Linux-Networking Digest #749, Volume #11          Thu, 1 Jul 99 20:13:37 EDT

Contents:
  Re: Could Microsoft Cheat On The New Mindcraft Benchmark? ("Anthony D. Tribelli")
  How can I use Win98 to access Linux Server? ("Jason Pun")
  Non-typical firewall IP interfaces numbers (Rafal Podeszwa)
  blah ([EMAIL PROTECTED])
  KDE vagy X problema (Jan CSERNOCH)
  mail & databases ("jmr")
  Re: Anyone get Redhat 6.0 + Cable Modem working????? (Mike)
  Re: [ignore if repost] gethostent() on linux? (Juergen Heinzl)
  Re: Why not C++ (Nathan Myers)
  Re: Why not C++ (Chance Harris)
  Re: PPP Server problems (Bill)
  DNS question (root)
  Re: HELP:  How do I set up a caching DNS server? ("Michael Faurot")
  Newbie needs help with DNS: Can't get host lookup ([EMAIL PROTECTED])
  IPoATM module? ([EMAIL PROTECTED])
  IRC Problem. ("Frank Apap")
  Re: Fun with mail routing ("Michael Faurot")
  Re: BBS? (Bill Pitz)
  Re: Local IP addresses (Bill Pitz)
  Re: Linux - Windows emulators? (Bill Pitz)
  Re: quota system (Bill Pitz)
  Re: Removing Anonymous FTP access (Bill Pitz)
  Re: RH Linux Guru Final Exam (Ricky Sethi)
  Re: Non-typical firewall IP interfaces numbers (Luca Filipozzi)
  Re: RH Linux Guru Final Exam ("Ricky J. Sethi")
  Re: samba and win98 reg hack (Bill Pitz)
  PPP connect - pppd: bad local IP address 127.0.0.1 (Chris)

----------------------------------------------------------------------------

From: "Anthony D. Tribelli" <[EMAIL PROTECTED]>
Crossposted-To: 
omp.os.ms-windows.nt.advocacy,comp.os.linux.advocacy,comp.infosystems.www.servers.unix,comp.os.linux.misc
Subject: Re: Could Microsoft Cheat On The New Mindcraft Benchmark?
Date: 1 Jul 1999 17:57:07 GMT

In comp.os.linux.advocacy Chad Mulligan <[EMAIL PROTECTED]> wrote:
> "Bob Taylor" wrote in message ...
>>In article <[EMAIL PROTECTED]>,

>>> Do they cover the US Army deliberately starving German POWs
>>> to death immediately after the war?
>>
>>And how do you know this actually happened? Were you present? You read
>>it in a book written by an American hater? On behalf of the Americans
>>who died saving your sorry ass in WWII, I *demand* a retraction and
>>appology for such a vicious attack!
>
> I would have to agree with Mr taylor on this one.  The stories I've heard,
> some first hand from German POW's in the US, friends of my Granddad who was
> a Latvian pressed into German service, all said they were treated well and
> some even remained friends with their jailers.

In the US POWs were treated extremely well. Many who were behaving well
were permitted to work as day laborers in nearby agriculture. There are
many anecdotal stories about the farmer calling up the camp saying that he
and the POW were working pretty late in the fields and could the Army let
the POW stay for dinner and spend the night at the farm to get an early
start on work in the morning. Local history gives some support to such
stories. My area of southern California has some vineyards and Italian
POWs were allowed to work there. Immediately after the end of the war some
of the former POWs immediately returned to the US and married local girls. 

I once had a history class in school where an elderly gentlemen was also
enrolled. It turned out he was a waste gunner on a bomber that was shot up
over Polesti (sp?). They eventually were forced down and captured. He says
that they were beaten up a little during initial interrogation but after
that they were treated OK. Towards the end of the war he said there were
constant food shortages and there was an attempt to march POWs from
various camps to a common location. They had no supplies, few were
delivered during the march, and their guards were as hungry as they were. 

I believe there may have been very hungry POWs in Allied custody in
Europe, but that was not intentional as claimed by the original poster. 
There were incredible food shortages in many areas, supply lines were
thin, it was difficult to predict where hundreds of thousands of POWs
would be taken, ... It takes time to organize and equip for the care and
feeding of such large numbers, especially when they had no supplies of
their own. 

