From owner-fwtk-users@ex.tis.com Thu Mar  1 00:53 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA26714
	Thu, 1 Mar 2001 00:53:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA03153;
	Wed, 28 Feb 2001 21:55:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Feb 2001 20:54:51 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA29446
	for fwtk-users-outgoing; Wed, 28 Feb 2001 20:54:30 -0800 (PST)
Message-ID: <3A9DE447.B90C0186@dreamwvr.com>
Date: Wed, 28 Feb 2001 22:55:19 -0700
From: dreamwvr <dreamwvr@dreamwvr.com>
X-Mailer: Mozilla 4.72 [en] (X11; U; Linux 2.2.14-5.0 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Ted Keller <keller@bfg.com>
Cc: "South, Harold" <hsouth@amgen.com>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: socks
References: <Pine.GSO.4.10.10102282232210.5348-100000@ns1.bfg.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 180

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi,
   There is also 'dante'  both work well..

>


From owner-fwtk-users@ex.tis.com Thu Mar  1 10:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA28624
	Thu, 1 Mar 2001 10:48:04 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08668;
	Thu, 1 Mar 2001 07:50:06 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 06:41:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA29445
	for fwtk-users-outgoing; Thu, 1 Mar 2001 06:41:21 -0800 (PST)
Date: Thu, 1 Mar 2001 09:40:31 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Ted Keller <keller@bfg.com>
Cc: fwtk-users@ex.tis.com
Subject: Re: socks
Message-Id: <20010301094031.G24909@washington.cospo.osis.gov>
Mail-Followup-To: Ted Keller <keller@bfg.com>, fwtk-users@ex.tis.com
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com> <Pine.GSO.4.10.10102282232210.5348-100000@ns1.bfg.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <Pine.GSO.4.10.10102282232210.5348-100000@ns1.bfg.com>; from keller@bfg.com on Wed, Feb 28, 2001 at 10:33:01PM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 607

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, Feb 28, 2001 at 10:33:01PM -0500, Ted Keller wrote:
> Go to www.socks.nec.com.  A socks server is there.  Note - these are not
> application proxies but circuit proxies.  No protocol checks are
> performed.

Is that actually a circuit "proxy"?

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Mar  1 10:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA28627
	Thu, 1 Mar 2001 10:48:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08696;
	Thu, 1 Mar 2001 07:50:15 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 06:39:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA29215
	for fwtk-users-outgoing; Thu, 1 Mar 2001 06:39:20 -0800 (PST)
Date: Thu, 1 Mar 2001 09:38:33 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: "South, Harold" <hsouth@amgen.com>
Cc: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: socks
Message-Id: <20010301093833.F24909@washington.cospo.osis.gov>
Mail-Followup-To: "South, Harold" <hsouth@amgen.com>,
	"'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com>; from hsouth@amgen.com on Wed, Feb 28, 2001 at 05:30:25PM -0800
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1028

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, Feb 28, 2001 at 05:30:25PM -0800, South, Harold wrote:
...
> I didn't see this in a FAQ so I'm asking here. Is there a socks "proxy" for
> FWTK 2.X ?
> 
> I'm assuming this would be the best way to let the napster traffic out.

SOCKS is not TCP, so there can be no proxy.  If there is no mention of
SOCKS in the FAQ or the other parts of the Web site, then you should
look in the archives, because it has been discussed.  Running SOCKS in
parallel with the FWTK [assuming that your application has been
"socksified", whatever that means] decreases security; but if you have
a server, presumably you're going to run it in a DMZ outside your
regular network, anyway.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Mar  1 11:24 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA28722
	Thu, 1 Mar 2001 11:24:09 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA14753;
	Thu, 1 Mar 2001 08:26:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 07:25:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA04999
	for fwtk-users-outgoing; Thu, 1 Mar 2001 07:24:59 -0800 (PST)
Date: Thu, 1 Mar 2001 10:23:04 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Joseph S D Yao <jsdy@cospo.osis.gov>
cc: fwtk-users@ex.tis.com
Subject: Re: socks
In-Reply-To: <20010301094031.G24909@washington.cospo.osis.gov>
Message-ID: <Pine.GSO.4.10.10103011022180.16629-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 797

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Well it sure doesn't do much protocol checking.  Just verifies that it is
proper tcp or udp.  You call it...




tek


On Thu, 1 Mar 2001, Joseph S D Yao wrote:

> On Wed, Feb 28, 2001 at 10:33:01PM -0500, Ted Keller wrote:
> > Go to www.socks.nec.com.  A socks server is there.  Note - these are not
> > application proxies but circuit proxies.  No protocol checks are
> > performed.
> 
> Is that actually a circuit "proxy"?
> 
> -- 
> Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
> COSPO/OSIS Computer Support					EMT-B
> -----------------------------------------------------------------------
> This message is not an official statement of COSPO policies.
> 


From owner-fwtk-users@ex.tis.com Thu Mar  1 11:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA28756
	Thu, 1 Mar 2001 11:40:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA17198;
	Thu, 1 Mar 2001 08:42:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 07:41:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA07365
	for fwtk-users-outgoing; Thu, 1 Mar 2001 07:41:09 -0800 (PST)
Message-ID: <3A9E6E67.14D48F67@v-one.com>
Date: Thu, 01 Mar 2001 10:44:39 -0500
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Joseph S D Yao <jsdy@cospo.osis.gov>
CC: "South, Harold" <hsouth@amgen.com>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: socks on fwtk.org
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com> <20010301093833.F24909@washington.cospo.osis.gov>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 889

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Joseph S D Yao wrote:
> 
> > I didn't see this in a FAQ so I'm asking here. Is there a socks "proxy" for
> > FWTK 2.X ?
> >
> > I'm assuming this would be the best way to let the napster traffic out.
> 
> SOCKS is not TCP, so there can be no proxy.  If there is no mention of
> SOCKS in the FAQ or the other parts of the Web site, then you should
> look in the archives, because it has been discussed. 

Hmmm... on the Patches page...

3.20 Proxy for SOCKS4/SOCKS5
http://www.fwtk.org/fwtk/patches/patches.html#3.20
   /\    /\    /\    /\   /\    /\ 
(this one is different than NEC's proxy)

and SOCKS is mentioned in 3.6:
http://www.fwtk.org/fwtk/patches/patches.html#3.6

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Thu Mar  1 11:53 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA28797
	Thu, 1 Mar 2001 11:53:00 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA18943;
	Thu, 1 Mar 2001 08:55:00 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 07:51:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA08750
	for fwtk-users-outgoing; Thu, 1 Mar 2001 07:50:39 -0800 (PST)
Date: Thu, 1 Mar 2001 10:48:32 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Keith Young <kyoung@v-one.com>
Cc: "South, Harold" <hsouth@amgen.com>,
        "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: Re: socks on fwtk.org
Message-Id: <20010301104832.O24909@washington.cospo.osis.gov>
Mail-Followup-To: Keith Young <kyoung@v-one.com>,
	"South, Harold" <hsouth@amgen.com>,
	"'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com> <20010301093833.F24909@washington.cospo.osis.gov> <3A9E6E67.14D48F67@v-one.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <3A9E6E67.14D48F67@v-one.com>; from kyoung@v-one.com on Thu, Mar 01, 2001 at 10:44:39AM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 945

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Mar 01, 2001 at 10:44:39AM -0500, Keith Young wrote:
...
> Hmmm... on the Patches page...
> 
> 3.20 Proxy for SOCKS4/SOCKS5
> http://www.fwtk.org/fwtk/patches/patches.html#3.20
>    /\    /\    /\    /\   /\    /\ 
> (this one is different than NEC's proxy)

?????  Oh, this only does the TCP part.

> and SOCKS is mentioned in 3.6:
> http://www.fwtk.org/fwtk/patches/patches.html#3.6

This apparently is not a "proxy" in the way the proxies that come with
FWTK are.

And I should have remembered these, because I had seen them.  Sorry to
speak first without putting brain in gear.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Mar  1 17:01 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA00101
	Thu, 1 Mar 2001 17:01:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA02725;
	Thu, 1 Mar 2001 14:03:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 12:52:56 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA21210
	for fwtk-users-outgoing; Thu, 1 Mar 2001 12:52:40 -0800 (PST)
From: bleary@ipass.net
Date: Thu, 1 Mar 2001 15:52:01 -0500 (EST)
Message-Id: <200103012052.PAA00798@jupiter.ipass.net>
X-Authentication-Warning: jupiter.ipass.net: web set sender to bleary@ipass.net using -f
To: fwtk-users <fwtk-users@lists.nai.com>
Reply-To: bleary@ipass.net
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
User-Agent: IMP/PHP3 Imap webMail Program 2.0.11
X-Originating-IP: 56.0.160.18
Subject: MTA no HELO -> smap dies
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 1038

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I found the following bug in smap -

given the exchange:

MTA connects to server
smap  220 mta.bar.foo SMTP/smap Ready.
MTA   NOOP
smap  220 OK
MTA   MAIL FROM:<user@lamemailer.foo>
smap  250 <user@lamemailer.foo>... Sender Ok
MTA   RCPT TO:<user@bar.foo>
smap  250 <user@bar.foo> OK
MTA   DATA
smap  354 Enter mail, and end with "." on a line by
itself
smap dies.

I have confirmed that sendmail and smap in Gauntlet will
accept a NOOP and continue to successfully accept mail.

The bug is the passing of a null string pointer (rhost)
to fprintf at -

fprintf(vout,"Received: from %s(%s %s) by %s via smap
(%s)\n\tid %s; %s\n",
	rhost,	
	strcasecmp(rhost,rladdr) ? rladdr : "" ,
	riaddr,myhostname,
	FWTK_VERSION_MINOR,tempfile,
	arpadate((char *)0));
	
My fix was to add the line -

        printf("220 %s SMTP/smap
Ready.\r\n",myhostname);
        fflush(stdout);
+       rhost = "lameMailer" ;

- Brion



From owner-fwtk-users@ex.tis.com Thu Mar  1 17:26 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA00248
	Thu, 1 Mar 2001 17:26:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA06670;
	Thu, 1 Mar 2001 14:28:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 13:27:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA26478
	for fwtk-users-outgoing; Thu, 1 Mar 2001 13:26:44 -0800 (PST)
Message-ID: <2FDC06D944A6D311A022009027C3BD64858283@ab-exchange1.gmd.com.au>
From: Andrew Winter <Andrew@gmd.com.au>
To: fwtk-users@ex.tis.com
Subject: http-gw and ftp-gw 'timing out'
Date: Fri, 2 Mar 2001 08:24:51 +1100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2016

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Here's a difficult problem that people may be able to help me with.

We recently installed a 2mb HDSL (full duplex) connection.
Hence I started building a new firewall.

PII200 with 2 * 3c905c ethernet cards.
Redhat 6.2 (kernel 2.2.14-5.0)
compiled and installed fwtk2.1

Now if I use the ftp-gw or http-gw, for either ftp get or http get, the
majority of downloads (ie large files) 'stop'. they get to a certain point
and just sit there until it times out.
There is nothing in the log to indicate an error. The log shows the
download/get as starting but thats all. It occasionally works which is more
frustrating.

If I FTP directly from the FW machine to a site, i dont get any
hangs/freezes/stopping. It downloads properly and well. Therefore it's not
the HDSL link.

I've verified on many sites, including 'known good' and 'known fast'
(i've even started downloads thru both the ftp-gw and the machine itself at
the same time. the ftp-gw bombs out and the machine itself is fine)

Our internal network is fine, so all i can see that is problematic is the
plugs.

The load of the machine is fairly low when the 'freezes' happen.
The network load is fairly low (since we havent rolled out to the company
yet)
There are no tx or rx errors or overflows.
I've downloaded and installed all relevant patches
(jumbo/win95ftp/gate-ftp/non std ports ftp/extended ftp permissions), but no
resolution.
I've updated the kernel to kernel 2.2.17 - 14 but that doesnt help.
Using gcc egcs-2.91.66 to compile. no errors.
Tried updating ethernet drivers to the
http://www.scyld.com/network/vortex.html version.


-------------
On a different note -
FWTK requires ip_forwarding to be turned off
IPSEC requires ip_forwarding
Any probs if have ip_forwarding on and use ipfwadm/ipchains to only forward
to the IPSEC IP ranges, everything else is denied except for ports/hosts
defined by fwtk gws?

andrew

From owner-fwtk-users@ex.tis.com Thu Mar  1 18:23 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA00439
	Thu, 1 Mar 2001 18:23:22 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA16047;
	Thu, 1 Mar 2001 15:25:46 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 14:20:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA05310
	for fwtk-users-outgoing; Thu, 1 Mar 2001 14:19:53 -0800 (PST)
Message-ID: <2FDC06D944A6D311A022009027C3BD64858287@ab-exchange1.gmd.com.au>
From: Andrew Winter <Andrew@gmd.com.au>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: http-gw and ftp-gw 'timing out'
Date: Fri, 2 Mar 2001 09:18:04 +1100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2016

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Here's a difficult problem that people may be able to help me with.

We recently installed a 2mb HDSL (full duplex) connection.
Hence I started building a new firewall.

PII200 with 2 * 3c905c ethernet cards.
Redhat 6.2 (kernel 2.2.14-5.0)
compiled and installed fwtk2.1

Now if I use the ftp-gw or http-gw, for either ftp get or http get, the
majority of downloads (ie large files) 'stop'. they get to a certain point
and just sit there until it times out.
There is nothing in the log to indicate an error. The log shows the
download/get as starting but thats all. It occasionally works which is more
frustrating.

If I FTP directly from the FW machine to a site, i dont get any
hangs/freezes/stopping. It downloads properly and well. Therefore it's not
the HDSL link.

I've verified on many sites, including 'known good' and 'known fast'
(i've even started downloads thru both the ftp-gw and the machine itself at
the same time. the ftp-gw bombs out and the machine itself is fine)

Our internal network is fine, so all i can see that is problematic is the
plugs.

The load of the machine is fairly low when the 'freezes' happen.
The network load is fairly low (since we havent rolled out to the company
yet)
There are no tx or rx errors or overflows.
I've downloaded and installed all relevant patches
(jumbo/win95ftp/gate-ftp/non std ports ftp/extended ftp permissions), but no
resolution.
I've updated the kernel to kernel 2.2.17 - 14 but that doesnt help.
Using gcc egcs-2.91.66 to compile. no errors.
Tried updating ethernet drivers to the
http://www.scyld.com/network/vortex.html version.


-------------
On a different note -
FWTK requires ip_forwarding to be turned off
IPSEC requires ip_forwarding
Any probs if have ip_forwarding on and use ipfwadm/ipchains to only forward
to the IPSEC IP ranges, everything else is denied except for ports/hosts
defined by fwtk gws?

andrew

From owner-fwtk-users@ex.tis.com Thu Mar  1 20:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA00821
	Thu, 1 Mar 2001 20:16:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA25461;
	Thu, 1 Mar 2001 17:18:31 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 16:11:59 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA20221
	for fwtk-users-outgoing; Thu, 1 Mar 2001 16:11:27 -0800 (PST)
Message-Id: <5.0.2.1.0.20010301184950.01d35300@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 01 Mar 2001 18:55:56 -0500
To: Joseph S D Yao <jsdy@cospo.osis.gov>, "South, Harold" <hsouth@amgen.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: socks
Cc: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
In-Reply-To: <20010301093833.F24909@washington.cospo.osis.gov>
References: <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com>
 <C2E1EDCE28D9D211844F0008C7CF088E05650A59@blue-exch.amgen.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 415

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:38 AM 3/1/01 -0500, Joseph S D Yao wrote:
>SOCKS is not TCP, so there can be no proxy.

Actually, it is TCP from the client to the SOCKS "server" (which is, as 
stated earlier, basically a circuit proxy.) Socks can also relay UDP for 
those sorts of applications.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Mar  1 20:35 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA01006
	Thu, 1 Mar 2001 20:35:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA26803;
	Thu, 1 Mar 2001 17:37:31 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 16:37:45 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA22350
	for fwtk-users-outgoing; Thu, 1 Mar 2001 16:37:24 -0800 (PST)
Date: Thu, 1 Mar 2001 19:36:11 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Andrew Winter <Andrew@gmd.com.au>
cc: fwtk-users@ex.tis.com
Subject: Re: http-gw and ftp-gw 'timing out'
In-Reply-To: <2FDC06D944A6D311A022009027C3BD64858283@ab-exchange1.gmd.com.au>
Message-ID: <Pine.GSO.4.10.10103011934230.9432-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2641

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Andrew,

This sounds like a timeout issue somewhere - and probably the command port
is timeing out during the file transfer.  Not sure what is in front of the
firewall (router - other firewall) but make sure that idle connections
(ftpcommand port) don't have timeout values associated with them - or at
least extend them out a bit.

ted keller


On Fri, 2 Mar 2001, Andrew Winter wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Here's a difficult problem that people may be able to help me with.
> 
> We recently installed a 2mb HDSL (full duplex) connection.
> Hence I started building a new firewall.
> 
> PII200 with 2 * 3c905c ethernet cards.
> Redhat 6.2 (kernel 2.2.14-5.0)
> compiled and installed fwtk2.1
> 
> Now if I use the ftp-gw or http-gw, for either ftp get or http get, the
> majority of downloads (ie large files) 'stop'. they get to a certain point
> and just sit there until it times out.
> There is nothing in the log to indicate an error. The log shows the
> download/get as starting but thats all. It occasionally works which is more
> frustrating.
> 
> If I FTP directly from the FW machine to a site, i dont get any
> hangs/freezes/stopping. It downloads properly and well. Therefore it's not
> the HDSL link.
> 
> I've verified on many sites, including 'known good' and 'known fast'
> (i've even started downloads thru both the ftp-gw and the machine itself at
> the same time. the ftp-gw bombs out and the machine itself is fine)
> 
> Our internal network is fine, so all i can see that is problematic is the
> plugs.
> 
> The load of the machine is fairly low when the 'freezes' happen.
> The network load is fairly low (since we havent rolled out to the company
> yet)
> There are no tx or rx errors or overflows.
> I've downloaded and installed all relevant patches
> (jumbo/win95ftp/gate-ftp/non std ports ftp/extended ftp permissions), but no
> resolution.
> I've updated the kernel to kernel 2.2.17 - 14 but that doesnt help.
> Using gcc egcs-2.91.66 to compile. no errors.
> Tried updating ethernet drivers to the
> http://www.scyld.com/network/vortex.html version.
> 
> 
> -------------
> On a different note -
> FWTK requires ip_forwarding to be turned off
> IPSEC requires ip_forwarding
> Any probs if have ip_forwarding on and use ipfwadm/ipchains to only forward
> to the IPSEC IP ranges, everything else is denied except for ports/hosts
> defined by fwtk gws?
> 
> andrew
> 


From owner-fwtk-users@ex.tis.com Fri Mar  2 04:07 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA02001
	Fri, 2 Mar 2001 04:07:29 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA13798;
	Fri, 2 Mar 2001 01:09:53 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 1 Mar 2001 23:45:43 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA10194
	for fwtk-users-outgoing; Thu, 1 Mar 2001 23:45:31 -0800 (PST)
Message-ID: <003a01c0a2ed$5bcb4190$ae58718c@cis.nctu.edu.tw>
Reply-To: "gis88530" <gis88530@cis.nctu.edu.tw>
From: "gis88530" <gis88530@cis.nctu.edu.tw>
To: "fwtk" <fwtk-users@ex.tis.com>
Subject: perfomance comparison
Date: Fri, 2 Mar 2001 15:49:47 +0800
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
X-Virus-Scanned: by AMaViS perl
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="big5"
Content-Length: 857

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
    I have construct the following environment, where squid use
    cache_peer to redirect http request to tis. Thanks GOD. It works.

    (webstone)------(squid<-->tis)------(web server)


    When I use webstone to measure the performance of following two
    environments, I found the performance of second environment is 
    very BAD. Could you give me a hand ? I don't know why.

    1:    (webstone)------(PC router)------(web server)
        throughput: 43.18 Mbps
        response time: 0.003 sec
        connection rate: 284.98 conn/sec 

    2:    (webstone)------(squid<-->tis)------(web server)
        throughput: 4.37 Mbps
        response time: 0.034 sec
        connection rate: 28.06 conn/sec

Steven



From owner-fwtk-users@ex.tis.com Fri Mar  2 05:32 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA02196
	Fri, 2 Mar 2001 05:32:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA18100;
	Fri, 2 Mar 2001 02:35:00 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 01:29:27 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA14637
	for fwtk-users-outgoing; Fri, 2 Mar 2001 01:29:16 -0800 (PST)
Message-ID: <XFMail.20010302092840.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.7 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <003a01c0a2ed$5bcb4190$ae58718c@cis.nctu.edu.tw>
Date: Fri, 02 Mar 2001 09:28:40 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: gis88530 <gis88530@cis.nctu.edu.tw>
Subject: RE: perfomance comparison
Cc: fwtk <fwtk-users@ex.tis.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1549

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Could you also try

(webstone) ---- (squid) ---- (web server)

and

(webstone) ---- (fwtk) ---- (web server)

The fwtk isn't renowned for it's performance. Are you running squid
and fwtk on the same box? If so, that will kill your performance.

-tony



On 02-Mar-2001 gis88530 wrote:
> [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello,
>     I have construct the following environment, where squid use
>     cache_peer to redirect http request to tis. Thanks GOD. It
> works.
> 
>     (webstone)------(squid<-->tis)------(web server)
> 
> 
>     When I use webstone to measure the performance of following two
>     environments, I found the performance of second environment is 
>     very BAD. Could you give me a hand ? I don't know why.
> 
>     1:    (webstone)------(PC router)------(web server)
>         throughput: 43.18 Mbps
>         response time: 0.003 sec
>         connection rate: 284.98 conn/sec 
> 
>     2:    (webstone)------(squid<-->tis)------(web server)
>         throughput: 4.37 Mbps
>         response time: 0.034 sec
>         connection rate: 28.06 conn/sec
> 
> Steven
> 
> 

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
Who's on first?

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Fri Mar  2 06:23 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA02272
	Fri, 2 Mar 2001 06:23:07 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA20847;
	Fri, 2 Mar 2001 03:25:35 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 02:24:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA17555
	for fwtk-users-outgoing; Fri, 2 Mar 2001 02:24:37 -0800 (PST)
Date: Fri, 2 Mar 2001 13:22:17 +0300 (MSK)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: gis88530 <gis88530@cis.nctu.edu.tw>
cc: fwtk <fwtk-users@ex.tis.com>
Subject: Re: perfomance comparison
In-Reply-To: <003a01c0a2ed$5bcb4190$ae58718c@cis.nctu.edu.tw>
Message-ID: <Pine.BSF.4.21.0103021317020.62984-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1320

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, 2 Mar 2001, gis88530 wrote:

> Hello,
>     I have construct the following environment, where squid use
>     cache_peer to redirect http request to tis. Thanks GOD. It works.
> 
>     (webstone)------(squid<-->tis)------(web server)
> 
> 
>     When I use webstone to measure the performance of following two
>     environments, I found the performance of second environment is 
>     very BAD. Could you give me a hand ? I don't know why.
> 
>     1:    (webstone)------(PC router)------(web server)
>         throughput: 43.18 Mbps
>         response time: 0.003 sec
>         connection rate: 284.98 conn/sec 
> 
>     2:    (webstone)------(squid<-->tis)------(web server)
>         throughput: 4.37 Mbps
>         response time: 0.034 sec
>         connection rate: 28.06 conn/sec
	It is quite simple I guess. PC router (or HW router) just forwards
packets and maybe checks IP header when filtering is active. squid/httpgw
og squid-gw makes application specific analysis of HTML code. If webstone
makes connections serially, it would detect dramatical perfomance
decrease.

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Fri Mar  2 06:44 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA02343
	Fri, 2 Mar 2001 06:44:38 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA21902;
	Fri, 2 Mar 2001 03:47:02 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 02:45:29 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA18647
	for fwtk-users-outgoing; Fri, 2 Mar 2001 02:45:13 -0800 (PST)
Message-ID: <00b201c0a306$6e7d4a90$ae58718c@cis.nctu.edu.tw>
Reply-To: "gis88530" <gis88530@cis.nctu.edu.tw>
From: "gis88530" <gis88530@cis.nctu.edu.tw>
To: "Tony Gale" <gale@syntax.dera.gov.uk>
Cc: "fwtk" <fwtk-users@ex.tis.com>
References: <XFMail.20010302092840.gale@syntax.dera.gov.uk>
Subject: Re: perfomance comparison
Date: Fri, 2 Mar 2001 18:49:15 +0800
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
X-Virus-Scanned: by AMaViS perl
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="big5"
Content-Length: 2667

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
    Thanks.
    I have try following conditions, 
    (The squid only condition doesn't work, because 
    webstone will hang to retrieve html pages)

    1:    (webstone)----(fwtk)----(web server)
        throughput: 0.34 Mbps
        response time: 0.023 sec
        connection rate: 42.62 conn/sec

    2:    (webstone)------(PC router)------(web server)
        throughput: 43.18 Mbps
        response time: 0.003 sec
        connection rate: 284.98 conn/sec 
 
    3:    (webstone)------(squid<-->tis)------(web server)
        throughput: 4.37 Mbps
        response time: 0.034 sec
        connection rate: 28.06 conn/sec

    I am wondering the performance of tis.
    Could you give me some hints ?
    Maybe we can improve it.
    Thanks for disscussion.

Steven


----- Original Message ----- 
From: "Tony Gale" <gale@syntax.dera.gov.uk>
To: "gis88530" <gis88530@cis.nctu.edu.tw>
Cc: "fwtk" <fwtk-users@ex.tis.com>
Sent: Friday, March 02, 2001 5:28 PM
Subject: RE: perfomance comparison


> 
> Could you also try
> 
> (webstone) ---- (squid) ---- (web server)
> 
> and
> 
> (webstone) ---- (fwtk) ---- (web server)
> 
> The fwtk isn't renowned for it's performance. Are you running squid
> and fwtk on the same box? If so, that will kill your performance.
> 
> -tony
> 
> 
> 
> On 02-Mar-2001 gis88530 wrote:
> > [To be removed from this list send the message "unsubscribe
> > fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > Hello,
> >     I have construct the following environment, where squid use
> >     cache_peer to redirect http request to tis. Thanks GOD. It
> > works.
> > 
> >     (webstone)------(squid<-->tis)------(web server)
> > 
> > 
> >     When I use webstone to measure the performance of following two
> >     environments, I found the performance of second environment is 
> >     very BAD. Could you give me a hand ? I don't know why.
> > 
> >     1:    (webstone)------(PC router)------(web server)
> >         throughput: 43.18 Mbps
> >         response time: 0.003 sec
> >         connection rate: 284.98 conn/sec 
> > 
> >     2:    (webstone)------(squid<-->tis)------(web server)
> >         throughput: 4.37 Mbps
> >         response time: 0.034 sec
> >         connection rate: 28.06 conn/sec
> > 
> > Steven
> > 
> > 
> 
> ---
> E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
> Who's on first?
> 
> The views expressed above are entirely those of the writer
> and do not represent the views, policy or understanding of
> any other person or official body.
> 


From owner-fwtk-users@ex.tis.com Fri Mar  2 07:03 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA02390
	Fri, 2 Mar 2001 07:03:13 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA22846;
	Fri, 2 Mar 2001 04:05:22 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 03:08:20 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA19894
	for fwtk-users-outgoing; Fri, 2 Mar 2001 03:08:00 -0800 (PST)
Message-ID: <XFMail.20010302110715.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.7 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <00b201c0a306$6e7d4a90$ae58718c@cis.nctu.edu.tw>
Date: Fri, 02 Mar 2001 11:07:15 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: gis88530 <gis88530@cis.nctu.edu.tw>
Subject: Re: perfomance comparison
Cc: fwtk <fwtk-users@ex.tis.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 2152

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


On 02-Mar-2001 gis88530 wrote:
> Hello,
>     Thanks.
>     I have try following conditions, 
>     (The squid only condition doesn't work, because 
>     webstone will hang to retrieve html pages)

I don't understand what the problem is - is it a problem with
webstone?


> 
>     1:    (webstone)----(fwtk)----(web server)
>         throughput: 0.34 Mbps
>         response time: 0.023 sec
>         connection rate: 42.62 conn/sec
> 
>     2:    (webstone)------(PC router)------(web server)
>         throughput: 43.18 Mbps
>         response time: 0.003 sec
>         connection rate: 284.98 conn/sec 
>  
>     3:    (webstone)------(squid<-->tis)------(web server)
>         throughput: 4.37 Mbps
>         response time: 0.034 sec
>         connection rate: 28.06 conn/sec
> 
>     I am wondering the performance of tis.
>     Could you give me some hints ?
>     Maybe we can improve it.
>     Thanks for disscussion.
> 

There's no easy solution to improve the performance of the FWTK. It's
design really isn't up to it. It fork()'s a new process for each
connection, doesn't support any kind of presistent connections and
its logging will kill your performance unless you set it up right.
I'm also not convinced by its html checking.

Don't get me wrong, I like it, and it has served me well over many
years. You just have to be aware of its limitations. I use multiple
proxy servers, for example.

BTW, on the subject of logging, did you have the fwtk logging through
syslog in your tests? If so, turn that off to see what difference it
makes - I don't know what system you are using, but you may also want
to try if after turning off sync'ing in your syslog.conf

-tony


---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
Recent research has tended to show that the Abominable No-Man
is being replaced by the Prohibitive Procrastinator.
		-- C.N. Parkinson

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Fri Mar  2 10:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA03239
	Fri, 2 Mar 2001 10:48:30 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08019;
	Fri, 2 Mar 2001 07:50:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 06:46:57 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA00401
	for fwtk-users-outgoing; Fri, 2 Mar 2001 06:46:42 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3A9F67DB.A19F06DD@peaktime.be>
Date: Fri, 02 Mar 2001 10:28:59 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk <fwtk-users@ex.tis.com>
Subject: Re: perfomance comparison
References: <003a01c0a2ed$5bcb4190$ae58718c@cis.nctu.edu.tw>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1982

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

gis88530 wrote:
 > 
 > Hello,
 >     I have construct the following environment, where squid use
 >     cache_peer to redirect http request to tis. Thanks GOD. It works.
 > 
 >     (webstone)------(squid<-->tis)------(web server)
 > 
 >     When I use webstone to measure the performance of following two
 >     environments, I found the performance of second environment is
 >     very BAD. Could you give me a hand ? I don't know why.
 > 
 >     1:    (webstone)------(PC router)------(web server)
 >         throughput: 43.18 Mbps
 >         response time: 0.003 sec
 >         connection rate: 284.98 conn/sec
 > 
 >     2:    (webstone)------(squid<-->tis)------(web server)
 >         throughput: 4.37 Mbps
 >         response time: 0.034 sec
 >         connection rate: 28.06 conn/sec
 > 
 > Steven

It's hard to tell without knwing more precisely what you do. "squid use
cache_peer to redirect http request to tis" is extremely vague. Is squid
configured as proxy only, or does it do http caching too? What do you
mean by "tis", http-gw or plug-gw? What is there in your netperm-table?
Is the TIS proxy started from inetd or with -daemon from rc?

In any case, application-level proxies will *never* be as fast as packet
filters, since the former will fork and/or exec new process(es) for
every connection (1 to accept, one for netacl if used, maybe 1 fork in
squid unless it's thread-based, I don't know squid well enough).

If you really want 200+ connections per second, and you don't need any
functionality that requires understanding of the protocol, you can use
some form of *filtered* packet forwarding, eg on Linux ipfwadm, ipchains
or iptable.

For 200+ conn/sec *and* application-level proxying, IMHO you will need a
ton of hardware, or some thread-based proxy, most probably commercial
and expensive.

Greetings.
-- 
Michel Bardiaux


From owner-fwtk-users@ex.tis.com Fri Mar  2 10:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA03242
	Fri, 2 Mar 2001 10:48:39 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08023;
	Fri, 2 Mar 2001 07:50:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 06:40:07 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA29872
	for fwtk-users-outgoing; Fri, 2 Mar 2001 06:39:46 -0800 (PST)
Message-ID: <3A9EEBD6.225ED030@memphis.edu>
Date: Thu, 01 Mar 2001 18:39:50 -0600
From: mjani <mjani@memphis.edu>
X-Mailer: Mozilla 4.74 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: one way ftp service
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 509

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi ken,

Did you found out, how to do the following?
thanks,
mitesh

Does anyone know whether it is possible to configure
firewall to have one-way ftp meaning they can only
transferring files in from outside but not transferring out
from inside.

I am confused with Source/Destination on how it filtering
packet.

Any advises or suggests are greatly appreciated.

Thanks,
Ken.




From owner-fwtk-users@ex.tis.com Fri Mar  2 10:48 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA03245
	Fri, 2 Mar 2001 10:48:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA08027;
	Fri, 2 Mar 2001 07:50:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 06:44:27 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA00126
	for fwtk-users-outgoing; Fri, 2 Mar 2001 06:43:41 -0800 (PST)
Message-Id: <5.0.2.1.0.20010301212748.01d2f7b0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 01 Mar 2001 21:29:31 -0500
To: Ted Keller <keller@bfg.com>, Andrew Winter <Andrew@gmd.com.au>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: http-gw and ftp-gw 'timing out'
Cc: fwtk-users@ex.tis.com
In-Reply-To: <Pine.GSO.4.10.10103011934230.9432-100000@ns1.bfg.com>
References: <2FDC06D944A6D311A022009027C3BD64858283@ab-exchange1.gmd.com.au>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 914

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:36 PM 3/1/01 -0500, Ted Keller wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >Andrew,
 >
 >This sounds like a timeout issue somewhere - and probably the command port
 >is timeing out during the file transfer.  Not sure what is in front of the
 >firewall (router - other firewall) but make sure that idle connections
 >(ftpcommand port) don't have timeout values associated with them - or at
 >least extend them out a bit.

I've also seen problems like this when there's a MTU mismatch somewhere and 
a filter is keeping MTU discovery from working. Try setting the MTU on your 
external interface to something small (576 bytes) and see if the problem 
gets better.
          -Rick



From owner-fwtk-users@ex.tis.com Fri Mar  2 12:13 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA03506
	Fri, 2 Mar 2001 12:12:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA19348;
	Fri, 2 Mar 2001 09:15:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 08:08:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA10366
	for fwtk-users-outgoing; Fri, 2 Mar 2001 08:07:43 -0800 (PST)
Message-ID: <002901c0a333$6cecc610$ae58718c@cis.nctu.edu.tw>
Reply-To: "gis88530" <gis88530@cis.nctu.edu.tw>
From: "gis88530" <gis88530@cis.nctu.edu.tw>
To: "fwtk" <fwtk-users@ex.tis.com>
References: <XFMail.20010302110715.gale@syntax.dera.gov.uk>
Subject: Re: perfomance comparison
Date: Sat, 3 Mar 2001 00:11:21 +0800
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
X-Virus-Scanned: by AMaViS perl
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="big5"
Content-Length: 1220

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Sorry,
    I just use http-gw, and there are many
    log in /var/log/messages.

    Maybe my configurations are WRONG.
    Could you give me a hand?
    My netperm-table is as follows:

http-gw: permit-hosts 140.113.113.153 192.168.100.254 127.0.0.1
192.168.100.* -nojava -nojavascript -noactivex


Steven

> There's no easy solution to improve the performance of the FWTK. It's
> design really isn't up to it. It fork()'s a new process for each
> connection, doesn't support any kind of presistent connections and
> its logging will kill your performance unless you set it up right.
> I'm also not convinced by its html checking.
>
> Don't get me wrong, I like it, and it has served me well over many
> years. You just have to be aware of its limitations. I use multiple
> proxy servers, for example.
>
> BTW, on the subject of logging, did you have the fwtk logging through
> syslog in your tests? If so, turn that off to see what difference it
> makes - I don't know what system you are using, but you may also want
> to try if after turning off sync'ing in your syslog.conf
>
> -tony



From owner-fwtk-users@ex.tis.com Fri Mar  2 13:02 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA03672
	Fri, 2 Mar 2001 13:02:56 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA24251;
	Fri, 2 Mar 2001 10:04:18 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 09:02:10 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA17546
	for fwtk-users-outgoing; Fri, 2 Mar 2001 09:01:46 -0800 (PST)
Message-ID: <11630904.983552429742.JavaMail.imail@dotty.excite.com>
Date: Fri, 2 Mar 2001 09:00:29 -0800 (PST)
From: "T. Esting" <T_Esting@excite.com>
Reply-To: <T_Esting@excite.com>
To: mjani <mjani@memphis.edu>, fwtk-users@tis.com
Subject: Re: one way ftp service
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Mailer: Excite Inbox
X-Sender-Ip: 63.73.213.5
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1281

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


  Check out ftp-gw and its documentation.  You can use ftp-gw to specify
which operations are allowed (PUT, MPUT, CWD) or denied (GET, MGET). 
IP-level filtering won't quite cut it because at layers 3 and 4, you merely
have a connection, and the direction in which it is established won't
necessarily correspond to the action (upload or download) that the user
takes.
  
  Good luck.

On Thu, 01 Mar 2001 18:39:50 -0600, mjani wrote:

>  [To be removed from this list send the message "unsubscribe fwtk-users"
in the
>  BODY of a mail message to majordomo@ex.tis.com.]
>  
>  Hi ken,
>  
>  Did you found out, how to do the following?
>  thanks,
>  mitesh
>  
>  Does anyone know whether it is possible to configure
>  firewall to have one-way ftp meaning they can only
>  transferring files in from outside but not transferring out
>  from inside.
>  
>  I am confused with Source/Destination on how it filtering
>  packet.
>  
>  Any advises or suggests are greatly appreciated.
>  
>  Thanks,
>  Ken.
>  
>  
>





_______________________________________________________
Send a cool gift with your E-Card
http://www.bluemountain.com/giftcenter/



From owner-fwtk-users@ex.tis.com Fri Mar  2 13:14 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA03729
	Fri, 2 Mar 2001 13:14:03 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA25279;
	Fri, 2 Mar 2001 10:16:02 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 09:11:05 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA18713
	for fwtk-users-outgoing; Fri, 2 Mar 2001 09:10:38 -0800 (PST)
Message-ID: <XFMail.20010302170943.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.7 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <002901c0a333$6cecc610$ae58718c@cis.nctu.edu.tw>
Date: Fri, 02 Mar 2001 17:09:43 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: gis88530 <gis88530@cis.nctu.edu.tw>
Subject: Re: perfomance comparison
Cc: fwtk <fwtk-users@ex.tis.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 2805

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


By default the FWTK logs to syslog. Syslog will sync your disks after
*every* message. Fine if you want to guarantee that you log every
message in case of a crash, but it kills your performance, especially
on something that logs as much as the FWTK (and it logs too much,
IMHO). So, for testing purposes, I would re-run your tests having
first commented out the appropriate line in /etc/syslog.conf, and
sending syslog a HUP signal (kill -HUP <pid of syslog>) such that
nothing from the FWTK gets logged.

I would then re-run the tests again, with the logging, but with the
sync'ing turned off. You do that by adding a '-' to the approproiate
entry in /etc/syslog.conf, so for example:

*.info;mail.none;authpriv.none                     /var/log/messages

becomes

*.info;mail.none;authpriv.none                     -/var/log/messages

(be careful not to break the tabbing between these two entries -
syslog won't work if you do)

You may won't to check your syslog.conf man page to see that it
supports the no sync'ing option.

-tony



On 02-Mar-2001 gis88530 wrote:
> [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Sorry,
>     I just use http-gw, and there are many
>     log in /var/log/messages.
> 
>     Maybe my configurations are WRONG.
>     Could you give me a hand?
>     My netperm-table is as follows:
> 
> http-gw: permit-hosts 140.113.113.153 192.168.100.254 127.0.0.1
> 192.168.100.* -nojava -nojavascript -noactivex
> 
> 
> Steven
> 
>> There's no easy solution to improve the performance of the FWTK.
>> It's
>> design really isn't up to it. It fork()'s a new process for each
>> connection, doesn't support any kind of presistent connections and
>> its logging will kill your performance unless you set it up right.
>> I'm also not convinced by its html checking.
>>
>> Don't get me wrong, I like it, and it has served me well over many
>> years. You just have to be aware of its limitations. I use
>> multiple
>> proxy servers, for example.
>>
>> BTW, on the subject of logging, did you have the fwtk logging
>> through
>> syslog in your tests? If so, turn that off to see what difference
>> it
>> makes - I don't know what system you are using, but you may also
>> want
>> to try if after turning off sync'ing in your syslog.conf
>>
>> -tony
> 
> 

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
flannister, n.:
	The plastic yoke that holds a six-pack of beer together.
		-- "Sniglets", Rich Hall & Friends

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Fri Mar  2 14:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA04081
	Fri, 2 Mar 2001 14:40:12 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA04230;
	Fri, 2 Mar 2001 11:42:16 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 10:39:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA27319
	for fwtk-users-outgoing; Fri, 2 Mar 2001 10:39:10 -0800 (PST)
Date: Fri, 2 Mar 2001 10:20:05 -0800 (PST)
From: David Lang <dlang@diginsite.com>
To: Tony Gale <gale@syntax.dera.gov.uk>
cc: gis88530 <gis88530@cis.nctu.edu.tw>, fwtk <fwtk-users@ex.tis.com>
Subject: Re: perfomance comparison
In-Reply-To: <XFMail.20010302170943.gale@syntax.dera.gov.uk>
Message-ID: <Pine.LNX.4.31.0103021014580.19344-100000@dlang.diginsite.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 4001

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

also the OS you are useing can make a HUGE difference. I ran some tests a
couple months ago for one firewall we were looking at putting in.

that firewall was running 1300 plug-gw proxies (different ports)

on Linux 2.2.x (after recompiling to raise the max procs) I was seeing
~50% CPU at ~30 connections/sec

on Linux 2.4.0pre11 I was seeing ~20% CPU on ~300 connections/sec

System was 950MHz Athlon 512MB PC133 Ram

shutting down syslog entirly appeared to make no significant diffence to
these numbers. I ended up configuring the machine to syslog out the serial
port to another machine (I did tweak the code to not log quite as much as
it normally does)

David Lang

On Fri, 2 Mar 2001, Tony Gale wrote:

> Date: Fri, 02 Mar 2001 17:09:43 -0000 (GMT)
> From: Tony Gale <gale@syntax.dera.gov.uk>
> To: gis88530 <gis88530@cis.nctu.edu.tw>
> Cc: fwtk <fwtk-users@ex.tis.com>
> Subject: Re: perfomance comparison
>
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
>
> By default the FWTK logs to syslog. Syslog will sync your disks after
> *every* message. Fine if you want to guarantee that you log every
> message in case of a crash, but it kills your performance, especially
> on something that logs as much as the FWTK (and it logs too much,
> IMHO). So, for testing purposes, I would re-run your tests having
> first commented out the appropriate line in /etc/syslog.conf, and
> sending syslog a HUP signal (kill -HUP <pid of syslog>) such that
> nothing from the FWTK gets logged.
>
> I would then re-run the tests again, with the logging, but with the
> sync'ing turned off. You do that by adding a '-' to the approproiate
> entry in /etc/syslog.conf, so for example:
>
> *.info;mail.none;authpriv.none                     /var/log/messages
>
> becomes
>
> *.info;mail.none;authpriv.none                     -/var/log/messages
>
> (be careful not to break the tabbing between these two entries -
> syslog won't work if you do)
>
> You may won't to check your syslog.conf man page to see that it
> supports the no sync'ing option.
>
> -tony
>
>
>
> On 02-Mar-2001 gis88530 wrote:
> > [To be removed from this list send the message "unsubscribe
> > fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > Sorry,
> >     I just use http-gw, and there are many
> >     log in /var/log/messages.
> >
> >     Maybe my configurations are WRONG.
> >     Could you give me a hand?
> >     My netperm-table is as follows:
> >
> > http-gw: permit-hosts 140.113.113.153 192.168.100.254 127.0.0.1
> > 192.168.100.* -nojava -nojavascript -noactivex
> >
> >
> > Steven
> >
> >> There's no easy solution to improve the performance of the FWTK.
> >> It's
> >> design really isn't up to it. It fork()'s a new process for each
> >> connection, doesn't support any kind of presistent connections and
> >> its logging will kill your performance unless you set it up right.
> >> I'm also not convinced by its html checking.
> >>
> >> Don't get me wrong, I like it, and it has served me well over many
> >> years. You just have to be aware of its limitations. I use
> >> multiple
> >> proxy servers, for example.
> >>
> >> BTW, on the subject of logging, did you have the fwtk logging
> >> through
> >> syslog in your tests? If so, turn that off to see what difference
> >> it
> >> makes - I don't know what system you are using, but you may also
> >> want
> >> to try if after turning off sync'ing in your syslog.conf
> >>
> >> -tony
> >
> >
>
> ---
> E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
> flannister, n.:
> 	The plastic yoke that holds a six-pack of beer together.
> 		-- "Sniglets", Rich Hall & Friends
>
> The views expressed above are entirely those of the writer
> and do not represent the views, policy or understanding of
> any other person or official body.
>

From owner-fwtk-users@ex.tis.com Fri Mar  2 14:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA04185
	Fri, 2 Mar 2001 14:54:21 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA05716;
	Fri, 2 Mar 2001 11:56:19 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 10:58:17 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA29462
	for fwtk-users-outgoing; Fri, 2 Mar 2001 10:58:01 -0800 (PST)
Date: Fri, 2 Mar 2001 13:57:23 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: gis88530 <gis88530@cis.nctu.edu.tw>
Cc: Tony Gale <gale@syntax.dera.gov.uk>, fwtk <fwtk-users@ex.tis.com>
Subject: Re: perfomance comparison
Message-Id: <20010302135723.M5148@washington.cospo.osis.gov>
Mail-Followup-To: gis88530 <gis88530@cis.nctu.edu.tw>,
	Tony Gale <gale@syntax.dera.gov.uk>, fwtk <fwtk-users@ex.tis.com>
References: <XFMail.20010302092840.gale@syntax.dera.gov.uk> <00b201c0a306$6e7d4a90$ae58718c@cis.nctu.edu.tw>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <00b201c0a306$6e7d4a90$ae58718c@cis.nctu.edu.tw>; from gis88530@cis.nctu.edu.tw on Fri, Mar 02, 2001 at 06:49:15PM +0800
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1117

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Mar 02, 2001 at 06:49:15PM +0800, gis88530 wrote:
>     I am wondering the performance of tis.
>     Could you give me some hints ?
>     Maybe we can improve it.
>     Thanks for disscussion.

TIS was absorbed by NAI, and is no more.  Therefore its performance is
similarly non-existant.

The FWTK is probably what you're talking about.  And, particularly, the
http-gw.  It picks up every outgoing query and incoming piece of HTML,
examines them for correctness and any attacks, and passes them on to
the other side.  There is NO WAY to get it to be as fast as a copper
wire; but it provides a heck of a lot more protection!

Having said that, there may be ways to improve its performance.  Why
don't you instrument it and see where it spends its time?

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Mar  2 16:18 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA04435
	Fri, 2 Mar 2001 16:18:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA14133;
	Fri, 2 Mar 2001 13:21:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 12:15:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA07546
	for fwtk-users-outgoing; Fri, 2 Mar 2001 12:15:26 -0800 (PST)
Date: Fri, 2 Mar 2001 15:14:41 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: mjani <mjani@memphis.edu>
Cc: fwtk-users@tis.com
Subject: Re: one way ftp service
Message-Id: <20010302151441.Q5148@washington.cospo.osis.gov>
Mail-Followup-To: mjani <mjani@memphis.edu>, fwtk-users@tis.com
References: <3A9EEBD6.225ED030@memphis.edu>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <3A9EEBD6.225ED030@memphis.edu>; from mjani@memphis.edu on Thu, Mar 01, 2001 at 06:39:50PM -0600
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1097

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Mar 01, 2001 at 06:39:50PM -0600, mjani wrote:
...
> Does anyone know whether it is possible to configure
> firewall to have one-way ftp meaning they can only
> transferring files in from outside but not transferring out
> from inside.
> 
> I am confused with Source/Destination on how it filtering
> packet.

Simply configure [in netperm-table] your ftp-gw to accept connectiond
from outside, but NOT from inside.  Why you would want to do this, I
don't know.

Or do you mean that you want to configure it to allow PUTs from the
outside and not GETs, and GETs from the inside and not PUTs?  I can
see why you might want to do that, but I don't know whether there is
any code in ftp-gw to allow that.  Not too hard to add, of course.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Mar  2 17:30 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA04771
	Fri, 2 Mar 2001 17:30:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA21512;
	Fri, 2 Mar 2001 14:33:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 2 Mar 2001 13:29:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA14921
	for fwtk-users-outgoing; Fri, 2 Mar 2001 13:29:24 -0800 (PST)
From: "Sid Wilson" <swilson@fps-edl.com>
To: "Fwtk-Users \(E-mail\)" <fwtk-users@lists.nai.com>
Subject: help with "n2a get_local_info"
Date: Fri, 2 Mar 2001 16:24:42 -0500
Message-ID: <003501c0a35f$33079750$041da8c0@fpsedl.com>
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2911.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0036_01C0A335.4A318F50"
Content-Length: 1305

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_0036_01C0A335.4A318F50
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

I'm sure this is a simple one, but I haven't been able to discover the
source of this message:

Mar  2 15:53:21 igate http-gw[12855]: n2a get_local_info: open to get
interface configuration: No such file or directory

I haven't really been able to discern a pattern to the message either.
Can someone help point me in the right direction?

Thanks:

Sid Wilson

------=_NextPart_000_0036_01C0A335.4A318F50
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
I'm = sure this is a=20 simple one, but I haven't been able to discover the source of this=20 message:
  
Mar  2 15:53:21 igate = http-gw[12855]: n2a=20 get_local_info: open to get interface=20 configuration: No such file or directory
I = haven't really=20 been able to discern a pattern to the message = either.
Can = someone help=20 point me in the right direction?
  
