From owner-fwtk-users@ex.tis.com Thu Feb  1 00:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA07259
	Thu, 1 Feb 2001 00:52:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA02660;
	Wed, 31 Jan 2001 21:54:30 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 31 Jan 2001 21:51:27 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA02034
	for fwtk-users-outgoing; Wed, 31 Jan 2001 21:51:23 -0800 (PST)
From: "Sajeev" <sajeevm@vantel.net>
To: <fwtk-users@lists.nai.com>
Subject: Trouble in SMAP/SMAPD
Date: Thu, 1 Feb 2001 11:22:48 +0530
Message-ID: <MFEGKNIIMHJHHBBEOKELMEJBCAAA.sajeevm@vantel.net>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1377

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

HI.
I have set up a firewall with fwtk. My internal network is on a Private Ip.
Is theer any special set up that I should do for the http-gw to work. I have
made all the necessary entries in my netperm table for both smap and
http-gw. But both are not working.
Is it necessary for me to have sendmail accepting requests on the firewall
machine for smap to be running.


A snap shot of my netperm table is as follows.

smap, smapd:	userid 6
smap, smapd:	directory /u2/spool/smap
smapd:		executable /usr/local/etc/smapd
smapd:		sendmail /usr/sbin/sendmail
smap:		timeout 3600

http-gw:	timeout 1800
http-gw:	permit-hosts	10.50.50.*
http-gw:	deny-hosts unknown

ftp-gw:	denial-msg	/usr/local/etc/ftp-deny.txt
ftp-gw:	welcome-msg	/usr/local/etc/ftp-welcome.txt
ftp-gw:	help-msg	/usr/local/etc/ftp-help.txt
ftp-gw:		timeout 3600


tn-gw:		timeout 3600
tn-gw:		permit-hosts YOURNET.* -passok -xok


rlogin-gw:	timeout 3600
rlogin-gw:	permit-hosts YOURNET.* -passok -xok


authsrv:	hosts 127.0.0.1
authsrv:	database /usr/local/etc/fw-authdb
authsrv:	badsleep 1200
authsrv:	nobogus true

# clients using the auth server
*:		authserver 127.0.0.1 7777

# X-forwarder rules
tn-gw, rlogin-gw:	xforwarder /usr/local/etc/x-gw


Thanks in advance...

Sajeev






From owner-fwtk-users@ex.tis.com Thu Feb  1 04:55 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA07817
	Thu, 1 Feb 2001 04:55:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA09369;
	Thu, 1 Feb 2001 01:58:20 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Feb 2001 01:55:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA08769
	for fwtk-users-outgoing; Thu, 1 Feb 2001 01:55:50 -0800 (PST)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <3A794073.355C1145@radio.hundert6.de>
Date: Thu, 01 Feb 2001 10:54:43 +0000
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.2-STABLE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: Sajeev <sajeevm@vantel.net>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: Trouble in SMAP/SMAPD
References: <MFEGKNIIMHJHHBBEOKELMEJBCAAA.sajeevm@vantel.net>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 753

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> made all the necessary entries in my netperm table for both smap and
> http-gw. But both are not working.

I'd be interested in HOW exactly you are running the daemons,
from inetd or standalone...? If from inetd, I'd like to see your
inetd.conf, if standalone, make sure they're running.

> Is it necessary for me to have sendmail accepting requests on the firewall
> machine for smap to be running.

Definitely not. The only one listening on port 25 should be smap.
It uses sendmail to hand on the received mail, but that's a
different thing. 

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Feb  2 02:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id CAA11877
	Fri, 2 Feb 2001 02:05:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id XAA25187;
	Thu, 1 Feb 2001 23:08:28 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Feb 2001 23:01:35 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA24277
	for fwtk-users-outgoing; Thu, 1 Feb 2001 23:01:29 -0800 (PST)
From: "Sajeev" <sajeevm@vantel.net>
To: <fwtk-users@lists.nai.com>
Subject: smap/smapd not working
Date: Fri, 2 Feb 2001 12:32:48 +0530
Message-ID: <MFEGKNIIMHJHHBBEOKELMEKDCAAA.sajeevm@vantel.net>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 549

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi
I have set up the fwtk . Now after I have set up the toolkit I am not able
to send any mails using my mail server located outside my network. I have
configured
smap  and smapd
plug-gw has been configured to run on two different ports for smtp and pop3.
But after all this my outlook client gives the following error message.
Unable to connect to the server.

Can any body be of help on this.
Thanks in advance
Sajev


From owner-fwtk-users@ex.tis.com Fri Feb  2 05:35 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA12494
	Fri, 2 Feb 2001 05:35:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA00988;
	Fri, 2 Feb 2001 02:37:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Feb 2001 02:35:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA00361
	for fwtk-users-outgoing; Fri, 2 Feb 2001 02:35:02 -0800 (PST)
Message-ID: <20010202103428.30320.qmail@web12408.mail.yahoo.com>
Date: Fri, 2 Feb 2001 02:34:28 -0800 (PST)
From: Zakharov Mikhail <zmey20000@yahoo.com>
Subject: Some questions [authentification, ftp-gw, http-gw]
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 595

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,

I have several questions about FWTK:

1. Is it possible to setup ftp-gw to work with
browsers, or I have to use http-gw for ftp-connections
(as it was written in FAQ) ?

2. How can I setup authentification to work with
browsers? For http-gw it's impossible, and what about
ftp-gw?

Best regards
Mikhail

__________________________________________________
Get personalized email addresses from Yahoo! Mail - only $35 
a year!  http://personal.mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Fri Feb  2 07:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA12677
	Fri, 2 Feb 2001 07:05:20 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA14108;
	Fri, 2 Feb 2001 04:07:51 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Feb 2001 04:04:13 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA13021
	for fwtk-users-outgoing; Fri, 2 Feb 2001 04:04:12 -0800 (PST)
From: "Sajeev" <sajeevm@vantel.net>
To: <fwtk-users@lists.nai.com>
Subject: RE: Trouble in SMAP/SMAPD
Date: Fri, 2 Feb 2001 17:35:14 +0530
Message-ID: <MFEGKNIIMHJHHBBEOKELAEKICAAA.sajeevm@vantel.net>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
In-Reply-To: <3A794073.355C1145@radio.hundert6.de>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="us-ascii"
Content-Length: 739

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi.

I am not able to push my mails through the firewall. My configurations are
as follows.

smap and smapd are running as daemons
plug-gw is being started thru inetd

my mail client is MS Outlook. The settings on the client are as follows
 1. outgoing pop3 server is the firewall machine
 2. outgoing smtp server is also the firewall machine
 3. the connecting port is the default pop3 and smtp ports
The mail server is located outside the network with our ISP.
Thanks in advance
Can anyone out there be of any help .....
Sajeev


-
--
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de


From owner-fwtk-users@ex.tis.com Fri Feb  2 10:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA13307
	Fri, 2 Feb 2001 10:15:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA00074;
	Fri, 2 Feb 2001 07:18:24 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Feb 2001 07:15:03 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29036
	for fwtk-users-outgoing; Fri, 2 Feb 2001 07:14:56 -0800 (PST)
X-Authentication-Warning: stargate.diomass.org: smap set sender to <Mhodges@diomass.org> using -f
Message-ID: <51D4F81EFAF7D111B33600805FBB112530964E@HQ_APPS>
From: "Hodges, Michael" <Mhodges@diomass.org>
To: fwtk-users@lists.nai.com
Subject: SMAP Patch
Date: Fri, 2 Feb 2001 10:12:15 -0500 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C08D2A.8C2DEBD0"
Content-Length: 3283

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C08D2A.8C2DEBD0
Content-Type: text/plain;
	charset="iso-8859-1"

I'm trying to apply the yao smap patch.  The patch goes through fine, but
when I try to make the file I get the following output.  Where do I rectify
the undefined reference?  TIA

------------------------------------
# make smap
cc -I.. -g -DLINUX   -c smap.c -o smap.o
cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
smap.o: In function `from_address_ok':
/apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
/apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
collect2: ld returned 1 exit status
make: *** [smap] Error 1

------------------------------------
Michael J. Hodges
Computer Systems Coordinator
The Episcopal Diocese of Massachusetts
138 Tremont Street
Boston, MA  02111-1319
------------------------------------
Phone: (617) 879-6300
Fax:     (617) 482-8431
email:   mhodges@diomass.org
Web:    http://www.diomass.org



------_=_NextPart_001_01C08D2A.8C2DEBD0
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2650.12">
<TITLE>SMAP Patch</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2>I'm trying to apply the yao smap patch.&nbsp; The =
patch goes through fine, but when I try to make the file I get the =
following output.&nbsp; Where do I rectify the undefined =
reference?&nbsp; TIA</FONT></P>

<P><FONT SIZE=3D2>------------------------------------</FONT>
<BR><FONT SIZE=3D2># make smap</FONT>
<BR><FONT SIZE=3D2>cc -I.. -g -DLINUX&nbsp;&nbsp; -c smap.c -o =
smap.o</FONT>
<BR><FONT SIZE=3D2>cc -g -static -o smap smap.o arpadate.o =
../libfwall.a -lcrypt</FONT>
<BR><FONT SIZE=3D2>smap.o: In function `from_address_ok':</FONT>
<BR><FONT SIZE=3D2>/apps/src/fwtk/smap/smap.c:2015: undefined reference =
to `res_query'</FONT>
<BR><FONT SIZE=3D2>/apps/src/fwtk/smap/smap.c:2015: undefined reference =
to `res_query'</FONT>
<BR><FONT SIZE=3D2>collect2: ld returned 1 exit status</FONT>
<BR><FONT SIZE=3D2>make: *** [smap] Error 1</FONT>
</P>

<P><FONT SIZE=3D2>------------------------------------</FONT>
<BR><FONT SIZE=3D2>Michael J. Hodges</FONT>
<BR><FONT SIZE=3D2>Computer Systems Coordinator</FONT>
<BR><FONT SIZE=3D2>The Episcopal Diocese of Massachusetts</FONT>
<BR><FONT SIZE=3D2>138 Tremont Street</FONT>
<BR><FONT SIZE=3D2>Boston, MA&nbsp; 02111-1319</FONT>
<BR><FONT SIZE=3D2>------------------------------------</FONT>
<BR><FONT SIZE=3D2>Phone: (617) 879-6300</FONT>
<BR><FONT SIZE=3D2>Fax:&nbsp;&nbsp;&nbsp;&nbsp; (617) 482-8431</FONT>
<BR><FONT SIZE=3D2>email:&nbsp;&nbsp; mhodges@diomass.org</FONT>
<BR><FONT SIZE=3D2>Web:&nbsp;&nbsp;&nbsp; <A =
HREF=3D"http://www.diomass.org" =
TARGET=3D"_blank">http://www.diomass.org</A></FONT>
</P>
<BR>

</BODY>
</HTML>
------_=_NextPart_001_01C08D2A.8C2DEBD0--

From owner-fwtk-users@ex.tis.com Fri Feb  2 11:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13559
	Fri, 2 Feb 2001 11:15:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA07854;
	Fri, 2 Feb 2001 08:17:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Feb 2001 08:15:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA06992
	for fwtk-users-outgoing; Fri, 2 Feb 2001 08:15:07 -0800 (PST)
Date: Fri, 2 Feb 2001 11:14:35 -0500 (EST)
X-Authentication-Warning: conch.msen.com: mjo set sender to mjo@dojo.mi.org using -f
Subject: Re: SMAP Patch
To: fwtk-users@lists.nai.com
Late: Fri, 2 Feb 101 11:14:35 -0500 (EST)
From: "Mike O'Connor" <mjo@dojo.mi.org>
Reply-To: "Mike O'Connor" <mjo@dojo.mi.org>
Message-Id: <010202111435.mjo@dojo.mi.org>
X-Organization: :noitazinagrO-X
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1228

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

:
:I'm trying to apply the yao smap patch.  The patch goes through fine, but
:when I try to make the file I get the following output.  Where do I rectify
:the undefined reference?  TIA
:
:------------------------------------
:# make smap
:cc -I.. -g -DLINUX   -c smap.c -o smap.o
:cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
:smap.o: In function `from_address_ok':
:/apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
:/apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
:collect2: ld returned 1 exit status
:make: *** [smap] Error 1
:

Depending on your Linux system's libc incarnation, res_query may
either be in libc or libresolv.  It looks like in your case, it's
not in libc.  So, you'll need to add -lresolv to the libraries.

-- 
 Michael J. O'Connor | WWW: http://dojo.mi.org/~mjo/ | Email: mjo@dojo.mi.org
 Royal Oak, Michigan | (has my PGP & Geek Code info) | Phone: +1 248-848-4481
 =--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--=
"God must have a goofy sense of humor."                               -Hobbes

From owner-fwtk-users@ex.tis.com Fri Feb  2 11:23 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13569
	Fri, 2 Feb 2001 11:23:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA09734;
	Fri, 2 Feb 2001 08:26:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Feb 2001 08:23:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA08993
	for fwtk-users-outgoing; Fri, 2 Feb 2001 08:23:53 -0800 (PST)
Date: Fri, 2 Feb 2001 11:21:51 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "Hodges, Michael" <Mhodges@diomass.org>
cc: fwtk-users@lists.nai.com
Subject: Re: SMAP Patch
In-Reply-To: <51D4F81EFAF7D111B33600805FBB112530964E@HQ_APPS>
Message-ID: <Pine.GSO.4.10.10102021121210.2080-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1235

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Add -lresolv to your make file.  These are the resolver libraries which
smap used to validate sending domain.

ted keller


On Fri, 2 Feb 2001, Hodges, Michael wrote:

> I'm trying to apply the yao smap patch.  The patch goes through fine, but
> when I try to make the file I get the following output.  Where do I rectify
> the undefined reference?  TIA
> 
> ------------------------------------
> # make smap
> cc -I.. -g -DLINUX   -c smap.c -o smap.o
> cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
> smap.o: In function `from_address_ok':
> /apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
> /apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
> collect2: ld returned 1 exit status
> make: *** [smap] Error 1
> 
> ------------------------------------
> Michael J. Hodges
> Computer Systems Coordinator
> The Episcopal Diocese of Massachusetts
> 138 Tremont Street
> Boston, MA  02111-1319
> ------------------------------------
> Phone: (617) 879-6300
> Fax:     (617) 482-8431
> email:   mhodges@diomass.org
> Web:    http://www.diomass.org
> 
> 
> 


From owner-fwtk-users@ex.tis.com Fri Feb  2 12:10 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA13726
	Fri, 2 Feb 2001 12:09:56 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA17402;
	Fri, 2 Feb 2001 09:12:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Feb 2001 09:08:18 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA15751
	for fwtk-users-outgoing; Fri, 2 Feb 2001 09:08:17 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A7ADD72.BB3B1051@peaktime.be>
Date: Fri, 02 Feb 2001 17:16:50 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
CC: fwtk-users@lists.nai.com
Subject: Re: SMAP Patch
References: <51D4F81EFAF7D111B33600805FBB112530964E@HQ_APPS>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1076

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> "Hodges, Michael" wrote:
> 
> I'm trying to apply the yao smap patch.  The patch goes through fine,
> but when I try to make the file I get the following output.  Where do
> I rectify the undefined reference?  TIA
> 
> ------------------------------------
> # make smap
> cc -I.. -g -DLINUX   -c smap.c -o smap.o
> cc -g -static -o smap smap.o arpadate.o ../libfwall.a -lcrypt
> smap.o: In function `from_address_ok':
> /apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
> /apps/src/fwtk/smap/smap.c:2015: undefined reference to `res_query'
> collect2: ld returned 1 exit status
> make: *** [smap] Error 1
> 

nm -D -o /lib/li*.so.* | fgrep res_q

reveals the horrible truth: with libc5 the resolver stuff was inside
libc; starting with libc6 you need -lresolv

Did someone say "DLL hell"?

Greetings.
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10

From owner-fwtk-users@ex.tis.com Sun Feb  4 00:13 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA18156
	Sun, 4 Feb 2001 00:13:07 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA19889;
	Sat, 3 Feb 2001 21:15:36 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 3 Feb 2001 21:09:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA19283
	for fwtk-users-outgoing; Sat, 3 Feb 2001 21:09:36 -0800 (PST)
Date: Sun, 4 Feb 2001 00:08:20 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Fwtk Users <fwtk-users@lists.nai.com>
Subject: updated smap
Message-ID: <Pine.GSO.4.10.10102040000170.14216-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 740

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I've updated my smap version to enable spam content filtering for mail
with embedded html tags.  Been running it for a couple of weeks now and it
seems to hold together pretty good.

The code also recognized javascript - and handles it effectively.

I also added a feature to allow for substing matching in html tagged
areas.  This permits the rejection of mail based on a partial url entry.
An example may be 

tag nudecasino.com

This will reject any message with a url containing these characters.

If anyone is interested, please contact me offline and I will tell you
where to pick it up at.

ted keller



From owner-fwtk-users@ex.tis.com Mon Feb  5 01:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id BAA21237
	Mon, 5 Feb 2001 01:33:39 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id WAA15285;
	Sun, 4 Feb 2001 22:36:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 4 Feb 2001 22:31:08 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id WAA14624
	for fwtk-users-outgoing; Sun, 4 Feb 2001 22:31:06 -0800 (PST)
Message-ID: <20010205063029.37323.qmail@web12407.mail.yahoo.com>
Date: Sun, 4 Feb 2001 22:30:29 -0800 (PST)
From: Zakharov Mikhail <zmey20000@yahoo.com>
Subject: Re: Some questions [authentification, ftp-gw, http-gw]
To: Ted Keller <keller@bfg.com>
Cc: fwtk-users@lists.nai.com
In-Reply-To: <Pine.GSO.4.10.10102031953210.12281-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1304

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


--- Ted Keller <keller@bfg.com> wrote:
> Zakharov,
> 
> Did you get your question answered? 

Unfortunally not.  Can you help me?

> If not - let me know and I will try
> to help.  Been pretty busy lately, so I haven't been
> able to respond
> sooner.
> 
> ted keller
> 
> 
> On Fri, 2 Feb 2001, Zakharov Mikhail wrote:
> 
> > [To be removed from this list send the message
> "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > Hello,
> > 
> > I have several questions about FWTK:
> > 
> > 1. Is it possible to setup ftp-gw to work with
> > browsers, or I have to use http-gw for
> ftp-connections
> > (as it was written in FAQ) ?
> > 
> > 2. How can I setup authentification to work with
> > browsers? For http-gw it's impossible, and what
> about
> > ftp-gw?
> > 
> > Best regards
> > Mikhail
> > 
> > __________________________________________________
> > Get personalized email addresses from Yahoo! Mail
> - only $35 
> > a year!  http://personal.mail.yahoo.com/
> > 
> 


__________________________________________________
Get personalized email addresses from Yahoo! Mail - only $35 
a year!  http://personal.mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Mon Feb  5 05:17 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA21747
	Mon, 5 Feb 2001 05:17:39 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA20904;
	Mon, 5 Feb 2001 02:20:14 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 02:17:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA20300
	for fwtk-users-outgoing; Mon, 5 Feb 2001 02:17:34 -0800 (PST)
X-Authentication-Warning: firewall.strathom.com: nobody set sender to <frederic.lebastard@strathom.com> using -f
Message-ID: <319DB26BA2E818469512F920DCE19E18013AF3@futuna.agences.strathom>
From: Frederic Le Bastard <frederic.lebastard@strathom.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Antivirus for FWTK (smap / smapd)
Date: Mon, 5 Feb 2001 11:16:46 +0100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id CAA20295
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 471

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello there,

I'm currently looking for a good antivirus software tweaked for FWTK.
If any of you here have already implemented such a configuration, please let
me know.

Thanks in advance

Fred


Frédéric LE BASTARD - flb@strathom.com
Tél. +33 240 353 232 / Fax. +33 240 121 874
GSM. +33 615 022 951
STRATHOM Informatique - Nantes - France


From owner-fwtk-users@ex.tis.com Mon Feb  5 05:36 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA21771
	Mon, 5 Feb 2001 05:36:04 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA22232;
	Mon, 5 Feb 2001 02:38:38 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 02:37:00 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA21675
	for fwtk-users-outgoing; Mon, 5 Feb 2001 02:36:59 -0800 (PST)
Message-Id: <200102051035.LAA04545@leto.esrf.fr>
Date: Mon, 5 Feb 2001 11:35:40 +0100 (MET)
From: lebayle <lebayle@esrf.fr>
Reply-To: lebayle <lebayle@esrf.fr>
Subject: Re: Antivirus for FWTK (smap / smapd)
To: frederic.lebastard@strathom.com
Cc: fwtk-users@lists.nai.com
MIME-Version: 1.0
Content-MD5: U86dQ3C7S615PnEopXYWoA==
X-Mailer: dtmail 1.3.0 CDE Version 1.3 SunOS 5.7 sun4u sparc 
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/plain; charset=us-ascii
Content-Length: 495

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>I'm currently looking for a good antivirus software tweaked for FWTK.
>If any of you here have already implemented such a configuration, please 
let
>me know.

We are using Trend VirusWall on our internal Mail server. Works fine and 
does not overload the firewall itself.
Bruno LEBAYLE (lebayle@esrf.fr)
European Synchrotron Radiation Facility - Grenoble, FRANCE


From owner-fwtk-users@ex.tis.com Mon Feb  5 06:28 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA21863
	Mon, 5 Feb 2001 06:28:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA24035;
	Mon, 5 Feb 2001 03:31:27 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 03:29:34 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA23471
	for fwtk-users-outgoing; Mon, 5 Feb 2001 03:29:33 -0800 (PST)
Message-Id: <5.0.2.1.0.20010205062009.01d2c080@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Mon, 05 Feb 2001 06:25:08 -0500
To: Zakharov Mikhail <zmey20000@yahoo.com>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Some questions [authentification, ftp-gw, http-gw]
In-Reply-To: <20010202103428.30320.qmail@web12408.mail.yahoo.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1387

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:34 AM 2/2/01 -0800, Zakharov Mikhail wrote:
>1. Is it possible to setup ftp-gw to work with
>browsers, or I have to use http-gw for ftp-connections
>(as it was written in FAQ) ?

The proxy for a browser responds HTTP commands, not FTP commands. In other 
words, when you set up a ftp proxy, a browser connects to that and sends 
"get ftp://..." and expects HTML as the response. Because of this, you 
can't use the ftp-gw as a FTP proxy for a web browser.

>2. How can I setup authentification to work with
>browsers? For http-gw it's impossible, and what about
>ftp-gw?

This is the same problem as above - you can't authenticate http with the 
toolkit.

Actually, it wouldn't be hard to add authentication, but then it would only 
work with password authentication - and every element of every web page 
would require an authentication server request to verify the passsword. 
This would be very slow.
To get authentication for http to work well requires a persistent front-end 
that the browser connects to which then authenticates. That only has to 
reauthenticate when the user breaks the connection (by clicking ahead, for 
example.) That front-end could cache the authentication results to avoid 
unnecessary authserver traffic.
         -Rick


From owner-fwtk-users@ex.tis.com Mon Feb  5 07:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA22236
	Mon, 5 Feb 2001 07:52:18 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA26469;
	Mon, 5 Feb 2001 04:54:53 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 04:52:22 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA25886
	for fwtk-users-outgoing; Mon, 5 Feb 2001 04:52:21 -0800 (PST)
Message-ID: <3A7EA2CD.9580B4BE@v-one.com>
Date: Mon, 05 Feb 2001 07:55:41 -0500
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: fwtk-users@lists.nai.com
Subject: Re: Some questions [authentification, ftp-gw, http-gw]
References: <5.0.2.1.0.20010205062009.01d2c080@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1411

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick Murphy wrote:
> 
> Actually, it wouldn't be hard to add authentication, but then it would only
> work with password authentication - and every element of every web page
> would require an authentication server request to verify the passsword.
> This would be very slow.
> To get authentication for http to work well requires a persistent front-end
> that the browser connects to which then authenticates. That only has to
> reauthenticate when the user breaks the connection (by clicking ahead, for
> example.) That front-end could cache the authentication results to avoid
> unnecessary authserver traffic.

Rick,

Instead of the front-end, couldn't you add 2 auth timeouts in http-gw:
one timeout which states that your auth will be good for X seconds, and
another which states that if you don't go through http-gw in X seconds,
you will need to re-auth?

I know that it is not as secure (since people could then "steal" your IP
address and go through the proxy un-authenticated), but I'd guess that
it would be easier to write than what you mentioned. But I guess if you
are using clear-text name/password schemes then you don't really care
about being secure in the first place  :-).....

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Mon Feb  5 08:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA22294
	Mon, 5 Feb 2001 08:04:20 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA27716;
	Mon, 5 Feb 2001 05:06:56 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 05:05:18 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA27142
	for fwtk-users-outgoing; Mon, 5 Feb 2001 05:05:17 -0800 (PST)
From: ark@eltex.ru
Date: Mon, 5 Feb 2001 16:20:44 +0300
Message-Id: <200102051320.QAA25429@paranoid.alpha.int>
In-Reply-To: <319DB26BA2E818469512F920DCE19E18013AF3@futuna.agences.strathom> from "Frederic Le Bastard <frederic.lebastard@strathom.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: Antivirus for FWTK (smap / smapd)
To: frederic.lebastard@strathom.com
Cc: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1547

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

I am developing a client-server protocol for that now, any suggestions?
The server part will probably be AMaViS.

I am not going to limit it to mail only, so one of the questions is: how
to deal with client timeouts when i have to inspect a big file being transferred
via http or ftp over a slow link? I can't start passing data to the client
before the file was checked.. 

Frederic Le Bastard <frederic.lebastard@strathom.com> said :

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello there,
> 
> I'm currently looking for a good antivirus software tweaked for FWTK.
> If any of you here have already implemented such a configuration, please let
> me know.
> 
> Thanks in advance
> 
> Fred
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOn6opKH/mIJW9LeBAQFEpAP+LoPvR76lslgisEtAnPtb9oKThWX6PU/t
GXUbyGw0N6+GiQNTaabfsfHpXEeoW22M4JG5B9jBe011R2VnKWUzmrKEzLrQtnqD
NgBlUw+T+oHItV/jl78CHz5fy9jZeomZwXYW7Urt2Mppbp5NGx3Qr/ofBGvrgnUc
cZvsUn+vSis=
=4grj
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Mon Feb  5 09:07 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA22601
	Mon, 5 Feb 2001 09:07:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA01041;
	Mon, 5 Feb 2001 06:10:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 06:07:59 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA00448
	for fwtk-users-outgoing; Mon, 5 Feb 2001 06:07:58 -0800 (PST)
Message-ID: <00d001c08f7d$5857b1c0$7236a8c0@ibmbn1f23h>
From: "Larry Moore" <lmoore@starwon.com.au>
To: "Frederic Le Bastard" <frederic.lebastard@strathom.com>,
        <fwtk-users@lists.nai.com>
References: <319DB26BA2E818469512F920DCE19E18013AF3@futuna.agences.strathom>
Subject: Re: Antivirus for FWTK (smap / smapd)
Date: Mon, 5 Feb 2001 22:10:07 +0800
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 944

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

You may want to have a look at AvMailGate.

It can be found at http://www.hbedv.com

Cheers,

Larry.
----- Original Message -----
From: "Frederic Le Bastard" <frederic.lebastard@strathom.com>
To: <fwtk-users@lists.nai.com>
Sent: Monday, February 05, 2001 6:16 PM
Subject: Antivirus for FWTK (smap / smapd)


> [To be removed from this list send the message "unsubscribe fwtk-users" in
the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Hello there,
>
> I'm currently looking for a good antivirus software tweaked for FWTK.
> If any of you here have already implemented such a configuration, please
let
> me know.
>
> Thanks in advance
>
> Fred
>
>
> Frédéric LE BASTARD - flb@strathom.com
> Tél. +33 240 353 232 / Fax. +33 240 121 874
> GSM. +33 615 022 951
> STRATHOM Informatique - Nantes - France
>
>
>


From owner-fwtk-users@ex.tis.com Mon Feb  5 18:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA24977
	Mon, 5 Feb 2001 18:15:19 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA05999;
	Mon, 5 Feb 2001 15:17:49 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 15:02:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA00244
	for fwtk-users-outgoing; Mon, 5 Feb 2001 15:02:27 -0800 (PST)
Message-Id: <5.0.2.1.0.20010205172938.01d21ca0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Mon, 05 Feb 2001 17:34:16 -0500
To: Keith Young <kyoung@v-one.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Some questions [authentification, ftp-gw, http-gw]
Cc: fwtk-users@lists.nai.com
In-Reply-To: <3A7EA2CD.9580B4BE@v-one.com>
References: <5.0.2.1.0.20010205062009.01d2c080@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1127

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:55 AM 2/5/01 -0500, Keith Young wrote:

>Rick,
>
>Instead of the front-end, couldn't you add 2 auth timeouts in http-gw:
>one timeout which states that your auth will be good for X seconds, and
>another which states that if you don't go through http-gw in X seconds,
>you will need to re-auth?

