Re: [Lug-bg] iptables, NAT and PPTP

2009-02-12 Thread Kamen Medarski
-bulgaria.org] On Behalf Of Nickola Kolev Sent: Tuesday, February 03, 2009 9:38 PM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Здравей, L2TP наистина иска порт 1701, но не съм сигурен какво се получава при NAT/маскиране. IPSec от своя страна, иска отворени порт 500

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-04 Thread Svetlin Nakov
[mailto:lug-bg-boun...@linux-bulgaria.org] On Behalf Of Nickola Kolev Sent: Tuesday, February 03, 2009 9:38 PM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Здравей, L2TP наистина иска порт 1701, но не съм сигурен какво се получава при NAT/маскиране. IPSec от своя страна

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Svetlin Nakov
Activities National Academy for Software Development http://academy.devbg.org _ From: lug-bg-boun...@linux-bulgaria.org [mailto:lug-bg-boun...@linux-bulgaria.org] On Behalf Of Danail Petrov Sent: Monday, February 02, 2009 9:47 PM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Svetlin Nakov
: [Lug-bg] iptables, NAT and PPTP Здрасти, Пробвай с едно: lsmod | grep ip_nat_pptp Ако няма такъв модул, зареди го с: modprobe ip_nat_pptp И виж какво се случва. On Mon, 2 Feb 2009 20:32:42 +0200 Svetlin Nakov svet...@nakov.com wrote: Здравейте, [ cut ] Някой имал ли е такъв проблем и знае

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Nickola Kolev
-bulgaria.org [mailto:lug-bg-boun...@linux-bulgaria.org] On Behalf Of Nickola Kolev Sent: Monday, February 02, 2009 10:17 PM To: lug-bg@linux-bulgaria.org Subject: Re: [Lug-bg] iptables, NAT and PPTP Здрасти, Пробвай с едно: lsmod | grep ip_nat_pptp Ако няма такъв модул, зареди го с

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Georgi Chorbadzhiyski
Svetlin Nakov wrote ... , On 2/3/09 10:57 AM: Ами въпросният модул го няма: [r...@border-router tmp]# lsmod | grep ip_nat_pptp [r...@border-router tmp]# modprobe ip_nat_pptp modprobe: Can't locate module ip_nat_pptp Аз съм с kernel 2.4.20 (Red Hat Linux 3). Как мога да добавя този модул?

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Svetlin Nakov
да пачвам кърнела? Наков -Original Message- From: lug-bg-boun...@linux-bulgaria.org [mailto:lug-bg-boun...@linux-bulgaria.org] On Behalf Of Georgi Chorbadzhiyski Sent: Tuesday, February 03, 2009 11:18 AM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Nickola Kolev
[mailto:lug-bg-boun...@linux-bulgaria.org] On Behalf Of Georgi Chorbadzhiyski Sent: Tuesday, February 03, 2009 11:18 AM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Svetlin Nakov wrote ... , On 2/3/09 10:57 AM: Ами въпросният модул го няма: [r...@border

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Danail Petrov
To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Здрасти, Можеш да прочетеш отговорите ми по-долу. На Tue, 3 Feb 2009 14:03:42 +0200 Svetlin Nakov svet...@nakov.com написа: Ами да, наистина и аз стигнах до тази идея. Обаче трябва да мигрирам и всички настройки: dns

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Marian Marinov
: Tuesday, February 03, 2009 2:49 PM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Здрасти, Можеш да прочетеш отговорите ми по-долу. На Tue, 3 Feb 2009 14:03:42 +0200 Svetlin Nakov svet...@nakov.com написа: Ами да, наистина и аз стигнах до тази идея. Обаче

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Danail Petrov
- Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Здрасти, Можеш да прочетеш отговорите ми по-долу. На Tue, 3 Feb 2009 14:03:42 +0200 Svetlin Nakov svet...@nakov.com написа: Ами да, наистина и аз стигнах до тази идея. Обаче трябва да мигрирам и всички настройки: dns settings, routing

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Svetlin Nakov
Message- From: lug-bg-boun...@linux-bulgaria.org [mailto:lug-bg-boun...@linux-bulgaria.org] On Behalf Of Nickola Kolev Sent: Tuesday, February 03, 2009 2:49 PM To: Linux Users Group - Bulgaria Subject: Re: [Lug-bg] iptables, NAT and PPTP Здрасти, Можеш да прочетеш отговорите ми по-долу. На Tue, 3

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-03 Thread Peter Pentchev
On Tue, Feb 03, 2009 at 10:05:02PM +0200, Danail Petrov wrote: Marian Marinov wrote: Мариян On Tuesday 03 February 2009 21:04:53 Svetlin Nakov wrote: Благодаря за насоките, Никола. Мисля, че ще е по-лесно да накарам отсрещната страна да минем на L2TP/IPSec VPN. Той иска

