You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(259) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(361) |
Feb
(71) |
Mar
(270) |
Apr
(164) |
May
(55) |
Jun
(218) |
Jul
(203) |
Aug
(146) |
Sep
(105) |
Oct
(70) |
Nov
(156) |
Dec
(223) |
| 2003 |
Jan
(229) |
Feb
(126) |
Mar
(461) |
Apr
(288) |
May
(203) |
Jun
(64) |
Jul
(97) |
Aug
(228) |
Sep
(384) |
Oct
(208) |
Nov
(88) |
Dec
(291) |
| 2004 |
Jan
(425) |
Feb
(382) |
Mar
(457) |
Apr
(300) |
May
(323) |
Jun
(326) |
Jul
(487) |
Aug
(458) |
Sep
(636) |
Oct
(429) |
Nov
(174) |
Dec
(288) |
| 2005 |
Jan
(242) |
Feb
(148) |
Mar
(146) |
Apr
(148) |
May
(200) |
Jun
(134) |
Jul
(120) |
Aug
(183) |
Sep
(163) |
Oct
(253) |
Nov
(248) |
Dec
(63) |
| 2006 |
Jan
(96) |
Feb
(65) |
Mar
(88) |
Apr
(172) |
May
(122) |
Jun
(111) |
Jul
(83) |
Aug
(210) |
Sep
(102) |
Oct
(37) |
Nov
(28) |
Dec
(41) |
| 2007 |
Jan
(82) |
Feb
(84) |
Mar
(218) |
Apr
(61) |
May
(66) |
Jun
(35) |
Jul
(55) |
Aug
(64) |
Sep
(20) |
Oct
(92) |
Nov
(420) |
Dec
(399) |
| 2008 |
Jan
(149) |
Feb
(72) |
Mar
(209) |
Apr
(155) |
May
(77) |
Jun
(150) |
Jul
(142) |
Aug
(99) |
Sep
(78) |
Oct
(98) |
Nov
(82) |
Dec
(25) |
| 2009 |
Jan
(38) |
Feb
(86) |
Mar
(129) |
Apr
(64) |
May
(106) |
Jun
(121) |
Jul
(149) |
Aug
(110) |
Sep
(74) |
Oct
(98) |
Nov
(83) |
Dec
(46) |
| 2010 |
Jan
(53) |
Feb
(43) |
Mar
(86) |
Apr
(185) |
May
(44) |
Jun
(58) |
Jul
(41) |
Aug
(47) |
Sep
(52) |
Oct
(49) |
Nov
(47) |
Dec
(66) |
| 2011 |
Jan
(58) |
Feb
(33) |
Mar
(37) |
Apr
(31) |
May
(8) |
Jun
(8) |
Jul
(2) |
Aug
(28) |
Sep
(75) |
Oct
(46) |
Nov
(40) |
Dec
(7) |
| 2012 |
Jan
(61) |
Feb
(32) |
Mar
(20) |
Apr
(6) |
May
(11) |
Jun
(8) |
Jul
(1) |
Aug
(16) |
Sep
(21) |
Oct
(12) |
Nov
(12) |
Dec
(1) |
| 2013 |
Jan
(15) |
Feb
(8) |
Mar
(21) |
Apr
(25) |
May
(18) |
Jun
(20) |
Jul
(21) |
Aug
|
Sep
(1) |
Oct
(9) |
Nov
(10) |
Dec
(13) |
| 2014 |
Jan
(33) |
Feb
(41) |
Mar
(10) |
Apr
(44) |
May
(3) |
Jun
|
Jul
(6) |
Aug
(2) |
Sep
(1) |
Oct
(7) |
Nov
(10) |
Dec
(12) |
| 2015 |
Jan
(1) |
Feb
(17) |
Mar
(8) |
Apr
|
May
|
Jun
|
Jul
|
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
(1) |
| 2016 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
(2) |
Nov
|
Dec
|
| 2017 |
Jan
|
Feb
(1) |
Mar
(1) |
Apr
|
May
|
Jun
(2) |
Jul
(5) |
Aug
|
Sep
(1) |
Oct
(2) |
Nov
|
Dec
|
| 2018 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
|
Dec
|
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
|
|
|
|
1
(6) |
2
(2) |
3
(5) |
4
(1) |
|
5
|
6
|
7
(1) |
8
|
9
(1) |
10
(5) |
11
(15) |
|
12
(5) |
13
(2) |
14
(2) |
15
(1) |
16
(2) |
17
(17) |
18
(4) |
|
19
(8) |
20
(4) |
21
(18) |
22
(10) |
23
(2) |
24
(7) |
25
(20) |
|
26
(1) |
27
(4) |
28
|
29
(5) |
30
(1) |
31
|
|
|
From: SourceForge.net <no...@so...> - 2009-07-30 21:03:32
|
Bugs item #2829906, was opened at 2009-07-31 00:03 Message generated for change (Tracker Item Submitted) made by mguvenc You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2829906&group_id=40604 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: Build Group: V2 alpha Status: Open Resolution: None Priority: 5 Private: No Submitted By: Mustafa (mguvenc) Assigned to: Nobody/Anonymous (nobody) Summary: on libc 2.9 installed systems build fails Initial Comment: on libc 2.9 installed systems, version check while building toolchain fails. because the following command; check_version "GNU libc" ${REQUIRED_GLIBC} `/lib/libc.so.6* | head -n1 | cut -d" " -f7 | cut -d"," -f1` should be check_version "GNU libc" ${REQUIRED_GLIBC} `/lib/libc.so.6* | head -n1 | cut -d" " -f8 | cut -d"," -f1` ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2829906&group_id=40604 |
|
From: Olaf W. <wei...@ip...> - 2009-07-29 19:43:49
|
Eric Oberlander wrote: > On the Interfaces page, should it be possible to include a hyphen (-) > in the interface name, or are they reserved for IPCop interface names. > At the moment you are limited to A-Z a-z0-9 and a colon (:). We should allow that. No reason to be overly restrictive. Olaf -- A weizen a day helps keep the doctor away. |
|
From: Eric O. <eri...@gm...> - 2009-07-29 18:13:55
|
2009/7/27 Olaf Westrik <wei...@ip...>: > Hi Eric, > > > Addresses, Address Groups and Interfaces > > > 2.6.6. Addresses Administrative Web Page > > You can assign names to IP Addresses, IP Networks and MAC Addresses. The > advantage of using names is that when you have to change an internal Servers > IP Address or exchange a network card (different MAC), there is only 1 place > that needs modification and you do not have to change multiple outgoing > rules, pinholes and portforwards. > > Note: MAC Addresses can only be used as source in rules, not as destination. > > Note: if the mask is left empty when defining an IP Address, the mask > 255.255.255.255 will be used. > > > 2.6.7. Address Groups Administrative Web Page > > Default addresses (i.e. Green Network, Blue Network, etc.) and addressnames > can be combined to groups. > In an address Group you could combine Green and Blue Network and then allow > a specific service for this group with 1 rule. > > (screenshot showing GreenBlue as Address Group name and Green Network+Blue > Network added). > > You can also combine Address names (link to 2.6.6) into a group. For example > if you have multiple computers in Blue, but only want to create a pinhole > for 2 specific laptops. > > > Note: groups can not be used as destination in a portforward. > > > 2.6.8. Interfaces Administrative Web Page > > There are special cases where interfaces are present beyond the standard > Green, Blue, Orange, Red interfaces. After assigning a name to such an > interface it is possible to create firewall rules for those interfaces. > > Note: you will still need to assign drivers and IP addresses manually. Thanks for your primer, you will have seen the Work in Progress online. I like dotzball's improvements to the radio buttons on the Groups pages. Works much better. Thanks Achim. On the Interfaces page, should it be possible to include a hyphen (-) in the interface name, or are they reserved for IPCop interface names. At the moment you are limited to A-Z a-z0-9 and a colon (:). Eric |
|
From: SourceForge.net <no...@so...> - 2009-07-29 02:43:44
|
Bugs item #2828759, was opened at 2009-07-29 06:43 Message generated for change (Tracker Item Submitted) made by azlk You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2828759&group_id=40604 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: General Group: V2 alpha Status: Open Resolution: None Priority: 5 Private: No Submitted By: azlk (azlk) Assigned to: Nobody/Anonymous (nobody) Summary: System hangs on boot Initial Comment: Pentium-3 with 384 MB RAM, 40Gb IDE HDD and CDROM. Not every time but unpredictable. I've tested my memory and all other hw - everything is OK. I can't post any logs as there are no any if system doesn't start, but...for comparison: other Linux systems (Puppy, Ubuntu, Fedora) NEVER hang on thic PC, IpFIRE boots every time without hassle :-( Maybe GRUB problems? ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2828759&group_id=40604 |
|
From: SourceForge.net <no...@so...> - 2009-07-29 02:36:41
|
Bugs item #2828751, was opened at 2009-07-29 06:36 Message generated for change (Tracker Item Submitted) made by azlk You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2828751&group_id=40604 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: General Group: V2 alpha Status: Open Resolution: None Priority: 5 Private: No Submitted By: azlk (azlk) Assigned to: Nobody/Anonymous (nobody) Summary: IpCOP unpredictable deny access to system Initial Comment: Simultaneously web-interface and ssh session dies. No ping also. It is completely unpredictable: it can die in process of copying files to IPCOP box or without any interference. By the way SFTP with Filezilla really result in denying access very often, especially when copying many files. For reference - fresh install of IpFIRE never hangs not ssh nor web-interface. Unfortunately seems that version 1.96 is quite crude... ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2828751&group_id=40604 |
|
From: SourceForge.net <no...@so...> - 2009-07-29 02:22:49
|
Bugs item #2828746, was opened at 2009-07-29 06:22 Message generated for change (Tracker Item Submitted) made by azlk You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2828746&group_id=40604 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: VPN Group: V2 alpha Status: Open Resolution: None Priority: 5 Private: No Submitted By: azlk (azlk) Assigned to: Nobody/Anonymous (nobody) Summary: VPN PPTP is not working Initial Comment: We have a very big provider Beeline (former Corbina) here in Russia. They give access to external net (Internet) ONLY over Micro$oft-way VPN-PPTP: all I have is gateway address (smth like 10.177.48.10), name of a bunch of their vpn servers - "vpn.internet.beeline.ru", user name and password. With every connect this "vpn.internet.beeline.ru" returns a new IP, there are 10-15 servers and they dynamically change with every connect. So if I setup RED interface as PPTP it simply doesn't work: "Connecting......Idle". (Additional PPTP settings: ->DHCP; Hostname: vpn.internet.beeline.ru; User Name, Password; Method: PAP or CHAP; DNS: Automatic) And this is not something unexpected - PPTP setup even doesn't have needed fields to connect, but rather have other not unclear fields like "Additional PPTP settings -> Phonebook entry". I'm afraid this PPTP setup is really for PPOE and not actually PPTP VPN, is it?.. If I use DHCP on RED interface it shows right gw and IP but this way I cannot use PPTP from existing menu. Also, there is a big local net in Beeline, which is accessible only with additional routes. There are no fields in design to write these routes too. At the same time D-Link 524 makes this painlessly: I simply type server address (vpn.internet.beeline.ru), user name, password and that's all - connection is on. And there is a page where one can write additional routes. Is there any hope that IpCOP will ever have this ugly but unfortunately the one possible for us micro$oft VPN PPTP working?.... I tried PPTP addon from ftp.shauff.de but it it was designed for previous IpCOP (1.14 and so) and it cannot be even installed. Also I was very dissapointed not being able to find MC for IpCOP 1.96, without MC it becomes a real trouble to make a lot of search, edit and digger's work :-( When I tried to install toolchain to compile MC by myself, I discovered that toolchain contains other version of binutils (older than existing in ISO) so I couldn't install it, moreover - directory tree in toolchain differ from original on fresh install.... ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=428516&aid=2828746&group_id=40604 |
|
From: Olaf W. <wei...@ip...> - 2009-07-27 15:43:56
|
Martin Dubreuil wrote: > Just wondering if we will be able to setup Multiple WAN interfaces as RED > without diving into the manual file modification and scripting in 2.0 No. Olaf -- A weizen a day helps keep the doctor away. |
|
From: Martin D. <Mar...@ne...> - 2009-07-27 15:20:46
|
Hello busy Dev's, Just wondering if we will be able to setup Multiple WAN interfaces as RED without diving into the manual file modification and scripting in 2.0 Dual WAN + Load Balancing would be a great asset. Thanks Martin |
|
From: Olaf W. <wei...@ip...> - 2009-07-27 12:35:31
|
