Re: squid process dies when it reaches a size of 1GB.

2006-07-18 Thread Janne Johansson

Joe Gibbens wrote:

Thanks for the reply Janne.
 
So my only way to run a process over 1GB in size is a custom kernel?  Is 


Yes, as of now, on i386.

there an easier way to run a large cache with a process size over 1GB?  


You can do other things aswell, like bumping cachepct to ~12 with
config -ef /bsd (I believe there is a limit close to 256M for filesystem 
cache on obsd, and you're having 2G ram gives 12 percent for that)

Not much help there, but at least something.

I can re-configure the memory usage, but it would be nice to be able to 
utilize more of my physical memory without having to go with a custom 
kernel.


Hack away, solve the issues! =)
(Or pay someone to do it for you/us)



Network debuggery on OpenBSD

2006-07-18 Thread R. Tyler Ballance
Howdy,

I'm working on debugging a quirky bug (aren't they all) when using an  
OpenBSD NFS client with a FreeBSD NFS server, I'm certain it's  
agnostic of the NFS server, but I can't say for sure because we rely  
on FreeBSD servers, and the Mac OS X and redhat NFS clients function  
properly. I'm still working out the specific, and appropriate  
reproduction steps for the bug, but in short, it leaves the OpenBSD  
machine completely frozen. Interestingly enough, the OpenBSD machine  
still responds to pings over the network, but all physical and  
virtual terminals become completely locked. (This excludes the  
keyboard shortcuts to drop the machine into ddb when ddb.console => 1 )

The basic question is, what are my options for pinpointing this bug?  
 From what I remember correctly I can setup ddb over a serial console  
through some means, but the machine is atop a bookshelf and about  
50ft from my workstation ;) I've examined the tcpdump output on the  
server side of things, but nothing out of order, with the exception  
of the sudden drop in data being transferred, is noticable on that  
side of things. I'm wondering if there's anyway from ddb I can  
accurately gauge _where_ the lock up is happening, and then of  
course, how it is happening ;)

Usually I'm comfortable with attaching gdb to a process and then  
making progress that way, but this is a realm unfamiliar to me in  
terms of debugging, so suggestions are welcome.


Cheers,

-R. Tyler Ballance
Lead Developer, bleep. LLC
http://www.bleepsoft.com

[demime 1.01d removed an attachment of type application/pgp-signature which had 
a name of PGP.sig]



Re: dhcpd static addresses

2006-07-18 Thread Nick Holland

Dave Gloez wrote:

Hello,


I have a soekris box where dhcpd is running to give ip addresses for
clients, now i was thinking is it possible to give clients a static
ip based on which interface it is connected, so when i plug the
network cable to specified network port on soekris it would always
give the same ip address no matter what.


yes it is possible (and another person has told you how to do it, very 
well, I might add, a tip and a pointer to the man page.  Good style! :)


On the other hand...if the machines are used at least once in a while, I 
think you will find the addresses given out by OpenBSD's dhcpd are 
amazingly "static" (in the "once you get an IP address, you will keep 
getting that same address" sense).  So, if you are only concerned about 
them having a stable IP address rather than a particular IP address, you 
may not need to do anything at all.


note: if you chose to go the "defined address" route, the defined 
address does NOT go in your DHCP "range".  I think I was bit by that at 
least once. :)


Nick.



sasl and openbsd 3.8

2006-07-18 Thread Gustavo Rios

Helo folks,

Is any one aware of any issue related to the openbsd ports' sasl 2.1.20 ?

I am not able to get GSSAPI reconized and, of course, i do have
heimdal working perfectly. It sounds but it is as if it could detect
support for GSSAPI.

Is there anything i lost?

Thanks in advance.



confirma tu presencia gracias

2006-07-18 Thread Lic. Sandra Riveroll
Haz que todo el DF conozca tu empresa y servicios,
 invmtalos a que te llamen y visiten, gracias a nuestros

!!10 millones 200 mil correos masivos!! como iste,

que loquierotodo.com emite con tu publicidad

!Por sslo $1,500 pesos el trimestre

(IVA incluido)

Ademas te obsequiaremos por el mismo precio,

• un anuncio AA dentro del portal www.loquierotodo.com durante tres meses

• Y otro anuncio !gratis! de 6.2 x 5.0 cm. en el perisdico impreso a
color de 45,000 ejemplares
 que se distribuye en las 10 principales colonias de la ciudad.

(Santa Fe, Polanco, Zona Rosa, Condesa, Roma, Del Valle, Napoles, San
Josi Insurgentes, San Angel, Coyoacan y en todas las oficinas del WTC)

[IMAGE]

El correo masivo se manda a toda nuestra base de datos, que es segmentada,
de mas de 1 millsn 700 mil personas en el DF y quienes quincenalmente
recibiran su publicidad  a travis de  un correo masivo (como el que se
muestra abajo) llegando asm al total de 10 millones 200 mil correos
emitidos durante el trimestre, nuestra base de datos esta conformada por
hombres y mujeres mayores de 18 aqos. Nivel socio-cultural A, B, C, y C+,
que viven o trabajan en la Ciudad de Mixico. Universitarios,
profesionistas, empresarios, amas de casa, especialistas, gobierno y
pzblico en general.

Ejemplo del correo masivo, dar click sobre la imagen central:

[IMAGE]

[IMAGE]

[IMAGE]

Invitamos a todo aquel, que tenga una empresa, negocio, institucisn o
consultorio a que adquiera esta promocisn, al mas bajo costo, creada
pensando en las micro y  medianas empresas (PYMES) para hacerles !Crecer
sus Ventas!

!Pregunta por nuestras formas de pago!

•Llama hoy para hacer tu pedido•

Y recibe un 10% de descuento al adquirir tu anuncio ya sea en nuestras
oficinas o por cierre electrsnico o telefsnico

5682-5545, 5020-9220, 3187-0485 y 1041-7446

[EMAIL PROTECTED]

www.loquierotodo.com

[IMAGE]

Recomienda nuestros servicios a tus amigos, reenviando este correo.

Si no deseas recibir correos futuros, favor de responder este mensaje
poniendo en asunto "Borrar lista"



Re: Something like Plesk for OpenBSD

2006-07-18 Thread Bryan Irvine

I would like recommendations on solutions like Plesk for OpenBSD.


AFAIK plesk runs on OpenBSD.  If you are looking for something free, I
think there is only webmin.

--Bryan



Re: best place to specify ipv6 default route

2006-07-18 Thread Paul de Weerd
On Tue, Jul 18, 2006 at 04:33:36PM -0500, Eric Pancer wrote:
| Send a patch if you really want the behavior, but I'm pretty sure that's
| only intended for IPv4.

The patch is already there .. check [1]

| $ grep -A 2 -B 2 mygate /etc/netstart
| done
|
| # /etc/mygate, if it exists, contains the name of my gateway host
| # that name must be in /etc/hosts.
| if [ -f /etc/mygate ]; then
| route -qn delete default > /dev/null 2>&1
| route -qn add -host default `stripcom /etc/mygate`
| fi

You should a) use grep -C and b) check out 3.9 or -current ;)

Cheers,

Paul 'WEiRD' de Weerd

[1]: http://marc.theaimsgroup.com/?l=openbsd-cvs&m=112930507105045&w=2

--
>[<++>-]<+++.>+++[<-->-]<.>+++[<+
+++>-]<.>++[<>-]<+.--.[-]
 http://www.weirdnet.nl/

[demime 1.01d removed an attachment of type application/pgp-signature]



Still getting some random connections blocked in pf- hardware problem?