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-02 Thread Danail Petrov
Здрасти, не съм много в час за това как точно кернела транслира GRE пакетите (със сигурност не прави стандарното маскиране/транслиране, тъй като това не е TCP/UDP протокол и той няма src/dst port), но имаш ли този модул зареден |ip_masq_pptp.o| (или в ядрото)? Svetlin Nakov wrote:

Re: [Lug-bg] iptables, NAT and PPTP

2009-02-02 Thread Nickola Kolev
Здрасти, Пробвай с едно: lsmod | grep ip_nat_pptp Ако няма такъв модул, зареди го с: modprobe ip_nat_pptp И виж какво се случва. On Mon, 2 Feb 2009 20:32:42 +0200 Svetlin Nakov svet...@nakov.com wrote: Здравейте, [ cut ] Някой имал ли е такъв проблем и знае ли как се оправя? В Интернет

Re: [Lug-bg] iptables blocklist

2007-09-04 Thread Georgi Alexandrov
Bozhidar Maramski wrote: Ако женати се чука с друг или нямаш пет лева в джоба не съм ти виновен Избивай си го или си го набивай на друго място Мерси за поздравите, много си учтив. Наистина е по-добре да се занимаваш с двигатели с вътрешно горене. Малко обяснения: snip Наистина е така: Кое

Re: [Lug-bg] iptables blocklist

2007-09-04 Thread Peter Pentchev
On Tue, Sep 04, 2007 at 10:43:50AM +0300, Georgi Alexandrov wrote: Bozhidar Maramski wrote: Ако женати се чука с друг или нямаш пет лева в джоба не съм ти виновен Избивай си го или си го набивай на друго място Мерси за поздравите, много си учтив. Наистина е по-добре да се занимаваш с

Re: [Lug-bg] iptables blocklist

2007-09-04 Thread Georgi Alexandrov
Peter Pentchev wrote: snip Само като идея - хората и xargs са измислили :) xargs dig +short /tmp/blacklist | sudo xargs -n 1 ip route add prohibit snip Прав си. Даже сега като се загледах видях, че dig има и '-f' опция. -- regards, Georgi Alexandrov key server - pgp.mit.edu :: key id -

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Georgi Chorbadzhiyski
Around 09/03/07 11:23, [EMAIL PROTECTED] scribbled: Hi, можеш да използваш и iproute2 [EMAIL PROTECTED] ip route add prohibit 209.10.26.51 [EMAIL PROTECTED] ssh 209.10.26.51 ssh: connect to address 209.10.26.51 port 22: No route to host [EMAIL PROTECTED] tcpdump -nnq -i eth2 tcpdump:

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread boikov
Hi, можеш да използваш и iproute2 [EMAIL PROTECTED] ip route add prohibit 209.10.26.51 [EMAIL PROTECTED] ssh 209.10.26.51 ssh: connect to address 209.10.26.51 port 22: No route to host [EMAIL PROTECTED] tcpdump -nnq -i eth2 tcpdump: listening on eth2 22:13:13.740406 192.168.99.35.51973

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Vasil Kolev
В пн, 2007-09-03 в 11:35 +0300, Georgi Chorbadzhiyski написа: Around 09/03/07 11:23, [EMAIL PROTECTED] scribbled: Hi, можеш да използваш и iproute2 [EMAIL PROTECTED] ip route add prohibit 209.10.26.51 [EMAIL PROTECTED] ssh 209.10.26.51 ssh: connect to address 209.10.26.51 port 22:

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Georgi Chorbadzhiyski
Around 09/03/07 12:00, Vasil Kolev scribbled: В пн, 2007-09-03 в 11:35 +0300, Georgi Chorbadzhiyski написа: Around 09/03/07 11:23, [EMAIL PROTECTED] scribbled: Hi, можеш да използваш и iproute2 [EMAIL PROTECTED] ip route add prohibit 209.10.26.51 [EMAIL PROTECTED] ssh 209.10.26.51 ssh:

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Vasil Kolev
В пн, 2007-09-03 в 12:35 +0300, Georgi Chorbadzhiyski написа: Е па може, но пък трябва насила да прекарваш лузерта през проксито, което си идва с изискванията за памет, диск, настройки на на pool-ове и т.н. Ако искаш просто да отрежеш разните му там clubs.dir.bg, сладури, асл-та и подобни

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Georgi Chorbadzhiyski
Around 09/03/07 12:44, Vasil Kolev scribbled: В пн, 2007-09-03 в 12:35 +0300, Georgi Chorbadzhiyski написа: Е па може, но пък трябва насила да прекарваш лузерта през проксито, което си идва с изискванията за памет, диск, настройки на на pool-ове и т.н. Ако искаш просто да отрежеш разните му

