<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter posts tagged with firewall</title>
      <link>http://ask.metafilter.com/tags/firewall</link>
      <description>tag posts with firewall</description>
	  	  <pubDate>Mon, 21 Jul 2008 09:06:12 -0800</pubDate>
      <lastBuildDate>Mon, 21 Jul 2008 09:06:12 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>XP Filter:  I set up a non admin account for safer computing -- Am I safe enough now?</title>
	<link>http://ask.metafilter.com/97107/XP-Filter-I-set-up-a-non-admin-account-for-safer-computing-Am-I-safe-enough-now</link>	
	<description>I&apos;ve read so much here lately &lt;a href=&quot;http://ask.metafilter.com/90788/Help-me-make-a-PC-safe&quot;&gt;1&lt;/a&gt; &lt;a href=&quot;http://ask.metafilter.com/96996/How-safe-is-Firefox-20&quot;&gt;2&lt;/a&gt; &lt;a href=&quot;http://ask.metafilter.com/59546/do-the-right-thing-AND-know-what-day-it-is&quot;&gt;3&lt;/a&gt; about not browsing as an admin, decided to &lt;a href=&quot;http://lifehacker.com/software/windows-tip/quickly-check-if-youre-logged-in-as-administrator-255758.php&quot;&gt;check it out&lt;/a&gt; and yepper, I surely was using an admin account.  I&apos;ve set up a non admin account, made a few other changes (described inside), hoping to find out from The Hive Mind if I am now safe enough to breathe easy(er). Ya&apos;ll put the fear of computer death into me, I finally decided to check and yeah, I was doing it &lt;em&gt;wrong wrong wrong&lt;/em&gt;.  So I set about trying to get my mind (and puter) right in the eyes of The Hive Mind.&lt;br&gt;
&lt;br&gt;
I set up an account without Admin rights, and will use this for most everything from now on.&lt;br&gt;
&lt;br&gt;
I left both accounts without passwords because of reading &lt;a href=&quot;http://nonadmin.editme.com/RunningAsNonAdmin&quot;&gt;this post&lt;/a&gt; -- is this a good plan, or is this guy off the wall?&lt;br&gt;
&lt;br&gt;
I am using a fairly fresh XP install (maybe two months) and I&apos;m pretty sure I&apos;m still clean -- I&apos;ve run Spybot and AdAware, updated as needed, maybe every couple weeks.&lt;br&gt;
&lt;br&gt;
I&apos;m using AVG Anti-Virus Free and update it as it says it&apos;s needed.  &lt;br&gt;
&lt;br&gt;
I&apos;m using the ZoneAlarm free firewall -- I LOVE that it allows me to determine when software decides to &apos;call home&apos; and I get to decide -- Apple is pretty determined with this, I&apos;ve found, and so is Open Office, a few others.&lt;br&gt;
&lt;br&gt;
I&apos;ve got Windows Auto Update turned on but not to auto download and install -- I want it to prompt me and let me decide if and when.  &lt;br&gt;
&lt;br&gt;
I&apos;m using MS Windows Defender and upgrading as it suggests.&lt;br&gt;
&lt;br&gt;
I&apos;m using Firefox 3 upgraded automatically any time they suggest, and running AdBlock Plus and NoScript, updated when suggested.&lt;br&gt;
&lt;br&gt;
If any site gives me problems in Firefox, I first try Opera (updated as needed) and then IE7, last resort.  I run IE Tab through Firefox rather than firing up IE7, and I only use it on sites that demand IE7 (NetFlix, Sprint, a couple of others) -- I&apos;m hoping this helps me but I don&apos;t actually know if it adds safety or not.  I update IE7 as Windows Update suggests, pretty sure I&apos;m always current.&lt;br&gt;
&lt;br&gt;
I&apos;m using Foxit PDF rather than Adope bloatware.&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://ask.metafilter.com/90788/Help-me-make-a-PC-safe&quot;&gt;&quot;Aye&quot; suggested Disabliing all AutoRun and AutoPlay options with TweakUI&lt;/a&gt; (a Microsoft PowerToy) is this needed/wanted?&lt;br&gt;
&lt;br&gt;
What have I missed?  Where have I gone overboard?  I want safety but don&apos;t want to live locked down so hard I cannot move.&lt;br&gt;
&lt;br&gt;
Thanx in advance.&lt;br&gt;
&lt;br&gt;
Peace.&lt;br&gt;
&lt;br&gt;
dancestoblue</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.97107</guid>
	<pubDate>Mon, 21 Jul 2008 09:06:12 -0800</pubDate>

