From bounce-fwtk-users-303@listserv.nai.com Thu Aug  1 05:28 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id FAA29152
	Thu, 1 Aug 2002 05:28:06 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id FAA15692; Thu, 1 Aug 2002 05:42:05 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma015688; Thu, 1 Aug 02 09:41:34 GMT
Subject: [fwtk-users] Re: http-gw V 2.1 - page won't load
From: Tony Gale <gale@syntax.dstl.gov.uk>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
In-Reply-To: 
	<LISTMANAGER-769-27152-2002.07.31-14.27.18--gale#syntax.dstl.gov.uk@listserv
	.nai.com>
Content-Transfer-Encoding: 7bit
X-Mailer: Ximian Evolution 1.0.8.99 
Date: 01 Aug 2002 10:41:51 +0100
Message-Id: <LISTMANAGER-303-27454-2002.08.01-04.29.44--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 1454
Status: RO


Sent Philip a patch which should hopefully fix it - seems the list
doesn't allow attachments anymore - sillyness.

Anyway, the patch is in the list archive at:

http://marc.theaimsgroup.com/?l=fwtk-users&m=97733456929934&w=2

Cheers,
-tony



On Wed, 2002-07-31 at 20:36, Atwood, Philip L. wrote:
> I'm using http-gw V 2.1 on a Linux box and also on an older freebsd system. Several months ago I had
> problems loading some pages a different web sites. These problems were solved by applying Tony
> Gale's Jumbo patch (trg-jumbo-20001114.diff).
> 
> I have recently found a page ( www.fitchratings.com ) that still won't load through either the Linux
> or the freebsd firewalls. I can load the page on a browser connected outside our firewall, so I'm
> certain that the pages are being dropped by http-gw. This web site is using cold fusion to generate
> a lot of their web content. Can anyone confirm that they have a similar problem with this site? Any
> thoughts on the cause or a solution?
> 
> Thanks,
> 
> -------------------
> Philip L. Atwood
> Systems & Networking Manager
> ALAS, Inc.
> (312) 697-6985
> platwood@alas.com
> 
> ---
> You are currently subscribed to fwtk-users as: gale@syntax.dstl.gov.uk
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Aug  1 23:37 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id XAA01556
	Thu, 1 Aug 2002 23:37:33 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id XAA10644; Thu, 1 Aug 2002 23:51:32 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma010636; Fri, 2 Aug 02 03:50:53 GMT
Message-ID: <LISTMANAGER-303-27989-2002.08.01-22.39.02--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Atwood, Philip L." <platwood@alas.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: http-gw V 2.1 - page won't load
Date: Thu, 1 Aug 2002 22:48:29 -0500 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 1859
Status: RO

Tony's patch solved the problem. Thanks to all for the help

-Phil

-----Original Message-----
From: Tony Gale [mailto:gale@syntax.dstl.gov.uk]
Sent: Thursday, August 01, 2002 4:42 AM
To: fwtk-users
Subject: [fwtk-users] Re: http-gw V 2.1 - page won't load



Sent Philip a patch which should hopefully fix it - seems the list
doesn't allow attachments anymore - sillyness.

Anyway, the patch is in the list archive at:

http://marc.theaimsgroup.com/?l=fwtk-users&m=97733456929934&w=2

Cheers,
-tony



On Wed, 2002-07-31 at 20:36, Atwood, Philip L. wrote:
> I'm using http-gw V 2.1 on a Linux box and also on an older freebsd system. Several months ago I
had
> problems loading some pages a different web sites. These problems were solved by applying Tony
> Gale's Jumbo patch (trg-jumbo-20001114.diff).
> 
> I have recently found a page ( www.fitchratings.com ) that still won't load through either the
Linux
> or the freebsd firewalls. I can load the page on a browser connected outside our firewall, so I'm
> certain that the pages are being dropped by http-gw. This web site is using cold fusion to
generate
> a lot of their web content. Can anyone confirm that they have a similar problem with this site?
Any
> thoughts on the cause or a solution?
> 
> Thanks,
> 
> -------------------
> Philip L. Atwood
> Systems & Networking Manager
> ALAS, Inc.
> (312) 697-6985
> platwood@alas.com
> 
> ---
> You are currently subscribed to fwtk-users as: gale@syntax.dstl.gov.uk
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com



---
You are currently subscribed to fwtk-users as: platwood@alas.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug  5 10:07 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA07120
	Mon, 5 Aug 2002 10:07:57 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id KAA05708; Mon, 5 Aug 2002 10:22:00 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma005689; Mon, 5 Aug 02 14:21:57 GMT
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: http-gw V 2.1 - page won't load
X-Sun-Charset: US-ASCII
Message-Id: <LISTMANAGER-303-29597-2002.08.05-09.10.02--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon,  5 Aug 2002 10:22:13 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 1001
Status: RO

> From: "Atwood, Philip L." <platwood@alas.com>
> 
> I'm using http-gw V 2.1 on a Linux box and also on an older freebsd
> system. Several months ago I had problems loading some pages a
> different web sites. 
[snip]

Hmmm...  We're running an older version of Gauntlet (4.2) and
experiencing similar problems with some sites.  I've been looking for a
replacement HTTP proxy for some time, but not found anything suitable.
(For some reason, FWTK's HTTP proxy didn't occur to me?) Perhaps FWTK's
http-gw proxy would be better than Gauntlet 4.2's http-gw proxy?
Anybody know?