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Bozhidar Maramski
iptables не е много подходящ за това, което искаш да направиш, но ако все пак държиш Наистина е така: -h' or 'iptables --help' for more information. iptables v1.3.6: host/network `myfirstorgasm.org' not found Try `iptables -h' or 'iptables --help' for more information. iptables v1.3.6:

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Bozhidar Maramski
можеш да използваш и iproute2 [EMAIL PROTECTED] ip route add prohibit 209.10.26.51 ip route add prohibit $(cat /etc/blacklist) -bash: /sbin/ip: Argument list too long :( ___ Lug-bg mailing list Lug-bg@linux-bulgaria.org

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Georgi Alexandrov
Bozhidar Maramski wrote: iptables не е много подходящ за това, което искаш да направиш, но ако все пак държиш Наистина е така: -h' or 'iptables --help' for more information. iptables v1.3.6: host/network `myfirstorgasm.org' not found Try `iptables -h' or 'iptables --help' for more

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Georgi Chorbadzhiyski
On 09/03/07 18:41, Bozhidar Maramski wrote: можеш да използваш и iproute2 [EMAIL PROTECTED] ip route add prohibit 209.10.26.51 ip route add prohibit $(cat /etc/blacklist) -bash: /sbin/ip: Argument list too long for i in $(cat /etc/blacklist) do ip route add prohibit 209.10.26.51 $i

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Bozhidar Maramski
Ако женати се чука с друг или нямаш пет лева в джоба не съм ти виновен Избивай си го или си го набивай на друго място On Mon, 03 Sep 2007 19:26:19 +0300, Georgi Alexandrov [EMAIL PROTECTED] wrote: Bozhidar Maramski wrote: iptables не е много подходящ за това, което искаш да направиш, но ако

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Danail Petrov
Bozhidar Maramski wrote: Ако женати се чука с друг или нямаш пет лева в джоба не съм ти виновен Избивай си го или си го набивай на друго място Божидаре, нямаш никакво право да проявяваш такова аругантно отношение към хората които се опитват да ти помогнат. Най-малкото от уважение към

Re: [Lug-bg] iptables blocklist

2007-09-03 Thread Yulian Stefanov
Да ще пракарваш... мисля че е най-доброто решение. Памет си иска и то бая, но диск - не (зависи как го настроиш). Кой ще ти прави /blacklist..всеки ден ще update-ва, ще му бае.. squid3+squidguard(BerkeleyDB)+shalla's blacklist. Shalla's url blacklist has just jumped over 1.400.000 entries Набиваш

Re: [Lug-bg] iptables blocklist

2007-09-02 Thread Georgi Chorbadzhiyski
Bozhidar Maramski mumbled something about, On 9/3/07 2:17 AM: Някой може ли да ми помогне да блокирам списък с домейни с iptables Става въпрос за порно сайтове. iptables не е много подходящ за това, което искаш да направиш, но ако все пак държиш for PORN in DOMAIN1 DOMAIN2 DOMAIN2 do

Re: lug-bg: iptables masquerade problem

2005-07-31 Thread Dragomir Zhelev
Здравей, и въпреки всичко защо не опиташ без -d ! 192.168.0.0/24 тоест в нат да имаш само iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE аз имах същият ( да абсолютно същият ) проблем. Just try it! :) -- =+==+==+==+==+==+==+==+==+==+==+==+= Dragomir Zhelev Network

Re: lug-bg: iptables masquerade problem

2005-07-31 Thread Danail Petrov
Dragomir Zhelev wrote: Здравей, и въпреки всичко защо не опиташ без -d ! 192.168.0.0/24 тоест в нат да имаш само iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE аз имах същият ( да абсолютно същият ) проблем. Just try it! :) ами да , и това пробвах но не ... не

RE: lug-bg: iptables masquerade problem

2005-07-29 Thread Georgi Sinapov
Chain FORWARD (policy ACCEPT 2349 packets, 144K bytes) pkts bytes target prot opt in out source destination 15 870 ACCEPT all -- * * 192.168.0.0/24 0.0.0.0/0 Какво казва lsmod? Best e-gards, Georgi Sinapov smime.p7s Description: S/MIME cryptographic

Re: lug-bg: iptables masquerade problem

2005-07-29 Thread Danail Petrov
Georgi Sinapov wrote: Chain FORWARD (policy ACCEPT 2349 packets, 144K bytes) pkts bytes target prot opt in out source destination 15 870 ACCEPT all -- * * 192.168.0.0/24 0.0.0.0/0 Какво казва lsmod? Best e-gards, Georgi Sinapov Там всичко е наред. Но

RE: lug-bg: iptables masquerade problem

2005-07-28 Thread Georgi Sinapov
Chain POSTROUTING (policy ACCEPT 74 packets, 4519 bytes) pkts bytes target prot opt in out source destination 0 0 SNAT all -- * * 192.168.0.0/24 0.0.0.0 to:84.хх.хх.хх това е в момента правилото и пак нищо ... Може ли да сложиш

Re: lug-bg: iptables masquerade problem

2005-07-28 Thread Danail Petrov
Georgi Sinapov wrote: Chain POSTROUTING (policy ACCEPT 74 packets, 4519 bytes) pkts bytes target prot opt in out source destination 0 0 SNAT all -- * * 192.168.0.0/24 0.0.0.0 to:84.хх.хх.хх това е в момента правилото и пак нищо ...

