From owner-fwtk-users@ex.tis.com Thu Jun  1 09:09 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA02343
	Thu, 1 Jun 2000 09:09:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA23387;
	Thu, 1 Jun 2000 06:16:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Jun 2000 05:35:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA21667
	for fwtk-users-outgoing; Thu, 1 Jun 2000 05:35:44 -0700 (PDT)
Message-ID: <3934402A.1B5B5123@altavista.net>
Date: Wed, 31 May 2000 00:26:50 +0200
From: "Alvaro =?iso-8859-1?Q?Mu=F1oz=2DAycuens?= M." <alvarom@altavista.com>
Organization: =?iso-8859-1?Q?=B8?=,=?iso-8859-1?Q?=F8=A4=BA=B0=60=B0=BA=A4=F8?=,
	=?iso-8859-1?Q?=B8=B8?=,=?iso-8859-1?Q?=F8=A4=BA=B0=60?= Aycuens 
	Security =?iso-8859-1?Q?=B0=BA=A4=F8?=,=?iso-8859-1?Q?=B8=B8?=,
	=?iso-8859-1?Q?=F8=A4=BA=B0=60=B0=BA=A4=F8?=,=?iso-8859-1?Q?=B8?=
X-Mailer: Mozilla 4.72 [en] (Win98; U)
X-Accept-Language: en,es
MIME-Version: 1.0
To: Lista FWTK <fwtk-users@ex.tis.com>
Subject: Controled relaying
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 837

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi to all

I had been using smap with yao patches for some time, performing like a
charm, now I need to permit relay to some users that are travelling
around my country since the isp we are using use dinamic IP and i don't
want to open the relay for all his netblock, is there anyway to have a
controled realying?

Note: They have to send mail to anybody on the internet and i have tried
with the broken from, how does broken from test?
Thanks in advance
-- 
Alvaro MuŅoz-Aycuens Martinez
El Argonauta Virtual
C\Gaztambide 9
28015 Madrid Spain
alvarom@altavista.net

KeyID 2048/0xA1378C19
Fingerprint BB E8 6D 56 83 4A 3A 9E D2 12 2F AA AB 9F 76 72
PGP Key Available at http:\\alvarom.freeshell.org/pgp.html

From owner-fwtk-users@ex.tis.com Thu Jun  1 09:09 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA02345
	Thu, 1 Jun 2000 09:09:23 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA23383;
	Thu, 1 Jun 2000 06:16:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Jun 2000 05:18:54 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA21408
	for fwtk-users-outgoing; Thu, 1 Jun 2000 05:18:43 -0700 (PDT)
Message-Id: <4.2.2.20000531221753.00cda170@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Wed, 31 May 2000 22:21:35 -0400
To: "Ken Long" <ken@lectrosonics.com>,
        TIS Mailing List <fwtk-users@ex.tis.com>, DAVIDT@lectrosonics.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: smap and mail from:<>
In-Reply-To: <3934BD0A.27638.27DF7B@localhost>
References: <4.2.2.20000530203320.00c6b690@mail.itm-inst.com>
 <Pine.GSO.4.10.10005301755490.11652-100000@ns1.bfg.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 925

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:19 AM 5/31/00 -0600, Ken Long wrote:
>[To be removed from this list send the message "unsubscribe fwtk-users" in the
>BODY of a mail message to majordomo@ex.tis.com.]
>
>Ok, this makes sense.  Now, do you have any suggestions for allowing "mail
>from:<>" yet still keeping the spam protection that blocking non-verifyable
>from addresses provides?  Remember, our site is using sendmail behind smap.

I use 'smap: broken-from <>" to permit these in.
(Joe Yao smap with my own RBL hooks; my configuration below.)
smap:           domains itm-inst.com *.itm-inst.com
smap:           localhosts *.itm-inst.com
smap:           scrub-spam 1
smap:           broken-from <>
#smap:          check-from-address 1

Enabling 'from' address checking broke far more mail than it was worth.
         -Rick

From owner-fwtk-users@ex.tis.com Thu Jun  1 09:15 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA02386
	Thu, 1 Jun 2000 09:15:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA23636;
	Thu, 1 Jun 2000 06:22:46 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Jun 2000 05:43:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA21890
	for fwtk-users-outgoing; Thu, 1 Jun 2000 05:42:44 -0700 (PDT)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3934DDBF.F807CF40@usrconsult.be>
Date: Wed, 31 May 2000 11:39:11 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: UsrConsult SPRL
X-Mailer: Mozilla 4.5 [en] (X11; I; IRIX64 6.5 IP27)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Re: SSL tunneling
References: <A30AA7228345D311A8FF009027935C8001AF5B@dominika.fnplzen.cz>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 3104

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Mikes Roman wrote:
> 
> Hi,
> i have just a problem. I need to connect external users to internal S-HTTP
> server.

I assume by "external" you mean "on the big bad Internet" and by
"internal"
you mean your truly internal (corporate or whatever) network, not your
DMZ?
Well, one should not do that, because although SSL provides session
encryption
and authenticates the server to the client, AFAIK it does *NOT*
authenticate
the client to the server (anyone on the list knows how to use
client-side
certificates?) Since the incoming SSL traffic is not authenticated, it
should
not be tunnelled through the firewall. If the HHTPS server really has to
be on
your internal net rather than the DMZ, consider using SSH (H, not L!)
with
forwarding of port 443. Note that it is a requirement that the clients
are
trusted, so they must be properly protected and administered machines
with trusted
users at the keyboard!

> Could you recommend me any solution. Now i use plug-gw whithout
> option -ssl:
> 
> running daemon: plug-gw -daemon https
> netperm-table: plug-gw:         port https -plug-to w.x.y.z

Should work (except for the security problems above!)

> 
> with option -ssl it doesn't work:  plug-gw:     port https -plug-to w.x.y.z
> -ssl

The -ssl option is actually a misnomer. What it does is to force plug-gw
to
expect an HTTP request of the form "CONNECT host:port HTTP/1.0" and then
establish the connection. After that, it does not care at all what goes
on.
It is called "-ssl" because it was created specifically to allow
*outgoing*
HTTPS requests, but it does not know anything about SSL. As a matter of
fact,
NETSCAPE 4 abuses the security proxy to pass ICQ through the firewall!

Since your external clients consider you as a server, not as a "security
proxy",
they come with an HTTP "GET", not "CONNECT", which is why it does not
work.

Besides, unless you have ipchains, ipfwadm, ipfilter, iptables or netacl
rules that you
did not quote, "plug-gw -ssl" is bloody dangerous: it allows anyone to
bounce a
connection from your site, hence to perform attacks (DoS, spam, mail
relay or whatever)
as if it came from you!
> 
> 1. What is proper configuration of plug-gw or http-gw for tunneling https ?

Either you put your server in the DMZ, in which case plug-gw works fine
to
relay HTTPS; we do not use http-gw here so I can't comment on its use as
proxy for
incoming traffic.

Or you have to have your server in your intranet, in which case HTTPS
over SSH
over plug-gw is the only solution.

> 2. Does any special ssl gateway like fwtk extension exist ?

An "SSL aware" gateway is 'ex hypothesis' impossible, since the traffic
is encrypted.
Actually, it would be nice if "plug-gw -ssl" were able to *recognize*
SSL traffic and 
reject other protocols like ICQ, IRC,...

> 3. Whitch solution of 1. and 2. is better ?
> 
> Thanks Roman

-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10

From owner-fwtk-users@ex.tis.com Thu Jun  1 11:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA02796
	Thu, 1 Jun 2000 11:24:47 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA26407;
	Thu, 1 Jun 2000 08:31:53 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Jun 2000 07:18:53 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA25546
	for fwtk-users-outgoing; Thu, 1 Jun 2000 07:18:42 -0700 (PDT)
From: ark@eltex.ru
Date: Thu, 1 Jun 2000 18:15:19 +0400
Message-Id: <200006011415.SAA12622@paranoid.eltex.spb.ru>
In-Reply-To: <3934402A.1B5B5123@altavista.net> from ""Alvaro =?iso-8859-1?Q?Mu=F1oz=2DAycuens?= M." <alvarom@altavista.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: Controled relaying
To: alvarom@altavista.com
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1623

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Why not to send via ISP's relay?

"Alvaro =?iso-8859-1?Q?Mu=F1oz=2DAycuens?= M." <alvarom@altavista.com> said :

> I had been using smap with yao patches for some time, performing like a
> charm, now I need to permit relay to some users that are travelling
> around my country since the isp we are using use dinamic IP and i don't
> want to open the relay for all his netblock, is there anyway to have a
> controled realying?
> 
> Note: They have to send mail to anybody on the internet and i have tried
> with the broken from, how does broken from test?
> Thanks in advance
> -- 
> Alvaro MuŅoz-Aycuens Martinez
> El Argonauta Virtual
> C\Gaztambide 9
> 28015 Madrid Spain
> alvarom@altavista.net
> 
> KeyID 2048/0xA1378C19
> Fingerprint BB E8 6D 56 83 4A 3A 9E D2 12 2F AA AB 9F 76 72
> PGP Key Available at http:\\alvarom.freeshell.org/pgp.html
> 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBOTZv9qH/mIJW9LeBAQEgGgQAtGBWfADcXDmYOmlJMlc8HlXaWosfWhfN
7pEZ61FguUHOWxLboyi2ZXDH7vttMu4wScDohHcWgQPRXpGeZ/n23MrkVp7keaKe
Sc4OBLQzdS/0jkQpr2ImQiUpu36BHZHm5SIkYNn4F4Ipbm9JvpPe7i5ysND9lLEW
71GWBOfHa8Y=
=3l5r
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Thu Jun  1 12:08 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA02945
	Thu, 1 Jun 2000 12:07:57 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA27614;
	Thu, 1 Jun 2000 09:15:03 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Jun 2000 08:31:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA26385
	for fwtk-users-outgoing; Thu, 1 Jun 2000 08:31:07 -0700 (PDT)
Message-ID: <XFMail.000601173047.mm@i.cz>
X-Mailer: XFMail 1.3 [p0] on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <3934DDBF.F807CF40@usrconsult.be>
Date: Thu, 01 Jun 2000 17:30:47 +0200 (MET DST)
Reply-To: mm@i.cz
From: Martin Machacek <mm@i.cz>
To: fwtk-users@tis.com
Subject: Re: SSL tunneling
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-2
Content-Length: 2565

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


On 31-May-00 Michel Bardiaux wrote:
> I assume by "external" you mean "on the big bad Internet" and by
> "internal" you mean your truly internal (corporate or whatever) network, not
> your DMZ?
> Well, one should not do that, because although SSL provides session
> encryption and authenticates the server to the client, AFAIK it does *NOT*
> authenticate the client to the server (anyone on the list knows how to use
> client-side certificates?)

It depends in which application. It is quite easy in WWW browsers. Both
Netscape and MSIE allow to use client certificate for authentication. All WWW
servers worth their names support client authentication in SSL. There are
OpenSource SSL proxies supporting client authentication (e.g. stunnel).

> Since the incoming SSL traffic is not authenticated, it should
> not be tunnelled through the firewall. If the HHTPS server really has to
> be on your internal net rather than the DMZ, consider using SSH (H, not L!)
> with forwarding of port 443. Note that it is a requirement that the clients
> are trusted, so they must be properly protected and administered machines
> with trusted users at the keyboard!

Or use ssl proxy on the firewall.

> The -ssl option is actually a misnomer. What it does is to force plug-gw
> to expect an HTTP request of the form "CONNECT host:port HTTP/1.0" and then
> establish the connection. After that, it does not care at all what goes
> on.

It even cannot care what goes on, because the rest of the communication is
encrypted :-).

> Since your external clients consider you as a server, not as a "security
> proxy", they come with an HTTP "GET", not "CONNECT", which is why it does not
> work.

You can try stunnel, see: http://mike.daewoo.com.pl/computer/stunnel
It should work in theis scenario and it will allow you to do client
authetication is SSL at the firewall. The other possibility is to use simple
plug-gw (without -ssl) and plug the incoming HTTPS connection directly to the
internal server. This is doable only if you trust the internal server and there
is potential risk of denial of service attacks. 

> An "SSL aware" gateway is 'ex hypothesis' impossible, since the traffic
> is encrypted.

However, the gateway can serve as the endpoint of the SSL connection from
client and establish another one (of course with different certificate) to the
inside and realy all data between those two.


        Martin 

---
[PGP KeyID F3F409C4]

From owner-fwtk-users@ex.tis.com Thu Jun  1 20:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA06861
	Thu, 1 Jun 2000 20:33:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA02955;
	Thu, 1 Jun 2000 17:40:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Jun 2000 16:47:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA02091
	for fwtk-users-outgoing; Thu, 1 Jun 2000 16:47:35 -0700 (PDT)
Message-ID: <009301bfb490$7061a140$1b20a0d4@ppp>
From: "Olaf" <olafpcs@poczta.onet.pl>
To: "TIS - fwtk users" <fwtk-users@tis.com>
Subject: libfwall.a?
Date:   Wed, 3 May 2000 01:45:01 +0200
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2417.2000
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0090_01BFB4A1.31FC0EC0"
Content-Length: 1807

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_0090_01BFB4A1.31FC0EC0
Content-Type: text/plain;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

Hi all !

I've linux RH 5.2 kernel 2.0.36 and fwtk from the TIS sides.
But I can't compile source because I haven't libfwall.a .
I can't find this file.
Thanks in advance

PS
I'm sorry - my english is poor.

OLAF
olafpcs@poczta.onet.pl


------=_NextPart_000_0090_01BFB4A1.31FC0EC0
Content-Type: text/html;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Diso-8859-2" =
http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2314.1000" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3D"Arial CE" size=3D2>Hi all !</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>I've linux RH 5.2 kernel 2.0.36 =
and fwtk from=20
the TIS sides.</FONT></DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>But&nbsp;I&nbsp;can't compile =
source because=20
I&nbsp;haven't libfwall.a .<BR>I&nbsp;can't&nbsp;find this =
file.</FONT><FONT=20
face=3D"Arial CE" size=3D2><BR>Thanks in advance</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>PS<BR>I'm sorry - my english is=20
poor.</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>OLAF<BR><A=20
href=3D"mailto:olafpcs@poczta.onet.pl">olafpcs@poczta.onet.pl</A></FONT><=
/DIV>
<DIV><FONT face=3D"Arial CE" size=3D2><A=20
href=3D"mailto:olafpcs@poczta.onet.pl"></A></FONT>&nbsp;</DIV></BODY></HT=
ML>

------=_NextPart_000_0090_01BFB4A1.31FC0EC0--


From owner-fwtk-users@ex.tis.com Fri Jun  2 08:04 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA08433
	Fri, 2 Jun 2000 08:04:35 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA12210;
	Fri, 2 Jun 2000 05:11:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 04:17:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA10930
	for fwtk-users-outgoing; Fri, 2 Jun 2000 04:17:40 -0700 (PDT)
From: "Piet Bos" <p.bos@lake.xs4all.nl>
To: <fwtk-users@tis.com>
Subject: trouble with the compilation/linking of authsrv 
Date: Fri, 2 Jun 2000 13:17:01 +0200
Message-ID: <000101bfcc84$13bb3ad0$0b00a8c0@gate.thuis>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Importance: Normal
X-Hops: 1
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 716

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I'm having trouble during the make of the pass.c source.
The error I'm getting is:

pass.o: In function `passverify':
/usr/local/fwtk/auth/pass.c:39: undefined reference to `crypt`
pass.o: In function `passset':
/usr/local/fwtk/auth/pass.c:70: undefined reference to `crypt`
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

I using gcc 2.91.66 on redhat 6.2 (Zoot) with kernel 2.2.14-5.0
The version of fwtk is 2.1 downloaded at Tis.com on May 29

Is there anyone who can help me?

cheers Pieter.
--
Pieter Bos
p.bos@lake.xs4all.nl
bos_p@hotmail.com
pieter_bos@yahoo.com

From owner-fwtk-users@ex.tis.com Fri Jun  2 08:44 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA08517
	Fri, 2 Jun 2000 08:44:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA13674;
	Fri, 2 Jun 2000 05:51:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 05:09:25 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA12139
	for fwtk-users-outgoing; Fri, 2 Jun 2000 05:09:20 -0700 (PDT)
From: Ted_Rule@flextech.co.uk
X-Lotus-FromDomain: FLEXTECH
To: fwtk-users@tis.com
Message-ID: <802568F2.0042BA25.00@fttvgpslnhub1.flextech.co.uk>
Date: Fri, 2 Jun 2000 13:09:13 +0100
Subject: Re: trouble with the compilation/linking of authsrv
Mime-Version: 1.0
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1277

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



This may be your problem.

Within Makefile.config in the source tree:

# Some versions of Linux have broken the crypt() function out into a
# separate library - uncomment the following line if authsrv fails to build.
AUXLIB= -lcrypt






"Piet Bos" <p.bos@lake.xs4all.nl> on 02/06/2000 12:17:01

To:   fwtk-users@tis.com
cc:    (bcc: Ted Rule/160GPS/Flextech/UK)

Subject:  trouble with the compilation/linking of authsrv



[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I'm having trouble during the make of the pass.c source.
The error I'm getting is:

pass.o: In function `passverify':
/usr/local/fwtk/auth/pass.c:39: undefined reference to `crypt`
pass.o: In function `passset':
/usr/local/fwtk/auth/pass.c:70: undefined reference to `crypt`
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

I using gcc 2.91.66 on redhat 6.2 (Zoot) with kernel 2.2.14-5.0
The version of fwtk is 2.1 downloaded at Tis.com on May 29

Is there anyone who can help me?

cheers Pieter.
--
Pieter Bos
p.bos@lake.xs4all.nl
bos_p@hotmail.com
pieter_bos@yahoo.com





From owner-fwtk-users@ex.tis.com Fri Jun  2 09:35 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA08673
	Fri, 2 Jun 2000 09:35:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA15692;
	Fri, 2 Jun 2000 06:42:37 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 05:54:27 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA13791
	for fwtk-users-outgoing; Fri, 2 Jun 2000 05:54:21 -0700 (PDT)
Message-ID: <3937C7E6.2884BD77@tyc.es>
Date: Fri, 02 Jun 2000 16:42:46 +0200
From: Jacobo Gonzalez Simon <jacobo@tyc.es>
X-Mailer: Mozilla 4.5 [es] (Win98; I)
X-Accept-Language: es
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Re: trouble with the compilation/linking of authsrv
References: <000101bfcc84$13bb3ad0$0b00a8c0@gate.thuis>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id FAA13781
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1103

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hello,
I had a similar problem with another product and i fixed it adding an
option -lcrypt at end of compile line in the Makefile file.

gcc "OPTIONS" -lcrypt

Sorry for my poor english
Piet Bos escribió:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I'm having trouble during the make of the pass.c source.
> The error I'm getting is:
> 
> pass.o: In function `passverify':
> /usr/local/fwtk/auth/pass.c:39: undefined reference to `crypt`
> pass.o: In function `passset':
> /usr/local/fwtk/auth/pass.c:70: undefined reference to `crypt`
> collect2: ld returned 1 exit status
> make: *** [authsrv] Error 1
> 
> I using gcc 2.91.66 on redhat 6.2 (Zoot) with kernel 2.2.14-5.0
> The version of fwtk is 2.1 downloaded at Tis.com on May 29
> 
> Is there anyone who can help me?
> 
> cheers Pieter.
> --
> Pieter Bos
> p.bos@lake.xs4all.nl
> bos_p@hotmail.com
> pieter_bos@yahoo.com

From owner-fwtk-users@ex.tis.com Fri Jun  2 18:54 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA11199
	Fri, 2 Jun 2000 18:54:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA21746;
	Fri, 2 Jun 2000 16:01:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 14:45:38 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA20598
	for fwtk-users-outgoing; Fri, 2 Jun 2000 14:45:32 -0700 (PDT)
From: "Piet Bos" <p.bos@lake.xs4all.nl>
To: <fwtk-users@tis.com>
Subject: RE: trouble with the compilation/linking of authsrv
Date: Fri, 2 Jun 2000 23:43:46 +0200
Message-ID: <000001bfccdb$a16d1d10$0b00a8c0@gate.thuis>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
In-Reply-To: <802568F2.0042BA25.00@fttvgpslnhub1.flextech.co.uk>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
X-Hops: 1
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1793

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Alas,
it din't do the trick, I'm still having difficulties making authsrv.
Is there something else to do, so it will work?

Piet.

-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of Ted_Rule@flextech.co.uk
Sent: Friday, June 02, 2000 2:09 PM
To: fwtk-users@tis.com
Subject: Re: trouble with the compilation/linking of authsrv


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]



This may be your problem.

Within Makefile.config in the source tree:

# Some versions of Linux have broken the crypt() function out into a
# separate library - uncomment the following line if authsrv fails to build.
AUXLIB= -lcrypt






"Piet Bos" <p.bos@lake.xs4all.nl> on 02/06/2000 12:17:01

To:   fwtk-users@tis.com
cc:    (bcc: Ted Rule/160GPS/Flextech/UK)

Subject:  trouble with the compilation/linking of authsrv



[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

I'm having trouble during the make of the pass.c source.
The error I'm getting is:

pass.o: In function `passverify':
/usr/local/fwtk/auth/pass.c:39: undefined reference to `crypt`
pass.o: In function `passset':
/usr/local/fwtk/auth/pass.c:70: undefined reference to `crypt`
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

I using gcc 2.91.66 on redhat 6.2 (Zoot) with kernel 2.2.14-5.0
The version of fwtk is 2.1 downloaded at Tis.com on May 29

Is there anyone who can help me?

cheers Pieter.
--
Pieter Bos
p.bos@lake.xs4all.nl
bos_p@hotmail.com
pieter_bos@yahoo.com





From owner-fwtk-users@ex.tis.com Fri Jun  2 19:27 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA11267
	Fri, 2 Jun 2000 19:27:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA22732;
	Fri, 2 Jun 2000 16:34:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 15:51:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA21491
	for fwtk-users-outgoing; Fri, 2 Jun 2000 15:51:38 -0700 (PDT)
Message-ID: <393871D3.B1EA5236@cetec.br>
Date: Fri, 02 Jun 2000 23:47:47 -0300
From: Andre Gustavo Lomonaco <lomonaco@cetec.br>
X-Mailer: Mozilla 4.7 [en] (X11; I; SunOS 5.8 i86pc)
X-Accept-Language: en
MIME-Version: 1.0
To: TIS Mailing List <fwtk-users@ex.tis.com>
Subject: Problem with squid-gw 1.3
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 583

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I'm trying to use the new squid-gw, version 1.3, but only I got is the
following error when I use a FQDN, like www.sun.com

Error detected by squid-gw:
Duplicate response header field: X-Cache: MISS from cache.cetec.br

When I use the IP address, for example, 192.18.97.195 (www.sun.com), it
works fine...

I had been using squid-gw version 0.8 without problems...

Sorry for my bad english and any tip will be welcome.....

Thanks

Andre Lomonaco


From owner-fwtk-users@ex.tis.com Sat Jun  3 00:16 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA11784
	Sat, 3 Jun 2000 00:16:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA26326;
	Fri, 2 Jun 2000 21:23:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 20:30:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA24797
	for fwtk-users-outgoing; Fri, 2 Jun 2000 20:30:29 -0700 (PDT)
Message-Id: <4.2.2.20000602231705.00ccac70@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Fri, 02 Jun 2000 23:18:41 -0400
To: "Olaf" <olafpcs@poczta.onet.pl>, "TIS - fwtk users" <fwtk-users@tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: libfwall.a?
In-Reply-To: <009301bfb490$7061a140$1b20a0d4@ppp>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 623

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 01:45 AM 5/3/00 +0200, Olaf wrote:
>Hi all !
>
>I've linux RH 5.2 kernel 2.0.36 and fwtk from the TIS sides.
>But I can't compile source because I haven't libfwall.a .
>I can't find this file.
>Thanks in advance
libfwall.a is created when you make fwtk. The source files in fwtk/lib are 
compiled to make this library.
If your libfwall isn't being built, one of the compile operations is not 
working.
Try using 'make' from the top-level fwtk directory and watch for errors.
         -Rick


From owner-fwtk-users@ex.tis.com Sat Jun  3 00:16 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA11785
	Sat, 3 Jun 2000 00:16:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA26330;
	Fri, 2 Jun 2000 21:23:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Jun 2000 20:30:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA24798
	for fwtk-users-outgoing; Fri, 2 Jun 2000 20:30:29 -0700 (PDT)
Message-Id: <4.2.2.20000602232058.00d0a1a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Fri, 02 Jun 2000 23:23:21 -0400
To: "Piet Bos" <p.bos@lake.xs4all.nl>, <fwtk-users@tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: RE: trouble with the compilation/linking of authsrv
In-Reply-To: <000001bfccdb$a16d1d10$0b00a8c0@gate.thuis>
References: <802568F2.0042BA25.00@fttvgpslnhub1.flextech.co.uk>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 445

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:43 PM 6/2/00 +0200, Piet Bos wrote:
>Alas,
>it din't do the trick, I'm still having difficulties making authsrv.
>Is there something else to do, so it will work?

Disable password authentication - it shouldn't be used anyway.
(edit auth.h to comment out the '#define AUTHPROTO_PASSWORD' line.)
         -Rick


From owner-fwtk-users@ex.tis.com Sat Jun  3 06:52 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA12376
	Sat, 3 Jun 2000 06:52:23 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA00344;
	Sat, 3 Jun 2000 03:59:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 3 Jun 2000 03:05:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA29389
	for fwtk-users-outgoing; Sat, 3 Jun 2000 03:05:06 -0700 (PDT)
Message-ID: <005201bfcd4a$f1119ac0$6402a8c0@ppks4.pks-4.metronet.chelm.pl>
From: "olaf" <olafpcs@poczta.onet.pl>
To: "TIS-fwtk-users" <fwtk-users@tis.com>
Date:   Sat, 3 Jun 2000 12:00:31 +0100
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 4.72.3612.1700
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3612.1700
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_004F_01BFCD53.514C5580"
Content-Length: 1271

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_004F_01BFCD53.514C5580
Content-Type: text/plain;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

Hi all !

Thanks, thanks, thanks... all.

All is OK.

OLAF
olafpcs@poczta.onet.pl

------=_NextPart_000_004F_01BFCD53.514C5580
Content-Type: text/html;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">
<HTML>
<HEAD>

<META content=3Dtext/html;charset=3Diso-8859-2 =
http-equiv=3DContent-Type>
<META content=3D'"MSHTML 4.72.3612.1706"' name=3DGENERATOR>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>Hi all !</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT color=3D#000000 size=3D2>Thanks, thanks, thanks... =
all.</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT size=3D2>All is OK.</FONT></DIV>
<DIV><FONT size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>OLAF<BR><A=20
href=3D"mailto:olafpcs@poczta.onet.pl">olafpcs@poczta.onet.pl</A></FONT><=
/DIV></DIV></BODY></HTML>

------=_NextPart_000_004F_01BFCD53.514C5580--


From owner-fwtk-users@ex.tis.com Sat Jun  3 07:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA12429
	Sat, 3 Jun 2000 07:56:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA01934;
	Sat, 3 Jun 2000 05:02:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 3 Jun 2000 04:15:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA00613
	for fwtk-users-outgoing; Sat, 3 Jun 2000 04:15:35 -0700 (PDT)
Message-ID: <008301bfcd54$d4c6ab80$6402a8c0@ppks4.pks-4.metronet.chelm.pl>
From: "olaf" <olafpcs@poczta.onet.pl>
To: "TIS-fwtk-users" <fwtk-users@tis.com>
Subject: Can you tell us if anything else is failing?
Date:   Sat, 3 Jun 2000 13:11:12 +0100
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 4.72.3612.1700
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3612.1700
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_007C_01BFCD5D.30F9E7C0"
Content-Length: 5079

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_007C_01BFCD5D.30F9E7C0
Content-Type: text/plain;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

Hi all !
...
>Can you tell us if anything else is failing?
...
Ja jestem ju=BF zadowolony.
Ja musz=EA teraz troch=EA zrobi=E6 co=B6 z fwtk zanim zn=F3w znajd=EA =
jaki=B6 problem.
Teraz mam tylko kilka komunikat=F3w przy kompilacji \fwtk\tools:

I'm right now contented.
I must now a little make anything with fwtk before again I find any =
problem.
I've now only a few errors in time compilation \fwtk\tools:

1. ...\fwtk\tools\server\ftpd
    glob.o Error1
    glob.c: In function 'matchdir'
    glob.c:231: deferencing pointer to incomplete type
   =20
2. ...\fwtk\tools\client
    du=BFo komunikat=F3w:
            ftp.c:xxxx: warning: passing arg 2 of 'signal' from =
incompatible pointer type
                  xxxx=3D..., 1016, 1018, 1047, ..., 1280,..., 1424, =
..., 1668
       and
           ftp.c:xxxx storage size of 'mask' isn't know
                 xxxx=3D..., 1367: In funktion 'pswitch', 1367: In =
funktion 'proxtrans', 1673: In funktion 'reset'

This hasn't weight yet.

