spamdb never shows any entries ?!?

2007-09-21 Thread Stefan Sczekalla-Waldschmidt
Hi, I tryed to set up spamd on OpenBSD4.1 but after "preloading" the database at /var/db/spamd using: isabsd # /usr/libexec/spamd-setup -d Getting http://www.openbsd.org/spamd/nixspam.gz blacklist nixspam 39960 entries whitelist override 40138 entries Getting http://www.openbsd.org/spamd/chinac

Re: VPN/IPSEC trouble with Checkpoint

2007-01-12 Thread Stefan Sczekalla-Waldschmidt
Hi, Once we had a lot of trouble with checkpoint too. While to one company ( also using a chekpoint ) every thing works fine, a vpn to a other company using checkpoint gave a lot trouble. we used "rather standard" 3des-md5 to both directions. One problem was located on the checkpoint side - t

How to disable NAT-T advertisement ?

2006-09-25 Thread Stefan Sczekalla-Waldschmidt
Hi, Can I prevent OpenBSD from advertising its NAT-T Capability or prevent to negociate it ? Kind regards, Stefan

Interface Alias Trouble.

2006-09-14 Thread Stefan Sczekalla-Waldschmidt
Hi, I have a interface on my default gateway defined as follows: hostname.dc1: inet 192.168.110.254 255.255.255.0 192.168.110.255 inet alias 172.22.125.243 255.255.255.240 172.22.125.255 192.168.110.254 is default gw-address in my network. pinging to somewhere ( how to get there is known by the

question about nat and pf behaviour ...

2006-09-13 Thread Stefan Sczekalla-Waldschmidt
Hi, I have a Router/Gateway with: dc1: flags=8843 mtu 1500 address: 00:80:c8:c9:88:95 media: Ethernet autoselect (100baseTX full-duplex) status: active inet6 fe80::280:c8ff:fec9:8895%dc1 prefixlen 64 scopeid 0x2 inet 192.168.110.254 netmask 0xff00 broad

question about nat.

2006-08-30 Thread Stefan Sczekalla-Waldschmidt
Hi, I had a subnet 192.168.110.0 to subnet 10.11.12.0 IPSEC Tunnel running fine. Now the owner of the remote end of the vpn-tunnel asks if I can change vpn-config and do Nat to 172.3.4.0 because he has some trouble routing packets from my 192.168.110.0 network. I don't hav any problems to chang

Is it possible to compile and run ntop 3.2 successful on OpenBSD 3.8 / 3.9

2006-05-26 Thread Stefan Sczekalla-Waldschmidt
Hi, caused by the lack of an available test-computer for trying this my own right now - has somone already made any experiences in getting ntop 3.x running on System with OpenBSD 3.8 or 3.9 installed ? Kind reagrds, Stefan

I need some help on frequently failing ipsec tunnel.

2006-03-31 Thread Stefan Sczekalla-Waldschmidt
-level Options should I set to get a better glue what ist happening ? All other Ideas/suggestions are welcome ! Kind regards, Stefan Sczekalla-Waldschmidt

weird vpn dropouts ...

2006-03-02 Thread Stefan Sczekalla-Waldschmidt
Hi, I'm facing a problem where a vpn-tunnel fails for 1 to approx. 3 Secs. every few minuntes. we have - well quite successful established a ipsec-vpn-mesh with Carp-failover across our four locations. While the connection between three members of the mesh runs fine - we have a problem with our

pf w/ squid reroute traffic howto ?

2005-10-19 Thread Stefan Sczekalla-Waldschmidt
Hi, i'm facing a problem where I need to reroute requests made by a squid-cache. I already tried to add a route-to statement to my pf.conf: pass out on ep2 route-to ep0:192.168.110.241 from any to any port 80 flags S/SA keep state ( where ep2 is the "external" interface, ep0 is t

carp-sasync-isakmpd failover problem...

2005-10-10 Thread Stefan Sczekalla-Waldschmidt
Hi, we have an failover-test-setup looking like below: +CARP0-HOST(M)-CARP1--(WAN) | (WAN)RemoteHost---RemotLAN +CARP0-HOST(B)-CARP1--(WAN) | | LocalLAN ipsec(isakmpd) is setup to build a vpn between LocalLAN and RemoteLAN

question on the behavior of pfsync and interaction with pf...

2005-10-07 Thread Stefan Sczekalla-Waldschmidt
uld I check this using a connection which would "fail" in case pfsync is not working ? Kind regards, Stefan Sczekalla-Waldschmidt

I've a question about sasync ...

2005-08-09 Thread Stefan Sczekalla-Waldschmidt
Hi, we are going to deploy a new firewall which will relay on carp, pfsync and will use ipsec for networking between our branch-offices. for failover functionality - I'd like to use "sasync" too, but I'm somewhat confused - do I have to wait for 3.8 for this feature or if I can use the 3.7 Stable

Re: raid for boot/root disk ?

2005-08-04 Thread Stefan Sczekalla-Waldschmidt
> > Would a hardware el-cheapo raid-controller be of any help in a way > > that the joe-user standard setup procedure will work ? > > If your mobo supports booting from the controller that would > probably be the easies way, just create the array and install > onto it just as if it had been a n

raid for boot/root disk ?

2005-08-02 Thread Stefan Sczekalla-Waldschmidt
Hi, I've googled a lot about how I simply could mirror the boot disk of my OpenBSD based routers. The intention is not to have the harddisk as a single point of failure. I've seen a rather interesting documentation on how to do this using raidframe at: http://wiki.abstrakt.ch/bin/view/HOWTOs/Ope

need Idea on howto do a kind of "policy based" routing w/ OpenBSD

2005-06-29 Thread Stefan Sczekalla-Waldschmidt
Hi, we are going to have a router with two WAN interfaces - one WAN interface should be used primarily for our company-to-branch vpn wheras the other WAN interface ( which is a "el-cheapo" DSL ) should be used for WEB-traffic. I like to set up routing in such way that if one "WAN-Line" fails the