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Delian Krustev
On Wednesday 27 July 2005 15:08, Danail Petrov wrote: Това е работило близо 1 година, но тези дни една от етернет платките на сървъра е изгоряла , и вследствие подменена със същата като модел платка. Примерно модулите ти се зареждат в различен ред, това което е било eth0 ти е станало eth1 ..

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Danail Petrov
Delian Krustev wrote: On Wednesday 27 July 2005 15:08, Danail Petrov wrote: Това е работило близо 1 година, но тези дни една от етернет платките на сървъра е изгоряла , и вследствие подменена със същата като модел платка. Примерно модулите ти се зареждат в различен ред, това което е

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Delian Krustev
On Wednesday 27 July 2005 16:30, Danail Petrov wrote: Примерно няма смисъл да се пишат излишни неща? :) Примерно, хич не са излишни. И пак примерно погледни къде е валиден входния интерфейс: -i, --in-interface [!] name Name of an interface via which a packet is going to be received

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Georgi Alexandrov
Danail Petrov wrote: Здравейте, преди малко попаднах на много странен проблем. Накратко схемата: Линукс (Дебиан sid) , действащ като рутер който се връзва по pppoe , и маскира вътрешната мрежа навън. Проблема е че ,в един момент iptables просто спря да маскира. С tcpdump виждам , как линукса

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Danail Petrov
Delian Krustev wrote: On Wednesday 27 July 2005 16:30, Danail Petrov wrote: Примерно няма смисъл да се пишат излишни неща? :) Примерно, хич не са излишни. И пак примерно погледни къде е валиден входния интерфейс: -i, --in-interface [!] name Name of an interface via which a

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Danail Petrov
Georgi Alexandrov wrote: примерно -d ! 192.168.0.0/24 е безмислено в случая. Примерно , е просто така написано. Мислиш че това е проблема ли? :) П.с. В случая наистина няма смисал , но при други обстоятелства , ако мрежата е разделена на под-мрежи (/30, /29) , тогава не би искал да правиш

RE: lug-bg: iptables masquerade problem

2005-07-27 Thread Georgi Sinapov
iptables: Chain POSTROUTING (policy ACCEPT 6 packets, 378 bytes) pkts bytes target prot opt in out source destination 0 0 SNAT all -- eth1 * 192.168.0.0/24 ! 192.168.0.0/24 to:84.xx.xx.xx Аз имам следното питане - как си успял да

Re: lug-bg: iptables masquerade problem

2005-07-27 Thread Danail Petrov
Georgi Sinapov wrote: iptables: Chain POSTROUTING (policy ACCEPT 6 packets, 378 bytes) pkts bytes target prot opt in out source destination 0 0 SNAT all -- eth1 * 192.168.0.0/24 ! 192.168.0.0/24 to:84.xx.xx.xx Аз имам следното питане

Re: lug-bg: iptables(ipfw) web based panel

2005-03-30 Thread George Danchev
On Monday 28 March 2005 15:34, Ziumbiulev, Peter wrote: a LAN iptables ipfw(ako FreeBSD). : - 2 ISP - , ISP . - squid-a ISP - Firewall Perl + Mysql, . , ? [1] , , ..php code , ''.

Re: lug-bg: iptables(ipfw) web based panel

2005-03-30 Thread Nikolai Alexandrov
George Danchev wrote: On Monday 28 March 2005 15:34, Ziumbiulev, Peter wrote: a LAN iptables ipfw(ako FreeBSD). : - 2 ISP - , ISP . - squid-a ISP - Firewall Perl + Mysql, . , ? [1] , , ..php code ,

Re: lug-bg: iptables(ipfw) web based panel

2005-03-29 Thread Peter Pentchev
On Mon, Mar 28, 2005 at 05:38:58PM +0300, George Danchev wrote: On Monday 28 March 2005 16:53, Peter Pentchev wrote: On Mon, Mar 28, 2005 at 02:34:00PM +0200, Ziumbiulev, Peter wrote: a LAN iptables ipfw(ako FreeBSD). : - 2 ISP - , ISP . -

Re: lug-bg: iptables(ipfw) web based panel

2005-03-29 Thread George Danchev
On Tuesday 29 March 2005 13:52, Peter Pentchev wrote: [snip defense] [1] http://linux-bulgaria.org/archive/2005/Mar/32997.html ... ... . , , NetBoz, , 1. 2. -, ,. , - :) NetBoz - , , ,( - ,

