Re: [leaf-user] trying to get ipsec VPN working

2004-06-04 Thread Charles Steinkuehler
of 'what-now..it should work' type problems. Be careful when editing, read through the manpages (find online), and try to follow some examples verbatim for your first tunnel(s). A misplaced (or missing) space or tab can do you in... -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Bering 1.2 backup destination problem

2004-05-26 Thread Charles Steinkuehler
/dev/fd0u1440 /mnt # copy files from /tmp cp /tmp/*.lrp /mnt # unmount disk umount /mnt HTH... -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit

Re: [leaf-user] Bering Serial port problem on IBM Aptiva

2004-05-26 Thread Charles Steinkuehler
. Note that Bering uses getty from tinylogin, rather than the gnu getty, so there might be some differences in how it operates. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: Oracle 10g Get certified

[leaf-user] Bering + Shorewall + ProxyARP + Advanced Routing

2004-05-25 Thread Charles Steinkuehler
the cable-modem, and the (really) easy way to do this is to just build another firewall, but I'd really like to have the new mirror system on my internal lan if possible. Thanks in advance for any help or pointers. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Bering 1.2 doesn't renew dhcp leases to internal hosts.

2004-05-24 Thread Charles Steinkuehler
to in /etc/init.d/dhcpd (via the ifs variable) just like in Dachstein. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take

Re: [leaf-user] No syslinux.cfg on Bering CD?

2004-05-24 Thread Charles Steinkuehler
are probably the best utility for handling package creation if you don't want to use tar and gzip at the command line. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever

Re: [leaf-user] BadThing: Doc links broken (404)atleaf.sourceforge.net

2004-05-05 Thread Charles Steinkuehler
this pretty easily, and it shouldn't take any more webspace than it was taking before (when it was part of the SF web site I was mirroring anyway). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by Sleepycat Software

Re: [leaf-user] LEAF article

2004-05-04 Thread Charles Steinkuehler
is a bit more powerful than what I normally use for LEAF, mainly because that's what was onhand when the router was getting built: 360 MHz P-II 64M Ram (2) Generic tulip 10/100 cards 100 MBit upstream link from Cogent -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Dachstein as border_router? (public ip addresses etc)

2004-04-28 Thread Charles Steinkuehler
be FREE given your ISP's bandwidth metering policy). Of course there could be valid reasons you can't do this that you haven't shared with us...I'm just going on the info you've provided in your emails. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Dachstein as border_router? (public ip addresses etc)

2004-04-27 Thread Charles Steinkuehler
) | - | | | (addrPUBB) (addrPUBC) (addrPUBD) Server 1 (VPN etc) Server 2 Server 3 (addrPRIVA) | internal network Should work fine... -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Dachstein as border_router? (public ip addresses etc)

2004-04-27 Thread Charles Steinkuehler
to masquerade/NAT IPSec traffic from server1, but pass (route) other traffic. This is possible with linux, but it's not done often, so you'll likely have a harder time setting it up (and likely with maintainence next year, when you've forgotten how everything worked). -- Charles Steinkuehler [EMAIL

Re: [leaf-user] SNMPd using Dachstien netsnmpd.lrp

2004-04-26 Thread Charles Steinkuehler
context sec.model sec.level prefix read write notif access notConfigGroup any noauthexact systemview none none everything past here is commented -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored

Re: [leaf-user] SNMPd using Dachstien netsnmpd.lrp

2004-04-26 Thread Charles Steinkuehler
-CD/CD-Contents/netsnmpu.lrp Is there a snmp(mib) xml gateway available ? ??? I have no idea...I typically don't mess with the MIBs or use much in the way of XML. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored

Re: [leaf-user] SNMPd using Dachstien netsnmpd.lrp

2004-04-26 Thread Charles Steinkuehler
results. From my working system: # lrpkg -l | grep snmp netsnmpd4.2.1-1-CS http://net-snmp.sourceforge.net netsnmpu4.2.1-1-CS http://net-snmp.sourceforge.net -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email

Re: [leaf-user] SNMPd using Dachstien netsnmpd.lrp

2004-04-23 Thread Charles Steinkuehler
package) rather than the snmp.lrp package (based on cmu-snmp 3.6b7) which has some known vunerabilities. Of course, you shouldn't be allowing snmp access from untrusted IP space anyway, but it's always good to have defense in depth. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] IPsec between FreeS/WAN 1.91 (Dachstein) and Linksys router/Windows 2000 computer

2004-04-23 Thread Charles Steinkuehler
and the configuration settings on the Linksys. Also, is there a newer version of FreeS/WAN for Dachstein? I have some routing issues that is making the migration to Bering difficult at the moment... Not That I'm aware of... -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] IPSEC help needed....

2004-04-20 Thread Charles Steinkuehler
. To do this, add the following in /etc/network.conf EXTERN_UDP_PORTS=0/0_500 EXTERN_PORTS=50_0/0 51_0/0 -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel

Re: [leaf-user] dachstein vt100 emulation

2004-04-20 Thread Charles Steinkuehler
it wouldn't necessarily work properly with terminal settings (which tend to be a linked C library thing). If you're having problems outside of the editor as well, make sure your TERM variable is set correctly. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] IPSEC help needed....

2004-04-20 Thread Charles Steinkuehler
. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administration.http

Re: [leaf-user] LEAF Theory of Operation

2004-04-15 Thread Charles Steinkuehler
with the rest of the lrcfg menu scripts. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything

Re: [leaf-user] Probably OT: Cisco VPN Passthrough Bering 1.2

2004-04-15 Thread Charles Steinkuehler
are using appropriate credientials (or group password, whatever that is in Cisco parlance)? -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins

Re: [leaf-user] Bering 1.2 Throughput Test Results

2004-04-15 Thread Charles Steinkuehler
routine. If the AES routines are generic C code, it would likely explain the performance difference. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel

[leaf-user] Re: Thanks

2004-04-15 Thread Charles Steinkuehler
done, and thought it was high time I said so. I appreciate the feedback, and am glad you found Dachstein and Eigerstein useful! -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux

Re: [leaf-user] Bering 1.2 Throughput Test Results

2004-04-15 Thread Charles Steinkuehler
tunnels. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system

Re: [leaf-user] Bering 1.2 Throughput Test Results

2004-04-14 Thread Charles Steinkuehler
is usually not much of a bottleneck (even with the 'slow' Nortel devices), as usually the upstream WAN link is substantially slower than the potential CPU throughput when compressing, but if you've got fast pipes, you'll notice a drastic difference by choosing an alternate encryption scheme. -- Charles

Re: [leaf-user] OT: UPX v1.11

2004-04-06 Thread Charles Steinkuehler
linux kernels, although I have yet to try it. It might work instead of version 1.11. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President

[leaf-user] Increasing ip_conntrack_max and hashsize

2004-04-05 Thread Charles Steinkuehler
loading the ip_conntrack module (or at compile time, if compiled into the kernel). A handy table of prime numbers good for hash table sizes can be found at PlanetMath: http://planetmath.org/encyclopedia/GoodHashTablePrimes.html -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] 2nd instance of dnscache, for serving my DMZ

2004-04-02 Thread Charles Steinkuehler
your own domain (ie: to answer questions from everyone else on the internet about names under your control, such as: www.yourdomain.net). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free

Re: [leaf-user] serial support with Dachstein

2004-04-02 Thread Charles Steinkuehler
to the file 'linux' on your floppy disk (or other boot media). You may have to replace any kernel modules you're using, as well. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial

Re: [leaf-user] ISP and DNS issues

2004-03-31 Thread Charles Steinkuehler
your ISP's names resolve. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from

Re: [leaf-user] Bering 1.2; Diagnosis for ntpsimpl logfile deletion problem

2004-03-29 Thread Charles Steinkuehler
like to do this is with ls and sed: SAVELOGS=7 oldlogs=`ls -1t log.file.pattern | sed 1-${SAVELOGS}d` [ $oldlogs != ] rm $oldlogs -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux

Re: [leaf-user] Difficulty assigning multiple IP addresses

2004-03-24 Thread Charles Steinkuehler
) to save my changes??? Also, what file(s) were modified by using this method(out of curiosity)? To save your changes, backup etc.lrp. The file modified is /etc/network/interfaces which you edited. No other files are dynamically modified when you make changes to this file. -- Charles Steinkuehler

Re: [leaf-user] Difficulty assigning multiple IP addresses

2004-03-23 Thread Charles Steinkuehler
for eth0:0, eth0:1, etc., along with the entry for eth0). With the masq entry you list above, you'll be round-robining through source IP's for outbound traffic, which I doubt is what you really want. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Difficulty assigning multiple IP addresses

