From owner-fwtk-users@ex.tis.com Tue Jan  2 18:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA01180
	Tue, 2 Jan 2001 18:34:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA22960;
	Tue, 2 Jan 2001 15:34:49 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 2 Jan 2001 13:59:04 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA13434
	for fwtk-users-outgoing; Tue, 2 Jan 2001 13:58:53 -0800 (PST)
Message-ID: <3D6CFAEE245FD411938A00508BE37148013387A1@exchnj01.sbi.com>
From: "Barreira, Fernando [IT]" <fernando.barreira@ssmb.com>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: ftp-gw not passing the "Fin" on data session
Date: Tue, 2 Jan 2001 16:08:49 -0500 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
	boundary="----_=_NextPart_000_01C07500.33CF3040"
Content-Length: 5964

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_000_01C07500.33CF3040
Content-Type: text/plain

hi there,

i have fwtk 2.1 on a solaris 5.6 machine, when a user goes to a specific
site (ftp1.lewcosec.com) and does something that triggers a data session(the
"ls" command), the ftp session hungs.
this does not happen every single session but it happens very often that
causes ftp scripts to fail.

on the machine that runs the fwtk, i did capture both sessions, the one
between the client machine and the ftp-gw and between the ftp-gw and the
remote server (ftp1.lewcosec.com).
i noticed on one og the hung sessions, the remote server sends a packet for
the data session with the Fin=1 to terminate the data session and the ftp-gw
never frowards it to the client machine.

why would the ftp-gw sometimes send it and sometimes not?

here are the captures for the the same data session, "client" is the
client<===>ftp-gw connection; "server" is the
ftp-gw<===ftp1.lewcosec.com connection. any help would be appreciated.


  <<client>>  <<server>> 



------_=_NextPart_000_01C07500.33CF3040
Content-Type: application/octet-stream;
	name="client.log"
Content-Disposition: attachment;
	filename="client.log"
Content-Description: client


TCP:  Source port = 2534
TCP:  Destination port = 21 (FTP)
TCP:  Sequence number = 5985957
TCP:  Acknowledgement number = 1101451146
TCP:  Data offset = 20 bytes
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP:  "NLST\r\n"
  
TCP:  Source port = 21
TCP:  Destination port = 2534
TCP:  Sequence number = 1101451146
TCP:  Acknowledgement number = 5985963
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP:  "150 Opening ASCII mode data connection for file list.\r\n"

TCP:  Source port = 33617
TCP:  Destination port = 2539
TCP:  Sequence number = 1109723159
TCP:  Acknowledgement number = 0
TCP:        .... ..1. = Syn

TCP:  Source port = 2539
TCP:  Destination port = 33617
TCP:  Sequence number = 5985813
TCP:  Acknowledgement number = 1109723160
TCP:        ...1 .... = Acknowledgement
TCP:        .... ..1. = Syn

TCP:  Source port = 33617
TCP:  Destination port = 2539
TCP:  Sequence number = 1109723160
TCP:  Acknowledgement number = 5985814
TCP:        ...1 .... = Acknowledgement

TCP:  Source port = 33617
TCP:  Destination port = 2539
TCP:  Sequence number = 1109723160
TCP:  Acknowledgement number = 5985814
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push

TCP:  Source port = 2534
TCP:  Destination port = 21 (FTP)
TCP:  Sequence number = 5985963
TCP:  Acknowledgement number = 1101451201
TCP:        ...1 .... = Acknowledgement

TCP:  Source port = 21
TCP:  Destination port = 2534
TCP:  Sequence number = 1101451201
TCP:  Acknowledgement number = 5985963
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP:  "226 Transfer complete.\r\n"

TCP:  Source port = 2539
TCP:  Destination port = 33617
TCP:  Sequence number = 5985814
TCP:  Acknowledgement number = 1109723465
TCP:        ...1 .... = Acknowledgement

TCP:  Source port = 2534
TCP:  Destination port = 21 (FTP)
TCP:  Sequence number = 5985963
TCP:  Acknowledgement number = 1101451225
TCP:  Data offset = 20 bytes
TCP:        ...1 .... = Acknowledgement

------_=_NextPart_000_01C07500.33CF3040
Content-Type: application/octet-stream;
	name="server.log"
Content-Disposition: attachment;
	filename="server.log"
Content-Description: server


TCP:  Source port = 33607
TCP:  Destination port = 21 (FTP)
TCP:  Sequence number = 1102492571
TCP:  Acknowledgement number = 209797995
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP:  "NLST\r\n"
  
TCP:  Source port = 21
TCP:  Destination port = 33607
TCP:  Sequence number = 209797995
TCP:  Acknowledgement number = 1102492577
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP:  "150 Opening ASCII mode data connection for file list.\r\n"
  
TCP:  Source port = 20
TCP:  Destination port = 33616
TCP:  Sequence number = 209797650
TCP:        .... ..1. = Syn

TCP:  Source port = 33616
TCP:  Destination port = 20 (FTP-DATA)
TCP:  Sequence number = 1109643465
TCP:  Acknowledgement number = 209797651
TCP:        ...1 .... = Acknowledgement
TCP:        .... ..1. = Syn

TCP:  Source port = 20
TCP:  Destination port = 33616
TCP:  Sequence number = 209797651
TCP:  Acknowledgement number = 1109643466
TCP:        ...1 .... = Acknowledgement
  
TCP:  Source port = 20
TCP:  Destination port = 33616
TCP:  Sequence number = 209797956
TCP:  Acknowledgement number = 1109643466
TCP:        ...1 .... = Acknowledgement
TCP:        .... ...1 = Fin

TCP:  Source port = 20
TCP:  Destination port = 33616
TCP:  Sequence number = 209797651
TCP:  Acknowledgement number = 1109643466
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP-DATA:  "ftproot\r\nkimtest\r\nPS2.TXT\r\nSACCTPAY.20001213.OLD\r\nSACCTPAY.2"

TCP:  Source port = 33616
TCP:  Destination port = 20 (FTP-DATA)
TCP:  Sequence number = 1109643466
TCP:  Acknowledgement number = 209797956
TCP:        ...1 .... = Acknowledgement

TCP:  Source port = 33607
TCP:  Destination port = 21 (FTP)
TCP:  Sequence number = 1102492577
TCP:  Acknowledgement number = 209798050
TCP:        ...1 .... = Acknowledgement

TCP:  Source port = 21
TCP:  Destination port = 33607
TCP:  Sequence number = 209798050
TCP:  Acknowledgement number = 1102492577
TCP:        ...1 .... = Acknowledgement
TCP:        .... 1... = Push
FTP:  "226 Transfer complete.\r\n"
  
TCP:  Source port = 33607
TCP:  Destination port = 21 (FTP)
TCP:  Sequence number = 1102492577
TCP:  Acknowledgement number = 209798074
TCP:        ...1 .... = Acknowledgement
  

------_=_NextPart_000_01C07500.33CF3040--


From owner-fwtk-users@ex.tis.com Tue Jan  2 18:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA01183
	Tue, 2 Jan 2001 18:34:45 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA22964;
	Tue, 2 Jan 2001 15:34:51 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 2 Jan 2001 14:11:25 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA14995
	for fwtk-users-outgoing; Tue, 2 Jan 2001 14:11:15 -0800 (PST)
Message-ID: <3D6CFAEE245FD411938A00508BE37148013387A2@exchnj01.sbi.com>
From: "Barreira, Fernando [IT]" <fernando.barreira@ssmb.com>
To: "'fwtk-users@tis.com'" <fwtk-users@tis.com>
Subject: fwtk documents
Date: Tue, 2 Jan 2001 17:00:11 -0500 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 362

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi there,

is there any thechnical paper that describes in detail how the fwtk ftp-gw
operates, i need the mechanics of what takes place between the
client<===>ftpgw<===>remote_ftp, i need this to troubleshoot a problem.

thanks.




From owner-fwtk-users@ex.tis.com Tue Jan  2 18:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA01184
	Tue, 2 Jan 2001 18:34:46 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA22968;
	Tue, 2 Jan 2001 15:34:51 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 2 Jan 2001 13:21:41 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA09808
	for fwtk-users-outgoing; Tue, 2 Jan 2001 13:21:30 -0800 (PST)
Date: Tue, 2 Jan 2001 14:20:18 -0700
From: Ricardo Meleschi <meleschi@elp.rr.com>
To: fwtk-users@lists.nai.com
Subject: FWTK - CIDR Patch
Message-ID: <20010102142018.D889@dt02q3nfc.elp.rr.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 322

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

To All,

        Does anyone know where the Classless InterDomain Routing patch is for
FWTK 2.1?  It's the patch which allows you to use the "/24" type of
netmasking.

Thanks,
Ricardo Meleschi

From owner-fwtk-users@ex.tis.com Wed Jan  3 07:21 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA03554
	Wed, 3 Jan 2001 07:21:42 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA26663;
	Wed, 3 Jan 2001 04:21:48 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 3 Jan 2001 02:47:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA23739
	for fwtk-users-outgoing; Wed, 3 Jan 2001 02:47:40 -0800 (PST)
Date: Wed, 3 Jan 2001 11:46:15 +0100 (MET)
From: Thomas Off <Alberik@gmx.de>
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Subject: FWTK as general gateway
X-Priority: 3 (Normal)
X-Authenticated-Sender: #0001725558@gmx.net
X-Authenticated-IP: [212.89.102.100]
Message-ID: <4733.978518775@www21.gmx.net>
X-Mailer: WWW-Mail 1.5 (Global Message Exchange)
X-Flags: 0001
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 695

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello everybody!

I have the following problem within my network:
I shall configure the FWTK as one single gateway so that Windows-Users
don't have to configure all the single proxies but just change the standard
gateway to point to the firewall. This shall be done because they don't want to
make one single entry on the FWTK for each new service, for example if they
have to access a http-server on a port different from standard 80. Can
there anybody give me tips on who to do this?

Thanks a lot.

Thomas Off

-- 
Sent through GMX FreeMail - http://www.gmx.net


From owner-fwtk-users@ex.tis.com Wed Jan  3 08:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA04120
	Wed, 3 Jan 2001 08:52:33 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA29779;
	Wed, 3 Jan 2001 05:52:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 3 Jan 2001 04:32:48 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA26955
	for fwtk-users-outgoing; Wed, 3 Jan 2001 04:32:38 -0800 (PST)
Date: Wed, 3 Jan 2001 14:31:58 +0200
From: Berend De Schouwer <bds@jhb.ucs.co.za>
To: "'fwtk-users @ tis . com'" <fwtk-users@tis.com>
Subject: ftp-pasv patch and ProFTPD.
Message-ID: <20010103143158.F20853@bds.ucs.co.za>
Reply-To: bds@jhb.ucs.co.za
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Mailer: Balsa 1.0.1
Lines: 58
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 1850

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I've tried the ftp-pasv patch for TIS FWTK, and noticed
it failed to connect to some Pro-FTPD servers.  It breaks
when it tries to decode the remote port.

So here goes:
* The patch expects 'Entering Passive Mode (a,b,c,d,x,y)'
* Pro-FTPD sends 'Entering Passive Mode (a,b,c,d,x,y).'
  (notice the full-stop).

I'm playing with a lot of other options, so I can't
give the exact line numbers, but here is an attempt
at a patch:

To fix it, in ftp-gw/ftp-gw.c, replace

        for(i=1;i<tokac;i++) {
                if( tokav[i][0] == '(' ) {
                        x = strlen(tokav[i]);
                        if ( tokav[i][x-1] == ')' ) {
                                tokav[i][x-1] = 0;
                                (tokav[i])++;
                                break;
                         }
                }
        }

with:

        for(i=1;i<tokac;i++) {
                if( tokav[i][0] == '(' ) {
                        x = strlen(tokav[i]);
                        if (x < 2) {
                                syslog(LLEV,
                               "WARNING: response from server too
short.");
                        }
                        if ( (tokav[i][x-1] == ')') ||
                             ( (tokav[i][x-1] == '.') &&
                               (tokav[i][x-2] == ')')
                             )
                           ) {
                                tokav[i][x-1] = 0;
                                (tokav[i])++;
                                break;
                         }
                }
        }



Kind regards,				  
Berend                                  

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Berend De Schouwer, +27-11-712-1435, UCS


From owner-fwtk-users@ex.tis.com Wed Jan  3 11:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA04709
	Wed, 3 Jan 2001 11:05:13 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA09924;
	Wed, 3 Jan 2001 08:05:16 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 3 Jan 2001 06:41:02 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA02361
	for fwtk-users-outgoing; Wed, 3 Jan 2001 06:40:52 -0800 (PST)
Date: Wed, 3 Jan 2001 15:39:26 +0100 (MET)
From: Thomas Off <Alberik@gmx.de>
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Subject: Patch for ftp-gw
X-Priority: 3 (Normal)
X-Authenticated-Sender: #0001725558@gmx.net
X-Authenticated-IP: [212.89.102.100]
Message-ID: <14106.978532766@www29.gmx.net>
X-Mailer: WWW-Mail 1.5 (Global Message Exchange)
X-Flags: 0001
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 440

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi everyone!

I just found that patch for the ftp-gw to give it plug-capability. But now
i'm not sure, how to use it: when i try to patch it with the FWTK (both
versions 2.0 and 2.0) all six hunks fail!
What do i have to do to fix this?

Regards, Thomas Off

-- 
Sent through GMX FreeMail - http://www.gmx.net


From owner-fwtk-users@ex.tis.com Wed Jan  3 19:55 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA06340
	Wed, 3 Jan 2001 19:55:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA03042;
	Wed, 3 Jan 2001 16:55:19 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 3 Jan 2001 14:50:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA21973
	for fwtk-users-outgoing; Wed, 3 Jan 2001 14:50:00 -0800 (PST)
Message-Id: <sa535739.097@css.edu>
X-Mailer: Novell GroupWise 5.5.3
Date: Wed, 03 Jan 2001 16:45:31 -0600
From: "Chris Jugasek" <CJugasek@css.edu>
To: <Fwtk-users@lists.nai.com>
Subject: I.P. Recognition
Mime-Version: 1.0
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 1202

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Using "HTTP-GW" freeware software, on a secured access page, we redirect
the user through our server on a specific port in order to authenticate
the i.p. address to this url:

http://spweb.silverplatter.com/c124936?_ 
I get the following error message:

******************
No Server

You have accessed the HTTP-GW and the proxy has not been able to find
any server information in your request and there is no
default server configured to hand the request off to.

You may be able to get your firewall administrator to configure the
firewall to pass these requests off to a local HTTP server.	
I am perplexed and hoping you may offer some insight.  Thank you!!

*****************

I know this site is using JavaScript.  Can anyone offer any insight as
why I am erroring out.  I have a couple other sites configured this same
way without any trouble but they are not using a JavaScript.

Any help would truly be appreciated!  Thanks!

Chris

Christine Jugasek
Information Technologies
The College of St. Scholastica
ph. 218-723-7007
fax 218-723-6290
email:  cjugasek@css.edu

From owner-fwtk-users@ex.tis.com Wed Jan  3 19:55 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA06339
	Wed, 3 Jan 2001 19:55:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA03038;
	Wed, 3 Jan 2001 16:55:18 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 3 Jan 2001 14:50:43 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA22055
	for fwtk-users-outgoing; Wed, 3 Jan 2001 14:50:32 -0800 (PST)
Message-Id: <sa535758.098@css.edu>
X-Mailer: Novell GroupWise 5.5.3
Date: Wed, 03 Jan 2001 16:45:53 -0600
From: "Chris Jugasek" <CJugasek@css.edu>
To: <Fwtk-users@lists.nai.com>
Subject: I.P. Recognition
Mime-Version: 1.0
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 1202

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Using "HTTP-GW" freeware software, on a secured access page, we redirect
the user through our server on a specific port in order to authenticate
the i.p. address to this url:

http://spweb.silverplatter.com/c124936?_ 
I get the following error message:

******************
No Server

You have accessed the HTTP-GW and the proxy has not been able to find
any server information in your request and there is no
default server configured to hand the request off to.

You may be able to get your firewall administrator to configure the
firewall to pass these requests off to a local HTTP server.	
I am perplexed and hoping you may offer some insight.  Thank you!!

*****************

I know this site is using JavaScript.  Can anyone offer any insight as
why I am erroring out.  I have a couple other sites configured this same
way without any trouble but they are not using a JavaScript.

Any help would truly be appreciated!  Thanks!

Chris

Christine Jugasek
Information Technologies
The College of St. Scholastica
ph. 218-723-7007
fax 218-723-6290
email:  cjugasek@css.edu

From owner-fwtk-users@ex.tis.com Thu Jan  4 05:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA07857
	Thu, 4 Jan 2001 05:59:33 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA22590;
	Thu, 4 Jan 2001 02:59:47 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 4 Jan 2001 01:30:15 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA19675
	for fwtk-users-outgoing; Thu, 4 Jan 2001 01:30:14 -0800 (PST)
Message-ID: <3A544026.803F0B05@ordix.de>
Date: Thu, 04 Jan 2001 10:19:34 +0100
From: Markus Schreier <ms@ordix.de>
X-Mailer: Mozilla 4.7 [de]C-CCK-MCD QXW03237  (WinNT; I)
X-Accept-Language: de,en
MIME-Version: 1.0
To: Thomas Off <Alberik@gmx.de>, fwtk-users@lists.nai.com
Subject: Re: Patch for ftp-gw
References: <14106.978532766@www29.gmx.net>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1171

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello Thomas,
i always had the following problem:
The patch looked al wright. Wenn i looked at the lines it wanted to
replace they also seemed to fit together. Still the patch would fail.

Whenn looking at the downloaded patch with an hex-editor, i found \n \r
(dos-style) instead of only \n (unix-style). Removing the \r solved the
problems.
Perhaps you can download the patches using soley unix -utilities.

Sorry for my poor english. I'm not used to righting that language :-(
I hope that helps anyway

Best regards from Wiesbaden (Germany)

Markus

Thomas Off schrieb:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi everyone!
> 
> I just found that patch for the ftp-gw to give it plug-capability. But now
> i'm not sure, how to use it: when i try to patch it with the FWTK (both
> versions 2.0 and 2.0) all six hunks fail!
> What do i have to do to fix this?
> 
> Regards, Thomas Off
> 
> --
> Sent through GMX FreeMail - http://www.gmx.net

From owner-fwtk-users@ex.tis.com Thu Jan  4 06:22 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA07964
	Thu, 4 Jan 2001 06:22:37 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA23371;
	Thu, 4 Jan 2001 03:22:54 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 4 Jan 2001 02:11:20 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA21010
	for fwtk-users-outgoing; Thu, 4 Jan 2001 02:11:10 -0800 (PST)
Message-ID: <XFMail.20010104100954.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.4 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <sa535758.098@css.edu>
Date: Thu, 04 Jan 2001 10:09:54 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: Chris Jugasek <CJugasek@css.edu>
Subject: RE: I.P. Recognition
Cc: Fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1803

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


I don't understand what the problem is. The URL given gives me a
login page. Could you explain further.

-tony



On 03-Jan-2001 Chris Jugasek wrote:
> [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Using "HTTP-GW" freeware software, on a secured access page, we
> redirect
> the user through our server on a specific port in order to
> authenticate
> the i.p. address to this url:
> 
> http://spweb.silverplatter.com/c124936?_ 
> I get the following error message:
> 
> ******************
> No Server
> 
> You have accessed the HTTP-GW and the proxy has not been able to
> find
> any server information in your request and there is no
> default server configured to hand the request off to.
> 
> You may be able to get your firewall administrator to configure the
> firewall to pass these requests off to a local HTTP server.   
> I am perplexed and hoping you may offer some insight.  Thank you!!
> 
> *****************
> 
> I know this site is using JavaScript.  Can anyone offer any insight
> as
> why I am erroring out.  I have a couple other sites configured this
> same
> way without any trouble but they are not using a JavaScript.
> 
> Any help would truly be appreciated!  Thanks!
> 
> Chris
> 
> Christine Jugasek
> Information Technologies
> The College of St. Scholastica
> ph. 218-723-7007
> fax 218-723-6290
> email:  cjugasek@css.edu

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
Bus error -- driver executed.

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Thu Jan  4 11:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA09099
	Thu, 4 Jan 2001 11:42:04 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA13129;
	Thu, 4 Jan 2001 08:42:43 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 4 Jan 2001 07:13:27 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA01904
	for fwtk-users-outgoing; Thu, 4 Jan 2001 07:13:16 -0800 (PST)
Message-ID: <3D6CFAEE245FD411938A00508BE37148013387AB@exchnj01.sbi.com>
From: "Barreira, Fernando [IT]" <fernando.barreira@ssmb.com>
To: fwtk-users@tis.com
Subject: error message after 2.9 patch being applied
Date: Thu, 4 Jan 2001 10:06:00 -0500 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 536

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi there,

i have applied the fwtk patch 2.9 so that data port 20 is used instead of a
random port. after testing, i noticed the machine still uses a random port,
also noticed on the loge file a messages is being logged:


Jan  3 14:02:45 ftpproxy1 ftp-gw[989]: fwtksyserr: bind failed: Permission
denied 

does anyone know what this message means and if it has anything to do with
the patch 2.9.

thanks.


From owner-fwtk-users@ex.tis.com Thu Jan  4 11:46 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA09105
	Thu, 4 Jan 2001 11:46:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA13729;
	Thu, 4 Jan 2001 08:46:52 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 4 Jan 2001 07:36:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA05241
	for fwtk-users-outgoing; Thu, 4 Jan 2001 07:36:15 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A549633.6531448F@peaktime.be>
Date: Thu, 04 Jan 2001 16:26:43 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Re: error message after 2.9 patch being applied
References: <3D6CFAEE245FD411938A00508BE37148013387AB@exchnj01.sbi.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 870

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

"Barreira, Fernando [IT]" wrote:
 > 
 > hi there,
 > 
 > i have applied the fwtk patch 2.9 so that data port 20 is used instead of a
 > random port. after testing, i noticed the machine still uses a random port,
 > also noticed on the loge file a messages is being logged:
 > 
 > Jan  3 14:02:45 ftpproxy1 ftp-gw[989]: fwtksyserr: bind failed: Permission
 > denied
 > 
 > does anyone know what this message means and if it has anything to do with
 > the patch 2.9.
 > 
 > thanks.

It usually means an attempt by a non-root process to bind to a
privileged port (low number). Do you run fwtk processes as 'nobody'?

-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Thu Jan  4 12:36 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA09340
	Thu, 4 Jan 2001 12:36:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA23038;
	Thu, 4 Jan 2001 09:36:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 4 Jan 2001 08:16:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA10030
	for fwtk-users-outgoing; Thu, 4 Jan 2001 08:16:20 -0800 (PST)
Message-ID: <01C07679.2CB2A740.gmclean@icon.co.za>
From: Gavin Mclean <gmclean@icon.co.za>
Reply-To: "gmclean@icon.co.za" <gmclean@icon.co.za>
To: "'fwtk-users@lists.nai.com.'" <fwtk-users@lists.nai.com>
Subject: fwtk and Solaris 7 for intel
Date: Thu, 4 Jan 2001 18:07:16 -0000
Organization: Private
X-Mailer: Microsoft Internet E-mail/MAPI - 8.0.0.4211
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 199

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi There

I need to know if fwtk works on Solaris 7 for Intel

Gavin


From owner-fwtk-users@ex.tis.com Thu Jan  4 15:19 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA09951
	Thu, 4 Jan 2001 15:19:15 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA14304;
	Thu, 4 Jan 2001 12:19:01 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 4 Jan 2001 10:52:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA02350
	for fwtk-users-outgoing; Thu, 4 Jan 2001 10:52:25 -0800 (PST)
X-Authentication-Warning: Draco.house.gov: smap set sender to <Karen.Alcorn@mail.house.gov> SIZE=1508 using -f
Message-ID: <462720E13B20D311BF170008C75D282001BE24C7@hrm08.house.gov>
From: "Alcorn, Karen" <Karen.Alcorn@mail.house.gov>
To: "'gmclean@icon.co.za'" <gmclean@icon.co.za>,
        "'fwtk-users@lists.nai.com.'" <fwtk-users@lists.nai.com>
Subject: RE: fwtk and Solaris 7 for intel
Date: Thu, 4 Jan 2001 13:50:46 -0500 
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 583

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

The smap portion works because that is what I use on Solaris 7 x86.

-----Original Message-----
From: Gavin Mclean [mailto:gmclean@icon.co.za]
Sent: Thursday, January 04, 2001 1:07 PM
To: 'fwtk-users@lists.nai.com.'
Subject: fwtk and Solaris 7 for intel


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

Hi There

I need to know if fwtk works on Solaris 7 for Intel

Gavin

From owner-fwtk-users@ex.tis.com Fri Jan  5 11:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13453
	Fri, 5 Jan 2001 11:15:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA07856;
	Fri, 5 Jan 2001 08:15:45 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 5 Jan 2001 06:05:24 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA26020
	for fwtk-users-outgoing; Fri, 5 Jan 2001 06:05:13 -0800 (PST)
Date: Fri, 5 Jan 2001 15:04:16 +0100
From: Georg Wittig <Georg.Wittig@gmd.de>
To: fwtk-users@tis.com
Subject: plug-gw + ssh  config question
Message-ID: <20010105150416.A14030@twister.gmd.de>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1394

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I need some help to get ssh proxied to the internal net via plug-gw. I
searched the list archives and tried my setup according to the article
	http://marc.theaimsgroup.com/?l=fwtk-users&m=95544510922458&w=2
by Michel Bardiaux. But alas, this doesn't work for me. My firewall
machine is running RedHat-6.2.

Here's my current setup:

[/etc/services]
ssh             22/tcp                          # SSH Remote Login Protocol

[ps axww | grep ssh]
27055 tty1     S      0:00 /path/to/netacl -daemon 22 ssh
(No, I'm not running inetd, so I started netacl manually.)

[netperm-table]
netacl-ssh:     permit hosts * -exec /path/to/plug-gw ssh
plug-gw:        port ssh * -plug-to 11.22.33.44 -port ssh


When I try an inbound ssh connection, the connection is closed
immediately. In /var/log/messages I just see the line

	netacl[27080]: deny host=55.66.77.88s service=ssh

Why's that? Doesn't the "netacl-ssh" line in my netperm-table *allow*
that connection? What did I do wrong?

Thanks for your help,
      Georg


-- 
Georg Wittig, GMD				Georg.Wittig@gmd.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
Macht Sie den um Gang mit dem Juice nett auch nicht leichter.

From owner-fwtk-users@ex.tis.com Fri Jan  5 11:41 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13526
	Fri, 5 Jan 2001 11:41:33 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA11224;
	Fri, 5 Jan 2001 08:42:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 5 Jan 2001 07:24:28 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA02169
	for fwtk-users-outgoing; Fri, 5 Jan 2001 07:24:07 -0800 (PST)
Message-Id: <200101051523.KAA02929@fw-nyc-02.proexam.org>
Date: Fri, 5 Jan 2001 10:23:21 -0500 (EST)
From: Charles Robinson <crobins@proexam.org>
To: Georg Wittig <Georg.Wittig@gmd.de>
cc: fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
In-Reply-To: <20010105150416.A14030@twister.gmd.de>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1860

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

1. Have you tried using the ssh-gw from the toolkit?
2. Did you add your client ip to your hosts.allow file?

~~~~~~~~~~~~~~~~
Charles Robinson
    IT Dept.
Professional Examination Service
~~~~~~~~~~~~~~~~

On Fri, 5 Jan 2001, Georg Wittig wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi,
> 
> I need some help to get ssh proxied to the internal net via plug-gw. I
> searched the list archives and tried my setup according to the article
> 	http://marc.theaimsgroup.com/?l=fwtk-users&m=95544510922458&w=2
> by Michel Bardiaux. But alas, this doesn't work for me. My firewall
> machine is running RedHat-6.2.
> 
> Here's my current setup:
> 
> [/etc/services]
> ssh             22/tcp                          # SSH Remote Login Protocol
> 
> [ps axww | grep ssh]
> 27055 tty1     S      0:00 /path/to/netacl -daemon 22 ssh
> (No, I'm not running inetd, so I started netacl manually.)
> 
> [netperm-table]
> netacl-ssh:     permit hosts * -exec /path/to/plug-gw ssh
> plug-gw:        port ssh * -plug-to 11.22.33.44 -port ssh
> 
> 
> When I try an inbound ssh connection, the connection is closed
> immediately. In /var/log/messages I just see the line
> 
> 	netacl[27080]: deny host=55.66.77.88s service=ssh
> 
> Why's that? Doesn't the "netacl-ssh" line in my netperm-table *allow*
> that connection? What did I do wrong?
> 
> Thanks for your help,
>       Georg
> 
> 
> -- 
> Georg Wittig, GMD				Georg.Wittig@gmd.de
> - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
> Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
> Macht Sie den um Gang mit dem Juice nett auch nicht leichter.
> 


From owner-fwtk-users@ex.tis.com Sat Jan  6 17:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA22739
	Sat, 6 Jan 2001 17:04:47 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA03867;
	Sat, 6 Jan 2001 14:04:49 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 6 Jan 2001 11:52:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA01722
	for fwtk-users-outgoing; Sat, 6 Jan 2001 11:52:35 -0800 (PST)
Date: Sat, 6 Jan 2001 20:50:40 +0100
From: Georg Wittig <Georg.Wittig@gmd.de>
To: Charles Robinson <crobins@proexam.org>, fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
Message-ID: <20010106205040.A2236@twister.gmd.de>
References: <20010105150416.A14030@twister.gmd.de> <200101051523.KAA02929@fw-nyc-02.proexam.org>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <200101051523.KAA02929@fw-nyc-02.proexam.org>; from crobins@proexam.org on Fri, Jan 05, 2001 at 10:23:21AM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1079

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Charles Robinson wrote:


> 1. Have you tried using the ssh-gw from the toolkit?


No, I think we cannot use ssh-gw because it is a patch to a VERY old
version of sshd (1.2.20). I doubt it can be applied successfully to
ssh-2.3 or ssh-2.4 or openssh. Furthermore, data is not encrypted
between the gateway and the ssh Server.


> 2. Did you add your client ip to your hosts.allow file?


Yes, the client is allowed in /etc/hosts. But tcpwrapper is not
involved in that business at all; inetd isn't running. The tcpwrapper
message would have been "refused connection from ...". But the message
I see is "deny host=... service=ssh" which can be found in netacl.c.
So I think it is a problem with netacl.


-- 
Georg Wittig, GMD				Georg.Wittig@gmd.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
Macht Sie den um Gang mit dem Juice nett auch nicht leichter.

From owner-fwtk-users@ex.tis.com Sat Jan  6 18:50 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA01459
	Sat, 6 Jan 2001 18:50:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA06806;
	Sat, 6 Jan 2001 15:50:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 6 Jan 2001 14:27:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA04330
	for fwtk-users-outgoing; Sat, 6 Jan 2001 14:27:35 -0800 (PST)
Date: Sat, 6 Jan 2001 17:26:01 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Georg Wittig <Georg.Wittig@gmd.de>
cc: fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
In-Reply-To: <20010105150416.A14030@twister.gmd.de>
Message-ID: <Pine.GSO.4.10.10101061717220.19501-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2620

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Georg,

A couple of things here.  First, the format if the netacl netperm entry
should be something like....

netacl-ssh: permit-hosts xxx.xxx.xxx.* -exec /usr/sbin/plug-gw ssh

I think you were getting the failure from netacl since it didn't see the
permit-hosts entry in the netacl line.

Next - then I think the netperm-entry for the plug-gw line (assuming you
are running version 2.1) should be....

ssh:        port ssh * -plug-to 11.22.33.44 -port ssh

Plug-gw now looks for the name of the service on the executing line and
look up that name for it's parameters.  This allows you to have different
parameters based on the type of plug.  Very handy if you want different
timeout values.

Now - before you go and implement everything - plug-gw can run in daemon
mode.  It has all of the checking required to limit by source host the
same as netacl.  Not sure what netacl brings to the picture - other than
additional complications in your rulesets.

ted keller


On Fri, 5 Jan 2001, Georg Wittig wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi,
> 
> I need some help to get ssh proxied to the internal net via plug-gw. I
> searched the list archives and tried my setup according to the article
> 	http://marc.theaimsgroup.com/?l=fwtk-users&m=95544510922458&w=2
> by Michel Bardiaux. But alas, this doesn't work for me. My firewall
> machine is running RedHat-6.2.
> 
> Here's my current setup:
> 
> [/etc/services]
> ssh             22/tcp                          # SSH Remote Login Protocol
> 
> [ps axww | grep ssh]
> 27055 tty1     S      0:00 /path/to/netacl -daemon 22 ssh
> (No, I'm not running inetd, so I started netacl manually.)
> 
> [netperm-table]
> netacl-ssh:     permit hosts * -exec /path/to/plug-gw ssh
> plug-gw:        port ssh * -plug-to 11.22.33.44 -port ssh
> 
> 
> When I try an inbound ssh connection, the connection is closed
> immediately. In /var/log/messages I just see the line
> 
> 	netacl[27080]: deny host=55.66.77.88s service=ssh
> 
> Why's that? Doesn't the "netacl-ssh" line in my netperm-table *allow*
> that connection? What did I do wrong?
> 
> Thanks for your help,
>       Georg
> 
> 
> -- 
> Georg Wittig, GMD				Georg.Wittig@gmd.de
> - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
> Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
> Macht Sie den um Gang mit dem Juice nett auch nicht leichter.
> 


From owner-fwtk-users@ex.tis.com Sun Jan  7 15:22 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA13925
	Sun, 7 Jan 2001 15:22:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA24363;
	Sun, 7 Jan 2001 12:22:23 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 7 Jan 2001 10:45:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA22374
	for fwtk-users-outgoing; Sun, 7 Jan 2001 10:45:48 -0800 (PST)
Date: Sun, 7 Jan 2001 19:44:17 +0100 (CET)
To: fwtk-users@lists.nai.com
Subject: content filter for http, ftp and mail
Message-ID: <Pine.LNX.3.96.1010107184924.2615A-100000@mars.private.de>
MIME-Version: 1.0
From: Frank Neuber <frank.neuber@gmx.de>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1429

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi fwtk-users,
I have no experience with fwtk but I am looking for an firewall that can 
do content filtering on e-mail and http under linux.

I have to set up a firewall with ip-filter, virus scanning and free
configurable content filtering. AFAIK ip-filter and and virus scanning is
not the problem ... But I can't find a solution for my content filtering
problem. The content filter should provide some features:
1. Blocking html-requests with "junk" in the url (I think that can I do
with a http-Proxy ?)
2. Blocking html-pages with "junk" in the body (I have no idea how can I
do that) 
3. The same behavior for ftp and e-mail

With "junk" I mean a database with keywords. This database should be free
configurable.

Is is possible to do this with the tis-firewall? I did not found anything
of this topic in the tis-documentation.
Maybe it is possible to integrate a commecial product in the tis-firewall?
Has anyone an advice or experience in an software that can do content
filtering under Linux (commecial products also welcome).

thanks in advance  

Frank

-- 
     _/_/_/_/ _//   _/ Frank Neuber
    _/       _/_/  _/  frank.neuber@gmx.de (private)
   _/_/_/   _/ _/ _/
  _/       _/  _/_/    neuber@opensource-systemberatung.de
 _/       _/    // http://www.opensource-systemberatung.de


From owner-fwtk-users@ex.tis.com Sun Jan  7 21:17 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA14500
	Sun, 7 Jan 2001 21:16:59 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA01459;
	Sun, 7 Jan 2001 18:17:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 7 Jan 2001 16:11:18 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA28350
	for fwtk-users-outgoing; Sun, 7 Jan 2001 16:10:58 -0800 (PST)
Date: Sun, 7 Jan 2001 19:09:44 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Frank Neuber <frank.neuber@gmx.de>
cc: fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <Pine.LNX.3.96.1010107184924.2615A-100000@mars.private.de>
Message-ID: <Pine.GSO.4.10.10101071903290.2451-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2624

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Frank,

I haven't seen this type of filtering for http or ftp.  However, my
version of the smap/smapd probably has most of the filtering you would
need for mail.  I do content filtering on both the message header
(subject, from, to, and other fields) as well as content filtering on the
message body (first 10 lines).

It doesn't yet do anything with html code burried in the body.  Keep
thinking about getting around to it - but haven't done it yet.

The filters were orginally gotten from 

   Linkname: Oasel the Spam-Catcher's Report to the Nation              
        URL: http://www.cnx.com/stopspam.html

I've sense updated it with the many local entries we receive here.

Tend to block ~15,000+ messages weekly - out of 200,000 total e-mail
messages we recieve.  Doesn't hit everything - but sure eliminates the
15,000 junk ones we do get.

I can make this available to you if you are interested (standard
disclaimers apply).

ted keller



On Sun, 7 Jan 2001, Frank Neuber wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi fwtk-users,
> I have no experience with fwtk but I am looking for an firewall that can 
> do content filtering on e-mail and http under linux.
> 
> I have to set up a firewall with ip-filter, virus scanning and free
> configurable content filtering. AFAIK ip-filter and and virus scanning is
> not the problem ... But I can't find a solution for my content filtering
> problem. The content filter should provide some features:
> 1. Blocking html-requests with "junk" in the url (I think that can I do
> with a http-Proxy ?)
> 2. Blocking html-pages with "junk" in the body (I have no idea how can I
> do that) 
> 3. The same behavior for ftp and e-mail
> 
> With "junk" I mean a database with keywords. This database should be free
> configurable.
> 
> Is is possible to do this with the tis-firewall? I did not found anything
> of this topic in the tis-documentation.
> Maybe it is possible to integrate a commecial product in the tis-firewall?
> Has anyone an advice or experience in an software that can do content
> filtering under Linux (commecial products also welcome).
> 
> thanks in advance  
> 
> Frank
> 
> -- 
>      _/_/_/_/ _//   _/ Frank Neuber
>     _/       _/_/  _/  frank.neuber@gmx.de (private)
>    _/_/_/   _/ _/ _/
>   _/       _/  _/_/    neuber@opensource-systemberatung.de
>  _/       _/    // http://www.opensource-systemberatung.de
> 


From owner-fwtk-users@ex.tis.com Mon Jan  8 06:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA15777
	Mon, 8 Jan 2001 06:12:29 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA14128;
	Mon, 8 Jan 2001 03:12:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 01:36:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA11444
	for fwtk-users-outgoing; Mon, 8 Jan 2001 01:36:17 -0800 (PST)
Date: Mon, 8 Jan 2001 10:34:36 +0100 (CET)
To: Ted Keller <keller@bfg.com>
cc: fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <Pine.GSO.4.10.10101071903290.2451-100000@ns1.bfg.com>
Message-ID: <Pine.LNX.3.96.1010108102901.1142B-100000@mars.private.de>
MIME-Version: 1.0
From: Frank Neuber <frank.neuber@gmx.de>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 743

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Sun, 7 Jan 2001, Ted Keller wrote:

Hi Ted,
thanks for this quick response.
I will check out this link below.
> 
> The filters were orginally gotten from 
> 
>    Linkname: Oasel the Spam-Catcher's Report to the Nation              
>         URL: http://www.cnx.com/stopspam.html
> 
I'm also never seen content filtering for http and ftp, but it is a
customer wish ....

Frank

--
     _/_/_/_/ _//   _/ Frank Neuber
    _/       _/_/  _/  frank.neuber@gmx.de (private)
   _/_/_/   _/ _/ _/
  _/       _/  _/_/    neuber@opensource-systemberatung.de
 _/       _/    // http://www.opensource-systemberatung.de


From owner-fwtk-users@ex.tis.com Mon Jan  8 09:09 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA16389
	Mon, 8 Jan 2001 09:09:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA21152;
	Mon, 8 Jan 2001 06:10:09 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 04:46:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA16739
	for fwtk-users-outgoing; Mon, 8 Jan 2001 04:46:44 -0800 (PST)
Message-ID: <XFMail.20010106013159.zoli@deltav.hu>
X-Mailer: XFMail 1.4.6-3 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <200101051523.KAA02929@fw-nyc-02.proexam.org>
Date: Sat, 06 Jan 2001 01:31:59 -0000 (GMT)
Reply-To: zoli@deltav.hu
From: Hanko Zoltan <zoli@deltav.hu>
To: fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1367

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On 05-Jan-2001 Charles Robinson wrote:
Hi All,
 > 1. Have you tried using the ssh-gw from the toolkit?
I have the same problem. I tried to do it earlier, but I couldn't. Because it is
a patch for ssh 1.x, isn't it?

In this case, have anybody a patched ssh source/binary for redhat 6.2? (I have
openssh at the moment.)
(Pls. send me URL, where I can download it.)

I read the ssh-gw doc.
I remember it support connection from inside to Internet.
If I'd like to connect from outside to a protected computer behind firewall, I
have to use plug-gw. But the only possible solution the one-one connection
(from outside to inside). The one-many isn't possible.
There is no real gw, like telnet-gw or ftp-gw.

Have anybody a working ssh-gw example? What I have to install? What are the
right config file settings? I'd like to ssh from outside to one or more inside
host. (I have a public ip addres on fw. The computers behind fw have only
internal ip address.)
(I'm using ip masqurading from inside to outside, so I haven't got problem with
ssh, at the moment. But is it safe?

Thanks in advance!


Zoli
----------------------------------
E-Mail: Zoltan Hanko <zoli@deltav.hu>
This message was sent by XFMail
----------------------------------


From owner-fwtk-users@ex.tis.com Mon Jan  8 09:10 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA16393
	Mon, 8 Jan 2001 09:10:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA21162;
	Mon, 8 Jan 2001 06:10:19 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 04:59:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA17114
	for fwtk-users-outgoing; Mon, 8 Jan 2001 04:59:23 -0800 (PST)
Date: Mon, 8 Jan 2001 21:01:51 +0800 (WST)
From: Laurence Moore <lmoore@starwon.com.au>
X-Sender: lmoore@Merlin
To: Frank Neuber <frank.neuber@gmx.de>
cc: Ted Keller <keller@bfg.com>, fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <Pine.LNX.3.96.1010108102901.1142B-100000@mars.private.de>
Message-ID: <Pine.GSO.4.21.0101082100460.21757-100000@Merlin>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1102

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Check out Trends Interscan Viruswall.

There is a version for Linux

Here is the URL - http://www.antivirus.com

Cheers,

Larry.

On Mon, 8 Jan 2001, Frank Neuber wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> On Sun, 7 Jan 2001, Ted Keller wrote:
> 
> Hi Ted,
> thanks for this quick response.
> I will check out this link below.
> > 
> > The filters were orginally gotten from 
> > 
> >    Linkname: Oasel the Spam-Catcher's Report to the Nation              
> >         URL: http://www.cnx.com/stopspam.html
> > 
> I'm also never seen content filtering for http and ftp, but it is a
> customer wish ....
> 
> Frank
> 
> --
>      _/_/_/_/ _//   _/ Frank Neuber
>     _/       _/_/  _/  frank.neuber@gmx.de (private)
>    _/_/_/   _/ _/ _/
>   _/       _/  _/_/    neuber@opensource-systemberatung.de
>  _/       _/    // http://www.opensource-systemberatung.de
> 
> 
> 


From owner-fwtk-users@ex.tis.com Mon Jan  8 09:38 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA16472
	Mon, 8 Jan 2001 09:38:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA23593;
	Mon, 8 Jan 2001 06:39:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 05:26:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA18246
	for fwtk-users-outgoing; Mon, 8 Jan 2001 05:26:38 -0800 (PST)
Date: Mon, 8 Jan 2001 14:24:26 +0100 (CET)
To: Jonathan Wilson <jwilson@western-reflections.com>
cc: fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <1.5.4.32.20010108121304.00b5df20@aix2.western-reserve.com>
Message-ID: <Pine.LNX.3.96.1010108134355.8539B-100000@mars.private.de>
MIME-Version: 1.0
From: Frank Neuber <frank.neuber@gmx.de>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1356

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, 8 Jan 2001, Jonathan Wilson wrote:

Hi Jonathan,
thanks for your mail ...

> Well, if you are willing to do the homework you can run Squid on your
> firewall instead of the fwtk http proxies. This opens you up for a
> world of security problems if you're not careful... but I think that
Yes I will :-)

> it can be done if you _are_ careful. Squid can do all kinds of
> filtering of http access. We're using it to prevent users from surfing
> porn sites, connecting to napster, listening to broadcast music, and
> other bandwidth-sucking wastes of time.
AFAIK napster and broadcast music using different ports then port 80
(http). There is no problem in blocking these ports using ipchais under
linux.
Blocking url's can be done with e.g. WebFilter, httpf or junkbuster

What I want to do is checking the content on html-pages (and e-mail and
ftp) for indecent words. 

I think scanning viruses for mail, http and ftp could be done with 
the VirusWall from TrendMicro.

regards
Frank 

-- 
     _/_/_/_/ _//   _/ Frank Neuber
    _/       _/_/  _/  frank.neuber@gmx.de (private)
   _/_/_/   _/ _/ _/
  _/       _/  _/_/    neuber@opensource-systemberatung.de
 _/       _/    // http://www.opensource-systemberatung.de


From owner-fwtk-users@ex.tis.com Mon Jan  8 10:36 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA16654
	Mon, 8 Jan 2001 10:36:34 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA00576;
	Mon, 8 Jan 2001 07:36:47 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 06:16:06 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA21658
	for fwtk-users-outgoing; Mon, 8 Jan 2001 06:15:44 -0800 (PST)
Date: Mon, 8 Jan 2001 15:14:58 +0100
From: Georg Wittig <Georg.Wittig@gmd.de>
To: Ted Keller <keller@bfg.com>
Cc: Georg Wittig <Georg.Wittig@gmd.de>, fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
Message-ID: <20010108151458.A22771@twister.gmd.de>
References: <20010105150416.A14030@twister.gmd.de> <Pine.GSO.4.10.10101061717220.19501-100000@ns1.bfg.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <Pine.GSO.4.10.10101061717220.19501-100000@ns1.bfg.com>; from keller@bfg.com on Sat, Jan 06, 2001 at 05:26:01PM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2117

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Ted Keller wrote:


> A couple of things here.  First, the format if the netacl netperm entry
> should be something like....
> 
> netacl-ssh: permit-hosts xxx.xxx.xxx.* -exec /usr/sbin/plug-gw ssh


Ahh, thanks to point out my typo. I should have typed "permit-hosts"
instead of "permit hosts". Well, now the "deny host=" message has
gone! yaba daba doo.


> I think you were getting the failure from netacl since it didn't see the
> permit-hosts entry in the netacl line.
> 
> Next - then I think the netperm-entry for the plug-gw line (assuming you
> are running version 2.1) should be....
> 
> ssh:        port ssh * -plug-to 11.22.33.44 -port ssh


Alas, that doesn't help me. The symptom remains: On machine A I type
"ssh gateway". Then the connection is terminated immediately without
an error message appearing on A. In the syslog of the gateway I now
see
	netacl[31408]: permit host=A service=ssh execute=/path/to/plug-gw

- nothing else, even if I include an additional netperm-table line
"ssh: permit-service ssh".


> Now - before you go and implement everything - plug-gw can run in daemon
> mode.  It has all of the checking required to limit by source host the
> same as netacl.  Not sure what netacl brings to the picture - other than
> additional complications in your rulesets.


This doesn't work for me. If I kill the netacl process and start
	/path/to/plug-gw -daemon 22 ssh
then the symptom remains: On machine A I type "ssh gateway". Then the
connection is terminated immediately without an error message
appearing on A. In the syslog of the gateway I now see - nothing!
(Currently I prefer the netacl way: netacl at least drops a line into
syslog, even if that ain't gonna help me. :-)

Anyone knows what's going on?


-- 
Georg Wittig, GMD				Georg.Wittig@gmd.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
Macht Sie den um Gang mit dem Juice nett auch nicht leichter.

From owner-fwtk-users@ex.tis.com Mon Jan  8 10:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA16723
	Mon, 8 Jan 2001 10:54:07 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA02409;
	Mon, 8 Jan 2001 07:54:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 06:42:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA23808
	for fwtk-users-outgoing; Mon, 8 Jan 2001 06:41:48 -0800 (PST)
Date: Mon, 8 Jan 2001 15:16:58 +0100 (CET)
To: Laurence Moore <lmoore@starwon.com.au>
cc: fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <Pine.GSO.4.21.0101082100460.21757-100000@Merlin>
Message-ID: <Pine.LNX.3.96.1010108150402.8755B-100000@mars.private.de>
MIME-Version: 1.0
From: Frank Neuber <frank.neuber@gmx.de>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1009

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, 8 Jan 2001, Laurence Moore wrote:

Hi Laurence,
yesterday evening I tested the 30 day trail-version of the 
Trends Interscan Viruswall.
I think this is the virusscanner I want :-)
There is also a content checker for e-mail "eManager" as an plugin for the 
Interscan Viruswall. Unfortunately not for Linux. The supportcenter of
germany said:
 "the eManager is not planned in the near future for linux"

.... :-(

> Check out Trends Interscan Viruswall.
> 
> There is a version for Linux
> 
> Here is the URL - http://www.antivirus.com
> 

If anybody has an advice for content filtering about my subject, please
let me know.

Cheers,

Frank

--
     _/_/_/_/ _//   _/ Frank Neuber
    _/       _/_/  _/  frank.neuber@gmx.de (private)
   _/_/_/   _/ _/ _/
  _/       _/  _/_/    neuber@opensource-systemberatung.de
 _/       _/    // http://www.opensource-systemberatung.de


From owner-fwtk-users@ex.tis.com Mon Jan  8 12:26 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA17045
	Mon, 8 Jan 2001 12:25:29 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA13404;
	Mon, 8 Jan 2001 09:26:09 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 08:00:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA03038
	for fwtk-users-outgoing; Mon, 8 Jan 2001 08:00:07 -0800 (PST)
Date: Mon, 8 Jan 2001 17:23:13 +0200
From: Berend De Schouwer <bds@jhb.ucs.co.za>
To: Georg Wittig <Georg.Wittig@gmd.de>
Cc: Ted Keller <keller@bfg.com>, Georg Wittig <Georg.Wittig@gmd.de>,
        fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
Message-ID: <20010108172313.A13232@bds.ucs.co.za>
Reply-To: bds@jhb.ucs.co.za
References: <20010105150416.A14030@twister.gmd.de> <Pine.GSO.4.10.10101061717220.19501-100000@ns1.bfg.com> <20010108151458.A22771@twister.gmd.de>
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
In-Reply-To: <20010108151458.A22771@twister.gmd.de>; from Georg.Wittig@gmd.de on Mon, Jan 08, 2001 at 16:14:58 +0200
X-Mailer: Balsa 1.0.1
Lines: 78
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 2870

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


On Mon, 08 Jan 2001 16:14:58 Georg Wittig wrote:
 > [To be removed from this list send the message "unsubscribe fwtk-users"
 > in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Ted Keller wrote:
 > 
 > 
 > > A couple of things here.  First, the format if the netacl netperm entry
 > > should be something like....
 > > 
 > > netacl-ssh: permit-hosts xxx.xxx.xxx.* -exec /usr/sbin/plug-gw ssh
 > 
 > 
 > Ahh, thanks to point out my typo. I should have typed "permit-hosts"
 > instead of "permit hosts". Well, now the "deny host=" message has
 > gone! yaba daba doo.
 > 
 > 
 > > I think you were getting the failure from netacl since it didn't see
 > the
 > > permit-hosts entry in the netacl line.
 > > 
 > > Next - then I think the netperm-entry for the plug-gw line (assuming
 > you
 > > are running version 2.1) should be....
 > > 
 > > ssh:        port ssh * -plug-to 11.22.33.44 -port ssh
 > 
 > 
 > Alas, that doesn't help me. The symptom remains: On machine A I type
 > "ssh gateway". Then the connection is terminated immediately without
 > an error message appearing on A. In the syslog of the gateway I now
 > see
 > 	netacl[31408]: permit host=A service=ssh execute=/path/to/plug-gw
 > 
 > - nothing else, even if I include an additional netperm-table line
 > "ssh: permit-service ssh".

If you do a 'netstat -a' on the proxy, do you see any /attempts/
to connect to the far side.  Does the client send more than just
the SYN packet?  Can you do a network dump to find out if it sends
an ICMP response?

 > > Now - before you go and implement everything - plug-gw can run in
 > daemon
 > > mode.  It has all of the checking required to limit by source host the
 > > same as netacl.  Not sure what netacl brings to the picture - other
 > than
 > > additional complications in your rulesets.
 > 
 > 
 > This doesn't work for me. If I kill the netacl process and start
 > 	/path/to/plug-gw -daemon 22 ssh
 > then the symptom remains: On machine A I type "ssh gateway". Then the
 > connection is terminated immediately without an error message
 > appearing on A. In the syslog of the gateway I now see - nothing!
 > (Currently I prefer the netacl way: netacl at least drops a line into
 > syslog, even if that ain't gonna help me. :-)
 > 
 > Anyone knows what's going on?

What does ssh -v spit out?

 > -- 
 > Georg Wittig, GMD				Georg.Wittig@gmd.de
 > - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
 > Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
 > Macht Sie den um Gang mit dem Juice nett auch nicht leichter.
 > 

Kind regards,				  
Berend                                  

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Berend De Schouwer, +27-11-712-1435, UCS



From owner-fwtk-users@ex.tis.com Mon Jan  8 13:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA17358
	Mon, 8 Jan 2001 13:59:36 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA24113;
	Mon, 8 Jan 2001 11:00:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 09:38:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA14663
	for fwtk-users-outgoing; Mon, 8 Jan 2001 09:38:05 -0800 (PST)
Date: Tue, 9 Jan 2001 01:41:29 +0800 (WST)
From: Laurence Moore <lmoore@starwon.com.au>
X-Sender: lmoore@Merlin
To: Frank Neuber <frank.neuber@gmx.de>
cc: fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <Pine.LNX.3.96.1010108150402.8755B-100000@mars.private.de>
Message-ID: <Pine.GSO.4.21.0101090128390.21757-200000@Merlin>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-1483920592-978975689=:21757"
Content-Length: 8243

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.
  Send mail to mime@docserver.cac.washington.edu for more info.

---559023410-1483920592-978975689=:21757
Content-Type: TEXT/PLAIN; charset=US-ASCII

Hmmm,

There was a product on their site that does smtp, http & ftp filtering
whilst also having the virus scanner for scanning files.

I'll have to dig out my eval. CD from Trend Micro and have a look.

I have attached the readme from the Linux section of the evaluation CD.

As you can see from the listing files in this directory certainly suggest 
ftp, http and smtp scanners however you will need to install isbase
before you can use the listener daemons.

-r-xr-xr-x  1 root  wheel     4117 Nov  2  1999 Readme.txt
-r-xr-xr-x  1 root  wheel  1151138 Nov  2  1999 isadm.tz
-r-xr-xr-x  1 root  wheel  2143939 Nov  2  1999 isbase.tz
-r-xr-xr-x  1 root  wheel   156484 Nov  2  1999 isftp.evl
-r-xr-xr-x  1 root  wheel   155409 Nov  2  1999 isftp.tz
-r-xr-xr-x  1 root  wheel   193413 Nov  2  1999 ishttp.evl
-r-xr-xr-x  1 root  wheel   191475 Nov  2  1999 ishttp.tz
-r-xr-xr-x  1 root  wheel    90847 Nov  2  1999 isinst
-r-xr-xr-x  1 root  wheel   185396 Nov  2  1999 issmtp.evl
-r-xr-xr-x  1 root  wheel   182818 Nov  2  1999 issmtp.tz
-r-xr-xr-x  1 root  wheel   222513 Nov  2  1999 istvcs.tz
-r-xr-xr-x  1 root  wheel     6119 Nov  2  1999 license.txt

I have moved away from Linux to OpenBSD. I have been searching for at
least a suitable Virus and E-Mail scanner and I am presently playing with
AvMailGate and AntiVir from http://www.hbedv.com


Cheers,

Larry.


On Mon, 8 Jan 2001, Frank Neuber wrote:

> yesterday evening I tested the 30 day trail-version of the 
> Trends Interscan Viruswall.
> I think this is the virusscanner I want :-)
> There is also a content checker for e-mail "eManager" as an plugin for the 
> Interscan Viruswall. Unfortunately not for Linux. The supportcenter of
> germany said:
>  "the eManager is not planned in the near future for linux"
> 


---559023410-1483920592-978975689=:21757
Content-Type: TEXT/PLAIN; charset=X-UNKNOWN; name="Readme.txt"
Content-Transfer-Encoding: BASE64
Content-ID: <Pine.GSO.4.21.0101090141290.21757@Merlin>
Content-Description: 
Content-Disposition: attachment; filename="Readme.txt"

fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+
fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn4NDQogICAgICAgICAgICAg
ICAgICAgIEludGVyU2NhbiBWaXJ1c1dhbGwgMy4wMSBmb3IgTGludXgNDQp+
fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+
fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fn5+fg0NCiAgICAgICAgICAgICAg
ICAoYykgQ29weXJpZ2h0IFRyZW5kIE1pY3JvIEluYy4sIDE5OTctOQ0NCg0N
Cg0NCiAgICAgICAgICAgICAgICBJTkRFWA0NCiAgICAgICAgICAgICAgID09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQ0N
CiAgICAgICAgICAgICAgICAxLiAgSW50cm9kdWN0aW9uIGFuZCBPdmVydmll
dw0NCiAgICAgICAgICAgICAgICAyLiAgU3lzdGVtIFJlcXVpcmVtZW50cyAN
DQogICAgICAgICAgICAgICAgMy4gIEluc3RhbGxhdGlvbiBOb3Rlcw0NCgkJ
NC4gIEFib3V0IFRyZW5kIE1pY3JvIEluYy4NDQogICAgICAgICAgICAgICAg
NS4gIENvbnRhY3QgSW5mb3JtYXRpb24NDQogICAgICAgICAgICAgICA9PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0NDQoN
DQoNDQoxLiBJbnRyb2R1Y3Rpb24gYW5kIE92ZXJ2aWV3DQ0KPT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PQ0NClRyZW5kIEludGVyU2NhbiBWaXJ1
c1dhbGwgKHIpIGlzIGEgc3VpdGUgb2YgYW50aXZpcnVzIHByb2dyYW1zIHRo
YXQNDQp3b3JrIGF0IHRoZSBJbnRlcm5ldCBnYXRld2F5IHRvIGRldGVjdCBh
bmQgY2xlYW4gdmlydXMtaW5mZWN0ZWQNDQpmaWxlcyBiZWZvcmUgdGhleSBj
YW4gZW50ZXIgeW91ciBjb3Jwb3JhdGUgbmV0d29yay4gSXQgaXMgYXZhaWxh
YmxlDQ0KZm9yIGJvdGggdGhlIFNvbGFyaXMsIEhQLVVYLCBhbmQgTGludXgg
cGxhdGZvcm1zLg0NCpUgRS1tYWlsIFZpcnVzV2FsbCBtb25pdG9ycyBhbGwg
aW5ib3VuZCBhbmQgb3V0Ym91bmQgZW1haWwNDQptZXNzYWdlcyBmb3Igdmly
dXNlcywgaW5jbHVkaW5nIG1hY3JvIHZpcnVzZXMuIEUtbWFpbA0NClZpcnVz
V2FsbCBjYW4gYWxzbyBzdXBwb3J0IGFudGktcmVsYXkuDQ0KlSBXZWIgVmly
dXNXYWxsIG1vbml0b3JzIGFsbCBIVFRQIHRyYWZmaWMgYW5kIGNoZWNrcyBm
b3INDQp2aXJ1c2VzLCBtYWxpY2lvdXMgSmF2YSAmIEFjdGl2ZVggYXBwbGV0
cy4gDQ0KlSBGVFAgVmlydXNXYWxsIHByb3RlY3RzIGFnYWluc3QgdmlydXNl
cyBlbnRlcmluZyB5b3VyIGNvcnBvcmF0ZQ0NCm5ldHdvcmsgdGhyb3VnaCBG
VFAgZmlsZSB0cmFuc2ZlcnMuIE9yLCBpdCBjYW4gZXhjbHVzaXZlbHkNDQpw
cm90ZWN0IGEgZ2l2ZW4gc2VydmVyLg0NCg0NCg0NCjIuIFN5c3RlbSBSZXF1
aXJlbWVudHMNDQo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09DQ0K
SW5zdGFsbCBJbnRlclNjYW4gVmlydXNXYWxsIDMuMDEgZm9yIExpbnV4IG9u
IGEgSW50ZWwtYmFzZWQgbWFjaGluZSBydW5uaW5nDQ0KdGhlIFJlZCBIYXQg
Ni4wIGRpc3RyaWJ1dGlvbiBvZiBMaW51eC4NDQoNDQpPdGhlciByZXF1aXJl
bWVudHM6DQ0KICAgbyBBIFBlbnRpdW0gSUkgMzUwIG9yIGZhc3RlciBwcm9j
ZXNzb3INDQogICBvIDI1NiBNQiBSQU0NDQogICBvIDIgR0Igb2YgZnJlZSBk
aXNrIHNwYWNlDQ0KICAgbyBBIG1vbml0b3Igd2l0aCA4MDB4NjAwIG9yIGhp
Z2hlciByZXNvbHV0aW9uDQ0KICAgbyBJbnRlcm5ldCBFeHBsb3JlciB2ZXIu
IDMuMDIgb3IgbGF0ZXIsIE5ldHNjYXBlIHZlci4gNC4wNCBvciBsYXRlcg0N
Cg0NCldpdGggdGhpcyBjb25maWd1cmF0aW9uLCB3ZSBoYXZlIHRlc3RlZCB0
aGUgc29mdHdhcmUgdG8gaGFuZGxlIGFwcHJveGltYXRlbHkNDQoyLDcwMCBl
LW1haWwgbWVzc2FnZXMvaG91ciB3aXRoIGFuIGF2ZXJhZ2UgbG9hZCBvZiA0
LjguICBUaGUgbWVzc2FnZSBtaXgNDQp3YXM6DQ0KDQ0KNDAlIG1lc3NhZ2Vz
IHdpdGggbm8gYXR0YWNobWVudCAtIH42MjcgYnl0ZXMgaW4gc2l6ZQ0NCjQw
JSBtZXNzYWdlcyB3aXRoIHdpdGggYXR0YWNobWVudCB+MzJLIGluIHNpemUN
DQoyMCUgbWVzc2FnZXMgd2l0aCB3aXRoIGF0dGFjaG1lbnQgfjI2N0sgaW4g
c2l6ZQ0NCg0NCldlIGRvIG5vdCByZWNvbW1lbmQgcnVubmluZyBJbnRlclNj
YW4gVmlydXNXYWxsIGF0IGEgaGlnaGVyIGxvYWQgYXZlcmFnZQ0NCnRoYW4g
NS4yLiAgSXQgaXMgcmVjb21tZW5kZWQgdGhhdCB5b3UgdXBncmFkZSB5b3Vy
IGhhcmR3YXJlIGNvbmZpZ3VyYXRpb24NDQppZiBuZWNlc3NhcnkuICBZb3Ug
c3lzdGVtIHRocm91Z2hwdXQgd2lsbCBhbHNvIHZhcnkgZGVwZW5kaW5nIG9u
IHlvdXINDQptZXNzYWdlIG1peC4NDQoNDQoNDQozLiBBYm91dCBUcmVuZCBN
aWNybyBJbmMuDQ0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0N
DQpUcmVuZCBNaWNybyBpcyB0aGUgbGVhZGluZyBkZXZlbG9wZXIgb2Ygc2Vy
dmVyLWJhc2VkIHZpcnVzIHByb3RlY3Rpb24gZm9yIA0NCmhpZ2gtcGVyZm9y
bWFuY2UgY29ycG9yYXRlIG5ldHdvcmtzLiBTY2FuTWFpbCBpcyBwYXJ0IG9m
IFRyZW5kJ3MgaW50ZWdyYXRlZCANDQpnYXRld2F5LXRvLWRlc2t0b3AgZW50
ZXJwcmlzZS13aWRlIHNvbHV0aW9uLiBUcmVuZCBNaWNybydzIHZpcnVzIHBy
b3RlY3Rpb24gDQ0KdGVjaG5vbG9neSBpcyB1c2VkIGJ5IEludGVsLCBOb3Zl
bGwsIE5ldHNjYXBlLCBTdW4gTWljcm9zeXN0ZW1zLCBDb250cm9sIERhdGEg
DQ0KU3lzdGVtcywgU0NPLCBhbmQgV29ybGRUYWxrIGFzIGEga2V5IHBhcnQg
b2YgdGhlaXIgc2VydmVyIHNlY3VyaXR5IHNvbHV0aW9ucy4NDQoNDQo0LiBS
dW5uaW5nIEluc3RhbGxhdGlvbiBzY3JpcHQNDQo9PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PQ0NClRvIGluc3RhbGwgSW50ZXJTY2FuLCBydW4g
dGhlIGluc3RhbGxhdGlvbiBzY3JpcHQgYnkgdHlwaW5nICIuL2lzaW5zdCIN
DQoNDQoNDQo1LiBDb250YWN0IEluZm9ybWF0aW9uDQ0KPT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT0NDQoNDQogICAgICAgICAgICAgICAgICAg
ICAgICAgIEUtbWFpbDogdHJlbmRAdHJlbmRtaWNyby5jb20NDQogICAgICAg
ICAgICAgICAgICAgICAgICAgIEUtbWFpbDogc2FsZXNAdHJlbmRtaWNyby5j
b20NDQogICAgICAgICAgICAgICAgICAgICAgICAgIFdlYjogICAgd3d3LmFu
dGl2aXJ1cy5jb20NDQogDQ0KICAgICAgICAgICAgICAgICAgICAgICAgICBU
cmVuZCBNaWNybyBJbmNvcnBvcmF0ZWQNDQogICAgICAgICAgICAgICAgICAg
ICAgICAgIFN1aXRlIDQwMCwgMTAxMDEgRGUgQW56YSBCdmxkLiANDQogICAg
ICAgICAgICAgICAgICAgICAgICAgIEN1cGVydGlubywgQ0EgOTUwMTQNDQoN
DQogICAgICAgICAgICAgICAgICAgICAgICAgIFRvbGwgZnJlZTogICAgIDgw
MC0yMjgtNTY1MQ0NCiAgICAgICAgICAgICAgICAgICAgICAgICAgVm9pY2U6
ICAgICAgICAgNDA4LTI1Ny0xNTAwDQ0KICAgICAgICAgICAgICAgICAgICAg
ICAgICBGYXg6OiAgICAgICAgICA0MDgtMjU3LTIwMDMNDQogDQ0KICAgICAg
ICAgICAgICAgIFZpc2l0IHd3dy5hbnRpdmlydXMuY29tIHRvIGRvd25sb2Fk
IGV2YWx1YXRpb24gDQ0KICAgICAgICAgICAgICAgIGNvcGllcyBvZiBUcmVu
ZCdzICJUb3RhbCBTb2x1dGlvbiIgdmlydXMgcHJvdGVjdGlvbiANDQogICAg
ICAgICAgICAgICAgcHJvZHVjdHMuDQ0KDQ0KICAgICAgICAgICAgICAgIENv
cHlyaWdodCAxOTk3LTk5LCBUcmVuZCBNaWNybyBJbmNvcnBvcmF0ZWQuDQ0K
ICAgICAgICAgICAgICAgIFNjYW5NYWlsIGlzIGEgdHJhZGVtYXJrIG9mIFRy
ZW5kIE1pY3JvIEluY29ycG9yYXRlZC4gDQ0KICAgICAgICAgICAgICAgIEFs
bCBvdGhlciBtYXJrcyBhcmUgdGhlIHRyYWRlbWFya3Mgb3IgcmVnaXN0ZXJl
ZCANDQogICAgICAgICAgICAgICAgdHJhZGVtYXJrcyBvZiB0aGVpciByZXNw
ZWN0aXZlIGNvbXBhbmllcy4NDQoNDQoNDQoNDQo=
---559023410-1483920592-978975689=:21757--

From owner-fwtk-users@ex.tis.com Mon Jan  8 15:07 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA17693
	Mon, 8 Jan 2001 15:07:36 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA02477;
	Mon, 8 Jan 2001 12:07:57 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 10:43:06 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA22086
	for fwtk-users-outgoing; Mon, 8 Jan 2001 10:42:44 -0800 (PST)
Date: Tue, 9 Jan 2001 02:42:51 +0800 (WST)
From: Laurence Moore <lmoore@starwon.com.au>
X-Sender: lmoore@Merlin
To: Frank Neuber <frank.neuber@gmx.de>
cc: fwtk-users@lists.nai.com
Subject: Re: content filter for http, ftp and mail
In-Reply-To: <Pine.LNX.3.96.1010108150402.8755B-100000@mars.private.de>
Message-ID: <Pine.GSO.4.21.0101090239420.21757-100000@Merlin>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 519

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

As far as scanning of http is concerned, if it for offensive, pornographic
etc type content then you could look at

SquidGuard: http://www.squidguard.org  (I think)

If you are wanting to detect malicious objects within the web document
beit Java, Active-X then you would need to be looking at a commercial
scanner such as Trends InterScan VirusWall (per previous e-mail).

Cheers,

Larry


From owner-fwtk-users@ex.tis.com Mon Jan  8 23:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA19222
	Mon, 8 Jan 2001 23:05:33 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA13858;
	Mon, 8 Jan 2001 20:06:08 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 17:53:06 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA06567
	for fwtk-users-outgoing; Mon, 8 Jan 2001 17:52:55 -0800 (PST)
From: auther_bin@263.net
MIME-Version: 1.0
Message-Id: <3A592B94.27685@mta5>
Date: Mon, 8 Jan 2001 10:53:08 +0800 (CST)
To: fwtk-users@tis.com
Subject: About spam mail
X-Priority: 3
X-Originating-IP: [202.102.161.195]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 763

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  use smap to encapsulation sendmail, but many many spam mails went to our email server, and I modifyed the sendmail.cf, in which change an item like this:

O PrivacyOptions=authwarnings # orignal
O PrivacyOptions=authwarnings, noexpn, novrfy # Now I used

but when I telnet the firewall port 25, the command "expn" & "vrfy" is still active! and How can I deal with this problem? Ted.

_____________________________________________
Ê×¶¼ÔÚÏß--ÖÐ¹úÈËµÄÍøÉÏ¼ÒÔ° http://www.263.net
@263.netÖÐ¹ú×î´óµÄÔÚÏßÓÊ¾Ö http://freemail.263.net
ÖÐ¹úÈËµÄÔÚÏß¹ºÎïÀÖÔ°¡ª¡ª263ÉÌ³Ç http://shopping.263.net
ÍøÉÏÁôÑ§×ÉÑ¯-ÖÐ¹ú½ÌÓý·þÎñÍø http://edu.263.net/ 

From owner-fwtk-users@ex.tis.com Mon Jan  8 23:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA19465
	Mon, 8 Jan 2001 23:59:38 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA16648;
	Mon, 8 Jan 2001 21:00:24 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 8 Jan 2001 19:40:03 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA12484
	for fwtk-users-outgoing; Mon, 8 Jan 2001 19:39:42 -0800 (PST)
Date: Mon, 8 Jan 2001 22:38:51 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: auther_bin@263.net
cc: fwtk-users@tis.com
Subject: Re: About spam mail
In-Reply-To: <3A592B94.27685@mta5>
Message-ID: <Pine.GSO.4.10.10101082237210.20808-100000@ns1.bfg.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from QUOTED-PRINTABLE to 8bit by relay2.nai.com id TAA12466
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=X-UNKNOWN
Content-Length: 1318

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

smap has a set of built in functions which include support for expn and
vrfy.  However, they simply echo the email address entered - and no real
lookups against the system occur.  Therefore - it provides no useful
information.