Hi Eric, Addresses, Address Groups and Interfaces 2.6.6. Addresses Administrative Web Page You can assign names to IP Addresses, IP Networks and MAC Addresses. The advantage of using names is that when you have to change an internal Servers IP Address or exchange a network card (different MAC), there is only 1 place that needs modification and you do not have to change multiple outgoing rules, pinholes and portforwards. Note: MAC Addresses can only be used as source in rules, not as destination. Note: if the mask is left empty when defining an IP Address, the mask 255.255.255.255 will be used. 2.6.7. Address Groups Administrative Web Page Default addresses (i.e. Green Network, Blue Network, etc.) and addressnames can be combined to groups. In an address Group you could combine Green and Blue Network and then allow a specific service for this group with 1 rule. (screenshot showing GreenBlue as Address Group name and Green Network+Blue Network added). You can also combine Address names (link to 2.6.6) into a group. For example if you have multiple computers in Blue, but only want to create a pinhole for 2 specific laptops. Note: groups can not be used as destination in a portforward. 2.6.8. Interfaces Administrative Web Page There are special cases where interfaces are present beyond the standard Green, Blue, Orange, Red interfaces. After assigning a name to such an interface it is possible to create firewall rules for those interfaces. Note: you will still need to assign drivers and IP addresses manually. Olaf -- A weizen a day helps keep the doctor away. |
|
From: Eric O. <eri...@gm...> - 2009-07-27 10:51:38
|
2009/7/25 David W Studeman <avi...@ai...>: > Eric Oberlander wrote: >> How much RAM do have in your machines? >> > > 1GB OK, I've tested snort-2.8 on 1.4.23. Update rules won't work with 128Mb of RAM, or 196Mb of RAM. It does work with 256Mb of RAM (I turned off snort while downloading the update to save memory). Gilles, have you decided which update to include snort in, 1.4.22 or 1.4.23? Eric |
|
From: Olaf W. <wei...@ip...> - 2009-07-26 06:54:13
|
Hi Gilles, > I need now to clean my changes and update to a current tree. > I will not be able to test my changes on different distrib before some days. feel free to commit your changes. So you can distribute the testing load ;-) Olaf -- A weizen a day helps keep the doctor away. |
|
From: Gilles E. <g....@fr...> - 2009-07-25 21:46:26
|
I have found my mistake in the cross-compilation changes. That was simply a missing / before $(TOOL_DIR) in a sed inside lfs/gcc. Not knowing that, I was already decided to include the / in TOOL_DIR as this is more cleaner. That would disallow my mistake but is intrusive as TOOL_DIR is present in many lfs files. I need now to clean my changes and update to a current tree. I will not be able to test my changes on different distrib before some days. Gilles |
|
From: Olaf W. <wei...@ip...> - 2009-07-25 20:27:19
|
Eric Oberlander wrote: > 2009/7/25 Olaf Westrik <wei...@ip...>: >> Eric Oberlander wrote: >> >>> What's the 'ICMP Type' dropdown for? >> ICMP is kinda special, as it does not have ports but types. >> Providing them as an option gives you the possibility to only allow the >> 'normal' ones, like ping and pong and blocking the obscure ones. >> >> >>> Visually, can the ICMP Type dropdown be moved left on the screen, as >>> it's making the screenshot wider than 704. (I know, picky picky picky) >> How about moving the Service Name to a separate line. And then have this >> arrangement ? >> >> Service Name >> Ports Protocol >> ICMP Types > > The first version, I think.. I've done and committed slightly different. More 'IPCop Style' IMHO. Does not look ideal, but I think it is the best we can do. >>>> 2.6.5. Service Groups Administrative Web Page >>>> >>>> The IPCop Firewall is configured by using Services and/or Service Groups. >>>> Service Groups give you the possibility to combine several Services into >>>> a >>>> Group. After which you can create rule(s) which then combine all Services >>>> in >>>> a single step. >>>> >>>> A typical example is to create a DropNoLog Group which then holds those >>>> Services that you know about and do not want to fill up your Firewall >>>> log. >>> The 'Add service to Group' section is also cramped for width. Can the >>> the Remark field be made narrower? >> Certainly. No reason to use fixed view size. >> >> >>> Why are there radio buttons I can't select? >> Probably easier to code ;-) >> IIRC removing the radiobutton requires to have hidden <input type='hidden' >> etc. > lines instead, to make sure CGI parameters are present. >> >> If this is a big issue I can look into it. > > It's no deal breaker. > I was just curious. > Perhaps it becomes obvious when the section is populated with more information? Yes, just add a Custom Service and then create a Service Group and populate it. For the Manual we could populate a DropNoLog Group with netbios-dgm (tcp+udp/138) and netbios-ns (tcp+udp/137) and make a screenshot. That is a pretty common case if you have (talkative) Windows Clients in Green, have Logging enabled on Green and don't want if filled with Netbios Broadcasts. Olaf -- A weizen a day helps keep the doctor away. |
|
From: David W S. <avi...@ai...> - 2009-07-25 20:14:42
|
Eric Oberlander wrote: > How much RAM do have in your machines? > > Eric > > ------------------------------------------------------------------------------ 1GB -- Dave Studeman http://www.raqcop.com |
|
From: Eric O. <eri...@gm...> - 2009-07-25 19:50:16
|
2009/7/25 Olaf Westrik <wei...@ip...>: > Eric Oberlander wrote: > >> What's the 'ICMP Type' dropdown for? > > ICMP is kinda special, as it does not have ports but types. > Providing them as an option gives you the possibility to only allow the > 'normal' ones, like ping and pong and blocking the obscure ones. > > >> Visually, can the ICMP Type dropdown be moved left on the screen, as >> it's making the screenshot wider than 704. (I know, picky picky picky) > > How about moving the Service Name to a separate line. And then have this > arrangement ? > > Service Name > Ports Protocol > ICMP Types The first version, I think.. > or: > Service Name > Protocol Ports > ICMP Types > > >>> 2.6.5. Service Groups Administrative Web Page >>> >>> The IPCop Firewall is configured by using Services and/or Service Groups. >>> Service Groups give you the possibility to combine several Services into >>> a >>> Group. After which you can create rule(s) which then combine all Services >>> in >>> a single step. >>> >>> A typical example is to create a DropNoLog Group which then holds those >>> Services that you know about and do not want to fill up your Firewall >>> log. >> >> The 'Add service to Group' section is also cramped for width. Can the >> the Remark field be made narrower? > > Certainly. No reason to use fixed view size. > > >> Why are there radio buttons I can't select? > > Probably easier to code ;-) > IIRC removing the radiobutton requires to have hidden <input type='hidden' > etc. > lines instead, to make sure CGI parameters are present. > > If this is a big issue I can look into it. It's no deal breaker. I was just curious. Perhaps it becomes obvious when the section is populated with more information? Eric |
|
From: Eric O. <eri...@gm...> - 2009-07-25 19:06:43
|
How much RAM do have in your machines? Eric |
|
From: David W S. <avi...@ai...> - 2009-07-25 15:43:01
|
Guenter wrote: > David W Studeman schrieb: >> Hello all. I built a current cvs version of 1.4.23 and so far I have >> been able to download current rules and apply them as well as get snort >> to start upon applying the downloaded rules, beyond that we'll see. >> >> Now to the point of this post. The issue with flash installs that >> still lingers is that the rules download tarball stays in /var/log/snort >> which we know is really in /ram/var/log/snort and the rules tarball is >> now 86MB in size with 2.8. This ends up being compressed into the >> tarball in /var/log_compressed which is a 30MB partition. Unless one >> knows to manually delete the download, problems will ensue at the next >> cron which uses rc.flash.down to compress the logs. > exactly what I said with my post already: the downloaded tarball is not > deleted; > and IIRC it was even duplicated = one original download in /tmp and then > a copy in var/log/snort ... > > Günter. > > > > ------------------------------------------------------------------------------ I guess if I would have read the whole thread I would have seen that. If the file always has the same name, another exclusion argument in rc.flash.down should work. -- Dave Studeman http://www.raqcop.com |