(I'm sorry - my english is poor)       =20

OLAF
olafpcs@poczta.onet.pl

------=_NextPart_000_007C_01BFCD5D.30F9E7C0
Content-Type: text/html;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">
<HTML>
<HEAD>

<META content=3Dtext/html;charset=3Diso-8859-2 =
http-equiv=3DContent-Type>
<META content=3D'"MSHTML 4.72.3612.1706"' name=3DGENERATOR>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV>
<DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>Hi all !</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>...</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>&gt;Can you tell us if anything else =
is=20
failing?</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>...</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>Ja jestem ju=BF =
zadowolony.</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>Ja musz=EA teraz troch=EA zrobi=E6 =
co=B6 z fwtk zanim=20
zn&oacute;w znajd=EA jaki=B6 problem.</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2></FONT><FONT size=3D2>Teraz mam =
tylko kilka=20
komunikat&oacute;w przy kompilacji \fwtk\tools:</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT color=3D#000000 size=3D2>I'm right now =
contented.<BR></FONT><FONT=20
color=3D#000000 size=3D2>I must now a little make anything with fwtk =
before again I=20
find any problem.<BR>I've now only a few errors in time compilation=20
\fwtk\tools:</FONT></DIV>
<DIV><FONT size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT size=3D2>1. ...\fwtk\tools\server\ftpd</FONT></DIV>
<DIV><FONT size=3D2></FONT><FONT color=3D#000000 =
size=3D2>&nbsp;&nbsp;&nbsp; glob.o=20
Error1</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>&nbsp;&nbsp;&nbsp; glob.c: In =
function=20
'matchdir'</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>&nbsp;&nbsp;&nbsp; glob.c:231: =
deferencing=20
pointer to incomplete type</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>&nbsp;&nbsp;&nbsp; </FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2></FONT><FONT size=3D2>2.=20
...\fwtk\tools\client</FONT></DIV>
<DIV><FONT size=3D2></FONT><FONT color=3D#000000 =
size=3D2>&nbsp;&nbsp;&nbsp; du=BFo=20
komunikat&oacute;w:</FONT></DIV>
<DIV><FONT color=3D#000000=20
size=3D2>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;=20
ftp.c:xxxx: warning: passing arg 2 of 'signal' from incompatible pointer =

type</FONT></DIV>
<DIV><FONT color=3D#000000=20
size=3D2>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
xxxx=3D..., 1016, 1018, 1047, ..., 1280,..., 1424, ..., =
1668</FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =

and</FONT></DIV>
<DIV><FONT color=3D#000000=20
size=3D2>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
ftp.c:xxxx=20
storage size of 'mask' isn't know</FONT></DIV>
<DIV><FONT color=3D#000000=20
size=3D2>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
xxxx=3D..., 1367: </FONT><FONT color=3D#000000 size=3D2>In funktion =
'pswitch', 1367:=20
<FONT color=3D#000000 size=3D2>In funktion 'proxtrans', 1673: <FONT =
color=3D#000000=20
size=3D2>In funktion 'reset'</FONT></FONT></FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2><FONT color=3D#000000 size=3D2><FONT =
color=3D#000000=20
size=3D2></FONT></FONT></FONT>&nbsp;</DIV>
<DIV><FONT color=3D#000000 size=3D2>This hasn't weight =
yet.<BR></FONT></DIV>
<DIV><FONT color=3D#000000 size=3D2>(I'm sorry - my english is=20
poor)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3D"Arial CE" size=3D2>OLAF<BR><A=20
href=3D"mailto:olafpcs@poczta.onet.pl">olafpcs@poczta.onet.pl</A></FONT><=
/DIV></DIV></DIV></BODY></HTML>

------=_NextPart_000_007C_01BFCD5D.30F9E7C0--


From owner-fwtk-users@ex.tis.com Mon Jun  5 08:28 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA18798
	Mon, 5 Jun 2000 08:28:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA17597;
	Mon, 5 Jun 2000 05:34:53 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Jun 2000 04:52:23 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA16361
	for fwtk-users-outgoing; Mon, 5 Jun 2000 04:52:17 -0700 (PDT)
Message-ID: <C901B1D9820CD411A11E0060B03CEAB605C4F4@email.domain.com>
From: "Nixon, Anthony" <snixon@mei-charlotte.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: http-gw  + ipchains
Date: Mon, 5 Jun 2000 07:51:53 -0400 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 445

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I have applied the ftp PASV+plug-to patches and finally got ftp-gw working
with my ipchains rules, but http-gw still does not work with ipchains when
trying to access an ftp site through the browser (confirmed that it does
work by disabling ipchains). Any one have this problem, and how did you deal
with it?


Shon

From owner-fwtk-users@ex.tis.com Mon Jun  5 08:28 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA18799
	Mon, 5 Jun 2000 08:28:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA17601;
	Mon, 5 Jun 2000 05:34:53 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Jun 2000 04:10:36 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA15915
	for fwtk-users-outgoing; Mon, 5 Jun 2000 04:10:30 -0700 (PDT)
To: fwtk-users@lists.nai.com
Subject: Problems using in.telnetd under Solaris 2.5.1 under netacl
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-MD5: 8rEY1p/UBzRgEY5xs+m6Jg==
Message-Id: <E12yula-0002uR-00@kd.mpi-dortmund.mpg.de>
From: "K.Dreher" <klaus.dreher@mpi-dortmund.mpg.de>
Date: Mon, 5 Jun 2000 13:09:58 +0200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1171

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,

using standard telnetd from Solaris 2.5.1 under netacl I am not able to enter 
the name of the name/password pair. The request is timed and a new name is requested from telnet.
The same telnetd under inetd is working properly.


Configuration:

fwtk:		2.1
OS:		Solaris 2.5.1 Sparc
netperm-table:	netacl-telnet: permit-hosts *  -exec /usr/sbin/in.telnetd
ps -ef:		root  9215     1  0 11:38:14 ?        0:00 /opt/fwtk/netacl -daemon 23 telnet
inetd.conf:	# telnet        stream  tcp     nowait  root    /usr/sbin/in.telnetd    in.telnetd

log:		kd:/mnt/dreher[1] telnet kd
		Trying 141.5.196.11...
		Connected to kd.
		Escape character is '^]'.


		UNIX(r) System V Release 4.0 (kd)

		login: dreher		<< no CR accepted !!
		Login incorrect
		login: ^CConnection closed by foreign host.
		kd:/mnt/dreher[2]
		
Any idea out there?

- Klaus


__

Klaus Dreher
Max Planck Institut
    fuer molekulare Physiologie
Otto Hahn Strasse 11
D 44227 Dortmund
Tel. +49 (0)231 133 2671
Fax: +49 (0)231 133 1006
Mail: klaus.dreher@mpi-dortmund.mpg.de



From owner-fwtk-users@ex.tis.com Mon Jun  5 08:59 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA19015
	Mon, 5 Jun 2000 08:59:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18610;
	Mon, 5 Jun 2000 06:06:07 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Jun 2000 05:24:15 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA17172
	for fwtk-users-outgoing; Mon, 5 Jun 2000 05:24:04 -0700 (PDT)
Message-ID: <XFMail.20000605132323.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.4 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <C901B1D9820CD411A11E0060B03CEAB605C4F4@email.domain.com>
Date: Mon, 05 Jun 2000 13:23:23 +0100 (BST)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: "Nixon, Anthony" <snixon@mei-charlotte.com>
Subject: RE: http-gw  + ipchains
Cc: "fwtk-users@ex.tis.com" <fwtk-users@ex.tis.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1014

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


You probably need to allow incoming connections to ports >1023

It's difficult to say without seeing your ruleset though.

-tony



On 05-Jun-2000 Nixon, Anthony wrote:
> [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I have applied the ftp PASV+plug-to patches and finally got ftp-gw
> working
> with my ipchains rules, but http-gw still does not work with
> ipchains when
> trying to access an ftp site through the browser (confirmed that it
> does
> work by disabling ipchains). Any one have this problem, and how did
> you deal
> with it?
> 

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
One person's error is another person's data.

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Mon Jun  5 14:07 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA20557
	Mon, 5 Jun 2000 14:07:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA21922;
	Mon, 5 Jun 2000 11:14:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Jun 2000 10:23:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA21139
	for fwtk-users-outgoing; Mon, 5 Jun 2000 10:23:45 -0700 (PDT)
From: "Piet Bos" <p.bos@lake.xs4all.nl>
To: "'Rick Murphy'" <rmurphy@itm-inst.com>, <fwtk-users@tis.com>
Subject: RE: trouble with the compilation/linking of authsrv
Date: Mon, 5 Jun 2000 19:22:58 +0200
Message-ID: <000001bfcf12$b25ec720$0b00a8c0@gate.thuis>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
Importance: Normal
In-Reply-To: <4.2.2.20000602232058.00d0a1a0@mail.itm-inst.com>
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
X-Hops: 1
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1027

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


This sugeestion works, but isn't it a pity or rather a shame that the
feature of password authentication has to be switched of?
And why shouldn't is be used anyway, Rick?
Please elaborate.

Piet.
-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of Rick Murphy
Sent: Saturday, June 03, 2000 5:23 AM
To: Piet Bos; fwtk-users@tis.com
Subject: RE: trouble with the compilation/linking of authsrv


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:43 PM 6/2/00 +0200, Piet Bos wrote:
>Alas,
>it din't do the trick, I'm still having difficulties making authsrv.
>Is there something else to do, so it will work?

Disable password authentication - it shouldn't be used anyway.
(edit auth.h to comment out the '#define AUTHPROTO_PASSWORD' line.)
         -Rick


From owner-fwtk-users@ex.tis.com Mon Jun  5 17:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA21498
	Mon, 5 Jun 2000 17:55:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA24503;
	Mon, 5 Jun 2000 15:02:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Jun 2000 14:13:35 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA23630
	for fwtk-users-outgoing; Mon, 5 Jun 2000 14:13:24 -0700 (PDT)
Message-Id: <4.2.2.20000605165927.00c79f00@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Mon, 05 Jun 2000 17:01:24 -0400
To: "Piet Bos" <p.bos@lake.xs4all.nl>, <fwtk-users@tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: RE: trouble with the compilation/linking of authsrv
In-Reply-To: <000001bfcf12$b25ec720$0b00a8c0@gate.thuis>
References: <4.2.2.20000602232058.00d0a1a0@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 642

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:22 PM 6/5/00 +0200, Piet Bos wrote:

>This sugeestion works, but isn't it a pity or rather a shame that the
>feature of password authentication has to be switched of?

Well, you can probably find a crypt library source somewhere.

>And why shouldn't is be used anyway, Rick?
>Please elaborate.
Because password authentication is weak - anyone watching traffic to your 
firewall can capture user passwords and reuse them. All the other 
authentication protocols cannot be reused or replayed.
         -Rick


From owner-fwtk-users@ex.tis.com Tue Jun  6 08:16 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA23766
	Tue, 6 Jun 2000 08:16:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA01105;
	Tue, 6 Jun 2000 05:23:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Jun 2000 04:13:15 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA00203
	for fwtk-users-outgoing; Tue, 6 Jun 2000 04:13:09 -0700 (PDT)
Subject: Problems using in.telnetd under Solaris 2.5.1 under netacl
To: fwtk-users@lists.nai.com
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-MD5: RkPrDVoyqL3JYPAn1l/DFg==
Message-Id: <E12zHH1-0002jW-00@kd.mpi-dortmund.mpg.de>
From: "K.Dreher" <klaus.dreher@mpi-dortmund.mpg.de>
Date: Tue, 6 Jun 2000 13:11:55 +0200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 4337

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,

I had send the following mail to the fwtk-users list without response.

|| From dreher Mon Jun  5 13:09:58 2000
|| To: fwtk-users@lists.nai.com
|| Subject: Problems using in.telnetd under Solaris 2.5.1 under netacl
|| Mime-Version: 1.0
|| Content-Transfer-Encoding: 7bit
|| Content-MD5: 8rEY1p/UBzRgEY5xs+m6Jg==
|| 
|| Hi,
|| 
|| using standard telnetd from Solaris 2.5.1 under netacl I am not able to enter 
|| the name of the name/password pair. The request is timed and a new name is requested from telnet.
|| The same telnetd under inetd is working properly.
|| 
|| 
|| Configuration:
|| 
|| fwtk:		2.1
|| OS:		Solaris 2.5.1 Sparc
|| netperm-table:	netacl-telnet: permit-hosts *  -exec /usr/sbin/in.telnetd
|| ps -ef:		root  9215     1  0 11:38:14 ?        0:00 /opt/fwtk/netacl -daemon 23 telnet
|| inetd.conf:	# telnet        stream  tcp     nowait  root    /usr/sbin/in.telnetd    in.telnetd
|| 
|| log:		kd:/mnt/dreher[1] telnet kd
|| 		Trying 141.5.196.11...
|| 		Connected to kd.
|| 		Escape character is '^]'.
|| 
|| 
|| 		UNIX(r) System V Release 4.0 (kd)
|| 
|| 		login: dreher		<< no CR accepted !!
|| 		Login incorrect
|| 		login: ^CConnection closed by foreign host.
|| 		kd:/mnt/dreher[2]
|| 		
|| Any idea out there?
|| 
||- Klaus
|| 
|| 
|| __
|| 
|| K|| laus Dreher
|| Max Planck Institut
||     fuer molekulare Physiologie
|| Otto Hahn Strasse 11
|| D 44227 Dortmund
|| Tel. +49 (0)231 133 2671
|| Fax: +49 (0)231 133 1006
|| Mail: klaus.dreher@mpi-dortmund.mpg.de


In addition I have "trussed" inetd and netacl and I have found, that /bin/login called by
/usr/sbin/in.telnetd needs /dev/tty to reopen the inputchannel for the password. Under netacl
/dev/tty does not exist, so the password is not recognised.


truss inetd:

 getmsg(5, 0xEFFFE2F0, 0x0002CC48, 0xEFFFE33C)   = 0
7238:   lseek(3, 0, SEEK_CUR)                           = 0
7238:   close(3)                                        = 0	<<<<<<<<< close
7238:   munmap(0xEF563000, 2308)                        = 0
7238:   munmap(0xEF550000, 13374)                       = 0
7238:   munmap(0xEF543000, 4324)                        = 0
7238:   munmap(0xEF530000, 15086)                       = 0
7238:   open("/dev/tty", O_RDONLY)                      = 3     <<<<<<<<< reopen
7238:   sigaction(SIGINT, 0xEFFFE598, 0xEFFFE698)       = 0
7238:   ioctl(3, TCGETA, 0xEFFFE73C)                    = 0
7238:   ioctl(3, TCSETAF, 0xEFFFE73C)                   = 0
7238:   write(2, " P a s s w o r d :  ", 10)            = 10
7238:   read(3, 0xEF653704, 1)          (sleeping...)
7238:   read(3, " $", 1)                                = 1
7238:   read(3, " $", 1)                                = 1
7238:   read(3, " J", 1)                                = 1
7238:   read(3, " A", 1)                                = 1

truss netacl:

poll(0x00031B14, 1, 15000)                      = 1
6555:   getmsg(5, 0xEFFFE310, 0x0002CC48, 0xEFFFE35C)   = 0
6555:   lseek(3, 0, SEEK_CUR)                           = 0
6555:   close(3)                                        = 0     <<<<<<<<< close
6555:   munmap(0xEF563000, 2308)                        = 0
6555:   munmap(0xEF550000, 13374)                       = 0
6555:   munmap(0xEF543000, 4324)                        = 0
6555:   munmap(0xEF530000, 15086)                       = 0
6555:   open("/dev/tty", O_RDONLY)                      Err#6 ENXIO <<<<<< !!!!!!!
6555:   alarm(0)                                        = 298
6555:   sigaction(SIGALRM, 0xEFFFE748, 0xEFFFE7F8)      = 0
6555:   sigprocmask(SIG_BLOCK, 0xEFFFE7E8, 0xEFFFE7D8)  = 0
6555:   alarm(4)                                        = 0
6555:   sigsuspend(0xEFFFE7C8)          (sleeping...)
6555:       Received signal #14, SIGALRM, in sigsuspend() [caught]
6555:   sigsuspend(0xEFFFE7C8)                          Err#4 EINTR
6555:   setcontext(0xEFFFE5A8)
6555:   alarm(0)                                        = 0

Is there anyone using netacl in conjuction with in.telnetd 
under Solaris??

		Klaus Dreher
		
		
__

Klaus Dreher
Max Planck Institut
    fuer molekulare Physiologie
Otto Hahn Strasse 11
D 44227 Dortmund
Tel. +49 (0)231 133 2671
Fax: +49 (0)231 133 1006
Mail: klaus.dreher@mpi-dortmund.mpg.de


From owner-fwtk-users@ex.tis.com Tue Jun  6 12:07 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA26597
	Tue, 6 Jun 2000 12:07:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA03350;
	Tue, 6 Jun 2000 09:14:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Jun 2000 08:14:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA02518
	for fwtk-users-outgoing; Tue, 6 Jun 2000 08:14:50 -0700 (PDT)
Message-ID: <393D143B.C0ABF3CD@newscomp.com>
Date: Tue, 06 Jun 2000 11:09:48 -0400
From: Scott McEachern <smceachern@jamedia.com>
Reply-To: smceachern@jamedia.com
X-Mailer: Mozilla 4.72 [en] (X11; U; SunOS 5.8 i86pc)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: ftp-gw mkdir problem
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1114

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

    Hi, I'm running fwtk 2.1 on OpenBSD 2.6, and everything is working
great, except one little thing:
    One of my machines ftp's to an external site and places files
there.  During the placement, it creates a directory and continues to
place files into the newly created directory.
    The problem is that when I send the "mkdir <directory" command,
I get a "500 command not understood" error.
    The machine that does the ftp has worked correctly for months, and
this problem has only occurred since I put this machine behind the
firewall.
    My netperm entry for this is:

ftp-gw: permit-hosts 192.168.0.55 -log { retr stor dele mkd syst pasv }
-plug-to <external machine IP>

    I have applied the gate-ftp patch, the fix for extended ftp
permissions, and the patch for plug capability.  Can anyone help?  TIA.


--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.,
300 John St., Suite 500
Thornhill, ON, CA.  L3T 5W4
tel: 905-881-6902  fax: 905-881-6945




From owner-fwtk-users@ex.tis.com Tue Jun  6 12:58 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA27460
	Tue, 6 Jun 2000 12:58:13 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA04720;
	Tue, 6 Jun 2000 10:05:27 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Jun 2000 09:20:23 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA03433
	for fwtk-users-outgoing; Tue, 6 Jun 2000 09:20:12 -0700 (PDT)
Date: Tue, 6 Jun 2000 12:18:57 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Scott McEachern <smceachern@jamedia.com>
cc: fwtk-users@tis.com
Subject: Re: ftp-gw mkdir problem
In-Reply-To: <393D143B.C0ABF3CD@newscomp.com>
Message-ID: <Pine.GSO.4.10.10006061217200.10294-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1999

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Scott,

I suspect you are running a W/9x client...  If so, the client sends a new
commad to the firewall that the ftp-gw proxy does not understand. 

The attached patch (you might have to fix this up since the tabs will be
lost) should fix the problem.  It adds support for the windows command.

ted keller


*** ftp-gw.c.dist	Mon Oct 25 20:43:51 1999
--- ftp-gw.c	Mon Oct 25 20:43:16 1999
***************
*** 137,142 ****
--- 137,143 ----
  	"rest",		OP_CONN,			0,
  	"rmd",		OP_CONN|OP_XTND,		0,
  	"mkd",		OP_CONN|OP_XTND,		0,
+ 	"xmkd",		OP_CONN|OP_XTND,		0,
  	"syst",		OP_CONN,			0,
  	"acct",		OP_CONN,			0,
  	"quit",		OP_AOK,				cmd_quit,

On Tue, 6 Jun 2000, Scott McEachern wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
>     Hi, I'm running fwtk 2.1 on OpenBSD 2.6, and everything is working
> great, except one little thing:
>     One of my machines ftp's to an external site and places files
> there.  During the placement, it creates a directory and continues to
> place files into the newly created directory.
>     The problem is that when I send the "mkdir <directory" command,
> I get a "500 command not understood" error.
>     The machine that does the ftp has worked correctly for months, and
> this problem has only occurred since I put this machine behind the
> firewall.
>     My netperm entry for this is:
> 
> ftp-gw: permit-hosts 192.168.0.55 -log { retr stor dele mkd syst pasv }
> -plug-to <external machine IP>
> 
>     I have applied the gate-ftp patch, the fix for extended ftp
> permissions, and the patch for plug capability.  Can anyone help?  TIA.
> 
> 
> --
> R. Scott McEachern, Network Administrator
> J&A Media Services, Inc.,
> 300 John St., Suite 500
> Thornhill, ON, CA.  L3T 5W4
> tel: 905-881-6902  fax: 905-881-6945
> 
> 
> 


From owner-fwtk-users@ex.tis.com Tue Jun  6 16:52 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA28828
	Tue, 6 Jun 2000 16:52:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA07738;
	Tue, 6 Jun 2000 13:59:36 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Jun 2000 13:08:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA06823
	for fwtk-users-outgoing; Tue, 6 Jun 2000 13:08:32 -0700 (PDT)
From: "Yibing Li" <yli@simplexity.com>
To: <fwtk-users@lists.nai.com>
Cc: "David Tirtamidjaja" <dtirtami@simplexity.com>,
        "Joo C Chung" <jchung@simplexity.com>,
        "Yibing Li" <yli@simplexity.com>,
        "David Mobley" <dmobley@simplexity.com>,
        "Chris McNeilly" <cmcneilly@simplexity.com>
Subject: how does plug-gw work with https
Date: Tue, 6 Jun 2000 16:07:26 -0400
Message-ID: <NDBBLEGGOKDJMHANDHBOEEJPCBAA.yli@simplexity.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1100

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear fwtk-users,

    I am using plug-gw as a proxy for an ecredit checking.
we used to use HTTP to send request to ecredit through plug-gw and
it works well. Right now we are using https and I can DIRECTLY send
https request to ecredit and get the response back. But if I try to
pass through plug-gw, I never get it working. The following three lines
are my configurations. Are there any thing wrong with my configuration?

    someplace mentioned ssl-gw. I wonder whether that is the package
I should use instead.  Is this package also included in fwtk? I can
not find it.

    Any help is highly appreciated.

Thanks,

Yibing Li, Ph.D.
Senior Software Engineer,
Simplexity.com
703-654-4720


# plug-gw is running at 10.2.0.7 at port 8000
# ECredit rules
plug-gw:        permit-hosts 10.2.0.* -log {retr stor }

plug-gw:    port 8000 10.2.0.68 -plug-to globalfinancingnetwork.com -port
443
plug-gw:    port 443 globalfinancingnetwork.com -plug-to 10.2.0.68 -port
8000


From owner-fwtk-users@ex.tis.com Wed Jun  7 09:41 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA02688
	Wed, 7 Jun 2000 09:41:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA13822;
	Wed, 7 Jun 2000 06:48:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Jun 2000 05:36:38 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA12859
	for fwtk-users-outgoing; Wed, 7 Jun 2000 05:36:32 -0700 (PDT)
Date: Wed, 07 Jun 2000 14:35:16 +0200
From: "Overdijk, Harrie" <overdijk@ecn.nl>
Subject: smap/smapd/postfix: malformed sender addesses
To: fwtk-users@tis.com
Message-id: <50B56D407D2DD31191DE00902771E9F4015934AE@ecntex.ecn.nl>
X-Envelope-to: fwtk-users@tis.com
MIME-version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Content-transfer-encoding: 7BIT
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 2062

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear FWTK-guru's

The time has come to get rid of ouw good old mail-gateway
and replace it by a system running the smap/smapd combo from
fwtk 2.1 with the Joseph Yao Antirelay/AntiSPAM patches. As
a replacement for sendmail I have chosen for postfix in send
only mode and configured it for use on a firewall. I have
tested it local from several systems using telnet to simulate
a SMTP session and all looks well.

So the time has come to let our Microsoft Exchange server
version 5.5 send the messages via the described system to
the outside world. I was very scared when I saw the
following type of messages in the log:

 -----8<-----
Jun  7 13:26:10 ecnwall postfix/sendmail[2427]: warning: -f option specified
malformed sender: <veldman@ecn.nl> SIZE=1639
 -----8<-----

That does not look good... especially not when I saw:

 -----8<-----
Jun  7 13:26:11 ecnwall postfix/pickup[2149]: 0B0DD2F: uid=5
from=<SIZE=1639>
Jun  7 13:26:11 ecnwall postfix/cleanup[2425]: 0B0DD2F:
message-id=<20000607112610.0B0DD2F@ecnwall.ecn.nl>
Jun  7 13:26:11 ecnwall postfix/qmgr[1738]: 0B0DD2F:
from=<SIZE=1639@ecnwall.ecn.nl>, size=1979 (queue active)
 -----8<-----

The 'sender' address has become <SIZE=1639@blabla> instead of
<veldman@ecn.nl>. Most messages were accepted by the remote
system, but I don't feel good about it. I think there are
remote systems that will not accept these types of sender
addresses... So... I switched back to the old mailgateway
and wait for a response on my following question:

Has anyone seen this before? And (even better) has anyone a
patch to fight this type of Gatesware functionallity?

Thanks in advance for your help!

Harrie.

Harrie Overdijk, ECN, Postbox 1, 1755 ZG  Petten (NH), The Netherlands.
Internet: overdijk@ecn.nl              Noisenet: +31 224 56 4597
Fidonet : 2:500/43.1902  (At home!)    FAXnet  : +31 224 56 1864
ICP/Postmaster/UseNet-News-manager/WWW-manager/Security-manager of ECN.


From owner-fwtk-users@ex.tis.com Wed Jun  7 10:45 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA03270
	Wed, 7 Jun 2000 10:45:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA15425;
	Wed, 7 Jun 2000 07:52:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Jun 2000 07:05:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA14058
	for fwtk-users-outgoing; Wed, 7 Jun 2000 07:04:51 -0700 (PDT)
To: fwtk-users@tis.com
Subject: Re: smap/smapd/postfix: malformed sender addesses
Cc: overdijk@ecn.nl
X-Sun-Charset: US-ASCII
Message-Id: <20000607140431.352E42C15C@skynet.medar.com>
Date: Wed,  7 Jun 2000 10:04:31 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1752

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In Message-id: <50B56D407D2DD31191DE00902771E9F4015934AE@ecntex.ecn.nl>,
"Overdijk, Harrie" <overdijk@ecn.nl> wrote:
[snip]
>                                                      ... As
> a replacement for sendmail I have chosen for postfix 

Good idea, IMO :-).  Except...

