Linux Material For 6&7
Linux Material For 6&7
Linux Material For 6&7
Ratnakar Page 1
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 2
Abhisol : RED-HAT LINUX 6/7
2. What is a user?
In Linux user is one who uses the system.
Type of
Example User ID Group ID Home Directory Default Shell
User
Super User Root 0 0 /root /bin/bash
Normal users
Same as Same as
Sudo User with admin /home/<user name> /bin/bash
normal users normal users
privileges
Ratnakar Page 3
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 4
Abhisol : RED-HAT LINUX 6/7
19. What are the uses of .bash_logout, .bash_profile and .bashrc files?
.bash_logout : is a user's logout ending program file. It will execute first whenever the user is logout.
.bash_profile : is user's login startup program file. It will execute first whenever the user is login. It
consists the user's environmental variables.
.bashrc : This file is used to create the user's custom commands and to specify the umask values for
that user's only.
21. What is the command to check the user belongs to how many groups?
# groups <user name>
Ratnakar Page 5
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 6
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 7
Abhisol : RED-HAT LINUX 6/7
Defaults : <user1>, <user2>, <user3> timestamp_timeout=0 (the system will ask passwords for user1, user2,
user3 to execute sudo commands)
33. How to assign the password to normal user by him whenever first login to the system?
Whenever the user is created and that user is trying to login to the system, it will ask the password. If
the root user is not assign the password to that user, then that normal user can assign the password by his
own using the following commands.
# useradd <user name> (to create the user)
# passwd -S <user name> (to see the status of the password of that user. if root user is not
assigned the password then the password status is locked)
# passwd -d <user name> (then delete the password for that user)
# chage -d 0 <user name> (it will change the password age policy)
# su - <user name> (Try to switch to that user then it will display the following
message)
Newpassword : (type new password for that user)
Retype password : (retype the password again)
The other useful commands :
# w (this command gives the login user information like how many users currently login and full
information )
# who (to see users who are currently login and on which terminal they login)
# last (see the list of users who are login and logout since the /var/log/wtmp file was
created)
# lastb (to see the list of the users who tried as bad logins)
# lastreboot (to see all reboots since the log file was created)
# uptime (to see the information from how long the system is running, how many
users login
and load average)
* The load average is from 1 sec : 5 secs : 15 secs
# df (to see the mounted partitions, their mount points and amount of disk space)
# du (to see the disk usage of the each file in bytes)
# uname -r (gives the current kernel version)
# last -x (It shows last shutdown date and time)
# last -x grep shutdown (only shutdown time shows ie., grep will filter the 'last -x' command)
* grep: It is used to search a word or sentence in file (ie., inside the file)
* find : It is used to search a command or file inside the system)
# cat /etc/shells or # chsh -l (to see how many shells that are supported by Linux)
/bin/sh -----> default shell for Unix
/bin/bash -----> default shell for Linux
/sbin/nologin -----> users cannot login shell
/bin/tcsh -----> c shell to write 'C++' language programs
/bin/csh -----> c shell to write 'C' language programs
# echo $SHELL (to see the current shell)
# chsh <user name> (to change the user's shell)
Changing shell for <user name> :
New shell : <type new shell for example /bin/sh to change the current shell>
New shell changed (But it will effect by restarting the server)
# date + %R (to display the time only)
# date + %x (to display the date only)
Ratnakar Page 8
Abhisol : RED-HAT LINUX 6/7
# ls -ld <directory name> (to see the long listing of the directories)
# stat <file name/directory name> (to see the statistics of the file or directory)
Ratnakar Page 9
Abhisol : RED-HAT LINUX 6/7
35. What are permission types available in Linux and their numeric representations?
There are mainly three types of permissions available in Linux and those are,
read ----- r ----- 4 null permission ------ 0
write ----- r ----- 4
execute ----- r ----- 4
Permissions File Directory
r Read a file Ex. # cat <file name> Read a directory contents Ex. ls /dir
w Create, delete or modify the file contents Create, delete or modify the files in a directory
Not required for file. It is required only for
x Go to inside the directory Ex. # cd /dir
scripting files
Ratnakar Page 10
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 11
Abhisol : RED-HAT LINUX 6/7
(iii) So, using this file we can easily get users information.
Shadow file : (i) This file tells about the login id, user's encrypted password, password when last
changed, min. days the password valid, max. days valid, warning days, inactive days and expiry days.
(ii) If shadow file is missed or deleted we can recover those entries of shadow file using password file.
(iii) We can change the users encrypted passwords with the permissions of the higher authorities in
case of emergency.
RHEL - 7 :
(i) Restart the system.
(ii) Using arrow keys select 1st line and press 'e' to edit.
(iii) Go to Linux 16 line press End key or Ctrl + e to go to the end of the line and give one space.
(iv) Then type as rd.break console=tty1 selinux=0
(v) Then press Ctrl + x to start the computer in single user mode.
(vi) After starting we get swith_root :/# prompt appears and then type as follows.
(vii) # mount -o remount, rw /sysroot and press Enter and then type as follows.
(viii) # chroot /sysroot press Enter.
(ix) Then sh - 4.2 # prompt appears and type as
(x) sh - 4.2 #passwd root
New password : XXXXXX
Retype password : XXXXXX
(xi) sh - 4.2 # exit
(xii) switch-root :/# exit
(xiii) Then the system starts and the desktop appears.
Ratnakar Page 12
Abhisol : RED-HAT LINUX 6/7
54. How to find the users who are login and how to kill them?
# fuser -cu (to see who are login)
#fuser -ck <user login name> (to kill the specified user)
Ratnakar Page 13
Abhisol : RED-HAT LINUX 6/7
59. What is the syntax to assign read and write permissions to particular user, group and other?
# setfacl -m u : <user name> : <permissions><file or directory>
# setfacl -m g : <user name> : <permissions><file or directory>
# setfacl -m o : <user name> : <permissions><file or directory>
60. What is the syntax to assign read and write permissions to particular user, group and other at a
time?
# setfacl -m u : <user name> : <permissions>, g : <user name> : <permissions>, o : <user name> :
<permissions><file or directory>
Useful commands :
# setfacl -x u : <user name><file or directory name> (to remove the ACL permissions from the
user)
# setfacl -x g : <user name><file or directory name>(to remove the ACL permissions from group)
# setfacl -x o : <user name><file or directory name> (to remove the ACL permissions from other)
# setfacl -b <file or directory> (to remove all the ACL permissions on that file directory)
61. How will you lock a user, if he enters wrong password 3 times?
pam_tally.so module maintains a count of attempted accesses, can reset count on success, can deny
access if too many attempts fail. Edit /etc/pam.d/system-auth file, enter:
(i) # vi /etc/pam.d/system-auth
Modify as follows:
auth required pam_tally.so no_magic_root
account required pam_tally.so deny=3 no_magic_root lock_time=180
Where,
deny=3 : Deny access if tally for this user exceeds 3 times.
lock_time=180 : Always deny for 180 seconds after failed attempt. There is alsounlock_time=n option. It allow
access after n seconds after failed attempt. If this option is used the user will be locked out for the specified
amount of time after he exceeded his maximum allowed attempts. Otherwise the account is locked until the
lock is removed by a manual intervention of the system administrator.
magic_root : If the module is invoked by a user with uid=0 the counter is not incremented. The sys-admin
should use this for user launched services, like su, otherwise this argument should be omitted.
no_magic_root : Avoid root account locking, if the module is invoked by a user with uid=0
Save and close the file.
Ratnakar Page 14
Abhisol : RED-HAT LINUX 6/7
First check whether the quota package is installed or not by # rpm -qa |grep quota command.
If quota package is not Installed then install the quota package by # yum install quota* -y command.
# quotaon (to enable the quota)
# quotaoff (to disable the quota)
# edquota (to edit or modify the quota)
# repquota (to display or report the present quota)
# quotacheck (to create a quota database)
* quotas cab be applied on file systems only.
# edquota -p <user name 1><user name 2> (to apply user name 1 quotas to user name 2, ie., no
need to edit the quota editor for user
name 2)
Ratnakar Page 15
Abhisol : RED-HAT LINUX 6/7
(ii) Update the quota on mount point by # mount -o remount, usrquota, grpquota <mount point>command.
(iii) Create the user quota database by # quotacheck -cug <mount point> command (where -c means
created the quota database, -u means user quota and -g means group quota ).
(iv) Check whether the quota is applied or not by # mount command.
(v) Enable the quota by # quotaon <mount point> command.
(vi) Apply the user quota for a user by # edquota -g <group name><mount point> command.
File system blocks soft hard inodes soft
hard
/dev/sdb1 0 0 0 0 0
0
blocks -----> No. of blocks used (already)
soft -----> Warning limit
hard -----> Maximum limit
0 -----> Unlimited usage
inodes -----> No. of files created (already)
* Here we can specify the block level quota or file level quotas.
* group quota can be applicable to all the users of that specified group.
(save and exit the above quota editor)
Ratnakar Page 16
Abhisol : RED-HAT LINUX 6/7
1. What is partition?
A partition is a contiguous set of blocks on a drive that are treated as independent disk.
2. What is partitioning?
Partitioning means to divide a single hard drive into many logical drives.
Ratnakar Page 17
Abhisol : RED-HAT LINUX 6/7
It is a method of storing the data in an organized fashion on the disk. Every partition on the disk
except MBR and Extended partition should be assigned with some file system in order to make them to store
the data. File system is applied on the partition by formatting it with a particular type of file system.
Ratnakar Page 18
Abhisol : RED-HAT LINUX 6/7
14. What are differences between the ext2, ext3, ext4 and xfs file systems?
S.No. Ext2 Ext3 Ext4
1. Stands for Second Stands for Third Extended Stands for Fourth
Extended file system. file system. Extended file system.
2. Does not having Journaling Supports Journaling Supports Journaling
feature. feature. feature.
3. Max. file size can be from Max. file size can be from Max. file size can be from
16 GB to 2 TB. 16 GB to 2 TB. 16 GB to 16 TB.
4. Max. file system size can Max. file system size can Max. file system size can
be from 2 TB to 32 TB be from 2 TB to 32 TB be from 2 TB to 1 EB
*1EB = 1024 Peta bytes.
16. The partitions are not mounting even though there are entries in /etc/fstab. How to solve this
problem?
First check any wrong entries are there in /etc/fstab file. If all are ok then unmount all the partitions
by
executing the below command,
# umount -a
Then mount again mount all the partitions by executing the below command,
# mount -a
17. When trying to unmounting it is not unmounting, how to troubleshoot this one?
Some times directory reflects error while unmounting because,
(i) you are in the same directory and trying to unmount it, check with # pwdcommand.
(ii) some users are present or accessing the same directory and using the contents in it, check this
with
# fuser -cu <device name> (to check the users who are accessing that partition)
# lsof <device name> (to check the files which are open in that mount point)
# fuser -ck <opened file name with path> (to kill that opened files)
Now we can unmount that partition using # umount <mount point>
Ratnakar Page 19
Abhisol : RED-HAT LINUX 6/7
# mount -l (to list all the mounted partitions along with their labels)
27. How to check the integrity of a file system or consistency of the file system?
Ratnakar Page 20
Abhisol : RED-HAT LINUX 6/7
# fsck <device or partition name>command we can check the integrity of the file system.
But before running the fsck command first unmount that partition and then run fsck command.
28. What is fsck check or what are the phases of the fsck?
(a) First it checks blocks and sizes of the file system
(b) Second it checks file system path names
(c) Third it checks file system connectivity
(d) Fourth it checks file system reference counts (nothing but inode numbers)
(e) Finally it checks file system occupied cylindrical groups
29. Why the file system should be unmount before running the fsck command?
If we run fsck on mounted file systems, it leaves the file systems in unusable state and also deletes
the data. So, before running the fsck command the file system should be unmounted.
31. How to extend the root file system which is not on LVM?
By using # gparted command we can extend the root partition, otherwise we cannot extend
the file systems which is not on LVM.
34. How to know which file system occupy more space and top 10 file systems?
# df -h <device or partition name> | sort -r | head -10
39. How to find how many disk are attached to the system?
# fdisk -l (to see how many disk are attached to the system)
Ratnakar Page 21
Abhisol : RED-HAT LINUX 6/7
Whenever we want to store the data into the hard disk, if the input/output error occurs then the
Superblock of the file system may be erased or corrupted. So, we have to restore or repair that
Superblock.
# umount <file system mount point> (to unmount the file system)
# dumpe2fs </dev/vgname/lvname> | grep superblock (to list the superblocks first primary
superblock and then secondary superblock and so on)
# e2fsck -b <copy and paste the secondary super block from the above list></dev/vgname/lvname>
(to restore the damaged superblock)
# mount -a (to mount the file system)
42. How to create the file systems with the user specified superblock reserve space?
# mkfs.ext4 -m <no.><partition name> (to format the partition with <no.>% of reserve space to
superblock)
Whenever we format the file system, by default it reserve the 5% partition space for Superblock.
Important Commands :
# fsck <partition name> (to check the consistency of the file system)
# e2fsck <partition name> (to check the consistency of the file system in interactive
mode)
# e2fsck -p <partition name> (to check the consistency of the file system without interact
mode)
# mke2fs -n <partition name> (to see the superblock information)
# mke2fs -t <file system type><partition name> (to format the partition in the specified filesys type)
# mke2fs <partition name> (to format the partition in default ext2 file system type)
# blockdev --getbs /dev/sdb1 (to check the block size of the /dev/sdb1 file system)
# fsck <device or partition name> (to check and repair the file system)
Note: Before running this command first unmount that partition then run fsck command.
# umount -a (to unmount all the file systems except ( / ) root file system)
# mount -a (to mount all the file systems which are having entries in /etc/fstab file)
# fsck -A (to run fsck on all file systems)
# fsck -AR -y (to run fsck without asking any questions)
# fsck -AR -t ext3 -y (to run fsck on all ext3 file systems)
# fsck -AR -t no ext3 -y (to run fsck on all file systems except ext3 file systems)
# fsck -n /dev/sdb1 (to see the /dev/sdb1 file system report without running fsck)
# tune2fs -l /dev/sdb1 (to check whether the journaling is there or not)
# tune2fs -j /dev/sdb1 (to convert ext2 file system to ext3 file system)
# tune2fs -l /dev/sdb1 (to check whether the journaling is added or not)
# tune2fs -O ^has_journal /dev/sdb1 (to convert ext3 file system to ext2 file system)
# tune2fs -O dir_index, has_journal, unit_bg /dev/sdb1 (to convert ext2 file system to ext4 file system)
# tune2fs -O extents, dir_index, unit_bg /dev/sdb1 (to convert ext3 file system to ext4 file system)
# mount -o remount, rw /dev/sdb1 (to mount the partition with read and write permissions)
# mount -o remount, ro /dev/sdb1 (to mount the partition with read only permissions)
# mount < directory name> (to check whether this directory is mount/ normal directory)
# dump2fs <device or partition name> (to check the metadata of the partition and repair the metadata)
# fdisk -l (to list total hard disks attached to system and their partitions)
# fuser -cu <device or partition name> (to see the users who are accessing that file system)
# fuser -cK <device or partition name> (to kill the users processes who accessing the file systems)
Note: Even though we kill those users processes sometimes we cannot unmount those partitions, so if this
Ratnakar Page 22
Abhisol : RED-HAT LINUX 6/7
situation arises then first see the process id's of the user opened files by
# lsof <mount point>
# kill -9 <process id> killthose processesforcefully
# journalctl (It tracks all the log files between two different timings and by default saved in /run/log )
* /run/log is mounted on tmpfs file system. ie., if system is rebooted, the whole information in that
location will be deleted or erased.
* We can change the location of the /run/log to another like /var/log/journal by
# mkdir -p /var/log/journal (to make a directory in /var/log location)
# chown root : systemd-journal /var/log/journal (to change the group ownership of /var/log/journal)
# chmod g+s /var/log/journal (to set the sgid on /var/log/journal)
# killall -URS1 systemd-journald (It is necessary to kill old /run/log process and the location of journal
messages is changed to /var/log/journal)
# journalctl -n 5 (to display last five lines of all the log files)
# journalctl -p err (to display all the error messages)
# journalctl -f (to watch journalctl messages continuously)
# journalctl --since<today> or <yesterday> (to see all the journalctl messages since today or yesterday)
# journalctl --since "date" --until "date" (to see the journal messages between the specified two dates)
# journalctl -pid=1 (to see the pid=1 process name)
# auditctl (to see the audit report).
2. Logical Volume Management and RAID Levels
Ratnakar Page 23
Abhisol : RED-HAT LINUX 6/7
(vi) Create a mount point to mount the above created LVM file system by,
# mkdir /mnt/<directory name>
(vii) Mount the LVM on the above created mount point temporarily by,
# mount /dev/<volume group name>/<logical volume name><mount point>or
Mount the LVM on mount point permanently by,
# vim /etc/fstab
/dev/<VG name>/<LV name> /mnt/<directory> <file system type> defaults 0
0
Esc+:+wq!
# mount -a
# df -hT (to see the mounted partitions with file system types)
4. How to see the details of the Physical Volumes?
# pvs (displays all physical volumes with less details)
# pvdisplay (displays all physical volumes with more details)
# pvdisplay <physical volume name> (displays the details of the specified physical volume)
# pvscan (to scan all the physical volumes)
#pvscan <PV name> (to scan the specified physical volume)
5. How to see the details of the Volume Groups?
# vgs (displays all volume groups with less details)
# vgdisplay (displays all volume groups with more details)
# vgdisplay <VG name> (displays the specified volume group with more details)
# vgscan (to scan all the volume groups)
# vgscan <VG name> (to scan the specified volume group)
6. How to see the details of the Logical Volumes?
# lvs (displays all logical volumes with less details)
# lvdisplay (displays all logical volumes with more details)
# lvdisplay <LV name> (displays the specified logical volume details)
# lvscan (to scan all the logical volumes)
# lvscan <LV name> (to scan the specified logical volume)
7. How to extend the Volume Group?
Extending the volume group is actually adding a new physical volume to the volume group.
To extend the volume group we need to create a new partition using # fdisk command and make sure that it's
partition id should be 8e, save the changes and update the partition table by # partprobe
Create a physical volume on the newly created partition using # pvcreate command.
Add the partition to the volume group using # vgextend command
Example : # fdisk /dev/sdb
Command (m for help) : n
First cylinder : press Enter for default one
Last cylinder : +500M (create 500MB partition)
Command (m for help) : t (to change the partition id)
Select the partition : type the partition number
Specify the Hexa code : 8e
Command (m for help) : w (to save the changes)
# partprobe /dev/sdb1
# pvcreate /dev/sdb1
# vgextend <VG name> /dev/sdb1
# vgdisplay <VG name> (to check the size of the volume group)
8. How to extend the logical volume and update it's file system?
Ratnakar Page 24
Abhisol : RED-HAT LINUX 6/7
Sometimes the file system size may be full, so we need to increase the size of the logical volume to continue
adding the data in it.
The size of the logical volume can be increased online, no downtime required.
Check current size of the logical volume by # lvdisplay <LV name>and the size of the file system by # df -
hT command.
Increase the size of the logical volume by # lvextend or # lvresize commands.
Then finally update the file system by # resize2fs or # xfs_growfs commands.
Example : # df -hT
# lvextend -L +<size in MB></dev/vgname/lvname> or
# lvresize -L +<size in MB></dev/vgname/lvname>
# resize2fs </dev/vgname/lvname>
# lvdisplay </dev/vgname/lvname> (to check the size of the logical volume)
# df -hT (to check the size of the file
system)
9. How to reduce the logical volume and update the file system?
Reducing the size of the logical volume is a complicated task and we have remember some points before
reducing the logical volume, otherwise the file system may be damaged .
Logical volume size cannot be reduced online and it requires downtime because we have to unmount the file
system by # umount <file system mount point>command.
Check the consistency of the file system by # e2fsck <device or partition name> command.
Reduce the logical volume by # lvreduce -L - <Size of in MB></dev/vgname/lvname> command.
Then update the file system by # resize2fs </dev/vgname/lvname>
Finally mount the file system by # mount -a
Example : # umount <file system mount point>
# e2fsck <device or partition name>
# lvreduce -L -<size in MB></dev/vgname/lvname>
# resize2fs </dev/vgname/lvname>
# lvdisplay </dev/vgname/lvname> (to check the size of the logical volume>
# mount -a (to mount the file system)
# df -hT (to check the size of the file system)
10. How to move or migrate the logical volume data from one physical volume to another physical
volume?
There might be a situation where the physical volume might be failing and it is required to replaced. In such
case, we need to migrate or move the logical volume data from the failed physical volume new physical
volume and isolate (remove) the failed physical volume.
First access the mount point of the failing physical volume and check the data in it.
Verify the size of the physical volume by #pvs or #pvdisplay </dev/vgname/lvname>command.
Unmount the file system of that physical volume by # umount <file system mount point>
Add a new physical volume and the size should be same size or higher than that failing physical volume.
Migrate the physical volume contents to the new physical volume using # pvmove <old PV><new PV>
Mount back the logical volume, access the mount point and verify the data in it.
Remove the failed the physical volume by #vgreduce <vgname><pvname> command.
Example : # cd <file system mount point>
# ls
# pvs <pvname> or # pvdisplay <pvname>
# umount <file system mount point>
# pvcreate <device or partition name>
#vgextend <vgname><pvname>
# pvmove <old pvname><new pvname>
# mount -a
# vgreduce <vgname><failed pvname>
# cd <file system mount point>
# ls
11. How to delete or remove the logical volume?
To delete or remove the logical volume, first unmount the file system by # umount <mount point>
Remove the entry in /etc/fstab file.
Remove the logical volume by # lvremove </dev/vgname/lvname>command.
Ratnakar Page 25
Abhisol : RED-HAT LINUX 6/7
Verify whether the logical volume is removed or not by # lvs or # lvdisplay command.
Example : # umount <file system mount point>
# vim /etc/fstab (delete the entry of the logical volume)
Esc+:+wq! (save and exit the file)
# lvremove </dev/vgname/lvname>
# lvs or # lvdisplay (to verify whether logical volume is removed or
not)
12. How to delete or remove the volume group?
To delete or remove the volume group, first make sure that any logical volume should not be mounted
because while removing a volume group it will delete or remove the logical volumes in that volume group.
Then delete or remove the volume group by # vgremove <vgname>command.
Verify whether the volume group is remove or not by # vgs or # vgdisplay command.
Example : # umount <file system mount point> (to unmount the file system if
there is any LV)
# vim /etc/fstab (delete the entry of the logical volume)
Esc+:+wq! (save and exit the file)
# vgremove <vgname>
# vgs or # vgdisplay (to verify whether volume
group is removed or not)
13. How to delete or remove the physical volume?
Deleting or removing a physical volume is very simple and the only thing we should check that the physical
volume we are going to delete should not belong to any volume group ie., we can only delete or remove the
physical volume which is free.
Then delete or remove the physical volume by # pvremove <pvname>command.
Verify whether the physical volume is removed or not by # pvs or #pvdisplay command.
Example : # pvremove <pvname>
# pvs or #pvdisplay (to verify whether the physical volume is
removed or not)
14. How to restore the volume group which is removed mistakenly?
First unmount file system by # umount <file system mount point> command.
Check the volume group backup list by # vgcfgrestore --list <volume group name>command.
Then remove the logical volume by # lvremove </dev/vgname/lvname> command.
Copy the backup file which is taken backup before removed the volume group from the above backup list and
paste it in this command # vgcfgrestore -f <paste the above copied file name><vgname>
The logical volume is created automatically after restoring the volume group but the volume group and logical
volumes both will be in inactive state. So, check the state of the volume group by #vgscanand the logical
volume state by # lvscan commands.
Then activate that volume group by # vgchange -ay <volume group name>commandand activate the logical
volume by # lvchange -ay <logical volume name>command.
Mount the logical volume file system by # mount -a command.
Example : # umount <file system mount point>
# vgcfgrestore --list <volume group name> (copy the backup file from the
list)
# lvremove </dev/vgname/lvname>
# vgcfgrestore -f <paste the above copied file><volume group name>
# vgscan (to check the status of the
volume group)
# lvscan (to check the status of the
logical volume)
# vgchange -ay <volume group name> (activate the volume group if it is in
inactive state)
# lvchange -ay <logical volume name> (activate the logical volume if it is in
inactive state)
Note: The option a means active VG or LV and option y means yes.
# mount -a
Ratnakar Page 26
Abhisol : RED-HAT LINUX 6/7
15. How to change the volume group name and other parameters?
# vgrename <existing volume group name><new volume group name> (to rename the volume
group)
By default, unlimited logical volumes can be created per volume group. But we can control this limit
by
# vgchange -l <no.><volume group> (to limit max. no. of logical volumes to the specified
number)
Example : # vgchange -l 2 <vgname> (to limit max. 2 logical volumes cab be created in this
volume group)
# vgchange -p <no.><volume group> (to limit max. no. of physical volumes to the specified
number)
Example : # vgchange -p 2 <vgname> (to limit max. 2 physical volumes can be added to this
volume group)
# vgchange -s <block size in no.><volume group> (to change the block size of the volume
group)
Example : # vgchange -s 4 <vgname> (to change the volume group block size to 4MB)
16. How to change the logical volume name and other parameters?
# lvrename <existing lvname><new lvname> (to rename the logical volume)
# lvchange -pr <logical volume> (to put the logical volume into read only mode)
# lvs (to see the logical volume permissions)
# lvchange -prw <logical volume> (to put the logical volume into read and write mode)
20. What are the locations of the logical volume and volume groups?
# cd /etc/lvm/backup (the logical volumes backup location)
# cd /etc/lvm/archive (the volume groups backup location)
23. How to extend the logical volume to max. disk space and half of the disk space?
# lvextend -l +100% FREE <logical volume> (to extend the logical volume by adding the
volume group's total available space)
# lvextend -l 50% <vgname><lvname> (to extend the logical volume by adding the 50%
free space of the volume group)
24. How to check on which physical volume the data is writing in the logical volume?
# lvdisplay -m ( to check on which physical volume the data is currently writing from all
logical volumes)
# lvdisplay -m <lvname> (to check on which physical volume the data is writing from the
Specified logical volume)
Ratnakar Page 27
Abhisol : RED-HAT LINUX 6/7
26. How to scan and detect the luns over the network?
# ls /sys/class/fc_host (to check the available fibre channels)
# echo "---" > /sys/class/scsi_host/<lun no.>/scan (to scan and detect the luns over the network)
29. How to mount the " .iso " image files in Linux?
# mount -t iso9660 /root/rhel6.iso /iso -o ro, loop (to mount the .iso image files)
# cdrecord /root/Desktop/rhel6.iso (to write the CD/DVD ROM. Before executing this
command put the empty CD/DVD into CD/DVD drive)
# eject (to eject the CD/DVD drive tray)
# eject -t (to insert and close the CD/DVD drive tray)
30. What is RAID? What is the use of the RAID and how many types of RAIDs available?
RAID stands for Redundant Array of Independent Disks.
It provides fault tolerance, load balancing using stripping, mirroring and parity concepts.
There are mainly two types of RAIDs available.
(i) Hardware RAID (Depends on vendors and also more expensive)
(ii) Software RAID (Does not depends on vendors and less expensive when compared to Hardware
RAID and also it is maintained by system administrator only.
