Re: pf examples needed

2007-01-16 Thread Todd Boyer
On Tuesday, January 16, 2007, Charles Farinella wrote: > I have an OpenBSD 3.9 machine with a public IP providing NAT > and firewalling for our internal network. It has 3 interfaces: > > dc0: public ip from internet X.X.X.25 > dc1: 192.168.100.x to internal network. This works well. > dc2: 19

Problem using Nslookup through VPN link

2006-02-18 Thread Todd Boyer
I have two 3.8 (GENERIC) IPSec VPN gateways using ISAKMP transforms for negotiation. No complicated PF rules, everything is wide open between networks. I can access and negotiate every protocol except when I call an nslookup request from one side to a W2K3 server on the other. I receive timeouts an

Re: routing question

2005-09-06 Thread Todd Boyer
On Tuesday, September 06, John Brooks wrote: > > (209.145.160.141) > OBSD #1 - > \ > Switch DSL Modem ISP(209.145.160.1) > / > OBSD #2 - > (207.246.198.220) > > I was expecting that 207.246.198.217 would have been set

Re: routing question - why one way?

2005-09-01 Thread Todd Boyer
On Thursday, September 01, 2005, Bill wrote: > Right now I have the router installed with two active interfaces... > > Segment A (192.168.0.4) interface on the router Segment B > (10.3.0.1) interface on the router > > Now I have a machine on each segment also: > > 192.168.0.2 (Segment A) > 10.

Re: web server pf problem

2005-08-30 Thread Todd Boyer
On Tuesday, August 30, 2005, [EMAIL PROTECTED] wrote: > So my problem is that i can't access any of my web server via internet but it works in local Locate these pf.conf rules: > block all > pass in on $ext_if proto tcp from any to $web_srv port 80 flags S/SA synproxy state > pass in on $ext_

Re: Stupid Carp question

2005-08-04 Thread Todd Boyer
On Thursday, August 04, 2005 Monah Baki wrote: > However when I physiclly remove the ethernet cable from sis0 > on the master, the internal machine cannot access the net anymore. > Do I need to copy the pf.conf from the master to the scondary > unit, have them both identical arp cache on t

Re: Stupid Carp question

2005-08-04 Thread Todd Boyer
On Thursday, August 04, 2005 Monah Baki wrote: > However when I physiclly remove the ethernet cable from sis0 > on the master, the internal machine cannot access the net anymore. > Do I need to copy the pf.conf from the master to the scondary > unit, have them both identical Sorry about my

Re: 3.7 CDs

2005-05-01 Thread Todd Boyer
On Saturday, April 30, Theo de Raadt wrote: > Something else... today I had a chance to checkout a new > wireframe puffy tshirt. The texture of them is incredible, > blind people will appreciate the shirts a lot, heck they are > just plain sexy. We should have made a wireframe blowfish > t