>                                                      in send
> only mode and configured it for use on a firewall. I have
> tested it local from several systems using telnet to simulate
> a SMTP session and all looks well.
[snip]

Kind of a "carrying coals to Newcastle" approach, IMO.  Postfix is not
a monolithic MTA like sendmail.  It was developed from scratch by
someone who is arguably one of the best-known and most talented Unix
security folks on the net (one of your own countrymen:  Wietse
Venema).  The "exposed" part of Postfix is the SMTP daemon.  Like with
smap/smapd, this is a separate piece of code.  And like
smap/smapd/sendmail: Postfix's separate components are isolated from
each other.  Further, if you're really concerned about Postfix possibly
being breached, you can run it under a unique UID and/or put it in a
chroot'd jail.

And tho I haven't looked at Yao's smap/smapd patches (nor is it my
intention to belittle his work!), I'd be almost willing to bet
Postfix has more extensive anti-spam controls.

(Guess what I'm running on both my Gauntlet and T.REX firewalls?)


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems & Network Administrator     | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Wed Jun  7 17:29 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA04829
	Wed, 7 Jun 2000 17:29:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA19818;
	Wed, 7 Jun 2000 14:36:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Jun 2000 13:36:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA18274
	for fwtk-users-outgoing; Wed, 7 Jun 2000 13:36:08 -0700 (PDT)
From: "Yibing Li" <yli@simplexity.com>
To: "Yibing Li" <yli@simplexity.com>, <fwtk-users@lists.nai.com>
Cc: "David Tirtamidjaja" <dtirtami@simplexity.com>
Subject: RE: how does plug-gw work with https
Date: Wed, 7 Jun 2000 16:35:03 -0400
Message-ID: <NDBBLEGGOKDJMHANDHBOAEKGCBAA.yli@simplexity.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
In-Reply-To: <NDBBLEGGOKDJMHANDHBOEEJPCBAA.yli@simplexity.com>
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2244

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Thanks for the help. I have got it working for sometime this morning.
But at this moment, I got the following messages:


 Jun  7 15:33:13 db-east plug-gw[1947]: cannot connect to server
/globalfinancing
network.com/443: Not owner
Jun  7 15:33:13 db-east plug-gw[1948]: cannot connect to server
/globalfinancing
network.com/443: No child processes
Jun  7 15:33:13 db-east plug-gw[1949]: cannot connect to server
/globalfinancing
network.com/443: No child processes
Jun  7 15:33:38 db-east unix: NOTICE: oracle, uid 60003: setuid execution
not al
lowed, dev=1540000

My configuration file has the following line:
plug-gw:    port 8000 10.2.0.68 -plug-to globalfinancingnetwork.com -ssl

>From above message, it looks that it can not connnect to
globalfinancingnetwork.com/443.
What can be wrong?

Thanks,

Yibing


> -----Original Message-----
> From: Yibing Li [mailto:yli@Simplexity.COM]
> Sent: Tuesday, June 06, 2000 4:07 PM
> To: fwtk-users@lists.nai.com
> Cc: David Tirtamidjaja; Joo C Chung; Yibing Li; David Mobley; Chris
> McNeilly
> Subject: how does plug-gw work with https
>
>
> Dear fwtk-users,
>
>     I am using plug-gw as a proxy for an ecredit checking.
> we used to use HTTP to send request to ecredit through plug-gw and
> it works well. Right now we are using https and I can DIRECTLY send
> https request to ecredit and get the response back. But if I try to
> pass through plug-gw, I never get it working. The following three lines
> are my configurations. Are there any thing wrong with my configuration?
>
>     someplace mentioned ssl-gw. I wonder whether that is the package
> I should use instead.  Is this package also included in fwtk? I can
> not find it.
>
>     Any help is highly appreciated.
>
> Thanks,
>
> Yibing Li, Ph.D.
> Senior Software Engineer,
> Simplexity.com
> 703-654-4720
>
>
> # plug-gw is running at 10.2.0.7 at port 8000
> # ECredit rules
> plug-gw:        permit-hosts 10.2.0.* -log {retr stor }
>
> plug-gw:    port 8000 10.2.0.68 -plug-to globalfinancingnetwork.com -port
> 443
> plug-gw:    port 443 globalfinancingnetwork.com -plug-to 10.2.0.68 -port
> 8000
>


From owner-fwtk-users@ex.tis.com Wed Jun  7 17:29 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA04832
	Wed, 7 Jun 2000 17:29:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA19822;
	Wed, 7 Jun 2000 14:36:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Jun 2000 13:37:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA18295
	for fwtk-users-outgoing; Wed, 7 Jun 2000 13:36:55 -0700 (PDT)
From: Eberhard Mattes <mattes@azu.informatik.uni-stuttgart.de>
Date: Wed, 7 Jun 2000 22:36:27 +0200 (MET DST)
Message-Id: <200006072036.WAA16292@azu.informatik.uni-stuttgart.de>
To: lomonaco@cetec.br
CC: fwtk-users@ex.tis.com
In-reply-to: <393871D3.B1EA5236@cetec.br> (message from Andre Gustavo Lomonaco
	on Fri, 02 Jun 2000 23:47:47 -0300)
Subject: Re: Problem with squid-gw 1.3
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 456

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> Error detected by squid-gw:
> Duplicate response header field: X-Cache: MISS from cache.cetec.br

In http-res.tab, locate the line containing x-cache in its 1st column.
Change the value in the 3rd column of that line from 0 to H_MULTI.
Then, rebuild squid-gw.

-- 
  Eberhard Mattes <mattes@azu.informatik.uni-stuttgart.de>


From owner-fwtk-users@ex.tis.com Thu Jun  8 07:12 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07091
	Thu, 8 Jun 2000 07:12:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA28601;
	Thu, 8 Jun 2000 04:19:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 03:25:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA25543
	for fwtk-users-outgoing; Thu, 8 Jun 2000 03:25:15 -0700 (PDT)
Message-ID: <393F73F3.1ABBC95C@ordix.de>
Date: Thu, 08 Jun 2000 12:22:43 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: nntp-gw: Problem at line 175 emo.c
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 828

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello fwtk-guru's,
i send this message again, cause i'm not shure if i had the right list.
I realy nead to get news set up with the tis fwtk. 

i'm trying to set up News to work over a firewall.
In the local network there are clients which want to use news (reading 
and posting). Newsservers are all outside the firewall.

I decided to use the nntp-gw from the em-gw.tar.gz.
It compiles fine and seems to work so far. As soon as i try to connect
to the Firewall with Netscape Newsreader. I get the following message in
the syslog of the firewall: 
Jun  2 16:15:11 localhost nntp-gw[24470]: Assertion failed: f != NULL,
file emo.c, line 175

Can anyone help me in that matter? 

Thanks a lot
Markus

From owner-fwtk-users@ex.tis.com Thu Jun  8 07:12 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07092
	Thu, 8 Jun 2000 07:12:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA28614;
	Thu, 8 Jun 2000 04:19:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 03:26:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA25583
	for fwtk-users-outgoing; Thu, 8 Jun 2000 03:25:55 -0700 (PDT)
Message-ID: <393F73F3.1ABBC95C@ordix.de>
Date: Thu, 08 Jun 2000 12:22:43 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: nntp-gw: Problem at line 175 emo.c
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 828

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello fwtk-guru's,
i send this message again, cause i'm not shure if i had the right list.
I realy nead to get news set up with the tis fwtk. 

i'm trying to set up News to work over a firewall.
In the local network there are clients which want to use news (reading 
and posting). Newsservers are all outside the firewall.

I decided to use the nntp-gw from the em-gw.tar.gz.
It compiles fine and seems to work so far. As soon as i try to connect
to the Firewall with Netscape Newsreader. I get the following message in
the syslog of the firewall: 
Jun  2 16:15:11 localhost nntp-gw[24470]: Assertion failed: f != NULL,
file emo.c, line 175

Can anyone help me in that matter? 

Thanks a lot
Markus

From owner-fwtk-users@ex.tis.com Thu Jun  8 07:12 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07093
	Thu, 8 Jun 2000 07:12:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA28605;
	Thu, 8 Jun 2000 04:19:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 03:24:15 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA25494
	for fwtk-users-outgoing; Thu, 8 Jun 2000 03:24:09 -0700 (PDT)
Message-ID: <393F73B5.6FDA4C78@ordix.de>
Date: Thu, 08 Jun 2000 12:21:41 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: ssh - Which one
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 598

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello fwtk-helpers,
sorry if i'm to far of toppic.
i'm setting up a fwtk on redhat linux. I would like to administer it
over the network form an windwos nt and from a linux system.
I've looked at diffrent sources of ssh (one and two).

Can anyone tell me which is the best practice if i'm looking for a
charge free available stable secure shell?

Wich Server would be the best to use?
Are there clients under NT working with it?

Thank you for any information.

Markus

From owner-fwtk-users@ex.tis.com Thu Jun  8 07:12 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07098
	Thu, 8 Jun 2000 07:12:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA28610;
	Thu, 8 Jun 2000 04:19:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 03:24:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA25516
	for fwtk-users-outgoing; Thu, 8 Jun 2000 03:24:51 -0700 (PDT)
Message-ID: <393F73B5.6FDA4C78@ordix.de>
Date: Thu, 08 Jun 2000 12:21:41 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: ssh - Which one
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 598

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello fwtk-helpers,
sorry if i'm to far of toppic.
i'm setting up a fwtk on redhat linux. I would like to administer it
over the network form an windwos nt and from a linux system.
I've looked at diffrent sources of ssh (one and two).

Can anyone tell me which is the best practice if i'm looking for a
charge free available stable secure shell?

Wich Server would be the best to use?
Are there clients under NT working with it?

Thank you for any information.

Markus

From owner-fwtk-users@ex.tis.com Thu Jun  8 07:27 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07166
	Thu, 8 Jun 2000 07:27:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA00065;
	Thu, 8 Jun 2000 04:34:40 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 03:53:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA27033
	for fwtk-users-outgoing; Thu, 8 Jun 2000 03:53:05 -0700 (PDT)
Message-Id: <4.2.2.20000608064829.00c6ef00@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Thu, 08 Jun 2000 06:50:45 -0400
To: jseymour@medar.com (James Seymour), fwtk-users@tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: smap/smapd/postfix: malformed sender addesses
Cc: overdijk@ecn.nl
In-Reply-To: <20000607140431.352E42C15C@skynet.medar.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 548

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 10:04 AM 6/7/00 -0400, James Seymour wrote:
>Kind of a "carrying coals to Newcastle" approach, IMO.

I've got to agree with Jim. If you're going to go through the effort to 
configure postfix, get rid of smap and smapd. Combining the two won't do 
much to tighten up the postfix installation and it only serves to 
complicate the setup. (More complicated means more likely to be set up 
wrong IMHO.)
         -Rick


From owner-fwtk-users@ex.tis.com Thu Jun  8 07:49 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07231
	Thu, 8 Jun 2000 07:49:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA02092;
	Thu, 8 Jun 2000 04:56:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 04:15:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA28351
	for fwtk-users-outgoing; Thu, 8 Jun 2000 04:15:38 -0700 (PDT)
Message-ID: <393F7FB2.F13E7DC2@bath.tmac.com>
Date: Thu, 08 Jun 2000 07:12:50 -0400
From: Steve Sandau <ssandau@bath.tmac.com>
X-Mailer: Mozilla 4.72 [en] (X11; I; Linux 2.2.13 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: Markus Schreier <ms@ordix.de>
CC: fwtk-users@ex.tis.com
Subject: Re: ssh - Which one
References: <393F73B5.6FDA4C78@ordix.de>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1236

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I use a small, simple (I believe free) ssh client for 32-bit Windows
called "putty." It's simple and does everything I need it to.

As for Linux, I have used ssh-1.2.27 compiled from source, which gives a
command-line ssh client that works fine, too.

I haven't used eitehr of these extensively, but they have bot worked for
my needs. Others may have more detailed information.

Markus Schreier wrote:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello fwtk-helpers,
> sorry if i'm to far of toppic.
> i'm setting up a fwtk on redhat linux. I would like to administer it
> over the network form an windwos nt and from a linux system.
> I've looked at diffrent sources of ssh (one and two).
> 
> Can anyone tell me which is the best practice if i'm looking for a
> charge free available stable secure shell?
> 
> Wich Server would be the best to use?
> Are there clients under NT working with it?
> 
> Thank you for any information.
> 
> Markus

Steve Sandau
IS Technician, TMA, Bath, Maine
ssandau@bath.tmac.com

From owner-fwtk-users@ex.tis.com Thu Jun  8 07:51 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA07237
	Thu, 8 Jun 2000 07:51:16 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA02263;
	Thu, 8 Jun 2000 04:58:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 04:19:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA28606
	for fwtk-users-outgoing; Thu, 8 Jun 2000 04:19:04 -0700 (PDT)
Message-ID: <50B56D407D2DD31191DE00902771E9F4015934B5@ecntex.ecn.nl>
From: "Overdijk, Harrie" <overdijk@ecn.nl>
To: "'Rick Murphy'" <rmurphy@itm-inst.com>, jseymour@medar.com
Cc: fwtk-users@tis.com
Subject: RE: smap/smapd/postfix: malformed sender addesses
Date: Thu, 8 Jun 2000 13:17:15 +0200 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 1608

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear Rick and Jim,

Rick wrote me the following:

> -----Original Message-----
> From:	Rick Murphy [SMTP:rmurphy@itm-inst.com]
> Sent:	Thursday, June 08, 2000 12:51 PM
> To:	jseymour@medar.com; fwtk-users@tis.com
> Cc:	overdijk@ecn.nl
> Subject:	Re: smap/smapd/postfix: malformed sender addesses
> 
> At 10:04 AM 6/7/00 -0400, James Seymour wrote:
> >Kind of a "carrying coals to Newcastle" approach, IMO.
> 
> I've got to agree with Jim. If you're going to go through the effort to 
> configure postfix, get rid of smap and smapd. Combining the two won't do 
> much to tighten up the postfix installation and it only serves to 
> complicate the setup. (More complicated means more likely to be set up 
> wrong IMHO.)
> 
	[Harrie]  OK, you both have convinced me now... I haven't
	[Harrie]  studied postfix that much, but after reading
	[Harrie]  the available doc's and testing by using smtpd
	[Harrie]  of postfix I have a good feeling about it.
	[Harrie]  Jim Seymour mentioned Wietse Venema as the writer
	[Harrie]  of postfix. Indeed Jim, I know Wietse and met him
	[Harrie]  during a security meeting in The Netherlands.
	[Harrie]  Thank you both for convincing me!

	Greetings,
	          Harrie

Harrie Overdijk, ECN, Postbox 1, 1755 ZG  Petten (NH), The Netherlands.
Internet: overdijk@ecn.nl              Noisenet: +31 224 56 4597
Fidonet : 2:500/43.1902  (At home!)    FAXnet  : +31 224 56 1864
ICP/Postmaster/UseNet-News-manager/WWW-manager/Security-manager of ECN.


From owner-fwtk-users@ex.tis.com Thu Jun  8 08:51 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA07587
	Thu, 8 Jun 2000 08:51:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA06051;
	Thu, 8 Jun 2000 05:58:13 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 05:11:17 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA03520
	for fwtk-users-outgoing; Thu, 8 Jun 2000 05:11:12 -0700 (PDT)
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: Re: ssh - Which one
X-Sun-Charset: US-ASCII
Message-Id: <20000608121029.9DB5A2C15C@skynet.medar.com>
Date: Thu,  8 Jun 2000 08:10:29 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 793

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In message <393F73B5.6FDA4C78@ordix.de>,
Markus Schreier <ms@ordix.de> wrote:
> 
[snip]
> 
> Can anyone tell me which is the best practice if i'm looking for a
> charge free available stable secure shell?
> 
> Wich Server would be the best to use?
[snip]
> 

I'm using OpenSSH on my T.REX firewall.  For Linux, you need to make
sure to get the portable OpenSSH version at

    http://www.openssh.com/portable.html


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems & Network Administrator     | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Thu Jun  8 08:51 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA07588
	Thu, 8 Jun 2000 08:51:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA06055;
	Thu, 8 Jun 2000 05:58:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 05:11:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA03593
	for fwtk-users-outgoing; Thu, 8 Jun 2000 05:11:43 -0700 (PDT)
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: Re: ssh - Which one
X-Sun-Charset: US-ASCII
Message-Id: <20000608121029.9DB5A2C15C@skynet.medar.com>
Date: Thu,  8 Jun 2000 08:10:29 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 793

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In message <393F73B5.6FDA4C78@ordix.de>,
Markus Schreier <ms@ordix.de> wrote:
> 
[snip]
> 
> Can anyone tell me which is the best practice if i'm looking for a
> charge free available stable secure shell?
> 
> Wich Server would be the best to use?
[snip]
> 

I'm using OpenSSH on my T.REX firewall.  For Linux, you need to make
sure to get the portable OpenSSH version at

    http://www.openssh.com/portable.html


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems & Network Administrator     | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Thu Jun  8 09:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA07847
	Thu, 8 Jun 2000 09:55:35 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08836;
	Thu, 8 Jun 2000 07:02:41 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 06:00:29 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA06111
	for fwtk-users-outgoing; Thu, 8 Jun 2000 06:00:23 -0700 (PDT)
Message-ID: <393F9843.BA0D88C2@ordix.de>
Date: Thu, 08 Jun 2000 14:57:39 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: smap Joe Yao's patch: res_query
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 753

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
i aplied Joe Yao's patch to smap.c. But afterwards i could not compile/
link smap anymore. The output of make looks like this.

make
cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
-L/usr/local/src/firewall/source/fwtk/fwtk/fwtk/skey -lskey -lmd
smap.o: In function `from_address_ok':
/usr/local/src/firewall/source/fwtk/fwtk/fwtk/smap/smap.c:2016:
undefined reference to `res_query'
/usr/local/src/firewall/source/fwtk/fwtk/fwtk/smap/smap.c:2016:
undefined reference to `res_query'
collect2: ld returned 1 exit status
make: *** [smap] Error 1
[root@younix smap]# 

Any help would be areceated.

Markus

From owner-fwtk-users@ex.tis.com Thu Jun  8 09:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA07851
	Thu, 8 Jun 2000 09:55:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08832;
	Thu, 8 Jun 2000 07:02:41 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 06:01:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA06150
	for fwtk-users-outgoing; Thu, 8 Jun 2000 06:01:03 -0700 (PDT)
Message-ID: <393F9843.BA0D88C2@ordix.de>
Date: Thu, 08 Jun 2000 14:57:39 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: smap Joe Yao's patch: res_query
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 753

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
i aplied Joe Yao's patch to smap.c. But afterwards i could not compile/
link smap anymore. The output of make looks like this.

make
cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
-L/usr/local/src/firewall/source/fwtk/fwtk/fwtk/skey -lskey -lmd
smap.o: In function `from_address_ok':
/usr/local/src/firewall/source/fwtk/fwtk/fwtk/smap/smap.c:2016:
undefined reference to `res_query'
/usr/local/src/firewall/source/fwtk/fwtk/fwtk/smap/smap.c:2016:
undefined reference to `res_query'
collect2: ld returned 1 exit status
make: *** [smap] Error 1
[root@younix smap]# 

Any help would be areceated.

Markus

From owner-fwtk-users@ex.tis.com Thu Jun  8 14:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA08911
	Thu, 8 Jun 2000 14:23:57 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA12682;
	Thu, 8 Jun 2000 11:31:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 10:38:58 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA11191
	for fwtk-users-outgoing; Thu, 8 Jun 2000 10:38:47 -0700 (PDT)
Message-ID: <952FAEB97E0AD111BB7000805F0D84F6049DA5A5@eesusciexs3.eesus.jnj.com>
From: "Drash, Jim [EESUS]" <JDrash@EESUS.JNJ.com>
To: "'Markus Schreier'" <ms@ordix.de>, fwtk-users@lists.nai.com,
        fwtk-users@ex.tis.com
Subject: RE: ssh - Which one
Date: Thu, 8 Jun 2000 13:37:26 -0400 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1068

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

openssh on the unix box and putty or teraterm pro with the ttssh extentions
on the windows side.

> -----Original Message-----
> From: Markus Schreier [mailto:ms@ordix.de]
> Sent: Thursday, June 08, 2000 6:22 AM
> To: fwtk-users@lists.nai.com; fwtk-users@ex.tis.com
> Subject: ssh - Which one
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello fwtk-helpers,
> sorry if i'm to far of toppic.
> i'm setting up a fwtk on redhat linux. I would like to administer it
> over the network form an windwos nt and from a linux system.
> I've looked at diffrent sources of ssh (one and two).
> 
> Can anyone tell me which is the best practice if i'm looking for a
> charge free available stable secure shell?
> 
> Wich Server would be the best to use?
> Are there clients under NT working with it?
> 
> Thank you for any information.
> 
> Markus
> 

From owner-fwtk-users@ex.tis.com Thu Jun  8 14:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA08912
	Thu, 8 Jun 2000 14:23:58 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA12686;
	Thu, 8 Jun 2000 11:31:16 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Jun 2000 10:39:55 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA11218
	for fwtk-users-outgoing; Thu, 8 Jun 2000 10:39:44 -0700 (PDT)
Message-ID: <952FAEB97E0AD111BB7000805F0D84F6049DA5A5@eesusciexs3.eesus.jnj.com>
From: "Drash, Jim [EESUS]" <JDrash@EESUS.JNJ.com>
To: "'Markus Schreier'" <ms@ordix.de>, fwtk-users@lists.nai.com,
        fwtk-users@ex.tis.com
Subject: RE: ssh - Which one
Date: Thu, 8 Jun 2000 13:37:26 -0400 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1068

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

openssh on the unix box and putty or teraterm pro with the ttssh extentions
on the windows side.

> -----Original Message-----
> From: Markus Schreier [mailto:ms@ordix.de]
> Sent: Thursday, June 08, 2000 6:22 AM
> To: fwtk-users@lists.nai.com; fwtk-users@ex.tis.com
> Subject: ssh - Which one
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello fwtk-helpers,
> sorry if i'm to far of toppic.
> i'm setting up a fwtk on redhat linux. I would like to administer it
> over the network form an windwos nt and from a linux system.
> I've looked at diffrent sources of ssh (one and two).
> 
> Can anyone tell me which is the best practice if i'm looking for a
> charge free available stable secure shell?
> 
> Wich Server would be the best to use?
> Are there clients under NT working with it?
> 
> Thank you for any information.
> 
> Markus
> 

From owner-fwtk-users@ex.tis.com Fri Jun  9 06:53 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA11235
	Fri, 9 Jun 2000 06:53:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA21522;
	Fri, 9 Jun 2000 04:00:13 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Jun 2000 02:56:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA19957
	for fwtk-users-outgoing; Fri, 9 Jun 2000 02:56:38 -0700 (PDT)
Message-ID: <3940BEC4.3A7DB142@ordix.de>
Date: Fri, 09 Jun 2000 11:54:12 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: smap with Joe Yao's patch
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2845

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
thanks to evrybody for the help to get smap with Joe's patch compiled.

Now, i'm trying to set up smap (for now just for testing)

I have teh following network:

merlot.wbn.ordix.de (193.30.132.250) This is the host i send testmails
from (per telnet to port 25)
younix.wbn.ordix.de (193.30.132.241) this is (for now) my firewall with
smap.
The following is my configuration for  smap:

smap:           check-from-address 1
smap:           domains ordix.de *.ordix.de
# smap:         hosts 193.30.132.*
smap:           hosts 193.30.132.220
smap:           max-dirent 20
smap:           max-email 500
smap:           require-full-email 1
smap:           scrub-spam 1
smap:           spam spamdomain.spam 255.1.2.*
# smap, smapd:   userid 700
# smap, smapd:  groupid 700
smap, smapd:    directory /var/spool/smap
smap:           timeout 3600

I'm changing the setting for 
smap: host 
to simulate mails comming from extern and intern.

Having smap set up to recon merlot as internal server (host
193.30.132.*)
I get the following:
no matter which mail from: address nor which rcpt to address i use, mail
is always accepted. (expect realy bogous sender-adresses)
That is about that what i want. :-)

On the other hand: 
having smap set up to recon merlot as external server (host
193.30.132.220)
mail from: ms@merlot.wbn.ordix.de
gives the following output to syslog
Jun  9 10:28:54 localhost smap.relay[5164]: deny    
host=merlot.wbn.ordix.de/193.30.132.250 use of gateway
Jun  9 10:28:55 localhost smap.relay[5164]: security: rejected mail    
purporting to be from ms@merlot.wbn.ordix.de [NULL] from host    
merlot.wbn.ordix.de/193.30.132.250
This message will be denied no matter what comes next.

mail from: mdschreier@gmx.de
replies
250 mdschreier@gmx.de... Sender Ok
but i still get this syslog-output

Jun  9 10:31:09 localhost smap.relay[5167]: deny         
host=merlot.wbn.ordix.de/193.30.132.250 use of gateway

Now giving a rcpt to: adress in the domain ordix.de
will give the following line to syslog:

Jun  9 10:32:42 localhost smap.relay[5167]: permit         
host=merlot.wbn.ordix.de/193.30.132.250 use of gateway

and the message will be deliverd

What does the message " deny host .. use of gateway" express? Why is it
there? Why is the mail still being deliverd?

Are Sender-Adresses of my local domain (ordix.de) from hosts beeing
external always rejected?

If i use the Joe Yao patches, does it make sense to use two smap
versions: one with SPECIALDOMAIN set for mails from the external network
(internet) and the other whith SPECIALDOMAIN not set for mails from the
internal (cooperate) network?

I would apreceate any tips or hints.

Greetings from Wiesbaden

Markus Schreier

ORDIX AG

From owner-fwtk-users@ex.tis.com Fri Jun  9 06:53 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA11236
	Fri, 9 Jun 2000 06:53:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA21518;
	Fri, 9 Jun 2000 04:00:13 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Jun 2000 02:57:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA19983
	for fwtk-users-outgoing; Fri, 9 Jun 2000 02:57:20 -0700 (PDT)
Message-ID: <3940BEC4.3A7DB142@ordix.de>
Date: Fri, 09 Jun 2000 11:54:12 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: smap with Joe Yao's patch
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2845

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
thanks to evrybody for the help to get smap with Joe's patch compiled.

Now, i'm trying to set up smap (for now just for testing)

I have teh following network:

merlot.wbn.ordix.de (193.30.132.250) This is the host i send testmails
from (per telnet to port 25)
younix.wbn.ordix.de (193.30.132.241) this is (for now) my firewall with
smap.
The following is my configuration for  smap:

smap:           check-from-address 1
smap:           domains ordix.de *.ordix.de
# smap:         hosts 193.30.132.*
smap:           hosts 193.30.132.220
smap:           max-dirent 20
smap:           max-email 500
smap:           require-full-email 1
smap:           scrub-spam 1
smap:           spam spamdomain.spam 255.1.2.*
# smap, smapd:   userid 700
# smap, smapd:  groupid 700
smap, smapd:    directory /var/spool/smap
smap:           timeout 3600

I'm changing the setting for 
smap: host 
to simulate mails comming from extern and intern.

Having smap set up to recon merlot as internal server (host
193.30.132.*)
I get the following:
no matter which mail from: address nor which rcpt to address i use, mail
is always accepted. (expect realy bogous sender-adresses)
That is about that what i want. :-)

On the other hand: 
having smap set up to recon merlot as external server (host
193.30.132.220)
mail from: ms@merlot.wbn.ordix.de
gives the following output to syslog
Jun  9 10:28:54 localhost smap.relay[5164]: deny    
host=merlot.wbn.ordix.de/193.30.132.250 use of gateway
Jun  9 10:28:55 localhost smap.relay[5164]: security: rejected mail    
purporting to be from ms@merlot.wbn.ordix.de [NULL] from host    
merlot.wbn.ordix.de/193.30.132.250
This message will be denied no matter what comes next.

mail from: mdschreier@gmx.de
replies
250 mdschreier@gmx.de... Sender Ok
but i still get this syslog-output

Jun  9 10:31:09 localhost smap.relay[5167]: deny         
host=merlot.wbn.ordix.de/193.30.132.250 use of gateway

Now giving a rcpt to: adress in the domain ordix.de
will give the following line to syslog:

Jun  9 10:32:42 localhost smap.relay[5167]: permit         
host=merlot.wbn.ordix.de/193.30.132.250 use of gateway

and the message will be deliverd

What does the message " deny host .. use of gateway" express? Why is it
there? Why is the mail still being deliverd?

