Entries Tagged as 'International'

OpenVPN + AWS

A friend put me onto AWS – Amazon Web Services. I had known about it for some time, but had not dabbled in it because I thought it would be too expensive. As of November last year though, Amazon, obviously aware that many people see their web services this way, decided to make a free use tier for basic testing and small production use.

So, I setup OpenVPN on an Ubuntu server micro-instance in the Asia Pacific region of Amazon AWS. I followed the instructions located here to setup the keys and certificates for the server and some local clients. At this stage I am only using the basic tunneling interface, I do plan to try the alternative TAP interface though, which would allow me to bridge my workstation at home with my mobile Internet tablet, the Nokia N900.

I found that using the sample configuration files from the OpenVPN HOWTO was the quickest way to get up and running. Apart from defining the necessary PKI files, These are the things I changed:

  • For the server configuration. set or change the following options
View Code CONFIG
push "redirect-gateway"
push "dhcp-option DNS 172.16.0.23"
  • For the Nokia N900 client configuration, The DNS must be directed away from the internal proxy on the tablet. add this to the end:
View Code CONFIG
script-security 2
up /etc/openvpn/maemo-update-resolvconf
down /etc/openvpn/maemo-update-resolvconf
  • The server must have masquerading enabled as well for the VPN IP range. This involves using the following rules in iptables:
Download rulesfile.txt
*nat
:POSTROUTING ACCEPT [0:0]
:PREROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A POSTROUTING -s 10.8.0.0/24 -d 0.0.0.0/0 -o eth0 -j MASQUERADE
COMMIT
  • On Ubuntu 10.10 server, one can use “sudo iptables-apply rulesfile.txt” to apply the above ruleset. You may want to add this to a startup script in /etc/init.d – perhaps the openvpn startup script.

That covers the basics and gets me a faster, more open Internet connection from my mobile 3G tablet in China.

Please note that setting up a micro instance in AWS Console is fairly easy, I suggest you be careful not to choose a large image if you want to remain within the 10Gb free limit of Elastic Block Storage. The firewall will need to be opened up for port 1194 as well as the standard ssh.

Corley Saxophonist

Here is a video that my friend Alexei made of his wife Tanya and I performing at GuoMao SanQi, the tallest building in Beijing. Alexei is also playing guitar but cannot be seen because there were only enough stage mics for Tanya and me.

The video will start as soon as it is downloaded.

If you would like to book me to play sax, please contact me at this email: corley.kinnane (at) gmail.com

Length: 3:07 Size: 7.9 Mb.


Click here for a direct download of this video.

Note: The video is an AVC High Profile MP4, you will need a recent version of Flash to play it. If it it doesn’t play, upgrade your Adobe Flash Player here.

Gig in Lin Yi

A fun 2 days in Shandong province. There’s me, Natalia, Tony and Sergey.

Sanity

I wish I could say I found this in a butcher’s shop but alas, no. This was in a bakery that’s just opened nearby. Great bakery, run by an older lady, Macbeth I think her name is.

Baby On Road

The New York Times had some great photos of chinglish recently. Here is another classic I snapped today.

Exploding Cars

Exploding cars please use other exit.

Beijing Hu Tong

A nice example of a hu-tong (胡同) pathway in Beijing, I took this near DaWangLu which is an expensive area showing the close contrasts in Beijing. I think that maybe the original wheel.

Hejira

Hejira is one of my favourite albums. It is quite a delicate creation, but delivered with such confidence by Joni. Of course working with Jaco gave it an extra confident edge. I find it to be the album I turn to for emotional stability. Its an album created through travel, so it came with me to China.

I listened to it and Weather Report’s "Black Market" for much of 2nd. and 3rd. trips to China. This time for me was very special, experiencing living in Beijing and travelling to The Great Wall, Tianjin, The Summer Palace, then Qingdao by train and Laoshan on the 3rd trip. This music definitely provided an appropriate backdrop for such an amazing experience. I deliberately over-listened to it so that now when I listen to it, it sends me back to that time. Both occasions were in Autumn, which is a great time to be in China.

Its definitely my favourite Joni Mitchell album – but I must admit I know only a few. Of course, along with Weather Report’s "Black Market" – the first recording they made with Jaco Pastorious, they travel together well in my portable player.