Re: [Leaf-user] dialup with leaf - how?

2002-02-04 Thread Stephen More

Please put a direct link in even if it has not been tested. ( It provides
hints for other users ). 

I spent time trying to find these docs, since there were no docs I spent a
lot of time figuring out how to make Dachstein Dial on my own.

I have also started writing up my own docs to post on the web. 

Had a link existed previously, I could have saved alot of time :-)


-Steve More


At 12:30 PM 2/2/02 -0800, Kenneth Hadley wrote:
>You can try http://leaf.sourceforge.net/devel/khadley/ppp.html
>there is right now no direct link on my web pages to it cause I need some
>testers
>Let me know if it works for you
>
>
>- Original Message -
>From: "Tim Wegner" <[EMAIL PROTECTED]>
>To: <[EMAIL PROTECTED]>
>Sent: Saturday, February 02, 2002 12:25 PM
>Subject: [Leaf-user] dialup with leaf - how?
>
>
>> I am sure this question is so obvious that I can't see the answer
>> right in front of my nose! I am a happy user of Dachstein with dhcp
>> DSL, but I have a friend who wants to use Dachstein with dialup.
>>
>> What is needed to use leaf (e.g. Dachstein) with ppp dialup? ppp.lrp?
>> pppd.lrp? Can Kenneth Hadley's instructions for pppoe (which support
>> pppoe over ethernet) be modified for dialup? I have seached the mail
>> archives and a few of the leaf sites and haven't quite figure this
>> out.
>>
>> I'm guessing this is very simple once one knows the answer :-)
>>
>> Tim Wegner
>>
>> ___
>> Leaf-user mailing list
>> [EMAIL PROTECTED]
>> https://lists.sourceforge.net/lists/listinfo/leaf-user
>
>___
>Leaf-user mailing list
>[EMAIL PROTECTED]
>https://lists.sourceforge.net/lists/listinfo/leaf-user
>
>

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



RE: [Leaf-user] changing internal subnet addrs on Dachstein

2002-02-04 Thread Tony



Don't forget hosts.allow

Later

Tony



> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Christopher
> Holmes
> Sent: Sunday, February 03, 2002 5:34 PM
> To: [EMAIL PROTECTED]
> Subject: [Leaf-user] changing internal subnet addrs on Dachstein
> 
> 
> I just changed the internal network address on my Dachstein box.
> 
> I changed the 192.168.1.xx to 192.168.5.xx in...
> 
> /etc/dhcpd.conf
> /etc/network.conf
> /etc/sh-httpd.conf
> 
> /etc/ipfilter.conf looked OK as-is.
> 
> I backed up packages etc, dhcpd, & weblet. Everything works fine except I
> can't get the weblet page to display.
> 
> What did I miss?
> 
> Chris
> 
> 
> 
> 
> ___
> Leaf-user mailing list
> [EMAIL PROTECTED]
> https://lists.sourceforge.net/lists/listinfo/leaf-user
> 

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] DCD & java ???

2002-02-04 Thread Jack Coates


On Sun, 3 Feb 2002, Matt Schalit wrote:

> To strip it for leaf, I'm thinking that the
>
>libraries/clib/awt/*
>libraries/javalib/java/awt/*
>
>
> stuff contributes the most useless parts, simply because it's all
> X and gui applets or standalone gui application classes.  Also
> the appletviewer is not needed, and that's part of a jre.
>

agreed, but it looks like one must modify the source tree or Makefile to
disable these, and it's definitely complex territory for someone who
doesn't write Java and has no idea what's needed and not needed.

> Having at it, Michael?  What classes does your app import?
> Matt
>

-- 
Jack Coates
Monkeynoodle: A Scientific Venture...


___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] HELP - UNSUBSCRIBE

2002-02-04 Thread Kenny Ton

UNSUBSCRIBE

-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of
[EMAIL PROTECTED]
Sent: Sunday, February 03, 2002 4:52 PM
To: [EMAIL PROTECTED]
Subject: Leaf-user digest, Vol 1 #607 - 15 msgs


Send Leaf-user mailing list submissions to
[EMAIL PROTECTED]

To subscribe or unsubscribe via the World Wide Web, visit
https://lists.sourceforge.net/lists/listinfo/leaf-user
or, via email, send a message with subject or body 'help' to
[EMAIL PROTECTED]

You can reach the person managing the list at
[EMAIL PROTECTED]

When replying, please edit your Subject line so it is more specific
than "Re: Contents of Leaf-user digest..."


