gt;
Pre-defined Grafana dashboards can be easily imported:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-009.png|Switch to the menu option Dashboards → Home.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-010.png|Go to Create → Import, to import a dashboard. &lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-011.png|Search for a suitable dashboard on Grafana and enter the URL or dashboard ID here.&lt;br /&gt;
File:Ubuntu-Server-18.04-Grafana-012.png|Depending on the dashboard, adjust a few more variables and then click &amp;#039;&amp;#039;Import&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[Category:Monitoring]]&lt;br /&gt;
[[pl:Instalacja i konfiguracja oprogramowania Grafana w Ubuntu Server 18.04 LTS]]&lt;br /&gt;
[[de:Grafana Installation und Konfiguration unter Ubuntu Server 18.04 LTS]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Upload_own_Ubuntu_packages_to_reprepro_repository</id>
		<title>Upload own Ubuntu packages to reprepro repository</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Upload_own_Ubuntu_packages_to_reprepro_repository"/>
		<updated>2026-07-01T05:30:30Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;In the following article, it is explained &amp;#039;&amp;#039;&amp;#039;how to upload&amp;#039;&amp;#039;&amp;#039; your own Ubuntu packages to a &amp;#039;&amp;#039;&amp;#039;reprepro&amp;#039;&amp;#039;&amp;#039; repository. The packages are transferred in a folder on the repository server with &amp;#039;&amp;#039;&amp;#039;dupload&amp;#039;&amp;#039;&amp;#039; via scp and processed there via an inoticoming job from reprepro. In the examples shown, the client is running Ubuntu 12.10, and the server is running &amp;#039;&amp;#039;&amp;#039;Ubuntu 12.04.2&amp;#039;&amp;#039;&amp;#039; with kernel 3.2.0-38-generic.   In the article Create Own apt repository using reprepro on Ubuntu...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the following article, it is explained &amp;#039;&amp;#039;&amp;#039;how to upload&amp;#039;&amp;#039;&amp;#039; your own Ubuntu packages to a &amp;#039;&amp;#039;&amp;#039;reprepro&amp;#039;&amp;#039;&amp;#039; repository. The packages are transferred in a folder on the repository server with &amp;#039;&amp;#039;&amp;#039;dupload&amp;#039;&amp;#039;&amp;#039; via scp and processed there via an inoticoming job from reprepro. In the examples shown, the client is running Ubuntu 12.10, and the server is running &amp;#039;&amp;#039;&amp;#039;Ubuntu 12.04.2&amp;#039;&amp;#039;&amp;#039; with kernel 3.2.0-38-generic. &lt;br /&gt;
&lt;br /&gt;
In the article [[Create Own apt repository using reprepro on Ubuntu]], it is explained how to generate an own reprepro repository.&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
=== On the repository server === &lt;br /&gt;
&amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[http://manpages.ubuntu.com/manpages/lucid/man1/inoticoming.1.html inoticoming Ubuntu-package] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; triggered actions, when files are added to a folder.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ sudo apt-get install inoticoming&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== On the client ===&lt;br /&gt;
&amp;lt;code&amp;gt;dupload&amp;lt;/code&amp;gt;&amp;lt;ref&amp;gt;[http://packages.ubuntu.com/precise/dupload dupload Ubuntu-package] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; loads the Ubuntu packages from the repository server that is monitored by inoticoming.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ sudo apt-get install dupload&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
=== On the server ===&lt;br /&gt;
The configuration file &amp;lt;code&amp;gt;incoming&amp;lt;/code&amp;gt; sets the rules and folders for uploads of new packages into the reprepro repository. The configuration file &amp;lt;code&amp;gt;incoming&amp;lt;/code&amp;gt; is located in the &amp;lt;code&amp;gt;/conf&amp;lt;/code&amp;gt; folder of the used reprepro repos.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ vi packages/conf/incoming&lt;br /&gt;
Name: incoming&lt;br /&gt;
IncomingDir: /home/repository/incoming&lt;br /&gt;
Allow: precise&lt;br /&gt;
Cleanup: on_deny on_error&lt;br /&gt;
Tempdir: /home/repository/incoming_tmp&lt;br /&gt;
LogDir: /home/repository/incoming_log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The &amp;lt;code&amp;gt;incoming&amp;lt;/code&amp;gt; rule is called by &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; via &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ inoticoming --logfile /home/repository/incoming_log/upload.log /home/repository/incoming/ \&lt;br /&gt;
&amp;gt; --stderr-to-log --stdout-to-log --suffix &amp;#039;.changes&amp;#039; \&lt;br /&gt;
&amp;gt; reprepro --waitforlock 100 processincoming incoming {} \;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Make sure that &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; runs under the same user account that manages the repository and uploads the packages. This ensures that the files and folders can be created and have the correct permissions.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ ps -u repository&lt;br /&gt;
  PID TTY          TIME CMD&lt;br /&gt;
[...]&lt;br /&gt;
 3098 ?        00:00:00 inoticoming&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== On the client ===&lt;br /&gt;
First, an SSH key is transmitted to the server for authentication:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ ssh-copy-id -i .ssh/key_rsa.pub repository@192.168.56.102&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The dupload-configuration specifies how the packages are loaded into the rep: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ vi .dupload.conf&lt;br /&gt;
package config;&lt;br /&gt;
$default_host = &amp;quot;tkpack&amp;quot;;&lt;br /&gt;
$cfg{&amp;#039;tkpack&amp;#039;} = {&lt;br /&gt;
        fqdn =&amp;gt; &amp;quot;192.168.56.102&amp;quot;,&lt;br /&gt;
        method =&amp;gt; &amp;quot;scp&amp;quot;,&lt;br /&gt;
        login =&amp;gt; &amp;quot;repository&amp;quot;,&lt;br /&gt;
        incoming =&amp;gt; &amp;quot;/home/repository/incoming/&amp;quot;,&lt;br /&gt;
        # files pass on to dinstall which sends emails itself&lt;br /&gt;
        dinstall_runs =&amp;gt; 1,&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Upload packages to repository == &lt;br /&gt;
You can then use &amp;lt;code&amp;gt;dupload&amp;lt;/code&amp;gt; to upload a package to the repo &amp;#039;&amp;#039;&amp;#039;from the client&amp;#039;&amp;#039;&amp;#039; (in this case, without sending notification emails):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~$ dupload -f --nomail -t tkpack tkmon_0.0.1-1_amd64.changes&lt;br /&gt;
dupload warning: mail options disabled, can&amp;#039;t run `/usr/sbin/sendmail&amp;#039;: No such file or directory&lt;br /&gt;
dupload note: no announcement will be sent.&lt;br /&gt;
Uploading (scp) to 192.168.56.102:/home/repository/incoming/&lt;br /&gt;
[ job tkmon_0.0.1-1_amd64 from tkmon_0.0.1-1_amd64.changes&lt;br /&gt;
 tkmon_0.0.1-1.dsc, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1-1.debian.tar.gz, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1.orig.tar.gz, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1-1_all.deb, size ok, md5sum ok, sha1sum ok, sha256sum ok&lt;br /&gt;
 tkmon_0.0.1-1_amd64.changes ok ]&lt;br /&gt;
Uploading (scp) to tkpack (192.168.56.102)&lt;br /&gt;
[ Uploading job tkmon_0.0.1-1_amd64&lt;br /&gt;
 tkmon_0.0.1-1.dsc 0.8 kB, ok (0 s, 0.81 kB/s)&lt;br /&gt;
 tkmon_0.0.1-1.debian.tar.gz 6.1 kB, ok (0 s, 6.07 kB/s)&lt;br /&gt;
 tkmon_0.0.1.orig.tar.gz 720.0 kB, ok (1 s, 720.00 kB/s)&lt;br /&gt;
 tkmon_0.0.1-1_all.deb 701.7 kB, ok (1 s, 701.66 kB/s)&lt;br /&gt;
 tkmon_0.0.1-1_amd64.changes 1.4 kB, ok (0 s, 1.43 kB/s) ]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;On the server&amp;#039;&amp;#039;&amp;#039;, &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; loads the packages with reprepro into the repository:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
:~/incoming_log$ cat upload.log &lt;br /&gt;
Will call action reprepro for: tkmon_0.0.1-1_amd64.changes&lt;br /&gt;
Exporting indices...&lt;br /&gt;
:~/incoming_log$ reprepro list precise &lt;br /&gt;
precise|main|i386: tkmon 0.0.1-1&lt;br /&gt;
precise|main|amd64: tkmon 0.0.1-1&lt;br /&gt;
precise|main|source: tkmon 0.0.1-1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
The following error occurs when using the upload method &amp;lt;code&amp;gt;scpb&amp;lt;/code&amp;gt;, which is actually recommended in the dupload man page:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1.dsc&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1.debian.tar.gz&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1.orig.tar.gz&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1_all.deb&amp;#039;: No such file or directory&lt;br /&gt;
chmod: cannot access `tkmon_0.0.1-1_amd64.changes&amp;#039;: No such file or directory&lt;br /&gt;
dupload fatal error: ssh -x -l repository 192.168.56.102 &amp;#039;cd /home/repository/incoming/;chmod 0644 tkmon_0.0.1-1.dsc tkmon_0.0.1-1.debian.tar.gz tkmon_0.0.1.orig.tar.gz tkmon_0.0.1-1_all.deb tkmon_0.0.1-1_amd64.changes ;&amp;#039; failed&lt;br /&gt;
 at /usr/bin/dupload line 662&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
This error occurs because &amp;lt;code&amp;gt;inoticoming&amp;lt;/code&amp;gt; is processing the uploaded packages too quickly. The packages have already been moved to the repository by &amp;lt;code&amp;gt;reprepro&amp;lt;/code&amp;gt;, so &amp;lt;code&amp;gt;dupload&amp;lt;/code&amp;gt; can no longer perform a &amp;lt;code&amp;gt;chmod&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== Workaround ===&lt;br /&gt;
The right permissions can be set with preupload-hook before the upload. This also allows you to upload using &amp;lt;code&amp;gt;scpb&amp;lt;/code&amp;gt;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
$preupload{&amp;#039;file&amp;#039;} = &amp;#039;chmod 644 %1&amp;#039;,&lt;br /&gt;
$preupload{&amp;#039;deb&amp;#039;} = &amp;#039;chmod 644 %1&amp;#039;,&lt;br /&gt;
$cfg{&amp;#039;tkpack&amp;#039;} = {&lt;br /&gt;
        fqdn =&amp;gt; &amp;quot;192.168.56.102&amp;quot;,&lt;br /&gt;
        method =&amp;gt; &amp;quot;scpb&amp;quot;,&lt;br /&gt;
        login =&amp;gt; &amp;quot;repository&amp;quot;,&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Eigene Ubuntu-Pakete in reprepro Repository hochladen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Linux_file_systems</id>
		<title>Linux file systems</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Linux_file_systems"/>
		<updated>2026-06-30T10:37:36Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;There are numerous &amp;#039;&amp;#039;&amp;#039;file systems&amp;#039;&amp;#039;&amp;#039; for different application purposes. This article includes excerpts highlighting particularly relevant file systems that are also included in the Linux Storage Stack Diagram.  Further file systems are mentioned in the documentation of the Linux kernel.&amp;lt;ref&amp;gt;[https://www.kernel.org/doc/html/latest/filesystems/ Filesystems in the Linux kernel] (www.kernel.org)&amp;lt;/ref&amp;gt;  == File systems for storing data ==  ==...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;There are numerous &amp;#039;&amp;#039;&amp;#039;file systems&amp;#039;&amp;#039;&amp;#039; for different application purposes. This article includes excerpts highlighting particularly relevant file systems that are also included in the [[Linux Storage Stack Diagram|Linux Storage Stack Diagram]]. &lt;br /&gt;
Further file systems are mentioned in the documentation of the Linux kernel.&amp;lt;ref&amp;gt;[https://www.kernel.org/doc/html/latest/filesystems/ Filesystems in the Linux kernel] (www.kernel.org)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== File systems for storing data ==&lt;br /&gt;
&lt;br /&gt;
=== Block-based file systems ===&lt;br /&gt;
The following list displays block-based file systems:&lt;br /&gt;
* [https://docs.kernel.org/filesystems/btrfs.html btrfs] - Copy-on-write file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ext2.html ext2] - New version of extended file system.&lt;br /&gt;
* [https://docs.kernel.org/admin-guide/ext4.html ext4] - An enhanced version of the journal-based ext3 file system with support for large file systems (64-bit).&lt;br /&gt;
* [https://www.kernel.org/doc/html/latest/filesystems/f2fs.html f2fs] - A file system that uses NAND flash storage devices and is based on a log-structured file system (LFS).&lt;br /&gt;
* [https://docs.kernel.org/filesystems/gfs2.html gfs2] - Cluster file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/isofs.html iso9660] - Read-only file system for optical data carrier (CD-ROM, DVD-ROM, Blu-ray Disc etc.).&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ntfs3.html ntfs3] - A fully functional read/write driver for NTFS up to version 3.1.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ocfs2-online-filecheck.html ocfs2] - (Oracle Cluster File System 2) cluster file system from Oracle.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/squashfs.html squashfs] - Comprimized, read-only file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/vfat.html vfat] - File system for Microsoft operating systems. &lt;br /&gt;
* [https://docs.kernel.org/admin-guide/xfs.html xfs] - Journaling file system for Unix-like operating systems developed by Silicon Graphics (SGI) &lt;br /&gt;
&lt;br /&gt;
More details can be found in the article [[Block-based Linux file systems]].&lt;br /&gt;
&lt;br /&gt;
=== Network FS ===&lt;br /&gt;
* ceph&lt;br /&gt;
* coda&lt;br /&gt;
* nfs&lt;br /&gt;
* smbfs&lt;br /&gt;
&lt;br /&gt;
=== Stackable FS ===&lt;br /&gt;
* [https://docs.kernel.org/filesystems/ecryptfs.html ecryptfs] - (Enterprise Cryptographic Filesystem) POSIX-compliant cryptographic stacked file system.&lt;br /&gt;
* [https://docs.kernel.org/filesystems/overlayfs.html overlayfs] - An overlay file system that provides a writable file system on top of another (usually read-only) file system (often used for live CDs).&lt;br /&gt;
&lt;br /&gt;
=== Raw Flash FS ===&lt;br /&gt;
* jffs2&lt;br /&gt;
* ubifs&lt;br /&gt;
&lt;br /&gt;
== More file systems ==&lt;br /&gt;
&lt;br /&gt;
=== Pseudo FS ===&lt;br /&gt;
* futexfs&lt;br /&gt;
* pipefs&lt;br /&gt;
* [https://docs.kernel.org/filesystems/proc.html proc] - (process filesystem) serves as an interface to internal data structures in the kernel. It can be used to obtain information about the system and to change certain kernel parameters at runtime (sysctl).&lt;br /&gt;
* [https://docs.kernel.org/filesystems/sysfs.html sysfs] - RAM-based file system that was originally based on ramfs. It provides the ability to export kernel data structures, their attributes, and the relationships between them to user space.&lt;br /&gt;
* usbfs&lt;br /&gt;
&lt;br /&gt;
=== Special Purpose FS ===&lt;br /&gt;
* devtmpfs&lt;br /&gt;
* ramfs&lt;br /&gt;
* tmpfs&lt;br /&gt;
&lt;br /&gt;
== Einzelnachweise ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category: Linux Basics]]&lt;br /&gt;
[[de:Linux Dateisysteme]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/FSCK_Best_Practices</id>
		<title>FSCK Best Practices</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/FSCK_Best_Practices"/>
		<updated>2026-06-30T08:14:53Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;File system checks (FSCK) verify the consistency of &amp;#039;&amp;#039;&amp;#039;file systems&amp;#039;&amp;#039;&amp;#039;. Generally, a check of journaling file systems such as Ext3, [[Ext4]], or [[XFS]] is performed quickly, since the metadata journal ensures consistency. Nevertheless, there may be situations in which a file system becomes corrupted and must be &amp;#039;&amp;#039;&amp;#039;fixed&amp;#039;&amp;#039;&amp;#039;. A &amp;#039;&amp;#039;&amp;#039;regular FSCK&amp;#039;&amp;#039;&amp;#039; is &amp;#039;&amp;#039;&amp;#039;recommended&amp;#039;&amp;#039;&amp;#039; on server systems to prevent file system problems. &lt;br /&gt;
&lt;br /&gt;
== Periodic check on Ubuntu ==&lt;br /&gt;
Ubuntu has deactivated the periodical file system check (FSCK) with the release of [[Ubuntu]] 12.04 Precise.&amp;lt;ref name=&amp;quot;e2fsprogs&amp;quot;&amp;gt;[https://bugs.launchpad.net/ubuntu/+source/e2fsprogs/+bug/1083985 fsck routine checks on boot are disabled] (launchpad.net)&amp;lt;/ref&amp;gt;&lt;br /&gt;
* Up through Ubuntu 12.04, FSCK was run at regular intervals during system boot. For this, &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt; were set on certain values when generating the file system:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo tune2fs -l /dev/sda1 | egrep -i &amp;quot;mount count|Check interval|Last|Next&amp;quot;&lt;br /&gt;
Mount count:              2&lt;br /&gt;
Maximum mount count:      39&lt;br /&gt;
Last checked:             Mon Jun 29 20:23:44 2015&lt;br /&gt;
Check interval:           15552000 (6 months)&lt;br /&gt;
Next check after:         Sat Dec 26 19:23:44 2015&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Starting on April 12, you will see the following output: a value of -1 for &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt; and a value of 0 for &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt; disable periodic FSCK:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo tune2fs -l /dev/sda1 | egrep -i &amp;quot;mount count|Check interval|Last|Next&amp;quot;&lt;br /&gt;
Last mounted on:          /&lt;br /&gt;
Mount count:              80&lt;br /&gt;
Maximum mount count:      -1&lt;br /&gt;
Last checked:             Fri Jul 18 21:27:32 2014&lt;br /&gt;
Check interval:           0 (&amp;lt;none&amp;gt;)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint:&amp;#039;&amp;#039;&amp;#039; In server environments, it is generally recommended to verify file systems on a regular basis. Further information can be also found in:&lt;br /&gt;
* [https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Storage_Administration_Guide/ch-fsck.html#fsck-best-practices FSCK Best Practices] (redhat.com)&lt;br /&gt;
* [https://access.redhat.com/solutions/39682 Is it advisable to disable filesystem checks?] (redhat.com)&lt;br /&gt;
&lt;br /&gt;
== Enable periodic FSCK == &lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; In some cases, it may be advisable to perform an FSCK manually rather than on a scheduled basis on server systems.  For larger file systems, an FSCK can take quite a while. If a reboot causes the mount count to reach its limit or if you exceed the interval between checks, an FSCK will be performed during boot, during which the server will be unavailable! When performing the FSCK manually, you determine when it runs.&lt;br /&gt;
&lt;br /&gt;
The use of [[LVM basics|LVM]] also allows to dismiss the FSCK on a snapshot. The downtime of the productive file system can be limited to a minimum with that. See also [[#Filesystem check with LVM Snapshot]].&lt;br /&gt;
&lt;br /&gt;
=== Requirement fstab ===&lt;br /&gt;
In fstab, the &amp;#039;&amp;#039;pass&amp;#039;&amp;#039;, or &amp;#039;&amp;#039;fs_passno&amp;#039;&amp;#039;, field must be set right for the periodic check.&amp;lt;ref&amp;gt;[http://linux.die.net/man/5/fstab fstab man Page]&amp;lt;/ref&amp;gt;&lt;br /&gt;
The default value for the root filesystem is 1. It is best to set other filesystems to 2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo vi /etc/fstab&lt;br /&gt;
# / was on /dev/sda1 during installation&lt;br /&gt;
UUID=410ffeb7-f200-4d44-9517-d1b0926bd574 /               ext4    errors=remount-ro 0       1&lt;br /&gt;
# /home was on /dev/sda2 during installation&lt;br /&gt;
UUID=30995b90-3348-4de3-905b-593f7e2de487 /home           ext4    defaults        0       2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configure settings ===&lt;br /&gt;
To enable periodic FSCK at boot time, adjust the values &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt; with tune2fs:&lt;br /&gt;
# &amp;lt;code&amp;gt;max-mount-counts&amp;lt;/code&amp;gt;: Number of mount-processes on which the file system is verified automatically.&lt;br /&gt;
# &amp;lt;code&amp;gt;interval-between-checks&amp;lt;/code&amp;gt;: Maximum time elapsed between two checks.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo tune2fs -c 60 /dev/sda1&lt;br /&gt;
tune2fs 1.42.9 (4-Feb-2014)&lt;br /&gt;
Setting maximal mount count to 60&lt;br /&gt;
$ sudo tune2fs -i 30d /dev/sda1&lt;br /&gt;
tune2fs 1.42.9 (4-Feb-2014)&lt;br /&gt;
Setting interval between checks to 2592000 seconds&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Force FSCK when booting ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint:&amp;#039;&amp;#039;&amp;#039; The settings of the &amp;#039;&amp;#039;pass&amp;#039;&amp;#039;, or also &amp;#039;&amp;#039;fs_passno&amp;#039;&amp;#039;, field ( see [[#Requirement fstab]]) are ignored during a forced FSCK! All file systems listed in fstab are verified.&lt;br /&gt;
&lt;br /&gt;
Up through Ubuntu version 15.10, it was possible to force an FSCK on the next reboot by creating the file /forcefsck. The next boot would then run an FSCK:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo touch /forcefsck&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
From Ubuntu 16.04, this is possible via the following kernel boot parameter (that can be set in the Grub configuration):&amp;lt;ref&amp;gt;[https://ubuntuforums.org/showthread.php?t=2326230&amp;amp;p=13496775#post13496775 forcefsck not working] (ubuntuforums.org, 30.05.2016)&amp;lt;/ref&amp;gt;&lt;br /&gt;
 fsck.mode=force&lt;br /&gt;
&lt;br /&gt;
=== Auto repair ===&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; The following option triggers an auto-repair when errors occur. Automatic error correction is not always desirable or practical in every situation!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo vi /etc/default/rcS&lt;br /&gt;
[...]&lt;br /&gt;
# automatically repair filesystems with inconsistencies during boot&lt;br /&gt;
FSCKFIX=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Standard settings for new file systems ==&lt;br /&gt;
The standard settings for new created file systems can be made in the &amp;#039;&amp;#039;mke2fs.conf&amp;#039;&amp;#039; file. The periodical check of file systems is deactivated via default. To activate it, set &amp;#039;&amp;#039;enable_periodic_fsck&amp;#039;&amp;#039; to 1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo vi /etc/mke2fs.conf&lt;br /&gt;
[defaults]&lt;br /&gt;
        base_features = sparse_super,filetype,resize_inode,dir_index,ext_attr&lt;br /&gt;
        default_mntopts = acl,user_xattr&lt;br /&gt;
        enable_periodic_fsck = 1&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
As a result, the FSCK is set up automatically for new file systems:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo mkfs.ext4 /dev/loop0&lt;br /&gt;
[...]&lt;br /&gt;
This filesystem will be automatically checked every 23 mounts or&lt;br /&gt;
180 days, whichever comes first.  Use tune2fs -c or -i to override.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Manual file system check ==&lt;br /&gt;
A manual file system check for ext4 can be started with fsck.ext4 from the e2fsprogs package.&amp;lt;ref&amp;gt;[http://packages.ubuntu.com/trusty/e2fsprogs Package e2fsprogs] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; The name of the other tools, for example for XFS, can be found in the article [[Linux file systems]]. &lt;br /&gt;
&lt;br /&gt;
Ideally, a FSCK is not only started on mounted file systems. The following is located in the manpage:&amp;lt;ref&amp;gt;[http://linux.die.net/man/8/e2fsck e2fsck man Page] (linux.die.net)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Note that, in general, it is not safe to run e2fsck on mounted filesystems.  The only exception is if the -n option is specified,  and  -c, -l, or -L options are not specified.   However, even if it is safe to do so, the results printed by e2fsck are not valid if the filesystem is mounted.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If the file system is currently in a &amp;#039;&amp;#039;clean&amp;#039;&amp;#039; state, the FSCK must be started with &amp;#039;&amp;#039;-f&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo fsck.ext4  /dev/loop0&lt;br /&gt;
e2fsck 1.42.9 (4-Feb-2014)&lt;br /&gt;
/dev/loop0: clean, 11/7680 files, 2370/30720 blocks&lt;br /&gt;
$ sudo fsck.ext4 -f /dev/loop0&lt;br /&gt;
e2fsck 1.42.9 (4-Feb-2014)&lt;br /&gt;
Pass 1: Checking inodes, blocks, and sizes&lt;br /&gt;
Pass 2: Checking directory structure&lt;br /&gt;
Pass 3: Checking directory connectivity&lt;br /&gt;
Pass 4: Checking reference counts&lt;br /&gt;
Pass 5: Checking group summary information&lt;br /&gt;
/dev/loop0: 11/7680 files (9.1% non-contiguous), 2370/30720 blocks&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Not interactive filesystem check ===&lt;br /&gt;
The option &amp;#039;&amp;#039;-n&amp;#039;&amp;#039; performs a FSCK in read-only mode and assumes &amp;#039;&amp;#039;No&amp;#039;&amp;#039; as the answer to any question that may arise.  The option is therefore suitable for not starting an FSCK interactively, for example regularly and automatized via cron job. Please note that the file system must not be mounted in this case.&lt;br /&gt;
&lt;br /&gt;
== Filesystem check with LVM snapshot ==&lt;br /&gt;
Using LVM allows you to perform file system checks using a snapshot. This means the device being checked does not need to be unmounted for the duration of the check. It is sufficient to unmount the file system being checked in order to create the snapshot. Theoretically, an LVM snapshot of a mounted file system would also be possible. However, the snapshot is only clean and truly consistent if the logical volume is not mounted.&lt;br /&gt;
&lt;br /&gt;
This method for a FSCK using an LVM snapshot is also recommended by Theodore Ts&amp;#039;o in Mailing List Posts.&amp;lt;ref name=&amp;quot;e2fsprogs&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;periodicfsck&amp;quot;&amp;gt;[https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773267 Provide a means to query fsck whether it would run a routine check] (debian.org)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The &amp;#039;&amp;#039;lazy&amp;#039;&amp;#039; option can be helpful if users are currently working with the file system. With a lazy unmount, file system resources are released when they are no longer in use by users. You can also use &amp;#039;&amp;#039;lsof&amp;#039;&amp;#039; beforehand to check whether a file system is currently still in use. In the following example, unmounting is not possible because a user is still in the directory:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# lsof | grep -i mnt&lt;br /&gt;
bash       6963            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
lsof      14456            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
grep      14457            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
lsof      14458            root  cwd       DIR              252,0     1024          2 /mnt&lt;br /&gt;
# umount /mnt&lt;br /&gt;
umount: /mnt: device is busy.&lt;br /&gt;
        (In some cases useful info about processes that use&lt;br /&gt;
         the device is found by lsof(8) or fuser(1))&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; The snapshot must not fill up during the FSCK. Therefore, when creating the snapshot, make sure to choose an appropriate size! In this case, a snapshot size of 20 gigabytes was selected.&lt;br /&gt;
&lt;br /&gt;
The following commands must be used for creating the snapshot and for starting the FSCK:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# umount -l /dev/vg00/data&lt;br /&gt;
# lvcreate -s -n data_snap -L 20G /dev/vg00/data&lt;br /&gt;
# mount /dev/vg00/data /mnt/&lt;br /&gt;
# fsck.ext4 -f /dev/vg00/data_snap&lt;br /&gt;
# lvremove -f /dev/vg00/data_snap&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The advantage of LVM is that the file system can be remounted immediately after the snapshot is created.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Basics]]&lt;br /&gt;
[[de:FSCK Best Practices]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/VMware_Contract_ID</id>
		<title>VMware Contract ID</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/VMware_Contract_ID"/>