Tony

------------------------------

From: "Jason Pun" <[EMAIL PROTECTED]>
Subject: How can I use Win98 to access Linux Server?
Date: Fri, 2 Jul 1999 02:48:29 +0800

Dear All,

I am a newbie of Linux. I want to setup a Linux Server for accessing by
Win98 / WinNT. I just know set samba to let Win98 access to Linux Server.
But how to configure Win98 indeed? Anyone can tell me the whole process of
setting up a new Linux network for connecting Linux with Win98?

Thanks if anyone can help me!

mailto:[EMAIL PROTECTED]



------------------------------

From: Rafal Podeszwa <[EMAIL PROTECTED]>
Subject: Non-typical firewall IP interfaces numbers
Date: Thu, 01 Jul 1999 21:52:32 GMT

I would like to insert a firewall into a present ethernet network
without necessity to change any network/gateway IP numbers on the
network computers. 

Present situation:

148.81.22.0               148.81.22.254
 -------------               ---------
|local network|------------ | gateway | 
 -------------               ---------

After inserting the firewall:

148.81.22.0           148.81.22.254    148.81.2.253     148.81.22.254
 -------------          eth0 ----------  eth1              -------- 
|local network|-------------| firewall | -----------------| gateway | 
 -------------               ----------                    ---------

Firewall should act as the gateway for local network computers and as
local computers for the gateway. 

I read Firewall, NET-3 and other relevant HOWTOs and haven't found
such configuration. Usually, firewall has different network numbers on
different network interfaces. I wanted to configure the firewall this
way because void (non filtering) firewall would be totally transparent
in this configuration and in case of any break-down of the firewall
computer I would be able just to connect the cables and return to the
present situation.

I also read (and tried the hints from) Bridge+Firewall Mini HOWTO but it
doesn't work either. 

Is it possible to configure the firewall behaving this way using
standard Linux kernel and utility programs?

Rafal Podeszwa

------------------------------

From: [EMAIL PROTECTED]
Subject: blah
Date: Thu, 01 Jul 1999 22:10:49 GMT

blah


Sent via Deja.com http://www.deja.com/
Share what you know. Learn what you don't.

------------------------------

From: Jan CSERNOCH <[EMAIL PROTECTED]>
Subject: KDE vagy X problema
Date: Thu, 01 Jul 1999 21:16:29 +0200

Sziasztok!

Van egy problemam, amivel mar regota kuszkodok.

SuSE 6.1-et hasznalok, KDE 1.1-el.

A jelenseg az, hogy mikor a KDE-t hasznalom (lehet, hogy altalanos X
problema), akkor neha egyszeruen megall az elet. A pointert tudom
mozgatni, a vrtualis kepernyo is mozog, az alkalmazasok futnak tovabb,
csak megszunik minden interakcio koztem es a felulet kozott (pl. az MP3
szol tovabb, de a kijelzo megmerevedik, mint minden mas). Olyan mintha a
'talca' csak egy kep volna. Innen az a megoldas, hogy
ctrl-alt-backspace-el ujrainditok mindent, de ilyenkor persze elveszitem
a munkam egy reszet, meg a beallitasaimat. Raadasul mindig akkor
kovetkezik be, ha valakinek megmutatom, hogy milyen jo kis felulete van
mar a Linux-nak :-).

Eloszor azt hittem, hogy a video kartyam IRQ konfliktol valamivel. Erre
azert gondoltam, mert egyszer az OSS isntallalasa kozben kaptan egy
ilyen uzenetet:

----
You appear to have a graphics card based on Nvidia Riva128 chip.
It's a known problem that this chip can't share it's IRQ
with any other device when X is being used (this is nothing OSS
related).
Unfortunately Riva128 appears to share it's IRQ with some other
device(s)
in your system.
Please use BIOS PCI/PnP setup to allocate a private IRQ for Riva128.

   In your case the conflict is between Riva128 and a _NON_ sound
device.
   This means that the conflict should NOT affect functionality of OSS.
   However you may experience system lockups while starting X11.

The following IRQ number(s) appear to be shared with Riva128: 11
----

Atallitottam a video IRQ-t 9-re, majd 5-re. Ez egy darabig jo volt, de
most upgradeltem 1.1-rol 1.1.1-re es minden kezdodott elorol az 5-os
IRQ-n is.

Elso kerdes, hogyan lehet a KDE-t vagy az X-et ugy resettelni, hogy nem
lepek ki a sessionbol?
Masodik, hogy mi okozhatja ezt egyaltalaban? Ez nagyon zavaro es kezdi
megkeseriteni a munkam.