2004-03-23 Thread Charles Steinkuehler
Tom Eastep wrote: Tom Eastep wrote: Charles Steinkuehler wrote: Are you using the /etc/shorewall/masq file to try and *ASSIGN* the extra IP addresses? With your setup, I'd simply assign all IP's in your /etc/network/interfaces file (add entries for eth0:0, eth0:1, etc., along with the entry

Re: [leaf-user] Difficulty assigning multiple IP addresses

2004-03-23 Thread Charles Steinkuehler
I have made the correct modifications, ip addr should show all of the addresses, and I should be able to ping them all, shouldn't I??? You should be able to ping all assigned IP's, assuming the firewall rules allow it (you can allow/prevent just about anything with iptables). -- Charles

Re: [leaf-user] Dachstein routing to squid

2004-03-22 Thread Charles Steinkuehler
. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system

Re: [leaf-user] Sending mail from a script

2004-03-22 Thread Charles Steinkuehler
equivelent for end-of-file. You can simply pipe something to (or otherwise redirect the input of) the mail command, which will correctly identify the end of file, ie: echo hello world | mail -s test [EMAIL PROTECTED] -or- mail -s test [EMAIL PROTECTED] /my/test/message -- Charles Steinkuehler

[leaf-user] Bering terminfo missing?

2004-03-15 Thread Charles Steinkuehler
I'm not seeing the /etc/terminfo entries in Bering, nor could I find a package they moved to. Am I missing something, or do I need to copy these from Dachstein (or Debian)? -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email

Re: [leaf-user] Bering terminfo missing?

2004-03-15 Thread Charles Steinkuehler
they should either be part of the default etc.lrp (as they were for ages) or re-packaged to a seperate terminfo.lrp if they're no longer wanted in the default release. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored

Re: [leaf-user] Am I out of luck?

2004-03-07 Thread Charles Steinkuehler
or serial ports) within 16 addresses of the base address of each card. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo

Re: [leaf-user] ISP and DNS issues

2004-02-28 Thread Charles Steinkuehler
this out. -- Charles Steinkuehler [EMAIL PROTECTED] --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356alloc_id

Re: [leaf-user] routing issue with Dachstein

2004-02-12 Thread Charles Steinkuehler
, probably by adding your ISP's name servers to /etc/resolv.conf. -- Charles Steinkuehler [EMAIL PROTECTED] --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps Web services for Linux with a free DVD software kit from

Re: [leaf-user] routing issue with Dachstein - Sucess!! (kinda)

2004-02-12 Thread Charles Steinkuehler
from the internet, just like your windows box running ICS. -- Charles Steinkuehler [EMAIL PROTECTED] --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps Web services for Linux with a free DVD software kit from IBM

Re: [leaf-user] routing issue with Dachstein

2004-02-11 Thread Charles Steinkuehler
by default in RH, but I install it on all my systems). Otherwise use: ifconfig and route. -- Charles Steinkuehler [EMAIL PROTECTED] --- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps Web services for Linux

Re: [leaf-user] Amateur Radio Modules?

2004-02-08 Thread Charles Steinkuehler
(with Dachstein or something else), please let us all know. -- Charles Steinkuehler [EMAIL PROTECTED] --- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development and Integration See the breadth of Eclipse activity

Re: [leaf-user] Got serial working except for boot messages

2004-02-05 Thread Charles Steinkuehler
if you really need boot-time messages from the kernel over the serial port. -- Charles Steinkuehler [EMAIL PROTECTED] --- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development and Integration See

Re: [leaf-user] Got serial working except for boot messages

2004-02-05 Thread Charles Steinkuehler
or ipmasqadm portfw -ln) - Try setting your masquerade timeouts to a shorter value (ipchains -M -S) -- Charles Steinkuehler [EMAIL PROTECTED] --- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development

Re: [leaf-user] Getting serial to work under Dachstein

2004-02-04 Thread Charles Steinkuehler
the normal or RAID kernel with serial support built-in, or if you're using the small kernel (the default kernel for floppy versions of dachstein), you need to load the serial.o module: http://lrp.steinkuehler.net/files/kernels/Dachstein-small/modules/misc/serial.o -- Charles Steinkuehler [EMAIL

Re: [leaf-user] machine access by hostname in the DMZ?

2004-02-03 Thread Charles Steinkuehler
Erich Titl wrote: Charles At 13:16 02.02.2004 -0600, Charles Steinkuehler wrote: .. I do this sort of thing using the 'views' feature of Bind9. Systems get different IP's for the same hostname depending on who's asking (based on IP address of the querying system). It's pretty easy to setup

Re: [leaf-user] machine access by hostname in the DMZ?

