Saturday, April 10, 2010

Cisco ios keyboard shortcut

Delete: Removes the character to the right of the cursor
Backspace: Removes the character to the left of the cursor
Up Arrow: Allows you to scroll forward through previous commands
Down Arrow: Allows you to scroll backwards through previous commands
Ctrl+P (or up arrow): Displays the last command entered
Ctrl+N (or down arrow): Displays previous commands entered
Ctrl+A: Moves the cursor to the beginning of the current line
Ctrl+E: Moves the cursor to the end of the current line
Ctrl+F: Moves forward one character
Ctrl+B: Moves backwards one character
Esc+F: Moves forward one word
Esc+B: Moves backwards one word
Ctrl+R: Redisplays a line (starts a new line, with the same command shown)
Ctrl+U: Erases a line
Ctrl+W: Erases a word
Tab: Completes a partial command
Ctrl+Z: Exits configuration mode, returning you to privileged EXEC mode

Interview with 6x CCIE Roman Rodichev!!!!

It is my pleasure and honor to introduce Roman Rodichev 6x CCIE #7927 ( yes six ). Roman is the first person in the world to hold all 6 active CCIE certifications!!! He is also the instructor, content developer, and owner of ieMentor

Larry: Thanks for taking the time to participate in this interview.

Roman: Thank you, Larry. It’s great to see a new online resource dedicated to the CCIE training industry. Thank you for spending time on doing this! A lot of folks who are going for a CCIE appreciate this too.

Larry: Thanks. I am hoping that the blog will become a valuable resource. The first thing I have to ask about is – 6 CCIE certifications!!! What drove you to want to go that far?

