Re: smoothwall and httpd questions


Subject: Re: smoothwall and httpd questions
From: Justin Dieters (enderak@yahoo.com)
Date: Tue Mar 19 2002 - 20:59:43 AKST


> a.) you might take a look at the exact rules that smoothwall sets up. the
> file is /etc/init.d/firewall* (I don't remember the exact filename.. it
> might be somehere else in /etc too) I distinctly remember the docs saying
> something about the green interface not being allowed to talk to the
> orange interface (which is the USUAL target for port forwarding.. see
> below) so... maybe it's a feature, not a bug. =p

Technically it's a green interface talking to itself.. or a green
interface with another green interface. I know the faq has provisions
for a green talking to an orange and vise-versa, but not green-green..
so you are probably right... So once I get my server up on the orange
hopefully it will work correctly.. I guess I won't worry about it until
then.

> <soap-box>
> b.) my security training forces me to point out the security problems
> inherent in having your server on the same subnet as your internal
> computers. if someone breaks into your server they have access to all your
> machines. the usual way to set this stuff up is to have the server on a
> seperate network, so if the server is penetrated all the hacker has access
> to is that single machine.
> </soap-box>

Yes yes, I know. Right now I'm just playing around with learning how
it's all set up. My actual server (which will be in the DMZ) is out of
commission until I get a new power supply for it tomorrow. So right now
I'm just playing around with learning the ins and outs of smoothwall
using my laptop instead. So nothing to worry about! :)

> Sounds like a mime-type issue, except that you said you didn't tweak
> anything, and your site a.) appears to be feeding the correct mime-type
> and b.) works fine for me (Mozilla 0.9.8). =) have you tweaked anything
> since sending this e-mail?

Yes, it was sending the mime-type as application/html instead of
text/html - have since fixed it by futzing around with the AddType
settings in httpd.conf.

Thanks,
Justin
enderak@yahoo.com

_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



This archive was generated by hypermail 2a23 : Tue Mar 19 2002 - 21:06:14 AKST