From owner-fwtk-users@ex.tis.com Fri Sep  1 06:16 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA04488
	Fri, 1 Sep 2000 06:16:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA05266;
	Fri, 1 Sep 2000 03:25:19 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 1 Sep 2000 00:44:27 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA07557
	for fwtk-users-outgoing; Fri, 1 Sep 2000 00:44:04 -0700 (PDT)
From: swilso39@csc.com
X-Lotus-FromDomain: CSC
To: fwtk-users@lists.nai.com
Message-ID: <0025694D.00301D56.00@uk-fbr10.eu.csc.com>
Date: Fri, 1 Sep 2000 09:41:05 +0100
Subject: SMAP/SMAPD
Mime-Version: 1.0
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 984

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



Hi,

Im a newbie to all this so forgive me if I make a complete idiot of myself with
my explanation!

Im running a recent version of SMAP and SMAPD, and for the past three months
have had no problems (that I am aware of!).
Recently I have noticed that my log files have been growing at a major rate.
This is all due to the same message appearing literally all the time :


Sep  1 08:29:16 nadsc6 smap[505]: connect host=unknown/195.217.247.18
Sep  1 08:29:16 nadsc6 smap[500]: Relay: <twngirl@cyberway.com.sg>
<lists@headland.co.uk> (195.217.247.18)

Although the first address after ":Relay: <" may change frequently the second
address is pretty much consistent (domain is anyway!)

Does anybody know what is going on with this or do I have some sort of localised
problem?

Any help that can be offered would be greatly appreciated.


Stuart Wilson.



From owner-fwtk-users@ex.tis.com Fri Sep  1 06:54 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA04630
	Fri, 1 Sep 2000 06:54:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA06477;
	Fri, 1 Sep 2000 04:03:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 1 Sep 2000 02:33:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA26482
	for fwtk-users-outgoing; Fri, 1 Sep 2000 02:33:23 -0700 (PDT)
From: "TJ O Connor" <toconnor@comnitel.com>
To: "Fwtk Users 1" <fwtk-users@lists.nai.com>
Subject: smapd,smap,semdmail
Date: Fri, 1 Sep 2000 10:32:08 +0100
Message-ID: <NEBBINOGOEDMFIMMJPJMOEDDCCAA.toconnor@comnitel.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1043

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,
      I am trying to setup smap and smapd but i keep getting an error when i
try to send mail.
      I have added
(1) smtp stream tcp nowait root /usr/local/etc/smap smap
    to inetd.conf

(2) smap, smapd:  userid uucp
    smap, smapd:  directory /var/spool/inspool
    smapd:        executable /usr/local/etc/smapd

    to the netperm-table

(3) script for starting smapd to my bootscript that starts sendmail
    if [ /usr/local/etc/smapd ] ; then
          echo " Starting sendmail proxy"
          /usr/local/etc/smapd
    fi

Does sendmail have to be shut off before i run this?
do i have an error in any of the above?

Please help me

TJ


- --                      _
T.J.O'Connor            _/ \_   2200 Cork Airport Business Park,
SysAdmin               / \_/ \  Kinsale Rd., Cork, Ireland.
Comnitel Technologies  \_/ \_/  Ph: +353 21 7305620
toconnor@comnitel.com    \_/    Fax: +353 21 7305624


From owner-fwtk-users@ex.tis.com Fri Sep  1 16:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA06241
	Fri, 1 Sep 2000 16:37:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA08347;
	Fri, 1 Sep 2000 13:45:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 1 Sep 2000 11:31:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA19105
	for fwtk-users-outgoing; Fri, 1 Sep 2000 11:31:32 -0700 (PDT)
Message-ID: <39AFB4F6.2BC8D79B@lclcan.com>
Date: Fri, 01 Sep 2000 09:53:58 -0400
From: Don <don@lclcan.com>
X-Mailer: Mozilla 4.75 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: Instant messaging problem
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/html; charset=us-ascii
Content-Length: 500

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

<!doctype html public "-//w3c//dtd html 4.0 transitional//en">
<html>
Has anyone had and problems logging into IM's after installing the TIS
proxies?&nbsp; I've set up an http proxy on my RedHat Linux 6.2 box.&nbsp;
Interestingly enough, AOL works fine.&nbsp; However, when I try to log
in to Yahoo IM, I actually do log in but then get immediately disconnected.</html>


From owner-fwtk-users@ex.tis.com Fri Sep  1 16:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA06244
	Fri, 1 Sep 2000 16:37:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA08351;
	Fri, 1 Sep 2000 13:45:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 1 Sep 2000 11:17:18 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA16682
	for fwtk-users-outgoing; Fri, 1 Sep 2000 11:16:34 -0700 (PDT)
Date: Fri, 1 Sep 2000 09:10:36 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: TJ O Connor <toconnor@comnitel.com>
Cc: Fwtk Users 1 <fwtk-users@lists.nai.com>
Subject: Re: smapd,smap,semdmail
Message-Id: <20000901091036.B28030@washington.cospo.osis.gov>
Mail-Followup-To: TJ O Connor <toconnor@comnitel.com>,
	Fwtk Users 1 <fwtk-users@lists.nai.com>
References: <NEBBINOGOEDMFIMMJPJMOEDDCCAA.toconnor@comnitel.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NEBBINOGOEDMFIMMJPJMOEDDCCAA.toconnor@comnitel.com>; from toconnor@comnitel.com on Fri, Sep 01, 2000 at 10:32:08AM +0100
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1544

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 01, 2000 at 10:32:08AM +0100, TJ O Connor wrote:
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hi all,
 >       I am trying to setup smap and smapd but i keep getting an error when i
 > try to send mail.
 >       I have added
 > (1) smtp stream tcp nowait root /usr/local/etc/smap smap
 >     to inetd.conf
 > 
 > (2) smap, smapd:  userid uucp
 >     smap, smapd:  directory /var/spool/inspool
 >     smapd:        executable /usr/local/etc/smapd
 > 
 >     to the netperm-table
 > 
 > (3) script for starting smapd to my bootscript that starts sendmail
 >     if [ /usr/local/etc/smapd ] ; then
 >           echo " Starting sendmail proxy"
 >           /usr/local/etc/smapd
 >     fi
 > 
 > Does sendmail have to be shut off before i run this?
 > do i have an error in any of the above?

Ah!  That last says it all.

Sendmail should NOT be running in daemon [-bd] mode.  Sendmail MAY be
running in queue-only [-qNNm or -qNNh] mode.

Note that, since you have given a 'chroot' directory, everything that
smap, smapd, or sendmail need must be available in the 'chroot'ed
directory.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


From owner-fwtk-users@ex.tis.com Fri Sep  1 16:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA06240
	Fri, 1 Sep 2000 16:37:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA08396;
	Fri, 1 Sep 2000 13:45:54 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 1 Sep 2000 12:13:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA25797
	for fwtk-users-outgoing; Fri, 1 Sep 2000 12:13:21 -0700 (PDT)
Message-ID: <20000901191201.5776.qmail@web1804.mail.yahoo.com>
Date: Fri, 1 Sep 2000 12:12:01 -0700 (PDT)
From: Naresh Narang <nknarang@yahoo.com>
Subject: Re: SMAP/SMAPD
To: swilso39@csc.com
Cc: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1147

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

It looks like you are openly allowing users outside
your domain to relay messages. It might be spam sent
to others using your mail server. 

Naresh

 
> Im running a recent version of SMAP and SMAPD, and
> for the past three months
> have had no problems (that I am aware of!).
> Recently I have noticed that my log files have been
> growing at a major rate.
> This is all due to the same message appearing
> literally all the time :
> 
> 
> Sep  1 08:29:16 nadsc6 smap[505]: connect
> host=unknown/195.217.247.18
> Sep  1 08:29:16 nadsc6 smap[500]: Relay:
> <twngirl@cyberway.com.sg>
> <lists@headland.co.uk> (195.217.247.18)
> 
> Although the first address after ":Relay: <" may
> change frequently the second
> address is pretty much consistent (domain is
> anyway!)
> 
> Does anybody know what is going on with this or do I
> have some sort of localised
> problem?
> 


__________________________________________________
Do You Yahoo!?
Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Fri Sep  1 16:39 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA06251
	Fri, 1 Sep 2000 16:39:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA08657;
	Fri, 1 Sep 2000 13:48:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 1 Sep 2000 12:29:51 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA28460
	for fwtk-users-outgoing; Fri, 1 Sep 2000 12:29:40 -0700 (PDT)
Message-ID: <005b01c01449$ad7ea460$c93b0dd8@webnet.qc.ca>
From: "Jonathan Marchand" <jonathanm@webnet.qc.ca>
To: <fwtk-support@tis.com>
Cc: <fwtk-users@tis.com>
References: <384272173.967802695549.JavaMail.root@web307-mc.mail.com>
Subject: FTP Behind Masquerade?
Date: Fri, 1 Sep 2000 15:20:23 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2314.1300
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 915

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi there,

I just setup a linux box with masquerading enabled. Behind it, there's a
win2k machine. It runs an ftp server. I did a redirection for port 21 on the
linux to that internal host. But, I only get ftp to work in passive mode. It
won't work in active/normal mode. Why is that? How can I fix it? Is it
possible?

I inserted the ip_masq_ftp.o module on the linux, but it just says "unused"
when I do a lsmod, I'm not sure if it ip_masq_ftp is supposed to help in any
way for what I want to do. When I try to ftp (from the outside) to my ftp
behind the masquerade, I just get:

500 Invalid PORT Command.
ftp: bind: Address already in use

But if I set my client in passive mode, it work fine. So, is there anything
I could do to make it work in normal mode?

Regards,

Jonathan.



From owner-fwtk-users@ex.tis.com Tue Sep  5 08:03 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA06667
	Tue, 5 Sep 2000 08:03:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA21549;
	Tue, 5 Sep 2000 05:10:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 02:58:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA16697
	for fwtk-users-outgoing; Tue, 5 Sep 2000 02:57:50 -0700 (PDT)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <39B4C372.78A973FD@radio.hundert6.de>
Date: Tue, 05 Sep 2000 11:57:06 +0200
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.0-RELEASE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: smap standalone?
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 360

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi there,
I want to use smap as an addition to an otherwise only
filter-based firewall. 
Can it be run independent from the rest of the fwtk?

Cheers, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Tue Sep  5 08:03 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA06668
	Tue, 5 Sep 2000 08:03:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA21546;
	Tue, 5 Sep 2000 05:10:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 02:44:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA16372
	for fwtk-users-outgoing; Tue, 5 Sep 2000 02:44:12 -0700 (PDT)
Message-Id: <4.3.2.7.0.20000905103812.040ecd60@192.168.2.2>
X-Sender: john@192.168.2.2
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Tue, 05 Sep 2000 10:39:48 +0100
To: fwtk-users@lists.nai.com
From: John Armstrong <john@lrf.leeds.ac.uk>
Subject: Napster
In-Reply-To: <007101bfed7f$8ccdf2c0$9001a8c0@sctech.co.jp>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 691

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I'm running fwtk 2.1 on my Linux firewall.  Has anyone set up this to allow 
proxy access to the napster server?  The connection screen only mentions 
socks 4/5 proxies.

Thanks
__________________________________________________________________________
  John Armstrong                        	Computer System Adminstrator

  john@lrf.leeds.ac.uk			LRF Centre at Leeds University
  j.d.c.armstrong@leeds.ac.uk            	30 Hyde Terrace
                                         		Leeds LS2 9LN
  0113 233 3912 (phone)                  	
  0113 245 9806 (fax)



From owner-fwtk-users@ex.tis.com Tue Sep  5 09:08 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA06855
	Tue, 5 Sep 2000 09:08:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA27393;
	Tue, 5 Sep 2000 06:16:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 04:46:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA19907
	for fwtk-users-outgoing; Tue, 5 Sep 2000 04:45:34 -0700 (PDT)
Message-ID: <39B226AC.34A8D5DD@intstar.com>
Date: Sun, 03 Sep 2000 11:23:40 +0100
From: Gareth Bromley <gbromley@intstar.com>
X-Mailer: Mozilla 4.7 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: FWTK Mailing List <fwtk-users@tis.com>
Subject: ftp-gw 'hand-off' function
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
  boundary="------------81BF04341666C81532BC81BB"
Content-Length: 1148

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------81BF04341666C81532BC81BB
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

As subject:

Is there a patch anywhere to make ftp-gw act like Gauntlets FTP
'hand-off' so that DMZ FTP servers can be accessed via FWTK??

Many thanks,

--Gareth

--------------81BF04341666C81532BC81BB
Content-Type: text/x-vcard; charset=us-ascii;
  name="gbromley.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Gareth Bromley
Content-Disposition: attachment;
  filename="gbromley.vcf"

begin:vcard 
n:Bromley;Gareth
tel;cell:+44 7976 237 831
tel;fax:+44 870 056 8430
tel;home:+44 1256 844 272
tel;work:+44 7970 200 546
x-mozilla-html:FALSE
url:http://www.intstar.com/
org:Int* Consulting Ltd
version:2.1
email;internet:gbromley@intstar.com
title:Managing Director
adr;quoted-printable:;;30 Fox's Furlong,=0D=0AChineham;Basingstoke;Hampshire;RG24 8WN;United Kingdom
fn:Gareth Bromley
end:vcard

--------------81BF04341666C81532BC81BB--



From owner-fwtk-users@ex.tis.com Tue Sep  5 09:08 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA06859
	Tue, 5 Sep 2000 09:08:26 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA27403;
	Tue, 5 Sep 2000 06:16:57 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 04:50:25 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA20164
	for fwtk-users-outgoing; Tue, 5 Sep 2000 04:50:14 -0700 (PDT)
Message-ID: <EDDE188CE4A3D311950C0008C7EB764D8E78BD@EXCSRVSQY2>
From: "MONIER Jean-Christophe (EURIWARE S.A.)" <jcmonier@euriware.fr>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: A small patch for authmgr
Date: Tue, 5 Sep 2000 13:10:23 +0200 
Importance: high
X-Priority: 1
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
	boundary="----_=_NextPart_000_01C0172A.97DB13DA"
Content-Length: 6391

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_000_01C0172A.97DB13DA
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hello all,

I've writting a small patch to extand syntax of the 'login' command of =
the
authmgr software.
This patch allow you to use login in 3 differents methods :

- original : enter "login" and authmgr prompt you for Username: and
Password:
or
- enter "login <username>" and authmgr prompt you only for Password:
or=20
- enter "login <username> <user's password>" and authmgr prompt nothing

The last method allow you to login into authmgr from a script like a =
perl
program for example.
I use this 3th in a perl script that allow me to put new users from a
flat-text file.

Here is the patch

----------- CUT HERE ------------------------------

--- /usr/src/fwtk/auth/authmgr.c	Tue Sep  5 13:04:34 2000
+++ authmgr.c	Tue Sep  5 11:35:06 2000
@@ -45,7 +45,7 @@
  static	Cmd	*find_command();
=20
  static Cmd ctab[] =3D {
-"login",	FLG_LOCAL,	"login",			do_login,
+"login",	FLG_LOCAL,	"login [username [password]]",
do_login,
  "adduser",	0,	"adduser username [longname]",		0,
  "deluser",	0,		"deluser username",		0,
  "display",	FLG_LOCAL,	"display username",
do_multiline,
@@ -203,6 +203,12 @@
  	char		*p;
=20
  	logged_in =3D 0;
+	if(ac > 2) {
+		strncpy(usrbuf,av[1], 512);
+		usrbuf[511] =3D '\0';
+		strncpy(pbuf,av[2], 512);
+		rbuf[511] =3D '\0';
+	} else {
  	if(ac > 1) {
  		strncpy(usrbuf,av[1], 512);
  		usrbuf[511] =3D '\0';
@@ -212,6 +218,7 @@
  		if(fgets(usrbuf,sizeof(usrbuf),stdin) =3D=3D (char *)0)
  			do_quit();
  	}
+	}
  	sprintf(rbuf,"authorize %s",usrbuf);
  	if(auth_send(rbuf))
  		lostconn();
@@ -238,9 +245,17 @@
  		if(!strncmp(rbuf,"chalnecho ",10)) {
  			p =3D getpassword(&rbuf[10]);
  		} else
-		if(!strncmp(rbuf,"password",8)) {
-			p =3D getpassword("Password: ");
-		} else {
+		if (ac <=3D 2) {
+			if(!strncmp(rbuf,"password",8)) {
+				p =3D getpassword("Password: ");
+			}
+		}
+		else
+		if  (ac > 2) {
+			p =3D pbuf;
+		}
+		else
+		{
  			fprintf(stderr,"%s\n",rbuf);
  			return(1);
  		}

----------- CUT HERE ------------------------------


Here is the perl script I use :


----------- CUT HERE ------------------------------
#!/usr/bin/perl5
#USAGE: authadd.pl [ userfile ]
# userfile is : userid \t groupid \t password \t longname
$DATABASE =3D @ARGV[0];
$AUTHSRV=3D"/usr/local/etc/authmgr";

open(IN, "$DATABASE");
open(OUT, "| $AUTHSRV");
# Authenticate with a SUPER-WIZ user
print OUT "login adminuser adminpwd\n";

# Add users from userfile (one user per line)
while (<IN>) {
   $_ =3D~  s/[\r\n]//g;
   ($uid, $group, $PASSWORD, @longnameparts) =3D split(/[ \t]/, $_);
   $longname =3D "\"" . join(" ", @longnameparts) . "\"";
    print OUT "adduser $uid $longname\n";
    print OUT "group $uid $group\n";
    print OUT "password $uid $PASSWORD\n";
    print OUT "enable $uid\n";
    print OUT "display $uid\n";
}
print OUT "quit\n";

----------- CUT HERE ------------------------------


I include this 2 files to this mail too.

I put this 2 codes in public domain for FWTK user's.

Comments are welcome.

Hope this help somebody ...

Regards,

  <<authadd.pl>>  <<authmgr.patch>>=20
PS : Please, excuse my 'poor' english language.

Jean-Christophe MONIER
EURIWARE S.A. - France
Responsable de la Cellule S=E9curit=E9 des Syst=E8mes d'Informations
ASSI  - R=E9gion SQY



------_=_NextPart_000_01C0172A.97DB13DA
Content-Type: application/octet-stream;
	name="authadd.pl"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
	filename="authadd.pl"

#!/usr/bin/perl5=0A=
#USAGE: authadd.pl [ userfile ]
# userfile is : userid \t groupid \t password \t longname=0A=
$DATABASE =3D @ARGV[0];=0A=
$AUTHSRV=3D"/usr/local/etc/authmgr";=0A=
=0A=
open(IN, "$DATABASE");=0A=
open(OUT, "| $AUTHSRV");
# Authenticate with a SUPER-WIZ user=0A=
print OUT "login adminuser adminpwd\n";

# Add users from userfile (one user per line)=0A=
while (<IN>) {=0A=
   $_ =3D~  s/[\r\n]//g;=0A=
   ($uid, $group, $PASSWORD, @longnameparts) =3D split(/[ \t]/, $_);=0A=
   $longname =3D "\"" . join(" ", @longnameparts) . "\"";=0A=
    print OUT "adduser $uid $longname\n";=0A=
    print OUT "group $uid $group\n";=0A=
    print OUT "password $uid $PASSWORD\n";=0A=
    print OUT "enable $uid\n";=0A=
    print OUT "display $uid\n";=0A=
}=0A=
print OUT "quit\n";=0A=

------_=_NextPart_000_01C0172A.97DB13DA
Content-Type: application/octet-stream;
	name="authmgr.patch"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
	filename="authmgr.patch"

--- /home/jcmonier/authmgr.c	Tue Sep  5 13:04:34 2000=0A=
+++ authmgr.c	Tue Sep  5 11:35:06 2000=0A=
@@ -45,7 +45,7 @@=0A=
  static	Cmd	*find_command();=0A=
  =0A=
  static Cmd ctab[] =3D {=0A=
-"login",	FLG_LOCAL,	"login",			do_login,=0A=
+"login",	FLG_LOCAL,	"login [username [password]]",			do_login,=0A=
  "adduser",	0,	"adduser username [longname]",		0,=0A=
  "deluser",	0,		"deluser username",		0,=0A=
  "display",	FLG_LOCAL,	"display username",		do_multiline,=0A=
@@ -203,6 +203,12 @@=0A=
  	char		*p;=0A=
  =0A=
  	logged_in =3D 0;=0A=
+	if(ac > 2) {=0A=
+		strncpy(usrbuf,av[1], 512);=0A=
+		usrbuf[511] =3D '\0';=0A=
+		strncpy(pbuf,av[2], 512);=0A=
+		rbuf[511] =3D '\0';=0A=
+	} else {=0A=
  	if(ac > 1) {=0A=
  		strncpy(usrbuf,av[1], 512);=0A=
  		usrbuf[511] =3D '\0';=0A=
@@ -212,6 +218,7 @@=0A=
  		if(fgets(usrbuf,sizeof(usrbuf),stdin) =3D=3D (char *)0)=0A=
  			do_quit();=0A=
  	}=0A=
+	}=0A=
  	sprintf(rbuf,"authorize %s",usrbuf);=0A=
  	if(auth_send(rbuf))=0A=
  		lostconn();=0A=
@@ -238,9 +245,17 @@=0A=
  		if(!strncmp(rbuf,"chalnecho ",10)) {=0A=
  			p =3D getpassword(&rbuf[10]);=0A=
  		} else=0A=
-		if(!strncmp(rbuf,"password",8)) {=0A=
-			p =3D getpassword("Password: ");=0A=
-		} else {=0A=
+		if (ac <=3D 2) {=0A=
+			if(!strncmp(rbuf,"password",8)) {=0A=
+				p =3D getpassword("Password: ");=0A=
+			}=0A=
+		}=0A=
+		else=0A=
+		if  (ac > 2) {=0A=
+			p =3D pbuf;=0A=
+		}=0A=
+		else=0A=
+		{=0A=
  			fprintf(stderr,"%s\n",rbuf);=0A=
  			return(1);=0A=
  		}=0A=

------_=_NextPart_000_01C0172A.97DB13DA--


From owner-fwtk-users@ex.tis.com Tue Sep  5 09:10 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA06863
	Tue, 5 Sep 2000 09:10:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA27555;
	Tue, 5 Sep 2000 06:18:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 05:02:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA20804
	for fwtk-users-outgoing; Tue, 5 Sep 2000 05:01:51 -0700 (PDT)
Date: Tue, 5 Sep 2000 08:00:23 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Jan Muenther <jan@radio.hundert6.de>
cc: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: smap standalone?
In-Reply-To: <39B4C372.78A973FD@radio.hundert6.de>
Message-ID: <Pine.GSO.4.10.10009050759440.28843-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 685

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jan,

I've run smap/smapd successfully in a checkpoint system before.  So - yes
- it can be run independently.

ted keller


On Tue, 5 Sep 2000, Jan Muenther wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi there,
> I want to use smap as an addition to an otherwise only
> filter-based firewall. 
> Can it be run independent from the rest of the fwtk?
> 
> Cheers, Jan
> -- 
> Radio HUNDERT,6 Medien GmbH Berlin
> - EDV -
> j.muenther@radio.hundert6.de
> 


From owner-fwtk-users@ex.tis.com Tue Sep  5 10:45 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA07296
	Tue, 5 Sep 2000 10:45:45 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA09069;
	Tue, 5 Sep 2000 07:54:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 06:23:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA28023
	for fwtk-users-outgoing; Tue, 5 Sep 2000 06:23:32 -0700 (PDT)
Message-Id: <200009051317.PAA00543@kea.inferenzsysteme.informatik.tu-darmstadt.de>
Date: Tue, 5 Sep 2000 15:17:48 +0200 (MET DST)
From: Matthias Bormann <bormann@inferenzsysteme.informatik.tu-darmstadt.de>
Reply-To: Matthias Bormann <bormann@inferenzsysteme.informatik.tu-darmstadt.de>
Subject: smap / yao-patch
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Content-MD5: 9mXxVwXEZkw/qCYE4kQJMQ==
X-Mailer: dtmail 1.2.1 CDE Version 1.2.1 SunOS 5.6 sun4u sparc 
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/plain; charset=us-ascii
Content-Length: 1450

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,

I tried to apply the yao-patch to smap, but
compiling and linking result in the following error:

cc -g -static -lresolv -o smap smap.o arpadate.o ../libfwall.a -lcrypt
smap.o: In function `from_address_ok':
/usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
/usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
collect2: ld returned 1 exit status
make: *** [smap] Error 1

I already changed the Makefile by including the resolv-library (-lresolv)
(a hint in a former fwtk-users-list answere to such a question).
But I think, res_query is not defined there and I cannot find 
(with nm -o -C) another library where it is defined.

I use RedHat 6.1 Linux.

Does anyone have an idea?

Thanks in advance,

Matthias Bormann
 
_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/

   MATTHIAS BORMANN

   Fachgebiet Programmiermethodik
   Fachbereich Informatik, Technische Universitaet Darmstadt

   adress: Alexanderstrasse 10, 64283 Darmstadt, Germany
   fon: +49 6151 16 5668, +49 171 7784 250
   fax: +49 6151 16 6241

   e-mail: bormann@informatik.tu-darmstadt.de
   http://www.inferenzsysteme.informatik.tu-darmstadt.de/~bormann
   pgp-fingerprint: 02146D7545D4FCF7 D3F55B448C30070F

_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/


From owner-fwtk-users@ex.tis.com Tue Sep  5 18:39 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA08740
	Tue, 5 Sep 2000 18:39:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA16489;
	Tue, 5 Sep 2000 15:47:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 5 Sep 2000 14:10:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA02945
	for fwtk-users-outgoing; Tue, 5 Sep 2000 14:10:28 -0700 (PDT)
Message-Id: <4.2.2.20000905165007.00b36dd0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Tue, 05 Sep 2000 16:53:04 -0400
To: Matthias Bormann <bormann@inferenzsysteme.informatik.tu-darmstadt.de>,
        fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: smap / yao-patch
In-Reply-To: <200009051317.PAA00543@kea.inferenzsysteme.informatik.tu-da
 rmstadt.de>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 695

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 03:17 PM 9/5/00 +0200, Matthias Bormann wrote:
>I tried to apply the yao-patch to smap, but
>compiling and linking result in the following error:
>
>cc -g -static -lresolv -o smap smap.o arpadate.o ../libfwall.a -lcrypt
>smap.o: In function `from_address_ok':
>/usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
>/usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'

res_* routines are in libresolv. Move the '-lresolv' to the end of the "cc" 
line; the way you have it, it's probably not being searched.
         -Rick


From owner-fwtk-users@ex.tis.com Wed Sep  6 13:21 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA12956
	Wed, 6 Sep 2000 13:21:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA20959;
	Wed, 6 Sep 2000 10:29:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 6 Sep 2000 08:03:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA04253
	for fwtk-users-outgoing; Wed, 6 Sep 2000 08:02:57 -0700 (PDT)
Date: Tue, 5 Sep 2000 10:56:07 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Matthias Bormann <bormann@inferenzsysteme.informatik.tu-darmstadt.de>
cc: fwtk-users@lists.nai.com
Subject: Re: smap / yao-patch
In-Reply-To: <200009051317.PAA00543@kea.inferenzsysteme.informatik.tu-darmstadt.de>
Message-ID: <Pine.GSO.4.10.10009051055530.6088-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1786

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Looks like you have to add -lresolv to the smap make file

ted keller


On Tue, 5 Sep 2000, Matthias Bormann wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello,
> 
> I tried to apply the yao-patch to smap, but
> compiling and linking result in the following error:
> 
> cc -g -static -lresolv -o smap smap.o arpadate.o ../libfwall.a -lcrypt
> smap.o: In function `from_address_ok':
> /usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
> /usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
> collect2: ld returned 1 exit status
> make: *** [smap] Error 1
> 
> I already changed the Makefile by including the resolv-library (-lresolv)
> (a hint in a former fwtk-users-list answere to such a question).
> But I think, res_query is not defined there and I cannot find 
> (with nm -o -C) another library where it is defined.
> 
> I use RedHat 6.1 Linux.
> 
> Does anyone have an idea?
> 
> Thanks in advance,
> 
> Matthias Bormann
>  
> _/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/
> 
>    MATTHIAS BORMANN
> 
>    Fachgebiet Programmiermethodik
>    Fachbereich Informatik, Technische Universitaet Darmstadt
> 
>    adress: Alexanderstrasse 10, 64283 Darmstadt, Germany
>    fon: +49 6151 16 5668, +49 171 7784 250
>    fax: +49 6151 16 6241
> 
>    e-mail: bormann@informatik.tu-darmstadt.de
>    http://www.inferenzsysteme.informatik.tu-darmstadt.de/~bormann
>    pgp-fingerprint: 02146D7545D4FCF7 D3F55B448C30070F
> 
> _/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/
> 

From owner-fwtk-users@ex.tis.com Wed Sep  6 18:13 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA13776
	Wed, 6 Sep 2000 18:13:13 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA04082;
	Wed, 6 Sep 2000 15:22:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 6 Sep 2000 14:01:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA23436
	for fwtk-users-outgoing; Wed, 6 Sep 2000 14:01:17 -0700 (PDT)
From: bukys@cs.rochester.edu
Date: Wed, 6 Sep 2000 17:00:41 -0400 (EDT)
Message-Id: <200009062100.RAA26355@tern.cs.rochester.edu>
To: fwtk-users@lists.nai.com
Subject: ftp://user:password@host:port/filename
Cc: bukys@cs.rochester.edu
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 727

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Contrary to a previous thread in the mailing list archive (entitled
"Http-gw user:password@site.com URLs"),
	FWTK 2.1 DOES seem to support ftp://user:password@host/filename URLs
	(or at least seems to try), and it IS in RFC1736 (section 3.1).