2006-07-18 Thread Ashley Moran
I'm trying to diagnose the problem in our new firewall setup.  I've  
drawn a digram below.  We have two IP ranges, one serviced by an  
IPCop Linux distro, another by a CARPed OpenBSD pf pair (currently  
OpenBSD 3.8).  Currently our old windows web server is assigned  
addresses from the first range, and the two clustered (CARPed  
FreeBSD) are behind the OpenBSD pair.  (The issue occurs with the  
windows server too though.)


The aim is to relegate the IPCop server to a spam filter in front of  
the internal network.  Currently all internal traffic goes through  
IPCop, even that destined for hosts filtered by the OpenBSD boxes.


Basicaly I have made pf rules that seem to allow traffic through, and  
after reading through them hundreds of times, even my inexperienced  
eyes are beginning to think they must be correct (they're in my  
previous email though.)


Here are my observations of the problem:
 - access through the OpenBSD firewalls is REALLY slow, giving a
   noticeable delay on web sites
 - despite this MOST traffic goes through
 - however, a small number of connections are blocked by the main
   "block all log" rule, seen in a tcpdump of pflog0:
   - the connections from the internet are blocked IN on the dmz
 interface (em0)
   - and the wierd bit! traffic from out internal network is blocked
 going OUT on the external interface (vr0)
   - I have even seen packets dropped on pflog where there was
 apparently a state for that connection - I might have to sanity
 check that but I'm fairly sure it's not me going mad


Here are my thoughts about the likely cause of the problem:

- I don't think it's the firewall rules, as they work 90% of the time
- I don't think it's any of the physical networking as the other  
machines run fine


- Could it be hardware incompatibility?
  - I saw this in the em man page:
 There is a known compatibility issue where time to link is slow  
or link
 is not established between 82541/82547 controllers and some  
switches.

 Known switches include:
   I-O Data ETG-SH8
   Planex FXG-08TE
  - Also it is brand new hardware, Intel board and onboard ethernet

Unforunately I'm at home now and can't find the exact hardware  
description of the machines from here.  I don't know whether the  
bizarre pf logs showing different failures from our internal requests  
to external (which are ALL external as far as the firewalls are  
concerned) are evidence for or against it being hardware (or driver)  
related.


Tomorrow I plan to rebuild the firewalls with OpenBSD 3.9 in the hope  
it is a recently-fixed bug.  Failing that I will be forced to find an  
old desktop and try installing one on that.


I'm hoping someone will recognise the symptoms as that might point me  
in the right direction and save me time (although I ran out of that  
days ago!!!)


Thanks
Ashley


  internet
  |
  |
  --
 | ISP Cisco Router |
  --
  |
  |
>--- eth switch >
   ^ |
   | x.x.1.x v x.x.2.x
--- -<-- eth switch 
 --->--| IPCop |   ||
|   ---v vr0| vr
|   |     
|   | | OpenBSD/pf | | OpenBSD/pf |
^   |     
|   |em0|   |em1em0|__switch_|em1
|   |   v  | |
|   |-->- eth switch --  |
|   | |  |
|   |  <__v  |
|   |   DMZ   |  |
|  ---   |
^ |   webserv1 (win)  [ipcop] |  .
| |  webserv2a (fbsd) [obsd]  |  .
| |  webserv2b (fbsd) [obsd]  |  .
|  ---   .
|.
 <---<---<-internal network

 arrows show route from internal network to new webservers




(On the plus side, drawing the above piece of ASCII art was very  
theraputic.)




Re: best place to specify ipv6 default route

2006-07-18 Thread Darrin Chandler
On Tue, Jul 18, 2006 at 04:33:36PM -0500, Eric Pancer wrote:
> $ grep -A 2 -B 2 mygate /etc/netstart
> done
> 
> # /etc/mygate, if it exists, contains the name of my gateway host
> # that name must be in /etc/hosts.
> if [ -f /etc/mygate ]; then
> route -qn delete default > /dev/null 2>&1
> route -qn add -host default `stripcom /etc/mygate`
> fi

Ahhh. That's not what's in my 3.9-stable. The netstart in -stable has
two similar sections, one for ip4 and one for ip6.

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



Re: best place to specify ipv6 default route

2006-07-18 Thread Darrin Chandler
On Tue, Jul 18, 2006 at 05:10:11PM -0400, Will H. Backman wrote:
> It did have dhcp when I installed, but then I changed the 
> /etc/hostname.xl0 to contain only
> inet IP NETMASK.

There's a comment in /etc/netstart that says the gateway *must* exist in
/etc/hosts. I just checked my machine using ip4 in mygate, and I do NOT
have a hosts entry, and it's been working. Hmm.

The script in netstart is simple and clean. You might try running bits
of it and see what's not working. Looks to me like it should work fine,
though I can't see the reason for an entry in /etc/hosts so I might be
missing something.

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



Something like Plesk for OpenBSD

2006-07-18 Thread Rico Secada
Hi

I would like recommendations on solutions like Plesk for OpenBSD.

The main fokus is to make it easy for people (clients) to log on to OpenBSD 
servers and administer their webhotels, change FTP password and so on.

What are people, if any, on the list using?

Best and kind regards!
Rico



Re: best place to specify ipv6 default route

2006-07-18 Thread Eric Pancer
On Tue, 2006-07-18 at 17:13:30 -0400, Will H. Backman wrote...

> Yes, that does work, but I'm curious if /etc/mygate should work.  I 
> usually use /etc/mygate for IPv4, so I'm inclined to use it for IPv6 also.

Send a patch if you really want the behavior, but I'm pretty sure that's
only intended for IPv4.

$ grep -A 2 -B 2 mygate /etc/netstart
done

# /etc/mygate, if it exists, contains the name of my gateway host
# that name must be in /etc/hosts.
if [ -f /etc/mygate ]; then
route -qn delete default > /dev/null 2>&1
route -qn add -host default `stripcom /etc/mygate`
fi

- Eric



Re: best place to specify ipv6 default route

2006-07-18 Thread Will H. Backman

Eric Pancer wrote:

On Tue, 2006-07-18 at 16:37:23 -0400, Will H. Backman wrote...

  
The man page for mygate says that one can add an IPv6 gateway address to 
/etc/mygate, but it doesn't seem to add an entry to the routing table 
upon reboot.  I'm not using rtsol anywhere.
Most of my searching on the internet shows people adding a line to the 
/etc/hostname.gif0 file, i.e:


!route -n add -host -inet6 default 2001:470:1f00:::244

Adding the line to the hostname.if file does work, but putting the gateway 
IPv6 address in /etc/mygate doesn't.

What is the suggested way to do this?
This is on 3.9-RELEASE.



Put it in /etc/hostname.gifX.

Such as this..

$ cat /etc/hostname.gif0
giftunnel 207.227.243.193 205.234.148.199
!ifconfig gif0 inet6 2001:4830:e5:6::2 2001:4830:e5:6::1 prefixlen 128 mtu 1480
!route -n add -inet6 default 2001:4830:e5:6::1

Then you'll be all set to go.
  
Yes, that does work, but I'm curious if /etc/mygate should work.  I 
usually use /etc/mygate for IPv4, so I'm inclined to use it for IPv6 also.




Re: best place to specify ipv6 default route

2006-07-18 Thread Will H. Backman

Darrin Chandler wrote:


On Tue, Jul 18, 2006 at 04:37:23PM -0400, Will H. Backman wrote:
> The man page for mygate says that one can add an IPv6 gateway address to
> /etc/mygate, but it doesn't seem to add an entry to the routing table
> upon reboot.  I'm not using rtsol anywhere.
> Most of my searching on the internet shows people adding a line to the
> /etc/hostname.gif0 file, i.e:
>
> !route -n add -host -inet6 default 2001:470:1f00:::244
>
> Adding the line to the hostname.if file does work, but putting the 
gateway

> IPv6 address in /etc/mygate doesn't.
> What is the suggested way to do this?
> This is on 3.9-RELEASE.

Are you using *any* dhcp, by chance?

--
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |

It did have dhcp when I installed, but then I changed the 
/etc/hostname.xl0 to contain only

inet IP NETMASK.



Re: best place to specify ipv6 default route

2006-07-18 Thread Eric Pancer
On Tue, 2006-07-18 at 16:37:23 -0400, Will H. Backman wrote...

> The man page for mygate says that one can add an IPv6 gateway address to 
> /etc/mygate, but it doesn't seem to add an entry to the routing table 
> upon reboot.  I'm not using rtsol anywhere.
> Most of my searching on the internet shows people adding a line to the 
> /etc/hostname.gif0 file, i.e:
> 
> !route -n add -host -inet6 default 2001:470:1f00:::244
> 
> Adding the line to the hostname.if file does work, but putting the gateway 
> IPv6 address in /etc/mygate doesn't.
> What is the suggested way to do this?
> This is on 3.9-RELEASE.

Put it in /etc/hostname.gifX.

Such as this..

$ cat /etc/hostname.gif0
giftunnel 207.227.243.193 205.234.148.199
!ifconfig gif0 inet6 2001:4830:e5:6::2 2001:4830:e5:6::1 prefixlen 128 mtu 1480
!route -n add -inet6 default 2001:4830:e5:6::1

Then you'll be all set to go.



Re: TTL increment

2006-07-18 Thread Darrin Chandler
On Tue, Jul 18, 2006 at 11:41:40PM +0300, Rosen Nedialkov wrote:
> Hi all! Is there a way to increment a packet TTL value that passes through
> OpenBSD router ? My ISP sends me packets with TTL=1 so I can't route my net. 
> In
> Linux there is a ttl_inc.ko which does the job, but I want to switch to 
> OpenBSD
> so I need to find a solution :)
> 
> Thanks in advance

scrub with min-ttl?

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



Re: best place to specify ipv6 default route

2006-07-18 Thread Darrin Chandler
On Tue, Jul 18, 2006 at 04:37:23PM -0400, Will H. Backman wrote:
> The man page for mygate says that one can add an IPv6 gateway address to 
> /etc/mygate, but it doesn't seem to add an entry to the routing table 
> upon reboot.  I'm not using rtsol anywhere.
> Most of my searching on the internet shows people adding a line to the 
> /etc/hostname.gif0 file, i.e:
> 
> !route -n add -host -inet6 default 2001:470:1f00:::244
> 
> Adding the line to the hostname.if file does work, but putting the gateway 
> IPv6 address in /etc/mygate doesn't.
> What is the suggested way to do this?
> This is on 3.9-RELEASE.

Are you using *any* dhcp, by chance?

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



TTL increment

2006-07-18 Thread Rosen Nedialkov
Hi all! Is there a way to increment a packet TTL value that passes through
OpenBSD router ? My ISP sends me packets with TTL=1 so I can't route my net. In
Linux there is a ttl_inc.ko which does the job, but I want to switch to OpenBSD
so I need to find a solution :)

Thanks in advance



best place to specify ipv6 default route

2006-07-18 Thread Will H. Backman
The man page for mygate says that one can add an IPv6 gateway address to 
/etc/mygate, but it doesn't seem to add an entry to the routing table 
upon reboot.  I'm not using rtsol anywhere.
Most of my searching on the internet shows people adding a line to the 
/etc/hostname.gif0 file, i.e:


!route -n add -host -inet6 default 2001:470:1f00:::244

Adding the line to the hostname.if file does work, but putting the gateway IPv6 
address in /etc/mygate doesn't.
What is the suggested way to do this?
This is on 3.9-RELEASE.

Thanks in advance.

-- Will



Re: 3.9 freeze

2006-07-18 Thread diego

Federico, I put "option NKMEMPAGES_MAX=65535" on the kernel config.
vmstat -m show that
 UVM amap 68283  2676K   2871K157284K   2166240 0 
16,32,64,128,256,512,1024,2048,4096,32768,65536


the limit now is 157284K, before was 39322K.

regards,.


- Original Message - 
From: "Federico Giannici" <[EMAIL PROTECTED]>

To: "Pedro Martelletto" <[EMAIL PROTECTED]>
Cc: ; "diego" <[EMAIL PROTECTED]>; "mickey" 
<[EMAIL PROTECTED]>

Sent: Tuesday, July 18, 2006 2:34 PM
Subject: Re: 3.9 freeze



Pedro Martelletto wrote:

Federico,

Your diagnosis is correct, that freeze can be the result of reaching the
limit for UVM amap allocations. These get used by the kernel to describe
anonymous memory mappings, and mmap malloc() puts the UVM subsystem
under a higher load of those, eventually reaching the limit. Until an
appropriate solution is found, you can try bumping the number of pages
in the kernel's memory map (NKMEMPAGES).


I'm not sure of what variables to set and where.
Is it correct to add the following line to the kernel configuration file?

option  NKMEMPAGES_MAX  65536


Thanks.

--
___
__
   |-  [EMAIL PROTECTED]
   |ederico Giannici  http://www.neomedia.it
___




Icecast defaults

2006-07-18 Thread Karel Kulhavy
The icecast.xml.dist in Icecast is containing nonexisting directories - maybe
it's intended for the user to fill in, maybe it's just forgotten.

CL<



Re: squid process dies when it reaches a size of 1GB.

2006-07-18 Thread Joe Gibbens
Thanks for the reply Janne.

So my only way to run a process over 1GB in size is a custom kernel?  Is
there an easier way to run a large cache with a process size over 1GB?  I
can re-configure the memory usage, but it would be nice to be able to
utilize more of my physical memory without having to go with a custom
kernel.


On 7/18/06, Janne Johansson <[EMAIL PROTECTED]> wrote:
>
> Joe Gibbens wrote:
> > I'm running squid-transparent on 3.9, and the process dies every time
> > it reaches 1GB.
> > FATAL: xcalloc: Unable to allocate 1 blocks of 4108 bytes!
> > The system has 2GB ram
> >
> > # ulimit -aH
> > time(cpu-seconds)unlimited
> > file(blocks) unlimited
> > coredump(blocks) unlimited
> > data(kbytes) 1048576  <- (where is this limit
> configured?)
>
> /sys/arch/i386/include/vmparam.h:#defineMAXDSIZ
> (1024*1024*1024)/* max data size */
>
> Note though, I could not go to 2G on amd64, since the kernel elf-loader
> code would act up while compiling (and other parts later might aswell!),
> but I did try 1.5G with a complete make build going through.
>
> > stack(kbytes)32768
> > lockedmem(kbytes)1907008
> > memory(kbytes)   1907008
> > nofiles(descriptors) 1024
> > processes532
> >
> > How do I change the 1GB maximum data segment size?  ulimit -d does not
> > seem to change anything.  Also, how do the limits in login.conf apply?
> > The _squid user is in the daemon class, and that class is set to a
> > data size of infinity?
>
> The resource limits are inherited from the hard limit that vmparam.h
> sets of course, so if you manage to increase it, the the login.conf
> "infinity" should go up also. You wont reach 2G though, if I can make a
> guess.
>



-- 
Joe Gibbens



Re: 3.9 freeze

2006-07-18 Thread Pedro Martelletto
On Tue, Jul 18, 2006 at 07:34:00PM +0200, Federico Giannici wrote:
> I'm not sure of what variables to set and where.

options(4) should tell you that.