		<updated>2026-06-30T05:37:18Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;For the renewal of an existing or soon-to-expire VMware support &amp;amp; subscription contract, the &amp;#039;&amp;#039;&amp;#039;Support Contract ID&amp;#039;&amp;#039;&amp;#039; of the product is required.  This information can be found in your [https://support.broadcom.com/ Broadcom Support Portal] in &amp;#039;&amp;#039;&amp;#039;MyEntitlements.&amp;#039;&amp;#039;&amp;#039;  &amp;lt;gallery width=&amp;quot;1024&amp;quot; height=&amp;quot;820&amp;quot; showcarousel=&amp;quot;false&amp;quot; slideinfozoneopacity=&amp;quot;0.95&amp;quot;&amp;gt; file:Vmware support id 1.png|Select &amp;#039;&amp;#039;&amp;#039;My Entitlements&amp;#039;&amp;#039;&amp;#039; file:Vmware support id 2.png|Select your &amp;#039;&amp;#039;&amp;#039;Site ID&amp;#039;&amp;#039;&amp;#039; , then &amp;#039;&amp;#039;...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For the renewal of an existing or soon-to-expire VMware support &amp;amp; subscription contract, the &amp;#039;&amp;#039;&amp;#039;Support Contract ID&amp;#039;&amp;#039;&amp;#039; of the product is required.&lt;br /&gt;
&lt;br /&gt;
This information can be found in your [https://support.broadcom.com/ Broadcom Support Portal] in &amp;#039;&amp;#039;&amp;#039;MyEntitlements.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery width=&amp;quot;1024&amp;quot; height=&amp;quot;820&amp;quot; showcarousel=&amp;quot;false&amp;quot; slideinfozoneopacity=&amp;quot;0.95&amp;quot;&amp;gt;&lt;br /&gt;
file:Vmware support id 1.png|Select &amp;#039;&amp;#039;&amp;#039;My Entitlements&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
file:Vmware support id 2.png|Select your &amp;#039;&amp;#039;&amp;#039;Site ID&amp;#039;&amp;#039;&amp;#039; , then &amp;#039;&amp;#039;&amp;#039;Entitlement Details&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;Contract Details&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
file:Vmware support id 3.png|You will find the required &amp;#039;&amp;#039;&amp;#039;Contract Number&amp;#039;&amp;#039;&amp;#039; in the left column.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Npauli}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:VMware vSphere 8.0]]&lt;br /&gt;
[[de:VMware Contract ID]]&lt;br /&gt;
[[pl:Przedłużenie wsparcia producenta oraz subskrypcji produktów VMware - VMware Contract ID]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Upgrade_Linux_Mint_Debian_Edition</id>
		<title>Upgrade Linux Mint Debian Edition</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Upgrade_Linux_Mint_Debian_Edition"/>
		<updated>2026-06-29T11:52:39Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;An installation of &amp;#039;&amp;#039;&amp;#039;Linux Mint Debian Edition&amp;#039;&amp;#039;&amp;#039; (LMDE) can be updated to a newer version once it is released. In this example, we present the upgrade from LMDE 6 to LMDE 7.   == Preparation ==  To prepare, the updatetool mintupgrade must be installed:&amp;lt;ref&amp;gt;[https://blog.linuxmint.com/?p=4923 How to upgrade to LMDE 7] (blog.linuxmint.com, 14.10.2025)&amp;lt;/ref&amp;gt;  apt update  apt install mintupgrade  &amp;#039;&amp;#039;&amp;#039;Important note - create backup:&amp;#039;&amp;#039;&amp;#039; Before you continue, we recommend t...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;An installation of &amp;#039;&amp;#039;&amp;#039;[[Linux]] Mint Debian Edition&amp;#039;&amp;#039;&amp;#039; (LMDE) can be updated to a newer version once it is released. In this example, we present the upgrade from LMDE 6 to LMDE 7. &lt;br /&gt;
&lt;br /&gt;
== Preparation == &lt;br /&gt;
To prepare, the updatetool mintupgrade must be installed:&amp;lt;ref&amp;gt;[https://blog.linuxmint.com/?p=4923 How to upgrade to LMDE 7] (blog.linuxmint.com, 14.10.2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
 apt update&lt;br /&gt;
 apt install mintupgrade&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important note - create backup:&amp;#039;&amp;#039;&amp;#039; Before you continue, we recommend to create a recent backup of your data.&lt;br /&gt;
&lt;br /&gt;
== Perform update ==&lt;br /&gt;
Next, start the updatetool:&lt;br /&gt;
 sudo mintupgrade&lt;br /&gt;
&lt;br /&gt;
The following screenshots display the individual steps of the upgrade process:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:LMDE-7-Upgrade-01.png&lt;br /&gt;
File:LMDE-7-Upgrade-02.png&lt;br /&gt;
File:LMDE-7-Upgrade-03.png&lt;br /&gt;
File:LMDE-7-Upgrade-08.png&lt;br /&gt;
File:LMDE-7-Upgrade-09.png&lt;br /&gt;
File:LMDE-7-Upgrade-10.png&lt;br /&gt;
File:LMDE-7-Upgrade-11.png&lt;br /&gt;
File:LMDE-7-Upgrade-12.png&lt;br /&gt;
File:LMDE-7-Upgrade-13.png&lt;br /&gt;
File:LMDE-7-Upgrade-14.png&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cancel and restart upgrade ==&lt;br /&gt;
After this, remove the updatetool and restart the system:&lt;br /&gt;
&lt;br /&gt;
 apt remove mintupgrade&lt;br /&gt;
 sudo reboot&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Mint]]&lt;br /&gt;
[[de:Upgrade Linux Mint Debian Edition]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Installation_of_N8n</id>
		<title>Installation of N8n</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Installation_of_N8n"/>
		<updated>2026-06-19T06:10:54Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;n8n&amp;#039;&amp;#039;&amp;#039; is a performant open-source platform for automatizing workflows. In contrast to cloud services such as Zapier or Make.com, n8n enables self-hostet operation, which allows you to maintain full control over your data, workflows, and costs. &lt;br /&gt;
&lt;br /&gt;
This article describes four different self-contained methods (&amp;quot;paths&amp;quot;) to install n8n on a local Linux server. Select the path that fits best to your use case and follow the steps from beginning to end. &lt;br /&gt;
&lt;br /&gt;
== Requirements == &lt;br /&gt;
=== General requirements (for all methods) ===&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Server:&amp;#039;&amp;#039;&amp;#039; A physical server or a virtual machine. &lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Resources:&amp;#039;&amp;#039;&amp;#039; At least 1 vCPU and 2 GB RAM. 2+ vCPUs and 4+ GB RAM are recommended for productive use.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;User rights:&amp;#039;&amp;#039;&amp;#039; You will require a user with &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt;-rights.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;System updates:&amp;#039;&amp;#039;&amp;#039; It is recommended to update the system in advance:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo apt update &amp;amp;&amp;amp; sudo apt upgrade -y&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Specific software (depending on the path) ===&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;For path 1 &amp;amp; 2 (Docker / Docker Compose):&amp;#039;&amp;#039;&amp;#039; Install the docker engine and the compose plugin via the &amp;#039;&amp;#039;&amp;#039;official docker repositories&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo apt-get remove docker docker-engine docker.io containerd runc &amp;amp;&amp;amp; sudo apt-get autoremove -y&lt;br /&gt;
# 2. Set up Repository and install docker&lt;br /&gt;
sudo apt-get update &amp;amp;&amp;amp; sudo apt-get install -y ca-certificates curl&lt;br /&gt;
sudo install -m 0755 -d /etc/apt/keyrings&lt;br /&gt;
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg&lt;br /&gt;
echo &amp;quot;deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(. /etc/os-release &amp;amp;&amp;amp; echo &amp;quot;$VERSION_CODENAME&amp;quot;) stable&amp;quot; | sudo tee /etc/apt/sources.list.d/docker.list &amp;gt; /dev/null&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin&lt;br /&gt;
# 3. Set permissions (crucial!)&lt;br /&gt;
sudo usermod -aG docker $USER&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important:&amp;#039;&amp;#039;&amp;#039; So that docker permissions work, you have to &amp;#039;&amp;#039;&amp;#039;log out and log in&amp;#039;&amp;#039;&amp;#039; or execute the command &amp;lt;code&amp;gt;newgrp docker&amp;lt;/code&amp;gt; in your current shell. &lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;For path 3 (npm):&amp;#039;&amp;#039;&amp;#039; Install Node.js (v18+) and the package manager npm.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -&lt;br /&gt;
sudo apt-get install -y nodejs&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;For path 4 (Proxmox):&amp;#039;&amp;#039;&amp;#039; A functional Proxmox VE installation is required.&lt;br /&gt;
&lt;br /&gt;
== Installation paths ==&lt;br /&gt;
&lt;br /&gt;
=== Path 1: Docker (fast &amp;amp; simple for tests) ===&lt;br /&gt;
This method is ideal to test n8n fast and uncomplicated.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Create data directory&amp;#039;&amp;#039;&amp;#039; This steps avoids permission issues in the container.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkdir -p ~/.n8n&lt;br /&gt;
sudo chown -R $USER:$USER ~/.n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Start container&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
docker run -d --rm --name n8n -p 5678:5678 -v ~/.n8n:/home/node/.n8n n8nio/n8n:latest&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
n8n is available on &amp;lt;code&amp;gt;http://&amp;lt;Ihre-Server-IP&amp;gt;:5678&amp;lt;/code&amp;gt;. You will see a security warning about &amp;quot;secure cookie&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Resolve access issue&amp;#039;&amp;#039;&amp;#039; You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; Stop the old container (&amp;lt;code&amp;gt;docker stop n8n&amp;lt;/code&amp;gt;) and restart it with additional environment variable.&lt;br /&gt;
This is only suitable for localhost testing!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
docker run -d --rm --name n8n -p 5678:5678 -v ~/.n8n:/home/node/.n8n -e &amp;quot;N8N_SECURE_COOKIE=false&amp;quot; n8nio/n8n:latest&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach using Reverse Proxy (recommended):&amp;#039;&amp;#039;&amp;#039; Set up a reverse proxy to run n8n over HTTPS using a domain.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
=== Path 2: Docker Compose (recommended for productive use) ===&lt;br /&gt;
This method is a robust method and ideal for long-term use, as it clearly divides the data base and n8n.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Create project directory and configuration file&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkdir -p ~/n8n-produktiv&lt;br /&gt;
cd ~/n8n-produktiv&lt;br /&gt;
nano docker-compose.yml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Add content for &amp;lt;code&amp;gt;docker-compose.yml&amp;lt;/code&amp;gt;&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Replace the placeholders for the passwords.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
services:&lt;br /&gt;
  n8n:&lt;br /&gt;
    image: n8nio/n8n:latest&lt;br /&gt;
    ports:&lt;br /&gt;
      - &amp;quot;5678:5678&amp;quot;&lt;br /&gt;
    restart: always&lt;br /&gt;
    environment:&lt;br /&gt;
      - DB_TYPE=postgresdb&lt;br /&gt;
      - DB_POSTGRESDB_HOST=postgres&lt;br /&gt;
      - DB_POSTGRESDB_PORT=5432&lt;br /&gt;
      - DB_POSTGRESDB_DATABASE=n8n&lt;br /&gt;
      - DB_POSTGRESDB_USER=n8n&lt;br /&gt;
      - DB_POSTGRESDB_PASSWORD=IHR_N8N_DB_PASSWORT&lt;br /&gt;
      - GENERIC_TIMEZONE=Europe/Berlin&lt;br /&gt;
    volumes:&lt;br /&gt;
      - n8n_data:/home/node/.n8n&lt;br /&gt;
    depends_on:&lt;br /&gt;
      - postgres&lt;br /&gt;
  postgres:&lt;br /&gt;
    image: postgres:14&lt;br /&gt;
    restart: always&lt;br /&gt;
    environment:&lt;br /&gt;
      - POSTGRES_USER=n8n&lt;br /&gt;
      - POSTGRES_PASSWORD=IHR_N8N_DB_PASSWORT&lt;br /&gt;
      - POSTGRES_DB=n8n&lt;br /&gt;
    volumes:&lt;br /&gt;
      - postgres_data:/var/lib/postgresql/data&lt;br /&gt;
volumes:&lt;br /&gt;
  n8n_data:&lt;br /&gt;
  postgres_data:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Start container&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
docker compose up -d&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
As the port is only connected to 127.0.0.1, n8n is not directly accessible from outside. This is intentional. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 4: Enable access&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; Change the port assignment in the &amp;lt;code&amp;gt;docker-compose.yml&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;&amp;quot;5678:5678&amp;quot;&amp;lt;/code&amp;gt; and add to the &amp;lt;code&amp;gt;environment&amp;lt;/code&amp;gt;-block in n8n the line &amp;lt;code&amp;gt;- N8N_SECURE_COOKIE=false&amp;lt;/code&amp;gt;. Restart with &amp;lt;code&amp;gt;docker compose up -d&amp;lt;/code&amp;gt;.&lt;br /&gt;
This is only suitable for LAN-only test without external accessibility!&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach using Reverse Proxy (recommended): &amp;#039;&amp;#039;&amp;#039;Set up a Reverse Proxy, that forwards the traffic to &amp;lt;code&amp;gt;127.0.0.1:5678&amp;lt;/code&amp;gt;.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
=== Path 3: npm (for developers) ===&lt;br /&gt;
This method installs n8n directly on the host system.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Install n8n globally&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
The global installation requires administrator rights.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
sudo npm install -g n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Start n8n&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Execute the command as normal user.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
n8n is now available on &amp;lt;code&amp;gt;http://&amp;amp;#x3C;Your&amp;lt;nowiki/&amp;gt;-Server-IP&amp;gt;:5678&amp;lt;/code&amp;gt; and displays a safety warning. Terminate the process with &amp;lt;code&amp;gt;Strg+C&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Resolve access issue&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; Start n8n with a preceding environment variable.&lt;br /&gt;
Please note that this is only suitable for localhost tests!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
N8N_SECURE_COOKIE=false n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach with Reverse Proxy (recommended): &amp;#039;&amp;#039;&amp;#039;Let n8n run in the background (for example with &amp;lt;code&amp;gt;pm2&amp;lt;/code&amp;gt; oder &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt;) and set up a Reverse Proxy in front of it.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
=== Path 4: Proxmox Helper Scripts (LXC) ===&lt;br /&gt;
This method creates a dedicated, lean Linux container for n8n. &lt;br /&gt;
&lt;br /&gt;
Attention: We do not recommend this for productive use!&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 1: Execute installation script&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
Execute this command on the &amp;#039;&amp;#039;&amp;#039;Proxmox-Host&amp;#039;&amp;#039;&amp;#039; shell and follow the interactive dialogue.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
bash -c &amp;quot;$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/ct/n8n.sh)&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 2: Test access&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
After the installation, the script outputs the IP address of the container. n8n is available on &amp;lt;code&amp;gt;http://&amp;lt;IP-des-LXC-Containers&amp;gt;:5678&amp;lt;/code&amp;gt; and displays the safety warning.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Step 3: Resolve access issue&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
You have two possibilities:&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;A) Fast workaround (unsafe):&amp;#039;&amp;#039;&amp;#039; The environment variable must be configured directly in the container.&lt;br /&gt;
This is only suitable for LAN-tests without external availability!&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# 1. Verbinden Sie sich mit der Shell des n8n-Containers&lt;br /&gt;
ssh root@&amp;lt;IP-des-LXC-Containers&amp;gt;&lt;br /&gt;
# 2. Öffnen Sie die systemd-Service-Datei&lt;br /&gt;
nano /etc/systemd/system/n8n.service&lt;br /&gt;
# 3. Fügen Sie unter dem Abschnitt [Service] folgende Zeile hinzu:&lt;br /&gt;
Environment=&amp;quot;N8N_SECURE_COOKIE=false&amp;quot;&lt;br /&gt;
# 4. Speichern, schließen und die Dienste neu laden/starten&lt;br /&gt;
systemctl daemon-reload &amp;amp;&amp;amp; systemctl restart n8n&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;B) Secure approach with Reverse Proxy (recommended):&amp;#039;&amp;#039;&amp;#039; Set up a Reverse Proxy on another server or in another container that forwards the traffic to &amp;lt;code&amp;gt;http://&amp;lt;IP-des-LXC-Containers&amp;gt;:5678&amp;lt;/code&amp;gt;.&lt;br /&gt;
:&amp;#039;&amp;#039;&amp;#039;Detailed instructions: [[Installation of Reverse Proxy for n8n with Nginx Proxy Manager]]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
* [https://docs.n8n.io/hosting/self-hosted/ n8n Documentation – Self‑Hosted] (en)&lt;br /&gt;
* [https://github.com/n8n-io/n8n n8n auf GitHub] (en)&lt;br /&gt;
* [https://tteck.github.io/Proxmox/ Proxmox VE Helper-Scripts von tteck] (en)&lt;br /&gt;
&lt;br /&gt;
{{fmueller}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Automation]]&lt;br /&gt;
[[Category:Artificial Intelligence]]&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[Category:VMs/Containers]]&lt;br /&gt;
[[de:N8n installieren]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Creation_of_Proxmox_HA_cluster</id>
		<title>Creation of Proxmox HA cluster</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Creation_of_Proxmox_HA_cluster"/>
		<updated>2026-06-18T10:12:06Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes the configuration of a &amp;#039;&amp;#039;&amp;#039;High Availability Cluster&amp;#039;&amp;#039;&amp;#039; or &amp;#039;&amp;#039;&amp;#039;HA Cluster&amp;#039;&amp;#039;&amp;#039; using three servers with &amp;#039;&amp;#039;&amp;#039;Proxmox&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;VE&amp;#039;&amp;#039;&amp;#039; 8.2.2. In this example, Ceph is configured within the cluster as the data storage.  ==Requirements for High Availability== Before configuring the HA cluster, it must be verified if all requirements are fulfilled: *3 server systems identical in design  * all nodes must be located in the same system * date and time must be sy...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes the configuration of a &amp;#039;&amp;#039;&amp;#039;High Availability Cluster&amp;#039;&amp;#039;&amp;#039; or &amp;#039;&amp;#039;&amp;#039;HA Cluster&amp;#039;&amp;#039;&amp;#039; using three servers with &amp;#039;&amp;#039;&amp;#039;Proxmox&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;VE&amp;#039;&amp;#039;&amp;#039; 8.2.2. In this example, [[Ceph]] is configured within the cluster as the data storage.&lt;br /&gt;
&lt;br /&gt;
==Requirements for High Availability==&lt;br /&gt;
Before configuring the HA cluster, it must be verified if all requirements are fulfilled:&lt;br /&gt;
*3 server systems identical in design &lt;br /&gt;
* all nodes must be located in the same system&lt;br /&gt;
* date and time must be synchronized (NTP)&lt;br /&gt;
* SSH must be released for SSH on port 22&lt;br /&gt;
&lt;br /&gt;
==Installation and configuration==&lt;br /&gt;
First, Proxmox must be installed on all 3 nodes. Please make sure that you have entered the correct host name and IP configuration.&lt;br /&gt;
&lt;br /&gt;
=== Network configuration === &lt;br /&gt;
After that, the network configuration of all nodes must be made. The following steps must be executed after the installation has been successful:&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:Initiale Netzwerkkonfiguration.png|First, select the host name and click on &amp;#039;&amp;#039;&amp;#039;[Network]&amp;#039;&amp;#039;&amp;#039;. Next, you will see the initial network configuration, which can be adjusted according to your requirements. &lt;br /&gt;
file:Netzwerkkonfiguration PVE.png|After that, the changes are applied by clicking on &amp;#039;&amp;#039;&amp;#039;[Apply]&amp;#039;&amp;#039;&amp;#039;. This process must be repeated on the remaining nodes.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now, the network configuration can be verified with a ping test. You can also test the ping with jumbo frames, if configured. The following command would test this with an MTU configured to 9000 bytes:&amp;lt;pre&amp;gt;&lt;br /&gt;
ping -M do -s 8972 [IP-Adresse]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Create Proxmox VE cluster===&lt;br /&gt;
The following steps must be executed to create the cluster:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:Create PVE Cluster.png|Go to &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[Cluster]&amp;#039;&amp;#039;&amp;#039; and click on &amp;#039;&amp;#039;&amp;#039;[Create Cluster]&amp;#039;&amp;#039;&amp;#039;. Now, a pop-up appears where a   &amp;#039;&amp;#039;&amp;#039;Clustername&amp;#039;&amp;#039;&amp;#039; and the &amp;#039;&amp;#039;&amp;#039;Network&amp;#039;&amp;#039;&amp;#039; are entered for the PVE-cluster. By clicking on  &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039; , the cluster is created. &lt;br /&gt;
file:PVE Cluster Join Information .png|Now you can copy the join information by selecting the &amp;#039;&amp;#039;&amp;#039;[Join Information]&amp;#039;&amp;#039;&amp;#039; option and clicking &amp;#039;&amp;#039;&amp;#039;[Copy Information]&amp;#039;&amp;#039;&amp;#039;. This step is required for adding the remaining nodes.  &lt;br /&gt;
file:PVE Cluster Join.png|To add the remaining nodes to the cluster, connect to their GUI and under &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[Cluster]&amp;#039;&amp;#039;&amp;#039;, click &amp;#039;&amp;#039;&amp;#039;[Join Cluster]&amp;#039;&amp;#039;&amp;#039;. After that, the join information, the password and the network can be entered. By clicking on &amp;#039;&amp;#039;&amp;#039;[Join &amp;#039;Clustername&amp;#039;],&amp;#039;&amp;#039;&amp;#039; the host is added. Repeat this process for the remaining servers. &lt;br /&gt;
file:PVE Cluster Final.png|The overview should look similar to this.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint for a cluster with a lot of nodes:&amp;#039;&amp;#039;&amp;#039; For clusters with a large number of nodes (25 or more), enter all nodes in the local hosts file on each cluster node. Otherwise, it may come to high network traffic and stability problems.&lt;br /&gt;
&lt;br /&gt;
===Add Ceph storage===&lt;br /&gt;
To create a Ceph storage for storing all data, the following steps must be performed:&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:1 Ceph Installation.png|Select a node here and click on &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;[Install Ceph]&amp;#039;&amp;#039;&amp;#039; to start the installation.&lt;br /&gt;
file:Ceph Network.png|After the installation has been completed, the &amp;#039;&amp;#039;&amp;#039;Ceph-Network&amp;#039;&amp;#039;&amp;#039; can be stated. In addition, you can also set the number of &amp;#039;&amp;#039;&amp;#039;replicates&amp;#039;&amp;#039;&amp;#039; here. Click on &amp;#039;&amp;#039;&amp;#039;[Next]&amp;#039;&amp;#039;&amp;#039; to complete the configuration. This process is repeated for all nodes.  &lt;br /&gt;
file:Ceph MON MGR.png|Next, some services must be configured for Ceph.  The first are the monitoring and management services. For this, click &amp;#039;&amp;#039;&amp;#039;[Ceph],&amp;#039;&amp;#039;&amp;#039; then  &amp;#039;&amp;#039;&amp;#039;[Monitor]&amp;#039;&amp;#039;&amp;#039; and then &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039; in Monitor and Manager. In this example, one service is created per host. &lt;br /&gt;
file:Ceph MON MGR done.png|The result should look similar to this image.&lt;br /&gt;
file:Disk Wipe GPT.png|The HDDs/SSDs/NVMes must be prepared for the creation of the OSDs.  To do this, delete them under &amp;#039;&amp;#039;&amp;#039;[Disks]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[Wipe Disk]&amp;#039;&amp;#039;&amp;#039; and initialize them with GPT &amp;#039;&amp;#039;&amp;#039;[Initialize Disk with GPT]&amp;#039;&amp;#039;&amp;#039;. Repeat this with all data carriers. &lt;br /&gt;
file:Ceph OSD.png|Now, you can create the OSDs under  &amp;#039;&amp;#039;&amp;#039;[Ceph]&amp;#039;&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;[OSD]&amp;#039;&amp;#039;&amp;#039; by clicking on &amp;#039;&amp;#039;&amp;#039;[Create: OSD].&amp;#039;&amp;#039;&amp;#039; Select the disk and a device class and confirm it by clicking on &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039;. This must be repeated for all data carriers. &lt;br /&gt;
file:MDS Erstellung.png|After creating the OSD, a Meta Data server can be created under &amp;#039;&amp;#039;&amp;#039;[CephFS].&amp;#039;&amp;#039;&amp;#039; These are required for CephFS. For this, click on  &amp;#039;&amp;#039;&amp;#039;[Create].&amp;#039;&amp;#039;&amp;#039; In this example, a MDS host is created per host&amp;#039;&amp;#039;&amp;#039;.&amp;#039;&amp;#039;&amp;#039; &lt;br /&gt;
file:CephFS.png|You can now create CephFS by clicking &amp;#039;&amp;#039;&amp;#039;[Create CephFS]&amp;#039;&amp;#039;&amp;#039;. You can use the default values here.&lt;br /&gt;
file:Ceph Pool erstellen.png|Finally, a pool must be created to store all data from the VMs/CTs. For this, switch to  &amp;#039;&amp;#039;&amp;#039;[Pools]&amp;#039;&amp;#039;&amp;#039; and click &amp;#039;&amp;#039;&amp;#039;[Create]&amp;#039;&amp;#039;&amp;#039;. Next, you must assign a pool name; you can also set a &amp;#039;&amp;#039;&amp;#039;target ratio&amp;#039;&amp;#039;&amp;#039; of &amp;#039;&amp;#039;&amp;#039;0.9&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
file:Ceph Health Status.png|Finally, you can check the Ceph dashboard, and everything should be showing as Healthy.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Configuration High Availability ===&lt;br /&gt;
Now you can create the required virtual machines and containers on the cluster. To take advantage of the cluster&amp;#039;s high availability, it is essential that the configured VMs/CTs are added to the HA. To set this up, follow the steps below:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
file:Add VM to HA.png|Go to &amp;#039;&amp;#039;&amp;#039;[Datacenter]&amp;#039;&amp;#039;&amp;#039; and click on &amp;#039;&amp;#039;&amp;#039;[HA]&amp;#039;&amp;#039;&amp;#039;. You can now add the VM to HA by clicking &amp;#039;&amp;#039;&amp;#039;[Add]&amp;#039;&amp;#039;&amp;#039;. To do so, enter the VM ID and a request state, then confirm by clicking &amp;#039;&amp;#039;&amp;#039;[Add]&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After all steps have been executed, the cluster is functional and your virtual instance is highly available.&lt;br /&gt;
&lt;br /&gt;
{{Npauli}}&lt;br /&gt;
{{Tlindinger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Proxmox Administration]]&lt;br /&gt;
[[de:Proxmox HA Cluster erstellen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/LVM_basic_configuration</id>
		<title>LVM basic configuration</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/LVM_basic_configuration"/>
		<updated>2026-06-18T07:09:52Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the following article, the &amp;#039;&amp;#039;&amp;#039;basic configuration&amp;#039;&amp;#039;&amp;#039; of LVs is explained. The used system is a &amp;#039;&amp;#039;&amp;#039;Ubuntu Server 10.4&amp;#039;&amp;#039;&amp;#039; with the 2.6.32-24 kernel and the LVM-version 2.02.54(1) (2009-10-26). In the following, it is explained how to create &amp;#039;&amp;#039;&amp;#039;partitions&amp;#039;&amp;#039;&amp;#039; of &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Physical Volumes&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (PVs), a &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Volume Group&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (VG) and the &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Logical Volumes&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; (LVs) built on top of them.&lt;br /&gt;
&lt;br /&gt;
==Creating partitions== &lt;br /&gt;
First, the partitions for the PVs are created. The following points must be taken into account:&lt;br /&gt;
&lt;br /&gt;
*[[Partition Alignment]]&lt;br /&gt;
