Re: Asking abt my PF

2007-10-02 Thread Brian A. Seklecki
To get debugging info out of pf(4): $ sudo pfctl -x loud Also check "netstat -s" for layer 3/4 errors, and "netstat -m" for kernel memory resource consumption, and "ifconfig -i(?)" for layer 2 errors. ~BAS On Tue, 2007-10-02 at 14:20 +0700, dika wrote: > Dear teams, > > Im using OpenBSD4.1 for

Re: Cisco 3002 VPN client to OpenBSD?

2007-10-04 Thread Brian A. Seklecki
racoon, though. ~BAS On Wed, 2007-10-03 at 20:32 -0700, Jeff Simmons wrote: > 3002 -- Brian A. Seklecki <[EMAIL PROTECTED]> Collaborative Fusion, Inc. IMPORTANT: This message contains confidential information and is intended only for the individual named. If the reader of this me

Re: hardware for vpn

2007-10-04 Thread Brian A. Seklecki
On Thu, 2007-10-04 at 15:24 +0200, Marc Balmer wrote: > Tang Tse wrote: > > > Just one question regarding VPNs OpenBSD and HW, is there any recomendation > > for hardware? i mean, i want to setup a VPN between 2 offices and i need > > some reasonable speed.. with a computer with some recent hardwa

Re: hardware for vpn

2007-10-04 Thread Brian A. Seklecki
On Thu, 2007-10-04 at 17:54 +0200, Piotrek Kapczuk wrote: > 2007/10/4, Brian A. Seklecki <[EMAIL PROTECTED]>: > > > I'm demo'ing some 1U P4-class network appliance hardware that will > > probably fit your needs well. See URLs below. > [...] > > &g

Re: Soekris vpn1401 and vpn1411 (use Hi/fn 7955 security accelerator chip) supported?

2007-10-04 Thread Brian A. Seklecki
> Timo Schoeler <[EMAIL PROTECTED]> wrote: On an semi-related note, I recently tested the vpn1411 in a significantly faster (2.8GHz P4 Celeron D): des3/3des: w/ acceleration: # time dd if=/dev/zero bs=1m count=100 | openssl des3 -pass pass:test -engine cryptodev -out /dev/null engine "cryptodev

Re: Cisco 3002 VPN client to OpenBSD?

2007-10-05 Thread Brian A. Seklecki
On Fri, 2007-10-05 at 12:14 -0700, Jeff Simmons wrote: > On Friday 05 October 2007 01:17, Claer wrote: > > The Cisco client license forbids explicitely to connect to anything but > > Cisco Hardware. > > If that's so, then legal forgot to tell marketing. ;-) > > "The Cisco VPN 3002 Hardware Client

Re: Cisco 3002 VPN client to OpenBSD?

2007-10-09 Thread Brian A. Seklecki
On Fri, 2007-10-05 at 18:50 -0400, Rod Dorman wrote: > On Friday, October 5, 2007, 15:14:41, Jeff Simmons wrote: > > On Friday 05 October 2007 01:17, Claer wrote: > >> The Cisco client license forbids explicitely to connect to anything but > >> Cisco Hardware. You could rip the ISA controller out

em(4) - IFCAP_VLAN_MTU & IFCAP_VLAN_HWTAGGING ?

2007-10-16 Thread Brian A. Seklecki
r=;dmesgid=1911#1911 l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/

Re: vlan & hostname.if "problem"

2007-10-17 Thread Brian A. Seklecki
k it might be worth mentioning in > hostname.ifman page! > > > > > > > -- Brian A. Seklecki <[EMAIL PROTECTED]> Collaborative Fusion, Inc. IMPORTANT: This message contains confidential information and is intended only for the individual named. If the reader

Re: em(4) - IFCAP_VLAN_MTU & IFCAP_VLAN_HWTAGGING ?

2007-10-17 Thread Brian A. Seklecki
On Wed, 17 Oct 2007 10:52:34 +0200 Henning Brauer <[EMAIL PROTECTED]> wrote: > * Brian A. Seklecki <[EMAIL PROTECTED]> [2007-10-16 23:01]: > > All: > > > > I see that IFCAP_VLAN_MTU is available, but IFCAP_VLAN_HWTAGGING, as seen > > in ti(4), is

ipsec(4) routing for a branch offices

2007-10-17 Thread Brian A. Seklecki
56 "!port 22" 20:00:28.610672 esp x.east.verizon.net > vpncxxx.pub.collaborativefusion.com spi 0x0ACAEE17 seq 89 len 116 ICMP packets giving me the old slip-a-roo out the back door >:} -- Brian A. Seklecki <[EMAIL PROTECTED]> IMPORTANT: This message contains confident

Re: em(4) - IFCAP_VLAN_MTU & IFCAP_VLAN_HWTAGGING ?