Nope. Each http-gw instance only handles one element of a web page. You 
need something to keep the context. Worse is how click-ahead works - if you 
open a web page with 15 or 20 different elements, your browser posts 
requests for those 4 or 5 at a time. If you click off that page, the 
browser then drops all those connections.

Now, the front-end isn't the only way to do this. A simple authentication 
process that keeps open a shared-memory segment that all the daemon http-gw 
processes interrogate about authentication decisions could also work. 
You've got to do something to minimize the overhead - http-gw processes are 
short-lived so you want them to be lightweight.
         -Rick


From owner-fwtk-users@ex.tis.com Mon Feb  5 18:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA24981
	Mon, 5 Feb 2001 18:15:39 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA06165;
	Mon, 5 Feb 2001 15:18:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 15:02:29 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA00237
	for fwtk-users-outgoing; Mon, 5 Feb 2001 15:02:17 -0800 (PST)
Date: Mon, 5 Feb 2001 17:59:18 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: ark@eltex.ru
cc: fwtk-users@lists.nai.com
Subject: Re: updated smap
In-Reply-To: <200102051300.QAA25368@paranoid.alpha.int>
Message-ID: <Pine.GSO.4.10.10102051753540.3593-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2107

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Pretty much wrote my own.  Based it on the spam list provided by 

 Linkname: Oasel the Spam-Catcher's Report to the Nation
        URL: http://www.cnx.com/stopspam.html

This is all part of the smap program.  Processing is performed in copies
of standard buffers - not to modify the original message in any way.  This
- along with the spam filters modified from pabs provided list above -
are catching an estimated 95+ percent of spam coming into my
organization.

Last week alone - I blocked .... somewhere arount 21,000-25,000 spam
messages out of about 150.000 total deliveries.

This isn't everything - but it is a big help to the downstream e-mail
admins and end users.

tek


On Mon, 5 Feb 2001 ark@eltex.ru wrote:

> nuqneH,
> 
> What did you use for filtering engine? Wrote your own one?
> 
> Ted Keller <keller@bfg.com> said :
> 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > I've updated my smap version to enable spam content filtering for mail
> > with embedded html tags.  Been running it for a couple of weeks now and it
> > seems to hold together pretty good.
> > 
> > The code also recognized javascript - and handles it effectively.
> > 
> > I also added a feature to allow for substing matching in html tagged
> > areas.  This permits the rejection of mail based on a partial url entry.
> > An example may be 
> > 
> > tag nudecasino.com
> > 
> > This will reject any message with a url containing these characters.
> > 
> > If anyone is interested, please contact me offline and I will tell you
> > where to pick it up at.
> > 
> > ted keller
> > 
> > 
> 
>                                      _     _  _  _  _      _  _
>  {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
>  (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
>  [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!
> 


From owner-fwtk-users@ex.tis.com Mon Feb  5 18:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA24988
	Mon, 5 Feb 2001 18:16:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA06385;
	Mon, 5 Feb 2001 15:18:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 15:05:36 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA01351
	for fwtk-users-outgoing; Mon, 5 Feb 2001 15:05:30 -0800 (PST)
Date: Mon, 5 Feb 2001 17:27:50 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Zakharov Mikhail <zmey20000@yahoo.com>
cc: fwtk-users@lists.nai.com
Subject: Re: Some questions [authentification, ftp-gw, http-gw]
In-Reply-To: <20010205063029.37323.qmail@web12407.mail.yahoo.com>
Message-ID: <Pine.GSO.4.10.10102051724090.3593-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1978

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Mikhail,

>From your browser, set all of the services to point to the http-gw gateway
- http and ftp - on port 80.  Have the http-gw permit access with the
permit-hosts entries.  No separate authtentication is avaialable.

With regard to ftp-gw, a number of graphical clients work well with the
ftp-gw.  Here you can implement separaate authentication based on a user
id if desired.  I have a number of users that employ cute-ftp, ws-ftp, and
others and use the ftp-gw.

Let me know if you need additional info.

ted keller

On Sun, 4 Feb 2001, Zakharov Mikhail wrote:

> 
> --- Ted Keller <keller@bfg.com> wrote:
> > Zakharov,
> > 
> > Did you get your question answered? 
> 
> Unfortunally not.  Can you help me?
> 
> > If not - let me know and I will try
> > to help.  Been pretty busy lately, so I haven't been
> > able to respond
> > sooner.
> > 
> > ted keller
> > 
> > 
> > On Fri, 2 Feb 2001, Zakharov Mikhail wrote:
> > 
> > > [To be removed from this list send the message
> > "unsubscribe fwtk-users" in the
> > > BODY of a mail message to majordomo@ex.tis.com.]
> > > 
> > > Hello,
> > > 
> > > I have several questions about FWTK:
> > > 
> > > 1. Is it possible to setup ftp-gw to work with
> > > browsers, or I have to use http-gw for
> > ftp-connections
> > > (as it was written in FAQ) ?
> > > 
> > > 2. How can I setup authentification to work with
> > > browsers? For http-gw it's impossible, and what
> > about
> > > ftp-gw?
> > > 
> > > Best regards
> > > Mikhail
> > > 
> > > __________________________________________________
> > > Get personalized email addresses from Yahoo! Mail
> > - only $35 
> > > a year!  http://personal.mail.yahoo.com/
> > > 
> > 
> 
> 
> __________________________________________________
> Get personalized email addresses from Yahoo! Mail - only $35 
> a year!  http://personal.mail.yahoo.com/
> 


From owner-fwtk-users@ex.tis.com Mon Feb  5 19:09 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA25197
	Mon, 5 Feb 2001 19:09:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA16642;
	Mon, 5 Feb 2001 16:11:45 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Feb 2001 16:06:04 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA15230
	for fwtk-users-outgoing; Mon, 5 Feb 2001 16:06:01 -0800 (PST)
Message-ID: <3A7F40B2.E1B568FE@v-one.com>
Date: Mon, 05 Feb 2001 19:09:22 -0500
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: fwtk-users@lists.nai.com
Subject: Re: Some questions [authentication, ftp-gw, http-gw]
References: <5.0.2.1.0.20010205062009.01d2c080@mail.itm-inst.com> <5.0.2.1.0.20010205172938.01d21ca0@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1578

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick Murphy wrote:
> 
> At 07:55 AM 2/5/01 -0500, Keith Young wrote:
> >Rick,
> >
> >Instead of the front-end, couldn't you add 2 auth timeouts in http-gw:
> >one timeout which states that your auth will be good for X seconds, and
> >another which states that if you don't go through http-gw in X seconds,
> >you will need to re-auth?
> 
> Nope. Each http-gw instance only handles one element of a web page. You
> need something to keep the context. Worse is how click-ahead works - if you
> open a web page with 15 or 20 different elements, your browser posts
> requests for those 4 or 5 at a time. If you click off that page, the
> browser then drops all those connections.
> 
> Now, the front-end isn't the only way to do this. A simple authentication
> process that keeps open a shared-memory segment that all the daemon http-gw
> processes interrogate about authentication decisions could also work.
> You've got to do something to minimize the overhead - http-gw processes are
> short-lived so you want them to be lightweight.

Actually, I thought about my comments as I was driving into work. Guess
trying to think before 8:00am is a bad idea for me  :-).

I forgot to mention to use my recommendation with a shared memory pool,
which could also be used to "cache" the netperm-table instead of reading
it from disk.

Sorry for my (early morning) stupidity.

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Tue Feb  6 06:35 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA28415
	Tue, 6 Feb 2001 06:35:08 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA20236;
	Tue, 6 Feb 2001 03:34:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Feb 2001 03:28:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA19487
	for fwtk-users-outgoing; Tue, 6 Feb 2001 03:28:25 -0800 (PST)
From: ark@eltex.ru
Date: Tue, 6 Feb 2001 14:44:17 +0300
Message-Id: <200102061144.OAA29618@paranoid.alpha.int>
In-Reply-To: <Pine.GSO.4.10.10102051753540.3593-100000@ns1.bfg.com> from "Ted Keller <keller@bfg.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: updated smap
To: keller@bfg.com
Cc: ark@eltex.ru, fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 3068

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

What about using html filtering engine from squid-gw for html mail?

I am thinking about dropping the whole smap/smapd thing completely and replacing
it with smtpd/smtpfwdd converted to fwtk configuration and logging style
(because of NAI licensing problems with original toolkit).

smtpd/smtpfwdd is much bigger, that is bad.
OpenBSD audited version does exist, that is good.

Ted Keller <keller@bfg.com> said :

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Pretty much wrote my own.  Based it on the spam list provided by 
> 
>  Linkname: Oasel the Spam-Catcher's Report to the Nation
>         URL: http://www.cnx.com/stopspam.html
> 
> This is all part of the smap program.  Processing is performed in copies
> of standard buffers - not to modify the original message in any way.  This
> - along with the spam filters modified from pabs provided list above -
> are catching an estimated 95+ percent of spam coming into my
> organization.
> 
> Last week alone - I blocked .... somewhere arount 21,000-25,000 spam
> messages out of about 150.000 total deliveries.
> 
> This isn't everything - but it is a big help to the downstream e-mail
> admins and end users.
> 
> tek
> 
> 
> On Mon, 5 Feb 2001 ark@eltex.ru wrote:
> 
> > nuqneH,
> > 
> > What did you use for filtering engine? Wrote your own one?
> > 
> > Ted Keller <keller@bfg.com> said :
> > 
> > > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > > BODY of a mail message to majordomo@ex.tis.com.]
> > > 
> > > I've updated my smap version to enable spam content filtering for mail
> > > with embedded html tags.  Been running it for a couple of weeks now and it
> > > seems to hold together pretty good.
> > > 
> > > The code also recognized javascript - and handles it effectively.
> > > 
> > > I also added a feature to allow for substing matching in html tagged
> > > areas.  This permits the rejection of mail based on a partial url entry.
> > > An example may be 
> > > 
> > > tag nudecasino.com
> > > 
> > > This will reject any message with a url containing these characters.
> > > 
> > > If anyone is interested, please contact me offline and I will tell you
> > > where to pick it up at.
> > > 
> > > ted keller
                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOn/jj6H/mIJW9LeBAQFcjgP9EuKl7jIZFwHw8fxzO0bjDeIfCMVsdxNU
irA2hcavTL2NIxRJbIJHFCwkdIaD8hooNIr93hoYDtw76r4yUjOCpiKw8VvPD62s
jMw9mg09a6Z6dlHuJ1VzdNaHnUYfDk7JcdtYtaCb2cGUuRHv4z0vYQJypsm3j0R0
I0XIkfNqcow=
=UYXG
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Tue Feb  6 10:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA29885
	Tue, 6 Feb 2001 10:08:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA04573;
	Tue, 6 Feb 2001 07:11:29 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Feb 2001 07:08:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA03458
	for fwtk-users-outgoing; Tue, 6 Feb 2001 07:08:05 -0800 (PST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@lists.nai.com>
Subject: smtpd/smtpfwdd
Date: Tue, 6 Feb 2001 09:05:59 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFCEPJOPAA.luba@assist.com.gt>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 541

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

How bad is smtpd/smtpdfwdd?

I don't ask how good, becuase I use it already instead of smap/smapd, since
it has a simpler (I think) way
of configuring the anti-relay-anti-spam stuff...

I read some comentary about the smtpd/smtpdfwdd being too big...

If ark@eltex.ru can integrate this software into the fwtk configuration
style, that
really would be nice...

Luis Fernando Barrera
luba@assist.com.gt


From owner-fwtk-users@ex.tis.com Tue Feb  6 12:14 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA00696
	Tue, 6 Feb 2001 12:14:55 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA22805;
	Tue, 6 Feb 2001 09:17:31 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Feb 2001 09:12:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA21600
	for fwtk-users-outgoing; Tue, 6 Feb 2001 09:12:22 -0800 (PST)
Message-ID: <3A802EFC.ED932F18@promos-consult.de>
Date: Tue, 06 Feb 2001 18:06:04 +0100
From: Andreas Priebe <Andreas.Priebe@promos-consult.de>
X-Mailer: Mozilla 4.7 [de]C-CCK-MCD QXW0322h  (WinNT; I)
X-Accept-Language: de,en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: PORT ftp problem
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 869

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I use the ftp-gw to allow access from external machines.
Some sites which connect to us experience problems, which I nailed
down to the following scenario:

They connect with PORT, e.g. with

PORT 194,141,101,131,239,255

they request a connection to data port 61439.
The ftp-gw opens a connection from port 4146 (e.g.) -
i.e. not from port 20.
Is this conforming to the RFCs? The admin of the
remote site claims, that the connection should
originate from port 20 in case of the "normal" (non passive)
scenario so they effectivly block my connection attempts
for the data caonnection on their firewall.

Any references? I tried to extract the information
form RFCs 959 and 1123 but without sucess.

Thanx for any information,

Andreas

From owner-fwtk-users@ex.tis.com Tue Feb  6 17:44 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA02898
	Tue, 6 Feb 2001 17:44:20 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA19658;
	Tue, 6 Feb 2001 14:46:58 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Feb 2001 14:42:34 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA18489
	for fwtk-users-outgoing; Tue, 6 Feb 2001 14:42:32 -0800 (PST)
Message-Id: <5.0.2.1.0.20010206172947.0460a920@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 06 Feb 2001 17:34:21 -0500
To: Keith Young <kyoung@v-one.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Some questions [authentification, ftp-gw, http-gw]
Cc: fwtk-users@lists.nai.com
In-Reply-To: <3A7EA2CD.9580B4BE@v-one.com>
References: <5.0.2.1.0.20010205062009.01d2c080@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1305

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:55 AM 2/5/01 -0500, Keith Young wrote:
>Instead of the front-end, couldn't you add 2 auth timeouts in http-gw:
>one timeout which states that your auth will be good for X seconds, and
>another which states that if you don't go through http-gw in X seconds,
>you will need to re-auth?

That's perfectly OK - especially with one-time passwords. There's no such 
thing as a persistent connection, so you've got to have some way of 
avoiding re-authenticating users all the time.

>I know that it is not as secure (since people could then "steal" your IP
>address and go through the proxy un-authenticated), but I'd guess that
>it would be easier to write than what you mentioned. But I guess if you
>are using clear-text name/password schemes then you don't really care
>about being secure in the first place  :-).....

But.. you've got to have something somewhere to keep track of what users 
are authenticated, external to the http-gw. It's got to be a lightweight 
authentication process of some sort.

(Admittedly, I'm biased by the design of the Gauntlet authenticating http 
proxy; we had to solve several of these problems to make something usable.)
         -Rick


From owner-fwtk-users@ex.tis.com Tue Feb  6 17:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA02971
	Tue, 6 Feb 2001 17:59:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA23037;
	Tue, 6 Feb 2001 15:01:54 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Feb 2001 14:57:30 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA22232
	for fwtk-users-outgoing; Tue, 6 Feb 2001 14:57:29 -0800 (PST)
Message-Id: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 06 Feb 2001 17:39:43 -0500
To: Andreas Priebe <Andreas.Priebe@promos-consult.de>,
        fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: PORT ftp problem
In-Reply-To: <3A802EFC.ED932F18@promos-consult.de>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 851

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 06:06 PM 2/6/01 +0100, Andreas Priebe wrote:
>The ftp-gw opens a connection from port 4146 (e.g.) -
>i.e. not from port 20.

That's right.

>Is this conforming to the RFCs?
Yes.
The recommended default data port is control port - 1 (or port 20).
Some filters allow *anything* with source port 20 to sail through in order 
to allow FTP data connections; sounds like that's what your remote site 
admin wants.
There's a patch for the ftp-gw to permit this, but you really should be 
warning your remote admin that if they're really trusting everything with 
source port 20 to sail through their filters, they're wide open to attack.

Get the patch from <http://www.fwtk.org/fwtk/patches/patches.html#2.9>
         -Rick


From owner-fwtk-users@ex.tis.com Thu Feb  8 10:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA04486
	Thu, 8 Feb 2001 10:42:53 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA24905;
	Thu, 8 Feb 2001 07:45:30 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Feb 2001 07:38:10 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA23245
	for fwtk-users-outgoing; Thu, 8 Feb 2001 07:37:57 -0800 (PST)
Message-ID: <3A82A95A.947F100C@promos-consult.de>
Date: Thu, 08 Feb 2001 15:12:42 +0100
From: Andreas Priebe <Andreas.Priebe@promos-consult.de>
X-Mailer: Mozilla 4.7 [de]C-CCK-MCD QXW0322h  (WinNT; I)
X-Accept-Language: de,en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: fwtk-users@lists.nai.com
Subject: Re: PORT ftp problem
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 690

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi Rick,

you wrote:

> At 06:06 PM 2/6/01 +0100, Andreas Priebe wrote:
> >The ftp-gw opens a connection from port 4146 (e.g.) -
> >i.e. not from port 20.
> 
> That's right.
> 
> >Is this conforming to the RFCs?
> Yes.
> The recommended default data port is control port - 1 (or port 20).

Have you any concrete references in some RFC that other data ports
are allowed?
I little bit of digging in Stevens' Vol. I gives me:
"... The server's end of the data connection always uses port 20."

(6th printing, 1985, p. 425 - yes I know its ancient ... :-)

Andreas

From owner-fwtk-users@ex.tis.com Thu Feb  8 21:56 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA06518
	Thu, 8 Feb 2001 21:56:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA08184;
	Thu, 8 Feb 2001 18:58:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Feb 2001 18:54:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA07575
	for fwtk-users-outgoing; Thu, 8 Feb 2001 18:54:39 -0800 (PST)
Message-Id: <5.0.2.1.0.20010208213812.0499f310@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 08 Feb 2001 21:49:05 -0500
To: Andreas Priebe <Andreas.Priebe@promos-consult.de>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: PORT ftp problem
Cc: fwtk-users@lists.nai.com
In-Reply-To: <3A82A95A.947F100C@promos-consult.de>
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1229

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 03:12 PM 2/8/01 +0100, Andreas Priebe wrote:
>Have you any concrete references in some RFC that other data ports
>are allowed?

RFC 959 ("FILE TRANSFER PROTOCOL"). The specification of the data port to 
be used (20) calls it the "default data port", and says that the user agent 
can initiate the use of non-default ports (Section 3.3, Data management.)

You can require the use of port 20 only if you remove the word "default".
Whether ftp-gw is a server agent or a user agent, however, is quite debatable.

>I little bit of digging in Stevens' Vol. I gives me:
>"... The server's end of the data connection always uses port 20."

That's an unjustified absolute. "usually" is more accurate.

Basically, there's no way to guarantee that you can always use port 20. 
(Because of a previous connection in close-wait state.) For most ftp 
servers, that's not a big problem, but firewalls occasionally run into 
this. All you can do in that case is to try another source port, or 
generate an error. Using a random port eliminates this problem, but it's 
not in the spirit of RFC 959.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Feb  9 05:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA07452
	Fri, 9 Feb 2001 05:16:03 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA23882;
	Fri, 9 Feb 2001 02:18:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 02:13:06 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA23259
	for fwtk-users-outgoing; Fri, 9 Feb 2001 02:13:03 -0800 (PST)
Message-ID: <3A83C150.89A9F330@promos-consult.de>
Date: Fri, 09 Feb 2001 11:07:12 +0100
From: Andreas Priebe <Andreas.Priebe@promos-consult.de>
X-Mailer: Mozilla 4.7 [de]C-CCK-MCD QXW0322h  (WinNT; I)
X-Accept-Language: de,en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: fwtk-users@lists.nai.com
Subject: Re: PORT ftp problem
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com> <5.0.2.1.0.20010208213812.0499f310@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1483

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick Murphy wrote:
 
> RFC 959 ("FILE TRANSFER PROTOCOL"). The specification of the data port to
> be used (20) calls it the "default data port", and says that the user agent
> can initiate the use of non-default ports (Section 3.3, Data management.)
> 
> You can require the use of port 20 only if you remove the word "default".
> Whether ftp-gw is a server agent or a user agent, however, is quite debatable.

But in my case I think it is quite clear that ftp-gw is the server
agent,
as we talk about a remote ftp client, who ftp's into my ftp-gw.
So this together with RFC 959 (Sect. 3.3) "and only the User-PI may
initiate
the use of non-default ports." seems to indicate (at least for me),
that the behaviour of ftp-gw is not correct.

I am not sure if I made really clear, what I mean, so just to be
sure:

1. remote client opens ftp control channel from port >1024 to
ftp-gw-port 21.
2. remote client says PORT a,b,c,d,e,f
3. ftp-gw opens data channel from port >1024 to remote client port
e*256+f
4. this fails, because firewall on the side of the remote clients
expects
   "active" ftp (negotiated with PORT) always to come from port 20 (and
   not from random port >1024 as ftp-gw does).

BTW: The fix in http://www.fwtk.org/fwtk/patches/patches.html#2.9 does
not work for me, because It collieds with patch 2.11 which I have
applied.

Andreas

From owner-fwtk-users@ex.tis.com Fri Feb  9 05:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA07495
	Fri, 9 Feb 2001 05:34:36 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA25542;
	Fri, 9 Feb 2001 02:37:16 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 02:32:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA24752
	for fwtk-users-outgoing; Fri, 9 Feb 2001 02:32:52 -0800 (PST)
Message-ID: <3A83C5C8.DC424ECD@promos-consult.de>
Date: Fri, 09 Feb 2001 11:26:16 +0100
From: Andreas Priebe <Andreas.Priebe@promos-consult.de>
X-Mailer: Mozilla 4.7 [de]C-CCK-MCD QXW0322h  (WinNT; I)
X-Accept-Language: de,en
MIME-Version: 1.0
To: Tor Perkins <979070108@noid.net>
CC: fwtk-users@tis.com
Subject: Re: ftp-pasv patch and remote port decodes (a patch)
References: <20010103143158.F20853@bds.ucs.co.za> <200101092048.MAA20045@noid.net>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1108

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Tor Perkins wrote on Tue, 9 Jan 2001 12:48:34:
 
> The problem:
> 
>    The original code for parsing an FTP servers PASV response was not
>    sufficiently general, so sometimes the port decode would fail and
>    the data connection could not happen.
> 
>      possible formats include (RFC 959 is ambiguous):
> 
>        227 Entering Passive Mode (h1,h2,h3,h4,p1,p2)    <-- most servers
>        227 Entering Passive Mode (h1,h2,h3,h4,p1,p2).   <-- some servers
>        227 =h1,h2,h3,h4,p1,p2                           <-- sez' D. J. Bernstein
> 
> Luis Fernando Barrera pointed this out to me and Berend De Schouwer
> has even included a patch for it already.  This is the patch I made.
> It tries to handle all of the cases listed above.

I have downloaded the path from fwtk.org.
I had previously applied the older patch (ftp-pasv.tgz with only two
diffs).
How do I apply the new patch? Additionally, or do I have to aplly
some procedure to remove the older one?

Andreas

From owner-fwtk-users@ex.tis.com Fri Feb  9 08:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA07958
	Fri, 9 Feb 2001 08:33:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA01244;
	Fri, 9 Feb 2001 05:36:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 05:32:48 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA00568
	for fwtk-users-outgoing; Fri, 9 Feb 2001 05:32:47 -0800 (PST)
Message-ID: <00c401c09294$652bd380$0d72a4a4@vantel.soft.net>
From: "Manav" <manavg@vantel.soft.net>
To: <fwtk-users@ex.tis.com>
Date: Fri, 9 Feb 2001 18:02:36 +0530
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_00C1_01C092C2.7BA02F20"
Content-Length: 1313

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_00C1_01C092C2.7BA02F20
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

hi
   i need to setup my sendmail behind a firewall. the mail server is in =
my private netwrok and i want it like that. can utell me how to =
configure it

thxs

------=_NextPart_000_00C1_01C092C2.7BA02F20
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Diso-8859-1" =
http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2920.0" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>
<DIV><FONT face=3DArial size=3D2>hi</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>&nbsp;&nbsp; i need to setup my =
sendmail behind a=20
firewall. the mail server is in my private netwrok and i want it like =
that. can=20
utell me how to configure it</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial =
size=3D2>thxs</FONT></DIV></FONT></DIV></BODY></HTML>

------=_NextPart_000_00C1_01C092C2.7BA02F20--

From owner-fwtk-users@ex.tis.com Fri Feb  9 14:11 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA08907
	Fri, 9 Feb 2001 14:11:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA08325;
	Fri, 9 Feb 2001 11:14:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 11:08:19 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA07109
	for fwtk-users-outgoing; Fri, 9 Feb 2001 11:08:17 -0800 (PST)
Message-Id: <5.0.2.1.0.20010209134013.042385f0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Fri, 09 Feb 2001 13:53:47 -0500
To: Andreas Priebe <Andreas.Priebe@promos-consult.de>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: PORT ftp problem
Cc: fwtk-users@lists.nai.com
In-Reply-To: <3A83C150.89A9F330@promos-consult.de>
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com>
 <5.0.2.1.0.20010208213812.0499f310@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1129

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:07 AM 2/9/01 +0100, Andreas Priebe wrote:
>But in my case I think it is quite clear that ftp-gw is the server
>agent,

Not always. It's the user agent when it's talking to the remote FTP server 
at the very least. :-)

>4. this fails, because firewall on the side of the remote clients
>expects
>    "active" ftp (negotiated with PORT) always to come from port 20 (and
>    not from random port >1024 as ftp-gw does).

I know that's the problem; in my opinion, that "expectation" isn't 
guaranteed; however, the patch exists to try to meet the expectations when 
possible.


>BTW: The fix in http://www.fwtk.org/fwtk/patches/patches.html#2.9 does
>not work for me, because It collieds with patch 2.11 which I have
>applied.

I think patch 2.11 adds a data-port capability already - if not, you should 
be able to add the code from patch 2.9 "by hand" into the callback() 
routine. I might suggest splitting the setting into "pasv-port" and 
"data-port" netperm-entries, though.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Feb  9 14:46 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA09027
	Fri, 9 Feb 2001 14:46:52 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA14010;
	Fri, 9 Feb 2001 11:49:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 11:45:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA12817
	for fwtk-users-outgoing; Fri, 9 Feb 2001 11:45:35 -0800 (PST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@lists.nai.com>
Subject: smap issue
Date: Fri, 9 Feb 2001 13:43:09 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFOEABPAAA.luba@assist.com.gt>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 643

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

I'm having the following problem:


When someone behind the firewall sends an email message to a non-existent
user,
like anybody@yahoo.com or to a non-existen domaind, let's say
test@nodomain.com;
he or she doesn't receive any notification about the problem.

I saw in the logfile that when smapd, tries to connect back to the mail
server, to inform
the user about the non-existen user/domain, the mail server answer "service
unavailable".

Any ideas...

Thanks

Luis Fernando Barrera
luba@assist.com.gt


From owner-fwtk-users@ex.tis.com Fri Feb  9 17:50 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA09354
	Fri, 9 Feb 2001 17:50:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA07277;
	Fri, 9 Feb 2001 14:52:54 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 14:48:55 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA06454
	for fwtk-users-outgoing; Fri, 9 Feb 2001 14:48:53 -0800 (PST)
Date: Fri, 9 Feb 2001 17:47:12 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Luis Fernando Barrera <luba@assist.com.gt>
cc: fwtk-users@lists.nai.com
Subject: Re: smap issue
In-Reply-To: <NABBIDJPNCAGKGOFGHBFOEABPAAA.luba@assist.com.gt>
Message-ID: <Pine.GSO.4.10.10102091746450.5385-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 996

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Luis,

Try telneting to you mail server on port 25 and see if it responds.  YOu
may not have the service running?

tek


On Fri, 9 Feb 2001, Luis Fernando Barrera wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi all,
> 
> I'm having the following problem:
> 
> 
> When someone behind the firewall sends an email message to a non-existent
> user,
> like anybody@yahoo.com or to a non-existen domaind, let's say
> test@nodomain.com;
> he or she doesn't receive any notification about the problem.
> 
> I saw in the logfile that when smapd, tries to connect back to the mail
> server, to inform
> the user about the non-existen user/domain, the mail server answer "service
> unavailable".
> 
> Any ideas...
> 
> Thanks
> 
> Luis Fernando Barrera
> luba@assist.com.gt
> 


From owner-fwtk-users@ex.tis.com Fri Feb  9 21:03 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA09832
	Fri, 9 Feb 2001 21:03:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA17652;
	Fri, 9 Feb 2001 18:05:52 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Feb 2001 18:00:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA17027
	for fwtk-users-outgoing; Fri, 9 Feb 2001 18:00:07 -0800 (PST)
Date: Fri, 09 Feb 2001 18:19:07 -0800
From: Carson Gaspar <carson@taltos.org>
To: Andreas Priebe <Andreas.Priebe@promos-consult.de>,
        Rick Murphy <rmurphy@itm-inst.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: PORT ftp problem
Message-ID: <627885111.981742747@[10.10.3.1]>
In-Reply-To: <3A82A95A.947F100C@promos-consult.de>
References:  <3A82A95A.947F100C@promos-consult.de>
X-Mailer: Mulberry/2.1.0a2 (Win32)
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Length: 932

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



--On Thursday, February 08, 2001 3:12 PM +0100 Andreas Priebe 
<Andreas.Priebe@promos-consult.de> wrote:

> Have you any concrete references in some RFC that other data ports
> are allowed?