Sendmail is never contacted for these functions.  That's why your sendmail
modifications had no effect.

ted keller


On Mon, 8 Jan 2001 auther_bin@263.net wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
>   use smap to encapsulation sendmail, but many many spam mails went to our email server, and I modifyed the sendmail.cf, in which change an item like this:
> 
> O PrivacyOptions=authwarnings # orignal
> O PrivacyOptions=authwarnings, noexpn, novrfy # Now I used
> 
> but when I telnet the firewall port 25, the command "expn" & "vrfy" is still active! and How can I deal with this problem? Ted.
> 
> _____________________________________________
> Ê×¶¼ÔÚÏß--ÖÐ¹úÈËµÄÍøÉÏ¼ÒÔ° http://www.263.net
> @263.netÖÐ¹ú×î´óµÄÔÚÏßÓÊ¾Ö http://freemail.263.net
> ÖÐ¹úÈËµÄÔÚÏß¹ºÎïÀÖÔ°¡ª¡ª263ÉÌ³Ç http://shopping.263.net
> ÍøÉÏÁôÑ§×ÉÑ¯-ÖÐ¹ú½ÌÓý·þÎñÍø http://edu.263.net/ 
> 


From owner-fwtk-users@ex.tis.com Tue Jan  9 04:58 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA20268
	Tue, 9 Jan 2001 04:57:43 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA26536;
	Tue, 9 Jan 2001 01:58:29 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 00:31:36 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA22971
	for fwtk-users-outgoing; Tue, 9 Jan 2001 00:31:15 -0800 (PST)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <3A5ADA33.833A5377@radio.hundert6.de>
Date: Tue, 09 Jan 2001 09:30:27 +0000
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.2-STABLE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: auther_bin@263.net, "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: About spam mail
References: <3A592B94.27685@mta5>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1229

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

>   use smap to encapsulation sendmail, but many many spam mails went to our email server, and I modifyed the sendmail.cf, in which change an item like this:
> 
> O PrivacyOptions=authwarnings # orignal
> O PrivacyOptions=authwarnings, noexpn, novrfy # Now I used
> 
> but when I telnet the firewall port 25, the command "expn" & "vrfy" is still active! and How can I deal with this problem? Ted.

As you were already told, twiddling the sendmail config won't
help, since smap's the external wrapper. Above that, EXPN and
VRFY have no direct effect on spamming. They're there to verify
whether a certain address exists and which user may be behind it.
This can be used to find out valid user names, which is half way
for a successful attack. 

Spamming is caused by letting people use your mail host as a
relay. Unfortunately, smap does this by default. You'll have to
patch it to stop this behaviour. Get the Yao patch from fwtk.org
and read the comments in the source to find out what to do about
it. 

Cheers, Jan


-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Tue Jan  9 09:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA21211
	Tue, 9 Jan 2001 09:34:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA07080;
	Tue, 9 Jan 2001 06:34:14 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 05:05:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA02356
	for fwtk-users-outgoing; Tue, 9 Jan 2001 05:04:58 -0800 (PST)
Date: Tue, 9 Jan 2001 16:28:02 +0530 (IST)
From: seema khanna <seema@hub.nic.in>
X-Sender: seema@hub
To: fwtk-users@ex.tis.com
Subject: HI DESPERATE HELP NEEDED
Message-ID: <Pine.GSO.3.96.1010109162659.9973A-100000@hub>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 270

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


how do I stop mails with a blank from:<>, I don't want them to reach my
server..

pls do help..will be really grateful

regards,
seema






From owner-fwtk-users@ex.tis.com Tue Jan  9 10:41 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA21584
	Tue, 9 Jan 2001 10:40:59 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA13004;
	Tue, 9 Jan 2001 07:41:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 06:21:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA06066
	for fwtk-users-outgoing; Tue, 9 Jan 2001 06:21:45 -0800 (PST)
Date: Tue, 9 Jan 2001 15:21:03 +0100
From: Georg Wittig <Georg.Wittig@gmd.de>
To: Georg Wittig <Georg.Wittig@gmd.de>
Cc: fwtk-users@tis.com
Subject: Re: plug-gw + ssh  config question
Message-ID: <20010109152103.A17167@twister.gmd.de>
References: <20010105150416.A14030@twister.gmd.de>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <20010105150416.A14030@twister.gmd.de>; from Georg.Wittig@gmd.de on Fri, Jan 05, 2001 at 03:04:16PM +0100
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1096

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

My problem is solved in the meantime. Thanks to all who helped me. I
had made 2 errors: First, I had made a typo in my netperm-table
("permit hosts" instead of "permit-hosts"). Second, I found I had used
a hand-edited plug-gw; as soon as I replaced it by plug-gw of the
official version 2.1, everything worked fine.

Blush. Sorry for all the fuss.

For those who are interested in the final configuration, here's my
setup:

[/etc/services]
ssh             22/tcp                          # SSH Remote Login Protocol

[ps axww | grep ssh]
27055 tty1     S      0:00 /path/to/plug-gw -daemon ssh ssh
(I'm not running inetd, so I started plug-gw manually.)

[netperm-table]
ssh:	port ssh * -plug-to 11.22.33.44 -port ssh



-- 
Georg Wittig, GMD				Georg.Wittig@gmd.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Du hast keine Spracherkennung installiert? Doch Komma aber Mai Stenz
Macht Sie den um Gang mit dem Juice nett auch nicht leichter.

From owner-fwtk-users@ex.tis.com Tue Jan  9 10:41 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA21583
	Tue, 9 Jan 2001 10:40:59 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA13008;
	Tue, 9 Jan 2001 07:41:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 06:18:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA05777
	for fwtk-users-outgoing; Tue, 9 Jan 2001 06:18:28 -0800 (PST)
Subject: ftp-gw and tn-gw
To: fwtk-users@ex.tis.com
X-Mailer: Lotus Notes Release 5.0a (Intl) 4 May 1999
Message-ID: <OF27A05C4D.783EFF6D-ON802569CF.004DBFC9@eu.csc.com>
From: "Stuart Wilson" <swilso39@csc.com>
Date: Tue, 9 Jan 2001 14:16:26 +0000
MIME-Version: 1.0
X-MIMETrack: Serialize by Router on UK-FBR10/UK/CSC(Release 5.0.4a |July 24, 2000) at 09/01/2001
 02:16:19 PM,
	Itemize by SMTP Server on DOMRELAY/UK-MDSRELAY(Release 5.0.4a |July 24, 2000) at
 09/01/2001 02:16:18 PM,
	Serialize by Router on DOMRELAY/UK-MDSRELAY(Release 5.0.4a |July 24, 2000) at
 09/01/2001 02:16:33 PM,
	Serialize complete at 09/01/2001 02:16:33 PM
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 419

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

Some of my users are receiving a "Connection closed by foreign host" error
when trying to connect to my ftp/telnet proxy. All of the correct rules
have been entered in the netperm-table. It is only happening to a small
number of users.

Does anyone know what to do?



Stuart Wilson.


From owner-fwtk-users@ex.tis.com Tue Jan  9 11:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA21891
	Tue, 9 Jan 2001 11:33:39 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA18351;
	Tue, 9 Jan 2001 08:33:38 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 07:16:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA10506
	for fwtk-users-outgoing; Tue, 9 Jan 2001 07:15:48 -0800 (PST)
Date: Tue, 9 Jan 2001 10:13:59 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: seema khanna <seema@hub.nic.in>
cc: fwtk-users@ex.tis.com
Subject: Re: HI DESPERATE HELP NEEDED
In-Reply-To: <Pine.GSO.3.96.1010109162659.9973A-100000@hub>
Message-ID: <Pine.GSO.4.10.10101090928410.4144-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 990

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Seema,

Normally, mails with a envelope from line indicate a remote mailer-daemon
talking to you - often regarding non-deliverable messages.  If you block
these, you tend to be non-rfc-821 compliant - and your users will not be
able to received non-deliverable responses.

Some sites, however, have implemented smap changes to prevent <> type
mailerdaemon messages.

I suspect you want to do this to eliminate spam type messages.  There may
be other approaches to this other than violating rfc specifications.

tek


On Tue, 9 Jan 2001, seema khanna wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
> how do I stop mails with a blank from:<>, I don't want them to reach my
> server..
> 
> pls do help..will be really grateful
> 
> regards,
> seema
> 
> 
> 
> 
> 


From owner-fwtk-users@ex.tis.com Tue Jan  9 13:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA22193
	Tue, 9 Jan 2001 13:08:19 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA00236;
	Tue, 9 Jan 2001 10:08:23 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 08:46:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA19799
	for fwtk-users-outgoing; Tue, 9 Jan 2001 08:45:53 -0800 (PST)
Date: Tue, 9 Jan 2001 11:43:33 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Stuart Wilson <swilso39@csc.com>
cc: fwtk-users@ex.tis.com
Subject: Re: ftp-gw and tn-gw
In-Reply-To: <OF27A05C4D.783EFF6D-ON802569CF.004DBFC9@eu.csc.com>
Message-ID: <Pine.GSO.4.10.10101091142540.4144-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 782

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Stuart,

Check out your logs and see if you have any "deny" messages from the tn-gw
or ftp-gw proxies.  May be something as small as a typo....


ted keller


On Tue, 9 Jan 2001, Stuart Wilson wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi,
> 
> Some of my users are receiving a "Connection closed by foreign host" error
> when trying to connect to my ftp/telnet proxy. All of the correct rules
> have been entered in the netperm-table. It is only happening to a small
> number of users.
> 
> Does anyone know what to do?
> 
> 
> 
> Stuart Wilson.
> 


From owner-fwtk-users@ex.tis.com Tue Jan  9 13:23 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA22239
	Tue, 9 Jan 2001 13:23:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA02177;
	Tue, 9 Jan 2001 10:23:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 09:10:01 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA22469
	for fwtk-users-outgoing; Tue, 9 Jan 2001 09:09:50 -0800 (PST)
Message-ID: <3A5B4631.41767195@lclcan.com>
Date: Tue, 09 Jan 2001 12:11:13 -0500
From: Don <don@lclcan.com>
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: Patch request
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/html; charset=us-ascii
Content-Length: 300

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

<!doctype html public "-//w3c//dtd html 4.0 transitional//en">
<html>
Is the patch that resolved the problem connecting to www.boston.com posted
on the fwtk site?</html>


From owner-fwtk-users@ex.tis.com Tue Jan  9 14:22 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA22432
	Tue, 9 Jan 2001 14:22:52 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA08631;
	Tue, 9 Jan 2001 11:22:56 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 09:57:48 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA28557
	for fwtk-users-outgoing; Tue, 9 Jan 2001 09:57:26 -0800 (PST)
Message-ID: <XFMail.20010109175614.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.4 on Linux
X-Priority: 3 (Normal)
MIME-Version: 1.0
In-Reply-To: <3A5B4631.41767195@lclcan.com>
Date: Tue, 09 Jan 2001 17:56:14 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: Don <don@lclcan.com>
Subject: RE: Patch request
Cc: fwtk <fwtk-users@lists.nai.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="_=XFMail.1.4.4.Linux:20010109175614:18743=_"
Content-Length: 12815

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format
--_=XFMail.1.4.4.Linux:20010109175614:18743=_
Content-Type: text/plain; charset=iso-8859-1


No, I would really like someone to review it before it does. It's
quicker than me having to wait until it clears out of my memory and
then reviewing it myself.

Patch attached.

-tony

PS. Please don't send HTML email messages.


On 09-Jan-2001 Don wrote:
> [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> <!doctype html public "-//w3c//dtd html 4.0 transitional//en">
> <html>
> Is the patch that resolved the problem connecting to www.boston.com
> posted
> on the fwtk site?</html>

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
The farther you go, the less you know.
		-- Lao Tsu, "Tao Te Ching"

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

--_=XFMail.1.4.4.Linux:20010109175614:18743=_
Content-Disposition: attachment; filename="fwtk-broken-web.diff"
Content-Transfer-Encoding: base64
Content-Description: fwtk-broken-web.diff
Content-Type: application/octet-stream;
 name=fwtk-broken-web.diff; SizeOnDisk=8420

T25seSBpbiBmd3RrLmRpc3QvZnd0azogTWFrZWZpbGUuY29uZmlnCk9ubHkgaW4gZnd0ay5wYXRj
aGVkL2Z3dGsvaHR0cC1ndzogYXV0aC5jLnJlagpPbmx5IGluIGZ3dGsucGF0Y2hlZC9md3RrL2h0
dHAtZ3c6IGZ0cC5jLnJlagpkaWZmIC11ciBmd3RrLmRpc3QvZnd0ay9odHRwLWd3L2htYWluLmMg
Znd0ay5wYXRjaGVkL2Z3dGsvaHR0cC1ndy9obWFpbi5jCi0tLSBmd3RrLmRpc3QvZnd0ay9odHRw
LWd3L2htYWluLmMJV2VkIERlYyAyMCAxNDo1ODowNyAyMDAwCisrKyBmd3RrLnBhdGNoZWQvZnd0
ay9odHRwLWd3L2htYWluLmMJV2VkIERlYyAyMCAxNDo1MzoyOSAyMDAwCkBAIC05NDIsMjQgKzk0
MiwzNSBAQAogY2hhcgkqczsKIGludAluOwogewotCWNoYXIgKmJ1ZmY7CisJLyogQXR0ZW1wdCB0
byB3cml0ZSB0aGUgbWVzc2FnZSBpbiBvbmUgcGFja2V0CisJICogRmFpbGluZyB0aGF0LCB0cnkg
YW5kIG1ha2Ugc3VyZSBpdCBhbGwgZ2V0cyBzZW50CisgICAgICAgICAqIFRSRyAtIDIwMDAxMjIw
CisgICAgICAgICAqLworIAljaGFyICpidWZmLCAqYnVmZnB0cjsKIAlpbnQgcmV0dmFsOwotCi0J
LyogQXR0ZW1wdCB0byBzZW5kIG1lc3NhZ2UgaW4gb25lIHBhY2tldAotCSAqIFNvbWUgRlRQIHNl
cnZlcnMgZG9uJ3QgbGlrZSBzcGxpdCBtZXNzYWdlcwotCSAqIFRSRyAtIDIwMDAxMTE0Ci0JICov
Ci0JaWYgKCAoYnVmZiA9IG1hbGxvYyhuKzIpKSA9PSBOVUxMKSB7CisgCWludCBsZW5ndGg7Cisg
CisgCWlmICggKGJ1ZmYgPSBtYWxsb2MobisyKSkgPT0gTlVMTCkgewogCQlpZihuZXRfd3JpdGUo
ZmQscyxuKSAhPSBuKQogCQkJcmV0dXJuKDEpOwogCQlyZXR1cm4obmV0X3dyaXRlKGZkLCJcclxu
IiwyKSAhPSAyKTsKIAl9Ci0JbWVtY3B5KGJ1ZmYsIHMsIG4pOwotCWJ1ZmZbbl09J1xyJzsKLQli
dWZmW24rMV09J1xuJzsKLQlyZXR2YWwgPSBuZXRfd3JpdGUoZmQsYnVmZixuKzIpOwotCWZyZWUo
YnVmZik7Ci0JcmV0dXJuKHJldHZhbCk7CisgCW1lbWNweShidWZmLCBzLCBuKTsKKyAJYnVmZltu
XT0nXHInOworIAlidWZmW24rMV09J1xuJzsKKyAJbGVuZ3RoID0gbisyOworIAlidWZmcHRyID0g
YnVmZjsKKyAJd2hpbGUgKGxlbmd0aCA+IDApIHsKKyAJCXJldHZhbCA9IG5ldF93cml0ZShmZCxi
dWZmcHRyLGxlbmd0aCk7CisgCQlpZiAocmV0dmFsID4gMCkgeworIAkJCWxlbmd0aCAtPSByZXR2
YWw7CisgCQkJYnVmZnB0ciArPSByZXR2YWw7CisgCQl9IGVsc2UgeworIAkJCWJyZWFrOworIAkJ
fQorIAl9CisgCWZyZWUoYnVmZik7CisgCXJldHVybihyZXR2YWwpOwogfQogCiAKT25seSBpbiBm
d3RrLnBhdGNoZWQvZnd0ay9odHRwLWd3OiBobWFpbi5jLm9yaWcKT25seSBpbiBmd3RrLnBhdGNo
ZWQvZnd0ay9odHRwLWd3OiBobWFpbi5jLnJlagpkaWZmIC11ciBmd3RrLmRpc3QvZnd0ay9odHRw
LWd3L2h0dHAtZ3cuYyBmd3RrLnBhdGNoZWQvZnd0ay9odHRwLWd3L2h0dHAtZ3cuYwotLS0gZnd0
ay5kaXN0L2Z3dGsvaHR0cC1ndy9odHRwLWd3LmMJV2VkIERlYyAyMCAxNDo1ODowNyAyMDAwCisr
KyBmd3RrLnBhdGNoZWQvZnd0ay9odHRwLWd3L2h0dHAtZ3cuYwlXZWQgRGVjIDIwIDE2OjEzOjQ5
IDIwMDAKQEAgLTU2OCw3ICs1NjgsNyBAQAogCWlmKCAocmVtX3R5cGUgJiBUWVBFX0hUVFApICl7
CiAJCWludCBobGVuID0gMDsKIAkJaWYoIGh0dHBfcHJvdG9jb2xbMF0gIT0gJ1wwJyl7Ci0gCQkJ
Y29weV9odHRwX2hlYWRlcnMoIC0xLCBzb2NrZmQsIDAsICZobGVuLCBHX05PUEVSTSk7CisgCQkJ
Y29weV9odHRwX2hlYWRlcnMoIE5VTEwsIC0xLCBzb2NrZmQsIDAsICZobGVuLCBHX05PUEVSTSk7
CiAJCX0KIAl9CiAJaWYoIHJlbV90eXBlICYgVFlQRV9GVFApewpAQCAtMTE3OCw4ICsxMTc4LDcg
QEAKIAl9ZWxzZXsKIAkJc3ByaW50Zihnb19yZXF1ZXN0LCIlcyVzIiwgaHR0cF9tZXRob2QsIGJ1
Zik7CiAJfQotCWlmKCByZmQgIT0gLTEpc2F5KHJmZCwgZ29fcmVxdWVzdCk7Ci0KKyAgCiBmcm9t
aW50ZXJuYWw6CiAJaWYoIGh0dHBfcHJvdG9jb2xbMF0pewkvKiBXYXMgdGhlcmUgaHR0cCBwcm90
b2NvbCBpbmZvPyAqLwogCQlpbnQgaGxlbiA9IDA7CkBAIC0xMTg3LDcgKzExODYsNyBAQAogCiAJ
CWlmKCAocGVybWlzc2lvbnMgJiBHX1BMVVMpID09IDApCiAJCQlyZmQgPSAtMTsKLSAJCWlmKCBj
b3B5X2h0dHBfaGVhZGVycyhyZmQsIHNvY2tmZCwgKHJlbV90eXBlJlRZUEVfV1JJVEUpLCAmaGxl
biwgR19OT1BFUk0pICYmCisgCQlpZiggY29weV9odHRwX2hlYWRlcnMoZ29fcmVxdWVzdCwgcmZk
LCBzb2NrZmQsIChyZW1fdHlwZSZUWVBFX1dSSVRFKSwgJmhsZW4sIEdfTk9QRVJNKSAmJgogCQkJ
KHJlbV90eXBlJlRZUEVfV1JJVEUpKXsKIAkJCXJmZCA9IHJzYXZlZDsKIAkJCXRyYW5zX2h0bWxf
ZmlsZShyZmQsIHNvY2tmZCwgImh0dHAiLCBobGVuKTsKQEAgLTExOTgsMTIgKzExOTcsMTUgQEAK
IAkJCXJldHVybiAwOwogCQl9CiAJCXJmZCA9IHJzYXZlZDsKKwl9IGVsc2UgeworCQlpZiggcmZk
ICE9IC0xKQorCQkJc2F5KHJmZCwgZ29fcmVxdWVzdCk7CiAJfQotCisgICAgCiAvKiBHZXQgcG9z
c2libGUgcmVzcG9uc2UgbGluZSAobWF5YmUgYW4gb2xkIHNlcnZlcikqLwogCWlmKCBnZXRfaHR0
cF9yZXNwb25zZShzb2NrZmQsIHJmZCkpewogCi0JCWlmKCBjb3B5X2h0dHBfaGVhZGVycyhzb2Nr
ZmQsIHJmZCwgMSwgTlVMTCwgbG9nZ2luZykpeworCQlpZiggY29weV9odHRwX2hlYWRlcnMoTlVM
TCwgc29ja2ZkLCByZmQsIDEsIE5VTEwsIGxvZ2dpbmcpKXsKIAkJCXRyYW5zX2h0bWxfZmlsZShz
b2NrZmQsIHJmZCwgImh0dHAiLCAtMSk7CiAJCX0KIAl9ZWxzZSBpZiggcmVtX3R5cGUgJiBUWVBF
X0hFQUQpewpAQCAtMTIzMCw3ICsxMjMyLDE2IEBACiAJcmV0dXJuIDA7CiB9CiAKLWludCBjb3B5
X2h0dHBfaGVhZGVycyhzb2NrZmQsIHJmZCxleHBlY3RfZGF0YSwgbHB0ciwgbG9nZ2luZykKKy8q
IGNvcHlfaHR0cF9oZWFkZXJzIGJ1ZmZlcnMgaXRzIG91dHB1dCBpbiBhbiBhdHRlbXB0IHRvIHdv
cmthcm91bmQKKyAqIHNvbWUgYnJva2VuIHdlYiBzZXJ2ZXJzIHRoYXQgY2FuJ3QgaGFuZGxlIHJl
Y2VpdmluZyByZXF1ZXN0cyB0aGF0IGFyZQorICogc3BsaXQgb3ZlciBtdWx0aXBsZSBwYWNrZXRz
CisgKiBUUkcgLSAyMDAwMTIyMAorICovCisKKyNkZWZpbmUgUkVRX0JVRkZfTEVOIChNQVhfVVJM
X0xFTioyKSAvKiBTRUNVUklUWTogTXVzdCBiZSBiaWdnZXIgdGhhbiBNQVhfVVJMX0xFTiAqLwor
CitpbnQgY29weV9odHRwX2hlYWRlcnMocmVxdWVzdCwgc29ja2ZkLCByZmQsZXhwZWN0X2RhdGEs
IGxwdHIsIGxvZ2dpbmcpCitjaGFyICpyZXF1ZXN0OwogaW50IHNvY2tmZCwgcmZkOwogaW50IGV4
cGVjdF9kYXRhLCAqbHB0ciwgbG9nZ2luZzsKIHsJaW50IGxlbiwgY250OwpAQCAtMTIzOCwxMiAr
MTI0OSwyNiBAQAogCWludCBuOwogCXN0YXRpYyBjaGFyIGNvbnRlbnRfbGVuWzgwXTsKIAlzdGF0
aWMgY2hhciBjb250ZW50X3R5cGVbNTEzXTsKKwlzdGF0aWMgY2hhciByZXF1ZXN0X2J1ZmZbUkVR
X0JVRkZfTEVOXTsKKwlpbnQgcmVxdWVzdF9idWZmX2xlbjsKIAlpbnQJdG1wWDsKIAljaGFyCSp0
bXBQOwogCisJcmVxdWVzdF9idWZmX2xlbiA9IDA7CisJaWYgKCByZXF1ZXN0ICYmIChzdHJsZW4o
cmVxdWVzdCkgPiBSRVFfQlVGRl9MRU4tMykpIHsKKwkJZ290byBicm9rZW47CisJfQorICAKKwlp
ZiAocmVxdWVzdCkgeworICAgICAgICAgICAgICAgIHJlcXVlc3RfYnVmZl9sZW4gPSBzdHJsZW4o
cmVxdWVzdCk7CisJCXN0cm5jcHkocmVxdWVzdF9idWZmLCByZXF1ZXN0LCByZXF1ZXN0X2J1ZmZf
bGVuKTsKKwkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xlbiwgIlxyXG4iLCAy
KTsKKwkJcmVxdWVzdF9idWZmX2xlbiArPSAyOworCX0KKyAgCiAJY29udGVudF9sZW5bMF0gPSAn
XDAnOwogCWNvbnRlbnRfdHlwZVswXT0gJ1wwJzsKLQorICAKIAlpZiggbHB0cikKIAkJKmxwdHIg
PSAwOwogCkBAIC0xMjYzLDcgKzEyODgsMTUgQEAKIAkJfWVsc2UgaWYoIGNoZWNrQnJvd3NlclR5
cGUgJiYKIAkJICAgICAgIXN0cm5jYXNlY21wKGdvX3JlcXVlc3QsICJ1c2VyLWFnZW50OiIsIDEx
KSApIHsKIAkJCWlmKCBzb2NrZmQgIT0gLTEpewotCQkJCSBzYXkoc29ja2ZkLCBnb19yZXF1ZXN0
KTsKKwkJCQlpZiAoKHN0cmxlbihnb19yZXF1ZXN0KStyZXF1ZXN0X2J1ZmZfbGVuKzIpID4gUkVR
X0JVRkZfTEVOLTEpIHsKKwkJCQkJcmVxdWVzdF9idWZmW3JlcXVlc3RfYnVmZl9sZW4tMl0gPSAn
XDAnOworCQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOworCQkJCQlyZXF1ZXN0X2J1ZmZf
bGVuID0gMDsKKwkJCQl9CisJCQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xl
biwgZ29fcmVxdWVzdCwgc3RybGVuKGdvX3JlcXVlc3QpKTsKKwkJCQlyZXF1ZXN0X2J1ZmZfbGVu
ICs9IHN0cmxlbihnb19yZXF1ZXN0KTsKKwkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1ZXN0
X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOworCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gMjsKIAkJCX0K
IAkJCWlmIChub2phdmEgPT0gMikKIAkJCSAgICBmb3IgKHRtcFg9MDsKQEAgLTEyODcsNyArMTMy
MCwxNSBAQAogCQkJY3B5c3RyKGNvbnRlbnRfdHlwZSwgZ29fcmVxdWVzdCwgNTEyKTsKIAkJCWNv
bnRlbnRfdHlwZVs1MTFdID0gJ1wwJzsKIAkJCWlmKCBzb2NrZmQgIT0gLTEpewotCQkJCSBzYXko
c29ja2ZkLCBnb19yZXF1ZXN0KTsKKwkJCQlpZiAoKHN0cmxlbihnb19yZXF1ZXN0KStyZXF1ZXN0
X2J1ZmZfbGVuKzIpID4gUkVRX0JVRkZfTEVOLTEpIHsKKwkJCQkJcmVxdWVzdF9idWZmW3JlcXVl
c3RfYnVmZl9sZW4tMl0gPSAnXDAnOworCQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOwor
CQkJCQlyZXF1ZXN0X2J1ZmZfbGVuID0gMDsKKwkJCQl9CisJCQkJc3RybmNweShyZXF1ZXN0X2J1
ZmYrcmVxdWVzdF9idWZmX2xlbiwgZ29fcmVxdWVzdCwgc3RybGVuKGdvX3JlcXVlc3QpKTsKKwkJ
CQlyZXF1ZXN0X2J1ZmZfbGVuICs9IHN0cmxlbihnb19yZXF1ZXN0KTsKKwkJCQlzdHJuY3B5KHJl
cXVlc3RfYnVmZityZXF1ZXN0X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOworCQkJCXJlcXVlc3RfYnVm
Zl9sZW4gKz0gMjsKIAkJCX0KIAkJCWlmKCBsb2dnaW5nICYgR19DT05UWVBFKXsKIAkJCQlzeXNs
b2coTExFViwiY29udGVudC10eXBlPSUuNTEycyIsICZnb19yZXF1ZXN0WzEzXSk7CkBAIC0xMjk5
LDExICsxMzQwLDI3IEBACiAJCQlpZiggZG9udF90b3VjaChwKSA9PSAwKXsKIAkJCQlzcHJpbnRm
KGVycmJ1ZiwgIkxvY2F0aW9uOiBodHRwOi8vJXM6JXUvJXMiLCBvdXJuYW1lLCBvdXJwb3J0LCBw
KTsKIAkJCQlpZiggc29ja2ZkICE9IC0xKXsKLQkJCQkJc2F5KHNvY2tmZCwgZXJyYnVmKSA7CisJ
CQkJCWlmICgoc3RybGVuKGVycmJ1ZikrcmVxdWVzdF9idWZmX2xlbisyKSA+IFJFUV9CVUZGX0xF
Ti0xKSB7CisJCQkJCQlyZXF1ZXN0X2J1ZmZbcmVxdWVzdF9idWZmX2xlbi0yXSA9ICdcMCc7CisJ
CQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOworCQkJCQkJcmVxdWVzdF9idWZmX2xlbiA9
IDA7CisJCQkJCX0KKwkJCQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xlbiwg
ZXJyYnVmLCBzdHJsZW4oZXJyYnVmKSk7CisJCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gc3RybGVu
KGVycmJ1Zik7CisJCQkJCXN0cm5jcHkocmVxdWVzdF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sICJc
clxuIiwgMik7CisJCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gMjsKIAkJCQl9CiAJCQl9ZWxzZXsK
IAkJCQlpZiggc29ja2ZkICE9IC0xKXsKLSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
CSBzYXkoc29ja2ZkLCBnb19yZXF1ZXN0KSA7CisJCQkJCWlmICgoc3RybGVuKGdvX3JlcXVlc3Qp
K3JlcXVlc3RfYnVmZl9sZW4rMikgPiBSRVFfQlVGRl9MRU4tMSkgeworCQkJCQkJcmVxdWVzdF9i
dWZmW3JlcXVlc3RfYnVmZl9sZW4tMl0gPSAnXDAnOworCQkJCQkJc2F5KHNvY2tmZCwgcmVxdWVz
dF9idWZmKTsKKwkJCQkJCXJlcXVlc3RfYnVmZl9sZW4gPSAwOworCQkJCQl9CisJCQkJCXN0cm5j
cHkocmVxdWVzdF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sIGdvX3JlcXVlc3QsIHN0cmxlbihnb19y
ZXF1ZXN0KSk7CisJCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gc3RybGVuKGdvX3JlcXVlc3QpOwor
CQkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1ZXN0X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOwor
CQkJCQlyZXF1ZXN0X2J1ZmZfbGVuICs9IDI7CiAJCQkJfQogCQkJfQogCQl9ZWxzZSBpZiggIXN0
cm5jYXNlY21wKGdvX3JlcXVlc3QsICJjb25uZWN0aW9uOiIsIDExKSl7CkBAIC0xMzEyLDcgKzEz
NjksMTUgQEAKIAkJCWNvbnRpbnVlOwogCQl9ZWxzZSB7CiAJCQlpZiggc29ja2ZkICE9IC0xKXsK
LSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHNheShzb2NrZmQsIGdvX3JlcXVlc3Qp
IDsKKwkJCQlpZiAoKHN0cmxlbihnb19yZXF1ZXN0KStyZXF1ZXN0X2J1ZmZfbGVuKzIpID4gUkVR
X0JVRkZfTEVOLTEpIHsKKwkJCQkJcmVxdWVzdF9idWZmW3JlcXVlc3RfYnVmZl9sZW4tMl0gPSAn
XDAnOworCQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOworCQkJCQlyZXF1ZXN0X2J1ZmZf
bGVuID0gMDsKKwkJCQl9CisJCQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xl
biwgZ29fcmVxdWVzdCwgc3RybGVuKGdvX3JlcXVlc3QpKTsKKwkJCQlyZXF1ZXN0X2J1ZmZfbGVu
ICs9IHN0cmxlbihnb19yZXF1ZXN0KTsKKwkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1ZXN0
X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOworCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gMjsKIAkJCX0K
IAkJfQogCX0KQEAgLTEzNDIsMTEgKzE0MDcsMjAgQEAKIC8qIG5vdCBhbiBodG1sIGZpbGU/IHNv
IGp1c3QgYmxvY2sgY29weSAqLwogCQlpZiggY29udGVudF9sZW5bMF0pewogCQkJaWYoIHNvY2tm
ZCAhPSAtMSl7Ci0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBzYXkoc29ja2ZkLGNv
bnRlbnRfbGVuKSA7CisJCQkJaWYgKChzdHJsZW4oY29udGVudF9sZW4pK3JlcXVlc3RfYnVmZl9s
ZW4rMikgPiBSRVFfQlVGRl9MRU4tMSkgeworCQkJCQlyZXF1ZXN0X2J1ZmZbcmVxdWVzdF9idWZm
X2xlbi0yXSA9ICdcMCc7CisJCQkJCXNheShzb2NrZmQsIHJlcXVlc3RfYnVmZik7CisJCQkJCXJl
cXVlc3RfYnVmZl9sZW4gPSAwOworCQkJCX0KKwkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1
ZXN0X2J1ZmZfbGVuLCBjb250ZW50X2xlbiwgc3RybGVuKGNvbnRlbnRfbGVuKSk7CisJCQkJcmVx
dWVzdF9idWZmX2xlbiArPSBzdHJsZW4oY29udGVudF9sZW4pOworCQkJCXN0cm5jcHkocmVxdWVz
dF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sICJcclxuIiwgMik7CisJCQkJcmVxdWVzdF9idWZmX2xl
biArPSAyOwogCQkJfQogCQl9CiAJCWlmKCBzb2NrZmQgIT0gLTEpewotICAgICAgICAgICAgICAg
ICAgICAgICAgIHNheShzb2NrZmQsIiIpIDsKKwkJCXJlcXVlc3RfYnVmZltyZXF1ZXN0X2J1ZmZf
bGVuXSA9ICdcMCc7CisJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOwogCQl9CiAKIAkJaWYo
ZXhwZWN0X2RhdGEgJiYgKHJlbV90eXBlICYgVFlQRV9IRUFEKT09MCl7CkBAIC0xMzg0LDExICsx
NDU4LDIwIEBACiBpc2h0bWw6CiAJaWYoIGxwdHIpewkvKiBpdHMgYSBQT1NUIHNvIG5lZWQgY29u
dGVudC1sZW5ndGg6ICovCiAJCWlmKGNvbnRlbnRfbGVuWzBdICYmIHNvY2tmZCAhPSAtMSl7Ci0J
CQkgc2F5KHNvY2tmZCwgY29udGVudF9sZW4pIDsKKwkJCQlpZiAoKHN0cmxlbihjb250ZW50X2xl
bikrcmVxdWVzdF9idWZmX2xlbisyKSA+IFJFUV9CVUZGX0xFTi0xKSB7CisJCQkJCXJlcXVlc3Rf
YnVmZltyZXF1ZXN0X2J1ZmZfbGVuLTJdID0gJ1wwJzsKKwkJCQkJc2F5KHNvY2tmZCwgcmVxdWVz
dF9idWZmKTsKKwkJCQkJcmVxdWVzdF9idWZmX2xlbiA9IDA7CisJCQkJfQorCQkJCXN0cm5jcHko
cmVxdWVzdF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sIGNvbnRlbnRfbGVuLCBzdHJsZW4oY29udGVu
dF9sZW4pKTsKKwkJCQlyZXF1ZXN0X2J1ZmZfbGVuICs9IHN0cmxlbihjb250ZW50X2xlbik7CisJ
CQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xlbiwgIlxyXG4iLCAyKTsKKwkJ
CQlyZXF1ZXN0X2J1ZmZfbGVuICs9IDI7CiAJCX0KIAl9CiAJaWYoIHNvY2tmZCAhPSAtMSl7Ci0J
CXNheShzb2NrZmQsIiIpIDsKKwkJcmVxdWVzdF9idWZmW3JlcXVlc3RfYnVmZl9sZW5dID0gJ1ww
JzsKKwkJc2F5KHNvY2tmZCwgcmVxdWVzdF9idWZmKTsKIAl9CiAJaWYoIHJlbV90eXBlICYgVFlQ
RV9IRUFEKXsKIAkJcmV0dXJuIDA7CS8qIGZsYWcgYXMgZG9uZSAqLwo=

--_=XFMail.1.4.4.Linux:20010109175614:18743=_--
End of MIME message

From owner-fwtk-users@ex.tis.com Tue Jan  9 16:57 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA23216
	Tue, 9 Jan 2001 16:57:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA01878;
	Tue, 9 Jan 2001 13:57:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 12:28:49 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA20768
	for fwtk-users-outgoing; Tue, 9 Jan 2001 12:28:38 -0800 (PST)
Message-Id: <200101091823.SAA15736@leotel.co.uk>
Date: Tue, 9 Jan 2001 18:23:32 +0000 (GMT)
From: Stuart Little <Stuart.Little@leotel.co.uk>
Reply-To: Stuart Little <Stuart.Little@leotel.co.uk>
To: fwtk-users@ex.tis.com
MIME-Version: 1.0
Content-MD5: ldYEuIlIGo3GUX8oEpDTyg==
X-Mailer: dtmail 1.2.1 CDE Version 1.2.1 SunOS 5.6 sun4m sparc 
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/plain; charset=us-ascii
Content-Length: 951

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,
   Don't know if the list is still active but...
   
