From bounce-fwtk-users-303@listserv.nai.com Wed Jan  2 07:11 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id HAA14190
	Wed, 2 Jan 2002 07:11:52 -0500 (EST)
Message-ID: <LISTMANAGER-303-323-2002.01.02-06.16.55--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Wed, 02 Jan 2002 13:21:33 +0100
From: Markus Schreier <ms@ordix.de>
Organization: ORDIX AG
X-Mailer: Mozilla 4.7 [de] (WinNT; I)
X-Accept-Language: de
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Reverse-Proxy witch apache
Content-Transfer-Encoding: 8bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 2558
Status: RO

Hello all,
and happy new year to all of you.

I'd like to setup some way to provide Services from the inner network to
people on the internet.
This setup should 
* only allow authorized people
* be secure

I've been playing with the following setup and would like you to provide
me whith any thoughts to that subject, which come to your mind.


                                           |
internal network                          
|                                         internet
                                           |
                                           
http-service      -------------------  fw-gateway   
----------+--------/\/\/\------ client
(e.g. webfrontend                     running fwtk             |
for mailserver)                                            webserver
                                                           running
apache 1.3.20
 

                                                                                                                                
<-------------SSL-------------------------      
<------SSL-------             
http-service     <-<-<-<-<-<-<-<-<-<-<-< plug-gw -<-<-<-<-<-< apache 
-<-<-<-<--<-<-< browser
                                                           reverse-proxy


The client connects via https to a certain URL on the webserver.
The webserver is configured as reverse-Proxy. It passes the request of
this url to fw-gateway Port XY.
On the fw-gateway plug-gw passes connects on Port XY to the inner
http-service port 443.

The url on the webserver is configured with password-Protection. Since
this is ssl-connection i believe it is secure?
I believe the mod_proxy opens a new ssl-connection through plug-gw.
Plug-gw is configured to allow connects from the webserver only.
------------

Do i open some unwanted holes by this configuration? Are there drawbacks
you can warn me from? Any ideas and suggestions are appreciated.


Greetings from Wiesbaden, Germany

Markus


-- 
-------------------------------------------------------------------------
Dipl.-Inform. (FH)    ORDIX AG                                 \\|||//
Markus Schreier       Kreuzberger Ring 13   mailto:ms@ordix.de  o   ô
Consultant            D-65205 Wiesbaden     Tel:0611/77840-00     ^
Systeme & Netze       http://www.ordix.de   Fax:0611/77840-11   `---´
-------------------------------------------------------------------------

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Jan  4 22:57 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id WAA19836
	Fri, 4 Jan 2002 22:57:21 -0500 (EST)
Date: Fri, 4 Jan 2002 23:07:10 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] smap updates
Message-ID: <LISTMANAGER-303-324-2002.01.04-22.02.37--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1020
Status: RO

Just in case anyone is interested, I updated my smap program again.  These
updates dramatically improve the effectiveness of the content filtering
feature by now recognizing basic html tags (like &nbsp; and %quot;) and
now allow filters to pass across multiple input lines.  I've also redid
the algorithm and have significantly reduced the IO and computational
needs for the program.  It now runs nearly as fast as the unmodiffied smap
programs.

I've been running it stable for a week or so now - so I think the code is
pretty solid.  We are scrapping off > 30,000 unwanted spam messages - and
that has a direct impact on the support levels for mail adminstration.

I've also integrated the first of Rick Murphy's patches into the code.  I
will get more later.

If anyone is interested, let me know and I will tell you where to pick up
the code.

ted keller



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Sat Jan  5 15:12 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id PAA20848
	Sat, 5 Jan 2002 15:12:19 -0500 (EST)
Message-ID: <LISTMANAGER-303-325-2002.01.05-14.16.59--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Sat, 5 Jan 2002 12:21:46 -0800 (PST)
From: Naresh Narang <nknarang@yahoo.com>
Subject: [fwtk-users] Re: smap updates
To: "fwtk-users" <fwtk-users@listserv.nai.com>
In-Reply-To: <LISTMANAGER-395-324-2002.01.04-22.02.37--nknarang#yahoo.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 1480
Status: RO

Hi Ted,

I am interested.

Thanks
Naresh

--- Ted Keller <keller@bfg.com> wrote:
> Just in case anyone is interested, I updated my smap
> program again.  These
> updates dramatically improve the effectiveness of
> the content filtering
> feature by now recognizing basic html tags (like
> &nbsp; and %quot;) and
> now allow filters to pass across multiple input
> lines.  I've also redid
> the algorithm and have significantly reduced the IO
> and computational
> needs for the program.  It now runs nearly as fast
> as the unmodiffied smap
> programs.
> 
> I've been running it stable for a week or so now -
> so I think the code is
> pretty solid.  We are scrapping off > 30,000
> unwanted spam messages - and
> that has a direct impact on the support levels for
> mail adminstration.
> 
> I've also integrated the first of Rick Murphy's
> patches into the code.  I
> will get more later.
> 
> If anyone is interested, let me know and I will tell
> you where to pick up
> the code.
> 
> ted keller
> 
> 
> 
> ---
> You are currently subscribed to fwtk-users as:
> nknarang@yahoo.com
> To unsubscribe send a blank email to
leave-fwtk-users-303A@listserv.nai.com


=====
-- Naresh

__________________________________________________
Do You Yahoo!?
Send FREE video emails in Yahoo! Mail!
http://promo.yahoo.com/videomail/

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Sun Jan  6 17:00 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id RAA22273
	Sun, 6 Jan 2002 17:00:15 -0500 (EST)
Message-ID: <LISTMANAGER-303-326-2002.01.06-16.04.50--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Sun, 06 Jan 2002 17:09:39 -0500
From: Keith Young <kyoung@v-one.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Organization: V-ONE
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:0.9.7) Gecko/20011221
X-Accept-Language: en-us
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: smap updates
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Length: 963
Status: RO

Ted Keller wrote:

> Just in case anyone is interested, I updated my smap program again.  These
> updates dramatically improve the effectiveness of the content filtering
> feature by now recognizing basic html tags (like &nbsp; and %quot;) and
> now allow filters to pass across multiple input lines.  I've also redid
> the algorithm and have significantly reduced the IO and computational
> needs for the program.  It now runs nearly as fast as the unmodiffied smap
> programs.
	<snip>
> If anyone is interested, let me know and I will tell you where to pick up
> the code.
> 


Ted,

When it gets to a "stable" point, send it to me and I'll add it to the 
list of batch updates for FWTK.ORG...

