Re: Loading pf rules at boot with '-o' flag to pfctl...

2006-10-08 Thread Ryan McBride
On Sun, Oct 08, 2006 at 01:53:42AM -0400, Martin Gignac wrote: > Is there any plan to add a variable in /etc/rc.conf to achieve this, > or is using '-o' during boot considered a bad thing? The plan is to make it possible to specify the optimization level directly in the pf.conf file (which one cou

Re: benefits of older versions

2006-10-08 Thread prad
On Sun, 08 Oct 2006 22:36:47 -0400 Nick Holland <[EMAIL PROTECTED]> wrote: > Keep your system current. There are lots of reasons to do that, few > good reasons not to. > nick you have answered my questions totally! even those i had difficulty in figuring out how to ask (and therefore didn't). i

Re: benefits of older versions

2006-10-08 Thread Nick Holland
prad wrote: > why are older versions of openbsd (or linux or whatever os) kept around? Not sure what you are referring to..I'm guessing you are referring to things you saw on some FTP servers and for sale on the website... If so, the answer is, much the same reason libraries don't throw away book

Re: best hardware plataform for openbsd

2006-10-08 Thread Gustavo Rios
I would use them for a X server. It will serve about 128 X clients. On 10/8/06, Diana Eichert <[EMAIL PROTECTED]> wrote: On Sun, 8 Oct 2006, Gustavo Rios wrote: > I meant more CPU processing cycles per a given constant amount of money! > That's it. Hmmm, before I answer that question I'd like

Re: benefits of older versions

2006-10-08 Thread Darrin Chandler
On Sun, Oct 08, 2006 at 05:39:58PM -0700, prad wrote: > why are older versions of openbsd (or linux or whatever os) kept around? > > is it because some of the older versions may work better with older > machines? for instance, i recall that our 486 and p120 did really well > with slackware 8. we'r

Re: Vlans using a trunk device

2006-10-08 Thread Dustin Lundquist
Two ideas come to mind: Either use one interface for each VLAN, or create VLAN interfaces on each ethernet interface and then trunk all the VLAN interfaces assigned to the same VLAN. Dustin Lundquist Axton Grams wrote: While working with the trunk and vlan features of OpenBSD, I ran into one

benefits of older versions

2006-10-08 Thread prad
why are older versions of openbsd (or linux or whatever os) kept around? is it because some of the older versions may work better with older machines? for instance, i recall that our 486 and p120 did really well with slackware 8. we're going to get some 486s going again - should i use an older ver

Re: IPv6 over PPPoE

2006-10-08 Thread Stuart Henderson
On 2006/10/08 17:41, Thomas Bader wrote: > I tried to reach fe80::ff1c:1402 link-local needs the network interface to be specified; you would need fe80::ff1c:1402%tun0 here. > - According to the manual page the Framed-IPv6-Prefix can be used > in commands through the IPV6PREFIX variable. that'

Thanks (USB umass device)

2006-10-08 Thread Brian
I plugged in my attache' USB drive in today, and it worked. scsibus2 at umass1: 2 targets sd4 at scsibus2 targ 1 lun 0: SCSI0 0/direct removable sd4: 117MB, 117 cyl, 64 head, 32 sec, 512 bytes/sec, 239872 sec total Thanks for fixing this issue. I had posted about it not working well over a year

Re: Vlans using a trunk device

2006-10-08 Thread Axton Grams
Stuart Henderson wrote: > On 2006/10/08 15:31, Axton Grams wrote: >> While working with the trunk and vlan features of OpenBSD, I ran into >> one thing that I do not understand. In order to use a trunk device for >> multiple vlan's, the trunk device must have an ip address assigned. > > Your ifco

Re: Vlans using a trunk device

2006-10-08 Thread Stuart Henderson
On 2006/10/08 15:31, Axton Grams wrote: > While working with the trunk and vlan features of OpenBSD, I ran into > one thing that I do not understand. In order to use a trunk device for > multiple vlan's, the trunk device must have an ip address assigned. Your ifconfig output is from when it's wor

Re: lightweight openbsd

2006-10-08 Thread ropers
On 08/10/06, Marc Balmer <[EMAIL PROTECTED]> wrote: * ropers wrote: > >I am trying to make [OpenBSD] smaller by deleting unuseful files. I read > >man > >and then deside whether I need it or not. After deleting a dozen of files I > >received diffirent errors during startup. OpenBSD, with samba c

Re: FTP Account Lockout

2006-10-08 Thread ICMan
Also, you could do the following: 1) Limit the scope of the PCI certification by placing all CC storing or processing systems on a DMZ behind an appropriately configured firewall; AND 2) make sure that your FTP server is outside of this DMZ. This assumes that the FTP server does not contain

