Re: pgt firmware ...

2012-02-27 Thread Wesley M.
pkg_db: $!"); >>> >>> Somethings wrong with my environment but what ... >>> >>> On 27/02/2012, Peter Hessler wrote: >>>> NO! >>>> >>>> For the love of everything holy, don't fucking use wget. >>>> >>>

Re: pgt firmware ...

2012-02-26 Thread Wesley M.
rk and then fw_update reports there are no devices to > update - the conexant card is no longer attached. > :] > > If you can think of a way to run this locally it'd be great. > > On 26/02/2012, Wesley M. wrote: >> try fw_update (provided in OpenBSD 5.0) >

Re: pgt firmware ...

2012-02-26 Thread Wesley M.
try fw_update (provided in OpenBSD 5.0) Wesley. On Sun, 26 Feb 2012 17:51:03 +1030, David Walker wrote: > Hi. > > I'm trying to do: > pkg_add http://firmware.openbsd.olg/firmware/pgt-firmware-1.2.tgz > > I get this: > parsing pgt-firmware-1.2.tgz > Bad pkg_db: No such file or directory at > /u

Re: SSH Mastery -- New book by Michal Lucas!

2012-02-17 Thread Wesley M.
Hi, I ordered a copy too ;-) Wesley. On Fri, 17 Feb 2012 17:27:49 -0700 (MST), Austin Hook wrote: > Here's the entry I just finished adding to OpenBSD's books.html page > > > SSH Mastery > by Michael Lucas > ISBN-13: 978-1470069711 > ISBN-10: 1470069717 > February 2012, 14

Re: Re : vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Wesley M.
t; Router <- Internet -> RemoteFW <- LAN 2 -> SomeDevice > My PC is > connected to a LAN1 switch, and it's able to ssh SomeDevice. As you can > see my > OpenBSD has just one interface and the VPN is mounted between OpenBSD and > RemoteFW. > > > > - Mai

Re: vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Wesley M.
for > that one IP address: > ike esp from 172.17.2.21/32 to 192.168.0.0/24 peer ip_fwA ... > > Then tell the FTP server to listen on the IP of the lo2 interface > (172.17.2.21?) > > > /m > > On 02/13/12 14:43, Wesley M. wrote: >> o;?Hi, >> >>

vpn isakmpd ipsec, one side with only one interface

2012-02-13 Thread Wesley M.
o;?Hi, I was using ipsec vpn between 2 OpenBSD Gateway. It worked very well. Here : ---rl0---[fwA]---rl1(internet)-sis1---[fwB with ftpd]---sis0--- Now we remove ftp services from fwB and put it on an other machine fwC with an internet connection (only one network card). is i

Re: The use of DUID

2012-01-30 Thread Wesley M.
Thank you for your explanation. I understand better. On Mon, 30 Jan 2012 12:05:58 -0500, Nick Holland wrote: > On 01/30/2012 11:10 AM, Wesley M. wrote: >> Hi, >> >> I have a question, i read faq "14 - Disk Setup (DiskLabel Unique >> Identifiers) ". &g

The use of DUID

2012-01-30 Thread Wesley M.
Hi, I have a question, i read faq "14 - Disk Setup (DiskLabel Unique Identifiers) ". It is a pretty feature. We can start OpenBSD OS from the disk put anywhere(order). But what's about after a dump/restore Boot in single user : backup the disk using 'dump -0af /mnt/root.dump /dev/wd0a' ... Whe

error keyboad

2012-01-27 Thread Wesley M.
Hi, I have a problem with my keyboard. I use OpenBSD 5.0 with Bind Patch, acpi is disabled in the kernel (because it hangs on Mtrr pentium...) When i was in the OpenBSD install script, i was able to have this "^" working. But now, at i can't do this "^", there's a bip when i try to have it. Any

Re: strange localhost address

2012-01-21 Thread Wesley M.
On Sat, 21 Jan 2012 11:46:00 +0400, "Wesley M." wrote: > sorry, it was a stupid error. > My hostname, there was an error in the name !! > > Again sorry. > > On Sat, 21 Jan 2012 11:40:32 +0400, "Wesley M." > wrote: >> Hi, >> I don't