Re: lug-bg: iptables(ipfw) web based panel

2005-03-28 Thread Peter Pentchev
On Mon, Mar 28, 2005 at 02:34:00PM +0200, Ziumbiulev, Peter wrote: a LAN iptables ipfw(ako FreeBSD). : - 2 ISP - , ISP . - squid-a ISP - Firewall Perl + Mysql, . , ? , , * * . , , - NetBoz,

Re: lug-bg: iptables(ipfw) web based panel

2005-03-28 Thread George Danchev
On Monday 28 March 2005 16:53, Peter Pentchev wrote: On Mon, Mar 28, 2005 at 02:34:00PM +0200, Ziumbiulev, Peter wrote: a LAN iptables ipfw(ako FreeBSD). : - 2 ISP - , ISP . - squid-a ISP - Firewall Perl + Mysql, . ,

Re: lug-bg: iptables icmp3/10 and limit

2005-02-16 Thread Nickola Kolev
, , , man iptables? On , 2005-02-16 at 13:17 +0200, an0nym0us wrote: , HOWTO iptables, - icmp 3/10 - Destination host administratively prohibited iptables -A INPUT -p tcp -s -j REJECT --reject-with \ icmp-host-prohibited or

Re: lug-bg: iptables icmp3/10 and limit

2005-02-16 Thread Delian Krustev
On Wednesday 16 February 2005 13:34, Nickola Kolev wrote: - - 3 1 Request timed out . , . nth This module matches every `n'th packet --every value Match every `value' packet [--counter num]

Re: lug-bg: iptables TOS

2004-12-26 Thread Peter Pentchev
On Thu, Dec 23, 2004 at 09:48:23PM +0200, raptor wrote: On Wed, 22 Dec 2004 16:50:48 +0200 (EET) Anton Glinkov [EMAIL PROTECTED] wrote: |TOS/4 = DSCP |puskash si _HEX_ calculator i smiatash | |TOS 64 = DSCP 19 |TOS 60 = DSCP 18 |etc.. | |-- |Anton Glinkov |network administrator

Re: lug-bg: iptables TOS

2004-12-23 Thread raptor
On Wed, 22 Dec 2004 16:50:48 +0200 (EET) Anton Glinkov [EMAIL PROTECTED] wrote: |TOS/4 = DSCP |puskash si _HEX_ calculator i smiatash | |TOS 64 = DSCP 19 |TOS 60 = DSCP 18 |etc.. | |-- |Anton Glinkov |network administrator Gledam iptables source i kernel i mi se struwa che ako mahna prowerkata

Re: lug-bg: iptables TOS

2004-12-22 Thread Anton Glinkov
TOS/4 = DSCP puskash si _HEX_ calculator i smiatash TOS 64 = DSCP 19 TOS 60 = DSCP 18 etc.. -- Anton Glinkov network administrator A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).

Re: lug-bg: iptables TOS

2004-12-22 Thread Delian Krustev
On Tuesday 21 December 2004 18:21, [EMAIL PROTECTED] wrote: i az si misleh za nesto takowa !!! ako nqkoi ima pointer.. , DSCP, - u32,POM., 2.6 .. A mail-list of Linux Users Group -

Re: lug-bg: iptables TOS

2004-12-21 Thread Peter Pentchev
On Tue, Dec 21, 2004 at 11:51:49AM +0200, [EMAIL PROTECTED] wrote: hi, nqkoi da ima ideq kak da markiram s iptables na bazata na nestandartni TOS stoinosti.. Mnoo se iznenadah che -m tos --tos XX move da markira samo na standartni stoinost (super typa hawa) :) TOS -hardcode-

RE: lug-bg: iptables TOS

2004-12-21 Thread Stoimen Gerenski
Title: RE: lug-bg: iptables TOS , DSCP . -- Regards, Stoimen -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] bulgaria.org] On Behalf Of Peter Pentchev Sent: Tuesday, December 21, 2004 12:03 PM To: [EMAIL PROTECTED] Subject: Re: lug-bg: iptables

Re: lug-bg: iptables TOS

2004-12-21 Thread [EMAIL PROTECTED]
i az si misleh za nesto takowa !!! ako nqkoi ima pointer.. |On Tue, Dec 21, 2004 at 11:51:49AM +0200, [EMAIL PROTECTED] wrote: | hi, | | nqkoi da ima ideq kak da markiram s iptables na bazata na nestandartni TOS stoinosti.. | Mnoo se iznenadah che -m tos --tos XX move da markira samo na

Re: lug-bg: iptables SNAT --to pool ...

