Re: [CentOS] Security help desperately needed - more info

2008-02-08 Thread Anne Wilson
On Thursday 07 February 2008 21:30, mouss wrote: > do an > # iptables-save > somefile > > edit somefile and put the following 4 lines "somewhere" (before the > lines that reject everything) > > -A RH-Firewall-1-INPUT -p udp -m udp -s 192.168.0.0/24 --dport 137 -j > ACCEPT -A RH-Firewall-1-INPUT -p

RE: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Carol Anne Ogdin
age- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of mouss > Sent: Thursday, February 07, 2008 1:21 PM > To: CentOS mailing list > Subject: Re: [CentOS] Security help desperately needed - more info > > Milton Calnek wrote: > > > > > >

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread mouss
Anne Wilson wrote: /etc/hosts is fine. All possible connections on the lan are correctly defined. dns resolution is via my isp, and again the IP addresses are correctly set. That leaves the security settings, where I believe the problem is. So, let's start with iptables. I've never worked

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread mouss
Milton Calnek wrote: Michael Simpson wrote: Hi there, Should the IP address supplied be the actual address for eth0 rather than the network address? ie 192.168.0.1/24 rather than 192.168.0.0/24 I dunno... what does 192.168.0.1/24 mean? this one is not always accepted. what does 192.168

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Anne Wilson
On Thursday 07 February 2008 16:10:24 Michael Simpson wrote: > On 2/7/08, Anne Wilson <[EMAIL PROTECTED]> wrote: > > On Thursday 07 February 2008 15:13, Michael Simpson wrote: > > > I could be wrong (often am) but it might be worth trying it out to see > > > if it gets rid of the error pertaining t

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Michael Simpson
On 2/7/08, Anne Wilson <[EMAIL PROTECTED]> wrote: > On Thursday 07 February 2008 15:13, Michael Simpson wrote: > > I could be wrong (often am) but it might be worth trying it out to see > > if it gets rid of the error pertaining to subnet creation. > > I took the notation as I set it from a book wh

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Anne Wilson
On Thursday 07 February 2008 15:14, Ross S. W. Walker wrote: > I would look at the DNS setup to make sure all host names are resolvable, > maybe the /etc/hosts file isn't setup properly. Make sure smb ports are > open inbound and outbound in iptables and the latest selinux profile is > installed.

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Anne Wilson
On Thursday 07 February 2008 15:13, Michael Simpson wrote: > I could be wrong (often am) but it might be worth trying it out to see > if it gets rid of the error pertaining to subnet creation. I took the notation as I set it from a book when I first started using samba - 2001/2? 'Using Samba', I

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Anne Wilson
On Thursday 07 February 2008 14:34, Milton Calnek wrote: > Anne Wilson wrote: > > On Thursday 07 February 2008 13:53, Milton Calnek wrote: > >> Anne Wilson wrote: > >>> - samba Begin > >>> > >>> > >>> WARNING!! > >>> Errors when creating subnets:

RE: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Ross S. W. Walker
Michael Simpson wrote: > On 2/7/08, Anne Wilson <[EMAIL PROTECTED]> wrote: > > On Thursday 07 February 2008 13:53, Milton Calnek wrote: > > > Anne Wilson wrote: > > > > - samba Begin > > > > > > > > > > > > WARNING!! > > > > Errors when creating s

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Michael Simpson
On 2/7/08, Milton Calnek <[EMAIL PROTECTED]> wrote: > > > Michael Simpson wrote: > > Hi there, > > > > Should the IP address supplied be the actual address for eth0 rather > > than the network address? > > > > ie 192.168.0.1/24 rather than 192.168.0.0/24 > > I dunno... > what does 192.168.0.1/24 me

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Milton Calnek
Michael Simpson wrote: Hi there, Should the IP address supplied be the actual address for eth0 rather than the network address? ie 192.168.0.1/24 rather than 192.168.0.0/24 I dunno... what does 192.168.0.1/24 mean? what does 192.168.0.0/24 mean? The way I see it, they both mean 192.168.0.0

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Michael Simpson
On 2/7/08, Anne Wilson <[EMAIL PROTECTED]> wrote: > On Thursday 07 February 2008 13:53, Milton Calnek wrote: > > Anne Wilson wrote: > > > - samba Begin > > > > > > > > > WARNING!! > > > Errors when creating subnets: > > > No subnets to listen

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Milton Calnek
Anne Wilson wrote: On Thursday 07 February 2008 13:53, Milton Calnek wrote: Anne Wilson wrote: - samba Begin WARNING!! Errors when creating subnets: No subnets to listen to. Shutting down. : 1 Time(s) Hmmm... let's see your smb.conf.

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Anne Wilson
On Thursday 07 February 2008 13:53, Milton Calnek wrote: > Anne Wilson wrote: > > - samba Begin > > > > > > WARNING!! > > Errors when creating subnets: > > No subnets to listen to. Shutting down. : 1 Time(s) > > Hmmm... let's see your smb.conf

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Milton Calnek
Anne Wilson wrote: - samba Begin WARNING!! Errors when creating subnets: No subnets to listen to. Shutting down. : 1 Time(s) Hmmm... let's see your smb.conf. -- Milton Calnek BSc, A/Slt(Ret.) [EMAIL PROTECTED] 306-717-8737 --

Re: [CentOS] Security help desperately needed - more info

2008-02-07 Thread Anne Wilson
On Thursday 07 February 2008 10:29, Anne Wilson wrote: > I need to have the following services from my server: > > imap - mostly by lan, but occasionally external > file and print serve > samba access - read and write to some directories > > > I feel to be thrashing helplessly. I need help to fin

[CentOS] Security help desperately needed

2008-02-07 Thread Anne Wilson
I need to have the following services from my server: imap - mostly by lan, but occasionally external file and print serve samba access - read and write to some directories The problems I'm seeing are inconsistent, making it difficult to know how to find the source. Samba access is essential to