-p.



Re: 3.9 freeze

2006-07-18 Thread Federico Giannici

Pedro Martelletto wrote:

Federico,

Your diagnosis is correct, that freeze can be the result of reaching the
limit for UVM amap allocations. These get used by the kernel to describe
anonymous memory mappings, and mmap malloc() puts the UVM subsystem
under a higher load of those, eventually reaching the limit. Until an
appropriate solution is found, you can try bumping the number of pages
in the kernel's memory map (NKMEMPAGES).


I'm not sure of what variables to set and where.
Is it correct to add the following line to the kernel configuration file?

option  NKMEMPAGES_MAX  65536


Thanks.

--
___
__
   |-  [EMAIL PROTECTED]
   |ederico Giannici  http://www.neomedia.it
___



OT question

2006-07-18 Thread stan
I recognize this question is of topic for this list, but I figure that the
people hanging out here have experience with this.

I'm looking for a free sanding GPS based NTP time source for our network.
Anyone have a recommendation?


I would consider a ad in card to a computer, if it's supported under
OpemBSD BTW.

-- 
U.S. Encouraged by Vietnam Vote - Officials Cite 83% Turnout Despite Vietcong 
Terror 
- New York Times 9/3/1967



Re: Epson 1200 Scanner problem

2006-07-18 Thread Denny White

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1




Epson 1200 scanner worked great until a few days ago. Shut
all boxes down for a bad thunderstorm blowing through. Later
when I turned this box on with the scanner, scanimage -L no
longer picked it up, although it showed up in dmesg with
uscanner0 as usual. I was able to run

scanimage -d epson:/dev/uscanner
and get it to scan, but the gimp no longer could acquire it.
Thinking maybe something happened during the storm, like a
surge somewhere, I hooked the scanner up to my xp box and it
worked fine, went through its warmup, scanned okay, etc. Hooked
it back up to this box running obsd 3.9. Immediate message at
the terminal when you connect/disconnect it. Tried disabling
uscanner in the kernel and setting epson.conf to use libusb with

usb 0x04b8 0x0104.

When I use sane-find-scanner I get

found USB scanner (vendor=0x04b8 [EPSON], product=0x0104
[Perfection1200]) at libusb:/dev/usb0:/dev/ugen0
# Your USB scanner was (probably) detected. It may or may not be
# supported by SANE. Try scanimage -L and read the backend's manpage.

where before I disabled uscanner, sane-find-scanner couldn't find
it. Scanimage -L still doesn't find it. And, scanimage with the
-d switch & info no longer works. When this problem first started,
I hadn't changed the kernel or rebuilt userland for quite a while,
so it's not that I changed something in the system to cause it.
Since, however, I have tried updating my source code, rebuilding
everything, reinstalling sane-backends and frontends, but to no
avail. Included my dmesg below, hoping someone would see something
I'd missed. Any ideas very welcome.

Denny White
---dmesg follows
OpenBSD 3.9-stable (GENERIC) #1: Mon Jul 17 10:40:42 CDT 2006
   [EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC
cpu0: Intel Pentium III ("GenuineIntel" 686-class) 801 MHz
cpu0: 
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,FXSR,SSE

real mem  = 268017664 (261736K)
avail mem = 237563904 (231996K)
using 3297 buffers containing 13504512 bytes (13188K) of memory
mainbus0 (root)
bios0 at mainbus0: AT/286+(f4) BIOS, date 07/19/02, BIOS32 rev. 0 @ 0xfb140
apm0 at bios0: Power Management spec V1.2
apm0: AC on, battery charge unknown
apm0: flags 70102 dobusy 1 doidle 1
pcibios0 at bios0: rev 2.1 @ 0xf/0xdf84
pcibios0: PCI IRQ Routing Table rev 1.0 @ 0xfdef0/112 (5 entries)
pcibios0: PCI Exclusive IRQs: 9 10 11
pcibios0: PCI Interrupt Router at 000:31:0 ("Intel 82371SB ISA" rev 0x00)
pcibios0: PCI bus #1 is the last bus
bios0: ROM list: 0xc/0x8000 0xc8000/0x800
cpu0 at mainbus0
pci0 at mainbus0 bus 0: configuration mode 1 (no bios)
pchb0 at pci0 dev 0 function 0 "Intel 82815 Hub" rev 0x04
ppb0 at pci0 dev 30 function 0 "Intel 82801BA AGP" rev 0x05
pci1 at ppb0 bus 1
vga1 at pci1 dev 5 function 0 "3DFX Interactive Voodoo3" rev 0x01
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
fxp0 at pci1 dev 8 function 0 "Intel 82562" rev 0x03, i82562: irq 11, address 
00:01:80:0b:76:77

inphy0 at fxp0 phy 1: i82562ET 10/100 PHY, rev. 0
xl0 at pci1 dev 10 function 0 "3Com 3c905C 100Base-TX" rev 0x78: irq 11, 
address 00:01:03:1a:2f:21

bmtphy0 at xl0 phy 24: Broadcom 3C905C internal PHY, rev. 7
ichpcib0 at pci0 dev 31 function 0 "Intel 82801BA LPC" rev 0x05
pciide0 at pci0 dev 31 function 1 "Intel 82801BA IDE" rev 0x05: DMA, channel 
0 wired to compatibility, channel 1 wired to compatibility

wd0 at pciide0 channel 0 drive 0: 
wd0: 16-sector PIO, LBA, 38166MB, 78165360 sectors
wd1 at pciide0 channel 0 drive 1: 
wd1: 16-sector PIO, LBA, 28629MB, 58633344 sectors
wd0(pciide0:0:0): using PIO mode 4, Ultra-DMA mode 5
wd1(pciide0:0:1): using PIO mode 4, Ultra-DMA mode 4
atapiscsi0 at pciide0 channel 1 drive 0
scsibus0 at atapiscsi0: 2 targets
cd0 at scsibus0 targ 0 lun 0:  SCSI0 5/cdrom 
removable

cd0(pciide0:1:0): using PIO mode 4, DMA mode 2
uhci0 at pci0 dev 31 function 2 "Intel 82801BA USB" rev 0x05: irq 10
usb0 at uhci0: USB revision 1.0
uhub0 at usb0
uhub0: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
ichiic0 at pci0 dev 31 function 3 "Intel 82801BA SMBus" rev 0x05: irq 9
iic0 at ichiic0
uhci1 at pci0 dev 31 function 4 "Intel 82801BA USB" rev 0x05: irq 9
usb1 at uhci1: USB revision 1.0
uhub1 at usb1
uhub1: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub1: 2 ports with 2 removable, self powered
auich0 at pci0 dev 31 function 5 "Intel 82801BA AC97" rev 0x05: irq 9, ICH2 
AC97

ac97: codec id 0x41445360 (Analog Devices AD1885)
ac97: codec features headphone, Analog Devices Phat Stereo
audio0 at auich0
isa0 at ichpcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pmsi0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pmsi0 mux 0
pcppi0 at isa0 port 0x61
midi0 at pcppi0: 
spkr0 at p

Re: where is gif tunnel syntax in the man pages

2006-07-18 Thread Jason McIntyre
On Tue, Jul 18, 2006 at 12:13:35PM -0400, Will H. Backman wrote:
> I can't seem to find the man page that mentions the "tunnel" option for 
> gif interfaces.
> There is a lot of information out there on the net, but I don't see it 
> in the man page for gif or hostname.if.
> Also, is it true that "giftunnel" is the old syntax?
> 
> -- Will

it's in ifconfig(8). in the TUNNEL section, if you're reading -current.
jmc



Re: dhcpd static addresses

2006-07-18 Thread djgoku

On 7/18/06, Dave Gloez <[EMAIL PROTECTED]> wrote:

I have a soekris box where dhcpd is running to give ip addresses for clients, 
now i was thinking is it possible to give clients a static ip based on which 
interface it is connected, so when i plug the network cable to specified 
network port on soekris it would always give the same ip address no matter what.


