[Leaf-user] VPN ?

2001-06-25 Thread Ricardo Kleemann
Hi, I've setup an Eigerstein2BETA system, just starting to play around with it. Is it possible to have it run a vpn server so that I can have outside ssh clients connect to servers in the internal network? Do I have to start using a hard disk instead of floppy? _

[Leaf-user] anyone using SBC ?

2001-06-25 Thread Ricardo Kleemann
Hi, is anyone using SBC (single board computer) setups for LRP ? Where can I find small sbc's with enclosures that would allow me to build a compact appliance that runs LRP ? Thanks Ricardo ___ Leaf-user mailing list [EMAIL PROTECTED] http://lists

Re: [Leaf-user] anyone using SBC ?

2001-06-25 Thread Ricardo Kleemann
Thanks! Can LRP support compact flash cards (instead of having a floppy drive)? On Mon, 25 Jun 2001 16:46:49 -0700 Mike Noyes wrote: > Ricardo Kleemann, 2001-06-25 15:21 -0800 > >is anyone using SBC (single board computer) setups for LRP ? > > > >Where can I find small

Re: [Leaf-user] anyone using SBC ?

2001-06-25 Thread Ricardo Kleemann
On Mon, 25 Jun 2001 17:17:12 -0700 Mike Noyes wrote: > Ricardo Kleemann, 2001-06-25 16:04 -0800 > >Can LRP support compact flash cards (instead of having a floppy drive)? > > Ricardo, > Yes. The setup is similar to using an ide hard drive. > > Thanks Mike. But wha

[Leaf-user] masquerading for DNS?

2001-06-26 Thread Ricardo Kleemann
Hi guys, I was wondering if it is possible to have primary and secondary name servers within the internal network, and have them be accessed by the firewall? So instead of having the pri. and sec. being directly on the public network, they're behind the firewall and queries flow to them via the

Re: [Leaf-user] games, IPsec VPN from *behind* LRP firewall

2001-07-02 Thread Ricardo Kleemann
Hello Scott, are these the same directions for setting up a VPN server on the LRP box? Can the LRP act as a VPN server as well? On Mon, 2 Jul 2001, Scott C. Best wrote: > Alan: > Heya. So...from looking over Intelispan's website, > it looks as if their "Secure VPN Service" is an IPsec on

Re: [Leaf-user] games, IPsec VPN from *behind* LRP firewall

2001-07-02 Thread Ricardo Kleemann
PSec) has been packaged for LRP, and > I believe that PopTop (PPTP) has as well. The intructions for doing this > are far better than my own; point yourself here: > > http://lrp.steinkuehler.net/Packages/ipsec1.5.htm > > Good luck! > > -Scott > > At 1:01

[Leaf-user] Serial port Console?

2001-07-02 Thread Ricardo Kleemann
Hi, I was wondering if the kenel needs special configuration in order to boot up with a console on a serial port? I'm planning on building a router with soekris.com's net4501 little SBC computer, but it doesn't have a VGA port, only a serial port. So the only way I can control it is via serial p

[Leaf-user] Re: [LRP] How to make CF disk bootable

2001-07-09 Thread Ricardo Kleemann
> > Good luck, > Chris > > On Mon, 9 Jul 2001, Ricardo Kleemann wrote: > > Date: Mon, 9 Jul 2001 12:04:49 -0700 (PDT) > > To: [EMAIL PROTECTED] > > From: Ricardo Kleemann <[EMAIL PROTECTED]> > > Subject: [LRP] How to make CF disk bootable > > > >

[Leaf-user] Re: [LRP] How to make CF disk bootable

2001-07-09 Thread Ricardo Kleemann
eated (and set bootable), just copy > the contents of your floppy to the CF card (should be c: under DOS). > Next "syslinux c:". (In my experience, setting up syslinux works best > from DOS.) > > Good luck, > Chris > > On Mon, 9 Jul 2001, Ricardo Kleemann wrote

RE: [Leaf-user] How to make CF disk bootable

2001-07-09 Thread Ricardo Kleemann
IL PROTECTED] > > [mailto:[EMAIL PROTECTED]]On Behalf Of Chris > > Carbaugh > > Sent: 09 July 2001 21:10 > > To: Ricardo Kleemann; [EMAIL PROTECTED] > > Cc: [EMAIL PROTECTED] > > Subject: [Leaf-user] Re: [LRP] How to make CF disk bootable > > > > > &g

[Leaf-user] How to make CF disk bootable

2001-07-09 Thread Ricardo Kleemann
Hi everyone, I'm using the PC Engines CF - IDE adapter. The CF disk is properly recognized as a small IDE disk. I'm trying to figure out how to make it bootable. I thought maybe just doing a dd from a working LRP floppy would work, but I was mistaken. So I have a working LRP floppy with my conf

RE: [Leaf-user] Re: [LRP] How to make CF disk bootable

2001-07-10 Thread Ricardo Kleemann
e > convenient to use DOS (it doesn't have to be MS-DOS). > > Regards > > John Ridout > C T A Systems Ltd > http://www.ctasystems.co.uk/ > > > -Original Message- > > From: [EMAIL PROTECTED] > > [mailto:[EMAIL PROTECTED]]On Behalf Of Ric

[Leaf-user] eigerstein2Beta with 2.2.19?

2001-07-10 Thread Ricardo Kleemann
Hi everyone, Are there pre-built 2.2.19 kernels (or maybe even 2.4) for eigerstein? Should I even bother trying to upgrade from 2.2.16? I heard stateful inspection mentioned relative to 2.4 kernels... but how does that work actually? Does E2B support it? Thanks Ricardo __

Re: [Leaf-user] eigerstein2Beta with 2.2.19?

2001-07-10 Thread Ricardo Kleemann
Thanks for the info On Tue, 10 Jul 2001, David Douthitt wrote: > > 2.2.19 is more stable, as 2.4 is still being worked out. My last > attempt at compiling 2.4.6 kept ending in failures, which I almost never > ever saw with 2.2. You might wish to hold back or not; it's up to you. But then is

Re: [Leaf-user] eigerstein2Beta with 2.2.19?

2001-07-10 Thread Ricardo Kleemann
ein router. > > HTH, > Chris > - Original Message - > From: "David Douthitt" <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Sent: Tuesday, July 10, 2001 3:01 PM > Subject: Re: [Leaf-user] eigerstein2Beta with 2.2.19? > > > > Ricardo Kleema

[Leaf-user] newer binaries?

2001-07-11 Thread Ricardo Kleemann
Hi, Along with building a regular LRP firewall, I'm also considering the minimal LRP distributions to build small servers for dedicated purposes. For example, I'm interested in building an LVS cluster, and it would be a good idea to have an LVS server which does only that, not having all the blo

Re: [Leaf-user] newer binaries?

2001-07-11 Thread Ricardo Kleemann
Thanks David! On Wed, 11 Jul 2001, David Douthitt wrote: > > Well, Oxygen doesn't need two disks; it's just designed so that the > first disk holds basic system commands and utilities, and the > applications are on a second disk. It's also designed to load packages > over the network, also all

[leaf-user] Please help adding virtual interfaces

2006-02-21 Thread Ricardo Kleemann
Hi, I want to add virtual interfaces, like eth0:0, eth0:1, etc... that have a different network and mask as my current addresses. Can those be added in the /etc/network/interfaces file? How do I configure ip aliases in the interfaces file? Or should I add them through shorewall? I tried ad

Re: [leaf-user] Re: Bering uClibc on a serial console

2006-02-28 Thread Ricardo Kleemann
getty enabled? Is it the etc.lrp that needs to be modified? Ricardo - Original Message - From: "Eric Spakman" <[EMAIL PROTECTED]> To: "Charles Steinkuehler" <[EMAIL PROTECTED]> Cc: "Ricardo Kleemann" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]

Re: [leaf-user] Re: Bering uClibc on a serial console

2006-02-28 Thread Ricardo Kleemann
Great, thanks! It's great to know that lrp is simply a tgz. I never knew that! That certainly helps. Ricardo - Original Message - From: "Eric Spakman" <[EMAIL PROTECTED]> To: "Ricardo Kleemann" <[EMAIL PROTECTED]> Cc: "Charles Steinku

Re: [leaf-user] Re: Bering uClibc on a serial console

2006-02-28 Thread Ricardo Kleemann
Thanks Martin. BTW does anyone know where to find a vim lrp for Bering uClibc? I only found one for the older Bering distro. Ricardo - Original Message - From: "Martin Hejl" <[EMAIL PROTECTED]> To: "Ricardo Kleemann" <[EMAIL PROTECTED]> Cc: Sent: Tue

[leaf-user] tinydns as a secondary name server?

2006-03-02 Thread Ricardo Kleemann
Hi, Can tinydns be easily configured as a secondary nameserver, slaving off a BIND primary? If not, is there a small dns server lrp that can function as a secondary that slaves off BIND? Thanks Ricardo --- This SF.Net email is sponsored by x

[leaf-user] Repost... axfr-get for Bering uClibc?

2006-03-03 Thread Ricardo Kleemann
Hi, I posted yesterday a question relative to tinydns. I guess what I really need is tinydns + axfr-get in order to get a secondary nameserver running. I've searched around but have not found an LRP that contains both. Does anyone know where I can get an lrp with both, or at least an lrp with a

Re: [leaf-user] Repost... axfr-get for Bering uClibc?

2006-03-03 Thread Ricardo Kleemann
Certainly, thank you! - Original Message - From: "Eric Spakman" <[EMAIL PROTECTED]> To: "Ricardo Kleemann" <[EMAIL PROTECTED]> Cc: Sent: Friday, March 03, 2006 11:04 AM Subject: Re: [leaf-user] Repost... axfr-get for Bering uClibc? > Hello Ricar

Re: [leaf-user] Repost... axfr-get for Bering uClibc?