31. How many types of software RAIDs available and their requirements?
(i) RAID - 0 ---- Stripping ---- Minimum 2 disks required
(ii) RAID - 1 ---- Mirroring ---- Minimum 2 disks required
(iii) RAID - (1+0) --- Mirroring + Stripping ---- Minimum 4 disks required
(iv) RAID - (0+1) --- Stripping + Mirroring ---- Minimum 4 disks required
(v) RAID - 5 ---- Stripping with parity ---- Minimum 3 disks required
Ratnakar Page 28
Abhisol : RED-HAT LINUX 6/7
1 2
3 4
5 Disk - 1
6
Disk - 2
If the Disk - 1 is /dev/sdb and the Disk - 2 is /dev/sdc then,
# mdadm -Cv /dev/md0 -n 2 /dev/sdb /dev/sdc -l 0 (to
create the RAID - 0 using disk - 1 and disk - 2)
# cat /proc/mdstat (to check the RAID - 0 is created or not)
# mkfs.ext4 /dev/md0 (to create the ext4 file system on the RAID - 0)
# mkdir /mnt/raid0 (to create the RAID - 0 mount point)
# mount /dev/md0 /mnt/raid0 (to mount RAID - 0 on the mount point)
# mdadm -D /dev/md0 (to see the details of the RAID - 0 partition)
# mdadm /dev/md0 -f /dev/sdb (to failed the disk manually)
# mdadm /dev/md0 -r /dev/sdb (to remove the above failed disk)
# mdadm /dev/md0 -a /dev/sdd (to add the new disk in place of failed disk)
# umount /mnt/raid0 (to unmount the raid file system)
# mdadm --stop /dev/md0 (to stop the RAID - 0 volume)
# mdadm /dev/md0 --add /dev/sde (to add third disk to the RAID - 0 volume)
# mdadm --grow /dev/md0 --raid_device=3 (to grow the RAID - 0 file system)
1 1
2 2
3 3
4 4
5 5 Disk - 1 Disk - 2
If the Disk - 1 is 6 6 /dev/sdb and the Disk - 2 is /dev/sdc then,
# mdadm -Cv /dev/md0 -n 2 /dev/sdb /dev/sdc -l 1 (to create
the RAID - 1 using disk - 1 and disk - 2)
# cat /proc/mdstat (to check the RAID - 1 is created or not)
# mkfs.ext4 /dev/md0 (to create the ext4 file system on the RAID - 1)
# mkdir /mnt/raid1 (to create the RAID - 1 mount point)
# mount /dev/md0 /mnt/raid1 (to mount RAID - 1 on the mount point)
# mdadm -D /dev/md0 (to see the details of the RAID - 1 partition)
# mdadm /dev/md0 -f /dev/sdb (to failed the disk manually)
# mdadm /dev/md0 -r /dev/sdb (to remove the above failed disk)
# mdadm /dev/md0 -a /dev/sdd (to add the new disk in place of failed disk)
# umount /mnt/raid1 (to unmount the raid file system)
# mdadm --stop /dev/md0 (to stop the RAID - 1 volume)
# mdadm /dev/md0 --add /dev/sde (to add third disk to the RAID - 1 volume)
# mdadm --grow /dev/md0 --raid_device=3 (to grow the RAID - 1 file system)
Ratnakar Page 29
Abhisol : RED-HAT LINUX 6/7
2 1+2
1
3 4
3+4 Disk - 1
5+6 5
Disk - 2 6 Disk - 3
If the Disk - 1 is /dev/sdb, the Disk - 2 is /dev/sdc
and Disk - 3 is /dev/sddthen,
# mdadm -Cv /dev/md0 -n 2 /dev/sdb /dev/sdc -l 5 (to create the RAID - 5 using disks - 1, 2
and 3)
# cat /proc/mdstat (to check the RAID - 5 is created or not)
# mkfs.ext4 /dev/md0 (to create the ext4 file system on the RAID - 5)
# mkdir /mnt/raid5 (to create the RAID - 5 mount point)
# mount /dev/md0 /mnt/raid5 (to mount RAID - 5 on the mount point)
# mdadm -D /dev/md0 (to see the details of the RAID - 5 partition)
# mdadm /dev/md0 -f /dev/sdb (to failed the disk manually)
# mdadm /dev/md0 -r /dev/sdb (to remove the above failed disk)
# mdadm /dev/md0 -a /dev/sde (to add the new disk in place of failed disk)
# umount /mnt/raid5 (to unmount the raid file system)
# mdadm --stop /dev/md0 (to stop the RAID - 5 volume)
# mdadm /dev/md0 --add /dev/sdf (to add fourth disk to the RAID - 5 volume)
# mdadm --grow /dev/md0 --raid_device=4 (to grow the RAID - 5 file system)
36. How will you troubleshoot if one of the eight disks failed in LVM?
First umount the file system and add the new disk with same size of the failed disk to the volume
group. Then move the data from failed physical volume to newly added physical volume and then
remove the failed physical volume from the volume group. And finally mount the file system.
38. How to inform the client and then troubleshoot if the disk is full?
First check which files are accessing more disk space by #du -h |sort - r command. if any temporary
and junk files are present remove them from the disk to make a room for new or updated data. Then
inform the actual situation to the client, take the permission from the client to get the lun
from storage and extend the file system by adding that lun to the LVM.
Ratnakar Page 30
Abhisol : RED-HAT LINUX 6/7
storage hardware from Emc square, Netapp and others. And I am dreaming to work on storage,
cloud and virtualization.
40. I have four disks each 1TB in RAID - (1+0). So, total how much disk space can I utilize in that RAID –
(1+0)? RAID - (1+0) means Mirroring + Stripping. It requires 4 disks, ie., 2 disks for mirroring and
remaining 2 disks for stripping. And 5 - 10% disk space is used for superblock information. So,
finally we can utilize 2TB - 2TB X 10% disk space in that RAID - (1+0).
41. If two disks failed in RAID - (1+0), can we recover the data?
The RAID - (1+0) requires minimum 4 disks and it uses Mirroring + Stripping. If one disk is failed we
can
recover the data, but if two disks are failed we cannot recover the data.
42. How many types of disk space issues can we normally get?
(i) Disk is full.
(ii) Disk is failing or failed.
(iii) File system corrupted or crashed.
(iv) O/S is not recognizing the remote luns when scanning, ...etc.,
Ratnakar Page 31
Abhisol : RED-HAT LINUX 6/7
impacts on performance of the servers. So, to overcome this problem we normally use # find
command on production servers.
# updatedb (to update the locate database)
# locate <file name/directory name> (to search the specified file or directory)
Examples :
# find / -name <file name> (to search for file names in / directory)
# find / -name <file name> -type f (to find file names only)
# find / -name <directory name> -type d (to find directories with small letters only)
# find / -iname <file/directory name> -t d (to search for small or capital letter
files/directories)
#find / -empty (to search empty files or directories)
# find / -empty -type f (to search for empty files only)
# find / -empty -type d (to search for empty directories only)
# find / -name " *.mp3" (to search for .mp3 files only)
# find / -size 10M (to search for exact 10M size file/directories)
# find / -size -10M (to search for less than 10M size files/directories)
# find / -size +10M (to search for greater than 10M size files/directories)
# find / -user student (to search for student user files/directories)
# find / -group student (to search for student group files/directories)
# find / -user student -not -group student (to search for student user files and not student
group files)
# find / -user student -o -group student (to search for student user and student group
files/directories)
# find / -uid <uid no.> (to search for files/directories which belongs to the user
having the specified user id)
# find / -gid <gid no.> (to search for files/directories which belongs to the group
having the specified group id)
# find / -prem 755 (to search file/directories which are having the
permissions 755)
# find / -prem -755 (to search file/directories which are having the
permissions below 755 and also at least one match also)
# find / -mmin 20 (to search for files/directories which are modified within 20 minutes,
+20 ----> above 20 minutes and -20 -----> below 20
minutes)
# find / -mtime 2 (to search files/directories which are modified within 2 days)
# find / -name "*.mp3" -exec rm -rf { } \; (to search all .mp3 files and delete them)
Ratnakar Page 32
Abhisol : RED-HAT LINUX 6/7
# find / -name "*.mp3" -exec cp -a { } /ram \ ;(to search all mp3 files and copy them into /ram
directory)
# find / -user student -exec cp -a { } /ram \; (to search student user's files and directories
and copy them into /ram directory)
# find / -nouser -exec mv -a { } /home/ram \; (to search files/directories which are
not
belongs to any user and move them into /home/ram directory)
# du -h / |sort -r |head -n 10 (to search 10 big size files in reverse order)
Ratnakar Page 33
Abhisol : RED-HAT LINUX 6/7
9. What is an IP address?
Every Computer will be assigned an IP address to identify each one to communicate in the network.
The IP address sub components are Classes of an IP address, Subnet masks and Gateway.
Classes of IP address :
The IP addresses are further divided into classes. The classes are A, B, C, D, E and the ranges are
given below.
Class Start End Default Subnet mask Classless Inter Domain Routing
Class A 0.0.0.0 127.255.255.255 255.0.0.0 /8
Class B 128.0.0.0 191.255.255.255 255.255.0.0 /16
Class C 192.0.0.0 223.255.255.255 255.255.255.0 /24
Class D 224.0.0.0 239.255.255.255
Class E 240.0.0.0 255.255.255.255
Ratnakar Page 34
Abhisol : RED-HAT LINUX 6/7
It is two types.
IPV4 :(It is divided into 4 parts )
It is divided into 6 parts. --- . --- . --- . --- (each 8 bits. So, 8 X 4 = 32 bits
--- : --- : --- : --- : --- : --- (each 8 bits. So, 8 X 6 = 48 bits IPV6 : ( It is divided into 16 parts )
--- . --- . --- . --- . --- . --- . --- . --- . --- . --- . --- . --- . --- . --- .
--- . --- (each 8 bits. So, 8 X 16 = 128 bits.
ifconfig (to see the MAC address) # ifconfig (to see the IP address)
16. How many types of NIC cards available?
(a) eth0 (1st NIC card)
(b) eth1 (2nd NIC card)
(c) br0 (Bridge -----> used for communication from physical to virtual)
(d) lo (loopback device name and IP address is 127.0.0.1)
# ifconfig (to see all the NIC devices connected to the system)
17. How many types of cable connections available?
(i) Cross cable (to connect two systems directly)
(ii) Straight cable (to connect more systems with the help of switch)
# ethtool <device name> (to check the network cable is connected or not)
# miitool <device name> (It is also used to check the network cable but it will not
supports RHEL - 7 and only supports RHEL - 6 and it also works on physical system
only not on virtual system)
18. In how many ways we can configure the network?
There are two ways to configure the network.
(a) Static Network.
(b) Dynamic Network.
Static Network :
In this way we assign the IP address and hostname manually. Once we configure the IP address, it will
not change.
Dynamic Network :
In this way we assign the IP address and hostname dynamically. This means the IP address will change
at every boot.
19. How to assign the static IP address to the NIC card?
In RHEL - 6 :
# setup
(Move the cursor to Network configuration and press Enter key)
(Move the cursor to Device configuration and press Enter key)
(Select the NIC adapter ie., eth0 and press Enter key)
(Assign the above IP address and other details as per our requirements and move the cursor to "OK"
and press
Enter key)
(Move the cursor to "Save" to save the changes in device configuration and press Enter key)
(Once again move the cursor to "Save & Quit" button and press Enter key)
(Finally move the cursor to "Quit" button and press Enter key to quit the utility)
(Then restart the network service and check for the IP address by # service network restart
command)
(If the change is not reflected with the above service, then restart the network manager by
# service NetworkManager
restart command)
# ifconfig (to see the IP address of the NIC card)
# ping < IP address > (to check whether the IP is pinging or not)
In RHEL - 7 :
Ratnakar Page 35
Abhisol : RED-HAT LINUX 6/7
21. What are the differences between Dynamic and Static configuration information?
Dynamic configuration information Static configuration information
Device =<NIC device name> Device =<NIC device name>
HWADDR=02:8a:a6:30:45 HWADDR=02:8a:a6:30:45
Bootproto=DHCP Bootproto=none (means static network)
Onboot=yes (yes means whenever we restart the system
this connection will be activated and no means whenever Onboot=yes
we restart the system the connection will be deactivated)
Type=Ethernet Type=Ethernet
Userctl=yes/no ----> If it is yes all normal users can disable Userctl=yes/no ----> If it is yes all normal users can disable
the NIC card and If it is no except root user nobody can the NIC card and If it is no except root user nobody can
disable the NIC card. disable the NIC card.
RHEL - 7 :
# hostname <fully qualified domain name> (to set the hostname
temporarily)
# hostnamectl set-hostname <fully qualified domain name> (to set the hostname
permanently)
# systemctl restart network (to update the hostname in
the network)
Ratnakar Page 36
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 37
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 38
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 39
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 40
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 41
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 42
Abhisol : RED-HAT LINUX 6/7
Note : By default this command will not available. So, first install the nmap package by # you install
nmap -y
# nmap <remote system IP address> (to see all the services which are running in the specified
remote system)
# nmap <remote IP 1><remote IP 2><remote IP 3> (to see the running services on specified remote
systems)
# nmap 172.25.0.11 - 50 (to see the running service on 172.25.0.11 to
172.25.0.50 systems)
# nmap -p 80 <remote IP> (to see the http port is running or not on specified remote system)
# nmap -p 80 - 90 <remote IP> (to see port no's 80 to 90 are running or not on remote systems)
# nmap -sp 172.25.0.0/24 (to see all the systems which are in upstate ie., 172.25.0.1,
172.25.0.2,
(where s -- scan & p -- ping) 172.25.0.3, ......upto 172.25.0.254
systems)
Open a file, write all the systems IP addresses, save & exit the file. Example has given below,
# vim coss
172.25.2.50
172.25.3.50
172.25.4.50 ....etc., (save and exit this file)
# nmap -iL coss (to scan all the IP addresses by reading the coss file)(where -i ---->
input, -L ----> list)
# nmap --iflist (to see all the routing table information in the network)
# nmap 172.25.0.10 - 20 --exclude 172.25.0.15 (to scan all the systems from 172.25.0.10 to
172.25.0.20 systems and excluding
172.25.0.15 system)
# nmcli connection show --active (to control the network connections)
# ip link (to check the network connection)
# ping -I eth1 <IP address> (to check the 2nd NIC card connection)
Ratnakar Page 43
Abhisol : RED-HAT LINUX 6/7
5. Managing SELinux
1. What is SELinux?
It is a one type of security that enhances the security that allows users and administrators more
control over which users and applications can access which resources, such as files, Standard Linux access
controls etc.,
It is mainly used to protect internal data (not from external data) from system services. In real time
SELinux is disabled and instead of this IP tables are used. It protects all the services, files and directories by
default if SELinux is enabled.
2. In how many ways we can implement the SELinux? Explain them.
We can implement the SELinux mainly in 2 modes.
(i) Enabled
(ii) Disabled (default mode)
Enabled :
Enabled means enabling the SELinux policy and this mode of SELinux is divided into two parts.
(a) Enforcing
(b) Permissive
Disabled :
Disabled means disabling the SELinux policy.
3. What is Enforcing mode in SELinux?
Enforcing means SELinux is on. It checks SELinux policy and stored a log. No can access the services by
default but we can change the policy whenever we needed.
4. What is Permissive mode in SELinux?
SELinux is on and it don't check SELinux policy and stored the log. Everybody can access the services
by default and we can also change the SELinux policy. It is also called as debugging mode or troubleshooting
mode. In this mode SELinux policies and rules are applied to subjects and objects but actions are not affected.
5. What is Disabled mode in SELinux?
SELinux is turned off and no warning and log messages will be generated and stored.
6. What are Booleans?
Booleans are variables that can either be set as true or false. Booleans enhance the effect of SELinux
policies implemented by the System Administrators. A policy may protects certain deamons or services by
applying various access control rules.
7. What is SELinux policy?
The SELinux policy is the set of rules that guide the SELinux security engine. It defines types for file
objects and domains for process. It uses roles to limit the domains that can be entered and the user identities
to specify the role that can be attained.
8. What are the required files for SELinux?
# vim /etc/selinux/config -----> It is main file for SELinux.
# vim /etc/sysconfig/selinux -----> It is a link file to the above file.
# vim /var/log/audit/audit.log -----> SELinux log messages will be stored in this file.
9. what is the command to see the SELinux mode?
# getenforce (to check the SELinux mode)
10. What is command to set the SELinux mode temporarily?
# setenforce 0 or 1 (to set the SELinux mode. Where ' 0 ' -----> permissive and ' 1 ' ----->
Enforcing)
Ratnakar Page 44
Abhisol : RED-HAT LINUX 6/7
Note : (i) To change the SELinux mode from Permissive to Enforcing or Enforcing to Permissive
modes the system restart is not required.
(ii) To change Enforcing mode to Disabled mode or Disabled mode to Enforcing mode
the system restart is required.
(iii) The above commands are changed the SELinux mode temporarily only. To make the
selinux changes permanently then open /etc/selinux/config and go to ,
SELINUX=Enforcing or Permissive or Disabled (save and
exit this file)
11. What is command to see the SELinux policy details?
# sestatus (to see the SELinux policy details)
Other useful commands :
# ls -Z <file name> (to see the SELinux context of the file)
# ls -ldZ <directory name> (to see the SELinux context of the directory)
# ps -efZ | grep <process name> (to see the SELinux context of the process running on the system)
# ps -efZ | grep http (to see the SELinux context of the http process running on the
system)
# chcon -t <argument> <file/directory name> (to change SELinux context of the file or
directory)
# chcon -t public_content_t /public (to change the SELinux context of the /public
directory)
# chcon -R public_content_t /public (to change the SELinux context of the /public
directory and
its contents)
# restorecon -v <file/directory name> (to restore the previous SELinux context of the
file/directory)
# restorecon -v /public (to restore the previous SELinux context of that
directory)
# restorecon -Rv <directory> (to restore the previous SELinux context of the
directory and
its contents)
# restorecon -Rv /public (to restore the previous SELinux context
of the /public
directory and its contents)
# getsebool -a | grep <service name> (to see the booleans of the specified service)
# getsebool -a | grep ftp (to see the booleans of the ftp service)
# setsebool <boolean><option on/off> (to change the boolean of a specified service)
# setsebool allow_ftpd_anon_write on (to change the boolean of the ftpd service
temporarily)
# setsebool -P <service name> = <0/1> (to change the boolean for the service on or off
permanently)
# setsebool -P samba_export_all_rw = 1 (to change the boolean for samba service
permanently on)
Ratnakar Page 45
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 46
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 47
Abhisol : RED-HAT LINUX 6/7
# reboot command will not send the kill signals to the system and it will kill all the running processes
and services forcefully and then restart the system.
# init 6 command will send the kill signals to the system and it will stop all the processes and
services one by one and then restart the system.
8. What is console port and how to connect to the console port?
Console port is used to connect the system even though the system is not booted with the main O/S.
This port is used to connect the system for troubleshooting purpose only. We can connect the console
port as same as connect to systems LAN port and it is also having IP address, user name and password to
connect to the console.
There are different types of console ports for different types of servers. They are given below.
Server Name Name of the Console port Expansion name
DRAC ---> DELL Remote Access Controllers
DELL DRAC or i-DRAC i-DRAC ---> Integrated DELL Remote Access
Controllers
IBM Power series HMC Hardware Management Console
HP ILO Integrated Light Out
Ratnakar Page 48
Abhisol : RED-HAT LINUX 6/7
We can login to the system remotely in single user mode also but it is possible to connect to console
instead of LAN port through putty tool by giving IP address, user name and password. Then console
port appears and boot the system with CDROM in single user mode.
14. How to check the present kernel version?
# uname -r (it displays the present kernel version)
# uname -a (it displays the present kernel version with other details)
# cat /boot/grub/grub.conf (in this file also we can find the kernel version)
15. What is the command to see the system architecture?
# arch or # uname -m (both commands gives the architecture of the system)
16. How to check the version of the O/S ?
# cat /etc/redhat-release (gives the version of the O/S)
17. How to repair the corrupted boot loader and recover it?
This problems may be occur if the GRUB is corrupted. So, we have to recover the GRUB. Basically the
repairing of GRUB means installing the new grub on the existing one from RHEL - 6 DVD. The steps are
given below.
(i) Insert the RHEL - 6 DVD and make sure that system should boot from CD/DVD.
(ii) Boot the system in Rescue Installed System mode.
(iii) Select the language with which we want to continue and click on OK.
(iv) Select the Keyboard type as US and click OK.
(v) Select Local CD/DVD and click OK.
(vi) Move the cursor to NO to ignore the Networking.
(vii) Move the cursor to Continue tab to mount the root ( / ) from CD/DVD and press Enter key.
(viii) Now the root ( / ) file system is mounted on /mnt/sysimage, here click on OK and Press Enter to
continue.
(ix) Select the "shell Start shell" option and click on OK, then shell will be displayed on screen.
(xi) At shell prompt type as # chroot /mnt/sysimage command, press Enter.
(xii) Check the /boot partition by # fdisk -l command.
(xiii) Install the new grub on the boot device ie., may be /dev/sda2 by # grub-install <device
name> command (For example #
grub-install /dev/sda2).
(xiv) If it show no error reported that means we have successfully recovered the grub.
(xv) Then type # exit command and again type # exit or # reboot command to reboot the
system.
18. What are Modules or Kernel Modules? How to find the Kernel Modules?
The drivers is Linux system are known as Modules or Kernel Modules. These modules are assigned by
kernel depending on the hardware. Hardware can only be communicated and can work efficiently when the
proper module is loaded in the kernel. we can find the kernel modules by # ls /etc/lib/modules command.
All the kernel modules in the system will be ended with " .ko " extension. So, we can see all the
modules in the system by # find / -name *.ko command.
19. What other commands related to kernel modules?
# lsmod (to list all the currently loaded modules)
# lsmod |grep -i <module name> (to check whether the particular module is
loaded or not)
# lsmod |grep -i fat (to check the fat module is loaded or not)
There might be a situation where our module is not working properly, in that case we have to remove
that module and re-install it again by,
# modprobe -r <module name> (to remove the specified module)
# modprobe -r fat (to remove the fat module)
# modprobe <module name> (to install or re-install the module)
# modprobe fat (to install or re-install the module)
# modinfo <module name> (to see the specified module information)
# uname (to see the which O/S is present in the system)
# uname -s (to see which O/S kernel is this either Linux or
Unix)
# rpm -qa kernel --last (to see the kernel installation date and time)
# rpm -qa kernel* (to see how many kernels are there in the
system)
Ratnakar Page 49
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 50
Abhisol : RED-HAT LINUX 6/7
7. Job Automation
1. What is Job scheduling?
The process of creating the jobs and make them occur on the system repeatedly hourly, daily, weekly,
monthly and yearly is called Job scheduling. In Linux and other Unix systems this process is handled by
the cron service or deamon called crondand atd is the at jobs deamon which can be used to schedule the
tasks (also called as jobs).
2. What is the importance of the job scheduling?
The importance of the job scheduling is that the critical tasks like backups, which the client usually
wants to be taken in nights, can easily performed without the intervention of the administrator by
scheduling a cron job. If the cron job is scheduled carefully then the backup will be taken at any given time
of the client and there will be no need for the administrator to remain back at nights to take the backup.
3. What are the differences between cron and at jobs?
cron job :
(i) cron jobs are scheduling jobs automatically at a particular time, day of the week, week of
the month and month of the year.
(ii) The job may be a file or file system.
(iii) We cannot get the information as a log file if the job was failed to execute ie., when it was
failed and where is was failed and also cannot execute automatically the failed jobs.
at job :
(i) at jobs are executes only once.
(ii) Here also we cannot get the information if the job is failed and it is also do not execute the
failed jobs automatically.
4. What are the important files related to cron and at jobs?
/etc/crontab -----> is the file which stores all the scheduled jobs.
/etc/cron.deny -----> is the file used to restrict the users from using cron jobs.
/etc/cron.allow -----> is used to allow only users whose names are mentioned in this file to use cron jobs
and this file does not exist by
default.
/etc/at.deny ----->same as cron.deny for restricting the users to use at jobs.
/etc/at.allow -----> same as cron.allow for allowing users to use at jobs.
5. What is the format of the cron job?
# crontab -e (to edit the cron job editor to create or remove the cron
jobs)
<minutes><hours><day of the month><month of the year><day of the week><job or script>
(0 - 59) (0 - 23) (1 - 31) (1 - 12 or jan, feb, ...) (0 - 6 or sun, mon, ...)
Options Explanation
* Is treated as a wild card. Meaning any possible value.
Is treated as ever 5 minutes, hours, days or months. Replacing he 5 with any numerical value will
*/ 5
change this option.
2, 4, 6 Treated as an OR, so if placed in the hours, this could mean at 2, 4 or 6 o-clock
Treats for any value between 9 and 17. So if placed in day of the month this would be days 9 through
9-17
17 or if put in hours, it would be between 9 AM and 5 PM.
Ratnakar Page 51
Abhisol : RED-HAT LINUX 6/7
(ii) Put the entries of the user names whom do we (ii) Put the entries of the user names whom do we
want to allow the cron jobs. want to deny the cron jobs.
Ratnakar Page 52
Abhisol : RED-HAT LINUX 6/7
(ii) Put the entries of the user names whom do we (ii) Put the entries of the user names whom do we
want to allow the at jobs. want to deny the at jobs.
Ratnakar Page 53
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 54
Abhisol : RED-HAT LINUX 6/7
* If the system is scheduled for a job, but at that time the system is under down then anacron
command is
responsible for those pending jobs to be executed.
# cat /etc/anacron is the configuration file for anacron jobs.
# anacron (anacron is used to execute the pending cron jobs)
# vim /etc/rc.local (to execute the cron pending jobs automatically whenever the
system is rebooted)
* Open the above file and go to last line and type as, anacron then save and exit this file to execute
the pending jobs automatically whenever the system is rebooted.
Ratnakar Page 55
Abhisol : RED-HAT LINUX 6/7
It is used to connect to remote system and perform administrative task or jobs. By default ssh takes
password authentication mechanism and its port no. is 22. Through ssh the data will be transferred in
encrypted format.
3. What is telnet?
Telnet is a mechanism to connect and to administrate the remote system from local system. This is
the oldest program which is available on most network capable operating systems. Accessing a remote shell
account through the telnet method is danger because in that everything that you send or receive over that
telnet session is visible in plain text on your local network and the local network of the machine you are
connecting to.
So, anyone can sniff the connection in-between can see our user name, password, email and other
messages that we read and command that we run. For these reasons we need a more sophisticated program
than telnet to connect to a remote host.
4. What are the differences between Telnet and SSH?
Telnet SSH
(a) Through telnet we can connect the remote (a) Through ssh also we can connect the remote
system, but any network hacker may see the system, but nobody can see the transferred data.
transferred data. And the telnet port no. is 23. And the ssh port no. is 22.
(b) Data will be transferred in non-encrypted format. (b) Data will be transferred in encrypted format.
(c) We cannot trust this telnet connection. (c) We can trust this ssh connection.
(d) We cannot give the trusting in telnet. (d) We can give the trusting in ssh.
(e) By snooping or sniffing technologies we can see (e) By snooping or sniffing technologies we cannot
the data like system or hostname, login name, see the data like system name or hostname, login
password and other data. name, password and other data.
So, there is no security. So, there is a security
(f) # telnet<IP address of the remote system> (f) # ssh<IP address of the remote system>
(provide login name and password) (provide login name and password)
5. In how many ways we can connect the remote host through ssh?
Through ssh we can connect the remote host by two methods.
(i) Command Line Interface (CLI).
Example : # ssh <IP address of the remote system> (provide login name and password)
(ii) Graphical User Interface (GUI).