Thanks:
  
Sid=20 Wilson

------=_NextPart_000_0036_01C0A335.4A318F50--



From owner-fwtk-users@ex.tis.com Sat Mar  3 13:47 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA07169
	Sat, 3 Mar 2001 13:47:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA25718;
	Sat, 3 Mar 2001 10:49:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 3 Mar 2001 09:30:40 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA23747
	for fwtk-users-outgoing; Sat, 3 Mar 2001 09:30:19 -0800 (PST)
Message-ID: <000901c0a408$23e83cd0$ae58718c@cis.nctu.edu.tw>
Reply-To: "gis88530" <gis88530@cis.nctu.edu.tw>
From: "gis88530" <gis88530@cis.nctu.edu.tw>
To: "fwtk" <fwtk-users@ex.tis.com>
Subject: how many clients
Date: Sun, 4 Mar 2001 01:34:01 +0800
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
X-Virus-Scanned: by AMaViS perl
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="big5"
Content-Length: 292

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello,
    Execuse me! Could I investigate one condition ?

    How many clients connect to Internet through TIS in your environment?
    Thanks a lot!

Steven
 


From owner-fwtk-users@ex.tis.com Mon Mar  5 00:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA10895
	Mon, 5 Mar 2001 00:52:50 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA29398;
	Sun, 4 Mar 2001 21:55:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 4 Mar 2001 20:31:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA27461
	for fwtk-users-outgoing; Sun, 4 Mar 2001 20:30:47 -0800 (PST)
From: zhangfan79@263.net
MIME-Version: 1.0
Message-Id: <3AA31428.20425@mta4.263.net>
Date: Mon, 5 Mar 2001 12:20:56 +0800 (CST)
To: fwtk-users@ex.tis.com
Subject: md5auth help
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 518

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hello all
  fwtk 2.0 have a file mdauth.c in directory auth,but i don't know how to use this file ,could you tell me how to write the makefile to add mdauth to auth protocal
                         thanks a lot

_____________________________________________
低价IP卡，震撼人心   http://shopping.263.net/hotsale/ipcard.htm
买手机，100%中大奖   http://shopping.263.net/fs/huafeng/index.asp

From owner-fwtk-users@ex.tis.com Mon Mar  5 14:18 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA13431
	Mon, 5 Mar 2001 14:18:20 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA23508;
	Mon, 5 Mar 2001 11:20:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Mar 2001 10:07:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA18797
	for fwtk-users-outgoing; Mon, 5 Mar 2001 10:07:21 -0800 (PST)
X-Version: ireland 6.2.3.2329.0
From: "David Furlong" <def345@ireland.com>
Message-Id: <EFF6E6D7F5115D115A850005B8ACC2B0@def345.ireland.com>
Date: Mon, 5 Mar 2001 13:36:27 +0000
X-Priority: Normal
To: "fwtk-users@tis.com" <fwtk-users@tis.com>
Subject: Ports
CC: def345@hotmail.com
X-Mailer: Web Based Pronto
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1058

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


After doing a quick port scan on my proxy server, using nmap
it came back with the following
   25/tcp smtp             
   53/tcp domain          53/udp domain
                         123/udp ntp
                         514/udp syslog
  515/tcp printer 
1080/tcp socks
2766/tcp listen 
This is running on a solaris 2.6 machine, which has squid, tis for 
ftp, and news, socks running on it.
I know the ports open above are not entirely safe, and was wondering 
should I also proxy them using TIS, should they be disabled, (and if 
so how, inetd isn't used I think) and are they safe??

If this isn't a question for the fwtk mailing list, could someone 
point me to a better newsgroup for dealing with this kind of problem

And lastly, are there other utilities I should use to test my 
firewall / proxy machine.

Regards and thanks
Dave 

_____________________________________

Get your free E-mail at http://www.ireland.com


From owner-fwtk-users@ex.tis.com Mon Mar  5 15:25 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA13639
	Mon, 5 Mar 2001 15:25:15 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA27887;
	Mon, 5 Mar 2001 12:27:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Mar 2001 11:21:17 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA23517
	for fwtk-users-outgoing; Mon, 5 Mar 2001 11:20:51 -0800 (PST)
Message-ID: <019601c0a59b$fd2aac00$2202a8c0@beacon>
From: "dave" <def345@ireland.com>
To: <fwtk-users@lists.nai.com>
Cc: <def345@hotmail.com>
Subject: Ports
Date: Mon, 5 Mar 2001 17:44:55 -0000
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2314.1300
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2314.1300
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 960

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


After doing a quick port scan on my proxy server, using nmap
it came back with the following

25/tcp smtp
53/tcp domain  53/udp domain
                         123/udp ntp
                         514/udp syslog
515/tcp printer
1080/tcp socks
2766/tcp listen

This is running on a solaris 2.6 machine, which has squid, tis for ftp, and
news, socks running on it.
I know the ports open above are not entirly safe, and was wondering should I
also proxy them using TIS,
should they be disabled, (and if so how, inetd isn't used I think)
and are they safe??

If this isn't a question for the fwtk mailing list, could someone point me
to a better newsgroup for dealing with this kind of problem

And lastly, are there other utilities I should use to test my firewall /
proxy machine.


Regards
Dave

cc replies to def345@hotmail.com



From owner-fwtk-users@ex.tis.com Mon Mar  5 17:46 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA13964
	Mon, 5 Mar 2001 17:46:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA05059;
	Mon, 5 Mar 2001 14:49:04 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 5 Mar 2001 13:47:35 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA01887
	for fwtk-users-outgoing; Mon, 5 Mar 2001 13:47:09 -0800 (PST)
Date: Mon, 5 Mar 2001 16:36:07 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Sid Wilson <swilson@fps-edl.com>
Cc: "Fwtk-Users E-mail\"" <fwtk-users@lists.nai.com>
Subject: Re: help with "n2a get_local_info"
Message-Id: <20010305163607.J20366@washington.cospo.osis.gov>
Mail-Followup-To: Sid Wilson <swilson@fps-edl.com>,
	"Fwtk-Users E-mail\"" <fwtk-users@lists.nai.com>
References: <003501c0a35f$33079750$041da8c0@fpsedl.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <003501c0a35f$33079750$041da8c0@fpsedl.com>; from swilson@fps-edl.com on Fri, Mar 02, 2001 at 04:24:42PM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 863

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Mar 02, 2001 at 04:24:42PM -0500, Sid Wilson wrote:
> I'm sure this is a simple one, but I haven't been able to discover the
> source of this message:
> 
> Mar  2 15:53:21 igate http-gw[12855]: n2a get_local_info: open to get
> interface configuration: No such file or directory
> 
> I haven't really been able to discern a pattern to the message either.
> Can someone help point me in the right direction?
> 
> Thanks:
> 
> Sid Wilson

What OS?  What version?  When does this happen?  I am puzzled.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Tue Mar  6 06:13 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA15868
	Tue, 6 Mar 2001 06:12:59 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA00048;
	Tue, 6 Mar 2001 03:15:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 01:56:34 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA28242
	for fwtk-users-outgoing; Tue, 6 Mar 2001 01:56:23 -0800 (PST)
Date: Tue,  6 Mar 2001 10:55:24 +0100
Message-Id: <G9RSWC$InlrevzYHK_ZDlKqeDrSrV_Yj2bon1OuNvHqukH2lFez3fXy@respublica.fr>
Subject: problems with chrooting. 
MIME-Version: 1.0
From: "qgiorgi@respublica.fr"<qgiorgi@respublica.fr>
To: fwtk-users@lists.nai.com
X-XaM3-API-Version: 1.1.9.1.22
X-SenderIP: 212.234.59.105
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id BAA28238
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 4446

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all, 

I am currently working with fwtk2.1, and i have some 
prolems to make plug-gw working correctly on my red-hat 
6.1 linux. 

First of all, in the manpages I saw the support of 
userid and groupid, but with a look at the source, i 
didn't manage to find it. So i added this few lines in 
plug-gw.c (shown in annex) and now it seems to work 
fine. ( childs runs under the unpriviledged userid).

I also decided to chroot this plug-gw and here i have 
still problems with name resolution (in syslog logs I 
only have IPs but not names, and rules cannot be set 
using names ( even if a line is added in 
$jail/etc/hosts). When i run chroot $jail /usr/bin/plug-
gw -daemon 7070

here is the config: 
# file plug-gw
plug-gw: ELF 32-bit LSB executable, Intel 80386,version 
1, statically linked, not stripped
(I compiled it statically so i think i should not have 
to copy libs ) 

the simple jail is: 

# ls -lR $jail
/home/quentin/jail:
total 12
drwxr-xr-x   2 root     users        4096 Mar  4 04:02 
dev
drwxr-xr-x   2 root     users        4096 Mar  6 10:38 
etc
drwxr-xr-x   4 root     users        4096 Mar  5 14:26 
usr

/home/quentin/jail/dev:
total 0
srw-rw-rw-   1 root     users           0 Mar  4 04:02 
log

/home/quentin/jail/etc:
total 20
-rw-r--r--   1 root     users          28 Mar  2 15:04 
group
-rwxr-xr-x   1 root     users          93 Mar  5 14:11 
hosts
-rw-r--r--   1 root     users        1727 Mar  2 15:01 
nsswitch.conf
-rw-r--r--   1 root     users         100 Mar  5 18:39 
passwd
-rw-r--r--   1 root     users           1 Mar  5 14:12 
resolv.conf

/home/quentin/jail/usr:
total 8
drwxr-xr-x   2 root     users        4096 Mar  5 18:28 
bin
drwxr-xr-x   3 root     users        4096 Mar  5 18:28 
local

/home/quentin/jail/usr/bin:
total 3008
-rwxr-xr-x   1 root     users     1594385 Mar  5 13:17 
plug-gw
-rwxr-xr-x   1 root     root      1470509 Mar  6 09:21 
udprelay

/home/quentin/jail/usr/local:
total 4
drwxr-xr-x   2 root     users        4096 Mar  5 18:29 
etc

/home/quentin/jail/usr/local/etc:
total 8
-rw-r--r--   1 root     users         229 Mar  5 18:10 
netperm-table
-rw-r--r--   1 root     root           44 Mar  5 18:29 
udp-netperm-table


Note: 
I also do the same thing with udprelay and encounter 
the same kind of problem with id in $jail/etc/passwd 
when compiled with NOBODY=nobody 
even if nobody is in my $jail/etc/paswd. 

I'd be very happy if someone could help me :) 

Thanks 
Quentin. 

ANNEX: 
55,56d54
<       int             rungid = -1;
<       int             runuid = -1;
119,144d116
< /*BEGIN:  ADD ON TO SUPPORT GROUPID AND USERID OPTION 
*/
<       if((cf = cfg_get("groupid",cfp)) != (Cfg *)0) {
<
<                 if(cf->argc != 1) {
<                         syslog(LLEV,"fwtkcfgerr: 
groupid must have one paramet
er,line %d",cf->ln);
<                         exit(1);
<                 }
<                 if((rungid = mapgid(cf->argv[0])) == -
1) {
<                         syslog(LLEV,"fwtkcfgerr: 
cannot map %.100s to gid",cf-
>argv[0]);
<                         exit(1);
<                 }
<         }
<
<       if((cf = cfg_get("userid",cfp)) != (Cfg *)0) {
<
<                 if(cf->argc != 1) {
<                         syslog(LLEV,"fwtkcfgerr: 
userid must have one paramete
r,line %d",cf->ln);
<                         exit(1);
<                 }
<                 if((runuid = mapuid(cf->argv[0])) == -
1) {
<                         syslog(LLEV,"fwtkcfgerr: 
cannot map %.100s to uid",cf-
>argv[0]);
<                         exit(1);
<                 }
<         }
< /* END:  ADD ON TO SUPPORT USERID AND GROUPID OPTION 
*/
<
159,168d130
< /*BEGIN:  ADD ON TO SUPPORT USERID AND GROUPID OPTION 
*/
<      if(rungid != -1 && setgid(rungid)) {
<              syslog(LLEV,"fwtksyserr: cannot setgid %
d: %m",rungid);
<              exit(1);
<      }
<      if(runuid != -1 && setuid(runuid)) {
<              syslog(LLEV,"fwtksyserr: cannot setuid %
d: %m",runuid);
<              exit(1);
<      }
<
170d131
< /*END:  ADD ON TO SUPPORT USERID AND GROUPID OPTION */

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Choisissez les offres que vous voulez recevoir
Et gagnez une playstation 2 ou des baladeurs MP3 
----> http://www.respublica.fr/site/yoptin <----
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



From owner-fwtk-users@ex.tis.com Tue Mar  6 08:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA16423
	Tue, 6 Mar 2001 08:43:15 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA04283;
	Tue, 6 Mar 2001 05:45:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 04:46:39 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA02257
	for fwtk-users-outgoing; Tue, 6 Mar 2001 04:46:23 -0800 (PST)
MIME-Version: 1.0
Message-Id: <3AA49924.12727@mta6.263.net>
Date: Tue, 6 Mar 2001 16:00:36 +0800 (CST)
From: "hedeuong" <hedyong@263.net>
To: fwtk-users@lists.nai.com
Subject: ask help
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 322

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Where can I get sourecode of  s/key

_____________________________________________
妇女节送她一束花 
http://shopping.263.net/category12.htm
新品玩具上市
http://shopping.263.net/category20.htm


From owner-fwtk-users@ex.tis.com Tue Mar  6 11:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA17013
	Tue, 6 Mar 2001 11:08:45 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA12204;
	Tue, 6 Mar 2001 08:11:08 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 07:08:24 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA08436
	for fwtk-users-outgoing; Tue, 6 Mar 2001 07:08:08 -0800 (PST)
Date: Tue,  6 Mar 2001 16:07:14 +0100
Message-Id: <G9S7C2$IyntYlJOfI9fFnIkQBpUtX8md0Zuh3MqxsFso9Fo7Hc1xdV8@respublica.fr>
Subject: Re: ask help 
MIME-Version: 1.0
From: "qgiorgi@respublica.fr"<qgiorgi@respublica.fr>
To: fwtk-users@lists.nai.com
X-XaM3-API-Version: 1.1.9.1.22
X-SenderIP: 212.234.59.105
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id HAA08433
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 483

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>Where can I get sourecode of  s/key

You can try in ftp thumper.bellcore.com in pub/nmh/skey.

Quentin.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Choisissez les offres que vous voulez recevoir
Et gagnez une playstation 2 ou des baladeurs MP3 
----> http://www.respublica.fr/site/yoptin <----
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



From owner-fwtk-users@ex.tis.com Tue Mar  6 12:17 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA17187
	Tue, 6 Mar 2001 12:17:16 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA17595;
	Tue, 6 Mar 2001 09:19:35 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 08:18:17 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA12741
	for fwtk-users-outgoing; Tue, 6 Mar 2001 08:18:02 -0800 (PST)
Date: Tue, 6 Mar 2001 10:10:58 -0600 (CST)
From: Jeff Barnette <barnette@alamo.satlug.org>
To: <fwtk-users@lists.nai.com>
Subject: Maintaining timestamps with ftp-gw
Message-ID: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 834

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I asked this question 2 weeks ago and got zero replies.  I'll ask it once
more before putting it in the "nobody knows and they're not sending 'I
dunno' responses".

This regards a RedHat 6.2 box using ncftp as the ftp client.

ncftp has a handy feature whereby it can skip any download where a file
already exists on the local machine with the same name, size and
timestamp.  This works great for me when I use my dial-up connection,
which doesn't go through the ftp-gw.  However, when I use my network
connection at work, which _does_ go through the ftp-gw, the timestamps
always get set to the current time.  Is there a 'switch' or other
technique that I haven't found yet?

Thanks for any help,

Jeff


From owner-fwtk-users@ex.tis.com Tue Mar  6 14:06 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA17504
	Tue, 6 Mar 2001 14:06:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA25703;
	Tue, 6 Mar 2001 11:08:56 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 10:02:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA20573
	for fwtk-users-outgoing; Tue, 6 Mar 2001 10:01:52 -0800 (PST)
Date: Tue, 6 Mar 2001 12:59:42 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Jeff Barnette <barnette@alamo.satlug.org>
cc: fwtk-users@lists.nai.com
Subject: Re: Maintaining timestamps with ftp-gw
In-Reply-To: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
Message-ID: <Pine.GSO.4.10.10103061257080.544-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1512

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jeff,

Well I'll respond but I don't know the answer.  Question, however, what
timestamp does your ftp client use to determine if it is new?  The last
updated? date created? or some other time maintained by the OS.  Would
probably like to put a trace on the client to see what it is sending to
the server; same with the ftp-gw - and see what the different responses
are.  The ftp-gw isn't too bad if we have to do a small code hack to
include that support.

tek


On Tue, 6 Mar 2001, Jeff Barnette wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I asked this question 2 weeks ago and got zero replies.  I'll ask it once
> more before putting it in the "nobody knows and they're not sending 'I
> dunno' responses".
> 
> This regards a RedHat 6.2 box using ncftp as the ftp client.
> 
> ncftp has a handy feature whereby it can skip any download where a file
> already exists on the local machine with the same name, size and
> timestamp.  This works great for me when I use my dial-up connection,
> which doesn't go through the ftp-gw.  However, when I use my network
> connection at work, which _does_ go through the ftp-gw, the timestamps
> always get set to the current time.  Is there a 'switch' or other
> technique that I haven't found yet?
> 
> Thanks for any help,
> 
> Jeff
> 


From owner-fwtk-users@ex.tis.com Tue Mar  6 14:45 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA17633
	Tue, 6 Mar 2001 14:45:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA28966;
	Tue, 6 Mar 2001 11:48:10 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 10:40:36 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA23417
	for fwtk-users-outgoing; Tue, 6 Mar 2001 10:40:15 -0800 (PST)
From: ark@eltex.ru
Date: Tue, 6 Mar 2001 21:49:13 +0300
Message-Id: <200103061849.VAA06965@paranoid.alpha.int>
Organization: "Klingon Imperial Intelligence Service"
Subject: protecting the server?
To: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 928

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

nuqneH,

As we all know, fwtk proxies are designed to protect client, not server.

Acutally all firewalls on the market are. But - there is one thing that
(somehow) impressed me: see http://www.sanctuminc.com/.

So the questions is: can we expand http-in functionality to perform similar
task? I'd say it in other words: are generic size/header based checks 
+ sophisticated set of url regexps enough to perform such a task?

Does anybody here have a personal expirience with sanctum product?
Any comments?

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

From owner-fwtk-users@ex.tis.com Tue Mar  6 18:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA18398
	Tue, 6 Mar 2001 18:40:29 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA07156;
	Tue, 6 Mar 2001 15:42:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 14:26:19 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA13157
	for fwtk-users-outgoing; Tue, 6 Mar 2001 14:25:59 -0800 (PST)
Message-ID: <91A5926EFF44D3118B1200104B7276EB654F64@hart-exchange.hartwellcorp.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "FWTK Users Mailing List (E-mail)" <fwtk-users@ex.tis.com>
Subject: Trouble compiling ms-sql-gw addon
Date: Tue, 6 Mar 2001 11:21:54 -0800 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1217

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I am trying to get the ms-sql-gw addon to compile using the crypto functions
from openssl.  This is on a RedHat 7.0 i386 system.  I've modified the
include line to find the "blowfish.h" file but I still get the following
errors:

gcc -I.. -O -DLINUX -DPROTECTINBOUND   -c -o ms-sql-gw.o ms-sql-gw.c
In file included from ms-sql-gw.c:25:
/usr/include/md5.h:27: parse error before `UINT4'
/usr/include/md5.h:27: warning: no semicolon at end of struct or union
/usr/include/md5.h:28: warning: data definition has no type or storage class
/usr/include/md5.h:30: parse error before `}'
/usr/include/md5.h:30: warning: data definition has no type or storage class
/usr/include/md5.h:32: parse error before `PROTO_LIST'
/usr/include/md5.h:33: parse error before `PROTO_LIST'
/usr/include/md5.h:35: parse error before `PROTO_LIST'
/usr/include/md5.h:37: parse error before `PROTO_LIST'
ms-sql-gw.c:81: parse error before `md5_ctx'
ms-sql-gw.c:81: warning: data definition has no type or storage class
make: *** [ms-sql-gw.o] Error 1

--------------------
Michael St. Laurent
Hartwell Corporation

From owner-fwtk-users@ex.tis.com Tue Mar  6 18:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA18411
	Tue, 6 Mar 2001 18:53:59 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA10626;
	Tue, 6 Mar 2001 15:56:24 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 14:53:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA21383
	for fwtk-users-outgoing; Tue, 6 Mar 2001 14:53:44 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3AA51A64.D25C963B@peaktime.be>
Date: Tue, 06 Mar 2001 18:12:04 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Re: Maintaining timestamps with ftp-gw
References: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1456

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jeff Barnette wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > I asked this question 2 weeks ago and got zero replies.  I'll ask it once
 > more before putting it in the "nobody knows and they're not sending 'I
 > dunno' responses".
 > 
 > This regards a RedHat 6.2 box using ncftp as the ftp client.
 > 
 > ncftp has a handy feature whereby it can skip any download where a file
 > already exists on the local machine with the same name, size and
 > timestamp.  This works great for me when I use my dial-up connection,
 > which doesn't go through the ftp-gw.  However, when I use my network
 > connection at work, which _does_ go through the ftp-gw, the timestamps
 > always get set to the current time.  

This is unclear. Which timestamps? Which current time?

 > Is there a 'switch' or other
 > technique that I haven't found yet?
 > 
 > Thanks for any help,
 > 
 > Jeff

Could you do the same ftp session, in debug mode (if ncftp can't do
that, use the vanilla ftp client), once through the ftp-gw and once
through your dialup, so we can see which commands are issued and what
they return?

-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10


From owner-fwtk-users@ex.tis.com Tue Mar  6 19:32 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA18541
	Tue, 6 Mar 2001 19:32:19 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA18450;
	Tue, 6 Mar 2001 16:34:43 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 6 Mar 2001 15:30:49 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA03633
	for fwtk-users-outgoing; Tue, 6 Mar 2001 15:30:33 -0800 (PST)
Message-Id: <5.0.2.1.0.20010306182343.01d5b610@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 06 Mar 2001 18:24:55 -0500
To: "qgiorgi@respublica.fr"<qgiorgi@respublica.fr>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: problems with chrooting. 
In-Reply-To: <G9RSWC$InlrevzYHK_ZDlKqeDrSrV_Yj2bon1OuNvHqukH2lFez3fXy@re
 spublica.fr>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 610

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 10:55 AM 3/6/01 +0100, qgiorgi@respublica.fr wrote:
>here is the config:
># file plug-gw
>plug-gw: ELF 32-bit LSB executable, Intel 80386,version
>1, statically linked, not stripped
>(I compiled it statically so i think i should not have
>to copy libs )

Not necessarily true - some operating systems always use shared libraries 
for their resolver routines (Solaris). It wouldn't surprise me that you're 
missing a libresolv.so or some such in the chroot area.
         -Rick


From owner-fwtk-users@ex.tis.com Wed Mar  7 04:57 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA19744
	Wed, 7 Mar 2001 04:56:55 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA14709;
	Wed, 7 Mar 2001 01:59:13 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 00:54:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA12902
	for fwtk-users-outgoing; Wed, 7 Mar 2001 00:54:47 -0800 (PST)
X-Authentication-Warning: proxy.hundert6.de: mail set sender to <jan@radio.hundert6.de> using -f
Message-ID: <3AA6052B.E39DD5F1@radio.hundert6.de>
Date: Wed, 07 Mar 2001 09:53:47 +0000
From: Jan Muenther <jan@radio.hundert6.de>
Organization: Radio Hundert,6
X-Mailer: Mozilla 4.72 [en] (X11; I; FreeBSD 4.2-STABLE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: smap anti-spoof
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 884

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello there,

I wonder whether the yao-patched smap's default behaviour is to
reject mail from hosts which cause a name lookup mismatch is to
reject them...?!

I currently have problems with one person who's mailserver
obviously has a different forward / reverse resolution and this
person is the only one complaining about mail problems. 

In my system's logfiles I only find messages about a possible
spoof and it doesn't look like mail's delivered. From the other
side, the smtp connection is obviously ended by a 451 error and
it doesn't look like mail is delivered. Strangely, this only
seems to occur occasionally, sometimes mail hust gets through...
any hints?

Ciao, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Wed Mar  7 10:24 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA20521
	Wed, 7 Mar 2001 10:24:15 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA02155;
	Wed, 7 Mar 2001 07:26:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 06:01:47 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA22383
	for fwtk-users-outgoing; Wed, 7 Mar 2001 06:01:21 -0800 (PST)
Message-Id: <5.0.2.1.0.20010306181844.01d584c0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 06 Mar 2001 18:23:15 -0500
To: Jeff Barnette <barnette@alamo.satlug.org>, <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Maintaining timestamps with ftp-gw
In-Reply-To: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1063

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 10:10 AM 3/6/01 -0600, Jeff Barnette wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >I asked this question 2 weeks ago and got zero replies.  I'll ask it once
 >more before putting it in the "nobody knows and they're not sending 'I
 >dunno' responses".

