Re: Opinion on firewall virtualization with Xen

2006-11-22 Thread Rene Mayrhofer
Am Mittwoch, 22. November 2006 10:28 schrieb Abel Martín: I'd like to hear your opinion on xenifying several Debian boxes that run iptables to offer independent and isolated configuration for different networks. Would it be mad setting up a dom0 with a large number of domUs inside it to

Re: ssh connection survives reboot of stateful iptables router

2006-07-04 Thread Rene Mayrhofer
Am Monday 03 July 2006 22:52 schrieb martin f krafft: I was surprised today to find an SSH connection from my LAN to the 'Net surviving a power cycle of my router -- a laptop running sarge with kernel 2.6 and iptables. I have the following two rules first thing in the FORWARD chain: -A

Re: How to kill DNAT'ed connection

2006-06-09 Thread Rene Mayrhofer
Am Friday 09 June 2006 08:29 schrieb Покотиленко Костик: This problem now solved using only iptables rules. If anybody interested in details let me know. Yes, please share your solution - it will certainly be interesting to at least a few people and is always good to have in the archives. with

Re: Multiple LAN's through one vpn

2006-03-10 Thread Rene Mayrhofer
Am Friday 10 March 2006 09:20 schrieb Sturla Holm Hansen: Hi there, I have a problem with the following scenario: I have 5 customers in 1 building sharing 1 SHDSL-line, each of them have their own router behind the main router to segment the net and now they want VPN. The problem is that they

Re: Changes to /etc/init.d/networking

2001-04-14 Thread Rene Mayrhofer
Would it be recomended to execute an IPTables script via the networking init script? I am starting it via a pre-up statement from /etc/network/interfaces. Rene

Re: Ipsec behind linux FireWall

2000-11-29 Thread Rene Mayrhofer
Jean-François JOLY wrote: Hello all, I'm currently working on VPNs, I just wonder if it's possible to set up an Ipsec server behind a Linux FireWall. The question is: is the Linux Kernel able to forward IP protocols (AH+IKE if I remember well ...) he don't understand ? Yes, this is

Re: Newbie, someone have how-to on from-scratch Debian firewall?

2000-11-08 Thread Rene Mayrhofer
IML-debian-firewall wrote: Howdy, Does someone have some notes to share on a from-scratch install of Debian for firewall purposes? For those that don't know Debian install and barely know Linux? I know this may be asking a lot, but I'm sure that I'm not the only one who would benefit.

upcoming Gibraltar release (Debian-based firewall distribution)

2000-10-10 Thread Rene Mayrhofer
Hi all I was told that not everybody who is interested in firewalling with Debian is subscribed to debian-firewall. Therefore I would like to introduce my Debian-based firewall distribution 'Gibraltar'. It boots from a live CD-ROM and therefore does not have to be installed on a harddisk,

Gibraltar ISO images version 0.90pre1 available

2000-07-31 Thread Rene Mayrhofer
Hi all Since there was that much interest in Gibraltar, I have made a pre-version of Gibraltar 0.90 available. You can find it under ftp://ftp.vianova.at/pub/gibraltar/iso-images/ This is a pre-release. It works for me on my system, it might not work for you. Please let me know of all problems

Re: modifying boot floppies to do a firewall only install.

2000-07-30 Thread Rene Mayrhofer
Mircea Luca wrote: Bernd Eckenfels wrote: On Wed, Jul 26, 2000 at 05:17:35AM +0800, [EMAIL PROTECTED] wrote: I just (subscribed and) posted a similar query to debian-user - does anyone know of an existing project along these lines or should I go ahead and start one?: We

Re: modifying boot floppies to do a firewall only install.

2000-07-30 Thread Rene Mayrhofer
Mircea Luca wrote: Rene Mayrhofer wrote: Please have a look at http://gibraltar.vianova.at/ It describes my Debian-based firewall project. ISO images of the first beta version will be available in a few days (if nothing unexpected happens until then). If you have any questions

URGENT: Problem with source-based routing and masquerading.

1999-12-14 Thread Rene Mayrhofer
it be that the source address is generated from the routing table (in this case: the default route for packets from interface lo points to another interface) and not set the same as the address that the ping was sent to ??? Thanks Rene Mayrhofer

Re: Should I propose a Debian Firewall?

1999-11-30 Thread Rene Mayrhofer
Tim Sailer wrote: On Mon, Nov 29, 1999 at 04:35:47PM +, Rene Mayrhofer wrote: Kiss Csaba wrote: What type of your firewall ? Packet-filtering or proxy-based or statefull or other In principle it is open to any concept. We use a combination of packet-filtering (standard linux

Re: Should I propose a Debian Firewall?

1999-11-29 Thread Rene Mayrhofer
Kiss Csaba wrote: Hi all, What type of your firewall ? Packet-filtering or proxy-based or statefull or other In principle it is open to any concept. We use a combination of packet-filtering (standard linux kernel) and proxies (e.g. for ftp which is a nightmare to packet-filter). But if

Re: VPN to a host behind the firewall

1999-11-26 Thread Rene Mayrhofer
Jarle Aase wrote: Thanks for your reply. If it was up to me, they would not be running NT at all :) The decision to use NT as the VPN server is not mine, - I'm just asked to find a technical solution. If GRE tunneling is possible, that seems like a easy and safe way to do it. The

Re: VPN to a host behind the firewall

1999-11-25 Thread Rene Mayrhofer
Jarle Aase wrote: I have a firewall running Linux 2.12 kernel with patch from kerneli.org, Debian Slink (latest stable) and ipchains 1.3.9 (compiled from the original source). The setup is like this: Internal net, non-legal IP series, masqueraded | |