Example : open VNS server window and provide remote hostname, login name and
password.
6. What are the requirements for ssh?
(i) Remote systems IP address.
(ii) Remote systems user name and password
(iii) A proper network ie., our local and remote systems should be in the same network.
(iv) Open ssh package to configure the ssh.
7. In how many ways we can connect the remote system?
(i) telnet (ii) ssh
(iii) rlogin (iv) rcp
(v) ftp (vi) scp
(vii) sftp (viii) tftp
8. What is the syntax for ssh?
# ssh <IP address of the remote system> -l <user name>
# ssh <user name>@<IP address of the remote system>
# ssh <user name>@<remote hostname with fully qualified domain name>
* After executing any of the above commands, it may asks user name and password. Then type user
name and
Ratnakar Page 56
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 57
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 58
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 59
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 60
Abhisol : RED-HAT LINUX 6/7
(v) Check all the files whether the telnet service is blocked or not, if blocked remove those
entries.
23. How will you login or start the system in what mode if you don't know the root password?
(i) If the user having sudo permissions, then login as sudo user.
(ii) If no sudo permissions then boot with CDROM in single user mode and start the system.
Then provide the root password to root user if there is no root password.
(iii) Even though if it is not possible then finally break the root password.
Other useful commands :
# telnet <IP address or hostname> (to connect the specified remote system through
telnet)
# ssh <IP address or hostname> (to connect the specified remote system through
ssh)
Username : xxxxxx
Password : xxxxxxx
# ssh <IP address> -l <user name> (to connect the remote system using user name)
Password : xxxxxxx
# ssh 192.168.1.1 -l root (to connect this remote system as root
user)
# ssh root@192.168.1.1 (to connect this remote system as root user)
# ssh root@server1.example.com (to connect the server1 system in example.com
domain)
#w (to see all the users who are login to our system)
# w -f (to see all the users who are login to our system with
other details)
# ssh <IP address> (if we not specified the user name, then it will ask the current users
password and search the current
account in remote system)
# cat /root/.ssh/known_hosts (to see the ssh trusting remote hosts finger print
information)
# ssh root@192.168.1.1 <command> (to run a command on remote host without login to that
system)
# ssh root@192.168.1.1 -X (to run GUI commands on the remote system because by default
the ssh is configured as command line
interface, X is capital)
# lastb (to see the login failed tries)
# last -x |grep shutdown (to see the date & time of the system's last
shutdown)
9. Memory Management (Swap)
1. What is swap?
Swap space in Linux is used when the amount of the Physical memory (RAM) is full. If the system
needs more memory resources and the RAM is full, inactive pages in the memory are moved from RAM to
swap space. It helps the machines which are having small amount RAM and it should not be considered a
replacement for more RAM. Swap is located on the hard disks which have slower access time than Physical
memory.
2. What is the recommended swap space?
Generally the recommended swap space is double the RAM size, but the following table shows actual
amount.
Apart from the below recommendation a basic rule is applied to create the swap partition.
* If the RAM size is less than or equal to 2 GB, then the size of the swap = 2 X RAM size.
* If the RAM size is more than 2 GB, then the size of the swap = 2 GB + RAM size.
Amount of RAM in the System Recommended Amount of Swap Space
4 GB or less Min. 2 GB
4 GB - 16 GB Min. 4 GB
16 GB - 64 GB Min. 8 GB
Ratnakar Page 61
Abhisol : RED-HAT LINUX 6/7
64 GB - 256 GB Min. 16 GB
Ratnakar Page 62
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 63
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 64
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 65
Abhisol : RED-HAT LINUX 6/7
* Update will look first the package is available in that system or not. If it is available, it will update
that package otherwise it will install as fresh package.
# rpm -qRp <package name> (to check the dependency packages of that package
before install)
# rpm -ivh <package name> --nodeps (to install the package without dependent
packages)
8. What is yum and explain the yum?
yum stands for yellow dog updater modified. yum is a package management application for
computers running on Linux O/S.yum is a standard method of managing the installation and removal of
software. It is from RHEL - 5 onwards. Packages are downloaded from collections called repositories, which
may be online, on a network and or on installation media. yum is a front end tool for rpm. It is used to resolve
the dependency which cannot be done by rpm. The yum command has access the repository where the
packages are available and can install, update/upgrade, remove and query the packages automatically.
9. What are the important files that are related to yum?
/etc/yum.conf -----> is the yum configuration file.
/etc/yum.repos.d -----> is the directory which contains the yum repository configuration file.
/etc/yum.repos.d/xxxxx.repo ------> is the yum repository configuration file.
/var/lib/yum -----> is the directory which contains the yum databases.
/var/log/yum.log -----> is the file which stores the yum log messages.
10. How setup the yum server?
(i) Insert the RHEL DVD, goto that directory and install the vsftpd package by # rpm -ivh
vsftpd*
(ii) Goto /var/ftp/pub directory and create rhel6 directory by # mkdir rhel6
(iii) Goto DVD mounted directory and copy all the DVD content into /var/ftp/pub/rhel
directory by
# cp -rvpf /media/DVD/ /var/ftp/pub/rhel6
(iv) Restart the vsftpd service by # service vsftpd restart command.
(v) Then enable the vsftpd service by # chkconfig vsftpd on command.
(vi) Goto /etc/yum.repos.d directory and create one yum repository file by # vim linux.repo
command.
(vii) In the above file the contents are as below,
[linux] (Linux repo id)
name=yum repo server (yum server name)
baseurl=file:///var/ftp/pub/rhel6 or baseurl=ftp://<IP address of the
system>/pub/rhel6
gpgcheck=0 (0 means while installing it will not ask
any signature keys of yum packages, If it is 1, then it will ask the signature keys
while installing the packages)
enabled=1 (if multiple repositories are there, then
enable this only)
(save and exit this file)
(viii) # yum clean all (to clean the old one update the new repository)
(ix) # yum repolist (it displays no. of packages in that
repository)
11. How to setup the yum client?
(i) Goto /etc/yum.repos.d directory and create the repository file by # vim linux.repo
(ii) Type the entries as below,
[linux] (Linux repo id)
name=yum repo client (yum repo client)
baseurl=ftp or http://<IP address of the server>/pub/rhel6
gpgcheck=0 (0 means while installing it will not ask
any signature keys of yum packages, If it is 1, then it will ask the signature keys
while installing the packages)
enabled=1 (if multiple repositories are there, then enable this only)
(save and exit)
(iii) # yum clean all (to clean the old one update the new repository)
Ratnakar Page 66
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 67
Abhisol : RED-HAT LINUX 6/7
(xiv) After the test period, if there is no problems raised then attach the system in live mode and also
with mirror disk to sync the data to update the system.
(xv) Then we inform the Application, Database, Monitoring and other teams who are dealing with
that server to test application, database, monitoring and others see the status.
(xvi) Then finally close the issue or CRQ.
17. After installation of package or patch if the package or patch is removed then what will happened?
(i) If kernel patch is removed, then the system will hang and for others there is no effect.
(ii) If package is removed then the application that belongs to that removed package will effect.
18. After applying the patch need to reboot the system or not?
(i) If the patch is kernel patch or clustered patch then only the system reboot is required.
(ii) If the patch is normal patch then there is no need of the reboot required.
19. If the package is not installing. How to troubleshoot?
(i) Check the package pre-requisites to install the package.
(ii) If pre-requisites are not matched with our system, then the package will not be installed i.e.,
O/S compatibility to install that package.
(iii) If there is no sufficient space in the system, the package will not be installed.
(iv) If the package is not properly downloaded, then the package will not be installed.
20. If the patch is not applied successfully what will you do?
(i) Check whether the patch is installed properly or not by # rpm -qa <patch name>
command.
(ii) Check the /var/log/yum.log file to verify or see why the patch is not successfully installed.
(iii) If any possible to resolved those issues, resolve and remove that patch with # rpm -e
<patch name> command.
(iv) If any reboots required to effect, then reboot the system.
(v) Again add that patch by # rpm -ivh <patch name> command.
(vi) Then check the patch by # rpm -qa <patch name> command
Other useful yum commands :
# yum repoinfo (to list all the information on all the repositories)
# yum repoinfo <repo id> (to list all the information on specified
repository)
# yum install <package name> -y (to download and install the package and y
means yes)
# yum install <package name> -d (to download the package)
# yum erase or remove <package name> -y (to remove or uninstall the package and y
means yes)
# yum list installed (to display the list of all installed
packages)
# yum list available (to list all the available packages to be installed)
# yum list all | less (to list all the installed and not installed
packages)
# yum search <package name> (to search a particular package is available or
not)
# yum info <package name> (to display the information on that package)
# yum update <package name> (if the update version of the specified package is
available, then
update that package)
# yum update all (to update all the packages nothing but whole
system will be updated)
# yum downgrade <package name>(to revert back ie., go back to previous version of that package if
new version is not working
properly)
# yum history (to display the yum history)
# yum history info < id > (to display the information of that history id)
# yum history undo < id > (to remove that history id)
# yum history undo < id > (to redo the above removed history id)
# yum grouplist (to display the list of group packages)
# yum groupinstall <package name> (to install the group package)
Ratnakar Page 68
Abhisol : RED-HAT LINUX 6/7
# yum install@<group package name> (to install the group package in another way)
# yum groupinfo <group package name> (to display the group package information)
# yum grouplist hidden (to list all the group packages names including
installed or not installed and
hidden group packages)
# yum-config-manager disablerepo=<repo id> (to disable the yum repository. So, we cannot
install any package
from the repository)
# yum clean all (to clear the history, if we disable the repository id, then we have to clean the
history, then only it will
disable the repository)
# yumdownloader <package name> (to download the package from the repository,
and the downloaded location is the present
working directory)
# man yum.conf (to see the manual pages on yum configuration
file)
# yum-config-manager --add-repo=http://content.example.com/rhel7.0/x86_64/dvd (then the
yum repository will be created automatically with .repo file also. And this works
only in RHEL - 7)
# subscription-manager register --username=<user name> --password=<password> (to register
our product with RHN--Redhat Network. The user name and passwords will be provided by the Redhat
when we purchase the software)
# subscription-manager unregister --username=<user name> --password=<password> (to
unregister our product with RHN--Redhat Network. The user name and passwords will be provided by the
Redhat when we purchase the software)
Ratnakar Page 69
Abhisol : RED-HAT LINUX 6/7
Windows ntbackup
Linux tar, cpio, dd, dump, restore
3rd party Veritas netbackup, Amanda and Tivoli
4. What is tar and Explain it or how to take a backup using tar?
Archiving means collection of files and directories and to make a single file nothing but compression.
tar means tape archiving. It is an archive file. By using tar command we can take a backup of files and
directories. It cannot support file systems backup and also not support for large files more than 80GB. tar will
not skip any single file including bad blocks also.
Full syntax of tar :
# tar <options><destination file name with path><source file or directory with path>
The options are, -c -----> create
-v -----> verbose
-f -----> file name
-t -----> listing
-tv ----> long listing
-x -----> extract
-w ---->interactive
-C -----> specific location (Capital C)
-u -----> update means adding new contents to the existing tar file
--update -----> " "
--delete -----> deletes the contents from the tar file
-p ----> preserve the old permissions of the files/directories when
extracting the tar file
-z ----> gzip (gun zip) compression
-j ----> bzip2 (bun zip) compression
-J ----> xz compression (from RHEL - 7)
Examples:
# tar -cvf /root/etc.tar /etc/* (to copy all the files and directories from /etc and make
a single file and place in
the /root/etc.tar file)
# tar -tvf /root/etc/tar (to long listing the contents of the /root/etc.tar
file)
# tar -xvf /root/etc.tar -C /root1/ (to extract and copy the files in /root1/
location)
# tar -xf /root/etc.tar (to list the contents of the tar file)
# tar -f /root/etc.tar --update or -u <file name or directory> (to add the new contents to the
existing
tar file)
# tar -f /root/etc.tar --delete <file name or directory> (to delete the file from the tar)
# tar -u /root/etc.tar /var (to add the /var contents into the /root/etc.tar file)
# tar -cvf mytar.tar / --xattrs (to archive the contents along with SELinux and ACL
permissions)
# du -h /root/etc.tar (to see the size of the tar compressed file)
5. What are the compressing & uncompressing tools available for tar and explain them?
Compressing Tools Uncompressing Tools
# gzip (.gz) # gunzip
# bzip2 (.bz2) # bunzip2
# xz (RHEL - 7) # unxz
# gzip <tar file name> (to compress the size of the tar file and the output file is
.tar.gz)
# gunzip < .gz compressed file name> (to uncompress the compressed tar file and the output is
.tar only)
# bzip2 <tar file name> (to compress the size of the tar file and the output is
.tar.bz2)
Ratnakar Page 70
Abhisol : RED-HAT LINUX 6/7
# bunzip2 < .bz2 compressed file name> (to uncompress the compressed file and the output is
.tar only)
6. What is scp, rsyncand how to use it?
scp means secure copy. ie., ssh + cp = scp which is used to copy the files/directories into remote
system.
scp will copy files/directories into remote system blindly ie., if the file already exits, it will over write
that file.
So, scp will take more time to copy when compared to # rsync tool.
# scp <file name><user name>@ <IP address of the remote system>:<location to be copied>
# scp anaconda* root@192.168.1.1:/root (to copy anaconda file into /root of the remote system)
# scp -r /etc/ root@192.168.1.1:/raju (to copy /etc/ directory into /raju of remote
system)
#scp -av /raju root@192.168.1.1:/root (to copy /raju into /root of the remote system)
# scp -r root@192.168.1.1 :/etc /home (to copy /etc of the remote system into /home of the
local
system)
rsync is also used to copy files/directories into remote systems. rsync tool will compare the new files
or directories and copy only the changed or modified contents of the files into remote system. So, it takes less
time to copy when compared to # scp tool.
# rsync -av root@192.168.1.1:/etc /home (to copy /etc directory changed contents into
/home)
rsync options are, -a -----> all (copy the file with all permissions except SELinux and ACL
permissions)
-aA -----> synchronize ACL permissions
-aAx ----> synchronize ACL and SELinux permissions also.
7. What is cpio and how to take a backup and restore using cpio?
cpio means copy input and output. It supports any size of the file system. It skips the bad blocks
also.
Syntax of cpio with full options :
# ls <source file name> |cpio <options>><destination file name> (to take a backup of the source
directory and stored the backup into
destination directory)
The options are, -t -----> to list the cpio contents
-i -----> to restore the cpio backup
-v -----> to display on the screen ie., verbose
-o -----> to take a backup
Examples :
# ls | cpio -ov > /opt/root.cpio (to take a backup of root directory and stored in
/opt )
# cpio -iv < /opt/root.cpio (to restore the backup)
# ls /etc | cpio -ov > /opt/etc.cpio (to take a backup of the /etc directory and
stored in /opt)
# cd /etc (go to that /etc directory)
# rm -rf * (to remove all the contents from /etc)
# cpio -iv < /opt/etc.cpio (to restore the /etc contents from the cpio
backup)
8. What is dd and how to take a backup and restore using dd?
dd means disk to disk backup. Using dd command we can take a backup of the data from one
disk to another disk. It copies the data in byte to byte. It can take a backup of the disk including bad blocks.
# dd if = <disk 1> of = <disk 2> (to take a backup from disk 1 and stores in disk
2)
# dd if = /dev/zero of = /root/raju bs = 1M count = 2048 (to create an empty file with
2GB size)
# dd if = /dev/sda of = /root/mbr.bak bs = 1 count = 512 (to take the backup of
/dev/sda Master
Boot Record)
Ratnakar Page 71
Abhisol : RED-HAT LINUX 6/7
# dd if = /root/mbr.bak of = /dev/sdb (to restore the MBR from backup to second disk
/dev/sdb)
# dd if = /dev/sda1 of = /dev/sdb1 (to take a backup of the entire /dev/sda1 disk
partition)
# dd if = /dev/sdb1 of = /dev/sda1 (to restore the /dev/sda1 contents from the
above backup)
# dd if = /dev/sda of = /dev/sdb (to take a backup of the entire /dev/sda disk
into /dev/sdb)
# dd if = /dev/cdrom of = /root/rhel6.iso (to create a ISO image file of the CD/DVD)
9. What is dump and how to take a backup and restore using dump and restore?
dump is a command used to take a backup of file systems only. We cannot take a backup of files and
directories. We cannot take a backup of disk to disk backup. It is not recommended to take a backup on
mounted file systems. So, unmount the file system and then take a backup is recommended. By default dump
is not available in the system. so, first install the dump package and then execute the dump commands.
# yum install dump* -y (to install the dump package)
The syntax for dump :
# dump <options><destination file name><source file name>(to take a backup of the file systems)
The options are, -0----->full backup
-(1 - 9) -----> incremental backups
-u -----> update the /etc/dumpdates file after successful dump
-v -----> verbose
-f ----->make the backup in a file
-e -----> exclude inode number while backing up
# dump -0uvf /opt/full.dump /coss (to take a full backup of the /coss file system and copied
it in /opt)
# dump -1uvf /opt/full.dump /coss (to take a backup modified files from the last full backup
nothing but
incremental backup)
# dump -2uvf /opt/full.dump /coss (to take a backup modified files from the last
incremental level -1
backup)
The syntax for restore :
# restore <options><dump backup file> (to restore the backup contents if that data is lost)
The options are, -f -----> used to specify the dump or backup file
-C -----> used to compare the dump file with original file
-v -----> verbose
-e -----> exclude the inode number
-i -----> restore in interactive mode
The commands in interactive mode are,
restore> ls -----> list the files and directories in the backup file
restore> add ----> add the files from dump file to current working directory
restore> cd -----> change the directory
restore> pwd ---> displays the present working directory
restore> extract ----> extract the files from the dump file
restore> quit ---> to quit from the interactive mode
# restore -tf /opt/full.dump (to list the dump file contents)
# restore -rf /opt/full.dump (to restore the dump file contents)
10. How many types of backup available?
There are mainly three types of backups available.
(i) Full backup (Entire file system backup)
(ii) Incremental backup (backup from the last full backup or incremental backup)
(iii) Cumulative or differential backup (backup from last full backup or cumulative backup)
11. What is the difference between incremental and differential backup?
Incremental backup :
Taking a backup from the last full backup or last incremental backup
Differential backup :
Taking a backup from last full backup or last cumulative or differential backup
Ratnakar Page 72
Abhisol : RED-HAT LINUX 6/7
12. Which file will update when backing up with dump command?
/etc/dumpdates file will be updated when backing up with dump command.
13. What are the dump devices?
(i) Tape drives
(ii) Disks (local disks)
(iii) Luns (network disks)
14. What is snap shot?
(i) The point - in - time copy of the file system is called the snap shot.
(ii) It provides online backup solution of the file system.
(iii) We can take a backup while the file system is mounted and it is in multi-user mode.
(iv) It occupied only as much disk space as the file system ie., being captured.
(v) We can also create backup, delete, query temporary (read-only) snap shots using fssnap
command.
15. What are the differences between tar and cpio commands?
(i) By tar we can take backup upto 80GB size of file systems , but using cpio there is no limit.
(ii) In tar the backup is in archive format ie., in compressed state, but in cpio there is no
compression.
(iii) In both the types only the whole backup is possible.
16. How to take a backup on production servers?
(i) Normally in backup environment we have 3 servers.
(a) Master server (production servers -- 1 or 2 no's).
(b) Media server (backup server -- 1 or 2 no's).
(c) Client server (Normal system)
(ii) Backups can be taken in types.
(a) Application Backup (Normally application users will take these types of backups)
(b) File system Backup (O/S backup, System Administrators will take these types of
backups)
(c) Database Backup (DBA users will take these types of backups)
(iii) Normally backup is automated through some backup tools like Veritas Net backup, IBM Tivoli and
Autosys.
(iv) Using cron tool also we can take backup. But cron will not inform the failed backup. The other
tools will inform by sending messages like why the backup is failed, when and where it is failed, ..etc.,
(v) On production servers the backup will follow the procedure,
(a) Master server deport from production.
(b) Import the master server on Media server.
(c) Then Master server will join with the Media server.
(d) Sync the data with the Master server.
(e) Take a backup from Master server and store the copy on Media server.
(f) Split the Master server from Media server.
(g) Deport the Master server from Media server.
(h) Import the Master server on production.
(i) Join the Master server with production.
17. What is your company's backup policy?
(i) By dump command we can take backups on disks, tapes and takes full, incremental and
differential or cumulative backups.
(ii) level 0 -- Full backup (monthly once)
level 3 -- Performed on every Monday (Incremental from last full or last
incremental backup)
level 4 -- Performed on every Tuesday (Incremental from last level 3
backup)
level 5 -- Performed on every Wednesday (Incremental from last level 4 backup)
level 6 -- Performed on every Thursday (Incremental from last level 5 backup)
level 7 -- Performed on every Friday (Incremental from last level 6
backup)
level 8 -- Performed on every Saturday (Incremental from last level 7
backup)
Ratnakar Page 73
Abhisol : RED-HAT LINUX 6/7
(c) # service command is used to start or stop the (c) # systemctl is the command to start or stop
services temporarily and # chkconfig is used the services temporarily or next booting
to start or stop the services at next booting time. time.
Ratnakar Page 74
Abhisol : RED-HAT LINUX 6/7
(a) It is the starting process in RHEL - 4, 5 and 6. (a) It is starting process in RHEL - 7.
(c) It will take more time to the system and (c) It will take less time to start the system and
services. services when compared to RHEL - 6.
(d) It will start the services one by one. (d) It will start the services parallel not one by one.
adjustable niceness)
# renice (to alter the scheduling priority of one or more running processes)
# pgrep (to list the process id's which matches with the pgrep argument)
RHEL - 6 commands :
Ratnakar Page 75
Abhisol : RED-HAT LINUX 6/7
# service <service name> status (to check the status of the service)
# service <service name> start (to start the service)
# service <service name> stop (to stop the service)
# service <service name> reload (to reload the service)
# service <service name> restart (to restart the service)
* These above commands will change the service statuses temporarily. So if we want to change
statuses of the
process automatically from next boot onwards we have to enable those services as given below.
# chkconfig --list (to check the availability of the services in
different run levels)
# chkconfig --list <service name> (to check the availability of the service in
different run levels)
# chkconfig <service name> on (to make the service available after restart)
# chkconfig <service name> off (to make the service unavailable after next boot)
# chkconfig --level <1-6><service name><on/off> (to make the service available or unavailable on
the
particular run level)
# chkconfig --level 5 vsftpd on (to make the vsftpd service available on run level 5)
# chkconfig --level 345 vsftpd on (to make the vsftpd service available on run levels 3, 4
and 5)
RHEL - 7 commands :
# systemctl status <service name> (to check the status of the service)
# systemctl start <service name> (to start the service)
# systemctl stop <service name> (to stop the service)
# systemctl reload <service name> (to reload the service)
# systemctl restart <service name> (to restart the service)
* These above commands will change the service statuses temporarily. So if we want to change
statuses of the
process automatically from next boot onwards we have to enable those services as given below.
# systemctl enable <service name> (to make the service available at next boot)
# systemctl disable <service name> (to make the service unavailable at next boot)
# grep <string name><file name> (to display the specified string in that file)
# grep -n <string name><file name> (to display the string with line no's)
# grep -e <string name 1> -e <string 2><file name> (to display 2 or multiple strings in that
file)
# grep -o <string name><file name> (to display only that string in that file not whole the text
of that file)
# grep -v <string name><file name> (to display all the strings except the specified one)
# grep ^ this coss (to display the line which is starting with the
specified string)
Ratnakar Page 76
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 77
Abhisol : RED-HAT LINUX 6/7
is 1. Only after initd process gets started, the remaining processes are called by it, and hence it is
responsible for all the remaining processes in the system. The parent process is identified by PPID (parent
process ID).
4. What is child process?
A process which started or created by the parent process is called child process and it is identified
by PID.
Useful # ps commands :
# ps -a (it displays all the terminals processes information)
# ps -au (it displays all the terminals processes information with
user names)
# ps -aux (it displays all the terminals processes information
including background
processes with user names)
* ? (question mark) if it is appeared at tty column, it indicates that is a background process.
# ps -ef (it displays the total processes information with parent
process ID (PPID))
# ps -P <process id> (it displays the process name if we know the process ID (pid))
# pidof<process name> (to see the process ID of the specified process)
# pidof initd (to see the process ID of the initd process)
# pstree (to display the parent and child processes structure in tree
format)
# ps -u <user name> (to display all the processes of the specified user)
# ps -u raju (to display all the processes of the user raju)
# ps -G <group name> (to display all the processes that are running by a particular group)
# ps -o pid, comm, %mem, %cpu (to display process id, command, %memory and %cpu
utilization nothing
but filtering the output)
# ps -Ao pid, comm, %mem, %cpu (to display the same information as above but including
some more
information)
# ps -o pid, comm, %mem, %cpu |sort -k <no.> -r |head -n 10 (to display which process is
utilizingmore
memory or cpu in reverse order where -k means field, <no.> means field no. and -r reverse order)
# ps -o pid, comm, %mem, %cpu |sort -k 3 -r |head -n 10 (to display the process which
occupies more memory and cpu
utilization in reverse order)
# ps -aux |grep firefox (to check whether the firefox is
running or not)
# pgrep -U <user name> (to display all the process
ID's only for that user)
* To communicate with the processes # kill and # pkill commands are used.
# kill -----> It will kill the processes using PID's.
# pkill -----> It will kill the processes using process names.
* We can also give some signals while using the above commands and we get the signals information
by
# kill -l command. This command will list all the signals with no's and there are 64 signals to pass.
5. What is signal in Process management?
Signals are a way of sending simple messages to processes. Most of these messages are already
defined and however signals can only be processed when the process is in user mode. Every signal has a
unique signal name. Each signal name is a macro which stands for a positive integer. Signals can be generated
by the process itself or they can be sent from one process to another. A variety of signals can be generated
or delivered and they have many uses for programmers.
6. What are the important signals in process management?
1. SIGHUP -----> to reload (read the configuration and load)
2. SIGINT -----> to interrupt from the keyboard (nothing but Ctrl + c)
3. SIGQUIT -----> to quit the process from keyboard (nothing but Ctrl + l)
9. SIGKILL -----> to kill the process forcefully (nothing but unblockable)
Ratnakar Page 78
Abhisol : RED-HAT LINUX 6/7
15. SIGTERM -----> wait for completing the process and then terminate (terminate gracefully)
18. SIGCONT -----> to continue or resume the process if it is stopped
19. SIGSTOP -----> to terminate the process (If it is not stopped the process we cannot
continue or resume that process
by Ctrl + c or Ctrl + z)
20. SIGHTSTP ----> to stop the process (nothing but Ctrl + z)
* But the most commonly used signals are 1, 9, 15 and 20.
* The default signal is 15 (gracefully) when we not specified any signal.
# kill - <signal><process ID> (to kill the specified process using kill signal)
# kill -9 1291 (to kill the process which has the PID as 1291)
* If we not specified the signal no. then the default signal 15 will effect.
# kill 1291 (to kill the process 1291 with default signal)
# pkill -u <user name> (to kill all the processes of the specified user)
# pkill -u raju (to kill all the processes of the user raju)
# pkill -9 firefox (to kill the firefox process)
7. How many process states are there?
There are six process states and they are,
(i) Running process (the process which is in running state and is indicated by " r " ).
(ii) Sleeping process (the process which is in sleeping state and is indicated by " s " )
(iii) Waiting process (the process which is in waiting state and is indicated by " w " ).
(iv) Stopping process (the process which is in stopping state and is indicated by " T " ).
(v) Orphan process (the process which is running without parent process and is indicated by " o " ).
(vi) Zombie process (the process which is running without child process and is indicated by " Z " ).
8. What is Orphan process?
The processes which are running without parent processes are called Orphan processes. Sometimes
parent process closed without knowing the child processes. But the child processes are running at that time.
These child processes are called Orphan processes.
9. What is Zombie process?
When we start parent process, it will start some child processes. After some time the child processes
will died because of not knowing the parent processes. These parent processes (which are running without
child processes) are called Zambie processes. These are also called as defaunct processes.
10. How to set the priority for a process?
Processes priority means managing processor time. The processor or CPU will perform multiple
tasks at the same time. Sometimes we can have enough room to take on multiple projects and sometimes we
can only focus on one thing at a time. Other times something important pops up and we want to devote all of
our energy into solving that problem while putting less important tasks on the back burner.
In Linux we can set guidelines for the CPU to follow when it is looking at all the tasks it has to do.
These guidelines are called niceness or nice value. The Linux niceness scale goes from -20 to 19. The
lower the number the more priority that task gets. If the niceness value is higher number like 19 the task will
be set to the lowest priority and the CPU will process it whenever it gets a chance. The default nice value is 0
(zero).
By using this scale we can allocate our CPU resources more appropriately. Lower priority programs
that are not important can be set to a higher nice value, while the higher priority programs like deamons and
services can be set to receive more of the CPU's focus. We can even give a specific user a lower nice value for
all his/her processes so we can limit their ability to slow down the computer's core services.
There are two options to reduce/increase the value of a process. We can either do it using the nice
or renice commands.
Examples :
# nice -n <nice value range from -20 to 19><command> (to set a priority to a process before
starting it)
# nice -n 5 cat > raju (to set the medium priority to cat
command)
# ps -elf (to check the nice value
for that command)
* To reschedule the nice value of existing process, first check the PID of that process by # ps -elf
command
and then change the niceness of that command by # renice <nice value (-20 to 19)>< PID > command.
Ratnakar Page 79
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 80
Abhisol : RED-HAT LINUX 6/7
(i) First check which process and who executed that process is consuming more CPU utilization
or memory utilization by executing # top command.
(ii) Then inform to those users who executed that process though mail, message or raising the
ticket.
(iii) If those users are not available or not responding to our mail then we have to change the
priority of that process using # renice command.
(iv) Before changing the process priority level , we have to get or take approval from our team lead
or project manager.
13. How to check the wwn no. of lun?
(i) First install sysutils package to execute the commands to know the wwn number by
executing command,
# yum install sysutils -y
(ii) # systool -c fs_host -v |grep "port-name" (to check the wwn number)
14. How to remove the page caches and other caches?
# sysnc ; echo 2 > /proc/sys/vm/drop_caches (to remove the page caches)
# sysnc ; echo 3 > /proc/sys/vm/drop_caches (to remove all types of caches like dent
cache,
page caches and others)
15. What is "sosreport" and how to generate it?
Sosreport is a command in linux (RHEL / CentOS) which collects system configuration and
diagnostic information of your linux box like running kernel version, loaded modules, and system and
service configuration files. This command also runs external programs to collect further information, and
stores this output in the resulting archive.
Sosreport is required when you have open a case with redhat for technical support. Redhat support
Engineers will require sosreport of your server for troubleshooting purpose.
To run sosreport , sos package should be installed. Sos package is part of default installation in most
of linux. If for any reason this package is no installed , then use below yum command to install sos
package :
# yum install sos -y
Generate the sosreport :
Open the terminal and type sosreport command :
# sosreport
This command will normally complete within a few minutes. Depending on local configuration and
the options specified in some cases the command may take longer to finish. Once completed, sosreport
will generate a compressed a file under /tmp folder. Different versions use different compression schemes
(gz, bz2, or xz). The file should be provided to Redhat support representative (normally as an
attachment to an open case).
Note: sosreport requires root permissions to run.
Different Options used in sosreport command :
The sosreport command has a modular structure and allows the user to enable and disable
modules and specify module options via the command line. To list available modules (plug-ins) use the
following command:
# sosreport -l
To turn off a module include it in a comma-separated list of modules passed to the -n/–skip-
plugins option. For instance to disable both the kvmand amd modules:
# sosreport -n kvm,amd
Individual modules may provide additional options that may be specified via the -k option. For
example on Red Hat Enterprise Linux 5 installations the sos rpm module collects "rpm -Va" output by default.
As this may be time-consuming the behaviour may be disabled via:
# sosreport -k rpm.rpmva=off
16. What is the command to see the complete information on virtual memory?
# vmstat is the command to the complete information on virtual memory like no of processes,
memory usage, paging memory, block I/O (input /output), traps, disk and CPU activity.
# vmstat 2 10 (It will give the report for every 2 seconds upto 10 times)
The fields are, r -----> how many waiting processes
Ratnakar Page 81
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 82
Abhisol : RED-HAT LINUX 6/7
(iii) We can do start or stop the deamon, but we cannot start or stop the process. We only
kill the process.
(iv) We can enable or disable to start the deamons at boot time as per our requirement, ie., on
demand is possible, but it is not possible if is a process.
(v) Deamon is a background process where as process is a foreground process.
24. What is command to check the load average?
# uptime is the command to check the system load, present time, from how many hours the
system is running and load average.
* The load average shows three fields. The 1st field shows the load average from 1 minute, 2nd
field shows the load average from 5 minutes and 3rd field shows the load average from 15
minutes.
25. How to assign or shift the process to the particular CPU?
(i) First install util-linux package by # yum install util-linux -y command.
(ii) Check the specified process is assigned to which processor ie., which CPU by # taskset -p
<pid> command.
(iii) Then shift the process to another available CPU by # taskset -cp <cpu -list><pid> command.
Examples:
# taskset -p 2125 (to check which processor is assigned to that process ID)
# taskset -cp 0, 4 2125 (to shift the process to the CPUs 0 and 4)
# taskset 0 firefox (to assign the firefox process to the CPU 0)
26. How to limit the CPU usage of a linux process?
(a) First install the cpulimit package by # yum install cpulimit -y command.
* This package is not available in normal Linux packages and it is available in EPEL (Extra
Packages for Enterprise Linux). So, first we have to enable the EPEL repository in our
system by following steps.
(i) # yum install epel-release -y (to install the epel-release package in
RHEL - 7)
(ii) # rpm -Uvh http://mirrors.kernel.org/fedora-epel/6/i386/epel-release-6-8.noarch.rpm
(to install the
EPEL package in RHEL - 6)
(ii) # rpm -Uvh http://mirrors.kernel.org/fedora-epel/5/i386/epel-release-5-4.noarch.rpm
(to install the
EPEL package in RHEL - 5)
(iii) # rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-5 (to import the gpg key if it ask
when executing the above
command in RHEL - 5)
(iv) # rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-6 (to import the gpg key if it ask
when executing the
above command in RHEL - 6)
(v) # rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-7 (to import the gpg key if it ask
when executing the
above command in RHEL - 7)
(vi) # yum repolist (to check EPEL repolist)
(b) # cpulimit -p <PID> -l 10 (to see the CPU usage of that process and limit
the CPU usage to
10%)
(c) # cpulimit -e /usr/local/bin/myprog -l 20 (to limit the CPU usage of this
command to 20%)
27. How to capture the network traffic?
# tcpdump is the command to capture and analyze the network traffic. By using this command we
can also troubleshoot the network problems.
Examples :
# tcpdump (to capture and analyze the network traffic)
# tcpdump -i eth0 (to capture the network traffic from eth0 continuously and Ctrl
+ c to exit)
# tcpdump -c 30 -i eth0 (to capture the network traffic from eth0 upto 30
packets only)
Ratnakar Page 83
Abhisol : RED-HAT LINUX 6/7
# tcpdump -w /root/tcp.pcap -i eth0 (to capture the network traffic from eth0 and
write that in
/root/tcp.pcap file)
# tcpdump -t t t -r /root/tcp.pcap (to read the contents of the above
captured file)
# tcpdump -i eth0 port 22 (to capture the network traffic from eth0 of
ssh traffic)
# tcpdump -i eth0 dst 172.25.0.11 and port 22 (to capture the network traffic from
172.25.0.11
system of ssh traffic)
28. What is SAR utility and how to use it?
SAR stands for System Activity Report. Using SAR we can check the information of CPU usage,
memory, swap, I/O, disk I/O, networking and paging. We can get the information of the present
status and post status (history using the data) upto last 7 days because HISTORY=7 is there in the
configuration file. The log messages are stored in /var/log/sa/sa1, /var/log/sa/sa2, /var/log/sa/sa3, ....etc.,
(where 1, 2, 3, ....etc., are dates). The SAR configuration is stored in /etc/sysconfig/sysstat file. In
this file the HISTORY=7 default option will be there. So, we can change the default 7 days to our
required value.
Before using the SAR utility first we should install the SAR utility package by # yum install sysstat*
-y command.
Examples :
# sar 2 10 (It will give the system report for every 2 seconds upto
10 times)
# sar -p 2 10 (to see the CPU utilization for every 2 seconds upto
10 times)
# sar -p ALL -f /var/log/sa/sa25 (to check the CPU utilization on 25th day of the
current month)
# sar -p ALL -f /var/log/sa/sa10 -s 07:00:00 -e 15:00:00 (to check the CPU utilization on
10th day of the current month from 7:00 to 15:00 hrs. where -s means
start time -e end time)
# sar -r 2 10 (to see the memory utilization for every 2 seconds upto
10 times)
# sar -r -f /var/log/sa/sa14 (to check the memory utilization on 14th day of the
current month)
# sar -r -f /var/log/sa/sa10 -s 07:00:00 -e 15:00:00 (to check the memory utilization on
10th day of the current month from 7:00 to 15:00 hrs. where -s means
start time -e end time)
# sar -S 2 10 (to see the swap utilization for every 2 seconds upto
10 times)
# sar -S -f /var/log/sa/sa25 (to check the swap utilization on 25th day of the
current month)
# sar -S -f /var/log/sa/sa10 -s 07:00:00 -e 15:00:00 (to check the swap utilization on 10th
day of the current month from 7:00 to 15:00 hrs. where -s
means start time -e end time)
# sar -q 2 10 (to see the load average for every 2 seconds upto
10 times)
# sar -q -f /var/log/sa/sa14 (to check the load average on 14th day of the
current month)
# sar -q -f /var/log/sa/sa10 -s 07:00:00 -e 15:00:00 (to check the load average on 10th day
of the current month from 7:00 to 15:00 hrs. where -s means start
time -e end time)
# sar -B 2 10 (to see the paging information for every 2 seconds upto
10 times)
# sar -d 2 10 (to see the disk usage for every 2 seconds
upto 10 times)
Ratnakar Page 84
Abhisol : RED-HAT LINUX 6/7
# sar -m 2 10 (to see the power management for every 2 seconds upto
10 times)
# sar -b 2 10 (to see the disk input and output statistics for every 2 seconds upto
10 times)
29. What are the port no. for different services?
The Port no. list :
FTP (For data transfer) 20 HTTP 80
FTP (For connection) 21 POP3 110
SSH 22 NTP 123
Telnet 23 LDAP 389
Send Mail or Postfix 25 Log Server 514
DNS 53 HTTPS 443
DHCP (For Server) 67 LDAPS (LDAP + SSL) 636
DHCP (For Client) 68 NFS 2049
TFTP (Trivial File transfer) 69 Squid 3128
Samba shared name verification 137 Samba Data Transfer 138
Samba Connection Establishment 138 Samba Authentication 445
MySQL 3306 ISCSI 3260
* Ping is not used any port number. It is used ICMP (Internet Control Message Protocol) only.
Other useful commands :
# uptime (to see from how long the system is running and also gives the load
average report)
* The load average is having 3 fields. 1 - present status, 2 - 5 minutes back and 3 - 15 minutes
back.
# iostat 5 2 (to monitor the input and output statistics for every 5 seconds upto
10 times)
# nproc (to check how many processors (CPUs) are there in
the system)
# top 1 (to see the no. processors (CPUs) are there in
the system)
# iptraf (to monitor the TCP or network traffic statistics in graphical
mode)
* Before using this command install the iptraf package by # yum install iptraf* -y command.
# iftraf -ng -f eth0 (to see the IP traffic statistics in
graphical mode)
# lscpu (to see the no. of CPUs present in the
system)
# lsusb (to see the no. of USB devices present in the
system)
# lsblk (to see all the partitions or block devices
information)
# cat /etc/redhat-release (to see the RHEL
version of system)
# dmidecode (to see the complete hardware information of
the system)
# dmidecode -t memory (to see the memory
information of the system)
# dmidecode -t bios (to see the system's bios
information)
Ratnakar Page 85
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 86
Abhisol : RED-HAT LINUX 6/7
FTP stands for File Transfer Protocol used to transfer files from one host to another host over a
TCP-based network.
2. How ftp works?
FTP is built on client-server architecture and utilizes separate control and data connection between
the client and server. FTP users may authenticate themselves using a clear-text sign-in protocol but can
connect anonymously if the server is configured to allow it.
Usually, the FTP server, which stores files to be transferred, uses two ports for the transferring
purpose. One port for commands and another port for sending and receiving data. Requesting from client
computers are received at the port 21 of server. ie., it is exclusively reserved for sending commands, therefore
it is called the Command Port.
Once an incoming request is received, the data requested or uploaded by the client computer is
transferred through a separate port 22 and referred as Data Port. At this point, depending on the Active or
Passive mode of the FTP connection, the port number used for the Data Transfer Varies.
3. What is Active FTP?
In Active FTP connection, the connection is initiated by the Client, and the data connection is initiated
by the Server. And as the server actively establishes the data connection with the client, hence it is called the
Active FTP. Here the client opens up a port higher than 1024 and it connects to the server through port 21.
Then the server opens its port 20 to establish a data connection.
4. What is Passive FTP?
In Passive FTP connection, both command and data connections are established by the client. In
this the server acts as entirely passive, that's why it is called the Passive FTP. Here the server listens for
incoming requested connections from client through port 21 and the client also initiates the data connection
at port 20.
5. What is the main difference between the Active FTP and Passive FTP?
The main difference between the Active FTP and the Passive FTP is based on who initiates the data
connection between the server and the client. If the data connection is initiated by the server, that is called
Active FTP and if the data connection is initiated by the client, that is called Passive FTP.
6. What is the profile for FTP server?
(i) It is used for uploading and downloading the files and directories cannot be downloaded.
(ii) The FTP server packageis vsftpd.
(iii) The FTP client packages are ftp and lftp.
(iv) The FTP server deamon is vsftpd (Very Secure FTP deamon)
(v) The FTP scripting file is /etc/initd/vsftpd
(vi)Port numbers 20 for data connection and 21 for FTP command connection.
(vii) The document root for FTP is /var/ftp
(viii) The FTP home directory is /var/ftp
(ix) The FTP configuration files are,
(a) /etc/vsftpd/vsftpd.conf
(b) /etc/vsftpd/user_list
(c) /etc/vsftpd/ftpuser
(d) /etc/pam.d/vsftpd
7. How to configure the FTP server?
(i) Install the FTP package by # yum install vsftpd* -y command.
(ii) Goto FTP document root directory and create some files by # cd /var/ftp/pub
# touch f(1..10}
(iii) Restart the FTP service or deamon by # service vsftpd restart command in RHEL - 6.
# systemctl restart vsftpd command in RHEL - 7.
(iv) Make the FTP service or deamon enable even after reboot the server by
# chkconfig vsftpd on command in RHEL - 6 and # systemctl enable vsftpd command
in RHEL - 7.
(v) Add the FTP service to the IP tables (RHEL - 6) and Firewalld (RHEL - 7).
RHEL - 6 :
# iptables -A INPUT -m state --state NEW -m tcp -p tcp --deport 21 -j ACCEPT
# iptables -A OUTPUT -m state --state NEW -m tcp -p tcp --deport 21 -j
ACCEPT
# iptables -A INPUT -m state --state NEW -m tcp -p tcp --deport 20 -j ACCEPT
Ratnakar Page 87
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 88
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 89
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 90
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 91
Abhisol : RED-HAT LINUX 6/7
For example, to mount the directory /product on the remote machine server9.example.com at the
mount point /mnt/nfs on your machine, add the following line to auto.master:
/mnt /etc/auto.misc --timeout 60
Next, add the following line to /etc/auto.misc:
nfs -rw server9.example.com:/product
The first field in /etc/auto.misc is the name of the /mnt subdirectory. This subdirectory is created
dynamically by automount. It should not actually exist on the client machine. The second field contains
mount options such asrw for read and write access. The third field is the location of the NFS export
including the hostname and directory.
The directory /mnt must be exits on the local file system. There should be no sub directories on the
local file system.
To start the autofs service, at a shell prompt, type the following command:
# servive autofs restart
To view the active mount points, type the following command at a shell prompt:
# service autofs status
If you modify the /etc/auto.master configuration file while autofs is running, you must tell the
automount daemon(s) to reload by typing the following command at a shell prompt:
# service autofs reload
7. How to configure NFS server?
(i) First install the NFS package by # yum install nfs* -y command.
(ii) Create the NFS shared directory on server system by # mkdir /public command.
(iii) Modify the permissions of the /public directory by # chmod 777 /public command. (These
permissions may be changed
depend on it's requirement)
(iv) Modify the SELinux context of the /public directory if SELinux is enabled by executing the below
command. # chcon -t public_content_t /public
(v) create some files in the /public directory by # touch f{1..10} command.
(vi) Open the file NFS configuration file and put an entry of the NFS shared information by # vim
/etc/exports command and type as an entry like <shared directory name> <to whom to export
the shared directory> (<permissions>, sync)
For example,
# vim /etc/exports
/public *.example.com (ro/rw, sync) (save
and exit the file)
* Where *.example.com means the shared directory can be exported to all the systems of
the example.com domain.
* Permissions like ro (read only) or rw (read & write) and sync means the data will
always be synced.
/public desktop9.example.com (rw, sync) (to export the /public to desktop 5
system only)
/public *.example.com (ro, sync) (export to the entire example.com domain
with read only)
/public 172.25.0.0/24 (rw, sync) (export to 172.25.0.0 network only with
read and write)
/public server [ 0 - 20 ].example.com (rw, sync) (export to server0 to server20
in example.com
domain with read and write)
/public 172.25.0.10 (rw, sync) (export to 172.25.0.10 network only
with read and write)
Common Mount permission options :
rw read/write permissions
ro read-only permissions
Ratnakar Page 92
Abhisol : RED-HAT LINUX 6/7
(vii) Export the above shared directory to the defined client systems by # exportfs -rv command.
(viii) Restart the NFS services by following the commands in RHEL - 6 and RHEL - 7.
# service rpcbind restart (to restart the rpcbind service
in RHEL - 6)
# service nfs restart (to restart the
NFS service in RHEL - 6)
# systemctl restart nfs-server (to restart the NFS service
in RHEL - 7)
(ix) Make the NFS service permanently boot at next boot time onwards as follows.
# chkconfig rpcbind on (to on the rpcbind service
in RHEL - 6)
# chkconfig nfs on (to on the nfs
service in RHEL - 6)
# systemctl enable nfs-server (to enable the
nfs-server in RHEL - 7)
(x) Export the NFS shared directory as follows.
# exportfs -rv
(xi) Enable the NFS service to the IP tables and Firewall in RHEL - 6 and RHEL - 7 as follows.
In RHEL - 6 :
(i) # setup
(a) Select Firewall Configuration.
(b) Select Customize ( Make sure firewall option remain selected ).
(c) Select NFS4 ( by pressing spacebar once ).
(d) Select Forward and press Enter.
(e) Select eth0 and Select Close button and press Enter.
(f) Select ok and press Enter.
(g) Select Yes and press Enter.
(h) Select Quit and press Enter.
(ii) Now open/etc/sysconfig/iptables file and add the following rules under the rule for port
2049 and save file.
-A INPUT -m state --state NEW -m udp -p udp --dport 111 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 111 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 32803 -j ACCEPT
-A INPUT -m state --state NEW -m udp -p udp --dport 32769 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 892 -j ACCEPT
-A INPUT -m state --state NEW -m udp -p udp --dport 892 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 875 -j ACCEPT
-A INPUT -m state --state NEW -m udp -p udp --dport 875 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 662 -j ACCEPT
-A INPUT -m state --state NEW -m udp -p udp --dport 662 -j ACCEPT
(iii) Restart the IP tables service by # service iptables restart command.
(iv) Make the IP tables service as permanent from next boot onwards as follows.
# chkconfig iptables on
The following commands could be helpful for troubleshooting :
Ratnakar Page 93
Abhisol : RED-HAT LINUX 6/7
In RHEL - 7 :
# firewall-cmd --permanent -add-service=nfs (to enable the nfs
service at firewall)
# firewall-cmd --permanent -add-service=mountd (to enable
the mountd service at firewall)
# firewall-cmd --permanent -add-service=rpc-bind (to enable
the rpc-bind service at firewall)
# firewall-cmd --complete-reload (to reload the
firewall)
8. What are requirements for NFS client?
(i) NFS server IP address or hostname.
(ii) Check the NFS shared name.
(iii) Create the local mount point.
(iv) Mount the NFS shared name on the local mount point.
(v) Go to mount point (local mount point) and access the NFS shared data.
9. How to access the NFS shared directory from the client?
(i) On Client system, install the nfs-utils package by # yum install nfs-utils* -y
command.
(ii) Check the exported NFS shared directory by # showmount -e <IP address or
hostname of the server>
Example : # showmount -e 172.25.9.11 or # showmount -e
server9.example.com
(iii) Create one mount point to mount the NFS shared directory by # mkdir /<mount point>
command.
Example : # mkdir /mnt/nfs
(iv) Mount the NFS shared directory on the above created mount point.
# mount <IP address or server hostname> : <NFS shared directory><mount
point>
Example : # mount 172.25.9.11:/public /mnt/nfs or
# mount server9.example.com:/public /mnt/nfs
* These are temporary mount only. ie., If the system is rebooted these are unmounted
automatically and we have to mount again after the system is rebooted.
(v) So, if we want to mount it permanently, then open /etc/fstab file and put an entry of the
mount point.
# vim /etc/fstab (to open the file)
<IP address or server hostname> : <shared name><mount point><file system>
defaults 0 0
Example : 172.25.9.11:/public /mnt/nfs nfs defaults 0 0 ( or )
server9.example.com:/public /mnt/nfs nfs defaults 0 0
(save and exit the file)
(vi) Mount all the mount points as mentioned in the above /etc/fstab file by # mount -a
command.
(vii) # df -hT command is used to check all the mounted partitions with file system types.
10. Why root user cannot create the files in the NFS shared directory and how to make him to create
the files?
The root user normally has all the permissions, but in NFS root user is also becomes as a normal
user. So, the root user having no permissions to create the files on the NFS shared directory.
The root user becomes as nfsnobodyuser and group also nfsnobody due to root_squash
permission is there by default. So, if we want to make the root user to create file on the NFS shared
directory, then go to server side and open the /etc/exports file and type as below,
<shared name> <domain name or systems names>(permissions, sync, no_root_squash)
Example : /public *.example.com(rw, sync, no_root_squash)
(save and exit the file)
# exportfs -rv (to export the shared directory)
Ratnakar Page 94
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 95
Abhisol : RED-HAT LINUX 6/7
Ratnakar Page 96
Abhisol : RED-HAT LINUX 6/7
16. How to add the LDAP user shared directory and how the LDAP user access that directory on client?
(i) Create a sub-directory in /securenfs directory.
# mkdir /securenfs/secure
(ii) Change the ownership of the above sub directory to LDAP user.
# chown ldapuser9 /securenfs/secure
(iii) Assign the full permissions on that directory to LDAP user.
# setfacl -m u : ldapuser9 : rwx /securenfs/secure
(iv) Change the SELinux context of that directory if SELinux is enabled.
# chcon -t public_content_t /securenfs/secure
(v) Re-export the secure NFS shared directory.
# exportfs -rv
(vi) Restart the NFS services.
# service nfs restart (restart the NFS
service In RHEL - 6)
# service nfs-secure-server restart (restart the secure NFS
service In RHEL - 6)
# systemctl restart nfs (restart the NFS
service In RHEL - 7)
# systemctl restart nfs-secure (restart the secure NFS
service In RHEL - 7)
On Client side :
(i) Login as LDAP user on local system through ssh.
# ssh ldapuser9@localhost (type yes and press Enter
if it asks (yes/no))
(ii) Type the password as kerberos if it asks the LDAP user password.
(iii) Go to that secure NFS shared mount point and access the contents.
$ cd /mnt/nfssecure (to
access the mount point)
$ ls (to
see the contents in that)
$ cd secure (to
access the sub directory)
$ ls (to
see the contents in that)
$ exit (to exit or
logout from ssh)
17. What are the advantages of NFS?
(i) NFS allows multiple computers can use same files, because all the users on the network or
domain can access the same data.
(ii) NFS reduces the storage costs by sharing applications on computers instead of allocating
local disk space for each user application.
(iii) NFS provides data consistency and reliability, because all users can read same set of files.
(iv) NFS supports heterogeneous environments which are compatible to NFS.
(v) NFS reduces System Administration overhead.
18. Remote user cannot mount the NFS shared directory. How to resolve this?
(i) First check the user belongs to the same domain as the NFS shared or not. ie., the user's
system domain and NFS shared system domain should communicate.
(ii) Check the user's system is pinging or not.
(iii) Check the user's name is present, not present or disabled to access the NFS server.
(iv) Check the mounted file system is shared or not.
(v) Check all the NFS server and client deamons are running or not.
(vi) Check all the network connections are properly established or not.
(vii) Check whether the NFS service is running or not in server's current run level.
(viii) Check whether the NFS server is running or hung or shutdown.
Ratnakar Page 97
Abhisol : RED-HAT LINUX 6/7
(ix) Check both NFS server and NFS client systems network routers, network connections and IP
addresses.
(x) Check the mount point is correct or not, paths are correct or not and files are there or
not.
(xi) Check the NFS shared directory and mount point details are correct or not in /etc/fstab
file.
(xii) Check the keytabs are downloaded and stored properly in /etc/krb5.keytab file on both NFS
server and client.
(xii) Finally check whether the NFS port no. 2049 is running or not and make sure that the IP tables
or firewall should not block the NFS service.
19. NFS server and NFS client configurations are OK, but at client it is not showing anything. How to
resolve?
(i) The rpcbind may be failed.
(ii) The server is not responding.
(iii) NFS client may be failed at reboot.
(iv) The NFS service is not responding.
(v) The deamons on both systems may not be running.
(vi) Network may be failed on both server and client or any one system.
(vii) May be server and client are not in the same domain or not pinging.
(viii) The server may be in hung or shutdown state.
20. What is Autofs ?
Autofs is service that can automatically mount the shared directory on demand and will automatically
unmount the shared directory if it is not accessed within the specified timeout period. The default timeout
period is 5 minutes or we can specify the timeout period in /etc/auto.master file.
21. What are the advantages of the Autofs?
(i) Shares are accessed automatically and transparently when a user tries to access any files or
directories under the designated mount point of the remote file system to be mounted.
(ii) Booting time is significantly reduced because no mounting is done at boot time.
(iii) Network access and efficiency are improved by reducing the number of permanently active mount
points.
(iv) Failed mount requests can be reduced by designating alternate servers as the source of a file
system.
(v) Users do not need to have root privilegesto mount or unmount the mount point.