2004-02-02 Thread Charles Steinkuehler
ask. I do this sort of thing using the 'views' feature of Bind9. Systems get different IP's for the same hostname depending on who's asking (based on IP address of the querying system). It's pretty easy to setup if you're running bind already. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Port fw won't work in Dachstein-Ipsec image

2004-01-21 Thread Charles Steinkuehler
, ip_masq_portfw should be enough): ip_masq_autofw ip_masq_mfw ip_masq_portfw You can verify which modules are loded with the 'lsmod' command. -- Charles Steinkuehler [EMAIL PROTECTED] Thanks in advance, Rick Here is the output you asked for: ip addr gave me: 1: lo: LOOPBACK,UP mtu 3924 qdisc

Re: [leaf-user] Port fw won't work in Dachstein-Ipsec image

2004-01-20 Thread Charles Steinkuehler
the only thing I can think of that might be causing your problems. Please provide the output of the following commands, *WITH* any IPSec connections up and running: net ipfilter list ip addr ip route -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] set MAC address manually on eepro100 card

2004-01-14 Thread Charles Steinkuehler
patch is unavailable on LRP, you shouldn't have much trouble manually applying the diffs (just add one line to /etc/init.d/modutils, and two comment lines to /etc/modules). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email

Re: [leaf-user] set MAC address manually on eepro100 card

2004-01-13 Thread Charles Steinkuehler
believe in Bering by proxy), so you can simply add the proper commands to your /etc/modules file (should be documentation in the comments at the top of the file). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored

Re: [leaf-user] Boot Bering from floppy, most Pkgs on CD

2003-12-30 Thread Charles Steinkuehler
to a 1440K disk and fewer files once you get the system reading packages off the CD. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up

Re: [leaf-user] Boot Bering from floppy, most Pkgs on CD

2003-12-30 Thread Charles Steinkuehler
questions... -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash shell

Re: [leaf-user] Change an IP address on the fly

2003-12-24 Thread Charles Steinkuehler
settings: net reload -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash

Re: [leaf-user] e1000 module (version 4.3.15) for Dachstein?

2003-12-22 Thread Charles Steinkuehler
on the same system you're building the driver for (highly unlikely in this case), so you'll have to short-circuit the automatic 'find the kernel source directory' code in the makefile to compile against the Dachstein kernel. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] 2 VPN Clients through Bering

2003-12-21 Thread Charles Steinkuehler
with what new features might be in 2.4. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn

Re: [leaf-user] Moving from Dachstein to Bering

2003-12-18 Thread Charles Steinkuehler
be fixed. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash shell

Re: [leaf-user] Moving from Dachstein to Bering

2003-12-18 Thread Charles Steinkuehler
Charles Steinkuehler wrote: Eddie Wilson wrote: Hi Charles, I do have the /29 being routed as you expected. I have had them assigned to the same interface as the p-t-p /30 address for the last 2 years and running fine. If there is a better (correct) way of doing this I would be greatfull

Re: [leaf-user] Moving from Dachstein to Bering

2003-12-17 Thread Charles Steinkuehler
configration might present itself, as well. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials

Re: [leaf-user] Moving from Dachstein to Bering

2003-12-17 Thread Charles Steinkuehler
copy the code between the ` marks (ie: starting with ifconfig and ending with }' ) and paste it into a shell window, you can easily see what settings are getting extracted by this code, and test any potential changes w/o having to mess with stopping/restarting IPSec. -- Charles Steinkuehler [EMAIL

Re: [leaf-user] Why run Squid in the DMZ?

2003-12-16 Thread Charles Steinkuehler
. There would also be some amount of low-level confusion caused by this setup, perhaps enough to break basic web functionality (depends somewhat on exactly how everything is setup, as well as the OS's TCPIP stacks involved). -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Mail Server / DNS server behind Dachstien firewall

2003-12-09 Thread Charles Steinkuehler
the following: EXTERN_UDP_PORT0 0/0 domain EXTERN_UDP_PORT3 0/0 domain INTERN_SERVERS=tcp_${EXTERN_IP}_domain_192.168.x.y_domain udp_${EXTERN_IP}_domain_192.168.x.y_domain Replacing 192.168.x.y with your actual internal IP, of course. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Bering on an IDE Hard drive

2003-11-29 Thread Charles Steinkuehler
? -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code? SHARE THE LOVE, and help us help YOU! Click Here