Are Sender-Adresses of my local domain (ordix.de) from hosts beeing
external always rejected?

If i use the Joe Yao patches, does it make sense to use two smap
versions: one with SPECIALDOMAIN set for mails from the external network
(internet) and the other whith SPECIALDOMAIN not set for mails from the
internal (cooperate) network?

I would apreceate any tips or hints.

Greetings from Wiesbaden

Markus Schreier

ORDIX AG

From owner-fwtk-users@ex.tis.com Fri Jun  9 08:51 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA11704
	Fri, 9 Jun 2000 08:51:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA24008;
	Fri, 9 Jun 2000 05:58:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Jun 2000 05:08:16 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22994
	for fwtk-users-outgoing; Fri, 9 Jun 2000 05:08:05 -0700 (PDT)
Date: Thu, 8 Jun 2000 14:49:13 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Markus Schreier <ms@ordix.de>
cc: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: Re: smap Joe Yao's patch: res_query
In-Reply-To: <393F9843.BA0D88C2@ordix.de>
Message-ID: <Pine.GSO.4.10.10006081449030.11407-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1041

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

add -lresolv to the Makefile

ted keller


On Thu, 8 Jun 2000, Markus Schreier wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hello,
 > i aplied Joe Yao's patch to smap.c. But afterwards i could not compile/
 > link smap anymore. The output of make looks like this.
 > 
 > make
 > cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
 > -L/usr/local/src/firewall/source/fwtk/fwtk/fwtk/skey -lskey -lmd
 > smap.o: In function `from_address_ok':
 > /usr/local/src/firewall/source/fwtk/fwtk/fwtk/smap/smap.c:2016:
 > undefined reference to `res_query'
 > /usr/local/src/firewall/source/fwtk/fwtk/fwtk/smap/smap.c:2016:
 > undefined reference to `res_query'
 > collect2: ld returned 1 exit status
 > make: *** [smap] Error 1
 > [root@younix smap]# 
 > 
 > Any help would be areceated.
 > 
 > Markus
 > 



From owner-fwtk-users@ex.tis.com Fri Jun  9 10:12 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA12030
	Fri, 9 Jun 2000 10:12:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA26291;
	Fri, 9 Jun 2000 07:19:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Jun 2000 06:18:16 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA24349
	for fwtk-users-outgoing; Fri, 9 Jun 2000 06:18:10 -0700 (PDT)
Message-ID: <3940ED8A.89DB6C8C@ordix.de>
Date: Fri, 09 Jun 2000 15:13:46 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: smap with joe yao's patch: localhost
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1237

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
i'm still setting up smap and sendmail. I find more and more questions:
Sending mail through the firewall adds the following lines to the
mail-header:

Received: 
from localhost.localdomain (root@younix.wbn.ordix.de [193.30.132.251])
by gate.ordix.de (8.8.3/8.8.8) with ESMTP id MAA31127 for <ms@ordix.de>;
Fri, 9 Jun 2000 12:41:14 +0200
Received: 
(from fwtk@localhost) by localhost.localdomain (8.9.3/8.9.3) id MAA07609
for
ms@ordix.de; Fri, 9 Jun 2000 12:35:41 GMT
Date: 
Fri, 9 Jun 2000 12:35:41 GMT
Message-ID: 
<200006091235.MAA07609@localhost.localdomain>
 X-Authentication-Warning: 
localhost.localdomain: fwtk set sender to mdschreier@gmx.de using -f
Received: 
from merlot.wbn.ordix.de(193.30.132.250) by localhost.localdomain via
smap
V2.1/2.1+anti-relay+anti-spam) id xma007607; Fri, 9 Jun 00 12:35:06 GMT

I would prefer to read the real (full qualified) hostname instead of
localhost. 
If i cahnge /etc/hosts to list the fqdn first for 127.0.0.1 it works all
right. But i mislike the idea of bending localhost not to be localhost.

What can i do?

Thanks a lot
Markus Schreier

ORDIX AG

From owner-fwtk-users@ex.tis.com Fri Jun  9 10:12 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA12031
	Fri, 9 Jun 2000 10:12:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA26295;
	Fri, 9 Jun 2000 07:19:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Jun 2000 06:16:43 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA24289
	for fwtk-users-outgoing; Fri, 9 Jun 2000 06:16:37 -0700 (PDT)
Message-ID: <3940ED8A.89DB6C8C@ordix.de>
Date: Fri, 09 Jun 2000 15:13:46 +0200
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.61 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com, fwtk-users@ex.tis.com
Subject: smap with joe yao's patch: localhost
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1237

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
i'm still setting up smap and sendmail. I find more and more questions:
Sending mail through the firewall adds the following lines to the
mail-header:

Received: 
from localhost.localdomain (root@younix.wbn.ordix.de [193.30.132.251])
by gate.ordix.de (8.8.3/8.8.8) with ESMTP id MAA31127 for <ms@ordix.de>;
Fri, 9 Jun 2000 12:41:14 +0200
Received: 
(from fwtk@localhost) by localhost.localdomain (8.9.3/8.9.3) id MAA07609
for
ms@ordix.de; Fri, 9 Jun 2000 12:35:41 GMT
Date: 
Fri, 9 Jun 2000 12:35:41 GMT
Message-ID: 
<200006091235.MAA07609@localhost.localdomain>
 X-Authentication-Warning: 
localhost.localdomain: fwtk set sender to mdschreier@gmx.de using -f
Received: 
from merlot.wbn.ordix.de(193.30.132.250) by localhost.localdomain via
smap
V2.1/2.1+anti-relay+anti-spam) id xma007607; Fri, 9 Jun 00 12:35:06 GMT

I would prefer to read the real (full qualified) hostname instead of
localhost. 
If i cahnge /etc/hosts to list the fqdn first for 127.0.0.1 it works all
right. But i mislike the idea of bending localhost not to be localhost.

What can i do?

Thanks a lot
Markus Schreier

ORDIX AG

From owner-fwtk-users@ex.tis.com Fri Jun  9 19:08 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA14265
	Fri, 9 Jun 2000 19:08:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA01775;
	Fri, 9 Jun 2000 16:14:54 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Jun 2000 15:18:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA00723
	for fwtk-users-outgoing; Fri, 9 Jun 2000 15:18:34 -0700 (PDT)
Message-ID: <3767486.960589056420.JavaMail.imail@dotty.excite.com>
Date: Fri, 9 Jun 2000 15:17:36 -0700 (PDT)
From: "T. Esting" <T_Esting@excite.com>
Reply-To: <T_Esting@excite.com>
To: fwtk-users@lists.nai.com
Subject: macromedia (shockwave/flash) && activex
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Mailer: Excite Inbox
X-Sender-Ip: 63.73.213.5
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 818

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


  I know this has come up once in the past ('97, if my recollection is
reliable), but I'm wondering if anyone has come up with a definitive answer
on whether it is possible to allow Macromedia content, be it either the
Flash plugin or Shockwave applications, to pass through http-gw without also
allowing ActiveX?  My impression is that, since Flash uses the <OBJECT> HTML
tag, this is a losing proposition, but I thought I'd query the group since
the FAQ does not mention it and nothing new has been posted in years.

  Thanks!

  T.E.





_______________________________________________________
Get 100% FREE Internet Access powered by Excite
Visit http://freelane.excite.com/freeisp


From owner-fwtk-users@ex.tis.com Tue Jun 13 10:46 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA25854
	Tue, 13 Jun 2000 10:46:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA14400;
	Tue, 13 Jun 2000 07:52:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 06:26:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA13217
	for fwtk-users-outgoing; Tue, 13 Jun 2000 06:26:39 -0700 (PDT)
Message-Id: <s945efab.005@css.edu>
X-Mailer: Novell GroupWise 5.5.3
Date: Tue, 13 Jun 2000 08:24:04 -0500
From: "Michael Linval" <Mlinval@css.edu>
To: <Fwtk-users@ex.tis.com>
Subject: Anti-relay patch
Mime-Version: 1.0
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 625

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I know this is a common thread and I have been following the posts
lately.  I also use smap and smapd with sendmail and have been recently
targeted for relaying. 

Being fairly new to the program and Unix in general, I have been unsure
how to go about the process of patching the software.  I cant seem to
download the Yao patch and am looking for help/suggestions.

I am running a Solaris box with 2.7 and sendmail version that comes
with it.

Thanks for any help

Mike Linval
mlinval@css.edu 


From owner-fwtk-users@ex.tis.com Tue Jun 13 12:18 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA26418
	Tue, 13 Jun 2000 12:18:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA16313;
	Tue, 13 Jun 2000 09:25:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 08:36:28 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA15045
	for fwtk-users-outgoing; Tue, 13 Jun 2000 08:36:17 -0700 (PDT)
Message-ID: <CAE0A17F1713D311A44500105A16C90B652C1D@BUSH>
From: Malcolm Tester <MTester@cambric.com>
To: Michael Linval <Mlinval@css.edu>, Fwtk-users@ex.tis.com
Subject: RE: Anti-relay patch
Date: Tue, 13 Jun 2000 09:46:19 -0600
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="windows-1252"
Content-Length: 1801

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,

This is both an answer and a question.  I used Sendmail too, with smap/smapd
on Solaris, and ran into some problems with it.  In the process of fixing
it, I came across Postfix, which is a replacement MTA for Sendmail. (and is
compatible).  I installed that, turned off smap/smapd/sendmail, and since
then, I have not run into any problems with relay or hacking with the mail.
So my answer is that you should try Postfix as an alternative.  The process
you connect to on port 25 is not setuid root, and as far as I have been able
to tell, causes no problems.  My question, on the other hand, is: Has anyone
else on this list run Postfix in conjunction with TIS FWTK?  And if so, did
you have any problems, or configuration issues?  And did you turn off
smap/smapd or leave them on?

Regards,
Malcolm W. Tester II



> -----Original Message-----
> From: Michael Linval [mailto:Mlinval@css.edu]
> Sent: Tuesday, June 13, 2000 7:24 AM
> To: Fwtk-users@ex.tis.com
> Subject: Anti-relay patch
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I know this is a common thread and I have been following the posts
> lately.  I also use smap and smapd with sendmail and have 
> been recently
> targeted for relaying. 
> 
> Being fairly new to the program and Unix in general, I have 
> been unsure
> how to go about the process of patching the software.  I cant seem to
> download the Yao patch and am looking for help/suggestions.
> 
> I am running a Solaris box with 2.7 and sendmail version that comes
> with it.
> 
> Thanks for any help
> 
> Mike Linval
> mlinval@css.edu 
> 

From owner-fwtk-users@ex.tis.com Tue Jun 13 13:04 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA26711
	Tue, 13 Jun 2000 13:04:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA17770;
	Tue, 13 Jun 2000 10:11:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 09:27:19 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA16343
	for fwtk-users-outgoing; Tue, 13 Jun 2000 09:27:03 -0700 (PDT)
Message-ID: <39465F97.D1203A5B@newscomp.com>
Date: Tue, 13 Jun 2000 12:21:43 -0400
From: Scott McEachern <smceachern@jamedia.com>
Reply-To: smceachern@jamedia.com
X-Mailer: Mozilla 4.72 [en] (X11; U; SunOS 5.8 i86pc)
X-Accept-Language: en
MIME-Version: 1.0
To: Malcolm Tester <MTester@cambric.com>
CC: Michael Linval <Mlinval@css.edu>, Fwtk-users@ex.tis.com
Subject: Re: Anti-relay patch
References: <CAE0A17F1713D311A44500105A16C90B652C1D@BUSH>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 895

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Malcolm Tester wrote:

> So my answer is that you should try Postfix as an alternative.  The process
> you connect to on port 25 is not setuid root, and as far as I have been able
> to tell, causes no problems.  My question, on the other hand, is: Has anyone
> else on this list run Postfix in conjunction with TIS FWTK?  And if so, did
> you have any problems, or configuration issues?  And did you turn off
> smap/smapd or leave them on?

    I gave up on sendmail, between the config and perpetual security issues.
I went with qmail and haven't had a problem yet.  I'm not using smap/smapd at
all.


--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.,
300 John St., Suite 500
Thornhill, ON, CA.  L3T 5W4
tel: 905-881-6902  fax: 905-881-6945




From owner-fwtk-users@ex.tis.com Tue Jun 13 14:20 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA26990
	Tue, 13 Jun 2000 14:20:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA19758;
	Tue, 13 Jun 2000 11:27:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 10:39:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA18465
	for fwtk-users-outgoing; Tue, 13 Jun 2000 10:39:02 -0700 (PDT)
From: dreamwvr <dreamwvr@dreamwvr.com>
To: smceachern@jamedia.com, Scott McEachern <smceachern@jamedia.com>,
        Malcolm Tester <MTester@cambric.com>
Subject: Re: Anti-relay patch
Date: Tue, 13 Jun 2000 11:50:07 -0600
X-Mailer: KMail [version 1.0.28]
Cc: Michael Linval <Mlinval@css.edu>, Fwtk-users@ex.tis.com
References: <CAE0A17F1713D311A44500105A16C90B652C1D@BUSH> <39465F97.D1203A5B@newscomp.com>
In-Reply-To: <39465F97.D1203A5B@newscomp.com>
MIME-Version: 1.0
Message-Id: <00061312005702.01514@tyr.dreamwvr.com>
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 2968

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi,
   Agreed i fell in love with postfix the moment i brought it up. it is secure,
scales very well, is a drop in replacement for sendmail. Since Sendmail
batbook made light bedtime reading (i read it page to page.) My first thought 
about postfix was oh..oh this is going to be fun..;-() Guess what it was a 
painless switch. qmail well .. secure is quite diff than sendmail so if someone
has used sendmail well postfix is quite easy to switch to. Don't get me wrong 
djb does some very great stuff but myself well i use postfix. 
postfix = simular minus the sendmail.cf file + less progs to learn does the
same thing IMHO. from the author of tcp_wrappers and postfix is non restricted
sw.. qmail is more restrictive ..
qmail = not simular to sendmail but uniquely diff with lots of
progs to learn..   but if you use lots of djb programs you most likely will be
giving  it a try. 
Both of these guys write excellent security conscious programs..
					Best Regards,
					dreamwvr@dreamwvr.com
 > Malcolm Tester wrote:
> 
> > So my answer is that you should try Postfix as an alternative.  The process
> > you connect to on port 25 is not setuid root, and as far as I have been able
> > to tell, causes no problems.  My question, on the other hand, is: Has anyone
> > else on this list run Postfix in conjunction with TIS FWTK?  And if so, did
> > you have any problems, or configuration issues?  And did you turn off
> > smap/smapd or leave them on?
> 
>     I gave up on sendmail, between the config and perpetual security issues.
> I went with qmail and haven't had a problem yet.  I'm not using smap/smapd at
> all.
> 
> 
> --
> R. Scott McEachern, Network Administrator
> J&A Media Services, Inc.,
> 300 John St., Suite 500
> Thornhill, ON, CA.  L3T 5W4
> tel: 905-881-6902  fax: 905-881-6945
-- 
Reuters, London, February 29, 1998:
Scientists have announced discovering a meteorite which will strike the
earth in March, 2028.  Millions of UNIX coders expressed relief for being
spared the UNIX epoch "crisis" of 2038. 
_______________________________________________________________________
 
************** DREAMWVR.COM - TOTAL INTERNET SERVICES ****************
  TOTAL DESIGN - DEVELOPMENT - INTEGRATION - SECURITY - Click Here..
           <http://www.dreamwvr.com/services/MAX_SEC.html>;
   DREAMWVR.COM - The Console of Many... 90 Topics Covered
<http://www.dreamwvr.com/dynamicduo.html>;
<mailto:dreamwvr@dreamwvr.com>;
->> LINUX-MANDRAKE Solution Provider and North American Distributor<<-
                        PRODUCT OF THE YEAR!
<http://www.dreamwvr.com/mandrake/mandrake-main.html>;
 "===0 PGP Key Available
*************** "As Unique as the Company You Keep."*****************
    "If anyone speaks from DREAMWVR.COM its certainly not me:-)"
________________________________________________________________________  

From owner-fwtk-users@ex.tis.com Tue Jun 13 15:31 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA27285
	Tue, 13 Jun 2000 15:31:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA22047;
	Tue, 13 Jun 2000 12:38:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 11:49:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA20148
	for fwtk-users-outgoing; Tue, 13 Jun 2000 11:49:31 -0700 (PDT)
To: fwtk-users@ex.tis.com
Subject: Postfix MTA (was: RE: Anti-relay patch)
Cc: MTester@cambric.com
X-Sun-Charset: US-ASCII
Message-Id: <20000613184910.242682C15C@skynet.medar.com>
Date: Tue, 13 Jun 2000 14:49:10 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2523

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In <CAE0A17F1713D311A44500105A16C90B652C1D@BUSH>,
Malcolm Tester <MTester@cambric.com> wrote:
[snip]
> ... I came across Postfix, which is a replacement MTA for Sendmail. (and is
> compatible).  I installed that, turned off smap/smapd/sendmail, and since
> then, I have not run into any problems with relay or hacking with the mail.
> So my answer is that you should try Postfix as an alternative.  The process
> you connect to on port 25 is not setuid root, and as far as I have been able
> to tell, causes no problems.  

Postfix, rather than being a monolithic solution like sendmail,
consists of a group of cooperating pieces that are coordinated via a
master daemon (kind of like smapd, only more so).  For example: smtpd
is a separate piece that is responsible only for the SMTP part of
things.  (Much like smap.)

>                               My question, on the other hand, is: Has anyone
> else on this list run Postfix in conjunction with TIS FWTK?  

Close.  I'm running it on my Gauntlet firewall.  (And I replaced the
T.REX MTA with Postfix, as well.)

>                                                              And if so, did
> you have any problems, or configuration issues?  

Nope and nope.  I installed Postfix on my Gauntlet firewall back on
Nov. 18.  It has given me no cause to regret the move yet.

>                                                  And did you turn off
> smap/smapd or leave them on?

Turned 'em off.  Don't need them anymore with the way Postfix is
designed, IMHO.  Not only does Postfix consist of separate, cooperating
pieces, but you can run them in a chroot'd jail if you want.


It doesn't hurt that Postfix is written by Wietse Venema.  One of the
better-known computer security people in the business.  (Does "tcp
wrapper" sound familiar? :-))

I replaced smap/smapd/sendmail with Postfix on my Gauntlet firewall for
a number of reasons.  Sendmail's line-noise-looking configuration being
one.  Smap/smapd leaving things laying about was another.  More
comprehensive anti-spam support was yet another.

The Postfix main web site is http://www.postfix.org, for those who may
be interested.


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems & Network Administrator     | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Tue Jun 13 15:43 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA27316
	Tue, 13 Jun 2000 15:43:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA22530;
	Tue, 13 Jun 2000 12:50:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 12:08:25 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA20802
	for fwtk-users-outgoing; Tue, 13 Jun 2000 12:08:19 -0700 (PDT)
Date: Tue, 13 Jun 2000 14:10:48 -0500 (CDT)
From: Sergio Jimenez Tovar <sjimenez@galois.dgae.unam.mx>
X-Sender: sjimenez@laplace
To: fwtk <Fwtk-users@ex.tis.com>
Subject: Patch httpd
Message-ID: <Pine.GSO.4.05.10006131400530.4895-100000@laplace>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 290

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

	Where can I download a patch for httpd for fwtk 2.1 firewall,
because the web's pages don't see complety and  suggestme I download a
patch for this. Thanks.




From owner-fwtk-users@ex.tis.com Tue Jun 13 16:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA27456
	Tue, 13 Jun 2000 16:33:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA24803;
	Tue, 13 Jun 2000 13:40:46 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 12:53:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA22633
	for fwtk-users-outgoing; Tue, 13 Jun 2000 12:53:06 -0700 (PDT)
Message-ID: <005e01bfd571$0dac9c60$a641fea9@sundash.com>
Reply-To: "Jack Mullins" <jmullins@sundash.com>
From: "Jack Mullins" <jmullins@sundash.com>
To: "TIS Firewall E-mail list" <fwtk-users@ex.tis.com>
Subject: Searchable mail archive and blocking access to specific internet sites
Date: Tue, 13 Jun 2000 14:53:32 -0500
Organization: Sun Industries, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6600
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="Windows-1252"
Content-Length: 798

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Is there a searchable archive available other than the one at
http://www.support.nl/online/fwtkquery.html?  The last several times I've
needed to look for something, I have received the following error from that
page, "Error: No Index to query on.  Apparently, there is no index available
for this collection, so queries cannot be made at this time."

Anyway, what I'm looking for is an answer to the question, how do I block my
inside users from accessing specific internet sites such as www.real.com and
anything to do with RealAudio?


73,

Jack Mullins
Sun Ergoline
P.O. Box 2026
Jonesboro, AR 72402
http://www.sunergoline.com
jackm@sundash.com
870.935.1130 x 109


From owner-fwtk-users@ex.tis.com Tue Jun 13 17:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA27830
	Tue, 13 Jun 2000 17:24:52 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA27023;
	Tue, 13 Jun 2000 14:32:02 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 13:49:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA24935
	for fwtk-users-outgoing; Tue, 13 Jun 2000 13:49:08 -0700 (PDT)
Message-ID: <39469E56.DCD53F3C@v-one.com>
Date: Tue, 13 Jun 2000 16:49:26 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.73 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Jack Mullins <jmullins@sundash.com>
CC: TIS Firewall E-mail list <fwtk-users@ex.tis.com>
Subject: Re: Searchable mail archive and blocking access to specific internet 
 sites
References: <005e01bfd571$0dac9c60$a641fea9@sundash.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1230

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jack Mullins wrote:
> 
> Is there a searchable archive available other than the one at
> http://www.support.nl/online/fwtkquery.html?  The last several times I've
> needed to look for something, I have received the following error from that
> page, "Error: No Index to query on.  Apparently, there is no index available
> for this collection, so queries cannot be made at this time."

Look at fwtk.org... I've updated the links and removed that searchable
database.

Goto here for info:
http://www.fwtk.org/fwtk/download/downloading.html#3.5
 
> Anyway, what I'm looking for is an answer to the question, how do I block my
> inside users from accessing specific internet sites such as www.real.com and
> anything to do with RealAudio?

Make sure that you are not running the RealAudio/RealVideo proxy server
(obviously). You'll need to filter the following MIME types in http-gw: 
"audio/x-pn-realaudio"
	"video/vndrn-realvideo"
	"audio/vndrn-realaudio"
	"audio/x-realaudio"

How you do that, I have no idea...  :-)

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Tue Jun 13 17:34 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA27854
	Tue, 13 Jun 2000 17:34:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA27322;
	Tue, 13 Jun 2000 14:41:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Jun 2000 13:56:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA25228
	for fwtk-users-outgoing; Tue, 13 Jun 2000 13:56:11 -0700 (PDT)
Message-ID: <002d01bfd577$eeae7b60$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "TIS Firewall E-mail list" <fwtk-users@ex.tis.com>
Cc: "Jack Mullins" <jmullins@sundash.com>
References: <005e01bfd571$0dac9c60$a641fea9@sundash.com>
Subject: Re: Searchable mail archive and blocking access to specific internet sites
Date: Tue, 13 Jun 2000 16:40:42 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6600
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1344

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jack Mullins <jmullins@sundash.com> asked:
>
> Is there a searchable archive available other than the one at
> http://www.support.nl/online/fwtkquery.html?  The last several times I've
> needed to look for something, I have received the following error from
that
> page, "Error: No Index to query on.  Apparently, there is no index
available
> for this collection, so queries cannot be made at this time."

The following is a a searchable archive:
http://marc.theaimsgroup.com/?l=fwtk-users&r=1&w=2

> Anyway, what I'm looking for is an answer to the question, how do I block
my
> inside users from accessing specific internet sites such as www.real.com
and
> anything to do with RealAudio?

My understanding is that you can use ipfilter to deny use of the normal udp
ports, BUT
they can configure it to use http protocol.  You could block http access to
http://www.real.com BUT
they only really need this site to get the player, the content comes from
all over.
The only thing you could do is use some kind of filter like JunkBuster and
keep adding sites to its block file.
You could probably monitor your network for the long connections needed to
play music and then block those sites.

LarryJackson@iName.com



From owner-fwtk-users@ex.tis.com Wed Jun 14 06:19 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA29929
	Wed, 14 Jun 2000 06:19:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA10635;
	Wed, 14 Jun 2000 03:01:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 02:06:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA09701
	for fwtk-users-outgoing; Wed, 14 Jun 2000 02:06:34 -0700 (PDT)
Message-ID: <394749E0.2EE7291C@newscomp.com>
Date: Wed, 14 Jun 2000 05:01:20 -0400
From: Scott McEachern <smceachern@jamedia.com>
Reply-To: smceachern@jamedia.com
X-Mailer: Mozilla 4.72 [en] (X11; U; SunOS 5.8 i86pc)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: xntpd udp relay
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1198

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

    Just a quick question here:
    I'm running xntpd on my firewall box, and my boss wants it off and
running on an internal machine.
    As far as I know, xntpd uses udp and the toolkit doesn't relay udp
at all, thus the xntpd _must_ run on the firewall machine.
    Is there _any_ way to get around this?

    Actually, while I'm thinking about it, something similar applies to
nameservers.  I have dns running on the f/w too.  How would our ISP do
zone transfers off an internal machine (hosting our external domain.)
    I'm quite puzzled by this, as I understand you shouldn't be running
any services like these on the f/w, but I don't see any way around it.
I asked this some months ago when I was less familiar with how things
work, and I was told that xntpd and dns must run on the f/w, but my boss
really _insists_ they do not, but is unable to explain how.

    Any help would be appreciated.


--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.,
300 John St., Suite 500
Thornhill, ON, CA.  L3T 5W4
tel: 905-881-6902  fax: 905-881-6945




From owner-fwtk-users@ex.tis.com Wed Jun 14 08:58 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA00607
	Wed, 14 Jun 2000 08:58:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA13024;
	Wed, 14 Jun 2000 06:05:45 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 05:16:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA12112
	for fwtk-users-outgoing; Wed, 14 Jun 2000 05:15:56 -0700 (PDT)
To: fwtk-users@ex.tis.com
Subject: Re: xntpd udp relay
X-Sun-Charset: US-ASCII
Message-Id: <20000614121540.3F32A2C15C@skynet.medar.com>
Date: Wed, 14 Jun 2000 08:15:40 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1714

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In message <394749E0.2EE7291C@newscomp.com>,
Scott McEachern <smceachern@jamedia.com> wrote:
[snip]
> 
>     Just a quick question here:
>     I'm running xntpd on my firewall box, and my boss wants it off and
> running on an internal machine.
>     As far as I know, xntpd uses udp and the toolkit doesn't relay udp
> at all, ...

Yes.

>     ... thus the xntpd _must_ run on the firewall machine.
>     Is there _any_ way to get around this?

Udprelay, maybe?

> 
>     Actually, while I'm thinking about it, something similar applies to
> nameservers.  ...
[snip]
> 

Assuming that you name serve for your domain as it appears on the 'net,
and assuming that you don't want the DNS for your internal stuff
exposed to the 'net, you need an outside nameserver anyway.  If your
boss is concerned about possible BIND exploits compromising your
firewall, then you need to put it up on a separate "outside" server.
But now you have a quandary.  You don't really want to put it up on an
outside server that's unprotected by the firewall (I wouldn't
think--unless you want to deal with hardening that machine), so you'd
probably want to put it up on a third ("service") port off your
firewall.

Personally, I don't see any problem with running ntp or bind on the
firewall--providing you keep an eye out for exploits and keep 'em
up-to-date.