Elore is kosz
Jean




------------------------------

From: "jmr" <[EMAIL PROTECTED]>
Crossposted-To: comp.os.linux.misc,comp.os.linux
Subject: mail & databases
Date: Fri, 2 Jul 1999 00:13:48 +0200

This is a multi-part message in MIME format.

=======_NextPart_000_000C_01BEC41F.C1CF6F60
Content-Type: text/plain;
        charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hi!

We're probably switching from NT to Linux because we need more =
flexibility...
Currently, we're using Postoffice in NT. Furthermore, I like the ASP =
programming one can use to access databases via the DSN stuff in NT.
What in-built Linux solutions, e.g. mail server and database interface =
comparable to the ones listed above exist, so that at least for the =
beginning we can simply take over any NT stuff and run mail server and =
database services with a comparable performance (e.g. same features) =
under Linux?

Best regards,

=========
J.M. Roth
[EMAIL PROTECTED] --- http://www.roth.lu
voice (352) 3697 5341 - fax (352) 3697 5369 - cellular (352) 091 266 878 =

"Trust No One"


=======_NextPart_000_000C_01BEC41F.C1CF6F60
Content-Type: text/html;
        charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Diso-8859-1" =
http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2614.3401" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV>Hi!</DIV>
<DIV>&nbsp;</DIV>
<DIV>We're probably switching from NT to Linux because we need more=20
flexibility...</DIV>
<DIV>Currently, we're using Postoffice in NT. Furthermore, I like the =
ASP=20
programming one can use to access databases via the DSN stuff in =
NT.</DIV>
<DIV>What in-built Linux solutions, e.g.&nbsp;mail server and database =
interface=20
comparable to the ones listed above exist, so that at least for the =
beginning we=20
can simply take over any NT stuff and run mail server and database =
services with=20
a comparable performance&nbsp;(e.g. same features) under Linux?</DIV>
<DIV>&nbsp;</DIV>
<DIV>Best regards,</DIV>
<DIV><BR>---------<BR>J.M. Roth<BR><A =
href=3D"mailto:[EMAIL PROTECTED]">[EMAIL PROTECTED]</A>=20
--- <A href=3D"http://www.roth.lu">http://www.roth.lu</A><BR>voice (352) =
3697 5341=20
- fax (352) 3697 5369 - cellular (352) 091 266 878 <BR>"Trust No=20
One"<BR></DIV></BODY></HTML>

=======_NextPart_000_000C_01BEC41F.C1CF6F60==


------------------------------

From: Mike <[EMAIL PROTECTED]>
Crossposted-To: 
linux.redhat.announce,linux.redhat.digest,linux.redhat.install,linux.redhat.list,linux.redhat.misc,linux.redhat.rpm,linux.samba
Subject: Re: Anyone get Redhat 6.0 + Cable Modem working?????
Date: Thu, 01 Jul 1999 17:47:07 -0400

root wrote:

> Mark A <[EMAIL PROTECTED]> writes:
>
> Here's what I did to get RH6.0-out-of-the-box to work with DHCP. During
> install, I indicated that I had a network and to fetch an IP address via
> DHCP. Worked fine except that `dnsdomainname' would return an error. After
> mucking around a bit, I did the following:
>
>   0) Used linuxconf to set my FQDN (full qualified domain name)
>
>   1) ran /sbin/dhcpcd -D
>      This reconfigured eth0 with a *new* IP address and set some DNS server
>      values in /etc/resolv.conf
>
>   2) Made a copy of /etc/resolv.conf
>      ...because the next step will remove the DHCPCD version
>
>   3) Killed DHCPCD with /sbin/dhcpcd -k
>
>   4) Replaced the saved copy of /etc/resolv.conf
>
> Now, everything works just fine. In a previous life/install, I placed dhcpcd in
> an `rc' script. However, this always seemd to give me an IP address different
> than what was found in DNS. Since eth0 always had a valid IP address at boot, I
> surmised that something was not quite right with my use of /sbin/dhcpcd. Anyone
> else with some hints/tips here?
>
> HTH...
>
> Brad

I stated this before somewhere, For some reason Linux doesnt know what to do with
the DNS entries, Just
find out what they are and put them in manually, DHCP will work for the rest.
Type netconf at the console and put them in the DNS entries, when you click on it,
it will say Error. invaild something or other in etc/resolv.conf.  Just put in the
DNS entries.  I use Mediaone.  I live in the Boston Area, my DNS servers are
24.128.232.6, 24.128.16.6, 24.128.81.1  You only need one to make it work.  The
other 2 are for backup.  I dont see why you couldnt use these if you do not know
yours.  But it might take longer to get a query back depending on where you are.
Just my 2 cents....

