Displaying 20 results from an estimated 2000 matches similar to: "New Terminology"
2011 Jan 08
2
tdbdump, tdbbackup
Do these programs still exist?
They don't seem to be part of the samba3x package on RHEL5.
2010 Dec 30
2
Questions about ldap organizational units
Environment is Samba as a PDC, OpenLDAP backend, with
smbldap-tools providing the scripts to manipulate the data.
What are the recommended/mandated organizational units (OU=)
for user, computer, group info.
I'm pretty sure that groups go in ou=Groups, but I am confused
about where user and computer data goes.
I have seen ou=People, ou=Computers, and ou=Users in various places.
Which is it
2004 Nov 01
9
Some issues with proxy ARP
This is some ramblings on why using proxy ARP (on a host in a DMZ)
is a good or bad thing.
The good is that a computer X retains a public IP address which makes
it easy to connect it directly to the net if the firewall has to
be taken down for extended periods. Thus, if computer X is a mail
server for example, it can still function in a reduced capacity
until the firewall is restored.
The bad
2004 Nov 08
3
nessusd on shorewall
Hi,
I have shorewall version 1.4.10g on Redhat 9 Local clients are on eth1
in subnet 192.168.3.0/24. eth0 is for the outside (over xdsl with
includes a ppp0 interface).
Nessus (nessusd) is installed *on the firewall* and managed trough
nessus (the client or frontend) running on one of the internal machines.
When I was running a scan against 194.152.181.36 I observed several
entries like
2004 May 26
6
Newnotsyn Behavior
Hello,
I''ve been doing some tests on a firewall system running Shorewall 1.4, and
have been getting some unexpected behavior when enabling the "newnotsyn"
option.
In the test setup, I have:
----------------------------------------
/etc/shorewall/interfaces
net eth0 detect routefilter,tcpflags,blacklist
loc eth1 10.0.0.255 dhcp,tcpflags,newnotsyn
2004 Dec 01
5
PPTP connections through Shorewall - WinXP Workstation to Win2003 Server
The problem scenario I describe was reported previously in the Shorewall
lists but its resolution does not seem to have made it into the lists.
Scenario:
Windows XP client seeking to establish a VPN connection to a Windows 2003
Server located behind a Shorewall firewall (running on Mandrake kernel 2.4.22-37mdk).
The connection cannot be made, the client reports error code 721.
Discussion:
2004 Nov 16
4
Query re Tom''s firewall (see http://www.shorewall.net/myfiles.htm)
On the firewall, what is the rationale for giving eth1 an IP address
that is also assigned eto eth0? (Rather than a private one.)
--
Taso Hatzi
caesar 17 <<-salad
cjbx jc vdwwjar jc xi jc jd
salad
2005 May 08
2
Samba docs
Hi, especially John H. T :)
I'm yet again plodding through chapter 14 of the
Samba-HOWTO-Collection.pdf. Not because I can't make what's in it work
for me, I did that long ago, I found out for myself, because a great
deal of what's in it is wrong. I just got fed up with trying to get
Nagios to work - I gave up, for various reasons and started on the Samba
doco.
At the risk of
2004 Nov 25
5
newnotsyn responsible for sporadic delays?
Has anyone encountered a situation where packets dropped by the
newnotsyn chain can result in sporadic browsing problems, slowness, and
even timeouts?
I noticed that of the 3300 hits for newnotsyn in our current log (6 hours
worth), over 2700 of them were to/from our proxy servers. And browsing
through them, most *appear* to be otherwise valid packets from remote
web servers that would have
2002 Dec 19
4
Shorewall 1.3.12 Beta1
The first Beta Version is available at:
http://www.shorewall.net/pub/shorewall/Beta
ftp://ftp.shorewall.net/pub/shorewall/Beta
New features include:
1) "shorewall refresh" now reloads the traffic shaping rules (tcrules
and tcstart).
2) "shorewall debug [re]start" now turns off debugging after an error
occurs. This places the point of the failure near the end of the
2011 Jan 09
1
DFS - access shares via \\domain\dfsroot\...
