From owner-fwtk-users@ex.tis.com Mon Apr  2 11:57 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26448
	Mon, 2 Apr 2001 11:57:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14091;
	Mon, 2 Apr 2001 09:00:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:42:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29105
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:42:18 -0700 (PDT)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE310@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@lists.nai.com
Subject: Deny Access
Date: Wed, 28 Mar 2001 15:16:13 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 367

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

   Does any one know of the command to place in the netperm-table to deny web
access to a URL?

- Jonathan



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:57 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26449
	Mon, 2 Apr 2001 11:57:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14098;
	Mon, 2 Apr 2001 09:00:16 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:48:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29953
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:48:20 -0700 (PDT)
Date: Mon, 26 Mar 2001 23:38:46 -0600 (CST)
From: wei zheng <weizheng@uiuc.edu>
X-Sender: weizheng@ux7.cso.uiuc.edu
To: fwtk-users@lists.nai.com
Subject: install http-gw
Message-ID: <Pine.GSO.4.10.10103262315240.17547-100000@ux7.cso.uiuc.edu>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1283

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I am installing TIS FWTK. I have finished installing tn-gw and ftp-gw, and
they seemed to work fine. But I don't know how to set up http-gw.

Could any one point me to a tutorial? I have found the man page for
http-gw, and the tutorial for TIS Firewall Toolkit -- configuration and
Administration, but I don't think they help me on this. The tutorial
doesn't mention http-gw, and the man page only tells about options, but it
almost doesn't say much about how to set up http-gw in the first place.

My questions are:

What port should http-gw use? If it uses port 80, what port should httpd
use on the same machine? How to specify them? In which files?

What should the entries look like in inetd.conf and netperm-table?

How could I tell the browser the existence of http-gw?

And after the inetd is reloaded, when the client on an inside machine
wants to connect to an outside http server, what URL should I enter in
the client brower's URL bar? 

I am using RedHat 7.0 and Netscape.

Thank you for your help.

Wei




From owner-fwtk-users@ex.tis.com Mon Apr  2 11:57 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26454
	Mon, 2 Apr 2001 11:57:38 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14105;
	Mon, 2 Apr 2001 09:00:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:44:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29241
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:43:27 -0700 (PDT)
Message-ID: <030c01c0b7bb$0e8f17c0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Cc: "Rick Murphy" <rmurphy@itm-inst.com>
References: <5.0.2.1.0.20010327205701.01d534a0@mail.itm-inst.com>
Subject: Re: install http-gw (Why run it as a daemon?)
Date: Wed, 28 Mar 2001 14:12:38 -0500
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2172

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

What is the advantage of runnning http-d as a daemon, compared to runnning
it via inetd?

Thanks,
LarryJackson@iName.com
----- Original Message -----
From: "Rick Murphy" <rmurphy@itm-inst.com>
To: "wei zheng" <weizheng@uiuc.edu>; <fwtk-users@lists.nai.com>
Sent: Tuesday, March 27, 2001 9:04 PM
Subject: Re: install http-gw


 > [To be removed from this list send the message "unsubscribe fwtk-users" in
the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > At 11:38 PM 3/26/01 -0600, wei zheng wrote:
 > >My questions are:
 > >
 > >What port should http-gw use? If it uses port 80, what port should httpd
 > >use on the same machine? How to specify them? In which files?
 >
 > The http-gw can use any port you like, but it is typically configured to
 > use port 80. It is highly inadvisable to use a http daemon (httpd) on your
 > firewall.
 >
 > >What should the entries look like in inetd.conf and netperm-table?
 >
 > Don't put anything for http in the inetd.conf, a line like
 > /usr/local/bin/http-gw -daemon 80
 > in your rc.local, rc.inetd, or some other startup file.
 > in your netperm-table, something like:
 >
 > http-gw: userid uucp
 > http-gw: permit-hosts 1.2.3.4
 > http-gw: deny-hosts *
 > http-gw: permit-destination *
 >
 > is enough to get it working. (1.2.3.4 in the "permit-hosts" line above is
 > your internal network.)
 >
 > >How could I tell the browser the existence of http-gw?
 >
 > Configure the web proxy on your browser to use the firewall port 80 (or
 > whatever port http-gw uses.)
 >
 > >And after the inetd is reloaded, when the client on an inside machine
 > >wants to connect to an outside http server, what URL should I enter in
 > >the client brower's URL bar?
 >
 > If you set the proxy in the browser, the user simply enters the URL. If
you
 > don't use a proxy, you must use the
 > "http://firewall/http://external-host/directory" form.
 >          -Rick
 >
 >



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:57 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26458
	Mon, 2 Apr 2001 11:57:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14079;
	Mon, 2 Apr 2001 09:00:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:41:58 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA28983
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:41:28 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010328223917.01d616a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 28 Mar 2001 22:41:09 -0500
To: "Larry Jackson" <LarryJackson@iName.com>,
        "FWTK List Server" <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: Any suggestions for running Napster/GNUtella through
   firewall?
In-Reply-To: <032401c0b7bb$8bf301e0$fc00a8c0@k62350>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 574

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:16 PM 3/28/01 -0500, Larry Jackson wrote:
 >So I'll ask again,
 >Any suggestions for running Napster or GNUtella through my personal
 >firewall?

Napster works through Socks5; whether or not this is very smart to do 
(allowing outsiders to copy files from your internal systems) is arguable.
          -Rick



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:57 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26456
	Mon, 2 Apr 2001 11:57:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14111;
	Mon, 2 Apr 2001 09:00:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:47:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29780
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:47:28 -0700 (PDT)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE30B@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@lists.nai.com
Subject: SMAP
Date: Tue, 27 Mar 2001 13:21:37 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 455

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

   Does anyone have or know of a configuration that will no allow promiscuous
relay though my firewall?  Or is their a version of smap and smapd that does
not allow that?

Thank You,
   Jonathan



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:57 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26463
	Mon, 2 Apr 2001 11:57:47 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14115;
	Mon, 2 Apr 2001 09:00:21 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:49:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA00177
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:49:29 -0700 (PDT)
X-Authentication-Warning: weedev1.brass.com: sunmgr owned process doing -bs
Date: Wed, 28 Mar 2001 11:39:35 -0500 (EST)
From: "Sun M. account" <sunmgr@brass.com>
X-Sender: sunmgr@weedev1
To: fwtk-users@lists.nai.com
Subject: Question about sybase request passthrough function setup
Message-ID: <Pine.GSO.4.21.0103281117250.1335-100000@weedev1>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1123

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


FWTP Guru

I recently installed fwtp version 2.1 in our system.  I successfully setup
ftp, telnet, and rlogin gateway.  Now, I like to setup sybase gateway for
sybase isql and sybase application.  I checked FAQ and unfortunatelly not
much data there to help me to setup sybase gateway for isql and
application request passthrough(looks like its not possible for
application, just wonder if anyone try it before).  Is anyone done this
before who can give me more direction to start with?

(*SUMMARY:  Application request passthrough I am looking for is:  if I can
setup a sybsae client keeps all sybase server's interface, which acts as
an sybase application gateway as well.  Anyone from outside must set
DSQUERY to backend sybase server, but will point to gateway first, then
redirected the connection to final desitnation by gateway).

Thanx for any reply.
JC



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:58 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26450
	Mon, 2 Apr 2001 11:57:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14083;
	Mon, 2 Apr 2001 09:00:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:44:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAB29355
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:44:19 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010327205701.01d534a0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 27 Mar 2001 21:04:35 -0500
To: wei zheng <weizheng@uiuc.edu>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: install http-gw
In-Reply-To: <Pine.GSO.4.10.10103262315240.17547-100000@ux7.cso.uiuc.edu
  >
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1614

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:38 PM 3/26/01 -0600, wei zheng wrote:
 >My questions are:
 >
 >What port should http-gw use? If it uses port 80, what port should httpd
 >use on the same machine? How to specify them? In which files?

The http-gw can use any port you like, but it is typically configured to 
use port 80. It is highly inadvisable to use a http daemon (httpd) on your 
firewall.

 >What should the entries look like in inetd.conf and netperm-table?

Don't put anything for http in the inetd.conf, a line like
/usr/local/bin/http-gw -daemon 80
in your rc.local, rc.inetd, or some other startup file.
in your netperm-table, something like:

http-gw: userid uucp
http-gw: permit-hosts 1.2.3.4
http-gw: deny-hosts *
http-gw: permit-destination *

is enough to get it working. (1.2.3.4 in the "permit-hosts" line above is 
your internal network.)

 >How could I tell the browser the existence of http-gw?

Configure the web proxy on your browser to use the firewall port 80 (or 
whatever port http-gw uses.)

 >And after the inetd is reloaded, when the client on an inside machine
 >wants to connect to an outside http server, what URL should I enter in
 >the client brower's URL bar?

If you set the proxy in the browser, the user simply enters the URL. If you 
don't use a proxy, you must use the 
"http://firewall/http://external-host/directory" form.
          -Rick



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:58 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26471
	Mon, 2 Apr 2001 11:58:03 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14126;
	Mon, 2 Apr 2001 09:00:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:51:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA00530
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:51:23 -0700 (PDT)
Message-ID: <000101c0b839$41bd1010$c8c8c8c0@is_fileserver>
From: "saigonnet" <infosc@saigonnet.vn>
To: <fwtk-users@tis.com>
Subject: Help me! SCO 5.0.2c- A student from VietNam 
Date: Thu, 29 Mar 2001 09:57:57 +0700
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 4.72.3110.5
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_000F_01C0B836.BB234710"
Content-Length: 3474

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.

------=_NextPart_000_000F_01C0B836.BB234710
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Dear,

I have a PPP connection model like this;

1. Server SCO 5.0.2 that incoming PPP connections. Address for the =
server is 192.200.1.2

2.One NT server(address 192.200.200.200) that consider RAS server for =
LAN 192.200.200.0 and=20

It will dial out to SCO server. After dial out, Server NT will have a IP =
address 192.200.1.100 with interface is PPP connection.

3. There are problem appear with me:

A.

I can ping 192.200.1.2 from NT server to SCO server , and I can ping the =
ppp connection 192.200.1.100 between them. But can not ping =
192.200.200.200 from SCO to NT.

So I must add more a entry to IP routing table from SCO :

route add 192.200.200.0 192.200.1.100

And then , I can ping 192.200.200.200 from SCO to NT.

B.

I catch some problem from that:

If I disconnect the PPP link from SCO to TCP, And I ping 192.200.200.200 =
from SCO to NT again , SCO will give me a error: " Network is down" =
although there are still the entry for host 192.200.200.0 and network =
192.200.200.0 on routing table. Hence I must delete the entry and add =
this entry once more.

My troubles are like this:=20

How can I setup default routing table without do by manual ?=20

How can I solve the problem. Is there any script that running after I =
dial out from NT to SCO for updating IP routing table.

Please help me,

Thank you very much

Quach Bao Nguyen, Viet Nam










------=_NextPart_000_000F_01C0B836.BB234710
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">

Dear,

I have a PPP connection model like this;

1. Server SCO 5.0.2 that incoming PPP connections. Address for the = server is=20 192.200.1.2

2.One NT server(address 192.200.200.200) that consider RAS server for = LAN=20 192.200.200.0 and 

It will dial out to SCO server. After dial out, Server NT will have a = IP=20 address 192.200.1.100 with interface is PPP connection.

3. There are problem appear with me:

A.

I can ping 192.200.1.2 from NT server to SCO server , and I can ping = the ppp=20 connection 192.200.1.100 between them. But can not ping 192.200.200.200 = from SCO=20 to NT.

So I must add more a entry to IP routing table from SCO :

route add 192.200.200.0 192.200.1.100

And then , I can ping 192.200.200.200 from SCO to NT.

B.

I catch some problem from that:

If I disconnect the PPP link from SCO to TCP, And I ping = 192.200.200.200 from=20 SCO to NT again , SCO will give me a error: " Network is down" = although there are still the entry for host 192.200.200.0 and network=20 192.200.200.0 on routing table. Hence I must delete the entry and add = this entry=20 once more.

My troubles are like this: 

How can I setup default routing table without do by manual ? 

How can I solve the problem. Is there any script that running after I = dial=20 out from NT to SCO for updating IP routing table.

Please help me,

Thank you very much

Quach Bao Nguyen, Viet Nam

   

   

   

   

------=_NextPart_000_000F_01C0B836.BB234710--




From owner-fwtk-users@ex.tis.com Mon Apr  2 11:58 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26469
	Mon, 2 Apr 2001 11:57:52 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14119;
	Mon, 2 Apr 2001 09:00:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:44:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29238
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:43:23 -0700 (PDT)
Date: Wed, 28 Mar 2001 12:16:22 -0800 (PST)
From: David Lang <dlang@diginsite.com>
To: Larry Jackson <LarryJackson@iName.com>
cc: FWTK List Server <fwtk-users@lists.nai.com>,
        Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: install http-gw (Why run it as a daemon?)
In-Reply-To: <030c01c0b7bb$0e8f17c0$fc00a8c0@k62350>
Message-ID: <Pine.LNX.4.33.0103281215510.25227-100000@dlang.diginsite.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2847

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

you avoid the HUGE overhead that you get from inetd as well as the large
startup overhead for each connection.

David Lang

On Wed, 28 Mar 2001, Larry Jackson wrote:

 > Date: Wed, 28 Mar 2001 14:12:38 -0500
 > From: Larry Jackson <LarryJackson@iName.com>
 > To: FWTK List Server <fwtk-users@lists.nai.com>
 > Cc: Rick Murphy <rmurphy@itm-inst.com>
 > Subject: Re: install http-gw (Why run it as a daemon?)
 >
 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > What is the advantage of runnning http-d as a daemon, compared to runnning
 > it via inetd?
 >
 > Thanks,
 > LarryJackson@iName.com
 > ----- Original Message -----
 > From: "Rick Murphy" <rmurphy@itm-inst.com>
 > To: "wei zheng" <weizheng@uiuc.edu>; <fwtk-users@lists.nai.com>
 > Sent: Tuesday, March 27, 2001 9:04 PM
 > Subject: Re: install http-gw
 >
 >
 > > [To be removed from this list send the message "unsubscribe fwtk-users" in
 > the
 > > BODY of a mail message to majordomo@ex.tis.com.]
 > >
 > > At 11:38 PM 3/26/01 -0600, wei zheng wrote:
 > > >My questions are:
 > > >
 > > >What port should http-gw use? If it uses port 80, what port should httpd
 > > >use on the same machine? How to specify them? In which files?
 > >
 > > The http-gw can use any port you like, but it is typically configured to
 > > use port 80. It is highly inadvisable to use a http daemon (httpd) on your
 > > firewall.
 > >
 > > >What should the entries look like in inetd.conf and netperm-table?
 > >
 > > Don't put anything for http in the inetd.conf, a line like
 > > /usr/local/bin/http-gw -daemon 80
 > > in your rc.local, rc.inetd, or some other startup file.
 > > in your netperm-table, something like:
 > >
 > > http-gw: userid uucp
 > > http-gw: permit-hosts 1.2.3.4
 > > http-gw: deny-hosts *
 > > http-gw: permit-destination *
 > >
 > > is enough to get it working. (1.2.3.4 in the "permit-hosts" line above is
 > > your internal network.)
 > >
 > > >How could I tell the browser the existence of http-gw?
 > >
 > > Configure the web proxy on your browser to use the firewall port 80 (or
 > > whatever port http-gw uses.)
 > >
 > > >And after the inetd is reloaded, when the client on an inside machine
 > > >wants to connect to an outside http server, what URL should I enter in
 > > >the client brower's URL bar?
 > >
 > > If you set the proxy in the browser, the user simply enters the URL. If
 > you
 > > don't use a proxy, you must use the
 > > "http://firewall/http://external-host/directory" form.
 > >          -Rick
 > >
 > >
 >



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:58 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26480
	Mon, 2 Apr 2001 11:58:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14075;
	Mon, 2 Apr 2001 09:00:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:47:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29770
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:47:23 -0700 (PDT)
From: "Ken Long" <ken@lectrosonics.com>
Organization: Lectrosonics, Inc.
To: fwtk-users@lists.nai.com
Date: Tue, 27 Mar 2001 16:05:59 -0700
MIME-Version: 1.0
Content-transfer-encoding: 7BIT
Subject: Re: SMAP
Message-ID: <3AC0BA65.8737.C81819@localhost>
In-reply-to: <79C524BDBB22D411915800A0C96F68FB9FE30B@A8MC.PSNS.NAVY.MIL>
X-mailer: Pegasus Mail for Win32 (v3.12c)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=US-ASCII
Content-Length: 701

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Smap 2.1 plus the Yao patches will plug that up for you.  There is another 
branch in the development tree that will do the job as well.  That branch is 
maintained by Ted Keller on this list.

Ken

On 27 Mar 2001, at 13:21, Fritsch Jonathan D CONT PSNS wrote:

 >   Does anyone have or know of a configuration that will no allow promiscuous
 > relay though my firewall?  Or is their a version of smap and smapd that does
 > not allow that?



From owner-fwtk-users@ex.tis.com Mon Apr  2 11:59 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA26483
	Mon, 2 Apr 2001 11:58:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA14087;
	Mon, 2 Apr 2001 09:00:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 07:45:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29487
	for fwtk-users-outgoing; Mon, 2 Apr 2001 07:45:17 -0700 (PDT)
Date: Wed, 28 Mar 2001 22:00:04 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
cc: fwtk-users@lists.nai.com
Subject: Re: SMAP
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE30B@A8MC.PSNS.NAVY.MIL>
Message-ID: <Pine.GSO.4.10.10103282159170.1425-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 841

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

The Yao patches will do this - or, if you which, you can use my version
which as this feature and many more.  Let me know if you are interested.

ted keller


On Tue, 27 Mar 2001, Fritsch Jonathan D CONT PSNS wrote:

  > [To be removed from this list send the message "unsubscribe fwtk-users" in the
  > BODY of a mail message to majordomo@ex.tis.com.]
  > 
  >   Does anyone have or know of a configuration that will no allow promiscuous
  > relay though my firewall?  Or is their a version of smap and smapd that does
  > not allow that?
  > 
  > Thank You,
  >   Jonathan
  > 




From owner-fwtk-users@ex.tis.com Mon Apr  2 13:53 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA26760
	Mon, 2 Apr 2001 13:53:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA04409;
	Mon, 2 Apr 2001 10:55:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 09:50:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA24268
	for fwtk-users-outgoing; Mon, 2 Apr 2001 09:50:24 -0700 (PDT)
From: ark@eltex.ru
Date: Mon, 2 Apr 2001 21:07:53 +0400
Message-Id: <200104021707.VAA06556@paranoid.eltex.spb.ru>
Organization: "Klingon Imperial Intelligence Service"
Subject: squid-gw authentication patch?
To: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 613

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

nuqneH,

I remember reusable password proxy authentication patch for squid-gw was
posted here some months ago, does anybody still have it? The list archive search
system does not help much :(

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

From owner-fwtk-users@ex.tis.com Mon Apr  2 19:39 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA27808
	Mon, 2 Apr 2001 19:39:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA15754;
	Mon, 2 Apr 2001 16:41:46 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 2 Apr 2001 15:41:25 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA10242
	for fwtk-users-outgoing; Mon, 2 Apr 2001 15:41:08 -0700 (PDT)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE318@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@tis.com
Subject: ICQ
Date: Mon, 2 Apr 2001 15:34:40 -0700 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 185

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

What changes need to be made to allow ICQ though FWTK?


From owner-fwtk-users@ex.tis.com Thu Apr  5 16:39 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA11047
	Thu, 5 Apr 2001 16:39:26 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA07440;
	Thu, 5 Apr 2001 13:42:37 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 5 Apr 2001 12:14:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA25234
	for fwtk-users-outgoing; Thu, 5 Apr 2001 12:14:23 -0700 (PDT)
From: =?iso-8859-1?Q?Matthias_F=FCgger?= <matthias.fuegger@lion.cc>
To: <fwtk-users@lists.nai.com>
Subject: Problem using smap, smapd and sendmail
Date: Thu, 5 Apr 2001 21:13:25 +0200
Message-ID: <IFEPJNMCHGNJLPEHEMNOMEMACAAA.matthias.fuegger@lion.cc>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1079

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


I've got a problem using smap, smapd and sendmail:

I have installed TIS-FWTK on my computer, a PC 350MHz, running Linux (SuSE
7.0). It is used as a proxy server and firewall for my internal network
(containing Macs and Windows PCs).
Furthermore the newest version of sendmail is installed on the Linux PC.
When I tried to use smap to send mail from an internal PC, the mail is
stored on the firewall in the "/usr/spool/smapd" directory, 2 transcript
files are made ("pff34FPoK00789" and "qff34FPoK00789", which are stored in
"/usr/spool/mqueue", with a message in "qff34....":

MCan't create transcript file ./xff34FPoK00789 : Permission denied


When I run "sendmail -q" it produces the same error.

I ran "chown uucp /usr/spool/smapd", too and did the same with all other
directories and files, recommanded by the manual too, but I couldn't get rid
of the error-message.

Thank you in advance!

			Matthias Fuegger
			(matthias.fuegger@lion.cc)


From owner-fwtk-users@ex.tis.com Thu Apr  5 17:47 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA11167
	Thu, 5 Apr 2001 17:47:16 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA16443;
	Thu, 5 Apr 2001 14:50:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 5 Apr 2001 13:48:07 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA08031
	for fwtk-users-outgoing; Thu, 5 Apr 2001 13:47:46 -0700 (PDT)
Message-ID: <054701c0be11$406d4bc0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Subject: What is the best way to get/retry with FTP client?
Date: Thu, 5 Apr 2001 16:44:46 -0400
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 738

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I have a project where I use the telnet and ftp clients.
I send commands to a unix server via telnet, which works fine.

I then get the results of the unix program using FTP.
The problem is that it sometimes takes 5 or 10 seconds
for the Unix program to fully create the output file and
I need to wait to its done to get the file with FTP.

I currently try to get it, if it fails I set a TTimer and try again a second
later.
If it fails more a certain number of times I give up and it fails.

I'm not happy with my current implemation and want some other ideas/code
snippets.

Thanks,
LarryJackson@iName.com


From owner-fwtk-users@ex.tis.com Thu Apr  5 17:48 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA11173
	Thu, 5 Apr 2001 17:48:22 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA16657;
	Thu, 5 Apr 2001 14:51:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 5 Apr 2001 13:52:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA08698
	for fwtk-users-outgoing; Thu, 5 Apr 2001 13:52:34 -0700 (PDT)
Message-ID: <054f01c0be11$e18fe800$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Subject: Can you use ASync style events when using Sync commands?
Date: Thu, 5 Apr 2001 16:49:16 -0400
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 347

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I am using Sync FTP commands
(I know everyone loves the Async ones, but I can't do anything til I get the
file)
and want to modify the underlying Async events.

Should this cause any problems?

LarryJackson@iName.com


From owner-fwtk-users@ex.tis.com Thu Apr  5 21:24 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA11798
	Thu, 5 Apr 2001 21:24:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA02546;
	Thu, 5 Apr 2001 18:27:25 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 5 Apr 2001 17:24:28 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA29472
	for fwtk-users-outgoing; Thu, 5 Apr 2001 17:24:12 -0700 (PDT)
Date: Thu, 5 Apr 2001 20:23:23 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: =?iso-8859-1?Q?Matthias_F=FCgger?= <matthias.fuegger@lion.cc>
cc: fwtk-users@lists.nai.com
Subject: Re: Problem using smap, smapd and sendmail
In-Reply-To: <IFEPJNMCHGNJLPEHEMNOMEMACAAA.matthias.fuegger@lion.cc>
Message-ID: <Pine.GSO.4.10.10104052021300.24384-100000@ns1.bfg.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from QUOTED-PRINTABLE to 8bit by relay2.nai.com id RAA29467
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=X-UNKNOWN
Content-Length: 1637

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Matthias,

This appears to be a sendmail issue... the xff34FPoK00789 is essential a
lock file sendmail creates while actually processing (for sending) the
mail to a remote host.  Sendmail often forks - or otherwise runs a new
copy of its self.  I wonder if it is running as someone other than root?

ted keller


On Thu, 5 Apr 2001, [iso-8859-1] Matthias Függer wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> 
> I've got a problem using smap, smapd and sendmail:
> 
> I have installed TIS-FWTK on my computer, a PC 350MHz, running Linux (SuSE
> 7.0). It is used as a proxy server and firewall for my internal network
> (containing Macs and Windows PCs).
> Furthermore the newest version of sendmail is installed on the Linux PC.
> When I tried to use smap to send mail from an internal PC, the mail is
> stored on the firewall in the "/usr/spool/smapd" directory, 2 transcript
> files are made ("pff34FPoK00789" and "qff34FPoK00789", which are stored in
> "/usr/spool/mqueue", with a message in "qff34....":
> 
> MCan't create transcript file ./xff34FPoK00789 : Permission denied
> 
> 
> When I run "sendmail -q" it produces the same error.
> 
> I ran "chown uucp /usr/spool/smapd", too and did the same with all other
> directories and files, recommanded by the manual too, but I couldn't get rid
> of the error-message.
> 
> Thank you in advance!
> 
> 			Matthias Fuegger
> 			(matthias.fuegger@lion.cc)
> 


From owner-fwtk-users@ex.tis.com Fri Apr  6 09:35 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA13846
	Fri, 6 Apr 2001 09:35:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA29044;
	Fri, 6 Apr 2001 06:38:16 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 6 Apr 2001 05:34:19 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA24998
	for fwtk-users-outgoing; Fri, 6 Apr 2001 05:33:58 -0700 (PDT)
Message-ID: <3ACDB736.CFA8A8D0@uni-bonn.de>
Date: Fri, 06 Apr 2001 14:31:50 +0200
From: Uwe Krause <uzswas@uni-bonn.de>
X-Mailer: Mozilla 4.74 [en] (X11; U; Linux 2.2.16 i586)
X-Accept-Language: en
MIME-Version: 1.0
To: "fwtk-users@tis.com" <fwtk-users@tis.com>
Subject: mail through firewall
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 713

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello everybody out there,

I have set up fwtk 2.1 with http, telnet and ftp gateways functioning
with Netscape 4.74 on my internal hosts. 
What I have problems with is getting mail through the firewall in
either direction (in and out). For sending mail I have to use POP3
protocol with my ISP. Smtp queuer and listener run as daemons and my
mail is queued on the firewall (but I cannot get _rid_ of it).
Any hints on how to configure sendmail.cf (provided by SuSE 7.0) to
forward mails?
ThanX in advance
Uwe

-- 
Uwe Krause
Dohmstr. 2
Germany, 53121 Bonn
e-mail: uzswas@uni-bonn.de


From owner-fwtk-users@ex.tis.com Fri Apr  6 11:26 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA14306
	Fri, 6 Apr 2001 11:26:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA13599;
	Fri, 6 Apr 2001 08:29:07 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 6 Apr 2001 07:22:16 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA03799
	for fwtk-users-outgoing; Fri, 6 Apr 2001 07:21:56 -0700 (PDT)
Message-ID: <3ACE5D0B.E4F6ACFA@yahoo.com>
Date: Sat, 07 Apr 2001 10:19:23 +1000
From: Educatee <educatee2001@yahoo.com>
X-Mailer: Mozilla 4.76 [en] (X11; U; FreeBSD 4.2-RELEASE i386)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users newsgroup <fwtk-users@lists.nai.com>
Subject: how do I get started with fwtk? plz advice.
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 571

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I have done the following:

1. installed FreeBSD4.2
2. download fwtk2.1.tar.Z and fwtk-doc-only.tar.Z
    place these two files in /usr/ports/distfiles
3. run make at /usr/ports/security/fwtk
    and it's ok

What do I do next? How can I test run? Is there any place in the
internet I could learn the complete setup til test run before I goes
into more details? I am very new to this fwtk. I appreciate any advice
you could gave me. Thanks.


From owner-fwtk-users@ex.tis.com Sat Apr  7 05:08 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA16471
	Sat, 7 Apr 2001 05:08:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA18626;
	Sat, 7 Apr 2001 02:11:19 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 7 Apr 2001 00:59:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id AAA17209
	for fwtk-users-outgoing; Sat, 7 Apr 2001 00:59:27 -0700 (PDT)
From: jkm_79@sify.com
To: smceachern@jamedia.com, Scott McEachern <smceachern@jamedia.com>
Subject: Re: Deny Access
Message-ID: <986629827.3acec6c395f9f@webdev.maa.sify.net>
Date: Sat, 07 Apr 2001 13:20:27 +0600 (IST)
Cc: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>,
        fwtk-users@lists.nai.com
References: <79C524BDBB22D411915800A0C96F68FB9FE310@A8MC.PSNS.NAVY.MIL> <3AC48001.6E0DCE3D@jamedia.com>
In-Reply-To: <3AC48001.6E0DCE3D@jamedia.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
User-Agent: IMP/PHP IMAP webmail program 2.2.3
X-Originating-IP: 210.214.178.153
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 1734

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

friends,
There is an option in http-gw called url-filter.
enter like this in netperm-table
http-gw: url-filter http://

you can see the message like requested url is not valid.
you can prevent the usage of http ie the entire url


*****************************************************************
Quoting Scott McEachern <smceachern@jamedia.com>:

> [To be removed from this list send the message "unsubscribe fwtk-users"
> in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Fritsch Jonathan D CONT PSNS wrote:
> 
>  > [To be removed from this list send the message "unsubscribe
> fwtk-users" in the
>  > BODY of a mail message to majordomo@ex.tis.com.]
>  >
>  >   Does any one know of the command to place in the netperm-table to
> deny web
>  > access to a URL?
>  >
>  > - Jonathan
> 
>      I could be wrong here, but I don't think that's a part of the
> FWTK's
> functionality.
>      However, once upon a time when I actually gave a darn where people
> surfed
> what I did was use my internal DNS server to ``host'' the restricted
> domains.
> The DNS would point to an internal web server with a page that said
> something to
> the effect of ``access is restricted.''  Obviously my DNS wasn't serving
> to
> anything other than our intranet, but this worked for me.  HTH.
> 
> --
> R. Scott McEachern, Network Administrator
> J&A Media Services, Inc.
> 300 John St., Suite 500, Thornhill, ON, CA  L3T 5W4
> tel:905-881-6902  fax:905-881-6945
> 
> 
> 
> 
> 

-------------------------------------------------
Vaseline Lipguard Keep Smiling
This mail sent through : http://mail.sify.com

From owner-fwtk-users@ex.tis.com Sat Apr  7 06:21 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA16580
	Sat, 7 Apr 2001 06:21:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA20505;
	Sat, 7 Apr 2001 03:24:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 7 Apr 2001 02:28:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA18976
	for fwtk-users-outgoing; Sat, 7 Apr 2001 02:28:07 -0700 (PDT)
From: =?us-ascii?Q?Matthias_Fugger?= <matthias.fuegger@lion.cc>
To: <fwtk-users@lists.nai.com>
Subject: Re: Problem using smap, smapd and sendmail
Date: Sat, 7 Apr 2001 11:27:23 +0200
Message-ID: <IFEPJNMCHGNJLPEHEMNOOEMGCAAA.matthias.fuegger@lion.cc>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
Importance: Normal
In-Reply-To: <Pine.NEB.4.05.10104060817170.24895-100000@vals.intramed.rito.no>
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="us-ascii"
Content-Length: 862

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, 5 Apr 2001, Ted Keller wrote:

> This appears to be a sendmail issue... the xff34FPoK00789 is essential a
> lock file sendmail creates while actually processing (for sending) the
> mail to a remote host.  Sendmail often forks - or otherwise runs a new
> copy of its self.  I wonder if it is running as someone other than root?

With current versions of sendmail you can specify
O RunAsUser=
in sendmail.cf (the program itself is installed suid root)

Anders Baardsgaard  ---  <anders@nhn.no>

------------------------------------------------------------

Thank you,

I set "O RunAsUser=uucp" and it worked! It seems that it doesn't have to be
set to "root", like expected.

			Matthias Fuegger
			(matthias.fuegger@lion.cc)


From owner-fwtk-users@ex.tis.com Mon Apr  9 15:55 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA22830
	Mon, 9 Apr 2001 15:54:59 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA04952;
	Mon, 9 Apr 2001 12:57:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 9 Apr 2001 11:33:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA24515
	for fwtk-users-outgoing; Mon, 9 Apr 2001 11:33:21 -0700 (PDT)
Message-Id: <4.2.2.20010409100132.00bb18c0@mail.xidak.com>
X-Sender: damian@mail.xidak.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.2 
Date: Mon, 09 Apr 2001 11:35:48 -0700
To: fwtk-users@lists.nai.com
From: "R. Damian Koziel" <damian@xidak.com>
Subject: FWTK & SKey...
Cc: damian@xidak.com
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 736

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Greetings.

I have been all over the net and have been unable to find a distribution of
*both* FWTK and S/Key that will compile GNU C  Version 2.95.2 or the
Sun WorkShop Compiler C Version 4.2 under Solaris 2.6 even after tweaking
the source to amend the list of include files.