2007-10-18 Thread Brian A. Seklecki
On Thu, 18 Oct 2007 14:16:59 +0100 "Tony Sarendal" <[EMAIL PROTECTED]> wrote: > Just a 5 minute quick test, nothing too scientific. Thanks! What was your IXIA platform? RHEL with gig interface or an appliance? ~BAS -- Brian A. Seklecki <[EMAIL PROTECTED]> IMPORTA

Building bsd.rd in cdrom39.fs with RAIDFrame

2006-09-08 Thread Brian A. Seklecki
.fs as your '-B'. You may now safely burn a CD-R for binary upgrades of existing RAIDFrame enabled OpenBSD systems, or use your .ISO with your DRAC card via remote media. l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/ "...

Re: Building bsd.rd in cdrom39.fs with RAIDFrame

2006-09-11 Thread Brian A. Seklecki
R}/../sys/arch/i386/compile/GENERIC.MP+RAIDFRAME && \ ${MAKE} clean && ${MAKE} depend && exec ${MAKE} notes: -- On Fri, 8 Sep 2006, Brian A. Seklecki wrote: One of the big problems with RAIDFrame support absence in GENERIC is that it's also lacking in RAMDISK and R

Re: contact info for PC Weasel?

2008-08-06 Thread Brian A. Seklecki
On Wed, 2008-08-06 at 13:58 -0700, Chris Cappuccio wrote: > spend your money on a motherboard with serial console. like a supermicro > board or something. you'll be happier. No offense but: No. No you wont. Unless you have IPMI or something like Dell's DRAC (4, not 5 -- 5 sux big time). The A

Re: isakmpd

2008-09-16 Thread Brian A. Seklecki
wiki somewhere with lots of known-good-working isakmpd(8) / isakmpd.conf(5) examples. ~BAS > I think i have seen some sample config before but i cant seem to find any > now.. > > Any help would be appreciated.. > > /Daniel > -- Brian A. Seklecki <[EMAIL PROTECTED]>

Re: recommendation for router (COMMELL)

2008-09-17 Thread Brian A. Seklecki
> "What *would* you recommend?" > > In addition to the listed duties, I am looking for stability, For a mail server appliance, Axiomtek units are the only way to fly. Try the NA-820. We've been nothing but pleased, and of all the cheap Award/AMI BIOS's, theirs has been the best performing so f

Re: LDAP and OpenBSD

2008-10-10 Thread Brian A. Seklecki
On Fri, 2008-10-10 at 19:52 +0200, raven wrote: > I'm thinking how my users into an ldap db can login into my openbsd One would need NSS_LDAP and PAM_LDAP, which requires PAM and NSS infrastructure in-tree. Likely you'd want to sponsor development for something like that. ~BAS

Re: PF Queue on a GROUP of nics?

2008-10-15 Thread Brian A. Seklecki
On Mon, 2008-10-06 at 16:39 +1100, Sunnz wrote: > Is it possible? > > Say I have a few nics of the same group... dc0 dc1 dc2 dc3... which > all belong to a group "dc". Sunnz Do you mean a "shared queue" where "downstream" bandwidth from a single "upstream" interface is proportionally divided int

Advanced Queuing: Host-Only Stateful Inspection and Queues

2008-10-15 Thread Brian A. Seklecki
[Long Message Disclaimer] All: I was just looking over Peter Hansteen's PF book -- It's a great reference, but the coverage on QUEUING is limited (6 pages of ~150). I was hoping to find an answer to a question there-in, that I had back in 2006 when I filed system/4574 -- but with behind me, I w

Re: Can't SSH into CARP'd system from the outside

2008-10-20 Thread Brian A. Seklecki
On Mon, 2008-10-20 at 14:19 -0700, Vivek Ayer wrote: > So far, I can't ssh into the carp from the outside, can't ntp from the Try: % sudo tcpdump -ttt -e -vvv -n -i pflog0 -s 1024 -- Brian A. Seklecki <[EMAIL PROTECTED]> Collaborative Fusion, Inc. IMPORTANT: Th

Re: configuration tweaks for CF-based systems?

2008-04-03 Thread Brian A. Seklecki
___ > You rock. That's why Blockbuster's offering you one month of Blockbuster > Total Access, No Cost. > http://tc.deals.yahoo.com/tc/blockbuster/text5.com > -- Brian A. Seklecki <[EMAIL PROTECTED]> Collaborative Fusion, Inc.

Re: nagios monitoring of a remote openntp service

2008-05-08 Thread Brian A. Seklecki
anybody gotten Nagois' check_ntp_* to play nicely with a remote > >> openntp service ? It appears to rely upon services not implemented > >> in openntp ? > > > > this is against an OpenNTP server; > > > > <[EMAIL PROTECTED]:12>$ /usr/local/libexec/

Re: snmpd

2008-05-08 Thread Brian A. Seklecki
Its just not been at the top of my priority list. -- Brian A. Seklecki <[EMAIL PROTECTED]> Collaborative Fusion, Inc.

