OpenBSD 6.7 - uncommon behavior

2020-05-19 Thread R0me0 ***
Hello guys. Today, I've installed OpenBSD 6.7 on Windows 10 pro ( Hyper-V ) which I already has 6.6 running very well. So, the planning was: Migrate my conf's, turn off my 6.6 and make use of 6.7. 1 - By default hyper-v add's one processor. In the end of my fresh install it doesn't work (

Re: OpenBSD insecurity rumors from isopenbsdsecu.re

2020-05-10 Thread R0me0 ***
That Talk of isopen ... is a joke! He start agreeing with puffy supremacy. All these years I have made jokes with fbsd guys and some "hax0rs" during event's. The reason is simple, they attack OpenBSD community and then always end with a lack of arguments. Even with Qualys recent discoveries,

Re: Unable to create IKEv2 VPN using strongSwan to iked

2020-04-20 Thread R0me0 ***
Ajust as your necessity * ( Don't forget to adjust your pf rules accordingly ) * OpenBSD 6.X ( Works with IPHONE AND STRONGSWAN ) ikev2 "roadwarrior" passive esp from 0.0.0.0/0 to 10.20.30.0/24 \ local egress peer any \ ikesa enc aes-256 auth hmac-sha2-256 group modp2048 \ childsa enc

Re: Security of OpenBSD

2019-06-03 Thread R0me0 ***
I think the OpenBSD code review is taken so seriously thank is more than a good practice matter. https://www.openbsd.org/security.html Em seg, 3 de jun de 2019 às 22:33, Josef Pospisil escreveu: > Hey, thank you all for this mailing list. > > I have a question regarding the security of

Re: OpenBSD on VMware ESXi

2019-05-22 Thread R0me0 ***
Vmware ESXI detects as FreeBSD 32bit. Set network interface to vmxnet3. Also you can use pvscsi driver ( I had some issues with filesystem corruption, there is a weird bug, but there is a workaround.) In general buslogic is more resilient. Regards, Em qua, 22 de mai de 2019 às 14:26, mxb

Re: Firefox bug: 66.0.3 disables all extensions

2019-05-06 Thread R0me0 ***
They already fixed it a couple of hours after the issue. Em seg, 6 de mai de 2019 às 11:45, Juan Francisco Cantero Hurtado < i...@juanfra.info> escreveu: > On Mon, May 06, 2019 at 11:54:04AM +0300, Dumitru Moldovan wrote: > > On Sat, May 04, 2019 at 10:13:39PM +0200, Juan Francisco Cantero

Re: packet loss when > 1000 clients connect

2019-04-16 Thread R0me0 ***
+1 Em ter, 16 de abr de 2019 às 09:44, Torsten escreveu: > > Check with pfctl -si if you reach a limit > > Thanks, will do. > > Marc Peters also suggested to check pf state limit, upon digging into > that I found > > https://serverascode.com/2011/09/12/openbsd-pf-set-limit-states.html > > and

Re: hacked for the second time

2019-04-03 Thread R0me0 ***
you can block connections from tor, the ssh keys must be replaced and of course, are you using a passphrase for them? Regards, Em qua, 3 de abr de 2019 às 16:12, Zeb Packard escreveu: > If you've got money go here: https://www.openbsd.org/support.html > > If you don't have money go ask here:

OpenBSD HTTPD and yourls

2019-02-18 Thread R0me0 ***
Hello guys, Please anyone already deployed yourls with OpenBSD HTTPD? I´m having issues with url rewrite. Any direction will be appreciated. Thanks in advance.

relayd websocket issue

2018-10-19 Thread R0me0 ***
Hello misc, I am trying to perform a relay on webapp that uses websocket. I am able to use the app, but when websocket is requested it does not work .Any direction will be appreciated Here is my config: # cat /etc/relayd.conf http protocol "https" { match request header append

Re: IKEDv2 OpenBSD Roadwarrior

2018-05-29 Thread R0me0 ***
Puffy to puffy # cat /etc/iked.conf ikev2 “virtualmachine” passive esp from 172.0.16.0/24 to 192.168.10.0/24 \ local egress peer any psk “secret” # cat /etc/iked.conf ikev2 “openbsdgw” active esp from 192.168.10.0/24 to 172.0.16.0/24 \ local egress peer 10.20.30.10 psk “secret”

Re: RPI3 fails to relink kernel

2017-10-17 Thread R0me0 ***
thanks for that [] 's 2017-10-17 22:22 GMT-02:00 Jonathan Gray : > On Tue, Oct 17, 2017 at 04:48:19PM -0700, Carlos Cardenas wrote: > > Howdy. > > > > I found a working USB (Sandisk Cruzer Fit 8GB) to install 6.2 on a RPI3. > > > > Install went fine and so was first boot, then

Re: About WPA2 compromised protocol

2017-10-17 Thread R0me0 ***
Stefan Sperling r0x :D Cheers 2017-10-17 15:19 GMT-02:00 Christoph R. Murauer : > The patch is there since 6.1 027 on the errata page. > > Saw the comic yesterday at Libertree. > > > On Tue, 17 Oct 2017 19:09:29 +0200 > > "Stephane HUC \"PengouinBSD\""

Re: OpenBSD IPsec/L2TP to Android VPN?