Re: AW: [leaf-user] Bering on an IDE Hard drive

2003-11-29 Thread Charles Steinkuehler
at that point, post details to the list and we'll try to figure it out. Also, IIRC there's a section of the Bering users guide that goes over getting setup to boot from a HDD: http://leaf.sourceforge.net/doc/guide/bubooting.html -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] LRP apache http setup

2003-11-29 Thread Charles Steinkuehler
starts at 1 and goes up to whatever is required). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code

Re: [leaf-user] LRP apache http setup

2003-11-26 Thread Charles Steinkuehler
to the private IP assigned to your web-server machine. People outside your network can then connect using the IP of your firewall (assuming you get apache fixed :). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored

Re: [leaf-user] cdrom boot problem

2003-11-18 Thread Charles Steinkuehler
to the PKGPATH= setting, you effectively reversed what would be the normal load order (CD first, floppy last) for a CD-ROM system with configuration stored on the floppy. HTH, -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF. Net email is sponsored

Re: [leaf-user] Success report! / Dachstein question . . .

2003-11-17 Thread Charles Steinkuehler
as yourself is running a 'doze box as a firewall and dhcp server, you'll see the sort of traffic you list above. The firewall rules are blocking the traffic because of the private IP source address. -- Charles Steinkuehler [EMAIL PROTECTED

[leaf-user] Re: Howdy !

2003-11-05 Thread Charles Steinkuehler
for making a CD in one of the Bering manuals. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code

Re: [leaf-user] weblet (sh-httpd) bug - How to Patch please

2003-10-29 Thread Charles Steinkuehler
, it can be undone with set +f following the set -- $URI line. I think the third chunk I posted previously will work as-is. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. Does

Re: [leaf-user] LEAF on compact flash

2003-10-29 Thread Charles Steinkuehler
) on a hard-disk are a good starting point, and you can post to the list if you run into any problems. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more

Re: [leaf-user] Full Duplex

2003-10-29 Thread Charles Steinkuehler
switches didn't support auto-negotiation, and it worked like a champ. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you

[leaf-user] weblet (sh-httpd) bug

2003-10-28 Thread Charles Steinkuehler
(blocked by default in all LEAF varients, so you'd have to explicitly enable access). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: The SF.net Donation Program. Do you like what SourceForge.net is doing

Re: [leaf-user] Fw: host.allow questions

2003-10-16 Thread Charles Steinkuehler
://leaf.sourceforge.net/devel/cstein/Packages/weblet.htm -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program. SourceForge.net hosts over 70,000 Open Source Projects. See the people who have HELPED US

Re: [leaf-user] Types of DMZ - Dachstein

2003-10-14 Thread Charles Steinkuehler
is the magic that connects systems through the firewall, but lets them think they're all on the same physical network segment. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SF.net Giveback Program

Re: [leaf-user] Types of DMZ - Dachstein

2003-10-13 Thread Charles Steinkuehler
-arp DMZ (mainly in how you setup routing, and an understanding of the arp protocol and arp cache timeouts), so don't be afraid to ask for help with the config file details if you decide to setup this sort of DMZ. -- Charles Steinkuehler [EMAIL PROTECTED

[leaf-user] Re: Leaf

2003-10-06 Thread Charles Steinkuehler
firewall is usually a necessary part of an overall security solution, but it is usually only a part. -- Charles Steinkuehler [EMAIL PROTECTED] P.S. Please continue to route all LEAF related questions through the leaf-user mailing list, rather than e-mailing me personally. You can cc: me directly

Re: [leaf-user] Dachstein, 2 internal nets routing

2003-09-26 Thread Charles Steinkuehler
networks. To allow all traffic to be forwarded between your two internal networks, you should add an appropriate rule to /etc/ipchains.forward. Something like: $IPCH -I forward -j ACCEPT -s 192.168.1.0/24 -d 192.168.2.0/24 -b -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Changing default backup location

2003-09-24 Thread Charles Steinkuehler
line with: boot=/dev/device ...typically found in syslinux.cfg on your boot floppy (the exact location of this option is dependent on the boot-loader you're using, and exactly how you're booting your system). -- Charles Steinkuehler [EMAIL PROTECTED

[leaf-user] Re: Leaf

2003-09-19 Thread Charles Steinkuehler
:// traffic, for instance, which you probably want to allow). Again, thank you for brining this tool to us. I'm glad you found it useful! -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek

Re: [leaf-user] Dachstein and ssh tunneling

2003-09-17 Thread Charles Steinkuehler
-port:host:port Forward remote port to local address -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf

Re: [leaf-user] RE: leaf-use rDachstein lrpkg.cfg - BOOT_IMAGE=linux (nf!)