**Switch display to sectors (Switch &amp;quot;-u&amp;quot;)&lt;br /&gt;
**switch off DOS-compatible mode (Switch &amp;quot;-c&amp;quot;)&lt;br /&gt;
*for later LVM management&lt;br /&gt;
**switch system ID of partition to &amp;quot;8e&amp;quot; (Switch &amp;quot;-t&amp;quot; bei fdisk)&lt;br /&gt;
After the changes, the partition table looks as follows: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:/home/tktest# fdisk -lu&lt;br /&gt;
&lt;br /&gt;
Disk /dev/sda: 5368 MB, 5368709120 bytes&lt;br /&gt;
255 heads, 63 sectors/track, 652 cylinders, total 10485760 sectors&lt;br /&gt;
Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;br /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;br /&gt;
Disk identifier: 0x00051afd&lt;br /&gt;
&lt;br /&gt;
   Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;
/dev/sda1   *        2048     9920511     4959232   83  Linux&lt;br /&gt;
Partition 1 does not end on cylinder boundary.&lt;br /&gt;
/dev/sda2         9922558    10483711      280577    5  Extended&lt;br /&gt;
Partition 2 does not end on cylinder boundary.&lt;br /&gt;
/dev/sda5         9922560    10483711      280576   82  Linux swap / Solaris&lt;br /&gt;
&lt;br /&gt;
Disk /dev/sdb: 2147 MB, 2147483648 bytes&lt;br /&gt;
22 heads, 16 sectors/track, 11915 cylinders, total 4194304 sectors&lt;br /&gt;
Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;br /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;br /&gt;
Disk identifier: 0x1673663d&lt;br /&gt;
&lt;br /&gt;
   Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;
/dev/sdb1            2048     4194303     2096128   8e  Linux LVM&lt;br /&gt;
&lt;br /&gt;
Disk /dev/sdc: 2147 MB, 2147483648 bytes&lt;br /&gt;
22 heads, 16 sectors/track, 11915 cylinders, total 4194304 sectors&lt;br /&gt;
Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;br /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;br /&gt;
Disk identifier: 0xbd277faf&lt;br /&gt;
&lt;br /&gt;
   Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;
/dev/sdc1            2048     4194303     2096128   8e  Linux LVM&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Preparation of PVs==&lt;br /&gt;
PVs also include meta data for the administration of volumes (see also [[LVM basics]]). 255 sectors (á 512 byte) are created for the meta data by default. Among other things, a meta data area that is too small can result in, for example, the inability to create snapshots anymore: [[Fix LVM VG vgname metadata too large for circular buffer]]. Therefore, it will make sense to configure a larger meta data area. If you want to enlargen your meta data area, the parameter &amp;quot;--metadatasize&amp;quot; must be added to the command &amp;quot;pvcreate&amp;quot; and then select the desired size at:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
--metadatasize size&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After that, the partitions are initialized as PV.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvcreate /dev/sdb1 &lt;br /&gt;
  Physical volume &amp;quot;/dev/sdb1&amp;quot; successfully created&lt;br /&gt;
root@ubuntu:~# pvcreate /dev/sdc1 &lt;br /&gt;
  Physical volume &amp;quot;/dev/sdc1&amp;quot; successfully created&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The commands &amp;quot;pvs&amp;quot; and &amp;quot;pvdisplay&amp;quot; offer a variety of possibilities to display the current status of the PVs. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvs&lt;br /&gt;
  PV         VG   Fmt  Attr PSize PFree&lt;br /&gt;
  /dev/sdb1       lvm2 --   2.00g 2.00g&lt;br /&gt;
  /dev/sdc1       lvm2 --   2.00g 2.00g&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Creating a VG==&lt;br /&gt;
The PVs, that have been created before, are now summarized to a VG.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# vgcreate vg00 /dev/sdb1 /dev/sdc1 &lt;br /&gt;
  Volume group &amp;quot;vg00&amp;quot; successfully created&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The  &amp;quot;pvdisplay&amp;quot; now shows that a VG was created with the PVs:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvdisplay &lt;br /&gt;
  --- Physical volume ---&lt;br /&gt;
  PV Name               /dev/sdb1&lt;br /&gt;
  VG Name               vg00&lt;br /&gt;
  PV Size               2.00 GiB / not usable 3.00 MiB&lt;br /&gt;
  Allocatable           yes &lt;br /&gt;
  PE Size               4.00 MiB&lt;br /&gt;
  Total PE              511&lt;br /&gt;
  Free PE               511&lt;br /&gt;
  Allocated PE          0&lt;br /&gt;
  PV UUID               fl9ipM-bhhQ-V46G-2iH3-R3yZ-9DsN-JbRmY9&lt;br /&gt;
   &lt;br /&gt;
  --- Physical volume ---&lt;br /&gt;
  PV Name               /dev/sdc1&lt;br /&gt;
  VG Name               vg00&lt;br /&gt;
  PV Size               2.00 GiB / not usable 3.00 MiB&lt;br /&gt;
  Allocatable           yes &lt;br /&gt;
  PE Size               4.00 MiB&lt;br /&gt;
  Total PE              511&lt;br /&gt;
  Free PE               511&lt;br /&gt;
  Allocated PE          0&lt;br /&gt;
  PV UUID               d1iY5L-ac3F-W5Sz-zyaE-uaT3-f66r-I3831o&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
vgdisplay also shows information on VG: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# vgdisplay &lt;br /&gt;
  --- Volume group ---&lt;br /&gt;
  VG Name               vg00&lt;br /&gt;
  System ID             &lt;br /&gt;
  Format                lvm2&lt;br /&gt;
  Metadata Areas        2&lt;br /&gt;
  Metadata Sequence No  1&lt;br /&gt;
  VG Access             read/write&lt;br /&gt;
  VG Status             resizable&lt;br /&gt;
  MAX LV                0&lt;br /&gt;
  Cur LV                0&lt;br /&gt;
  Open LV               0&lt;br /&gt;
  Max PV                0&lt;br /&gt;
  Cur PV                2&lt;br /&gt;
  Act PV                2&lt;br /&gt;
  VG Size               3.99 GiB&lt;br /&gt;
  PE Size               4.00 MiB&lt;br /&gt;
  Total PE              1022&lt;br /&gt;
  Alloc PE / Size       0 / 0   &lt;br /&gt;
  Free  PE / Size       1022 / 3.99 GiB&lt;br /&gt;
  VG UUID               YTEj9f-9LCT-EOP5-JBEA-YHSz-c0R1-TMzVmy&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
What stands out here is, that the PE size is 4.00 MiB. Since the lvm2-format, the number of PEs is not limited anymore. According to the Man page of vgcreate, a high number of PEs can slow down the tools. However, the number of pEs does not have influence on the I/O-performance of the Logical Volumes. If you want to change the PE-size, add the parameter to &amp;quot;vgcreate&amp;quot;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
-s, --physicalextentsize PhysicalExtentSize&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Creating LVs==&lt;br /&gt;
&lt;br /&gt;
There are different possibilities to specify the size of the LV to be created. However, all LVs require the parameter &amp;quot;-l&amp;quot; or &amp;quot;-L&amp;quot;.&lt;br /&gt;
*size specification in, for example, Gigabyte: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lvcreate -n data -L1G vg00&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
*Percentage of available storage in the VG:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lvcreate -n data -l100%VG vg00&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
*Percentage of free storage in the VG: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lvcreate -n data -l100%FREE vg00&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The example in progress is continued by dividing the VG into two equally sized LVs:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# lvcreate -n data -l50%VG vg00&lt;br /&gt;
  Logical volume &amp;quot;data&amp;quot; created&lt;br /&gt;
root@ubuntu:~# lvcreate -n data1 -l100%FREE vg00&lt;br /&gt;
  Logical volume &amp;quot;data1&amp;quot; created&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, the status of the Logical Volume can be taken into consideration:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# lvdisplay &lt;br /&gt;
  --- Logical volume ---&lt;br /&gt;
  LV Name                /dev/vg00/data&lt;br /&gt;
  VG Name                vg00&lt;br /&gt;
  LV UUID                S1btrq-zQZQ-h9oU-2VE6-UNoT-hkqB-Fpv7pG&lt;br /&gt;
  LV Write Access        read/write&lt;br /&gt;
  LV Status              available&lt;br /&gt;
  # open                 0&lt;br /&gt;
  LV Size                2.00 GiB&lt;br /&gt;
  Current LE             511&lt;br /&gt;
  Segments               1&lt;br /&gt;
  Allocation             inherit&lt;br /&gt;
  Read ahead sectors     auto&lt;br /&gt;
  - currently set to     256&lt;br /&gt;
  Block device           252:0&lt;br /&gt;
   &lt;br /&gt;
  --- Logical volume ---&lt;br /&gt;
  LV Name                /dev/vg00/data1&lt;br /&gt;
  VG Name                vg00&lt;br /&gt;
  LV UUID                Syaml9-d1Ax-RYTs-tSZy-vEyq-yzqW-VoOddZ&lt;br /&gt;
  LV Write Access        read/write&lt;br /&gt;
  LV Status              available&lt;br /&gt;
  # open                 0&lt;br /&gt;
  LV Size                2.00 GiB&lt;br /&gt;
  Current LE             511&lt;br /&gt;
  Segments               1&lt;br /&gt;
  Allocation             inherit&lt;br /&gt;
  Read ahead sectors     auto&lt;br /&gt;
  - currently set to     256&lt;br /&gt;
  Block device           252:1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Creating file system== &lt;br /&gt;
Now, the LVs can be formatted with a file system and mounted afterwards:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
mkfs.ext4 /dev/vg00/data&lt;br /&gt;
mkdir data&lt;br /&gt;
mount /dev/vg00/data data&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Removing LV==&lt;br /&gt;
If a LV should be removed, it can be removed via lvremove command:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# lvremove /dev/vg00/data_snap &lt;br /&gt;
  Do you really want to remove active logical volume data_snap? [y/n]: y  &lt;br /&gt;
  Logical volume &amp;quot;data_snap&amp;quot; successfully removed &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The LV data_snap does no longer appear as an LV. However, the underlying partition is still listed as a PV:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
  --- Physical volume ---   &lt;br /&gt;
PV Name               /dev/sde1   &lt;br /&gt;
VG Name               vg00   &lt;br /&gt;
PV Size               2.00 GiB / not usable 3.00 MiB   &lt;br /&gt;
Allocatable           yes    &lt;br /&gt;
PE Size               4.00 MiB   &lt;br /&gt;
Total PE              511   &lt;br /&gt;
Free PE               511   &lt;br /&gt;
Allocated PE          0   &lt;br /&gt;
PV UUID               lKEW15-1YHu-dikC-S0Pm-72UJ-UMPg-fgiW0Y&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
If the partition should be released completely, the PV must be removed from the VG first:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# vgreduce vg00 /dev/sde1   &lt;br /&gt;
  Removed &amp;quot;/dev/sde1&amp;quot; from volume group &amp;quot;vg00&amp;quot;&lt;br /&gt;
root@ubuntu:~# pvdisplay&lt;br /&gt;
 &amp;quot;/dev/sde1&amp;quot; is a new physical volume of &amp;quot;2.00 GiB&amp;quot;  &lt;br /&gt;
 --- NEW Physical volume ---&lt;br /&gt;
   PV Name               /dev/sde1&lt;br /&gt;
   VG Name                 &lt;br /&gt;
   PV Size               2.00 GiB&lt;br /&gt;
   Allocatable           NO&lt;br /&gt;
   PE Size               0&lt;br /&gt;
   Total PE              0 &lt;br /&gt;
   Free PE               0&lt;br /&gt;
   Allocated PE          0&lt;br /&gt;
   PV UUID               lKEW15-1YHu-dikC-S0Pm-72UJ-UMPg-fgiW0Y &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, the PV can be also deleted completely to reformat, for example, the hard drive:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@ubuntu:~# pvremove /dev/sde1&lt;br /&gt;
  Labels on physical volume &amp;quot;/dev/sde1&amp;quot; successfully wiped&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:LVM]]&lt;br /&gt;
[[de:LVM Grundkonfiguration]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Linux_performance_analysis_in_60_seconds</id>
		<title>Linux performance analysis in 60 seconds</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Linux_performance_analysis_in_60_seconds"/>
		<updated>2026-06-17T13:17:30Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;When a critical &amp;#039;&amp;#039;&amp;#039;performance issue&amp;#039;&amp;#039;&amp;#039; arises on a [[Linux]] server, there is often little time to analyze the problem in detail. Brendan Gregg, computer performance analyst and kernel engineer, describes in a blog posting and in a video, &amp;#039;&amp;#039;&amp;#039;which Linux commands he uses for the performance analysis in the first 60 seconds&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Commands for performance analysis == &lt;br /&gt;
The following commands are recommended by Brendan Gregg:&amp;lt;ref&amp;gt;[http://techblog.netflix.com/2015/11/linux-performance-analysis-in-60s.html Linux Performance Analysis in 60,000 Milliseconds] (techblog.netflix.com, 30.11.2015)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
uptime&lt;br /&gt;
dmesg | tail&lt;br /&gt;
vmstat 1&lt;br /&gt;
mpstat -P ALL 1&lt;br /&gt;
pidstat 1&lt;br /&gt;
iostat -xz 1&lt;br /&gt;
free -m&lt;br /&gt;
sar -n DEV 1&lt;br /&gt;
sar -n TCP,ETCP 1&lt;br /&gt;
top&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
More information on these commands can be found in the following articles:&lt;br /&gt;
* vmstat: [[Linux Performance Measurements using vmstat]]&lt;br /&gt;
* mpstat: [[Linux CPU performance measurements with mpstat]]&lt;br /&gt;
* iostat: [[Linux I/O Performance measurements with iostat]]&lt;br /&gt;
* free: [[Linux Page Cache Basics]]&lt;br /&gt;
* sar: [[Collect and report Linux System Activity Information with sar]]&lt;br /&gt;
* top: [[Linux-tool top]]&lt;br /&gt;
&lt;br /&gt;
== Video ==&lt;br /&gt;
In this video, Brendan Gregg shows how to execute these commands in 60 seconds:&amp;lt;ref&amp;gt;[http://www.brendangregg.com/blog/2015-12-03/linux-perf-60s-video.html Linux Performance Analysis in 60s (video)] (www.brendangregg.com/blog, 03.12.2015)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#widget:YouTube|id=ZdVpKx6Wmc8}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Performance]]&lt;br /&gt;
[[de:Linux Performance Analyse in 60 Sekunden]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Docker_basics_-_the_most_important_terms</id>
		<title>Docker basics - the most important terms</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Docker_basics_-_the_most_important_terms"/>
		<updated>2026-06-17T12:17:57Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article provides an introduction in Docker and shows useful terms, which can be useful when using Docker and Docker containers:  &amp;lt;pre&amp;gt; # Start container docker container run &amp;lt;IMAGENAME&amp;gt; starts a container based on an image (Example: checkmk/check-mk-raw:2.2.0-latest)   # List containers (active) docker ps displays a list of all containers that are currently active   # List containers (all)  docker ps -all displays all containers on the system including those that ha...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article provides an introduction in Docker and shows useful terms, which can be useful when using Docker and Docker containers:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Start container&lt;br /&gt;
docker container run &amp;lt;IMAGENAME&amp;gt; starts a container based on an image (Example: checkmk/check-mk-raw:2.2.0-latest) &lt;br /&gt;
&lt;br /&gt;
# List containers (active)&lt;br /&gt;
docker ps displays a list of all containers that are currently active &lt;br /&gt;
&lt;br /&gt;
# List containers (all) &lt;br /&gt;
docker ps -all displays all containers on the system including those that have been stopped. &lt;br /&gt;
&lt;br /&gt;
# Stop container &lt;br /&gt;
docker stop &amp;lt;CONTAINER-NAME&amp;gt; stops a container &lt;br /&gt;
&lt;br /&gt;
# Reboot container&lt;br /&gt;
docker restart &amp;lt;CONTAINER-NAME&amp;gt; restarts a Docker container &lt;br /&gt;
&lt;br /&gt;
# Delete container&lt;br /&gt;
docker remove &amp;lt;CONTAINER-NAME&amp;gt; deletes a container &lt;br /&gt;
&lt;br /&gt;
# Display container volume &lt;br /&gt;
docker volume ls displays all created container volumes &lt;br /&gt;
&lt;br /&gt;
# Delete container volume &lt;br /&gt;
docker volume rm &amp;lt;VOLUME-NAME&amp;gt; - deletes a named volume &lt;br /&gt;
&lt;br /&gt;
# Execute container shell command in container&lt;br /&gt;
docker exec &amp;lt;CONTAINER-NAME&amp;gt; &amp;lt;COMMAND&amp;gt; executes the command and displays the output on its own terminal (locally)&lt;br /&gt;
&lt;br /&gt;
# Open the interactive full shell in the container (interactive terminal) &lt;br /&gt;
docker exec -it &amp;lt;CONTAINER-NAME&amp;gt; bash&lt;br /&gt;
&lt;br /&gt;
# Display container logs: &lt;br /&gt;
docker container logs &amp;lt;CONTAINER-NAME&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[de:Docker Grundlagen - die wichtigsten Befehle]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Measuring_TCP_and_UDP_Network_Performance_with_iperf</id>
		<title>Measuring TCP and UDP Network Performance with iperf</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Measuring_TCP_and_UDP_Network_Performance_with_iperf"/>
		<updated>2026-06-17T08:44:44Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;iperf&amp;#039;&amp;#039;&amp;#039;, the open-source tool, allows to measure the maximum TCP and UDP network bandwidth. It is an alternative for netperf&amp;lt;ref&amp;gt;[http://www.netperf.org/ Netperf] (www.netperf.org)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
Iperf is already included in the Debian and Ubuntu repository, which means that an installation is easy possible via &amp;lt;code&amp;gt;apt-get install iperf&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
For RHEL and CentOS, the package is available in the EPEL&amp;lt;ref&amp;gt;[http://dl.fedoraproject.org/pub/epel/6/x86_64/repoview/iperf.html IPerf Paket aus EPEL Repository] (download.fedora.redhat.com)&amp;lt;/ref&amp;gt; repository.&lt;br /&gt;
&lt;br /&gt;
Alternatively, the source code can be downloaded from the IPerf website &amp;lt;ref&amp;gt;[http://sourceforge.net/projects/iperf/files/ IPerf] (sourceforge.net)&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Use ==&lt;br /&gt;
Iperf works according to the client-sever model, which means that the iperf daemon must be started first on a server and then connects to the iperf client. Client and server are included in the same binary. When entering the IP address for the client, be sure to select the one associated with the network interface you want to test.&lt;br /&gt;
&lt;br /&gt;
=== Measure TCP performance ===&lt;br /&gt;
In this case, the TCP performance of a 1 GBit network card is measured.&lt;br /&gt;
&lt;br /&gt;
Server1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server1 ~]# iperf -s&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Server listening on TCP port 5001&lt;br /&gt;
TCP window size: 85.3 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  4] local 192.168.255.1 port 5001 connected with 192.168.255.2 port 39838&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth&lt;br /&gt;
[  4]  0.0-10.0 sec  1.10 GBytes   941 Mbits/sec&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Server2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server2 ~]# iperf -c 192.168.255.1&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Client connecting to 192.168.255.1, TCP port 5001&lt;br /&gt;
TCP window size: 16.0 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  3] local 192.168.255.2 port 39838 connected with 192.168.255.1 port 5001&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth&lt;br /&gt;
[  3]  0.0-10.0 sec  1.10 GBytes   944 Mbits/sec&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Measure UDP performance ===&lt;br /&gt;
The UDP performance is measured on the same system. In this case, the used bandwidth (-b) must be stated. The default here is only 1 MBit per second. &lt;br /&gt;
&lt;br /&gt;
Server1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server1 ~]# iperf -s -u&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Server listening on UDP port 5001&lt;br /&gt;
Receiving 1470 byte datagrams&lt;br /&gt;
UDP buffer size:  126 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  3] local 192.168.255.1 port 5001 connected with 192.168.255.2 port 40612&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth        Jitter   Lost/Total Datagrams&lt;br /&gt;
[  3]  0.0-10.0 sec   889 MBytes   746 Mbits/sec   0.065 ms  621/634707 (0.098%)&lt;br /&gt;
[  3]  0.0-10.0 sec  1 datagrams received out-of-order&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Server2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[root@server2 ~]# iperf -c 192.168.255.1 -u -b 1000M&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
Client connecting to 192.168.255.1, UDP port 5001&lt;br /&gt;
Sending 1470 byte datagrams&lt;br /&gt;
UDP buffer size:  126 KByte (default)&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
[  3] local 192.168.255.2 port 40612 connected with 192.168.255.1 port 5001&lt;br /&gt;
[ ID] Interval       Transfer     Bandwidth&lt;br /&gt;
[  3]  0.0-10.0 sec   890 MBytes   746 Mbits/sec&lt;br /&gt;
[  3] Sent 634708 datagrams&lt;br /&gt;
[  3] Server Report:&lt;br /&gt;
[  3]  0.0-10.0 sec   889 MBytes   746 Mbits/sec   0.065 ms  621/634707 (0.098%)&lt;br /&gt;
[  3]  0.0-10.0 sec  1 datagrams received out-of-order&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Hints for 10G/40G tests ==&lt;br /&gt;
When testing 40 Gbit/s connections, it is possible that an individual CPU-core can become a bottleneck. In this case, it is recommended that several parallel tests are operated on different ports.&lt;br /&gt;
&lt;br /&gt;
More information on this topic can be found, for example, on the following pages:&lt;br /&gt;
* [https://fasterdata.es.net/host-tuning/linux/100g-tuning/ 40G/100G Tuning] (fasterdata.es.net)&lt;br /&gt;
* [https://fasterdata.es.net/performance-testing/network-troubleshooting-tools/iperf/multi-stream-iperf3/ iperf3 at 40Gbps and above] (fasterdata.es.net)&lt;br /&gt;
* [https://calomel.org/network_performance.html Network Tuning and Performance: a simple guide to enhancing network speeds] (calomel.org)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux Networking]]&lt;br /&gt;
[[Category:Linux Performance]]&lt;br /&gt;
[[de:TCP und UDP Netzwerk Performance mit iperf messen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Permanently_Change_the_Root_Data_Directory_in_Docker</id>
		<title>Permanently Change the Root Data Directory in Docker</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Permanently_Change_the_Root_Data_Directory_in_Docker"/>
		<updated>2026-06-17T05:40:20Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article explains how to permanently switch the default root data directory &amp;lt;code&amp;gt;/var/lib/docker/&amp;lt;/code&amp;gt; to a different directory.  == Background information ==  The &amp;lt;code&amp;gt;/var/lib/docker&amp;lt;/code&amp;gt; directory stores all images, volumes from Docker and can grow significantly depending on how many containers are used. The directory is structured as follows:&amp;lt;pre&amp;gt; root@js-checkmk-02:/var/lib/docker# ls buildkit  containers  engine-id  image  network  overlay2  plugins  runt...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article explains how to permanently switch the default root data directory &amp;lt;code&amp;gt;/var/lib/docker/&amp;lt;/code&amp;gt; to a different directory.&lt;br /&gt;
&lt;br /&gt;
== Background information == &lt;br /&gt;
The &amp;lt;code&amp;gt;/var/lib/docker&amp;lt;/code&amp;gt; directory stores all images, volumes from Docker and can grow significantly depending on how many containers are used. The directory is structured as follows:&amp;lt;pre&amp;gt;&lt;br /&gt;
root@js-checkmk-02:/var/lib/docker# ls&lt;br /&gt;
buildkit  containers  engine-id  image  network  overlay2  plugins  runtimes  swarm  tmp  volumes&amp;lt;/pre&amp;gt; You can see that it is used if you, for example, verify the status with df -h:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;root@js-checkmk-02:/var/lib/docker# df -h&lt;br /&gt;
Filesystem      Size  Used Avail Use% Mounted on&lt;br /&gt;
udev            3.9G     0  3.9G   0% /dev&lt;br /&gt;
tmpfs           794M  684K  794M   1% /run&lt;br /&gt;
/dev/sda1        47G  3.8G   41G   9% /&lt;br /&gt;
tmpfs           3.9G     0  3.9G   0% /dev/shm&lt;br /&gt;
tmpfs           5.0M     0  5.0M   0% /run/lock&lt;br /&gt;
/dev/sda15      124M   12M  113M  10% /boot/efi&lt;br /&gt;
tmpfs           794M     0  794M   0% /run/user/0&lt;br /&gt;
tmpfs           794M     0  794M   0% /run/user/1000&lt;br /&gt;
overlay          47G  3.8G   41G   9% /var/lib/docker/overlay2/a6a4203cef42815c7187f584436e5eb9dff385e3ca9c92d597a38806b9dc255d/merged&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
First, &amp;lt;code&amp;gt;docker&amp;lt;/code&amp;gt; must be stopped, which has immediately influence on all active containers. In addition, we install the tool &amp;lt;code&amp;gt;rsync&amp;lt;/code&amp;gt;.&amp;lt;pre&amp;gt;&lt;br /&gt;
root@js-checkmk-02:/# systemctl stop docker &amp;amp;&amp;amp; apt install rsync&lt;br /&gt;
&amp;lt;/pre&amp;gt;After this, it must be communicated to Docker where to find the new data root:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;# Create directory if it has not been created yet&lt;br /&gt;
root@js-checkmk-02:/# mkdir -p /root/docker/root&lt;br /&gt;
&lt;br /&gt;
# Daemon-Datei anlegen in /etc/docker&lt;br /&gt;
root@js-checkmk-02:/# nano /etc/docker/daemon.json&lt;br /&gt;
&lt;br /&gt;
# Please add the following into the file, then adjust your path and store it. In this example, we change it to /root/docker/root&lt;br /&gt;
&lt;br /&gt;
{&lt;br /&gt;
   &amp;quot;data-root&amp;quot;: &amp;quot;/root/docker/root&amp;quot;&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;Next, the whole content of the old docker-root-directory is copied into the new data-root-directory and then the old &amp;lt;code&amp;gt;/var/lib/docker&amp;lt;/code&amp;gt; directory is renamed to &amp;lt;code&amp;gt;/var/lib/docker.old&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;rsync -aP /var/lib/docker/ &amp;quot;/root/docker/root&amp;quot;&lt;br /&gt;
cp -rp /var/lib/docker/* &amp;quot;/root/docker/root&amp;quot;&lt;br /&gt;
mv /var/lib/docker /var/lib/docker.old&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After that, Docker can be restarted and it should be verified if all containers still function:&amp;lt;pre&amp;gt;&lt;br /&gt;
systemctl start docker&lt;br /&gt;
&amp;lt;/pre&amp;gt;If everything functions, the old data-root-directory can be deleted:&amp;lt;pre&amp;gt;&lt;br /&gt;
rm -rf /var/lib/docker.old&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[de:Root Data Directory in Docker dauerhaft ändern]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Checkmk_RAW_Edition_-_Docker_Container_Installation</id>
		<title>Checkmk RAW Edition - Docker Container Installation</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Checkmk_RAW_Edition_-_Docker_Container_Installation"/>
		<updated>2026-06-16T11:51:57Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;These instructions show how to install and start the free RAW-edition on a Debian server.  == Installation == The installation of Docker on a server is a requirement (see Docker installation on Debian 12).  == Container (custom parameter) == Please note: We will provide the default password shortly so that you can log in right away. Otherwise, you may have trouble logging in. Please note that you have to change the following parameters:  * &amp;lt;code&amp;gt;-p 8006:5000&amp;lt;/cod...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;These instructions show how to install and start the free RAW-edition on a [[Debian]] server.&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
The installation of Docker on a server is a requirement (see [[Docker installation on Debian 12]]).&lt;br /&gt;
&lt;br /&gt;
== Container (custom parameter) ==&lt;br /&gt;
Please note: We will provide the default password shortly so that you can log in right away. Otherwise, you may have trouble logging in. Please note that you have to change the following parameters:&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;code&amp;gt;-p 8006:5000&amp;lt;/code&amp;gt; (This is the port for accessing the Web-UI, default is usually 8080:5000)&lt;br /&gt;
