Re: ifconfig creates a bogus(?) route

2016-05-28 Thread Kimmo Paasiala
On Sat, May 28, 2016 at 10:19 AM, Bruce Evans wrote: > Sometime between r191220 and r201220, ifconfig started creating a bogus(?) > static route. The following is under r248255 with > "ifconfig em0 inet 192.168.2.8" (where 192.168.2.8 is for the local host > and I don't bother typing the netmsk)

Re: HELP! Mysterious socket 843/tcp listening on CURRENT system

2015-09-15 Thread Kimmo Paasiala
On Tue, Sep 15, 2015 at 10:06 AM, O. Hartmann wrote: > Hopefully, I'm right on this list. if not, please forward. > > Running CURRENT as of FreeBSD 11.0-CURRENT #3 r287780: Mon Sep 14 13:34:16 > CEST 2015 amd64, I check via nmap for open sockets since I had trouble > protecting a server with IPFW

Re: Ethernet tunneling options under FreeBSD

2015-08-13 Thread Kimmo Paasiala
On Fri, Aug 14, 2015 at 1:40 AM, James Lott wrote: > Hello list, > > I am in the process of planning a build out of a L2 VPN, in which I'd like > to have my primary "switch" and DHCP server be a FreeBSD system. I would > like to join each new host to the VPN by establishing an IP tunnel with the >

Re: unknown UDP caused by dhclient

2015-06-04 Thread Kimmo Paasiala
On Thu, Jun 4, 2015 at 9:20 PM, Matthias Apitz wrote: > El día Thursday, June 04, 2015 a las 07:54:35PM +0300, Kimmo Paasiala > escribió: > >> That is how a DHCP client ask for lease renewal from the DHCP server, >> you should allow the traffic if the interface in questio

Re: unknown UDP caused by dhclient

2015-06-04 Thread Kimmo Paasiala
On Thu, Jun 4, 2015 at 10:31 AM, Matthias Apitz wrote: > > Hello, > > I'm seeing in my firewall log unknow UDP traffic which is caused by the > running dhclient: > > Jun 3 21:57:02 c720-r276659 dhclient[2601]: send_packet: Network is > unreachable > Jun 3 21:57:02 c720-r276659 ipmon[2368]: 21:5

Re: Why default route is not installed last?

2013-08-26 Thread Kimmo Paasiala
On Mon, Aug 26, 2013 at 2:37 PM, Hiroki Sato wrote: > Xin Li wrote > in <521670ff.6080...@delphij.net>: > > de> -BEGIN PGP SIGNED MESSAGE- > de> Hash: SHA512 > de> > de> Hi, > de> > de> I've noticed that we do not install default route last (after other > de> static routes). I think we

Re: how calculate the number of ip addresses in a range?

2013-08-09 Thread Kimmo Paasiala
On Sat, Aug 10, 2013 at 2:07 AM, Kimmo Paasiala wrote: > On Sat, Aug 10, 2013 at 1:44 AM, Peter Wemm wrote: >> On Fri, Aug 9, 2013 at 9:34 AM, Fleuriot Damien wrote: >>> >>> On Aug 8, 2013, at 10:27 AM, Peter Wemm wrote: >>> >>>> On Thu, Aug 8

Re: how calculate the number of ip addresses in a range?

2013-08-09 Thread Kimmo Paasiala
On Sat, Aug 10, 2013 at 1:44 AM, Peter Wemm wrote: > On Fri, Aug 9, 2013 at 9:34 AM, Fleuriot Damien wrote: >> >> On Aug 8, 2013, at 10:27 AM, Peter Wemm wrote: >> >>> On Thu, Aug 8, 2013 at 12:04 AM, s m wrote: hello guys, i have a question about ip addresses. i know my question

Re: Duplicate Address Detection misfire?

2013-07-22 Thread Kimmo Paasiala
On Tue, Jul 23, 2013 at 8:44 AM, Zaphod Beeblebrox wrote: > What to do when you don't trust the interface? VMWare is obviously > emulating the hardware and their interpretation of what the hardware "is" > is possibly different from ours. > > If I boot single-user and tcpdump the interface, I see

Re: ipfilter(4) needs maintainer

2013-04-15 Thread Kimmo Paasiala
On Mon, Apr 15, 2013 at 1:54 PM, Kimmo Paasiala wrote: > On Mon, Apr 15, 2013 at 1:50 PM, Lev Serebryakov wrote: >> Hello, Kimmo. >> You wrote 15 апреля 2013 г., 14:47:24: >> >> KP> I'm however talking about an ftp client behind a very restrictive >> KP&g

Re: ipfilter(4) needs maintainer

2013-04-15 Thread Kimmo Paasiala
On Mon, Apr 15, 2013 at 1:50 PM, Lev Serebryakov wrote: > Hello, Kimmo. > You wrote 15 апреля 2013 г., 14:47:24: > > KP> I'm however talking about an ftp client behind a very restrictive > KP> firewall making an IPv6 connection an ftp server that uses passive > KP> mode data ports that can't be kn

Re: ipfilter(4) needs maintainer

2013-04-15 Thread Kimmo Paasiala
On Mon, Apr 15, 2013 at 1:44 PM, Lev Serebryakov wrote: > Hello, Kimmo. > You wrote 15 апреля 2013 г., 14:36:27: > >>> And, yes, NAT64 will be useful for sure, but it is another story, >>> not IPv6<->IPv6 translation. > KP> You're forgetting set ups where outgoing traffic is controlled by > KP> f

Re: ipfilter(4) needs maintainer

2013-04-15 Thread Kimmo Paasiala
On Mon, Apr 15, 2013 at 1:32 PM, Lev Serebryakov wrote: > Hello, Kimmo. > You wrote 15 апреля 2013 г., 14:26:40: > >>> MM> ... and as far as I can tell none of them is currently usable >>> MM> on an IPv6-only FreeBSD (like protecting a host with sshguard), >>> MM> none of them supports stateful NA

Re: ipfilter(4) needs maintainer

2013-04-15 Thread Kimmo Paasiala
On Mon, Apr 15, 2013 at 1:15 PM, Lev Serebryakov wrote: > Hello, Mark. > You wrote 15 апреля 2013 г., 2:25:07: > >>> Yes! This is the most clever thought in this thread. Why we need 3 >>> firewalls? Two packet filters it's excess too. We have two packet filters: >>> one with excellent syntax and f

Re: ipfilter(4) needs maintainer

2013-04-13 Thread Kimmo Paasiala
On Sat, Apr 13, 2013 at 3:03 PM, Scott Long wrote: > > On Apr 13, 2013, at 12:33 AM, Rui Paulo wrote: > >> On 2013/04/12, at 22:31, Scott Long wrote: >> >>> On Apr 12, 2013, at 7:43 PM, Rui Paulo wrote: >>> On 2013/04/11, at 13:18, Gleb Smirnoff wrote: > Lack of maintainer in a n