Re: Odd df reporting (On Apr 3 snapshot, data copied via 3.8snapshot)

2006-04-21 Thread Whyzzi
Cool! That seems to have done the trick (April 20, 2006 snapshot): (I)nstall, (U)pgrade, or (S)hell? s # fsck -b32 -f /dev/rwd0d Alternate Superblock Location: 32 ** /dev/rwd0d ** File system is already clean ** Last mounted on ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames **

Re: Wireless NIC for soekris 4801

2006-04-21 Thread Joakim Aronius
Hi, Note that the PCI slot is 3.3V only, most WiFI PCI cards i have looked at are 5V. My guess is that you have to go with MiniPCI (but i might be wrong). Cheers, /Joakim * Lasse Bach ([EMAIL PROTECTED]) wrote: Hi all, I wrote a message about OpenBSD hardware recommendations some time

Re: Wireless NIC for soekris 4801

2006-04-21 Thread Didier Wiroth
Hi, I'm planning to do the same. The NET4801 has an USB 1.1 interface. I use it at home and I don't have a lot of traffic on wifi, so I thought I would try using the Zonet ZEW2500P USB Adapter. See: http://www.zonetusa.com/DispProduct.asp?ProductID=139 and Here: http://www.openbsdmetastore.com/

Re: VPN server and winxp client

2006-04-21 Thread Marek Nixworx
Try OpenVPN - client software isn't native for win xp but exists and it's stable and usable.. http://openvpn.net http://openvpn.se Marek 2006/4/19, wolk [EMAIL PROTECTED]: Hello I want to create simply vpn server with native windows xp vpn client. What is the simply way to create this

Re: PF/CARP load balancing

2006-04-21 Thread Stephan A. Rickauer
Ashley Moran wrote: simplicity) is Pound. From what I read, failover is best provided by Heartbeat although so far I have only skimmed a few FAQs. I use 'heartbeast' for several years now and would not do so again. Failover always takes several seconds because of ARP change propagation. Do

Re: problems with carp and vlans

2006-04-21 Thread Lars Weste
Hi, thank you all, it seems to work now. just for the records, my configuration: master carp interfaces are configured like this: vhid 1 pass foo carpdev vlan3 192.168.0.1 192.168.0.255 netmask 255.255.255.0 up and the backup interfaces are configured like this: vhid 1 pass foo carpdev vlan3

Re: Best WAN Adaper?

2006-04-21 Thread tony sarendal
On 21/04/06, Toni Mueller [EMAIL PROTECTED] wrote: Hello, On Wed, 19.04.2006 at 12:57:16 +0100, tony sarendal [EMAIL PROTECTED] wrote: On 19/04/06, Toni Mueller [EMAIL PROTECTED] wrote: Anyway, if someone of you comes across good E3 cards, please drop me a note. Otherwise, try to

Re: pf blocking nets in a way like *.google.com ?

2006-04-21 Thread Falk Husemann
[EMAIL PROTECTED] wrote: That doesn`t mean I can use *.google.com but I would be able to use www.google.com if I understood the FAQ and the manual correctly. Because I may not be bale to know every Hostname in a foreign network a Joker would be a neat solution. Is it maybe planed to add any

Re: pf blocking nets in a way like *.google.com ?

2006-04-21 Thread Lars Hansson
On Friday 21 April 2006 17:52, Falk Husemann wrote: Why isn't it feasible to use Googles allocated netblock (216.239.32.0/19)? Because there's nothing that says that every *.google.com site has to be within a block allocated to Google. --- Lars Hansson

Re: pf blocking nets in a way like *.google.com ?

2006-04-21 Thread Moritz Grimm
Lars Hansson wrote: Why isn't it feasible to use Googles allocated netblock (216.239.32.0/19)? Because there's nothing that says that every *.google.com site has to be within a block allocated to Google. Duh. The obvious solution is to have pf make a DNS lookup on each and every packet

Re: pf blocking nets in a way like *.google.com ?

2006-04-21 Thread tony sarendal
On 21/04/06, Moritz Grimm [EMAIL PROTECTED] wrote: Lars Hansson wrote: Why isn't it feasible to use Googles allocated netblock (216.239.32.0/19 )? Because there's nothing that says that every *.google.com site has to be within a block allocated to Google. Duh. The obvious solution is

Re: Wireless NIC for soekris 4801

2006-04-21 Thread Rod.. Whitworth
On Fri, 21 Apr 2006 08:46:14 +0200, Joakim Aronius wrote: Hi, Note that the PCI slot is 3.3V only, most WiFI PCI cards i have looked at are 5V. My guess is that you have to go with MiniPCI (but i might be wrong). Cheers, /Joakim Nup! MSI PC54G2 is ral Netgear WAG311 is atheros AR5212 both

Re: PF/CARP load balancing

2006-04-21 Thread Ashley Moran
On Thursday 20 April 2006 19:26, Joachim Schipper wrote: Some monitoring script sounds like the way to go, though. Perhaps you're right. Monit looks good - presumably I could install that both on the firewalls and the webservers, so that in the event of an httpd failure the local monit could

Re: PF/CARP load balancing

2006-04-21 Thread Stuart Henderson
On 2006/04/21 12:08, Ashley Moran wrote: I think rdr/source-hash avoids the need to use CARP on the web servers, Failover should be quicker if you CARP on the web servers. Otherwise you have to wait until the monitoring script on the rdr box picks up the failure. which should avoid SSL

Re: PF/CARP load balancing

2006-04-21 Thread Ashley Moran
On Friday 21 April 2006 09:08, Stephan A. Rickauer wrote: I use 'heartbeast' for several years now and would not do so again. Failover always takes several seconds because of ARP change propagation. I though Heartbeast ( I'm assuming you wrote that on purpose :) ) was the flagship output of

Re: PF/CARP load balancing

2006-04-21 Thread Ashley Moran
On Friday 21 April 2006 12:18, Stuart Henderson wrote: On 2006/04/21 12:08, Ashley Moran wrote: I think rdr/source-hash avoids the need to use CARP on the web servers, Failover should be quicker if you CARP on the web servers. Otherwise you have to wait until the monitoring script on the rdr

advantages/disadvantages of kernel pppoe(4) vs userland pppoe(8)?

2006-04-21 Thread Jonathan Thornburg
Hi, I'm about to setup up ADSL at home for the first time, using the following network topology: ADSL+---+ +--+ +--+ to - | DSL |--- | firewall | - | ethernet | ISP | modem | pppoe | + router | | switch |

Re: pf blocking nets in a way like *.google.com ?

2006-04-21 Thread James Mackinnon
What do the client systems run? if they are on windows 2000/2003 Domain, use a GPO and block them as untrusted. Just a thought because what you want is done above PF James - Original Message - From: tony sarendal [EMAIL PROTECTED] To: misc misc@openbsd.org Sent: Friday, April 21,

Re: advantages/disadvantages of kernel pppoe(4) vs userland pppoe(8)?

2006-04-21 Thread Melameth, Daniel D.
Jonathan Thornburg wrote: The firewall/router/nat box is (will be when I get this setup) an old 486 laptop with 2 pcmcia ethernet cards, running 3.9-stable. (Yes, I've ordered a CD; until it arrives I'm using 3.8-stable.) I already have the (external) DSL modem, and from talking to other

Re: PF/CARP load balancing

2006-04-21 Thread Stephan A. Rickauer
Ashley Moran wrote: I though Heartbeast ( I'm assuming you wrote that on purpose :) ) was the flagship output of the Linux HA project. Can the same be achieved on *BSD heartbeat is ancient. They want to replace it with keepalived. with CARP and some monitoring software? Or have I

Re: advantages/disadvantages of kernel pppoe(4) vs userland pppoe(8)?

2006-04-21 Thread Jacob Yocom-Piatt
Original message Date: Fri, 21 Apr 2006 14:30:00 +0200 (CEST) From: Jonathan Thornburg [EMAIL PROTECTED] Subject: advantages/disadvantages of kernel pppoe(4) vs userland pppoe(8)? To: misc@openbsd.org Cc: Jonathan Thornburg [EMAIL PROTECTED] Hi, I'm about to setup up ADSL at home

Re: advantages/disadvantages of kernel pppoe(4) vs userland pppoe(8)?

2006-04-21 Thread Schöberle Dániel
Hi, I'm about to setup up ADSL at home for the first time, using the following network topology: ADSL+---+ +--+ +--+ to - | DSL |--- | firewall | - | ethernet | ISP | modem | pppoe | + router | | switch |

Re: PF/CARP load balancing

2006-04-21 Thread Roy Morris
I think rdr/source-hash avoids the need to use CARP on the web servers, Failover should be quicker if you CARP on the web servers. Otherwise you have to wait until the monitoring script on the rdr box picks up the failure. That's a good point about failover time. The only issue

Re: pf blocking nets in a way like *.google.com ?

2006-04-21 Thread Nick Holland
Falk Husemann wrote: [EMAIL PROTECTED] wrote: That doesn`t mean I can use *.google.com but I would be able to use www.google.com if I understood the FAQ and the manual correctly. Because I may not be bale to know every Hostname in a foreign network a Joker would be a neat solution. Is it maybe

Odd problem with mtu

2006-04-21 Thread Tomas Stankevičius
Hi all, I have this strange problem with my openbsd setup. I have a box which I use for one of my networks gateway. It has two NICs. One for internal network with ethernet connection (fxp0 driver) and one for external network (internet) with pppoe connection (rl0 driver). pppoe connection is set

Re: Virtualization of OpenBSD 3.9 on Xen

2006-04-21 Thread Dave Feustel
On Friday 21 April 2006 11:10, Stefan Kaltenbrunner [EMAIL PROTECTED] wrote: Dave Feustel wrote: On Saturday 15 April 2006 17:53, Anthony Liguori wrote: On Sat, 15 Apr 2006 17:39:10 -0500, Dave Feustel wrote: AMD Pacifica and Intel's VT make possible the virtualization of unmodified

Re: PF/CARP load balancing

2006-04-21 Thread Ashley Moran
On Friday 21 April 2006 15:50, you wrote: I must be missing something. Is this a mission critical setup? If so why not just get it over with and use hardware LB with checking and let the servers do a single job well. There are several cheap LB on ebay radware and the like that are surely

Re: PF/CARP load balancing

2006-04-21 Thread Ashley Moran
On Friday 21 April 2006 13:54, Stephan A. Rickauer wrote: All heartbeat does is having one virtual IP on the live server. In case of failure, a script runs which takes up the IP on the secondary, while some arp faking is done to update the arp tables. You can then also start services in the

Secure programming over openbsd

2006-04-21 Thread João Salvatti
Hi all, Does anyone know a book, tutorial or documents of any kind that treat about secure programming over OpenBSD? Since OpenBSD implements many secure system calls and lots of other methods that are much more secure that respective implementations in other platforms: mkstem, strlcpy,

Re: Best WAN Adaper?

2006-04-21 Thread Adam D. Morley
On Fri, Apr 21, 2006 at 10:36:27AM +0200, Toni Mueller wrote: Hello, On Wed, 19.04.2006 at 12:57:16 +0100, tony sarendal [EMAIL PROTECTED] wrote: On 19/04/06, Toni Mueller [EMAIL PROTECTED] wrote: Anyway, if someone of you comes across good E3 cards, please drop me a note. Otherwise,

Re: Secure programming over openbsd

2006-04-21 Thread Ted Unangst
On 4/21/06, Joco Salvatti [EMAIL PROTECTED] wrote: Does anyone know a book, tutorial or documents of any kind that treat about secure programming over OpenBSD? Since OpenBSD implements many secure system calls and lots of other methods that are much more secure that respective implementations

Re: Multi Firewalls Admin

2006-04-21 Thread xanadu
Thanks for your answears ! You gave me nice ideas, if I'm resuming to admin my remote OpenBSD boxes : - Monitoring: Cacti, Nagios, Argus and a centralised syslog - Distribued Configs: with CVS or maybe http://www.allard.nu/pfw/ for PF or Rsync/Rdisf/FTP - Distribued scripts: ssh It will be

problem with LSI Fibre Channel MPT AMD64 OpenBSD 3.9-current

2006-04-21 Thread Diana Eichert
Howdy I'm having a problem with an LSI929 FC card on a Tyan dual Opteron board. Here's the dmesg snippet specific to the 929 card: mpt2 at pci5 dev 9 function 0 Symbios Logic FC929 rev 0x02: irq 10 mpt2: mpt_read_cfg_header: Config Info Status 22 mpt2: Could not retrieve Manufacturing Page 4

