VPN SA expires in a minute

2006-03-26 Thread HEINER Péter
Hi all, I'd appreciate some help on the following: I have set up an OpenBSD 3.8 box as a VPN gateway, the other end is a Symantec enterprise firewall 7 box, which is not under my control. Tunnels get established and transfer data fine, but in under one minute the SA seems to become expired if

Queueing + load balancing for multiple outside connections

2006-03-19 Thread Heiner Péter
Hi all, I have a machine that has 4 NICs, one to an ISP, one to a router that connects to another ISP, one for LAN, one for DMZ. I did host-based traffic rate limiting in both directions, which worked fine with 1 external NIC. Recently a second line was bought because it was cheaper than addit

Re: Biased trunking

2006-03-12 Thread HEINER Péter
Shit, don't reply to this. I don't know why trunk stuck in the void I affectionately call my brain. I have the answer, thanks all for enduring my stupidity. Hi all, I'd like to be able to trunk 2 external interfaces and still have some control over which connections choose which route. The 2

Biased trunking

2006-03-12 Thread HEINER Péter
Hi all, I'd like to be able to trunk 2 external interfaces and still have some control over which connections choose which route. The 2 connections are from 2 different ISPs, one is 4Mbit/4Mbit, the other 10Mbit/10Mbit, the nominally faster tends to be slow for international traffic, however

OpenBSD behind Cisco 1800 series

2006-03-05 Thread HEINER Péter
Hi all, I've come across the same problem with 2 distinct networks, each with an OpenBSD server behind a Cisco 1800 series device. ASCII diagrams follow: Network 1|Network 2 | Internet | LAN 1 | | | C 1800 router