I really wish that all the ignorant "the RFC says it has to use port 20" 
folks would actually bother reading the RFC themselves. Until then, here is 
Yet Another FTP Data Port Explanation. <sigh>

The RFC states that the default data port SHOULD be one less than the 
control port. So:

- If FTP is on a port 21, the server SHOULD use port 20. But this is a 
SHOULD, not a MUST, therefore other ports are legal.
- Similarly, if you install an FTP server on port 666, it SHOULD use port 
665 as a data port, but it may use a different port.

-- 
Carson Gaspar - carson@taltos.org
Queen trapped in a butch body

From owner-fwtk-users@ex.tis.com Sat Feb 10 16:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA11874
	Sat, 10 Feb 2001 16:08:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA08114;
	Sat, 10 Feb 2001 13:10:59 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 10 Feb 2001 12:59:45 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA07410
	for fwtk-users-outgoing; Sat, 10 Feb 2001 12:59:43 -0800 (PST)
X-Authentication-Warning: proxy.tfcc.com: mail set sender to <twilliams@tfcci.com> using -f
From: "Todd Williams" <twilliams@tfcci.com>
To: <fwtk-users@lists.nai.com>
Subject: SMAP/SMAPD virus scan question
Date: Sat, 10 Feb 2001 15:55:34 -0500
Message-ID: <017801c093a3$d09b12b0$c802a8c0@toddntbox.tfcc.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 790

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Forgive me for this is slightly off topic, but...

Is anybody successfully using smap/smapd with virus scanning?  I looked into
AMaViS a while ago, and it looks okay.  I had some difficulties in getting
it to work with smap/smapd correctly, and gave up after several hours of
working on it and reconfiguring it to try to get it to work properly.  My
virus scanner of choice is NAI/McAfee's uvscan.  Is there anybody out there
running AMaViS that might be willing to share some configuration tips, or
are there any other good suggestions for a virus scanner that will integrate
into the TIS FWTK smap/smapd compiled on Redhat 5.x/6.x?

Thanks in advance,

Todd


From owner-fwtk-users@ex.tis.com Sat Feb 10 16:32 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA11910
	Sat, 10 Feb 2001 16:32:29 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA09664;
	Sat, 10 Feb 2001 13:35:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 10 Feb 2001 13:29:29 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA09006
	for fwtk-users-outgoing; Sat, 10 Feb 2001 13:29:29 -0800 (PST)
From: rreiner@fscinternet.com
X-OpenMail-Hops: 1
Date: Sat, 10 Feb 2001 16:28:44 -0500
Message-Id: <H000006a0028d690.0981840524.river.fscinternet.com@MHS>
Subject: RE: SMAP/SMAPD virus scan question
MIME-Version: 1.0
TO: fwtk-users@lists.nai.com, twilliams@tfcci.com
Content-Disposition: inline
	;Creation-Date="Sat, 10 Feb 2001 16:28:44 -0500"
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
	;Creation-Date="Sat, 10 Feb 2001 16:28:44 -0500"
Content-Length: 361

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> Is anybody successfully using smap/smapd with virus scanning? 

Yes, but only on Gauntlet, not TIS FWTK :-).

(On Gauntlet, the NAI/McAfee engine is built in -- just turn it on, no 
additional components required, works great).



From owner-fwtk-users@ex.tis.com Mon Feb 12 13:02 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA18882
	Mon, 12 Feb 2001 13:02:51 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA12798;
	Mon, 12 Feb 2001 10:05:38 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 12 Feb 2001 09:54:03 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA10317
	for fwtk-users-outgoing; Mon, 12 Feb 2001 09:54:01 -0800 (PST)
Date: Mon, 12 Feb 2001 12:52:53 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: rreiner@fscinternet.com
Cc: fwtk-users@lists.nai.com, twilliams@tfcci.com
Subject: Re: SMAP/SMAPD virus scan question
Message-Id: <20010212125253.B28047@washington.cospo.osis.gov>
Mail-Followup-To: rreiner@fscinternet.com, fwtk-users@lists.nai.com,
	twilliams@tfcci.com
References: <H000006a0028d690.0981840524.river.fscinternet.com@MHS>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <H000006a0028d690.0981840524.river.fscinternet.com@MHS>; from rreiner@fscinternet.com on Sat, Feb 10, 2001 at 04:28:44PM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 809

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Sat, Feb 10, 2001 at 04:28:44PM -0500, rreiner@fscinternet.com wrote:
> > Is anybody successfully using smap/smapd with virus scanning? 
> 
> Yes, but only on Gauntlet, not TIS FWTK :-).
> 
> (On Gauntlet, the NAI/McAfee engine is built in -- just turn it on, no 
> additional components required, works great).

No, several people have successfully inserted virus scanners betwen
'smap' and 'smapd' in FWTK.  This is not a great feat of engineering.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Mon Feb 12 13:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA18943
	Mon, 12 Feb 2001 13:16:24 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA16051;
	Mon, 12 Feb 2001 10:19:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 12 Feb 2001 10:12:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA13935
	for fwtk-users-outgoing; Mon, 12 Feb 2001 10:12:25 -0800 (PST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: "Ted Keller" <keller@bfg.com>
Cc: <fwtk-users@lists.nai.com>
Subject: RE: smap issue
Date: Mon, 12 Feb 2001 12:09:37 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFKEAEPAAA.luba@assist.com.gt>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
In-Reply-To: <Pine.GSO.4.10.10102091746450.5385-100000@ns1.bfg.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1874

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Yes, the service is running... In fact I can send/receive email without
any problem...
The problem is when I send an email to a non-existent user in other domain
(like nobody@bfg.com); I should (I guess) receive a notificaction about the
non-existent user.

I also noticed that smap (maybe it is sendmail) creates a file called
"dead.letter" in the /var/tmp directory. Into that
file there are all the messages I should receive about the non-existent user
or domain.

I'm thinking it is a problem of the mail server, but I don't have a clue,
since the normally all
the emaill messages pass through ok.

Luis



> -----Original Message-----
> From: Ted Keller [mailto:keller@bfg.com]
> Sent: Friday, February 09, 2001 4:47 PM
> To: Luis Fernando Barrera
> Cc: fwtk-users@lists.nai.com
> Subject: Re: smap issue
>
>
> Luis,
>
> Try telneting to you mail server on port 25 and see if it responds.  YOu
> may not have the service running?
>
> tek
>
>
> On Fri, 9 Feb 2001, Luis Fernando Barrera wrote:
>
> > [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > Hi all,
> >
> > I'm having the following problem:
> >
> >
> > When someone behind the firewall sends an email message to a
> non-existent
> > user,
> > like anybody@yahoo.com or to a non-existen domaind, let's say
> > test@nodomain.com;
> > he or she doesn't receive any notification about the problem.
> >
> > I saw in the logfile that when smapd, tries to connect back to the mail
> > server, to inform
> > the user about the non-existen user/domain, the mail server
> answer "service
> > unavailable".
> >
> > Any ideas...
> >
> > Thanks
> >
> > Luis Fernando Barrera
> > luba@assist.com.gt
> >


From owner-fwtk-users@ex.tis.com Mon Feb 12 13:41 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA19000
	Mon, 12 Feb 2001 13:41:35 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA23213;
	Mon, 12 Feb 2001 10:44:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 12 Feb 2001 10:37:34 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA20817
	for fwtk-users-outgoing; Mon, 12 Feb 2001 10:37:33 -0800 (PST)
From: ark@eltex.ru
Date: Mon, 12 Feb 2001 21:52:24 +0300
Message-Id: <200102121852.VAA28557@paranoid.alpha.int>
In-Reply-To: <20010212125253.B28047@washington.cospo.osis.gov> from "Joseph S D Yao <jsdy@cospo.osis.gov>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: SMAP/SMAPD virus scan question
To: jsdy@cospo.osis.gov
Cc: rreiner@fscinternet.com, fwtk-users@lists.nai.com, twilliams@tfcci.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1621

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

It is, if you are not going to run virus scanner on firewall itself (and you
are probably not, because it is big untrusted binary)

What we really do need is client-server protocol, like CVP but open one.

Joseph S D Yao <jsdy@cospo.osis.gov> said :

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> On Sat, Feb 10, 2001 at 04:28:44PM -0500, rreiner@fscinternet.com wrote:
> > > Is anybody successfully using smap/smapd with virus scanning? 
> > 
> > Yes, but only on Gauntlet, not TIS FWTK :-).
> > 
> > (On Gauntlet, the NAI/McAfee engine is built in -- just turn it on, no 
> > additional components required, works great).
> 
> No, several people have successfully inserted virus scanners betwen
> 'smap' and 'smapd' in FWTK.  This is not a great feat of engineering.


                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOogw56H/mIJW9LeBAQFBRwP/WqPfAdOsbDn31rOIrZVMid4zbykL9b2R
ZBLJRnUU/sZNFKVIIecaWHy3muZpgDiu4KSgb/Kn9lWJ0mq3Fadg0aDV8v3oBy1E
kcKAqlajOKvI9MsKGNzomCLA3kiaaYmxGPm6wMBgrN1TvUrGMnwl+QyAzr2OviWu
PFRvq+FXmrA=
=upbe
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Mon Feb 12 16:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA19435
	Mon, 12 Feb 2001 16:12:42 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA23986;
	Mon, 12 Feb 2001 13:15:19 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 12 Feb 2001 12:39:17 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA10275
	for fwtk-users-outgoing; Mon, 12 Feb 2001 12:39:16 -0800 (PST)
X-Authentication-Warning: devel.brosco.com: mail set sender to <jwelch@brosco.com> using -f
From: "John Welch" <jwelch@brosco.com>
To: "Todd Williams" <twilliams@tfcci.com>, <fwtk-users@lists.nai.com>
Subject: RE: SMAP/SMAPD virus scan question
Date: Mon, 12 Feb 2001 12:43:40 -0500
Message-ID: <NDBBJIMDKEMHHLFCGKGEEEPMCDAA.jwelch@brosco.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
In-Reply-To: <017801c093a3$d09b12b0$c802a8c0@toddntbox.tfcc.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2027

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Todd,
   I recently set up virus scanning on my TIS firewall using AMaViS and
NAI/McAfee's uvscan.  My firewall server has RedHat 6.2 for the OS.  Not
being an expert C programmer I did not want to get into hacking the
smap/smapd code.  Figuring that smap/smapd eventually passes the message on
to sendmail (at least in my environment) I simply followed the installation
instructions for using AMaViS with sendmail.  I was missing a couple of the
required pieces of software, but I just followed the links on the
installation instructions page to get them.  I didn't have any problems
installing any of the required software or the AMaViS program itself.  I'm
not sure if this is the ideal setup, but I do know that it has already
caught several incoming viruses so it is better than what I had before,
which was nothing.

John Welch
Systems Analyst
Brockway-Smith Co.

-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of Todd Williams
Sent: Saturday, February 10, 2001 3:56 PM
To: fwtk-users@lists.nai.com
Subject: SMAP/SMAPD virus scan question


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

Forgive me for this is slightly off topic, but...

Is anybody successfully using smap/smapd with virus scanning?  I looked into
AMaViS a while ago, and it looks okay.  I had some difficulties in getting
it to work with smap/smapd correctly, and gave up after several hours of
working on it and reconfiguring it to try to get it to work properly.  My
virus scanner of choice is NAI/McAfee's uvscan.  Is there anybody out there
running AMaViS that might be willing to share some configuration tips, or
are there any other good suggestions for a virus scanner that will integrate
into the TIS FWTK smap/smapd compiled on Redhat 5.x/6.x?

Thanks in advance,

Todd



From owner-fwtk-users@ex.tis.com Mon Feb 12 16:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA19451
	Mon, 12 Feb 2001 16:15:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA25110;
	Mon, 12 Feb 2001 13:17:58 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 12 Feb 2001 12:42:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA11179
	for fwtk-users-outgoing; Mon, 12 Feb 2001 12:41:58 -0800 (PST)
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Message-Id: <200102121809.KAA31959@noid.net>
X-Mini-Diatribe: To fix America:
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Date: Mon, 12 Feb 2001 10:09:25 -0800
From: Tor Perkins <981998129@noid.net>
To: fwtk-users@lists.nai.com
Subject: Re: PORT ftp problem
Mail-Followup-To: fwtk-users@lists.nai.com
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com> <5.0.2.1.0.20010208213812.0499f310@mail.itm-inst.com> <3A83C150.89A9F330@promos-consult.de>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <3A83C150.89A9F330@promos-consult.de>; from Andreas.Priebe@promos-consult.de on Fri, Feb 09, 2001 at 11:07:12AM +0100
X-Operating-System: Linux 2.2.17pre19
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1491

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


 > BTW: The fix in http://www.fwtk.org/fwtk/patches/patches.html#2.9 does
 > not work for me, because It collieds with patch 2.11 which I have
 > applied.

The 2.9 patch comes with the 2.11 patch; If you've applied 2.11 then
you are covered, you can use:

   ftp-gw: data-port 20

Here's three qoutes from http://www.interhack.net/pubs/fwfaq/:

   The traditional behaviour of FTP servers in active mode is to
   establish the data session FROM port 20, and to the dynamic port on
   the client. FTP servers are steering away from this behaviour
   somewhat due to the need to run as ``root'' on unix systems in
   order to be able to allocate ports below 1024.

and...

   In some cases, if FTP downloads are all you wish to support, you
   might want to consider declaring FTP a ``dead protocol'' and
   letting you users download files via the Web instead.  The user
   interface certainly is nicer, and it gets around the ugly callback
   port problem.

and...

   Checking the source port on incoming FTP data connections is a weak
   security method. It also breaks access to some FTP sites. It makes use
   of the service more difficult for users without preventing bad guys
   from scanning your systems.

-- 
}    __o
}  _(\<._  Tor Perkins           Send me e-mail with subject "get
} (_)/ (_) 981998128@noidDoTnet  pgp key" for automatic response.



From owner-fwtk-users@ex.tis.com Mon Feb 12 18:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA19801
	Mon, 12 Feb 2001 18:32:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA08979;
	Mon, 12 Feb 2001 15:35:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 12 Feb 2001 15:26:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA07009
	for fwtk-users-outgoing; Mon, 12 Feb 2001 15:26:41 -0800 (PST)
From: rreiner@fscinternet.com
X-OpenMail-Hops: 1
Date: Mon, 12 Feb 2001 18:25:58 -0500
Message-Id: <H000006a0028f7ab.0982020358.river.fscinternet.com@MHS>
Subject: RE: Re: SMAP/SMAPD virus scan question
MIME-Version: 1.0
TO: jsdy@cospo.osis.gov
CC: fwtk-users@lists.nai.com
Content-Disposition: inline
	;Creation-Date="Mon, 12 Feb 2001 18:25:58 -0500"
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
	;Creation-Date="Mon, 12 Feb 2001 18:25:58 -0500"
Content-Length: 797

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> > > Is anybody successfully using smap/smapd with virus scanning? 
> > 
> > Yes, but only on Gauntlet, not TIS FWTK :-).
> > 
> > (On Gauntlet, the NAI/McAfee engine is built in -- just 
> > turn it on, no 
> > additional components required, works great).
> 
> No, several people have successfully inserted virus scanners betwen
> 'smap' and 'smapd' in FWTK.  This is not a great feat of engineering.

Agreed.  The hooks for doniog this are a published part of the way the 
FWTK operates.

The original poster's question, however, was "Is anybody successfully 
using smap/smapd with virus scanning?", not "Is it possible to use 
smap/smapd with virus scanning?".



From owner-fwtk-users@ex.tis.com Tue Feb 13 06:06 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA21689
	Tue, 13 Feb 2001 06:06:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA17088;
	Tue, 13 Feb 2001 03:08:45 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 02:58:24 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA16331
	for fwtk-users-outgoing; Tue, 13 Feb 2001 02:58:22 -0800 (PST)
Message-ID: <003501c095ac$d6c174d0$9f58718c@speedpc154>
From: "luke" <gis89524@cis.nctu.edu.tw>
To: <fwtk-users@lists.nai.com>
Subject: TIS performance
Date: Tue, 13 Feb 2001 19:05:13 +0800
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
X-Virus-Scanned: by AMaViS perl-10
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="big5"
Content-Length: 568

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi, everybody:
        Recently, I use TIS as http,ftp,telnet proxy.
        I integrated TIS with ipchains,  squid, FreeS/WAN packages in Red
Hat Linux.
        But it seem to become the system performance bottleneck.
        May I ask  whether  there is a good replacement for TIS in
performance and capability ?
        It seems that zorp( http://www.balabit.hu/en/products/Zorp/ ) is a
good choice.  Someone have tried it ?

Thanks.



From owner-fwtk-users@ex.tis.com Tue Feb 13 09:07 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA22416
	Tue, 13 Feb 2001 09:07:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA25727;
	Tue, 13 Feb 2001 06:10:18 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 06:02:32 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA24736
	for fwtk-users-outgoing; Tue, 13 Feb 2001 06:02:12 -0800 (PST)
Message-ID: <3A893DE9.E5241D13@jamedia.com>
Date: Tue, 13 Feb 2001 09:00:09 -0500
From: Scott McEachern <smceachern@jamedia.com>
Reply-To: smceachern@jamedia.com
X-Mailer: Mozilla 4.75 [en] (X11; U; OpenBSD 2.8 i386)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: ftp-gw
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 977

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


    I'm curious to know if the ftp-gw uses anything ``non-standard''
to create directories?
    My problem is that I have a client that is using WFTPD 2.30 (by
Texas Imperial Software) and when an automated process I have tries to
create a directory on their end, I get a 500 error.  I have the script
output to a text file, and it simply reads:

mkdir 010213              #(today's date, for today's delivery)
500 command not understood

    and I'm trying to figure out what's going on.  As a result of
this, I manually ftp to their site once a month and create the daily
directories by hand, and I'd really like to not do that! ;-)
    Any thoughts/experience in this matter?  TIA!


--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.
300 John St., Suite 500, Thornhill, ON, CA  L3T 5W4
tel:905-881-6902  fax:905-881-6945




From owner-fwtk-users@ex.tis.com Tue Feb 13 10:03 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA22639
	Tue, 13 Feb 2001 10:03:30 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA02097;
	Tue, 13 Feb 2001 07:05:36 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 06:55:37 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA00210
	for fwtk-users-outgoing; Tue, 13 Feb 2001 06:55:36 -0800 (PST)
Message-ID: <3A894A9D.FB61D68D@jamedia.com>
Date: Tue, 13 Feb 2001 09:54:21 -0500
From: Scott McEachern <smceachern@jamedia.com>
Reply-To: smceachern@jamedia.com
X-Mailer: Mozilla 4.75 [en] (X11; U; OpenBSD 2.8 i386)
X-Accept-Language: en
MIME-Version: 1.0
To: Robin Swale <RLSwale@scs.dera.gov.uk>
CC: fwtk-users@lists.nai.com
Subject: Re: ftp-gw
References: <D9B1937D4099D411B0670090277C004F03D15A@ntexch02s.scs.dra.hmg.gb>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1881

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Robin Swale wrote:

> I have just had an issue where I have updated my wu-ftpd server
> which
> lives outside my FWTK firewall and now I cannot create a new
> directory
> in the anonymous area although I have set up ftpaccess  with an
> appropriate "upload ........ dirs" directive. It turns out that my
> NT
> command line ftp client sends an "XMKD" directive to the server but
> ftp-gw only likes an "MKD" directive. XMKD seems to be an extended
> MKD
> and is mentioned in one of the FTP RFC's. Other FTP clients work
> okay.
> I assume that ftp-gw needs a patch to handle XMKD.
> I'd be pleased to hear an explanation of MKD and XMKD and why they
> are
> not both handled - they both seem to have been around for a long
> time!
>
> Robin Swale

    I'm using the ftp-gw with the plug-to patch applied, and I'm
trying to plug an NT box to another NT machine (running the WFTPD.)
Perhaps my NT ftp is also using XMKD.  I'm really just trying to nail
down what's not playing nice, and if it were NT I wouldn't be
shocked.  I logged into the WFTPD box and I could do a MKD but not
XMKD, so this is leading me to believe that NT is the bad guy.
    Also, I did a lookup in the RFC's for details on this.  The
regular mkd stuff comes from RFC 959 (1985) and the ``experimental''
commands are in RFC 1123 (Oct. 89.)  The gotcha however is that 1123
only states that FTP servers ``should'' implement the experimental
stuff, not _must_.
    I have also contacted Texas Imperial Software to confirm that
their 2.30 client does not accept the X stuff.  To be honest I'd be
surprised if they reply.

--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.
300 John St., Suite 500, Thornhill, ON, CA  L3T 5W4
tel:905-881-6902  fax:905-881-6945




From owner-fwtk-users@ex.tis.com Tue Feb 13 12:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA23353
	Tue, 13 Feb 2001 12:40:26 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA19611;
	Tue, 13 Feb 2001 09:43:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 09:36:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA18615
	for fwtk-users-outgoing; Tue, 13 Feb 2001 09:36:39 -0800 (PST)
Message-ID: <3A895A72.5C4995A4@doc.ic.ac.uk>
Date: Tue, 13 Feb 2001 16:01:54 +0000
From: Sherif Yusuf <sy99@doc.ic.ac.uk>
X-Mailer: Mozilla 4.06 [en] (WinNT; I)
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Help!!!
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 929

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear All,

I am a PhD student at Imperial College and I am trying to use the
Firewall Toolkit for my research, but I seem to be having some problems.

I copied Makefile.config.linux to Makefile.config and after typing
'make' I got an error to do with x-gw, so I commented it out in the
Makefile.
Now when I type 'make' I get an error saying:

Entering directory `/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'
cc -I.. -g -DLINUX   -c -o db.o db.c
db.c:16: ndbm.h: No such file or directory
make[1]: *** [db.o] Error 1
make[1]: Leaving directory
`/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'

I know that the file ndbm.h does exist cos' when I use the 'locate'
command it finds it, so I don't know what I am doing wrong.
Can you help, please.

Thank you
Sherif Yusuf
sy99@doc.ic.ac.uk





From owner-fwtk-users@ex.tis.com Tue Feb 13 13:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA23576
	Tue, 13 Feb 2001 13:43:37 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA25470;
	Tue, 13 Feb 2001 10:46:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 10:37:15 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA24436
	for fwtk-users-outgoing; Tue, 13 Feb 2001 10:37:14 -0800 (PST)
Date: Tue, 13 Feb 2001 17:30:17 -0100 (GMT+1)
From: Morelli Enrico <morelli@CERM.UNIFI.IT>
To: Sherif Yusuf <sy99@doc.ic.ac.uk>
cc: <fwtk-users@tis.com>
Subject: Re: Help!!!
In-Reply-To: <3A895A72.5C4995A4@doc.ic.ac.uk>
Message-ID: <Pine.LNX.4.30.0102131728220.23372-100000@alpha.cerm.unifi.it>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1602

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, 13 Feb 2001, Sherif Yusuf wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > Dear All,
 >
 > I am a PhD student at Imperial College and I am trying to use the
 > Firewall Toolkit for my research, but I seem to be having some problems.
 >
 > I copied Makefile.config.linux to Makefile.config and after typing
 > 'make' I got an error to do with x-gw, so I commented it out in the
 > Makefile.
 > Now when I type 'make' I get an error saying:
 >
 > Entering directory `/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'
 > cc -I.. -g -DLINUX   -c -o db.o db.c
 > db.c:16: ndbm.h: No such file or directory
 > make[1]: *** [db.o] Error 1
 > make[1]: Leaving directory
 > `/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'

Try to change in db.c the following row:
#include <nbdm.h>  to #include <gdbm/ndbm.h>


-- 
                            \\\ //
                            (0 0)
------------------------ooO-(_)-Ooo-------------------------------
#============================#=====================================#
|     ENRICO MORELLI         |  email: morelli@CERM.UNIFI.IT       |
| *     *       *       *    |  phone: +39 055 4574269             |
|  University of Florence    |  fax  : +39 055 4574253             |
|  CERM - via Sacconi, 6 -  50019 Sesto Fiorentino (FI) - ITALY    |
#============================#=====================================#




From owner-fwtk-users@ex.tis.com Tue Feb 13 14:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA23629
	Tue, 13 Feb 2001 14:05:49 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA27655;
	Tue, 13 Feb 2001 11:08:35 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 11:02:30 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA26781
	for fwtk-users-outgoing; Tue, 13 Feb 2001 11:01:53 -0800 (PST)
Message-ID: <3A897444.A4535EBF@promos-consult.de>
Date: Tue, 13 Feb 2001 18:52:04 +0100
From: Andreas Priebe <Andreas.Priebe@promos-consult.de>
X-Mailer: Mozilla 4.7 [de]C-CCK-MCD QXW0322h  (WinNT; I)
X-Accept-Language: de,en
MIME-Version: 1.0
To: Tor Perkins <981998129@noid.net>
CC: fwtk-users@lists.nai.com
Subject: Re: PORT ftp problem
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com> <5.0.2.1.0.20010208213812.0499f310@mail.itm-inst.com> <3A83C150.89A9F330@promos-consult.de> <200102121809.KAA31959@noid.net>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 724

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Tor Perkins wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 >  > BTW: The fix in http://www.fwtk.org/fwtk/patches/patches.html#2.9 does
 >  > not work for me, because It collieds with patch 2.11 which I have
 >  > applied.
 > 
 > The 2.9 patch comes with the 2.11 patch; If you've applied 2.11 then
 > you are covered, you can use:
 > 
 >    ftp-gw: data-port 20
 > 
Indeed? I thougth the 2.9 thing is the source port for "normal" ftp, in
2.11 data-port ist the port given for passive ftp?!?


