Displaying 20 results from an estimated 90000 matches similar to: "Firwall certifcate"
2004 Nov 25
1
Firwall on and no one home
Hi Guys
luv your product but ive become stuck since updating to Suse Linux
Enterprise 9, Id luv some advice on where i should be looking to resolve
this issue..
basically... when shorewall is off all ports are showing to the internet
''25,80,443,ect'' and i can ping my box from an external source. ''with
stopped rule created to allow ppp0''
when shorewall is on
2005 Feb 02
1
Informatio request - FreeBSD Native Firewall Certificate
I'd like to request information about the FreeBSD native firewall
software
Does the firewall attends to the security certification at
International Computer Security Association (ICSA Labs Firewall
Certification Program) Labs or Trust Technology Assessment Program
(TTAP) or similar programs?
Thanks for your attention
Fernando Castro
fcastro@smsweb.com.br
2004 Mar 03
1
FreeBSD ipsec and NAT
Hi All,
I currently have setup a site to site vpn using racoon on my freebsd
firewall. All is well there and I can connect through the vpn when I am
on the firewall and get the connection fine.
Now I want to be able to connect from other machines through the
firewall - this is where I come unstuck, the ipsec policy allows for my
external address range to connect through the vpn, but then I would
2007 Apr 02
1
Stronger security with BSD Firewall and Freeradius
I've seen that is possible to use switch port blocking with freeradius
and cisco switches via 802.1X and EAP protocol. Here is more info:
http://wiki.freeradius.org/FreeRADIUS_Active_Directory_Integration_HOWTO
What if I don't have switch that supports 802.1X or I want that blocking
is done by FreeBSD, not the switch. Because FreeBSD is the firewall or
gateway to some networks. Is there
2003 Nov 21
0
how to get IPFW rules for SMTP server behind NAT server "right"?
hi all,
i've been struggling with setting appropriate rules for an SMTP-server
behind by NAT'd firewall.
it's not that there is too little info on the web -- or here, for that
matter -- there's scads of it for seemingly endless configs/req'ts --
none that seem to be exactly my own.
bottom line: i'm a bit confused, and looking for some experienced
advice.
my goals (for
2003 May 08
1
bridge and firewall
Can anyone help with this. Bridge is enabled, even in sysctl. Firewall is
enabled and configured. But my reality is done this way..
Cisco
(NATing
192.168.1.0/24) ---- Freebsd Bridge (Public IP) ------ stations
(Public IP) (NATing 172.16.0.0/24 192.168.1.xx
or something similar) 172.16.0.xx and on
one public IP one
2004 May 05
0
worms and fw sending rst's instead of drop
Hi,
I was wondering upon how some of you think upon some issues upon block
policies in firewalls. Basically you can choose a firewall to send resets
back as answer upon probes etc to not allowed ports, or you can choose a
firewall to drop the packets.
In general i think just dropping is the better one.
Consider the lastest worms like blaster and sasser. How many hits would
some firewalls
2005 Jun 27
1
running jail with alternate IP
I am currently setting up a firewall that translates my internal network
over to 5 public IP addresses. The addresses are dynamically assigned, so I
use ddclient to update my www.dyndns.org account. I've set up several
aliases on the external interface of the firewall, and succeeded in having
the internal computers use those extra public IPs.
What I want to do is have 5 copies of ddclient
2004 Oct 04
1
Shorewall-users Digest, Vol 23, Issue 4
Sorry some email problem, i have change it for more reliable one.
I have try this morning to netmasq 192.168.11.0 (eth1) to 192.168.1.0
(eth0), but it is a mistake.
Yes thank you for answering so fast !
I have corrected it, here the new diagram and the new routing table. But it
still doesn''t work. From the router i can access to 192.168.11.254 I have
add the rules :
DNAT loc
2003 Jul 28
1
ssh and X11Forwarding
What has to be installed on a host for it to do X11Forwarding in SSH?
My (FreeBSD) workstation at home is behind NAT. From home, I can SSH to
a FreeBSD firewall at work, and from there I can get to other hosts
around the internal network there, some of which run X clients.
