Testing new firewall to replace operational firewall

2009-05-17 Thread mehma sarja
This is a long and complicated affair. I have warned you and you still persist on reading further. I will try to protect you as much as possible, but please be forewarned. GOAL I want to test two pf firewalls in-line - an old openBSD (3.7 #50, i386) is on the 'outside' and a new FreeBSD (7.2 #0 am

Re: PF Nat Problem after PPP reconnection

2009-05-17 Thread britneyfreek
i've had such problems when using a mtu other than 1492... sorry, have no other solution. 2009/5/17 Max Laier : > On Sunday 17 May 2009 23:08:32 Kevin Smith wrote: >> You mean the ext_ad macro right ? >> >> What do you tell with that to pf, and why do I need it, can you tell me >> ? :) > > http://

Re:altq

2009-05-17 Thread irix
Hello , First of all,person who is responsible for this answer for my question about dynamics queues and finely complete to merge cdnr into pf, that altq nothing else, and complete does not this function. You need and you do. We are not interested in this. But altq is not complete solution.

Re: PF Nat Problem after PPP reconnection

2009-05-17 Thread Max Laier
On Sunday 17 May 2009 23:08:32 Kevin Smith wrote: > You mean the ext_ad macro right ? > > What do you tell with that to pf, and why do I need it, can you tell me > ? :) http://www.freebsd.org/cgi/query-pr.cgi?pr=69954 > Thank you! > > 2009/5/17 Max Laier > > > On Sunday 17 May 2009 21:50:52 Kevi

Re: PF Nat Problem after PPP reconnection

2009-05-17 Thread Max Laier
On Sunday 17 May 2009 21:50:52 Kevin Smith wrote: > /etc/pf.conf - i just added log for debugging but without log the > behaviour was the same > > ext_if = "tun0" > int_if = "nfe0" > ext_ad = "(tun0)" change that to "(tun0:0)" - it's an FAQ, only we don't have a good place to document it. Sugge

PF Nat Problem after PPP reconnection

2009-05-17 Thread Kevin Smith
Hello, I have a weird problem I couldn't solve. I have it from 7.0, after ppp reconnects to the ISP weird stuff happening, packets don't come back, the connection to the ISP gets very slow, http requests got timed out or load but items missing or the connection gets reset, but only for the compute

Re: altq

2009-05-17 Thread Nenhum_de_Nos
On Sat, May 16, 2009 21:45, irix wrote: > Hello Freebsd-pf, > > Sorry for my english. > > OpenBSD team is abandon the altq project. I just got curious about this: where you heard that OpenBSD is abandoning altq ? thanks, matheus -- We will call you cygnus, The God of balance you shall be A