Re: pf.conf "reply-to" routing parameter seemingly not working?

2018-05-12 Thread Joseph Crivello
Apologies, correction: obsd3# pfctl -f /etc/pf.conf Should be: obsd2# pfctl -f /etc/pf.conf Joe On Sat, May 12, 2018 at 9:37 PM Joseph Crivello wrote: > I cannot get reply-to working with if-bound under any circumstances. It > works fine with floating, though. > Is this expected

Re: pf.conf "reply-to" routing parameter seemingly not working?

2018-05-12 Thread Joseph Crivello
I cannot get reply-to working with if-bound under any circumstances. It works fine with floating, though. Is this expected behavior? The (similar) route-to option works fine with if-bound rules, and I cannot find any documentation that states reply-to cannot be used with if-bound rules. Assuming

Re: Booting Live openbsd image on fat32 media

2015-09-21 Thread Joseph Crivello
Actually Windows won't allow you to create more than one partition on a USB device only if it has the "removable disk" flag set. Some USB mass storage devices don't have this flag set (from the factory), and if it's not set you can partition it normally. It is also possible to flash many makes

Re: Firewall question: is using a NIC with multiple jacks considered insecure?

2015-07-27 Thread Joseph Crivello
If someone successfully attacks the firmware on any of your network cards, you are screwed no matter what. Any modern network card is going to have the ability to issue DMAs and can easily root your entire system.

Re: Duplicate pf rules when using groupname

2015-04-27 Thread Joseph Crivello
http://www.openbsd.org/faq/pf/macros.html "Lists A list allows the specification of multiple similar criteria within a rule. For example, multiple protocols, port numbers, addresses, etc. So, instead of writing one filter rule for each IP address that needs to be blocked, one rule can be written

Re: Problem With Default Route Over IPSEC Site-To-Site Tunnel VPN

2014-12-16 Thread Joseph Crivello
I was able to resolve my own problem. The solution I found was to create a gre tunnel between the two routers using the gre(4) pseudo-device. Once I had that working, I used IPSEC transport mode to protect the GRE tunnel. This method eliminates all default encap routes from both routers; which was