Re: Local routing issue when iked running

2014-02-27 Thread Josh
On Fri, Feb 28, 2014 at 9:52 AM, Stuart Henderson wrote: > > I'm sure it's a bug, I suspect possibly in some dark corner of radix.c. > I haven't heard of anybody else hitting this same problem so in a way > I'm quite glad it's not just me :) > > On box1 you have these flows > > 192.168.150.13/32

Re: L2TP VPN / pf

2014-02-27 Thread Paul B. Henson
> From: YASUOKA Masahiko > Sent: Thursday, February 27, 2014 5:44 PM > >> In L2TP/IPsec, "transport mode" IPsec is used instead of tunnel mode. > >> This means enc(4) is not used. And de-capsulated L2TP packets are > >> received on the same interface which receives IPsec packet. > > > > Hmm, that'

Re: Content Filtering in smtpd(8) with amavisd-new

2014-02-27 Thread Aaron Poffenberger
On Feb 27, 2014, at 2:17 AM, Marcus MERIGHI wrote: >> The question I have for Gilles et al.: Is there a better way to send the >> emails to amavisd? It would be more efficient if emails went through >> "virtual " first so invalid recipients were rejected before >> content filtering. > > I'm not

Re: Local routing issue when iked running

2014-02-27 Thread Stuart Henderson
On 2014-02-27, Josh wrote: > On Thu, Feb 27, 2014 at 11:00 AM, Stuart Henderson > wrote: >> >> Try tcpdumping packets going over the ipsec tunnel, do you see those packets >> which should be local actually being sent over the tunnel? If so, I don't >> have >> an answer for this, but I've seen i

Re: L2TP VPN / pf

2014-02-27 Thread YASUOKA Masahiko
On Thu, 27 Feb 2014 13:51:10 -0800 "Paul B. Henson" wrote: >> From: YASUOKA Masahiko >> Sent: Wednesday, February 26, 2014 8:46 PM >> sysctl net.pipex.enable=1 > > Hmm, yeah, that... I had updated my /etc/sysctl.conf with that change, but > the system had not been rebooted since I did that; and

Re: L2TP VPN / pf

2014-02-27 Thread Paul B. Henson
> From: YASUOKA Masahiko > Sent: Wednesday, February 26, 2014 8:46 PM > "set skip on pppx0" needs to be improved because npppd may use pppx1, > pppx2 ... Once I've got things working, I'm probably going to want to have more explicit rules rather than skipping; if I understand correctly I can just

Re: Content Filtering in smtpd(8) with amavisd-new

2014-02-27 Thread Marcus MERIGHI
a...@hypernote.com (Aaron Poffenberger), 2014.02.26 (Wed) 18:30 (CET): > I recently configured smptd to replace a postfix-based solution. > smtpd(8) is a joy to work with. In ~four rules I had a working email > server! > > My next goals was to get content filtering in place. I decided on > amavisd