[leaf-user] Dropbear and sshd in Bering_uClibc 2.1.3

2004-07-15 Thread [EMAIL PROTECTED]
HI AGAIN, I am new to LEAF and have just got my Leaf system running. However, I have been reading about dropbear, dropbearkeys, and SSH and it seems if these have to do with some sort of remote admin packages. Am I right? Is there some good beginer information you could point me to to read ab

Re: [leaf-user] RFC1918 packets to NET

2004-07-15 Thread grharry
> At 16:44 15.07.2004 +0300, [EMAIL PROTECTED] wrote: > > >I 've noticed that when installing the default shorewall configuration of= > Bering-* > >there is no block of rfc1918 packets going out to NET > >That is traceroute from LOC of any address not included in LOCAL LAN but in= > the RF

Re: [leaf-user] sshd on uclib 2.1.1 not working

2004-07-15 Thread Gabriel Mueller
Hi OK, the following link really solved the problem: http://www.mail-archive.com/[EMAIL PROTECTED]/msg16980.html But Iam asking if this solution is a good one because of disabling the rule ALL : ALL in /etc/hosts.deny ? Gabriel Erich Titl wrote: Gabriel At 17:06 15.07.2004 +0200, Gabriel Mueller

RE: [leaf-user] Using LEAF (Bering-uClibc) as a router (no shorewall)

2004-07-15 Thread S Mohan
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Ben Conrad > Sent: Friday, July 16, 2004 3:29 AM > To: [EMAIL PROTECTED] > Subject: [leaf-user] Using LEAF (Bering-uClibc) as a router > (no shorewall) > > Hello, > > I want to use LEAF as a simpl

[leaf-user] Re:

2004-07-15 Thread Tom Eastep
[EMAIL PROTECTED] wrote: Tom, Thanks, I have been teaching myself how to read the logs. What are the indications that I should look for? A message that says that your connection tracking table is full and that packets are being dropped. And what would cause the connection tracking table to be fu

Re: [leaf-user] Using LEAF (Bering-uClibc) as a router (no shorewall)

2004-07-15 Thread Larry Platzek
On Thu, 15 Jul 2004, Richard Doyle wrote: Date: Thu, 15 Jul 2004 15:32:41 -0700 From: Richard Doyle <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: Re: [leaf-user] Using LEAF (Bering-uClibc) as a router (no shorewall) On Thu, 2004-07-15 at 14:58, Ben Conrad wrote: Hello, I want to use LEAF as a

[leaf-user] (no subject)

2004-07-15 Thread mcartter
Tom, Thanks, I have been teaching myself how to read the logs. What are the indications that I should look for? And what would cause the connection tracking table to be full? An error in the way I set up the system? Matt Date sent: Mon, 12 Jul 2004 10:12:39 -0700 From:

Re: [leaf-user] Using LEAF (Bering-uClibc) as a router (no shorewall)

2004-07-15 Thread Erich Titl
Ben At 23:58 15.07.2004, Ben Conrad wrote: Hello, I want to use LEAF as a simple router inside my internal networks. I don't need any firewalling or NAT. What is the best way to turn off all the Shorewall and IPTables configurations so that I can pass all traffic in/out of eth0 and eth1? I tried

Re: [leaf-user] multiple port bridging/filtering

2004-07-15 Thread Erich Titl
Tom At 21:54 15.07.2004, Tom Eastep wrote: Charles Steinkuehler wrote: Erich Titl wrote: Hi Folks I have a requirement to bridge multiple ports on a single network and filtering packets between these ports based on mac and/or Ip addresses. Can I do that using ebtables? Does anyone have any experi

Re: [leaf-user] Using LEAF (Bering-uClibc) as a router (no shorewall)

2004-07-15 Thread Richard Doyle
On Thu, 2004-07-15 at 14:58, Ben Conrad wrote: > Hello, > > I want to use LEAF as a simple router inside my internal networks. I > don't need any firewalling or NAT. > > What is the best way to turn off all the Shorewall and IPTables > configurations so that I can pass all traffic in/out of eth0

[leaf-user] Using LEAF (Bering-uClibc) as a router (no shorewall)

2004-07-15 Thread Ben Conrad
Hello, I want to use LEAF as a simple router inside my internal networks. I don't need any firewalling or NAT. What is the best way to turn off all the Shorewall and IPTables configurations so that I can pass all traffic in/out of eth0 and eth1? I tried to rename /etc/rc2.d/S41shorewall and the

Re: [leaf-user] multiple port bridging/filtering

2004-07-15 Thread Tom Eastep
Charles Steinkuehler wrote: Erich Titl wrote: Hi Folks I have a requirement to bridge multiple ports on a single network and filtering packets between these ports based on mac and/or Ip addresses. Can I do that using ebtables? Does anyone have any experience with such a situation? I don't know

Re: [leaf-user] bering 1.2 does not dial out - strange behaviour

2004-07-15 Thread Richard Doyle
UmOn Thu, 2004-07-15 at 07:38, Thomas Wille wrote: > Hello Community, > > I have Bering 1.2 Installation which works as a router between analog modem > and local ethernet, e-mail-server etc. It has been running on several boxes > without problems. > > Now I built a box for this installation out o

Re[2]: [leaf-user] Hiding network behind Bering Box

2004-07-15 Thread Yazgot
Hello Tom, TE> firewall/router and has no native support for doing so. The OP needs to TE> insert the appropriate rules into the mangle table POSTROUTING chain to TE> set TTL as required. The iptables commands can be placed in the TE> /etc/shorewall/start file. i exactly planned to do this, but

Re: [leaf-user] multiple port bridging/filtering

2004-07-15 Thread Erich Titl
Charles interesting approach do you do any mac based filtering? At 10:22 15.07.2004 -0500, Charles Steinkuehler wrote: >Erich Titl wrote: > >>Hi Folks >>I have a requirement to bridge multiple ports on a single network and filtering >>packets between these ports based on mac and/or Ip addresses.

Re: [leaf-user] multiple port bridging/filtering

2004-07-15 Thread Charles Steinkuehler
Erich Titl wrote: Hi Folks I have a requirement to bridge multiple ports on a single network and filtering packets between these ports based on mac and/or Ip addresses. Can I do that using ebtables? Does anyone have any experience with such a situation? I don't know about bridging, but you can do w

Re: [leaf-user] RFC1918 packets to NET

2004-07-15 Thread Erich Titl
At 16:44 15.07.2004 +0300, [EMAIL PROTECTED] wrote: >I 've noticed that when installing the default shorewall configuration of Bering-* >there is no block of rfc1918 packets going out to NET >That is traceroute from LOC of any address not included in LOCAL LAN but in the >RFC1918 range will

Re: [leaf-user] Hiding network behind Bering Box

2004-07-15 Thread Erich Titl
Tom At 07:32 15.07.2004 -0700, Tom Eastep wrote: >Erich Titl wrote: >>Paul >>At 21:23 14.07.2004 +0200, Yazgot wrote: >> >>>Hello ! >>> >>>Recently i figured out i need to change TTL of all outgoing packets to >>>the same value eg 64. Behind bering box is NATed 3 computers network >>>and i need to

Re: [leaf-user] sshd on uclib 2.1.1 not working

2004-07-15 Thread Erich Titl
Gabriel At 17:06 15.07.2004 +0200, Gabriel Mueller wrote: >Hi > >bash-2.05b# telnet 22 >Trying ... >Connected to . >Escape character is '^]'. >(a few seconds nothing happens) >Connection closed by foreign host. You should at least see something like this, possibly you are right sshd seems to not

[leaf-user] multiple port bridging/filtering

2004-07-15 Thread Erich Titl
Hi Folks I have a requirement to bridge multiple ports on a single network and filtering packets between these ports based on mac and/or Ip addresses. Can I do that using ebtables? Does anyone have any experience with such a situation? Thanks Erich THINK Püntenstrasse 39 8143 Stallikon mail

[leaf-user] bering 1.2 does not dial out - strange behaviour

2004-07-15 Thread Thomas Wille
Hello Community, I have Bering 1.2 Installation which works as a router between analog modem and local ethernet, e-mail-server etc. It has been running on several boxes without problems. Now I built a box for this installation out of a Ali Motherboard S7AX, 192MB Ram, an AMD K6-200 CPU, and a 3c5

Re: [leaf-user] Hiding network behind Bering Box

2004-07-15 Thread Tom Eastep
Erich Titl wrote: Paul At 21:23 14.07.2004 +0200, Yazgot wrote: Hello ! Recently i figured out i need to change TTL of all outgoing packets to the same value eg 64. Behind bering box is NATed 3 computers network and i need to make all outgoing traffic look like it is originating from one machine.

[leaf-user] RFC1918 packets to NET

2004-07-15 Thread grharry
I 've noticed that when installing the default shorewall configuration of Bering-* there is no block of rfc1918 packets going out to NET That is traceroute from LOC of any address not included in LOCAL LAN but in the RFC1918 range will go out and traverse the net( Default route ). Who is re

Re: [leaf-user] sshd on uclib 2.1.1 not working

2004-07-15 Thread Gabriel Mueller
Hi bash-2.05b# telnet 22 Trying ... Connected to . Escape character is '^]'. (a few seconds nothing happens) Connection closed by foreign host. - is sshd showing up in the process table (ps -ef) Yes: root 964 S /usr/sbin/sshd - do you allow port 22 access to the firewall Yes: Working with shorewa

Re: [leaf-user] sshd on uclib 2.1.1 not working

2004-07-15 Thread Erich Titl
Gabriel At 13:01 15.07.2004 +0200, Gabriel Mueller wrote: >Hi again > >| Do you allow password authentication or only RSA? >| If you allow RSA only then you have to use a valid key. > >I checked my sshd_conf (or better said, I compared it with another sshd_conf on an >bering-machine (Bering,

Re: [leaf-user] sshd on uclib 2.1.1 not working

2004-07-15 Thread Gabriel Mueller
Hi again | Do you allow password authentication or only RSA? | If you allow RSA only then you have to use a valid key. I checked my sshd_conf (or better said, I compared it with another sshd_conf on an bering-machine (Bering, not Bering-uclib)) and there is no difference between both. And on the

Re: [leaf-user] sshd on uclib 2.1.1 not working

2004-07-15 Thread Erich Titl
Gabriel At 01:59 15.07.2004 +0200, Gabriel Mueller wrote: >Hi all > >Iam having some trouble to get sshd to work on a uclib-bering 2.1.1 . >These are the packages Iam using: >(Iam giving the full link, so you can check if Iam using the right versions of >packages) >http://leaf.sourceforge.net/pac

[leaf-user] [Fwd: [gentoo-announce] [ GLSA 200407-12 ] Linux Kernel: Remote DoS vulnerability with IPTables TCP Handling]

2004-07-15 Thread Juan J. Prieto
Hi all, kernel security advisory: kernel 2.6 Remote DoS vulnerability. I think kernel 2.4 is not affected. - Mensaje reenviado De: Tim Yamin <[EMAIL PROTECTED]> Para: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED] Asunto: [gentoo-announce] [ GLSA 200