Thanks,
Jim
-- 
Jim Seymour                         | Welding Technology Corporation
jseymour@weldtechcorp.com           | 24775 Crestview Ct.
Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug  5 10:15 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA07133
	Mon, 5 Aug 2002 10:15:59 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id KAA05885; Mon, 5 Aug 2002 10:30:02 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma005876; Mon, 5 Aug 02 14:29:39 GMT
Message-ID: <LISTMANAGER-303-29609-2002.08.05-09.17.10--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Hirsch Wolfgang <hirsch@fwf.ac.at>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] AW: Re: http-gw V 2.1 - page won't load
Date: Mon, 5 Aug 2002 16:28:58 +0200 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id KAA07133
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1558
Status: RO

I've had the same problems with FWTK's http-gw. I solved the problem by
replaceing http-gw with squid and it works fine.

Wolfgang

> -----Ursprüngliche Nachricht-----
> Von: jseymour@medar.com [mailto:jseymour@medar.com] 
> Gesendet: Montag, 05. August 2002 16:22
> An: fwtk-users
> Betreff: [fwtk-users] Re: http-gw V 2.1 - page won't load
> 
> 
> > From: "Atwood, Philip L." <platwood@alas.com>
> > 
> > I'm using http-gw V 2.1 on a Linux box and also on an older freebsd
> > system. Several months ago I had problems loading some pages a
> > different web sites. 
> [snip]
> 
> Hmmm...  We're running an older version of Gauntlet (4.2) and
> experiencing similar problems with some sites.  I've been 
> looking for a
> replacement HTTP proxy for some time, but not found anything suitable.
> (For some reason, FWTK's HTTP proxy didn't occur to me?) 
> Perhaps FWTK's
> http-gw proxy would be better than Gauntlet 4.2's http-gw proxy?
> Anybody know?
> 
> 
> Thanks,
> Jim
> -- 
> Jim Seymour                         | Welding Technology Corporation
> jseymour@weldtechcorp.com           | 24775 Crestview Ct.
> Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
>                                     | FAX: (248)477-8897
> 
> ---
> You are currently subscribed to fwtk-users as: hirsch@fwf.ac.at
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug  5 10:31 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA07148
	Mon, 5 Aug 2002 10:31:07 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id KAA06203; Mon, 5 Aug 2002 10:45:10 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma006199; Mon, 5 Aug 02 14:44:37 GMT
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: AW: Re: http-gw V 2.1 - page won't load
X-Sun-Charset: US-ASCII
Message-Id: <LISTMANAGER-303-29625-2002.08.05-09.32.34--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon,  5 Aug 2002 10:44:47 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 1053
Status: RO

> From: Hirsch Wolfgang <hirsch@fwf.ac.at>
> 
> I've had the same problems with FWTK's http-gw. I solved the problem by
> replaceing http-gw with squid and it works fine.

Problem is: last time I looked at squid (maybe as much as a year
ago now) it didn't support removing ActiveX, Java, etc., whereas
Gauntlet's and FWTK's http-gw proxies do.  This is important to
us.  We don't allow ActiveX in *ever*.  And on occasion there is
a new exploit/hole in Java that causes us to block that, as well,
until the hole is plugged.  FWTK's http-gw also appears to allow
selective (by site) (non)blocking and the same for JavaScript.


Regards,
Jim
-- 
Jim Seymour                         | Welding Technology Corporation
jseymour@weldtechcorp.com           | 24775 Crestview Ct.
Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug  5 10:37 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA07165
	Mon, 5 Aug 2002 10:37:08 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id KAA06342; Mon, 5 Aug 2002 10:51:12 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma006336; Mon, 5 Aug 02 14:50:20 GMT
Message-ID: <LISTMANAGER-303-29632-2002.08.05-09.38.11--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Hirsch Wolfgang <hirsch@fwf.ac.at>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] AW: Re: AW: Re: http-gw V 2.1 - page won't load
Date: Mon, 5 Aug 2002 16:49:58 +0200 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by lists.tislabs.com id KAA07165
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1597
Status: RO



> -----Ursprüngliche Nachricht-----
> Von: jseymour@medar.com [mailto:jseymour@medar.com] 
> Gesendet: Montag, 05. August 2002 16:45
> An: fwtk-users
> Betreff: [fwtk-users] Re: AW: Re: http-gw V 2.1 - page won't load
> 
> 
> > From: Hirsch Wolfgang <hirsch@fwf.ac.at>
> > 
> > I've had the same problems with FWTK's http-gw. I solved 
> the problem by
> > replaceing http-gw with squid and it works fine.
> 
> Problem is: last time I looked at squid (maybe as much as a year
> ago now) it didn't support removing ActiveX, Java, etc., whereas
> Gauntlet's and FWTK's http-gw proxies do.  This is important to
> us.  We don't allow ActiveX in *ever*.  And on occasion there is
> a new exploit/hole in Java that causes us to block that, as well,
> until the hole is plugged.  FWTK's http-gw also appears to allow
> selective (by site) (non)blocking and the same for JavaScript.
> 

Yes, you're right. We solved this problem by not installing this features at
our client boxes.
regards,
Wolfgang
> 
> Regards,
> Jim
> -- 
> Jim Seymour                         | Welding Technology Corporation
> jseymour@weldtechcorp.com           | 24775 Crestview Ct.
> Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
>                                     | FAX: (248)477-8897
> 
> ---
> You are currently subscribed to fwtk-users as: hirsch@fwf.ac.at
> To unsubscribe send a blank email to 
> leave-fwtk-users-303A@listserv.nai.com
> 

