Re: Testing new firewall to replace operational firewall

2009-05-19 Thread Peter Jeremy
On 2009-May-17 23:20:40 -0700, mehma sarja wrote: >I want to test two pf firewalls in-line - an old openBSD (3.7 #50, i386) is >on the 'outside' and a new FreeBSD (7.2 #0 amd64) is on the 'inside.' The >FreeBSD firewall does NOT have altq enabled. Here is the setup: I can't think of anything spec

Re: Testing new firewall to replace operational firewall

2009-05-18 Thread mehma sarja
Maciej, Thanks for answering one question. Now, does anyone know anything about "modulated state" running on tandem firewalls causing problems? Yudhvir === 2009/5/18 Maciej Milewski > Monday 18 May 2009 08:20:40 mehma sarja napisał(a): > > SECOND > > Are the "flags S/SA" altq functions? Becaus

Re: Testing new firewall to replace operational firewall

2009-05-18 Thread Maciej Milewski
Monday 18 May 2009 08:20:40 mehma sarja napisał(a): > SECOND > Are the "flags S/SA" altq functions? Because, as I said before, the new > firewall is FreeBSD GENERIC kernel with altq not compiled in. No, they aren't as far as I know. Altq is a mechanism using for queuing/traffic shaping. If you don

Testing new firewall to replace operational firewall

2009-05-17 Thread mehma sarja
This is a long and complicated affair. I have warned you and you still persist on reading further. I will try to protect you as much as possible, but please be forewarned. GOAL I want to test two pf firewalls in-line - an old openBSD (3.7 #50, i386) is on the 'outside' and a new FreeBSD (7.2 #0 am