Put this in your dhcpd.conf:

host joe {
hardware ethernet 08:00:2b:4c:29:32;
fixed-address 10.0.0.1;
}

More info @ : 
http://www.openbsd.org/cgi-bin/man.cgi?query=dhcpd.conf&sektion=5&arch=i386&apropos=0&manpath=OpenBSD+Current



where is gif tunnel syntax in the man pages

2006-07-18 Thread Will H. Backman
I can't seem to find the man page that mentions the "tunnel" option for 
gif interfaces.
There is a lot of information out there on the net, but I don't see it 
in the man page for gif or hostname.if.

Also, is it true that "giftunnel" is the old syntax?

-- Will



Re: dhcpd static addresses

2006-07-18 Thread Falk Brockerhoff
Hello,

what's about running several dhcp processes parallel, listening only on
the ip address associated to the specified interface? You can configure,
in each configuration file, the ip-addresse and the corresponding mac
address, so you will get always the same ip-address...

Regards,

Falk

[demime 1.01d removed an attachment of type APPLICATION/DEFANGED which had a 
name of fb.12923DEFANGED-vcf]



dhcpd static addresses

2006-07-18 Thread Dave Gloez
Hello,


I have a soekris box where dhcpd is running to give ip addresses for clients, 
now i was thinking is it possible to give clients a static ip based on which 
interface it is connected, so when i plug the network cable to specified 
network port on soekris it would always give the same ip address no matter what.


Regards Dave.



Re: Experiences with Drupal on OpenBSD 3.9

2006-07-18 Thread Darrin Chandler
On Tue, Jul 18, 2006 at 04:04:35PM +0200, Paulo Rodriguez wrote:
> Hoping you are having a good summer and all that jazz.
> Just a quick question, I was wondering whether anybody had some 
> interesting feedback, positive or negative, on the use of OpenBSD 3.9, 
> PHP 5.0.5, and PostgreSQL 8.1. on a chrooted Apache.

I have set up Apache+PHP+Drupal with both MySQL and Postgresql. It's not
difficult. You WILL want to search the archives for info on running
MySQL or Postgresql well under OpenBSD. You WILL need to move some
things into the chroot environment so they can be accessed.

Overall everything works great. Two things stand out that I don't like:
1) Drupal wants to write to the database a lot, needlessly. 2) Despite
what other people say, I have found MySQL to be very brittle in the face
of any failures. But then you were asking about pgsql. Better.

Be aware that some Drupal modules are only available for mysql. I'm only
using a handful of modules, and they're all available for both mysql and
pgsql. If you're comfortable enough with sql it will be fairly easy to
add pgsql compatibility to any module, as Drupal uses a (simple) DB
abstraction layer.

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



Re: Experiences with Drupal on OpenBSD 3.9

2006-07-18 Thread Inigo Tejedor Arrondo
El mar, 18-07-2006 a las 16:04 +0200, Paulo Rodriguez escribis:
> Hey guys,
> 
> Hoping you are having a good summer and all that jazz.
> Just a quick question, I was wondering whether anybody had some 
> interesting feedback, positive or negative, on the use of OpenBSD 3.9, 
> PHP 5.0.5, and PostgreSQL 8.1. on a chrooted Apache.
> 
> Kind regards,
> 
> Paulo
> 

I have positive feedback ... but on mysql 5

My drupal has been migrating from 4.0 to latest, and from debian stable
to obsd 3.8 and now 3.9.

Works fine, good luck :)

P.D. you should use sendmail-chroot for user accounts and registrations.
Consider any binary/lib/program needed by your modules to be accesible
into the chroot.



Re: 3.9 freeze

2006-07-18 Thread Pedro Martelletto
Federico,

Your diagnosis is correct, that freeze can be the result of reaching the
limit for UVM amap allocations. These get used by the kernel to describe
anonymous memory mappings, and mmap malloc() puts the UVM subsystem
under a higher load of those, eventually reaching the limit. Until an
appropriate solution is found, you can try bumping the number of pages
in the kernel's memory map (NKMEMPAGES).

-p.



Re: CD Creation question

2006-07-18 Thread Darrin Chandler
On Mon, Jul 17, 2006 at 11:44:43PM -0700, Rob Baldassano wrote:
> I'm working on a low budget, so I can't even afford the cost of the CD's 
> being sent to me :( 
>   However, I am running into a problem
>   I am attempting to install OpenBSD onto an eMachines system, however, I can 
> not get the BIOS to come up so that I can tell it to boot from floppy, and 
> the information I have for creating the Boot CD's is... well, lacking for one 
> who isn't the strongest in System Administration skills. 
>
>   So, 
>   Is there anyone out there that could provide me with the instructions on 
> how to create a bootable CD from Windows, so that I can boot from the CD, and 
> have the install media on the CD itself as well? 

You've had good suggestions about burning CDs...

Why can't you get into the BIOS? Is it password locked? Normally
eMachines will flash a quick text screen, then show the eMachines splash
screen. When the splash screen shows up press the "Del" key and you
should get BIOS setup.

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



Re: sensorsd

2006-07-18 Thread Mark Zimmerman
On Mon, Jul 17, 2006 at 11:42:01PM -0300, Gustavo Rios wrote:
> Hey folks,
> 
> I am running a Dell Precision Workstation, is it possible to have
> sensors working with such hardware? Any special consideration?
> 
First, try 'sysctl hw.sensors'. If you get nothing (like on the Dell I
am using right now) then you are probably out of luck.

-- Mark



Re: CD Creation question

2006-07-18 Thread JR Dalrymple

Bernd Schoeller wrote:

On Tue, Jul 18, 2006 at 09:01:47AM -0400, Jeff Quast wrote:
  

On 7/18/06, Rob Baldassano <[EMAIL PROTECTED]> wrote:


So,
Is there anyone out there that could provide me with the instructions on 
how to create a bootable CD from Windows, so that I can boot from the CD, 
and have the install media on the CD itself as well?
  

You can burn cd39.iso from most any cd burning software in windows.
Unfortunately, a brand new $200 version of microsoft windows does not
offer this most simple of task by default. (Welcome to 1993)

I only know of commercial software that supports this. However, some
of these come with free 30 day trials that may meet your needs. I
would start at one of those massive shareware sites and start
downloading software in the 'cd burning' software category.



AFAIK, there is a free cdrecord version for cygwin that you can use.

Bernd
  

This works well in Windows http://www.cdburnerxp.se/

-JR



Experiences with Drupal on OpenBSD 3.9

2006-07-18 Thread Paulo Rodriguez

Hey guys,

Hoping you are having a good summer and all that jazz.
Just a quick question, I was wondering whether anybody had some 
interesting feedback, positive or negative, on the use of OpenBSD 3.9, 
PHP 5.0.5, and PostgreSQL 8.1. on a chrooted Apache.


Kind regards,

Paulo



Re: IBM 586V crashes during boot

2006-07-18 Thread Steve Shockley

Shawn D'Alimonte wrote:
I have recently obtained a PC that I want to run OpenBSD, but can't get 
it to boot.


You might try disabling the onboard video and use a PCI or ISA VGA card.