Roman: I’m not even sure what exactly drove me to this. I definitely like being challenged, I like taking tests. There is no one common reason for each of the CCIEs though.
R&S was my first and it took a couple of years to prepare for, finally passing it in August 2001 on second attempt. I just got out of college, not yet legal to drink or to rent a car. Clearly that was the most exciting CCIE to get, far more exciting compared to the last one I got this year. What an experience that was, so much inspiration, drive, fear, stress, so little sleep! First attempt was a disaster, out of excitement I threw away one of the provided pieces of paper into trash, and Kathy, my favorite proctor, wouldn’t let me continue on my second day, even though I passed the first day. She said “You are lucky we are not putting you on a black list”. I would have had to wait for almost 6 months to get another seat.
Fortunately, past programming skills helped me develop a quick script that checked Cisco’s CCIE scheduling site for available dates and grabbed a date if it became available. I was back in a month and paid more attention that time. The big driver for R&S was career advancement and desire to get through that magic $100K/year salary barrier. But more importantly, I really liked what I was doing and was fortunate enough to become inspired by a couple of CCIE Cisco folks I met around that time. One of them, Dmitry Bokotey, 5xCCIE#4460, became a very good friend of mine and was the main point of inspiration for getting drunk on Cisco Kool-Aid.
I got Security CCIE six months later on first attempt. Playing with PIXs and VPNs at that time helped out a lot. The other factor was the young age of the Security CCIE track. I always recommend students to take the CCIE lab when it just comes out and not wait for the second version of the blueprint. I realize, of course, that not everyone gets a chance to do that. The first version of the Security lab was a little raw and wasn’t as advanced as the latest blueprint. It didn’t require as much effort. I’m not saying it was easy, but definitely easier than what other folks have to go through now to achieve Security CCIE.
If Cisco could take my Security track away and let me retake the new lab, I’d like to do that. I don’t think they allow this, though.
I remember asking them the same about my Storage CCIE so that I could go and try the new second version of the lab. They wouldn’t let me.
During those two years in 2002 and 2003, I was heavily involved in some voice deployments with CallManager, Unity, IPCC, and other Cisco voice offerings. This helped me gain enough interest and knowledgebase for attempting Voice track. My sheer interest for UC (or IPT back then) held me hostage and begged me to try it. I studied for a couple of months, went and failed. I have to thank proctor Ben Ng for creating a very challenging lab. He was the most helpful proctor of all!
I haven’t seen the new security lab, but based on the six labs I took, in my opinion, Voice was the hardest.
After failing, I studied each night after work for a month, and then went back and was lucky enough to pass it.
This is where the story stops for about three years. During that time I got a chance to do a consulting gig in Europe for about a year, got married, bought a home, those dollars had to go somewhere!!
I forgot about CCIEs for a while. Finally in 2005, around the same time Storage track was coming out, I got involved with ieMentor. It was more of a hobby than a business. I wanted to do something fun and take advantage of all the knowledge CCIEs gave me and pass this knowledge on to other people. Our CCIE Service Provider, CCIE Voice and CCIE Storage workbooks came out around the same time, followed by the CCIE Service Provider and CCIE Storage bootcamps.
Writing a CCIE Storage workbook drove me to take the CCIE Storage lab. Developing labs and questions is the best way to study for the lab. Of course, not everyone would decide to use this wacky approach, but it certainly helped me pass the Storage lab on first attempt in March of 2006 and then release the workbook a month after that. In the summer of 2006, I started delivering the CCIE Service Provider bootcamps without actually having the cert.
CCIE Service Provider is my favorite track. No other track has such a collection of interconnected technologies that allows you to achieve the result only if you get every little piece right. Doing that successful final ping between two CEs is more exciting to me than making a successful phone call between two IP phones. Discovering a failed ping between two CEs is more stressful for me than discovering a broken VPN session. I don’t know, maybe it’s just me, but Service Provider technologies are just a lot of fun to work with! Obviously, I couldn’t teach the class for too long without having the certification. I went and passed it in November of 2006.
Finally, in 2008, a rumor spread that a CCIE wireless track was on the horizon. My brain was refusing to even think about it, while my heart was telling me “Just one more, and that’s it”. Also, the word “sextuple” had something sexy about it. Probably the only sexy thing ever associated with a CCIE. I locked myself in the room for two months studying controllers, access points, authentication, security, WCS, roaming, wireless voice, all the fun stuff you have to know for this great track. I took the lab in San Jose in May of 2009 and it kicked my butt.
Past experience taking these labs taught me a lesson:
1. Document the entire lab even if you think you passed it. This takes about 3 days. Don’t be lazy!!
2. Practice your lab at home and research every topic even if you believe you will get a different lab next time
3. Don’t wait after failing, schedule the lab for the soonest date possible. The most studying you will do is between the attempts.
After coming back from the wireless lab, I locked myself in a room for a month again, went back in July and was lucky to pass it. It was a very nostalgic experience coming to San Jose for the last CCIE, the same location I went to get my first one eight years ago.
In conclusion, what helped me get six CCIEs? A different thing each time:
1. R&S = lots of studying for about two years, a true CCIE preparation experience that most go through
2. Security = experience with PIXes and IOS security + luck
3. Voice = experience with IPT + two months of non-stop studying
4. Storage = writing a workbook
5. SP = teaching a bootcamp
6. Wireless = two months of non-stop studying
Some people who don’t know me think I have no life and that all I do is study. I would say that studying for CCIE R&S was really like that, no partying, lots of lab hours, lots of sleepless nights. Other tracks involved short but intense study methods. I would simply lock myself in a room with equipment and books for a couple of months. Another thing that helps me a lot is that I enjoy reading technical literature, Cisco Press books, but mostly Cisco’s documentation. The problem is that 90% of reading I do is in my car. I certainly don’t recommend it! At any point in time, you will find around ten 20-30 page Cisco website print-outs on my passenger’s seat. I don’t know why, but it helps me better digest and remember the information.
I don’t like long and boring tasks that don’t require some knowledge transfer, like driving, running on treadmill, waiting at the doctor’s office. I can’t just sit and stare at something, I need to read. Yes, reading while driving is not a good idea, but I never had an accident because of it, I usually feel more distracted talking on the phone while driving.
Larry: Wow – that’s quite a story . I think that all of us that have passed, taken or are preparing for a lab can relate in some way. As an instructor, how do you keep up to date on all of the tracks and the changes to the labs?

Roman : Various sources can help. I currently teach SP track and since the blueprint hasn’t changed for a long time, it doesn’t require too many changes to the curriculum. I make sure that I cover all topics on the blueprint. I also monitor IOS release notes to be aware of any changes or new features introduced. I listen to what students are saying or what they hear about from other people preparing for SP. I myself learn something new in each class.

Larry: That is definitely something to remember. We can always learn something new!!
Do you have a favorite technology area? One that really interests you more than the others?

Roman: I enjoy working with Data Center, Virtualization, Unified Communications and Wireless. I like them all equally as long as the project is challenging.

