Re: [leaf-devel] 6.0.1 - shorewall init script

2017-01-05 Thread Tom Eastep
in the start > function of the init script but in the past was missing from > restart, reload e.t.c. > > It is _not_ a shorewall issue :-) Thanks Erich! - -Tom - -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his s

Re: [leaf-devel] 6.0.1 - shorewall init script

2017-01-05 Thread Tom Eastep
restart > > would be equivalent to $ svi serviceName stop ; svi serviceName > start > Beginning with Shorewall 5, there is a RESTART configuration option which may be set to 'reload' or 'restart'. Prior to Shorewall 5, 'shorewall restart' was not equivalent to 'shorewall stop &&

Re: [leaf-devel] shorewall

2015-10-01 Thread Tom Eastep
On 9/29/2015 11:58 PM, Erich Titl wrote: > Hi Tom > > Am 30.09.2015 um 03:36 schrieb Tom Eastep: >> On 9/29/2015 3:59 PM, Erich Titl wrote: >>> Hi Tom >>> >>> Am 30.09.2015 um 00:34 schrieb Tom Eastep: >>> ... >>> >>>> >&

Re: [leaf-devel] shorewall

2015-09-29 Thread Tom Eastep
o shorewall is supposed to load helpers when needed. > > Any bright ideas welcome AUTOHELPERS=Yes doesn't cause helpers to be loaded automatically, unless module autoloading is enabled. It rather associates each helper with its standard protocols and ports -- see the /etc/shorewall/conntrack fi

Re: [leaf-devel] Git

2014-12-16 Thread Tom Eastep
: Fehler beim Versenden einiger Referenzen nach 'ssh://et...@git.code.sf.net/p/leaf/bering-ucl Hi Erich, I'm seeing the same issue with the Shorewall Sourceforge Git repository. -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his

Re: [leaf-devel] Next branch: improvements

2012-04-17 Thread Tom Eastep
On 4/23/12 12:20 PM, Andrew wrote: - Andrew -- check your system clock - you are 6 days ahead of the rest of us :-) -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington

Re: [leaf-devel] microperl / OT

2010-11-21 Thread Tom Eastep
firewall builder on different hardware to not have perl on my systems. Do you package Shorewall-lite (and Shorewall6-lite) for Bering? Those products were developed to meet the needs of small appliances. -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline

Re: [leaf-devel] microperl / OT

2010-11-21 Thread Tom Eastep
On 11/21/10 8:16 AM, KP Kirchdoerfer wrote: I understand right, they don't require perl on the router? Correct. -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all

Re: [leaf-devel] grsecurity

2010-11-21 Thread Tom Eastep
not work with Shorewall Multi-ISP support but there was a busybox developer working on the problem. -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his

Re: [leaf-devel] Signed e-mail

2010-11-18 Thread Tom Eastep
apologize for any inconvenience this issue has caused you. Note that my e-mail is typically signed, and I have not noticed any issue with sending mails to the list. ?!? Same here -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully

Re: [leaf-devel] Fwd: Re: Bering-uClibc4: shorewall startup error on boot - further details

2010-10-28 Thread Tom Eastep
=1 /var/lib/shorewall/firewall version The patch at http://shorewall.git.sourceforge.net/git/gitweb.cgi?p=shorewall/shorewall;a=commitdiff;h=8758d3a834a4377669517372168c0bdd55eb37c5 should allow this to work regardless of whether VERBOSITY is exported or not. -Tom -- Tom Eastep\ When I die

Re: [leaf-devel] Fwd: Re: Bering-uClibc4: shorewall startup error on boot - further details

2010-10-28 Thread Tom Eastep
On 10/28/10 2:03 PM, KP Kirchdoerfer wrote: Thx for quick response! Am Donnerstag, 28. Oktober 2010, 22:03:31 schrieb Tom Eastep: On 10/28/10 12:28 PM, KP Kirchdoerfer wrote: The difference is the latest value for temp, as you may see. Let me know, if more info is needed. The problem

Re: [leaf-devel] Fwd: Re: Bering-uClibc4: shorewall startup error on boot - further details