OK, "I dunno". However..
How is ncftp getting the creation date of the remote file?  Somehow, ncftp 
isn't getting the information it needs to set the creation date on files 
you receive.
There isn't any way using the FTP protocol to reliably do that. (You can 
parse the output of a LIST command, but that's OS dependent.)
If ncftp is using an "X" command that ftp-gw is rejecting, you'll find it 
in the fwtk log file; adding that command to the command table may fix it.
(Basically, what they're trying to do can't be done reliably. This is a 
case in point.)
          -Rick



From owner-fwtk-users@ex.tis.com Wed Mar  7 10:24 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA20520
	Wed, 7 Mar 2001 10:24:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA02151;
	Wed, 7 Mar 2001 07:26:26 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 06:14:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA23826
	for fwtk-users-outgoing; Wed, 7 Mar 2001 06:14:15 -0800 (PST)
Date: Wed, 7 Mar 2001 12:06:46 +0100 ("MET)
From: philipp@gandalf.mathematik.uni-freiburg.de (Philipp Schott)
Message-Id: <200103071106.MAA07566@gandalf.mathematik.uni-freiburg.de>
To: fwtk-users@lists.nai.com
Subject: fwtk in bridge mode
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1061

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hi,

i've got one question and could not find the
answer on the net. i think of using fwtk but
i'm not sure whether it works...

i'd like to setup a bridging firewall under
openbsd2.8 with ipf. unfortunately this is
only a packet filter and i'd like to check
data also on application level. here comes my
question: is it possible to utilize fwtk on
a firewalling bridge, i.e. the firewall is
completely transparent and has no ip etc. 
i don't see, how proxying works if you've got
no proxy ip to use. otoh is there any way to
check packets on the bridge on application
level? i don't see why it shouldn't work.

any hints?

tia,
philipp
========================================================================
   Philipp M. W. Schott                                  http://pmws.de  
    The Internet interprets censorship as damage and routes around it.   
========================================================================


From owner-fwtk-users@ex.tis.com Wed Mar  7 11:51 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA20734
	Wed, 7 Mar 2001 11:51:14 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA15731;
	Wed, 7 Mar 2001 08:53:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 07:47:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA05576
	for fwtk-users-outgoing; Wed, 7 Mar 2001 07:47:39 -0800 (PST)
X-Authentication-Warning: cor_smtp: smap set sender to <Chris.Hutchison@Brewers.Com> using -f
Message-ID: <037D9C3BD3CDD311B45A009027DE2EF8CB8911@DIAMOND>
From: "Hutchison, Chris" <Chris.Hutchison@Brewers.Com>
To: fwtk-users@lists.nai.com
Subject: Windows 2000 PPTP
Date: Wed, 7 Mar 2001 10:44:30 -0500 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 364

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Has anyone tried using Windows 2000 VPN through the FWTK?

I tried setting it up using plug-gw on port 1723 and it appears to make the
initial connection but not the return connection and times out.

Any input is appreciated.

Chris



From owner-fwtk-users@ex.tis.com Wed Mar  7 12:57 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA21045
	Wed, 7 Mar 2001 12:57:05 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA27126;
	Wed, 7 Mar 2001 09:59:22 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 08:51:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA15409
	for fwtk-users-outgoing; Wed, 7 Mar 2001 08:51:36 -0800 (PST)
Mime-Version: 1.0
Date: Wed, 7 Mar 2001 16:48:38 +0000
Message-ID: <0005992D.C22300@it.glasgow.gov.uk>
From: derek.torrance@it.glasgow.gov.uk (Derek Torrance)
Subject: netperm table corruption
To: fwtk-users@lists.nai.com
Content-Transfer-Encoding: 7bit
Content-Description: cc:Mail note part
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="US-ASCII"
Content-Length: 263

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

     
     Has anyone else had problems with their netperm table occasionally 
     becoming corrupted?
     
     thanks,
     derek

From owner-fwtk-users@ex.tis.com Wed Mar  7 13:19 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA21107
	Wed, 7 Mar 2001 13:19:08 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA00439;
	Wed, 7 Mar 2001 10:21:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 09:17:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA19950
	for fwtk-users-outgoing; Wed, 7 Mar 2001 09:16:55 -0800 (PST)
Date: Wed, 7 Mar 2001 12:15:04 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "Hutchison, Chris" <Chris.Hutchison@Brewers.Com>
cc: fwtk-users@lists.nai.com
Subject: Re: Windows 2000 PPTP
In-Reply-To: <037D9C3BD3CDD311B45A009027DE2EF8CB8911@DIAMOND>
Message-ID: <Pine.GSO.4.10.10103071213100.4408-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 831

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Chris,

I suspect the W2000 is the same as the nt4 protocol in that the remoted
connected machine wants to make an inbound connection to the initating
host using the GRE protocol.  The took-kit doesn't support GRE - I don't
linke inbound connectivity.

ted keller


On Wed, 7 Mar 2001, Hutchison, Chris wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Has anyone tried using Windows 2000 VPN through the FWTK?
> 
> I tried setting it up using plug-gw on port 1723 and it appears to make the
> initial connection but not the return connection and times out.
> 
> Any input is appreciated.
> 
> Chris
> 
> 


From owner-fwtk-users@ex.tis.com Wed Mar  7 17:44 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA22085
	Wed, 7 Mar 2001 17:44:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA08502;
	Wed, 7 Mar 2001 14:46:36 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 13:36:36 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA27807
	for fwtk-users-outgoing; Wed, 7 Mar 2001 13:36:15 -0800 (PST)
Date: Wed, 7 Mar 2001 16:34:31 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Derek Torrance <derek.torrance@it.glasgow.gov.uk>
cc: fwtk-users@lists.nai.com
Subject: Re: netperm table corruption
In-Reply-To: <0005992D.C22300@it.glasgow.gov.uk>
Message-ID: <Pine.GSO.4.10.10103071633270.13510-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 709

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Derek,

This should never happen.  The netperm-table is open read-only by all of
the fwtk applications.  The only thing that can write it is vi (or what
ever your favorite editor is).  Make sure no one else has access to your
firewall...

ted keller


On Wed, 7 Mar 2001, Derek Torrance wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
>      
>      Has anyone else had problems with their netperm table occasionally 
>      becoming corrupted?
>      
>      thanks,
>      derek
> 


From owner-fwtk-users@ex.tis.com Wed Mar  7 21:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA22702
	Wed, 7 Mar 2001 21:04:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA25967;
	Wed, 7 Mar 2001 18:07:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 16:54:01 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA21839
	for fwtk-users-outgoing; Wed, 7 Mar 2001 16:53:45 -0800 (PST)
From: "Brian Desmond" <bdesmond@au.infogrames.com>
To: <fwtk-users@lists.nai.com>
Subject: FW: Loopback and multi-homed routing flaw in TCP/IP stack.
Date: Thu, 8 Mar 2001 11:52:10 +1100
Message-ID: <NDBBLBCNGLKNBEMCOGCKOEJAEJAA.bdesmond@au.infogrames.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 9751

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi All,

No doubt many of you were following this thread on bugtraq over
the last couple of days. For those who weren't - don't panic
when you read this advisory - this was the first email of the 
thread, and should not be interpreted as the last word on this
issue.

However, the fact remains that even with ipforwarding disabled
on my Linux based fwtk proxy firewall, my internal interfaces are not 
completely hidden from those with evil intentions.

Forgive me if this is documented with fwtk - I have had another
quick look but I haven't seen this mentioned.

I'm going to come clean and say "I did not know this". 

So finally my question: 

What kind of packet filtering are people using to protect themselves
from this?

With thanks in advance,

Brian

> -----Original Message-----
> From: Bugtraq List [mailto:BUGTRAQ@SECURITYFOCUS.COM]On Behalf Of Woody
> Sent: Tuesday, 6 March 2001 6:45 AM
> To: BUGTRAQ@SECURITYFOCUS.COM
> Subject: Loopback and multi-homed routing flaw in TCP/IP stack.
> 
> 
> Subject: Loopback and multi-homed routing flaw in TCP/IP stack.
> Author: Woody <woody@thebunker.net>
> 
> We believe there to be a serious security flaw in the TCP/IP stack of
> several Unix-like operating systems. Whilst being "known" behavior on
> technical mailing lists, we feel that the implications of this
> "feature" are unexpected. Furthermore, not all platforms behave in the
> same way, which will obviously lead to invalid expectations.
> 
> PLEASE NOTE: We have received a lot of replies to this advisory from
>         developers who have missed the point. Before you reply, please
>         read the advisory at least twice, to ensure you understand its
>         implications, and scope.
> 
> The Issue:
> 
> There is a flaw in the TCP/IP stack, such that packets intended for
> loopback and/or local network interfaces, routed via any other
> interface, will be delivered EVEN IF THE MACHINE IS CONFIGURED NOT TO
> BE A GATEWAY (note that in the case of packets destined for the
> loopback interface, we consider this to be a fault no matter how the
> host is configured - see RFC 1122 comments below). This means that
> connections can be made to services that were intended to be invisible
> by virtue of the fact that they were only listening on the "inside" of
> a system. This may lead to further compromise of the host and/or
> connected networks, either via (e.g.) buffer overflows or enhanced
> privileges via access to SOCKS or other internal proxies.
> 
> Examples:
> 
> In these scenarios, the 213.129.64.x network represents the public
> internet, and 172.16.x.x the private, internal network.
> 
> Server 213.129.64.1 runs sendmail bound only to loopback on port 25,
> providing an outgoing smtp gateway for local programs. Attacker is on
> 213.129.64.2.
> 
>   213.129.64.2# route delete 127.0.0.1
>   delete host 127.0.0.1
>   213.129.64.2# route add 127.0.0.1 213.129.64.1
>   add host 127.0.0.1 gateway 213.129.64.1
>   213.129.64.2# telnet 127.0.0.1 25
>   Trying 127.0.0.1...
>   Connected to 127.0.0.1.
>   Escape character is '^]'.
>   220 eeek.woodyland.not ESMTP sendmail blah blah blah
> 
> Equally alarmingly, the same trick can be done for back end
> networks. In this example, 213.129.64.1 runs a SOCKS server, bound
> only to it's "internal network" on 172.16.1.1. A routed connection to
> this service potentially allow full access to internal and other
> network resources via SOCKSified clients.
> 
>   213.129.64.2# route add 172.16.1.1 213.129.64.1
>   add host 172.16.1.1: gateway 213.129.64.1
>   213.129.64.2# telnet 172.16.1.1 1080
>   Trying 172.16.1.1...
>   Connected to 172.16.1.1.
>   Escape character is '^]'.
> 
> So for example, an internal server on 172.16.1.2 running telnetd can
> now be connected to from 213.129.64.2:
> 
>    213.129.64.2# export SOCKS_SERVER=172.16.1.1
>    213.129.64.2# rtelnet 172.16.1.2
>    Trying 172.16.1.2...
>    Connected to kerpow.woodyland.not
>    Escape character is '^]'.
> 
>    02/02/01 22:25:32 on /dev/con1
>    Last login: 02/02/01 21:22:54 on /dev/con1
>    login:
> 
> At the moment, any machine which has either:
> 
> o       services running on the loopback interface
> 
> o       two or more external interfaces
> 
> must be configured, using a firewall, to drop IP packets arriving from
> the wrong network in order to be secure. This is commonly not the
> case.
> 
> 
> Known Vulnerable Systems:
> 
>         FreeBSD - all releases to date.
>         OpenBSD - all releases to date.
>         NetBSD  - all releases to date.
> 
> Known Not Vulnerable:
> 
>         Linux - RH6.2 stock kernel
> 
> As a checkpoint, one COTS o/s was tested:
> 
>         Solaris 5.6, 5.7 - although a connection to remote services can
>                            be established, a full two way session
>                            cannot, so it is unlikely that Solaris is
>                            truly vulnerable.
>                            Further investigation is advised.
> 
> Discussion:
> 
> Restrictions to the behavior of loopback packets are defined in RFC 1122
> section 3.2.1.3
>                 (g)  { 127, <any> }
>                       Internal host loopback address.  Addresses of this
>                       form MUST NOT appear outside a host.
> 
> Although this only constrains the output from the stack, in our opinion
> the implementation of this section should be extended to control the
> input as well, and this appears to be the consensus of the BSD groups.
> NOTE: This advisory is not about RFC compliance, it is about expected
> behavior.
> 
> *BSD groups were notified at the beginning of December 2000. Both
> FreeBSD and OpenBSD realised the need to resolve this problem and have
> endeavored to produce a patch. We understand that there are some things
> in OpenBSD which rely on the fact that the loopback interface is not
> routable, and as a result of this not being the case, remote holes may
> be exposed.
> 
> The NetBSD group have made the following statement:
> 
>     This is not a new "discovery".  The "correct" behavior of
>     multi-homed host stacks in this case has been the subject of
>     substantial debate in the networking community. Changing this
>     behavior has been discussed in the past, but involves many
>     complications and cases. NetBSD strongly recommends that users
>     running multi-homed hosts, where the interfaces are separated into
>     different security domains, should use appropriate filters which
>     include source address spoofing detection. NetBSD provides the
>     ipfilter mechanism for this purpose, and have issued a patch for
>     the loopback issue (below).
> 
> Rant:
> 
> quoting Obvious Security Inc. Bulletin #2600:
> 
>     Remember - "Just because it's right in your face, does
>     not mean that it's obvious".
> 
> Fix:
> 
> FreeBSD:
> 
> Ben Laurie has written a patch for FreeBSD (tested on 3.x and 4.x). This
> patch IS NOT COMPLETE by any means, but it does the job for simple
> cases. Further modification is required to ensure all routing
> scenarios behave correctly. Angelos Keromytis <angelos@keromytis.org>
> has observed that this patch will not allow packets to be routed to
> the remote interfaces themselves even if routing is enabled, and that
> encapsulation protocols that use virtual interfaces will probably be
> broken by it, however a patch that fixes these problems is not
> currently available.
> 
> We recommend that ipfw is used instead of our patch in these
> scenarios, pending a complete fix for FreeBSD.
> 
> The FreeBSD group have added some fixes to 4.2-current, and serious
> users should follow their progress.
> 
> 
> --- /usr/src/sys/netinet/ip_input.c.org Sun Dec 17 16:04:49 2000
> +++ /usr/src/sys/netinet/ip_input.c     Mon Dec 18 16:46:14 2000
> @@ -486,7 +486,9 @@
> 
>                                         ip_fw_fwd_addr->sin_addr.s_addr)
>                         goto ours;
>  #else
> -               if (IA_SIN(ia)->sin_addr.s_addr == ip->ip_dst.s_addr)
> +               if (IA_SIN(ia)->sin_addr.s_addr == ip->ip_dst.s_addr
> +                   && (ia->ia_ifp == m->m_pkthdr.rcvif
> +                       || m->m_pkthdr.rcvif->if_flags & IFF_LOOPBACK))
>                         goto ours;
>  #endif
>                 if (ia->ia_ifp && ia->ia_ifp->if_flags & IFF_BROADCAST)
> {
> 
> OpenBSD:
> 
> The OpenBSD group are expected to publish a patch shortly.
> 
> NetBSD:
> 
> The following patch to sys/netinet/ip_input.c is now in
> NetBSD-current.  This patch disables reception of external packets
> with source or destination in the 127/8 network. NetBSD will advise
> users when this change is incorporated into the release branches;
> concerned users may apply the patch now.
> 
> *** ip_input.c  2001/03/01 16:31:39     1.128
> --- ip_input.c  2001/03/02 02:05:36     1.129
> ***************
> *** 416,421 ****
> --- 416,428 ----
>         if (IN_MULTICAST(ip->ip_src.s_addr)) {
>                 /* XXX stat */
>                 goto bad;
> +       }
> +
> +       /* 127/8 must not appear on wire - RFC1122 */
> +       if ((ntohl(ip->ip_dst.s_addr) >> IN_CLASSA_NSHIFT) ==
> IN_LOOPBACKNET ||
> +           (ntohl(ip->ip_src.s_addr) >> IN_CLASSA_NSHIFT) ==
> IN_LOOPBACKNET) {
> +               if ((m->m_pkthdr.rcvif->if_flags & IFF_LOOPBACK) == 0)
> +                       goto bad;
>         }
> 
>         if (in_cksum(m, hlen) != 0) {
> 
> Acknowledgments:
> 
>   Woody       <woody@thebunker.net>
>   Adam Laurie <adam@algroup.co.uk>
>   Ben Laurie  <ben@algroup.co.uk>
>   Doug Lang   <doug@thebunker.net>
>   http://www.thebunker.net
> 

From owner-fwtk-users@ex.tis.com Thu Mar  8 00:32 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA23299
	Thu, 8 Mar 2001 00:32:35 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA05632;
	Wed, 7 Mar 2001 21:35:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 7 Mar 2001 20:31:38 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id UAA03004
	for fwtk-users-outgoing; Wed, 7 Mar 2001 20:31:17 -0800 (PST)
Message-Id: <5.0.2.1.0.20010307232705.01d5b5c0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 07 Mar 2001 23:30:42 -0500
To: "Brian Desmond" <bdesmond@au.infogrames.com>, <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FW: Loopback and multi-homed routing flaw in TCP/IP stack.
In-Reply-To: <NDBBLBCNGLKNBEMCOGCKOEJAEJAA.bdesmond@au.infogrames.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 757

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:52 AM 3/8/01 +1100, Brian Desmond wrote:
>What kind of packet filtering are people using to protect themselves
>from this?

Most any anti-spoofing will fix this - the problem in the Bugtraq article 
is, after all, a local one - someone on one of the subnets directly 
connected to your firewall sends a packet through the firewall to 127.0.0.1 
and it's accepted. Fortunately, most people have a router between the 
internet and their firewall, so there's no untrusted users on that subnet.

You can just add 127.0.0.0/8 to your martian filter on your firewall (the 
one that denies 10.*, 192.168.*, etc.)
         -Rick


From owner-fwtk-users@ex.tis.com Thu Mar  8 10:55 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA25245
	Thu, 8 Mar 2001 10:55:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA01685;
	Thu, 8 Mar 2001 07:57:46 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 06:53:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA24298
	for fwtk-users-outgoing; Thu, 8 Mar 2001 06:53:24 -0800 (PST)
Date: Thu, 8 Mar 2001 09:51:24 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Brian Desmond <bdesmond@au.infogrames.com>
cc: fwtk-users@lists.nai.com
Subject: Re: FW: Loopback and multi-homed routing flaw in TCP/IP stack.
In-Reply-To: <NDBBLBCNGLKNBEMCOGCKOEJAEJAA.bdesmond@au.infogrames.com>
Message-ID: <Pine.GSO.4.10.10103080950340.29657-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 10569

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

If you are running solaris - you can use the ndd command


/usr/sbin/ndd -set /dev/ip ip_strict_dst_multihoming 1


ted keller


On Thu, 8 Mar 2001, Brian Desmond wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hi All,
> 
> No doubt many of you were following this thread on bugtraq over
> the last couple of days. For those who weren't - don't panic
> when you read this advisory - this was the first email of the 
> thread, and should not be interpreted as the last word on this
> issue.
> 
> However, the fact remains that even with ipforwarding disabled
> on my Linux based fwtk proxy firewall, my internal interfaces are not 
> completely hidden from those with evil intentions.
> 
> Forgive me if this is documented with fwtk - I have had another
> quick look but I haven't seen this mentioned.
> 
> I'm going to come clean and say "I did not know this". 
> 
> So finally my question: 
> 
> What kind of packet filtering are people using to protect themselves
> from this?
> 
> With thanks in advance,
> 
> Brian
> 
> > -----Original Message-----
> > From: Bugtraq List [mailto:BUGTRAQ@SECURITYFOCUS.COM]On Behalf Of Woody
> > Sent: Tuesday, 6 March 2001 6:45 AM
> > To: BUGTRAQ@SECURITYFOCUS.COM
> > Subject: Loopback and multi-homed routing flaw in TCP/IP stack.
> > 
> > 
> > Subject: Loopback and multi-homed routing flaw in TCP/IP stack.
> > Author: Woody <woody@thebunker.net>
> > 
> > We believe there to be a serious security flaw in the TCP/IP stack of
> > several Unix-like operating systems. Whilst being "known" behavior on
> > technical mailing lists, we feel that the implications of this
> > "feature" are unexpected. Furthermore, not all platforms behave in the
> > same way, which will obviously lead to invalid expectations.
> > 
> > PLEASE NOTE: We have received a lot of replies to this advisory from
> >         developers who have missed the point. Before you reply, please
> >         read the advisory at least twice, to ensure you understand its
> >         implications, and scope.
> > 
> > The Issue:
> > 
> > There is a flaw in the TCP/IP stack, such that packets intended for
> > loopback and/or local network interfaces, routed via any other
> > interface, will be delivered EVEN IF THE MACHINE IS CONFIGURED NOT TO
> > BE A GATEWAY (note that in the case of packets destined for the
> > loopback interface, we consider this to be a fault no matter how the
> > host is configured - see RFC 1122 comments below). This means that
> > connections can be made to services that were intended to be invisible
> > by virtue of the fact that they were only listening on the "inside" of
> > a system. This may lead to further compromise of the host and/or
> > connected networks, either via (e.g.) buffer overflows or enhanced
> > privileges via access to SOCKS or other internal proxies.
> > 
> > Examples:
> > 
> > In these scenarios, the 213.129.64.x network represents the public
> > internet, and 172.16.x.x the private, internal network.
> > 
> > Server 213.129.64.1 runs sendmail bound only to loopback on port 25,
> > providing an outgoing smtp gateway for local programs. Attacker is on
> > 213.129.64.2.
> > 
> >   213.129.64.2# route delete 127.0.0.1
> >   delete host 127.0.0.1
> >   213.129.64.2# route add 127.0.0.1 213.129.64.1
> >   add host 127.0.0.1 gateway 213.129.64.1
> >   213.129.64.2# telnet 127.0.0.1 25
> >   Trying 127.0.0.1...
> >   Connected to 127.0.0.1.
> >   Escape character is '^]'.
> >   220 eeek.woodyland.not ESMTP sendmail blah blah blah
> > 
> > Equally alarmingly, the same trick can be done for back end
> > networks. In this example, 213.129.64.1 runs a SOCKS server, bound
> > only to it's "internal network" on 172.16.1.1. A routed connection to
> > this service potentially allow full access to internal and other
> > network resources via SOCKSified clients.
> > 
> >   213.129.64.2# route add 172.16.1.1 213.129.64.1
> >   add host 172.16.1.1: gateway 213.129.64.1
> >   213.129.64.2# telnet 172.16.1.1 1080
> >   Trying 172.16.1.1...
> >   Connected to 172.16.1.1.
> >   Escape character is '^]'.
> > 
> > So for example, an internal server on 172.16.1.2 running telnetd can
> > now be connected to from 213.129.64.2:
> > 
> >    213.129.64.2# export SOCKS_SERVER=172.16.1.1
> >    213.129.64.2# rtelnet 172.16.1.2
> >    Trying 172.16.1.2...
> >    Connected to kerpow.woodyland.not
> >    Escape character is '^]'.
> > 
> >    02/02/01 22:25:32 on /dev/con1
> >    Last login: 02/02/01 21:22:54 on /dev/con1
> >    login:
> > 
> > At the moment, any machine which has either:
> > 
> > o       services running on the loopback interface
> > 
> > o       two or more external interfaces
> > 
> > must be configured, using a firewall, to drop IP packets arriving from
> > the wrong network in order to be secure. This is commonly not the
> > case.
> > 
> > 
> > Known Vulnerable Systems:
> > 
> >         FreeBSD - all releases to date.
> >         OpenBSD - all releases to date.
> >         NetBSD  - all releases to date.
> > 
> > Known Not Vulnerable:
> > 
> >         Linux - RH6.2 stock kernel
> > 
> > As a checkpoint, one COTS o/s was tested:
> > 
> >         Solaris 5.6, 5.7 - although a connection to remote services can
> >                            be established, a full two way session
> >                            cannot, so it is unlikely that Solaris is
> >                            truly vulnerable.
> >                            Further investigation is advised.
> > 
> > Discussion:
> > 
> > Restrictions to the behavior of loopback packets are defined in RFC 1122
> > section 3.2.1.3
> >                 (g)  { 127, <any> }
> >                       Internal host loopback address.  Addresses of this
> >                       form MUST NOT appear outside a host.
> > 
> > Although this only constrains the output from the stack, in our opinion
> > the implementation of this section should be extended to control the
> > input as well, and this appears to be the consensus of the BSD groups.
> > NOTE: This advisory is not about RFC compliance, it is about expected
> > behavior.
> > 
> > *BSD groups were notified at the beginning of December 2000. Both
> > FreeBSD and OpenBSD realised the need to resolve this problem and have
> > endeavored to produce a patch. We understand that there are some things
> > in OpenBSD which rely on the fact that the loopback interface is not
> > routable, and as a result of this not being the case, remote holes may
> > be exposed.
> > 
> > The NetBSD group have made the following statement:
> > 
> >     This is not a new "discovery".  The "correct" behavior of
> >     multi-homed host stacks in this case has been the subject of
> >     substantial debate in the networking community. Changing this
> >     behavior has been discussed in the past, but involves many
> >     complications and cases. NetBSD strongly recommends that users
> >     running multi-homed hosts, where the interfaces are separated into
> >     different security domains, should use appropriate filters which
> >     include source address spoofing detection. NetBSD provides the
> >     ipfilter mechanism for this purpose, and have issued a patch for
> >     the loopback issue (below).
> > 
> > Rant:
> > 
> > quoting Obvious Security Inc. Bulletin #2600:
> > 
> >     Remember - "Just because it's right in your face, does
> >     not mean that it's obvious".
> > 
> > Fix:
> > 
> > FreeBSD:
> > 
> > Ben Laurie has written a patch for FreeBSD (tested on 3.x and 4.x). This
> > patch IS NOT COMPLETE by any means, but it does the job for simple
> > cases. Further modification is required to ensure all routing
> > scenarios behave correctly. Angelos Keromytis <angelos@keromytis.org>
> > has observed that this patch will not allow packets to be routed to
> > the remote interfaces themselves even if routing is enabled, and that
> > encapsulation protocols that use virtual interfaces will probably be
> > broken by it, however a patch that fixes these problems is not
> > currently available.
> > 
> > We recommend that ipfw is used instead of our patch in these
> > scenarios, pending a complete fix for FreeBSD.
> > 
> > The FreeBSD group have added some fixes to 4.2-current, and serious
> > users should follow their progress.
> > 
> > 
> > --- /usr/src/sys/netinet/ip_input.c.org Sun Dec 17 16:04:49 2000
> > +++ /usr/src/sys/netinet/ip_input.c     Mon Dec 18 16:46:14 2000
> > @@ -486,7 +486,9 @@
> > 
> >                                         ip_fw_fwd_addr->sin_addr.s_addr)
> >                         goto ours;
> >  #else
> > -               if (IA_SIN(ia)->sin_addr.s_addr == ip->ip_dst.s_addr)
> > +               if (IA_SIN(ia)->sin_addr.s_addr == ip->ip_dst.s_addr
> > +                   && (ia->ia_ifp == m->m_pkthdr.rcvif
> > +                       || m->m_pkthdr.rcvif->if_flags & IFF_LOOPBACK))
> >                         goto ours;
> >  #endif
> >                 if (ia->ia_ifp && ia->ia_ifp->if_flags & IFF_BROADCAST)
> > {
> > 
> > OpenBSD:
> > 
> > The OpenBSD group are expected to publish a patch shortly.
> > 
> > NetBSD:
> > 
> > The following patch to sys/netinet/ip_input.c is now in
> > NetBSD-current.  This patch disables reception of external packets
> > with source or destination in the 127/8 network. NetBSD will advise
> > users when this change is incorporated into the release branches;
> > concerned users may apply the patch now.
> > 
> > *** ip_input.c  2001/03/01 16:31:39     1.128
> > --- ip_input.c  2001/03/02 02:05:36     1.129
> > ***************
> > *** 416,421 ****
> > --- 416,428 ----
> >         if (IN_MULTICAST(ip->ip_src.s_addr)) {
> >                 /* XXX stat */
> >                 goto bad;
> > +       }
> > +
> > +       /* 127/8 must not appear on wire - RFC1122 */
> > +       if ((ntohl(ip->ip_dst.s_addr) >> IN_CLASSA_NSHIFT) ==
> > IN_LOOPBACKNET ||
> > +           (ntohl(ip->ip_src.s_addr) >> IN_CLASSA_NSHIFT) ==
> > IN_LOOPBACKNET) {
> > +               if ((m->m_pkthdr.rcvif->if_flags & IFF_LOOPBACK) == 0)
> > +                       goto bad;
> >         }
> > 
> >         if (in_cksum(m, hlen) != 0) {
> > 
> > Acknowledgments:
> > 
> >   Woody       <woody@thebunker.net>
> >   Adam Laurie <adam@algroup.co.uk>
> >   Ben Laurie  <ben@algroup.co.uk>
> >   Doug Lang   <doug@thebunker.net>
> >   http://www.thebunker.net
> > 
> 


