OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Togan Muftuoglu (toganm_at_users.sourceforge.net)
Date: Fri Nov 08 2002 - 03:08:18 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    * Frédéric Poulet; <pofredericyahoo.fr> on 08 Nov, 2002 wrote:
    >I don't see my web server from internet and from internal network. I don't see my erros.

    ># 13.)
    >FW_FORWARD="0/0,192.168.5.2/32,tcp,80 192.168.1.0/24,192.168.5.2/32,tcp,80"

    Leave this blank as you can only use it if your DMZ has a real IP not
    from the private range

    >
    ># 14.)
    >FW_FORWARD_MASQ="0/0,192.168.5.2,tcp,80"

    keep this

    >
    ># 16.)

    >FW_LOG_DROP_CRIT="no"
    >FW_LOG_DROP_ALL="no"
    >FW_LOG_ACCEPT_CRIT="no"
    >FW_LOG_ACCEPT_ALL="no"

    Of course you won^t see any errors has logging is basicly disabled
    changed at least

    FW_LOG_*_CRIT="yes" so you will have some logs to work with. If you are
    debugging ( trying to make sure everything works with protectşon then
    change logging options to "yes" (warning lots of messages) once you are
    sure about of your config then change it with only loggging the critical
    ones.

    -- 
    

    Togan Muftuoglu Unofficial SuSE FAQ Maintainer http://dinamizm.ath.cx

    -- Check the headers for your unsubscription address For additional commands, e-mail: suse-security-helpsuse.com Security-related bug reports go to securitysuse.de, not here