(vi) We can reduce the CPU and memory utilizations because autofs will not mount permanently.
(vii) We can also reduce hard disk utilization because permanent mount points occupies the hard disk
space.
22. What are the minimum requirements for Autofs?
(i) autofs package.
(ii) autofs deamon.
(iii) One shared directory.
(iv) One mount point.
(v) Two configuration files are,
(a) /etc/auto.master
(b) /etc/auto.misc
23. How to configure Autofs?
(i) Install the autofs package by # yum install autofs* -y command.
(ii) Open /etc/auto.master file by # vim /etc/auto.master and at last type as below.
< Client's local mount point> /etc/auto.misc --timeout=60
Example :
/mnt /etc/auto.misc
(save and exit this file)
( * Where timeout=60 means, if the directory is not used for 60 seconds then the shared
directory is unmounted automatically. And the default is 5 minutes.)
(iii) Open /etc/auto.misc file by # vim /etc/auto.misc and types as below.
< Client temporary mount point >-<permissions><IP address or hostname of the server> :
<shared
name>
Ratnakar Page 98
Abhisol : RED-HAT LINUX 6/7
Example :
nfs -ro (or) -rw classroom.example.com:/public (save and
exit this file)
( * where -ro means read-only and -rw means read-write)
(iv) Restart the autofs service in RHEL -6 and RHEL - 7.
# service autofs restart (restart the autofs service in
RHEL - 6)
# chkconfig autofs on (enable the autofs service at next
boot in RHEL - 6)
# systemctl restart autofs (restart the autofs
service in RHEL - 7)
# systemctl enable autofs (enable the autofs service at next
boot in RHEL - 7)
(iv) Goto the Client local mount point which is entered in /et/auto.master file by # cd <mount
point> command.
Example :
# cd /mnt
(v) Goto the Client temporary mount point which is entered in /etc/auto.misc file as below.
# cd /mnt/<temporary mount point>
Example :
# cd nfs
# pwd (the
output is /mnt/nfs)
24. What is LDAP server?
LDAP (Lightweight Directory Access Protocol) is a software protocol for enabling anyone to locate
organizations, individuals, and other resources such as files and devices in a network, whether on the public
Internet or on a corporate intranet.LDAP is lighter because in its initial version it did not include security
features.
25. What is LDAP client?
LDAP Client is a network user creation and activity. LDAP user means network user. Network user
means login the user through network. If a user wants to login to the remote system, the LDAP user should be
created and login to the remote system through LDAP account.
Upto RHEL -5 for this NIS (Network Information System) is used. From RHEL - 6 onwards LDAP is
using. The main feature of the LDAP is to share the users information in network.
26. What are the requirements of LDAP and explain it?
(i) Packages.
(a) authconfig-gtk (to configure the LDAP client)
(b) sssd (system security service deamon)
(ii) LDAP client configuration file is /etc/ldap.conf
(iii) LDAP kerberos configuration file is /etc/krb5.conf
(iv) sssd (systems security service deamon) deamon.
(v) LDAP port no. is 389.
(vi) sssd deamon responsibility is retrieving and caching the authentication information.
(vii) The configuration file of sssd is /etc/sssd/sssd.conf
(viii) Through NIS the data is transferred in plain text format. So, there is no security. But LDAP will
transfer the data in encrypted format. So, the data will be in secured way.
(ix) LDAP is used by default sssd ie., kerberos.
27. What are the requirements for LDAP client?
(i) dc (domain controller)
Example : If the domain is example.com then dc=example, dc=com
(ii) ldap server
Example : ldap://classroom.example.com
(iii) Authentication certificate (example-ca.crt) is located in http://classroom.example.com/pub
directory.
28. How to configure the LDAP client?
(i) Create the LDAP user.
(ii) Configure the kerberos.
Ratnakar Page 99
Abhisol : RED-HAT LINUX 6/7
(iii) configure the NFS automount to share the LDAP user's home directory.
So, LDAP + NFS + sssd is the LDAP system.
* LDAP is used share the user name and password to remote system.
* sssd is used to authenticate in secured communication.
* NFS is used to share the user's home directory to remote system.
Steps :
(i) Install the LDAP + kerberos packages by the following commands.
# yum groupinstall directory* -y (installation
in RHEL - 6)
# yum install authconfig-gtk* sssd* -y (installation
in RHEL - 7)
* The LDAP packages are different in RHEL - 6 and RHEL - 7 but, the configuration of LDAP
is same in both the versions.
(ii) Create the LDAP users and passwords in the LDAP server.
(iii) Configure the LDAP user's authentication by # system_config_authentication command in
graphical user interface.
(iv) The above command will display the configuration window and in that select and type the option
as below.
User Account Database = LDAP
LDAP search base on = dc=example, dc=com
LDAP server = ldap://classroom.example.com/
Enable TLS to encrypt = Click on Download CA Certificate button and then
enter the url as,
http://classroom.example.com:/pub/example-ca.crt
Authentication Method = LDAP Password (then click on
Apply button)
(v) Check whether the LDAP user is configured or not by # getent password ldapuser9
command.
29. How to mount the LDAP user's home directory automatically when demand using Autofs tool?
(i) Install the autofs package by # yum install autofs* -y command.
(ii) Open the /etc/auto.master file by # vim /etc/auto.master command and type as below.
/home/guests /etc/auto.misc
(save and exit this file)
(iii) Open the /etc/auto.misc file by # vim /etc/auto.misc command and type as below.
ldapuesr9 -rw classrrom.example.com:/home/guests/ldapuser9 (save and
exit this file)
(iv) Restart the autofs services.
# service autofs restart (restart the autofs service in RHEL - 6)
# chkconfig autofs on (enable the autofs service at
next boot in RHEL - 6)
# systemctl restart autofs (restart the autofs service in
RHEL - 7)
# systemctl enable autofs (enable the autofs service at
next boot in RHEL - 7)
smb:/> put <file 1><file 2><file 3><file 4> ... (to upload multiple files to the
samba server)
smb:/> exit (to exit from the
samba server)
7. How to mount the samba shared directory permanently?
(i) Create the mount point for the samba shared directory.
# mkdir /mnt/samba
(ii) Put an entry of the mount point details in /etc/fstab file.
# vim /etc/fstab
//<samba server host name or IP address>/<shared directory name><mount
point> cifs defaults , username=<samba user name>,
password=<user's samba password> 0 0
Example : //server9.example.com/samba /mnt/samba cifs defaults,
username=raju, password=<samba
password> 0 0 (save and exit this file)
(iii) Mount all the mount points which are having entries in /etc/fstab file.
# mount -a
(iv) Check all the mount points by # df -hT command.
8. How to mount the samba shared directory using credential file?
(i) Create one file and put an entries of the user name and password details.
# vim /root/smbuser
username=raju
password=<user's samba password>
(save and exit the file)
(ii) Open /etc/fstab file and put an entries of the above credential details of user.
# vim /etc/fstab
//server9.example.com/samba /mnt/samba cifs credentials=/root/smbuser,
multiuser, sec=ntlmssp
0 0
(save and exit this file)
9. How to access the samba share directory if it already mounted?
(i) Go to Client system and switch to samba user.
# su - raju
$ cd /mnt/samba
$ ls (permission denied
message will be displayed)
$ cifscreds add <host name or IP address of the samba server>(to add cifs
credentials to the server)
$ ls (to see the contents
of the samba shared directory)
10. How to access the samba server from windows system?
(i) Goto Windows system, click on START button, click on Run and type as \\172.25.9.11\samba
command.
(ii) Then provide samba user name and password if it prompts us.
(iii) Then see the contents of the samba shared directory.
Other useful commands :
# smbpasswd -a <user name> (to add the samba password to the
samba user)
# smbpasswd -d <user name> (to disable the samba user's
password)
# smbpasswd -e <user name> (to enable the samba user's
password)
# smbpasswd -r <user name> (to remove the samba user's
password)
# smbpasswd -x <user name> (to delete the samba user's
password)
It's deamon is ntpd and Port number is 123. It's deamon is chronyd and Port number is 123.
We have to install the package manually. By default this package is installed.
# chronyc sources -v (to check chrony is
# ntpq -p (to check ntp is configured or not).
configured or not).
Configuration file is /etc/ntp.conf Configuration file is /etc/chrony.conf
Log file is /var/log/ntpstat Log file is /var/log/chrony
DNS is a distributed database of computers that is responsible for resolving hostnames against IP addresses
and vice-versa.
Any DNS query involves two parts.
(i) The Resolver: The resolver forms up or initiates the query. The resolver itself does not run as
a program. /etc/resolve.conf is an example of a resolver.
(ii) Name Server: The Name Server is the service running in the server that responds to the DNS
query generated by the resolver i.e. answers to the question of the
resolver.
The working DNS :
(i) The client initiates a query to find a domain example.com. The client sends the query to
the DNS server of the ISP. (The DNS Server IP in the client computer is set as the IP address of
the DNS Server of the ISP)
(ii) The DNS Server of the ISP first checks it's own cache to check whether it already knows the
answer. But as the answer is not present, it generates another query. As the Top Level Domain of
example.com is .com, so the DNS server queries the Internet Registration Authority to find who
is responsible for example.com.
(iii) The Internet Registration Authority responds to the ISP by answering the query.
(iv) Once the ISP DNS Server knows the authoritative name servers, it contacts the authoritative name
servers to find out the IP address for www.example.com i.e. the IP address of host www in
the domain example.com. (v) example.com responds to the ISP DNS Server by answering the query and
providing the IP address of the web server i.e. www
(vi) The ISP DNS Server stores the answer in it's cache for future use and answers to the client by
sending the IP address of the www server.
(vii) The client may store the answer to the DNS query in it's own cache for future use. Then the client
communicates directly with the www server of domain example.com using the IP
address.
(viii) The www server responds by sending the index.html page.
3. What is the format of the domain name?
Like a physical address, internet domain names are hierarchical way. If the Fully Qualified Domain
Name is www.google.co.in , the www is the Hostname, google is the Domain, co is the Second Level
Domain and in is the Top Level Domain.
4. What are the files we have to edit to configure the DNS?
There are four files to edit to configure the DNS. They are /etc/named.conf,
/etc/named.rfc1912.zones, Forward Lookup Zoneand Reverse Lookup Zone. DNS provides a
centralised database for resolution. Zone
is storage databasewhich contains all the records.
Forward Lookup Zone is used to resolveHostnames to IP addresses.
Reverse Lookup Zone is used to resolve IP addresses to Hostnames.
5. What are the DNS record and explain them?
(i) SOA Record : (Start of Authority)
SOA contains the general administration and control information about the domain.
(ii) Host A Record :
(a) It is nothing but aForward Lookup Zone.
(b) It maps Hostname to IP address.
(iii) PTR : (Pointer Record)
(a) It is nothing but a Reverse Lookup Zone.
(b) It maps IP address to Hostname.
(iv) NS Record : (Name Server Record)
It stores the DNS server IP addresses.
(v) MX Record : (Mail Exchange Record)
It stores the records of the Mail Server IP address.
(vi) CNME Record :
It is nothing but Host's Canonical name allows additional names or aliases to be used
locate a system.
6. What is the profile of the DNS?
Package : bind and caching-name
Script : /etc/init.d/named
Configuration file : /etc/named.conf and /etc/named.rfc1912.zones
Client's configuration file : /etc/resolve.conf
Document root : /var/named/
Log file : /var/log/messages
Deamon : named
Port number : 53
7. How to configure the DNS server?
(i) Install the packages bind, caching-name for RHEL - 6 &bind, cashing-name and unbound
for RHEL - 7.
# yum install bind* caching-name* -y (to install the DNS packages
for RHEL - 6)
# yum install bind* caching-name* unbound* -y (to install the DNS
packages for RHEL - 7)
(ii) Change the hostname by adding fully qualified domain name and make it permanent.
# hostname <fully qualified domain name> (to change the
hostname in RHEL - 6)
# hostname server9.example.com (example for setting hostname temporarily in
RHEL - 6)
# hostnamectl set <fully qualified domain name> (to change the hostname in
RHEL - 7)
# hostnamectl set server9.example.com (example for setting hostname temporarily in
RHEL - 7)
# vim /etc/hosts (open this file and go to last line and type as below in
RHEL - 6 only)
<IP address> <fully qualified domain name> <hostname>
172.25.9.11 server9.example.com server9 (for example of the
above syntax)
# vim /etc/sysconfig/network (open this file and go to last line and type as below
in RHEL - 6 only)
HOSTNAME=<fully qualified domain name>
HOSTNAME=server9.example.com (for example of the
above syntax)
(ii) Open the DNS main configuration file by # vim /etc/named.conf command.
* Go to line number 11 and edit this line as below.
listen-on port 53 { 127.0.0.1; <server IP address>; };
Example : listen-on port 53 {127.0.0.1; 172.25.9.11; };
* Go to line number 17 and edit this line as below.
allow-query { localhost; <Network ID>/<netmask>; };
Example : allow-query {localhost; 172.25.9.0/24; };
(save and exit this file)
(iii) Open the DNS zone reference file by # vim /etc/named.rfc1912.zones command
* Go to line number 19 and copy 5 lines and paste them at last of the file.
zone "<domain name>" IN {
type-master;
file "<forward lookup zone file name>";
allow-update { none; };
};
Example : zone "example.com" IN {
type-master;
file "named.forward";
allow-update { none; };
};
* Go to line number 31 and copy 5 lines and paste them at last of the file.
zone "<Three octets of the DNS server IP address> . in . addr . arpa" IN {
type-master;
file "<reverse lookup zone file name>";
allow-update { none; };
};
Example : zone "9.25.172 . in . addr . arpa" IN {
type-master;
file "named.reverse";
allow-update { none; };
};
(save and exit this file)
(iv) Copy /var/named/named.localhost file to /var/named/named.forward and edit as follows.
# cp -p /var/named/named.localhost /var/named/named.forward
# vim /var/named/named.forward
* Go to line number 2 and edit as follows.
@ IN SOA <DNS server fully qualified domain name> . com root . <domain
name> . {
* Go to line number 8 and edit as follows.
NS <DNS server fully qualified domain name> .
A <DNS server IP address>
<DNS server fully qualified domain name> IN A <DNS server IP address>
<Client 1 fully qualified domain name> IN A <Client 1 IP address>
<Client 2 fully qualified domain name> IN A <Client 2 IP address>
<Client 3 fully qualified domain name> IN A <Client 3 IP address>
www IN CNAME <DNS server fully qualified domain name>
Example : The line number 2 should be edited as follows.
@ IN SOA server9.example.com. root.example.com. {
The line number 8 should be edited as follows.
NS server9.example.com.
A 172.25.9.11
server9.example.com. IN A 172.25.9.11
client9.example.com. IN A 172.25.9.10
client10.example.com. IN A 172.25.9.12
client11.example.com. IN A 172.25.9.13
www IN CNAME server9.example.com.
(save and exit this file)
(v) Copy /var/named/named.empty file to /var/named/named.reverse and edit as follows.
# cp -p /var/named/named.empty /var/named/named.reverse
# vim /var/named/named.reverse
* Go to line number 2 and edit as follows.
@ IN SOA <DNS server fully qualified domain name> . com root . <domain
name> . {
* Go to line number 8 and edit as follows.
NS <DNS server fully qualified domain name> .
<Last octet of the DNS server IP address> IN PTR <DNS server fully qualified
domain name>
<Last octet of the Client 1 IP address> IN PTR <Client 1 fully qualified domain
name>
<Last octet of the Client 2 IP address> IN PTR <Client 2 fully qualified domain
name>
<Last octet of the Client 3 IP address> IN PTR <Client 3 fully qualified domain
name>
<DNS server fully qualified domain name> IN A <DNS server IP address>
www IN CNAME <DNS server fully qualified domain name>
Example : The line number 2 should be edited as follows.
@ IN SOA server9.example.com. root.example.com. {
The line number 8 should be edited as follows.
NS server9.example.com.
11 IN PTR server9.example.com.
10 IN PTR client9.example.com.
12 IN PTR client10.example.com.
13 IN PTR client11.example.com.
server9.example.com. IN A 172.25.9.11
www IN CNAME server9.example.com.
(save and exit this file)
(vi) Check the DNS configuration files for syntax errors.
# named-checkconf /etc/named.conf
# named-checkconf /etc/named.rfc1912.zones
# name-checkzone <domain name><forward lookup zone>
Example : # named-checkzone example.com /var/named/named.forward
# named-checkzone <domain name><reverse lookup zone>
Example : # named-checkzone example.com /var/named/named.reverse
(vii) Give full permissions to the forward and reverse lookup zones.
# chmod 777 /var/named/named.forward
# chmod 777 /var/named/named.reverse
(viii) Open /etc/sysconfig/network-scripts/ifcfg-eth0 and enter the DNS domain details if not
present.
# vim /etc/sysconfig/network-scripts/ifcfg-eth0 (go to last line and
type as follows)
DNS 1=example.com
(save and exit this file)
# ping -c3 <IP address of the DNS server> (to check the ping
test with IP address)
Example :
# ping -c3 server9.example.com
# ping -c3 172.25.9.11
(xiii) Check the resolution with host command.
# host <hostname> (to check the
resolution with hostname)
# host <IP address> (to check the
resolution with IP address)
Example :
# host server9.example.com
# host 172.25.9.11
(xiv) Check the resolution with nslookup command.
# nslookup <hostname> (to check the
resolution with hostname)
# nslookup <IP address> (to check the
resolution with IP address)
Example :
# nslookup server9.example.com
# nslookup 172.25.9.11
8. How to configure the DNS client?
(i) First assign the static IP address to the client.
(ii) Set the hostname to the client.
(iii) Restart the network service by #service network restart command.
(iv) Open /etc/resolve.conf file and edit as below.
# vim /etc/resolve.conf
search <domain name>
nameserver <DNS server IP address>
Example :
search example.com
nameserver 172.25.9.11
(save and exit this file)
(v) Check whether the DNS is resolving or not.
# dig <DNS server fully qualified name> (to check the resolving from hostname to
IP address)
# dig -x <DNS server IP address> (to check the resolving from IP
address to hostname)
Example : # dig server9.example.com
# dig -x 172.25.9.11
# dig client9.example.com
# dig -x 172.25.9.10
(vi) Check the resolution with ping test.
# ping -c3 <DNS client fully qualified domain name> (to check the ping test with
hostname)
# ping -c3 <IP address of the DNS server> (to check the ping
test with IP address)
Example :
# ping -c3 client9.example.com
# ping -c3 172.25.9.10
# ping -c3 server9.example.com
# ping -c3 172.25.9.11
(vii) Check the resolution with host command.
# host <hostname> (to check the
resolution with hostname)
# host <IP address> (to check the
resolution with IP address)
Example :
# host server9.example.com
# host 172.25.9.11
# host client9.example.com
# host 172.25.9.10
(viii) Check the resolution with nslookup command.
# nslookup <hostname> (to check the
resolution with hostname)
# nslookup <IP address> (to check the
resolution with IP address)
Example :
# nslookup server9.example.com
# nslookup 172.25.9.11
# nslookup client9.example.com
# nslookup 172.25.9.10
9. How to configure the Secondary DNS server?
(i) Install the packages bind, caching-name for RHEL - 6 &bind, cashing-name and unbound
for RHEL - 7.
# yum install bind* caching-name* -y (to install the DNS packages
for RHEL - 6)
# yum install bind* caching-name* unbound* -y (to install the DNS
packages for RHEL - 7)
(ii) Change the hostname by adding fully qualified domain name and make it permanent.
# hostname <fully qualified domain name> (to change the
hostname in RHEL - 6)
# hostname server6.example.com (example for setting hostname temporarily in
RHEL - 6)
# hostnamectl set <fully qualified domain name> (to change the hostname in
RHEL - 7)
# hostnamectl set server6.example.com (example for setting hostname temporarily in
RHEL - 7)
# vim /etc/hosts (open this file and go to last line and type as below
in RHEL - 6 only)
<IP address> <fully qualified domain name> <hostname>
172.25.6.11 server6.example.com server6 (for example of the
above syntax)
# vim /etc/sysconfig/network (open this file and go to last line and type as below
in RHEL - 6 only)
HOSTNAME=<fully qualified domain name>
HOSTNAME=server6.example.com (for example of the
above syntax)
(ii) Open the DNS main configuration file by # vim /etc/named.conf command.
* Go to line number 11 and edit this line as below.
listen-on port 53 { 127.0.0.1; <server IP address>; };
Example : listen-on port 53 {127.0.0.1; 172.25.6.11; };
* Go to line number 17 and edit this line as below.
allow-query { localhost; <Network ID>/<netmask>; };
Example : allow-query {localhost; 172.25.6.0/24; };
(save and exit this file)
(iii) Open the DNS zone reference file by # vim /etc/named.rfc1912.zones command
* Go to line number 19 and copy 5 lines and paste them at last of the file.
zone "<domain name>" IN {
type-slave;
file "slaves/<forward lookup zone file name>";
master { <Primary DNS server IP address; };
};
Example : zone "example.com" IN {
type-slave;
file "slaves/named.forward";
master { 172.25.9.11; };
};
* Go to line number 31 and copy 5 lines and paste them at last of the file.
zone "<Three octets of the DNS server IP address> . in . addr . arpa" IN {
type-slave;
file "slaves/<reverse lookup zone file name>";
master { <Primary DNS server IP address; };
};
Example : zone "9.25.172 . in . addr . arpa" IN {
type-slave;
file "slaves/named.reverse";
master { 172.25.9.11; };
};
(save and exit this file)
(iv) Copy /var/named/slaves/named.localhost to /var/named/slaves/named.forward and edit as
follows.
# mkdir /var/named/slaves
# cp -p /var/named/slaves/named.localhost /var/named/slaves/named.forward
# vim /var/named/slaves/named.forward
* Go to line number 2 and edit as follows.
@ IN SOA <secondary DNS server fully qualified domain name> . com root
. <domain name> . {
* Go to line number 8 and edit as follows.
NS <DNS server fully qualified domain name> .
A <DNS server IP address>
<secondary DNS server fully qualified domain name> IN A <secondary DNS server
IP address>
<DNS server fully qualified domain name> IN A <DNS server IP address>
<Client 1 fully qualified domain name> IN A <Client 1 IP address>
<Client 2 fully qualified domain name> IN A <Client 2 IP address>
<Client 3 fully qualified domain name> IN A <Client 3 IP address>
www IN CNAME <DNS server fully qualified domain name>
Example : The line number 2 should be edited as follows.
@ IN SOA server6.example.com. root.example.com. {
The line number 8 should be edited as follows.
NS server6.example.com.
A 172.25.6.11
server6.example.com. IN A 172.25.6.11
server9.example.com. IN A 172.25.9.11
client9.example.com. IN A 172.25.9.10
client10.example.com. IN A 172.25.9.12
client11.example.com. IN A 172.25.9.13
www IN CNAME server6.example.com.
(save and exit this file)
(v) Copy /var/named/slaves/named.empty file to /var/named/slaves/named.reverse and edit
as follows.
# cp -p /var/named/slaves/named.empty /var/named/slaves/named.reverse
# vim /var/named/slaves/named.reverse
* Go to line number 2 and edit as follows.
@ IN SOA <secondary DNS server fully qualified domain name> . com root
. <domain name> . {
* Go to line number 8 and edit as follows.
NS <secondary DNS server fully qualified domain name> .
<Last octet of the secondary DNS server IP address> IN PTR <secondary DNS server
fully qualified
domain name>
<Last octet of the DNS server IP address> IN PTR <DNS server fully qualified domain
name>
<Last octet of the Client 1 IP address> IN PTR <Client 1 fully qualified domain
name>
<Last octet of the Client 2 IP address> IN PTR <Client 2 fully qualified domain
name>
<Last octet of the Client 3 IP address> IN PTR <Client 3 fully qualified domain
name>
<secondary DNS server fully qualified domain name> IN A <secondary DNS server
IP address>
www IN CNAME <secondary DNS server fully qualified domain name>
Example : The line number 2 should be edited as follows.
@ IN SOA server6.example.com. root.example.com. {
The line number 8 should be edited as follows.
NS server6.example.com.
11 IN PTR server6.example.com.
11 IN PTR server9.example.com.
10 IN PTR client9.example.com.
12 IN PTR client10.example.com.
13 IN PTR client11.example.com.
server6.example.com. IN A 172.25.6.11
www IN CNAME server6.example.com.
(save and exit this file)
(vi) Check the DNS configuration files for syntax errors.
# named-checkconf /etc/named.conf
# named-checkconf /etc/named.rfc1912.zones
# name-checkzone <domain name><forward lookup zone>
Example : # named-checkzone example.com /var/named/slaves/named.forward
# named-checkzone <domain name><reverse lookup zone>
Example : # named-checkzone example.com /var/named/slaves/named.reverse
(vii) Give full permissions to the forward and reverse lookup zones.
# chmod 777 /var/named/slaves/named.forward
# chmod 777 /var/named/slaves/named.reverse
(viii) Open /etc/sysconfig/network-scripts/ifcfg-eth0 and enter the DNS domain details if not
present.
# vim /etc/sysconfig/network-scripts/ifcfg-eth0 (go to last line and
type as follows)
DNS 1=example.com
(save and exit this file)
(ix) Add the DNS server IP address in /etc/resolve.conf
# vim /etc/resolve.conf
search <domain name>
namesever <IP address of the DNS server>
namesever <IP address of the secondary DNS server>
Example :
search example.com
nameserver 172.25.9.11
nameserver 172.25.6.11
(save and exit this file)
(x) Restart the DNS server deamons.
# service named restart (to restart the deamon in RHEL - 6)
# chkconfig named on (to enable the deamon at next
boot time in RHEL - 6)
# setup
Network Configuration -----> Press Enter -----> Device Configuration -----> Select
eth0 ----->
Press Enter -----> Select Use DHCP -----> Press Spacebar -----> OK -----> Save -----
>Save & Quit
-----> Quit
# service NetworkManager restart
# service network restart
In RHEL - 7:
# nmcli connection modify "System eth0" ipv4.method auto or dynamic
# nmcli connection down "System eth0"
# nmcli connection up "System eth0"
# systemctl restart network
(ii) Open /etc/sysconfig/network-scripts/ifcfg-eth0 file and edit the BOOTPROTO line.
# vim /etc/sysconfig/network-scripts/ifcfg-eth0
* Go to BOOTPROTO line and edit that line as below.
BOOTPROTO=dhcp
(save and exit this file)
(iii) Get the IP address from the DHCP server.
# dhclient
# ifdown eth0
# ifup eth0
7. How to fix the IP address to the client every time it requests or how to configure the MAC
binding?
The process of assigning the same IP address (fixed IP address) to the DHCP client every time it
booted is called "MAC binding".
(i) Open the file /etc/dhcp/dhcpd.conf by # vim /etc/dhcp/dhcpd.conf command.
* Go to line number 76 and 77 and edit those lines as below.
host <dhcp client hostname> {
hardware ethernet <MAC address of the Client's NIC card>;
fixed addresses <IP address>;
}
Example :
host client 1 {
hardware ethernet 2015:ac18::55;
fixed addresses 172.25.9.150;
}
(save and exit this file)
(ii) Restart the DHCP services in RHEL - 6 and RHEL - 7.
# service dhcpd restart (to restart the DHCP service
in RHEL - 6)
# chkconfig dhcpd on (to enable the DHCP service at next
boot in RHEL - 6)
# systemctl restart dhcpd (to restart the DHCP service
in RHEL - 7)
# systemctl enable dhcpd (to enable the DHCP service at next boot in
RHEL - 7)
* Then the above MAC address of the system will get the same IP address every time it booted.