2017-08-07 Thread R0me0 ***
https://www.authbsd.com/blog/?p=20 2017-08-07 14:54 GMT-03:00 aaron marcher : > hi dan, > > i recently set up something like that using the following two tutorials > (note that this is l2tp/ipsec instead of raw ipsec): > > -

Question from Dummies about FreeBSD PF VS Magic Puffer Fish

2017-07-25 Thread R0me0 ***
Hello Misc, I already used currently FreeBSD PF grammar on OpenBSD during years and AFAIK and I remember this always worked ( On Magic Puffer Fish of course ) My case is simple: FreeBSD RPI3/AMD64 ( That I tested ) - ( DNS REQUESTS TO LOCALHOST port 1053 running TOR) rdr pass on ue0 inet

Re: Recommendation on OpenBSD host

2017-07-25 Thread R0me0 ***
Vultr/Linode I already tested and are good choices. DigitalOcean - If you used disk encryption, they corrupt your disk 2017-07-25 22:01 GMT-03:00 : > Hey list. I need a server to host a very simple website. > I've been looking for a OpenBSD host that offers 'full' control >

Re: vmd: routing problem

2017-07-25 Thread R0me0 ***
Hetzner routes additional subnets through a specified mac address on robots page. ( Some cases you need to open a trouble ticket ) Also, all related information is provided there. Cheers, 2017-07-25 10:26 GMT-03:00 Stuart Henderson : > On 2017-07-20, Mike Larkin

Httpd Content-Length with NextCloud

2017-07-17 Thread R0me0 ***
Hello guys, not sure if its a bug or not. But trying to contribute. I am running OpenBSD 6.1 stable branch When downloading a large file with from poor connection ie: 100 kbps ( I don't have time remaining ) I notice that OpenBSD HTTPD does not set Content-Lenght and connections is

Re: Can I use OpenBSD in a virtual machine, for example, VirtualBox?

2017-07-06 Thread R0me0 ***
@Reyk Yes on ESXi ahci(4) hangs as you described, the procedure is to remove, since "sata" is a default to cdrom device. A great feedback you provided! Long life to magic puffer fish Cheers, 2017-07-04 9:21 GMT-03:00 Reyk Floeter : > On Mon, Jul 03, 2017 at 02:36:20PM

Re: DHCP in vmm guest

2017-06-16 Thread R0me0 ***
Hello guys, I am testing Nested OpenBSD VMM -current under Vmware ESXI 6.5 and the console aleatory freezes ( the VM still working as well as "~^D" ( reattach to console but can't interact through ) Error is: Jun 16 18:55:08 vmm vmd[94945]: vcpu_process_com_data: guest reading com1 when not

Re: httpd and Wordpress

2017-06-10 Thread R0me0 ***
+1 Wordpress must be installed on the desired path, if you are moving from previous scheme like site/wordpress to wordpress, you have a problem. Refer to wordpress manual and you find how to fix. The best bet is like Todd said: Deploy again. 2017-06-10 20:56 GMT-03:00 Todd :

Re: /etc/mygate equivalent for IPv6?

2017-06-06 Thread R0me0 ***
That's it: magic puffer fish 2017-06-06 16:53 GMT-03:00 mabi : > Fantastic, that was an easy one. Somehow I missed that from the OpenBSD > FAQ, must have skimmed it too fast... > > So I guess here that I can have my IPv4 default gw and IPv6 default gw > both on two different

Re: /etc/mygate equivalent for IPv6?

2017-06-06 Thread R0me0 ***
for example: fe80::1%carp0 :) 2017-06-06 16:48 GMT-03:00 Janne Johansson : > Just add the ipv6 gw ip to /etc/mygate. > > > 2017-06-06 21:45 GMT+02:00 mabi : > > > Hi, > > > > What is the "standard" approach for adding an IPv6 default gateway to an > >

Re: OpenBSD and you

2017-05-10 Thread R0me0 ***
Peter, With a presentation like that, everyone is tempt to met Mr. Puffy Thank you for keep it uptated ! ( ~6.1 ) It's amazing job ! You rock . Cheers, 2017-05-10 7:20 GMT-03:00 Manolis Tzanidakis : > On Wed (10/05/17), Peter N. M. Hansteen wrote: > > That was the

Re: Arch and vmd

2017-05-07 Thread R0me0 ***
Thanks Karl Your instructions saved a lot of research. Running funtoo linux -current with minimal kernel ( compiled by hand ) adjusted root partition to vda disk. Tests performed with OpenBSD 6.0 with binary patches applied . Cheers, 2017-04-26 13:47 GMT-03:00 Karl Pettersson

OpenBSD 6.1 - Song released

2017-04-27 Thread R0me0 ***
Great work ! Bryan Adams - Summer of 69 - Parody Long Life to Puffy Cheers

Re: Topics for revised PF and networking tutorial

2017-04-07 Thread R0me0 ***
+1 Queue Prioritization and ToS ( set prio / set tos combinations ) by examples will be great 2017-04-07 13:00 GMT-03:00 I love OpenBSD : > I second to more IPv6 related information. > I am curious about blocking port scanning in IPv6 Web. Does pf let me put > a CIDR into

vmwpvs driver

2016-12-05 Thread R0me0 ***
Hello misc, Some days ago , I tried to install OpenBSD 6.0 using vmwpvs ( Vmware Paravirtual ) When obsd installer finish, I received a message that the boot could not been done using my disk. So I did a research on OBSD mailing lists and found: "There's a problem with vmwpvs(4) where the

Re: IPv6 Setup not working on Hetzner server

2016-12-05 Thread R0me0 ***
+1 ping -c 1 fe80::1%em0 > /dev/null 2016-12-05 11:05 GMT-02:00 Marc Peters : > Am 12/02/16 um 13:39 schrieb Leo Unglaub: > > I just found out that since i changed my mygate up to your suggestion > > that i now have to ping6 fe80::1%em0 first and then i am able to > > connecto

OpenBSD and you

2016-11-25 Thread R0me0 ***
Hello everybody, As I did see any mention around here, I was boosted to post this great presentation by Peter N . M. Hansteen. https://home.nuug.no/~peter/blug2016/ Individually my sincerely grateful for each developer of OpenBSD the true reliable and high secure operating system. Regards,

Re: OpenBSD 6-stable vmd

2016-10-24 Thread R0me0 ***
:00 R0me0 *** <knight@gmail.com>: > Hey Peter , > > Thank you for the advice, I'll get current > > Cheers dude ! > > (: > > > 2016-10-22 6:44 GMT-02:00 Peter Hessler <phess...@theapt.org>: > >> This isn't expected to work at all. Tha

Re: pf rule for openvpn

2016-10-24 Thread R0me0 ***
Assuming you block the traffic by default pf.conf block log all # tcpdump -e -ttt -ni pflog0 action block You will be able to see what exactly is being blocked :) -Regards 2016-10-24 12:19 GMT-02:00 Kenneth Gober : > On Sun, Oct 23, 2016 at 4:46 PM, Thuban

Re: OpenBSD 6-stable vmd

2016-10-22 Thread R0me0 ***
s > released. > > > > On 2016 Oct 22 (Sat) at 00:06:08 -0200 (-0200), R0me0 *** wrote: > :Hello misc. > : > :For testing purposes > : > :I compiled kernel with vmd support. > : > :After start the vm -> vmctl start "myvm" -m 512M -i 1 -d disk.img -k &

OpenBSD 6-stable vmd

2016-10-21 Thread R0me0 ***
Hello misc. For testing purposes I compiled kernel with vmd support. After start the vm -> vmctl start "myvm" -m 512M -i 1 -d disk.img -k /bsd.rd I created a bridge and added vether0 and tap0 In the vm I have configured an ip 192.168.1.30 If I perform ping from OpenBSD Hypervisor -> ping

Re: what all touches the carp demote counter?

2016-10-10 Thread R0me0 ***
if you have a huge traffic ( the node you rebooted must delay until states be syncronized ) About ospf I have no experience working with carp. one more time sorry any typo []'s 2016-10-10 22:58 GMT-03:00 Paul B. Henson <hen...@acm.org>: > On Mon, Oct 10, 2016 at 09:43:56PM -0300,

Re: what all touches the carp demote counter?