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug  5 11:04 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA07206
	Mon, 5 Aug 2002 11:04:15 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id LAA06880; Mon, 5 Aug 2002 11:18:20 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma006867; Mon, 5 Aug 02 15:18:14 GMT
From: ark@eltex.ru
Date: Mon, 5 Aug 2002 19:07:55 +0400
Message-Id: <LISTMANAGER-303-29659-2002.08.05-10.06.04--fwtk-archive#lists.tislabs.com@listserv.nai.com>
In-Reply-To: <LISTMANAGER-333-29597-2002.08.05-09.10.02--ark#eltex.ru@listserv.nai.com> from "jseymour@medar.com (James Seymour)"
Organization: "Klingon Imperial Intelligence Service"
Subject: [fwtk-users] Re: http-gw V 2.1 - page won't load
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Virus-Scanned: by Eltex TC
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 1129
Status: RO

Considered using em's squid-gw?

jseymour@medar.com (James Seymour) said :

> > From: "Atwood, Philip L." <platwood@alas.com>
> > 
> > I'm using http-gw V 2.1 on a Linux box and also on an older freebsd
> > system. Several months ago I had problems loading some pages a
> > different web sites. 
> [snip]
> 
> Hmmm...  We're running an older version of Gauntlet (4.2) and
> experiencing similar problems with some sites.  I've been looking for a
> replacement HTTP proxy for some time, but not found anything suitable.
> (For some reason, FWTK's HTTP proxy didn't occur to me?) Perhaps FWTK's
> http-gw proxy would be better than Gauntlet 4.2's http-gw proxy?
> Anybody know?
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug  5 11:15 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id LAA07240
	Mon, 5 Aug 2002 11:15:18 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id LAA07107; Mon, 5 Aug 2002 11:29:22 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma007100; Mon, 5 Aug 02 15:29:04 GMT
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: AW: Re: AW: Re: http-gw V 2.1 - page won't load
X-Sun-Charset: ISO-8859-1
Message-Id: <LISTMANAGER-303-29670-2002.08.05-10.17.08--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon,  5 Aug 2002 11:29:20 -0400 (EDT)
From: jseymour@medar.com (James Seymour)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 1519
Status: RO

> From: Hirsch Wolfgang <hirsch@fwf.ac.at>
> 
> > -----Ursprüngliche Nachricht-----
> > Von: jseymour@medar.com [mailto:jseymour@medar.com] 
> > Gesendet: Montag, 05. August 2002 16:45
> > An: fwtk-users
> > Betreff: [fwtk-users] Re: AW: Re: http-gw V 2.1 - page won't load
> > 
[snip]
> > 
> > Problem is: last time I looked at squid (maybe as much as a year
> > ago now) it didn't support removing ActiveX, Java, etc., ...
[snip]
> > 
> 
> Yes, you're right. We solved this problem by not installing this features at
> our client boxes.

The problem there, IMO, is if a user of a client machine turns around
and undoes your hard work one way or the other (perhaps by accident,
perhaps not), they're exposed.  Particularly in an enterprise
environment consisting of dozens, hundreds or thousands of desktops,
the "do it at the client" solution is impractical and untrustworthy,
IMO.

We also work to turn of active scripting and so-forth on client
machines (defense in depth), but I wouldn't rely just on that.  Keeping
Evil Stuff out of our trusted network is properly the firewall's job.


Regards,
Jim
-- 
Jim Seymour                         | Welding Technology Corporation
jseymour@weldtechcorp.com           | 24775 Crestview Ct.
Systems, Network & TelCom Admin.    | Farmington Hills, MI. 48335
                                    | FAX: (248)477-8897

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Thu Aug  8 08:46 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA14452
	Thu, 8 Aug 2002 08:46:00 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id JAA19414; Thu, 8 Aug 2002 09:00:08 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma019406; Thu, 8 Aug 02 12:59:47 GMT
Envelope-to: fwtk-users@listserv.nai.com
Delivery-date: Thu, 08 Aug 2002 12:02:24 +0400
Message-ID: <LISTMANAGER-303-31464-2002.08.08-07.47.19--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Andrew Petrov" <andreyp@nnov.impexbank.ru>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Problem with telnet proxy.
Date: Thu, 8 Aug 2002 12:04:13 +0300
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0007_01C23ED3.B607EEF0"
Content-Length: 7983
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_0007_01C23ED3.B607EEF0
Content-Type: text/plain;
	charset="koi8-r"
Content-Transfer-Encoding: quoted-printable

Hi managers.

I've compiled and installed FWTK 2.1 on Linux Slakware 7.0 (Intel 486)
successfully. The FWTK were configured for telnet use only.

But, I've met one strange thing.

When I try to connect to firewall from Windows workstations,
everything works fine.

But in case of trying to connect from Solaris, Cisco or BSD  I receive a =
message
Trying x.x.x.x
Unable to connect to remote host. Connection refused.
All stations are in the same subnet.

Here is my inetd.conf and netperm-table examples:
#
# Internet server configuration database
#
#       @(#)inetd.conf  5.4 (Berkeley) 6/30/90
#       Modified, mjr@tis.com
#
# modified to allow daemon mode use of proxies.
stelnet stream  tcp     nowait  root    /usr/local/etc/netacl   =
in.telnetd
telnet  stream  tcp     nowait   root    /usr/local/etc/tn-gw    tn-gw
authsrv stream  tcp     nowait  root    /usr/local/etc/authsrv  authsrv
auth    stream  tcp     nowait  root    /usr/local/etc/authsrv  authsrv


netperm-table.

netacl-in.telnetd: permit-hosts 127.0.0.1 -exec /usr/sbin/in.telnetd
netacl-in.telnetd: permit-hosts X.X.X.X -exec /usr/sbin/in.telnetd
netacl-in.telnetd: permit-hosts X.X.X.X -exec /usr/sbin/in.telnetd
#
# if the next line is uncommented, the telnet proxy is available
netacl-in.telnetd: permit-hosts * -exec /usr/local/etc/tn-gw