(P.S. I am still working to get FWTK to have a GNU-like license...)

-- 
--Keith Young
-kyoung@v-one.com



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Sun Jan  6 18:39 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id SAA22378
	Sun, 6 Jan 2002 18:39:58 -0500 (EST)
Date: Sun, 6 Jan 2002 18:50:12 -0500 (EST)
From: Ted Keller <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: smap updates
In-Reply-To: <LISTMANAGER-13-326-2002.01.06-16.04.50--keller#bfg.com@listserv.nai.com>
Message-ID: <LISTMANAGER-303-327-2002.01.06-17.45.25--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: TEXT/PLAIN; charset=US-ASCII
Content-Length: 1564
Status: RO

Keith,

the patches are so large that I tend to pass it out as complete source
tarball - just for the smap/smapd part.  There are also additional source
programs not part of the original fwtk that help make up this package.
I've hesitated posting a public version due to possible tis licensing
issues.  Your closer to this than I am, what do your recommend?

tek


On Sun, 6 Jan 2002, Keith Young wrote:

> Ted Keller wrote:
>
> > Just in case anyone is interested, I updated my smap program again.  These
> > updates dramatically improve the effectiveness of the content filtering
> > feature by now recognizing basic html tags (like &nbsp; and %quot;) and
> > now allow filters to pass across multiple input lines.  I've also redid
> > the algorithm and have significantly reduced the IO and computational
> > needs for the program.  It now runs nearly as fast as the unmodiffied smap
> > programs.
> 	<snip>
> > If anyone is interested, let me know and I will tell you where to pick up
> > the code.
> >
>
>
> Ted,
>
> When it gets to a "stable" point, send it to me and I'll add it to the
> list of batch updates for FWTK.ORG...
>
> (P.S. I am still working to get FWTK to have a GNU-like license...)
>
> --
> --Keith Young
> -kyoung@v-one.com
>
>
>
> ---
> You are currently subscribed to fwtk-users as: keller@bfg.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan  7 02:09 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id CAA23329
	Mon, 7 Jan 2002 02:09:30 -0500 (EST)
Message-ID: <LISTMANAGER-303-328-2002.01.07-01.14.05--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "MARCON Michel, CETU/SG/Informatique"
	 <Michel.Marcon@equipement.gouv.fr>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RE: smap updates
Date: Mon, 7 Jan 2002 08:18:21 +0100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id CAA23329
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1507
Status: RO

Hi.

I'm interested to get your version of Smap. Where is it ???
TYA

> -----Message d'origine-----
> De : Ted Keller [mailto:keller@bfg.com]
> Envoyé : samedi 5 janvier 2002 05:07
> À : fwtk-users
> Objet : [fwtk-users] smap updates
> 
> 
> Just in case anyone is interested, I updated my smap program 
> again.  These
> updates dramatically improve the effectiveness of the content 
> filtering
> feature by now recognizing basic html tags (like &nbsp; and 
> %quot;) and
> now allow filters to pass across multiple input lines.  I've 
> also redid
> the algorithm and have significantly reduced the IO and computational
> needs for the program.  It now runs nearly as fast as the 
> unmodiffied smap
> programs.
> 
> I've been running it stable for a week or so now - so I think 
> the code is
> pretty solid.  We are scrapping off > 30,000 unwanted spam 
> messages - and
> that has a direct impact on the support levels for mail adminstration.
> 
> I've also integrated the first of Rick Murphy's patches into 
> the code.  I
> will get more later.
> 
> If anyone is interested, let me know and I will tell you 
> where to pick up
> the code.
> 
> ted keller
> 
> 
> 
> ---
> You are currently subscribed to fwtk-users as: 
> Michel.Marcon@equipement.gouv.fr
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan  7 02:23 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id CAA23343
	Mon, 7 Jan 2002 02:23:27 -0500 (EST)
From: Lutz Kittler <Lutz.Kittler@sse-erfurt.de>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Message-ID: <LISTMANAGER-303-329-2002.01.07-01.28.09--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 7 Jan 2002 08:32:50 +0100 (MET)
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] smap updates
In-Reply-To: <LISTMANAGER-313-324-2002.01.04-22.02.37--Lutz.Kittler#sse-erfurt.de@listserv.nai.com>
X-Mailer: VM 6.75 under 21.1 (patch 7) "Biscayne" XEmacs Lucid
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 1147
Status: RO

Ted Keller writes:
 > Just in case anyone is interested, I updated my smap program again.  These
 > updates dramatically improve the effectiveness of the content filtering
 > feature by now recognizing basic html tags (like &nbsp; and %quot;) and
 > now allow filters to pass across multiple input lines.  I've also redid
 > the algorithm and have significantly reduced the IO and computational
 > needs for the program.  It now runs nearly as fast as the unmodiffied smap
 > programs.
 > 
 > I've been running it stable for a week or so now - so I think the code is
 > pretty solid.  We are scrapping off > 30,000 unwanted spam messages - and
 > that has a direct impact on the support levels for mail adminstration.
 > 
 > I've also integrated the first of Rick Murphy's patches into the code.  I
 > will get more later.
 > 
 > If anyone is interested, let me know and I will tell you where to pick up
 > the code.
 > 
 > ted keller
 > 
 > 
 > 

Hi.

I'm also interested .

      lutz


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan  7 09:18 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA24977
	Mon, 7 Jan 2002 09:18:52 -0500 (EST)
Message-ID: <LISTMANAGER-303-330-2002.01.07-08.23.26--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: smap updates
Date: Mon, 7 Jan 2002 09:30:18 -0500
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-Mimeole: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1506
Status: RO

Hi Ted,

You know I am definitely interested.  Are the changes/additions documented?

