background preloader

Firewalls

Facebook Twitter

Minecraft multiplayer server - ClearFoundation. Alrighty, I'l try to keep it as simple as possible (This post is quite big, but that's because I have tried to break it down as much as possible) 1. Hook up a screen/kb/mouse to the clear os machine 2. 3. 4. To enable the shell access option for ordinary users, enter the following command: In nano, the text editor, add this line at the end: It should look something like this: After adding that line, press "Ctrl-O" and enter to save, then press "Ctrl-X" to exit The last thing we need to do is to restart the admin web interface to apply the change we made.

Then write exit and press enter 5. 6. 7. Afterwards, right click in the main area of WinSCP and select "New"->"File... " Afterwards, save the file by clicking the save icon and close the editor window. 8. And The first time we launch a minecraft server, it creates a lot of files and then it quits. 9. 10. Return to the clear os machine and execute the command again. Transparent Proxy for Hot Spot/Public Network Web-Based Authentication on ClearOS | foxpa.ws. Despite the title neither making a hot spot nor “public” network is my intent in this article, but what it will cover can be directly applied to these situations. One of my clients is a small ISP and collocation datacentre which has a network that is configured 100% statically on both sides.

This sounds tedious at first but consider that we could use a DHCP server to direct un-configured clients (new server/virtual machine, new router, wiped configuration, new computer etc.) to use a gateway running a transparent web proxy that forcefully tells them to call in and have their router/host reconfigured remotely or by phone. This ensures that clients call in quickly (because they can’t do anything but see the instructions telling them to) rather than assume there is a long-but-temporary problem with the connection, leading to unjustified dissatisfaction with the service. We will need to install at least three modules from ClearSDN. Click on Web Proxy under the Gateway menu.

. # yum install at. IPsec firewall settings - ClearFoundation. Nick Howitt wrote:In the incoming firewall just allow the IPSec service. This allows UDP on port 500 and ESP/AH (protocols 50 and 51). Yes, that was what webconfig added and I quoted from the iptables listing, right ? And on the incoming firewall settings I already see the IPsec service added to the firewall rules. If you're connecting to a third party device, do not use the webconfig as you are pretty much guaranteed to fail. It uses a legacy type of set up which is not normally supported in modern devices. Yes I noticed that, I just mentioned that I used the IPsec webconfig just to point out that that was how the IPSec firewall rules were added, but I'm doing the setup by hand, editing the /etc/ipsec.conf.d/ipsec.*.conf file that webconfig created.

You will need to learn to configure Openswan manually (which is not too difficult for a basic set up). Well, for what I have seen, OpenSwan documentation sucks, their wiki is very incomplete and outdated. Be a little bit careful with tcpdump. Documentation | ClearOS Enterprise 5.1 | User Guide | Starting The Install | ClearCenter Support. Before starting a ClearOS Enterprise installation, you will need to download the installation media (details are in the next section). To verify the integrity of the download, you can check the MD5Sum of the file. What is an MD5sum? To make a long story short, an MD5sum is a simple way to verify the integrity of a downloaded file. For Windows, you can often use CD burning software to verify an MD5sum. There are three ways to install or upgrade ClearOS Enterprise: Bootable CD USB key (requires Internet access) PXE-enabled network card The ClearOS software can be installed from a CD-ROM drive. If necessary, change your BIOS settings to run bootable CDs Insert the ClearOS CD Turn on your target system Installing via a USB key is also possible.

You should then use desktop tools to image your USB key with this file. If you have a PXE Boot environment on your network, you can also configure it for ClearOS. Once you have booted the installer, you can follow the installation wizard. WebDAV. Web Distributed Authoring and Versioning (WebDAV) is an extension of the Hypertext Transfer Protocol (HTTP) that allows clients to perform remote Web content authoring operations. A working group of the Internet Engineering Task Force (IETF) defined WebDAV in RFC 4918. The WebDAV working group concluded its work in March 2007, after the Internet Engineering Steering Group (IESG) accepted an incremental update to RFC 2518. Other extensions left unfinished at that time, such as the BIND method, have been finished by their individual authors, independent of the formal working group. Many modern operating systems provide built-in client-side support for WebDAV. History[edit] The W3C meeting decided to form an IETF working group, because the new effort would lead to extensions to HTTP, which the IETF had started to standardize.