Re: snmpd

2008-06-14 Thread Brian A. Seklecki
> > Tim > > - Original Message > > From: Brian A. Seklecki <[EMAIL PROTECTED]> > > To: Tim Kuijsten <[EMAIL PROTECTED]> > > Cc: misc@openbsd.org > > Sent: Friday, May 9, 2008 1:35:46 AM > > Subject: Re: snmpd > > > > > >

sshd_config(5) PermitRootLogin yes

2008-07-10 Thread Brian A. Seklecki
Am I reading this right? http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config?rev=1.80&content-type=text/x-cvsweb-markup I dont have a fresh install anywhere -- but I want to say that it doesnt default to PermitRootLogin yes after the install. I remember that I filed PRs with Fre

Re: sshd_config(5) PermitRootLogin yes

2008-07-10 Thread Brian A. Seklecki
On Thu, 10 Jul 2008, Brynet wrote: The keyword here is *default*. Say you installed OpenBSD on a soekris, it's nice having root enabled "temporarily". That way you can login at a later time, create a lesser privledged account, On Soekris, does the first boot console access not function pro

Re: sshd_config(5) PermitRootLogin yes

2008-07-10 Thread Brian A. Seklecki
afterboot(8) covers this Works for me, I guess. =/ ~BAS http://www.openbsd.org/cgi-bin/man.cgi?query=afterboot&apropos=0&sektion=0&ma npath=OpenBSD+Current&arch=i386&format=html

Re: sshd_config(5) PermitRootLogin yes

2008-07-10 Thread Brian A. Seklecki
ikely the rationel why the rest of the projects changed it. ~~BAS On Thu, Jul 10, 2008 at 10:35:06AM -0400, Brian A. Seklecki wrote: Am I reading this right? http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config?rev=1.80&content-type=text/x-cvsweb-markup I dont have a fres

Re: sshd_config(5) PermitRootLogin yes

2008-07-10 Thread Brian A. Seklecki
does anything other than make mgmt types worry because they don't really understand security. On Thu, Jul 10, 2008 at 01:38:22PM -0400, Brian A. Seklecki wrote: On Thu, 10 Jul 2008, Marco Peereboom wrote: Of course it is enabled by default. Why do I want a box that is freshly insta

carp(4) debugging

2006-10-10 Thread Brian A. Seklecki
elp debug the decision making algorithm used in master/standy/backup election process. Certainly a way to log events (interfaces, etc.) and the resulting actions taken by the code would be useful in mission critical environments. Anything beats "tcpdump 'proto carp'&q

Re: carp(4) debugging

2006-10-11 Thread Brian A. Seklecki
number of max states (set limit states 20, etc.) ~BAS On Wed, 11 Oct 2006, Ryan McBride wrote: On Tue, Oct 10, 2006 at 05:50:50PM -0400, Brian A. Seklecki wrote: Certainly a way to log events (interfaces, etc.) and the resulting actions taken by the code would be useful in missio

Re: ports question

2006-10-11 Thread Brian A. Seklecki
and so the screen just keeps right on trucking and you don't have time to read it. Is there some command or somewhere you can go to see what the message was? --Bryan l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/ "...fr

RAID-1 Root + boot(8) on i386/amd64

2005-06-30 Thread Brian A. Seklecki
Please confirm that the following are applicable: * boot(8), biosboot(8), installboot(8), boot_i386(8) lack any support for booting off RAIDFrame volumes (a 13 line patch 22 months ago fixed this on the bother side of the isleb(r)). * No support is planned *

Re: HP ProLiant DL140 serial consola installation

2005-06-30 Thread Brian A. Seklecki
The same behavior happens on Dell's serial console redirection. It happens when you boot FreeBSD too. As soon as the kernel starts output ANSI characters it goes dead. Dell lets you toggle between VT100/220 mode and ANSI mode, but it's unaffected. The kernel output just kills it. Dell has an o

Re: OpenBSD 3.7 + Bridge Wireless (Orinoco)

2005-07-04 Thread Brian J. Woods
Roberto Gonzalez Azevedo wrote: Hello everybody... I have a little problem to solve here and i hope that you can help me. I wanna do a 'wireless bridge' : rl0 <--> wi0 But it4s not working. I4m trying to use PPPoE in this bridge, but the PADI is not passing over wi0 ... Thanks ... Robert

IPSec Routing / Multiple Subnets / GRE Revisited

2005-07-22 Thread Brian A. Seklecki
The URL: http://digitalfreaks.org/~lavalamp/openbsd_ipsec_generic.png Outlines the generic cookie-cutter configuration from vpn(8) with addressing changes. A couple of comments on that document: *) The output of 'netstat -rn -f encap' should probably be included at the end. *) ...possibl

Re: Raidframe and Raid Level -6-

2005-07-24 Thread Brian A. Seklecki
RAIDFrame hasn't been updated in two years... It's stable with the known supported levels. ~BAS On Sat, 2005-07-23 at 21:31, Mathias Mueller wrote: > Hello, > > I have a short question to the community... > > Does anybody have experience with raid level 6 on a raidframe software > raid? Is i

