Re: [leaf-user] Ftpd-ssl behind Bering?

2003-10-13 Thread Jeff Newmiller
On Fri, 10 Oct 2003, Sean wrote: > I have an FTP/SSL server behind a Bering firewall. Problem is this: > > Oct 9 20:02:57 firewall Shorewall:net2all:DROP: IN=eth0 OUT= > MAC=00:03:47:08:40:1a:00:30:7b:fa:18:a8:08:00 SRC=204.60.67.237 > DST=12.243.231.253 LEN=44 TOS=00 PREC=0x00 TTL=112 ID=57030

RE: [leaf-user] Ftpd-ssl behind Bering?

2003-10-13 Thread Sean
Jeff, I was surprised to see that both CuteFTP and WS_FTP Pro clients both support SFTP. You have to look around a bit to find it, but its there. Bummer to have to open a range. Luckily I only open FTP to a few Ips anyway. FTP/SSL is getting more and more popular (especially since HIPPA). I h

[leaf-user] Types of DMZ - Dachstein

2003-10-13 Thread Doug Sampson
I'm using Dachstein CD 1.02 which works well in its present state. I would like to add a DMZ using a second ethernet card. I see in the network.conf file there are various types of DMZ- YES, PROXY, NAT, PRIVATE, and NO. I do not know what a PROXY DMZ does nor do I know the purpose of a private DMZ.

Re: [leaf-user] Types of DMZ - Dachstein

2003-10-13 Thread Charles Steinkuehler
Doug Sampson wrote: I'm using Dachstein CD 1.02 which works well in its present state. I would like to add a DMZ using a second ethernet card. I see in the network.conf file there are various types of DMZ- YES, PROXY, NAT, PRIVATE, and NO. I do not know what a PROXY DMZ does nor do I know the purpo

RE: [leaf-user] Types of DMZ - Dachstein

2003-10-13 Thread Doug Sampson
> DMZ=PROXY > This setting uses proxy-arp to separate your DMZ systems from the "raw" > upstream connection. The main benefit to using proxy-arp is your DMZ > systems can have REAL PUBLIC IP's. The main drawback is it's kind of > complex to get the networking and firewall rules setup correctly