* &amp;lt;code&amp;gt;-p 8007:8000&amp;lt;/code&amp;gt; (This is the port for the agent communication, default is usually 8000:8000)&lt;br /&gt;
* &amp;lt;code&amp;gt;-e CMK_PASSWORD=&amp;#039;relation&amp;#039;&amp;lt;/code&amp;gt; (The password for the Web-UI user cmkadmin is set here)&lt;br /&gt;
* &amp;lt;code&amp;gt;-e MAIL_RELAY_HOST=&amp;#039;mail.thomas-krenn.com&amp;#039;&amp;lt;/code&amp;gt; (Please state your mail server if it can be used as relay host) &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
root@js-checkmk-02:/home/tk#  docker container run -dit -p 8006:5000 -p 8007:8000 --tmpfs /opt/omd/sites/cmk/tmp:uid=1000,gid=1000 -v monitoring:/omd/sites --name monitoring -v /etc/localtime:/etc/localtime:ro -e CMK_PASSWORD=&amp;#039;relation&amp;#039; -e MAIL_RELAY_HOST=&amp;#039;mail.thomas-krenn.com&amp;#039; --restart always checkmk/check-mk-raw:2.2.0-latest&lt;br /&gt;
&lt;br /&gt;
Unable to find image &amp;#039;checkmk/check-mk-raw:2.2.0-latest&amp;#039; locally&lt;br /&gt;
2.2.0-latest: Pulling from checkmk/check-mk-raw&lt;br /&gt;
125a6e411906: Pull complete&lt;br /&gt;
1a8b24f9c661: Pull complete&lt;br /&gt;
e005a80d7504: Pull complete&lt;br /&gt;
727db143e9a5: Pull complete&lt;br /&gt;
1c9d1984857d: Pull complete&lt;br /&gt;
6261e32c9473: Pull complete&lt;br /&gt;
Digest: sha256:c75927b694b02fbd748c48f1aa9469964f3c003757ebbd01c17e21daaeb08b20&lt;br /&gt;
Status: Downloaded newer image for checkmk/check-mk-raw:2.2.0-latest&lt;br /&gt;
23a12948f6b3d3a8bb0ed1808a9e4aef6f4183509c14b34de8b84175e7a12a00&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It is searched for the container image online, which will be downloaded. After that, the container will start immediately. You can verify with &amp;lt;code&amp;gt;docker ps&amp;lt;/code&amp;gt;  if everything has functioned:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@js-checkmk-01:~# docker ps&lt;br /&gt;
CONTAINER ID   IMAGE                               COMMAND                  CREATED          STATUS                             PORTS                                                                                            NAMES&lt;br /&gt;
756a5156e143   checkmk/check-mk-raw:2.2.0-latest   &amp;quot;/docker-entrypoint.…&amp;quot;   29 seconds ago   Up 28 seconds (health: starting)   6557/tcp, 0.0.0.0:8000-&amp;gt;8000/tcp, :::8000-&amp;gt;8000/tcp, 0.0.0.0:8080-&amp;gt;5000/tcp, :::8080-&amp;gt;5000/tcp   monitoring&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Webinterface ==&lt;br /&gt;
You can test the Web-UI with &amp;lt;code&amp;gt;http://IP-DES-DOCKER-SERVERS:8006&amp;lt;/code&amp;gt;. Here, we used custom port 8006.&lt;br /&gt;
&lt;br /&gt;
== Login data ==&lt;br /&gt;
You can log in using the following data in the login screen. Please note that the password is the one you set when you first started the container!&lt;br /&gt;
&lt;br /&gt;
* User: cmkadmin&lt;br /&gt;
* Password: relation&lt;br /&gt;
&lt;br /&gt;
{{jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Docker]]&lt;br /&gt;
[[Category:Monitoring]]&lt;br /&gt;
[[de:Checkmk RAW Edition - Docker Container Installation]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Proxmox_Backup_Server_No_Subscription_Update_Repository</id>
		<title>Proxmox Backup Server No Subscription Update Repository</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Proxmox_Backup_Server_No_Subscription_Update_Repository"/>
		<updated>2026-06-16T09:08:21Z</updated>

		<summary type="html">&lt;p&gt;Smueller: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Proxmox Backup Server]] provides different package repositories for installing updates. For production systems, Thomas-Krenn.AG recommends using a [[Proxmox Backup Server Support Subscriptions|Proxmox Backup Server Subscription]].&lt;br /&gt;
&lt;br /&gt;
A valid subscription provides access to the extensively tested Enterprise Repository. Depending on the selected subscription level, technical support from Proxmox is also included. Purchasing a subscription also supports the continuous development of Proxmox Backup Server.&lt;br /&gt;
&lt;br /&gt;
For test and development environments, the publicly available No-Subscription Repository can be used instead. It contains newer packages that have not yet undergone the same extensive testing and validation process as the packages in the Enterprise Repository. Therefore, the No-Subscription Repository is not recommended for production systems.&lt;br /&gt;
&lt;br /&gt;
== Error message without a valid subscription ==&lt;br /&gt;
&lt;br /&gt;
After a default installation, the Enterprise Repository is enabled. If no valid subscription is configured, updating the package lists may result in an error similar to the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Err: https://enterprise.proxmox.com/debian/pbs trixie InRelease&lt;br /&gt;
  401 Unauthorized&lt;br /&gt;
E: Failed to fetch https://enterprise.proxmox.com/debian/pbs/dists/trixie/InRelease&lt;br /&gt;
E: The repository &amp;#039;https://enterprise.proxmox.com/debian/pbs trixie InRelease&amp;#039; is not signed.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this case, the Enterprise Repository must be disabled and the No-Subscription Repository must be configured.&lt;br /&gt;
&lt;br /&gt;
The following configuration applies to Proxmox Backup Server 4.x based on Debian 13 “Trixie”.&lt;br /&gt;
&lt;br /&gt;
== Disable the Enterprise Repository ==&lt;br /&gt;
&lt;br /&gt;
By default, the Enterprise Repository is configured in the following file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/etc/apt/sources.list.d/pbs-enterprise.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The file can be opened using an editor such as &amp;lt;code&amp;gt;nano&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/apt/sources.list.d/pbs-enterprise.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The default repository configuration looks similar to the following:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: https://enterprise.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-enterprise&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To disable the Enterprise Repository, add the following line:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Enabled: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The complete file should then look as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: https://enterprise.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-enterprise&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
Enabled: false&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, the repository file can be removed:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
rm /etc/apt/sources.list.d/pbs-enterprise.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disabling the repository configuration is generally preferable, as it can easily be enabled again later.&lt;br /&gt;
&lt;br /&gt;
== Configure the No-Subscription Repository ==&lt;br /&gt;
&lt;br /&gt;
Create or edit the following file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
nano /etc/apt/sources.list.d/proxmox.sources&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the following content:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: http://download.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-no-subscription&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, the file can be created directly from the command line:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat &amp;gt; /etc/apt/sources.list.d/proxmox.sources &amp;lt;&amp;lt; &amp;#039;EOF&amp;#039;&lt;br /&gt;
Types: deb&lt;br /&gt;
URIs: http://download.proxmox.com/debian/pbs&lt;br /&gt;
Suites: trixie&lt;br /&gt;
Components: pbs-no-subscription&lt;br /&gt;
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg&lt;br /&gt;
EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Verify the repository configuration ==&lt;br /&gt;
&lt;br /&gt;
Update the package lists:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The configured package repositories can be checked using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt policy&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The output should include the No-Subscription Repository for Debian 13 “Trixie”. The Enterprise Repository should no longer be queried.&lt;br /&gt;
&lt;br /&gt;
The system can then be updated:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt update&lt;br /&gt;
apt full-upgrade&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After kernel updates or other system-level updates, the Proxmox Backup Server should be restarted:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
reboot&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Check for outdated repository files ==&lt;br /&gt;
&lt;br /&gt;
After upgrading from Proxmox Backup Server 3 to Proxmox Backup Server 4, repository entries for Debian 12 “Bookworm” may still be present.&lt;br /&gt;
&lt;br /&gt;
All configured repository files can be checked using the following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
grep -R --line-number --extended-regexp \&lt;br /&gt;
  &amp;#039;bookworm|trixie|enterprise\.proxmox|download\.proxmox&amp;#039; \&lt;br /&gt;
  /etc/apt/sources.list \&lt;br /&gt;
  /etc/apt/sources.list.d/ 2&amp;gt;/dev/null&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Outdated entries containing &amp;lt;code&amp;gt;bookworm&amp;lt;/code&amp;gt; must be removed or disabled. Repository entries for different Debian releases must not be mixed.&lt;br /&gt;
&lt;br /&gt;
{{Smueller}}&lt;br /&gt;
[[Category:Proxmox Backupserver]]&lt;br /&gt;
[[de:Proxmox Backup Server No Subscription Update Repository]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Secure_SSH_login_with_2_factor_authentication</id>
		<title>Secure SSH login with 2 factor authentication</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Secure_SSH_login_with_2_factor_authentication"/>
		<updated>2026-06-11T10:08:07Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A SSH shell belongs to the essential management tools on Linux based servers. This shell is already well covered by using certificate based login methods only and by deactivating root logins.&lt;br /&gt;
Furthermore, an additional registration step can be added, for example a one-time password, with a second factor. This further enhances security, as a successful login now relies on something you have (the certificate) and something you know (the one-time password). This article shows how to secure &amp;#039;&amp;#039;&amp;#039;the SSH login with Google Authenticator as second factor&amp;#039;&amp;#039;&amp;#039; on an &amp;#039;&amp;#039;&amp;#039;Ubuntu Server 18.04 LTS&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Preparatory measures == &lt;br /&gt;
First, configure certificate-based authentication on your Ubuntu Server 18.04 LTS system using a [[OpenSSH Public Key Authentifizierung unter Ubuntu|OpenSSH Public Key]].&lt;br /&gt;
&lt;br /&gt;
== libpam-google-authenticator ==&lt;br /&gt;
The following paragraph provides an insight into the Google Authenticator PAM-module and shows the installation and configuration. &lt;br /&gt;
&lt;br /&gt;
=== Integration ===&lt;br /&gt;
The two-factor authentication is connected as PAM module ((Pluggable Authentication Module) to the operating system. &lt;br /&gt;
&lt;br /&gt;
=== Installation ===&lt;br /&gt;
The installation of the PAM module from Google Authenticator can be made on Debian and Ubuntu via apt. It is contained in the official package sources.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;$ sudo apt install libpam-google-authenticator&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compatibility ===&lt;br /&gt;
The authentication via PAM module is compatible with a variety of system services. A lot of steps can therefore be further secured using Google Authenticator. The list command applied to the /etc/pam.d/ directory returns the services and tools currently supported in a base installation of Ubuntu 18.04 LTS Server.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ ls -m /etc/pam.d/&lt;br /&gt;
atd, chfn, chpasswd, chsh, common-account, common-auth, common-password,&lt;br /&gt;
common-session, common-session-noninteractive, cron, login, newusers, other,&lt;br /&gt;
passwd, polkit-1, runuser, runuser-l, sshd, su, sudo, systemd-user, vmtoolsd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
After the PAM module has been installed, it can be presented, initialized and configured as follows:&lt;br /&gt;
&lt;br /&gt;
# Execute Google Authenticator on the console:&lt;br /&gt;
#: $ google-authenticator&lt;br /&gt;
# Do you want authentication tokens to be time-based (y/n)&lt;br /&gt;
#: y, this is used to generate TOTP tokens (time-based one-time password)&lt;br /&gt;
#: n, this generates HOTP tokens (counter-based one-time passwords)&lt;br /&gt;
#: In this case, the TOTP method is used&lt;br /&gt;
# Now, a QR-code is displayed on the SSH-console &lt;br /&gt;
#: Scan this code with a compatible app on your smartphone&lt;br /&gt;
#: Copy and store the keys listed below safely. &lt;br /&gt;
#: With the &amp;#039;&amp;#039;emergency scratch codes,&amp;#039;&amp;#039; the login can be performed without OTP  &lt;br /&gt;
# Update the &amp;#039;&amp;#039;.google_authenticator&amp;#039;&amp;#039; file with this information.&lt;br /&gt;
#: For this, type &amp;#039;&amp;#039;y&amp;#039;&amp;#039;.&lt;br /&gt;
# Confirm all other questions with &amp;#039;&amp;#039;y&amp;#039;&amp;#039; or with &amp;#039;&amp;#039;n&amp;#039;&amp;#039; if you want to use different settings.&lt;br /&gt;
&lt;br /&gt;
== Integration into SSH-login ==&lt;br /&gt;
The Google Authenticator PAM module is fully configured. Now, these services, such as the SSH daemon, can be adjusted to enable a two-factor authentication through it. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Important hint:&amp;#039;&amp;#039;&amp;#039; If the following configuration is made via SSH session, be sure to keep the current session open and test it in parallel with a second session. If the SSH daemon is misconfigured, you will no longer be able to log in.&lt;br /&gt;
&lt;br /&gt;
=== Adjustments in /etc/pam.d/sshd ===&lt;br /&gt;
Open the /etc/pam.d/sshd file with an editor. Comment out the line &amp;#039;&amp;#039;@include common-&amp;#039;&amp;#039;auth and add the line for Google Authenticator below it. Store and close the file afterwards.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
# Standard Un*x authentication.&lt;br /&gt;
#@include common-auth&lt;br /&gt;
[...]&lt;br /&gt;
# Google Authenticator&lt;br /&gt;
auth required pam_google_authenticator.so&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Adjust sshd_config ===&lt;br /&gt;
In the configuration file &amp;#039;&amp;#039;/etc/ssh/sshd_config&amp;#039;&amp;#039;, you can now set &amp;#039;&amp;#039;&amp;#039;ChallengeResponseAuthentication&amp;#039;&amp;#039;&amp;#039; to &amp;#039;&amp;#039;yes&amp;#039;&amp;#039;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
# Change to yes to enable challenge-response passwords (beware issues with&lt;br /&gt;
# some PAM modules and threads)&lt;br /&gt;
ChallengeResponseAuthentication yes&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Also, check that UsePAM is set to yes and add the following line below it: &amp;#039;&amp;#039;&amp;#039;AuthenticationMethods&amp;#039;&amp;#039;&amp;#039;. In this example, an authentication is accepted via public key and one-time password.&amp;lt;ref&amp;gt;[http://manpages.ubuntu.com/manpages/bionic/man5/sshd_config.5.html sshd_config — OpenSSH SSH daemon configuration file] (manpages.ubuntu.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
UsePAM yes&lt;br /&gt;
AuthenticationMethods publickey,keyboard-interactive&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Restart SSH daemon === &lt;br /&gt;
Now, you can restart the SSH daemon to activate the configuration.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;$ sudo systemctl restart sshd.service&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Login process ===&lt;br /&gt;
The following screenshots show the login process of an SSH shell with activated two-factor authentication by Google Authenticator.&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Ubuntu-Bionic-SSH-Login-01.png|Start the SSH session.  You will now be asked for the time-based one-time password. Open your app and enter the six-digit numeric code.&lt;br /&gt;
File:Ubuntu-Bionic-SSH-Login-02.png|After entering TOTP, the login is made on the Ubuntu server 18.04 LTS system.&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:SSH-Login mit 2-Faktor-Authentifizierung absichern]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Restrict_executable_SSH-commands_via_authorized_keys</id>
		<title>Restrict executable SSH-commands via authorized keys</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Restrict_executable_SSH-commands_via_authorized_keys"/>
		<updated>2026-06-11T07:56:38Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot; The &amp;#039;&amp;#039;&amp;#039;OpenSSH&amp;#039;&amp;#039;&amp;#039; secure shell server allows a secure and encrypted remote access on Linux and Unix systems. On the server side, the &amp;#039;&amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039;&amp;#039; file in the &amp;#039;&amp;#039;.ssh&amp;#039;&amp;#039; folder is primarily used for configuring a SSH public key authentication under Ubuntu. Normally, a user is granted &amp;#039;&amp;#039;&amp;#039;full access&amp;#039;&amp;#039;&amp;#039; on the system, on which the authentication was set up. In some cases, such as automatized backup processes, it is useful that the access is restricted to just a...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;OpenSSH&amp;#039;&amp;#039;&amp;#039; secure shell server allows a secure and encrypted remote access on Linux and Unix systems. On the server side, the &amp;#039;&amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039;&amp;#039; file in the &amp;#039;&amp;#039;.ssh&amp;#039;&amp;#039; folder is primarily used for configuring a [[SSH public key authentication under Ubuntu]]. Normally, a user is granted &amp;#039;&amp;#039;&amp;#039;full access&amp;#039;&amp;#039;&amp;#039; on the system, on which the authentication was set up. In some cases, such as automatized backup processes, it is useful that the access is restricted to just a few, or even just a single &amp;#039;&amp;#039;&amp;#039;command&amp;#039;&amp;#039;&amp;#039;. The successful configuration steps are explained in this article.&lt;br /&gt;
&lt;br /&gt;
== Purpose == &lt;br /&gt;
The restriction of executable commands via SSH is mainly used for automatized backups. The dedicated backup users mostly have a private key without key phrase to execute automated backups. On the backup destination server, the public key of the user is added to the &amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039; file so that this user can connect without entering a password. &lt;br /&gt;
&lt;br /&gt;
Strictly speaking, from this point on, the user would actually have full access to the backup server, even though, for example, the &amp;quot;rsync&amp;quot; command is always used. &lt;br /&gt;
&lt;br /&gt;
A command restriction for the user avoids that if the private key is compromised, the backup server is automatically compromised as well. As the user is restricted to a command in the &amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039; file, it is not allowed to execute another command or to establish a terminal session via SSH.&lt;br /&gt;
&lt;br /&gt;
== Restrict to a single command in authorized_keys ==&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;/~/.ssh/authorized_keys&amp;#039;&amp;#039;&amp;#039; file contains the public key of the user that is allowed to connect. (see also [[SSH public key authentication under Ubuntu]]):&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ cat .ssh/authorized_keys &lt;br /&gt;
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCj98R[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
To restrict the user to a single command, the parameter &amp;#039;&amp;#039;&amp;#039;command=&amp;#039;&amp;#039;&amp;#039; is entered before the key. After that, whenever an attempt is made to establish an SSH connection, only this command will be executed, even if, for example, a different command was provided.&amp;lt;ref name=&amp;quot;sshdef&amp;quot;&amp;gt;[http://oreilly.com/catalog/sshtdg/chapter/ch08.html Per-Account Server Configuration] (oreilly.com)&amp;lt;/ref&amp;gt; In the following example, the user &amp;#039;&amp;#039;dailybackup&amp;#039;&amp;#039; is restricted to the &amp;#039;&amp;#039;date&amp;#039;&amp;#039; command for demonstration purposes.&lt;br /&gt;
For this, the &amp;#039;&amp;#039;command=date&amp;#039;&amp;#039; parameter is defined on the SSH-server:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ cat .ssh/authorized_keys &lt;br /&gt;
command=&amp;quot;date&amp;quot; ssh-rsa AAAA[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
From the client computer that connects to the server via SSH, the only command the user can then execute is &amp;#039;&amp;#039;date&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ ssh dailybackup@192.168.56.105&lt;br /&gt;
Wed Apr 30 14:46:53 CEST 2014&lt;br /&gt;
Connection to 192.168.56.105 closed.&lt;br /&gt;
:~$ ssh dailybackup@192.168.56.105 &amp;quot;tail /etc/passwd&amp;quot;&lt;br /&gt;
Wed Apr 30 14:47:02 CEST 2014&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Analyse executed command on SSH-server ==&lt;br /&gt;
The analysis, which command must be entered in &amp;#039;&amp;#039;authorized_keys&amp;#039;&amp;#039;, is made easier by the environment variable &amp;#039;&amp;#039;$SSH_ORIGINAL_COMMAND&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
command=&amp;quot;/bin/echo You invoked: $SSH_ORIGINAL_COMMAND&amp;quot; ssh-rsa AAAAB[..]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
When a command is issued from the client, the command executed on the server is then displayed for analysis purposes:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ ssh dailybackup@192.168.56.105 tail /etc/passwd&lt;br /&gt;
You invoked: tail /etc/passwd&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Some commands, for example &amp;#039;&amp;#039;rsync&amp;#039;&amp;#039;, lead to an error message when used with the above &amp;#039;&amp;#039;command&amp;#039;&amp;#039;. By taking a roundabout route using a script on the SSH server, the command, that was executed, can be also accessed: &amp;lt;ref name=&amp;quot;sshdef&amp;quot; /&amp;gt;&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ vi logssh.sh&lt;br /&gt;
#!/bin/sh&lt;br /&gt;
if [ -n &amp;quot;$SSH_ORIGINAL_COMMAND&amp;quot; ]&lt;br /&gt;
then&lt;br /&gt;
  echo &amp;quot;`/bin/date`: $SSH_ORIGINAL_COMMAND&amp;quot; &amp;gt;&amp;gt; $HOME/ssh-command-log&lt;br /&gt;
  exec $SSH_ORIGINAL_COMMAND&lt;br /&gt;
fi&lt;br /&gt;
:~$ vi .ssh/authorized_keys&lt;br /&gt;
command=&amp;quot;/home/dailybackup/logssh.sh&amp;quot; ssh-rsa AAAAB3N[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The client then calls up rsync: &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~/tmp$ rsync -avz test.txt dailybackup@192.168.56.105:/home/dailybackup&lt;br /&gt;
sending incremental file list&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The command executed via SSH appears in the log file on the SSH server. This command can be used again via &amp;#039;&amp;#039;command=&amp;#039;&amp;#039; for restrictions:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
:~$ cat ssh-command-log &lt;br /&gt;
Wed Apr 30 15:10:54 CEST 2014: rsync --server -vlogDtprze.iLsf . /home/dailybackup&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Hint:&amp;#039;&amp;#039;&amp;#039; For problems with output redirection, &amp;lt;code&amp;gt;exec&amp;lt;/code&amp;gt; can be used instead of &amp;lt;code&amp;gt;eval&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Restrict multiple commands in authorized_keys ==&lt;br /&gt;
In general, it is possible via additional scripts to allow multiple commands for a key pair.&lt;br /&gt;
&lt;br /&gt;
However, for maximum security, it is easier to generate a private key pair for every desired command and to safe the corresponding command.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:Ausführbare SSH-Kommandos per authorized keys einschränken]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OpenSSH_public_key_authentication_fails</id>
		<title>OpenSSH public key authentication fails</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OpenSSH_public_key_authentication_fails"/>
		<updated>2026-06-11T06:25:36Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes how to resolve issues with SSH authentication using public key authentication. In the article SSH key login, it is explained how to set up public key authentication in general.    == Server-side problems ==  In most cases, the reason why public key authentication is not working can be found in the file and directory permissions. The home directory on the server as well as the sub-directory .ssh is not allowed to have writing right...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes how to resolve issues with SSH authentication using public key authentication. In the article [[SSH Key Login|SSH key login]], it is explained how to set up public key authentication in general.  &lt;br /&gt;
&lt;br /&gt;
== Server-side problems == &lt;br /&gt;
In most cases, the reason why public key authentication is not working can be found in the file and directory permissions. The home directory on the server as well as the sub-directory .ssh is not allowed to have writing rights for group and other. Furthermore, the file &amp;lt;code&amp;gt;authorized_keys&amp;lt;/code&amp;gt; must be accessible only to the owner. &lt;br /&gt;
&lt;br /&gt;
To set the rights correctly, log in to the server with the user for whom the SSH authentication should function.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
chmod go-w $HOME $HOME/.ssh&lt;br /&gt;
chmod 600 $HOME/.ssh/authorized_keys&lt;br /&gt;
chown `whoami` $HOME/.ssh/authorized_keys&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If this is not possible, you can alternatively deactivate the right verification of the server. The following option must be entered in the &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt; file:&lt;br /&gt;
 StrictModes no&lt;br /&gt;
&lt;br /&gt;
Another error source can be the wrong settings in &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt;. Here is an extract of options that can influence the public key authentication:&lt;br /&gt;
* AuthorizedKeysFile&lt;br /&gt;
* PreferredAuthentications&lt;br /&gt;
* PubkeyAuthentication&lt;br /&gt;
&lt;br /&gt;
More settings can be found in the &amp;#039;&amp;#039;&amp;#039;man sshd_config&amp;#039;&amp;#039;&amp;#039; manpage.&lt;br /&gt;
&lt;br /&gt;
== Client-sided problems == &lt;br /&gt;
Alternatively, there may still be issues on the client side, that is, on the computer from which the SSH connection is initiated.&lt;br /&gt;
&lt;br /&gt;
If the file rights are set open for the private key, the following error message is displayed by the SSH client:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;
@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @&lt;br /&gt;
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;
Permissions 0777 for &amp;#039;xyz&amp;#039; are too open.&lt;br /&gt;
It is recommended that your private key files are NOT accessible by others.&lt;br /&gt;
This private key will be ignored.&lt;br /&gt;
bad permissions: ignore key: xyz&lt;br /&gt;
Permission denied (publickey,gssapi-with-mic).&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this case, the private key is ignored. Set the rights correctly using the following command: &lt;br /&gt;
 chmod 600 $HOME/.ssh/&amp;lt;Keyname&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Another possible error source could be a wrong setting in &amp;lt;code&amp;gt;.ssh/config&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;/etc/ssh/ssh_config&amp;lt;/code&amp;gt;. An excerpt of possible options that may affect public key authentication, can be found here:&lt;br /&gt;
* PreferredAuthentications&lt;br /&gt;
* PubkeyAuthentication&lt;br /&gt;
&lt;br /&gt;
All settings can be found in the &amp;#039;&amp;#039;&amp;#039;man ssh_config&amp;#039;&amp;#039;&amp;#039; manpage.&lt;br /&gt;
&lt;br /&gt;
== Sources: == &lt;br /&gt;
* http://www.openssh.org/faq.html#3.14&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:OpenSSH Public Key Authentication schlägt fehl]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/AMD_Security_Vulnerabilities_-_June_2026</id>
		<title>AMD Security Vulnerabilities - June 2026</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/AMD_Security_Vulnerabilities_-_June_2026"/>
		<updated>2026-06-10T12:16:49Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;On &amp;#039;&amp;#039;&amp;#039;June 9th, 2026&amp;#039;&amp;#039;&amp;#039;, AMD published the security bulletins &amp;#039;&amp;#039;&amp;#039;AMD-SB-3039&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3039.html ASP non-Coherent Memory Access – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; and &amp;#039;&amp;#039;&amp;#039;AMD-SB-9025&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9025.html AMD uProf Vulnerabilities – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; for security vulnerabili...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On &amp;#039;&amp;#039;&amp;#039;June 9th, 2026&amp;#039;&amp;#039;&amp;#039;, AMD published the security bulletins &amp;#039;&amp;#039;&amp;#039;AMD-SB-3039&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3039.html ASP non-Coherent Memory Access – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; and &amp;#039;&amp;#039;&amp;#039;AMD-SB-9025&amp;#039;&amp;#039;&amp;#039;&amp;lt;ref&amp;gt;[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9025.html AMD uProf Vulnerabilities – June 2026] (www.amd.com/en/resources/product-security)&amp;lt;/ref&amp;gt; for security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
== Information ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;AMD-SB-3039&amp;#039;&amp;#039;&amp;#039;: This is a malicious hypervisor that can undermine the integrity protection mechanisms of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP), by forcing AMD Security Processor (ASP) to work with the system storage without cache coherence. According to the publication, system settings controlled by the hypervisor enable the reconfiguration of the interaction between the storage requirements of the ASP and the CPU-cache. By disabling coherence, the ASP can read stale data from the DRAM when copying pages and updating the associated metadata, causing the guest to lose the most recent updates in the CPU cache. This could potentially undermine the integrity warranties of the SEV-SNP for guests and could cause data corruption.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;AMD-SB-9025&amp;#039;&amp;#039;&amp;#039;: The vulnerability could allow a local attacker with user privileges to write to memory assigned by the kernel. AMD confirms that the issue occurs because from the driver creating a shared-section object with a NULL security descriptor and exposing kernel pointers in shared memory, which could allow an attacker to write to kernel-allocated memory and potentially cause a system crash or a denial-of-service condition.  &lt;br /&gt;
&lt;br /&gt;
== Affected systems ==&lt;br /&gt;
&lt;br /&gt;
Here is a table listing the affected processors. &lt;br /&gt;
&lt;br /&gt;
===== AMD EPYC™ Processors =====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|Product&lt;br /&gt;
|Mitigation&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ 8004 Series Processors&lt;br /&gt;
|GenoaPI&lt;br /&gt;
1.0.0.H&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ 9004 Series Processors&lt;br /&gt;
|GenoaPI&lt;br /&gt;
1.0.0.H&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ 9005 Series Processors&lt;br /&gt;
|TurinPI&lt;br /&gt;
&lt;br /&gt;
1.0.0.8&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 8004 Series Processors&lt;br /&gt;
|EmbGenoaPI-SP5&lt;br /&gt;
&lt;br /&gt;
1.0.0.D&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 9004 Series Processors&lt;br /&gt;
&lt;br /&gt;
(formerly codenamed &amp;quot;Genoa&amp;quot;)&lt;br /&gt;
|EmbGenoaPI-SP5&lt;br /&gt;
&lt;br /&gt;
1.0.0.D&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 9004 Series Processors&lt;br /&gt;
&lt;br /&gt;
(formerly codenamed &amp;quot;Bergamo&amp;quot;)&lt;br /&gt;
|EmbGenoaPI-SP5&lt;br /&gt;
&lt;br /&gt;
1.0.0.D&lt;br /&gt;
|-&lt;br /&gt;
|AMD EPYC™ Embedded 9005 Series Processors&lt;br /&gt;
|EmbeddedTurinPI_SP5&lt;br /&gt;
&lt;br /&gt;
1004&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |CVE&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |CVSS Score&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |[https://www.cve.org/CVERecord?id=CVE-2026-54509 CVE-2025-54509]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |4.0 (Medium)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |[https://www.cve.org/CVERecord?id=CVE-2026-0466 CVE-2026-0466]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |6.8 (Medium)&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |[https://www.cve.org/CVERecord?id=CVE-2026-28237 CVE-2026-28237]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |6.8 (Medium)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
In the following, there is an extract of this table in which all Supermicro mainboards are included that are offered by Thomas-Krenn:&amp;lt;ref&amp;gt;[https://www.supermicro.com/en/support/security_AMD-SB-3027 AMD Security Bulletin AMD-SB-3027, January 2027] (www.supermicro.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!AMD motherboard &lt;br /&gt;
! align=&amp;quot;center&amp;quot; |&amp;#039;&amp;#039;&amp;#039;BIOS version&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |H13SSW&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |3.8&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |H13SSL-N/NT&lt;br /&gt;
| align=&amp;quot;center&amp;quot; |3.8&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Updates for Thomas-Krenn products ===&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;download area of Thomas-Krenn&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The updates in the download area have been tested by us to guarantee the stability and compatibility of our systems. &lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you can get it at &lt;br /&gt;
[https://www.asus.com/de/support/download-center/ Asus], [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro] or [https://www.gigabyte.com/de/Support/Consumer/Download Gigabyte]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information == &lt;br /&gt;
* [https://www.supermicro.com/en/support/security_AMD-SB-3027 AMD Security Bulletin AMD-SB-3039] (supermicro.com, Juni 2026)&lt;br /&gt;
&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:AMD Safety Information]]&lt;br /&gt;
[[de:AMD Sicherheitslücken - Juni 2026]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Slow_SSH_login_due_to_DNS_timeout</id>
		<title>Slow SSH login due to DNS timeout</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Slow_SSH_login_due_to_DNS_timeout"/>
		<updated>2026-06-10T08:52:47Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;This article describes solutions for when an &amp;#039;&amp;#039;&amp;#039;SSH login is slow&amp;#039;&amp;#039;&amp;#039;.  ==Problem== It takes approximately 10 seconds when you log in to a Linux system via SSH until the password prompt appears. After this, the SSH session functions completely normal.  ==Background==  The SSH server tries to make a reverse DNS lookup for the IP from which the SSH connection is established. If there is no functioning configured DNS (for example a wrong registered IP for the DNS server in /...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article describes solutions for when an &amp;#039;&amp;#039;&amp;#039;SSH login is slow&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
==Problem==&lt;br /&gt;
It takes approximately 10 seconds when you log in to a Linux system via SSH until the password prompt appears. After this, the SSH session functions completely normal.&lt;br /&gt;
&lt;br /&gt;
==Background== &lt;br /&gt;
The SSH server tries to make a reverse DNS lookup for the IP from which the SSH connection is established. If there is no functioning configured DNS (for example a wrong registered IP for the DNS server in /etc/resolv.conf), it takes 10 seconds until the timeout is reached for the reverse DNS lookup. Then, the password prompt appears. &lt;br /&gt;
&lt;br /&gt;
In the following, information on the use of &amp;lt;code&amp;gt;ssh -v&amp;lt;/code&amp;gt; (verbose mode) is listed:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[admin@tpw admin]$ ssh -v root@192.168.1.154&lt;br /&gt;
OpenSSH_5.1p1, OpenSSL 0.9.8g 19 Oct 2007&lt;br /&gt;
debug1: Reading configuration data /etc/ssh/ssh_config&lt;br /&gt;
debug1: Applying options for *&lt;br /&gt;
debug1: Connecting to 192.168.1.154 [192.168.1.154] port 22.&lt;br /&gt;
debug1: Connection established.&lt;br /&gt;
debug1: identity file /home/admin/.ssh/identity type -1&lt;br /&gt;
debug1: identity file /home/admin/.ssh/id_rsa type -1&lt;br /&gt;
debug1: identity file /home/admin/.ssh/id_dsa type -1&lt;br /&gt;
debug1: Remote protocol version 2.0, remote software version OpenSSH_5.1p1 Debian-5&lt;br /&gt;
debug1: match: OpenSSH_5.1p1 Debian-5 pat OpenSSH*&lt;br /&gt;
debug1: Enabling compatibility mode for protocol 2.0&lt;br /&gt;
debug1: Local version string SSH-2.0-OpenSSH_5.1&lt;br /&gt;
debug1: SSH2_MSG_KEXINIT sent&lt;br /&gt;
debug1: SSH2_MSG_KEXINIT received&lt;br /&gt;
debug1: kex: server-&amp;gt;client aes128-cbc hmac-md5 none&lt;br /&gt;
debug1: kex: client-&amp;gt;server aes128-cbc hmac-md5 none&lt;br /&gt;
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024&amp;lt;1024&amp;lt;8192) sent&lt;br /&gt;
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP&lt;br /&gt;
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent&lt;br /&gt;
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY&lt;br /&gt;
debug1: Host &amp;#039;192.168.1.154&amp;#039; is known and matches the RSA host key.&lt;br /&gt;
debug1: Found key in /home/admin/.ssh/known_hosts:153&lt;br /&gt;
debug1: ssh_rsa_verify: signature correct&lt;br /&gt;
debug1: SSH2_MSG_NEWKEYS sent&lt;br /&gt;
debug1: expecting SSH2_MSG_NEWKEYS&lt;br /&gt;
debug1: SSH2_MSG_NEWKEYS received&lt;br /&gt;
debug1: SSH2_MSG_SERVICE_REQUEST sent&lt;br /&gt;
debug1: SSH2_MSG_SERVICE_ACCEPT received&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, it takes ten minutes until it continues:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
debug1: Authentications that can continue: publickey,password&lt;br /&gt;
debug1: Next authentication method: publickey&lt;br /&gt;
debug1: Trying private key: /home/admin/.ssh/identity&lt;br /&gt;
debug1: Trying private key: /home/admin/.ssh/id_rsa&lt;br /&gt;
debug1: Trying private key: /home/admin/.ssh/id_dsa&lt;br /&gt;
debug1: Next authentication method: password&lt;br /&gt;
root@192.168.1.154&amp;#039;s password: &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After entering the password, it continues:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
debug1: Authentication succeeded (password).&lt;br /&gt;
debug1: channel 0: new [client-session]&lt;br /&gt;
debug1: Requesting no-more-sessions@openssh.com&lt;br /&gt;
debug1: Entering interactive session.&lt;br /&gt;
debug1: Sending environment.&lt;br /&gt;
debug1: Sending env LANG = en_US.utf8&lt;br /&gt;
Linux debian5 2.6.9-023stab048.6-smp #1 SMP Mon Nov 17 18:41:14 MSK 2008 x86_64&lt;br /&gt;
&lt;br /&gt;
The programs included with the Debian GNU/Linux system are free software;&lt;br /&gt;
the exact distribution terms for each program are described in the&lt;br /&gt;
individual files in /usr/share/doc/*/copyright.&lt;br /&gt;
&lt;br /&gt;
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent&lt;br /&gt;
permitted by applicable law.&lt;br /&gt;
Last login: Wed Jun 17 13:20:19 2009 from 192.168.1.52&lt;br /&gt;
debian5:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Solution==&lt;br /&gt;
On the target system, either add the IP address of the computer from which the connection is being established to /etc/hosts, or make sure that the DNS configuration on the target system is working properly.&lt;br /&gt;
&lt;br /&gt;
===Enter IP in /etc/hosts===&lt;br /&gt;
The IP can be, for example, entered in /etc/hosts as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@debian5:/# echo &amp;quot;192.168.1.52 laptop&amp;quot; &amp;gt;&amp;gt; /etc/hosts&lt;br /&gt;
root@debian5:/# cat /etc/hosts&lt;br /&gt;
127.0.0.1  debian5 localhost localhost.localdomain&lt;br /&gt;
&lt;br /&gt;
::1     localhost ip6-localhost ip6-loopback&lt;br /&gt;
fe00::0 ip6-localnet&lt;br /&gt;
ff00::0 ip6-mcastprefix&lt;br /&gt;
ff02::1 ip6-allnodes&lt;br /&gt;
ff02::2 ip6-allrouters&lt;br /&gt;
ff02::3 ip6-allhosts&lt;br /&gt;
192.168.1.52 laptop&lt;br /&gt;
root@debian5:/# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Verify DNS configuration===&lt;br /&gt;
In the example, an incorrect DNS server was configured on the Debian 5 target system. The configuration was corected as follows:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@debian5:/# cat /etc/resolv.conf &lt;br /&gt;
nameserver 10.10.18.1&lt;br /&gt;
root@debian5:/# echo &amp;quot;nameserver 192.168.1.254&amp;quot; &amp;gt; /etc/resolv.conf&lt;br /&gt;
root@debian5:/# cat /etc/resolv.conf &lt;br /&gt;
nameserver 192.168.1.254&lt;br /&gt;
root@debian5:/# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==More information==&lt;br /&gt;
* [http://www.macosxhints.com/article.php?story=20050329185832952 macosxhints.com: A possible fix for slow SSH connections ]&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[pl:Logowanie przez ssh powolne przez DNS Timeout]]&lt;br /&gt;
[[de:SSH Login langsam durch DNS Timeout]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/OpenSSH_configuration</id>
		<title>OpenSSH configuration</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/OpenSSH_configuration"/>
		<updated>2026-06-10T06:30:22Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;The following configuration describes advanced OpenSSH configurations that can be expaned as needed. If you have more interesting contents, kindly send us a message.  An overview of all server-side SSH configuration options can be found in the manpage of sshd_config.  man sshd_config  === Conditional configuration with &amp;quot;Match&amp;quot; === &amp;quot;Match&amp;quot;, the configuration option, allows a global configuration (for example in &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt;) to ove...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The following configuration describes advanced OpenSSH configurations that can be expaned as needed. If you have more interesting contents, kindly send us a [[Special:contact|message]].&lt;br /&gt;
&lt;br /&gt;
An overview of all server-side SSH configuration options can be found in the manpage of sshd_config.&lt;br /&gt;
 man sshd_config&lt;br /&gt;
&lt;br /&gt;
=== Conditional configuration with &amp;quot;Match&amp;quot; ===&lt;br /&gt;
&amp;quot;Match&amp;quot;, the configuration option, allows a global configuration (for example in &amp;lt;code&amp;gt;/etc/ssh/sshd_config&amp;lt;/code&amp;gt;) to overwrite one that is conditional. The following conditions are possible:&lt;br /&gt;
* User&lt;br /&gt;
* Group&lt;br /&gt;
* Host&lt;br /&gt;
* Address[&lt;br /&gt;
&lt;br /&gt;
Here is an example for a configuration in /etc/ssh/sshd_config:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
PasswordAuthentication no&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
Match User admin&lt;br /&gt;
        PasswordAuthentication yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this case, the password authentication is deactivated globally. However, it was subsequently enabled for the &amp;quot;admin&amp;quot; user using a MATCH statement.&lt;br /&gt;
&lt;br /&gt;
In general, &amp;quot;Match&amp;quot; is only for one option allowed:&lt;br /&gt;
&lt;br /&gt;
AllowAgentForwarding, AllowTcpForwarding, Banner, ChrootDirectory, ForceCommand, GatewayPorts, GSSAPIAuthentication, HostbasedAuthentication, KbdInteractiveAuthentication, KerberosAuthentication, MaxAuthTries, MaxSessions, PasswordAuthentication, PermitEmptyPasswords, PermitOpen, PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication, RSAAuthentication, X11DisplayOffset, X11Forwarding und X11UseLocalHost&lt;br /&gt;
&lt;br /&gt;
=== VPN with OpenSSH ===&lt;br /&gt;
OpenSSH offers from version 4.3 the opportunity to set up a VPN tunnel. This creates a tun device on both the local and remote sides. As soon as it has been configured, the VPN can be used.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;uml-utilities&amp;quot; package must be installed in advance on Ubuntu/Debian. This comes with the &amp;#039;&amp;#039;&amp;#039;tunctl&amp;#039;&amp;#039;&amp;#039; binary.&lt;br /&gt;
&lt;br /&gt;
The SSH sever configuration &amp;#039;&amp;#039;&amp;#039;sshd_config&amp;#039;&amp;#039;&amp;#039; must be expanded by the following options:&lt;br /&gt;
 PermitRootLogin yes&lt;br /&gt;
 PermitTunnel yes&lt;br /&gt;
&lt;br /&gt;
A tunnel can be set up with the option &amp;#039;&amp;#039;&amp;#039;&amp;quot;-w&amp;quot;&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
 ssh -w 0:0 1.2.3.4&lt;br /&gt;
&lt;br /&gt;
After this, a &amp;quot;tun0&amp;quot; interface should be visible on both sides. An IP address must then be assigned to it.&lt;br /&gt;
&lt;br /&gt;
You may need to enable IP forwarding.&lt;br /&gt;
 echo 1 &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
&lt;br /&gt;
For long-term VPN use, we recommend the use of [[OpenVPN with Pre-shared Key|OpenVPN]], which is much easier to configure and automate.&lt;br /&gt;
&lt;br /&gt;
More information can be found here: https://help.ubuntu.com/community/SSH_VPN&lt;br /&gt;
&lt;br /&gt;
{{Cmitasch}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[de:OpenSSH Konfiguration]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Samba-server_basics</id>
		<title>Samba-server basics</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Samba-server_basics"/>
		<updated>2026-06-09T11:35:50Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;A &amp;#039;&amp;#039;&amp;#039;Samba-Server&amp;#039;&amp;#039;&amp;#039; helps with the integration of &amp;#039;&amp;#039;&amp;#039;Windows- and Unix/Linux computers&amp;#039;&amp;#039;&amp;#039;.&amp;lt;ref&amp;gt;[http://www.oreilly.de/german/freebooks/samba2ger/ch01.html#936841 Samba, 2. Auflage] www.oreilly.de&amp;lt;/ref&amp;gt; &amp;#039;&amp;#039;&amp;#039;Files&amp;#039;&amp;#039;&amp;#039; can be, for example, exchanged or &amp;#039;&amp;#039;&amp;#039;printers&amp;#039;&amp;#039;&amp;#039; can be shared. The name Samba comes from the SMB protocol (&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Server Message Block&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;), which is used for network-based data exchange on Windows. These days, people are increasingly referring to the &amp;quot;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Co...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A &amp;#039;&amp;#039;&amp;#039;Samba-Server&amp;#039;&amp;#039;&amp;#039; helps with the integration of &amp;#039;&amp;#039;&amp;#039;Windows- and Unix/Linux computers&amp;#039;&amp;#039;&amp;#039;.&amp;lt;ref&amp;gt;[http://www.oreilly.de/german/freebooks/samba2ger/ch01.html#936841 Samba, 2. Auflage] www.oreilly.de&amp;lt;/ref&amp;gt; &amp;#039;&amp;#039;&amp;#039;Files&amp;#039;&amp;#039;&amp;#039; can be, for example, exchanged or &amp;#039;&amp;#039;&amp;#039;printers&amp;#039;&amp;#039;&amp;#039; can be shared. The name Samba comes from the SMB protocol (&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Server Message Block&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;), which is used for network-based data exchange on Windows. These days, people are increasingly referring to the &amp;quot;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Common Internet File System&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;quot; (CIFS) instead of SMB. CIFS is a further development of SMB and was developed by Microsoft.&amp;lt;ref&amp;gt;[http://msdn.microsoft.com/en-us/library/aa365233%28v=vs.85%29.aspx SMB and CIFS overview] (msdn.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A free online book by O&amp;#039;Reilly provides detailed information about Samba/CIFS in German. It is available at [http://www.oreilly.de/german/freebooks/samba2ger/ Oreilly Samba 2nd edition]. Furthermore, the Samba community provides a detailed documentation about Samba: [https://help.ubuntu.com/community/Samba Samba Community]. This article presents the basics of working with a Samba server that is set up on &amp;#039;&amp;#039;&amp;#039;Ubuntu 10.04 LTS&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
== Server ==&lt;br /&gt;
=== Installation ===&lt;br /&gt;
The Samba package &amp;lt;ref&amp;gt;[http://packages.ubuntu.com/lucid/samba Samba Package] (packages.ubuntu.com)&amp;lt;/ref&amp;gt; is installed on the server so that a file and print server can be set up. &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
apt-get install samba&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Configuration === &lt;br /&gt;
The central configuration file is located at&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo vi /etc/samba/smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The corresponding man page provides a range of information on how to configure the Samba server using this file:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
man smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The file is divided into several parts. The global section ([global]) includes basic settings that may be followed by other sections on the release of resources.&lt;br /&gt;
&lt;br /&gt;
As the first step in the configuration, comment out the following line in the &amp;quot;Authentication&amp;quot; section:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# &amp;quot;security = user&amp;quot; is always a good idea. This will require a Unix account&lt;br /&gt;
# in this server for every user accessing the server. See&lt;br /&gt;
# /usr/share/doc/samba-doc/htmldocs/Samba3-HOWTO/ServerType.html&lt;br /&gt;
# in the samba-doc package for details.&lt;br /&gt;
   security = user&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Due to these security measures, an existing user account on the server is required to access the Samba shares.&amp;lt;ref&amp;gt;[https://help.ubuntu.com/10.04/serverguide/C/samba-fileprint-security.html Samba Security] (help.ubuntu.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Network interfaces ====&lt;br /&gt;
If your server possesses multiple network interfaces, it may be that the smb-server is connected to the wrong interface. To do this, the line &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
interfaces = 192.168.1.1/24&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
can be added to the &amp;quot;[global]&amp;quot; area of smb.conf. In this example, the SMB server listens on the address range in the 192.168.1.1/24 network.&amp;lt;ref&amp;gt;http://tldp.org/HOWTO/SMB-HOWTO-6.html&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Add smb password ====&lt;br /&gt;
The following command creates a smb-password for the existing user &amp;quot;smbuser&amp;quot;. It is important that this step is performed for an existing user, as every smb-user needs a valid account on the server. The password you set can be used later to access the SMB share:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo smbpasswd -a smbuser&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
As the smb-password does not have to comply with the password of the actual account, it can definitely time-consuming to administrate different passwords. On Ubuntu, the &amp;quot;libpam-smbpass&amp;quot; package exists, which can be used to keep Linux and smb passwords synchronized. &lt;br /&gt;
&lt;br /&gt;
So that the changes are effective, the server must reload the configuration:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo service smbd reload&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Zuvor können die modifizierten Einstellungen auch auf ihre Korrektheit geprüft werden:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
testparm /etc/samba/smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Add a resource ===&lt;br /&gt;
In the following configuration example, the home directories of the smb-users are released. In the first step, a new resource is added to the &amp;quot;smb.conf&amp;quot; file:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo vi /etc/samba/smb.conf&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
The following paragraph is commented out:  &lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# Un-comment the following (and tweak the other settings below to suit)&lt;br /&gt;
# to enable the default home directory shares.  This will share each&lt;br /&gt;
# user&amp;#039;s home directory as \\server\username&lt;br /&gt;
[homes]&lt;br /&gt;
   comment = Home Directories&lt;br /&gt;
   browseable = yes&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Now, the home-directories are available for all users, which means that the users can access each other´s directories (provided, of course, that an SMB password has been set and the user therefore has access to the SMB server). The parameter &amp;quot;browseable&amp;quot; allows Windows users to browse the Samba share using Windows Explorer.&lt;br /&gt;
To be more restrictive with home directories, the following line can be commented out:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
# By default, \\server\username shares can be connected to by anyone&lt;br /&gt;
# with access to the samba server.  Un-comment the following parameter&lt;br /&gt;
# to make sure that only &amp;quot;username&amp;quot; can connect to \\server\username&lt;br /&gt;
# This might need tweaking when using external authentication schemes&lt;br /&gt;
   valid users = %S&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Then, for example, the user &amp;quot;tktest&amp;quot; will no longer be able to access the home directory of &amp;quot;smbuser&amp;quot; (from clients perspective):&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mount -t smbfs //192.168.56.101/smbuser /media/ -o username=tktest&lt;br /&gt;
Password: &lt;br /&gt;
mount error(13): Permission denied&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
Further security measures are presented, for example, on  [https://help.ubuntu.com/10.04/serverguide/C/samba-fileprint-security.html Samba Security] (help.ubuntu.com) or [http://samba.org/samba/docs/man/Samba-HOWTO-Collection/securing-samba.html Securing samba] (samba.org).&lt;br /&gt;
&lt;br /&gt;
== Client ==&lt;br /&gt;
=== Installation ===&lt;br /&gt;
The following package is required for the access on the smb-server on the client:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo apt-get install smbfs smbclient&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
With the smbclient, an initial connection test can be started:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
smbclient -U smbuser -L 192.168.56.101&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Mounting of smb share === &lt;br /&gt;
With the mount command, the smb directory can be integrated locally:&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo mount -t cifs //192.168.56.101/smbuser /media/ -o username=smbuser&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
After this command, the smb-directory will be accessible at &amp;quot;/media/&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Ubuntu]]&lt;br /&gt;
[[de:Samba-Server Grundlagen]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_June_2026</id>
		<title>Supermicro BMC Security Advisories June 2026</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Supermicro_BMC_Security_Advisories_June_2026"/>
