You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(259) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(361) |
Feb
(71) |
Mar
(270) |
Apr
(164) |
May
(55) |
Jun
(218) |
Jul
(203) |
Aug
(146) |
Sep
(105) |
Oct
(70) |
Nov
(156) |
Dec
(223) |
| 2003 |
Jan
(229) |
Feb
(126) |
Mar
(461) |
Apr
(288) |
May
(203) |
Jun
(64) |
Jul
(97) |
Aug
(228) |
Sep
(384) |
Oct
(208) |
Nov
(88) |
Dec
(291) |
| 2004 |
Jan
(425) |
Feb
(382) |
Mar
(457) |
Apr
(300) |
May
(323) |
Jun
(326) |
Jul
(487) |
Aug
(458) |
Sep
(636) |
Oct
(429) |
Nov
(174) |
Dec
(288) |
| 2005 |
Jan
(242) |
Feb
(148) |
Mar
(146) |
Apr
(148) |
May
(200) |
Jun
(134) |
Jul
(120) |
Aug
(183) |
Sep
(163) |
Oct
(253) |
Nov
(248) |
Dec
(63) |
| 2006 |
Jan
(96) |
Feb
(65) |
Mar
(88) |
Apr
(172) |
May
(122) |
Jun
(111) |
Jul
(83) |
Aug
(210) |
Sep
(102) |
Oct
(37) |
Nov
(28) |
Dec
(41) |
| 2007 |
Jan
(82) |
Feb
(84) |
Mar
(218) |
Apr
(61) |
May
(66) |
Jun
(35) |
Jul
(55) |
Aug
(64) |
Sep
(20) |
Oct
(92) |
Nov
(420) |
Dec
(399) |
| 2008 |
Jan
(149) |
Feb
(72) |
Mar
(209) |
Apr
(155) |
May
(77) |
Jun
(150) |
Jul
(142) |
Aug
(99) |
Sep
(78) |
Oct
(98) |
Nov
(82) |
Dec
(25) |
| 2009 |
Jan
(38) |
Feb
(86) |
Mar
(129) |
Apr
(64) |
May
(106) |
Jun
(121) |
Jul
(149) |
Aug
(110) |
Sep
(74) |
Oct
(98) |
Nov
(83) |
Dec
(46) |
| 2010 |
Jan
(53) |
Feb
(43) |
Mar
(86) |
Apr
(185) |
May
(44) |
Jun
(58) |
Jul
(41) |
Aug
(47) |
Sep
(52) |
Oct
(49) |
Nov
(47) |
Dec
(66) |
| 2011 |
Jan
(58) |
Feb
(33) |
Mar
(37) |
Apr
(31) |
May
(8) |
Jun
(8) |
Jul
(2) |
Aug
(28) |
Sep
(75) |
Oct
(46) |
Nov
(40) |
Dec
(7) |
| 2012 |
Jan
(61) |
Feb
(32) |
Mar
(20) |
Apr
(6) |
May
(11) |
Jun
(8) |
Jul
(1) |
Aug
(16) |
Sep
(21) |
Oct
(12) |
Nov
(12) |
Dec
(1) |
| 2013 |
Jan
(15) |
Feb
(8) |
Mar
(21) |
Apr
(25) |
May
(18) |
Jun
(20) |
Jul
(21) |
Aug
|
Sep
(1) |
Oct
(9) |
Nov
(10) |
Dec
(13) |
| 2014 |
Jan
(33) |
Feb
(41) |
Mar
(10) |
Apr
(44) |
May
(3) |
Jun
|
Jul
(6) |
Aug
(2) |
Sep
(1) |
Oct
(7) |
Nov
(10) |
Dec
(12) |
| 2015 |
Jan
(1) |
Feb
(17) |
Mar
(8) |
Apr
|
May
|
Jun
|
Jul
|
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
(1) |
| 2016 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
(2) |
Nov
|
Dec
|
| 2017 |
Jan
|
Feb
(1) |
Mar
(1) |
Apr
|
May
|
Jun
(2) |
Jul
(5) |
Aug
|
Sep
(1) |
Oct
(2) |
Nov
|
Dec
|
| 2018 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
|
Dec
|
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
|
|
1
|
2
(2) |
3
(2) |
4
|
5
(7) |
6
|
|
7
|
8
|
9
|
10
|
11
|
12
|
13
|
|
14
(1) |
15
(2) |
16
|
17
|
18
|
19
|
20
|
|
21
|
22
(1) |
23
|
24
(1) |
25
|
26
|
27
|
|
28
(2) |
29
|
30
(5) |
31
(2) |
|
|
|
|
From: Olaf W. <wei...@ip...> - 2008-12-31 16:43:03
|
