164020254637_590660007503Marco Nicoloso

 
200022934535_574360007671Pradeep Jindal

 
121923854679_559260007698Hal Moroff
Hi all, I installed the "conntrack" command line tool on a Debian Linux 4.0 (etch) with a default 2.6.17 kernel. When I tried to execute the test script I found in the SVN repository (/net

 
143429484734_590160007923FranxE7ois Barel
Hi. Google for portknocking ! It is a solution for opening ports "at run time" by accessing some, already closed ports, and sending a specific packet type. You can add/delete iptables rul

 
182728834951_542060007851gary douglas
I am trying to patch a recent kernel (2.6.17) but connlimit seems to no longer be in patch-o-matic-ng as of the snapshop 20061110. Any assistance would be appreciated. -- Your life is like a penny

 
188723904876_552460007127Pablo Neira Ayuso
I am able to capture packets via QUEUE, but not ULOG. Ive have these two rules: Chain OUTPUT (policy ACCEPT) target prot opt source destination ULOG 0 -- anywh

 
102622954420_556260007962Mato Vidovic
mael.boutin@xxxxxxxxxxx wrote: You can change them via: - /proc/sys/net/ipv4/netfilter/ip_conntrack_[tcp|udp]_* - conntrack tool/libnetfilter_conntrack library In fact i m tracking ipv6

 
123322574347_591360007729Pascal Hambourg
Hi, I am not sure, but you are probably missing the extra module from patch-o-matic-ng... rel="nofollow" www.netfilter.org/projects/patch-o-matic/pom-extra.html#pom-extra-ROU www.netfilter.or

 
161122834677_534460007026Pablo Neira Ayuso
Hi, INL devel team is proud to announce the availability of pyctd, PYthon Conntrack Daemon. pyctd is a XML-RPC service for monitoring and altering Netfilter connections tracking for network admins.

 
126720094909_521760007660gary douglas
I am trying to patch a recent kernel (2.6.17) but connlimit seems to no longer be in patch-o-matic-ng as of the snapshop 20061110. Any assistance would be appreciated. -- Your life is like a penny

 
106723164049_594460007346Pablo Neira Ayuso
I am able to capture packets via QUEUE, but not ULOG. Ive have these two rules: Chain OUTPUT (policy ACCEPT) target prot opt source destination ULOG 0 -- anywh

 
107028674641_549160007679Mato Vidovic
mael.boutin@xxxxxxxxxxx wrote: You can change them via: - /proc/sys/net/ipv4/netfilter/ip_conntrack_[tcp|udp]_* - conntrack tool/libnetfilter_conntrack library In fact i m tracking ipv6

 
145326624936_580060007785Taylor Grant
Guys, Im looking to see if an IPTables solution exists for NATing DNS responses? I am already using multiple views within Bind to address this and I would like to find a way to alter just the records

 
152921854068_520560007251Pascal Hambourg
Hi, I am not sure, but you are probably missing the extra module from patch-o-matic-ng... rel="nofollow" www.netfilter.org/projects/patch-o-matic/pom-extra.html#pom-extra-ROU www.netfilter.or

 
123227974261_514160007691Pablo Neira Ayuso
Hi, INL devel team is proud to announce the availability of pyctd, PYthon Conntrack Daemon. pyctd is a XML-RPC service for monitoring and altering Netfilter connections tracking for network admins.

 
180120814006_585160007847Jasbir Khehra

 
119620954713_583760007141Taylor Grant
Guys, Im looking to see if an IPTables solution exists for NATing DNS responses? I am already using multiple views within Bind to address this and I would like to find a way to alter just the records

 
151520404804_545160007377Satvika Bejai

 
123623684562_530460007091Jasbir Khehra

 
155528064889_581760007903Bo Yang
Ive just been introduced to netfilter. I would like to know if it is possible to configure the firewall rules from a text file that is written to by some script attached to a website. I am tryi

 
150727474984_551460007008Satvika Bejai

 
136027944104_507360007692Bo Yang
Ive just been introduced to netfilter. I would like to know if it is possible to configure the firewall rules from a text file that is written to by some script attached to a website. I am tryi

 
121421464732_501760007571Rob Sterenborg

 
139528344940_595860007513Rob Sterenborg
I tried this. But whatever patch, i try to apply i get the message "n missing files "(n=1,2,3 etc..) and patch fails. Is it possible to apply only the random patch and skip others. Also w

 
104926934319_593860007265utteerna
utteerna wrote: I want to use the iptables "-m random" option. download linux 2.6.18 & iptables 1.3.6, it is called "statistic match".

 
184020164012_582460007610utteerna
utteerna wrote: I tried the following 1) Took 2.6.18.2 kernel source - Compiled it with "statistic match" option on 2) Then compiled iptables 1.3.6 and installed it But sti

 
183228914404_593760007034utteerna
utteerna wrote: 3)Downloaded patch-o-matic-ng-20061108.tar and put it in /usr/src dir and untarred it You dont need POM. ---QUESTION-- Do i have to compile them in to the kernel rather tha

 
162921784180_536060007778Ury Segal
On Friday 10 November 2006 08:38, utteerna wrote: Heres steps i followed and error details. Please let me know if i missed something Are you running Debian or a Debian derivative? 1)Downloa

 
193225924612_587260007749Justin Schoeman
Hallo! Ich suche nach einer Möglichkeit ein externes Programm bei einem match einer Regel auszuführen. Beispiel: iptables ... -j exec("/usr/bin/beep -f 5000 -l 1000") -------

 
138426004442_570360007952Pablo Neira Ayuso
On Tue, 07 Nov 2006 08:51:50 +0200, Justin wrote in message <45502D05.1050807@xxxxxxxxxxxxxxx : Erik Alberti wrote: Hallo! Ich suche nach einer Möglichkeit ein externes Progr

 
196923774969_598160007499willutellmemore will
Every time I try to login to bugzilla, I get error messages from DBI rel="nofollow" bugzilla.netfilter.org/bugzilla/query.cgi?GoAheadAndLogIn=1 bugzilla.netfilter.org/bugzilla/query.cgi?GoAhea

 
159120324389_599560007354Rob Sterenborg
Hi: My network is like this: A(IP:192.168.0.2) B(IP: 192.168.0.1)(IP:192.168.1.2) C(IP:192.168.1.1) (netmask:255.255.255.0) 255.255.255.0 255.255.255.0 255.255.255.

 
102925974533_521060007729Lawrence Daltron

 
198928904321_560060007872woger151
http tunneling? Watch you squid logs. Regards, Steffen I dont understand what you mean, please explain in less technical words Teddy L. --------------------------------------------

 
134921444471_579260007007lubasi
-----Original Message----- From: netfilter-bounces@xxxxxxxxxxxxxxxxxxx [ rel="nofollow" mailto:netfilter-bounces@xxxxxxxxxxxxxxxxxxx mailto:netfilter-bounces@xxxxxxxxxxxxxxxxxxx ] On Beh

 
174328164385_571160007585Jasbir Khehra
Hi I have setup rules on my iptables and when i block yahoo, only those using gaim IM client using yahoo are blocked but the native yahoo IM client is passing through my firewall. Whats w

 
120923884617_559960007586lee nookx

 
195324124183_548560007140Scott van Looy
<citaat van="lee nookx" Hi, I am trying to find a way of transparently intercepting packets flowing across my network, so that I can transform them for use in another applicat

 
121426114029_553660007790Monty Ree

 
140725614935_587960007783Monty Ree

 
188720944599_527160007395Alan Ezust
Im trying to get conntrack -E to show me events, with conntrack IDs. At the moment, the ctid is now showing up in the output unless there is an [UNREPLIED] part to the line. $ conntrack -E -i connt

 
185620154784_547360007166Alan Ezust
Im trying to get conntrack -E to show me events, with conntrack IDs. At the moment, the ctid is now showing up in the output unless there is an [UNREPLIED] part to the line. $ conntrack -E -i connt

 
105825674579_524160007202Alan Ezust
Alan Ezust wrote: Is there a trick to getting the ctids to be sent to the output of this? There is not. conntrack -L -i seems to work, showing me the id. Personally, I think conntrack shou

 
138122674813_541160007024Alan Ezust
Alan Ezust wrote: Is there a trick to getting the ctids to be sent to the output of this? There is not. conntrack -L -i seems to work, showing me the id. Personally, I think conntrack shou

 
120122104585_513560007937Alan Ezust

 
191829764031_551660007838Alan Ezust

 
191221024853_569660007467Alan Ezust
Alan Ezust wrote: Thanks for the reply. Ok, I can see how I can generate some IDs, but I first want to make sure i have all of the information I need. When I run conntrack, I only see one p

 
186326334034_544260007087Alan Ezust
Alan Ezust wrote: Thanks for the reply. Ok, I can see how I can generate some IDs, but I first want to make sure i have all of the information I need. When I run conntrack, I only see one p

 
164422554354_545760007157Eric Leblond
Greetings, I have an unusual (maybe?) request. I have several private IPs (192.168.x.x) behind a Linux gateway. All are NATed to the Internet. Now I want to explicitely map each private IP to a fi

 
148128684367_506560007456Eric Leblond
Greetings, I have an unusual (maybe?) request. I have several private IPs (192.168.x.x) behind a Linux gateway. All are NATed to the Internet. Now I want to explicitely map each private IP to a fi