2003-09-07 Thread Charles Steinkuehler
spit out by linuxrc (or as much as you can write down), particularly the portions where it's mounting media. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com

Re: [leaf-user] reduce load on a bering box

2003-09-02 Thread Charles Steinkuehler
...not a full blown multi-GHz P4, but at least something along the lines of an intel BX chipset or newer, multi-100 MHz CPU (P-II class), and good NICs (I personally like the DEC derrived 21xxx chipsets (tulip driver), but Intel's are reportedly pretty good too). -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] PPPoE, MTU, IPSEC and SNAT woes

2003-08-14 Thread Charles Steinkuehler
PPPoE traffic that heads back out the IPSec link). Provide a diagram of how your network is setup, and maybe I (or someone else) will have some ideas on how to get things working properly. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] OT: Congratulations

2003-08-14 Thread Charles Steinkuehler
missing sleep! :) -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual

Re: [leaf-user] OT: Results of Internal Security Scan.

2003-08-14 Thread Charles Steinkuehler
ICMP echo request/reply messages should have a message code of 0 (although some vendors co-opt the message code for specific services). Do you have a packet dump of the offending ping traffic? -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Last package won't load (Bering v 1.2 on CD)

2003-08-14 Thread Charles Steinkuehler
part of the MS-DOS CRLF sequence will get added to your LRP filename and confuse the package loading scripts. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E

Re: [leaf-user] PPPoE, MTU, IPSEC and SNAT woes

2003-08-14 Thread Charles Steinkuehler
to have problems, I might be able to help if you provide a full dump of your firewall rules, routing tables, and interface setup, but you'll probably need someone more familiar with Bering, IPTables, and shorewall (I'm still stuck in the 2.2 kernel era with Dachstein and IPChains). -- Charles

Re: [leaf-user] OT: Results of Internal Security Scan.

2003-08-10 Thread Charles Steinkuehler
} /code While you could easily change the server name and version to IIS, I don't think this was done by deafult for Bering. I suspect your network scanner is confused by non-windows systems. I suggest you try some linux based tools for serious scanning capabilities. -- Charles Steinkuehler [EMAIL

Re: [leaf-user] Weblet question ?

2003-08-05 Thread Charles Steinkuehler
/Packages/weblet.htm Info on properly installing and configuring lrpStat is available on Martin Hejl's page: http://www.leaf-project.org/devel/hejl/ -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Free pre-built ASP.NET

Re: [leaf-user] Bering 1.0 IDE cdrom Device not found

2003-08-02 Thread Charles Steinkuehler
cdrom device found (this feature was added to Dachstein, which Bering is based on, so it should probably work). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports

Re: [leaf-user] VPN Setup

2003-07-31 Thread Charles Steinkuehler
, but it's important for us to know if you're running with non-standard ports, actually using IPSec and not something else, etc., if we're going to be able to help you). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored

Re: [leaf-user] HD Booting Dachstein with a twist

2003-07-28 Thread Charles Steinkuehler
that if this techinque works with Dachstein, it should also work with Bering, should you choose to migrate. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals

Re: [leaf-user] LEAF doing some DAC stuff

2003-07-20 Thread Charles Steinkuehler
doesn't work). :) -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: VM Ware With VMware you can run multiple operating systems on a single machine. WITHOUT REBOOTING! Mix Linux / Windows / Novell virtual machines

Re: [leaf-user] What LEAF needs

2003-07-20 Thread Charles Steinkuehler
for the (still in development) code. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: VM Ware With VMware you can run multiple operating systems on a single machine. WITHOUT REBOOTING! Mix Linux / Windows / Novell

Re: [leaf-user] VPN Setup

2003-07-18 Thread Charles Steinkuehler
with IDE support: linux-2.2.19-3-LEAF-normal-IDE-IPSec.bzImage.upx -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: VM Ware With VMware you can run multiple operating systems on a single machine. WITHOUT REBOOTING

Re: [leaf-user] wireless LAN security

2003-07-18 Thread Charles Steinkuehler
Steve Wright wrote: Charles Steinkuehler wrote: I recently tried setting up something like this between a couple of Dachstein boxes, and I've since fallen back to simply firewalling both ends of the wireless link and treating it like a hostile network. It would be possible with my current

<    1   2   3   4   5   6   7   8   9   10   >