2010-10-28 Thread Tom Eastep
On 10/28/10 2:13 PM, Tom Eastep wrote: On 10/28/10 2:03 PM, KP Kirchdoerfer wrote: Thx for quick response! Am Donnerstag, 28. Oktober 2010, 22:03:31 schrieb Tom Eastep: On 10/28/10 12:28 PM, KP Kirchdoerfer wrote: The difference is the latest value for temp, as you may see. Let me know

Re: [leaf-devel] Fwd: Re: Bering-uClibc4: shorewall startup error on boot - further details

2010-10-28 Thread Tom Eastep
On 10/28/10 3:07 PM, Tom Eastep wrote: On 10/28/10 3:03 PM, KP Kirchdoerfer wrote: Am Donnerstag, 28. Oktober 2010, 23:16:04 schrieb Tom Eastep: How about capturing the output of 'env' when starting Shorewall at boot? Here it is: USER=root HOME=/ TERM=linux SHOREWALL_INIT_SCRIPT=0

Re: [leaf-devel] LEAF v4: shorewall-perl

2010-06-21 Thread Tom Eastep
. Hi KP, Let me know if there is anything I can help with. -Tom -- Tom Eastep\ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net

Re: [leaf-devel] [Shorewall-users] v3.4.x problems on Bering-uClibc

2007-06-21 Thread Tom Eastep
/pub/shorewall/3.4/shorewall-3.4.4/errata/Shorewall/lib.tc And yes, it will work with Shorewall 3.4.3. Bering team: There's a patch in the errata/patches/Shorewall sub-directory. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net

[leaf-devel] [Fwd: [Shorewall-devel] Looking for a Maintainter for Shorewall-shell]

2007-05-11 Thread Tom Eastep
-- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key ---BeginMessage--- Taso Hatzi's post this evening has brought it home to me that I need

Re: [leaf-devel] TCRules in Bering-uClibc 3.0

2007-04-27 Thread Tom Eastep
0.0.0.0/0 -d 0.0.0.0/0 --dport 21 -j MARK --set-mark 2 Failed Processing /etc/shorewall/stop ... You cannot specify a port number with protocol = 'all'; the protocol must be either 'tcp' or 'udp' -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

[leaf-devel] [Fwd: [Shorewall-users] Shorewall 3.4.2]

2007-04-01 Thread Tom Eastep
-- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key ---BeginMessage--- While there are a couple of bug fixes here, the main reason

[leaf-devel] Shorewall-perl 3.9.0

2007-04-01 Thread Tom Eastep
This is the first development release of the new Perl-based compiler. It may be downloaded from: http://www1.shorewall.net/pub/shorewall/development/3.9/shorewall-perl-3.9.0/ ftp://ftp1.shorewall.net/pub/shorewall/development/3.9/shorewall-perl-3.9.0/ Release notes are attached. -Tom -- Tom

[leaf-devel] Amazing Result

2007-04-01 Thread Tom Eastep
I just installed stock shorewall-3.4.2 and shorewall-perl-3.9.0 under Cygwin on this Windows XP system. I downloaded the two-interface sample and modified shorewall.conf by adding SHOREWALL_COMPILER=perl. I copied a capabilities file from my desktop and: [EMAIL PROTECTED] ~/Configs/test $

Re: [leaf-devel] [Shorewall-users] Shorewall4

2007-03-28 Thread Tom Eastep
Simon Hobson wrote: Tom Eastep wrote: Eventually, I might break Shorewall into three pieces: - shorewall-common - shorewall-shell - shorewall-perl Now that does make sense. As such time as I do this (maybe as early as Shorewall 4.0.0), I will be looking for someone else to take over

[leaf-devel] Shorewall4

2007-03-24 Thread Tom Eastep
, -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key - Take

[leaf-devel] New Perl-based Compiler

2007-03-20 Thread Tom Eastep
as a testbed for the new compiler as I've done above (e.g., cd to that directory and specify . in your 'shorewall' commands). -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https