Mike


------------------------------

From: [EMAIL PROTECTED] (Juergen Heinzl)
Subject: Re: [ignore if repost] gethostent() on linux?
Date: Thu, 01 Jul 1999 22:32:49 GMT

In article <7lgi71$nmn$[EMAIL PROTECTED]>, [EMAIL PROTECTED] wrote:
>hi,
>
>i'm looking for the equivalent of gethostent() on linux.. is there
>such a beast?

See man 2 uname (not linux specific).

Ta',
Juergen

-- 
\ Real name     : J�rgen Heinzl                 \       no flames      /
 \ EMail Private : [EMAIL PROTECTED] \ send money instead /

------------------------------

From: [EMAIL PROTECTED] (Nathan Myers)
Crossposted-To: comp.os.linux.development.apps,comp.os.linux.development.system
Subject: Re: Why not C++
Date: 1 Jul 1999 12:24:52 -0700

Stephan Houben  <[EMAIL PROTECTED]> wrote:
>
>If you did this, then you would realize that "templates" are only
>the shadow on the wall of a much more powerful and elegant system,
>namely an ML-style type system. 

That is easily said, but it happens to be false.  C++ templates
can express useful ideas that are impossible in "an ML-style
type system".

Perhaps some future language will have the strengths of C++ and ML.

-- 
Nathan Myers
[EMAIL PROTECTED]  http://www.cantrip.org/


------------------------------

From: [EMAIL PROTECTED] (Chance Harris)
Crossposted-To: comp.os.linux.development.apps,comp.os.linux.development.system
Subject: Re: Why not C++
Date: 1 Jul 1999 19:25:24 GMT

Johan Kullstam ([EMAIL PROTECTED]) wrote:

: the developers of C++ think so too.  templates are a way to avoid
: explicit typing.

I disagree. 

I think they are a hack to get around the lack of parameterized typing.

------------------------------

From: Bill <[EMAIL PROTECTED]>
Subject: Re: PPP Server problems
Date: Thu, 01 Jul 1999 21:45:09 GMT

I forgot to mention that my laptop connects to my ISP without
a hitch, that is why I�m sure that its a problem on my server.
I just copied chat-ppp0 and ifcfg-ppp0 to *-ppp1 and matched
changed the approriate entries for telephone, password, device,
etc.

If I have not supplied enough information to formulate a response
then please let me know and I will gladly supply the required
infos.

Bill.


Sent via Deja.com http://www.deja.com/
Share what you know. Learn what you don't.

------------------------------

From: root <[EMAIL PROTECTED]>
Subject: DNS question
Date: Wed, 30 Jun 1999 23:03:57 +0300

Hi guys,

I rather new to linux and communications issues, and already get messed
with it :-))
There is a question that doesn't allow me to sleep:
when I dial to ISP from Linux, I should explicitly indicate name servers
in /etc/resolv.conf file,
but when I dial from Windows,  it gets it automaticaly. Is there a way
to do the same in Linux (I guess, yes) ??

Thanx in advance,
Oleg



------------------------------

From: "Michael Faurot" <[EMAIL PROTECTED]>
Subject: Re: HELP:  How do I set up a caching DNS server?
Date: 1 Jul 1999 19:17:52 GMT

Alexander Atkin <[EMAIL PROTECTED]> wrote:
: I have a small LAN with a Linux router allowing it to access the
: internet through my V.90 modem.

: How could I set up a cachine DNS server to help speed up my access as my
: ISP has a very slow DNS server sometimes and so im sure it would double
: the speed of my access if the router knew the IP addresses of my
: favourite sites.
: I could put them in manually into hosts but that would be rather a drag
: as I have quite a few favourite sites and some of them have changed ISPs
: in the past so I dont want to have to keep reconfiguring it.

http://metalab.unc.edu/mdw/HOWTO/DNS-HOWTO.html

-- 
==============================================================================
 Michael | mfaurot  | Parents often talk about the younger generation as if
 Faurot  | atww.org | they didn't have much of anything to do with it.