   FWTK 2.1 on 1 4.1.3_U1 based machine. Been in use for some years and
   so I've left it alone. Just recently though I've been having problems
   getting to some sites, specifically www.perl.com. Turned http-gw logging
   on and I'm getting a network error:-
      Setting net_flags during read, -1, 4, 1
   virtually immediately I try to access the site.
   99% of all other sites are OK. I can ping www.perl.com from outside
   the firewall so routing would not a ppear to be a problem.
   
   Has anyone using the kit noticed similar problems?
   
   Cheers,
     Stuart
---
Onsite mailto:Stuart.Little@leotel.co.uk
Base   mailto:Stuart.Little@amberjack.demon.co.uk
Phone(onsite): +44-1438-220202   FAX(onsite): +44-1438-233777                              



From owner-fwtk-users@ex.tis.com Tue Jan  9 17:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA23237
	Tue, 9 Jan 2001 17:05:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA02757;
	Tue, 9 Jan 2001 14:06:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 9 Jan 2001 12:54:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA24559
	for fwtk-users-outgoing; Tue, 9 Jan 2001 12:54:40 -0800 (PST)
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Message-Id: <200101092048.MAA20045@noid.net>
X-Mini-Diatribe: To fix America:
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Date: Tue, 9 Jan 2001 12:48:34 -0800
From: Tor Perkins <979070108@noid.net>
To: fwtk-users@tis.com
Subject: ftp-pasv patch and remote port decodes (a patch)
Mail-Followup-To: fwtk-users@tis.com
References: <20010103143158.F20853@bds.ucs.co.za>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <20010103143158.F20853@bds.ucs.co.za>; from bds@jhb.ucs.co.za on Wed, Jan 03, 2001 at 02:31:58PM +0200
X-Operating-System: Linux 2.2.17pre19
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed; boundary="5/uDoXvLw7AC5HRs"
Content-Length: 2574

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


--5/uDoXvLw7AC5HRs
Content-Type: text/plain; charset=us-ascii


The problem:

   The original code for parsing an FTP servers PASV response was not
   sufficiently general, so sometimes the port decode would fail and
   the data connection could not happen.

     possible formats include (RFC 959 is ambiguous):

       227 Entering Passive Mode (h1,h2,h3,h4,p1,p2)    <-- most servers
       227 Entering Passive Mode (h1,h2,h3,h4,p1,p2).   <-- some servers
       227 =h1,h2,h3,h4,p1,p2                           <-- sez' D. J. Bernstein

Luis Fernando Barrera pointed this out to me and Berend De Schouwer
has even included a patch for it already.  This is the patch I made.
It tries to handle all of the cases listed above.

-- 
}    __o
}  _(\<._  Tor Perkins           Send me e-mail with subject "get
} (_)/ (_) 979071968@noidDoTnet  pgp key" for automatic response.

--5/uDoXvLw7AC5HRs
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment; filename="ftp_pasv.diff.2"

--- ./ftp-gw.c.org	Mon May 17 23:00:12 1999
+++ ./ftp-gw.c	Tue Nov 14 23:46:08 2000
@@ -2228,6 +2230,13 @@
  
  	x = getresp(rfd,buf,sizeof(buf),1);
  
+  /*
+   * possible formats include (RFC 959 is ambiguous):
+   *   227 Entering Passive Mode (h1,h2,h3,h4,p1,p2)    <-- most servers
+   *   227 Entering Passive Mode (h1,h2,h3,h4,p1,p2).   <-- some servers
+   *   227 =h1,h2,h3,h4,p1,p2                           <-- sez' D. J. Bernstein
+   */
+
  	if (x != 227)
  		return( ( sayn(0,buf,strlen(buf)) ? 1 : -1 ) );
  
@@ -2237,23 +2246,20 @@
  		return( ( sayn(0,nadr,sizeof(nadr)) ? 1 : -1 ) );
  	}
  
-	for(i=1;i<tokac;i++) {
-		if( tokav[i][0] == '(' ) {
-			x = strlen(tokav[i]);
-			if ( tokav[i][x-1] == ')' ) {
-				tokav[i][x-1] = 0;
-				(tokav[i])++;
-				break;
-			}
-		}
-	}
+  for( i = 1 ; i < tokac ; i++ ) {
+    if( strchr(tokav[i], ',') ) {
+      while ( tokav[i][0] && ( tokav[i][0] < '0' || tokav[i][0] > '9' ) )
+        (tokav[i])++;
+      x = strlen(tokav[i]);
+      while ( x > 10 && ( tokav[i][x-1] < '0' || tokav[i][x-1] > '9' ) ) x--;
+      if ( x > 10 ) {
+        tokav[i][x] = 0;
+        if( porttoaddr(tokav[i],&srvport) == 0 ) break;
+      }
+    }
+  }
  
  	if(i == tokac) {
-		sendsaved(0,500);
-		return( ( sayn(0,nadr,sizeof(nadr)) ? 1 : -1 ) );
-	}
-
-	if(porttoaddr(tokav[i],&srvport)) {
  		sendsaved(0,500);
  		return( ( sayn(0,nadr,sizeof(nadr)) ? 1 : -1 ) );
  	}

--5/uDoXvLw7AC5HRs--



From owner-fwtk-users@ex.tis.com Wed Jan 10 07:01 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA26303
	Wed, 10 Jan 2001 07:01:42 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA08420;
	Wed, 10 Jan 2001 04:01:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 10 Jan 2001 02:08:45 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA04696
	for fwtk-users-outgoing; Wed, 10 Jan 2001 02:08:14 -0800 (PST)
X-Authentication-Warning: stan.aipo.gov.au: anwsmh owned process doing -bs
Date: Wed, 10 Jan 2001 21:09:42 +1100 (EST)
From: Stanley Hopcroft <Stanley.Hopcroft@IPAustralia.Gov.AU>
X-Sender: anwsmh@stan.aipo.gov.au
To: Ted Keller <keller@bfg.com>
cc: Georg Wittig <Georg.Wittig@gmd.de>, fwtk-users@tis.com
Subject: Can't apply yao-patch.
In-Reply-To: <Pine.GSO.4.10.10101061717220.19501-100000@ns1.bfg.com>
Message-ID: <Pine.BSF.4.21.0101102055580.317-100000@stan.aipo.gov.au>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1992

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear Ladies and Gentlemen,

I am writing to ask your help applying the yao anti-spam patchs.

When I try and patch smap.c (either that from 2.0 or 2.1) the patch
program fails to recognise where it should start. Ignoring white space
doesn't help either.

hermes> patch < yao-smap.pch
Hmm...  Looks like a new-style context diff to me...
The text leading up to this was:
--------------------------
|*** smap.c.2.1  Fri May 22 13:31:00 1998
|--- smap.c      Tue Jun  9 14:21:39 1998
--------------------------
Patching file smap.c using Plan A...
patch: **** Overdue "---" at line 23--check line numbers at line 4
hermes> patch -F 3 < yao-smap.pch 
Hmm...  Looks like a new-style context diff to me...
The text leading up to this was:
--------------------------
|*** smap.c.2.1  Fri May 22 13:31:00 1998
|--- smap.c      Tue Jun  9 14:21:39 1998
--------------------------
Patching file smap.c using Plan A...
patch: **** Overdue "---" at line 23--check line numbers at line 4
hermes> 

I think that the original file (smap.c) is the correct version [1.22]

hermes> grep murphy smap.c
static  char    RcsId[] =
"$Header: /home/rmurphy/fwtk/fwtk/smap/RCS/smap.c,v 1.22 1998/01/13
22:56:06 rmurphy Exp $";
hermes> grep murphy yao-smap.pch 
  static        char    RcsId[] =
"$Header: /home/rmurphy/fwtk/fwtk/smap/RCS/smap.c,v 1.22 1998/01/13
 22:56:06 rmurphy Exp $";
  static        char    RcsId[] =
"$Header: /home/rmurphy/fwtk/fwtk/smap/RCS/smap.c,v 1.22 1998/01/13
 22:56:06 rmurphy Exp $";
hermes> 

The patch program has never failed me before. It's

hermes> patch -v
Patch version 2.1
hermes> uname -a
FreeBSD hermes.IPAustralia.gov.au 4.1-RELEASE FreeBSD 4.1-RELEASE
#0: Tue Oct 17 13:59:51 EST 2000
root@hermes.IPAustralia.gov.au:/usr/src/sys/compile/HERMES  i386
hermes> 

Thank you very much for your help,

Yours sincerely.

S Hopcroft

IP Australia





From owner-fwtk-users@ex.tis.com Wed Jan 10 07:01 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA26299
	Wed, 10 Jan 2001 07:01:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA08424;
	Wed, 10 Jan 2001 04:01:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 10 Jan 2001 01:52:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA04333
	for fwtk-users-outgoing; Wed, 10 Jan 2001 01:51:55 -0800 (PST)
Message-ID: <XFMail.20010110095116.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.4 on Linux
X-Priority: 3 (Normal)
MIME-Version: 1.0
In-Reply-To: <200101091823.SAA15736@leotel.co.uk>
Date: Wed, 10 Jan 2001 09:51:16 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: Stuart Little <Stuart.Little@leotel.co.uk>
Subject: RE: 
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="_=XFMail.1.4.4.Linux:20010110095116:9296=_"
Content-Length: 13784

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format
--_=XFMail.1.4.4.Linux:20010110095116:9296=_
Content-Type: text/plain; charset=iso-8859-1


www.perl.com is severely broken. Even though they are running apache
they seem to have screwed it up completely. Probably due to that
mod_perl thing they are running :-)

Apply the jumbo patch from www.fwtk.org and then apply the enclosed
patch over the top. You should satisfy yourself of the security
impact of the enclosed patch as it is quite new and comes with no
warranty, certificate of air worthiness, or anything that implies it
is fit for any purpose, explicit or implicit. 

-tony

(4.1.3_U1 - the best OS Sun ever made)

On 09-Jan-2001 Stuart Little wrote:
> [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi,
>    Don't know if the list is still active but...
>    
>    FWTK 2.1 on 1 4.1.3_U1 based machine. Been in use for some years
> and
>    so I've left it alone. Just recently though I've been having
> problems
>    getting to some sites, specifically www.perl.com. Turned http-gw
> logging
>    on and I'm getting a network error:-
>       Setting net_flags during read, -1, 4, 1
>    virtually immediately I try to access the site.
>    99% of all other sites are OK. I can ping www.perl.com from
> outside
>    the firewall so routing would not a ppear to be a problem.
>    
>    Has anyone using the kit noticed similar problems?
>    
>    Cheers,
>      Stuart
> ---
> Onsite mailto:Stuart.Little@leotel.co.uk
> Base   mailto:Stuart.Little@amberjack.demon.co.uk
> Phone(onsite): +44-1438-220202   FAX(onsite): +44-1438-233777      

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
If this fortune didn't exist, somebody would have invented it.

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

--_=XFMail.1.4.4.Linux:20010110095116:9296=_
Content-Disposition: attachment; filename="fwtk-broken-web.diff"
Content-Transfer-Encoding: base64
Content-Description: fwtk-broken-web.diff
Content-Type: application/octet-stream;
 name=fwtk-broken-web.diff; SizeOnDisk=8420

T25seSBpbiBmd3RrLmRpc3QvZnd0azogTWFrZWZpbGUuY29uZmlnCk9ubHkgaW4gZnd0ay5wYXRj
aGVkL2Z3dGsvaHR0cC1ndzogYXV0aC5jLnJlagpPbmx5IGluIGZ3dGsucGF0Y2hlZC9md3RrL2h0
dHAtZ3c6IGZ0cC5jLnJlagpkaWZmIC11ciBmd3RrLmRpc3QvZnd0ay9odHRwLWd3L2htYWluLmMg
Znd0ay5wYXRjaGVkL2Z3dGsvaHR0cC1ndy9obWFpbi5jCi0tLSBmd3RrLmRpc3QvZnd0ay9odHRw
LWd3L2htYWluLmMJV2VkIERlYyAyMCAxNDo1ODowNyAyMDAwCisrKyBmd3RrLnBhdGNoZWQvZnd0
ay9odHRwLWd3L2htYWluLmMJV2VkIERlYyAyMCAxNDo1MzoyOSAyMDAwCkBAIC05NDIsMjQgKzk0
MiwzNSBAQAogY2hhcgkqczsKIGludAluOwogewotCWNoYXIgKmJ1ZmY7CisJLyogQXR0ZW1wdCB0
byB3cml0ZSB0aGUgbWVzc2FnZSBpbiBvbmUgcGFja2V0CisJICogRmFpbGluZyB0aGF0LCB0cnkg
YW5kIG1ha2Ugc3VyZSBpdCBhbGwgZ2V0cyBzZW50CisgICAgICAgICAqIFRSRyAtIDIwMDAxMjIw
CisgICAgICAgICAqLworIAljaGFyICpidWZmLCAqYnVmZnB0cjsKIAlpbnQgcmV0dmFsOwotCi0J
LyogQXR0ZW1wdCB0byBzZW5kIG1lc3NhZ2UgaW4gb25lIHBhY2tldAotCSAqIFNvbWUgRlRQIHNl
cnZlcnMgZG9uJ3QgbGlrZSBzcGxpdCBtZXNzYWdlcwotCSAqIFRSRyAtIDIwMDAxMTE0Ci0JICov
Ci0JaWYgKCAoYnVmZiA9IG1hbGxvYyhuKzIpKSA9PSBOVUxMKSB7CisgCWludCBsZW5ndGg7Cisg
CisgCWlmICggKGJ1ZmYgPSBtYWxsb2MobisyKSkgPT0gTlVMTCkgewogCQlpZihuZXRfd3JpdGUo
ZmQscyxuKSAhPSBuKQogCQkJcmV0dXJuKDEpOwogCQlyZXR1cm4obmV0X3dyaXRlKGZkLCJcclxu
IiwyKSAhPSAyKTsKIAl9Ci0JbWVtY3B5KGJ1ZmYsIHMsIG4pOwotCWJ1ZmZbbl09J1xyJzsKLQli
dWZmW24rMV09J1xuJzsKLQlyZXR2YWwgPSBuZXRfd3JpdGUoZmQsYnVmZixuKzIpOwotCWZyZWUo
YnVmZik7Ci0JcmV0dXJuKHJldHZhbCk7CisgCW1lbWNweShidWZmLCBzLCBuKTsKKyAJYnVmZltu
XT0nXHInOworIAlidWZmW24rMV09J1xuJzsKKyAJbGVuZ3RoID0gbisyOworIAlidWZmcHRyID0g
YnVmZjsKKyAJd2hpbGUgKGxlbmd0aCA+IDApIHsKKyAJCXJldHZhbCA9IG5ldF93cml0ZShmZCxi
dWZmcHRyLGxlbmd0aCk7CisgCQlpZiAocmV0dmFsID4gMCkgeworIAkJCWxlbmd0aCAtPSByZXR2
YWw7CisgCQkJYnVmZnB0ciArPSByZXR2YWw7CisgCQl9IGVsc2UgeworIAkJCWJyZWFrOworIAkJ
fQorIAl9CisgCWZyZWUoYnVmZik7CisgCXJldHVybihyZXR2YWwpOwogfQogCiAKT25seSBpbiBm
d3RrLnBhdGNoZWQvZnd0ay9odHRwLWd3OiBobWFpbi5jLm9yaWcKT25seSBpbiBmd3RrLnBhdGNo
ZWQvZnd0ay9odHRwLWd3OiBobWFpbi5jLnJlagpkaWZmIC11ciBmd3RrLmRpc3QvZnd0ay9odHRw
LWd3L2h0dHAtZ3cuYyBmd3RrLnBhdGNoZWQvZnd0ay9odHRwLWd3L2h0dHAtZ3cuYwotLS0gZnd0
ay5kaXN0L2Z3dGsvaHR0cC1ndy9odHRwLWd3LmMJV2VkIERlYyAyMCAxNDo1ODowNyAyMDAwCisr
KyBmd3RrLnBhdGNoZWQvZnd0ay9odHRwLWd3L2h0dHAtZ3cuYwlXZWQgRGVjIDIwIDE2OjEzOjQ5
IDIwMDAKQEAgLTU2OCw3ICs1NjgsNyBAQAogCWlmKCAocmVtX3R5cGUgJiBUWVBFX0hUVFApICl7
CiAJCWludCBobGVuID0gMDsKIAkJaWYoIGh0dHBfcHJvdG9jb2xbMF0gIT0gJ1wwJyl7Ci0gCQkJ
Y29weV9odHRwX2hlYWRlcnMoIC0xLCBzb2NrZmQsIDAsICZobGVuLCBHX05PUEVSTSk7CisgCQkJ
Y29weV9odHRwX2hlYWRlcnMoIE5VTEwsIC0xLCBzb2NrZmQsIDAsICZobGVuLCBHX05PUEVSTSk7
CiAJCX0KIAl9CiAJaWYoIHJlbV90eXBlICYgVFlQRV9GVFApewpAQCAtMTE3OCw4ICsxMTc4LDcg
QEAKIAl9ZWxzZXsKIAkJc3ByaW50Zihnb19yZXF1ZXN0LCIlcyVzIiwgaHR0cF9tZXRob2QsIGJ1
Zik7CiAJfQotCWlmKCByZmQgIT0gLTEpc2F5KHJmZCwgZ29fcmVxdWVzdCk7Ci0KKyAgCiBmcm9t
aW50ZXJuYWw6CiAJaWYoIGh0dHBfcHJvdG9jb2xbMF0pewkvKiBXYXMgdGhlcmUgaHR0cCBwcm90
b2NvbCBpbmZvPyAqLwogCQlpbnQgaGxlbiA9IDA7CkBAIC0xMTg3LDcgKzExODYsNyBAQAogCiAJ
CWlmKCAocGVybWlzc2lvbnMgJiBHX1BMVVMpID09IDApCiAJCQlyZmQgPSAtMTsKLSAJCWlmKCBj
b3B5X2h0dHBfaGVhZGVycyhyZmQsIHNvY2tmZCwgKHJlbV90eXBlJlRZUEVfV1JJVEUpLCAmaGxl
biwgR19OT1BFUk0pICYmCisgCQlpZiggY29weV9odHRwX2hlYWRlcnMoZ29fcmVxdWVzdCwgcmZk
LCBzb2NrZmQsIChyZW1fdHlwZSZUWVBFX1dSSVRFKSwgJmhsZW4sIEdfTk9QRVJNKSAmJgogCQkJ
KHJlbV90eXBlJlRZUEVfV1JJVEUpKXsKIAkJCXJmZCA9IHJzYXZlZDsKIAkJCXRyYW5zX2h0bWxf
ZmlsZShyZmQsIHNvY2tmZCwgImh0dHAiLCBobGVuKTsKQEAgLTExOTgsMTIgKzExOTcsMTUgQEAK
IAkJCXJldHVybiAwOwogCQl9CiAJCXJmZCA9IHJzYXZlZDsKKwl9IGVsc2UgeworCQlpZiggcmZk
ICE9IC0xKQorCQkJc2F5KHJmZCwgZ29fcmVxdWVzdCk7CiAJfQotCisgICAgCiAvKiBHZXQgcG9z
c2libGUgcmVzcG9uc2UgbGluZSAobWF5YmUgYW4gb2xkIHNlcnZlcikqLwogCWlmKCBnZXRfaHR0
cF9yZXNwb25zZShzb2NrZmQsIHJmZCkpewogCi0JCWlmKCBjb3B5X2h0dHBfaGVhZGVycyhzb2Nr
ZmQsIHJmZCwgMSwgTlVMTCwgbG9nZ2luZykpeworCQlpZiggY29weV9odHRwX2hlYWRlcnMoTlVM
TCwgc29ja2ZkLCByZmQsIDEsIE5VTEwsIGxvZ2dpbmcpKXsKIAkJCXRyYW5zX2h0bWxfZmlsZShz
b2NrZmQsIHJmZCwgImh0dHAiLCAtMSk7CiAJCX0KIAl9ZWxzZSBpZiggcmVtX3R5cGUgJiBUWVBF
X0hFQUQpewpAQCAtMTIzMCw3ICsxMjMyLDE2IEBACiAJcmV0dXJuIDA7CiB9CiAKLWludCBjb3B5
X2h0dHBfaGVhZGVycyhzb2NrZmQsIHJmZCxleHBlY3RfZGF0YSwgbHB0ciwgbG9nZ2luZykKKy8q
IGNvcHlfaHR0cF9oZWFkZXJzIGJ1ZmZlcnMgaXRzIG91dHB1dCBpbiBhbiBhdHRlbXB0IHRvIHdv
cmthcm91bmQKKyAqIHNvbWUgYnJva2VuIHdlYiBzZXJ2ZXJzIHRoYXQgY2FuJ3QgaGFuZGxlIHJl
Y2VpdmluZyByZXF1ZXN0cyB0aGF0IGFyZQorICogc3BsaXQgb3ZlciBtdWx0aXBsZSBwYWNrZXRz
CisgKiBUUkcgLSAyMDAwMTIyMAorICovCisKKyNkZWZpbmUgUkVRX0JVRkZfTEVOIChNQVhfVVJM
X0xFTioyKSAvKiBTRUNVUklUWTogTXVzdCBiZSBiaWdnZXIgdGhhbiBNQVhfVVJMX0xFTiAqLwor
CitpbnQgY29weV9odHRwX2hlYWRlcnMocmVxdWVzdCwgc29ja2ZkLCByZmQsZXhwZWN0X2RhdGEs
IGxwdHIsIGxvZ2dpbmcpCitjaGFyICpyZXF1ZXN0OwogaW50IHNvY2tmZCwgcmZkOwogaW50IGV4
cGVjdF9kYXRhLCAqbHB0ciwgbG9nZ2luZzsKIHsJaW50IGxlbiwgY250OwpAQCAtMTIzOCwxMiAr
MTI0OSwyNiBAQAogCWludCBuOwogCXN0YXRpYyBjaGFyIGNvbnRlbnRfbGVuWzgwXTsKIAlzdGF0
aWMgY2hhciBjb250ZW50X3R5cGVbNTEzXTsKKwlzdGF0aWMgY2hhciByZXF1ZXN0X2J1ZmZbUkVR
X0JVRkZfTEVOXTsKKwlpbnQgcmVxdWVzdF9idWZmX2xlbjsKIAlpbnQJdG1wWDsKIAljaGFyCSp0
bXBQOwogCisJcmVxdWVzdF9idWZmX2xlbiA9IDA7CisJaWYgKCByZXF1ZXN0ICYmIChzdHJsZW4o
cmVxdWVzdCkgPiBSRVFfQlVGRl9MRU4tMykpIHsKKwkJZ290byBicm9rZW47CisJfQorICAKKwlp
ZiAocmVxdWVzdCkgeworICAgICAgICAgICAgICAgIHJlcXVlc3RfYnVmZl9sZW4gPSBzdHJsZW4o
cmVxdWVzdCk7CisJCXN0cm5jcHkocmVxdWVzdF9idWZmLCByZXF1ZXN0LCByZXF1ZXN0X2J1ZmZf
bGVuKTsKKwkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xlbiwgIlxyXG4iLCAy
KTsKKwkJcmVxdWVzdF9idWZmX2xlbiArPSAyOworCX0KKyAgCiAJY29udGVudF9sZW5bMF0gPSAn
XDAnOwogCWNvbnRlbnRfdHlwZVswXT0gJ1wwJzsKLQorICAKIAlpZiggbHB0cikKIAkJKmxwdHIg
PSAwOwogCkBAIC0xMjYzLDcgKzEyODgsMTUgQEAKIAkJfWVsc2UgaWYoIGNoZWNrQnJvd3NlclR5
cGUgJiYKIAkJICAgICAgIXN0cm5jYXNlY21wKGdvX3JlcXVlc3QsICJ1c2VyLWFnZW50OiIsIDEx
KSApIHsKIAkJCWlmKCBzb2NrZmQgIT0gLTEpewotCQkJCSBzYXkoc29ja2ZkLCBnb19yZXF1ZXN0
KTsKKwkJCQlpZiAoKHN0cmxlbihnb19yZXF1ZXN0KStyZXF1ZXN0X2J1ZmZfbGVuKzIpID4gUkVR
X0JVRkZfTEVOLTEpIHsKKwkJCQkJcmVxdWVzdF9idWZmW3JlcXVlc3RfYnVmZl9sZW4tMl0gPSAn
XDAnOworCQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOworCQkJCQlyZXF1ZXN0X2J1ZmZf
bGVuID0gMDsKKwkJCQl9CisJCQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xl
biwgZ29fcmVxdWVzdCwgc3RybGVuKGdvX3JlcXVlc3QpKTsKKwkJCQlyZXF1ZXN0X2J1ZmZfbGVu
ICs9IHN0cmxlbihnb19yZXF1ZXN0KTsKKwkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1ZXN0
X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOworCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gMjsKIAkJCX0K
IAkJCWlmIChub2phdmEgPT0gMikKIAkJCSAgICBmb3IgKHRtcFg9MDsKQEAgLTEyODcsNyArMTMy
MCwxNSBAQAogCQkJY3B5c3RyKGNvbnRlbnRfdHlwZSwgZ29fcmVxdWVzdCwgNTEyKTsKIAkJCWNv
bnRlbnRfdHlwZVs1MTFdID0gJ1wwJzsKIAkJCWlmKCBzb2NrZmQgIT0gLTEpewotCQkJCSBzYXko
c29ja2ZkLCBnb19yZXF1ZXN0KTsKKwkJCQlpZiAoKHN0cmxlbihnb19yZXF1ZXN0KStyZXF1ZXN0
X2J1ZmZfbGVuKzIpID4gUkVRX0JVRkZfTEVOLTEpIHsKKwkJCQkJcmVxdWVzdF9idWZmW3JlcXVl
c3RfYnVmZl9sZW4tMl0gPSAnXDAnOworCQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOwor
CQkJCQlyZXF1ZXN0X2J1ZmZfbGVuID0gMDsKKwkJCQl9CisJCQkJc3RybmNweShyZXF1ZXN0X2J1
ZmYrcmVxdWVzdF9idWZmX2xlbiwgZ29fcmVxdWVzdCwgc3RybGVuKGdvX3JlcXVlc3QpKTsKKwkJ
CQlyZXF1ZXN0X2J1ZmZfbGVuICs9IHN0cmxlbihnb19yZXF1ZXN0KTsKKwkJCQlzdHJuY3B5KHJl
cXVlc3RfYnVmZityZXF1ZXN0X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOworCQkJCXJlcXVlc3RfYnVm
Zl9sZW4gKz0gMjsKIAkJCX0KIAkJCWlmKCBsb2dnaW5nICYgR19DT05UWVBFKXsKIAkJCQlzeXNs
b2coTExFViwiY29udGVudC10eXBlPSUuNTEycyIsICZnb19yZXF1ZXN0WzEzXSk7CkBAIC0xMjk5
LDExICsxMzQwLDI3IEBACiAJCQlpZiggZG9udF90b3VjaChwKSA9PSAwKXsKIAkJCQlzcHJpbnRm
KGVycmJ1ZiwgIkxvY2F0aW9uOiBodHRwOi8vJXM6JXUvJXMiLCBvdXJuYW1lLCBvdXJwb3J0LCBw
KTsKIAkJCQlpZiggc29ja2ZkICE9IC0xKXsKLQkJCQkJc2F5KHNvY2tmZCwgZXJyYnVmKSA7CisJ
CQkJCWlmICgoc3RybGVuKGVycmJ1ZikrcmVxdWVzdF9idWZmX2xlbisyKSA+IFJFUV9CVUZGX0xF
Ti0xKSB7CisJCQkJCQlyZXF1ZXN0X2J1ZmZbcmVxdWVzdF9idWZmX2xlbi0yXSA9ICdcMCc7CisJ
CQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOworCQkJCQkJcmVxdWVzdF9idWZmX2xlbiA9
IDA7CisJCQkJCX0KKwkJCQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xlbiwg
ZXJyYnVmLCBzdHJsZW4oZXJyYnVmKSk7CisJCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gc3RybGVu
KGVycmJ1Zik7CisJCQkJCXN0cm5jcHkocmVxdWVzdF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sICJc
clxuIiwgMik7CisJCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gMjsKIAkJCQl9CiAJCQl9ZWxzZXsK
IAkJCQlpZiggc29ja2ZkICE9IC0xKXsKLSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
CSBzYXkoc29ja2ZkLCBnb19yZXF1ZXN0KSA7CisJCQkJCWlmICgoc3RybGVuKGdvX3JlcXVlc3Qp
K3JlcXVlc3RfYnVmZl9sZW4rMikgPiBSRVFfQlVGRl9MRU4tMSkgeworCQkJCQkJcmVxdWVzdF9i
dWZmW3JlcXVlc3RfYnVmZl9sZW4tMl0gPSAnXDAnOworCQkJCQkJc2F5KHNvY2tmZCwgcmVxdWVz
dF9idWZmKTsKKwkJCQkJCXJlcXVlc3RfYnVmZl9sZW4gPSAwOworCQkJCQl9CisJCQkJCXN0cm5j
cHkocmVxdWVzdF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sIGdvX3JlcXVlc3QsIHN0cmxlbihnb19y
ZXF1ZXN0KSk7CisJCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gc3RybGVuKGdvX3JlcXVlc3QpOwor
CQkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1ZXN0X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOwor
CQkJCQlyZXF1ZXN0X2J1ZmZfbGVuICs9IDI7CiAJCQkJfQogCQkJfQogCQl9ZWxzZSBpZiggIXN0
cm5jYXNlY21wKGdvX3JlcXVlc3QsICJjb25uZWN0aW9uOiIsIDExKSl7CkBAIC0xMzEyLDcgKzEz
NjksMTUgQEAKIAkJCWNvbnRpbnVlOwogCQl9ZWxzZSB7CiAJCQlpZiggc29ja2ZkICE9IC0xKXsK
LSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHNheShzb2NrZmQsIGdvX3JlcXVlc3Qp
IDsKKwkJCQlpZiAoKHN0cmxlbihnb19yZXF1ZXN0KStyZXF1ZXN0X2J1ZmZfbGVuKzIpID4gUkVR
X0JVRkZfTEVOLTEpIHsKKwkJCQkJcmVxdWVzdF9idWZmW3JlcXVlc3RfYnVmZl9sZW4tMl0gPSAn
XDAnOworCQkJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOworCQkJCQlyZXF1ZXN0X2J1ZmZf
bGVuID0gMDsKKwkJCQl9CisJCQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xl
biwgZ29fcmVxdWVzdCwgc3RybGVuKGdvX3JlcXVlc3QpKTsKKwkJCQlyZXF1ZXN0X2J1ZmZfbGVu
ICs9IHN0cmxlbihnb19yZXF1ZXN0KTsKKwkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1ZXN0
X2J1ZmZfbGVuLCAiXHJcbiIsIDIpOworCQkJCXJlcXVlc3RfYnVmZl9sZW4gKz0gMjsKIAkJCX0K
IAkJfQogCX0KQEAgLTEzNDIsMTEgKzE0MDcsMjAgQEAKIC8qIG5vdCBhbiBodG1sIGZpbGU/IHNv
IGp1c3QgYmxvY2sgY29weSAqLwogCQlpZiggY29udGVudF9sZW5bMF0pewogCQkJaWYoIHNvY2tm
ZCAhPSAtMSl7Ci0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBzYXkoc29ja2ZkLGNv
bnRlbnRfbGVuKSA7CisJCQkJaWYgKChzdHJsZW4oY29udGVudF9sZW4pK3JlcXVlc3RfYnVmZl9s
ZW4rMikgPiBSRVFfQlVGRl9MRU4tMSkgeworCQkJCQlyZXF1ZXN0X2J1ZmZbcmVxdWVzdF9idWZm
X2xlbi0yXSA9ICdcMCc7CisJCQkJCXNheShzb2NrZmQsIHJlcXVlc3RfYnVmZik7CisJCQkJCXJl
cXVlc3RfYnVmZl9sZW4gPSAwOworCQkJCX0KKwkJCQlzdHJuY3B5KHJlcXVlc3RfYnVmZityZXF1
ZXN0X2J1ZmZfbGVuLCBjb250ZW50X2xlbiwgc3RybGVuKGNvbnRlbnRfbGVuKSk7CisJCQkJcmVx
dWVzdF9idWZmX2xlbiArPSBzdHJsZW4oY29udGVudF9sZW4pOworCQkJCXN0cm5jcHkocmVxdWVz
dF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sICJcclxuIiwgMik7CisJCQkJcmVxdWVzdF9idWZmX2xl
biArPSAyOwogCQkJfQogCQl9CiAJCWlmKCBzb2NrZmQgIT0gLTEpewotICAgICAgICAgICAgICAg
ICAgICAgICAgIHNheShzb2NrZmQsIiIpIDsKKwkJCXJlcXVlc3RfYnVmZltyZXF1ZXN0X2J1ZmZf
bGVuXSA9ICdcMCc7CisJCQlzYXkoc29ja2ZkLCByZXF1ZXN0X2J1ZmYpOwogCQl9CiAKIAkJaWYo
ZXhwZWN0X2RhdGEgJiYgKHJlbV90eXBlICYgVFlQRV9IRUFEKT09MCl7CkBAIC0xMzg0LDExICsx
NDU4LDIwIEBACiBpc2h0bWw6CiAJaWYoIGxwdHIpewkvKiBpdHMgYSBQT1NUIHNvIG5lZWQgY29u
dGVudC1sZW5ndGg6ICovCiAJCWlmKGNvbnRlbnRfbGVuWzBdICYmIHNvY2tmZCAhPSAtMSl7Ci0J
CQkgc2F5KHNvY2tmZCwgY29udGVudF9sZW4pIDsKKwkJCQlpZiAoKHN0cmxlbihjb250ZW50X2xl
bikrcmVxdWVzdF9idWZmX2xlbisyKSA+IFJFUV9CVUZGX0xFTi0xKSB7CisJCQkJCXJlcXVlc3Rf
YnVmZltyZXF1ZXN0X2J1ZmZfbGVuLTJdID0gJ1wwJzsKKwkJCQkJc2F5KHNvY2tmZCwgcmVxdWVz
dF9idWZmKTsKKwkJCQkJcmVxdWVzdF9idWZmX2xlbiA9IDA7CisJCQkJfQorCQkJCXN0cm5jcHko
cmVxdWVzdF9idWZmK3JlcXVlc3RfYnVmZl9sZW4sIGNvbnRlbnRfbGVuLCBzdHJsZW4oY29udGVu
dF9sZW4pKTsKKwkJCQlyZXF1ZXN0X2J1ZmZfbGVuICs9IHN0cmxlbihjb250ZW50X2xlbik7CisJ
CQkJc3RybmNweShyZXF1ZXN0X2J1ZmYrcmVxdWVzdF9idWZmX2xlbiwgIlxyXG4iLCAyKTsKKwkJ
CQlyZXF1ZXN0X2J1ZmZfbGVuICs9IDI7CiAJCX0KIAl9CiAJaWYoIHNvY2tmZCAhPSAtMSl7Ci0J
CXNheShzb2NrZmQsIiIpIDsKKwkJcmVxdWVzdF9idWZmW3JlcXVlc3RfYnVmZl9sZW5dID0gJ1ww
JzsKKwkJc2F5KHNvY2tmZCwgcmVxdWVzdF9idWZmKTsKIAl9CiAJaWYoIHJlbV90eXBlICYgVFlQ
RV9IRUFEKXsKIAkJcmV0dXJuIDA7CS8qIGZsYWcgYXMgZG9uZSAqLwo=

--_=XFMail.1.4.4.Linux:20010110095116:9296=_--
End of MIME message

From owner-fwtk-users@ex.tis.com Wed Jan 10 09:07 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA26747
	Wed, 10 Jan 2001 09:07:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA13792;
	Wed, 10 Jan 2001 06:07:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 10 Jan 2001 04:47:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA09697
	for fwtk-users-outgoing; Wed, 10 Jan 2001 04:47:17 -0800 (PST)
Date: Wed, 10 Jan 2001 09:23:36 +0530 (IST)
From: seema khanna <seema@hub.nic.in>
X-Sender: seema@hub
To: Ted Keller <keller@bfg.com>
cc: fwtk-users@ex.tis.com
Subject: Re: HI DESPERATE HELP NEEDED
In-Reply-To: <Pine.GSO.4.10.10101090928410.4144-100000@ns1.bfg.com>
Message-ID: <Pine.GSO.3.96.1010110092219.26056A-100000@hub>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1402

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



thanks for replying...

yes I am aware in doing so I'll be violating RFC regulations...but I'll
not use the rule unles I am sure I am being spammed...I do want my users
to get non-delivery notifications....so pls do tell me how to do it...

regards,
seema




On Tue, 9 Jan 2001, Ted Keller wrote:

 > Seema,
 > 
 > Normally, mails with a envelope from line indicate a remote mailer-daemon
 > talking to you - often regarding non-deliverable messages.  If you block
 > these, you tend to be non-rfc-821 compliant - and your users will not be
 > able to received non-deliverable responses.
 > 
 > Some sites, however, have implemented smap changes to prevent <> type
 > mailerdaemon messages.
 > 
 > I suspect you want to do this to eliminate spam type messages.  There may
 > be other approaches to this other than violating rfc specifications.
 > 
 > tek
 > 
 > 
 > On Tue, 9 Jan 2001, seema khanna wrote:
 > 
 > > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > > BODY of a mail message to majordomo@ex.tis.com.]
 > > 
 > > 
 > > how do I stop mails with a blank from:<>, I don't want them to reach my
 > > server..
 > > 
 > > pls do help..will be really grateful
 > > 
 > > regards,
 > > seema
 > > 
 > > 
 > > 
 > > 
 > > 
 > 
 > 



From owner-fwtk-users@ex.tis.com Wed Jan 10 10:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA27506
	Wed, 10 Jan 2001 10:42:08 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21494;
	Wed, 10 Jan 2001 07:42:36 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 10 Jan 2001 06:22:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA14553
	for fwtk-users-outgoing; Wed, 10 Jan 2001 06:22:33 -0800 (PST)
Message-ID: <001201c07b10$8afd1970$da93a23d@authernote>
From: "auther_bin" <auther_bin@263.net>
To: <fwtk-users@tis.com>
References: <Pine.GSO.4.10.10101082237210.20808-100000@ns1.bfg.com>
Subject: Re: About spam mail
Date: Tue, 9 Jan 2001 16:45:34 +0800
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from base64 to 8bit by relay2.nai.com id GAA14540
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="gb2312"
Content-Length: 416

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Now I find the reason of so much spam mail, for I recived many unkonwn mails from our inside email server, these letters' head writed like this:

from: <>
RPPT TO:<0xL1D3EEC3CBB5E7C4D4z@mydomain.com>
.........