		<updated>2026-06-09T05:30:51Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;In &amp;#039;&amp;#039;&amp;#039;June 2026&amp;#039;&amp;#039;&amp;#039;, Supermicro published security advisories for the BMC-firmware of its mainboards. This security vulnerability requires a &amp;#039;&amp;#039;&amp;#039;firmware update&amp;#039;&amp;#039;&amp;#039;.   In this article, you will find information on this security advisory and where to find updates on Thomas-Krenn products.  == Security advisories == {| class=&amp;quot;wikitable&amp;quot; |- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot; ! align=&amp;quot;center&amp;quot; |CVE ! align=&amp;quot;center&amp;quot; |Risk potential: ! align=&amp;quot;center&amp;quot; |Title  |-...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In &amp;#039;&amp;#039;&amp;#039;June 2026&amp;#039;&amp;#039;&amp;#039;, Supermicro published security advisories for the BMC-firmware of its mainboards. This security vulnerability requires a &amp;#039;&amp;#039;&amp;#039;firmware update&amp;#039;&amp;#039;&amp;#039;. &lt;br /&gt;
&lt;br /&gt;
In this article, you will find information on this security advisory and where to find updates on Thomas-Krenn products.&lt;br /&gt;
&lt;br /&gt;
== Security advisories ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background-color: #EFEFEF; font-weight: bold;&amp;quot;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |CVE&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Risk potential:&lt;br /&gt;
! align=&amp;quot;center&amp;quot; |Title &lt;br /&gt;
|-&lt;br /&gt;
|align=&amp;quot;center&amp;quot; | [https://www.cve.org/CVERecord?id=CVE-2026-3820 CVE-2026-3820]&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | 7.2 (high)&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &amp;#039;&amp;#039;&amp;#039;&amp;lt;u&amp;gt;Command-Injection&amp;lt;/u&amp;gt;&amp;#039;&amp;#039;&amp;#039; (The security vulnerability allows an attacker to get administrator rights and to manipulate the SMTP service configuration. This could cause the system to execute unintended commands when calling processes)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Updates for Thomas-Krenn products ==&lt;br /&gt;
Updates on the corresponding system can be found in the &amp;lt;tklink type=&amp;quot;sitex&amp;quot; id=&amp;quot;440&amp;quot;&amp;gt;download area of Thomas-Krenn&amp;lt;/tklink&amp;gt;.&lt;br /&gt;
The updates in the download are have been tested by us to guarantee the stability and compatibility of our systems.&lt;br /&gt;
&lt;br /&gt;
If you require the latest version for your system and it is not yet available in our download area, you will find it at [https://www.asus.com/de/support/download-center/ Asus] or [https://www.supermicro.com/en/support/resources/downloadcenter/swdownload Supermicro].&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://www.supermicro.com/en/support/security_BMC_IPMI_Jun_2026 Vulnerabilities in Supermicro BMC firmware, June 2026]&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category: Server Hardware]]&lt;br /&gt;
[[de:Supermicro BMC Sicherheitshinweise Juni 2026]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Samba_Sharing_with_Authentication</id>
		<title>Samba Sharing with Authentication</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Samba_Sharing_with_Authentication"/>
		<updated>2026-06-08T13:06:35Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;As a supplement to a basic Samba share, this article shows you how to set up a username- and password-based Samba share using a Debian 8-based system. Ubuntu 16.04 as well as Windows 10 is used as client software to test the connection. Information on the fundamental and unrestricted release can be found in the article Simple Samba Shares in Debian.  == Installation and configuration on Debian server == The following paragraphs show the required configuration...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;As a supplement to a basic Samba share, this article shows you how to set up a username- and password-based Samba share using a [[Debian]] 8-based system. [[Ubuntu]] 16.04 as well as Windows 10 is used as client software to test the connection. Information on the fundamental and unrestricted release can be found in the article [[Simple Samba Shares in Debian]].&lt;br /&gt;
&lt;br /&gt;
== Installation and configuration on Debian server ==&lt;br /&gt;
The following paragraphs show the required configuration steps on a Debian server to set up the Samba server. The shared folder can then be mounted using a Linux-based or Windows-based client. &lt;br /&gt;
&lt;br /&gt;
=== Installation of the Samba service ===&lt;br /&gt;
The [[Simple Samba Sharing on Debian#Installation of Samba service|Installation of Samba service]] and the basic [[Einfache Samba Freigabe unter Debian#Konfiguration|configuration]] is done in the same way as for the article [[Simple Samba Shares in Debian]].&lt;br /&gt;
&lt;br /&gt;
=== User-restricted configuration ===&lt;br /&gt;
This configuration example shows how to do a &amp;#039;&amp;#039;&amp;#039;SMB-Share with authentication&amp;#039;&amp;#039;&amp;#039;. To do this, a user named &amp;quot;smbuser&amp;quot; is created on the Debian system, and a &amp;#039;&amp;#039;restricted&amp;#039;&amp;#039; share entry is added to the &amp;#039;&amp;#039;smb.conf&amp;#039;&amp;#039; configuration file.&lt;br /&gt;
&lt;br /&gt;
# Create SMB-user&lt;br /&gt;
#:&amp;lt;pre&amp;gt;$ sudo useradd -s /bin/false smbuser&amp;lt;/pre&amp;gt;&lt;br /&gt;
# Set password &lt;br /&gt;
#:&amp;lt;pre&amp;gt;$ sudo smbpasswd -a smbuser&amp;lt;/pre&amp;gt;&lt;br /&gt;
# Entry in the &amp;#039;&amp;#039;smb.conf&amp;#039;&amp;#039; file:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[global]&lt;br /&gt;
workgroup = smb&lt;br /&gt;
security = user&lt;br /&gt;
map to guest = never&lt;br /&gt;
&lt;br /&gt;
[homes]&lt;br /&gt;
comment = Home Directories&lt;br /&gt;
browsable = no&lt;br /&gt;
read only = no&lt;br /&gt;
create mode = 0750&lt;br /&gt;
&lt;br /&gt;
[restricted]&lt;br /&gt;
valid users = smbuser&lt;br /&gt;
#We restrict the acces on the &amp;#039;&amp;#039;smbuser&amp;#039;&amp;#039; user&lt;br /&gt;
#valid users = @smbusers&lt;br /&gt;
#Alternatively, it can also be restricted to one user group. &lt;br /&gt;
path = /media/storage2/&lt;br /&gt;
public = no&lt;br /&gt;
writable = yes&lt;br /&gt;
comment = smb restricted share&lt;br /&gt;
printable = no&lt;br /&gt;
guest ok = no&lt;br /&gt;
create mask = 0600&lt;br /&gt;
directory mask = 0700&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This configuration uses the example mountpoint &amp;#039;&amp;#039;/media/storage2&amp;#039;&amp;#039;.&lt;br /&gt;
To restrict access to the shared folder as much as possible, this &amp;#039;&amp;#039;/media/storage2&amp;#039;&amp;#039; mountpoint is assigned to the &amp;#039;&amp;#039;smbuser&amp;#039;&amp;#039; user and equipped with the directory rights 700 so that this user (and root) receives reading and writing rights.&lt;br /&gt;
&lt;br /&gt;
: &amp;lt;pre&amp;gt;$sudo chown -R smbuser:smbuser /media/storage2&amp;lt;/pre&amp;gt;&lt;br /&gt;
: &amp;lt;pre&amp;gt;$sudo chmod 700 /media/storage2&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Restart Samba ===&lt;br /&gt;
To apply the configuration, you have to restart the Samba service. This is made on Debian 8 with &amp;#039;&amp;#039;systemd&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
: &amp;lt;pre&amp;gt;$ sudo systemctl restart smbd.service&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Mounting of release ==&lt;br /&gt;
After the Samba server has been configured and restarted completely, the created share can now be used by clients. This is explained in the following sections using an Ubuntu 16.04 and a Windows 10 client.&lt;br /&gt;
&lt;br /&gt;
=== On a Linux-based client ===&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;cifs-utils&amp;#039;&amp;#039;&amp;#039; package is used in all current Linux-based distributions. Up to and including [[Ubuntu]] 12.04, the old &amp;#039;&amp;#039;&amp;#039;smbfs&amp;#039;&amp;#039;&amp;#039; package could be used.&amp;lt;ref&amp;gt;[https://wiki.ubuntuusers.de/Samba_Client_cifs/ Samba Client cifs] (wiki.ubuntuusers.de)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
: &amp;lt;pre&amp;gt;$ apt-get install cifs-utils&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Samba user &amp;#039;&amp;#039;smbuser&amp;#039;&amp;#039;, as configured on the Debian system, is used, and you will be prompted for the password.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ sudo mount -t cifs //&amp;lt;IP-des-Samba-Servers&amp;gt;/restricted /media/tniedermeier/test -o user=smbuser&lt;br /&gt;
Password for smbuser@//&amp;lt;IP-des-Samba-Servers&amp;gt;/restricted:  ********&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Further information on mounted releases can be received using the &amp;quot;mount&amp;quot; command in the terminal.&lt;br /&gt;
&lt;br /&gt;
=== On a Windows 10 client === &lt;br /&gt;
The share can be connected to a Windows 10 client as explained in the following section. There are multiple opportunities to establish a connection. &lt;br /&gt;
&lt;br /&gt;
You can connect to the network drive using the following command in the command prompt:&amp;lt;ref&amp;gt;[https://technet.microsoft.com/en-us/en-en/library/gg651155(v=ws.11).aspx Net use] (technet.microsoft.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&amp;lt;code&amp;gt;C:\Users\tniedermeier&amp;gt;net use &amp;lt;Laufwerksbuchstabe&amp;gt;: \\&amp;lt;IP-des-Samba-Servers&amp;gt;\restricted /user:smbuser &amp;lt;Passwort&amp;gt;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Alternatively, you can also connect the network drive using file explorer, as explained in the following steps:&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:samba-windows10-authentifizierung-001.png|&amp;#039;&amp;#039;&amp;#039;Step 1:&amp;#039;&amp;#039;&amp;#039; Click right on &amp;quot;Network&amp;quot; in the left-hand menu of the file explorer, then click left on the context menu option &amp;quot;Map network drive&amp;quot;.&lt;br /&gt;
File:samba-windows10-authentifizierung-002.png|&amp;#039;&amp;#039;&amp;#039;Step 2:&amp;#039;&amp;#039;&amp;#039; Select an available drive letter and type the path to the shared folder in the &amp;quot;Folder&amp;quot; field, for example &amp;#039;&amp;#039;\\&amp;lt;IP-des-Samba-Servers&amp;gt;\restricted&amp;#039;&amp;#039;. After this, click on &amp;#039;&amp;#039;Finish&amp;#039;&amp;#039;.&lt;br /&gt;
File:samba-windows10-authentifizierung-003.png|The network drive has been started successfully. Its content is now displayed in the explorer. &lt;br /&gt;
File:samba-windows10-authentifizierung-004.png|The new connected network drive &amp;#039;&amp;#039;restricted&amp;#039;&amp;#039; is now displayed in the left hand menu of the explorer.  &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you want to access the release without assigning a drive letter to it, you can also simply type the network path directly into the address bar in the explorer:&lt;br /&gt;
: &amp;lt;code&amp;gt;\\&amp;lt;IP-des-Samba-Servers&amp;gt;\restricted&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Tniedermeier}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[de:Samba Freigabe mit Authentifizierung]]&lt;br /&gt;
[[pl:Udostępnienie w Sambie z uwierzytelnieniem]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Secure_SSH_login_on_Debian_with_fail2ban</id>
		<title>Secure SSH login on Debian with fail2ban</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Secure_SSH_login_on_Debian_with_fail2ban"/>
		<updated>2026-06-05T08:26:17Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;fail2ban&amp;#039;&amp;#039;&amp;#039;, which is a tool written in Python, pursues the target to secure server services against DoS attacks. It verifies log files according to predefined patterns and temporarily blocks the relevant IP addresses if access attempts fail repeatedly. This article explains how to secure a Debian based server with fail2ban. The used version from fail2ban is &amp;#039;&amp;#039;&amp;#039;1.0.2-2&amp;#039;&amp;#039;&amp;#039; on &amp;#039;&amp;#039;&amp;#039;Debian 12&amp;#039;&amp;#039;&amp;#039;.  ==Problem== When executing the command &amp;quot;journalctl -u ssh&amp;quot;, multiple failed...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;fail2ban&amp;#039;&amp;#039;&amp;#039;, which is a tool written in Python, pursues the target to secure server services against DoS attacks. It verifies log files according to predefined patterns and temporarily blocks the relevant IP addresses if access attempts fail repeatedly. This article explains how to secure a Debian based server with fail2ban. The used version from fail2ban is &amp;#039;&amp;#039;&amp;#039;1.0.2-2&amp;#039;&amp;#039;&amp;#039; on &amp;#039;&amp;#039;&amp;#039;Debian 12&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
==Problem==&lt;br /&gt;
When executing the command &amp;quot;journalctl -u ssh&amp;quot;, multiple failed login attempts appear with the protocol SSH that were not written by you.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Feb 19 09:21:15 servername sshd[22796]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=218.207.xx.xx  user=root&lt;br /&gt;
Feb 19 09:21:17 servername sshd[22796]: Failed password for root from 218.207.xx.xx port 22 ssh2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Explanation==&lt;br /&gt;
* The removed user (accidentally) used the wrong server IP and accidentally tried to log in to your server. The number of login attempts is usually low here.&lt;br /&gt;
* You are the victim of a Brute Force attack, which automatically attempts to log in using the root user and various passwords (for example from so-called dictionary files). The number of login attempts is noticeably high here.&lt;br /&gt;
&lt;br /&gt;
==Solution==&lt;br /&gt;
Secure your SSH login with the fail2ban tool, [[Prohibit SSH root login on Debian]] or only login with [[SSH public key authentication under Ubuntu]].&lt;br /&gt;
&lt;br /&gt;
==What is fail2ban==&lt;br /&gt;
fail2ban is a tool written in Python that secures different server services against unauthorized access.&lt;br /&gt;
In the configuration example below, an IP address is blocked for one hour after 4 failed login attempts for SSH have occurred.&lt;br /&gt;
==Installation of fail2ban== &lt;br /&gt;
&amp;lt;pre lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo apt install fail2ban&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Configuration of fail2ban==&lt;br /&gt;
In the &amp;#039;&amp;#039;/etc/fail2ban/&amp;#039;&amp;#039; folder, you will find the global configuration file &amp;#039;&amp;#039;jail.conf&amp;#039;&amp;#039;. However, this file cannot be edited, since it is overwritten every time the package is updated. The own configuration can be made in the &lt;br /&gt;
&amp;quot;jail.local&amp;quot;.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# To avoid merges during upgrades DO NOT MODIFY THIS FILE&lt;br /&gt;
# and rather provide your changes in /etc/fail2ban/jail.local&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Hierzu kopieren Sie die &amp;quot;jail.conf&amp;quot; nach &amp;quot;jail.local&amp;quot;.&lt;br /&gt;
&amp;lt;pre lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Verify the settings on your local IP address of your server. The duration for which an IP address should be blocked is increased to an hour in our example and the number of blocks to be created is reduced to 3. Similarly, the Banaction must be changed from &amp;quot;iptables&amp;quot; to &amp;quot;nftables&amp;quot; when configuring. This configuration must be made in the following section of the &amp;#039;&amp;#039;jail.local&amp;#039;&amp;#039; file:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
[DEFAULT]&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
# MISCELLANEOUS OPTIONS&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
# &amp;quot;ignoreip&amp;quot; can be an IP address, a CIDR mask or a DNS host. Fail2ban will not&lt;br /&gt;
# ban a host which matches an address in this list. Several addresses can be&lt;br /&gt;
# defined using space (and/or comma) separator.&lt;br /&gt;
ignoreip = 127.0.0.1/8&lt;br /&gt;
&lt;br /&gt;
# External command that will take an tagged arguments to ignore, e.g. &amp;lt;ip&amp;gt;,&lt;br /&gt;
# and return true if the IP is to be ignored. False otherwise.&lt;br /&gt;
#&lt;br /&gt;
# ignorecommand = /path/to/command &amp;lt;ip&amp;gt;&lt;br /&gt;
ignorecommand =&lt;br /&gt;
&lt;br /&gt;
# &amp;quot;bantime&amp;quot; is the number of seconds that a host is banned.&lt;br /&gt;
bantime  = 3600&lt;br /&gt;
&lt;br /&gt;
# A host is banned if it has generated &amp;quot;maxretry&amp;quot; during the last &amp;quot;findtime&amp;quot;&lt;br /&gt;
# seconds.&lt;br /&gt;
findtime  = 600&lt;br /&gt;
&lt;br /&gt;
# &amp;quot;maxretry&amp;quot; is the number of failures before a host get banned.&lt;br /&gt;
maxretry = 3&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
banaction = nftables-multiport&lt;br /&gt;
banaction_allports = nftables-allports&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
You can adjust the parameters for individual services (as here in the SSH daemon article) separately.&lt;br /&gt;
&lt;br /&gt;
Now, in the section for the SSH daemon in your own &amp;#039;&amp;#039;jail.local&amp;#039;&amp;#039; configuration file (which you copied earlier), add the necessary parameters to monitor it via fail2ban:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
#&lt;br /&gt;
# SSH servers&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
[sshd]&lt;br /&gt;
&lt;br /&gt;
enabled	= true&lt;br /&gt;
port    = ssh&lt;br /&gt;
# filter	= sshd&lt;br /&gt;
logpath	= %(sshd_log)s&lt;br /&gt;
backend = systemd&lt;br /&gt;
maxretry = 4&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After this, restart fail2ban so that the changes are applied.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;sudo systemctl restart fail2ban.service&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Thomas-Krenn.AG}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[Category:SSH]]&lt;br /&gt;
[[pl:Zabezpieczenie loginu SSH w Debianie z fail2ban]]&lt;br /&gt;
[[de:SSH Login unter Debian mit fail2ban absichern]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Prohibit_SSH_root_login_on_Debian</id>
		<title>Prohibit SSH root login on Debian</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Prohibit_SSH_root_login_on_Debian"/>
		<updated>2026-06-05T05:25:36Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Further securing of the SSH server */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;If you want to prohibit the direct SSH root login on Debian, you will need at least one additional user to the root user, who is authorized to log in to the server. With this user, you can switch to the root account. &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;ATTENTION:&amp;#039;&amp;#039;&amp;#039; If you did not create any other users, you will log yourself out of the system!&lt;br /&gt;
&lt;br /&gt;
== PermitRootLogin no ==&lt;br /&gt;
&lt;br /&gt;
Edit the /etc/ssh/sshd_config file and set &lt;br /&gt;
 PermitRootLogin yes&lt;br /&gt;
&lt;br /&gt;
on &lt;br /&gt;
 PermitRootLogin no&lt;br /&gt;
&lt;br /&gt;
After this, restart the SSH service&lt;br /&gt;
 /etc/init.d/ssh restart (alternatively: service ssh restart)&lt;br /&gt;
&lt;br /&gt;
Now, the root user is not allowed to log into the system directly. You have to log in as usual with a user account and then switch with&lt;br /&gt;
 su&lt;br /&gt;
&lt;br /&gt;
to the root account.&lt;br /&gt;
&lt;br /&gt;
== AllowGroups ==&lt;br /&gt;
&lt;br /&gt;
You can also use the AllowGroups parameter to restrict which users are allowed to log in via SSH.&lt;br /&gt;
&lt;br /&gt;
Excerpt from the &amp;lt;code&amp;gt;man sshd_config&amp;lt;/code&amp;gt;:&lt;br /&gt;
:&amp;lt;cite&amp;gt;AllowGroups&amp;lt;/cite&amp;gt;&lt;br /&gt;
::&amp;lt;cite&amp;gt;This keyword can be followed by a list of group name patterns, separated by spaces. If specified, login is allowed only for users whose primary group or supplementary group list matches one of the patterns. Only group names are valid; a numerical group ID is not recognized. By default, login is allowed for all groups. The allow/deny directives are processed in the following order: DenyUsers, AllowUsers, DenyGroups, and finally AllowGroups.&amp;lt;/cite&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To create a group named sshusers and add a user to that group, execute the following commands as the root user:&lt;br /&gt;
 addgroup --system sshusers&lt;br /&gt;
 adduser xyz sshusers&lt;br /&gt;
&lt;br /&gt;
After this, configure the following options in /etc/ssh/sshd_config:&lt;br /&gt;
 LoginGraceTime 30&lt;br /&gt;
 AllowGroups sshusers&lt;br /&gt;
 PermitRootLogin no&lt;br /&gt;
 StrictModes yes&lt;br /&gt;
&lt;br /&gt;
Then restart the SSH service&lt;br /&gt;
 /etc/init.d/ssh restart&lt;br /&gt;
&lt;br /&gt;
== Further securing of the SSH server ==&lt;br /&gt;
More information on securing a SSH server can be found in the following articles:&lt;br /&gt;
* [[Securing SSH Login on Debian with fail2ban]]&lt;br /&gt;
* [[SSH Key Login]]&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]][[Category:Linux]]&lt;br /&gt;
[[de:SSH Root Login unter Debian verbieten]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Raspi-firmware:_missing_/boot/firmware,_did_you_forget_to_mount_it</id>
		<title>Raspi-firmware: missing /boot/firmware, did you forget to mount it</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Raspi-firmware:_missing_/boot/firmware,_did_you_forget_to_mount_it"/>
		<updated>2026-06-03T12:41:35Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;When installing [[Debian]] 12.0 using the live image, the raspi-firmware package will be also installed. However, this is not required on x86 systems and should therefore be deinstalled. If raspi-firmware is present, however, it causes the following error when installing a kernel update: &amp;#039;&amp;#039;&amp;#039;raspi-firmware: missing /boot/firmware, did you forget to mount it?&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Problem ==&lt;br /&gt;
Debian 12.0 was installed via live image. When attempting to install updates using &amp;#039;&amp;#039;&amp;#039;sudo apt dist-upgrade&amp;#039;&amp;#039;&amp;#039;, the following error occurs:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/etc/kernel/postinst.d/initramfs-tools:&lt;br /&gt;
update-initramfs: Generating /boot/initrd.img-6.1.0-10-amd64&lt;br /&gt;
raspi-firmware: missing /boot/firmware, did you forget to mount it?&lt;br /&gt;
run-parts: /etc/initramfs/post-update.d//z50-raspi-firmware exited with return code 1&lt;br /&gt;
run-parts: /etc/kernel/postinst.d/initramfs-tools exited with return code 1&lt;br /&gt;
dpkg: error processing package linux-image-6.1.0-10-amd64 (--configure):&lt;br /&gt;
 installed linux-image-6.1.0-10-amd64 package post-installation script subprocess returned error exit status 1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It is no longer possible to deinstall raspi-firmware without first performing some preparatory steps. The deinstallation will fail otherwise.&lt;br /&gt;
&lt;br /&gt;
== Solution ==&lt;br /&gt;
First, the new kernel must be deinstalled. Remove raspi-firmware and reinstall linux-image-amd64. After this, updates are possible without problems:&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;sudo apt purge linux-image-6.1.0-10-amd64&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
#: This will remove two packages: &amp;#039;&amp;#039;The following packages will be REMOVED: linux-image-6.1.0-10-amd64* linux-image-amd64*&amp;#039;&amp;#039; &amp;#039;&amp;#039;&amp;#039;sudo apt purge raspi-firmware&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;sudo apt install linux-image-amd64&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
#: This will reinstall both packages due to their dependencies: &amp;#039;&amp;#039;The following NEW packages will be installed: linux-image-6.1.0-10-amd64 linux-image-amd64&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://forums.debian.net/viewtopic.php?t=154857 Errors while updating system or install new packages Debian 12 (Solved sort of)] (forums.debian.net, 12.06.2023)&lt;br /&gt;
* [https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035382 Bookworm amd64 live install ISO RC1 and RC2 install pointless raspi-firmware package] (bugs.debian.org)&lt;br /&gt;
* [https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035783 raspi-firmware: unowned files after purge (policy 6.8, 10.8): /boot/firmware/fixup*.dat, /boot/firmware/start*.elf, /boot/firmware/bootcode.bin] (bugs.debian.org)&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[de:Raspi-firmware: missing /boot/firmware, did you forget to mount it]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Setup_Postfix_in_Debian</id>
		<title>Setup Postfix in Debian</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Setup_Postfix_in_Debian"/>
		<updated>2026-05-29T06:24:32Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;Postfix&amp;#039;&amp;#039;&amp;#039; is a widely used mail server, or more specifically, an MTA ([http://de.wikipedia.org/wiki/Mail_Transfer_Agent Mail Transfer Agent]). In this article, we describe how to install Postfix on Debian Lenny 5.0. In this example, we use a test server (lists.wefi.net). Replace this name with the name of your server.   == Install package == The Postfix installation must be started on the command line as follows:  apt-get install postfix  Debian provides a note that...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Postfix&amp;#039;&amp;#039;&amp;#039; is a widely used mail server, or more specifically, an MTA ([http://de.wikipedia.org/wiki/Mail_Transfer_Agent Mail Transfer Agent]). In this article, we describe how to install Postfix on Debian Lenny 5.0. In this example, we use a test server (lists.wefi.net). Replace this name with the name of your server. &lt;br /&gt;
&lt;br /&gt;
== Install package ==&lt;br /&gt;
The Postfix installation must be started on the command line as follows:&lt;br /&gt;
 apt-get install postfix&lt;br /&gt;
&lt;br /&gt;
Debian provides a note that Exim is removed and questions if you want to continue with the installation:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# apt-get install postfix&lt;br /&gt;
Reading package lists... Done&lt;br /&gt;
Building dependency tree       &lt;br /&gt;
Reading state information... Done&lt;br /&gt;
Suggested packages:&lt;br /&gt;
  procmail postfix-mysql postfix-pgsql postfix-ldap postfix-pcre sasl2-bin libsasl2-modules&lt;br /&gt;
  resolvconf postfix-cdb ufw&lt;br /&gt;
The following packages will be REMOVED:&lt;br /&gt;
  exim4 exim4-base exim4-config exim4-daemon-light&lt;br /&gt;
The following NEW packages will be installed:&lt;br /&gt;
  postfix&lt;br /&gt;
0 upgraded, 1 newly installed, 4 to remove and 0 not upgraded.&lt;br /&gt;
Need to get 1224kB of archives.&lt;br /&gt;
After this operation, 1008kB disk space will be freed.&lt;br /&gt;
Do you want to continue [Y/n]? y&lt;br /&gt;
Get:1 http://http.at.debian.org lenny/main postfix 2.5.5-1.1 [1224kB]&lt;br /&gt;
Fetched 1224kB in 0s (6060kB/s)&lt;br /&gt;
Preconfiguring packages ...&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Package configuration ===&lt;br /&gt;
[[file:Postfix-Installation-unter-Debian-Lenny-01-tpye-of-mail-configuration.png|right|thumb|300px|Postfix Configuration: General type of mail configuration]]&lt;br /&gt;
In the first configuration step, we select &amp;#039;&amp;#039;&amp;#039;Internet Site&amp;#039;&amp;#039;&amp;#039; in this example. Select the corresponding entry depending on your individual requirements.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Package configuration&lt;br /&gt;
         ┌───────────────────────────┤ Postfix Configuration ├───────────────────────────┐&lt;br /&gt;
         │ Please select the mail server configuration type that best meets your needs.  │ &lt;br /&gt;
         │                                                                               │ &lt;br /&gt;
         │  No configuration:                                                            │ &lt;br /&gt;
         │   Should be chosen to leave the current configuration unchanged.              │ &lt;br /&gt;
         │  Internet site:                                                               │ &lt;br /&gt;
         │   Mail is sent and received directly using SMTP.                              │ &lt;br /&gt;
         │  Internet with smarthost:                                                     │ &lt;br /&gt;
         │   Mail is received directly using SMTP or by running a utility such           │ &lt;br /&gt;
         │   as fetchmail. Outgoing mail is sent using a smarthost.                      │ &lt;br /&gt;
