Re: Single IP failover without carpdev

2007-07-20 Thread Alexandre Biancalana
On 7/20/07, Max Laier <[EMAIL PROTECTED]> wrote: I am working on a patch to bring over carpdev functionality sponsored by pil.sk This will, however, take a bit longer than I initially though it would. Great !! ___ freebsd-pf@freebsd.org mailing lis

Re: Single IP failover without carpdev

2007-07-20 Thread Tom Judge
Alexandre Biancalana wrote: On 7/20/07, David DeSimone <[EMAIL PROTECTED]> wrote: -BEGIN PGP SIGNED MESSAGE- That is OpenBSD's documentation you are referring to, but this is FreeBSD we are talking about. The implementation is not the same. In order for CARP to be effective, it must s

Re: Attention pf/ipfw users with uid/gid/jail rules (Re: Reminder: NET_NEEDS_GIANT, debug.mpsafenet going away in 7.0)

2007-07-20 Thread Robert Watson
On Fri, 20 Jul 2007, Julian Elischer wrote: Robert Watson wrote: On Tue, 17 Jul 2007, Max Laier wrote: So far I have had 0 (zero) reports of problems since this thread began. Could people using uid/gid/jail rules with ipfw or pf on 7.x *please* try running their firewalls without debug.mpsa

Re: Attention pf/ipfw users with uid/gid/jail rules (Re: Reminder: NET_NEEDS_GIANT, debug.mpsafenet going away in 7.0)

2007-07-20 Thread Robert Watson
On Fri, 20 Jul 2007, Paul Allen wrote: From Julian Elischer <[EMAIL PROTECTED]>, Fri, Jul 20, 2007 at 11:36:50AM -0700: Robert Watson wrote: On Tue, 17 Jul 2007, Max Laier wrote: So far I have had 0 (zero) reports of problems since this thread began. Could people using uid/gid/jail rules wi

Re: Single IP failover without carpdev

2007-07-20 Thread Max Laier
I am working on a patch to bring over carpdev functionality sponsored by pil.sk This will, however, take a bit longer than I initially though it would. -- /"\ Best regards, | [EMAIL PROTECTED] \ / Max Laier | ICQ #67774661 X http://pf4freebsd.

Re: Single IP failover without carpdev

2007-07-20 Thread Alexandre Biancalana
On 7/20/07, David DeSimone <[EMAIL PROTECTED]> wrote: -BEGIN PGP SIGNED MESSAGE- That is OpenBSD's documentation you are referring to, but this is FreeBSD we are talking about. The implementation is not the same. In order for CARP to be effective, it must send out hello packets on a pa

Re: Attention pf/ipfw users with uid/gid/jail rules (Re: Reminder: NET_NEEDS_GIANT, debug.mpsafenet going away in 7.0)

2007-07-20 Thread Paul Allen
>From Julian Elischer <[EMAIL PROTECTED]>, Fri, Jul 20, 2007 at 11:36:50AM >-0700: > Robert Watson wrote: > > > >On Tue, 17 Jul 2007, Max Laier wrote: > > > >So far I have had 0 (zero) reports of problems since this thread began. > >Could people using uid/gid/jail rules with ipfw or pf on 7.x *pl

Re: Attention pf/ipfw users with uid/gid/jail rules (Re: Reminder: NET_NEEDS_GIANT, debug.mpsafenet going away in 7.0)

2007-07-20 Thread Julian Elischer
Robert Watson wrote: On Tue, 17 Jul 2007, Max Laier wrote: So far I have had 0 (zero) reports of problems since this thread began. Could people using uid/gid/jail rules with ipfw or pf on 7.x *please* try running their firewalls without debug.mpsafenet -- ignore the witness warnings and/or d

Re: Single IP failover without carpdev

2007-07-20 Thread Dalibor Gudzic
Ah, sorry, got lost in tons of messages, didn't see where I was replying to. My apology. On 7/20/07, David DeSimone <[EMAIL PROTECTED]> wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dalibor Gudzic <[EMAIL PROTECTED]> wrote: > > http://www.openbsd.org/faq/pf/carp.html > > I think You thi

Re: Single IP failover without carpdev

2007-07-20 Thread David DeSimone
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dalibor Gudzic <[EMAIL PROTECTED]> wrote: > > http://www.openbsd.org/faq/pf/carp.html > > I think You think that one must have two IP addresses to get redundant > failover firewalls with Carp? That is OpenBSD's documentation you are referring to, but

Re: Single IP failover without carpdev

2007-07-20 Thread Dalibor Gudzic
On 7/20/07, Alexandre Biancalana <[EMAIL PROTECTED]> wrote: On 7/19/07, Marko Lerota <[EMAIL PROTECTED]> wrote: >How can I associate carp interface with physical interface without ifconfig >carpdev option and without have more ips available in the same network of >carp interface ? I'm not s

Attention pf/ipfw users with uid/gid/jail rules (Re: Reminder: NET_NEEDS_GIANT, debug.mpsafenet going away in 7.0)

2007-07-20 Thread Robert Watson
On Tue, 17 Jul 2007, Max Laier wrote: [ Excess CC-list ... testers needed!!! ] On Tuesday 17 July 2007, Robert Watson wrote: Dear all: This is a reminder e-mail that, in the very near future, Giant compatibility shims for network protocols will be removed. <...> The *only* remaining case