What FWTK 2.1 doesn't seem to support is ftp://host:port/filename URLs.
It looks easy to add, though, and I will do it -- unless someone can
supply me a patch first.  Please?

Thanks.


Liudvikas Bukys
University of Rochester
Computer Science Department
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747

<bukys@cs.rochester.edu>

From owner-fwtk-users@ex.tis.com Thu Sep  7 14:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA17698
	Thu, 7 Sep 2000 14:01:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA07718;
	Thu, 7 Sep 2000 11:11:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 7 Sep 2000 10:11:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA26870
	for fwtk-users-outgoing; Thu, 7 Sep 2000 10:10:52 -0700 (PDT)
Message-ID: <39B74B62.D5531F8@bofh.maldata.se>
Date: Thu, 07 Sep 2000 10:01:38 +0200
From: =?iso-8859-1?Q?G=F6ran=20H=E4ggsj=F6?= <goha@bofh.maldata.se>
Organization: =?iso-8859-1?Q?M=E5ldata?= Teknik AB
X-Mailer: Mozilla 4.5 [en] (X11; I; SunOS 5.6 sun4m)
X-Accept-Language: sv, en
MIME-Version: 1.0
CC: fwtk-users@ex.tis.com
Subject: Re: Ftp'ing from outside to inside via Netscape
References: <Pine.LNX.4.21.0008312315430.860-100000@iceman.mydomain.ice>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="------------F0333ECB03789E01558121AE"
Content-Length: 2552

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------F0333ECB03789E01558121AE
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

There is a problem with the mapping to the right IP-adress.
You should use a internal nameserver that provides the IP-address on the DMZ as
well as internals.
When you come from the internet there is an external nameserver which resolves
the name.
(If the firewall is a fast machine it can do the nameserving also, but there can
be some traps here).

By the way, have you tried to use IP-adress ?

If that works then you know that it is the DNS-2-IP.

cheers /GoHa

Leandro Gelasi wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> I am using FWTk 2.1 and all works fine.
>
> Now I would like to set up a link on my web server that point to our
> anonymous ftp server.
>
> The anon ftp server is into the dmz and it's correctly reachable
> (from outside) using a ftp client this way :
> ftp firewall.myrealdomain.it
> user ftp@anonserver
> password email@emailsrv.domain
>
> There is an URL that permit to connect to the server from the outside?
> I tried
> ftp://ftp@anonserver:email@emailsrv.domain@firewall.myrealdomain.it
>
> following the ftp://user:password@server.domain syntax but it didn't worked.
>
> Any hints?
>
> TIA
>
> LG
>
> *********************************************************************
> Leandro Gelasi
> V year Computer Science Engineering student at Siena University
> gelasi@interfree.it
>
> Gilles Villeneuve will live forever
> *********************************************************************

--------------F0333ECB03789E01558121AE
Content-Type: text/x-vcard; charset=us-ascii;
 name="goha.vcf"
Content-Description: Card for G–ran H”ggsj–
Content-Disposition: attachment;
 filename="goha.vcf"
Content-Transfer-Encoding: quoted-printable
X-MIME-Autoconverted: from 8bit to quoted-printable by bofh.maldata.se id JAA07265

begin:vcard=20
n:H=E4ggsj=F6;G=F6ran
tel;cell:+46 708 34 4013
tel;work:+46 (0)8 734 4191
x-mozilla-html:FALSE
url:http://www.maldata.se
org:Sigma M=E5ldata Network Systems AB;Security
adr:;;Dalv=E4gen 28;Solna;;S-169 56;Sweden
version:2.1
email;internet:goha@bofh.maldata.se
title:Network Systems Management/Security
x-mozilla-cpt:;29728
fn:G=F6ran H=E4ggsj=F6
end:vcard

--------------F0333ECB03789E01558121AE--

From owner-fwtk-users@ex.tis.com Thu Sep  7 14:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA17696
	Thu, 7 Sep 2000 14:01:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA07714;
	Thu, 7 Sep 2000 11:11:07 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 7 Sep 2000 10:10:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA26678
	for fwtk-users-outgoing; Thu, 7 Sep 2000 10:09:58 -0700 (PDT)
X-Authentication-Warning: gatekeeper.d2000.com: bin set sender to <larry@d2000.com> using -f
Message-Id: <4.3.2.7.0.20000906131156.00d239d0@cpq>
X-Sender: larry@cpq
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Wed, 06 Sep 2000 13:32:48 -0500
To: fwtk-users@ex.tis.com
From: "Larry D. Bonham" <larry@d2000.com>
Subject: ftp-gw problem with Checkpoint
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1873

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Has anyone run into this?

I have FWTK 2.1 with all of the latest ftp patches (as far as I 
know).  ftp-gw has been working fine for years.

A customer upgraded their firewall to the latest version of Checkpoint 
FW-1.  Now when they try to access ftp-gw they get disconnected at this point.

$ ftp gatekeeper.d2000.com
Connected to gatekeeper.d2000.com.
220 gatekeeper.d2000.com FTP proxy (Version V2.1) ready.
Name (fw:root): dummy@web3.d2000.com
331-(

It pukes right here.  According to my sniffer, instead of receiving the 
rest of the 331 message as below.  The client end sends a RST (I assume 
reset) and then tries to resend the username@system command again.  The 
internal server gets confused and disconnects.

----GATEWAY CONNECTED TO web3.d2000.com----)
331-(220 web3.d2000.com NcFTPd Server (licensed copy) ready.)
331 User dummy okay, need password.
Password:

Any patch or fix that anyone is aware of?  I know that it really is a 
Checkpoint problem but that may be more difficult to deal with than 
applying a workable patch on my end.

Thanks

=================================================
Larry D. Bonham     <larry@d2000.com>
Distribution 2000
10401-F Baur
Olivette, MO  63132
Phone: (314)997-4342 x312  /  Fax: (314)997-7814





**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote also confirms that this email message has been swept by
MAILsweeper for the presence of computer viruses.
**********************************************************************

From owner-fwtk-users@ex.tis.com Thu Sep  7 14:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA17697
	Thu, 7 Sep 2000 14:01:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA07724;
	Thu, 7 Sep 2000 11:11:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 7 Sep 2000 10:10:29 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA26676
	for fwtk-users-outgoing; Thu, 7 Sep 2000 10:09:58 -0700 (PDT)
Date: Wed, 6 Sep 2000 16:18:50 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Ted Keller <keller@bfg.com>
Cc: Matthias Bormann <bormann@inferenzsysteme.informatik.tu-darmstadt.de>,
        fwtk-users@lists.nai.com
Subject: Re: smap / yao-patch
Message-Id: <20000906161850.Z19426@washington.cospo.osis.gov>
Mail-Followup-To: Ted Keller <keller@bfg.com>,
	Matthias Bormann <bormann@inferenzsysteme.informatik.tu-darmstadt.de>,
	fwtk-users@lists.nai.com
References: <200009051317.PAA00543@kea.inferenzsysteme.informatik.tu-darmstadt.de> <Pine.GSO.4.10.10009051055530.6088-100000@ns1.bfg.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <Pine.GSO.4.10.10009051055530.6088-100000@ns1.bfg.com>; from keller@bfg.com on Tue, Sep 05, 2000 at 10:56:07AM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2589

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, Sep 05, 2000 at 10:56:07AM -0400, Ted Keller wrote:
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Looks like you have to add -lresolv to the smap make file
> 
> ted keller

He already had added it.  But in the WRONG PLACE.

Matthias, this is why this is a "toolkit".  It assumes experience with
a lot of things.

Library flags, such as -lresolv [or -lres on some systems] must be
added at the END of the compilation command line.  See where "-lcrypt"
is?

> On Tue, 5 Sep 2000, Matthias Bormann wrote:
> 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > Hello,
> > 
> > I tried to apply the yao-patch to smap, but
> > compiling and linking result in the following error:
> > 
> > cc -g -static -lresolv -o smap smap.o arpadate.o ../libfwall.a -lcrypt
> > smap.o: In function `from_address_ok':
> > /usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
> > /usr/local/src/fwtk/smap/smap.c:2054: undefined reference to `res_query'
> > collect2: ld returned 1 exit status
> > make: *** [smap] Error 1
> > 
> > I already changed the Makefile by including the resolv-library (-lresolv)
> > (a hint in a former fwtk-users-list answere to such a question).
> > But I think, res_query is not defined there and I cannot find 
> > (with nm -o -C) another library where it is defined.
> > 
> > I use RedHat 6.1 Linux.
> > 
> > Does anyone have an idea?
> > 
> > Thanks in advance,
> > 
> > Matthias Bormann
> >  
> > _/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/
> > 
> >    MATTHIAS BORMANN
> > 
> >    Fachgebiet Programmiermethodik
> >    Fachbereich Informatik, Technische Universitaet Darmstadt
> > 
> >    adress: Alexanderstrasse 10, 64283 Darmstadt, Germany
> >    fon: +49 6151 16 5668, +49 171 7784 250
> >    fax: +49 6151 16 6241
> > 
> >    e-mail: bormann@informatik.tu-darmstadt.de
> >    http://www.inferenzsysteme.informatik.tu-darmstadt.de/~bormann
> >    pgp-fingerprint: 02146D7545D4FCF7 D3F55B448C30070F
> > 
> > _/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/_/
> > 

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep  8 10:34 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA23343
	Fri, 8 Sep 2000 10:34:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA28798;
	Fri, 8 Sep 2000 07:43:57 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 06:21:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA17039
	for fwtk-users-outgoing; Fri, 8 Sep 2000 06:20:48 -0700 (PDT)
Message-Id: <4.2.2.20000907164105.00b51e10@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Thu, 07 Sep 2000 16:42:41 -0400
To: "Larry D. Bonham" <larry@d2000.com>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw problem with Checkpoint
In-Reply-To: <4.3.2.7.0.20000906131156.00d239d0@cpq>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 743

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 01:32 PM 9/6/00 -0500, Larry D. Bonham wrote:
>[To be removed from this list send the message "unsubscribe fwtk-users" in the
>BODY of a mail message to majordomo@ex.tis.com.]
>
>Has anyone run into this?
>
>I have FWTK 2.1 with all of the latest ftp patches (as far as I 
>know).  ftp-gw has been working fine for years.
>
>A customer upgraded their firewall to the latest version of Checkpoint 
>FW-1.  Now when they try to access ftp-gw they get disconnected at this point.

Firewall-1 requires that FTP connections come from port 20.  There's been 
patches posted in the past to permit this.
         -Rick

From owner-fwtk-users@ex.tis.com Fri Sep  8 12:17 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA23704
	Fri, 8 Sep 2000 12:17:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA23644;
	Fri, 8 Sep 2000 09:26:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 08:27:58 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA09879
	for fwtk-users-outgoing; Fri, 8 Sep 2000 08:27:52 -0700 (PDT)
Message-Id: <v02120d00b5df3f5f8407@[134.60.9.100]>
Mime-Version: 1.0
Date: Fri, 8 Sep 2000 17:22:38 -0800
To: fwtk-users@ex.tis.com
From: heim@sip.medizin.uni-ulm.de (Stefan Heim, Dipl.-Ing.)
Subject: fwtk under IRIX 
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 596

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear All:

Does anybody use fwtk on IRIX 5.2 ?

Please share your experience (Makefile.config, etc.).

Thanks!

/--------------------------------o00-----00o-------------------------\
Stefan Heim

Uni Ulm
Sektion Informatik in der Psychotherapie
Am Hochstraess 8
89081 Ulm
Germany
E-Mail: heim@sip.Medizin.Uni-Ulm.de
http://sip.medizin.uni-ulm.de
Tel: +49-(0)731-50-25702 Fax: +49-(0)731-50-25662
\-------------------------------ooo0-----0ooOo---------------------/



From owner-fwtk-users@ex.tis.com Fri Sep  8 14:14 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA24056
	Fri, 8 Sep 2000 14:14:51 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA23399;
	Fri, 8 Sep 2000 11:24:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 10:24:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA08266
	for fwtk-users-outgoing; Fri, 8 Sep 2000 10:23:57 -0700 (PDT)
Date: Fri, 8 Sep 2000 13:20:03 -0400 (EDT)
X-Authentication-Warning: conch.msen.com: mjo set sender to mjo@dojo.mi.org using -f
Subject: Re: fwtk under IRIX 
To: fwtk-users@tis.com (TIS FWTK Mailing List)
Late: Fri, 8 Sep 100 13:20:03 -0400 (EDT)
From: "Mike O'Connor" <mjo@dojo.mi.org>
Reply-To: "Mike O'Connor" <mjo@dojo.mi.org>
Message-Id: <000908132003.mjo@dojo.mi.org>
X-Organization: :noitazinagrO-X
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 875

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

:Does anybody use fwtk on IRIX 5.2 ?
:
:Please share your experience (Makefile.config, etc.).

That wouldn't be a terribly secure or stable OS with which to start
running fwtk on.  I'd suggest either IRIX 6.2 or 5.3, but not IRIX 6.5
since it is too bloated for the IRIX 5.2-vintage hardware.

I ran a subset of fwtk on IRIX 6.2 a _long_ time ago, and was able to
get what I needed to work.  I probably used the 7.2 compilers.  

-- 
 Michael J. O'Connor | WWW: http://dojo.mi.org/~mjo/ | Email: mjo@dojo.mi.org
 Royal Oak, Michigan | (has my PGP & Geek Code info) | Phone: +1 248-848-4481
 =--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--=
"I think the word you're looking for is 'space ranger'."      -Buzz Lightyear

From owner-fwtk-users@ex.tis.com Fri Sep  8 15:00 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA24245
	Fri, 8 Sep 2000 15:00:51 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA03418;
	Fri, 8 Sep 2000 12:10:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 11:15:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA21277
	for fwtk-users-outgoing; Fri, 8 Sep 2000 11:15:41 -0700 (PDT)
Date: Fri, 8 Sep 2000 14:14:42 -0400 (EDT)
Message-Id: <200009081814.OAA04502@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for URL scheme case insensitivity
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2490

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

According to RFC1738 http://www.ietf.org/rfc/rfc1738.txt?number=1738

``	For resiliency, programs interpreting URLs should treat upper
	case letters as equivalent to lower case in scheme names (e.g.,
	allow "HTTP" as well as "http").	''

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>


*** http-gw.c	1998/09/24 14:53:52	1.1
--- http-gw.c	2000/09/08 15:17:49
***************
*** 436,438 ****
  	if( parse_vec[3] == NULL){
! 		if( ourport && !strcmp(parse_vec[2], ourname)){
  			sprintf(url_port,"%d", ourport);
--- 436,438 ----
  	if( parse_vec[3] == NULL){
! 		if( ourport && !strcasecmp(parse_vec[2], ourname)){
  			sprintf(url_port,"%d", ourport);
***************
*** 637,639 ****
  /* Now look for our special formats (URL's) */
! 	if( !strncmp(path, "gopher://", 9)){
  		ret &= ~MASK_BASE;
--- 637,639 ----
  /* Now look for our special formats (URL's) */
! 	if( !strncasecmp(path, "gopher://", 9)){
  		ret &= ~MASK_BASE;
***************
*** 657,659 ****
  		return ret;
! 	}else if( !strncmp(path, "http://", 7)){
  		ret &= ~MASK_BASE;
--- 657,659 ----
  		return ret;
! 	}else if( !strncasecmp(path, "http://", 7)){
  		ret &= ~MASK_BASE;
***************
*** 668,670 ****
  
! 	}else if( !strncmp(path, "ftp://", 6) || !strncmp(path, "file://", 7)){
  		ret &= ~MASK_BASE;
--- 668,670 ----
  
! 	}else if( !strncasecmp(path, "ftp://", 6) || !strncasecmp(path, "file://", 7)){
  		ret &= ~MASK_BASE;
***************
*** 764,766 ****
  	case 'e':
! 		if(strncmp(buf, "exec:", 5)== 0){
  			ret = TYPE_EXEC;
--- 764,766 ----
  	case 'e':
! 		if(strncasecmp(buf, "exec:", 5)== 0){
  			ret = TYPE_EXEC;
***************
*** 770,772 ****
  	case 'f':
! 		if(strncmp(buf, "ftp:", 4) == 0){
  			ret = parse_ftp(buf);
--- 770,772 ----
  	case 'f':
! 		if(strncasecmp(buf, "ftp:", 4) == 0){
  			ret = parse_ftp(buf);
***************
*** 776,781 ****
  	case 'w':
! 		if(strncmp(buf, "waissrc:", 8)== 0){
  			ret = TYPE_WAIS|TYPE_DIR;
  		}
! 		if( strncmp(buf, "waisdocid:", 10) == 0){
  			ret = TYPE_WAIS;
--- 776,781 ----
  	case 'w':
! 		if(strncasecmp(buf, "waissrc:", 8)== 0){
  			ret = TYPE_WAIS|TYPE_DIR;
  		}
! 		if( strncasecmp(buf, "waisdocid:", 10) == 0){
  			ret = TYPE_WAIS;


From owner-fwtk-users@ex.tis.com Fri Sep  8 15:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA24248
	Fri, 8 Sep 2000 15:01:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA03468;
	Fri, 8 Sep 2000 12:10:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 11:19:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA22055
	for fwtk-users-outgoing; Fri, 8 Sep 2000 11:18:59 -0700 (PDT)
Date: Fri, 8 Sep 2000 14:18:04 -0400 (EDT)
Message-Id: <200009081818.OAA04518@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for displaying entire version string in error output
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 698

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

What is the point of omitting the first word of the version string
in the http-gw error message?

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>

-------------------------------------------------------------------------------

diff -r1.1 error.c
62c62
< 		while(*p && *p != ' ')p++;
---
> 		/* while(*p && *p != ' ')p++; */

-------------------------------------------------------------------------------


From owner-fwtk-users@ex.tis.com Fri Sep  8 15:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA24252
	Fri, 8 Sep 2000 15:01:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA03623;
	Fri, 8 Sep 2000 12:11:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 11:20:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA22448
	for fwtk-users-outgoing; Fri, 8 Sep 2000 11:20:32 -0700 (PDT)
Date: Fri, 8 Sep 2000 14:19:41 -0400 (EDT)
Message-Id: <200009081819.OAA04530@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for displaying entire version string in error output
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1555

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

If you try an FTP URL with a port number (try ftp://localhost:666),
you'll find that FWTK 2.1 overrides the user-specified port, forcing it
to port 21.  The reason it did that was because the http-gw.c code
defaulted the port number to 80 for FTP URLs, and the (incorrect)
workaround was to force it to 21 in all cases.  The enclosed patch
defaults to port 21, then allows the user to override with the URL.

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>

-------------------------------------------------------------------------------

*** ftp.c	1998/09/24 14:53:52	1.1
--- ftp.c	2000/09/08 16:54:32
***************
*** 281,286 ****
  
! 	port = FTPPORT;
! 	port = get_port(host, port);
! 	rem_port = port;
! 
  
--- 281,289 ----
  
! 	if( rem_port == 0){
! 		port = FTPPORT;
! 		port = get_port(host, port);
! 		rem_port = port;
! 	}else{
! 		port = rem_port;
! 	}
  
-------------------------------------------------------------------------------

*** http-gw.c	2000/09/08 15:24:21	1.3
--- http-gw.c	2000/09/08 17:43:28
***************
*** 441,442 ****
--- 441,444 ----
  			parse_vec[3] = "70";
+ 		else if (!strcasecmp(parse_vec[0], "ftp"))
+ 			parse_vec[3] = "21";
  		else

-------------------------------------------------------------------------------

From owner-fwtk-users@ex.tis.com Fri Sep  8 16:07 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA24505
	Fri, 8 Sep 2000 16:07:26 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA19604;
	Fri, 8 Sep 2000 13:16:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 12:10:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA03515
	for fwtk-users-outgoing; Fri, 8 Sep 2000 12:10:41 -0700 (PDT)
Date: Fri, 8 Sep 2000 15:09:34 -0400 (EDT)
Message-Id: <200009081909.PAA04723@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for correct handling of ftp: URLs with port numbers
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1769

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[Previously sent about an hour ago with the correct contents but the
wrong Subject.  I'm resending it "for the record", as the preceding
messages were trivial problems that I fixed on the way to fixing this one.]

If you try an FTP URL with a port number (try ftp://localhost:666),
you'll find that FWTK 2.1 overrides the user-specified port, forcing it
to port 21.  The reason it did that was because the http-gw.c code
defaulted the port number to 80 for FTP URLs, and the (incorrect)
workaround was to force it to 21 in all cases.  The enclosed patch
defaults to port 21, then allows the user to override with the URL.

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>

-------------------------------------------------------------------------------

*** ftp.c	1998/09/24 14:53:52	1.1
--- ftp.c	2000/09/08 16:54:32
***************
*** 281,286 ****
  
! 	port = FTPPORT;
! 	port = get_port(host, port);
! 	rem_port = port;
! 
  
--- 281,289 ----
  
! 	if( rem_port == 0){
! 		port = FTPPORT;
! 		port = get_port(host, port);
! 		rem_port = port;
! 	}else{
! 		port = rem_port;
! 	}
  
-------------------------------------------------------------------------------

*** http-gw.c	2000/09/08 15:24:21	1.3
--- http-gw.c	2000/09/08 17:43:28
***************
*** 441,442 ****
--- 441,444 ----
  			parse_vec[3] = "70";
+ 		else if (!strcasecmp(parse_vec[0], "ftp"))
+ 			parse_vec[3] = "21";
  		else

-------------------------------------------------------------------------------

From owner-fwtk-users@ex.tis.com Fri Sep  8 17:20 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA24691
	Fri, 8 Sep 2000 17:20:01 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA03424;
	Fri, 8 Sep 2000 14:29:11 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 13:31:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA23267
	for fwtk-users-outgoing; Fri, 8 Sep 2000 13:31:33 -0700 (PDT)
Date: Fri, 8 Sep 2000 16:31:11 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Scott Newton <scott@quanta.co.nz>
Cc: fwtk-users@ex.tis.com
Subject: Re: Mail relaying (one direction only)
Message-Id: <20000908163111.K6517@washington.cospo.osis.gov>
Mail-Followup-To: Scott Newton <scott@quanta.co.nz>, fwtk-users@ex.tis.com
References: <399B2127.ACDD61F8@quanta.co.nz>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <399B2127.ACDD61F8@quanta.co.nz>; from scott@quanta.co.nz on Thu, Aug 17, 2000 at 11:17:59AM +1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 976

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Aug 17, 2000 at 11:17:59AM +1200, Scott Newton wrote:
...
> We have a situation where we have a mail server internal to the
> firewall and want to be able to relay all mail from the server
> through the firewall (running smap + yao patches) to our ISP, but
> block any messages coming in that are not for our domain.  I am able
> 
> to allow both directions on the firewall or deny both directions on
> the firewall, but can not find the correct combination of
> hosts/domains to allow out but not in. Can someone please help
...

smap: domains quanta.co.nz *.quanta.co.nz
smap: hosts quanta.co.nz *.quanta.co.nz

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep  8 17:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA24737
	Fri, 8 Sep 2000 17:33:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA05951;
	Fri, 8 Sep 2000 14:42:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 13:55:27 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA27501
	for fwtk-users-outgoing; Fri, 8 Sep 2000 13:55:16 -0700 (PDT)
Date: Fri, 8 Sep 2000 16:54:36 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Malcolm Tester <MTester@cambric.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: plug-gw
Message-Id: <20000908165436.L6517@washington.cospo.osis.gov>
Mail-Followup-To: Malcolm Tester <MTester@cambric.com>,
	fwtk-users@lists.nai.com
References: <CAE0A17F1713D311A44500105A16C90B6531B9@bush.cambric.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <CAE0A17F1713D311A44500105A16C90B6531B9@bush.cambric.com>; from MTester@cambric.com on Mon, Aug 28, 2000 at 10:14:42AM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 976

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, Aug 28, 2000 at 10:14:42AM -0600, Malcolm Tester wrote:
> on this same topic, can anyone recommend a good (free) pop3 server?

Qualcomm Qpopper.  Cf. <URL: http://www.eudora.com/qpopper/>.

> What I need is to be able to sit at a client on the inside, and pull pop3
> mail from and send it to the outside world through the fw.  The firewall
> itself would not be performing any mail activities.  If I use plug-gw to
> plug it, would it be  plug-to internal address for incoming mail and plug-to
> external machine for outgoing? Or some other way?

Generally not advisable but if you can avoid it, but some can't.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep  8 17:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA24816
	Fri, 8 Sep 2000 17:56:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA11058;
	Fri, 8 Sep 2000 15:05:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 14:19:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA01770
	for fwtk-users-outgoing; Fri, 8 Sep 2000 14:19:10 -0700 (PDT)
Date: Fri, 8 Sep 2000 17:18:46 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Jan Muenther <jan@radio.hundert6.de>
Cc: fwtk-users@ex.tis.com
Subject: Re: smap standalone?
Message-Id: <20000908171846.O6517@washington.cospo.osis.gov>
Mail-Followup-To: Jan Muenther <jan@radio.hundert6.de>,
	fwtk-users@ex.tis.com
References: <39B4C372.78A973FD@radio.hundert6.de>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <39B4C372.78A973FD@radio.hundert6.de>; from jan@radio.hundert6.de on Tue, Sep 05, 2000 at 11:57:06AM +0200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 643

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, Sep 05, 2000 at 11:57:06AM +0200, Jan Muenther wrote:
> I want to use smap as an addition to an otherwise only
> filter-based firewall. 
> Can it be run independent from the rest of the fwtk?

Yes, certainly.  Also good for running, e.g., with Raptor instead of
their mail thing.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep  8 17:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA24819
	Fri, 8 Sep 2000 17:56:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA11070;
	Fri, 8 Sep 2000 15:06:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 14:16:53 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA01222
	for fwtk-users-outgoing; Fri, 8 Sep 2000 14:16:42 -0700 (PDT)
Date: Fri, 8 Sep 2000 17:16:22 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Jonathan Marchand <jonathanm@webnet.qc.ca>
Cc: fwtk-support@tis.com, fwtk-users@tis.com
Subject: Re: FTP Behind Masquerade?
Message-Id: <20000908171622.N6517@washington.cospo.osis.gov>
Mail-Followup-To: Jonathan Marchand <jonathanm@webnet.qc.ca>,
	fwtk-support@tis.com, fwtk-users@tis.com
References: <384272173.967802695549.JavaMail.root@web307-mc.mail.com> <005b01c01449$ad7ea460$c93b0dd8@webnet.qc.ca>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <005b01c01449$ad7ea460$c93b0dd8@webnet.qc.ca>; from jonathanm@webnet.qc.ca on Fri, Sep 01, 2000 at 03:20:23PM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1587

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 01, 2000 at 03:20:23PM -0400, Jonathan Marchand wrote:
...
> I just setup a linux box with masquerading enabled. Behind it, there's a
> win2k machine. It runs an ftp server. I did a redirection for port 21 on the
> linux to that internal host. But, I only get ftp to work in passive mode. It
> won't work in active/normal mode. Why is that? How can I fix it? Is it
> possible?
> 
> I inserted the ip_masq_ftp.o module on the linux, but it just says "unused"
> when I do a lsmod, I'm not sure if it ip_masq_ftp is supposed to help in any
> way for what I want to do. When I try to ftp (from the outside) to my ftp
> behind the masquerade, I just get:
> 
> 500 Invalid PORT Command.
> ftp: bind: Address already in use
> 
> But if I set my client in passive mode, it work fine. So, is there anything
> I could do to make it work in normal mode?

FTP is a full-duplex protocol, with each direction over a separate
channel.  The client initiates a connection to the server, but then the
server initiates a second connection back to the client.  With some
forms of masquerading, the second connection cannot be made.  So, you
can't do active FTP.  Passive works fine, since it's a half-duplex
protocol over a single channel.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep  8 17:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA24822
	Fri, 8 Sep 2000 17:56:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA11062;
	Fri, 8 Sep 2000 15:05:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 14:14:23 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA00704
	for fwtk-users-outgoing; Fri, 8 Sep 2000 14:14:01 -0700 (PDT)
Date: Fri, 8 Sep 2000 17:13:00 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: swilso39@csc.com
Cc: fwtk-users@lists.nai.com, uce@ftc.gov, abuse@ers.state.tx.us,
        postmaster@ers.state.tx.us, webmaster@ers.state.tx.us,
        hostmaster@ers.state.tx.us
Subject: Re: SMAP/SMAPD
Message-Id: <20000908171300.M6517@washington.cospo.osis.gov>
Mail-Followup-To: swilso39@csc.com, fwtk-users@lists.nai.com, uce@ftc.gov,
	abuse@ers.state.tx.us, postmaster@ers.state.tx.us,
	webmaster@ers.state.tx.us, hostmaster@ers.state.tx.us
References: <0025694D.00301D56.00@uk-fbr10.eu.csc.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <0025694D.00301D56.00@uk-fbr10.eu.csc.com>; from swilso39@csc.com on Fri, Sep 01, 2000 at 09:41:05AM +0100
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2247

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 01, 2000 at 09:41:05AM +0100, swilso39@csc.com wrote:
...
> Im a newbie to all this so forgive me if I make a complete idiot of myself with
> my explanation!
> 
> Im running a recent version of SMAP and SMAPD, and for the past three months
> have had no problems (that I am aware of!).
> Recently I have noticed that my log files have been growing at a major rate.
> This is all due to the same message appearing literally all the time :
> 
> 
> Sep  1 08:29:16 nadsc6 smap[505]: connect host=unknown/195.217.247.18
> Sep  1 08:29:16 nadsc6 smap[500]: Relay: <twngirl@cyberway.com.sg>
> <lists@headland.co.uk> (195.217.247.18)
> 
> Although the first address after ":Relay: <" may change frequently the second
> address is pretty much consistent (domain is anyway!)
> 
> Does anybody know what is going on with this or do I have some sort of localised
> problem?