<category>XP</category>

<category>Windows</category>

<category>admin</category>

<category>useraccount</category>

<category>Firefox</category>

<category>IE7</category>

<category>browser</category>

<category>virus</category>

<category>malware</category>

<category>firewall</category>

	<dc:creator>dancestoblue</dc:creator>
	</item>
	<item>
	<title>Can I edit my Akismet plugin?</title>
	<link>http://ask.metafilter.com/96525/Can-I-edit-my-Akismet-plugin</link>	
	<description>Can I edit the Akismet plugin I use on my Wordpress blog? My host has a firewall which is preventing my Akismet plugin from working properly. They offered me a proxy address and number I can use instead, but I don&apos;t know how to get the plugin to use them. (Alternatively, can you recommend a good comment-spam catcher that won&apos;t run into firewall problems?) I&apos;ve asked the Akismet people for help with this, but they say they don&apos;t provide that level of service. &lt;br&gt;
&lt;br&gt;
I&apos;ve never modified a plug-in before, but would be happy to get my hands dirty if given clear instructions. &lt;br&gt;
&lt;br&gt;
My previous host had no problems with it (just terrible customer service).  I was really happy with how well Akismet worked, so I&apos;d prefer to keep it going if possible.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.96525</guid>
	<pubDate>Mon, 14 Jul 2008 04:08:22 -0800</pubDate>

<category>akismet</category>

<category>wordpress</category>

<category>firewall</category>

<category>php</category>

	<dc:creator>harriet vane</dc:creator>
	</item>
	<item>
	<title>Help me securely share folders across different networks</title>
	<link>http://ask.metafilter.com/95566/Help-me-securely-share-folders-across-different-networks</link>	
	<description>Help me share a folder across the internet without compromising my firewall I have a desktop at work with multiple hard drives and a large amount of data. Lately I have been working at several remote research sites and find the need to grab files from the desktop. So I shared some folders and restricted access to my username. The desktop has a static IP so the share works like so&lt;br&gt;
&lt;br&gt;
\\ip.add.re.ss\share_name&lt;br&gt;
&lt;br&gt;
so far so good. Zone alarm [on the desktop], however, denies access when I am on a different network. I&apos;ve talked to the IT admins at a few of my research sites and entered those IP ranges into my trusted zone but it would be impossible for me to cover every single site (and the occasional coffee shop in the middle of nowhere). What can I do to get around this?&lt;br&gt;
&lt;br&gt;
Sharing works perfectly when zone alarm is turned off. I could, for example, enter 1.1.1.1 to 255.255.255.255 as a trusted range but that would defeat the purpose of having the firewall. I&apos;m stumped.&lt;br&gt;
&lt;br&gt;
Both computers run XP</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.95566</guid>
	<pubDate>Wed, 02 Jul 2008 10:04:46 -0800</pubDate>

<category>firewall</category>

<category>sharing</category>

<category>folder</category>

<category>xp</category>

<category>resolved</category>

	<dc:creator>special-k</dc:creator>
	</item>
	<item>
	<title>My company&apos;s firewall is blocking my website.  Is there anything I can do on my end to fix this?</title>
	<link>http://ask.metafilter.com/91895/My-companys-firewall-is-blocking-my-website-Is-there-anything-I-can-do-on-my-end-to-fix-this</link>	
	<description>My company&apos;s firewall is blocking my website.  Is there anything I can do on my end to fix this? (Be kind, I am a website newb.)  Up until last week, I had no problems accessing my website or its cPanel admin from work.  Now I just get a timed out error even when I just try to load the page (or something of that effect--can&apos;t remember the exact wording.)&lt;br&gt;
&lt;br&gt;
My work is pretty laid back about web surfing during breaks/lunch, etc., and I have never had any problems accessing any other sites (flickr, myspace, youtube) so what could possibly be so bad about my site that they would block it?  It&apos;s just a simple online portfolio.&lt;br&gt;
&lt;br&gt;
My hosting company says that it is because the firewall is blocking the port the cPanel is on and apparently a lot of companies view it as an insecure port?  They said the only thing I could do is request that my company allow it.&lt;br&gt;
&lt;br&gt;
I don&apos;t really want to go that far just to access a personal website from work (I mean, I do have real work to be doing :) but I guess my bigger concern is that if our firewall is blocking it, how many others are as well?  I didn&apos;t even realize that the reason I couldn&apos;t access it was because of the firewall, I just thought the server was down or something.  If other people experience the same thing, might they just think I have an unreliable site?&lt;br&gt;
&lt;br&gt;
Are there any changes I should make to make it more firewall-friendly?  Sorry if these are totally dumb questions, but I am totally new at this website stuff.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.91895</guid>
	<pubDate>Tue, 20 May 2008 07:29:34 -0800</pubDate>

<category>firewall</category>

<category>website</category>

	<dc:creator>Anonymous</dc:creator>
	</item>
	<item>
	<title>Yoggie Pico</title>
	<link>http://ask.metafilter.com/90059/Yoggie-Pico</link>	
	<description>Will &lt;a href=&quot;http://www.linuxdevices.com/articles/AT8368967523.html&quot;&gt;this cute little firewall device&lt;/a&gt; work well with a small Server 2003 domain setup? Found via the always-fun Gadget Show.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.90059</guid>
	<pubDate>Tue, 29 Apr 2008 02:14:37 -0800</pubDate>

