Re: [leaf-user] Dachstein - can't reach mail server on DMZ

2002-10-04 Thread Ray Olszewski
At 11:51 PM 10/4/02 -0400, Bob Skaroff comcast.net wrote: >I'm running Dachstein linux 4.0.6 with private.network at 192.168.1 and >dmz.network at 192.168.2. >The web server on dmz.network can be reached from the net. "the" net? Do you mean the Internet? If so, this is inconsistent with my tests

[leaf-user] Dachstein - can't reach mail server on DMZ

2002-10-04 Thread Bob Skaroff comcast.net
I'm running Dachstein linux 4.0.6 with private.network at 192.168.1 and dmz.network at 192.168.2. The web server on dmz.network can be reached from the net. Mail sent to the mail server on dmz.network returns an error message to the sender. I've tried varying the coding of the DMZ_OPEN_DEST and DM

RE: [leaf-user] internet restriction

2002-10-04 Thread S Mohan
You will need to use squid. All port 80 requests can be redirected to 3128 the default port for squid using iptables. In squid, you can ban sites by regular expression matching. This, however, does not eliminate IP based access. Squidguard or dansguardian do this. I've seen squidguard in lrp but d

[leaf-user] internet restriction

2002-10-04 Thread Liu Mei
Hi, If I want to prevent people from playing online game, watching online video, listening online music and downloading any file bigger than 5M, what I should use? Can any LEAF tool support this? Kind Regards, Liumei __ Do you Yahoo!? Faith Hil

Re: [leaf-user] Can't ping

2002-10-04 Thread Liu Mei
> Option 3: proceed as you have been, using a > different private-address range > (192.168.2.0/24) on your LAN, and have the router > NAT (MASQ) the LAN. > Matthew's suggestion on the forward-chain rule is > correct for this, except > that it has to be the first relevant rule the > packets enc

Re: [leaf-user] Bering VPN questions-School project

2002-10-04 Thread Eric Wolzak
Hello Craig , list, > Hi Eric, > Yes, that's absolutely correct. They are two different physical > locations. We have an IT department that does not allow us to "touch" > the incoming line at the router to the school. They will just allow us > to use the extra public IP addresses that we would a

[leaf-user] Bering VPN questions-School project

2002-10-04 Thread Craig
Hi Eric, Yes, that's absolutely correct. They are two different physical locations. We have an IT department that does not allow us to "touch" the incoming line at the router to the school. They will just allow us to use the extra public IP addresses that we would actually connect to inside my off