Almost certainly, some evil spammer is using your firewall to send
e-mail SPAM to scores of unwitting victims all over the world.

Go to www.fwtk.org, download the set of patches that I compiled and
proofed for smap ["smap-yao patches"].  Install them.  Tell your
firewall to ONLY let mail in for your domain, and to ONLY let your mail
servers [or your whole domain] send e-mail via your firewall.  End of
problem.

If you can, get someone to throw nasty spammer at "195.217.247.18"
completely off the Internet.  For twenty seconds, anyway.

Hmmmm ...
18.247.217.195.in-addr.arpa     canonical name = 18.16.247.217.195.in-addr.arpa

Authoritative answers can be found from:
in-addr.arpa    nameserver = ns.ers.state.tx.us.in-addr.arpa
...
*** No address information is available for "18.16.247.217.195.in-addr.arpa."

You are being used as a SPAM relay by someone working for the State of
Texas in the USA!  This is a criminal action!  I am cc'ing the
Employees Retirement System, State of Texas, USA.  And the FTC.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Sat Sep  9 12:07 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA17523
	Sat, 9 Sep 2000 12:07:00 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA19168;
	Sat, 9 Sep 2000 09:16:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 9 Sep 2000 08:15:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA15750
	for fwtk-users-outgoing; Sat, 9 Sep 2000 08:15:50 -0700 (PDT)
Message-ID: <001601bb8605$a0d6a2c0$23c7c7c7@seclab.sharif.ac.ir>
From: "Hossein Pourreza" <pourreza@hadid.sharif.ac.ir>
To: <fwtk-users@ex.tis.com>
References: <39B4C372.78A973FD@radio.hundert6.de> <20000908171846.O6517@washington.cospo.osis.gov>
Subject: Problem in downloading
Date: Fri, 9 Aug 1996 19:45:40 +0430
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2314.1300
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 559

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi to all,
    I downloaded and worked with FWTK but It doesn't pop-gw.
I wanna to download it but when I want to connect to ftp server it rejects
me.
I connect from a server that has valid IP and DNS name and It is my mail
server too so I think its
DNS works well but the FWTK server tells me that your reverse DNS lookup
faild.
Can some one mail me pop-gw or someone has souloution for this.
Any suggestion will be appreciated


From owner-fwtk-users@ex.tis.com Sat Sep  9 12:07 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA17528
	Sat, 9 Sep 2000 12:07:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA19172;
	Sat, 9 Sep 2000 09:16:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 9 Sep 2000 08:01:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA15151
	for fwtk-users-outgoing; Sat, 9 Sep 2000 08:01:12 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000909105254.00bb4960@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Sat, 09 Sep 2000 10:58:01 -0400
To: "Larry D. Bonham" <root@d2000.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw problem with Checkpoint
Cc: fwtk-users@ex.tis.com
In-Reply-To: <Pine.SCO.3.96.1000908105302.10208B-100000@pro.d2000.com>
References: <4.2.2.20000907164105.00b51e10@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 892

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:10 AM 9/8/00 -0500, Larry D. Bonham wrote:
>Rick,
>
>Thanks for the response.  We had already had the default port setting at
>port 20.  We dealt with that problem quite some time ago.

Rats. Never anything easy.


>As it turns out I had to do a little slash and burn.  I disabled most of
>the entire sendsaved() function and sent it directly to flushsaved().  For
>whatever reason the Checkpoint proxy couldn't (wouldn't) handle the
>multiline response 331-.

That's probably a side effect of Checkpoint's "patch" to fix their FTP 
vulnerability. That's the only time ftp-gw adds anything to the 
interaction, so your change shouldn't have any effect (authenticated ftp 
users will probably break, though, if you're using authentication.)
         -Rick



From owner-fwtk-users@ex.tis.com Mon Sep 11 09:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21675
	Mon, 11 Sep 2000 09:36:26 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18624;
	Mon, 11 Sep 2000 06:45:46 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:09:43 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA23363
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:09:26 -0700 (PDT)
Date: Fri, 8 Sep 2000 17:18:46 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Jan Muenther <jan@radio.hundert6.de>
Cc: fwtk-users@ex.tis.com
Subject: Re: smap standalone?
Message-Id: <20000908171846.O6517@washington.cospo.osis.gov>
Mail-Followup-To: Jan Muenther <jan@radio.hundert6.de>,
	fwtk-users@ex.tis.com
References: <39B4C372.78A973FD@radio.hundert6.de>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <39B4C372.78A973FD@radio.hundert6.de>; from jan@radio.hundert6.de on Tue, Sep 05, 2000 at 11:57:06AM +0200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 776

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, Sep 05, 2000 at 11:57:06AM +0200, Jan Muenther wrote:
 > I want to use smap as an addition to an otherwise only
 > filter-based firewall. 
 > Can it be run independent from the rest of the fwtk?

Yes, certainly.  Also good for running, e.g., with Raptor instead of
their mail thing.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21678
	Mon, 11 Sep 2000 09:36:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18636;
	Mon, 11 Sep 2000 06:45:45 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:09:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA23362
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:09:25 -0700 (PDT)
Date: Fri, 8 Sep 2000 17:16:22 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Jonathan Marchand <jonathanm@webnet.qc.ca>
Cc: fwtk-support@tis.com, fwtk-users@tis.com
Subject: Re: FTP Behind Masquerade?
Message-Id: <20000908171622.N6517@washington.cospo.osis.gov>
Mail-Followup-To: Jonathan Marchand <jonathanm@webnet.qc.ca>,
	fwtk-support@tis.com, fwtk-users@tis.com
References: <384272173.967802695549.JavaMail.root@web307-mc.mail.com> <005b01c01449$ad7ea460$c93b0dd8@webnet.qc.ca>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <005b01c01449$ad7ea460$c93b0dd8@webnet.qc.ca>; from jonathanm@webnet.qc.ca on Fri, Sep 01, 2000 at 03:20:23PM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1733

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 01, 2000 at 03:20:23PM -0400, Jonathan Marchand wrote:
...
 > I just setup a linux box with masquerading enabled. Behind it, there's a
 > win2k machine. It runs an ftp server. I did a redirection for port 21 on the
 > linux to that internal host. But, I only get ftp to work in passive mode. It
 > won't work in active/normal mode. Why is that? How can I fix it? Is it
 > possible?
 > 
 > I inserted the ip_masq_ftp.o module on the linux, but it just says "unused"
 > when I do a lsmod, I'm not sure if it ip_masq_ftp is supposed to help in any
 > way for what I want to do. When I try to ftp (from the outside) to my ftp
 > behind the masquerade, I just get:
 > 
 > 500 Invalid PORT Command.
 > ftp: bind: Address already in use
 > 
 > But if I set my client in passive mode, it work fine. So, is there anything
 > I could do to make it work in normal mode?

FTP is a full-duplex protocol, with each direction over a separate
channel.  The client initiates a connection to the server, but then the
server initiates a second connection back to the client.  With some
forms of masquerading, the second connection cannot be made.  So, you
can't do active FTP.  Passive works fine, since it's a half-duplex
protocol over a single channel.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21682
	Mon, 11 Sep 2000 09:36:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18611;
	Mon, 11 Sep 2000 06:45:50 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 04:56:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA21241
	for fwtk-users-outgoing; Mon, 11 Sep 2000 04:56:08 -0700 (PDT)
X-Authentication-Warning: gatekeeper.d2000.com: bin set sender to <root@d2000.com> using -f
Date: Fri, 8 Sep 2000 11:10:14 -0500 (CDT)
From: "Larry D. Bonham" <root@d2000.com>
To: Rick Murphy <rmurphy@itm-inst.com>
cc: fwtk-users@ex.tis.com
Subject: Re: ftp-gw problem with Checkpoint
In-Reply-To: <4.2.2.20000907164105.00b51e10@mail.itm-inst.com>
Message-ID: <Pine.SCO.3.96.1000908105302.10208B-100000@pro.d2000.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2551

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick,

Thanks for the response.  We had already had the default port setting at
port 20.  We dealt with that problem quite some time ago.

As it turns out I had to do a little slash and burn.  I disabled most of
the entire sendsaved() function and sent it directly to flushsaved().  For
whatever reason the Checkpoint proxy couldn't (wouldn't) handle the
multiline response 331-.

The best I can tell everything is working.  It didn't break it for other
clients that could handle the multiline.  It just appears that it is
sending less information back to the client.  Most of the users are
utilizing send/wait scripting (expect) so I assume they are only looking
for the last lines anyway.

There must more to this than I am realizing.  What other effects might
this have?  Everything that I have tested with so far seems to work (DIR,
CD, PWD, GET, PUT, BINARY, ASCII).  We don't do much more than the basics.

Thanks for your help.

Larry B.



On Thu, 7 Sep 2000, Rick Murphy wrote:

 > At 01:32 PM 9/6/00 -0500, Larry D. Bonham wrote:
 > >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 > >BODY of a mail message to majordomo@ex.tis.com.]
 > >
 > >Has anyone run into this?
 > >
 > >I have FWTK 2.1 with all of the latest ftp patches (as far as I 
 > >know).  ftp-gw has been working fine for years.
 > >
 > >A customer upgraded their firewall to the latest version of Checkpoint 
 > >FW-1.  Now when they try to access ftp-gw they get disconnected at this point.
 > 
 > Firewall-1 requires that FTP connections come from port 20.  There's been 
 > patches posted in the past to permit this.
 >          -Rick
 > 

=====================================================
Larry D. Bonham           Email: larry@d2000.com
Distribution 2000         Phone: (314)997-4342 x312
1160 Research Blvd.       Fax  : (314)997-7814
St. Louis, MO  63132
=====================================================




**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote also confirms that this email message has been swept by
MAILsweeper for the presence of computer viruses.
**********************************************************************


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21688
	Mon, 11 Sep 2000 09:36:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18620;
	Mon, 11 Sep 2000 06:45:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:11:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA23760
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:11:23 -0700 (PDT)
Date: Fri, 8 Sep 2000 16:54:36 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Malcolm Tester <MTester@cambric.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: plug-gw
Message-Id: <20000908165436.L6517@washington.cospo.osis.gov>
Mail-Followup-To: Malcolm Tester <MTester@cambric.com>,
	fwtk-users@lists.nai.com
References: <CAE0A17F1713D311A44500105A16C90B6531B9@bush.cambric.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <CAE0A17F1713D311A44500105A16C90B6531B9@bush.cambric.com>; from MTester@cambric.com on Mon, Aug 28, 2000 at 10:14:42AM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1112

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, Aug 28, 2000 at 10:14:42AM -0600, Malcolm Tester wrote:
 > on this same topic, can anyone recommend a good (free) pop3 server?

Qualcomm Qpopper.  Cf. <URL: http://www.eudora.com/qpopper/>.

 > What I need is to be able to sit at a client on the inside, and pull pop3
 > mail from and send it to the outside world through the fw.  The firewall
 > itself would not be performing any mail activities.  If I use plug-gw to
 > plug it, would it be  plug-to internal address for incoming mail and plug-to
 > external machine for outgoing? Or some other way?

Generally not advisable but if you can avoid it, but some can't.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21707
	Mon, 11 Sep 2000 09:37:01 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18142;
	Mon, 11 Sep 2000 06:44:45 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:06:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22778
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:06:11 -0700 (PDT)
Date: Fri, 8 Sep 2000 13:20:03 -0400 (EDT)
X-Authentication-Warning: conch.msen.com: mjo set sender to mjo@dojo.mi.org using -f
Subject: Re: fwtk under IRIX 
To: fwtk-users@tis.com (TIS FWTK Mailing List)
Late: Fri, 8 Sep 100 13:20:03 -0400 (EDT)
From: "Mike O'Connor" <mjo@dojo.mi.org>
Reply-To: "Mike O'Connor" <mjo@dojo.mi.org>
Message-Id: <000908132003.mjo@dojo.mi.org>
X-Organization: :noitazinagrO-X
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1008

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

:Does anybody use fwtk on IRIX 5.2 ?
:
:Please share your experience (Makefile.config, etc.).

That wouldn't be a terribly secure or stable OS with which to start
running fwtk on.  I'd suggest either IRIX 6.2 or 5.3, but not IRIX 6.5
since it is too bloated for the IRIX 5.2-vintage hardware.

I ran a subset of fwtk on IRIX 6.2 a _long_ time ago, and was able to
get what I needed to work.  I probably used the 7.2 compilers.  

-- 
  Michael J. O'Connor | WWW: http://dojo.mi.org/~mjo/ | Email: mjo@dojo.mi.org
  Royal Oak, Michigan | (has my PGP & Geek Code info) | Phone: +1 248-848-4481
  =--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--=
"I think the word you're looking for is 'space ranger'."      -Buzz Lightyear


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21708
	Mon, 11 Sep 2000 09:37:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18449;
	Mon, 11 Sep 2000 06:45:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:02:32 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22129
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:02:20 -0700 (PDT)
Date: Fri, 8 Sep 2000 14:18:04 -0400 (EDT)
Message-Id: <200009081818.OAA04518@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for displaying entire version string in error output
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 829

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

What is the point of omitting the first word of the version string
in the http-gw error message?

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>

-------------------------------------------------------------------------------

diff -r1.1 error.c
62c62
< 		while(*p && *p != ' ')p++;
---
 > 		/* while(*p && *p != ' ')p++; */

-------------------------------------------------------------------------------



From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21713
	Mon, 11 Sep 2000 09:37:04 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18772;
	Mon, 11 Sep 2000 06:46:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:04:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22417
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:04:30 -0700 (PDT)
Date: Fri, 8 Sep 2000 14:19:41 -0400 (EDT)
Message-Id: <200009081819.OAA04530@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for displaying entire version string in error output
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1691

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

If you try an FTP URL with a port number (try ftp://localhost:666),
you'll find that FWTK 2.1 overrides the user-specified port, forcing it
to port 21.  The reason it did that was because the http-gw.c code
defaulted the port number to 80 for FTP URLs, and the (incorrect)
workaround was to force it to 21 in all cases.  The enclosed patch
defaults to port 21, then allows the user to override with the URL.

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>

-------------------------------------------------------------------------------

*** ftp.c	1998/09/24 14:53:52	1.1
--- ftp.c	2000/09/08 16:54:32
***************
*** 281,286 ****
   
! 	port = FTPPORT;
! 	port = get_port(host, port);
! 	rem_port = port;
! 
   
--- 281,289 ----
   
! 	if( rem_port == 0){
! 		port = FTPPORT;
! 		port = get_port(host, port);
! 		rem_port = port;
! 	}else{
! 		port = rem_port;
! 	}
   
-------------------------------------------------------------------------------

*** http-gw.c	2000/09/08 15:24:21	1.3
--- http-gw.c	2000/09/08 17:43:28
***************
*** 441,442 ****
--- 441,444 ----
   			parse_vec[3] = "70";
+ 		else if (!strcasecmp(parse_vec[0], "ftp"))
+ 			parse_vec[3] = "21";
   		else

-------------------------------------------------------------------------------


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21717
	Mon, 11 Sep 2000 09:37:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18445;
	Mon, 11 Sep 2000 06:45:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:05:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22606
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:05:18 -0700 (PDT)
Date: Fri, 8 Sep 2000 15:09:34 -0400 (EDT)
Message-Id: <200009081909.PAA04723@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for correct handling of ftp: URLs with port numbers
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1905

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[Previously sent about an hour ago with the correct contents but the
wrong Subject.  I'm resending it "for the record", as the preceding
messages were trivial problems that I fixed on the way to fixing this one.]

If you try an FTP URL with a port number (try ftp://localhost:666),
you'll find that FWTK 2.1 overrides the user-specified port, forcing it
to port 21.  The reason it did that was because the http-gw.c code
defaulted the port number to 80 for FTP URLs, and the (incorrect)
workaround was to force it to 21 in all cases.  The enclosed patch
defaults to port 21, then allows the user to override with the URL.

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>

-------------------------------------------------------------------------------

*** ftp.c	1998/09/24 14:53:52	1.1
--- ftp.c	2000/09/08 16:54:32
***************
*** 281,286 ****
   
! 	port = FTPPORT;
! 	port = get_port(host, port);
! 	rem_port = port;
! 
   
--- 281,289 ----
   
! 	if( rem_port == 0){
! 		port = FTPPORT;
! 		port = get_port(host, port);
! 		rem_port = port;
! 	}else{
! 		port = rem_port;
! 	}
   
-------------------------------------------------------------------------------

*** http-gw.c	2000/09/08 15:24:21	1.3
--- http-gw.c	2000/09/08 17:43:28
***************
*** 441,442 ****
--- 441,444 ----
   			parse_vec[3] = "70";
+ 		else if (!strcasecmp(parse_vec[0], "ftp"))
+ 			parse_vec[3] = "21";
   		else

-------------------------------------------------------------------------------


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21720
	Mon, 11 Sep 2000 09:37:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18799;
	Mon, 11 Sep 2000 06:46:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 04:53:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA20728
	for fwtk-users-outgoing; Mon, 11 Sep 2000 04:53:19 -0700 (PDT)
Message-Id: <4.2.2.20000907164105.00b51e10@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Thu, 07 Sep 2000 16:42:41 -0400
To: "Larry D. Bonham" <larry@d2000.com>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw problem with Checkpoint
In-Reply-To: <4.3.2.7.0.20000906131156.00d239d0@cpq>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 884

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 01:32 PM 9/6/00 -0500, Larry D. Bonham wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >Has anyone run into this?
 >
 >I have FWTK 2.1 with all of the latest ftp patches (as far as I 
 >know).  ftp-gw has been working fine for years.
 >
 >A customer upgraded their firewall to the latest version of Checkpoint 
 >FW-1.  Now when they try to access ftp-gw they get disconnected at this point.

Firewall-1 requires that FTP connections come from port 20.  There's been 
patches posted in the past to permit this.
          -Rick


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21721
	Mon, 11 Sep 2000 09:37:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18777;
	Mon, 11 Sep 2000 06:46:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:07:59 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22987
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:07:40 -0700 (PDT)
Date: Fri, 8 Sep 2000 16:31:11 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Scott Newton <scott@quanta.co.nz>
Cc: fwtk-users@ex.tis.com
Subject: Re: Mail relaying (one direction only)
Message-Id: <20000908163111.K6517@washington.cospo.osis.gov>
Mail-Followup-To: Scott Newton <scott@quanta.co.nz>, fwtk-users@ex.tis.com
References: <399B2127.ACDD61F8@quanta.co.nz>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <399B2127.ACDD61F8@quanta.co.nz>; from scott@quanta.co.nz on Thu, Aug 17, 2000 at 11:17:59AM +1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1114

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Aug 17, 2000 at 11:17:59AM +1200, Scott Newton wrote:
...
 > We have a situation where we have a mail server internal to the
 > firewall and want to be able to relay all mail from the server
 > through the firewall (running smap + yao patches) to our ISP, but
 > block any messages coming in that are not for our domain.  I am able
 > 
 > to allow both directions on the firewall or deny both directions on
 > the firewall, but can not find the correct combination of
 > hosts/domains to allow out but not in. Can someone please help
...

smap: domains quanta.co.nz *.quanta.co.nz
smap: hosts quanta.co.nz *.quanta.co.nz

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


From owner-fwtk-users@ex.tis.com Mon Sep 11 09:37 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21727
	Mon, 11 Sep 2000 09:37:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18441;
	Mon, 11 Sep 2000 06:45:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:11:29 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA23589
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:10:46 -0700 (PDT)
Date: Fri, 8 Sep 2000 17:13:00 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: swilso39@csc.com
Cc: fwtk-users@lists.nai.com, uce@ftc.gov, abuse@ers.state.tx.us,
        postmaster@ers.state.tx.us, webmaster@ers.state.tx.us,
        hostmaster@ers.state.tx.us
Subject: Re: SMAP/SMAPD
Message-Id: <20000908171300.M6517@washington.cospo.osis.gov>
Mail-Followup-To: swilso39@csc.com, fwtk-users@lists.nai.com, uce@ftc.gov,
	abuse@ers.state.tx.us, postmaster@ers.state.tx.us,
	webmaster@ers.state.tx.us, hostmaster@ers.state.tx.us
References: <0025694D.00301D56.00@uk-fbr10.eu.csc.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <0025694D.00301D56.00@uk-fbr10.eu.csc.com>; from swilso39@csc.com on Fri, Sep 01, 2000 at 09:41:05AM +0100
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2395

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 01, 2000 at 09:41:05AM +0100, swilso39@csc.com wrote:
...
 > Im a newbie to all this so forgive me if I make a complete idiot of myself with
 > my explanation!
 > 
 > Im running a recent version of SMAP and SMAPD, and for the past three months
 > have had no problems (that I am aware of!).
 > Recently I have noticed that my log files have been growing at a major rate.
 > This is all due to the same message appearing literally all the time :
 > 
 > 
 > Sep  1 08:29:16 nadsc6 smap[505]: connect host=unknown/195.217.247.18
 > Sep  1 08:29:16 nadsc6 smap[500]: Relay: <twngirl@cyberway.com.sg>
 > <lists@headland.co.uk> (195.217.247.18)
 > 
 > Although the first address after ":Relay: <" may change frequently the second
 > address is pretty much consistent (domain is anyway!)
 > 
 > Does anybody know what is going on with this or do I have some sort of localised
 > problem?

Almost certainly, some evil spammer is using your firewall to send
e-mail SPAM to scores of unwitting victims all over the world.

Go to www.fwtk.org, download the set of patches that I compiled and
proofed for smap ["smap-yao patches"].  Install them.  Tell your
firewall to ONLY let mail in for your domain, and to ONLY let your mail
servers [or your whole domain] send e-mail via your firewall.  End of
problem.

If you can, get someone to throw nasty spammer at "195.217.247.18"
completely off the Internet.  For twenty seconds, anyway.

Hmmmm ...
18.247.217.195.in-addr.arpa     canonical name = 18.16.247.217.195.in-addr.arpa

Authoritative answers can be found from:
in-addr.arpa    nameserver = ns.ers.state.tx.us.in-addr.arpa
...
*** No address information is available for "18.16.247.217.195.in-addr.arpa."

You are being used as a SPAM relay by someone working for the State of
Texas in the USA!  This is a criminal action!  I am cc'ing the
Employees Retirement System, State of Texas, USA.  And the FTC.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


From owner-fwtk-users@ex.tis.com Mon Sep 11 10:19 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA22768
	Mon, 11 Sep 2000 10:19:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA01552;
	Mon, 11 Sep 2000 07:28:52 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:43:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA01262
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:42:56 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000909105254.00bb4960@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Sat, 09 Sep 2000 10:58:01 -0400
To: "Larry D. Bonham" <root@d2000.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw problem with Checkpoint
Cc: fwtk-users@ex.tis.com
In-Reply-To: <Pine.SCO.3.96.1000908105302.10208B-100000@pro.d2000.com>
References: <4.2.2.20000907164105.00b51e10@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1031

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:10 AM 9/8/00 -0500, Larry D. Bonham wrote:
 >Rick,
 >
 >Thanks for the response.  We had already had the default port setting at
 >port 20.  We dealt with that problem quite some time ago.

Rats. Never anything easy.


 >As it turns out I had to do a little slash and burn.  I disabled most of
 >the entire sendsaved() function and sent it directly to flushsaved().  For
 >whatever reason the Checkpoint proxy couldn't (wouldn't) handle the
 >multiline response 331-.

That's probably a side effect of Checkpoint's "patch" to fix their FTP 
vulnerability. That's the only time ftp-gw adds anything to the 
interaction, so your change shouldn't have any effect (authenticated ftp 
users will probably break, though, if you're using authentication.)
          -Rick




From owner-fwtk-users@ex.tis.com Mon Sep 11 10:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA22883
	Mon, 11 Sep 2000 10:24:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA02892;
	Mon, 11 Sep 2000 07:33:35 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 05:45:52 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA01979
	for fwtk-users-outgoing; Mon, 11 Sep 2000 05:45:45 -0700 (PDT)
Message-ID: <001601bb8605$a0d6a2c0$23c7c7c7@seclab.sharif.ac.ir>
From: "Hossein Pourreza" <pourreza@hadid.sharif.ac.ir>
To: <fwtk-users@ex.tis.com>
References: <39B4C372.78A973FD@radio.hundert6.de> <20000908171846.O6517@washington.cospo.osis.gov>
Subject: Problem in downloading
Date: Fri, 9 Aug 1996 19:45:40 +0430
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2314.1300
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 690

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi to all,
     I downloaded and worked with FWTK but It doesn't pop-gw.
I wanna to download it but when I want to connect to ftp server it rejects
me.
I connect from a server that has valid IP and DNS name and It is my mail
server too so I think its
DNS works well but the FWTK server tells me that your reverse DNS lookup
faild.
Can some one mail me pop-gw or someone has souloution for this.
Any suggestion will be appreciated



From owner-fwtk-users@ex.tis.com Mon Sep 11 11:44 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA24986
	Mon, 11 Sep 2000 11:44:14 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA26475;
	Mon, 11 Sep 2000 08:53:44 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 06:11:59 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA09008
	for fwtk-users-outgoing; Mon, 11 Sep 2000 06:11:56 -0700 (PDT)
Message-Id: <4.2.2.20000911080639.00bbb3f0@pop.gw.tislabs.com>
X-Sender: listmast@pop.gw.tislabs.com (Unverified)
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Mon, 11 Sep 2000 08:07:18 -0400
To: fwtk-users@lists.nai.com
From: owner-fwtk-users@lists.tislabs.com (by way of Majordomo Listmaster <listmast@tislabs.com>)
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 4173

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dor.fwtk-users
  >From listmast@tislabs.com  Fri Sep  8 12:37:57 2000
Received: from sicgw.sic.co.jp (sicgw.sic.co.jp [202.15.240.66])
	by relay2.nai.com (8.9.3/8.9.3) with ESMTP id MAA10011
	for <fwtk-users@lists.nai.com>; Fri, 8 Sep 2000 12:37:53 -0700 (PDT)
Received: from pegasus.sic.co.jp ([131.3.37.5])
	by sicgw.sic.co.jp (8.9.1+3.1W/3.7Wpl2/sic-4.3mg-mx) with ESMTP
	id EAA20392;
	Sat, 9 Sep 2000 04:37:19 +0900 (JST)
Received: from sicgw.sic.co.jp (sicgw.sic.co.jp [202.15.240.66])
	by pegasus.sic.co.jp (8.9.3+3.2W/3.7Wpl2/sic-4.00hub.mx) with ESMTP
	id EAA21213
	for <kota@sic.co.jp>; Sat, 9 Sep 2000 04:36:58 +0900
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by sicgw.sic.co.jp (8.9.1+3.1W/3.7Wpl2/sic-4.3mg-mx) with ESMTP
	id EAA20388
	for <kota@sic.co.jp>; Sat, 9 Sep 2000 04:37:15 +0900 (JST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA09447;
	Fri, 8 Sep 2000 12:34:50 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 8 Sep 2000 11:15:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA21277
	for fwtk-users-outgoing; Fri, 8 Sep 2000 11:15:41 -0700 (PDT)
Date: Fri, 8 Sep 2000 14:14:42 -0400 (EDT)
Message-Id: <200009081814.OAA04502@tern.cs.rochester.edu>
From: Liudvikas Bukys  <bukys@cs.rochester.edu>
cc: bukys@cs.rochester.edu
Subject: http-gw 2.1 patch for URL scheme case insensitivity
To: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@ex.tis.com

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

According to RFC1738 http://www.ietf.org/rfc/rfc1738.txt?number=1738

``	For resiliency, programs interpreting URLs should treat upper
	case letters as equivalent to lower case in scheme names (e.g.,
	allow "HTTP" as well as "http").	''

Liudvikas Bukys
University of Rochester
734 Computer Studies Building
Rochester, NY 14627-0226

tel# 716-275-7747
fax# 716-273-4556

<bukys@rochester.edu>
<bukys@infosec.rochester.edu>
<bukys@cs.rochester.edu>


*** http-gw.c	1998/09/24 14:53:52	1.1
--- http-gw.c	2000/09/08 15:17:49
***************
*** 436,438 ****
    	if( parse_vec[3] == NULL){
! 		if( ourport && !strcmp(parse_vec[2], ourname)){
    			sprintf(url_port,"%d", ourport);
--- 436,438 ----
    	if( parse_vec[3] == NULL){
! 		if( ourport && !strcasecmp(parse_vec[2], ourname)){
    			sprintf(url_port,"%d", ourport);
***************
*** 637,639 ****
    /* Now look for our special formats (URL's) */
! 	if( !strncmp(path, "gopher://", 9)){
    		ret &= ~MASK_BASE;
--- 637,639 ----
    /* Now look for our special formats (URL's) */
! 	if( !strncasecmp(path, "gopher://", 9)){
    		ret &= ~MASK_BASE;
***************
*** 657,659 ****
    		return ret;
! 	}else if( !strncmp(path, "http://", 7)){
    		ret &= ~MASK_BASE;
--- 657,659 ----
    		return ret;
! 	}else if( !strncasecmp(path, "http://", 7)){
    		ret &= ~MASK_BASE;
***************
*** 668,670 ****
    
! 	}else if( !strncmp(path, "ftp://", 6) || !strncmp(path, "file://", 7)){
    		ret &= ~MASK_BASE;
--- 668,670 ----
    
! 	}else if( !strncasecmp(path, "ftp://", 6) || !strncasecmp(path, "file://", 7)){
    		ret &= ~MASK_BASE;
***************
*** 764,766 ****
    	case 'e':
! 		if(strncmp(buf, "exec:", 5)== 0){
    			ret = TYPE_EXEC;
--- 764,766 ----
    	case 'e':
! 		if(strncasecmp(buf, "exec:", 5)== 0){
    			ret = TYPE_EXEC;
***************
*** 770,772 ****
    	case 'f':
! 		if(strncmp(buf, "ftp:", 4) == 0){
    			ret = parse_ftp(buf);
--- 770,772 ----
    	case 'f':
! 		if(strncasecmp(buf, "ftp:", 4) == 0){
    			ret = parse_ftp(buf);
***************
*** 776,781 ****
    	case 'w':
! 		if(strncmp(buf, "waissrc:", 8)== 0){
    			ret = TYPE_WAIS|TYPE_DIR;
    		}
! 		if( strncmp(buf, "waisdocid:", 10) == 0){
    			ret = TYPE_WAIS;
--- 776,781 ----
    	case 'w':
! 		if(strncasecmp(buf, "waissrc:", 8)== 0){
    			ret = TYPE_WAIS|TYPE_DIR;
    		}
! 		if( strncasecmp(buf, "waisdocid:", 10) == 0){
    			ret = TYPE_WAIS;




From owner-fwtk-users@ex.tis.com Mon Sep 11 12:20 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA25928
	Mon, 11 Sep 2000 12:20:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA08028;
	Mon, 11 Sep 2000 09:29:39 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 06:46:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA13984
	for fwtk-users-outgoing; Mon, 11 Sep 2000 06:45:54 -0700 (PDT)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <39BCDA20.C103FD90@peaktime.be>
Date: Mon, 11 Sep 2000 15:12:00 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: Re: FTP Behind Masquerade?
References: <384272173.967802695549.JavaMail.root@web307-mc.mail.com> <005b01c01449$ad7ea460$c93b0dd8@webnet.qc.ca> <20000908171622.N6517@washington.cospo.osis.gov>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1455

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Joseph S D Yao wrote:
 > 
 > FTP is a full-duplex protocol, with each direction over a separate
 > channel.  The client initiates a connection to the server, but then the
 > server initiates a second connection back to the client.  With some
 > forms of masquerading, the second connection cannot be made.  So, you
 > can't do active FTP.  Passive works fine, since it's a half-duplex
 > protocol over a single channel.
 > 
 > --
 > Joe Yao                         jsdy@cospo.osis.gov - Joseph S. D. Yao

Sorry, but this is not correct. FTP uses a command channel, which is
bi-directional, and a data channel is opened in the appropriate
direction for each transfer. This is true whether the server is in
active or passive mode. In passive mode, the server prepares to receive
the data connection, but it is the client that connects to it, and there
are still 2 channels, one full-duplex and one half-duplex. Hence, even
passive mode requires masquerading support.