Re: IPSec Routing / Multiple Subnets / GRE Revisited

2005-07-25 Thread Brian A. Seklecki
On Sat, 23 Jul 2005, Hans-Joerg Hoexer wrote: Hi, On Fri, Jul 22, 2005 at 06:43:34PM -0400, Brian A. Seklecki wrote: The URL: http://digitalfreaks.org/~lavalamp/openbsd_ipsec_generic.png Outlines the generic cookie-cutter configuration from vpn(8) with addressing changes. A couple of

Re: Sendmail security problem

2006-03-28 Thread Brian A. Seklecki
On Fri, 24 Mar 2006, Joachim Schipper wrote: On Fri, Mar 24, 2006 at 02:14:50PM +, Stuart Henderson wrote: On 2006/03/24 14:12, Alexander Bochmann wrote: ...on Thu, Mar 23, 2006 at 12:22:37PM +0100, Anthony Howe wrote: P gnu/usr.sbin/sendmail/libsm/refill.c P gnu/usr.sbin/sendmail/sendma

Re: Panic: biodone already

2006-04-20 Thread Brian A. Seklecki
2) is there a command where I can entirely erase my drives so I can start from scratch? This is a sparc64 build and I can't use fdisk - is newfs use dd(1) to blow away any trace of raidframe from your disks: dd if=/dev/zero of=/dev/rsd0{a,c} bs=1024k count=1 That will write a meg of null to

Re: Wireless NIC for soekris 4801

2006-04-20 Thread Brian A. Seklecki
On Thu, 20 Apr 2006, Lasse Bach wrote: Hi all, Does anyone have any HW recommendations on that and should it be PCI or MiniPCI? Moreover, can any one recommend a PCI NIC with dual antennas? The Cisco theoretically supports it since it's a glorified cardbus->PCI expander on a stick.

Re: Microsoft SP1 RPC traffic (Active Directory issues)

2006-04-20 Thread Brian A. Seklecki
On Thu, 20 Apr 2006, James Mackinnon wrote: Good day everyone Recently, I installed SP1 on some domain controllers and ran into an issue where microsoft changed rpc data with SP1 and firewalls such as microsofts own ISA server as well as checkpoint have started to randomly block this data. .

Re: Panic: biodone already

2006-04-20 Thread Brian A. Seklecki
On Thu, 20 Apr 2006, Pedro Martelletto wrote: The raid(4) codebase is old, unmaintained, and known to have issues. That's one of the reasons it's not in the stock kernel. Oh I thought the OpenBSD team was silently discouraging people from the practice of using software RAID. >:} That sound

Override errno EBUSY on rd(4) device after boot in mount(2)?

2006-04-21 Thread Brian A. Seklecki
Is there any way to override the flag on a device that permits it from being mounted twice?MNT_FORCE isn't it. I've got an embedded environment I'm setting up where I want to transfer the root (/) file system from an rd(4) to an MFS. To do this, I have to add some customizations to copy() in

Re: 3.7: weird IP address problem

2006-04-24 Thread Brian A. Seklecki
On Mon, 24 Apr 2006, Toni Mueller wrote: Hello, I have a box that once had two IP addresses on one interface. I deconfigured one of them using ifconfig -alias. I'd rather not reboot only to make a change in IP numbers effective... Check "netstat -rn" and "arp -an" for hangers-on lingeri

Re: isakmpd - DPD stops working

2006-04-24 Thread Brian A. Seklecki
On Fri, 21 Apr 2006, Mitja Mu?eni? wrote: I'm debbuging something weird here. Before I put together a full and sanitized error report, just a quick question: is anybody else seeing DPD to just stop working after a couple of hours, or is it just me & my setup? I have some pre-3.9 -current (mid M

Re: Tape drive DLT VS160

2006-04-24 Thread Brian A. Seklecki
On Mon, 24 Apr 2006, Planck wrote: Hello. I have tape drive Quantum DLT VS160 (part of dmesg bellow) connected to Adaptec AHA-2940. Everything work fine, but i dont know how to enable hardware compresion on that drive. There aren't any jumpers on enclosure, and mt(1) or st(4) dont say anytging a

Re: 3.7: weird IP address problem

2006-04-24 Thread Brian A. Seklecki
On Mon, 24 Apr 2006, Toni Mueller wrote: Hello, I have a box that once had two IP addresses on one interface. I deconfigured one of them using ifconfig -alias. Now, when I want to use any (?) program on that box to go over this interface, it wants to use the addresses which is no longer presen

Alter root FS device after boot?

2006-04-24 Thread Brian A. Seklecki
All: Would it be hypothetical possible to change the device mounted as (/) after the system has booted (possibly during the bootstrapping phase)? This of course overriding the checks in src/sys/kern/sys_vfs* ~BAS

Re: Alter root FS device after boot?

2006-04-26 Thread Brian A. Seklecki
> you can't ever unount the first / mount after init starts, because > that would mean revoking init's vnode. Yes after disabling the kernel checks I've tried to do this and it seems to cause a complete halt of the system. If only I could bypass the check that disallows a device from becoming mou

Re: CARP/PFSYNC over USB is possible?

