Blogs

apt-get install openvpn easy-rsa

remove/flush all rules & delete chains
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
iptables -t mangle -F
iptables -t mangle -X
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT

-F : Deleting (flushing) all the rules.
-X : Delete chain.
-t table_name : Select table (called nat or mangle) and delete/flush rules.
-P : Set the default policy (such as DROP, REJECT, or ACCEPT).

certbot certonly --standalone --preferred-challenges http -d waspa.org.za
certbot --apache certonly
certbot renew --dry-run

Change certs to LetsEncrypt
chmod 755 /etc/letsencrypt/{archive,live}; chgrp Debian-exim /etc/letsencrypt/{archive,live}

Check user exim -bt mailmanatispa [dot] org [dot] za

/var/virtual/waspa.org.za/mailman/bin/list_lists -b | while read list; do /var/virtual/waspa.org.za/mailman/bin/find_member -l $list "telkomsa.net"; done

or

`telkomsa.net"

or, best yet

/var/virtual/waspa/mailman/bin/find_member @telkomsa.net

waspa.org.za/mailman/bin/list_admins -a | grep -i ant@ff == no results

Delete a mailman list:
/var/virtual/waspa.org.za/mailman $ bin/rmlist no-alert
Not removing archives.  Reinvoke with -a to remove them.

 

netstat -anutp | grep SYN_RECV | wc -l

vnstat -l -i eth0

htop

tcpdump -i eth0 -nn 'tcp port 80' and 'tcp[13] == 2' -c 100

iptables -A INPUT -p tcp -m state --state NEW -m recent --update --seconds 60 --hitcount 20 -j DROP
 

 /etc/ufw/before.rules
 
*nat
:PREROUTING ACCEPT Array
# forward 129.232.230.123 port 22 to 192.168.230.123:22

-A PREROUTING -i eno1:1 -d 129.232.230.123 -p tcp --dport 22 -j DNAT --to-destination 192.168.230.123:22
# setup routing
-A POSTROUTING -s 192.168.230.0/24 ! -d 192.168.230.0/24 -j MASQUERADE
COMMIT

NOTE: NET-TOOLS (e.g. ifconfig) DEPRECATED. USE IPROUTE2

ip addr add 129.232.230.123/29 dev eno1 label eno1:0

iptables -t nat -A PREROUTING --src 129.232.230.123/29 -j NETMAP --to 192.168.230.123/24

https://serverfault.com/questions/627238/kvm-libvirt-how-to-configure-st...

virsh  dumpxml  ispa-vm | grep 'mac address'
virsh  net-list
virsh  net-edit default

virsh net-destroy default
virsh net-start default

Debian/Ubuntu only UID numbering!

mount -o nolock 10.10.122.1:/nfs/share /mnt/

export UGIDLIMIT=1000
cd /nfs/share/ff/move
awk -v LIMIT=$UGIDLIMIT -F: '($3>=LIMIT) && ($3!=29999)' /etc/passwd > move/passwd.mig
awk -v LIMIT=$UGIDLIMIT -F: '($3>=LIMIT) && ($3!=29999)' /etc/group > move/group.mig
awk -v LIMIT=$UGIDLIMIT -F: '($3>=LIMIT) && ($3!=29999) {print $1}' /etc/passwd | tee - |egrep -f - /etc/shadow > move/shadow.mig
less move/passwd.mig ls -ltr move/
ls -ltr move/

https://wiki.dovecot.org/ACL (Note, the configs moved from dovecot.conf)

UBUNTU 16.04:
/etc/dovecot/conf.d/10-mail.conf

# Directory where to look up mail plugins.
mail_plugin_dir = /usr/lib/dovecot/modules

# Space separated list of plugins to load for all services. Plugins specific to
# IMAP, LDA, etc. are added to this list in their own .conf files.
#mail_plugins =
mail_plugins = acl
protocol imap {
  mail_plugins = $mail_plugins imap_acl
}

In a nutshell, as root:
$ apt-get install mb2md
$ su - 'username
$ mb2md -s f2fpanel-aug2014.mbox -R ## User must be chown of source file!


Some excellent footage of Hole in the Wall in winter.

Don't be put off by the opening shots of Thailand. 

