[leaf-user] LEAF installment problem

2008-03-13 Thread Tom Hendrickx
Hi everyone, For a few days now I've been experimenting with LEAF. But I'm so stuck at the moment, that I've subscribed myself to this list in the hope someone could help me. What I try to do here, is install LEAF Bering 3.1 on a compact flash card, to use it on a NexGate security appliance. T

Re: [leaf-user] LEAF installment problem

2008-03-13 Thread Tom Hendrickx
Hi Martin, first of all, thx for the quick reply! Citeren Martin Hejl <[EMAIL PROTECTED]>: > Hi Tom, > >> - formatted the flash card (one fat partition (10mb) and one ext2 partition) >> - installed syslinux on the first partition >> - put the master boot record in order >> - copied the files of

Re: [leaf-user] LEAF installment problem

2008-03-13 Thread Tom Hendrickx
Hi! This indeed did the trick, thx! So the installing goes without any problem .. A lot of other things happen then, key's being made and so on .. Here's the last page's output: Creating action chain dropNotSyn Applying Policies... Setting up Masquarading/SNAT... ERROR: Unable to determine

Re: [leaf-user] LEAF installment problem

2008-03-13 Thread Tom Hendrickx
Hi Martin, You've allready proven to be a great help today! Citeren Martin Hejl <[EMAIL PROTECTED]>: > Hi Tom, > >> hda: hda1 hda2 >> initrd(nf) root(nf) config(nf) etc(nf) modules(nf) >> iptables(nf) dhcpcd(nf) keyboard shorwall(nf) ulogd(nf) >> dnsmasq dropbear mhttpd(nf) openntpd webcon

Re: [leaf-user] LEAF installment problem

2008-03-13 Thread Tom Hendrickx
My comprehension is now a little bit further .. The lib/modules and so on, I'll find in the lrp package .. How can I open and modify these? Tom Citeren Martin Hejl <[EMAIL PROTECTED]>: > Hi Tom, > >> hda: hda1 hda2 >> initrd(nf) root(nf) config(nf) etc(nf) modules(nf) >> iptables(nf) dhcpc

[leaf-user] multiple partitions => YAFFS

2008-03-25 Thread Tom Hendrickx
Hi everyone, a few weeks ago I got the leaf system working , but I had put everything on the first "msdos" partition .. To make it a bit more endurable, I would like to put as much as possible on the second partition, where I thought to use YAFFS. Has someone allready some experience with this

Re: [leaf-user] multiple partitions => YAFFS

2008-03-25 Thread Tom Hendrickx
Practical to know probably is .. once mounting the file system, I get this error : FAT: bogus logical sector size 0 This only happens when I refer the pkgpath to something else as hda1:msdos (like hda2) After this, it's just each module (nf!) Tom Citeren Tom Hendrickx <[EMAIL P

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
YAFFS nor for JFFS2 .. Is this one day gonna change? To make the flash drives more durable.. Or is it possible to give some extra parameters to the system with ext2, to make it more durable in this way? Greetz, Tom Citeren Erich Titl <[EMAIL PROTECTED]>: > Hi Tom > > Tom Hendri

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
part of it.. also afterwarts when I should save it , pressing m only saves the moddb.lrp .. So how save it afterwarts? Thx, Tom Citeren Tom Hendrickx <[EMAIL PROTECTED]>: > Hi Erich > > Thanks a lot and also to Eric! > The problem was indeed with the ext2 module not being loa

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
.. >> >> also afterwarts when I should save it , pressing m only saves the >> moddb.lrp .. So how save it afterwarts? >> >> Thx, Tom >> >> >> >> Citeren Tom Hendrickx <[EMAIL PROTECTED]>: >> >> >>> Hi Erich >>> &g

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
ng wrong somewhere .. I'm not a real expert at these things, so it's possible I'm looking over something very small grtz, Tom Citeren KP Kirchdoerfer <[EMAIL PROTECTED]>: > On Wednesday 26 March 2008 10:56:47 Tom Hendrickx wrote: >> Hi Eric >> >> My plan