Re: [leaf-devel] [Shorewall-devel] New Perl-based Compiler

2007-03-20 Thread Tom Eastep
Tom Eastep wrote: My experimentation with a Perl-based compiler for Shorewall is beginning to bear fruit. Here is a timing from the main firewall at shorewall.net using the Perl-based compiler. That compiler generates a script that uses iptables-restore to configure Netfilter. [EMAIL

Re: [leaf-devel] [Shorewall-devel] New Perl-based Compiler

2007-03-20 Thread Tom Eastep
Tom Eastep wrote: I forgot one step: e) Create a symbolic link /usr/share/shorewall/Shorewall which points to the Directory containing the trunk/New files. On my system, I have: [EMAIL PROTECTED]:~/shorewall# ll /usr/share/shorewall/Shorewall lrwxrwxrwx 1 root root 33 2007-03-15 09:37

Re: [leaf-devel] New Perl-based Compiler

2007-03-20 Thread Tom Eastep
Natanael Copa wrote: Looks like you will need some modolues too, like File::Basename etc. (so a compiled microperl binary is not enough) The current code has very modest standard module requirements: File::Basename File::Temp Cwd Exporter -Tom -- Tom Eastep\ Nothing is foolproof

Re: [leaf-devel] libstdc++

2007-03-04 Thread Tom Eastep
enthusiasm for learning yet one more programming language to add to the dozen or so that I already speak is quite low. Thanks, -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key

[leaf-devel] Adopting iptables-restore to instantiate Shorewall rules

2007-02-28 Thread Tom Eastep
it. But it would be another compatibility issue. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

Re: [leaf-devel] Future of Shorewall

2007-02-25 Thread Tom Eastep
important, especially to those whose Shorewall-based firewalls require several minutes to restart. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net

[leaf-devel] Shorewall 3.4.0 RC3

2007-02-25 Thread Tom Eastep
so that the output of dump cannot be used to breach IPSEC security. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

Re: [leaf-devel] [Shorewall-devel] Future of Shorewall

2007-02-25 Thread Tom Eastep
will be minimal). So those who are happy with the current state of the package can continue to use it. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net

Re: [leaf-devel] [Shorewall-devel] Future of Shorewall

2007-02-25 Thread Tom Eastep
Mike Noyes wrote: I'd worry when distributions start dropping Shorewall. That's an indication of decline. Good point. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key

Re: [leaf-devel] [Shorewall-devel] Future of Shorewall

2007-02-25 Thread Tom Eastep
, it is getting more and more difficult to extend the code to do new things without breaking old things. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net

Re: [leaf-devel] Perl

2007-02-25 Thread Tom Eastep
denominator. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

Re: [leaf-devel] [Shorewall-devel] Future of Shorewall

2007-02-24 Thread Tom Eastep
in C or C++ but writing C/C++ code is what I've done for a living for years. I look at Shorewall as an opportunity to do something other than what I do in my professional life. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net

[leaf-devel] Future of Shorewall

2007-02-23 Thread Tom Eastep
-- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key - Take Surveys. Earn

[leaf-devel] Shorewall 3.4 Manpages now online

2007-01-13 Thread Tom Eastep
http://www1.shorewall.net/manpages/Manpages.html They will be replicated to the main site and other mirrors shortly. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https

Re: [leaf-devel] Shorewall 3.4.0 Beta 1

2007-01-12 Thread Tom Eastep
on the shorewall.net pages? I'll try to do that over the weekend. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

Re: [leaf-devel] Shorewall 3.4.0 Beta 1

2007-01-10 Thread Tom Eastep
of. The string 'orig' doesn't appear in install.sh and there are no .orig files in the tarballs. How is buildtool installing Shorewall? -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP

[leaf-devel] Shorewall 3.4.0 Beta 1

2006-12-28 Thread Tom Eastep
made to routing as a result of entries in /etc/shorewall/providers and /etc/shorewall/route_rules and reverses those changes when appropriate. Happy Beta Testing, -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington

[leaf-devel] New SVN Connection Method at Sourceforge

2006-12-04 Thread Tom Eastep
For those of you who use Shorewall SVN, please note that SF have implemented a new connection method. See: https://sourceforge.net/docs/E09#notice The makeshorewall script in SVN has been updated to use this new method. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently

Re: [leaf-devel] LEAF News Aggregated

2006-10-28 Thread Tom Eastep
-- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key - Using Tomcat

[leaf-devel] Shorewall 3.3.2

2006-10-01 Thread Tom Eastep
Mostly bug fixes in this one. The shorewall-lite footprint has become smaller as a result of splitting the former 'functions' file into two libraries: lib.base and lib.config. See the release notes for details. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool

[leaf-devel] Shorewall 3.3.1

2006-08-31 Thread Tom Eastep
-30 23:14 shorewall.conf -rw-r--r-- 1 teastep users 20835 2006-08-30 15:55 lib.actions -rw-r--r-- 1 teastep users 16895 2006-05-18 11:05 rules -rwxr-xr-x 1 teastep users 15556 2006-08-27 10:27 help [EMAIL PROTECTED]:~/ShorewallBuild/3.3 -Tom -- Tom Eastep\ Nothing is foolproof

Re: [leaf-devel] Shorewall 3.3.0

2006-08-28 Thread Tom Eastep
in as much as I don't believe that the average non-embedded Shorewall user is the least bit sensitive to the footprint issue. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https

[leaf-devel] Shorewall Code Bloat

2006-08-27 Thread Tom Eastep
teastep 13174 2006-06-21 16:51 macro.template [EMAIL PROTECTED]:~/shorewall/tags/3.0.8/Shorewall$ I have experimented with modularizing Shorewall so that features like traffic shaping, accounting, etc. can be made optional and I will continue to pursue that approach for Shorewall 3.4. -Tom -- Tom

Re: [leaf-devel] GNU Compliance (section 3) - are you compliant??

2006-07-18 Thread Tom Eastep
release Shorewall, all you release is source. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

[leaf-devel] Shorewall 3.2.0 is Available

2006-07-11 Thread Tom Eastep
3.2.0 are available at the main download site and at mirrors world wide. -Tom PS -- there are two release notes attached -- the first is for Shorewall; the second is for Shorewall Lite. -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net

Re: [leaf-devel] Encryption

2006-03-21 Thread Tom Eastep
. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key pgpVHD1Y6gt37.pgp Description: PGP signature

Re: [leaf-devel] Encryption

2006-03-21 Thread Tom Eastep
mature alternative. There is a 2.4 backport of the 2.6 ipsec stack available. NAT Traversal *is* supported. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https

[leaf-devel] Shorewall Has Migrated to SVN

2006-02-24 Thread Tom Eastep
Thanks to the work of Cristian Rodriguez, the Shorewall source repository at Sourceforge has been migrated from CVS to SVN. http://sourceforge.net/svn/?group_id=22587 Thanks Cristian! -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

[leaf-devel] Bering and 'awk'

2006-02-21 Thread Tom Eastep
Can I assume the presence of the 'awk' utility on LEAF/Bering systems? I'm trying to fix a bug and the fix is much easier and more robust if I use awk rather than a combination of other tools. Thanks, -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline

Re: [leaf-devel] Bering and 'awk'

2006-02-21 Thread Tom Eastep
. I'll use the less elegant fix then. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

[leaf-devel] Fwd: ipt_recent needs a maintainer!

2005-12-09 Thread Tom Eastep
--- -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key pgp4enOuOFCOB.pgp Description: PGP

Re: [leaf-devel] Fwd: Proposed Shorewall CVS changes

2005-07-04 Thread Tom Eastep
Paul Gear wrote: BTW, if anyone from the LRP side of things can tell me what i should be doing with Lrp* at the top of CVS, i'd be grateful. Paul, The .lrp is now built from the standard CVS tree -- you don't need to do anything special to accommodate LEAF going forward. -Tom -- Tom

[leaf-devel] What happens now?

2005-05-18 Thread Tom Eastep
-- that will keep folks busy coding for a while :-) -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

[leaf-devel] I quit.

2005-05-18 Thread Tom Eastep
the possiblilty that I would walk in front of a bus. ... and you have to admit that the price was right :-) Shorewall will always be a part of my life that I look back on with fondness. As always, -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

Re: [leaf-devel] What happens now?