Today's Topics:

   1. QOS in Dachstein?? (Christopher Holmes)
   2. Re: QOS in Dachstein?? (Michael D. Schleif)
   3. Re: DCD & java ??? (Matt Schalit)
   4. Re: QOS in Dachstein?? (Jack Coates)
   5. Re: Confused about eth2 ROUTES - update (Victor McAllister)
   6. Re: DCD & java ??? (Mark Plowman)
   7. changing internal subnet addrs on Dachstein (Christopher Holmes)
   8. Re: DCD & java ??? (Michael Leone)
   9. Re: changing internal subnet addrs on Dachstein (Michael D. Schleif)
  10. Re: DCD & java ??? (Jack Coates)
  11. Re: DCD & java ??? (Jack Coates)
  12. Re: dialup with leaf - how? (Larry Platzek)
  13. Re: DCD & java ??? (Michael D. Schleif)
  14. Hardware router Linux look-alike (Stewart Adey)
  15. Re: Hardware router Linux look-alike (guitarlynn)

--__--__--

Message: 1
Reply-To: <[EMAIL PROTECTED]>
From: "Christopher Holmes" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Date: Sun, 3 Feb 2002 15:31:06 -0500
Subject: [Leaf-user] QOS in Dachstein??

Is there any kind of QOS built into Dachstein?  I noticed a fairq chain in
the packet fileter rules.

Thanks,
Chris




--__--__--

Message: 2
Date: Sun, 03 Feb 2002 15:23:11 -0600
From: "Michael D. Schleif" <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Organization: mds resource
To: [EMAIL PROTECTED]
CC: [EMAIL PROTECTED]
Subject: Re: [Leaf-user] QOS in Dachstein??


Christopher Holmes wrote:
>
> Is there any kind of QOS built into Dachstein?  I noticed a fairq chain in
> the packet fileter rules.

# grep -i 'qos\|fairq' /etc/network.conf
# Simple QoS/fair queueing support
eth0_FAIRQ=NO
# Complex QoS - Enable all of these + above to turn it on
eth1_FAIRQ=NO
#eth2_FAIRQ=NO
# Simple QoS support
#fr498_FAIRQ=YES
# Complex FR QoS - Enable ALL of these + above to turn it on
#ppp_FAIRQ=YES
# fairq chain
CLS_FAIRQ="${MRK_CRIT}_89_0/0 ${MRK_CRIT}_udp_0/0_route
${MRK_CRIT}_tcp_0/0_bgp ${MRK_CRIT}_tcp_0/0_domain
${MRK_CRIT}_udp_0/0_domain ${MRK_IA}_tcp_0/0_telnet
${MRK_IA}_tcp_0/0_ssh"
eval local FAIRQ=\${"$1"_FAIRQ:-""}
ip_frQoS $1
ip_QoS $1
# Clean up any QoS/fair queuing stuff
ip_QoSclear $1
# QoS/Fariqueing functions
ip_QoSclear () {
ip_frQoS () {
eval local FAIRQ=\${"$1"_FAIRQ:-""}
if [ "$FAIRQ" != "YES" -a "$FAIRQ" != "Yes" -a "$FAIRQ" != "yes"
]
ip_QoS () {
eval local FAIRQ=\${"$1"_FAIRQ:-""}
if [ -z "$FAIRQ" -a -n "$2" ]; then
 local FAIRQ=$2
if [ "$FAIRQ" != "YES" -a "$FAIRQ" != "Yes" -a "$FAIRQ" != "yes"
]


--

Best Regards,

mds
mds resource
888.250.3987

Dare to fix things before they break . . .

Our capacity for understanding is inversely proportional to how much we
think we know.  The more I know, the more I know I don't know . . .


--__--__--

Message: 3
Date: Sun, 03 Feb 2002 13:33:03 -0800
From: Matt Schalit <[EMAIL PROTECTED]>
Subject: Re: [Leaf-user] DCD & java ???
To: [EMAIL PROTECTED]

Jack Coates wrote:


> Is there interest in massive applications in general?

Massive but not rediculous.  Perl and java are useful but
large.  A LEAF box with them gets closer and closer to
being a full distro, minus the x-windows.  Certainly
the user would need a cdrom based LEAF.  I'd like to
see java2, but only the jre.  God only knows how well
that'll work on a crippled Linux box :)


> The appliance-friendly nature of LEAF makes one think yes,
> but then the limitations of RAM disk, glibc, etc...


