Re: hardware

2023-04-20 Thread Frans Haarman
Did you not know NetBSD runs on everything and OpenBSD runs on every fur! Op wo 19 apr. 2023 10:53 schreef Stanislav Syekirin < stanislav.syeki...@studium.fernuni-hagen.de>: > > > > On Mi, 19 Apr 2023 12:51:02 +1000 > David Diggles wrote: > > On 2023-04-19 01:40, folly bololey wrote: > >>> It

relayd.conf http headers from file

2017-02-02 Thread Frans Haarman
Hi List, Is it possible with relayd to match HTTP headers key and value from a file ? I want to store JWT authorisation tokens in a file. Pass request header "Authorize" value "123456" #works Once I start adding the file option things get confusing. Manual mentions we can only read keys from ex

Re: Editing hostname.if files

2016-06-02 Thread Frans Haarman
2016-06-02 20:28 GMT+02:00 Otto Moerbeek : > On Thu, Jun 02, 2016 at 08:08:19PM +0200, Frans Haarman wrote: > >> I got tired of typing hostname so came up with this little tweak. Now >> atleast I have some tab completion. >> >> Maybe useful for some ? D

Editing hostname.if files

2016-06-02 Thread Frans Haarman
I got tired of typing hostname so came up with this little tweak. Now atleast I have some tab completion. Maybe useful for some ? Do you have a differnt approach ? Regards, Frans # cd /etc/interface/ # ls -la total 12 drwxr-xr-x 2 root wheel 512 Jun 2 19:51 . drwxr-xr-x 23 root wheel

Re: NPPPD and IPSec

2013-12-02 Thread Frans Haarman
I have used this with windows 7 and osx: ike passive esp transport \ proto udp from $public_ip to any port 1701 \ main auth "hmac-sha1" enc "3des" group modp1024 \ quick auth "hmac-sha1" enc "aes" \ psk "" 2013/12/2 Or Elimelech > Hi, > > I'm having trouble conf

Re: slashdot rumours

2013-11-01 Thread Frans Haarman
It would amaze me if this is possible without external power! I assumed it was not possible on the internal battery. Perhaps I jumped to conclusions. 2013/11/1 Stuart Henderson > On 2013-11-01, Frans Haarman wrote: > > its a joke > > > > "Strangest of all w

Re: slashdot rumours

2013-11-01 Thread Frans Haarman
its a joke "Strangest of all was the ability of infected machines to transmit small amounts of network data with other infected machines even when their power cords and Ethernet cables were unplugged and their Wi-Fi and Bluetooth cards were removed" 2013/11/1 Mathieu KERJOUAN > Hi > Marko

fix for faq ?

2012-10-05 Thread Frans Haarman
The line mentioning running tftpd from inetd is no longer valid! Its now started via /etc/rc.d/tftpd. http://www.openbsd.org/faq/faq6.html#PXE You will also have to activate the tftpd(8) daemon. This is typically done through inetd(8). The standard OpenBSD install has a sample line in inetd.conf

Re: Narcicism?

2011-12-01 Thread Frans Haarman
2011/12/1 Brandon Weaver : > so remind me again why we're catering to NLB's and Trolls? > I think people are still debugging his bug report.

Re: HP Mini 5102, bluetooth & speakers not working

2011-06-30 Thread Frans Haarman
2011/6/30 Brynet : > Frans Haarman wrote: >> The built-in bluetooth is not working, neither are the laptop speakers >> or I am just not smart enough :) > > OpenBSD's bluetooth drivers are disabled in GENERIC, you can enable it with > config(8)/UKC but it's very

HP Mini 5102, bluetooth & speakers not working

2011-06-29 Thread Frans Haarman
Hi, since I am probably the only one running OpenBSD on this machine I am not expecting much. But here it goes. The builtin wifi chipset is unsupported still. I've bought one of those mini dlink wifi adapaters and its a great solution. Thanks for that damien@! Having a big usb-dongle stickout out

Re: HP Mini 5102 with networking ?

2010-11-15 Thread Frans Haarman
2010/11/15 Andres Perera > On Mon, Nov 15, 2010 at 3:05 PM, Frans Haarman > wrote: > > Does anybody have a hp min 5102 with networking ? > > > > I managed to install 4.8 amd on a usbdisk (using qemu, on windows7, > *sigh*). > > It boots, and works fine, just mi

HP Mini 5102 with networking ?