Anyway, maybe the ftp masquerading module only supports passive, or
maybe it supports active only for outgoing requests. If the doc (maybe
the Linux firewall HOWTO?) does not say, the OP should have a look at
the source.

Greetings.
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Mon Sep 11 15:53 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA29347
	Mon, 11 Sep 2000 15:53:03 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA26398;
	Mon, 11 Sep 2000 13:02:32 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 11:55:07 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA12843
	for fwtk-users-outgoing; Mon, 11 Sep 2000 11:55:00 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@ex.tis.com>
Subject: Relaying mail
Date: Mon, 11 Sep 2000 12:54:17 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFOEKKOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id LAA12794
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 449

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

How do you forward all email from an internal (i.e. behind the firewall)
to the smap software on the firewall, so it can send it to the internet?

Until now, I'm using the firewall itself to send the mail 
to the internet...It seems not such a good idea! (I guess)



Luis Fernando Barrera
luba@assist.com.gt 


From owner-fwtk-users@ex.tis.com Mon Sep 11 16:26 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA29440
	Mon, 11 Sep 2000 16:25:59 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA02886;
	Mon, 11 Sep 2000 13:34:44 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 12:50:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA23637
	for fwtk-users-outgoing; Mon, 11 Sep 2000 12:50:00 -0700 (PDT)
Date: Mon, 11 Sep 2000 15:49:27 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Hossein Pourreza <pourreza@hadid.sharif.ac.ir>
Cc: fwtk-users@ex.tis.com
Subject: Re: Problem in downloading
Message-Id: <20000911154927.Y15296@washington.cospo.osis.gov>
Mail-Followup-To: Hossein Pourreza <pourreza@hadid.sharif.ac.ir>,
	fwtk-users@ex.tis.com
References: <39B4C372.78A973FD@radio.hundert6.de> <20000908171846.O6517@washington.cospo.osis.gov> <001601bb8605$a0d6a2c0$23c7c7c7@seclab.sharif.ac.ir>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <001601bb8605$a0d6a2c0$23c7c7c7@seclab.sharif.ac.ir>; from pourreza@hadid.sharif.ac.ir on Fri, Aug 09, 1996 at 07:45:40PM +0430
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1484

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Aug 09, 1996 at 07:45:40PM +0430, Hossein Pourreza wrote:
>     I downloaded and worked with FWTK but It doesn't pop-gw.
> I wanna to download it but when I want to connect to ftp server it rejects
> me.
> I connect from a server that has valid IP and DNS name and It is my mail
> server too so I think its
> DNS works well but the FWTK server tells me that your reverse DNS lookup
> faild.
> Can some one mail me pop-gw or someone has souloution for this.
> Any suggestion will be appreciated

If you haven't downloaded FWTK, then I completely don't understand your
first sentence.

The FWTK FTP server must be able to use DNS to find your host name from
your IP address.  What are the host name and IP address from which you
are trying to download the machine?  Go to, e.g.,
	<URL: http://www.his.com/cgi-bin/nslookup>
and type in your IP address.  It should give you back your host name.[1]
It should NOT reply with "non-existent host/domain".  If it does the
latter, your site needs to fix its DNS.

[1]  I am simplifying.  It has to return a host name which then
resolves via DNS forward lookups to your IP address.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Mon Sep 11 18:02 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA29775
	Mon, 11 Sep 2000 18:02:58 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA17276;
	Mon, 11 Sep 2000 15:12:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 14:18:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA09828
	for fwtk-users-outgoing; Mon, 11 Sep 2000 14:18:28 -0700 (PDT)
Date: Mon, 11 Sep 2000 17:18:08 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Luis Fernando Barrera <luba@assist.com.gt>
Cc: fwtk-users@ex.tis.com
Subject: Re: Relaying mail
Message-Id: <20000911171808.C18248@washington.cospo.osis.gov>
Mail-Followup-To: Luis Fernando Barrera <luba@assist.com.gt>,
	fwtk-users@ex.tis.com
References: <NABBIDJPNCAGKGOFGHBFOEKKOOAA.luba@assist.com.gt>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NABBIDJPNCAGKGOFGHBFOEKKOOAA.luba@assist.com.gt>; from luba@assist.com.gt on Mon, Sep 11, 2000 at 12:54:17PM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1346

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, Sep 11, 2000 at 12:54:17PM -0600, Luis Fernando Barrera wrote:
...
> How do you forward all email from an internal (i.e. behind the firewall)
> to the smap software on the firewall, so it can send it to the internet?
> 
> Until now, I'm using the firewall itself to send the mail 
> to the internet...It seems not such a good idea! (I guess)

Correct, not a good idea.

This is done by 'sendmail', or whatever MTA [mail transfer agent] you
are using on your internal mail server [the only other one I would
consider is Postfix].  In the sendmail.cf file for many operating
systems distributed today, there is a line defining a "mail relay".  It
looks something like:

	# "Smart" relay host (may be null)
	DS

or

	# major relay host
	DRmailhost

The "D" stands for "Define".  The second letter varies from system to
system.  The name after that (here, "mailhost") should be changed to
the name of the firewall host that relays e-mail.  For instance, on
this system it is:

	DSrelay2

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Mon Sep 11 18:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA29823
	Mon, 11 Sep 2000 18:24:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA20350;
	Mon, 11 Sep 2000 15:33:46 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 11 Sep 2000 14:48:55 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA13935
	for fwtk-users-outgoing; Mon, 11 Sep 2000 14:48:44 -0700 (PDT)
Date: Mon, 11 Sep 2000 17:47:43 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Luis Fernando Barrera <luba@assist.com.gt>
cc: fwtk-users@ex.tis.com
Subject: Re: Relaying mail
In-Reply-To: <NABBIDJPNCAGKGOFGHBFOEKKOOAA.luba@assist.com.gt>
Message-ID: <Pine.GSO.4.10.10009111722210.20213-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 880

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Louis,

Depends on the behind the firewall mail server.

If you use sendmail, the Berkeley sendmails have the concept of
"smarthost" which automatically relays non-local mail to a
more-knowledgable host.

ted keller


On Mon, 11 Sep 2000, Luis Fernando Barrera wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi all,
> 
> How do you forward all email from an internal (i.e. behind the firewall)
> to the smap software on the firewall, so it can send it to the internet?
> 
> Until now, I'm using the firewall itself to send the mail 
> to the internet...It seems not such a good idea! (I guess)
> 
> 
> 
> Luis Fernando Barrera
> luba@assist.com.gt 
> 


From owner-fwtk-users@ex.tis.com Tue Sep 12 05:58 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA14870
	Tue, 12 Sep 2000 05:58:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA11197;
	Tue, 12 Sep 2000 03:06:53 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 00:56:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA04222
	for fwtk-users-outgoing; Tue, 12 Sep 2000 00:56:32 -0700 (PDT)
Date: Tue, 12 Sep 2000 09:52:57 +0200 (CEST)
From: Leandro Gelasi <gelasi@interfree.it>
To: fwtk-users@ex.tis.com
Subject: Re: Ftp'ing from outside to inside via Netscape
In-Reply-To: <39B74B62.D5531F8@bofh.maldata.se>
Message-ID: <Pine.LNX.4.21.0009120942020.470-100000@iceman.mydomain.ice>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from QUOTED-PRINTABLE to 8bit by relay2.nai.com id AAA04197
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=iso-8859-1
Content-Length: 2696

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, 7 Sep 2000, Göran Häggsjö wrote:

> There is a problem with the mapping to the right IP-adress.
> You should use a internal nameserver that provides the IP-address on the DMZ as
> well as internals.
> When you come from the internet there is an external nameserver which resolves
> the name.
> (If the firewall is a fast machine it can do the nameserving also, but there can
> be some traps here).
>

Thank you for your posting.

I use a split-DNS nameserver, half on the firewall (external names), half
on a server in the intranet.
All works fine (at least in name resolution)
 
> By the way, have you tried to use IP-adress ?
> 

Yes, I did.

I tried ftp://ftp@10.1.0.5@firewall.myreal.domain/
	ftp://ftp@anonserver@<my real ip>/
	ftp://ftp@10.1.0.5@<my real ip>/
and also the above with password integrated in the URLS.

Nothing worked!

In all the case, ftp-gw replies with "Use user@domain to connect via
gateway"

It seems that Netscape uncorrectly recognize "ftp@anonserver" as a
username, stopping at first "@" char.

I repeat, all works fine using a ftp client.

LG


> If that works then you know that it is the DNS-2-IP.
> 
> cheers /GoHa
> 
> Leandro Gelasi wrote:
> 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > I am using FWTk 2.1 and all works fine.
> >
> > Now I would like to set up a link on my web server that point to our
> > anonymous ftp server.
> >
> > The anon ftp server is into the dmz and it's correctly reachable
> > (from outside) using a ftp client this way :
> > ftp firewall.myrealdomain.it
> > user ftp@anonserver
> > password email@emailsrv.domain
> >
> > There is an URL that permit to connect to the server from the outside?
> > I tried
> > ftp://ftp@anonserver:email@emailsrv.domain@firewall.myrealdomain.it
> >
> > following the ftp://user:password@server.domain syntax but it didn't worked.
> >
> > Any hints?
> >
> > TIA
> >
> > LG
> >
> > *********************************************************************
> > Leandro Gelasi
> > V year Computer Science Engineering student at Siena University
> > gelasi@interfree.it
> >
> > Gilles Villeneuve will live forever
> > *********************************************************************
> 

*********************************************************************
Leandro Gelasi
V year Computer Science Engineering student at Siena University
gelasi@interfree.it

Gilles Villeneuve will live forever
*********************************************************************


From owner-fwtk-users@ex.tis.com Tue Sep 12 10:10 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA15549
	Tue, 12 Sep 2000 10:10:38 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA29300;
	Tue, 12 Sep 2000 07:19:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 05:36:03 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA19101
	for fwtk-users-outgoing; Tue, 12 Sep 2000 05:35:52 -0700 (PDT)
Reply-To: <joseph@gate.net>
From: "Joe M." <joseph@gate.net>
To: <fwtk-users@ex.tis.com>
Subject: TIS and Red Hat 5.2
Date: Tue, 12 Sep 2000 08:39:55 -0400
Message-ID: <DE5A03F1D888D3119792009027D3B42706CC@ESCNET2>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2911.0)
In-Reply-To: <DE5A03F1D888D3119792009027D3B4277922C9@ESCNET2>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 356

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all,  I am going to setup my first firewall with TIS. Can someone tell
me if the OS version is strict, does it have to be RH 5.2, or could a newer
RH version be used successfully.

         Thanks,

       Joe Massimino


From owner-fwtk-users@ex.tis.com Tue Sep 12 11:20 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA15836
	Tue, 12 Sep 2000 11:19:47 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA09674;
	Tue, 12 Sep 2000 08:29:01 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 06:54:35 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA25778
	for fwtk-users-outgoing; Tue, 12 Sep 2000 06:54:11 -0700 (PDT)
Message-ID: <AFE36742FF57D411862500508BDE8DD054C5@mail.herefordshire.gov.uk>
From: "Randal, Phil" <prandal@herefordshire.gov.uk>
To: "'joseph@gate.net'" <joseph@gate.net>, fwtk-users@ex.tis.com
Subject: RE: TIS and Red Hat 5.2
Date: Tue, 12 Sep 2000 14:53:44 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1141

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Joe,

I've had the fwtk (plus patches) working under Red Hat Linux
5.1 and 6.2, so I'm sure it will work for you.  I had to make
one simple patch to my smap (Joe Yao's patches plus others)
to compile under RH 6.2, but that change was trivial (a
forward declaration of a C library routine which was a #define
in RH 6.2's header files).

Phil

------------------------------------------------------------
Phil Randal
Network Engineer
Herefordshire Council, UK

> -----Original Message-----
> From: Joe M. [mailto:joseph@gate.net]
> Sent: 12 September 2000 13:40
> To: fwtk-users@ex.tis.com
> Subject: TIS and Red Hat 5.2
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello all,  I am going to setup my first firewall with TIS. 
> Can someone tell
> me if the OS version is strict, does it have to be RH 5.2, or 
> could a newer
> RH version be used successfully.
> 
>          Thanks,
> 
>        Joe Massimino
> 

From owner-fwtk-users@ex.tis.com Tue Sep 12 11:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA15901
	Tue, 12 Sep 2000 11:33:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA11786;
	Tue, 12 Sep 2000 08:42:41 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 07:19:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29170
	for fwtk-users-outgoing; Tue, 12 Sep 2000 07:18:49 -0700 (PDT)
Message-ID: <39BE3ADA.388CC9A8@dr.gdf.fr>
Date: Tue, 12 Sep 2000 16:16:58 +0200
From: Nicolas Leroy <nicolas.leroy@dr.gdf.fr>
X-Mailer: Mozilla 4.7 [fr] (WinNT; I)
X-Accept-Language: fr
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Next proxy
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 604

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,
I wonder how to configure http-gw in order to use the "next proxy"
fonctionnality, that is to say:
client ----> fwtk http-gw ----> proxy server ----> destination server
To reach the "destination server", the "fwtk server" must redirect the
"client" request (sent to the "destination server") to the "proxy
server". Therefore, it's necessary to indicate to http-gw that the
"destination server" stands behind the "proxy server".

Thanks in advance for the help,
N. Leroy


From owner-fwtk-users@ex.tis.com Tue Sep 12 13:27 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA16240
	Tue, 12 Sep 2000 13:26:54 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA28781;
	Tue, 12 Sep 2000 10:36:03 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 08:55:18 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA13543
	for fwtk-users-outgoing; Tue, 12 Sep 2000 08:55:06 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@ex.tis.com>
Subject: FW: TIS and Red Hat 5.2
Date: Tue, 12 Sep 2000 09:54:24 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFGEKPOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Importance: Normal
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id IAA13513
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 900

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I would not recommend RH 5.2, use RH 6.2...
which has newer versions (and more secure) of the
software.
You could also consider using the Linux Bastille scripts, which
make "more" secure a machine.

-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of Joe M.
Sent: Tuesday, September 12, 2000 6:40 AM
To: fwtk-users@ex.tis.com
Subject: TIS and Red Hat 5.2


[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all,  I am going to setup my first firewall with TIS. Can someone tell
me if the OS version is strict, does it have to be RH 5.2, or could a newer
RH version be used successfully.

         Thanks,

       Joe Massimino


From owner-fwtk-users@ex.tis.com Tue Sep 12 17:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA16970
	Tue, 12 Sep 2000 17:01:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA01284;
	Tue, 12 Sep 2000 14:10:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 11:47:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA08637
	for fwtk-users-outgoing; Tue, 12 Sep 2000 11:47:11 -0700 (PDT)
Message-ID: <382134953.968774829328.JavaMail.root@web301-mc.mail.com>
Date: Tue, 12 Sep 2000 12:06:41 -0400 (EDT)
From: kemal hajdarevic <kemalh@mail.com>
To: fwtk-users@lists.nai.com
Subject: Relaying smap problem
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Mailer: mail.com
X-Originating-IP: 195.130.44.3
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 890

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi people,

On my Linux box is installed FWTK and a patch for smap(Ted's). Now in
messages log file can be found line DNS entry not found if somebody want to
send e-mail to/form LAN through FW.

It is problem because I'm doing something wrong, but I don;t know what.

netperm-table is setup to se local-host  and local-domain boxes.

Before that smap was operational but spamable now FW blocks all
mail communications.

Assuming that new smap is not privileged to use DNS or something like that.

I'm repeating there were no problmes with smap/smapd/sendmail
configurations.

Solving this problem would be much appreciate.



Kemal


______________________________________________
FREE Personalized Email at Mail.com
Sign up at http://www.mail.com/?sr=signup



From owner-fwtk-users@ex.tis.com Tue Sep 12 17:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA16974
	Tue, 12 Sep 2000 17:01:31 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA01308;
	Tue, 12 Sep 2000 14:09:53 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 11:46:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA08536
	for fwtk-users-outgoing; Tue, 12 Sep 2000 11:46:18 -0700 (PDT)
Message-ID: <39BE5464.469C4A9B@jamedia.com>
Date: Tue, 12 Sep 2000 12:05:56 -0400
From: Scott McEachern <smceachern@jamedia.com>
X-Mailer: Mozilla 4.73 [en] (X11; U; FreeBSD 4.0-RELEASE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: joseph@gate.net
CC: fwtk-users@ex.tis.com
Subject: Re: TIS and Red Hat 5.2
References: <DE5A03F1D888D3119792009027D3B42706CC@ESCNET2>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 930

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

"Joe M." wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > Hello all,  I am going to setup my first firewall with TIS. Can someone tell
 > me if the OS version is strict, does it have to be RH 5.2, or could a newer
 > RH version be used successfully.
 >
 >          Thanks,
 >
 >        Joe Massimino

     FWIW, I've successfully run FWTK 2.1 under OpenBSD 2.[5-7]  I don't mean to
sound like an OS bigot and start a flame war here, but you should seriously
consider the proactive security auditing taken in OpenBSD to host your firewall.


--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.
300 John St., Suite 500, Thornhill, ON, CA  L3T 5W4
tel:905-881-6902  fax:905-881-6945





From owner-fwtk-users@ex.tis.com Tue Sep 12 17:03 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA16999
	Tue, 12 Sep 2000 17:03:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA01681;
	Tue, 12 Sep 2000 14:11:54 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 12 Sep 2000 12:14:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA12856
	for fwtk-users-outgoing; Tue, 12 Sep 2000 12:13:58 -0700 (PDT)
Date: Tue, 12 Sep 2000 18:47:28 +0200 (CEST)
From: Leandro Gelasi <gelaslean@lucy.dii.unisi.it>
To: "Joe M." <joseph@gate.net>
Cc: fwtk-users@ex.tis.com
Subject: Re: TIS and Red Hat 5.2
In-Reply-To: <DE5A03F1D888D3119792009027D3B42706CC@ESCNET2>
Message-ID: <Pine.LNX.4.21.0009121845550.20896-100000@giunone.dii.unisi.it>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 984

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, 12 Sep 2000, Joe M. wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hello all,  I am going to setup my first firewall with TIS. Can someone tell
 > me if the OS version is strict, does it have to be RH 5.2, or could a newer
 > RH version be used successfully.
 > 
 >

I can use a newer version, I suggest 6.2
Otherwise you can use Mandrake 7.1, SuSE 6.4.
The version (and distribution) is not a strict request, I think it's a
"minimal" request.

LG 

**************************************************************************
Leandro Gelasi
V Year Computer Science Engineering at Siena University
email : gelaslean@lucy.ing.unisi.it
Gilles Villeneuve will live forever
**************************************************************************



From owner-fwtk-users@ex.tis.com Wed Sep 13 18:40 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA22857
	Wed, 13 Sep 2000 18:40:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA10844;
	Wed, 13 Sep 2000 15:49:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 13 Sep 2000 10:38:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA29074
	for fwtk-users-outgoing; Wed, 13 Sep 2000 10:38:21 -0700 (PDT)
Date: Wed, 13 Sep 2000 09:02:17 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: kemal hajdarevic <kemalh@mail.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: Relaying smap problem
Message-Id: <20000913090217.F29325@washington.cospo.osis.gov>
Mail-Followup-To: kemal hajdarevic <kemalh@mail.com>,
	fwtk-users@lists.nai.com
References: <382134953.968774829328.JavaMail.root@web301-mc.mail.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <382134953.968774829328.JavaMail.root@web301-mc.mail.com>; from kemalh@mail.com on Tue, Sep 12, 2000 at 12:06:41PM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 447

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

You do have your firewall bastion host set up to use internal DNS, not
external DNS, right?

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Sep 14 21:20 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA27647
	Thu, 14 Sep 2000 21:20:24 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA23812;
	Thu, 14 Sep 2000 18:28:03 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 14 Sep 2000 12:30:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA18007
	for fwtk-users-outgoing; Thu, 14 Sep 2000 12:30:26 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@lists.nai.com>
Subject: Using SSH-GW
Date: Thu, 14 Sep 2000 13:29:02 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFAELJOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id MAA17966
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 963

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I'd like to let external users to telnet to some internal
hosts in my network... TIS FWTK provides the "tn-gw" to do this,
however I know telnet sends everything in clear text, so 
it is not such a good idea...

I also know that there is a way someone can encrypt all the
comunications between some external client and the firewall. Then
the firewall forwards the request to some internal host unencrypted...

Since I'm a totally newbie to ssh, I don't have a clue to setup
such an enviroment. I mean... to encryt the comunication
between the firewall and the external clients (the comunication
between the firewall and internal hosts does not have to be encrypted).

I saw the patch to enables this, but it is very confussing...

Any ideas how to start?

Thanks you all in advance.

Luis Fernando Barrera
luba@assist.com.gt 




From owner-fwtk-users@ex.tis.com Thu Sep 14 22:18 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA27736
	Thu, 14 Sep 2000 22:18:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA28808;
	Thu, 14 Sep 2000 19:27:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 14 Sep 2000 14:13:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA29766
	for fwtk-users-outgoing; Thu, 14 Sep 2000 14:13:28 -0700 (PDT)
Message-ID: <20000914202209.22736.qmail@wwcst271.netaddress.usa.net>
Date: 14 Sep 00 15:22:09 CDT
From: Rogelio Bazan Reyes <rogeliobazanr@netscape.net>
To: fwtk-users@lists.nai.com
Subject: x-gw
X-Mailer: USANET web-mailer (34WB1.4.03)
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id OAA29669
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 656

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,
i'm trying to compile fwtk, first the compiler said that he was unable to find
the intrinsic.h file, andf i read in the FAQ that my system needed the X11
programming environment installed, but i don't know what package to install to
achieve this, could anyone say me the name of the package or the site to
download it, or what can i do to solve that?
thanx 

____________________________________________________________________
Get your own FREE, personal Netscape WebMail account today at http://home.netscape.com/webmail

From owner-fwtk-users@ex.tis.com Fri Sep 15 05:21 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA28581
	Fri, 15 Sep 2000 05:21:27 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA04005;
	Fri, 15 Sep 2000 02:29:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 14 Sep 2000 21:26:38 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA08413
	for fwtk-users-outgoing; Thu, 14 Sep 2000 21:26:08 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000914235952.00bbd690@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Fri, 15 Sep 2000 00:04:06 -0400
To: Rogelio Bazan Reyes <rogeliobazanr@netscape.net>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: x-gw
In-Reply-To: <20000914202209.22736.qmail@wwcst271.netaddress.usa.net>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 776

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 03:22 PM 9/14/00 -0500, Rogelio Bazan Reyes wrote:
>Hi,
>i'm trying to compile fwtk, first the compiler said that he was unable to find
>the intrinsic.h file, andf i read in the FAQ that my system needed the X11
>programming environment installed, but i don't know what package to install to
>achieve this, could anyone say me the name of the package or the site to
>download it, or what can i do to solve that?

It's hard to answer your question without some hint about what operating 
system you're using. Some Linux distributions use the term "development" 
rather than programming, but that's almost too obvious to mention.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Sep 15 14:54 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA04283
	Fri, 15 Sep 2000 14:54:51 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA09850;
	Fri, 15 Sep 2000 12:02:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 15 Sep 2000 07:12:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA29997
	for fwtk-users-outgoing; Fri, 15 Sep 2000 07:12:34 -0700 (PDT)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <39C1DDBA.988627E9@peaktime.be>
Date: Fri, 15 Sep 2000 10:28:42 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Re: Using SSH-GW
References: <NABBIDJPNCAGKGOFGHBFAELJOOAA.luba@assist.com.gt>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1850

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Luis Fernando Barrera wrote:
 > 
 > Hi,
 > 
 > I'd like to let external users to telnet to some internal
 > hosts in my network... TIS FWTK provides the "tn-gw" to do this,
 > however I know telnet sends everything in clear text, so
 > it is not such a good idea...
 > 
Quite right.

 > I also know that there is a way someone can encrypt all the
 > comunications between some external client and the firewall. Then
 > the firewall forwards the request to some internal host unencrypted...
 > 
IMHO this is to be avoided. If your FW is compromised, the cracker would
have access to the cleartext of all traffic. On our FW we just tunnel
SSH to an internal host running the SSHD, using plug-gw. Pros: see the
ssh-gw README. In our case, we really wanted X11, IMAP, RSYNC and SMB
over SSH, and we did not feel we required more authentication than the
SSH private keys, and we *really* trust the external users, so ssh-gw
simply was not an option. Cons: anyone?

 > Since I'm a totally newbie to ssh, I don't have a clue to setup
 > such an enviroment. I mean... to encryt the comunication
 > between the firewall and the external clients (the comunication
 > between the firewall and internal hosts does not have to be encrypted).
 > 
As I said above, the traffic 'inside' the FW, so to speak, also has to
be considered. 

 > I saw the patch to enables this, but it is very confussing...
 > 
 > Any ideas how to start?
 > 

What OS and SSH version do you intend to use on clients, FW and/or
internal host?

 > Thanks you all in advance.
 > 
 > Luis Fernando Barrera
 > luba@assist.com.gt

Cheers
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Fri Sep 15 17:02 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA04770
	Fri, 15 Sep 2000 17:02:41 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA27361;
	Fri, 15 Sep 2000 14:10:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 15 Sep 2000 09:37:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA21719
	for fwtk-users-outgoing; Fri, 15 Sep 2000 09:35:48 -0700 (PDT)
Date: Fri, 15 Sep 2000 12:17:38 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Rogelio Bazan Reyes <rogeliobazanr@netscape.net>
Cc: fwtk-users@lists.nai.com
Subject: Re: x-gw
Message-Id: <20000915121738.I14842@washington.cospo.osis.gov>
Mail-Followup-To: Rogelio Bazan Reyes <rogeliobazanr@netscape.net>,
	fwtk-users@lists.nai.com
References: <20000914202209.22736.qmail@wwcst271.netaddress.usa.net>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <20000914202209.22736.qmail@wwcst271.netaddress.usa.net>; from rogeliobazanr@netscape.net on Tue, Oct 21, 2036 at 09:50:25PM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 908

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, Oct 21, 2036 at 09:50:25PM -0500, Rogelio Bazan Reyes wrote:
> i'm trying to compile fwtk, first the compiler said that he was unable to find
> the intrinsic.h file, andf i read in the FAQ that my system needed the X11
> programming environment installed, but i don't know what package to install to
> achieve this, could anyone say me the name of the package or the site to
> download it, or what can i do to solve that?

No, how could anybody?  We know nothing about the system on which
you're trying to compile this, or version, or anything.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Mon Sep 18 02:15 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id CAA11491
	Mon, 18 Sep 2000 02:15:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id XAA25531;
	Sun, 17 Sep 2000 23:24:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 17 Sep 2000 20:45:15 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA16878
	for fwtk-users-outgoing; Sun, 17 Sep 2000 20:45:04 -0700 (PDT)
Message-ID: <39C58D12.3B0B4F8F@mahindrabt.com>
Date: Mon, 18 Sep 2000 09:03:38 +0530
From: Rajesh Khanduja <khanduja@mahindrabt.com>
X-Mailer: Mozilla 4.7 [en] (Win95; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: ICQ ...
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 172

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi

How do I proxy ICQ ?

