<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5902990417442871140</id><updated>2011-04-21T12:36:29.131-07:00</updated><category term='Magang'/><title type='text'>awal yang baru</title><subtitle type='html'>nita's blog</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-8552217531176448091</id><published>2008-04-18T19:17:00.000-07:00</published><updated>2008-12-09T18:15:24.361-08:00</updated><title type='text'>TUGAS JARKOM 4 (INDIVIDU)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_MM3LiKZstVk/SAlcA_RfcQI/AAAAAAAAAAY/VKB7SEt8Mm8/s1600-h/INSTALASI+JAR.bmp"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_MM3LiKZstVk/SAlcA_RfcQI/AAAAAAAAAAY/VKB7SEt8Mm8/s320/INSTALASI+JAR.bmp" alt="" id="BLOGGER_PHOTO_ID_5190781217575760130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b style=""&gt;&lt;span style=""&gt;JARKOM 4&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b style=""&gt;&lt;span style=""&gt;KONFIGURASI JARINGAN&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;b style=""&gt;&lt;span style=""&gt;DI SMK ABDI NEGARA MUNTILAN&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="1" type="1"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style=""&gt;Konfigurasi LAN&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;SMK Abdi Negara Muntilan menggunakan 1 bentuk LAN dengan topologi yang sederhana dengan 10 komputer yang terhubung dengan jaringan Internet .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;Dengan IP Adress 192.168.15.xxx . Pc-pc tersebut pu hanya berada di dalam ruangan Lab. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ol style="margin-top: 0in;" start="2" type="1"&gt;&lt;li class="MsoNormal" style=""&gt;&lt;span style=""&gt;Instalasi Internet&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;Untuk instalasi internet kami menggunakan Jardiknas, tetapi selain itu kami juga menggunakan Dial Up Telkomnet Instant, tetapi kami jarang menggunakan layanan Dial Up karena kami rasakan terlalu lama untuk terkoneksi.&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;                    &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t202" coordsize="21600,21600" spt="202" path="m,l,21600r21600,l21600,xe"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:path gradientshapeok="t" connecttype="rect"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_s1028" type="#_x0000_t202" style="'position:absolute;" filled="f" stroked="f"&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;  &lt;v:stroke joinstyle="miter"&gt;  &lt;v:formulas&gt;   &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;   &lt;v:f eqn="sum @0 1 0"&gt;   &lt;v:f eqn="sum 0 0 @1"&gt;   &lt;v:f eqn="prod @2 1 2"&gt;   &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;   &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @0 0 1"&gt;   &lt;v:f eqn="prod @6 1 2"&gt;   &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;   &lt;v:f eqn="sum @8 21600 0"&gt;   &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;   &lt;v:f eqn="sum @10 21600 0"&gt;  &lt;/v:formulas&gt;  &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;  &lt;o:lock ext="edit" aspectratio="t"&gt; &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_s1026" type="#_x0000_t75" style="'position:absolute;"&gt;  &lt;v:imagedata src="file:///C:\DOCUME~1\PAIJOT~1\LOCALS~1\Temp\msohtml1\01\clip_image001.png" title=""&gt; &lt;/v:shape&gt;&lt;v:shape id="_x0000_s1027" type="#_x0000_t202" style="'position:absolute;" filled="f" stroked="f"&gt;  &lt;v:textbox&gt;   &lt;![if !mso]&gt;   &lt;table cellpadding="0" cellspacing="0" width="100%"&gt;    &lt;tr&gt;     &lt;td&gt;&lt;![endif]&gt;     &lt;div&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="';font-size:10.0pt';"&gt;Router ICT Kab. Magelang&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="';font-size:10.0pt';"&gt;192.168.33.254/24&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;/div&gt;     &lt;![if !mso]&gt;&lt;/td&gt;    &lt;/tr&gt;   &lt;/table&gt;   &lt;![endif]&gt;&lt;/v:textbox&gt; &lt;/v:shape&gt;&lt;v:shape id="_x0000_s1029" type="#_x0000_t202" style="'position:absolute;" filled="f" stroked="f"&gt;  &lt;v:textbox&gt;   &lt;![if !mso]&gt;   &lt;table cellpadding="0" cellspacing="0" width="100%"&gt;    &lt;tr&gt;     &lt;td&gt;&lt;![endif]&gt;     &lt;div&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="';font-size:10.0pt';"&gt;Router SMK Abdi Negara     Muntilan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;     &lt;/div&gt;     &lt;![if !mso]&gt;&lt;/td&gt;    &lt;/tr&gt;   &lt;/table&gt;   &lt;![endif]&gt;&lt;/v:textbox&gt; &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;o:p&gt;        &lt;/o:p&gt;Instalasi Ruang Lab Kami memang cukup sederhana, karena jumlah PC yang terbatas dan           minimnya pembelajaran siswa tentangb internet.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-8552217531176448091?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/8552217531176448091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=8552217531176448091' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/8552217531176448091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/8552217531176448091'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2008/04/tugas-jarkom-4-individu.html' title='TUGAS JARKOM 4 (INDIVIDU)'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_MM3LiKZstVk/SAlcA_RfcQI/AAAAAAAAAAY/VKB7SEt8Mm8/s72-c/INSTALASI+JAR.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-1517406730684315443</id><published>2008-04-16T23:19:00.000-07:00</published><updated>2008-04-16T23:20:37.059-07:00</updated><title type='text'>Setting up Mandrake 10.1 as a Firewall 1</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;Installation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Preparing for Installation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;For this installation I will be using an FTP install from one of Mandrake's Worldwide mirrors, as the downloadable 3-CD or DVD Images do not have the required packages. Note that even though this product is freely available under the GPL license, please either buy the full Mandrake distribution or join the Mandrake Club to ensure further development. Also, if you want commercial support for this firewall, Mandrake's MNF product is still available at their website.