2004-09-19 Thread Danail Petrow
, ( ) : undertown:~# uname -a Linux undertown 2.4.27 #2 Sun Sep 19 09:30:40 EDT 2004 i686 GNU/Linux Best Regards, A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).

Re: lug-bg: iptables SNAT --to pool ...

2004-09-18 Thread Danail Petrov
:) ( :)) undertown:~# iptables -t nat -I POSTROUTING -p tcp -d 212.5.145.42 --dport 80 -j SNAT --to 212.5.155.101 /212.5.145.42:80 212.5.155.101/ undertown:~# tcptraceroute 212.5.145.42 80 Selected device eth0, address 212.5.155.100, port 33414 for outgoing

Re: lug-bg: iptables SNAT --to pool ...

2004-09-17 Thread Danail Petrov
: undertown:~# tcptraceroute -s 212.5.155.100 212.5.145.17 Selected device eth0, address 212.5.155.100, port 33065 for outgoing packets Tracing the path to 212.5.145.17 on TCP port 80, 30 hops max 1 zora.inetg.bg (212.5.155.97) 0.436 ms 0.348 ms 0.321 ms 2

Re: lug-bg: iptables SNAT --to pool ...

2004-09-17 Thread Tsvetin Vasilev
? ,. POSTROUTING iptables. Danail Petrov wrote: : undertown:~# tcptraceroute -s 212.5.155.100 212.5.145.17 Selected device eth0, address 212.5.155.100, port 33065 for outgoing packets Tracing the path to 212.5.145.17 on TCP port 80, 30 hops max 1

Re: lug-bg: iptables SNAT --to pool ...

2004-09-17 Thread Danail Petrov
Tsvetin Vasilev wrote: ? ,. POSTROUTING iptables. , ... ... :) ? , A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers). http://www.linux-bulgaria.org -

Re: lug-bg: iptables

2004-03-28 Thread Ilia Lindov
! OUTPUT LOCAL_NET_IN_OUT: iptables -t filter -A OUTPUT -m mark --mark 1 -j LOCAL_NET_IN_OUT ( 1,15, ). OUTPUT .:). : A

Re: lug-bg: iptables

2004-03-26 Thread Radoslav Kolev
! packet filtering how-to: - mac -m mac -match mac . Ethernet ( MAC) , ! !! PREROUTING INPUT . : --mac-source ! , ethernet : ,macsource 00:60:08:91:CC:B7 . # mac iptables -t filter -A LOCAL_NET_IN_OUT -s 192.168.2.25

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread Georgi Chorbadzhiyski
asha wrote: ( ). , :(. : -: linux- iptables Cisco router. ... link . iptables + iproute2 cisco, , , cisco. Extreme Juniper. -- Georgi Chorbadzhiyski http://georgi.unixsol.org/

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread rninov
IMHO::-)asha [EMAIL PROTECTED]: , ( ). , :(. : -: linux- iptables Cisco router. .. . link .: :asha: A mail-list of Linux Users Group - Bulgaria (bulgarian

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread raptor
az bih predpochel iptables.. ako ima iptables se podrazbira che imash linux.. a tuk iznikwat oste mnogo predimstwa.. Taka ste izbroq nestata koito mi lipswat ama mnogo kogato prawq neshto pod cisco , ne che sam advanced-cisco-user : - no tcpdump,ngrep and all stuff based on pcap, trqbwa da

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread Georgi Chorbadzhiyski
[EMAIL PROTECTED] wrote: IMHO::-) cisco ? , IOS - , , cisco ? -- Georgi Chorbadzhiyski http://georgi.unixsol.org/ A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread melwin
Õàðäóåð ñðåùó ñîôòóåð ëè? Íåêà äà âèäèì: Õàðäóåð:300 Mhz-îâ RISC ïðîöåñîð ñ 256ÌÁ ïàìåò ñðåùó 3 Ghz Xeon s 2GB ïàìåò? Ñîôòóåð:IOS vs linux+iptables+iproute2 Ïðåäèìñòâîòî íà cisco-òî å â ïîääðúæêàòà íà ãîëÿì áðîé èíòåðôåéñè è ïðîòîêîëè. Ïðåäèìñòâîòî íà linux-a e â öåíàòà è âúçìîæíîñòèòå, êîèòî

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread Bozhan Bozhkov
Georgi Chorbadzhiyski wrote: , cisco ? - , , ,, . . A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers). http://www.linux-bulgaria.org - Hosted

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread peyo
:300 Mhz- RISC 256 3 Ghz Xeon s 2GB ? :IOS vs linux+iptables+iproute2 : 1) 3 Ghz Xeon s 2GB firewall,- . cisco- . 2) !. :) linux-a e, iptables+iproute2. 3) . Zebra ip* . , :(