Re: strange localhost address

2012-01-21 Thread Wesley M.
see http://www.openbsd.org/errata50.html On Sat, 21 Jan 2012 09:01:35 +0100, Jan Stary wrote: > On Jan 21 11:40:32, Wesley M. wrote: >> When i ping localhost it give me : 208.73.210.29 instead of 127.0.0.1 ! >> Where does it come from ? I don't understand. >> I use O

strange localhost address

2012-01-20 Thread Wesley M.
Hi, I don't know where it comes from. I just configured my iwi card using : iwi-firmware-3.1p1.tgz I can connect to my network, internet works. Therefore, i find a strange error : When i ping localhost it give me : 208.73.210.29 instead of 127.0.0.1 ! Where does it come from ? I don't understand.

use trap command in a script

2012-01-19 Thread Wesley M.
Hi, I want to see a message on console when i send signal like HUP KILL INT and TERM using for example in a script "manageprocess": #!/bin/ksh trap 'echo Kill detected!' 9 trap 'ctrl-c detected!' 2 run it with sudo sh manageprocess No message appear Therefore if i run manually this : trap

Re: could not read firmware iwi-bss

2012-01-18 Thread Wesley M.
You re very funny!! Now it works like a charm, thank for your replies, i downloaded the iwi-firmare. And wiconfig is pretty cool !!! Thank you a lot ! On Wed, 18 Jan 2012 07:17:00 -0500, Richard Thornton wrote: why not use gnu/linux instead On Wed, Jan 18, 2012 at 6:18 AM, Wesley M

could not read firmware iwi-bss

2012-01-18 Thread Wesley M.
I use OpenBSD 5.0 RELEASE on a notebook : twinhead F12DT There was a problem at startup, it hangs on MTRR pentium message. So i disabled acpi using config -ef /bsd Now i can boot. I'm trying to configure iwi0 interface. Wifi card : Intel PRO/Wireless 2200BG When i try ifconfig iwi0 : iwi0: flag

Re: mailserv project

2012-01-15 Thread Wesley M.
On Mon, 16 Jan 2012 07:40:57 +0100, Tomas Bodzar wrote: > There's sendmail in base system and there's ongoing work on smtpd by > OpenBDS devs (other components are in ports). Anyway you're welcome to > start port see http://www.openbsd.org/faq/ports/index.html > It is not an other MTA. It is a s

mailserv project

2012-01-15 Thread Wesley M.
Hi, It will be famous if somebody can update mailserv project to work on the last version OpenBSD 5.0 Therefore it works like a charm on OpenBSD 4.8/4.9 Here the source : https://github.com/mailserv/mailserv/ Best regards, Wesley.

Re: PF Snort tutorial

2012-01-04 Thread Wesley M.
Also, an idea, add scanlogd package, and do a small script to add ip in log to your pf table ;-) Cheers, Wesley MOUEDINE ASSABY http://mouedine.net/ruleset50.aspx On Tue, 3 Jan 2012 17:56:13 -0500, "Bentley, Dain" wrote: > ughthat's what I thought. > I'm reading through some OSSEC docs righ

Re: PF Snort tutorial

2012-01-04 Thread Wesley M.
Hi, Perhaps, this can be helpful ;-) http://www.procyonlabs.com/guides/openbsd/snort/ Cheers, Wesley MOUEDINE ASSABY http://mouedine.net/ruleset50.aspx On Tue, 3 Jan 2012 17:56:13 -0500, "Bentley, Dain" wrote: > ughthat's what I thought. > I'm reading through some OSSEC docs right now and

