Re: [leaf-user] DNAT vs. Proxy Arp DMZ ???

2005-04-29 Thread Tom Eastep
Michael D Schleif wrote: > This is the problem: > > [1] As desired, tcp 3389 is forwarded (DNAT) from the > Bering-uClibc/shorewall box to a server on the local LAN, when using > the the firewall's external interface. > > [2] When using a DMZ address, tcp 3389 is also forwarded to that se

[leaf-user] Building and Using QEMU

2005-04-29 Thread Calvin Webster
Eric & Arne: I finally got both QEMU and VDE built and fired up a generic LEAF Router in QEMU. It seems very fast! I could not find how to add Ethernet ports in the man page and html docs. The only place I could find it was using "qemu -h". Apparently, the man page and HTML haven't been updated in

[leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Calvin Webster
To the list: I need to get local copies of all the documentation for Bering-uClibc and all its packages, especially for "OpenSwan" which is what's contained in the Bering-uClibc IPSEC package (ipsec.lrp). First, I cannot find a complete documentation package in any form for Bering-uClibc. There i

Re: [leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Tom Eastep
Calvin Webster wrote: > > Second, the IPSEC documentation on the Shorewall site all refers to > FreeSwan which does not match the contents of ipsec.lrp. The proliferation of Swan species has been an absurd spectacle to observe to be sure but from the point of view of Shorewall, there are only t

Re: [leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Calvin Webster
On Fri, 2005-04-29 at 13:16, Tom Eastep wrote: > Calvin Webster wrote: > > > > > Second, the IPSEC documentation on the Shorewall site all refers to > > FreeSwan which does not match the contents of ipsec.lrp. > ... > Given that Bering* only runs on the 2.4 kernel and to my knowledge does > not

Re: [leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Tom Eastep
Calvin Webster wrote: > > Thanks Tom. I've been referencing that page already. It's great for the > configuration items. What about initial IPSEC setup, though (i.e. > generating keys, etc.). That's supposed to be in the *Swan docs that are > missing. What is everyone else using? Am I the only on

Re: [leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Tom Eastep
Calvin Webster wrote: >>-Tom/ > > Can I ask what you are using for IPSEC, then? It might be better for me > than flying blind. > I'm using the 2.6 kernel under Debian/Sarge with ipsec-tools/racoon -- not an option with Bering. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently tal

RE: [leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Peter Mueller
> > Given that Bering* only runs on the 2.4 kernel and to my knowledge > > does not include the backport of the Kernel 2.6 Native > IPSEC code, you > > want the Kernel 2.4 docs (http://shorewall.net/IPSEC.htm) > regardless > > of what color your Swans are. > > > > -Tom > > Thanks Tom. I've

Re: [leaf-user] Building and Using QEMU

2005-04-29 Thread Arne Bernin
On Fri, 2005-04-29 at 12:24 -0400, Calvin Webster wrote: > Eric & Arne: > Hi Calvin! > I haven't begun using VDE yet. Once I get the VMs running I'll tackle > that. > i use the following script to start 2 vde-switches (actually hubs) and load the kqemu module...Of course you can use more switc

RE: [leaf-user] Bering-uClibc Docs and IPSEC: FreeSwan or OpenSwan?

2005-04-29 Thread Calvin Webster
On Fri, 2005-04-29 at 14:06, Peter Mueller wrote: > > > Given that Bering* only runs on the 2.4 kernel and to my knowledge > > > does not include the backport of the Kernel 2.6 Native > > IPSEC code, you > > > want the Kernel 2.4 docs (http://shorewall.net/IPSEC.htm) > > regardless > > > of wh

Re: [leaf-user] Building and Using QEMU

2005-04-29 Thread Calvin Webster
On Fri, 2005-04-29 at 14:09, Arne Bernin wrote: > On Fri, 2005-04-29 at 12:24 -0400, Calvin Webster wrote: > > Eric & Arne: > > > Hi Calvin! > > > > I haven't begun using VDE yet. Once I get the VMs running I'll tackle > > that. > > > i use the following script to start 2 vde-switches (actuall

Re: [leaf-user] Building and Using QEMU

2005-04-29 Thread Eric Spakman
Calvin, >Am I going to have to download a windows exe to the Win95 rescue >diskette and boot it into QEMU with the hard disk image? I assume that's >what you did. This is going to bug me, you know. I won't be able to let >it go until I figure out why it's not working. > The hdimage from Arne is al

Re: [leaf-user] Building and Using QEMU

2005-04-29 Thread Calvin Webster
On Fri, 2005-04-29 at 16:08, Eric Spakman wrote: > Calvin, > > >Am I going to have to download a windows exe to the Win95 rescue > >diskette and boot it into QEMU with the hard disk image? I assume that's > >what you did. This is going to bug me, you know. I won't be able to let > >it go until I f