From owner-fwtk-users@ex.tis.com Tue Feb 13 20:51 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA25373
	Tue, 13 Feb 2001 20:51:24 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA22450;
	Tue, 13 Feb 2001 17:54:01 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 17:47:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA21287
	for fwtk-users-outgoing; Tue, 13 Feb 2001 17:46:59 -0800 (PST)
Date: Tue, 13 Feb 2001 20:46:37 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Luis Fernando Barrera <luba@assist.com.gt>
cc: fwtk-users@lists.nai.com
Subject: RE: smap issue
In-Reply-To: <NABBIDJPNCAGKGOFGHBFKEAEPAAA.luba@assist.com.gt>
Message-ID: <Pine.GSO.4.10.10102132045320.22477-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2267

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Louis,

Do you have the postmaster alias defined in your aliase table?  I'm
wondering if the unknown user return is actually occuring - but your local
sendmail doesn't know what to do with it?

ted keller


On Mon, 12 Feb 2001, Luis Fernando Barrera wrote:

> Yes, the service is running... In fact I can send/receive email without
> any problem...
> The problem is when I send an email to a non-existent user in other domain
> (like nobody@bfg.com); I should (I guess) receive a notificaction about the
> non-existent user.
> 
> I also noticed that smap (maybe it is sendmail) creates a file called
> "dead.letter" in the /var/tmp directory. Into that
> file there are all the messages I should receive about the non-existent user
> or domain.
> 
> I'm thinking it is a problem of the mail server, but I don't have a clue,
> since the normally all
> the emaill messages pass through ok.
> 
> Luis
> 
> 
> 
> > -----Original Message-----
> > From: Ted Keller [mailto:keller@bfg.com]
> > Sent: Friday, February 09, 2001 4:47 PM
> > To: Luis Fernando Barrera
> > Cc: fwtk-users@lists.nai.com
> > Subject: Re: smap issue
> >
> >
> > Luis,
> >
> > Try telneting to you mail server on port 25 and see if it responds.  YOu
> > may not have the service running?
> >
> > tek
> >
> >
> > On Fri, 9 Feb 2001, Luis Fernando Barrera wrote:
> >
> > > [To be removed from this list send the message "unsubscribe
> > fwtk-users" in the
> > > BODY of a mail message to majordomo@ex.tis.com.]
> > >
> > > Hi all,
> > >
> > > I'm having the following problem:
> > >
> > >
> > > When someone behind the firewall sends an email message to a
> > non-existent
> > > user,
> > > like anybody@yahoo.com or to a non-existen domaind, let's say
> > > test@nodomain.com;
> > > he or she doesn't receive any notification about the problem.
> > >
> > > I saw in the logfile that when smapd, tries to connect back to the mail
> > > server, to inform
> > > the user about the non-existen user/domain, the mail server
> > answer "service
> > > unavailable".
> > >
> > > Any ideas...
> > >
> > > Thanks
> > >
> > > Luis Fernando Barrera
> > > luba@assist.com.gt
> > >
> 


From owner-fwtk-users@ex.tis.com Tue Feb 13 20:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA25388
	Tue, 13 Feb 2001 20:54:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA23315;
	Tue, 13 Feb 2001 17:57:19 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 17:51:22 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA21841
	for fwtk-users-outgoing; Tue, 13 Feb 2001 17:51:19 -0800 (PST)
Date: Tue, 13 Feb 2001 20:50:52 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: ark@eltex.ru
cc: jsdy@cospo.osis.gov, rreiner@fscinternet.com, fwtk-users@lists.nai.com,
        twilliams@tfcci.com
Subject: Re: SMAP/SMAPD virus scan question
In-Reply-To: <200102121852.VAA28557@paranoid.alpha.int>
Message-ID: <Pine.GSO.4.10.10102132049550.22477-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2101

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I agree.  Virus scanners should be run behind the firewall on some
mail-hub machine - prior to delivery to your internal e-mail system.  The
firewall must be kept simple - or security issues will creep in.

ted keller


On Mon, 12 Feb 2001 ark@eltex.ru wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> 
> nuqneH,
> 
> It is, if you are not going to run virus scanner on firewall itself (and you
> are probably not, because it is big untrusted binary)
> 
> What we really do need is client-server protocol, like CVP but open one.
> 
> Joseph S D Yao <jsdy@cospo.osis.gov> said :
> 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > On Sat, Feb 10, 2001 at 04:28:44PM -0500, rreiner@fscinternet.com wrote:
> > > > Is anybody successfully using smap/smapd with virus scanning? 
> > > 
> > > Yes, but only on Gauntlet, not TIS FWTK :-).
> > > 
> > > (On Gauntlet, the NAI/McAfee engine is built in -- just turn it on, no 
> > > additional components required, works great).
> > 
> > No, several people have successfully inserted virus scanners betwen
> > 'smap' and 'smapd' in FWTK.  This is not a great feat of engineering.
> 
> 
>                                      _     _  _  _  _      _  _
>  {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
>  (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
>  [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!
> 
> -----BEGIN PGP SIGNATURE-----
> Version: PGP 6.5.1i
> 
> iQCVAwUBOogw56H/mIJW9LeBAQFBRwP/WqPfAdOsbDn31rOIrZVMid4zbykL9b2R
> ZBLJRnUU/sZNFKVIIecaWHy3muZpgDiu4KSgb/Kn9lWJ0mq3Fadg0aDV8v3oBy1E
> kcKAqlajOKvI9MsKGNzomCLA3kiaaYmxGPm6wMBgrN1TvUrGMnwl+QyAzr2OviWu
> PFRvq+FXmrA=
> =upbe
> -----END PGP SIGNATURE-----
> 


From owner-fwtk-users@ex.tis.com Tue Feb 13 21:56 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA25598
	Tue, 13 Feb 2001 21:56:50 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA26291;
	Tue, 13 Feb 2001 18:59:39 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Feb 2001 18:53:35 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA25577
	for fwtk-users-outgoing; Tue, 13 Feb 2001 18:53:34 -0800 (PST)
Date: Tue, 13 Feb 2001 21:53:10 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Scott McEachern <smceachern@jamedia.com>
cc: fwtk-users@lists.nai.com
Subject: Re: ftp-gw
In-Reply-To: <3A893DE9.E5241D13@jamedia.com>
Message-ID: <Pine.GSO.4.10.10102132152190.24290-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1669

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Scott,

I had to add the following command to make windows clients work.... maybe
this will fix your also.

ted keller


*** ftp-gw.c.dist	Mon Oct 25 20:43:51 1999
--- ftp-gw.c	Mon Oct 25 20:43:16 1999
***************
*** 137,142 ****
--- 137,143 ----
  	"rest",		OP_CONN,			0,
  	"rmd",		OP_CONN|OP_XTND,		0,
  	"mkd",		OP_CONN|OP_XTND,		0,
+ 	"xmkd",		OP_CONN|OP_XTND,		0,
  	"syst",		OP_CONN,			0,
  	"acct",		OP_CONN,			0,
  	"quit",		OP_AOK,				cmd_quit,

On Tue, 13 Feb 2001, Scott McEachern wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
>     I'm curious to know if the ftp-gw uses anything ``non-standard''
> to create directories?
>     My problem is that I have a client that is using WFTPD 2.30 (by
> Texas Imperial Software) and when an automated process I have tries to
> create a directory on their end, I get a 500 error.  I have the script
> output to a text file, and it simply reads:
> 
> mkdir 010213              #(today's date, for today's delivery)
> 500 command not understood
> 
>     and I'm trying to figure out what's going on.  As a result of
> this, I manually ftp to their site once a month and create the daily
> directories by hand, and I'd really like to not do that! ;-)
>     Any thoughts/experience in this matter?  TIA!
> 
> 
> --
> R. Scott McEachern, Network Administrator
> J&A Media Services, Inc.
> 300 John St., Suite 500, Thornhill, ON, CA  L3T 5W4
> tel:905-881-6902  fax:905-881-6945
> 
> 
> 


From owner-fwtk-users@ex.tis.com Wed Feb 14 08:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA27430
	Wed, 14 Feb 2001 08:04:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA24429;
	Wed, 14 Feb 2001 05:07:06 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 04:59:29 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA23466
	for fwtk-users-outgoing; Wed, 14 Feb 2001 04:59:27 -0800 (PST)
Message-Id: <5.0.2.1.0.20010213201224.01d44020@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 13 Feb 2001 20:15:11 -0500
To: smceachern@jamedia.com, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw
In-Reply-To: <3A893DE9.E5241D13@jamedia.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 916

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:00 AM 2/13/01 -0500, Scott McEachern wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >
 >     I'm curious to know if the ftp-gw uses anything ``non-standard''
 >to create directories?

No, it just passes the client command to the server.

 >     My problem is that I have a client that is using WFTPD 2.30 (by
 >Texas Imperial Software) and when an automated process I have tries to
 >create a directory on their end, I get a 500 error.  I have the script
 >output to a text file, and it simply reads:

If the client is using XMKD, you can add it to the command table in ftp-gw.
Just duplicate the
          "mkd", OP_CONN|OP_XTND, 0,
line and change "mxd" to "xmkd".
          -Rick



From owner-fwtk-users@ex.tis.com Wed Feb 14 10:13 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA27900
	Wed, 14 Feb 2001 10:13:24 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA04281;
	Wed, 14 Feb 2001 07:16:10 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 07:13:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA03566
	for fwtk-users-outgoing; Wed, 14 Feb 2001 07:13:44 -0800 (PST)
From: Douglas Bowerman <doug_b@kinexis.net>
Date: Wed, 14 Feb 2001 15:13:34 GMT
Message-ID: <20010214.15133414@102.kinexisdms.com>
Subject: Blocking ports
To: fwtk-users@ex.tis.com
X-Mailer: Mozilla/3.0 (compatible; StarOffice/5.2; Win32)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id HAA03555
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 723

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all,
After seeing the Frontline Hackers on PBS last night I did some checking.
The Sygate Tech Quickscan said something about ideally having Blocked 
ports not just closed.  

This may be of a Linux nature, but I'm new to this stuff.

I built the firewall and compiled the software two years ago.  It has 
been running since then and I have not really touched it.

This may have been covered in previous posts, which I have scoured all 
information without finding "HOW".

How do I block ports, and make our firewall secure?

We would need SMTP, POP, HTTP, HTTPS or course.

Thanks,
Doug

From owner-fwtk-users@ex.tis.com Wed Feb 14 10:26 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA27935
	Wed, 14 Feb 2001 10:26:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA06463;
	Wed, 14 Feb 2001 07:28:59 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 07:27:02 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA05748
	for fwtk-users-outgoing; Wed, 14 Feb 2001 07:27:00 -0800 (PST)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <3A8AB1BC.D845C619@radio.hundert6.de>
Date: Wed, 14 Feb 2001 16:26:36 +0000
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.2-STABLE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: Douglas Bowerman <doug_b@kinexis.net>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: Blocking ports
References: <20010214.15133414@102.kinexisdms.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1709

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> The Sygate Tech Quickscan said something about ideally having Blocked
> ports not just closed.

Very interesting expression. Basically, a TCP port can either be
open or closed, I'd say. I think what this tech might have wanted
to say was it's better to send back a RST flagged packet instead
of just sinking unwanted traffic in the network stack's nirvana.
This has nothing to do with how an application layer gateway like
the TIS fwtk works. 

 
> This may be of a Linux nature, but I'm new to this stuff.

It's not. It has to do with IP rather than with Linux or Unix or
whatever OS. 
 
> I built the firewall and compiled the software two years ago.  It has
> been running since then and I have not really touched it.

Ooops. I hope you did at least install the vendor's security
fixes for your OS.

> How do I block ports, and make our firewall secure?

You don't have to do that. Application level gateways like the
fwtk function with the use of proxies, which appear as open
services to the outside, but do a critical inspection of what
traffic they receive. Only if this is compliant with the protocol
of the relevant application, traffic is further processed. So, as
you see, for an application proxy it's fairly normal to have
'its' port open. 

It is, however, a good idea to use a packet filter
_additionally_, depending upon your needs and resources. 
 
> We would need SMTP, POP, HTTP, HTTPS or course.

Well, smap, plug-gw and http-gw should be able to work finely for
you. 

Cheers, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Wed Feb 14 11:21 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA28200
	Wed, 14 Feb 2001 11:21:09 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA14748;
	Wed, 14 Feb 2001 08:23:57 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 08:20:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA13813
	for fwtk-users-outgoing; Wed, 14 Feb 2001 08:20:43 -0800 (PST)
Date: Wed, 14 Feb 2001 17:33:33 +0200
From: Berend De Schouwer <bds@jhb.ucs.co.za>
To: Douglas Bowerman <doug_b@kinexis.net>
Cc: fwtk-users@ex.tis.com
Subject: Re: Blocking ports
Message-ID: <20010214173333.C9475@bds.ucs.co.za>
Reply-To: bds@jhb.ucs.co.za
References: <20010214.15133414@102.kinexisdms.com>
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
In-Reply-To: <20010214.15133414@102.kinexisdms.com>; from doug_b@kinexis.net on Wed, Feb 14, 2001 at 17:13:34 +0200
X-Mailer: Balsa 1.1.1
Lines: 47
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 1617

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, 14 Feb 2001 17:13:34 Douglas Bowerman wrote:
| [To be removed from this list send the message "unsubscribe fwtk-users"
| in the
| BODY of a mail message to majordomo@ex.tis.com.]
| 
| Hello all,
| After seeing the Frontline Hackers on PBS last night I did some checking.
| The Sygate Tech Quickscan said something about ideally having Blocked 
| ports not just closed.  
|
| This may be of a Linux nature, but I'm new to this stuff.
| 
| I built the firewall and compiled the software two years ago.  It has 
| been running since then and I have not really touched it.

Blocking ports (IP filtering) and running an application proxy/firewall
(TIS FWTK) are complimentary.  One enhances the other.

| This may have been covered in previous posts, which I have scoured all 
| information without finding "HOW".

Search for IP filtering.
  
| How do I block ports, and make our firewall secure?

Since Linux is the only OS you mention:
Linux 2.0.x uses ipfwadm
Linux 2.2.x uses ipchains (there is a ipfwadm2ipchains script)
Linux 2.4.x uses iptables

Search for man pages or howtos on these commands.

Off-topic: when did ip-based filtering get into the kernel?
I seem to recall (some) support in 1.2.x; but I haven't recompiled
a 1.2.x kernel in 6 months.
  
| We would need SMTP, POP, HTTP, HTTPS or course.
| 
| Thanks,
| Doug
| 
Kind regards,				  
Berend                                  

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Berend De Schouwer, +27-11-712-1435, UCS



From owner-fwtk-users@ex.tis.com Wed Feb 14 14:15 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA28946
	Wed, 14 Feb 2001 14:15:56 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA09896;
	Wed, 14 Feb 2001 11:18:41 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 11:12:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA07945
	for fwtk-users-outgoing; Wed, 14 Feb 2001 11:12:04 -0800 (PST)
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Message-Id: <200102141718.JAA08631@noid.net>
X-Mini-Diatribe: To fix America:
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Date: Wed, 14 Feb 2001 09:18:13 -0800
From: Tor Perkins <982166821@noid.net>
To: fwtk-users@lists.nai.com
Subject: Re: PORT ftp problem
Mail-Followup-To: fwtk-users@lists.nai.com
References: <5.0.2.1.0.20010206173527.0460d4d0@mail.itm-inst.com> <5.0.2.1.0.20010208213812.0499f310@mail.itm-inst.com> <3A83C150.89A9F330@promos-consult.de> <200102121809.KAA31959@noid.net> <3A897444.A4535EBF@promos-consult.de>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <3A897444.A4535EBF@promos-consult.de>; from Andreas.Priebe@promos-consult.de on Tue, Feb 13, 2001 at 06:52:04PM +0100
X-Operating-System: Linux 2.2.17pre19
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1215

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

 > Indeed? I thought the 2.9 thing is the source port for "normal" ftp,
 > in 2.11 data-port is the port given for passive ftp?!?
  
When I wrote the 2.11 patch, it so happened that I had the 2.9 patch
already applied to my ftp-gw.c.  I liked the way it worked when the
client did a PORT to ftp-gw.  I copied this behavior for when the
ftp-gw does a PASV to a server.  In both cases ftp-gw is initiating
the data connection.  'data-port' (the config option) and 'data_port'
(the C variable) are both being used in these cases.
  
If you do not use the 'pasv true' config option, ftp-gw will still use
'data-port' as per the 2.9 patch when interacting with the client,
it'll just not do PASV when it's talking to a server.  It'll PORT the
server using a random high port.  The server will then initiate the
data connection (the port it picks as it's source port is out of our
control).
   
By the way, PASV is just as "normal" as PORT.  :)

--
}    __o
}  _(\<._  Tor Perkins           Send me e-mail with subject "get
} (_)/ (_) 982166820@noidDoTnet  pgp key" for automatic response.



From owner-fwtk-users@ex.tis.com Wed Feb 14 14:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA28949
	Wed, 14 Feb 2001 14:15:57 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA09892;
	Wed, 14 Feb 2001 11:18:41 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 11:11:18 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA07773
	for fwtk-users-outgoing; Wed, 14 Feb 2001 11:11:17 -0800 (PST)
Message-ID: <3A8ABB16.A5EBDBC3@doc.ic.ac.uk>
Date: Wed, 14 Feb 2001 17:06:30 +0000
From: Sherif Yusuf <sy99@doc.ic.ac.uk>
X-Mailer: Mozilla 4.06 [en] (WinNT; I)
MIME-Version: 1.0
To: fwtk-support@tislabs.com, fwtk-users@tis.com
Subject: More Problems
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2957

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear All,

It's me again, Sherif Yusuf.  I managed to solve, with your help, the
problem of ndbm.h not existing.
Now I am faced with another problem which is:

make[1]: Entering directory
`/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'
cc -g -static -o authsrv authsrv.o proto.o db.o pass.o srvio.o
../libauth.a ../libfwall.a    -lgdbm
pass.o: In function `passverify':
/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth/pass.c:39: undefined
reference to `crypt'
pass.o: In function `passset':
/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth/pass.c:70: undefined
reference to `crypt'
collect2: ld returned 1 exit status
make[1]: *** [authsrv] Error 1
make[1]: Leaving directory
`/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'

Why is this so?!!!

This is the file that consists the two programs:

  * Copyright (c) 1993, Trusted Information Systems, Incorporated
  * All rights reserved.
  *
  * Redistribution and use are governed by the terms detailed in the
  * license document ("LICENSE") included with the toolkit.
  */

/*
  *      Author: Marcus J. Ranum, Trusted Information Systems, Inc.
  */
static  char    RcsId[] = "$Header:
/usr/home/rick/fwtk2.0/fwtk/auth/RCS/pass.c,v 1.2 1997/01/14 20:20:03
rick Exp $";
#include        <time.h>
#include        "firewall.h"
#include        "auth.h"

#ifdef  AUTHPROTO_PASSWORD

extern  char    *crypt();

passverify(user,pass,ap,rbuf)
char    *user;
char    *pass;
Auth    *ap;
char    *rbuf;
{
         char    lclpass[10];

         if(ap->pw[0] == '\0') {
                 strcpy(rbuf,"ok");
                 return(0);
         }

         if(pass == (char *)0)
                 goto reject;
         strncpy(lclpass, pass, 8);
         lclpass[8] = '\0';

         if(!strcmp(crypt(lclpass,ap->pw),ap->pw)) {
                 strcpy(rbuf,"ok");
                 return(0);
         }
reject:
         strcpy(rbuf,"Permission Denied.");
         return(1);
}


static unsigned char itoa64[] =         /* 0 ... 63 => ascii - 64 */

"./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";

passset(user,pass,ap,rbuf)
char    *user;
char    *pass;
Auth    *ap;
char    *rbuf;
{
         if(pass == (char *)0)
                 ap->pw[0] = '\0';
         else {
                 time_t  t;
                 char    salt[2];

                 time(&t);
                 salt[0] = itoa64[getpid() & 0x3f];
                 salt[1] = itoa64[(int)t & 0x3f];
                 if(strlen(pass) > 7)
                         pass[8] = '\0';
                 strncpy(ap->pw,crypt(pass,salt),AUTH_PWSIZ);
         }
         if(auth_dbputu(user,ap) == 0)
                 sprintf(rbuf,"Password for %s changed.",user);
         else
                 strcpy(rbuf,"Database error.");
         return(0);
}
#endif




Please help

Thanks
Sherif
sy99@doc.ic.ac.uk



From owner-fwtk-users@ex.tis.com Wed Feb 14 21:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA00544
	Wed, 14 Feb 2001 21:40:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA27725;
	Wed, 14 Feb 2001 18:42:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Feb 2001 18:38:28 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA26969
	for fwtk-users-outgoing; Wed, 14 Feb 2001 18:38:27 -0800 (PST)
Message-Id: <5.0.2.1.0.20010214204617.01d4b930@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 14 Feb 2001 20:49:30 -0500
To: Sherif Yusuf <sy99@doc.ic.ac.uk>, fwtk-support@tislabs.com,
        fwtk-users@tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: More Problems
In-Reply-To: <3A8ABB16.A5EBDBC3@doc.ic.ac.uk>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 617

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 05:06 PM 2/14/01 +0000, Sherif Yusuf wrote:
>pass.o: In function `passverify':
>/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth/pass.c:39: undefined
>reference to `crypt'
>
>Why is this so?!!!

Read "Makefile.config" - where it reads:
# Some versions of Linux have broken the crypt() function out into a
# separate library - uncomment the following line if authsrv fails to build.
#AUXLIB= -lcrypt

You'll need to uncomment the AUXLIB line (remove the leading "#").
         -Rick


From owner-fwtk-users@ex.tis.com Thu Feb 15 07:35 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA01895
	Thu, 15 Feb 2001 07:35:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA17711;
	Thu, 15 Feb 2001 04:38:36 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Feb 2001 04:35:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA17106
	for fwtk-users-outgoing; Thu, 15 Feb 2001 04:35:49 -0800 (PST)
From: zhangfan79@263.net
MIME-Version: 1.0
Message-Id: <3A8B732C.07740@mta4.263.net>
Date: Thu, 15 Feb 2001 14:11:56 +0800 (CST)
To: fwtk-users@tis.com
Subject: help!!!
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 856

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

dear all:
     I'm a new to fwtk,my system platform is redhat7.0 ,yestoday I get the soft a
nd complie it ,but when i compile it ,it said error like these below

    make[1]:Entering directory '/root/fwtk/fwtk/http-gw'
    cc -I..-g -DLINUX  -c -o error.o error.c
    error.c:126: parse error before '('
    error.c:133: parse error before string constant
    error.c:134: warning:parameter names (without types) in function declaration
    error.c:135: parse error before string constant
    ....
    when i check these error report, i found that all error occur in 
../http-gw/error.c,but i don't know how to do with it 
    

_____________________________________________
263CommailŁŹĆóŇľľÄľç×ÓÓĘźţ×¨źŇ http://mail.263.net


From owner-fwtk-users@ex.tis.com Thu Feb 15 07:39 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA01921
	Thu, 15 Feb 2001 07:39:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA18524;
	Thu, 15 Feb 2001 04:42:02 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Feb 2001 04:39:49 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA17768
	for fwtk-users-outgoing; Thu, 15 Feb 2001 04:39:48 -0800 (PST)
Message-ID: <8894CA1F87A5D411BD24009027EE783818EAB8@md-exchange1.nai.com>
From: "Churchyard, Peter" <Peter_Churchyard@NAI.com>
To: "'Sherif Yusuf'" <sy99@doc.ic.ac.uk>, fwtk-support@tislabs.com,
        fwtk-users@tis.com
Subject: RE: More Problems
Date: Wed, 14 Feb 2001 14:02:34 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 3607

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

You should replace the crypt call with any hash function of your choice. Do
a man crypt and see what library it is in?

Peter.

 > -----Original Message-----
 > From: Sherif Yusuf [mailto:sy99@doc.ic.ac.uk]
 > Sent: Wednesday, February 14, 2001 12:07 PM
 > To: fwtk-support@tislabs.com; fwtk-users@tis.com
 > Subject: More Problems
 > 
 > 
 > Dear All,
 > 
 > It's me again, Sherif Yusuf.  I managed to solve, with your help, the
 > problem of ndbm.h not existing.
 > Now I am faced with another problem which is:
 > 
 > make[1]: Entering directory
 > `/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'
 > cc -g -static -o authsrv authsrv.o proto.o db.o pass.o srvio.o
 > ../libauth.a ../libfwall.a    -lgdbm
 > pass.o: In function `passverify':
 > /homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth/pass.c:39: 
 > undefined
 > reference to `crypt'
 > pass.o: In function `passset':
 > /homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth/pass.c:70: 
 > undefined
 > reference to `crypt'
 > collect2: ld returned 1 exit status
 > make[1]: *** [authsrv] Error 1
 > make[1]: Leaving directory
 > `/homes/sy99/Research/Ponder/AlomainyProj/fwtk/auth'
 > 
 > Why is this so?!!!
 > 
 > This is the file that consists the two programs:
 > 
 >  * Copyright (c) 1993, Trusted Information Systems, Incorporated
 >  * All rights reserved.
 >  *
 >  * Redistribution and use are governed by the terms detailed in the
 >  * license document ("LICENSE") included with the toolkit.
 >  */
 > 
 > /*
 >  *      Author: Marcus J. Ranum, Trusted Information Systems, Inc.
 >  */
 > static  char    RcsId[] = "$Header:
 > /usr/home/rick/fwtk2.0/fwtk/auth/RCS/pass.c,v 1.2 1997/01/14 20:20:03
 > rick Exp $";
 > #include        <time.h>
 > #include        "firewall.h"
 > #include        "auth.h"
 > 
 > #ifdef  AUTHPROTO_PASSWORD
 > 
 > extern  char    *crypt();
 > 
 > passverify(user,pass,ap,rbuf)
 > char    *user;
 > char    *pass;
 > Auth    *ap;
 > char    *rbuf;
 > {
 >         char    lclpass[10];
 > 
 >         if(ap->pw[0] == '\0') {
 >                 strcpy(rbuf,"ok");
 >                 return(0);
 >         }
 > 
 >         if(pass == (char *)0)
 >                 goto reject;
 >         strncpy(lclpass, pass, 8);
 >         lclpass[8] = '\0';
 > 
 >         if(!strcmp(crypt(lclpass,ap->pw),ap->pw)) {
 >                 strcpy(rbuf,"ok");
 >                 return(0);
 >         }
 > reject:
 >         strcpy(rbuf,"Permission Denied.");
 >         return(1);
 > }
 > 
 > 
 > static unsigned char itoa64[] =         /* 0 ... 63 => ascii - 64 */
 > 
 > "./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
 > 
 > passset(user,pass,ap,rbuf)
 > char    *user;
 > char    *pass;
 > Auth    *ap;
 > char    *rbuf;
 > {
 >         if(pass == (char *)0)
 >                 ap->pw[0] = '\0';
 >         else {
 >                 time_t  t;
 >                 char    salt[2];
 > 
 >                 time(&t);
 >                 salt[0] = itoa64[getpid() & 0x3f];
 >                 salt[1] = itoa64[(int)t & 0x3f];
 >                 if(strlen(pass) > 7)
 >                         pass[8] = '\0';
 >                 strncpy(ap->pw,crypt(pass,salt),AUTH_PWSIZ);
 >         }
 >         if(auth_dbputu(user,ap) == 0)
 >                 sprintf(rbuf,"Password for %s changed.",user);
 >         else
 >                 strcpy(rbuf,"Database error.");
 >         return(0);
 > }
 > #endif
 > 
 > 
 > 
 > 
 > Please help
 > 
 > Thanks
 > Sherif
 > sy99@doc.ic.ac.uk
 > 


From owner-fwtk-users@ex.tis.com Thu Feb 15 13:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA03815
	Thu, 15 Feb 2001 13:40:18 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA17811;
	Thu, 15 Feb 2001 10:43:06 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Feb 2001 10:38:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA17057
	for fwtk-users-outgoing; Thu, 15 Feb 2001 10:38:36 -0800 (PST)
From: Douglas Bowerman <doug_b@kinexis.net>
Date: Thu, 15 Feb 2001 18:23:13 GMT
Message-ID: <20010215.18231371@102.kinexisdms.com>
Subject: Re: help!!!
To: fwtk-users@ex.tis.com
X-Mailer: Mozilla/3.0 (compatible; StarOffice/5.2; Win32)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id KAA17054
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 898

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
In error.c this is at your line -> 

int gostarterror(sockfd, errorno)
int sockfd;
int errorno;
{

Well, you should change the code to ->
int gostarterror(int sockfd, int errorno)
{


All of the occurrences of parameters sent to functions have this problem 
with the C compiler.

>>>>>>>>>>>>>>>>>> Original Message <<<<<<<<<<<<<<<<<<

On 02/15/2001, 1:11:56 AM, zhangfan79@263.net wrote regarding help!!!:


>     make[1]:Entering directory '/root/fwtk/fwtk/http-gw'
>     cc -I..-g -DLINUX  -c -o error.o error.c
>     error.c:126: parse error before '('
>     error.c:133: parse error before string constant
>     error.c:134: warning:parameter names (without types) in function 
declaration
>     error.c:135: parse error before string constant
>     ....