         │  Satellite system:                                                            │ &lt;br /&gt;
         │   All mail is sent to another machine, called a &amp;#039;smarthost&amp;#039;, for delivery.    │ &lt;br /&gt;
         │  Local only:                                                                  │ &lt;br /&gt;
         │   The only delivered mail is the mail for local users. There is no network.   │ &lt;br /&gt;
         │                                                                               │ &lt;br /&gt;
         │ General type of mail configuration:                                           │ &lt;br /&gt;
         │                                                                               │ &lt;br /&gt;
         │                            No configuration                                   │ &lt;br /&gt;
         │                            Internet Site                                      │ &lt;br /&gt;
         │                            Internet with smarthost                            │ &lt;br /&gt;
         │                            Satellite system                                   │ &lt;br /&gt;
         │                            Local only                                         │ &lt;br /&gt;
         │                                                                               │ &lt;br /&gt;
         │                                                                               │ &lt;br /&gt;
         │                     &amp;lt;Ok&amp;gt;                         &amp;lt;Cancel&amp;gt;                     │ &lt;br /&gt;
         │                                                                               │ &lt;br /&gt;
         └───────────────────────────────────────────────────────────────────────────────┘ &lt;br /&gt;
&amp;lt;/pre&amp;gt;                                                                                           &lt;br /&gt;
&lt;br /&gt;
[[file:Postfix-Installation-unter-Debian-Lenny-02-system-mail-name.png|right|thumb|300px|Postfix Configuration: System mail name]]&lt;br /&gt;
In the second step, we state the mail name of the server. Since the example involves a mailing list server, here lists.wefi.net (the mail address, for example, is then mailingliste@lists.wefi.net):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Package configuration&lt;br /&gt;
&lt;br /&gt;
 ┌──────────────────────────────────┤ Postfix Configuration ├───────────────────────────────────┐&lt;br /&gt;
  │ The &amp;quot;mail name&amp;quot; is the domain name used to &amp;quot;qualify&amp;quot; _ALL_ mail addresses without a domain   │ &lt;br /&gt;
  │ name. This includes mail to and from &amp;lt;root&amp;gt;: please do not make your machine send out mail   │ &lt;br /&gt;
  │ from root@example.org unless root@example.org has told you to.                               │ &lt;br /&gt;
  │                                                                                              │ &lt;br /&gt;
  │ This name will also be used by other programs. It should be the single, fully qualified      │ &lt;br /&gt;
  │ domain name (FQDN).                                                                          │ &lt;br /&gt;
  │                                                                                              │ &lt;br /&gt;
  │ Thus, if a mail address on the local host is foo@example.org, the correct value for this     │ &lt;br /&gt;
  │ option would be example.org.                                                                 │ &lt;br /&gt;
  │                                                                                              │ &lt;br /&gt;
  │ System mail name:                                                                            │ &lt;br /&gt;
  │                                                                                              │ &lt;br /&gt;
  │ lists.wefi.net______________________________________________________________________________ │ &lt;br /&gt;
  │                                                                                              │ &lt;br /&gt;
  │                          &amp;lt;Ok&amp;gt;                              &amp;lt;Cancel&amp;gt;                          │ &lt;br /&gt;
  │                                                                                              │ &lt;br /&gt;
  └──────────────────────────────────────────────────────────────────────────────────────────────┘ &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Completion of installation === &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
(Reading database ... 21540 files and directories currently installed.)&lt;br /&gt;
Removing exim4 ...&lt;br /&gt;
dpkg: exim4-config: dependency problems, but removing anyway as you request:&lt;br /&gt;
 exim4-base depends on exim4-config (&amp;gt;= 4.30) | exim4-config-2; however:&lt;br /&gt;
  Package exim4-config is to be removed.&lt;br /&gt;
  Package exim4-config-2 is not installed.&lt;br /&gt;
  Package exim4-config which provides exim4-config-2 is to be removed.&lt;br /&gt;
 exim4-base depends on exim4-config (&amp;gt;= 4.30) | exim4-config-2; however:&lt;br /&gt;
  Package exim4-config is to be removed.&lt;br /&gt;
  Package exim4-config-2 is not installed.&lt;br /&gt;
  Package exim4-config which provides exim4-config-2 is to be removed.&lt;br /&gt;
Removing exim4-config ...&lt;br /&gt;
dpkg: exim4-daemon-light: dependency problems, but removing anyway as you request:&lt;br /&gt;
 bsd-mailx depends on exim4 | mail-transport-agent; however:&lt;br /&gt;
  Package exim4 is not installed.&lt;br /&gt;
  Package mail-transport-agent is not installed.&lt;br /&gt;
  Package exim4-daemon-light which provides mail-transport-agent is to be removed.&lt;br /&gt;
Removing exim4-daemon-light ...&lt;br /&gt;
Stopping MTA: exim4_listener.&lt;br /&gt;
Removing exim4-base ...&lt;br /&gt;
Processing triggers for man-db ...&lt;br /&gt;
Selecting previously deselected package postfix.&lt;br /&gt;
(Reading database ... 21404 files and directories currently installed.)&lt;br /&gt;
Unpacking postfix (from .../postfix_2.5.5-1.1_i386.deb) ...&lt;br /&gt;
Processing triggers for man-db ...&lt;br /&gt;
Setting up postfix (2.5.5-1.1) ...&lt;br /&gt;
Adding group `postfix&amp;#039; (GID 108) ...&lt;br /&gt;
Done.&lt;br /&gt;
Adding system user `postfix&amp;#039; (UID 104) ...&lt;br /&gt;
Adding new user `postfix&amp;#039; (UID 104) with group `postfix&amp;#039; ...&lt;br /&gt;
Not creating home directory `/var/spool/postfix&amp;#039;.&lt;br /&gt;
Creating /etc/postfix/dynamicmaps.cf&lt;br /&gt;
Adding tcp map entry to /etc/postfix/dynamicmaps.cf&lt;br /&gt;
Adding group `postdrop&amp;#039; (GID 109) ...&lt;br /&gt;
Done.&lt;br /&gt;
setting myhostname: lists.wefi.net&lt;br /&gt;
setting alias maps&lt;br /&gt;
setting alias database&lt;br /&gt;
changing /etc/mailname to lists.wefi.net&lt;br /&gt;
setting myorigin&lt;br /&gt;
setting destinations: lists.wefi.net, localhost.wefi.net, , localhost&lt;br /&gt;
setting relayhost: &lt;br /&gt;
setting mynetworks: 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128&lt;br /&gt;
setting mailbox_size_limit: 0&lt;br /&gt;
setting recipient_delimiter: +&lt;br /&gt;
setting inet_interfaces: all&lt;br /&gt;
WARNING: /etc/aliases exists, but does not have a root alias.&lt;br /&gt;
&lt;br /&gt;
Postfix is now set up with a default configuration.  If you need to make &lt;br /&gt;
changes, edit&lt;br /&gt;
/etc/postfix/main.cf (and others) as needed.  To view Postfix configuration&lt;br /&gt;
values, see postconf(1).&lt;br /&gt;
&lt;br /&gt;
After modifying main.cf, be sure to run &amp;#039;/etc/init.d/postfix reload&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
Running newaliases&lt;br /&gt;
Stopping Postfix Mail Transport Agent: postfix.&lt;br /&gt;
Starting Postfix Mail Transport Agent: postfix.&lt;br /&gt;
lists:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Verification of mail delivery ===&lt;br /&gt;
You can verify with telnet (as described in [[Test TCP Port 25 (smtp) access with telnet]]) if the mail delivery functions:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ubuntu@ubuntu:~$ telnet lists.wefi.net 25&lt;br /&gt;
Trying 80.66.32.103...&lt;br /&gt;
Connected to lists.wefi.net.&lt;br /&gt;
Escape character is &amp;#039;^]&amp;#039;.&lt;br /&gt;
220 lists.wefi.net ESMTP Postfix (Debian/GNU)&lt;br /&gt;
EHLO test.example.com&lt;br /&gt;
250-lists.wefi.net&lt;br /&gt;
250-PIPELINING&lt;br /&gt;
250-SIZE 10240000&lt;br /&gt;
250-VRFY&lt;br /&gt;
250-ETRN&lt;br /&gt;
250-STARTTLS&lt;br /&gt;
250-ENHANCEDSTATUSCODES&lt;br /&gt;
250-8BITMIME&lt;br /&gt;
250 DSN&lt;br /&gt;
MAIL FROM: test@example.com&lt;br /&gt;
250 2.1.0 Ok&lt;br /&gt;
RCPT TO: postmaster@lists.wefi.net&lt;br /&gt;
250 2.1.5 Ok&lt;br /&gt;
DATA&lt;br /&gt;
354 End data with &amp;lt;CR&amp;gt;&amp;lt;LF&amp;gt;.&amp;lt;CR&amp;gt;&amp;lt;LF&amp;gt;&lt;br /&gt;
Subject: Test message&lt;br /&gt;
&lt;br /&gt;
This is a test.&lt;br /&gt;
&lt;br /&gt;
.&lt;br /&gt;
250 2.0.0 Ok: queued as 87D2CDE40A2&lt;br /&gt;
QUIT&lt;br /&gt;
221 2.0.0 Bye&lt;br /&gt;
Connection closed by foreign host.&lt;br /&gt;
user@ubuntu:~$ &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This message has now been delivered to the server:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# mail&lt;br /&gt;
Mail version 8.1.2 01/15/2001.  Type ? for help.&lt;br /&gt;
&amp;quot;/var/mail/root&amp;quot;: 1 message 1 new&lt;br /&gt;
&amp;gt;N  1 test@example.com  Tue Jun  1 10:00   16/545   Testnachricht&lt;br /&gt;
&amp;amp; 1&lt;br /&gt;
Message 1:&lt;br /&gt;
From test@example.com  Tue Jun  1 10:00:49 2010&lt;br /&gt;
X-Original-To: postmaster@lists.wefi.net&lt;br /&gt;
Subject: Testnachricht&lt;br /&gt;
Date: Tue,  1 Jun 2010 10:00:08 +0200 (CEST)&lt;br /&gt;
From: test@example.com&lt;br /&gt;
To: undisclosed-recipients:;&lt;br /&gt;
&lt;br /&gt;
This is a test. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;amp; q&lt;br /&gt;
Saved 1 message in /root/mbox&lt;br /&gt;
lists:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [http://de.wikipedia.org/wiki/Postfix_%28Mail_Transfer_Agent%29 Postfix (Mail Transfer Agent)] (Wikipedia)&lt;br /&gt;
* [http://www.postfix.org/ Postfix Projekt Webseite]&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[de:Postfix unter Debian einrichten]]&lt;br /&gt;
[[pl:Konfiguracja Postfix-a w Debianie]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Creating_mailing_lists_in_Mailman</id>
		<title>Creating mailing lists in Mailman</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Creating_mailing_lists_in_Mailman"/>
		<updated>2026-05-28T11:54:19Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Configuration parameter */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In this article, we explain how to &amp;#039;&amp;#039;&amp;#039;create a new mailing list in Debian&amp;#039;&amp;#039;&amp;#039;. We also present important configuration parameters. Information on installing Mailman can be found in the article [[Setup Mailman in Debian]].&lt;br /&gt;
&lt;br /&gt;
== Create mailing list ==&lt;br /&gt;
&lt;br /&gt;
A new mailing list can be created with the &amp;#039;&amp;#039;&amp;#039;newlist&amp;#039;&amp;#039;&amp;#039; command. Next, enter your email address. Mailman will use this address to send you email notifications in the future (for example, when new subscribers join the mailing list). Then, configure /etc/aliases as described:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# newlist test-mailingliste&lt;br /&gt;
Enter the email of the person running the list: email@example.org&lt;br /&gt;
Initial test-mailingliste password: &lt;br /&gt;
To finish creating your mailing list, you must edit your /etc/aliases (or&lt;br /&gt;
equivalent) file by adding the following lines, and possibly running the&lt;br /&gt;
`newaliases&amp;#039; program:&lt;br /&gt;
&lt;br /&gt;
## test-mailingliste mailing list&lt;br /&gt;
test-mailingliste:              &amp;quot;|/var/lib/mailman/mail/mailman post test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-admin:        &amp;quot;|/var/lib/mailman/mail/mailman admin test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-bounces:      &amp;quot;|/var/lib/mailman/mail/mailman bounces test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-confirm:      &amp;quot;|/var/lib/mailman/mail/mailman confirm test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-join:         &amp;quot;|/var/lib/mailman/mail/mailman join test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-leave:        &amp;quot;|/var/lib/mailman/mail/mailman leave test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-owner:        &amp;quot;|/var/lib/mailman/mail/mailman owner test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-request:      &amp;quot;|/var/lib/mailman/mail/mailman request test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-subscribe:    &amp;quot;|/var/lib/mailman/mail/mailman subscribe test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-unsubscribe:  &amp;quot;|/var/lib/mailman/mail/mailman unsubscribe test-mailingliste&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Hit enter to notify test-mailingliste owner...&lt;br /&gt;
&lt;br /&gt;
lists:~# vi /etc/aliases&lt;br /&gt;
lists:~# tail -n 12 /etc/aliases&lt;br /&gt;
&lt;br /&gt;
## test-mailingliste mailing list&lt;br /&gt;
test-mailingliste:              &amp;quot;|/var/lib/mailman/mail/mailman post test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-admin:        &amp;quot;|/var/lib/mailman/mail/mailman admin test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-bounces:      &amp;quot;|/var/lib/mailman/mail/mailman bounces test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-confirm:      &amp;quot;|/var/lib/mailman/mail/mailman confirm test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-join:         &amp;quot;|/var/lib/mailman/mail/mailman join test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-leave:        &amp;quot;|/var/lib/mailman/mail/mailman leave test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-owner:        &amp;quot;|/var/lib/mailman/mail/mailman owner test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-request:      &amp;quot;|/var/lib/mailman/mail/mailman request test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-subscribe:    &amp;quot;|/var/lib/mailman/mail/mailman subscribe test-mailingliste&amp;quot;&lt;br /&gt;
test-mailingliste-unsubscribe:  &amp;quot;|/var/lib/mailman/mail/mailman unsubscribe test-mailingliste&amp;quot;&lt;br /&gt;
lists:~# postalias /etc/aliases&lt;br /&gt;
lists:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration parameter ==&lt;br /&gt;
Some important configuration parameters can be adjusted in the web interface:&lt;br /&gt;
* General options:&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;real_name&amp;#039;&amp;#039;&amp;#039;: Name of mailing list.&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;description&amp;#039;&amp;#039;&amp;#039;: A brief one-lined description.&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;reply_goes_to_list&amp;#039;&amp;#039;&amp;#039;: Here, you can define where replies to postings should be sent (E-Mail Reply-To field). &amp;quot;This list&amp;quot; is often a good choice here. &amp;quot;Explicit address&amp;quot; is particularly useful for announcement mailing lists. In that case, you can use the &amp;#039;&amp;#039;&amp;#039;reply_to_address&amp;#039;&amp;#039;&amp;#039; option to specify, for example, a different mailing list as the Reply-To address, to which users can send their replies.&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;host_name&amp;#039;&amp;#039;&amp;#039;: Hostname, at which the email address can be reached (just check this value).&lt;br /&gt;
* Privacy options:&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;private_roster&amp;#039;&amp;#039;&amp;#039;: Specifies who can view the list of all mailing list subscribers. &amp;#039;&amp;#039;List members&amp;#039;&amp;#039; is the default setting, but &amp;#039;&amp;#039;List admin only&amp;#039;&amp;#039; is often the better choice.&lt;br /&gt;
* Privacy options: Sender filters:&lt;br /&gt;
** &amp;#039;&amp;#039;&amp;#039;default_member_moderation&amp;#039;&amp;#039;&amp;#039;: Specifies whether posts from new members are moderated. This is useful, for example, for announcement mailing lists.&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[de:Mailinglisten unter Mailman erstellen]]&lt;br /&gt;
[[pl:Tworzenie list dyskusyjnych w Mailman-ie]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Setup_of_Mailman_in_Debian</id>
		<title>Setup of Mailman in Debian</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Setup_of_Mailman_in_Debian"/>
		<updated>2026-05-22T08:10:39Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: /* Completed installation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;GNU Mailman&amp;#039;&amp;#039;&amp;#039; is a software for administrating mailing lists for free. In this article, we describe how to setup Mailman on Debian Lenny (Debian 5.0). At Thomas-Krenn, we use Mailman for mailing lists of the [[IPMI Sensor Monitoring Plugin]]. &lt;br /&gt;
&lt;br /&gt;
== Install MTA ==&lt;br /&gt;
For the operation of mailing lists with Mailman, the MTA (Mail Transfer Agent) is required. During the subsequent installation of Postfix, select &amp;#039;&amp;#039;&amp;#039;Internet Site&amp;#039;&amp;#039;&amp;#039; as the &amp;#039;General type of mail configuration&amp;#039;. &lt;br /&gt;
&lt;br /&gt;
Further information on the installation of Postfix can be found in the article [[Setup of Postfix on Debian]].&lt;br /&gt;
&lt;br /&gt;
== Install Mailman == &lt;br /&gt;
&lt;br /&gt;
The Mailman can be installed using apt-get: &lt;br /&gt;
&lt;br /&gt;
 apt-get install mailman&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# apt-get install mailman&lt;br /&gt;
Reading package lists... Done&lt;br /&gt;
Building dependency tree       &lt;br /&gt;
Reading state information... Done&lt;br /&gt;
The following extra packages will be installed:&lt;br /&gt;
  apache2 apache2-mpm-worker pwgen python-support ucf&lt;br /&gt;
Suggested packages:&lt;br /&gt;
  spamassassin lynx listadmin&lt;br /&gt;
The following NEW packages will be installed:&lt;br /&gt;
  apache2 apache2-mpm-worker mailman pwgen python-support ucf&lt;br /&gt;
0 upgraded, 6 newly installed, 0 to remove and 0 not upgraded.&lt;br /&gt;
Need to get 9965kB of archives.&lt;br /&gt;
After this operation, 45.7MB of additional disk space will be used.&lt;br /&gt;
Do you want to continue [Y/n]? y&lt;br /&gt;
Get:1 http://http.at.debian.org lenny/main python-support 0.8.4lenny1 [28.4kB]                     &lt;br /&gt;
Get:2 http://http.at.debian.org lenny/main ucf 3.0016 [64.4kB]                                     &lt;br /&gt;
Get:3 http://security.debian.org lenny/updates/main apache2-mpm-worker 2.2.9-10+lenny7 [242kB]&lt;br /&gt;
Get:4 http://http.at.debian.org lenny/main pwgen 2.06-1 [19.2kB]&lt;br /&gt;
Get:5 http://http.at.debian.org lenny/main mailman 1:2.1.11-11 [9566kB]&lt;br /&gt;
Get:6 http://security.debian.org lenny/updates/main apache2 2.2.9-10+lenny7 [45.4kB]&lt;br /&gt;
Fetched 9965kB in 1s (5665kB/s)                                &lt;br /&gt;
Preconfiguring packages ...&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Package configuration ===&lt;br /&gt;
&lt;br /&gt;
==== Supported language ==== &lt;br /&gt;
[[file:Mailman-Installation-unter-Debian-Lenny-01-languages-to-support.png|right|thumb|300px|Configuring mailman: Languages to support]]&lt;br /&gt;
The request on which language should be supported appears during installation:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Package configuration&lt;br /&gt;
&lt;br /&gt;
┌────────────────────────────────────┤ Configuring mailman ├────────────────────────────────────┐&lt;br /&gt;
 │ For each supported language, Mailman stores default language specific texts in                │ &lt;br /&gt;
 │ /etc/mailman/LANG/ giving them conffile like treatment with the help of ucf.  This means      │ &lt;br /&gt;
 │ approximately 150kB for each supported language on the root file system.                      │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ If you need a different set of languages at a later time, just run dpkg-reconfigure mailman.  │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ NOTE: Languages enabled on existing mailing lists are forcibly re-enabled when deselected     │ &lt;br /&gt;
 │ and mailman needs at least one language for displaying its messages.                          │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ Languages to support:                                                                         │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │    [ ] ar (Arabic)                                                                            │ &lt;br /&gt;
 │    [ ] ca (Catalan)                                                                           │ &lt;br /&gt;
 │    [ ] cs (Czech)                                                                         ▒   │ &lt;br /&gt;
 │    [ ] da (Danish)                                                                        ▒   │ &lt;br /&gt;
 │    [*] de (German)                                                                        ▒   │ &lt;br /&gt;
 │    [*] en (English)                                                                       ▒   │ &lt;br /&gt;
 │    [ ] es (Spanish)                                                                       ▒   │ &lt;br /&gt;
 │    [ ] et (Estonian)                                                                      ▒   │ &lt;br /&gt;
 │    [ ] eu (Basque)                                                                            │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │                                            &amp;lt;Ok&amp;gt;                                               │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 └───────────────────────────────────────────────────────────────────────────────────────────────┘ &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Default language ====&lt;br /&gt;
[[file:Mailman-Installation-unter-Debian-Lenny-02-default-language-for-mailman.png|right|thumb|300px|Configuring mailman: Default language for Mailman]]&lt;br /&gt;
If you have choosen multiple languages, the default language can be determined: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Package configuration&lt;br /&gt;
┌────────────────────────────────────┤ Configuring mailman ├────────────────────────────────────┐&lt;br /&gt;
 │ The web page will be shown in this language, and in general, Mailman will use this language   │ &lt;br /&gt;
 │ to communicate with the user.                                                                 │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ Default language for Mailman:                                                                 │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │                                         de (German)                                           │ &lt;br /&gt;
 │                                         en (English)                                          │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │                                            &amp;lt;Ok&amp;gt;                                               │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 └───────────────────────────────────────────────────────────────────────────────────────────────┘ &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Note on further configuration steps ====&lt;br /&gt;
[[file:Mailman-Installation-unter-Debian-Lenny-03-missing-site-list.png|right|thumb|300px|Configuring mailman: Missing site list]]&lt;br /&gt;
Finally, here is a note regarding additional configuration steps that are required that must be performed manually after installation:  &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Package configuration&lt;br /&gt;
&lt;br /&gt;
┌────────────────────────────────────┤ Configuring mailman ├────────────────────────────────────┐&lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ Missing site list                                                                             │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ Mailman needs a so-called &amp;quot;site list&amp;quot;, which is the list from which password reminders and    │ &lt;br /&gt;
 │ such are sent out from.  This list needs to be created before mailman will start.             │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │ To create the list, run &amp;quot;newlist mailman&amp;quot; and follow the instructions on-screen.  Note that   │ &lt;br /&gt;
 │ you also need to start mailman after that, using /etc/init.d/mailman start.                   │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 │                                            &amp;lt;Ok&amp;gt;                                               │ &lt;br /&gt;
 │                                                                                               │ &lt;br /&gt;
 └───────────────────────────────────────────────────────────────────────────────────────────────┘ &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Completion of installation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Selecting previously deselected package python-support.&lt;br /&gt;
(Reading database ... 21572 files and directories currently installed.)&lt;br /&gt;
Unpacking python-support (from .../python-support_0.8.4lenny1_all.deb) ...&lt;br /&gt;
Selecting previously deselected package apache2-mpm-worker.&lt;br /&gt;
Unpacking apache2-mpm-worker (from .../apache2-mpm-worker_2.2.9-10+lenny7_i386.deb) ...&lt;br /&gt;
Selecting previously deselected package apache2.&lt;br /&gt;
Unpacking apache2 (from .../apache2_2.2.9-10+lenny7_all.deb) ...&lt;br /&gt;
Selecting previously deselected package ucf.&lt;br /&gt;
Unpacking ucf (from .../archives/ucf_3.0016_all.deb) ...&lt;br /&gt;
Moving old data out of the way&lt;br /&gt;
Selecting previously deselected package pwgen.&lt;br /&gt;
Unpacking pwgen (from .../archives/pwgen_2.06-1_i386.deb) ...&lt;br /&gt;
Selecting previously deselected package mailman.&lt;br /&gt;
Unpacking mailman (from .../mailman_1%3a2.1.11-11_i386.deb) ...&lt;br /&gt;
Processing triggers for man-db ...&lt;br /&gt;
Setting up python-support (0.8.4lenny1) ...&lt;br /&gt;
Setting up apache2-mpm-worker (2.2.9-10+lenny7) ...&lt;br /&gt;
Starting web server: apache2.&lt;br /&gt;
Setting up apache2 (2.2.9-10+lenny7) ...&lt;br /&gt;
Setting up ucf (3.0016) ...&lt;br /&gt;
Setting up pwgen (2.06-1) ...&lt;br /&gt;
Setting up mailman (1:2.1.11-11) ...&lt;br /&gt;
Looking for enabled languages (this may take some time) ... done.&lt;br /&gt;
Installing site language en ............................................ done.&lt;br /&gt;
Configuring mailman for domain lists.wefi.net ...&lt;br /&gt;
Upgrading from version 0x0 to 0x2010bf0&lt;br /&gt;
getting rid of old source files&lt;br /&gt;
Site list for mailman missing (looking for list named &amp;#039;mailman&amp;#039;). (warning).&lt;br /&gt;
Please create it; until then, mailman will refuse to start. (warning).&lt;br /&gt;
lists:~#  &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Further configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Verify configuration ===&lt;br /&gt;
The configuration file, /etc/mailman/mm_cfg.py, must be verified. It is important that all DEFAULT entries are correct:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# grep DEFAULT /etc/mailman/mm_cfg.py &lt;br /&gt;
DEFAULT_MSG_FOOTER for an example.&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
DEFAULT_URL_PATTERN = &amp;#039;http://%s/cgi-bin/mailman/&amp;#039;&lt;br /&gt;
DEFAULT_EMAIL_HOST = &amp;#039;lists.wefi.net&amp;#039;&lt;br /&gt;
DEFAULT_URL_HOST   = &amp;#039;lists.wefi.net&amp;#039;&lt;br /&gt;
add_virtualhost(DEFAULT_URL_HOST, DEFAULT_EMAIL_HOST)&lt;br /&gt;
DEFAULT_SERVER_LANGUAGE = &amp;#039;en&amp;#039;&lt;br /&gt;
DEFAULT_SEND_REMINDERS = 0&lt;br /&gt;
lists:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== newlist mailman ===&lt;br /&gt;
&lt;br /&gt;
The so-called &amp;#039;site list&amp;#039; can be created using &lt;br /&gt;
 newlist mailman. &lt;br /&gt;
One of your addresses must be stated here as email address: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# newlist mailman&lt;br /&gt;
Enter the email of the person running the list: email@example.org&lt;br /&gt;