Re: Two CARP hosts both trying to be master

2006-07-18 Thread Steven Surdock
David Christiansen wrote:
...
> When I run tcpdump -i sis0 proto carp, I see the errant host
> advertising about three times per second, even though advbase=1 and
> advskew=100 (which
> shows up in the tcpdump output as well).  The host that
> should be master
> (with advskew=0) is advertising as expected.
> 
...
> 
> Does anyone have any ideas as to what I might have done wrong
> here?  I'm
> seriously puzzled.

Are these multiprocessor machines and are you running the MP kernel?  I
experienced a similar issue on the MP kernel.  Switching to GENERIC (SP)
seems to have stabalized the boxes.

-Steve S.



Re: CD Creation question

2006-07-18 Thread Kenny Mann

Jeff Quast wrote:

On 7/18/06, Rob Baldassano <[EMAIL PROTECTED]> wrote:

 So,
 Is there anyone out there that could provide me with the 
instructions on how to create a bootable CD from Windows, so that I 
can boot from the CD, and have the install media on the CD itself as 
well?


You can burn cd39.iso from most any cd burning software in windows.
Unfortunately, a brand new $200 version of microsoft windows does not
offer this most simple of task by default. (Welcome to 1993)

I only know of commercial software that supports this. However, some
of these come with free 30 day trials that may meet your needs. I
would start at one of those massive shareware sites and start
downloading software in the 'cd burning' software category.

Hopefully the windows partition you are using to burn the CD is the
one you will delete and install OpenBSD over, as it will probably
become flooded with privacy-invasive software (ad-ware)...



cdburnerxppro
Link: http://www.cdburnerxp.se/

I suggest using the latest stable as the beta seem to be a little flakey 
still.


Kenny



Re: CD Creation question

2006-07-18 Thread Bernd Schoeller
On Tue, Jul 18, 2006 at 09:01:47AM -0400, Jeff Quast wrote:
> On 7/18/06, Rob Baldassano <[EMAIL PROTECTED]> wrote:
> > So,
> > Is there anyone out there that could provide me with the instructions on 
> > how to create a bootable CD from Windows, so that I can boot from the CD, 
> > and have the install media on the CD itself as well?
> 
> You can burn cd39.iso from most any cd burning software in windows.
> Unfortunately, a brand new $200 version of microsoft windows does not
> offer this most simple of task by default. (Welcome to 1993)
> 
> I only know of commercial software that supports this. However, some
> of these come with free 30 day trials that may meet your needs. I
> would start at one of those massive shareware sites and start
> downloading software in the 'cd burning' software category.

AFAIK, there is a free cdrecord version for cygwin that you can use.

Bernd



Two CARP hosts both trying to be master

2006-07-18 Thread David Christiansen
I am in the process of setting up a redundant firewall using CARP and pfsync
and earlier today everything was working.  I'm not sure what configuration
change I made, but all of a sudden both machines are trying to be master on
the same interface. The only thing I did around that time was modify a few
scripts to change the routing table when necessary. If I manually shift the
machine that is supposed to be backup into backup, everything works.

When I run tcpdump -i sis0 proto carp, I see the errant host advertising
about three times per second, even though advbase=1 and advskew=100 (which
shows up in the tcpdump output as well).  The host that should be master
(with advskew=0) is advertising as expected.

Both machines have net.inet.carp.preempt=1 so that all of the interfaces
will go into backup mode together.  In addition, they've both got the same
vhid and both CARP interfaces have the same IP address.  I doubt that
there's a communication problem between them because they're both plugged
into the same switch with cables that work fine.  In addition, they can see
each other's advertisements in tcpdump.

Does anyone have any ideas as to what I might have done wrong here?  I'm
seriously puzzled.
Thanks in advance for any assistance!
-David Christiansen



Re: CD Creation question

2006-07-18 Thread Jeff Quast

On 7/18/06, Rob Baldassano <[EMAIL PROTECTED]> wrote:

 So,
 Is there anyone out there that could provide me with the instructions on how 
to create a bootable CD from Windows, so that I can boot from the CD, and have 
the install media on the CD itself as well?


You can burn cd39.iso from most any cd burning software in windows.
Unfortunately, a brand new $200 version of microsoft windows does not
offer this most simple of task by default. (Welcome to 1993)

I only know of commercial software that supports this. However, some
of these come with free 30 day trials that may meet your needs. I
would start at one of those massive shareware sites and start
downloading software in the 'cd burning' software category.

Hopefully the windows partition you are using to burn the CD is the
one you will delete and install OpenBSD over, as it will probably
become flooded with privacy-invasive software (ad-ware)...



Re: Make pf reload ruleset whenever a new file appears/changes

2006-07-18 Thread Lars Hansson
On Tuesday 18 July 2006 19:54, Olivier Mehani wrote:
> Maybe you can code a little deamon which, running outside of the chroot,
> would wait on a Unix(4) socket(2) to know when the rules have to be
> reloaded. The socket entry in the filesystem would lie in the chrooted
> tree so that one script run by the webserver would be able to write to
> it.

Or just use a cron job.

---
Lars Hansson



Re: Make pf reload ruleset whenever a new file appears/changes

2006-07-18 Thread Olivier Mehani
On Tue, Jul 18, 2006 at 01:37:52PM +0200, Mackan wrote:
> >> 4) same php script generates a new ruleset for pf
> >> 5) pf detect changes and reload new ruleset
> >> Step 1 - 4 is already done.  I need help with step 5.
> > You know pfctl(8)?
> Yes. But how do I make apache/php execute the pfctl program
> or signal to pfctl ro reload?
> Apache is chroot and run by www, and pfctl lives outside
> chroot and must be run as root.

Maybe you can code a little deamon which, running outside of the chroot,
would wait on a Unix(4) socket(2) to know when the rules have to be
reloaded. The socket entry in the filesystem would lie in the chrooted
tree so that one script run by the webserver would be able to write to
it.

-- 
Olivier Mehani <[EMAIL PROTECTED]>



Re: Make pf reload ruleset whenever a new file appears/changes

2006-07-18 Thread Mackan
Martin Schrvder wrote:
> 2006/7/18, Mackan <[EMAIL PROTECTED]>:
>> 4) same php script generates a new ruleset for pf
>> 5) pf detect changes and reload new ruleset
>>
>> Step 1 - 4 is already done.  I need help with step 5.
>
> You know pfctl(8)?

Yes. But how do I make apache/php execute the pfctl program
or signal to pfctl ro reload?

Apache is chroot and run by www, and pfctl lives outside
chroot and must be run as root.

I can't see your point - perhaps I'm missing something here.

Mackan



Re: Make pf reload ruleset whenever a new file appears/changes

2006-07-18 Thread Martin Schröder

2006/7/18, Mackan <[EMAIL PROTECTED]>:

4) same php script generates a new ruleset for pf
5) pf detect changes and reload new ruleset

Step 1 - 4 is already done.  I need help with step 5.


You know pfctl(8)?

Best
  Martin



Make pf reload ruleset whenever a new file appears/changes

2006-07-18 Thread Mackan
Hi list!

(Warning: poor english ahead!)

This is what I need to do:

1) a user authenticates and enters my website
2) the user enters one IP-address into a form and submit it.
3) php script receive this address and save it in a file or database.
4) same php script generates a new ruleset for pf
5) pf detect changes and reload new ruleset

Step 1 - 4 is already done.  I need help with step 5.

Apache is chroot.  I could have a cron job search for a new file
every five minutes or so, but that feels like an ugly solution.

Is there any better way to signal pf to reload the new ruleset
whenever a user submits a new IP-adress?