Thanks,
Don

----- Original Message ----- 
From: "Ted Keller" <keller@bfg.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Sent: Friday, January 04, 2002 11:07 PM
Subject: [fwtk-users] smap updates


> Just in case anyone is interested, I updated my smap program again.  These
> updates dramatically improve the effectiveness of the content filtering
> feature by now recognizing basic html tags (like &nbsp; and %quot;) and
> now allow filters to pass across multiple input lines.  I've also redid
> the algorithm and have significantly reduced the IO and computational
> needs for the program.  It now runs nearly as fast as the unmodiffied smap
> programs.
> 
> I've been running it stable for a week or so now - so I think the code is
> pretty solid.  We are scrapping off > 30,000 unwanted spam messages - and
> that has a direct impact on the support levels for mail adminstration.
> 
> I've also integrated the first of Rick Murphy's patches into the code.  I
> will get more later.
> 
> If anyone is interested, let me know and I will tell you where to pick up
> the code.
> 
> ted keller
> 
> 
> 
> ---
> You are currently subscribed to fwtk-users as: don@lclcan.com
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
> 


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan  7 14:04 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id OAA25834
	Mon, 7 Jan 2002 14:04:36 -0500 (EST)
From: ark@eltex.ru
Message-Id: <LISTMANAGER-303-331-2002.01.07-13.10.03--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Subject: [fwtk-users] Re: smap updates
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Date: Sat, 5 Jan 2002 14:15:52 +0300 (MSK)
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
In-Reply-To: <LISTMANAGER-333-324-2002.01.04-22.02.37--ark#eltex.ru@listserv.nai.com> from "Ted Keller" at Jan 04, 2002 11:07:10 PM
X-Mailer: ELM [version 2.5 PL3]
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by Eltex TC
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 1760
Status: RO

Yes, i'm interested.
BTW maybe it's better idea to use html filter from squid-gw?
It is modular so it should not be difficult to do.

P.S. have you seen netperm-table controlled smtpd/smtpfwdd?

YOU (Ted Keller) WROTE:
>  
>  Just in case anyone is interested, I updated my smap program again.  These
>  updates dramatically improve the effectiveness of the content filtering
>  feature by now recognizing basic html tags (like &nbsp; and %quot;) and
>  now allow filters to pass across multiple input lines.  I've also redid
>  the algorithm and have significantly reduced the IO and computational
>  needs for the program.  It now runs nearly as fast as the unmodiffied smap
>  programs.
>  
>  I've been running it stable for a week or so now - so I think the code is
>  pretty solid.  We are scrapping off > 30,000 unwanted spam messages - and
>  that has a direct impact on the support levels for mail adminstration.
>  
>  I've also integrated the first of Rick Murphy's patches into the code.  I
>  will get more later.
>  
>  If anyone is interested, let me know and I will tell you where to pick up
>  the code.
>  
>  ted keller
>  
>  
>  
>  ---
>  You are currently subscribed to fwtk-users as: ark@eltex.ru
>  To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
>  


-- 
                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Jan  9 12:35 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id MAA00967
	Wed, 9 Jan 2002 12:35:22 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-339-2002.01.09-11.40.14--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: smap updates
Date: Wed, 9 Jan 2002 09:46:07 -0800 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2276
Status: RO

I'd like to get a copy of your updated smap if I may.  Also, would it be
possible to see the settings you are using for it in the netperm-table?

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

> -----Original Message-----
> From: Ted Keller [mailto:keller@bfg.com] 
> Sent: Sunday, January 06, 2002 3:50 PM
> To: fwtk-users
> Subject: [fwtk-users] Re: smap updates
> 
> 
> Keith,
> 
> the patches are so large that I tend to pass it out as complete source
> tarball - just for the smap/smapd part.  There are also 
> additional source
> programs not part of the original fwtk that help make up this package.
> I've hesitated posting a public version due to possible tis licensing
> issues.  Your closer to this than I am, what do your recommend?
> 
> tek
> 
> 
> On Sun, 6 Jan 2002, Keith Young wrote:
> 
> > Ted Keller wrote:
> >
> > > Just in case anyone is interested, I updated my smap 
> program again.  These
> > > updates dramatically improve the effectiveness of the 
> content filtering
> > > feature by now recognizing basic html tags (like &nbsp; 
> and %quot;) and
> > > now allow filters to pass across multiple input lines.  
> I've also redid
> > > the algorithm and have significantly reduced the IO and 
> computational
> > > needs for the program.  It now runs nearly as fast as the 
> unmodiffied smap
> > > programs.
> > 	<snip>
> > > If anyone is interested, let me know and I will tell you 
> where to pick up
> > > the code.
> > >
> >
> >
> > Ted,
> >
> > When it gets to a "stable" point, send it to me and I'll 
> add it to the
> > list of batch updates for FWTK.ORG...
> >
> > (P.S. I am still working to get FWTK to have a GNU-like license...)
> >
> > --
> > --Keith Young
> > -kyoung@v-one.com
> >
> >
> >
> > ---
> > You are currently subscribed to fwtk-users as: keller@bfg.com
> > To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> >
> 
> 
> ---
> You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Jan 10 05:45 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id FAA02551
	Thu, 10 Jan 2002 05:45:28 -0500 (EST)
From: "Mathias Haas" <mathias.haas@ue.sr.se>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Fwtk and encypted FTP
Date: Thu, 10 Jan 2002 11:56:40 +0100
Message-ID: <LISTMANAGER-303-340-2002.01.10-04.50.05--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Importance: Normal
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 627
Status: RO

Hello!

Maybe this has been up before, and it's not my main skillarea, but is it
possible to run encrypted FTP through FWTK somehow (like MD4/MD5) ?

Has anyone tried other methods, like SSH or SafeTP through FWTK, are there
any problems?

I'm probably stretching it here, but would it be possible to run encrypted
FTP *to* FWTK and then run unencrypted from there to the real FTP-server, if
the FTP-server doesn't support encryption...

Kind regards,
Mathias Haas.



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 08:54 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id IAA10400
	Mon, 14 Jan 2002 08:54:24 -0500 (EST)
Message-ID: <LISTMANAGER-303-341-2002.01.14-07.59.29--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 14 Jan 2002 15:04:52 +0100
From: Markus Schreier <ms@ordix.de>
Organization: ORDIX AG
X-Mailer: Mozilla 4.7 [de] (WinNT; I)
X-Accept-Language: de
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Reverse-Proxy witch apache
Content-Transfer-Encoding: 8bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 3272
Status: RO

Hello all,
please excuse me asking this question again. It is important to me.
i've asked this question on the first working day in this year. I
believe, that most people where still on holiday or had to work up all
things which have piled up.
Any answer would be welcome.

Thanks a lot

Markus

-------- Original Message --------
Betreff: [fwtk-users] Reverse-Proxy witch apache
Datum: Wed, 02 Jan 2002 13:21:33 +0100
Von: Markus Schreier <ms@ordix.de>
Rückantwort: "fwtk-users" <fwtk-users@listserv.nai.com>
Firma: ORDIX AG
An: "fwtk-users" <fwtk-users@listserv.nai.com>

Hello all,
and happy new year to all of you.

