All of lore.kernel.org
 help / color / mirror / Atom feed
* icq
@ 2004-06-16 17:45 Peter Marshall
  2004-06-16 17:51 ` icq Alexis
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Peter Marshall @ 2004-06-16 17:45 UTC (permalink / raw)
  To: netfilter

what do I need to do to allow ICQ to work through my firewall


Peter Marshall, BCS
Network Administrator, CARIS 
115 Waggoners Lane, Fredericton NB, E3B 2L4 CANADA
Phone:  (506) 458-8533 (Reception) 


^ permalink raw reply	[flat|nested] 7+ messages in thread
* RE: icq
@ 2004-06-16 21:03 Hudson Delbert J Contr 61 CS/SCBN
  2004-06-17  2:26 ` icq Alistair Tonner
  0 siblings, 1 reply; 7+ messages in thread
From: Hudson Delbert J Contr 61 CS/SCBN @ 2004-06-16 21:03 UTC (permalink / raw)
  To: 'Rob Sterenborg', 'netfilter'

the rpc like tendencies of icq make it not worth the trouble to manage
access to/from it.

~piranha

-----Original Message-----
From: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Rob Sterenborg
Sent: Wednesday, June 16, 2004 1:42 PM
To: 'netfilter'
Subject: RE: icq


> what do I need to do to allow ICQ to work through my firewall

(Other answers already given..)

Not sure about recent versions, but with old versions you could only do
simple things like messaging when using NAT only.
If you wanted to do things like chat and/or filetransfer, you needed a
socks server. I guess this still holds.
NEC had a free socks5 server for *nix once, but stopped providing it.
It's now Permeo's (www.permeo.com) but AFAIK not free any more. If you
need it ; there's a source version on rpmfind.net.



Gr,
Rob



^ permalink raw reply	[flat|nested] 7+ messages in thread
* RE: icq
@ 2004-06-18 13:15 Hudson Delbert J Contr 61 CS/SCBN
  0 siblings, 0 replies; 7+ messages in thread
From: Hudson Delbert J Contr 61 CS/SCBN @ 2004-06-18 13:15 UTC (permalink / raw)
  To: 'Alistair Tonner', netfilter

A,

	you just dont get it...

	the access itself is risky for an enterprise.

	small home lans are not relevant in this conversation.

	the setup for rpc mimics some of the port nonsense that
rpc/portmapper
	type of architectures is the problem.

	the client-2-client interface is the security problem in and of
itself.

-----Original Message-----
From: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org]On Behalf Of Alistair Tonner
Sent: Wednesday, June 16, 2004 7:26 PM
To: netfilter@lists.netfilter.org
Subject: Re: icq


On June 16, 2004 05:03 pm, Hudson Delbert J Contr 61 CS/SCBN wrote:
> the rpc like tendencies of icq make it not worth the trouble to manage
> access to/from it.
>
> ~piranha

	? rpc like ? 

> Not sure about recent versions, but with old versions you could only do
> simple things like messaging when using NAT only.
> If you wanted to do things like chat and/or filetransfer, you needed a
> socks server. I guess this still holds.
> NEC had a free socks5 server for *nix once, but stopped providing it.
> It's now Permeo's (www.permeo.com) but AFAIK not free any more. If you
> need it ; there's a source version on rpmfind.net.
>
	
	Although there are already some answers here, the extended
attributes
	for icq can be managed in a small home lan situation by properly
configuring
	the clients (set the ports on which connections can be recieved to a

	different specific range per client) and then forward the
appropriate range
	of  ports per client from the firewall.  In my case at home, I have
three
	internal clients that are permanently forwarded.  You can't filter
on source
	address as icq -> icq transfers are client to client.  For standard
chatting 
	however, nothing need be done save the initial connection out to 
	login.icq.com and an established related rule.  Some folks might
find that
	they have to send the initial message through the servers (window
clients 
	auto fallback to this state, licq has to be told to do it) but after
the 
	first message out from behind the firewall, if the
ESTABLISHED,RELATED rule
	is in place, chat messages work just fine.

	Alistair Tonner.



>
>
> Gr,
> Rob


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2004-06-18 13:15 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-06-16 17:45 icq Peter Marshall
2004-06-16 17:51 ` icq Alexis
2004-06-16 18:25 ` icq Florian Boelstler
2004-06-16 20:42 ` icq Rob Sterenborg
  -- strict thread matches above, loose matches on Subject: below --
2004-06-16 21:03 icq Hudson Delbert J Contr 61 CS/SCBN
2004-06-17  2:26 ` icq Alistair Tonner
2004-06-18 13:15 icq Hudson Delbert J Contr 61 CS/SCBN

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.