Nimda retaliation??

2001-09-19 Thread Tony Saign
Has anyone used LaBrea successfully on a FreeBSD box? It's sounds very cool, basically it "traps" systems scanning your network (i.e. nimda or code red infected). -Tony To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-net" in the body of the message

Re[2]: ipfw problems ...

2001-09-19 Thread Igor Podlesny
> I recently setup a box on our network, running FreeBSD 4.4-PRERELEASE, > with ipfw and dummynet to do bandwidth shaping as well as firewalling ... > The machine is a Dual PIII 733 w/1gig of RAM and 2xfxp0 devices ... > I've got an /etc/fw.rules file that has ~1200 rules in it so far, and >

Re: ipfw problems ...

2001-09-19 Thread Julian Elischer
Luigi Rizzo wrote: > > > On Wed, Sep 19, 2001 at 07:39:13PM +0200, Leif Neland wrote: > > > > > Or you could patch ipfw to be able to use a hash-db :-) > > > > skipto caches the pointer of the rule its skipping to the first time > > it uses that rule. not going to get a better hash hit then that.

Re: IPSEC Tunnels vs Dynamoic IPs

2001-09-19 Thread Bjoern Fischer
On Tue, Sep 18, 2001 at 11:09:18PM -0700, Jerry Murdock wrote: > Can an IPSEC tunnel be established between two LANs when one side is using > PPPoE/DSL with dynamic IP using either manual keys or IKE? [...] > A simple "yes," "no," or "ARE YOU NUTS!?" would be adequate, but any > pointers on a "y

Re: ipv6/gif/cisco syslog noise

2001-09-19 Thread Joe Abley
On Thu, Sep 20, 2001 at 05:04:41AM +0900, Hajimu UMEMOTO wrote: > jabley> The tunnel is configured like this: > > jabley> buffoon# ifconfig gif0 > jabley> gif0: flags=8011 mtu 1280 > jabley> inet6 fe80::2d0:b7ff:fe79:a0a7%gif0 --> :: prefixlen 64 scopeid 0x4 > jabley> inet6 2001:

which book

2001-09-19 Thread [EMAIL PROTECTED]
The complete FreeBSD (Walnut Creek) or the new FreeBSD Handbook, which one is adequate to acquire as my first one, in your opinion?? saudações, irado furioso com tudo linux user 179402 Padre Marcelo Rossi (vulgo O Mala, TeViNaTV) é mosca nova na mesma mer*¨&% de sempre. por fav

Re: ipv6/gif/cisco syslog noise

2001-09-19 Thread Hajimu UMEMOTO
Hi, > On Wed, 19 Sep 2001 15:37:40 -0400 > Joe Abley <[EMAIL PROTECTED]> said: jabley> I have a cosmetic difficulty in a v6-in-v4 tunnel set up between jabley> a 4.3-RELEASE box and a cisco router. jabley> The tunnel is configured like this: jabley> buffoon# ifconfig gif0 jabley> gif0:

RE: Win32 to FreeBSD VPN

2001-09-19 Thread Peter Blok
Dmitry, I have W2K working with ipsec on FreeBSD. On FreeBSD racoon is doing the ISAKMP, out of the ports directory. On win2k the standard ipsec stuff. I also have PPTP running using netgraph on FreeBSD. There are plenty of examples how to set it up for PPTP. On windows 98 and W2k the standard P

Re: ipfw problems ...

2001-09-19 Thread Luigi Rizzo
> On Wed, Sep 19, 2001 at 07:39:13PM +0200, Leif Neland wrote: > > > Or you could patch ipfw to be able to use a hash-db :-) > > skipto caches the pointer of the rule its skipping to the first time > it uses that rule. not going to get a better hash hit then that... not enough. The original mes

ipv6/gif/cisco syslog noise

2001-09-19 Thread Joe Abley
Hi, I have a cosmetic difficulty in a v6-in-v4 tunnel set up between a 4.3-RELEASE box and a cisco router. The tunnel is configured like this: buffoon# ifconfig gif0 gif0: flags=8011 mtu 1280 inet6 fe80::2d0:b7ff:fe79:a0a7%gif0 --> :: prefixlen 64 scopeid 0x4 inet6 2001:438:1ff

Win32 to FreeBSD VPN

2001-09-19 Thread Dmitry Samersoff
Does anybody have working VPN between Win32 client and FreeBSD server (PPTP or IPSec) if yes - which software you use. Could someone point me to really working free or commercial software to solve this problem? Thank you. -- Dmitry Samersoff [EMAIL PROTECTED], http://devnull.wplus.net ICQ

Re: ipfw problems ...

2001-09-19 Thread Bill Fumerola
On Wed, Sep 19, 2001 at 07:39:13PM +0200, Leif Neland wrote: > Or you could patch ipfw to be able to use a hash-db :-) skipto caches the pointer of the rule its skipping to the first time it uses that rule. not going to get a better hash hit then that... -- - bill fumerola / [EMAIL PROTECTED]

Re: arp X moved from Y to Z messages

2001-09-19 Thread Bakul Shah
> > The gateway's IP address actually refers to two different machines. > > Naturally the gateway is used quite a bit, and the syslog fills up with "arp > > X moved from Y to Z on fxp0" messages. > > That's really not the right way to do it, and probably doesn't balance > the load as well as you m

fast ip filter

2001-09-19 Thread Joseph McDonald
Hi, Is there a utility that will allow me to inject an IP#/port# into a hash (or similiar structure) table that the kernel can consult to determine if it should drop an incoming connection? I am trying to stop the new worm that is out there. I have about 8000 and growing hosts that I need to blo

Re: ipfw: skipto changing value of where I want to skipto?

