Re: analysing packets in user space process

2006-01-17 Thread Bill Marquette
On 1/17/06, Edmond Dantes <[EMAIL PROTECTED]> wrote: > I would like to do some content analysis on packets from a user space process, > something like a L7 filter. rdr seems the way to go, but I cannot understand > how to get the packets back into pf so it can continue with the rules and > maintain

Re: analysing packets in user space process

2006-01-17 Thread Travis H.
You get a packet into pf by sending the packet. There is no easy way to "resume processing". Once it has been sent to userland, processing is over. There's nothing to resume. If you're asking about this, you're probably out of your depth. You might wish to look at the ftp proxy to see how that

Re: Warning: Sangoma S518 DSL card no longer OpenBSD compatible

2006-01-17 Thread eric
On Tue, 2006-01-17 at 15:27:20 -0700, Chris 'Xenon' Hanson proclaimed... > I just bought a Sangoma S518 ADSL card to replace my external Cisco 678, > hoping to realize numerous benefits. Unfortunately, after receiving it, I > discover that the new smaller-form-factor version of the card is d

Warning: Sangoma S518 DSL card no longer OpenBSD compatible

2006-01-17 Thread Chris 'Xenon' Hanson
I just bought a Sangoma S518 ADSL card to replace my external Cisco 678, hoping to realize numerous benefits. Unfortunately, after receiving it, I discover that the new smaller-form-factor version of the card is different internally from the original hardware, and the existing drivers for all

[OT] pf and vpn

2006-01-17 Thread Peter
Excuse the off-topic. I have some basic questions regarding implementing a vpn and I figured pf is closely related enough. I have posted similar questions to openbsd.misc and comp.security.unix without success. 1. There are many references to bypassing IPsec processing for gateway-gateway commun

analysing packets in user space process

2006-01-17 Thread Edmond Dantes
I would like to do some content analysis on packets from a user space process, something like a L7 filter. rdr seems the way to go, but I cannot understand how to get the packets back into pf so it can continue with the rules and maintain state info. Suggestions? TIA /ED

Help with transparent bridge + NAT'd PCs

2006-01-17 Thread yary
Hi. I'm having a confusing time with a network setup... this is using pf on OpenBSD 3.8, generic 386 kernel VOIP Phones (public 20.0.0.x/24) mixed with Office PCs (private 192.168.1.x/24) ||| \V/ HW switch | $int_if OpenBSD router (192.168.1. 1) | +--- $ext_if