I am pretty convinced that Openswan works as intended
I am not convinced at all. In my book, Openswan doesn't work.
Openswan works really great in 95% of the connections that I have seen over the years. It's utterly broken in the other 5%. It's not Openswan, but the whole IPsec protocol (yes, protocol) and stack in Linux. The reason we built the "Dynamic VPN" service is because IPsec is not reliable. Sad, but true. Openswan is fine on good solid networks (I can't remember the last time we had an issue with it in our environment), but utterly horrible in other environments (satellite networks, I'm looking at you).
Quite frankly, we're tired of dealing with IPsec and all its warts. I absolutely hate IPsec... it is the spawn of the devil. I will have a *big* pitcher of beer when OpenVPN becomes the default for ClearOS-to-ClearOS connections.
and releasing the full source code of this so-called "gpl licenced" software would not hurt either.
- If you really want to geek out, click on "Developer - Source Code" in the menu. You will not only see the source code, but all the usual detailed changes that you see in a source code control system (SVN).
- And if you really want to geek out, see some of the progress that is being made on the new build system (with more source code / developer info). You can find that in "Developer - Build" in the menu.
There are a handful of hand-rolled packages that have to move from the really old "ClarkConnect / Point Clark Networks" SVN system. These are packages that were built internally (i.e., there is no "upstream"). Just ask, and we can provide the source code manually... no big deal. We'll migrate these packages over to the new build system. Please be patient, there are only so many hours a week that we can dedicate time to ClearFoundation
I also have a feeling that you are looking for more detailed technical specifications. That would have made your multiWAN hacking a little nicer. Perhaps documents like this one are what you are looking for. Again, please give us some time to build out these documents as features pop-up for a "refresh".
We kept getting a lot of spam until I added the entries to postfix for bl.spamcop.net.
Careful... that will generate false positives! The SpamAssassin engine already uses this blacklist, but it scores only (not rejects them outright). I always suggest greylisting and spam training when too much spam sneaks through. It does take a week or so for a fresh install to catch up with the auto-learning engine.
Is there a log file that the ClearSDN AntiSpam service creates that shows that is is working and blocking spam
Funny... we are going to be releasing an update next week that will provide this information. In the meantime, the following command will give you a list of all the messages that have benefited from the Antispam Updates service:
It's not 100% accurate since some of these rules are actually viruses, not spam.
And I don't want to pay them more money to open a trouble ticket to ask them this quest
If you subscribe to a ClearSDN service, you are more than welcome to generate a support ticket at no charge. When you create a support ticket, select "ClearSDN Services" in the "Category/Type".
Darryl has been wanting to update the firewall configuration pages for a couple of years. The 1-to-1 NAT on different ports, along with the 3 common examples outlined in the Advanced Firewall Tool need to be added to the GUI.
Could you send your /var/log/system log file to security@clearfoundation.com (it's not a security issue, that's just the best mailing list to use for now).
Here's an example script that will delete the "test5" user. Please excuse the "GroupManager" line -- it shouldn't be necessary but there is a missing library dependency.
The Turkish language is not complete, so your offer to help finish the translation is much appreciated! We are going to move to a new translation tool with the move to the new web application framework in 6.0. When we have all the pieces in place, I will let you know.
I'm can't login system
I was not able to duplicate the issue. Perhaps the password has a character that is causing some grief? That's just a wild guess