2010-11-15 Thread Frans Haarman
Does anybody have a hp min 5102 with networking ? I managed to install 4.8 amd on a usbdisk (using qemu, on windows7, *sigh*). It boots, and works fine, just missing networking support. I managed to boot i386 bsd.rd, and snapshots bsd.rd but both claim [vlan0] is the way to go. OpenBSD 4.8 (GE

Re: [OT] New fund raising item, dream inspired

2010-09-16 Thread Frans Haarman
On 16 September 2010 13:23, Chris Bennett wrote: > I just woke up from a dream where I saw the new fund raising item. > Apparently it was an embedded firewall, and a can opener. > It had a list of PF settings on a knob. > The only PF setting I could remember was 'turnaround', > which seems oddly a

Re: MTA choice

2010-08-13 Thread Frans Haarman
On 13 August 2010 16:30, wrote: > On Fri, 13 Aug 2010 09:23:30 -0500, "j...@fixedpointgroup.com" > wrote: >> sendmail is fine if you have a few users at a relatively quiet domain, >> all of whom you want to have system accounts on the mailserver. smtpd >> does similarly but has unpredictable beh

Re: slow down dd - how?

2010-07-08 Thread Frans Haarman
On 8 July 2010 18:52, Jozsi Avadkan wrote: > How can I slow down dd? > > I don't want to slow down the pc, when generating a big file [~40 > GByte]. > > Does ionice work properly? > > Thank you for any help! :\ > maybe dd bs=1 ?

Re: Unable to ping routes learnt via BGP (OpenBSD 4.7)

2010-06-22 Thread Frans Haarman
On 22 June 2010 18:55, wrote: > Hello List, > > I'm sure I'm missing something fairly obvious but don't know where > to start. > > > First, forgive my ASCII art : > > [BSD A] <--> [PEER A] > ^ > | > v > [BSD B] <--> [PEER B] > > > The following works OK : > - eBGP > - iBGP > - Routing to and from

Re: OpenBSD culture?

2010-04-14 Thread Frans Haarman
On 14 April 2010 11:11, Zachary Uram wrote: > As a long time Linux user I will soon try out OpenBSD, I have been > reading the list emails and contacted 1 OpenBSD top person who was > very rude. There is some of the "RTFM" or "get lost" attitude in > Linux, but if a questioner seems sincere there

Re: OT: marco@ misc@ behavior Re: whiteboard over the net

2010-04-01 Thread Frans Haarman
Here's my top posting! load averages: 0.32, 0.16, 0.1015:39:59 26 processes: 25 idle, 1 on processor CPU states: 1.9% user, 0.0% nice, 0.3% system, 6.2% interrupt, 91.5% idle Memory: Real: 128M/338M act/tot Free: 662M Swap: 0K/2052M used/tot PID USERNAME PRI NICE SIZE RES STATE

Re: problems using djbdns

2010-03-02 Thread Frans Haarman
Hi, # tinydns-conf tinydns dnslog /etc/tinydns 127.0.0.1 # ./add-ns straz 172.16.144.132 # ./add-host candle.straz 172.16.144.129 Your authoritive NS is running on 127.0.0.1 but dnscache is forwarding to: # echo "172.16.144.129" > /etc/dnscache/root/servers/straz Perhaps it should forward to 12

Re: Script to ping, traceroute a destination and record the time

2009-10-29 Thread Frans Haarman
2009/10/29 Kasper Adel > thanks all for answering. > > Traceroute will allow me to find out if during the short period of > application disconnect is whether its an app problem or the network > topology > changes and where (which router) the packets couldnt get across. > > Cheers, > Kim > > On Th

Re: Live OpenBSD Bootable i386 CD

2009-04-23 Thread Frans Haarman
2009/4/23 Andreas Bihlmaier > Hi > > On Sun, Apr 19, 2009 at 09:59:02AM -0700, new_guy wrote: > > I'm interested in building a live, bootable OpenBSD CD for forensics, > cloning > > and data recovery. Basically, boot and try to automatically bring up any > > existing network interface. I'm not in

Re: OpenBGP load balancing between 2 ISP (multihoming)

2008-10-08 Thread Frans Haarman
nks > > -- > Cordialement, > Pierre BARDOU > > -Message d'origine- > De : Mariusz Makowski [mailto:[EMAIL PROTECTED] > Envoyi : mardi 7 octobre 2008 21:38 > @ : Frans Haarman > Cc : BARDOU Pierre; misc@openbsd.org > Objet : Re: OpenBGP load balancing betwe

Re: OpenBGP load balancing between 2 ISP (multihoming)