2005-05-18 Thread Tom Eastep
the list settings shouldn't need much tweaking. Ok -- I appreciate the offer to help. Let's wait until SF have upgraded then hopefully we can move the lists pretty much intact over there. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

Re: [leaf-devel] What happens now?

2005-05-18 Thread Tom Eastep
Mike Noyes wrote: On Wed, 2005-05-18 at 09:22, Tom Eastep wrote: Mike Noyes wrote: I don't mind continuing to host the mailing lists here for a while until mailing lists can be reestablished at SF (they were there once upon a time). The SF staff will even import your pipermail archive, so

[leaf-devel] Re: what to do about shorewall?

2005-05-18 Thread Tom Eastep
that it is always available. -Tom PS -- I've subscribed myself to the leaf-devel list again so I can help with this transition. -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https

[leaf-devel] Re: [Shorewall-devel] What happens now?

2005-05-18 Thread Tom Eastep
Cristian Rodriguez wrote: 2005/5/18, Tom Eastep [EMAIL PROTECTED]: - We need to look at the big issues and make sure we've got a good handle on them. For me, these include (in rough order of priority from my perspective): * Multiple ISPs load balancing * Features to enable building

Re: [leaf-devel] Re: [Shorewall-devel] What happens now?

2005-05-18 Thread Tom Eastep
. Ok -- I think I have a place where we can host an rsync server for the mirrors; I'll continue this thought in another thread. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key

[leaf-devel] Re: [Shorewall-devel] What happens now?

2005-05-18 Thread Tom Eastep
out from here, the better. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key

[leaf-devel] Re: Shorewall 2.3 and Bering

2005-05-04 Thread Tom Eastep
K.-P. Kirchdörfer wrote: Am Dienstag, 3. Mai 2005 00:53 schrieb Tom Eastep: I'm about to start development on Shorewall 2.3. Given that Paul has integrated Shorewall into the Bering buildtool environment, I propose that beginning with Shorewall 2.3, I no longer provide Bering packages. Any

[leaf-devel] Shorewall 2.3 and Bering

2005-05-02 Thread Tom Eastep
I'm about to start development on Shorewall 2.3. Given that Paul has integrated Shorewall into the Bering buildtool environment, I propose that beginning with Shorewall 2.3, I no longer provide Bering packages. Any thoughts? -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-12 Thread Tom Eastep
-- here is a patch that reflects what I think they should be. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key diff -au /home

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-11 Thread Tom Eastep
in sync with the /Shorewall2 project on a daily basis so if you need that project updated, please let me know. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-11 Thread Tom Eastep
Tom Eastep wrote: All this having been said, I haven't yet started using the LrpN project again since 2.2.0 as I haven't officially opened a 2.3 development release. Also, I don't maintain the LrpN/ project in sync with the /Shorewall2 project on a daily basis so if you need that project

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-11 Thread Tom Eastep
the directory tree. That's what is done when I build the .rpm. Note the PREFIX environmental variable -- allows installing in a directory other than /. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-11 Thread Tom Eastep
configuration for two-interface firewall (standard has no default config -- uses sample configurations which are overloaded). b) start.d and stop.d for scripts owned by other packages. c) shorewall.conf has different defaults. e) start and stop run all scripts in start.d and stop.d respectively. -Tom -- Tom

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-11 Thread Tom Eastep
Paul Traina wrote: Tom Eastep wrote: Paul Traina wrote: Tom Eastep wrote: Would you be willing to refresh the lrp version /etc files to match what you believe they should be? The files in LrpN/etc/shorewall are what I think that the files should look like as of today's development

Re: [leaf-devel] how is shorwall.lrp produced for Bering uClibc?