# Example telnet gateway rules:
# -----------------------------
tn-gw:          denial-msg      /usr/local/tis/tn-deny.txt
tn-gw:          welcome-msg     /usr/local/tis/tn-welcome.txt
tn-gw:          help-msg        /usr/local/tis/tn-help.txt
tn-gw:          timeout 90
# if this line is uncommented incoming traffic is permitted WITH
# authentication required
tn-gw:          permit-hosts MYNET -passok -xok
tn-gw:          permit-hosts * -auth

# Example auth server and client rules
# ------------------------------------
authsrv:        hosts 127.0.0.1
authsrv:        database /usr/local/etc/fw-authdb
authsrv:        badsleep 1200
authsrv:        nobogus true
*:              authserver 127.0.0.1 7777

Thanks for any suggestions.
Will summarize.

Andrew Petrov.
Unix SA.
Impexbank , Russia.



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_0007_01C23ED3.B607EEF0
Content-Type: text/html;
	charset="koi8-r"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dkoi8-r">
<META content=3D"MSHTML 6.00.2600.0" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Hi managers.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>I've compiled and installed FWTK 2.1 on =
Linux=20
Slakware 7.0 (Intel 486)</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>successfully. The FWTK were configured =
for telnet=20
use only.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>But, I've met one strange =
thing.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>When I try to connect to firewall from =
Windows=20
workstations,</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>everything&nbsp;works =
fine.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>But in case of&nbsp;trying to connect=20
from&nbsp;Solaris, Cisco or BSD&nbsp; I receive a message</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Trying x.x.x.x</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Unable to connect to remote host. =
Connection=20
refused.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>All stations are in the same =
subnet.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Here is my inetd.conf and netperm-table =

examples:</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>#<BR># Internet server configuration=20
database<BR>#<BR>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
@(#)inetd.conf&nbsp; 5.4=20
(Berkeley) 6/30/90<BR>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Modified, <A =

href=3D"mailto:mjr@tis.com">mjr@tis.com</A><BR>#<BR># modified to allow =
daemon=20
mode use of proxies.<BR>stelnet stream&nbsp; tcp&nbsp;&nbsp;&nbsp;&nbsp; =

nowait&nbsp; root&nbsp;&nbsp;&nbsp; /usr/local/etc/netacl&nbsp;&nbsp;=20
in.telnetd<BR>telnet&nbsp; stream&nbsp; tcp&nbsp;&nbsp;&nbsp;&nbsp;=20
nowait&nbsp;&nbsp; root&nbsp;&nbsp;&nbsp; =
/usr/local/etc/tn-gw&nbsp;&nbsp;&nbsp;=20
tn-gw<BR>authsrv stream&nbsp; tcp&nbsp;&nbsp;&nbsp;&nbsp; nowait&nbsp;=20
root&nbsp;&nbsp;&nbsp; /usr/local/etc/authsrv&nbsp;=20
authsrv<BR>auth&nbsp;&nbsp;&nbsp; stream&nbsp; =
tcp&nbsp;&nbsp;&nbsp;&nbsp;=20
nowait&nbsp; root&nbsp;&nbsp;&nbsp; /usr/local/etc/authsrv&nbsp;=20
authsrv<BR></FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>netperm-table.</DIV></FONT>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>netacl-in.telnetd: permit-hosts =
127.0.0.1 -exec=20
/usr/sbin/in.telnetd<BR>netacl-in.telnetd: permit-hosts&nbsp;X.X.X.X =
-exec=20
/usr/sbin/in.telnetd<BR>netacl-in.telnetd: permit-hosts&nbsp;X.X.X.X =
-exec=20
/usr/sbin/in.telnetd<BR>#<BR># if the next line is uncommented, the =
telnet proxy=20
is available<BR>netacl-in.telnetd: permit-hosts * -exec=20
/usr/local/etc/tn-gw</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2># Example telnet gateway rules:<BR>#=20
-----------------------------<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;=20
denial-msg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
/usr/local/tis/tn-deny.txt<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;=20
welcome-msg&nbsp;&nbsp;&nbsp;&nbsp;=20
/usr/local/tis/tn-welcome.txt<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;=20
help-msg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
/usr/local/tis/tn-help.txt<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;=20
timeout 90<BR># if this line is uncommented incoming traffic is =
permitted=20
WITH<BR># authentication=20
required<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =

permit-hosts&nbsp;MYNET -passok=20
-xok<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
permit-hosts * -auth</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2># Example auth server and client =
rules<BR>#=20
------------------------------------<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;=20
hosts 127.0.0.1<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
database=20
/usr/local/etc/fw-authdb<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;=20
badsleep 1200<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
nobogus=20
true<BR>*:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;=20
authserver 127.0.0.1 7777</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Thanks for any =
suggestions.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Will summarize.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Andrew Petrov.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Unix SA.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Impexbank , Russia.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>&nbsp;</DIV></FONT>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_0007_01C23ED3.B607EEF0--



From bounce-fwtk-users-303@listserv.nai.com Thu Aug  8 08:47 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA14456
	Thu, 8 Aug 2002 08:46:59 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id JAA19428; Thu, 8 Aug 2002 09:01:08 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma019421; Thu, 8 Aug 02 13:00:41 GMT
Message-ID: <LISTMANAGER-303-31465-2002.08.08-07.47.21--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Thu, 8 Aug 2002 04:16:01 -0700 (PDT)
From: Istvan Takacs <i_takacs@yahoo.com>
Subject: [fwtk-users] Disable downloads via HTTP?
To: "fwtk-users" <fwtk-users@listserv.nai.com>
MIME-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 675
Status: RO

Hi,

I'm having a problem with unwanted users downloading
materials from the internet.  
They are downloading those files via HTTP protocol by
their browsers.  I'd like to deny everyone in business
hours.  I am not about the best way to setup the
netperm-table file for this capability.