2005-09-22 Thread Brian A. Seklecki
On Mon, 29 Aug 2005, Vinicius Pavanelli Vianna wrote: I'm currently using an OpenBSD 3.7 as a firewall for my network, since this machines is a 1U rack I can't add an extra ethernet card to it, so I was looking for an alternative solution to use redundancy, since there are plenty of usb ports fr

Re: Load Balancing

2005-10-01 Thread Brian A. Seklecki
So have him send the message pre-formatted to the list? HTML? How about just draw the diagram using ports/graphics/dia/* and export to PNG, post the URL? ~BAS On Fri, 2005-09-30 at 10:01, J.C. Roberts wrote: > On Fri, 30 Sep 2005 18:35:16 +0530, Manpreet Singh Nehra > <[EMAIL PROTECTED]> wrote:

Re: ntop

2005-10-01 Thread Brian A. Seklecki
What platform are you on? Are you compiling it from source? It works just fine in 3.7/i386. Just: bash-3.00# cd /usr/ports/net/ntop && make install clean If you insist on source, try looking at /usr/ports/net/ntop/patches/* Try reading about Ports in the FAQ. ~BAS On Thu, 2005-09-29 at 12

Queing on Multiple Interfaces Revisited (WAS: Re: matching queues in both directions with stateful rulesets)

2005-10-03 Thread Brian A. Seklecki
with an Interface, i.e., the "ingress/egress" queue for matching traffic switched from interface-to-interface. We keep saying, "you can't queue inbound", which makese sense. But you need a technique for queuing a "shared ingress" ~BAS > > -- > http://2suck.net/hhwl.html - http://www.bsws.de/ > Unix is very simple, but it takes a genius to understand the simplicity. > (Dennis Ritchie) > > -- l8r* -- ~ Brian A. Seklecki "From back in the heady days when 'Help Desk' meant nothing, 'Disk Quota' meant everything, and lives could be bought and sold for a couple of pages of laser printout...and frequently were."

Shared Queues / Queuing on Multiple Interfaces

2005-10-06 Thread Brian A. Seklecki
--- Date: Mon, 3 Oct 2005 11:28:24 -0400 (EDT) From: Brian A. Seklecki <[EMAIL PROTECTED]> To: Henning Brauer <[EMAIL PROTECTED]> Cc: misc@openbsd.org, Tony Sarendal <[EMAIL PROTECTED]>, jared r r spiegel <[EMAIL PROTECTED]>, Seamus Wassman <[EMAIL PROTECTED]>

Re: /etc/hostname.if convention

2005-10-07 Thread Brian A. Seklecki
It's a solaris/sunos thing ~BAS On Fri, 2005-10-07 at 04:16, Stephan A. Rickauer wrote: > Hello, > > can anyone tell me, whether the current naming convention of > /etc/hostname.if is because of history of /etc/hostname (which has been > extended) or if there are other reasons. I am just cu

Re: Sun Ultra 5 as a firewall?

2005-10-07 Thread Brian A. Seklecki
On Fri, 7 Oct 2005, Joe S wrote: Is anyone on the list running an Ultra 5 as firewall? I would like to move my firewall from an overpowered P4-3GHz box to a Sun Ultra 5 360MHz. My main concern is wondering if the Ultra 5 is slow enough to become a bottleneck from one interface to another inte

"keep state" and PF Queues

2005-10-19 Thread Brian A. Seklecki
Would anyone like to elaborate on the impacts of using "keep state" on conjunction with pass rules that assign traffic to queues? One might assume that inverted traffic flows would also be queued, however that would break the "traffic can only be queued egress an interface" rule... There sho

Re: em(4) problems with -current

2005-10-19 Thread Brian A. Seklecki
The Intel IPMI on the motherboard may be to blame. It's always up/on and listening. Also, see my thread in freebsd-questions@ about Dells with Intel em(4) and Dell PowerEdge switches w/ NIC Teaming, 802.3ad, ng_many2_one, etc. For example, traffic sent from the IPMI IP/MAC of the interface i

Re: em(4) problems with -current

2005-10-19 Thread Brian A. Seklecki
I'll double check this today and verify. Will the IPMI on the motherboard only work with the onboard ethernet controllers, or will it get its grubby little hands on any/all controllers it finds? If it only The IPMI configuration screen gives you the option of configuring which Interface to bi

Re: em(4) problems with -current

2005-10-19 Thread Brian A. Seklecki
On Wed, 19 Oct 2005, Theo de Raadt wrote: Someone with one of these problematic cards should put it in the It isn't so much a bug; more so a caveat of Dell's implenentation. Maybe you can order PowerEdge 1850s w/o a hardware IPMI implementation, but I don't think it's an issue that warrants

Dell PowerEdge SC1420 w/ CERC SATA 2S RAID

2005-10-20 Thread Brian A. Seklecki
For the record, these systems run 3.7/i386 rock solid. Just forget entirely about using the "Software Assist RAID" support on the motherboard and use RAIDFrame instead. In the BIOS, you can toggle it between "RAID" and "NON-RAID" mode, but it makes no difference. The kernel probes it just the