If this is a known problem, can anyone point me to another UNIX proxy server
that will handle OTP?  Alternately, pointers to a SSH telnet client/server
that will run either under Solaris 2.6 or NT 4 would also be of interest.

Any tips are greatly appreciated.  Thanks!

R. Damian Koziel
XIDAK, Inc.
damian@-nospam-xidak.com



From owner-fwtk-users@ex.tis.com Tue Apr 10 08:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA25256
	Tue, 10 Apr 2001 08:32:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA29397;
	Tue, 10 Apr 2001 05:35:26 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 10 Apr 2001 04:34:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA26361
	for fwtk-users-outgoing; Tue, 10 Apr 2001 04:33:36 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010409172209.01d61390@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Mon, 09 Apr 2001 17:26:19 -0400
To: "R. Damian Koziel" <damian@xidak.com>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FWTK & SKey...
Cc: damian@xidak.com
In-Reply-To: <4.2.2.20010409100132.00bb18c0@mail.xidak.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1137

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 11:35 AM 4/9/01 -0700, R. Damian Koziel wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >
 >Greetings.
 >
 >I have been all over the net and have been unable to find a distribution of
 >*both* FWTK and S/Key that will compile GNU C  Version 2.95.2 or the
 >Sun WorkShop Compiler C Version 4.2 under Solaris 2.6 even after tweaking
 >the source to amend the list of include files.

S/Key is old and uses the older terminal functions; if you try to compile 
it on Solaris it won't work. However, none of the terminal handling code is 
used with FWTK.
You should be able to simply comment out the source lines in S/Key that are 
failing to compile and use what results.

A better idea would be to use something that's being maintained, and which 
uses a better hash - OPIE (One-Time Passwords in Everything) is a better 
choice.
Available from ftp.nrl.navy.mil, or google search for "NRL OPIE".
          -Rick



From owner-fwtk-users@ex.tis.com Wed Apr 11 17:00 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA00793
	Wed, 11 Apr 2001 17:00:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA29869;
	Wed, 11 Apr 2001 13:58:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 12:36:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA20987
	for fwtk-users-outgoing; Wed, 11 Apr 2001 12:35:52 -0700 (PDT)
Message-ID: <62BF4FEB8A80D411885D00508BE3A85EAB780E@SF-EXCH-6>
From: "Miller, Richard  M." <rmmiller@bofasecurities.com>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: plug-gw logs deny=(source host)
Date: Wed, 11 Apr 2001 12:34:38 -0700
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 3328

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I'm trying to setup plug-gw to proxy (and I use the term lightly) between
two networks that have no route to each other, but have a route to my
service network (DMZ). These networks are in extranet format and in no way
are connected to the internet.   There are very little routes in either
direction and each host can sucessfully initiate traffice to my plug-gw box.


I've configured the fwtk to use only plug-gw in the following manner:

(netperm-table) 

sna-gw: port sna-print peanut plug-to sna-print-host1 -port sna-print  

where:  sna-print is definded as port 8023 in my services file, and peanut
is the host that i'm testing from., and sna-print-host1 is the destination
of the print jobs ( a FEB running TN3270E for a printer session)


(line from services file)

sna-print       8023/tcp


plug-gw is configured to start from inetd:

(line from inetd.conf)
sna-print stream tcp nowait root /usr/local/etc/plug-gw sna-gw sna-print


When I configure a sna print session with a valid LU and destination, the
stream gets denied by plug-gw.  Keep in mind these networks have free and
clear access to my proxy box, but not each other. This is running on solairs
7 on sun hardware with all the latest patches.  Complied with GNU gcc and
GNU make on a full developer distribution load (on another dev box) and
seems to startup fine.  Netstat shows my box listening on port *.8023 (there
are four IP address's bound to hme0) and I get the following entries in
/var/adm/messages

Apr 10 11:23:17 proxy1 plug-gw[1671]: deny host=peanut/10.223.35.21
service=sna-
print
Apr 10 11:45:44 proxy1 plug-gw[1672]: deny host=peanut/10.223.35.21
service=sna-
print

It's clear to me that plug is denying the connection, even though "peanut"
is explicitly allowed in the netperm table.  scoured the Internet and can't
find any evidence that another service from the fwtk needs to be running.
Could this be the case??

I'm stumped.


This is driving me crazy, if anyone can help me I'd be willing to drive to
you and take you out for lunch if your in No. California...LOL!!


thx in advance.

 


Richard Miller
Sr. Network Analyst
SF Network Engineering Group 
Banc of America BrokerDealer Services
(formally Montgomery Correspondant Services)
Banc of America Securities, LLC
655 Montgomery Street
San Francisco, Ca. 94111
Phone: 415.913.4223
Cell: 510-517-8555
Fax: 415.913.6542
eMail: Rmmiller@bofasecurities.com




_____________________________________________________________________ 
IMPORTANT NOTICES: 
          This message is intended only for the addressee. Please notify the
sender by e-mail if you are not the intended recipient. If you are not the
intended recipient, you may not copy, disclose, or distribute this message
or its contents to any other person and any such actions may be unlawful.

         Banc of America Securities LLC("BAS") does not accept time
sensitive, action-oriented messages or transaction orders, including orders
to purchase or sell securities, via e-mail.

         BAS reserves the right to monitor and review the content of all
messages sent to or from this e-mail address. Messages sent to or from this
e-mail address may be stored on the BAS e-mail system.



From owner-fwtk-users@ex.tis.com Wed Apr 11 18:27 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA00959
	Wed, 11 Apr 2001 18:27:43 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA08100;
	Wed, 11 Apr 2001 15:24:55 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 14:24:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA02584
	for fwtk-users-outgoing; Wed, 11 Apr 2001 14:23:54 -0700 (PDT)
X-Authentication-Warning: proxy.tfcc.com: mail set sender to <twilliams@tfcci.com> using -f
From: "Todd Williams" <twilliams@tfcci.com>
To: <fwtk-users@lists.nai.com>
Subject: FTP-GW related question
Date: Wed, 11 Apr 2001 17:22:38 -0400
Message-ID: <028301c0c2cd$897dc860$c802a8c0@toddntbox.tfcc.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 789

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

We have recently added an application server using the FWTK 2.1's ftp-gw.
There is no authentication happening, nor should there be as there is no
auth server defined.  I've been using the ftp-gw in the past from other
hosts without any issues, however I am beginning to suspect that something
the ftp client of the app server has somehow generated these auth related
error messages in syslog:

Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver defined!
cannot authenticate!
Apr 11 16:50:37 fwtkhost ftp-gw[13903]: app1.my-internal.com/192.168.123.4:
STOR foo.txt


Is there any easy way to clean this error up?

Thanks in advance,

Todd


From owner-fwtk-users@ex.tis.com Wed Apr 11 21:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA01356
	Wed, 11 Apr 2001 21:32:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA19324;
	Wed, 11 Apr 2001 18:29:45 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 17:30:10 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA15714
	for fwtk-users-outgoing; Wed, 11 Apr 2001 17:29:55 -0700 (PDT)
Message-ID: <3AD4F720.B9A872C9@v-one.com>
Date: Wed, 11 Apr 2001 20:30:24 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Todd Williams <twilliams@tfcci.com>, fwtk-users@lists.nai.com
Subject: Re: FTP-GW related question
References: <028301c0c2cd$897dc860$c802a8c0@toddntbox.tfcc.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 942

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Todd Williams wrote:
> 
> We have recently added an application server using the FWTK 2.1's ftp-gw.
> There is no authentication happening, nor should there be as there is no
> auth server defined.  I've been using the ftp-gw in the past from other
> hosts without any issues, however I am beginning to suspect that something
> the ftp client of the app server has somehow generated these auth related
> error messages in syslog:
> 
> Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver defined!
> cannot authenticate!
> Apr 11 16:50:37 fwtkhost ftp-gw[13903]: app1.my-internal.com/192.168.123.4:
> STOR foo.txt
> 
> Is there any easy way to clean this error up?
> 

Todd,

What does your netperm-table look like?

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Wed Apr 11 21:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA01359
	Wed, 11 Apr 2001 21:32:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA19336;
	Wed, 11 Apr 2001 18:30:01 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 17:37:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA16130
	for fwtk-users-outgoing; Wed, 11 Apr 2001 17:36:45 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010411202737.01d4de40@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 11 Apr 2001 20:30:50 -0400
To: "Miller, Richard  M." <rmmiller@bofasecurities.com>,
        "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: plug-gw logs deny=(source host)
In-Reply-To: <62BF4FEB8A80D411885D00508BE3A85EAB780E@SF-EXCH-6>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 674

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 12:34 PM 4/11/01 -0700, Miller, Richard  M. wrote:
>(line from inetd.conf)
>sna-print stream tcp nowait root /usr/local/etc/plug-gw sna-gw sna-print

Change this to
sna-print stream tcp nowait root /usr/local/etc/plug-gw plug-gw sna-gw
Or, start it as a daemon:
/usr/local/etc/plug-gw -daemon sna-print sna-gw
Or, change the netperm-table to be
plug-gw: port sna-print peanut plug-to sna-print-host1 -port sna-print

Why is because plug-gw looks up rules using argv[1]. In your inetd.conf, 
the first argument is "sna-print".
         -Rick


From owner-fwtk-users@ex.tis.com Wed Apr 11 21:49 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA01393
	Wed, 11 Apr 2001 21:49:55 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA20518;
	Wed, 11 Apr 2001 18:47:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 17:52:10 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA16927
	for fwtk-users-outgoing; Wed, 11 Apr 2001 17:51:53 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010411203611.01d46140@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Wed, 11 Apr 2001 20:39:13 -0400
To: "Todd Williams" <twilliams@tfcci.com>, <fwtk-users@lists.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: FTP-GW related question
In-Reply-To: <028301c0c2cd$897dc860$c802a8c0@toddntbox.tfcc.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 645

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 05:22 PM 4/11/01 -0400, Todd Williams wrote:

>Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver defined!
>cannot authenticate!
>Apr 11 16:50:37 fwtkhost ftp-gw[13903]: app1.my-internal.com/192.168.123.4:
>STOR foo.txt
>
>
>Is there any easy way to clean this error up?
You've got -auth or -authall enabled on the ftp-gw, or your user is 
entering an "auth" command. It's possible they're running some peecee FTP 
client that's sending an auth command for some reason or another..
         -Rick


From owner-fwtk-users@ex.tis.com Wed Apr 11 22:50 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA01466
	Wed, 11 Apr 2001 22:50:41 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA24162;
	Wed, 11 Apr 2001 19:48:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 18:49:54 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA20650
	for fwtk-users-outgoing; Wed, 11 Apr 2001 18:49:33 -0700 (PDT)
Message-ID: <084d01c0c2f2$182ab4a0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Subject: Any easy way to specify server for SMTP?
Date: Wed, 11 Apr 2001 21:44:20 -0400
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 700

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I have multiple SMTP servers and was wondering 
if there are any patches to easily change servers?

Right now I am using separate ports for different servers via plug-gw,
but I would really like to specify the server from my mail program.

I currently use pop-gw to specify different POP servers on the username.
I know SMTP doesn't usually need authorization, BUT
I was wondering how hard it would be to use authorization, 
between the client and the firewall only, 
to specify a SMTP server on the username.

Any thoughts or other suggestions?

LarryJackson@iName.com


From owner-fwtk-users@ex.tis.com Wed Apr 11 23:37 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA01506
	Wed, 11 Apr 2001 23:37:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA26221;
	Wed, 11 Apr 2001 20:35:10 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 19:39:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA23665
	for fwtk-users-outgoing; Wed, 11 Apr 2001 19:38:48 -0700 (PDT)
Date: Wed, 11 Apr 2001 22:37:35 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Larry Jackson <LarryJackson@iName.com>
cc: FWTK List Server <fwtk-users@lists.nai.com>
Subject: Re: Any easy way to specify server for SMTP?
In-Reply-To: <084d01c0c2f2$182ab4a0$fc00a8c0@k62350>
Message-ID: <Pine.GSO.4.10.10104112236140.15197-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1167

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Larry,

Not sure if I fully understand your question.... but it seems that you
should be able to use the smap/smapd stuff with sendmail - and use the
sendmail mailertable to direct mail to multiple internal servers.  Am I
barking up the wrong tree?

tek


On Wed, 11 Apr 2001, Larry Jackson wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I have multiple SMTP servers and was wondering 
> if there are any patches to easily change servers?
> 
> Right now I am using separate ports for different servers via plug-gw,
> but I would really like to specify the server from my mail program.
> 
> I currently use pop-gw to specify different POP servers on the username.
> I know SMTP doesn't usually need authorization, BUT
> I was wondering how hard it would be to use authorization, 
> between the client and the firewall only, 
> to specify a SMTP server on the username.
> 
> Any thoughts or other suggestions?
> 
> LarryJackson@iName.com
> 


From owner-fwtk-users@ex.tis.com Thu Apr 12 01:09 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id BAA01615
	Thu, 12 Apr 2001 01:09:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id WAA00543;
	Wed, 11 Apr 2001 22:06:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 11 Apr 2001 21:08:55 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA27862
	for fwtk-users-outgoing; Wed, 11 Apr 2001 21:08:34 -0700 (PDT)
Message-ID: <20010412040806.7165.qmail@web11001.mail.yahoo.com>
Date: Wed, 11 Apr 2001 21:08:06 -0700 (PDT)
From: Naresh Narang <nknarang@yahoo.com>
Subject: Proxy Arp
To: fwtk-users@lists.nai.com
In-Reply-To: <Pine.GSO.4.10.10104112236140.15197-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 479

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi there,

   I am thinking of using proxy arp and Plug-gw to
redirect mail to Internal mail server. I know about
smap but was just wondering if it is safe?

Any inputs?

Thanks,
Naresh

=====
-- Naresh

__________________________________________________
Do You Yahoo!?
Get email at your own domain with Yahoo! Mail. 
http://personal.mail.yahoo.com/

From owner-fwtk-users@ex.tis.com Thu Apr 12 09:39 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA02836
	Thu, 12 Apr 2001 09:39:48 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA13837;
	Thu, 12 Apr 2001 06:37:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 12 Apr 2001 05:32:51 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA11497
	for fwtk-users-outgoing; Thu, 12 Apr 2001 05:32:30 -0700 (PDT)
Message-ID: <8393490.987024161223.JavaMail.imail@dotty.excite.com>
Date: Wed, 11 Apr 2001 14:22:41 -0700 (PDT)
From: "T. Esting" <T_Esting@excite.com>
Reply-To: <T_Esting@excite.com>
To: "Miller, Richard  M." <rmmiller@bofasecurities.com>,
        "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Subject: Re: plug-gw logs deny=(source host)
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Mailer: Excite Inbox
X-Sender-Ip: 4.17.250.5
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 4134

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


   Any chance peanut is a CNAME?  plug-gw is very particular about host name
matching.

On Wed, 11 Apr 2001 12:34:38 -0700, Miller, Richard  M. wrote:

 >  [To be removed from this list send the message "unsubscribe fwtk-users"
in the
 >  BODY of a mail message to majordomo@ex.tis.com.]
 >  
 >  I'm trying to setup plug-gw to proxy (and I use the term lightly) between
 >  two networks that have no route to each other, but have a route to my
 >  service network (DMZ). These networks are in extranet format and in no
way
 >  are connected to the internet.   There are very little routes in either
 >  direction and each host can sucessfully initiate traffice to my plug-gw
box.
 >  
 >  
 >  I've configured the fwtk to use only plug-gw in the following manner:
 >  
 >  (netperm-table) 
 >  
 >  sna-gw: port sna-print peanut plug-to sna-print-host1 -port sna-print  
 >  
 >  where:  sna-print is definded as port 8023 in my services file, and
peanut
 >  is the host that i'm testing from., and sna-print-host1 is the
destination
 >  of the print jobs ( a FEB running TN3270E for a printer session)
 >  
 >  
 >  (line from services file)
 >  
 >  sna-print       8023/tcp
 >  
 >  
 >  plug-gw is configured to start from inetd:
 >  
 >  (line from inetd.conf)
 >  sna-print stream tcp nowait root /usr/local/etc/plug-gw sna-gw sna-print
 >  
 >  
 >  When I configure a sna print session with a valid LU and destination, the
 >  stream gets denied by plug-gw.  Keep in mind these networks have free and
 >  clear access to my proxy box, but not each other. This is running on
solairs
 >  7 on sun hardware with all the latest patches.  Complied with GNU gcc and
 >  GNU make on a full developer distribution load (on another dev box) and
 >  seems to startup fine.  Netstat shows my box listening on port *.8023
(there
 >  are four IP address's bound to hme0) and I get the following entries in
 >  /var/adm/messages
 >  
 >  Apr 10 11:23:17 proxy1 plug-gw[1671]: deny host=peanut/10.223.35.21
 >  service=sna-
 >  print
 >  Apr 10 11:45:44 proxy1 plug-gw[1672]: deny host=peanut/10.223.35.21
 >  service=sna-
 >  print
 >  
 >  It's clear to me that plug is denying the connection, even though
"peanut"
 >  is explicitly allowed in the netperm table.  scoured the Internet and
can't
 >  find any evidence that another service from the fwtk needs to be running.
 >  Could this be the case??
 >  
 >  I'm stumped.
 >  
 >  
 >  This is driving me crazy, if anyone can help me I'd be willing to drive
to
 >  you and take you out for lunch if your in No. California...LOL!!
 >  
 >  
 >  thx in advance.
 >  
 >   
 >  
 >  
 >  Richard Miller
 >  Sr. Network Analyst
 >  SF Network Engineering Group 
 >  Banc of America BrokerDealer Services
 >  (formally Montgomery Correspondant Services)
 >  Banc of America Securities, LLC
 >  655 Montgomery Street
 >  San Francisco, Ca. 94111
 >  Phone: 415.913.4223
 >  Cell: 510-517-8555
 >  Fax: 415.913.6542
 >  eMail: Rmmiller@bofasecurities.com
 >  
 >  
 >  
 >  
 >  _____________________________________________________________________ 
 >  IMPORTANT NOTICES: 
 >            This message is intended only for the addressee. Please notify
the
 >  sender by e-mail if you are not the intended recipient. If you are not
the
 >  intended recipient, you may not copy, disclose, or distribute this
message
 >  or its contents to any other person and any such actions may be unlawful.
 >  
 >           Banc of America Securities LLC("BAS") does not accept time
 >  sensitive, action-oriented messages or transaction orders, including
orders
 >  to purchase or sell securities, via e-mail.
 >  
 >           BAS reserves the right to monitor and review the content of all
 >  messages sent to or from this e-mail address. Messages sent to or from
this
 >  e-mail address may be stored on the BAS e-mail system.
 >  
 >





_______________________________________________________
Send a cool gift with your E-Card
http://www.bluemountain.com/giftcenter/




From owner-fwtk-users@ex.tis.com Thu Apr 12 12:12 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA03200
	Thu, 12 Apr 2001 12:12:52 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA18899;
	Thu, 12 Apr 2001 09:10:23 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 12 Apr 2001 08:12:22 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA17203
	for fwtk-users-outgoing; Thu, 12 Apr 2001 08:12:06 -0700 (PDT)
X-Authentication-Warning: proxy.tfcc.com: mail set sender to <twilliams@tfcci.com> using -f
From: "Todd Williams" <twilliams@tfcci.com>
To: "'Keith Young'" <kyoung@v-one.com>, <fwtk-users@lists.nai.com>
Cc: "'Rick Murphy'" <rmurphy@itm-inst.com>
Subject: RE: FTP-GW related question
Date: Thu, 12 Apr 2001 10:30:42 -0400
Message-ID: <02a101c0c35d$28184d30$c802a8c0@toddntbox.tfcc.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
In-Reply-To: <3AD4F720.B9A872C9@v-one.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1889

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Todd Williams wrote:
>
> We have recently added an application server using the FWTK 2.1's ftp-gw.
> There is no authentication happening, nor should there be as there is no
> auth server defined.  I've been using the ftp-gw in the past from other
> hosts without any issues, however I am beginning to suspect that something
> the ftp client of the app server has somehow generated these auth related
> error messages in syslog:
>
> Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver defined!
> cannot authenticate!
> Apr 11 16:50:37 fwtkhost ftp-gw[13903]:
app1.my-internal.com/192.168.123.4:
> STOR foo.txt
>
> Is there any easy way to clean this error up?
>
>>
>>Todd,
>>
>>What does your netperm-table look like?
>>
>>--
>>--Keith Young
>>-Director of Customer Care/Support, V-ONE Corp.
>>-kyoung@v-one.com

The numbers have been changed to protect the innocent.  :)

netacl-in.ftpd: timeout 60
netacl-in.ftpd: hosts 192.168.8.100 -exec /usr/sbin/in.ftpd -l -a
netacl-in.ftpd: hosts 192.168.8.118 -exec /usr/sbin/in.ftpd -l -a
netacl-in.ftpd: hosts 192.168.8.145 -exec /usr/sbin/in.ftpd -l -a
netacl-in.ftpd: hosts 192.168.8.149 -exec /usr/sbin/in.ftpd -l -a
netacl-in.ftpd: hosts 192.168.9.135 -exec /usr/sbin/in.ftpd -l -a
netacl-in.ftpd: hosts unknown -exec /bin/cat /usr/local/etc/ftp/noftp.txt
netacl-in.ftpd: hosts * -exec /bin/cat /usr/local/etc/ftp/noftp.txt


Note, there is no reference to -auth or -authall.  The ftp application
(Net::FTP perl module) is possibly generating some sort of auth request, and
perhaps that's where we need to look.  Regardless, I was pondering if there
was an easy way to shut off the logging messages like this: "fwtkcfgerr: no
authserver defined! cannot authenticate!" in this case.

Thanks,

Todd


From owner-fwtk-users@ex.tis.com Thu Apr 12 22:31 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id WAA04527
	Thu, 12 Apr 2001 22:31:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id TAA09529;
	Thu, 12 Apr 2001 19:29:07 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 12 Apr 2001 18:14:23 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id SAA07332
	for fwtk-users-outgoing; Thu, 12 Apr 2001 18:13:55 -0700 (PDT)
Date: Thu, 12 Apr 2001 20:36:29 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Todd Williams <twilliams@tfcci.com>
cc: "'Keith Young'" <kyoung@v-one.com>, fwtk-users@lists.nai.com,
        "'Rick Murphy'" <rmurphy@itm-inst.com>
Subject: RE: FTP-GW related question
In-Reply-To: <02a101c0c35d$28184d30$c802a8c0@toddntbox.tfcc.com>
Message-ID: <Pine.GSO.4.10.10104122035120.18664-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2428

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

So your allowing specific addresses to ftp to your firewall? - then using
the vendor ftp daemon to connect externally.....  You may want to
reconsider this (or I'm not understanding what your are trying to do - and
use the ftp-gw for ftp proxying.

ted keller


On Thu, 12 Apr 2001, Todd Williams wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Todd Williams wrote:
> >
> > We have recently added an application server using the FWTK 2.1's ftp-gw.
> > There is no authentication happening, nor should there be as there is no
> > auth server defined.  I've been using the ftp-gw in the past from other
> > hosts without any issues, however I am beginning to suspect that something
> > the ftp client of the app server has somehow generated these auth related
> > error messages in syslog:
> >
> > Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver defined!
> > cannot authenticate!
> > Apr 11 16:50:37 fwtkhost ftp-gw[13903]:
> app1.my-internal.com/192.168.123.4:
> > STOR foo.txt
> >
> > Is there any easy way to clean this error up?
> >
> >>
> >>Todd,
> >>
> >>What does your netperm-table look like?
> >>
> >>--
> >>--Keith Young
> >>-Director of Customer Care/Support, V-ONE Corp.
> >>-kyoung@v-one.com
> 
> The numbers have been changed to protect the innocent.  :)
> 
> netacl-in.ftpd: timeout 60
> netacl-in.ftpd: hosts 192.168.8.100 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.8.118 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.8.145 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.8.149 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.9.135 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts unknown -exec /bin/cat /usr/local/etc/ftp/noftp.txt
> netacl-in.ftpd: hosts * -exec /bin/cat /usr/local/etc/ftp/noftp.txt
> 
> 
> Note, there is no reference to -auth or -authall.  The ftp application
> (Net::FTP perl module) is possibly generating some sort of auth request, and
> perhaps that's where we need to look.  Regardless, I was pondering if there
> was an easy way to shut off the logging messages like this: "fwtkcfgerr: no
> authserver defined! cannot authenticate!" in this case.
> 
> Thanks,
> 
> Todd
> 


From owner-fwtk-users@ex.tis.com Fri Apr 13 07:33 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA05429
	Fri, 13 Apr 2001 07:33:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA26060;
	Fri, 13 Apr 2001 04:31:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 03:31:34 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA24708
	for fwtk-users-outgoing; Fri, 13 Apr 2001 03:31:13 -0700 (PDT)
Date: Fri, 13 Apr 2001 03:31:56 -0700 (PDT)
Message-Id: <200104131031.DAA28699@electabuzz.tmcs.net>
X-Sender: Mark Bergstrom@pascamail-2.office.tmcs
X-Mailer: Windows Eudora Pro Version 2.1.2
Mime-Version: 1.0
To: Naresh Narang <nknarang@yahoo.com>, fwtk-users@lists.nai.com
From: Mark Bergstrom <mjollnir@citysearch.com>
Subject: Re: Proxy Arp
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"
Content-Length: 1283

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

OK, but for checking mail, your users (even marketing droids) should have
something like SecureCRT on their laptops; and you should have an
ssh-gateway (hint, modify /etc/profile to alter $PATH, run a check for
$SSH_CLIENT, and invoke /usr/lib/rsh with a ~/bin reduced to ssh, xauth, and
maybe telnet) so that they get setup to check mail on localhost with port 25
(and 110) forwarded to your hidden internal network mailserver.  You don't
make clear what you want.

Dr.B

At 09:08 PM 4/11/01 -0700, Naresh Narang wrote:
>[To be removed from this list send the message "unsubscribe fwtk-users" in the
>BODY of a mail message to majordomo@ex.tis.com.]
>
>Hi there,
>
>   I am thinking of using proxy arp and Plug-gw to
>redirect mail to Internal mail server. I know about
>smap but was just wondering if it is safe?
>
>Any inputs?
>
>Thanks,
>Naresh
>
>=====
>-- Naresh
>
>__________________________________________________
>Do You Yahoo!?
>Get email at your own domain with Yahoo! Mail. 
>http://personal.mail.yahoo.com/
>
______________________________________________________________________________
UNIX TEAM --Lasciate ogne speranza, voi ch'intrate


From owner-fwtk-users@ex.tis.com Fri Apr 13 11:29 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA05991
	Fri, 13 Apr 2001 11:29:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA01139;
	Fri, 13 Apr 2001 08:26:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 07:25:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA29308
	for fwtk-users-outgoing; Fri, 13 Apr 2001 07:24:42 -0700 (PDT)
X-Authentication-Warning: proxy.tfcc.com: mail set sender to <twilliams@tfcci.com> using -f
From: "Todd Williams" <twilliams@tfcci.com>
To: "'Ted Keller'" <keller@bfg.com>
Cc: "'Keith Young'" <kyoung@v-one.com>, <fwtk-users@lists.nai.com>,
        "'Rick Murphy'" <rmurphy@itm-inst.com>
Subject: RE: FTP-GW related question
Date: Fri, 13 Apr 2001 10:22:31 -0400
Message-ID: <02c701c0c425$30fa7bd0$c802a8c0@toddntbox.tfcc.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
In-Reply-To: <Pine.GSO.4.10.10104122035120.18664-100000@ns1.bfg.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2878

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

We're allowing specific internal private RFC 1918 host addresses to use the
ftp-gw as an ftp proxy to public internet sites, and seeing the error
messages as previously mentioned.  There is no FTP'ing to the firewall.

Todd Williams

-----Original Message-----
From: Ted Keller [mailto:keller@bfg.com]
Sent: Thursday, April 12, 2001 8:36 PM
To: Todd Williams
Cc: 'Keith Young'; fwtk-users@lists.nai.com; 'Rick Murphy'
Subject: RE: FTP-GW related question


So your allowing specific addresses to ftp to your firewall? - then using
the vendor ftp daemon to connect externally.....  You may want to
reconsider this (or I'm not understanding what your are trying to do - and
use the ftp-gw for ftp proxying.

ted keller


On Thu, 12 Apr 2001, Todd Williams wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in
the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Todd Williams wrote:
> >
> > We have recently added an application server using the FWTK 2.1's
ftp-gw.
> > There is no authentication happening, nor should there be as there is no
> > auth server defined.  I've been using the ftp-gw in the past from other
> > hosts without any issues, however I am beginning to suspect that
something
> > the ftp client of the app server has somehow generated these auth
related
> > error messages in syslog:
> >
> > Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver
defined!
> > cannot authenticate!
> > Apr 11 16:50:37 fwtkhost ftp-gw[13903]:
> app1.my-internal.com/192.168.123.4:
> > STOR foo.txt
> >
> > Is there any easy way to clean this error up?
> >
> >>
> >>Todd,
> >>
> >>What does your netperm-table look like?
> >>
> >>--
> >>--Keith Young
> >>-Director of Customer Care/Support, V-ONE Corp.
> >>-kyoung@v-one.com
>
> The numbers have been changed to protect the innocent.  :)
>
> netacl-in.ftpd: timeout 60
> netacl-in.ftpd: hosts 192.168.8.100 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.8.118 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.8.145 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.8.149 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts 192.168.9.135 -exec /usr/sbin/in.ftpd -l -a
> netacl-in.ftpd: hosts unknown -exec /bin/cat /usr/local/etc/ftp/noftp.txt
> netacl-in.ftpd: hosts * -exec /bin/cat /usr/local/etc/ftp/noftp.txt
>
>
> Note, there is no reference to -auth or -authall.  The ftp application
> (Net::FTP perl module) is possibly generating some sort of auth request,
and
> perhaps that's where we need to look.  Regardless, I was pondering if
there
> was an easy way to shut off the logging messages like this: "fwtkcfgerr:
no
> authserver defined! cannot authenticate!" in this case.
>
> Thanks,
>
> Todd
>



From owner-fwtk-users@ex.tis.com Fri Apr 13 13:37 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA06452
	Fri, 13 Apr 2001 13:37:18 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA05381;
	Fri, 13 Apr 2001 10:35:10 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 09:38:35 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA03062
	for fwtk-users-outgoing; Fri, 13 Apr 2001 09:38:29 -0700 (PDT)
From: ark@eltex.ru
Date: Fri, 13 Apr 2001 20:55:18 +0400
Message-Id: <200104131655.UAA28931@paranoid.eltex.spb.ru>
Organization: "Klingon Imperial Intelligence Service"
Subject: legacy code - what was it for?
To: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1037

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

I've noticed that tn-gw expects the following responces from authentication
server for auth command:
ok
display
challenge (*)
chalnecho
password (*)

only marked with (*) are implemented in authsrv (both Gauntlet and fwtk), 
two others are obvious, but what was `display' for?

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOtcvdaH/mIJW9LeBAQEB6AP9GVdPI/kI8iGucHE06no2QYy79i4Vwff7
RCsZMokvPm+v3eFLJ1NEQAJntHXdLRPA78dlIXY1Ik2CVPmHvgOa3dtUhPV5Bu4/
IV0+UsGpcxZYeFsjmubCmPTDt8mwBc8SFgid51hZg1/GMjdrgOW1ojq9ZFB0c8jM
aXOeACzInzw=
=6mkv
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Fri Apr 13 13:37 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA06455
	Fri, 13 Apr 2001 13:37:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA05368;
	Fri, 13 Apr 2001 10:34:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 09:35:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA02980
	for fwtk-users-outgoing; Fri, 13 Apr 2001 09:35:38 -0700 (PDT)
Message-ID: <77DA8BE17C46D2118B7A00805FA7D051047ADB2D@TPAEXCH2>
From: "Davis, Ricardo C." <RCDavis@intermedia.com>
To: fwtk-users@lists.nai.com
Subject: Re: plug-gw + ssh config question
Date: Fri, 13 Apr 2001 12:34:29 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 4827

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello, everyone.

After reading the thread on this message and the earlier discussion (Re:
ssh-gw?)  I set out to add the ability to ssh from the Internet to an SSH1
server (long story here) on the intranet.

