Re: pf and keep/modulate state on 6.2

2007-07-26 Thread Jordan Gordeev
Max Laier wrote: On Saturday 21 July 2007, Jordan Gordeev wrote: I'm replying to an old and long-forgotten thread to report my recent findings. There's a bug in PF with modulate/synproxy state. Modulate/synproxy state modulate sequence numbers, but don't modulate sequence numbers in TCP SACK o

Re: Attention pf/ipfw users with uid/gid/jail rules (Re: Reminder: NET_NEEDS_GIANT, debug.mpsafenet going away in 7.0)

2007-07-26 Thread Kris Kennaway
On Fri, Jul 20, 2007 at 11:36:50AM -0700, Julian Elischer wrote: > Robert Watson wrote: > > > >On Tue, 17 Jul 2007, Max Laier wrote: > > > >So far I have had 0 (zero) reports of problems since this thread began. > >Could people using uid/gid/jail rules with ipfw or pf on 7.x *please* > >try runni

Re: Single IP failover without carpdev

2007-07-26 Thread Alexandre Biancalana
On 7/20/07, Max Laier <[EMAIL PROTECTED]> wrote: I am working on a patch to bring over carpdev functionality sponsored by pil.sk This will, however, take a bit longer than I initially though it would. Any news about it ? ___ freebsd-pf@freebsd.org

Re: connect: not permitted by pf state lookup failures on heavier load

2007-07-26 Thread Max Laier
On Thursday 26 July 2007, Gergely CZUCZY wrote: > Recently I've been playing around with a carp+pfsync+pound applevel > proxy. On a high connection rate I've noticed some failed connections > and the applevel proxy rendered the backend web servers DEAD, that > means unreachable. See http://lists.f

Re: HEADSUP: pf 4.1 import

2007-07-26 Thread Brian A. Seklecki
Right -- all of the BSDs that import pf(4) should have these patches to their net-snmp port. I can beta-test patches if you want to fwd them my way. I'll have to check to see when NetBSD plans to pull in the 4.1 pf(4). ~BAS On Tue, 2007-07-10 at 21:24 +0200, Lars Thegler wrote: > On 10-07-2007

connect: not permitted by pf state lookup failures on heavier load

2007-07-26 Thread Gergely CZUCZY
Hello, Recently I've been playing around with a carp+pfsync+pound applevel proxy. On a high connection rate I've noticed some failed connections and the applevel proxy rendered the backend web servers DEAD, that means unreachable. Pound sets on the gateway, accepts connections from the outside wo