Re: "keep state" and PF Queues

2005-10-21 Thread Brian A. Seklecki
t the FAQ contains > an > example much as you describe (as I recall, specifying a queue for -incoming- > traffic will indeed cause that traffic to be processed through the named queue > as it is -outgoing-). > > > Bill > > Brian A. Seklecki wrote: >> Would anyone

Re: Carp / VLAN and net.inet.carp.preempt=1

2005-10-21 Thread Brian A. Seklecki
On Fri, 21 Oct 2005, Xavier Beaudouin wrote: Hello there, I have 2 openbsd box (that does as well openbgpd but this is not the aim of this mail). Question is that any problems to do sysctl net.inet.carp.preempt=1 and ifconfig em0 up ifconfig vlan0 vlan 11 vlandev em0 Each machine must hav

Re: passwd: /sbin/nologin --- not working for me

2005-10-21 Thread Brian A. Seklecki
You said you "entered" into those files. Did you vi(1) them mnaually? Did you rebuild the database afterward? When you finger the user, what does the shell show up as? Use either vipw(8) as root, to do this, or use chfn(1) as the user. ~BAS On Fri, 21 Oct 2005, morla wrote: hello all, i

Re: Statefull VPN failover a fork from "Re: iptables vs pf"

2005-10-21 Thread Brian A. Seklecki
More to the point, "how to find this info". 1: Go to http://www.openbsd.org/cgi-bin/man.cgi 2: click "apropos" 3: make sure "current" is selected 4: query "sync" 5: click on "sasynchd(8)" and "sasychd.conf(5)" http://www.openbsd.org/cgi-bin/man.cgi?query=sasyncd&sektion=8&apropos=0&manpath=OpenB

Re: "keep state" and PF Queues

2005-10-21 Thread Brian A. Seklecki
name exists on the given interface, we do so, otherwise it goes to the default queue. * Brian A. Seklecki <[EMAIL PROTECTED]> [2005-10-21 17:59]: I was just curious if any of the developers (or experts) would care to articulate officially >:} ~BAS On Wed, 19 Oct 2005, William Bloom wrote:

Notes on RAID1 Root Tutorial Adaption

2005-10-26 Thread Brian A. Seklecki
...a while back, i wrote a tutorial for RAIFRame RAID1 as a root FS on NetBSD. I used the "bootstrap" method. Sometime not soon after, NetBSD added RAIDFrame to the INSTALL* kernels and presumably menus to sysinst, mitigating the need for this approach. the boostrap process is: *) do a basi

Re: isakmpd - Single Phase 1 - Multiple Phase 2 Address

2005-10-27 Thread Brian A. Seklecki
This is confirmed to work? I suppose that would resolve part of my problem with 4314/system ~BAS On Thu, 2005-10-27 at 05:02, Runo Forrisdahl wrote: > On Wed, Oct 26, 2005 at 02:40:52PM -0400, Roy Morris wrote: > | I have been reading through the archives but have not found a reliable > answer

isakmpd(8) + gre(4) reproducible crash

2005-10-28 Thread Brian A. Seklecki
per some previous remarks(1), i was able to get two i386 boxes in a lab to crash but not panic and core out, makit it impossible to debug this problem. two i386 machines in the config below would just "reset back to the bios", as if the reset button had been tapped. the problem occurs when tw

Re: isakmpd(8) + gre(4) reproducible crash

2005-10-28 Thread Brian A. Seklecki
The behavior does not exist when I setup IPSEC TRANSPORT mode across the GRE tunnel. I'll send-pr(1). ~BAS On Fri, 28 Oct 2005, Brian A. Seklecki wrote: per some previous remarks(1), i was able to get two i386 boxes in a lab to crash but not panic and core out, makit it impossible to

Re: OpenBSD 3.8 X.org on Sun Blade 100

2005-11-16 Thread Brian A. Seklecki
Wait...1280x1024 or 1600x1200 w/ 8MB of RAM? Is that right? Onboard video only occupies 8MB? (II) ATI(0): Using Block 1 MMIO aperture at 0x00426000. (II) ATI(0): MMIO write caching enabled. (--) ATI(0): 8192 kB of SDRAM (1:1) detected (using 8191 kB). (WW) ATI(0): Cannot shadow an accelerated fra

Re: Tyan Thunder LE SMP issues

2005-11-16 Thread Brian A. Seklecki
Why were they given to you? Something wrong with them perhaps. Try booting Memtest86+ ISO and let it ride for a while? Try another kernel from another OS? Try a non MP kernel? ~BAS On Wed, 2005-11-16 at 22:01, Lokkju wrote: > Hey all, hoping someone might be able to point me in some sort of di

Re: RAIDFrame, failed component

2005-11-16 Thread Brian A. Seklecki
> I'm not sure what to make of 'component1'. It's not an explicit For some reason, RAIDFrame refers to a missing drive "component1" whenever the RAID device is initialized and the drive is absent. ~BAS > device, did you use that string your raid0.conf? The first slot in > these commands shoul