Credit: https://www.youtube.com/watch?v=cgsUYWdxcs0

We had a lovely month at Ncinci One’s Montessori and September brought us Spring, seedlings, World Peace Day and super development from the children.

August was Woman’s Month and it was a very challenging one at Ncinci One’s Montessori.  Talk about testing the strength of a woman………..but it definitely does make you stronger and wiser…and needing another box of hair colour! 

Overseeing the building works at Ncinci One’s Montessori and dealing with the challenges has not been an easy task.  But I am very glad to say that the thatching of the new classroom is well underway (by the 3rd thatcher), a lovely old-school thatching tata….with a nice thick roof in the making. 

“Education is the most powerful weapon which you can use to change the world” – Nelson Mandela

Garden Road Montessori owner, Delicia Moraleda and her family brought sunshine, happiness and educational materials to the children of Ncinci One’s Montessori today.  It really was true Mandela Day Celebrations, which will be remembered by all in time to come.   It took Delicia way more than 67 minutes or even 67 hours to: 

Brand new Montessori materials donated by Garden Road Montessori

It has been busy days at Ncinci One’s Montessori!  We hosted our first parents workshop on Saturday, 3 June 2017.  Dr Eybe Meents came and spoke to the mama’s about “How to keep your children healthy”.  He covered the topics of immunisation, de-worming, nutrition, recognizing serious illness and avoiding injuries and intoxication.

Lauren from Kamvalethu and I

The beauty of South Africa's Wild Coast‚ its eco-systems‚ culture and communities will be highlighted in a locally-produced documentary in the hope of declaring it a World Heritage site.

The adventures of three paddlers‚ three cyclists and three runners who will each traverse the entire Wild Coast in the Eastern Cape‚ covering about 300 kilometres from the Great Kei River in the south to the Umtamvuna River in the north‚ will be followed by a film crew.

Ncinci One's Montessori attended  the National SAMA Conference, which was held in Johannesburg at the end of April 2017.  It was a very well organised, inspirational conference and I have never networked as much in my life - it was really super!  Truly connecting with old Montessorians and meeting new one's.......absolutely divine! We are very pleased and excited to share the lovely news, that Garden Road Montessori have 'adopted' Ncinci One's Montessori as their charity for this year's fundraising.

Delica Moraleda from Garden Road Montessori and Dawn

An annual green music and cultural event held at Mdumbi Point on the Wild Coast.

WOW! Time really does fly when you are having fun. Ncinci One's Montessori celebrated it's 1st birthday this week and the week was full of good happenings again!

The best birthday present we received  is that we are all so excited about the new building that is going up and the expansion of our school!  We say a huge thank you to The Kamvalethu Foundation and Susan Gallagher for making this happen.  

Imange and Ahlumile

 

Rule 26 -- Navigation Lights for Fishing Vessels


INTERNATIONAL

INLAND

(a) A vessel engaged in fishing, whether underway or at anchor, shall exhibit only the lights and shapes prescribed in this Rule.

Nav lights for fishing

Zuma axes the Finance Minister and other opposition in his cabinet.

It really should have been announced tomorrow. Fool.

The Rand closed at R12.79 on Thursday 30 April 2017. Down 5% by 6:30am. How far will it go?

Click on the pics to the left.

Tuesday 4/4/17, 8:40AM it's at R13.84 against the dollar, after S&P announced downgrade to 'junk' status on Monday.

 

Rand exchange

The past 6 weeks have been magical at Ncinci One’s Montessori.  The children are all absorbing and developing at a rapid rate and it is really great to observe and be a part of.

Be aware of illegal fishing vessels along the Wild Coast.

Especially during the Shad Season and Sardine Run from May through August!

There is now a permanent AIS monitoring station at Hole in the Wall, capable of monitoring all legal marine traffic along the Wild Coast.

"Legal" Chinese fishing vessel with 600 tons of squid that ran away from our coastguard

Amadiba Crisis Committee 2017-03-23:

We are instructed by the meeting at Komkhulu today 23 March 2017 to say exactly the following in a short letter from the Traditional Authority of Umgungundlovu to the new CEO of SANRAL:

“Starting from now, SANRAL will cease and desist from all activities in our community. If you don’t respect this, we will tie up your staff and keep them here by us, until their father comes and fetch them.” 

We have decided to let this be an open letter: