Re: pf.conf: match seems to clean up previous log statements.

2010-06-22 Thread Henning Brauer
bugs with logging after match entered the game (since match changes some things fundamentally) -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: Processeur Atom ?

2010-06-11 Thread Henning Brauer
cost over recycled hardware. that might be (I am not convinced tho) with the electricity price in the US, but certainly isn't universal. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers

Re: pf anchors

2010-06-10 Thread Henning Brauer
* Kevin Chadwick ma1l1i...@yahoo.co.uk [2010-06-10 18:08]: no. it is imposing limits that should not be there and that the new pf core does not require any more. Is it not even slightly required or would a warning message be appropriate. warnings are useless -- Henning Brauer, h

Re: pf anchors

2010-06-08 Thread Henning Brauer
* Teemu Rinta-aho te...@rinta-aho.org [2010-06-07 21:22]: On Jun 7, 2010, at 10:05 PM, Henning Brauer wrote: I am (and always have been) inclined to just remove this stupid check (that I added myself :)) and just explain the consequences wrt route lookup of doing rdr outbound

Re: Xorg slugish performance in AMD64 with intel GM965

2010-06-08 Thread Henning Brauer
of xorg.conf.output] -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pf anchors

2010-06-07 Thread Henning Brauer
to no valid combination hmm. your understanding is correct, the in is (kind of, practically it is, we won't hit the rule unless the in condition in the anchor is true) inherited. the little validity check in pfctl doesn't grok that tho. hrm. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web

Re: pf anchors

2010-06-07 Thread Henning Brauer
, for nat inbound) in the manpage. but it is very very very hard to explain. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: Installer bug? - Upgrade 4.6 to 4.7 failed to upgrade base47, on i386 and amd64

2010-06-04 Thread Henning Brauer
* Uwe Dippel udip...@gmail.com [2010-06-04 18:26]: I didn't know that the object directories need to be cleaned manually. this should not be needed assuming system time didn't jump. it is still good practice tho. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http

Re: unknown i686 model 0x1e, can't get bus clock (0x0)

2010-06-04 Thread Henning Brauer
be done on these processors due to MSR differences. Just 'hide' them. Such a great solution! that doesn't mean anything. the info just isn't in the same place as it used to be, so it is pointless for this part of the code to try to figure it out. -- Henning Brauer, h...@bsws.de, henn

Re: traffic management

2010-06-03 Thread Henning Brauer
they lower my motivation to work in that area. that was my share of cheap talk on the topic. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: carp and OS upgrades

2010-06-02 Thread Henning Brauer
perfectly valid tcp sessions that just idle a bit when I am at foreign networks (conferences, especially at universities, hotels, ...) users must be used to that :) -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS

Re: carp and OS upgrades

2010-06-02 Thread Henning Brauer
, not OpenBSD. The idea that someone installing those networks could have remotely enough of a clue to find tcp.established and change it to, what, 300 seconds... no. impossible. wait. clue and changing tcp.established to something small in one person cannot exist. q. e. d. -- Henning Brauer, h

Re: pfsync question

2010-05-28 Thread Henning Brauer
different names for the interface and the states for rl0 (from em0) are invalid? interface names must match. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application

Re: Question about one slide from Puffy at work presentation

2010-05-27 Thread Henning Brauer
* Tomas Bodzar tomas.bod...@gmail.com [2010-05-27 07:40]: someone know which commercial SW is mentioned here in example? http://quigon.bsws.de/papers/2010/bsdcan/mgp5.html I long forgot. that is from like, 8 years ago. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services

Re: major bump note in faq/current.html

2010-05-27 Thread Henning Brauer
* Charles Smith chasm_...@gmx.com [2010-05-27 20:06]: Can we ask in the future something similar at src/*/shlib_version major bumps? this is not practical. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS

Re: PF log files.

2010-05-26 Thread Henning Brauer
* Henning Brauer lists-open...@bsws.de [2010-05-25 20:31]: * Peter Fraser p...@thinkage.ca [2010-05-25 19:10]: I have been modifying my fire rules using the 4.7 syntax. It would have been really nice if the tcpdump showed the final address as well as the initial address of the packet

Re: PF log files.

2010-05-25 Thread Henning Brauer
recently discovered and plan to fix real soon now. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: 4.7 pf: quick and rdr-to/nat-to

2010-05-23 Thread Henning Brauer
the firewall. If there was a other rule, comment this rule out, can't stop the traffic. I don't understand this behaviour. well, there HAS to be another rule that matches later, or this would not happen. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full

Re: panic: pool_do_get(mcl2k) on -current

2010-05-23 Thread Henning Brauer
a kernel panic before. Thanks. noone can tell without the trace. and please transscribe. you want to make it easy for us to help you, right? -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers

Re: OpenBGP: 3 doubts regarding localpref, rib out and announcement

2010-05-23 Thread Henning Brauer
. However its still dont get announced to my peers. i bet this is an invalid nexthop case. set nexthop-self might be required. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers

Re: pf, altq and interface groups

2010-05-22 Thread Henning Brauer
? pf.conf's BNF, it appears, says I'm not... no ifgroup support for altq - and it is not easy to add either. the BNF is simplified, otherwise it would explode. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS

Re: PF: Example: Firewall for Home or Small Office

2010-05-22 Thread Henning Brauer
* Peter N. M. Hansteen pe...@bsdly.net [2010-05-22 19:08]: a little odd that the pf faq has not been updated huh? it has been updated, the same day 4.7 has been released -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail

Re: PF: Example: Firewall for Home or Small Office

2010-05-22 Thread Henning Brauer
* Mike M the.li...@mgm51.com [2010-05-22 19:45]: On 5/22/2010 at 7:26 PM Henning Brauer wrote: |* Peter N. M. Hansteen pe...@bsdly.net [2010-05-22 19:08]: | a little odd that the pf faq has not been updated | |huh? it has been updated, the same day 4.7 has been released

Re: Resilient RAID

2010-05-21 Thread Henning Brauer
* Kevin Chadwick ma1l1i...@yahoo.co.uk [2010-05-21 11:28]: On Thu, 20 May 2010 18:53:38 +0200 Henning Brauer lists-open...@bsws.de wrote: * Xavier Beaudouin k...@oav.net [2010-05-20 17:34]: And if you don't want to suffer because of a harddisk failure you can also use flashrd

Re: Resilient RAID

2010-05-21 Thread Henning Brauer
* Siju George sgeorge...@gmail.com [2010-05-21 19:13]: On Thu, May 20, 2010 at 9:53 AM, Henning Brauer lists-open...@bsws.de wrote: 2) flash never fails, right. fuck redundancy, I have flash! when you say flash are you talking about http://www.transcendusa.com/products/ModDetail.asp

Re: DISKLESS kernel for moving an install to a larger disk

2010-05-20 Thread Henning Brauer
there is plain no need for a special diskless kernel any more, generic figures out where it was booted from, the ramdisks don't need to. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers

Re: dmesg FW-8750 with 4G from 4.7-current

2010-05-20 Thread Henning Brauer
useable as of now or it would be default. the difference being PCI space mostly. only have 32bit adressing ake 4G for mem AND pci etc, ya know. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated

Re: Resilient RAID

2010-05-20 Thread Henning Brauer
questions: What is the most recent OpenBSD release that does support and document installing on to RAID? none. it's pointless anyway. use two machines and carp, et voila, resilent against a lot more things than just disk failures. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web

Re: Resilient RAID

2010-05-20 Thread Henning Brauer
a regular harddisk. the write cycle myth is just a myth these days, the current stuff copes transparently. 2) flash never fails, right. fuck redundancy, I have flash! -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS

Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-20 Thread Henning Brauer
* Graham Allan al...@physics.umn.edu [2010-05-20 19:23]: On Thu, May 20, 2010 at 07:02:23PM +0200, Axel Rau wrote: Am 20.05.2010 um 00:04 schrieb Henning Brauer: * Axel Rau axel@chaos1.de [2010-05-19 10:34]: Now the question: Can I put a trunk on top of a carp? you put carp

Re: Where is OpenBSD/LibSpec/Build.pm?

2010-05-20 Thread Henning Brauer
but that is current. 4.7 doesn't have it. as in, you have something -current in your mix (pbly ports) and mixing release/stable is not supported. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated

Re: Where is OpenBSD/LibSpec/Build.pm?

2010-05-20 Thread Henning Brauer
* Eric d'Alibut eric.hali...@gmail.com [2010-05-20 20:01]: On Thu, May 20, 2010 at 1:31 PM, Henning Brauer lists-open...@bsws.de wrote: but that is current. 4.7 doesn't have it. as in, you have something -current in your mix (pbly ports) and mixing release/stable is not supported. So I

Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-20 Thread Henning Brauer
* Jussi Peltola pe...@pelzi.net [2010-05-20 20:07]: On Thu, May 20, 2010 at 07:28:55PM +0200, Henning Brauer wrote: * Graham Allan al...@physics.umn.edu [2010-05-20 19:23]: On Thu, May 20, 2010 at 07:02:23PM +0200, Axel Rau wrote: Am 20.05.2010 um 00:04 schrieb Henning Brauer

Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-20 Thread Henning Brauer
* Henning Brauer lists-open...@bsws.de [2010-05-20 20:23]: * Jussi Peltola pe...@pelzi.net [2010-05-20 20:07]: On Thu, May 20, 2010 at 07:28:55PM +0200, Henning Brauer wrote: * Graham Allan al...@physics.umn.edu [2010-05-20 19:23]: On Thu, May 20, 2010 at 07:02:23PM +0200, Axel Rau wrote

Re: something to do

2010-05-19 Thread Henning Brauer
-neil_dcbsdcon2009.pdf That is what you're referring to, correct? while I am not Ted - yes, that is what he means. We talked about it in Ottawa. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated

Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-19 Thread Henning Brauer
* Axel Rau axel@chaos1.de [2010-05-19 10:34]: Now the question: Can I put a trunk on top of a carp? you put carp on top of the trunk of course. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services

Re: pf change in upgrade47.html

2010-05-16 Thread Henning Brauer
rule, it will apply to any interface in the egress group at the time the packet in question is evaluated by pf. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application

Re: pf change in upgrade47.html

2010-05-16 Thread Henning Brauer
else who hangs out here, it seems. pass / block and match nat-to afterwards works fine. so does doing that very same match nat-to beforehands. so does doing the nat-to on the pass rules. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure

Re: pf change in upgrade47.html

2010-05-16 Thread Henning Brauer
; author: henning; state: Exp; lines: +91 -66 -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pf change in upgrade47.html

2010-05-16 Thread Henning Brauer
use the () notation. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: strangely slow OpenBSD server connection

2010-05-16 Thread Henning Brauer
* Claudio Jeker cje...@diehard.n-r-g.com [2010-05-10 19:30]: On Mon, May 10, 2010 at 06:56:27PM +0200, Henning Brauer wrote: * Benny Lvfgren bl-li...@lofgren.biz [2010-05-10 17:42]: What does ifconfig say, particularly the media: line? I've had various problems in the past

Re: strangely slow OpenBSD server connection

2010-05-16 Thread Henning Brauer
the spec. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: strangely slow OpenBSD server connection

2010-05-16 Thread Henning Brauer
were ciscoese, dell sonicwall. that is a partial list of vendors to avoid. not just for that reason. personally I have not run into a cisco broken like that, but I rarely use that shit any more. and dell/sonicwall, leave me alone. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web

Re: strangely slow OpenBSD server connection

2010-05-10 Thread Henning Brauer
asking them whether they set the port to auto or fixed is a good idea, but randomly pushing buttons is as idiotic as ever. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers

Re: Hardware for a PF box

2010-05-10 Thread Henning Brauer
firewalls. what is written to disks? logs. not all that much. read? after boot, not much. so using your expensive SAS-disks elsewhere is a good idea. a cheap 40..64G SSD will do fine. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure

Re: OT - UML, can someone state that it works ?

2010-05-06 Thread Henning Brauer
be the goal. think of the children, their dads need jobs! -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: [Bulk] Re: State of multiprocessing and multithreading in OpenBSD

2010-05-05 Thread Henning Brauer
. once booted the processors are treated the same. one is just special up to the point where the secondary CPUs are spun up. well, in general, that is the story. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services

Re: Testing bigmem properly on amd64?

2010-04-15 Thread Henning Brauer
proving the fact, well, you could test that water is wet, too. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: licensing

2010-04-15 Thread Henning Brauer
agree to a new license. or don't use that code. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: Trying to boot OpenBSD on Juniper Networks J2320.

2010-04-14 Thread Henning Brauer
it is all custome and closed yadda yadda there is close to zero chance we ever run on that gear. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: feature request: fallback boot image

2010-04-02 Thread Henning Brauer
* Toni Mueller openbsd-m...@oeko.net [2010-04-02 12:25]: it would be great to be able to specify a fallback kernel in case booting a new kernel fails how exactly does the bootloader notice your new kernel sitting in ddb? -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services

Re: Quad or dual port 1000baseSX nics ?

2010-04-02 Thread Henning Brauer
successful report with quad or dual (at least) pci-e fiber nics ? i dunno about the many-ports ones, but my (oldish) fiber ems work just fine. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated

Re: pfctl(8): unclear docs

2010-03-17 Thread Henning Brauer
that could break. A clarification in the docs is imho the way to go. no, we'll kill that bullshit, soon. it is just leftover pf must be ipf alike goo. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services

Re: pfctl(8): unclear docs

2010-03-17 Thread Henning Brauer
them. soon. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: questions about OpenBSD 4.7

2010-03-17 Thread Henning Brauer
be at least some performance, stability improvements. yes, there are massive improvents. in ours. not theirs. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application

Re: 4.7: doesn't route IPSEC traffic very well

2010-03-17 Thread Henning Brauer
* Toni Mueller openbsd-m...@oeko.net [2010-03-17 18:02]: Ideas about how to debug these, are most welcome! you forgot to read the release notes. ok, they don't exist yet. so it is current.html instead. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full

Re: h323 statefull firewall

2010-03-16 Thread Henning Brauer
in the first place obviously. at least not enough to write a proxy. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: any known working configuration of OpenBGPd and CARP ?

2010-03-12 Thread Henning Brauer
of BGP plase send me the diff for tcp session failover that you must have written -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: any known working configuration of OpenBGPd and CARP ?

2010-03-12 Thread Henning Brauer
. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: tools for finding a type of bug?

2010-03-06 Thread Henning Brauer
to search the tree and find all instances of this bug. grep! (or, advanced grep, gid from id-utils) -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: any known working configuration of OpenBGPd and CARP ?

2010-03-06 Thread Henning Brauer
on the inner interface. what you are seeing is kinda expected, the routes are invalid from the backup host's POV since it does not have a valid route to the nexthop (this is half guessed since you didn't provide any details) -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http

Re: Opteron 250 Overheating

2010-03-03 Thread Henning Brauer
* Jeff Ross jr...@openvistas.net [2010-03-02 17:48]: Henning Brauer wrote: * Jeff Ross jr...@openvistas.net [2010-03-02 16:59]: I bought a replacement supermicro motherboard off fleabay that has dual Opteron 250 @2.4GHz. The cpus have passive heatsinks, it is in a supermicro 2U chassis

Re: Opteron 250 Overheating

2010-03-02 Thread Henning Brauer
a tunnel over the heatsinks? it is required. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: kern.maxclusters: 6144 - ?

2010-03-01 Thread Henning Brauer
and the system copes with the ressource shortage. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: selling bsd in cd for profit??

2010-03-01 Thread Henning Brauer
* Peter N. M. Hansteen pe...@bsdly.net [2010-02-28 13:37]: Henning Brauer lists-open...@bsws.de writes: except that the openbsd cd layout is not BSD licensed. you are not allowed to burn the iso and sell that. It's the layout of the official CD sets that's explicitly not BSD licensed

Re: kern.maxclusters: 6144 - ?

2010-03-01 Thread Henning Brauer
* Claudio Jeker cje...@diehard.n-r-g.com [2010-03-01 15:32]: On Mon, Mar 01, 2010 at 02:48:50PM +0100, Henning Brauer wrote: * Pete Vickers p...@systemnet.no [2010-03-01 12:28]: okay, sounds reasonable. I've also 'fiddled with other knobs' too, so I hope my kern.maxclusters at 8192

Re: selling bsd in cd for profit??

2010-02-28 Thread Henning Brauer
and sell that. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pfctl table cleared time is jumping around

2010-02-24 Thread Henning Brauer
* Dan Harnett dan...@harnett.name [2010-02-24 15:29]: On Wed, Feb 24, 2010 at 08:30:05AM +0100, Henning Brauer wrote: * Dan Harnett dan...@harnett.name [2010-02-23 21:19]: Probably wrong, but this fixes it. i would not call that wrong. i don't understand how this ever worked

Re: pf packet tagging and keep state

2010-02-23 Thread Henning Brauer
* Andreas Mueller andr...@stapelspeicher.org [2010-02-22 23:57]: Henning Brauer wrote: err? packets matching the state are of course queued in the queue specified in the rule, what else? Maybe I am influenced too much with linux traffic-shaping/firewalling. And from that point, I

Re: Sparc classic serial ports ttya vs cuaa

2010-02-23 Thread Henning Brauer
the onboard cereals use tho. the manpage would have a note. However, the device does exist in the /dev tree: of course. that doesn't mean anything. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services

Re: pfctl table cleared time is jumping around

2010-02-23 Thread Henning Brauer
, approximately? -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pfctl table cleared time is jumping around

2010-02-23 Thread Henning Brauer
* Dan Harnett dan...@harnett.name [2010-02-23 21:19]: On Tue, Feb 23, 2010 at 02:28:17PM -0500, Dan Harnett wrote: On Tue, Feb 23, 2010 at 05:24:30PM +0100, Henning Brauer wrote: I don't remember any changes in that area lately so this puzzles me. do we know when this breakage

Re: Sparc classic serial ports ttya vs cuaa

2010-02-23 Thread Henning Brauer
* Alexander Carver agcar...@acarver.net [2010-02-24 04:01]: Mattieu Baptiste wrote: On Tue, Feb 23, 2010 at 5:20 PM, Henning Brauer lists-open...@bsws.de wrote: * Alex Carver agcarver+open...@acarver.net [2010-02-23 05:53]: I've been working on getting gpsd working on one of my old Sun IPXes

Re: Using OpenBGPd as a route reflector in a ring topology

2010-02-22 Thread Henning Brauer
* Laurent CARON lca...@unix-scripts.info [2010-02-19 12:44]: Is it realistic to hook up those sites (6 sites) in a ring topology yeah, well, why not? -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services

Re: anything better than the em(4)?

2010-02-22 Thread Henning Brauer
* Kapetanakis Giannis bil...@edu.physics.uoc.gr [2010-02-20 16:59]: Does Intel still not provide appropriate documentation or did that web page expire? no, not really. they ae your best bet anyway tho. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full

Re: another filesystem as backup

2010-02-22 Thread Henning Brauer
that contents the dumps - reaon why. Are there any constraints in doing so ? May you strongly recommand to keep ffs as file system on the backup disk for relevant reasons ? Regards -- http://www.openbsd.org/lyrics.html -- Henning Brauer, h...@bsws.de, henn

Re: RAID1 : offline - online (how to?)

2010-02-22 Thread Henning Brauer
, softraid didn't support rebuilds in 4.4; it was added later. Judging from the man page differences between releases, I'd say it was between 4.4 and 4.5. i'm pretty sure it was after 4.5. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure

Re: pf packet tagging and keep state

2010-02-21 Thread Henning Brauer
* Andreas Mueller andr...@stapelspeicher.org [2010-02-22 03:00]: Hi, Henning Brauer wrote: [...] in general, tag/tagged influences ruleset evaluation. once state is created there is no ruleset eval any more for packets matching that state. Is there any way to, e.g., tag or queue

Re: OpenNTPd source IP

2010-02-19 Thread Henning Brauer
by hand. yes, all our lexers are handrolled, lex sucks. check yylex() in parse.y -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: Kernel page fault trap, code=0, uvm_fault, what to do next

2010-02-19 Thread Henning Brauer
. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pf packet tagging and keep state

2010-02-19 Thread Henning Brauer
on same interface, thus there will be no re-evaluate rule. am i right ? i have a hard time extracting anything that would make sense from the above. in general, tag/tagged influences ruleset evaluation. once state is created there is no ruleset eval any more for packets matching that state. -- Henning

Re: MAX_KMAPENT and NKMEMPAGES

2010-02-19 Thread Henning Brauer
also ended up pushing the wrong ones. the mbuf related pools these days are 1) way bigger by default than they used to be, and rarely need any adjustment at all and 2) the relevant one (mbuf cluster pool, mcl2k) grows on demand up to the value in sysctl kern.maxclusters. -- Henning Brauer, h

Re: routing and pf at 10Gbps

2010-02-12 Thread Henning Brauer
. it was onbiously not to be taken seriously, of course the graphics adapter is irrelevant (i'm sure you could construct a case where a stupid one actually hurts, but please). -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS

Re: Is OpenBSD + PF accredited or certified in any way ?

2010-02-12 Thread Henning Brauer
and I am pretty sure it isn't but it turns out that our security people will be happy is the firewall is accredited for use by another government ! i herewith certify openbsd + pf for use by government clowns -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de

Re: routing and pf at 10Gbps

2010-02-11 Thread Henning Brauer
with loads of memory of course. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pfctl table cleared time is jumping around

2010-02-09 Thread Henning Brauer
any more. for some time tho. i don't remember any recent changes to the table code (as if anybody wanted to touch that mess) -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers

Re: Maximizing File/Network I/O

2010-02-03 Thread Henning Brauer
* nixlists nixmli...@gmail.com [2010-01-14 08:39]: On Wed, Jan 13, 2010 at 11:43 PM, Henning Brauer lists-open...@bsws.de wrote: * nixlists nixmli...@gmail.com [2010-01-14 03:21]: test results on old P4 are unfortunately pretty much pointless. Why? cpu0: Intel(R) Pentium(R) 4 CPU

Re: HP/Dell RAID

2010-01-13 Thread Henning Brauer
* Steve Shockley steve.shock...@shockley.net [2010-01-13 14:34]: On 1/11/2010 8:54 PM, Henning Brauer wrote: ciss and work well in one sentence without a negation involved? I have several, and haven't experienced any problems. To which PR are you referring? I have a bunch of HP hardware

Re: Maximizing File/Network I/O

2010-01-13 Thread Henning Brauer
* nixlists nixmli...@gmail.com [2010-01-14 01:09]: On Tue, Jan 5, 2010 at 2:32 PM, Henning Brauer lists-open...@bsws.de wrote: I really like the 275 - 420MBit/s change for 4.6 - current with pf. Update: both machines run -current again this time. I think my initial tcpbench results were

Re: pf: reassemble tcp

2010-01-13 Thread Henning Brauer
a page. Any ideas? yeah, don't use reassemble tcp. it's not perfect. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: pf: reassemble tcp

2010-01-13 Thread Henning Brauer
* Ted t...@pobox.com [2010-01-14 05:03]: On Thu, Jan 14, 2010 at 12:46 PM, Henning Brauer lists-open...@bsws.dewrote: I have match in all scrub (tcp reassemble no-df random-id max-mss 1440) in my pf.conf (-current) yeah, don't use reassemble tcp. it's not perfect

Re: Maximizing File/Network I/O

2010-01-13 Thread Henning Brauer
, but still... What's the issue? cache -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: obsd as domU?

2010-01-12 Thread Henning Brauer
. it is this mindset that gets this industry in shit every other day. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: HP/Dell RAID

2010-01-11 Thread Henning Brauer
* Steve Shockley steve.shock...@shockley.net [2010-01-12 01:36]: The Compaq/HP Smart 5 and above controllers (ciss) should work well. ciss and work well in one sentence without a negation involved? -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full

Re: Which laptops do the developers use?

2010-01-10 Thread Henning Brauer
* nixlists nixmli...@gmail.com [2010-01-11 02:20]: If I'd want to buy a laptop, I'd want nothing else than the recent MacBook or MacBook Pro stockholm syndrome -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS

Re: obsd as dom0?

2010-01-10 Thread Henning Brauer
* Vadkan Jozsef jozsi.avad...@gmail.com [2010-01-10 12:40]: Is it possible? yes, you just have to write the code -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers

Re: Maximizing File/Network I/O

2010-01-08 Thread Henning Brauer
. others have improved performance in subsystems used. i almost always bench my changes. i cannot point my finger to one change between 4.6 and -current that is the cause for this improvement, there were a few - and i keep forgetting what made 4.6 and what was after. -- Henning Brauer, h...@bsws.de, henn

Re: Maximizing File/Network I/O

2010-01-08 Thread Henning Brauer
* nixlists nixmli...@gmail.com [2010-01-06 09:33]: On Wed, Jan 6, 2010 at 2:31 PM, Henning Brauer lists-open...@bsws.de wrote: I really like the 275 - 420MBit/s change for 4.6 - current with pf. Disabling pf gives a couple of MB/s more. really. what a surprise. -- Henning Brauer, h

Re: pf: match vs. pass - nat and rdr

2010-01-08 Thread Henning Brauer
that, undebuggable with the info at hand. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting

Re: Maximizing File/Network I/O

2010-01-05 Thread Henning Brauer
unless you are a @henning or @claudio :) heh :) I really like the 275 - 420MBit/s change for 4.6 - current with pf. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers

<    1   2   3   4   5   6   7   8   9   10   >