[Leaf-user] pppd and PPPoe together

2001-06-18 Thread Joseph L. Patt III
Hello all,   I am running an Eigersteinbeta variant with PPPOE.  I want to be able to add an incoming dialup account using pppd that would be masq'ed like any other client.  I'm worried that if I install pppd that it may overwrite configuration files for the PPP and PPPOE packages I already

Re: [Leaf-user] LEAF (LRP)

2001-06-18 Thread Ray Olszewski
At 11:06 PM 6/18/01 -0500, NOC wrote: >Well, I hate to say it... but the daemons have just gotten to big >to keep updated with a floppy based router. There is NO way I can >get the basics on a single floppy (sshd, telnet, psentry) and have >the thing boot. My drive just doesnt like the la

Re: [Leaf-user] LEAF (LRP)

2001-06-18 Thread Greg Morgan
How about a second floppy drive for $15 to $25? I have two in my firewall just for easy of use. You would have to set your syslinux package path variable so that LEAF can find the modules on the second drive. >From the optional section of http://lrp.steinkuehler.net/files/diskimages/eiger/Eige

Re: [Leaf-user] LRP 2.9.8 (2.0.x) and sshd

2001-06-18 Thread Jacques Nilo
From: "Ray Olszewski" <[EMAIL PROTECTED]> > Chris -- the Koon Wong versions of ssh and sshd are pretty old. I believe > there has been (at least) one security-update release since it day. I did > find what I think are newer versions of ssh and sshd ("Openssh v2.9p1") on > the LEAF site, at URL > >

RE: [Leaf-user] LEAF (LRP)

2001-06-18 Thread Steven Peck
Ack, html email. You could always just go with a second floppy drive. Other solutions, zip drive, LS-120 and Compaq Flash memory. http://leaf.sourceforge.net/article.php?sid=25&mode=&order=0 for sshd v2.9p1 Though I suspect you already know that. I hope to set up a dual floppy drive system a

Re: [Leaf-user] LEAF (LRP)

2001-06-18 Thread Victor McAllister
> NOC wrote: > > Well, I hate to say it... but the daemons have just > gotten to big to keep updated with a floppy based router. > There is NO way I can get the basics on a single floppy > (sshd, telnet, psentry) and have the thing boot. My drive > just doesnt like the larger floppies. > >

Re: [Leaf-user] vnc through lrp

2001-06-18 Thread Victor McAllister
> Dean Moreton wrote: > > Hey there thanks alot for your advice much appreciated. I > understand most of what it is doing, but being a bit of a > newbie just need a bit of clarification with what the dhcp > bit is doing. > > so this is entered into/edited in the /etc/dhcp.conf on my > lrp box?

Re: [Leaf-user] vnc through lrp

2001-06-18 Thread Scott C. Best
Dean: I use VNC in a manner very similar to what you want to do. You should try out the echowall.lrp firewall config script: I designed it specifically for people "a bit new to this stuff", and it's pretty tiny (~11k I think). It's got the VNC rules built in, plays nice with PPPoE, and w

[Leaf-user] LEAF (LRP)

2001-06-18 Thread NOC
    Well, I hate to say it... but the daemons have just gotten to big to keep updated with a floppy based router.  There is NO way I can get the basics on a single floppy (sshd, telnet, psentry) and have the thing boot.  My drive just doesnt like the larger floppies.       The only sshd, for

RE: [Leaf-user] vnc through lrp

2001-06-18 Thread Dean Moreton
Hey there thanks alot for your advice much appreciated. I understand most of what it is doing, but being a bit of a newbie just need a bit of clarification with what the dhcp bit is doing.   so this is entered into/edited in the /etc/dhcp.conf on my lrp box?   >dynamic-bootp-lease-length 604

RE: [Leaf-user] Routing in Prozy ARP DMZ

2001-06-18 Thread Dan
Charles, We are definitely making progress, but a few kinks remain. Subject: Re: [Leaf-user] Routing in Prozy ARP DMZ RE: Ping failures >You've got me on this one...I don't know why pings are not working. There are no denies of ICMP packets in your firewall rules listed above. Is the