I'd like to setup some way to provide Services from the inner network to
people on the internet.
This setup should 
* only allow authorized people
* be secure

I've been playing with the following setup and would like you to provide
me whith any thoughts to that subject, which come to your mind.


                                           |
internal network                          
|                                         internet
                                           |
                                           
http-service      -------------------  fw-gateway   
----------+--------/\/\/\------ client
(e.g. webfrontend                     running fwtk             |
for mailserver)                                            webserver
                                                           running
apache 1.3.20
 

                                                                                                                                
<-------------SSL-------------------------      
<------SSL-------             
http-service     <-<-<-<-<-<-<-<-<-<-<-< plug-gw -<-<-<-<-<-< apache 
-<-<-<-<--<-<-< browser
                                                           reverse-proxy


The client connects via https to a certain URL on the webserver.
The webserver is configured as reverse-Proxy. It passes the request of
this url to fw-gateway Port XY.
On the fw-gateway plug-gw passes connects on Port XY to the inner
http-service port 443.

The url on the webserver is configured with password-Protection. Since
this is ssl-connection i believe it is secure?
I believe the mod_proxy opens a new ssl-connection through plug-gw.
Plug-gw is configured to allow connects from the webserver only.
------------

Do i open some unwanted holes by this configuration? Are there drawbacks
you can warn me from? Any ideas and suggestions are appreciated.


Greetings from Wiesbaden, Germany

Markus


-- 
-------------------------------------------------------------------------
Dipl.-Inform. (FH)    ORDIX AG                                 \\|||//
Markus Schreier       Kreuzberger Ring 13   mailto:ms@ordix.de  o   ô
Consultant            D-65205 Wiesbaden     Tel:0611/77840-00     ^
Systeme & Netze       http://www.ordix.de   Fax:0611/77840-11   `---´
-------------------------------------------------------------------------

---
You are currently subscribed to fwtk-users as: ms@ordix.de
To unsubscribe send a blank email to
leave-fwtk-users-303A@listserv.nai.com

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 09:43 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA10457
	Mon, 14 Jan 2002 09:43:00 -0500 (EST)
From: "Luis Fernando Barrera" <luba@assist.com.gt>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RE: Reverse-Proxy witch apache
Date: Mon, 14 Jan 2002 08:55:35 -0600
Message-ID: <LISTMANAGER-303-342-2002.01.14-08.47.36--fwtk-archive#lists.tislabs.com@listserv.nai.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200
Importance: Normal
In-Reply-To: <LISTMANAGER-501-341-2002.01.14-07.59.29--luba#assist.com.gt@listserv.nai.com>
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 3581
Status: RO

I have a fw configured in a similar way...

I'd like to ask you some questions:

1) do you have a full web server running at your firewall?
2) If not, what piece of software do you use to provide the reverse proxy?
Plug-gw?


Regards,

Luis Fernando Barrera
luba@assist.com.gt

-----Original Message-----
From: Markus Schreier [mailto:ms@ordix.de]
Sent: Monday, January 14, 2002 08:05
To: fwtk-users
Subject: [fwtk-users] Reverse-Proxy witch apache


Hello all,
please excuse me asking this question again. It is important to me.
i've asked this question on the first working day in this year. I
believe, that most people where still on holiday or had to work up all
things which have piled up.
Any answer would be welcome.

Thanks a lot

Markus

-------- Original Message --------
Betreff: [fwtk-users] Reverse-Proxy witch apache
Datum: Wed, 02 Jan 2002 13:21:33 +0100
Von: Markus Schreier <ms@ordix.de>
Rückantwort: "fwtk-users" <fwtk-users@listserv.nai.com>
Firma: ORDIX AG
An: "fwtk-users" <fwtk-users@listserv.nai.com>

Hello all,
and happy new year to all of you.

I'd like to setup some way to provide Services from the inner network to
people on the internet.
This setup should
* only allow authorized people
* be secure

I've been playing with the following setup and would like you to provide
me whith any thoughts to that subject, which come to your mind.


                                           |internal network
|                                         internet
                                           |

http-service      -------------------
w-gateway   ----------+--------/\/\/\------ client(e.g. webfrontend
running fwtk             |for mailserver)
webserver                                                           running
apache 1.3.20



<-------------SSL-------------------------
<------SSL-------
http-service     <-<-<-<-<-<-<-<-<-<-<-< plug-gw -<-<-<-<-<-< apache
-<-<-<-<--<-<-< browser
                                                           reverse-proxy


The client connects via https to a certain URL on the webserver.
The webserver is configured as reverse-Proxy. It passes the request of
this url to fw-gateway Port XY.
On the fw-gateway plug-gw passes connects on Port XY to the inner
http-service port 443.

The url on the webserver is configured with password-Protection. Since
this is ssl-connection i believe it is secure?
I believe the mod_proxy opens a new ssl-connection through plug-gw.
Plug-gw is configured to allow connects from the webserver only.
------------

Do i open some unwanted holes by this configuration? Are there drawbacks
you can warn me from? Any ideas and suggestions are appreciated.


Greetings from Wiesbaden, Germany

Markus


--
-------------------------------------------------------------------------
Dipl.-Inform. (FH)    ORDIX AG                                 \\|||//
Markus Schreier       Kreuzberger Ring 13   mailto:ms@ordix.de  o   ô
Consultant            D-65205 Wiesbaden     Tel:0611/77840-00     ^
Systeme & Netze       http://www.ordix.de   Fax:0611/77840-11   `---´
-------------------------------------------------------------------------

---
You are currently subscribed to fwtk-users as: ms@ordix.de
To unsubscribe send a blank email to
leave-fwtk-users-303A@listserv.nai.com

---
You are currently subscribed to fwtk-users as: luba@assist.com.gt
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 10:06 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id KAA10491
	Mon, 14 Jan 2002 10:06:16 -0500 (EST)
Message-ID: <LISTMANAGER-303-343-2002.01.14-09.10.54--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 14 Jan 2002 16:16:14 +0100
From: Markus Schreier <ms@ordix.de>
Organization: ORDIX AG
X-Mailer: Mozilla 4.7 [de] (WinNT; I)
X-Accept-Language: de
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RE: Reverse-Proxy witch apache
Content-Transfer-Encoding: 8bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 3706
Status: RO