On this RH Linux box (fwall) I modified the services, inetd.conf, and
netperm-table files:

[services]
ssh             22/tcp          # SSH remote login

[inetd.conf]
ssh     stream tcp      nowait     root /usr/local/etc/netacl ssh

[netperm-table]
# Plug-gw rules:
# --------------
netacl-ssh:     permit-hosts * -exec /usr/local/etc/plug-gw ssh
plug-gw:        port ssh * -plug-to 192.168.0.50 -port 22


I fired up my OpenSSH 2.5.2p2-1 ssh client on an external box:

$ ssh -l davis@192.168.0.50 -o "Protocol 1" -v -v -v fwall
OpenSSH_2.5.2p2, SSH protocols 1.5/2.0, OpenSSL 0x0090581f
debug1: Seeding random number generator
debug1: Rhosts Authentication disabled, originating port will not be
trusted.
debug1: ssh_connect: getuid 302 geteuid 0 anon 1
debug1: Connecting to fwall [....] port 22.
debug1: Connection established.
ssh_exchange_identification: Connection closed by remote host
debug1: Calling cleanup 0x80605a0(0x0)
$

On fwall, the following messages were logged in /var/log/messages:

Apr 13 12:21:16 proxy netacl[29063]: permit
host=ftp2.abnbilling.com/209.48.180.234 service=ssh
execute=/usr/local/etc/plug-gw
Apr 13 12:21:16 proxy plug-gw[29063]: deny
host=ftp2.abnbilling.com/209.48.180.234 service=ssh


This looks similar to the problem Georg was having.  Did I mess up the
plug-gw configuration?


-Ricardo 



----Original Message----
From: Georg Wittig <Georg.Wittig@gmd.de> 
Subject: Re: plug-gw + ssh config question 
Date: 2001-01-09 14:21:03

My problem is solved in the meantime. Thanks to all who helped me. I
had made 2 errors: First, I had made a typo in my netperm-table
("permit hosts" instead of "permit-hosts"). Second, I found I had used
a hand-edited plug-gw; as soon as I replaced it by plug-gw of the
official version 2.1, everything worked fine.

Blush. Sorry for all the fuss.

For those who are interested in the final configuration, here's my
setup:

[/etc/services]
ssh             22/tcp                          # SSH Remote Login Protocol

[ps axww | grep ssh]
27055 tty1     S      0:00 /path/to/plug-gw -daemon ssh ssh
(I'm not running inetd, so I started plug-gw manually.)

[netperm-table]
ssh:	port ssh * -plug-to 11.22.33.44 -port ssh


----Original Message----
Subject: Re: ssh-gw? 
From: Michel Bardiaux <mbardiaux@usrconsult.be> 
Date: 2000-04-11 8:24:28

[To be removed from this list send the message "unsubscribe fwtk-users" in
the BODY of a mail message to majordomo@ex.tis.com.]

Michael Thies wrote:
> > > is it possible, to leave a network protected by a tis-fw using ssh?
> In our company only a telnet-gw and a ftp-gw is installed. .-(
> And on the website http://www.tis.com/research/software/ I also didn't
> found anything about ssh.
> > Maybe one of You has a solution?
>  * INCOMING SSH:

We simply pass SSH through the FW with plug-gw, e.g.:
[/etc/services]
ssh             22/tcp                          # SSH Remote Login
Protocol
[/etc/inetd.conf]
ssh             stream  tcp     nowait  root   
/usr/local/fwtk/etc/netacl ssh
[/usr/local/fwtk/etc/netperm-table]
netacl-ssh: permit-hosts * -exec /usr/local/fwtk/etc/plug-gw ssh
plug-gw: port ssh * -plug-to aa.bb.cc.1 -port
22

(aa.bb.cc.1 is the IP address of the SSHD server on the internal net)

You also have to allow SSH through whatever filtering system is used on
the
machine at the DMZ/intranet boundary, but that's outside FWTK.

<pedantic> Of course, since you tunnel *any* SSH in, your SSH setup better
be
'military'
grade: large keys, and strict rules for public key management: long
passphrase,
public keys have to be carried on floppy and personnally handed to the
system
manager, etc... Basically, outside hosts become part of the internal
net, and
security policies for internal hosts must be applied to them. Even
stronger policies,
actually, since the outside hosts might *not* be protected by an FW.
</pedantic>  Something still worries me in that setup: what are the risks of
DoS
attacks on the
internal net? Ideas anybody?

* OUTGOING SSH

We have created an extra service on the FW for every destination
(including the
DMZ machines). The netperm-table rules read like:

netacl-ssh-XX: permit-hosts aa.bb.cc.* -exec /usr/local/fwtk/etc/plug-gw
ssh-XX
plug-gw: port ssh-XX aa.bb.cc.129 -privport -plug-to XX.XX.XX.XX -port
PPPP

(aa.bb.cc is our assigned Class-C, 129 is the IP address of the
Intranet/DMZ boundary
NIC)

All this is IMHO, of course. Critiques welcome!

Greetings.                                    
-- 
Michel Bardiaux

From owner-fwtk-users@ex.tis.com Fri Apr 13 14:08 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA06533
	Fri, 13 Apr 2001 14:08:57 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA06603;
	Fri, 13 Apr 2001 11:06:35 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 10:11:32 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA04337
	for fwtk-users-outgoing; Fri, 13 Apr 2001 10:11:07 -0700 (PDT)
Date: Fri, 13 Apr 2001 13:09:32 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Todd Williams <twilliams@tfcci.com>
cc: "'Keith Young'" <kyoung@v-one.com>, fwtk-users@lists.nai.com,
        "'Rick Murphy'" <rmurphy@itm-inst.com>
Subject: RE: FTP-GW related question
In-Reply-To: <02c701c0c425$30fa7bd0$c802a8c0@toddntbox.tfcc.com>
Message-ID: <Pine.GSO.4.10.10104131306570.3244-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 3438

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

So why don't you have entries like....


ftp-gw: denial-msg      /usr/local/fwtk/deny.txt
ftp-gw:         timeout 21600
ftp-gw:         directory /fwroot
ftp-gw:         permit-hosts xxx.xxx.xxx.* -log { retr stor }
ftp-gw:         permit-hosts xxx.xxx.xxx.* -log { retr stor }


and have your inetd file call your ftp-gw proxy?


ted keller


On Fri, 13 Apr 2001, Todd Williams wrote:

> We're allowing specific internal private RFC 1918 host addresses to use the
> ftp-gw as an ftp proxy to public internet sites, and seeing the error
> messages as previously mentioned.  There is no FTP'ing to the firewall.
> 
> Todd Williams
> 
> -----Original Message-----
> From: Ted Keller [mailto:keller@bfg.com]
> Sent: Thursday, April 12, 2001 8:36 PM
> To: Todd Williams
> Cc: 'Keith Young'; fwtk-users@lists.nai.com; 'Rick Murphy'
> Subject: RE: FTP-GW related question
> 
> 
> So your allowing specific addresses to ftp to your firewall? - then using
> the vendor ftp daemon to connect externally.....  You may want to
> reconsider this (or I'm not understanding what your are trying to do - and
> use the ftp-gw for ftp proxying.
> 
> ted keller
> 
> 
> On Thu, 12 Apr 2001, Todd Williams wrote:
> 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in
> the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > Todd Williams wrote:
> > >
> > > We have recently added an application server using the FWTK 2.1's
> ftp-gw.
> > > There is no authentication happening, nor should there be as there is no
> > > auth server defined.  I've been using the ftp-gw in the past from other
> > > hosts without any issues, however I am beginning to suspect that
> something
> > > the ftp client of the app server has somehow generated these auth
> related
> > > error messages in syslog:
> > >
> > > Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver
> defined!
> > > cannot authenticate!
> > > Apr 11 16:50:37 fwtkhost ftp-gw[13903]:
> > app1.my-internal.com/192.168.123.4:
> > > STOR foo.txt
> > >
> > > Is there any easy way to clean this error up?
> > >
> > >>
> > >>Todd,
> > >>
> > >>What does your netperm-table look like?
> > >>
> > >>--
> > >>--Keith Young
> > >>-Director of Customer Care/Support, V-ONE Corp.
> > >>-kyoung@v-one.com
> >
> > The numbers have been changed to protect the innocent.  :)
> >
> > netacl-in.ftpd: timeout 60
> > netacl-in.ftpd: hosts 192.168.8.100 -exec /usr/sbin/in.ftpd -l -a
> > netacl-in.ftpd: hosts 192.168.8.118 -exec /usr/sbin/in.ftpd -l -a
> > netacl-in.ftpd: hosts 192.168.8.145 -exec /usr/sbin/in.ftpd -l -a
> > netacl-in.ftpd: hosts 192.168.8.149 -exec /usr/sbin/in.ftpd -l -a
> > netacl-in.ftpd: hosts 192.168.9.135 -exec /usr/sbin/in.ftpd -l -a
> > netacl-in.ftpd: hosts unknown -exec /bin/cat /usr/local/etc/ftp/noftp.txt
> > netacl-in.ftpd: hosts * -exec /bin/cat /usr/local/etc/ftp/noftp.txt
> >
> >
> > Note, there is no reference to -auth or -authall.  The ftp application
> > (Net::FTP perl module) is possibly generating some sort of auth request,
> and
> > perhaps that's where we need to look.  Regardless, I was pondering if
> there
> > was an easy way to shut off the logging messages like this: "fwtkcfgerr:
> no
> > authserver defined! cannot authenticate!" in this case.
> >
> > Thanks,
> >
> > Todd
> >
> 
> 


From owner-fwtk-users@ex.tis.com Fri Apr 13 15:13 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA06715
	Fri, 13 Apr 2001 15:13:42 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA09889;
	Fri, 13 Apr 2001 12:10:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 11:12:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA06823
	for fwtk-users-outgoing; Fri, 13 Apr 2001 11:11:47 -0700 (PDT)
X-Authentication-Warning: proxy.tfcc.com: mail set sender to <twilliams@tfcci.com> using -f
From: "Todd Williams" <twilliams@tfcci.com>
To: "'Ted Keller'" <keller@bfg.com>
Cc: "'Keith Young'" <kyoung@v-one.com>, <fwtk-users@lists.nai.com>,
        "'Rick Murphy'" <rmurphy@itm-inst.com>
Subject: RE: FTP-GW related question
Date: Fri, 13 Apr 2001 13:44:33 -0400
Message-ID: <02cb01c0c441$66ad5dd0$c802a8c0@toddntbox.tfcc.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook 8.5, Build 4.71.2173.0
In-Reply-To: <Pine.GSO.4.10.10104131306570.3244-100000@ns1.bfg.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1055

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

You'll have to forgive my brain fart...  I copied the wrong part of the
netperm-table file.  I don't know what I was thinking there.  My apologies.

Here's what it should have been:

ftp-gw: denial-msg      /usr/local/etc/ftp/ftp-deny.txt
ftp-gw: welcome-msg     /usr/local/etc/ftp/ftp-welcome.txt
ftp-gw: help-msg        /usr/local/etc/ftp/ftp-help.txt
ftp-gw: permit-hosts 192.168.120.* -log { retr stor }
ftp-gw: permit-hosts 192.168.130.* -log { retr stor }
ftp-gw: permit-hosts 192.168.123.4 -log { retr stor }
ftp-gw: permit-hosts 192.168.123.6 -log { retr stor }
ftp-gw: timeout 900


> error messages in syslog:
> > >
> > > Apr 11 16:50:36 fwtkhost ftp-gw[13903]: fwtkcfgerr: no authserver
defined!
> > > cannot authenticate!
> > > Apr 11 16:50:37 fwtkhost ftp-gw[13903]:
app1.my-internal.com/192.168.123.4:
> > > STOR foo.txt
> > >
> > > Is there any easy way to clean this error up?

Sorry for the confusion.

Todd


From owner-fwtk-users@ex.tis.com Fri Apr 13 15:28 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA06777
	Fri, 13 Apr 2001 15:28:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA10615;
	Fri, 13 Apr 2001 12:26:26 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 11:31:20 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA07840
	for fwtk-users-outgoing; Fri, 13 Apr 2001 11:31:04 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010413141843.01d15850@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Fri, 13 Apr 2001 14:20:34 -0400
To: ark@eltex.ru, fwtk-users@tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: legacy code - what was it for?
In-Reply-To: <200104131655.UAA28931@paranoid.eltex.spb.ru>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 561

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 08:55 PM 4/13/01 +0400, ark@eltex.ru wrote:
>only marked with (*) are implemented in authsrv (both Gauntlet and fwtk),
>two others are obvious, but what was `display' for?
There are authentication protocols that need to send extended prompts to 
the user.
The one that comes to mind immediately is SecurID in new-PIN mode. It wants 
to send a multi-line prompt to the user containing instructions on the new PIN.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Apr 13 15:33 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA06787
	Fri, 13 Apr 2001 15:33:00 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA10817;
	Fri, 13 Apr 2001 12:30:37 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 11:36:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA08104
	for fwtk-users-outgoing; Fri, 13 Apr 2001 11:36:21 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010413142109.01d1d850@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Fri, 13 Apr 2001 14:24:40 -0400
To: "Davis, Ricardo C." <RCDavis@intermedia.com>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: plug-gw + ssh config question
In-Reply-To: <77DA8BE17C46D2118B7A00805FA7D051047ADB2D@TPAEXCH2>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 980

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 12:34 PM 4/13/01 -0400, Davis, Ricardo C. wrote:
># Plug-gw rules:
># --------------
>netacl-ssh:     permit-hosts * -exec /usr/local/etc/plug-gw ssh
>plug-gw:        port ssh * -plug-to 192.168.0.50 -port 22

...

>Apr 13 12:21:16 proxy netacl[29063]: permit
>host=ftp2.abnbilling.com/209.48.180.234 service=ssh
>execute=/usr/local/etc/plug-gw
>Apr 13 12:21:16 proxy plug-gw[29063]: deny
>host=ftp2.abnbilling.com/209.48.180.234 service=ssh
>
>
>This looks similar to the problem Georg was having.  Did I mess up the
>plug-gw configuration?

Yes. Netacl fires up plug-gw as ssh; plug-gw looks for "ssh" rules and fails.
Try changing "plug-gw" to "ssh" on the second netperm-table line.

Why are you running netacl in front of plug-gw in this configuration? If 
you *always* run a plug-gw, just run it and don't bother with netacl.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Apr 13 16:24 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA06895
	Fri, 13 Apr 2001 16:24:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA13295;
	Fri, 13 Apr 2001 13:21:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 13 Apr 2001 12:23:15 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA10430
	for fwtk-users-outgoing; Fri, 13 Apr 2001 12:22:55 -0700 (PDT)
Message-ID: <77DA8BE17C46D2118B7A00805FA7D051047ADB32@TPAEXCH2>
From: "Davis, Ricardo C." <RCDavis@intermedia.com>
To: "'Rick Murphy'" <rmurphy@itm-inst.com>
Cc: fwtk-users@lists.nai.com
Subject: RE: plug-gw + ssh config question
Date: Fri, 13 Apr 2001 15:21:49 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1517

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Rick,

It appears I wasn't thinking carefully about what I was doing.  So I went
back to the docs regarding plug-gw and fixed the problem...works like a
charm now.


-R

[netperm-table]
ssh:        port ssh * -plug-to 192.168.0.50 -port 22

[inetd.conf]
ssh     stream tcp      nowait     root /usr/local/etc/plug-gw  plug-gw ssh



-----Original Message-----
From: Rick Murphy [mailto:rmurphy@itm-inst.com]
Sent: Friday, April 13, 2001 2:25 PM
To: Davis, Ricardo C.; fwtk-users@lists.nai.com
Subject: Re: plug-gw + ssh config question


At 12:34 PM 4/13/01 -0400, Davis, Ricardo C. wrote:
># Plug-gw rules:
># --------------
>netacl-ssh:     permit-hosts * -exec /usr/local/etc/plug-gw ssh
>plug-gw:        port ssh * -plug-to 192.168.0.50 -port 22

...

>Apr 13 12:21:16 proxy netacl[29063]: permit
>host=ftp2.abnbilling.com/209.48.180.234 service=ssh
>execute=/usr/local/etc/plug-gw
>Apr 13 12:21:16 proxy plug-gw[29063]: deny
>host=ftp2.abnbilling.com/209.48.180.234 service=ssh
>
>
>This looks similar to the problem Georg was having.  Did I mess up the
>plug-gw configuration?

Yes. Netacl fires up plug-gw as ssh; plug-gw looks for "ssh" rules and
fails.
Try changing "plug-gw" to "ssh" on the second netperm-table line.

Why are you running netacl in front of plug-gw in this configuration? If 
you *always* run a plug-gw, just run it and don't bother with netacl.
         -Rick

From owner-fwtk-users@ex.tis.com Sat Apr 14 09:17 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA07901
	Sat, 14 Apr 2001 09:17:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA25877;
	Sat, 14 Apr 2001 06:15:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sat, 14 Apr 2001 04:57:19 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA24426
	for fwtk-users-outgoing; Sat, 14 Apr 2001 04:57:04 -0700 (PDT)
Date: Sat, 14 Apr 2001 07:56:20 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: "Davis, Ricardo C." <RCDavis@intermedia.com>
cc: fwtk-users@lists.nai.com
Subject: Re: plug-gw + ssh config question
In-Reply-To: <77DA8BE17C46D2118B7A00805FA7D051047ADB2D@TPAEXCH2>
Message-ID: <Pine.GSO.4.10.10104140753130.16571-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 5544

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Richardo,

I assume that you are using the verion 2.1 of plug-gw.  Change your
netperm-table to


ssh:	port ssh * -plug-to 192.168.0.50 -port 22


note - you also may want to restrict a bit more who can connect....

ted keller


On Fri, 13 Apr 2001, Davis, Ricardo C. wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Hello, everyone.
> 
> After reading the thread on this message and the earlier discussion (Re:
> ssh-gw?)  I set out to add the ability to ssh from the Internet to an SSH1
> server (long story here) on the intranet.
> 
> On this RH Linux box (fwall) I modified the services, inetd.conf, and
> netperm-table files:
> 
> [services]
> ssh             22/tcp          # SSH remote login
> 
> [inetd.conf]
> ssh     stream tcp      nowait     root /usr/local/etc/netacl ssh
> 
> [netperm-table]
> # Plug-gw rules:
> # --------------
> netacl-ssh:     permit-hosts * -exec /usr/local/etc/plug-gw ssh
> plug-gw:        port ssh * -plug-to 192.168.0.50 -port 22
> 
> 
> I fired up my OpenSSH 2.5.2p2-1 ssh client on an external box:
> 
> $ ssh -l davis@192.168.0.50 -o "Protocol 1" -v -v -v fwall
> OpenSSH_2.5.2p2, SSH protocols 1.5/2.0, OpenSSL 0x0090581f
> debug1: Seeding random number generator
> debug1: Rhosts Authentication disabled, originating port will not be
> trusted.
> debug1: ssh_connect: getuid 302 geteuid 0 anon 1
> debug1: Connecting to fwall [....] port 22.
> debug1: Connection established.
> ssh_exchange_identification: Connection closed by remote host
> debug1: Calling cleanup 0x80605a0(0x0)
> $
> 
> On fwall, the following messages were logged in /var/log/messages:
> 
> Apr 13 12:21:16 proxy netacl[29063]: permit
> host=ftp2.abnbilling.com/209.48.180.234 service=ssh
> execute=/usr/local/etc/plug-gw
> Apr 13 12:21:16 proxy plug-gw[29063]: deny
> host=ftp2.abnbilling.com/209.48.180.234 service=ssh
> 
> 
> This looks similar to the problem Georg was having.  Did I mess up the
> plug-gw configuration?
> 
> 
> -Ricardo 
> 
> 
> 
> ----Original Message----
> From: Georg Wittig <Georg.Wittig@gmd.de> 
> Subject: Re: plug-gw + ssh config question 
> Date: 2001-01-09 14:21:03
> 
> My problem is solved in the meantime. Thanks to all who helped me. I
> had made 2 errors: First, I had made a typo in my netperm-table
> ("permit hosts" instead of "permit-hosts"). Second, I found I had used
> a hand-edited plug-gw; as soon as I replaced it by plug-gw of the
> official version 2.1, everything worked fine.
> 
> Blush. Sorry for all the fuss.
> 
> For those who are interested in the final configuration, here's my
> setup:
> 
> [/etc/services]
> ssh             22/tcp                          # SSH Remote Login Protocol
> 
> [ps axww | grep ssh]
> 27055 tty1     S      0:00 /path/to/plug-gw -daemon ssh ssh
> (I'm not running inetd, so I started plug-gw manually.)
> 
> [netperm-table]
> ssh:	port ssh * -plug-to 11.22.33.44 -port ssh
> 
> 
> ----Original Message----
> Subject: Re: ssh-gw? 
> From: Michel Bardiaux <mbardiaux@usrconsult.be> 
> Date: 2000-04-11 8:24:28
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in
> the BODY of a mail message to majordomo@ex.tis.com.]
> 
> Michael Thies wrote:
> > > > is it possible, to leave a network protected by a tis-fw using ssh?
> > In our company only a telnet-gw and a ftp-gw is installed. .-(
> > And on the website http://www.tis.com/research/software/ I also didn't
> > found anything about ssh.
> > > Maybe one of You has a solution?
> >  * INCOMING SSH:
> 
> We simply pass SSH through the FW with plug-gw, e.g.:
> [/etc/services]
> ssh             22/tcp                          # SSH Remote Login
> Protocol
> [/etc/inetd.conf]
> ssh             stream  tcp     nowait  root   
> /usr/local/fwtk/etc/netacl ssh
> [/usr/local/fwtk/etc/netperm-table]
> netacl-ssh: permit-hosts * -exec /usr/local/fwtk/etc/plug-gw ssh
> plug-gw: port ssh * -plug-to aa.bb.cc.1 -port
> 22
> 
> (aa.bb.cc.1 is the IP address of the SSHD server on the internal net)
> 
> You also have to allow SSH through whatever filtering system is used on
> the
> machine at the DMZ/intranet boundary, but that's outside FWTK.
> 
> <pedantic> Of course, since you tunnel *any* SSH in, your SSH setup better
> be
> 'military'
> grade: large keys, and strict rules for public key management: long
> passphrase,
> public keys have to be carried on floppy and personnally handed to the
> system
> manager, etc... Basically, outside hosts become part of the internal
> net, and
> security policies for internal hosts must be applied to them. Even
> stronger policies,
> actually, since the outside hosts might *not* be protected by an FW.
> </pedantic>  Something still worries me in that setup: what are the risks of
> DoS
> attacks on the
> internal net? Ideas anybody?
> 
> * OUTGOING SSH
> 
> We have created an extra service on the FW for every destination
> (including the
> DMZ machines). The netperm-table rules read like:
> 
> netacl-ssh-XX: permit-hosts aa.bb.cc.* -exec /usr/local/fwtk/etc/plug-gw
> ssh-XX
> plug-gw: port ssh-XX aa.bb.cc.129 -privport -plug-to XX.XX.XX.XX -port
> PPPP
> 
> (aa.bb.cc is our assigned Class-C, 129 is the IP address of the
> Intranet/DMZ boundary
> NIC)
> 
> All this is IMHO, of course. Critiques welcome!
> 
> Greetings.                                    
> -- 
> Michel Bardiaux
> 


From owner-fwtk-users@ex.tis.com Sun Apr 15 20:28 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id UAA10482
	Sun, 15 Apr 2001 20:27:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA06797;
	Sun, 15 Apr 2001 17:31:10 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 15 Apr 2001 16:03:55 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA04831
	for fwtk-users-outgoing; Sun, 15 Apr 2001 16:03:28 -0700 (PDT)
Message-ID: <000901c0c5ff$53139ae0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Cc: <ygk@nb.com>, <ygk@ygk.net>
Subject: Configuring socks-gw
Date: Sun, 15 Apr 2001 18:56:34 -0400
Organization: Falun Technical Service, Inc.
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 906

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I just downloaded socks-gw from the FWTK Patches section.
I compiled and installed it OK, but there are no docs.

How do I configure the socks-gw proxy
( netperm-table and inetd.conf entries please) ?

I'm trying to use socks-gw to run gnutella through my personal firewall.

P.S. Has any more work been done on this proxy?

Thanks,
LarryJackson@iName.com

On  2000-01-04 "Yakov Kravets" <ygk@nb.com> said:
>
> I have put together a socks-gw proxy. 
> From the name you can tell that it implements SOCKS protocol. 
> The goal for this project was to integrate SOCKS proxy into FWTK.
> At this time it only implements CONNECT request and 
> I'm working on getting BIND done.
>
> HNY everybody.
>
> -------------------------------------
> Yakov Kravets, CISSP, NeubergerBerman



From owner-fwtk-users@ex.tis.com Sun Apr 15 23:31 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA10709
	Sun, 15 Apr 2001 23:31:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA11419;
	Sun, 15 Apr 2001 20:34:37 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 15 Apr 2001 19:32:25 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA09435
	for fwtk-users-outgoing; Sun, 15 Apr 2001 19:32:05 -0700 (PDT)
Message-ID: <007201c0c61c$904b1ec0$fc00a8c0@k62350>
From: "Larry Jackson" <LarryJackson@iName.com>
To: "FWTK List Server" <fwtk-users@lists.nai.com>
Cc: "Ted Keller" <keller@pm.bfg.com>
References: <Pine.GSO.4.10.10104152216220.3314-100000@ns1.bfg.com>
Subject: Why don't you just run the socks daemon was Configuring socks-gw
Date: Sun, 15 Apr 2001 22:25:49 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1592

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I don't know ANYTHING about socks-gw or the NEC socks daemon.

I'm trying to run GNUtella through my personal firewall
using the ToadNode client and I saw it supports socks.
I went to fwtk.org and found socks-gw.

What are the advantages/disadvantages between them.

P.S. I was astonished to see GNUtella sending packets out
using ports 137-139, ie Windows Networking/ NetBIOS.

Thanks,
LarryJackson@iName.com

----- Original Message -----
"Ted Keller" <keller@pm.bfg.com> asked:
>

> So why don't you just run the socks daemon?
>
> ted keller
>
>
> On Sun, 15 Apr 2001, Larry Jackson wrote:
>
> > I just downloaded socks-gw from the FWTK Patches section.
> > I compiled and installed it OK, but there are no docs.
> >
> > How do I configure the socks-gw proxy
> > ( netperm-table and inetd.conf entries please) ?
> >
> > I'm trying to use socks-gw to run gnutella through my personal firewall.
> >
> > P.S. Has any more work been done on this proxy?
> >
> > Thanks,
> > LarryJackson@iName.com
> >
> > On  2000-01-04 "Yakov Kravets" <ygk@nb.com> said:
> > >
> > > I have put together a socks-gw proxy.
> > > From the name you can tell that it implements SOCKS protocol.
> > > The goal for this project was to integrate SOCKS proxy into FWTK.
> > > At this time it only implements CONNECT request and
> > > I'm working on getting BIND done.
> > >
> > > HNY everybody.
> > >
> > > -------------------------------------
> > > Yakov Kravets, CISSP, NeubergerBerman



From owner-fwtk-users@ex.tis.com Sun Apr 15 23:50 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA10730
	Sun, 15 Apr 2001 23:50:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id UAA12067;
	Sun, 15 Apr 2001 20:53:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 15 Apr 2001 19:59:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id TAA10131
	for fwtk-users-outgoing; Sun, 15 Apr 2001 19:59:17 -0700 (PDT)
Date: Sun, 15 Apr 2001 22:58:21 -0400 (EDT)
From: Ted Keller <keller@pm.bfg.com>
X-Sender: keller@ns1.bfg.com
To: Larry Jackson <LarryJackson@iName.com>
cc: FWTK List Server <fwtk-users@lists.nai.com>
Subject: Re: Why don't you just run the socks daemon was Configuring socks-gw
In-Reply-To: <007201c0c61c$904b1ec0$fc00a8c0@k62350>
Message-ID: <Pine.GSO.4.10.10104152254300.3715-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 2391

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Socks5 is available from www.socks.nec.com.  It is freely available for
non-commercial use.  I think you fit that bill.

Socks allows you to control who make a connection to what computers and
for which protocols.  It does include support for both udp and tcp
packets.  Now saying that, if you permit your local computer through the
socks daemon - using an unsafe protocol, socks will gladly let you do
that.  It operates more as a circuit proxy as opposed to a true
application proxy.  It's primary purpose is to grant/deny access - not
analyze protocl and ensure what you are doing is safe.

If you trust this program - give it a try.

ted keller


On Sun, 15 Apr 2001, Larry Jackson wrote:

> I don't know ANYTHING about socks-gw or the NEC socks daemon.
> 
> I'm trying to run GNUtella through my personal firewall
> using the ToadNode client and I saw it supports socks.
> I went to fwtk.org and found socks-gw.
> 
> What are the advantages/disadvantages between them.
> 
> P.S. I was astonished to see GNUtella sending packets out
> using ports 137-139, ie Windows Networking/ NetBIOS.
> 
> Thanks,
> LarryJackson@iName.com
> 
> ----- Original Message -----
> "Ted Keller" <keller@pm.bfg.com> asked:
> >
> 
> > So why don't you just run the socks daemon?
> >
> > ted keller
> >
> >
> > On Sun, 15 Apr 2001, Larry Jackson wrote:
> >
> > > I just downloaded socks-gw from the FWTK Patches section.
> > > I compiled and installed it OK, but there are no docs.
> > >
> > > How do I configure the socks-gw proxy
> > > ( netperm-table and inetd.conf entries please) ?
> > >
> > > I'm trying to use socks-gw to run gnutella through my personal firewall.
> > >
> > > P.S. Has any more work been done on this proxy?
> > >
> > > Thanks,
> > > LarryJackson@iName.com
> > >
> > > On  2000-01-04 "Yakov Kravets" <ygk@nb.com> said:
> > > >
> > > > I have put together a socks-gw proxy.
> > > > From the name you can tell that it implements SOCKS protocol.
> > > > The goal for this project was to integrate SOCKS proxy into FWTK.
> > > > At this time it only implements CONNECT request and
> > > > I'm working on getting BIND done.
> > > >
> > > > HNY everybody.
> > > >
> > > > -------------------------------------
> > > > Yakov Kravets, CISSP, NeubergerBerman
> 
> 


From owner-fwtk-users@ex.tis.com Mon Apr 16 07:14 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA15658
	Mon, 16 Apr 2001 07:14:35 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA20358;
	Mon, 16 Apr 2001 04:18:07 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 16 Apr 2001 03:19:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA18974
	for fwtk-users-outgoing; Mon, 16 Apr 2001 03:19:29 -0700 (PDT)
From: ark@eltex.ru
Date: Mon, 16 Apr 2001 14:35:55 +0400
Message-Id: <200104161035.OAA12400@paranoid.eltex.spb.ru>
In-Reply-To: <5.0.2.1.0.20010413141843.01d15850@mail.itm-inst.com> from "Rick Murphy <rmurphy@itm-inst.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: legacy code - what was it for?
To: rmurphy@itm-inst.com
Cc: fwtk-users@tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1729

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Rick Murphy <rmurphy@itm-inst.com> said :

> At 08:55 PM 4/13/01 +0400, ark@eltex.ru wrote:
> >only marked with (*) are implemented in authsrv (both Gauntlet and fwtk),
> >two others are obvious, but what was `display' for?
> There are authentication protocols that need to send extended prompts to 
> the user.
> The one that comes to mind immediately is SecurID in new-PIN mode. It wants 
> to send a multi-line prompt to the user containing instructions on the new PIN.

Nope, does not look like that..

 		if(!strncmp(buf,"display ", 8)) {
                                strcpy(cbuf, &buf[8]);
                                x = strlen(cbuf);
                                if(sayn(0,cbuf,x))
                                        goto close_go;
                                strcpy(cbuf,"response dummy");
                                if(auth_send(cbuf))
                                        goto lostconn;
                                continue;
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOtrLCqH/mIJW9LeBAQF7pwP+ML1rWiTNIBgH12mlHF/+5SqoseX8rOT8
w7XGA/ZYvAI/+cA87Y1Ypxgbf8LRt4Z4N1Iq9eXvZdsMzn231cQZbMUF9gBcEPRq
wpcaq1Vnd6KKiSsa8tbEOM/LzRzTzTnql8VEQq9yxejkQc075SCPbY5G8rW68ZGc
bwY6rHa9dW4=
=YZ/Q
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Mon Apr 16 15:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA17436
	Mon, 16 Apr 2001 15:32:11 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA07142;
	Mon, 16 Apr 2001 12:35:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 16 Apr 2001 11:28:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA29361
	for fwtk-users-outgoing; Mon, 16 Apr 2001 11:27:56 -0700 (PDT)
Date: Sun, 15 Apr 2001 22:16:49 -0400 (EDT)
From: Ted Keller <keller@pm.bfg.com>
X-Sender: keller@ns1.bfg.com
To: Larry Jackson <LarryJackson@iName.com>
cc: FWTK List Server <fwtk-users@lists.nai.com>, ygk@nb.com, ygk@ygk.net
Subject: Re: Configuring socks-gw
In-Reply-To: <000901c0c5ff$53139ae0$fc00a8c0@k62350>
Message-ID: <Pine.GSO.4.10.10104152216220.3314-100000@ns1.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1197

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

So why don't you just run the socks daemon? 

ted keller


On Sun, 15 Apr 2001, Larry Jackson wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> I just downloaded socks-gw from the FWTK Patches section.
> I compiled and installed it OK, but there are no docs.
> 
> How do I configure the socks-gw proxy
> ( netperm-table and inetd.conf entries please) ?
> 
> I'm trying to use socks-gw to run gnutella through my personal firewall.
> 
> P.S. Has any more work been done on this proxy?
> 
> Thanks,
> LarryJackson@iName.com
> 
> On  2000-01-04 "Yakov Kravets" <ygk@nb.com> said:
> >
> > I have put together a socks-gw proxy. 
> > From the name you can tell that it implements SOCKS protocol. 
> > The goal for this project was to integrate SOCKS proxy into FWTK.
> > At this time it only implements CONNECT request and 
> > I'm working on getting BIND done.
> >
> > HNY everybody.
> >
> > -------------------------------------
> > Yakov Kravets, CISSP, NeubergerBerman
> 
> 

From owner-fwtk-users@ex.tis.com Mon Apr 16 18:20 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA18000
	Mon, 16 Apr 2001 18:20:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA27304;
	Mon, 16 Apr 2001 15:23:52 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 16 Apr 2001 14:22:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA19046
	for fwtk-users-outgoing; Mon, 16 Apr 2001 14:22:17 -0700 (PDT)
Date: Mon, 16 Apr 2001 11:59:18 -0500 (CDT)
From: Sergio Jimenez Tovar <sjimenez@galois.dgae.unam.mx>
X-Sender: sjimenez@laplace
To: Fwtk <fwtk-users@ex.tis.com>
Subject: New version, when ?
Message-ID: <Pine.GSO.4.05.10104161155190.2187-100000@laplace>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 232

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

	Why the version actual is the same 3 years early, anybody know
when will be the new version ? thanks.