Yes, reinventing the wheel is bogus, and that's what happens
when we try to pack everything from a full distro into a LEAF.


> At any rate, I've just uploaded my 3.2 MB postfix.lrp to
> the www.monkeynoodle.org packages repository. If I get a chance today
> I'll see if a JRE will compile too :-)


Well that's 3.2MB of _something_, I don't know what :)

You might be interested in j2me.  That's the Java2 Micro Edition
targeted at embedded systems like color pda's and cell phones with
limited memory and space.

   http://java.sun.com/j2me/

It's like Java2 minus the swing and awt stuff.  Might work
well for people.  I'm busy writing full blown java2 apps,
but once I learn those, I may poke around with j2me also.

Regards,
Matthew


--__--__--

Message: 4
Date: Sun, 3 Feb 2002 14:12:01 -0800 (PST)
From: Jack Coates <[EMAIL PROT

[Leaf-user] crontab vs /etc/cron.d/multicron

2002-02-04 Thread Victor McAllister

I am using an older Pentium 90 for my DCD.  For some reason the system
clock gains over a minute a day.
I tried putting the rdate -s command in /etc/crontab as suggested by
Charles in a recent message.

syslog showed that it runs on schedule - but the clock never got
synchronized.  The command ran as root and file permissions and path
were correct.  It would not work with either an internal or an
external time server.
However, the clock always was updated from the keyboard when typing in
rdate -s "favorite.time.server" or putting it in /root/.profile
(requires a login to function).

If I put the rdate in /etc/cron.d/multicron  - everything worked.  I
have not made any changes to the firewall by allowing ntp.

crontab would not correctly run the command.  Same command in
mutlicron works.  Strange - but at least it works now.
-
# cat /etc/cron.d/multicron
#Periodic schedule for multicron. (Ping check, Space check, etc)
#Default: Every 15 minutes
*/15* * * * root/etc/multicron-p
11 05,11,17,23   * * *   rootrdate -s 132.163.4.101
12 05,11,17,23   * * *   roothwclock --systohc

--
Victor McAllister



___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] HELP - UNSUBSCRIBE

2002-02-04 Thread Patrick Benson

Kenny Ton wrote:
> 
> UNSUBSCRIBE
> 
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of
> [EMAIL PROTECTED]
> Sent: Sunday, February 03, 2002 4:52 PM
> To: [EMAIL PROTECTED]
> Subject: Leaf-user digest, Vol 1 #607 - 15 msgs
> 
> Send Leaf-user mailing list submissions to
> [EMAIL PROTECTED]


Please read below:
 
> To subscribe or unsubscribe via the World Wide Web, visit
> https://lists.sourceforge.net/lists/listinfo/leaf-user
> or, via email, send a message with subject or body 'help' to
> [EMAIL PROTECTED]

Instead of sending a huge 24kb file with one word to a global mailing
list community, it would be highly preferable to read the instructions
on how to unsubscribe before doing it. Info can be found in your e-mail
headers, as well. There are people on other continents other than Europe
and North America who have to actually pay for their downloads... 
Thank you.

-- 
Patrick Benson
Stockholm, Sweden

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] Masq and VPN to the same address causes problems?

2002-02-04 Thread Ed R. Zahurak

This might be a known thing, but first time I've experienced it,
so I thought I'd share/ask...
 
I punched a few holes through one of my routers this weekend to
do some work remotely, specifically mapping:

port 8080 to 192.168.0.141:80
port 23   to 192.168.0.141:23
port 5800 to 192.168.0.141:5800 (vnc. love this puppy.)
 
everything worked well from my remote location.
 
I run a VPN tunnel between 2 sites using the same
box, and while visiting the remote site, I tried to
hit both the web site (port 80) and telnet (port 23)
on 192.168.0.141, over the tunnel. No go.
Would not connect.
 
I was able to get around it by telnetting in through
the "open" masquerade port, and added a sub-interface
to 192.168.0.141, giving it a second address of
192.168.0.150.  I was able to telnet and www through
the tunnel then, with no problem, to the new address.
 
I take it the various components of a LEAF device
"clash" on occasion like this?  Is there a more
elegant solution?  Not that I mind just tossing
a second address on the box, that's no big deal at
all.