From owner-fwtk-users@ex.tis.com Thu Mar  8 10:55 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA25248
	Thu, 8 Mar 2001 10:55:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA01689;
	Thu, 8 Mar 2001 07:57:48 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 06:34:10 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA22505
	for fwtk-users-outgoing; Thu, 8 Mar 2001 06:33:37 -0800 (PST)
Message-ID: <3AA791E9.F93CC5A0@algroup.co.uk>
Date: Thu, 08 Mar 2001 14:06:33 +0000
From: Adam Laurie <adam@algroup.co.uk>
Organization: A.L. Group plc
X-Mailer: Mozilla 4.76 [en] (Win95; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: Brian Desmond <bdesmond@au.infogrames.com>, fwtk-users@lists.nai.com
Subject: Re: FW: Loopback and multi-homed routing flaw in TCP/IP stack.
References: <5.0.2.1.0.20010307232705.01d5b5c0@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1404

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick Murphy wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > At 11:52 AM 3/8/01 +1100, Brian Desmond wrote:
 > >What kind of packet filtering are people using to protect themselves
 > >from this?
 > 
 > Most any anti-spoofing will fix this - the problem in the Bugtraq article
 > is, after all, a local one - someone on one of the subnets directly
 > connected to your firewall sends a packet through the firewall to 127.0.0.1
 > and it's accepted. Fortunately, most people have a router between the
 > internet and their firewall, so there's no untrusted users on that subnet.

But unfortunately if your host is in a managed environment like a co-lo
or ISP there will most likely be *many* untrusted users on your subnet
so protecting individual machines in this way (or, hopefully, by fixing
the stack) is a necessary evil.

cheers,
Adam
--
Adam Laurie                   Tel: +44 (20) 8742 0755
A.L. Digital Ltd.             Fax: +44 (20) 8742 5995
Voysey House                  http://www.thebunker.net
Barley Mow Passage            http://www.aldigital.co.uk
London W4 4GB                 mailto:adam@algroup.co.uk
UNITED KINGDOM                PGP key on keyservers


From owner-fwtk-users@ex.tis.com Thu Mar  8 17:09 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA26168
	Thu, 8 Mar 2001 17:09:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA20868;
	Thu, 8 Mar 2001 14:11:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 13:02:53 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA11643
	for fwtk-users-outgoing; Thu, 8 Mar 2001 13:02:26 -0800 (PST)
Reply-To: <nico_baggus@compuserve.com>
From: "Nico Baggus" <nico_baggus@compuserve.com>
To: "'Jeff Barnette'" <barnette@alamo.satlug.org>, <fwtk-users@lists.nai.com>
Subject: RE: Maintaining timestamps with ftp-gw
Date: Thu, 8 Mar 2001 21:42:47 +0100
Message-ID: <006101c0a810$56474bb0$1106a8c0@niconet.nl>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
In-Reply-To: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 907

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> This regards a RedHat 6.2 box using ncftp as the ftp client.
> 
> ncftp has a handy feature whereby it can skip any download 
> where a file
> already exists on the local machine with the same name, size and
> timestamp.  This works great for me when I use my dial-up connection,
> which doesn't go through the ftp-gw.  However, when I use my network
> connection at work, which _does_ go through the ftp-gw, the timestamps
> always get set to the current time.  Is there a 'switch' or other
> technique that I haven't found yet?

NcFTP tries various commands (look at the batchlog
after doing a bgget & bgstart)


The command used is MDTM.....
(is also does CLNT <client name>,
SIZE <file>)
It expects a 213 response with the requested data....

I hope it helps,
Nico Baggus

From owner-fwtk-users@ex.tis.com Thu Mar  8 18:46 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA26355
	Thu, 8 Mar 2001 18:46:03 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA03690;
	Thu, 8 Mar 2001 15:48:18 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 14:40:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA24292
	for fwtk-users-outgoing; Thu, 8 Mar 2001 14:40:17 -0800 (PST)
Date: Thu, 8 Mar 2001 17:04:39 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Nico Baggus <nico_baggus@compuserve.com>
cc: "'Jeff Barnette'" <barnette@alamo.satlug.org>, fwtk-users@lists.nai.com
Subject: RE: Maintaining timestamps with ftp-gw
In-Reply-To: <006101c0a810$56474bb0$1106a8c0@niconet.nl>
Message-ID: <Pine.GSO.4.10.10103081703090.17782-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1422

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Well,

This should be pretty easy to add to the ftp-ops table - and pass it along
to the server for a response.

The routine usrcmd searches ftp-ops to get a match - then calls either a
special routine - or passes it along.  Seems as if these commands to be
added to the table.

ted keller


On Thu, 8 Mar 2001, Nico Baggus wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> > This regards a RedHat 6.2 box using ncftp as the ftp client.
> > 
> > ncftp has a handy feature whereby it can skip any download 
> > where a file
> > already exists on the local machine with the same name, size and
> > timestamp.  This works great for me when I use my dial-up connection,
> > which doesn't go through the ftp-gw.  However, when I use my network
> > connection at work, which _does_ go through the ftp-gw, the timestamps
> > always get set to the current time.  Is there a 'switch' or other
> > technique that I haven't found yet?
> 
> NcFTP tries various commands (look at the batchlog
> after doing a bgget & bgstart)
> 
> 
> The command used is MDTM.....
> (is also does CLNT <client name>,
> SIZE <file>)
> It expects a 213 response with the requested data....
> 
> I hope it helps,
> Nico Baggus
> 


From owner-fwtk-users@ex.tis.com Thu Mar  8 18:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA26360
	Thu, 8 Mar 2001 18:54:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA04613;
	Thu, 8 Mar 2001 15:56:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 14:56:48 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA26768
	for fwtk-users-outgoing; Thu, 8 Mar 2001 14:56:22 -0800 (PST)
Message-Id: <5.0.2.1.0.20010308174024.01d4e990@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 08 Mar 2001 17:50:43 -0500
To: <nico_baggus@compuserve.com>,
        "'Jeff Barnette'" <barnette@alamo.satlug.org>,
        <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: RE: Maintaining timestamps with ftp-gw
In-Reply-To: <006101c0a810$56474bb0$1106a8c0@niconet.nl>
References: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 832

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:42 PM 3/8/01 +0100, Nico Baggus wrote:
>NcFTP tries various commands (look at the batchlog
>after doing a bgget & bgstart)
>
>
>The command used is MDTM.....

That's not "standard" FTP. (There's an internet draft proposal to add the 
command, however.) In any case, add it to the 'ops' table in ftp-gw just 
below the line that reads
         "size",         OP_CONN,        0,

just add
         "mdtm",         OP_CONN,        0,
below that line and rebuild ftp-gw.

>(is also does CLNT <client name>,
>SIZE <file>)
>It expects a 213 response with the requested data....

SIZE is supported; I'm not sure what "CLNT" does (client?) - potentially 
risky until you know what it is.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Mar  8 19:38 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA26451
	Thu, 8 Mar 2001 19:38:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA09214;
	Thu, 8 Mar 2001 16:41:05 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 15:40:09 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA02716
	for fwtk-users-outgoing; Thu, 8 Mar 2001 15:39:39 -0800 (PST)
Message-Id: <5.0.2.1.0.20010308182830.01d657b0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 08 Mar 2001 18:33:37 -0500
To: Adam Laurie <adam@algroup.co.uk>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FW: Loopback and multi-homed routing flaw in TCP/IP stack.
Cc: Brian Desmond <bdesmond@au.infogrames.com>, fwtk-users@lists.nai.com
In-Reply-To: <3AA791E9.F93CC5A0@algroup.co.uk>
References: <5.0.2.1.0.20010307232705.01d5b5c0@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 949

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:06 PM 3/8/01 +0000, Adam Laurie wrote:
>Rick Murphy wrote:
> > Fortunately, most people have a router between the
> > internet and their firewall, so there's no untrusted users on that subnet.
>
>But unfortunately if your host is in a managed environment like a co-lo
>or ISP there will most likely be *many* untrusted users on your subnet
>so protecting individual machines in this way (or, hopefully, by fixing
>the stack) is a necessary evil.

True, but you don't normally run your own firewall in that managed 
environment.

I'm not saying that you can ignore this problem just because you've got a 
firewall in place - it's worth investigating to make sure you have some 
protection in place to avoid localhost spoofing. That protection is part of 
what it takes to make FWTK into a firewall.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Mar  8 22:58 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA26970
	Thu, 8 Mar 2001 22:58:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA20404;
	Thu, 8 Mar 2001 20:00:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 18:57:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA17546
	for fwtk-users-outgoing; Thu, 8 Mar 2001 18:57:20 -0800 (PST)
Date: Thu, 8 Mar 2001 21:56:36 -0500
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Rick Murphy <rmurphy@itm-inst.com>
Cc: Jeff Barnette <barnette@alamo.satlug.org>, fwtk-users@lists.nai.com
Subject: Re: Maintaining timestamps with ftp-gw
Message-Id: <20010308215636.H21978@washington.cospo.osis.gov>
Mail-Followup-To: Rick Murphy <rmurphy@itm-inst.com>,
	Jeff Barnette <barnette@alamo.satlug.org>, fwtk-users@lists.nai.com
References: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org> <5.0.2.1.0.20010306181844.01d584c0@mail.itm-inst.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <5.0.2.1.0.20010306181844.01d584c0@mail.itm-inst.com>; from rmurphy@itm-inst.com on Tue, Mar 06, 2001 at 06:23:15PM -0500
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1387

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, Mar 06, 2001 at 06:23:15PM -0500, Rick Murphy wrote:
> At 10:10 AM 3/6/01 -0600, Jeff Barnette wrote:
>  >I asked this question 2 weeks ago and got zero replies.  I'll ask it once
>  >more before putting it in the "nobody knows and they're not sending 'I
>  >dunno' responses".
> 
> OK, "I dunno". However..
> How is ncftp getting the creation date of the remote file?  Somehow, ncftp 
> isn't getting the information it needs to set the creation date on files 
> you receive.
> There isn't any way using the FTP protocol to reliably do that. (You can 
> parse the output of a LIST command, but that's OS dependent.)
> If ncftp is using an "X" command that ftp-gw is rejecting, you'll find it 
> in the fwtk log file; adding that command to the command table may fix it.
> (Basically, what they're trying to do can't be done reliably. This is a 
> case in point.)
>           -Rick

Weren't they parsing the FTPD output?  In which case, if ftp-gw
modifies it, it wouldn't be able to parse it.  Assuming a simplistic
parser.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Thu Mar  8 23:35 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA27025
	Thu, 8 Mar 2001 23:35:01 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA22291;
	Thu, 8 Mar 2001 20:37:34 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 8 Mar 2001 19:39:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA19376
	for fwtk-users-outgoing; Thu, 8 Mar 2001 19:39:23 -0800 (PST)
Message-Id: <5.0.2.1.0.20010308222543.01d43570@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Thu, 08 Mar 2001 22:27:23 -0500
To: Joseph S D Yao <jsdy@cospo.osis.gov>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Maintaining timestamps with ftp-gw
Cc: Jeff Barnette <barnette@alamo.satlug.org>, fwtk-users@lists.nai.com
In-Reply-To: <20010308215636.H21978@washington.cospo.osis.gov>
References: <5.0.2.1.0.20010306181844.01d584c0@mail.itm-inst.com>
 <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
 <5.0.2.1.0.20010306181844.01d584c0@mail.itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 583

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 09:56 PM 3/8/01 -0500, Joseph S D Yao wrote:

>Weren't they parsing the FTPD output?  In which case, if ftp-gw
>modifies it, it wouldn't be able to parse it.  Assuming a simplistic
>parser.

No, they're using a proposed new FTP command that returns the timestamp for 
a file.
In any case, ftp-gw doesn't do anything to modify most of the ftp 
transactions, so that shouldn't be a problem. (See my earlier post about 
how to fix this).
         -Rick


From owner-fwtk-users@ex.tis.com Fri Mar  9 10:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA28379
	Fri, 9 Mar 2001 10:04:55 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA18998;
	Fri, 9 Mar 2001 07:07:24 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Mar 2001 05:58:32 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA11820
	for fwtk-users-outgoing; Fri, 9 Mar 2001 05:58:06 -0800 (PST)
MIME-Version: 1.0
Message-Id: <3AA49924.12727@mta6.263.net>
Date: Tue, 6 Mar 2001 16:00:36 +0800 (CST)
From: "hedeuong" <hedyong@263.net>
To: fwtk-users@lists.nai.com
Subject: ask help
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 451

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Where can I get sourecode of  s/key

_____________________________________________
妇女节送她一束花 
http://shopping.263.net/category12.htm
新品玩具上市
http://shopping.263.net/category20.htm


From owner-fwtk-users@ex.tis.com Fri Mar  9 10:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA28382
	Fri, 9 Mar 2001 10:05:03 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA19012;
	Fri, 9 Mar 2001 07:07:29 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Mar 2001 05:58:23 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA11810
	for fwtk-users-outgoing; Fri, 9 Mar 2001 05:58:02 -0800 (PST)
X-Version: ireland 6.2.3.2329.0
From: "David Furlong" <def345@ireland.com>
Message-Id: <EFF6E6D7F5115D115A850005B8ACC2B0@def345.ireland.com>
Date: Mon, 5 Mar 2001 13:36:27 +0000
X-Priority: Normal
To: "fwtk-users@tis.com" <fwtk-users@tis.com>
Subject: Ports
CC: def345@hotmail.com
X-Mailer: Web Based Pronto
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1192

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


After doing a quick port scan on my proxy server, using nmap
it came back with the following
    25/tcp smtp             
    53/tcp domain          53/udp domain
                          123/udp ntp
                          514/udp syslog
   515/tcp printer 
1080/tcp socks
2766/tcp listen 
This is running on a solaris 2.6 machine, which has squid, tis for 
ftp, and news, socks running on it.
I know the ports open above are not entirely safe, and was wondering 
should I also proxy them using TIS, should they be disabled, (and if 
so how, inetd isn't used I think) and are they safe??

If this isn't a question for the fwtk mailing list, could someone 
point me to a better newsgroup for dealing with this kind of problem

And lastly, are there other utilities I should use to test my 
firewall / proxy machine.

Regards and thanks
Dave 

_____________________________________

Get your free E-mail at http://www.ireland.com


From owner-fwtk-users@ex.tis.com Fri Mar  9 11:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA28507
	Fri, 9 Mar 2001 11:16:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA28484;
	Fri, 9 Mar 2001 08:18:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 9 Mar 2001 06:57:36 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA17726
	for fwtk-users-outgoing; Fri, 9 Mar 2001 06:57:10 -0800 (PST)
Date: Fri, 9 Mar 2001 09:55:15 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: David Furlong <def345@ireland.com>
cc: "fwtk-users@tis.com" <fwtk-users@tis.com>, def345@hotmail.com
Subject: Re: Ports
In-Reply-To: <EFF6E6D7F5115D115A850005B8ACC2B0@def345.ireland.com>
Message-ID: <Pine.GSO.4.10.10103090954340.3604-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1641

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Dave,

Some of these protocols can be bound to the internal interface of the
firewall - hence they shouldn't be seen from the outside (unless you need
them there).  Examples - socks 5, bind-8.

ted keller


On Mon, 5 Mar 2001, David Furlong wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
> After doing a quick port scan on my proxy server, using nmap
> it came back with the following
>     25/tcp smtp             
>     53/tcp domain          53/udp domain
>                           123/udp ntp
>                           514/udp syslog
>    515/tcp printer 
> 1080/tcp socks
> 2766/tcp listen 
> This is running on a solaris 2.6 machine, which has squid, tis for 
> ftp, and news, socks running on it.
> I know the ports open above are not entirely safe, and was wondering 
> should I also proxy them using TIS, should they be disabled, (and if 
> so how, inetd isn't used I think) and are they safe??
> 
> If this isn't a question for the fwtk mailing list, could someone 
> point me to a better newsgroup for dealing with this kind of problem
> 
> And lastly, are there other utilities I should use to test my 
> firewall / proxy machine.
> 
> Regards and thanks
> Dave 
> 
> _____________________________________
> 
> Get your free E-mail at http://www.ireland.com
> 


From owner-fwtk-users@ex.tis.com Sun Mar 11 10:13 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA03992
	Sun, 11 Mar 2001 10:13:02 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA07506;
	Sun, 11 Mar 2001 07:15:48 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 11 Mar 2001 05:53:28 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA05883
	for fwtk-users-outgoing; Sun, 11 Mar 2001 05:53:17 -0800 (PST)
Message-ID: <20010311135249.80334.qmail@web12407.mail.yahoo.com>
Date: Sun, 11 Mar 2001 05:52:49 -0800 (PST)
From: Zakharov Mikhail <zmey20000@yahoo.com>
Subject: "%20" problem with http-gw & ftp-gw
To: fwtk-users@ex.tis.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 458

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

HI!

When using http-gw i found, I  can't access some targets with spaces in
the URL. For example: ftp://ftp.ratm.ru/pub/ErWin%203.52/ 

Is there any solucion for it?

Mikhail

__________________________________________________
Do You Yahoo!?
Yahoo! Auctions - Buy the things you want at great prices.
http://auctions.yahoo.com/

From owner-fwtk-users@ex.tis.com Tue Mar 13 11:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA11025
	Tue, 13 Mar 2001 11:40:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA27314;
	Tue, 13 Mar 2001 08:43:00 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 07:20:32 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA21802
	for fwtk-users-outgoing; Tue, 13 Mar 2001 07:20:11 -0800 (PST)
Date: Tue,  6 Mar 2001 16:07:14 +0100
Message-Id: <G9S7C2$IyntYlJOfI9fFnIkQBpUtX8md0Zuh3MqxsFso9Fo7Hc1xdV8@respublica.fr>
Subject: Re: ask help 
MIME-Version: 1.0
From: "qgiorgi@respublica.fr"<qgiorgi@respublica.fr>
To: fwtk-users@lists.nai.com
X-XaM3-API-Version: 1.1.9.1.22
X-SenderIP: 212.234.59.105
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id HAA08433
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 698

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>Where can I get sourecode of  s/key

You can try in ftp thumper.bellcore.com in pub/nmh/skey.

Quentin.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Choisissez les offres que vous voulez recevoir
Et gagnez une playstation 2 ou des baladeurs MP3 
----> http://www.respublica.fr/site/yoptin <----
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-- 

John C. Kelley
Computer Scientist
NAILabs at Network Associates, Inc.
Glenwood, MD

From owner-fwtk-users@ex.tis.com Tue Mar 13 12:10 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA11128
	Tue, 13 Mar 2001 12:10:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA29771;
	Tue, 13 Mar 2001 09:13:25 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 08:16:10 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA25218
	for fwtk-users-outgoing; Tue, 13 Mar 2001 08:15:47 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3AA51A64.D25C963B@peaktime.be>
Date: Tue, 06 Mar 2001 18:12:04 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: Re: Maintaining timestamps with ftp-gw
References: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1672

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Jeff Barnette wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > I asked this question 2 weeks ago and got zero replies.  I'll ask it once
 > more before putting it in the "nobody knows and they're not sending 'I
 > dunno' responses".
 > 
 > This regards a RedHat 6.2 box using ncftp as the ftp client.
 > 
 > ncftp has a handy feature whereby it can skip any download where a file
 > already exists on the local machine with the same name, size and
 > timestamp.  This works great for me when I use my dial-up connection,
 > which doesn't go through the ftp-gw.  However, when I use my network
 > connection at work, which _does_ go through the ftp-gw, the timestamps
 > always get set to the current time.  

This is unclear. Which timestamps? Which current time?

 > Is there a 'switch' or other
 > technique that I haven't found yet?
 > 
 > Thanks for any help,
 > 
 > Jeff

Could you do the same ftp session, in debug mode (if ncftp can't do
that, use the vanilla ftp client), once through the ftp-gw and once
through your dialup, so we can see which commands are issued and what
they return?

-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10
-- 

John C. Kelley
Computer Scientist
NAILabs at Network Associates, Inc.
Glenwood, MD

From owner-fwtk-users@ex.tis.com Tue Mar 13 12:19 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA11246
	Tue, 13 Mar 2001 12:19:48 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA00560;
	Tue, 13 Mar 2001 09:22:25 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 08:26:20 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA25915
	for fwtk-users-outgoing; Tue, 13 Mar 2001 08:26:09 -0800 (PST)
Message-ID: <91A5926EFF44D3118B1200104B7276EB654F64@hart-exchange.hartwellcorp.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "FWTK Users Mailing List (E-mail)" <fwtk-users@ex.tis.com>
Subject: Trouble compiling ms-sql-gw addon
Date: Tue, 6 Mar 2001 11:21:54 -0800 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1434

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I am trying to get the ms-sql-gw addon to compile using the crypto functions
from openssl.  This is on a RedHat 7.0 i386 system.  I've modified the
include line to find the "blowfish.h" file but I still get the following
errors:

gcc -I.. -O -DLINUX -DPROTECTINBOUND   -c -o ms-sql-gw.o ms-sql-gw.c
In file included from ms-sql-gw.c:25:
/usr/include/md5.h:27: parse error before `UINT4'
/usr/include/md5.h:27: warning: no semicolon at end of struct or union
/usr/include/md5.h:28: warning: data definition has no type or storage class
/usr/include/md5.h:30: parse error before `}'
/usr/include/md5.h:30: warning: data definition has no type or storage class
/usr/include/md5.h:32: parse error before `PROTO_LIST'
/usr/include/md5.h:33: parse error before `PROTO_LIST'
/usr/include/md5.h:35: parse error before `PROTO_LIST'
/usr/include/md5.h:37: parse error before `PROTO_LIST'
ms-sql-gw.c:81: parse error before `md5_ctx'
ms-sql-gw.c:81: warning: data definition has no type or storage class
make: *** [ms-sql-gw.o] Error 1

--------------------
Michael St. Laurent
Hartwell Corporation
-- 

John C. Kelley
Computer Scientist
NAILabs at Network Associates, Inc.
Glenwood, MD

From owner-fwtk-users@ex.tis.com Tue Mar 13 12:20 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA11250
	Tue, 13 Mar 2001 12:20:29 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA00594;
	Tue, 13 Mar 2001 09:22:56 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 08:26:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA25907
	for fwtk-users-outgoing; Tue, 13 Mar 2001 08:26:05 -0800 (PST)
Date: Tue, 6 Mar 2001 10:10:58 -0600 (CST)
From: Jeff Barnette <barnette@alamo.satlug.org>
To: <fwtk-users@lists.nai.com>
Subject: Maintaining timestamps with ftp-gw
Message-ID: <Pine.LNX.4.30.0103061004300.17295-100000@alamo.satlug.org>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1050

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I asked this question 2 weeks ago and got zero replies.  I'll ask it once
more before putting it in the "nobody knows and they're not sending 'I
dunno' responses".

This regards a RedHat 6.2 box using ncftp as the ftp client.

ncftp has a handy feature whereby it can skip any download where a file
already exists on the local machine with the same name, size and
timestamp.  This works great for me when I use my dial-up connection,
which doesn't go through the ftp-gw.  However, when I use my network
connection at work, which _does_ go through the ftp-gw, the timestamps
always get set to the current time.  Is there a 'switch' or other
technique that I haven't found yet?

Thanks for any help,

Jeff
-- 

John C. Kelley
Computer Scientist
NAILabs at Network Associates, Inc.
Glenwood, MD

From owner-fwtk-users@ex.tis.com Tue Mar 13 17:31 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA12464
	Tue, 13 Mar 2001 17:31:35 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA18065;
	Tue, 13 Mar 2001 14:33:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 13:32:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA14827
	for fwtk-users-outgoing; Tue, 13 Mar 2001 13:32:18 -0800 (PST)
Message-ID: <51D4F81EFAF7D111B33600805FBB112530970F@HQ_APPS>
From: "Hodges, Michael" <Mhodges@diomass.org>
To: fwtk-users@lists.nai.com
Subject: Form Data Truncated
Date: Mon, 12 Mar 2001 17:16:14 -0500
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C0AB42.0D7AEBC0"
Content-Length: 2889

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C0AB42.0D7AEBC0
Content-Type: text/plain;
	charset="iso-8859-1"

We are trying to access a sit which is pretty much plain vanilla http with
the exection that it sends large chunks (up to 15k) of session context back
and forth between client and server, encoded as hidden FORM objects.  It
seems like the data is being truncated which causes their perl scripts to
produce errors.

Is it http-gw which is truncating that data?  If so is there a fix?

Thanks,

-----------------
Michael J. Hodges
Computer Systems Coordinator
The Episcopal Diocese of Massachusetts
138 Tremont Street
Boston, MA  02111

(617) 879-6300 (voice)
(617) 482-8431 (fax)
mhodges@diomass.org
http://www.diomass.org 



------_=_NextPart_001_01C0AB42.0D7AEBC0
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2650.12">
<TITLE>Form Data Truncated</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2 FACE=3D"Courier New">We are trying to access a sit =
which is pretty much plain vanilla http with the exection that it sends =
large chunks (up to 15k) of session context back and forth between =
client and server, encoded as hidden FORM objects.&nbsp; It seems like =
the data is being truncated which causes their perl scripts to produce =
errors.</FONT></P>

<P><FONT SIZE=3D2 FACE=3D"Courier New">Is it http-gw which is =
truncating that data?&nbsp; If so is there a fix?</FONT>
</P>

<P><FONT SIZE=3D2 FACE=3D"Courier New">Thanks,</FONT>
</P>

<P><FONT SIZE=3D2 FACE=3D"Courier New">-----------------</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">Michael J. Hodges</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">Computer Systems =
Coordinator</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">The Episcopal Diocese of =
Massachusetts</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">138 Tremont Street</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">Boston, MA&nbsp; 02111</FONT>
</P>

<P><FONT SIZE=3D2 FACE=3D"Courier New">(617) 879-6300 (voice)</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">(617) 482-8431 (fax)</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">mhodges@diomass.org</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New"><A =
HREF=3D"http://www.diomass.org" =
TARGET=3D"_blank">http://www.diomass.org</A> </FONT>
</P>
<BR>

</BODY>
</HTML>
------_=_NextPart_001_01C0AB42.0D7AEBC0--
-- 
-- 

John C. Kelley
Computer Scientist
NAILabs at Network Associates, Inc.
Glenwood, MD

From owner-fwtk-users@ex.tis.com Tue Mar 13 19:04 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA12649
	Tue, 13 Mar 2001 19:04:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA23347;
	Tue, 13 Mar 2001 16:07:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 15:07:47 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA19625
	for fwtk-users-outgoing; Tue, 13 Mar 2001 15:07:31 -0800 (PST)
Message-ID: <91A5926EFF44D3118B1200104B7276EB654F7B@hart-exchange.hartwellcorp.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "FWTK Users Mailing List (E-mail)" <fwtk-users@ex.tis.com>
Subject: How do I compile ms-sql-gw under RedHat 7?
Date: Tue, 13 Mar 2001 15:03:44 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 415

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I got the libmd5 stuff from the "w3c-libwww" package and have tried to get
the "libblowfish" requirement with the "libmcrypt" package but that doesn't
seem to do the trick.  Has anyone got this working under RedHat-7 yet?


--------------------
Michael St. Laurent
Hartwell Corporation

From owner-fwtk-users@ex.tis.com Tue Mar 13 19:54 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA12729
	Tue, 13 Mar 2001 19:54:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA25926;
	Tue, 13 Mar 2001 16:57:17 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 15:58:22 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA22797
	for fwtk-users-outgoing; Tue, 13 Mar 2001 15:58:07 -0800 (PST)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE2E7@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: FWTK & IPFilter
Date: Tue, 13 Mar 2001 13:56:56 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 509

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I'm currently running TIS on a Solaris 5.7.  The netperm-table has been
configured and is working successfully, with http proxy enabled on my
workstations.  Does anyone know how to setup ipfiltering using fwtk?  So
that I would no long need to use the proxy, for http access.
All the documentation that I've found and read, has left me running in
circles.

Thank You,
  Jonathan


From owner-fwtk-users@ex.tis.com Tue Mar 13 21:45 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA12928
	Tue, 13 Mar 2001 21:45:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA01028;
	Tue, 13 Mar 2001 18:47:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 17:47:03 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA27803
	for fwtk-users-outgoing; Tue, 13 Mar 2001 17:46:42 -0800 (PST)
Date: Tue, 13 Mar 2001 16:55:00 -0800 (PST)
From: David Lang <dlang@diginsite.com>
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
cc: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Re: FWTK & IPFilter
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE2E7@A8MC.PSNS.NAVY.MIL>
Message-ID: <Pine.LNX.4.33.0103131654130.2081-100000@dlang.diginsite.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1075

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

the FWTK and ipfiltering are two seperate things. if you use them both on
the same machine you configure each completely independantly of the other.

David Lang

On Tue, 13 Mar 2001, Fritsch Jonathan D CONT PSNS wrote:

> Date: Tue, 13 Mar 2001 13:56:56 -0800
> From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
> To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
> Subject: FWTK & IPFilter
>
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> I'm currently running TIS on a Solaris 5.7.  The netperm-table has been
> configured and is working successfully, with http proxy enabled on my
> workstations.  Does anyone know how to setup ipfiltering using fwtk?  So
> that I would no long need to use the proxy, for http access.
> All the documentation that I've found and read, has left me running in
> circles.
>
> Thank You,
>   Jonathan
>


From owner-fwtk-users@ex.tis.com Wed Mar 14 03:35 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id DAA13616
	Wed, 14 Mar 2001 03:35:48 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id AAA16132;
	Wed, 14 Mar 2001 00:38:27 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 13 Mar 2001 23:37:15 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA13168
	for fwtk-users-outgoing; Tue, 13 Mar 2001 23:36:59 -0800 (PST)
Date: Wed, 14 Mar 2001 10:36:24 +0300 (MSK)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
cc: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Re: FWTK & IPFilter
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE2E7@A8MC.PSNS.NAVY.MIL>
Message-ID: <Pine.BSF.4.21.0103141035310.283-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 745

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, 13 Mar 2001, Fritsch Jonathan D CONT PSNS wrote:

> I'm currently running TIS on a Solaris 5.7.  The netperm-table has been
> configured and is working successfully, with http proxy enabled on my
> workstations.  Does anyone know how to setup ipfiltering using fwtk?  So
> that I would no long need to use the proxy, for http access.
> All the documentation that I've found and read, has left me running in
> circles.
	Go to http://cheops.anu.edu.au/~avalon/ip-filter.html. IPFilter is
separate product.

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Wed Mar 14 07:01 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA14113
	Wed, 14 Mar 2001 07:01:32 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA24552;
	Wed, 14 Mar 2001 04:03:55 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Mar 2001 03:02:58 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA22137
	for fwtk-users-outgoing; Wed, 14 Mar 2001 03:02:38 -0800 (PST)
From: ark@eltex.ru
Date: Wed, 14 Mar 2001 14:19:51 +0300
Message-Id: <200103141119.OAA11627@paranoid.alpha.int>
In-Reply-To: <91A5926EFF44D3118B1200104B7276EB654F64@hart-exchange.hartwellcorp.com> from ""Michael St. Laurent" <mikes@hartwellcorp.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: Trouble compiling ms-sql-gw addon
To: mikes@hartwellcorp.com
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1626

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

nuqneH,

looks like you use incompatible md5 library. Try BSD one or one from OPIE.


"Michael St. Laurent" <mikes@hartwellcorp.com> said :

> I am trying to get the ms-sql-gw addon to compile using the crypto functions
> from openssl.  This is on a RedHat 7.0 i386 system.  I've modified the
> include line to find the "blowfish.h" file but I still get the following
> errors:
> 
> gcc -I.. -O -DLINUX -DPROTECTINBOUND   -c -o ms-sql-gw.o ms-sql-gw.c
> In file included from ms-sql-gw.c:25:
> /usr/include/md5.h:27: parse error before `UINT4'
> /usr/include/md5.h:27: warning: no semicolon at end of struct or union
> /usr/include/md5.h:28: warning: data definition has no type or storage class
> /usr/include/md5.h:30: parse error before `}'
> /usr/include/md5.h:30: warning: data definition has no type or storage class
> /usr/include/md5.h:32: parse error before `PROTO_LIST'
> /usr/include/md5.h:33: parse error before `PROTO_LIST'
> /usr/include/md5.h:35: parse error before `PROTO_LIST'
> /usr/include/md5.h:37: parse error before `PROTO_LIST'
> ms-sql-gw.c:81: parse error before `md5_ctx'
> ms-sql-gw.c:81: warning: data definition has no type or storage class
> make: *** [ms-sql-gw.o] Error 1


                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

From owner-fwtk-users@ex.tis.com Wed Mar 14 14:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA15969
	Wed, 14 Mar 2001 14:34:28 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA14316;
	Wed, 14 Mar 2001 11:36:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Mar 2001 10:18:44 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA11077
	for fwtk-users-outgoing; Wed, 14 Mar 2001 10:18:33 -0800 (PST)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE2ED@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@ex.tis.com
Subject: IPFilter3.4.16
Date: Wed, 14 Mar 2001 09:38:04 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 310

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  I'm currently have ipf3.4.16 installed on Solaris 5.7.  I was wondering if
anyone would have a sample of the configuration files that I need to
configure.

Thank You.
  Jonathan


From owner-fwtk-users@ex.tis.com Wed Mar 14 21:18 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA16772
	Wed, 14 Mar 2001 21:18:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA27130;
	Wed, 14 Mar 2001 18:21:04 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Mar 2001 17:16:59 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA24446
	for fwtk-users-outgoing; Wed, 14 Mar 2001 17:16:48 -0800 (PST)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE2EF@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "'fwtk-users@ex.tis.com'" <fwtk-users@ex.tis.com>
Subject: netperm
Date: Wed, 14 Mar 2001 14:53:43 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 354

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  I'm having a heck of a time getting my http and gopher proxy to work
correctly.  Does anyone have a working netperm-table that I can have a look.
So that I might be able to see what I'm doing wrong.

Thank You,
  Jonathan


From owner-fwtk-users@ex.tis.com Wed Mar 14 21:53 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA16882
	Wed, 14 Mar 2001 21:53:55 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA28637;
	Wed, 14 Mar 2001 18:56:30 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 14 Mar 2001 18:00:15 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA26167
	for fwtk-users-outgoing; Wed, 14 Mar 2001 17:59:54 -0800 (PST)
Date: Wed, 14 Mar 2001 17:21:35 -0500
From: Bob Perkins <rnpnj@optonline.net>
Subject: ftp-gw - Patch for enhanced PASV support
X-Sender: rnpnj@mail-hub.optonline.net
To: fwtk-users@lists.nai.com
Message-id: <5.0.2.1.0.20010314170245.009fe200@mail-hub.optonline.net>
MIME-version: 1.0
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Content-transfer-encoding: 7BIT
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Length: 888

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I am having problems when I try to install these patch files (item 2.11
from the patches page at www.fwtk.org).  The data_port.diff and
ftp_pasv_1.diff files seem to load correctly, but when I load the
ftp_pasv_2.diff file, I get the following response:

# patch < ../patches/ftp_pasv_2.diff
   Looks like a unified context diff.
Hunk #1 succeeded at 2141 (offset 79 lines)
Hunk #2 succeeded at 2160 (offset 79 lines)
done

The diff file calls for Hunk #1 to be loaded at line 2230 and Hunk #2 at
line 2246.

Is there another patch that needs to be loaded between ftp_pasv_1.diff
amd ftp_pasv_2.diff?

I am experiencing problems with with the patched ftp-gw not properly
closing the data connections.  Could that be related to the missing lines?

Thanks
Bob


From owner-fwtk-users@ex.tis.com Thu Mar 15 05:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA17666
	Thu, 15 Mar 2001 05:08:21 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA10132;
	Thu, 15 Mar 2001 02:11:01 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Mar 2001 01:05:54 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA07802
	for fwtk-users-outgoing; Thu, 15 Mar 2001 01:05:28 -0800 (PST)
Date: Thu, 15 Mar 2001 12:04:30 +0300 (MSK)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
cc: fwtk-users@ex.tis.com
Subject: Re: IPFilter3.4.16
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE2ED@A8MC.PSNS.NAVY.MIL>
Message-ID: <Pine.BSF.4.21.0103151204001.236-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 512

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, 14 Mar 2001, Fritsch Jonathan D CONT PSNS wrote:

>   I'm currently have ipf3.4.16 installed on Solaris 5.7.  I was wondering if
> anyone would have a sample of the configuration files that I need to
> configure.
	Check ipfilter homepage for IPFilter how-to documents...

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Thu Mar 15 10:19 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA18483
	Thu, 15 Mar 2001 10:19:25 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA26149;
	Thu, 15 Mar 2001 07:22:12 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Mar 2001 06:14:23 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA18454
	for fwtk-users-outgoing; Thu, 15 Mar 2001 06:14:02 -0800 (PST)
Date: Thu, 15 Mar 2001 15:13:14 +0100
From: Georg Wittig <Georg.Wittig@gmd.de>
To: fwtk-users@tis.com
Subject: ftp-gw and welcome-msg
Message-ID: <20010315151313.D21307@twister.gmd.de>
Mime-Version: 1.0
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
User-Agent: Mutt/1.2.5i
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 498

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Is it possible to configure ftp-gw (fwtk-2.1) such that a different
welcome-msg is displayed depending on where the connection comes from?


-- 
Georg Wittig, GMD				Georg.Wittig@gmd.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
	Linux ist wie ein Pinguin im Wasser, elegant und geschmeidig
	und f黵 manch andere Spezies durchaus gef鋒rlich.

From owner-fwtk-users@ex.tis.com Thu Mar 15 10:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA18583
	Thu, 15 Mar 2001 10:51:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA00875;
	Thu, 15 Mar 2001 07:54:39 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 15 Mar 2001 06:54:51 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA22496
	for fwtk-users-outgoing; Thu, 15 Mar 2001 06:54:26 -0800 (PST)
Message-ID: <XFMail.20010315145333.gale@syntax.dera.gov.uk>
X-Mailer: XFMail 1.4.7 on Linux
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <51D4F81EFAF7D111B33600805FBB112530970F@HQ_APPS>
Date: Thu, 15 Mar 2001 14:53:33 -0000 (GMT)
From: Tony Gale <gale@syntax.dera.gov.uk>
To: "Hodges, Michael" <Mhodges@diomass.org>
Subject: RE: Form Data Truncated
Cc: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1077

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


It shouldn't be truncating it. Have you applied the JaveScript
quoting fix, which may sort out the problem (see www.fwtk.org, it's
in the jumbo patch)

Failing that, you'll to give details of the actual site in question.

-tony



On 12-Mar-2001 Hodges, Michael wrote:
> We are trying to access a sit which is pretty much plain vanilla
> http with
> the exection that it sends large chunks (up to 15k) of session
> context back
> and forth between client and server, encoded as hidden FORM
> objects.  It
> seems like the data is being truncated which causes their perl
> scripts to
> produce errors.
> 
> Is it http-gw which is truncating that data?  If so is there a fix?
> 
> Thanks,
> 
> 

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
The discerning person is always at a disadvantage.

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Sun Mar 18 21:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA28860
	Sun, 18 Mar 2001 21:52:24 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA02474;
	Sun, 18 Mar 2001 18:55:00 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 18 Mar 2001 17:20:18 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA26630
	for fwtk-users-outgoing; Sun, 18 Mar 2001 17:19:57 -0800 (PST)
Message-ID: <007501c0b010$31676980$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Subject: How do I handle Gnutella connections?
Date: Sun, 18 Mar 2001 20:01:54 -0500
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 270

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

What is the best way to handle Gnutella connections on a personal firewall?

LarryJackson@iName.com
Runnning FWTK on OpenBSD w/ IPF filters


From owner-fwtk-users@ex.tis.com Mon Mar 19 11:24 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00932
	Mon, 19 Mar 2001 11:24:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA16753;
	Mon, 19 Mar 2001 08:26:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Mar 2001 07:19:43 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA06257
	for fwtk-users-outgoing; Mon, 19 Mar 2001 07:19:22 -0800 (PST)
Message-ID: <20010319150549.13438.qmail@nwcst320.netaddress.usa.net>
Date: 19 Mar 2001 22:05:49 JVT
From: krishna moorthy <krishnamoorthy_j@usa.net>
To: fwtk-users@tis.com
Subject: please-clarify my doubts
Read-Receipt: krishnamoorthy_j@usa.net
X-Mailer: USANET web-mailer (34FM.0700.16A.01)
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id HAA04591
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 2598

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Sir,
I am J. Krishnamoorthy, completed my B.E., and now working as an software 
engineer.  I am interested in studying firewall.  Now i am analizing the 
codes of HTTP proxy in TIS.  I am having some doubts.  Kindly rectify them.

I am doing my works in Red Hat Linux 7.0.  
In http proxy there is function called go_error(shown below). 

1.) In this fn. i don't know what is meant by va_alist, va_dcl, 
va_list.  What is the use of these things?

FUNCTION GO_ERROR:

int go_error(sockfd, errorno, msg, va_alist)
int sockfd;
int errorno;
char *msg;
va_dcl
{	static int last_errno = 0;
	va_list marker;

	if( errorno != last_errno){	/* flush previous error stuff */
		if( last_errno){
			goenderror(sockfd);
		}
		last_errno = errorno;
		if( last_errno){
			gostarterror(sockfd, errorno);
		}
	}
	if( msg != NULL){
		va_start(marker);
		vsprintf(errbuf, msg, marker);
		va_end(marker);
		if( (rem_type & (TYPE_HTTP|TYPE_DIR)) == (TYPE_DIR)){
			say_sub(sockfd,"-");
		}
		say_sub(sockfd, errbuf);
		if( (rem_type & (TYPE_HTTPREQ|TYPE_PROXYCLIENT)) || rem_typech == 'h'){
			say(sockfd, "<br>");
		}else if( rem_type & TYPE_DIR){
			say(sockfd, "\t\t\t");
		}else {
			say(sockfd, " ");
		}
	}

	return 0;
}


2.) Suppose if i wish to implement this function in c++, please kindly
guide me how to convert that va_alist from c to c++ (or) is there any 
need to add special header files.

3.) In the code of Http there are options like default policy, browser,
id string, ident, url-filter, safejave, java, javascript...
sir, i don't know how to apply them in the netperm-table i.e. i am in
need of sample netperm-table with all options.

4.) From book, i came to know that it is possible to implement ftp and 
authentication in http proxy.

sir, we are doing our work in browsers.  How it is possible to write
files in browsers through ftp. Please kindly guide me.

also, guide me how to implement authentication.  Is it possible to add 
username and password through browser.

5.) Sir, suppose if wish to control the printer through this proxy, what i
have to do? and also if i don't want to allow downloading of images what are
things i have to do?

sir, kindly clarify my doubts and guide me in the correct sense.
Please answer me, atleast for some questions at the earliest.
expecting your positive reply.
I thank you sir.


____________________________________________________________________
Get free email and a permanent address at http://www.netaddress.com/?N=1


From owner-fwtk-users@ex.tis.com Mon Mar 19 17:47 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA02887
	Mon, 19 Mar 2001 17:47:10 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA14486;
	Mon, 19 Mar 2001 14:49:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Mar 2001 13:45:00 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA04462
	for fwtk-users-outgoing; Mon, 19 Mar 2001 13:44:39 -0800 (PST)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE302@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@tis.com
Subject: HTTP Error's
Date: Mon, 19 Mar 2001 13:42:56 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 288

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  When I try to go to a URL I get the fallowing error in my messages file.

http-gw[945]: failed to connect to http server "URL" (80)


Thank You,
  Jonathan


From owner-fwtk-users@ex.tis.com Mon Mar 19 23:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA03524
	Mon, 19 Mar 2001 23:43:56 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA08768;
	Mon, 19 Mar 2001 20:46:41 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Mar 2001 19:35:04 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA05642
	for fwtk-users-outgoing; Mon, 19 Mar 2001 19:34:43 -0800 (PST)
Message-Id: <5.0.2.1.0.20010319221629.01d5d530@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Mon, 19 Mar 2001 22:19:57 -0500
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>, fwtk-users@tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: HTTP Error's
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE302@A8MC.PSNS.NAVY.MIL>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 559

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 01:42 PM 3/19/01 -0800, Fritsch Jonathan D CONT PSNS wrote:
>   When I try to go to a URL I get the fallowing error in my messages file.
>
>http-gw[945]: failed to connect to http server "URL" (80)

That's usually a host unreachable or equivalent error.
The user is given a reason for the failure in their HTML screen, and I 
think there's a preceding message in the syslog giving the reason for the 
failure.
         -Rick



From owner-fwtk-users@ex.tis.com Mon Mar 19 23:44 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA03527
	Mon, 19 Mar 2001 23:44:17 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA08772;
	Mon, 19 Mar 2001 20:46:43 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 19 Mar 2001 19:35:10 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA05646
	for fwtk-users-outgoing; Mon, 19 Mar 2001 19:34:49 -0800 (PST)
Message-Id: <5.0.2.1.0.20010319204325.01cf6a10@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Mon, 19 Mar 2001 22:22:45 -0500
To: krishna moorthy <krishnamoorthy_j@usa.net>, fwtk-users@tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: please-clarify my doubts
In-Reply-To: <20010319150549.13438.qmail@nwcst320.netaddress.usa.net>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 2058

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 10:05 PM 3/19/01 +0000, krishna moorthy wrote:

>1.) In this fn. i don't know what is meant by va_alist, va_dcl,
>va_list.  What is the use of these things?

These are used to support variable argument lists. man varargs on your 
favorite system should give you some help.

>2.) Suppose if i wish to implement this function in c++, please kindly
>guide me how to convert that va_alist from c to c++ (or) is there any
>need to add special header files.

stdarg.h should be adequate to make these work.

>3.) In the code of Http there are options like default policy, browser,
>id string, ident, url-filter, safejave, java, javascript...
>sir, i don't know how to apply them in the netperm-table i.e. i am in
>need of sample netperm-table with all options.

I don't think anyone uses *all* the options in http-gw; indeed, some of the 
documented options aren't implemented - http authentication, for example.

>4.) From book, i came to know that it is possible to implement ftp and
>authentication in http proxy.
>
>sir, we are doing our work in browsers.  How it is possible to write
>files in browsers through ftp. Please kindly guide me.

I don't know how to put files using FTP through a browser. Anyone else?

>also, guide me how to implement authentication.  Is it possible to add
>username and password through browser.

Authentication by a remove web server (http authentication) will work 
through http-gw. The proxy doesn't support proxy authentication, however.

>5.) Sir, suppose if wish to control the printer through this proxy, what i
>have to do? and also if i don't want to allow downloading of images what are
>things i have to do?