2005-04-11 Thread Tom Eastep
Tom Eastep wrote: Thanks -- I note that KP had added another change to the rules file in LrpN which I hadn't included in my patch. Something to do with dnsmasq... Ok -- I took a look at that and it has to do with DHCP -- I personally think that a better approach is to set the 'dhcp' option

Re: [leaf-devel] A new developer

2004-12-28 Thread Tom Eastep
. Welcome, Andrea! -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key --- SF email

Re: [leaf-devel] Sourceforge Mailing List SPF Problems

2004-11-29 Thread Tom Eastep
On Mon, 2004-11-29 at 11:31 -0800, Mike Noyes wrote: On Mon, 2004-11-29 at 11:10, Tom Eastep wrote: In case you are unaware, the current SPF configuration of lists.sourceforge.net is hosed. As a result, SPF-aware MTAs are rejecting all list traffic. There are many open trouble reports

Re: [leaf-devel] Sourceforge Mailing List SPF Problems

2004-11-29 Thread Tom Eastep
On Mon, 2004-11-29 at 12:32 -0800, Mike Noyes wrote: On Mon, 2004-11-29 at 11:33, Tom Eastep wrote: At http://sourceforge.net/tracker/index.php, I see SPF mentioned 6 times (including my own report). Tom, Thanks for the aid. I'll monitor it. https://sourceforge.net/support

Re: [leaf-devel] Sourceforge Mailing List SPF Problems

2004-11-29 Thread Tom Eastep
On Mon, 2004-11-29 at 12:32 -0800, Mike Noyes wrote: Either way, your SR should be attended to by one of the SF staff members shortly. No particular hurry -- I've turned off SPF screening in my MTA until the problem is resolved. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently

[leaf-devel] Re: [leaf-user] Shorewall rfc1918 list

2004-09-23 Thread Tom Eastep
The 1.4 rfc1918 file and 2.x bogons file are maintained in parallel but users still need to download and install the updates. See the top of http://shorewall.net/errata.htm -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington

[leaf-devel] Re: [leaf-user] Traceroute issues through Bering 1.2

2004-09-22 Thread Tom Eastep
On Tuesday 21 September 2004 13:14, Tom Eastep wrote: So I think the above link is in error. Unless there is a different UDP traceroute that I don't know of... ? The 'traceroute' program on any *nix system. The 'tracert' thingy on Windoze systems uses ICMP echo-request (ping

Re: [--ot] [leaf-devel] leaf-tools overview (cdb, trig, tmpl)

2004-07-06 Thread Tom Eastep
but will enhance the chance to use different interpreters. So which constructs do you propose that we do away with? -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED

Re: [leaf-devel] Source: config

2004-07-05 Thread Tom Eastep
; nevertheless, I'll try to follow the discussion. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] --- This SF.Net email sponsored by Black Hat Briefings

Re: [leaf-devel] leaf-tools overview (cdb, trig, tmpl)

2004-07-05 Thread Tom Eastep
that Shorewall works with it. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] --- This SF.Net email sponsored by Black Hat Briefings Training. Attend

Re: [leaf-devel] Shorewall: leaf scripting package format

2004-07-04 Thread Tom Eastep
requires people to do something differently. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] --- This SF.Net email sponsored by Black Hat

Re: [leaf-devel] New Website IE

2004-07-03 Thread Tom Eastep
Ray Olszewski wrote: It is important, I think, to keep these two sets of issues distinct, not to bounce from one to the other arbitrarily. You're right Ray -- I'll go back in my cave. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

Re: [leaf-devel] New Website IE

2004-07-02 Thread Tom Eastep
know who I think would mistakenly get blamed. If we would just admit that .lrp files are nothing more than stylized gzip-compressed tar files and change their extension to .tgz, we wouldn't have this problem. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline

Re: [leaf-devel] New Website IE

2004-07-02 Thread Tom Eastep
Ray Olszewski wrote: At 06:58 PM 7/2/2004 -0700, Tom Eastep wrote: The .lrp extension isn't the problem. It requires only a 1-line addition to an Apache config file. No big deal to do, and we get the same order of magnitude improvement. Ray, it is the dozens of 1-line differences

Re: [leaf-devel] New Website

2004-05-16 Thread Tom Eastep
the nav bar stand out for you. Given that it is both dark and tiny, it does not stand out at all. Under Firefox on my 19 monitor, Bering uClibc is only about 2/3 wide and is almost unreadable. Lince *is* unreadable. I agree with KP that the Releases/Branches menu should return. -Tom -- Tom Eastep