Re: create a backup of an online server

2011-12-28 Thread Wesley M.
In fact, -1- i want to copy the mail server system to another machine. I suppose rsnaphot or a dump/restore in single user? is a good choice... -2- And keep emails synchronized between the 2 mail server using rsync, this step is ok. Thank you very much for all your replies. Cheers, Wesley. O

create a backup of an online server

2011-12-27 Thread Wesley M.
Hi, I want to backup our mailserver(4.7) in production. I read : http://www.openbsd.org/faq/faq10.html#DupFS Can i do this wd1(my backup disk) : mount /dev/wd1a /mnt dump -0auf /mnt/etc_backup /dev/wd0a ... same for wd0d and wd0e ... Or do i need absolutely to do it in Single User? Or perhaps,

Re: kernel panic (mii_phy_setmedia) on mac mini A1347 (bge device unknown)

2011-12-23 Thread Wesley M.
Thank you very much. It works, i can now use bge0 on the mac mini. (OpenBSD 4.9) Wesley.

Re: kernel panic (mii_phy_setmedia) on mac mini A1347 (bge device unknown)

2011-12-23 Thread Wesley M.
thank's, small forget ;-) I will try it . On Fri, 23 Dec 2011 11:51:33 +0100, Mike Belopuhov wrote: > On Fri, Dec 23, 2011 at 11:43 AM, Wesley M. wrote: >> Hi, >> >> So i installed a fresh OpenBSD 4.9 to try to patch the files : brgphy.c >> and miidevs &g

Re: trendnet ethernet usb

2011-12-22 Thread Wesley M.
ture=8 sd0 detached scsibus1 detached umass0 detached umass0 at uhub5 port 2 configuration 1 interface 0 "JetFlash Mass Storage Device" rev 2.00/1.00 addr 4 umass0: using SCSI over Bulk-Only scsibus1 at umass0: 2 targets, initiator 0 sd0 at scsibus1 targ 1 lun 0: SCSI2 0/direct removable sd

Re: trendnet ethernet usb

2011-12-21 Thread Wesley M.
i read man page axe(4) there's no my model trendnet TU2-ETG :( So i suppose that it is not compatible :( Wesley. On Wed, 21 Dec 2011 16:10:35 +0400, "Wesley M." wrote: > tried on OpenBSD 5.0 : same problem > ifconfig show : > media : Ethernet none (none) > > On W

Re: trendnet ethernet usb

2011-12-21 Thread Wesley M.
tried on OpenBSD 5.0 : same problem ifconfig show : media : Ethernet none (none) On Wed, 21 Dec 2011 16:04:36 +0400, "Wesley M." wrote: > I plug on my OpenBSD 4.9 (fresh install) :Ethernet USB Device, trendnet > TU2-ETG > It detects axe0, i configured it using dhcp, it doesn&#

trendnet ethernet usb

2011-12-21 Thread Wesley M.
I plug on my OpenBSD 4.9 (fresh install) :Ethernet USB Device, trendnet TU2-ETG It detects axe0, i configured it using dhcp, it doesn't work. Manually also doesn't work. Pf disabled, no traffic out any issue ? Here dmesg | grep axe0 : axe0 at uhub5 port 2 configuration 1 interface 0 "ASIX Ele

newfs, fsck slow

2011-12-21 Thread Wesley M.
Hi, When i do a newfs on HD 500Go , it takes much more times using OpenBSD 4.9 instead of 5.0 RELEASE. Same problem using fsck -y dev. Why ? Machine : mac mini model : A1347 Thank you very much for your replies. Cheers, Wesley.

Re: kernel panic (mii_phy_setmedia) on mac mini A1347 with trace and ps picture url

2011-12-19 Thread Wesley M.
21:20 +, Stuart Henderson wrote: > It's committed so wait for new snaps and you can avoid this step. > > > On 2011/12/19 17:10, Wesley M. wrote: >> Hi Stuart, >> >> I tried this : boot -c at boot prompt (startup) >> I have this message : "kbc c

Re: kernel panic (mii_phy_setmedia) on mac mini A1347 with trace and ps picture url

2011-12-19 Thread Wesley M.
Hi Stuart, I tried this : boot -c at boot prompt (startup) I have this message : "kbc cmd word write error" just after. And i can't use keyboard at UKC Prompt :( Wesley. On Mon, 19 Dec 2011 12:51:58 +, Stuart Henderson wrote: > On 2011/12/19 16:10, Wesley M. wrote: >&