So smap accept this mail, and put it into it's queue. And no next works.




From owner-fwtk-users@ex.tis.com Wed Jan 10 23:24 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA00398
	Wed, 10 Jan 2001 23:24:45 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA28722;
	Wed, 10 Jan 2001 20:24:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 10 Jan 2001 18:48:22 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA24130
	for fwtk-users-outgoing; Wed, 10 Jan 2001 18:48:10 -0800 (PST)
X-Authentication-Warning: stan.aipo.gov.au: anwsmh owned process doing -bs
Date: Thu, 11 Jan 2001 13:54:14 +1100 (EST)
From: Stanley Hopcroft <Stanley.Hopcroft@IPAustralia.Gov.AU>
X-X-Sender:  <anwsmh@stan.aipo.gov.au>
To: <fwtk-users@tis.com>
Subject: Please ignore problems applying yao-smap.pch. Patch mangled by
 browser ..
Message-ID: <Pine.BSF.4.31.0101111351190.3592-100000@stan.aipo.gov.au>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 539

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear Ladies and Gentlemen,

Please ignore my ignorant plea for help in applying the Yao smap patch
(anti-spam).

My browser borke long patch lines into two leading to extra lines in
the downloaded patch that are inconsistent with it's hunk definitions.

After editing the patch file to join the lines and applying it with
--ignore-whitespace all the hunks succeeded.

Thank you,

Yours sincerely.

S Hopcroft


From owner-fwtk-users@ex.tis.com Thu Jan 11 08:01 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA01745
	Thu, 11 Jan 2001 08:01:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA12986;
	Thu, 11 Jan 2001 05:01:40 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 11 Jan 2001 02:51:19 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA09650
	for fwtk-users-outgoing; Thu, 11 Jan 2001 02:51:09 -0800 (PST)
X-Authentication-Warning: stan.aipo.gov.au: anwsmh owned process doing -bs
Date: Thu, 11 Jan 2001 21:53:25 +1100 (EST)
From: Stanley Hopcroft <Stanley.Hopcroft@IPAustralia.Gov.AU>
X-Sender: anwsmh@stan.aipo.gov.au
To: fwtk-users@tis.com
Subject: How does one compile the Lebayle jumbo-smap patch ? (anti-spam
 content filter)
Message-ID: <Pine.BSF.4.21.0101112143100.234-100000@stan.aipo.gov.au>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1587

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Dear Ladies and Gentlemen,

I would dearly love to use the SPAMBODY options in the Lebayle
jumbo-smap patch to filter the Win.HYBRIS virus (the From: header is
hahaha@sexyfun.net), but I am too stupid to know how to compile smap
with Monsieur Lebayles enhancements.

The patch contains as far as I can tell at least two important files

. Makefile.changes
. smap.c.changes

The smap.c.changes is not a diff file (as far as I can tell) and is
mainly C code with plain text lines like (..-- end of modif -- .. and
.. -- begin of modif-global --.. )

char    sfn[MAXDOMAINLEN] = "sfn.asso.fr";
#endif
---------------------------------end of
modif----------------------------------

---------------------------------begin of modif-global
variables---------------
#ifdef NOSPAM
extern int mailFromSpammer(char *sender, char *hostname, char *addr,
Cfg *configTable);

The README apart from specifying the role of #defines and the use of
the other 6-10 files does not mention building (
tsitc> grep -i build README 
tsitc>
)

Should I inspect the smap.c and the smap.c.changes and add the changes
where I think they belong in smap.c ?

What version of smap.c should I be "patching" ?

Is it a really stupid question to ask if there are any diffs against
smap.c ?

Your comments will be modt grafeully received. (When I email Monsieur
Lebayle, his MTA bounces the letter really quickly with a "content is
spam" reason).

Thank you,

Yours sincerely,

S Hopcroft




From owner-fwtk-users@ex.tis.com Thu Jan 11 12:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA02714
	Thu, 11 Jan 2001 12:04:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA03518;
	Thu, 11 Jan 2001 09:04:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 11 Jan 2001 07:32:48 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA22677
	for fwtk-users-outgoing; Thu, 11 Jan 2001 07:32:37 -0800 (PST)
Message-ID: <3A5DCFAE.D6290CFF@lclcan.com>
Date: Thu, 11 Jan 2001 10:22:23 -0500
From: Don <don@lclcan.com>
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: Problem installing FWTK on Linux
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 579

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I have a RedHat 6.2 system (fresh) with everything installed and am
attempting to install the FWTK.  After copying the Makefile.config.linux
to Makefile.config and running make, I get the following error
messages.  I looked through the FAQ's and could not find a reference.

/usr/bin/ld: cannot find -lXaw
collect2: ld returned 1 exit status
make[1]: *** [x-gw] Error 1
make[1]: Leaving directory `/usr/local/fwtk/x-gw'
make: *** [all] Error 2


From owner-fwtk-users@ex.tis.com Thu Jan 11 12:25 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA02793
	Thu, 11 Jan 2001 12:25:30 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA06628;
	Thu, 11 Jan 2001 09:25:31 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 11 Jan 2001 08:12:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA26787
	for fwtk-users-outgoing; Thu, 11 Jan 2001 08:12:39 -0800 (PST)
Message-ID: <3A5DD8C9.84427ED7@lclcan.com>
Date: Thu, 11 Jan 2001 11:01:13 -0500
From: Don <don@lclcan.com>
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: My previous install problem
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 338

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Regarding my previous email concerning a problem installing the FWTK on
RedHat Linux 6.2 (/usr/bin/ld: cannot find -lXaw),  I traced the problem
to incorrect paths in the Makefile.config

Problem solved,
Don


From owner-fwtk-users@ex.tis.com Thu Jan 11 13:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA02888
	Thu, 11 Jan 2001 13:03:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA11411;
	Thu, 11 Jan 2001 10:03:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 11 Jan 2001 08:43:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA00658
	for fwtk-users-outgoing; Thu, 11 Jan 2001 08:43:19 -0800 (PST)
Message-ID: <3A5DDD47.96DB185E@zrz.TU-Berlin.DE>
Date: Thu, 11 Jan 2001 17:20:23 +0100
From: Gerd Schering <Schering@zrz.tu-berlin.de>
Organization: TUB
X-Mailer: Mozilla 4.75 [en] (X11; U; Linux 2.2.14-15mdk i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Don <don@lclcan.com>
CC: fwtk <fwtk-users@lists.nai.com>
Subject: Re: Problem installing FWTK on Linux
References: <3A5DCFAE.D6290CFF@lclcan.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=sha1; boundary="------------ms97647B8195ECFAE6E3D995BA"
Content-Length: 2694

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a cryptographically signed message in MIME format.

--------------ms97647B8195ECFAE6E3D995BA
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Don wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hi,
 > 
 > I have a RedHat 6.2 system (fresh) with everything installed and am
 > attempting to install the FWTK.  After copying the Makefile.config.linux
 > to Makefile.config and running make, I get the following error
 > messages.  I looked through the FAQ's and could not find a reference.
 > 
 > /usr/bin/ld: cannot find -lXaw

libXaw.so is part of the Xfree86-devel rpm which you haven'
probably not installed.
So simply (or first of all) install it and then retry.

Gerd
------------------------------------------------------
-- Gerd Schering
-- Email: Schering@zrz.TU-Berlin.DE
------------------------------------------------------
--------------ms97647B8195ECFAE6E3D995BA
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIDvwYJKoZIhvcNAQcCoIIDsDCCA6wCAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAaCC
AiMwggIfMIIBiKADAgECAgIA2zANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJERTESMBAG
A1UEChMJVFUtQmVybGluMQwwCgYDVQQLEwNaUloxFDASBgNVBAMTC1RDIFRVQiAyMDAwMB4X
DTAwMDgyMTExNDcyNVoXDTAyMDIxMjExNDcyNVowcTELMAkGA1UEBhMCREUxEjAQBgNVBAoT
CVRVLUJlcmxpbjEMMAoGA1UECxMDWlJaMRYwFAYDVQQDEw1HZXJkIFNjaGVyaW5nMSgwJgYJ
KoZIhvcNAQkBFhlTY2hlcmluZ0B6cnouVFUtQmVybGluLkRFMFwwDQYJKoZIhvcNAQEBBQAD
SwAwSAJBAMzO07BsdY4ao1jwlxpa3z6t32gF+XfuOORFv5n8cg4vBbjipcmd8xujpYDGY9GY
gZa24RA34B4ZHwKv7Af1XOECAwEAAaM2MDQwEQYJYIZIAYb4QgEBBAQDAgCgMB8GA1UdIwQY
MBaAFAbN8qubZqQJJpbjkE+k2mOXQCqPMA0GCSqGSIb3DQEBBAUAA4GBAFmom4WWG42yDme4
Thl+NXRjM+tCqbmE6L70TkL0IU8D0LaJb2KcfvU1FCK+xZWvHn7q1wSUioAFn2Kg4jD/hPww
40E7WMDT+0RNWDWqd94z6+UCBp453jdqwuq4gw+d6vYC7coCdnoW/6VQw+ZaFQs0RFnObEtM
132MBEUbQ0nyMYIBZDCCAWACAQEwSzBFMQswCQYDVQQGEwJERTESMBAGA1UEChMJVFUtQmVy
bGluMQwwCgYDVQQLEwNaUloxFDASBgNVBAMTC1RDIFRVQiAyMDAwAgIA2zAJBgUrDgMCGgUA
oIGxMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTAxMDExMTE2
MjAyNVowIwYJKoZIhvcNAQkEMRYEFJl++YmaSk7JxQNiMk/vkGyAQSUCMFIGCSqGSIb3DQEJ
DzFFMEMwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMAcGBSsOAwIHMA0GCCqGSIb3DQMC
AgFAMA0GCCqGSIb3DQMCAgEoMA0GCSqGSIb3DQEBAQUABEA3lPU1/k1qxug1pJOhVscja+Gy
kRjrXzJpzJ7vV2ww66WyLUm9w1zB2Z9ZY/QZzpFkJX+GhF81A/euvHdEm0+N
--------------ms97647B8195ECFAE6E3D995BA--



From owner-fwtk-users@ex.tis.com Thu Jan 11 16:09 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA03562
	Thu, 11 Jan 2001 16:09:22 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA05398;
	Thu, 11 Jan 2001 13:09:25 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 11 Jan 2001 11:37:57 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA24205
	for fwtk-users-outgoing; Thu, 11 Jan 2001 11:37:46 -0800 (PST)
Message-ID: <3A5E0756.5C629282@lclcan.com>
Date: Thu, 11 Jan 2001 14:19:51 -0500
From: Don <don@lclcan.com>
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: Possible compile problem
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 867

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

Running RedHat Linux 6.2 complete fresh install.  Get the following when
running make although I can still install the toolkit:

make[1]: Entering directory
cc -I.. -g -DLINUX   -c -o d
db.c:16: ndbm.h: No such file or directory
make[1]: *** [db.o] Error 1

Now, ndbm.h exists in two subdirectories, 'gdbm' and 'db1' but when I
copy either file into /usr/include, I get the error:

pass.o: In function `passverify':
/usr/local/fwtk/auth/pass.c:39: undefined reference to `crypt'
pass.o: In function `passset':
/usr/local/fwtk/auth/pass.c:70: undefined reference to `crypt'
collect2: ld returned 1 exit status
make[1]: *** [authsrv] Error 1
make[1]: Leaving directory `/usr/local/fwtk/auth'

Can I just ignore the first error?

Don



From owner-fwtk-users@ex.tis.com Thu Jan 11 20:20 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA04249
	Thu, 11 Jan 2001 20:20:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA29590;
	Thu, 11 Jan 2001 17:20:55 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 11 Jan 2001 15:54:43 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA24326
	for fwtk-users-outgoing; Thu, 11 Jan 2001 15:54:32 -0800 (PST)
Message-ID: <3A5E473C.F0FFBA20@davis-net.org>
Date: Thu, 11 Jan 2001 18:52:28 -0500
From: Jeff Davis <blackbear@davis-net.org>
Organization: davis-net.org
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.14-win4lin i686)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Re: Possible compile problem
References: <3A5E0756.5C629282@lclcan.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1507

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Don wrote:

> Hi,
> 
> Running RedHat Linux 6.2 complete fresh install.  Get the following when
> running make although I can still install the toolkit:
> 
> make[1]: Entering directory
> cc -I.. -g -DLINUX   -c -o d
> db.c:16: ndbm.h: No such file or directory
> make[1]: *** [db.o] Error 1
> 
> Now, ndbm.h exists in two subdirectories, 'gdbm' and 'db1' but when I
> copy either file into /usr/include, I get the error:
> 
> pass.o: In function `passverify':
> /usr/local/fwtk/auth/pass.c:39: undefined reference to `crypt'
> pass.o: In function `passset':
> /usr/local/fwtk/auth/pass.c:70: undefined reference to `crypt'
> collect2: ld returned 1 exit status
> make[1]: *** [authsrv] Error 1
> make[1]: Leaving directory `/usr/local/fwtk/auth'
> 
> Can I just ignore the first error?
> 
> Don


Part of this is documented. You have two problems. One you solved by
copying ndbm.h. A better solution may be to prepend "gdbm/" to the
"ndbm.h" include line in the auth directory like this:

#include        <gdbm/ndbm.h>

I think there are three or four files that you have to change. You can
grep for it.

The other problem is documented in "Makefile.config.linux" and the
README. It tells you, among other things to uncomment "AUXLIB= -lcrypt"
for some distributions. Red Hat 6.2 is one. So if you followed all of
the other directions, you should have no other problems.

Jeff

From owner-fwtk-users@ex.tis.com Fri Jan 12 13:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA07237
	Fri, 12 Jan 2001 13:48:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA17896;
	Fri, 12 Jan 2001 10:47:58 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 12 Jan 2001 08:37:19 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA03559
	for fwtk-users-outgoing; Fri, 12 Jan 2001 08:37:08 -0800 (PST)
Message-ID: <47DF77CF5F0E1048B226C487D7B6B39DE3D18D@il06exm25.ds.mot.com>
From: Khurram Salman-ASK004 <S.Khurram@motorola.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: connection hanging
Date: Fri, 12 Jan 2001 10:36:12 -0600
Importance: high
X-Priority: 1
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2651.58)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 798

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

While running TIS fwtk2.1 for our telnet and ftp proxies, we have come across some issues where internal Motorolans (when proxying through fwtk2.1 proxy) go to some sites and after initial hand shake of telnet connection and after getting welcome banner, their connection hangs and they don't get any login prompt.
I have recreated this problems several times. As a possible resolution, I installed all the recommended Solaris 2.6 patches yesterday but nothing seems to be making any difference.

I in fact applied 1.6 patch but my connection still hangs.

Any ideas????

Thanks,
Salman Khurram
Network Engineer
S.Khurram@Motorola.Com
847-538-7317
Motorola, Inc.


From owner-fwtk-users@ex.tis.com Mon Jan 15 15:03 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA17330
	Mon, 15 Jan 2001 15:03:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA08275;
	Mon, 15 Jan 2001 12:03:30 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 15 Jan 2001 09:48:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA01321
	for fwtk-users-outgoing; Mon, 15 Jan 2001 09:48:00 -0800 (PST)
Message-ID: <3A6337B0.3D3FD0D0@lclcan.com>
Date: Mon, 15 Jan 2001 12:47:29 -0500
From: Don <don@lclcan.com>
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: IM through proxy
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 533

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Does anyone know if Instant Messangers work through the FWTK?  Not that
I've installed and configured the FWTK on my Linux RedHat 6.2 server,
Yahoo IM no longer connects.

Actually, it tries to connect, appears to connect and then immediately
disconnects.  I say the it "appears" to connect because while I don't
see any indication of this, others online tell me that they see me light
up for a second.


From owner-fwtk-users@ex.tis.com Mon Jan 15 18:19 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA18245
	Mon, 15 Jan 2001 18:19:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA17353;
	Mon, 15 Jan 2001 15:20:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 15 Jan 2001 13:55:55 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA13405
	for fwtk-users-outgoing; Mon, 15 Jan 2001 13:55:44 -0800 (PST)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: fwtk-users@lists.nai.com
Date: Mon, 15 Jan 2001 14:54:29 -0700
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Re: IM through proxy
Message-ID: <3A630F23.7666.C8223A@localhost>
In-reply-to: <3A6337B0.3D3FD0D0@lclcan.com>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 778

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

AOL IM works so good through my FWTK box that I couldn't block it if I wanted 
to! I tell it to use an https proxy and it slips right through. I've never 
played with Yahoo IM.  

Ken Long


On 15 Jan 2001, at 12:47, Don wrote:

> Does anyone know if Instant Messangers work through the FWTK?  Not that
> I've installed and configured the FWTK on my Linux RedHat 6.2 server,
> Yahoo IM no longer connects.
> 
> Actually, it tries to connect, appears to connect and then immediately
> disconnects.  I say the it "appears" to connect because while I don't
> see any indication of this, others online tell me that they see me light
> up for a second.


From owner-fwtk-users@ex.tis.com Mon Jan 15 20:44 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA18697
	Mon, 15 Jan 2001 20:44:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA22015;
	Mon, 15 Jan 2001 17:45:06 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 15 Jan 2001 16:23:35 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA19428
	for fwtk-users-outgoing; Mon, 15 Jan 2001 16:23:14 -0800 (PST)
Date: Mon, 15 Jan 2001 16:20:50 -0800 (PST)
From: David Lang <dlang@diginsite.com>
To: Ken Long <ken@lectrosonics.com>
cc: <fwtk-users@lists.nai.com>
Subject: Re: IM through proxy
In-Reply-To: <3A630F23.7666.C8223A@localhost>
Message-ID: <Pine.LNX.4.31.0101151619110.21696-100000@dlang.diginsite.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1407

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

the only way to block AIM is to block all access to those IP addresses

other then that AIM will go through any outbound proxy you have unless it
changes the data as it goes through or strictly enforces the protocol
rules (and in the case of HTTP even that is not enough)

 David Lang

On Mon, 15 Jan 2001, Ken Long wrote:

> Date: Mon, 15 Jan 2001 14:54:29 -0700
> From: Ken Long <ken@lectrosonics.com>
> To: fwtk-users@lists.nai.com
> Subject: Re: IM through proxy
>
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> AOL IM works so good through my FWTK box that I couldn't block it if I wanted
> to! I tell it to use an https proxy and it slips right through. I've never
> played with Yahoo IM.
>
> Ken Long
>
>
> On 15 Jan 2001, at 12:47, Don wrote:
>
> > Does anyone know if Instant Messangers work through the FWTK?  Not that
> > I've installed and configured the FWTK on my Linux RedHat 6.2 server,
> > Yahoo IM no longer connects.
> >
> > Actually, it tries to connect, appears to connect and then immediately
> > disconnects.  I say the it "appears" to connect because while I don't
> > see any indication of this, others online tell me that they see me light
> > up for a second.
>

From owner-fwtk-users@ex.tis.com Tue Jan 16 11:11 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA22177
	Tue, 16 Jan 2001 11:11:21 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA26416;
	Tue, 16 Jan 2001 08:11:27 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 16 Jan 2001 06:38:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA16730
	for fwtk-users-outgoing; Tue, 16 Jan 2001 06:37:52 -0800 (PST)
X-Authentication-Warning: beamish.nsd.ca: smap set sender to <akobelan@nsd.ca> using -f
Reply-To: <akobelan@nsd.ca>
From: "Allan Kobelansky" <akobelan@nsd.ca>
To: <fwtk-users@tis.com>
Subject: Contivity Access
Date: Sun, 14 Jan 2001 22:03:19 -0500
Message-ID: <002301c07e9f$b7525520$8065a8c0@nsd.logistec.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2911.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1369

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

Some time ago the following was posted ... by Terry Witherspoon
[withers_t@hotmail.com]:

	I've some client PCs inside a fwtk firewall needing to
	use Nortel's Extranet Access Client to talk to a Contivity
	switch at another location. Is it possible to Proxy ipsec
	with fwtk? Any info welcome.

To which the reply from Rick Murphy [rmurphy@itm-inst.com] was:

	Nope. IPsec uses some non-TCP protocols. About all you can do is to use
	packet filtering rules to permit AH/ESP through (and probably IKE, which
	uses UDP).

Several months had passed sine the original post and I contacted
Terry for a followup. The response he gave was:

	The secret is the external interface has to have unique
	IPs for each internally proxied IPSec session. So I made
	sure the internal Nortel users received there on IP and
	it works flawlessly.

I've asked for clarification but no response so far has been received.
Does anyone out there know how to interpret his response? Anyone interested
in giving it a try? I have the same problem to solve and would be most
appreciative if someone could elaborate a little on his response. It seems
that I am not alone since many posts have appeared with similar inquiries.

Best regards,

Allan Kobelansky





From owner-fwtk-users@ex.tis.com Wed Jan 17 09:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA27658
	Wed, 17 Jan 2001 09:16:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA08079;
	Wed, 17 Jan 2001 06:16:47 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 17 Jan 2001 04:07:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA00149
	for fwtk-users-outgoing; Wed, 17 Jan 2001 04:06:54 -0800 (PST)
X-Authentication-Warning: fireinet.3suisses.be: wall set sender to <F.Beuserie@3suisses.be> using -f
Message-ID: <8FF4A557FE65D311BDF80000E88EAB192BD407@DSISS002>
From: =?iso-8859-1?Q?Beuserie_Fr=E9d=E9ric_=28stbrice_dsi=29?=
	 <F.Beuserie@3suisses.be>
To: "'fwtk-users@TIS.COM'" <fwtk-users@tis.com>
Subject: squid-gw and https problem
Date: Wed, 17 Jan 2001 13:05:51 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C0807D.D60B7E9E"
Content-Length: 3056

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C0807D.D60B7E9E
Content-Type: text/plain;
	charset="iso-8859-1"


hi,

I'm in trouble with squid-gw and https
we have two firewall and a dmz, squid-gw on the internal one log,control and
then pass http requests to a http-gw on the outside firewall (it has
'server w.x.y.z p' into netperm-table squid-gw). works pretty fine, but with
-https- uri, it seems that squid-gw try to resolv and connect to the remote
hosts from the local machine (eg, the one where squid-gw runs) and not to
pass request to the outside firewall like with http. 

into the log, I can't see :

Jan 17 13:39:56 firelan squid-gw[31168]: request: CONNECT www.xxx.yy:443
HTTP/1.0
Jan 17 13:39:56 firelan squid-gw[31168]: www.xxx.yy host name lookup failed

in netperm-table, i have a 'connect www.xx.yy' line. ' seems to me that
squid-gw accept the request (from the log).
is squid-gw doesn't able to pass ssl CONNECT requests to one another http
proxy, or a config mistake ?

thanks in advance.

Beuserie Frederic
f.beuserie@3suisses.be

------_=_NextPart_001_01C0807D.D60B7E9E
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2650.12">
<TITLE>squid-gw and https problem</TITLE>
</HEAD>
<BODY>
<BR>

<P><FONT SIZE=3D2>hi,</FONT>
</P>

<P><FONT SIZE=3D2>I'm in trouble with squid-gw and https</FONT>
<BR><FONT SIZE=3D2>we have two firewall and a dmz, squid-gw on the =
internal one log,control and then pass http requests to a http-gw on =
the outside firewall (it has&nbsp; 'server w.x.y.z p' into =
netperm-table squid-gw). works pretty fine, but with -https- uri, it =
seems that squid-gw try to resolv and connect to the remote hosts from =
the local machine (eg, the one where squid-gw runs) and not to pass =
request to the outside firewall like with http. </FONT></P>

<P><FONT SIZE=3D2>into the log, I can't see :</FONT>
</P>

<P><FONT SIZE=3D2>Jan 17 13:39:56 firelan squid-gw[31168]: request: =
CONNECT www.xxx.yy:443 HTTP/1.0</FONT>
<BR><FONT SIZE=3D2>Jan 17 13:39:56 firelan squid-gw[31168]: www.xxx.yy =
host name lookup failed</FONT>
</P>

<P><FONT SIZE=3D2>in netperm-table, i have a 'connect www.xx.yy' line. =
' seems to me that squid-gw accept the request (from the log).</FONT>
<BR><FONT SIZE=3D2>is squid-gw doesn't able to pass ssl CONNECT =
requests to one another http proxy, or a config mistake ?</FONT>
</P>

<P><FONT SIZE=3D2>thanks in advance.</FONT>
</P>

<P><FONT SIZE=3D2>Beuserie Frederic</FONT>
<BR><FONT SIZE=3D2>f.beuserie@3suisses.be</FONT>
</P>

</BODY>
</HTML>
------_=_NextPart_001_01C0807D.D60B7E9E--

From owner-fwtk-users@ex.tis.com Thu Jan 18 14:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA05134
	Thu, 18 Jan 2001 14:34:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA10075;
	Thu, 18 Jan 2001 11:34:15 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 18 Jan 2001 09:20:20 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA20728
	for fwtk-users-outgoing; Thu, 18 Jan 2001 09:20:07 -0800 (PST)
From: "Thomas Off" <alberik@gmx.de>
To: <fwtk-users@lists.nai.com>
Subject: Firewall as gateway
Date: Thu, 18 Jan 2001 18:17:42 +0100
Message-ID: <MABBJOBDCONABBCEOLHGIEFJCAAA.alberik@gmx.de>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from base64 to 8bit by relay2.nai.com id JAA20676
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 527

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello!

I have installed FWTK v2.1 on a SuSE Linux 6.3 System and everything works fine if I set the proxies separate on the NT machines in our intranet. But if I change the network settings to pint to the firewall as standard gateway, there is no incoming traffic on the firewall (i.e. no proxy requests are logged). What do I have to do/change or is this just not possible.

Regards,
 Thomas Off

From owner-fwtk-users@ex.tis.com Thu Jan 18 14:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA05137
	Thu, 18 Jan 2001 14:34:22 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA10044;
	Thu, 18 Jan 2001 11:34:15 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 18 Jan 2001 10:07:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA27217
	for fwtk-users-outgoing; Thu, 18 Jan 2001 10:06:54 -0800 (PST)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <3A673E81.B21F6816@radio.hundert6.de>
Date: Thu, 18 Jan 2001 19:05:37 +0000
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.2-STABLE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: Thomas Off <alberik@gmx.de>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: Firewall as gateway
References: <MABBJOBDCONABBCEOLHGIEFJCAAA.alberik@gmx.de>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1089

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

> I have installed FWTK v2.1 on a SuSE Linux 6.3 System and everything works fine if I set the proxies separate on the NT machines in our intranet. But if I change the network settings to pint to the firewall as standard gateway, there is no incoming traffic on the firewall (i.e. no proxy requests are logged). What do I have to do/change or is this just not possible.

I don't quite get the point. An application layer gateway like
the FWTK is not routing any packets, so you can hardly use it as
a default gateway. The traffic is decoded on the application
layer and then the valid requests are handed on to the outside
servers - that's what proxies are all about. 

So if you want to use the FWTK, tell your clients to use your
FWTK host as a proxy for the relevant services. 

And if you have packet forwarding enabled on the FWTK host
GODDAMN SWITCH IT OFF!!!

Cheers, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Jan 19 18:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA10975
	Fri, 19 Jan 2001 18:51:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA28055;
	Fri, 19 Jan 2001 15:52:46 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 19 Jan 2001 13:38:47 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA09481
	for fwtk-users-outgoing; Fri, 19 Jan 2001 13:38:35 -0800 (PST)
Message-ID: <D232AEB4AA44D411B4B900508BDF077451D754@usahm011.exmi01.exch.eds.com>
From: "Glen, Mike" <mike.glen@eds.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: compiling problem
Date: Fri, 19 Jan 2001 16:37:26 -0500
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 667

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi Everyone,

I'm not so sure that this is more of a compiling problem vs a fwtk problem,
but nevertheless. When I try to compile the auth server, I get the error.  

db.c:16: ndbm.h: No such file or directory
make: *** [db.o] error 1

Has anyone ever seen this and/or know how to fix it? I've searched the disks
and found a copy of this file in /usr/include/gdbm and in /usr/include/db1 (
btw this is redhat 6.2 ).  I even tried copying the file to the directory
where to the other .h files are.  Any help would be appreciated.

-Mike  

From owner-fwtk-users@ex.tis.com Sat Jan 20 23:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA14248
	Sat, 20 Jan 2001 23:58:52 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA06889;
	Sat, 20 Jan 2001 20:59:53 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 20 Jan 2001 18:44:27 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA04290
	for fwtk-users-outgoing; Sat, 20 Jan 2001 18:44:06 -0800 (PST)
Date: Sat, 20 Jan 2001 21:41:23 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "Glen, Mike" <mike.glen@eds.com>
cc: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Re: compiling problem
In-Reply-To: <D232AEB4AA44D411B4B900508BDF077451D754@usahm011.exmi01.exch.eds.com>
Message-ID: <Pine.GSO.4.10.10101202138100.19258-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1164

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Mike,

This is the header file for the new dbm routines used by the auth
mechanism.  I don't run linux.... - but you should be able to make it work
by copying Makefile.config.linux to Makefile.conf.  This has specfic
language regarding the location of the dbm.h header files.

ted keller


On Fri, 19 Jan 2001, Glen, Mike wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi Everyone,
> 
> I'm not so sure that this is more of a compiling problem vs a fwtk problem,
> but nevertheless. When I try to compile the auth server, I get the error.  
> 
> db.c:16: ndbm.h: No such file or directory
> make: *** [db.o] error 1
> 
> Has anyone ever seen this and/or know how to fix it? I've searched the disks
> and found a copy of this file in /usr/include/gdbm and in /usr/include/db1 (
> btw this is redhat 6.2 ).  I even tried copying the file to the directory
> where to the other .h files are.  Any help would be appreciated.
> 
> -Mike  
> 


From owner-fwtk-users@ex.tis.com Mon Jan 22 06:02 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA17512
	Mon, 22 Jan 2001 06:01:48 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA06026;
	Mon, 22 Jan 2001 03:02:43 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 22 Jan 2001 00:50:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA02841
	for fwtk-users-outgoing; Mon, 22 Jan 2001 00:50:18 -0800 (PST)
Message-ID: <3A6BF3CB.127FE207@zrz.TU-Berlin.DE>
Date: Mon, 22 Jan 2001 09:48:12 +0100
From: Gerd Schering <Schering@zrz.tu-berlin.de>
Organization: TUB
X-Mailer: Mozilla 4.75 [en] (X11; U; Linux 2.2.14-15mdk i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Beuserie =?iso-8859-1?Q?Fr=E9d=E9ric?= (stbrice dsi) 
	<F.Beuserie@3suisses.be>
CC: FWTK Mailing Liste <fwtk-users@tis.com>
Subject: Re: squid-gw and https problem
References: <8FF4A557FE65D311BDF80000E88EAB192BD407@DSISS002>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=sha1; boundary="------------msE79A67C11FF7D06E952BE424"
Content-Length: 2387

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a cryptographically signed message in MIME format.

--------------msE79A67C11FF7D06E952BE424
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit

> Beuserie Frédéric (stbrice dsi) wrote:

> is squid-gw doesn't able to pass ssl CONNECT requests to one another
> http proxy, or a config mistake ?

Squid-gw always makes SSL connections directly, there is no possibility 
to forward the request to another proxy - as I was told by the author.
(I had the same problem).

Gerd
------------------------------------------------------
-- Gerd Schering
-- Email: Schering@zrz.TU-Berlin.DE
------------------------------------------------------
--------------msE79A67C11FF7D06E952BE424
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIDvwYJKoZIhvcNAQcCoIIDsDCCA6wCAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAaCC
AiMwggIfMIIBiKADAgECAgIA2zANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJERTESMBAG
A1UEChMJVFUtQmVybGluMQwwCgYDVQQLEwNaUloxFDASBgNVBAMTC1RDIFRVQiAyMDAwMB4X
DTAwMDgyMTExNDcyNVoXDTAyMDIxMjExNDcyNVowcTELMAkGA1UEBhMCREUxEjAQBgNVBAoT
CVRVLUJlcmxpbjEMMAoGA1UECxMDWlJaMRYwFAYDVQQDEw1HZXJkIFNjaGVyaW5nMSgwJgYJ
KoZIhvcNAQkBFhlTY2hlcmluZ0B6cnouVFUtQmVybGluLkRFMFwwDQYJKoZIhvcNAQEBBQAD
SwAwSAJBAMzO07BsdY4ao1jwlxpa3z6t32gF+XfuOORFv5n8cg4vBbjipcmd8xujpYDGY9GY
gZa24RA34B4ZHwKv7Af1XOECAwEAAaM2MDQwEQYJYIZIAYb4QgEBBAQDAgCgMB8GA1UdIwQY
MBaAFAbN8qubZqQJJpbjkE+k2mOXQCqPMA0GCSqGSIb3DQEBBAUAA4GBAFmom4WWG42yDme4
Thl+NXRjM+tCqbmE6L70TkL0IU8D0LaJb2KcfvU1FCK+xZWvHn7q1wSUioAFn2Kg4jD/hPww
40E7WMDT+0RNWDWqd94z6+UCBp453jdqwuq4gw+d6vYC7coCdnoW/6VQw+ZaFQs0RFnObEtM
132MBEUbQ0nyMYIBZDCCAWACAQEwSzBFMQswCQYDVQQGEwJERTESMBAGA1UEChMJVFUtQmVy
bGluMQwwCgYDVQQLEwNaUloxFDASBgNVBAMTC1RDIFRVQiAyMDAwAgIA2zAJBgUrDgMCGgUA
oIGxMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTAxMDEyMjA4
NDgxNlowIwYJKoZIhvcNAQkEMRYEFF30+JH5f6u1kr8nJrusUhB/Ts8gMFIGCSqGSIb3DQEJ
DzFFMEMwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMAcGBSsOAwIHMA0GCCqGSIb3DQMC
AgFAMA0GCCqGSIb3DQMCAgEoMA0GCSqGSIb3DQEBAQUABEAU7djxl8/PbZGBIUBhCQKepF95
LC6+9XpjeBKS4LqdYY5A6Hl5OzeBI3JmoAG9ny+kShqWhr19g1hK+DgTKyNX
--------------msE79A67C11FF7D06E952BE424--


From owner-fwtk-users@ex.tis.com Mon Jan 22 10:02 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA18397
	Mon, 22 Jan 2001 10:02:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA20498;
	Mon, 22 Jan 2001 07:03:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 22 Jan 2001 05:39:06 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA12101
	for fwtk-users-outgoing; Mon, 22 Jan 2001 05:38:44 -0800 (PST)
Message-Id: <3A6BFF59.A055AE9@icon.hu>
Date: Mon, 22 Jan 2001 10:37:29 +0100
From: Varga Zsolt <zsvarga@icon.hu>
X-Mailer: Mozilla 4.7 [en] (X11; I; SunOS 5.8 sun4m)
X-Accept-Language: en
MIME-Version: 1.0
To: "Glen, Mike" <mike.glen@eds.com>, fwtk-users@lists.nai.com
Subject: Re: compiling problem
References: <D232AEB4AA44D411B4B900508BDF077451D754@usahm011.exmi01.exch.eds.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 956

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

"Glen, Mike" wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hi Everyone,
 > 
 > I'm not so sure that this is more of a compiling problem vs a fwtk problem,
 > but nevertheless. When I try to compile the auth server, I get the error.
 > 
 > db.c:16: ndbm.h: No such file or directory
 > make: *** [db.o] error 1
 > 
 > Has anyone ever seen this and/or know how to fix it? I've searched the disks
 > and found a copy of this file in /usr/include/gdbm and in /usr/include/db1 (
 > btw this is redhat 6.2 ).  I even tried copying the file to the directory
 > where to the other .h files are.  Any help would be appreciated.