From owner-fwtk-users@ex.tis.com Fri Feb 16 05:22 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA06299
	Fri, 16 Feb 2001 05:22:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA26648;
	Fri, 16 Feb 2001 02:24:53 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Feb 2001 02:20:06 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA26065
	for fwtk-users-outgoing; Fri, 16 Feb 2001 02:20:05 -0800 (PST)
From: zhangfan79@263.net
MIME-Version: 1.0
Message-Id: <3A8CFE75.01778@mta1>
Date: Fri, 16 Feb 2001 18:18:29 +0800 (CST)
To: fwtk-users@tis.com
Subject: How to build fwtk under Redhat 7.0 
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1449

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

dear all:
   I'm a new to fwtk and linux,when I build fwtk under Redhat,
so many errors come to me and i don't know how to do with it,
the error are listed below:

make[1]:Entering directory '/root/fwtk/fwtk/auth'
cc -g -static -o authsrv authsrv.o proto.o db.o pass.o sevio.o   ..libauth.a
pass.o:In function 'passverify':
/root/fwtk/fwtk/auth/pass.c:41 undefined reference to 'crypt'
pass.o:In function 'passset':
/root/fwtk/fwtk/auth/pass.c:72:undefined reference to 'crypt'
collect2:Id returned 1 exit status
make[1]: *** [authsrv] Error 1
....
make[1]:Entering directory '/root/fwtk/fwtk/http-gw'
cc -I .. -g -DLINUX -c -o error.o error.c
error.c:175: parse error before '__builtin_va_alist'
error.c:In function 'go_error':
error.c:179:declaration for parameter '__builtin_va_alist' but no such parameter
error.c:178:declaration for parameter 'msg' but no such parameter
error.c:177:declaration for parameter '__errno_location' but no such parameter
error.c:176:declaration for parameter 'sockfd' but no such parameter
error.c:189:declaration for parameter 'gostarterror' but no such parameter
make[1]: *** [error.o] Error 1
                             thanks a lot

           

_____________________________________________
ÓĐ"Ŕń"×ßąéĚěĎÂ            http://ad2.263.net/cgi-bin/advert/push/redirect.cgi?aid=2452


From owner-fwtk-users@ex.tis.com Fri Feb 16 07:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA06684
	Fri, 16 Feb 2001 07:42:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA02164;
	Fri, 16 Feb 2001 04:45:00 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Feb 2001 04:41:48 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA01032
	for fwtk-users-outgoing; Fri, 16 Feb 2001 04:41:47 -0800 (PST)
Message-Id: <5.0.2.1.0.20010215211647.01d4ee70@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 15 Feb 2001 21:18:44 -0500
To: Douglas Bowerman <doug_b@kinexis.net>, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: help!!!
In-Reply-To: <20010215.18231371@102.kinexisdms.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 744

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 06:23 PM 2/15/01 +0000, Douglas Bowerman wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >Hello,
 >In error.c this is at your line ->
 >
 >int gostarterror(sockfd, errorno)
 >int sockfd;
 >int errorno;
 >{
 >
 >Well, you should change the code to ->
 >int gostarterror(int sockfd, int errorno)
 >{
 >
 >
 >All of the occurrences of parameters sent to functions have this problem
 >with the C compiler.

Your compiler isn't accepting K&R "C"; try compiling with "-traditional" on 
the command line.
          -Rick




From owner-fwtk-users@ex.tis.com Fri Feb 16 07:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA06687
	Fri, 16 Feb 2001 07:42:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA02172;
	Fri, 16 Feb 2001 04:45:02 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Feb 2001 04:42:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA01278
	for fwtk-users-outgoing; Fri, 16 Feb 2001 04:42:47 -0800 (PST)
Date: Fri, 16 Feb 2001 12:38:14 +0200
From: Berend De Schouwer <bds@jhb.ucs.co.za>
To: zhangfan79@263.net
Cc: fwtk-users@tis.com
Subject: Re: How to build fwtk under Redhat 7.0
Message-ID: <20010216123814.E32049@bds.ucs.co.za>
Reply-To: bds@jhb.ucs.co.za
References: <3A8CFE75.01778@mta1>
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
In-Reply-To: <3A8CFE75.01778@mta1>; from zhangfan79@263.net on Fri, Feb 16, 2001 at 12:18:29 +0200
X-Mailer: Balsa 1.1.1
Lines: 54
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 1986

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


On Fri, 16 Feb 2001 12:18:29 zhangfan79@263.net wrote:
| [To be removed from this list send the message "unsubscribe fwtk-users"
| in the
| BODY of a mail message to majordomo@ex.tis.com.]
| 
| dear all:
|    I'm a new to fwtk and linux,when I build fwtk under Redhat,
| so many errors come to me and i don't know how to do with it,
| the error are listed below:
| 
| make[1]:Entering directory '/root/fwtk/fwtk/auth'
| cc -g -static -o authsrv authsrv.o proto.o db.o pass.o sevio.o  
| ..libauth.a
| pass.o:In function 'passverify':
| /root/fwtk/fwtk/auth/pass.c:41 undefined reference to 'crypt'
| pass.o:In function 'passset':
| /root/fwtk/fwtk/auth/pass.c:72:undefined reference to 'crypt'
| collect2:Id returned 1 exit status
| make[1]: *** [authsrv] Error 1
| ....

Read the Makefile.  There are comments about what to do to
make crypt work.

| make[1]:Entering directory '/root/fwtk/fwtk/http-gw'
| cc -I .. -g -DLINUX -c -o error.o error.c
| error.c:175: parse error before '__builtin_va_alist'
| error.c:In function 'go_error':
| error.c:179:declaration for parameter '__builtin_va_alist' but no such
| parameter
| error.c:178:declaration for parameter 'msg' but no such parameter
| error.c:177:declaration for parameter '__errno_location' but no such
| parameter
| error.c:176:declaration for parameter 'sockfd' but no such parameter
| error.c:189:declaration for parameter 'gostarterror' but no such
| parameter
| make[1]: *** [error.o] Error 1

Redhat 7.0?  With the broken C compiler? :)

|                              thanks a lot
| 
|            
| 
| _____________________________________________
| ÓĐ"Ŕń"×ßąéĚěĎÂ            http://ad2.263.net/cgi-bin/advert/push/redirect.cgi?aid=2452
| 
Kind regards,				  
Berend                                  

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Berend De Schouwer, +27-11-712-1435, UCS



From owner-fwtk-users@ex.tis.com Fri Feb 16 10:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA07995
	Fri, 16 Feb 2001 10:40:22 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA17686;
	Fri, 16 Feb 2001 07:43:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Feb 2001 07:40:45 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA16892
	for fwtk-users-outgoing; Fri, 16 Feb 2001 07:40:44 -0800 (PST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@tis.com>
Subject: FW: How to build fwtk under Redhat 7.0
Date: Fri, 16 Feb 2001 09:38:33 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFGEBCPAAA.luba@assist.com.gt>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MIMEOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2475

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Broken compiler on RedHat 7.0? What does it mean?

I'm (was) planning to migrate my FWTK Box w/RedHat 6.2 to
RedHat 7.0...

Luis Fernando Barrera
luba@assist.com.gt


-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of Berend De Schouwer
Sent: Friday, February 16, 2001 4:38 AM
To: zhangfan79@263.net
Cc: fwtk-users@tis.com
Subject: Re: How to build fwtk under Redhat 7.0


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]


On Fri, 16 Feb 2001 12:18:29 zhangfan79@263.net wrote:
| [To be removed from this list send the message "unsubscribe fwtk-users"
| in the
| BODY of a mail message to majordomo@ex.tis.com.]
|
| dear all:
|    I'm a new to fwtk and linux,when I build fwtk under Redhat,
| so many errors come to me and i don't know how to do with it,
| the error are listed below:
|
| make[1]:Entering directory '/root/fwtk/fwtk/auth'
| cc -g -static -o authsrv authsrv.o proto.o db.o pass.o sevio.o
| ..libauth.a
| pass.o:In function 'passverify':
| /root/fwtk/fwtk/auth/pass.c:41 undefined reference to 'crypt'
| pass.o:In function 'passset':
| /root/fwtk/fwtk/auth/pass.c:72:undefined reference to 'crypt'
| collect2:Id returned 1 exit status
| make[1]: *** [authsrv] Error 1
| ....

Read the Makefile.  There are comments about what to do to
make crypt work.

| make[1]:Entering directory '/root/fwtk/fwtk/http-gw'
| cc -I .. -g -DLINUX -c -o error.o error.c
| error.c:175: parse error before '__builtin_va_alist'
| error.c:In function 'go_error':
| error.c:179:declaration for parameter '__builtin_va_alist' but no such
| parameter
| error.c:178:declaration for parameter 'msg' but no such parameter
| error.c:177:declaration for parameter '__errno_location' but no such
| parameter
| error.c:176:declaration for parameter 'sockfd' but no such parameter
| error.c:189:declaration for parameter 'gostarterror' but no such
| parameter
| make[1]: *** [error.o] Error 1

Redhat 7.0?  With the broken C compiler? :)

|                              thanks a lot
|
|
|
| _____________________________________________
| ÓĐ"Ŕń"×ßąéĚěĎÂ
http://ad2.263.net/cgi-bin/advert/push/redirect.cgi?aid=2452
|
Kind regards,
Berend

--
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Berend De Schouwer, +27-11-712-1435, UCS


From owner-fwtk-users@ex.tis.com Fri Feb 16 11:26 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA08181
	Fri, 16 Feb 2001 11:26:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA24206;
	Fri, 16 Feb 2001 08:29:22 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 16 Feb 2001 08:27:08 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA23482
	for fwtk-users-outgoing; Fri, 16 Feb 2001 08:27:05 -0800 (PST)
Date: Fri, 16 Feb 2001 18:21:05 +0200
From: Berend De Schouwer <bds@jhb.ucs.co.za>
To: Luis Fernando Barrera <luba@assist.com.gt>
Cc: fwtk-users@tis.com
Subject: Re: FW: How to build fwtk under Redhat 7.0
Message-ID: <20010216182105.I1285@bds.ucs.co.za>
Reply-To: bds@jhb.ucs.co.za
References: <NABBIDJPNCAGKGOFGHBFGEBCPAAA.luba@assist.com.gt>
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
In-Reply-To: <NABBIDJPNCAGKGOFGHBFGEBCPAAA.luba@assist.com.gt>; from luba@assist.com.gt on Fri, Feb 16, 2001 at 17:38:33 +0200
X-Mailer: Balsa 1.1.1
Lines: 96
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 3197

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, 16 Feb 2001 17:38:33 Luis Fernando Barrera wrote:
| [To be removed from this list send the message "unsubscribe fwtk-users"
| in the
| BODY of a mail message to majordomo@ex.tis.com.]
| 
| Broken compiler on RedHat 7.0? What does it mean?

Search the updates on redhat.com, or try:
http://www.redhat.com/support/errata/RHBA-2000-132.html

I've seen it break on varargs before, but can't remember the fix.
Maybe get the glibc update? (I'm not running RedHat)
  
| I'm (was) planning to migrate my FWTK Box w/RedHat 6.2 to
| RedHat 7.0...
| 
| Luis Fernando Barrera
| luba@assist.com.gt
| 
| 
| -----Original Message-----
| From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
| Behalf Of Berend De Schouwer
| Sent: Friday, February 16, 2001 4:38 AM
| To: zhangfan79@263.net
| Cc: fwtk-users@tis.com
| Subject: Re: How to build fwtk under Redhat 7.0
| 
| 
| [To be removed from this list send the message "unsubscribe fwtk-users"
| in
| the
| BODY of a mail message to majordomo@ex.tis.com.]
| 
| 
| On Fri, 16 Feb 2001 12:18:29 zhangfan79@263.net wrote:
| | [To be removed from this list send the message "unsubscribe fwtk-users"
| | in the
| | BODY of a mail message to majordomo@ex.tis.com.]
| |
| | dear all:
| |    I'm a new to fwtk and linux,when I build fwtk under Redhat,
| | so many errors come to me and i don't know how to do with it,
| | the error are listed below:
| |
| | make[1]:Entering directory '/root/fwtk/fwtk/auth'
| | cc -g -static -o authsrv authsrv.o proto.o db.o pass.o sevio.o
| | ..libauth.a
| | pass.o:In function 'passverify':
| | /root/fwtk/fwtk/auth/pass.c:41 undefined reference to 'crypt'
| | pass.o:In function 'passset':
| | /root/fwtk/fwtk/auth/pass.c:72:undefined reference to 'crypt'
| | collect2:Id returned 1 exit status
| | make[1]: *** [authsrv] Error 1
| | ....
| 
| Read the Makefile.  There are comments about what to do to
| make crypt work.
| 
| | make[1]:Entering directory '/root/fwtk/fwtk/http-gw'
| | cc -I .. -g -DLINUX -c -o error.o error.c
| | error.c:175: parse error before '__builtin_va_alist'
| | error.c:In function 'go_error':
| | error.c:179:declaration for parameter '__builtin_va_alist' but no such
| | parameter
| | error.c:178:declaration for parameter 'msg' but no such parameter
| | error.c:177:declaration for parameter '__errno_location' but no such
| | parameter
| | error.c:176:declaration for parameter 'sockfd' but no such parameter
| | error.c:189:declaration for parameter 'gostarterror' but no such
| | parameter
| | make[1]: *** [error.o] Error 1
| 
| Redhat 7.0?  With the broken C compiler? :)
| 
| |                              thanks a lot
| |
| |
| |
| | _____________________________________________
| | ÓĐ"Ŕń"×ßąéĚěĎÂ
| http://ad2.263.net/cgi-bin/advert/push/redirect.cgi?aid=2452
| |
| Kind regards,
| Berend
| 
| --
| -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
| Berend De Schouwer, +27-11-712-1435, UCS
| 
Kind regards,				  
Berend                                  

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Berend De Schouwer, +27-11-712-1435, UCS



From owner-fwtk-users@ex.tis.com Mon Feb 19 03:36 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id DAA15451
	Mon, 19 Feb 2001 03:36:48 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id AAA10436;
	Mon, 19 Feb 2001 00:39:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Feb 2001 00:29:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA08665
	for fwtk-users-outgoing; Mon, 19 Feb 2001 00:29:48 -0800 (PST)
Message-ID: <3A90D80B.CF92232C@evosoft.hu>
Date: Mon, 19 Feb 2001 09:23:39 +0100
From: "Pelhrimovszky, Zsolt" <Pelhrimovszky.Zsolt@evosoft.hu>
X-Mailer: Mozilla 4.7 [en] (WinNT; I)
X-Accept-Language: en,de,hu
MIME-Version: 1.0
To: fwtk-users <fwtk-users@lists.nai.com>
Subject: https
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 248

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dear All, 

Which part of the fwtk can be used for https proxying? Are any paches
nedded?

Thanks, 
	Zs. Pelhrimovszky

From owner-fwtk-users@ex.tis.com Mon Feb 19 11:06 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA16787
	Mon, 19 Feb 2001 11:06:04 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA05839;
	Mon, 19 Feb 2001 08:08:14 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Feb 2001 06:43:41 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA28286
	for fwtk-users-outgoing; Mon, 19 Feb 2001 06:43:30 -0800 (PST)
From: zhangfan79@263.net
MIME-Version: 1.0
Message-Id: <3A91305B.23902@mta1>
Date: Mon, 19 Feb 2001 22:40:27 +0800 (CST)
To: fwtk-users@lists.nai.com
Subject: http-gw problem
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1155

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

dear all 
    I have already build the fwtk,but when i test netperm-table configration ,i found some problem 
    all my computer link on a intel 410 switch,and one computer
act the proxy and eth0's ip address is 192.168.2.1 and eth1's ip address is 192.168.3.1 ,and other two computer  ip are 192.168.3.2
and 192.168.2.2
    when I use IE,no problem occur to me,but use Netscape,when I set the proxy option, it is ok,but when I did not use proxy option,something puzzled me,whenever how to configure,192.168.2.2 always can connect the 192.168.3.2,and i use tcpdump,found that 
192.168.2.2 connect 192.168.3.2 directly,not via proxy,i don't know what cause this problem and how to solve this problem,i need help
     
                             thanks a lot

                                      


_____________________________________________
ÓĐ"Ŕń"×ßąéĚěĎÂ            http://ad2.263.net/cgi-bin/advert/push/redirect.cgi?aid=2452
 
×ö¸öśŽľĂÚšĘÍĹŽČËľÄĹŽČË      http://ad2.263.net/cgi-bin/advert/push/redirect.cgi?aid=2453

From owner-fwtk-users@ex.tis.com Mon Feb 19 12:46 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA17086
	Mon, 19 Feb 2001 12:46:38 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA17816;
	Mon, 19 Feb 2001 09:48:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Feb 2001 08:45:20 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA09794
	for fwtk-users-outgoing; Mon, 19 Feb 2001 08:44:59 -0800 (PST)
Date: Mon, 19 Feb 2001 10:38:03 -0600 (CST)
From: Jeff Barnette <barnette@alamo.satlug.org>
To: <fwtk-users@lists.nai.com>
Subject: Maintaining timestamps with ftp-gw
Message-ID: <Pine.LNX.4.30.0102191011050.31752-100000@alamo.satlug.org>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 670

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This regards a RedHat 6.2 box using ncftp as the ftp client.

ncftp has a handy feature whereby it can skip any download where the file
already exists on the local machine with the same file size and timestamp.
This works great for me when I use my dial-up connection, which doesn't go
through the ftp-gw.  However, when I use my network connection at work,
which _does_ go through the ftp-gw, the timestamps always get set to the
current time.  Is there a 'switch' or other technique that I haven't found
yet?

Thanks for any help,

Jeff



From owner-fwtk-users@ex.tis.com Mon Feb 19 21:20 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA18347
	Mon, 19 Feb 2001 21:20:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA14932;
	Mon, 19 Feb 2001 18:22:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Feb 2001 17:19:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA11218
	for fwtk-users-outgoing; Mon, 19 Feb 2001 17:19:27 -0800 (PST)
Date: Mon, 19 Feb 2001 20:18:10 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Fwtk Users <fwtk-users@lists.nai.com>
Subject: ftp-gw on dmz zone of Checkpoint Firewall
Message-ID: <Pine.GSO.4.10.10102192012360.24380-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 958

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,

I am trying to implement the ftp-gw process within a DMZ zone of a
checkpoint firewall.  All other proxies seem to work there - but the
ftp-gw appears, in conjunction with checkpoint, drops the connections to
the remote host.

The configuation is as follows.....


client --->checkpoint -->ftp server
             |  ^
             v  |
            ftp-gw

I see the connection made to the ftp server from the client (via the
ftp-gw) - but as soon as the connection is made (command connection)
someone hangs up - the ftp server complains - the ftp-gw doesn't record
any errors - just terminates the connction.

Has anyone tried to implement this or a similiar process?  Looking to do
this to eliminate inbound data connections from external ftp servers (or
whatever replies....).

Any help is appreciated.

ted keller



From owner-fwtk-users@ex.tis.com Mon Feb 19 22:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA18527
	Mon, 19 Feb 2001 22:43:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA18156;
	Mon, 19 Feb 2001 19:45:19 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Feb 2001 18:47:04 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA15764
	for fwtk-users-outgoing; Mon, 19 Feb 2001 18:46:48 -0800 (PST)
Message-ID: <045101c09ae7$1ee9b710$160912ac@stcostlnds2zxj>
From: "List User" <lists@chaven.com>
To: "Ted Keller" <keller@bfg.com>, "Fwtk Users" <fwtk-users@lists.nai.com>
References: <Pine.GSO.4.10.10102192012360.24380-100000@ns1.bfg.com>
Subject: Re: ftp-gw on dmz zone of Checkpoint Firewall
Date: Mon, 19 Feb 2001 20:44:56 -0600
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1820

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Yes, we were attempting that at a point (when we were changing
over from FWTK to checkpoint).  There some problems with the
checkpoint security servers that we keep running into.  The main
work-around that we were able to do was to not use any of the checkpoint
security servers at all.  (They would keep grabbing connections and wouldn't
follow through properly).

If it's not this simple then you'll need to track it with the fw monitor
commands or call up your vendor.

Steve
----- Original Message -----
From: "Ted Keller" <keller@bfg.com>
To: "Fwtk Users" <fwtk-users@lists.nai.com>
Sent: Monday, February 19, 2001 19:18
Subject: ftp-gw on dmz zone of Checkpoint Firewall


> [To be removed from this list send the message "unsubscribe fwtk-users" in
the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Hello,
>
> I am trying to implement the ftp-gw process within a DMZ zone of a
> checkpoint firewall.  All other proxies seem to work there - but the
> ftp-gw appears, in conjunction with checkpoint, drops the connections to
> the remote host.
>
> The configuation is as follows.....
>
>
> client --->checkpoint -->ftp server
>              |  ^
>              v  |
>             ftp-gw
>
> I see the connection made to the ftp server from the client (via the
> ftp-gw) - but as soon as the connection is made (command connection)
> someone hangs up - the ftp server complains - the ftp-gw doesn't record
> any errors - just terminates the connction.
>
> Has anyone tried to implement this or a similiar process?  Looking to do
> this to eliminate inbound data connections from external ftp servers (or
> whatever replies....).
>
> Any help is appreciated.
>
> ted keller
>
>


From owner-fwtk-users@ex.tis.com Tue Feb 20 09:09 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA20156
	Tue, 20 Feb 2001 09:09:42 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA14570;
	Tue, 20 Feb 2001 06:11:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Feb 2001 05:03:29 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA08135
	for fwtk-users-outgoing; Tue, 20 Feb 2001 05:02:54 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A90E41D.3159AE59@peaktime.be>
Date: Mon, 19 Feb 2001 10:15:09 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users <fwtk-users@lists.nai.com>
Subject: Re: https
References: <3A90D80B.CF92232C@evosoft.hu>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 491

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

"Pelhrimovszky, Zsolt" wrote:
 > 
 > Dear All,
 > 
 > Which part of the fwtk can be used for https proxying? 

plug-gw with the "-ssl" flag.

 > Are any paches
 > nedded?

Nope.

 > 
 > Thanks,
 >         Zs. Pelhrimovszky

Greetings.
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Tue Feb 20 11:45 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA20993
	Tue, 20 Feb 2001 11:45:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA03234;
	Tue, 20 Feb 2001 08:48:06 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Feb 2001 07:27:41 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA24279
	for fwtk-users-outgoing; Tue, 20 Feb 2001 07:27:14 -0800 (PST)
X-Authentication-Warning: lxpc02.vrm.com: uucp set sender to <Heike.Wohllebe@vrm.de> using -f
Message-ID: <005101c09a86$73133e30$0fb91982@vrm.com>
Reply-To: "Heike Wohllebe" <Heike.Wohllebe@vrm.de>
From: "Heike Wohllebe" <Heike.Wohllebe@vrm.de>
To: <fwtk-users@ex.tis.com>
Subject: Problem which ftp-Connection 
Date: Mon, 19 Feb 2001 16:13:00 +0100
Organization: Verlagsgruppe Rhein Main
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
         boundary="----=_NextPart_000_004D_01C09A8E.D4A6AB20"
Content-Length: 3697

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_004D_01C09A8E.D4A6AB20
Content-Type: multipart/alternative;
         boundary="----=_NextPart_001_004E_01C09A8E.D4A6AB20"


------=_NextPart_001_004E_01C09A8E.D4A6AB20
Content-Type: text/plain;
         charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

hallo fwtk-users,

i have problems which one ftp-site to connect the
ftp-server. Reverse-DNS is ok, i have test it. I don=B4t find
something else in the faq.
Here ist the output:

ftp proxy-server
Name: Genios-VGRM@ftp.vhb.de
----GATEWAY CONNECTED TO ftp.vhb.de----
Login failed.
Remote system type is ftp.
ftp> bye
USER Genios-VGRM
ftp> ls
USER Genios-VGRM
ftp> ls
530 Peer has closed connection
ftp: bind: Address already in use
ftp>  =20

Does anybody know what happens. I know, it WindowsNT, but
the Administrator has only problems which our account :-(

In the INternet there are no problems:
# ftp ftp.vhb.de
Connected to ftp.vhb.de.
220 ftp Microsoft FTP Service (Version 3.0).
Name (ftp.vhb.de:root): Genios-VGRM
331 Password required for Genios-VGRM.
Password:
230-Willkommen bei der Verlagsgruppe Handelsblatt
230 User Genios-VGRM logged in.
Remote system type is Windows_NT.
ftp> ls
200 PORT command successful.
150 Opening ASCII mode data connection for /bin/ls.
226 Transfer complete.
ftp> bye                =20

Anybody ideas ?

Thank you.

Heike Wohllebe

------=_NextPart_001_004E_01C09A8E.D4A6AB20
Content-Type: text/html;
         charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
hallo fwtk-users,
  
i have problems which one ftp-site to = connect=20 the
ftp-server. Reverse-DNS is ok, i have = test it. I=20 don=B4t find
something else in the faq.
Here ist the output:
  
ftp proxy-server
Name: <3d.htm>Genios-VGRM@ftp.vhb<3d.htm>.de
----= GATEWAY=20 CONNECTED TO <3d.htm>ftp.vhb<3d.htm>.de----
Login=20 failed.
Remote system type is ftp.
ftp> bye
USER = Genios-VGRM
ftp> ls
USER = Genios-VGRM
ftp> ls
530=20 Peer has closed connection
ftp: bind: Address already in=20 use
ftp>   
  
Does anybody know what happens. I know, = it=20 WindowsNT, but
the Administrator has only problems = which our=20 account :-(
  
In the INternet there are no = problems:
# ftp <3d.htm>ftp.vhb<3d.htm>.de
Connected to <3d.htm>ftp.vhb<3d.htm>.de.
220 ftp Microsoft FTP = Service=20 (Version 3.0).
Name (<3d.htm>ftp.vhb<3d.htm>.de:root):=20 Genios-VGRM
331 Password required for=20 Genios-VGRM.
Password:
230-Willkommen bei der Verlagsgruppe=20 Handelsblatt
230 User Genios-VGRM logged in.
Remote system type is = Windows_NT.
ftp> ls
200 PORT command successful.
150 Opening = ASCII=20 mode data connection for /bin/ls.
226 Transfer complete.
ftp>=20 bye           &nbs=
p;    =20 
  
Anybody ideas ?
  
Thank you.
  
Heike = Wohllebe

------=_NextPart_001_004E_01C09A8E.D4A6AB20--

------=_NextPart_000_004D_01C09A8E.D4A6AB20
Content-Type: text/x-vcard;
         name="Wohllebe Heike.vcf"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: attachment;
         filename="Wohllebe Heike.vcf"

BEGIN:VCARD
VERSION:2.1
N:Wohllebe;Heike
FN:Wohllebe Heike
ORG:Verlagsgruppe Rhein Main;IS-NUS
TEL;WORK;VOICE:06131 48-4631
TEL;WORK;FAX:06131 48-4677
ADR;WORK:;;Erich-Dombrowski-Str.2;55127 Mainz;Rheinland-Pfalz;55127
LABEL;WORK;ENCODING=3DQUOTED-PRINTABLE:Erich-Dombrowski-Str.2=3D0D=3D0A55=
127 Mainz, Rheinland-Pfalz 55127
EMAIL;PREF;INTERNET:hwohllebe@vrm.de
REV:20010219T151300Z
END:VCARD

------=_NextPart_000_004D_01C09A8E.D4A6AB20--



From owner-fwtk-users@ex.tis.com Tue Feb 20 16:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA22215
	Tue, 20 Feb 2001 16:34:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA12639;
	Tue, 20 Feb 2001 13:36:52 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Feb 2001 12:31:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA03294
	for fwtk-users-outgoing; Tue, 20 Feb 2001 12:31:00 -0800 (PST)
Message-ID: <E6C8B3EE167BD411B62F00D0B79EA1FD0683AA@chicago_srv2>
From: "Skolnik, Ed" <Ed.Skolnik@FLORSHEIM.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject:  FTP proxy problem with one location and was wondering 
Date: Tue, 20 Feb 2001 14:26:10 -0600
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2567

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I seem to be having a FTP proxy problem with one location and was wondering
if anyone out there could maybe point me in the right direction?
It seems like I am seeing either "CNTRL-M's or CNTRL-H's" where the password
should be.



Script command is started on Tue Feb 20 14:10:40 CST 2001.
# ./eis.ksh
+ id -u
+ ((  0 == 0  ))
+ + hostname
PS1=flrprdd# 
+ set -o vi
+ date
+ echo Starting ./eis.ksh Tue Feb 20 14:10:45 CST 2001
Starting ./eis.ksh Tue Feb 20 14:10:45 CST 2001
+ + basename ./eis.ksh
tmpfile=/tmp/eis.ksh.33516
+ echo open firewall\nuser 062677@ftp.scudder.com xxxxx\nprompt\ndir \nbye\n
+ tee /tmp/eis.ksh.33516
+ ftp -v -n
+ 2>& 1
Connected to gateway.
220 gw.florsheim.com FTP proxy (Version V2.0) ready.
----GATEWAY CONNECTED TO ftp.scudder.com----
Invalid reply.
220 FTP server ready.
Login failed.
Interactive mode off.
USER 062677
Invalid reply.
530 Peer has closed connection
500 must be connected to remote server
+ cat /tmp/eis.ksh.33516
Connected to gateway.
220 gw.florsheim.com FTP proxy (Version V2.0) ready.
----GATEWAY CONNECTED TO ftp.scudder.com----
Invalid reply.
220 FTP server ready.
Login failed.
Interactive mode off.
USER 062677
Invalid reply.
530 Peer has closed connection
500 must be connected to remote server
+ ls -l /tmp/eis.ksh.33516
-rw-r--r--   1 root     system       292 Feb 20 14:10 /tmp/eis.ksh.33516



+ vi /tmp/eis.ksh.33516
[?7h[?1l(B=[24;1H[?25h="/tmp/eis.ksh.33516" 11 lines, 292 characters
[H[2JConnected to gateway.[H
220 gw.florsheim.com FTP proxy (Version V2.0) ready.
----GATEWAY CONNECTED TO ftp.scudder.com----^M
Invalid reply.
220 FTP server ready.
Login failed.
Interactive mode off.
USER 062677^M
Invalid reply.
530 Peer has closed connection
500 must be connected to remote server
[J[?25h>[?7h[?7h[?1l(B=[24;1H[J[?25h+ exit
flrprdd# 

Script command is complete on Tue Feb 20 14:11:11 CST 2001.