Cheers,
Rajesh



From owner-fwtk-users@ex.tis.com Mon Sep 18 11:23 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13258
	Mon, 18 Sep 2000 11:23:36 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA03196;
	Mon, 18 Sep 2000 08:31:29 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 18 Sep 2000 06:50:36 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA09898
	for fwtk-users-outgoing; Mon, 18 Sep 2000 06:50:25 -0700 (PDT)
Message-ID: <91A5926EFF44D3118B1200104B7276EB654D82@hart-exchange.hartwellcorp.com>
From: "Michael St. Laurent" <mstlaurent@hartwellcorp.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Smap hangs till timeout on some connections
Date: Fri, 15 Sep 2000 17:38:15 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1663

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I've got fwtk 2.1 with the yao-smap patches running under SuSE Linux on
Intel.  In the netperm-table I've specified the "smap: unknown-host 1"
setting as well as the "broken-from" setting.  The logfile indicates (unless
I'm reading it wrong) that the connection is allowed but is dropped after
the 10 minute timeout period expires.  Below is a snippet from the logfile:

Sep 15 16:40:12 guardian smap[5150]: 207.204.245.3 host address lookup
failed
Sep 15 16:40:12 guardian smap[5150]: connect host=unknown/207.204.245.3
Sep 15 16:50:12 guardian smap[5150]: Network timeout signal after 600
seconds

A packet trace shows that the sending system connects, is sent the greeting
"220 guardian.hartwellcorp.com SMTP/smap Ready", it replies with a "HELO
cadmail.cadnet.com" which is acknowledged by smap (with a TCP ACK) and then
nothing more happens on the wire til the timeout triggers and smap
terminates the connection.  A "gdb" stack backtrace shows the following:

(gdb) bt
#0  0x4008674e in ?? ()
#1  0x400e87f5 in ?? ()
#2  0x400ddef8 in ?? ()
#3  0x805f54e in   ()
#4  0x805f39e in gethostbyaddr ()
#5  0x804c4d0 in hostmatch (pattern=0x8087e20 "localhost.hartwellcorp.com",
     name=0x8086190 "207.204.245.3") at nama.c:363
#6  0x804a64e in check_hostname ()
#7  0x8048d1c in main ()
(gdb)

The sender admits that their ISP will not allow/perform reverse DNS on the
address (which is probably what is causing the problem).  Is there some way
to work around this?


--------------------
Michael St. Laurent
Hartwell Corporation


From owner-fwtk-users@ex.tis.com Mon Sep 18 13:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA13963
	Mon, 18 Sep 2000 13:55:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA29834;
	Mon, 18 Sep 2000 11:04:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 18 Sep 2000 09:29:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA14304
	for fwtk-users-outgoing; Mon, 18 Sep 2000 09:29:28 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: "Michel Bardiaux" <mbardiaux@peaktime.be>
Cc: <fwtk-users@lists.nai.com>
Subject: RE: Using SSH-GW
Date: Mon, 18 Sep 2000 10:27:35 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFAELMOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
In-Reply-To: <39C1DDBA.988627E9@peaktime.be>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id JAA14241
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2007

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Thanks for you response...
> IMHO this is to be avoided. If your FW is compromised, the cracker would
> have access to the cleartext of all traffic. On our FW we just tunnel
> SSH to an internal host running the SSHD, using plug-gw. Pros: see the
> ssh-gw README. In our case, we really wanted X11, IMAP, RSYNC and SMB
> over SSH, and we did not feel we required more authentication than the
> SSH private keys, and we *really* trust the external users, so ssh-gw
> simply was not an option. Cons: anyone?
> 
>  > Since I'm a totally newbie to ssh, I don't have a clue to setup
>  > such an enviroment. I mean... to encryt the comunication
>  > between the firewall and the external clients (the comunication
>  > between the firewall and internal hosts does not have to be encrypted).
>  > 
> As I said above, the traffic 'inside' the FW, so to speak, also has to
> be considered. 

I know... This should be considered in the near future, since there's a lot
of traffice to be encripted... Windows 95/98, Mcintosh, Windows NT/2000,
RS/6000, etc... It's almost impossible (I think) to encrypt all this kind of
traffic..

> 
>  > I saw the patch to enables this, but it is very confussing...
>  > 
>  > Any ideas how to start?
>  > 
> 
> What OS and SSH version do you intend to use on clients, FW and/or
> internal host?
> 
The OS of the Firewall is RedHat 6.2 and the clients would be Windows machines... (I already
got a ssh client for windows).

It seems harder to encrypt only the traffic between the firewall and the clients (i.e. using ssh-gw), than
encrypt the traffice between the clients and the target host (i.e. using plug-gw)? 

Have you used the ssh-gw? I've read the README file, but it's kind of confussing...I mean...
do you have to set up the ssh server in the firewall? Or just install the ssh-gw?

Thanks again...


Luis Fernando Barrera
luba@assist.com.gt 


From owner-fwtk-users@ex.tis.com Tue Sep 19 12:34 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA19007
	Tue, 19 Sep 2000 12:34:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA17949;
	Tue, 19 Sep 2000 09:42:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 19 Sep 2000 07:18:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA25465
	for fwtk-users-outgoing; Tue, 19 Sep 2000 07:18:37 -0700 (PDT)
Reply-To: <roelfs@crossroads.co.za>
From: "Roelf Schreurs" <roelfs@crossroads.co.za>
To: <fwtk-users@ex.tis.com>
Subject: version
Date: Tue, 19 Sep 2000 12:54:02 +0200
Message-ID: <NEBBKOMDILECKHDCCLLEGEDJCDAA.roelfs@crossroads.co.za>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 166

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Is FWTK regarded as a firewall 1?




From owner-fwtk-users@ex.tis.com Tue Sep 19 19:03 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA20157
	Tue, 19 Sep 2000 19:03:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA20602;
	Tue, 19 Sep 2000 16:12:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 19 Sep 2000 13:37:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA25894
	for fwtk-users-outgoing; Tue, 19 Sep 2000 13:37:20 -0700 (PDT)
Date: Tue, 19 Sep 2000 16:36:03 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Roelf Schreurs <roelfs@crossroads.co.za>
Cc: fwtk-users@ex.tis.com
Subject: Re: version
Message-Id: <20000919163603.B5010@washington.cospo.osis.gov>
Mail-Followup-To: Roelf Schreurs <roelfs@crossroads.co.za>,
	fwtk-users@ex.tis.com
References: <NEBBKOMDILECKHDCCLLEGEDJCDAA.roelfs@crossroads.co.za>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NEBBKOMDILECKHDCCLLEGEDJCDAA.roelfs@crossroads.co.za>; from roelfs@crossroads.co.za on Tue, Sep 19, 2000 at 12:54:02PM +0200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 943

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, Sep 19, 2000 at 12:54:02PM +0200, Roelf Schreurs wrote:
> Is FWTK regarded as a firewall 1?

I do not understand your question.

The FireWall ToolKit is a kit of various software pieces from which
professional computer security engineers can build a firewall with some
reasonable functionality on a hardened computer base [which they must
supply].  Many regard it as a compile-and-go firewall, although the
people who distribute it are careful to point out that it is not.

Firewall-1 is a product of Checkpoint, and has nothing to do with FWTK.

Cf. <URL: http://www.fwtk.org/>.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Wed Sep 20 21:44 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA24873
	Wed, 20 Sep 2000 21:44:04 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA28179;
	Wed, 20 Sep 2000 18:53:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 20 Sep 2000 16:29:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA13498
	for fwtk-users-outgoing; Wed, 20 Sep 2000 16:29:27 -0700 (PDT)
Date: Wed, 20 Sep 2000 19:28:39 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: fwtk-users@ex.tis.com
Cc: "Michael St. Laurent" <mstlaurent@hartwellcorp.com>
Subject: Re: Can you help with this?
Message-Id: <20000920192838.R12272@washington.cospo.osis.gov>
Mail-Followup-To: fwtk-users@ex.tis.com,
	"Michael St. Laurent" <mstlaurent@hartwellcorp.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2670

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Messed up the group mailing list address.  Here it is again.

On Wed, Sep 20, 2000 at 01:38:52PM -0700, Michael St. Laurent wrote:
> I sent this to the list but got no response.  I also noticed that the
amount
> of mail I get from the list has gone down a lot.  Since the problem I'm
> having is with smap I started to wonder if I was getting every message
that
> was sent.
> 
> Could you take a moment to look at this?
> 
> I've got fwtk 2.1 with the yao-smap patches running under SuSE Linux on
> Intel.  In the netperm-table I've specified the "smap: unknown-host 1"
> setting as well as the "broken-from" setting.  The logfile indicates
(unless
> I'm reading it wrong) that the connection is allowed but is dropped after
> the 10 minute timeout period expires.  Below is a snippet from the
logfile:
> 
> Sep 15 16:40:12 guardian smap[5150]: 207.204.245.3 host address lookup
> failed
> Sep 15 16:40:12 guardian smap[5150]: connect host=unknown/207.204.245.3
> Sep 15 16:50:12 guardian smap[5150]: Network timeout signal after 600
> seconds
> 
> A packet trace shows that the sending system connects, is sent the
greeting
> "220 guardian.hartwellcorp.com SMTP/smap Ready", it replies with a "HELO
> cadmail.cadnet.com" which is acknowledged by smap (with a TCP ACK) and
then
> nothing more happens on the wire til the timeout triggers and smap
> terminates the connection.  A "gdb" stack backtrace shows the following:
> 
> (gdb) bt
> #0  0x4008674e in ?? ()
> #1  0x400e87f5 in ?? ()
> #2  0x400ddef8 in ?? ()
> #3  0x805f54e in   ()
> #4  0x805f39e in gethostbyaddr ()
> #5  0x804c4d0 in hostmatch (pattern=0x8087e20
"localhost.hartwellcorp.com",
>     name=0x8086190 "207.204.245.3") at nama.c:363
> #6  0x804a64e in check_hostname ()
> #7  0x8048d1c in main ()
> (gdb)
> 
> The sender admits that their ISP will not allow/perform reverse DNS on the
> address (which is probably what is causing the problem).  Is there some
way
> to work around this?
> 
> 
> --------------------
> Michael St. Laurent
> Hartwell Corporation

I don't remember seeing this, so I will CC it to the list.

It looks like your DNS lookups are taking an unconscionably long time.
What is your DNS setup?

Ah!  It did appear - but was sandwiched between a lot of other things.
Perhaps now someone might come up with a better answer.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Sep 21 00:23 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA25141
	Thu, 21 Sep 2000 00:22:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA10247;
	Wed, 20 Sep 2000 21:31:32 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 20 Sep 2000 19:58:51 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA03955
	for fwtk-users-outgoing; Wed, 20 Sep 2000 19:58:19 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000920223711.00b98260@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Wed, 20 Sep 2000 22:48:12 -0400
To: Joseph S D Yao <jsdy@cospo.osis.gov>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Can you help with this?
Cc: "Michael St. Laurent" <mstlaurent@hartwellcorp.com>
In-Reply-To: <20000920192838.R12272@washington.cospo.osis.gov>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1640

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:28 PM 9/20/00 -0400, Joseph S D Yao wrote:
>I don't remember seeing this, so I will CC it to the list.
>
>It looks like your DNS lookups are taking an unconscionably long time.
>What is your DNS setup?
>
>Ah!  It did appear - but was sandwiched between a lot of other things.
>Perhaps now someone might come up with a better answer.

Ah! I've just had this problem!

I've got a long list of banned domains in my netperm-table. (I'm one of 
those anti-spam natzis here, I guess.) The problem with this happens when 
you've got a mail host that's trying to send to you with an invalid reverse 
DNS lookup. (Specifically when you try nslookup on their address and you 
see delay followed by 'server failed').
This triggers a long delay in smap - when a host connects, smap calls 
check_spamhost(); that routine reads each "smap: spam xxxxx" line in the 
netperma table and tries a match with the host address against those records.
If the netperm-table entry isn't a network address (1.1.3.* versus 
*.spammer.com), hostmatch must convert the passed-in address to a hostname 
in order to check if it matches. For broken DNS systems, this can take a 
VERY long time if you've got several name entires in your spam list.

I fixed this by adding a new routine to smap that front-ends hostmatch. 
Since smap already knows the IP and the hostname (or unknown), this new 
routine uses that already-known information to pass to hostmatch; then 
hostmatch doesn't have to do it's own reverse lookup.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Sep 21 12:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA27746
	Thu, 21 Sep 2000 12:55:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA16521;
	Thu, 21 Sep 2000 10:04:12 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 21 Sep 2000 08:19:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA28200
	for fwtk-users-outgoing; Thu, 21 Sep 2000 08:18:34 -0700 (PDT)
Date: Thu, 21 Sep 2000 11:16:59 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Rick Murphy <rmurphy@itm-inst.com>
Cc: fwtk-users@ex.tis.com, "Michael St. Laurent" <mstlaurent@hartwellcorp.com>
Subject: Re: Can you help with this?
Message-Id: <20000921111659.C20898@washington.cospo.osis.gov>
Mail-Followup-To: Rick Murphy <rmurphy@itm-inst.com>, fwtk-users@ex.tis.com,
	"Michael St. Laurent" <mstlaurent@hartwellcorp.com>
References: <20000920192838.R12272@washington.cospo.osis.gov> <4.3.2.7.2.20000920223711.00b98260@mail.itm-inst.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <4.3.2.7.2.20000920223711.00b98260@mail.itm-inst.com>; from rmurphy@itm-inst.com on Wed, Sep 20, 2000 at 10:48:12PM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 980

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, Sep 20, 2000 at 10:48:12PM -0400, Rick Murphy wrote:
> I fixed this by adding a new routine to smap that front-ends hostmatch. 
> Since smap already knows the IP and the hostname (or unknown), this new 
> routine uses that already-known information to pass to hostmatch; then 
> hostmatch doesn't have to do it's own reverse lookup.
>          -Rick

Oh, right!  I noticed that problem.  And I was going to do much the
same thing, but it involved re-writing a LOT of the code, the way I was
going to do it.  So it didn't get done.

Did you post your patch?

[@itm-inst.com???  Interesting.  Where is Evergreen Lane?]

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Sep 21 15:29 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA28260
	Thu, 21 Sep 2000 15:29:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA16779;
	Thu, 21 Sep 2000 12:39:11 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 21 Sep 2000 11:06:59 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA29491
	for fwtk-users-outgoing; Thu, 21 Sep 2000 11:06:47 -0700 (PDT)
X-Authentication-Warning: zerberus.promos-consult.de: smap set sender to <priebe@promos-consult.de> using -f
From: Andreas Priebe <Andreas.Priebe@promos-consult.de>
Message-Id: <200009211803.UAA18621@dimon.promos-consult.de>
Subject: smap@do.main in envelope
To: fwtk-users@ex.tis.com
Date: Thu, 21 Sep 2000 20:03:29 +0200 (CEST)
X-Mailer: ELM [version 2.4ME+ PL65 (25)]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1047

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

as you (at least those reading on UNIX) can probably see,
my e-mail is going trough smap and is then handled over to sendmail.

This makes smap@promos-consult.de the sender in the envelope and appears
in the Return-Path header, i.e.  the UNIX mail folder format I have

>From smap@promos-consult.de  Mon Sep 18 19:37:42 2000
Return-Path: <smap@promos-consult.de>

The From: lines are correct. Nevertheless some mailers out there
in real life use Return-Path: for replies.

Can I change this or is or is this problem particular for me
and you all don't suffer from this?

I use FWTK2.1.

TIA,

Andreas
-- 
****************************************************************************
* Andreas Priebe                E-Mail:   Andreas.Priebe@promos-consult.de *
* Promos consult GmbH & Co KG   Tel/FAX:             030 243 117 -13 / -29 *
****************************************************************************

From owner-fwtk-users@ex.tis.com Thu Sep 21 15:49 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA28300
	Thu, 21 Sep 2000 15:49:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA20308;
	Thu, 21 Sep 2000 12:58:48 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 21 Sep 2000 11:37:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA05287
	for fwtk-users-outgoing; Thu, 21 Sep 2000 11:37:44 -0700 (PDT)
X-Authentication-Warning: proxy.tfcc.com: mail set sender to <twilliams@tfcci.com> using -f
From: "Todd Williams" <twilliams@tfcci.com>
To: <fwtk-users@ex.tis.com>
Subject: http-gw buffer overrun?
Date: Thu, 21 Sep 2000 14:36:26 -0400
Message-ID: <00fa01c023fa$da817fd0$c802a8c0@toddntbox.tfcc.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 369

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Has anybody seen this before?

> Sep 20 16:36:15 proxy http-gw[19092]: getline: buffer overrun
> Sep 20 16:37:30 proxy http-gw[19128]: getline: buffer overrun

It doesn't look good, regardless.  Any insight would be helpful!

Thanks,

Todd

From owner-fwtk-users@ex.tis.com Thu Sep 21 19:14 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA28822
	Thu, 21 Sep 2000 19:14:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA24020;
	Thu, 21 Sep 2000 16:23:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 21 Sep 2000 14:46:05 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA08926
	for fwtk-users-outgoing; Thu, 21 Sep 2000 14:45:34 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000921173340.00bb95b0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Thu, 21 Sep 2000 17:41:52 -0400
To: Joseph S D Yao <jsdy@cospo.osis.gov>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Can you help with this?
Cc: fwtk-users@ex.tis.com, "Michael St. Laurent" <mstlaurent@hartwellcorp.com>
In-Reply-To: <20000921111659.C20898@washington.cospo.osis.gov>
References: <4.3.2.7.2.20000920223711.00b98260@mail.itm-inst.com>
 <20000920192838.R12272@washington.cospo.osis.gov>
 <4.3.2.7.2.20000920223711.00b98260@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1084

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:16 AM 9/21/00 -0400, Joseph S D Yao wrote:
>Oh, right!  I noticed that problem.  And I was going to do much the
>same thing, but it involved re-writing a LOT of the code, the way I was
>going to do it.  So it didn't get done.
>
>Did you post your patch?

I put the change in last weekend.. I'd like to run this a bit longer before 
making it 'public'. My smap uses your patch with several tweaks here and 
there - RBL support, corrections for spam rejects (there are hosts that 
don't accept an error on the connect when you send 'em a 421 - they just 
immediately connect back, get the error, try again. Tens of thousands of 
rejects over a few hours.),   etc. You're welcome to the source if you're 
brave.

>[@itm-inst.com???  Interesting.  Where is Evergreen Lane?]

ITMI is my wife's company. Actually located on Annandale Rd in Annandale 
(inside the beltway.) The company pays for the DSL connection, I support 
the firewall.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Sep 21 19:14 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA28823
	Thu, 21 Sep 2000 19:14:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA24042;
	Thu, 21 Sep 2000 16:23:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 21 Sep 2000 15:00:34 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA11267
	for fwtk-users-outgoing; Thu, 21 Sep 2000 15:00:13 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000921174352.00bd4a50@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Thu, 21 Sep 2000 17:45:27 -0400
To: Andreas Priebe <Andreas.Priebe@promos-consult.de>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: smap@do.main in envelope
In-Reply-To: <200009211803.UAA18621@dimon.promos-consult.de>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 509

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 08:03 PM 9/21/00 +0200, Andreas Priebe wrote:
>This makes smap@promos-consult.de the sender in the envelope and appears
>in the Return-Path header, i.e.  the UNIX mail folder format I have

There's a sendmail.cf option to permit the SMAP user to be trusted - add 
"smap" to the end of your "T" line (which probablu now reads like the 
following:)
Troot daemon
         -Rick



From owner-fwtk-users@ex.tis.com Thu Sep 21 19:14 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA28824
	Thu, 21 Sep 2000 19:14:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA24024;
	Thu, 21 Sep 2000 16:23:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 21 Sep 2000 15:01:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA11518
	for fwtk-users-outgoing; Thu, 21 Sep 2000 15:00:53 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000921174217.00bbd680@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Thu, 21 Sep 2000 17:43:47 -0400
To: "Todd Williams" <twilliams@tfcci.com>, <fwtk-users@ex.tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: http-gw buffer overrun?
In-Reply-To: <00fa01c023fa$da817fd0$c802a8c0@toddntbox.tfcc.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 676

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:36 PM 9/21/00 -0400, Todd Williams wrote:
>Has anybody seen this before?
>
> > Sep 20 16:36:15 proxy http-gw[19092]: getline: buffer overrun
> > Sep 20 16:37:30 proxy http-gw[19128]: getline: buffer overrun
>
>It doesn't look good, regardless.  Any insight would be helpful!

That just means a request line was larger than the http-gw buffer. There 
are unfortunately some systems that like HUGE amounts of query data on the 
end of their URLs. Nothing bad happens other than the fact that the request 
doesn't get through.
         -Rick



From owner-fwtk-users@ex.tis.com Sun Sep 24 21:13 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA08216
	Sun, 24 Sep 2000 21:13:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA26530;
	Sun, 24 Sep 2000 18:21:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 24 Sep 2000 15:53:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA23354
	for fwtk-users-outgoing; Sun, 24 Sep 2000 15:53:34 -0700 (PDT)
X-Authentication-Warning: crusade.pcsnc.lab: smap set sender to <pcimon@pcsnc.com> using -f
Message-ID: <51B208AA1634D411A46600400567B31124A4@babylon5.pcsnc.lab>
From: Pascal Cimon <pcimon@pcsnc.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Smap gives a deny messages even when the message gets delivered
Date: Sun, 24 Sep 2000 18:52:33 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 936

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all,

I recently turned smap spam checking in my netperm-table (I use smap with
the yao-patch) with the following options:

smap, smapd:    userid 300
smap: domains pcsnc.com 
smap: hosts 10.1.1.1
smap: check-from-address 1
smap: scrub-spam 1
smap: spam fill.zzn.com sumomo.oiuw.oiu.ac.jp
smap: spam-block deny fill.zzn.com *
smap, smapd:    directory /var/spool/smap
smapd:          executable /usr/bin/smapd
smapd:          sendmail /usr/sbin/sendmail
smapd:          baddir /var/spool/smap/badmail
smapd:          wakeup 10
smap:           timeout 3600

The problem is that ever since I added the spam lines when a valid e-mail
comes in I first get a deny then a permit and the message is delivered. Why
does the deny appear even if the mail gets delivered? any way to fix it?

Thanks for any help

From owner-fwtk-users@ex.tis.com Tue Sep 26 01:01 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id BAA12623
	Tue, 26 Sep 2000 01:01:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id WAA19727;
	Mon, 25 Sep 2000 22:10:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 25 Sep 2000 19:32:07 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA15118
	for fwtk-users-outgoing; Mon, 25 Sep 2000 19:31:56 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@ex.tis.com>
Subject: ssh-gw
Date: Mon, 25 Sep 2000 20:30:38 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFEEMIOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id TAA15107
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 859

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

Has anyone applied with success the ssh-gw patch? 

The readme file says the patch is intended to ssh 1.2.20, but the
lastest 1.2.x version is 1.2.30... Anyone has use it?
I've applied the patch to the 1.2.20 version, but even on that
I got compile time errors...

I've tracked the user-list back to 1997 without  seeing anyone
who applied it with success.... It seems that the majority of people
prefers to encrypt the whole connection, from the remote host
to the target host, and using only plug-gw.

I'd like to encryp only the connection from the remote host (in the internet)
to the firewall and then clear-text to the internal servers...

thanks in advance for the help

Luis Fernando Barrera
luba@assist.com.gt 


From owner-fwtk-users@ex.tis.com Tue Sep 26 06:34 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA13796
	Tue, 26 Sep 2000 06:34:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA27815;
	Tue, 26 Sep 2000 03:42:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 26 Sep 2000 02:08:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA25246
	for fwtk-users-outgoing; Tue, 26 Sep 2000 02:08:28 -0700 (PDT)
X-Authentication-Warning: block.type.co.uk: mail set sender to <stewart@type.co.uk> using -f
Message-Id: <4.3.2.7.2.20000926095813.00b87520@127.0.0.1>
X-Sender: anderson/mailhost.type.co.uk@127.0.0.1
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Tue, 26 Sep 2000 10:06:35 +0100
To: fwtk-users@ex.tis.com
From: Stewart Anderson <stewart@type.co.uk>
Subject: fwtksyserr
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 394

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

Running with RH 6.2 dist. FWTK 2.1

Although everything appears to be functioning correctly the logs are 
showing an fwtksyserr every two minutes;

Failed to bind port xx, Address already in use.

Is this normal behaviour?

TIA for any thoughts

Stewart.


From owner-fwtk-users@ex.tis.com Tue Sep 26 06:55 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA13877
	Tue, 26 Sep 2000 06:55:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA28410;
	Tue, 26 Sep 2000 04:04:48 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 26 Sep 2000 02:42:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA26025
	for fwtk-users-outgoing; Tue, 26 Sep 2000 02:42:45 -0700 (PDT)
X-Authentication-Warning: sncom1.scs.dra.hmg.gb: smapd set sender to <RLSwale@scs.dera.gov.uk> using -f
Message-ID: <D92E8A325F44D311808F009027723AA401C000@ntexch01s.scs.dra.hmg.gb>
From: Robin Swale <RLSwale@scs.dera.gov.uk>
To: fwtk-users@ex.tis.com
Subject: UDP through a Firewall
Date: Tue, 26 Sep 2000 10:40:10 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 920

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Friends,
I need to add UDP capabilities to my firewall which is currently running
FWTK 2.1 on Linux 6.0. Is udprelay the preferred method or are there other
solutions? I should be grateful for any information.
Thanks in advance.
Robin Swale
------------------------------------------------------------------------
Robin Swale
Computer Manager
Space Department
DERA Farnborough
Hants GU14 0LX
------------------------------------------------------------------------
The Information contained in this E-Mail and any subsequent correspondence
is private and is intended solely for the intended recipient(s). For those
other
than the recipient any disclosure, copying, distribution, or any action
taken or
omitted to be taken in reliance on such information is prohibited and may be
unlawful.



From owner-fwtk-users@ex.tis.com Tue Sep 26 10:46 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA14884
	Tue, 26 Sep 2000 10:46:22 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA16972;
	Tue, 26 Sep 2000 07:55:52 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 26 Sep 2000 06:25:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA05212
	for fwtk-users-outgoing; Tue, 26 Sep 2000 06:25:34 -0700 (PDT)
X-Authentication-Warning: block.type.co.uk: mail set sender to <stewart@type.co.uk> using -f
Message-Id: <4.3.2.7.2.20000926142211.00b8de40@127.0.0.1>
X-Sender: anderson/mailhost.type.co.uk@127.0.0.1
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Tue, 26 Sep 2000 14:23:50 +0100
To: fwtk-users@ex.tis.com
From: Stewart Anderson <stewart@type.co.uk>
Subject: Re: fwtksyserr
In-Reply-To: <39D0A22A.A505B937@v-one.com>
References: <4.3.2.7.2.20000926095813.00b87520@127.0.0.1>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 670

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:18 26/09/00 -0400, you wrote:
 >Stewart Anderson wrote:
 >>
 >> Running with RH 6.2 dist. FWTK 2.1
 >>
 >> Although everything appears to be functioning correctly the logs are
 >> showing an fwtksyserr every two minutes;
 >>
 >> Failed to bind port xx, Address already in use.
 >
 >Answer is in the FAQ:
 >	2.1.13 I can't start the toolkit; I am getting "Failed to bind to port
 >XXX" or "Address already in use"
 >	http://www.fwtk.org/fwtk/faq/faq.html#2.1.13
 >

Oops, thanks for info Keith, Paul - missed it in the FAQ -


Stewart


From owner-fwtk-users@ex.tis.com Tue Sep 26 10:46 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA14885
	Tue, 26 Sep 2000 10:46:22 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA16966;
	Tue, 26 Sep 2000 07:55:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 26 Sep 2000 06:18:19 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA04397
	for fwtk-users-outgoing; Tue, 26 Sep 2000 06:17:59 -0700 (PDT)
Message-ID: <39D0A22A.A505B937@v-one.com>
Date: Tue, 26 Sep 2000 09:18:34 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.75 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Stewart Anderson <stewart@type.co.uk>
CC: fwtk-users@ex.tis.com
Subject: Re: fwtksyserr
References: <4.3.2.7.2.20000926095813.00b87520@127.0.0.1>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 622

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Stewart Anderson wrote:
> 
> Running with RH 6.2 dist. FWTK 2.1
> 
> Although everything appears to be functioning correctly the logs are
> showing an fwtksyserr every two minutes;
> 
> Failed to bind port xx, Address already in use.

Answer is in the FAQ:
	2.1.13 I can't start the toolkit; I am getting "Failed to bind to port
XXX" or "Address already in use"
	http://www.fwtk.org/fwtk/faq/faq.html#2.1.13

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Tue Sep 26 10:52 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA14906
	Tue, 26 Sep 2000 10:49:16 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA17426;
	Tue, 26 Sep 2000 07:58:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 26 Sep 2000 06:40:20 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA06432
	for fwtk-users-outgoing; Tue, 26 Sep 2000 06:36:45 -0700 (PDT)
X-Authentication-Warning: conga.super.unam.mx: dsc owned process doing -bs
Date: Mon, 25 Sep 2000 18:30:58 -0500 (CDT)
From: Seguridad en Computo - Mexico <dsc@asc.unam.mx>
X-Sender: dsc@conga.super.unam.mx
To: Area de Seguridad en Computo <asc@conga.super.unam.mx>
cc: aleph1@securityfocus.org, ryan@securityfocus.com, me@robertgraham.com,
        jroculan@securityfocus.com, jroculan@securityfocus.org,
        amackie@home.com, BlueBoar@thievco.com, vpn@securityfocus.com,
        firewall-wizards@nfr.net, firewalls@lists.gnac.net,
        fwtk-users@ex.tis.com, isn@sekurity.org, cert@cert.org,
        comp-privacy@uwm.edu, ntbugtraq@listserv.ntbugtraq.com,
        ntsecurity@iss.net, maryhdz@servidor.unam.mx
Subject: Computer Security Mexico
In-Reply-To: <Pine.LNX.4.21.0007240204160.19658-100000@conga.super.unam.mx>
Message-ID: <Pine.LNX.4.21.0009251812590.25077-100000@conga.super.unam.mx>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2272

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----


Good day!!