Try to make a sym.link:
cd /usr/include
ln -s gdbm/ndbm.h


-- 

---Zsolt---
mailto:zsvarga@icon.hu


From owner-fwtk-users@ex.tis.com Wed Jan 24 14:45 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA02304
	Wed, 24 Jan 2001 14:44:28 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA06661;
	Wed, 24 Jan 2001 11:42:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 24 Jan 2001 07:32:22 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA04409
	for fwtk-users-outgoing; Wed, 24 Jan 2001 07:32:10 -0800 (PST)
Message-ID: <C901B1D9820CD411A11E0060B03CEAB605C645@email.midrex.com>
From: "Nixon, Anthony" <snixon@mei-charlotte.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: SMAP issues
Date: Wed, 24 Jan 2001 09:09:50 -0500
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
	boundary="----_=_NextPart_000_01C0860F.56771AD2"
Content-Length: 56188

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_000_01C0860F.56771AD2
Content-Type: text/plain;
	charset="iso-8859-1"

Hello,
I am trying to get smap/sendmail working. I can send outbound without a
problem. But inbound mail does not seem to work. I am using the  split DNS
model (firewall is primary outside and resolv.conf points to primary inside)
and have followed the FAQ on the FWTK website. I have tried to use a
mailertable without success. Smap does receive the message, but does not
deliver it and returns a message to the sender like below (I have altered
the users email address). I think (not an expert here) that it is trying to
process to mail locally to the firewall, but do not know how to tell it to
just forward to mail to the internal mail server. There is an MX record on
the internal DNS server that points to the internal email server. This is a
desperate problem for me as I am trying to go live with this firewall and am
already several weeks behind. Any and all help will be greatly appreciated.
I have also included the sendmail.cf file for review if that is a possible
problem.

The original message was received at Wed, 24 Jan 2001 09:32:35 -0500
from uucp@localhost

----- The following addresses had permanent fatal errors -----
<user@midrex.com>
(reason: 550 5.1.1 User unknown)

----- Transcript of session follows -----
550 5.1.1 <user@midrex.com>... User unknown

Reporting-MTA: dns; fw3.midrex.com
Arrival-Date: Wed, 24 Jan 2001 09:32:35 -0500

Final-Recipient: RFC822; user@midrex.com
Action: failed
Status: 5.1.1
Diagnostic-Code: X-Unix; 550 5.1.1 User unknown
Last-Attempt-Date: Wed, 24 Jan 2001 09:32:36 -0500

--- Start of the Attached Message ---

# From message log:
Jan 24 09:34:06 fw3 smapd[12964]: discarding (no user) pid=12965 code=67
Jan 24 09:34:06 fw3 smapd[12964]: delivered file=sma012959 pid=12965 code=67
Jan 24 09:34:19 fw3 smap[12966]: connect host=po2.thetrip.com/205.169.236.32
Jan 24 09:34:20 fw3 smap[12966]: host=po2.thetrip.com/205.169.236.32
bytes=11635 from=<sender@que.thetrip.com> to=<user@midrex.com>
Jan 24 09:34:20 fw3 smap[12966]: exiting host=po2.thetrip.com/205.169.236.32
bytes=11635





Regards - Shon Nixon



  <<sendmail.cf>> 

------_=_NextPart_000_01C0860F.56771AD2
Content-Type: application/octet-stream;
	name="sendmail.cf"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
	filename="sendmail.cf"

#=0A=
# Copyright (c) 1998-2000 Sendmail, Inc. and its suppliers.=0A=
#	All rights reserved.=0A=
# Copyright (c) 1983, 1995 Eric P. Allman.  All rights reserved.=0A=
# Copyright (c) 1988, 1993=0A=
#	The Regents of the University of California.  All rights reserved.=0A=
#=0A=
# By using this file, you agree to the terms and conditions set=0A=
# forth in the LICENSE file which can be found at the top level of=0A=
# the sendmail distribution.=0A=
#=0A=
#=0A=
=0A=
######################################################################=0A=
######################################################################=0A=
#####=0A=
#####		SENDMAIL CONFIGURATION FILE=0A=
#####=0A=
#####=0A=
######################################################################=0A=
######################################################################=0A=
=0A=
#####  $Id: cfhead.m4,v 8.76.4.13 2000/08/24 17:09:50 gshapiro Exp $  =
#####=0A=
#####  $Id: cf.m4,v 8.32 1999/02/07 07:26:14 gshapiro Exp $  #####=0A=
=0A=
#####  $Id: linux.m4,v 8.11.16.2 2000/09/17 17:04:22 gshapiro Exp $  =
#####=0A=
=0A=
=0A=
=0A=
#####  $Id: local_procmail.m4,v 8.21 1999/11/18 05:06:23 ca Exp $  =
#####=0A=
=0A=
=0A=
#####  $Id: generic.m4,v 8.15 1999/04/04 00:51:09 ca Exp $  #####=0A=
=0A=
#####  $Id: redirect.m4,v 8.15 1999/08/06 01:47:36 gshapiro Exp $  =
#####=0A=
=0A=
#####  $Id: use_cw_file.m4,v 8.9 1999/02/07 07:26:13 gshapiro Exp $  =
#####=0A=
=0A=
=0A=
#####  $Id: smrsh.m4,v 8.14 1999/11/18 05:06:23 ca Exp $  #####=0A=
=0A=
#####  $Id: mailertable.m4,v 8.18 1999/07/22 17:55:35 gshapiro Exp $  =
#####=0A=
=0A=
#####  $Id: virtusertable.m4,v 8.16 1999/07/22 17:55:36 gshapiro Exp $  =
#####=0A=
=0A=
#####  $Id: redirect.m4,v 8.15 1999/08/06 01:47:36 gshapiro Exp $  =
#####=0A=
=0A=
#####  $Id: always_add_domain.m4,v 8.9 1999/02/07 07:26:08 gshapiro Exp =
$  #####=0A=
=0A=
#####  $Id: use_cw_file.m4,v 8.9 1999/02/07 07:26:13 gshapiro Exp $  =
#####=0A=
=0A=
=0A=
#####  $Id: local_procmail.m4,v 8.21 1999/11/18 05:06:23 ca Exp $  =
#####=0A=
=0A=
#####  $Id: access_db.m4,v 8.15 1999/07/22 17:55:34 gshapiro Exp $  =
#####=0A=
=0A=
#####  $Id: blacklist_recipients.m4,v 8.13 1999/04/02 02:25:13 gshapiro =
Exp $  #####=0A=
=0A=
=0A=
=0A=
#####  $Id: proto.m4,v 8.446.2.5.2.29 2000/09/15 04:45:14 gshapiro Exp =
$  #####=0A=
=0A=
=0A=
# level 9 config file format=0A=
V9/Berkeley=0A=
=0A=
# override file safeties - setting this option compromises system =
security,=0A=
# addressing the actual file configuration problem is preferred=0A=
# need to set this before any file actions are encountered in the cf =
file=0A=
#O DontBlameSendmail=3Dsafe=0A=
=0A=
# default LDAP map specification=0A=
# need to set this now before any LDAP maps are defined=0A=
#O LDAPDefaultSpec=3D-h localhost=0A=
=0A=
##################=0A=
#   local info   #=0A=
##################=0A=
=0A=
Cwlocalhost=0A=
# file containing names of hosts for which we receive email=0A=
Fw/etc/mail/local-host-names=0A=
=0A=
# my official domain name=0A=
# ... define this only if sendmail cannot automatically determine your =
domain=0A=
#Dj$w.Foo.COM=0A=
=0A=
CP.=0A=
=0A=
# "Smart" relay host (may be null)=0A=
DS=0A=
=0A=
=0A=
# operators that cannot be in local usernames (i.e., network =
indicators)=0A=
CO @ % !=0A=
=0A=
# a class with just dot (for identifying canonical names)=0A=
C..=0A=
=0A=
# a class with just a left bracket (for identifying domain literals)=0A=
C[[=0A=
=0A=
# access_db acceptance class=0A=
C{Accept}OK RELAY=0A=
=0A=
=0A=
# Resolve map (to check if a host exists in check_mail)=0A=
Kresolve host -a<OK> -T<TEMP>=0A=
=0A=
=0A=
=0A=
# Hosts for which relaying is permitted ($=3DR)=0A=
FR-o /etc/mail/relay-domains=0A=
=0A=
# arithmetic map=0A=
Karith arith=0A=
# possible values for tls_connect in access map=0A=
C{tls}VERIFY ENCR=0A=
=0A=
# who I send unqualified names to (null means deliver locally)=0A=
DR=0A=
=0A=
# who gets all local email traffic ($R has precedence for unqualified =
names)=0A=
DH=0A=
=0A=
# dequoting map=0A=
Kdequote dequote=0A=
=0A=
# class E: names that should be exposed as from this host, even if we =
masquerade=0A=
# class L: names that should be delivered locally, even if we have a =
relay=0A=
# class M: domains that should be converted to $M=0A=
# class N: domains that should not be converted to $M=0A=
#CL root=0A=
CEroot=0A=
=0A=
# who I masquerade as (null for no masquerading) (see also $=3DM)=0A=
DM=0A=
=0A=
# my name for error messages=0A=
DnMAILER-DAEMON=0A=
=0A=
=0A=
CPREDIRECT=0A=
=0A=
# Mailer table (overriding domains)=0A=
Kmailertable hash /etc/mail/mailertable=0A=
=0A=
# Virtual user table (maps incoming users)=0A=
Kvirtuser hash -o /etc/mail/virtusertable=0A=
=0A=
CPREDIRECT=0A=
=0A=
# Access list database (for spam stomping)=0A=
Kaccess hash /etc/mail/access=0A=
=0A=
# Configuration version number=0A=
DZ8.11.1=0A=
=0A=
=0A=
###############=0A=
#   Options   #=0A=
###############=0A=
=0A=
# strip message body to 7 bits on input?=0A=
O SevenBitInput=3DFalse=0A=
=0A=
# 8-bit data handling=0A=
O EightBitMode=3Dpass8=0A=
=0A=
# wait for alias file rebuild (default units: minutes)=0A=
O AliasWait=3D10=0A=
=0A=
# location of alias file=0A=
O AliasFile=3D/etc/mail/aliases=0A=
=0A=
# minimum number of free blocks on filesystem=0A=
O MinFreeBlocks=3D100=0A=
=0A=
# maximum message size=0A=
#O MaxMessageSize=3D1000000=0A=
=0A=
# substitution for space (blank) characters=0A=
O BlankSub=3D.=0A=
=0A=
# avoid connecting to "expensive" mailers on initial submission?=0A=
O HoldExpensive=3DFalse=0A=
=0A=
# checkpoint queue runs after every N successful deliveries=0A=
#O CheckpointInterval=3D10=0A=
=0A=
# default delivery mode=0A=
O DeliveryMode=3Dbackground=0A=
=0A=
# automatically rebuild the alias database?=0A=
# NOTE: There is a potential for a denial of service attack if this is =
set.=0A=
#       This option is deprecated and will be removed from a future =
version.=0A=
#O AutoRebuildAliases=3DFalse=0A=
=0A=
# error message header/file=0A=
#O ErrorHeader=3D/etc/mail/error-header=0A=
=0A=
# error mode=0A=
#O ErrorMode=3Dprint=0A=
=0A=
# save Unix-style "From_" lines at top of header?=0A=
#O SaveFromLine=3DFalse=0A=
=0A=
# temporary file mode=0A=
O TempFileMode=3D0600=0A=
=0A=
# match recipients against GECOS field?=0A=
#O MatchGECOS=3DFalse=0A=
=0A=
# maximum hop count=0A=
#O MaxHopCount=3D17=0A=
=0A=
# location of help file=0A=
O HelpFile=3D/etc/mail/helpfile=0A=
=0A=
# ignore dots as terminators in incoming messages?=0A=
#O IgnoreDots=3DFalse=0A=
=0A=
# name resolver options=0A=
#O ResolverOptions=3D+AAONLY=0A=
=0A=
# deliver MIME-encapsulated error messages?=0A=
O SendMimeErrors=3DTrue=0A=
=0A=
# Forward file search path=0A=
O =
ForwardPath=3D$z/.forward.$w+$h:$z/.forward+$h:$z/.forward.$w:$z/.forwar=
d=0A=
=0A=
# open connection cache size=0A=
O ConnectionCacheSize=3D2=0A=
=0A=
# open connection cache timeout=0A=
O ConnectionCacheTimeout=3D5m=0A=
=0A=
# persistent host status directory=0A=
#O HostStatusDirectory=3D.hoststat=0A=
=0A=
# single thread deliveries (requires HostStatusDirectory)?=0A=
#O SingleThreadDelivery=3DFalse=0A=
=0A=
# use Errors-To: header?=0A=
O UseErrorsTo=3DFalse=0A=
=0A=
# log level=0A=
O LogLevel=3D9=0A=
=0A=
# send to me too, even in an alias expansion?=0A=
#O MeToo=3DTrue=0A=
=0A=
# verify RHS in newaliases?=0A=
O CheckAliases=3DFalse=0A=
=0A=
# default messages to old style headers if no special punctuation?=0A=
O OldStyleHeaders=3DTrue=0A=
=0A=
# SMTP daemon options=0A=
O DaemonPortOptions=3DName=3DMTA=0A=
O DaemonPortOptions=3DPort=3D587, Name=3DMSA, M=3DE=0A=
=0A=
# SMTP client options=0A=
#O ClientPortOptions=3DAddress=3D0.0.0.0=0A=
=0A=
# privacy flags=0A=
O PrivacyOptions=3Dauthwarnings,goaway,restrictmailq,restrictqrun=0A=
=0A=
# who (if anyone) should get extra copies of error messages=0A=
#O PostmasterCopy=3DPostmaster=0A=
=0A=
# slope of queue-only function=0A=
#O QueueFactor=3D600000=0A=
=0A=
# queue directory=0A=
O QueueDirectory=3D/var/spool/mqueue=0A=
=0A=
# timeouts (many of these)=0A=
#O Timeout.initial=3D5m=0A=
#O Timeout.connect=3D5m=0A=
#O Timeout.iconnect=3D5m=0A=
#O Timeout.helo=3D5m=0A=
#O Timeout.mail=3D10m=0A=
#O Timeout.rcpt=3D1h=0A=
#O Timeout.datainit=3D5m=0A=
#O Timeout.datablock=3D1h=0A=
#O Timeout.datafinal=3D1h=0A=
#O Timeout.rset=3D5m=0A=
#O Timeout.quit=3D2m=0A=
#O Timeout.misc=3D2m=0A=
#O Timeout.command=3D1h=0A=
#O Timeout.ident=3D5s=0A=
#O Timeout.fileopen=3D60s=0A=
#O Timeout.control=3D2m=0A=
O Timeout.queuereturn=3D5d=0A=
#O Timeout.queuereturn.normal=3D5d=0A=
#O Timeout.queuereturn.urgent=3D2d=0A=
#O Timeout.queuereturn.non-urgent=3D7d=0A=
O Timeout.queuewarn=3D4h=0A=
#O Timeout.queuewarn.normal=3D4h=0A=
#O Timeout.queuewarn.urgent=3D1h=0A=
#O Timeout.queuewarn.non-urgent=3D12h=0A=
#O Timeout.hoststatus=3D30m=0A=
#O Timeout.resolver.retrans=3D5s=0A=
#O Timeout.resolver.retrans.first=3D5s=0A=
#O Timeout.resolver.retrans.normal=3D5s=0A=
#O Timeout.resolver.retry=3D4=0A=
#O Timeout.resolver.retry.first=3D4=0A=
#O Timeout.resolver.retry.normal=3D4=0A=
=0A=
# should we not prune routes in route-addr syntax addresses?=0A=
#O DontPruneRoutes=3DFalse=0A=
=0A=
# queue up everything before forking?=0A=
O SuperSafe=3DTrue=0A=
=0A=
# status file=0A=
O StatusFile=3D/etc/mail/statistics=0A=
=0A=
# time zone handling:=0A=
#  if undefined, use system default=0A=
#  if defined but null, use TZ envariable passed in=0A=
#  if defined and non-null, use that info=0A=
#O TimeZoneSpec=3D=0A=
=0A=
# default UID (can be username or userid:groupid)=0A=
O DefaultUser=3D8:12=0A=
=0A=
# list of locations of user database file (null means no lookup)=0A=
#O UserDatabaseSpec=3D/etc/mail/userdb=0A=
=0A=
# fallback MX host=0A=
#O FallbackMXhost=3Dfall.back.host.net=0A=
=0A=
# if we are the best MX host for a site, try it directly instead of =
config err=0A=
O TryNullMXList=3Dtrue=0A=
=0A=
# load average at which we just queue messages=0A=
#O QueueLA=3D8=0A=
=0A=
# load average at which we refuse connections=0A=
#O RefuseLA=3D12=0A=
=0A=
# maximum number of children we allow at one time=0A=
#O MaxDaemonChildren=3D12=0A=
=0A=
# maximum number of new connections per second=0A=
#O ConnectionRateThrottle=3D3=0A=
=0A=
# work recipient factor=0A=
#O RecipientFactor=3D30000=0A=
=0A=
# deliver each queued job in a separate process?=0A=
#O ForkEachJob=3DFalse=0A=
=0A=
# work class factor=0A=
#O ClassFactor=3D1800=0A=
=0A=
# work time factor=0A=
#O RetryFactor=3D90000=0A=
=0A=
# shall we sort the queue by hostname first?=0A=
#O QueueSortOrder=3Dpriority=0A=
=0A=
# minimum time in queue before retry=0A=
#O MinQueueAge=3D30m=0A=
=0A=
# default character set=0A=
#O DefaultCharSet=3Diso-8859-1=0A=
=0A=
# service switch file (ignored on Solaris, Ultrix, OSF/1, others)=0A=
#O ServiceSwitchFile=3D/etc/mail/service.switch=0A=
=0A=
# hosts file (normally /etc/hosts)=0A=
#O HostsFile=3D/etc/hosts=0A=
=0A=
# dialup line delay on connection failure=0A=
#O DialDelay=3D10s=0A=
=0A=
# action to take if there are no recipients in the message=0A=
#O NoRecipientAction=3Dadd-to-undisclosed=0A=
=0A=
# chrooted environment for writing to files=0A=
#O SafeFileEnvironment=3D/arch=0A=
=0A=
# are colons OK in addresses?=0A=
#O ColonOkInAddr=3DTrue=0A=
=0A=
# how many jobs can you process in the queue?=0A=
#O MaxQueueRunSize=3D10000=0A=
=0A=
# shall I avoid expanding CNAMEs (violates protocols)?=0A=
#O DontExpandCnames=3DFalse=0A=
=0A=
# SMTP initial login message (old $e macro)=0A=
O SmtpGreetingMessage=3D$j=0A=
=0A=
# UNIX initial From header format (old $l macro)=0A=
O UnixFromLine=3DFrom $g $d=0A=
=0A=
# From: lines that have embedded newlines are unwrapped onto one =
line=0A=
#O SingleLineFromHeader=3DFalse=0A=
=0A=
# Allow HELO SMTP command that does not include a host name=0A=
#O AllowBogusHELO=3DFalse=0A=
=0A=
# Characters to be quoted in a full name phrase (@,;:\()[] are =
automatic)=0A=
#O MustQuoteChars=3D.=0A=
=0A=
# delimiter (operator) characters (old $o macro)=0A=
O OperatorChars=3D.:%@!^/[]+=0A=
=0A=
# shall I avoid calling initgroups(3) because of high NIS costs?=0A=
#O DontInitGroups=3DFalse=0A=
=0A=
# are group-writable :include: and .forward files (un)trustworthy?=0A=
#O UnsafeGroupWrites=3DTrue=0A=
=0A=
# where do errors that occur when sending errors get sent?=0A=
#O DoubleBounceAddress=3Dpostmaster=0A=
=0A=
# where to save bounces if all else fails=0A=
#O DeadLetterDrop=3D/var/tmp/dead.letter=0A=
=0A=
# what user id do we assume for the majority of the processing?=0A=
#O RunAsUser=3Dsendmail=0A=
=0A=
# maximum number of recipients per SMTP envelope=0A=
#O MaxRecipientsPerMessage=3D100=0A=
=0A=
# shall we get local names from our installed interfaces?=0A=
O DontProbeInterfaces=3Dtrue=0A=
=0A=
# Return-Receipt-To: header implies DSN request=0A=
#O RrtImpliesDsn=3DFalse=0A=
=0A=
# override connection address (for testing)=0A=
#O ConnectOnlyTo=3D0.0.0.0=0A=
=0A=
# Trusted user for file ownership and starting the daemon=0A=
#O TrustedUser=3Droot=0A=
=0A=
# Control socket for daemon management=0A=
#O ControlSocketName=3D/var/spool/mqueue/.control=0A=
=0A=
# Maximum MIME header length to protect MUAs=0A=
#O MaxMimeHeaderLength=3D0/0=0A=
=0A=
# Maximum length of the sum of all headers=0A=
O MaxHeadersLength=3D32768=0A=
=0A=
# Maximum depth of alias recursion=0A=
#O MaxAliasRecursion=3D10=0A=
=0A=
# location of pid file=0A=
#O PidFile=3D/var/run/sendmail.pid=0A=
=0A=
# Prefix string for the process title shown on 'ps' listings=0A=
#O ProcessTitlePrefix=3Dprefix=0A=
=0A=
# Data file (df) memory-buffer file maximum size=0A=
#O DataFileBufferSize=3D4096=0A=
=0A=
# Transcript file (xf) memory-buffer file maximum size=0A=
#O XscriptFileBufferSize=3D4096=0A=
=0A=
# list of authentication mechanisms=0A=
#O AuthMechanisms=3DGSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5=0A=
=0A=
# default authentication information for outgoing connections=0A=
#O DefaultAuthInfo=3D/etc/mail/default-auth-info=0A=
=0A=
# SMTP AUTH flags=0A=
#O AuthOptions=0A=
=0A=
=0A=
=0A=
# CA directory=0A=
#O CACERTPath=0A=
# CA file=0A=
#O CACERTFile=0A=
# Server Cert=0A=
#O ServerCertFile=0A=
# Server private key=0A=
#O ServerKeyFile=0A=
# Client Cert=0A=
#O ClientCertFile=0A=
# Client private key=0A=
#O ClientKeyFile=0A=
# DHParameters (only required if DSA/DH is used)=0A=
#O DHParameters=0A=
# Random data source (required for systems without /dev/urandom under =
OpenSSL)=0A=
#O RandFile=0A=
=0A=
=0A=
=0A=
###########################=0A=
#   Message precedences   #=0A=
###########################=0A=
=0A=
Pfirst-class=3D0=0A=
Pspecial-delivery=3D100=0A=
Plist=3D-30=0A=
Pbulk=3D-60=0A=
Pjunk=3D-100=0A=
=0A=
#####################=0A=
#   Trusted users   #=0A=
#####################=0A=
=0A=
# this is equivalent to setting class "t"=0A=
#Ft/etc/mail/trusted-users=0A=
Troot=0A=
Tdaemon=0A=
Tuucp=0A=
=0A=
#########################=0A=
#   Format of headers   #=0A=
#########################=0A=
=0A=
H?P?Return-Path: <$g>=0A=
HReceived: $?sfrom $s $.$?_($?s$|from $.$_)=0A=
	$.$?{auth_type}(authenticated$?{auth_ssf} (${auth_ssf} bits)$.)=0A=
	$.by $j ($v/$Z)$?r with $r$. id $i$?{tls_version}=0A=
	(using ${tls_version} with cipher ${cipher} (${cipher_bits} bits) =
verified ${verify})$.$?u=0A=
	for $u; $|;=0A=
	$.$b=0A=
H?D?Resent-Date: $a=0A=
H?D?Date: $a=0A=
H?F?Resent-From: $?x$x <$g>$|$g$.=0A=
H?F?From: $?x$x <$g>$|$g$.=0A=
H?x?Full-Name: $x=0A=
# HPosted-Date: $a=0A=
# H?l?Received-Date: $b=0A=
H?M?Resent-Message-Id: <$t.$i@$j>=0A=
H?M?Message-Id: <$t.$i@$j>=0A=
=0A=
#=0C=0A=
######################################################################=0A=
######################################################################=0A=
#####=0A=
#####			REWRITING RULES=0A=
#####=0A=
######################################################################=0A=
######################################################################=0A=
=0A=
############################################=0A=
###  Ruleset 3 -- Name Canonicalization  ###=0A=
############################################=0A=
Scanonify=3D3=0A=
=0A=
# handle null input (translate to <@> special case)=0A=
R$@			$@ <@>=0A=
=0A=
# strip group: syntax (not inside angle brackets!) and trailing =
semicolon=0A=
R$*			$: $1 <@>			mark addresses=0A=
R$* < $* > $* <@>	$: $1 < $2 > $3			unmark <addr>=0A=
R@ $* <@>		$: @ $1				unmark @host:...=0A=
R$* :: $* <@>		$: $1 :: $2			unmark node::addr=0A=
R:include: $* <@>	$: :include: $1			unmark :include:...=0A=
R$* [ IPv6 $- ] <@>	$: $1 [ IPv6 $2 ]		unmark IPv6 addr=0A=
R$* : $* [ $* ]		$: $1 : $2 [ $3 ] <@>		remark if leading colon=0A=
R$* : $* <@>		$: $2				strip colon if marked=0A=
R$* <@>			$: $1				unmark=0A=
R$* ;			   $1				strip trailing semi=0A=
R$* < $* ; >		   $1 < $2 >			bogus bracketed semi=0A=
=0A=
# null input now results from list:; syntax=0A=
R$@			$@ :; <@>=0A=
=0A=
# strip angle brackets -- note RFC733 heuristic to get innermost =
item=0A=
R$*			$: < $1 >			housekeeping <>=0A=
R$+ < $* >		   < $2 >			strip excess on left=0A=
R< $* > $+		   < $1 >			strip excess on right=0A=
R<>			$@ < @ >			MAIL FROM:<> case=0A=
R< $+ >			$: $1				remove housekeeping <>=0A=
=0A=
# strip route address <@a,@b,@c:user@d> -> <user@d>=0A=
R@ $+ , $+		$2=0A=
R@ $+ : $+		$2=0A=
=0A=
# find focus for list syntax=0A=
R $+ : $* ; @ $+	$@ $>Canonify2 $1 : $2 ; < @ $3 >	list syntax=0A=
R $+ : $* ;		$@ $1 : $2;			list syntax=0A=
=0A=
# find focus for @ syntax addresses=0A=
R$+ @ $+		$: $1 < @ $2 >			focus on domain=0A=
R$+ < $+ @ $+ >		$1 $2 < @ $3 >			move gaze right=0A=
R$+ < @ $+ >		$@ $>Canonify2 $1 < @ $2 >	already canonical=0A=
=0A=
# do some sanity checking=0A=
R$* < @ $* : $* > $*	$1 < @ $2 $3 > $4		nix colons in addrs=0A=
=0A=
# convert old-style addresses to a domain-based address=0A=
R$- ! $+		$@ $>Canonify2 $2 < @ $1 .UUCP >	resolve uucp names=0A=
R$+ . $- ! $+		$@ $>Canonify2 $3 < @ $1 . $2 >		domain uucps=0A=
R$+ ! $+		$@ $>Canonify2 $2 < @ $1 .UUCP >	uucp subdomains=0A=
=0A=
# if we have % signs, take the rightmost one=0A=
R$* % $*		$1 @ $2				First make them all @s.=0A=
R$* @ $* @ $*		$1 % $2 @ $3			Undo all but the last.=0A=
R$* @ $*		$@ $>Canonify2 $1 < @ $2 >	Insert < > and finish=0A=
=0A=
# else we must be a local name=0A=
R$*			$@ $>Canonify2 $1=0A=
=0A=
=0A=
################################################=0A=
###  Ruleset 96 -- bottom half of ruleset 3  ###=0A=
################################################=0A=
=0A=
SCanonify2=3D96=0A=
=0A=
# handle special cases for local names=0A=
R$* < @ localhost > $*		$: $1 < @ $j . > $2		no domain at all=0A=
R$* < @ localhost . $m > $*	$: $1 < @ $j . > $2		local domain=0A=
R$* < @ localhost . UUCP > $*	$: $1 < @ $j . > $2		.UUCP domain=0A=
=0A=
# check for IPv6 domain literal (save quoted form)=0A=
R$* < @ [ IPv6 $- ] > $*	$: $2 $| $1 < @@ [ $(dequote $2 $) ] > $3	mark =
IPv6 addr=0A=
R$- $| $* < @@ $=3Dw > $*		$: $2 < @ $j . > $4		self-literal=0A=
R$- $| $* < @@ [ $+ ] > $*	$@ $2 < @ [ IPv6 $1 ] > $4	canon IP addr=0A=
=0A=
# check for IPv4 domain literal=0A=
R$* < @ [ $+ ] > $*		$: $1 < @@ [ $2 ] > $3		mark [a.b.c.d]=0A=
R$* < @@ $=3Dw > $*		$: $1 < @ $j . > $3		self-literal=0A=
R$* < @@ $+ > $*		$@ $1 < @ $2 > $3		canon IP addr=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
# if really UUCP, handle it immediately=0A=
=0A=
# try UUCP traffic as a local address=0A=
R$* < @ $+ . UUCP > $*		$: $1 < @ $[ $2 $] . UUCP . > $3=0A=
R$* < @ $+ . . UUCP . > $*	$@ $1 < @ $2 . > $3=0A=
=0A=
# hostnames ending in class P are always canonical=0A=
R$* < @ $* $=3DP > $*		$: $1 < @ $2 $3 . > $4=0A=
R$* < @ $* $~P > $*		$: $&{daemon_flags} $| $1 < @ $2 $3 > $4=0A=
R$* CC $* $| $*			$: $3=0A=
# pass to name server to make hostname canonical=0A=
R$* $| $* < @ $* > $*		$: $2 < @ $[ $3 $] > $4=0A=
R$* $| $*			$: $2=0A=
=0A=
# local host aliases and pseudo-domains are always canonical=0A=
R$* < @ $=3Dw > $*		$: $1 < @ $2 . > $3=0A=
R$* < @ $=3DM > $*		$: $1 < @ $2 . > $3=0A=
R$* < @ $=3D{VirtHost} > $* 	$: $1 < @ $2 . > $3=0A=
R$* < @ $* . . > $*		$1 < @ $2 . > $3=0A=
=0A=
=0A=
##################################################=0A=
###  Ruleset 4 -- Final Output Post-rewriting  ###=0A=
##################################################=0A=
Sfinal=3D4=0A=
=0A=
R$* <@>			$@				handle <> and list:;=0A=
=0A=
# strip trailing dot off possibly canonical name=0A=
R$* < @ $+ . > $*	$1 < @ $2 > $3=0A=
=0A=
# eliminate internal code=0A=
R$* < @ *LOCAL* > $*	$1 < @ $j > $2=0A=
=0A=
# externalize local domain info=0A=
R$* < $+ > $*		$1 $2 $3			defocus=0A=
R@ $+ : @ $+ : $+	@ $1 , @ $2 : $3		<route-addr> canonical=0A=
R@ $*			$@ @ $1				... and exit=0A=
=0A=
# UUCP must always be presented in old form=0A=
R$+ @ $- . UUCP		$2!$1				u@h.UUCP =3D> h!u=0A=
=0A=
# delete duplicate local names=0A=
R$+ % $=3Dw @ $=3Dw		$1 @ $2				u%host@host =3D> u@host=0A=
=0A=
=0A=
=0A=
##############################################################=0A=
###   Ruleset 97 -- recanonicalize and call ruleset zero   ###=0A=
###		   (used for recursive calls)		   ###=0A=
##############################################################=0A=
=0A=
SRecurse=3D97=0A=
R$*			$: $>canonify $1=0A=
R$*			$@ $>parse $1=0A=
=0A=
=0A=
######################################=0A=
###   Ruleset 0 -- Parse Address   ###=0A=
######################################=0A=
=0A=
Sparse=3D0=0A=
=0A=
R$*			$: $>Parse0 $1		initial parsing=0A=
R<@>			$#local $: <@>		special case error msgs=0A=
R$*			$: $>ParseLocal $1	handle local hacks=0A=
R$*			$: $>Parse1 $1		final parsing=0A=
=0A=
#=0A=
#  Parse0 -- do initial syntax checking and eliminate local =
addresses.=0A=
#	This should either return with the (possibly modified) input=0A=
#	or return with a #error mailer.  It should not return with a=0A=
#	#mailer other than the #error mailer.=0A=
#=0A=
=0A=
SParse0=0A=
R<@>			$@ <@>			special case error msgs=0A=
R$* : $* ; <@>		$#error $@ 5.1.3 $: "501 List:; syntax illegal for =
recipient addresses"=0A=
R@ <@ $* >		< @ $1 >		catch "@@host" bogosity=0A=
R<@ $+>			$#error $@ 5.1.3 $: "501 User address required"=0A=
R$*			$: <> $1=0A=
R<> $* < @ [ $+ ] > $*	$1 < @ [ $2 ] > $3=0A=
R<> $* <$* : $* > $*	$#error $@ 5.1.3 $: "501 Colon illegal in host =
name part"=0A=
R<> $*			$1=0A=
R$* < @ . $* > $*	$#error $@ 5.1.2 $: "501 Invalid host name"=0A=
R$* < @ $* .. $* > $*	$#error $@ 5.1.2 $: "501 Invalid host name"=0A=
R$* , $~O $*		$#error $@ 5.1.2 $: "501 Invalid route address"=0A=
=0A=
# now delete the local info -- note $=3DO to find characters that cause =
forwarding=0A=
R$* < @ > $*		$@ $>Parse0 $>canonify $1	user@ =3D> user=0A=
R< @ $=3Dw . > : $*	$@ $>Parse0 $>canonify $2	@here:... -> ...=0A=
R$- < @ $=3Dw . >		$: $(dequote $1 $) < @ $2 . >	dequote "foo"@here=0A=
R< @ $+ >		$#error $@ 5.1.3 $: "501 User address required"=0A=
R$* $=3DO $* < @ $=3Dw . >	$@ $>Parse0 $>canonify $1 $2 $3	...@here -> =
...=0A=
R$- 			$: $(dequote $1 $) < @ *LOCAL* >	dequote "foo"=0A=
R< @ *LOCAL* >		$#error $@ 5.1.3 $: "501 User address required"=0A=
R$* $=3DO $* < @ *LOCAL* >=0A=
			$@ $>Parse0 $>canonify $1 $2 $3	...@*LOCAL* -> ...=0A=
R$* < @ *LOCAL* >	$: $1=0A=
=0A=
#=0A=
#  Parse1 -- the bottom half of ruleset 0.=0A=
#=0A=
=0A=
SParse1=0A=
=0A=
# handle numeric address spec=0A=
R$* < @ [ $+ ] > $*	$: $>ParseLocal $1 < @ [ $2 ] > $3	numeric internet =
spec=0A=
R$* < @ [ $+ ] > $*	$1 < @ [ $2 ] : $S > $3		Add smart host to path=0A=
R$* < @ [ IPv6 $- ] : > $*=0A=
		$#esmtp $@ [ $(dequote $2 $) ] $: $1 < @ [IPv6 $2 ] > $3	no =
smarthost: send=0A=
R$* < @ [ $+ ] : > $*	$#esmtp $@ [$2] $: $1 < @ [$2] > $3	no smarthost: =
send=0A=
R$* < @ [ $+ ] : $- : $*> $*	$#$3 $@ $4 $: $1 < @ [$2] > $5	smarthost =
with mailer=0A=
R$* < @ [ $+ ] : $+ > $*	$#esmtp $@ $3 $: $1 < @ [$2] > $4	smarthost =
without mailer=0A=
=0A=
# handle virtual users=0A=
R$+			$: <!> $1		Mark for lookup=0A=
R<!> $+ < @ $=3D{VirtHost} . > 	$: < $(virtuser $1 @ $2 $@ $1 $: @ $) > =
$1 < @ $2 . >=0A=
R<!> $+ < @ $=3Dw . > 	$: < $(virtuser $1 @ $2 $@ $1 $: @ $) > $1 < @ =
$2 . >=0A=
R<@> $+ + $* < @ $* . >=0A=
			$: < $(virtuser $1 + * @ $3 $@ $1 $@ $2 $: @ $) > $1 + $2 < @ $3 . =
 >=0A=
R<@> $+ + $* < @ $* . >=0A=
			$: < $(virtuser $1 @ $3 $@ $1 $: @ $) > $1 + $2 < @ $3 . >=0A=
R<@> $+ + $+ < @ $+ . >	$: < $(virtuser + * @ $3 $@ $1 $@ $2 $: @ $) > =
$1 + $2 < @ $3 . >=0A=
R<@> $+ + $* < @ $+ . >	$: < $(virtuser @ $3 $@ $1 $@ $2 $: @ $) > $1 + =
$2 < @ $3 . >=0A=
R<@> $+ < @ $+ . >	$: < $(virtuser @ $2 $@ $1 $: @ $) > $1 < @ $2 . =
 >=0A=
R<@> $+			$: $1=0A=
R<!> $+			$: $1=0A=
R< error : $-.$-.$- : $+ > $* 	$#error $@ $1.$2.$3 $: $4=0A=
R< error : $- $+ > $* 	$#error $@ $(dequote $1 $) $: $2=0A=
R< $+ > $+ < @ $+ >	$: $>Recurse $1=0A=
=0A=
# short circuit local delivery so forwarded email works=0A=
=0A=
=0A=
R$=3DL < @ $=3Dw . >	$#local $: @ $1			special local names=0A=
R$+ < @ $=3Dw . >		$#local $: $1			regular local name=0A=
=0A=
# not local -- try mailer table lookup=0A=
R$* <@ $+ > $*		$: < $2 > $1 < @ $2 > $3	extract host name=0A=
R< $+ . > $*		$: < $1 > $2			strip trailing dot=0A=
R< $+ > $*		$: < $(mailertable $1 $) > $2	lookup=0A=
R< $~[ : $* > $* 	$>MailerToTriple < $1 : $2 > $3		check -- =
resolved?=0A=
R< $+ > $*		$: $>Mailertable <$1> $2		try domain=0A=
=0A=
# resolve remotely connected UUCP links (if any)=0A=
=0A=
# resolve fake top level domains by forwarding to other hosts=0A=
=0A=
=0A=
=0A=
# pass names that still have a host to a smarthost (if defined)=0A=
R$* < @ $* > $*		$: $>MailerToTriple < $S > $1 < @ $2 > $3	glue on =
smarthost name=0A=
=0A=
# deal with other remote names=0A=
R$* < @$* > $*		$#esmtp $@ $2 $: $1 < @ $2 > $3	user@host.domain=0A=
=0A=
# handle locally delivered names=0A=
R$=3DL			$#local $: @ $1		special local names=0A=
R$+			$#local $: $1			regular local names=0A=
=0A=
########################################################################=
###=0A=
###   Ruleset 5 -- special rewriting after aliases have been expanded   =
###=0A=
########################################################################=
###=0A=
=0A=
SLocal_localaddr=0A=
Slocaladdr=3D5=0A=
R$+			$: $1 $| $>"Local_localaddr" $1=0A=
R$+ $| $#$*		$#$2=0A=
R$+ $| $*		$: $1=0A=
=0A=
=0A=
=0A=
=0A=
# deal with plussed users so aliases work nicely=0A=
R$+ + *			$#local $@ $&h $: $1=0A=
R$+ + $*		$#local $@ + $2 $: $1 + *=0A=
=0A=
# prepend an empty "forward host" on the front=0A=
R$+			$: <> $1=0A=
=0A=
=0A=
# see if we have a relay or a hub=0A=
R< > $+			$: < $H > $1			try hub=0A=
R< > $+			$: < $R > $1			try relay=0A=
=0A=
R< > $+			$: < > < $1 <> $&h >		nope, restore +detail=0A=
R< > < $+ <> + $* >	$: < > < $1 + $2 >		check whether +detail=0A=
R< > < $+ <> $* >	$: < > < $1 >			else discard=0A=
R< > < $+ + $* > $*	   < > < $1 > + $2 $3		find the user part=0A=
R< > < $+ > + $*	$#local $@ $2 $: @ $1		strip the extra +=0A=
R< > < $+ >		$@ $1				no +detail=0A=
R$+			$: $1 <> $&h			add +detail back in=0A=
R$+ <> + $*		$: $1 + $2			check whether +detail=0A=
R$+ <> $*		$: $1				else discard=0A=
R< local : $* > $*	$: $>MailerToTriple < local : $1 > $2	no host =
extension=0A=
R< error : $* > $*	$: $>MailerToTriple < error : $1 > $2	no host =
extension=0A=
R< $- : $+ > $+		$: $>MailerToTriple < $1 : $2 > $3 < @ $2 >=0A=
R< $+ > $+		$@ $>MailerToTriple < $1 > $2 < @ $1 >=0A=
=0A=
###################################################################=0A=
###  Ruleset 90 -- try domain part of mailertable entry 	###=0A=
###################################################################=0A=
=0A=
SMailertable=3D90=0A=
R$* <$- . $+ > $*	$: $1$2 < $(mailertable .$3 $@ $1$2 $@ $2 $) > $4=0A=
R$* <$~[ : $* > $*	$>MailerToTriple < $2 : $3 > $4		check -- =
resolved?=0A=
R$* < . $+ > $* 	$@ $>Mailertable $1 . <$2> $3		no -- strip & try =
again=0A=
R$* < $* > $*		$: < $(mailertable . $@ $1$2 $) > $3	try "."=0A=
R< $~[ : $* > $*	$>MailerToTriple < $1 : $2 > $3		"." found?=0A=
R< $* > $*		$@ $2				no mailertable match=0A=
=0A=
###################################################################=0A=
###  Ruleset 95 -- canonify mailer:[user@]host syntax to triple	###=0A=
###################################################################=0A=
=0A=
SMailerToTriple=3D95=0A=
R< > $*				$@ $1			strip off null relay=0A=
R< error : $-.$-.$- : $+ > $* 	$#error $@ $1.$2.$3 $: $4=0A=
R< error : $- $+ > $*		$#error $@ $(dequote $1 $) $: $2=0A=
R< local : $* > $*		$>CanonLocal < $1 > $2=0A=
R< $- : $+ @ $+ > $*<$*>$*	$# $1 $@ $3 $: $2<@$3>	use literal user=0A=
R< $- : $+ > $*			$# $1 $@ $2 $: $3	try qualified mailer=0A=
R< $=3Dw > $*			$@ $2			delete local host=0A=
R< [ IPv6 $+ ] > $*		$#relay $@ $(dequote $1 $) $: $2	use unqualified =
mailer=0A=
R< $+ > $*			$#relay $@ $1 $: $2	use unqualified mailer=0A=
=0A=
###################################################################=0A=
###  Ruleset CanonLocal -- canonify local: syntax		###=0A=
###################################################################=0A=
=0A=
SCanonLocal=0A=
# strip local host from routed addresses=0A=
R< $* > < @ $+ > : $+		$@ $>Recurse $3=0A=
R< $* > $+ $=3DO $+ < @ $+ >	$@ $>Recurse $2 $3 $4=0A=
=0A=
# strip trailing dot from any host name that may appear=0A=
R< $* > $* < @ $* . >		$: < $1 > $2 < @ $3 >=0A=
=0A=
# handle local: syntax -- use old user, either with or without host=0A=
R< > $* < @ $* > $*		$#local $@ $1@$2 $: $1=0A=
R< > $+				$#local $@ $1    $: $1=0A=
=0A=
# handle local:user@host syntax -- ignore host part=0A=
R< $+ @ $+ > $* < @ $* >	$: < $1 > $3 < @ $4 >=0A=
=0A=
# handle local:user syntax=0A=
R< $+ > $* <@ $* > $*		$#local $@ $2@$3 $: $1=0A=
R< $+ > $* 			$#local $@ $2    $: $1=0A=
=0A=
###################################################################=0A=
###  Ruleset 93 -- convert header names to masqueraded form	###=0A=
###################################################################=0A=
=0A=
SMasqHdr=3D93=0A=
=0A=
=0A=
# do not masquerade anything in class N=0A=
R$* < @ $* $=3DN . >	$@ $1 < @ $2 $3 . >=0A=
=0A=
# special case the users that should be exposed=0A=
R$=3DE < @ *LOCAL* >	$@ $1 < @ $j . >		leave exposed=0A=
R$=3DE < @ $=3DM . >	$@ $1 < @ $2 . >=0A=
R$=3DE < @ $=3Dw . >	$@ $1 < @ $2 . >=0A=
=0A=
# handle domain-specific masquerading=0A=
R$* < @ $=3DM . > $*	$: $1 < @ $2 . @ $M > $3	convert masqueraded =
doms=0A=
R$* < @ $=3Dw . > $*	$: $1 < @ $2 . @ $M > $3=0A=
R$* < @ *LOCAL* > $*	$: $1 < @ $j . @ $M > $2=0A=
R$* < @ $+ @ > $*	$: $1 < @ $2 > $3		$M is null=0A=
R$* < @ $+ @ $+ > $*	$: $1 < @ $3 . > $4		$M is not null=0A=
=0A=
###################################################################=0A=
###  Ruleset 94 -- convert envelope names to masqueraded form	###=0A=
###################################################################=0A=
=0A=
SMasqEnv=3D94=0A=
R$* < @ *LOCAL* > $*	$: $1 < @ $j . > $2=0A=
=0A=
###################################################################=0A=
###  Ruleset 98 -- local part of ruleset zero (can be null)	###=0A=
###################################################################=0A=
=0A=
SParseLocal=3D98=0A=
=0A=
# addresses sent to foo@host.REDIRECT will give a 551 error code=0A=
R$* < @ $+ .REDIRECT. >		$: $1 < @ $2 . REDIRECT . > < ${opMode} >=0A=
R$* < @ $+ .REDIRECT. > <i>	$: $1 < @ $2 . REDIRECT. >=0A=
R$* < @ $+ .REDIRECT. > < $- >	$#error $@ 5.1.1 $: "551 User has moved; =
please try " <$1@$2>=0A=
=0A=
=0A=
# addresses sent to foo@host.REDIRECT will give a 551 error code=0A=
R$* < @ $+ .REDIRECT. >		$: $1 < @ $2 . REDIRECT . > < ${opMode} >=0A=
R$* < @ $+ .REDIRECT. > <i>	$: $1 < @ $2 . REDIRECT. >=0A=
R$* < @ $+ .REDIRECT. > < $- >	$#error $@ 5.1.1 $: "551 User has moved; =
please try " <$1@$2>=0A=
=0A=
=0A=
=0A=
=0A=
######################################################################=0A=
###  LookUpDomain -- search for domain in access database=0A=
###=0A=
###	Parameters:=0A=
###		<$1> -- key (domain name)=0A=
###		<$2> -- default (what to return if not found in db)=0A=
###		<$3> -- passthru (additional data passed unchanged through)=0A=
###		<$4> -- mark (must be <(!|+) single-token>)=0A=
###			! does lookup only with tag=0A=
###			+ does lookup with and without tag=0A=
######################################################################=0A=
=0A=
SLookUpDomain=0A=
R<[IPv6 $-]> <$+> <$*> <$*>	$: <[$(dequote $1 $)]> <$2> <$3> <$4>=0A=
R<$*> <$+> <$*> <$- $->		$: < $(access $5:$1 $: ? $) > <$1> <$2> <$3> =
<$4 $5>=0A=
R<?> <$+> <$+> <$*> <+ $*>	$: < $(access $1 $: ? $) > <$1> <$2> <$3> <+ =
$4>=0A=
R<?> <[$+.$-]> <$+> <$*> <$*>	$@ $>LookUpDomain <[$1]> <$3> <$4> =
<$5>=0A=
R<?> <[$+:$-]> <$+> <$*> <$*>	$: $>LookUpDomain <[$1]> <$3> <$4> =
<$5>=0A=
R<?> <$+.$+> <$+> <$*> <$*>	$@ $>LookUpDomain <$2> <$3> <$4> <$5>=0A=
R<?> <$+> <$+> <$*> <$*>	$@ <$2> <$3>=0A=
R<$*> <$+> <$+> <$*> <$*>	$@ <$1> <$4>=0A=
=0A=
######################################################################=0A=
###  LookUpAddress -- search for host address in access database=0A=
###=0A=
###	Parameters:=0A=
###		<$1> -- key (dot quadded host address)=0A=
###		<$2> -- default (what to return if not found in db)=0A=
###		<$3> -- passthru (additional data passed through)=0A=
###		<$4> -- mark (must be <(!|+) single-token>)=0A=
###			! does lookup only with tag=0A=
###			+ does lookup with and without tag=0A=
######################################################################=0A=
=0A=
SLookUpAddress=0A=
R<$+> <$+> <$*> <$- $+>		$: < $(access $5:$1 $: ? $) > <$1> <$2> <$3> =
<$4 $5>=0A=
R<?> <$+> <$+> <$*> <+ $+>	$: < $(access $1 $: ? $) > <$1> <$2> <$3> <+ =
$4>=0A=
R<?> <$+:$-> <$+> <$*> <$*>	$@ $>LookUpAddress <$1> <$3> <$4> <$5>=0A=
R<?> <$+.$-> <$+> <$*> <$*>	$@ $>LookUpAddress <$1> <$3> <$4> <$5>=0A=
R<?> <$+> <$+> <$*> <$*>	$@ <$2> <$3>=0A=
R<$*> <$+> <$+> <$*> <$*>	$@ <$1> <$4>=0A=
=0A=
######################################################################=0A=
###  CanonAddr --	Convert an address into a standard form for=0A=
###			relay checking.  Route address syntax is=0A=
###			crudely converted into a %-hack address.=0A=
###=0A=
###	Parameters:=0A=
###		$1 -- full recipient address=0A=
###=0A=
###	Returns:=0A=
###		parsed address, not in source route form=0A=
######################################################################=0A=
=0A=
SCanonAddr=0A=
R$*			$: $>Parse0 $>canonify $1	make domain canonical=0A=
=0A=
=0A=
######################################################################=0A=
###  ParseRecipient --	Strip off hosts in $=3DR as well as possibly=0A=
###			$* $=3Dm or the access database.=0A=
###			Check user portion for host separators.=0A=
###=0A=
###	Parameters:=0A=
###		$1 -- full recipient address=0A=
###=0A=
###	Returns:=0A=
###		parsed, non-local-relaying address=0A=
######################################################################=0A=
=0A=
SParseRecipient=0A=
R$*				$: <?> $>CanonAddr $1=0A=
R<?> $* < @ $* . >		<?> $1 < @ $2 >			strip trailing dots=0A=
R<?> $- < @ $* >		$: <?> $(dequote $1 $) < @ $2 >	dequote local part=0A=
=0A=
# if no $=3DO character, no host in the user portion, we are done=0A=
R<?> $* $=3DO $* < @ $* >		$: <NO> $1 $2 $3 < @ $4>=0A=
R<?> $*				$@ $1=0A=
=0A=
=0A=
=0A=
R<NO> $* < @ $* $=3DR >		$: <RELAY> $1 < @ $2 $3 >=0A=
R<NO> $* < @ $+ >		$: $>LookUpDomain <$2> <NO> <$1 < @ $2 >> <+To>=0A=
R<$+> <$+>			$: <$1> $2=0A=
=0A=
=0A=
R<RELAY> $* < @ $* >		$@ $>ParseRecipient $1=0A=
R<$-> $*			$@ $2=0A=
=0A=
=0A=
######################################################################=0A=
###  check_relay -- check hostname/address on SMTP startup=0A=
######################################################################=0A=
=0A=
SLocal_check_relay=0A=
Scheck_relay=0A=
R$*			$: $1 $| $>"Local_check_relay" $1=0A=
R$* $| $* $| $#$*	$#$3=0A=
R$* $| $* $| $*		$@ $>"Basic_check_relay" $1 $| $2=0A=
=0A=
SBasic_check_relay=0A=
# check for deferred delivery mode=0A=
R$*			$: < ${deliveryMode} > $1=0A=
R< d > $*		$@ deferred=0A=
R< $* > $*		$: $2=0A=
=0A=
R$+ $| $+		$: $>LookUpDomain < $1 > <?> < $2 > <+Connect>=0A=
R<?> <$+>		$: $>LookUpAddress < $1 > <?> < $1 > <+Connect>	no: another =
lookup=0A=
R<?> < $+ >		$: $1					found nothing=0A=
R<$=3D{Accept}> < $* >	$@ $1				return value of lookup=0A=
R<REJECT> $*		$#error $@ 5.7.1 $: "550 Access denied"=0A=
R<DISCARD> $*		$#discard $: discard=0A=
R<ERROR:$-.$-.$-:$+> <$*>	$#error $@ $1.$2.$3 $: $4=0A=
R<ERROR:$+> <$*>		$#error $: $1=0A=
R<$+> <$*>		$#error $: $1=0A=
=0A=
=0A=
# DNS based IP address spam list rbl.maps.vix.com=0A=
R$*			$: $&{client_addr}=0A=
R::ffff:$-.$-.$-.$-	$: <?> $(host $4.$3.$2.$1.rbl.maps.vix.com. $: OK =
$)=0A=
R$-.$-.$-.$-		$: <?> $(host $4.$3.$2.$1.rbl.maps.vix.com. $: OK $)=0A=
R<?>OK			$: OKSOFAR=0A=
R<?>$+			$#error $@ 5.7.1 $: "550 Mail from " $&{client_addr} " refused =
by blackhole site rbl.maps.vix.com"=0A=
=0A=
=0A=
######################################################################=0A=
###  check_mail -- check SMTP `MAIL FROM:' command argument=0A=
######################################################################=0A=
=0A=
SLocal_check_mail=0A=
Scheck_mail=0A=
R$*			$: $1 $| $>"Local_check_mail" $1=0A=
R$* $| $#$*		$#$2=0A=
R$* $| $*		$@ $>"Basic_check_mail" $1=0A=
=0A=
SBasic_check_mail=0A=
# check for deferred delivery mode=0A=
R$*			$: < ${deliveryMode} > $1=0A=
R< d > $*		$@ deferred=0A=
R< $* > $*		$: $2=0A=
=0A=
# authenticated?=0A=
R$*			$: $1 $| $>"tls_client" $&{verify} $| MAIL=0A=
R$* $| $#$+		$#$2=0A=
R$* $| $*		$: $1=0A=
=0A=
R<>			$@ <OK>			we MUST accept <> (RFC 1123)=0A=
R$+			$: <?> $1=0A=
R<?><$+>		$: <@> <$1>=0A=
R<?>$+			$: <@> <$1>=0A=
R$*			$: $&{daemon_flags} $| $1=0A=
R$* f $* $| <@> < $* @ $- >	$: < ? $&{client_name} > < $3 @ $4 >=0A=
R$* u $* $| <@> < $* >	$: <?> < $3 >=0A=
R$* $| $*		$: $2=0A=
# handle case of @localhost on address=0A=
R<@> < $* @ localhost >	$: < ? $&{client_name} > < $1 @ localhost >=0A=
R<@> < $* @ [127.0.0.1] >=0A=
			$: < ? $&{client_name} > < $1 @ [127.0.0.1] >=0A=
R<@> < $* @ localhost.$m >=0A=
			$: < ? $&{client_name} > < $1 @ localhost.$m >=0A=
R<@> < $* @ localhost.UUCP >=0A=
			$: < ? $&{client_name} > < $1 @ localhost.UUCP >=0A=
R<@> $*			$: $1			no localhost as domain=0A=
R<? $=3Dw> $*		$: $2			local client: ok=0A=
R<? $+> <$+>		$#error $@ 5.5.4 $: "501 Real domain name required for =
sender address"=0A=
R<?> $*			$: $1=0A=
R$*			$: <?> $>CanonAddr $1		canonify sender address and mark it=0A=
R<?> $* < @ $+ . >	<?> $1 < @ $2 >			strip trailing dots=0A=
# handle non-DNS hostnames (*.bitnet, *.decnet, *.uucp, etc)=0A=
R<?> $* < @ $* $=3DP >	$: <OK> $1 < @ $2 $3 >=0A=
R<?> $* < @ $+ >	$: <? $(resolve $2 $: $2 <PERM> $) > $1 < @ $2 >=0A=
R<? $* <$->> $* < @ $+ >=0A=
			$: <$2> $3 < @ $4 >=0A=
=0A=
# check sender address: user@address, user@, address=0A=
R<$+> $+ < @ $* >	$: @<$1> <$2 < @ $3 >> $| <F:$2@$3> <U:$2@> <H:$3>=0A=
R<$+> $+		$: @<$1> <$2> $| <U:$2@>=0A=
R@ <$+> <$*> $| <$+>	$: <@> <$1> <$2> $| $>SearchList <+From> $| <$3> =
<>=0A=
R<@> <$+> <$*> $| <$*>	$: <$3> <$1> <$2>		reverse result=0A=
# retransform for further use=0A=
R<?> <$+> <$*>		$: <$1> $2	no match=0A=
R<$+> <$+> <$*>		$: <$1> $3	relevant result, keep it=0A=
=0A=
# handle case of no @domain on address=0A=
R<?> $*			$: $&{daemon_flags} $| <?> $1=0A=
R$* u $* $| <?> $*	$: <OK> $3=0A=
R$* $| $*		$: $2=0A=
R<?> $*			$: < ? $&{client_name} > $1=0A=
R<?> $*			$@ <OK>				...local unqualed ok=0A=
R<? $+> $*		$#error $@ 5.5.4 $: "501 Domain name required for sender =
address " $&f=0A=
							...remote is not=0A=
# check results=0A=
R<?> $*			$: @ $1		mark address: nothing known about it=0A=
R<OK> $*		$@ <OK>=0A=
R<TEMP> $*		$#error $@ 4.1.8 $: "451 Domain of sender address " $&f " =
does not resolve"=0A=
R<PERM> $*		$#error $@ 5.1.8 $: "501 Domain of sender address " $&f " =
does not exist"=0A=
R<$=3D{Accept}> $*	$# $1=0A=
R<DISCARD> $*		$#discard $: discard=0A=
R<REJECT> $*		$#error $@ 5.7.1 $: "550 Access denied"=0A=
R<ERROR:$-.$-.$-:$+> $*		$#error $@ $1.$2.$3 $: $4=0A=
R<ERROR:$+> $*		$#error $: $1=0A=
R<$+> $*		$#error $: $1		error from access db=0A=
=0A=
######################################################################=0A=
###  check_rcpt -- check SMTP `RCPT TO:' command argument=0A=
######################################################################=0A=
=0A=
SLocal_check_rcpt=0A=
Scheck_rcpt=0A=
R$*			$: $1 $| $>"Local_check_rcpt" $1=0A=
R$* $| $#$*		$#$2=0A=
R$* $| $*		$@ $>"Basic_check_rcpt" $1=0A=
=0A=
SBasic_check_rcpt=0A=
# check for deferred delivery mode=0A=
R$*			$: < ${deliveryMode} > $1=0A=
R< d > $*		$@ deferred=0A=
R< $* > $*		$: $2=0A=
=0A=
=0A=
R$*			$: $>ParseRecipient $1		strip relayable hosts=0A=
=0A=
=0A=
=0A=
# blacklist local users or any host from receiving mail=0A=
R$*			$: <?> $1=0A=
R<?> $+ < @ $=3Dw >	$: <> <$1 < @ $2 >> $| <F:$1@$2> <U:$1@> <H:$2>=0A=
R<?> $+ < @ $* >	$: <> <$1 < @ $2 >> $| <F:$1@$2> <H:$2>=0A=
R<?> $+			$: <> <$1> $| <U:$1@>=0A=
R<> <$*> $| <$+>	$: <@> <$1> $| $>SearchList <+To> $| <$2> <>=0A=
R<@> <$*> $| <$*>	$: <$2> <$1>		reverse result=0A=
R<?> <$*>		$: @ $1		mark address as no match=0A=
R<$=3D{Accept}> <$*>	$: @ $2		mark address as no match=0A=
=0A=
R<REJECT> $*		$#error $@ 5.2.1 $: "550 Mailbox disabled for this =
recipient"=0A=
R<DISCARD> $*		$#discard $: discard=0A=
R<ERROR:$-.$-.$-:$+> $*		$#error $@ $1.$2.$3 $: $4=0A=
R<ERROR:$+> $*		$#error $: $1=0A=
R<$+> $*		$#error $: $1		error from access db=0A=
R@ $*			$1		remove mark=0A=
=0A=
=0A=
# authenticated?=0A=
R$*		$: $1 $| $>RelayAuth $1 $| $&{verify}	client authenticated?=0A=
R$* $| $# $+		$# $2				error/ok?=0A=
R$* $| $*		$: $1				no=0A=
=0A=
# authenticated by a trusted mechanism?=0A=
R$*			$: $1 $| $&{auth_type}=0A=
R$* $|			$: $1=0A=
R$* $| $=3D{TrustAuthMech}	$# RELAYAUTH=0A=
R$* $| $*		$: $1=0A=
# anything terminating locally is ok=0A=
R$+ < @ $=3Dw >		$@ RELAYTO=0A=
R$+ < @ $* $=3DR >	$@ RELAYTO=0A=
R$+ < @ $+ >		$: $>LookUpDomain <$2> <?> <$1 < @ $2 >> <+To>=0A=
R<RELAY> $*		$@ RELAYTO=0A=
R<$*> <$*>		$: $2=0A=
=0A=
=0A=
=0A=
# check for local user (i.e. unqualified address)=0A=
R$*			$: <?> $1=0A=
R<?> $* < @ $+ >	$: <REMOTE> $1 < @ $2 >=0A=
# local user is ok=0A=
R<?> $+			$@ RELAYTOLOCAL=0A=
R<$+> $*		$: $2=0A=
=0A=
# anything originating locally is ok=0A=
# check IP address=0A=
R$*			$: $&{client_addr}=0A=
R$@			$@ RELAYFROM		originated locally=0A=
R0			$@ RELAYFROM		originated locally=0A=
R$=3DR $*			$@ RELAYFROM		relayable IP address=0A=
R$*			$: $>LookUpAddress <$1> <?> <$1> <+Connect>=0A=
R<RELAY> $* 		$@ RELAYFROM		relayable IP address=0A=
R<$*> <$*>		$: $2=0A=
R$*			$: [ $1 ]		put brackets around it...=0A=
R$=3Dw			$@ RELAYFROM		... and see if it is local=0A=
=0A=
=0A=
# check client name: first: did it resolve?=0A=
R$*			$: < $&{client_resolve} >=0A=
R<TEMP>			$#error $@ 4.7.1 $: "450 Relaying temporarily denied. Cannot =
resolve PTR record for " $&{client_addr}=0A=
R<FORGED>		$#error $@ 5.7.1 $: "550 Relaying denied. IP name possibly =
forged " $&{client_name}=0A=
R<FAIL>			$#error $@ 5.7.1 $: "550 Relaying denied. IP name lookup =
failed " $&{client_name}=0A=
R$*			$: <?> $&{client_name}=0A=
# pass to name server to make hostname canonical=0A=
R<?> $* $~P 		$:<?>  $[ $1 $2 $]=0A=
R$* .			$1			strip trailing dots=0A=
R<?>			$@ RELAYFROM=0A=
R<?> $=3Dw		$@ RELAYFROM=0A=
R<?> $* $=3DR			$@ RELAYFROM=0A=
R<?> $*			$: $>LookUpDomain <$1> <?> <$1> <+Connect>=0A=
R<RELAY> $*		$@ RELAYFROM=0A=
R<$*> <$*>		$: $2=0A=
=0A=
# anything else is bogus=0A=
R$*			$#error $@ 5.7.1 $: "550 Relaying denied"=0A=
=0A=
######################################################################=0A=
###  SearchList: search a list of items in the access map=0A=
###	Parameters:=0A=
###		<exact tag> $| <mark:address> <mark:address> ... <>=0A=
###	where "exact" is either "+" or "!":=0A=
###	<+ TAG>	lookup with and w/o tag=0A=
###	<! TAG>	lookup with tag=0A=
###	possible values for "mark" are:=0A=
###		H: recursive host lookup (LookUpDomain)=0A=
###		E: exact lookup, no modifications=0A=
###		F: full lookup, try user+ext@domain and user@domain=0A=
###		U: user lookup, try user+ext and user (input must have trailing =
@)=0A=
###	return: <RHS of lookup> or <?> (not found)=0A=
######################################################################=0A=
=0A=
# class with valid marks for SearchList=0A=
C{src}E F H U=0A=
SSearchList=0A=
# mark H: lookup domain=0A=
R<$+> $| <H:$+> <$*>		$: <$1> $| <@> $>LookUpDomain <$2> <?> <$3> =
<$1>=0A=
R<$+> $| <@> <$+> <$*>		$: <$1> $| <$2> <$3>=0A=
R<$- $-> $| <$=3D{src}:$+> <$*>	$: <$1 $2> $| <$(access $2:$4 $: $3:$4 =
$)> <$5>=0A=
R<+ $-> $| <$=3D{src}:$+> <$*>	$: <+ $1> $| <$(access $3 $: $2:$3 $)> =
<$4>=0A=
R<$- $-> $| <F:$* + $*@$+> <$*>	$: <$1 $2> $| <$(access $2:$3@$5 $: =
F:$3 + $4@$5$)> <$6>=0A=
R<+ $-> $| <F:$* + $*@$+> <$*>	$: <+ $1> $| <$(access $2@$4 $: F:$2 + =
$3@$4$)> <$5>=0A=
R<$- $-> $| <U:$* + $*> <$*>	$: <$1 $2> $| <$(access $2:$3@ $: U:$3 + =
$4$)> <$5>=0A=
R<+ $-> $| <U:$* + $*> <$*>	$: <+ $1> $| <$(access $2@ $: U:$2 + $3$)> =
<$4>=0A=
R<$+> $| <$=3D{src}:$+> <$+>	$@ $>SearchList <$1> $| <$4>=0A=
R<$+> $| <$=3D{src}:$+> <>	$@ <?>=0A=
R<$+> $| <$+> <$*>		$@ <$2>=0A=
R<$+> $| <$+>			$@ <$2>=0A=
=0A=
# is user trusted to authenticate as someone else?=0A=
Strust_auth=0A=
R$*			$: $&{auth_type} $| $1=0A=
# required by RFC 2554 section 4.=0A=
R$@ $| $*		$#error $@ 5.7.1 $: "550 not authenticated"=0A=
R$* $| $&{auth_authen}		$@ identical=0A=
R$* $| <$&{auth_authen}>	$@ identical=0A=
R$* $| $*		$: $1 $| $>"Local_trust_auth" $1=0A=
R$* $| $#$*		$#$2=0A=
R$*			$#error $@ 5.7.1 $: "550 " $&{auth_authen} " not allowed to act =
as " $&{auth_author}=0A=
=0A=
SLocal_trust_auth=0A=
=0A=
=0A=
# is connection with client "good" enough? (done in server)=0A=
# input: ${verify} $| (MAIL|STARTTLS)=0A=
Stls_client=0A=
R$* $| $*	$: $1 $| $>LookUpDomain <$&{client_name}> <?> <> <! =
TLS_Clt>=0A=
R$* $| <?>$*	$: $1 $| $>LookUpAddress <$&{client_addr}> <?> <> <! =
TLS_Clt>=0A=
R$* $| <?>$*	$: $1 $| <$(access TLS_Clt: $: ? $)>=0A=
R$*		$@ $>"tls_connection" $1=0A=
=0A=
# is connection with server "good" enough? (done in client)=0A=
# input: ${verify}=0A=
Stls_server=0A=
R$*		$: $1 $| $>LookUpDomain <$&{server_name}> <?> <> <! TLS_Srv>=0A=
R$* $| <?>$*	$: $1 $| $>LookUpAddress <$&{server_addr}> <?> <> <! =
TLS_Srv>=0A=
R$* $| <?>$*	$: $1 $| <$(access TLS_Srv: $: ? $)>=0A=
R$*		$@ $>"tls_connection" $1=0A=
=0A=
Stls_connection=0A=
R$* $| <$*>$*			$: $1 $| <$2>=0A=
R$* $| <PERM + $=3D{tls} $*>	$: $1 $| <503:5.7.0> <$2 $3>=0A=
R$* $| <TEMP + $=3D{tls} $*>	$: $1 $| <403:4.7.0> <$2 $3>=0A=
R$* $| <$=3D{tls} $*>		$: $1 $| <403:4.7.0> <$2 $3>=0A=
RSOFTWARE $| <$-:$+> $* 	$#error $@ $2 $: $1 " TLS handshake =
failed."=0A=
RSOFTWARE $| $* 		$#error $@ 4.7.0 $: "403 TLS handshake failed."=0A=
R$* $| <$*> <VERIFY>		$: <$2> <VERIFY> $1=0A=
R$* $| <$*> <$=3D{tls}:$->$*	$: <$2> <$3:$4> $1=0A=
R$* $| $*			$@ OK=0A=
# authentication required: give appropriate error=0A=
# other side did authenticate (via STARTTLS)=0A=
R<$*><VERIFY> OK		$@ OK=0A=
R<$*><VERIFY:$-> OK		$: <$1> <REQ:$2>=0A=
R<$*><ENCR:$-> $*		$: <$1> <REQ:$2>=0A=
R<$-:$+><VERIFY $*>		$#error $@ $2 $: $1 " authentication required"=0A=
R<$-:$+><VERIFY $*> FAIL	$#error $@ $2 $: $1 " authentication =
failed"=0A=
R<$-:$+><VERIFY $*> NO		$#error $@ $2 $: $1 " not authenticated"=0A=
R<$-:$+><VERIFY $*> NONE	$#error $@ $2 $: $1 " other side does not =
support STARTTLS"=0A=
R<$-:$+><VERIFY $*> $+		$#error $@ $2 $: $1 " authentication failure " =
$4=0A=
R<$*><REQ:$->			$: <$1> <REQ:$2> $>max $&{cipher_bits} : =
$&{auth_ssf}=0A=
R<$*><REQ:$-> $-		$: <$1> <$2:$3> $(arith l $@ $3 $@ $2 $)=0A=
R<$-:$+><$-:$-> TRUE		$#error $@ $2 $: $1 " encryption too weak " $4 " =
less than " $3=0A=
=0A=
Smax=0A=
R:		$: 0=0A=
R:$-		$: $1=0A=
R$-:		$: $1=0A=
R$-:$-		$: $(arith l $@ $1 $@ $2 $) : $1 : $2=0A=
RTRUE:$-:$-	$: $2=0A=
R$-:$-:$-	$: $2=0A=
=0A=
SRelayAuth=0A=
# authenticated?=0A=
R$* $| OK		$: $1=0A=
R$* $| $*		$@ NO		not authenticated=0A=
R$*			$: $1 $| $&{cert_issuer}=0A=
R$* $| $+		$: $1 $| $(access CERTISSUER:$2 $)=0A=
R$* $| RELAY		$# RELAYCERTISSUER=0A=
R$* $| SUBJECT		$: $1 $| <@> $&{cert_subject}=0A=
R$* $| <@> $+		$: $1 $| <@> $(access CERTSUBJECT:$2 $)=0A=
R$* $| <@> RELAY	$# RELAYCERTSUBJECT=0A=
R$* $| $*		$: $1=0A=
=0A=
=0A=
#=0C=0A=
######################################################################=0A=
######################################################################=0A=
#####=0A=
#####			MAILER DEFINITIONS=0A=
#####=0A=
######################################################################=0A=
######################################################################=0A=
=0A=
=0A=
##################################################=0A=
###   Local and Program Mailer specification   ###=0A=
##################################################=0A=
=0A=
#####  $Id: local.m4,v 8.50.16.2 2000/09/17 17:04:22 gshapiro Exp $  =
#####=0A=
=0A=
#=0A=
#  Envelope sender rewriting=0A=
#=0A=
SEnvFromL=3D10=0A=
R<@>			$n			errors to mailer-daemon=0A=
R@ <@ $*>		$n			temporarily bypass Sun bogosity=0A=
R$+			$: $>AddDomain $1	add local domain if needed=0A=
R$*			$: $>MasqEnv $1		do masquerading=0A=
=0A=
#=0A=
#  Envelope recipient rewriting=0A=
#=0A=
SEnvToL=3D20=0A=
R$+ < @ $* >		$: $1			strip host part=0A=
=0A=
#=0A=
#  Header sender rewriting=0A=
#=0A=
SHdrFromL=3D30=0A=
R<@>			$n			errors to mailer-daemon=0A=
R@ <@ $*>		$n			temporarily bypass Sun bogosity=0A=
R$+			$: $>AddDomain $1	add local domain if needed=0A=
R$*			$: $>MasqHdr $1		do masquerading=0A=
=0A=
#=0A=
#  Header recipient rewriting=0A=
#=0A=
SHdrToL=3D40=0A=
R$+			$: $>AddDomain $1	add local domain if needed=0A=
R$* < @ *LOCAL* > $*	$: $1 < @ $j . > $2=0A=
=0A=
#=0A=
#  Common code to add local domain name (only if always-add-domain)=0A=
#=0A=
SAddDomain=3D50=0A=
R$* < @ $* > $* 	$@ $1 < @ $2 > $3	already fully qualified=0A=
R$+			$@ $1 < @ *LOCAL* >	add local qualification=0A=
=0A=
Mlocal,		P=3D/usr/bin/procmail, F=3DlsDFMAw5:/|@qSPfhn9, =
S=3DEnvFromL/HdrFromL, R=3DEnvToL/HdrToL,=0A=
		T=3DDNS/RFC822/X-Unix,=0A=
		A=3Dprocmail -Y -a $h -d $u=0A=
Mprog,		P=3D/usr/sbin/smrsh, F=3DlsDFMoqeu9, S=3DEnvFromL/HdrFromL, =
R=3DEnvToL/HdrToL, D=3D$z:/,=0A=
		T=3DX-Unix/X-Unix/X-Unix,=0A=
		A=3Dsmrsh -c $u=0A=
=0A=
#####################################=0A=
###   SMTP Mailer specification   ###=0A=
#####################################=0A=
=0A=
#####  $Id: smtp.m4,v 8.56.2.1.2.3 2000/09/25 13:53:27 ca Exp $  =
#####=0A=
=0A=
#=0A=
#  common sender and masquerading recipient rewriting=0A=
#=0A=
SMasqSMTP=3D61=0A=
R$* < @ $* > $*		$@ $1 < @ $2 > $3		already fully qualified=0A=
R$+			$@ $1 < @ *LOCAL* >		add local qualification=0A=
=0A=
#=0A=
#  convert pseudo-domain addresses to real domain addresses=0A=
#=0A=
SPseudoToReal=3D51=0A=
=0A=
# pass <route-addr>s through=0A=
R< @ $+ > $*		$@ < @ $1 > $2			resolve <route-addr>=0A=
=0A=
# output fake domains as user%fake@relay=0A=
=0A=
# do UUCP heuristics; note that these are shared with UUCP mailers=0A=
R$+ < @ $+ .UUCP. >	$: < $2 ! > $1			convert to UUCP form=0A=
R$+ < @ $* > $*		$@ $1 < @ $2 > $3		not UUCP form=0A=
=0A=
# leave these in .UUCP form to avoid further tampering=0A=
R< $&h ! > $- ! $+	$@ $2 < @ $1 .UUCP. >=0A=
R< $&h ! > $-.$+ ! $+	$@ $3 < @ $1.$2 >=0A=
R< $&h ! > $+		$@ $1 < @ $&h .UUCP. >=0A=
R< $+ ! > $+		$: $1 ! $2 < @ $Y >		use UUCP_RELAY=0A=
R$+ < @ $+ : $+ >	$@ $1 < @ $3 >			strip mailer: part=0A=
R$+ < @ >		$: $1 < @ *LOCAL* >		if no UUCP_RELAY=0A=
=0A=
=0A=
#=0A=
#  envelope sender rewriting=0A=
#=0A=
SEnvFromSMTP=3D11=0A=
R$+			$: $>PseudoToReal $1		sender/recipient common=0A=
R$* :; <@>		$@				list:; special case=0A=
R$*			$: $>MasqSMTP $1		qualify unqual'ed names=0A=
R$+			$: $>MasqEnv $1			do masquerading=0A=
=0A=
=0A=
#=0A=
#  envelope recipient rewriting --=0A=
#  also header recipient if not masquerading recipients=0A=
#=0A=
SEnvToSMTP=3D21=0A=
R$+			$: $>PseudoToReal $1		sender/recipient common=0A=
R$+			$: $>MasqSMTP $1		qualify unqual'ed names=0A=
R$* < @ *LOCAL* > $*	$: $1 < @ $j . > $2=0A=
=0A=
#=0A=
#  header sender and masquerading header recipient rewriting=0A=
#=0A=
SHdrFromSMTP=3D31=0A=
R$+			$: $>PseudoToReal $1		sender/recipient common=0A=
R:; <@>			$@				list:; special case=0A=
=0A=
# do special header rewriting=0A=
R$* <@> $*		$@ $1 <@> $2			pass null host through=0A=
R< @ $* > $*		$@ < @ $1 > $2			pass route-addr through=0A=
R$*			$: $>MasqSMTP $1		qualify unqual'ed names=0A=
R$+			$: $>MasqHdr $1			do masquerading=0A=
=0A=
=0A=
#=0A=
#  relay mailer header masquerading recipient rewriting=0A=
#=0A=
SMasqRelay=3D71=0A=
R$+			$: $>MasqSMTP $1=0A=
R$+			$: $>MasqHdr $1=0A=
=0A=
Msmtp,		P=3D[IPC], F=3DmDFMuX, S=3DEnvFromSMTP/HdrFromSMTP, =
R=3DEnvToSMTP, E=3D\r\n, L=3D990,=0A=
		T=3DDNS/RFC822/SMTP,=0A=
		A=3DTCP $h=0A=
Mesmtp,		P=3D[IPC], F=3DmDFMuXa, S=3DEnvFromSMTP/HdrFromSMTP, =
R=3DEnvToSMTP, E=3D\r\n, L=3D990,=0A=
		T=3DDNS/RFC822/SMTP,=0A=
		A=3DTCP $h=0A=
Msmtp8,		P=3D[IPC], F=3DmDFMuX8, S=3DEnvFromSMTP/HdrFromSMTP, =
R=3DEnvToSMTP, E=3D\r\n, L=3D990,=0A=
		T=3DDNS/RFC822/SMTP,=0A=
		A=3DTCP $h=0A=
Mdsmtp,		P=3D[IPC], F=3DmDFMuXa%, S=3DEnvFromSMTP/HdrFromSMTP, =
R=3DEnvToSMTP, E=3D\r\n, L=3D990,=0A=
		T=3DDNS/RFC822/SMTP,=0A=
		A=3DTCP $h=0A=
Mrelay,		P=3D[IPC], F=3DmDFMuXa8, S=3DEnvFromSMTP/HdrFromSMTP, =
R=3DMasqSMTP, E=3D\r\n, L=3D2040,=0A=
		T=3DDNS/RFC822/SMTP,=0A=
		A=3DTCP $h=0A=
=0A=
=0A=
######################*****##############=0A=
###   PROCMAIL Mailer specification   ###=0A=
##################*****##################=0A=
=0A=
#####  $Id: procmail.m4,v 8.20 1999/10/18 04:57:54 gshapiro Exp $  =
#####=0A=
=0A=
Mprocmail,	P=3D/usr/bin/procmail, F=3DDFMSPhnu9, =
S=3DEnvFromSMTP/HdrFromSMTP, R=3DEnvToSMTP/HdrFromSMTP,=0A=
		T=3DDNS/RFC822/X-Unix,=0A=
		A=3Dprocmail -Y -m $h $f $u=0A=
=0A=

