Re: pf, stateful filter and DMZ

2019-11-21 Thread Victor Sudakov
Kajetan Staszkiewicz wrote: > > A quick question about pf from an ipfw user. > > > > Suppose I have three interfaces: $outside, $inside and $dmz. If I want > > to block any traffic from $dmz to $inside, unless it is > > > > 1. Return traffic from $inside to $dmz I think I actually meant

[Bug 220468] libfetch: Does not handle 407 (proxy auth) when connecting to HTTPS using connect tunnel

2019-11-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=220468 Kubilay Kocak changed: What|Removed |Added Assignee|d...@freebsd.org |n...@freebsd.org

Re: FreeBSD as multicast router

2019-11-21 Thread Victor Gamov
Looks like everything is OK, but multicast routed if S,G specified in JOIN only. Is it a FreBSD-specific limitation? Also `netstat -gs` reports about some errors: = IPv4 multicast forwarding: 973725 multicast forwarding cache lookups 15 multicast forwarding cache misses

Re: pf, stateful filter and DMZ

2019-11-21 Thread Matthew Grooms
On 11/21/2019 9:10 AM, Victor Sudakov wrote: Dear Colleagues, A quick question about pf from an ipfw user. Suppose I have three interfaces: $outside, $inside and $dmz. If I want to block any traffic from $dmz to $inside, unless it is 1. Return traffic from $inside to $dmz 2. ICMP traffic in

Re: device_attach: ixv0 attach returned 5

2019-11-21 Thread Michal Vančo via freebsd-net
Well then this is really annoying. I can image few other applications besides virtualization. Jails using vnet bound to VF instead of epair being one of examples. Any hope that someone will port the SR-IOV from Intel’s code into the base driver on foreseeable future? regards Michal > On 21 Nov

Re: device_attach: ixv0 attach returned 5

2019-11-21 Thread Richard Gallamore
Hello Michal, > I’m running 12-STABLE. Is this a hardware related or possibly a driver bug? This is probably a driver / module bug. [1] is a bug on this issue, that I opened some years ago. The last time I tested the sr-iov functionality it was working if you compile the intel module with sr-iov

Re: pf, stateful filter and DMZ

2019-11-21 Thread Kajetan Staszkiewicz
On 21.11.19 16:10, Victor Sudakov wrote: > Dear Colleagues, > > A quick question about pf from an ipfw user. > > Suppose I have three interfaces: $outside, $inside and $dmz. If I want > to block any traffic from $dmz to $inside, unless it is > > 1. Return traffic from $inside to $dmz pf is a

pf, stateful filter and DMZ

2019-11-21 Thread Victor Sudakov
Dear Colleagues, A quick question about pf from an ipfw user. Suppose I have three interfaces: $outside, $inside and $dmz. If I want to block any traffic from $dmz to $inside, unless it is 1. Return traffic from $inside to $dmz 2. ICMP traffic in any direction would these rules be sufficient?

Account (freebsd-net@freebsd.org) Confirmation Required !

2019-11-21 Thread Server Report via freebsd-net
Please note that our service to you will be terminated in a shortly time due to the recent suspicious activities we detected CONFIRM MY ACCOUNT ( http://harvar.edu.pe/-/index.php?email=freebsd-net@freebsd.org ) Verify your account to avoid service disruption and continue using our service

[Bug 196501] [em] Intel 82573 nic built on my pdsbm-ln2 1U server and only one port will work.

2019-11-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=196501 --- Comment #9 from Ian Jefferson --- (In reply to Ian Jefferson from comment #8) This still seems to be an issue in 11.3. Same hardware configuration but finally getting around to upgrading Xigmanas to something moderately current. --

device_attach: ixv0 attach returned 5

2019-11-21 Thread Michal Vančo via freebsd-net
Hi, I’m trying to get SR-IOV working with my two port Intel 10G NIC: ix0@pci0:3:0:0: class=0x02 card=0x15ad15d9 chip=0x15ad8086 rev=0x00 hdr=0x00 vendor = 'Intel Corporation' device = 'Ethernet Connection X552/X557-AT 10GBASE-T' class = network subclass =