Could some kind soul direct me in solving this.  

Thanks in advance!

Regards;

           Istvan

__________________________________________________
Do You Yahoo!?
HotJobs - Search Thousands of New Jobs
http://www.hotjobs.com

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Aug 16 09:57 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA04194
	Fri, 16 Aug 2002 09:57:12 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id KAA29360; Fri, 16 Aug 2002 10:11:34 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma029286; Fri, 16 Aug 02 14:10:35 GMT
content-class: urn:content-classes:message
MIME-Version: 1.0
Subject: [fwtk-users] RE: Problem with telnet proxy.
X-MimeOLE: Produced By Microsoft Exchange V6.0.5762.3
Date: Fri, 16 Aug 2002 15:10:43 +0100
Message-ID: <LISTMANAGER-303-35296-2002.08.16-08.58.07--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Thread-Topic: [fwtk-users] Problem with telnet proxy.
Thread-Index: AcI+3DJzRaQ1CRG8T8yEqXHpy5QWCQGUeDeQ
From: "Torrance, Derek" <Derek.Torrance@it.glasgow.gov.uk>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C2452E.B5634D06"
Content-Length: 10508
Status: RO

This is a multi-part message in MIME format.

------_=_NextPart_001_01C2452E.B5634D06
Content-Type: text/plain;
	charset="koi8-r"
Content-Transfer-Encoding: quoted-printable

Hi Andrew,
=20
Sounds like the problem may be more fundamental than a fwtk =
mis-configuration. Can you ping the fwtk Linux box from the =
Solaris/Cisco/BSD systems?
=20
dt

-----Original Message-----
From: Andrew Petrov [mailto:andreyp@nnov.impexbank.ru]
Sent: 08 August 2002 10:04
To: fwtk-users
Subject: [fwtk-users] Problem with telnet proxy.


Hi managers.
=20
I've compiled and installed FWTK 2.1 on Linux Slakware 7.0 (Intel 486)
successfully. The FWTK were configured for telnet use only.
=20
But, I've met one strange thing.
=20
When I try to connect to firewall from Windows workstations,
everything works fine.
=20
But in case of trying to connect from Solaris, Cisco or BSD  I receive a =
message
Trying x.x.x.x
Unable to connect to remote host. Connection refused.
All stations are in the same subnet.
=20
Here is my inetd.conf and netperm-table examples:
#
# Internet server configuration database
#
#       @(#)inetd.conf  5.4 (Berkeley) 6/30/90
#       Modified, mjr@tis.com
#
# modified to allow daemon mode use of proxies.
stelnet stream  tcp     nowait  root    /usr/local/etc/netacl   =
in.telnetd
telnet  stream  tcp     nowait   root    /usr/local/etc/tn-gw    tn-gw
authsrv stream  tcp     nowait  root    /usr/local/etc/authsrv  authsrv
auth    stream  tcp     nowait  root    /usr/local/etc/authsrv  authsrv

=20
netperm-table.
=20
netacl-in.telnetd: permit-hosts 127.0.0.1 -exec /usr/sbin/in.telnetd
netacl-in.telnetd: permit-hosts X.X.X.X -exec /usr/sbin/in.telnetd
netacl-in.telnetd: permit-hosts X.X.X.X -exec /usr/sbin/in.telnetd
#
# if the next line is uncommented, the telnet proxy is available
netacl-in.telnetd: permit-hosts * -exec /usr/local/etc/tn-gw
=20
# Example telnet gateway rules:
# -----------------------------
tn-gw:          denial-msg      /usr/local/tis/tn-deny.txt
tn-gw:          welcome-msg     /usr/local/tis/tn-welcome.txt
tn-gw:          help-msg        /usr/local/tis/tn-help.txt
tn-gw:          timeout 90
# if this line is uncommented incoming traffic is permitted WITH
# authentication required
tn-gw:          permit-hosts MYNET -passok -xok
tn-gw:          permit-hosts * -auth
=20
# Example auth server and client rules
# ------------------------------------
authsrv:        hosts 127.0.0.1
authsrv:        database /usr/local/etc/fw-authdb
authsrv:        badsleep 1200
authsrv:        nobogus true
*:              authserver 127.0.0.1 7777
=20
Thanks for any suggestions.
Will summarize.
=20
Andrew Petrov.
Unix SA.
Impexbank , Russia.
=20
---
You are currently subscribed to fwtk-users as: =
derek.torrance@it.glasgow.gov.uk
To unsubscribe send a blank email to =
leave-fwtk-users-303A@listserv.nai.com=20



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------_=_NextPart_001_01C2452E.B5634D06
Content-Type: text/html;
	charset="koi8-r"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dkoi8-r">