Re: kernel panic (mii_phy_setmedia) on mac mini A1347 with trace and ps picture url

2011-12-19 Thread Wesley M.
On Mon, 19 Dec 2011 10:33:56 -0200, Daniel Bolgheroni wrote: > On Mon, Dec 19, 2011 at 04:10:16PM +0400, Wesley M. wrote: >> >> Here is the ps message : http://i43.tinypic.com/mkufyo.jpg >> Here is the >> trace message : http://i40.tinypic.com/25syfxf.jpg > > H

kernel panic (mii_phy_setmedia) on mac mini A1347 with trace and ps picture url

2011-12-19 Thread Wesley M.
Hi, I tried to install OpenBSD 4.9 on an Apple mac mini (new generation). Model : A1347 ; Core i5, thunderbolt Technology, HD 500Go At installation using 4.9 RELEASE : It takes a long time to format slides. At the reboot : i have a kernel panic just after "starting network" So i tried to use

kernel panic (mii_phy_setmedia) on mac mini A1347

2011-12-19 Thread Wesley M.
Hi, I tried to install OpenBSD 4.9 on an Apple mac mini (new generation). Model : A1347 Core i5, thunderbolt Technology, HD 500Go At installation using 4.9 RELEASE : It takes a long time to format slides. At the reboot : i have a kernel panic just after "starting network" So i tried to use 5

Re: roundcubemail on openbsd 5.0

2011-12-15 Thread Wesley M.
ser@domain user userx@domainx userx Thank you for your replies and your help. Wesley M. PS : OpenBSD 5.0 / rouncubemail package 0.5.3p1 Original Message Subject: Re: roundcubemail on openbsd 5.0 Date: Wed, 14 Dec 2011 21:35:49 + From: Stuart Henderson To: "Wesle

Re: roundcubemail on openbsd 5.0

2011-12-14 Thread Wesley M.
ould probably open up the database > manually and change the records directly. > > Regards. > > On 14/12/2011 > 06:33, Wesley M. wrote: > >> Hi, >> >> I use sendmail 8.14.15 with > virtusertable and procmail for multiple >> domains and >> doveco

Re: roundcubemail on openbsd 5.0

2011-12-13 Thread Wesley M.
Hi, I use sendmail 8.14.15 with virtusertable and procmail for multiple domains and dovecot 2.0; and Apache (chrooted in /var/www) MAILDIR : /var/mailserver/%u/ IMAP/POP3/IMAPS/POP3S works. I just want : At the Roundcube login page, type user1@domain1 and send emails from this email :user1@domai

Re: roundcubemail on openbsd 5.0

2011-12-12 Thread Wesley M.
I tried this : cp /etc/mail/virtusertable /var/www/roundcubemail/ And changed in /var/www/roundcubemail/main.inc.php this line to $rcmail_config['virtuser_file'] = '/roundcubemail/virtusertable'; Add a new user. Try it, only works with his username, and when i try to send emails, it comes from us

roundcubemail on openbsd 5.0

2011-12-12 Thread Wesley M.
Hi, I use sendmail with procmail(for maildir) and dovecot on OpenBSD 5.0 And a virtusertable /etc/mail/virtusertable for multiple domains. All works fine, i can send and receive emails. When i use roundcube, if i type a username, try to send an email, it is from username@localhost So, i modified

Re: maildir in sendmail

2011-12-08 Thread Wesley M.
en't you? It comes with its own delivery > agent, which can be fed over LMTP, and supports maildir/mbox/mdbox etc > using the same choice of directory layout as dovecot pop3/imap daemons. > > > On 2011-12-08, Wesley M. wrote: >> I noticed that sendmail use by default mbox

maildir in sendmail

2011-12-08 Thread Wesley M.
I noticed that sendmail use by default mbox : /var/mail/%u Is there a easy way to have maildir ? without procmail feature ? Or there's no other way except using procmail ? I don't want to use procmail, because, i will need a second large slide /home. I just want that all emails are in /var/mail/%