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems & Network Administrator     | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Wed Jun 14 09:59 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA00835
	Wed, 14 Jun 2000 09:59:48 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA14659;
	Wed, 14 Jun 2000 07:06:55 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 06:18:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA13259
	for fwtk-users-outgoing; Wed, 14 Jun 2000 06:18:02 -0700 (PDT)
Date: Wed, 14 Jun 2000 09:16:24 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Scott McEachern <smceachern@jamedia.com>
cc: fwtk-users@ex.tis.com
Subject: Re: xntpd udp relay
In-Reply-To: <394749E0.2EE7291C@newscomp.com>
Message-ID: <Pine.GSO.4.10.10006140841290.24833-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2803

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Scott,

ntpd uses both tcp and udp.  So you are right - with the firewall by
itself, you can't pass these packets through to an internal server.

However, you may want to ask yourself a couple of questions....
1. why am I running it?

2. where do I get my time source from?

As for the first question, ntpd runs in two modes - that as a client (I go
and get the time and set my clock functions accordingly) and as a server
(I will tell someone else the time if they ask for it).

If accurate time on the firewall is important to you, then you have to run
at least the client on the firewall machine - otherwise the firewall
machine's clock will drift.  If I use the Internet as the time source and
want to sync my internal network, then the firewall will also have to be a
server in addition.  Now, with the ntp.conf file, you can at least specify
who can ask you for time.

On the second question, where do I get my time from?  Consider acquiring
an internal time source (GPS system or equivalent).  They are relatively
inexpensive and help solve the problem of trusting internet sources for
this function. Also, it helps solve the issue of passing these type of
packets across your firewall.  Your internal network can use the trusted
time source.  Your firewall, if you desire, can also point to that source.
Everything can operate in "client mode".

ted keller
 

On Wed, 14 Jun 2000, Scott McEachern wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
>     Just a quick question here:
>     I'm running xntpd on my firewall box, and my boss wants it off and
> running on an internal machine.
>     As far as I know, xntpd uses udp and the toolkit doesn't relay udp
> at all, thus the xntpd _must_ run on the firewall machine.
>     Is there _any_ way to get around this?
> 
>     Actually, while I'm thinking about it, something similar applies to
> nameservers.  I have dns running on the f/w too.  How would our ISP do
> zone transfers off an internal machine (hosting our external domain.)
>     I'm quite puzzled by this, as I understand you shouldn't be running
> any services like these on the f/w, but I don't see any way around it.
> I asked this some months ago when I was less familiar with how things
> work, and I was told that xntpd and dns must run on the f/w, but my boss
> really _insists_ they do not, but is unable to explain how.
> 
>     Any help would be appreciated.
> 
> 
> --
> R. Scott McEachern, Network Administrator
> J&A Media Services, Inc.,
> 300 John St., Suite 500
> Thornhill, ON, CA.  L3T 5W4
> tel: 905-881-6902  fax: 905-881-6945
> 
> 
> 


From owner-fwtk-users@ex.tis.com Wed Jun 14 12:23 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA01405
	Wed, 14 Jun 2000 12:23:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA17733;
	Wed, 14 Jun 2000 09:30:37 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 08:15:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA15737
	for fwtk-users-outgoing; Wed, 14 Jun 2000 08:15:19 -0700 (PDT)
To: fwtk-users@ex.tis.com
Subject: Re: xntpd udp relay
X-Sun-Charset: US-ASCII
Message-Id: <20000614151458.7E5232C15C@skynet.medar.com>
Date: Wed, 14 Jun 2000 11:14:58 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1238

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In message <Pine.GSO.4.10.10006140841290.24833-100000@ns1.bfg.com>,
Ted Keller <keller@bfg.com> wrote:
[snip]
> 
> On the second question, where do I get my time from?  Consider acquiring
> an internal time source (GPS system or equivalent).  They are relatively
> inexpensive and help solve the problem of trusting internet sources for
> this function. ...
[snip]
> 

Just to clarify (IOW: I'm not disagreeing with Ted): NTP is highly
resistant to spoofing.  Particularly if you select several servers
against which to sync.  And even if it does get spoofed: the client
code will not make drastic changes in your system's idea of what the
present time is all at once.  Instead, it will "slew" the clock
gradually.  The point there being that it is hoped the Admin will
notice the error before the clock gets slewed out to sometime in the
next millennium :-).

Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems & Network Administrator     | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Wed Jun 14 12:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA01461
	Wed, 14 Jun 2000 12:37:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA18151;
	Wed, 14 Jun 2000 09:44:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 09:02:04 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA16564
	for fwtk-users-outgoing; Wed, 14 Jun 2000 09:01:53 -0700 (PDT)
Message-ID: <118CA1DAEB29D4118F7108002BE77E291293@gamera.int-appgeo.com>
From: Sean Brown <srbrown@appgeo.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Cc: "'smceachern@jamedia.com'" <smceachern@jamedia.com>
Subject: RE: xntpd udp relay
Date: Wed, 14 Jun 2000 12:00:47 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2778

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Scott,

ntpd can be configured to use certificate authentication between the client
and server similar to SSH, kerberos, or SSL.  However, I prefer to use
packet filtering to selectively allow traffic from my time sources on port
123.  Using ipchains, I create a new chain containing rules for the
timesources I use (there are three).  I then forward all traffic going to
port 123 to this rule.  Anything not from those timesources gets dumped.

My firewall acts as the main time server for my network.  I have other
systems get their time from the firewall and then act as lower tier time
servers for the workstations.

Since I use public time sources, I have not taken the time to configure
certificate authentication.  However, a more secure option would probably
use both packet filtering and the builtin authentication of ntpd.

Sean Brown

> -----Original Message-----
> From: Ted Keller [mailto:keller@bfg.com]
> Sent: Wednesday, June 14, 2000 9:16 AM
> To: Scott McEachern
> Cc: fwtk-users@ex.tis.com
> Subject: Re: xntpd udp relay
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Scott,
> 
> ntpd uses both tcp and udp.  So you are right - with the firewall by
> itself, you can't pass these packets through to an internal server.
> 
> However, you may want to ask yourself a couple of questions....
> 1. why am I running it?
> 
> 2. where do I get my time source from?
> 
> As for the first question, ntpd runs in two modes - that as a 
> client (I go
> and get the time and set my clock functions accordingly) and 
> as a server
> (I will tell someone else the time if they ask for it).
> 
> If accurate time on the firewall is important to you, then 
> you have to run
> at least the client on the firewall machine - otherwise the firewall
> machine's clock will drift.  If I use the Internet as the 
> time source and
> want to sync my internal network, then the firewall will also 
> have to be a
> server in addition.  Now, with the ntp.conf file, you can at 
> least specify
> who can ask you for time.
> 
> On the second question, where do I get my time from?  
> Consider acquiring
> an internal time source (GPS system or equivalent).  They are 
> relatively
> inexpensive and help solve the problem of trusting internet 
> sources for
> this function. Also, it helps solve the issue of passing these type of
> packets across your firewall.  Your internal network can use 
> the trusted
> time source.  Your firewall, if you desire, can also point to 
> that source.
> Everything can operate in "client mode".
> 
> ted keller
>  
> 

From owner-fwtk-users@ex.tis.com Wed Jun 14 13:38 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA01873
	Wed, 14 Jun 2000 13:38:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA21325;
	Wed, 14 Jun 2000 10:45:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 09:56:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA18577
	for fwtk-users-outgoing; Wed, 14 Jun 2000 09:56:44 -0700 (PDT)
Message-ID: <CAE0A17F1713D311A44500105A16C90B652C52@BUSH>
From: Malcolm Tester <MTester@cambric.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: tn-gw character display settings
Date: Wed, 14 Jun 2000 11:07:02 -0600
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1399

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


here's a question that may be easily answered.  When using the tn-gw proxy,
if I connect to a site where I can't use a command like "stty", my backspace
key is the Delete key.  Backspace produces the control code ^H.  Is there a
way to default the setting in the proxy to use the regular key?  I know
normally you would use "stty erase ^H" but if that's not available, it's
pretty frustrating to hit the backspace key a few times, realize it isn't
working, and then hit the delete key several more times.

Regards,
Malcolm

Malcolm W. Tester II
Systems Administrator
Cambric Corporation
110 West Business Park Drive
Draper, Utah 84020
http://www.cambric.com

This message is intended only for the use of the individual or entity to
whom it is addressed and may contain information that is privileged,
confidential and exempt from disclosure under applicable law.  If the reader
of this message is not the intended recipient, or the employee or agent
responsible for delivering the message to the intended recipient, you are
hereby notified that any dissemination, distribution or copying of this
communication is strictly prohibited.  If you have received this
communication in error, please delete it from your system and notify the
sender identified above by e-mail.

From owner-fwtk-users@ex.tis.com Wed Jun 14 13:38 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA01872
	Wed, 14 Jun 2000 13:38:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA21321;
	Wed, 14 Jun 2000 10:45:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 09:58:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA18644
	for fwtk-users-outgoing; Wed, 14 Jun 2000 09:57:56 -0700 (PDT)
Message-ID: <91A5926EFF44D3118B1200104B7276EB0E98F3@hart-exchange.hartwellcorp.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Extremely slow response with http-gw & IE 4.0 - 5.0
Date: Tue, 13 Jun 2000 08:25:41 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 715

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Recently to try to correct an unrelated problem I re-downloaded fwtk v2.1,
applied all the ftp-gw & http-gw patches I could find then re-compiled.
Since installing the resulting executables I've noticed extremely slow
response to web browsing requests with Internet Exploder 4.0 & 5.0.
Netscape version 3.04 does not show this behaviour at all.  The firewall is
running Debian GNU/Linux version 2.0 with kernel 2.0.37 on a uniprocessor
Pentium II (Klamath) 300 MHz system.

Anyone know what is going on and/or have a fix?


--------------------
Michael St. Laurent
Hartwell Corporation

From owner-fwtk-users@ex.tis.com Wed Jun 14 14:27 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA02126
	Wed, 14 Jun 2000 14:27:57 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA23720;
	Wed, 14 Jun 2000 11:34:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 10:50:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA21532
	for fwtk-users-outgoing; Wed, 14 Jun 2000 10:50:15 -0700 (PDT)
From: dreamwvr <dreamwvr@dreamwvr.com>
To: fwtk-users@ex.tis.com
Subject: Re: xntpd udp relay
Date: Wed, 14 Jun 2000 12:00:41 -0600
X-Mailer: KMail [version 1.0.28]
References: <20000614121540.3F32A2C15C@skynet.medar.com>
In-Reply-To: <20000614121540.3F32A2C15C@skynet.medar.com>
MIME-Version: 1.0
Message-Id: <00061412124207.01918@tyr.dreamwvr.com>
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 2597

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,
   well here is another read on it. if you are lucky enough to use gps clock
well your most likely not allowing udp port 123 anyhow. But lets justs say you
need to hit 3 stratum 2 timeservers out there. Well another approach is to 
allow only stateful connections est from   the inside to the 3 timeservers that 
you keep time with.. Then make certain that those time servers are allowed to 
tell you the time for your client but that's it using the nomodify in your 
ntp.conf file. That way even if they are spoofed the time servers can't 
modify can only give time. Plus when i scoured all the advisories from 
beginning to end i did not see any on ntp hacks. That is not saying they do 
not exist just that non are recorded. most likely they make your time screwed 
up which is why you have redundant ones so that 'insane' values are rejected.
which means if all 3 are screwed well your screwed.. which is why insane values 
are rejected.. you can widen your stratum 2 volume of servers for more
redundancy but do not gain any more really. There is a way to dailup as well
to NIS to get the time which as well might be a better idea. 
 Last but certainly not least consider udp-relay or equivalent but
your most  likely on your own on that one as have yet to come across a good faq
on  that issue. Anyone using it successfully? they would be on FWTK if anywhere
i would say. 
					Best Regards,
					dreamwvr@dreamwvr.com
  Reuters, London, February 29, 1998:
Scientists have announced discovering a meteorite which will strike the
earth in March, 2028.  Millions of UNIX coders expressed relief for being
spared the UNIX epoch "crisis" of 2038. 
_______________________________________________________________________
 
************** DREAMWVR.COM - TOTAL INTERNET SERVICES ****************
  TOTAL DESIGN - DEVELOPMENT - INTEGRATION - SECURITY - Click Here..
           <http://www.dreamwvr.com/services/MAX_SEC.html>;
   DREAMWVR.COM - The Console of Many... 90 Topics Covered
<http://www.dreamwvr.com/dynamicduo.html>;
<mailto:dreamwvr@dreamwvr.com>;
->> LINUX-MANDRAKE Solution Provider and North American Distributor<<-
                        PRODUCT OF THE YEAR!
<http://www.dreamwvr.com/mandrake/mandrake-main.html>;
 "===0 PGP Key Available
*************** "As Unique as the Company You Keep."*****************
    "If anyone speaks from DREAMWVR.COM its certainly not me:-)"
________________________________________________________________________  

From owner-fwtk-users@ex.tis.com Wed Jun 14 23:48 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA03637
	Wed, 14 Jun 2000 23:47:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA00143;
	Wed, 14 Jun 2000 20:55:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 19:59:58 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA29136
	for fwtk-users-outgoing; Wed, 14 Jun 2000 19:59:52 -0700 (PDT)
X-Server-Uuid: 3789b954-9c4e-11d3-af68-0008c73b0911
From: "Lamb, Geoff (Australia)" <Geoff_Lamb@exchange.au.ml.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Message-ID: <A12E983143A9D31194F300805FA74CA613847E@mepsexch02.au.ml.com>
Subject: scripting connection thru ftp-gw?
Date: Thu, 15 Jun 2000 12:59:30 +1000
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
X-WSS-ID: 1556991D81301-01-01
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; 
 charset=iso-8859-1
Content-Length: 434

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I want to do a scripted command line connection (on UNIX) through our
ftp-gw, Does anyone know
how I can do this? Is there a command line ftp that uses the ftp-gw? 

Thanks in advance.

Geoff

---------------
Geoff Lamb
Merrill Lynch Australia
+61 3 9659 2249
Mobile: 0414 325230
Geoff_Lamb@ml.com



From owner-fwtk-users@ex.tis.com Thu Jun 15 01:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id BAA03896
	Thu, 15 Jun 2000 01:56:22 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id XAA01841;
	Wed, 14 Jun 2000 23:03:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Jun 2000 22:15:31 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id WAA01067
	for fwtk-users-outgoing; Wed, 14 Jun 2000 22:15:19 -0700 (PDT)
Message-ID: <00ed01bfd689$fa71f860$8214a8c0@dyn.beam.com.au>
From: "Brian Desmond" <bdesmond@au.infogrames.com>
To: "Lamb, Geoff (Australia)" <Geoff_Lamb@exchange.au.ml.com>,
        <fwtk-users@ex.tis.com>
References: <A12E983143A9D31194F300805FA74CA613847E@mepsexch02.au.ml.com>
Subject: Re: scripting connection thru ftp-gw?
Date: Thu, 15 Jun 2000 15:24:28 +1000
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2615.200
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 439

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Yup! ncftp

see www.ncftp.com - comes with RedHat so is presumably
open source.

Cheers,

Brian

> Hi,
>
> I want to do a scripted command line connection (on UNIX) through
our
> ftp-gw, Does anyone know
> how I can do this? Is there a command line ftp that uses the ftp-gw?
>
> Thanks in advance.
>
> Geoff



From owner-fwtk-users@ex.tis.com Thu Jun 15 10:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA05941
	Thu, 15 Jun 2000 10:36:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA05926;
	Thu, 15 Jun 2000 07:43:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Jun 2000 06:48:30 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA04440
	for fwtk-users-outgoing; Thu, 15 Jun 2000 06:48:09 -0700 (PDT)
X-Authentication-Warning: gateway.satlantic.com: mail set sender to <jandrea@satlantic.com> using -f
Message-Id: <3.0.1.32.20000615102315.00959ea0@mail>
X-Sender: jandrea@mail
X-Mailer: Windows Eudora Light Version 3.0.1 (32)
Date: Thu, 15 Jun 2000 10:23:15 -0300
To: "Lamb, Geoff (Australia)" <Geoff_Lamb@exchange.au.ml.com>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
From: John Andrea <jandrea@satlantic.com>
Subject: Re: scripting connection thru ftp-gw?
In-Reply-To: <A12E983143A9D31194F300805FA74CA613847E@mepsexch02.au.ml.co
 m>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 1112

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This works fine for me

$ ftp -n firewall <<EOF
user anonymous@somehost.com me@myhost.com
cd pub
ls
quit
EOF

Non-anonymous works as well, use true username instead of
"anonymous" and true password instead of "me@myhost.com".





At 12:59 PM 6/15/00 +1000, Lamb, Geoff (Australia) wrote:
>[To be removed from this list send the message "unsubscribe fwtk-users" in the
>BODY of a mail message to majordomo@ex.tis.com.]
>
>Hi,
>
>I want to do a scripted command line connection (on UNIX) through our
>ftp-gw, Does anyone know
>how I can do this? Is there a command line ftp that uses the ftp-gw? 
>
>Thanks in advance.
>
>Geoff
>
>---------------
>Geoff Lamb
>Merrill Lynch Australia
>+61 3 9659 2249
>Mobile: 0414 325230
>Geoff_Lamb@ml.com
>
>
>
_______________________________________
John Andrea             Satlantic Inc.
Sys Admin               3295 Barrington St.
jandrea@satlantic.com   Halifax, NS
                        Canada   B3K 5X8
                        902-492-4780

From owner-fwtk-users@ex.tis.com Thu Jun 15 10:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA05940
	Thu, 15 Jun 2000 10:36:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA05922;
	Thu, 15 Jun 2000 07:43:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Jun 2000 06:48:25 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA04439
	for fwtk-users-outgoing; Thu, 15 Jun 2000 06:48:09 -0700 (PDT)
Message-ID: <394831F9.EE2F7795@asiabondportal.com>
Date: Thu, 15 Jun 2000 09:31:37 +0800
From: Raymond Lee <rlee@asiabondportal.com>
Reply-To: rlee@asiabondportal.com
X-Mailer: Mozilla 4.72 [en] (WinNT; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Sean Brown <srbrown@appgeo.com>
CC: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>,
        "'smceachern@jamedia.com'" <smceachern@jamedia.com>
Subject: Re: xntpd udp relay
References: <118CA1DAEB29D4118F7108002BE77E291293@gamera.int-appgeo.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 4034

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

I'm a new subscriber to the list.  The reason for my joining it is because I just
got started in the role of Internet Security and there are numerous security
issues out there that I need to pick up and learned in a very limited period of
time, say 6 months or less. I've read up numerous article and books as well as
visited internet security sites and got myself even more confused.

Before I go on, I should outline my background on the Internet security - limited
hands on experience in CISCO Router configm, a tad of experience in CheckPoint
Firewall and ISS RealSecure stuff.  As for Linux, my experience so far is ----- 1
week.

Just wondering if I want to get up to speed in the shortest period of time, do I
need to get myself setup like the rest of most people i.e. have the entire LAN,
WAN and servers installed at home?

I will keep reading up the good stuff that's been trading back and forth.

Any suggestion/advise will be very much appreciated.

Thanks.


Ray

Sean Brown wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Scott,
>
> ntpd can be configured to use certificate authentication between the client
> and server similar to SSH, kerberos, or SSL.  However, I prefer to use
> packet filtering to selectively allow traffic from my time sources on port
> 123.  Using ipchains, I create a new chain containing rules for the
> timesources I use (there are three).  I then forward all traffic going to
> port 123 to this rule.  Anything not from those timesources gets dumped.
>
> My firewall acts as the main time server for my network.  I have other
> systems get their time from the firewall and then act as lower tier time
> servers for the workstations.
>
> Since I use public time sources, I have not taken the time to configure
> certificate authentication.  However, a more secure option would probably
> use both packet filtering and the builtin authentication of ntpd.
>
> Sean Brown
>
> > -----Original Message-----
> > From: Ted Keller [mailto:keller@bfg.com]
> > Sent: Wednesday, June 14, 2000 9:16 AM
> > To: Scott McEachern
> > Cc: fwtk-users@ex.tis.com
> > Subject: Re: xntpd udp relay
> >
> >
> > [To be removed from this list send the message "unsubscribe
> > fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > Scott,
> >
> > ntpd uses both tcp and udp.  So you are right - with the firewall by
> > itself, you can't pass these packets through to an internal server.
> >
> > However, you may want to ask yourself a couple of questions....
> > 1. why am I running it?
> >
> > 2. where do I get my time source from?
> >
> > As for the first question, ntpd runs in two modes - that as a
> > client (I go
> > and get the time and set my clock functions accordingly) and
> > as a server
> > (I will tell someone else the time if they ask for it).
> >
> > If accurate time on the firewall is important to you, then
> > you have to run
> > at least the client on the firewall machine - otherwise the firewall
> > machine's clock will drift.  If I use the Internet as the
> > time source and
> > want to sync my internal network, then the firewall will also
> > have to be a
> > server in addition.  Now, with the ntp.conf file, you can at
> > least specify
> > who can ask you for time.
> >
> > On the second question, where do I get my time from?
> > Consider acquiring
> > an internal time source (GPS system or equivalent).  They are
> > relatively
> > inexpensive and help solve the problem of trusting internet
> > sources for
> > this function. Also, it helps solve the issue of passing these type of
> > packets across your firewall.  Your internal network can use
> > the trusted
> > time source.  Your firewall, if you desire, can also point to
> > that source.
> > Everything can operate in "client mode".
> >
> > ted keller
> >
> >

From owner-fwtk-users@ex.tis.com Fri Jun 16 03:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id DAA09594
	Fri, 16 Jun 2000 03:55:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA12574;
	Fri, 16 Jun 2000 01:02:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Jun 2000 23:41:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA11689
	for fwtk-users-outgoing; Thu, 15 Jun 2000 23:41:18 -0700 (PDT)
Message-ID: <3949784F.6942702B@home.com>
Date: Fri, 16 Jun 2000 00:43:59 +0000
From: chris holland <rangerco1@home.com>
X-Mailer: Mozilla 4.7 [en] (X11; U; Linux 2.2.15 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Problem getting the servers to work
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 665

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi everyone, I've compiled my own version of linux to use on my firewall
and I would like to use
fwtk as my proxy but for some reason I can get it to make connections, I
install the servers, set up the files exactly as explained in various
howto's but when I try to telnet of ftp to the machine or accross the
machine it tells me "connection refused"
I'm thinking that maybe it's not loading the daemons properly or I might
possibly ne missing a supporting program or something, anyone have any
ideas on how to fix this?

Thanks
Chris


From owner-fwtk-users@ex.tis.com Fri Jun 16 06:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA09895
	Fri, 16 Jun 2000 06:33:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA14368;
	Fri, 16 Jun 2000 03:40:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Jun 2000 02:51:31 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA13570
	for fwtk-users-outgoing; Fri, 16 Jun 2000 02:51:21 -0700 (PDT)
From: "Tom Krotchko" <tomk@toad.net>
To: "chris holland" <rangerco1@home.com>, <fwtk-users@ex.tis.com>
Subject: RE: Problem getting the servers to work
Date: Fri, 16 Jun 2000 05:50:50 -0400
Message-ID: <NDBBLGNJKLEFAOCFENPNAEFLCCAA.tomk@toad.net>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
In-Reply-To: <3949784F.6942702B@home.com>
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1226

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Have you altered inetd.conf and restarted inetd?

In BSD, inetd.conf is the file that governs what ports are open
and what program should be invoked when a connection is received
on that port.

-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of chris holland
Sent: Thursday, June 15, 2000 8:44 PM
To: 'fwtk-users@ex.tis.com'
Subject: Problem getting the servers to work


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

Hi everyone, I've compiled my own version of linux to use on my firewall
and I would like to use
fwtk as my proxy but for some reason I can get it to make connections, I
install the servers, set up the files exactly as explained in various
howto's but when I try to telnet of ftp to the machine or accross the
machine it tells me "connection refused"
I'm thinking that maybe it's not loading the daemons properly or I might
possibly ne missing a supporting program or something, anyone have any
ideas on how to fix this?

Thanks
Chris


From owner-fwtk-users@ex.tis.com Fri Jun 16 11:08 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA10948
	Fri, 16 Jun 2000 11:08:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA17218;
	Fri, 16 Jun 2000 08:16:19 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Jun 2000 07:23:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA15798
	for fwtk-users-outgoing; Fri, 16 Jun 2000 07:23:31 -0700 (PDT)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3949DECB.E0E43DCE@usrconsult.be>
Date: Fri, 16 Jun 2000 10:01:15 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: UsrConsult SPRL
X-Mailer: Mozilla 4.5 [en] (X11; I; IRIX64 6.5 IP27)
X-Accept-Language: en
MIME-Version: 1.0
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: Problem getting the servers to work
References: <3949784F.6942702B@home.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1068

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

chris holland wrote:
> 
> Hi everyone, I've compiled my own version of linux to use on my firewall
> and I would like to use
> fwtk as my proxy but for some reason I can get it to make connections, I
> install the servers, set up the files exactly as explained in various
> howto's but when I try to telnet of ftp to the machine or accross the
> machine it tells me "connection refused"
[snip]

It is extremely hard to help if you do not post your config files! There
is
a lot of flexibility in configuring FWTK and just telling 'according to
the howtos' does not say much...

Do you start the proxies via inetd (in which case post your inetd.conf)
or as daemons (in which case post the startup scripts)? And you should
also post netperm-table, and relevant system log entries.

As a wild guess, I would say the proxies are simply not running, i.e.
they are
configured neither in inted.conf nor in /etc/rc.

Greetings.
-- 
Michel Bardiaux

From owner-fwtk-users@ex.tis.com Fri Jun 16 11:08 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA10947
	Fri, 16 Jun 2000 11:08:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA17222;
	Fri, 16 Jun 2000 08:16:19 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Jun 2000 07:22:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA15775
	for fwtk-users-outgoing; Fri, 16 Jun 2000 07:22:31 -0700 (PDT)
Message-ID: <39495971.2EF3FFE4@calpha.com>
Date: Thu, 15 Jun 2000 17:32:17 -0500
From: concepts <syntax@calpha.com>
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.0-RELEASE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: "Lamb, Geoff (Australia)" <Geoff_Lamb@exchange.au.ml.com>
CC: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: scripting connection thru ftp-gw?
References: <A12E983143A9D31194F300805FA74CA613847E@mepsexch02.au.ml.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 827

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

My suggestion is one that most people have never looked at or even heard
of: Expect. It takes any UNIX text based interactive process, and with
very little code automates the process.

