Ik probeer uit te vissen waarom ik niet kan unrealen van achter deze firewall. Ik heb er niet zoveel verstand van, ziet iemand waar het mis zit?
Dit zijn de instellingen:
# Q: Would you like to run the packet filtering script? [N]
Firewall.ip_intro="Y"
# Q:
Firewall.ip_detail_level_kludge="Y"
# Q: Do you need the advanced networking options?
Firewall.ip_advnetwork="Y"
# Q: DNS servers: [0.0.0.0/0]
Firewall.ip_s_dns="0.0.0.0/0"
# Q: Trusted interface names: [lo]
Firewall.ip_s_trustiface="lo eth1"
# Q: Public interfaces: [eth+ ppp+ slip+]
Firewall.ip_s_publiciface="eth0 ppp+ slip+"
# Q: TCP services to audit: [telnet ftp imap pop-3 finger sunrpc exec login linuxconf ssh]
Firewall.ip_s_tcpaudit="telnet ftp imap pop-3 finger sunrpc exec login linuxconf ssh"
# Q: UDP services to audit: [31337]
Firewall.ip_s_udpaudit="31337"
# Q: TCP service names or port numbers to allow on public interfaces:[ ]
Firewall.ip_s_publictcp="ssh 10000"
# Q: Force passive mode? [N]
Firewall.ip_s_passiveftp="N"
# Q: TCP services to block: [2049 2065:2090 6000:6020 7100]
Firewall.ip_s_tcpblock="2049 2065:2090 6000:6020 7100"
# Q: UDP services to block: [2049 6770]
Firewall.ip_s_udpblock="2049 6770"
# Q: ICMP allowed types: [destination-unreachable echo-reply time-exceeded]
Firewall.ip_s_icmpallowed="destination-unreachable echo-reply time-exceeded"
# Q: Enable source address verification? [Y]
Firewall.ip_s_srcaddr="Y"
# Q: Masqueraded networks: [ ]
Firewall.ip_s_ipmasq="192.168.0.0"
# Q: Kernel modules to masquerade: [ftp raudio vdolive]
Firewall.ip_s_kernelmasq="ftp raudio vdolive cuseeme irc quake user"
# Q: Reject method: [DENY]
Firewall.ip_s_rejectmethod="DENY"
# Q: Interfaces for DHCP queries: [ ]
Firewall.ip_s_dhcpiface="eth0"
# Q: ICMP types to disallow outbound: [destination-unreachable time-exceeded]
Firewall.ip_s_icmpout="destination-unreachable time-exceeded"
# Q: Should Bastille run the firewall and enable it at boot time? [N]
Firewall.ip_enable_firewall="Y"
# Q: Would you like to disable SUID status for mount/umount?
FilePermissions.suidmount="Y"
# Q: Would you like to disable SUID status for ping? [Y]
FilePermissions.suidping="N"
# Q: Would you like to disable SUID status for at? [Y]
FilePermissions.suidat="Y"
# Q: Would you like to disable SUID status for the r-tools? [Y]
FilePermissions.suidrtool="Y"
# Q: Would you like to disable SUID status for usernetctl? [Y]
FilePermissions.suidusernetctl="Y"
# Q: Would you like to disable SUID status for traceroute? [Y]
FilePermissions.suidtrace="Y"
# Q: May we take strong steps to disallow the dangerous r-protocols? [Y]
AccountSecurity.protectrhost="Y"
# Q: Would you like to enforce password aging? [Y]
AccountSecurity.passwdage="N"
# Q: Would you like to restrict the use of cron to administrative accounts? [Y]
AccountSecurity.cronuser="Y"
# Q: Should we allow root to login on tty's 1-6? [Y]
AccountSecurity.rootttylogins="Y"
# Q: Would you like to password-protect the LILO prompt? [N]
BootSecurity.protectlilo="N"
# Q: Would you like to reduce the LILO delay time to zero? [N]
BootSecurity.lilodelay="N"
# Q: Do you ever boot Linux from the hard drive? [Y]
BootSecurity.lilosub_drive="Y"
# Q: Would you like to write the LILO changes to a boot floppy? [N]
BootSecurity.lilosub_floppy="N"
# Q: Would you like to disable CTRL-ALT-DELETE rebooting? [N]
BootSecurity.secureinittab="N"
# Q: Would you like to password protect single-user mode? [Y]
BootSecurity.passsum="N"