The dates for the call for papers is ending next September 29th.

Please send your works in Progress,conference, workshops  to :

	Computer Security Department
	National autonomus University of Mexico
	DGSCA-UNAM
	E-Mail: comite@seguridad.unam.mx
	http://www.seguridad2000.unam.mx

The Academic-Scientific committe Will evaluate all the submissions and
proposals.

 				Important Dates
 				................
 
 Paper submissions: September 29th
 Acceptance notification: October 10th
 Final papers due: October 28th
 Event Dates: November 26th to December 1st
 
                           Program Committee 
 			.....................
 
 The committe will be composed by:
 
 	     >> Dr. Eugene Spafford 
         	Director of CERIAS, Purdue University, EU
 
 	     >> Wietse Venema
         	IBM T.J. Watson Research Center
 
 	     >> Dr. Eugene Schultz
         	Global Integrity, EU
 
 	     >> Linda McCarthy
         	Net-Defense, EU
 
 	     >> M. en C. Diego Zamboni
         	CERIAS, Purdue University
 
 	     >> Juan Carlos Guel Lopez
         	Computer Security Department DGSCA-UNAM, Mexico

 
 			     Further Information
 			    .....................
 
      E-mail:comite@seguridad.unam.mx 
      http://www.seguridad2000.unam.mx
      http://www.disc2000.unam.mx
      http://www.seguridad.unam.mx



- ---
Juan Carlos Guel L'opez
Departamento Seguridad en C'omputo   E-mail: dsc@asc.unam.mx
DGSCA, UNAM                          Tel.: 5622-81-69  Fax: 5622-80-43
Circuito Exterior, C. U.             WWW: http://www.seguridad.unam.mx/
04510 Mexico D. F.                   PGP: finger dsc@ds5000.super.unam.mx 

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQEVAwUBOc/gPI13HVLc009TAQEU8wgAlWY8YCo1UpFssK5gqm4ojZIHHN4m4qJP
Otu2EkqowYZLBP+WD/Kiq1I9T4AiwJdvlsuLwjObv5DGNf2PtK3uM4lRX9tAyzwh
QpRqoSCwZO2An7jS3UAWfFCkQI7U8EQvf1mgJZfZyKMbQKa0Ge/orkAHTge+syZM
vVEAIeqx2LC23icO5IUK1vODZSvyAoWAdKaZ4efNWhp3hOH0Z0QJkGtVVXrRi1MU
zBCWwzeQJ8ti/HBabJX9EfqDtAovpj32b+Afkz3/UhTwurRp4jK670RtmD+r+IY7
+anu5/CZciSLP1so2+0YQCKay5WbkMJ6Qn0Ndv5qJ5H7TasjQWpk4w==
=rIa8
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Wed Sep 27 05:52 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA19001
	Wed, 27 Sep 2000 05:52:27 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA14175;
	Wed, 27 Sep 2000 03:00:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 00:31:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA10771
	for fwtk-users-outgoing; Wed, 27 Sep 2000 00:31:33 -0700 (PDT)
Message-Id: <s9d21273.004@genting.com.my>
X-Mailer: Novell GroupWise 4.1
Date: Wed, 27 Sep 2000 15:27:55 +0800
From: LIM CHUAN CHUIEN <cclim@genting.com.my>
To: fwtk-users@ex.tis.com
Subject: RE: Gauntlet Firewall Issue
Mime-Version: 1.0
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 380

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

My gauntlet firewall version 5.5 in Solaris had mail problem. Based on log
file, "bogus mail" appear on the log files. It causes my firewall not
working properly. Can anyone provide me some solution about it.

Thanks in advance.

Regards,
 CClim

From owner-fwtk-users@ex.tis.com Wed Sep 27 10:06 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA19718
	Wed, 27 Sep 2000 10:06:13 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA25396;
	Wed, 27 Sep 2000 07:15:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 05:43:07 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA18816
	for fwtk-users-outgoing; Wed, 27 Sep 2000 05:42:57 -0700 (PDT)
Message-ID: <200009270839340990.17FC0A8D@ford>
X-Mailer: Calypso Version 3.10.03.02 (3)
Date: Wed, 27 Sep 2000 08:39:34 -0400
From: "Phil Udel" <Phil_Udel@salemleasing.com>
To: fwtk-users@ex.tis.com
Subject: FWTK Lic Questions
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative; boundary="=====_97005837416827=_"
Content-Length: 3161

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

--=====_97005837416827=_
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable

HI
I just started at a new company that ran the FWTC.  It Looks like a nice=
 product.  I called PNP to see what the current version of the FWTC was,=
 and to see what gauntlet cost. Well, When the salesman found out we ran=
 the FWTC at a company he said I need to pay him 12k or stop using the=
 product.  I told him No Way and that I would replace the product with=
 t.rex ASAP.  The salesman said he was going to send software cops to make=
 sure I did.  I don't know the history of this product or the company, so=
 here are my questions.  Question 1:Has the FWTC always been a non-profit=
 product?   Question Two: has anyone else had to pay for the FWTK. Question=
 Three: If so How much did you pay?
Thanks 
Phillip Udel
Admin@SalemLeasing.com
(800) 877-2536 Ext 212

Rules To Live By:
1) On the keyboard of life, always keep one finger on the escape key.
2) There are absolutely no absolutes.


--=====_97005837416827=_
Content-Type: text/html; charset="ISO-8859-1"

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=iso-8859-1" http-equiv=Content-Type>
<META content="MSHTML 5.00.2614.3500" name=GENERATOR></HEAD>
<BODY bgColor=#ffffff style="FONT-FAMILY: Arial" text=#000000><FONT size=2>
<DIV><FONT size=2>HI</FONT></DIV>
<DIV><FONT size=2>I just started at a new company that ran the FWTC.&nbsp; It 
Looks like a nice product.&nbsp; I called PNP to see what the current version of 
the FWTC was, and&nbsp;to see what gauntlet cost</FONT><FONT size=2>. Well, When 
the salesman found out we ran the FWTC at a company he said I need to pay him 
12k or stop using the product.&nbsp; I told him No Way and that I would replace 
the product with t.rex ASAP.&nbsp; The salesman said&nbsp;he was going to send 
software cops to make sure I did.&nbsp;</FONT><FONT size=2>&nbsp;I don't know 
the history of this product or the company, so here&nbsp;are my questions.&nbsp; 
Question 1:Has the FWTC </FONT><FONT size=2>always been a non-profit 
product?&nbsp;&nbsp; Question Two: has anyone else had to pay for the FWTK. 
Question Three: If so How much did you pay?</FONT></DIV>
<DIV>&nbsp;</DIV></FONT></BODY></HTML>

<BR>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=windows-1252" http-equiv=Content-Type>
<META content="MSHTML 5.00.2614.3500" name=GENERATOR></HEAD>
<BODY bgColor=#ffffff style="FONT-FAMILY: Arial" text=#000000>
<DIV>Thanks </DIV>
<DIV>Phillip Udel</DIV>
<DIV><A href="mailto:Admin@SalemLeasing.com">Admin@SalemLeasing.com</A></DIV>
<DIV>(800) 877-2536 Ext 212</DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT size=3>Rules To Live By:</FONT></DIV>
<DIV><FONT size=3>1) On the keyboard of life, always keep one finger on the 
escape key.</FONT></DIV>
<DIV><FONT size=3>2) There are absolutely no absolutes.</FONT></DIV>
<DIV>&nbsp;</DIV></BODY></HTML>


--=====_97005837416827=_--


From owner-fwtk-users@ex.tis.com Wed Sep 27 12:00 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA20541
	Wed, 27 Sep 2000 12:00:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA10618;
	Wed, 27 Sep 2000 09:09:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 07:38:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA28043
	for fwtk-users-outgoing; Wed, 27 Sep 2000 07:38:36 -0700 (PDT)
X-Authentication-Warning: medtel.medtel.com: mail set sender to <pmahan@medtel.com> using -f
Message-ID: <39D206C4.BFFCF2D2@medtel.com>
Date: Wed, 27 Sep 2000 10:40:04 -0400
From: Patrick Mahan <pmahan@medtel.com>
X-Mailer: Mozilla 4.05 [en] (WinNT; I)
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Unable to exchange mail after yao-smap patch
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1456

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Greetings,

I have seen folks post with similar
problems to mine, but have seen no
resolution, so forgive me if this is
redundant.

Successfuly applied the yao-smap patch
and recompile went well. Edited my
netperm-table as follows:

smap, smapd:    userid 8
smap, smapd:    groupid 12
smap, smapd:    directory
/var/spool/smap
smapd:          executable
/usr/local/etc/smapd
smapd:          sendmail
/usr/sbin/sendmail
smap:   permit-domains mydomain.com,
*.mydomain.com
smap:   permit-hosts 192.168.101.1
smap:           timeout
3600                                             

However, no mail is going through
firewall either way. There are no
references to smap in the syslog and
telnet to port 25 produces:

telnet: Unable to connect to remote
host: Connection refused 

ps ax shows that smap is running as
daemon.    

netstat -an on the internal mailserver
shows:

tcp        0      2
192.168.101.1:1763     
206.239.xxx.xxx:25       SYN_SENT
tcp        0      2
192.168.101.1:1682     
206.239.xxx.xxx:25       SYN_SENT   

which seems a tad odd to me as the
206.239.xxx.xxx is the external
interface on the firewall.

Where have I gone wrong? My hunch is the
netperm-table (I have tried things with
and without the "permit-" prefix). Any
and all help will be greatly
appreciated.  

Running on a Linux box.

Patrick

From owner-fwtk-users@ex.tis.com Wed Sep 27 12:14 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA20582
	Wed, 27 Sep 2000 12:14:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA12602;
	Wed, 27 Sep 2000 09:23:16 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 08:04:11 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA01030
	for fwtk-users-outgoing; Wed, 27 Sep 2000 08:04:00 -0700 (PDT)
Message-ID: <200009261614350710.14761F0C@ford>
X-Mailer: Calypso Version 3.10.03.02 (3)
Date: Tue, 26 Sep 2000 16:14:35 -0400
From: "Phil Udel" <Phil_Udel@salemleasing.com>
To: fwtk-users@ex.tis.com
Subject: FWTC LIC Question
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative; boundary="=====_9699992755705=_"
Content-Length: 3137

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

--=====_9699992755705=_
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable

HI
I just started at a new company that ran the FWTC.  It Looks like a nice=
 product.  I called PNP to see what the current version of the FWTC was,=
 and to see what gauntlet cost. Well, When the salesman found out we ran=
 the FWTC at a company he said I need to pay him 12k or stop using the=
 product.  I told him No Way and that I would replace the product with=
 t.rex ASAP.  The salesman said he was going to send software cops to make=
 sure I did.  I don't know the history of this product or the company, so=
 here are my questions.  Question 1:Has the FWTC always been a non-profit=
 product?   Question Two: has anyone else had to pay for the FWTK. Question=
 Three: If so How much did you pay?
Thanks 
Phillip Udel
Admin@SalemLeasing.com
(800) 877-2536 Ext 212

Rules To Live By:
1) On the keyboard of life, always keep one finger on the escape key.
2) There are absolutely no absolutes.


--=====_9699992755705=_
Content-Type: text/html; charset="ISO-8859-1"

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=iso-8859-1" http-equiv=Content-Type>
<META content="MSHTML 5.00.2614.3500" name=GENERATOR></HEAD>
<BODY bgColor=#ffffff style="FONT-FAMILY: Arial" text=#000000>
<DIV><FONT size=2>HI</FONT></DIV>
<DIV><FONT size=2>I just started at a new company that ran the FWTC.&nbsp; It 
Looks like a nice product.&nbsp; I called PNP to see what the current version of 
the FWTC was, and&nbsp;to see what gauntlet cost</FONT><FONT size=2>. Well, When 
the salesman found out we ran the FWTC at a company he said I need to pay him 
12k or stop using the product.&nbsp; I told him No Way and that I would replace 
the product with t.rex ASAP.&nbsp; The salesman said&nbsp;he was going to send 
software cops to make sure I did.&nbsp;</FONT><FONT size=2>&nbsp;I don't know 
the history of this product or the company, so here&nbsp;are my questions.&nbsp; 
Question 1:Has the FWTC </FONT><FONT size=2>always been a non-profit 
product?&nbsp;&nbsp; Question Two: has anyone else had to pay for the FWTK. 
Question Three: If so How much did you pay?</FONT></DIV>
<DIV>&nbsp;</DIV></BODY></HTML>

<BR>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=windows-1252" http-equiv=Content-Type>
<META content="MSHTML 5.00.2614.3500" name=GENERATOR></HEAD>
<BODY bgColor=#ffffff style="FONT-FAMILY: Arial" text=#000000>
<DIV>Thanks </DIV>
<DIV>Phillip Udel</DIV>
<DIV><A href="mailto:Admin@SalemLeasing.com">Admin@SalemLeasing.com</A></DIV>
<DIV>(800) 877-2536 Ext 212</DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT size=3>Rules To Live By:</FONT></DIV>
<DIV><FONT size=3>1) On the keyboard of life, always keep one finger on the 
escape key.</FONT></DIV>
<DIV><FONT size=3>2) There are absolutely no absolutes.</FONT></DIV>
<DIV>&nbsp;</DIV></BODY></HTML>


--=====_9699992755705=_--

From owner-fwtk-users@ex.tis.com Wed Sep 27 14:09 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA20921
	Wed, 27 Sep 2000 14:09:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA27107;
	Wed, 27 Sep 2000 11:19:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 09:47:35 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA15669
	for fwtk-users-outgoing; Wed, 27 Sep 2000 09:47:24 -0700 (PDT)
From: "C. Regis Wilson" <rwilson@gnp.com>
To: <fwtk-users@lists.nai.com>
Subject: SSH proxy/gateway
Date: Wed, 27 Sep 2000 09:45:47 -0700
Message-ID: <NEBBKBGDKLMNCDGFGONOOECCCAAA.rwilson@gnp.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1164

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I recently read a question about SSH and fwtk.  If I read it correctly,
the person wants the following setup (a VPN, essentially):

internal machine <-via clear-- SSHd <-via SSH-- external user

My question is the reverse.  I'd like to find out if anybody has
modified the fwtk telnet proxy (a grea proxy!!) so that it will
interact with OpenSSH on outbound connections, as follows:

interal user --via clear-> telnet/SSH proxy --via SSH-> server

It seems easy enough to modify the source for the telnet proxy
to use an SSH connection (instead of clear-text) on the "other"
side.  But I'm not a coder.

One SSH die-hard suggested putting a user with an ssh2 shell
in the bastion host's /etc/passwd.  That's like putting gaffer's
tape on a cut -- it works, but it's not pretty.

Alternatively, there was another attempt I saw that was a
full-blown fwtk proxy:

internal user <-via ssh-> SSH server proxy
                          SSH client proxy <-via SSH-> server

Is there anything resembling what I'd like in the second paragraph?

From owner-fwtk-users@ex.tis.com Wed Sep 27 17:30 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA21613
	Wed, 27 Sep 2000 17:29:57 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA16678;
	Wed, 27 Sep 2000 14:39:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 13:06:32 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA10749
	for fwtk-users-outgoing; Wed, 27 Sep 2000 13:06:09 -0700 (PDT)
Date: Wed, 27 Sep 2000 16:05:33 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: LIM CHUAN CHUIEN <cclim@genting.com.my>
Cc: fwtk-users@ex.tis.com
Subject: Re: Gauntlet Firewall Issue
Message-Id: <20000927160533.K24287@washington.cospo.osis.gov>
Mail-Followup-To: LIM CHUAN CHUIEN <cclim@genting.com.my>,
	fwtk-users@ex.tis.com
References: <s9d21273.004@genting.com.my>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <s9d21273.004@genting.com.my>; from cclim@genting.com.my on Wed, Sep 27, 2000 at 03:27:55PM +0800
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1050

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, Sep 27, 2000 at 03:27:55PM +0800, LIM CHUAN CHUIEN wrote:
...
> My gauntlet firewall version 5.5 in Solaris had mail problem. Based on log
> file, "bogus mail" appear on the log files. It causes my firewall not
> working properly. Can anyone provide me some solution about it.

There may be some on this mailing list who have Gauntlet expertise.
However, Gauntlet is not the same as the FireWall ToolKit, and this is
the FWTK mailing list.  I believe that there is also a Gauntlet mailing
list somewhere.

It would help if you explained what you meant by "bogus mail", how your
firewall is "not working properly", and what evidence you have that
there is any connection between the two.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Wed Sep 27 18:45 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA21789
	Wed, 27 Sep 2000 18:44:55 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA03613;
	Wed, 27 Sep 2000 15:54:32 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 14:09:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA15764
	for fwtk-users-outgoing; Wed, 27 Sep 2000 14:08:40 -0700 (PDT)
Date: Wed, 27 Sep 2000 17:05:26 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Patrick Mahan <pmahan@medtel.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: Unable to exchange mail after yao-smap patch
Message-Id: <20000927170526.Q24287@washington.cospo.osis.gov>
Mail-Followup-To: Patrick Mahan <pmahan@medtel.com>,
	fwtk-users@lists.nai.com
References: <39D206C4.BFFCF2D2@medtel.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <39D206C4.BFFCF2D2@medtel.com>; from pmahan@medtel.com on Wed, Sep 27, 2000 at 10:40:04AM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2982

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, Sep 27, 2000 at 10:40:04AM -0400, Patrick Mahan wrote:
...
> I have seen folks post with similar
> problems to mine, but have seen no
> resolution, so forgive me if this is
> redundant.

Oddly enough, this has been answered several times.  ;-}

> Successfuly applied the yao-smap patch
> and recompile went well. Edited my
> netperm-table as follows:
> 
> smap, smapd:    userid 8
> smap, smapd:    groupid 12
> smap, smapd:    directory
> /var/spool/smap
> smapd:          executable
> /usr/local/etc/smapd
> smapd:          sendmail
> /usr/sbin/sendmail
> smap:   permit-domains mydomain.com,
> *.mydomain.com
> smap:   permit-hosts 192.168.101.1
> smap:           timeout
> 3600                                             
> 
> However, no mail is going through
> firewall either way. There are no
> references to smap in the syslog and
> telnet to port 25 produces:
> 
> telnet: Unable to connect to remote
> host: Connection refused 
> 
> ps ax shows that smap is running as
> daemon.    
> 
> netstat -an on the internal mailserver
> shows:
> 
> tcp        0      2
> 192.168.101.1:1763     
> 206.239.xxx.xxx:25       SYN_SENT
> tcp        0      2
> 192.168.101.1:1682     
> 206.239.xxx.xxx:25       SYN_SENT   
> 
> which seems a tad odd to me as the
> 206.239.xxx.xxx is the external
> interface on the firewall.
> 
> Where have I gone wrong? My hunch is the
> netperm-table (I have tried things with
> and without the "permit-" prefix). Any
> and all help will be greatly
> appreciated.  

The "permit-" is stripped off only for certain keywords.  Very
idiosyncratic.  I'd give that feature an "F" and not play with it.

Your source code now has tons of comments in them.  They were lovingly
placed there for a reason.  Two of them say:

**	domains
**		"smap: domains ..." specifies the DNS domains which are
**		accepted as internal to the firewall.  If you accept
**		names in both @domain fashion and @host.domain fashion,
**		you should probably list both "domain" and "*.domain".
**	hosts
**		"smap: hosts ..." specifies the mail hosts that are to
**		be considered "internal".  These hosts may send mail to
**		anybody.  Wildcards may be used.

If you take out the "permit-"s, then your config above allows incoming
mail to "somebody@mydomain.com" and "somebody@myhost.mydomain.com".  It
allows outgoing mail only from the host whose IP address is
"192.168.101.1".

It still needs code in the "sendmail.cf" file on "192.168.101.1" to
send all non-local mail to the firewall, and code in the "sendmail.cf"
file on the firewall to send all accepted e-mail to the internal mail
server [192.168.101.1?].

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Wed Sep 27 22:58 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA22442
	Wed, 27 Sep 2000 22:58:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA16712;
	Wed, 27 Sep 2000 20:07:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 27 Sep 2000 18:32:03 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA12764
	for fwtk-users-outgoing; Wed, 27 Sep 2000 18:31:42 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000927211022.00b6e6a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Wed, 27 Sep 2000 21:16:56 -0400
To: "Phil Udel" <Phil_Udel@salemleasing.com>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FWTK Lic Questions
In-Reply-To: <200009270839340990.17FC0A8D@ford>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1596

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 08:39 AM 9/27/00 -0400, Phil Udel wrote:
>HI
>I just started at a new company that ran the FWTC.  It Looks like a nice 
>product.
Assuming you mean the Firewall Toolkit, aka FWTK. It's not a product, it's 
a toolkit that can be used to build a firewall.

>   I called PNP to see what the current version of the FWTC was, and to 
> see what gauntlet cost.

Who is PNP? PGP?

>Well, When the salesman found out we ran the FWTC at a company he said I 
>need to pay him 12k or stop using the product.

The FWTK license permits you to run a firewall on your own network. If 
you're willing to share the name of the person who threatened you this way, 
I'll look into what's going on.

>   I told him No Way and that I would replace the product with t.rex ASAP.

I won't touch this. :-)

>   The salesman said he was going to send software cops to make sure I 
> did.  I don't know the history of this product or the company, so here 
> are my questions.  Question 1:Has the FWTC always been a non-profit product?

The FWTK has never been a product. You (or someone at your organization) 
has read the license, thus you should be aware of the terms - FWTK is 
freely usable to build a firewall for your organization; it's yours with no 
suppport and no commercial rights (you can't sell it or charge to install 
or support it.)

>    Question Two: has anyone else had to pay for the FWTK. Question Three: 
> If so How much did you pay?

No and nothing.
         -Rick



From owner-fwtk-users@ex.tis.com Thu Sep 28 06:44 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA23701
	Thu, 28 Sep 2000 06:43:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA29716;
	Thu, 28 Sep 2000 03:53:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 01:32:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA26217
	for fwtk-users-outgoing; Thu, 28 Sep 2000 01:32:29 -0700 (PDT)
Message-ID: <XFMail.20000928093123.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.4 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <NEBBKBGDKLMNCDGFGONOOECCCAAA.rwilson@gnp.com>
Date: Thu, 28 Sep 2000 09:31:23 +0100 (BST)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: "C. Regis Wilson" <rwilson@gnp.com>
Subject: RE: SSH proxy/gateway
Cc: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 880

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


On 27-Sep-2000 C. Regis Wilson wrote:
> I recently read a question about SSH and fwtk.  If I read it
> correctly,
> the person wants the following setup (a VPN, essentially):
> 
> internal machine <-via clear-- SSHd <-via SSH-- external user
> 

I did attempt to implement this at one point, but couldn't quite get
it to work. SSH didn't like the lack of a full pseudo terminal that
it was getting

If I ever get the time/inclination I may try it again with OpenSSH.

-tony


---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
The best laid plans of mice and men are usually about equal.
		-- Blair

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Thu Sep 28 07:03 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA23716
	Thu, 28 Sep 2000 07:02:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA00307;
	Thu, 28 Sep 2000 04:12:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 02:49:36 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA27921
	for fwtk-users-outgoing; Thu, 28 Sep 2000 02:49:05 -0700 (PDT)
From: ark@eltex.ru
Date: Thu, 28 Sep 2000 13:42:06 +0400
Message-Id: <200009280942.NAA30707@paranoid.alpha.int>
In-Reply-To: <200009270839340990.17FC0A8D@ford> from ""Phil Udel" <Phil_Udel@salemleasing.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: FWTK Lic Questions
To: Phil_Udel@salemleasing.com
Cc: fwtk-users@ex.tis.com, firewall-wizards@nfr.net
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2339

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Sounds damn strange. The license is clear enough. Could you please provide us
the name of that asshole? Hope NAI will fsck him for spreading bullshit.

That looks quite bad, though. Not because they will send software cops to you -
just because NAI is too big to control itself and it is bad for fwtk.

Speaking on licensing and development, looks like they simply can not find
a person inside the company who is responsible for fwtk and has the power
to make decisions on it.

I am cc'ing to firewall-wizards.

BTW if you don't know that, t.rex contains some fwtk code too.

"Phil Udel" <Phil_Udel@salemleasing.com> said :

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> HI
> I just started at a new company that ran the FWTC.  It Looks like a nice=
>  product.  I called PNP to see what the current version of the FWTC was,=

You mean PGP?

>  and to see what gauntlet cost. Well, When the salesman found out we ran=
>  the FWTC at a company he said I need to pay him 12k or stop using the=
>  product.  I told him No Way and that I would replace the product with=
>  t.rex ASAP.  The salesman said he was going to send software cops to make=
>  sure I did.  I don't know the history of this product or the company, so=
>  here are my questions.  Question 1:Has the FWTC always been a non-profit=
>  product?   Question Two: has anyone else had to pay for the FWTK. Question=
>  Three: If so How much did you pay?
> Thanks 
> Phillip Udel
> Admin@SalemLeasing.com
> (800) 877-2536 Ext 212


                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOdMSbqH/mIJW9LeBAQF5YAQAsh+LHvEBvtKowACwW+caq8jfCTjJkkRW
9vPb27A7SIMC2/tRVJZ4kF4w2e4q3ZXvhtckaONz03WaV+8WHQMHbMRyyTq9p5A1
XHdBpsTHlmyHGni+EgLpwVfxGC40d2I0jcFPZvbg9EZyhfhdPrvEctgATz1Mbhbr
oh2M4GSVbPM=
=ZNC4
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Thu Sep 28 10:28 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA24446
	Thu, 28 Sep 2000 10:28:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA15107;
	Thu, 28 Sep 2000 07:36:47 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 06:03:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA06469
	for fwtk-users-outgoing; Thu, 28 Sep 2000 06:03:17 -0700 (PDT)
Message-ID: <200009280859350170.1D34EA56@ford>
In-Reply-To: <200009280942.NAA30707@paranoid.alpha.int>
References: <200009280942.NAA30707@paranoid.alpha.int>
X-Mailer: Calypso Version 3.10.03.02 (3)
Date: Thu, 28 Sep 2000 08:59:35 -0400
From: "Phil Udel" <Phil_Udel@salemleasing.com>
To: ark@eltex.ru
Cc: fwtk-users@ex.tis.com, firewall-wizards@nfr.net
Subject: Re: FWTK Lic Questions
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id GAA06442
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 3096

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hmmmm
Thanks for your response.   Ya, I did mean PGP, I am cixelsyd :).  The fine person that made all off this possible was....
John ?Brient?  Direct Line is (972) 619-7528.  Any help would be greatly appreciated.  Jumping from one firewall to another
in a week is hazardous at best. 

*********** REPLY SEPARATOR  ***********

On 9/28/00 at 1:42 PM ark@eltex.ru wrote:

>[To be removed from this list send the message "unsubscribe fwtk-users" in the
>BODY of a mail message to majordomo@ex.tis.com.]
>
>-----BEGIN PGP SIGNED MESSAGE-----
>
>nuqneH,
>
>Sounds damn strange. The license is clear enough. Could you please provide us
>the name of that asshole? Hope NAI will fsck him for spreading bullshit.
>
>That looks quite bad, though. Not because they will send software cops to you -
>just because NAI is too big to control itself and it is bad for fwtk.
>
>Speaking on licensing and development, looks like they simply can not find
>a person inside the company who is responsible for fwtk and has the power
>to make decisions on it.
>
>I am cc'ing to firewall-wizards.
>
>BTW if you don't know that, t.rex contains some fwtk code too.
>
>"Phil Udel" <Phil_Udel@salemleasing.com> said :
>
>> [To be removed from this list send the message "unsubscribe fwtk-users" in the
>> BODY of a mail message to majordomo@ex.tis.com.]
>> HI
>> I just started at a new company that ran the FWTC.  It Looks like a nice=
>>  product.  I called PNP to see what the current version of the FWTC was,=
>
>You mean PGP?
>
>>  and to see what gauntlet cost. Well, When the salesman found out we ran=
>>  the FWTC at a company he said I need to pay him 12k or stop using the=
>>  product.  I told him No Way and that I would replace the product with=
>>  t.rex ASAP.  The salesman said he was going to send software cops to make=
>>  sure I did.  I don't know the history of this product or the company, so=
>>  here are my questions.  Question 1:Has the FWTC always been a non-profit=
>>  product?   Question Two: has anyone else had to pay for the FWTK. Question=
>>  Three: If so How much did you pay?
>> Thanks 
>> Phillip Udel
>> Admin@SalemLeasing.com
>> (800) 877-2536 Ext 212
>
>
>                                     _     _  _  _  _      _  _
> {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
> (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
> [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!
>
>-----BEGIN PGP SIGNATURE-----
>Version: PGP 6.5.1i
>
>iQCVAwUBOdMSbqH/mIJW9LeBAQF5YAQAsh+LHvEBvtKowACwW+caq8jfCTjJkkRW
>9vPb27A7SIMC2/tRVJZ4kF4w2e4q3ZXvhtckaONz03WaV+8WHQMHbMRyyTq9p5A1
>XHdBpsTHlmyHGni+EgLpwVfxGC40d2I0jcFPZvbg9EZyhfhdPrvEctgATz1Mbhbr
>oh2M4GSVbPM=
>=ZNC4
>-----END PGP SIGNATURE-----


Thanks 
Phillip Udel
Admin@SalemLeasing.com
(800) 877-2536 Ext 212

Rules To Live By:
1) On the keyboard of life, always keep one finger on the escape key.
2) There are absolutely no absolutes.