Re: [Leaf-user] LRP 2.9.8 (2.0.x) and sshd

2001-06-18 Thread Mike Noyes
Ray Olszewski, 2001-06-18 15:27 -0700 >Chris -- the Koon Wong versions of ssh and sshd are pretty old. I >believe there has been (at least) one security-update release since it >day. I did find what I think are newer versions of ssh and sshd >("Openssh v2.9p1") on the LEAF site, at URL > >

Re: [Leaf-user] vnc through lrp

2001-06-18 Thread Victor McAllister
Dean Moreton wrote: > Hi, im using a modified version of Eigersteinbeta 2 with a > pppoe package. What id like to achieve is to be able to > vnc into a machine on my internal network through my lrp > box from an external ip (i.e work). I take it this will > require some modifying of the ip rules

RE: [Leaf-user] vnc through lrp

2001-06-18 Thread Dean Moreton
hey thanks for the advice, only problem is my lrp disk is full. Ive always wanted to add ssh to it but theres not enough room for it.  Im not too fussed about it being too secure as its only my home box so theres nothing too important on it.  Is there away you can tunnel it without ssh??    

Re: [Leaf-user] eigersteinbeta2 Docs

2001-06-18 Thread Ray Olszewski
At 07:03 PM 6/18/01 -0500, NOC - KP2 wrote: >I have 2 questions about eigerstein. > >1.) Where can I find different modules (sshd, psentry, etc) that can >be used with this? I know about lrp.c0wz.com, but I am unsure where >I need to bee looking for the proper modules. You mean packages; modu

[Leaf-user] eigersteinbeta2 Docs

2001-06-18 Thread NOC - KP2
I have 2 questions about eigerstein. 1.) Where can I find different modules (sshd, psentry, etc) that can be used with this? I know about lrp.c0wz.com, but I am unsure where I need to bee looking for the proper modules. 2.) Is there a guide anywhere for someone that is converting from LRP 2

Re: [Leaf-user] vnc through lrp

2001-06-18 Thread Michael McClure
I would use SSHD on the LRP and tunnel VNC through SSH. You'd establish the ssh connection to your LRP with tunnels set up (For a Windoze clt, I'd use SecureCRT if you use the SSH1 package (30 day free trial which you can reload), and SSH Communications software with an individual license if you

[Leaf-user] vnc through lrp

2001-06-18 Thread Dean Moreton
Hi, im using a modified version of Eigersteinbeta 2 with a pppoe package.  What id like to achieve is to be able to vnc into a machine on my internal network through my lrp box from an external ip (i.e work). I take it this will require some modifying of the ip ruleset i.e port forwarding et

Re: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread James Barrett
Nope. He's got kernels for FPU emulation on 2.2.16 and 2.2.16 with the VPN patches, but not both options together. -J - Original Message - From: "Steven Peck" <[EMAIL PROTECTED]> To: "'James Barrett '" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Monday, June 18,

Re: [Leaf-user] A strange firewall log

2001-06-18 Thread Ray Olszewski
Jacques -- the additional information doesn't give me any great ideas. You do mention that you get a dynamic address. Might it be that it was *once* 195.132.172.176 that that you're getting the packets due to some arp cache not updating properly (especially plausible since the address seems not to

RE: [Leaf-user] LRP 2.9.8 (2.0.x) and sshd

2001-06-18 Thread Steven Peck
I have never understood the urge to use Koon Wong's ssh. I have always used the ssh from the kernel for the distribution I setup. -sp -Original Message- From: Ray Olszewski To: [EMAIL PROTECTED]; [EMAIL PROTECTED] Sent: 6/18/2001 3:27 PM Subject: Re: [Leaf-user] LRP 2.9.8 (2.0.x) and s

RE: [Leaf-user] Newbie questions

2001-06-18 Thread Steven Peck
Keep in mind that any speed increase you see from using switches instead of hubs (I use 10/100 Netgear hubs at home) will only be on your internal network. I have had great luck with the Netgear FA-310tx NIC. It uses the tulip driver. I was so happy with it, that I replaced all my internal NI

Re: [Leaf-user] LRP 2.9.8 (2.0.x) and sshd

2001-06-18 Thread Ray Olszewski
At 04:14 PM 6/18/01 -0500, Chris wrote: >Quick question about sshd. I am running the sshd.lrp from the Koon Wong lrp >archive and every so often it seems that the daemon just dies. It wont >accept connections for a period of time, then all of a sudden, its back up >and running as it should. The

RE: [Leaf-user] Stupid Newbie questions

2001-06-18 Thread Hilton Travis
Hi, I tend to agree with Jon here. Since you are new to Linux and networking in general, you need to have the simplest setup you can, so that there are fewer things to go wrong. In your case, I'd install 2 NICs in the LRP box as per Jon's suggestions, locate the box at one end of the house, run

Re: [Leaf-user] Stupid Newbie questions

2001-06-18 Thread Ray Olszewski
At 01:10 PM 6/18/01 -0700, James A Roush wrote: >We recently moved into a house with a DSL line and more 7 comuters. Half >the computers are on one end of the the house and half more or les on the >other end. What we would like to do is build a box with thre NICs. The >first would be for the DS

Re: [Leaf-user] George Metz' 2.4.3 image

2001-06-18 Thread Charles Steinkuehler
> So knowing that 2.4 kernels are definitely experimental, I grabbed > George Metz' 2.4.3 distribution of his site and booted it up. It booted > up fine (though I had issues with the newest syslinux, had to use 1.54 > instead of 1.62), but it doesn't include IDE support (unless I totally > missed

Re: [Leaf-user] Using PoPToP behind LRP

2001-06-18 Thread Charles Steinkuehler
> > > I was looking at installing PoPToP (PPTP server) on a RedHat server on > my > > > internal network so users at home, mobile etc. can access our Samba > shares > > > using a dialup connection. > > > > > > I know I need to open ports 1723 (tcp) and protocol 47 to allow the PPTP > > > protocol

RE: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread Steven Peck
Dude, http://lrp.steinkuehler.net/files/kernels/ There might be a few more poking around the leaf developers sites. -sp -Original Message- From: James Barrett To: [EMAIL PROTECTED]; [EMAIL PROTECTED] Sent: 6/18/2001 2:11 PM Subject: Re: [Leaf-user] Now here's an interesting auction I

RE: [Leaf-user] LRP 2.9.8 (2.0.x) and sshd

2001-06-18 Thread Steven Peck
While I haven't had any problems with mine. It has been reported and some suspect it is a session timeout setting. I forget where the setting is, but hopefully someone will pop up with it before I get home tonight and have to look myself. -sp -Original Message- From: Chris To: [EMAIL

Re: [Leaf-user] Routing in Prozy ARP DMZ

2001-06-18 Thread Charles Steinkuehler
> >I assume your reports of ping failures are accurate, but the cause is not. Your routing tables are setup properly (assuming your server machines are on the DMZ and not plugged directly into the cable-modem network). > > OK...now it's just the pings that are failing. I can access the server in

[Leaf-user] LRP 2.9.8 (2.0.x) and sshd

2001-06-18 Thread Chris
Quick question about sshd. I am running the sshd.lrp from the Koon Wong lrp archive and every so often it seems that the daemon just dies. It wont accept connections for a period of time, then all of a sudden, its back up and running as it should. There doesnt seem to be any pattern to the amou

Re: [Leaf-user] Stupid Newbie questions

2001-06-18 Thread Peter Nosko
--- Jonathan French <[EMAIL PROTECTED]> wrote: > To follow up on Danny's answers, and to save you a lot of trouble, if it > doesn't cost too much skip the 3 NICs and just use two and buy an extra > hub. Use one NIC for the DSL, and plug the second NIC into the extra > hub (or switch) which then s

Re: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread James Barrett
I would find it valuable as I have not yet been able to find anyone willing to compile a 2.2.16 w/patches for VPN Masq'ing (or 2.2.18 or 2.0.38) kernel with the FPU emulation for a 486SX2. I can easily get the modules I need to build my own disk -- the problem I'm having is finding the right comp

[Leaf-user] LRPGen for LEAF

2001-06-18 Thread Mike Noyes
James Sturdevant, 2001-06-18 13:42 -0500 >Actually, I made the changes to Paul's modmaker to create LRPGen. Paul >hosted it for a while to test it. I gave up on it when I couldn't make it >work on WinXX machines with 1.68MB formats and it appeared that the newer, >unofficial releases were getti

Re: [Leaf-user] Stupid Newbie questions

2001-06-18 Thread Jonathan French
To follow up on Danny's answers, and to save you a lot of trouble, if it doesn't cost too much skip the 3 NICs and just use two and buy an extra hub. Use one NIC for the DSL, and plug the second NIC into the extra hub (or switch) which then services the other two hubs. That way you won't have a

[Leaf-user] George Metz' 2.4.3 image

2001-06-18 Thread Zachariah Mully
Howdy all- I recently started toying with the idea of deploying a LEAF based firewall/VPN in our colo after I saw Exodus wants $4000/mo. for a "managed" Cisco Pix. I figure LEAF probably can save me some of that $48,000. So my questions revolve around the possibilities of using 2.4.3+ kern

Re: [Leaf-user] Stupid Newbie questions

2001-06-18 Thread Danny Carter
First off, there are NO stupid questions. What we would like to do is build a box with thre NICs. The > first would be for the DSL line and the other two NICs would each service a > hub. Is this feasible? Yes > I also have the questions: > >1: I've never used hubs before, how do you ass

Re: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread James Sturdevant
Actually, I made the changes to Paul's modmaker to create LRPGen. Paul hosted it for a while to test it. I gave up on it when I couldn't make it work on WinXX machines with 1.68MB formats and it appeared that the newer, unofficial releases were getting more support and use. (Dave's attitude di

Re: [Leaf-user] Using PoPToP behind LRP

2001-06-18 Thread John P
> > I was looking at installing PoPToP (PPTP server) on a RedHat server on my > > internal network so users at home, mobile etc. can access our Samba shares > > using a dialup connection. > > > > I know I need to open ports 1723 (tcp) and protocol 47 to allow the PPTP > > protocol to work, and I c

Re: [Leaf-user] A strange firewall log

2001-06-18 Thread Ray Olszewski
At 07:23 PM 6/18/01 +0200, Jacques Nilo wrote: >Dear Leaf fellows ! >I have been receiving in my syslog for the past few days this type if >record: >Jun 18 19:04:49 firewall kernel: Packet log: input DENY eth0 PROTO=6 >210.232.219.66:3377 195.132.172.176:25 L=44 S=0x10 I=24833 F=0x4000 T=95 >SYN (

RE: [Leaf-user] Using PoPToP behind LRP

2001-06-18 Thread Steven Peck
let's see. SOmeone will correct me if I am wrong. I think you will need to change your kernel with one compiled with the pptp stuff compiled in. See Charles' site for one. Or peruse the devlopers sites on Leaf and replace the one on your system. then you will probably need a combination of ip

[Leaf-user] A strange firewall log

2001-06-18 Thread Jacques Nilo
Dear Leaf fellows ! I have been receiving in my syslog for the past few days this type if record: Jun 18 19:04:49 firewall kernel: Packet log: input DENY eth0 PROTO=6 210.232.219.66:3377 195.132.172.176:25 L=44 S=0x10 I=24833 F=0x4000 T=95 SYN (#45) The strange thing is that the destination adress