Ed Skolnik 
Florsheim Group Inc. 
MIT Consultants 
200 N. LaSalle 
Chicago IL. 60601 
312-458-2655 Phone 
312-458-2661 Fax 
ed.skolnik@florsheim.com 



Confidentiality Notice: This e-mail message, including any attachments, is
for the sole use of the intended recipient(s) and may contain confidential
and privileged information. Any unauthorized review, use, disclosure or
distribution is prohibited. If you are not the intended recipient, please
contact the sender by reply e-mail and destroy all copies of the original
message. Thank you. 






From owner-fwtk-users@ex.tis.com Tue Feb 20 18:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA22622
	Tue, 20 Feb 2001 18:08:43 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA28010;
	Tue, 20 Feb 2001 15:11:00 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Feb 2001 14:06:24 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA17474
	for fwtk-users-outgoing; Tue, 20 Feb 2001 14:06:08 -0800 (PST)
Date: Tue, 20 Feb 2001 17:04:56 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Fwtk Users <fwtk-users@lists.nai.com>
Subject: Re: ftp-gw on dmz zone of Checkpoint Firewall
In-Reply-To: <Pine.GSO.4.10.10102192012360.24380-100000@ns1.bfg.com>
Message-ID: <Pine.GSO.4.10.10102201654120.2846-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1871

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This problem seems to now be solved.  My Checkpoint wizard made the
following fixes to the checkpoint base file - not this is 4.0 sp7...


 I placed the following fix in the base.def file
  
  1) FIX 1: Remove the PASV newline check:
  
  --Comment out (with // marks) the following line:
  
       #define FTPPORT(match)        (call KFUNC_FTPPORT <0x1|(match)>)
  
  --Uncomment out the following line:
  
       //#define FTPPORT(match)  (call KFUNC_FTPPORT <(match)>)
  
  =====================================================================
  2) FIX 2: Remove the FTP control port newline check:
  
  --Comment out the following line:
       #define FTP_ENFORCE_NL


tek


On Mon, 19 Feb 2001, Ted Keller wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello,
> 
> I am trying to implement the ftp-gw process within a DMZ zone of a
> checkpoint firewall.  All other proxies seem to work there - but the
> ftp-gw appears, in conjunction with checkpoint, drops the connections to
> the remote host.
> 
> The configuation is as follows.....
> 
> 
> client --->checkpoint -->ftp server
>              |  ^
>              v  |
>             ftp-gw
> 
> I see the connection made to the ftp server from the client (via the
> ftp-gw) - but as soon as the connection is made (command connection)
> someone hangs up - the ftp server complains - the ftp-gw doesn't record
> any errors - just terminates the connction.
> 
> Has anyone tried to implement this or a similiar process?  Looking to do
> this to eliminate inbound data connections from external ftp servers (or
> whatever replies....).
> 
> Any help is appreciated.
> 
> ted keller
> 
> 


From owner-fwtk-users@ex.tis.com Tue Feb 20 22:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA23329
	Tue, 20 Feb 2001 22:33:52 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA20345;
	Tue, 20 Feb 2001 19:35:59 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Feb 2001 18:31:57 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA17040
	for fwtk-users-outgoing; Tue, 20 Feb 2001 18:31:32 -0800 (PST)
Date: Tue, 20 Feb 2001 21:30:00 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Rick Murphy <rmurphy@itm-inst.com>
cc: Fwtk Users <fwtk-users@lists.nai.com>
Subject: Re: ftp-gw on dmz zone of Checkpoint Firewall
In-Reply-To: <5.0.2.1.0.20010220200437.01d34420@mail.itm-inst.com>
Message-ID: <Pine.GSO.4.10.10102202123100.10177-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2975

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick,

You force me to think!  I suspect fix 1 did actually resolve my problem.
It may not be the best general solution...

If you remember the picture - my inside client connected to port 21 of the
ftp-gw proxy server - through the checkpoint firewall.  That consumed port
21.  The proxy server then connected - again through the same checkpoint
firewall to the destination computer on port 21.  This, if I understand
things correctly, would match your description of source port and target
port being the same and consumed.  Therefore, this probably did resolve my
issue as far as the ftp-gw is concerned.  Now, what I have to think about
is if I permit general internal clients to make direct ftp connections
through the firewall without using the ftp-gw proxy server.  Do I open up
any issues there?

Seems as if the newline thing was something they added "becaused it fixed
other clients with similar problems".  They talked about a server at
compaq that required these fixes.  I wonder if that part of the fix was
to resolve a site specific issue.

Can you point me to some information regarding the Dug Song findings?

Many thanks.

tek


On Tue, 20 Feb 2001, Rick Murphy wrote:

> At 05:04 PM 2/20/01 -0500, Ted Keller wrote:
> >[To be removed from this list send the message "unsubscribe fwtk-users" in the
> >BODY of a mail message to majordomo@ex.tis.com.]
> >
> >This problem seems to now be solved.  My Checkpoint wizard made the
> >following fixes to the checkpoint base file - not this is 4.0 sp7...
> >
> >
> >  I placed the following fix in the base.def file
> >
> >   1) FIX 1: Remove the PASV newline check:
> >
> >   --Comment out (with // marks) the following line:
> >
> >        #define FTPPORT(match)        (call KFUNC_FTPPORT <0x1|(match)>)
> >
> >   --Uncomment out the following line:
> >
> >        //#define FTPPORT(match)  (call KFUNC_FTPPORT <(match)>)
> 
> That's not a newline check - changing this allows active FTP to use a 
> destination port for the control connection that's assigned to an existing 
> service. Since some of the high ports have service definitions, there's 
> some chance of collision; of course, that leaves you open to FTP bounce 
> attacks. Actually, this change probably had no effect on fixing your problem.
> 
> >   =====================================================================
> >   2) FIX 2: Remove the FTP control port newline check:
> >
> >   --Comment out the following line:
> >        #define FTP_ENFORCE_NL
> 
> This is a newline check; commenting that out leaves you wide open to the 
> exploit that Dug Song and gang found and publicised at the Black Hat 
> briefings.
> 
> It seems to me that these recommendations should have come with some 
> warnings of the possible side-effects.. do you consider the possible 
> security risks reasonable?
>          -Rick
> 


From owner-fwtk-users@ex.tis.com Wed Feb 21 08:49 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA25227
	Wed, 21 Feb 2001 08:49:07 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA16481;
	Wed, 21 Feb 2001 05:51:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 04:50:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA12453
	for fwtk-users-outgoing; Wed, 21 Feb 2001 04:50:05 -0800 (PST)
Message-Id: <5.0.2.1.0.20010220234623.01d1da00@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 20 Feb 2001 23:52:46 -0500
To: Ted Keller <keller@bfg.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw on dmz zone of Checkpoint Firewall
Cc: Fwtk Users <fwtk-users@lists.nai.com>
In-Reply-To: <Pine.GSO.4.10.10102202123100.10177-100000@ns1.bfg.com>
References: <5.0.2.1.0.20010220200437.01d34420@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1304

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:30 PM 2/20/01 -0500, Ted Keller wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >Rick,
 >
 >You force me to think!  I suspect fix 1 did actually resolve my problem.
 >It may not be the best general solution...

Now that you point out the picture, that's a good possibility - that fix is 
much lower risk.


 >Can you point me to some information regarding the Dug Song findings?

I'll see if I can dig up a reference off securityfocus.com; basically, with 
Firewall-1 you could arrange a FTP server to send text containing an 
embedded newline followed by the text "PORT ....." - that would cause the 
firewall to open the port mentioned in the banner string. All you've got to 
do is own a FTP server someone's going to through a FW-1 box.

My basic problem is that this change removes a fix for a security hole in 
the firewall. There should be some warnings about the consequences of 
turning this off.
(The Compaq problem actually is a limitation of the newline patch - any FTP 
site with a long banner message won't work unless you turn the fix off.)
          -Rick



From owner-fwtk-users@ex.tis.com Wed Feb 21 08:49 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA25228
	Wed, 21 Feb 2001 08:49:07 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA16462;
	Wed, 21 Feb 2001 05:50:58 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 04:45:17 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA12118
	for fwtk-users-outgoing; Wed, 21 Feb 2001 04:44:56 -0800 (PST)
Message-Id: <5.0.2.1.0.20010220200437.01d34420@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 20 Feb 2001 20:10:30 -0500
To: Ted Keller <keller@bfg.com>, Fwtk Users <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: ftp-gw on dmz zone of Checkpoint Firewall
In-Reply-To: <Pine.GSO.4.10.10102201654120.2846-100000@ns1.bfg.com>
References: <Pine.GSO.4.10.10102192012360.24380-100000@ns1.bfg.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1730

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 05:04 PM 2/20/01 -0500, Ted Keller wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >This problem seems to now be solved.  My Checkpoint wizard made the
 >following fixes to the checkpoint base file - not this is 4.0 sp7...
 >
 >
 >  I placed the following fix in the base.def file
 >
 >   1) FIX 1: Remove the PASV newline check:
 >
 >   --Comment out (with // marks) the following line:
 >
 >        #define FTPPORT(match)        (call KFUNC_FTPPORT <0x1|(match)>)
 >
 >   --Uncomment out the following line:
 >
 >        //#define FTPPORT(match)  (call KFUNC_FTPPORT <(match)>)

That's not a newline check - changing this allows active FTP to use a 
destination port for the control connection that's assigned to an existing 
service. Since some of the high ports have service definitions, there's 
some chance of collision; of course, that leaves you open to FTP bounce 
attacks. Actually, this change probably had no effect on fixing your problem.

 >   =====================================================================
 >   2) FIX 2: Remove the FTP control port newline check:
 >
 >   --Comment out the following line:
 >        #define FTP_ENFORCE_NL

This is a newline check; commenting that out leaves you wide open to the 
exploit that Dug Song and gang found and publicised at the Black Hat 
briefings.

It seems to me that these recommendations should have come with some 
warnings of the possible side-effects.. do you consider the possible 
security risks reasonable?
          -Rick



From owner-fwtk-users@ex.tis.com Wed Feb 21 08:49 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA25233
	Wed, 21 Feb 2001 08:49:17 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA16487;
	Wed, 21 Feb 2001 05:51:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 04:46:21 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA12161
	for fwtk-users-outgoing; Wed, 21 Feb 2001 04:45:55 -0800 (PST)
Message-Id: <5.0.2.1.0.20010220210818.01d45140@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 20 Feb 2001 21:12:04 -0500
To: "Skolnik, Ed" <Ed.Skolnik@FLORSHEIM.com>,
        "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FTP proxy problem with one location and was wondering 
In-Reply-To: <E6C8B3EE167BD411B62F00D0B79EA1FD0683AA@chicago_srv2>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 850

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:26 PM 2/20/01 -0600, Skolnik, Ed wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >I seem to be having a FTP proxy problem with one location and was wondering
 >if anyone out there could maybe point me in the right direction?
 >It seems like I am seeing either "CNTRL-M's or CNTRL-H's" where the password
 >should be.

You're trying to use "echo" to feed a set of commands to your ftp client 
with newline separators; are you sure that client's going to work that way? 
I'd start out with trying the same commands interactively - if they work 
through the ftp-gw then you've eliminated it as the cause.
          -Rick



From owner-fwtk-users@ex.tis.com Wed Feb 21 11:00 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA25708
	Wed, 21 Feb 2001 11:00:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA01197;
	Wed, 21 Feb 2001 08:02:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 06:56:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA22527
	for fwtk-users-outgoing; Wed, 21 Feb 2001 06:56:37 -0800 (PST)
From: eduval@synergia-france.com.fr
Message-ID: <3A93D474.A1F3DCD9@synergia-france.com.fr>
Date: Wed, 21 Feb 2001 15:45:08 +0100
X-Mailer: Mozilla 4.72 [en] (WinNT; I)
X-Accept-Language: fr
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: plug-gw and samba
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 542

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I want make two plug to server1 and server2 samba.

I have into netperm-table this config :

plug-gw: port netbios-ns 1.2.3.* -plug-to server1 -port netbios-ns
plug-gw: port netbios-ssn 1.2.3.* -plug-to server1 -port netbios-ssn

and into my rc.local, I have :

[...]/plug-gw -daemon 137 netbios-ns &
[...]/plug-gw -daemon 139 netbios-ssn &


How make for append an other plug (samba) to server2 ?

Regards.

From owner-fwtk-users@ex.tis.com Wed Feb 21 11:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA25740
	Wed, 21 Feb 2001 11:05:49 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA01748;
	Wed, 21 Feb 2001 08:07:51 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 07:09:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA23808
	for fwtk-users-outgoing; Wed, 21 Feb 2001 07:08:53 -0800 (PST)
From: dw@netzstation.net
X-Authentication-Warning: fw.netzstation.net: Processed by hermes with -C /etc/sendmail.orig.cf
Subject: Using ms-sql-gw
To: <fwtk-users@lists.nai.com>
Message-ID: <OF18D03AB1.08C5C6A5-ONC12569FA.00506871@netzstation.net>
Date: Wed, 21 Feb 2001 16:02:52 +0100
 February 2000) at 21/02/2001 16:03:06
MIME-Version: 1.0
X-AntiVirus: scanned for viruses by AMaViS 0.2.1 (http://amavis.org/)
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id HAA23791
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 866

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi @ll,
I've downloaded ms-sql-gw a few days ago.
I got it installed, but I don't understand the syntax
of it correctly.

Can anyone mail me an example netperm-table please?

For interested:

I've got a private network (10.108.1.*) and a DMZ (172.16.1.*):

There are three SQL- Servers:

10.108.1.21, 10.108.1.22 and 172.16.1.5

The first two need to communicate with the third.
Has anyone an idea of doing this?

(They use Ms-SQL 6 Protocol; I tried using udprelay (1434) together with
  plug-gw on port 1433 but it seems not to work)


Mit freundlichem Gruss / Best Regards
-------------------------------------------------------------------------
- Dieter Windmüller -
Netzstation Informationstechnik GmbH
e-mail: dw@netzstation.net


From owner-fwtk-users@ex.tis.com Wed Feb 21 13:03 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA26233
	Wed, 21 Feb 2001 13:03:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA18420;
	Wed, 21 Feb 2001 10:05:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 08:40:51 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA05954
	for fwtk-users-outgoing; Wed, 21 Feb 2001 08:40:29 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A93EC7B.D6C4FA60@peaktime.be>
Date: Wed, 21 Feb 2001 17:27:39 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: Re: plug-gw and samba
References: <3A93D474.A1F3DCD9@synergia-france.com.fr>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1325

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

eduval@synergia-france.com.fr wrote:
 > 
 > I want make two plug to server1 and server2 samba.
 > 
 > I have into netperm-table this config :
 > 
 > plug-gw: port netbios-ns 1.2.3.* -plug-to server1 -port netbios-ns
 > plug-gw: port netbios-ssn 1.2.3.* -plug-to server1 -port netbios-ssn
 > 
 > and into my rc.local, I have :
 > 
 > [...]/plug-gw -daemon 137 netbios-ns &
 > [...]/plug-gw -daemon 139 netbios-ssn &
 > 
 > How make for append an other plug (samba) to server2 ?
 > 
 > Regards.

Untried WAG: use a relayer.

On *another* machine, say 1.2.3.1, which is not itself a 'true' Samba
server, run plug-gw like this:

in /etc/services: netbios-alt-ns 9137

in netperm-table:

plug-gw: port netbios-ns 1.2.3.* -plug-to firewall -port netbios-alt-ns

in rc.local

plug-gw -daemon 137 netbios-ns

On the firewall:

in /etc/services: netbios-alt-ns 9137

in netperm-table:

plug-gw: port netbios-alt-ns 1.2.3.1 -plug-to server2 -port netbios-ns
plug-gw: port netbios-ns 1.2.3.* -plug-to server1 -port netbios-ns

in rc.local

plug-gw -daemon 137 netbios-ns
plug-gw -daemon 9137 netbios-alt-ns

As I said, this is a wild-assed guess. If I'm wrong, someone please tell
me!

-- 
Michel Bardiaux


From owner-fwtk-users@ex.tis.com Wed Feb 21 14:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA26603
	Wed, 21 Feb 2001 14:33:18 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA00963;
	Wed, 21 Feb 2001 11:35:09 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 10:29:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA21264
	for fwtk-users-outgoing; Wed, 21 Feb 2001 10:29:11 -0800 (PST)
Message-ID: <91A5926EFF44D3118B1200104B7276EB654F3C@hart-exchange.hartwellcorp.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "'eduval@synergia-france.com.fr'" <eduval@synergia-france.com.fr>
Cc: "'mbardiaux@peaktime.be'" <mbardiaux@peaktime.be>, fwtk-users@ex.tis.com
Subject: RE: plug-gw and samba
Date: Wed, 21 Feb 2001 10:29:57 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2012

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Part of the problem is that netbios-ns is a UDP service not TCP.  Plug-gw
will only work for TCP services.  You must use another program such as
Udprelay for UDP services.


--------------------
Michael St. Laurent
Hartwell Corporation


> -----Original Message-----
> From: Michel Bardiaux [mailto:mbardiaux@peaktime.be]
> Sent: Wednesday, February 21, 2001 8:28 AM
> To: fwtk-users@ex.tis.com
> Subject: Re: plug-gw and samba
> 
> 
> [To be removed from this list send the message "unsubscribe 
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> eduval@synergia-france.com.fr wrote:
>  > 
>  > I want make two plug to server1 and server2 samba.
>  > 
>  > I have into netperm-table this config :
>  > 
>  > plug-gw: port netbios-ns 1.2.3.* -plug-to server1 -port netbios-ns
>  > plug-gw: port netbios-ssn 1.2.3.* -plug-to server1 -port 
> netbios-ssn
>  > 
>  > and into my rc.local, I have :
>  > 
>  > [...]/plug-gw -daemon 137 netbios-ns &
>  > [...]/plug-gw -daemon 139 netbios-ssn &
>  > 
>  > How make for append an other plug (samba) to server2 ?
>  > 
>  > Regards.
> 
> Untried WAG: use a relayer.
> 
> On *another* machine, say 1.2.3.1, which is not itself a 'true' Samba
> server, run plug-gw like this:
> 
> in /etc/services: netbios-alt-ns 9137
> 
> in netperm-table:
> 
> plug-gw: port netbios-ns 1.2.3.* -plug-to firewall -port 
> netbios-alt-ns
> 
> in rc.local
> 
> plug-gw -daemon 137 netbios-ns
> 
> On the firewall:
> 
> in /etc/services: netbios-alt-ns 9137
> 
> in netperm-table:
> 
> plug-gw: port netbios-alt-ns 1.2.3.1 -plug-to server2 -port netbios-ns
> plug-gw: port netbios-ns 1.2.3.* -plug-to server1 -port netbios-ns
> 
> in rc.local
> 
> plug-gw -daemon 137 netbios-ns
> plug-gw -daemon 9137 netbios-alt-ns
> 
> As I said, this is a wild-assed guess. If I'm wrong, someone 
> please tell
> me!
> 
> -- 
> Michel Bardiaux
> 

From owner-fwtk-users@ex.tis.com Wed Feb 21 15:06 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA26800
	Wed, 21 Feb 2001 15:06:35 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA06185;
	Wed, 21 Feb 2001 12:08:49 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Feb 2001 11:08:51 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA26908
	for fwtk-users-outgoing; Wed, 21 Feb 2001 11:08:34 -0800 (PST)
X-Authentication-Warning: stargate.diomass.org: smap set sender to <Mhodges@diomass.org> using -f
Message-ID: <51D4F81EFAF7D111B33600805FBB11253096A9@HQ_APPS>
From: "Hodges, Michael" <Mhodges@diomass.org>
To: fwtk-users@tis.com
Subject: Broken Web Servers
Date: Wed, 21 Feb 2001 14:05:48 -0500
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C09C39.4F9CBF60"
Content-Length: 1556

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C09C39.4F9CBF60
Content-Type: text/plain;
	charset="iso-8859-1"

To make an embarassingly long story short, I've lost (in more than one
place, mind you) the http-gw patch for the broken web servers.  Could
someone mail it to me directly?

TIA

Michael Hodges
The Episcopal Diocese of Massachusetts
mhodges@diomass.org

------_=_NextPart_001_01C09C39.4F9CBF60
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2650.12">
<TITLE>Broken Web Servers</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2 FACE=3D"Arial">To make an embarassingly long story =
short, I've lost (in more than one place, mind you) the http-gw patch =
for the broken web servers.&nbsp; Could someone mail it to me =
directly?</FONT></P>

<P><FONT SIZE=3D2 FACE=3D"Arial">TIA</FONT>
</P>

<P><FONT SIZE=3D2 FACE=3D"Arial">Michael Hodges</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Arial">The Episcopal Diocese of =
Massachusetts</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Arial">mhodges@diomass.org</FONT>
</P>

</BODY>
</HTML>
------_=_NextPart_001_01C09C39.4F9CBF60--

From owner-fwtk-users@ex.tis.com Thu Feb 22 07:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA29675
	Thu, 22 Feb 2001 07:43:08 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA19902;
	Thu, 22 Feb 2001 04:45:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Feb 2001 03:39:42 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA17252
	for fwtk-users-outgoing; Thu, 22 Feb 2001 03:39:26 -0800 (PST)
Message-ID: <3A94F9D8.683DB90C@interchain.nl>
Date: Thu, 22 Feb 2001 12:36:56 +0100
From: Kees van Veen <cvn@interchain.nl>
Organization: Interchain International
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.14-5.0 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Telnet (HOLE) through http-gw (!) with CONNECT ???
References: <D9B1937D4099D411B0670090277C004F03D15A@ntexch02s.scs.dra.hmg.gb>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="------------7F4426E0AF4E0141C79D72E2"
Content-Length: 3520

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------7F4426E0AF4E0141C79D72E2
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

I'm running the fwtk for quite a while now and was looking into
tunneling through http proxies when I discovered that my firewall wasn't
as safe as I thought.

I have users on the Intranet connected to the outside through http-gw.
I allow people from the outside to connect to one internal destination
(called xxxx) with the netperm-table line:

http-gw:  ... all internal hosts ...
http-gw:  permit-hosts * -dest xxxx -httpd xxxx -java -javascript -deny
exec

Now on machine 'xxxx' I also have telnetd listening on port 23 and to MY
SURPRISE I could FROM THE OUTSIDE connect to http-gw with:

	telnet firewall 80

and then type

	CONNECT xxxx:23 HTTP/1.0

and get the login prompt (!?!).

Seems like the -dest flag in the http-gw nerperm-table options only
checks on destination host/address, but not on the port. My naive
assumption was that http-gw would only forward port 80.

I don't know of other ways to protect this, so I wrote a patch to
http-gw that would check on the portnumber as well, if I would have a
netperm-table line like:

http-gw:  permit-hosts * -dest xxxx:80 -httpd xxxx -java -javascript
-deny exec

so the hosts after the -dest flag may be specified with portnumber which
would be checked if specified (without it only the hostname is checked).

If anyone knows another way of protecting for this with http-gw
(plug-gw), I would be interested in it. Also are there other protocols
like ftp, etc. that allow for such a tunnel ?

I've included the patch for 'hmain.c' of http-gw.

Regards,
Kees
--------------7F4426E0AF4E0141C79D72E2
Content-Type: application/octet-stream;
 name="http-gw-CONNECT.patch"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
 filename="http-gw-CONNECT.patch"

LS0tIG9sZC9obWFpbi5jCVdlZCBGZWIgMjEgMTU6MTM6NDIgMjAwMQorKysgaG1haW4uYwlU
aHUgRmViIDIyIDEyOjM1OjU3IDIwMDEKQEAgLTEyMDEsMjIgKzEyMDEsMzcgQEAKIGludCBj
aGVja19kZXN0KHNvY2tmZCkKIGludCBzb2NrZmQ7CiB7CWNoYXIgKip4cDsKLQlpbnQgeDsK
KwlpbnQgeCwgcG9ydDsKIAljaGFyICpwOwogCiAJaWYoIHZhbGlkZXN0cyAhPSBOVUxMKXsK
LQkJcCA9IHJlbV9zZXJ2ZXI7Ci0JCXdoaWxlKCpwICYmICpwIT0gJzonKXArKzsKLQkJaWYo
ICpwID09ICc6Jyl7CisJCXBvcnQgPSByZW1fcG9ydDsKKwkJcCA9IHN0cmNocihyZW1fc2Vy
dmVyLCAnOicpOwkvKiBUcnkgdGhlIHBvcnRudW1iZXIgKi8KKwkJaWYgKHApewogCQkJKnAg
PSAnXDAnOwotCQl9ZWxzZQotCQkJcCA9IE5VTEw7CisJCQlwb3J0ID0gYXRvaShwKzEpOwor
CQl9CiAKIAkJZm9yKHhwID0gdmFsaWRlc3RzOyAqeHAgIT0gTlVMTDsgeHArKyl7Ci0JCQlp
ZiggKip4cCA9PSAnIScgJiYgaG9zdG1hdGNoKCp4cCsxLCByZW1fc2VydmVyKSl7Ci0JCQkJ
Z290byBkZW5pZWQ7Ci0JCQl9ZWxzZXsKLQkJCQlpZihob3N0bWF0Y2goKnhwLCByZW1fc2Vy
dmVyKSkKKwkJCWludCBtYXRjaCwgdmFsaWRwb3J0OworCQkJY2hhciAqZGVzdCwgKnE7CisK
KwkJCS8qIFNwbGl0IHRoZSB2YWxpZCBkZXN0aW5hdGlvbnMgYW5kIHBvcnRudW1iZXIgKi8K
KwkJCWRlc3QgPSAoKip4cD09JyEnID8gKnhwKzEgOiAqeHApOworCQkJdmFsaWRwb3J0ID0g
cmVtX3BvcnQ7CisJCQlxID0gc3RyY2hyKCp4cCwgJzonKTsJLyogVHJ5IHRoZSBwb3J0bnVt
YmVyICovCisJCQlpZiAocSl7CisJCQkJKnEgPSAnXDAnOworCQkJCXZhbGlkcG9ydCA9IGF0
b2kocSsxKTsKKwkJCX0KKwkJCW1hdGNoID0gKGhvc3RtYXRjaChkZXN0LHJlbV9zZXJ2ZXIp
ICYmIHBvcnQ9PXZhbGlkcG9ydCk7CisKKwkJCWlmIChxKSAqcSA9ICc6JzsJLyogcHV0IHRo
ZSBjb2xvbiBiYWNrICovCisKKwkJCWlmIChtYXRjaCl7CisJCQkJaWYgKCoqeHA9PSchJykK
KwkJCQkJZ290byBkZW5pZWQ7CisJCQkJZWxzZQogCQkJCQlicmVhazsKIAkJCX0KIAkJfQo=
--------------7F4426E0AF4E0141C79D72E2--


From owner-fwtk-users@ex.tis.com Thu Feb 22 09:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA00218
	Thu, 22 Feb 2001 09:40:13 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA26941;
	Thu, 22 Feb 2001 06:42:23 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Feb 2001 05:38:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA22378
	for fwtk-users-outgoing; Thu, 22 Feb 2001 05:38:32 -0800 (PST)
Message-ID: <3A9515BC.801E317C@interchain.nl>
Date: Thu, 22 Feb 2001 14:35:56 +0100
From: Kees van Veen <cvn@interchain.nl>
Organization: Interchain International
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.14-5.0 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Re: Telnet (HOLE) through http-gw (!) with CONNECT ???
References: <D9B1937D4099D411B0670090277C004F03D15A@ntexch02s.scs.dra.hmg.gb> <3A94F9D8.683DB90C@interchain.nl>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="------------AD0BCE094F1223F499D5B134"
Content-Length: 2344

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------AD0BCE094F1223F499D5B134
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: base64