Hello,

Luis Fernando Barrera schrieb:
> 
> I have a fw configured in a similar way...
> 
> I'd like to ask you some questions:
> 
> 1) do you have a full web server running at your firewall?
Well it runn's on a seperate Linux-System outside the firewall. First of
all it is meant 
to provide Webservice.
It ist an self-compiled apache server on security- updated RedHat Linux
6.2

> 2) If not, what piece of software do you use to provide the reverse proxy?
> Plug-gw?
> 
> Regards,
> 
> Luis Fernando Barrera
> luba@assist.com.gt

Regards,

Markus
> 
> -----Original Message-----
> From: Markus Schreier [mailto:ms@ordix.de]
> Sent: Monday, January 14, 2002 08:05
> To: fwtk-users
> Subject: [fwtk-users] Reverse-Proxy witch apache
> 
> Hello all,
> please excuse me asking this question again. It is important to me.
> i've asked this question on the first working day in this year. I
> believe, that most people where still on holiday or had to work up all
> things which have piled up.
> Any answer would be welcome.
> 
> Thanks a lot
> 
> Markus
> 
> -------- Original Message --------
> Betreff: [fwtk-users] Reverse-Proxy witch apache
> Datum: Wed, 02 Jan 2002 13:21:33 +0100
> Von: Markus Schreier <ms@ordix.de>
> Rückantwort: "fwtk-users" <fwtk-users@listserv.nai.com>
> Firma: ORDIX AG
> An: "fwtk-users" <fwtk-users@listserv.nai.com>
> 
> Hello all,
> and happy new year to all of you.
> 
> I'd like to setup some way to provide Services from the inner network to
> people on the internet.
> This setup should
> * only allow authorized people
> * be secure
> 
> I've been playing with the following setup and would like you to provide
> me whith any thoughts to that subject, which come to your mind.
> 
>                                            |internal network
> |                                         internet
>                                            |
> 
> http-service      -------------------
> w-gateway   ----------+--------/\/\/\------ client(e.g. webfrontend
> running fwtk             |for mailserver)
> webserver                                                           running
> apache 1.3.20
> 
> <-------------SSL-------------------------
> <------SSL-------
> http-service     <-<-<-<-<-<-<-<-<-<-<-< plug-gw -<-<-<-<-<-< apache
> -<-<-<-<--<-<-< browser
>                                                            reverse-proxy
> 
> The client connects via https to a certain URL on the webserver.
> The webserver is configured as reverse-Proxy. It passes the request of
> this url to fw-gateway Port XY.
> On the fw-gateway plug-gw passes connects on Port XY to the inner
> http-service port 443.
> 
> The url on the webserver is configured with password-Protection. Since
> this is ssl-connection i believe it is secure?
> I believe the mod_proxy opens a new ssl-connection through plug-gw.
> Plug-gw is configured to allow connects from the webserver only.
> ------------
> 
> Do i open some unwanted holes by this configuration? Are there drawbacks
> you can warn me from? Any ideas and suggestions are appreciated.
> 
> Greetings from Wiesbaden, Germany
> 
> Markus
> 
-- 
-------------------------------------------------------------------------
Dipl.-Inform. (FH)    ORDIX AG                                 \\|||//
Markus Schreier       Kreuzberger Ring 13   mailto:ms@ordix.de  o   ô
Consultant            D-65205 Wiesbaden     Tel:0611/77840-00     ^
Systeme & Netze       http://www.ordix.de   Fax:0611/77840-11   `---´
-------------------------------------------------------------------------

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 12:40 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id MAA10682
	Mon, 14 Jan 2002 12:40:47 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-344-2002.01.14-11.45.07--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Does anyone know about "ort-r01.mx.aol.com"?
Date: Mon, 14 Jan 2002 09:51:19 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 559
Status: RO

Does anyone know anything about the host system "ort-r01.mx.aol.com"?  I
keep getting connection attempts from it which are denied by smap due to a
relay attempt.  It appears to be a legitimate AOL server and I find it very
disturbing that they've initiated probing our firewall without permission.

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 12:48 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id MAA10708
	Mon, 14 Jan 2002 12:48:31 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-345-2002.01.14-11.53.08--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Suggestions for better spam filtering
Date: Mon, 14 Jan 2002 09:59:16 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1228
Status: RO

Currently I'm using the following blocklists for smap spam filtering:

smap:           block-list "ORL" block .relays.osirusoft.com:127.0.0.2
"%s/%s was found in the Osirusoft relays list (see
http://relays.osirusoft.com/)"
smap:           block-list "ORD" block .dialups.osirusoft.com "%s/%s was
found in the Osirusoft dialups list (see http://relays.osirusoft.com/)"
smap:           block-list "ORS" block .spamsites..relays.osirusoft.com
"%s/%s was found in the Spamhouse blocking list (see
http://relays.osirusoft.com/)"
smap:           block-list "SBL" block .spamhaus.relays.osirusoft.com "%s/%s
was found in the SPAMHAUS.ORG spamsource list (see
http://www.spamhaus.org/sbl/)"
smap:           block-list "SPEWS" block .spews.relays.osirusoft.com "%s/%s
wasfound in the SPEWS.ORG spamsource list (see http://www.spews.org/)"

Only the SPEWS list does much blocking at all.  I've been asked to see if
there isn't a better list available.  Any suggestions anyone?

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 13:04 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id NAA10788
	Mon, 14 Jan 2002 13:04:00 -0500 (EST)
Message-ID: <LISTMANAGER-303-346-2002.01.14-12.08.42--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 14 Jan 2002 19:13:59 +0100
From: Markus Schreier <ms@ordix.de>
Organization: ORDIX AG
X-Mailer: Mozilla 4.7 [de] (WinNT; I)
X-Accept-Language: de
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: FW: RE: Reverse-Proxy witch apache
References: <NABBIDJPNCAGKGOFGHBFGEHLPEAA.luba@assist.com.gt>
Content-Transfer-Encoding: 8bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=iso-8859-1
Content-Length: 2756
Status: RO

Hello Luis, 
thanks for your responses, I'm including the list, perhaps someone else
is interested 
in our talk.