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread Georgi Chorbadzhiyski
peyo wrote: linux-a e, iptables+iproute2. 3) . Zebra ip* . , :( cisco BGP $1.5kPC :-) -- Georgi Chorbadzhiyski http://georgi.unixsol.org/ A mail-list of Linux Users

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread sub
[EMAIL PROTECTED] wrote: IMHO::-) cisco ? , IOS - , , cisco ? 1. , Cisco Layer 3 , , Application Layer. - Layers ,-( - ) 2. Cisco - - LinkSys, D-link .. How-To, LinkSys . 3.Cisco / . , . --

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread rninov
-, . . iptables.. flame, pls. Georgi Chorbadzhiyski [EMAIL PROTECTED]: [EMAIL PROTECTED] wrote: IMHO::-)cisco ? , IOS - , , cisco ? -- Georgi Chorbadzhiyski http://georgi.unixsol.org/

Re: lug-bg: iptables vc Cisco Router

2004-01-20 Thread Georgi Chorbadzhiyski
[EMAIL PROTECTED] wrote: -, . . iptables. . flame, pls. ? . access-lists iptables . -- Georgi Chorbadzhiyski http://georgi.unixsol.org/ A mail-list of Linux Users Group - Bulgaria

Re: lug-bg: IPTABLES

2004-01-07 Thread G. Georgiev (Skeleta)
Vasko Tomanov wrote: v minaloto niakoi beshe izpratil URL na sait koito generira IPTABLES configuracionen fail.. moje li niakoi da mi pripomni URL-to ? ... http://morizot.net/firewall/gen/ -- Skelet -- http://skelet.hit.bg/

Re: lug-bg: IPTABLES

2004-01-06 Thread
On 06.01.2004 13:15, Vasko Tomanov wrote: v minaloto niakoi beshe izpratil URL na sait koito generira IPTABLES configuracionen fail.. moje li niakoi da mi pripomni URL-t http://morizot.net/firewall/gen/ ., !

Re: lug-bg: iptables accounting

2004-01-06 Thread Lyubomir Popov
eth0, i-net-a eth1 eth1: iptables -N Accounting iptables -A Accounting -o eth1 # upstream traffic iptables -A Accounting -i eth1 # downstream traffic iptables -A INPUT -i eth1 -j Accounting iptables -A OUTPUT -o eth1 -j Accounting iptables -A FORWARD -i eth1 -j Accounting iptables

Re: lug-bg: iptables and ADSL

2003-12-04 Thread Peter Georgiev
On Thu, 4 Dec 2003 10:18:54 - Vasko Tomanov [EMAIL PROTECTED] wrote: Imama server s ADSL vrazaka.. obasthe adresa koito polutshavam ot ADSL-a se meni vseki pat kato se restartne vrazkata po niakakva pritshina.. iskam w definiciata na pravilata na IPTABLES da zadan ne tvardo IP s maska

Re: lug-bg: iptables and ADSL

2003-12-04 Thread Hristo Erinin
, On Thu, 4 Dec 2003 10:18:54 - Vasko Tomanov [EMAIL PROTECTED] wrote: iskam w definiciata na pravilata na IPTABLES da zadan ne tvardo IP s maska a IP-to na ppp0 naprimer ? kak moga da go nparavia tova za da ne mi se nalaga sled vseki restart da opraviam ip tables RTFM. iptables(8)

Re: lug-bg: iptables problem

2003-11-26 Thread Elin
10x za pomosht na sichki razbrah problema kade poneze kato edin red raboti no kato izreda celia piaring te stavt mnogo redove ot kadeto idva problema zashtoto oshte v purvia red izliza che osven tozi ip sichki drugi da gi prashta kam proxyto toest sledvashtite redove negi priema poneze oshte

Re: lug-bg: iptables problem

2003-11-26 Thread Doncho N. Gunchev
On Tuesday 25 November 2003 10:48, wrote: On 25.11.2003 11:53, Elin wrote: iptables -t nat -A PREROUTING -d 192.168.1.2 -p tcp -s !212.91.161.0/24 --dport 80 -j DNAT --to-destination 192.168.1.253:3128 , IP- ? - ! - - :) - - , .

Re: lug-bg: iptables problem

2003-11-25 Thread
On 25.11.2003 11:53, Elin wrote: iptables -t nat -A PREROUTING -d 192.168.1.2 -p tcp -s !212.91.161.0/24 --dport 80 -j DNAT --to-destination 192.168.1.253:3128 , IP- ? - ! A mail-list of Linux

Re: lug-bg: iptables problem

2003-11-25 Thread Elin
ne sam copy pasteval ima interval prosto sam go ispusnal v pismoto Stoyan Zalev wrote: Zdrasti, Na prima vista - otricanieto (!) trjabva da ima 1 interval razstojanie,ako si copy/paste-val de :) -s !212.91.161.0/24 cykni go taka: -s ! 212.91.161.0/24 Stoyan