Re: lightweight openbsd

2006-10-08 Thread Marc Balmer
* ropers wrote: > >I am trying to make [OpenBSD] smaller by deleting unuseful files. I read > >man > >and then deside whether I need it or not. After deleting a dozen of files I > >received diffirent errors during startup. OpenBSD, with samba cups and everything to make a nice embedded server can

Re: lightweight openbsd

2006-10-08 Thread ropers
I am trying to make [OpenBSD] smaller by deleting unuseful files. I read man and then deside whether I need it or not. After deleting a dozen of files I received diffirent errors during startup. Don't do that then. I want to install it to 128mb CF. Unless you really WANT to find yourself tot

Vlans using a trunk device

2006-10-08 Thread Axton Grams
While working with the trunk and vlan features of OpenBSD, I ran into one thing that I do not understand. In order to use a trunk device for multiple vlan's, the trunk device must have an ip address assigned. Let me illustrate my configuration (vlan ids do not match, but it's not relavent, see if

Re: Problems with traffic shaping

2006-10-08 Thread tony sarendal
I don't see anything wrong here, perhaps tired eyes. If you run PPPoE and the DSL line then is ATM AAL5 with LLC/SNAP encapsulation altq isn't going to be very effective in cases where you have lots of ACKs going up stream. When altq sees an ACK it calculates 40 bytes, but that ACK is 106 bytes (2

Re: Letter to OLPC

2006-10-08 Thread Daniel Ouellet
Jeroen Massar wrote: Daniel Ouellet wrote: [.. a part that you didn't want to make a 'point' about anyway..] Men, I must be pretty darn stupid I have to say. My point wasn't about the dam licenses or comparing GPL to BSD for crying at loud! Then don't mention it. Also learn how to reply to

OpenBSD PF firewall and Cisco VPN client

2006-10-08 Thread Phusion
I am new to setting up VPN's. Is the following possible using OpenBSD pf for firewalling. The internal network is made up of Windows servers and workstations, and the external laptop/workstation is running Windows as well as having Cisco VPN client software. Would this external machine running Win

Re: IPv6 over PPPoE

2006-10-08 Thread Alexandre Ratchov
On Sun, Oct 08, 2006 at 05:41:33PM +0200, Thomas Bader wrote: > Hi all > > With the help of my ISP I'm trying to get native IPv6 over ADSL (PPPoE). > This isn't a regular offer and I'm the first customer who tries it out. > > My ISP has set me the following two RADIUS attributes: > > Framed-IPv6

OpenBSD IPSec/ipsecctl + setkey

2006-10-08 Thread Tom
Hello misc I'm trying to setup IPSec between my OpenBSD wireless access point and a Linux client using setkey. I have managed to get IPSec working fine between the other OpenBSD servers on my network using ipsecctl, almost seemed too easy. Below are my ipsec.conf from the OpenBSD box and the ipse

Re: Letter to OLPC

2006-10-08 Thread Joachim Schipper
tions in general, but it does indeed > appear to apply to this particular project. :-( > > Small wonder the project exhibits other flaws, too, > when even this central aspect has been screwed up... Just to add some numbers, and because it's a neat tool (even if the 'export to

IPv6 over PPPoE

2006-10-08 Thread Thomas Bader
Hi all With the help of my ISP I'm trying to get native IPv6 over ADSL (PPPoE). This isn't a regular offer and I'm the first customer who tries it out. My ISP has set me the following two RADIUS attributes: Framed-IPv6-Prefix = 2001:x:3000::1 Framed-IPv6-Route = 2001:x:4000::/48 2001:x:3000::1 1

Re: graphviz rendering of installed ports dependencies

2006-10-08 Thread Bruno Carnazzi
Note there is a problem when graphing application dependencies (-D option) . Graphviz can not draw nodes that are shared in multiples subgraph (ie : shared library used by multiple application). So, this functionnality only works for simple installations. Explanation : https://mailman.research.

Re: Loading pf rules at boot with '-o' flag to pfctl...

2006-10-08 Thread Martin Gignac
On 10/8/06, z0mbix <[EMAIL PROTECTED]> wrote: You are supposed to use the -o option to optimise your ruleset, then correct the ruleset in /etc/pf.conf so there should be no need to load the ruleset with -o everytime. Ok, thanks, my bad. I originally thought the intent of the flag was to permit

Re: best hardware plataform for openbsd

2006-10-08 Thread Diana Eichert
On Sun, 8 Oct 2006, Gustavo Rios wrote: > I meant more CPU processing cycles per a given constant amount of money! > That's it. Hmmm, before I answer that question I'd like to know what are the intended uses? For example, for a DNS server I would seriously consider some of the platforms recently