2016-10-10 Thread R0me0 ***
Hello Paul, Did you adjust advskew value on the machine you want to be Backup ? For example: Primary/Master # cat hostname.carp0 vhid 1 cardev em0 pass THEPASSWORD inet 10.20.30.40 255.255.255.0 Slave/Backup # cat hostname.carp0 vhid 1 cardev em0 advskew 100 pass THEPASSWORD inet

Re: OpenBSD 6 + CARP + PFSYNC + vmware esxi 6 - stalled nat connections

2016-10-09 Thread R0me0 ***
://mirrors.slackware.com/slackware/ slackware-iso/slackware64-14.2-iso/slackware64-14.2-install-dvd.iso Workaround to solve "ifconfig pfsync0 down" was use "no-sync" on nat rule pass out (no-sync) nat-to 10.20.30.40 Thanks 2016-10-08 18:54 GMT-03:00 R0me0 *** &

OpenBSD 6 + CARP + PFSYNC + vmware esxi 6 - stalled nat connections

2016-10-08 Thread R0me0 ***
Hello Misc, I kindly would like to ask if anyone already faced something like this: I have the follow setup VMware 6 ( one physical interface ) 2x OpenBSD 6 ( cloned machine) ( using E1000 ) ( was using vmxnet3 ) OpenBSD Router running 3 carps ( ext / dmz / lan ) Physical Carp interfaces has

Re: Building OpenBSD 6.0 -stable - Error

2016-09-03 Thread R0me0 ***
Hello Teno, I have successfully updated five OpenBSD 5.9 to 6.0 on release day , following https://www.openbsd.org/faq/upgrade60.html After, I rebuilt all them to stable branch from: $ cd /usr $ cvs -qd anon...@anoncvs.ca.openbsd.org:/cvs get -rOPENBSD_6_0 -P src Was magical as expected.

Re: OpenBSD 6.0 release and errata60.html

2016-09-01 Thread R0me0 ***
Howdy ! Thanks for quick reply Really appreciated. Regards, 2016-09-01 16:06 GMT-03:00 Francois Pussault <fpussa...@contactoffice.fr>: > hello, no apply patches new if you want to > > > ---- > > From: R0me0 *** <knight@g

OpenBSD 6.0 release and errata60.html

2016-09-01 Thread R0me0 ***
Hello misc, I have a little doubt Today was a Official Release of 6.0 This release already include errata60.html patches or I need to apply ? Thanks in advance,

Re: DigitalOcean and OpenBSD

2016-08-25 Thread R0me0 ***
installtion consider to have a freesh backup before reboot LoL :) That's my point 2016-08-25 11:35 GMT-03:00 ds <d...@bitmail.cc>: > On Thu, 25 Aug 2016 11:28:19 -0300 > "R0me0 ***" <knight@gmail.com> wrote: > > > http://www.elnur.pro/digitalocean-drop

Re: DigitalOcean and OpenBSD

2016-08-25 Thread R0me0 ***
http://www.elnur.pro/digitalocean-droplet-corruption 2016-08-25 11:18 GMT-03:00 ds <d...@bitmail.cc>: > On Wed, 24 Aug 2016 10:40:38 -0300 > "R0me0 ***" <knight@gmail.com> wrote: > > > Hello everybody ! > > > > Please, > > &g

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
't know if other keyboards will have similar > > problems. > > > > Just wanted to share my experience so you could try alternatives if you > > DOcean experience leaves you hanging. > > > > On Aug 24, 2016 20:52, "R0me0 ***" <knight@gmail.com&

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
Hello misc Unfortunately even copying raw disk and writing it to a local vm, Disklabel isn't able to "see" labels, the only thing is partitioning scheme. Thank you everyone that gime directions really appreciated ( all those in pvt as well ) Cheers guys ! 2016-08-24 15:37 GMT-03:00 Martin

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
: The Problem is not with OpenBSD but something on DigitalOcean. Thank you man ! 2016-08-24 17:00 GMT-03:00 Chris Cappuccio <ch...@nmedia.net>: > R0me0 *** [knight@gmail.com] wrote: > > > > I have NO O/S found . > > > > That's it > > >

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
Hey Anton ! I didn't ask for support ! You are miss understanding ! If I need a support from OpenBSD will be related with some kernel panic or something related as I already reported in the past. In my point of view, I could be wrong sorry if it the case, I see a lot of people sharing

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
ots on my encrypted OpenBSD > droplet on DO. > > It's running a 5.9 snapshot, not quite current. > > I followed the Tubsta instructions on getting it running. But deviated > since I wanted encryption just for fun. > > On Aug 24, 2016 9:42 AM, "R0me0 ***" <kni

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
he droplet unbootable. > > Suggest working from a hosting service that is OpenBSD friendly. You'll > have an easier time things that manipulate the disk. > > Troy. > # > > > On Wed, Aug 24, 2016 at 11:41 AM, Daniel Ouellet <dan...@presscom.net> > wrote:

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
and a at least the silence its better that write a holy fucking shift . 2016-08-24 13:00 GMT-03:00 Daniel Ouellet <dan...@presscom.net>: > On 8/24/16 10:52 AM, R0me0 *** wrote: > > Just asked if someone already faced this issue after a simple reboot > > > > # reboot

Re: DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
Just asked if someone already faced this issue after a simple reboot # reboot Do you need a draw ? KIND Regards, 2016-08-24 11:48 GMT-03:00 <li...@wrant.com>: > Wed, 24 Aug 2016 10:40:38 -0300 "R0me0 ***" <knight@gmail.com> > > Hello everybody ! > >

DigitalOcean and OpenBSD

2016-08-24 Thread R0me0 ***
Hello everybody ! Please, Anyone already had a disk corruption running OpenBSD @ DigitalOcean with disk encryption ? I had this issue for the third time running OpenBSD 5.9 stable branch and a simple "reboot" == No O/S Thanks in advance,

relayd as transparent reverse proxy

2016-08-09 Thread R0me0 ***
Hello misc, I'm trying to use relayd as transparent reverse proxy with httpd. The goal is keep source IP I'am using OBSD 5.9 stable branch relayd and httpd coexist in the same machine. pf.conf ( tried with rdr and divert-to ) pass in on egress divert-to localhost port 8080 relayd.conf

Re: How to configure OpenBSD L2TP/IPSEC VPN to work with Windows 10?

2016-08-06 Thread R0me0 ***
> > Thanks, > Sebastian > > -Original Message- > From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of > R0me0 *** > Sent: Thursday, August 4, 2016 1:57 PM > To: Sebastian Wain <sebastian.w...@nektra.com> > Cc: OpenBSD misc <misc@openb

Re: How to configure OpenBSD L2TP/IPSEC VPN to work with Windows 10?

2016-08-04 Thread R0me0 ***
ike passive esp transport proto udp from egress to 0.0.0.0/0 port 1701 \ main auth hmac-sha1 enc 3des group modp2048 \ quick auth hmac-sha1 enc 3des psk "YOURSECRET" You are welcome (: 2016-08-04 13:15 GMT-03:00 Sebastian Wain : > I can't figure out

Re: HTTPD location index issue

2016-07-28 Thread R0me0 ***
Solved location "/app/" { directory index index.php } location "/app/*.php" { fastcgi socket "/run/php-fpm.sock" } Thanks 2016-07-28 18:17 GMT-03:00 R0me0 *** <knight@gmail.com>: > Yes that's what I intend > > I noticed directory index gra

Re: HTTPD location index issue

2016-07-28 Thread R0me0 ***
Yes that's what I intend I noticed directory index grammar just works out of location grammar and I cant setup more than one time 2016-07-28 18:00 GMT-03:00 Alexander Hall <alexan...@beard.se>: > > > On July 28, 2016 10:33:04 PM GMT+02:00, R0me0 *** <knight@gmail.com&

Re: HTTPD location index issue

2016-07-28 Thread R0me0 ***
diiff < # Root path and directory index is already index.php > # Root path and directory index is already index.hml 2016-07-28 17:33 GMT-03:00 R0me0 *** <knight@gmail.com>: > Howdy ! > > I'm running OpenBSD 5.9 stable branch > > I can't setup two different loc

HTTPD location index issue

2016-07-28 Thread R0me0 ***
Howdy ! I'm running OpenBSD 5.9 stable branch I can't setup two different locations with different index files Sample: server "example.com" listen on egress port 80 # Root path and directory index is already index.php root "/htdocs/example.com" location "/app/*.php" { # setting new index

Gource

2015-03-26 Thread R0me0 ***
http://www.echothrust.com/blogs/monitoring-pf-logs-gource

Re: DNS over IPSec weirdness

2014-12-11 Thread R0me0 ***
Hey man, I'm not sure about what is happening, but pflog is your best friend ever ! http://www.openbsd.org/faq/pf/logging.html Try find out if a specific rule is blocking traffic in one of endpoints ( both ? ) Cheers, 2014-12-11 14:13 GMT-02:00 Zé Loff zel...@zeloff.org: TL,DR: Queries to

Re: CARP cluster: howto keep pf.conf in sync?

2014-08-01 Thread R0me0 ***
I wrote a little script sometime ago and it run from crontab every 5 min and do: check and generate md5 of important files like hostname.if , pf include files, etc ... All necessaries modification is monitored natively by OpenBSD, but there is an ossec in deployment as well. ifstated is used to

Re: CARP cluster: howto keep pf.conf in sync?