Larry: There are a lot of folks that are currently studying for their first CCIE. They have problems balancing work, studying and family. Do you have any advice for them?

Roman: First of all, I need to mention that my wife and I don’t have kids yet, so I’m absolutely in no position to make recommendation of how to balance your time between kids and studying. For my situation, my success at getting CCIE and how quickly I can achieve it depends entirely on how much I am interested in the technology. If configuring MPLS VPNs is more interesting than watching TV, I will pass the lab quickly.
Find time to read. Print out a 10-20 page section of a configuration guide or a tech note and read it the same day. Do this every day. There are plenty of moments in your day, wherever you are, when you are idling and could spend that time reading.
Finally, again, it’s all about INTEREST and ENJOYMENT. If you are truly interested in the technology, if you are really enjoying studying, you will find time how to balance work, wife (can’t speak for kids) and studying. People who “can’t find time for studying”, don’t actually enjoy studying that technology.

Larry: That is an important item to consider. Having a passion for what you are studying makes it more bearable. What is your reaction to the major changes to the R&S lab structure? Do you have any advice for folks that are studying for this “new breed” of lab?

Roman: I’m not very familiar with it. I’ve heard about new troubleshooting section, but can’t speak much to it. I live in the SP and Storage world.

Larry: One question that I get quite often from people is - Should I go for a professional level certification before moving to the CCIE? What is your advice on that?

Roman: If you are going to do CCIE, why waste time on CCNP? If you are ready for CCIE, you can go and take all CCNP tests in one day, and you’ll pass them. Getting CCNP might get you a $10-20K salary increase, but probably only if you switch jobs. If you think that CCIE is your ultimate goal, go for CCIE, don’t think about CCNP. These two certifications require a different approach in studying. Some people choose to study with pass4sure and pass the CCNP within a week. I would rather prepare first for a CCIE, and then take CCNP tests without preparation a week before the CCIE lab.

Larry: Thanks again for taking the time for this out of your busy schedule. One last closing question – If Cisco brings out another CCIE track will you go for it?

Roman: Well, it’s kind of obvious that Data Center CCIE will be the next track. It would be interesting to see if Cisco keeps Storage CCIE alive or if it decides to merge them. I love Data Center technologies and therefore will do this track. Now, if Cisco decides to make a track on TelePresence, that’s a different story!

Tuesday, March 2, 2010

MIKROTIK: How to apply different limits for Local/Overseas traffic

Introduction

Let's consider the scenario, when you want to apply different limit to Local and Oversea traffic. Oversea traffic - traffic that doesn't belong to the Local country traffic. To distinguish oversea traffic from Local country traffic, we will use 'mangle marks' and 'address-list' features. It will place appropriate marks to the packets to/from the Local country and Oversea networks. Note, 'address-list' entries should be replaced with respective addresses, if your router isn't located in Latvia. To find the actual list of network numbers belonging to your country, use Google or any other resources. Simple queues will limit data rate for the Local country traffic and Oversea traffic.

Address-list

First we create Local country address-list, where are placed list of network numbers belonging to ISPs in Latvia (any other country network addresses can be used instead). Full address-list configuration is not included (too many address-list entries), but address-list idea is clear. Networks added to the list 'Latvia':

/ ip firewall address-list
add list=Latvia address=159.148.0.0/16 comment="" disabled=no
add list=Latvia address=193.41.195.0/24 comment="" disabled=no
add list=Latvia address=193.41.33.0/24 comment="" disabled=no
add list=Latvia address=193.41.45.0/24 comment="" disabled=no
add list=Latvia address=193.68.64.0/19 comment="" disabled=no
add list=Latvia address=193.108.29.0/24 comment="" disabled=no
add list=Latvia address=193.108.144.0/22 comment="" disabled=no
add list=Latvia address=193.108.185.0/24 comment="" disabled=no
add list=Latvia address=193.109.211.0/24 comment="" disabled=no
add list=Latvia address=193.109.85.0/24 comment="" disabled=no
add list=Latvia address=193.110.8.0/23 comment="" disabled=no
add list=Latvia address=193.110.164.0/23 comment="" disabled=no
...
add list=Latvia address=193.111.244.0/22 comment="" disabled=no

Mangle

First we add rule to mark connections that belong to local router's subnet (192.168.100.0/24). Second rule marks connections between local subnet and overseas networks. Third rule marks oversea packets and exclude them from mangle table (passtrough=no). Finally, the last rule places packet mark on all packets that belong to Local country traffic.

