Using Ipchains

Using Ipchains

I’m really digging getting back into using ipchains. I really like the off server logging I was able to set up a while ago. I like working on my box much more than the PIX 515 at work.

I’m going to write more about this after I determine how to discuss it without revealing my configuration specifics.

New Gang Symbol

image Have you seen this symbol? More and more of these decals are appearing on the bumpers of cars all over the country. You have to be a “member” of a law enforcement agency to buy one (by providing a verifiable badge number to epolicesupply.com). So it’s a symbol for the nationwide law enforcement gang “the thin blue line.” A symbol of pride? It’s more like “I’m a fellow cop, so don’t pull me over if you see me speeding in my civilian car.”

Mike Davis made this point: If I want to put one of these stickers on my car what’s to stop me from printing one out of Photoshop? And once I have what laws going to say I can’t have this sticker on my car? Would I be arrested for impersonating a law enforcement official because I have this symbol that can only be sold to cops? I’m sure plenty of people who don’t dive have diver down front license plates and stickers on their cars. So if I think this is a pretty black and blue design no law I’m aware of can stop me from putting one on my car, forehead or front door.

I really like this bumper sticker on the epolicesupply website: “Sometimes there’s justice, Sometimes there’s just us.”

Sorry Officer(s). There’s only justice – no gangs allowed. It’s your job to enforce laws and that’s the extent of it. It’s an individual job. Okay, so sometimes you might need back-up or manpower to perform your job. Just remember that gang symbols and slogans don’t put you above the rules of engagement set forth by the justice system and legislators. Of all people cops ought to recognize that the “thin blue line” is a term used by the civilian public to pronounce distrust of officers involved in scandals and cover ups.

Identifying law enforcement symbols should be banned on all civilian possessions and clothing to protect the integrity and trust of the profession. I particulary like it most when a girlfriend or wife of a cop has one of these decals. It says “my husbands/boyfriends a cop”. Um, so what? I guess they’re entitled to some special treatment also.

Microsoft Single Label DNS Names

Microsoft suggests not using single label DNS names. In my recent experience, this should be more than just a suggestion.

I had to open a call to Microsoft this week because some brilliant systems integrator from Alphanumeric decided to leave off the domain suffix from the name of first Windows 2000 domain controller at Dillon Supply. It was dscdc1 instead of the required dscdc1.dillonsupply.com. This server is also one of two DNS servers for the domain. What this means is that the domain controller was unable to update it’s own entry in DNS because Microsoft Active Directory integrated DNS does not allow for single label DNS names by default.

So my options were thin. I tried the registry hack in this Microsoft Knowledgebase Article but it didn’t do much to help (in fact I couldn’t see that it did anything). When I ran netdiag -v I still received a fatal error that the domain controller was not registered with any DNS servers. Some websites suggest demoting the domain controller (dcpromo), changing the machine name to include the domain suffix, and then promoting it again. This is a risky venture because you gotta pray the replication takes place without error to another DC and since your DNS is hosed you will need the luck of the gods. Here’s an alternative: don’t do it.

My call to Microsoft payed off in the form of a .vbs file that will append the domain suffix to any machine name and correctly register the machine in DNS. I have only used it on a Windows 2000 server running SP4. I don’t know how it will work on any other OS version. If you download it run it at your own risk – I’m not responsible for what you do to your systems. All I can say is that it worked flawlessly for me. After running it netdiag showed successful DNS entries for the DC on all AD DNS servers.

BT Unveils Mobile Phone-Landline Handset

BT Unveils Mobile Phone-Landline Handset

I’ve been talking about this for over three years. Someone has finally done it. Of course it wasn’t in the US since we’ve decided not to be the front runners in telecom innovation. Don’t worry BT; I don’t see a mobile phone that can turn into an IP based land line as much of a gamble. It’s definately the future. For all countries except ours that is. Our Ma Bell’s will stiffle the technology for as long as they can.