The browser is responsible for handling printing of web pages - the proxy 
doesn't play any part in the printing process. There's no reliable way to 
disallow download of images; HTTP 0.9, which some servers still use, 
doesn't send a MIME Content-Type header.
         -Rick


From owner-fwtk-users@ex.tis.com Tue Mar 20 08:23 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA04987
	Tue, 20 Mar 2001 08:23:47 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA25128;
	Tue, 20 Mar 2001 05:26:14 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Mar 2001 04:21:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA22023
	for fwtk-users-outgoing; Tue, 20 Mar 2001 04:21:26 -0800 (PST)
Message-ID: <3AB74C16.2BC633F4@v-one.com>
Date: Tue, 20 Mar 2001 07:24:55 -0500
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.76 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Rick Murphy <rmurphy@itm-inst.com>
CC: krishna moorthy <krishnamoorthy_j@usa.net>, fwtk-users@tis.com
Subject: Re: please-clarify my doubts
References: <5.0.2.1.0.20010319204325.01cf6a10@mail.itm-inst.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1593

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick Murphy wrote:
> 
> >4.) From book, i came to know that it is possible to implement ftp and
> >authentication in http proxy.
> >
> >sir, we are doing our work in browsers.  How it is possible to write
> >files in browsers through ftp. Please kindly guide me.
> 
> I don't know how to put files using FTP through a browser. Anyone else?

Easy... just open a window in your browser to your favorite site (say
"ftp://ftp.v-one.com/"), and drag a file into that window. It should (at
least it does with Netscape 4.x and IE 5.x) begin the upload to the FTP
site.

> >5.) Sir, suppose if wish to control the printer through this proxy, what i
> >have to do?
> 
> The browser is responsible for handling printing of web pages - the proxy
> doesn't play any part in the printing process. 

Do you want to print through the browser or just access a printer? 

You could open up the printer port using plug-gw or lp-gw, but the
browser machine will need to push the printer request (somehow?).

> > and also if i don't want to allow downloading of images what are
> > things i have to do?
>
> There's no reliable way to
> disallow download of images; HTTP 0.9, which some servers still use,
> doesn't send a MIME Content-Type header.

Rick, could you filter URLs to disallow any "*.gif, *.jpg, *.png" URLs?
Of course, you would need to do some trickery if they also wanted
HTTP/1.1...

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Tue Mar 20 08:47 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA05022
	Tue, 20 Mar 2001 08:47:15 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA26936;
	Tue, 20 Mar 2001 05:50:08 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 20 Mar 2001 04:52:32 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA23115
	for fwtk-users-outgoing; Tue, 20 Mar 2001 04:52:11 -0800 (PST)
From: zhangfan79@263.net
MIME-Version: 1.0
Message-Id: <3AB6D789.28007@mta3.263.net>
Date: Tue, 20 Mar 2001 12:07:37 +0800 (CST)
To: fwtk-users@lists.nai.com
Subject: ftp-gw configure
X-Priority: 3
X-Originating-IP: [61.150.43.8]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 815

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

dear all:
    After i installed the fwtk,i test it's component one by one,
but i found that some configure option confused me,configure like that 'ftp-gw: permit-hosts 192.168.2.1' is availbale , but in fwtk document ,there are no configure rule available like that,so i think maybe some rule are not list in fwtk document.
    who can send me a full configure manual. you can directly send to 
zhangfan79@263.net.
                                   thanks a lot
                                         zhangfan
    

_____________________________________________
视听小家电精品展卖  http://shopping.263.net/fs/81shop/
IP卡特价，低至六折    http://shopping.263.net/hotsale/ipcard.htm


From owner-fwtk-users@ex.tis.com Wed Mar 21 16:52 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA10852
	Wed, 21 Mar 2001 16:52:11 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA05563;
	Wed, 21 Mar 2001 13:54:55 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 21 Mar 2001 12:28:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA15779
	for fwtk-users-outgoing; Wed, 21 Mar 2001 12:27:55 -0800 (PST)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: fwtk-users@lists.nai.com
Date: Wed, 21 Mar 2001 13:26:48 -0700
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Incoming spool files getting corrupted
Message-ID: <3AB8AC16.26718.1394B4C@localhost>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 879

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I've been seeing a problem with our fwtk box since the beginning.  We use 
smap and smapd.  The spool files in /var/spool/mail are getting corrupted.  
The very first character in the file, an uppercase "F", is not there.  This 
causes the pop3 clients to think there is nothing to retrieve.  The problem 
is very intermittant and we can sometimes go for weeks before it happens.  
Fixing it is easy, I just have to add the F at the beginning of the file.

Sometime back we updated smap to the 2.1+Yao version and we were seeing the 
problem both before the update and after.  My morning routine now includes 
scanning the spool files for missing Fs to catch the problem before the users 
do.

Anyone know what might be causing this?

TIA,
Ken Long


From owner-fwtk-users@ex.tis.com Thu Mar 22 05:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA12356
	Thu, 22 Mar 2001 05:34:50 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA17799;
	Thu, 22 Mar 2001 02:37:28 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 01:33:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA15052
	for fwtk-users-outgoing; Thu, 22 Mar 2001 01:32:54 -0800 (PST)
Date: Thu, 22 Mar 2001 10:30:50 +0100
From: Georg Wittig <Georg.Wittig@gmd.de>
To: fwtk-users@tis.com
Subject: ftp-gw and welcome-msg (2nd try)
Message-ID: <20010322103050.E7777@twister.gmd.de>
Mime-Version: 1.0
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
User-Agent: Mutt/1.2.5i
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 673

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

	(I posted this question a week ago. I didn't see any answer
	yet. Does this mean the answer is no or nobody knows or nobody
	cares? :-)


Is it possible to configure ftp-gw (fwtk-2.1) such that a different
welcome-msg is displayed depending on where the connection comes from?

Thanks in advance for your answers


-- 
Georg Wittig, GMD				Georg.Wittig@gmd.de
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
	Linux ist wie ein Pinguin im Wasser, elegant und geschmeidig
	und f黵 manch andere Spezies durchaus gef鋒rlich.

From owner-fwtk-users@ex.tis.com Thu Mar 22 08:50 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA13223
	Thu, 22 Mar 2001 08:50:26 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA26782;
	Thu, 22 Mar 2001 05:52:48 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 04:53:53 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA23014
	for fwtk-users-outgoing; Thu, 22 Mar 2001 04:53:32 -0800 (PST)
From: ark@eltex.ru
Date: Thu, 22 Mar 2001 15:55:08 +0300
Message-Id: <200103221255.PAA14011@paranoid.eltex.spb.ru>
In-Reply-To: <20010322103050.E7777@twister.gmd.de> from "Georg Wittig <Georg.Wittig@gmd.de>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: ftp-gw and welcome-msg (2nd try)
To: Georg.Wittig@gmd.de
Cc: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1320

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

Not yet, but it is easy to implement.

Georg Wittig <Georg.Wittig@gmd.de> said :

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > 	(I posted this question a week ago. I didn't see any answer
 > 	yet. Does this mean the answer is no or nobody knows or nobody
 > 	cares? :-)
 > 
 > 
 > Is it possible to configure ftp-gw (fwtk-2.1) such that a different
 > welcome-msg is displayed depending on where the connection comes from?
 > 
 > Thanks in advance for your answers
  

                                      _     _  _  _  _      _  _
  {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
  (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
  [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOrn2KqH/mIJW9LeBAQHomwQApACdXuKeOEatLVnM2G0wGAQhF03jjtVk
Gwi5jsydtoCYt2kdwtodHTOj7B98o4pCRqjSzGw5d7D9DNgnkWFUVQzSMy9wSmJ8
3r2Hvk57dLmUGGDkjKgTktWDtPZ6xrXUoxFEJQofADUPa+bpwnmbuQ8oeGRA3Zq3
zz4n19jbNtw=
=coyP
-----END PGP SIGNATURE-----


From owner-fwtk-users@ex.tis.com Thu Mar 22 08:50 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA13226
	Thu, 22 Mar 2001 08:50:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA26773;
	Thu, 22 Mar 2001 05:52:44 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 04:51:59 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA22912
	for fwtk-users-outgoing; Thu, 22 Mar 2001 04:51:32 -0800 (PST)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3AB9CE2A.46E3E127@peaktime.be>
Date: Thu, 22 Mar 2001 11:04:26 +0100
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: Georg Wittig <Georg.Wittig@gmd.de>
CC: fwtk-users@tis.com
Subject: Re: ftp-gw and welcome-msg (2nd try)
References: <20010322103050.E7777@twister.gmd.de>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id CAA16490
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1005

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Georg Wittig wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 >         (I posted this question a week ago. I didn't see any answer
 >         yet. Does this mean the answer is no or nobody knows or nobody
 >         cares? :-)

It means "Did you look in the source code?"

 > 
 > Is it possible to configure ftp-gw (fwtk-2.1) such that a different
 > welcome-msg is displayed depending on where the connection comes from?
 > 
 > Thanks in advance for your answers
 > 
 > --
 > Georg Wittig, GMD                               Georg.Wittig@gmd.de
 > - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
 >         Linux ist wie ein Pinguin im Wasser, elegant und geschmeidig
 >         und f黵 manch andere Spezies durchaus gef鋒rlich.


-- 
Michel Bardiaux


From owner-fwtk-users@ex.tis.com Thu Mar 22 10:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA13681
	Thu, 22 Mar 2001 10:43:57 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA07889;
	Thu, 22 Mar 2001 07:46:10 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 06:45:02 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA00749
	for fwtk-users-outgoing; Thu, 22 Mar 2001 06:44:36 -0800 (PST)
Date: Thu, 22 Mar 2001 17:43:40 +0300 (MSK)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: Georg Wittig <Georg.Wittig@gmd.de>
cc: fwtk-users@tis.com
Subject: Re: ftp-gw and welcome-msg (2nd try)
In-Reply-To: <20010322103050.E7777@twister.gmd.de>
Message-ID: <Pine.BSF.4.21.0103221440380.15392-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 449

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, 22 Mar 2001, Georg Wittig wrote:

> Is it possible to configure ftp-gw (fwtk-2.1) such that a different
> welcome-msg is displayed depending on where the connection comes from?
	Without source patching, no.	

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Thu Mar 22 11:27 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13915
	Thu, 22 Mar 2001 11:27:13 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA14430;
	Thu, 22 Mar 2001 08:29:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 07:30:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA05629
	for fwtk-users-outgoing; Thu, 22 Mar 2001 07:29:58 -0800 (PST)
Message-ID: <3ABA1A4D.25FB8235@china.com>
Date: Thu, 22 Mar 2001 16:29:17 +0100
From: hannes achleitner <hannes_a@china.com>
X-Mailer: Mozilla 4.76 [en] (WinNT; U)
X-Accept-Language:  de-AU,de-DE
MIME-Version: 1.0
To: fwtk-users@tis.com
Subject: http-gw "dokument contained no data" and net_flags[4]
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 444

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello

I use fwtk 2.1 on a SuSE 6.4 box, almost all works fine,
but on some sites I get on my WinNT-client with Netscape 4.76
a error message "The Dokument contained no data"
 There is a line like "Network error: net_flags[4] set (read) in the
/var/log/messages.
Can anyone help me, please
thanks in advance
hannes

From owner-fwtk-users@ex.tis.com Thu Mar 22 11:32 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA13965
	Thu, 22 Mar 2001 11:32:41 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA15422;
	Thu, 22 Mar 2001 08:35:07 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 07:38:24 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA06716
	for fwtk-users-outgoing; Thu, 22 Mar 2001 07:38:08 -0800 (PST)
Date: Thu, 22 Mar 2001 18:37:37 +0300 (MSK)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: fwtk-users@tis.com
Subject: more customizing *-gw
Message-ID: <Pine.BSF.4.21.0103221800130.15392-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2028

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi!

Some ago we read some letters about "unusual" customization of gateways
from fwtk. The problem is that gateways uses hard-codded tags when
selecting netperm-table configuration lines. That is why it is impossible
to make custom welcome messages for ftp/tn/rlogin-gw depending on
different addresses -- such customization cannot be performed using
*host-rules.

Here is a quick solution we're using last two years. I could post a patch,
but code I'm using is very different from one taken from fwtk bundle. So.
Let's do it with ftp-gw.c

1. First, we declare char[] variable. We store tagname in this
variable. Probably we have make this variable global, not in main(). Let
we name it 'myname[128]'.

2. Then we note that using xinetd or modern inetd we can change argv[0].
Using this knowledge first we do in main() we strncpy(myname, argv[0],
sizeof(myname)) for future use.

3. For more nice logging we may use myname in openlog near
main() begins. So change:

#ifndef LOG_DAEMON
    openlog("ftp-gw",LOG_PID);
#else
    openlog("ftp-gw",LOG_PID|LOG_NDELAY,LFAC);
#endif

to

#ifndef LOG_DAEMON
    openlog(myname,LOG_PID);
#else
    openlog(myname,LOG_PID|LOG_NDELAY,LFAC);
#endif

4. Next, we skip some lines locating the next code:

    if((confp = cfg_read("ftp-gw")) == (Cfg *)-1)
        exit(1);

This procedure opens netperm-table and fills confp structure. Changing
first of strings above to:

    if((confp = cfg_read(myname)) == (Cfg *)-1)

we got result we looking for -- ftp-gw will look for tags depending on
argv[0], not on hardcodded string.

Perfect. Now we just have to use different daemons for different
purposes. This is a taste of each own. I prefer xinetd and different
addresses to use. Someone may found different ports more useful.

Questions? None?! Fine! :-)

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585



From owner-fwtk-users@ex.tis.com Thu Mar 22 12:17 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA14126
	Thu, 22 Mar 2001 12:17:50 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA22761;
	Thu, 22 Mar 2001 09:20:10 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 08:16:11 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA12354
	for fwtk-users-outgoing; Thu, 22 Mar 2001 08:15:48 -0800 (PST)
Message-ID: <3ABA2509.6A9E1210@china.com>
Date: Thu, 22 Mar 2001 17:15:05 +0100
From: hannes achleitner <hannes_a@china.com>
X-Mailer: Mozilla 4.76 [en] (WinNT; U)
X-Accept-Language:  de-AU,de-DE
MIME-Version: 1.0
To: fwtk <fwtk-users@tis.com>
Subject: error compiling x-gw
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1086

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hello
when I try to compile x-gw I get this error messages, and I dont't know
how to fix it.
can anyone help
tx in advance
hannes

/usr/lib/crt1.o: In function `_start':
/usr/lib/crt1.o(.text+0x18): undefined reference to `main'
/tmp/ccTAOAcX.o: In function `become_child':
/usr/local/TIS_21/fwtk/x-gw/child.c:23: undefined reference to `pmsg'
/tmp/ccTAOAcX.o: In function `dup_stdio':
/usr/local/TIS_21/fwtk/x-gw/child.c:36: undefined reference to `pmsg'
/usr/local/TIS_21/fwtk/x-gw/child.c:44: undefined reference to `pmsg'
/tmp/ccTAOAcX.o: In function `pipe_sync':
/usr/local/TIS_21/fwtk/x-gw/child.c:67: undefined reference to `pmsg'
/usr/local/TIS_21/fwtk/x-gw/child.c:75: undefined reference to `pmsg'
/tmp/ccTAOAcX.o:/usr/local/TIS_21/fwtk/x-gw/child.c:80: more undefined
references to `pmsg' follow
collect2: ld returned 1 exit status
make[1]: *** [child.o] Error 1
make[1]: Leaving directory `/usr/local/TIS_21/fwtk/x-gw'
make: *** [all] Error 2



From owner-fwtk-users@ex.tis.com Thu Mar 22 12:18 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA14130
	Thu, 22 Mar 2001 12:18:28 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA22851;
	Thu, 22 Mar 2001 09:20:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 08:15:55 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA12321
	for fwtk-users-outgoing; Thu, 22 Mar 2001 08:15:34 -0800 (PST)
Message-ID: <3ABA24FE.5EA8B6B6@china.com>
Date: Thu, 22 Mar 2001 17:14:54 +0100
From: hannes achleitner <hannes_a@china.com>
X-Mailer: Mozilla 4.76 [en] (WinNT; U)
X-Accept-Language:  de-AU,de-DE
MIME-Version: 1.0
To: fwtk <fwtk-users@tis.com>
Subject: error compiling x-gw
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1086

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

hello
when I try to compile x-gw I get this error messages, and I dont't know
how to fix it.
can anyone help
tx in advance
hannes

/usr/lib/crt1.o: In function `_start':
/usr/lib/crt1.o(.text+0x18): undefined reference to `main'
/tmp/ccTAOAcX.o: In function `become_child':
/usr/local/TIS_21/fwtk/x-gw/child.c:23: undefined reference to `pmsg'
/tmp/ccTAOAcX.o: In function `dup_stdio':
/usr/local/TIS_21/fwtk/x-gw/child.c:36: undefined reference to `pmsg'
/usr/local/TIS_21/fwtk/x-gw/child.c:44: undefined reference to `pmsg'
/tmp/ccTAOAcX.o: In function `pipe_sync':
/usr/local/TIS_21/fwtk/x-gw/child.c:67: undefined reference to `pmsg'
/usr/local/TIS_21/fwtk/x-gw/child.c:75: undefined reference to `pmsg'
/tmp/ccTAOAcX.o:/usr/local/TIS_21/fwtk/x-gw/child.c:80: more undefined
references to `pmsg' follow
collect2: ld returned 1 exit status
make[1]: *** [child.o] Error 1
make[1]: Leaving directory `/usr/local/TIS_21/fwtk/x-gw'
make: *** [all] Error 2



From owner-fwtk-users@ex.tis.com Thu Mar 22 13:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA14375
	Thu, 22 Mar 2001 13:05:36 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA29848;
	Thu, 22 Mar 2001 10:08:02 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 09:05:57 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA20433
	for fwtk-users-outgoing; Thu, 22 Mar 2001 09:05:41 -0800 (PST)
From: eduval@synergia-france.com.fr
Message-ID: <3ABA2DE2.86D27FC0@synergia-france.com.fr>
Date: Thu, 22 Mar 2001 17:52:50 +0100
X-Mailer: Mozilla 4.72 [en] (WinNT; I)
X-Accept-Language: fr
MIME-Version: 1.0
To: TIS FWTK <fwtk-users@ex.tis.com>
Subject: ftp via http-gw
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 826

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I try to connect on ftp server (anonymous login) through my http-gw.

I use netscape with anonymous login enable and value proxy ftp port 
is egal at 80 (80 is my port for http-gw on my firewall)

If i use ftp://ftp.internal-domain is OK
but 
If i use ftp://ftp.external-domain, the connexion is stalled ??

If i use WS_FTP or CUTE FTP or Other FTP product, the connexion 
directly through my ftp-gw is OK.

I think which my router ADSL (Netopia R9100+) with NAT enable 
that's the problem, but the firewall make a first adress translation 
and the router a second adress translation.

Do you have an idea for my problem ?

My computer----FWTK------Router NETOPIA R9100-----Internet

Thanks.

From owner-fwtk-users@ex.tis.com Thu Mar 22 13:05 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA14381
	Thu, 22 Mar 2001 13:05:53 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA29908;
	Thu, 22 Mar 2001 10:08:30 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 09:08:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA20869
	for fwtk-users-outgoing; Thu, 22 Mar 2001 09:08:30 -0800 (PST)
From: eduval@synergia-france.com.fr
Message-ID: <3ABA2E8B.6647E2E9@synergia-france.com.fr>
Date: Thu, 22 Mar 2001 17:55:39 +0100
X-Mailer: Mozilla 4.72 [en] (WinNT; I)
X-Accept-Language: fr
MIME-Version: 1.0
To: TIS FWTK <fwtk-users@ex.tis.com>
Subject: Napster through FWTK
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 233

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi, 

How to use napster through my FWTK firewall ?
Do you have an example of netperm-table ?

Regards.

From owner-fwtk-users@ex.tis.com Thu Mar 22 15:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA14796
	Thu, 22 Mar 2001 15:40:45 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA21465;
	Thu, 22 Mar 2001 12:43:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 22 Mar 2001 11:37:26 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA12297
	for fwtk-users-outgoing; Thu, 22 Mar 2001 11:37:05 -0800 (PST)
From: eduval@synergia-france.com.fr
Message-ID: <3ABA493A.893AF04F@synergia-france.com.fr>
Date: Thu, 22 Mar 2001 19:49:30 +0100
X-Mailer: Mozilla 4.72 [en] (WinNT; I)
X-Accept-Language: fr
MIME-Version: 1.0
To: TIS FWTK <fwtk-users@ex.tis.com>
Subject: Re: ftp via http-gw
References: <3ABA2DE2.86D27FC0@synergia-france.com.fr>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1130

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I have apply the patch  "jumbo", it's OK for this problem.

eduval@synergia-france.com.fr wrote:
 > 
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 > Hi,
 > 
 > I try to connect on ftp server (anonymous login) through my http-gw.
 > 
 > I use netscape with anonymous login enable and value proxy ftp port
 > is egal at 80 (80 is my port for http-gw on my firewall)
 > 
 > If i use ftp://ftp.internal-domain is OK
 > but
 > If i use ftp://ftp.external-domain, the connexion is stalled ??
 > 
 > If i use WS_FTP or CUTE FTP or Other FTP product, the connexion
 > directly through my ftp-gw is OK.
 > 
 > I think which my router ADSL (Netopia R9100+) with NAT enable
 > that's the problem, but the firewall make a first adress translation
 > and the router a second adress translation.
 > 
 > Do you have an idea for my problem ?
 > 
 > My computer----FWTK------Router NETOPIA R9100-----Internet
 > 
 > Thanks.


From owner-fwtk-users@ex.tis.com Fri Mar 23 16:02 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA23604
	Fri, 23 Mar 2001 16:01:55 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA22347;
	Fri, 23 Mar 2001 13:04:51 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 23 Mar 2001 11:39:21 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA12075
	for fwtk-users-outgoing; Fri, 23 Mar 2001 11:39:00 -0800 (PST)
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Message-Id: <200103231724.JAA13159@noid.net>
X-Mini-Diatribe: To fix America:
	1. Cut Government in half
	2. Wait thirty years
	3. Repeat as necessary
Date: Fri, 23 Mar 2001 09:24:13 -0800
From: Tor Perkins <985311216@noid.net>
To: fwtk-users@lists.nai.com
Subject: Re: ftp-gw - Patch for enhanced PASV support
Mail-Followup-To: fwtk-users@lists.nai.com
References: <5.0.2.1.0.20010314170245.009fe200@mail-hub.optonline.net>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <5.0.2.1.0.20010314170245.009fe200@mail-hub.optonline.net>; from rnpnj@optonline.net on Wed, Mar 14, 2001 at 05:21:35PM -0500
X-Operating-System: Linux 2.2.17pre19
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1561

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

 > I am having problems when I try to install these patch files (item 2.11
 > from the patches page at www.fwtk.org).  The data_port.diff and
 > ftp_pasv_1.diff files seem to load correctly, but when I load the
 > ftp_pasv_2.diff file, I get the following response:
 > 
 > # patch < ../patches/ftp_pasv_2.diff
 >    Looks like a unified context diff.
 > Hunk #1 succeeded at 2141 (offset 79 lines)
 > Hunk #2 succeeded at 2160 (offset 79 lines)
 > done
 > 
 > The diff file calls for Hunk #1 to be loaded at line 2230 and Hunk #2 at
 > line 2246.
 > 
 > Is there another patch that needs to be loaded between ftp_pasv_1.diff
 > amd ftp_pasv_2.diff?

The patches have all been applied properly for your system.  The 79
line offset means that I had some other mods in my source when that
diff was made...  A cosmetic oversight as far as you are concerned.

 > I am experiencing problems with with the patched ftp-gw not properly
 > closing the data connections.  Could that be related to the missing lines?

The "missing lines" are not missing from the PASV patch.  They are
missing from some other patches that I happen to have in my ftp-gw.c
that you do not have in yours (like transperancy and plug-to).  I do
not recall anything that affects closing of the data connection
however.

-- 
}    __o
}  _(\<._  Tor Perkins           Send me e-mail with subject "get
} (_)/ (_) 985311216@noidDoTnet  pgp key" for automatic response.



From owner-fwtk-users@ex.tis.com Mon Mar 26 04:23 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA29709
	Mon, 26 Mar 2001 04:23:05 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id BAA18201;
	Mon, 26 Mar 2001 01:26:06 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Mar 2001 00:07:30 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA15533
	for fwtk-users-outgoing; Mon, 26 Mar 2001 00:07:14 -0800 (PST)
Message-Id: <v02120d02b6e525593036@[134.60.9.100]>
Mime-Version: 1.0
Date: Mon, 26 Mar 2001 09:00:39 -0800
To: fwtk-users@lists.nai.com
From: heim@sip.medizin.uni-ulm.de (Stefan Heim)
Subject: lp-gw
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 212

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Were is to be found lp-gw (or anather programm with
similar functions) ?
Thanks!



