Author: Corey

m0n0wall And You: Die Harder

hardware : by Corey — October 24th 2006, 12:11PM
hardwareRecently, the router at the gym where I work out has been going on the fritz. It's a D-Link DI-524 so it stands to reason. As the local technology consultant for the gym, I convinced them to allow me to build a m0n0wall box for them.

The issue is that the gym is a small private studio and they are trying very hard to make it look chic and fashionable. To me, this means that they'd rather not have a honking Dell Optiplex G1 like the unit I built a few months ago. I found a solution over in SA's SH/SC forum: The IBM NetVista N2800 8364 Thin Client.

In the thread, a guy from England discussed how he made his unit work. His site has a good write-up on how to accomplish it, including this image where he outlines what is what inside the case. I picked up an 8364 off eBay for $55 shipped.

Dealing with the two BIOS flavors can be a bit daunting if you're not experienced in editing BIOS settings so if you attempt to do this, please make sure you're not dumb. But even if you are, there is a PWD_RST jumper that will restore everything back to the land of lollypops and bikinis.

The issue I'm having at the moment is one that apparently plagues the Ethernet models of the 8364. During the Linux boot process, the screen becomes garbled and the machine eventually locks. As recommended on the aforementioned page, enabling the on-board Ethernet controller seems to solve this problem.

While that was well and fine, a new problem that is undocumented as far as I can tell has emerged. The keyboard I am using to assign interfaces as well as the LAN IP address is not functioning correctly when attached to the thin client. The same keyboard works fine on my server so I know the keyboard is not the issue. Strange characters are entered for every keystroke and always entered twice. It's the oddest thing I've seen in a while. If anyone has any ideas how to work around this, please leave a comment. I'll post an update when I get it resolved.

Now, what did I do with that USB keyboard...

Late to the game.

games : by Corey — May 21st 2006, 10:10AM
gamesA couple of weeks ago I ordered an Xbox from a guy on the SA Forums. I paid $80 shipped and felt that this was a good deal considering that new units are still running $180 in stores. After a shipping snafu, I received my Xbox. It was in a box with no padding and had made three trips to and from the east coast. I'm sure that the package had been the game ball in a FedEx corporate soccer tournament. This did not bode well.

And indeed, the DVD drive had ceased to function properly. I found large caches of drives on eBay for $40 shipped. I bit the bullet and bought one from the closest shipper I could find. So now I was at $120 for my v. 1.0 Xbox (made in Hungary!) when for $40 more I could have a brand new one (made in Mexico!). In any event, I realized that Microsoft was attempting to subsidize the odd screw market and invested in three different sizes of Torx screws to secure the case and internal components as well as needlessly making my life more difficult.

I had ordered a set of T10, T15, and T20 Torx screwdrivers from Northern Tool but they would not bee here until a couple of days from now. I found myself at Fry's yesterday and so picked up a 9-in-1 Torx tool that included the correct sizes for the Xbox. I'm still wondering why the Phillips head isn't getting as much love these days. Thankfully the computer hardware industry has kept with Phillips, be it ever so skewed in choice for head size.

I woke up this morning and, after scratching my head for five minutes then finding the two stupid hidden screws, popped the case off. The folks up in Redmond took a page out of Dell's case design with this one. They jammed more crap in this box than I would've thought could be allowed by UL or FCC safety standards. And yet, here it sits. The only redeeming feature about the design is that the optical and hard drives both sit flat and not in some impenetrable cage. The plastic risers weren't a terrible chore and actually did a nice job. So I swapped the drives out and all was well. At least until I realized I left the game disc in the drive I just took out.

Times like that make you humble. Some might say they are character building. We've all had them and they're good for the enterprising geek. They make us realize that we're capable of being just as dumb as the people who allow some of us to charge them upwards of $75 in labor for installing a new stick of RAM.

After a quick power switch I had the disc and Burnout Revenge was loading in its new home. Playing four or five missions left me with the feeling that the problem was thankfully resolved. In a way I'm glad I had to take it apart and replace the drive; now I know how to do it when I install my mod chip and load XBMC. After all, that was my real goal here: a media center that can stream content from my main machine, file server, or other device that someone may bring over. And it fills up the last open port on my Ethernet switch; nothing brings a sense of accomplishment like crashing cars and a full switch.

01:02:03 04/05/06

news : by Corey — April 4th 2006, 07:11PM
newsWhere will you be at 01:02:03 on 04/05/06? Though I could stay up until 1AM my old man complex I've recently developed puts me to bed well before that. I'll be up for the second one, though!

Grendel sez: That's 01:02:03pm for our more dense readers.

m0n0wall and you - part tres!

hardware : by Corey — February 12th 2006, 10:32AM
hardwareSo the system hardware is configured and ready to go. It's now time to install the m0n0wall image onto the CF card. Because my main machine is Windows, I used PhyDiskWrite 0.5.1 to unpack the image and write it to the card. It's a handy command line utility written specifically for Windows users who need to write the m0n0wall generic PC image to a CF card. Do be aware of what disk interface you select to write to when running this application; it displays all logical drives on your system so you could potentially write the image to one of your hard drives. That would be bad, m'kay?

Once the image is written, simply plug the card into the adapter and boot the machine. Upon booting the G1, I noticed that the BIOS revision was A06 and having looked at the Dell site I knew A10 was available. Having already removed the floppy drive from the machine, I was not apt to update it unless it was necessary. As it turns out, it was not.

