<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>wehuberconsultingllc.com &#187; firewall</title>
	<atom:link href="http://wehuberconsultingllc.com/wordpress/category/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://wehuberconsultingllc.com/wordpress</link>
	<description></description>
	<lastBuildDate>Sun, 15 Aug 2010 13:27:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>How To Set Up A Terminal Server In Linux Using Ubuntu 9.10 And FreeNX</title>
		<link>http://wehuberconsultingllc.com/wordpress/2010/01/28/how-to-set-up-a-terminal-server-in-linux-using-ubuntu-9-10-and-freenx/</link>
		<comments>http://wehuberconsultingllc.com/wordpress/2010/01/28/how-to-set-up-a-terminal-server-in-linux-using-ubuntu-9-10-and-freenx/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 13:16:23 +0000</pubDate>
		<dc:creator>Bill</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[firewall]]></category>

		<guid isPermaLink="false">http://wehuberconsultingllc.com/wordpress/2010/01/28/how-to-set-up-a-terminal-server-in-linux-using-ubuntu-9-10-and-freenx/</guid>
		<description><![CDATA[This article was timely. I had just installed virtual version of Ubuntu on my ESXi server and set up VNC so I could access it. It was okay but FreeNX is a more elegant solution. The combination of FreeNX and Firehol to setup the firewall makes it a winner in my book. How To Set [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>This article was timely. I had just installed virtual version of Ubuntu on my ESXi server and set up <a href="http://www.tightvnc.com">VNC</a> so I could access it. It was okay but <a href="http://freenx.berlios.de/">FreeNX</a> is a more elegant solution. The combination of FreeNX and <a title="FireHOL, a Linux iptables packet filtering firewall builder for humans" href="http://firehol.sourceforge.net/">Firehol</a> to setup the firewall makes it a winner in my book.</p>
<blockquote><p><a href="http://wehuberconsultingllc.com/wordpress/wp-content/uploads/2010/01/ubuntu.gif"><img title="ubuntugif" alt="ubuntu.gif" src="http://wehuberconsultingllc.com/wordpress/wp-content/uploads/2010/01/ubuntu_thumb.gif" width="43" height="44" /></a></p>
<p><b>How To Set Up A Terminal Server In Linux Using Ubuntu 9.10 And FreeNX</b></p>
<p>FreeNX is an open source implementation of NoMachine&#8217;s NX Server. It is a bit more akin to Microsoft&#8217;s RDP protocol that the usual VNC, so while keeping bandwidth to a minimum, it maintains good visual quality and responsiveness. </p>
</blockquote>
<p><a href="http://www.howtoforge.com/how-to-set-up-a-terminal-server-in-linux-using-ubuntu-9.10-and-freenx">How To Set Up A Terminal Server In Linux Using Ubuntu 9.10 And FreeNX</a>     <br />(author unknown)     <br />Mon, 25 Jan 2010 16:42:09 GMT</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://wehuberconsultingllc.com/wordpress/2010/01/28/how-to-set-up-a-terminal-server-in-linux-using-ubuntu-9-10-and-freenx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Vista cannot obtain an IP address from certain routers or from certain non-Microsoft DHCP servers</title>
		<link>http://wehuberconsultingllc.com/wordpress/2009/08/04/windows-vista-cannot-obtain-an-ip-address-from-certain-routers-or-from-certain-non-microsoft-dhcp-servers/</link>
		<comments>http://wehuberconsultingllc.com/wordpress/2009/08/04/windows-vista-cannot-obtain-an-ip-address-from-certain-routers-or-from-certain-non-microsoft-dhcp-servers/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 22:34:00 +0000</pubDate>
		<dc:creator>Bill</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://wehuberconsultingllc.com/wordpress/2009/08/04/windows-vista-cannot-obtain-an-ip-address-from-certain-routers-or-from-certain-non-microsoft-dhcp-servers/</guid>
		<description><![CDATA[&#160; Consider the following scenario: You connect a Windows Vista-based computer to a network. A router or other device that is configured as a Dynamic Host Configuration Protocol (DHCP) server is configured on the network. The router or the other device does not support the DHCP BROADCAST flag. In this scenario, Windows Vista cannot obtain [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<blockquote><p>Consider the following scenario: </p>
<ul>
<li>You connect a Windows Vista-based computer to a network. </li>
<li>A router or other device that is configured as a Dynamic Host Configuration Protocol (DHCP) server is configured on the network. </li>
<li>The router or the other device does not support the DHCP <b>BROADCAST</b> flag. </li>
</ul>
<p>In this scenario, Windows Vista cannot obtain an IP address.</p>
</blockquote>
<p>Consider the following scenario:</p>
<ul>
<li>You just bought your son a new Toshiba tablet with Vista Business pre-installed on it. You want to make sure that when the tablet goes off to school it has all critical patches applied.</li>
<li>You are using pfSense as a DHCP server.</li>
<li>The XP, Linux, and Windows 7 computers are able to connect to the network and get an IP address.</li>
</ul>
<p>You would have thought DHCP problems were solved twenty years ago but here is the solution.</p>
<p><a href="http://support.microsoft.com/default.aspx/kb/928233">Windows Vista cannot obtain an IP address from certain routers or from certain non-Microsoft DHCP servers</a></p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://wehuberconsultingllc.com/wordpress/2009/08/04/windows-vista-cannot-obtain-an-ip-address-from-certain-routers-or-from-certain-non-microsoft-dhcp-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adventures with iRedMail &#8211; Part II</title>
		<link>http://wehuberconsultingllc.com/wordpress/2009/05/24/adventures-with-iredmail-part-ii/</link>
		<comments>http://wehuberconsultingllc.com/wordpress/2009/05/24/adventures-with-iredmail-part-ii/#comments</comments>
		<pubDate>Mon, 25 May 2009 01:16:36 +0000</pubDate>
		<dc:creator>Bill</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[SBS2K-SBS2K3]]></category>
		<category><![CDATA[firewall]]></category>