From owner-fwtk-users@ex.tis.com Thu Sep 28 12:22 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA24773
	Thu, 28 Sep 2000 12:22:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA01752;
	Thu, 28 Sep 2000 09:31:12 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 08:14:05 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA19163
	for fwtk-users-outgoing; Thu, 28 Sep 2000 08:13:44 -0700 (PDT)
Message-ID: <01C0294B.9FDB76A0.dinesh.tashildar@wipro.com>
From: "Dinesh Tashildar" <dinesh.tashildar@wipro.com>
Reply-To: "dinesh.tashildar@wipro.com" <dinesh.tashildar@wipro.com>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: Telnet problem
Date: Thu, 28 Sep 2000 12:57:13 -0000
Organization: WIPRO
X-Mailer: Microsoft Internet E-mail/MAPI - 8.0.0.4211
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 347

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

After Installation of TIS I can not able to telnet to linux comp.
What will will be the prob.
Regards,

Dinesh Tashildar	
Wipro
Phone: 4003113 / 4218400 ext. 306
dinesh.tashildar@wipro.com
dinesh_tashildar@hotmail.com

From owner-fwtk-users@ex.tis.com Thu Sep 28 12:22 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA24774
	Thu, 28 Sep 2000 12:22:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA01736;
	Thu, 28 Sep 2000 09:31:09 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 08:00:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA17688
	for fwtk-users-outgoing; Thu, 28 Sep 2000 08:00:15 -0700 (PDT)
Message-Id: <v02120d03b5f995274a4e@[134.60.9.100]>
Mime-Version: 1.0
Date: Thu, 28 Sep 2000 16:46:15 -0800
To: fwtk-users@lists.nai.com
From: heim@sip.medizin.uni-ulm.de (Stefan Heim, Dipl.-Ing.)
Subject: encrypted page
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 554

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,
how can I allow connections to ecrypted pages through
fwtk 2.0 ?

/--------------------------------o00-----00o-------------------------\
Stefan Heim

Uni Ulm
Sektion Informatik in der Psychotherapie
Am Hochstraess 8
89081 Ulm
Germany
E-Mail: heim@sip.Medizin.Uni-Ulm.de
http://sip.medizin.uni-ulm.de
Tel: +49-(0)731-50-25702 Fax: +49-(0)731-50-25662
\-------------------------------ooo0-----0ooOo---------------------/



From owner-fwtk-users@ex.tis.com Thu Sep 28 12:22 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA24775
	Thu, 28 Sep 2000 12:22:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA01764;
	Thu, 28 Sep 2000 09:31:16 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 08:13:54 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA19162
	for fwtk-users-outgoing; Thu, 28 Sep 2000 08:13:43 -0700 (PDT)
Date: Wed, 27 Sep 2000 15:11:55 -0500 (CDT)
From: Sergio Jimenez Tovar <sjimenez@galois.dgae.unam.mx>
X-Sender: sjimenez@laplace
To: Fwtk <fwtk-users@ex.tis.com>
Subject: How print in remote printer ?
Message-ID: <Pine.GSO.4.05.10009271501400.22444-100000@laplace>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 378

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

	Somebody can tell me how to print in a printer out of firewall ?
	I have linux 6.1 R.H
	I put in netperm-table :
	plug-gw: port printer 132.248.78.* -plug-to 132.248.211.250

	And I cant't to print, the files go to mqueue
	Thanks for yours answer.

From owner-fwtk-users@ex.tis.com Thu Sep 28 16:28 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA25638
	Thu, 28 Sep 2000 16:27:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA04250;
	Thu, 28 Sep 2000 13:37:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 12:08:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA21470
	for fwtk-users-outgoing; Thu, 28 Sep 2000 12:08:23 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@tis.com>
Subject: Squid
Date: Thu, 28 Sep 2000 13:07:21 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFCENBOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Importance: Normal
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id MAA21429
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 330

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

How bad is to put the Squid software in the same
box as the FWTK? 

It seemed to me more secure
and it works better than the http-gw

Any thoughts?

Luis Fernando Barrera
luba@assist.com.gt 


From owner-fwtk-users@ex.tis.com Thu Sep 28 16:28 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA25637
	Thu, 28 Sep 2000 16:27:56 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA04245;
	Thu, 28 Sep 2000 13:37:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 12:01:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA20271
	for fwtk-users-outgoing; Thu, 28 Sep 2000 12:01:19 -0700 (PDT)
Date: Thu, 28 Sep 2000 15:00:40 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Dinesh Tashildar <dinesh.tashildar@wipro.com>
Cc: fwtk-users@tis.com
Subject: Re: Telnet problem
Message-Id: <20000928150040.F307@washington.cospo.osis.gov>
Mail-Followup-To: Dinesh Tashildar <dinesh.tashildar@wipro.com>,
	fwtk-users@tis.com
References: <01C0294B.9FDB76A0.dinesh.tashildar@wipro.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <01C0294B.9FDB76A0.dinesh.tashildar@wipro.com>; from dinesh.tashildar@wipro.com on Thu, Sep 28, 2000 at 12:57:13PM -0000
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1609

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Sep 28, 2000 at 12:57:13PM -0000, Dinesh Tashildar wrote:
> After Installation of TIS I can not able to telnet to linux comp.
> What will will be the prob.
> Regards,
> 
> Dinesh Tashildar	
> Wipro
> Phone: 4003113 / 4218400 ext. 306
> dinesh.tashildar@wipro.com
> dinesh_tashildar@hotmail.com

NAI installed TIS into itself.  But I suspect that you installed FWTK.

I assume that "linux comp." is some Linux company or computer outside
your firewall bastion host.

What is happening is that the FWTK is working exactly right, protecting
you from the Internet and vice versa.  If you want to telnet out, you
must telnet to your firewall bastion host.  It will give you a "tn-gw->"
prompt.  You tell it one of:
	t external-host-name
	c external-host-name
and it will PROXY your 'telnet' session to that internal host.

At no time will any IP from your network go out to the Internet, and
vice versa.

Now if "linux comp." above refers to your firewall bastion host, then
you must 'telnet' to the secondary port that you set up for authentica-
ted telnet to that host.  If you haven't set this up, you will have to
do so.

If you can't get a "tn-gw-> " prompt from the firewall bastion host,
check your netperm-table file.

Read the documentation.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Sep 28 17:59 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA25835
	Thu, 28 Sep 2000 17:59:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA16978;
	Thu, 28 Sep 2000 15:08:44 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 13:42:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA04856
	for fwtk-users-outgoing; Thu, 28 Sep 2000 13:41:51 -0700 (PDT)
From: "C. Regis Wilson" <rwilson@gnp.com>
To: "Luis Fernando Barrera" <luba@assist.com.gt>, <fwtk-users@tis.com>
Subject: RE: Squid
Date: Thu, 28 Sep 2000 13:40:56 -0700
Message-ID: <NEBBKBGDKLMNCDGFGONOIECGCAAA.rwilson@gnp.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
In-Reply-To: <NABBIDJPNCAGKGOFGHBFCENBOOAA.luba@assist.com.gt>
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1052

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I think it's "secure enough" as long as you have a packet filter
behind your bastion host.  If you don't have a packet
filter (in front *and* behind for extra measure), it's probably
not a good idea.

I run Squid as a separate host outside my packet filter, but that's
just for perfomance and redundancy reasons.

--Regis

> -----Original Message-----
> From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
> Behalf Of Luis Fernando Barrera
> Sent: Thursday, September 28, 2000 12:07 PM
> To: fwtk-users@tis.com
> Subject: Squid
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi all,
> 
> How bad is to put the Squid software in the same
> box as the FWTK? 
> 
> It seemed to me more secure
> and it works better than the http-gw
> 
> Any thoughts?
> 
> Luis Fernando Barrera
> luba@assist.com.gt 
> 
> 

From owner-fwtk-users@ex.tis.com Thu Sep 28 19:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA26001
	Thu, 28 Sep 2000 19:56:18 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA27094;
	Thu, 28 Sep 2000 17:05:58 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 15:33:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA19829
	for fwtk-users-outgoing; Thu, 28 Sep 2000 15:33:20 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000928181755.00bd9e30@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Thu, 28 Sep 2000 18:19:22 -0400
To: heim@sip.medizin.uni-ulm.de (Stefan Heim, Dipl.-Ing.),
        fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: encrypted page
In-Reply-To: <v02120d03b5f995274a4e@[134.60.9.100]>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 465

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 04:46 PM 9/28/00 -0800, Stefan Heim, Dipl.-Ing. wrote:
>how can I allow connections to ecrypted pages through fwtk 2.0 ?

What is an "encrypted page" - do you mean SSL connections (https:// URLs)?
If so, there's a ssl-gw mentioned on the FWTK faq page as well as support 
in the http-gw and plug-gw for ssl proxying.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Sep 28 19:56 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA26002
	Thu, 28 Sep 2000 19:56:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA27098;
	Thu, 28 Sep 2000 17:06:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 15:44:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA20671
	for fwtk-users-outgoing; Thu, 28 Sep 2000 15:44:19 -0700 (PDT)
Date: Thu, 28 Sep 2000 18:43:43 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Luis Fernando Barrera <luba@assist.com.gt>
Cc: fwtk-users@tis.com
Subject: Re: Squid
Message-Id: <20000928184343.H2457@washington.cospo.osis.gov>
Mail-Followup-To: Luis Fernando Barrera <luba@assist.com.gt>,
	fwtk-users@tis.com
References: <NABBIDJPNCAGKGOFGHBFCENBOOAA.luba@assist.com.gt>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NABBIDJPNCAGKGOFGHBFCENBOOAA.luba@assist.com.gt>; from luba@assist.com.gt on Thu, Sep 28, 2000 at 01:07:21PM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 706

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Sep 28, 2000 at 01:07:21PM -0600, Luis Fernando Barrera wrote:
...
> How bad is to put the Squid software in the same
> box as the FWTK? 
> 
> It seemed to me more secure
> and it works better than the http-gw

Read the archives for the many times this has been discussed.  Summary:
run BOTH.  Which goes first depends on what you want to do.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep 29 04:32 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA28468
	Fri, 29 Sep 2000 04:32:59 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA15096;
	Fri, 29 Sep 2000 01:42:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 28 Sep 2000 23:27:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA10428
	for fwtk-users-outgoing; Thu, 28 Sep 2000 23:27:22 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@tis.com>
Subject: squid, http-gw and squid-gw
Date: Fri, 29 Sep 2000 00:26:24 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFGENGOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id XAA10423
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1464

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

I recently asked whether squid versus http-gw versus squid-gw.... Somebody
"gracefully" sent me to the list archive... So I did it...

However some questions still bother me, maybe the guys who already
passed for this info nightmare can give me a hand...

1) http-gw is the same as squid-gw?
	
	I read that they are almost the same with a little advantage of
	squid-gw above http-gw?

2) It is not recommended to put squid in the firewall box, right?
	I saw several messages that squid alone and squid-gw (http-gw)
            are the same in terms of security...

3) You can put the squid software in an internal host and then all the http
    requests from the internal users, go "relayed" to the squid-gw?

4) If you want to put a public web server, it is not a good idea to put it 
   behind the firewall, even with the "accelerated options" of squid
   or another trick from squid-gw, right? 

5) You can put the web server in a third network segment, using a 3 nic in the
   firewall, and configure the squid-gw to ONLY permite http traffic from
   the web server to the internet and viceversa? 
	
How am I doing?  My head is a little mixed up, maybe some definitions
of the products and their intentions could help... Anybody know
these definitions?

Thanks a lot in advance

Luis Fernando Barrera
luba@assist.com.gt 


From owner-fwtk-users@ex.tis.com Fri Sep 29 07:44 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA28877
	Fri, 29 Sep 2000 07:44:04 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA20587;
	Fri, 29 Sep 2000 04:53:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 02:43:05 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA16404
	for fwtk-users-outgoing; Fri, 29 Sep 2000 02:42:55 -0700 (PDT)
Message-ID: <002101c029f9$adfcdf40$0601a8c0@wen>
From: "wen" <wen_su@263.net>
To: <fwtk-users@lists.nai.com>
Subject: plug-gw
Date: Fri, 29 Sep 2000 17:43:00 +0800
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2615.200
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_001E_01C02A3C.B6229D20"
Content-Length: 2954

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_001E_01C02A3C.B6229D20
Content-Type: text/plain;
	charset="gb2312"
Content-Transfer-Encoding: base64

aGksZXZlcnlvbjoNCiAgICBteSBzeXN0ZW0gaXMgcmVkaGF0Ni4yICBhbmQgaSBoYXZlIGluc3Rh
bGxlZCBmd3RrMi4xLiBJbiBteSBpbnRyYW5ldCBJIHdhbnQgdG8gb2ZmZXIgd3d3LHRlbG5ldCBh
bmQgZnRwIHNlcnZlcnMgdG8gaW50ZXJuZXQuIG5vdyBpIGhhdmUgZG9uZSB3d3cgc2VydmVyIHdp
dGggcGx1Zy1ndyBpbiB0aGUgL2V0Yy9yYy5kL3JjLmxvY2FsIGZpbGU6DQoNCiAgICAvdXNyL2xv
Y2FsL2V0Yy9wbHVnLWd3IC1kYWVtb24geC54LngueDo4MCAtbmFtZSBwbHVnLWd3DQogeC54Lngu
eCBpcyBpbnRlcm5ldCBhZGRyZXNzIG9mIG15IGZpcmV3YWxsIGJveC4NCnRoZW4gaW4gdGhlIG5l
dHBlcm0tdGFibGUgZmlsZSBpIGNvbmZpZzoNCg0KcGx1Zy1ndzpwb3J0IDgwICogLXBsdWctdG8g
MTkyLjE2OC4xLjEwIC1wb3J0IDgwDQoNCmkgd2FudCB0byBjb25maWcgZnRwIGFuZCB0ZWxuZXQg
IHNlcnZpY2VzIGJ5IHRoZSBzYW1lIHdheS4gYnV0IGkgZmFpbGVkIGFuZCBpIGdvdCBhIHJlc3Vs
dDogcGx1Zy1ndyBjYW4ndCBkbyBmb3IgdHdvIG9yIGFib3ZlIHNlcnZpY2VzIGF0IHRoZSBzYW1l
IHRpbWUuIA0Kd2h5Pw0KaWYgSSB3YW50IHRvIG9mZmVyIHd3dyxmdHAgYW5kIHRlbG5ldCBzZXJ2
aWNlcyBhdCB0aGUgc2FtZSB0aW1lLiB3aGF0IHNob3VsZCBpIGRvPyANCg==

------=_NextPart_000_001E_01C02A3C.B6229D20
Content-Type: text/html;
	charset="gb2312"
Content-Transfer-Encoding: base64

PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9XM0MvL0RURCBIVE1MIDQuMCBUcmFuc2l0aW9uYWwv
L0VOIj4NCjxIVE1MPjxIRUFEPg0KPE1FVEEgY29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PWdi
MjMxMiIgaHR0cC1lcXVpdj1Db250ZW50LVR5cGU+DQo8TUVUQSBjb250ZW50PSJNU0hUTUwgNS4w
MC4yNjE0LjM1MDAiIG5hbWU9R0VORVJBVE9SPg0KPFNUWUxFPjwvU1RZTEU+DQo8L0hFQUQ+DQo8
Qk9EWSBiZ0NvbG9yPSNmZmZmZmY+DQo8RElWPjxGT05UIHNpemU9Mj5oaSxldmVyeW9uOjxCUj4m
bmJzcDsmbmJzcDsmbmJzcDsgbXkgc3lzdGVtIGlzIHJlZGhhdDYuMiZuYnNwOyANCmFuZCBpIGhh
dmUgaW5zdGFsbGVkIGZ3dGsyLjEuIEluIG15IGludHJhbmV0IEkgd2FudCB0byBvZmZlciB3d3cs
dGVsbmV0IGFuZCBmdHAgDQpzZXJ2ZXJzIHRvIGludGVybmV0LiBub3cgaSBoYXZlIGRvbmUgd3d3
IHNlcnZlciB3aXRoIHBsdWctZ3cgaW4gdGhlIA0KL2V0Yy9yYy5kL3JjLmxvY2FsIGZpbGU6PC9G
T05UPjwvRElWPg0KPERJVj4mbmJzcDs8L0RJVj4NCjxESVY+PEZPTlQgc2l6ZT0yPiZuYnNwOyZu
YnNwOyZuYnNwOyAvdXNyL2xvY2FsL2V0Yy9wbHVnLWd3IC1kYWVtb24geC54LngueDo4MCANCi1u
YW1lIHBsdWctZ3c8QlI+Jm5ic3A7eC54LngueCBpcyBpbnRlcm5ldCBhZGRyZXNzIG9mIG15IGZp
cmV3YWxsIGJveC48QlI+dGhlbiANCmluIHRoZSBuZXRwZXJtLXRhYmxlIGZpbGUgaSBjb25maWc6
PC9GT05UPjwvRElWPg0KPERJVj4mbmJzcDs8L0RJVj4NCjxESVY+PEZPTlQgc2l6ZT0yPnBsdWct
Z3c6cG9ydCA4MCAqIC1wbHVnLXRvIDE5Mi4xNjguMS4xMCAtcG9ydCA4MDwvRk9OVD48L0RJVj4N
CjxESVY+PEZPTlQgc2l6ZT0yPjxCUj5pIHdhbnQgdG8gY29uZmlnIGZ0cCBhbmQgdGVsbmV0Jm5i
c3A7IHNlcnZpY2VzIGJ5IHRoZSBzYW1lIA0Kd2F5LiBidXQgaSBmYWlsZWQgYW5kIGkgZ290IGEg
cmVzdWx0OiBwbHVnLWd3IGNhbid0IGRvIGZvciB0d28gb3IgYWJvdmUgc2VydmljZXMgDQphdCB0
aGUgc2FtZSB0aW1lLiA8QlI+d2h5PzxCUj5pZiBJIHdhbnQgdG8gb2ZmZXIgd3d3LGZ0cCBhbmQg
dGVsbmV0IHNlcnZpY2VzIGF0IA0KdGhlIHNhbWUgdGltZS4gd2hhdCBzaG91bGQgaSBkbz8gPC9G
T05UPjwvRElWPjwvQk9EWT48L0hUTUw+DQo=

------=_NextPart_000_001E_01C02A3C.B6229D20--


From owner-fwtk-users@ex.tis.com Fri Sep 29 07:44 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA28876
	Fri, 29 Sep 2000 07:44:04 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA20583;
	Fri, 29 Sep 2000 04:53:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 03:07:03 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA16972
	for fwtk-users-outgoing; Fri, 29 Sep 2000 03:06:52 -0700 (PDT)
Message-ID: <380853179.970221957097.JavaMail.root@web305-mc.mail.com>
Date: Fri, 29 Sep 2000 06:05:57 -0400 (EDT)
From: kemal hajdarevic <kemalh@mail.com>
To: fwtk-users@lists.nai.com
Subject: possible http attack
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Mailer: mail.com
X-Originating-IP: 195.130.44.8
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 713

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi people

I have installed FWTK 2.1 as my firewall and message log is full
of connection atempts on http-gw from the internet. All requests were
rejcted but they(folks form the Internet) try again and again to use
http-gw. I don-t know why they see my fw as possible vulnerable proxy and
they don't want tyo stop they action after http-gw refused each time to
permit those requests from the Intrenet.

Any idea would be great.

Thanks in advance.


Kemal


______________________________________________
FREE Personalized Email at Mail.com
Sign up at http://www.mail.com/?sr=signup


From owner-fwtk-users@ex.tis.com Fri Sep 29 07:50 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA28886
	Fri, 29 Sep 2000 07:49:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA20779;
	Fri, 29 Sep 2000 04:59:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 03:39:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA17915
	for fwtk-users-outgoing; Fri, 29 Sep 2000 03:39:16 -0700 (PDT)
From: ark@eltex.ru
Date: Fri, 29 Sep 2000 14:32:48 +0400
Message-Id: <200009291032.OAA03065@paranoid.alpha.int>
In-Reply-To: <NABBIDJPNCAGKGOFGHBFGENGOOAA.luba@assist.com.gt> from ""Luis Fernando Barrera" <luba@assist.com.gt>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: squid, http-gw and squid-gw
To: luba@assist.com.gt
Cc: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2560

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

"Luis Fernando Barrera" <luba@assist.com.gt> said :


> I recently asked whether squid versus http-gw versus squid-gw.... Somebody
> "gracefully" sent me to the list archive... So I did it...
> 
> However some questions still bother me, maybe the guys who already
> passed for this info nightmare can give me a hand...
> 
> 1) http-gw is the same as squid-gw?
> 	
> 	I read that they are almost the same with a little advantage of
> 	squid-gw above http-gw?

Wrong. squid-gw is much more paranoid ;)
See the README file, it will explain much to you.
 
> 2) It is not recommended to put squid in the firewall box, right?
> 	I saw several messages that squid alone and squid-gw (http-gw)
>             are the same in terms of security...

Wrong again. Squid is not designed as security-oriented tool.
 
> 3) You can put the squid software in an internal host and then all the http
>     requests from the internal users, go "relayed" to the squid-gw?

You will get problems with distinguishing users one from another and
statistics gathering.
 
> 4) If you want to put a public web server, it is not a good idea to put it 
>    behind the firewall, even with the "accelerated options" of squid
>    or another trick from squid-gw, right? 

Yep.
 
> 5) You can put the web server in a third network segment, using a 3 nic in the
>    firewall, and configure the squid-gw to ONLY permite http traffic from
>    the web server to the internet and viceversa? 

squid-gw is designed to secure the client, not the server. Use http-in for it.
 	
> How am I doing?  My head is a little mixed up, maybe some definitions
> of the products and their intentions could help... Anybody know
> these definitions?

Hope this helps..

P.S. about ssh-gw, i am working on a new version now but it will take some
time.. 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOdRvz6H/mIJW9LeBAQGGpgQAjpdDp8jkNrdeNY4EQ4QFI+fqJwY7PsHl
itP0mR68eEFqFNxg/d1bmTQ1tqEglpMor2nH8N3tyJUEQwaWN7GyapgpE/QSZYD8
WoUaaulL29K6CsFKJui7GKgtpNICqSAefJTi5nda6gL3rnXEwCl6ICMFKa1X7W8g
VFxTVw+4IEs=
=6VXq
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Fri Sep 29 09:51 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA29351
	Fri, 29 Sep 2000 09:51:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA00961;
	Fri, 29 Sep 2000 07:00:58 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 05:32:18 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22626
	for fwtk-users-outgoing; Fri, 29 Sep 2000 05:32:07 -0700 (PDT)
To: fwtk-users@ex.tis.com
Subject: Gauntlet Mailing List (was: Re: Gauntlet Firewall Issue)
X-Sun-Charset: US-ASCII
Message-Id: <20000929123142.CBFDF41A31@skynet.medar.com>
Date: Fri, 29 Sep 2000 08:31:42 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 822

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


In <20000927160533.K24287@washington.cospo.osis.gov>,
Joseph S D Yao <jsdy@cospo.osis.gov> wrote:
>
[snip]
> 
> There may be some on this mailing list who have Gauntlet expertise.
> However, Gauntlet is not the same as the FireWall ToolKit, and this is
> the FWTK mailing list.  I believe that there is also a Gauntlet mailing
> list somewhere.

Yup.  Gauntlet-user.  More info at http://rmsbus.com/gauntlet-user.htm


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc., a Division of WTC Corp.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Fri Sep 29 09:52 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA29356
	Fri, 29 Sep 2000 09:52:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA00979;
	Fri, 29 Sep 2000 07:01:11 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 05:45:53 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA23274
	for fwtk-users-outgoing; Fri, 29 Sep 2000 05:45:42 -0700 (PDT)
To: fwtk-users@ex.tis.com
Subject: Re: FWTK Lic Questions
X-Sun-Charset: US-ASCII
Message-Id: <20000929124514.D9AE141A2E@skynet.medar.com>
Date: Fri, 29 Sep 2000 08:45:14 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1724

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

In message <4.3.2.7.2.20000927211022.00b6e6a0@mail.itm-inst.com>,
Rick Murphy <rmurphy@itm-inst.com> wrote:
>
[snip]
>                                                         ... - FWTK is 
> freely usable to build a firewall for your organization; it's yours with no 
> suppport and no commercial rights (you can't sell it or charge to install 
> or support it.)
[snip]
> 

Correct me if I'm wrong: but my reading of the license, some time back,
was that not only was one prohibited from reselling or otherwise
charging to install or support it, but that one was completely
prohibited from re-distributing it to others in any form whatsoever.

As a whimsical aside: if one is not allowed to "charge for supporting
it", and a company is in need of a consultant that understands it--for
some "out-sourced" help, does that mean the consultant can't take the
job?  For example: I've been working with Gauntlet for years.  So I
imagine I could find my way around an FWTK installation.  Say I decided
to give up my life as a masochist (Sys. & Network Admin.) and go it
alone as an independent consultant.  And a potential client calls one
day needing help with a FWTK installation (their lone staff SysAdmin is
on vacation or whatever).  Hmmm...

I surely wish NAI would "free the source" and be done with it, fer
crissakes.


Regards,
Jim
-- 
Jim Seymour                         | Medar, Inc., a Division of WTC Corp.
jseymour@medar.com                  | 24775 Crestview Ct.
Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

From owner-fwtk-users@ex.tis.com Fri Sep 29 11:09 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA29535
	Fri, 29 Sep 2000 11:09:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA10365;
	Fri, 29 Sep 2000 08:18:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 06:48:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA29256
	for fwtk-users-outgoing; Fri, 29 Sep 2000 06:47:53 -0700 (PDT)
Message-ID: <39D49DA6.6E417BBD@v-one.com>
Date: Fri, 29 Sep 2000 09:48:22 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.75 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: James Seymour <jseymour@medar.com>
CC: fwtk-users@ex.tis.com
Subject: Re: FWTK Lic Questions
References: <20000929124514.D9AE141A2E@skynet.medar.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2049

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

James Seymour wrote:
> 
> >                                                         ... - FWTK is
> > freely usable to build a firewall for your organization; it's yours with no
> > suppport and no commercial rights (you can't sell it or charge to install
> > or support it.)
> [snip]
> >
> 
> Correct me if I'm wrong: but my reading of the license, some time back,
> was that not only was one prohibited from reselling or otherwise
> charging to install or support it, but that one was completely
> prohibited from re-distributing it to others in any form whatsoever.

That is correct; in order to verify that people have read and understand
the license, they require that you agree to it in "writing" by sending
an e-mail to them.

> As a whimsical aside: if one is not allowed to "charge for supporting
> it", and a company is in need of a consultant that understands it--for
> some "out-sourced" help, does that mean the consultant can't take the
> job?  For example: I've been working with Gauntlet for years.  So I
> imagine I could find my way around an FWTK installation.  Say I decided
> to give up my life as a masochist (Sys. & Network Admin.) and go it
> alone as an independent consultant.  And a potential client calls one
> day needing help with a FWTK installation (their lone staff SysAdmin is
> on vacation or whatever).  Hmmm...

The message from NAI before was that they wouldn't prosecute if you did
2-3 installations a year, but that you couldn't advertise yourself as a
"free FWTK consultant".

See the message from about a year ago by John Kelley.

> 
> I surely wish NAI would "free the source" and be done with it, fer
> crissakes.

They can't, since it is still being used in some contracts. I wish that
they would also, so that I can then run CVS on fwtk.org and stop putting
up patches for everything :-).

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Fri Sep 29 12:43 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA29893
	Fri, 29 Sep 2000 12:43:21 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA23696;
	Fri, 29 Sep 2000 09:52:41 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 08:23:36 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA11209
	for fwtk-users-outgoing; Fri, 29 Sep 2000 08:23:24 -0700 (PDT)
Message-ID: <01C029F9.334CF190.dinesh.tashildar@wipro.com>
From: "Dinesh Tashildar" <dinesh.tashildar@wipro.com>
Reply-To: "dinesh.tashildar@wipro.com" <dinesh.tashildar@wipro.com>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: Firewall problem
Date: Fri, 29 Sep 2000 09:39:44 -0000
Organization: WIPRO
X-Mailer: Microsoft Internet E-mail/MAPI - 8.0.0.4211
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 1066

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Thanks for your reply.
I will now explain you what is the situation.
We have one  Red Hat Linux server, which installed on normal Intel 
computer.
Now I install on that PC FWTK 2.1. After Installation it is not allowed me 
to login.
After that I check /etc/initd.conf file ....no problem with this file 
also....
Then I did necessary settings in netperm-table still is I not allowing me 
to telnet.
When I try to telnet  from same computer to itself then if gives me an 
error

telnet: Unable to connect to remote host : connection refuse

Then I check /var/log/messages in that it is giving me an error line
This is on

sept25 telnet [16507] : ttloop: peer died :EOF

Now Please helps me what should I do. It's a very urgent for me. If any one 
want my initd.conf and netperm-table file I will send it to them.