Ed Z.
[EMAIL PROTECTED]

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] Hardware router Linux look-alike

2002-02-04 Thread guitarlynn

On Monday 04 February 2002 08:24, [EMAIL PROTECTED] wrote:

> Just my thoughts. What are the possibilities?

I've started a somewhat minimal install script base, as has Ken Hadley
for respective ethernet and ppp/pppoe installs. It is still somewhat 
basic at this time w/o full capabilities (in my scripts). To keep the 
size managable and the scripts/configuration in a non-confusing state,
/etc/network.conf will likely cease to exist as we know it and likely
be broken down into several different files. 

Preferably, IMHO, this wouldn't necessarily be a good thing in the 
Dachstein release for the following reasons:

1. It breaks compatibility for support and configuration
as we know DCD now if expanded too much, or simply
becomes a byte-monster (within my scripting skills).

2. The next major CS release will likely be a move to
something quite non-DCD compatible and we will
have to rewrite everything (to some degree). 

Testing/devel on DCD would be allright towards a
a new layout, but not very practical considering the
end of the "mountain" base is approching.

3. For reason #2, script development on Bering might
be a more resonable place to start and incorporate
into the next CS release. It is likely to be more 
compatible than DCD, I guess we'll see when a 
devel base or bases appear. This would be the time
to consider  the _future_ format though, rather than as  
an afterthought. 

4. A floppy-generator will likely be the best move in the
future to achieve a more verstile floppy. Once that
network.conf is broken down, you lose the benefit
of the file itself, and pure script configuration would
be a very nice option (IMHO).


You could use these "scripts" as a lrcfg menu item (as I have started) 
or a weblet-configuration applet, all of which could be added/removed
as packages themselves for user preferences. Things are in a planning 
stage (on my part anyway), so there won't be (much) re-work towards
a final product. I would prefer to extend as opposed to re-write, but
that is dependant on future distribution bases implicitly. 

You can find my scripts (testing), that work for ethernet/cable at:
http://leaf.sourceforge.net/devel/guitarlynn

I'm more than willing to take any and all suggestions, advice, and help
that anyone is willing to give. The more I look into it, the necessary 
planning gets to take up a pretty wide scope!

-- 

~Lynn Avants
aka Guitarlynn

guitarlynn at users.sourceforge.net
http://leaf.sourceforge.net

If linux isn't the answer, you've probably got the wrong question!


___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] Hardware router Linux look-alike

2002-02-04 Thread Erich Titl

Hi folks

Maybe it's worth to hava a look at

http://www.fli4l.de/e_index.htm

They apparently did quite a good job on the config stuff using a GUI 
client, maybe it's adaptable

>Date: Sun, 03 Feb 2002 23:31:45 -0800
>From: Matt Schalit <[EMAIL PROTECTED]>
>Subject: Re: [Leaf-user] Hardware router Linux look-alike
>To: [EMAIL PROTECTED]
>
>Stewart Adey wrote:
> >
> > Does anyone know how _HARD_ it would be to create an interface like so many
> > commerically available hardware routers on the market?
>
>
>Start small.  There's nothing wrong with learning how
>to shell script.  Btw, David has mentioned a few times
>that his menu configuration system is almost done.
>You can use his dialog.lrp to make menus.  And
>there's Xdialog I think to for remote usage.
>

regards

Erich


___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] Hardware router Linux look-alike

2002-02-04 Thread JMullan


I can see the point.  network.conf (and others) would need a re-write to
make my idea work.


However, once I further my scripting knowledge I may just look at tackling
one or two little areas.


Cheers.





   

  guitarlynn   

cc:   
[EMAIL PROTECTED]   
   Subject:  Re: [Leaf-user] Hardware 
router Linux look-alike  
  02/04/02 12:57 PM

   

   





On Monday 04 February 2002 08:24, [EMAIL PROTECTED] wrote:



that anyone is willing to give. The more I look into it, the necessary
planning gets to take up a pretty wide scope!

--

~Lynn Avants
aka Guitarlynn

guitarlynn at users.sourceforge.net
http://leaf.sourceforge.net

If linux isn't the answer, you've probably got the wrong question!