2014-08-01 Thread R0me0 ***
Hi Giancarlo, I would like to thank your background (: Yes the important files is included @changelist and it's sha256, but as firewall rules has modifications during all time, another nodes need be updated. So, it's because of this I run the script every 5 min and I sync it using SCP. * My

Happy New Year

2013-12-31 Thread R0me0 ***
Hi there ! I would like to wish a Happy New Year for all. Sincerely Guilherme Hakme

Re: OpenBSD, ipsec and sasyncd issue

2013-04-25 Thread R0me0 ***
ike active esp…… main …… quick ….. srcid $local_gw //mxb On 24 apr 2013, at 20:33, R0me0 *** knight@gmail.com wrote: Hello misc, A couple of days, I'm fighting with OpenBSD+Ipsec+sasyncd. I searching at google and misc, read the man pages and I do

Re: OpenBSD, ipsec and sasyncd issue

2013-04-25 Thread R0me0 ***
, this means that you have to configure em0 with IP, if em0 is physical NIC used for carp0. On 25 apr 2013, at 13:16, R0me0 *** knight@gmail.com wrote: mxb - my em's not have any ip only inside hostname.emX up my advskew is 100 on backup node 2013/4/24 mxb m...@alumni.chalmers.se

OpenBSD, ipsec and sasyncd issue

2013-04-24 Thread R0me0 ***
Hello misc, A couple of days, I'm fighting with OpenBSD+Ipsec+sasyncd. I searching at google and misc, read the man pages and I do a review of configurations many times to do work something that apparently is very very simple. my simple pf.conf on both firewalls in HA ( OpenBSD 5.2 and tests

Microsoft VPN PPTP

2013-01-31 Thread R0me0 ***
Hello misc, I've the follow situation: WAN --OBSD---LAN | |__DMZ 192.168.1.0/24 ---Windows 2003 - RRAS -- 10.20.30.x/27- VPN IP's CLIENT Clients connect to RRAS server and pf, filter traffic from VPN clients to LAN services. The problem is:

Re: Microsoft VPN PPTP

2013-01-31 Thread R0me0 ***
. Not because of the storm, but because PPTP has been broken security-wise. Good results have been achieved with OpenVPN. On Thu, Jan 31, 2013 at 11:56 PM, R0me0 *** knight@gmail.com wrote: Hello misc, I've the follow situation: WAN --OBSD---LAN

CARP compatibility between 5.1 and 5.2

2013-01-15 Thread R0me0 ***
Hello misc, I've a OpenBSD 5.1 in production and I will put another OpenBSD 5.2 and then configure CARP. will I have some compatibility issue ? Thanks in advanced

Re: No route to host

2012-11-27 Thread R0me0 ***
Look for states of pf the default is 1 if the maximum is reached pf will block # systat pf If needed increase this 2012/11/27 Laurent Caron (Mobile) lca...@unix-scripts.info Loïc BLOT loic.b...@frostsapphirestudios.com a écrit : Hello to OpenBSD users, i have a little problem, i

Re: Carp doubt

2012-10-31 Thread R0me0 ***
I tried this: ifconfig -g carp carpdemote 50 , and all carps are moved to another node :) that is sorry 2012/10/31 R0me0 *** knight@gmail.com Hello misc, I' ve a simple setup to test carp my setup is follow: - Frw A # cat /etc/hostname.carp0 inet 192.168.28.128 255.255.255.0

Re: Carp doubt

2012-10-31 Thread R0me0 ***
My doubt persists, from FAQ To failover a particular CARP group, shut down the carp(4) interface on the master node .. I think that if execute ifconfig carp0 down, all carps would be moved , because default carp group is carp 2012/10/31 R0me0 *** knight@gmail.com I tried

Re: Can't install rrdtool on OpenBSD 5.0

2012-05-03 Thread R0me0 ***
Hello Nick, I understand your their point of view. But Nicolas, shared a thing very cool, and I believe that there, many mates that watch the list, sometimes, learn something new, with the experience of each one. Regards Guilherme Hakme 2012/5/2 Nick Holland n...@holland-consulting.net On

Can't install rrdtool on OpenBSD 5.0

2012-05-02 Thread R0me0 ***
Hello misc, I'm trying to install: pkg_add -vi ftp://ftp.openbsd.org/pub/OpenBSD/5.0/packages/i386/rrdtool-1.2.30p3.tgz but I got this error: Can't install rrdtool-1.2.30p3 because of libraries |library freetype.18.0 not found | not found anywhere Direct dependencies for rrdtool-1.2.30p3 resolve