------------------------------

From: [EMAIL PROTECTED]
Subject: Newbie needs help with DNS: Can't get host lookup
Date: Thu, 01 Jul 1999 22:08:44 GMT



        I can't get my DNS to resolve on the host file first.  I have host.conf
set with hosts first and files are first in nsswich.conf.  Restarted the
daemon and everything and it still won't do.

Help!
[EMAIL PROTECTED]


Sent via Deja.com http://www.deja.com/
Share what you know. Learn what you don't.

------------------------------

From: [EMAIL PROTECTED]
Subject: IPoATM module?
Date: Thu, 01 Jul 1999 22:06:11 GMT

hi,

     Is there any IP over ATM module available?

Wayne


Sent via Deja.com http://www.deja.com/
Share what you know. Learn what you don't.

------------------------------

From: "Frank Apap" <[EMAIL PROTECTED]>
Subject: IRC Problem.
Date: Thu, 01 Jul 1999 22:57:52 GMT

I have two windows machined hooked up through a hub to a  linux
machine...(with some ip masqing and what not)...non of the systems seem to
be able to get on an IRC server that requires IDENTD, how can i fix this?

--
==============================
Frank Apap
==============================



------------------------------

From: "Michael Faurot" <[EMAIL PROTECTED]>
Subject: Re: Fun with mail routing
Date: 1 Jul 1999 19:16:48 GMT

[EMAIL PROTECTED] wrote:
: Here's what I wanna do.
: I want to have the above linux box download my
: mail from a multiple mail addresses and then when
: I want to read it from a computer on the network
: I can use a mail client and download my mail from
: the linux box.

: So how do I go about doing this?

fetchmail.

-- 
==============================================================================
 Michael | mfaurot  | Parents often talk about the younger generation as if
 Faurot  | atww.org | they didn't have much of anything to do with it.

------------------------------

From: Bill Pitz <[EMAIL PROTECTED]>
Subject: Re: BBS?
Date: Thu, 01 Jul 1999 23:19:48 GMT

SpiKe <[EMAIL PROTECTED]> gave us the interesting posting of:
> Is it possible to make a BBS for people to dial into? I know that you can
> get people to dial in but what I really want to know is if you can limit
> them to a certain amount of time and a certain amount of download KB?

You can download Linux BBS software from http://bbs.ipass.net/  Probably
the easiest way would be to set up a standard Shell dialup which automatically
launches the BBS login app as the login program.

There's some other apps around, but in the few minutes I had to mess
around with BBSs on Linux, Falken (the ipass software) was the easiest
software package to setup and get working.

-Bill
-- 
Bill Pitz                                         [EMAIL PROTECTED]
Silicon Valley North, Inc.                                www.svn.net
Internet and World Wide Web Services                   (707) 781-9999

------------------------------

From: Bill Pitz <[EMAIL PROTECTED]>
Subject: Re: Local IP addresses
Crossposted-To: comp.sys.next.sysadmin
Date: Thu, 01 Jul 1999 23:01:43 GMT

In comp.os.linux.networking Lee Sau Dan ~{@nJX6X~} <[EMAIL PROTECTED]> babbled:
>     Erik> 192.168.0.255 is the the so-called broadcast
>     Erik> address. I don't know it's exact purpose. 

> As its  name implies, it  is used for  broadcasting IP packets  to the
> whole subnet.  Experiment: "ping 192.168.0.255".

This will always produce responses from any router/device on your network
that is capable of routing packets for that particular subnet.

>     Erik> Also, address 192.168.0.0 is often reserved.

It's always reserved unless you're using non-standard IP protocols.

> This is used for identifying the whole subnet.

-Bill

-- 
Bill Pitz                                         [EMAIL PROTECTED]
Silicon Valley North, Inc.                                www.svn.net
Internet and World Wide Web Services                   (707) 781-9999

------------------------------

From: Bill Pitz <[EMAIL PROTECTED]>
Subject: Re: Linux - Windows emulators?
Date: Thu, 01 Jul 1999 23:22:32 GMT

Christopher A. Gaul <[EMAIL PROTECTED]> gave us the interesting posting of:

> --------------56AF33FA20130D00320DE559
> Content-Type: text/plain; charset=us-ascii
> Content-Transfer-Encoding: 7bit

> Probably the ultimate solution exists at:
>  VM-Ware

VMWare is definitely the best solution I've seen...  I love it.

When it joins forces with a cool machine, Red Hat 6.0, and Gnome,
it's great.