From owner-fwtk-users@ex.tis.com Mon Apr 16 18:24 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA18007
	Mon, 16 Apr 2001 18:24:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA27724;
	Mon, 16 Apr 2001 15:27:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 16 Apr 2001 14:31:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA20212
	for fwtk-users-outgoing; Mon, 16 Apr 2001 14:30:50 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010416171044.01d2acd0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Mon, 16 Apr 2001 17:20:01 -0400
To: ark@eltex.ru
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: legacy code - what was it for?
Cc: fwtk-users@tis.com
In-Reply-To: <200104161035.OAA12400@paranoid.eltex.spb.ru>
References: <5.0.2.1.0.20010413141843.01d15850@mail.itm-inst.com>
 <rmurphy@itm-inst.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1710

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 02:35 PM 4/16/01 +0400, ark@eltex.ru wrote:
>Rick Murphy <rmurphy@itm-inst.com> said :
>
> > At 08:55 PM 4/13/01 +0400, ark@eltex.ru wrote:
> > >only marked with (*) are implemented in authsrv (both Gauntlet and fwtk),
> > >two others are obvious, but what was `display' for?
> > There are authentication protocols that need to send extended prompts to
> > the user.
> > The one that comes to mind immediately is SecurID in new-PIN mode. It 
> wants
> > to send a multi-line prompt to the user containing instructions on the 
> new PIN.
>
>Nope, does not look like that..
>
>                 if(!strncmp(buf,"display ", 8)) {
>                                 strcpy(cbuf, &buf[8]);
>                                 x = strlen(cbuf);
>                                 if(sayn(0,cbuf,x))
>                                         goto close_go;
>                                 strcpy(cbuf,"response dummy");
>                                 if(auth_send(cbuf))
>                                         goto lostconn;
>                                 continue;

Well, it may not look like that, but that's exactly what this is used for. 
See securid.c at around line 78 - you'll see several "display" commands.

The authentication program (securid.c) sends a "display" command. Authsrv 
reads it, cuts off the "display " portion, then echoes it to the user (the 
"sayn" call.) Then, it sends a response back, which isn't used. (All 
authsrv <-> token program communications are command/response, so we need 
to provide a response even though it's not used.)
         -Rick


From owner-fwtk-users@ex.tis.com Tue Apr 17 05:29 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA19477
	Tue, 17 Apr 2001 05:29:15 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA00412;
	Tue, 17 Apr 2001 02:32:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 01:16:34 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA25727
	for fwtk-users-outgoing; Tue, 17 Apr 2001 01:16:22 -0700 (PDT)
Message-ID: <3ADBFA07.AD7392E6@quest-innovations.com>
Date: Tue, 17 Apr 2001 10:08:39 +0200
From: Richard Meester <rme@quest-innovations.com>
X-Mailer: Mozilla 4.7 [en] (Win98; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: [Fwd: http404 : reason hostname unknown.]
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/mixed;
 boundary="------------3DB96FCBFE335DD8DD9FFA8D"
Content-Length: 1657

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a multi-part message in MIME format.
--------------3DB96FCBFE335DD8DD9FFA8D
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit



--
Quest Innovations
tel: +31 (0) 227 604046
http://www.quest-innovations.com


--------------3DB96FCBFE335DD8DD9FFA8D
Content-Type: message/rfc822
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

X-Mozilla-Status2: 00000000
Message-ID: <3ADBF894.3D66C1C4@quest-innovations.com>
Date: Tue, 17 Apr 2001 10:02:28 +0200
From: Richard Meester <rme@quest-innovations.com>
X-Mailer: Mozilla 4.7 [en] (Win98; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: http404 : reason hostname unknown.
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Hello all,

I have a weird problem.
I installed the TIS firewall and everything went well. I was able to
internet, send/receive mail, ftp etc.

I later changed the IP-address to 10.x.x.x. range, and changed the
netperm table file.

I am able to FTP, send/receive email etc, but get a http-gw http 404
error message with reason hostname unknown. The http-gw returns
immediatly after the request has been made. It seems that it cannot find
the resolver files or something, because when i run nslookup hostnames
are resolved correctly. I reinstalled the whole machine with linux
redhat 6.2, but have the same problem.

Any hints,

Richard

--
Quest Innovations
tel: +31 (0) 227 604046
http://www.quest-innovations.com



--------------3DB96FCBFE335DD8DD9FFA8D--


From owner-fwtk-users@ex.tis.com Tue Apr 17 07:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA19807
	Tue, 17 Apr 2001 07:31:59 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA05333;
	Tue, 17 Apr 2001 04:35:32 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 03:36:35 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA03202
	for fwtk-users-outgoing; Tue, 17 Apr 2001 03:36:15 -0700 (PDT)
From: ark@eltex.ru
Date: Tue, 17 Apr 2001 14:52:35 +0400
Message-Id: <200104171052.OAA16353@paranoid.eltex.spb.ru>
In-Reply-To: <Pine.GSO.4.05.10104161155190.2187-100000@laplace> from "Sergio Jimenez Tovar <sjimenez@galois.dgae.unam.mx>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: New version, when ?
To: sjimenez@galois.dgae.unam.mx
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1126

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

The license is scary anyways. We have compatible core library, though,
so i hope there will be a thing that could be called new release - but
it will not be TIS fwtk, i mean no TIS code inside.

Sergio Jimenez Tovar <sjimenez@galois.dgae.unam.mx> said :

> 	Why the version actual is the same 3 years early, anybody know
> when will be the new version ? thanks.
> 


                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOtwgcqH/mIJW9LeBAQEVsAQAj7wRBUnsO40d5o2FTpYoSMFye7D9IJau
T03KBAzvsdR2t4qyow7+LDqvaTPn77Dj0BLJeiqkVwi7ZoIzShlVuG2Lmxux79FB
tIL6gagd0fdl5nNysvSIro1JOVJZapYhenWgzSkxgfIw6OJ+gwjQBVKMgm68MLNV
URVPCIXiSKA=
=hE+I
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Tue Apr 17 09:29 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA20321
	Tue, 17 Apr 2001 09:29:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA12485;
	Tue, 17 Apr 2001 06:32:50 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 05:32:00 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA08150
	for fwtk-users-outgoing; Tue, 17 Apr 2001 05:31:44 -0700 (PDT)
Date: Tue, 17 Apr 2001 16:30:29 +0400 (MSD)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: ark@eltex.ru
cc: fwtk-users@ex.tis.com
Subject: Re: New version, when ?
In-Reply-To: <200104171052.OAA16353@paranoid.eltex.spb.ru>
Message-ID: <Pine.BSF.4.21.0104171629281.75795-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 515

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Tue, 17 Apr 2001 ark@eltex.ru wrote:

> The license is scary anyways. We have compatible core library, though,
> so i hope there will be a thing that could be called new release - but
> it will not be TIS fwtk, i mean no TIS code inside.
	And what about particular gw-s code?.. 

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Tue Apr 17 09:34 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA20345
	Tue, 17 Apr 2001 09:33:54 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA12858;
	Tue, 17 Apr 2001 06:37:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 05:41:32 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA08640
	for fwtk-users-outgoing; Tue, 17 Apr 2001 05:41:11 -0700 (PDT)
From: ark@eltex.ru
Date: Tue, 17 Apr 2001 16:57:39 +0400
Message-Id: <200104171257.QAA16701@paranoid.eltex.spb.ru>
In-Reply-To: <Pine.BSF.4.21.0104171629281.75795-100000@tyger.hq.internetmedia.ru> from "Antuan Avdioukhine <antuan@internetmedia.ru>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: New version, when ?
To: antuan@internetmedia.ru
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1428

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

You should know the answer - we discussed that several times offline.
smap/smapd will be replaced with smtpd/smtpfwdd converted to new API.
ftp, telnet, rlogin need rewrite or code import, there are several candidates.
authsrv definitely needs rewrite (i want _software_ securid, sso and maybe radius
and stuff there)

Antuan Avdioukhine <antuan@internetmedia.ru> said :

> On Tue, 17 Apr 2001 ark@eltex.ru wrote:
> 
> > The license is scary anyways. We have compatible core library, though,
> > so i hope there will be a thing that could be called new release - but
> > it will not be TIS fwtk, i mean no TIS code inside.
> 	And what about particular gw-s code?.. 
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOtw9wqH/mIJW9LeBAQF1lwP/QmyoYCJHmSRt4lkA9oimwRO8nOyy+PzN
5cv0SIprX67pC6x3hAW4GuwRcc4vYb8KAACN1h4GxL35y9pxjzIjvWekprVkp9Am
KT+9qXtf1j+zX/7RJXWfXdVupWc88N7hFCi0YqvQW9fHDVi2rWWnkFG1RFRUAqgX
Zg/tcGd0NGc=
=68g7
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Tue Apr 17 12:20 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA21490
	Tue, 17 Apr 2001 12:20:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA03774;
	Tue, 17 Apr 2001 09:23:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 08:22:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA24136
	for fwtk-users-outgoing; Tue, 17 Apr 2001 08:21:54 -0700 (PDT)
Message-ID: <3ADBF894.3D66C1C4@quest-innovations.com>
Date: Tue, 17 Apr 2001 10:02:28 +0200
From: Richard Meester <rme@quest-innovations.com>
X-Mailer: Mozilla 4.7 [en] (Win98; I)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: http404 : reason hostname unknown.
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 844

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello all,

I have a weird problem.
I installed the TIS firewall and everything went well. I was able to
internet, send/receive mail, ftp etc.

I later changed the IP-address to 10.x.x.x. range, and changed the
netperm table file.

I am able to FTP, send/receive email etc, but get a http-gw http 404
error message with reason hostname unknown. The http-gw returns
immediatly after the request has been made. It seems that it cannot find
the resolver files or something, because when i run nslookup hostnames
are resolved correctly. I reinstalled the whole machine with linux
redhat 6.2, but have the same problem.

Any hints,

Richard

--
Quest Innovations
tel: +31 (0) 227 604046
http://www.quest-innovations.com

From owner-fwtk-users@ex.tis.com Tue Apr 17 12:20 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA21489
	Tue, 17 Apr 2001 12:20:09 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA03792;
	Tue, 17 Apr 2001 09:23:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 08:22:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA24224
	for fwtk-users-outgoing; Tue, 17 Apr 2001 08:22:19 -0700 (PDT)
Message-ID: <3ADC5FA3.13219D19@v-one.com>
Date: Tue, 17 Apr 2001 11:22:11 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Antuan Avdioukhine <antuan@internetmedia.ru>
CC: ark@eltex.ru, fwtk-users@ex.tis.com
Subject: Re: New version, when ?
References: <Pine.BSF.4.21.0104171629281.75795-100000@tyger.hq.internetmedia.ru>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 652

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> > The license is scary anyways. We have compatible core library, though,
> > so i hope there will be a thing that could be called new release - but
> > it will not be TIS fwtk, i mean no TIS code inside.

I've heard a rumor that the FWTK may go open source in a couple of
months...

If it does, then I'll work on getting a FTP/CVS server set up at
fwtk.org for new FWTK versions. Then, we can have new versions whenever
we want...  :-)

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Tue Apr 17 12:20 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA21493
	Tue, 17 Apr 2001 12:20:20 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA03806;
	Tue, 17 Apr 2001 09:23:50 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 08:21:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA23969
	for fwtk-users-outgoing; Tue, 17 Apr 2001 08:20:57 -0700 (PDT)
From: ark@eltex.ru
Date: Tue, 17 Apr 2001 14:47:52 +0400
Message-Id: <200104171047.OAA16335@paranoid.eltex.spb.ru>
In-Reply-To: <Pine.GSO.4.10.10104152216220.3314-100000@ns1.bfg.com> from "Ted Keller <keller@pm.bfg.com>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: Configuring socks-gw
To: keller@pm.bfg.com
Cc: fwtk-users@lists.nai.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1764

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

nuqneH,

Let me guess.. Because it is too complex, its security is questionable
and it cannot be configured via netperm-table.


Ted Keller <keller@pm.bfg.com> said :

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> So why don't you just run the socks daemon? 
> 
> ted keller
> 
> 
> On Sun, 15 Apr 2001, Larry Jackson wrote:
> 
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> > 
> > I just downloaded socks-gw from the FWTK Patches section.
> > I compiled and installed it OK, but there are no docs.
> > 
> > How do I configure the socks-gw proxy
> > ( netperm-table and inetd.conf entries please) ?
> > 
> > I'm trying to use socks-gw to run gnutella through my personal firewall.
> > 
> > P.S. Has any more work been done on this proxy?
> > 
> > Thanks,
> > LarryJackson@iName.com
> > 
> > On  2000-01-04 "Yakov Kravets" <ygk@nb.com> said:
> > >
> > > I have put together a socks-gw proxy. 
> > > From the name you can tell that it implements SOCKS protocol. 
> > > The goal for this project was to integrate SOCKS proxy into FWTK.
> > > At this time it only implements CONNECT request and 
> > > I'm working on getting BIND done.
> > >
> > > HNY everybody.
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

From owner-fwtk-users@ex.tis.com Tue Apr 17 16:07 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA22530
	Tue, 17 Apr 2001 16:07:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA05422;
	Tue, 17 Apr 2001 13:10:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 12:07:58 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA26757
	for fwtk-users-outgoing; Tue, 17 Apr 2001 12:07:37 -0700 (PDT)
From: john@someperson.com
Message-ID: <020b01c0c76b$24261ec0$eea23240@webfirst.com>
To: <fwtk-users@tis.com>
Subject: http-gw
Date: Tue, 17 Apr 2001 14:20:51 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2919.6700
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 353

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I tried starting http-gw (fwtk2.1) and keeping getting "cannot get our port"
in the error logs. Apache is running on 81 now so I can't see how that could
be interfering. Could this be a problem w/ netperm?

thanks,
    john

From owner-fwtk-users@ex.tis.com Tue Apr 17 18:05 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA23324
	Tue, 17 Apr 2001 18:05:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA25624;
	Tue, 17 Apr 2001 15:08:22 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 17 Apr 2001 14:04:53 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id OAA14430
	for fwtk-users-outgoing; Tue, 17 Apr 2001 14:04:32 -0700 (PDT)
From: ark@eltex.ru
Message-Id: <200104172120.BAA18561@paranoid.eltex.spb.ru>
Subject: Re: New version, when ?
To: darrenr@reed.wattle.id.au (Darren Reed)
Date: Wed, 18 Apr 2001 01:20:29 +0400 (MSD)
Cc: antuan@internetmedia.ru (Antuan Avdioukhine), ark@eltex.ru,
        fwtk-users@ex.tis.com
Reply-To: ark@eltex.ru
In-Reply-To: <200104171822.EAA26714@avalon.reed.wattle.id.au> from "Darren Reed" at Apr 18, 2001 04:22:07 AM
X-Mailer: ELM [version 2.5 PL3]
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 627

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

nuqneH,

What's wrong with fwtk api and ideology? I always loved it..
Though it needs some work, i know.

> 
> 
> bah, someone should just develop a *NEW* set of proxy tools and scrap these
> ancient ones.

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

From owner-fwtk-users@ex.tis.com Wed Apr 18 07:05 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA25935
	Wed, 18 Apr 2001 07:05:53 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id EAA28992;
	Wed, 18 Apr 2001 04:09:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 18 Apr 2001 02:54:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA26452
	for fwtk-users-outgoing; Wed, 18 Apr 2001 02:53:52 -0700 (PDT)
From: ark@eltex.ru
Date: Wed, 18 Apr 2001 14:09:50 +0400
Message-Id: <200104181009.OAA20786@paranoid.eltex.spb.ru>
In-Reply-To: <200104172123.HAA27152@avalon.reed.wattle.id.au> from "Darren Reed <darrenr@reed.wattle.id.au>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: New version, when ?
To: darrenr@reed.wattle.id.au
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2610

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Darren Reed <darrenr@reed.wattle.id.au> said :

> I cannot see the FWTK ever being "open source".  It was always felt as if it
> competed too well with the commercial product in various ways.

Yep, that's true.
 
> Time spent waiting is better spent coding something new than twiddling thumbs.

Why waiting? There are things to do anyways. f.e. the whole smap thing is
semi-broken (no flames please but small annoying bugs appear again and again),
authsrv needs improvement so much that rewrite is required and more..

We already do have numerous add-on proxies that can be run without a bit of TIS
code (i (with some help of Eberhard Mattes and other people) wrote a replacement
core library that implements 100% compatible API)
 
> That is if you want something GPL. 

I'd say i want something BSD. GPL is too restrictive ;)

> The problem, I suspect, with that is
> there are more people waiting to download, compile, install and build
> firewalls for others (charging $$) using a free product than there are
> capable people of coding it.  (So I'm a bit cynical...)

Yep. but those people may pay for support and sponsor development..
 
> The real problem with the FWTK api/design is it has been sitting in a
> virtual closet for how ever many years with little or no upkeep, etc.
> I'm sure even the original author would recommend 'start over' :)

The original API is pretty low-level, but the problem is close to be solved.
The design is still good, there are not many things changed since applictation
firewalls were invented.

> 
> Darren
> 
> In some email I received from ark@eltex.ru, sie wrote:
> > nuqneH,
> > 
> > What's wrong with fwtk api and ideology? I always loved it..
> > Though it needs some work, i know.
> > 
> > > 
> > > 
> > > bah, someone should just develop a *NEW* set of proxy tools and scrap these
> > > ancient ones.

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOt1n7KH/mIJW9LeBAQHuVwQAkd7eVALVOEIpabx/aJ4MSR39EosrMo1q
dMD3jRA3SCNmd/bnIhXDKy4AqfLJMOX9RDNkclOlklXqybXPGhUpUqPZyMcWTsnK
tq2mdfWB9KCdCE4sZdLXFJETHM3AvqzgPjR2zD0Svi1walQcvD3kTMRxV3II5fQt
SMU+KohS0sM=
=97Ud
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Wed Apr 18 08:20 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA26153
	Wed, 18 Apr 2001 08:20:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA02020;
	Wed, 18 Apr 2001 05:23:09 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 18 Apr 2001 04:24:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA29573
	for fwtk-users-outgoing; Wed, 18 Apr 2001 04:23:36 -0700 (PDT)
From: ark@eltex.ru
Date: Wed, 18 Apr 2001 15:39:55 +0400
Message-Id: <200104181139.PAA21091@paranoid.eltex.spb.ru>
In-Reply-To: <NDBBLKIFCKDHHCOAGHFDCEADCAAA.gale@dera.gov.uk> from ""Tony Gale" <gale@dera.gov.uk>"
Organization: "Klingon Imperial Intelligence Service"
Subject: RE: New version, when ?
To: gale@dera.gov.uk
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 2509

[To be removed from this list send the message "unsubscrFrom fwtk-archive Wed Apr 18 23:45 EDT 2001
Received: by lists.tislabs.com (8.9.1/8.9.1) id XAA02369
	Wed, 18 Apr 2001 23:45:04 -0400 (EDT)
Date: Wed, 18 Apr 2001 23:45:04 -0400 (EDT)
From: Archive of fwtk-users <fwtk-archive>
Message-Id: <200104190345.XAA02369@lists.tislabs.com>
To: fwtk-archive
Subject: Output from "cron" command
Content-Type: text
Content-Length: 128

Your "cron" job

/usr/local/home/fwtk-archive/sweep

produced the following output:

cat: write error: No space left on device


From owner-fwtk-users@ex.tis.com Thu Apr 19 02:53 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id CAA02825
	Thu, 19 Apr 2001 02:53:45 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id XAA25178;
	Wed, 18 Apr 2001 23:26:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 18 Apr 2001 15:22:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA26823
	for fwtk-users-outgoing; Wed, 18 Apr 2001 15:20:44 -0700 (PDT)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE363@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: fwtk-users@ex.tis.com
Subject: Port
Date: Wed, 18 Apr 2001 15:19:04 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 306

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

  What file do I need to modify to open all my port or allow traffic though,
and what do I need to say in the file to allow port 1 though 65535 to be
open?

Thankx,
  Jonathan


From owner-fwtk-users@ex.tis.com Thu Apr 19 11:31 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA06709
	Thu, 19 Apr 2001 11:31:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA17029;
	Thu, 19 Apr 2001 07:48:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 18 Apr 2001 23:44:27 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA25563
	for fwtk-users-outgoing; Wed, 18 Apr 2001 23:39:04 -0700 (PDT)
Date: Thu, 19 Apr 2001 10:37:15 +0400 (MSD)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: Tony Gale <gale@dera.gov.uk>
cc: ark@eltex.ru, Darren Reed <darrenr@reed.wattle.id.au>,
        fwtk-users@ex.tis.com
Subject: RE: New version, when ?
In-Reply-To: <NDBBLKIFCKDHHCOAGHFDCEADCAAA.gale@dera.gov.uk>
Message-ID: <Pine.BSF.4.21.0104191026590.47001-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1125

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, 18 Apr 2001, Tony Gale wrote:

> The trouble is the model is simply wrong for anything approaching high
> request rates.
	Tony, what is -- high request rate? And why firewall have to be an
perfomance giant? 

> I should, at this point, declare that I have been developing a replacement
> for the http-gw for a while. It's not feature complete yet, and a couple of
> areas need work, but it's getting there.
	Have you tried squid-gw by Mattes (em-gw tools)? It seems to be
smart enough and introduces good perfomance.

> The FWTK design uses a fork()-per-request model, which has the advantage of
> simplicity and being very forgiving of coding errors, but suffers some
> serious performance issues.
	Simplicity is the only requirement for programming of security
tools. Trying to build smart monster with fantastical perfomance you may
produce something like M$ ISA. Is it good idea?

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Thu Apr 19 14:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA07340
	Thu, 19 Apr 2001 14:32:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id LAA02274;
	Thu, 19 Apr 2001 11:04:18 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 19 Apr 2001 03:00:07 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA01205
	for fwtk-users-outgoing; Thu, 19 Apr 2001 02:57:26 -0700 (PDT)
From: ark@eltex.ru
Date: Thu, 19 Apr 2001 14:13:46 +0400
Message-Id: <200104191013.OAA25810@paranoid.eltex.spb.ru>
In-Reply-To: <3ADD7B3D.B2E53C8F@peaktime.be> from "Michel Bardiaux <mbardiaux@peaktime.be>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: New version, when ?
To: mbardiaux@peaktime.be
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1116

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

I am not sure it is bad thing.

Michel Bardiaux <mbardiaux@peaktime.be> said :
 
> ark@eltex.ru wrote:
> 
> > > That is if you want something GPL.
> > 
> > I'd say i want something BSD. GPL is too restrictive ;)
> > 
> Please consider LGPL. BSD has the (to me) extremely irritating feature
> that it allows proprietary, closed, *incompatible* derivatives.

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOt66WaH/mIJW9LeBAQHu5QP/Wk55MmmMK77kvRYoNaNIKWs04pdVAIuj
c4BR6tXurlZWbzEhQ2cmsCj7+kmo6uzq1yPFoei3i70UiRIsfNapq1wiMJtLydar
Qp6wOmIIscMtqPGF5OLLkU9lPrCc13OBzNpiaiZF+2cDdg6mwPYVE2/jmLCJol/l
+D7kJ0XjSqs=
=KtJq
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Thu Apr 19 15:43 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA07820
	Thu, 19 Apr 2001 15:43:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA06895;
	Thu, 19 Apr 2001 12:15:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 19 Apr 2001 04:10:58 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA03216
	for fwtk-users-outgoing; Thu, 19 Apr 2001 04:09:37 -0700 (PDT)
From: jan@radio.hundert6.de
Message-ID: <XFMail.010419130842.jan@radio.hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE363@A8MC.PSNS.NAVY.MIL>
Date: Thu, 19 Apr 2001 13:08:42 -0000 (GMT)
To: fwtk-users@ex.tis.com
Subject: RE: Port
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 727

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>   What file do I need to modify to open all my port or allow traffic
> though,
> and what do I need to say in the file to allow port 1 though 65535 to
> be
> open?

You can't. The thing with application level gateways such as the fwtk
is they don't forward packets at the transport layer, i.e. on the IP
layer itself. An fwtk host is not a router, thus you can't just heave
arbitrary packets to certain ports to the other interface. You might
take a look at plug-gw for allowing certain additional services. 

Bye, Jan

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 08:17 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA09796
	Fri, 20 Apr 2001 08:17:13 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA20127;
	Thu, 19 Apr 2001 15:00:52 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 19 Apr 2001 06:58:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA13072
	for fwtk-users-outgoing; Thu, 19 Apr 2001 06:55:43 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010419105524.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE363@A8MC.PSNS.NAVY.MIL>
Date: Thu, 19 Apr 2001 10:55:24 -0000 (GMT)
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
Subject: RE: Port
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 727

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>   What file do I need to modify to open all my port or allow traffic
> though,
> and what do I need to say in the file to allow port 1 though 65535 to
> be
> open?

You can't. The thing with application level gateways such as the fwtk
is they don't forward packets at the transport layer, i.e. on the IP
layer itself. An fwtk host is not a router, thus you can't just heave
arbitrary packets to certain ports to the other interface. You might
take a look at plug-gw for allowing certain additional services. 

Bye, Jan

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 08:30 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA09880
	Fri, 20 Apr 2001 08:30:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA27259;
	Thu, 19 Apr 2001 17:56:28 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 19 Apr 2001 10:01:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA26891
	for fwtk-users-outgoing; Thu, 19 Apr 2001 09:59:07 -0700 (PDT)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE366@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "'jan@radio.hundert6.de'" <jan@radio.hundert6.de>
Cc: fwtk-users@ex.tis.com
Subject: RE: Port
Date: Thu, 19 Apr 2001 09:57:03 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1080

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Does anyone know what kind of plug-gw I might use?

-----Original Message-----
From: jan@radio.hundert6.de [mailto:jan@radio.hundert6.de]
Sent: Thursday, April 19, 2001 6:09 AM
To: fwtk-users@ex.tis.com
Subject: RE: Port


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

>   What file do I need to modify to open all my port or allow traffic
> though,
> and what do I need to say in the file to allow port 1 though 65535 to
> be
> open?

You can't. The thing with application level gateways such as the fwtk
is they don't forward packets at the transport layer, i.e. on the IP
layer itself. An fwtk host is not a router, thus you can't just heave
arbitrary packets to certain ports to the other interface. You might
take a look at plug-gw for allowing certain additional services. 

Bye, Jan

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de


From owner-fwtk-users@ex.tis.com Fri Apr 20 08:49 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA09952
	Fri, 20 Apr 2001 08:49:36 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA22258;
	Thu, 19 Apr 2001 15:36:52 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 19 Apr 2001 07:41:36 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA16402
	for fwtk-users-outgoing; Thu, 19 Apr 2001 07:38:54 -0700 (PDT)
From: "Tony Gale" <gale@dera.gov.uk>
To: <ark@eltex.ru>
Cc: <fwtk-users@ex.tis.com>
Subject: RE: New version, when ?
Date: Thu, 19 Apr 2001 11:56:33 +0100
Message-ID: <NDBBLKIFCKDHHCOAGHFDAEAECAAA.gale@dera.gov.uk>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
In-Reply-To: <200104181139.PAA21091@paranoid.eltex.spb.ru>
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 4065

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


I have looked at squid-gw, but not in any great depth. A fork() vs
multithread model does not necessarily map to simplicity vs complexity, and
neither map directly to any level of security. The http-gw is fork()ed and
simple, but it isn't exactly well written or bug free. Look at the 'net
flags' issue as an example.

Here's my favourite comment from the FWTK code:

        the object of this program is to allow us to present an SMTP service
        for people to talk to, which is unprivileged, and runs in a chrooted
        directory. a secondary requirement is that the code be as simple as
        possible, to permit manual review. this code, therefore, contains
        no comments other than this one - comments being an indication that
        code is too complex to be trusted.

        ....

        mjr. 1993

Makes me laugh everytime I read it.

Anyway, back to the point. Yes my code it GPL'ed, but I haven't released it
yet as there is one more feature I need to add before I do so. I works fine
in it's current state, but I don't want to prejudice it by releasing before
I've re-implemented the resolver, which is currently using a pre-forked
process pool as a temporary measure.

-tony

-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of ark@eltex.ru
Sent: 18 April 2001 12:40
To: gale@dera.gov.uk
Cc: fwtk-users@ex.tis.com
Subject: RE: New version, when ?


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Can't call it `simply wrong'. Not the best, but acceptable.

Have you seen squid-gw? It hadles pretty high load well. Acutally in-depth
content analysis gives more overhead than fork()s so there is (almost) no
reason
to implement sophisticated pre-forked or multithreaded model. Code
simplicity and
readabilty are more important for security applications than performance
hacks.

Your proxy may be useful too in some environments, though. Is it public
code?

"Tony Gale" <gale@dera.gov.uk> said :

> The trouble is the model is simply wrong for anything approaching high
> request rates.
>
> I should, at this point, declare that I have been developing a replacement
> for the http-gw for a while. It's not feature complete yet, and a couple
of
> areas need work, but it's getting there.
>
> The FWTK design uses a fork()-per-request model, which has the advantage
of
> simplicity and being very forgiving of coding errors, but suffers some
> serious performance issues.
>
> The http-gw content checking is a performance killer, and offers very
little
> in return, as it's easy to bypass.
>
> -tony
>
> -----Original Message-----
> From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
> Behalf Of ark@eltex.ru
> Sent: 17 April 2001 22:20
> To: Darren Reed
> Cc: Antuan Avdioukhine; ark@eltex.ru; fwtk-users@ex.tis.com
> Subject: Re: New version, when ?
>
>
> [To be removed from this list send the message "unsubscribe fwtk-users" in
> the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> nuqneH,
>
> What's wrong with fwtk api and ideology? I always loved it..
> Though it needs some work, i know.
>
> >
> >
> > bah, someone should just develop a *NEW* set of proxy tools and scrap
> these
> > ancient ones.



                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOt19CqH/mIJW9LeBAQGvlQQAo336uwwks/Zi0kSagL7xXmCvOBz8FdJP
GiKLmI0f/eMP/hKg2p9d4EsN60hhB/RKYOyS3HK2rhnLQzj5zWwr44wm808dhAua
ErVVRNmnOolxjYfNOzCuZiI1f5X+Gtcnrth5PulGyS4LmYt62DOntMLtHvh1BZuv
3LF2WPWQiHM=
=CzxJ
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Fri Apr 20 09:03 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA09969
	Fri, 20 Apr 2001 09:03:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA28318;
	Thu, 19 Apr 2001 18:32:28 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 19 Apr 2001 10:35:42 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA29932
	for fwtk-users-outgoing; Thu, 19 Apr 2001 10:34:21 -0700 (PDT)
From: jan@radio.hundert6.de
Message-ID: <XFMail.010419193300.jan@radio.hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
Date: Thu, 19 Apr 2001 19:33:00 -0000 (GMT)
To: fwtk-users@ex.tis.com
Subject: queue filling up... I/O errors
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 6939

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello everybody,

I am encountering pretty heavy problems with smap / smapd /sendmail.
While my config generally works flawlessly, messages to a couple of
hosts seem to time out during data transfer. I can easily reach the
relevant mail exchangers and since it's clearly not a length-based
problem, I don't think my ip-filter config is the culprit. If this were
the case, it should work during the next re-send, which it doesn't. 

A lot of these mails go out to yahoo and from the list archive I could
there have already been problems reported with them. Unfortunately it's
not yahoo exclusively, neither can I lock it down to one certain MTA
smap doesn't like talking to. 

Mysteriously, some mails are being sent without any problems while
others land in the queue because of I/O errors or timeouts or
connection resets. This seems to happen especially with forwarded
messages, but then again, not exclusively. 

I am totally clueless. 