2006-03-03 Thread Ricardo Kleemann
Thanks again, Eric. Who's the package maintainer for the tinydns lrp? Maybe we could request that axfer-get gets added to the lrp? Ricardo - Original Message - From: "Eric Spakman" <[EMAIL PROTECTED]> To: "Ricardo Kleemann" <[EMAIL PROTECTED]>

Re: [leaf-user] Re: Repost... axfr-get for Bering uClibc?

2006-03-06 Thread Ricardo Kleemann
Hi Eric, Do you happen to have tcpclient compiled as well? It turns out axfr-get will not run by itself, it needs tcpclient. Ricardo - Original Message - From: "Eric Spakman" <[EMAIL PROTECTED]> To: "Kwon" <[EMAIL PROTECTED]> Cc: Sent: Friday, March 03, 2006 1:25 PM Subject: Re: [leaf-u

[leaf-user] still trying to find secondary nameserver alternative

2006-03-09 Thread Ricardo Kleemann
Hi guys, Anyone have a version of bind (named) for bering-uClibc? I want to run a secondary nameserver on my leaf box. The only options I know of are axfr-get and named. Except axfr-get also needs tcpclient. I have not found any of these (other than axfr-get that Eric provided to me). But eit

Re: [leaf-user] still trying to find secondary nameserver alternative

2006-03-10 Thread Ricardo Kleemann
Thanks for the suggestion. The primary dns server is on another network, another location. And the leaf system is on a separate location where there aren't any full blown linux boxes Ricardo - Original Message - From: "Erich Titl" <[EMAIL PROTECTED]> To: "

[leaf-user] changing /etc/TZ

2006-03-11 Thread Ricardo Kleemann
Hi, I'm running ntpdate, and wonder if it's possible to have TZ to auto-update for daylight savings? TZ is set to UTC by default, what should I change it to for Pacific time (PDT or PST) and will it automatically change to daylight savings? Ricardo -

[leaf-user] help: shorewall accounting settings

2006-03-17 Thread Ricardo Kleemann
Hi, I was looking into the shorewall accounting rules, and wondering how to setup the accounting chain for specific servers. For example, something like this accounts for all of the smtp traffic routed by the firewall: #ACTION CHAIN SOURCE DESTINATION PROTOCOLDEST SOURCE #

[leaf-user] dropbear authorized_keys?

2006-03-17 Thread Ricardo Kleemann
Hi, Does the dropbear lrp not honor keys in authorized_keys? I placed a public key in /etc/dropbear/authorized_keys but it's not working, it still requests password. Where can I configure this? Thanks Ricardo --- This SF.Net email is

Re: [leaf-user] [ANN] Bering-uClibc 2.4

2006-03-18 Thread Ricardo Kleemann
Great! Is there a simple way to upgrade? I'm currently running the previous version (I'm guessing 2.3?) but didn't want to have to setup everything again. What is the easiest way to upgrade? Ricardo - Original Message - From: "KP Kirchdoerfer" <[EMAIL PROTECTED]> To: Sent: Saturda

[leaf-user] telnet for bering uclibc?

2006-03-25 Thread Ricardo Kleemann
Hi, I'm trying to find a telnet lrp package for bering uclibc, but haven't found one. Can someone point me to an lrp package, or at least a binary? Thanks Ricardo --- This SF.Net email is sponsored by xPML, a groundbreaking scripting l

Re: [leaf-user] telnet for bering uclibc?

2006-03-26 Thread Ricardo Kleemann
kp Am Samstag, 25. März 2006 17:50 schrieb Ricardo Kleemann: Hi, I'm trying to find a telnet lrp package for bering uclibc, but haven't found one. Can someone point me to an lrp package, or at least a binary? Thanks Ricardo --- Thi

[leaf-user] help with shorewall problems

2006-04-13 Thread Ricardo Kleemann
Hi, I'm running shorewall 2.4.7 and I'm having trouble getting it to work properly. I've been working with an older version of shorewall on another leaf box for a couple of years now, without any problems. I have this in /etc/shorewall/nat aa.bb.cc.ddeth0192.168.111.247 n

[leaf-user] ip_conntrack: table full, dropping packet

2007-11-05 Thread Ricardo Kleemann
Hi I recently started having this problem on my leaf box. I'm guessing this is being caused by floods hitting the box. How can I better diagnose this? I know I can increase the /proc/sys/net/ipv4/ip_conntrack_max but that's not fixing the problem. Am I able to figure out which interface is get

Re: [leaf-user] ip_conntrack: table full, dropping packet

2007-11-05 Thread Ricardo Kleemann
Thanks Erich. > These two links may help: > > http://osdir.com/ml/linux.leaf.user/2005-04/msg00089.html > > http://www.wallfire.org/misc/netfilter_conntrack_perf.txt > Those links show how to change the conntrack_max. But my problem is really trying to prevent the table from filling up. I'm sure