Re: firewall

2001-09-11 Thread Simon Huggins
On Mon, Sep 10, 2001 at 05:24:15PM +0100, Tim Haynes wrote: My script, previously plugged, does this with connection tracking. iptables -A block -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A block -m state --state INVALID -j DROP Indeed though some people may prefer

Re: firewall

2001-09-11 Thread Tim Haynes
Simon Huggins [EMAIL PROTECTED] writes: On Mon, Sep 10, 2001 at 05:24:15PM +0100, Tim Haynes wrote: My script, previously plugged, does this with connection tracking. iptables -A block -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A block -m state --state INVALID -j

Re: firewall

2001-09-11 Thread Tim Haynes
Simon Huggins [EMAIL PROTECTED] writes: [snip] That's why my script, previously plugged, proceeds to REJECT, with TCP-RST, ident requests separately, further down. The above does not DROP identd, unless you're sending me invalid packets, of course. Indeed it does. Perhaps you should

Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode (I fixed that by commenting out the restart line) but I'm not getting anything in the daily notification emails either. /etc/ppp/ip-up.d/snort doesn't start snort with -s, so nothing goes into

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread sjk
What version are you using?? make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH --sjk On 12 Sep, Andrew Pollock wrote: Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode

Re: firewall

2001-09-11 Thread Giacomo Mulas
On 10 Sep 2001, Tim Haynes wrote: Adam Olsen [EMAIL PROTECTED] writes: It should be sufficient to do update-rc.d -f portmap remove update-rc.d -f lpd remove update-rc.d -f bind remove As an aside, I did this with proftpd, but when I upgrade the install

Re: firewall

2001-09-11 Thread Simon Huggins
On Mon, Sep 10, 2001 at 05:24:15PM +0100, Tim Haynes wrote: My script, previously plugged, does this with connection tracking. iptables -A block -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A block -m state --state INVALID -j DROP Indeed though some people may prefer

Re: firewall

2001-09-11 Thread Tim Haynes
Simon Huggins [EMAIL PROTECTED] writes: On Mon, Sep 10, 2001 at 05:24:15PM +0100, Tim Haynes wrote: My script, previously plugged, does this with connection tracking. iptables -A block -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A block -m state --state INVALID -j

Re: firewall

2001-09-11 Thread Simon Huggins
On Tue, Sep 11, 2001 at 11:31:01AM +0100, Tim Haynes wrote: Simon Huggins [EMAIL PROTECTED] writes: On Mon, Sep 10, 2001 at 05:24:15PM +0100, Tim Haynes wrote: My script, previously plugged, does this with connection tracking. iptables -A block -m state --state ESTABLISHED,RELATED -j

Re: firewall

2001-09-11 Thread Tim Haynes
Simon Huggins [EMAIL PROTECTED] writes: [snip] That's why my script, previously plugged, proceeds to REJECT, with TCP-RST, ident requests separately, further down. The above does not DROP identd, unless you're sending me invalid packets, of course. Indeed it does. Perhaps you should

Heartbeat (Cluster etc.)

2001-09-11 Thread m . c . p
Hi there, is any one on this whole wide world able to help me with the heartbeat package? I want to use it with debian sid, neither the sid package nor the rpm/tgz from the website linux-ha.org are working?! I will be very glad if anyone can help me!! -- Kind regards Marc-Christian

Heartbeat

2001-09-11 Thread Marc-Christian Petersen
Hi there, is any one on this whole wide world able to help me with the heartbeat package? I want to use it with debian sid, neither the sid package nor the rpm/tgz from the website linux-ha.org are working?! I will be very glad if anyone can help me!! -- Kind regards Marc-Christian

Re: Heartbeat (Cluster etc.)

2001-09-11 Thread Joerg Wendland
On Tue, Sep 11, 2001 at 01:22:10PM +0200, [EMAIL PROTECTED] wrote: is any one on this whole wide world able to help me with the heartbeat package? I want to use it with debian sid, neither the sid package nor the rpm/tgz from the website linux-ha.org are working?! What's exactly your

Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode (I fixed that by commenting out the restart line) but I'm not getting anything in the daily notification emails either. /etc/ppp/ip-up.d/snort doesn't start snort with -s, so nothing goes into

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread sjk
What version are you using?? make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH --sjk On 12 Sep, Andrew Pollock wrote: Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
On 12.09.2001 at 12:24:59, [EMAIL PROTECTED] wrote: What version are you using?? Version 1.8-RELEASE (Build 43) make sure the following line is in your snort.conf -- I think the debian equiv is snort-lib: output alert_syslog: LOG_AUTH I've uncommented this line in my snort.conf. I'm