<category>yoggie</category>

<category>pico</category>

<category>linux</category>

<category>firewall</category>

	<dc:creator>chuckdarwin</dc:creator>
	</item>
	<item>
	<title>Trying to stream at work</title>
	<link>http://ask.metafilter.com/88736/Trying-to-stream-at-work</link>	
	<description>How can I listen to NPR on my office PC when audio/video streaming is not allowed? I cannont get streaming audio from npr.org.  Nor can I get video from the usual sources, cnn.com, etc.  Oddly, I can get streaming audio from &lt;a href=&quot;http://projectvibe.net/&quot;&gt;Project Vibe&lt;/a&gt; by setting the &quot;listen now&quot; properties to &quot;Hi Bandwith (FM quality)&quot; and &quot;Stand Alone Windows Media.&quot;&lt;br&gt;
&lt;br&gt;
How can I replicate this process so that I can listen to NPR?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.88736</guid>
	<pubDate>Mon, 14 Apr 2008 07:28:40 -0800</pubDate>

<category>stream</category>

<category>streaming</category>

<category>audio</category>

<category>projectvibe</category>

<category>npr</category>

<category>firewall</category>

	<dc:creator>Juicylicious</dc:creator>
	</item>
	<item>
	<title>&quot;Reverse&quot; firewall testing?</title>
	<link>http://ask.metafilter.com/88488/Reverse-firewall-testing</link>	
	<description>Simply put, I would like to determine which (outgoing) ports are open and which are closed on my company&apos;s network. They have a firewall blocking most ports...so far I can only get through port 80 and port 443.  I know for example, ports 23, 25, 110 and 6667 are blocked.

So I may be over-thinking this, but what I think I need to do is find a way to listen on all ports (or at least a select list) on an external computer, then scan that computer&apos;s IP from inside the network to see what connects...

The catch: I would like to open these ports for connections without having to install servers that actually use those ports. If we&apos;re talking a couple hundred ports, I don&apos;t want to install and configure a couple hundred server apps. (or all 65535?)

Does anyone know of an app that will open &apos;fake&apos; ports on a system and respond with some sort of generic server type?

I know I&apos;ve seen such an app before, but I just don&apos;t remember what it was called, and my google skillz are not coming through this time.

Side note: I originally thought what I was looking for was a &quot;leak tester&quot; ...but this isn&apos;t quite right, as it is testing incoming ports, not outgoing ports.

Thanks,</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.88488</guid>
	<pubDate>Thu, 10 Apr 2008 20:30:09 -0800</pubDate>

<category>firewall</category>

<category>security</category>

	<dc:creator>AltReality</dc:creator>
	</item>
	<item>
	<title>New software for a new computer?</title>
	<link>http://ask.metafilter.com/84392/New-software-for-a-new-computer</link>	
	<description>I&apos;m setting up my spankin&apos; new computer.  So far I&apos;ve downloaded AVG as my anti-virus solution, but I&apos;m not sure which way to go for anti-spyware.   Is Ad-Aware still any good?  Should I use ZoneAlarm (which doesn&apos;t play nice with Adaware), or is there something better?  And does anyone have experience with AVG&apos;s anti-spyware setup?  I realize that ZoneAlarm serves more of a &quot;firewall&quot; niche, so input / corrections are appreciated.  Anyone have experience with AVG&apos;s anti-spyware solution?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.84392</guid>
	<pubDate>Sat, 23 Feb 2008 08:39:31 -0800</pubDate>

<category>security</category>

<category>newcomputer</category>

<category>avg</category>

<category>zonealarm</category>

<category>avast!</category>

<category>adaware</category>

<category>lavasoft</category>

<category>firewall</category>

<category>spyware</category>

	<dc:creator>&#xae;@</dc:creator>
	</item>
	<item>
	<title>That&apos;s not art, that&apos;s my firewall!</title>
	<link>http://ask.metafilter.com/80056/Thats-not-art-thats-my-firewall</link>	
	<description>How do you draw a picture depicting firewall rules? Do you know of any examples? I&apos;m looking for a way to depict firewall rules as a picture or graph, sort of like a network diagram. Can you point me to examples or documentation on standard ways of depicting firewall rules graphically?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.80056</guid>
	<pubDate>Thu, 03 Jan 2008 10:05:41 -0800</pubDate>

<category>network</category>

<category>firewall</category>

<category>graphing</category>

	<dc:creator>grumpy</dc:creator>
	</item>
	<item>
	<title>Take me to Mac network security school.</title>
	<link>http://ask.metafilter.com/77940/Take-me-to-Mac-network-security-school</link>	
	<description>I noticed this morning in my system logs that I had some failed FTP and SSH login attempts from an IP in China.  I thought I was going to have get all Cliff Stoll on this guy, but then looking back further I saw that this has been happening for months, from lots of different IP addresses. I&apos;m many things, but I have never claimed to be a network guy.  I know my way around the command line, for the most part, but after the basic network utilities, I&apos;m done.  Further, I&apos;ve been pretty lax with network security, generally having a &quot;wouldn&apos;t happen to me&quot; sort of attitude about hackers.  That being said, I admittedly have a very insecure setup between the outside world and my computer.  My router is set with DMZ to my computer, so I can get to it easily. I have web sharing, remote desktop, ssh, ftp, and afp enabled -- and use all of them regularly.  Up until about half an hour ago, I also had my software firewall disabled.&lt;br&gt;
&lt;br&gt;
On the other hand, fortunately, my passwords are strong, and the root account isn&apos;t enabled.&lt;br&gt;
&lt;br&gt;
After seeing the mountain of failed login attempts, I&apos;ve become a little more paranoid, and would like to be more cautious.  A few questions, though:&lt;br&gt;
&lt;br&gt;
1.  These people trying to break in, do you they just do pings of a range of IP addresses until one responds, and then have a program that just tries a whole lot of logins/passwords at that IP?  I see lots of attempts for Administrator, root, and mysql, but there are also attempts for random ones like &apos;raphael&apos;.  What&apos;s the deal?&lt;br&gt;
&lt;br&gt;
2.  I have test users on my system for debug purposes, some of them with admin rights.  Is there any way to disallow these users to log in with ftp and ssh?  How paranoid should I be?   &lt;br&gt;
&lt;br&gt;
3.  I&apos;d still like to be able to access my computer from the outside world using the same services I have been before, but I&apos;m thinking I should start using my firewall properly, and take off DMZ and enable port forwarding instead, right?  Question is, how is this any better at preventing break in attempts?  If I can get in here from the outside, they could too, right?&lt;br&gt;
&lt;br&gt;
Any other tips, suggested readings, or words of wisdom?  School me.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.77940</guid>
	<pubDate>Wed, 05 Dec 2007 18:12:01 -0800</pubDate>

