Re: iptables vs pf

2005-10-22 Thread Peter N. M. Hansteen
Roger Neth Jr <[EMAIL PROTECTED]> writes: > and it was okay on response. Then I redid my pf.conf with the tutorial > by Jeff Hansteen posted a couple of days ago. It's Peter, not Jeff, but I'm very happy to hear you found the tutorial useful. > Wow! what a difference. My DEC firewall is faster

Re: Statefull VPN failover a fork from "Re: iptables vs pf"

2005-10-21 Thread Theo de Raadt
Please note that at this time, sasyncd can fail IPSEC associations to a 2nd machine But not yet fail them back, when the master recovers The developer of this stuff hasn't finished it yet.

Re: Statefull VPN failover a fork from "Re: iptables vs pf"

2005-10-21 Thread Brian A. Seklecki
tatefully, too. :)" ? -Original Message- From: Jason Dixon [mailto:[EMAIL PROTECTED] Sent: Thursday, October 20, 2005 02:07 AM To: 'Edy Purnomo' Cc: misc@openbsd.org Subject: Re: iptables vs pf On Oct 19, 2005, at 6:21 PM, Edy Purnomo wrote: i suggested to my friend

Re: Statefull VPN failover a fork from "Re: iptables vs pf"

2005-10-20 Thread Spruell, Darren-Perot
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > I have been moving a single Linux FW to a pair of OBSD > machines, lured by carp and pfsync. This has been working > well in my test environment. This also lead me to vpns > running with ISAKMPD, replaceing a Freeswan box, and > forestalling

Statefull VPN failover a fork from "Re: iptables vs pf"

2005-10-20 Thread dagrichards
x27;Edy Purnomo' > Cc: misc@openbsd.org > Subject: Re: iptables vs pf > > On Oct 19, 2005, at 6:21 PM, Edy Purnomo wrote: > > > i suggested to my friend to replace his linux box to openbsd. > > he uses mailnly for internet gateway : pf + squid proxy > > after 2 weeks l

Re: iptables vs pf

2005-10-20 Thread Stephan A. Rickauer
Hi, Edy Purnomo wrote: i suggested to my friend to replace his linux box to openbsd. he uses mailnly for internet gateway : pf + squid proxy after 2 weeks later he switched it back linux and said : linux much faster to respond the http requests (he had a same configuration on openbsd, pf + squ

Re: iptables vs pf

2005-10-20 Thread Roger Neth Jr
On 10/20/05, Marc Peters <[EMAIL PROTECTED]> wrote: > hi roger, > > i searched in the archives at marc.theaimsgroup.com but didn't find the > thread you mention. du you have a link for me? > > TIA, > marc > > Roger Neth Jr schrieb: > > > > > > Hello, I put OpenBSD 3.8 snapshot on an old DEC 500pws

Re: iptables vs pf

2005-10-20 Thread Roger Neth Jr
On 10/19/05, Budhi Setiawan <[EMAIL PROTECTED]> wrote: > On Wed, 19 Oct 2005 20:43:38 -0700 > Roger Neth Jr <[EMAIL PROTECTED]> wrote: > > > Hello, I put OpenBSD 3.8 snapshot on an old DEC 500pws with pf.conf > > and it was okay on response. Then I redid my pf.conf with the tutorial > > by Jeff Han

Re: iptables vs pf

2005-10-20 Thread David Benfell
On Thu, 20 Oct 2005 09:59:10 +0200, Jan Johansson wrote: > > And knowing thoose Linux dudes, maybe his Linux squid is a > loadable kernel module so it will be uber fast, I mean crashing > the machine instead of just squid is not really a problem now is > it? > Yes, we know the Linux kernel is blo

Re: iptables vs pf

2005-10-20 Thread Daniel Ouellet
I actually was reading a good document on PF tonight and I came across this quote that I think would answer your question as to the difference between iptables and pf. OK, may be it's more poetic, but still I really liked it. Hope it make you think as well! (:> And I think it describe it very

Re: iptables vs pf

2005-10-20 Thread Jan Johansson
Edy Purnomo <[EMAIL PROTECTED]> wrote: > i suggested to my friend to replace his linux box to openbsd. > he uses mailnly for internet gateway : pf + squid proxy after 2 > weeks later he switched it back linux and said : linux much > faster to respond the http requests (he had a same > configuration

Re: iptables vs pf

2005-10-19 Thread Andrew Daugherity
On 10/19/05, Roger Neth Jr <[EMAIL PROTECTED]> wrote: > Hello, I put OpenBSD 3.8 snapshot on an old DEC 500pws with pf.conf > and it was okay on response. Then I redid my pf.conf with the tutorial > by Jeff Hansteen posted a couple of days ago. > I assume you meant the one posted by Peter N. M. Ha

Re: iptables vs pf

2005-10-19 Thread Roger Neth Jr
On 10/19/05, Edy Purnomo <[EMAIL PROTECTED]> wrote: > i suggested to my friend to replace his linux box to openbsd. > he uses mailnly for internet gateway : pf + squid proxy > after 2 weeks later he switched it back linux and said : linux much faster > to respond the http requests (he had a same co

Re: iptables vs pf

2005-10-19 Thread Jason Dixon
On Oct 19, 2005, at 6:21 PM, Edy Purnomo wrote: i suggested to my friend to replace his linux box to openbsd. he uses mailnly for internet gateway : pf + squid proxy after 2 weeks later he switched it back linux and said : linux much faster to respond the http requests (he had a same configura

Re: iptables vs pf

2005-10-19 Thread Han Boetes
Edy Purnomo wrote: > i suggested to my friend to replace his linux box to openbsd. he > uses mailnly for internet gateway : pf + squid proxy after 2 > weeks later he switched it back linux and said : linux much > faster to respond the http requests (he had a same configuration > on openbsd, pf + sq

Re: iptables vs pf

2005-10-19 Thread per engelbrecht
Edy Purnomo wrote: i suggested to my friend to replace his linux box to openbsd. he uses mailnly for internet gateway : pf + squid proxy after 2 weeks later he switched it back linux and said : linux much faster to respond the http requests (he had a same configuration on openbsd, pf + squid pr

Re: iptables vs pf

2005-10-19 Thread Wolfpaw - Dale Corse
> Edy Purnomo wrote: > > i suggested to my friend to replace his linux box to > openbsd. he uses > > mailnly for internet gateway : pf + squid proxy after 2 > weeks later he > > switched it back linux and said : linux much faster to respond the > > http requests (he had a same configuration on

Re: iptables vs pf

2005-10-19 Thread Chris
Edy Purnomo wrote: > i suggested to my friend to replace his linux box to openbsd. > he uses mailnly for internet gateway : pf + squid proxy > after 2 weeks later he switched it back linux and said : linux much > faster to respond the http requests (he had a same configuration on > openbsd, pf + sq

iptables vs pf

2005-10-19 Thread Edy Purnomo
i suggested to my friend to replace his linux box to openbsd. he uses mailnly for internet gateway : pf + squid proxy after 2 weeks later he switched it back linux and said : linux much faster to respond the http requests (he had a same configuration on openbsd, pf + squid proxy). is there any