Regards,

Dinesh Tashildar	
Wipro
Phone: 4003113 / 4218400 ext. 306
dinesh.tashildar@wipro.com
dinesh_tashildar@hotmail.com

From owner-fwtk-users@ex.tis.com Fri Sep 29 12:43 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA29892
	Fri, 29 Sep 2000 12:43:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA23692;
	Fri, 29 Sep 2000 09:52:40 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 08:22:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA11038
	for fwtk-users-outgoing; Fri, 29 Sep 2000 08:22:24 -0700 (PDT)
Message-ID: <39D3C4F6.26A1A5FC@efa.nl>
Date: Thu, 28 Sep 2000 22:23:50 +0000
From: Willem Brouwer <w.c.m.brouwer@efa.nl>
Reply-To: W.c.m.brouwer@efa.nl
X-Mailer: Mozilla 4.73 [en] (Win98; I)
X-Accept-Language: en
MIME-Version: 1.0
To: Luis Fernando Barrera <luba@assist.com.gt>, fwtk-users@tis.com
Subject: Re: Squid
References: <NABBIDJPNCAGKGOFGHBFCENBOOAA.luba@assist.com.gt>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 591

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



Luis Fernando Barrera wrote:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi all,
> 
> How bad is to put the Squid software in the same
> box as the FWTK?
> 
> It seemed to me more secure
> and it works better than the http-gw

I have had that working succesfully for years with about 300 pc's.

squid adds the cache facility. Perfect. Just let squid do ONLY http.

From owner-fwtk-users@ex.tis.com Fri Sep 29 13:58 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA00185
	Fri, 29 Sep 2000 13:58:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA06246;
	Fri, 29 Sep 2000 11:07:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 09:41:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA22114
	for fwtk-users-outgoing; Fri, 29 Sep 2000 09:40:48 -0700 (PDT)
Date: Fri, 29 Sep 2000 12:40:09 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: James Seymour <jseymour@medar.com>
Cc: fwtk-users@ex.tis.com
Subject: Re: FWTK Lic Questions
Message-Id: <20000929124009.A7467@washington.cospo.osis.gov>
Mail-Followup-To: James Seymour <jseymour@medar.com>, fwtk-users@ex.tis.com
References: <20000929124514.D9AE141A2E@skynet.medar.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <20000929124514.D9AE141A2E@skynet.medar.com>; from jseymour@medar.com on Fri, Sep 29, 2000 at 08:45:14AM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2163

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 29, 2000 at 08:45:14AM -0400, James Seymour wrote:
> In message <4.3.2.7.2.20000927211022.00b6e6a0@mail.itm-inst.com>,
> Rick Murphy <rmurphy@itm-inst.com> wrote:
> >
> [snip]
> >                                                         ... - FWTK is 
> > freely usable to build a firewall for your organization; it's yours with no 
> > suppport and no commercial rights (you can't sell it or charge to install 
> > or support it.)
> [snip]
> > 
> 
> Correct me if I'm wrong: but my reading of the license, some time back,
> was that not only was one prohibited from reselling or otherwise
> charging to install or support it, but that one was completely
> prohibited from re-distributing it to others in any form whatsoever.

That is my reading as well.  Of course, IANALNDIPOOTV.

> As a whimsical aside: if one is not allowed to "charge for supporting
> it", and a company is in need of a consultant that understands it--for
> some "out-sourced" help, does that mean the consultant can't take the
> job?  For example: I've been working with Gauntlet for years.  So I
> imagine I could find my way around an FWTK installation.  Say I decided
> to give up my life as a masochist (Sys. & Network Admin.) and go it
> alone as an independent consultant.  And a potential client calls one
> day needing help with a FWTK installation (their lone staff SysAdmin is
> on vacation or whatever).  Hmmm...

I think you can't go around advertising yourself as an FWTK expert and
get hired for that.  But if you get hired to help fix up their network,
and one component happens to be FWTK ... that would be a different
story.  But before you do this, I would consult your legal counsel.
Isn't that sad?

> I surely wish NAI would "free the source" and be done with it, fer
> crissakes.

Agreed but unlikely.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep 29 14:25 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA00293
	Fri, 29 Sep 2000 14:25:24 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA10653;
	Fri, 29 Sep 2000 11:34:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 10:16:31 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA26835
	for fwtk-users-outgoing; Fri, 29 Sep 2000 10:16:10 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: "wen" <wen_su@263.net>
Cc: <fwtk-users@lists.nai.com>
Subject: RE: plug-gw
Date: Fri, 29 Sep 2000 11:14:07 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFAENIOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
In-Reply-To: <002101c029f9$adfcdf40$0601a8c0@wen>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0002_01C02A06.624E1A70"
Content-Length: 4091

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_0002_01C02A06.624E1A70
Content-Type: text/plain;
	charset="gb2312"
Content-Transfer-Encoding: 7bit

You should use tn-gw and ftp-gw for the telnet and ftp service, besides
is not good idea to put a web server behind the firewall. You should put
it in another network segment with a third NIC of the firewall...


  -----Original Message-----
  From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of wen
  Sent: Friday, September 29, 2000 3:43 AM
  To: fwtk-users@lists.nai.com
  Subject: plug-gw


  hi,everyon:
      my system is redhat6.2  and i have installed fwtk2.1. In my intranet I
want to offer www,telnet and ftp servers to internet. now i have done www
server with plug-gw in the /etc/rc.d/rc.local file:

      /usr/local/etc/plug-gw -daemon x.x.x.x:80 -name plug-gw
   x.x.x.x is internet address of my firewall box.
  then in the netperm-table file i config:

  plug-gw:port 80 * -plug-to 192.168.1.10 -port 80

  i want to config ftp and telnet  services by the same way. but i failed
and i got a result: plug-gw can't do for two or above services at the same
time.
  why?
  if I want to offer www,ftp and telnet services at the same time. what
should i do?

------=_NextPart_000_0002_01C02A06.624E1A70
Content-Type: text/html;
	charset="gb2312"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Dwindows-1252" =
http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2919.6307" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN =
class=3D705031217-29092000>You=20
should use tn-gw and ftp-gw for the telnet and ftp service,=20
besides</SPAN></FONT></DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN =
class=3D705031217-29092000>is not=20
good idea to put a web server behind the firewall. You should=20
put</SPAN></FONT></DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN =
class=3D705031217-29092000>it in=20
another network segment with a third NIC of the =
firewall...</SPAN></FONT></DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN=20
class=3D705031217-29092000></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN=20
class=3D705031217-29092000></SPAN></FONT>&nbsp;</DIV>
<BLOCKQUOTE=20
style=3D"BORDER-LEFT: #0000ff 2px solid; MARGIN-LEFT: 5px; MARGIN-RIGHT: =
0px; PADDING-LEFT: 5px">
  <DIV align=3Dleft class=3DOutlookMessageHeader dir=3Dltr><FONT =
face=3DTahoma=20
  size=3D2>-----Original Message-----<BR><B>From:</B> =
owner-fwtk-users@ex.tis.com=20
  [mailto:owner-fwtk-users@ex.tis.com]<B>On Behalf Of =
</B>wen<BR><B>Sent:</B>=20
  Friday, September 29, 2000 3:43 AM<BR><B>To:</B>=20
  fwtk-users@lists.nai.com<BR><B>Subject:</B> =
plug-gw<BR><BR></DIV></FONT>
  <DIV><FONT size=3D2>hi,everyon:<BR>&nbsp;&nbsp;&nbsp; my system is=20
  redhat6.2&nbsp; and i have installed fwtk2.1. In my intranet I want to =
offer=20
  www,telnet and ftp servers to internet. now i have done www server =
with=20
  plug-gw in the /etc/rc.d/rc.local file:</FONT></DIV>
  <DIV>&nbsp;</DIV>
  <DIV><FONT size=3D2>&nbsp;&nbsp;&nbsp; /usr/local/etc/plug-gw -daemon =
x.x.x.x:80=20
  -name plug-gw<BR>&nbsp;x.x.x.x is internet address of my firewall =
box.<BR>then=20
  in the netperm-table file i config:</FONT></DIV>
  <DIV>&nbsp;</DIV>
  <DIV><FONT size=3D2>plug-gw:port 80 * -plug-to 192.168.1.10 -port=20
80</FONT></DIV>
  <DIV><FONT size=3D2><BR>i want to config ftp and telnet&nbsp; services =
by the=20
  same way. but i failed and i got a result: plug-gw can't do for two or =
above=20
  services at the same time. <BR>why?<BR>if I want to offer www,ftp and =
telnet=20
  services at the same time. what should i do?=20
</FONT></DIV></BLOCKQUOTE></BODY></HTML>

------=_NextPart_000_0002_01C02A06.624E1A70--


From owner-fwtk-users@ex.tis.com Fri Sep 29 14:53 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA00360
	Fri, 29 Sep 2000 14:53:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA14795;
	Fri, 29 Sep 2000 12:02:19 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 10:41:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA01597
	for fwtk-users-outgoing; Fri, 29 Sep 2000 10:41:25 -0700 (PDT)
Date: Fri, 29 Sep 2000 13:40:44 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Luis Fernando Barrera <luba@assist.com.gt>
Cc: fwtk-users@tis.com
Subject: Re: squid, http-gw and squid-gw
Message-Id: <20000929134044.F7467@washington.cospo.osis.gov>
Mail-Followup-To: Luis Fernando Barrera <luba@assist.com.gt>,
	fwtk-users@tis.com
References: <NABBIDJPNCAGKGOFGHBFGENGOOAA.luba@assist.com.gt>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NABBIDJPNCAGKGOFGHBFGENGOOAA.luba@assist.com.gt>; from luba@assist.com.gt on Fri, Sep 29, 2000 at 12:26:24AM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1959

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 29, 2000 at 12:26:24AM -0600, Luis Fernando Barrera wrote:
...
> I recently asked whether squid versus http-gw versus squid-gw.... Somebody
> "gracefully" sent me to the list archive... So I did it...
> 
> However some questions still bother me, maybe the guys who already
> passed for this info nightmare can give me a hand...
> 
> 1) http-gw is the same as squid-gw?
> 	
> 	I read that they are almost the same with a little advantage of
> 	squid-gw above http-gw?

This was doubtless someone's opinion.  They provide different services,
though.  Each does its thing well.

The rest looks pretty OK.

> 2) It is not recommended to put squid in the firewall box, right?
> 	I saw several messages that squid alone and squid-gw (http-gw)
>             are the same in terms of security...
> 
> 3) You can put the squid software in an internal host and then all the http
>     requests from the internal users, go "relayed" to the squid-gw?
> 
> 4) If you want to put a public web server, it is not a good idea to put it 
>    behind the firewall, even with the "accelerated options" of squid
>    or another trick from squid-gw, right? 
> 
> 5) You can put the web server in a third network segment, using a 3 nic in the
>    firewall, and configure the squid-gw to ONLY permite http traffic from
>    the web server to the internet and viceversa? 
> 	
> How am I doing?  My head is a little mixed up, maybe some definitions
> of the products and their intentions could help... Anybody know
> these definitions?
> 
> Thanks a lot in advance
> 
> Luis Fernando Barrera
> luba@assist.com.gt 
> 

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep 29 15:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA00436
	Fri, 29 Sep 2000 15:36:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA22723;
	Fri, 29 Sep 2000 12:44:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 11:20:26 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA08376
	for fwtk-users-outgoing; Fri, 29 Sep 2000 11:20:02 -0700 (PDT)
Date: Fri, 29 Sep 2000 14:18:36 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: wen <wen_su@263.net>
Cc: fwtk-users@lists.nai.com
Subject: Re: plug-gw
Message-Id: <20000929141836.N7467@washington.cospo.osis.gov>
Mail-Followup-To: wen <wen_su@263.net>, fwtk-users@lists.nai.com
References: <002101c029f9$adfcdf40$0601a8c0@wen>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <002101c029f9$adfcdf40$0601a8c0@wen>; from wen_su@263.net on Fri, Sep 29, 2000 at 05:43:00PM +0800
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1319

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 29, 2000 at 05:43:00PM +0800, wen wrote:
> hi,everyon:
>     my system is redhat6.2  and i have installed fwtk2.1. In my intranet I want to offer www,telnet and ftp servers to internet. now i have done www server with plug-gw in the /etc/rc.d/rc.local file:
> 
>     /usr/local/etc/plug-gw -daemon x.x.x.x:80 -name plug-gw
>  x.x.x.x is internet address of my firewall box.
> then in the netperm-table file i config:
> 
> plug-gw:port 80 * -plug-to 192.168.1.10 -port 80
> 
> i want to config ftp and telnet  services by the same way. but i failed and i got a result: plug-gw can't do for two or above services at the same time. 
> why?
> if I want to offer www,ftp and telnet services at the same time. what should i do? 

This is all a very bad idea.  You should have a separate network on a
third leg of your firewall [on a third NIC] for your externally visible
hosts.  Then you can use some weak form of protection for that leg,
such as ipchains.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep 29 16:02 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA00495
	Fri, 29 Sep 2000 16:02:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA27216;
	Fri, 29 Sep 2000 13:11:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 11:50:05 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA13146
	for fwtk-users-outgoing; Fri, 29 Sep 2000 11:49:42 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: "C. Regis Wilson" <rwilson@gnp.com>
Cc: <fwtk-users@tis.com>
Subject: RE: squid, http-gw and squid-gw
Date: Fri, 29 Sep 2000 12:48:26 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFKENJOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
In-Reply-To: <NEBBKBGDKLMNCDGFGONOAECICAAA.rwilson@gnp.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id LAA13085
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 3638

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Thanks you all for trying to desmitify squid, http-gw and squid-gw...

You're right about the several ways to put the squid and http-gw and squid-gw
together. My problem was that in the list there were too many
comments and it is hard to get something clear from them.

Maybe you guys can clarify more some points...

The *first* part of my questions is concerning the security of the firewall
and the internal network...
The *second* part is concerning the security of some web server and the
security of the internal network...


> Squid:  Squid is a fabulous cache with lots of tuning and security
> for destination, source, method, and lots of other options.  Squid
> was not designed from scratch for security, but it has been tested
> and debugged extensively so that it is probably very secure by now.

My question is if I put the squid software in my firewall, would it be
secure enough to avoid the hackers exploit the squid itself and take
over the firewall? 

Right now I'm using squid on the firewall for performance reasons,
as you did say.

>  Serial mode is probably the "most" secure,
> since it adds extra layers of security.  The idea is that you utilize
> the strenghts of both pieces of software.  I don't use serial mode
> because it's overkill and slows down requests.  

Serial mode means something like this...?


Internal Client (browser) ---> squid box ---> FW w/ SQUID-GW ----> router w/packet filter ----> Internet

I just read that squid-gw cannot do the thing described above.... With squid-gw you
have to do something like this...?

Internal Client (browser) ----->  FW w/ SQUID-GW ---> squid box ----> router w/packet filter ---> Internet

Am I right?
 If so, then this is the where http-gw comes to the game...?

Internal Client (browser) -----> squid box ----> FW w/HTTP-GW  ---> router w/packet filter ----> Internet

Right?


Someone said that if you put squid *behind* the firewall and then you try to
relay the internal client requests to the http-gw or squid-gw, you'd find trouble... 


>If you have the
> hardware and are very security conscious, I recommend that you run
> squid in accelerated mode behind the http-gw.  

I understand that using squid in accelerated mode, means to put a web server which contains
public information (i.e. a web server used by a company to show itself in the Internet) behind
the firewall, AND squid is supposed to hide all services of the web server from the Internet,
except the port designated for the service (usually 80)???

*second part*

Which method do you recommend to put  the company web server ?

1) The easiest is to put it the the public network... Totally exposed (bad idea)
2) To put it behind the firewall, using squid in accelerated mode... Some people
    says that if the web server is compromised, so you whole internal network would be... How
    true it is?
3) Put the web server behind the firewall in a separated segment from the internal network,
    using squid again...
4) Using http-in to forward the incoming requests from the internet to the internal webserver ?????
5) Using squid-gw to forward the incoming requests from the internet to the internal webserver???

In the readme of http-in says its function is to forward the internet request to an internal
web server, but cannot protect from data driver attacks.... The most attacks in these days are
of this kind... SO what's the diference of using squid in accelerated mode than http-in


Thanks again,

Luis Fernando Barrera
luba@assist.com.gt 



From owner-fwtk-users@ex.tis.com Fri Sep 29 16:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA00624
	Fri, 29 Sep 2000 16:33:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA01410;
	Fri, 29 Sep 2000 13:42:10 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 12:23:18 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA19195
	for fwtk-users-outgoing; Fri, 29 Sep 2000 12:23:04 -0700 (PDT)
Date: Fri, 29 Sep 2000 17:44:51 +0200 (CEST)
From: Leandro Gelasi <gelasi@interfree.it>
To: fwtk-users@tis.com
Subject: ftp URLs
Message-ID: <Pine.LNX.4.21.0009291735250.1143-100000@iceman.mydomain.ice>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1039

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi to all!

If I try to reach this kind of url :

ftp://<username>@ftp.server.dom 

from outside http-gw, Netscape opens a password box

If I try the same behind http-gw Netscape does nothing, and connects to
ftp.server.dom without password, getting "connection refused" or similar.
URLs like ftp://<username>:<password>@ftp.server.dom work fine, but
sometimes first type of URLs are found in web pages, in particular for ftp
servers with shared password (one ftp user, many people using the same
password).

ftp://<username>@ftp.server.dom URLs also let users not to show their
password on the screen.

Any hints about?

TIA

LG


*********************************************************************
Leandro Gelasi
V year Computer Science Engineering student at Siena University
gelasi@interfree.it

Gilles Villeneuve will live forever
*********************************************************************


From owner-fwtk-users@ex.tis.com Fri Sep 29 16:33 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA00628
	Fri, 29 Sep 2000 16:33:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA01434;
	Fri, 29 Sep 2000 13:42:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 12:23:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA19287
	for fwtk-users-outgoing; Fri, 29 Sep 2000 12:23:28 -0700 (PDT)
Date: Fri, 29 Sep 2000 21:09:30 +0200 (CEST)
From: Leandro Gelasi <gelasi@interfree.it>
To: wen <wen_su@263.net>
Cc: fwtk-users@lists.nai.com
Subject: Re: plug-gw
In-Reply-To: <002101c029f9$adfcdf40$0601a8c0@wen>
Message-ID: <Pine.LNX.4.21.0009292106210.1540-100000@iceman.mydomain.ice>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1444

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, 29 Sep 2000, wen wrote:

> hi,everyon:
>     my system is redhat6.2  and i have installed fwtk2.1. In my intranet I want to offer www,telnet and ftp servers to internet. now i have done www server with plug-gw in the /etc/rc.d/rc.local file:
> 
>     /usr/local/etc/plug-gw -daemon x.x.x.x:80 -name plug-gw
>  x.x.x.x is internet address of my firewall box.
> then in the netperm-table file i config:
> 
> plug-gw:port 80 * -plug-to 192.168.1.10 -port 80
> 
> i want to config ftp and telnet  services by the same way. but i failed and i got a result: plug-gw can't do for two or above services at the same time. 
> why?
> if I want to offer www,ftp and telnet services at the same time. what should i do? 
> 

You have to change the name of the service.
For example :

 /usr/local/etc/plug-gw -daemon x.x.x.x:80 -name http
 /usr/local/etc/plug-gw -daemon x.x.x.x:21 -name ftp

and so on...

In netpermtable

http: port 80 * -plug-to 192.168.1.10 -port 80 
ftp:  port 21 * -plug-to <internal_ip of your ftp server> -port 21

LG


*********************************************************************
Leandro Gelasi
V year Computer Science Engineering student at Siena University
gelasi@interfree.it

Gilles Villeneuve will live forever
*********************************************************************


From owner-fwtk-users@ex.tis.com Fri Sep 29 17:24 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA00685
	Fri, 29 Sep 2000 17:24:48 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA09546;
	Fri, 29 Sep 2000 14:33:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 13:08:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA26563
	for fwtk-users-outgoing; Fri, 29 Sep 2000 13:08:46 -0700 (PDT)
Date: Fri, 29 Sep 2000 17:05:43 -0300 (BRT)
From: Eurico Hautz Giacon <euricoh@cit.com.br>
To: fwtk-users@lists.nai.com
Subject: http-gw problem
Message-ID: <Pine.LNX.4.21.0009291649280.4836-100000@ravel.cit.com.br>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 571

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,

I have a network with 100 hosts using the http-gw to access the
internet. I use the line above in my inet.conf:

http  stream  tcp  nowait.400  root  /usr/local/tis/etc/http-gw
/usr/local/tis/etc/http-gw

Several times every day, the inet daemon stop and I need to restart it. I
think that the problem is the http-gw. I think that it is overload, does
somebody know how many connections http-gw supports ?

Thanks in advice,
Eurico.
 


From owner-fwtk-users@ex.tis.com Fri Sep 29 18:06 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA00798
	Fri, 29 Sep 2000 18:06:00 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA16523;
	Fri, 29 Sep 2000 15:15:10 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 13:52:48 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA02762
	for fwtk-users-outgoing; Fri, 29 Sep 2000 13:52:37 -0700 (PDT)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@tis.com>
Subject: pop-gw encrypted?
Date: Fri, 29 Sep 2000 14:51:42 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFEENLOOAA.luba@assist.com.gt>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id NAA02736
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 565

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

Is there a way to encrypt the connection between some external user
and the pop-gw of the FWTK? Thus, not sending the user/password
of the outlook client (for example) in clear text...

I've seen an option of the pop-gw called APOP, but I understant that its
purpose is not to encrypt the user/password.
As far as I know the POP3 protocol itself sends the user/password in clear text...

Luis Fernando Barrera
luba@assist.com.gt 


From owner-fwtk-users@ex.tis.com Fri Sep 29 18:54 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA00875
	Fri, 29 Sep 2000 18:54:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA21290;
	Fri, 29 Sep 2000 16:03:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 14:42:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA11052
	for fwtk-users-outgoing; Fri, 29 Sep 2000 14:42:14 -0700 (PDT)
Date: Fri, 29 Sep 2000 17:41:27 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Luis Fernando Barrera <luba@assist.com.gt>
Cc: "C. Regis Wilson" <rwilson@gnp.com>, fwtk-users@tis.com
Subject: Re: squid, http-gw and squid-gw
Message-Id: <20000929174127.Y7467@washington.cospo.osis.gov>
Mail-Followup-To: Luis Fernando Barrera <luba@assist.com.gt>,
	"C. Regis Wilson" <rwilson@gnp.com>, fwtk-users@tis.com
References: <NEBBKBGDKLMNCDGFGONOAECICAAA.rwilson@gnp.com> <NABBIDJPNCAGKGOFGHBFKENJOOAA.luba@assist.com.gt>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NABBIDJPNCAGKGOFGHBFKENJOOAA.luba@assist.com.gt>; from luba@assist.com.gt on Fri, Sep 29, 2000 at 12:48:26PM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2426

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Sep 29, 2000 at 12:48:26PM -0600, Luis Fernando Barrera wrote:
...
> My question is if I put the squid software in my firewall, would it be
> secure enough to avoid the hackers exploit the squid itself and take
> over the firewall? 

Maybe.  Probably not.  Do you really like playing Russian roulette with
your network?

> Right now I'm using squid on the firewall for performance reasons,
> as you did say.

Best performance == worst security.  In general.  Although I can't
think of any exceptions.  I try for fairly high security and acceptable
performance.  Because if security is blown, you may get NO performance.

...
> Someone said that if you put squid *behind* the firewall and then you try to
> relay the internal client requests to the http-gw or squid-gw, you'd find trouble... 

One of them will know which ones it has spoken to before.  One will
not.  You choose.

> >If you have the
> > hardware and are very security conscious, I recommend that you run
> > squid in accelerated mode behind the http-gw.  
> 
> I understand that using squid in accelerated mode, means to put a web server which contains
> public information (i.e. a web server used by a company to show itself in the Internet) behind
> the firewall, AND squid is supposed to hide all services of the web server from the Internet,
> except the port designated for the service (usually 80)???
> 
> *second part*
> 
> Which method do you recommend to put  the company web server ?
> 
> 1) The easiest is to put it the the public network... Totally exposed (bad idea)
> 2) To put it behind the firewall, using squid in accelerated mode... Some people
>     says that if the web server is compromised, so you whole internal network would be... How
>     true it is?

Entirely and completely true.

> 3) Put the web server behind the firewall in a separated segment from the internal network,
>     using squid again...
> 4) Using http-in to forward the incoming requests from the internet to the internal webserver ?????

These last two are not incompatible.  Probably best to do both.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Sep 29 21:06 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA01140
	Fri, 29 Sep 2000 21:06:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA27937;
	Fri, 29 Sep 2000 18:15:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 16:47:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA24740
	for fwtk-users-outgoing; Fri, 29 Sep 2000 16:46:53 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000929193202.00ba4230@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Fri, 29 Sep 2000 19:40:52 -0400
To: jseymour@medar.com (James Seymour), fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FWTK Lic Questions
In-Reply-To: <20000929124514.D9AE141A2E@skynet.medar.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 2308

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 08:45 AM 9/29/00 -0400, James Seymour wrote:
>Correct me if I'm wrong: but my reading of the license, some time back,
>was that not only was one prohibited from reselling or otherwise
>charging to install or support it, but that one was completely
>prohibited from re-distributing it to others in any form whatsoever.

That's what the copyright is for :-)
Actually, the distribution restrictions were put in place because people 
WERE selling FWTK systems (one individual actually installed dozens of FWTK 
firewalls and told his customers that "fwtk-support@tis.com" was where they 
went for support. Some rather unhappy people resulted when they realized 
they had no support :-)
The distribution restrictions were a way of enforcing the agreement with 
the license terms before you got the software. This was made necessary by 
the folks who claimed to have never seen or read the license.

>As a whimsical aside: if one is not allowed to "charge for supporting
>it", and a company is in need of a consultant that understands it--for
>some "out-sourced" help, does that mean the consultant can't take the
>job?

In essence, yes. In reality, you're probably not consulting in this case 
for the sole purpose of running the firewall, so while it's a gray area, 
that's probably OK. It's hard to craft legalese that captured the intent - 
use it as you see fit in your company, don't sell it, don't make money from it.

>   For example: I've been working with Gauntlet for years.  So I
>imagine I could find my way around an FWTK installation.  Say I decided
>to give up my life as a masochist (Sys. & Network Admin.) and go it
>alone as an independent consultant.  And a potential client calls one
>day needing help with a FWTK installation (their lone staff SysAdmin is
>on vacation or whatever).  Hmmm...

Again, if this is primarily a FWTK support job, you're in violation of the 
intent.

>I surely wish NAI would "free the source" and be done with it, fer
>crissakes.

Me too. The current restrictions keep this from being an attractive add-on 
to the filters available in BSD and Linux systems, and discourages 
open-source advocates from contributing.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Sep 29 22:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA01284
	Fri, 29 Sep 2000 22:36:36 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA01297;
	Fri, 29 Sep 2000 19:45:44 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 18:17:10 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA27990
	for fwtk-users-outgoing; Fri, 29 Sep 2000 18:16:49 -0700 (PDT)
Message-Id: <4.3.2.7.2.20000929210413.00b99ac0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 4.3.2
Date: Fri, 29 Sep 2000 21:10:45 -0400
To: "Luis Fernando Barrera" <luba@assist.com.gt>, <fwtk-users@tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: pop-gw encrypted?
In-Reply-To: <NABBIDJPNCAGKGOFGHBFEENLOOAA.luba@assist.com.gt>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1164

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:51 PM 9/29/00 -0600, Luis Fernando Barrera wrote:
>Is there a way to encrypt the connection between some external user
>and the pop-gw of the FWTK? Thus, not sending the user/password
>of the outlook client (for example) in clear text...

You would need to have a mail client that knows how to encrypt the 
connection (as well as an encrypting POP server). I seem to remember that 
there's some mail readers that can use POP-over-SSL to encrypt the 
connection; that's probably worth investigating.

>I've seen an option of the pop-gw called APOP, but I understant that its
>purpose is not to encrypt the user/password.

APOP replaces the password authentication with a challenge-response 
mechanism. Thus, the password isn't sent over the wire - it's used to hash 
a challenge. APOP is far better than standard POP because the password 
isn't sent in the clear; it's still subject to a dictionary attack against 
the password (if you can sniff the challenge and the response, you can 
brute-force the password).
         -Rick


From owner-fwtk-users@ex.tis.com Fri Sep 29 22:36 EDT 2000
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA01287
	Fri, 29 Sep 2000 22:36:42 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA01301;
	Fri, 29 Sep 2000 19:45:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 29 Sep 2000 18:19:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA28034
	for fwtk-users-outgoing; Fri, 29 Sep 2000 18:18:47 -0700 (PDT)
Date: Fri, 29 Sep 2000 21:14:41 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Eurico Hautz Giacon <euricoh@cit.com.br>
cc: fwtk-users@lists.nai.com
Subject: Re: http-gw problem
In-Reply-To: <Pine.LNX.4.21.0009291649280.4836-100000@ravel.cit.com.br>
Message-ID: <Pine.GSO.4.10.10009292113540.20502-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 997

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Eurico,

You are probably exeeding the threshold that your inetd allows for
connections per second. You may want to consider running http-gw in
-daemon mode.  This is supported in version 2.1.

ted keller


On Fri, 29 Sep 2000, Eurico Hautz Giacon wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
> Hi,
> 
> I have a network with 100 hosts using the http-gw to access the
> internet. I use the line above in my inet.conf:
> 
> http  stream  tcp  nowait.400  root  /usr/local/tis/etc/http-gw
> /usr/local/tis/etc/http-gw
> 
> Several times every day, the inet daemon stop and I need to restart it. I
> think that the problem is the http-gw. I think that it is overload, does
> somebody know how many connections http-gw supports ?
> 
> Thanks in advice,
> Eurico.
>  
> 