Luis Fernando Barrera schrieb:
> 
> Hi,
> 
> So, you have a web server outside the firewall, that forwards
> all the incomming connections on port 443 to a plug-gw at the
> firewall, which redirects the connections to the internal web server, right?

yes, that's it. The internal webserver is being connected via ssl as
well.

> First, I think there's too much overhead having an external web server. Why
> don't
> you redirect all the requests from the clients, directly to the firewall?

The Web-Server is given anyway. It is used for being webserver first of
all. I only use one URL-Path inside the webserver for redirecting. I
believe useing apache for redirecting, gives me two seperate
ssl-Connections: One from Client to external Apache Server the other
from the external server through the firewall to the internal server. I
thought that's cute. I hope, apache doesen't do the redirecting job
blindly and only redirects requests which are somewhat http-alike. Which
may be better than no filtering at all?
 
> Another point, which is worth to talk about, is that maybe you should
> consider
> putting the internal web server in a separate segment, besides the internal
> network. Remember that most of the attacks to the web servers, are based
> on the http protocol, so in case the web server is compromised, it remains
> isolated from the other internal servers.
That is a good point. The draw back is, the internal server does not
only have 
static pages. But it helps, having a mail to show up with, which argues
in that direction.
> 
> Also, there is a program called http-in, which is "part" of the
> fwtk, which has the function of redirecting external http requests to
> an internal web server. I don't remember if it can redirect SSL connections,
> but you can take a look at it. It's located
> http://www.fwtk.org/fwtk/patches/patches.html#3.9

That realy is a good information too. I didn't know of that proxy and
will have a look at it in near future.

> Regards,
> 
> Luis Fernando Barrera
> luba@assist.com.gt

Regards,

Markus 

-- 
-------------------------------------------------------------------------
Dipl.-Inform. (FH)    ORDIX AG                                 \\|||//
Markus Schreier       Kreuzberger Ring 13   mailto:ms@ordix.de  o   ô
Consultant            D-65205 Wiesbaden     Tel:0611/77840-00     ^
Systeme & Netze       http://www.ordix.de   Fax:0611/77840-11   `---´
-------------------------------------------------------------------------

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 14:37 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id OAA10972
	Mon, 14 Jan 2002 14:37:03 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-347-2002.01.14-13.41.41--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Possible bug in the smap RBL style lookup patch
Date: Mon, 14 Jan 2002 11:48:11 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 2678
Status: RO

Recently a piece of spam was received here that I believe should have been
caught by the RBL DNS lookup style spam patch but was not.  I have the
following in my netperm-table file:

smap:           block-list "OSRELAY" block .relays.osirusoft.com:127.0.0.2
"%s/%s was found in the Osirusoft Verified Open Relays list (see
http://relays.osirusoft.com/)"
smap:           block-list "OSDUL" block .relays.osirusoft.com:127.0.0.3
"%s/%swas found in the Osirusoft Dialup Spam Source list (see
http://relays.osirusoft.com/)"
smap:           block-list "OSSRC" block .relays.osirusoft.com:127.0.0.4
"%s/%swas found in the Osirusoft Confirmed Spam Source list (see
http://relays.osirusoft.com/)"
smap:           block-list "OSSOFT" block .relays.osirusoft.com:127.0.0.6
"%s/%s was found in the Osirusoft Spamware Software Developers list (see
http://relays.osirusoft.com/)"
smap:           block-list "OSPROXY" block .relays.osirusoft.com:127.0.0.9
"%s/%s was found in the Osirusoft Open Proxy Servers list (see
http://relays.osirusoft.com/)"
smap:           block-list "SPEWS" block .spews.relays.osirusoft.com "%s/%s
wasfound in the SPEWS.ORG spamsource list (see http://www.spews.org/)"


But the following managed to slip through:

Jan 12 11:25:07 guardian smap[4832]: securityalert: possible spoof
icc.icc-conventions.net/216.151.192.26 != 216.139.200.251 name lookup
mismatch
Jan 12 11:25:07 guardian smap[4832]: connect host=unknown/216.151.192.26
Jan 12 11:25:07 guardian smap[4832]: EHLO icc.icc-conventions.net
host=unknown/216.151.192.26
Jan 12 11:25:07 guardian smap[4832]: mail from: <akljsghiure@home.ro>
address=216.151.192.26 host=unknown
Jan 12 11:25:07 guardian smap[4832]: checking address
<akljsghiure@home.ro>/home.ro
Jan 12 11:25:07 guardian smap[4832]: RCPT TO: <cinda@hartwellcorp.com>
Jan 12 11:25:09 guardian smap[4832]: permit host=unknown/216.151.192.26 use
of gateway
Jan 12 11:25:09 guardian smap[4832]: host=unknown/216.151.192.26 bytes=2027
from=<akljsghiure@home.ro> to=<cinda@hartwellcorp.com> xma004832
Jan 12 11:25:09 guardian smap[4832]: exiting host=unknown/216.151.192.26
bytes=2027
Jan 12 11:25:34 guardian smapd[4833]: delivered file=sma004832 pid=4834
code=0


However, a check with the osirusoft database shows that the OSRELAY rule
should have caught this one.  Is it possible that the spoofing on the first
line of the log messages prevented the DNS check from working correctly?

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 21:48 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id VAA11754
	Mon, 14 Jan 2002 21:48:28 -0500 (EST)
Message-Id: <LISTMANAGER-303-348-2002.01.14-20.53.10--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 14 Jan 2002 21:49:17 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Does anyone know about "ort-r01.mx.aol.com"?
In-Reply-To: <LISTMANAGER-602-344-2002.01.14-11.45.07--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 761
Status: RO

At 09:51 AM 1/14/02 -0800, Michael St. Laurent wrote:
>Does anyone know anything about the host system "ort-r01.mx.aol.com"?  I
>keep getting connection attempts from it which are denied by smap due to a
>relay attempt.  It appears to be a legitimate AOL server and I find it very
>disturbing that they've initiated probing our firewall without permission.

ORT - "open relay test".
They do probe systems that deliver mail to them. There's a way that you can 
opt out of the probing - see 
<http://postmaster.info.aol.com/index.cfm?article=8> - but then AOL will 
refuse mail from you.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jan 14 21:51 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id VAA11759
	Mon, 14 Jan 2002 21:51:03 -0500 (EST)
Message-Id: <LISTMANAGER-303-349-2002.01.14-20.53.11--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Mon, 14 Jan 2002 21:55:13 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Possible bug in the smap RBL style lookup
  patch
In-Reply-To: <LISTMANAGER-602-347-2002.01.14-13.41.41--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 971
Status: RO

At 11:48 AM 1/14/02 -0800, Michael St. Laurent wrote:
>Recently a piece of spam was received here that I believe should have been
>caught by the RBL DNS lookup style spam patch but was not.  I have the
>following in my netperm-table file:
...
>However, a check with the osirusoft database shows that the OSRELAY rule
>should have caught this one.  Is it possible that the spoofing on the first
>line of the log messages prevented the DNS check from working correctly?