2008-10-07 Thread Frans Haarman
2008/10/7 BARDOU Pierre <[EMAIL PROTECTED]> > Hello, > > I am trying to set up a configuraion like this : > > +--- -+ +-+ > | ISP1 | | ISP2 | Cisco > | ROUTER | | ROUTER | > | AS3215 | | AS12670 | >

Re: ipsecctl psk usage

2008-09-08 Thread Frans Haarman
2008/9/8 Otto Moerbeek <[EMAIL PROTECTED]> > On Mon, Sep 08, 2008 at 12:57:09PM +0200, Reyk Floeter wrote: > > > hi! > > > > On Mon, Sep 08, 2008 at 12:33:20PM +0200, Frans Haarman wrote: > > > If you use an unqouted string as psk (pre-shared key)

ipsecctl psk usage

2008-09-08 Thread Frans Haarman
If you use an unqouted string as psk (pre-shared key) it can't start with a number so: fails: ike from any to any psk 123 works: ike from any to any psk "123" Same goes for the tag-strings. For most this is probably obvious, because it has to be a string right ? But not for me :P Regards, Fr

Re: multiple bgpd ?

2008-07-13 Thread Frans Haarman
2008/7/13 Frank Habicht <[EMAIL PROTECTED]>: > Hi misc, > > is it possible to run multiple bgpd instances on the same box? > with different sockets (-s) and non-overlapping "listen on" and only one with > "fib-update yes" ? > > doesn't seem to work here. > no error message, > all sessions only "Ac

Re: bgp routing question

2008-03-26 Thread Frans Haarman
On Tue, Mar 25, 2008 at 4:31 PM, Fridiric Pli <[EMAIL PROTECTED]> wrote: > Hi, > > I have an openbsd router with two ebgp peers. > > I have serveral prefixes to announce but I would like to know how I could > influence outcoming traffic from each of my prefix. > > I did not understand how to us

Re: HP Raid hardware

2008-01-22 Thread Frans Haarman
On Jan 22, 2008 11:59 AM, Max <[EMAIL PROTECTED]> wrote: > Thanks for you answer. > I know that hardware compatibilty page exists but drivers/hardware > names are not really clear for me :| > > And does anyone know if HP SC40Ge SAS HBA RAID on Proliant DL160 G5 > is supported ? You can find the s

Re: Is pf all I need to set up a gateway/router?

2007-12-20 Thread Frans Haarman
On Dec 20, 2007 11:23 AM, Sunnz <[EMAIL PROTECTED]> wrote: > Hi, > > I am just trying to set up a wireless gateway/router using an old Mac > with OpenBSD 4.2 installed... I have followed through the FAQ and set > up my device, IP addresses, and DHCPD accordingly. > > Now I have come to this part of

ipsec tunnels with same destination networks

2007-12-18 Thread Frans Haarman
Hi, Is it possible to have VPN tunnels which reach the same private networks ? Basicly I want to reach all the networks without having to renumber everything: ike esp from 10.200.0.0/16 to 192.168.1.0/16 peer 1.2.3.4 tag IPSEC-ONE ike esp from 10.200.0.0/16 to 192.168.1.0/16 peer 5.6.7.8 tag IPS

Re: Straw men (Straw women too thx Hannah)

2007-12-17 Thread Frans Haarman
On Dec 17, 2007 3:14 PM, Karthik Kumar <[EMAIL PROTECTED]> wrote: > Sorry, we are already overstocked on requests. Please try again next year. > > The Santa Claus Company, > North Pole Dear Santa, Please cancel all our requests, I think the OpenBSD people deserve some extra attention this Christm

Re: Bernstein puts qmail in public domain

2007-11-30 Thread Frans Haarman
On Nov 30, 2007 9:38 AM, Matthew Dempsky <[EMAIL PROTECTED]> wrote: > (Ugh, I wish I had noticed this message a few minutes earlier.) > > On 11/29/07, Tobias Weisserth <[EMAIL PROTECTED]> wrote: > > I just wanted to point out that D.J. Bernstein has put qmail in public > > domain. I'm not implying

Re: Replace sendmail with qmail?

