Re: Help with pf

2005-12-10 Thread Travis H.
Please provide the output of "pfctl -s all" when the host is acting problematic and I'll do what I can to help. -- http://www.lightconsulting.com/~travis/ -><- Knight of the Lambda Calculus "We already have enough fast, insecure systems." -- Schneier & Ferguson GPG fingerprint: 50A1 15C5 A9DE 23B9

Re: Firewall concepts

2005-12-10 Thread Travis H.
On 12/8/05, Marcus Franke <[EMAIL PROTECTED]> wrote: > > A firewall on every pc will soon become a nightmare to manage as the > > network grows. Not necessarily. If the needs of the machines do not change, then there is no change to manage. Your pf rules, in theory, can be quite simple, and adju

Re: Syntax errors in pf.conf

2005-12-10 Thread Travis H.
> Yes, the BNF at the bottom of the pf.conf man page. Or "pfctl -n". -- http://www.lightconsulting.com/~travis/ -><- Knight of the Lambda Calculus "We already have enough fast, insecure systems." -- Schneier & Ferguson GPG fingerprint: 50A1 15C5 A9DE 23B9 ED98 C93E 38E9 204A 94C2 641B ___

DIOCADDALTQ: Cannot allocate memory

2005-12-10 Thread Robert
this is what i get when i try to start pf in the home256 queue i have 80 clients i have 1GB RAM and a 3Ghz processor pfctl: DIOCADDALTQ: Cannot allocate memory cam asa arata pful altq on $int_if hfsc bandwidth 100Mb queue { default, manager, home256 } queue default bandwidth 8Kb hfsc(default)

DIOCADDALTQ: Cannot allocate memory

2005-12-10 Thread Robert
this is my problem i have 80 clients in the home256 queue this is how my pf.conf looks i have 1GB RAM and 3Ghz P4 pfctl: DIOCADDALTQ: Cannot allocate memory cam asa arata pful altq on $int_if hfsc bandwidth 100Mb queue { default, manager, home256 } queue default bandwidth 8Kb hfsc(default) q

if_bridge + altq (CBQ)

2005-12-10 Thread Hideki Yamamoto
Dear Gentleman, I am trying the packect shaping by CBQ of altq on FBSD6 box. The box is configured as bridge by if_bridge kernel configuration. The target packet is UDP on IPv6. Though I wrote output port number of the udp packet on /etc/services and wrote CBQ shaping rule on /etc/pf.conf, the s