Re: Filtering on IPSEC

2012-01-11 Thread Bjoern A. Zeeb
On 12. Jan 2012, at 07:29 , Alex Dupre wrote: > Bjoern A. Zeeb ha scritto: >> Need more input. A) why are using gif? B) are you using transport mode? > > I'm using gif, because the official FreeBSD documentation says so > (http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/ipsec.html).

Re: Filtering on IPSEC

2012-01-11 Thread Alex Dupre
Bjoern A. Zeeb ha scritto: Need more input. A) why are using gif? B) are you using transport mode? I'm using gif, because the official FreeBSD documentation says so (http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/ipsec.html). My configuration is very similar to what described in

Re: Filtering on IPSEC

2012-01-11 Thread David DeSimone
Alex Dupre wrote: > > I've setup my first IPSEC VPN beetween FreeBSD 8.2 and CheckPoint > VPN-1. I've used a gif interface for the tunnel, setkey for security > policies and racoon for ikev1. I've peered with Checkpoint VPN's using FreeBSD but I never needed to use gif interfaces to make it happe

Re: interface for import/export flowtable

2012-01-11 Thread K. Macy
On Sat, Jul 24, 2010 at 2:17 PM, Bjoern A. Zeeb wrote: > On Thu, 22 Jul 2010, alan yang wrote: > > Hey, > > >> Wonder people had implemented interface to import / export flowtable. > Yes I did, and I added an API to query it more generally. I didn't add it to net/flowtable.c because my usage seem

Re: Processes' FIBs

2012-01-11 Thread Bjoern A. Zeeb
On 11. Jan 2012, at 15:06 , Oliver Fromme wrote: > > Bjoern A. Zeeb wrote: >> On 10. Jan 2012, at 20:32 , Paul A. Procacci wrote: >>> On Tue, Jan 10, 2012 at 09:12:17PM +0100, Oliver Fromme wrote: Is there a way to find out the default FIB number of a process (from a shell script)? I'v

Re: Filtering on IPSEC

2012-01-11 Thread Bjoern A. Zeeb
On 11. Jan 2012, at 18:12 , Alex Dupre wrote: > Hi All, > I've setup my first IPSEC VPN beetween FreeBSD 8.2 and CheckPoint VPN-1. I've > used a gif interface for the tunnel, setkey for security policies and racoon > for ikev1. All is working fine, but I get a strange behavior: outgoing > pack

Re: Very fresh (two days ago) 10-current becomes completely unresponsive under load

2012-01-11 Thread Lev Serebryakov
Hello, Chuck. You wrote 11 января 2012 г., 3:47:08: > If it were me, I would also try with the older 44BSD scheduler, just to > see what happens. It helps both with mpd5.5 and mpd5.6. Now under network load top lines in `top' are PID USERNAME PRI NICE SIZERES STATETIME WCPU COMMAN

Filtering on IPSEC

2012-01-11 Thread Alex Dupre
Hi All, I've setup my first IPSEC VPN beetween FreeBSD 8.2 and CheckPoint VPN-1. I've used a gif interface for the tunnel, setkey for security policies and racoon for ikev1. All is working fine, but I get a strange behavior: outgoing packets go via enc0, while incoming packets arrive in gif0. T

Re: Processes' FIBs

2012-01-11 Thread Oliver Fromme
Bjoern A. Zeeb wrote: > On 10. Jan 2012, at 20:32 , Paul A. Procacci wrote: > > On Tue, Jan 10, 2012 at 09:12:17PM +0100, Oliver Fromme wrote: > > > Is there a way to find out the default FIB number of a > > > process (from a shell script)? I've checked the > > > manpages of ps and procstat,

Re: kern/155597: [panic] Kernel panics with " sbdrop" message

2012-01-11 Thread Vladimir Kutakov
The following reply was made to PR kern/155597; it has been noted by GNATS. From: Vladimir Kutakov To: Arnaud Lacombe Cc: bug-follo...@freebsd.org Subject: Re: kern/155597: [panic] Kernel panics with "sbdrop" message Date: Wed, 11 Jan 2012 17:55:41 +0400 We have tried RELENG_8_2 and the panic

Re: Processes' FIBs

2012-01-11 Thread Bjoern A. Zeeb
On 10. Jan 2012, at 20:32 , Paul A. Procacci wrote: > http://lists.freebsd.org/pipermail/freebsd-questions/2009-April/196532.html > > Not sure about ps/et al, but you can do it according to that post. Nearly 2 > years old now. > If you are thinking in terms of multiple forwarding information