------_=_NextPart_000_01C0860F.56771AD2--


From owner-fwtk-users@ex.tis.com Thu Jan 25 11:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA05411
	Thu, 25 Jan 2001 11:34:20 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA10763;
	Thu, 25 Jan 2001 08:35:22 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 25 Jan 2001 07:20:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA01671
	for fwtk-users-outgoing; Thu, 25 Jan 2001 07:20:50 -0800 (PST)
Mime-Version: 1.0
Date: Thu, 25 Jan 2001 15:15:17 +0000
Message-ID: <000400E3.C22300@it.glasgow.gov.uk>
From: derek.torrance@it.glasgow.gov.uk (Derek Torrance)
Subject: smap anti-relaying - outward-bound mail rejected
To: fwtk-users@lists.nai.com
Content-Transfer-Encoding: 7bit
Content-Description: cc:Mail note part
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="US-ASCII"
Content-Length: 1818

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

     
     We have a working smap/sendmail configuration to which I have applied 
     the yao-smap patch. This has stopped messages from being relayed and 
     incoming messages are ok but outward-bound messages from valid domains 
     are also being rejected:
     
        220 corpinter1 SMTP/smap Ready.
        helo corpinter1
        250 (corpinter1) pleased to meet you.
        mail from:derek.torrance@it.glasgow.gov.uk
        250 derek.torrance@it.glasgow.gov.uk... Sender Ok
        rcpt to:derektorrance@hotmail.com
        551 Recipient must be in the local domain(s).
        501 Mail not local. Closing connection.
     
     I've spent the last few hours going through the mailing list archives 
     and others with this problem have been advised to make entries in the 
     netperm-table like these:
     
        smap: domains quanta.co.nz *.quanta.co.nz
        smap: hosts quanta.co.nz *.quanta.co.nz
     
     But that's pretty much what I was using:
     
        # mail access
        smap, smapd:            userid mail
        smap, smapd:            directory /var/spool/smap
        smapd:                  executable /usr/local/etc/smapd
        smapd:                  sendmail /usr/local/etc/sendmail-save
        smapd:                  baddir /var/spool/smap/undelivered
        smap:                   timeout 3600
        smap:                   domains glasgow.gov.uk *.glasgow.gov.uk
        smap:                   hosts glasgow.gov.uk *.glasgow.gov.uk
     
     My guess is I've missed something pretty basic somewhere but I'm 
     tearing my hair out trying to figure out what. Does anyone have any 
     ideas?
     
     Thanks,
     Derek

From owner-fwtk-users@ex.tis.com Fri Jan 26 18:37 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA17129
	Fri, 26 Jan 2001 18:37:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA10635;
	Fri, 26 Jan 2001 15:39:09 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 26 Jan 2001 14:29:27 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA02362
	for fwtk-users-outgoing; Fri, 26 Jan 2001 14:29:21 -0800 (PST)
Message-ID: <3A71FA23.38BC91C8@neonet.lv>
Date: Sat, 27 Jan 2001 00:28:51 +0200
From: anri priede <anri@neonet.lv>
X-Mailer: Mozilla 4.7C-SGI [en] (X11; I; IRIX64 6.5 IP30)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: compile problem
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="------------D8622E70EA89337F6862F02C"
Content-Length: 10296

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------D8622E70EA89337F6862F02C
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Hi all,

I got fwtk2.1 compile problem on SGI running IRIX 6.5.10f
Please find attached text file with shell output.
I am not a programmer, so any directions how to get it
compiled will be highly appreciated.

Maybe somebody has already compiled fwtk2.1 for SGI?

Thanks in advance.

Anri Priede
--------------D8622E70EA89337F6862F02C
Content-Type: text/plain; charset=us-ascii;
 name="gmake_shell_output.txt"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline;
 filename="gmake_shell_output.txt"

Grafika-6 64% gmake
for a in lib auth smap smapd netacl plug-gw ftp-gw tn-gw rlogin-gw http-gw ; do \
        ( cd $a; echo all: `pwd`; gmake all ); \
done
all: /usr/people/anri/fwtk2.1/fwtk/lib
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/lib'
gcc -I.. -g    -c -o config.o config.c
gcc -I.. -g    -c -o daemon.o daemon.c
gcc -I.. -g    -c -o pname.o pname.c
pname.c: In function `peername':
pname.c:53: warning: passing arg 2 of `strncpy' makes pointer from integer without a cast
gcc -I.. -g    -c -o nama.o nama.c
gcc -I.. -g    -c -o mapu.o mapu.c
gcc -I.. -g    -c -o mapg.o mapg.c
gcc -I.. -g    -c -o conn.o conn.c
gcc -I.. -g    -c -o hnam.o hnam.c
gcc -I.. -g    -c -o mktemp.o mktemp.c
gcc -I.. -g    -c -o rand.o rand.c
gcc -I.. -g    -c -o enargv.o enargv.c
gcc -I.. -g    -c -o alldi.o alldi.c
gcc -I.. -g    -c -o lock.o lock.c
gcc -I.. -g    -c -o urg.o urg.c
gcc -I.. -g    -c -o syslog.o syslog.c
gcc -I.. -g    -c -o signal.o signal.c
gcc -I.. -g    -c -o getp.o getp.c
gcc -I.. -g    -c -o getenv.o getenv.c
gcc -I.. -g    -c -o setenv.o setenv.c
gcc -I.. -g    -c -o strerror.o strerror.c
ar rcv ../libfwall.a config.o daemon.o pname.o nama.o mapu.o mapg.o conn.o hnam.o mktemp.o rand.o enargv.o alldi.o lock.o urg.o syslog.o signal.o getp.o getenv.o setenv.o strerror.o 
a - config.o
a - daemon.o
a - pname.o
a - nama.o
a - mapu.o
a - mapg.o
a - conn.o
a - hnam.o
a - mktemp.o
a - rand.o
a - enargv.o
a - alldi.o
a - lock.o
a - urg.o
a - syslog.o
a - signal.o
a - getp.o
a - getenv.o
a - setenv.o
a - strerror.o
ranlib ../libfwall.a
gmake[1]: ranlib: Command not found
gmake[1]: *** [../libfwall.a] Error 127
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/lib'
all: /usr/people/anri/fwtk2.1/fwtk/auth
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/auth'
gcc -I.. -g   -c cliio.c
ar rcv ../libauth.a cliio.o
a - cliio.o
ranlib ../libauth.a
gmake[1]: ranlib: Command not found
gmake[1]: *** [../libauth.a] Error 127
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/auth'
all: /usr/people/anri/fwtk2.1/fwtk/smap
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/smap'
gcc -I.. -g    -c -o smap.o smap.c
gcc -I.. -g    -c -o arpadate.o arpadate.c
gcc -g -o smap smap.o arpadate.o ../libfwall.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/smap'
all: /usr/people/anri/fwtk2.1/fwtk/smapd
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/smapd'
gcc -DPARSEADDR -I.. -g    -c -o smapd.o smapd.c
gcc -g -o smapd smapd.o ../libfwall.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/smapd'
all: /usr/people/anri/fwtk2.1/fwtk/netacl
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/netacl'
gcc -I.. -g    -c -o netacl.o netacl.c
gcc -g -o netacl netacl.o ../libfwall.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/netacl'
all: /usr/people/anri/fwtk2.1/fwtk/plug-gw
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/plug-gw'
gcc -I.. -g    -c -o plug-gw.o plug-gw.c
gcc -g -o plug-gw plug-gw.o ../libfwall.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
ld32: WARNING 85: definition of strerror in ../libfwall.a(strerror.o) preempts that definition in /usr/lib32/mips3/libc.so.
chmod 755 plug-gw
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/plug-gw'
all: /usr/people/anri/fwtk2.1/fwtk/ftp-gw
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/ftp-gw'
gcc -I.. -g    -c -o ftp-gw.o ftp-gw.c
gcc -g -o ftp-gw ftp-gw.o ../libauth.a ../libfwall.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
ld32: WARNING 85: definition of strerror in ../libfwall.a(strerror.o) preempts that definition in /usr/lib32/mips3/libc.so.
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/ftp-gw'
all: /usr/people/anri/fwtk2.1/fwtk/tn-gw
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/tn-gw'
gcc -I.. -g    -c -o tn-gw.o tn-gw.c
gcc -g -o tn-gw tn-gw.o ../libfwall.a ../libauth.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
ld32: WARNING 85: definition of strerror in ../libfwall.a(strerror.o) preempts that definition in /usr/lib32/mips3/libc.so.
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/tn-gw'
all: /usr/people/anri/fwtk2.1/fwtk/rlogin-gw
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/rlogin-gw'
gcc -I.. -g    -c -o rlogin-gw.o rlogin-gw.c
gcc -g -o rlogin-gw rlogin-gw.o ../libauth.a ../libfwall.a 
ld32: WARNING 85: definition of signal in ../libfwall.a(signal.o) preempts that definition in /usr/lib32/mips3/libc.so.
ld32: WARNING 85: definition of strerror in ../libfwall.a(strerror.o) preempts that definition in /usr/lib32/mips3/libc.so.
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/rlogin-gw'
all: /usr/people/anri/fwtk2.1/fwtk/http-gw
gmake[1]: Entering directory `/usr/people/anri/fwtk2.1/fwtk/http-gw'
gcc -I.. -g    -c -o hmain.o hmain.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from hmain.c:28:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o http-gw.o http-gw.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from http-gw.c:19:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o ftp.o ftp.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from ftp.c:15:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o gof2html.o gof2html.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from gof2html.c:12:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o auth.o auth.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from auth.c:12:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o gio.o gio.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from gio.c:14:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o noproxy.o noproxy.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from noproxy.c:9:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
gcc -I.. -g    -c -o error.o error.c
In file included from /usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/stdarg.h:27,
                 from /usr/include/syslog.h:34,
                 from http-gw.h:38,
                 from error.c:10:
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:121: warning: `va_start' redefined
/usr/freeware/lib/gcc-lib/mips-sgi-irix6.2/2.95.2/include/va-mips.h:161: warning: this is the location of the previous definition
error.c:195: macro `va_start' used with just one arg
gmake[1]: *** [error.o] Error 1
gmake[1]: Leaving directory `/usr/people/anri/fwtk2.1/fwtk/http-gw'
gmake: *** [all] Error 2
Grafika-6 65% 

--------------D8622E70EA89337F6862F02C--


From owner-fwtk-users@ex.tis.com Mon Jan 29 11:53 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA24718
	Mon, 29 Jan 2001 11:53:39 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA23113;
	Mon, 29 Jan 2001 08:55:08 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 29 Jan 2001 07:23:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA12688
	for fwtk-users-outgoing; Mon, 29 Jan 2001 07:23:36 -0800 (PST)
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Message-Id: <200101282105.NAA24328@noid.net>
X-Mini-Diatribe: To fix America:
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Date: Sun, 28 Jan 2001 13:05:12 -0800
From: Tor Perkins <980712860@noid.net>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: SMAP issues
Mail-Followup-To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
References: <C901B1D9820CD411A11E0060B03CEAB605C645@email.midrex.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <C901B1D9820CD411A11E0060B03CEAB605C645@email.midrex.com>; from snixon@mei-charlotte.com on Wed, Jan 24, 2001 at 09:09:50AM -0500
X-Operating-System: Linux 2.2.17pre19
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1055

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Try running:

  sendmail -bt -d21.12

Then put:

  3,0 user@midrex.com

at the '> ' prompt.

You'll probably see that sendmail is trying to deliver the message
locally (as you've already guessed).

I use a mailertable.  I have a line like:

  midrex.com          smtp:[my-internal-smart-relay.midrex.com]

That will work _if_ you've made the db hash properly and your
sendmail.cf is configured to use the mailertable hash.  You can
confirm that it's working by using the above test.

The hash can be made like so:

  makemap hash ./mailertable.db <./mailertable

I gen my sendmail.cf using m4.  Using this technique, this line will
activate the mailertable:

  FEATURE(mailertable)

If you are not using m4, I suggest you try it.  I'm not sure how to
edit sendmail.cf by hand to activate the mailertable.

Alternatively, this line in sendmail.cf _might_ work:

  DRmy-internal-smart-relay.midrex.com

Hope this helps.

- Tor

From owner-fwtk-users@ex.tis.com Mon Jan 29 12:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA24782
	Mon, 29 Jan 2001 12:16:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA24716;
	Mon, 29 Jan 2001 09:18:08 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 29 Jan 2001 08:32:49 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA20784
	for fwtk-users-outgoing; Mon, 29 Jan 2001 08:32:42 -0800 (PST)
Mime-Version: 1.0
Date: Mon, 29 Jan 2001 16:28:14 +0000
Message-ID: <00041C23.C22300@it.glasgow.gov.uk>
From: derek.torrance@it.glasgow.gov.uk (Derek Torrance)
Subject: RE: smap anti-relaying - outward-bound mail rejected
To: fwtk-users@lists.nai.com
Content-Transfer-Encoding: 7bit
Content-Description: cc:Mail note part
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="US-ASCII"
Content-Length: 386

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

     
     I have my problems with this sorted. You can all stop worrying and 
     sleep easy tonight. :)
     Thanks to Jan and Kemal for their suggestions. The problem was mainly 
     due to the way I was testing rather than my config.
     
     derek

From owner-fwtk-users@ex.tis.com Tue Jan 30 10:02 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA00443
	Tue, 30 Jan 2001 10:02:00 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA27933;
	Tue, 30 Jan 2001 07:03:20 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 30 Jan 2001 06:56:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA26709
	for fwtk-users-outgoing; Tue, 30 Jan 2001 06:56:09 -0800 (PST)
Date: Mon, 29 Jan 2001 19:04:59 +0100 (MET)
Message-Id: <2.2.16.20010129185959.1d1f12be@hermitage.iut-valence.fr>
X-Sender: aktouf@hermitage.iut-valence.fr
X-Mailer: Windows Eudora Pro Version 2.2 (16)
Mime-Version: 1.0
To: fwtk-support@tis.com, fwtk-users@tis.com
From: Chouki Aktouf <Chouki.Aktouf@iut-valence.fr>
Subject: problems to install TIS under Linux
Cc: Nadege.Greve@iut-valence.fr, Julie.Frassy@iut-valence.fr
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id KAA27253
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="iso-8859-1"
Content-Length: 678

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,

We tried to install TIS under Linux without success.
                + fixmake works fine
                + make did not work because we do not know how to configure
the file firewall.h.

Any help is welcomed as soon as you can.

Thanks in advance

Best regards,

/**********************************************************/
DÈpartement GTR, IUT Valence
51 rue B. de Laffemas
26901 Valence Cedex 09
tel: (+33) 4 75 418 854
fax: (+33) 4 75 418 844
URL : http://www.iut-valence.fr 
/**********************************************************/

From owner-fwtk-users@ex.tis.com Tue Jan 30 10:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA00496
	Tue, 30 Jan 2001 10:12:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA00148;
	Tue, 30 Jan 2001 07:14:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 30 Jan 2001 07:10:13 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29032
	for fwtk-users-outgoing; Tue, 30 Jan 2001 07:10:12 -0800 (PST)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <3A76E730.673EE34A@radio.hundert6.de>
Date: Tue, 30 Jan 2001 16:09:20 +0000
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.2-STABLE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: Chouki Aktouf <Chouki.Aktouf@iut-valence.fr>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: problems to install TIS under Linux
References: <2.2.16.20010129185959.1d1f12be@hermitage.iut-valence.fr>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 481

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>                 + fixmake works fine
>                 + make did not work because we do not know how to configure

As far as I recall you do not need to run fixmake for a Linux
installation. It will be easier to help you if you tell us which
Linux you're using. 

Bye, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Wed Jan 31 06:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA04119
	Wed, 31 Jan 2001 06:42:38 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA05914;
	Wed, 31 Jan 2001 03:45:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 03:40:13 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA05298
	for fwtk-users-outgoing; Wed, 31 Jan 2001 03:40:12 -0800 (PST)
Message-ID: <20010131113934.51202.qmail@web12401.mail.yahoo.com>
Date: Wed, 31 Jan 2001 03:39:34 -0800 (PST)
From: Zakharov Mikhail <zmey20000@yahoo.com>
Subject: ftp-gw & http-gw errors
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 710

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello!

I have troubles while configuring FWTK under FreeBSD
4.1. 
When connecting with Netscape Comm. or Internet
Explorer to ftp-servers I get errors:

1) Using ftp-gw I get error "220 fwtktest.memonet.ru
FTP proxy (Version V2.1) ready. 500 command not
understood 500 command not understood 500 ..."

2) The same error with http-gw looks as: "FTP error -
215"

Command-line ftp client without errors.

Best regards
Mikhail


__________________________________________________
Get personalized email addresses from Yahoo! Mail - only $35 
a year!  http://personal.mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Wed Jan 31 09:38 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA04688
	Wed, 31 Jan 2001 09:38:23 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA13118;
	Wed, 31 Jan 2001 06:40:52 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 06:38:08 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA12370
	for fwtk-users-outgoing; Wed, 31 Jan 2001 06:38:06 -0800 (PST)
X-Originating-IP: [209.178.191.59]
From: "Mr Harold" <hsouth2000@hotmail.com>
To: fwtk-users@lists.nai.com
Date: Tue, 30 Jan 2001 15:10:05 -0800
Mime-Version: 1.0
Message-ID: <F48yMJiQTyfPefLJGWS0000053c@hotmail.com>
X-OriginalArrivalTime: 30 Jan 2001 23:10:05.0797 (UTC) FILETIME=[C8532150:01C08B11]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/html
Content-Length: 889

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

<html><DIV>Hi, </DIV>
<DIV></DIV>Has anyone seen the following message on 2.1 running on RedHat 6.2 ? 
<DIV></DIV>
<DIV></DIV>Jan 30 05:24:41 jerry inetd[371]: www/tcp server failing (looping or being flooded), service terminated for 10 min 
<DIV></DIV>
<DIV></DIV>
<DIV></DIV>This is my entry in the /etc/inetd.conf 
<DIV></DIV>
<DIV></DIV>www stream tcp nowait root /usr/sbin/in.http-gw in.http-gw 
<DIV></DIV>
<DIV></DIV>I'm using a link back back to the original file. 
<DIV></DIV>
<DIV></DIV>ls -sl /usr/sbin/*http* 
<DIV></DIV>0 lrwxrwxrwx 1 root root 22 Jan 14 17:51 /usr/sbin/in.http-gw -&gt; /usr/local/etc/http-gw<br clear=all><hr>Get your FREE download of MSN Explorer at <a href="http://explorer.msn.com">http://explorer.msn.com</a><br></p></html>

From owner-fwtk-users@ex.tis.com Wed Jan 31 10:56 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA05128
	Wed, 31 Jan 2001 10:56:49 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21905;
	Wed, 31 Jan 2001 07:59:18 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 07:54:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA20949
	for fwtk-users-outgoing; Wed, 31 Jan 2001 07:54:30 -0800 (PST)
Message-ID: <012801c08b9c$04d682e0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Subject: RTSP proxy
Date: Wed, 31 Jan 2001 10:39:37 -0500
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 354

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I've been considering adding the RTSP proxy to my personal CableModem
OpenBSD firewall.

Any concerns or suggestions?

Should I use the stock reference proxy or is there a better on for FWTK?

Thanks,
LarryJackson@iName.com


From owner-fwtk-users@ex.tis.com Wed Jan 31 11:07 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA05157
	Wed, 31 Jan 2001 11:07:53 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA24331;
	Wed, 31 Jan 2001 08:10:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 08:07:37 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA23329
	for fwtk-users-outgoing; Wed, 31 Jan 2001 08:07:35 -0800 (PST)
Message-ID: <20010131160707.66538.qmail@web12402.mail.yahoo.com>
Date: Wed, 31 Jan 2001 08:07:07 -0800 (PST)
From: Zakharov Mikhail <zmey20000@yahoo.com>
Subject: Ftp throug http-gw (HELP!!!)
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1636

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello! Help!
I have troubles with http-gw. I'm going to use it for
ftp-connections. It does not work. Ports in browser
are correct (the ftp-proxy==http-proxy). Html-page
shows: "FTP Error 215" or "FTP Error 200". It tries to
run commands "system" & "binary". Unix-box - i386
under FreeBSD 4.1. 

Here is my inetd.conf:
#-----------------------------------------------
ftp     stream  tcp     nowait  root
/usr/local/libexec/ftp-gw       ftp-gw

gopher  stream  tcp     nowait  root   
/usr/local/libexec/http-gw      http-gw

http    stream  tcp     nowait  root   
/usr/local/libexec/http-gw      http-gw

authsrv stream  tcp     nowait  root   
/usr/local/libexec/authsrv      authsrv

#----------------------------------------
here is my netperm-table:

netacl-ftp: permit-hosts * -exec
/usr/local/libexec/ftp-gw

ftp-gw:  directory /home/zmey
ftp-gw:  timeout 1800
ftp-gw:  permit-hosts * -log { retr stor }

http-gw: userid 1000
http-gw: directory /home/www
http-gw: permit-hosts * -log { read write ftp }
http-gw: ftp-proxy 127.0.0.1
http-gw: timeout 1800 192.168.45.14

authsrv:        hosts *
authsrv:        permit-hosts *
authsrv:        database /usr/local/etc/fw-authdb
authsrv:        badsleep 1200
authsrv:        nobogus true

*:              authserver 127.0.0.1 7777
#---------------------------------------------
Best regards
Mikhail

__________________________________________________
Get personalized email addresses from Yahoo! Mail - only $35 
a year!  http://personal.mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Wed Jan 31 11:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA05312
	Wed, 31 Jan 2001 11:59:46 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA02532;
	Wed, 31 Jan 2001 09:02:14 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 08:58:55 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA01590
	for fwtk-users-outgoing; Wed, 31 Jan 2001 08:58:54 -0800 (PST)
Date: Wed, 31 Jan 2001 11:57:06 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Mr Harold <hsouth2000@hotmail.com>
cc: fwtk-users@lists.nai.com
Subject: Re: your mail
In-Reply-To: <F48yMJiQTyfPefLJGWS0000053c@hotmail.com>
Message-ID: <Pine.GSO.4.10.10101311153210.6315-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1672

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

You may want to run http-gw from daemon mode instead of inetd mode.
Alternatively, you can specify the number of connections you will allow
inetd to start for a particular service during a one second (?) interval
in inetd.conf.

inetd has default predefined limits on the number of activiations
permitted.  If these thresholds are exceeded, inetd assumes your machine
is under attack - and as a precaution - refuses additional connections for
that service.

This model breaks down for protocols like http - since each little object
represents yet another new connections.  It is easy to exceed these
thresholds on relatively lightly loaded machines.

By using the deamon model, you can completely skip the inetd limitations.

ted keller


On Tue, 30 Jan 2001, Mr Harold wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users"
> in the BODY of a mail message to majordomo@ex.tis.com.] Hi,
> Has anyone seen the following message on 2.1 running on RedHat 6.2 ?
> Jan 30 05:24:41 jerry inetd[371]: www/tcp server failing (looping or
> being flooded), service terminated for 10 min
> This is my entry in the /etc/inetd.conf
> www stream tcp nowait root /usr/sbin/in.http-gw in.http-gw
> I'm using a link back back to the original file.
> ls -sl /usr/sbin/*http*
> 0 lrwxrwxrwx 1 root root 22 Jan 14 17:51 /usr/sbin/in.http-gw ->
> /usr/local/etc/http-gw
> 
> ________________________________________________________________________________
> 
> Get your FREE download of MSN Explorer at http://explorer.msn.com
> 
> 
> 


From owner-fwtk-users@ex.tis.com Wed Jan 31 12:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA05326
	Wed, 31 Jan 2001 12:05:24 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA04586;
	Wed, 31 Jan 2001 09:07:53 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 09:03:29 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA02905
	for fwtk-users-outgoing; Wed, 31 Jan 2001 09:03:27 -0800 (PST)
Date: Wed, 31 Jan 2001 12:01:12 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Larry Jackson <LarryJackson@iName.com>
cc: FWTK List Server <fwtk-users@lists.nai.com>
Subject: Re: RTSP proxy
In-Reply-To: <012801c08b9c$04d682e0$fc00a8c0@k62350>
Message-ID: <Pine.GSO.4.10.10101311158030.6315-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1239

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

The RTSP proxy does not have support to limit who connects and who
proxies.  If you run this on your firewall - you will permit inbound as
well as outbound connections for this service.  May not be what you want
to do.

Also, the rtpd proxy is fairly complex codes.  It opens bi-directional udp
tunnels on the fly.... and other elegant feature - neat but hard to
validate from a security standpoint.

I've implemented this type of proxy on an internal machine ... behind a
socks server on the firewall.  It is fairly easy to "socksify" this code.
The socks server deals with the connection issues - allowing the traffic
to be carried to the backend server as required....

ted keller


On Wed, 31 Jan 2001, Larry Jackson wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I've been considering adding the RTSP proxy to my personal CableModem
> OpenBSD firewall.
> 
> Any concerns or suggestions?
> 
> Should I use the stock reference proxy or is there a better on for FWTK?
> 
> Thanks,
> LarryJackson@iName.com
> 


From owner-fwtk-users@ex.tis.com Wed Jan 31 12:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA05337
	Wed, 31 Jan 2001 12:08:07 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA05643;
	Wed, 31 Jan 2001 09:10:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 09:05:22 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA03580
	for fwtk-users-outgoing; Wed, 31 Jan 2001 09:05:19 -0800 (PST)
Date: Wed, 31 Jan 2001 12:03:31 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Zakharov Mikhail <zmey20000@yahoo.com>
cc: fwtk-users@lists.nai.com
Subject: Re: Ftp throug http-gw (HELP!!!)
In-Reply-To: <20010131160707.66538.qmail@web12402.mail.yahoo.com>
Message-ID: <Pine.GSO.4.10.10101311202100.6315-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2133

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Mikhail,

In your browser, set the http proxy and ftp proxy to your firewall on port
80 - both of them.

In you netperm table - remove the http-gw line

http-gw: ftp-proxy 127.0.0.1


See if it works.

tek


On Wed, 31 Jan 2001, Zakharov Mikhail wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello! Help!
> I have troubles with http-gw. I'm going to use it for
> ftp-connections. It does not work. Ports in browser
> are correct (the ftp-proxy==http-proxy). Html-page
> shows: "FTP Error 215" or "FTP Error 200". It tries to
> run commands "system" & "binary". Unix-box - i386
> under FreeBSD 4.1. 
> 
> Here is my inetd.conf:
> #-----------------------------------------------
> ftp     stream  tcp     nowait  root
> /usr/local/libexec/ftp-gw       ftp-gw
> 
> gopher  stream  tcp     nowait  root   
> /usr/local/libexec/http-gw      http-gw
> 
> http    stream  tcp     nowait  root   
> /usr/local/libexec/http-gw      http-gw
> 
> authsrv stream  tcp     nowait  root   
> /usr/local/libexec/authsrv      authsrv
> 
> #----------------------------------------
> here is my netperm-table:
> 
> netacl-ftp: permit-hosts * -exec
> /usr/local/libexec/ftp-gw
> 
> ftp-gw:  directory /home/zmey
> ftp-gw:  timeout 1800
> ftp-gw:  permit-hosts * -log { retr stor }
> 
> http-gw: userid 1000
> http-gw: directory /home/www
> http-gw: permit-hosts * -log { read write ftp }
> http-gw: ftp-proxy 127.0.0.1
> http-gw: timeout 1800 192.168.45.14
> 
> authsrv:        hosts *
> authsrv:        permit-hosts *
> authsrv:        database /usr/local/etc/fw-authdb
> authsrv:        badsleep 1200
> authsrv:        nobogus true
> 
> *:              authserver 127.0.0.1 7777
> #---------------------------------------------
> Best regards
> Mikhail
> 
> __________________________________________________
> Get personalized email addresses from Yahoo! Mail - only $35 
> a year!  http://personal.mail.yahoo.com/
> 