-- 
Bill Pitz                                         [EMAIL PROTECTED]
Silicon Valley North, Inc.                                www.svn.net
Internet and World Wide Web Services                   (707) 781-9999

------------------------------

From: Bill Pitz <[EMAIL PROTECTED]>
Subject: Re: quota system
Crossposted-To: redhat.general
Date: Thu, 01 Jul 1999 23:03:49 GMT

In comp.os.linux.networking Bosco Tsang <[EMAIL PROTECTED]> babbled:
> I am trying to activite the quote on my system but got the following
> message,

> root /etc]# df
> Filesystem         1024-blocks  Used Available Capacity Mounted on
> /dev/sda2            7786721 4069634  3313454     55%   /
> [root /etc]# /sbin/quotaon /
> quotaon: using /quota.user on /dev/sda2: No such file or directory

You need to create a file called quota.user in /.  ie:
# touch /quota.user

You'll probably want to set the permissions on it so that only root can
view it.  That's why it's complaining about "no such file or directory"

-Bill
-- 
Bill Pitz                                         [EMAIL PROTECTED]
Silicon Valley North, Inc.                                www.svn.net
Internet and World Wide Web Services                   (707) 781-9999

------------------------------

From: Bill Pitz <[EMAIL PROTECTED]>
Subject: Re: Removing Anonymous FTP access
Date: Thu, 01 Jul 1999 23:24:09 GMT

Matt <[EMAIL PROTECTED]> gave us the interesting posting of:
> I've setup wu-ftpd, and in order to get guest groups working I had to
> install anon-ftp.  I don't want to allow anonymous access to my server
> however.  How can I set this up?

Add "anonymous" to /etc/ftpusers...  You'll see the syntax of the file
when you open it up.  It just contains a list of users who are unable
to login to the FTP server.

Hope this helps,

-Bill
-- 
Bill Pitz                                         [EMAIL PROTECTED]
Silicon Valley North, Inc.                                www.svn.net
Internet and World Wide Web Services                   (707) 781-9999

------------------------------

From: Ricky Sethi <[EMAIL PROTECTED]>
Crossposted-To: comp.os.linux.misc,comp.os.linux.help
Subject: Re: RH Linux Guru Final Exam
Date: Thu, 01 Jul 1999 15:39:21 -0700

Hi Rich,

Nope, although I did try installing them once to see if I could force it to
update and include the latest.  I've also tried manually updating using
/sbin/route all to no avail (except for when I remove all the interfaces and
then add them back again, including the routes).

Regards,


Rick.




Rich Sena ras*at*tiac.net wrote:

> did you install gated? or anyother routing daemon (routed) it may be
> riping and then removing the routes that it thinks are dead...
>
> --
> <T.I.A.C.>
> There Is A Cabal






------------------------------

From: [EMAIL PROTECTED] (Luca Filipozzi)
Subject: Re: Non-typical firewall IP interfaces numbers
Date: Thu, 1 Jul 1999 15:43:56 -0700

[This followup was posted to comp.os.linux.networking and a copy was sent 
to the cited author.]

In article <[EMAIL PROTECTED]>, 
[EMAIL PROTECTED] says...
> X-Mailer: Mozilla 4.5 [pl] (Win95; I)
> X-Accept-Language: pl,en
> 
> I would like to insert a firewall into a present ethernet network
> without necessity to change any network/gateway IP numbers on the
> network computers. 
> 
> Present situation:
> 
> 148.81.22.0               148.81.22.254
>  -------------               ---------
> |local network|------------ | gateway | 
>  -------------               ---------
> 
> After inserting the firewall:
> 
> 148.81.22.0           148.81.22.254    148.81.2.253     148.81.22.254
>  -------------          eth0 ----------  eth1              -------- 
> |local network|-------------| firewall | -----------------| gateway | 
>  -------------               ----------                    ---------

More appropriately:

OPTION A:
148.81.22.1-251       148.81.22.252    148.81.2.253     148.81.22.254
 -------------          eth0 ----------  eth1              -------- 
|local network|-------------| firewall | -----------------| gateway | 
 -------------               ----------                    ---------
- requires you to change default gateway

Or

OPTION B:
148.81.22.3-253       148.81.22.254    148.81.2.2       148.81.22.1
 -------------          eth0 ----------  eth1              -------- 
|local network|-------------| firewall | -----------------| gateway | 
 -------------               ----------                    ---------

Either way, you lose two two ip addresses.

