Jump to content

Admiral Ross

Experienced Members
  • Posts

    215
  • Joined

  • Last visited

Posts posted by Admiral Ross

  1. You can read more about iptables in the manual page by typing "man iptables" in the shell.

     

    http://en.wikipedia.org/wiki/Netfilter/iptables

    http://www.netfilter.org/documentation/

     

    There are documentations, guides, how-to, scripts, etc.

     

    I like to write the configuration scripts by hand, because it gives me alot of flexibility, freedom and control to configure it in every aspect exactly as I want it to behave. I drop all packets except those which I allow.

    I haven't used it for routing though, I've only used it for firewalling.

    It was love at first eye-sight, I immediately fell in love with it! :D

     

    Pretty impressive links! There is a whole lot of info in there that would take me at least a month to digust! As for playing with iptables I'd have to make a TEST subnet so that my PRODUCTION subnet won't get damaged. BTW Wikipedia is awesome! Thanks for the links too.

  2. Ok a simple question. I have a vague memory of reading that there is a performance gain to be had by running your computer in 16 bit colour mode instead of 32 bit, is there anything in this? i know there is supposed to be a performance gain using 16bit for gaming but what about everyday use?

     

    If memory serves me correct. 16 bit mode uses less video memory then 32 bit mode. But, todays video cards come packed with memory. Then again all of that will change when Windows Vista comes out.

     

    Cheers,

  3. If you haven't formatted as yet you could try to boot from a Win98 boot floppy.

     

    At the A:/ prompt type "fdisk /mbr" - enter, then see if it will boot from C.

     

    Space between fdisk and /mbr

     

    thanks, It wasn't having a problem booting. It would stuck at the xp boot screen. It was trying to make a transition from xp boot screen to the desktop. It was in the process of starting the os.

     

    Cheers,

  4. Hello All?

     

    For the past week, I've been constructing an xp custom cd with nLite. The ISO burned fine and I installed it in VM it worked fine. When I tested it out on my system it hung at the xp start screen. It just sat there with the blue boxes stuck on the right side. I was able to get into safe mode, but I couldn't find the root of the problem. Sent many hours working on the ISO making sure I got everything. Even the SATA drivers installed correctly in the TXTsetup mode.

     

    Why am I doing all of this? First off you get a machine from an OEM, it comes preloaded with factory BLOATWARE! I HATE the factory cd that I have. So, I wanted to create a nice sleek unattended xp sp2 9/06 updated security patched + tweaked cd. All that unnessary bs just eats precious resources and hard drive space that you desprately need. My system, I even have all of the themes and eye candy turned off. Classic explorer, searches.

     

    Cheers,

  5. I am pretty sure you could have different sets of rules for different IP addresses and be able to have some computers protected while the servers have some ports open.

     

    iptables is crazy awesome.

     

    What you are describing is called a pinhole, if I'm not mistaken. All of those devices would be on different subnets. I'd have to agree, iptables is awesome! Unfortuanitly, I'm not too savvy on configuring iptables from scratch/by hand.

     

    Cheers,

  6. IRC is old school, but its still alive and kicking!

     

    What if you put webserver on the LAN, then you could live with only 3 ports, not 4. You could even put the Wi-Fi on the LAN too, then live with only 2 ports.

     

    Though you were only using firewall, then a 486 would be adequate. Didn't know you intended to run Squid, Dansguardian, POP, SMTP proxying and HTTP/FTP virus scanning.

     

    Moving those objects as you suggested would defeat the purpose of the firewall. The Orange interface is designed for servers that accept incoming connections from the internet. So the Orange serves as the DMZ. As for the Blue it's for WiFi. At currently I have a pretty strong setup. But, what if my Access Point was compromised? The attacker would be locked into the blue (wifi) subnet.

     

    Cheers,

  7. You can get try some help at some Linux-related channel on IRC.

    Freenode (irc.freenode.net) has plenty of Linux-people.

     

    You don't really need quad NIC firewall with 1.2 GHz and 512 mb RAM for a firewall, an old 486 would work just fine. ;)

     

    Wow! I haven't touched IRC in a long time. I used to chat, but not in recent years.

     

    The quad Nic is for the following:

    Nic 1 - Red - Internet

    Nic 2 - Orange - Web Server

    Nic 3 - Blue - Wifi WLAN

    NIc 4 - Green - LAN (Wired)

     

    I rather have all of them in one card then spread across 4 pci slots. As for a 486 I dont know. Why? I'll be running squid, dansguardian, pop, smtp proxying, HTTP / FTP virus scanning.

     

    Cheers,

  8. You can try state your problem and ask for further information on the Clark Connect community forums.

     

    Reformat everything was not a good idea if you cared for the data, as it makes recovery more difficult.

    I wouldn't install Win2k Adv Srv, for a firewall, Linux or OpenBSD is really great.

     

    Their forums for some reason are on slow response. Not like here.

     

    As for the data. It was alot of muisc that can be restored just takes alot of time. Other stuff was docs, mail, things I had on my computer. 99% of the stuff could be downloaded again, but it's time consuming.

     

    As for win 2k adv srv, it's only a file server for now. I'll be going back to using Endian Firewall v2 again, but on another computer.

     

    Future objectives: Quad Nic card for the firewall., 512 mb ram, P3 1.2 ghz, 20 gb hdd. File Server, 1 gb ram, athlon 64 x2 3800 dual core, 2TB hdd.

     

    Thanks,

  9. Hello All!

     

    Attempting to expand my storage capabilities on my ClarkConnect Firewall last night broke it big time! I lost data across 3 hard drives. I was trying so carefully to preserve the mount points. It didn't work out the way I planned. Trying to force myself to learn Linux. I do have some knowledge but not enough to get out of the pickle I was in last night. Eventually, I reformated everything to NTFS 5, and install Win 2k Adv Srv.

     

    -=-=- /etc/fstab -=-=-

    /dev/hdb1 /data01 ext3 defaults 0 0

    /dev/hdc1 /data02 ext3 defaults 0 0

    -=-=- /etc/fstab -=-=-

     

    For some strange reason the first mount point was in the root "/" and I know I had data on all of them. There were specific dirs in there that I made. They were gone after the mount. Umounted them and re-mounted them again, still I couldn't see anything. Where the hell did the data go! I was fustrated by this time, it was hours later.

     

    The fiance was calling me to bed so it must've been late...:)

  10. Yeh, it was a terrible day.

    The sad thing is that since then, everything just got worse, with all the new silly "anti terrorist" laws.

     

    Yeah these "silly laws" are changing our lives and our childrens lives. The consitution and the bill of rights are being destroyed!

     

    http://en.wikipedia.org/wiki/Patriot_Act

    http://en.wikipedia.org/wiki/Homeland_Security_Act

    http://en.wikipedia.org/wiki/ECHELON

    http://en.wikipedia.org/wiki/NSA_warrantle...nce_controversy

     

    These are my own person opinion. I believe everyone has a choice to believe in whatever they wish. After all this is America, land of the free, right?

  11. okay! I got it to working.. its 128bit encryption ;)

     

    thank you guys!!

     

    If you don't mind let me recommend a site for inspection. This is what I use here.

     

    WRT54GC & WMP54G Combo

    WPA2 Personal, AES & a 63 bit key

    I rather have used WPA2 Mixed but the WMP54G card doesn't support.

    channel 10, not 6, why? EVERYONE uses Channel 6. Most people just leave the defaults on. From experience I get better reception moving the channel to 10. List of inference: Cell, cordless phones, Microwaves, florencent lighting(WORSE), large mechanical motors(elevators)

     

    SSID is enabled, why? With SSID off it makes it more difficult to authenticate machine. Also you are more prone to diconnects. I may be wrong, but this works for me. I used to run with out SSID off, had nothing but problems.

     

    http://www.kurtm.net/wpa-pskgen/

     

    http://www.dslreports.com/forum/remark,16091930

  12. forgot to add, we had that router but the wireless range sucked!

     

    With some routers they have an option to add an external antenna. Like mine, I use a WRT54GC. At this point in time my connect spans about 20 feet. Personally the best is WRT54G or GS, why? I replace the firmware in there with a DDR-WART. I won't suggest this to amatuers. You can brick your router. Yes, even I have bricked a few. That's if you have the money to blow.

     

    Good Luck,

  13. ...... do you want us to tell you what we think of it?? If so, It sucks, Pentiums suck, go for amd and a new mobo right now, or go for the Core Duo 2.

     

    You only have so many options when you're a Dell Prefered Account Holder. For years I've used AMD and they perform beautifily. What I was asking is, this upgrade worth purchasing? The upgrade is only going to produce a marginal speed improvement or not? That's what I'm asking. If I can't get what need from this. Then I'll just finish paying off this account and custom build one later. I got this Dell in a pinch for school. At the time I didn't have the money to build a custom system. Building the system from scratch is the way I usually do it.

     

     

    Netburst architecture sucks.

     

    Western Digital disks are good, especially the one with 16 mb cache. Note that the one you picked is SATA-150 (SATA I), there exists SATA-300 (SATA II).

     

    Mushkin memory have a good reputation as high performance.

     

    I'm trying to play catch up here. I'm a lil behind the times here. I saw that but wasn't sure if my SATA 150 is directly compatible with SATA 300, meaning the interface. Will my mobo support it? Chipset Intel 945G Express.

     

    In my personal opinion I'm starting to think this was a bad purchase. I'm finding that my upgrade options are narrow. More narrow then I originally estimated. But like what I was telling the other guy, I was in a pinch to get something.

  14. Hello All!

     

    For the past few hours I've been investigating on upgrades for my current system. Is this worth the trouble upgrading it? Here a list of the following components:

     

    Western Digital Caviar SE16 WD4000KDRTL 400GB 7200 RPM Serial ATA150 Hard Drive - Retail

    Intel Pentium 4 630 Prescott 3.0GHz LGA 775 EM64T Processor Model BX80547PG3000F - Retail

    mushkin 2GB (2 x 1GB) 240-Pin DDR2 SDRAM DDR2 533 (PC2 4200) Dual Channel Kit System Memory Model 996519 - Retail

     

    This is what I have now Dell XP2/5150c

    PROCESSOR, 80551, PENTIUM D SMITHFIELD FOR DESKTOPS, 820, SKT-T, MALE

    DUAL IN-LINE MEMORY MODULE, 256, 533, 32X64, 8, 240, 1RX16

    HARD DRIVE, 80G, S2, 7.2K, 8MB, LEAD FREE, WD-UNIC

     

    My machines specs are as follows:

     

    Intel? Pentium? 4 5XXX and 6XXX processors with Hyper-Threading technology

     

    Pentium D 8XXX dual core processors (no Hyper-Threading)

     

    Intel Celeron? D processors

     

     

    16 KB for Pentium 4 5XXX and 6XXX processors and Celeron D processors

     

    2 x 16 KB for Pentium D 8XXX dual core processors

     

    1 MB for Pentium 4 5XXX processors

     

    2 MB for Pentium 4 6XXX processors

     

    2 x 1 MB for Pentium D 8XXX processors

     

    128 KB for Celeron D processors

     

    (depending on your computer configuration) pipelined-burst, eight-way set associative, write-back SRAM

     

     

     

     

    Currently running via siw.exe

     

    Memory Summary

    Capacity 512 MBytes

    Location System board or motherboard

    Maximum Capacity 1024 MBytes

    Memory Slots 4

    Error Correction None

    Name Physical Memory Array

    Use System memory

     

    Device Locator Slot 1

    Manufacturer Infineon (formerly Siemens)

    Part Number 64T32000HU3.7A

    Serial Number 03143713

    Capacity 256 MBytes

    Memory Type DDR2 SDRAM

    Speed DDR2-533 (266 MHz)

    Data Width 64 bits

    Voltage SSTL 1.8V

    Error Correction None

    Refresh Reduced (.5x)...7.8 ?s

    Manufacturing Date 2005, Week 50

    EPP SPD Support No

     

     

    Device Locator Slot 3

    Manufacturer Infineon (formerly Siemens)

    Part Number 64T32000HU3.7A

    Serial Number 0302C926

    Capacity 256 MBytes

    Memory Type DDR2 SDRAM

    Speed DDR2-533 (266 MHz)

    Data Width 64 bits

    Voltage SSTL 1.8V

    Error Correction None

    Refresh Reduced (.5x)...7.8 ?s

    Manufacturing Date 2005, Week 51

    EPP SPD Support No

     

    Sorry for the long post but I wanted to cover all of my bases..:)

     

    Thanks.

  15. Hello All!

     

    For the past few hours I've been investigating on upgrades for my current system. Is this worth the trouble upgrading it? Here a list of the following components:

     

    Western Digital Caviar SE16 WD4000KDRTL 400GB 7200 RPM Serial ATA150 Hard Drive - Retail

    Intel Pentium 4 630 Prescott 3.0GHz LGA 775 EM64T Processor Model BX80547PG3000F - Retail

    mushkin 2GB (2 x 1GB) 240-Pin DDR2 SDRAM DDR2 533 (PC2 4200) Dual Channel Kit System Memory Model 996519 - Retail

     

    This is what I have now Dell XP2/5150c

    PROCESSOR, 80551, PENTIUM D SMITHFIELD FOR DESKTOPS, 820, SKT-T, MALE

    DUAL IN-LINE MEMORY MODULE, 256, 533, 32X64, 8, 240, 1RX16

    HARD DRIVE, 80G, S2, 7.2K, 8MB, LEAD FREE, WD-UNIC

     

    My machines specs are as follows:

     

    Intel? Pentium? 4 5XXX and 6XXX processors with Hyper-Threading technology

     

    Pentium D 8XXX dual core processors (no Hyper-Threading)

     

    Intel Celeron? D processors

     

     

    16 KB for Pentium 4 5XXX and 6XXX processors and Celeron D processors

     

    2 x 16 KB for Pentium D 8XXX dual core processors

     

    1 MB for Pentium 4 5XXX processors

     

    2 MB for Pentium 4 6XXX processors

     

    2 x 1 MB for Pentium D 8XXX processors

     

    128 KB for Celeron D processors

     

    (depending on your computer configuration) pipelined-burst, eight-way set associative, write-back SRAM

     

     

     

     

    Currently running via siw.exe

     

    Memory Summary

    Capacity 512 MBytes

    Location System board or motherboard

    Maximum Capacity 1024 MBytes

    Memory Slots 4

    Error Correction None

    Name Physical Memory Array

    Use System memory

     

    Device Locator Slot 1

    Manufacturer Infineon (formerly Siemens)

    Part Number 64T32000HU3.7A

    Serial Number 03143713

    Capacity 256 MBytes

    Memory Type DDR2 SDRAM

    Speed DDR2-533 (266 MHz)

    Data Width 64 bits

    Voltage SSTL 1.8V

    Error Correction None

    Refresh Reduced (.5x)...7.8 ?s

    Manufacturing Date 2005, Week 50

    EPP SPD Support No

     

     

    Device Locator Slot 3

    Manufacturer Infineon (formerly Siemens)

    Part Number 64T32000HU3.7A

    Serial Number 0302C926

    Capacity 256 MBytes

    Memory Type DDR2 SDRAM

    Speed DDR2-533 (266 MHz)

    Data Width 64 bits

    Voltage SSTL 1.8V

    Error Correction None

    Refresh Reduced (.5x)...7.8 ?s

    Manufacturing Date 2005, Week 51

    EPP SPD Support No

     

    Sorry for the long post but I wanted to cover all of my bases..:)

     

    Thanks.

  16.  

    Thanks for the link to your website. I looked through all the pictures from 9/11 and there were many I hadn't seen before. I also checked out some of the NASA links and thought they were cool. I guess some people think NASA's not a good place to spend our taxes, but IMHO I think we get a lot of good return on the money. I know NASA provides all kinds of materials to educators that want to develop a curriculum about space science or similar studies. Then I somehow wandered into an area having to do with computer science or something like that and I had to run away because I started having cranial seizures. Too advanced for me to understand :huh: . Nice site though. You've obviously put a lot of work into it and it shows.

     

    Well I gotta go [people reading this are like "Thank God! I thought he'd never shut up! :wacko: ]. The Path to 9/11 movie on ABC is starting. I keep reading it's a real piece of cr*p but I guess I'll give it a go...

     

    Thanks Mike for your kind words. I do have a 9/11 Banner but I haven't had time to get into my backups to retrieve it. Once I put it up you'll see it on the main page once I get it up. One of my dreams was to work for NASA but you have to be in the airforce. So that is not an option. So I burried myself with computers.

  17. Hello All!

     

    I used to work in those buildings for Citbank and Arcus. My weekly visits to 2 wtc sub basement 2. Took the DC2120 tapes in 2 blue metal locked boxes back to WTC on tuesday mornings. But that contracted ended in Jan 2000. At the time of the attacks I was in ATL on vacation and couldn't return home til mid Oct. Home for me at that time was Indy.

     

    NYC is where I was born and raised. I left NYC when I was 21 and move to ATL. But as life turns out I return to NYC often. Now I'm located in Newport TN.

     

    Honor our Heros, Our Armed Forces! God Bless America, and all of those who passed away! Last count was 2,749. Plus Bayonne NJ as erected a memorial too.

     

    Tomorrow, I'll be putting up a lil memorial on my website.

     

    http://www.stb575.com

  18. Hello All!

     

    Is this a sign that the NIC is dying?

     

    eth0 - Green

    Link encap:Ethernet

    UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1

    RX packets:10338860 errors:149 dropped:0 overruns:0 frame:0

    TX packets:13301958 errors:0 dropped:0 overruns:0 carrier:0

    collisions:0 txqueuelen:1000

    RX bytes:1479638566 (1.3 GiB) TX bytes:3209697671 (2.9 GiB)

    Interrupt:9 Base address:0xd800

     

    Are these errors a result of CRC errors? Also, there are no dropped or overruns. That is a good sign.

     

    Thanks,

  19. Hello All!

     

    I've searched google and came up with nothing. Last night I activated my outbound firewall. Java will NOT function! Once I turn the outbound firewall off, Java is happy again. Is there a port that Java uses to estabilish a connection? If so, I can just set up a rule to allow Java out.

     

    Thanks,

  20. Get a remote Unix shell and nmap. :)

     

    Oh sure that would be awesome and be one of the best ways. What I could do is use Knoppix-STD. It should have nmap on it. Actually, I have a Knoppix-STD around here somewhere. If I have time later I could go to my friends house and run it from there.

     

    What about Nessus? Would have to study up on that one. Not too sure how to use it.

     

    Thanks for the suggestion.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.