Odd question perhaps... :-)


Mackan



Re: Recompiling Perl 5.8.6

2006-07-18 Thread Marc Espie
On Tue, Jul 18, 2006 at 12:40:10AM +0200, Marc Espie wrote:
> Anyways, I can build a GDBM port, it's no hardship, and probably trivial
> to do...

Committed. Quite simple, seems to work. Much better than recompiling the
whole of perl.



PF mysteriously blocking some return traffic (ignore my other email)

2006-07-18 Thread Ashley Moran
Hi... can anyone work out what is wrong with my PF rules?

We have a DMZ and internal corporate network.  Externally, we have to IP 
ranges with 28 bit netmasks.  Currently, we have an IPCop server handling the 
old range in the DMZ (say a.b.c.d, which is rdr'd to 10.0.x.x inside the DMZ) 
and the internal network, and two CARPed/pfsynced OpenBSD 3.8 servers 
handling the new range (say e.f.g.h).

Yesterday morning the Linux box randomly corrupted and we tried to move the 
new IP range onto the OpenBSD firewalls and switch the windows webserver 
over.  We set the web server to use the cluster as the default gateway, and 
moved the aliases from IPCop to the carp0 interface on the primary OpenBSD 
firewall.  We swapped the IPs on the internal interface so that our internal 
network was using the cluster to reach the internet.

However we get two big problems:

- network connections from internal to the DMZ or the internet were really 
slow (despite minimal CPU load on the firewalls)

- we get loads of tcpdump block logs of the form:
Jul 17 12:21:51.070264 rule 0/(match) block in on em0: 10.0.0.13.80 > 
62.6.139.10.15309: [|tcp]
Jul 17 12:21:51.144867 rule 0/(match) block in on em0: 10.0.0.13.80 > 
84.71.160.155.1603: [|tcp]
Jul 17 12:21:52.063020 rule 0/(match) block in on em0: 10.0.0.13.80 > 
159.168.7.200.21039: [|tcp]
Jul 17 12:21:52.611955 rule 0/(match) block in on em0: 10.0.0.13.80 > 
86.134.106.43.2013: [|tcp]

I've just seen this:
Jul 17 17:36:17.307019 rule 0/(match) block in on em0: 10.0.100.1.22 > 
211.137.76.105.27953: [|tcp] (DF)

Presumably it's just a skiddie attack, but mainly it shows it's not just HTTP 
traffic causing problems.

The block logs really puzzle me, because all web traffic should create a state 
to let the return traffic back out.  What's strange is that you can still 
access the sites through the firewalls despite the random errors.

Anyone got any ideas?  I'm kinda at the end of my tether now... I'm not the 
network admin here (although I seem to do most of his work lately) so these 
rules might not be very well written.  They appeared to work ok in testing 
but have blown up live.

Thanks for any advice...
Ashley



##
#   INTERFACES   #
##

ext_if   = "vr0"
dmz_if   = "em0"
int_if   = "em1"
pfsync_phys_if   = "em1"
pfsync_secure_if = "enc0"
all_if   = "{ vr0, em0, em1 }"
# can't antispoof on em1 because enc0 (created by ipsec) shares an IP range
# not critical as this is on the internal interface anyway
antispoof_if = "{ vr0, em0 }"


##
# ADDRESSES AND SERVICES #
##

### External

table  persist { a.b.c.d/28, e.f.g.h/28 }

### DMZ

dmz_ad="10.0.0.0/16"
dmz_tcp_services_out = "{ http, https, ftp, ntp, domain, 5999 }" 
  # 5999 is cvsup (FreeBSD)
dmz_udp_services_out = "{ ntp, domain }"

## webserv1
webserv1_ext_ad = "x.x.x.x"
webserv1_dmz_ad = "10.0.0.12"

gr8_ext_ad = "x.x.x.x"
gr8_dmz_ad = "10.0.0.13"

codeweavers_secure_ext_ad = "x.x.x.x"
codeweavers_secure_dmz_ad = "10.0.0.14"

dealersystem_ext_ad = "x.x.x.x"
dealersystem_dmz_ad = "10.0.0.15"

easidrive_ext_ad = "x.x.x.x"
easidrive_dmz_ad = "10.0.0.21"

## webserv2 (cluster)
# primary dmz address is "physical address", others are CARPED
webserv2_ext_ad = "x.x.x.x"
webserv2_dmz_primary_ad = "{ 10.0.1.1, 10.0.1.2 }"
webserv2_dmz_ad = "{ 10.0.100.1, 10.0.101.1 }"

# applies to all webservers
webserver_tcp_services = "{ http, https, ssh }"
webserv1_extra_tcp_services = "{ smtp, 3389 }"

## database servers
magneto_dmz_ad = "10.0.2.1"
mystique_dmz_ad = "10.0.2.2"
dbserv_ext_ad = "x.x.x.x"
dbserv_tcp_services = "{ , 2223 }"


# Internal

table  persist { 192.168.136.0/24, 192.168.0.0/24 }

intranet_ext_ad = "x.x.x.x"

jigsawfirewall_ad = "192.168.136.251"
jigsawfirewall_tcp_services_in = "{ smtp }"

# include both firewalls here to save maintaining separate
# scripts for each server
# note: these are the IPs used over the internal interface
firewall_ad = "{ 192.168.136.253, 192.168.136.252,
 192.168.254.254, 192.168.254.253 }"

# Spam

table  persist



# DEFAULTS #


# dont filter on loopback:
set skip on lo0 


#
# SCRUBBING #
#

# clean all packets:
#   - random-id: helps prevent OS identification and NAT host counting
#   - reassemble tcp: used with fragment reassemble for NAT
#   - fragment reassemble: makes sure packet fragments are reassembled before 
# sending through the network
scrub all reassemble tcp
scrub in all fragment reassemble
scrub out all random-id



###
# NAT/REDIRECTION #
###

### DMZ

nat on $ext_if inet proto { tcp, udp, icmp } \
  from $webserv1_dmz_ad -> $webserv1_ext_ad

nat on $ext_if inet proto { tcp, udp, icmp } \
  from $webserv2_dmz_primary_ad -> $webserv2_ext_ad

nat on $ext_if inet proto { tcp, udp, icmp } \
  from { $magneto_dmz_ad, $mystique_dmz_ad }

CD Creation question

2006-07-18 Thread Rob Baldassano
I'm working on a low budget, so I can't even afford the cost of the CD's being 
sent to me :( 
  However, I am running into a problem
  I am attempting to install OpenBSD onto an eMachines system, however, I can 
not get the BIOS to come up so that I can tell it to boot from floppy, and the 
information I have for creating the Boot CD's is... well, lacking for one who 
isn't the strongest in System Administration skills. 
   
  So, 
  Is there anyone out there that could provide me with the instructions on how 
to create a bootable CD from Windows, so that I can boot from the CD, and have 
the install media on the CD itself as well? 
   
  Thank you in advance. 
   
  FYI, I don't know how many times this has gone over the list, but if this is 
a common thread, is there a way that this could be added into perhaps an 
addendum to the documentation for installation processes? 
   
  Thanks !!!
   
  --Rob


- 
 
Eirik Goransson / Rob Baldassano
Member, Barony of Endless Hills; 
House Odlahorde; 
Viking & All around Good Egg ; 
VROC #5029 (Tigger)
come visit http://www.dracowolf.com 
Yahoo! Music Unlimited - Access over 1 million songs.Try it free. 



Re: BOB is dying.