Re: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread Ray Olszewski
At 07:54 AM 6/18/01 -0400, James Barrett wrote: >I remember there used to be those places where you entered what you wanted >and an image was built for you -- do they still exist anywhere? No, at least not if you mean in a LEAF or LRP context. There was modmaker, a system used with LRP 2.9.3 to m

Re: [Leaf-user] Re: Commands for the Eigerstein

2001-06-18 Thread Victor McAllister
Martin Randall wrote:Eigerstein. > > Does anyone else have problems with :- > > A) Occasional problems saving/exiting the setups. Sometimes ctrl-c and > alt-q don't work and I have to use ctrl-k/alt-k. > > B) Quite often, doing a simple change (removing a singles #) will prevent > me from ba

RE: [Leaf-user] Routing in Prozy ARP DMZ

2001-06-18 Thread Dan
>I think you're getting close...I'll try to help you get everything working properly. Much appreciated :) >I assume your reports of ping failures are accurate, but the cause is not. Your routing tables are setup properly (assuming your server machines are on the DMZ and not plugged directly

Re: [Leaf-user] Compiling cipe for lrp

2001-06-18 Thread Charles Steinkuehler
> Ok I have been trying to make CIPE work with eigersteinbeta2 I have > tried 3 different cipe lrp packages and juest about every lrp kernel > version 2.2.16 I could get my hands on. Every single one of them throws > errors beyond config issues. I found on the CIPE website a comment about > the ty

Re: [Leaf-user] Routing in Prozy ARP DMZ

2001-06-18 Thread Charles Steinkuehler
> I have my game servers in the DMZ, and they can "see" the internet, browse the web, etc. I have tested an http server running on one of them, and it is accessible from the outside. My external testers still can't see the game servers --- but I'll park that concern for now, since the http serve

Re: [Leaf-user] IP Packet Rejection

2001-06-18 Thread Charles Steinkuehler
> I am using the newest Eiger2Beta from Charles Steinkuehler's site. I > have set it up exactly as specified on the leaf site with Rich Lohman's > How-to at: > http://nw-hoosier.dyndns.org/rlohman/linux/eiger-contents.html > > The main problem I have is, when everything is connected I can ping

RE: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread Tony
I think what you were thinking of was the modmaker, which made the modules on the fly for what you needed. That thing has been dead since before I logged onto the list (May 2000). That was for the old 2.9.4 which ran the 2.0.36 kernel (I think that was the kernel). All that has been solved by t

[Leaf-user] Re: Commands for the Eigerstein

2001-06-18 Thread Martin Randall
Hello Martin On 17-Jun-01, you wrote: > Hello Charles. > > I've got a problem. ah...forget it.. just tired. Comes from supporting 13 OS's. Eigerstein. Does anyone else have problems with :- A) Occasional problems saving/exiting the setups. Sometimes ctrl-c and alt-q don't work and I hav

Re: [Leaf-user] Now here's an interesting auction

2001-06-18 Thread James Barrett
I remember there used to be those places where you entered what you wanted and an image was built for you -- do they still exist anywhere? Thanks, -J - Original Message - From: "Michael McClure" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Sunday, June 17, 2001 10:28 PM Subject: Re:

RE: [Leaf-user] problem with itapi cdrom

2001-06-18 Thread Luis.F.Correia
It is probably just that, a VERY old CD-ROM. The lens is probably full of dirt and therefore, the CD-ROM is almost blind :) Try the same thing with a new one. -Original Message- From: douglas orr [mailto:[EMAIL PROTECTED]] Sent: Saturday, June 16, 2001 10:23 PM To: [EMAIL PROTECTED] Sub

[Leaf-user] Routing in Prozy ARP DMZ

2001-06-18 Thread Dan
OKit seems I have straightened out the first layer of problems with my setup --- thanks Charles. Now, I am running into my limitations on proper routing statements. I have my game servers in the DMZ, and they can "see" the internet, browse the web, etc. I have tested an http server runnin