setfib+pf

2009-01-12 Thread Dimitar Vasilev
Hi, I originally posted my message to questions, however no response for about a week. Therefore I'm reposting here. Original question available at http://lists.freebsd.org/pipermail/freebsd-questions/2009-January/190056.html For those who prefer reading human text, here are my questions: I'd like

Re: setfib+pf

2009-01-14 Thread Dimitar Vasilev
> > >> >> I'd much appreciate if someone thinks with me for the best options of >> using >> the setfib features along with pf. >> > > I know setfib but I don't know pf unfortunately.. I use ipfw > (which is why ipfw has fib support :-) > > > possibly Max Lair may know both.. > > Hi Julian, Could y

Re: setfib+pf

2009-01-15 Thread Dimitar Vasilev
2009/1/15 Julian Elischer > Dimitar Vasilev wrote: > >> >> >>I'd much appreciate if someone thinks with me for the best >>options of using >>the setfib features along with pf. >> >> >>I know setfib but

Re: TARPIT for pf/ipfw

2009-01-16 Thread Dimitar Vasilev
see spamd for mail and you may use the don't peer list of sbl . 2009/1/16 Vlad GALU > This particular iptables module keeps the incoming connection up and > running, but it sends ACKs advertising a window size of 0 bytes, so > that the remote end can't send any data until the local process has >

Re: TARPIT for pf/ipfw

2009-01-16 Thread Dimitar Vasilev
see spamd for mail and you may use the don't peer list of sbl . 2009/1/16 Vlad GALU > This particular iptables module keeps the incoming connection up and > running, but it sends ACKs advertising a window size of 0 bytes, so > that the remote end can't send any data until the local process has >