Firewall Wizards mailing list archives

RE: Altavista Firewall98 SP3 broken on DU40D


From: "Munroe, Peg" <Munroe () siast sk ca>
Date: Fri, 17 Dec 1999 09:35:49 -0600

Had a similar error with an upgrade to AV Firewall 97. I believe I was
missing the line  

pseudo-device gwscreen

in the kernel config file.

I've just upgraded to  AV FW 98/sp3 on DU40D/sp5 and it appears screend
isn't working properly on it either, although I do not get any errors on
startup. I just get flaky results with the proxies, and my client community
is suffering internet withdrawal...

...Peg Munroe
Wide Area Network Admin
SIAST Information Resources




----------
From:         Van Bemmel, Berend[SMTP:VanBemmel.Berend () kpmg nl]
Reply To:     Van Bemmel, Berend
Sent:         Wednesday, December 15, 1999 5:07 AM
To:   firewall-wizards () nfr net
Subject:      Altavista Firewall98 SP3 broken on DU40D

Hello,

I have made a test install of Altavista Firewall 98 on a DU40D box (with
and
without digital patch kit 5). After I install the firewall SP3 the screen
function on the ethernet devices is broken. The following message is shown
during boot:

  ioctl (SIOCSREENON): Operation not supported on socket
  Cannot set Screen Mode ON

This means that after aplying this service pack the machine no longer does
screening (packet filtering) and might even be acting as a router now
since
the forwarding on the firewall is (and should be?) on. This is fatal for
security afcourse!

Regular support through compaq and axent gave no help at all on this issue
so far (altough is looks pretty serious to me). Has anybody else seen this
and/or solved it?

btw. I need SP3 because in SP2 the generic proxies are broken in a very
bad
way (among some other stuff).

Cheers,

Berend W. van Bemmel


**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote also confirms that this email message has been swept by
MIMEsweeper for the presence of computer viruses.

www.mimesweeper.com
**********************************************************************




Current thread: