Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Stuart Henderson
On 2023-07-05, Anthony Coulter wrote: > OK, I've sorted out my network issues server but it turns out that I > was misinterpreting the tcpdump output on my VPS. When an external > computer tries to ping my client's virtual IP address, the VPS's > gateway router is *not* forwarding the pings to my

Re: Question regarding pf rules: block in on em0: ...

2023-07-06 Thread Why 42? The lists account.
On Tue, Jul 04, 2023 at 10:42:39AM -0600, Zack Newman wrote: > ... > I am guessing you didn't flush the rules after disabling pf since > clearly pf rules are still being used. Run pfctl -F all after disabling > pf. Run pfctl -s all to verify there are no active rules. Hi, I see that I was not c

Re: Question regarding pf rules: block in on em0: ...

2023-07-06 Thread Zack Newman
On 7/6/23 06:14, Why 42? The lists account. wrote: Hi, I see that I was not clear enough. You were not. One of the first things in your initial e-mail was the following: "While trying to debug the issue, it occurred to me that it could be a network / pf problem. This doesn't seem to be the is

Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Zack Newman
While I suppose the /64 your VPS provider gives you is "enormous" compared to IPv4, I don't find such a comparison relevant since IPv6 and IPv4 are entirely different protocols. In fact I actually think it is small. Why? RFC 6177 (https://datatracker.ietf.org/doc/html/rfc6177) recommends that /48

dmesg Framework 13, 13th gen

2023-07-06 Thread Volker Schlecht
Works: - Touchpad (it sucks, but it works) - Camera - Microphone - WiFi - Ethernet with the Framework Ethernet adapter - HDMI output with the Framework HDMI adapter - DRM - Suspend (zzz) Doesn't work: - Bluetooth (scnr) - Resume ... it comes back to life in that it shows the contents of ttyC0,

Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Anthony Coulter
First, thank you! The "ndp -s" trick does exactly what I need. (I did not need to consider ndp-reflector.) The rest of this email could be summarized as "That works so perfectly I would pay for someone to make it automatic; meanwhile the other things I asked about were in fact bad ideas and I wil

Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Anthony Coulter
Summary of this email: I repeat my argument that automatic NDP proxying is the right way to handle the "road warrior" use case for IPv6. The reasons I'm pushing this so hard are that (1) including this functionality in iked would be much more robust than any hacky script I could write that tries to

Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Stuart Henderson
veering slightly from the topic (typical setup for a server host would not be to use DHCPv6 but just statically route another block - usually a /56 or /48), but... On 2023-07-07, Anthony Coulter wrote: > The trouble with subnets is that they have to be configured. I would > have to install a DHCP

Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Zack Newman
Yeah, I don't have the interest to get into it about this; but I find it (informally) inconsistent to take an ideological stance against NAT and not have a similar stance against NDP proxying. Networking is a lot cleaner when it can be reasoned about with a rudimentary grasp of graph theory where

Re: IPsec "road warrior" VPN not getting set up properly.

2023-07-06 Thread Anthony Coulter
> veering slightly from the topic (typical setup for a server host would > not be to use DHCPv6 but just statically route another block - usually a > /56 or /48), but... I don't doubt this is typical for serious network operators. But I would counter that for every user who is in a position to r

recommendations for web hosting in Canada?

2023-07-06 Thread Jonathan Thornburg
I'm looking for a web hosting provider based in Canada. Performance isn't critical (the websites will be relatively small, static, and low-traffic), but I'd like a firm whose customer support doesn't core-dump if I mention Perl or OpenBSD. Any recommendations? Thanks, -- -- "Jonathan Thornburg

Re: recommendations for web hosting in Canada?

2023-07-06 Thread Steve Williams
Hi, Small town British Columbia here... I know it's not what you are asking, but... I have a Telus business plan (fiber) which gives me 2 static IP addresses and host it myself.  You can't do it on a "Residential" because some of the ports are filtered.  I had a huge battle with Telus over t

Re: recommendations for web hosting in Canada?

2023-07-06 Thread Abel Abraham Camarillo Ojeda
On Thu, Jul 6, 2023 at 11:32 PM Jonathan Thornburg wrote: > I'm looking for a web hosting provider based in Canada. Performance > isn't critical (the websites will be relatively small, static, and > low-traffic), but I'd like a firm whose customer support doesn't > core-dump if I mention Perl or

Re: recommendations for web hosting in Canada?

2023-07-06 Thread Sean Kamath
On Jul 6, 2023, at 23:09, Abel Abraham Camarillo Ojeda wrote: > vultr seems to have vps in toronto, canada and last time I checked they > supported OpenBSD via its deployment webapp I literally deployed a Vultr VPS with OpenBSD 7.3 last night. Took about 10 minutes. I only mention it because,