Re: Can't install rrdtool on OpenBSD 5.0

2012-05-02 Thread R0me0 ***
Installing xbase solve problem =/ 2012/5/2 R0me0 *** knight@gmail.com Hello misc, I'm trying to install: pkg_add -vi ftp://ftp.openbsd.org/pub/OpenBSD/5.0/packages/i386/rrdtool-1.2.30p3.tgz but I got this error: Can't install rrdtool-1.2.30p3 because of libraries |library freetype

Re: Can't install rrdtool on OpenBSD 5.0

2012-05-02 Thread R0me0 ***
can do it like this (change the values for your release and libfreetype version): tar -C / -xzphf xbase51.tgz ./usr/X11R6/lib/libfreetype.so.18.1 you can check yours with: tar tvzf xbase${RELEASE}.tgz | grep libfreetype.so good luck! El 02/05/12 17:30, R0me0 *** escribis: Installing

time exceeded in-transit

2012-04-17 Thread R0me0 ***
Hello misc, I have an OpenBSD 5.0 running with outgoing load balance and ifstated to check link status I've pf.conf with rules for outgoing load balance for link 1 and link 2 , pf.link1 and pf.link2 respectively ifstated.conf link1_test = '(ping -q -c 3 74.125.234.212 /dev/null every 20)'

Re: My OpenBSD 5.0 installation experience (long rant)

2012-03-07 Thread R0me0 ***
*UNIX was not designed to stop its users from doing stupid things, as that would also stop them from doing clever things.*  Doug Gwynhttp://pt.wikipedia.org/w/index.php?title=Doug_Gwynaction=editredlink= 1 Em 7 de margo de 2012 11:27, Leonardo Sabino dos Santos leonardo.sab...@gmail.com

Re: OpenBSD 4.4

2012-01-25 Thread R0me0 ***
.jpg After read all comments, I only am writing to show the error and share the information. As soon as possible, I will upgrade. Thank's to all Em 24 de janeiro de 2012 20:46, Peter N. M. Hansteen pe...@bsdly.netescreveu: R0me0 *** knight@gmail.com writes: I'm running a full patched

OpenBSD 4.4

2012-01-24 Thread R0me0 ***
Hello misc :) I'm running a full patched OpenBSD 4.4 with very complex setup, and I'm planning an upgrade to 5.0. At this moment, if I execute nmap 10.20.0/16, I have a dbg . I've limited the number of max connections and connections per seconds, that solved the problem. When dbg occurs, I cannot

Re: OpenBSD 4.4

2012-01-24 Thread R0me0 ***
It is a GENERIC kernel, the name is only copy of GENERIC.MP :) . As I said, it is a complex setup and I'm planning an upgrade. Cheers, Em 24 de janeiro de 2012 16:10, Rares Aioanei bsdlis...@gmail.comescreveu: On 01/24/2012 07:48 PM, R0me0 *** wrote: Hello misc :) I'm running a full

Re: essential reading for beginning OpenBSD users

2011-09-06 Thread R0me0 ***
http://www.amazon.com/Absolute-OpenBSD-Unix-Practical-Paranoid/dp/1886411999 ! 2011/9/6 Daniel Villarreal yclwebmas...@gmail.com I consider the following to be essential reading for beginning OpenBSD users... Absolute FreeBSD, 2nd Edition information by Michael W. Lucas...

change pciide0 native-pci to compatibility mode

2011-08-01 Thread R0me0 ***
Hello, misc, I'm with a problem pluggin pci ethernet card which is suported by Openbsd I have a machine that: channel 0 configured to compatibility, and this machine the network card is recognized. On another machine : channel 0 configured to native-PCI , on this machine the network card not is

Re: Transparent smtp/pop3 proxy

2011-07-29 Thread R0me0 ***
, R0me0 *** knight@gmail.com wrote: Hello misc. I would like to know if is possible do the following: clients--OpenBSD_FWExternal_mail_server when clients send or receive an email, OpenBSD catch this mail and send a copy of this to another email

Transparent smtp/pop3 proxy

2011-07-28 Thread R0me0 ***
Hello misc. I would like to know if is possible do the following: clients--OpenBSD_FWExternal_mail_server when clients send or receive an email, OpenBSD catch this mail and send a copy of this to another email account, it must be transparently to user. Please,

Re: Transparent smtp/pop3 proxy

2011-07-28 Thread R0me0 ***
. Nothing ilegal. Thank you, you help me so much, Cheers, 2011/7/28 roberth rob...@openbsd.pap.st On Thu, 28 Jul 2011 18:00:03 -0300 R0me0 *** knight@gmail.com wrote: when clients send or receive an email, OpenBSD catch this mail and send a copy of this to another email account, it must