>From the sendmail homepage I could tell there were certain
incompatibilities reported - I couldn't find any specific for OpenBSD
2.8 and the sendmail version that comes shipped with it (is there a
simple way to find out which version it is?). 

Is this maybe a platform-related problem? Anyone else using OpenBSD
2.8??

I'll attach my queue output to illustrate the issue. Maybe some of you
have problem with certain of the listed hosts as well. 

This is really giving me a bad headache, so I'm very grateful for every
helpful hint. FWTK version's 2.1, of course, smap has the Yao-patch
applied. 

Cheers, Jan

                /var/spool/mqueue (28 requests)
----Q-ID---- --Size-- -----Q-Time-----
------------Sender/Recipient------------
f3JEIu417172*   20484 Thu Apr 19 16:18 <newsletter@shortnews.de>
                 (I/O error)
                                       <micka@nexgo.de>
f3JEluw31730   104950 Thu Apr 19 16:47 <S.vBramann@radio.hundert6.de>
                 (I/O error)
                                       <micka@nexgo.de>
f3JD1OA03796   100026 Thu Apr 19 15:01 <KreuzerS@fleishman.com>
                 (Warning: could not send message for past 4 hours)
                                       <patzak@snafu.de>
f3JBdqj18237*    1634 Thu Apr 19 13:39 <sfranzen@radio.hundert6.de>
                 (<b.schneider@atkon.de>... reply: read error from
mail.atkon.)
                                       <b.schneider@atkon.de>
f3JBSMJ13484     1361 Thu Apr 19 13:28 <M.Steuer@hundert6.de>
                 (Deferred: 451 Timeout)
                                       <melha5@yahoo.de>
f3JBZqe31960     1387 Thu Apr 19 13:35 <s.neuthor@radio.hundert6.de>
                 (I/O error: Input/output error)
                                       <neuthor@diemediafabrik.de>
f3J7JWx06867      700 Thu Apr 19 09:19 <sfranzen@radio.hundert6.de>
                 (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <b.schneider@atkon.de>
f3J7obb25545    14271 Thu Apr 19 09:50 MAILER-DAEMON
      8BITMIME   (Deferred: Connection refused by gs3.serverdienst.de.)
                                       <www6@gs3.serverdienst.de>
f3J701129967     1359 Thu Apr 19 09:00 <M.Steuer@hundert6.de>
                 (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <melha5@yahoo.de>
f3J6sVa30689     1385 Thu Apr 19 08:54 <s.neuthor@radio.hundert6.de>
                 (I/O error: Input/output error)
                                       <neuthor@diemediafabrik.de>
f3J23Qx08220    17448 Thu Apr 19 04:03 MAILER-DAEMON
                 (I/O error)
                                       <aynn@weedmail.com>
f3IGTCe27668    13212 Wed Apr 18 18:29 MAILER-DAEMON
                 (host map: lookup (Advisor.net): deferred)
                                       <Financial@Advisor.net>
f3IEHdD14321    20811 Wed Apr 18 16:17 <newsletter@shortnews.de>
                 (I/O error)
                                       <micka@nexgo.de>
f3ID37T00078*    1379 Wed Apr 18 15:03 <s.neuthor@radio.hundert6.de>
                 (Deferred: Connection reset by mail.snafu.de.)
                                       <neuthor@diemediafabrik.de>
f3IBQ5v00150   220116 Wed Apr 18 13:26 <d.mitzlaff@hundert6.de>
      8BITMIME   (I/O error)
                                      
<charlotte.bussy@dresdner-bank.com>
f3I8B1J07959     1067 Wed Apr 18 10:11 <J.Zang@radio.hundert6.de>
                 (<enquiries@seeglasgow.com>... reply: read error from
velma.s)
                                       <enquiries@seeglasgow.com>
f3I710800841   645910 Wed Apr 18 09:01 <sfranzen@radio.hundert6.de>
                 (I/O error)
                                       <silke.franzen@epost.de>
f3HFXeP15290     1067 Tue Apr 17 17:33 <J.Zang@radio.hundert6.de>
                 (Deferred: Connection reset by velma.seeglasgow.com.)
                                       <enquiries@seeglasgow.com>
f3HD6Zu11150     1305 Tue Apr 17 15:06 <messtechnik@hundert6.de>
      8BITMIME   (<frank.scholz@bundestag.de>... reply: read error from
mail.b)
                                       <frank.scholz@bundestag.de>
f3HCnZS29113*    1528 Tue Apr 17 14:49 <jan@hundert6.de>
                 (<tom.fun@bigfoot.de>... reply: read error from
mail.bigfoot.)
                                       <tom.fun@bigfoot.de>
f3HBlYb06640      721 Tue Apr 17 13:47 <M.Steuer@hundert6.de>
                 (Deferred: 451 Timeout)
                                       <marius_zekri@yahoo.de>
f3H9ssR29880     1410 Tue Apr 17 11:54 <S.Skala@radio.hundert6.de>
                 (<cynthiapaerschke@yahoo.de>... reply: read error from
mx2.ma)
                                       <cynthiapaerschke@yahoo.de>
f3H8tNt02532   218604 Tue Apr 17 10:55 <d.mitzlaff@hundert6.de>
      8BITMIME   (I/O error)
                                      
<charlotte.bussy@dresdner-bank.com>
f3H7bL902824      720 Tue Apr 17 09:37 <M.Steuer@hundert6.de>
                 (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <marius_zekri@yahoo.de>
f3H6roa11291   642351 Tue Apr 17 08:53 <sfranzen@radio.hundert6.de>
                 (I/O error)
                                       <silke.franzen@epost.de>
f3H6toA12584   642555 Tue Apr 17 08:55 <sfranzen@radio.hundert6.de>
                 (I/O error)
                                       <steuerberater-koebe@snafu.de>
f3G8Ur316379      977 Mon Apr 16 10:30 <A.Schwaff@radio.hundert6.de>
      8BITMIME   (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <otterfieb@yahoo.de>
f3FJo4x17545*  900736 Sun Apr 15 21:50 <>
                 (I/O error)
                                       <micka@nexgo.de>

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 09:16 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA09990
	Fri, 20 Apr 2001 09:16:42 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA12176;
	Fri, 20 Apr 2001 06:20:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 05:46:21 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA10023
	for fwtk-users-outgoing; Fri, 20 Apr 2001 05:46:04 -0700 (PDT)
Date: Fri, 20 Apr 2001 08:45:21 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: jan@radio.hundert6.de
Cc: fwtk-users@ex.tis.com
Subject: Re: Port
Message-Id: <20010420084521.D24143@washington.cospo.osis.gov>
Mail-Followup-To: jan@radio.hundert6.de, fwtk-users@ex.tis.com
References: <79C524BDBB22D411915800A0C96F68FB9FE363@A8MC.PSNS.NAVY.MIL> <XFMail.010419130842.jan@radio.hundert6.de>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <XFMail.010419130842.jan@radio.hundert6.de>; from jan@radio.hundert6.de on Thu, Apr 19, 2001 at 01:08:42PM -0000
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 887

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Apr 19, 2001 at 01:08:42PM -0000, jan@radio.hundert6.de wrote:
> >   What file do I need to modify to open all my port or allow traffic
> > though,
> > and what do I need to say in the file to allow port 1 though 65535 to
> > be
> > open?

You take your firewall, dump it in the nearest trash can, and replace
it with a piece of copper wire.

What did you think a firewall did?  It's not magic.  If you want to
leave yourself open to any random network probe, which is to say to all
attacks, then just don't use a firewall.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Apr 20 09:25 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA10047
	Fri, 20 Apr 2001 09:25:45 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA12873;
	Fri, 20 Apr 2001 06:29:41 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 05:56:17 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA10473
	for fwtk-users-outgoing; Fri, 20 Apr 2001 05:56:01 -0700 (PDT)
Date: Fri, 20 Apr 2001 08:55:17 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Tony Gale <gale@dera.gov.uk>
Cc: ark@eltex.ru, fwtk-users@ex.tis.com
Subject: Re: New version, when ?
Message-Id: <20010420085517.F24143@washington.cospo.osis.gov>
Mail-Followup-To: Tony Gale <gale@dera.gov.uk>, ark@eltex.ru,
	fwtk-users@ex.tis.com
References: <200104181139.PAA21091@paranoid.eltex.spb.ru> <NDBBLKIFCKDHHCOAGHFDAEAECAAA.gale@dera.gov.uk>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <NDBBLKIFCKDHHCOAGHFDAEAECAAA.gale@dera.gov.uk>; from gale@dera.gov.uk on Thu, Apr 19, 2001 at 11:56:33AM +0100
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1115

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, Apr 19, 2001 at 11:56:33AM +0100, Tony Gale wrote:
...
> Here's my favourite comment from the FWTK code:
> 
>         the object of this program is to allow us to present an SMTP service
>         for people to talk to, which is unprivileged, and runs in a chrooted
>         directory. a secondary requirement is that the code be as simple as
>         possible, to permit manual review. this code, therefore, contains
>         no comments other than this one - comments being an indication that
>         code is too complex to be trusted.
> 
>         ....
> 
>         mjr. 1993
> 
> Makes me laugh everytime I read it.
...

;-)

Marcus is no stranger to hubris.  ;-)

In contrast, see my patches to 'smap'.  I contributed more comment than
code!

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Apr 20 10:22 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10173
	Fri, 20 Apr 2001 10:22:03 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA19825;
	Fri, 20 Apr 2001 07:25:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 06:50:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA14524
	for fwtk-users-outgoing; Fri, 20 Apr 2001 06:50:24 -0700 (PDT)
Date: Fri, 20 Apr 2001 09:47:44 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: <jan@radio.hundert6.de>
cc: <fwtk-users@ex.tis.com>
Subject: Re: queue filling up... I/O errors
In-Reply-To: <XFMail.010419193300.jan@radio.hundert6.de>
Message-ID: <Pine.GSO.4.31.0104200944190.19972-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 7839

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Note - this is not a smap/smapd issue.  Sendmail is the MTA that attempts
do to the delivery.  Focus your research in the sendmail area.

You may want to start by doing a survey on the remote system - determing
what their standard mailer is (telnet remotehost 25 usually does the
trick).

Next - determine if you ever deliver mail to them - Is this a hard
problem - or one of those hardtosovle it sometimes works type of problem.

Pick one - contact them and see if they can shed any light (oh! my disk
filled up).

ted keller


On Thu, 19 Apr 2001 jan@radio.hundert6.de wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Hello everybody,
>
> I am encountering pretty heavy problems with smap / smapd /sendmail.
> While my config generally works flawlessly, messages to a couple of
> hosts seem to time out during data transfer. I can easily reach the
> relevant mail exchangers and since it's clearly not a length-based
> problem, I don't think my ip-filter config is the culprit. If this were
> the case, it should work during the next re-send, which it doesn't.
>
> A lot of these mails go out to yahoo and from the list archive I could
> there have already been problems reported with them. Unfortunately it's
> not yahoo exclusively, neither can I lock it down to one certain MTA
> smap doesn't like talking to.
>
> Mysteriously, some mails are being sent without any problems while
> others land in the queue because of I/O errors or timeouts or
> connection resets. This seems to happen especially with forwarded
> messages, but then again, not exclusively.
>
> I am totally clueless.
>
> From the sendmail homepage I could tell there were certain
> incompatibilities reported - I couldn't find any specific for OpenBSD
> 2.8 and the sendmail version that comes shipped with it (is there a
> simple way to find out which version it is?).
>
> Is this maybe a platform-related problem? Anyone else using OpenBSD
> 2.8??
>
> I'll attach my queue output to illustrate the issue. Maybe some of you
> have problem with certain of the listed hosts as well.
>
> This is really giving me a bad headache, so I'm very grateful for every
> helpful hint. FWTK version's 2.1, of course, smap has the Yao-patch
> applied.
>
> Cheers, Jan
>
>                 /var/spool/mqueue (28 requests)
> ----Q-ID---- --Size-- -----Q-Time-----
> ------------Sender/Recipient------------
> f3JEIu417172*   20484 Thu Apr 19 16:18 <newsletter@shortnews.de>
>                  (I/O error)
>                                        <micka@nexgo.de>
> f3JEluw31730   104950 Thu Apr 19 16:47 <S.vBramann@radio.hundert6.de>
>                  (I/O error)
>                                        <micka@nexgo.de>
> f3JD1OA03796   100026 Thu Apr 19 15:01 <KreuzerS@fleishman.com>
>                  (Warning: could not send message for past 4 hours)
>                                        <patzak@snafu.de>
> f3JBdqj18237*    1634 Thu Apr 19 13:39 <sfranzen@radio.hundert6.de>
>                  (<b.schneider@atkon.de>... reply: read error from
> mail.atkon.)
>                                        <b.schneider@atkon.de>
> f3JBSMJ13484     1361 Thu Apr 19 13:28 <M.Steuer@hundert6.de>
>                  (Deferred: 451 Timeout)
>                                        <melha5@yahoo.de>
> f3JBZqe31960     1387 Thu Apr 19 13:35 <s.neuthor@radio.hundert6.de>
>                  (I/O error: Input/output error)
>                                        <neuthor@diemediafabrik.de>
> f3J7JWx06867      700 Thu Apr 19 09:19 <sfranzen@radio.hundert6.de>
>                  (Deferred: Connection timed out with
> mx2.mail.yahoo.com.)
>                                        <b.schneider@atkon.de>
> f3J7obb25545    14271 Thu Apr 19 09:50 MAILER-DAEMON
>       8BITMIME   (Deferred: Connection refused by gs3.serverdienst.de.)
>                                        <www6@gs3.serverdienst.de>
> f3J701129967     1359 Thu Apr 19 09:00 <M.Steuer@hundert6.de>
>                  (Deferred: Connection timed out with
> mx2.mail.yahoo.com.)
>                                        <melha5@yahoo.de>
> f3J6sVa30689     1385 Thu Apr 19 08:54 <s.neuthor@radio.hundert6.de>
>                  (I/O error: Input/output error)
>                                        <neuthor@diemediafabrik.de>
> f3J23Qx08220    17448 Thu Apr 19 04:03 MAILER-DAEMON
>                  (I/O error)
>                                        <aynn@weedmail.com>
> f3IGTCe27668    13212 Wed Apr 18 18:29 MAILER-DAEMON
>                  (host map: lookup (Advisor.net): deferred)
>                                        <Financial@Advisor.net>
> f3IEHdD14321    20811 Wed Apr 18 16:17 <newsletter@shortnews.de>
>                  (I/O error)
>                                        <micka@nexgo.de>
> f3ID37T00078*    1379 Wed Apr 18 15:03 <s.neuthor@radio.hundert6.de>
>                  (Deferred: Connection reset by mail.snafu.de.)
>                                        <neuthor@diemediafabrik.de>
> f3IBQ5v00150   220116 Wed Apr 18 13:26 <d.mitzlaff@hundert6.de>
>       8BITMIME   (I/O error)
>
> <charlotte.bussy@dresdner-bank.com>
> f3I8B1J07959     1067 Wed Apr 18 10:11 <J.Zang@radio.hundert6.de>
>                  (<enquiries@seeglasgow.com>... reply: read error from
> velma.s)
>                                        <enquiries@seeglasgow.com>
> f3I710800841   645910 Wed Apr 18 09:01 <sfranzen@radio.hundert6.de>
>                  (I/O error)
>                                        <silke.franzen@epost.de>
> f3HFXeP15290     1067 Tue Apr 17 17:33 <J.Zang@radio.hundert6.de>
>                  (Deferred: Connection reset by velma.seeglasgow.com.)
>                                        <enquiries@seeglasgow.com>
> f3HD6Zu11150     1305 Tue Apr 17 15:06 <messtechnik@hundert6.de>
>       8BITMIME   (<frank.scholz@bundestag.de>... reply: read error from
> mail.b)
>                                        <frank.scholz@bundestag.de>
> f3HCnZS29113*    1528 Tue Apr 17 14:49 <jan@hundert6.de>
>                  (<tom.fun@bigfoot.de>... reply: read error from
> mail.bigfoot.)
>                                        <tom.fun@bigfoot.de>
> f3HBlYb06640      721 Tue Apr 17 13:47 <M.Steuer@hundert6.de>
>                  (Deferred: 451 Timeout)
>                                        <marius_zekri@yahoo.de>
> f3H9ssR29880     1410 Tue Apr 17 11:54 <S.Skala@radio.hundert6.de>
>                  (<cynthiapaerschke@yahoo.de>... reply: read error from
> mx2.ma)
>                                        <cynthiapaerschke@yahoo.de>
> f3H8tNt02532   218604 Tue Apr 17 10:55 <d.mitzlaff@hundert6.de>
>       8BITMIME   (I/O error)
>
> <charlotte.bussy@dresdner-bank.com>
> f3H7bL902824      720 Tue Apr 17 09:37 <M.Steuer@hundert6.de>
>                  (Deferred: Connection timed out with
> mx2.mail.yahoo.com.)
>                                        <marius_zekri@yahoo.de>
> f3H6roa11291   642351 Tue Apr 17 08:53 <sfranzen@radio.hundert6.de>
>                  (I/O error)
>                                        <silke.franzen@epost.de>
> f3H6toA12584   642555 Tue Apr 17 08:55 <sfranzen@radio.hundert6.de>
>                  (I/O error)
>                                        <steuerberater-koebe@snafu.de>
> f3G8Ur316379      977 Mon Apr 16 10:30 <A.Schwaff@radio.hundert6.de>
>       8BITMIME   (Deferred: Connection timed out with
> mx2.mail.yahoo.com.)
>                                        <otterfieb@yahoo.de>
> f3FJo4x17545*  900736 Sun Apr 15 21:50 <>
>                  (I/O error)
>                                        <micka@nexgo.de>
>
> --
> Radio HUNDERT,6 Medien GmbH Berlin
> - EDV -
> j.muenther@radio.hundert6.de
>


From owner-fwtk-users@ex.tis.com Fri Apr 20 10:22 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10176
	Fri, 20 Apr 2001 10:22:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA19911;
	Fri, 20 Apr 2001 07:26:25 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 06:51:45 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA14656
	for fwtk-users-outgoing; Fri, 20 Apr 2001 06:51:28 -0700 (PDT)
Date: Fri, 20 Apr 2001 09:49:17 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Joseph S D Yao <jsdy@cospo.osis.gov>
cc: Tony Gale <gale@dera.gov.uk>, <ark@eltex.ru>, <fwtk-users@ex.tis.com>
Subject: Re: New version, when ?
In-Reply-To: <20010420085517.F24143@washington.cospo.osis.gov>
Message-ID: <Pine.GSO.4.31.0104200948180.19972-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1537

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Likewise - mine version also added much comments.  I'm not ready to
throw smap out in the bath water.  I find it quite stable and performing a
very good job here.

Just my two cents.

tek


On Fri, 20 Apr 2001, Joseph S D Yao wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> On Thu, Apr 19, 2001 at 11:56:33AM +0100, Tony Gale wrote:
> ...
> > Here's my favourite comment from the FWTK code:
> >
> >         the object of this program is to allow us to present an SMTP service
> >         for people to talk to, which is unprivileged, and runs in a chrooted
> >         directory. a secondary requirement is that the code be as simple as
> >         possible, to permit manual review. this code, therefore, contains
> >         no comments other than this one - comments being an indication that
> >         code is too complex to be trusted.
> >
> >         ....
> >
> >         mjr. 1993
> >
> > Makes me laugh everytime I read it.
> ...
>
> ;-)
>
> Marcus is no stranger to hubris.  ;-)
>
> In contrast, see my patches to 'smap'.  I contributed more comment than
> code!
>
> --
> Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
> COSPO/OSIS Computer Support					EMT-B
> -----------------------------------------------------------------------
> This message is not an official statement of COSPO policies.
>


From owner-fwtk-users@ex.tis.com Fri Apr 20 10:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10185
	Fri, 20 Apr 2001 10:32:04 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21454;
	Fri, 20 Apr 2001 07:35:59 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:02:02 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA03216
	for fwtk-users-outgoing; Thu, 19 Apr 2001 04:09:37 -0700 (PDT)
From: jan@radio.hundert6.de
Message-ID: <XFMail.010419130842.jan@radio.hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE363@A8MC.PSNS.NAVY.MIL>
Date: Thu, 19 Apr 2001 13:08:42 -0000 (GMT)
To: fwtk-users@ex.tis.com
Subject: RE: Port
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 727

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>   What file do I need to modify to open all my port or allow traffic
> though,
> and what do I need to say in the file to allow port 1 though 65535 to
> be
> open?

You can't. The thing with application level gateways such as the fwtk
is they don't forward packets at the transport layer, i.e. on the IP
layer itself. An fwtk host is not a router, thus you can't just heave
arbitrary packets to certain ports to the other interface. You might
take a look at plug-gw for allowing certain additional services. 

Bye, Jan

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 10:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10189
	Fri, 20 Apr 2001 10:32:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21462;
	Fri, 20 Apr 2001 07:36:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:02:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA01205
	for fwtk-users-outgoing; Thu, 19 Apr 2001 02:57:26 -0700 (PDT)
From: ark@eltex.ru
Date: Thu, 19 Apr 2001 14:13:46 +0400
Message-Id: <200104191013.OAA25810@paranoid.eltex.spb.ru>
In-Reply-To: <3ADD7B3D.B2E53C8F@peaktime.be> from "Michel Bardiaux <mbardiaux@peaktime.be>"
Organization: "Klingon Imperial Intelligence Service"
Subject: Re: New version, when ?
To: mbardiaux@peaktime.be
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text
Content-Length: 1116

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

I am not sure it is bad thing.

Michel Bardiaux <mbardiaux@peaktime.be> said :
 
> ark@eltex.ru wrote:
> 
> > > That is if you want something GPL.
> > 
> > I'd say i want something BSD. GPL is too restrictive ;)
> > 
> Please consider LGPL. BSD has the (to me) extremely irritating feature
> that it allows proprietary, closed, *incompatible* derivatives.

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOt66WaH/mIJW9LeBAQHu5QP/Wk55MmmMK77kvRYoNaNIKWs04pdVAIuj
c4BR6tXurlZWbzEhQ2cmsCj7+kmo6uzq1yPFoei3i70UiRIsfNapq1wiMJtLydar
Qp6wOmIIscMtqPGF5OLLkU9lPrCc13OBzNpiaiZF+2cDdg6mwPYVE2/jmLCJol/l
+D7kJ0XjSqs=
=KtJq
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Fri Apr 20 10:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10193
	Fri, 20 Apr 2001 10:32:19 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21504;
	Fri, 20 Apr 2001 07:36:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:02:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA25563
	for fwtk-users-outgoing; Wed, 18 Apr 2001 23:39:04 -0700 (PDT)
Date: Thu, 19 Apr 2001 10:37:15 +0400 (MSD)
From: Antuan Avdioukhine <antuan@internetmedia.ru>
X-Sender: antuan@tyger.hq.internetmedia.ru
To: Tony Gale <gale@dera.gov.uk>
cc: ark@eltex.ru, Darren Reed <darrenr@reed.wattle.id.au>,
        fwtk-users@ex.tis.com
Subject: RE: New version, when ?
In-Reply-To: <NDBBLKIFCKDHHCOAGHFDCEADCAAA.gale@dera.gov.uk>
Message-ID: <Pine.BSF.4.21.0104191026590.47001-100000@tyger.hq.internetmedia.ru>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1125

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Wed, 18 Apr 2001, Tony Gale wrote:

> The trouble is the model is simply wrong for anything approaching high
> request rates.
	Tony, what is -- high request rate? And why firewall have to be an
perfomance giant? 

> I should, at this point, declare that I have been developing a replacement
> for the http-gw for a while. It's not feature complete yet, and a couple of
> areas need work, but it's getting there.
	Have you tried squid-gw by Mattes (em-gw tools)? It seems to be
smart enough and introduces good perfomance.

> The FWTK design uses a fork()-per-request model, which has the advantage of
> simplicity and being very forgiving of coding errors, but suffers some
> serious performance issues.
	Simplicity is the only requirement for programming of security
tools. Trying to build smart monster with fantastical perfomance you may
produce something like M$ ISA. Is it good idea?

--
Antuan Avdioukhine (DEKA-RIPN)
InternetMedia Holding Ltd.
St.Petersburg, Russia. +7 (812) 320 8585


From owner-fwtk-users@ex.tis.com Fri Apr 20 10:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10196
	Fri, 20 Apr 2001 10:32:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21552;
	Fri, 20 Apr 2001 07:36:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:02:06 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id GAA13072
	for fwtk-users-outgoing; Thu, 19 Apr 2001 06:55:43 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010419105524.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <79C524BDBB22D411915800A0C96F68FB9FE363@A8MC.PSNS.NAVY.MIL>
Date: Thu, 19 Apr 2001 10:55:24 -0000 (GMT)
To: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
Subject: RE: Port
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 727

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

>   What file do I need to modify to open all my port or allow traffic
> though,
> and what do I need to say in the file to allow port 1 though 65535 to
> be
> open?

You can't. The thing with application level gateways such as the fwtk
is they don't forward packets at the transport layer, i.e. on the IP
layer itself. An fwtk host is not a router, thus you can't just heave
arbitrary packets to certain ports to the other interface. You might
take a look at plug-gw for allowing certain additional services. 

Bye, Jan

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 10:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10199
	Fri, 20 Apr 2001 10:32:42 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21565;
	Fri, 20 Apr 2001 07:36:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:02:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA26891
	for fwtk-users-outgoing; Thu, 19 Apr 2001 09:59:07 -0700 (PDT)
Message-ID: <79C524BDBB22D411915800A0C96F68FB9FE366@A8MC.PSNS.NAVY.MIL>
From: Fritsch Jonathan D CONT PSNS <fritschj@PSNS.navy.mil>
To: "'jan@radio.hundert6.de'" <jan@radio.hundert6.de>
Cc: fwtk-users@ex.tis.com
Subject: RE: Port
Date: Thu, 19 Apr 2001 09:57:03 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
X-N-Score: scored -400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1080

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Does anyone know what kind of plug-gw I might use?

-----Original Message-----
From: jan@radio.hundert6.de [mailto:jan@radio.hundert6.de]
Sent: Thursday, April 19, 2001 6:09 AM
To: fwtk-users@ex.tis.com
Subject: RE: Port


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

>   What file do I need to modify to open all my port or allow traffic
> though,
> and what do I need to say in the file to allow port 1 though 65535 to
> be
> open?

You can't. The thing with application level gateways such as the fwtk
is they don't forward packets at the transport layer, i.e. on the IP
layer itself. An fwtk host is not a router, thus you can't just heave
arbitrary packets to certain ports to the other interface. You might
take a look at plug-gw for allowing certain additional services. 

Bye, Jan

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de


From owner-fwtk-users@ex.tis.com Fri Apr 20 10:34 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10204
	Fri, 20 Apr 2001 10:34:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA21931;
	Fri, 20 Apr 2001 07:38:03 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:03:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA16402
	for fwtk-users-outgoing; Thu, 19 Apr 2001 07:38:54 -0700 (PDT)
From: "Tony Gale" <gale@dera.gov.uk>
To: <ark@eltex.ru>
Cc: <fwtk-users@ex.tis.com>
Subject: RE: New version, when ?
Date: Thu, 19 Apr 2001 11:56:33 +0100
Message-ID: <NDBBLKIFCKDHHCOAGHFDAEAECAAA.gale@dera.gov.uk>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
In-Reply-To: <200104181139.PAA21091@paranoid.eltex.spb.ru>
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
Importance: Normal
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 4065

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


I have looked at squid-gw, but not in any great depth. A fork() vs
multithread model does not necessarily map to simplicity vs complexity, and
neither map directly to any level of security. The http-gw is fork()ed and
simple, but it isn't exactly well written or bug free. Look at the 'net
flags' issue as an example.

Here's my favourite comment from the FWTK code:

        the object of this program is to allow us to present an SMTP service
        for people to talk to, which is unprivileged, and runs in a chrooted
        directory. a secondary requirement is that the code be as simple as
        possible, to permit manual review. this code, therefore, contains
        no comments other than this one - comments being an indication that
        code is too complex to be trusted.

        ....

        mjr. 1993

Makes me laugh everytime I read it.

Anyway, back to the point. Yes my code it GPL'ed, but I haven't released it
yet as there is one more feature I need to add before I do so. I works fine
in it's current state, but I don't want to prejudice it by releasing before
I've re-implemented the resolver, which is currently using a pre-forked
process pool as a temporary measure.

-tony

-----Original Message-----
From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
Behalf Of ark@eltex.ru
Sent: 18 April 2001 12:40
To: gale@dera.gov.uk
Cc: fwtk-users@ex.tis.com
Subject: RE: New version, when ?


[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

Can't call it `simply wrong'. Not the best, but acceptable.

Have you seen squid-gw? It hadles pretty high load well. Acutally in-depth
content analysis gives more overhead than fork()s so there is (almost) no
reason
to implement sophisticated pre-forked or multithreaded model. Code
simplicity and
readabilty are more important for security applications than performance
hacks.

Your proxy may be useful too in some environments, though. Is it public
code?

"Tony Gale" <gale@dera.gov.uk> said :

> The trouble is the model is simply wrong for anything approaching high
> request rates.
>
> I should, at this point, declare that I have been developing a replacement
> for the http-gw for a while. It's not feature complete yet, and a couple
of
> areas need work, but it's getting there.
>
> The FWTK design uses a fork()-per-request model, which has the advantage
of
> simplicity and being very forgiving of coding errors, but suffers some
> serious performance issues.
>
> The http-gw content checking is a performance killer, and offers very
little
> in return, as it's easy to bypass.
>
> -tony
>
> -----Original Message-----
> From: owner-fwtk-users@ex.tis.com [mailto:owner-fwtk-users@ex.tis.com]On
> Behalf Of ark@eltex.ru
> Sent: 17 April 2001 22:20
> To: Darren Reed
> Cc: Antuan Avdioukhine; ark@eltex.ru; fwtk-users@ex.tis.com
> Subject: Re: New version, when ?
>
>
> [To be removed from this list send the message "unsubscribe fwtk-users" in
> the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> nuqneH,
>
> What's wrong with fwtk api and ideology? I always loved it..
> Though it needs some work, i know.
>
> >
> >
> > bah, someone should just develop a *NEW* set of proxy tools and scrap
> these
> > ancient ones.



                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBOt19CqH/mIJW9LeBAQGvlQQAo336uwwks/Zi0kSagL7xXmCvOBz8FdJP
GiKLmI0f/eMP/hKg2p9d4EsN60hhB/RKYOyS3HK2rhnLQzj5zWwr44wm808dhAua
ErVVRNmnOolxjYfNOzCuZiI1f5X+Gtcnrth5PulGyS4LmYt62DOntMLtHvh1BZuv
3LF2WPWQiHM=
=CzxJ
-----END PGP SIGNATURE-----

From owner-fwtk-users@ex.tis.com Fri Apr 20 10:34 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10209
	Fri, 20 Apr 2001 10:34:38 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA22038;
	Fri, 20 Apr 2001 07:38:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:04:04 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA29932
	for fwtk-users-outgoing; Thu, 19 Apr 2001 10:34:21 -0700 (PDT)
From: jan@radio.hundert6.de
Message-ID: <XFMail.010419193300.jan@radio.hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
Date: Thu, 19 Apr 2001 19:33:00 -0000 (GMT)
To: fwtk-users@ex.tis.com
Subject: queue filling up... I/O errors
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 6939

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello everybody,

I am encountering pretty heavy problems with smap / smapd /sendmail.
While my config generally works flawlessly, messages to a couple of
hosts seem to time out during data transfer. I can easily reach the
relevant mail exchangers and since it's clearly not a length-based
problem, I don't think my ip-filter config is the culprit. If this were
the case, it should work during the next re-send, which it doesn't. 

A lot of these mails go out to yahoo and from the list archive I could
there have already been problems reported with them. Unfortunately it's
not yahoo exclusively, neither can I lock it down to one certain MTA
smap doesn't like talking to. 

Mysteriously, some mails are being sent without any problems while
others land in the queue because of I/O errors or timeouts or
connection resets. This seems to happen especially with forwarded
messages, but then again, not exclusively. 

I am totally clueless. 

>From the sendmail homepage I could tell there were certain
incompatibilities reported - I couldn't find any specific for OpenBSD
2.8 and the sendmail version that comes shipped with it (is there a
simple way to find out which version it is?). 

Is this maybe a platform-related problem? Anyone else using OpenBSD
2.8??

I'll attach my queue output to illustrate the issue. Maybe some of you
have problem with certain of the listed hosts as well. 

This is really giving me a bad headache, so I'm very grateful for every
helpful hint. FWTK version's 2.1, of course, smap has the Yao-patch
applied. 