Re: Problem with ISAKMPD

2005-11-16 Thread Brian A. Seklecki
Are you expiring lifetime on bandwidth or time? Probably the defaults of whatever transforms suite you're using. Try manually defining it? If you expire on time, say...10 minutes, you can tcpdump for udp 500 on either side at the expected time and watch the renegotiation. Maybe UDP packets are

Re: OpenBSD 3.8 X.org on Sun Blade 100

2005-11-17 Thread Brian A. Seklecki
d to create listener for local Is /tmp mounted MFS or so? Is it mode 777? ~BAS On Thu, 17 Nov 2005, Simon Morgan wrote: On 17/11/05, Brian A. Seklecki <[EMAIL PROTECTED]> wrote: Wait...1280x1024 or 1600x1200 w/ 8MB of RAM? Is that right? Onboard video only occupies 8MB? Sorry, yes.

Re: OpenBSD 3.8 X.org on Sun Blade 100

2005-11-17 Thread Brian A. Seklecki
On Thu, 17 Nov 2005, Simon Morgan wrote: On 17/11/05, Brian A. Seklecki <[EMAIL PROTECTED]> wrote: I just dont see 8mb video cards making it to 1280x1024 at 24/16bpp I've now managed to get a display up. Many thanks to you and everyone else who offered advice. Unfortunately t

Re: OpenBSD 3.8 X.org on Sun Blade 100

2005-11-17 Thread Brian A. Seklecki
On Thu, 17 Nov 2005, Simon Morgan wrote: On 17/11/05, Brian A. Seklecki <[EMAIL PROTECTED]> wrote: I had a U5 270? 330? Mhz for a year or two; the only way to get into 1280x1024 (the max res of the monitor that it shipped with) was to drop into 8bpp. At 16/24 bpp, with the 8mb integrat

Re: Tyan Thunder LE SMP issues

2005-11-17 Thread Brian A. Seklecki
As far as I know, this is UP, and does not use SMP. Chances are you have some sort of SMP issue... maybe with the 2nd CPU. He indicated that he swapped them up. --Toby. l8* -lava x.25 - minix - bitnet - plan9 - 110 bps - ASR 33 - base8

Re: Annoying echoes in console DRAC III/XT on DELL Poweredge

2005-12-04 Thread Brian A. Seklecki
The thing emulates a USB keyboard. Trying toggling legacy emulation mode in the BIOS. ~BAS On Thu, 2005-12-01 at 03:55, Xavier MilliC(s-Lacroix wrote: > Hello, > > I 'm trying to install OBSD 3.8 on a Dell Poweredge 750 server using the Card > DRAC III/XT (provides remote console/screen). > But

Re: multiple Local-IDs for isakmpd

2005-12-04 Thread Brian A. Seklecki
I opened a PR on this earlier this year. Seach my last name in query-pr. The Cisco 3000 supports SA Proposals with multiple discontiguous subnets. ~BAS On Tue, 2005-06-07 at 20:54, Tamas TEVESZ wrote: > hi, > > i have a situation where a branch office with multiple, > non-overlapping, non-aggr

PF NAT Address Pool Source Interface

2005-12-05 Thread Brian A. Seklecki
All: It may seem rudimentary, but no where in the FAQ or man pages is it explicitly stated that the source address or address pool of a NAT translation must be assigned to an interface. Obviously it can be either be a primary address (such as 99.9% of the PAT configurations on the Internet)

Re: OpenBSD 3.8 and Dell 1850 with PERC4/DC controller

2005-12-05 Thread Brian A. Seklecki
I've only had the priv. to run OpenBSD on the 750 and 850 1Us from Dell. However I have a number of FreeBSD 5.3x hosts on single and dual-proc 1850 models, some with RAID and some with standard SCSI. The standard SCSI config (on which I run software RAID) probes as: NAME mpt(4) -- LSI F

*STUPID* IPSEC Routing Bug - No Default Gateway?!

2005-12-05 Thread Brian A. Seklecki
All: I'm CC'ing everyone who has previously posted the "destination host unreachable" behavior when setting up a generic 4-host IPSec VPN tunnel config per the template in vpn(8) / isakmpd.conf(5). NOTE: This is not the "I can't ping the other side of the tunnel from the remote gateway becau

Re: *STUPID* IPSEC Routing Bug - No Default Gateway?!

2005-12-06 Thread Brian A. Seklecki
> no, you just need a route to the destination, this is a known a route to the destination of the tunnel...(that overlaps with the encap route...)... > but and there's no simple fix. however, just create a network > route for the peer that points back to the sender. this way ...or a route to th

Re: UltraSparc documentation

2005-12-07 Thread Brian A. Seklecki
> There is the (expensive) Real Weasel for x86 kit, Dell's crappy lights DRAC/4 isn't that bad >:} You can always use serial console redirection on the 1850s/2850s; it works well until OS boot (BIOS menus works, RAID, IPMI menus), when you have to setup serial console redirection on the boot load