Hi Eric, > I solved it by chmod 666 /dev/urandom > > Is this another line to add to rc.sysinit ? Probably better to solve the problem ;-) Your message made me revisit this rule thing, and sure enough I figured out what is happening this time. It *does* seem to help to put an issue aside for some time and then return to it later. We simply do not have 50-udev-default.rules in the ISO (never had for that matter), caused by a change in udev rulessets several months ago. You can grab 50-udev-default.rules from build_i486/ipcop/lib/udev/rules.d directory and put it in /lib/udev/rules.d, after ipcopreboot boot all should be well. Nice to end an interesting 2008 this way. Looking forward to 2009. Watch out for those firecrackers, Olaf -- A weizen a day helps keep the doctor away. |
|
From: Eric O. <eri...@gm...> - 2008-12-31 15:41:47
|
Hi I just installed 1.9.4 for testing and noticed that the fingerprint and size of the ssh_host keys was not displayed in remote.cgi The error in the logs was "PRNG is not seeded\r" I solved it by chmod 666 /dev/urandom Is this another line to add to rc.sysinit ? Eric |
|
From: Olaf W. <wei...@ip...> - 2008-12-30 19:07:05
|
Gilles Espinasse wrote: >> Is it really necessary to have CA/host cert for IPsec and OpenVPN > separate? >> Or could we merge and at the same time create 1 GUI page for that? >> > It has been suggested that should be merged. > Just that nobody has yet done that. Okay thanks. I will start with that then. I think my old brain is finally giving up on me ... Olaf -- A weizen a day helps keep the doctor away. |
|
From: Gilles E. <g....@fr...> - 2008-12-30 18:39:27
|
----- Original Message ----- From: <ow...@us...> To: <ipc...@li...> Sent: Tuesday, December 30, 2008 7:19 PM Subject: [Ipcop-svn] SF.net SVN: ipcop:[2254] ipcop/trunk > Revision: 2254 > http://ipcop.svn.sourceforge.net/ipcop/?rev=2254&view=rev > Author: owes > Date: 2008-12-30 18:19:12 +0000 (Tue, 30 Dec 2008) > > Log Message: > ----------- > Add openssl config file for OpenVPN. > Is it really necessary to have CA/host cert for IPsec and OpenVPN separate? > Or could we merge and at the same time create 1 GUI page for that? > It has been suggested that should be merged. Just that nobody has yet done that. Gilles |
|
From: Olaf W. <wei...@ip...> - 2008-12-30 10:46:49
|
Gilles Espinasse wrote:
> I don't understand the added value to force the user to add nic*.
> I don't know why the author could have think that's a feature.
> I know this has been present at a time on Suse patch against rp-pppoe plugin
> before to being removed.
There are 2 uses for nic- that I found, first in plugin.c
/**********************************************************************
* %FUNCTION: PPPoEDevnameHook
* %ARGUMENTS:
* cmd -- the command (actually, the device name
* argv -- argument vector
* doit -- if non-zero, set device name. Otherwise, just check if possible
* %RETURNS:
* 1 if we will handle this device; 0 otherwise.
* %DESCRIPTION:
* Checks if name is a valid interface name; if so, returns 1. Also
* sets up devnam (string representation of device).
