Re: Ethernet Switch Framework

2012-01-26 Thread Adrian Chadd
Ok, I do like the idea of: * mdiobus/miibus proxy tidyup; * then the switch API; * then the switch devices themselves. Can we get some consensus/agreement from Marius (and others) about the first step? Adrian ___ freebsd-net@freebsd.org mailing list h

Re: stateful firewall implementation in FreeBSD

2012-01-26 Thread Nikolay Denev
On Jan 27, 2012, at 4:41 AM, Kevin Oberman wrote: > On Thu, Jan 26, 2012 at 11:41 AM, Chuck Swiger wrote: >> Hi-- >> >> On Jan 26, 2012, at 9:24 AM, satish amara wrote: >>> I have question regarding the size of the state table kept in FreeBSD for >>> stateful packet inspection. Say we have a va

Re: stateful firewall implementation in FreeBSD

2012-01-26 Thread Kevin Oberman
On Thu, Jan 26, 2012 at 11:41 AM, Chuck Swiger wrote: > Hi-- > > On Jan 26, 2012, at 9:24 AM, satish amara wrote: >> I have question regarding the size of the state table kept in FreeBSD for >> stateful packet inspection. Say we have a valid senario where we have >> stateful firewall rule for HTTP

Re: stateful firewall implementation in FreeBSD

2012-01-26 Thread Chuck Swiger
Hi-- On Jan 26, 2012, at 9:24 AM, satish amara wrote: > I have question regarding the size of the state table kept in FreeBSD for > stateful packet inspection. Say we have a valid senario where we have > stateful firewall rule for HTTP and we get lot of incoming new HTTP session > and state table

Re: stateful firewall implementation in FreeBSD

2012-01-26 Thread Mike Tancsa
On 1/26/2012 12:24 PM, satish amara wrote: > Hi, > I have question regarding stateful firewall implementation of FreeBSD. > IPF has stateful “keep state” option. Hi, Take a look at pf, not ipf. ipf is not really maintained or used much any more under FreeBSD. With respect to dealing with

stateful firewall implementation in FreeBSD

2012-01-26 Thread satish amara
Hi, I have question regarding stateful firewall implementation of FreeBSD. IPF has stateful “keep state” option. Stateful filtering treats traffic as a bi-directional exchange of packets comprising a session conversation. When activated, keep-state dynamically generates internal rules for each ant

Re: bin/145934: [patch] add count option to netstat(1)

2012-01-26 Thread pluknet
Synopsis: [patch] add count option to netstat(1) State-Changed-From-To: open->closed State-Changed-By: pluknet State-Changed-When: Thu Jan 26 13:54:57 UTC 2012 State-Changed-Why: Close per submitter request. Similar functionality is available since 8.1 using the -q option. http://www.freebsd.org

Re: bin/145934: [patch] add count option to netstat(1)

2012-01-26 Thread Dmitry Banschikov
The following reply was made to PR bin/145934; it has been noted by GNATS. From: Dmitry Banschikov To: bug-follo...@freebsd.org Cc: Subject: Re: bin/145934: [patch] add count option to netstat(1) Date: Thu, 26 Jan 2012 16:09:45 +0300 --001636ed74f71f7ceb04b76e18c4 Content-Type: text/plain; c

Re: msk0: watchdog timeout interface hang

2012-01-26 Thread Kim Culhan
On Wed, Jan 25, 2012 at 3:26 PM, Kim Culhan wrote: > Running 10-curent from 01-20-12 > the msk0 interface hung, on the console: > > msk0: watchdog timeout > msk0: prefetch unit stuck? > msk0: initialization failed: no memory for Rx buffers > > Verbose boot dmesg output attached. This additional d