/ ip firewall mangle
add chain=prerouting src-address=192.168.100.0/24 action=mark-connection \
new-connection-mark="Con Entire Traffic" passthrough=yes \
comment="Mark-connection All Traffic" disabled=no
add chain=prerouting src-address=192.168.100.0/24 connection-mark="Con Entire \
Traffic" dst-address-list=!Latvia action=mark-connection \
new-connection-mark="Con Oversea" passthrough=yes comment="Mark-connection \
Oversea Traffic" disabled=no
add chain=prerouting connection-mark="Con Oversea" action=mark-packet \
new-packet-mark="Oversea traffic" passthrough=no comment="Mark-packet \
Oversea Traffic" disabled=no
add chain=prerouting action=mark-packet new-packet-mark="Local Country Traffic" \
passthrough=no comment="Mark-packet Local Country Traffic" disabled=no

Simple Queue

Queue configuration is quite simple in the particular case. 192.168.100.254 is the local network host. First rule sets limit 256k/256k to Oversea traffic for the particular host. Respectively second simple queue set limit 1M/1M for Local country traffic.
/ queue simple
add name="Oversea" target-addresses=192.168.100.254/32 dst-address=0.0.0.0/0 \
interface=all parent=none packet-marks="Oversea traffic" direction=both \
priority=8 queue=default-small/default-small limit-at=0/0 \
max-limit=256000/256000 total-queue=default-small disabled=no
add name="Local Country" target-addresses=192.168.100.254/32 dst-address=0.0.0.0/0 \
interface=all parent=none packet-marks="Local Country Traffic" direction=both \
priority=8 queue=default-small/default-small limit-at=0/0 \
max-limit=1024000/1024000 total-queue=default-small disabled=no

Thursday, February 4, 2010

Debian Mail Server Setup with Postfix + Dovecot + SASL + Squirrel Mail

Install Postfix MTA (Mail Transfer Agent)

Use the following command to install postfix in debian

#aptitude install postfix postfix-tls libsasl2 sasl2-bin libsasl2-modules popa3d

During installation, postfix will ask for few questions like name of server and answer those questions by entering your domain name and select Internet site for postfix.

Postfix configuration file is located at:/etc/postfix/main.cf. You can edit this file using popular text editor vi /etc/postfix/main.cf

Restart Postfix Server using the following command

#/etc/init.d/postfix restart

Install Dovecot

Dovecot is POP3/IMAP server which needs MTA like Postfix to work properly.

#aptitude install dovecot-imapd dovecot-pop3d dovecot-common

Dovecot configuration file is located at: /etc/dovecot/dovecot.conf

Before we proceed we need to make some changes with dovecot configuration file. Double check the following entries in the file if the values are entered properly.

Edit the dovecot configuration file using the following command

#vi /etc/dovecot/dovecot.conf

# specify protocols = imap imaps pop3 pop3s
protocols = pop3 imap
# uncomment this and change to no.
disable_plaintext_auth = no
pop3_uidl_format = %08Xu%08Xv

Now, create a user to test our pop3 mail with outlook:

#adduser user_name

Note: Always create a separate user to test your mail or ftp.

Restart Dovecot using the following command

#/etc/init.d/dovecot restart

Now, you can use your outlook express to test whether your new mail server is working or not. Just enter username: with password in outlook.

Remember you will NOT be able to send email outside your network, you will be only be able to send within your domain or local network. If you attempt to send email you get “relay access denied” error from outlook express. However, you should have no problems in receiving your email from outlook. Inorder to send email external email you will need to configure SASL authentication as described below.

Configure SASL Authentication with TLS

SASL Configuration + TLS (Simple authentication security layer with transport layer security) used mainly to authenticate users before sending email to external server, thus restricting relay access. If your relay server is kept open, then spammers could use your mail server to send spam. It is very essential to protect your mail server from misuse.

Let us set up SMTP authentication for our users with postfix and dovecot.

Edit the postfix configuration file /etc/postfix/main.cf and enter the few lines to enable authentication of our users

smtpd_sasl_auth_enable = yes
smtpd_sasl_local_domain = yourdomain.com
smtpd_recipient_restrictions = permit_mynetworks,permit_sasl_authenticated,reject_unauth_destination
smtpd_sasl_security_options = noanonymous

postfix does a chroot so it can’t communicate with saslauthd.