<META content=3D"MSHTML 5.00.3315.2870" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN =
class=3D468110614-16082002>Hi=20
Andrew,</SPAN></FONT></DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN=20
class=3D468110614-16082002></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN =
class=3D468110614-16082002>Sounds=20
like the problem may be more fundamental than a fwtk mis-configuration. =
Can you=20
ping the fwtk Linux box from the Solaris/Cisco/BSD =
systems?</SPAN></FONT></DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN=20
class=3D468110614-16082002></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT color=3D#0000ff face=3DArial size=3D2><SPAN=20
class=3D468110614-16082002>dt</SPAN></FONT></DIV>
<BLOCKQUOTE>
  <DIV align=3Dleft class=3DOutlookMessageHeader dir=3Dltr><FONT =
face=3DTahoma=20
  size=3D2>-----Original Message-----<BR><B>From:</B> Andrew Petrov=20
  [mailto:andreyp@nnov.impexbank.ru]<BR><B>Sent:</B> 08 August 2002=20
  10:04<BR><B>To:</B> fwtk-users<BR><B>Subject:</B> [fwtk-users] Problem =
with=20
  telnet proxy.<BR><BR></DIV></FONT>
  <DIV><FONT face=3DArial size=3D2>Hi managers.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>I've compiled and installed FWTK 2.1 =
on Linux=20
  Slakware 7.0 (Intel 486)</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>successfully. The FWTK were =
configured for telnet=20
  use only.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>But, I've met one strange =
thing.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>When I try to connect to firewall =
from Windows=20
  workstations,</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>everything&nbsp;works =
fine.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>But in case of&nbsp;trying to connect =

  from&nbsp;Solaris, Cisco or BSD&nbsp; I receive a message</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>Trying x.x.x.x</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>Unable to connect to remote host. =
Connection=20
  refused.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>All stations are in the same =
subnet.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>Here is my inetd.conf and =
netperm-table=20
  examples:</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>#<BR># Internet server configuration=20
  database<BR>#<BR>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
@(#)inetd.conf&nbsp;=20
  5.4 (Berkeley) 6/30/90<BR>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
Modified, <A=20
  href=3D"mailto:mjr@tis.com">mjr@tis.com</A><BR>#<BR># modified to =
allow daemon=20
  mode use of proxies.<BR>stelnet stream&nbsp; =
tcp&nbsp;&nbsp;&nbsp;&nbsp;=20
  nowait&nbsp; root&nbsp;&nbsp;&nbsp; /usr/local/etc/netacl&nbsp;&nbsp;=20
  in.telnetd<BR>telnet&nbsp; stream&nbsp; tcp&nbsp;&nbsp;&nbsp;&nbsp;=20
  nowait&nbsp;&nbsp; root&nbsp;&nbsp;&nbsp;=20
  /usr/local/etc/tn-gw&nbsp;&nbsp;&nbsp; tn-gw<BR>authsrv stream&nbsp;=20
  tcp&nbsp;&nbsp;&nbsp;&nbsp; nowait&nbsp; root&nbsp;&nbsp;&nbsp;=20
  /usr/local/etc/authsrv&nbsp; authsrv<BR>auth&nbsp;&nbsp;&nbsp; =
stream&nbsp;=20
  tcp&nbsp;&nbsp;&nbsp;&nbsp; nowait&nbsp; root&nbsp;&nbsp;&nbsp;=20
  /usr/local/etc/authsrv&nbsp; authsrv<BR></FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>netperm-table.</DIV></FONT>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>netacl-in.telnetd: permit-hosts =
127.0.0.1 -exec=20
  /usr/sbin/in.telnetd<BR>netacl-in.telnetd: permit-hosts&nbsp;X.X.X.X =
-exec=20
  /usr/sbin/in.telnetd<BR>netacl-in.telnetd: permit-hosts&nbsp;X.X.X.X =
-exec=20
  /usr/sbin/in.telnetd<BR>#<BR># if the next line is uncommented, the =
telnet=20
  proxy is available<BR>netacl-in.telnetd: permit-hosts * -exec=20
  /usr/local/etc/tn-gw</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2># Example telnet gateway rules:<BR>#=20
  =
-----------------------------<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;=20
  denial-msg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
  =
/usr/local/tis/tn-deny.txt<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;=20
  welcome-msg&nbsp;&nbsp;&nbsp;&nbsp;=20
  =
/usr/local/tis/tn-welcome.txt<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;=20
  help-msg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
  =
/usr/local/tis/tn-help.txt<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;=20
  timeout 90<BR># if this line is uncommented incoming traffic is =
permitted=20
  WITH<BR># authentication=20
  =
required<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =

  permit-hosts&nbsp;MYNET -passok=20
  -xok<BR>tn-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
  permit-hosts * -auth</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2># Example auth server and client =
rules<BR>#=20
  =
------------------------------------<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;=20
  hosts 127.0.0.1<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
database=20
  =
/usr/local/etc/fw-authdb<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;=20
  badsleep 1200<BR>authsrv:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
nobogus=20
  =
true<BR>*:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;=20
  authserver 127.0.0.1 7777</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>Thanks for any =
suggestions.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>Will summarize.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2>Andrew Petrov.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>Unix SA.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>Impexbank , Russia.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2>&nbsp;</DIV></FONT>---<BR>You are =
currently=20
  subscribed to fwtk-users as: derek.torrance@it.glasgow.gov.uk<BR>To=20
  unsubscribe send a blank email to =
leave-fwtk-users-303A@listserv.nai.com=20
</BLOCKQUOTE>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------_=_NextPart_001_01C2452E.B5634D06--


----------------------------------------------------------------------------
Disclaimer: 
This message is intended only for use of the addressee. If this message
was sent to you in error, please notify the sender and delete this message.
Glasgow City Council cannot accept responsibility for viruses, so please
scan attachments. Views expressed in this message do not necessarily reflect
those of the Council who will not necessarily be bound by its contents.

----------------------------------------------------------------------------


From bounce-fwtk-users-303@listserv.nai.com Mon Aug 19 16:45 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA10682
	Mon, 19 Aug 2002 16:45:00 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA17027; Mon, 19 Aug 2002 16:59:26 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma016989; Mon, 19 Aug 02 20:58:55 GMT
From: "David L Kindred (Dave)" <d.kindred@telesciences.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Message-ID: <LISTMANAGER-303-36465-2002.08.19-15.46.05--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Mon, 19 Aug 2002 16:57:47 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Is plug-gw the only option for IMAP?
X-Mailer: VM 6.90 under 21.1 (patch 14) "Cuyahoga Valley" XEmacs Lucid
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 950
Status: RO

I have a short-term need to allow some access to an internal IMAP server
from the outside world.  A Google search seems to show that no options
exist except to either actually run an IMAP server on the outside and
copy mail to it, or to use plug-gw to pass the traffic inside.

Are there any other options?

Note: yes, I know IMAP to the outside isn't a great idea, but you have
to keep the executive staff happy.

-- 
David L. Kindred <mailto:d.kindred@telesciences.com>
Unix Systems & Network Administrator
Telesciences, Inc. <http://www.telesciences.com>
Support: <http://support.telesciences.com>
2000 Midlantic Drive, Suite 410, Mt. Laurel, NJ 08054
Tel: +1.856.866.1000 ext. 4184
Fax: +1.856.866.0185
Cel: +1.609.413.6205
Pgr: +1.800.689.5182
SMS: <mailto:davidlkindred@vtext.com>
---

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Aug 19 17:29 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA10785
	Mon, 19 Aug 2002 17:29:24 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id RAA19285; Mon, 19 Aug 2002 17:43:51 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma019281; Mon, 19 Aug 02 21:43:20 GMT
From: ark@eltex.ru
Message-Id: <LISTMANAGER-303-36483-2002.08.19-16.29.51--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Date: Tue, 20 Aug 2002 01:31:58 +0400 (MSD)
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
In-Reply-To: <LISTMANAGER-333-36465-2002.08.19-15.46.05--ark#eltex.ru@listserv.nai.com> from "David L Kindred (Dave)" at Aug 19, 2002 04:57:47 PM
X-Mailer: ELM [version 2.5 PL3]
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by Eltex TC
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 1176
Status: RO

Selective replication to outside server is definitely better idea
than allowing imap to inside

(i am planning imap proxy somedays though)

btw for those who is interested in mail filtering we are testing
milter-enabled pop3-gw now ;-)

YOU ("David L Kindred (Dave)") WROTE:
>  
>  I have a short-term need to allow some access to an internal IMAP server
>  from the outside world.  A Google search seems to show that no options
>  exist except to either actually run an IMAP server on the outside and
>  copy mail to it, or to use plug-gw to pass the traffic inside.
>  
>  Are there any other options?
>  
>  Note: yes, I know IMAP to the outside isn't a great idea, but you have
>  to keep the executive staff happy.


-- 
                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Aug 20 04:05 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA11761
	Tue, 20 Aug 2002 04:05:17 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id EAA14638; Tue, 20 Aug 2002 04:19:45 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma014611; Tue, 20 Aug 02 08:19:28 GMT
Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?
From: Tony Gale <gale@syntax.dstl.gov.uk>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
In-Reply-To: 
	<LISTMANAGER-769-36465-2002.08.19-15.46.05--gale#syntax.dstl.gov.uk@listserv
	.nai.com>
Content-Transfer-Encoding: 7bit
X-Mailer: Ximian Evolution 1.0.8.99 
Date: 20 Aug 2002 09:19:20 +0100
Message-Id: <LISTMANAGER-303-36638-2002.08.20-03.06.40--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 968
Status: RO

On Mon, 2002-08-19 at 21:57, David L Kindred (Dave) wrote:
> I have a short-term need to allow some access to an internal IMAP server
> from the outside world.  A Google search seems to show that no options
> exist except to either actually run an IMAP server on the outside and
> copy mail to it, or to use plug-gw to pass the traffic inside.
> 
> Are there any other options?
> 

Other options:

o Run a webmail system outside that is the only box allowed to IMAP to
the internal server.

o There are some imap proxies around (google: imap proxy):  
	http://www.vergenet.net/linux/perdition/ seems to do what you want, but
I haven't even downloaded it, so use at your own risk.

o You could probably use stunnel on an external server to setup an
SSL-IMAP server to the internal mail server. Maybe.

-tony



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Aug 20 04:12 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id EAA11766
	Tue, 20 Aug 2002 04:12:26 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id EAA14906; Tue, 20 Aug 2002 04:26:55 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma014888; Tue, 20 Aug 02 08:26:13 GMT
X-Authentication-Warning: spider.usrconsult.be: mail set sender to <mbardiaux@peaktime.be> using -f
Message-ID: <LISTMANAGER-303-36643-2002.08.20-03.11.44--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Tue, 20 Aug 2002 10:24:23 +0200
From: Michel Bardiaux <mbardiaux@peaktime.be>
Organization: Peaktime Belgium S.A.
X-Mailer: Mozilla 4.73 [en] (WinNT; I)
X-Accept-Language: en,fr
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 1153
Status: RO

ark@eltex.ru wrote:
> 
> Selective replication to outside server is definitely better idea
> than allowing imap to inside

Access to the internal IMAP server over ssh over plug-gw would be
somewhat more secure than plain plug-gw.