Re: graphviz rendering of installed ports dependencies

2006-10-08 Thread Bruno Carnazzi
Now, with colored nodes, colored dependencies, and options handling : #!/bin/sh PROGNAME=$(basename $0) NODE_COLOR=0 DEP_COLOR=0 TOP_COL=greenyellow BOTTOM_COL=firebrick DEP_COL=lightgrey TOP_PKGS="" get_fulldepends() { FULLDEP= STEP=$(pkg_info -f $1 | grep '@depend' | cut -d':

Re: Letter to OLPC

2006-10-08 Thread Darrin Chandler
On Sun, Oct 08, 2006 at 02:22:35PM +0200, Ingo Schwarze wrote: > > So those children will get laptops before their families > have electricity? Had they any choice, how many of them > would choose that way? Given the effort and money used > for the OLPC project - on what would those people like

Re: Letter to OLPC

2006-10-08 Thread Ingo Schwarze
Theo de Raadt wrote on Sat, Oct 07, 2006 at 02:55:22PM -0600: > Adriaan <[EMAIL PROTECTED]> wrote: >> See Jim Gettys defense at >> http://www.gettysfamily.org/wordpress/?p=27 [...] > You can't say anything bad about the children, can you? Just as your rhetorical question suggests, indeed you can.

Re: Problems with traffic shaping

2006-10-08 Thread tony sarendal
On 08/10/06, tony sarendal <[EMAIL PROTECTED]> wrote: > > > > On 07/10/06, S t i n g r a y <[EMAIL PROTECTED]> wrote: > > > > it is asymmetric > > > What bandwidth have you configured the shaper for ? > Doh ! > altq on $extif cbq bandwidth 500Kb queue { def, msn, www, https, smtp, ssh, ftp } Wha

Re: Problems with traffic shaping

2006-10-08 Thread tony sarendal
On 07/10/06, S t i n g r a y <[EMAIL PROTECTED]> wrote: > > it is asymmetric What bandwidth have you configured the shaper for ? Some technologies like PPPoA or PPPoE over DSL will give you an overhead of 165% for empty ACKs, meaning that your shaper wont kick in since it doesn't consider the lin

Re: best hardware plataform for openbsd

2006-10-08 Thread viq
On 08/10/06, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2006/10/07 18:08, Brian wrote: > > There are more options than just those. macppc and sparc64 are amongst > > the faster arch's too (and if you don't need out-and-out speed there are > > more to choose from). Motherboard chipsets also ma

Re: best hardware plataform for openbsd

2006-10-08 Thread Stuart Henderson
On 2006/10/07 18:08, Brian wrote: > > There are more options than just those. macppc and sparc64 are amongst > > the faster arch's too (and if you don't need out-and-out speed there are > > more to choose from). Motherboard chipsets also make a *HUGE* difference, > > of course. > > I am looking at

Re: graphviz rendering of installed ports dependencies

2006-10-08 Thread Bruno Carnazzi
Now, with colors : #!/bin/sh TOP_COLOR=greenyellow BOTTOM_COLOR=firebrick echo "digraph pkg_dep" echo "{" for PKG in $(pkg_info | cut -d' ' -f1) ; do PKG_INFO=$(pkg_info -c $PKG | tail -n+4 | tr -s '\n') echo "\t\"$PKG\" [label=\"$PKG\\\n$PKG_INFO\"];" REQ_BY="" for

Re: Loading pf rules at boot with '-o' flag to pfctl...

2006-10-08 Thread z0mbix
On 08/10/06, Martin Gignac <[EMAIL PROTECTED]> wrote: Hi, While playing around with pf I've gotten used to passing the '-o' flag to pfctl to optimize my rulesets when loading them. However, I've noticed that /etc/rc does not pass the '-o' flag when loading the ruleset with pfctl during boot. Mo

Re: X not working with NVIDIA GeForce 7800 GS on amd64

2006-10-08 Thread Andreas Bihlmaier
On Sat, Oct 07, 2006 at 12:11:53AM +0200, Andreas Maus wrote: > Hi. > > I recently replaced my ATI X800 with a new NVIDIA GeForce 7800 GS. > Checking the nv(4) man page and it states that it supports: > > [... snipp ...] > GeForce 7XXX > [... snipp ...] I have the same problem with a GeForce 7

can not compile the new kernel

2006-10-08 Thread LeVA
Hi! I've applied the patches from the errata page, and now I'm trying to recompile the kernel. /usr/src/sys/arch/i386/conf $ config GENERIC Don't forget to run "make depend" /usr/src/sys/arch/i386/conf $ cd ../compile/GENERIC /usr/src/sys/arch/i386/compile/GENERIC $ make clean depend "Makefile",

Re: best hardware plataform for openbsd

2006-10-08 Thread Daniel Ouellet
Gustavo Rios wrote: I meant more CPU processing cycles per a given constant amount of money! That's it. Then go for AMD, they have more instructions then Intel that now try to catch up to them! So, call it more instructions machine per dollar if you like that!