Re: RAIDframe issues on 3.8

2005-12-07 Thread Brian A. Seklecki
> started filing PR's for RAIDframe stuff in OpenBSD -- there have been > a lot of changes/fixes to RAIDframe in the last 5 years that aren't I have $100 via Paypal for the person who commits RAID enabled boot blocks for Sparc[64] and i386/amd64 on OpenBSD. I have an $100 additional via Paypal

Re: OpenBSD beep

2005-12-17 Thread Brian A. Seklecki
PC speaker beep (something action on the console?) Or possibly hardware alarm? ~BAS On Sat, 2005-12-17 at 09:12, dimaz wrote: > I've installed OpenBSD on my small server, before on server was linux, > and 2-3 times a day my server beeps (3 times)... > What does it mean? And how I can control th

Re: isakmpd + gre crashing on OpenBSD 3.8

2006-01-09 Thread Brian A. Seklecki
But as soon as I start an scp from Perspex to Soekris, Perspex reboots after a few hundred kb. Unfortunately, Perspex is in a datacenter and I do not have console access to it to see what the heck is happening at that exact moment. I don't recall. But for the record (IPSEC inside GRE): If the

Re: Annoying echoes in console DRAC III/XT on DELL Poweredge

2006-01-13 Thread Brian A. Seklecki
d get MUX'd in. Compile a kernel w/o wscons or wskbd? I dunno. I'd really have to play with it. All that I can personally attest to is: It works fine with Drac/4 on FreeBSD 5.x =/ ~BAS > > -Message d'origine- > De : Brian A. Seklecki [mailto:[EMAIL PROT

Re: ipmi(4) (IPMI MIB?)

2006-01-26 Thread Brian A. Seklecki
All: Regarding the future of IPMI and SNMP, where do they intersect in the evolution of enterprise free software (aka, BSD) ? Specifically, the OpenBSD implementation we're seeing here seems to provide sysctl style access to Sensor data, watchdog info, etc., but what about other IPMI functio

IPMI / SNMP / MRTG (WAS: RE: ipmi(4) (IPMI MIB?))

2006-02-03 Thread Brian A. Seklecki
On Thu, 26 Jan 2006, Bruce Shaw wrote: We've actually got several different problems here. Specifically, the OpenBSD implementation we're seeing here seems to provide sysctl style access to Sensor data, watchdog info, etc., but what about other IPMI functions? I've been working on better sen

Re: IPMI / SNMP / MRTG (WAS: RE: ipmi(4) (IPMI MIB?))

2006-02-03 Thread Brian A. Seklecki
On Fri, 3 Feb 2006, Marco Peereboom wrote: What's wrong with? # sysctl hw | grep ipmi hw.sensors.0=ipmi0, Temp, OK, temp, 43.00 degC / 109.40 degF hw.sensors.1=ipmi0, Planar Temp, OK, temp, 30.00 degC / 86.00 degF hw.sensors.2=ipmi0, CMOS Battery, OK, volts_dc, 3.12 V hw.sensors.3=ipmi0, Front F

Re: Reading a damaged disk

2012-09-24 Thread Brian Seklecki (Mobile)
CloneZilla has a provision for backing-off invalid/unreadble sectors using a configurable set of thresholds. ~BAS (Hates to recommend GNU/Linux based systems, but G4U didn't cut it with my last failed drive)

Re: systat colors?

2011-11-10 Thread Brian Seklecki (Mobile)
Use OPENBSD-VM-MIB; extract via SNMP and prettify it later. ~BAS Has anyone already modified systat to support colored text?

Re: LaCie

2009-08-14 Thread Brian A. Seklecki
On Tue, 2009-08-04 at 13:53 -0300, Marcos Laufer wrote: > Hello, has anyone had any experience with LaCie Raid and Storage very Feng shui ~BAS "I'm the kind of Mac-using sociopath that looks at an external NAS and asks: 'What kind of RAID array defines me as a person?'"

Re: cell card on vaio p

2009-11-03 Thread Brian A. Seklecki
On Fri, 2009-10-30 at 12:01 -0700, Lawrence-Sporkton wrote: > I believe its the Gobi 1000 or Gobi UNDP-1 which appear to be the same > device Very odd. This is a CDMA/3G/GSM/EVDO modem? Normally they show up as PCMICIA, USB, or PCI Serial devices. A lot of times the PCMCIA ones present a USB Ho

Re: Starting a Radius / Nas in openbsd

2009-11-03 Thread Brian A. Seklecki
On Fri, 2009-10-30 at 22:08 +0100, C. Diego Raffaelli A. wrote: > Any idea? Am i right using OpenBSD and trying to use Radius and/or > NAS?? RADIUS Authentication and RADIUS Accounting are what you want, but that's off-topic for this list. Look in ports for RADIUS servers. Good luck. ~BAS

Kindly Respond

2010-11-07 Thread Brian Jit Singh
I am Brian Jit Singh ,an attorney at law in Malaysia. A deceased client of mine, who shares the same last name as yours, died as the result of a heart-related condition on March 12th 2005. His heart condition was due to the death of all then known members of his family in the tsunami disaster

<    3   4   5   6   7   8   9   >