That's strange - the entry in relays.osirusoft.com is there and returns the 
right value; it was added/updated on 12 December, so it's not a new entry.
The RBL lookups always use the source IP only - the failed reverse DNS 
lookup doesn't make a difference.

About my only guess is a nameserver hiccup of some kind or another.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Jan 15 12:57 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id MAA13756
	Tue, 15 Jan 2002 12:57:19 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-353-2002.01.15-12.02.15--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Does anyone know about "ort-r01.mx.aol.com"?
Date: Tue, 15 Jan 2002 10:08:49 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1632
Status: RO

That's interesting.  We've been having trouble sending them mail for about a
month and a half now.  Some of our mail gets there and some of it doesn't.
In either case, they don't give an error.  They accept the mail and our logs
show "stat=Sent (OK)" giving us no clue what the problem might be.  I wonder
if the two things might be related.


--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

> -----Original Message-----
> From: Rick Murphy [mailto:rmurphy@itm-inst.com] 
> Sent: Monday, January 14, 2002 6:49 PM
> To: fwtk-users
> Subject: [fwtk-users] Re: Does anyone know about "ort-r01.mx.aol.com"?
> 
> 
> At 09:51 AM 1/14/02 -0800, Michael St. Laurent wrote:
> >Does anyone know anything about the host system 
> "ort-r01.mx.aol.com"?  I
> >keep getting connection attempts from it which are denied by 
> smap due to a
> >relay attempt.  It appears to be a legitimate AOL server and 
> I find it very
> >disturbing that they've initiated probing our firewall 
> without permission.
> 
> ORT - "open relay test".
> They do probe systems that deliver mail to them. There's a 
> way that you can 
> opt out of the probing - see 
> <http://postmaster.info.aol.com/index.cfm?article=8> - but 
> then AOL will 
> refuse mail from you.
>          -Rick
> 
> 
> ---
> You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Jan 15 13:11 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id NAA13783
	Tue, 15 Jan 2002 13:11:47 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-354-2002.01.15-12.16.16--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Possible bug in the smap RBL style lookup pa
     tch
Date: Tue, 15 Jan 2002 10:22:25 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1619
Status: RO

OK, but your code is using the actual IP address of the sender and not the
spoofed IP address, yes?

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

> -----Original Message-----
> From: Rick Murphy [mailto:rmurphy@itm-inst.com] 
> Sent: Monday, January 14, 2002 6:55 PM
> To: fwtk-users
> Subject: [fwtk-users] Re: Possible bug in the smap RBL style 
> lookup patch
> 
> 
> At 11:48 AM 1/14/02 -0800, Michael St. Laurent wrote:
> >Recently a piece of spam was received here that I believe 
> should have been
> >caught by the RBL DNS lookup style spam patch but was not.  
> I have the
> >following in my netperm-table file:
> ...
> >However, a check with the osirusoft database shows that the 
> OSRELAY rule
> >should have caught this one.  Is it possible that the 
> spoofing on the first
> >line of the log messages prevented the DNS check from 
> working correctly?
> 
> That's strange - the entry in relays.osirusoft.com is there 
> and returns the 
> right value; it was added/updated on 12 December, so it's not 
> a new entry.
> The RBL lookups always use the source IP only - the failed 
> reverse DNS 
> lookup doesn't make a difference.
> 
> About my only guess is a nameserver hiccup of some kind or another.
>          -Rick
> 
> 
> ---
> You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Jan 15 14:44 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id OAA13933
	Tue, 15 Jan 2002 14:44:20 -0500 (EST)
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-355-2002.01.15-13.48.48--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Log file analysis scripts?
Date: Tue, 15 Jan 2002 11:55:12 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 485
Status: RO

Is there a collection of log file analysis scripts anywhere?  I have the
summary script written in perl but I need something to make sense of the
http-gw logs that will show the when and for how long the sites were
visited. 

--------------------
Michael St. Laurent
Hartwell Corporation

[root@earth] root# rm -rf /bin/laden

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Jan 15 17:15 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id RAA14168
	Tue, 15 Jan 2002 17:15:43 -0500 (EST)
Message-Id: <LISTMANAGER-303-356-2002.01.15-16.20.10--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Tue, 15 Jan 2002 17:23:13 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Possible bug in the smap RBL style lookup
  pa tch
In-Reply-To: <LISTMANAGER-602-354-2002.01.15-12.16.16--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 357
Status: RO

At 10:22 AM 1/15/02 -0800, Michael St. Laurent wrote:
>OK, but your code is using the actual IP address of the sender and not the
>spoofed IP address, yes?

Yes, the actual address.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Jan 30 08:12 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id IAA20436
	Wed, 30 Jan 2002 08:12:06 -0500 (EST)
Message-ID: <LISTMANAGER-303-359-2002.01.30-07.17.08--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Michel.Marcon@equipement.gouv.fr
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Usage of authsrv and time
Date: Wed, 30 Jan 2002 14:22:27 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 580
Status: RO

Hello.

I want to start and stop ftp-gw service (I use ftp-gw thru authsrv) only on
certain hours of the day.
I noticed the "time" option of authsrv for that pupose; it mut be used with
the -extnd option of ftp-gw. But I am unable to make it work.
Anyone has a solution for this kind of problem ??

TYA

--------------------------
Michel Marcon
SysAdmin Unix & Windows NT
Ministere Equipement, CETU
Tel (33) 04 7214-3408

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Jan 30 18:32 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id SAA21939
	Wed, 30 Jan 2002 18:32:38 -0500 (EST)
Message-Id: <LISTMANAGER-303-360-2002.01.30-17.36.52--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 30 Jan 2002 18:32:32 -0500
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: Usage of authsrv and time
In-Reply-To: <LISTMANAGER-602-359-2002.01.30-07.17.08--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1350
Status: RO

At 02:22 PM 1/30/02 +0100, Michel.Marcon@equipement.gouv.fr wrote:
>Hello.
>
>I want to start and stop ftp-gw service (I use ftp-gw thru authsrv) only on
>certain hours of the day.
>I noticed the "time" option of authsrv for that pupose; it mut be used with
>the -extnd option of ftp-gw. But I am unable to make it work.
>Anyone has a solution for this kind of problem ??