USB to ethernet adapter

2011-12-07 Thread Wesley M.
Hi, I'm going to build a small firewall with proxy cache for web. Using an Apple Mac mini. For the second ethernet, i will use : - Trendnet TU2-ETG OR Apple MC704ZM. What is better ? using trendnet or Apple Adapter ? And is it enough stable to use a USB Adapter ? Thank you very much for your an

Re: roundcubemail packet

2011-12-05 Thread Wesley M.
Hi, First, thank you for your email. I use it at work, a purchased version(75$) (allard mail server) : v4.7.6 I want to build my own mail server with sendmail, because, mailserv doesn't work on OpenBSD 5.0, for example : there's no dovecot-sieve ; dovecot 2 is a big update; and especially install

Re: roundcubemail packet

2011-12-05 Thread Wesley M.
dovecot: imap(wesley): Disconnected: Logged out bytes=29/399 On Mon, 5 Dec 2011 14:10:03 +0200, Gregory Edigarov wrote: > On Mon, 05 Dec 2011 15:47:23 +0400 > "Wesley M." wrote: > >> in my /etc/dovecot/dovecot.conf >> i added this line : >> mail_location = mbox

Re: roundcubemail packet

2011-12-05 Thread Wesley M.
, 2011 at 11:56 AM, Wesley M. wrote: >> Hi, >> >> Thank you for your reply. >> Already done. But still doesn't work. >> I have "connection error on imap server" >> >> I have 3 users created, with 3 2 domains hosted. >> 993, 143 dovecot po

Re: roundcubemail packet

2011-12-05 Thread Wesley M.
,smtps} So my configuration : OpenBSD 5.0 dovecot-2.0.13p5 roundcubemail-0.5.3p1 sendmail mysql-server php On Mon, 5 Dec 2011 13:18:02 +0200, Gregory Edigarov wrote: > On Mon, 05 Dec 2011 14:56:20 +0400 > "Wesley M." wrote: > >> Hi, >> >> Thank you

Re: roundcubemail packet

2011-12-05 Thread Wesley M.
on, 05 Dec 2011 12:38:46 +0400 > "Wesley M." wrote: > >> Thank you very much. It works. >> >> Except i can't connect to my imap server. :-( >> I use dovecot. Ports are opened. >> ?? >> > again,search your roundcube config fil

Re: roundcubemail packet

2011-12-05 Thread Wesley M.
Thank you very much. It works. Except i can't connect to my imap server. :-( I use dovecot. Ports are opened. ?? On Mon, 05 Dec 2011 21:15:08 +1300, Richard Toohey wrote: > On 5/12/2011, at 9:03 PM, Wesley M. wrote: > >> Hi, >> >> I have the following error :

roundcubemail packet

2011-12-05 Thread Wesley M.
Hi, I have the following error : Check DB config DSN (write): NOT OK(MDB2 Error: connect failed) Make sure that the configured database exists and that the user has write privileges DSN: mysql://roundcube:pass@localhost/roundcubemail Using http://mailserver_ip/roundcubemail/installer/ I have a

Re: sendmail(failed)

2011-12-01 Thread Wesley M.
> Change in startup procedure for Postfix and exim: The base OS has moved > to using scripts in /etc/rc.d to start all daemons. The script for > sendmail does not function fully for alternative MTAs (in particular it > will display "failed" at startup, although the daemon will still be > starte

sendmail(failed)

2011-12-01 Thread Wesley M.
Hi I upgraded my mailserver to OpenBSD 5.0 Now at startup i have : Starting Network Daemons : sshd sendmail(failed) inetd failed ? why ? Normal ? And in rc.local we have a script that execute postfix with the option set-permissions If i do : netstat -anf inet ; i can see that the box listen well

Re: original sendmail.cf, mc ?

