Screenshot instructions:
Windows
Mac
Red Hat Linux
Ubuntu
Click URL instructions:
Right-click on ad, choose "Copy Link", then paste here →
(This may not be possible with some types of ads)
You can subscribe to this list here.
2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(93) |
Nov
(89) |
Dec
(68) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2002 |
Jan
(229) |
Feb
(204) |
Mar
(314) |
Apr
(380) |
May
(367) |
Jun
(244) |
Jul
(300) |
Aug
(505) |
Sep
(359) |
Oct
(531) |
Nov
(427) |
Dec
(390) |
2003 |
Jan
(585) |
Feb
(623) |
Mar
(412) |
Apr
(315) |
May
(480) |
Jun
(394) |
Jul
(544) |
Aug
(768) |
Sep
(602) |
Oct
(680) |
Nov
(499) |
Dec
(398) |
2004 |
Jan
(407) |
Feb
(400) |
Mar
(410) |
Apr
(576) |
May
(619) |
Jun
(424) |
Jul
(513) |
Aug
(404) |
Sep
(433) |
Oct
(455) |
Nov
(550) |
Dec
(659) |
2005 |
Jan
(450) |
Feb
(472) |
Mar
(443) |
Apr
(465) |
May
(434) |
Jun
(273) |
Jul
(518) |
Aug
(484) |
Sep
(380) |
Oct
(400) |
Nov
(351) |
Dec
(265) |
2006 |
Jan
(335) |
Feb
(462) |
Mar
(498) |
Apr
(398) |
May
(280) |
Jun
(273) |
Jul
(229) |
Aug
(377) |
Sep
(201) |
Oct
(279) |
Nov
(247) |
Dec
(229) |
2007 |
Jan
(301) |
Feb
(190) |
Mar
(281) |
Apr
(444) |
May
(394) |
Jun
(247) |
Jul
(259) |
Aug
(391) |
Sep
(219) |
Oct
(306) |
Nov
(307) |
Dec
(257) |
2008 |
Jan
(256) |
Feb
(248) |
Mar
(330) |
Apr
(219) |
May
(194) |
Jun
(179) |
Jul
(183) |
Aug
(116) |
Sep
(260) |
Oct
(204) |
Nov
(274) |
Dec
(228) |
2009 |
Jan
(251) |
Feb
(160) |
Mar
(178) |
Apr
(196) |
May
(189) |
Jun
(239) |
Jul
(92) |
Aug
(155) |
Sep
(147) |
Oct
(169) |
Nov
(159) |
Dec
(205) |
2010 |
Jan
(63) |
Feb
(230) |
Mar
(94) |
Apr
(103) |
May
(113) |
Jun
(149) |
Jul
(158) |
Aug
(203) |
Sep
(255) |
Oct
(138) |
Nov
(122) |
Dec
(108) |
2011 |
Jan
(93) |
Feb
(100) |
Mar
(153) |
Apr
(175) |
May
(349) |
Jun
(210) |
Jul
(176) |
Aug
(179) |
Sep
(148) |
Oct
(151) |
Nov
(102) |
Dec
(83) |
2012 |
Jan
(179) |
Feb
(125) |
Mar
(211) |
Apr
(164) |
May
(195) |
Jun
(160) |
Jul
(137) |
Aug
(159) |
Sep
(214) |
Oct
(189) |
Nov
(71) |
Dec
(90) |
2013 |
Jan
(161) |
Feb
(99) |
Mar
(190) |
Apr
(133) |
May
(119) |
Jun
(97) |
Jul
(116) |
Aug
(109) |
Sep
(213) |
Oct
(175) |
Nov
(119) |
Dec
(90) |
2014 |
Jan
(104) |
Feb
(105) |
Mar
(125) |
Apr
(119) |
May
(141) |
Jun
(82) |
Jul
(193) |
Aug
(164) |
Sep
(160) |
Oct
(162) |
Nov
(44) |
Dec
(43) |
2015 |
Jan
(92) |
Feb
(67) |
Mar
(117) |
Apr
(67) |
May
(121) |
Jun
(39) |
Jul
(31) |
Aug
(87) |
Sep
(143) |
Oct
(130) |
Nov
(116) |
Dec
(67) |
2016 |
Jan
(66) |
Feb
(78) |
Mar
(127) |
Apr
(148) |
May
(56) |
Jun
(67) |
Jul
(30) |
Aug
(48) |
Sep
(87) |
Oct
(113) |
Nov
(64) |
Dec
(115) |
2017 |
Jan
(95) |
Feb
(73) |
Mar
(166) |
Apr
(27) |
May
(75) |
Jun
(94) |
Jul
(144) |
Aug
(94) |
Sep
(70) |
Oct
(98) |
Nov
(69) |
Dec
(176) |
2018 |
Jan
(140) |
Feb
(112) |
Mar
(68) |
Apr
(52) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
|
1
(6) |
2
(4) |
3
(10) |
4
(13) |
5
(5) |
6
(3) |
7
|
8
(17) |
9
(20) |
10
(16) |
11
(13) |
12
(8) |
13
|
14
(2) |
15
(9) |
16
(21) |
17
(8) |
18
(3) |
19
(14) |
20
(5) |
21
(13) |
22
(5) |
23
(19) |
24
(14) |
25
(6) |
26
(7) |
27
(4) |
28
(4) |
29
(17) |
30
(3) |
31
(31) |
|
|
|
From: Greg M <subtle1@ho...> - 2002-07-08 23:55:36
|
>Greg M wrote: >>Hi folks, >> >>If I do... >> >>shorewall drop x.x.x.x >> >>Then I do... >> >>shorewall save >> >>the blacklist file doesn't seem to be updated. > >Did you see anywhere in the documentation that said that it would be >updated? No, it didn't clearly state how or where. See what I get for assuming... :-) >/var/lib/shorewall/save. Thanks! _________________________________________________________________ Send and receive Hotmail on your mobile device: http://mobile.msn.com |
From: j2 <spamfilter2@mu...> - 2002-07-08 23:53:55
|
----- Original Message ----- From: "Tom Eastep" <teastep@...> To: "j2" <spamfilter2@...> Cc: <shorewall-users@...> Sent: Tuesday, July 09, 2002 1:47 AM Subject: Re: [Shorewall-users] Rules for PPTP? > On Tue, 9 Jul 2002, j2 wrote: > > > Uhm,. one more Q. (This is prolly mor eWindows Networking then shorewall.. > > but someone might know) > > > > i have set the PPTP server to allocate ips on the 192.168.10.[2-10] range. > > The server it self is 192.168.0.160. > > You shouldn't do that. You should allocate the remote IPs in the > 192.168.0.0/24 subnet and specify 'proxyarp' in your /etc/ppp/options > file. And translated to a "pure windows" enviroment client is outside the shorewall on a public IP, and the server is as above? |
From: Tom Eastep <teastep@sh...> - 2002-07-08 23:48:53
|
On Mon, 8 Jul 2002, Jim Van Eeckhoutte wrote: > ---------- Original Message ---------------------------------- > From: "Jim Van Eeckhoutte" <jim@...> > Reply-To: <jim@...> > Date: Mon, 8 Jul 2002 15:27:14 -0700 > > this is shorewall status output: > > tcp 6 431899 ESTABLISHED src=192.168.20.5 dst=64.4.12.45 sport=2185 dport=1863 src=64.4.12.45 dst=63.25.123.58 sport=1863 dport=2185 [ASSURED] use=1 > udp 17 30 src=192.168.20.5 dst=192.168.20.254 sport=2359 dport=53 [UNREPLIED] src=192.168.20.254 dst=192.168.20.5 sport=53 dport=2359 use=1 > tcp 6 431999 ESTABLISHED src=192.168.20.5 dst=192.168.20.254 sport=2130 dport=22 src=192.168.20.254 dst=192.168.20.5 sport=22 dport=2130 [ASSURED] use=1 > udp 17 28 src=192.168.20.5 dst=192.168.20.254 sport=2358 dport=53 [UNREPLIED] src=192.168.20.254 dst=192.168.20.5 sport=53 dport=2358 use=1 > > i have dnscache.lrp and daemontl.lrp running on bering box. When setting > client to point to bering router as dns , it cant resolve. Is there a > reason why the above is UNREPLIED? Because either dnscache hasn't replied (do you have rules allowing DNS queries from the firewall to the internet at large?) or you have a routing problem such that there isn't a route back to 192.168.20.5 (I think you would have noticed that before however). -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: Tom Eastep <teastep@sh...> - 2002-07-08 23:47:06
|
On Tue, 9 Jul 2002, j2 wrote: > Uhm,. one more Q. (This is prolly mor eWindows Networking then shorewall.. > but someone might know) > > i have set the PPTP server to allocate ips on the 192.168.10.[2-10] range. > The server it self is 192.168.0.160. You shouldn't do that. You should allocate the remote IPs in the 192.168.0.0/24 subnet and specify 'proxyarp' in your /etc/ppp/options file. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: j2 <spamfilter2@mu...> - 2002-07-08 23:44:46
|
Uhm,. one more Q. (This is prolly mor eWindows Networking then shorewall.. but someone might know) i have set the PPTP server to allocate ips on the 192.168.10.[2-10] range. The server it self is 192.168.0.160. Now, is it possible to add routing on the W2k server so that a client connected to pptp can access shares on 192.168.0.130? |
From: Tom Eastep <teastep@sh...> - 2002-07-08 23:43:35
|
Greg M wrote: > Hi folks, > > If I do... > > shorewall drop x.x.x.x > > Then I do... > > shorewall save > > the blacklist file doesn't seem to be updated. Did you see anywhere in the documentation that said that it would be updated? > > http://www.shorewall.net/blacklisting_support.htm states "save the > dynamic blacklisting configuration so that it will be automatically > restored the next time that the firewall is restarted". > > This infers the blacklisted ip's will be saved, but where? /var/lib/shorewall/save. > > Am I misinterpreting the documentation on how this feature works? Yes and No -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: Tom Eastep <teastep@sh...> - 2002-07-08 23:41:35
|
j2 wrote: >>>I tried the following as per the Documentation, but i get >>> >>># >>>#PPTP >>>DNAT net loc tcp 1723 >>>DNAT net loc 47 - >>>#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE >>> >>>Error: DNAT rules require a server address; rule: "DNAT net loc tcp >> > 1723" > >>Did you mean to have a dash in the first rule???? No. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: Greg M <subtle1@ho...> - 2002-07-08 23:37:56
|
Hi folks, If I do... shorewall drop x.x.x.x Then I do... shorewall save the blacklist file doesn't seem to be updated. http://www.shorewall.net/blacklisting_support.htm states "save the dynamic blacklisting configuration so that it will be automatically restored the next time that the firewall is restarted". This infers the blacklisted ip's will be saved, but where? Am I misinterpreting the documentation on how this feature works? I'm using shorewall-1.3.2-1 RPM package on Mandrake 8.2. Thanks, Greg _________________________________________________________________ Join the worlds largest e-mail service with MSN Hotmail. http://www.hotmail.com |
From: j2 <spamfilter2@mu...> - 2002-07-08 23:34:21
|
> Duh -- looks like I get to wear the pointy hat this time. Try: > > DNAT net loc:192.168.0.160 tcp 1723 > DNAT net loc:192.168.0.160 47 - Worked (and looks) better.. but i figured "THIS time ill just gobythebook" Thanks :) |
From: Jim Van Eeckhoutte <jim@va...> - 2002-07-08 23:33:51
|
---------- Original Message ---------------------------------- From: "Jim Van Eeckhoutte" <jim@...> Reply-To: <jim@...> Date: Mon, 8 Jul 2002 15:27:14 -0700 this is shorewall status output: tcp 6 431899 ESTABLISHED src=192.168.20.5 dst=64.4.12.45 sport=2185 dport=1863 src=64.4.12.45 dst=63.25.123.58 sport=1863 dport=2185 [ASSURED] use=1 udp 17 30 src=192.168.20.5 dst=192.168.20.254 sport=2359 dport=53 [UNREPLIED] src=192.168.20.254 dst=192.168.20.5 sport=53 dport=2359 use=1 tcp 6 431999 ESTABLISHED src=192.168.20.5 dst=192.168.20.254 sport=2130 dport=22 src=192.168.20.254 dst=192.168.20.5 sport=22 dport=2130 [ASSURED] use=1 udp 17 28 src=192.168.20.5 dst=192.168.20.254 sport=2358 dport=53 [UNREPLIED] src=192.168.20.254 dst=192.168.20.5 sport=53 dport=2358 use=1 i have dnscache.lrp and daemontl.lrp running on bering box. When setting client to point to bering router as dns , it cant resolve. Is there a reason why the above is UNREPLIED? |
From: Tom Eastep <teastep@sh...> - 2002-07-08 23:31:11
|
j2 wrote: > I tried the following as per the Documentation, but i get > > # > #PPTP > DNAT net loc tcp 1723 > DNAT net loc 47 - > #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE > > Error: DNAT rules require a server address; rule: "DNAT net loc tcp 1723" > > when doing a check/restart? > > Firewall with one public IP. A w2k Pro living behind it is to act as PPTP > server on 192.168.0.160. Uhm i am sure i am missing some RTFM (but i DID > read the errata this time Tom, promise! ;) ) > Duh -- looks like I get to wear the pointy hat this time. Try: DNAT net loc:192.168.0.160 tcp 1723 DNAT net loc:192.168.0.160 47 - And I'll fix the documentation... -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: j2 <spamfilter2@mu...> - 2002-07-08 23:30:30
|
> > I tried the following as per the Documentation, but i get > > > > # > > #PPTP > > DNAT net loc tcp 1723 > > DNAT net loc 47 - > > #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE > > > > Error: DNAT rules require a server address; rule: "DNAT net loc tcp 1723" > > > > Did you mean to have a dash in the first rule???? http://www.shorewall.net/PPTP.htm I stole the config from there. What _do_ i want then? |
From: j2 <spamfilter2@mu...> - 2002-07-08 23:23:01
|
I tried the following as per the Documentation, but i get # #PPTP DNAT net loc tcp 1723 DNAT net loc 47 - #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Error: DNAT rules require a server address; rule: "DNAT net loc tcp 1723" when doing a check/restart? Firewall with one public IP. A w2k Pro living behind it is to act as PPTP server on 192.168.0.160. Uhm i am sure i am missing some RTFM (but i DID read the errata this time Tom, promise! ;) ) |
From: Tom Eastep <teastep@sh...> - 2002-07-08 21:39:23
|
Lorenzo Marignoni reports that the packages are available at http://security.dsi.unimi.it/~lorenzo/debian.html. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: Tom Eastep <teastep@sh...> - 2002-07-08 21:31:44
|
Tom Eastep wrote: > > > A VPN would be more secure but it definitely isn't easier. And given > that your firewall runs Bering, I suspend that you don't want to add ------- Make that "suspect" :-) > large packages to your firewall? > I knew I should have stayed on vacation... -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: Tom Eastep <teastep@sh...> - 2002-07-08 21:28:16
|
Steve Sobka wrote: > > Everything DOES work, but I am wondering if there is some easier way to go > about this? Like using aVPN or somthing similar? I just have no idea what to > look for if there is a better way, or what it would be called? A VPN would be more secure but it definitely isn't easier. And given that your firewall runs Bering, I suspend that you don't want to add large packages to your firewall? > > Could anyone make a suggestion on a more secure way of accomplishing the > same task? Do any of the boxes behind your firewall support a VPN server (W2K, NT Server)? If so, setting one of them up as a VPN server then using your laptop as a VPN client would probably be the easiest. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@... |
From: Steve Sobka <hickbot@fu...> - 2002-07-08 16:53:06
|
I am not sure if this setup is correct, or if I could go about doing this in a more secure manner. I thought I would post here for suggestions. I have a somewhat strange setup here at my house. I have a leaf-bering box running shorewall 1.3.1. I get my IP via DHCP from cable company. I have a 3 nic setup. I have most of my computers in the loc zone, including a Samba Server at 192.168.1.200. I use the setup: loc=192.168.1.0/24 dmz =192.168.2.0/24 Now the only thing I have in the dmz zome is a wireless router (not an Access Point). It was given to me free and I use it to allow me access to the internet while walking around the house. Now this router will not let me put the WAN and LAN ip's on the same subnet (i.e. wont allow both WAN and LAN on the 192.168.2.0/24), therefore I put the routers WAN IP at 192.168.2.253 so it's on the subnet of the leaf-bering box and the LAN IP as 10.150.150.1 and my wireless nic on my laptop as 10.150.150.2 with the .1 address of the wireless router specified as the gateway, dns, etc for my laptop and it works fine, I can browse the internet and connect to the Samba shares on the loc zone. Since I wanted to allow samba between the wireless NIC at 10.150.150.2 and the samba server on the loc zone at 192.168.1.200. I've added this to my rules file: ACCEPT dmz loc udp 137:139 ACCEPT dmz loc tcp 137,139 ACCEPT dmz loc udp 1024: 137 ACCEPT loc dmz udp 137:139 ACCEPT loc dmz tcp 137,139 ACCEPT loc dmz udp 1024: 137 Everything DOES work, but I am wondering if there is some easier way to go about this? Like using aVPN or somthing similar? I just have no idea what to look for if there is a better way, or what it would be called? Could anyone make a suggestion on a more secure way of accomplishing the same task? All I really want to do is allow my laptop to browse the internet and connect to shares & printers on the loc zone, but I really dont want to open the loc zone up to the entire dmz incase someone hitches a free ride onto my wireless router. I hope that made sense :-) Steve Sobka |