A computer that runs a Web site. Using the HTTP protocol, the Web server delivers Web pages to
browsers as well as other data files to Web-based applications. The Web server includes the hardware,
operating system, Web server software, TCP/IP protocols and site content (Web pages, images and
other files). If the Web server is used internally and is not exposed to the public, it is an "intranet server"
and if the Web server is used in the internet and is exposed to the public, it is an Internet server.
2. What is Protocol?
A uniform set of rules that enable two devices to connect and transmit the data to one another.
Protocols determine how data are transmitted between computing devices and over networks. They
define issues such as error control and data compression methods. The protocol determines the
following type of error checking to be used, data compression method (if any), how the sending device
will indicate that it has finished a message and how the receiving device will indicate that it has received the
message. Internet protocols include TCP/IP (Transmission Control Protocol / Internet Protocol),
HTTP (Hyper Text Transfer Protocol), FTP (File Transfer Protocol) and SMTP (Simple Mail Transfer
Protocol).
3. How a Web server works?
(i) If the user types an URL in his browsers address bar, the browser will splits that URL into a
number of separate parts including address, path name and protocol.
(ii) A DNS (Domain Naming Server) translates the domain name the user has entered into its
IP address, a numeric combination that represents the site's true address on the internet.
(iii) The browser now determines which protocol (rules and regulation which the client machine used
to communicate with servers) should be used. For example FTP (File Transfer
Protocol) and HTTP (Hyper Text Transfer Protocol).
(iv) The server sends a GET request to the Web Server to retrieve the address it has been given. For
example when a user types http://www.example.com/Myphoto.jpg , the browser sends a
GET Myphoto.jpg command to example.com server and waits for a response. The
server now responds to the browser's requests. It verifies that the given address exist, finds
the necessary files, runs the appropriate scripts, exchanges cookies if necessary and returns
the results back to the browser. If it cannot locate the file, the server sends an error message to
the client.
(v) Then the browser translates the data it has been given into HTML and displays the results
to the user.
4. In how many ways can we host the websites?
IP based Web Hosting :
IP based web hosting is usedIP address or hostname web hosting.
Name based Web Hosting :
Hosting the multiple websites using single IP address.
Port based Web Hosting :
Web hosting using another port number ie., other than the default port number.
User based Web Hosting :
We can host the Web sites using the user name and password.
* If we want to configure the httpd server, we have to follow the ISET rules. where I - Install, S-
Start,
E - Enable and T - Test.
* To access the websites using the CLI mode e-links, curl tools are used and to access the
websites using
the browser in Linux Firefox is used.
7. How to make the http web server available to the cleint?
(a) First assign the static IP address and hostname to the server.
(b) Check whether the server package by # rpm -qa httpd* command.
(c) If not installed, install the web server package by # yum install httpd* -y command.
(d) Start the web server and enable web server service at next boot.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(e) Open the browser and access the web server document.
# firefox (to open the
firefox browser)
* Then in address bar type as http://localhost/manual and press Enter key.
8. How to configure the IP based virtual host Web server?
(a) First assign the static IP address and hostname to the server.
(b) Check whether the server package by # rpm -qa httpd* command.
(c) If not installed, install the web server package by # yum install httpd* -y command.
(d) Check the configuration file to configure the http web server by # rpm -qac httpd
command.
(e) If required open the web server document by # rpm -qad httpd command.
(f) Go to the configuration file directory by # cd /etc/httpd/conf.d
(g) Create the configuration for IP based hosting.
# vim /etc/httpd/conf.d/ip.conf
<VirtualHost <IP address of the web server> : 80>
ServerAdmin root@<hostname of the web server>
ServerName <hostname of the web server>
DocumentRoot /var/www/html
</VirtualHost>
<Directory "/var/www/html">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
Example :
# vim /etc/httpd/conf.d/ip.conf (create the
configuration file)
<VirtualHost 172.25.9.11:80>
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
</VirtualHost>
<Directory "/var/www/html">
AllowOverride none
Require All Granted
</Directory>
<Directory "/var/www/virtual">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
Example :
# vim /etc/httpd/conf.d/virtual.conf (create
the configuration file)
<VirtualHost 172.25.9.11:80>
ServerAdmin root@server9.example.com
ServerName www9.example.com
DocumentRoot /var/www/virtual
</VirtualHost>
<Directory "/var/www/virtual">
AllowOverride none
Require All Granted
</Directory>
(d) Go to named based virtual directory and create the index.html file.
# cd /var/www/virtual
# vim index.html
<html>
<H1>
This is Name based Web Hosting
</H1>
</html>
(save and exit this file)
(e) Restart the web server deamon.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(f) Add the service to the IP tables and firewall.
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
# firewall-cmd --complete-reload
(g) Go to client system, open the firefox browser and type as http://www9.example.com in
address bar and check the index page is displayed or not.
(h) We can also access the website using elinks CLI tool.
# yum install elinks* -y (install the
elinks package)
# elinks --dump www9.example.com (access the
index page)
10. How to configure the port based web hosting?
(a) Make a directory for port based hosting.
# mkdir /var/www/port
(b) Go to the configuration file directory by # cd /etc/httpd/conf.d
(c) Create the configuration for port based hosting.
# vim /etc/httpd/conf.d/port.conf
<VirtualHost <IP address of the web server> : 8999>
ServerAdmin root@<hostname of the web server>
ServerName <port based hostname of the web server>
DocumentRoot /var/www/port
</VirtualHost>
<Directory "/var/www/port">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
Example :
# vim /etc/httpd/conf.d/virtual.conf (create
the configuration file)
<VirtualHost 172.25.9.11:8999>
ServerAdmin root@server9.example.com
ServerName port9.example.com
DocumentRoot /var/www/port
</VirtualHost>
<Directory "/var/www/port">
AllowOverride none
Require All Granted
</Directory>
(d) Go to port based virtual directory and create the index.html file.
# cd /var/www/port
# vim index.html
<html>
<H1>
This is Port based Web Hosting
</H1>
</html>
(save and exit this file)
(e) Generally port based web hosting requires DNS server. So, we can solve this problem by
the following way.
For that open the /etc/hosts file enter the server name and IP addresses on
both server and client.
# vim /etc/hosts
172.25.9.11 port5.example.com
(save and exit this file)
(f) By default the web server runs on port number 80. If we want to configure on deferent port
number, we have to add the port number in the main configuration file.
# vim /etc/httpd/conf/httpd.conf
* Go to Listen : 80 line and open new line below this line and type as,
Listen : 8999
(save and exit this file)
(g) By default SELinux will allow 80 and 8080 port numbers only for webserver. If we use
different port numbers other than 80 or 8080 then execute the following command.
# semanage port -a -t http_port_t -p tcp 8999
(h) Restart the web server deamon.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(i) Add the service to the IP tables and firewall.
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 8999 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 8999 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
<Directory "/var/www/html">
AllowOverride none
Require All Granted
AuthType Basic
AuthName "This site is protected"
AuthUserFile /etc/httpd/pass
Require User <user name>
</Directory>
(save and exit this file)
Example :
# vim /etc/httpd/conf.d/userbase.conf (create the
configuration file)
<VirtualHost 172.25.9.11:80>
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
</VirtualHost>
<Directory "/var/www/html">
AllowOverride none
Require All Granted
AuthType Basic
AuthName "This site is protected"
AuthUserFile /etc/httpd/pass
Require User raju
</Directory>
(h) Go to document root directory and create the index.html file.
# cd /var/www/html
# vim index.html
<html>
<H1>
This is User Authentication based Web Hosting
</H1>
</html>
(save and exit this file)
(i) Restart the web server deamon.
<Directory "/var/www/html">
AllowOverride none
Require All Granted
Order Allow, Deny
Allow from 172.25.9.0 or 172.25.0 (allows 172.25.9 network or 172.25 network to
access the websites)
Deny from .my133t.org (deny all the systems of *.my133t.org domain to access the
websites)
</Directory>
13. How to Redirect the website?
* Redirecting means whenever we access the website, it redirects to another website.
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
Redirect / "http://www.google.com"
</VirtualHost>
<Directory "/var/www/html">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
(c) Go to document root directory and create the index.html file.
# cd /var/www/html
# vim index.html
<html>
<H1>
This is Redirect based Web Hosting
</H1>
</html>
(save and exit this file)
(d) Restart the web server deamon.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(e) Add the service to the IP tables and firewall.
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
# firewall-cmd --complete-reload
(f) Go to client system, open the firefox browser and type as http://server9.example.com in
address bar and check the redirection google web page is displayed or not.
(g) We can also access the website using elinks CLI tool.
# yum install elinks* -y (install the
elinks package)
# elinks --dump server9.example.com (access the
index page)
* This website redirects to the google website.
14. How to configure the website with alias name?
(a) Go to the configuration file directory by # cd /etc/httpd/conf.d
(b) Create the configuration for alias based hosting.
# vim /etc/httpd/conf.d/alias.conf
<VirtualHost 172.25.9.11:80>
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
Alias /private /var/www/html/private
</VirtualHost>
<Directory "/var/www/html/private">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
(c) Create private directory in /var/www/html.
# mkdir /var/www/html/private
(c) Go to document root private directory and create the index.html file.
# cd /var/www/html/private
# vim index.html
<html>
<H1>
This is Alias based Web Hosting
</H1>
</html>
(save and exit this file)
(d) Restart the web server deamon.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(e) Add the service to the IP tables and firewall.
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
# firewall-cmd --complete-reload
(f) Go to client system, open the firefox browser and type as
http://server9.example.com/privae in address bar and check the private or alias based web page is
displayed or not.
(g) We can also access the website using elinks CLI tool.
# yum install elinks* -y (install the
elinks package)
# elinks --dump server9.example.com/private (access the
index page)
15. How to configure the directory based web hosting?
(a) Go to the configuration file directory by # cd /etc/httpd/conf.d
(b) Create the configuration for direct based hosting.
# vim /etc/httpd/conf.d/confidential.conf
<VirtualHost 172.25.9.11:80>
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
</VirtualHost>
<Directory "/var/www/html/confidential">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
(c) Create confidentialdirectory in /var/www/html.
# mkdir /var/www/html/confidential
(c) Go to confidential directory and create the index.html file.
# cd /var/www/html/confidential
# vim index.html
<html>
<H1>
This is Alias based Web Hosting
</H1>
</html>
(save and exit this file)
(d) Restart the web server deamon.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(e) Add the service to the IP tables and firewall.
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
# firewall-cmd --complete-reload
(f) Go to client system, open the firefox browser and type as
http://server9.example.com/confidential in address bar and check the directory based web page is
displayed or not.
(g) We can also access the website using elinks CLI tool.
# yum install elinks* -y (install the
elinks package)
# elinks --dump server9.example.com/confidential
(access the index page)
16. How to configure the web server to display the user defined home page not the index.html page?
Normally Apache will look the index.html as the home page by default. If the name changed it will
display the home page without configure that one. For that we can do the above as follows.
(i) Go to configuration file directory by # cd /etc/httpd/conf.d command.
(ii) Create a userpage configuration file.
# vim userpage.conf
<VirtualHost 172.25.9.11:80>
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
DirectoryIndex userpage.html
</VirtualHost>
<Directory "/var/www/html">
AllowOverride none
Require All Granted
</Directory>
(save and exit this file)
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 80 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
# firewall-cmd --complete-reload
(f) Go to client system, open the firefox browser and type as http://webapp9.example.com
in address bar and check the CGI based web page is displayed or not.
(g) We can also access the website using elinks CLI tool.
# yum install elinks* -y (install the
elinks package)
# elinks --dump webapp9.example.com (access the
index page)
18. What is secured web server?
Secured web server means normal Apache web server with SSL support. In normal web server the
data communication is done in plain text format. So, there is no security for data because everyone can
access the data. If we want to provide security to the data, then we have to configure the web server with SSL
support.
19. What is the profile of secured web server?
Package : mod_ssl
Configuration file : /etc/httpd/conf.d/ssl.conf
Private key location : /etc/pki/tls/private
Public key location : /etc/pki/tls/certs
Authentication certificate : /etc/pki/tls/certs
Port number : 443
* Private key extention is " . key " and public key extention is " . crt "
20. How to configure the secured web server?
(a) Install the web server and secure shell packages.
# yum install httpd* mod_ssl* -y command.
(b) Download the private key and public certificates.
# cd /etc/pki/tls/private
# wget http://classroom.example.com/pub/tls/private/server<no.> . key
# cd /etc/pki/tls/certs
# wget http://classroom.example.com/pub/tls/certs/server<no.> . crt
# wget http://classroom.example.com/pub/example-ca.crt
(c) Create the configuration file for secured web server.
# vim /etc/httpd/conf.d/https.conf
<VirtualHost 172.25.9.11:443>
ServerAdmin root@server9.example.com
ServerName server9.example.com
DocumentRoot /var/www/html
</VirtualHost>
(d) We have to copy 7 lines from ssl.conf file to https.conf file.
# vim -O ssl.conf https.conf
Copy the line numbers 70, 75, 80, 93, 100, 107, 116 copy and paste them in
https.conf file.
So, after copied those line the https.conf file should be as below.
<VirtualHost 172.25.9.11:443>
ServerAdmin root@server9.example.com
ServerName server9.example.com
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW
SSLCertificateFile /etc/pki/tls/certs/server9.crt
SSLCertificateKeyFile /etc/pki/tls/private/server9.key
#SSLCertificateChainFile /etc/pki/tls/certs/example-ca.crt
DocumentRoot /var/www/html
</VirtualHost>
<Directory "/var/www/html">
AllowOverride
Require All Granted
</Directory>
(save and exit this file)
(e) Go to document root directory by # cd /var/www/html command.
(f) # vim index.html
<html>
<H1>
This is a secured web hosting
</H1>
</html>
(save and exit this file)
(g) Restart the web server deamon.
# service httpd start (to start the webserver
deamon in RHEL - 6)
# chkconfig httpd on (to enable the service at
next boot in RHEL - 6)
# systemctl restart httpd (to start the webserver deamon
in RHEL - 7)
# systemctl enable httpd (to enable the service at next boot
in RHEL - 7)
(h) Add the service to the IP tables and firewall.
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 443 -j ACCEPT
# iptables -A OUTPUT -i eth0 -p tcp -m tcp --deport 443 -j ACCEPT
# service iptables save
# service iptables restart
In RHEL - 7 :
# firewall-cmd --permanent --add-service=http
# firewall-cmd --permanent --add-service=https
# firewall-cmd --complete-reload
(i) Go to client system, open the firefox browser and type as https://server9.example.com/
in address bar and check the secured web page is displayed or not.
21. How to generate our own private and public keys using crypto-utils package?
(i) Install the package by # yum install crypto-utils* -y command.
(ii) Create our own public and private keys by # genkey <hostname of the server>
command.
Example : #genkey server9.example.com (one window will be opened and we have
to enter the details)
Click on Next ---> Don't change the default size ---> Next ---> No ---
>The keys are generated in
their directories.
Other useful commands :
# httpd -t (to check the web server configuration file
for syntax errors)
normally the computer where you read your e-mails, for example your computer at home or in your office.
Also an advanced mobile phone or Smartphone, with e-mail capabilities, can be regarded as a client computer
in these circumstances.
2. How many types of mail servers available in Linux?
There are two types of mail servers.
(i) Sendmail server (default in RHEL - 5, available in 6 and 7)
(ii) Postfix (default in RHEL - 6 and 7)
These both mail server are used to send and receive the mails, but we cannot used both mail
servers at a time ie., we have to use only one server at a time. These mail servers are used as CLI mode.
Outlook express in windows is used to send or receive the mails. Thunderbird is used to send or receive the
mails using GUI mode in Linux. # mail is the command used to send the mails in CLI mode.
3. What are MUA, MTA, SMTP, MDA and MRAs?
MUA :
MUA stands for Mail User Agent. It is the e-mail client which we used to create-draft-send emails.
Generally Microsoft Outlook, Thunderbird, kmail, ....etc., are the examples for MUAs.
MTA :
MTA stands for Mail Transfer Agent. It is used to transfer the messages and mails between
senders and recipients. Exchange, Qmail, Sendmail, Postfix, ....etc., are the examples for MTAs.
SMTP:
SMTP stands for Simple Mail Transfer Protocol. It is used to transfer the messages and mails
between the MTAs.
MDA :
MDA stands for Mail Delivery Agent. It is a computer software component that is responsible for
the delivery of e-mail messages to a local recipient's mailbox. Within the Internet mail architecture, local
message delivery is achieved through a process of handling messages from the message transfer agent, and
storing mail into the recipient's environment (typically a mailbox).
MRA :
MRA stands for Mail Retrieval Agent. It is a computer application that retrieves or fetches e-
mail from a remote mail server and works with a mail delivery agent to deliver mail to a local or remote email
mailbox. MRAs may be external applications by themselves or be built into a bigger application like an MUA.
Significant examples of standalone MRAs include fetchmail, getmail and retchmail.
4. What is the profile of mail server?
Package : sendmail (in RHEL - 5, 6 and 7) or postfix (in RHEL - 6 and 7).
Configuration file : /etc/postfix/main.cf, /etc/dovecot/dovecot.conf
Log file : /var/log/mail.log
User's mails location : /var/spool/mail/<user name>
root user's mail location : /var/spool/mail/root
Deamons : postfix
Port number : 25
5. How to configure the mail server?
The pre-requisite for mail server is DNS. ie., Domain Naming System should be configured first.
(i) Check the hostname of the server by # hostname command.
(ii) Install the mail server package by # yum install postfix* dovecot* -y command.
(iii) Open the mail configuration file and at last type as below.
# vim /etc/postfix/main.cf
myhostname = server9.example.com
mydomain = example.com
myorigin = $mydomain
inet_interfaces = $myhostname, localhost
mydestination = $myhostname, localhost.$localdomain, localhost, $mydomain
home_mailbox = Maildir /
(save and exit this file)
(iv) Open the another configuration file and at last type as below.
# vim /etc/dovecot/dovecot.conf
protocols = imap pop3 lmtp
(save and exit this file)
(v) Restart the mail server services.
$ cd Maildir
$ ls
$ cd new
$ cat <mail name>
Other useful commands :
* To send a mail to the local system, no need to configure the mail server.
* To send a mail to the remote system, then only we have to configure the mail server.
# mail raju@server9.example.com (to send the mail to the raju user of the
server9)
type the message whatever you want (press Ctrl + d to exit and send the
mail)
# su - raju (to switch to the raju user)
$ mail (to check the mails of the raju user)
N abcd
N efgh
N ijkl
N mnop (there are four mails in the
mail box)
& 1 (to read the 1st mail)
* If the mail is new one then 'N' letter is appears before the mail. If it is already seen then
there is no letter before the mail.
* press 'q' to quit the mail utility.
# mail or mutt -s " hello " <user name1><user name2><user name3>
type the matter whatever you want (press Ctrl + d to exit and send the
mail to 3 users)
$ mail (to see all the mail in the mail box)
&<type the mail number> (to read the specified mail by it's number)
& r (to send the replay mail to that user)
& p (to send the mail to the printer for
printing)
& w (to write the contents of the mail into a file, ie., save the contents of the mail ina
file)
& q (to quit the mail box)
& d (to delete the mail)
& d <mail number> (to delete the specified mail by it's
number)
& d 1-20 (to delete the mails from 1 to
20 numbers)
# mail -s "hello" <user name>@<servername> . <domain name> (to send the mail to the
remote system)
# mailq (to see the mails in the queue)
* If the mail server is not configured or not running, then the sent mails will be in the queue.
# mail -s "hello" <user name1><user name2><<File name> (send the mail with attached
file to
the 2 users)
# postfixcheck (to verify the mail configuration file for
syntax errors)
(i) Create one partition and create the LVM with that partition.
# fdisk <device name>
: n (new partition) ---> Enter ---> Enter ---> Enter ---> +<size in MB/GB/TB> ---> w
(write the changes into the disk)
# partprobe (to write the changes
into the partition table)
# pvcreate <disk partition name> (to create the physical volume)
# vgcreate <physical volume name> (to create the volume
group)
# lvcreate -s <extent size> -n <logical volume name><vg name> (to create the logical
volume)
(ii) Install the iSCSI package by # yum install scsi-target-utils -y command in RHEL - 6 or
Install the iSCSI package by # yum install target* -y command in RHEL - 7.
(iii) Start the iSCSI deamon and enable the deamon at next boot time.
# service tgtd restart (to start the iSCSI
deamon in RHEL - 6)
# chkconfig tgtd on (to enable the iSCSI deamon at next
boot in RHEL - 6)
# systemctl start target (to start the target deamon in
RHEL - 7)
# systemctl enable target (to enable the target deamon at next
boot in RHEL - 7)
(iv) Configure the iSCSI storage.
In RHEL - 6 :
#vi /etc/tgt/targets.conf
default-driver iscsi
<target iqn.2015-06.com.example:server9.target1>
backing-store <iSCSI partition name>
write-cache off
</target>
In RHEL - 7 :
# targetcli (to get the configuration window and displays "/>"
prompt appears)
/> ls (to see the
configuration contents)
/> /backstores/block create <block storage name><the above created volume name>
(create the
block storage)
/> /iscsi create iqn.2015-06.com.example:server9 (to create the lun number not the
lun name)
/> /iscsi/iqn.2015-06.com.example:server9/tpg1/acls create iqn.2015-
06.com.example:server9 (to
create the alias name for client side lun number)
/> /iscsi/iqn.2015-06.com.example:server9/tpg1/luns create /backstores/block/<block
storage name>
(to create the lun using the
block storage device)
/> /iscsi/iqn.2015-06.com.example:server9/tpg1/portals create <IP address of the server>
(to allot the above created lun to the IP address and port
number, ie., 3260)
/> saveconfig (to save the iSCSI configuration into the
configuration file)
/> exit (to exit from the
configuration window)
(v) Restart the iSCSI deamons after the configuration of iSCSI or target.
# service tgtd restart (to start the iSCSI
deamon in RHEL - 6)
name>="<value>";
Example : mysql or mariadb > update mydetails name="bangaram" where name='raju';
8. How to delete the table from the database?
mysql or mariadb > drop table <table name>;
Example : mysql or mariadb > drop table mydetails;
9. How to connect the remote database from our system?
# mysql -u root -h <host name> -p (here we have to enter the
password)
Example : # mysql -u root -h server9.example.com -p
(If the database is configured as localhost database, then server will not allow remote database
connections and Permission denied message will be displayed on the screen)
10. How to add mysqld service to IPtables and mariadb service to firewall?
In RHEL - 6 :
# iptables -A INPUT -i eth0 -p tcp -m tcp --deport 3306 -j ACCEPT
# iptables -A INPUT -p tcp -m tcp --deport 514 -j ACCEPT (to add the incoming
port no. to
Iptables in RHEL - 6)
# iptables -A INPUT -p udp -m udp --deport 514 -j ACCEPT (to add the
incoming port no. to
Iptables in RHEL - 6)
# iptables -A OUTPUT -p tcp -m tcp --deport 514 -j ACCEPT (to add the
outgoing port no. to
Iptables in RHEL - 6)
# iptables -A OUTPUT -p udp -m udp --deport 514 -j ACCEPT (to add
the outgoing port no. to
Iptables in RHEL - 6)
# firewall-cmd --permanent -add-port=514/tcp (to add the 514 tcp port no. to
the firewall)
# firewall-cmd --permanent -add-port=514/udp (to add the 514 udp port no.
to the firewall)
# firewall-cmd --complete-reload (to reload the firewall
configuration)
4. How to configure the client system to send log messages to the log server?
(i) Open the log server configuration file by # vim /etc/rsyslog.conf command.
(ii) Go to line no. 90 and type as below.
*.*@<log server IP address> : 514
Example : *.* @172.25.9.11:514 (save and
exit this file)
(iii) Restart the log server deamons in RHEL - 6 and RHEL - 7.
# service rsyslog restart (to restart the log server deamon in
RHEL - 6)
# chkconfig rsyslog on (to enable the log server deamon at next boot in
RHEL - 6)
# systemctl restart rsyslog (to restart the log server
deamon in RHEL - 7)
# systemctl enable rsyslog (to enable the log server deamon at
next boot in RHEL - 7)
* Then all the log messages are stored in /var/log/secure location.
* To monitor all the messages on the server by # tailf /var/log/secure command.
* Open the /etc/rsyslog.conf file and type as below to store all the client's log messages in
remote log server only.
# vim /etc/rsyslog.conf
*.* /var/log/secure
(save and exit this file)
* Then restart the log server deamons in RHEL - 6 and RHEL - 7.
# service rsyslog restart (to restart the log server deamon in
RHEL - 6)
# systemctl restart rsyslog (to restart the log server
deamon in RHEL - 7)
5. What is log file?
Log file is file that contains messages about that system, including the kernel, services and
applications running on it, ....etc., There are different log files for different information. These files are very
useful when trying to troubleshoot a problem with systems.
Almost all log messages are stored in /var/log directory. Only root user can read these log
messages. We can use less or more commands to read these log files. The messages will be generated only
when rsyslog service is running, otherwise the log messages will not be generated.
The different types of log files and their locations :
/var/log/messages -----> System and general messages and DHCP log messages.
/var/log/authlog -----> Authentication log messages.
/var/log/secure -----> Security and authentication and user log messages.
/var/log/maillog -----> Mail server log messages.
# iptables -A INPUT -i eth0 -p tcp --deport 22 -j ACCEPT (to add the rules to the
existing
iptables to allow ssh)
where -A ---> Add or append a rule to the INPUT chain for incoming traffic.
-i eth0 ---> Incoming packets through the interface eth0 will be verified against this
added new rule.
-p tcp -deport 22 ---> protocol is tcp and the destination port is 22.
-j ACCEPT ---> Accept the packet.
# iptables -A INPUT -p tcp -m state --state NEW -m tcp --deport 80 -j ACCEPT
# ping -a 192.168.10.1 (to ping the IP address with audiable ping ie., it
makes noises)
# shred -n 5 trail.txt (to over write the trail.txt file five times default
is 3 times)
# shred -u 5 trail.txt (to remove a file after
over writing)
* This shed tool may not work in journaling or RAID file systems.
# file <file name> (to know what type
file is that)
# mtr <IP address> (to check the connection between the source and the
destinations)
* The above command gives the report continuously until the user press Ctrl+c.
# htop (it is an improved top command and it allows to scroll vertically or
horizontally)
# logsave filelist.txt ls -l (to capture the output of any command and stores it in a file
along with the starting and ending
time of the command)
# look "printf" avltree.c (to display all the lines in a file that start with a particular
string and performance of this command
is more than grep)
# stat <file name> (to display the status of a file or file system like absolute path of the files,
the no of blocks used by the file, the I/O block size, inode access specifier, access time, time of
modification, ....etc)
# mc (it is a powerful text based file manager and it is a directory browsing tool and
allows to see thecontents of the
archived files, ...etc.;)
* In RHEL - 6 we have to write the rules and regulations to allow or deny the system but, in RHEL -
7 we have
enable or disable the firewalld options only.