2011-11-24 Thread Wesley M.
Thank you very much for your help ! Now all works fine. I just configured the smart host my mc file. On Thu, 24 Nov 2011 10:12:17 +0100, Antoine Jacoutot wrote: > On Thu, Nov 24, 2011 at 09:54:17AM +0100, Paul de Weerd wrote: >> Looking more closely at how I set this up, hostname.mc is actually

original sendmail.cf, mc ?

2011-11-24 Thread Wesley M.
Hi, I use OpenBSD 5.0 I know the *.mc files are in : /usr/share/sendmail/cf/ And sendmail.cf file is in /etc/mail, but it comes from which mc file ? I just want to modify the origin mc file to allow me to send email from a real domain instead of his hostname. Or perhaps, there an easiest way to

Re: What is wrong with this pf config

2011-11-21 Thread Wesley M.
Hi, Please read again : http://www.openbsd.org/faq/pf/example1.html Or you can take a look here : http://mouedine.net/ruleset5.aspx Cheers, Wesley On Mon, 21 Nov 2011 19:15:06 +1100, John Tate wrote: > I am having troubles with this pf configuration, it seems when loaded > nothing can access m

opensmtpd

2011-11-17 Thread Wesley M.
Hi, I seen http://www.opensmtpd.org Does exist a "stable" version ? can we put it on production ? And what's about your handbook : https://www.poolp.org/OpenSMTPD/ Possible to have this hanbook in french ? Thank you very much for replies. All the best, Wesley M.

optimize adsl bandwidth

2011-11-09 Thread Wesley M.
Hi, I use OpenBSD 5.0, what is better between use "prio" or altq on em0 priq bandwidth 200Kb queue {q_def,q_pri}" ? I explain : altq on em0 priq bandwidth 200Kb queue {q_def,q_pri} queue q_def priority 1 queue q_pri priority 7 priq(default) ... pass out on egress inet proto tcp queue(q_def,q_pri

Re: jeu de règles PF/ PF Ruleset - OpenBSD 5.0

2011-11-04 Thread Wesley M.
Je prends note ;-) Merci. On Fri, 4 Nov 2011 19:37:46 +0100, "hvom .org" wrote: > Le 4 novembre 2011 19:14, Wesley M. a C)crit : >> Hi, >> >> See here : >> >> http://mouedine.net/ruleset5.aspx >> >> (with divert/tag use) >> >

jeu de règles PF/ PF Ruleset - OpenBSD 5.0

2011-11-04 Thread Wesley M.
Hi, See here : http://mouedine.net/ruleset5.aspx (with divert/tag use) All the best, Wesley MOUEDINE ASSABY

post-Altq

2011-11-03 Thread Wesley M.
Hi, What's about the post-Altq ? See here : http://bsdly.blogspot.com/2011/07/anticipating-post-altq-world.html Does someone have any news about that? Cheers, Wesley.

Full ruleset Packet filter OpenBSD 5.0

2011-11-03 Thread Wesley M.
Hi, See here : http://mouedine.net/ruleset49.aspx (with divert/tag use) All the best, Wesley MOUEDINE ASSABY

Re: limit ftp download

2011-11-03 Thread Wesley M.
I tried this : added a second ftpproxy_flags in my /etc/rc.conf.local So in the file, we have : ftpproxy_flags="-q ilimit" # Listen by default on 8021 ftpproxy_flags="-q istd" # It doesn't work, it use the last line in /etc/rc.conf.local : istd queue I suppose that it doesn't listen on the same

Re: Packet Tagging issues with NAT in pf OBSD 4.9

2011-11-03 Thread Wesley M.
Hi, try this sample _int = "re0" _ext = "fxp1" int_net = "192.168.200.0/24" set block-policy drop set skip on lo match in all scrub (no-df max-mss 1440) match out on $_ext inet from $int_net to any nat-to (egress) block log all pass in on $_int inet proto udp from $int_net to any port domain pass