___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] LRP Oxygen CD and floppy disk boot question

2002-02-04 Thread malik menzong

My box is working
I would like to a few minutes to say thanks to all of you who provided me 
with such wonderful and unselfish assistance. Thanks Dave and Jeff Lynn and 
everyone else on this post. I am going to write a little step by step 
procedures as well. Hopefully it will help someone who is trying to do the 
same thing.
-M


>From: Jeff Newmiller <[EMAIL PROTECTED]>
>To: malik menzong <[EMAIL PROTECTED]>
>CC: [EMAIL PROTECTED], [EMAIL PROTECTED]
>Subject: Re: [Leaf-user] LRP Oxygen CD and floppy disk boot question
>Date: Wed, 30 Jan 2002 16:35:31 -0800 (PST)
>
>On Thu, 31 Jan 2002, malik menzong wrote:
>
> > Lynn:
> > That is what I was saying. I open the resolv.conf file and wrote 
>something
> > like this:
> > XXX.XXX.XXX # DNS0
> > XXX.XXX.XX # DNS1
> >
> > That is the only thing in that file. From behind the firewall I can ping 
>to
> > both network card address. from the router I can ping to the gateway 
>fine.
> > But if I type:
> > ping cnn.com or ping XXX.XXX.XXX (actually ip address for cnn) it wont
> > resolve it. all packets are lost.
>
>Sounds like you don't have a default gateway specified.
>
>Note that default gateway is different than gateway... the latter can
>apply to any route, but the former means the route destination is 0.0.0.0.
>I don't use Oxygen so I dont know what variables you need to change.
>
>---
>Jeff NewmillerThe .   .  Go Live...
>DCN:<[EMAIL PROTECTED]>Basics: ##.#.   ##.#.  Live Go...
>   Live:   OO#.. Dead: OO#..  Playing
>Research Engineer (Solar/BatteriesO.O#.   #.O#.  with
>/Software/Embedded Controllers)   .OO#.   .OO#.  rocks...2k
>---
>
>
>___
>Leaf-user mailing list
>[EMAIL PROTECTED]
>https://lists.sourceforge.net/lists/listinfo/leaf-user


_
Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp.


___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] DCD, ipsec, gateways & road warriors ???

2002-02-04 Thread Charles Steinkuehler

> > > Do the samba servers need to communicate with each other?  If so, the
> > > DCD gateways cannot ping each other, because they are concurrent with
> > > the gateway itself -- although, from anywhere else on the remote
> > > network, we can ping the opposite gateway by private address.
> >
> > This is a routing issue.  The VPN connects the two private IP LAN's.
> > Default traffic sent between the two VPN gateways will use a source IP
of
> > the primary external interface, so the gateway-gateway packets don't
match
> > your subnet-subnet tunnel.  You can either build a gateway-gateway
tunnel
> > for the samba traffic, or possibly send the gateway-gateway traffic
through
> > the existing subnet-subnet tunnel via advanced routing.
>
> I give up!
>
> How do we accomplish either suggestion in your last sentence?  What do
> we need to do?

The easiest is the first suggestion, build a gateway-gateway tunnel.  To do
this, simply clone your existing subnet-subnet ipsec configuration, and
delete the [left|right]subnet sections.  This will allow your two VPN
gateways to talk to each other.

Charles Steinkuehler
http://lrp.steinkuehler.net
http://c0wz.steinkuehler.net (lrp.c0wz.com mirror)



___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] QOS question.

2002-02-04 Thread David McBride

Anyone hear of the Sorenson broadcast algorithm?

Thanks,
David

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] Oxygen CD

2002-02-04 Thread Cokey de Percin

Is there an Oxygen 1.8 CD image and if so, where can it be found?

There seems to be one at http://download.sourceforge.net/leaf
called Oxygen_1.8_iso_OxygenISO.bin, but the file is empty.

Tnx

Cokey

-- 
--
F. 'Cokey' de Percin, DBA   Email:
CSC (formerly Mynd)  Work - [EMAIL PROTECTED]
Columbia, South Carolina Home - [EMAIL PROTECTED]

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] LEAF "Bering" beta-3 available

2002-02-04 Thread Jacques Nilo

The LEAF 2.4.16 - beta2 distribution has been updated and now becomes
LEAF "Bering" - beta3.
Main features:

- 2.4.16 Kernel with support for IDE, DOC, SCSI, Parport, USB, PPP,
PPPoE, PPPoA, PCMCIA, ISDN, Bridging, ext2/ext3/reiserfs, IPV6, Wireless
LAN, ...
- Provided with latest 1.2.5 Shorewall package
- New packages available: pcmcia.lrp (3.1.31), wireless.lrp and
ppp-filter.lrp in the Bering package area
- Winimage disk image now available for Windows users
- Updated documentation