***********************************************************************/
static int
PPPoEDevnameHook(char *cmd, char **argv, int doit)
{
int r = 1;
int fd;
struct ifreq ifr;
/* Only do it if name is "ethXXX" or "brXXX" or what was specified
by rp_pppoe_dev option (ugh). */
/* Can also specify nic-XXXX in which case the nic- is stripped off. */
if (!strncmp(cmd, "nic-", 4)) {
cmd += 4;
} else {
if (strncmp(cmd, "eth", 3) &&
strncmp(cmd, "br", 2)) {
if (OldDevnameHook) return OldDevnameHook(cmd, argv, doit);
return 0;
}
}
The way I see that it is checked for interface match eth* or br*, if no
match return an error.
In case nic- is used, it is tested whether the interface is Ethernet.
Second use is in pppoe-server.c in function startPPPDLinuxKernelMode,
there nic- is always added to interface name (do not ask me why, I do
not know ;-))
Olaf
--
A weizen a day helps keep the doctor away.
|
|
From: Gilles E. <g....@fr...> - 2008-12-30 10:37:28
|
----- Original Message ----- From: "Olaf Westrik" <wei...@ip...> To: "IPCop devel" <ipc...@li...> Sent: Tuesday, December 30, 2008 11:19 AM Subject: [IPCop-devel] [1.4] rc.red modification for rp-pppoe > > Any objections to making the same modification as SVN#2244 for 1.4 as > well? See patch below. > > > For reference: http://www.ipcop-forum.de/forum/viewtopic.php?f=28&t=23309 > > It seems possible to use PPPoE over a WLAN connection (did not know that > was possible ;-)) > However with rp-pppoe that is not possible as is, since in this case the > interface ath0 (WLAN thru madwifi driver) is not accepted. > When using nic-ath0 everything works OK. > > I have changed my 'normal' PPPoE DSL connection to use the same nic-eth1 > instead of eth1 and that works OK too. > > > Olaf > I would have to check with eci driver (wich use a tun or tap interface if I remember well) That's the only problem I see for now without yet testing. I don't understand the added value to force the user to add nic*. I don't know why the author could have think that's a feature. I know this has been present at a time on Suse patch against rp-pppoe plugin before to being removed. Gilles |
|
From: Olaf W. <wei...@ip...> - 2008-12-30 10:20:07
|
Any objections to making the same modification as SVN#2244 for 1.4 as well? See patch below. For reference: http://www.ipcop-forum.de/forum/viewtopic.php?f=28&t=23309 It seems possible to use PPPoE over a WLAN connection (did not know that was possible ;-)) However with rp-pppoe that is not possible as is, since in this case the interface ath0 (WLAN thru madwifi driver) is not accepted. When using nic-ath0 everything works OK. I have changed my 'normal' PPPoE DSL connection to use the same nic-eth1 instead of eth1 and that works OK too. Olaf =================================================================== RCS file: /cvsroot/ipcop/ipcop/src/rc.d/Attic/rc.red,v retrieving revision 1.29.2.62 diff -u -r1.29.2.62 rc.red --- ipcop/src/rc.d/rc.red 18 Oct 2007 11:27:43 -0000 1.29.2.62 +++ ipcop/src/rc.d/rc.red 30 Dec 2008 10:17:02 -0000 @@ -615,7 +615,7 @@ # PPPoE plugin system ('/sbin/modprobe pppoe'); my @pppcommand = ('/usr/sbin/pppd'); - push(@pppcommand,'plugin','rp-pppoe.so',"$netsettings{'RED_DEV'}"); + push(@pppcommand,'plugin','rp-pppoe.so',"nic-$netsettings{'RED_DEV'}"); if ($pppsettings{'DNS'} eq 'Automatic') { push(@pppcommand, ('usepeerdns')); } -- A weizen a day helps keep the doctor away. |
|
From: Olaf W. <wei...@ip...> - 2008-12-28 14:51:36
|
Gilles Espinasse wrote: > There will be still some works on the perl side to be done. > We probably should drop suid perl feature and replace with a wrapper like we > already have for some scripts. > > Read why perl suid feature is broken in perl-5.8.9 at > http://www.nntp.perl.org/group/perl.perl5.porters/2008/12/msg142835.html That would only be rc.red, correct? No problem to add wrapper ipcopred, restartred, name-your-favourite-wrapper Olaf -- A weizen a day helps keep the doctor away. |
|
From: Gilles E. <g....@fr...> - 2008-12-28 14:20:53
|
After a few problems, I have perl-5.10.0 compilation and all tests ok. I still need to update the rootfile. In fact, my error was to mix some LFS and DIY instructions and then the second perl compilation fail. That's not so important now to run perl-5.10.0 but as perl-5.10.1 should come in a near futur, I was looking to be ready for testing if a 5.10.1.rc1 happen. I should be able to commit that change in a week. There will be still some works on the perl side to be done. We probably should drop suid perl feature and replace with a wrapper like we already have for some scripts. Read why perl suid feature is broken in perl-5.8.9 at http://www.nntp.perl.org/group/perl.perl5.porters/2008/12/msg142835.html Gilles |
|
From: jingxu f. <io...@gm...> - 2008-12-24 13:48:58
|
when i compiled successfully under version 2227 and installed in vmware with the cd, it started with the following mistake message: SSLCertificateFile: file '/etc/httpd/server.crt' does not exist or is empty. and i can't open the web page . is this a bug? |
|
From: Achim W. <dot...@gm...> - 2008-12-22 20:21:40
|
> Revision: 2218 > http://ipcop.svn.sourceforge.net/ipcop/?rev=2218&view=rev > Author: owes > Date: 2008-12-22 16:37:42 +0000 (Mon, 22 Dec 2008) > > Log Message: > ----------- > I do not see a reason to have /root mounted as ramfs during setup / restore. > In fact this kills the user possibillity to backup/restore files to /root, > for example .ssh/authorized_keys as noticed by Achim. Hi Olaf thanks for fixing this one :-) Achim |
|
From: Gilles E. <g....@fr...> - 2008-12-15 12:26:48
|
Selon Chris Taylor <ch...@eq...>: > Olaf Westrik wrote: > > ges...@us... wrote: > >> Revision: 2194 > >> http://ipcop.svn.sourceforge.net/ipcop/?rev=2194&view=rev > >> Author: gespinasse > >> Date: 2008-12-13 23:51:04 +0000 (Sat, 13 Dec 2008) > >> > >> Log Message: > >> ----------- > >> Upgrade openswan to 2.6.20dr2 (this is in developement directory) > > > > > > Does this actually build ? The way I see it we can only solve this by > > including xmlto (and probably some more to make xmlto actually work) or > > much more patching :-/ > > > > > > Build log: > > ... > > xmlto man ipsec.secrets.5.xml) > > /bin/sh: xmlto: command not found > > /bin/sh: xmlto: command not found > > make[4]: *** [doinstall] Error 127 ... > > > > Unless I'm mistaken, it should only need xmlto on the build host, or the > toolchain.. Likely the toolchain.. > > Easiest way to test would be to try and copy/link the binary into the > relevant place in the toolchain during build, before it reaches > openswan.. I think. Not built ipcop in quite a while, so not sure how > the build process works these days... ;) > > I don't xlmto as requirement as it will pull more and more dependencies. I have workaround with a dirty patch to remove the offending parts. I should try to have something cleaner in the futur that could be accepted upstream, letting man pages as an option to be optionally not build. The easy part is to replace in Makefile.top --- openswan-2.6.20dr2/Makefile.top.old 2008-12-03 19:22:30.000000000 +0100 +++ openswan-2.6.20dr2/Makefile.top 2008-12-14 11:12:15.000000000 +0100 @@ -29,7 +29,7 @@ KVUTIL=${MAKEUTILS}/kernelversion KVSHORTUTIL=${MAKEUTILS}/kernelversion-short -SUBDIRS=doc lib programs testing +SUBDIRS ?= doc lib programs testing clean:: -(cd ${OPENSWANSRCDIR} && $(MAKE) modclean && $(MAKE) mod26clean) So for us, we could redefine SUBDIRS and not build man pages using SUBDIRS="lib programs" make programs But there is some man pages build out of doc directory, so more tweaking is needed to not build those pages when SUBDIRS does not contain 'doc' word. Gilles |
|
From: Chris T. <ch...@eq...> - 2008-12-15 10:59:56
|
Olaf Westrik wrote: > ges...@us... wrote: >> Revision: 2194 >> http://ipcop.svn.sourceforge.net/ipcop/?rev=2194&view=rev >> Author: gespinasse >> Date: 2008-12-13 23:51:04 +0000 (Sat, 13 Dec 2008) >> >> Log Message: >> ----------- >> Upgrade openswan to 2.6.20dr2 (this is in developement directory) > > > Does this actually build ? The way I see it we can only solve this by > including xmlto (and probably some more to make xmlto actually work) or > much more patching :-/ > > > Build log: > > make[4]: Entering directory > `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386/programs/pluto' > mkdir -p /usr/libexec/ipsec /usr/lib/ipsec > mkdir -p -m 755 /etc/ipsec.d > mkdir -p -m 755 /etc/ipsec.d/cacerts > mkdir -p -m 755 /etc/ipsec.d/aacerts > mkdir -p -m 755 /etc/ipsec.d/ocspcerts > mkdir -p -m 755 /etc/ipsec.d/certs > mkdir -p -m 755 /etc/ipsec.d/crls > mkdir -p -m 700 /etc/ipsec.d/private > mkdir -p -m 700 /var/run/pluto > install -b --suffix=.old pluto whack /usr/libexec/ipsec > #install --mode=u+rxs,g+rx,o+rx --group=root -b --suffix=.old whackinit > /usr/libexec/ipsec > if false ; then install -b --suffix=.old _pluto_adns /usr/libexec/ipsec > ; fi > ( cd /usr/src/openswan-2.6.20dr2/programs/pluto ; xmlto man pluto.8.xml > ; mv ipsec_pluto.8 pluto.8; > xmlto man ipsec.secrets.5.xml) > /bin/sh: xmlto: command not found > /bin/sh: xmlto: command not found > make[4]: *** [doinstall] Error 127 > make[4]: Leaving directory > `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386/programs/pluto' > make[3]: *** [install] Error 1 > make[3]: Leaving directory > `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386/programs' > make[2]: *** [install] Error 1 > make[2]: Leaving directory `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386' > make[1]: *** [install] Error 2 > make[1]: Leaving directory `/usr/src/openswan-2.6.20dr2' > make: *** [/usr/src/log_i486/03_ipcop/openswan-2.6.20dr2] Error 2 > > > > > Olaf > Unless I'm mistaken, it should only need xmlto on the build host, or the toolchain.. Likely the toolchain.. Easiest way to test would be to try and copy/link the binary into the relevant place in the toolchain during build, before it reaches openswan.. I think. Not built ipcop in quite a while, so not sure how the build process works these days... ;) Chris |
|
From: Olaf W. <wei...@ip...> - 2008-12-14 08:21:15
|
ges...@us... wrote: > Revision: 2194 > http://ipcop.svn.sourceforge.net/ipcop/?rev=2194&view=rev > Author: gespinasse > Date: 2008-12-13 23:51:04 +0000 (Sat, 13 Dec 2008) > > Log Message: > ----------- > Upgrade openswan to 2.6.20dr2 (this is in developement directory) Does this actually build ? The way I see it we can only solve this by including xmlto (and probably some more to make xmlto actually work) or much more patching :-/ Build log: make[4]: Entering directory `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386/programs/pluto' mkdir -p /usr/libexec/ipsec /usr/lib/ipsec mkdir -p -m 755 /etc/ipsec.d mkdir -p -m 755 /etc/ipsec.d/cacerts mkdir -p -m 755 /etc/ipsec.d/aacerts mkdir -p -m 755 /etc/ipsec.d/ocspcerts mkdir -p -m 755 /etc/ipsec.d/certs mkdir -p -m 755 /etc/ipsec.d/crls mkdir -p -m 700 /etc/ipsec.d/private mkdir -p -m 700 /var/run/pluto install -b --suffix=.old pluto whack /usr/libexec/ipsec #install --mode=u+rxs,g+rx,o+rx --group=root -b --suffix=.old whackinit /usr/libexec/ipsec if false ; then install -b --suffix=.old _pluto_adns /usr/libexec/ipsec ; fi ( cd /usr/src/openswan-2.6.20dr2/programs/pluto ; xmlto man pluto.8.xml ; mv ipsec_pluto.8 pluto.8; xmlto man ipsec.secrets.5.xml) /bin/sh: xmlto: command not found /bin/sh: xmlto: command not found make[4]: *** [doinstall] Error 127 make[4]: Leaving directory `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386/programs/pluto' make[3]: *** [install] Error 1 make[3]: Leaving directory `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386/programs' make[2]: *** [install] Error 1 make[2]: Leaving directory `/usr/src/openswan-2.6.20dr2/OBJ.linux.i386' make[1]: *** [install] Error 2 make[1]: Leaving directory `/usr/src/openswan-2.6.20dr2' make: *** [/usr/src/log_i486/03_ipcop/openswan-2.6.20dr2] Error 2 Olaf -- A weizen a day helps keep the doctor away. |
|
From: Dressel, T <TDR...@rt...> - 2008-12-05 16:57:04
|
Manuel, I'm running what you are proposing, minus update accelerator and BOT (I did run BOT, but found it more annoying than helpful for a small network, and I run WSUS in house so I don't need update accelerator). It replaced a commercial firewall which was 7 years old. I'm running it on a P4 xeon workstation that came out of desktop service,,, 2.4Ghz, 1gig ram, 80gig IDE disk, red, blue, and green interfaces. It has been rock solid since I put it in place over a year ago. I can't say enough good about IPCop and the development team. I have roughly 40 machines behind it connected to a T1. I have roughly a dozen VPN road warriors, and this machine never skips a beat. I've got another spare old desktop sitting by loaded with the bare minimum (port forwarding) ready to drop in should the current box ever die. I am in the process of replacing IPCop though because of a single failing,,, IPCop does not support multi-WAN and I recently put in a satellite link to backup my main DSL line. I have been evaluating PFSense. They have a similar feature set to IPCop, but its a different "class" of product, and not nearly as brain dead to make work effectively. PFSense also has some more enterprise class features out of the box, like failover, sync between two boxes, etc. It also has a nicer interface for routing (in IPCop its iptables entries). I think PFSense is a more feature laden product out of the box, however from what I have seen so far the performance on identical hardware for identical workloads is not as good as IPCop. IPCop also sort of has this idea that having less things strapped onto the box makes it more secure. For sure this is true and the developers seem to know the product inside out and backwards and keep up on security vulnerabilities. If you want to see how dedicated they are, join the developer email list and just watch for a few months. Something gets brought up and they beat it out pretty quickly. They are in the process now of turning 1.9 (or is is 2.0??) into a final release. I expect it to be 6 months though before its production ready. Don't wait for it though, the product out now is incredibly stable. I also think the community support of IPCop tends to be more kind to "newb's". The PFSense community is typical of the elitist open source arrogant crowd who snipe from behind the keyboard with directions of "search the archives" in a condescending manner. PFSense also has some paid support options. IPCop has third party companies who would also provide support, but I think you won't need it. Because PFSense is a much more complex product, I think offering support is required. Bottom line, go forward with IPCop with confidence that your corporate business will be secure and stable. Good luck! Tim ________________________________________ From: manuel mendez [man...@sb...] Sent: Friday, December 05, 2008 7:27 AM To: ipc...@li... Subject: [IPCop-devel] IPCOP Advice Hi all. I use IPCOP for home use but I want to use in the company where I work any one is use IPCOP in corporate company ? I will use IPCOP with advanced proxy Update Accelerator URL filter ZERINA-0.9.5b whit openvpn on the cliens BlockOutTraffic: Thanks for any advice. -- This message was scanned by RTI Mailscanner and is believed to be clean. Click here to report this message as spam.<http://mailscanner/cgi-bin/learn-msg.cgi?id=A80A327FFD.DB829> -- This message was scanned by RTI Mailscanner and is believed to be clean. |
|
From: Sam S. <sn...@la...> - 2008-12-05 16:16:34
|
manuel mendez wrote: > Hi all. > > I use IPCOP for home use but I want to use in the company where I work > any one is use IPCOP in corporate company ? > > I will use IPCOP with > advanced proxy > Update Accelerator > URL filter > ZERINA-0.9.5b whit openvpn on the cliens > BlockOutTraffic: > > > > Thanks for any advice. > > ------------------------------------------------------------------------ > > We use it for a business with ZERINA for VPN and no other add-ons. I have set it up 2 additional boxes, one for a school and one for a church. Both have ZERINA and Cop+ (Dansguardian Filtering) add-ons. Works great. The only feature I wish we had was the ability for load balancing/failover for Red. Sam |
|
From: Héctor S. M. O. <he...@ac...> - 2008-12-05 15:44:14
|
Manuel: It Works great, I have it in my main and branch offices, and at several customer installations, ranging from small office (less 20 computers) to mid scale office (100-150 computers), just take consideration on number of clients to pick cpu power, memory and disk capacity Hector _____ De: manuel mendez [mailto:man...@sb...] Enviado el: Viernes, 05 de Diciembre de 2008 09:28 a.m. Para: ipc...@li... Asunto: [IPCop-devel] IPCOP Advice Hi all. I use IPCOP for home use but I want to use in the company where I work any one is use IPCOP in corporate company ? I will use IPCOP with advanced proxy Update Accelerator URL filter ZERINA-0.9.5b whit openvpn on the cliens BlockOutTraffic: Thanks for any advice. |
|
From: William W. <hes...@em...> - 2008-12-05 15:35:07
|
manuel mendez wrote: > Hi all. > > I use IPCOP for home use but I want to use in the company where I work > any one is use IPCOP in corporate company ? > > I will use IPCOP with > advanced proxy > Update Accelerator > URL filter > ZERINA-0.9.5b whit openvpn on the cliens > BlockOutTraffic: > > > > Thanks for any advice. > > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------------ > SF.Net email is Sponsored by MIX09, March 18-20, 2009 in Las Vegas, Nevada. > The future of the web can't happen without you. Join us at MIX09 to help > pave the way to the Next Web now. Learn more and register at > http://ad.doubleclick.net/clk;208669438;13503038;i?http://2009.visitmix.com/ > ------------------------------------------------------------------------ > > _______________________________________________ > IPCop-devel mailing list > IPC...@li... > https://lists.sourceforge.net/lists/listinfo/ipcop-devel > I have a couple of clients that i have installed it for..it works just fine..:) |
|
From: manuel m. <man...@sb...> - 2008-12-05 15:27:50
|
Hi all. I use IPCOP for home use but I want to use in the company where I work any one is use IPCOP in corporate company ? I will use IPCOP with advanced proxy Update Accelerator URL filter ZERINA-0.9.5b whit openvpn on the cliens BlockOutTraffic: Thanks for any advice. |
|
From: Chris T. <ch...@eq...> - 2008-12-05 13:52:50
|
John Edwards wrote: > On Wed, Dec 03, 2008 at 06:21:10PM +0200, Tapani Tarvainen wrote: >> On Tue, Dec 02, 2008 at 01:05:04PM +0100, Gilles Espinasse (g....@fr...) wrote: >> >>> If you have pcmcia, you have a laptop (at 99.9%). So the machine is unusable >>> (particulary for IPCop) without pcmcia. >> Not necessarily. First, many laptops already have two >> network connections, wired and wlan (and often modem >> as third) and could be usable with IPCop as such >> Second, all (?) laptops have several USB ports >> which can also be used for extra network connections. > > Most USB ethernet adapaters require a 2.6 kernel. > > Which 2.0 will be using, as I understand it. However, I do think that pcmcia can be quite useful.. I for one have an number of laptops with pcmcia support - it's a lot faster than usb1! Chris |
|
From: Tapani T. <ip...@ta...> - 2008-12-05 03:09:30
|
On Wed, Dec 03, 2008 at 04:36:11PM +0000, John Edwards (jo...@co...) wrote: > On Wed, Dec 03, 2008 at 06:21:10PM +0200, Tapani Tarvainen wrote: > > Second, all (?) laptops have several USB ports > > which can also be used for extra network connections. > > Most USB ethernet adapaters require a 2.6 kernel. True, but not all of them - several are listed in current IPCop hardware compatibility list. As usual it's a question of how rare cases are worth supporting. I don't presently have any box where this'd make a difference, nor do I even know of one, so I've no strong feelings either way. -- Tapani Tarvainen |