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
gt; at these things, so it's possible I'm looking over something very small >> >> grtz, Tom >> >> >> >> Citeren KP Kirchdoerfer <[EMAIL PROTECTED]>: >> >> >>> On Wednesday 26 March 2008 10:56:47 Tom Hendrickx wrote: >>&g

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
if=initrd.lrp" >>>> instead of "dd if=/dev/zero" I guess .. So I changed this, and my >>>> file is now a lot bigger .. but still 70kb's smaller then the original >>>> file and still blocking on the same >>>> >>>> So I m

Re: [leaf-user] multiple partitions => YAFFS

2008-03-26 Thread Tom Hendrickx
Forget the last mail please .. while copying the ext2.o I'd messed /etc/modules up thx for helping me everyone! Citeren Tom Hendrickx <[EMAIL PROTECTED]>: > Thx eric! > > That was exactly what I needed! > to edit the /mnt/boot/etc/modules however .. I tried vi and nan

[leaf-user] "no space left"

2008-03-28 Thread Tom Hendrickx
Hi my leaf on ext2 partition was working perfectly .. Then I added some extra packages which I needed , namely openvpn and a few others Everything was still working .. till I read on a document of openvpn it also needed some library modules .. So I added libcrpto.lrp,libssl.lrp,liblzo.lrp,ncurs

[leaf-user] Setting up a bridge with leaf

2008-03-31 Thread Tom Hendrickx
Hi, I have a little annoying problem .. I try setting up a bridge on the LEAF system following the documentation. (doc\bk04ch21s02.html) But it states here that I need the bridge.lrp file .. Problem is that file is nowhere to be found .. Has it changed how to configure the bridge or is the file

Re: [leaf-user] Setting up a bridge with leaf

2008-03-31 Thread Tom Hendrickx
Ok thanks .. I have no idea how I could have looked over it in the ISO image, but I did :$ Making it work is another problem I fear I've added the bridge.lrp .. put it also in leaf.cfg bridge.o is also added and for my interface : e100.o and in interfaces is only this selected : auto br0 iface

Re: [leaf-user] Setting up a bridge with leaf

2008-03-31 Thread Tom Hendrickx
Hi Eric Citeren Eric Spakman <[EMAIL PROTECTED]>: > Hello Tom, > >> Ok thanks .. I have no idea how I could have looked over it in the ISO >> image, but I did :$ >> >> Making it work is another problem I fear >> >> >> I've added the bridge.lrp .. put it also in leaf.cfg >> bridge.o is also added

Re: [leaf-user] Setting up a bridge with leaf

2008-03-31 Thread Tom Hendrickx
Hallo Eric, Citeren Eric Spakman <[EMAIL PROTECTED]>: > Hello Tom, >>> >>> Ok thanks .. I have no idea how I could have looked over it in the ISO image, but I did :$ Making it work is another problem I fear I've added the bridge.lrp .. put it also in l

Re: [leaf-user] Setting up a bridge with leaf

2008-04-01 Thread Tom Hendrickx
extra info down.. Citeren Tom Hendrickx <[EMAIL PROTECTED]>: > Hallo Eric, > > Citeren Eric Spakman <[EMAIL PROTECTED]>: > >> Hello Tom, >>>> >>>> >>>>> Ok thanks .. I have no idea how I could have looked over it in the >

Re: [leaf-user] Setting up a bridge with leaf

2008-04-01 Thread Tom Hendrickx
Hi Tom, > > Can you ping the bridge interface from the firewall itself? > > I guess shorewall is blocking the ping, because it's probably not setup > for bridging. > > > Eric > > >> extra info down.. >> >> Citeren Tom Hendrickx <[EMAIL

Re: [leaf-user] Setting up a bridge with leaf

2008-04-01 Thread Tom Hendrickx
t;>> >>> Can you ping the bridge interface from the firewall itself? >>> >>> >>> I guess shorewall is blocking the ping, because it's probably not setup >>> for bridging. >>> >>> >>> Eric >>> >>> >>>

