Question about linux firewall

2000-02-25 Thread Frank Oh
I want to setup up our department firewall as "packet filtering firewalls" and "application proxy server" so that I could block certain network packets and log everything what people are doing. Here are our situation: Internet --- OSU/router --- gateway (xxx.xxx.67.1) --- Firewall --- WS/s

SANE 2000 program details and registration - May 22-25, 2000

2000-02-25 Thread Fred Donck
At the SANE 2000 web site ( http://www.nluug.nl/sane/ ) you will find full program details, on-line registration, hotel information reservation forms, travel information and much more, regarding the SANE 2000 conference.

Satan Error

2000-02-25 Thread aaron ma
I apologize if I have posted a question on a wrong list. When I compile sata, I have the following error, any suggestion? I have put /usr/local/bin on the top of PATH # make sunos5 cd src/misc; make "LIBS=-lsocket -lnsl" "XFLAGS=-DAUTH_GID_T=gid_t -DTIRPC" "RPCGEN=rpcgen" cd src/boot; make

RE: A Newbee.What's a Proxy Server

2000-02-25 Thread C.C. Venkataraghavan
Mr. Yepes Just because you happen to be from Houston or some goddamn part of the United States doesnt make you an authority on the English language. And even if someone from a third world country like ours does make a mistake in spelling a couple of words, I dont think you had to be such a

Is this working....Test

2000-02-25 Thread Blanco, Juan
This is a test...I send two messagess and not response. Tony Blanco UJA-Federation * \\\|/// \\ - - // ( @ @ ) -oOOo-(_)-oOOo

RE: Is this working....Test

2000-02-25 Thread Rainbow, Neil
Yes. Neil Rainbow London Network Controller Amerada Hess Limited DDI: 0171 887 2363 e-mail: [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] -Original Message- From: Blanco, Juan [SMTP:[EMAIL PROTECTED]] Sent: 25 February 2000 13:53 To: '[EMAIL

FW1 and the CVP For URL Filtering

2000-02-25 Thread Magowan, Richard M. \(ITS\)
I have heard conflicting information regarding Checkpoint's performance/reliability using the UFP facilities to filter URL content. I am using a fully patched version of CPFW on a high-end UNIX system w/T3 Internet connection and about 4~5000 users. There is a LOT of web activity. I want to

Load balancing.......

2000-02-25 Thread Blanco, Juan
Folks, Any idea or best solution how to do the following: 1 - To have connectivity to two different isp. 2 - Be able to use only one firewall (checkpoint) 3 - One connectivity via a T1 and the second via a DSL 4 - This should be transparent to the users. I really appreciate you help

Checklist for hardening Netscape Entreprise Server on HP and AIX UNIX??

2000-02-25 Thread mssjim
Request for checklist (security set-up guides) for hardening Netscape Enterprise Server running on UNIX platform (HP, AIX or Solaris)?? What is the the most updated patches for NES ver 3.x or iPlanet 4.x? Where can I find such security information? Many thanks again - [To unsubscribe,

DSL agreement forbids portscanning, etc.

2000-02-25 Thread Michael E. Cummins
I know some people are tired of the port-scanning/doorknobs thread, but I still find the ethical discussions that relate to what I put my firewalls up for in the first place to be interesting. That's the great thing about newsgroups, you only have to follow the threads that you want to. :) I

RE: Load balancing.......

2000-02-25 Thread Pepmiller, Craig E.
Assumptions: 1)You are assigned at least one ip address from each ISP. 2)Your use of the Internet involves a range of outside addresses- i.e. you do not primarily communicate with one outside host. Put a router outside the firewall. The router should have one connection to each

RE: Load balancing.......

2000-02-25 Thread Erwin Geirnaert
Folks, Any idea or best solution how to do the following: 1 - To have connectivity to two different isp. 2 - Be able to use only one firewall (checkpoint) 3 - One connectivity via a T1 and the second via a DSL 4 - This should be transparent to the users. Maybe a Cisco router

VPN Products

2000-02-25 Thread Andy Maslar
Greetings all, I'm in need of a VPN solution for a very small business (5-box LAN). They want the ability to mount network drives on remote win 98 clients using Internet connectivity, not dial-in RAS. The LAN includes Win 98 and a Novell box that runs some property management software. They

RE: Load balancing.......