Fire it up and pray you did everything correctly. Prior to installing the CF to IDE adapter and card I did boot the machine and make BIOS edits. I turned off all interfaces not required for operation and ensured that nothing else was amiss. During the initial boot, you will need to connect the machine to a monitor and have a keyboard connected. If you're running it on a virtual machine or have a serial port you can use HyperTerminal through a console. For me, that was a lot more trouble that in it was worth considering that the G1 has a video card built in.

After the boot process completes, m0n0wall is up and running. You're greeted with a list of options that looks much like this. The first thing you'll need to do is assign interfaces. It is interesting to note how m0n0wall sensed the two NICs present in the machine; one integrated and one PCI. The PCI NIC was presented first and thus made into the WAN interface; the integrated NIC was then made into the LAN NIC. For units without integrated NICs, the PCI slot closest to the AGP slot will probably come up as the first interface. After assigning interfaces, I set the LAN IP to my normal networking scheme of 10.0.0.254/24; With the 24 subnet, DHCP clients have 10.0.0.1-253 to use.

Once this is accomplished, I connected cables. One Cat5 to my cable modem; the other to my Dell Powerconnect 2016 10/100 switch. I also have a Netgear FS-104 five port switch for my media center. You can set up an optional third interface for a separate subnet as well as VLAN tagging but all of that is overly complicated for my simple home network. After powercycling the router and the cable modem the network was operational. All of my clients received DHCP leases according to the default settings in m0n0wall; two hours by default and a maximum of two days.

Now that all the interfaces are operational, I can access the web-based GUI for m0n0wall. Much like consumer routers, opening a browser and navigating to the router's LAN IP works for this. The options in m0n0wall are quite extensive and do require some basic networking skills to properly configure and implement things like firewall rules and NAT rules, known in some circles as port forwarding. Because I'm not going into great detail here, you can read the documentation on all of the features by clicking here.

The first thing to do is, of course, set a password and the time zone for logging purposes. The only other really special settings I needed were to enable the PPTP VPN server so that I can create an encrypted tunnel for VNC when I'm at work or away from home. To this point I've been using VNC unencrypted over the commodity Internet because I had neither the hardware nor the time to set up an SSH tunnel for windows or a generic VPN server. m0n0wall comes with both PPTP and IPSec VPN server capabilities; the PPTP flavor works best with Windows XP. It is important to note that when setting up the VPN, all of the options it asks for are internal. That is, the server IP should be an internal address; same with the DHCP leases it gives out on a /28 subnet. Because it requires /28, be sure your private assignable space starts with 192 (ex: 10.0.1.192). After this is done, check the box that adds a firewall rule and save the settings. Create a user and you're good to go.

It is important to note that interface or protocol changes are not implicitly applied to the firewall like they are in most consumer networking routers. When you create something like a PPTP VPN or other interface feature, you must also add a firewall rule to allow that traffic to pass. Most setup screens in the GUI prompt you with a checkbox to create a firewall rule for you. If you choose not to do this, it's ok. Just remember why you can't connect later. =)

To say that m0n0wall is fully featured is an understatement; it has everything you could ever want in an enterprise-grade router with none of the fuss and certainly a lot less expense. As a geek, I was overjoyed when the entire unit worked almost completely out of the box. Minimal problems have been experienced in three days of duty.

For action shots, click here and here.

m0n0wall and you - part deaux!

hardware : by Corey — February 12th 2006, 09:35AM
hardwareAfter some rather interesting deals with FedEx, I finally received all the parts required to build my m0n0wall system. It should be noted that this was among the easiest projects I've ever undertaken which is remarkable given that m0n0wall requires some intermediate level of networking skill and my last experience with *NIX operating systems left me with nothing other than feelings of general hostility.

I was in a quandary as to what type of system to base the firewall off of. Tommy has a lovely MiniITX board that runs completely solid state when booting off the CF card. The only problem is that those all-in-one systems can run upwards of $180 before memory. The embedded PCs that m0n0wall was designed to operate on also suffer from the same types of cost. I'm in agreement with Tommy that most of it is due to lack of demand. I decided that it would be more cost effective as an enterprising young lad living in one of the most expensive places on earth to acquire some old PC; something on the order of 400MHz of processing power and 128MB of RAM or so (the m0n0wall minimum is 64 for swap space).

I ordered a Dell Optiplex G1 from RetroBox.Com. They specialize in reselling old gear that is surpluses by corporations when they upgrade their technology. For $48 shipped I received a 400MHz slot Celeron with 192MB of PC133 RAM. It was nearly perfect for what I'm trying to do. When I received the unit, I promptly stripped out the 4GB hard drive, generic CD-ROM, floppy drive, and PCI sound card. See pics here.

After cleaning everything out, it was time to install the CF to IDE Adapter I purchased. It takes a standard 40-pin IDE cable but with one exception; it has a pin for the dead pin spot just above the center notch. Having no IDE cables that fit this job, on the advice of a buddy I warmed a knife and melted the plastic covering the hole. The pin inserted nicely and everything was fine. Under the CF card are the instructions for jumper settings; it came configured for standard voltage and to be the master drive on the IDE channel so no changes were required. It takes a standard floppy power connecter and the LEDs are very bright. See pics here.

The next thing to do was to add an NIC. The motherboard on the G1 came with a 3COM 10/100 NIC built in. I needed an extra interface for WAN/LAN connectivity. Because m0n0wall is built on FreeBSD 4.x, I felt relatively comfortable pulling an old NIC out of a stack I have in my Cabinet O' Geek™ and slapping it in. As you'll see in the next installment, this was not a problem. It was interesting, however, to see how m0n0wall read the interfaces.

The next (and final) installment will cover loading the m0n0wall image on the CF card and initial setup of the unit. Thanks for reading.