I've never tried to make this work, but here's how it's supposed to work.

You must run ftp-gw with the -extnd option.

You have authsrv lines in the netperm-table like:

authsrv:        permit-unknown unauth
authsrv:        permit-operation ftp-gw user <user> <command> <dest> <tokens>
authsrv:        permit-operation ftp-gw group <group> <command> <dest> <tokens>

The first line is required if you don't enable authentication. In that 
case, the only form of the "operation" line that works is the "user unauth" 
type.

For ftp-gw, "<command>" can be RETR, STOR, etc.
The "<tokens>" field should be something like
         time 17:00 23:59
to allow time between 17:00 and 23:59

If you'll post the way you're trying to configure it - and what errors 
you're seeing - I can make better suggestions.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Jan 31 09:45 EST 2002
Received: from listserv.nai.com (listserv.nai.com [161.69.213.6])
	by lists.tislabs.com (8.9.1/8.9.1) with SMTP id JAA23709
	Thu, 31 Jan 2002 09:45:05 -0500 (EST)
Message-ID: <LISTMANAGER-303-361-2002.01.31-08.49.15--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Michel.Marcon@equipement.gouv.fr
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Usage of authsrv and time (solved)
Date: Thu, 31 Jan 2002 15:54:53 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id JAA23709
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 4108
Status: RO

Hello.
Thanks Rick, but I think you are not right.

Excerpt of my netperm-table:
...
ftp-gw:	permit-hosts 172.21.36.45 -extnd -authall -log { retr stor }
authsrv:	permit-operation user alice ftp-gw ftp.inria  time 08:00
12:00
authsrv:	deny-operation user michael ftp-gw ftp.zoo.fr  time 17:00
11:00
..

This configuration works well. I (ip 172.21.36.45) can connect thru ftp-gw,
as user alice, to ftp.inria from 08:00 to 12:00.
I ( same ip) cannot connect, thru ftp-gw, as user michael to ftp.zoo.fr from
17:00 to 11:00. Great !

However, to make this works, I had to patch authsrv.c.  Attached is
authsrv.c.diff.
Cp this file in fwtk/auth; then type: patch < authsrv.c.diff ; make authsrv,
...

HTH.
cmic
-------------start of diff -------------8<-----------------------------
--- /usr/tmp2/authsrv.c	Thu Jan 31 13:18:47 2002
+++ authsrv.c	Thu Jan 31 13:22:13 2002
@@ -5,7 +5,15 @@
  * Redistribution and use are governed by the terms detailed in the
  * license document ("LICENSE") included with the toolkit.
  */
-
+/*
+ * Fixed some bugs related to operation with time argument.
+ * NB Example of usage in netperm-table :
+ * ftp-gw:	permit-hosts 172.21.36.45 -extnd -authall -log { retr stor }
+ * authsrv:	permit-operation user alice ftp-gw ftp.inria  time 08:00
12:00
+ * authsrv:	deny-operation user michael ftp-gw ftp.zoo.fr  time 17:00
11:00
+ *
+ *    Michel Marcon CETU (cmic) cmic@caramail.com
+ */
 /*
  *	Author: Marcus J. Ranum, Trusted Information Systems, Inc.
  */
@@ -407,6 +415,9 @@
 minutes(p)
 char *p;
 {
+/* FIXED kludge : supress any char after p[5] */
+	p[5]='\0';
+
 #define D(x) isdigit((unsigned char) x)
 	if (!D(p[0]) || !D(p[1]) || p[2] != ':' ||
 	    !D(p[3]) || !D(p[4]) || p[5] != '\0') {
@@ -419,6 +430,7 @@
 
 /*
  * Return 0 if current time is between upper and lower (inclusive)
+ * Return 1 if invlaid time or current time not between upper and lower.
  */
 static int
 time_ok(upper,lower)
@@ -548,7 +560,8 @@
 	more than 5 argments implies time range is specified.
 	*/
 	if(cfp->argc != top) {
-		if(!time_ok(cfp->argv[cfp->argc - 1], cfp->argv[cfp->argc -
2]))
+/* FIXED  !time_ok ==> time_ok */
+		if(time_ok(cfp->argv[cfp->argc - 1], cfp->argv[cfp->argc -
2]))
 			goto deny_cmd;
 	}
---end of diff-----------------8<------------------------------

> -----Message d'origine-----
> De : Rick Murphy [mailto:rmurphy@itm-inst.com]
> Envoyé : jeudi 31 janvier 2002 00:33
> À : fwtk-users
> Objet : [fwtk-users] Re: Usage of authsrv and time
> 
> 
> At 02:22 PM 1/30/02 +0100, Michel.Marcon@equipement.gouv.fr wrote:
> >Hello.
> >
> >I want to start and stop ftp-gw service (I use ftp-gw thru 
> authsrv) only on
> >certain hours of the day.
> >I noticed the "time" option of authsrv for that pupose; it 
> mut be used with
> >the -extnd option of ftp-gw. But I am unable to make it work.
> >Anyone has a solution for this kind of problem ??
> 
> I've never tried to make this work, but here's how it's 
> supposed to work.
> 
> You must run ftp-gw with the -extnd option.
> 
> You have authsrv lines in the netperm-table like:
> 
> authsrv:        permit-unknown unauth
> authsrv:        permit-operation ftp-gw user <user> <command> 
> <dest> <tokens>
> authsrv:        permit-operation ftp-gw group <group> 
> <command> <dest> <tokens>
> 
> The first line is required if you don't enable 
> authentication. In that 
> case, the only form of the "operation" line that works is the 
> "user unauth" 
> type.
> 
> For ftp-gw, "<command>" can be RETR, STOR, etc.
> The "<tokens>" field should be something like
>          time 17:00 23:59
> to allow time between 17:00 and 23:59
> 
> If you'll post the way you're trying to configure it - and 
> what errors 
> you're seeing - I can make better suggestions.
>          -Rick
> 
> 
> ---
> You are currently subscribed to fwtk-users as: 
> Michel.Marcon@equipement.gouv.fr
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