> 
> (i am planning imap proxy somedays though)
> 
> btw for those who is interested in mail filtering we are testing
> milter-enabled pop3-gw now ;-)
> 
> YOU ("David L Kindred (Dave)") WROTE:
> >
> >  I have a short-term need to allow some access to an internal IMAP server
> >  from the outside world.  A Google search seems to show that no options
> >  exist except to either actually run an IMAP server on the outside and
> >  copy mail to it, or to use plug-gw to pass the traffic inside.
> >
> >  Are there any other options?
> >
> >  Note: yes, I know IMAP to the outside isn't a great idea, but you have
> >  to keep the executive staff happy.
> 


-- 
Michel Bardiaux
Peaktime Belgium S.A.  Bd. du Souverain, 191  B-1160 Bruxelles
Tel : +32 2 790.29.41

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Aug 20 06:28 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id GAA12007
	Tue, 20 Aug 2002 06:28:20 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id GAA19995; Tue, 20 Aug 2002 06:42:48 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma019978; Tue, 20 Aug 02 10:42:07 GMT
From: ark@eltex.ru
Date: Tue, 20 Aug 2002 14:31:03 +0400
Message-Id: <LISTMANAGER-303-36710-2002.08.20-05.29.14--fwtk-archive#lists.tislabs.com@listserv.nai.com>
In-Reply-To: <LISTMANAGER-333-36643-2002.08.20-03.11.44--ark#eltex.ru@listserv.nai.com> from "Michel Bardiaux <mbardiaux@peaktime.be>"
Organization: "Klingon Imperial Intelligence Service"
Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?
To: "fwtk-users" <fwtk-users@listserv.nai.com>
X-Virus-Scanned: by Eltex TC
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text
Content-Length: 946
Status: RO

Michel Bardiaux <mbardiaux@peaktime.be> said :

> ark@eltex.ru wrote:
> > 
> > Selective replication to outside server is definitely better idea
> > than allowing imap to inside
> 
> Access to the internal IMAP server over ssh over plug-gw would be
> somewhat more secure than plain plug-gw.

Somewhat. You have to keep ssh bugs in mind and windows client configuration
becomes non-trivial. And you cannot use per-ip access control on the server.

So i think replication is the only proper way.

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Aug 20 14:07 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA12707
	Tue, 20 Aug 2002 14:07:30 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id OAA07064; Tue, 20 Aug 2002 14:21:59 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma007006; Tue, 20 Aug 02 18:20:58 GMT
X-Authentication-Warning: rainmaker.dreamwvr.com: neo set sender to dreamwvr@dreamwvr.com using -f
Date: Tue, 20 Aug 2002 12:21:04 -0600
From: "dreamwvr@dreamwvr.com" <dreamwvr@dreamwvr.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?
Message-ID: <LISTMANAGER-303-36930-2002.08.20-13.08.20--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
Content-Disposition: inline
In-Reply-To: <LISTMANAGER-165-36643-2002.08.20-03.11.44--dreamwvr#dreamwvr.com@listserv.nai.com>; from mbardiaux@peaktime.be on Tue, Aug 20, 2002 at 10:24:23AM +0200
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 2165
Status: RO

On Tue, Aug 20, 2002 at 10:24:23AM +0200, Michel Bardiaux wrote:
> ark@eltex.ru wrote:
> > 
> > Selective replication to outside server is definitely better idea
> > than allowing imap to inside
> 
> Access to the internal IMAP server over ssh over plug-gw would be
> somewhat more secure than plain plug-gw.
> 
> > 
> > (i am planning imap proxy somedays though)
> > 
> > btw for those who is interested in mail filtering we are testing
> > milter-enabled pop3-gw now ;-)
> > 
> > YOU ("David L Kindred (Dave)") WROTE:
> > >
> > >  I have a short-term need to allow some access to an internal IMAP server
> > >  from the outside world.  A Google search seems to show that no options
> > >  exist except to either actually run an IMAP server on the outside and
> > >  copy mail to it, or to use plug-gw to pass the traffic inside.
> > >
> > >  Are there any other options?
> > >
> > >  Note: yes, I know IMAP to the outside isn't a great idea, but you have
> > >  to keep the executive staff happy.
> > 
Please don't top post it makes the thread hard to follow. Here is some 
food for thought. It has been a long time since using plug-gw but I 
see not reason why it would not work. Why not use stunnel combined with 
client based certs? You then get a number of good things IMHO:
1 - SSL/TLS to the imapd or whatever else you want..
2 - Client Cert based authentication.. (let me know how this works for you.)
    OR if you prefer simply use only the imapd server account as is..
3 - Decrypt the stream in transit so you can do traffic analysis at 
    the point of redirection in stunnel. stick in plug-gw and voila!

Hope that helps!

Best Regards,
dreamwvr@dreamwvr.com

-- 
/*  Security is a work in progress - dreamwvr                 */
#                                                             
# Note: To begin Journey type man afterboot,man help,man hier[.]      
#                                                             
// "Who's Afraid of Schrodinger's Cat?" /var/(.)?mail/me \?  ;-]

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Aug 20 14:55 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA12741
	Tue, 20 Aug 2002 14:55:25 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA09030; Tue, 20 Aug 2002 15:09:53 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma009018; Tue, 20 Aug 02 19:09:00 GMT
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-36948-2002.08.20-13.56.25--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?
Date: Tue, 20 Aug 2002 12:09:12 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain
Content-Length: 774
Status: RO

> -----Original Message-----
> From: dreamwvr@dreamwvr.com [mailto:dreamwvr@dreamwvr.com] 
> Sent: Tuesday, August 20, 2002 11:21 AM
> To: fwtk-users
> Subject: [fwtk-users] Re: Is plug-gw the only option for IMAP?

> Please don't top post it makes the thread hard to follow. 

Does anyone know how to configure Outlook to bottom post?  I can't find a
setting that will let me change this.  It always puts my signature at the
top and I have to move it to the bottom by hand.

Note:  Switching email clients is not an option here as the company mandates
use of Outlook.

-- 
Michael St. Laurent
Hartwell Corporation

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