[leaf-user] bridged openVPN connection

2008-04-17 Thread Tom Hendrickx
Hi! I have a problem setting up the connection between my bridge br0 and the tap interface.. My internal network can reach the bridge, so this setup is ok.. And my vpn connection is also established and completely set up for ethernet bridging. In my /etc/network/interfaces the bridge has been

Re: [leaf-user] bridged openVPN connection

2008-04-17 Thread Tom Hendrickx
documentation which served me so good the last weeks! Regards, Tom Citeren Tom Hendrickx <[EMAIL PROTECTED]>: > Hi! > > I have a problem setting up the connection between my bridge br0 and > the tap interface.. My internal network can reach the bridge, so this > setup

Re: [leaf-user] how to add shorewall rule for this?

2008-04-17 Thread Tom Hendrickx
Hi, this is what I would do! keep your policy very simple: /etc/shorewall/policy loc netACCEPT all allREJECT and specify what can come through in the rules files: here you add this: #ACTION SOURCE DEST PROTO DESTSOURCE #

Re: [leaf-user] bridged openVPN connection

2008-04-17 Thread Tom Hendrickx
nd found >> this beautiful explanation: >> http://openvpn.net/archive/openvpn-users/2004-12/msg00349.html >> >> >> made the little script running .. And everything works perfectly >> >> sorry for the unnecessairy question .. But thanks for all the good >> docu

[leaf-user] SSH connection

2008-04-18 Thread Tom Hendrickx
Hi everyone, I was wondering something about the hosts.allow file. I have for example the following line inserted: ALL: 192.168.1.2/255.255.255.255 but I'm still able to ssh to the machine from other addresses inside the 192.168.1.0/24 network.. Shouldn't this file take care of this or should it

[leaf-user] openswan

2008-04-21 Thread Tom Hendrickx
Hi, I try to install openswan on my leafsystem, but I do not find the following packages: openswan.lrp and libpthread.lrp. They're not included in the iso file. libpthread is maybe renamed to lpthread? But I'm not certain, and for openswan.lrp I see no possibilities.. Grtz, Tom --

Re: [leaf-user] openswan

2008-04-23 Thread Tom Hendrickx
Hi, I want to make my leafsystem a vpn server through openswan. This for roadwarriors alone to be able to connect to the network behind it. Is this configuration out of chapter 9 also working for this, or what changes should be made? I'm getting really in trouble trying to configure this.. # ba

Re: [leaf-user] openswan

2008-04-23 Thread Tom Hendrickx
192.168.2.3 scope global ipsec0 When I now use at the roadwarrior: ipsec auto --up road nothing happens and it's just doing nothing till I hit ^c I hope this helps in understanding the problem.. Regards, Tom Citeren Erich Titl <[EMAIL PROTECTED]>: > Tom > > Tom He

Re: [leaf-user] openswan

2008-04-24 Thread Tom Hendrickx
iving a clear view of the situation.. Grtz, Tom Citeren Charles Steinkuehler <[EMAIL PROTECTED]>: > -BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Tom Hendrickx wrote: > | Here's my very easy test-setup: > | > | 192.168.

Re: [leaf-user] openswan

2008-04-24 Thread Tom Hendrickx
Hey Citeren Erich Titl <[EMAIL PROTECTED]>: > Tom > > Tom Hendrickx wrote: >> Hi! thanks Charles for your reply, but I fear it didn't helped.. >> >> the subnet for the roadwarrior I got from here : >> http://wiki.openswan.org/index.php/Openswan/Ext

Re: [leaf-user] openswan

2008-04-24 Thread Tom Hendrickx
which is being used, making it useless for its former connection with the leaf system.. So no more pinging or ssh connection is possible.. Tom Citeren Erich Titl <[EMAIL PROTECTED]>: > Tom > > Tom Hendrickx wrote: >> Hey >> >> Citeren Erich Titl <[EMAIL