|
From: Guenter <li...@gk...> - 2009-07-25 15:30:01
|
David W Studeman schrieb: > Hello all. I built a current cvs version of 1.4.23 and so far I have > been able to download current rules and apply them as well as get snort > to start upon applying the downloaded rules, beyond that we'll see. > > Now to the point of this post. The issue with flash installs that > still lingers is that the rules download tarball stays in /var/log/snort > which we know is really in /ram/var/log/snort and the rules tarball is > now 86MB in size with 2.8. This ends up being compressed into the > tarball in /var/log_compressed which is a 30MB partition. Unless one > knows to manually delete the download, problems will ensue at the next > cron which uses rc.flash.down to compress the logs. exactly what I said with my post already: the downloaded tarball is not deleted; and IIRC it was even duplicated = one original download in /tmp and then a copy in var/log/snort ... Günter. |
|
From: Olaf W. <wei...@ip...> - 2009-07-25 15:07:54
|
Hi Dave, > In the warning before formatting and installing 1.9.6, the warning > uses the word loose rather than lose. Nothing major. Thanks for bringing it up, already changed a few days ago though ;-) SVN is moving fast these days :-) Olaf -- A weizen a day helps keep the doctor away. |
|
From: David W S. <avi...@ai...> - 2009-07-25 14:48:00
|
In the warning before formatting and installing 1.9.6, the warning uses the word loose rather than lose. Nothing major. -- Dave Studeman http://www.raqcop.com |
|
From: David W S. <avi...@ai...> - 2009-07-25 14:40:33
|
Hello all. I built a current cvs version of 1.4.23 and so far I have been able to download current rules and apply them as well as get snort to start upon applying the downloaded rules, beyond that we'll see. Now to the point of this post. The issue with flash installs that still lingers is that the rules download tarball stays in /var/log/snort which we know is really in /ram/var/log/snort and the rules tarball is now 86MB in size with 2.8. This ends up being compressed into the tarball in /var/log_compressed which is a 30MB partition. Unless one knows to manually delete the download, problems will ensue at the next cron which uses rc.flash.down to compress the logs. -- Dave Studeman http://www.raqcop.com |
|
From: Olaf W. <wei...@ip...> - 2009-07-25 14:38:23
|
Eric Oberlander wrote:
> What's the 'ICMP Type' dropdown for?
ICMP is kinda special, as it does not have ports but types.
Providing them as an option gives you the possibility to only allow the
'normal' ones, like ping and pong and blocking the obscure ones.
> Visually, can the ICMP Type dropdown be moved left on the screen, as
> it's making the screenshot wider than 704. (I know, picky picky picky)
How about moving the Service Name to a separate line. And then have this
arrangement ?
Service Name
Ports Protocol
ICMP Types
or:
Service Name
Protocol Ports
ICMP Types
>> 2.6.5. Service Groups Administrative Web Page
>>
>> The IPCop Firewall is configured by using Services and/or Service Groups.
>> Service Groups give you the possibility to combine several Services into a
>> Group. After which you can create rule(s) which then combine all Services in
>> a single step.
>>
>> A typical example is to create a DropNoLog Group which then holds those
>> Services that you know about and do not want to fill up your Firewall log.
>
> The 'Add service to Group' section is also cramped for width. Can the
> the Remark field be made narrower?
Certainly. No reason to use fixed view size.
> Why are there radio buttons I can't select?
Probably easier to code ;-)
IIRC removing the radiobutton requires to have hidden <input
type='hidden' etc. > lines instead, to make sure CGI parameters are present.
If this is a big issue I can look into it.