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;In order to perform an FTP installation you must first create two diskettes that will be used for the install. Go to http://www.mandrakelinux.com/en/ftp.php3 and select a mirror to download the floppy images from. The diskette images will be located in the&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;./official/10.1/i586/install/imagesdirectory, the files you want are network.img and network_drivers.img.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;To get these images onto a floppy under Linux, simply type&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;dd if=network.img of=/dev/fd0 bs=1024 conv=syncat a command prompt. Under Windows, you must also download a floppy image writer utility, which can be found in the&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;./official/10.1/i586/dosutilitydirectory, the file you want is rawritewin.exe. Once Downloaded, simply launch the application and locate the image file you want to write to a floppy.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Starting the Installation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Upon booting the computer with the network.img diskette, the installation routine should start and (hopefully) at least one of your network cards will be detected. Enter all the relevant information, such as IP Address, DNS and Gateway addresses that will allow you to download the software from an FTP server through your Internet connection.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The next step will be to select the installation type and either select an "Official" mirror, or enter the FTP server settings you want to use. If everything is correct, the graphical Installation program will be downloaded from the Internet and setup will continue. Depending on your connection speed, and the speed of the FTP server, this could take a while. If you are planning to "mass produce" these firewalls, it is best to setup a local mirror to speed up installation.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Once the graphical part of the installation starts, just step through the beginning settings of the installation, choosing what suits your machine. You will however want to choose "Higher" as the "Security Setting". Also once you get to package Selection, you must uncheck every "Package Group Selection" item and make sure you select "Individual Package Selection" before proceeding.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;After you continue from the package selection screen, the installation program will ask you which minimum installation selection you want, usually it is a good idea not to run X on a firewall, so just select "with basic documentation", or "Truly minimal install" and continue on. When it asks for the packages you want to install, you will want to switch the package list to "flat" instead of group sorted, you do this by clicking on the arrows that look like a refresh button.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Now we will select the packages that will allow Mandrake 10.1 to act as a Firewall Device. First you must find and select "httpd2-naat", this will select this package as well as automatically select various other packages needed. Next you will want to select the "mnf-en" meta package that will select most of the other needed packages. Note: You must select httpd2-naat before you select mnf-en, otherwise it will try to use settings for apache ver 1.x instead of apache ver 2.x, thus the software will not work. The only other mandatory package you must select is naat-frontend-www-doc, although you may want to select other packages, such as "slocate" or "kernel-secure" (recommended) depending on your preferences. Just remember that this is a firewall, and the fewer packages you install the better.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;As you continue the install, when it asks for users, ensure that you create the "admin" user, as well as one other user that you will use to login to the firewall. The admin user will be the user that you will use to login to the web configuration page. Also, when you configure services that start on boot, make sure you select any that your computer may need to boot, as well as the httpd2-naat service and possibly ssh if you want to remotely login.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;After the first boot&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;After the install is done and you reboot the computer, you will notice that many services might have failed, even the httpd2-naat service will fail. To get the httpd2-naat service to work, you need to update the SSL certificates. You can do this by issuing the following command, (as root, in the /root directory):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;/usr/lib/ssl/apache2-mod_ssl/gentestcrt.shThis script will ask you a few questions before it generates the required SSL Certificates, so you can either enter the information, or just hit enter through all the questions and the certificates will be created. Now, copy the certificates to the correct place:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;cp server.* /etc/ssl/apache2Before httpd2-naat will actually run, you must edit one of the apache configuration files, "/etc/httpd/conf.d/51_ssl.httpd2-naat-vhost.naat". Within that file, wherever it says:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;"/etc/ssl/apache/server.crt" and "/etc/ssl/apache/server.key"change it to&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;"/etc/ssl/apache2/server.crt" and "/etc/ssl/apache2/server.key"Once you are done editing that file, go ahead and try to restart the httpd2-naat services with:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;/etc/init.d/httpd2-naat restartNow the service should start and you should now be able to remotely log into the web based configuration pages.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Sumber : http://www.flexbeta.net/main/printarticle.php?id=87&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-1517406730684315443?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/1517406730684315443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=1517406730684315443' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1517406730684315443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1517406730684315443'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2008/04/setting-up-mandrake-101-as-firewall-1.html' title='Setting up Mandrake 10.1 as a Firewall 1'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-401205925867057538</id><published>2008-04-16T23:16:00.000-07:00</published><updated>2008-04-16T23:18:27.100-07:00</updated><title type='text'>Setting up Mandrake 10.1 as a Firewall 2</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span&gt;&lt;span&gt;Configuration Using the Web Interface&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Once installation is complete and you have the httpd2-naat service running, you will want to log into your firewall remotely by using a web browser. The address you will need to use is:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;https://IPADDRESS:8443/ - for example https://10.0.0.10:8443/If you run into a "connection refused" or any other similar error, the problem is that shorewall is enabled, but not yet configured. To fix this simply type the following at the Firewall Computer:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;shorewall clearNote: While setting up your firewall, the software will automatically restart Shorewall in some instances. Until Shorewall is properly configured, you may need to run the "shorewall clear" command whenever you find that you cannot connect to the web interface on your firewall.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;System Setup&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;To begin configuring your firewall, you must enter the system setup section, it will have you hit next to read the current settings. Unfortunately these scripts are a little outdated, so you will probably have an empty slate to start with, just click "apply". Again, if you get a connection refused error or similar, you must execute the "shorewall clear" command at the firewall to reconnect.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Continuing setup, go back into the "System Setup" section, click on modify and re-enter the system and domain name you will use. Then click on "Network Cards" and ensure that all of you network cards are detected and all the basic settings are correct.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Continuing down the line of the System Setup section, the Account section will allow you to change your password, the Alert section will allow you to change the system's log level, and Time will allow you to change the time zone and specify a ntp server to sync the time with. You will want to rerun the Time setup after you configure your Internet settings and Shorewall to ensure you will be able to connect to a time server.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Internet Settings&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;The Internet Access section allows you to configure how your firewall accesses the Internet as well as the settings required to connect. Most firewalls will use the Cable/LAN settings to connect to the Internet, so click on it and enter the required fields for your Internet connection, otherwise select the proper connection method and enter the appropriate settings.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Don't worry to much about the Internet status section, as it rarely works properly. Also on this page, the "Provider Accounts" will eventually allow you to setup commercial ISP settings, but for now it just tells you to use the Cable/Lan settings. The "Schedule" setting allows you to set the time where the firewall will be able to connect to the Internet if you are using a modem to dial into another server. If you want to adjust the schedule for Internet access using a LAN connection, you will only be able to do this if you enable the Squid Proxy service, and utilize Squidguard (accessed through the "Services" section, which will be covered later).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Firewall Rules&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Firewall Rules&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;The Firewall Rules section is where you will be able to configure Shorewall to specify what traffic through your firewall will be allowed and denied. The first thing you must do is to setup your zones. By default there are 3 different zones; WAN, LAN and DMZ. These specify what type of connection each Network card will be connected to, most people will only use the WAN and LAN zones. So, you will want to specify the network card connected to the Internet as a "WAN" zone, and the network card connected to your private network as a "LAN" zone.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;After setting up your network "zones", you will want to skip down to the default policies section. Default policies allow you to setup the default behavior for information traveling between different zones. Most of the default policies should be properly setup for you. One setting you may want to change, however, is the policy of traffic coming from the LAN zone to the Internet zone. By default, you must specifically allow any connection going through the firewall. This means that if your computers on the LAN interface try to access the Internet through a non-standard port (such as streaming video), the connection will be refused (and you will hear about it from the user). A very quick fix for this problem is to either:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;A ) set the default policy to allow all connections originating from the LAN Interface&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;B ) specifically allow certain IP addresses full outgoing permissions&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;If you choose to deny Internet access through all but certain popular ports, be prepared to add lots of rules to the firewall in the first week or two. I usually go ahead and deny most ports, then add whatever ports are needed. If it gets to be quite a few for only one or two users, go ahead and create a rule that says anything coming from their IPs are allowed.