Re: [leaf-user] VPN Setup

2003-07-17 Thread Charles Steinkuehler
the floppy versions include a kernel that supports masqerading of VPN connections. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: VM Ware With VMware you can run multiple operating systems on a single machine. WITHOUT

Re: [leaf-user] wireless LAN security

2003-07-17 Thread Charles Steinkuehler
of setup can be found in the current FreeS/WAN documentation and mailing list archives. I intend to set something like this up eventually, but I don't want to go through the effort until after I upgrade to Bering... -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Problem accessing Weblet after changing to a internalpublic ip number

2003-07-16 Thread Charles Steinkuehler
of all leaf-user list e-mail) for details on how to provide proper diagnostic information. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: VM Ware With VMware you can run multiple operating systems on a single

Re: [leaf-user] Problem accessing Weblet after changing to a internalpublic ip number

2003-07-15 Thread Charles Steinkuehler
), and the sh-httpd configuration file (/etc/sh-httpd.conf). Both of these can prohibit access to weblet based on source IP. A useful trick for finding these files is to grep for the old IP range in /etc: grep 192.168.0 /etc/* -- Charles Steinkuehler [EMAIL PROTECTED

[leaf-user] Re: More Bash Help

2003-07-09 Thread Charles Steinkuehler
) to the sh-httpd user and see if you can cat the file. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Parasoft Error proof Web apps, automate testing more. Download eval WebKing and get a free book. www.parasoft.com

Re: [leaf-user] OT: Bash question

2003-07-08 Thread Charles Steinkuehler
Peter Nosko wrote: -Original Message- From: Charles Steinkuehler To get around this problem (if necessary), you'll either need to recursively parse each digit of the parameter to see if it's a number (ugly, but relies only on built-in shell commands)...something like: pn] Somehow I knew

Re: [leaf-user] Safe transparent proxying via DS1.02 and Squid

2003-07-02 Thread Charles Steinkuehler
in general. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio

Re: [leaf-user] Bering 1.1 on SCSI HDD

2003-06-27 Thread Charles Steinkuehler
help gave some pointer And guide to this newbie. Start here: http://www.tldp.org/HOWTO/SCSI-2.4-HOWTO/llevel.html -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: INetU Attention Web Developers Consultants: Become

Re: [leaf-user] Strange happenings with Bering 1.2

2003-06-23 Thread Charles Steinkuehler
with the 3Com driver, and you may have to build your own version of the driver from the latest source, an earlier release, or possibly a patched version. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: INetU

Re: [leaf-user] Bering and 1DES

2003-06-20 Thread Charles Steinkuehler
/politics.html#weak I stronlgy suggest you do whatever you have to to implement a stronger encryption method if you really want a Virtual *PRIVATE* Network. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.Net email is sponsored by: INetU Attention

Re: [leaf-user] Windows VPN newbie

2003-06-20 Thread Charles Steinkuehler
across a subnet-subnet VPN, but does not necessarily represent the best, or necessarily even appropriate way to do this in the microsoft world...I'm a linux networking guy, and know just enough microsoft networking to keep my 2KPro desktop linked to the internet and the home office. -- Charles

Re: [leaf-user] Hard Disk setup

2003-06-10 Thread Charles Steinkuehler
, cd to the mount point, and run lrpkg -i package-name. Note that you do *NOT* include the .lrp extention. This will install the package at run-time. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Etnus

Re: [leaf-user] 2 Dachstein Questions

2003-06-10 Thread Charles Steinkuehler
it if you didn't crawl through the /etc/ipfilter.conf shell script... -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Etnus, makers of TotalView, The best thread debugger on the planet. Designed with thread debugging

Re: [leaf-user] Hard Disk setup

2003-06-09 Thread Charles Steinkuehler
command line in syslinux.cfg (subject to a 256 character limit for all kernel parameters), or you can create a lrpkg.cfg file in the root directory of the hard drive with the names of all packages you want to load. See the DachsteinCD readme for details on using this file. -- Charles

Re: [leaf-user] boot floppy to boot Bering cdrom

2003-06-09 Thread Charles Steinkuehler
help. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Etnus, makers of TotalView, The best thread debugger on the planet. Designed with thread debugging features you've never dreamed of, try TotalView 6 free

[leaf-user] Improving wireless link

2003-06-05 Thread Charles Steinkuehler
as well, but I'd still like to find something that can tweak TCP operation for running over wireless. Thanks for any pointers, -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Etnus, makers of TotalView

Re: [leaf-user] opening port 22 on Dachstein 1.02

2003-05-31 Thread Charles Steinkuehler
-in port-forwarding for ssh: INTERN_SSH_SERVER=192.168.1.1 EXTERN_SSH_PORT=22 instead of the INTERN_SERVERS setting. You still need the EXTERN_TCP_PORTS setting for either of these options to allow the packets through your firewall so they can be forwarded. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] My wife says Ipsec is going to drive her nuts.

2003-05-31 Thread Charles Steinkuehler
Shorewall mail durring business hours anymore): http://www.shorewall.net/IPSEC.htm ...it looks like you might have missed assigning the ipsec0 interface to the VPN zone in /etc/shorewall/interfaces. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Limit Number of Connections

2003-04-02 Thread Charles Steinkuehler
start and end ports for the masquerade range. You may also have to tweak ip_masq.c if you use more than than the default 4096 ports, but I'm not sure. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: ValueWeb

Re: [leaf-user] RFC-3514

2003-04-01 Thread Charles Steinkuehler
] Subject: Re: [leaf-user] RFC-3514 And what day is it today:) Looks like a new Security flag in IPV4 headers will make life much easier for firewalls: ftp://ftp.rfc-editor.org/in-notes/rfc3514.txt -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Multiple routable IPs to multiple non-routable subnets

2003-04-01 Thread Charles Steinkuehler
servers on each network, and are using two networks to keep them isolated from each other, a proxy-arp solution would be worth considering. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: ValueWeb: Dedicated

Re: [leaf-user] Ipsec Setup with Bering LEAF

2003-03-27 Thread Charles Steinkuehler
://www.freeswan.org/freeswan_trees/freeswan-1.99/doc/config.html Note that X.509 support is in the form of a patch, with documentation available at a different location: http://www.strongsec.com/freeswan/ http://www.strongsec.com/freeswan/install.htm -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Ipsec Setup with Bering LEAF

2003-03-27 Thread Charles Steinkuehler
anything about the VPN, so it doesn't have to be happy with RSA keys...only the VPN gateways (the two Bering boxes) need to know anything about the VPN. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored

Re: [leaf-user] RoadWarrior and RSA: What does leftid or rightidmean? conn example

2003-03-26 Thread Charles Steinkuehler
kind of sense, and maybe even answers your question in some sort of round-about way. :) -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: The Definitive IT and Networking Event. Be There! NetWorld+Interop Las

Re: [leaf-user] Help! I can't create RSA Key

2003-03-21 Thread Charles Steinkuehler
processors) and copy them over. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Does your code think in ink? You could win a Tablet PC. Get a free Tablet PC hat just for playing. What are you waiting for? http

Re: [leaf-user] DMZ issues

2003-03-21 Thread Charles Steinkuehler
the firewall's public port (ie imap, pop, custom exchange protcol, or whatever). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by:Crypto Challenge is now open! Get cracking and register here for some mind boggling

Re: [leaf-user] dachstein NTP Internal Time Server - Up and running

2003-03-17 Thread Charles Steinkuehler
, but I couldn't get NTP clients to sync to any but the primary IP of an interface. Of course, if you've got a Mandrake box available, I'd just set that up as you local time server, and sync everything (including the firewall) to it. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] dachstein NTP Internal Time Server - Up and running

2003-03-17 Thread Charles Steinkuehler
personally don't think something like an NTP server should be running on the firewall anyway (run only those things that *HAVE* to be on the firewall for security...fewer applications running means fewer potential security risks). -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] dachstein NTP Internal Time Server - EXTERNAL portsnow open

2003-03-16 Thread Charles Steinkuehler
of your internal interface. If nothing is listening on that port, you either need different NTP software to support the server portion of NTP, or have some kind of configuration problem. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net

Re: [leaf-user] dachstein NTP Internal Time Server - udp internalport looks open

2003-03-16 Thread Charles Steinkuehler
really wacky to the ipchains rules, that's not your problem either. I'd make sure your windows client is actually talking NTP, rather than one of the other (typically simpler) time protocols. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Adding Extra Static IP's on External Interface

2003-03-13 Thread Charles Steinkuehler
specification from the main interface configuration variables. This will break if you have different networks and specify the exact broadcast address, but will work as expected if you use the shorthand + for the broadcast address. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Adding Extra Static IP's on External Interface

2003-03-13 Thread Charles Steinkuehler
for 2.4 to say for sure, however, and it probably depends a lot on exactly how the current traffic is showing up at your router, and why simply adding extra IP addresses didn't work. Grab a tcpdump package (typically requires libpcap as well), and take a look at your trafffic... -- Charles

Re: [leaf-user] Adding Extra Static IP's on External Interface

2003-03-13 Thread Charles Steinkuehler
. FYI: You'll probably want something like the following tcpdump command while attempting to ping: tcpdump -i eth0 -n If possible, run this test when there's not a lot of other activity on your external link. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Winzip and .lrp

2003-03-10 Thread Charles Steinkuehler
than extracting a zip file. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf leaf-user

Re: [leaf-user] One nic router.

2003-03-04 Thread Charles Steinkuehler
can probably provide decent advice. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Etnus, makers of TotalView, The debugger for complex code. Debugging C/C++ programs can leave you feeling lost

Re: [leaf-user] One nic router.

2003-03-04 Thread Charles Steinkuehler
here simply pitch stuff that old. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Etnus, makers of TotalView, The debugger for complex code. Debugging C/C++ programs can leave you feeling lost and disoriented

Re: FW: [leaf-user] Help w/ bcm5700.o module for Dashstein branch

2003-03-03 Thread Charles Steinkuehler
-circuit this process to get the module to compile against the correct kernel source tree if the broadcom modules do something similar. Just holler if you get stuck with anything, and I can probably get you going. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] CGI-BIN problems with thttpd

2003-02-28 Thread Charles Steinkuehler
will generally assume your CGI program crashed, and what gets back to the client (if anything) is server dependent. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf

Re: [leaf-user] Bering 1.1 Web Interface

2003-02-28 Thread Charles Steinkuehler
the threasholds for error and warning levels by editing /etc/weblet.conf. Any error/warning level can also be completely disabled by setting it's threashold value to -1. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email

Re: [leaf-user] Question running Dachstein Router/FW/DHCP/DSN andUnix...

2003-02-28 Thread Charles Steinkuehler
suns to begin to tell you how to debug dynamic configuration. I think ipconfig -a and netstat -nr should work on your sun box. Report their output if you continue to have problems. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net

Re: [leaf-user] sh-httpd Authentication

2003-02-27 Thread Charles Steinkuehler
. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf leaf-user mailing list: [EMAIL

Re: [leaf-devel] RE: [leaf-user] htpasswd Generator

2003-02-27 Thread Charles Steinkuehler
-2.20c.tar.gz -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf leaf-user mailing list

[leaf-user] Re: easy help question

2003-02-26 Thread Charles Steinkuehler
, or download individually from my site: http://lrp.steinkuehler.net/files/kernels/Dachstein-normal/modules/net/fa311.o -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Scholarships for Techies! Can't afford IT training

Re: [leaf-user] sh-httpd Authentication

2003-02-26 Thread Charles Steinkuehler
as insecure enough no-one has felt a pressing need to implement it when there are already good methods for IP based access control, and secure authentication (and encryption) can be provided by tunneling through ssh. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] sh-httpd Authentication

2003-02-26 Thread Charles Steinkuehler
of these already, as well. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Scholarships for Techies! Can't afford IT training? All 2003 ictp students receive scholarships. Get hands-on training in Microsoft

Re: [leaf-user] sh-httpd Authentication

2003-02-26 Thread Charles Steinkuehler
, this has been done by someone already, a google search would probably find it). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Scholarships for Techies! Can't afford IT training? All 2003 ictp students receive

Re: [leaf-user] Problem adding internal networks in Dachstein

2003-02-26 Thread Charles Steinkuehler
indicate any bug fixes related to multiple internal networks, but IIRC, I did have to fix some sort of problem related to that around the time of Dachstein. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored

[leaf-user] Re: [leaf-devel] GRUB problem

2003-02-26 Thread Charles Steinkuehler
the LRP= portion of the linux command line, allowing you to load as many packages as you like. This functionality is part of the linuxrc init scripts, and is distribution specific, although at least Dachstein and Bering support this extention. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Bonehead VPN port number question?

2003-02-21 Thread Charles Steinkuehler
protocols 50 51 to traverse masquerading firewalls can be a problem, there are recent versions of IPSec that support NAT Traversal, by using UDP instead of ESP or AH for the data payloads. IIRC, the same UDP port 500 is typically used, allowing one rule to cover all VPN traffic. -- Charles

Re: [leaf-user] [bug] Dachstein with IPSEC image

2003-02-20 Thread Charles Steinkuehler
, ie: svi ipsec stop net ipfilter reload svi ipsec start Which is one nice thing about using ipchains.forward to implement the forwarding rules, you can simply net ipfilter reload to change firewall rules, and your IPSec link will continue to work. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] IDE HD only for booting and switch to standby

2003-02-20 Thread Charles Steinkuehler
-sector operation, and the speed tests. All of these should work on pretty much any IDE device, not just a mechanical hard-disk. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: SlickEdit Inc. Develop an edge

Re: [leaf-user] hardware requirements bering router 100 mbit+

2003-02-18 Thread Charles Steinkuehler
a P-2 or P-3 system with a BX chipset (or better...anything with a 100 MHz FSB) would give you quite a bit of headroom. -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http

Re: [leaf-user] My Dachstein not quite up and running

2003-02-18 Thread Charles Steinkuehler
Foreign AddressState TCP0.0.0.0:25 0.0.0.0:0 LISTENING -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf

[leaf-user] Re: LEAF/LRP

2003-02-17 Thread Charles Steinkuehler
a firewall running, and allow you to analyze it's characteristics, to see if it is doing what you want. Alternatively, you can directly run ipchains -nvL, and get just the firewall rules, without the port-forwarding information. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Secondary SMTP server for Bering

2003-02-17 Thread Charles Steinkuehler
[EMAIL PROTECTED] wrote: Charles Steinkuehler [EMAIL PROTECTED] wrote on 02/17/2003 02:10:51 PM: You'll also need some sort of non-volitle memory (hdd, flash, etc) for a mail queue. Note that flash tends to be quite slow on writes, which could be a problem for a mail queue (depnding on how

Re: [leaf-user] vlan workstation configuration in linux

2003-02-15 Thread Charles Steinkuehler
conected to this workstation in the bridge I don't receive anything. Do any of you know why? Not without seeing some debugging output. Start with the output of ip addr and ip route, and add any vlan specific commands. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Cisco VPN client through (Dachstein) LRP

2003-02-14 Thread Charles Steinkuehler
}_500_192.168.1.1_500 firewall-# svi network reload I hope this helps! -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: FREE SSL Guide from Thawte are you planning your Web Server Security? Click here to get

Re: [leaf-user] Cisco VPN client through (Dachstein) LRP

2003-02-14 Thread Charles Steinkuehler
ipfilter list to the mailing list, along with any logs you can capture from your IPSec client? -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: FREE SSL Guide from Thawte are you planning your Web Server

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-14 Thread Charles Steinkuehler
don't they are passing traffic (need to run tcpdump to see what's going on, now that I'm an expert!) Charles, thanks again for the education. Glad to help, and thanks for the final report! Lots of folks never let us know how they finally got everything working. -- Charles Steinkuehler [EMAIL

Re: [leaf-user] My Dachstein not quite up and running

2003-02-13 Thread Charles Steinkuehler
/dhcpd.htm http://leaf.steinkuehler.net/devel/cstein/Packages/man/dhcpd.conf.5.man.htm http://leaf.steinkuehler.net/devel/cstein/Packages/man/dhcp-options.5.man.htm -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored

Re: [leaf-user] DS2.2.20 + FS1.99 + WIN2K = Tunnelled but can't ping

2003-02-13 Thread Charles Steinkuehler
is negative. - I'll be glad to send more command results if needed. The FreeS/WAN side logs (in /var/log/auth.log) are always helpful, and the equivelent logs from the windows side (wherever they live) would also be good to review. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Follow Up To: DS2.2.20+FS1.99+WIN2K = Tunnelled butcan't ping

2003-02-13 Thread Charles Steinkuehler
that is typically tunneled inside a VPN protocol (like ipsec). I suggest staying away from l2tp unless absolutely required. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: FREE SSL Guide from Thawte are you

Re: [leaf-user] Cisco VPN client through (Dachstein) LRP

2003-02-13 Thread Charles Steinkuehler
is ignoring you for some reason (invalid authentication credentials, unknown connection description, far-end firewall rules, etc). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: FREE SSL Guide from Thawte are you

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-13 Thread Charles Steinkuehler
tell you everything you need to know (especially if you can do this on both ends). If any packets disappear between the ends (without ICMP errors or similar), you'll know you have to look at the VPN or PPPoE setup. BTW: Do any of your other locations use PPPoE, or just the broken one? -- Charles

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-13 Thread Charles Steinkuehler
GIVE UP!!! :) -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: FREE SSL Guide from Thawte are you planning your Web Server Security? Click here to get a FREE Thawte SSL guide and find the answers to all your

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-13 Thread Charles Steinkuehler
-side traffic dump. You might also try setting the MSS on shorewall to whatever a 1500 byte packet minus the PPPoP and IPSec wrappers comes out to (should be online somewhere). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-13 Thread Charles Steinkuehler
on only those packets traveling to the troublesome PPPoE endpoint. Thank you Charles for a huge chunk of your time!!! Glad to help. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: FREE SSL Guide from Thawte

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-13 Thread Charles Steinkuehler
Todd Pearsall wrote: Charles Steinkuehler wrote Using overridemtu may not be the best solution, but I think it should work properly. While it doesn't look like it's possible to set overridemtu on a per-connection basis, clamping *ALL* VPN traffic to an MTU that fits through the PPPoE links

Re: [leaf-user] My Dachstein not quite up and running

2003-02-12 Thread Charles Steinkuehler
relates to DNS. Run ipconfig /all on your internal systems, and compare the DNS settings. Once you figure out which settings work, and which are broken, we can begin to determine why, and fix the problem. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-12 Thread Charles Steinkuehler
by sniffing your problematic traffic at this point...once you figure out what's wrong, an appropriate fix will likely present itself. Note that you can get tcpdump for LEAF, which I find very handy in these situations. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-12 Thread Charles Steinkuehler
decode it. Don't try to be helpful and pull any lines from the tcpdump...you might pull something significant and not realize it. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-02-12 Thread Charles Steinkuehler
). Probably take you less time than it took me to write this e-mail... -- Charles Steinkuehler [EMAIL PROTECTED] --- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf

Re: [leaf-user] Dachstein Port Forwarding

2003-02-11 Thread Charles Steinkuehler
everything will begin working. If you continue to have problems, post the network confiuration (ipconfig /all and route print) from the Exchange box for debugging. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored

Re: [leaf-user] Using a wireless router with LEAF (Dachstein, Bering)

2003-02-11 Thread Charles Steinkuehler
security model. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com

Re: [leaf-user] Aliasing IP Addres : HOWTO do ?

2003-02-11 Thread Charles Steinkuehler
with a route to it's subnet. Details on configuring this to happen automatically at startup, and modifying any firewall rules as required are distribution specific, and you failed to mention which distribution you are running. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] IPsec routing

2003-02-11 Thread Charles Steinkuehler
specific /1 routes through the VPN take precedence over any /0 default route you may (or may not) have in place. It's a simple safety measure to insure no unencrypted traffic is sent out by mistake. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Win2K and LEAF

2003-02-10 Thread Charles Steinkuehler
. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com

Re: [leaf-user] More Bering IPSec questions ...

2003-02-10 Thread Charles Steinkuehler
to figure out who you're talking to, and which connection description to use. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http

Re: [leaf-user] [problems] Dachstein with IPSec

2003-02-10 Thread Charles Steinkuehler
pages for more usage info. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com

Re: [leaf-user] Dachstein Port Forwarding

2003-02-10 Thread Charles Steinkuehler
for debugging, along with the results of the above tests if you can't get things working. Some details about your ISP (including where your are, as folks like RoadRunner and Cox do things differently in different cities) would also help. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] My Dachstein not quite up and running

2003-02-08 Thread Charles Steinkuehler
$192.168.1.2_smtp_10.10.10.200_smtp Um...didn't you just indicate your internal exchange box is 10.10.10.2, *NOT* 10.10.10.200?!? Probably a big part of your problem! -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored

Re: [leaf-user] Win2K and LEAF

2003-02-08 Thread Charles Steinkuehler
it has to be better than NT, and we'll have to upgrade someday anyway, right?!?. sigh ...sorry about the rant :-/ -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM

Re: [leaf-user] My Dachstein not quite up and running

2003-02-08 Thread Charles Steinkuehler
), make sure you properly updated the name-servers option in /etc/dhcpd.conf. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http

Re: [leaf-user] DACHSTEIN VS BERING

2003-02-02 Thread Charles Steinkuehler
examples of what you're seeing on each platform, we can probably tell you more about exactly what's going on. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld

Re: [leaf-user] PPPoE, IPSec and MTU size problems

2003-01-31 Thread Charles Steinkuehler
the registry tweaks required for good performance on a high-bandwidth internet link. This increases the TCP window size, which helps M$ systems deal with high-latency networks. That's important for your VPN as well as for maximizing kazza download speed. :-) -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] My Dachstein not quite up and running

