RE: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Paul M. Wright, Jr.
PROTECTED]] On Behalf Of Cass Tolken Sent: Sunday, July 21, 2002 11:28 AM To: Leaf User Subject: [leaf-user] Bering/Shorewall question Hi there, I'm a networking newbie so excuse me if this question or my terminolgy seems strange ;). I'm logging a whole LOT of these hits: [sn

Re: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Cass Tolken
--- Kim Oppalfens <[EMAIL PROTECTED]> wrote: > At 20:28 21/07/2002, Cass Tolken wrote: > > Taking out the norfc on should stop logging these. > It is in there by default because you are not supposed to have an > address > in the 10.x.y.z range > on an external interface. The norfc means to blo

Re: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Kim Oppalfens
At 21:13 21/07/2002, Cass Tolken wrote: Your external address 24.46.y.z doesn't appear to be in the rfc1918 range. So there is no reason to take the norfc1918 out. Is your intern dhcp server serving up addresses in this 10 range by any chance? I don't think so sonce your internal ip is in the 192

Re: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Cass Tolken
--- Kim Oppalfens <[EMAIL PROTECTED]> wrote: > At 21:13 21/07/2002, Cass Tolken wrote: > > Your external address 24.46.y.z doesn't appear to be in the rfc1918 > range. So there is no reason to take the norfc1918 out. Is your > intern dhcp server serving up addresses in this 10 range by any > cha

Re: [leaf-user] Bering/Shorewall question

2002-07-21 Thread guitarlynn
On Sunday 21 July 2002 14:30, Kim Oppalfens wrote: > At 21:13 21/07/2002, Cass Tolken wrote: > > Your external address 24.46.y.z doesn't appear to be in the rfc1918 > range. So there is no reason to take the norfc1918 out. > Is your intern dhcp server serving up addresses in this 10 range by > any

RE: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Paul M. Wright, Jr.
>>Some ISP's use private ip's on their DHCP and DNS servers, though >>this is a bad way to save real ip's, it works for them. This is not >>the case in your situation however, you would not have received >>a DHCP lease if it was. Lynn - I'm curious as to your reasoning on this. Doesn't the DHC

Re: [leaf-user] Bering/Shorewall question

2002-07-21 Thread guitarlynn
On Sunday 21 July 2002 16:02, Paul M. Wright, Jr. wrote: > Lynn - > > I'm curious as to your reasoning on this. Doesn't the DHCP lease > request occur before the firewall rules are started? > > My ISP is using an RFC1918 DHCP server and I get and maintain a lease > even with the default Shorewall

RE: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Ray Olszewski
At 02:02 PM 7/21/02 -0700, Paul M. Wright, Jr. wrote: > >>Some ISP's use private ip's on their DHCP and DNS servers, though > >>this is a bad way to save real ip's, it works for them. This is not > >>the case in your situation however, you would not have received > >>a DHCP lease if it was. > >Lyn

FW: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Paul M. Wright, Jr.
-Original Message- From: Paul M. Wright, Jr. [mailto:[EMAIL PROTECTED]] Sent: Sunday, July 21, 2002 2:49 PM To: 'Ray Olszewski' Subject: RE: [leaf-user] Bering/Shorewall question >>The first DHCP lease request (and delivery) occurs before the firewall >>rules

RE: [leaf-user] Bering/Shorewall question

2002-07-21 Thread David Pitts
nn [mailto:[EMAIL PROTECTED]] Sent: Monday, 22 July 2002 5:17 AM To: [EMAIL PROTECTED] Subject: Re: [leaf-user] Bering/Shorewall question On Sunday 21 July 2002 16:02, Paul M. Wright, Jr. wrote: > Lynn - > > I'm curious as to your reasoning on this. Doesn't the DHCP lease > r

RE: [leaf-user] Bering/Shorewall question

2002-07-22 Thread Tom Eastep
On Mon, 22 Jul 2002, David Pitts wrote: > This is exactly my problem with Bering and Dachstein (but not with > Eigerstein!). > > Is it too lazy of me to ask someone to offer a script line that will > allow packets from 10.96.4.1 for Shorewall and Dachstein?? > I'm afraid so. For Bering, this

Re: FW: [leaf-user] Bering/Shorewall question

2002-07-21 Thread Tom Eastep
On Sun, 21 Jul 2002, Paul M. Wright, Jr. wrote: > > > Thanks for the answer! In the interim, I had double-checked my firewall > logs and my ISP's DHCP server is now on a private IP address - hence my > lack of problems with the noRFC1918 option. DHCP assignments are now > coming from a 172.19