2000-02-25 Thread Michael E. Cummins
I would love to hear comments on this topic. Yesterday I tried using two different firewall/routers, one hooked to a DSL connection and the other hooked to two POTS lines with dial up accounts. I intended to use the two firewall/routers as gateways, the DSL firewall/router also offering DHCP

RE: VPN Products

2000-02-25 Thread Michael E. Cummins
Talk to the nice people at RampNet ( http://www.rampnet.com ) -- or surf their site. I think you will be pleasantly surprised. The 700s is an affordable firewall/router/DHCP server that can be firmware upgraded to support VPN. If you buy their stuff, let them know "Advantage Services"

Re: VPN Products

2000-02-25 Thread Jim
Well, because they all ready have the OpenBSD box there, you might as well use that and do it all for no cost. Look at http://www.secureops.com/resources/vpn/ and http://www.codetalker.com/greenbox/docs/vpn-24-minifaq.html and http://www.openbsd.org/faq/faq13.html for information on how to do

RE: TO ALL (fwd)

2000-02-25 Thread Micheal Espinola Jr
To: All Since the initial posting on the 18th, I waited 6 days before being an ass myself in response. I ASSuMEd hat because there had been no public rebuttal to the original, that it would be safe to do so. I think we all know how the expression goes. Apparently Mr Yepes did indeed send a

Load Balancing (Enough Already)

2000-02-25 Thread Christopher Adams, Sr.
I have not been able to read all of the opinions on this subject. I think people are expending too much effort to something that is easily achieved. I also hope that I am interpreting the original question correctly. 'Load Balancing' is a difficult objective. How about just distributing

RE: VPN Products

2000-02-25 Thread Dean A. Luethje
Greetings All! First, let me say thank you to all of you who share your knowledge and experience so willingly. This list is a great learning tool for me and I'm sure many others! I have some interest in the threads that address products such as the RampNet 700s listed below, so I went to their

RE: Load balancing.......

2000-02-25 Thread Pepmiller, Craig E.
The problem with two gateways at the client: The client uses the top gateway until it can not reach that gateway. The DSL firewall/router looses connection to the outside world but still responds at 10.0.0.150. Thus the client thinks the path is ok even when the router is discarding all

RE: Load balancing.......

2000-02-25 Thread Patrick
You could try VRRP on the routers or HSRP which ever is supported. Patrick . -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Pepmiller, Craig E. Sent: 25 February 2000 15:45 To: 'Michael E. Cummins'; Firewalls Mailing List Subject:

Re: Load Balancing (Enough Already)

2000-02-25 Thread It's The Zoooomer
The only problem with Round Robin load balancing is stickiness... What happens when you load something in a shopping cart and the secure server goes belly up and another one takes over.. Do you re-authenticate...? Robert --- "Christopher Adams, Sr." [EMAIL

Re: Load Balancing (Enough Already)

2000-02-25 Thread Ryan Russell
On Fri, 25 Feb 2000, It's The Zmer wrote: The only problem with Round Robin load balancing is stickiness... What happens when you load something in a shopping cart and the secure server goes belly up and another one takes over.. Do you re-authenticate...? For that type of

RE: TO ALL (fwd)

2000-02-25 Thread C.C. Venkataraghavan
I join Micheal Espinola in apologizing to Mr. Yepes and as was the case with Michael, I also did not receive the e-mail which Mr.Yepes apparently sent soon after he discovered the mischief and in which he claims he clarified things. Let us all call it quits now and I am sure each of us believes

RE: VPN Products

2000-02-25 Thread Michael E. Cummins
I do not know much at all about the SonicWall products, but I know that RampNet has been around for some time, and their products are their own. I bought their very first WebRamp several years ago when I was an admin in Northern California. (Now I am in South Florida) Michael -Original

Re: Load balancing.......

2000-02-25 Thread Carric Dooley
Nokia firewall running BGP. BAM!!! Carric Dooley Network Security Consultant "A little inaccuracy sometimes saves a ton of explanation. " - H. H. Munro (Saki) (1870-1916) - Original Message - From: Blanco, Juan [EMAIL PROTECTED] To: '[EMAIL PROTECTED]' [EMAIL PROTECTED] Cc: [EMAIL

Internet Sharing Device or Dedicated Proxy?

2000-02-25 Thread Alcratin
This may seem rather like a fundamental question. I have a small file-sharing network of about 15 users that is about to be hooked up to the net using a DSL router, do I neccessarily need to have a proxy server in place for my DHCP and firewall, or can I get by with an internet sharing

Re: Internet Sharing Device or Dedicated Proxy?

2000-02-25 Thread John Adams
http://www.linuxrouter.org One Disk router/NAT/DHCP/SOCKS, etc. Very easy to set up. -john On Fri, 25 Feb 2000 [EMAIL PROTECTED] wrote: This may seem rather like a fundamental question. I have a small file-sharing network of about 15 users that is about to be hooked up to the net

Re: Load Balancing (Enough Already)

2000-02-25 Thread Jonathon William Ross
This can cause problems if you are using stateful filtering. Products such as PIX, however, can work in a redundant fashion. This means if one PIX falls over, the other PIX takes over it's states. However, firewalls are not for high-tech load balancing. Look at Cisco LocalDirector and

Re: Oracle Client

2000-02-25 Thread David J. Cavuto
Madhur, The Oracle SQL*Net protocol, though technically proprietary, is fairly well understood and is parsed by several firewalls to be able to open and close ports at the correct times. SQL*Net v2 (also known as the Transparent Network Substrate or TNS -- and recently replaced by the moniker