Re: native vlan

2009-08-31 Thread Brian A. Seklecki
On Mon, 2009-08-24 at 12:12 -0700, Graham Smith wrote: > requiring creation of native vlan (vlan 0) and why native vlan are > most suitable for this scene ? Cisco highly recommend changing the management VLAN away from VLAN1. Here's an example, of using alternative native VLANs, ironically, on t

re: [trouble] restart network & vlan`s interface (if_vlan / conf/63700 redux)

2010-06-04 Thread Brian A. Seklecki
destroying your routing table after adding an alias to a VLAN interface in rc.conf(5), simply run: $ sudo /etc/rc.d/netif [VLAN] start DO NOT RESTART, and you should be okay. ~BAS References: http://lists.freebsd.org/pipermail/freebsd-hackers/2008-February/023440.html http://www.freebsd.or

Dropped/Duplicate SYN, Cisco PIX/ASA, and and random ISN w/ net.inet.ip.random_id=1

2009-07-17 Thread Brian A. Seklecki
o doubt their own existence. ~Brian A. Seklecki (*) To disable port randomization on the Cisco PIX: tcp-map verify-chksum check-retransmission checksum-verification exceed-mss drop syn-data drop tcp-options selective-ack allow urgent-flag clear no ttl-evasion-protection ! icmp unreachable

net.inet.tcp.keepidle and friends

2009-08-03 Thread Brian A. Seklecki
All: The description on this sysctl was just recently added in -CURRENT. It was missing during all of RELENG_6 and RELENG_7? Do we not trust it entirely, ergo the two hour initial threshold and lack of documentation? It also seems like the description could be bit more insightful; looks like it

checking SO_ACCEPTFILTER with netstat(1)/sockstat(1)

2007-07-20 Thread Brian A. Seklecki
,SNDBUF=262144 TF=MSS=1024,NODELAY,REQ_SCALE,REQ_TSTMP) A little bit more definitive than "Oh hey apache stopped complaining." Any other way? l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/ "Guilty? Yeah. But he k