Olaf
--
A weizen a day helps keep the doctor away.
|
|
From: Olaf W. <wei...@ip...> - 2009-07-25 14:21:31
|
Ouch. Sorry this commit also pulled in changes to the startup and shutdown beeps I had in my tree. Did not mean to hide these and wanted to send them separate. > Modified: ipcop/trunk/src/rc.d/rc.halt > =================================================================== > --- ipcop/trunk/src/rc.d/rc.halt 2009-07-25 12:04:34 UTC (rev 3322) > +++ ipcop/trunk/src/rc.d/rc.halt 2009-07-25 14:15:28 UTC (rev 3323) > @@ -137,10 +137,7 @@ > > # Send nice shutdown beep now > if [ "$IPCOPUPDOWNBEEP" = "on" ]; then > - /usr/bin/beep -l 75 -f 3000 > - /usr/bin/beep -l 75 -f 2000 > - /usr/bin/beep -l 75 -f 1000 > - /usr/bin/beep -l 75 -f 500 > + /usr/bin/beep -l 250 -f 514 -n -l 250 -f 343 -n -l 250 -f 686 -n -l 250 -f 864 -n -l 500 -f 770 > fi > > if [ "$1" = "halt" ]; then > > Modified: ipcop/trunk/src/rc.d/rc.sysinit > =================================================================== > --- ipcop/trunk/src/rc.d/rc.sysinit 2009-07-25 12:04:34 UTC (rev 3322) > +++ ipcop/trunk/src/rc.d/rc.sysinit 2009-07-25 14:15:28 UTC (rev 3323) > @@ -398,8 +398,5 @@ > > # Send nice startup beep now > if [ "$IPCOPUPDOWNBEEP" = "on" ]; then > - /usr/bin/beep -l 75 -f 500 > - /usr/bin/beep -l 75 -f 1000 > - /usr/bin/beep -l 75 -f 2000 > - /usr/bin/beep -l 75 -f 3000 > + /usr/bin/beep -l 250 -f 770 -n -l 250 -f 864 -n -l 250 -f 686 -n -l 250 -f 343 -n -l 500 -f 514 > fi > > -- A weizen a day helps keep the doctor away. |
|
From: Eric O. <eri...@gm...> - 2009-07-25 12:42:31
|
> 2.6.4. Services Administrative Web Page > > > The IPCop Firewall is configured by using Services and/or Service Groups. If > you want to create a rule for a Service that is not present in the list of > Default Services, you will have to add it first. > > Give the custom Service a descriptive name, choose the Ports (TCP and UDP > only) and Protocol. > > Note: Use the Invert option with great care, as this can create far larger > holes in your IPCop Firewall than you might expect! What's the 'ICMP Type' dropdown for? Visually, can the ICMP Type dropdown be moved left on the screen, as it's making the screenshot wider than 704. (I know, picky picky picky) > 2.6.5. Service Groups Administrative Web Page > > The IPCop Firewall is configured by using Services and/or Service Groups. > Service Groups give you the possibility to combine several Services into a > Group. After which you can create rule(s) which then combine all Services in > a single step. > > A typical example is to create a DropNoLog Group which then holds those > Services that you know about and do not want to fill up your Firewall log. The 'Add service to Group' section is also cramped for width. Can the the Remark field be made narrower? Why are there radio buttons I can't select? Eric |
|
From: Olaf W. <wei...@ip...> - 2009-07-25 10:29:59
|
Hi Eric, (small) explanation about Services / Service Groups. Please apply grammar, textual modifications where required ;-) 2.6.4. Services Administrative Web Page The IPCop Firewall is configured by using Services and/or Service Groups. If you want to create a rule for a Service that is not present in the list of Default Services, you will have to add it first. Give the custom Service a descriptive name, choose the Ports (TCP and UDP only) and Protocol. Note: Use the Invert option with great care, as this can create far larger holes in your IPCop Firewall than you might expect! 2.6.5. Service Groups Administrative Web Page The IPCop Firewall is configured by using Services and/or Service Groups. Service Groups give you the possibility to combine several Services into a Group. After which you can create rule(s) which then combine all Services in a single step. A typical example is to create a DropNoLog Group which then holds those Services that you know about and do not want to fill up your Firewall log. Olaf -- A weizen a day helps keep the doctor away. |