# firewall-config (to manage the firewalld services using graphical
user mode)
# firewall-cmd --get-zones (to display all
available zones)
# firewall-cmd --get-default-zone (to check the default zone, the default zone is
public zone)
# firewall-cmd --set-default-zone=work (to activate the work zone, nothing but
changing default
zone temporarily)
# firewall-cmd --permanent --set-default-zone=work (to set the default zone as work
permanently)
# firewall-cmd --get-activate-zones (to display which zone is an active with IP address and
interface eth0)
# firewall-cmd --add-service=172.25.0.0/24 --zone=public (to add the source to the public zone
temporarily)
# firewall-cmd --get-activate-zone (to see the default zone which is
activated)
# firewall-cmd --permanent -add-source=172.25.0.0/24 --zone=public
(to add the IP address to
public zone permanently)
# firewall-cmd --remove -souce =172.25.0.0/24 --zone=public (to remove the iP address from
public zone
temporarily)
# firewall-cmd --permanent --remove-source=172.25.0.0/24 --zone=public
(to remove the iP address from public
zone permanently)
26. Virtualization
1. What is virtualization?
Virtualization allows multiple operating system instances to run concurrently on a single computer;it
is a means of separating hardware from a single operating system. Each “guest” OS is managed bya
Virtual Machine Monitor (VMM), also known as a hypervisor. Because the virtualization system sitsbetween
the guest and the hardware, it can control the guests’ use of CPU, memory, and storage,even allowing
a guest OS to migrate from one machine to another.
2. What are types of virtualizations available in Linux?
RHEL - 5 : RHEL - 6 & 7 :
xen kvm
64 bit 64 bit
VT-Enabled VT-Enabled
Intel/AMD Intel/AMD
2 GB RAM 2 GB RAM
6 GB Hard disk 6 GB Hard disk
3. What are the packages of virtualization and how to install the packages?
(i) qemu (It is used to provide user level KVM virtualization and disk image also)
(ii) virt (It is used to provide virtualization software)
(iii) libvirt (It is used to provide the libraries for virtualization software)
(iv) python (This package provides the host and server libraries for interacting with Hypervisor
and
Host system)
# yum install qemu* virt* libvirt* python* -y (to install the
virtualization softwares)
4. How to start the virtualization manager and how to create a new virtual machine?
(i) Go to Applications -----> System Tools -----> Virtual Machine Manager
(ii) Vitual Machine Manager is used to check and displays the available virtual machines. It is
also used to create the new virtual machines.
(iii) To create a new virtual machine first click on monitor icon, then enter the virtual machine
name, Select Local and Select Forward.
(iv) Click on Browse Local, Select the guest O/S " . iso " image file and Select Forward.
5. What are the packages of Virtualization Hypervisor and how to install the packages?
(i) "virtualization hypervisor" (provides the foundation to host virtual machines
includes the libvirt and
qemu- kvm package)
(ii) "virtualization client" (provides the support to install and manage virtual
machines includes virsh, virt-install, virt-manager, virt-
top and virt-viewer packages)
(iii) "virtualization tools" (provides tools for offline management of virtual machines
includes the
libguestfs package)
(iv) "virtualization platform" (provides an interface to access and control virtual machines
includes the libvirt, libvirt-client and
virt-who packages)
Installation of Virtualization Hypervisor :
# yum group install "virtualization hypervisor" "virtualization client" "virtualization tools"
"virtualization platform" -y
systems, Gab is not running, llt not running, and configuration files main.cf
crashed or missed and resources are not started, ... etc.
(d) I also write small scripts to perform internal routine jobs, document preparation,
handover mails checking, how many tickets issued, how many tickets solved and how many
jobs pending, ....etc.,
(e) I also supports in application deployment, database deployment and others.
3. What are the tools you are using?
(i) netstat, vmstat, iostat, nmap and top for performance monitoring tools.
(ii) cron and at for job scheduling.
(iii) Remedy tool for ticketing system.
(iv) Veritas Netbackup, Tivoli, .... etc., for backing purpose
(v) Outlook for internal mailing.
4. What are the storage boxes using?
(i) NetApps, VMC, Clarian and EMC2.
(ii) Emulex, Qlogic (HBA cards).
5. What are the Applications are you using?
(i) Databases (Oracle 10g, 11g and Mysql).
(ii) Oracle Applications like ERP packages (Oracle 11i and 12).
(iii) SAP applications.
(iv) Datawarehousing, ....etc.,
6. What is your company hierarchy?
Me -----> Team Lead or Tech Lead -----> Manager -----> Delivery Manager -----> Asia head
7. What level are you supporting?
Linux Administrator as Level 2.
8. What are your shift timings?
General shift -----> 09:00 - 18:00 hrs.
Shifts : One shift from USA and two shifts from India operations upto last 2 months and now all the
operations are from India only and data centre operations from USA only.
1 st shift from 07:00 - 15:00 hrs, 2 nd shift from 15:00 - 23:00 hrs, 3 rd shift from 21:00 -
07:00 hrs.
9. What is your team size?
Total 18 members. For each shift 5 members each and 3 members on weekly off.
10. What about tickets issues and tickets frequency?
(i) 7 - 8 tickets daily and Max. 10 per day.
In those 85 - 90% are CPU utilization full, memory full, file system full, login problems and
sometimes node down issues.
(ii) General tickets severity - 3, severity - 2, severity - 1.
We are not resolved severity level - 1 tickets.
(iii) Incidents :
Severity level - 1 should be solved within 1 hour (Immediate).
Severity level - 2 should be solved within 6 hours.
Severity level - 1 should be solved within 24 hours.
Severity level - 1 should be solved within 2 days.
Request priority ----> High, medium and low
11. What is your notice period?
25 - 30 days.
12. Any Mail ids?
Internal mail id (mails won't come from outside and go to outside).
13. Are you contract or permanent? And why are you changing?
Permanent in XXXXXXXXXXX Pvt limited. I am looking the company which provides high availability
on cloud, virtualization and storage environments to enhance my knowledge and better career growth.
14. What are the projects are you dealing?
(i) Databases.
(ii) Banking.
(iii) Finance.
(iv) Logistics.
(v) Hotel and Tourism, .....etc.,
(viii) If any files are open in the production server, the backup may be failed. So, check any files
opened or not by # lsof or # fuser -cv <file system> commands.
(ix) Sometimes the script in Veritas Net backup or Tivoli tools may be corrupted or not running,
then restore those scripts from backup or we need manually deport & import and take backup.
(x) Sometimes backup failed due to backup port no. 13782 may be not working or in blocked state.
It can be checked by # netstat -ntulp | grep 13782 command.
(xi) If the media server and production server are not in the same domain, then backup may be failed.
(ie., production server domain name may be changed but no intimation to backup
team about that change, so media server is in another domain).
Backup Procedure :
(i) Deport the disk group on production server.
(ii) Import the disk group on backup (media) server.
(iii) Join the disk group with media server.
(iv) Sync the data with production server.
(v) Take the backup.
(vi) split the disk group from media server.
(vii) Join the disk group with production server.
(viii) Deport the disk group from media server.
(ix) Import the disk group on production server.
Backup policy :
(i) Complete (full) backup (every month ie., once in a month).
(ii) Incremental backup (Daily).
(iii) Differential or cumulative backup (every week end).
22. How to troubleshoot if the file system is full?
(i) First check whether the file system is O/S or other than O/S.
(ii) If it is other than O/S, then inform to that respective teams to house keep the file system (ie.,
remove the unnecessary files in those file system).
(iii) If not possible to house keep then inform to different teams (raise the CRQ (Change Request)) for
increasing the file system.
(a) First take business approval and raise the CRQ to monitoring team to ignore the alerts
from the system, stop the application team to stop the application and database team to stop the
database.
(b) Normally team lead or tech lead or manager will do this by initiate the mail thread.
(c) We will do this on weekend to reduce the business impact.
(iv) First take a backup of the file system then unmount the file system.
(v) Remove that partition and again create that file system with increased size, then mount again that
file system and restore the backup.
(vi) If the file system belongs to system log files or other log files and not to delete then they
requested us to provide one Repository server (only for log files). Normally one script will do
automatically redirect the log files to that repository server.
(vii) Sometimes we will delete file contents not the files to reduce the file sizes. For that we execute
the command # cat /dev/null ><file name with path> ie., nullifying the files.
(ix) If it is root file system or O/S file system,
(a) may be /opt full or may be /var full or may be /tmp full
(b) In /var/log/secure or /var/log/system or /var/tmp files may be full. If those files are
important then redirect them to other central repository server or backup those files and
nullifying those files.
(c) If /home directory is present in root ( / ) file system then this file system full will
occur. Generally /home will be separated from root file system and created as separate /home file
system. If /home is in root ( / ) as a directory then create a separate file system for
/home and copy those files and directories belongs to /home and remove that /home
directory.
(d) If root ( / ) is full then cannot login to the system. So, boot with net or CDROM in single
user mode and do the above said.
(x) Normally if file system is other than O/S then we will inform to that respective manager or owner
and take the permissions to remove unnecessary files through verbal permission or CRQ .
23. CPU utilization full, how to troubleshoot it?
(a) Normally we get these scenarios on weekends because backup team will take heavy backups.
(b) First check which processes are using more CPU utilization by # top and take a snap shot of that
user processes and send the snap shot and inform to that user to kill the unnecessary
process.
(c) If those processes are backups then inform to the backup team to reduce the backups by stopping
some backups to reduce the CPU utilization.
(d) Sometimes in peak stages (peak hours means having business hours) CPU utilization will full and
get back to the normal position automatically after some time (within seconds). But ticket
raised by monitoring team. So, we have to take a snap shot of that peak stage and attach that
snap shot to the raised ticket and close that ticket.
(e) Sometimes if heavy applications are running and not to kill (ie., business applications), then if any
spare processor is available or other low load CPUs available then move those heavy
application processes to those CPUs.
(d) If CPUs are also not available then if the system supports another CPU then inform to the data
centre people or CPU vendor to purchase new CPU though Business approval and move some
processes to the newly purchased CPUs.
24. How to troubleshoot when the system is slow?
(a) System slow means the end users response is slow.
(b) Check the Application file system, CPU utilization, memory utilization and O/S file system
utilization.
(c) If all are ok, then check network statistics and interfaces whether the interfaces are running in full
duplex mode or half duplex mode and check whether the packets are missing. If all are ok from our
side then,
(d) Inform to network team and other respective teams to solve this issue.
25. How to troubleshoot if the node is down?
(a) Check pinging the system. If pinging, then check whether the system is in single user mode or
not.
(b) If the system is in single user mode then put the system in multi user mode ie., default run
level by confirming with our team whether system is under maintenance or not.
(c) Check in which run level the system is running. If it is in init 1 it will not be able to ping. If it is
in init s then it will ping.
(d) In this situation also if it is not pinging then try to login through console port. If not possible
then inform to data centres people to hard boot the system.
(d) If connected through console port then we may get the console prompt.
26. How to troubleshoot if the memory utilization full?
(a) Check how much memory is installed in the system by # dmidecode -t memory
command.
(b) Check the memory utilization by # vmstat -v command.
(c) Normally application or heavy backups utilize more memory. So, inform to application team
or backup team or other teams which team is utilizing the more memory to reduce the processes by
killing them or pause them.
(d) Try to kill or disable or stop the unnecessary services.
(e) If all the ways are not possible then inform to team lead or tech lead or manager to
increase the memory (swap space). If it is also not possible then taking higher authority's
permissions to increase the physical memory. For those we contact the server vendor
and co-ordinate with them through data centre people to increase the RAM size.
27. How to replace the failed hard disk?
(a) Check whether the disk is failed or not by # iostat -En | grep -i hard/soft command.
(b) If hard errors are above 20 then we will go for replacement of the disk.
(c) If the disk is from SAN people then we will inform to them about the replacement of the disk.
If it is internal disk then we raise the CRQ to replace the disk.
(d) For this we will considered two things.
(i) whether the system is within the warranty.
(ii) without warranty.
(e) We will directly call to the toll free no. of the system vendor and raise the ticket. They will
issue the case no. This is the no. we have to mention in all correspondences to vendor
regarding this issue.
(f) If it is having warranty they asks rack no. system no. and other details and replace the hard
disk with co- ordinate of the data centre people.
(g) If it is not having warranty, we have to solve the problem by our own or re-agreement to
extend the warranty and solve that problem.
28. How to replace the processor?
(a) Check the processor's status using # lscpu or # dmidecode -t processor commands.
(b) If it shows any errors then we have to replace the processor.
(c) Then raise the case to vendor by toll free no. with higher authorities permission.
(d) The vendor will give case no. for future references.
(e) They also asks rack no. system no. of the data centre for processor replacement.
(f) We will inform to the Data centre people to co-ordinate with vendor.
29. How replace the failed memory modules?
Causes :
(a) The system is continuously rebooting .
(b) When in peak business hours, if the heavy applications are running the system get panic
and rebooted. This is repeating regularly.
Solution :
(a) First we check how much RAM present in the system with # dmidecode -t memory
command.
(b) Then we raise the case to vendor with the help of higher authorities.
(c) Then the vendors will provide the case no. for future reference.
(d) They will also asks rack no. system no. to replace the memory.
(e) we will inform the data centre people to co-ordinate with the vendor.
30. What is your role in DB patching?
In Database patching the following teams will be involved.
(i) Database Administrator (DBA) team.
(ii) Linux Administrators team.
(iii) Monitoring team.
(iv) Application team.
(i) DBA team :
This is the team to apply the patches to the databases.
(ii) Linux team :
This team is also involved if any problems occur. If the database volume is having a mirror we
should first break the mirror and then the DBA people will apply the patches. After 1 or 2 days
there is no problem again we need sync the data between mirrored volume to patch applied
volume. If there is no space for patch we have to provide space to DBA team.
(iii) Monitoring team :
This team should receive requests or suggestions to ignore any problems occurs. After
applied the patch if the system is automatically rebooted then monitoring team will raise the
ticket "Node down" to system administrators team. So, to avoid those type of tickets we
have to sent requests to ignore those type alerts.
(iv) Application team :
For applying any patches, the databases should not be available to application. So, if
suddenly database is not available then application may be crashed. So, first the application
should be stopped. This will be done by application team.
31. What is SLA?
A service-level agreement (SLA) is simply a document describing the level of service expected by a
customer from a supplier, laying out the metrics by which that service is measured and the remedies
or penalties, if any, should the agreed-upon levels not be achieved. Usually, SLAs are between
companies and external suppliers, but they may also be between two departments within a company .
32. What is Problem Management?
The objective of Problem Management is to minimize the impact of problems on the organisation.
Problem Management plays an important role in the detection and providing solutions to problems
(work around& known errors) and prevents their reoccurrence.
A 'Problem' is the unknown cause of one or more incidents, often identified as a result of multiple
similar
It acts as an interpreter between Linux OS and its hardware. It is the fundamental component of Linux
OS and contains hardware drivers for the devices installed on the system. The kernel is a part of the system
which loads first and it stays on the memory.
41. What are the main parameters effect on server performance?
The one of the most important task of any Linux Admin includes performance monitoring which
includes a parameter "Load Average" or "CPU Load".
42. What is load average?
Load Average is the value which represents the load on your system for a specific period of time. Also
it can be considered the ratio of the number of active tasks to the number of available CPUs.
43. How to check?
We can use either top or uptime command to view the output of the load average as shown below.
# uptime
00:07:00 up 4 days, 6:14, 1 user, load average: 0.11, 0.14, 0.09
# top
top - 00:07:12 up 4 days, 6:15, 1 user, load average: 0.09, 0.13, 0.09
44. What are the three values?
As you can see three values representing the load average column. These show the load on your
system over a significant period of time (one or current, five and fifteen minutes averages).
45. How do you know your system has a high load?
The most important question as in most cases I have seen how do you determine your system has
high load.
Does a high value represents high load average and that your system requires attention?
What is the threshold value for load average?
How can we conclude if the load average value is good or bad?
A Central Processing Unit in earlier days used to be having only one processor and the core concept
was not their in those days. But with the advancement in technology and the urge of higher speed to meet up
demands of IT industry multiple processor were integrated in the same CPU making it multi-processor.
However increasing the no. of processor did increased the working speed of many tasks and
performance but it also leads to increase in size, complexity and heat issues. So, in order to continue
improvement of performance the core concept was introduced.
Instead of having two CPUs and a motherboard capable of hosting them, two CPUS are taken together
and combined to form a dual core processor which will utilize an individual socket using less power and
size capable of performing the same amount of task as dual processor CPU.
Bottom Line is that Load value depends on the no. of cores in your machine. For example a dual core
is relevant to 2 processor or 2 cores and quad core is relevant to 4 processor or four cores as the
maximum value for load.
46. How do I check the no. of cores on my Linux system?
The information which you see under /proc/cpuinfo can be confusing at times. If you run the below
command
# less /proc/cpuinfo | grep processor
processor :0
processor :1
processor :2
processor :3
processor :4
processor :5
So as per the above command my system has 16 processors in it. However it really has 8 processors
with hyper threading enabled. The hyper threading presents 2 logical CPUs to the operating system for
each actual core so it effectively doubles the no. of logical CPU in your system.
47. How to find if hyper threading is enabled
Look out for "ht" in the flags section inside cpuinfo with the below command
# less /proc/cpuinfo | grep flags | uniq | grep -i "ht"
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts
acpi mmx fxsr sse sse2 ss ht tm syscall nx rdtscp lm constant_tsc nonstop_tsc pni monitor
ds_cpl vmx est tm2 ssse3 cx16 xtpr sse4_1 sse4_2 popcnt lahf_lm.
The fields we need to compare to find the no. of core are "physical id" and "core id". Run the below
command
# less /proc/cpuinfo | grep "physical id" | sort|uniq | wc -l
2
# less /proc/cpuinfo | grep "core id" | sort|uniq | wc -l
4
So the no. of cores would be 2x4 = 8 cores.
48. What do you understand the Load Average?
If the number of active tasks utilizing CPU is less as compared to available CPU cores then the load
average can be considered normal but if the no. of active tasks starts increasing with respect to available
CPU cores then the load average will start rising.For example,
# uptime
00:43:58 up 212 days, 14:19, 4 users, load average: 6.07, 7.08, 8.07
49. How to check all the current running services in Linux?
To find the status of any single service :
# service vsftpd status
vsftpd (pid 5909) is running...
To get the status of all the running services :
# service --status-all | grep running
acpid (pid 5310) is running...
atd (pid 6528) is running...
auditd (pid 5012) is running...
Avahi daemon is not running
Avahi DNS daemon is not running
The Pegasus CIM Listener is running.
The Pegasus CIM Object Manager is running.
crond (pid 6242) is running...
dcerpcd (pid 5177) is running...
eventlogd (pid 5223) is running...
In case you don't use grep you will be able to see all the services on your machine :
# service --status-all
NetworkManager is stopped
acpid (pid 5310) is running...
anacron is stopped
atd (pid 6528) is running...
auditd (pid 5012) is running...
automount is stopped
Avahi daemon is not running
Avahi DNS daemon is not running
hcid is stopped
sdpd is stopped
You can also check the active ports along with their services using :
# netstat -ntlp
Active Internet connections (only servers)
Protocol Recv-Q Send-Q Local Address Foreign Address State
PID/Program name
tcp 0 0 0.0.0.0:52961 0.0.0.0:*
LISTEN 5223/eventlogd
tcp 0 0 0.0.0.0:5988 0.0.0.0:*
LISTEN 6116/cimserver
tcp 0 0 0.0.0.0:5989 0.0.0.0:*
LISTEN 6116/cimserver
tcp 0 0 0.0.0.0:678 0.0.0.0:*
LISTEN 5160/rpc.statd
tcp 0 0 0.0.0.0:14247 0.0.0.0:*
LISTEN 6460/java
tcp 0 0 127.0.0.1:199 0.0.0.0:*
LISTEN 5857/snmpd
tcp 0 0 0.0.0.0:135 0.0.0.0:*
LISTEN 5177/dcerpcd
50. How do you check Linux machine is Physical or Virtual remotely?
There is no hard and fast rule to check whether the machine is physical or virtual but still we do have
some commands which can be used for the same purpose.
The command used to view all the required hardware related information for any Linux machine is
# dmidecode
But the output would be very long and hard to find out the specific details looking for. So, let's narrow
it down.
Physical Servers:
# dmidecode -s system-product-name
System x3550 M2 -[7284AC1]-
Now to get more details about the system
# dmidecode | less (And search for "System Information")
System Information
Manufacturer: IBM
Product Name: System x3550 M2 -[7284AC1]-
Version: 00
Wake-up Type: Other
SKU Number: XxXxXxX
Family: System x
Virtual Servers :
# dmidecode -s system-product-name
VMware Virtual Platform
# dmidecode | less
System Information
Manufacturer: VMware, Inc.
Product Name: VMware Virtual Platform
Version: None
Wake-up Type: Power Switch
SKU Number: Not Specified
Family: Not Specified
On a virtual server running VMware you can run the below command to verify :
# lspci | grep -i vmware
00:0f.0 VGA compatible controller: VMware SVGA II Adapter
51. How to find the bit size of your linux machine?
# uname -m
i686
# uname -m
x86_64
If we get i386, i586 and i686 that signifies your machine is 32-bit but if we
getx86_64 or ia64 then your machine will be 64-bit.
# getconf LONG_BIT
32
# getconf LONG_BIT
64 (Here we get an output of bit size either 32 or 64)
52. How can you add a banner or login message in Linux?
By editing these two files
/etc/issue
/etc/motd
53. What is the difference between normal kernel and kernel-PAE?
kernel in 32 bit machine supports max of 4 GB RAM, whereas
kernel PAE in 32 bit linux machine supports till 64 GB RAM
54. Tell me the command to find all the commands in your linux machine having only 2 words like ls,
cp, cd etc.
# find /bin /sbin/usr/bin /usr/sbin -name ?? -type f
55. Which file is generally used to configure kickstart?
anaconda.cfg
56. Which log file will you check for all authentication related messages?
/var/log/secure
57. What is the command used to find the process responsible for a particular running file?
# fuser filename
# lsof filename
58. What is the command to take remote of any Linux machine?
# rdesktop
59. What are the three values shown in load average section of top command?
It shows the current, 5 min back and 15 min back load average value.
60. How to check all the process running by a particular user?
# ps -u<username>
61. What is an orphan process?
An orphan process is a process that is still executing, but whose parent has died.
62. What is a defunct process?
These are also termed as zombie process. These are those process who have completed their
execution but still has an entry in the process table. When a process ends, all of the memory and
resources associated with it are de-allocated so they can be used by other processes.After the zombie is
removed, its process identifier (PID) and entry in the process table can then be reused.
Zombies can be identified in the output from the Unix ps command by the presence of a "Z" in the
"STAT" column
63. How do you limit maximum connections in your apache server?
Change the below parameter value inside httpd.conf
MaxClients 256
64. Which command do you use to download a file from ftp or http website using CLI?
# wget path_to_the_file
65. What is the default port for ssh? How will you change it to some other random port no.?
SSH port no. by default is 22. To change the default port no. we need make required changes inside
sshd_config file in the below mentioned line
#Port 22 (Uncomment the above line and define the new port no)
Restart the services for changes to take effect.
66. What is the difference between A record and CNAME record in DNS?
A record :
It is the Address records also known as host records
Points to the IP address reflecting the domain
Used for forward lookup of any domain name
For example:
Our website is configured on 50.63.202.15 IP so the A record of my domain name will point towards
that IP.
Every time a query for golinuxhub.com is made the internet will lookup for contents stored on the
machine with 50.63.202.15 this IP.
CNAME Record :
It is short abbreviation for Canonical Name
Provides an alias name for same hostname
Helps create subdomains
NOTE: You cannot create a CNAME record for the domain name itself (it should be done with A
record)
For example:
golinuxhub.com is a domain name whereas www.golinuxhub.com is a sub domain name.
boot : linux ip=< IP address to the client> netmask=<netmask of that IP> ks=ftp://< IP
address of the kickstart server>/<kickstart file name with full path>
(press Enter key)
* Then the installation will continue by taking the installation information from the kickstart
file.
5. In how many ways can we install RedHat Linux through network?
(i) FTP
(ii) NFS
(iii) HTTP
(iv) PXE
6. How to install RedHat Linux though FTP?
(i) First configure the FTP server and copy the entire RedHat Linux DVD in that FTP document
root directory.
(ii) Installation of Linux through network requires one boot.iso image or RHEL DVD.
To make a DVD/Pendrive bootable using boot.iso image :
(a) Download the boot.iso image from redhat website.
# cdrecord /root/boot.iso (/root/boot.iso is the path of
boot.iso image)
(b) Copy the boot.iso image into DVD or pendrive.
# dd if=/root/boot.iso of=/dev/sdb1 (/dev/sdb1 is the address of the USB
or pendrive)
(iii) Boot the system with the above created boot.iso image and press Esc key to get the boot :
prompt.
(iv) Then execute the below command to install the O/S.
boot : linux askmethod (Press Enter key)
(v) Select the preferred language for installation (for example English).
(vi) Select the Keyboard layout as US.
(vii) Select the urloption for the installation media (for example FTP/NFS/HTTP).
(viii) Select IPv4 or IPv6 to define network settings and select dynamic or static options.
(ix) Assign the same range IP address and netmask to the client system to communicate with
server.
(x) Then specify the FTP server IP address and path of the installation media to install the
O/S.
7. How to install RedHat Linux through NFS?
(i) Make an entry in /etc/exports to export the RHEL media.
# vim /etc/exports
<installation media directory> <network ID>(rw, sync)
(save and exit this file)
Example :
/var/ftp/pub/rhel6 172.25.9.0(rw, sync) (If the installation media is in
/var/ftp/pub/rhel6)
(ii) Export the above NFS shared directory by # exportfs -rv command.
(iii) Then restart the NFS service by # service restart nfs command and add the NFS to IPtables
or firewall.
(iv) Installation of Linux through network requires one boot.iso image or RHEL DVD.
To make a DVD/Pendrive bootable using boot.iso image :
(a) Download the boot.iso image from redhat website.
# cdrecord /root/boot.iso (/root/boot.iso is the path of
boot.iso image)
(b) Copy the boot.iso image into DVD or pendrive.
# dd if=/root/boot.iso of=/dev/sdb1 (/dev/sdb1 is the address of the USB
or pendrive)
(v) Boot the system with the above created boot.iso image and press Esc key to get the boot :
prompt.
(vi) Then execute the below command to install the O/S.
boot : linux askmethod (Press Enter key)
(vii) Select the preferred language for installation (for example English).
# chkconfig dhcpd on
# iptables -A INPUT -m state --state NEW -m tcp -p tcp --deport 67 -j ACCEPT
# iptables -A OUTPUT -m state --state NEW -m tcp -p tcp --deport 68 -j
ACCEPT
# iptables -A INPUT -m state --state NEW -m tcp -p tcp --deport 67 -j ACCEPT
# iptables -A OUTPUT -m state --state NEW -m tcp -p tcp --deport 68 -j
ACCEPT
(h) Configure the TFTP server.
# yum install tftp* syslinux* -y
# vim /etc/xinetd.d/tft
* Go to disable=yes line and make it as no (save and
exit this file)
# cp -rvpf /media/RHEL6/isolinux/*.* /var/lib/tftpboot
# mkdir /var/lib/tftpboot/pxelinux.cfg
# cp /var/lib/tftpboot/isolinux.cfg /var/lib/ftfpboot/pxelinux.cfg/default
# cp -rvpf /usr/share/syslinux/pxelinux.0 /var/lib/tftpboot
# service xinetd restart
# chkconfig xinetd on
# iptables -A INPUT -m state --state NEW -m tcp -p tcp --deport 69 -j ACCEPT
# iptables -A OUTPUT -m state --state NEW -m tcp -p tcp --deport 69 -j
ACCEPT
(i) Create the kickstart file
# yum install system-config-kickstart -y
# system-config-kickstart (create a kickstart file and save it in /var/ftp/pub
directory)
# ksvalidator /var/ftp/pub/ks.cfg
(j) Specify the kickstart file location in pxelinux.cfg file.