You hear that Bell South? Eventualy you won’t be needed anymore. May you perish in bankruptcy court.

And the winner is….

image IBM! For five weeks I’ve been drilling through performance specifications for eight way x86 servers to replace Dillon Supply’s HP DL580 four way Win2K SQL server. Through this I’ve learned the TPC-C rankings for almost every four processor AMD Opteron dual core (aka – Opteron 875) system available as well as every eight processor single core Pentium Xeon MP solution in the marketspace.

As of yesterday it looked like we would be going with the SUN V40z four chip Opteron 875. SUN has not submitted this server to the Transaction Processing Council (TPC) for published performance results and therefore I had to rely on the results benchmarked by the HP DL585 4 processor Opteron 875 which also had a strong quote in the running. The DL585 server delivered unmatched performance with a record-breaking TPC-C benchmark of 187,296 tpmC configured with 64Gb of RAM and 8Mb of L3 cache. Unfortunately the SUN V40z cannot address more than 32Gb of RAM. But like I said, as of this morning the SUN was still in the lead primarily because of a non-hardware factor: Veritas Storage Foundation 4.2.

Within the last two weeks I became convinced that Storage Foundation (formerly Veritas Volume Manager) was a good fit for some of the off-site LUN duplication we’re trying to achieve and the SUN vendor had superior knowledge and experience with this product. All things being equal, including pricing, we were ready to make the call for the V40z.

But in the 11th hour the Mayor of Creedmoor NC, Darryl Moss, who is also our IBM sales rep for Champion Solutions Group, through us a curve ball that only the big blue powerhouse could. They discounted their SAN solution including an IBM xSeries 460 eight processor 64-bit Xeon MP by an astonishing $50k+, meaning their offer was not only the lowest in price but also the fastest in performance. This server holds the world record for 8-way systems clocking 250,975 tpmC. That’s the same system we’re buying (minus 96Gb of RAM). Previously we hadn’t given this server much consideration because of cost but with a discount of that magnitude our minds were literally changed in a matter of minutes. Thank you Mayor Moss.

Beach Baby

image Connor loves the Carolina coast. Last weekend he got a tan; mommy and daddy got burned. He makes heading on to the water a whole new experience. We can forget about laying around anymore. Someone’s got to constantly keep him out of the ocean or go in with him. We take shifts because he has no fear and will go in by himself. Now that he’s putting words together he said “bye-bye beach” the whole way home Sunday.

image When I got home last night he ran to my truck screaming “beach! beach!”. I don’t think he cares that it takes 2 1/2 hours to get there.

I’m not used to wearing sunscreen but I’m not going to argue with Amy about putting an SPF 45 all over the little man. It works. He has a tan and I’m peeling a little.

Sirius Radio

image I’m now an official satellite radio subscriber. This is one of those things I wasn’t sure I wanted to buy and now I don’t know how I lived without it. I went with Sirius over XM radio because one is for adults and the other is for kids with Honda Civics and go-cart mufflers. XM radio sports selection consists of Major League Baseball. The only thing more boring than watching baseball on TV would be listening to it on the radio.

Sirius on the other hand has NHL, NFL, NBA and many ESPN channels. During my research I found that the music and news selections are better too. I guess “XM” just sounds cooler than “Sirius” so parents this is what your teenager will want (and why XM has more subscribers). Despite this Sirius is in better financial shape than XM. This could be because of a more mature user base that can actually pay the bill. Personally I like the fact that there is better news and jazz on Sirius. I guess that makes me an ol’ geezer but that’s what life deals.

WRAL.com – News – House Committee Approves Two-Year Death Penalty Moratorium

WRAL.com – News – House Committee Approves Two-Year Death Penalty Moratorium

So at least the NC House of Reps has a little common sense. WRAL has a poll going that is evenly split between people that think the moratorium is a good idea and those who think it’s a step towards outlawing the death penalty.