Re: limit ftp download

2011-11-03 Thread Wesley M.
Ko/s ? Thank you very much for your help. Wesley. On Thu, 03 Nov 2011 07:04:04 +0100, Camiel Dobbelaar wrote: > On 3-11-2011 6:07, Wesley M. wrote: >> I suppose it is because traffic are redirect to 127.0.0.1 (ftpproxy) >> >> sample of my pf.conf: >> ... >&

limit ftp download

2011-11-02 Thread Wesley M.
Hi, I'm using OpenBSD 5.0 I'm testing traffic shapping using altq. I can limit a user (his Ip address) to a 160Kb/s, it works great. But when this user try to download a file using ftp, he downloads it at 1024Kb/s. I suppose it is because traffic are redirect to 127.0.0.1 (ftpproxy) sample o

Re: NIDS on OpenBSD

2011-10-19 Thread Wesley M.
is a good firewall, we can play with QoS/IP,Ports filter/NAT/ Src NAT/ Statefull/Load Balancing/scrub But it is not a NIDS. ;-) All the best, Wesley M. On Wed, 19 Oct 2011 10:05:33 +0300, Gregory Edigarov wrote: > I think it is bad practice to use something that's not even in the >

Re: NIDS on OpenBSD

2011-10-18 Thread Wesley M.
eb monitor to view alerts provided by scanlogd. Any idea ? cheers, Wesley. On Wed, 19 Oct 2011 09:31:35 +0400, "Wesley M." wrote: > Hi, > > I use OpenBSD 4.9, i'm looking for a good nids. > > I found > "scanlogd" in ports, works very well. >

NIDS on OpenBSD

2011-10-18 Thread Wesley M.
Hi, I use OpenBSD 4.9, i'm looking for a good nids. I found "scanlogd" in ports, works very well. But is there a way to work this last one with pf ? For example add the ip-address detected by scanlogd to a "Blacklist" table ? Also, is there a way to have a web monitor to view alert? Perha

Re: Help setting up a PF NAT gateway

2011-10-10 Thread Wesley M.
Hi, see my sample, it is well explained. http://mouedine.net/ruleset49.aspx All the best, Wesley MOUEDINE ASSABY www.mouedine.net On Mon, 10 Oct 2011 17:38:26 +0200, Stefan Midjich wrote: > Simplest of things but I'm failing miserably. > > $ sudo cat /etc/hostname.vic2 # External NIC with st

Re: problem routing

2011-09-29 Thread Wesley M.
INTERNETsis1sis2---(server,ISP_ROUTER,workstations) sis2:10.100.1.250 ISP_ROUTER:10.100.1.254 server:10.100.1.150 , gateway : 10.100.1.254 worskstations 10.100.1.0/24 , gateway : 10.100.1.250 I already tried isakmpd ikev1 vpn : ping 10.100.1.250 ok ssh ok can't ping 10.100.1.150, rdp doesn't

Re: routing problem

2011-09-28 Thread Wesley M.
On Wed, 28 Sep 2011 15:42:05 +0400, pavel pocheptsov wrote: > 28 QP5P=QQP1QQ 2011, 15:28 P>Q "Wesley M." : >> The VPN is between a fictif ip address(gives by the_green_bow) to >> 10.100.1.0/24 >> >> Using VPN, i can ping 10.100.1.250 and use also ssh

Re: routing problem

2011-09-28 Thread Wesley M.
main auth hmac-sha1 enc aes-256 group modp1024 \ quick auth hmac-sha1 enc aes-256 psk demokey On Wed, 28 Sep 2011 15:05:52 +0400, pavel pocheptsov wrote: > what settings on client/home side? > B ipconfig /all, route print..etc > > > 28 QP5P=QQP1QQ 2011,