Re: lug-bg: iptables problem

2003-11-25 Thread oneofus
Hi, ili az ne moga da te razbera ... ili ti ne si se izkazal prawilno :) Wupros N1. S kakwo IP e tazi mashina na koqto pishesh towa prawilo Wupros N2. Kakvot tochno se opitwash da naprawish ? shtoto w momenta s towa prawilo okazwash Wsichki TCP packeti !except 212.91.161.0/24 kum 192.168.1.2 na

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-08-01 Thread Mihail Vlahovski
On Thursday 31 July 2003 22:19, George Danchev wrote: --cut-- Ta kato si patchvah i az iptables-a mi se poluchi problem - tova make install ne se poluchi (vypreki che nqmashe msg za greshka). Ostana si stariq iptables v /usr/sbin/iptables, kakto i vsichki stari libs v /usr/lib/iptables/

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-08-01 Thread
Mihail Vlahovski wrote: I sled cqloto tova mazane shteshe da e dobre doshla nqkakva ideika kak da se napravi za da ne stava mazane :-)) vse pak celta mi e da si patchna (inache kazano da omaja na nivo source code?) iptables :-) kak stava tova nai-dobre? , iptables /usr iptables

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-08-01 Thread George Danchev
--cut-- source code ;-) patch /, ,OK. I sled cqloto tova mazane shteshe da e dobre doshla nqkakva ideika kak da se napravi za da ne stava mazane :-)) vse pak celta mi e da si patchna (inache kazano da omaja na nivo source code?) iptables :-) kak stava tova

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-08-01 Thread Mihail Vlahovski
Mdaa sega razbrah kakvo sym omazal :-) Danchev, mersi za zabelejkata, a na Ognian Kulev - mersi za obqsneniqta. Pozdravi, Misho On Friday 01 August 2003 11:59, wrote: Mihail Vlahovski wrote: I sled cqloto tova mazane shteshe da e dobre doshla nqkakva ideika kak da se napravi za da ne

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-07-30 Thread Mihail Vlahovski
Zdrasti, pri instalaciqta na patch-o-matic ima edin takyv etap: --- Once you have applied all the patches you wished to apply, the next step is recompile your kernel and install it. This HOWTO will not explain how to do this. Instead, you can read the Linux Kernel HOWTO. While

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-07-30 Thread
iptables- a -ttl time. iptables-a :))) , On Wed, 30 Jul 2003 16:49:47 +0300, Mihail Vlahovski [EMAIL PROTECTED] wrote: Zdrasti, pri instalaciqta na patch-o-matic ima edin takyv etap: --- Once you have applied all the patches you wished to

Re: lug-bg: Iptables 1.2.8 i patch-o-matic

2003-07-30 Thread Mihail Vlahovski
Ami pogledni dali imash /usr/lib/iptables/libipt_time.so ... Ne znam inache kakyv bi mogyl da e problema shtom i iptables-a si e compiliran i instaliran normalno :-) A btw i v default paketa na iptables ima opciq ttl (no s drugi parametri - -m ttl --ttl ttl) - sega go vidqh... Pozdravi, Misho

Re: lug-bg: iptables MAC

2003-03-13 Thread Nickola Kolev
Marian wrote: [ cut ] iptables -A INPUT -s 192.168.0.40 -m mac -mac-source 00:04:c0:76:70:80 -j DROP [ cut ] . iptables -A INPUT -s 192.168.0.40 -m mac --mac-source 00:04:c0:76:70:80 -j DROP ^

Re: lug-bg: iptables MAC

2003-03-13 Thread peyo
Marian Popov wrote: Zdraveite pak :) Opitvam se da filtriram po MAC address s iptables no niakak si ne se poluchava tova koeto triabva. Naprimer: iptables -A INPUT -s 192.168.0.40 -m mac -mac-source 00:04:c0:76:70:80 -j DROP Spored men tozi red triabva da spre vsichko idvashto ot IP

Re: lug-bg: iptables MAC

2003-03-13 Thread Marian Popov
Naposledyk sym tolkova zaspal che ne znam kyde mi e uma. Blagodaria ti vse pak a i na Nikola Kolev :)) Zaspala rabota. Ama toi Chorbadji verno kaza da ne se pishat takiva neshta na sybujdane ama ... Moje. compiliray si modula za MAC v iptables.Sled tova probvay:)) Vupreki , che sega vijdam

Re: lug-bg: iptables match mark problem

2003-03-07 Thread George Danchev
On 07 03 2003 10:09, Georgi Chorbadzhiyski wrote: , 16. 8. IP. iptables -A PREROUTING -t nat -s 10.0.0.0/8 --match mark --mark 16 -j SNAT --to 193.110.159.3 , iptables: Invalid argument ? P.S. mark,:) # Tuka kvo

  1   2   >