S2VlcyB2YW4gVmVlbiB3cm90ZToNCg0KPiBJJ3ZlIGluY2x1ZGVkIHRoZSBwYXRjaCBmb3Ig
J2htYWluLmMnIG9mIGh0dHAtZ3cuDQoNCkkgcG9zdGVkIHRoZSBwYXRjaCBhIGxpdHRsZSB0
b28gc29vbiwgaGVyZSdzIGEgc2xpZ2h0IG1vZGlmaWNhdGlvbiBpbiB0aGUgY2FzZQ0KdGhh
dCB0aGUgcmVtb3RlIHBvcnQgaXMgZXF1YWwgdG8gemVyby4NCg0KUmVnYXJkcywNCktlZXMN
Cg==
--------------AD0BCE094F1223F499D5B134
Content-Type: application/octet-stream;
 name="http-gw-CONNECT.patch"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
 filename="http-gw-CONNECT.patch"

LS0tIG9sZC9obWFpbi5jCVdlZCBGZWIgMjEgMTU6MTM6NDIgMjAwMQorKysgaG1haW4uYwlU
aHUgRmViIDIyIDE0OjMyOjMzIDIwMDEKQEAgLTEyMDEsMjIgKzEyMDEsMzggQEAKIGludCBj
aGVja19kZXN0KHNvY2tmZCkKIGludCBzb2NrZmQ7CiB7CWNoYXIgKip4cDsKLQlpbnQgeDsK
KwlpbnQgeCwgcG9ydDsKIAljaGFyICpwOwogCiAJaWYoIHZhbGlkZXN0cyAhPSBOVUxMKXsK
LQkJcCA9IHJlbV9zZXJ2ZXI7Ci0JCXdoaWxlKCpwICYmICpwIT0gJzonKXArKzsKLQkJaWYo
ICpwID09ICc6Jyl7CisJCXBvcnQgPSByZW1fcG9ydDsKKwkJaWYgKCFwb3J0KSBwb3J0ID0g
SFRUUFBPUlQ7CisJCXAgPSBzdHJjaHIocmVtX3NlcnZlciwgJzonKTsJLyogVHJ5IHRoZSBw
b3J0bnVtYmVyICovCisJCWlmIChwKXsKIAkJCSpwID0gJ1wwJzsKLQkJfWVsc2UKLQkJCXAg
PSBOVUxMOworCQkJcG9ydCA9IGF0b2kocCsxKTsKKwkJfQogCiAJCWZvcih4cCA9IHZhbGlk
ZXN0czsgKnhwICE9IE5VTEw7IHhwKyspewotCQkJaWYoICoqeHAgPT0gJyEnICYmIGhvc3Rt
YXRjaCgqeHArMSwgcmVtX3NlcnZlcikpewotCQkJCWdvdG8gZGVuaWVkOwotCQkJfWVsc2V7
Ci0JCQkJaWYoaG9zdG1hdGNoKCp4cCwgcmVtX3NlcnZlcikpCisJCQlpbnQgbWF0Y2gsIHZh
bGlkcG9ydDsKKwkJCWNoYXIgKmRlc3QsICpxOworCisJCQkvKiBTcGxpdCB0aGUgdmFsaWQg
ZGVzdGluYXRpb25zIGFuZCBwb3J0bnVtYmVyICovCisJCQlkZXN0ID0gKCoqeHA9PSchJyA/
ICp4cCsxIDogKnhwKTsKKwkJCXZhbGlkcG9ydCA9IHJlbV9wb3J0OworCQkJcSA9IHN0cmNo
cigqeHAsICc6Jyk7CS8qIFRyeSB0aGUgcG9ydG51bWJlciAqLworCQkJaWYgKHEpeworCQkJ
CSpxID0gJ1wwJzsKKwkJCQl2YWxpZHBvcnQgPSBhdG9pKHErMSk7CisJCQl9CisJCQltYXRj
aCA9IChob3N0bWF0Y2goZGVzdCxyZW1fc2VydmVyKSAmJiBwb3J0PT12YWxpZHBvcnQpOwor
CisJCQlpZiAocSkgKnEgPSAnOic7CS8qIHB1dCB0aGUgY29sb24gYmFjayAqLworCisJCQlp
ZiAobWF0Y2gpeworCQkJCWlmICgqKnhwPT0nIScpCisJCQkJCWdvdG8gZGVuaWVkOworCQkJ
CWVsc2UKIAkJCQkJYnJlYWs7CiAJCQl9CiAJCX0K
--------------AD0BCE094F1223F499D5B134--


From owner-fwtk-users@ex.tis.com Thu Feb 22 10:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA00413
	Thu, 22 Feb 2001 10:47:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA04663;
	Thu, 22 Feb 2001 07:50:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Feb 2001 06:45:33 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA27197
	for fwtk-users-outgoing; Thu, 22 Feb 2001 06:45:26 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A94DFB4.27254297@peaktime.be>
Date: Thu, 22 Feb 2001 10:45:24 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: Re: plug-gw and samba
References: <91A5926EFF44D3118B1200104B7276EB654F3C@hart-exchange.hartwellcorp.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1545

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

"Michael St. Laurent" wrote:
 > 
 > Part of the problem is that netbios-ns is a UDP service not TCP.  Plug-gw
 > will only work for TCP services.  You must use another program such as
 > Udprelay for UDP services.
 > 

Quite right, I confused NS and SSN! As a matter of fact, the plug for
netbios-ns was actually useless in the OP's config as well. Fortunately,
one does not *need* netbios-ns to connect to a *known* samba drive, only
to "browse network neighborhood". Correction for my proposed config
follows:

On the relayer, say 1.2.3.1, which is not itself a 'true' Samba
server, run plug-gw like this:

in /etc/services: netbios-alt-ssn 9139

in netperm-table:
plug-gw: port netbios-ssn 1.2.3.* -plug-to firewall -port
netbios-alt-ssn

in rc.local

plug-gw -daemon 139 netbios-ssn

On the firewall:

in /etc/services: netbios-alt-ssn 9139

in netperm-table:

plug-gw: port netbios-alt-ssn 1.2.3.1 -plug-to server2 -port netbios-ssn
plug-gw: port netbios-ssn 1.2.3.* -plug-to server1 -port netbios-ssn

in rc.local

plug-gw -daemon 139 netbios-ssn
plug-gw -daemon 9139 netbios-alt-ssn

That should take care of the NETBIOS-SSN service. For NETBIOS-NS, as you
said, udprelay will be needed, even for 1 server. For two, I think the
same relaying strategy might be required.

Comments?

-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Thu Feb 22 14:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA01439
	Thu, 22 Feb 2001 14:54:17 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA06648;
	Thu, 22 Feb 2001 11:56:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Feb 2001 10:34:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA26294
	for fwtk-users-outgoing; Thu, 22 Feb 2001 10:34:18 -0800 (PST)
Date: Thu, 22 Feb 2001 10:14:16 -0800 (PST)
From: David Lang <dlang@diginsite.com>
To: Kees van Veen <cvn@interchain.nl>
cc: <fwtk-users@lists.nai.com>
Subject: Re: Telnet (HOLE) through http-gw (!) with CONNECT ???
In-Reply-To: <3A94F9D8.683DB90C@interchain.nl>
Message-ID: <Pine.LNX.4.31.0102221011070.10876-101000@dlang.diginsite.com>
MIME-Version: 1.0
Content-ID: <Pine.LNX.4.31.0102221011071.10876@dlang.diginsite.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: MULTIPART/Mixed; boundary=------------7F4426E0AF4E0141C79D72E2
Content-Length: 4831

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.
  Send mail to mime@docserver.cac.washington.edu for more info.

--------------7F4426E0AF4E0141C79D72E2
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-ID: <Pine.LNX.4.31.0102221011072.10876@dlang.diginsite.com>

the problem is that it's not a valid assumption that all webservers in the
world will run on port 80.

for that matter the usual use of connect is to port 443 (for SSL traffic)

almost every firewall out there has this vunerability. some try to address
it by outlawing connections to 'known ports' like 23, but the only one
that I think really addresses the issue is the Raptor 6.5 proxy that
watches what happens after the connect and if it's not a SSL negotiation
(or I think they allow another connect, they should anyway) the proxy
closes the connection.

I haven't taken the time to figure out how to identify the start of SSL or
I would be working on a patch for http-gw to add that capability.

David Lang

 On Thu, 22 Feb 2001, Kees van Veen wrote:

> Date: Thu, 22 Feb 2001 12:36:56 +0100
> From: Kees van Veen <cvn@interchain.nl>
> To: fwtk-users@lists.nai.com
> Subject: Telnet (HOLE) through http-gw (!) with CONNECT ???
>
> I'm running the fwtk for quite a while now and was looking into
> tunneling through http proxies when I discovered that my firewall wasn't
> as safe as I thought.
>
> I have users on the Intranet connected to the outside through http-gw.
> I allow people from the outside to connect to one internal destination
> (called xxxx) with the netperm-table line:
>
> http-gw:  ... all internal hosts ...
> http-gw:  permit-hosts * -dest xxxx -httpd xxxx -java -javascript -deny
> exec
>
> Now on machine 'xxxx' I also have telnetd listening on port 23 and to MY
> SURPRISE I could FROM THE OUTSIDE connect to http-gw with:
>
> 	telnet firewall 80
>
> and then type
>
> 	CONNECT xxxx:23 HTTP/1.0
>
> and get the login prompt (!?!).
>
> Seems like the -dest flag in the http-gw nerperm-table options only
> checks on destination host/address, but not on the port. My naive
> assumption was that http-gw would only forward port 80.
>
> I don't know of other ways to protect this, so I wrote a patch to
> http-gw that would check on the portnumber as well, if I would have a
> netperm-table line like:
>
> http-gw:  permit-hosts * -dest xxxx:80 -httpd xxxx -java -javascript
> -deny exec
>
> so the hosts after the -dest flag may be specified with portnumber which
> would be checked if specified (without it only the hostname is checked).
>
> If anyone knows another way of protecting for this with http-gw
> (plug-gw), I would be interested in it. Also are there other protocols
> like ftp, etc. that allow for such a tunnel ?
>
> I've included the patch for 'hmain.c' of http-gw.
>
> Regards,
> Kees
>
>


--------------7F4426E0AF4E0141C79D72E2
Content-Type: APPLICATION/OCTET-STREAM; name="http-gw-CONNECT.patch"
Content-Transfer-Encoding: BASE64
Content-ID: <Pine.LNX.4.31.0102221011073.10876@dlang.diginsite.com>
Content-Description: 
Content-Disposition: attachment; filename="http-gw-CONNECT.patch"

LS0tIG9sZC9obWFpbi5jCVdlZCBGZWIgMjEgMTU6MTM6NDIgMjAwMQorKysgaG1haW4uYwlUaHUg
RmViIDIyIDEyOjM1OjU3IDIwMDEKQEAgLTEyMDEsMjIgKzEyMDEsMzcgQEAKIGludCBjaGVja19k
ZXN0KHNvY2tmZCkKIGludCBzb2NrZmQ7CiB7CWNoYXIgKip4cDsKLQlpbnQgeDsKKwlpbnQgeCwg
cG9ydDsKIAljaGFyICpwOwogCiAJaWYoIHZhbGlkZXN0cyAhPSBOVUxMKXsKLQkJcCA9IHJlbV9z
ZXJ2ZXI7Ci0JCXdoaWxlKCpwICYmICpwIT0gJzonKXArKzsKLQkJaWYoICpwID09ICc6Jyl7CisJ
CXBvcnQgPSByZW1fcG9ydDsKKwkJcCA9IHN0cmNocihyZW1fc2VydmVyLCAnOicpOwkvKiBUcnkg
dGhlIHBvcnRudW1iZXIgKi8KKwkJaWYgKHApewogCQkJKnAgPSAnXDAnOwotCQl9ZWxzZQotCQkJ
cCA9IE5VTEw7CisJCQlwb3J0ID0gYXRvaShwKzEpOworCQl9CiAKIAkJZm9yKHhwID0gdmFsaWRl
c3RzOyAqeHAgIT0gTlVMTDsgeHArKyl7Ci0JCQlpZiggKip4cCA9PSAnIScgJiYgaG9zdG1hdGNo
KCp4cCsxLCByZW1fc2VydmVyKSl7Ci0JCQkJZ290byBkZW5pZWQ7Ci0JCQl9ZWxzZXsKLQkJCQlp
Zihob3N0bWF0Y2goKnhwLCByZW1fc2VydmVyKSkKKwkJCWludCBtYXRjaCwgdmFsaWRwb3J0Owor
CQkJY2hhciAqZGVzdCwgKnE7CisKKwkJCS8qIFNwbGl0IHRoZSB2YWxpZCBkZXN0aW5hdGlvbnMg
YW5kIHBvcnRudW1iZXIgKi8KKwkJCWRlc3QgPSAoKip4cD09JyEnID8gKnhwKzEgOiAqeHApOwor
CQkJdmFsaWRwb3J0ID0gcmVtX3BvcnQ7CisJCQlxID0gc3RyY2hyKCp4cCwgJzonKTsJLyogVHJ5
IHRoZSBwb3J0bnVtYmVyICovCisJCQlpZiAocSl7CisJCQkJKnEgPSAnXDAnOworCQkJCXZhbGlk
cG9ydCA9IGF0b2kocSsxKTsKKwkJCX0KKwkJCW1hdGNoID0gKGhvc3RtYXRjaChkZXN0LHJlbV9z
ZXJ2ZXIpICYmIHBvcnQ9PXZhbGlkcG9ydCk7CisKKwkJCWlmIChxKSAqcSA9ICc6JzsJLyogcHV0
IHRoZSBjb2xvbiBiYWNrICovCisKKwkJCWlmIChtYXRjaCl7CisJCQkJaWYgKCoqeHA9PSchJykK
KwkJCQkJZ290byBkZW5pZWQ7CisJCQkJZWxzZQogCQkJCQlicmVhazsKIAkJCX0KIAkJfQo=

--------------7F4426E0AF4E0141C79D72E2--

From owner-fwtk-users@ex.tis.com Thu Feb 22 21:20 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA03114
	Thu, 22 Feb 2001 21:20:24 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA21976;
	Thu, 22 Feb 2001 18:22:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Feb 2001 17:17:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA17810
	for fwtk-users-outgoing; Thu, 22 Feb 2001 17:17:17 -0800 (PST)
Message-Id: <5.0.2.1.0.20010222200537.01d506c0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 22 Feb 2001 20:08:49 -0500
To: Kees van Veen <cvn@interchain.nl>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Telnet (HOLE) through http-gw (!) with CONNECT ???
In-Reply-To: <3A94F9D8.683DB90C@interchain.nl>
References: <D9B1937D4099D411B0670090277C004F03D15A@ntexch02s.scs.dra.hmg.gb>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 723

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 12:36 PM 2/22/01 +0100, Kees van Veen wrote:
>I'm running the fwtk for quite a while now and was looking into
>tunneling through http proxies when I discovered that my firewall wasn't
>as safe as I thought.

This is a FAQ. I've said this hundreds of times.
DO NOT use http-gw to front-end your web server.
Now you know why.

Use a plug-gw to allow outside access to your web server, or eviscerate the 
CONNECT code and use http-gw's "forward" directive. Plug-gw is a better 
choice - it's going to be more efficient and can't be exploited to connect 
where you don't intend.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Feb 23 05:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA04359
	Fri, 23 Feb 2001 05:08:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA08716;
	Fri, 23 Feb 2001 02:10:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 01:06:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA07029
	for fwtk-users-outgoing; Fri, 23 Feb 2001 01:06:19 -0800 (PST)
Message-ID: <3A962764.6C059003@interchain.nl>
Date: Fri, 23 Feb 2001 10:03:32 +0100
From: Kees van Veen <cvn@interchain.nl>
Organization: Interchain International
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.14-5.0 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: fwtk-users@lists.nai.com
Subject: Re: Telnet (HOLE) through http-gw (!) with CONNECT ???
References: <D9B1937D4099D411B0670090277C004F03D15A@ntexch02s.scs.dra.hmg.gb> <5.0.2.1.0.20010222200537.01d506c0@mail.itm-inst.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from base64 to 8bit by relay2.nai.com id BAA07023
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 313

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick Murphy wrote:

> This is a FAQ. I've said this hundreds of times.
> DO NOT use http-gw to front-end your web server.
> Now you know why.

I'll look before I post next time.

Kees

From owner-fwtk-users@ex.tis.com Fri Feb 23 09:26 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA05215
	Fri, 23 Feb 2001 09:26:06 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18064;
	Fri, 23 Feb 2001 06:28:09 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 05:21:00 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA13666
	for fwtk-users-outgoing; Fri, 23 Feb 2001 05:20:39 -0800 (PST)
Message-ID: <3A95C74C.A07C626@bridgepoint.com.au>
Date: Fri, 23 Feb 2001 12:13:32 +1000
From: Ken Blinco <ken_blinco@bridgepoint.com.au>
Organization: http://www.bridgepoint.com.au
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.2.16-22 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: help with transparency needed.
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 990

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

O/S Linux redhat 6.2 (kernel  2.2.14)
FWTK v2.1

I'm getting nowhere fast trying to get transparency working with my fwtk
proxies (need it for http-gw, tn-gw and ftp-gw)
I have applied the transparency patch and have configured my ipchains
rules like this: (I have http-gw running as a daemon on port 8080)

ipchains -A input -p tcp -s $INT_NET -d $ANYWHERE 80 -j REDIRECT 8080

I have my default gateway on an internal host set to the firewall to
test this.
The redirection seems to work as the http-gw logs a permitted
connnection in /var/log/messages.  However, the proxy doesn't try to
forward to connection on to the remote server, but instead just closes
the connection after my browser issues the GET command.

Not alot of detail here, but anyone got any ideas?
Could anyone send me an example config (both netperm-table and ipchains
rules)?


Ken


From owner-fwtk-users@ex.tis.com Fri Feb 23 09:49 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA05336
	Fri, 23 Feb 2001 09:49:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA20021;
	Fri, 23 Feb 2001 06:51:10 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 05:51:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA15153
	for fwtk-users-outgoing; Fri, 23 Feb 2001 05:50:52 -0800 (PST)
Message-Id: <5.0.2.1.0.20010223073119.01d338d0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Fri, 23 Feb 2001 08:38:11 -0500
To: Kees van Veen <cvn@interchain.nl>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Telnet (HOLE) through http-gw (!) with CONNECT ???
Cc: fwtk-users@lists.nai.com
In-Reply-To: <3A962764.6C059003@interchain.nl>
References: <D9B1937D4099D411B0670090277C004F03D15A@ntexch02s.scs.dra.hmg.gb>
 <5.0.2.1.0.20010222200537.01d506c0@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 828

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 10:03 AM 2/23/01 +0100, Kees van Veen wrote:
>Rick Murphy wrote:
>
> > This is a FAQ. I've said this hundreds of times.
> > DO NOT use http-gw to front-end your web server.
> > Now you know why.
>
>I'll look before I post next time.

I'd like to figure out a way to make this more obvious; http-gw has many 
different ways it can be exploited if it's used inbound ("CONNECT" is just 
one of them.)
Using a plug-gw to do this is the right thing to do because it allows you 
to limit the target to just one IP address and just one port. Of course, 
neither http-gw or plug-gw protect you from someone exploiting a 
vulnerability on the web server that uses port 80 for the exploit.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Feb 23 12:31 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA06056
	Fri, 23 Feb 2001 12:31:06 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA07697;
	Fri, 23 Feb 2001 09:33:09 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 08:28:21 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA00095
	for fwtk-users-outgoing; Fri, 23 Feb 2001 08:28:04 -0800 (PST)
Mime-Version: 1.0
X-Sender: jdonovan@mail.beth.k12.pa.us
Message-Id: <p05001903b6bc3e53943c@[204.170.128.50]>
Date: Fri, 23 Feb 2001 11:23:50 -0500
To: fwtk-users <fwtk-users@tis.com>
From: Jeff Donovan <jdonovan@beth.k12.pa.us>
Subject: New Install question
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Content-Length: 806

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Greetings

I am Installing fwtk on a BSDi 4.2 system. My question is concerning 
IP forwarding.

Currently the system I have running is forwarding packets between the 
2 interfaces( ef0 & we0 ). I read that ip forwarding should be turned 
OFF.

does FWTK take care of forwarding the packets or allowing packets to 
pass through to each interface? if yes what is the process that 
handles that?

TIA

--jeff
-- 
------------------------------------------------------------------------
Jeff Donovan                    Network Analyst
Bethlehem Area School District  Information & Communication Technologies
Bethlehem, PA  18020            (610) 807-5571  jdonovan@beth.k12.pa.us

From owner-fwtk-users@ex.tis.com Fri Feb 23 13:06 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA06231
	Fri, 23 Feb 2001 13:06:33 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA11610;
	Fri, 23 Feb 2001 10:08:49 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 09:07:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA04872
	for fwtk-users-outgoing; Fri, 23 Feb 2001 09:07:48 -0800 (PST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@lists.nai.com>
Subject: plug-gw to access internal web server
Date: Thu, 22 Feb 2001 20:34:20 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFIECGPAAA.luba@assist.com.gt>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 535

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

I know you can use plug-gw to access an internal web
server from the internet...

How can you implement that access to the internal web server,
but in the case you have multiple domains, which are supposed
to point to the same web server, and maybe different servers?

Do you need to add several IP addresses to the external interface
of the firewall?

Luis Fernando Barrera 
luba@assist.com.gt



From owner-fwtk-users@ex.tis.com Fri Feb 23 13:55 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA06528
	Fri, 23 Feb 2001 13:55:04 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA16974;
	Fri, 23 Feb 2001 10:57:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 09:53:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA09894
	for fwtk-users-outgoing; Fri, 23 Feb 2001 09:53:25 -0800 (PST)
Date: Fri, 23 Feb 2001 12:52:11 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Jeff Donovan <jdonovan@beth.k12.pa.us>
cc: fwtk-users <fwtk-users@tis.com>
Subject: Re: New Install question
In-Reply-To: <p05001903b6bc3e53943c@[204.170.128.50]>
Message-ID: <Pine.GSO.4.10.10102231250020.6923-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1434

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jeff,

The tool kit is a application proxy based firewall.  Individual session
packets are accepted by the proxy - validated - then retransmitted to the
remote computer.  Since it is application proxy based - users must make
connections to the firewall based proxies - authenticate to them - then
request connection to the remote system.  Direct access to the remote
system is not possible.

ted keller


On Fri, 23 Feb 2001, Jeff Donovan wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Greetings
> 
> I am Installing fwtk on a BSDi 4.2 system. My question is concerning 
> IP forwarding.
> 
> Currently the system I have running is forwarding packets between the 
> 2 interfaces( ef0 & we0 ). I read that ip forwarding should be turned 
> OFF.
> 
> does FWTK take care of forwarding the packets or allowing packets to 
> pass through to each interface? if yes what is the process that 
> handles that?
> 
> TIA
> 
> --jeff
> -- 
> ------------------------------------------------------------------------
> Jeff Donovan                    Network Analyst
> Bethlehem Area School District  Information & Communication Technologies
> Bethlehem, PA  18020            (610) 807-5571  jdonovan@beth.k12.pa.us
> 


From owner-fwtk-users@ex.tis.com Fri Feb 23 14:37 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA06792
	Fri, 23 Feb 2001 14:37:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA21931;
	Fri, 23 Feb 2001 11:39:55 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 10:37:30 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA14727
	for fwtk-users-outgoing; Fri, 23 Feb 2001 10:37:09 -0800 (PST)
Message-Id: <5.0.2.1.0.20010223132533.01d2d740@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Fri, 23 Feb 2001 13:26:36 -0500
To: Jeff Donovan <jdonovan@beth.k12.pa.us>, fwtk-users <fwtk-users@tis.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: New Install question
In-Reply-To: <p05001903b6bc3e53943c@[204.170.128.50]>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 595

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:23 AM 2/23/01 -0500, Jeff Donovan wrote:
>does FWTK take care of forwarding the packets or allowing packets to pass 
>through to each interface? if yes what is the process that handles that?

You disable IP forwarding. For any traffic that you want to let through the 
firewall, you use a proxy that determines whether or not to permit the 
traffic. If you enable forwarding, the proxies will never see the traffic 
and you'll be unprotected.
         -Rick



From owner-fwtk-users@ex.tis.com Fri Feb 23 14:37 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA06794
	Fri, 23 Feb 2001 14:37:47 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA21950;
	Fri, 23 Feb 2001 11:40:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 10:37:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA14726
	for fwtk-users-outgoing; Fri, 23 Feb 2001 10:37:09 -0800 (PST)
Message-Id: <5.0.2.1.0.20010223132132.01d50720@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Fri, 23 Feb 2001 13:25:30 -0500
To: "Luis Fernando Barrera" <luba@assist.com.gt>, <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: plug-gw to access internal web server
In-Reply-To: <NABBIDJPNCAGKGOFGHBFIECGPAAA.luba@assist.com.gt>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1189

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 08:34 PM 2/22/01 -0600, Luis Fernando Barrera wrote:

>How can you implement that access to the internal web server,
>but in the case you have multiple domains, which are supposed
>to point to the same web server, and maybe different servers?

That depends on what web server you're using, and how it supports multiple 
domain names.
For example, Apache can support multiple virtual hosts all pointing to the 
same IP address - it distinguishes what virtual server to use by using the 
"Host:" header in the HTTP request. In this case, you just have one plug 
and let the web server distinguish.
Microsoft IIS, however, requires that you use different IP addresses or 
different port numbers to distinguish between virtual hosts. In that case, 
you run multiple plug-gw's on the outside that plug to the virtual targets 
on the inside. The plug-gw's on the outside can either bind to different IP 
addresses (assuming you've got the ipbind patch) or different port numbers 
on the outside, each of which point to different internal servers.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Feb 23 15:18 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA06978
	Fri, 23 Feb 2001 15:18:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA26603;
	Fri, 23 Feb 2001 12:20:28 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 11:08:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA18257
	for fwtk-users-outgoing; Fri, 23 Feb 2001 11:08:40 -0800 (PST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: <fwtk-users@tis.com>
Cc: <jdonovan@beth.k12.pa.us>
Subject: RE: New Install question
Date: Thu, 22 Feb 2001 13:09:34 -0600
Message-ID: <NABBIDJPNCAGKGOFGHBFEECJPAAA.luba@assist.com.gt>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
In-Reply-To: <p05001903b6bc3e53943c@[204.170.128.50]>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1083

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


>
> I am Installing fwtk on a BSDi 4.2 system. My question is concerning
> IP forwarding.
>
> Currently the system I have running is forwarding packets between the
> 2 interfaces( ef0 & we0 ). I read that ip forwarding should be turned
> OFF.

Yes, You must turn IP forwarding off, since FWTK is an application
level firewall, so it does not block packets  at the level of IP.

>
> does FWTK take care of forwarding the packets or allowing packets to
> pass through to each interface? if yes what is the process that
> handles that?

In case you want to implement a packet level firewall, you must use
IPChains,
but it's more secure to use FWTK.

Luis


>
> TIA
>
> --jeff
> --
> ------------------------------------------------------------------------
> Jeff Donovan                    Network Analyst
> Bethlehem Area School District  Information & Communication Technologies
> Bethlehem, PA  18020            (610) 807-5571  jdonovan@beth.k12.pa.us


From owner-fwtk-users@ex.tis.com Fri Feb 23 16:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA07375
	Fri, 23 Feb 2001 16:40:28 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA06341;
	Fri, 23 Feb 2001 13:42:49 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 12:39:25 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA28949
	for fwtk-users-outgoing; Fri, 23 Feb 2001 12:39:04 -0800 (PST)
Date: Fri, 23 Feb 2001 15:38:26 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Jeff Donovan <jdonovan@beth.k12.pa.us>
Cc: fwtk-users <fwtk-users@tis.com>
Subject: Re: New Install question
Message-Id: <20010223153826.K16770@washington.cospo.osis.gov>
Mail-Followup-To: Jeff Donovan <jdonovan@beth.k12.pa.us>,
	fwtk-users <fwtk-users@tis.com>
References: <p05001903b6bc3e53943c@[204.170.128.50]>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <p05001903b6bc3e53943c@[204.170.128.50]>; from jdonovan@beth.k12.pa.us on Fri, Feb 23, 2001 at 11:23:50AM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1307

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Feb 23, 2001 at 11:23:50AM -0500, Jeff Donovan wrote:
> I am Installing fwtk on a BSDi 4.2 system. My question is concerning 
> IP forwarding.
> 
> Currently the system I have running is forwarding packets between the 
> 2 interfaces( ef0 & we0 ). I read that ip forwarding should be turned 
> OFF.
> 
> does FWTK take care of forwarding the packets or allowing packets to 
> pass through to each interface? if yes what is the process that 
> handles that?

Absolutely not.  IP forwarding is not secure, and is strongly
discouraged.  [Unfortunately, it's the only way some things will work,
especially UDP services and what Microsoft laughably calls protocols.]