Assuming you pick OPTION B, then the firewall requires the following 
routing table entries:

  route add -net  148.81.22.0 netmask 255.255.255.0 eth0
  route add -host 148.82.22.1 netmask 255.255.255.0 eth1
  route add default gw 148.81.22.1

Machines on the local network require the following routing table 
entries:

  route add -net  148.81.22.0 netmask 255.255.255.0 eth0
* route add -host 148.81.22.1 netmask 255.255.255.0 148.81.22.254
* route add -host 148.82.22.2 netmask 255.255.255.0 148.82.22.254
  route add default gw 148.81.22.254

The two routes marked with * are only required if you want machines on 
your local network to access those two ip addresses specifically. You 
don't need them for proper operation of your network and default routing.

> I wanted to configure the firewall this
> way because void (non filtering) firewall would be totally transparent
> in this configuration and in case of any break-down of the firewall
> computer I would be able just to connect the cables and return to the
> present situation.

I wouldn't be too concerned about "break-down" of the firewall.

Hope this helps,

Luca
-- 
Luca Filipozzi <[EMAIL PROTECTED]>

------------------------------

From: "Ricky J. Sethi" <[EMAIL PROTECTED]>
Crossposted-To: comp.os.linux.misc,comp.os.linux.help
Subject: Re: RH Linux Guru Final Exam
Date: Thu, 1 Jul 1999 15:35:20 -0700

Hi Rich,

Nope, although I did try installing them once to see if I could force it to
update an include the latest.  I've also tried manually updating using
/sbin/route all to no avail (except for when I remove all the interfaces and
then add them back again, including the routes).

Regards,


Rick.


Rich Sena ras*at*tiac.net <[EMAIL PROTECTED]> wrote in message
news:[EMAIL PROTECTED]...
> did you install gated? or anyother routing daemon (routed) it may be
> riping and then removing the routes that it thinks are dead...
>
> --
> <T.I.A.C.>
> There Is A Cabal
>





------------------------------

From: Bill Pitz <[EMAIL PROTECTED]>
Subject: Re: samba and win98 reg hack
Date: Thu, 01 Jul 1999 23:28:20 GMT

Dave <[EMAIL PROTECTED]> gave us the interesting posting of:
> i have it all set up...only prob is that i ALWAYS get "bad password" when i
> login via my win98 box..where can i get hte registry patch for that so that
> it allows plain text? or what do i need? plz help...thanks
> -dave

Well, I have only been messing with Samba for a short time, but in some
cases, it does not like mixed-case passwords...  A very annoying little
glitch that I'm still trying to figure out.  I did pick up a pretty decent
book - "Teach Yourself Samba in 24 Hours" published by Sams publishing.

-Bill
-- 
Bill Pitz                                         [EMAIL PROTECTED]
Silicon Valley North, Inc.                                www.svn.net
Internet and World Wide Web Services                   (707) 781-9999

------------------------------

From: Chris <[EMAIL PROTECTED]>
Crossposted-To: comp.os.linux.hardware,redhat.networking.general
Subject: PPP connect - pppd: bad local IP address 127.0.0.1
Date: Thu, 01 Jul 1999 23:30:45 GMT

I have the Red Hat Linux Unleashed book that tells how to set up a PPP 
connection.  I followed all the directions, however I cannot get it to 
work.  I am using the command:

pppd connect "chat -f chatfile" /dev/cua2 -detach crtscts modem 127.0.0.1:

When I run this I get:

pppd: bad local IP address 127.0.0.1

The modem will dial and try to connect if I leave the 127.0.0.1: part out, 
but with that part it does nothing but give the above error.  I ran 
ifconfig and checked the hosts file and that IP address is shown in both.  
Can someone help me determine why it does not accept this IP address?

==================  Posted via SearchLinux  ==================
                  http://www.searchlinux.com

------------------------------


** FOR YOUR REFERENCE **

The service address, to which questions about the list itself and requests
to be added to or deleted from it should be directed, is:

    Internet: [EMAIL PROTECTED]

You can send mail to the entire list (and comp.os.linux.networking) via:

    Internet: [EMAIL PROTECTED]

Linux may be obtained via one of these FTP sites:
    ftp.funet.fi                                pub/Linux
    tsx-11.mit.edu                              pub/linux
    sunsite.unc.edu                             pub/Linux

End of Linux-Networking Digest
******************************

Reply via email to