# Q: Would you like to set a default-deny on TCP Wrappers and xinetd? [N]
SecureInetd.tcpd_default_deny="Y"
# Q: May we deactivate telnet? [y]
SecureInetd.deactivate_telnet="N"
# Q: May we deactivate ftp? [y]
SecureInetd.deactivate_ftp="Y"
# Q: Would you like to disable the compiler? [N]
DisableUserTools.compiler="N"
# Q: Would you like to put limits on system resource usage? [Y]
ConfigureMiscPAM.limitsconf="Y"
# Q: Should we restrict console access to a small group of user accounts? [N]
ConfigureMiscPAM.consolelogin="N"
# Q: Would you like to add additional logging? [Y]
Logging.morelogging="N"
# Q: Would you like to set up process accounting? [N]
Logging.pacct="N"
# Q: Would you like to deactivate the routing daemons? [Y]
MiscellaneousDaemons.routing="Y"
# Q: Do you want to leave sendmail running in daemon mode? [Y]
Sendmail.sendmaildaemon="Y"
# Q: Would you like to run sendmail via cron to process the queue? [N]
Sendmail.sendmailcron="N"
# Q: Would you like to disable the VRFY and EXPN sendmail commands? [Y]
Sendmail.vrfyexpn="Y"
# Q: Would you like to bind the web server to listen only to the localhost? [N]
Apache.bindapachelocal="N"
# Q: Would you like to bind the web server to a particular interface? [N]
Apache.bindapachenic="N"
# Q: Would you like to deactivate the following of symbolic links? [Y]
Apache.symlink="N"
# Q: Would you like to deactivate server-side includes? [Y]
Apache.ssi="N"
# Q: Would you like to disable CGI scripts, at least for now? [Y]
Apache.cgi="N"
# Q: Would you like to disable indexes? [N]
Apache.apacheindex="N"
# Q: Would you like to disable printing? [N]
Printing.printing="N"
# Q: Would you like to install TMPDIR/TMP scripts? [N]
TMPDIR.tmpdir="N"
Dit zijn de instellingen:
# Q: Would you like to run the packet filtering script? [N]
Firewall.ip_intro="Y"
# Q:
Firewall.ip_detail_level_kludge="Y"
# Q: Do you need the advanced networking options?
Firewall.ip_advnetwork="Y"
# Q: DNS servers: [0.0.0.0/0]
Firewall.ip_s_dns="0.0.0.0/0"
# Q: Trusted interface names: [lo]
Firewall.ip_s_trustiface="lo eth1"
# Q: Public interfaces: [eth+ ppp+ slip+]
Firewall.ip_s_publiciface="eth0 ppp+ slip+"
# Q: TCP services to audit: [telnet ftp imap pop-3 finger sunrpc exec login linuxconf ssh]
Firewall.ip_s_tcpaudit="telnet ftp imap pop-3 finger sunrpc exec login linuxconf ssh"
# Q: UDP services to audit: [31337]
Firewall.ip_s_udpaudit="31337"
# Q: TCP service names or port numbers to allow on public interfaces:[ ]
Firewall.ip_s_publictcp="ssh 10000"
# Q: Force passive mode? [N]
Firewall.ip_s_passiveftp="N"
# Q: TCP services to block: [2049 2065:2090 6000:6020 7100]
Firewall.ip_s_tcpblock="2049 2065:2090 6000:6020 7100"
# Q: UDP services to block: [2049 6770]
Firewall.ip_s_udpblock="2049 6770"
# Q: ICMP allowed types: [destination-unreachable echo-reply time-exceeded]
Firewall.ip_s_icmpallowed="destination-unreachable echo-reply time-exceeded"
# Q: Enable source address verification? [Y]
Firewall.ip_s_srcaddr="Y"
# Q: Masqueraded networks: [ ]
Firewall.ip_s_ipmasq="192.168.0.0"
# Q: Kernel modules to masquerade: [ftp raudio vdolive]
Firewall.ip_s_kernelmasq="ftp raudio vdolive cuseeme irc quake user"
# Q: Reject method: [DENY]
Firewall.ip_s_rejectmethod="DENY"
# Q: Interfaces for DHCP queries: [ ]
Firewall.ip_s_dhcpiface="eth0"
# Q: ICMP types to disallow outbound: [destination-unreachable time-exceeded]
Firewall.ip_s_icmpout="destination-unreachable time-exceeded"
# Q: Should Bastille run the firewall and enable it at boot time? [N]
Firewall.ip_enable_firewall="Y"
# Q: Would you like to disable SUID status for mount/umount?
FilePermissions.suidmount="Y"
# Q: Would you like to disable SUID status for ping? [Y]
FilePermissions.suidping="N"
# Q: Would you like to disable SUID status for at? [Y]
FilePermissions.suidat="Y"
# Q: Would you like to disable SUID status for the r-tools? [Y]
FilePermissions.suidrtool="Y"
# Q: Would you like to disable SUID status for usernetctl? [Y]
FilePermissions.suidusernetctl="Y"
# Q: Would you like to disable SUID status for traceroute? [Y]
FilePermissions.suidtrace="Y"
# Q: May we take strong steps to disallow the dangerous r-protocols? [Y]
AccountSecurity.protectrhost="Y"
# Q: Would you like to enforce password aging? [Y]
AccountSecurity.passwdage="N"
# Q: Would you like to restrict the use of cron to administrative accounts? [Y]
AccountSecurity.cronuser="Y"
# Q: Should we allow root to login on tty's 1-6? [Y]
AccountSecurity.rootttylogins="Y"
# Q: Would you like to password-protect the LILO prompt? [N]
BootSecurity.protectlilo="N"
# Q: Would you like to reduce the LILO delay time to zero? [N]
BootSecurity.lilodelay="N"
# Q: Do you ever boot Linux from the hard drive? [Y]
BootSecurity.lilosub_drive="Y"
# Q: Would you like to write the LILO changes to a boot floppy? [N]
BootSecurity.lilosub_floppy="N"
# Q: Would you like to disable CTRL-ALT-DELETE rebooting? [N]
BootSecurity.secureinittab="N"
# Q: Would you like to password protect single-user mode? [Y]
BootSecurity.passsum="N"
# Q: Would you like to set a default-deny on TCP Wrappers and xinetd? [N]
SecureInetd.tcpd_default_deny="Y"
# Q: May we deactivate telnet? [y]
SecureInetd.deactivate_telnet="N"
# Q: May we deactivate ftp? [y]
SecureInetd.deactivate_ftp="Y"
# Q: Would you like to disable the compiler? [N]
DisableUserTools.compiler="N"
# Q: Would you like to put limits on system resource usage? [Y]
ConfigureMiscPAM.limitsconf="Y"
# Q: Should we restrict console access to a small group of user accounts? [N]
ConfigureMiscPAM.consolelogin="N"
# Q: Would you like to add additional logging? [Y]
Logging.morelogging="N"
# Q: Would you like to set up process accounting? [N]
Logging.pacct="N"
# Q: Would you like to deactivate the routing daemons? [Y]
MiscellaneousDaemons.routing="Y"
# Q: Do you want to leave sendmail running in daemon mode? [Y]
Sendmail.sendmaildaemon="Y"
# Q: Would you like to run sendmail via cron to process the queue? [N]
Sendmail.sendmailcron="N"
# Q: Would you like to disable the VRFY and EXPN sendmail commands? [Y]
Sendmail.vrfyexpn="Y"
# Q: Would you like to bind the web server to listen only to the localhost? [N]
Apache.bindapachelocal="N"
# Q: Would you like to bind the web server to a particular interface? [N]
Apache.bindapachenic="N"
# Q: Would you like to deactivate the following of symbolic links? [Y]
Apache.symlink="N"
# Q: Would you like to deactivate server-side includes? [Y]
Apache.ssi="N"
# Q: Would you like to disable CGI scripts, at least for now? [Y]
Apache.cgi="N"
# Q: Would you like to disable indexes? [N]
Apache.apacheindex="N"
# Q: Would you like to disable printing? [N]
Printing.printing="N"
# Q: Would you like to install TMPDIR/TMP scripts? [N]
TMPDIR.tmpdir="N"
Mijn specs; Arm 47cm | Benchpress 175kg | Shotput 16,99m | BW 125kg