So here’s my poll: If you do not support a moratorium of the death penalty while it’s studied for problems explain your position by selecting one of the following (and you MUST chose one or you do not have a justifiable claim to your position):

A) I do not care if innocent people die as long as executions continue.

B) Despite mountains of evidence to the contrary I think the death penalty is a deterrent to would be murderers.

C) I believe our judicial system is efficient, just and without bias.

D) I do not think that prosecutors are politically motivated in their pursuit of criminal convictions.

E) I can cite a criminal case in NC where a prosecutor has obtained evidence that would exonerate a defendant and voluntarily presented it in court for an immediate dismissal.

F) I am a redneck, neo-Christian-conservative who believes an eye-for-an-eye is ordained by God. Innocent people are just casualties of our “War on (insert latest sin here)”.

WRAL.com – News – House Committee To Consider Two-Year Moratorium On Death Penalty

WRAL.com – News – House Committee To Consider Two-Year Moratorium On Death Penalty

I love it when hard-core Christian conservatives ban together in support of killing innocent people. Who cares if a couple of people who didn’t commit any crime get the hot needle? A few innocent lives is a small price to pay to make sure the real bad guys burn right? Ah,where would we be without good ‘ol NC redneck, lynch mob ideology?

This story quotes one really intelligent death penalty supporter, Representative Nelson Dollar, as saying that releasing two innocent men who spent over five years on death row shows the system works. Yep folks, this genius was elected. What does he care – no reparations are required. And never mind the controversy that surrounded the investigation of the crooked lawyers who withheld evidence that could have exonerated one of the men during their original trial.

Here’s a solution, I’ve posed it before but it doesn’t seem to popular among criminal prosecutors: If any defendant is aggressively prosecuted, with blatant disregard for researching facts that could lead to an acquittal, and that defendant is proven to have been wrongfully convicted, then the prosecutor must serve a minimum of half the sentence imposed on the innocent defendant.

Somehow I think the prosecutors are going to want to hold on to their current infallibility.

8-way system shootout? anyone…..anyone…..

Right now I’m doing research in uncharted territory at work. We have an SQL application performance problem we’ve decided to attack with hardware following months of performance analysis. I have reached a point where benchmarks are unavailable. This is because the server options we have on the table vary in platform architecture, therfore few performance comparisons. In the ring are:

The IBM xSeries 445 8-processor, Intel, single core server with dual fiber channel host bus adapters for redundant connections to SAN controllers and…
Servers from Sun and HP (v40z and HP585 respectively) that are 4-processor dual core solutions with dual FC HBA’s

So the question is: Can the new AMD Opteron dual core systems out perform the 8-processor dual bus system from IBM?

I’ve heard “yes” and “no” but no one has put these 8-way solutions up against each other in any performance comparisons that I can find. I’d really like to see it done by TPC.org since my solution needs to be transaction based. Therefore I’m tempted to go with the dual core solution because that is the trend of the industry with Intel currently having 15 dual core projects in the works. I will be spending the rest of this week and the first part of next week on the phone with IBM, HP and Sun engineers looking into specifics surrounding the architectures.

At present I have deduced that the AMD dual core Opterons do out perform the Intel Smithfield based dual core solution. This is because the Intel platform cannot distinguish ownership of cache data between the two cores. The AMD Opteron can actually pass memory data between the cores. But because the AMD chipset can only recognize DDR memory (not DDR2) AMD is having to go back to the drawing board for the base architecture in order to stay ahead of Intel in the future. For now, AMD has once again smoked Intel just like they did with the Athlon 64 vs. the Itanium.

During my research I contacted a relatively unknown server manufacturer who will be bringing an 8-processor AMD 875 solution to market within the next few weeks. Verari uses iWill motherboards and is trying to stablize the cooling issues now before the product launch. They don’t have the brand name but they may soon offer the best of both worlds with 16 total cores in 8 sockets.