2007-11-30 Thread Frans Haarman
On Nov 30, 2007 9:27 AM, Matthew Dempsky <[EMAIL PROTECTED]> wrote: > Dan Bernstein has placed qmail 1.03 into the public domain (see > http://cr.yp.to/qmail/dist.html). Is there any interest in replacing > sendmail with it to remove another component from the src/gnu/ > hierarchy? This would be

changing active slice at boot

2007-11-06 Thread Frans Haarman
Just wondering... Has anyone ever thought of having 2 openbsd installations to boot from ? This way I could upgrade the installation on one slice/disk and boot from it! Then if the kernel would crash/reboot the other slice would be used for booting. So at boot time the active slice is change

Re: 4.2 Trouble with HP Notebook

2007-11-04 Thread Frans Haarman
On Nov 2, 2007 1:22 PM, Rafal Brodewicz <[EMAIL PROTECTED]> wrote: > Frans Haarman pisze: > > > The model is HP Compaq 6710b > > > > And indeed, enableing acpi crashes things! > > I have 6510b model and enabling acpi crashes system. The main problem in >

Re: 4.2 Trouble with HP Notebook

2007-11-02 Thread Frans Haarman
On Nov 2, 2007 1:24 PM, Rafal Brodewicz <[EMAIL PROTECTED]> wrote: > Frans Haarman pisze: > > The model is HP Compaq 6710b > > > > And indeed, enableing acpi crashes things! > > > I have 6510b model and enabling acpi crashes system. The main problem in >

Re: 4.2 Trouble with HP Notebook

2007-11-02 Thread Frans Haarman
On Nov 1, 2007 6:51 PM, Valery Masiutsin <[EMAIL PROTECTED]> wrote: > Hello,Frans ! > > What hp model do you have ? > A lot of their models - models from nx line is a good example, > have broken acpi tables in BIOS, it means you won't be able to get acpi > working. > > Regards Valery > > The

Re: 4.2 Trouble with HP Notebook

2007-11-01 Thread Frans Haarman
On 11/1/07, Paul de Weerd <[EMAIL PROTECTED]> wrote: > On Thu, Nov 01, 2007 at 03:19:11PM +0100, Frans Haarman wrote: > | Hello, > | > | I am trying to install 4.2 on my HP. It boots & installs fine, but after > the > | install the > | kernel stops at: >

Re: 4.2 Trouble with HP Notebook

2007-11-01 Thread Frans Haarman
Frans Haarman De Giessen Automatisering B.V. Technische Dienst Telefoon : (0184) 67 53 75 Fax : (0184) 61 12 46 E-mail : [EMAIL PROTECTED] Website : http://www.giessen.nl/ Algemeen Tel. : (0184) 67 54 00 KvK nr. : 23091032 d u i d e l i j k e t a a l ! -Oorspronkelijk bericht- Van

4.2 Trouble with HP Notebook

2007-11-01 Thread Frans Haarman
y to disable that mtrr stuff ? Frans Haarman De Giessen Automatisering B.V. Technische Dienst Telefoon : (0184) 67 53 75 Fax : (0184) 61 12 46 E-mail : [EMAIL PROTECTED] Website : http://www.giessen.nl/ Algemeen Tel. : (0184) 67 54 00 KvK nr. : 23091032 d u i d e l i j k e t a a l !

Kernel crash after connecting NIC

2007-10-23 Thread Frans Haarman
This happend after connecting an network interface! It was previously connected to a HP SWitch, I moved the cable to a lan port on a Cisco PIX 501. The crash was almost instant I Think. It happend in a test lab I am setting up. So probably some config error on my side, but still I typed the

vlan & hostname.if "problem"

2007-10-17 Thread Frans Haarman
Hello, Several times I have noticed my vlan not getting an IP when I use vlan 1 vlandev bge0 10.3.3.1 255.255.255.252 10.3.3.3 It works everytime when I use: vlan 1 vlandev bge0 10.3.3.1 255.255.255.252 10.3.3.3 It seems the interface must be created first before the assining IP can be done ? Th

Re: Compaq 6710b

2007-07-18 Thread Frans Haarman
t; more than recent, with hardware like Core 2 duo 7300, GB965, SATA > drive, X3100 (Intel gpu), broadcom netlink GigE... > > On 7/18/07, Frans Haarman <[EMAIL PROTECTED]> wrote: > > My boss gave me a laptop! Its a Compaq 6710b. I am hoping someone is > > running OpenB

Compaq 6710b

2007-07-18 Thread Frans Haarman
My boss gave me a laptop! Its a Compaq 6710b. I am hoping someone is running OpenBSD on it. I couldnt boot the cd41.iso properly. Anyone running similar laptop ?

Monitoring with labels

2007-05-16 Thread Frans Haarman
Hello, I was wondering about using pf to monitor what is happening on our network. The idea is to connect a pf machine to the management port on the switch. I am building some rules to monitor certain protocols for all IP adresses connected to our network: pass in proto tcp from src_ip to dest_

pf logging tags and labels ?