# vim /var/lib/tftpboot/pxelinux.cfg/default
* Go to line 19 and edit the lines as below.
menu label ^ PXE SERVER
menu default
kernel vmlinuz
append initrd=initrd.img linux ks=ftp://172.25.9.11/pub/ks.cfg (save and
exit this file)
(k) Restart all the services once again.
# service network restart
# chkconfig network on
# service vsftpd restart
# chkconfig vsftpd on
# service dhcpd restart
# chkconfig dhcpd on
# service xinetd restart
# chkconfig xinetd on
(i) Bring the disk from O/S to Veritas Volume Manager control using the Veritas Advanced
Management tool, # vxdiskadm command (It gives (displays) options for easy
administration of Veritas Volume Manager).
(ii) Select 2nd option ie., Encapsulation because to preserve the existing data present in the
disk and reboot the system to effect Encapsulation and modify the /etc/sysconfig file. While
Encapsulating, it asks disk name and disk group (root disk name and rootdg).
(iii) Backup the / (root), /etc/sysconfig directories.
(iv) Take another disk and initialize it by # vxdisksetup -i <mirrored root disk name> command.
(v) Add the above initialized disk to the volume group ie., roodg by
# vxdg -g <rootdg> adddisk mirrordisk=<mirrored root disk name>
(vi) vxmirror -v -g <rootdg><original disk name><mirrored root disk name> (disk level
mirroring)
(vii) For individual mirroring, # vxassist -g <rootdg> mirror <volume name> or
# vxrootmirr -g <rootdg><volume name> command.
(i) Switchover is the manual task. (i) But, Failover is a automatic task.
(ii) We can switchover service groups from online (ii) But, the failover will failover the service group to
cluster node to offline cluster node incase of the other node when Veritas Cluster heartbeat
power outage, hardware failure, schedule linkdown, damaged, broken because of some
shutdown and reboot. disaster or system hung.
7. Which the main configuration file for VCS (Veritas Cluster) and where it is stored?
' main.cf ' is the main configuration file for VCS and it is located in /etc/VRTSvcs/conf/config
directory.
8. What is the public region and private region?
when we bring the disk from O/S control to Volume Manager control in any format (either CDS,
simple or sliced), the disk is logically divided into two parts.
(a) Private region :
It contains Veritas configuration information like disk type and name, disk group name,
groupid and configdb. The default size is 2048 KB.
(b) Public region :
It contains the actual user's data like applications, databases and others.
9. There are five disks on VxVM (Veritas Volume Manager) and all are failed. What are the steps
you follow to get those disks into online?
(i) Check the list of disks in Volume manager control by # vxdisk list command.
(ii) If the above disks are not present, then bring them O/S control to VxVM control by
# vxdisksetup -i <disk names> (if data is not on those disk) or execute
# vxdiskadm command and select 2nd option ie., encapsulation method if the disks
having the data.
(iii) Even though If it is not possible, then check the disks are available at O/S level by # fdisk
-l command.
(a) If the disks are available, execute the above command once again.
(b) If the disks are not available then recognize them by scanning the hardware.
(iv) Even though if it is not possible, then reboot the system and follow the steps (i) and (ii).
10. What is the basic difference between private disk group and shared disk group?
Private disk group :
The disk group is only visible for the host on which we have created it. If the host is a part of the
cluster, the private disk group will not be visible to the other cluster nodes.
18. Define LLT and GAB. What are the commands to create them?
LLT :
(i) LLT means Low Latency Transport protocol
(ii) It monitor the kernel to kernel communication.
(iii) It maintain and distribute the network traffic within the cluster.
(iv) It uses heartbeat between the interfaces.
GAB :
(i) GAB means Global Atomic Broadcasting.
(ii) It maintain and distribute the configuration information of the cluster.
(iii) It uses heartbeat between the disks.
Commands :
# gabconfig -a (to check the status of the GAB, ie., GAB
is running or not)
If port ' a ' is listening, means GAB is running, otherwise GAB is not running.
If port ' b ' is listening, means I/O fencing is enabled, otherwise I/O fencing is
disabled.
If port ' h ' is listening means had deamon is working, otherwise had deamon is
not working.
# gabconfig -c n 2 (to start the GAB in 2 systems in the cluster,
where 2 is seed no.)
# gabconfig -u (to stop the GAB)
# cat /etc/gabtab (to see the GAB configuration information and
the it contains as, )
gabconfig -c n x (where x is a no. ie., 1, 2, 3, ....etc.,)
# lltconfig -a (to see the status of the llt)
# lltconfig -c (to start the llt)
# lltconfig -u (to stop the llt)
# lltstat -nvv (to see the traffic status between the interfaces)
# llttab -a (to see the cluster ID)
# haclus -display (to see all the information on the cluster)
# cat /etc/llttab (to see the llt configuration and the entries are as,)
Cluster ID, host ID, interface MAC address, ...etc.,
# cat /etc/llthosts (to see the no. of nodes present in the cluster)
19. How to check the status of the Veritas Cluster?
# hastatus -summary
20. Which command is used to check the syntax of the main.cf?
# hacf -verify /etc/VRTSvcs/conf/config
21. How will you check the status of the individual resources of Veritas Cluster (VCS)?
# hares -state <resource name>
22. What is the use of # hagrp command?
# hagrp command is used doing administrative actions on service groups like, on-line service group,
off-line service group and switch, ...etc.,
23. How to switch over the service group?
# hagrp -switch <System A><System B>
24. How to online the service group in VCS?
# hagrp -online <service group name> -sys <System A>
25. What are the steps to follow for switch over the application from System A to System B?
(i) First unmount the file system on System A.
(ii) Stop the volume on System A.
(iii) Deport the disk group from System A.
(iv) Import the disk group to another System B.
(v) Start the volume on System B.
(vi) Finally mount the file system on System B.
26. How many types of clusters available?
(i) Hybrid Cluster.
(ii) Parallel Cluster.
(iii) Failover Cluster.
27. What is meant by seeding?
Normally, we will define how many nodes to start in a cluster while booting or explicitly by
executing
# gabconfig -c n 2 command. Here 2 means 2 seeds to start in a cluster. This no. is called
seeding.
28. What is Split brain issue in VCS and how to resolve this?
A Split brain issue means, multiple systems use the same exclusive resources and usually resulting in
data corruption.
Normally VCS is configured with multiple nodes and are communicates with each other. When
power loss or system crashed, the VCS assumes the system has failed and trying to move service group to
other system to maintain high availability. However communication (heartbeat) can also failed due to
network failures.
If network traffic (connection) between any two groups of systems fail simultaneously, a network
partition occurs. When this happen, systems on both sides of the partition can restart the applications
from the other side, ie., resulting in duplicate services. So, the most serious problem caused by this and
effects the data on shared disks.
This split brain issue normally occurs in VCS 3.5 to VCS 4.0 versions. But, from VCS 5.0 onwards the
I/O fencing (new feature) is introduced to minimize the split brain issue. If I/O fencing is enabled in a
cluster, then we can avoid the split brain issue.
29. What is Admin wait and Stale Admin wait?
ADMIN-WAIT :
If VCS is started on system with a valid configuration file and other systems are in the ADMIN-WAIT
state, The new system transition to the ADMIN-WAIT state (or)
If VCS is started on system with a stale configuration file and if other systems are in the ADMIN-
WAIT state, the new system transition to the ADMIN-WAIT state.
STALE-ADMIN-WAIT :
The configuration files are in read-only mode. If any changes wants to make that file as read-write
mode. If any changes occurs in ' main.cf ' file in cluster, then the changes are in ' .stale ' hidden file
under configuration directory. While changes occurring, if the system restarted or rebooted, then the
cluster will start with ' .stale ' file. So, the VCS is started on a system with a stale configuration file, the
system status will be STALE- ADMIN-WAIT until another system in the cluster starts with a valid
configuration file or otherwise execute
# hasys -stale -force <system name> (or) # hasys -force <system name> to start the
system forcefully with the correct or valid configuration file.
30. What is meant by resource and how many types?
Resource is a software or hardware component managed by the VCS.
Mount points, disk groups, volumes, IP addresses, ....etc., are the Software components.
Disks, Interfaces (NIC cards), ....etc., are the Hardware components.
There are two types of resources and they are,
(i) Persistent Resources (we can put them either on-line or off-line)
(ii) Non-Persistent Resources (we can put off-line only)
If the resource is in faulted state, then clear the service group state. Resources cab be critical or
non-critical. If the resource is critical, then it automatically failover if the resource is failed. If the
resource is Non-critical, then it switch over and we have to manually switch over the resource group to
another available system.
31. What are the dependencies between resources in a Cluster?
If one resource depends on other resource, then there is a dependency between those resources.
Example : NIC (Network Interface Card) is hardware component nothing but hardware resource.
The IP address is a software component nothing but software resource and it depends on NIC card. The
relationship between NIC and IP address is Parent - Child relationship. The resource which one is
starts first, that one is called Parentresource and the remaining dependency resources are called Child
resource.
32. What are the minimum requirements for or in VCS?
(i) Minimum two identical (same configuration) systems.
(ii) Two switches (Optical Fibre Channel).
(iii) Minimum three NIC cards. (Two NICs for private network and one NIC for public network).
(iv) One common storage.
(v) Veritas Volume Manager with license.
(v) If critical resource is failed, then only the service group moved automatically from one
system to another system. ie., failover, otherwise if non-critical resource is failed, then we
need to the manual movement of service group from one system to another system. ie., switchover.
46. What are the steps you follow to put the volume in a Cluster?
(i) First create the diskgroup, volume and create the file system and mount and unmount
before put the volume in a cluster because testing of that volume is working or not.
(ii) Create the service group and add the Attributes to it.
# hagrp -add <service group>
Example: # hagrp -add appssg
Attributes :
# hagrp -modify appssg system list={ sys A0, sys B0} (to add sys A and sys B attributes to
service group)
# hagrp -modify appssg autostart list={ sys A} (to start the sys A attributes
automatically)
# hagrp -modify appssg enabled 1 or 0 (1 means start and 0 means not to start
automatically)
(iii) Creating resources and adding them to the service group and specify their attributes.
For file system :
(a) /mnt/apps (the mount point)
(b) /appsvol (the volume name)
(c) /appsdg (the disk group)
# hares -add dg-apps diskgroup appssg (to add the diskgroup resource
to a service group)
(where dg-apps is resource name, diskgroup is a keyword and appssg is a service
group name)
# hares -modify dg-apps diskgroup appsdg (to add the diskgroup attribute to a
service group)
# hares -modify dg-apps enable 1 (to enable the resource)
# hares -add dg-volume volume appssg (to add the volume resource
to a service group)
# hares -modify dg-volume volume appsvol (to add the volume attribute to a
service group)
# hares -modify dg-volume diskgroup appsdg (to add the diskgroup to the volume)
# hares -modify dg-volume enable 1 (to enable the volume resource)
# hares -modify dg-volume critical 1 (to make the resource as critical)
# hares -add dg-mnt mount appssg (to add the mount point resource to a
service group)
# hares -modify dg-mnt blockdevice=/dev/vx/rdsk/appsdg/appsvol (to add the block
device resource
to a service group)
# hares -modify dg-mnt fstype=vxfs (to add the mount point attributes to a
service group)
# hares -modify dg-mnt mount=/mnt/apps (to add the mount point
directory attribute to a
service group)
# hares -modify dg-mnt fsckopt=% y or %n (to add the fsck attribute either yes or
no to
service group)
(iv) Create links between the above diskgroup, volume and mount point resources.
# hares -link parent-res child-res
# hares -link dg-appdg dg-volume
# hares -link dg-volume dg-mnt
47. What is meant by freezing and unfreezing a service group with persistent and evacuate options?
Freezing :
If we want to apply patches to the system in a cluster, then we have to freeze the service group
because first stop the service group, if it is critical, the service group will move automatically to another
system in Cluster. So, we don't want to move the service group from one system to another system,
we have to freeze the service group.
Unfreeze :
After completing the task, the service group should be unfreezed because, if the is crashed or down
and the resources are critical, then the service group cannot move from system 1 to system 2 due to
freezed the service group and results in not available of application. If unfreezed the service group after
maintenance, the service group can move from system 1 to system 2. So, if system 1 failed, the
system2 is available and application also available.
Persistent option :
If the service group is freezed with persistent option, then we can stop or down or restart the
system. So, there is no loss of data and after restarted the system, the service group is remains in
freezed state only.
Example : # hasys -freeze -persistent <system name>
# hasys -unfreeze -persistent <system name>
Evacuate :
If this option is used in freezed service group system, if the system down or restarted the persisted
information is evacuated, ie., before freeze all the service groups should be moved from system 1
to another system 2.
48. What are the layouts are available in VxVM and how they will work and how to configure?
(i) There are 5 layouts available in VxVM. They are RAID-0, RAID-1, RAID-5, RAID-0+1 and
RAID-1+0.
RAID-0 :
We can configure RAID-0 in two ways.
(a) Stripped (default).
(b) Concatenation.
Stripped :
(i) In this minimum two disks required to configure.
(ii) In this the data will write on both the disks parallelly. ie., one line in one disk and 2nd line on
2nd disk, ...etc.,
(iii) In this the data writing speed is fast.
(iv) In this there is no redundancy for data.
Concatenation :
(i) In this minimum one disk is required to configure.
(ii) In this the data will write in first disk and after filling of first disk then it will write on 2nd disk.
(iii) In this the data writing speed is less.
(iv) In this also there is no redundancy for data.
RAID-1 :
(I) It is nothing but mirroring.
(ii) In this minimum 4 disks are required to configure.
(iii) In this same data will be written on disk1 and disk 3, disk 2 and disk4.
(iv) If disk 1 failed, then we can recover the data from disk3 and if disk 2 failed, then we can
recover the data from disk 4. So, there is no data loss or we can minimize the data loss.
(v) In this half of the disk space may be wasted.
RAID-5 :
(i) It is nothing but stripped with distributed parity.
(ii) In this minimum 3 disks required to configure.
(iii) In this one line will write on disk 1 and 2nd line write on disk 2 and the parity bit will write
on disk3. The parity bit will write on 3 disk simultaneously. If disk 1 failed then we can recover the
data from disk2 and parity bit from disk 3. So, in this data will be more secured.
(iv) In this disk utilization is more when compared to RAID-1, ie., 1/3 rd of disk space may be
wasted.
(v) This RAID-5 will be configured for critical applications like Banking, Financial, SAX and
Insurance...etc., because the data must be more secured.
Creating a volume with layout :
# vxassist -g <diskgroup name> make <volume name><size in GB/TB> layout=<mirror/raid
5/raid 1>
Example : # vxassist -g appsdg make appsvol 50GB layout=raid 5 (the default is RAID-5
in VxVM)
Logs :
* If the layout is mirror, then log is DRL.
* If the layout is RAID-5, then the log is RAID-5 log.
* The main purpose of the log is fast recovery operation.
* We have to specify whether the log is required or not in all types of layouts except RAID-5
because the logging is default in RAID-5.
* If we want to configure RAID-5 without logging then,
# vxassist -g <diskgroup name> make <volume name> 50GB, nolog layout=raid 5
* If the layout is other than RAID-5 then,
# vxassist -g <diskgroup name> make <volume name> 50GB, log layout=mirror
* If we want to add the log to the existing volume then,
# vxassist -g <diskgroup name> addlog logtype=drl or raid5
* If we want to remove the log from the existing volume then,
# vxassist -g <diskgroup name> rmlog <volume name>
49. What is read policy and how many types of read policies available?
Read policy means, how the disk or volume should be read when accessing the data.
Types of read policies :
(i) Select
(ii) Prefer
(iii) Round Robin
* By default the read policy is Round Robin.
# vxvol -g <diskgroup name> rdpol = < select/prefer/roundrobin <volume name>
50. What is your role in VxVM?
Normally, we get requests from application, development, production and QA people like,
(i) Create a volume.
(ii) Increase the volume.
(iii) Decrease the volume.
(iv) Provide Redundancy by implementing RAID-1 or RAID-5.
(v) Provide the required permissions.
(vi) Put the volume in the Virtual machine.
(vii) Put the volume in the Cluster.
(viii) Provide high availability to the applications and databases.
(ix) Sometimes destroy or remove the volume.
(x) Backup and restore the data whenever necessary.
And sometimes we get some troubleshooting issues like,
(i) Volume is not started.
(ii) Volume is not accessible.
(iii) Mount point deleted.
(iv) File system crashed.
(v) One disk failed in a volume.
(vi) Volume manager deamons are not running.
(vii) Volume manager configuration files missed or deleted.
(viii) VxVM licensing issues.
(ix) Diskgroup not deporting and not importing.
(x) Volume is started, deamons are running but users cannot accessing the data.
(xi) Disk are not ditected.
(xii) Hardware and software errors.
51. What is meant by snap backup and how to take the snap backup?
(i) Snap backup means, taking backup using snapshots.
(ii) In 24X7/365 days running servers normally we take snap backup.ie., no downtime allowed.
(iii) The above said servers are called BCV (Business Continuity Volumes).
Backup :
(i) First stop the Application.
(ii) Stop the Database.
License :
(i) All the licenses are stored in /etc/vx/licenses directory and we can take backup of this
directory and restore it back, if we need reinstall the server.
(ii) Removing VxVM package will not remove the installed license.
(iii) To install license # vxlicinst command is used.
(iv) To see the VxVM license information by # vxlicrep command.
(v) To remove the VxVM license by # vxkeyless set NONE command.
(vi)The license packages are installed in /opt/VRTSvlic/bin/vxlicrep directory.
(vii) The license keys are stored in /etc/vx/licenses/lic directory.
(viii) We can see the licenses by executing the below commands,
# cat /etc/vx/licenses/lic/key or
# cat /opt/VRTSvlic/bin/vxlicrep | grep "License key"
(ix) To see the features of license key by # vxdctl license command.
Version :
(i) We are using VxVM6.2 version.
(ii) to know the version of VxVM by # rpm -qa VRTSvxvm command.
54. What are the available formats to take the control of disks from O/S to veritas in VxVM?
We can take the control of disks from O/S to veritas in 3 formats.
(i) CDS (Cross platform Data Sharing and the default format in VxVM).
(ii) Sliced.
(iii) Simple.
(i) CDS :
8. What is the order in which you will start the Red Hat Cluster services?
In Red Hat 4 :
# service ccsd start
# service cman start
# service fenced start
service clvmd start (If CLVM has been used to create clustered volumes)
# service gfs start
# service rgmanager start
In RedHat 5 :
# service cman start
# service clvmd start
# service gfs start
# service rgmanager start
In Red Hat 6 :
# service cman start
# service clvmd start
# service gfs2 start
# service rgmanager start
9. What is the order to stop the Red Hat Cluster services?
In Red Hat 4 :
# service rgmanager stop
# service gfs stop
# service clvmd stop
# service fenced stop
# service cmanstop
# service ccsd stop
In Red Hat 5 :
# service rgmanager stop
# servicegfsstop
# service clvmd stop
# servicecman stop
In Red Hat 6 :
# service rgmanagerstop
# service gfs2 stop
# service clvmdstop
# service cman stop
10. What are the performance enhancements in GFS2 as compared to GFS?
Better performance for heavy usage in a single directory
Faster synchronous I/O operations
Faster cached reads (no locking overhead)
Faster direct I/O with preallocated files (provided I/O size is reasonably large, such as 4M blocks)
Faster I/O operations in general
Faster Execution of the df command, because of faster statfs calls
Improved atime mode to reduce the number of write I/O operations generated by atime when compared with
GFS
GFS2 supports the following features.
Conga is an integrated set of software components that provides centralized configuration and management
of Red Hat clusters and storage
luci is a server that runs on one computer and communicates with multiple clusters and computers via ricci
CMAN has no internal tie-breakers for various reasons. However, tie-breakers can be implemented using the
API.
23. What is fencing in Red Hat Cluster?
Fencing is the disconnection of a node from the cluster's shared storage.
Fencing cuts off I/O from shared storage, thus ensuring data integrity.
The cluster infrastructure performs fencing through the fence daemon, fenced.
When CMAN determines that a node has failed, it communicates to other cluster-infrastructure components
that the node has failed.
fenced, when notified of the failure, fences the failed node.
24. What are the various types of fencing supported by High Availability Add On?
Power fencing — A fencing method that uses a power controller to power off an inoperable node.
storage fencing — A fencing method that disables the Fibre Channel port that connects storage to an
inoperable node.
Other fencing — Several other fencing methods that disable I/O or power of an inoperable node,
including IBM Bladecenters, PAP, DRAC/MC, HP ILO, IPMI, IBM RSA II, and others.
25. What are the lock states in Red Hat Cluster?
A lock state indicates the current status of a lock request. A lock is always in one of three states:
Granted — The lock request succeeded and attained the requested mode.
Converting — A client attempted to change the lock mode and the new mode is incompatible with an
existing lock.
Blocked — The request for a new lock could not be granted because conflicting locks exist.
A lock's state is determined by its requested mode and the modes of the other locks on the same
resource.
26. What is DLM lock model?
DLM is a short abbreviation for Distributed Lock Manager.
A lock manager is a traffic cop who controls access to resources in the cluster, such as access to a GFS file
system.
GFS2 uses locks from the lock manager to synchronize access to file system metadata (on shared storage)
CLVM uses locks from the lock manager to synchronize updates to LVM volumes and volume groups (also on
shared storage)
In addition, rgmanager uses DLM to synchronize service states.
without a lock manager, there would be no control over access to your shared storage, and the nodes in the
cluster would corrupt each other's data.
wa io wait cpu time (or) % CPU time spent in wait (on disk)
hi hardware irq (or) % CPU time spent servicing/handling hardware interrupts
si software irq (or) % CPU time spent servicing/handling software interrupts
steal time - - % CPU time in involuntary wait by virtual cpu while hypervisor is servicing another
st
processor (or) % CPU time stolen from a virtual machine
NOTE: You can enable/disable the marked blue line by pressing "m".
top - 17:51:07 up 1 day, 2:56, 27 users, load average: 5.33, 29.71, 28.33
Tasks: 1470 total, 1 running, 1469 sleeping, 0 stopped, 0 zombie
Cpu(s): 0.0%us, 0.1%sy, 0.0%ni, 99.9%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Mem: 264114424k total, 253006956k used, 11107468k free, 66964k buffers
Swap: 33554424k total, 3260k used, 33551164k free, 245826024k cached
Explanation: The next line shows your memory(RAM and swap) usage and capacity.
PID USER PR NI VIRT RES SHR S %CPU
%MEM TIME+ COMMAND
13916 stmprd 18 0 903m 129m 9936 S 51.4 0.1 3:07.01 java
13921 stmprd 18 0 901m 128m 9936 S 49.8 0.0 3:02.92 java
13825 stmprd 18 0 951m 190m 9932 S 49.5 0.1 3:07.13 java
13856 stmprd 20 0 978m 197m 9936 S 49.2 0.1 3:05.89 java
13853 stmprd 18 0 921m 150m 9932 S 48.5 0.1 3:09.14 java
13875 stmprd 18 0 907m 132m 9940 S 48.5 0.1 3:09.49 java
13937 stmprd 25 0 926m 165m 9936 S 48.2 0.1 3:10.31 java
13919 stmprd 18 0 917m 153m 9936 S 47.5 0.1 3:05.92 java
13879 stmprd 25 0 921m 160m 9936 S 47.2 0.1 3:08.43 java
13908 stmprd 25 0 901m 131m 9932 S 47.2 0.1 3:12.23 java
13905 stmprd 25 0 907m 137m 9932 S 46.6 0.1 2:59.85 java
The left sections shows you the details of the process running along with the below details.
Fields/Column Description
PID Process Id
USER The effective user name of the task's owner
PR The priority of the task
The nice value of the task. A negative nice value means higher priority, whereas a positive
NI nice value means lower priority. Zero in this field simply means priority will not be adjusted in
determining a task's dispatchability
The task's share of the elapsed CPU time since the last screen update, expressed as a
%CPU
percentage of total CPU time.
%MEM A task's currently used share of available physical memory
TIME+ Total CPU time the task has used since it started
The status of the task which can be one of:
'D' = uninterruptible sleep
'R' = running
S
'S' = sleeping
'T' = traced or stopped
'Z' = zombie
RES The non-swapped physical memory a task has used
SHR The amount of shared memory used by a task
Command Display the command line used to start a task or the name of the associated program
0:00.01 less
31328 deepak 15 0 110m 2348 1264 S 0.0 0.0
0:00.20 sshd
31329 deepak 16 0 27676 2564 1816 S 0.0 0.0
0:00.02 bash
31422 deepak 15 0 109m 2360 1260 S 0.0 0.0
0:00.14 sshd
31423 deepak 15 0 27548 2500 1784 S 0.0 0.0
0:00.02 bash
7. Change delay between terminal refresh
By default the top terminal is set for auto refresh after every 3 seconds but if you want you can
change it as per your requirement.
Press "d" when top is running. You should get a prompt as shown below in blue color.
top - 18:14:55 up 115 days, 8:50, 4 users, load average: 0.01, 0.04, 0.00
Tasks: 328 total, 1 running, 327 sleeping, 0 stopped, 0 zombie
Cpu(s): 0.0%us, 0.1%sy, 0.0%ni, 99.9%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Mem: 49432728k total, 2063828k used, 47368900k free, 310072k buffers
Swap: 2097144k total, 0k used, 2097144k free, 1297728k cached
Change delay from 3.0 to: 2.0 [Hit Enter]
PID USER PR NI VIRT RES SHR S %CPU
%MEM TIME+ COMMAND
5359 root 34 19 0 0 0 S 0.7 0.0 9431:58
kipmi0
1795 root 15 0 29492 2300 1524 R 0.3 0.0 0:00.20
top
1 root 15 0 10352 692 580 S 0.0 0.0 0:02.16
init
Verify the changes. You must see the screen buffer getting refresh much earlier or just to verify you
can provide a higher value of delay and observer the refresh rate on the terminal
8. No. of task to be displayed
By default this option is set to unlimited that is the reason your terminal is fully covered with list of
tasks when you run the top command. Any how you can list the no of tasks to be visible once you run
top command.
Press "n"when top is running. You should get a prompt as shown below in blue color
top - 18:18:07 up 115 days, 8:54, 4 users, load average: 0.01, 0.03, 0.00
Tasks: 328 total, 1 running, 327 sleeping, 0 stopped, 0 zombie
Cpu(s): 0.0%us, 0.2%sy, 0.0%ni, 99.7%id, 0.1%wa, 0.0%hi, 0.0%si, 0.0%st
Mem: 49432728k total, 2063348k used, 47369380k free, 310072k buffers
Swap: 2097144k total, 0k used, 2097144k free, 1297804k cached
Maximum tasks = 0, change to (0 is unlimited): 2 [Hit Enter]
PID USER PR NI VIRT RES SHR S %CPU
%MEM TIME+ COMMAND
5359 root 34 19 0 0 0 S 2.3 0.0 9432:08
kipmi0
1795 root 15 0 29492 2304 1528 R 0.7 0.0 0:00.65
top
1 root 15 0 10352 692 580 S 0.0 0.0 0:02.16
init
2 root RT -5 0 0 0 S 0.0 0.0 0:02.37
migration/0
top - 14:48:40 up 116 days, 5:24, 3 users, load average: 0.05, 0.04, 0.00
Tasks: 318 total, 1 running, 317 sleeping, 0 stopped, 0 zombie