<category>security</category>

<category>macosx</category>

<category>mac</category>

<category>firewall</category>

<category>ftp</category>

<category>ssh</category>

	<dc:creator>jeffxl</dc:creator>
	</item>
	<item>
	<title>Anti-virus compartions and Vista Firewall?</title>
	<link>http://ask.metafilter.com/75999/Antivirus-compartions-and-Vista-Firewall</link>	
	<description>Where can I find detailed information on anti-virus software comparisons? I&apos;ve heard of and seen some charts that display details such as catch rates and etc but have never known the exact source. Something like this perhaps: http://virus.untangle.com/ but a more broad spectrum, preferablly one that includes AVG and Avast!

Also what is the best firewall for Windows Vista?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.75999</guid>
	<pubDate>Sun, 11 Nov 2007 14:44:28 -0800</pubDate>

<category>anti-virus</category>

<category>virus</category>

<category>security</category>

<category>firewall</category>

<category>networking</category>

<category>vista</category>

	<dc:creator>meta.mark</dc:creator>
	</item>
	<item>
	<title>IMAP proxying help needed</title>
	<link>http://ask.metafilter.com/75502/IMAP-proxying-help-needed</link>	
	<description>My work&apos;s firewall recently began blocking outbound traffic that isn&apos;t on ports 22, 80, and 443, and I&apos;d like to use my home router (running openwrt) to proxy my personal IMAP email so I can read it from work. I&apos;m pretty network and linux-savvy, but I haven&apos;t really tried this out before, so I thought I&apos;d solicit some advice.  What I figure is that I&apos;ll point to my home address via dyndns or the like and then, for requests originating from my work subnet, forward the requests on to my ISP&apos;s imap server.  Here&apos;s some k-R4d ascii art to illustrate what I&apos;m going for:&lt;br&gt;
&lt;pre&gt;[work PC] ----&amp;gt; [work firewall] ---&amp;gt; [home router] ---&amp;gt;      [isp]&lt;br&gt;
pc.work.com     fw.work.com          myrouter.dyndns.org     imap.isp.net&lt;br&gt;
&lt;/pre&gt;&lt;br&gt;
So on my router, I want to forward requests for router.dyndns.org:443 to imap.isp.net:143.&lt;br&gt;
&lt;br&gt;
I&apos;m running the latest version of Thunderbird as an email client.  At home I have OpenWRT running on a Linksys WRT54G (it&apos;s running the release before kamikaze, IIRC, but I can upgrade it easily enough if I need to).  I&apos;d like to run whatever software I need to on the router itself, so I don&apos;t need to keep a machine in my home network on all the time and poke a hole in my home firewall.&lt;br&gt;
&lt;br&gt;
Has anyone had experience with doing this?  In particular I&apos;m wondering if the IMAP protocol itself involves my client sending out its own IP address (pc.work.com) and then confusing the IMAP server at imap.isp.net, which should actually be talking to myrouter.dyndns.org.&lt;br&gt;
&lt;br&gt;
My iptables skills are a little rusty, so if anyone has specific examples of the commands to use, I&apos;d be grateful.&lt;br&gt;
&lt;br&gt;
Also, could someone tell me if there&apos;s a better solution than just forwarding the raw TCP traffic?  Is this something setting up a SOCKs server on myrouter.dnydns.org could solve?  I do have one other IMAP account I&apos;d like to access if I could, and I wouldn&apos;t mind getting around my workplace&apos;s HTTP content filters if I can do so easily.  Neither one of these concerns is a big deal, though - mostly I just want to be able to access my personal email account.  And now that I&apos;m thinking about it, I&apos;d like to be able to send SMTP mail from pc.work.com through my ISP if I can, too, without letting spammers use my router for nefarious purposes.&lt;br&gt;
&lt;br&gt;
I&apos;ve also seen some linux software out there specifically for proxing imap (called &quot;imapproxy&quot; or something?), but I didn&apos;t see a version compiled for openwrt specifically - I&apos;m not adverse to setting up a wrt toolchain if I need to, but I&apos;d rather not spend time on that if there&apos;s an easier way.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.75502</guid>
	<pubDate>Mon, 05 Nov 2007 12:01:58 -0800</pubDate>

<category>proxy</category>

<category>imap</category>

<category>openwrt</category>

<category>routing</category>

<category>firewall</category>

<category>email</category>

<category>networking</category>

<category>tcp</category>

<category>tcpip</category>

	<dc:creator>whir</dc:creator>
	</item>
	<item>
	<title>Bizarre Linux Networking Problem</title>
	<link>http://ask.metafilter.com/72794/Bizarre-Linux-Networking-Problem</link>	
	<description>I have a server running Centos 5. It&apos;s currently refusing outside connections to any port except port 22. ip-tables and SELinux are both disabled. Whiskey Tango Foxtrot? By outside connections, I mean any connection that&apos;s not localhost. So, for example, I can telnet to localhost port 25, but from a machine on the same subnet (255.255.255.0) it refuses the connection. I&apos;ve also checked /etc/hosts.allow and /etc/hosts.deny, both are empty and in xinetd.conf no_access and only_from remain unset.&lt;br&gt;
&lt;br&gt;
Seriously guys, I&apos;m sure I&apos;m missing something really stupid, but I&apos;m baffled at the moment.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.72794</guid>
	<pubDate>Mon, 01 Oct 2007 16:13:23 -0800</pubDate>

<category>unix</category>

<category>centos</category>

<category>networking</category>

<category>firewall</category>

<category>linux</category>

<category>tcp-ip</category>

	<dc:creator>signalnine</dc:creator>
	</item>
	<item>
	<title>Help me bypass the great firewall of China?</title>
	<link>http://ask.metafilter.com/71568/Help-me-bypass-the-great-firewall-of-China</link>	
	<description>I&apos;m having trouble with people accessing my server from within China. Maybe you can help me bypass the great firewall? The full scoop:&lt;br&gt;
&lt;br&gt;
I run the web/email server for my wife&apos;s small family business. There are some employees here in the states, and some in China. The server itself is located in Texas. The folks here in the states never have any trouble accessing the server for email/web/etc, but the folks in China have intermittent access to the server in general. I&apos;m most concerned about the email access, for what it&apos;s worth. I run pop3 off ports 25 and 26, with SSL available. I have tried using both with SSL and without on the china clients with no difference in performance.&lt;br&gt;
&lt;br&gt;
During the times when it&apos;s down, I can&apos;t even ping the server from the computers in china. Doing a traceroute just shows stars (timeout) after the first hop or so. I&apos;m guessing we&apos;re running into the &quot;great firewall of China&quot;.&lt;br&gt;
&lt;br&gt;
The server has it&apos;s own (4) dedicated IP&apos;s, so we&apos;re not sharing with any other website that may be controversial - although there may be some websites in our local subnet that are being blocked (i&apos;m not sure). &lt;br&gt;
&lt;br&gt;
The employees in china aren&apos;t very technically adept, so I can&apos;t have any solutions that require technical knowledge on a frequent basis - but i do have access to their computers remotely and can setup any kind of software/settings as needed. The computers over in china are running Windows XP.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.71568</guid>
	<pubDate>Fri, 14 Sep 2007 13:51:25 -0800</pubDate>

<category>firewall</category>

<category>china</category>

<category>server</category>

	<dc:creator>escher</dc:creator>
	</item>
	<item>
	<title>filter/firewall new workaround?</title>
	<link>http://ask.metafilter.com/70684/filterfirewall-new-workaround</link>	
	<description>Please help me see if this gets around filters/ firewalls at work school. If you are blocked from cerain sites at work / school can you see if this works: Go here&lt;br&gt;
&lt;br&gt;
http://www.t-mobile.co.uk/services/mobile-tv-video-services/mobile-tv/webnwalk-demos/&lt;br&gt;
&lt;br&gt;
Click on a phone and then then surf the web through a virtual demo phone.&lt;br&gt;
&lt;br&gt;
I would be especially keen to see if this gets past the &quot;Gt. Firewall&quot;. You know what that is is you suffer with it.&lt;br&gt;
&lt;br&gt;
BTW I am not on T-mobile and have no links to them I just want to see if it is a new workaround.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.70684</guid>
	<pubDate>Mon, 03 Sep 2007 11:23:51 -0800</pubDate>

<category>firewall</category>

	<dc:creator>priorpark17</dc:creator>
	</item>
	<item>
	<title>Bandwidth throttling / traffic shaping on Fedora Core 6</title>
	<link>http://ask.metafilter.com/69920/Bandwidth-throttling-traffic-shaping-on-Fedora-Core-6</link>	
	<description>How do you set up bandwidth throttling / traffic shaping on Fedora Core 6? We have at server here at the office running Fedora Core 6. The server is mainly used as a Web and file sharing server. (I.e.: It is not used as an network authentication server or as a DHCP server.)&lt;br&gt;
&lt;br&gt;
The servers, including that one, and all our workstations are all connected to a switch, then a small D-Link router, the DSL modem, and finally, of course, the Internet. We run test Web sites on our server which clients can access from the outside.&lt;br&gt;
&lt;br&gt;
We are trying to limit how much outgoing bandwidth the server can use when a client connects to our server. We only have one DSL line for now, and with 15 people on the network, things can get slow. When clients connect to our server, it doesn&apos;t help.&lt;br&gt;
&lt;br&gt;
I tried setting up bandwidth throttling / traffic shaping on the Fedora Core 6 server. First, how do you call it? &quot;Bandwidth throttling&quot; or &quot;traffic shaping&quot;?&lt;br&gt;
&lt;br&gt;
After a read a bit of documentation about iproute, shorewall, iptables, and trickle, frankly, I&apos;m more at a loss than before. Is it possible to just use iptables to set it up? We also have Webmin installed on it -- can I do it with that? Any recommendations?&lt;br&gt;
&lt;br&gt;
Any help would be appreciated. Thanks in advance!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.69920</guid>
	<pubDate>Thu, 23 Aug 2007 05:42:49 -0800</pubDate>

<category>iptables</category>

<category>firewall</category>

<category>bandwidth</category>

<category>fedoracore6</category>

<category>linux</category>

	<dc:creator>remi</dc:creator>
	</item>
	<item>
	<title>Cisco PIX 501 Firewall</title>
	<link>http://ask.metafilter.com/69690/Cisco-PIX-501-Firewall</link>	
	<description>Can the Cisco PIX 501 be upgraded with any firmware so that it is IP Version 6 (IPv6) Compatible? We have a Cisco PIX 501 as seen in the link below...&lt;br&gt;
&lt;br&gt;
&lt;a&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/ps2031/index.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Is there any way for the firmware to be upgraded so that it is IP Version 6 (IPv6) Compatible?  If not, is there a comparable router that we can purchase that is?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.69690</guid>
	<pubDate>Mon, 20 Aug 2007 05:14:45 -0800</pubDate>

<category>Network</category>

<category>networking</category>

<category>internet</category>

<category>firmware</category>

<category>hardware</category>

<category>router</category>

<category>firewall</category>

	<dc:creator>kaozity</dc:creator>
	</item>
	<item>
	<title>How do I SFTP over an HTTP proxy with a mac?</title>
	<link>http://ask.metafilter.com/67685/How-do-I-SFTP-over-an-HTTP-proxy-with-a-mac</link>	
	<description>I have a Mac running OSX and use programs like Coda and Transmit to send out files. However, on certain networks, the only access I have to the net is via an http proxy (with no https, even!) . 

I understand there are ways to tunnel sftp over http but could not find an easy guide (or set of tools) to do so in a way where I can attach such tunneling to one profile (ie. CUSTOMER or WORK) and not have the proxying happen on another profile (ie. HOME) The challenge comes from the fact that the network is so clamped down that the http way is the only way (the good news is that it&apos;s on port 8090 and that windows applications seem to be able to proxy over 8090 without restrictions)&lt;br&gt;
&lt;br&gt;
What I&apos;m looking for is a WYSIWYG software package that would allow me to easily establish a link from my sftp client to tunnel over the http port back out to the Internet (and possibly also tunnel things like Skype over that http proxy)&lt;br&gt;
&lt;br&gt;
Any ideas?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.67685</guid>
	<pubDate>Tue, 24 Jul 2007 07:15:46 -0800</pubDate>

<category>mac</category>

<category>osx</category>

<category>proxy</category>

<category>tunnel</category>

<category>firewall</category>

	<dc:creator>TNLNYC</dc:creator>
	</item>
	<item>
	<title>How To Admin my Home Mac from Work Windows! Proxies and Firewalls Everywhere!</title>
	<link>http://ask.metafilter.com/66985/How-To-Admin-my-Home-Mac-from-Work-Windows-Proxies-and-Firewalls-Everywhere</link>	
	<description>I need a little help setting up remote admin (VNC) access for Mac OS X 10.4.10 from a Windows client at work. Firewalls on both ends, significant port restrictions at work, and FYI, I&apos;ve googled this into the ground. The closest I&apos;ve come to something useful is &lt;a href=&quot;http://www.macosxhints.com/article.php?story=20051102173302946&amp;query=remote%2Badmin%2Bwindows%2Bmac&quot;&gt;this post,&lt;/a&gt; &lt;a href=&quot;http://www.macosxhints.com/article.php?story=20070302234400232&amp;query=mac%2Bos%2Bport%2Bforwarding&quot;&gt;this post,&lt;/a&gt; and &lt;a href=&quot;http://www.macosxhints.com/article.php?story=20050429153115383&quot;&gt;this one&lt;/a&gt; on MacOSXHints.com, but a lot (read: most) of the crucial concepts are just not sinking in for some reason. Hope Me!&lt;br&gt;
&lt;br&gt;
Here&apos;s my setup:&lt;br&gt;
&lt;br&gt;
1 - Mac OS Tiger computer (acting as a file server) in my home router&apos;s DMZ with SSH and Remote Access turned on in the Preferences. Complicating note: I&apos;m presenting SSH over both port 22 and port 443 for reason listed below. &lt;br&gt;
&lt;br&gt;
2 - Windows XP Pro desktop at work with local system admin privileges in place. I have both Putty and UltraVNC installed and running. Our proxy only allows outbound connections from ports 80 and 443, hence the complication at home.  No big deal, only took about 2 hours and much hair pulling to figure out.&lt;br&gt;
&lt;br&gt;
3 - Have successfully set up a DynDNS.org account pointing to my home IP, no problem.&lt;br&gt;
&lt;br&gt;
Right now, I can connect from work with a Putty session via myurl.blah.blah:443 (to get through my proxy) and it works fine. W00t! I&apos;m badly stuck at the next step, though; how do I then successfully connect with a VNC client from work to port 5900 on the home Macintosh?&lt;br&gt;
&lt;br&gt;
Other notes: I have remote access to my desktop at work via RDP using a Java implementation of a Citrix client, which works fine, so I can accomplish all of my config and testing from home. Which is pretty cool, if you ask me.&lt;br&gt;
&lt;br&gt;
Thanks in advance, all.&lt;br&gt;
&lt;br&gt;
(I know I &lt;a href=&quot;http://www.metafilter.com/activity/26386/posts/ask/&quot;&gt;ask a lot of questions,&lt;/a&gt; but my life is so much better thanks to ask.me.  Y&apos;all rock.)</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.66985</guid>
	<pubDate>Sat, 14 Jul 2007 11:14:26 -0800</pubDate>

<category>macosx</category>

<category>10.4.10</category>

<category>remote</category>

<category>admin</category>

<category>ssh</category>

<category>proxy</category>

<category>firewall</category>

<category>windows</category>

<category>client</category>

	<dc:creator>ZakDaddy</dc:creator>
	</item>
	<item>
	<title>Quis custodiet ipsos custodes?</title>
	<link>http://ask.metafilter.com/64169/Quis-custodiet-ipsos-custodes</link>	
	<description>IT is taking my work computer for an hour tomorrow for something called &quot;Domain Migration&quot;.  Is there a way to find out exactly what they&apos;re doing? &lt;old company 1&gt; and &lt;old company 2&gt; are being fully combined as &lt;new company&gt; - so it&apos;s entirely understandable that they want some more consistency with the networking stuff.  They say they need my computer &quot;in order to connect to the new domain from the network&quot;, and I believe them (mostly), but I&apos;m still a little paranoid that they&apos;re going to start looking over my shoulder.  &lt;br&gt;
&lt;br&gt;
Is there any way to tell, or anything I should do in anticipation?&lt;/old&gt;&lt;/old&gt;&lt;/new&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.64169</guid>
	<pubDate>Tue, 05 Jun 2007 16:29:18 -0800</pubDate>

<category>domain</category>

<category>migration</category>

<category>firewall</category>

	<dc:creator>puddleglum</dc:creator>
	</item>
	<item>
	<title>Advanced Network Routing</title>
	<link>http://ask.metafilter.com/61411/Advanced-Network-Routing</link>	
	<description>Is it possible to configure a Mac OS X Server to route incoming and outgoing traffic via two different interfaces? Here&#8217;s the problem:  we have an Xserve providing various services to a small, company-wide network.  Among other services, it handles DNS, DHCP, and NAT, and acts as the gateway through an asymmetric DSL connection to the Internet.  We&#8217;ve recently begun noticing extremely high latency (over 1000ms,) with no appreciable degradation in download throughput (generally better than 3 Mib/s, as good as 6 Mib/s.)  We seem to have finally diagnosed the source of the latency:  our pitiful upstream is being saturated by larger uploads at just over 384 kib/s.&lt;br&gt;
&lt;br&gt;
Is it possible, using ipfw/dummynet or some other tools, to filter packets destined to travel out on this interface, and reroute them through a secondary interface dedicated to uploading?  Can return traffic still be delivered via the primary interface?&lt;br&gt;
&lt;br&gt;
Any other possible solutions are also welcome.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.61411</guid>
	<pubDate>Thu, 26 Apr 2007 12:37:26 -0800</pubDate>

<category>mac</category>

<category>server</category>

<category>ipfw</category>

<category>firewall</category>

<category>nat</category>

<category>internet</category>

<category>networking</category>

	<dc:creator>ijoshua</dc:creator>
	</item>
	<item>
	<title>Good, free firewalls.</title>
	<link>http://ask.metafilter.com/61368/Good-free-firewalls</link>	
	<description>What&apos;s a good, free firewall I can use on my home PC (running WindowsXP SP2) that &lt;i&gt;isn&apos;t&lt;/i&gt; Zone Alarm Pro, Sygate or Kerio? I currently use the last free version of the Sygate firewall. It&apos;s great and seems to protect my system from attacks well enough (as far as I can tell) but I&apos;m thinking that it&apos;s probably going to start becoming ridiculously obsolete soon (if it isn&apos;t hopelessly so already). So I need a new, preferably free firewall solution for my home computer which is linked via an Ethernet cable to one other home computer.&lt;br&gt;
&lt;br&gt;
I don&apos;t want to use Zone Alarm Pro, for the simple reason that it doesn&#8217;t get on with Nintendo&apos;s Wi-Fi service. So I suppose one other feature that I&apos;d like to see this new firewall use would be compatibility with that service.&lt;br&gt;
&lt;br&gt;
I&apos;ve tried Kerio, but I didn&apos;t like it. Maybe I didn&apos;t configure it correctly when I used it or something, but within a day or so of running it my system had collected more spyware than you could shake a stick at, something which simply hadn&apos;t happened under Sygate. It got so bad that I had to actually restore my Windows installation to a restore point from before Kerio was installed! So sufficed to say, it was a bad experience and I don&#8217;t intend to repeat the Kerio experiment again.&lt;br&gt;
&lt;br&gt;
If there aren&apos;t any free firewalls out there that are worth using, I&apos;d be happy to hear a few recommendations for low cost firewall solutions, but as I&apos;m sure many here would agree, free is pretty much always better.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.61368</guid>
	<pubDate>Wed, 25 Apr 2007 21:12:02 -0800</pubDate>

<category>firewall</category>

<category>security</category>

<category>internet</category>

<category>nintendo</category>

<category>wi-fi</category>

<category>wii</category>

<category>DS</category>

	<dc:creator>Effigy2000</dc:creator>
	</item>
	<item>
	<title>And why isn&apos;t it enabled by default, Steve?</title>
	<link>http://ask.metafilter.com/60416/And-why-isnt-it-enabled-by-default-Steve</link>	
	<description>This is so embarrassing. I&apos;d post it anonymously if I didn&apos;t think I&apos;d have to provide more info. Anyway...I set up my new iMac last night and didn&apos;t even &lt;i&gt;think&lt;/i&gt; about the firewall &apos;til this afternoon. So it was off for something like 12 hours of broadband, static-IP connectedness to the Net. How hosed am I, and is there anything I can do to put some or all of the horses back in the barn?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.60416</guid>
	<pubDate>Wed, 11 Apr 2007 13:34:03 -0800</pubDate>

<category>osx</category>

<category>firewall</category>

<category>damage_control</category>

	<dc:creator>bricoleur</dc:creator>
	</item>
	<item>
	<title>Need new internet security programs</title>
	<link>http://ask.metafilter.com/53366/Need-new-internet-security-programs</link>	
	<description>I need advice for buying a new internet security suite (or individual programs). For the past few years I&apos;ve been using McAfee Internet Security Suite, buying a new version each year to keep up to date, and getting 12 months of virus updates. However, I&apos;ve just read some troubling reviews of McAfee Internet Security Suite 2007 and am thinking I might want to go with something else. I&apos;ve had bad luck with Norton products in the past but will keep an open mind. I like the ease of a suite of products for anti-virus, firewall, anti-spam, etc. but I&apos;m willing to consider separate products. Ease of use wins out over price. Think of this question like, what would you recommend to your mother, and you can&apos;t be there to keep it running right all the time. My computer is Windows XP Media Center Edition. And how much trouble will I have uninstalling my current McAfee Security Suite 2006 if I switch to something else?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.53366</guid>
	<pubDate>Sun, 17 Dec 2006 12:48:58 -0800</pubDate>

<category>internet</category>

<category>security</category>

<category>suite</category>

<category>McAfee</category>

<category>antivirus</category>

<category>firewall</category>

	<dc:creator>Joleta</dc:creator>
	</item>
	<item>
	<title>ssh tunnel - allow remote connections on remote side?</title>
	<link>http://ask.metafilter.com/52931/ssh-tunnel-allow-remote-connections-on-remote-side</link>	
	<description>How can I allow remote connections to the remote side of my ssh tunnel? -g doesn&apos;t work. Neither does GatewayPorts. The situation: INSIDE---FIREWALL---OUTSIDE.  The possible connection is ssh from INSIDE to OUTSIDE.  I want to run a service on port 8080 of INSIDE. I want everybody in the world to be able to access it by connecting to OUTSIDE:8080.&lt;br&gt;
&lt;br&gt;
ssh -R8080:localhost:8080 OUTSIDE &lt;b&gt;does not work&lt;/b&gt; - that binds the 127.0.0.1 interface of OUTSIDE, not its public interface ... that is, only OUTSIDE itself can connect to its own port 8080.&lt;br&gt;
&lt;br&gt;
Putting &apos;GatewayPorts yes&apos; in OUTSIDE&apos;s /etc/ssh_config doesn&apos;t help.&lt;br&gt;
&lt;br&gt;
I successfully solved the problem by embedding one tunnel in another - tunneling an ssh port from INSIDE to OUTSIDE, like this:&lt;br&gt;
INSIDE$ ssh -R12345:INSIDE:22 OUTSIDE&lt;br&gt;
OUTSIDE$ ssh -p 12345 -L8080:INSIDE:8080 localhost&lt;br&gt;
&lt;br&gt;
but that seems unnecessarily contrived, and is highly inefficient. &lt;br&gt;
&lt;br&gt;
Can anyone help?&lt;br&gt;
&lt;br&gt;
Extra possibly vital information: INSIDE is Mac OS X, OUTSIDE is Windows XP running an up-to-date Cygwin.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.52931</guid>
	<pubDate>Mon, 11 Dec 2006 20:42:09 -0800</pubDate>

<category>ssh</category>

<category>firewall</category>

<category>tunnel</category>

<category>resolved</category>

	<dc:creator>dmd</dc:creator>
	</item>
	
	</channel>
</rss>