|
From: John E. <jo...@co...> - 2008-12-03 16:36:18
|
On Wed, Dec 03, 2008 at 06:21:10PM +0200, Tapani Tarvainen wrote: > On Tue, Dec 02, 2008 at 01:05:04PM +0100, Gilles Espinasse (g....@fr...) wrote: > >> If you have pcmcia, you have a laptop (at 99.9%). So the machine is unusable >> (particulary for IPCop) without pcmcia. > > Not necessarily. First, many laptops already have two > network connections, wired and wlan (and often modem > as third) and could be usable with IPCop as such > Second, all (?) laptops have several USB ports > which can also be used for extra network connections. Most USB ethernet adapaters require a 2.6 kernel. -- #---------------------------------------------------------# | John Edwards Email: jo...@co... | #---------------------------------------------------------# |
|
From: Tapani T. <ip...@ta...> - 2008-12-03 16:22:46
|
On Tue, Dec 02, 2008 at 01:05:04PM +0100, Gilles Espinasse (g....@fr...) wrote: > If you have pcmcia, you have a laptop (at 99.9%). So the machine is unusable > (particulary for IPCop) without pcmcia. Not necessarily. First, many laptops already have two network connections, wired and wlan (and often modem as third) and could be usable with IPCop as such Second, all (?) laptops have several USB ports which can also be used for extra network connections. I'm not sure though if laptops generally need pcmcia support anyway (like, are those built-in ports internally pcmcia-like anyway). -- Tapani Tarvainen |
|
From: Gilles E. <g....@fr...> - 2008-12-02 12:05:08
|
Selon John Edwards <jo...@co...>: > On Sat, Nov 01, 2008 at 01:36:19PM +0000, John Edwards wrote: > > The 2.4.37 kernel has been in rc1 state for 2 months, so > > I suspect it may not be in full release soon (some weeks). > > Just to mention that kernel 2.4.37 has been released today: > http://www.kernel.org/ > http://www.kernel.org/pub/linux/kernel/v2.4/?C=M;O=D > > -- Yes I know. I was waiting for that. I had a few contacts with Willy because since the last patch include in 2.4.36.9 change the ABI and so the kernel is binary incompatible with previous 2.4.36 release, so we have to provide both vmlinuz and all modules for 1.4.22 (will be 1.4.22/1.4.23) I will commit my kernel changes and some other changes (particulary the fix for dhcp.cgi slowdown when blue is not enabled but the blues adresses are found in settings). Then I still have to work for snort on 2.0 and on 1.4 sides. I have too some changes to commit on 2.0 side: - enhanced boot messages on /init (should be followed by same changes on rc.sysinit) - nousb support on /init - consequence of acpi=off on /init - maybe add "apm=power-off" with "acpi=off" - probably lazy umount (umount -l) should hide/solve the /dev busy message on halt. As this is a tmfs file, that should not matter. I am not so sure nopcmcia and noscsi flags have a sense on 2.0. If you have pcmcia, you have a laptop (at 99.9%). So the machine is unusable (particulary for IPCop) without pcmcia. So the particular flag does not help that much. For noscsi, it should be now probed cleanly like the other hardwares. We may have a way to not probe/blacklist one/somes modules on boot. That should be enought and may help a day if one of the hardware is a locking source. Gilles |
|
From: John E. <jo...@co...> - 2008-12-02 11:03:27
|
On Sat, Nov 01, 2008 at 01:36:19PM +0000, John Edwards wrote: > The 2.4.37 kernel has been in rc1 state for 2 months, so > I suspect it may not be in full release soon (some weeks). Just to mention that kernel 2.4.37 has been released today: http://www.kernel.org/ http://www.kernel.org/pub/linux/kernel/v2.4/?C=M;O=D -- #---------------------------------------------------------# | John Edwards Email: jo...@co... | #---------------------------------------------------------# |