Re: routing problem

2011-09-28 Thread Wesley M.
On Wed, 28 Sep 2011 06:49:59 -0400, Nick Holland wrote: > On 09/28/11 03:13, Wesley M. wrote: >> Hi, >> >> I have at work: >> TS Server : 10.100.1.100 his gateway is 10.100.1.254 (router for private >> network) > > bzzt. Bad. > (I'm guessing th

routing problem

2011-09-28 Thread Wesley M.
Hi, I have at work: TS Server : 10.100.1.100 his gateway is 10.100.1.254 (router for private network) Firewall : 10.100.1.250 (OpenBSD 4.9, ADSL : sis0, Lan (10.100.1.0/24) :sis2 On the firewall, i can ping 10.100.1.100 and telnet 10.100.1.100 3389 -> OK When i am at home, i connect to firewa

configure lan ports and wifi like a switch

2011-09-26 Thread Wesley M.
Hi, I use an appliance with OpenBSD 4.9, there are 3 network ports(sis0-2), and a wifi port (ral0) sis0 : egress (internet) sis1, sis2, ral0 : lan i configure a hostname.trunk0 : trunkport sis2 trunkport sis1 trunkport ral0 trunkproto loadbalance inet 10.100.1.50 255.255.255.0 hostname.sis1, ho

Re: IPsec+rdomain

2011-09-14 Thread Wesley M.
Hi, I already had the same problem. You need to use a Ipsec VPN and NAT. See here : http://www.undeadly.org/cgi?action=article&sid=20090127205841 Becare with your pf.conf syntax * many changes on recent OpenBSD Release. Cheers, Wesley MOUEDINE ASSABY www.mouedine.net On Wed, 14 Sep 2011 22:15

Re: Starting popa3d ...

2011-09-12 Thread Wesley M.
Hi, See the file /etc/inetd.conf cheers, Wesley MOUEDINE ASSABY On Tue, 13 Sep 2011 12:19:21 +0930, David Walker wrote: > Hi. > > uname -rsv > OpenBSD 5.0 GENERIC#39 > > I'm gearing up to use popa3d and testing it on a machine. > > I tried the following in rc.conf.local (where V is version

Re: Why aren't you running -current?

2011-09-07 Thread Wesley M.
Hi, Need to cvs update and rebuild, so take time. And configuration file can change. Cheers, Wesley. >> i'm sorry :( > > don't be sorry, just tell me why, i am just curious.

vpn ike1 ok, but can't access workstation

2011-09-07 Thread Wesley M.
Hi, I have a win7 with dynamic ip address connected using "green Bow VPN". [road warrior]>[OpenBSD]>>>[192.168.0.0/24] The tunnel is opened. I can ping the OpenBSD(4.9) gateway(192.168.0.249), but no workstations in the lan. I try : "tcpdump -nettti pflog0" report me nothing. I try :

ikev2

2011-09-05 Thread Wesley M.
Hi, sorry to post again this. Is there someone who have already tried a vpn using ikev2 with EAP-MSCHAP-V2 support ? Thank you very much. Cheers, Wesley.M

Re: vpn with a win7 workstation

2011-08-31 Thread Wesley M.
Ok, thank you a lot for your replay. Have you ever try to use ikev2 ? using iked and so win7 have ikev2 support. I tried to use it (iked) but no success... :( If you can take a eye on it. Cheers, Wesley M. On Wed, 31 Aug 2011 19:07:49 +0800, Zak Elep wrote: > On Wed, Aug 31, 2011 at 6:30

vpn with a win7 workstation

2011-08-31 Thread Wesley M.
Hi What is the best way to build a vpn between an OpenBSD 4.9 gateway and a Win7 workstation ? Thank you very much for your advices. All the best, Wesley M.

Re: ftpd server

2011-08-31 Thread Wesley M.
Hi, You will find your solution here : http://www.openbsd.org/faq/pf/ftp.html Best regards, Wesley MOUEDINE ASSABY http://mouedine.net/ruleset49.aspx On Tue, 30 Aug 2011 23:38:41 -0700, fqui nonez wrote: > Hello > > I have a ftpd server box, OBSD-4.9, and pflog shows: > > Aug 29 10:11:03.5

iked

2011-08-30 Thread Wesley M.
Hi, Is there someone already use iked to build a vpn with a win7 ? ... And of course an OpenBSD gateway. Thank you very much for your help and reply. All the best, Wesley. PS : I already read man pages iked; ikectl and iked.conf