Re: slightly OT: OpenNTPd on Linux still allows drift

2006-01-09 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 > Why don't you just figure out what is wrong in the first place? Changing > hammers doesn't change the size of the nail. Sometimes easier said than done. I fought with a problem with ntpd on Linux for days on end multiple times over the course o

Re: A great article ( found on the OpenBSD site)

2005-11-01 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 > quote: > "My experience is that if something has to be done, just do it - don't > ask! They will thank you later," he said. Yeah, an interesting quote, all right. It's obvious that his corporate culture is very different from the one where i w

Re: squid mime-type blocking

2005-10-05 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 > So, since his ACLs were all for req_mime_type, adding the line You > suggested doesn't solve the problem. I would venture to say that the > "-i" may be causing problems, since it's not listed as an option to > req_mime_type. Uncommenting the "#h

Re: squid mime-type blocking

2005-10-05 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Gleydson Soares wrote: >>http_access deny !allowed_mime > > > http_reply_access deny !allowed_mime - From the Squid configuration file: acl aclname req_mime_type mime-type1 ... # regex match agains the mime type of the request generated # b

Re: Amanda clients, behind a pf firewall?

2005-08-18 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 You can build Amanda Yourself and specify certain port ranges, which is a big win when configuring a firewall. Here are the rules i have in a neutral format (i actually use Netfilter on that firewall): server/src ports 702:712/udp -> clients/dst

Re: OpenBSD in commercial firewalls?

2005-06-14 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > If it is the latter there is strong evidence that IPSO (The OS on Nokia > and Checkpoint based firewalls) is derived from OpenBSD. Really? My understanding was that it was FreeBSD-based. It's worth emphasizing that IPSO is nothing more than the ope