Re: central administration techniques

2001-10-19 Thread nrvale0
> maybe have a look at cfengine? > or apt-cache search / freshmeat / google for other options I was down this road just a few months ago. cfengine is nice except that the author doesn't believe that 'administrative information' is something that should be protected and thus has no plans to move f

Re: central administration techniques

2001-10-19 Thread nrvale0
> maybe have a look at cfengine? > or apt-cache search / freshmeat / google for other options I was down this road just a few months ago. cfengine is nice except that the author doesn't believe that 'administrative information' is something that should be protected and thus has no plans to move

Re: iptables LOG target problem with syslog

2001-05-10 Thread nrvale0
Is the Linux syslog as sensitive to whitespace issues in syslog.conf as the Solaris version? Perhaps you have spaces where it is looking for TABs or the reverse? -- --- Nathan Valentine - [EMAIL PROTECTED]

Re: iptables LOG target problem with syslog

2001-05-10 Thread nrvale0
Is the Linux syslog as sensitive to whitespace issues in syslog.conf as the Solaris version? Perhaps you have spaces where it is looking for TABs or the reverse? -- --- Nathan Valentine - [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Troubl

piercing ipmasq

2001-02-16 Thread nrvale0
This message could just as easily be posted in debian-firewall but I'm no longer subscribed there. ;p I've been wanting to poke at the ipchains ruleset in ipmasq for sometime. It looks pretty tight to me, but one of the things I would like to test is sneaking certain ICMP pkts from externel(Inter

piercing ipmasq

2001-02-16 Thread nrvale0
This message could just as easily be posted in debian-firewall but I'm no longer subscribed there. ;p I've been wanting to poke at the ipchains ruleset in ipmasq for sometime. It looks pretty tight to me, but one of the things I would like to test is sneaking certain ICMP pkts from externel(Inte

Re: secure install

2001-02-15 Thread nrvale0
> apt-get install any other packages on an as-needed basis. After the > one machine is properly installed, you could clone the drive with tar, > drive image, ghost, etc. I usually make a Ghost image of a base install with just the absolute necessities. Then you can take your Ghost model machine a

Re: secure install

2001-02-15 Thread nrvale0
> apt-get install any other packages on an as-needed basis. After the > one machine is properly installed, you could clone the drive with tar, > drive image, ghost, etc. I usually make a Ghost image of a base install with just the absolute necessities. Then you can take your Ghost model machine

Re: Ipsec behind linux FireWall

2000-11-28 Thread nrvale0
I was just reading about this this weekend. From my very limited understanding you cannot have IPSec w/ AH connections that go through a masqing firewall. There is some problem with the key exchange sequence and also with the hashes that are generated from the src

Re: Ipsec behind linux FireWall

2000-11-28 Thread nrvale0
I was just reading about this this weekend. From my very limited understanding you cannot have IPSec w/ AH connections that go through a masqing firewall. There is some problem with the key exchange sequence and also with the hashes that are generated from the src