Is there a trick to being able to access shares via
\\domain\dfsroot\.. rather than
\\computer\dfsroot\... ? Only the latter works for me - samba 3.0.22
2010 Dec 23
1
How can one set/reset machine account passwords
Scenario:
a) Samba with an ldap backend.
b) The ldap database becomes irretrievably corrupted.
c) I roll in a new ldap database from a known good copy.
d) Problem is the passwords for the machine accounts are out of date.
e) Is it possible to coax Samba & the clients (mostly XP) to resynch
their passwords?
f) I want to preserve the client computers SIDs & names.
g) I really
2011 Jan 09
1
When is a machine SID created?
I have been having a problem with 'net getdomainsid' on a machine that I
set up to be a BDC.
# net getdomainsid
Could not fetch local SID
tdbdump shows that there is no machine SID in secrets.db, so I'm thinking
that I overlooked the step that creates a machine SID. What creates the machine
SID and when? Also, is it the hostname or the netbios name that samba uses as
the machine
2004 Oct 13
4
Connection tracking on non-masqueraded interfaces.
I don''t think this has anything to do with Shorewall but I am not too
familiar with iptables stuff yet so I''m not sure.
Running Shorewall shorewall-1.4.9 on Mandrake Linux release 9.2 (FiveStar)
for i586 Kernel 2.4.22-37mdk.
Run "nmap -sP 192.168.x.x/24" (for example), where 192.168.x.x/24 is the LAN.
You can do this from a firewall/router, or even from a
2004 Nov 07
3
Zone to same zone policy
Are there any scenarios that require traffic from a zone to itself to be
blocked? If not, Shorewall should possibly allow it as a matter of course.
It seems strange having to explicitly create such a policy & it''s not
immediately obvious when it is required.
--
Taso Hatzi
caesar 17 <<-salad
cjbx jc vdwwjar jc xi jc jd
salad
2005 Jan 26
9
Proxy-ARP on Same Segment
I have had to replace an existing setup which has a bunch of IPs
Proxy-NAT''ed onto the loc segment. While I do eventually want to move
them to their own segment, I have to deal with this for the next few weeks.
My problem is that from a loc system I can ping the public IP of a
system being proxy-ARP''d but I can''t hit it via HTTP. Nothing is being
blocked according
2003 Jan 12
10
Shorewall on a file/webserver/router Help
Hi,
I have a install of shorewall I have 2 interfaces(I think)
ppp0[connection device] and eth0 [LAN device],
I want to allow all traffic from the the internet in or aleast port 80 and
CVS and webmin and mail and everything normal to the main machine with
shorewall on it.
I changed to policy file but it just gave me errors as to double interfaces.
I also what still to alow connection sharing
2003 Mar 28
9
Squid
I''m attempting to setup Squid as shown on:
http://shorewall.sourceforge.net/Shorewall_Squid_Usage.html#DMZ
The firewall is a Bering 1.0 firewall running Shorewall 1.3.11, Red Hat
7.2 on the server in the DMZ. I''m not seeing the requests come in to the
server using tcpdump. The server is 192.168.2.1 connecting to eth2 on the
firewall, the local traffic I''m trying to
2004 Nov 06
3
shorewall.net Down Time
Tomorrow morning, the following systems will be unavailable while I
upgrade the OS on my firewall:
a) shorewall.net
b) lists.shorewall.net
c) cvs.shorewall.net
d) rsync.shorewall.net
The upgrade will begin around 0700 PST (-0800) and will like take two
hours or so.
Sorry for the inconvenience.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \
2004 Aug 11
6
connections getting dropped
Hi Guys, I need some help. I''ve been using shorewall for a while now
and it''s been running beautifully, but I''m now experiencing some
problems. It seems that connections are getting dropped much like the
behavior described by the NEWNOTSYN=no option in the shorewall.conf
file, but I have NEWNOTSYN=Yes in my file.
The messages I see in my logs are things like: