Re: Anonym.OS - OpenBSD-based live CD

2006-01-19 Thread NetNeanderthal
On 1/19/06, Scott Francis <[EMAIL PROTECTED]> wrote: > Surprisingly, nobody else has mentioned this on-list yet (perhaps > because it's been all over the news elsewhere): > http://news.google.com/news?hl=en&ned=us&q=anonym.os&btnG=Search+News It was reported on undeadly.org. > I'm not in the leas

Re: How can i send syslogd message to a OPENBSD server ?

2006-01-19 Thread Justin Krejci
On Thursday 19 January 2006 01:37 am, Michael Bibby wrote: > hello ,[EMAIL PROTECTED] > > I have a Linux(SUSE ENTERPRISE LINUX 9) system ,and i want to send all > syslogd messages > to another system which runs OpenBSD 3.8 release . How can i do with > OpenBSD ? > > well ,i know how to configure it

Re: 3.8/64 bits/snmp

2006-01-19 Thread Sylvain Coutant
> I've seen the same on amd64 (OpenBSD 3.7 and 3.8) running net-snmp 5.x. Yep, that's it ;-) > I haven't noticed any issue with interface counters, On our platform, interface counters are sent back using Counter32 while carrying 64 bits values. It works while the counter is less than 4 GB but

Re: Need advice about VPN

2006-01-19 Thread Simon Slaytor
Going to go against the flow here and say go for OpenVPN. This recommendation is based on the following observations: It's easy to implement It's secure It's stable By using the tls-auth option the fact that your firewall is acting as a vpn endpoint becomes invisible to the 'net' It easily han

Re: Need advice about VPN

2006-01-19 Thread Stuart Henderson
On 2006/01/19 09:38, Simon Slaytor wrote: > When comparing the two vpn solutions for speed, subjectively the OpenVPN > feels slightly faster If you're using compression on OpenVPN but not on IPSEC, that would probably explain the speed difference.

Re: Need advice about VPN

2006-01-19 Thread Simon Slaytor
Stuart Henderson wrote: >On 2006/01/19 09:38, Simon Slaytor wrote: > > >>When comparing the two vpn solutions for speed, subjectively the OpenVPN >>feels slightly faster >> >> > >If you're using compression on OpenVPN but not on IPSEC, that would >probably explain the speed difference. > >

Re: Need advice about VPN

2006-01-19 Thread Stuart Henderson
On 2006/01/19 10:39, Simon Slaytor wrote: > Stuart Henderson wrote: > >On 2006/01/19 09:38, Simon Slaytor wrote: > > > >>When comparing the two vpn solutions for speed, subjectively the OpenVPN > >>feels slightly faster > > > >If you're using compression on OpenVPN but not on IPSEC, that would > >

Newsletter della 4� settimana 2006

2006-01-19 Thread Borghi Toscani News
[IMAGE] [IMAGE] Borghi Toscani | E - mail | Registrati | Inserisci un locale | Meteo | News [IMAGE] NUOVI INSERIMENTI Newsletter della 4B0 settimana 2006 LINK CONSIGLIATI Lorenzo il Magnifico LAST MINUTE IN TOSCANA OFFERTE SOGGIORNI IN TOSCANA OFFERTE LAST MINUTE FIRENZE Last Minute Abet

Re: dup-to

2006-01-19 Thread john gotti
On 1/19/06, john gotti <[EMAIL PROTECTED]> wrote: > > hi , i meant where to put RULE with dup-to to not to mess with other , > espessially with RULE using route-to , i would test it mysel but this fw is > quite important , so if anyone using it a i would happy for tips , anyway > manpage no telling

Re: dup-to

2006-01-19 Thread john gotti
hi , i meant where to put RULE with dup-to to not to mess with other , espessially with RULE using route-to , i would test it mysel but this fw is quite important , so if anyone using it a i would happy for tips , anyway manpage no telling how dup-to is interact with rules with route-to , fastrout

Re: dup-to

2006-01-19 Thread john gotti
hi , i meant where to put RULE with dup-to to not to mess with other , espessially with RULE using route-to , i would test it mysel but this fw is quite important , so if anyone using it a i would happy for tips , anyway manpage no telling how dup-to is interact with rules with route-to , fastrout

Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Joakim Roubert
Hi! I have a computer based on this motherboard (more info here: http://www.asrock.com/product/product_775Twins-HDTV.htm), and the OpenBSD 3.8 install CD won't find the disks. The southbridge is an ULi 1573, and since it is not present in the OpenBSD chipset support list, the reason 3.8 won't fin

Re: ntpd is not adjusting time

2006-01-19 Thread Frank Bax
At 12:59 PM 2/11/05, Henning Brauer wrote: * Frank Bax <[EMAIL PROTECTED]> [2005-02-11 18:53]: > At 07:59 AM 2/11/05, Henning Brauer wrote: > >* Frank Bax <[EMAIL PROTECTED]> [2005-02-11 04:08]: > >> ntp engine ready > >> no reply from 192.117.105.69 received in time > >> no reply from 82.69.129

Re: Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Stuart Henderson
On 2006/01/19 14:33, Joakim Roubert wrote: > I have a computer based on this motherboard (more info here: > http://www.asrock.com/product/product_775Twins-HDTV.htm), and the > OpenBSD 3.8 install CD won't find the disks. > > The southbridge is an ULi 1573, and since it is not present in the > Open

Re: Need advice about VPN

2006-01-19 Thread Joachim Schipper
On Thu, Jan 19, 2006 at 11:28:31AM +, Stuart Henderson wrote: > On 2006/01/19 10:39, Simon Slaytor wrote: > > Stuart Henderson wrote: > > >On 2006/01/19 09:38, Simon Slaytor wrote: > > > > > >>When comparing the two vpn solutions for speed, subjectively the OpenVPN > > >>feels slightly faster

Victor

2006-01-19 Thread Victor
Florida Vacation Rental The Colony At Sable TraceNorth Port, FL30 Minutes South of Sarasota FL NEW CONDO 1st floor (1168 SQ/FT Living) Available Feb 1st. The Colony at Sable Trace is a new condominium gated community withinSable Trace Golf Course (semi-private course). This 1st floor unit offers:

Re: Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Joakim Roubert
On 2006-01-19 15:42, Stuart Henderson wrote: > No dmesg, so it's difficult to help you... Even if all you can do is > boot the install kernel, save a dmesg to a file, and ftp it somewhere, > that's a lot better than nothing. I will see if I can fix that. > ULi want an NDA before releasing docume

Generating ICMP Redirects

2006-01-19 Thread Steven S
Greetings, I'm using a pair of 3.8-stable (1/5/06) servers as the firewall and default gw (10.10.0.1/16) for a LAN . VPN users (10.4.0.0/16) come into the LAN from a PIX (10.10.0.254/16) (changing soon to OpenVPN), and when the VPN users hit a server return packets are sent to the default gw. I

Re: Generating ICMP Redirects

2006-01-19 Thread Claudio Jeker
On Thu, Jan 19, 2006 at 10:32:40AM -0500, Steven S wrote: > Greetings, > > I'm using a pair of 3.8-stable (1/5/06) servers as the firewall and default > gw (10.10.0.1/16) for a LAN . VPN users (10.4.0.0/16) come into the LAN > from a PIX (10.10.0.254/16) (changing soon to OpenVPN), and when the V

Re: Generating ICMP Redirects

2006-01-19 Thread Stuart Henderson
On 2006/01/19 10:32, Steven S wrote: > I'm using a pair of 3.8-stable (1/5/06) servers as the firewall and default > gw (10.10.0.1/16) for a LAN . VPN users (10.4.0.0/16) come into the LAN > from a PIX (10.10.0.254/16) (changing soon to OpenVPN), and when the VPN > users hit a server return packet

Re: Generating ICMP Redirects

2006-01-19 Thread Steven S
[EMAIL PROTECTED] wrote: > On Thu, Jan 19, 2006 at 10:32:40AM -0500, Steven S wrote: ... > > What about sysctl net.inet.ip.forwarding? Is it set to 1? > >> wq Claudio Yep. The firewalls are working perfectly aside from this redirect issue. They are even performing ISP load balancing (when the s

Re: Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Joakim Roubert
On 2006-01-19 15:42, Stuart Henderson wrote: > No dmesg, so it's difficult to help you... Ok, here goes: (there might be typos, since I write down what I read on the screen next to me...) = OpenBSD 3.8 (RAMDISK_CD) #794: Sat Sep 10 15:58:32 MDT 2005 [EMAIL PROTECTED]

Via K8T900 - Questions

2006-01-19 Thread Paulo Rodriguez
Dear misc, Not so long ago Via released a new chipset which sounds very promising performance-wise, compared to the Nvidia solutions, the K8T900. I was wondering whether there was already any interest from dev's for this platform. The reason is simple: a dual-boot machine which can handle OpenB

Re: Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Stuart Henderson
On 2006/01/19 17:08, Joakim Roubert wrote: > On 2006-01-19 15:42, Stuart Henderson wrote: > > No dmesg, so it's difficult to help you... > > Ok, here goes: > (there might be typos, since I write down what I read on the screen next > to me...) well done :) I have some similar ALi/ULi devices on a

Re: Need advice about VPN

2006-01-19 Thread NetNeanderthal
On 1/18/06, Hans-Joerg Hoexer <[EMAIL PROTECTED]> wrote: > On Wed, Jan 18, 2006 at 11:20:55AM +0100, Joachim Schipper wrote: > Forget about openvpn, there's no need to fiddle around with third > party stuff. OT: OpenVPN has its purposes, though this particular scenario shouldn't be one of them. On

Re: Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Joakim Roubert
On 2006-01-19 17:43, Stuart Henderson wrote: >>vendor "Acer Labs", unknown product 0x5287 (class mass storage subclass >>SATA, rev 0x02) at pci0 dev 31 function 1 not configured > > Good, it's not hidden behind an unrecognisable pci-pci bridge. Ok, at least that's something! :) > Try looking fo

Fwd: How can i send syslogd message to a OPENBSD server ?

2006-01-19 Thread Michael Bibby
thanks ,it works . ^_^ You will need to start syslog on the openbsd server with the -u option > (see /etc/rc.conf and syslogd man pages) and also make sure you have > pf.conf > allowing port 514 udp from your linux host.

Re: openbsd live cd

2006-01-19 Thread Bihlmaier Andreas
On Wed, Jan 18, 2006 at 11:55:15PM -0800, Jacob Meuser wrote: > On Thu, Jan 19, 2006 at 08:17:15AM +0100, Karl-Ludwig Reinhard wrote: > > hello list, > > > > I'm looking for a openbsd live cd for sys admins, but the only thing > > I've found was the anonym.os. Is there any other live cd based on

Re: openbsd live cd

2006-01-19 Thread Karl-Ludwig Reinhard
mh I don't want to build a live cd myself. I was looking for a ready- built one. may you have misunderstood me. On Jan 19, 2006, at 8:55 AM, Jacob Meuser wrote: On Thu, Jan 19, 2006 at 08:17:15AM +0100, Karl-Ludwig Reinhard wrote: hello list, I'm looking for a openbsd live cd for sys admins,

Re: Generating ICMP Redirects

2006-01-19 Thread ober
Isn't "Destination unreachable" icmp a reply to a closed udp port? -Ober Richard Chesler: [Reading a piece of paper] The first rule of Fight Club is you don't talk about Fight Club? Narrator: [Voice-over] I'm half asleep again; I must've left the original in the copy machine. Richard Chesler:

Re: Is it possible to run OpenBSD on ASRock 775TWINS-HDTV S775?

2006-01-19 Thread Stuart Henderson
On 2006/01/19 17:54, Joakim Roubert wrote: > On 2006-01-19 17:43, Stuart Henderson wrote: > > > Try looking for a BIOS setting called something like legacy/native, > > and toggle it. By doing that, I got M5289 to function (DMA unsupported, > > but even with onboard disks it still completes 'make b

Re: Generating ICMP Redirects

2006-01-19 Thread Stuart Henderson
On 2006/01/19 11:37, ober wrote: > Isn't "Destination unreachable" icmp a reply to a closed udp port? Not if it's coming from the firewall rather than the endpoint - but 'block return' to a udp port does give 'destination unreachable' icmp.

ath(4) and 802.11a/h with DFS and TPC

2006-01-19 Thread Holger Mauermann
Hi, when using 802.11a devices in Europe it is mandatory that they support Dynamic Frequency Selection DFS and Transmit Power Control TPC (802.11h). Is this supported by the OpenBSD ath(4) driver? Or is it automatically enabled by the hardware? But how do I set the countrycode for ath wifi cards?

Network performance on WRAP boards

2006-01-19 Thread Carlos Valiente
Hi! I have a couple of WRAP.1E boards running OpenBSD 3.8. Using iperf I can only get about 4 to 5 Mbit/s between them. Is that figure reasonable for that kind of systems? Cheers, Carlos

Re: Network problem

2006-01-19 Thread Jan Johansson
Sebastian Schucht <[EMAIL PROTECTED]> wrote: > rl0: flags=8843 mtu 1500 > address: 00:40:f4:63:63:3d > media: Ethernet autoselect (100baseTX full-duplex) > status: active > inet XXX.100.40.69 netmask 0xff00 broadcast 141.100.40.255 > inet XXX.100.40.70 ne

portmap daemon

2006-01-19 Thread Gustavo Rios
I have been playing around with openbsd portmap. I am confused about the fact that if a program is registered above port 1024 any local user may remove it, right? Does it sound good from a security point of view? PS: Sorry if i seem stupid, but it is really strange for me.

Re: portmap daemon

2006-01-19 Thread Theo de Raadt
> I have been playing around with openbsd portmap. I am confused about > the fact that if a program is registered above port 1024 any local > user may remove it, right? Yes. > Does it sound good from a security point of view? It's not that great, but unfortunately there is no solution to this pr

Release Song License

2006-01-19 Thread Will H. Backman
Are the OpenBSD Release songs also BSD licenced? The lyrics page doesn't specify. I wanted to know if they are "podcast safe".

Re: Generating ICMP Redirects

2006-01-19 Thread Steven S
Stuart Henderson wrote: ... >> [EMAIL PROTECTED] pfctl -s rules |grep 10.4 >> pass in quick on fxp2 inet from 10.10.0.0/16 to 10.4.0.0/16 >> pass out quick on fxp2 inet from 10.4.0.0/16 to 10.10.0.0/16 > > I suspect you will need to allow the packets through in order to get > the redirects sent. A

Re: Need advice about VPN

2006-01-19 Thread Rod.. Whitworth
On Thu, 19 Jan 2006 11:28:31 +, Stuart Henderson wrote: >On 2006/01/19 10:39, Simon Slaytor wrote: >> Stuart Henderson wrote: >> >On 2006/01/19 09:38, Simon Slaytor wrote: >> > >> >>When comparing the two vpn solutions for speed, subjectively the OpenVPN >> >>feels slightly faster >> > >> >If

OpenBSD for Sun Cobalt Qube3

2006-01-19 Thread Wolfgang Kess
Hi, can you give me some advice how to install OpenBSD on a Sun Cobalt Qube 3, please? The Cube comes without cdrom or fd and no display I read about the PXE installation http://www.openbsd.org/faq/faq6.html#PXE What kind of installation method do you recommend? Regards Wolfgang The Cube

OpenBSD3.8 + smtp-vilter + spamassassin

2006-01-19 Thread Mike_OpenBSDlistalias
Hello, Apologies if this is slightly OT, but I've been over this with the SA list and they tell me spamassassin is working correctly. Also since smtp-vilter is one of two milters in packages, I thought there must be people on this list with experience with it (And I know the author posts here) I

windows -> pf -> inet -> pf -> ftpd [not working]

2006-01-19 Thread Price, Joe
I have a problem that when a Windows client tries to connect to this ftp site, windows explorer returns 'The operation timed out'. The setup is, windows box behind a openbsd PF (NAT enabled) through the public internet to another openbsd PF (NAT enabled) which has a rdr rule to redirect to anoth

Re: OpenBSD for Sun Cobalt Qube3

2006-01-19 Thread Joachim Schipper
On Thu, Jan 19, 2006 at 11:03:33PM +0100, Wolfgang Kess wrote: > Hi, > > can you give me some advice how to install OpenBSD > on a Sun Cobalt Qube 3, please? > > The Cube comes without cdrom or fd and no display > > I read about the PXE installation > http://www.openbsd.org/faq/faq6.html#PXE

Re: Network performance on WRAP boards

2006-01-19 Thread Chris Cappuccio
at the smallest packet sizes, that sounds about right, if not slightly low Carlos Valiente [EMAIL PROTECTED] wrote: > Hi! I have a couple of WRAP.1E boards running OpenBSD 3.8. Using iperf > I can only get about 4 to 5 Mbit/s between them. > > Is that figure reasonable for that kind of systems? >

Re: OpenBSD for Sun Cobalt Qube3

2006-01-19 Thread Matthew S Elmore
Greetings, I'm not sure about this specific model but... the Cobalt stuff, in most cases, has a very unusual boot loader (a Linux kernel that can only boot only certain type binaries IIRC) that would make it impossible to boot a BSD kernel. I do recall seeing where someone was able to boot F

Re: OpenBSD for Sun Cobalt Qube3

2006-01-19 Thread Daniel Ouellet
Wolfgang Kess wrote: Hi, can you give me some advice how to install OpenBSD on a Sun Cobalt Qube 3, please? The Cube comes without cdrom or fd and no display I read about the PXE installation http://www.openbsd.org/faq/faq6.html#PXE What kind of installation method do you recommend? R

connection to 3.8 box times out

2006-01-19 Thread Igor Vilensky
Greetings, This is my first post. Apologies if not everything is pro forma. I hope someone might help me with this issue. Ssh session and pinging 3.8 Generic running on Compaq Deskpro SB time out after 800 to 2400 when not actively using the box. You get 'No route to Host' message in ping or ssh

Re: time warp in -current

2006-01-19 Thread Wolfgang S. Rupprecht
I wrote: > A GENERIC amd64 kernel compiled from today's sources is causing my > Asus k8v-se-d to run fast by approximately 3 seconds per minute. > (Obviously that was with ntpd not running.) This has never been a > problem before. Is anyone else seeing this? Turns out this was caused by the most

Re: Generating ICMP Redirects

2006-01-19 Thread Melameth, Daniel D.
Steven S wrote: > I'm using a pair of 3.8-stable (1/5/06) servers as the firewall and > default gw (10.10.0.1/16) for a LAN . VPN users (10.4.0.0/16) come > into the LAN from a PIX (10.10.0.254/16) (changing soon to OpenVPN), > and when the VPN users hit a server return packets are sent to the > d

Re: time warp in -current

2006-01-19 Thread Ted Unangst
On 1/19/06, Wolfgang S. Rupprecht > Turns out this was caused by the most recent changes to kern_clock.c > and kern_time.c. Compiling with these previous versions gave me a > functional system clock again. grr

ffs panic on i386 3.8/stable

2006-01-19 Thread Tamas TEVESZ
hello, i was setting up my wrap.1e board when the following happened. this is not the first actual installation of 3.8 on this very hardware, but i never got around to actually start configuring the box (i was playing with the etherboot upgrade mentioned earlier). everything is via wrap's seri

Re: windows -> pf -> inet -> pf -> ftpd [not working]

2006-01-19 Thread Clint M. Sand
To even begin to get help on this, you'd need to submit the pf rules on those obsd boxen. On Thu, Jan 19, 2006 at 05:36:02PM -0500, Price, Joe wrote: > I have a problem that when a Windows client tries to connect to this ftp > site, windows explorer returns 'The operation timed out'. > > > >

Re: ffs panic on i386 3.8/stable

2006-01-19 Thread Ted Unangst
On 1/19/06, Tamas TEVESZ <[EMAIL PROTECTED]> wrote: > barghest:/etc/ppp# chmod 06panic: ffs_read: type 0 can you perform some mem / hw testing? this smells like disk corruption. > as a strange addition, it seems that the board can pretty > reliably be panicked with the following: > > > barghest:

Re: Generating ICMP Redirects

2006-01-19 Thread Steven S
... > I know this is not the answer to your question and I'd like > to hear how > you wind up getting the OpenBSD box to send the redirects you are > looking for, but relying on redirects to do your routing for anything > length of time is asking for trouble IMHO. You might just be better > off, t

rexx on openbsd

2006-01-19 Thread Stephen Nelson
I have some rexx scripts that I would like to run on OpenBSD. Does anyone have any experience with running rexx on openbsd? I have tried brexx, regina, and oorexx so far. Regina and oorexx fail to compile, and brexx doesn't seem to be feature complete (it doesn't seem to be able to propagate var

OpenBSD 3.8, fxp, device timeout

2006-01-19 Thread Sven Wolf
Hello, I've a server at the German hoster Strato and I try to install OpenBSD 3.8 on this machine. But I always get a device timeout of the Intel Nic (because of a wrong irq assignment?) :( Here is the dmesg output: OpenBSD 3.8 (RAMDISK) #9: Tue Jan 17 18:24:51 CET 2006 [EMAIL PROTECTE