Stills fit on a 1680K floppy :-)

The detailed changelog is available at:
http://leaf.sourceforge.net/devel/jnilo/leaffw00.html#AEN68

For the full documentation refer to:
http://leaf.sourceforge.net/devel/jnilo/leaffw.html

Files are available for download at:
http://leaf.sourceforge.net/devel/jnilo/bering/latest/

Extra packages available at:
http://leaf.sourceforge.net/devel/jnilo/bering/packages/

Cheers
Jacques




___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] Cyclades & LEAF firewall routing question

2002-02-04 Thread Cokey de Percin

First I'd like to thank Charles and everyone else who worked on the
Dachstein release.  It's exceptional!  I've been running various LRP
and LEAF releases for the last few years, but this one is by far the
best.  

Now some background for my question.  I've set the Dach (and others) 
up for basic firewall and routing, DMZ and VPN setups, but this is the 
first time I've set up what I'd call a Bastion firewall.  I have a 
Cyclades 300 single port with DSU/CSU in a small pentium machine 
attached to a full T1 using Frame Relay.  I've modified the Dach 
release for support for the Cyclades hardware and it all works.  I 
have a block of 8 assigned public addresses to work with, one of which 
is be on eth1 (internal) of the bastion firewall, one is on eth0 
(external) of the Choke firewall guarding the internal private 
network, and the rest will be used as needed in the DMZ between the 
Bastion and the Choke machines.  

Now... on the Bastion firewall the Cyclades/Bell South setup puts a 
172.20.xx.xx address on the external (pvc0) interface (and yes there
is an hdlc0 interface, but no address get assigned to it) with the 
first of my static addresses on eth0, my internal interface, like this:
 
   internet
  | 

172.20.x.y pvc0 

   bastion  

65.83.a.b eth0

  |
   
 DMZ   
  
  |

Choke

  |

 private network

At this point I'm a bit lost as how to setup my firewall.  I don't see 
how I can use the external (pvc0) interface in the firewall setup as it 
uses private addresses.  I'm sure I'm missing something here...  If 
someone would clue me in I'd greatly appreate it!

Best

Cokey

-- 
--
F. 'Cokey' de Percin, DBA   Email:
CSC (formerly Mynd)  Work - [EMAIL PROTECTED]
Columbia, South Carolina Home - [EMAIL PROTECTED]

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] Oxygen CD

2002-02-04 Thread Mike Noyes

At 2002-02-04 17:52 -0500, Cokey de Percin wrote:
>Is there an Oxygen 1.8 CD image and if so, where can it be found?
>
>There seems to be one at http://download.sourceforge.net/leaf
>called Oxygen_1.8_iso_OxygenISO.bin, but the file is empty.

Cokey,
That's because I inadvertently released a file that David didn't want 
released. Every one of the zero byte files there is a mistake by me. :-(

Note: this is the only way I know of to simulate deleting a released file 
on SourceForge.

--
Mike Noyes <[EMAIL PROTECTED]>
http://sourceforge.net/users/mhnoyes/
http://leaf.sourceforge.net/content.php?menu=1000&page_id=4


___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



RE: [Leaf-user] changing internal subnet addrs on Dachstein

2002-02-04 Thread Christopher Holmes

That did it!
Thanks!

> -Original Message-
> From: Tony [mailto:[EMAIL PROTECTED]]
> Sent: Monday, February 04, 2002 8:57 AM
> To: [EMAIL PROTECTED]; [EMAIL PROTECTED]
> Subject: RE: [Leaf-user] changing internal subnet addrs on Dachstein
> 
> Don't forget hosts.allow
> 
> Later
> 
> Tony
> 
> 
> 
> > -Original Message-
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED]]On Behalf Of Christopher
> > Holmes
> > Sent: Sunday, February 03, 2002 5:34 PM
> > To: [EMAIL PROTECTED]
> > Subject: [Leaf-user] changing internal subnet addrs on Dachstein
> > 
> > 
> > I just changed the internal network address on my Dachstein box.
> > 
> > I changed the 192.168.1.xx to 192.168.5.xx in...
> > 
> > /etc/dhcpd.conf
> > /etc/network.conf
> > /etc/sh-httpd.conf
> > 
> > /etc/ipfilter.conf looked OK as-is.
> > 
> > I backed up packages etc, dhcpd, & weblet. Everything works 
> fine except I
> > can't get the weblet page to display.
> > 
> > What did I miss?
> > 
> > Chris