#rm -r /var/run/saslauthd/

#mkdir -p /var/spool/postfix/var/run/saslauthd

#ln -s /var/spool/postfix/var/run/saslauthd /var/run

#chgrp sasl /var/spool/postfix/var/run/saslauthd

#adduser postfix sasl

On the Dovecot side you also need to specify the dovecot authentication daemon socket. In this case we specify an absolute pathname. Refer to this postfix manual here

Edit /etc/dovecot/dovecot.conf file

#vi /etc/dovecot/dovecot.conf

Look for the line that starts with auth default, before that insert the lines below.

auth default {
mechanisms = plain login
passdb pam {
}
userdb passwd {
}
socket listen {
client {
path = /var/spool/postfix/private/auth
mode = 0660
user = postfix
group = postfix
}

}

}

Now, rename previous auth default to auth default2. If you dont rename this then dovecot server will give you error like multiple instances of auth default.

Now restart all the following components of mail server

#/etc/init.d/saslauthd restart

#/etc/init.d/postfix restart

#/etc/init.d/dovecot restart

Test whether your mail server works or not with your outlook express. Configure a user with a user name (without @domain) and make sure that you select my server requires authentication. Under settings select same as incoming mail server

Note:
1. If you dont enable My server requires authentication in outlook you cannot send emails to external recipients and you get relay access denied error.
2. Do not use root login to login to your mail server.
3. Dont forget to create a new user before you authenticate using outlook.

Forwarding Mails

Ever wondered how to forward your mails especially if you are a webmaster managing number of sites. You might need to forward any email sent to your primary email address. Its that easy. Just create a .forward file on your home directory. Insert list of emails addresses separated by commas, where you want to get forwarded.

Login as user and type

echo ‘destination_email_address’ > .forward

or you can use vi to create .forward file. Just Delete .forward file if you dont want any forwarding.

Installing Squirrel Web Mail

Before installing Squirrel Web Mail you need to make sure you have installed apache2 with php support

#aptitude install apache2

#aptitude install libapache2-mod-php5 php5-cli php5-common php5-cgi

#aptitude install squirrelmail

Squirrelmail configuration file is located in: /etc/squirrelmail/ folder. By default all settings are preloaded.

# Run squirrelmail configuration utility as ROOT
/usr/sbin/squirrelmail-configure

Now we want to setup to run under apache. Edit apache configuration file /etc/apache2/apache2.conf and insert the following line

Include /etc/squirrelmail/apache.conf

Restart the webserver using the following command

#/etc/init.d/apache2 restart

Access your webmail using the following link

http://yourdomain or server ip/squirrelmail

Create a separate local user and login as a new user.

Mail Server Logs

Always refer to logs located in /var/log/mail.log so that you can identify what the problem is before you can troubleshoot.

A detailed look at the filesystem in Debian

A typical Linux system has, among others, the following directories:

/

This is the root directory. This is where the whole tree starts.

/bin

This directory contains executable programs which are needed in single user mode and to bring the system up or repair it.

/boot

Contains static files for the boot loader. This directory only holds the files which are needed during the boot process.

/dev

Special or device files, which refer to physical devices.

/etc

Contains configuration files which are local to the machine. Some larger software packages, like X11, can have their own subdirectories below /etc. Site-wide configuration files may be placed here or in /usr/etc. Nevertheless, programs should always look for these files in /etc and you may have links for these files to /usr/etc.

/etc/skel

When a new user account is created, files from this directory are usually copied into the user's home directory.

/etc/X11

Configuration files for the X11 window system.

/home

On machines with home directories for users, these are usually beneath this directory, directly or not. The structure of this directory depends on local administration decisions.

/lib

This directory should hold those shared libraries that are necessary to boot the system and to run the commands in the root filesystem.

/mnt

is a mount point for temporarily mounted filesystems

/proc

This is a mount point for the proc filesystem, which provides information about running processes and the kernel.

/sbin

Like /bin, this directory holds commands needed to boot the system, but which are usually not executed by normal users.

/tmp

This directory contains temporary files which may be deleted with no notice, such as by a regular job or at system boot up.

/usr

This directory is usually mounted from a separate partition. It should hold only sharable, read-only data, so that it can be mounted by various machines running Linux.

/usr/X11R6

The X-Window system.

/usr/bin

This is the primary directory for executable pro grams. Most programs executed by normal users which are not needed for booting or for repairing the system and which are not installed locally should be placed in this directory.

/usr/bin/X11

is the traditional place to look for X11 executable's; on Linux, it usually is a symbolic link to /usr/X11R6/bin.

/usr/dict

This directory holds files containing word lists for spell checkers.

/usr/doc

You may find documentation about the installed software packages in this directory.

/usr/etc

Site-wide configuration files to be shared between several machines may be stored in this directory. However, commands should always reference those files using the /etc directory. Links from files in /etc should point to the appropriate files in /usr/etc.

/usr/include

Include files for the C compiler.

/usr/include/X11

Include files for the C compiler and the X-Windows system. This is usually a symbolic link to /usr/X11R6/include/X11.

/usr/include/asm

Include files which declare some assembler functions. This used to be a symbolic link to /usr/src/linux/include/asm.

/usr/include/linux

This contains information which may change from system release to system release and used to be a symbolic link to /usr/src/linux/include/linux to get at operating system specific information.

(Note that one should have include files there that work correctly with the current libc and in user space. However, Linux kernel source is not designed to be used with user programs and does not know anything about the libc you are using. It is very likely that things will break if you let /usr/include/asm and /usr/include/linux point at a random kernel tree. Debian systems don't do this and use headers from a known good kernel version, provided in the libc*-dev package.)

Include files to use with the GNU C++ compiler.

/usr/lib

Object libraries, including dynamic libraries, plus some executable's which usually are not invoked directly. More complicated programs may have whole subdirectories there.

/usr/lib/X11

The usual place for data files associated with X programs, and configuration files for the X system itself. On Linux, it usually is a symbolic link to /usr/X11R6/lib/X11

/usr/lib/gcc-lib

contains executable's and include files for the GNU C compiler.

/usr/lib/groff

Files for the GNU groff document formatting system.

/usr/local

This is where programs which are local to the site typically go.

/usr/local/bin

Binaries for programs local to the site go there.

/usr/local/doc

Local documentation

/usr/local/etc

Configuration files associated with locally installed programs go there.

/usr/local/lib

Files associated with locally installed programs go there.

/usr/local/info

Info pages associated with locally installed pro grams go there.

/usr/local/man

Manpages associated with locally installed programs go there.

/usr/local/sbin

Locally installed programs for system administration.

/usr/local/src

Source code for locally installed software.

/usr/man

Manpages traditionally go in there, into their sub directories.

/usr/sbin

This directory contains program binaries for system administration which are not essential for the boot process, for mounting /usr, or for system repair.

/usr/share

This directory contains subdirectories with specific application data, that can be shared among different architectures of the same OS. Often one finds stuff here that used to live in /usr/doc or /usr/lib or /usr/man.

/usr/share/man

Manpages go in there, into their subdirectories.

/usr/src

Source files for different parts of the system, included with some packages for reference purposes. Don't work here with your own projects, as files below /usr should be read-only except when installing software

/usr/src/linux

This has always been the traditional place where kernel sources were unpacked. This was important on systems that /usr/include/linux was a symlink here. You should probably use another directory for building the kernel now.

/usr/tmp

Obsolete. This should be a link to /var/tmp. This link is present only for compatibility reasons and shouldn't be used.

/var

This directory contains files which may change in size, such as spool and log files.

/var/adm

This directory is superseded by /var/log and should be a symbolic link to /var/log.

/var/backups

This directory is used to save backup copies of important system files.

/var/lock

Lock files are placed in this directory. The naming convention for device lock files is LCK.. where is the device's name in the filesystem. The format used is that of HDU UUCP lock files, i.e. lock files contain a PID as a 10-byte ASCII decimal number, followed by a newline character.

/var/log

Miscellaneous log files.

/var/preserve

This is where vi saves edit sessions so they can be restored later.

/var/run

Run-time variable files, like files holding process identifiers (PIDs) and logged user information (utmp). Files in this directory are usually cleared when the system boots.

/var/spool

Spooled (or queued) files for various programs.

/var/spool/at

Spooled jobs for at(1).

/var/spool/cron

Spooled jobs for cron

/var/spool/lpd

Spooled files for printing.

/var/spool/mail

Users' mailboxes.

/var/tmp

Like /tmp, this directory holds temporary files stored for an unspecified duration.