Re: OpenBSD - pf.conf fails to load on reboot, but loads fine after boot

2006-01-01 Thread Michael Erdely
On 1/1/06, Diana Eichert <[EMAIL PROTECTED]> wrote: > damn I feel like I'm playing 20 questions. > > diana And _still_ no pf.conf. -ME -- http://erdelynet.com/ Support OpenBSD! http://www.openbsd.org/orders.html

Re: OpenBSD - pf.conf fails to load on reboot, but loads fine after boot

2006-01-01 Thread Michael Erdely
On 31 Dec 2005 16:29:34 -0800, Randal L. Schwartz <[EMAIL PROTECTED]> wrote: > Nope. No hostnames. > > Any other ideas? Still no pf.conf, eh? Makes it hard to diagnose. -ME -- http://erdelynet.com/ Support OpenBSD! http://www.openbsd.org/orders.html

Re: OpenBSD - pf.conf fails to load on reboot, but loads fine after boot

2005-12-31 Thread Michael Erdely
On 31 Dec 2005 14:35:33 -0800, Randal L. Schwartz <[EMAIL PROTECTED]> wrote: > I have a fairly uncomplicated pf.conf (which I'm willing to share if > asked). When my OpenBSD 3.8 (but this also showed up on 3.7) box > reboots, it ends up staying in "safe" mode (ssh enabled, no pings > enabled), as

Re: HOWTO on spamd+transparent bridge under OpenBSD

2005-10-14 Thread Michael Erdely
You've got a couple of weird things and errors on your page: - You say OpenBSD doesn't support multiple consoles: ctrl+alt+f2 - Using the 3.7 ports tree on 3.6 is not recommended. - tarring and untarring fake-i386 to install a port is just weird. make install should already do that - Why not i

Re: Using DNS names in pf.conf?

2005-01-20 Thread Michael Erdely
The biggest problem I've run into with using DNS for pf rules is: when PF is first loaded, there is a VERY restrictive ruleset (not allowing NAT, etc). So if you've got a DNS server inside your firewall and you're using rules based on DNS names of hosts that your DNS server is not authoritative fo

Re: VPN client cannot connect through OpenBSD router/firewall

2005-01-17 Thread Michael Erdely
On Mon, 17 Jan 2005 18:02:47 -0600, J Moore <[EMAIL PROTECTED]> wrote: > On Mon, Jan 17, 2005 at 10:38:05PM +0100, the unit calling itself Laurent > Cheylus wrote: > > To use VPN IPsec client with a NAT gateway like yours, VPN client must > > use NAT-Traversal (ESP packets encapsulation in UDP pac