___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] crontab vs /etc/cron.d/multicron

2002-02-04 Thread David Douthitt

On 2/4/02 at 8:53 AM, Victor McAllister <[EMAIL PROTECTED]> wrote:

> crontab would not correctly run the command.  Same command in
> multicron works.  Strange - but at least it works now.
> -
> # cat /etc/cron.d/multicron
> #Periodic schedule for multicron. (Ping check, Space check, etc)
> #Default: Every 15 minutes
> */15* * * * root/etc/multicron-p
> 11 05,11,17,23   * * *   rootrdate -s 132.163.4.101
> 12 05,11,17,23   * * *   roothwclock --systohc
> 
> --

Entries in crontab should be pathed explicitly; what if you replace
"rdate ..." with "/usr/bin/rdate ..." or whatever?  Same for
hwclock...

Just a mini-soapbox: I never understood the need for "multicron-p"
anyway: Oxygen has removed it some time ago.  Multicron doesn't
provide any new capabilities at all that I can see - cron can do just
fine.  Seemed like multicron just provided several layers of
unnecessary indirection on top of cron and took up more disk space...

Another note: rdate uses an old obsolete form of network time
synchronization; I suspect more and more time servers may stop
providing the service rdate uses (wuarchive.wustl.edu seems to have
stopped...)

If anyone's bundled it, ntpdate would be better to use...
--
David Douthitt
UNIX Systems Administrator
HP-UX, Unixware, Linux
[EMAIL PROTECTED]

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] Oxygen CD

2002-02-04 Thread David Douthitt

On 2/4/02 at 5:52 PM, Cokey de Percin <[EMAIL PROTECTED]> wrote:

> Is there an Oxygen 1.8 CD image and if so, where can it be found?
> 
> There seems to be one at http://download.sourceforge.net/leaf
> called Oxygen_1.8_iso_OxygenISO.bin, but the file is empty.

I can't speak to the latter, but the former I can...

The Oxygen Bootable CDROM is now being worked on with Oxygen 1.9 as
its base.  Oxygen 1.9 uses a Linux kernel with no LRP-specific patches
in it.  The current 1.9 development is focused on Linux 2.2.20; future
development will use 2.4.17.

An Oxygen 1.8 Bootable CDROM shouldn't be difficult to put together;
I've just not done it.  Using a generic unpatched Linux kernel proved
to be too attractive :)

If there is call for one I can put one together
--
David Douthitt
UNIX Systems Administrator
HP-UX, Unixware, Linux
[EMAIL PROTECTED]

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



[Leaf-user] Need help getting LEAF running

2002-02-04 Thread hallm



I recently acquired cable internet service through 
AT&T @Home. I currently lease their SURFBoard SB3100 cable modem. My 
intended LEAF box is a Pentium 120MHz with 16MB RAM, 1.44 MB floppy, 1 DLink 
DFE530TX+ NIC, and 1 NetGear FA311 NIC. The BIOS is AMIBIOS 1.00.02.CB0. My 
internal, windows box has a NetGear FA311 NIC as well.
 
I started with Dachstein v1.0.2-1680. I uncommented 
pci-scan and added via-rhine (for the DLink NIC) and natsemi (for the NetGear 
NIC) in /etc/modules (I also tried the fa311 module without successful boot). 
The natsemi.o and via-rhine.o modules were added and backed up.
 
I modified network.conf as follows (everything else 
left at default setting):
MAX_LOOP=2
HOSTNAME=BIER
HOSTS0="eth1_IPADDR $HOSTNAME.attbi.com $HOSTNAME 
fw"
 
I backed up etc.
 
When I reboot two of the last messages to appear on 
the console are:
No subnet declaration for eth1 
(0.0.0.0).
Please write a subnet declaration in your 
dhcpd.conf file for the network segment to which eth1 is attached. 
 
I've seen some discussion in the archives regarding 
these messages, but there doesn't appear to be a consensus on the resolution. 
The Dachstein documentation implies that configuration will be automatic when 
connected to a DHCP server. Does that mean the subnet declaration in dhcpd.conf 
is OK? Or do I need to modify this file?
 