2006-07-18 Thread Wijnand Wiersma

2006/7/17, Han Boetes <[EMAIL PROTECTED]>:

Tim Donahue wrote:
> I swear, spam keeps getting wierder and wierder

I know a very peculiar fellow named Bob, his health is failing,
but I don't think it's that bad.


It would be better if Blobs health would be failing.



Epson 1200 Scanner problem

2006-07-18 Thread Denny White

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1


Epson 1200 scanner worked great until a few days ago. Shut
all boxes down for a bad thunderstorm blowing through. Later
when I turned this box on with the scanner, scanimage -L no
longer picked it up, although it showed up in dmesg with
uscanner0 as usual. I was able to run

scanimage -d epson:/dev/uscanner
and get it to scan, but the gimp no longer could acquire it.
Thinking maybe something happened during the storm, like a
surge somewhere, I hooked the scanner up to my xp box and it
worked fine, went through its warmup, scanned okay, etc. Hooked
it back up to this box running obsd 3.9. Immediate message at
the terminal when you connect/disconnect it. Tried disabling
uscanner in the kernel and setting epson.conf to use libusb with

usb 0x04b8 0x0104.

When I use sane-find-scanner I get

found USB scanner (vendor=0x04b8 [EPSON], product=0x0104
[Perfection1200]) at libusb:/dev/usb0:/dev/ugen0
# Your USB scanner was (probably) detected. It may or may not be
# supported by SANE. Try scanimage -L and read the backend's manpage.

where before I disabled uscanner, sane-find-scanner couldn't find
it. Scanimage -L still doesn't find it. And, scanimage with the
- -d switch & info no longer works. When this problem first started,
I hadn't changed the kernel or rebuilt userland for quite a while,
so it's not that I changed something in the system to cause it.
Since, however, I have tried updating my source code, rebuilding
everything, reinstalling sane-backends and frontends, but to no
avail. Included my dmesg below, hoping someone would see something
I'd missed. Any ideas very welcome.

Denny White
- ---dmesg follows
OpenBSD 3.9-stable (GENERIC) #1: Mon Jul 17 10:40:42 CDT 2006
[EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC
cpu0: Intel Pentium III ("GenuineIntel" 686-class) 801 MHz
cpu0: 
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,FXSR,SSE
real mem  = 268017664 (261736K)
avail mem = 237563904 (231996K)
using 3297 buffers containing 13504512 bytes (13188K) of memory
mainbus0 (root)
bios0 at mainbus0: AT/286+(f4) BIOS, date 07/19/02, BIOS32 rev. 0 @ 0xfb140
apm0 at bios0: Power Management spec V1.2
apm0: AC on, battery charge unknown
apm0: flags 70102 dobusy 1 doidle 1
pcibios0 at bios0: rev 2.1 @ 0xf/0xdf84
pcibios0: PCI IRQ Routing Table rev 1.0 @ 0xfdef0/112 (5 entries)
pcibios0: PCI Exclusive IRQs: 9 10 11
pcibios0: PCI Interrupt Router at 000:31:0 ("Intel 82371SB ISA" rev 0x00)
pcibios0: PCI bus #1 is the last bus
bios0: ROM list: 0xc/0x8000 0xc8000/0x800
cpu0 at mainbus0
pci0 at mainbus0 bus 0: configuration mode 1 (no bios)
pchb0 at pci0 dev 0 function 0 "Intel 82815 Hub" rev 0x04
ppb0 at pci0 dev 30 function 0 "Intel 82801BA AGP" rev 0x05
pci1 at ppb0 bus 1
vga1 at pci1 dev 5 function 0 "3DFX Interactive Voodoo3" rev 0x01
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
fxp0 at pci1 dev 8 function 0 "Intel 82562" rev 0x03, i82562: irq 11, address 
00:01:80:0b:76:77
inphy0 at fxp0 phy 1: i82562ET 10/100 PHY, rev. 0
xl0 at pci1 dev 10 function 0 "3Com 3c905C 100Base-TX" rev 0x78: irq 11, 
address 00:01:03:1a:2f:21
bmtphy0 at xl0 phy 24: Broadcom 3C905C internal PHY, rev. 7
ichpcib0 at pci0 dev 31 function 0 "Intel 82801BA LPC" rev 0x05
pciide0 at pci0 dev 31 function 1 "Intel 82801BA IDE" rev 0x05: DMA, channel 0 
wired to compatibility, channel 1 wired to compatibility
wd0 at pciide0 channel 0 drive 0: 
wd0: 16-sector PIO, LBA, 38166MB, 78165360 sectors
wd1 at pciide0 channel 0 drive 1: 
wd1: 16-sector PIO, LBA, 28629MB, 58633344 sectors
wd0(pciide0:0:0): using PIO mode 4, Ultra-DMA mode 5
wd1(pciide0:0:1): using PIO mode 4, Ultra-DMA mode 4
atapiscsi0 at pciide0 channel 1 drive 0
scsibus0 at atapiscsi0: 2 targets
cd0 at scsibus0 targ 0 lun 0:  SCSI0 5/cdrom 
removable
cd0(pciide0:1:0): using PIO mode 4, DMA mode 2
uhci0 at pci0 dev 31 function 2 "Intel 82801BA USB" rev 0x05: irq 10
usb0 at uhci0: USB revision 1.0
uhub0 at usb0
uhub0: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
ichiic0 at pci0 dev 31 function 3 "Intel 82801BA SMBus" rev 0x05: irq 9
iic0 at ichiic0
uhci1 at pci0 dev 31 function 4 "Intel 82801BA USB" rev 0x05: irq 9
usb1 at uhci1: USB revision 1.0
uhub1 at usb1
uhub1: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub1: 2 ports with 2 removable, self powered
auich0 at pci0 dev 31 function 5 "Intel 82801BA AC97" rev 0x05: irq 9, ICH2 AC97
ac97: codec id 0x41445360 (Analog Devices AD1885)
ac97: codec features headphone, Analog Devices Phat Stereo
audio0 at auich0
isa0 at ichpcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pmsi0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pmsi0 mux 0
pcppi0 at isa0 port 0x61
midi0 at pcppi0: 
spkr0 at pcppi

Re: Which WLAN mini PCI card to use?

2006-07-18 Thread Marian Hettwer
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hej Rod,

on a side note...

Rod.. Whitworth wrote:
> Do NOT CC me - I am subscribed to the list.
I can't CC you. You're in the "To:" Header when I hit reply.
> Replies to the sender address will fail except from the list-server.
oh. great!
> Your IP address will also be greytrapped for 24 hours after any attempt. 
Thats evil. Why don't you learn to configure your MUA correctly and use
the "Reply-To:" field? If you would set the Reply-To correctly, you
could skip your whole signature down here. Everybody hits reply and the
mails are going back to the list, because your reply-to would be set to
misc@openbsd.org
But since you don't configure your MUA, you want us to do your work,
replacing the To: field from Rod.. Whitworth <[EMAIL PROTECTED]> to
misc@openbsd.org 
BaaH!

> I am continually amazed by the people who run OpenBSD who don't take this 
> advice. I always expected a smarter class. I guess not.
Well, I would expect that someone talking about smarter classes is able
to configure its own MUA.
I don't mind wether you greylist my MTA or not. I suggest to set your
Reply-To header correctly and everything is fine (fewer flames in your
signature, less complains from others about being greylisted).
read: http://www.ietf.org/rfc/rfc0822.txt

Cheers so far,
Marian
iD8DBQFEvIZ0gAq87Uq5FMsRAo39AKC7/hgVsyDJo3auY7s1Hc4qIVhq7QCgoyas
FWrHb7FV7sA0q4NGqg239PQ=
=NfCd
-END PGP SIGNATURE-