		<guid isPermaLink="false">http://wehuberconsultingllc.com/wordpress/2009/05/24/adventures-with-iredmail-part-ii/</guid>
		<description><![CDATA[In the first installment of Adventures with iRedMail I got it to send emails but I left the MS Exchange integration for another day. Since then I have updated my DNS zone with the DKIM information, set up local DNS information, decided on naming standards, and reconfigured Postfix several times before I got it right. [...]


Related posts:<ol><li><a href='http://wehuberconsultingllc.com/wordpress/2010/02/13/cleaning-up-an-existing-newsletter-mailing-list/' rel='bookmark' title='Permanent Link: Cleaning up an existing newsletter mailing list'>Cleaning up an existing newsletter mailing list</a> <small>In December 2008 I was asked to clean up some...</small></li>
<li><a href='http://wehuberconsultingllc.com/wordpress/2010/04/18/importing-self-signed-ca-certificate-into-windows-7/' rel='bookmark' title='Permanent Link: Importing Self-signed CA Certificate into Windows 7'>Importing Self-signed CA Certificate into Windows 7</a> <small>Yesterday I opted to create self-signed certificates for my local...</small></li>
<li><a href='http://wehuberconsultingllc.com/wordpress/2009/11/29/notes-on-installing-the-network-monitoring-appliance/' rel='bookmark' title='Permanent Link: Notes on Installing the Network Monitoring Appliance'>Notes on Installing the Network Monitoring Appliance</a> <small>A couple of weeks ago I installed the Network Monitoring...</small></li>
</ol>