2001-09-19 Thread Luigi Rizzo
> > psychopompus# ipfw add 00661 skipto 00708 ip from any to 136.0.0.0/5 > 00661 skipto 56 ip from any to 136.0.0.0/5 > > why is the 00708 changing to 56? :( because the leading 0's force strtol to believe that the number is octal, then the trailing 8 is considered illegal in the basis so the n

Re: ipfw problems ...

2001-09-19 Thread Leif Neland
> > Third, take into account that since ipfw takes 'first matching rule > > wins' approach, you will get performance boost by moving more > > frequently used and more general rules "up" in the ruleset. For > > example, if you move the rule from position 700 to 200 packet will be > > matched only

RE: IPSEC Tunnels vs Dynamoic IPs

2001-09-19 Thread Lars Eggert
> Can an IPSEC tunnel be established between two LANs when one side is using > PPPoE/DSL with dynamic IP using either manual keys or IKE? ... > A simple "yes," "no," or "ARE YOU NUTS!?" would be adequate, but any > pointers on a "yes" answer would be great. Yes. :-) It should definitly work wi

Re: kernel arp messages

2001-09-19 Thread Mike Crosland
Hi i recently had exactly this problem, and it turned out to be the way I'd connected the machine. It was cured when I connected the uplink cable directly the the outside interface instead of into the hub. Could this be a similar situation? Best Regards Mike At 18:45 18/09/2001 -0500, you

ipfw: skipto changing value of where I want to skipto?

2001-09-19 Thread Marc G. Fournier
psychopompus# ipfw add 00661 skipto 00708 ip from any to 136.0.0.0/5 00661 skipto 56 ip from any to 136.0.0.0/5 why is the 00708 changing to 56? :( To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-net" in the body of the message

Re: Problem with IPFW and NATD (refined) !!!

2001-09-19 Thread Ruslan Ermilov
[Please don't cross-post] You did not tell us what exactly does not work. DNS should work, and FTP should not as it requires data channel on a separate port. If that's the case, you may run natd(8) with the -punch_fw option. On Wed, Sep 19, 2001 at 05:06:38PM +0300, Vladimir Terziev wrote: > S

Problem with IPFW and NATD (refined) !!!

2001-09-19 Thread Vladimir Terziev
Sorry, but there is a rule number mistake in my previous e-mail with the same subject. I have a gateway machine which runs NATD (natd -unregistered_only -interface an0) and have IP packet filter IPFW with the following rules: ipfw add 100 allow ip from any to any via lo0 ipfw add 10002 skipt

Problem with IPFW and NATD (refined) !!!

2001-09-19 Thread Vladimir Terziev
Sorry, but there is a rule number mistake in my previous e-mail with the same subject. I have a gateway machine which runs NATD (natd -unregistered_only -interface an0) and have IP packet filter IPFW with the following rules: ipfw add 100 allow ip from any to any via lo0 ipfw add 10002 skipt

Re: ipfw problems ...

2001-09-19 Thread Marc G. Fournier
On Wed, 19 Sep 2001, Krzysztof Zaraska wrote: > First, is there any specific reason for allowing only specific 900 subnets > instead of the whole 'cost nothing' network? How big is this network? How > would this increase the risk? CA*Net3 vs "commercial net" traffic ... > Second, with that numb

RE: IPSEC Tunnels vs Dynamoic IPs

2001-09-19 Thread [EMAIL PROTECTED]
maybe not so specific, but as you asked for any kind of info : freeswan (look at freshmeat) can clarify something, besides it is linux-based. Also you can ask to http://groups.google.com, with something like [freebsd ipsec mobile ], where you can tightening your search replacing mobile with som

Re: IPSEC Tunnels vs Dynamoic IPs

2001-09-19 Thread Jerry Murdock
Thanks, I know from an IPSEC perspective it is do-able. I've done it with several other products without problems. I'm hoping to get a FreeBSD specific answer. My real questions concern if and how gifconfig/gif and setkey/spdadd can manage a dynamic endpoint(0.0.0.0?). And if I should look tow

Re: ipfw problems ...

2001-09-19 Thread Bill Fumerola
On Wed, Sep 19, 2001 at 12:05:34AM -0400, Anthony Schneider wrote: > it might have something to do with the prereleasenature of the machine. > -Anthony. No it has nothing to do with -PRERELEASE. ipfw by any other name is ipfw. > On Tue, Sep 18, 2001 at 11:14:50PM -0400, Marc G. Fournier wrote:

Problem with IPFW and NATD

2001-09-19 Thread Vladimir Terziev
Hi, I have a gateway machine which runs NATD (natd -unregistered_only -interface an0) and have IP packet filter IPFW with the following rules: ipfw add 100 allow ip from any to any via lo0 ipfw add 10002 skipto 2 tcp from 192.168.15.2 to any 21 ipfw add 10003 skipto 2 tcp from 192.16

Re: ipfw problems ...

2001-09-19 Thread Krzysztof Zaraska
On Tue, 18 Sep 2001, Marc G. Fournier wrote: > > I recently setup a box on our network, running FreeBSD 4.4-PRERELEASE, > with ipfw and dummynet to do bandwidth shaping as well as firewalling ... > > The machine is a Dual PIII 733 w/1gig of RAM and 2xfxp0 devices ... > > I've got an /etc/fw.ru