The FWTK is exclusively a set of TCP-service proxies.  Each proxy STOPS
the IP flow for its service.  It initiates a new IP flow with the
resource that the internal user wants to use, and mediates the
transaction.  At no time does any IP flow from inside to outside or
back again.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Feb 23 17:47 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA07598
	Fri, 23 Feb 2001 17:47:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA15004;
	Fri, 23 Feb 2001 14:49:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Feb 2001 13:44:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA06491
	for fwtk-users-outgoing; Fri, 23 Feb 2001 13:44:08 -0800 (PST)
Message-ID: <C2E1EDCE28D9D211844F0008C7CF088E05650A26@blue-exch.amgen.com>
From: "South, Harold" <hsouth@amgen.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Web server on inner side of DMZ
Date: Fri, 23 Feb 2001 13:42:48 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 314

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I'm protecting a small lan with FWTK. I do have a web server that I'd like
to give access to external users. Is plug-gw the best
way to provide this access ?

Thanks in advance.



From owner-fwtk-users@ex.tis.com Mon Feb 26 09:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA15037
	Mon, 26 Feb 2001 09:12:09 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA01392;
	Mon, 26 Feb 2001 06:14:29 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 04:52:23 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA24561
	for fwtk-users-outgoing; Mon, 26 Feb 2001 04:51:50 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A97C3D8.C802B7FF@peaktime.be>
Date: Sat, 24 Feb 2001 15:23:20 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: Re: New Install question
References: <NABBIDJPNCAGKGOFGHBFEECJPAAA.luba@assist.com.gt>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1302

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Luis Fernando Barrera wrote:
 > 
 > > I am Installing fwtk on a BSDi 4.2 system. My question is concerning
 > > IP forwarding.
 > >
 > > Currently the system I have running is forwarding packets between the
 > > 2 interfaces( ef0 & we0 ). I read that ip forwarding should be turned
 > > OFF.
 > 
 > Yes, You must turn IP forwarding off, since FWTK is an application
 > level firewall, so it does not block packets  at the level of IP.
 > 
 > >
 > > does FWTK take care of forwarding the packets or allowing packets to
 > > pass through to each interface? if yes what is the process that
 > > handles that?
 > 
 > In case you want to implement a packet level firewall, you must use
 > IPChains,
 > but it's more secure to use FWTK.
 > 
 > Luis
 > 
In another recent thread it was pointed out that to pass HTTP from the
Internet to a web server, one should use plug-gw, *not* http-gw. Since
plug-gw is wholly unaware of stream contents, I don't think it would be
any more secure than ipchains, and ipchains is going to be a lot faster!

Greetings.
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Mon Feb 26 09:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA15035
	Mon, 26 Feb 2001 09:12:06 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA01384;
	Mon, 26 Feb 2001 06:14:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 05:00:15 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA25050
	for fwtk-users-outgoing; Mon, 26 Feb 2001 04:59:49 -0800 (PST)
Reply-To: <rene@mail-me.com>
From: =?iso-8859-1?Q?Ren=E9_Antonio_Araos_Carvacho?= <rene@manquehue.net>
To: <fwtk-support@tis.com>, <fwtk-users@tis.com>
Subject: Patch for transparent ftp proxy
Date: Sun, 25 Feb 2001 22:53:38 -0300
Message-ID: <NDBBJIDDCKDDFPBEGHEHMEHKCBAA.rene@manquehue.net>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2776.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0000_01C09F7D.CAA7D920"
Content-Length: 5701

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_0000_01C09F7D.CAA7D920
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

Hi

     This is a patch useful for a ftp proxy who is behind a firewall, this
makes connections like ftp, (example, ftp = 21 then ftp-data = 20, ftp =
1021, ftp-data=1020).

     Please send me comments, if you find a bug in this or not   :-)

greetings

René Araos

##begin diff file
diff -u --recursive --new-file fwtk/ftp-gw/ftp-gw.c fwtkrene/ftp-gw/ftp-gw.c

--- fwtk/ftp-gw/ftp-gw.c Thu Feb 5 21:05:43 1998

+++ fwtkrene/ftp-gw/ftp-gw.c Fri Feb 23 18:47:44 2001

@@ -66,6 +66,7 @@

static int outgoing = -1; /* fd for outgoing PORT data */

static int incoming = -1; /* fd for outgoing PORT data */

static struct sockaddr_in clntport;

+static struct sockaddr_in original;

static char **saveresp = (char **)0;

static int saveresps = 0;

static char riaddr[512];

@@ -173,6 +174,7 @@

char xuf[1024];

char huf[512];

char *passuser = (char *)0; /* passed user as av */

+ int addrlen;


#ifndef LOG_DAEMON

openlog("ftp-gw",LOG_PID);

@@ -227,6 +229,19 @@

exit(1);

}


+/* mod */

+

+ addrlen = sizeof(addrlen);

+ if (getsockname(0, (struct sockaddr *)&original, &addrlen) < 0) {

+ syslog(LOG_ERR, "getsockname (%s): %m",av[0]);

+ exit(1);

+ }

+ original.sin_port = htons(ntohs(original.sin_port) - 1);

+/*

+ original.sin_port = htons(0x14);

+*/

+

+/* fin mod */


if((cf = cfg_get("groupid",confp)) != (Cfg *)0) {


@@ -415,6 +430,7 @@

if(incoming != -1 && FD_ISSET(incoming,&rdy)) {

if(copyin())

break;

+ close(incoming);

}

}

leave:

@@ -1035,7 +1051,6 @@

if(porttoaddr(av[1],&clntport))

return(sayn(0,nadr,sizeof(nadr)-1));


-

/* paranoid: check that we are really PORTing to the client */

x = sizeof(r);

if(getpeername(0,(struct sockaddr *)&r,&x) < 0)

@@ -1313,6 +1328,8 @@

/* call back to the client on the address they gave as PORT */

callback()

{

+ int data, tries;

+ int on=1;

/* if we haven't gotten a valid PORT scrub the connection */

if((outgoing = accept(boundport,(struct sockaddr *)0,(int *)0)) < 0)

goto bomb;

@@ -1324,6 +1341,21 @@


if((incoming = socket(AF_INET,SOCK_STREAM,0)) < 0)

goto bomb;

+/*inicio mod*/

+ if (setsockopt(incoming, SOL_SOCKET, SO_REUSEADDR,

+ (char *) &on, sizeof(on)) < 0)

+ goto bomb;

+ for (tries = 1; ; tries++) {

+ if (bind(incoming, (struct sockaddr *)&original,

+ sizeof(original)) >= 0)

+ break;

+ if (errno != EADDRINUSE || tries > 10)

+ goto bomb;

+ sleep(tries);

+ }

+

+/*fin mod*/

+


if(connect(incoming,(struct sockaddr *)&clntport,sizeof(clntport)) < 0)

goto bomb;

##end diff file


------=_NextPart_000_0000_01C09F7D.CAA7D920
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
Hi
  
    =20 This is a patch useful for a ftp proxy who is behind a firewall, this = makes=20 connections like ftp, (example, ftp =3D 21 then ftp-data =3D 20, ftp =3D = 1021,=20 ftp-data=3D1020).
  
     Please send me comments, if you find a bug in this or = not  =20 :-)
  
greetings
  
Ren=E9 = Araos
  
##begin diff=20 file 

diff -u --recursive --new-file fwtk/ftp-gw/ftp-gw.c=20 fwtkrene/ftp-gw/ftp-gw.c

--- fwtk/ftp-gw/ftp-gw.c Thu Feb 5 21:05:43 = 1998

+++ fwtkrene/ftp-gw/ftp-gw.c Fri Feb 23 18:47:44 = 2001

@@ -66,6 +66,7 @@

static int outgoing =3D -1; /* fd for outgoing PORT = data=20 */

static int incoming =3D -1; /* fd for outgoing PORT = data=20 */

static struct sockaddr_in clntport;

+static struct sockaddr_in original;

static char **saveresp =3D (char **)0;

static int saveresps =3D 0;

static char riaddr[512];

@@ -173,6 +174,7 @@

char xuf[1024];

char huf[512];

char *passuser =3D (char *)0; /* passed user as av = */

+ int addrlen;

#ifndef LOG_DAEMON

openlog("ftp-gw",LOG_PID);

@@ -227,6 +229,19 @@

exit(1);

}

+/* mod */

+

+ addrlen =3D sizeof(addrlen);

+ if (getsockname(0, (struct sockaddr *)&original, = &addrlen) < 0) {

+ syslog(LOG_ERR, "getsockname (%s): = %m",av[0]);

+ exit(1);

+ }

+ original.sin_port =3D htons(ntohs(original.sin_port) = -=20 1);

+/*

+ original.sin_port =3D htons(0x14);

+*/

+

+/* fin mod */

if((cf =3D cfg_get("groupid",confp)) !=3D (Cfg *)0) = {

@@ -415,6 +430,7 @@

if(incoming !=3D -1 && = FD_ISSET(incoming,&rdy))=20 {

if(copyin())

break;

+ close(incoming);

}

}

leave:

@@ -1035,7 +1051,6 @@

if(porttoaddr(av[1],&clntport))

return(sayn(0,nadr,sizeof(nadr)-1));

-

/* paranoid: check that we are really PORTing to the = client=20 */

x =3D sizeof(r);

if(getpeername(0,(struct sockaddr *)&r,&x) = <=20 0)

@@ -1313,6 +1328,8 @@

/* call back to the client on the address they gave as = PORT=20 */

callback()

{

+ int data, tries;

+ int on=3D1;

/* if we haven't gotten a valid PORT scrub the = connection=20 */

if((outgoing =3D accept(boundport,(struct sockaddr = *)0,(int *)0))=20 < 0)

goto bomb;

@@ -1324,6 +1341,21 @@

if((incoming =3D socket(AF_INET,SOCK_STREAM,0)) < = 0)

goto bomb;

+/*inicio mod*/

+ if (setsockopt(incoming, SOL_SOCKET, = SO_REUSEADDR,

+ (char *) &on, sizeof(on)) < 0)

+ goto bomb;

+ for (tries =3D 1; ; tries++) {

+ if (bind(incoming, (struct sockaddr=20 *)&original,

+ sizeof(original)) >=3D 0)

+ break;

+ if (errno !=3D EADDRINUSE || tries > = 10)

+ goto bomb;

+ sleep(tries);

+ }

+

+/*fin mod*/

+

if(connect(incoming,(struct sockaddr=20 *)&clntport,sizeof(clntport)) < 0)

goto bomb;

##end = diff=20 file

------=_NextPart_000_0000_01C09F7D.CAA7D920--



From owner-fwtk-users@ex.tis.com Mon Feb 26 09:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA15038
	Mon, 26 Feb 2001 09:12:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA01396;
	Mon, 26 Feb 2001 06:14:29 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 04:52:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA24562
	for fwtk-users-outgoing; Mon, 26 Feb 2001 04:51:51 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A97C2C8.4BD3C28E@peaktime.be>
Date: Sat, 24 Feb 2001 15:18:48 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: [Re: Web server on inner side of DMZ]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
  boundary="------------014DE631E019BC463F4AF2DC"
Content-Length: 1752

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------014DE631E019BC463F4AF2DC
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit


-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10
--------------014DE631E019BC463F4AF2DC
Content-Type: message/rfc822
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

X-Mozilla-Status2: 00000000
Message-ID: <3A97C267.5622946E@peaktime.be>
Date: Sat, 24 Feb 2001 15:17:11 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: "South, Harold" <hsouth@amgen.com>
Subject: Re: Web server on inner side of DMZ
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A26@blue-exch.amgen.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

"South, Harold" wrote:
 > 
 > Hi,
 > 
 > I'm protecting a small lan with FWTK. I do have a web server that I'd like
 > to give access to external users. Is plug-gw the best
 > way to provide this access ?
 > 
 > Thanks in advance.

Yes, plug-gw for that. However, it is generally considered dangerous to
allow external access to the internal net (unless using secure
tunnelling e.g. with ssh). The web server should be on a separate,
dedicated net, usually called the 'demilitarized zone' or DMZ, and have
*no* access to the internal lan. NICs are so cheap nowadays, the extra
security is well worth the small investment.

Greetings.
-- 
Michel Bardiaux

--------------014DE631E019BC463F4AF2DC--



From owner-fwtk-users@ex.tis.com Mon Feb 26 09:12 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA15041
	Mon, 26 Feb 2001 09:12:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA01403;
	Mon, 26 Feb 2001 06:14:31 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 04:51:20 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA24501
	for fwtk-users-outgoing; Mon, 26 Feb 2001 04:50:43 -0800 (PST)
Message-ID: <3A97866D.B969EC88@algroup.co.uk>
Date: Sat, 24 Feb 2001 10:01:17 +0000
From: Adam Laurie <adam@algroup.co.uk>
X-Mailer: Mozilla 4.7 [en-gb] (Win98; I)
X-Accept-Language: en
MIME-Version: 1.0
To: "South, Harold" <hsouth@amgen.com>
CC: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Re: Web server on inner side of DMZ
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A26@blue-exch.amgen.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 963

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

"South, Harold" wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hi,
 > 
 > I'm protecting a small lan with FWTK. I do have a web server that I'd like
 > to give access to external users. Is plug-gw the best
 > way to provide this access ?

it's certainly one way, but whether it's the best depends on your
circumstances. it's a better idea than running http-gw that way round
anyway.

cheers,
Adam
--
Adam Laurie                   Tel: +44 (20) 8742 0755
A.L. Digital Ltd.             Fax: +44 (20) 8742 5995
Voysey House                  http://www.thebunker.net
Barley Mow Passage            http://www.aldigital.co.uk
London W4 4GB                 mailto:adam@algroup.co.uk
UNITED KINGDOM                PGP key on keyservers


From owner-fwtk-users@ex.tis.com Mon Feb 26 09:30 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA15101
	Mon, 26 Feb 2001 09:30:26 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA04001;
	Mon, 26 Feb 2001 06:32:41 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 05:32:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA27220
	for fwtk-users-outgoing; Mon, 26 Feb 2001 05:32:10 -0800 (PST)
 <20010223153826.K16770@washington.cospo.osis.gov>
Mime-Version: 1.0
X-Sender: jdonovan@mail.beth.k12.pa.us
Message-Id: <p05001900b6c008e1f48c@[204.170.128.50]>
In-Reply-To: <20010223153826.K16770@washington.cospo.osis.gov>
References: <p05001903b6bc3e53943c@[204.170.128.50]>
 <20010223153826.K16770@washington.cospo.osis.gov>
Date: Mon, 26 Feb 2001 08:27:09 -0500
To: fwtk-users <fwtk-users@tis.com>
From: Jeff Donovan <jdonovan@beth.k12.pa.us>
Subject: Re: New Install question(?x2)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Content-Length: 1469

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Greetings,
Ok, since I have to turn IP forwarding "off", how does the data get 
from port A to Port B without some type of forwarding mechanism?

here is what I am working with;

----ntwk A-----portA{ bsdi4.2 }portB----netwk B

This machine was using IP forwarding, and IPFW. I wanted to try FWTK 
as a firewall to either allow services or deny them.

Will FWTK work for what I want to do?

--jeff


>(snip)
>  >
>>  does FWTK take care of forwarding the packets or allowing packets to
>>  pass through to each interface? if yes what is the process that
>>  handles that?
>
>Absolutely not.  IP forwarding is not secure, and is strongly
>discouraged.  [Unfortunately, it's the only way some things will work,
>especially UDP services and what Microsoft laughably calls protocols.]
>
>The FWTK is exclusively a set of TCP-service proxies.  Each proxy STOPS
>the IP flow for its service.  It initiates a new IP flow with the
>resource that the internal user wants to use, and mediates the
>transaction.  At no time does any IP flow from inside to outside or
>back again.

-- 
------------------------------------------------------------------------
Jeff Donovan                    Network Analyst
Bethlehem Area School District  Information & Communication Technologies
Bethlehem, PA  18020            (610) 807-5571  jdonovan@beth.k12.pa.us

From owner-fwtk-users@ex.tis.com Mon Feb 26 10:06 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA15197
	Mon, 26 Feb 2001 10:06:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08956;
	Mon, 26 Feb 2001 07:08:41 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 06:04:17 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA00062
	for fwtk-users-outgoing; Mon, 26 Feb 2001 06:03:51 -0800 (PST)
Message-ID: <3A9A5EFD.E52B2C5A@sellbuysector.com>
Date: Mon, 26 Feb 2001 13:49:49 +0000
From: Masih Tavassoli <mtavasso@sellbuysector.com>
Organization: Sellbuy Sector
X-Mailer: Mozilla 4.6 [en-gb]C-CCK-MCD NetscapeOnline.co.uk  (Win98; I)
X-Accept-Language: en-GB,en
MIME-Version: 1.0
To: "South, Harold" <hsouth@amgen.com>
CC: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Re: Web server on inner side of DMZ
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A26@blue-exch.amgen.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 929

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Yes I think so.

We did the same thing a while ago, the only downside to it was that we were losing
the header information of all requests(all the requests were appearing to be
coming from the same host, fw) which is not good if you wanted to do any
statistics reporting.

We had to make a small modification to rewrite the headers so that the reporting
software(webtrend in this case) could tell were the requests came from.


Regards,
Masih

"South, Harold" wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Hi,
>
> I'm protecting a small lan with FWTK. I do have a web server that I'd like
> to give access to external users. Is plug-gw the best
> way to provide this access ?
>
> Thanks in advance.




From owner-fwtk-users@ex.tis.com Mon Feb 26 11:59 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA15727
	Mon, 26 Feb 2001 11:59:34 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA22771;
	Mon, 26 Feb 2001 09:01:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 07:56:53 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA14843
	for fwtk-users-outgoing; Mon, 26 Feb 2001 07:56:31 -0800 (PST)
From: ark@eltex.ru
Date: Mon, 26 Feb 2001 19:11:23 +0300
Message-Id: <200102261611.TAA00897@paranoid.alpha.int>
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: New Install question
To: mbardiaux@peaktime.be
Cc: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 817

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

Remember that there is http-in proxy designed for _inbound_ http.

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOpqAKqH/mIJW9LeBAQFikwP/bpoxMpDwvH1rEAw/fngbfuE8HeWo7bgg
8Au0nWPdp8Yx0NnitzVw6vtL/8o6Q87OZX76FL4Mm0FX3za1gPJvbJbjzaqMXRhJ
zdx7CDYnnoNiXnqzu42BA5w5STc+lkmfOOjQQjfBHuV/1yd9Nre0+sPYRelqQn6c
bMsFzy5q3yc=
=7zYt
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Mon Feb 26 14:11 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA16201
	Mon, 26 Feb 2001 14:11:04 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA08125;
	Mon, 26 Feb 2001 11:13:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 10:06:45 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA00396
	for fwtk-users-outgoing; Mon, 26 Feb 2001 10:06:24 -0800 (PST)
Date: Mon, 26 Feb 2001 13:05:40 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Jeff Donovan <jdonovan@beth.k12.pa.us>
Cc: fwtk-users <fwtk-users@tis.com>
Subject: Re: New Install question(?x2)
Message-Id: <20010226130540.K28055@washington.cospo.osis.gov>
Mail-Followup-To: Jeff Donovan <jdonovan@beth.k12.pa.us>,
	fwtk-users <fwtk-users@tis.com>
References: <p05001903b6bc3e53943c@[204.170.128.50]> <20010223153826.K16770@washington.cospo.osis.gov> <p05001900b6c008e1f48c@[204.170.128.50]>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <p05001900b6c008e1f48c@[204.170.128.50]>; from jdonovan@beth.k12.pa.us on Mon, Feb 26, 2001 at 08:27:09AM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2322

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, Feb 26, 2001 at 08:27:09AM -0500, Jeff Donovan wrote:
> Ok, since I have to turn IP forwarding "off", how does the data get 
> from port A to Port B without some type of forwarding mechanism?
> 
> here is what I am working with;
> 
> ----ntwk A-----portA{ bsdi4.2 }portB----netwk B
> 
> This machine was using IP forwarding, and IPFW. I wanted to try FWTK 
> as a firewall to either allow services or deny them.
> 
> Will FWTK work for what I want to do?

As most responders said,

> >The FWTK is exclusively a set of TCP-service proxies.  Each proxy STOPS
> >the IP flow for its service.  It initiates a new IP flow with the
> >resource that the internal user wants to use, and mediates the
> >transaction.  At no time does any IP flow from inside to outside or
> >back again.

Let's take Web for example.  Set up Navigator with a proxy of whatever
you call your FWTK machine, port 80, no-proxy list including your Web
server.  When you go to browse:

Local Web server:
	Navigator calls DNS to resolve Web server's name to IP address
	Navigator connects to Web server
	Navigator sends GET to Web server
	Navigator receives HTML back from Web server

External Web server:
	Navigator calls DNS to resolve Proxy's name to IP address
	Navigator connects to Proxy
	Navigator sends GET that includes remote Web server's name, to
		the Proxy server
	Proxy calls DNS to resolve Web server's name to IP address
	Proxy connects to external Web server
	Proxy sends GET to external Web server
	Proxy receives HTML back from external Web server
	Navigator receives HTML back from Proxy

It is important to note that the IP packet that travels between
external site and firewall proxy is NOT the same IP packet that travels
between the internal client and the firewall proxy.  Both connections
TERMINATE at the firewall proxy.  The DATA is taken out of one IP
stream and put into the other.  The external sites see the existence of
no machine but the single proxy server.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Tue Feb 27 00:49 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA17775
	Tue, 27 Feb 2001 00:49:53 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA26684;
	Mon, 26 Feb 2001 21:52:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Feb 2001 20:46:37 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA24291
	for fwtk-users-outgoing; Mon, 26 Feb 2001 20:46:20 -0800 (PST)
Date: Tue, 27 Feb 2001 12:49:25 +0800
From: chen dong <chd1998@netease.com>
X-Mailer: GMail SMTP Server  ---  100% Pure Java
Reply-To: chen dong <chd1998@netease.com>
X-Priority: 3 (Normal)
Message-ID: <701615461.20010227124925@netease.com>
To: fwtk-users@tis.com
Subject: question
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 393

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello fwtk-users,

  Could any one give me a detailed usage of udprelay? Examples of udprelay.conf,
  etc. .
  I have read the Readme of its package, but not so clear.
  Thanx in advance!

Best regards,
 chen                          mailto:chd1998@netease.com




From owner-fwtk-users@ex.tis.com Tue Feb 27 06:20 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA18744
	Tue, 27 Feb 2001 06:20:52 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA06359;
	Tue, 27 Feb 2001 03:23:14 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Feb 2001 02:21:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA04503
	for fwtk-users-outgoing; Tue, 27 Feb 2001 02:21:28 -0800 (PST)
Message-ID: <20010227102055.73898.qmail@web12405.mail.yahoo.com>
Date: Tue, 27 Feb 2001 02:20:55 -0800 (PST)
From: Zakharov Mikhail <zmey20000@yahoo.com>
Subject: plug-gw for unknown destination
To: fwtk-users@ex.tis.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 712

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello, fwtk-users!

I have troubles with plug-gw. I need to configure it
for unknown desthosts. How can I do it?

plug-gw: port port_nb src_host -plug-to dest_host
-port dest_port_nb

^^^^^^^^ This works for one, two destination hosts
with plug-gw rule for itch. 

Is it possible to configure plug-gw that way:

plug-gw: port port_nb src_host -plug-to * -port
dest_port_nb

What can i do to run this type of rule?

Best regards
Mikhail

__________________________________________________
Do You Yahoo!?
Get email at your own domain with Yahoo! Mail. 
http://personal.mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Tue Feb 27 11:51 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA19999
	Tue, 27 Feb 2001 11:51:09 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA26121;
	Tue, 27 Feb 2001 08:53:10 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Feb 2001 07:32:01 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA18895
	for fwtk-users-outgoing; Tue, 27 Feb 2001 07:31:44 -0800 (PST)
Date: Tue, 27 Feb 2001 10:29:00 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Zakharov Mikhail <zmey20000@yahoo.com>
cc: fwtk-users@ex.tis.com
Subject: Re: plug-gw for unknown destination
In-Reply-To: <20010227102055.73898.qmail@web12405.mail.yahoo.com>
Message-ID: <Pine.GSO.4.10.10102271027280.29762-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1214

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Zakharov,

plug-gw is a many to one proxy - not a one to many or a many to many.

If your application needs to connect to many hosts - you may want to look
at socksifying the application and using a socks daemon for that purpose.
See www.socks.nec.com.

ted keller


On Tue, 27 Feb 2001, Zakharov Mikhail wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello, fwtk-users!
> 
> I have troubles with plug-gw. I need to configure it
> for unknown desthosts. How can I do it?
> 
> plug-gw: port port_nb src_host -plug-to dest_host
> -port dest_port_nb
> 
> ^^^^^^^^ This works for one, two destination hosts
> with plug-gw rule for itch. 
> 
> Is it possible to configure plug-gw that way:
> 
> plug-gw: port port_nb src_host -plug-to * -port
> dest_port_nb
> 
> What can i do to run this type of rule?
> 
> Best regards
> Mikhail
> 
> __________________________________________________
> Do You Yahoo!?
> Get email at your own domain with Yahoo! Mail. 
> http://personal.mail.yahoo.com/
> 


From owner-fwtk-users@ex.tis.com Wed Feb 28 09:01 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA23667
	Wed, 28 Feb 2001 09:01:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA03701;
	Wed, 28 Feb 2001 06:03:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Feb 2001 04:53:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA00357
	for fwtk-users-outgoing; Wed, 28 Feb 2001 04:52:50 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A9CC76D.81DDBDEF@peaktime.be>
Date: Wed, 28 Feb 2001 10:39:57 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@ex.tis.com
Subject: Re: plug-gw for unknown destination
References: <Pine.GSO.4.10.10102271027280.29762-100000@ns1.bfg.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1656

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Ted Keller wrote:
 > 
 > Zakharov,
 > 
 > plug-gw is a many to one proxy - not a one to many or a many to many.
 > 
 > If your application needs to connect to many hosts - you may want to look
 > at socksifying the application and using a socks daemon for that purpose.
 > See www.socks.nec.com.
 > 
 > ted keller
 > 
Slight amendment: with the "-ssl" option, plug-gw *can* be used as a
one-to-many proxy *provided* the client application uses HTTP and
supports HTTP proxying. Web browsers do that, of course, but also wget,
apt (on Linux Debian), maybe others.

If the client does not so behave, it is relatively easy, starting from
an inetd or xinetd source, to write a relaying application translating
connections to known (I mean in a config file) ports, into connections
to outside host/port, using plug-gw on port 443, which you need anyway
for https.

As a matter of fact, it would be a good thing to have a way of
controlling "plug-gw -ssl": lists of allowed and forbidden destination
hosts/ports, and option to forbid non-ssl sessions. HTTPS support can
hardly be disabled, but once it's there, it is %&#@ easy for internal
users to install tunnels for protocols ranging from nuisance (napster)
through dangerous (IRC with some of these Wintel clients that actually
export every hard or network drive) to malicious (BackOrifice). Anyone
knows of such a patch, or working on one?

Greetings.
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Wed Feb 28 21:50 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA26255
	Wed, 28 Feb 2001 21:50:05 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA21895;
	Wed, 28 Feb 2001 18:52:22 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Feb 2001 17:31:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA16937
	for fwtk-users-outgoing; Wed, 28 Feb 2001 17:31:40 -0800 (PST)
Message-ID: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com>
From: "South, Harold" <hsouth@amgen.com>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: socks
Date: Wed, 28 Feb 2001 17:30:25 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 294

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I didn't see this in a FAQ so I'm asking here. Is there a socks "proxy" for
FWTK 2.X ?

I'm assuming this would be the best way to let the napster traffic out.

From owner-fwtk-users@ex.tis.com Wed Feb 28 23:31 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA26455
	Wed, 28 Feb 2001 23:31:00 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA28255;
	Wed, 28 Feb 2001 20:33:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Feb 2001 19:34:51 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA24459
	for fwtk-users-outgoing; Wed, 28 Feb 2001 19:34:30 -0800 (PST)
Date: Wed, 28 Feb 2001 22:33:01 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "South, Harold" <hsouth@amgen.com>
cc: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: socks
In-Reply-To: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com>
Message-ID: <Pine.GSO.4.10.10102282232210.5348-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 644

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Go to www.socks.nec.com.  A socks server is there.  Note - these are not
application proxies but circuit proxies.  No protocol checks are
performed.

tek


On Wed, 28 Feb 2001, South, Harold wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi,
> 
> I didn't see this in a FAQ so I'm asking here. Is there a socks "proxy" for
> FWTK 2.X ?
> 
> I'm assuming this would be the best way to let the napster traffic out.
> 