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;IP Masquerading&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;In order for the firewall to be able to "share" it's Internet connection, you must either setup IP Masquerading or setup a Proxy Server (or both). It is extremely easy to setup IP Masquerading with 2 Network cards using the web interface. Again, if you are planning on using the Squid Proxy server, you do not need to enable IP Masquerading for simple web browsing.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;For masquerading using 2 network cards, simply click on Masq NAT, then enter the Network Interface you want to masquerade (LAN Interface), then the Network card connected to the Internet. Also, you could enter all the relevant IP Addresses instead of Network Interfaces, but for simple masquerading this is not necessary. From this screen, you can also setup advanced NAT rules, such as utilizing a DMZ, if this is needed.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Creating Firewall Rules&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Firewall rules allow you to change the Default Policies (specified earlier) for certain circumstances. Firewall Rules also allow you to "Forward" any packets on a port to a different computer on the LAN, this is useful if you setup a server on your network that you want people to be able to access from the Internet. Also, if someone wants to play online games from behind the firewall, you will need to forward the traffic for that port to their computer's IP Address.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;To create a rule that will allow access through a port, click on "add simple rule". This will bring up a dialog that has a drop down box of popular ports and applications. This dialog will allow you to create a simple "Allow" or "Deny" rule based on the port number, what protocol is being used, where the traffic is originating from, and where it is going to (for example coming from the LAN (local network) and going to the WAN (Internet).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Note: Even though the "add simple rule" has a forward check box, DO NOT use it to setup a port forwarding rule. This interface was created for Shorewall version 1.3.7 and Mandrake 10.1 uses Shorewall version 2.0.8, which has changed the way it forwards packets. If you do inadvertently check that box, Shorewall will refuse to start.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;In order to create a port forwarding rule, you must go through the "Add Custom Rule" dialog. Simply enter all the relevant information, including the I.P. address of the computer you want the traffic to go to and make sure you select "DNAT" as the action. Then, after applying the Firewall Rules, port forwarding should work as expected.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;After you setup all the relevant rules you want, it is now time to start the firewall service and ensure that your machines on the LAN are able to access the Internet through the firewall computer. On any computer that you wish to be able to access the Internet through the Firewall, adjust it's Network Settings so it will use the Firewall's IP address as the default Gateway address.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Note: Before you actually start the firewall service, you must delete the rule for port 20022, that rule is not formatted properly and Shorewall will not start with that rule in place. Also, if you are having difficulty in getting shorewall to start, go to the firewall computer and restart the Shorewall service manually using the command:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;/etc/init.d/shorewall restartand watch the output. If shorewall fails to start it will tell you which rule is causing the problem. To fix it, simply do a "shorewall clear", login to the web config pages and delete any offending rules (recreate them if needed) and restart shorewall.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;The other options available through the Firewall Rules section include:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Blacklists - allows you to specify hosts by IP or network that the firewall will simply drop its packets. This is good if you continually get messages in your logs for "questionable" activity coming from certain IPs.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;TOS - allows you to define TOS service field in packet headers (advanced use).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;Tunnels - allows you to setup IPSEC tunnels for secure communication between hosts (advanced use).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Sumber : &lt;a href="http://www.flexbeta.net/main/printarticle.php?id=87"&gt;http://www.flexbeta.net/main/printarticle.php?id=87&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-401205925867057538?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/401205925867057538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=401205925867057538' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/401205925867057538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/401205925867057538'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2008/04/setting-up-mandrake-101-as-firewall-2.html' title='Setting up Mandrake 10.1 as a Firewall 2'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-9017593949443380012</id><published>2008-04-16T23:12:00.000-07:00</published><updated>2008-04-16T23:15:11.479-07:00</updated><title type='text'>Setting up Mandrake 10.1 as a Firewall 3</title><content type='html'>&lt;div align="justify"&gt;&lt;div align="justify"&gt;&lt;div align="justify"&gt;&lt;div align="justify"&gt;&lt;div align="justify"&gt;&lt;div align="justify"&gt;&lt;div align="justify"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Basic Web Services&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;So far we have setup a basic firewall that allows you to share the Internet connection, as well as protect your network from Internet traffic. Now we will enhance the Firewall with Services that will allow for easy client setup, improve your Internet speed and filter out undesirable web pages or content that you may wish to remove. Ordinarily, companies charge quite a bit of money to provide these services (especially for content filtering), but here I will discuss how to setup these services using Mandrake Linux and it's web interface.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;DHCP and Caching DNS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;To automate the configuration of your network clients, you can enable the DHCP server service available on the firewall. DHCP (Dynamic Host Configuration Protocol) allows you to have the firewall automatically send the computers on your LAN the correct IP configuration values during bootup. So, instead of going to each machine and entering a separate IP address, subnet, DNS server and gateway machine, you can have the LAN computers get this information from your firewall. To set this service up, click on DHCP and enter the relevant information, it is pretty self explanatory.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;To alleviate excess DNS lookups over your Internet connection, you can setup the firewall to act as a DNS server for your LAN. Doing this will enable the firewall to "cache" all of the nameserver lookups, so if multiple clients try to find the IP address for the same domain name, such as http://www.google.com/, the firewall will send the correct information without needing to access your Internet Service Provider's DNS server.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;To enable the Caching DNS service, you simply need to enter the IP address of a forwarding DNS server. This will allow the firewall to query that DNS server if it does not have the information in it's cache. If for some reason the DNS service fails to start or gets mis-configured, simply shut off the service, login to the firewall and move the /etc/named.conf file to something else, such as /etc/named.bak and re-enable the service. The software will re-create a correct /etc/named.conf file to allow the service to work again.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Note: If you run a network utilizing Microsoft Active Directory, Microsoft Exchange Server, or any other newer Microsoft Server, you must utilize Microsoft's DHCP and DNS Services, otherwise you will have severe network slowdowns and communication errors.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Web Proxy and Filtering&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;One way to really speed up your Internet service is to provide a way to "cache" web pages at the firewall so that if multiple users go to the same sites, most of the images and other information will be retrieved from the firewall instead of the remote Web Server. Also when you implement a proxy or "caching" service, you can also utilize a site/content filter to deny access to certain remote sites, such as pornography or content, such as ads. Many companies produce products that will do this type of filtering, however, these products are quite expensive and IMO are no better than what the OSS community offers with these tools.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Another benefit of a Proxy or "Caching" Server is the ability to only provide Internet Access to people "authenticated" to use the Internet. Mandrake offers the ability to provide a "transparent" proxy, manual proxy or manual "authenticating" proxy using either locally created usernames, an LDAP user database or a SMB (Windows Domain) user database.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;The "transparent" settings are just about the same as a "manual" setting, except that it simply adds a "Redirect" to port 3328 rule to your Shorewall settings for traffic coming from the LAN. So, I guess you could even have a "transparent authenticating" proxy if you really need one.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Using the web interface it is quite easy to enable the proxy server, simply click on the Web Proxy settings, then select the type of proxy, either manual, manual authenticating or transparent. The easiest is "transparent" because you will not have to adjust any settings on your clients to be able to use the proxy server, it will simply "just work".&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Once you setup and enable the Web Proxy, you will notice that you now have the opportunity to configure both a URL Filter (SquidGuard) and a Content Filter (Dansguardian). When you start to implement each of these services, it is best to do things a step at a time, any misconfiguration could lead to your LAN computers not being able to access the Internet at all.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;For those wishing to enable Squidguard here are a few tips. First, make sure you add your local network to the authorized network list (i.e. 192.168.0.0/24). If you plan to block quite a few sites, do not use the web based tools, instead go to a command line and manually add whatever you want to the database through simple text files. An easy way to do this would be to download an updated blacklists file from squidguard.org. Then, once these are downloaded, uncompress them in the root (/root) directory and add the contents of whatever list you want to ban to one the following files:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;/usr/share/squidGuard-1.2.0/db/advertising/urls&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;/usr/share/squidGuard-1.2.0/db/advertising/domains&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;/usr/share/squidGuard-1.2.0/db/banneddestination/urls&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;/usr/share/squidGuard-1.2.0/db/banneddestination/domains&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;/usr/share/squidGuard-1.2.0/db/banneddestination/expressionsyou can do this with vi by "reading" the file in using the ":r /path/to/filename" command. The advertising directory will replace advertising content with a small dot(so an annoying error box will not show up), while the banneddestination directory will deny all access to the specified sites. Once this is done, you must change these text files to a SquidGuard database by issuing:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;squidGuard -C allOne more thing, make sure that squid is both the owner and group of these files by executing the following command:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;chown squid.squid /usr/share/squidGuard-1.2.0/db -RYour Proxy Server will now block these sites (after you restart squid). Unfortunately, there is another bug we must fix, so the "denied page" is not an access denied to the squidguard.cgi file, but instead the nice, somewhat informative blue/green Mandrake denied page.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;To fix this you must edit the "/etc/httpd/conf/commonhttpd2-naat.conf" file. Toward the end of the file, it will list the "/var/www-naat/cgi-bin" directory. You must add the following so the web server will have permission to use the SquidGuard cgi-bin directory.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;AllowOverride All&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Options ExecCGI&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Order allow,deny&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Allow from all&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Finally, if you ever (accidentally) go back to the banned destination configuration page through the web interface, you must once again recreate the databases and change the ownership manually. As for configuring Dansguardian, please visit their website at http://www.dansguardian.org. In my experience, SquidGuard seems to be enough of a deterrent that Dansguardian is not needed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Intrusion Detection&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Using the web interface, you can enable both Snort and Prelude Intrusion Detection Systems. These IDS services work quite well, unfortunately, when you have an IDS on a computer directly connected to the Internet you will get quite a few false positives. So, weeding through the logfiles can quickly become a fulltime job. If you do plan on enabling the IDS on the firewall, it is best to also use a "helper" application that will allow you to just view "threats" on your machine, such as logwatch.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Optimally, if you do have a large network, it is best to place an IDS server somewhere on your LAN so you can monitor for any suspicious activity that somehow makes it through your firewall. For more information on how to do this, there are two books available from the Bruce Peren's Open Source series at http://phptr.com/perens. The titles are "Open Source Security Tools" and "Intrusion Detection with Snort".&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Testing and enhancing your Firewall&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Testing and enhancing your Firewall&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Testing your Firewall&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;One of the final things you should do before implementing a firewall solution is to ensure you fully test it to make sure it does what it is supposed to. You should run these tests on both sides of the firewall, the Internet side, as well as the LAN side. In order to properly test your firewall, there are a few applications available. The first application you should use would be a port scanner to ensure your firewall rules are in place. The most popular port scanner, NMAP is available for nearly any Operating System at http://insecure.org/nmap.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Another other tool that you should run on your firewall would be a vulnerability scanner. These tools will scan your server for known vulnerabilities, such as ones "script kiddies" would take advantage of. You can get a good vulnerabilitiy scanner called Nessus for Linux/Unix based machines from http://www.nessus.org.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Enhancing your Firewall&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;One of the great things about utilizing Mandrake Linux 10.1 for your firewall is the fact that there are so many packages available for it. It is very simple to add additional tools that would be beneficial for you run. A few of them would be:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;ntop- Network traffic probe - this package is accessed through a web interface. Once installed you must ensure that the "/usr/share/ntop" directory has correct permissions, then add the following to /etc/sysconfig/ntop - extra_args="-i eth0,eth1 -M" to allow ntop to monitor both network interfaces. Then simply open http://ipaddress:3000 in your browser to utilize the program.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;mrtg- Multi Router Traffic Grapher will monitor the traffic load on your firewall, also available through a web interface.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;netwatch- terminal based network watching program. Simply type in "netwatch -e eth1" at a prompt to watch all the traffic going through your LAN interface.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;All of these packages can be easily installed by running a "urpmi packagename", then after they are configured you will be able to take advantage of the software. There are hundreds other packages you could take advantage of, such as squid-log analyzers, packet sniffers, etc., all of these are only an urpmi away.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Note: It is extremely easy to add additional services to your firewall, such as a Mail, FTP or a Web Server, however, it is strongly discouraged to run anything but the "bare minimum" services on a firewall computer.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;A firewall is one of the first things that you must consider when securing a network. There are many products available to handle this job, ranging from "Linux on a floppy" firewalls and low-cost "home firewall" devices, all the way to highly expensive Cisco Pix firewalls. However, if you want full functionality, Mandrake offers an easy to use web interface coupled with all the features you could want in a firewall (including VPN services), plus the expandability that comes with a complete commercial Linux distribution. All for a price that will not break your budget.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-9017593949443380012?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/9017593949443380012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=9017593949443380012' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/9017593949443380012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/9017593949443380012'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2008/04/setting-up-mandrake-101-as-firewall-3.html' title='Setting up Mandrake 10.1 as a Firewall 3'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-1545293397495188539</id><published>2007-05-21T19:56:00.000-07:00</published><updated>2007-05-21T20:10:58.705-07:00</updated><title type='text'>CARA JALAN MENUNJUKAN KEPRIBADIAN</title><content type='html'>&lt;span&gt;&lt;strong&gt;&lt;/strong&gt;&lt;p align="justify"&gt;&lt;br /&gt;&lt;/span&gt;Walaupun dengan sengaja atau tidak, qita sering memperhatikan cara jalan baik teman terutama gebetan qita, ya kan ????????&lt;br /&gt;Nah sekarang bandingkan cara jalanmu dengan orang yang kamu perhatikan , apakan sama atau tidak, bacalah contekan di bawah ini, dijamin seru .&lt;br /&gt;&lt;strong&gt;Kepala selalu menunduk&lt;/strong&gt;&lt;br /&gt;Orang yang selalu menundukkan kepalanya ketika berjalan, berarti orangnya tertutup namun pandai menjaga rahasia. Huh sereeeeeeeeem ya ? Hanya mau bicara dengan orang-orang yang dianggap dekat, ya gak? Hingga untuk mendekati cowok ini, kita perlu bantuan dari teman dekatnya. Dia tidak begitu mempedulikan cinta. Tapi sekali jatuh cinta, ia akan setia." Ough Romantis banget "&lt;br /&gt;&lt;strong&gt;Matanya selalu menatap lurus ke depan&lt;/strong&gt;&lt;br /&gt;Orang yang berpendirian tegas. Tidak gampang tergoda. Jangan coba menentang apa yang dikatakannya, jika tak mau ribut. Dia senang bergaul sama ' orang yang wawasannya luas. Sebagai modal untuk merebut hatinya, persiapka diri dengan rajin baca buku clan majalah, cari tahu seputar olah raga, musik, dan gaul.&lt;br /&gt;&lt;strong&gt;Sering menoleh ke kiri dan ke kanan&lt;/strong&gt;&lt;br /&gt;Orangnya pandai menjaga rahasia. Senang diatur dan diurus. Berarti kalau ~ mau jadi pacarnya, harus banyak kasih perhatian. Tapi hati-hati, dia cenderung suka merugikan atau menipu teman.&lt;br /&gt;&lt;strong&gt;Bandanya terlihat tegak&lt;br /&gt;&lt;/strong&gt;Orang yang tegas dalam menentukan sikap. Dia tidak suka masalah pribadiny dicampuri. Gaya bicaranya serius clan selalu bertanggung jawab pada hal van dilakukannya. Menyukai cewek mandiri, tapi tidak melupakan sisi romantis.ladi jangan manja ya kalau mau dilirik&lt;br /&gt;gebetan yang satu ini ..&lt;br /&gt;&lt;strong&gt;Bergerak ke depan dan ke belakang&lt;/strong&gt;&lt;br /&gt;Orangnya sensitif gampang tersinggung . Sering merasa lemah dan tidak percaya&lt;br /&gt;diri. Menghadapi cowok ini coba beramah tamah dan dibaik-baikin.&lt;br /&gt;&lt;strong&gt;Menggerakkan Badan ke kiri dan ke kanan&lt;br /&gt;&lt;/strong&gt;Orangnya cuek. Enggak terlalu mempermasalahkan problem yang sedang dihadapi. Kadang cenderung mengentengkan masalah, sampai rugi sendiri. Untungnya dia jadi easy going dan enak diajak jalan. Kalau mau dekat cowok ini jangan serius, nanti disuruh pulang :). Lebih baik kita belajar untuk enggak terlalu polos, clan perbanyak humor.&lt;br /&gt;&lt;strong&gt;Jalanya Tampak dari bela&lt;/strong&gt;kang&lt;br /&gt;seperti tidak menginjak tanah Orang ini cenderung tidak jujur, suka membual, clan berlidah tajam. Egonya tinggi, dan suka boros. Kalau belanja tidak pikir panjang lagi. Herannya tipe cowok kayak begini banyak yang memuja. Mungkin kebanyakan berwajah keren ya? Kalau mau didekati olehnya, berpenampilanlah sebaik mungkin. Dan pujalah ia.&lt;br /&gt;Ayo kira-kira mana yang menjadi keprbadianmu dan gebetan kamu, kalau sudah tahu silahkan renumgkan dan pikirkan, Apakah masih ada yang perlu diperbaiki atau sudah cukup bahkan kalau perlu ada yang harus agak dikurangi. Selamat mencoba ……….&lt;br /&gt;Sumber : majalah kawanku edisi september 2005&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-1545293397495188539?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/1545293397495188539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=1545293397495188539' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1545293397495188539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1545293397495188539'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2007/05/cara-jalan-menunjukan-kepribadian.html' title='CARA JALAN MENUNJUKAN KEPRIBADIAN'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-1169699891081180193</id><published>2007-05-13T23:00:00.000-07:00</published><updated>2007-05-13T23:04:25.840-07:00</updated><title type='text'>MY SPEECH</title><content type='html'>&lt;div align="center"&gt;&lt;strong&gt;COMPUTER&lt;/strong&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;Good afternoon Ladies dan gentleman ………!!!&lt;br /&gt;Thank you for your attention, my name is Anita Sri Sirep from class MRIT-A, I stand here I will talk about personal computer (PC)&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;    &lt;strong&gt;First, Computer represent result of sophisticated industry.&lt;/strong&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Computer which we know in this time is technological development result of electronics and information technology, so that form old computer size is big, now in form of small but big ability. component of electronics IC ( integrated circuit) have pushed the sophisticated computer creation.&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;   In this time manager, educator, functionary, researcher and society have utilized the computer . Thereby computer represent the equipments to society requirement and not limited just for certain circle. If society have recognized the computer benefit better, in era internet everyone having personal computer (PC) can access the information internet by adding additional peripheral. Impressing more and more society recognized know a computer, society ready for competing in globalization era. So the level of computer benefit.&lt;br /&gt;&lt;strong&gt; Second, What is a Computer ?&lt;br /&gt;&lt;/strong&gt;  Computer is result from technological progress of functioning and information technology electronics as a means of assist to write, to drawing, editing picture or photo, making animation, operating scientific analysis program, simulation and to control the equipments. Form the old of computer big enough to operate a program, now in form of small ability operate the immeasurable program. hardware and software have made a computer become the useful object. A computer which is just only having(owning) hardware or software will not function. With both a computer can function to become the useful object. Some one who hobby computer or engineer, can develop the ordinary computer ability to control the machine equipments produce or household equipments. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;  By adding its brand electronic network, so ordinary computer can be utilized to control the industrial equipments and household. Existence of tendency a computer exploiting to control and technological support of chip IC enable the people to make the small robot  &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;strong&gt;Thrith, Consist of a computer ?&lt;/strong&gt;&lt;/div&gt;&lt;strong&gt;&lt;/strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;     Personal Computer (PC) consisted of the Central Processing Unit (CPU), keyboard and monitor the. CPU function as data processor, keyboard as a means of assist the inclusion of letter data , number or govern the control to computer to operate a data processing. Monitor is appliance to present the letter, number and draw. Existence of technological progress of electronics and information technology have given the additional peripheral at a personal computer (PC) like mouse ( appliance assist the computer control to operate the easier program comands), modem , sound card, video card, and ethernet card and also kinds of printer ( desk jet, buble jet, laser jet, plotter) and scanner.&lt;br /&gt;IV. How principle work a computer ?&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;strong&gt;   Computer work by:&lt;/strong&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Input data by operator through the keyboard ( letter or number), and scanner ( graphical data / draw) into CPU. The Data sent to software application to be processed in processor and presented in monitor. If data which come up in monitor have as according to mentioned computer operator, so the operator will command the computer for the save of result of its job in disket or hardisk, or command the computer to print it pass a printer.&lt;br /&gt;In CPU, happened the process of data communications that is data sent to application program is immediately distribute to a operating system program. By operating system program, this data is turned into a machine Ianguage which comprehensibility by electronic equipments of exist in for computer so that in monitor can display what wanted by operator , or computer can communicate with the printer and govern the printer to print the file wanted by operator.&lt;br /&gt;May be enough my presentation for about personal computer.i hope all off you agree and know with my presentation. thank you and good…LUCK…!!!&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-1169699891081180193?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/1169699891081180193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=1169699891081180193' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1169699891081180193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1169699891081180193'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2007/05/my-speech.html' title='MY SPEECH'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-3136409354094364621</id><published>2007-05-09T22:30:00.000-07:00</published><updated>2007-05-09T22:51:34.934-07:00</updated><title type='text'>BEASISWA BEASISWA</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:courier new;"&gt;&lt;em&gt;Mungkin dalam hati kalian akan senang dengan yang namanya beasiswa, apalagi itu adalah beasiswa untuk bersekolah di Universitas yang katakanlah universitas tersebut Adalah universitas yang terpandang lah. tapi gimana ya dengan beaisiswa yang aku dapatkan ya aku gak ngomong kalo gak seneng, aku seneng tapi tugasnya itu bo bo bo bo buanyak buanget dan susah-susah banget. tapi itu bagiku gak tahu bagaimana dengan teman-temanku.mungkin mereka juga merasakan hal yang sama, karena banyaknya tugas gak malah bikin seneng tapi malah bikin weng, he he he he...... Tul gak temen2 ????????????&lt;/em&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-3136409354094364621?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/3136409354094364621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=3136409354094364621' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/3136409354094364621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/3136409354094364621'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2007/05/beasiswa-beasiswa.html' title='BEASISWA BEASISWA'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5902990417442871140.post-1433940737217944682</id><published>2007-04-18T00:59:00.001-07:00</published><updated>2007-04-18T01:01:34.141-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Magang'/><title type='text'>hay friends how are you ?</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;Haloo my friends how are you? gimana rasanya mengikuti kuliah D3 TKJ di UMM. enak gak? kalau aku ada enaknya dan ada capeknya. Enaknya yaitu jadi banyak pengalaman dan banyak teman dan gak enaknya adalah banyak tugas-tugas dari kampus. he he he he. Dengan web pribadiku ini aku ingin mencurahkan semua unek-unek yang ada dalam diri aku, baik itu sekolahku, magangku, temenku dan lain sebagainya,&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: trebuchet ms;"&gt;Gimana kalian setuju gak ? Harus dong !&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5902990417442871140-1433940737217944682?l=anita-srisrep.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anita-srisrep.blogspot.com/feeds/1433940737217944682/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5902990417442871140&amp;postID=1433940737217944682' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1433940737217944682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5902990417442871140/posts/default/1433940737217944682'/><link rel='alternate' type='text/html' href='http://anita-srisrep.blogspot.com/2007/04/hay-friends-how-are-you.html' title='hay friends how are you ?'/><author><name>anita</name><uri>http://www.blogger.com/profile/00659545558477206670</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