Syntax

"Lamb, Geoff (Australia)" wrote:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi,
> 
> I want to do a scripted command line connection (on UNIX) through our
> ftp-gw, Does anyone know
> how I can do this? Is there a command line ftp that uses the ftp-gw?
> 
> Thanks in advance.
> 
> Geoff
> 
> ---------------
> Geoff Lamb
> Merrill Lynch Australia
> +61 3 9659 2249
> Mobile: 0414 325230
> Geoff_Lamb@ml.com

From owner-fwtk-users@ex.tis.com Fri Jun 16 13:15 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA11538
	Fri, 16 Jun 2000 13:15:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA19596;
	Fri, 16 Jun 2000 10:23:12 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Jun 2000 09:33:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA18747
	for fwtk-users-outgoing; Fri, 16 Jun 2000 09:33:06 -0700 (PDT)
Message-ID: <394A030F.8EAF8F49@home.com>
Date: Fri, 16 Jun 2000 10:35:59 +0000
From: chris holland <rangerco1@home.com>
X-Mailer: Mozilla 4.7 [en] (X11; U; Linux 2.2.15 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Celeron 566 on ebay
References: <3949896B.D52271EA@home.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 258

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> Hi, sorry my mail box was full so if you responded could you re-send,
> I've cleaned out my mail box now

thanks again
Chris



From owner-fwtk-users@ex.tis.com Fri Jun 16 13:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA11761
	Fri, 16 Jun 2000 13:56:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA21085;
	Fri, 16 Jun 2000 11:03:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Jun 2000 10:20:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA19508
	for fwtk-users-outgoing; Fri, 16 Jun 2000 10:20:36 -0700 (PDT)
Message-ID: <394A0E34.B818B0EA@home.com>
Date: Fri, 16 Jun 2000 11:23:32 +0000
From: chris holland <rangerco1@home.com>
X-Mailer: Mozilla 4.7 [en] (X11; U; Linux 2.2.15 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Celeron 566 on ebay
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 163

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

sorry guys, I sent this in error


From owner-fwtk-users@ex.tis.com Fri Jun 16 14:22 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA11832
	Fri, 16 Jun 2000 14:21:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA22075;
	Fri, 16 Jun 2000 11:29:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Jun 2000 10:42:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA20188
	for fwtk-users-outgoing; Fri, 16 Jun 2000 10:41:55 -0700 (PDT)
From: dreamwvr <dreamwvr@dreamwvr.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: scripting connection thru ftp-gw?
Date: Fri, 16 Jun 2000 10:51:59 -0600
X-Mailer: KMail [version 1.0.28]
References: <A12E983143A9D31194F300805FA74CA613847E@mepsexch02.au.ml.com> <39495971.2EF3FFE4@calpha.com>
In-Reply-To: <39495971.2EF3FFE4@calpha.com>
MIME-Version: 1.0
Message-Id: <0006161054140L.00530@tyr.dreamwvr.com>
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 2450

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,
    Expect is great stuff IMHO but if you are simply going to request
downloading of  files from ftp sites then perl is just fine and has modules
that do this very well. Second there is a Expect module for perl which allows 
you to ma both languages into a hybrid as you see fit. So take your choices..
					Best Regards,
					dreamwvr@dreamwvr.com 
  On Thu, 15 Jun 2000, concepts wrote:
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> My suggestion is one that most people have never looked at or even heard
> of: Expect. It takes any UNIX text based interactive process, and with
> very little code automates the process.
> 
> Syntax
> 
> "Lamb, Geoff (Australia)" wrote:
> > 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > Hi,
> > 
> > I want to do a scripted command line connection (on UNIX) through our
> > ftp-gw, Does anyone know
> > how I can do this? Is there a command line ftp that uses the ftp-gw?
> > 
> > Thanks in advance.
> > 
> > Geoff
> > 
> > ---------------
> > Geoff Lamb
> > Merrill Lynch Australia
> > +61 3 9659 2249
> > Mobile: 0414 325230
> > Geoff_Lamb@ml.com
-- 
Reuters, London, February 29, 1998:
Scientists have announced discovering a meteorite which will strike the
earth in March, 2028.  Millions of UNIX coders expressed relief for being
spared the UNIX epoch "crisis" of 2038. 
_______________________________________________________________________
 
************** DREAMWVR.COM - TOTAL INTERNET SERVICES ****************
  TOTAL DESIGN - DEVELOPMENT - INTEGRATION - SECURITY - Click Here..
           <http://www.dreamwvr.com/services/MAX_SEC.html>;
   DREAMWVR.COM - The Console of Many... 90 Topics Covered
<http://www.dreamwvr.com/dynamicduo.html>;
<mailto:dreamwvr@dreamwvr.com>;
->> LINUX-MANDRAKE Solution Provider and North American Distributor<<-
                        PRODUCT OF THE YEAR!
<http://www.dreamwvr.com/mandrake/mandrake-main.html>;
 "===0 PGP Key Available
*************** "As Unique as the Company You Keep."*****************
    "If anyone speaks from DREAMWVR.COM its certainly not me:-)"
________________________________________________________________________  

From owner-fwtk-users@ex.tis.com Wed Jun 21 11:19 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA01988
	Wed, 21 Jun 2000 11:19:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA25800;
	Wed, 21 Jun 2000 08:26:41 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Jun 2000 07:00:55 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA24944
	for fwtk-users-outgoing; Wed, 21 Jun 2000 07:00:50 -0700 (PDT)
Date: Tue, 20 Jun 2000 20:02:40 -0700 (PDT)
From: Scott Campbell <scampbel@gvpl.victoria.bc.ca>
To: fwtk-users@ex.tis.com
Subject: Opening a port
Message-ID: <Pine.BSF.4.05.10006201951250.5197-100000@pochta.gvpl.victoria.bc.ca>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1194

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


We are running fwtk 2.1 on FreeBSD v3.x and everything is running fine.
The users are using http-gw on port 8080 to the outside world and that is
working great.  Now I have a site that my users want to attach to that
requires port 5050 to be open (so says their tech staff) - how do I do
that? The site

http://www.webpac.leg.bc.ca

runs a java applet that connects you to a server on port 5050.  It is NOT
http://www.webpac.leg.bc.ca:5050. I don't get any usefull errors in the
log from http-gw.  It works just fine if I put my machine outside the
firewall.  Can I put a 5050 hole through the firewall? How?  I've tried a
couple of plug-gw's but realized that wouldn't do any good since http-gw
is handling the traffic (on port 8080). Anybody out there have a situation
like this or can offer some useful suggestions.  I'm told a number of
sites use this 5050 software.

Thank you in advance

Scott E. Campbell
_______________________________
Computer Operations
Greater Victoria Public Library
Victoria BC CANADA

(250)382-7241 x230
scampbel@gvpl.victoria.bc.ca

From owner-fwtk-users@ex.tis.com Wed Jun 21 13:54 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA02669
	Wed, 21 Jun 2000 13:54:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA27722;
	Wed, 21 Jun 2000 11:01:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Jun 2000 10:04:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA26813
	for fwtk-users-outgoing; Wed, 21 Jun 2000 10:04:11 -0700 (PDT)
Date: Wed, 21 Jun 2000 13:02:30 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Scott Campbell <scampbel@gvpl.victoria.bc.ca>
cc: fwtk-users@ex.tis.com
Subject: Re: Opening a port
In-Reply-To: <Pine.BSF.4.05.10006201951250.5197-100000@pochta.gvpl.victoria.bc.ca>
Message-ID: <Pine.GSO.4.10.10006211255340.18720-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2603

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Scott,

I've seen two types of applets that try to make connections.  Each
requires a different solution.

The more basic types want to do direct DNS lookups - but then ride on the
browsers communications pathway - which will go through your httpd proxy.
The big thing you have to do here is allow the client to lookup Internet
host names (or define them internally).

The second are those that want to make a connection directly. (I hate this
type).  There the applet contains the code to perform the connect to the
site and manages its own protocol.  For these, it would appear that you
need a route to the remote host through your firewall (kind of hard with
application proxies), and rulesets which permit that raw tcp connections
to be made.

I think these are inherantly unsafe.  Your downloading an applet that you
didn't write.  Permitting it to open an external connection, and do
anything that it want's to to the client machine and any resources it can
touch.  However, trusted partners are implementing these requirements.

In the end, depending on the type of application you have, you may not be
able to perform this with the fwtk by itself.

ted keller


On Tue, 20 Jun 2000, Scott Campbell wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
> We are running fwtk 2.1 on FreeBSD v3.x and everything is running fine.
> The users are using http-gw on port 8080 to the outside world and that is
> working great.  Now I have a site that my users want to attach to that
> requires port 5050 to be open (so says their tech staff) - how do I do
> that? The site
> 
> http://www.webpac.leg.bc.ca
> 
> runs a java applet that connects you to a server on port 5050.  It is NOT
> http://www.webpac.leg.bc.ca:5050. I don't get any usefull errors in the
> log from http-gw.  It works just fine if I put my machine outside the
> firewall.  Can I put a 5050 hole through the firewall? How?  I've tried a
> couple of plug-gw's but realized that wouldn't do any good since http-gw
> is handling the traffic (on port 8080). Anybody out there have a situation
> like this or can offer some useful suggestions.  I'm told a number of
> sites use this 5050 software.
> 
> Thank you in advance
> 
> Scott E. Campbell
> _______________________________
> Computer Operations
> Greater Victoria Public Library
> Victoria BC CANADA
> 
> (250)382-7241 x230
> scampbel@gvpl.victoria.bc.ca
> 


From owner-fwtk-users@ex.tis.com Wed Jun 21 18:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA03715
	Wed, 21 Jun 2000 18:33:36 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA00666;
	Wed, 21 Jun 2000 15:41:12 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Jun 2000 14:42:43 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA29443
	for fwtk-users-outgoing; Wed, 21 Jun 2000 14:42:37 -0700 (PDT)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: TIS Mailing List <fwtk-users@ex.tis.com>
Date: Wed, 21 Jun 2000 15:41:31 -0600
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: smap exploit by ORBS
Message-ID: <3950E228.15282.6B0F00@localhost>
In-reply-to: <55B025.B66AF8CA@eic.at>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 762

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I've received the dreaded "xxx.xxx.xxx.xxx has been detected as an insecure 
email relay and added to the ORBS database" message from ORBS.  The specific 
exploit they found was in the form of:  

X-Envelope-Recipient: <orbs-relaytest%manawatu.co.nz@us.company.com  

where us.company.com is our real email server.  

My first question is this, will the Yao spam patches close this hole?  My 
second question is rather embarrassing.  Our regular C guy is out for awhile 
and I need to apply the Yao smap patches to the stock version 2.1 of smap.c 
but I don't know how.  Would someone please point me to the details?

TIA,
Ken Long


From owner-fwtk-users@ex.tis.com Wed Jun 21 19:13 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA03824
	Wed, 21 Jun 2000 19:13:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA01808;
	Wed, 21 Jun 2000 16:21:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Jun 2000 15:29:17 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA00175
	for fwtk-users-outgoing; Wed, 21 Jun 2000 15:29:06 -0700 (PDT)
Message-ID: <395141C7.F5308911@v-one.com>
Date: Wed, 21 Jun 2000 18:29:27 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.73 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Ken Long <ken@lectrosonics.com>
CC: TIS Mailing List <fwtk-users@ex.tis.com>
Subject: Re: smap exploit by ORBS
References: <3950E228.15282.6B0F00@localhost>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 589

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Ken Long wrote:
> 
>  Our regular C guy is out for awhile
> and I need to apply the Yao smap patches to the stock version 2.1 of smap.c
> but I don't know how.  Would someone please point me to the details?

Actually, Joe Yao also wrote a beginner's tutorial on how to install
patches for the FWTK. You can find it here:
	http://www.fwtk.org/fwtk/docs/documentation.html#3.3

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Wed Jun 21 20:02 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA03886
	Wed, 21 Jun 2000 20:02:14 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA03550;
	Wed, 21 Jun 2000 17:09:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Jun 2000 16:16:11 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA01585
	for fwtk-users-outgoing; Wed, 21 Jun 2000 16:16:05 -0700 (PDT)
From: Eberhard Mattes <mattes@azu.informatik.uni-stuttgart.de>
Date: Thu, 22 Jun 2000 01:15:45 +0200 (MET DST)
Message-Id: <200006212315.BAA28799@azu.informatik.uni-stuttgart.de>
CC: fwtk-users@ex.tis.com
In-reply-to: <Pine.GSO.4.10.10006211255340.18720-100000@ns1.bfg.com> (message
	from Ted Keller on Wed, 21 Jun 2000 13:02:30 -0400 (EDT))
Subject: Re: Opening a port
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 753

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> I've seen two types of applets that try to make connections.  Each
> requires a different solution.

There's a third type, those that work out of the box.  Unfortunately,
quite few applet developers are aware of

  http://developer.java.sun.com/developer/technicalArticles/InnerWorkings/Burrowing/index.html

(Here's the URL again, broken into two lines, in case long lines are
chopped:)

  http://developer.java.sun.com/developer/technicalArticles/InnerWorkings/
  Burrowing/index.html

Of course, that method can also be used by malicious Java applets...

-- 
  Eberhard Mattes <mattes@azu.informatik.uni-stuttgart.de>


From owner-fwtk-users@ex.tis.com Wed Jun 21 20:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA04004
	Wed, 21 Jun 2000 20:33:18 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA04531;
	Wed, 21 Jun 2000 17:40:55 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Jun 2000 16:57:15 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA02977
	for fwtk-users-outgoing; Wed, 21 Jun 2000 16:57:09 -0700 (PDT)
From: "Gopakumar H. Pillai" <gopu@global.com>
To: "Fwtk-Users" <fwtk-users@ex.tis.com>
Subject: inetd/http looping error
Date: Wed, 21 Jun 2000 16:55:02 -0700
Message-ID: <NEBBLAONMDHKADNMMDOHGEDMCBAA.gopu@global.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 595

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Error: inetd[93]: www/tcp server failing (looping), service terminated

 I am running FreeBSD 2.1 & 3.0. I get this error on both systems. After
looking at the manual pages I changed the inetd.conf to have the www service
as nowait/1024 (since I wasn't sure, I tried nowait/1024/1024 too). FreeBSD
claims that the default is 256 connections per minute. Still the error
happens. I am sure that our server does not get 1024 hits per minute.

Any other ideas?

--Gopu


From owner-fwtk-users@ex.tis.com Thu Jun 22 06:18 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA05519
	Thu, 22 Jun 2000 06:18:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA08294;
	Thu, 22 Jun 2000 03:25:11 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 02:27:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA07430
	for fwtk-users-outgoing; Thu, 22 Jun 2000 02:27:10 -0700 (PDT)
From: ark@eltex.ru
Date: Thu, 22 Jun 2000 13:22:50 +0400
Message-Id: <200006220922.NAA11671@paranoid.eltex.spb.ru>
In-Reply-To: <Pine.BSF.4.05.10006201951250.5197-100000@pochta.gvpl.victoria.bc.ca> from "Scott Campbell <scampbel@gvpl.victoria.bc.ca>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: Opening a port
To: scampbel@gvpl.victoria.bc.ca
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2435

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,


People who write java applets that require direct connection to server
and are not proxy-aware are complete assholes and i don't think it is
wise to use things they do ;)

There is workaround, though. Set up a transparent plug-gw on that port.
It is easy if you run ipfilter, don't know if "divert socket" solution
exists. But - better just don't.

Scott Campbell <scampbel@gvpl.victoria.bc.ca> said :

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
> We are running fwtk 2.1 on FreeBSD v3.x and everything is running fine.
> The users are using http-gw on port 8080 to the outside world and that is
> working great.  Now I have a site that my users want to attach to that
> requires port 5050 to be open (so says their tech staff) - how do I do
> that? The site
> 
> http://www.webpac.leg.bc.ca
> 
> runs a java applet that connects you to a server on port 5050.  It is NOT
> http://www.webpac.leg.bc.ca:5050. I don't get any usefull errors in the
> log from http-gw.  It works just fine if I put my machine outside the
> firewall.  Can I put a 5050 hole through the firewall? How?  I've tried a
> couple of plug-gw's but realized that wouldn't do any good since http-gw
> is handling the traffic (on port 8080). Anybody out there have a situation
> like this or can offer some useful suggestions.  I'm told a number of
> sites use this 5050 software.
> 
> Thank you in advance
> 
> Scott E. Campbell
> _______________________________
> Computer Operations
> Greater Victoria Public Library
> Victoria BC CANADA
> 
> (250)382-7241 x230
> scampbel@gvpl.victoria.bc.ca
> 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBOVHa5aH/mIJW9LeBAQH2ZAP+K5xmdV2dQbJtvvLHmjh5ibS1CzSIhTtI
jZxLRFoUCgnPbhGd8dPLLnZ3LJuvAebDXFcSRdbQcebw+YGJPlYGOupuZMSxVjgD
NL2BLhQ3QsqIfY3esLACFNRRpm0cCP4R5OF2qZTo8SsO/unJGxr1Ua2yNYeFs7n2
28LfitTJxAI=
=D9Gd
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Thu Jun 22 08:31 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA05867
	Thu, 22 Jun 2000 08:31:35 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA09934;
	Thu, 22 Jun 2000 05:38:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 04:51:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA09163
	for fwtk-users-outgoing; Thu, 22 Jun 2000 04:50:55 -0700 (PDT)
Message-ID: <916E692A468AD31190D000A02478AAB60D244C@ALDORNT>
From: Alexander Filatov <afilatov@aldor.cz>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: problem with active web pages
Date: Thu, 22 Jun 2000 13:28:02 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-2"
Content-Length: 590

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear fwtk-users,

I am sorry if my question will seem to you foolish, but I am novice in
firewalling.

I run fwtk 2.1 on Linux Red Hat (kernel 2.2.15). The only problem is that
users browsing WWW can not use active pages - web pages which require login
or have some kind of questionaries. Other web pages work fine (through
http-gw). I even do not know in part of my settings the problem may be
hidden.

I will be very grateful for any help.

Alexander Filatov

From owner-fwtk-users@ex.tis.com Thu Jun 22 15:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA07453
	Thu, 22 Jun 2000 15:33:24 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA14282;
	Thu, 22 Jun 2000 12:36:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 10:56:43 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA11907
	for fwtk-users-outgoing; Thu, 22 Jun 2000 10:56:37 -0700 (PDT)
Message-ID: <20000622175512.8569.qmail@web4104.mail.yahoo.com>
Date: Thu, 22 Jun 2000 10:55:12 -0700 (PDT)
From: J A Shamsi <jashamsi@yahoo.com>
Subject: fwtk  on freebsd 3.2
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 612

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello 
I am building tis fwtk on a freebsd machine 3.2
i am facing compilation errors.
If anyone of u have any idea please let me know that
what changes do I have to make in
Makefile.config file  
because there is no Makefile.config specifically  for
BSD but they have it for linux etc.
do I have to keep the 
default Makefile.config

Thanks

Jawwad

__________________________________________________
Do You Yahoo!?
Send instant messages with Yahoo! Messenger.
http://im.yahoo.com/

From owner-fwtk-users@ex.tis.com Thu Jun 22 15:34 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA07460
	Thu, 22 Jun 2000 15:34:36 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA14529;
	Thu, 22 Jun 2000 12:41:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 11:55:59 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA12604
	for fwtk-users-outgoing; Thu, 22 Jun 2000 11:55:34 -0700 (PDT)
Message-Id: <3.0.3.32.20000622094710.009bacc8@macallan.denver.gd-is.com>
X-Sender: dsmith@macallan.denver.gd-is.com
X-Mailer: QUALCOMM Windows Eudora Light Version 3.0.3 (32)
Date: Thu, 22 Jun 2000 09:47:10 -0500
To: Alexander Filatov <afilatov@aldor.cz>,
        "'fwtk-users@tis.com'" <fwtk-users@tis.com>
From: "donald.j.smith" <donald.j.smith@gd-is.com>
Subject: Re: problem with active web pages
In-Reply-To: <916E692A468AD31190D000A02478AAB60D244C@ALDORNT>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 1797

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 01:28 PM 6/22/00 +0200, Alexander Filatov wrote:
>[To be removed from this list send the message "unsubscribe fwtk-users" in
the
>BODY of a mail message to majordomo@ex.tis.com.]
>
>Dear fwtk-users,
>
>I am sorry if my question will seem to you foolish, but I am novice in
>firewalling.
>
>I run fwtk 2.1 on Linux Red Hat (kernel 2.2.15). The only problem is that
>users browsing WWW can not use active pages - web pages which require login
>or have some kind of questionaries. Other web pages work fine (through
>http-gw). I even do not know in part of my settings the problem may be
>hidden.
You need to get the users browsers to be setup for using the gateway for
security.
In netscape you configure the proxy for security point to the same gateway
your using for http
you can even use the same port or configure http-gw to use a different port
for https.
>
>I will be very grateful for any help.
>
>Alexander Filatov
>
------------------------------------------------------------------------------
Don Smith                               General Dynamics Information Systems
Systems Administrator                   8005 South Chester St
                                        EngleWood, Co. 80112
Phone (303) 649-7554
FAX   (303) 649-7504			donald.j.smith@gd-is.com
Error msgs that I love: 
"Keyboard not found press F1 to continue" (pc bios)
"Harddrive controller failure insert new disk and press any key to
continue" (pc bios)
"The disk is write protected Remove the write protect or
 use another disk." (nt)
User must change his password before he logs in the first time. (nt)
------------------------------------------------------------------------------

From owner-fwtk-users@ex.tis.com Thu Jun 22 15:34 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA07463
	Thu, 22 Jun 2000 15:34:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA14533;
	Thu, 22 Jun 2000 12:41:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 12:00:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA12707
	for fwtk-users-outgoing; Thu, 22 Jun 2000 11:59:37 -0700 (PDT)
Message-Id: <4.2.2.20000621135955.024d99d0@mail.scls.lib.wi.us>
X-Sender: gregb@mail.scls.lib.wi.us
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Wed, 21 Jun 2000 14:08:36 -0500
To: fwtk-users@ex.tis.com
From: Greg Barniskis <gregb@scls.lib.wi.us>
Subject: Re: Opening a port
Cc: Ted Keller <keller@bfg.com>, Scott Campbell <scampbel@gvpl.victoria.bc.ca>
In-Reply-To: <Pine.GSO.4.10.10006211255340.18720-100000@ns1.bfg.com>
References: <Pine.BSF.4.05.10006201951250.5197-100000@pochta.gvpl.victoria.bc.ca>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1850

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 12:02 PM 6/21/00 , Ted Keller wrote:
>The second are those that want to make a connection directly. (I hate this
>type).  There the applet contains the code to perform the connect to the
>site and manages its own protocol.  For these, it would appear that you
>need a route to the remote host through your firewall (kind of hard with
>application proxies), and rulesets which permit that raw tcp connections
>to be made.
>
>I think these are inherantly unsafe.  Your downloading an applet that you
>didn't write.  Permitting it to open an external connection, and do
>anything that it want's to to the client machine and any resources it can
>touch.  However, trusted partners are implementing these requirements.

Scott, Ted is correct here. The applet you are trying to enable (which from 
your cursory description smells a lot like Java WebPAC for Dynix library 
systems) requires raw TCP connectivity to the remote WebPAC server and 
cannot be handled by FWTK application proxies (unless you can get plug-gw 
to work, which I doubt).

Use ipfw, router ACLs, and/or some other packet filter mechanism to set 
this up. You'll have to trust the neighboring library system and the applet 
authors (epixtech, inc.) to play nice.

On the other hand, if you can stall long enough, the next generation Dynix 
WebPAC is supposed to drop the Java applet and handle everything with HTTP. 
Due out at year end?

--------------------------------------------------------
Greg Barniskis                      gregb@scls.lib.wi.us
Network Administrator                     (608) 266-6394
Library Interchange Network (LINK)         fax: 266-6068
South Central Library System (SCLS)          Madison, WI
<http://www.scls.lib.wi.us/>

From owner-fwtk-users@ex.tis.com Thu Jun 22 16:15 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA07630
	Thu, 22 Jun 2000 16:15:48 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA16082;
	Thu, 22 Jun 2000 13:23:10 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 12:30:52 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA13942
	for fwtk-users-outgoing; Thu, 22 Jun 2000 12:30:46 -0700 (PDT)
Message-ID: <20000622192919.15340.qmail@web4105.mail.yahoo.com>
Date: Thu, 22 Jun 2000 12:29:19 -0700 (PDT)
From: J A Shamsi <jashamsi@yahoo.com>
Subject: fwtk on BSD machine
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 544

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello 
I am building TIS fwtk on a BSD machine 
and facing compilation errors.

when I use 'make' it gives me some errors regarding
include directives.

when I use 'gmake' it gives me errors
that cannot find "libfwall.a"

do u have any idea about the problem

Thanks

Jawwad Shamsi

__________________________________________________
Do You Yahoo!?
Send instant messages with Yahoo! Messenger.
http://im.yahoo.com/

From owner-fwtk-users@ex.tis.com Thu Jun 22 19:40 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA08342
	Thu, 22 Jun 2000 19:40:18 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA19028;
	Thu, 22 Jun 2000 16:46:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 15:50:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA18219
	for fwtk-users-outgoing; Thu, 22 Jun 2000 15:50:16 -0700 (PDT)
Message-ID: <395291E9.7C3B5FA6@calpha.com>
Date: Thu, 22 Jun 2000 17:23:37 -0500
From: syntax <syntax@calpha.com>
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.0-RELEASE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: J A Shamsi <jashamsi@yahoo.com>
CC: fwtk-users@lists.nai.com
Subject: Re: fwtk  on freebsd 3.2
References: <20000622175512.8569.qmail@web4104.mail.yahoo.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1225

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

J A Shamsi wrote:
If you have the ports collection installed copy the 2 main 
gzipped files to /usr/ports/distfiles. Go to 
/usr/ports/security/fwtk and type make then make install.

To install any patches you want you can type make then 
make clean. Then modify the source then type make and 
make install.

If you don't have the ports collection installed then look
at fwtk-2.1 under:
http://www.freebsd.org/ports/security.html

Syntax 


> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello
> I am building tis fwtk on a freebsd machine 3.2
> i am facing compilation errors.
> If anyone of u have any idea please let me know that
> what changes do I have to make in
> Makefile.config file
> because there is no Makefile.config specifically  for
> BSD but they have it for linux etc.
> do I have to keep the
> default Makefile.config
> 
> Thanks
> 
> Jawwad
> 
> __________________________________________________
> Do You Yahoo!?
> Send instant messages with Yahoo! Messenger.
> http://im.yahoo.com/

From owner-fwtk-users@ex.tis.com Fri Jun 23 03:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id DAA09623
	Fri, 23 Jun 2000 03:36:24 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id AAA22107;
	Fri, 23 Jun 2000 00:42:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Jun 2000 23:51:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA21304
	for fwtk-users-outgoing; Thu, 22 Jun 2000 23:51:43 -0700 (PDT)
Message-Id: <200006230646.OAA14911@server.qdhaixin.com.cn>
X-Authentication-Warning: server.qdhaixin.com.cn: nobody set sender to <wen@hisense.qd.sd.cn> using -f
Date: Fri, 23 Jun 2000 14:43:17 +0800
From: wen <wen@hisense.qd.sd.cn>
Reply-To: wen@hisense.qd.sd.cn
To: "fwtk-users@lists.nai.com" <fwtk-users@lists.nai.com>
Subject: http-gw rules about limiting user in a period time
X-mailer: FoxMail 3.0 beta 2 [cn]
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="GB2312"
Content-Length: 414

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi,everyone:
	I want to permit a user  to use http-gw in the period of time.I have seen manual about http-gw and tryed to config it in netperm file.but rules that limiting user in the  period of time don't work.
	why? who have configed  http-gw about those rules?

thanks.
          


From owner-fwtk-users@ex.tis.com Fri Jun 23 10:11 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA11117
	Fri, 23 Jun 2000 10:11:57 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA24661;
	Fri, 23 Jun 2000 07:19:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Jun 2000 06:21:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA23809
	for fwtk-users-outgoing; Fri, 23 Jun 2000 06:21:09 -0700 (PDT)
Message-ID: <C2416AA8DBFED1119B9500805F657E040474FA6C@xchange02.fcd.esys.com>
From: "Unrath, Mark" <munrath@fallschurch.esys.com>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: Missing in.telnetd and in.ftpd
Date: Fri, 23 Jun 2000 09:17:11 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 398

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I'm running Mandrake 6.5 and noticed that I don't have a in.telnetd or
in.ftpd.  Is this normal?  I'm not very familiar with linux so please
forgive me if this is normal.  If not, how do I install or get theses
daemons?

Thanks for your help in the past,
Mark Unrath



From owner-fwtk-users@ex.tis.com Fri Jun 23 17:09 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA12506
	Fri, 23 Jun 2000 17:09:52 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA27833;
	Fri, 23 Jun 2000 14:17:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Jun 2000 12:52:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA26645
	for fwtk-users-outgoing; Fri, 23 Jun 2000 12:51:42 -0700 (PDT)
Message-Id: <4.2.2.20000623154615.00b2dc60@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Fri, 23 Jun 2000 15:47:31 -0400
To: "Unrath, Mark" <munrath@fallschurch.esys.com>,
        "'fwtk-users@tis.com'" <fwtk-users@tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Missing in.telnetd and in.ftpd
In-Reply-To: <C2416AA8DBFED1119B9500805F657E040474FA6C@xchange02.fcd.esy
 s.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 479

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:17 AM 6/23/00 -0400, Unrath, Mark wrote:
>I'm running Mandrake 6.5 and noticed that I don't have a in.telnetd or
>in.ftpd.  Is this normal?
Yup. For some systems (Suns, primarily, if I'm not mistaken) they're 
in.ftpd, not ftpd. Your Linux system probably uses telnetd and ftpd, etc. 
See your original inetd.conf for the path.
         -Rick


From owner-fwtk-users@ex.tis.com Sat Jun 24 10:00 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA14321
	Sat, 24 Jun 2000 10:00:01 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA02950;
	Sat, 24 Jun 2000 07:07:32 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 24 Jun 2000 06:03:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA02179
	for fwtk-users-outgoing; Sat, 24 Jun 2000 06:03:34 -0700 (PDT)
Message-ID: <51B208AA1634D411A46600400567B311246D@babylon5.pcsnc.lab>
From: Pascal Cimon <pcimon@pcsnc.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: ftp-gw does not list directories
Date: Sat, 24 Jun 2000 09:01:24 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id GAA02175
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 727

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello everyone,

I'm currently using fwtk 2.1 with all the patches I could find on
www.fwtk.org on a Redhat 6.0 firewall. The problem I'm having is when I ftp
to a site through ftp-gw and do the ls command only the files are listed but
not the directories. If I ftp from the firewall I get the directories so the
ftp client is okay. 

Here are the netperm-table lines I have for ftp-gw:

ftp-gw:     timeout 3600
ftp-gw:     permit-hosts 10.*

I only allow access to the gateway from inside basicaly.

Did anyone have this problem? Any help would be apreciated.

Thanks,

Pascal Cimon
Hull Québec 

From owner-fwtk-users@ex.tis.com Sun Jun 25 09:59 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA16576
	Sun, 25 Jun 2000 09:59:31 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08335;
	Sun, 25 Jun 2000 07:06:37 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 25 Jun 2000 05:41:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA07509
	for fwtk-users-outgoing; Sun, 25 Jun 2000 05:41:11 -0700 (PDT)
Date: Sun, 25 Jun 2000 08:40:09 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Pascal Cimon <pcimon@pcsnc.com>
cc: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: ftp-gw does not list directories
In-Reply-To: <51B208AA1634D411A46600400567B311246D@babylon5.pcsnc.lab>
Message-ID: <Pine.GSO.4.10.10006250836370.15669-100000@ns1.bfg.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from QUOTED-PRINTABLE to 8bit by relay2.nai.com id FAA07504
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=X-UNKNOWN
Content-Length: 1504

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Pascal,

I assume that the site you are going to is the wu-ftpd-2.6.0 site.  The
wu-ftpd organization has taken a stand on enforcing the rfc exactly -
which, when using the nlst command, lists only those files which can be
down-loaded.  Hence - directories - are not listed.

You will probably find some cients works while others fail.  I know that
any solaris ftp client is considered "broken".

Replace your ls comand with a dir command.  These normally execute a ls -l
(or equivalent) which then calls the operatings systems ls command.

ted keller


On Sat, 24 Jun 2000, Pascal Cimon wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello everyone,
> 
> I'm currently using fwtk 2.1 with all the patches I could find on
> www.fwtk.org on a Redhat 6.0 firewall. The problem I'm having is when I ftp
> to a site through ftp-gw and do the ls command only the files are listed but
> not the directories. If I ftp from the firewall I get the directories so the
> ftp client is okay. 
> 
> Here are the netperm-table lines I have for ftp-gw:
> 
> ftp-gw:     timeout 3600
> ftp-gw:     permit-hosts 10.*
> 
> I only allow access to the gateway from inside basicaly.
> 
> Did anyone have this problem? Any help would be apreciated.
> 
> Thanks,
> 
> Pascal Cimon
> Hull Québec 
> 


From owner-fwtk-users@ex.tis.com Sun Jun 25 12:07 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA16664
	Sun, 25 Jun 2000 12:07:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA09859;
	Sun, 25 Jun 2000 09:14:26 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 25 Jun 2000 08:17:17 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA09029
	for fwtk-users-outgoing; Sun, 25 Jun 2000 08:17:12 -0700 (PDT)
Message-ID: <51B208AA1634D411A46600400567B311246E@babylon5.pcsnc.lab>
From: Pascal Cimon <pcimon@pcsnc.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: ftp-gw does not list directories  
Date: Sun, 25 Jun 2000 11:16:08 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 173

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

The dir command works. 

Thanks Ted

Pascal

From owner-fwtk-users@ex.tis.com Sun Jun 25 13:15 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA16872
	Sun, 25 Jun 2000 13:15:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA11348;
	Sun, 25 Jun 2000 10:22:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 25 Jun 2000 09:30:23 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA10122
	for fwtk-users-outgoing; Sun, 25 Jun 2000 09:30:18 -0700 (PDT)
Message-Id: <Version.32.20000623115302.00e0d1e0@192.168.2.1>
X-Sender: neuro@it-world.nu@192.168.2.1 (Unverified)
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.0
Date: Sun, 25 Jun 2000 18:28:03 +0200
To: fwtk-users@lists.nai.com
From: Robban <neuro@it-world.nu>
Subject: FWTK, SOCKS5 and allow some incomming connections.
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 609

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all!
(I know you're thinking, ohhh noooo, not he again... ;p)
I'm running fwtk and socks5 on a Linux mashine (kernel 2.2.13).
I want friends on Internet access my ftp and web server, but
there's some of the components that doesn't like this idea at all...

I have a reason to belive that socks5 is the bad guy in this
chapter, but I'm not sure.
I installed socks5 and reconfigured the fwtk, sience that day
no one is allowing access...

Please help me...

//Robban










From owner-fwtk-users@ex.tis.com Sun Jun 25 14:00 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA16949
	Sun, 25 Jun 2000 14:00:55 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA12566;
	Sun, 25 Jun 2000 11:08:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 25 Jun 2000 10:21:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA11297
	for fwtk-users-outgoing; Sun, 25 Jun 2000 10:21:37 -0700 (PDT)
Date: Sun, 25 Jun 2000 13:20:36 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Robban <neuro@it-world.nu>
cc: fwtk-users@lists.nai.com
Subject: Re: FWTK, SOCKS5 and allow some incomming connections.
In-Reply-To: <Version.32.20000623115302.00e0d1e0@192.168.2.1>
Message-ID: <Pine.GSO.4.10.10006251318580.17031-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1222

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Robban,

You will have to give us some more hints....

How did your users contact your internal systems prior to these
implementations?

Did you have IP forwarding enabled before?

Are they using special clients?

Do they access it via your http-gw proxy?  (not very usefule).

What do you want them to be able to do?

What are they seeing now that you've reconfigured the system?

ted keller


On Sun, 25 Jun 2000, Robban wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello all!
> (I know you're thinking, ohhh noooo, not he again... ;p)
> I'm running fwtk and socks5 on a Linux mashine (kernel 2.2.13).
> I want friends on Internet access my ftp and web server, but
> there's some of the components that doesn't like this idea at all...
> 
> I have a reason to belive that socks5 is the bad guy in this
> chapter, but I'm not sure.
> I installed socks5 and reconfigured the fwtk, sience that day
> no one is allowing access...
> 
> Please help me...
> 
> //Robban
> 
> 
> 
> 
> 
> 
> 
> 
> 


From owner-fwtk-users@ex.tis.com Mon Jun 26 10:45 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA20189
	Mon, 26 Jun 2000 10:45:38 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA19134;
	Mon, 26 Jun 2000 07:53:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 06:50:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA17279
	for fwtk-users-outgoing; Mon, 26 Jun 2000 06:50:51 -0700 (PDT)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: TIS Mailing List <fwtk-users@ex.tis.com>
Date: Mon, 26 Jun 2000 07:50:28 -0600
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Re: smap exploit by ORBS
Message-ID: <39570B41.5139.392F39@localhost>
In-reply-to: <3950E228.15282.6B0F00@localhost>
References: <55B025.B66AF8CA@eic.at>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 1011

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

The stock 2.1 smap with the Yao patches did the trick here.  Orbs re-scanned 
me last Friday and all of their attempts to bounce email off my server were 
rejected.

Ken Long

On 21 Jun 2000, at 15:41, Ken Long wrote:

> I've received the dreaded "xxx.xxx.xxx.xxx has been detected as an insecure 
> email relay and added to the ORBS database" message from ORBS.  The specific 
> exploit they found was in the form of:  
> 
> X-Envelope-Recipient: <orbs-relaytest%manawatu.co.nz@us.company.com  
> 
> where us.company.com is our real email server.  
> 
> My first question is this, will the Yao spam patches close this hole?  My 
> second question is rather embarrassing.  Our regular C guy is out for awhile 
> and I need to apply the Yao smap patches to the stock version 2.1 of smap.c 
> but I don't know how.  Would someone please point me to the details?
> 
> TIA,
> Ken Long


From owner-fwtk-users@ex.tis.com Mon Jun 26 10:45 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA20193
	Mon, 26 Jun 2000 10:45:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA19138;
	Mon, 26 Jun 2000 07:53:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 06:54:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA17379
	for fwtk-users-outgoing; Mon, 26 Jun 2000 06:54:20 -0700 (PDT)
From: "Gordon Knutas" <gordon.knutas@posten.se>
To: <fwtk-users@lists.nai.com>
Subject: max line exceed
Date: Mon, 26 Jun 2000 15:53:34 +0200
Message-ID: <003301bfdf75$ec9e0590$e3510e93@8930cbq50519.postcom.posten.se>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0034_01BFDF86.B026D590"
Content-Length: 5049

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_0034_01BFDF86.B026D590
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

Is there a "max line"  in fwtk or can a table grow to be as big as >480 ?
I have a netperm-table that concists 480 lines and whenever i try to add a
new ftp-gw entry in the bottom of the table it doesnt work.
I get a message like the rule doesnt exist:501 Not permitted to connect to
host. Login failed.
But when i yank the entry and put it in the middle or the beginning of the
table it works just fine and i get a connection.
The hosts that im trying to add are not already in the table. They are both
new entries.
I run SunOS 5.5.1 Generic_103640-29 sun4u sparc SUNW,Ultra-1 whith fwtk
V2.1.

Please answer if you know anything about this.

==================================
-  Gordon Knutas           Unix sysadmin
-  PostCom                   Internet&Security
-  Olof Palmes gata 29   10500 Stockholm
-  +46 8 7812653
-  gordon.knutas@posten.se
===================================



------=_NextPart_000_0034_01BFDF86.B026D590
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">



<META content=3D'"MSHTML 4.72.3110.7"' name=3DGENERATOR>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =
size=3D2>Is=20
there a &quot;max line&quot;&nbsp; in fwtk or can a table grow to be as =
big as=20
&gt;480 ?</FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =

size=3D2></FONT></SPAN><SPAN class=3D404053513-26062000><FONT =
color=3D#000000=20
face=3DArial size=3D2>I have a netperm-table that concists 480 lines and =
whenever i=20
try to add a new ftp-gw entry in the bottom of the table it doesnt work. =

</FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =
size=3D2>I get=20
a message like the rule doesnt exist:501 Not permitted to connect to =
host. Login=20
failed.</FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =

size=3D2></FONT></SPAN><SPAN class=3D404053513-26062000><FONT =
color=3D#000000=20
face=3DArial size=3D2>But when i yank the entry and put it in the middle =
or the=20
beginning of the table it works just fine and i get a=20
connection.</FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =
size=3D2>The=20
hosts that im trying to add are not already in the table. They are both =
new=20
entries.&nbsp; </FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =
size=3D2>I run=20
SunOS 5.5.1 Generic_103640-29 sun4u sparc SUNW,Ultra-1 whith fwtk=20
V2.1.</FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =
size=3D2>Please=20
answer if you know anything about this.</FONT></SPAN></DIV>
<DIV><SPAN class=3D404053513-26062000><FONT color=3D#000000 face=3DArial =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<P><FONT face=3DArial size=3D2><FONT face=3DArial=20
size=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<BR>-&nbsp; Gordon=20
Knutas&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<SPAN=20
class=3D942222312-20062000><FONT color=3D#000000 face=3DArial =
size=3D2>&nbsp;&nbsp;=20
</FONT></SPAN><SPAN class=3D942222312-20062000><FONT color=3D#000000 =
face=3DArial=20
size=3D2>Unix sysadmin</FONT></SPAN></FONT><BR><FONT face=3DArial =
size=3D2>-&nbsp;=20
PostCom<SPAN class=3D942222312-20062000><FONT color=3D#000000 =
face=3DArial=20
size=3D2>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
</FONT></SPAN></FONT><FONT face=3DArial size=3D2>Internet&amp;S<SPAN=20
class=3D942222312-20062000><FONT color=3D#000000 face=3DArial=20
size=3D2>ecurity</FONT></SPAN></FONT><BR><FONT face=3DArial =
size=3D2>-&nbsp; Olof=20
Palmes gata 29<SPAN class=3D942222312-20062000><FONT color=3D#000000 =
face=3DArial=20
size=3D2>&nbsp;&nbsp; </FONT></SPAN></FONT><FONT face=3DArial =
size=3D2>10500=20
Stockholm</FONT><BR><FONT face=3DArial size=3D2><FONT face=3D"Times New =
Roman"=20
size=3D3>-&nbsp; </FONT>+46 8 =
7812653&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
</FONT><BR>-&nbsp; <FONT face=3DArial size=3D2><A=20
href=3D"mailto:gordon.knutas@posten.se">gordon.knutas@posten.se</A><BR>=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D&nbsp;</FONT>=20
</FONT></P>
<DIV>&nbsp;</DIV></BODY></HTML>

------=_NextPart_000_0034_01BFDF86.B026D590--


From owner-fwtk-users@ex.tis.com Mon Jun 26 10:45 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA20192
	Mon, 26 Jun 2000 10:45:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA19142;
	Mon, 26 Jun 2000 07:53:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 06:31:36 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA17067
	for fwtk-users-outgoing; Mon, 26 Jun 2000 06:31:30 -0700 (PDT)
Message-ID: <916E692A468AD31190D000A02478AAB60D245A@ALDORNT>
From: Alexander Filatov <afilatov@aldor.cz>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: RE: problem with active web pages
Date: Mon, 26 Jun 2000 15:29:22 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="ISO-8859-2"
Content-Length: 1175

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello dear fwtk-users,

My problem was solved by applying the patch by Tony Gale for cgi scripts on
Netscape, though my users used not Netscape but IE 5 and 4. So it is
definetly not only Netscape problem but the patch fixes it.

I highly appreciate everybody's help

Alex

-----Original Message-----
From: Alexander Filatov [mailto:afilatov@aldor.cz]
Sent: Thursday, June 22, 2000 1:28 PM
To: 'fwtk-users@tis.com'
Subject: problem with active web pages


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

Dear fwtk-users,

I am sorry if my question will seem to you foolish, but I am novice in
firewalling.

I run fwtk 2.1 on Linux Red Hat (kernel 2.2.15). The only problem is that
users browsing WWW can not use active pages - web pages which require login
or have some kind of questionaries. Other web pages work fine (through
http-gw). I even do not know in part of my settings the problem may be
hidden.

I will be very grateful for any help.

Alexander Filatov

From owner-fwtk-users@ex.tis.com Mon Jun 26 15:32 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA21254
	Mon, 26 Jun 2000 15:32:27 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA22809;
	Mon, 26 Jun 2000 12:40:12 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 11:43:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA22011
	for fwtk-users-outgoing; Mon, 26 Jun 2000 11:42:49 -0700 (PDT)
X-Version: ireland 6.2.3.2329.0
From: "David Furlong" <def345@ireland.com>
Message-Id: <0DB5B6B5D4B44D115AC40005B8ACC251@def345.ireland.com>
Date: Mon, 26 Jun 2000 17:56:07 +0100
X-Priority: Normal
To: fwtk-users@tis.com
Subject: VPN Query
X-Mailer: Web Based Pronto
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 644

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I am new to firewall administration, and currently I run fwtk on 
solaris 2.6

I have been asked to implement a VPN on the network, for a travelling 
salesman to access a client database (which needs to be accessed by 
users in the office)

I have looked into doing this for another firewall before, and you 
could just purchase add-on's, but I am wondering what is the best way 
to implement this kind of VPN,

Regards

Dave.

_____________________________________

Get your free E-mail at http://www.ireland.com


From owner-fwtk-users@ex.tis.com Mon Jun 26 16:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA21494
	Mon, 26 Jun 2000 16:24:54 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA25014;
	Mon, 26 Jun 2000 13:32:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 12:46:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA22902
	for fwtk-users-outgoing; Mon, 26 Jun 2000 12:45:55 -0700 (PDT)
Message-ID: <3957B2E2.4FA3E4C3@bath.tmac.com>
Date: Mon, 26 Jun 2000 15:45:38 -0400
From: Steve Sandau <ssandau@bath.tmac.com>
Organization: TMA Bath
X-Mailer: Mozilla 4.51 [en] (X11; I; Linux 2.2.6 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: David Furlong <def345@ireland.com>
CC: fwtk-users@tis.com
Subject: Re: VPN Query
References: <0DB5B6B5D4B44D115AC40005B8ACC251@def345.ireland.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1810

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I don't know that it's the *best* way, but I have just recently
installed PoPToP for linux on the same machine that use for fwtk. I
decided on that rather than passing the PPTP *through* the firewall to
an internal machine. It seemed safer to me to have only one box
accessible from the internet. I have a DMZ with a web server, but the
prospect of filtering through the firewall twice discouraged me from
thinking about putting the VPN box on the DMZ segment too seriously.

I have not yet tested the final configuration of ipchains that is needed
in order to allow the PPTP software to be accessed from the Inernet, but
I do have PoPToP installed, compiled, and working (tunneling IPX even!).
The firewall was previously doing NO forwarding, (forwarding was turned
off in the kernel) just proxying simple stuff.

You might write me directly if you'd like the details that may not be
list-appropriate.


David Furlong wrote:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I am new to firewall administration, and currently I run fwtk on
> solaris 2.6
> 
> I have been asked to implement a VPN on the network, for a travelling
> salesman to access a client database (which needs to be accessed by
> users in the office)
> 
> I have looked into doing this for another firewall before, and you
> could just purchase add-on's, but I am wondering what is the best way
> to implement this kind of VPN,
> 
> Regards
> 
> Dave.
> 
> _____________________________________
> 
> Get your free E-mail at http://www.ireland.com

-- 
Steve Sandau
IS Technician, TMA, Bath, Maine
ssandau@bath.tmac.com

From owner-fwtk-users@ex.tis.com Mon Jun 26 16:38 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA21547
	Mon, 26 Jun 2000 16:38:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA25866;
	Mon, 26 Jun 2000 13:45:55 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 12:56:27 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA23219
	for fwtk-users-outgoing; Mon, 26 Jun 2000 12:56:21 -0700 (PDT)
Message-ID: <20000626195521.10784.qmail@web4103.mail.yahoo.com>
Date: Mon, 26 Jun 2000 12:55:21 -0700 (PDT)
From: J A Shamsi <jashamsi@yahoo.com>
Subject: ftp-gw and http-gw
To: fwtk-users@ex.tis.com, fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1041

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello

I am configuring tis fwtk 2.1
I want to run http-gw:
just wondering what port should I use in the services
file and what entry do I have make in the inetd file.

If I use http-gw: proxy on port 80, then
can I use apache web server.
if anyone can tell me what sample changes do I have 
to make for http-gw 
in /etc/services
/etc/inetd and 
netperm-table
files 

I am also working on  ftp-gw: I want anyone from
inside my network to be able to 
connect to the firewall ftp proxy.

I have the following entry for ftp proxy

netacl-in.ftpd: permit-hosts *.MYDOMAIN  -exec
/usr/local/libexec/ftp-gw
ftp-gw:  timeout  3600
ftp-gw:  permit-hosts *.MYDOMAIN

but even then my users are getting a prompt for 
username and passwd.

any idea or help...

thanks

JAS


__________________________________________________
Do You Yahoo!?
Get Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Mon Jun 26 16:38 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA21546
	Mon, 26 Jun 2000 16:38:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA25854;
	Mon, 26 Jun 2000 13:45:52 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 12:56:18 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA23197
	for fwtk-users-outgoing; Mon, 26 Jun 2000 12:56:12 -0700 (PDT)
Message-ID: <20000626195521.10784.qmail@web4103.mail.yahoo.com>
Date: Mon, 26 Jun 2000 12:55:21 -0700 (PDT)
From: J A Shamsi <jashamsi@yahoo.com>
Subject: ftp-gw and http-gw
To: fwtk-users@ex.tis.com, fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1041

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello

I am configuring tis fwtk 2.1
I want to run http-gw:
just wondering what port should I use in the services
file and what entry do I have make in the inetd file.

If I use http-gw: proxy on port 80, then
can I use apache web server.
if anyone can tell me what sample changes do I have 
to make for http-gw 
in /etc/services
/etc/inetd and 
netperm-table
files 

I am also working on  ftp-gw: I want anyone from
inside my network to be able to 
connect to the firewall ftp proxy.

I have the following entry for ftp proxy

netacl-in.ftpd: permit-hosts *.MYDOMAIN  -exec
/usr/local/libexec/ftp-gw
ftp-gw:  timeout  3600
ftp-gw:  permit-hosts *.MYDOMAIN

but even then my users are getting a prompt for 
username and passwd.

any idea or help...

thanks

JAS


__________________________________________________
Do You Yahoo!?
Get Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Mon Jun 26 17:09 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA21638
	Mon, 26 Jun 2000 17:09:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA27422;
	Mon, 26 Jun 2000 14:16:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 13:31:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA24930
	for fwtk-users-outgoing; Mon, 26 Jun 2000 13:31:20 -0700 (PDT)
Message-Id: <4.2.0.58.20000530203808.00aa7430@pop.fnac.net>
X-Sender: f088634_5_fnac@pop.fnac.net
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.0.58
Date: Mon, 26 Jun 2000 22:20:47 +0200
To: fwtk-users@ex.tis.com
From: Yomler <yomler.fwtk@fnac.net>
Subject: How to block httptunnel  ?
In-Reply-To: <200005242013.WAA00664@azu.informatik.uni-stuttgart.de>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 413

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I am not a security expert, but I am trying to to my best.

I have recently found this link :
http://www.nocrew.org/software/httptunnel.html

I'd like to know, if http-gw is able to block this kind of tunnel ?
Is squid better ?
or squid-gw + squid ?

Please advice ?

--
Yomler.

From owner-fwtk-users@ex.tis.com Mon Jun 26 22:30 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA22469
	Mon, 26 Jun 2000 22:30:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA01934;
	Mon, 26 Jun 2000 19:37:55 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Jun 2000 18:44:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA01114
	for fwtk-users-outgoing; Mon, 26 Jun 2000 18:44:52 -0700 (PDT)
Message-Id: <200006270138.JAA02343@server.qdhaixin.com.cn>
X-Authentication-Warning: server.qdhaixin.com.cn: nobody set sender to <wen@hisense.qd.sd.cn> using -f
Date: Tue, 27 Jun 2000 9:43:19 +0800
From: wen <wen@hisense.qd.sd.cn>
Reply-To: wen@hisense.qd.sd.cn
To: "fwtk-users@ex.tis.com" <fwtk-users@ex.tis.com>
Subject: http-gw rules about limiting user in a period time
X-mailer: FoxMail 3.0 beta 2 [cn]
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="GB2312"
Content-Length: 414

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi,everyone:
	I want to permit a user  to use http-gw in the period of time.I have seen manual about http-gw and tryed to config it in netperm file.but rules that limiting user in the  period of time don't work.
	why? who have configed  http-gw about those rules?

thanks.
          


From owner-fwtk-users@ex.tis.com Tue Jun 27 08:35 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA24571
	Tue, 27 Jun 2000 08:35:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA05679;
	Tue, 27 Jun 2000 05:43:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Jun 2000 04:55:31 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA04445
	for fwtk-users-outgoing; Tue, 27 Jun 2000 04:55:25 -0700 (PDT)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3958649A.2989B34@usrconsult.be>
Date: Tue, 27 Jun 2000 10:23:54 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: UsrConsult SPRL
X-Mailer: Mozilla 4.5 [en] (X11; I; IRIX64 6.5 IP27)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Re: VPN Query
References: <0DB5B6B5D4B44D115AC40005B8ACC251@def345.ireland.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1207

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

David Furlong wrote:
 > 
 > I have been asked to implement a VPN on the network, for a travelling
 > salesman to access a client database (which needs to be accessed by
 > users in the office)

I assume the database is on your internal net? 

 > 
 > I have looked into doing this for another firewall before, and you
 > could just purchase add-on's, but I am wondering what is the best way
 > to implement this kind of VPN,
 > 
 > Regards
 > 
 > Dave.

Do you really need a full VPN? If secured access from outside to a *specific*
inside port is enough, SSH would be a solution. However, *any* tunnelling through
the FW is a security risk, to be balanced against the security risk of putting
the DB in question in the DMZ rather than the internal net. So, the questions
are: how secure is the salesman's laptop? (In other words, how difficult would
it be to steal the SSH private key?) And, how sensitive is the DB? 

Greetings.
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10
Standard disclaimers.


From owner-fwtk-users@ex.tis.com Tue Jun 27 08:35 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA24575
	Tue, 27 Jun 2000 08:35:58 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA05683;
	Tue, 27 Jun 2000 05:43:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Jun 2000 04:47:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA04321
	for fwtk-users-outgoing; Tue, 27 Jun 2000 04:47:26 -0700 (PDT)
Message-ID: <20000627064749.14137.qmail@web210.mail.yahoo.com>
Date: Mon, 26 Jun 2000 23:47:49 -0700 (PDT)
From: Duardo Montelbarne <mr_duardo@yahoo.com>
Subject: Multiple http-gw daemons with diff policies ???
To: fwtk-users@ex.tis.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 597

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Greetz,

Need to run multiple instances of http-gw (bound to 
different TCP ports) that each have their own set
of rules defined in netperm-table (much the same way
as can be achieved with Gauntlet and the -as switch).

Is this possible in FWTK???

Or am I stuck with one instance and a messy
netperm-table???

./edy


__________________________________________________
Do You Yahoo!?
Get Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/


From owner-fwtk-users@ex.tis.com Tue Jun 27 12:11 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA25480
	Tue, 27 Jun 2000 12:11:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA08377;
	Tue, 27 Jun 2000 09:19:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Jun 2000 08:03:11 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA07399
	for fwtk-users-outgoing; Tue, 27 Jun 2000 08:03:00 -0700 (PDT)
Date: Tue, 27 Jun 2000 10:00:35 -0500 (CDT)
From: Superuser <dwoody1@startext.net>
To: fwtk@star1.home.com
Subject: compiling fwtk on SCO Unix 5.0.5
Message-ID: <Pine.SC5.4.02.10006270954400.15309-100000@star1.home.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 469

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

When compiling fwtk I get the following error. My OS is SCO Unix 5.0.5.

	/udk/usr/ccs/bin/cc -b elf -o authmgr authmgr.o ../libauth.a ../libfwall.a  -lsocket
UX:ld: ERROR: /usr/share/lib/libsocket.so: fatal error: cannot link OpenServer object into Intel iABI target
*** Error code 1 (bu21)

Any help will be greatly appreciated,


david


From owner-fwtk-users@ex.tis.com Tue Jun 27 12:47 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA25612
	Tue, 27 Jun 2000 12:47:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA09413;
	Tue, 27 Jun 2000 09:55:13 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Jun 2000 09:11:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA08162
	for fwtk-users-outgoing; Tue, 27 Jun 2000 09:11:40 -0700 (PDT)
From: "Michael Levy" <ml@mail.nh.ca>
To: <fwtk-users@lists.nai.com>
Subject: http-gw and tag processing
Date: Tue, 27 Jun 2000 09:11:08 -0700
Message-ID: <ADENLOODACBGEDNCNKAOKEMFCAAA.ml@nh.ca>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 579

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


I am new to this list, so my apologies if I am covering old ground.
We discovered that http-gw is truncating value="...." fields in
html files when sending them to us. Looking at the code, I see
that it doesn't allow quoted values to be longer than 1026 bytes.
Is there some sound reason for this restriction? Or is it simply
a case of no one thinking a quoted value would ever be longer than
this value?