Re: Multi Firewalls Admin

2006-04-21 Thread tony sarendal
On 20/04/06, xanadu [EMAIL PROTECTED] wrote: Thanks for your answears ! You gave me nice ideas, if I'm resuming to admin my remote OpenBSD boxes : - Monitoring: Cacti, Nagios, Argus and a centralised syslog - Distribued Configs: with CVS or maybe http://www.allard.nu/pfw/ for PF or

Intel PRO/1000 82571EB failing to load on latest 3.9 snapshot

2006-04-21 Thread Darrian Hale
Hello, I have a Nexcom NR2107 (uses 2x xeon em64t processors) with two intel 82571EB controllers with 4 ports each. I get the following panic after installing openbsd 3.9 amd64. Before the install, the cd39.iso will boot, but won't load em0 or em6 (each of which are the first port of the 2

isakmpd - DPD stops working

2006-04-21 Thread Mitja Muženič
I'm debbuging something weird here. Before I put together a full and sanitized error report, just a quick question: is anybody else seeing DPD to just stop working after a couple of hours, or is it just me my setup? I have some pre-3.9 -current (mid March or so) machines running some IPsec

OpenBGPd Questions

2006-04-21 Thread Ben Ashton
Hi Guys/Gals I have a stock install of OpenBSD/BGP 3.8 and I'm finding some weird happenings. I'm part of the Virt-IX project (http://www.virt-ix.net/), which is a training ground for learning BGP. The Setup is an OpenVPN connection to a peering LAN (194.126.235.0/24_ where other participants

Re: OpenBGPd Questions

2006-04-21 Thread tony sarendal
On 21/04/06, Ben Ashton [EMAIL PROTECTED] wrote: Hi Guys/Gals I have a stock install of OpenBSD/BGP 3.8 and I'm finding some weird happenings. I'm part of the Virt-IX project (http://www.virt-ix.net/), which is a training ground for learning BGP. The Setup is an OpenVPN connection to a

Re: problem with LSI Fibre Channel MPT AMD64 OpenBSD 3.9-current

2006-04-21 Thread Marco Peereboom
I don't have the magic cable to hook up my FC929 boards to my FC enclosure. Anyone interested in donating an optical FC-LC cable? Diana Eichert wrote: Howdy I'm having a problem with an LSI929 FC card on a Tyan dual Opteron board. Here's the dmesg snippet specific to the 929 card: mpt2 at

zaurus package

2006-04-21 Thread andrew patterson
My cd is on the way but won't have it till monday. I know about the flames but somebody please tar up the zaurus dir for me and post it please. Thx. Andrew Patterson

Re: problem with LSI Fibre Channel MPT AMD64 OpenBSD 3.9-current

2006-04-21 Thread Diana Eichert
On Fri, 21 Apr 2006, Diana Eichert wrote: Marco Would this work, LC/FC Duplex Multi Mode 5M Cable 2Gb/s to 1Gb/s device? http://cgi.ebay.com/LC-FC-Duplex-Multi-Mode-5M-Cable-2Gb-s-to-1Gb-s-device_W0QQitemZ9715347169QQcategoryZ3704QQssPageNameZWDVWQQrdZ1QQcmdZViewItem I've also asked my

Re: problem with LSI Fibre Channel MPT AMD64 OpenBSD 3.9-current

2006-04-21 Thread Marco Peereboom
So I really meant SC-LC. Marco Peereboom wrote: I don't have the magic cable to hook up my FC929 boards to my FC enclosure. Anyone interested in donating an optical FC-LC cable? Diana Eichert wrote: Howdy I'm having a problem with an LSI929 FC card on a Tyan dual Opteron board. Here's the

Override errno EBUSY on rd(4) device after boot in mount(2)?

2006-04-21 Thread Brian A. Seklecki
Is there any way to override the flag on a device that permits it from being mounted twice?MNT_FORCE isn't it. I've got an embedded environment I'm setting up where I want to transfer the root (/) file system from an rd(4) to an MFS. To do this, I have to add some customizations to copy() in