2003-01-30 Thread Charles Steinkuehler
sort of basic connectivity, e-mail any specific problems to the list, and we can get you up an running quickly. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld

Re: [leaf-user] My Dachstein not quite up and running

2003-01-30 Thread Charles Steinkuehler
information for debugging: Firewall: output of ip addr output of ip route contents of /etc/dhcpd.conf NT Box: output of ipconfig /all output of route print -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored

[leaf-user] Re: [leaf-devel] VNC, SSH, port forward

2003-01-27 Thread Charles Steinkuehler
firewall, and remote resolves to the ip of your remote system. You might also try an explicit IP (of the remote system, not the firewall) or the localhost (127.0.0.1) for remote, to make sure you're not getting hung up by name resolution issues. -- Charles Steinkuehler [EMAIL PROTECTED

[leaf-user] Re: [leaf-devel] VNC, SSH, port forward

2003-01-27 Thread Charles Steinkuehler
5900:192.168.3.200:5907 leaf.public.ip NOTE: It is OK to have a private IP in your port-forwarding switch to ssh. As long as the remote end can resolve and connect to the IP or hostname provided, everything will work. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] Passive FTP on Dachstein

2003-01-26 Thread Charles Steinkuehler
-forwarding, you also have to make sure your firewall rules allow the inbound traffic. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http

Re: [leaf-user] DS 2.2.19+FSwan1.91+WIN2K=sub2sub VPN interop?

2003-01-25 Thread Charles Steinkuehler
a server or advanced-server license, if you're trying to use 2K-Pro for a subnet-subnet connection. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something

Re: [leaf-user] H323/NetMeeting support in Bering

2003-01-22 Thread Charles Steinkuehler
Google string: linux netmeeting firewall -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.net email is sponsored by: Scholarships for Techies! Can't afford IT training? All 2003 ictp students receive scholarships. Get hands-on training

Re: [leaf-user] Dachstein Dead?

2003-01-22 Thread Charles Steinkuehler
about this as much as I should. I'm still running Dachstein on a number of production systems, as I have not yet overcome the inertia to migrate to IPTables/Shorewall/Bering. I do, however, recommend Bering if you're just starting out with LEAF, as it is being actively developed. -- Charles

[leaf-user] Re: Dachstein 1.02 and PCMCIA

2003-01-20 Thread Charles Steinkuehler
and/or using a 2.4 kernel (such as the kernel from Bering), unless there is an absolute requirement for Dachstein. IIRC, the 2.4 kernels support PCMCIA much better than 2.2 kernels, but I could be wrong, since I don't work with portable stuff. -- Charles Steinkuehler [EMAIL PROTECTED

Re: [leaf-user] My Dachstein not quite up and running

2003-01-17 Thread Charles Steinkuehler
) for details on how to report enough information we can help you. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: Thawte.com - A 128-bit supercerts will allow you to extend the highest allowed 128 bit

[leaf-user] LEAF in SysAdmin

2003-01-17 Thread Charles Steinkuehler
and the rest of the Bering crew! -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: Thawte.com - A 128-bit supercerts will allow you to extend the highest allowed 128 bit encryption to all your clients even

[leaf-user] Re: PPPoE help

2003-01-15 Thread Charles Steinkuehler
] Start browsing the leaf site: http://leaf-project.org There are several disk-images available that support PPPoE, and you should be able to easily modify them to load packages remotely, or you could create a large initial ramdisk image that included all required packages. -- Charles Steinkuehler

Re: [leaf-user] Dachstein Config, HW Issue or Comcast Download Cap?Approx 2MB dl Limit

2003-01-14 Thread Charles Steinkuehler
problems, and are not uncommon on old hardware). You might also want to do some googling on your chipset. There may be some early PCI chipsets/BIOSes that don't quite work right, and could cause strange problems. You can also try using different NICs, to see if that helps. -- Charles Steinkuehler

Re: [leaf-user] Partial backup problems with Dachstein CD

2003-01-14 Thread Charles Steinkuehler
, but AFAIK, it should still work (at least I haven't heard any other reports of problems). -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email is sponsored by: Take your first step towards giving your online business

Re: [leaf-user] Netmeeting and IP Telephony behind Dachstein

2003-01-14 Thread Charles Steinkuehler
to your internal client, and possibly open some UDP ports on the firewall to inbound traffic. More details should be available by googling and/or searching the list archives. -- Charles Steinkuehler [EMAIL PROTECTED] --- This SF.NET email

<    1   2   3   4   5   6   7   8   9   10   >