Does X have to be installed *on the firewall* for me to forward X11
connections from the X clients back to my workstation
2007 Jun 13
0
pf does not use IPv6 interface addresses at startups
>Submitter-Id: current-users
>Originator: Janos Mohacsi
>Organization: NIIF/HUNGARNET
>Confidential: no
>Synopsis: pf does not use IPv6 interface addresses at startups
>Severity: serious
>Priority: low
>Category: bin
>Class: sw-bug
>Release: FreeBSD 6.2-STABLE i386
>Environment:
System: FreeBSD scone.ki.iif.hu 6.2-STABLE FreeBSD 6.2-STABLE #23: Wed May 9 18:23:24
2003 Dec 23
0
How do I pass WWW (80) through the firewall on two NICs ?
I'm getting lost ...
Running two NICs - no problem. But trying to screw down the rules a bit and getting lost on passing the www - or port 80, through the firewall both waqys.
There are WebServers - real and virtual, on the inside interface, with their own PublicIP. I'm not using the OutsideInterface as their web address, as I'm using my own DNS etc.
So, in rc.firewall, what do I
2007 Mar 16
0
freebsd-security Digest, Vol 201, Issue 2
? 2007-3-15???8:00?freebsd-security-request@freebsd.org ???
> Send freebsd-security mailing list submissions to
> freebsd-security@freebsd.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> or, via email, send a message with subject or body 'help' to
> freebsd-security-request@freebsd.org
2004 Oct 03
1
RE: Shorewall-users Digest, Vol 23, Issue 4
Yes thank you for answering so fast !
I have corrected it, here the new diagram and the new routing table. But it
still doesn''t work.
>From the router i can access to 192.168.11.254
I have add the rules :
DNAT loc priv:192.168.11.254:22 tcp 22
But i can''t connect to 192.168.11.254 from LAN
The DNAT fonction doesn''t work, but i can DROP packet arriving on eth0 (loc)
2006 Jan 11
0
FreeBSD Security Advisory FreeBSD-SA-06:04.ipfw
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=============================================================================
FreeBSD-SA-06:04.ipfw Security Advisory
The FreeBSD Project
Topic: ipfw IP fragment denial of service
Category: core
Module: ipfw
Announced:
2006 Jan 11
0
FreeBSD Security Advisory FreeBSD-SA-06:04.ipfw
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=============================================================================
FreeBSD-SA-06:04.ipfw Security Advisory
The FreeBSD Project
Topic: ipfw IP fragment denial of service
Category: core
Module: ipfw
Announced:
2005 May 16
0
Configure a FreeBSD firewall to pass IPSec?
Greg White,.
I have noted your comment on some documentation found on the web, "I have
successfully (and repeatedly) used Nortel VPN client on a NATed host through a
FreeBSD gateway."
Currently i have the same problem with a Nortel BCM Running M$ Windows VPN, the
BCM sit's behind a FreeBSD Firewall / NATD.
---- Network ----
ADSL Modem
|
FreeBSD Server / Gateway / HTTP etc.
2003 May 12
0
Gateway config
>On Sunday 11 May 2003 03:19 pm, freebsdquestions@schatti.ch wrote:
>> Hi all!
>>
>> Short question: could anyone point me to documents regarding topics:
>> jails! & nat & (ipfw|ip tables) - I'm in process to build a new system...
>> Planned layout:
>>
>> NET---router/nat-----gateway:freebsd5.x/nat--------inner net
>>
>>
2006 Dec 29
2
ssh session from external machine
Hello,
I am having a small problem with the ssh daemon on my freebsd box. I am
using the standard ssh daemon asked at the installation. I am able to acces
my box using ssh from the internal lan network but not from any external
machine. The error code is connection refused. I am using release 6.1 and my
modem firewall permits the inbound traffic on port 22. I also use port
forwarding for sending
2004 Nov 14
1
ipfw logging
Hi all!
After installing 5.3 I've noticed
some change in firewall logging.
Prior (on 5.2) rules gave me what
I needed: trimed to 3 of the same
connection. Every new connection
on the same rule gave new log line
up to 3. I have in kernel:
FIREWALL
FIREWALL_VERBOSE
FIREWALL_VERBOSE_LIMIT=3
Now, all connections on the same
rule are trimed to 3. Is it possib-
le on 5.3 to have all