Curiosity about pftop rate monitoring

2010-11-23 Thread Elliott Barrere
Hi all, maybe I'm failing to understand pftop, but I can't seem to reconcile this. I run pftop -orate -vspeed (or just run it and switch to that view) and I see one connection supposedly using a huge amount of bandwidth: PRDIR SRCDEST RATE PEAK

OpenVPN with CARP

2010-11-17 Thread Elliott Barrere
Hi all, I have a set of OpenBSD firewalls running CARP for failover and OpenVPN (in UDP mode) for remote access. The problem is that when I don't specify an address in the OpenVPN config file, return packets from the BSD boxes to remote clients are sent from the local interface address rather

pam-devel package??

2009-11-18 Thread Elliott Barrere
Hi all, I need to build a pam-dependent plugin (openvpn-auth-pam) that requires the pam-devel libraries; I think that's why it's failing to build. I can't seem to find them in any OpenBSD port or package list; can someone point me in the right direction or tell me what to look for?

Security script in OpenBSD

2009-10-21 Thread Elliott Barrere
What is the preferred procedure for changing files that are watched by the security script (i.e. present in /etc/changelist)? I have a few boxes cloned from one and I would like to change SSH keys and other sensitive files but the script seems to be changing them back. Is there