Initial mailman password: &lt;br /&gt;
To finish creating your mailing list, you must edit your /etc/aliases (or&lt;br /&gt;
equivalent) file by adding the following lines, and possibly running the&lt;br /&gt;
`newaliases&amp;#039; program:&lt;br /&gt;
&lt;br /&gt;
## mailman mailing list&lt;br /&gt;
mailman:              &amp;quot;|/var/lib/mailman/mail/mailman post mailman&amp;quot;&lt;br /&gt;
mailman-admin:        &amp;quot;|/var/lib/mailman/mail/mailman admin mailman&amp;quot;&lt;br /&gt;
mailman-bounces:      &amp;quot;|/var/lib/mailman/mail/mailman bounces mailman&amp;quot;&lt;br /&gt;
mailman-confirm:      &amp;quot;|/var/lib/mailman/mail/mailman confirm mailman&amp;quot;&lt;br /&gt;
mailman-join:         &amp;quot;|/var/lib/mailman/mail/mailman join mailman&amp;quot;&lt;br /&gt;
mailman-leave:        &amp;quot;|/var/lib/mailman/mail/mailman leave mailman&amp;quot;&lt;br /&gt;
mailman-owner:        &amp;quot;|/var/lib/mailman/mail/mailman owner mailman&amp;quot;&lt;br /&gt;
mailman-request:      &amp;quot;|/var/lib/mailman/mail/mailman request mailman&amp;quot;&lt;br /&gt;
mailman-subscribe:    &amp;quot;|/var/lib/mailman/mail/mailman subscribe mailman&amp;quot;&lt;br /&gt;
mailman-unsubscribe:  &amp;quot;|/var/lib/mailman/mail/mailman unsubscribe mailman&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Hit enter to notify mailman owner...&lt;br /&gt;
&lt;br /&gt;
lists:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The message will not be sent to the specified email address until Mailman has been started.&lt;br /&gt;
&lt;br /&gt;
Now, the entries in /etc/aliases must be added and the command &amp;lt;code&amp;gt;postadmin /etc/aliases&amp;lt;/code&amp;gt; must be executed (if you use Postfix as here in the example):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
lists:~# vi /etc/aliases&lt;br /&gt;
lists:~# cat /etc/aliases&lt;br /&gt;
# /etc/aliases&lt;br /&gt;
mailer-daemon: postmaster&lt;br /&gt;
postmaster: root&lt;br /&gt;
nobody: root&lt;br /&gt;
hostmaster: root&lt;br /&gt;
usenet: root&lt;br /&gt;
news: root&lt;br /&gt;
webmaster: root&lt;br /&gt;
www: root&lt;br /&gt;
ftp: root&lt;br /&gt;
abuse: root&lt;br /&gt;
noc: root&lt;br /&gt;
security: root&lt;br /&gt;
&lt;br /&gt;
## mailman mailing list&lt;br /&gt;
mailman:              &amp;quot;|/var/lib/mailman/mail/mailman post mailman&amp;quot;&lt;br /&gt;
mailman-admin:        &amp;quot;|/var/lib/mailman/mail/mailman admin mailman&amp;quot;&lt;br /&gt;
mailman-bounces:      &amp;quot;|/var/lib/mailman/mail/mailman bounces mailman&amp;quot;&lt;br /&gt;
mailman-confirm:      &amp;quot;|/var/lib/mailman/mail/mailman confirm mailman&amp;quot;&lt;br /&gt;
mailman-join:         &amp;quot;|/var/lib/mailman/mail/mailman join mailman&amp;quot;&lt;br /&gt;
mailman-leave:        &amp;quot;|/var/lib/mailman/mail/mailman leave mailman&amp;quot;&lt;br /&gt;
mailman-owner:        &amp;quot;|/var/lib/mailman/mail/mailman owner mailman&amp;quot;&lt;br /&gt;
mailman-request:      &amp;quot;|/var/lib/mailman/mail/mailman request mailman&amp;quot;&lt;br /&gt;
mailman-subscribe:    &amp;quot;|/var/lib/mailman/mail/mailman subscribe mailman&amp;quot;&lt;br /&gt;
mailman-unsubscribe:  &amp;quot;|/var/lib/mailman/mail/mailman unsubscribe mailman&amp;quot;&lt;br /&gt;
&lt;br /&gt;
lists:~# postalias /etc/aliases&lt;br /&gt;
lists:~# &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Start Mailman ===&lt;br /&gt;
Now, start Mailman:&lt;br /&gt;
 /etc/init.d/mailman start&lt;br /&gt;
&lt;br /&gt;
=== Create mailing lists ===&lt;br /&gt;
Information on this topic can be found in the article [[Creation of mailing lists in Mailman]].&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* http://de.wikipedia.org/wiki/GNU_Mailman&lt;br /&gt;
* http://library.linode.com/email/mailman/debian-5-lenny&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[pl:Mailman w Debianie]]&lt;br /&gt;
[[de:Mailman unter Debian einrichten]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/Setting_up_password_authentication_with_Active_Directory_on_Debian</id>
		<title>Setting up password authentication with Active Directory on Debian</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/Setting_up_password_authentication_with_Active_Directory_on_Debian"/>
		<updated>2026-05-22T05:01:48Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;Central directory services such as OpenLDAP or Active Directory (AD) simplify the &amp;#039;&amp;#039;&amp;#039;password management&amp;#039;&amp;#039;&amp;#039; for administrator and user. With regard to Linux server, the aspect of the SSH &amp;#039;&amp;#039;&amp;#039;authentication&amp;#039;&amp;#039;&amp;#039; via AD is interesting. From an IT security perspective, this solution also has its advantages: * Administrators do not have to choose and administrate different passwords for every server. You can log in to the servers with the AD password. * The password change or d...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Central directory services such as OpenLDAP or Active Directory (AD) simplify the &amp;#039;&amp;#039;&amp;#039;password management&amp;#039;&amp;#039;&amp;#039; for administrator and user. With regard to Linux server, the aspect of the SSH &amp;#039;&amp;#039;&amp;#039;authentication&amp;#039;&amp;#039;&amp;#039; via AD is interesting. From an IT security perspective, this solution also has its advantages:&lt;br /&gt;
* Administrators do not have to choose and administrate different passwords for every server. You can log in to the servers with the AD password.&lt;br /&gt;
* The password change or deactivation of an account can be made via AD.&lt;br /&gt;
* Central administrated root passwords do not have to be known by all administrators anymore. &lt;br /&gt;
&lt;br /&gt;
The following article shows how to configure an in Debian 7 &amp;#039;&amp;#039;wheezy&amp;#039;&amp;#039; with &amp;#039;&amp;#039;&amp;#039;libpam-ldapd&amp;#039;&amp;#039;&amp;#039; via &amp;#039;&amp;#039;mod_pam&amp;#039;&amp;#039; with an AD. The authentication is not only valid for [[:Kategorie:SSH|SSH]] but also for all services that use PAM (like, for example, &amp;#039;&amp;#039;sudo&amp;#039;&amp;#039;) after successful configuration. As the libpam-ldapd packages are also available for Ubuntu&amp;lt;ref&amp;gt;[http://packages.ubuntu.com/trusty/libpam-ldapd libpam-ldapd] (packages.ubuntu.com)&amp;lt;/ref&amp;gt;, the instructions can be also used for Ubuntu.&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
== Requirements and purpose ==&lt;br /&gt;
The following information is required for the setup:&lt;br /&gt;
# The LDAP-URL of the AD server&lt;br /&gt;
# The search or Base DN in which the users are located.&lt;br /&gt;
# (recommended) A Bind DN, including a password, used to search the Active Directory or the base DN.&lt;br /&gt;
# For TLS&lt;br /&gt;
#* The certificate file for the encrypted communication (since passwords are transferred between the server and AD during authentication, an encrypted communication is highly recommended).&lt;br /&gt;
# The users, who want to sign up, &amp;#039;&amp;#039;&amp;#039;must already exist&amp;#039;&amp;#039;&amp;#039; on the server&lt;br /&gt;
&lt;br /&gt;
In the following, the objectives of the instructions are listed:&lt;br /&gt;
* Password authentication of users via the passwords stored in AD.&lt;br /&gt;
* Other things like groups, home-paths or similar are &amp;#039;&amp;#039;&amp;#039;not&amp;#039;&amp;#039;&amp;#039; retrieved from the AD.&lt;br /&gt;
* The &amp;#039;&amp;#039;root&amp;#039;&amp;#039; user should be able to sign up with local passwords.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention: Changes to PAM module configurations may prevent you from logging in or authenticating. Always have a root terminal ready in case of an emergency!&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Testing connection to AD ==&lt;br /&gt;
First, the connection between server&amp;lt;-&amp;gt;AD is tested. When using LDAP with START_TLS, the communication is made via port 389:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# telnet ldap.example.com 389&lt;br /&gt;
Trying ...&lt;br /&gt;
Connected to ldap.example.com&lt;br /&gt;
Escape character is &amp;#039;^]&amp;#039;.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After this, an actual LDAP query is made via ldapsearch (for an encrypted connection - parameter &amp;#039;-ZZ&amp;#039; -, the certificate must be configured in the &amp;#039;&amp;#039;/etc/ldap.conf&amp;#039;&amp;#039; file.):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ldapsearch -x -H ldap://ldap.example.com -D &amp;quot;CN=Georg Schönberger,OU=Users,DC=example,DC=com&amp;quot; \&lt;br /&gt;
-b OU=Users,DC=example,DC=com -W -ZZ sAMAccountName=gschoenberger&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Installation of libpam-ldapd ==&lt;br /&gt;
The central component on the Debian server forms the package [https://packages.debian.org/wheezy/libpam-ldapd libpam-ldapd] (packages.debian.org). With this package, the daemon [https://packages.debian.org/wheezy/nslcd nslcd] (packages.debian.org) is also installed that is responsible for the communication between server &amp;lt;-&amp;gt; AD.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# apt-get install libpam-ldapd&lt;br /&gt;
[...]&lt;br /&gt;
The following NEW packages will be installed:&lt;br /&gt;
  bind9-host geoip-database ldap-utils libbind9-80 libcap2 libdns88 libgeoip1 libisc84 libisccc80 libisccfg82&lt;br /&gt;
 liblwres80 libnss-ldapd libpam-ldapd libxml2 nscd nslcd sgml-base xml-core&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
Ldap-auth-configure-1.png|The LDAP-Url points to the host name of the AD-server.&lt;br /&gt;
Ldap-auth-configure-2.png|The search base is the part of the directory where users are located.&lt;br /&gt;
Ldap-auth-configure-3.png|If the AD is only used for the password authentication, the file &amp;#039;&amp;#039;nsswitch.conf&amp;#039;&amp;#039;  does not have to be configured. &lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Those who want to perform the package configuration once again, to adjust values, must to call up&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  dpkg-reconfigure nslcd&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Configuration of nslcd ==&lt;br /&gt;
The following map and filter entries, binddn and bindpw, and TLS options must be added to the &amp;#039;&amp;#039;/etc/nslcd.conf&amp;#039;&amp;#039; file:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
base ou=Users,dc=example,dc=com&lt;br /&gt;
map             passwd          uid     sAMAccountName&lt;br /&gt;
filter          passwd          (objectClass=user)&lt;br /&gt;
&lt;br /&gt;
# The LDAP protocol version to use.&lt;br /&gt;
ldap_version 3&lt;br /&gt;
&lt;br /&gt;
# The DN to bind with for normal lookups.&lt;br /&gt;
binddn cn=reader,dc=example,dc=com&lt;br /&gt;
bindpw secret&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
# SSL options&lt;br /&gt;
ssl start_tls&lt;br /&gt;
tls_reqcert demand&lt;br /&gt;
tls_cacertfile /etc/ssl/certs/Example-com-cacert.pem&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
The settings of the package installation that have been configured are located, as described above, in the &amp;#039;&amp;#039;/etc/nslcd.conf&amp;#039;&amp;#039; file.&lt;br /&gt;
&lt;br /&gt;
== Configuration of pam_ldap ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;In general, the configuration of the package installation is suitable for an AD-authentication&amp;#039;&amp;#039;&amp;#039;. However, users can authenticate themselves with the standard configuration per AD/LDAP as well as with local password. To disable local passwords for users other than &amp;quot;root&amp;quot;, the following change must be made to the file &amp;#039;&amp;#039;/etc/pam.d/common-auth.conf&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Attention:&amp;#039;&amp;#039;&amp;#039; After this change, only the &amp;#039;&amp;#039;root&amp;#039;&amp;#039; user can use its local password. All other users rely on Active Directory and a working connection between the server and Active Directory:&amp;lt;ref&amp;gt;[http://pig.made-it.com/pam.html PAM Explanation] (pig.made-it.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# vi /etc/pam.d/common-auth&lt;br /&gt;
[...]&lt;br /&gt;
auth    sufficient      pam_ldap.so minimum_uid=1000&lt;br /&gt;
auth    requisite       pam_succeed_if.so uid eq 0&lt;br /&gt;
auth    sufficient      pam_unix.so nullok_secure&lt;br /&gt;
# here&amp;#039;s the fallback if no module succeeds&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
After that, AD authentication will be sufficient for all users with a UID greater than 1000 to log in. Local passwords will no longer work!&lt;br /&gt;
&lt;br /&gt;
The configuration of the AD authentication is completed after the steps described above.&lt;br /&gt;
&lt;br /&gt;
== Error analysis ==&lt;br /&gt;
=== nslcd ===&lt;br /&gt;
The daemon &amp;#039;&amp;#039;nslcd&amp;#039;&amp;#039; provides a Debus mode for analyzing the LDAP authentication:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# nslcd -d&lt;br /&gt;
nslcd: DEBUG: add_uri(ldap://ldap.example.com)&lt;br /&gt;
nslcd: DEBUG: ldap_set_option(LDAP_OPT_X_TLS_REQUIRE_CERT,2)&lt;br /&gt;
[...]&lt;br /&gt;
nslcd: accepting connections&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
If the &amp;lt;code&amp;gt;-d&amp;lt;/code&amp;gt; parameter is stated more often, the &amp;#039;&amp;#039;nslcd&amp;#039;&amp;#039; debug level increases.&lt;br /&gt;
&lt;br /&gt;
The error message is a bit misleading&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEBUG: failed to bind to LDAP server ldap://ldap.example.com: Invalid credentials: 80090308:&lt;br /&gt;
LdapErr: DSID-0C0903C8, comment: AcceptSecurityContext error, data 52e, v23f0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
that also appears when a user account does not yet exist on the server. &lt;br /&gt;
&lt;br /&gt;
=== pam_ldap ===&lt;br /&gt;
Those who want to adjust the pam-rules in the &amp;#039;&amp;#039;/etc/pam.d/common-auth.conf&amp;#039;&amp;#039; file, encounters the following error in the log file ‘’/var/log/auth.log&amp;#039;&amp;#039;:&lt;br /&gt;
&amp;lt;pre&amp;gt;pam_succeed_if(sshd:auth): incomplete condition detected&amp;lt;/pre&amp;gt;, when the terms for &amp;#039;&amp;#039;pam_succeed_if.so &amp;#039;&amp;#039; are not correct.&amp;lt;ref&amp;gt;[https://bugzilla.redhat.com/show_bug.cgi?id=594903  Insufficient error checking in pam_succeed_if] (bugzilla.redhat.com)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Gschoenberger}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Debian]]&lt;br /&gt;
[[de:Passwort-Authentifizierung mit Active Directory unter Debian einrichten]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
	<entry>
		<id>https://www.thomas-krenn.com/en/wiki/PCIe_link_lost</id>
		<title>PCIe link lost</title>
		<link rel="alternate" type="text/html" href="https://www.thomas-krenn.com/en/wiki/PCIe_link_lost"/>
		<updated>2026-05-21T11:16:45Z</updated>

		<summary type="html">&lt;p&gt;Aranzinger: Created page with &amp;quot;On Linux systems, when using Intel I350 network chips, messages such as &amp;#039;&amp;#039;&amp;#039;PCIe link lost&amp;#039;&amp;#039;&amp;#039; may appear, followed by &amp;#039;&amp;#039;&amp;#039;igb 0000:82:00.0 enp130s0f0: malformed Tx packet detected and dropped, LVMMC:0xffffffff&amp;#039;&amp;#039;&amp;#039;. Therefore, the affected network interface does not work. As a solution, the Linux kernel parameter &amp;#039;&amp;#039;&amp;#039;pcie_aspm.policy=performance&amp;#039;&amp;#039;&amp;#039; or an updated BIOS with deactivated ASPM can be used.   == Affected hardware and software == We have encountered this issue i...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;On [[Linux]] systems, when using Intel I350 network chips, messages such as &amp;#039;&amp;#039;&amp;#039;PCIe link lost&amp;#039;&amp;#039;&amp;#039; may appear, followed by &amp;#039;&amp;#039;&amp;#039;igb 0000:82:00.0 enp130s0f0: malformed Tx packet detected and dropped, LVMMC:0xffffffff&amp;#039;&amp;#039;&amp;#039;. Therefore, the affected network interface does not work. As a solution, the Linux kernel parameter &amp;#039;&amp;#039;&amp;#039;pcie_aspm.policy=performance&amp;#039;&amp;#039;&amp;#039; or an updated BIOS with deactivated ASPM can be used. &lt;br /&gt;
&lt;br /&gt;
== Affected hardware and software ==&lt;br /&gt;
We have encountered this issue in isolated cases after several weeks of testing with the following components:&lt;br /&gt;
* ASUS RS500A-E11-RS12U with [[AMD EPYC 7003 Milan]] CPU (AMD EPYC 7543P) with Intel I350-AM2&lt;br /&gt;
** BIOS 0901&lt;br /&gt;
* [[Proxmox VE]] with kernel 5.15.35-1-pve&lt;br /&gt;
&lt;br /&gt;
== Problem ==&lt;br /&gt;
Example 21.6.2022:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.890225] igb 0000:82:00.0 enp130s0f0: PCIe link lost&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.890714] ------------[ cut here ]------------&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.891150] igb: Failed to read reg 0x40e8!&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.891611] WARNING: CPU: 15 PID: 1607760 at drivers/net/ethernet/intel/igb/igb_main.c:747 igb_rd32.cold+0x3a/0x46 [igb]&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.892059] Modules linked in: sch_ingress ebtable_filter ebtables ip_set ip6table_raw iptable_raw ip6table_filter ip6_tables iptable_filter bpfilter sctp ip6_udp_tunnel &lt;br /&gt;
udp_tunnel nf_tables bonding tls openvswitch nsh nf_conncount nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 softdog nfnetlink_log nfnetlink ipmi_ssif intel_rapl_msr intel_rapl_common amd64_edac edac_&lt;br /&gt;
mce_amd kvm_amd ast drm_vram_helper drm_ttm_helper kvm ttm drm_kms_helper cec irqbypass crct10dif_pclmul rc_core ghash_clmulni_intel aesni_intel fb_sys_fops crypto_simd cryptd rapl wmi_bmof efi_pstore pc&lt;br /&gt;
spkr acpi_ipmi syscopyarea cdc_ether sysfillrect usbnet sysimgblt joydev input_leds mii ipmi_si ccp ptdma k10temp ipmi_devintf ipmi_msghandler mac_hid vhost_net vhost vhost_iotlb tap ib_iser rdma_cm iw_c&lt;br /&gt;
&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.892098]  zstd_compress hid_generic usbmouse usbkbd usbhid hid raid6_pq libcrc32c simplefb crc32_pclmul nvme nvme_core igb xhci_pci i2c_algo_bit ahci xhci_pci_renesas &lt;br /&gt;
dca libahci xhci_hcd i2c_piix4 bnxt_en wmi&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.896894] CPU: 15 PID: 1607760 Comm: nload Tainted: P           O      5.15.35-1-pve #1&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.897392] Hardware name: ASUSTeK COMPUTER INC. RS500A-E11-RS12U/KMPA-U16 Series, BIOS 0901 12/03/2021&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.897890] RIP: 0010:igb_rd32.cold+0x3a/0x46 [igb]&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.898391] Code: c7 c6 94 23 3e c0 e8 ea e4 33 ed 48 8b bb 30 ff ff ff e8 5a 2c cc ec 84 c0 74 16 44 89 ee 48 c7 c7 60 30 3e c0 e8 b9 f2 2a ed &amp;lt;0f&amp;gt; 0b e9 b8 03 fe ff e9 &lt;br /&gt;
cf 03 fe ff 0f b6 d0 be 00 00 04 00 48 c7&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.899403] RSP: 0018:ffffbc9e812d3a98 EFLAGS: 00010282&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.899906] RAX: 0000000000000000 RBX: ffff947b663fced0 RCX: ffff949a0e1e0588&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.900414] RDX: 00000000ffffffd8 RSI: 0000000000000027 RDI: ffff949a0e1e0580&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.900915] RBP: ffffbc9e812d3ab0 R08: 0000000000000003 R09: 0000000000000001&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.901411] R10: ffff947b7610c7c0 R11: ffffffffc0d410c0 R12: 00000000ffffffff&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.901902] R13: 00000000000040e8 R14: 00000000000198e8 R15: 0000000003f1d080&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.902389] FS:  00007f4cb056d740(0000) GS:ffff949a0e1c0000(0000) knlGS:0000000000000000&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.902879] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.903364] CR2: 00007f4f7bbf2670 CR3: 00000006414e8004 CR4: 0000000000770ee0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.903850] PKRU: 55555554&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.904336] Call Trace:&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.904808]  &amp;lt;TASK&amp;gt;&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.905275]  igb_update_stats+0x4c0/0x880 [igb]&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.905743]  igb_get_stats64+0x30/0x80 [igb]&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.906205]  dev_get_stats+0x60/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.906663]  netstat_show.constprop.0+0x57/0xb0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.907117]  tx_dropped_show+0x16/0x20&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.907564]  dev_attr_show+0x1d/0x40&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.908014]  sysfs_kf_seq_show+0xa1/0x100&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.908451]  kernfs_seq_show+0x27/0x30&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.908882]  seq_read_iter+0x122/0x4b0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.909309]  ? aa_file_perm+0x11e/0x570&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.909732]  kernfs_fop_read_iter+0x150/0x1b0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.910150]  new_sync_read+0x110/0x1a0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.910564]  vfs_read+0x100/0x1a0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.910970]  ksys_read+0x67/0xe0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.911368]  __x64_sys_read+0x1a/0x20&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.911766]  do_syscall_64+0x5c/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.912170]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.912560]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.912944]  ? syscall_exit_to_user_mode+0x27/0x50&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.913330]  ? __x64_sys_read+0x1a/0x20&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.913706]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.914073]  ? syscall_exit_to_user_mode+0x27/0x50&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.914431]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.914777]  ? __x64_sys_close+0x12/0x40&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.915112]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.915436]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.915745]  ? do_syscall_64+0x69/0xc0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.916052]  ? asm_sysvec_apic_timer_interrupt+0xa/0x20&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.916342]  entry_SYSCALL_64_after_hwframe+0x44/0xae&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.916623] RIP: 0033:0x7f4cb0666e8e&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.916890] Code: c0 e9 b6 fe ff ff 50 48 8d 3d 6e 18 0a 00 e8 89 e8 01 00 66 0f 1f 84 00 00 00 00 00 64 8b 04 25 18 00 00 00 85 c0 75 14 0f 05 &amp;lt;48&amp;gt; 3d 00 f0 ff ff 77 5a &lt;br /&gt;
c3 66 0f 1f 84 00 00 00 00 00 48 83 ec 28&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.917444] RSP: 002b:00007ffe81260f78 EFLAGS: 00000246 ORIG_RAX: 0000000000000000&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.917719] RAX: ffffffffffffffda RBX: 0000000000001fff RCX: 00007f4cb0666e8e&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.917988] RDX: 0000000000001fff RSI: 000055e09cb3adf0 RDI: 0000000000000003&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.918250] RBP: 000055e09cb3adf0 R08: 0000000000000000 R09: 00007f4cb0736be0&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.918508] R10: 0000000001000000 R11: 0000000000000246 R12: 0000000000001fff&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.918764] R13: 00007ffe81261118 R14: 000055e09bc21398 R15: 000055e09bc21370&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.919020]  &amp;lt;/TASK&amp;gt;&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.919272] ---[ end trace e754faf722c4d59f ]---&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.919529] igb 0000:82:00.0 enp130s0f0: malformed Tx packet detected and dropped, LVMMC:0xffffffff&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.919586] igb 0000:82:00.1 enp130s0f1: PCIe link lost&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.920381] ------------[ cut here ]------------&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.920832] igb: Failed to read reg 0xc030!&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.921292] WARNING: CPU: 47 PID: 1607760 at drivers/net/ethernet/intel/igb/igb_main.c:747 igb_rd32.cold+0x3a/0x46 [igb]&lt;br /&gt;
Jun 21 00:53:43 PMX2 kernel: [568234.921782] Modules linked in: sch_ingress ebtable_filter ebtables ip_set ip6table_raw iptable_raw ip6table_filter ip6_tables iptable_filter bpfilter sctp ip6_udp_tunnel &lt;br /&gt;
udp_tunnel nf_tables bonding tls openvswitch nsh nf_conncount nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 softdog nfnetlink_log nfnetlink ipmi_ssif intel_rapl_msr intel_rapl_common amd64_edac edac_&lt;br /&gt;
mce_amd kvm_amd ast drm_vram_helper drm_ttm_helper kvm ttm drm_kms_helper cec irqbypass crct10dif_pclmul rc_core ghash_clmulni_intel aesni_intel fb_sys_fops crypto_simd cryptd rapl wmi_bmof efi_pstore pc&lt;br /&gt;
spkr acpi_ipmi syscopyarea cdc_ether sysfillrect usbnet sysimgblt joydev input_leds mii ipmi_si ccp ptdma k10temp ipmi_devintf ipmi_msghandler mac_hid vhost_net vhost vhost_iotlb tap ib_iser rdma_cm iw_c&lt;br /&gt;
m ib_cm ib_core iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi drm sunrpc ip_tables x_tables autofs4 zfs(PO) zunicode(PO) zzstd(O) zlua(O) zavl(PO) icp(PO) zcommon(PO) znvpair(PO) spl(O) btrfs blak&lt;br /&gt;
e2b_generic xor&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Beispiel 26.6.2022:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[...]&lt;br /&gt;
Jun 26 18:46:36 PMX2 kernel: [1064607.600707] igb 0000:82:00.0 enp130s0f0: malformed Tx packet detected and dropped, LVMMC:0xffffffff&lt;br /&gt;
Jun 26 18:46:37 PMX2 kernel: [1064608.624690] igb 0000:82:00.1 enp130s0f1: malformed Tx packet detected and dropped, LVMMC:0xffffffff&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Possible solutions ==&lt;br /&gt;
&lt;br /&gt;
=== Updated BIOS ===&lt;br /&gt;
The new BIOS version 1301 (Milan, 2023/03/15) deactivates ASPM on all PCIe ports (&amp;lt;cite&amp;gt;Disable ASPM on all PCIe ports.&amp;lt;/cite&amp;gt;) and resolves the problem.&lt;br /&gt;
&lt;br /&gt;
=== Kernel parameter === &lt;br /&gt;
Alternatively, as a workaround, the PCIe ASPM policy can be set to performance using the following kernel boot parameter:&amp;lt;pre&amp;gt;sed -i &amp;#039;$ s/$/ pcie_aspm.policy=performance/&amp;#039; /etc/kernel/cmdline&amp;lt;/pre&amp;gt;&lt;br /&gt;
On systemd-boot-systems, this command adds the parameter to the /etc/kernel/cmdline file. On Proxmox systems, a refresh of the Proxmox boot tool must be performed after changing the file:&lt;br /&gt;
&amp;lt;pre&amp;gt;proxmox-boot-tool refresh&amp;lt;/pre&amp;gt;After a reboot, it can be verified if the parameters are active using &amp;lt;pre&amp;gt;cat /proc/cmdline&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== More information ==&lt;br /&gt;
* [https://access.redhat.com/solutions/2190691 igb &amp;quot;malformed Tx packet detected and dropped, LVMMC&amp;quot; message] (access.redhat.com, 05.03.2016)&lt;br /&gt;
* [https://access.redhat.com/solutions/6753701 Intel I350 NIC with igb logs &amp;quot;Refused to change power state&amp;quot; and &amp;quot;PCIe link lost&amp;quot;] (access.redhat.com, Updated February 23 2022)&lt;br /&gt;
* [https://patchwork.ozlabs.org/project/netdev/patch/1406207604-31653-6-git-send-email-jeffrey.t.kirsher@intel.com/ igb: Add message when malformed packets detected by hw] (patchwork.ozlabs.org, 24.07.2014)&lt;br /&gt;
* [https://community.zyxel.com/en/discussion/2574/degraded-gigabit-problem-with-gs1200-8 Degraded Gigabit problem with GS1200-8] (community.zyxel.com, April 2019)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Wfischer}}&lt;br /&gt;
{{Jsterr}}&lt;br /&gt;
{{Aranzinger}}&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:Proxmox Troubleshooting]]&lt;br /&gt;
[[de:PCIe link lost]]&lt;/div&gt;</summary>
		<author><name>Aranzinger</name></author>
	</entry>
</feed>