Re: npf and carp

2015-05-27 Thread Mindaugas Rasiukevicius
Brook Milligan br...@nmsu.edu wrote: I am trying to get npf to play nicely with a carp interface and am having trouble. The basic setup is that two hosts share in IP via carp and I want to connect to that interface (i.e., either host) via ssh. The following works: - Carp will switch the

Re: npf and carp

2015-05-27 Thread Mindaugas Rasiukevicius
Mindaugas Rasiukevicius rm...@netbsd.org wrote: Brook Milligan br...@nmsu.edu wrote: I am trying to get npf to play nicely with a carp interface and am having trouble. The basic setup is that two hosts share in IP via carp and I want to connect to that interface (i.e., either host) via ssh

Re: NPF syntax

2015-03-17 Thread Mindaugas Rasiukevicius
D'Arcy J.M. Cain da...@netbsd.org wrote: I have decided to give up on pf after banging my head against the wall (and the OBSD mailing list) and try npf but I can't figure out the syntax. I followed the example at http://www.netbsd.org/~rmind/npf/ but I keep getting errors when I validate. I

Re: npf and multiple maps based on destination address

2015-03-15 Thread Mindaugas Rasiukevicius
Harry Waddell wadd...@caravaninfotech.com wrote: I'm trying to have npf ( on the latest netbsd 7 beta ) map address onto either an internal dmz network based on the destination address being in a fairly large table ( several hundred entries ) or map to the WAN address otherwise, e.g. as

Re: something is randomly closing ssh-tunnels (was: ipfilter randomly dropping..)

2014-06-23 Thread Mindaugas Rasiukevicius
Petar Bogdanovic pe...@smokva.net wrote: During the past few weeks the ssh-tunnels to a remote machine started failing randomly. In a previous mail to tech-net I prematurely blamed ipfilter because disabling it yielded some immediate success. Unfortunately, subsequent testing showed that

Re: NPF documentation

2013-03-10 Thread Mindaugas Rasiukevicius
Loganaden Velvindron logana...@gmail.com wrote: I've looked over NPF and sent some a bug report a while ago. The last time I tried to load a ruleset, it rebooted my netbsd-current box. I was hoping to see a less volatile -current so that interested users can experiment with NPF. That was