Re: Transparent smtp/pop3 proxy

2011-07-28 Thread R0me0 ***
Again, thank you I know that an user very determined can do some things, but he don't know what I can do with PF People should be educated like you :) Best regards and Thank you ! 2011/7/28 roberth rob...@openbsd.pap.st On Thu, 28 Jul 2011 19:39:20 -0300 R0me0 *** knight@gmail.com wrote

RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
Hello misc, I Have a ethernet RTL8169SC based chipset and it work very well with OpenBSD 4.8, the same card not work with 4.9 The motherboard of 4.9 is Intel DP43BF in attach dmesg.boot of 4.9 Regards, [demime 1.01d removed an attachment of type application/octet-stream which had a name of

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
you can upload your dmesg to pastebin and provide link in email. On 14:53 Thu 07 Jul , R0me0 *** wrote: Hello misc, I Have a ethernet RTL8169SC based chipset and it work very well with OpenBSD 4.8, the same card not work with 4.9 The motherboard of 4.9 is Intel DP43BF in attach

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
Allright, I disabled bge0 on BIOS SETUP but the error continues: pciide0 at pci2 dev 0 function 0 Marvell 88SE6101 IDE rev 0xb2: DMA (unsupported), channel 0 configured to native-PCI, channel 1 configured to native-PCI 2011/7/7 Zeb Packard zeb.pack...@gmail.com *Sorry about the direct

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
I booted OBSD 4.8 on this motherboard and I have the same error: can be this error related with BUG as described on man page of re driver ? Regards, 2011/7/7 R0me0 *** knight@gmail.com Allright, I disabled bge0 on BIOS SETUP but the error continues: pciide0 at pci2 dev 0 function 0

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
the ethernet that I'm plugging work very well on old hardware and work very well ( OBSD 4.8 ) the same ethernet accurs this error: ( re(4) chip ) pciide0 at pci2 dev 0 function 0 Marvell 88SE6101 IDE rev 0xb2: DMA :(unsupported), channel 0 configured to native-PCI, channel 1 :configured to

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
dmesg.boot of old hardware: ( same ethernet ) OpenBSD 4.8 (GENERIC.MP) #359: Mon Aug 16 09:16:26 MDT 2010 dera...@i386.openbsd.org:/usr/src/sys/arch/i386/compile/GENERIC.MP cpu0: Intel(R) Pentium(R) 4 CPU 3.00GHz (GenuineIntel 686-class) 3.01 GHz cpu0:

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
# uname -smr OpenBSD 4.8 i386 # ifconfig re0 re0: flags=8b43UP,BROADCAST,RUNNING,PROMISC,ALLMULTI,SIMPLEX,MULTICAST mtu 1500 lladdr 00:08:54:69:13:54 priority: 0 media: Ethernet 100baseTX full-duplex status: active inet 192.168.0.1 netmask 0xff00

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
Yes, the machine are different, I'm doing upgrade of hardware, I buy tp-link model n. TG-3269 and have the same chipset and work very well on this machine that have OBSD 4.8, but I tested the SAME ethernet that I'm running on 4.8 in new hardware with 4.9 2011/7/7 Miod Vallat m...@online.fr

Re: RTL8169SC OpenBSD 4.8 to 4.9 issue

2011-07-07 Thread R0me0 ***
Other thing, I have others servers, that are running OBSD 4.8 with the same ethernet model, and it work very well. The ethernet is ENLGA-1320 ( encore electronics ) ( YES, is a generic network card ) 2011/7/7 R0me0 *** knight@gmail.com Yes, the machine are different, I'm doing upgrade

Re: Routing Issue

2011-05-18 Thread R0me0 ***
Put a route !? 2011/5/18 David Schulz mailingli...@ironwhale.com Hi there, if i disable pf, it will not work (except when trying from router itself via ssh). Here some output from hostname.ifs and mygate, my routing table. Would be most grateful for any tips that help solving this. Best

Re: Squid on LAN

2011-05-09 Thread R0me0 ***
You can too try this: pass in on $int proto tcp from $int:network to port www route-to ( $dmz $ip_of_squid ) pass out on $dmz proto tcp to $ip_of_squid to port www Cheers 2011/5/9 Stuart Henderson s...@spacehopper.org If possible, put the proxy server on a different vlan. If you can't,

Re: Squid on LAN

2011-05-09 Thread R0me0 ***
Yes, You have the reason, I put DMZ because of this :) 2011/5/9 Stuart Henderson s...@spacehopper.org On 2011/05/09 16:31, R0me0 *** wrote: You can too try this: pass in on $int proto tcp from $int:network to port www route-to ( $dmz $ip_of_squid ) pass out on $dmz proto tcp

  1   2   >