Koozali.org: home of the SME Server

Legacy Forums => General Discussion (Legacy) => Topic started by: Lars on January 31, 2003, 10:08:50 PM

Title: Firewall on SME server 5.6?
Post by: Lars on January 31, 2003, 10:08:50 PM
I have a problem with the firewall in SME server 5.6, i don't know where the rules are. Can someone help me finding them?

Thanks

Lars

MyAss.dk @ Denmark
Title: Re: Firewall on SME server 5.6?
Post by: guestHH on January 31, 2003, 10:12:35 PM
/etc/rc.d/init.d/masq
Title: Re: Firewall on SME server 5.6?
Post by: Lars on January 31, 2003, 10:26:33 PM
can you tell me how can i port forward some ports from the internet to the local network?

// Lars
Title: Re: Firewall on SME server 5.6?
Post by: guestHH on January 31, 2003, 10:34:01 PM
ftp://ftp.e-smith.org/pub/e-smith/contrib/CharlieBrady/RPMS/noarch/

look for port forwarding
Title: Re: Firewall on SME server 5.6?
Post by: Lars on February 01, 2003, 12:12:49 AM
Thanks dude ;-)

Do you know if i can forward to a MAC address?
Title: Re: Firewall on SME server 5.6?
Post by: Bill Talcott on February 01, 2003, 12:19:59 AM
I haven't seen the 5.6 version, but in the older versions you can only use it to enter a single port at a time to an IP. If you're worried about DHCP stuff, you can assign that MAC a static IP via the Hostnames and Addresses panel.
Title: Re: Firewall on SME server 5.6?
Post by: Lars on February 01, 2003, 12:34:13 AM
how does it have too look when my MAC address is 12-D7-A4-EA-22-C4
and I want to use 192.168.1.10 for the client
Title: Re: Firewall on SME server 5.6?
Post by: ryan on February 01, 2003, 03:56:26 AM
Quick question,

Are the firewall rules on 5.6 more, less, or equally secure as 5.1.2?

ryan
Title: Re: Firewall on SME server 5.6?
Post by: Ray Mitchell on February 02, 2003, 01:59:17 PM
Ryan
I don't profess to fully understand it all but I would say it is better than 5.1.2

See
http://www.e-smith.org/article.php3&mode=threaded&order=0

To quote
"The firewalling code has been upgraded to include stateful packet inspection.

Packet filter and masquerading changes
The firewalling code has been rewritten to use the Linux iptables interface, and enables connection tracking to allow stateful packet filtering.
All actions which modify firewalling rules now use a new interface which preserves all existing rules. Previous versions rebuilt and reloaded all rules when modifications were required.
Specific protocol modules have been loaded to handle masquerading of FTP, TFTP and PPTP protocols.
The masquerading of all capablities of the H.323, ICQ and RTSP protocols is not supported in this release. Supported customers who require these features should contact smesupport@mitel.com to determine their availability.
The pidentd software which provided responses to IDENT queries has been replaced by oidentd. oidentd has a flexible mechanism for specifying IDENT responses and includes support for identifying netfilter masqueraded connections.
The iptstate program has been added to the release to provide a detailed view of masqueraded connections. This software is currently only available to administrators logged onto the server."

Regards
Ray Mitchell
Title: Re: Firewall on SME server 5.6?
Post by: Jeroen on February 03, 2003, 01:27:44 AM
Wondering if IRC including DCC-chat DCC-sent are still possible?
Title: Re: Firewall on SME server 5.6?
Post by: Treco on February 03, 2003, 03:27:11 AM
Well, with xchat i can dcc-chat and dcc-send, but some my friends on the same lan cant do it with mirc, i can bet that they have their irc client bad configured. With xchat i dont have any prob.
Title: Re: Firewall on SME server 5.6?
Post by: Jeroen on February 03, 2003, 03:44:07 AM
Treco wrote:
>
> Well, with xchat i can dcc-chat and dcc-send, but some my
> friends on the same lan cant do it with mirc, i can bet that
> they have their irc client bad configured. With xchat i dont
> have any prob.

Thanks for the info.

Jeroen
Title: Re: Firewall on SME server 5.6?
Post by: ryan on February 03, 2003, 07:21:44 PM
At home, I can't dcc with mirc through 5.1.2.  I use Virc and it works fine.
Title: Re: Firewall on SME server 5.6?
Post by: ryan on February 03, 2003, 07:22:59 PM
Virc is very similar to mirc and runs on windows.ryan wrote:
>
> At home, I can't dcc with mirc through 5.1.2.  I use Virc and
> it works fine.
Title: Re: Firewall on SME server 5.6?
Post by: jeroen on February 05, 2003, 02:46:34 AM
ryan wrote:
>
> Virc is very similar to mirc and runs on windows.ryan wrote:
> >
> > At home, I can't dcc with mirc through 5.1.2.  I use Virc and
> > it works fine.

I use mirc with 5.1.2 now, dcc works fine for me. Did you make sure that you -ONLY- connect to the server on port 6667?

Jeroen