Displaying 20 results from an estimated 2000 matches similar to: "bogons update"
2003 Jan 08
3
Shorewall blacklist does all
Hello,
I''m a very happy user of shorewall but I have found a problem
or maybe a misconfiguration I made which I can not resolve.
I use a fairly large blacklist based on probes, nimda & codered
attacks, proxy & relay probes etc.
The only problem is that I want to block incoming trafic on
all ports FROM a block but it does also block a httpd, ping
etc TO a ip in a block what I do
2003 Jan 27
7
Mac Addresses in the Log
How does one interpret the mac addresses in the log which
seem to have 14 segments...
Example, this appears in the log...
00:40:c7:2e:09:c0:00:01:64:4a:70:00:08:00
Yet I can''t find that in the arp table
norcomix:~ # arp -an
? (192.168.2.148) at 00:10:4B:6A:AE:E7 [ether] on eth1
? (192.168.2.149) at 00:D0:B7:1D:F2:F2 [ether] on eth1
? (24.237.19.16) at 00:10:DC:67:BA:80 [ether] on eth0
?
2005 Jun 06
5
Smb4K port
Hello,
Which port Smb4K uses?
I am not able to use Smb4K on my
server for the local network.
Thanks
Varun
2003 Jan 27
3
Another Bone Head question
Whilst configuring another shorewall firewall router
for another site, I must have made some totally newbie
error....
While directly on the cable modem, it works great.
But when placed on the LAN side of my existing
Shorewall box, the NEW shorwall box could not ping,
or look up dns or anything else.
If I shutdown shorewall (clear) in the NEW box then
it could surf the net and ping etc. When
2003 Jan 08
14
prerouting newbie question/mistake :)
Hola and thanks for any help in advance
I installed mandrake 9 a few days ago and wanted to set up some
additional rules to shorewall, bu i failed :)
What i want to do is basicly route any incomming udp and tcp packets on
port 4665 to a workstation behind the router.
router with mandrake 9, eth0 (192.168.0.1) internal net, eth1(10.0.0.0)
connected to dsl modem and gets a dynamic ip
2003 Feb 25
2
Offical Shorewall Support Forum
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
DeveloperCube is a new project started by veterans of the web
development industry. We are proud to announce that we are now the
Official Shorewall Support Forum. We are an online community
offering discussion geared towards web developers, designers, and
administrators of all skill levels. There are topics ranging from
how to market your website,
2004 Nov 09
9
Dyndns
Hi,
I''ve a little problem, I hope so..
First a hint, I haven''t a static IP - Adress and so I used a dyndns
Provider.
In DMZ runs a sftp server. It should accessible from net. My router is
forwarding the traffic from port 22 to the machine in DMZ. Now, in
basic installation I have rfc1918-dropping configured by net
interface.
My problem:
If rfc1918 dropping is on I
2004 Nov 23
2
OT: 1gigabt nics
Begging indulgence of the list - asking here because due
to the higher likelyhood of getting an answer...
I have an application that often loses connection from one machine to
another when one (or more) of the machines has particular brands of
1gig nics, but which runs rock solid when on 10meg nics and some 1
gig nics.
The application senses (falsely) that the connection has been shut
2004 Nov 30
2
RFC1918 all of a sudden?
Is my RFC1918 file obsolete? I have been assigned an ip in the
83.0.0.0/8 range, and of cource a lot of Shorewall systems drop me with
a RFC1918 error.
So, is my ISP actually giving me a RFC1918 IP, or am I missing
something?
.
2004 Nov 12
1
Shorewall''s bogon file needs updating
As far as I can tell from <http://shorewall.net/errata.htm> the current
shorewall bogons file is
<http://shorewall.net/pub/shorewall/errata/2.0.8/bogons> which contains
the line:
58.0.0.0/7 logdrop # Reserved
This is incorrect. These two /8s were allocated to APNIC as of April
2004. See also
<http://marc.theaimsgroup.com/?l=nanog&m=108319003517919&w=2> and the
main
2004 Jun 22
6
Linux choices ?
First of all, My apologies for this maybe slight OT post, but I have
so much confidence and read so much good replies on this list, that I
am still asking my question.
I''m looking for a linux distribution to use on our school''s homemade
routers. The routers are small miniITX based systems with 2 network
interfaces. I added a 4 port D-Link network card in some cases, when I
2003 Jan 19
8
Unable to have pc #2 connect
I''ve set up shorewall with the two-interface mode.
pc #1 eth1 ---> ppp0 ---> Internet eth1: 10.10.10.254
eth0: 10.10.10.1
> via a crossover cable
pc #2 eth0: 10.10.10.2 (gateway=10.10.10.254)
I am able to surf the net with pc #1, but pc #2 is completely cut off
from pc #1 and the net. I am also unable to ping from and to pc #2.
2005 May 29
17
Plans for 2.4.0
Hi folks,
Has anyone tested the changes to multiple ISPs/load balancing or
routestopped in 2.4.0-RC1 yet? We need to talk about what criteria we
will use for determining whether 2.4.0 is ready for release.
I''ve started configuring a firewall at work with the multiple ISPs
support, but its kernel doesn''t have connection marking support, so it''s
going to be a couple of
2004 Jan 09
32
Ideas for Shorewall 2.0
I''m beginning to think again about what will be different in 2.0. Here
are some thoughts.
a) User-defined actions will be emphasized.
- A library of actions will be available with names such as:
AcceptSSH
AcceptDNS
DropWindows (drops all SMB noise)
DropBroadcasts (Silently drop all Broadcast traffic)
...
The possibilities are nearly endless but should
2003 Nov 24
3
VNC Problem
Hello,
I want VNC Server,which is outside my network ,add my VNC Client, which is
behide shorewall box. How should I config the rule? TIA
Thongchai
2002 Dec 27
2
shorewall.net may be down for a while today
A violent wind storm is expected in western Washington state later today
and such storms often produce power/communications outages. I''ll do what I
can to keep things running here.
-Tom
--
Tom Eastep \ Shorewall - iptables made easy
Shoreline, \ http://shorewall.sf.net
Washington USA \ teastep@shorewall.net
2004 Apr 20
0
Updated rfc1918 and bogons files
Updated rfc1918 and bogons files are now available:
rfc1918 for Shorewall 2.0.0 and earlier:
http://shorewall.net/pub/shorewall/errata/1.4.10/rfc1918
bogons for Shorwall 2.0.1:
http://shorewall.net/pub/shorewall/errata/2.0.1/bogons
Thanks go to Thomas Backlund for pointing out that the file was out of date.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
2004 Nov 12
0
Updated rfc1918 and bogons files
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
To reflect recent allocations by the IANA, the following files are
available:
For Shorewall 2.0.0b and earlier:
http://shorewall.net/pub/shorewall/errata/1.4.10/rfc1918
ftp://shorewall.net/pub/shorewall/errata/1.4.10/rfc1918
For Shorewall 2.0.1 and later:
http://shorewall.net/pub/shorewall/errata/2.0.10/bogons
2005 Mar 10
7
norfc1918 not working in SW 2.2.1?
Hello all,
Yesterday I noticed that my system was "leaking" traffic towards the
10/8 network, I have shorewall installed on multiple machines ranging
from single interface devices to ones with 10+ interfaces. I tested all
the boxes and they are showing the same behavior.
All systems are CentOS 3.4, 2.4.21-27.0.2.ELsmp.
Shorewall version: 2.2.1
For the host mentioned is a single
2005 Sep 06
4
Paranoid Firewalling
After reading this article:
http://www.theregister.co.uk/2005/08/31/blocking_chinese_ip_addresses/
I got to thinking that there is really no reason for *any* traffic to
hit my servers that comes from anywhere outside North America. So I
wrote the perl script at the end of this posting to extract selected IP
ranges posted at iana.org and convert them into iptables rules blocking
any traffic