The protocol consists of a set of new methods and headers for use in HTTP. Implementations[edit] Servers[edit] For example: Clients[edit] Comparison of WebDAV software. Used Linux ClearOS instead of SBS 2008 - Technibble Forums. WHS user looking to change to ClearOS - ClearFoundation. Documentation | ClearOS Enterprise 5.1 | User Guide | Web Server | ClearCenter Support. ClearOS includes the Apache web server – the same software that powers many of the world's largest web sites. If you did not select this module to be included during the installation process, you must first install the module. You can find this feature in the menu system at the following location: Server Name The server name is a valid name (for example, www.example.com) for your web server. This name is used on some infrequently used error pages, so it is not all that important. SSL-Enabled - Secure Site The web server comes with built-in SSL encryption for enhanced security.

SSL encryption requires a web site certificate. The web server includes support for “virtual hosts”. There are many options for adding dynamic content to a website: PHP and perl CGI are installed by default. To upload files to your server, you can enable either FTP or File Server access to the site or you can use both. Samba access of your web server is only available from networks with the LAN role in IP Settings. Documentation | ClearOS Enterprise 5.1 | User Guide | Windows Settings | ClearCenter Support. Your ClearOS system provides network and file serving capabilities for a Windows network. Among other tasks, you can use the software for domain control, file storage and sharing printers. If you did not select this module to be included during the installation process, you must first install the module.

You can find this feature in the menu system at the following location: Server Name This is a one-word descriptive name of the system, for example: clearserver This is a short description of the server. Printing If you have a printer attached to your ClearOS system, you can share it via Windows networking. Raw - drivers must be installed on client system WINS Support / WINS Server Even for small networks, we recommend using WINS for your Windows networks. Administrator Password The winadmin account is used for the Windows domain administrator. ClearOS supports two modes for your network. Simple File and Print Server This mode should be used for creating a basic file and print server. Documentation | ClearOS Enterprise 5.1 | User Guide | Windows Settings | ClearCenter Support. Your ClearOS system provides network and file serving capabilities for a Windows network. Among other tasks, you can use the software for domain control, file storage and sharing printers.

If you did not select this module to be included during the installation process, you must first install the module. You can find this feature in the menu system at the following location: Server Name This is a one-word descriptive name of the system, for example: clearserver This is a short description of the server. Printing If you have a printer attached to your ClearOS system, you can share it via Windows networking. Raw - drivers must be installed on client system WINS Support / WINS Server Even for small networks, we recommend using WINS for your Windows networks. Administrator Password The winadmin account is used for the Windows domain administrator. ClearOS supports two modes for your network. Simple File and Print Server This mode should be used for creating a basic file and print server. Documentation | ClearOS Enterprise 5.1 | User Guide | SMTP Server | ClearCenter Support.

SMTP lets you can manage your own mail server. There are a number of reasons this might be advantageous: Ability to have a customized user and domain name - for example, anyone@anydomain.com Mailboxes limited only by hard disk storage capacity and your own administration settings Alias support - for example, sales@yourcompany.com can be sent to bob@yourcompany.com and joe@yourcompany.com No waiting around for new users to be added Custom antispam control Antivirus support Privacy Full control A number of services are available for mail services: If you did not select this module to be included during the installation process, you must first install the module. You can find this feature in the menu system at the following location: General Settings The Hostname does not have to be related to the e-mail domains that you host. The Primary domain field indicates the domain name this server will act as an SMTP/Mail server for. SMTP Authentication - Thunderbird Trusted Networks Outbound Relay Hosts.

Features. How to: Install SOGo groupware on ClearOS - ClearFoundation. Hi Kevin, I installed SOGo after a number of tries with Zarafa - I just could not get the Outlook connector to work there. The installation went smoothly. I am able to logon through the web interface and look at my mail. I can read mail, I can delete mail and I can send mail. I cannot use the Address Book (contacts) feature.

No matter where I try to reach it from (either the home web page, the icon, or email write window) it gives me a 502 Proxy Error Proxy Error The proxy server received an invalid response from an upstream server. Reason: Error reading from remote server Apache/2.2.3 (ClearOS) Server at 192.168.1.50 Port 443 The log file is filled with these errors: 2010-11-06 18:57:10.504 sogod[31381] Note(NGImap4Connection): using '/' as the IMAP4 folder separator. 127.0.0.1 - - [06/Nov/2010:18:57:10 GMT] "GET /SOGo/so/user/Mail//0/folderINBOX/expunge HTTP/1.1" 204 0/0 0.258 - - 832K 127.0.0.1 - - [06/Nov/2010:18:57:10 GMT] "GET /SOGo/so/user/Contacts HTTP/1.1" 302 0/0 0.004 - - 16K.

Simplify system security with the Uncomplicated Firewall. By Michael Anckaert on October 01, 2008 (4:00:00 PM) You must run UFW commands as root, so in Ubuntu, you must preface them with the sudo command. With UFW, enabling and disabling packet filtering is a simple matter of issuing the sudo ufw enable and sudo ufw disable commands. You set the default policy for filtering packets by running the sudo ufw default command and passing the allow or deny argument, depending on what you want to achieve. If you issue the sudo ufw default allow command, all incoming packets will be allowed by default, creating a very unsecure packet filter but giving you the broadest range of allowed services.

The command sudo ufw default deny will block all incoming packets, requiring that you allow specific services to pass the packet filter. Packet filters allow or deny certain services as specified by an administrator. Sudo ufw allow 80/tcp sudo ufw deny 21/tcp sudo ufw deny smtp sudo ufw allow ssh More complex filtering sudo ufw delete allow ssh from 192.168.2.3. Rix Tip Of the Day... branding. - Page 2 - Untangle Forums. Receive Email whenever new computer added to network - Untangle Forums. Pfsense.trendchiller.com. Open Source Firewall Distribution - Features.

Not sending e-mail - Page 2 - Untangle Forums. Wall. m0n0wall is a project aimed at creating a complete, embedded firewall software package that, when used together with an embedded PC, provides all the important features of commercial firewall boxes (including ease of use) at a fraction of the price (free software). m0n0wall is based on a bare-bones version of FreeBSD, along with a web server, PHP and a few other utilities.

The entire system configuration is stored in one single XML text file to keep things transparent. m0n0wall is probably the first UNIX system that has its boot-time configuration done with PHP, rather than the usual shell scripts, and that has the entire system configuration stored in XML format. In m0n0wall 1.8.1, the base system has been switched to FreeBSD 8.4 for better support of recent hardware, and there have been significant improvements, new features and bug fixes in many areas. Set up your firewall with Firewall Builder. Packages for fwbuilder are available in the Ubuntu Hardy and Fedora 9 repositories. fwbuilder is packaged as a 1-Click install for openSUSE 10.3, but not for version 11 as yet.

In this article I'll build from source on a 64-bit Fedora 9 machine using fwbuilder version 2.1.19. fwbuilder is shipped as two tarballs: libfwbuilder and fwbuilder. You have to install the library first. Install the two packages using the normal . /configure; make; sudo make install procedure. Running qmake: /usr/lib64/qt-3.3/bin/qmake WARNING: icns.path is not defined: install target not created When you start fwbuilder, you'll see the window shown behind the new firewall dialog in the screenshot below. Firewall Builder templates. The fourth item on the list, host fw template 1, simply protects a single host, only allowing incoming SSH access. The firewall rules for Template 1 are shown in the screenshot below. When you have your own copy of the SSH service port definition you are free to edit it.

Wish list. Features List. The most comprehensive, up to date features listing can be found on the pfSense website. A community contributed list follows. Firewall Easy to use Web Based Graphical Interface no need to know how to create firewall rules, it is helpful however. Installation Setup Wizard Wireless Access Point (must install a wifi interface) Abiltiy to setup and firewall multiple subnets ( seperate Accounting, Marketing, R&D and sales from each other) Traffic Shaping State Table NAT Redundancy CARP (failover) - CARP from OpenBSD allows for hardware failover.

Two or more firewalls can be configured as a failover group. The packages listed below can be installed with one click. Security snort - Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. Network Management Darkstat - darkstat is a network statistics gatherer. Diagnostic States - Paul Taylors version of Diagnostics States which utilizes pftop. Services System. The Logs Menu — Endian UTM Appliance v2.3 documentation. Community - Get Help. Complete Stealthing - Untangle Forums. Build and Deploy the Root Certificate Authority.