Re: packet order, ipf or ipfw

2004-07-29 Thread Andrew Riabtsev
Hello Charlie, Thursday, July 29, 2004, 1:23:33 AM, you wrote: CS> So, what is the order, if I'm running ipf AND ipfw at the same time? CS> Will it work at all in this manner? Load both firewalls as modules, then you can be sure packets goes first through firewall you load first. And yes, this sh

Re[2]: packet order, ipf or ipfw (offtopic)

2004-07-29 Thread Andrew Riabtsev
Hello Max, Thursday, July 29, 2004, 1:46:06 AM, you wrote: ML> Another alternative (on FreeBSD-current) would be pf+ALTQ, btw ;) Is there any chance to see one day pf for 4.X-RELEASE? I'm still thinking pf is the best firewall ever made but it is very frustrated i can't use it on freeBSD boxes. :

Re: netgraph questions on ng_tee, ng_iface, ng_socket

2004-01-19 Thread Andrew Riabtsev
Hi all, Monday, January 19, 2004, 12:34:25 PM, you wrote: DN> hey all, skiped DN> i need some understanding on what exactly ng_iface achieves, as it makes a DN> reference to the hook inet being connected to something. however, DN> connecting the ng_iface hook inet to ng_ether's upper or lower

Re[2]: netgraph questions on ng_tee, ng_iface, ng_socket

2004-01-20 Thread Andrew Riabtsev
Hi, Dinesh, Monday, January 19, 2004, 8:29:23 PM, you wrote: DN> On Mon, 19 Jan 2004, Andrew Riabtsev wrote: >> DN> connecting the ng_iface hook inet to ng_ether's upper or lower doesnt make >> DN> any sense because ng_ether itself does not do an encasulation of th

Re[2]: netgraph questions on ng_tee, ng_iface, ng_socket

2004-01-20 Thread Andrew Riabtsev
GS> On Tue, Jan 20, 2004 at 11:48:44AM +0300, Andrew Riabtsev wrote: A>> >> Connecting ng_iface:inet and ng_ether:upper/lower do nothing, well, it A>> >> do something but not what you are waiting for, i think. A>> A>> DN> i know, hence was asking if th

Re[2]: netgraph questions on ng_tee, ng_iface, ng_socket

2004-01-21 Thread Andrew Riabtsev
Tuesday, January 20, 2004, 9:51:52 PM, you wrote: DN> On Tue, 20 Jan 2004, Gleb Smirnoff wrote: >> Isn't ng_etf(4) the one you need? DN> ng_etf does filtering, i'm planning on doing round robin IP tranmission, DN> with source IP address set accordingly. see ng_one2many which gives an DN> exampl

netgraph: bridge with fwd and divert

2004-01-21 Thread Andrew Riabtsev
Hi, All I'm trying to let my FreeBSD 4.9 box, working as bridge, divert and fwd bridged packets. As i undestand it is not realized in FreeBSD 4.9. I was thinking about to do it (realize), but im too lazy and when i see this huge amount of work i start thinking :) Befor i continue my work i just w

Re: Linux ethernet bonding like driver

2004-02-06 Thread Andrew Riabtsev
Hi Anshuman, Thursday, February 5, 2004, 8:19:46 PM, you wrote: AK> Hi all, AK> I have a situation where my servers (Freebsd Solaris AK> and Linux) are connected to two independent switches AK> via 2 seperate NIC cards. To enhance my redundancy I AK> want to group 2 adapters in a active-standby

ng_netflow: request for feature

2004-02-19 Thread Andrew Riabtsev
Hi Gleb, Wednesday, February 18, 2004, 3:49:58 PM, you wrote: GS>Dear collegues, GS>a port of ng_netflow has been just commited to ports GS> tree. It builds both on STABLE and CURRENT, and was tested GS> to work on really busy routers. GS>As before, I'd be glad for any kind of feedba

Re[2]: ng_netflow: request for feature

2004-02-19 Thread Andrew Riabtsev
Привет Gleb, Thursday, February 19, 2004, 3:18:11 PM, you wrote: GS> On Thu, Feb 19, 2004 at 02:34:02PM +0300, Andrew Riabtsev wrote: A>> GS>a port of ng_netflow has been just commited to ports A>> GS> tree. It builds both on STABLE and CURRENT, and was tested A>>

Re[2]: ng_netflow: request for feature

2004-02-19 Thread Andrew Riabtsev
Привет Gleb, Thursday, February 19, 2004, 4:50:42 PM, you wrote: GS> On Thu, Feb 19, 2004 at 04:02:09PM +0300, Andrew Riabtsev wrote: A>> GS> In most cases the answer is no. In 90 % cases ng_netflow is used on A>> GS> top of ng_ether(4) node, which passes all data comin

Re[2]: ifconfig and route problem.

2004-02-24 Thread Andrew Riabtsev
>> # ifconfig rl0 $ip (where ip can be also 192.168.100.1), my >> default route is deleted, cut off server for my net. >> SDS> Say you wanted to change from 192.168.100.1/24 to 10.0.0.1/24 SDS> With default gateway changed from 192.168.100.254 to 10.0.0.254 SDS> ifconfig rl0 inet 10.0.0.1/24 a

Re[2]: Bad loopback traffic not stopped by ipfw.

2004-02-25 Thread Andrew Riabtsev
Привет Iasen, Wednesday, February 25, 2004, 3:37:25 PM, you wrote: IK> netstat -s -p ip IK> . IK> . IK> . IK> 3575124 datagrams with bad address in header IK> Could it be this that drops "bad" packets before they enter the IPFW ? To me it would be also interesting to know where this

problem with an (4.9-STABLE) and Cisco 340 PCI card

2004-03-23 Thread Andrew Riabtsev
Hello, I have the following problem with runing AIR-PCI340 on FreeBSD 4.9-STABLE: #ifconfig an0 media autoselect ifconfig: SIOCGAIRONET: Operation not permined #ifconfig -m an0 shows availible media types just as usual. Other parameters sets normal (essid, stationname and so on). But with media

Re: Problem with ng_ether packet flow..

2004-05-07 Thread Andrew Riabtsev
Hi Jian-Wei, Thursday, May 6, 2004, 6:46:16 PM, you wrote: JWW> Hi, I spent times to figure out the packet flow with ng_ether, like this: JWW> upper layer JWW> | JWW> ^ JWW> [ether_demux] JWW> ^ JW