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>In the first installment of <a href="http://wehuberconsultingllc.com/wordpress/2009/05/17/adventures-with-iredmail/">Adventures with iRedMail</a> I got it to send emails but I left the MS Exchange integration for another day. Since then I have updated my DNS zone with the DKIM information, set up local DNS information, decided on naming standards, and reconfigured Postfix several times before I got it right.</p>
<h4>Updating the DNS with DKIM information</h4>
<p>This task was relatively easy. I copied the DKIM information in the iRedMail.tips into a trouble ticket with my web provider. About 24 hours later it was ready to test. I sent an emails to my Yahoo account, <a href="mailto:sa-test@sendmail.net">sa-test@sendmail.net</a>, and <a href="mailto:autorespond+dkim@dk.elandsys.com">autorespond+dkim@dk.elandsys.com</a>. Although the email from dk.elandsys.com was the first to respond, it said it did not work. When I checked my Yahoo account the headers said the email was signed correctly with DKIM. Ironically the return email from sendmail.net ended up in my Junk Mail folder. It said that everything worked correctly. For one more test I created a Gmail account and sent an email to it, too. It said the email was signed correctly.</p>
<h4>Local DNS, naming standards, and more Postfix problems</h4>
<p>The next challenge was to configure Postfix to accept both local email addresses and email addresses for the exchange server under the same domain. I used PostFixAdmin to create Aliases that pointed to the Exchange server emails(e. g. <a href="mailto:myemail@mybusiness.com">myemail@mybusiness.com</a> points to <a href="mailto:myemail@mybusiness.local">myemail@mybusiness.local</a>). PostFix complained about the DNS records for my Exchange server so I added mybusiness.local as a relay_domain and set up a psuedo DNS so that PostFix can find the IP address for my Exchange server. In my case I decided to let my pfSense firewall act as a local DNS server to serve up the local IP addresses. At this point I can email to everyone from a local iRedMail account but I cannot get replies until I set up iRedMail as the SMTP gateway and the Exchange server as a relay domain.</p>
<h4>PostFix domain checks get me again!</h4>
<p>It took me a long time to figure this out. When I changed the firewall to redirect SMTP traffic to the PostFix gateway I could not get any mail. I thought I had messed up the firewall settings so I kept trying different settings. I was pretty limited with my testing tools. If I could Telnet into port 25 I could see what is happening but I could not make the connection work as long as I was located on this side of the firewall. Fortunately I found a solution on the Internet. The dnsqueries.com site provides a page, <a title="http://www.dnsqueries.com/en/smtp_test_check.php" href="http://www.dnsqueries.com/en/smtp_test_check.php">http://www.dnsqueries.com/en/smtp_test_check.php</a>, that allows me to check my local SMTP connection using their server.&#160; Within minutes I figured out that my email server did not like my sender’s domain. In fact it did not like anyone’s domain. This was the same type of problem I had with the Postfix recipient domain check, so I removed the sender domain check and the emails starting flowing.</p>
<h4>What have I achieved?</h4>
<ul>
<li>I have a gateway that checks all incoming mail for spam and viruses. Postini offers a similar service for about $1 per user per month. We use <a href="http://www.mxlogic.com/">MXLogic</a> at work.</li>
<li>I have an alternate email server that allows me to send email that passes the SPF and DKIM checks. One of the reasons I investigated iRedMail was to use it for sending out a newsletter at work. Like many Internet retailers we get a chunk of our business as a result of our biweekly newsletter. In our case DKIM is another piece of the puzzle to improve our <a href="https://www.senderscore.org/">sender reputation</a>. Since both Yahoo and Gmail require DKIM signing in order to set up feedback loops, DKIM is probably essential if you have ambitions of having a pristine email list. For those folks looking at ways to cut the umbilical cord to Microsoft this is one of several low cost, low maintenance migration alternatives to a local Exchange server. </li>
</ul>


<p>Related posts:<ol><li><a href='http://wehuberconsultingllc.com/wordpress/2010/02/13/cleaning-up-an-existing-newsletter-mailing-list/' rel='bookmark' title='Permanent Link: Cleaning up an existing newsletter mailing list'>Cleaning up an existing newsletter mailing list</a> <small>In December 2008 I was asked to clean up some...</small></li>
<li><a href='http://wehuberconsultingllc.com/wordpress/2010/04/18/importing-self-signed-ca-certificate-into-windows-7/' rel='bookmark' title='Permanent Link: Importing Self-signed CA Certificate into Windows 7'>Importing Self-signed CA Certificate into Windows 7</a> <small>Yesterday I opted to create self-signed certificates for my local...</small></li>
<li><a href='http://wehuberconsultingllc.com/wordpress/2009/11/29/notes-on-installing-the-network-monitoring-appliance/' rel='bookmark' title='Permanent Link: Notes on Installing the Network Monitoring Appliance'>Notes on Installing the Network Monitoring Appliance</a> <small>A couple of weeks ago I installed the Network Monitoring...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://wehuberconsultingllc.com/wordpress/2009/05/24/adventures-with-iredmail-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting McAfee to work behind an ISA 2004 Firewall</title>
		<link>http://wehuberconsultingllc.com/wordpress/2009/05/17/getting-mcafee-to-work-behind-an-isa-2004-firewall/</link>
		<comments>http://wehuberconsultingllc.com/wordpress/2009/05/17/getting-mcafee-to-work-behind-an-isa-2004-firewall/#comments</comments>
		<pubDate>Sun, 17 May 2009 14:05:58 +0000</pubDate>
		<dc:creator>Bill</dc:creator>
				<category><![CDATA[SBS2K-SBS2K3]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[isa sbs]]></category>

		<guid isPermaLink="false">http://wehuberconsultingllc.com/wordpress/2009/05/17/getting-mcafee-to-work-behind-an-isa-2004-firewall/</guid>
		<description><![CDATA[It has been a long time since I actively worked with Microsoft’s ISA Firewall so it took me some time to fix this problem. Buy.com periodically offers a 3 computer version of McAfee at a very cheap price. Since I am somewhat ambivalent about the merits of one virus checking software over another, I bought [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>It has been a long time since I actively worked with Microsoft’s ISA Firewall so it took me some time to fix this problem. Buy.com periodically offers a 3 computer version of McAfee at a very cheap price. Since I am somewhat ambivalent about the merits of one virus checking software over another, I bought a copy to replace a TrendMicro version up for renewal. The installation did not flag any errors or warnings so it took about a week before I noticed that the patterns had not updated. Yesterday I decided to fix the problem and write down for posterity how I accomplished it.</p>
<p>Unlike many firewalls Microsoft’s firewall typically restricts anonymous access. This typically is not a problem for most applications that run on Windows computers since the users are logged into the Active Domain. Occasionally there are applications that fail to connect to the internet despite the user being logged into the domain. Most of the time you need to open some non-standard ports to fix the problem. In this case McAfee is using standard HTTP and HTTPS ports and still failing to connect. </p>
<p>The solution is to create an anonymous access rule to the McAfee update site and to configure the client to not use the ISA Firewall client for these sites. One way to accomplish this&#160; is to configure Internet explorer(Tools-Internet Options-Connections-Lan settings-Advanced) to not use the proxy. This is the way I got McAfee to update. Another way is to configure the properties for the internal network in ISA to use direct access for these sites. You can configure a GPO, too.</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://wehuberconsultingllc.com/wordpress/2009/05/17/getting-mcafee-to-work-behind-an-isa-2004-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>pfSense 1.2.2 Upgrade</title>
		<link>http://wehuberconsultingllc.com/wordpress/2009/04/05/pfsense-122-upgrade/</link>
		<comments>http://wehuberconsultingllc.com/wordpress/2009/04/05/pfsense-122-upgrade/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 13:34:24 +0000</pubDate>
		<dc:creator>Bill</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[pfSense]]></category>

		<guid isPermaLink="false">http://wehuberconsultingllc.com/wordpress/2009/04/05/pfsense-122-upgrade/</guid>
		<description><![CDATA[Last year I finally got around to installing pfSense 1.2 and some packages. Last week I decided to upgrade to the latest release. I chose to use the command line version of the upgrade process and it worked great at updating the base package. The upgrade documentation is a little fuzzy about updating the packages. [...]


Related posts:<ol><li><a href='http://wehuberconsultingllc.com/wordpress/2009/11/30/windows-7-upgrade-from-windows-xp-home/' rel='bookmark' title='Permanent Link: Windows 7 Upgrade from Windows XP Home'>Windows 7 Upgrade from Windows XP Home</a> <small>I think I can finally say that I have finished...</small></li>
</ol>

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Last year I finally got around to installing pfSense 1.2 and some <a href="http://wehuberconsultingllc.com/wordpress/2008/05/27/picks-and-pans-for-pfsense-packages/">packages</a>. Last week I decided to upgrade to the latest release. I chose to use the command line version of the upgrade process and it worked great at updating the base package. The upgrade documentation is a little fuzzy about updating the packages. When I logged into the administrative panel the firewall started to upgrade the packages. That kind of worked but most of the packages I checked were not working after the upgrade. I tried to manually update or uninstall SNORT but it ignored me. So I rebooted the firewall.</p>
<p>As the firewall came up the second time, it upgraded SNORT. After logging into the administrative panel again, I saw that NMAP worked. Okay, that’s a step forward. Next I tried NTOP but the screen would not come up. Thinking it might have forgotten the configuration settings, I configured NTOP. It worked. Next I installed Open-VM-Tools since I run my firewall as virtual machine. Finally I tried SNORT. I could configure it but it still had problems downloading rules. This was the problem I had previously under 1.2 so I uninstalled SNORT. Everything seems to be working so it is probably safe to forget it for a couple more months.</p>


<p>Related posts:<ol><li><a href='http://wehuberconsultingllc.com/wordpress/2009/11/30/windows-7-upgrade-from-windows-xp-home/' rel='bookmark' title='Permanent Link: Windows 7 Upgrade from Windows XP Home'>Windows 7 Upgrade from Windows XP Home</a> <small>I think I can finally say that I have finished...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://wehuberconsultingllc.com/wordpress/2009/04/05/pfsense-122-upgrade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.955 seconds -->