2007-02-28 Thread Frans Haarman
Can I somehow see if a label or tag was applied to a certain packet in pflog ?

Re: pf log question

2007-02-27 Thread Frans Haarman
On 2/27/07, Gustavo Rios <[EMAIL PROTECTED]> wrote: Could you send your pf.conf entirely? On 2/27/07, Frans Haarman <[EMAIL PROTECTED]> wrote: > # tcpdump -e -ttt -n -i pflog0 > tcpdump: WARNING: pflog0: no IPv4 address assigned > tcpdump: verbose output suppressed, u

pf log question

2007-02-27 Thread Frans Haarman
# tcpdump -e -ttt -n -i pflog0 tcpdump: WARNING: pflog0: no IPv4 address assigned tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on pflog0, link-type PFLOG (OpenBSD pflog file), capture size 96 bytes 00 rule 4294967295/unkn(8): pass in on bge0: 172.16.10.8

Re: pf route-to & rdr

2007-02-15 Thread Frans Haarman
On 2/14/07, Frans Haarman <[EMAIL PROTECTED]> wrote: when routing packets to another interface, is it then possible to do redirection for those packets on the other interface ? I am trying to: - route subnets to a tunnel - redirect the subnets to private ip 10.100.1.1 > bge0 ---

pf route-to & rdr

2007-02-14 Thread Frans Haarman
when routing packets to another interface, is it then possible to do redirection for those packets on the other interface ? I am trying to: - route subnets to a tunnel - redirect the subnets to private ip 10.100.1.1 > bge0 --- route-to ---> tun0 --- rdr 10.100.1.1 -> 192.168.1.1 I am seeing

staticroutes & bgpd

2007-01-26 Thread Frans Haarman
How does bgpd handle routes it learns which are already a staticroute in the kernel ? We want the staticroute to be used if we do not learn the same route via bgp. Possible somehow ? Thanks, Gr. FH

Re: bgpd questions

2006-12-28 Thread Frans Haarman
On 12/28/06, Claudio Jeker <[EMAIL PROTECTED]> wrote: This is a more complex setup. In such cases it is best to add networks with a community tag "network 10.1.2/24 set community $as:123" and filter on these communities later on to allow or deny the prefix. Right. Thanks for both replies. Wil

bgpd questions

2006-12-28 Thread Frans Haarman
Hi! We are wondering about a certain bgp setup. We want to announce some private networks to a select group of neighhbors. Is it possible to define multiple networks in bgp.conf ? Can I choose which networks get announced to which neighbors ? I ask this because the manual states I can announce s

questions about performance - ipsec - pf

2006-11-08 Thread Frans Haarman
Greetings, The idea is to switch to OpenBSD for our BGP D/PF. In the future we will get Gigabit connections so I am concerned about performance! The idea is to have 2 carped boxes voor OpenBGPD and Packetfilter. Then behind that 2 carped boxes for IPSEC & Packetfilter (future) I am assuming wit

Re: webbased authpf ?

2006-09-19 Thread Frans Haarman
On 9/19/06, chris barry <[EMAIL PROTECTED]> wrote: Q: if the website gives away the password/key, how do you limit access? Is there some generic login, published in the company (like on the conference room wall), used first to get this session data? How would this login data be secured wirelessly

Re: webbased authpf ?

2006-09-19 Thread Frans Haarman
On 9/18/06, Brian Shackelford <[EMAIL PROTECTED]> wrote: While a web-based solution would be more than ideal - I think what I have will work. What our clients need is a piece of software that doesn't require much user interaction - even Putty would be hard to convince them to use. So we hide ev

webbased authpf ?

2006-09-15 Thread Frans Haarman
Is there someting which does "Authpf" like things, only via a website ? So the users authenticates on the website, then the firewall rules are loaded! Another idea I have is to simply have users authenticate, then they can download a ssh key with which they can login.

When todo ALTQ

2006-07-25 Thread Frans Haarman
We have 100Mbit connetion at work. I am wondering if it is every wise to start shaping the connection ? We never get more then 20mbit peaks, so it seems to me we have enough 'room' todo without shaping. But I see alot of people give the ACK packets preference, maybe we could benefit from this als

vpn gateway question

2006-06-21 Thread Frans Haarman
I have a quick question. I want to try to setup a vpn gateway. It would need vpn connections with several clients (using the same subnets!!). I want to somehow map each vpn connection to another IP range, so we can contact all networks at the same time. I think I can accomplish this using NAT or