Cheers, Jan

                /var/spool/mqueue (28 requests)
----Q-ID---- --Size-- -----Q-Time-----
------------Sender/Recipient------------
f3JEIu417172*   20484 Thu Apr 19 16:18 <newsletter@shortnews.de>
                 (I/O error)
                                       <micka@nexgo.de>
f3JEluw31730   104950 Thu Apr 19 16:47 <S.vBramann@radio.hundert6.de>
                 (I/O error)
                                       <micka@nexgo.de>
f3JD1OA03796   100026 Thu Apr 19 15:01 <KreuzerS@fleishman.com>
                 (Warning: could not send message for past 4 hours)
                                       <patzak@snafu.de>
f3JBdqj18237*    1634 Thu Apr 19 13:39 <sfranzen@radio.hundert6.de>
                 (<b.schneider@atkon.de>... reply: read error from
mail.atkon.)
                                       <b.schneider@atkon.de>
f3JBSMJ13484     1361 Thu Apr 19 13:28 <M.Steuer@hundert6.de>
                 (Deferred: 451 Timeout)
                                       <melha5@yahoo.de>
f3JBZqe31960     1387 Thu Apr 19 13:35 <s.neuthor@radio.hundert6.de>
                 (I/O error: Input/output error)
                                       <neuthor@diemediafabrik.de>
f3J7JWx06867      700 Thu Apr 19 09:19 <sfranzen@radio.hundert6.de>
                 (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <b.schneider@atkon.de>
f3J7obb25545    14271 Thu Apr 19 09:50 MAILER-DAEMON
      8BITMIME   (Deferred: Connection refused by gs3.serverdienst.de.)
                                       <www6@gs3.serverdienst.de>
f3J701129967     1359 Thu Apr 19 09:00 <M.Steuer@hundert6.de>
                 (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <melha5@yahoo.de>
f3J6sVa30689     1385 Thu Apr 19 08:54 <s.neuthor@radio.hundert6.de>
                 (I/O error: Input/output error)
                                       <neuthor@diemediafabrik.de>
f3J23Qx08220    17448 Thu Apr 19 04:03 MAILER-DAEMON
                 (I/O error)
                                       <aynn@weedmail.com>
f3IGTCe27668    13212 Wed Apr 18 18:29 MAILER-DAEMON
                 (host map: lookup (Advisor.net): deferred)
                                       <Financial@Advisor.net>
f3IEHdD14321    20811 Wed Apr 18 16:17 <newsletter@shortnews.de>
                 (I/O error)
                                       <micka@nexgo.de>
f3ID37T00078*    1379 Wed Apr 18 15:03 <s.neuthor@radio.hundert6.de>
                 (Deferred: Connection reset by mail.snafu.de.)
                                       <neuthor@diemediafabrik.de>
f3IBQ5v00150   220116 Wed Apr 18 13:26 <d.mitzlaff@hundert6.de>
      8BITMIME   (I/O error)
                                      
<charlotte.bussy@dresdner-bank.com>
f3I8B1J07959     1067 Wed Apr 18 10:11 <J.Zang@radio.hundert6.de>
                 (<enquiries@seeglasgow.com>... reply: read error from
velma.s)
                                       <enquiries@seeglasgow.com>
f3I710800841   645910 Wed Apr 18 09:01 <sfranzen@radio.hundert6.de>
                 (I/O error)
                                       <silke.franzen@epost.de>
f3HFXeP15290     1067 Tue Apr 17 17:33 <J.Zang@radio.hundert6.de>
                 (Deferred: Connection reset by velma.seeglasgow.com.)
                                       <enquiries@seeglasgow.com>
f3HD6Zu11150     1305 Tue Apr 17 15:06 <messtechnik@hundert6.de>
      8BITMIME   (<frank.scholz@bundestag.de>... reply: read error from
mail.b)
                                       <frank.scholz@bundestag.de>
f3HCnZS29113*    1528 Tue Apr 17 14:49 <jan@hundert6.de>
                 (<tom.fun@bigfoot.de>... reply: read error from
mail.bigfoot.)
                                       <tom.fun@bigfoot.de>
f3HBlYb06640      721 Tue Apr 17 13:47 <M.Steuer@hundert6.de>
                 (Deferred: 451 Timeout)
                                       <marius_zekri@yahoo.de>
f3H9ssR29880     1410 Tue Apr 17 11:54 <S.Skala@radio.hundert6.de>
                 (<cynthiapaerschke@yahoo.de>... reply: read error from
mx2.ma)
                                       <cynthiapaerschke@yahoo.de>
f3H8tNt02532   218604 Tue Apr 17 10:55 <d.mitzlaff@hundert6.de>
      8BITMIME   (I/O error)
                                      
<charlotte.bussy@dresdner-bank.com>
f3H7bL902824      720 Tue Apr 17 09:37 <M.Steuer@hundert6.de>
                 (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <marius_zekri@yahoo.de>
f3H6roa11291   642351 Tue Apr 17 08:53 <sfranzen@radio.hundert6.de>
                 (I/O error)
                                       <silke.franzen@epost.de>
f3H6toA12584   642555 Tue Apr 17 08:55 <sfranzen@radio.hundert6.de>
                 (I/O error)
                                       <steuerberater-koebe@snafu.de>
f3G8Ur316379      977 Mon Apr 16 10:30 <A.Schwaff@radio.hundert6.de>
      8BITMIME   (Deferred: Connection timed out with
mx2.mail.yahoo.com.)
                                       <otterfieb@yahoo.de>
f3FJo4x17545*  900736 Sun Apr 15 21:50 <>
                 (I/O error)
                                       <micka@nexgo.de>

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 10:47 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA10228
	Fri, 20 Apr 2001 10:47:55 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA24819;
	Fri, 20 Apr 2001 07:51:51 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 07:17:08 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA18090
	for fwtk-users-outgoing; Fri, 20 Apr 2001 07:16:49 -0700 (PDT)
From: jan@radio.hundert6.de
Message-ID: <XFMail.010420161547.jan@radio.hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <sae05e9e.037@mail.deggendorf.de>
Date: Fri, 20 Apr 2001 16:15:47 -0000 (GMT)
To: fwtk-users@ex.tis.com
Subject: RE: Antw:queue filling up... I/O errors (Abwesend)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 255

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

If I get one more notice of absence I get a fit.

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 11:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA10374
	Fri, 20 Apr 2001 11:32:02 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA00417;
	Fri, 20 Apr 2001 08:36:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 08:01:34 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA26566
	for fwtk-users-outgoing; Fri, 20 Apr 2001 08:01:17 -0700 (PDT)
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <3ADEFAC7.4241F216@peaktime.be>
Date: Thu, 19 Apr 2001 16:48:39 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: ark@eltex.ru
CC: fwtk-users@ex.tis.com
Subject: Re: New version, when ?
References: <200104191013.OAA25810@paranoid.eltex.spb.ru>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1969

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

ark@eltex.ru wrote:
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> 
> nuqneH,
> 
> I am not sure it is bad thing.
> 
> Michel Bardiaux <mbardiaux@peaktime.be> said :
> 
> > ark@eltex.ru wrote:
> >
> > > > That is if you want something GPL.
> > >
> > > I'd say i want something BSD. GPL is too restrictive ;)
> > >
> > Please consider LGPL. BSD has the (to me) extremely irritating feature
> > that it allows proprietary, closed, *incompatible* derivatives.
> 

IMNSHO I am *quite* sure it is. I was burned several times:

(1) I had been using the SGI release of the JPEG library; it had a
memory leak; I submitted bug reports, my own patches, test harnesses, no
cigar: after 2 years and one major OS release it was still not fixed
(not even acknowledged!). Then I switched to the source of the public
JPEG library.

(2) SGI (and others) have been shipping Motif1.2 only for *years* after
2.1 was released by OSF. But since the SGI X and Motif libraries had
proprietary stuff in them, it was impossible to use anything else on
their systems. Particularly, installation of Lesstif (the LGPL
implementation of the OSF Motif specs) was impossible because it was
impossible to make it binary-compatible with SGI stuff.

I really don't care about software "free as free beer", and I don't
share the Stallman/Raymond ideology on free software (to me, a cathedral
is a thing of beauty, and a bazaar is a stinking mess). I want *source*
because it is the *only* effective way to guarantee that support for
critical pieces of software can be done in-house if the supplier screws
up his job. Hence, GPL or LGPL, but not BSD. And GPL is not really good
either because it tends to exclude cooperation from corporations.

Kaplah :-)
-- 
Michel Bardiaux
Peaktime Belgium S.A.  Rue Margot, 37  B-1457 Nil St Vincent
Tel : +32 10 65.44.15  Fax : +32 10 65.44.10

From owner-fwtk-users@ex.tis.com Fri Apr 20 11:32 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA10378
	Fri, 20 Apr 2001 11:32:26 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA00443;
	Fri, 20 Apr 2001 08:36:24 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 08:02:38 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA26805
	for fwtk-users-outgoing; Fri, 20 Apr 2001 08:02:21 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010420160811.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <Pine.GSO.4.31.0104200944190.19972-100000@ns4.bfg.com>
Date: Fri, 20 Apr 2001 16:08:11 -0000 (GMT)
To: Ted Keller <keller@bfg.com>
Subject: Re: queue filling up... I/O errors
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 1900

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> Note - this is not a smap/smapd issue.  Sendmail is the MTA that
> attempts
> do to the delivery.  Focus your research in the sendmail area.

Already did, I just wanted to reassure. 
 
> You may want to start by doing a survey on the remote system -
> determing
> what their standard mailer is (telnet remotehost 25 usually does the
> trick).

I know, I know, and I already did. Unfortunately, the MTA were largely
different. I remember qmail and exim, but there were also others which
I hadn't heard of before (some NT stuff, I assume). So it can't really
be an incompatibility issue with one certain MTA...

> Next - determine if you ever deliver mail to them - Is this a hard
> problem - or one of those hardtosovle it sometimes works type of
> problem.

That's exactly it. If only it were I couldn't ever deliver mail to them!
Oddly enough, I thought it might some kind of encoding issue, since a
few mails from Windows users bounced... I then sent a message from my
XFmail to one of the attempted adresses and had it delivered
flawlessly. Then again, I tried to forward a message to the same adress
and I got an I/O error. 

It's all mixed up - plain text, HTML (ouch),
7bit clean, 8bit MIME, I can't really make out any common remarks of
the bounced messages. 
 
> Pick one - contact them and see if they can shed any light (oh! my
> disk
> filled up).

I already did - Deutscher Bundestag, the german House of Parliament,
that is. The guy I talked to told me I was the only one reporting
problems and that it might be a firewall issue, but the firewall
adminstrator was not present at the time. Argh. 

I might move on in the queue, just like sendmail would :-%

Thanks, however. 

Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 11:47 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA10499
	Fri, 20 Apr 2001 11:47:44 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA02221;
	Fri, 20 Apr 2001 08:51:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 08:18:03 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA28930
	for fwtk-users-outgoing; Fri, 20 Apr 2001 08:17:45 -0700 (PDT)
Date: Fri, 20 Apr 2001 11:15:27 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: <jan@hundert6.de>
cc: <fwtk-users@ex.tis.com>
Subject: Re: queue filling up... I/O errors
In-Reply-To: <XFMail.010420162128.jan@hundert6.de>
Message-ID: <Pine.GSO.4.31.0104201107130.13829-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1607

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Well I have another theory - just a theory here.....

I went and looked in my sendmail queues. I also have a few messages that
list I/O errors for their non delivery stats.  But - I noted one from my
firewall to my internal mailhub with an I/O error.  In looking at the
internal mail hub - I didn't see any logs for this message - the firewall
listed the status as an I/O error.  Hmmmm.  These systems are on the same
local net - they sit side by side.  The wire is clean.

So here's the theory.

I run the Trend Micro Virus scanner on the internal system.  It accepts
the inbound connections - not sendmail. My suscpisions are that if it gets
busy - it may partially accept the connection - then drop it - leaving the
sending mta in an errored conndition. The sendind MTA then queues it for
later transmission.

I need to look further here to see if this holds any water at all...

Any other thoughts?

tek


On Fri, 20 Apr 2001 jan@hundert6.de wrote:

>
> > Note - this is not a smap/smapd issue.  Sendmail is the MTA that
> > attempts
> > do to the delivery.  Focus your research in the sendmail area.
>
> Still, I wasn't 100% sure. As I do have split DNS with two MXers, smap
> accepts the mail from the internal mailhost first, so I was concerned
> that smap might have done something nasty (tm) to the messages ;o))
>
> It'S pretty clear this was probably not the case.
>
> Cheers, Jan
> --
> Radio HUNDERT,6 Medien GmbH Berlin
> - EDV -
> j.muenther@radio.hundert6.de
>


From owner-fwtk-users@ex.tis.com Fri Apr 20 12:06 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA10520
	Fri, 20 Apr 2001 12:06:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA03541;
	Fri, 20 Apr 2001 09:10:44 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 08:37:10 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA00470
	for fwtk-users-outgoing; Fri, 20 Apr 2001 08:36:53 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010420162128.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <Pine.GSO.4.31.0104200944190.19972-100000@ns4.bfg.com>
Date: Fri, 20 Apr 2001 16:21:28 -0000 (GMT)
To: Ted Keller <keller@bfg.com>
Subject: Re: queue filling up... I/O errors
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 625

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


> Note - this is not a smap/smapd issue.  Sendmail is the MTA that
> attempts
> do to the delivery.  Focus your research in the sendmail area.

Still, I wasn't 100% sure. As I do have split DNS with two MXers, smap
accepts the mail from the internal mailhost first, so I was concerned
that smap might have done something nasty (tm) to the messages ;o)) 

It'S pretty clear this was probably not the case. 

Cheers, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 13:04 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA10718
	Fri, 20 Apr 2001 13:04:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA05401;
	Fri, 20 Apr 2001 10:08:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 09:34:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA00470
	for fwtk-users-outgoing; Fri, 20 Apr 2001 08:36:53 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010420162128.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <Pine.GSO.4.31.0104200944190.19972-100000@ns4.bfg.com>
Date: Fri, 20 Apr 2001 16:21:28 -0000 (GMT)
To: Ted Keller <keller@bfg.com>
Subject: Re: queue filling up... I/O errors
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 625

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


> Note - this is not a smap/smapd issue.  Sendmail is the MTA that
> attempts
> do to the delivery.  Focus your research in the sendmail area.

Still, I wasn't 100% sure. As I do have split DNS with two MXers, smap
accepts the mail from the internal mailhost first, so I was concerned
that smap might have done something nasty (tm) to the messages ;o)) 

It'S pretty clear this was probably not the case. 

Cheers, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Fri Apr 20 16:39 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA11147
	Fri, 20 Apr 2001 16:39:39 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA01409;
	Fri, 20 Apr 2001 13:38:09 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 13:04:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA00329
	for fwtk-users-outgoing; Fri, 20 Apr 2001 13:04:21 -0700 (PDT)
Date: Fri, 20 Apr 2001 16:03:33 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: jan@radio.hundert6.de
Cc: fwtk-users@ex.tis.com
Subject: Re: Antw:queue filling up... I/O errors (Abwesend)
Message-Id: <20010420160333.B28436@washington.cospo.osis.gov>
Mail-Followup-To: jan@radio.hundert6.de, fwtk-users@ex.tis.com
References: <sae05e9e.037@mail.deggendorf.de> <XFMail.010420161547.jan@radio.hundert6.de>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <XFMail.010420161547.jan@radio.hundert6.de>; from jan@radio.hundert6.de on Fri, Apr 20, 2001 at 04:15:47PM -0000
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 588

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, Apr 20, 2001 at 04:15:47PM -0000, jan@radio.hundert6.de wrote:
...
> If I get one more notice of absence I get a fit.

Just submit the name of the offender(s) to our beloved
mailinglistmeisters to get the names removed.  ;-)

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Fri Apr 20 16:47 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA11165
	Fri, 20 Apr 2001 16:47:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id NAA01658;
	Fri, 20 Apr 2001 13:45:38 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 13:13:12 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA07639
	for fwtk-users-outgoing; Fri, 20 Apr 2001 11:41:11 -0700 (PDT)
Message-Id: <5.1.0.14.0.20010420143559.01f56c60@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Fri, 20 Apr 2001 14:38:36 -0400
To: jan@radio.hundert6.de, fwtk-users@ex.tis.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: queue filling up... I/O errors
In-Reply-To: <XFMail.010419193300.jan@radio.hundert6.de>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1011

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:33 PM 4/19/01 +0000, jan@radio.hundert6.de wrote:
>f3JEIu417172*   20484 Thu Apr 19 16:18 <newsletter@shortnews.de>
>                  (I/O error)
>                                        <micka@nexgo.de>
>f3JEluw31730   104950 Thu Apr 19 16:47 <S.vBramann@radio.hundert6.de>
>                  (I/O error)

As someone has already pointed out, these are sendmail problems, not FWTK.
But.. it's possibly related to your firewall. Do you have anything 
listening on the IDENT port? Some hosts will perform an unceremonious 
disconnect when they either can't resolve your IP to a hostname or if they 
can't connect to your IDENT port. Sometimes that error won't occur until 
after you say HELO, so you really have to go through the entire SMTP 
exchange to tell.

Running the sendmail queue in verbose mode (sendmail -v -q) can sometimes 
provide hints, as well.
         -Rick


From owner-fwtk-users@ex.tis.com Fri Apr 20 19:16 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA11363
	Fri, 20 Apr 2001 19:16:33 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA04088;
	Fri, 20 Apr 2001 16:15:04 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 20 Apr 2001 15:40:05 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA03335
	for fwtk-users-outgoing; Fri, 20 Apr 2001 15:39:49 -0700 (PDT)
Message-ID: <3AE0BA89.5CD907A7@ipass.net>
Date: Fri, 20 Apr 2001 18:39:05 -0400
From: Brion Leary <bleary@ipass.net>
Reply-To: bleary@ipass.net
X-Mailer: Mozilla 4.76 [en]C-CCK-MCD {United Systems Access}  (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Ted Keller <keller@bfg.com>
CC: jan@hundert6.de, fwtk-users@ex.tis.com
Subject: Re: queue filling up... I/O errors
References: <Pine.GSO.4.31.0104201107130.13829-100000@ns4.bfg.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 2254

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

I think you're getting closer.  I made mods to smap to
limit the number of children,  After accept, but before
fork, it checks number of running children, if too
many it sleeps until one dies.  Looking through my logs
I believe that if the wait for a free child slot is too
long the connection with the sender is dropped - times
out.  My guess is the sending MTA would report this as
an I/O error.

- Brion


Ted Keller wrote:
> 
> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
> 
> Well I have another theory - just a theory here.....
> 
> I went and looked in my sendmail queues. I also have a few messages that
> list I/O errors for their non delivery stats.  But - I noted one from my
> firewall to my internal mailhub with an I/O error.  In looking at the
> internal mail hub - I didn't see any logs for this message - the firewall
> listed the status as an I/O error.  Hmmmm.  These systems are on the same
> local net - they sit side by side.  The wire is clean.
> 
> So here's the theory.
> 
> I run the Trend Micro Virus scanner on the internal system.  It accepts
> the inbound connections - not sendmail. My suscpisions are that if it gets
> busy - it may partially accept the connection - then drop it - leaving the
> sending mta in an errored conndition. The sendind MTA then queues it for
> later transmission.
> 
> I need to look further here to see if this holds any water at all...
> 
> Any other thoughts?
> 
> tek
> 
> On Fri, 20 Apr 2001 jan@hundert6.de wrote:
> 
> >
> > > Note - this is not a smap/smapd issue.  Sendmail is the MTA that
> > > attempts
> > > do to the delivery.  Focus your research in the sendmail area.
> >
> > Still, I wasn't 100% sure. As I do have split DNS with two MXers, smap
> > accepts the mail from the internal mailhost first, so I was concerned
> > that smap might have done something nasty (tm) to the messages ;o))
> >
> > It'S pretty clear this was probably not the case.
> >
> > Cheers, Jan
> > --
> > Radio HUNDERT,6 Medien GmbH Berlin
> > - EDV -
> > j.muenther@radio.hundert6.de
> >

From owner-fwtk-users@ex.tis.com Sun Apr 22 12:03 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA14801
	Sun, 22 Apr 2001 12:03:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA25149;
	Sun, 22 Apr 2001 09:07:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 22 Apr 2001 08:29:54 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA23927
	for fwtk-users-outgoing; Sun, 22 Apr 2001 08:29:38 -0700 (PDT)
Date: Sun, 22 Apr 2001 11:28:57 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Fwtk Users <fwtk-users@lists.nai.com>
Subject: Slight update to smap
Message-ID: <Pine.GSO.4.31.0104221126590.23706-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 400

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

For all of you that use my version of smap/smapd, I've fixed it a bit to
correct an issue in the spam comparison routines.

Two changes are implemented....

I correctly now look for the rubout character.  Before I was
incoorectly Jtaggin on the
? character and that was


From owner-fwtk-users@ex.tis.com Sun Apr 22 12:03 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA14800
	Sun, 22 Apr 2001 12:03:50 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA25145;
	Sun, 22 Apr 2001 09:07:49 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Sun, 22 Apr 2001 08:34:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA24025
	for fwtk-users-outgoing; Sun, 22 Apr 2001 08:34:42 -0700 (PDT)
Date: Sun, 22 Apr 2001 11:33:53 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Fwtk Users <fwtk-users@lists.nai.com>
Subject: Updated smap routine
Message-ID: <Pine.GSO.4.31.0104221129050.23706-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 974

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Sorry for the previous send.... My fingers aren't working yet this
morning.

For all of you who use my version of the smap/smapd routines, I've fixed a
couple of things....

1. smap now correctly identifies the rub-out character.  Before I was
incorrectly tagging on the "?" character - that was messing up some of the
matching routines when looking for a ? in the spam routines.

2. I've also elinated multiple spacing on the input and spam file.
Multiple blank characters on the input message are eliminated and compared
directly with the spam file. Note - scan trough your spamfile and
eliminate multiple blanks there.

This is available at the normal place - again the file is hidden... Pick
it up by name  --  smap.tar.

If you don't remember - or anyone else want's it - drop me a quick line
and I will tell you where it is.

ted keller



From owner-fwtk-users@ex.tis.com Mon Apr 23 05:43 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA16602
	Mon, 23 Apr 2001 05:43:34 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA10576;
	Mon, 23 Apr 2001 02:47:34 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 23 Apr 2001 02:13:43 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA08143
	for fwtk-users-outgoing; Mon, 23 Apr 2001 02:13:27 -0700 (PDT)
Message-ID: <3AE3F1E9.E9FBF3F2@zrz.TU-Berlin.DE>
Date: Mon, 23 Apr 2001 11:12:09 +0200
From: Gerd Schering <Schering@zrz.tu-berlin.de>
Organization: TUB
X-Mailer: Mozilla 4.77 [en] (X11; U; Linux 2.2.14-15mdk i686)
X-Accept-Language: en
MIME-Version: 1.0
To: FWTK Mailing Liste <fwtk-users@ex.tis.com>
Subject: Strange problems - maybe caused by squid-gw?
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg=sha1; boundary="------------ms689540B54BD4927D545D0BB7"
Content-Length: 2803

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This is a cryptographically signed message in MIME format.

--------------ms689540B54BD4927D545D0BB7
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Hi all,

we use the FWTK-2.1 on a redhat 6.2 box. We use squid-gw
on the firewall to forward the http requests to our proxy.
We experience the folloing strange problem:

If squid-gw cannot retrieve the page from the proxy, no login
is possible on the firewall until the request is satisfied
or timed out.
It seems, that only the login process is blocked, because 
everything else seems to work fine.

We are not definitely shure that this problem is due to squid-gw
or maybe caused by something else.
We upgraded already the kernel from 2.2-17 to 2.2-19, but
it did not help.
Did anyone experience similar problems?
Any help would be welcome!

Gerd
------------------------------------------------------
-- Gerd Schering
-- Email: Schering@zrz.TU-Berlin.DE
-- TU Berlin, Zentraleinrichtung Rechenzentrum
-- Sekr. E-N 50, Einsteinufer 17, 10587 Berlin

------------------------------------------------------
--------------ms689540B54BD4927D545D0BB7
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIDvwYJKoZIhvcNAQcCoIIDsDCCA6wCAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAaCC
AiMwggIfMIIBiKADAgECAgIA2zANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJERTESMBAG
A1UEChMJVFUtQmVybGluMQwwCgYDVQQLEwNaUloxFDASBgNVBAMTC1RDIFRVQiAyMDAwMB4X
DTAwMDgyMTExNDcyNVoXDTAyMDIxMjExNDcyNVowcTELMAkGA1UEBhMCREUxEjAQBgNVBAoT
CVRVLUJlcmxpbjEMMAoGA1UECxMDWlJaMRYwFAYDVQQDEw1HZXJkIFNjaGVyaW5nMSgwJgYJ
KoZIhvcNAQkBFhlTY2hlcmluZ0B6cnouVFUtQmVybGluLkRFMFwwDQYJKoZIhvcNAQEBBQAD
SwAwSAJBAMzO07BsdY4ao1jwlxpa3z6t32gF+XfuOORFv5n8cg4vBbjipcmd8xujpYDGY9GY
gZa24RA34B4ZHwKv7Af1XOECAwEAAaM2MDQwEQYJYIZIAYb4QgEBBAQDAgCgMB8GA1UdIwQY
MBaAFAbN8qubZqQJJpbjkE+k2mOXQCqPMA0GCSqGSIb3DQEBBAUAA4GBAFmom4WWG42yDme4
Thl+NXRjM+tCqbmE6L70TkL0IU8D0LaJb2KcfvU1FCK+xZWvHn7q1wSUioAFn2Kg4jD/hPww
40E7WMDT+0RNWDWqd94z6+UCBp453jdqwuq4gw+d6vYC7coCdnoW/6VQw+ZaFQs0RFnObEtM
132MBEUbQ0nyMYIBZDCCAWACAQEwSzBFMQswCQYDVQQGEwJERTESMBAGA1UEChMJVFUtQmVy
bGluMQwwCgYDVQQLEwNaUloxFDASBgNVBAMTC1RDIFRVQiAyMDAwAgIA2zAJBgUrDgMCGgUA
oIGxMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTAxMDQyMzA5
MTIxMFowIwYJKoZIhvcNAQkEMRYEFK6encfRcCYfHkm4cWuQqFCXR+oMMFIGCSqGSIb3DQEJ
DzFFMEMwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMAcGBSsOAwIHMA0GCCqGSIb3DQMC
AgFAMA0GCCqGSIb3DQMCAgEoMA0GCSqGSIb3DQEBAQUABECatmgHtYPdt9P5SMAK1lrjs1ZD
prHiqVMAj/qkQqo+oCCcIU8r7v2WFasgext7gwHVXuSEetGQfN5Wp4IPoK4d
--------------ms689540B54BD4927D545D0BB7--


From owner-fwtk-users@ex.tis.com Mon Apr 23 07:56 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id HAA16987
	Mon, 23 Apr 2001 07:56:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA18447;
	Mon, 23 Apr 2001 05:00:20 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 23 Apr 2001 04:27:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA16424
	for fwtk-users-outgoing; Mon, 23 Apr 2001 04:26:44 -0700 (PDT)
Date: Fri, 20 Apr 2001 11:48:21 -0700 (PDT)
From: Scott Campbell <scampbel@gvpl.ca>
X-X-Sender:  <scampbel@pochta.gvpl.victoria.bc.ca>
To: <jan@hundert6.de>
cc: <fwtk-users@ex.tis.com>
Subject: Re: queue filling up... I/O errors
In-Reply-To: <XFMail.010420162128.jan@hundert6.de>
Message-ID: <Pine.BSF.4.32.0104201141290.78964-100000@pochta.gvpl.victoria.bc.ca>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1356

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Fri, 20 Apr 2001 jan@hundert6.de wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 >
 > > Note - this is not a smap/smapd issue.  Sendmail is the MTA that
 > > attempts
 > > do to the delivery.  Focus your research in the sendmail area.
 >
 > Still, I wasn't 100% sure. As I do have split DNS with two MXers, smap
 > accepts the mail from the internal mailhost first, so I was concerned
 > that smap might have done something nasty (tm) to the messages ;o))
 >
 > It'S pretty clear this was probably not the case.
 >

I was poking around the sendmail.org faq and found they were mentioning to
check your root.cache/named.boot to make sure it is up to date.  If one of
the entries isn't then it could lead to intermitant time-out problems.
Don't know if that would lead to this particular error but it was in the
faq as related -
http://www.sendmail.org/faq/section3.html#3.10
for some other possible leads.

My firewall probably isn't as busy as yours since I haven't seen these
yet.


Scott E. Campbell
_______________________________
Computer Operations
Greater Victoria Public Library
Victoria BC CANADA

scampbel@gvpl.ca




From owner-fwtk-users@ex.tis.com Mon Apr 23 09:14 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA17152
	Mon, 23 Apr 2001 09:14:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA23298;
	Mon, 23 Apr 2001 06:18:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 23 Apr 2001 05:45:20 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA21380
	for fwtk-users-outgoing; Mon, 23 Apr 2001 05:45:03 -0700 (PDT)
Date: Mon, 23 Apr 2001 08:43:31 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Gerd Schering <Schering@zrz.tu-berlin.de>
cc: FWTK Mailing Liste <fwtk-users@ex.tis.com>
Subject: Re: Strange problems - maybe caused by squid-gw?
In-Reply-To: <3AE3F1E9.E9FBF3F2@zrz.TU-Berlin.DE>
Message-ID: <Pine.GSO.4.31.0104230840350.11146-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1613

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Gerd,

I don't use squid-gw, but I have seen instances when using other proxies
of some remote machines not consistently terminating a transactions with
the traing <fin> (EOF) character.  The becomes especailly troubles on some
http 1.1 type servers - where content length is apparently sufficient via
rfc to tell the remote host the transmission is complete.

You may want to "snoop" your comminications line and see if all tcp
sessions are terminated with the trailing <fin>.

tek


On Mon, 23 Apr 2001, Gerd Schering wrote:

> Hi all,
>
> we use the FWTK-2.1 on a redhat 6.2 box. We use squid-gw
> on the firewall to forward the http requests to our proxy.
> We experience the folloing strange problem:
>
> If squid-gw cannot retrieve the page from the proxy, no login
> is possible on the firewall until the request is satisfied
> or timed out.
> It seems, that only the login process is blocked, because
> everything else seems to work fine.
>
> We are not definitely shure that this problem is due to squid-gw
> or maybe caused by something else.
> We upgraded already the kernel from 2.2-17 to 2.2-19, but
> it did not help.
> Did anyone experience similar problems?
> Any help would be welcome!
>
> Gerd
> ------------------------------------------------------
> -- Gerd Schering
> -- Email: Schering@zrz.TU-Berlin.DE
> -- TU Berlin, Zentraleinrichtung Rechenzentrum
> -- Sekr. E-N 50, Einsteinufer 17, 10587 Berlin
>
> ------------------------------------------------------


From owner-fwtk-users@ex.tis.com Mon Apr 23 13:01 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA17720
	Mon, 23 Apr 2001 13:01:54 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA11776;
	Mon, 23 Apr 2001 10:05:55 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 23 Apr 2001 09:29:40 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA10291
	for fwtk-users-outgoing; Mon, 23 Apr 2001 09:29:24 -0700 (PDT)
Message-ID: <3AE45904.182DEB86@lclcan.com>
Date: Mon, 23 Apr 2001 12:32:04 -0400
From: Don Pro <don@lclcan.com>
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: refusing email
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 342

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I am running the FWTK 2.1 w/ all patches on a RedHat Linux 6.2 machine.
If I wish to refuse e-mail from a specific domain adn NOT have it sent
to a specific user, do I make the alteration somewhere in SMAP?


From owner-fwtk-users@ex.tis.com Mon Apr 23 13:38 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA17882
	Mon, 23 Apr 2001 13:38:16 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA14242;
	Mon, 23 Apr 2001 10:42:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 23 Apr 2001 10:09:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA11857
	for fwtk-users-outgoing; Mon, 23 Apr 2001 10:08:58 -0700 (PDT)
Date: Mon, 23 Apr 2001 13:07:12 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Don Pro <don@lclcan.com>
cc: fwtk <fwtk-users@lists.nai.com>
Subject: Re: refusing email
In-Reply-To: <3AE45904.182DEB86@lclcan.com>
Message-ID: <Pine.GSO.4.31.0104231306030.11146-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 769

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Don,

My version of the smap program has the support you are looking for.  You
can block a complete domain - or block individual from/to addresses - or
block all addresses for or from a domain.