Other discussions center on whether or not the 
lease must be released prior to booting the LEAF box with the modem attached. I 
tried releasing the lease via winipcfg, and then connecting the modem to the 
LEAF box without any success. I also tried resetting the modem via power down (a 
couple hours) to clear the MAC address, without success. I also tried an archive 
suggestion to set the eth0 MAC address in network.conf to that of the NIC in the 
windows box, which was used to install the internet service. This also seemed to 
have little effect.
 
Several perhaps pertinent messages scroll by on the 
console during boot up too fast to read (is there a way to scroll back?). 

 
I managed to catch the following messages on 
screen, but not in logs:
DHCPDISCOVER on eth0 to 255:255:255:255 port 
67
DHCPOFFER 12.242.19:34
DHCPREQUEST on eth0 to 255:255:255:255 port 
67
DHCPACK 12:242:19.34
 
Does this look like a good handshake? winipcfg on 
the windows box shows that 12.242.19.34 is the ISPs DHCP server. Other pertinent 
info from winipcfg:
MAC address: 00-02-E3-04-DA-61 (I tried to assign 
this number to eth0)
IP address: 12.252.81.273
subnet mask: 255.255.248.0
Default Gateway: 12.252.80.1
 
Upon logging in to LEAF box I tried to ping 
192.168.1.1. This resulted in 100% packet loss, but the NIC lights appeared to 
cycle at 1 Hz as someone in the archives has suggested.
 
I executed net start with the following 
result:
 
Starting Network:[IP Always Defrag: 
ENABLED]
    IP Filters: firewall [IP 
forwarding: ENABLED]
    Loopback interface: 
lo
    Starting interface: Cannot find 
device eth1
SIOCGIFFLAGS: Operation not supported by device 
eth1
    Hostname: BIER
    Static NS: 2 hosts
 
It seems that regardless which slot the NICs 
are in or which order the module names are listed in /etc/modules, eth0 is 
always associated with the NetGear NIC. How do I force the use of the DLink NIC 
as eth0?
 
About the only things I have not tried 
are:
1. Attempting to boot LEAF box with only one 
NIC.
2. swapping the Windows NIC with one of the LEAF 
NICs
 
Can anyone suggest what I might try next to get 
this LEAF box operational? Any help will be appreciated.
 
Thanks,
Mike
 
 


Re: [Leaf-user] DCD & java ???

2002-02-04 Thread KP Kirchdörfer

Am Montag, 4. Februar 2002 16:25 schrieb Jack Coates:
> On Sun, 3 Feb 2002, Matt Schalit wrote:
> > To strip it for leaf, I'm thinking that the
> >
> >libraries/clib/awt/*
> >libraries/javalib/java/awt/*
> >
> >
> > stuff contributes the most useless parts, simply because it's all
> > X and gui applets or standalone gui application classes.  Also
> > the appletviewer is not needed, and that's part of a jre.
>
> agreed, but it looks like one must modify the source tree or
> Makefile to disable these, and it's definitely complex territory
> for someone who doesn't write Java and has no idea what's needed
> and not needed.

Another interesting link is:
http://www.embedded.oti.com/

where you'll find and IDE and Runtime's for different versions of 
embedded java - more fine-grained than kaffe - which hasn't been 
updated for mor ethan a year, whereas this edition is still under 
development and as far as I understand it will become part of eclipse 
(www.eclipse.org).

I tried something on that area, but failed with errors once I've 
started java on dcd, but this was sometime ago. Will look into it 
again later this week.

kp 

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user



Re: [Leaf-user] Need help getting LEAF running

2002-02-04 Thread guitarlynn

Your external NIC is coming up fine (the harder part), 
your internal NIC isn't.  

The dfe-530tx+ (note the "+") uses the rtl8139 module (note rt"L", 
not a "1"). You can download and add this module from Charles' site in
the 2.2.19 kernel directory.

To copy the module to your disk, download it and put it on a blank
floppy, boot Dachstein, enter the floppy with the added module, and
enter this:

mount -t msdos /dev/fd0 /mnt
cd /mnt
cp ./rtl8139.o /lib/modules/
cd /
umount /mnt

Now, fire "lrcfg" and edit "modules" to reflect the added "rtl8139
module and the "8390" module _below_ the "pci-scan" line. Exit and Save
the "modules" file, then back-up the modules package.

Do this and you should be working! 
-- 

~Lynn Avants
aka Guitarlynn

guitarlynn at users.sourceforge.net
http://leaf.sourceforge.net

If linux isn't the answer, you've probably got the wrong question!

___
Leaf-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user