From owner-fwtk-users@ex.tis.com Mon Mar 26 06:33 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA00062
	Mon, 26 Mar 2001 06:33:43 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA23485;
	Mon, 26 Mar 2001 03:36:42 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Mar 2001 02:37:28 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA21220
	for fwtk-users-outgoing; Mon, 26 Mar 2001 02:37:07 -0800 (PST)
Date: Mon, 26 Mar 2001 14:36:18 +0400 (MSD)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: Stefan Heim <heim@sip.medizin.uni-ulm.de>
cc: fwtk-users@lists.nai.com
Subject: Re: lp-gw
In-Reply-To: <v02120d02b6e525593036@[134.60.9.100]>
Message-ID: <Pine.BSF.4.21.0103261435530.40706-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 379

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, 26 Mar 2001, Stefan Heim wrote:

> Were is to be found lp-gw (or anather programm with
> similar functions) ?
> Thanks!
	www.fwtk.org? ;-)
--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Tue Mar 27 01:40 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id BAA02982
	Tue, 27 Mar 2001 01:40:23 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id WAA00022;
	Mon, 26 Mar 2001 22:42:59 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 26 Mar 2001 21:39:31 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA22827
	for fwtk-users-outgoing; Mon, 26 Mar 2001 21:39:15 -0800 (PST)
Date: Mon, 26 Mar 2001 23:38:46 -0600 (CST)
From: wei zheng <weizheng@uiuc.edu>
X-Sender: weizheng@ux7.cso.uiuc.edu
To: fwtk-users@lists.nai.com
Subject: install http-gw
Message-ID: <Pine.GSO.4.10.10103262315240.17547-100000@ux7.cso.uiuc.edu>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1153

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I am installing TIS FWTK. I have finished installing tn-gw and ftp-gw, and
they seemed to work fine. But I don't know how to set up http-gw.

Could any one point me to a tutorial? I have found the man page for
http-gw, and the tutorial for TIS Firewall Toolkit -- configuration and
Administration, but I don't think they help me on this. The tutorial
doesn't mention http-gw, and the man page only tells about options, but it
almost doesn't say much about how to set up http-gw in the first place.

My questions are:

What port should http-gw use? If it uses port 80, what port should httpd
use on the same machine? How to specify them? In which files?

What should the entries look like in inetd.conf and netperm-table?

How could I tell the browser the existence of http-gw?

And after the inetd is reloaded, when the client on an inside machine
wants to connect to an outside http server, what URL should I enter in
the client brower's URL bar? 

I am using RedHat 7.0 and Netscape.

Thank you for your help.

Wei



From owner-fwtk-users@ex.tis.com Tue Mar 27 17:46 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA06608
	Tue, 27 Mar 2001 17:46:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA07877;
	Tue, 27 Mar 2001 14:49:01 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Mar 2001 13:24:00 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA25964
	for fwtk-users-outgoing; Tue, 27 Mar 2001 13:23:39 -0800 (PST)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE30B@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@lists.nai.com
Subject: SMAP
Date: Tue, 27 Mar 2001 13:21:37 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 323

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  Does anyone have or know of a configuration that will no allow promiscuous
relay though my firewall?  Or is their a version of smap and smapd that does
not allow that?

Thank You,
  Jonathan


From owner-fwtk-users@ex.tis.com Tue Mar 27 19:03 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA06728
	Tue, 27 Mar 2001 19:03:52 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA16793;
	Tue, 27 Mar 2001 16:06:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Mar 2001 15:07:04 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA10179
	for fwtk-users-outgoing; Tue, 27 Mar 2001 15:06:43 -0800 (PST)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: fwtk-users@lists.nai.com
Date: Tue, 27 Mar 2001 16:05:59 -0700
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Re: SMAP
Message-ID: <3AC0BA65.8737.C81819@localhost>
In-reply-to: <79C524BDBB22D411915800A0C96F68FB9FE30B@A8MC.PSNS.NAVY.MIL>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 568

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Smap 2.1 plus the Yao patches will plug that up for you.  There is another 
branch in the development tree that will do the job as well.  That branch is 
maintained by Ted Keller on this list.

Ken

On 27 Mar 2001, at 13:21, Fritsch Jonathan D CONT PSNS wrote:

>   Does anyone have or know of a configuration that will no allow promiscuous
> relay though my firewall?  Or is their a version of smap and smapd that does
> not allow that?


From owner-fwtk-users@ex.tis.com Tue Mar 27 22:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA07157
	Tue, 27 Mar 2001 22:16:54 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA28914;
	Tue, 27 Mar 2001 19:19:56 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 27 Mar 2001 18:20:46 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA25623
	for fwtk-users-outgoing; Tue, 27 Mar 2001 18:20:25 -0800 (PST)
Message-Id: <5.0.2.1.0.20010327205701.01d534a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 27 Mar 2001 21:04:35 -0500
To: wei zheng <weizheng@uiuc.edu>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: install http-gw
In-Reply-To: <Pine.GSO.4.10.10103262315240.17547-100000@ux7.cso.uiuc.edu
 >
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1474

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:38 PM 3/26/01 -0600, wei zheng wrote:
>My questions are:
>
>What port should http-gw use? If it uses port 80, what port should httpd
>use on the same machine? How to specify them? In which files?

The http-gw can use any port you like, but it is typically configured to 
use port 80. It is highly inadvisable to use a http daemon (httpd) on your 
firewall.

>What should the entries look like in inetd.conf and netperm-table?

Don't put anything for http in the inetd.conf, a line like
/usr/local/bin/http-gw -daemon 80
in your rc.local, rc.inetd, or some other startup file.
in your netperm-table, something like:

http-gw: userid uucp
http-gw: permit-hosts 1.2.3.4
http-gw: deny-hosts *
http-gw: permit-destination *

is enough to get it working. (1.2.3.4 in the "permit-hosts" line above is 
your internal network.)

>How could I tell the browser the existence of http-gw?

Configure the web proxy on your browser to use the firewall port 80 (or 
whatever port http-gw uses.)

>And after the inetd is reloaded, when the client on an inside machine
>wants to connect to an outside http server, what URL should I enter in
>the client brower's URL bar?

If you set the proxy in the browser, the user simply enters the URL. If you 
don't use a proxy, you must use the 
"http://firewall/http://external-host/directory" form.
         -Rick


From owner-fwtk-users@ex.tis.com Wed Mar 28 12:43 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA09554
	Wed, 28 Mar 2001 12:43:19 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA18213;
	Wed, 28 Mar 2001 09:46:11 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Mar 2001 08:40:42 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA11080
	for fwtk-users-outgoing; Wed, 28 Mar 2001 08:40:21 -0800 (PST)
X-Authentication-Warning: weedev1.brass.com: sunmgr owned process doing -bs
Date: Wed, 28 Mar 2001 11:39:35 -0500 (EST)
From: "Sun M. account" <sunmgr@brass.com>
X-Sender: sunmgr@weedev1
To: fwtk-users@lists.nai.com
Subject: Question about sybase request passthrough function setup
Message-ID: <Pine.GSO.4.21.0103281117250.1335-100000@weedev1>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 993

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


FWTP Guru

I recently installed fwtp version 2.1 in our system.  I successfully setup
ftp, telnet, and rlogin gateway.  Now, I like to setup sybase gateway for
sybase isql and sybase application.  I checked FAQ and unfortunatelly not
much data there to help me to setup sybase gateway for isql and
application request passthrough(looks like its not possible for
application, just wonder if anyone try it before).  Is anyone done this
before who can give me more direction to start with?

(*SUMMARY:  Application request passthrough I am looking for is:  if I can
setup a sybsae client keeps all sybase server's interface, which acts as
an sybase application gateway as well.  Anyone from outside must set
DSQUERY to backend sybase server, but will point to gateway first, then
redirected the connection to final desitnation by gateway).

Thanx for any reply.
JC


From owner-fwtk-users@ex.tis.com Wed Mar 28 15:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA09980
	Wed, 28 Mar 2001 15:34:40 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA15377;
	Wed, 28 Mar 2001 12:37:27 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Mar 2001 11:33:52 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA02063
	for fwtk-users-outgoing; Wed, 28 Mar 2001 11:33:31 -0800 (PST)
Message-ID: <030c01c0b7bb$0e8f17c0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Cc: "Rick Murphy" <rmurphy@itm-inst.com>
References: <5.0.2.1.0.20010327205701.01d534a0@mail.itm-inst.com>
Subject: Re: install http-gw (Why run it as a daemon?)
Date: Wed, 28 Mar 2001 14:12:38 -0500
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1999

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

What is the advantage of runnning http-d as a daemon, compared to runnning
it via inetd?

Thanks,
LarryJackson@iName.com
----- Original Message -----
From: "Rick Murphy" <rmurphy@itm-inst.com>
To: "wei zheng" <weizheng@uiuc.edu>; <fwtk-users@lists.nai.com>
Sent: Tuesday, March 27, 2001 9:04 PM
Subject: Re: install http-gw


> [To be removed from this list send the message "unsubscribe fwtk-users" in
the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> At 11:38 PM 3/26/01 -0600, wei zheng wrote:
> >My questions are:
> >
> >What port should http-gw use? If it uses port 80, what port should httpd
> >use on the same machine? How to specify them? In which files?
>
> The http-gw can use any port you like, but it is typically configured to
> use port 80. It is highly inadvisable to use a http daemon (httpd) on your
> firewall.
>
> >What should the entries look like in inetd.conf and netperm-table?
>
> Don't put anything for http in the inetd.conf, a line like
> /usr/local/bin/http-gw -daemon 80
> in your rc.local, rc.inetd, or some other startup file.
> in your netperm-table, something like:
>
> http-gw: userid uucp
> http-gw: permit-hosts 1.2.3.4
> http-gw: deny-hosts *
> http-gw: permit-destination *
>
> is enough to get it working. (1.2.3.4 in the "permit-hosts" line above is
> your internal network.)
>
> >How could I tell the browser the existence of http-gw?
>
> Configure the web proxy on your browser to use the firewall port 80 (or
> whatever port http-gw uses.)
>
> >And after the inetd is reloaded, when the client on an inside machine
> >wants to connect to an outside http server, what URL should I enter in
> >the client brower's URL bar?
>
> If you set the proxy in the browser, the user simply enters the URL. If
you
> don't use a proxy, you must use the
> "http://firewall/http://external-host/directory" form.
>          -Rick
>
>


From owner-fwtk-users@ex.tis.com Wed Mar 28 15:34 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA09983
	Wed, 28 Mar 2001 15:34:46 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA15391;
	Wed, 28 Mar 2001 12:37:32 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Mar 2001 11:37:08 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA02958
	for fwtk-users-outgoing; Wed, 28 Mar 2001 11:36:46 -0800 (PST)
Message-ID: <032401c0b7bb$8bf301e0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Subject: Any suggestions for running Napster/GNUtella through firewall?
Date: Wed, 28 Mar 2001 14:16:09 -0500
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 344

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I've look at the FWTK FAQ and asked here before, but I haven't gotten any
response.

So I'll ask again,
Any suggestions for running Napster or GNUtella through my personal
firewall?

Thanks,
LarryJackson@iName.com


From owner-fwtk-users@ex.tis.com Wed Mar 28 16:18 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA10076
	Wed, 28 Mar 2001 16:18:59 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA23078;
	Wed, 28 Mar 2001 13:21:36 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Mar 2001 12:23:24 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA12738
	for fwtk-users-outgoing; Wed, 28 Mar 2001 12:22:58 -0800 (PST)
Date: Wed, 28 Mar 2001 12:16:22 -0800 (PST)
From: David Lang <dlang@diginsite.com>
To: Larry Jackson <LarryJackson@iName.com>
cc: FWTK List Server <fwtk-users@lists.nai.com>,
        Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: install http-gw (Why run it as a daemon?)
In-Reply-To: <030c01c0b7bb$0e8f17c0$fc00a8c0@k62350>
Message-ID: <Pine.LNX.4.33.0103281215510.25227-100000@dlang.diginsite.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2650

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

you avoid the HUGE overhead that you get from inetd as well as the large
startup overhead for each connection.

David Lang

On Wed, 28 Mar 2001, Larry Jackson wrote:

> Date: Wed, 28 Mar 2001 14:12:38 -0500
> From: Larry Jackson <LarryJackson@iName.com>
> To: FWTK List Server <fwtk-users@lists.nai.com>
> Cc: Rick Murphy <rmurphy@itm-inst.com>
> Subject: Re: install http-gw (Why run it as a daemon?)
>
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> What is the advantage of runnning http-d as a daemon, compared to runnning
> it via inetd?
>
> Thanks,
> LarryJackson@iName.com
> ----- Original Message -----
> From: "Rick Murphy" <rmurphy@itm-inst.com>
> To: "wei zheng" <weizheng@uiuc.edu>; <fwtk-users@lists.nai.com>
> Sent: Tuesday, March 27, 2001 9:04 PM
> Subject: Re: install http-gw
>
>
> > [To be removed from this list send the message "unsubscribe fwtk-users" in
> the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > At 11:38 PM 3/26/01 -0600, wei zheng wrote:
> > >My questions are:
> > >
> > >What port should http-gw use? If it uses port 80, what port should httpd
> > >use on the same machine? How to specify them? In which files?
> >
> > The http-gw can use any port you like, but it is typically configured to
> > use port 80. It is highly inadvisable to use a http daemon (httpd) on your
> > firewall.
> >
> > >What should the entries look like in inetd.conf and netperm-table?
> >
> > Don't put anything for http in the inetd.conf, a line like
> > /usr/local/bin/http-gw -daemon 80
> > in your rc.local, rc.inetd, or some other startup file.
> > in your netperm-table, something like:
> >
> > http-gw: userid uucp
> > http-gw: permit-hosts 1.2.3.4
> > http-gw: deny-hosts *
> > http-gw: permit-destination *
> >
> > is enough to get it working. (1.2.3.4 in the "permit-hosts" line above is
> > your internal network.)
> >
> > >How could I tell the browser the existence of http-gw?
> >
> > Configure the web proxy on your browser to use the firewall port 80 (or
> > whatever port http-gw uses.)
> >
> > >And after the inetd is reloaded, when the client on an inside machine
> > >wants to connect to an outside http server, what URL should I enter in
> > >the client brower's URL bar?
> >
> > If you set the proxy in the browser, the user simply enters the URL. If
> you
> > don't use a proxy, you must use the
> > "http://firewall/http://external-host/directory" form.
> >          -Rick
> >
> >
>


From owner-fwtk-users@ex.tis.com Wed Mar 28 19:31 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA10407
	Wed, 28 Mar 2001 19:31:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA18095;
	Wed, 28 Mar 2001 16:34:50 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Mar 2001 15:18:13 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA09613
	for fwtk-users-outgoing; Wed, 28 Mar 2001 15:17:54 -0800 (PST)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE310@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@lists.nai.com
Subject: Deny Access
Date: Wed, 28 Mar 2001 15:16:13 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 236

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  Does any one know of the command to place in the netperm-table to deny web
access to a URL?

- Jonathan


From owner-fwtk-users@ex.tis.com Wed Mar 28 23:45 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA10920
	Wed, 28 Mar 2001 23:45:58 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA05627;
	Wed, 28 Mar 2001 20:48:55 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 28 Mar 2001 19:51:50 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA02649
	for fwtk-users-outgoing; Wed, 28 Mar 2001 19:51:24 -0800 (PST)
Message-Id: <5.0.2.1.0.20010328223917.01d616a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 28 Mar 2001 22:41:09 -0500
To: "Larry Jackson" <LarryJackson@iName.com>,
        "FWTK List Server" <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Any suggestions for running Napster/GNUtella through
  firewall?
In-Reply-To: <032401c0b7bb$8bf301e0$fc00a8c0@k62350>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 440

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:16 PM 3/28/01 -0500, Larry Jackson wrote:
>So I'll ask again,
>Any suggestions for running Napster or GNUtella through my personal
>firewall?

Napster works through Socks5; whether or not this is very smart to do 
(allowing outsiders to copy files from your internal systems) is arguable.
         -Rick


From owner-fwtk-users@ex.tis.com Thu Mar 29 08:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA12203
	Thu, 29 Mar 2001 08:42:27 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA23315;
	Thu, 29 Mar 2001 05:45:37 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Mar 2001 04:41:13 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA19963
	for fwtk-users-outgoing; Thu, 29 Mar 2001 04:40:57 -0800 (PST)
Date: Wed, 28 Mar 2001 22:00:04 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
cc: fwtk-users@lists.nai.com
Subject: Re: SMAP
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE30B@A8MC.PSNS.NAVY.MIL>
Message-ID: <Pine.GSO.4.10.10103282159170.1425-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 701

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

The Yao patches will do this - or, if you which, you can use my version
which as this feature and many more.  Let me know if you are interested.

ted keller


On Tue, 27 Mar 2001, Fritsch Jonathan D CONT PSNS wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 > 
 >   Does anyone have or know of a configuration that will no allow promiscuous
 > relay though my firewall?  Or is their a version of smap and smapd that does
 > not allow that?
 > 
 > Thank You,
 >   Jonathan
 > 



From owner-fwtk-users@ex.tis.com Thu Mar 29 08:42 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA12206
	Thu, 29 Mar 2001 08:42:42 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA23324;
	Thu, 29 Mar 2001 05:45:41 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 29 Mar 2001 04:43:14 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA20073
	for fwtk-users-outgoing; Thu, 29 Mar 2001 04:42:58 -0800 (PST)
Message-ID: <000101c0b839$41bd1010$c8c8c8c0@is_fileserver>
From: "saigonnet" <infosc@saigonnet.vn>
To: <fwtk-users@tis.com>
Subject: Help me! SCO 5.0.2c- A student from VietNam 
Date: Thu, 29 Mar 2001 09:57:57 +0700
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 4.72.3110.5
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_000F_01C0B836.BB234710"
Content-Length: 3340

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_000F_01C0B836.BB234710
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Dear,

I have a PPP connection model like this;

1. Server SCO 5.0.2 that incoming PPP connections. Address for the =
server is 192.200.1.2

2.One NT server(address 192.200.200.200) that consider RAS server for =
LAN 192.200.200.0 and=20

It will dial out to SCO server. After dial out, Server NT will have a IP =
address 192.200.1.100 with interface is PPP connection.

3. There are problem appear with me:

A.

I can ping 192.200.1.2 from NT server to SCO server , and I can ping the =
ppp connection 192.200.1.100 between them. But can not ping =
192.200.200.200 from SCO to NT.

So I must add more a entry to IP routing table from SCO :

route add 192.200.200.0 192.200.1.100

And then , I can ping 192.200.200.200 from SCO to NT.

B.

I catch some problem from that:

If I disconnect the PPP link from SCO to TCP, And I ping 192.200.200.200 =
from SCO to NT again , SCO will give me a error: " Network is down" =
although there are still the entry for host 192.200.200.0 and network =
192.200.200.0 on routing table. Hence I must delete the entry and add =
this entry once more.

My troubles are like this:=20

How can I setup default routing table without do by manual ?=20

How can I solve the problem. Is there any script that running after I =
dial out from NT to SCO for updating IP routing table.

Please help me,

Thank you very much

Quach Bao Nguyen, Viet Nam










------=_NextPart_000_000F_01C0B836.BB234710
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">

Dear,

I have a PPP connection model like this;

1. Server SCO 5.0.2 that incoming PPP connections. Address for the = server is=20 192.200.1.2

2.One NT server(address 192.200.200.200) that consider RAS server for = LAN=20 192.200.200.0 and 

It will dial out to SCO server. After dial out, Server NT will have a = IP=20 address 192.200.1.100 with interface is PPP connection.

3. There are problem appear with me:

A.

I can ping 192.200.1.2 from NT server to SCO server , and I can ping = the ppp=20 connection 192.200.1.100 between them. But can not ping 192.200.200.200 = from SCO=20 to NT.

So I must add more a entry to IP routing table from SCO :

route add 192.200.200.0 192.200.1.100

And then , I can ping 192.200.200.200 from SCO to NT.

B.

I catch some problem from that:

If I disconnect the PPP link from SCO to TCP, And I ping = 192.200.200.200 from=20 SCO to NT again , SCO will give me a error: " Network is down" = although there are still the entry for host 192.200.200.0 and network=20 192.200.200.0 on routing table. Hence I must delete the entry and add = this entry=20 once more.

My troubles are like this: 

How can I setup default routing table without do by manual ? 

How can I solve the problem. Is there any script that running after I = dial=20 out from NT to SCO for updating IP routing table.

Please help me,

Thank you very much

Quach Bao Nguyen, Viet Nam

  

  

  

  

------=_NextPart_000_000F_01C0B836.BB234710--



From owner-fwtk-users@ex.tis.com Fri Mar 30 09:08 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA16855
	Fri, 30 Mar 2001 09:08:44 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA18449;
	Fri, 30 Mar 2001 06:11:33 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Mar 2001 04:52:32 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA14234
	for fwtk-users-outgoing; Fri, 30 Mar 2001 04:52:11 -0800 (PST)
Message-ID: <3AC48001.6E0DCE3D@jamedia.com>
Date: Fri, 30 Mar 2001 07:45:53 -0500
From: Scott McEachern <smceachern@jamedia.com>
Reply-To: smceachern@jamedia.com
X-Mailer: Mozilla 4.75 [en] (X11; U; OpenBSD 2.8 i386)
X-Accept-Language: en
MIME-Version: 1.0
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
CC: fwtk-users@lists.nai.com
Subject: Re: Deny Access
References: <79C524BDBB22D411915800A0C96F68FB9FE310@A8MC.PSNS.NAVY.MIL>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1050

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Fritsch Jonathan D CONT PSNS wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 >   Does any one know of the command to place in the netperm-table to deny web
 > access to a URL?
 >
 > - Jonathan

     I could be wrong here, but I don't think that's a part of the FWTK's
functionality.
     However, once upon a time when I actually gave a darn where people surfed
what I did was use my internal DNS server to ``host'' the restricted domains.
The DNS would point to an internal web server with a page that said something to
the effect of ``access is restricted.''  Obviously my DNS wasn't serving to
anything other than our intranet, but this worked for me.  HTH.

--
R. Scott McEachern, Network Administrator
J&A Media Services, Inc.
300 John St., Suite 500, Thornhill, ON, CA  L3T 5W4
tel:905-881-6902  fax:905-881-6945





From owner-fwtk-users@ex.tis.com Fri Mar 30 12:58 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA17637
	Fri, 30 Mar 2001 12:57:57 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA07672;
	Fri, 30 Mar 2001 10:00:02 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Mar 2001 09:00:16 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA02926
	for fwtk-users-outgoing; Fri, 30 Mar 2001 08:59:55 -0800 (PST)
X-Authentication-Warning: weedev1.brass.com: sunmgr owned process doing -bs
Date: Fri, 30 Mar 2001 11:26:59 -0500 (EST)
From: "Sun M. account" <sunmgr@brass.com>
To: fwtk-users@lists.nai.com
Subject: service time limition for certain user
Message-ID: <Pine.GSO.4.21.0103301118470.6894-100000@weedev1.brass.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 789

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi

I setup fwtp version 2.1 on my Solaris 2.6 host.  Most function are
running ok(tn-gw, ftp-gw, etc).  I checked man page of authsrv and there
is a way to set service time frame for different user/group and user.  I
try to implement this function but doesn't seems working properly:

I add this entry in netperm-table:

#Allow user ops to use ftp-gw to all destination bet. 10AM 10 10:10AM
authsrv:        permit-operation user ops ftp-gw * time 10:00 10:10

Then, I ran this command in authsrv:
operation user ops ftp-gw *
ok

But, I still able to be authenticated and to use ftp-gw function in other
time.  Anything I miss here?

Thanx for any reply.
JC


From owner-fwtk-users@ex.tis.com Fri Mar 30 15:16 EST 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA18225
	Fri, 30 Mar 2001 15:16:31 -0500 (EST)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA18829;
	Fri, 30 Mar 2001 12:19:21 -0800 (PST)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 30 Mar 2001 11:19:02 -0800
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA13331
	for fwtk-users-outgoing; Fri, 30 Mar 2001 11:18:46 -0800 (PST)
Date: Fri, 30 Mar 2001 09:22:12 -0800 (PST)
From: Scott Campbell <scampbel@gvpl.ca>
X-X-Sender:  <scampbel@pochta.gvpl.victoria.bc.ca>
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
cc: <fwtk-users@lists.nai.com>
Subject: Re: Deny Access
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE310@A8MC.PSNS.NAVY.MIL>
Message-ID: <Pine.BSF.4.32.0103300908350.79400-100000@pochta.gvpl.victoria.bc.ca>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1484

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, 28 Mar 2001, Fritsch Jonathan D CONT PSNS wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 >   Does any one know of the command to place in the netperm-table to deny web
 > access to a URL?
 >
If you want to deny web access to 1 (or a couple) urls you can do an entry
such as:

http-gw:        permit-hosts 10.2.0.9 -dest !142.104.6.7 -dest *

This restricts your machine of 10.2.0.9 to go anywhere except that one ip.
I use this for our public internets so that they can go anywhere except
our internal staff web server.  If you want to do that for all your
machines just replace the 10.2.0.9 with your internal ip mask.  You could
also do it by name such as:

http-gw:        permit-hosts 10.2.0.9 -dest !*.hotmail.com -dest *

which again will let that machine anywhere except a url that has a domain
ending in hotmail.com.

Your line can be up to 1024 characters (if I remember correct) and if you
don't have that final "-dest *" then they won't be able to go anywhere.

If you need to deny access to say 100 urls then you have to do it outside
of fwtk (unless someone who knows more says different ;)


Scott E. Campbell
_______________________________
Computer Operations
Greater Victoria Public Library
Victoria BC CANADA

scampbel@gvpl.ca