Let me know if you are interested.

tedkeller


On Mon, 23 Apr 2001, Don Pro wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Hi,
>
> I am running the FWTK 2.1 w/ all patches on a RedHat Linux 6.2 machine.
> If I wish to refuse e-mail from a specific domain adn NOT have it sent
> to a specific user, do I make the alteration somewhere in SMAP?
>
>


From owner-fwtk-users@ex.tis.com Mon Apr 23 18:36 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id SAA18752
	Mon, 23 Apr 2001 18:36:24 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id PAA26702;
	Mon, 23 Apr 2001 15:38:03 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 23 Apr 2001 15:04:18 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA22744
	for fwtk-users-outgoing; Mon, 23 Apr 2001 15:04:01 -0700 (PDT)
Date: Mon, 23 Apr 2001 18:02:38 -0400
From: Joseph S D Yao <jsdy@cospo.osis.gov>
To: Don Pro <don@lclcan.com>
Cc: fwtk <fwtk-users@lists.nai.com>
Subject: Re: refusing email
Message-Id: <20010423180238.R8636@washington.cospo.osis.gov>
Mail-Followup-To: Don Pro <don@lclcan.com>, fwtk <fwtk-users@lists.nai.com>
References: <3AE45904.182DEB86@lclcan.com>
Mime-Version: 1.0
X-Mailer: Mutt 1.0i
In-Reply-To: <3AE45904.182DEB86@lclcan.com>; from don@lclcan.com on Mon, Apr 23, 2001 at 12:32:04PM -0400
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 804

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Mon, Apr 23, 2001 at 12:32:04PM -0400, Don Pro wrote:
...
> I am running the FWTK 2.1 w/ all patches on a RedHat Linux 6.2 machine.
> If I wish to refuse e-mail from a specific domain adn NOT have it sent
> to a specific user, do I make the alteration somewhere in SMAP?

Can't specify a user [but you can in 'sendmail'].  Can specify a
domain.  If you have the so-called "Yao patch" package of patches
installed, the comments are very detailed.

-- 
Joe Yao				jsdy@cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.

From owner-fwtk-users@ex.tis.com Tue Apr 24 04:59 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA20329
	Tue, 24 Apr 2001 04:59:29 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA20617;
	Tue, 24 Apr 2001 02:03:31 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 01:26:35 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id BAA17112
	for fwtk-users-outgoing; Tue, 24 Apr 2001 01:26:18 -0700 (PDT)
From: dw@netzstation.net
X-Authentication-Warning: fw.netzstation.net: Processed by hermes with -C /etc/sendmail.orig.cf
Subject: Answer: refusing email
To: Don Pro  <don@lclcan.com>
Cc: <fwtk-users@lists.nai.com>
Message-ID: <OFA62859A8.F4CB3F29-ONC1256A38.002A7A54@netzstation.net>
Date: Tue, 24 Apr 2001 10:08:20 +0200
 February 2000) at 24/04/2001 10:08:36
MIME-Version: 1.0
X-AntiVirus: scanned for viruses by AMaViS 0.2.1 (http://amavis.org/)
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id BAA17085
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 815

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Hi,
have you tried the NoSpam ! patch against smap?
We use it since over one year, it is very good
and easy to understand.

www.sabernet.net/software/

I really like it :-)

Mit freundlichem Gruss / Best Regards
-------------------------------------------------------------------------
- Dieter Windmüller -
e-mail: dw@netzstation.net




[To be removed from this list send the message "unsubscribe fwtk-users" in
the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

I am running the FWTK 2.1 w/ all patches on a RedHat Linux 6.2 machine.
If I wish to refuse e-mail from a specific domain adn NOT have it sent
to a specific user, do I make the alteration somewhere in SMAP?






From owner-fwtk-users@ex.tis.com Tue Apr 24 08:46 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA21023
	Tue, 24 Apr 2001 08:46:27 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA09319;
	Tue, 24 Apr 2001 05:50:29 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 05:16:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA06084
	for fwtk-users-outgoing; Tue, 24 Apr 2001 05:16:30 -0700 (PDT)
Message-ID: <E6C8B3EE167BD411B62F00D0B79EA1FD068676@chicago_srv2>
From: "Skolnik, Ed" <Ed.Skolnik@FLORSHEIM.com>
To: fwtk-users@lists.nai.com
Subject: I've just taken over admin duties for FWK firewall   -beginners q
	uestions -
Date: Tue, 24 Apr 2001 07:10:42 -0500
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 413

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]



I've just taken over admin duties for our FWK firewall on BSD Unix.

*	How do I find out what release of the tool kit I am using?
*	How can I open up multiple ports, do I need multiple plug-gw's or
can I wildcard it?

Looking to open up about 600 ports for SAP GUI traffic

 

ed



From owner-fwtk-users@ex.tis.com Tue Apr 24 11:12 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA21637
	Tue, 24 Apr 2001 11:12:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA01942;
	Tue, 24 Apr 2001 08:16:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 07:41:56 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA25155
	for fwtk-users-outgoing; Tue, 24 Apr 2001 07:41:40 -0700 (PDT)
Message-Id: <5.0.2.1.0.20010424102208.02783ec0@mailhost.csca.ryerson.ca>
X-Sender: pdunphy@mailhost.csca.ryerson.ca
X-Mailer: QUALCOMM Windows Eudora Version 5.0.2
Date: Tue, 24 Apr 2001 10:31:34 -0400
To: Joseph S D Yao <jsdy@cospo.osis.gov>
From: Paul Dunphy <pdunphy@csca.ryerson.ca>
Subject: Re: refusing email
Cc: fwtk-users@lists.nai.com
In-Reply-To: <20010423180238.R8636@washington.cospo.osis.gov>
References: <3AE45904.182DEB86@lclcan.com>
  <3AE45904.182DEB86@lclcan.com>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1498

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Joe (and others),

Do you know of any good lists of well-known spam addresses that we should 
block? Any in netperm-table format? (Wishful thinking, I know, but it never 
hurts to ask... :)

Paul

At 06:02 PM 4/23/2001 -0400, you wrote:
 >[To be removed from this list send the message "unsubscribe fwtk-users" in the
 >BODY of a mail message to majordomo@ex.tis.com.]
 >
 >On Mon, Apr 23, 2001 at 12:32:04PM -0400, Don Pro wrote:
 >...
 > > I am running the FWTK 2.1 w/ all patches on a RedHat Linux 6.2 machine.
 > > If I wish to refuse e-mail from a specific domain adn NOT have it sent
 > > to a specific user, do I make the alteration somewhere in SMAP?
 >
 >Can't specify a user [but you can in 'sendmail'].  Can specify a
 >domain.  If you have the so-called "Yao patch" package of patches
 >installed, the comments are very detailed.
 >
 >--
 >Joe Yao                         jsdy@cospo.osis.gov - Joseph S. D. Yao
 >COSPO/OSIS Computer Support                                     EMT-B
 >-----------------------------------------------------------------------
 >This message is not an official statement of COSPO policies.


---------------------------------------------------------------------
Paul T. Dunphy, P.Eng.
Systems Administrator/Research Engineer
Centre for the Study of Commercial Activity
Ryerson Polytechnic University
Toronto, Ontario, CANADA



From owner-fwtk-users@ex.tis.com Tue Apr 24 17:01 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA22707
	Tue, 24 Apr 2001 17:01:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id OAA22940;
	Tue, 24 Apr 2001 14:05:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 13:28:44 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id NAA17152
	for fwtk-users-outgoing; Tue, 24 Apr 2001 13:28:28 -0700 (PDT)
Date: Tue, 24 Apr 2001 16:26:59 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Paul Dunphy <pdunphy@csca.ryerson.ca>
cc: Joseph S D Yao <jsdy@cospo.osis.gov>, <fwtk-users@lists.nai.com>
Subject: Re: refusing email
In-Reply-To: <5.0.2.1.0.20010424102208.02783ec0@mailhost.csca.ryerson.ca>
Message-ID: <Pine.GSO.4.31.0104241624030.14666-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1918

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Paul,

Here's a good link with links to other sites.


http://www.cnx.com/stopspam.html


Also, check out the sendmail.org site.  Believe they have some links to.

ted keller


On Tue, 24 Apr 2001, Paul Dunphy wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> Joe (and others),
>
> Do you know of any good lists of well-known spam addresses that we should
> block? Any in netperm-table format? (Wishful thinking, I know, but it never
> hurts to ask... :)
>
> Paul
>
> At 06:02 PM 4/23/2001 -0400, you wrote:
>  >[To be removed from this list send the message "unsubscribe fwtk-users" in the
>  >BODY of a mail message to majordomo@ex.tis.com.]
>  >
>  >On Mon, Apr 23, 2001 at 12:32:04PM -0400, Don Pro wrote:
>  >...
>  > > I am running the FWTK 2.1 w/ all patches on a RedHat Linux 6.2 machine.
>  > > If I wish to refuse e-mail from a specific domain adn NOT have it sent
>  > > to a specific user, do I make the alteration somewhere in SMAP?
>  >
>  >Can't specify a user [but you can in 'sendmail'].  Can specify a
>  >domain.  If you have the so-called "Yao patch" package of patches
>  >installed, the comments are very detailed.
>  >
>  >--
>  >Joe Yao                         jsdy@cospo.osis.gov - Joseph S. D. Yao
>  >COSPO/OSIS Computer Support                                     EMT-B
>  >-----------------------------------------------------------------------
>  >This message is not an official statement of COSPO policies.
>
>
> ---------------------------------------------------------------------
> Paul T. Dunphy, P.Eng.
> Systems Administrator/Research Engineer
> Centre for the Study of Commercial Activity
> Ryerson Polytechnic University
> Toronto, Ontario, CANADA
>
>
>


From owner-fwtk-users@ex.tis.com Tue Apr 24 19:34 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA23015
	Tue, 24 Apr 2001 19:34:17 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA15834;
	Tue, 24 Apr 2001 16:38:17 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 16:04:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA13304
	for fwtk-users-outgoing; Tue, 24 Apr 2001 16:04:30 -0700 (PDT)
X-Server-Uuid: fcd61bbe-67b5-11d4-b17e-00d0b7722d16
Message-ID: <3AE60676.1A59167@link-us.net>
Date: Tue, 24 Apr 2001 17:04:22 -0600
From: "mike.stowe" <mike.stowe@link-us.net>
X-Mailer: Mozilla 4.72 [en] (WinNT; U)
X-Accept-Language: en
MIME-Version: 1.0
To: fwtk-users@lists.nai.com
Subject: newbie question telnet logging
X-WSS-ID: 16F8D9F8116999-01-01
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; 
 charset=us-ascii
Content-Length: 2425

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

fwtk community:

we installed fwtk on a solaris 2.7 box.
we could not get the syslogd in the tools directory to compile on the
first pass.  so we are running the 2.7 syslogd.

we got the telnet proxy to work.  we tested telnet access through the
bastion host successfully.

we are puzzled by the lack of logging of telnet activity.  the
connections
are logged.
we were hoping to get telnet activity logged given the assertion at the
tis.com
website that:
=====
The
                      proxy server supports access control based on
IP-address and/or host name, and
                      supports secondary access control permitting any
destination to be selectively
                      blocked. All connections and bytes transferred are
logged.
========

 do the 'bytes transferred' get logged somewhere different from tn-gw
connection messages?  there is no -log paramter documented nor does one
work
on a tn-gw: ........permit.......... statement.

do we have to use the syslogd that ships with the toolkit (and if so,
why?)  we searched the supplied documentation, the faq, the
mailing list archives and did a general web search.

do we need to adjust some syslog.conf parms?

did we misunderstand what would be logged and just need to sniff one of
the bastion connections?

============-=
our syslog file looks like:
*.err;kern.notice;auth.notice                   /dev/sysmsg
*.err;kern.debug;daemon.notice;mail.crit        /var/adm/messages

*.alert;kern.err;daemon.err                     operator
*.alert                                         root

*.emerg                                         *

# if a non-loghost machine chooses to have authentication messages
# sent to the loghost machine, un-comment out the following line:
#auth.notice                    ifdef(`LOGHOST', /var/log/authlog,
@loghost)

mail.debug                      ifdef(`LOGHOST', /var/log/syslog,
@loghost)

#
# non-loghost machines will use the following lines to cause "user"
# log messages to be logged locally.
#
ifdef(`LOGHOST', ,
user.err                                        /dev/sysmsg
user.err                                        /var/adm/messages
user.alert                                      `root, operator'
user.emerg                                      *
=============-=

mike





From owner-fwtk-users@ex.tis.com Tue Apr 24 21:20 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA23311
	Tue, 24 Apr 2001 21:20:03 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA22333;
	Tue, 24 Apr 2001 18:24:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 17:51:01 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA20166
	for fwtk-users-outgoing; Tue, 24 Apr 2001 17:50:44 -0700 (PDT)
Message-Id: <5.1.0.14.0.20010424194458.01f61ec0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Tue, 24 Apr 2001 19:47:53 -0400
To: "Skolnik, Ed" <Ed.Skolnik@FLORSHEIM.com>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: I've just taken over admin duties for FWK firewall  
  -beginners q uestions -
In-Reply-To: <E6C8B3EE167BD411B62F00D0B79EA1FD068676@chicago_srv2>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 975

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 07:10 AM 4/24/01 -0500, Skolnik, Ed wrote:
>I've just taken over admin duties for our FWK firewall on BSD Unix.
>
>*       How do I find out what release of the tool kit I am using?
>*       How can I open up multiple ports, do I need multiple plug-gw's or
>can I wildcard it?
>
>Looking to open up about 600 ports for SAP GUI traffic

600 ports? About the only way you can do this is to have 600 plug-gw instances.
Isn't there a better alternative? Socks, or some other mechanism, such as 
limiting the port range?
Actually, why do you need to run a "SAP GUI" through your firewall? Do you 
have business support applications actually running outside the firewall? 
Or is this traffic going to a partner that doesn't care about security? If 
it's going to another network, running this over a VPN would be the best 
solution.
         -Rick


From owner-fwtk-users@ex.tis.com Tue Apr 24 21:23 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA23315
	Tue, 24 Apr 2001 21:23:40 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id SAA22592;
	Tue, 24 Apr 2001 18:27:42 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Tue, 24 Apr 2001 17:55:33 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id RAA20455
	for fwtk-users-outgoing; Tue, 24 Apr 2001 17:55:17 -0700 (PDT)
Date: Tue, 24 Apr 2001 20:54:41 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: "mike.stowe" <mike.stowe@link-us.net>
cc: <fwtk-users@lists.nai.com>
Subject: Re: newbie question telnet logging
In-Reply-To: <3AE60676.1A59167@link-us.net>
Message-ID: <Pine.GSO.4.31.0104242052280.8144-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 3013

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Mike,

Telnet does log who connected, destination host connected to, and total
bytes logged.

You configure this through your netperm table as such


tn-gw:	permit-hosts	172.16.1.* -dest xxx.xxx.xxx.xxx -dest !172.16.1.*

or something similar to that.

hope this helps

ted keller


On Tue, 24 Apr 2001, mike.stowe wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> fwtk community:
>
> we installed fwtk on a solaris 2.7 box.
> we could not get the syslogd in the tools directory to compile on the
> first pass.  so we are running the 2.7 syslogd.
>
> we got the telnet proxy to work.  we tested telnet access through the
> bastion host successfully.
>
> we are puzzled by the lack of logging of telnet activity.  the
> connections
> are logged.
> we were hoping to get telnet activity logged given the assertion at the
> tis.com
> website that:
> =====
> The
>                       proxy server supports access control based on
> IP-address and/or host name, and
>                       supports secondary access control permitting any
> destination to be selectively
>                       blocked. All connections and bytes transferred are
> logged.
> ========
>
>  do the 'bytes transferred' get logged somewhere different from tn-gw
> connection messages?  there is no -log paramter documented nor does one
> work
> on a tn-gw: ........permit.......... statement.
>
> do we have to use the syslogd that ships with the toolkit (and if so,
> why?)  we searched the supplied documentation, the faq, the
> mailing list archives and did a general web search.
>
> do we need to adjust some syslog.conf parms?
>
> did we misunderstand what would be logged and just need to sniff one of
> the bastion connections?
>
> ============-=
> our syslog file looks like:
> *.err;kern.notice;auth.notice                   /dev/sysmsg
> *.err;kern.debug;daemon.notice;mail.crit        /var/adm/messages
>
> *.alert;kern.err;daemon.err                     operator
> *.alert                                         root
>
> *.emerg                                         *
>
> # if a non-loghost machine chooses to have authentication messages
> # sent to the loghost machine, un-comment out the following line:
> #auth.notice                    ifdef(`LOGHOST', /var/log/authlog,
> @loghost)
>
> mail.debug                      ifdef(`LOGHOST', /var/log/syslog,
> @loghost)
>
> #
> # non-loghost machines will use the following lines to cause "user"
> # log messages to be logged locally.
> #
> ifdef(`LOGHOST', ,
> user.err                                        /dev/sysmsg
> user.err                                        /var/adm/messages
> user.alert                                      `root, operator'
> user.emerg                                      *
> =============-=
>
> mike
>
>
>
>
>


From owner-fwtk-users@ex.tis.com Wed Apr 25 05:54 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA24419
	Wed, 25 Apr 2001 05:54:08 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id CAA23888;
	Wed, 25 Apr 2001 02:58:11 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 02:24:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id CAA21134
	for fwtk-users-outgoing; Wed, 25 Apr 2001 02:24:33 -0700 (PDT)
Message-ID: <3AE697CB.B57AE9A0@syntax.dera.gov.uk>
Date: Wed, 25 Apr 2001 10:24:27 +0100
From: Tony Gale <gale@syntax.dera.gov.uk>
X-Mailer: Mozilla 4.76 [en] (X11; U; Linux 2.4.3 i686)
X-Accept-Language: en
MIME-Version: 1.0
To: Ted Keller <keller@bfg.com>
CC: "mike.stowe" <mike.stowe@link-us.net>, fwtk-users@lists.nai.com
Subject: Re: newbie question telnet logging
References: <Pine.GSO.4.31.0104242052280.8144-100000@ns4.bfg.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 618

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Ted Keller wrote:
> 
> Mike,
> 
> Telnet does log who connected, destination host connected to, and total
> bytes logged.
> 

It logs the number of bytes transfered. I believe the question was, does
it log what was transfered, i.e. what the user typed, and the answer
is...... no.

-tony
-- 
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.

From owner-fwtk-users@ex.tis.com Wed Apr 25 06:30 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA24513
	Wed, 25 Apr 2001 06:30:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id DAA27572;
	Wed, 25 Apr 2001 03:34:27 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 03:01:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id DAA24147
	for fwtk-users-outgoing; Wed, 25 Apr 2001 03:01:39 -0700 (PDT)
Message-Id: <5.1.0.14.0.20010425055246.01f685d0@mail.itm-inst.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 25 Apr 2001 05:56:44 -0400
To: "mike.stowe" <mike.stowe@link-us.net>, fwtk-users@lists.nai.com
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: Re: newbie question telnet logging
In-Reply-To: <3AE60676.1A59167@link-us.net>
Mime-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1274

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

At 05:04 PM 4/24/01 -0600, mike.stowe wrote:
>=====
>The proxy server supports access control based on
>IP-address and/or host name, and supports secondary access control 
>permitting any
>destination to be selectively blocked. All connections and bytes 
>transferred are
>logged.
>========

The exit message from tn-gw gives the *count* of bytes transferred.
If you want the actual telnet data for a session to be logged, you really 
don't want that to go to syslog - syslog is a performance hog. You'll have 
to modify the tn-gw source to save the session data to a log file of your 
own somewhere.

>do the 'bytes transferred' get logged somewhere different from tn-gw
>connection messages?  there is no -log paramter documented nor does one
>work on a tn-gw: ........permit.......... statement.

There's no need to have a "-log" parameter since there's no operations to 
log; protocols like FTP and HTTP have operations (GET, POST, CWD, etc.) 
that can be individually logged, but telnet is just a simple conection.

>do we have to use the syslogd that ships with the toolkit (and if so,
>why?)

No. In fact, I don't use it.
         -Rick


From owner-fwtk-users@ex.tis.com Wed Apr 25 10:52 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA00271
	Wed, 25 Apr 2001 10:52:03 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id HAA26396;
	Wed, 25 Apr 2001 07:55:54 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 07:21:46 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA20487
	for fwtk-users-outgoing; Wed, 25 Apr 2001 07:21:29 -0700 (PDT)
Message-ID: <3AE6DE19.C5CFF857@lclcan.com>
Date: Wed, 25 Apr 2001 10:24:26 -0400
From: Don Pro <don@lclcan.com>
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: SMAP giving me a headache
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 561

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

I'm running sendmail 8.9.3 on RedHat Linux 6.2
Relaying is denied by default.
I run fwtk 2.1

When I run SMAP, relaying is allowed.  However, if I try to run the
system without SMAP, internal users can no longer send mail to the
outside world as I get relaying denied messages.  How do I trouble shoot
this?  I would like to allow internal users to send mail out but keep
external users from using my server as a relay.




From owner-fwtk-users@ex.tis.com Wed Apr 25 11:06 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00381
	Wed, 25 Apr 2001 11:06:32 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA29615;
	Wed, 25 Apr 2001 08:10:33 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 07:38:20 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA23005
	for fwtk-users-outgoing; Wed, 25 Apr 2001 07:38:04 -0700 (PDT)
From: jan@radio.hundert6.de
Message-ID: <XFMail.010425163657.jan@radio.hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <3AE6DE19.C5CFF857@lclcan.com>
Date: Wed, 25 Apr 2001 16:36:57 -0000 (GMT)
To: fwtk-users@ex.tis.com
Subject: RE: SMAP giving me a headache
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 734

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> When I run SMAP, relaying is allowed.  However, if I try to run the
> system without SMAP, internal users can no longer send mail to the
> outside world as I get relaying denied messages.  How do I trouble
> shoot
> this?  

You've got two choices: Either you run sendmail without the smap
wrapper and add your domain name in /etc/mail/relay-domains (or
whatever your sendmail.cf points at) or you apply the 'Yao patch' or
Ted Keller's patch for smap and adjust netperm-table accordingly. 

Btw: The sendmail issue is a FAQ. 

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de

From owner-fwtk-users@ex.tis.com Wed Apr 25 11:18 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00435
	Wed, 25 Apr 2001 11:18:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA02332;
	Wed, 25 Apr 2001 08:22:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 07:49:29 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA25145
	for fwtk-users-outgoing; Wed, 25 Apr 2001 07:49:13 -0700 (PDT)
Message-ID: <3AE6E429.5F377429@v-one.com>
Date: Wed, 25 Apr 2001 10:50:17 -0400
From: Keith Young <kyoung@v-one.com>
Organization: V-ONE
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Don Pro <don@lclcan.com>
CC: fwtk <fwtk-users@lists.nai.com>
Subject: Re: SMAP giving me a headache
References: <3AE6DE19.C5CFF857@lclcan.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 808

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Don Pro wrote:
> 
> I'm running sendmail 8.9.3 on RedHat Linux 6.2
> Relaying is denied by default.
> I run fwtk 2.1
> 
> When I run SMAP, relaying is allowed.  However, if I try to run the
> system without SMAP, internal users can no longer send mail to the
> outside world as I get relaying denied messages.  How do I trouble shoot
> this?  I would like to allow internal users to send mail out but keep
> external users from using my server as a relay.

Check your "/etc/sendmail.cf" file... it sounds like your
"/etc/mail/access" file is denying relays from anyone except for
127.0.0.1....

-- 
--Keith Young
-Director of Customer Care/Support, V-ONE Corp.
-kyoung@v-one.com

From owner-fwtk-users@ex.tis.com Wed Apr 25 11:25 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00473
	Wed, 25 Apr 2001 11:25:52 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA04642;
	Wed, 25 Apr 2001 08:29:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 07:57:05 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id HAA26574
	for fwtk-users-outgoing; Wed, 25 Apr 2001 07:56:48 -0700 (PDT)
Mime-Version: 1.0
Date: Wed, 25 Apr 2001 15:51:10 +0000
Message-ID: <000787E5.C22300@it.glasgow.gov.uk>
From: derek.torrance@it.glasgow.gov.uk (Derek Torrance)
Subject: Re: SMAP giving me a headache
To: fwtk <fwtk-users@lists.nai.com>, Don Pro <don@lclcan.com>
Content-Transfer-Encoding: 7bit
Content-Description: cc:Mail note part
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset="US-ASCII"
Content-Length: 1563

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

     
     Patch SMAP. There are a few different patches that do this.
     See http://www.fwtk.org/fwtk/patches/patches.html#2.2
     
     dt

______________________________ Reply Separator _________________________________
Subject: SMAP giving me a headache
Author:  Don Pro <don@lclcan.com> at Internet
Date:    25/04/01 10:24


[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi all,

I'm running sendmail 8.9.3 on RedHat Linux 6.2
Relaying is denied by default.
I run fwtk 2.1

When I run SMAP, relaying is allowed.  However, if I try to run the
system without SMAP, internal users can no longer send mail to the
outside world as I get relaying denied messages.  How do I trouble shoot
this?  I would like to allow internal users to send mail out but keep
external users from using my server as a relay.





----------------------------------------------------------------------------
Disclaimer: 
This message is intended only for use of the addressee. If this message
was sent to you in error, please notify the sender and delete this message.
Glasgow City Council cannot accept responsibility for viruses, so please
scan attachments. Views expressed in this message do not necessarily reflect
those of the Council who will not necessarily be bound by its contents.

----------------------------------------------------------------------------

From owner-fwtk-users@ex.tis.com Wed Apr 25 11:33 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00495
	Wed, 25 Apr 2001 11:33:37 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA06614;
	Wed, 25 Apr 2001 08:37:39 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 08:03:39 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA27982
	for fwtk-users-outgoing; Wed, 25 Apr 2001 08:03:23 -0700 (PDT)
Message-ID: <3AE6E7F0.E2044AF2@lclcan.com>
Date: Wed, 25 Apr 2001 11:06:25 -0400
From: Don Pro <don@lclcan.com>
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: fwtk <fwtk-users@lists.nai.com>
Subject: Re: SMAP giving me a headache
References: <XFMail.010425163452.jan@hundert6.de>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 846

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

> > When I run SMAP, relaying is allowed.  However, if I try to run the
> > system without SMAP, internal users can no longer send mail to the
> > outside world as I get relaying denied messages.  How do I trouble
> > shoot
> > this?
>
> You've got two choices: Either you run sendmail without the smap
> wrapper and add your domain name in /etc/mail/relay-domains (or
> whatever your sendmail.cf points at) or you apply the 'Yao patch' or
> Ted Keller's patch for smap and adjust netperm-table accordingly.

I've tried to use Ted's patch but when I install it, I can no longer send

or receive e-mail from the outside world.  I'll have a look at the 'Yao
patch'.  Failing that, I'll just ditch SMAP.

Thanks,
Don




From owner-fwtk-users@ex.tis.com Wed Apr 25 11:39 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00505
	Wed, 25 Apr 2001 11:39:54 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA08258;
	Wed, 25 Apr 2001 08:43:56 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 08:10:14 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA29431
	for fwtk-users-outgoing; Wed, 25 Apr 2001 08:09:53 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010420162128.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <Pine.GSO.4.31.0104200944190.19972-100000@ns4.bfg.com>
Date: Fri, 20 Apr 2001 16:21:28 -0000 (GMT)
To: Ted Keller <keller@bfg.com>
Subject: Re: queue filling up... I/O errors
Cc: fwtk-users@ex.tis.com
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 758

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


 > Note - this is not a smap/smapd issue.  Sendmail is the MTA that
 > attempts
 > do to the delivery.  Focus your research in the sendmail area.

Still, I wasn't 100% sure. As I do have split DNS with two MXers, smap
accepts the mail from the internal mailhost first, so I was concerned
that smap might have done something nasty (tm) to the messages ;o)) 

It'S pretty clear this was probably not the case. 

Cheers, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de


From owner-fwtk-users@ex.tis.com Wed Apr 25 11:40 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA00509
	Wed, 25 Apr 2001 11:40:25 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id IAA08432;
	Wed, 25 Apr 2001 08:44:27 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 08:11:13 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA29699
	for fwtk-users-outgoing; Wed, 25 Apr 2001 08:10:52 -0700 (PDT)
From: jan@hundert6.de
Message-ID: <XFMail.010425163452.jan@hundert6.de>
X-Mailer: XFMail 1.4.0 on FreeBSD
X-Priority: 3 (Normal)
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
In-Reply-To: <3AE6DE19.C5CFF857@lclcan.com>
Date: Wed, 25 Apr 2001 16:34:52 -0000 (GMT)
To: Don Pro <don@lclcan.com>
Subject: RE: SMAP giving me a headache
Cc: fwtk <fwtk-users@lists.nai.com>
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 740

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

 > When I run SMAP, relaying is allowed.  However, if I try to run the
 > system without SMAP, internal users can no longer send mail to the
 > outside world as I get relaying denied messages.  How do I trouble
 > shoot
 > this?  

You've got two choices: Either you run sendmail without the smap
wrapper and add your domain name in /etc/mail/relay-domains (or
whatever your sendmail.cf points at) or you apply the 'Yao patch' or
Ted Keller's patch for smap and adjust netperm-table accordingly. 

Btw: The sendmail issue is a FAQ. 

-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther@radio.hundert6.de


From owner-fwtk-users@ex.tis.com Wed Apr 25 12:16 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA00571
	Wed, 25 Apr 2001 12:16:05 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA17189;
	Wed, 25 Apr 2001 09:20:08 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 08:47:34 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id IAA09106
	for fwtk-users-outgoing; Wed, 25 Apr 2001 08:47:17 -0700 (PDT)
Date: Wed, 25 Apr 2001 11:45:11 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Don Pro <don@lclcan.com>
cc: fwtk <fwtk-users@lists.nai.com>
Subject: Re: SMAP giving me a headache
In-Reply-To: <3AE6E7F0.E2044AF2@lclcan.com>
Message-ID: <Pine.GSO.4.31.0104251143410.26405-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1440

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Don,

I can help you through that problem if you forward the snippits in the
message log.  Check and verify the netperm table.  There are specific
settings indicating which hosts are allowed to "relay" to the outside
world and which have to have valid internal domain names.  Suspect the yao
patch has something very similar.  I sure wouldn't advise running sendmail
naked....

tek


On Wed, 25 Apr 2001, Don Pro wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> > > When I run SMAP, relaying is allowed.  However, if I try to run the
> > > system without SMAP, internal users can no longer send mail to the
> > > outside world as I get relaying denied messages.  How do I trouble
> > > shoot
> > > this?
> >
> > You've got two choices: Either you run sendmail without the smap
> > wrapper and add your domain name in /etc/mail/relay-domains (or
> > whatever your sendmail.cf points at) or you apply the 'Yao patch' or
> > Ted Keller's patch for smap and adjust netperm-table accordingly.
>
> I've tried to use Ted's patch but when I install it, I can no longer send
>
> or receive e-mail from the outside world.  I'll have a look at the 'Yao
> patch'.  Failing that, I'll just ditch SMAP.
>
> Thanks,
> Don
>
>
>
>


From owner-fwtk-users@ex.tis.com Wed Apr 25 12:51 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id MAA00669
	Wed, 25 Apr 2001 12:51:07 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id JAA24239;
	Wed, 25 Apr 2001 09:55:06 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 09:22:41 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id JAA17481
	for fwtk-users-outgoing; Wed, 25 Apr 2001 09:22:25 -0700 (PDT)
Message-ID: <3AE6FA7C.EF1FD91@lclcan.com>
Date: Wed, 25 Apr 2001 12:25:32 -0400
From: Don Pro <don@lclcan.com>
X-Mailer: Mozilla 4.77 [en] (Win98; U)
X-Accept-Language: en,pdf
MIME-Version: 1.0
To: Ted Keller <keller@bfg.com>
CC: fwtk <fwtk-users@lists.nai.com>
Subject: Re: SMAP giving me a headache
References: <Pine.GSO.4.31.0104251143410.26405-100000@ns4.bfg.com>
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 1856

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi Ted,

One thing I noticed is that there were no messages in my message log.  This was my
first red flag.   In order to allow relaying from my hosts (I have five domains), do
I have to configure this in my netperm-table file or simply add the domains to my
/etc/mail/access or /etc/mail/relay-comains file(s)?

