Toggle Sidebar
News Feed
  • Nick Howitt
    Nick Howitt replied to a discussion, I can't install Web-proxy

    Try doing a "yum clean all". What do you get from "yum repolist"? You can probably disable the clearos-contribs repo anyway as it is not enabled by default in 6.x.

    FWIW 6.x is end of life and has not had any updated for nearly a year now. Can I suggest upgrading to 7.x?

  • Can I suggest you look at the troubleshooting section of the app documentation?

  • Nick Howitt

    Have a look at the OpenVPN config file /etc/openvpn/clients.conf. In the short term moving everything across will work when you move it across, but what happens when you need a new user? the CA is in ClearOS so you will need to create his/her certificate there. Also at some point the server certificate will need to be regenerated (but not the CA) to get round what is current a warning in the connection log "WARNING: --ns-cert-type is DEPRECATED. Use --remote-cert-tls instead.". This will have to happen before the OpenVPN 2.5 client is released.

  • Nick Howitt
    Nick Howitt replied to a discussion, iptables rules

    You need a rule each for tcp and udp. You cannot do a port rule without a protocol.
    In general communication is initiated from a high port (aka unprivileged port), so >=1024. It follows, then, that for security reasons, it is valid to block replies to low ports <1024. The exception to this is ntp when using the ntp program, when communication is from and to port 123, so installing NTP gets this rule. Having said that, chronyd and ntpdate are from high ports and at some point we may switch to using chronyd as it is the upstream default. You could argue that a really basic rule could suffice not specifying ports, protocols or interfaces, but it is unlikely that the firewall will get that sort of review until ClearOS 8.

    I can't remember the details but, DHCP is either from 67 to 68 or vice versa, so the related/established rules are covered by the INPUT rules.The outbound request is allowed automatically by OUTPUT rules.

    The ClearOS firewall does some odd things where it creates an OUTPUT rule for every INPUT rule it creates. This is generally unnecessary because of the related/established rules, but **may** be necessary for the FORWARD chain if the default policy is to block all and allow by exception. There has been an issue for this for years but as the firewall works, no one has bothered fixing it.

  • Sruli Saurymper
    Sruli Saurymper started a new discussion, iptables rules

    iptables rules

    I checked my iptables rules and I don't understand some of the default rules,

    1. Why the separate "RELATED,ESTABLISHED" rules? why not 1 for each interface to cover all ports?
    2. for INPUT there are no "RELATED,ESTABLISHED" rules below port 1024, how does this work?

    Why do we need DHCP port open on the WAN interface?

  • DoMyEssay is an academic platform that will get your professional help in writing articles, dissertations, scientific papers, essay writing, and much more. If you are in school, student, graduate, bachelor, or creative person. A team of experienced writers will help you save time, improve your knowledge and writing skills. Visit our website

    How to Find the Best Essay Service
    If you are an employer who has a lot of work and if you would like to find a company that will be able to help you with writing your essays, then the best option for you is to use a website that can help you with all of your needs when it comes to essay writing. You should always keep in mind that this is a great resource and if you want to write your essay quickly and easily, then this is the way to go. However, it is not all the time that you can actually find the essay writing company that you are looking for. You may not find the company you are looking for because of the way they advertise. If you would like to know more about how you can find the best essay writer for you, then you should take a look at the following paragraph. If you would like to know more about how you can write my essay, then you should also take a look at the following paragraph.

    There are a lot of different websites out there that offer a lot of different services and most of these are dedicated to offering you with essay writing service. Most of these websites actually provide you with some types of special features and one of these is the fact that they will help you to write your essay on an easy to use program that you can use with just one click of your mouse. If you want to learn more about how you can get the best essay service, then you should take a look at the following paragraph. If you would like to know more about how you can write my essay, then you should also take a look at the following paragraph.

    When you want to hire a good essay writer, then you should make sure that you can find the right essay service that will be able to help you with your assignments. This can be a difficult task because it involves knowing what to look for and also knowing what you need.
  • Joy   Writer Mayo
    Hello! I am Joy Mayo - an essay writer in EssayService. Writing an essay is the work of my whole life. Since childhood, I loved to write and I am happy that now I can professionally help people. We will be very happy if you visit our website.

    Essay Service - How to Find a Good Essay Writer For Less
    There are many schools and colleges that offer essay services and there are also many essay writing services that you can find through online. If you are looking for a school to hire, it is important that you go through each of the essay service companies and choose the best one that you think is suitable for your needs. You can choose to either use an essay writer that has a portfolio or a list of samples that they have completed, or you can also use the services of a professional essay writing service who will complete your entire assignment. Whatever type of service you choose, it is very important that you go through the details of the company before you hire them so that you can be assured that you will be getting the best out of them.

    Most companies that offer essay writing service also have a portfolio of assignments that they have completed for various clients. In order to get a glimpse of their work, you will need to contact them and see what kind of results they have given for each assignment they have given to you. This will help you in deciding which company you will use so that you can be sure that the end result that you get from them will be top-notch.

    To be able to find a good essay writer for you, you will need to do some research on the company that you plan to hire. This will include checking for feedback from previous clients that they have given the company as well as doing a little bit of background check on the company. This will ensure that you are going to get the best services that you can get for a decent price.
  • I wish I was a Linux/ClearOS programmer and knew a lot more about the system layout and I would tackle it. In any event, thanks Nick! I do know there are a lot of good feature requests in the queue and all good things come in time. Most everything has a work around!

    Thanks again!!!


  • The webroot does not get redirected to /var/flexshare/shares. There are two different views of the same files. The only issue I know is that the CGI ScriptAlias points to the flexshare rather than directly to the path under /var/www, and someone reported an issue because of it.