...Michael Levy
VPR&D NewHeights Software


From owner-fwtk-users@ex.tis.com Tue Jun 27 13:49 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA25876
	Tue, 27 Jun 2000 13:49:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA11309;
	Tue, 27 Jun 2000 10:56:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Jun 2000 10:11:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA09750
	for fwtk-users-outgoing; Tue, 27 Jun 2000 10:11:36 -0700 (PDT)
Message-ID: <20000627161836.66251.qmail@hotmail.com>
X-Originating-IP: [204.94.209.1]
From: "Naresh Narang" <nknarang@hotmail.com>
To: wen@hisense.qd.sd.cn
Cc: fwtk-users@ex.tis.com
Subject: Re: http-gw rules about limiting user in a period time
Date: Tue, 27 Jun 2000 21:48:36 IST
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; format=flowed
Content-Length: 801

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Wen,

      I have not found any option in http-gw where you can limit users by 
what time they are permitted. So, I use Squid for who, at what time of the 
day, what day of the week they are permitted.

Regards,
Naresh Narang

 >
 >hi,everyone:
 >	I want to permit a user  to use http-gw in the period of time.I have seen 
 >manual about http-gw and tryed to config it in netperm file.but rules that 
 >limiting user in the  period of time don't work.
 >	why? who have configed  http-gw about those rules?
 >
 >thanks.
 >

________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com



From owner-fwtk-users@ex.tis.com Wed Jun 28 08:58 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA29154
	Wed, 28 Jun 2000 08:58:11 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18191;
	Wed, 28 Jun 2000 06:04:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Jun 2000 04:59:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA17373
	for fwtk-users-outgoing; Wed, 28 Jun 2000 04:59:27 -0700 (PDT)
From: Matthew Barnson <barnboy@imall.com>
To: Michel Bardiaux <mbardiaux@peaktime.be>, fwtk-users@tis.com
Subject: Re: VPN Query
Date: Wed, 28 Jun 2000 00:29:53 -0600
X-Mailer: KMail [version 1.0.28]
References: <0DB5B6B5D4B44D115AC40005B8ACC251@def345.ireland.com> <3958649A.2989B34@usrconsult.be>
In-Reply-To: <3958649A.2989B34@usrconsult.be>
MIME-Version: 1.0
Message-Id: <00062800320501.09921@jarjar.imall.com>
Content-Transfer-Encoding: 8bit
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 799

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

We have two setups that run in parallel at our work: Ravlin VPN software and
hardware operating in parallel with our firewall, and a dedicated "ssh
tunneling" host set up *behind* the firewall, with a plug-gw rule shunting
outside SSH traffic into this dedicated, extremely locked-down host.  That
way you avoid adding users to the firewall per se.  However, there is some
weirdness with identd we still haven't worked out...

-- 

Matthew P. Barnson 	     mbarnson@excitehome.net	
Mgr,Systems Administration   Excite Business Applications

-
If some day we are defeated, well, war has its fortunes, good and bad.
		-- Commander Kor, "Errand of Mercy", stardate 3201.7


From owner-fwtk-users@ex.tis.com Thu Jun 29 12:13 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA04653
	Thu, 29 Jun 2000 12:13:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA27889;
	Thu, 29 Jun 2000 09:21:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 07:47:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA25935
	for fwtk-users-outgoing; Thu, 29 Jun 2000 07:47:15 -0700 (PDT)
Message-ID: <20000629144249.27763.qmail@web4105.mail.yahoo.com>
Date: Thu, 29 Jun 2000 07:42:49 -0700 (PDT)
From: J A Shamsi <jashamsi@yahoo.com>
Subject: http proxy
To: fwtk-users@ex.tis.com, fwtk-users@lists.nai.com, questions@freebsd.org
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 852

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello

I am configuring TIS FWTK on free BSD machine.
I have a http proxy running.
My users can access the outside internet 
through http-gw proxy.
but they are facing problems in accessing certain
sites.
e.g.
when accessing hotmail.com, they can go to hotmail.com
but when they types their username and passwd
they cannot  proceed further, similarly there is no
problem with the yahoo mail when using standard
feature but problem is still there when using secure
feature.
looks like there is some security feature missing,
anyone has any idea problem.....

Thanks

jawwad


__________________________________________________
Do You Yahoo!?
Get Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Thu Jun 29 12:13 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA04654
	Thu, 29 Jun 2000 12:13:23 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA27893;
	Thu, 29 Jun 2000 09:21:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 07:47:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA25928
	for fwtk-users-outgoing; Thu, 29 Jun 2000 07:47:11 -0700 (PDT)
Message-ID: <20000629144249.27763.qmail@web4105.mail.yahoo.com>
Date: Thu, 29 Jun 2000 07:42:49 -0700 (PDT)
From: J A Shamsi <jashamsi@yahoo.com>
Subject: http proxy
To: fwtk-users@ex.tis.com, fwtk-users@lists.nai.com, questions@freebsd.org
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 852

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello

I am configuring TIS FWTK on free BSD machine.
I have a http proxy running.
My users can access the outside internet 
through http-gw proxy.
but they are facing problems in accessing certain
sites.
e.g.
when accessing hotmail.com, they can go to hotmail.com
but when they types their username and passwd
they cannot  proceed further, similarly there is no
problem with the yahoo mail when using standard
feature but problem is still there when using secure
feature.
looks like there is some security feature missing,
anyone has any idea problem.....

Thanks

jawwad


__________________________________________________
Do You Yahoo!?
Get Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Thu Jun 29 12:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA04963
	Thu, 29 Jun 2000 12:55:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA29733;
	Thu, 29 Jun 2000 10:02:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 09:10:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA27468
	for fwtk-users-outgoing; Thu, 29 Jun 2000 09:10:00 -0700 (PDT)
From: "TJ O Connor" <toconnor@comnitel.com>
To: <fwtk-users@ex.tis.com>, <fwtk-users@lists.nai.com>,
        <questions@freebsd.org>
Subject: Configuring the authsrv
Date: Thu, 29 Jun 2000 17:08:27 +0100
Message-ID: <NEBBINOGOEDMFIMMJPJMKEKGCAAA.toconnor@comnitel.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1982

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi
I'm just after downloading the TIS FWTK and im trying to configure it.
I've run my 'make' and 'make install' but when i come to initializing the
database and running './authsrv', I can't find it. I don't know what to do
to get it.


When i run a make in the auth directory this is what happens

cc -g -o authsrv authsrv.o proto.o db.o pass.o srvio.o     ../libauth.a
../libfwall.a
db.o: In function `auth_dbopen':
/usr/local/src/fwtk/auth/db.c:66: undefined reference to `dbm_open'
db.o: In function `auth_dbclose':
/usr/local/src/fwtk/auth/db.c:83: undefined reference to `dbm_close'
db.o: In function `auth_dbgetu':
/usr/local/src/fwtk/auth/db.c:123: undefined reference to `dbm_fetch'
db.o: In function `auth_dbputu':
/usr/local/src/fwtk/auth/db.c:152: undefined reference to `dbm_store'
db.o: In function `auth_dbdelu':
/usr/local/src/fwtk/auth/db.c:176: undefined reference to `dbm_delete'
db.o: In function `auth_dbtraversestart':
/usr/local/src/fwtk/auth/db.c:196: undefined reference to `dbm_firstkey'
/usr/local/src/fwtk/auth/db.c:200: undefined reference to `dbm_fetch'
db.o: In function `auth_dbtraversenext':
/usr/local/src/fwtk/auth/db.c:225: undefined reference to `dbm_nextkey'
/usr/local/src/fwtk/auth/db.c:229: undefined reference to `dbm_fetch'
pass.o: In function `passverify':
/usr/local/src/fwtk/auth/pass.c:39: undefined reference to `crypt'
pass.o: In function `passset':
/usr/local/src/fwtk/auth/pass.c:70: undefined reference to `crypt'
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

If anyone knows anything about this it would be very helpful.

- --                      _
T.J.O'Connor            _/ \_   2200 Cork Airport Business Park,
SysAdmin               / \_/ \  Kinsale Rd., Cork, Ireland.
Comnitel Technologies  \_/ \_/  Ph: +353 21 7305620
toconnor@comnitel.com    \_/    Fax: +353 21 7305624


From owner-fwtk-users@ex.tis.com Thu Jun 29 12:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA04968
	Thu, 29 Jun 2000 12:55:47 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA29729;
	Thu, 29 Jun 2000 10:02:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 09:10:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA27461
	for fwtk-users-outgoing; Thu, 29 Jun 2000 09:09:52 -0700 (PDT)
From: "TJ O Connor" <toconnor@comnitel.com>
To: <fwtk-users@ex.tis.com>, <fwtk-users@lists.nai.com>,
        <questions@freebsd.org>
Subject: Configuring the authsrv
Date: Thu, 29 Jun 2000 17:08:27 +0100
Message-ID: <NEBBINOGOEDMFIMMJPJMKEKGCAAA.toconnor@comnitel.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1982

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi
I'm just after downloading the TIS FWTK and im trying to configure it.
I've run my 'make' and 'make install' but when i come to initializing the
database and running './authsrv', I can't find it. I don't know what to do
to get it.


When i run a make in the auth directory this is what happens

cc -g -o authsrv authsrv.o proto.o db.o pass.o srvio.o     ../libauth.a
../libfwall.a
db.o: In function `auth_dbopen':
/usr/local/src/fwtk/auth/db.c:66: undefined reference to `dbm_open'
db.o: In function `auth_dbclose':
/usr/local/src/fwtk/auth/db.c:83: undefined reference to `dbm_close'
db.o: In function `auth_dbgetu':
/usr/local/src/fwtk/auth/db.c:123: undefined reference to `dbm_fetch'
db.o: In function `auth_dbputu':
/usr/local/src/fwtk/auth/db.c:152: undefined reference to `dbm_store'
db.o: In function `auth_dbdelu':
/usr/local/src/fwtk/auth/db.c:176: undefined reference to `dbm_delete'
db.o: In function `auth_dbtraversestart':
/usr/local/src/fwtk/auth/db.c:196: undefined reference to `dbm_firstkey'
/usr/local/src/fwtk/auth/db.c:200: undefined reference to `dbm_fetch'
db.o: In function `auth_dbtraversenext':
/usr/local/src/fwtk/auth/db.c:225: undefined reference to `dbm_nextkey'
/usr/local/src/fwtk/auth/db.c:229: undefined reference to `dbm_fetch'
pass.o: In function `passverify':
/usr/local/src/fwtk/auth/pass.c:39: undefined reference to `crypt'
pass.o: In function `passset':
/usr/local/src/fwtk/auth/pass.c:70: undefined reference to `crypt'
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

If anyone knows anything about this it would be very helpful.

- --                      _
T.J.O'Connor            _/ \_   2200 Cork Airport Business Park,
SysAdmin               / \_/ \  Kinsale Rd., Cork, Ireland.
Comnitel Technologies  \_/ \_/  Ph: +353 21 7305620
toconnor@comnitel.com    \_/    Fax: +353 21 7305624


From owner-fwtk-users@ex.tis.com Thu Jun 29 17:11 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA05671
	Thu, 29 Jun 2000 17:10:59 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA04338;
	Thu, 29 Jun 2000 14:18:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 13:20:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA03293
	for fwtk-users-outgoing; Thu, 29 Jun 2000 13:20:39 -0700 (PDT)
Date: Thu, 29 Jun 2000 15:09:04 -0500
Message-Id: <200006291509.AA828113062@mail.centraltx.com>
Mime-Version: 1.0
From: "marc " <marc@centraltx.com>
Reply-To: <marc@centraltx.com>
X-Sender: <marc@mail.centraltx.com>
To: <fwtk-users@ex.tis.com>
Subject: socks
X-Mailer: <IMail v6.00>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 230

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

How can I make fwtk compatiable with programs who have the only
firewall option as SOCKS4/5.

-Marc


From owner-fwtk-users@ex.tis.com Thu Jun 29 17:48 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA05829
	Thu, 29 Jun 2000 17:48:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA05453;
	Thu, 29 Jun 2000 14:56:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 14:06:30 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA04085
	for fwtk-users-outgoing; Thu, 29 Jun 2000 14:05:59 -0700 (PDT)
Message-Id: <4.2.2.20000629164540.00b1c700@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Thu, 29 Jun 2000 16:49:10 -0400
To: "TJ O Connor" <toconnor@comnitel.com>, <fwtk-users@lists.nai.com>,
        <questions@freebsd.org>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Configuring the authsrv
In-Reply-To: <NEBBINOGOEDMFIMMJPJMKEKGCAAA.toconnor@comnitel.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 643

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 05:08 PM 6/29/00 +0100, TJ O Connor wrote:
>When i run a make in the auth directory this is what happens
>
>db.o: In function `auth_dbopen':
>/usr/local/src/fwtk/auth/db.c:66: undefined reference to `dbm_open'

add '-ldbm' to the DBMLIB definition in Makefile.config

>pass.o: In function `passverify':
>/usr/local/src/fwtk/auth/pass.c:39: undefined reference to `crypt'

add -lcrypt to the AUXLIB definition.
See the FAQ at <http://www.fwtk.org/> as I'm pretty sure these are 
discussed there.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Jun 29 19:16 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA06017
	Thu, 29 Jun 2000 19:16:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA07307;
	Thu, 29 Jun 2000 16:24:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Jun 2000 15:27:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA06104
	for fwtk-users-outgoing; Thu, 29 Jun 2000 15:27:36 -0700 (PDT)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: <marc@centraltx.com>, <fwtk-users@ex.tis.com>
Date: Thu, 29 Jun 2000 16:27:01 -0600
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Re: socks
Message-ID: <395B78D0.2972.212CD39@localhost>
In-reply-to: <200006291509.AA828113062@mail.centraltx.com>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 497

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

FWTK is not SOCKS.  You can install a SOCKS server on the same machine as 
your FWTK and have the two work just fine.

A freeware socks server is available from NEC at

  http://www.socks.nec.com/socks5.html

Ken Long


On 29 Jun 2000, at 15:09, marc wrote:

> How can I make fwtk compatiable with programs who have the only
> firewall option as SOCKS4/5.
> 
> -Marc


From owner-fwtk-users@ex.tis.com Fri Jun 30 07:19 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA12033
	Fri, 30 Jun 2000 07:19:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA11766;
	Fri, 30 Jun 2000 04:27:25 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 03:28:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA10936
	for fwtk-users-outgoing; Fri, 30 Jun 2000 03:28:14 -0700 (PDT)
From: valves@estg.iplei.pt (Valter Alves)
To: fwtk-users@ex.tis.com, toconnor@comnitel.com
Subject: (fwd) Configuring the authsrv
Date: Fri, 30 Jun 2000 10:13:30 GMT
Message-ID: <397771bb.328607702@mail.estg.iplei.pt>
X-Mailer: Forte Agent 1.5/32.451
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id DAA10932
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2576

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



Hi
I don't know what operating system you have.
I have a problem in Slacware (copy Makefile.config.linux
Makefile.config).
The only think you have to do is
Edit Makefile.config and comment the line
#AUXLIB= -lcrypt



# Some versions of Linux have broken the crypt() function out into a
# separate library - uncomment the following line if authsrv fails to
build.
#AUXLIB= -lcrypt




On Thu, 29 Jun 2000 17:08:27 +0100, "TJ O Connor"
<toconnor@comnitel.com> wrote:

[To be removed from this list send the message "unsubscribe
fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi
I'm just after downloading the TIS FWTK and im trying to configure it.
I've run my 'make' and 'make install' but when i come to initializing
the
database and running './authsrv', I can't find it. I don't know what
to do
to get it.


When i run a make in the auth directory this is what happens

cc -g -o authsrv authsrv.o proto.o db.o pass.o srvio.o
../libauth.a
../libfwall.a
db.o: In function `auth_dbopen':
/usr/local/src/fwtk/auth/db.c:66: undefined reference to `dbm_open'
db.o: In function `auth_dbclose':
/usr/local/src/fwtk/auth/db.c:83: undefined reference to `dbm_close'
db.o: In function `auth_dbgetu':
/usr/local/src/fwtk/auth/db.c:123: undefined reference to `dbm_fetch'
db.o: In function `auth_dbputu':
/usr/local/src/fwtk/auth/db.c:152: undefined reference to `dbm_store'
db.o: In function `auth_dbdelu':
/usr/local/src/fwtk/auth/db.c:176: undefined reference to `dbm_delete'
db.o: In function `auth_dbtraversestart':
/usr/local/src/fwtk/auth/db.c:196: undefined reference to
`dbm_firstkey'
/usr/local/src/fwtk/auth/db.c:200: undefined reference to `dbm_fetch'
db.o: In function `auth_dbtraversenext':
/usr/local/src/fwtk/auth/db.c:225: undefined reference to
`dbm_nextkey'
/usr/local/src/fwtk/auth/db.c:229: undefined reference to `dbm_fetch'
pass.o: In function `passverify':
/usr/local/src/fwtk/auth/pass.c:39: undefined reference to `crypt'
pass.o: In function `passset':
/usr/local/src/fwtk/auth/pass.c:70: undefined reference to `crypt'
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

If anyone knows anything about this it would be very helpful.

- --                      _
T.J.O'Connor            _/ \_   2200 Cork Airport Business Park,
SysAdmin               / \_/ \  Kinsale Rd., Cork, Ireland.
Comnitel Technologies  \_/ \_/  Ph: +353 21 7305620
toconnor@comnitel.com    \_/    Fax: +353 21 7305624


From owner-fwtk-users@ex.tis.com Fri Jun 30 09:26 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA12575
	Fri, 30 Jun 2000 09:26:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA14105;
	Fri, 30 Jun 2000 06:33:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 05:38:32 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA12686
	for fwtk-users-outgoing; Fri, 30 Jun 2000 05:38:21 -0700 (PDT)
From: ark@eltex.ru
Date: Fri, 30 Jun 2000 12:27:33 +0400
Message-Id: <200006300827.MAA08605@paranoid.eltex.spb.ru>
In-Reply-To: <200006291509.AA828113062@mail.centraltx.com> from ""marc " <marc@centraltx.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: socks
To: marc@centraltx.com
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1102

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Just don't use that programs :-/

"marc " <marc@centraltx.com> said :

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > How can I make fwtk compatiable with programs who have the only
 > firewall option as SOCKS4/5.
 > 
 > -Marc
 > 

                                      _     _  _  _  _      _  _
  {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
  (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
  [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBOVxZ86H/mIJW9LeBAQEtzQQAkAZBrFOVu5oTBG259cBM2ZImDB1xTV/U
oI0jbMWV3WCFWjmVBYaNfbI44y/C2Hi1x/gPHxFh9nRUvq5qte3FEMVmYqoGYzpA
HU3oVWodCBUV5sxzR3uDHXGJ71n+NJXWe0VIpLPLMihvXgHA+VQ8ASJJ0fsxo40d
kbDWyZj3WO8=
=tA3h
-----END PGP SIGNATURE-----


From owner-fwtk-users@ex.tis.com Fri Jun 30 09:26 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA12578
	Fri, 30 Jun 2000 09:26:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA14109;
	Fri, 30 Jun 2000 06:33:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 05:39:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA12708
	for fwtk-users-outgoing; Fri, 30 Jun 2000 05:39:11 -0700 (PDT)
From: ark@eltex.ru
Date: Fri, 30 Jun 2000 12:28:53 +0400
Message-Id: <200006300828.MAA08609@paranoid.eltex.spb.ru>
In-Reply-To: <395B78D0.2972.212CD39@localhost> from ""Ken Long" <ken@lectrosonics.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: socks
To: ken@lectrosonics.com
Cc: marc@centraltx.com, <fwtk-users@ex.tis.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1450

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

.if you REALLY DO KNOW what you do and you are damn sure you WANT that. 

"Ken Long" <ken@lectrosonics.com> said :

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > FWTK is not SOCKS.  You can install a SOCKS server on the same machine as 
 > your FWTK and have the two work just fine.
 > 
 > A freeware socks server is available from NEC at
 > 
 >   http://www.socks.nec.com/socks5.html
 > 
 > Ken Long
 > 
 > 
 > On 29 Jun 2000, at 15:09, marc wrote:
 > 
 > > How can I make fwtk compatiable with programs who have the only
 > > firewall option as SOCKS4/5.
 > > 
 > > -Marc
 > 

                                      _     _  _  _  _      _  _
  {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
  (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
  [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBOVxaQ6H/mIJW9LeBAQHkmAP+NhXk2EM0ghsvQGovSMdn2gicA4n/+F0Z
DyV9mIWIwWsvfxA2BLvzKFkO7PqBDE4pnBoplpTn5a4V+f5sF2ifcz7xGu5HoULd
4OhwIIurXgAl6dX4grkS9Z9/s+yE3Dpoq6amFDFxiwmJgv7om/Ppe/x3i9Y8q/sy
rjUkdRau7sg=
=zQ5M
-----END PGP SIGNATURE-----


From owner-fwtk-users@ex.tis.com Fri Jun 30 10:17 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA12665
	Fri, 30 Jun 2000 10:17:58 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA16681;
	Fri, 30 Jun 2000 07:25:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 06:35:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA14150
	for fwtk-users-outgoing; Fri, 30 Jun 2000 06:34:58 -0700 (PDT)
From: "TJ O Connor" <toconnor@comnitel.com>
To: "Fwtk Users" <fwtk-users@lists.nai.com>,
        "fwtk users" <questions@freebsd.org>,
        "fwtk users" <fwtk-users@ex.tis.com>,
        "Fwtk Users" <owner-fwtk-users@ex.tis.com>
Date: Fri, 30 Jun 2000 14:35:43 +0100
Message-ID: <NEBBINOGOEDMFIMMJPJMGEKNCAAA.toconnor@comnitel.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 645

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,
After configuring you /etc/services, /etc/netperm-table, and /etc/inetd.conf
files
How do you actually run the firewal?
Any documentation i've looked at doesn't answer that question for me.
So of anyone knows what to do please let me know.
cheers
TJ


- --                      _
T.J.O'Connor            _/ \_   2200 Cork Airport Business Park,
SysAdmin               / \_/ \  Kinsale Rd., Cork, Ireland.
Comnitel Technologies  \_/ \_/  Ph: +353 21 7305620
toconnor@comnitel.com    \_/    Fax: +353 21 7305624


From owner-fwtk-users@ex.tis.com Fri Jun 30 10:17 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA12666
	Fri, 30 Jun 2000 10:17:58 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA16685;
	Fri, 30 Jun 2000 07:25:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 06:35:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA14159
	for fwtk-users-outgoing; Fri, 30 Jun 2000 06:35:01 -0700 (PDT)
From: "TJ O Connor" <toconnor@comnitel.com>
To: "Fwtk Users" <fwtk-users@lists.nai.com>,
        "fwtk users" <questions@freebsd.org>,
        "fwtk users" <fwtk-users@ex.tis.com>,
        "Fwtk Users" <owner-fwtk-users@ex.tis.com>
Date: Fri, 30 Jun 2000 14:35:43 +0100
Message-ID: <NEBBINOGOEDMFIMMJPJMGEKNCAAA.toconnor@comnitel.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 645

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,
After configuring you /etc/services, /etc/netperm-table, and /etc/inetd.conf
files
How do you actually run the firewal?
Any documentation i've looked at doesn't answer that question for me.
So of anyone knows what to do please let me know.
cheers
TJ


- --                      _
T.J.O'Connor            _/ \_   2200 Cork Airport Business Park,
SysAdmin               / \_/ \  Kinsale Rd., Cork, Ireland.
Comnitel Technologies  \_/ \_/  Ph: +353 21 7305620
toconnor@comnitel.com    \_/    Fax: +353 21 7305624


From owner-fwtk-users@ex.tis.com Fri Jun 30 20:15 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA14341
	Fri, 30 Jun 2000 20:15:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA21844;
	Fri, 30 Jun 2000 17:23:12 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 15:55:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA20657
	for fwtk-users-outgoing; Fri, 30 Jun 2000 15:55:51 -0700 (PDT)
Message-Id: <200006302255.PAA19848@relay.nai.com>
From: "Christian Kuhn" <Christian.Kuhn@QNo.de>
To: "fwtk-users" <fwtk-users@ex.tis.com>
Date: Sat, 01 Jul 2000 00:54:16 +0200
Reply-To: "Christian Kuhn" <Christian.Kuhn@QNo.de>
X-Mailer: PMMail 98 Standard (2.01.1600) For Windows 98 (4.10.2222)
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Subject: authserv - can't compile
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="iso-8859-1"
Content-Length: 1634

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I just tried to install fwtk2.1. make all produced the binaries,
make install copied them into the desired directory (netperm-table
appeared in the bin directory instead of the given etc, but still
it makes no problems). Next, i tried to use authserv - not present.
The compiler gave this error:

db.o: In function `auth_dbopen':
/usr/local/src/fwtk/auth/db.c:66: undefined reference to `dbm_open'
db.o: In function `auth_dbclose':
/usr/local/src/fwtk/auth/db.c:83: undefined reference to
`dbm_close'
db.o: In function `auth_dbgetu':
/usr/local/src/fwtk/auth/db.c:123: undefined reference to
`dbm_fetch'
db.o: In function `auth_dbputu':
/usr/local/src/fwtk/auth/db.c:152: undefined reference to
`dbm_store'
db.o: In function `auth_dbdelu':
/usr/local/src/fwtk/auth/db.c:176: undefined reference to
`dbm_delete'
db.o: In function `auth_dbtraversestart':
/usr/local/src/fwtk/auth/db.c:196: undefined reference to
`dbm_firstkey'
/usr/local/src/fwtk/auth/db.c:200: undefined reference to
`dbm_fetch'
db.o: In function `auth_dbtraversenext':
/usr/local/src/fwtk/auth/db.c:225: undefined reference to
`dbm_nextkey'
/usr/local/src/fwtk/auth/db.c:229: undefined reference to
`dbm_fetch'
pass.o: In function `passverify':
/usr/local/src/fwtk/auth/pass.c:39: undefined reference to `crypt'
pass.o: In function `passset':
/usr/local/src/fwtk/auth/pass.c:70: undefined reference to `crypt'
collect2: ld returned 1 exit status
make: *** [authsrv] Error 1

What did i wrong?

mfg
QNo
-- 
ICQ 57840861
AIM MrQNo




From owner-fwtk-users@ex.tis.com Fri Jun 30 21:54 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA14424
	Fri, 30 Jun 2000 21:54:18 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA23917;
	Fri, 30 Jun 2000 19:01:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Jun 2000 18:11:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA22548
	for fwtk-users-outgoing; Fri, 30 Jun 2000 18:11:25 -0700 (PDT)
Message-Id: <4.2.2.20000630204831.00af7880@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Fri, 30 Jun 2000 20:54:22 -0400
To: "TJ O Connor" <toconnor@comnitel.com>, <fwtk-users@lists.nai.com>,
        <questions@freebsd.org>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: 
In-Reply-To: <NEBBINOGOEDMFIMMJPJMGEKNCAAA.toconnor@comnitel.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 728

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:35 PM 6/30/00 +0100, TJ O Connor wrote:
>Hi,
>After configuring you /etc/services, /etc/netperm-table, and /etc/inetd.conf
>files
>How do you actually run the firewal?

If you've done it right, you reboot - the proxies are either running as 
daemons waiting for connections, or they're running from inetd.

Hint: "fwtk-users@lists.nai.com" is all you need. Your questions appear 
twice when you also post to fwtk-users@ex.tis.com.
(Not to mention the fact that freebsd has nothing to do with fwtk; the 
freebsd project shouldn't be redistributing or supplying fwtk.)
         -Rick
         