Thanks,
Don

Ted Keller wrote:

> Don,
>
> I can help you through that problem if you forward the snippits in the
> message log.  Check and verify the netperm table.  There are specific
> settings indicating which hosts are allowed to "relay" to the outside
> world and which have to have valid internal domain names.  Suspect the yao
> patch has something very similar.  I sure wouldn't advise running sendmail
> naked....
>
> tek
>
> On Wed, 25 Apr 2001, Don Pro wrote:
>
> > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > BODY of a mail message to majordomo@ex.tis.com.]
> >
> > > > When I run SMAP, relaying is allowed.  However, if I try to run the
> > > > system without SMAP, internal users can no longer send mail to the
> > > > outside world as I get relaying denied messages.  How do I trouble
> > > > shoot
> > > > this?
> > >
> > > You've got two choices: Either you run sendmail without the smap
> > > wrapper and add your domain name in /etc/mail/relay-domains (or
> > > whatever your sendmail.cf points at) or you apply the 'Yao patch' or
> > > Ted Keller's patch for smap and adjust netperm-table accordingly.
> >
> > I've tried to use Ted's patch but when I install it, I can no longer send
> >
> > or receive e-mail from the outside world.  I'll have a look at the 'Yao
> > patch'.  Failing that, I'll just ditch SMAP.
> >
> > Thanks,
> > Don
> >
> >
> >
> >


From owner-fwtk-users@ex.tis.com Wed Apr 25 13:45 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id NAA00862
	Wed, 25 Apr 2001 13:45:41 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id KAA00452;
	Wed, 25 Apr 2001 10:49:43 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 10:17:29 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA27770
	for fwtk-users-outgoing; Wed, 25 Apr 2001 10:17:13 -0700 (PDT)
X-Server-Uuid: fcd61bbe-67b5-11d4-b17e-00d0b7722d16
Message-ID: <3AE700D0.708FEB50@link-us.net>
Date: Wed, 25 Apr 2001 10:52:33 -0600
From: "mike.stowe" <mike.stowe@link-us.net>
X-Mailer: Mozilla 4.72 [en] (WinNT; U)
X-Accept-Language: en
MIME-Version: 1.0
To: "Ted Keller" <keller@bfg.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: newbie question telnet logging
References: <Pine.GSO.4.31.0104242052280.8144-100000@ns4.bfg.com>
X-WSS-ID: 16F9DF42135507-01-01
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; 
  charset=us-ascii
Content-Length: 3568

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

ted,  rick, tony:
  i appreciate your help.
we'll sniff the telnet connection to get what we want for now.
thanks,
mike

Ted Keller wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > Mike,
 >
 > Telnet does log who connected, destination host connected to, and total
 > bytes logged.
 >
 > You configure this through your netperm table as such
 >
 > tn-gw:  permit-hosts    172.16.1.* -dest xxx.xxx.xxx.xxx -dest !172.16.1.*
 >
 > or something similar to that.
 >
 > hope this helps
 >
 > ted keller
 >
 > On Tue, 24 Apr 2001, mike.stowe wrote:
 >
 > > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > > BODY of a mail message to majordomo@ex.tis.com.]
 > >
 > > fwtk community:
 > >
 > > we installed fwtk on a solaris 2.7 box.
 > > we could not get the syslogd in the tools directory to compile on the
 > > first pass.  so we are running the 2.7 syslogd.
 > >
 > > we got the telnet proxy to work.  we tested telnet access through the
 > > bastion host successfully.
 > >
 > > we are puzzled by the lack of logging of telnet activity.  the
 > > connections
 > > are logged.
 > > we were hoping to get telnet activity logged given the assertion at the
 > > tis.com
 > > website that:
 > > =====
 > > The
 > >                       proxy server supports access control based on
 > > IP-address and/or host name, and
 > >                       supports secondary access control permitting any
 > > destination to be selectively
 > >                       blocked. All connections and bytes transferred are
 > > logged.
 > > ========
 > >
 > >  do the 'bytes transferred' get logged somewhere different from tn-gw
 > > connection messages?  there is no -log paramter documented nor does one
 > > work
 > > on a tn-gw: ........permit.......... statement.
 > >
 > > do we have to use the syslogd that ships with the toolkit (and if so,
 > > why?)  we searched the supplied documentation, the faq, the
 > > mailing list archives and did a general web search.
 > >
 > > do we need to adjust some syslog.conf parms?
 > >
 > > did we misunderstand what would be logged and just need to sniff one of
 > > the bastion connections?
 > >
 > > ============-=
 > > our syslog file looks like:
 > > *.err;kern.notice;auth.notice                   /dev/sysmsg
 > > *.err;kern.debug;daemon.notice;mail.crit        /var/adm/messages
 > >
 > > *.alert;kern.err;daemon.err                     operator
 > > *.alert                                         root
 > >
 > > *.emerg                                         *
 > >
 > > # if a non-loghost machine chooses to have authentication messages
 > > # sent to the loghost machine, un-comment out the following line:
 > > #auth.notice                    ifdef(`LOGHOST', /var/log/authlog,
 > > @loghost)
 > >
 > > mail.debug                      ifdef(`LOGHOST', /var/log/syslog,
 > > @loghost)
 > >
 > > #
 > > # non-loghost machines will use the following lines to cause "user"
 > > # log messages to be logged locally.
 > > #
 > > ifdef(`LOGHOST', ,
 > > user.err                                        /dev/sysmsg
 > > user.err                                        /var/adm/messages
 > > user.alert                                      `root, operator'
 > > user.emerg                                      *
 > > =============-=
 > >
 > > mike
 > >
 > >
 > >
 > >
 > >




From owner-fwtk-users@ex.tis.com Wed Apr 25 15:13 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA01127
	Wed, 25 Apr 2001 15:13:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA13101;
	Wed, 25 Apr 2001 12:17:14 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 11:29:24 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id LAA06985
	for fwtk-users-outgoing; Wed, 25 Apr 2001 11:29:06 -0700 (PDT)
Date: Wed, 25 Apr 2001 14:28:15 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Don Pro <don@lclcan.com>
cc: fwtk <fwtk-users@lists.nai.com>
Subject: Re: SMAP giving me a headache
In-Reply-To: <3AE6FA7C.EF1FD91@lclcan.com>
Message-ID: <Pine.GSO.4.31.0104251417560.5498-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 3260

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Don,

My method of implementing this is as follows.....


Using sendmail features - mailertable

internaldomain.com		smtp:internal-mailhub.internaldomain.com

example:

bfg.com		smtp:mh.bfg.com



Then in netperm-table

smap:		local-domain	internaldomain.com *.internaldomain.com

for example

smap:		local-domain	bfg.com *.bfg.com
or
smap:		local-domain	bfgoodrich.com

The first example allows all sub-domains.  The second example is an
individual domain without subdomains.


When using smap, all mail comes from localhost - so the sendmail
anti-relaying features are disabled because sendmail thinks it is making
local deliveries.  Therefore, anti-relaying features must be handled by
the smap routines.  Appropraite entries in netperm-table are:

smap:	local-domain	bfg.com *.bfg.com

and

smap:	check-relay	1

Also to turn on the DNS validation on from addresses...

smap:	check_domain	1


The logging funtions have not been modified.  However, on some systems I
noted that syslog does not work across a chrooted environment.  This is an
issue in early solaris systems.  For initial testing, I would recommend
getting things working in a non-chrooted environment - then migrate to a
chroot environment once you know what works and what doesn't.

tedkeller




 On Wed, 25 Apr 2001, Don Pro wrote:

> Hi Ted,
>
> One thing I noticed is that there were no messages in my message log.  This was my
> first red flag.   In order to allow relaying from my hosts (I have five domains), do
> I have to configure this in my netperm-table file or simply add the domains to my
> /etc/mail/access or /etc/mail/relay-comains file(s)?
>
> Thanks,
> Don
>
> Ted Keller wrote:
>
> > Don,
> >
> > I can help you through that problem if you forward the snippits in the
> > message log.  Check and verify the netperm table.  There are specific
> > settings indicating which hosts are allowed to "relay" to the outside
> > world and which have to have valid internal domain names.  Suspect the yao
> > patch has something very similar.  I sure wouldn't advise running sendmail
> > naked....
> >
> > tek
> >
> > On Wed, 25 Apr 2001, Don Pro wrote:
> >
> > > [To be removed from this list send the message "unsubscribe fwtk-users" in the
> > > BODY of a mail message to majordomo@ex.tis.com.]
> > >
> > > > > When I run SMAP, relaying is allowed.  However, if I try to run the
> > > > > system without SMAP, internal users can no longer send mail to the
> > > > > outside world as I get relaying denied messages.  How do I trouble
> > > > > shoot
> > > > > this?
> > > >
> > > > You've got two choices: Either you run sendmail without the smap
> > > > wrapper and add your domain name in /etc/mail/relay-domains (or
> > > > whatever your sendmail.cf points at) or you apply the 'Yao patch' or
> > > > Ted Keller's patch for smap and adjust netperm-table accordingly.
> > >
> > > I've tried to use Ted's patch but when I install it, I can no longer send
> > >
> > > or receive e-mail from the outside world.  I'll have a look at the 'Yao
> > > patch'.  Failing that, I'll just ditch SMAP.
> > >
> > > Thanks,
> > > Don
> > >
> > >
> > >
> > >
>
>


From owner-fwtk-users@ex.tis.com Wed Apr 25 15:24 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA01182
	Wed, 25 Apr 2001 15:24:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA15230;
	Wed, 25 Apr 2001 12:28:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 11:40:27 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id KAA27770
	for fwtk-users-outgoing; Wed, 25 Apr 2001 10:17:13 -0700 (PDT)
X-Server-Uuid: fcd61bbe-67b5-11d4-b17e-00d0b7722d16
Message-ID: <3AE700D0.708FEB50@link-us.net>
Date: Wed, 25 Apr 2001 10:52:33 -0600
From: "mike.stowe" <mike.stowe@link-us.net>
X-Mailer: Mozilla 4.72 [en] (WinNT; U)
X-Accept-Language: en
MIME-Version: 1.0
To: "Ted Keller" <keller@bfg.com>
Cc: fwtk-users@lists.nai.com
Subject: Re: newbie question telnet logging
References: <Pine.GSO.4.31.0104242052280.8144-100000@ns4.bfg.com>
X-WSS-ID: 16F9DF42135507-01-01
Content-Transfer-Encoding: 7bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; 
  charset=us-ascii
Content-Length: 3568

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

ted,  rick, tony:
  i appreciate your help.
we'll sniff the telnet connection to get what we want for now.
thanks,
mike

Ted Keller wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > Mike,
 >
 > Telnet does log who connected, destination host connected to, and total
 > bytes logged.
 >
 > You configure this through your netperm table as such
 >
 > tn-gw:  permit-hosts    172.16.1.* -dest xxx.xxx.xxx.xxx -dest !172.16.1.*
 >
 > or something similar to that.
 >
 > hope this helps
 >
 > ted keller
 >
 > On Tue, 24 Apr 2001, mike.stowe wrote:
 >
 > > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > > BODY of a mail message to majordomo@ex.tis.com.]
 > >
 > > fwtk community:
 > >
 > > we installed fwtk on a solaris 2.7 box.
 > > we could not get the syslogd in the tools directory to compile on the
 > > first pass.  so we are running the 2.7 syslogd.
 > >
 > > we got the telnet proxy to work.  we tested telnet access through the
 > > bastion host successfully.
 > >
 > > we are puzzled by the lack of logging of telnet activity.  the
 > > connections
 > > are logged.
 > > we were hoping to get telnet activity logged given the assertion at the
 > > tis.com
 > > website that:
 > > =====
 > > The
 > >                       proxy server supports access control based on
 > > IP-address and/or host name, and
 > >                       supports secondary access control permitting any
 > > destination to be selectively
 > >                       blocked. All connections and bytes transferred are
 > > logged.
 > > ========
 > >
 > >  do the 'bytes transferred' get logged somewhere different from tn-gw
 > > connection messages?  there is no -log paramter documented nor does one
 > > work
 > > on a tn-gw: ........permit.......... statement.
 > >
 > > do we have to use the syslogd that ships with the toolkit (and if so,
 > > why?)  we searched the supplied documentation, the faq, the
 > > mailing list archives and did a general web search.
 > >
 > > do we need to adjust some syslog.conf parms?
 > >
 > > did we misunderstand what would be logged and just need to sniff one of
 > > the bastion connections?
 > >
 > > ============-=
 > > our syslog file looks like:
 > > *.err;kern.notice;auth.notice                   /dev/sysmsg
 > > *.err;kern.debug;daemon.notice;mail.crit        /var/adm/messages
 > >
 > > *.alert;kern.err;daemon.err                     operator
 > > *.alert                                         root
 > >
 > > *.emerg                                         *
 > >
 > > # if a non-loghost machine chooses to have authentication messages
 > > # sent to the loghost machine, un-comment out the following line:
 > > #auth.notice                    ifdef(`LOGHOST', /var/log/authlog,
 > > @loghost)
 > >
 > > mail.debug                      ifdef(`LOGHOST', /var/log/syslog,
 > > @loghost)
 > >
 > > #
 > > # non-loghost machines will use the following lines to cause "user"
 > > # log messages to be logged locally.
 > > #
 > > ifdef(`LOGHOST', ,
 > > user.err                                        /dev/sysmsg
 > > user.err                                        /var/adm/messages
 > > user.alert                                      `root, operator'
 > > user.emerg                                      *
 > > =============-=
 > >
 > > mike
 > >
 > >
 > >
 > >
 > >




From owner-fwtk-users@ex.tis.com Wed Apr 25 19:11 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA01786
	Wed, 25 Apr 2001 19:11:12 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id QAA17849;
	Wed, 25 Apr 2001 16:15:15 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 15:40:49 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id PAA13647
	for fwtk-users-outgoing; Wed, 25 Apr 2001 15:40:31 -0700 (PDT)
Date: Wed, 25 Apr 2001 14:23:20 -0700 (PDT)
From: Scott Campbell <scampbel@gvpl.ca>
X-X-Sender:  <scampbel@pochta.gvpl.victoria.bc.ca>
To: fwtk <fwtk-users@lists.nai.com>
Subject: Plug-gw and userid patch?
In-Reply-To: <Pine.GSO.4.31.0104251143410.26405-100000@ns4.bfg.com>
Message-ID: <Pine.BSF.4.32.0104251416300.40446-100000@pochta.gvpl.victoria.bc.ca>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 787

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]


Is there a patch out there to add the userid option to plug-gw?  The man
page says it comes with it but that isn't what I see - plugs run as root.
I can find the code in the other proxies (http-gw, tn-gw, smap,ftp-gw...)
but the code isn't there in plug-gw.c to read in the netperm option.  I
found other people mentioning this in the mail archives but no-one posted
a solution that I could find.  If not then I will start trying to do one
but no guarantees on my c ability and turnaround time.

Thanks in advance

Scott E. Campbell
_______________________________
Computer Operations
Greater Victoria Public Library
Victoria BC CANADA

scampbel@gvpl.ca




From owner-fwtk-users@ex.tis.com Thu Apr 26 00:38 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id AAA02335
	Thu, 26 Apr 2001 00:38:45 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id VAA05368;
	Wed, 25 Apr 2001 21:42:46 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 21:09:57 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id VAA03894
	for fwtk-users-outgoing; Wed, 25 Apr 2001 21:09:40 -0700 (PDT)
Message-ID: <20010426040937.63649.qmail@web11003.mail.yahoo.com>
Date: Wed, 25 Apr 2001 21:09:37 -0700 (PDT)
From: Naresh Narang <nknarang@yahoo.com>
Subject: PPTP through fwtk?
To: fwtk-users@lists.nai.com
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain; charset=us-ascii
Content-Length: 396

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

  I was wondering if there is a way I can run a pptp
server behind firewall?

Thanks,
Naresh

=====
-- Naresh

__________________________________________________
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/

From owner-fwtk-users@ex.tis.com Thu Apr 26 03:07 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id DAA02783
	Thu, 26 Apr 2001 03:07:46 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id AAA12075;
	Thu, 26 Apr 2001 00:11:48 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 23:39:51 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA09936
	for fwtk-users-outgoing; Wed, 25 Apr 2001 23:39:35 -0700 (PDT)
X-Authentication-Warning: fireinet.3suisses.be: wall set sender to <F.Beuserie@3suisses.be> using -f
Message-ID: <8FF4A557FE65D311BDF80000E88EAB192BD4DB@DSISS002>
From: =?iso-8859-1?Q?Beuserie_Fr=E9d=E9ric_=28stbrice_dsi=29?=
	 <F.Beuserie@3suisses.be>
To: "'fwtk-users@lists.nai.com'" <fwtk-users@lists.nai.com>
Cc: "'Naresh Narang'" <nknarang@yahoo.com>
Subject: RE: PPTP through fwtk?
Date: Thu, 26 Apr 2001 08:41:26 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C0CE1B.EB0201B0"
Content-Length: 4221

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C0CE1B.EB0201B0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

fwtk cannot be of any help in implementing pptp. it has not proxies for =
that
protocol=20
(as far has I know).
but with help from packet filtering you can open protocol 47 in both
directions and TCP port 1024+ > 1723 from the client to the server =
through
the firewall.=20
Then control the packets which go through the tunnel with the packet
filtering again to restrict the traffic (think: pptp is not secure)

this will work even if fwtk is not installed at all.

see http://poptop.lineo.com for a linux version of pptp server

-----------------------------------------
Beuserie Frederic
Email: F.Beuserie@3Suisses.be



-----Message d'origine-----
De: Naresh Narang [mailto:nknarang@yahoo.com]
Date: jeudi 26 avril 2001 6:10
=C0: fwtk-users@lists.nai.com
Objet: PPTP through fwtk?


[To be removed from this list send the message "unsubscribe fwtk-users" =
in
the
BODY of a mail message to majordomo@ex.tis.com.]

Hi,

  I was wondering if there is a way I can run a pptp
server behind firewall?

Thanks,
Naresh

=3D=3D=3D=3D=3D
-- Naresh

__________________________________________________
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/

------_=_NextPart_001_01C0CE1B.EB0201B0
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2653.12">
<TITLE>RE: PPTP through fwtk?</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2>fwtk cannot be of any help in implementing pptp. it =
has not proxies for that protocol </FONT>
<BR><FONT SIZE=3D2>(as far has I know).</FONT>
<BR><FONT SIZE=3D2>but with help from packet filtering you can open =
protocol 47 in both directions and TCP port 1024+ &gt; 1723 from the =
client to the server through the firewall. </FONT></P>

<P><FONT SIZE=3D2>Then control the packets which go through the tunnel =
with the packet filtering again to restrict the traffic (think: pptp is =
not secure)</FONT></P>

<P><FONT SIZE=3D2>this will work even if fwtk is not installed at =
all.</FONT>
</P>

<P><FONT SIZE=3D2>see <A HREF=3D"http://poptop.lineo.com" =
TARGET=3D"_blank">http://poptop.lineo.com</A> for a linux version of =
pptp server</FONT>
</P>

<P><FONT SIZE=3D2>-----------------------------------------</FONT>
<BR><FONT SIZE=3D2>Beuserie Frederic</FONT>
<BR><FONT SIZE=3D2>Email: F.Beuserie@3Suisses.be</FONT>
</P>
<BR>
<BR>

<P><FONT SIZE=3D2>-----Message d'origine-----</FONT>
<BR><FONT SIZE=3D2>De: Naresh Narang [<A =
HREF=3D"mailto:nknarang@yahoo.com">mailto:nknarang@yahoo.com</A>]</FONT>=

<BR><FONT SIZE=3D2>Date: jeudi 26 avril 2001 6:10</FONT>
<BR><FONT SIZE=3D2>=C0: fwtk-users@lists.nai.com</FONT>
<BR><FONT SIZE=3D2>Objet: PPTP through fwtk?</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>[To be removed from this list send the message =
&quot;unsubscribe fwtk-users&quot; in the</FONT>
<BR><FONT SIZE=3D2>BODY of a mail message to =
majordomo@ex.tis.com.]</FONT>
</P>

<P><FONT SIZE=3D2>Hi,</FONT>
</P>

<P><FONT SIZE=3D2>&nbsp; I was wondering if there is a way I can run a =
pptp</FONT>
<BR><FONT SIZE=3D2>server behind firewall?</FONT>
</P>

<P><FONT SIZE=3D2>Thanks,</FONT>
<BR><FONT SIZE=3D2>Naresh</FONT>
</P>

<P><FONT SIZE=3D2>=3D=3D=3D=3D=3D</FONT>
<BR><FONT SIZE=3D2>-- Naresh</FONT>
</P>

<P><FONT =
SIZE=3D2>__________________________________________________</FONT>
<BR><FONT SIZE=3D2>Do You Yahoo!?</FONT>
<BR><FONT SIZE=3D2>Yahoo! Auctions - buy the things you want at great =
prices</FONT>
<BR><FONT SIZE=3D2><A HREF=3D"http://auctions.yahoo.com/" =
TARGET=3D"_blank">http://auctions.yahoo.com/</A></FONT>
</P>

</BODY>
</HTML>
------_=_NextPart_001_01C0CE1B.EB0201B0--

From owner-fwtk-users@ex.tis.com Thu Apr 26 03:21 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id DAA02806
	Thu, 26 Apr 2001 03:21:06 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id AAA13574;
	Thu, 26 Apr 2001 00:25:09 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Wed, 25 Apr 2001 23:53:50 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id XAA10556
	for fwtk-users-outgoing; Wed, 25 Apr 2001 23:53:33 -0700 (PDT)
Date: Thu, 26 Apr 2001 07:52:58 +0100
Message-Id: <GCE0GA$INXAK9_U5jIO5xs9Xo7AxJcRlLS8gA0VdbzirM_wdcr6TUm0L@respublica.fr>
Subject: Re: Plug-gw and userid patch?
MIME-Version: 1.0
From: "qgiorgi@respublica.fr"<qgiorgi@respublica.fr>
To: fwtk-users@lists.nai.com
Cc: scampbel@gvpl.ca
X-XaM3-API-Version: 1.1.9.1.22
X-SenderIP: 194.206.181.239
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by relay2.nai.com id XAA10545
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 2501

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

Hello; 
few weeks ago i posted the same kind of messages, but 
still waiting :(
I do a workaround for this userid/grouid issue. ( 
mainly a copy/paste of other *-gw userid/groupid 
support. )

As i am not very confident with my C skills i'd like 
people of the early developpers to tell if it's this 
workaround is ok or not and maybe (if it is so simple 
as that why it  has not been implemented at start-
up ? :) ) 


Thanks, 

Quentin GIORGI 
Network enginner.
qgiorgi@respublica.fr


diff between plug-gw.c files: 
55,56d54
<       int             rungid = -1;
<       int             runuid = -1;
119,144d116
< /*BEGIN:  ADD ON TO SUPPORT GROUPID AND USERID OPTION 
*/
<       if((cf = cfg_get("groupid",cfp)) != (Cfg *)0) {
<
<                 if(cf->argc != 1) {
<                         syslog(LLEV,"fwtkcfgerr: 
groupid must have one paramet
er,line %d",cf->ln);
<                         exit(1);
<                 }
<                 if((rungid = mapgid(cf->argv[0])) == -
1) {
<                         syslog(LLEV,"fwtkcfgerr: 
cannot map %.100s to gid",cf-
>argv[0]);
<                         exit(1);
<                 }
<         }
<
<       if((cf = cfg_get("userid",cfp)) != (Cfg *)0) {
<
<                 if(cf->argc != 1) {
<                         syslog(LLEV,"fwtkcfgerr: 
userid must have one paramete
r,line %d",cf->ln);
<                         exit(1);
<                 }
<                 if((runuid = mapuid(cf->argv[0])) == -
1) {
<                         syslog(LLEV,"fwtkcfgerr: 
cannot map %.100s to uid",cf-
>argv[0]);
<                         exit(1);
<                 }
<         }
< /* END:  ADD ON TO SUPPORT USERID AND GROUPID OPTION 
*/
<
159,168d130
< /*BEGIN:  ADD ON TO SUPPORT USERID AND GROUPID OPTION 
*/
<      if(rungid != -1 && setgid(rungid)) {
<              syslog(LLEV,"fwtksyserr: cannot setgid %
d: %m",rungid);
<              exit(1);
<      }
<      if(runuid != -1 && setuid(runuid)) {
<              syslog(LLEV,"fwtksyserr: cannot setuid %
d: %m",runuid);
<              exit(1);
<      }
<
170d131
< /*END:  ADD ON TO SUPPORT USERID AND GROUPID OPTION */

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Choisissez les offres que vous voulez recevoir
Et gagnez une playstation 2 ou des baladeurs MP3 
----> http://www.respublica.fr/site/yoptin <----
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



From owner-fwtk-users@ex.tis.com Thu Apr 26 09:08 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA03671
	Thu, 26 Apr 2001 09:08:28 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id GAA00507;
	Thu, 26 Apr 2001 06:12:30 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Thu, 26 Apr 2001 05:40:09 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id FAA27804
	for fwtk-users-outgoing; Thu, 26 Apr 2001 05:39:52 -0700 (PDT)
Date: Thu, 26 Apr 2001 08:31:11 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: Naresh Narang <nknarang@yahoo.com>
cc: <fwtk-users@lists.nai.com>
Subject: Re: PPTP through fwtk?
In-Reply-To: <20010426040937.63649.qmail@web11003.mail.yahoo.com>
Message-ID: <Pine.GSO.4.31.0104260830120.6675-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 771

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

PPTP requires GRE protocol INBOUND access.  The fwtk toolset does not
support GRE IP protocol.  So, by itself, it cannot support pptp.

ted keller


On Wed, 25 Apr 2001, Naresh Narang wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > Hi,
 >
 >   I was wondering if there is a way I can run a pptp
 > server behind firewall?
 >
 > Thanks,
 > Naresh
 >
 > =====
 > -- Naresh
 >
 > __________________________________________________
 > Do You Yahoo!?
 > Yahoo! Auctions - buy the things you want at great prices
 > http://auctions.yahoo.com/
 >



From owner-fwtk-users@ex.tis.com Fri Apr 27 08:08 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA06615
	Fri, 27 Apr 2001 08:08:30 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id FAA28363;
	Fri, 27 Apr 2001 05:12:35 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Fri, 27 Apr 2001 04:37:37 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id EAA26508
	for fwtk-users-outgoing; Fri, 27 Apr 2001 04:37:20 -0700 (PDT)
Date: Thu, 26 Apr 2001 13:05:37 -0700 (PDT)
From: Scott Campbell <scampbel@gvpl.ca>
X-X-Sender:  <scampbel@pochta.gvpl.victoria.bc.ca>
To: "qgiorgi@respublica.fr" <qgiorgi@respublica.fr>
cc: fwtk <fwtk-users@lists.nai.com>
Subject: Re: Plug-gw and userid patch?
In-Reply-To: <GCE0GA$INXAK9_U5jIO5xs9Xo7AxJcRlLS8gA0VdbzirM_wdcr6TUm0L@respublica.fr>
Message-ID: <Pine.BSF.4.32.0104261241220.71262-100000@pochta.gvpl.victoria.bc.ca>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 3624

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

On Thu, 26 Apr 2001, qgiorgi@respublica.fr wrote:

 > [To be removed from this list send the message "unsubscribe fwtk-users" in the
 > BODY of a mail message to majordomo@ex.tis.com.]
 >
 > Hello;
 > few weeks ago i posted the same kind of messages, but
 > still waiting :(
 > I do a workaround for this userid/grouid issue. (
 > mainly a copy/paste of other *-gw userid/groupid
 > support. )
 >
 > As i am not very confident with my C skills i'd like
 > people of the early developpers to tell if it's this
 > workaround is ok or not and maybe (if it is so simple
 > as that why it  has not been implemented at start-
 > up ? :) )
 >

I spoke too soon - sort of - up until now all my plug-gw proxies have had
their rules as:

plug-gw:  port ....

since using the proxy name didn't work.  After I put in your diffs I now
have to put in the actual names of the proxies like:

geoweb-gw: port ....

which would mean for each plug-gw instance I need a rule in the
netperm-table to give the userid and groupid - hmmm there must be a way
for it to read its own plus the plug-gw lines. (damn my lack of C skills -
will poke away for awhile on it though)

Thanks again for your push in the right direction.

Scott E. Campbell
_______________________________
Computer Operations
Greater Victoria Public Library
Victoria BC CANADA



 >
 > Thanks,
 >
 > Quentin GIORGI
 > Network enginner.
 > qgiorgi@respublica.fr
 >
 >
 > diff between plug-gw.c files:
 > 55,56d54
 > <       int             rungid = -1;
 > <       int             runuid = -1;
 > 119,144d116
 > < /*BEGIN:  ADD ON TO SUPPORT GROUPID AND USERID OPTION
 > */
 > <       if((cf = cfg_get("groupid",cfp)) != (Cfg *)0) {
 > <
 > <                 if(cf->argc != 1) {
 > <                         syslog(LLEV,"fwtkcfgerr:
 > groupid must have one paramet
 > er,line %d",cf->ln);
 > <                         exit(1);
 > <                 }
 > <                 if((rungid = mapgid(cf->argv[0])) == -
 > 1) {
 > <                         syslog(LLEV,"fwtkcfgerr:
 > cannot map %.100s to gid",cf-
 > >argv[0]);
 > <                         exit(1);
 > <                 }
 > <         }
 > <
 > <       if((cf = cfg_get("userid",cfp)) != (Cfg *)0) {
 > <
 > <                 if(cf->argc != 1) {
 > <                         syslog(LLEV,"fwtkcfgerr:
 > userid must have one paramete
 > r,line %d",cf->ln);
 > <                         exit(1);
 > <                 }
 > <                 if((runuid = mapuid(cf->argv[0])) == -
 > 1) {
 > <                         syslog(LLEV,"fwtkcfgerr:
 > cannot map %.100s to uid",cf-
 > >argv[0]);
 > <                         exit(1);
 > <                 }
 > <         }
 > < /* END:  ADD ON TO SUPPORT USERID AND GROUPID OPTION
 > */
 > <
 > 159,168d130
 > < /*BEGIN:  ADD ON TO SUPPORT USERID AND GROUPID OPTION
 > */
 > <      if(rungid != -1 && setgid(rungid)) {
 > <              syslog(LLEV,"fwtksyserr: cannot setgid %
 > d: %m",rungid);
 > <              exit(1);
 > <      }
 > <      if(runuid != -1 && setuid(runuid)) {
 > <              syslog(LLEV,"fwtksyserr: cannot setuid %
 > d: %m",runuid);
 > <              exit(1);
 > <      }
 > <
 > 170d131
 > < /*END:  ADD ON TO SUPPORT USERID AND GROUPID OPTION */
 >
 > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 >  Choisissez les offres que vous voulez recevoir
 > Et gagnez une playstation 2 ou des baladeurs MP3
 > ----> http://www.respublica.fr/site/yoptin <----
 > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 >
 >
 >







From owner-fwtk-users@ex.tis.com Mon Apr 30 15:51 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA01003
	Mon, 30 Apr 2001 15:51:54 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id MAA07703;
	Mon, 30 Apr 2001 12:56:05 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 30 Apr 2001 12:19:28 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id MAA01287
	for fwtk-users-outgoing; Mon, 30 Apr 2001 12:19:11 -0700 (PDT)
From: David Hamm <dhamm@itrepro.com>
Reply-To: dhamm@itrepro.com
Organization: Imaging Technologies Services
To: fwtk <fwtk-users@lists.nai.com>
Subject: smap startup problem
Date: Mon, 30 Apr 2001 15:17:44 -0400
X-Mailer: KMail [version 1.0.20]
MIME-Version: 1.0
Message-Id: <01043015185000.14717@workbox.atlanta.itserve.com>
Content-Transfer-Encoding: 8bit
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: text/plain
Content-Length: 545

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

When I run smap I get the following errors in my /var/log/messages file.  Any
suggestions?
Apr 30 15:17:20 workbox smap[14987]: getpeername failed: Socket operation on non-socket
Apr 30 15:17:20 workbox smap[14987]: cannot get remote host


---------------------------------
David Hamm
Systems Analyst
Imaging Technologies Services Inc.
email: dhamm@itrepro.com
voice: 404-870-6663
---------------------------------

From owner-fwtk-users@ex.tis.com Mon Apr 30 19:56 EDT 2001
Received: from relay2.nai.com (relay2.nai.com [161.69.3.67])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id TAA01435
	Mon, 30 Apr 2001 19:56:49 -0400 (EDT)
Received: from localhost (daemon@localhost)
	by relay2.nai.com (8.9.3/8.9.3) with SMTP id RAA14262;
	Mon, 30 Apr 2001 17:01:00 -0700 (PDT)
Received: by ex.tis.com (bulk_mailer v1.11); Mon, 30 Apr 2001 16:29:47 -0700
Received: (from majordomo@localhost)
	by relay2.nai.com (8.9.3/8.9.3) id QAA11856
	for fwtk-users-outgoing; Mon, 30 Apr 2001 16:29:31 -0700 (PDT)
Date: Mon, 30 Apr 2001 19:28:58 -0400 (EDT)
From: Ted Keller <keller@bfg.com>
To: David Hamm <dhamm@itrepro.com>
cc: fwtk <fwtk-users@lists.nai.com>
Subject: Re: smap startup problem
In-Reply-To: <01043015185000.14717@workbox.atlanta.itserve.com>
Message-ID: <Pine.GSO.4.31.0104301928320.19375-100000@ns4.bfg.com>
MIME-Version: 1.0
Sender: owner-fwtk-users@lists.tislabs.com
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 874

[To be removed from this list send the message "unsubscribe fwtk-users" in the
BODY of a mail message to majordomo@ex.tis.com.]

David,

Looks like you are running it from the command line - not from inetd.
smap should be run from inetd.conf.

ted keller


On Mon, 30 Apr 2001, David Hamm wrote:

> [To be removed from this list send the message "unsubscribe fwtk-users" in the
> BODY of a mail message to majordomo@ex.tis.com.]
>
> When I run smap I get the following errors in my /var/log/messages file.  Any
> suggestions?
> Apr 30 15:17:20 workbox smap[14987]: getpeername failed: Socket operation on non-socket
> Apr 30 15:17:20 workbox smap[14987]: cannot get remote host
>
>
> ---------------------------------
> David Hamm
> Systems Analyst
> Imaging Technologies Services Inc.
> email: dhamm@itrepro.com
> voice: 404-870-6663
> ---------------------------------
>