Re: [leaf-devel] New Website

2004-05-16 Thread Tom Eastep
know if it is acceptable now. New navbar: http://leaf.steinkuehler.net/ Old navbar: http://leaf.steinkuehler.net/bering/ *Much* better, Mike Thanks! -Tom PS -- I'm not using the Bitstream Vera fonts. -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline

Re: [leaf-devel] New Website

2004-05-16 Thread Tom Eastep
K.-P. Kirchdörfer wrote: it's readable with Mozilla (anyway my Mozilla fonts are ugly) When you download Mozilla (or Firefox), be sure to download the GTK2/Xft version; with the standard version, the fonts suck... -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool

Re: [leaf-devel] problem starting shorewall on a iptable modularized kernel 2.4.24

2004-05-03 Thread Tom Eastep
0 ide-detect 144 0 (unused) ide-core 89424 0 [ide-disk ide-detect] What am I missing? The error message refers to the iptables TOS module, not the kernel module. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

Re: [leaf-devel] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-14 Thread Tom Eastep
to the swconf.lrp package. If only shorewall.lrp is installed then the file will go to shorewall.lrp. Ok -- now I understand. Thanks, -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED

Re: [leaf-devel] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-13 Thread Tom Eastep
/shorewalluser get populated initially? -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials

Re: [leaf-devel] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-13 Thread Tom Eastep
way for me to add a new config file in the future and have it reflected in the Shorewall configuration menu. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED

Re: [leaf-devel] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-13 Thread Tom Eastep
). - I don't have a lot of time for development (8 month old twins!) - I don't want to pull the rug out from under the new configuration scheme and hopefully a more full-featured packaging system. Nod. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http

[leaf-devel] Re: [Shorewall-devel] Re: [Shorewall-users] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-10 Thread Tom Eastep
$CONFIG_PATH] || CONFIG_PATH=/etc/shorewall:/usr/share/shorewall changed it to: [ -n $CONFIG_PATH ] || CONFIG_PATH=/etc/shorewall:/usr/share/shorewall Maybe it has to do with the version of sh/bash: Just a plain ordinary bug -- thanks. I've updated CVS with the correction. -Tom -- Tom Eastep\ Nothing

Re: [leaf-devel] Re: [Shorewall-devel] Re: [Shorewall-users] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-10 Thread Tom Eastep
Tom Eastep wrote: Stijn Jonker wrote: It works fine here after a small modification in firewall on line 5757: Loading /usr/share/shorewall/functions... Processing /etc/shorewall/params ... Processing /etc/shorewall/shorewall.conf... /usr/share/shorewall/firewall: line 5757: [: missing

[leaf-devel] Re: [Shorewall-users] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-09 Thread Tom Eastep
on the heals of 2.0 (it's a *big* change in the documentation so it would have to be a major releae). I'd also be willing to wave the 2 major release support rule and continue to support 1.4 until 2.2 is released. Opinions? -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool

[leaf-devel] Re: [Shorewall-users] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-09 Thread Tom Eastep
: For compatibilty, the default value is: $SHOREWALL_DIR:/etc/shorewall/:/usr/share/shorewall SHOREWALL_DIR is the configuration directory specified by the -c command option or named explicitly in the 'try' command. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline

[leaf-devel] Re: [Shorewall-users] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-09 Thread Tom Eastep
Tom Eastep wrote: Ok -- how about a CONFIG_SEARCH option in shorewall.conf: For compatibilty, the default value is: $SHOREWALL_DIR:/etc/shorewall/:/usr/share/shorewall SHOREWALL_DIR is the configuration directory specified by the -c command option or named explicitly in the 'try' command

[leaf-devel] Re: [Shorewall-devel] Re: [Shorewall-users] Feature Request: Shorewall 2.0 LocalConfDir

2004-04-09 Thread Tom Eastep
Tom Eastep wrote: The nice thing about this proposal is that I could implement it now in a minor release and we could hold off until next year to implement the more radical proposal (no files released directly to /etc/shorewall). The code in CVS (Shorewall2/) supports this notion. Be sure

  1   2   >