Re: VPN Concentrator

2007-12-03 Thread Chris Black
Joseph C. Bender wrote: Scott Learmonth wrote: And Khalid - sorry to hijack your thread. Most of my road warriors are going to be on macs and too cheap to purchase VPN Tracker. Any successes I gave I'll certainly share. There's always OpenVPN. GUI via Tunnelblick

Best way to do failover default route? (ifstated, pf route-to, etc)

2007-02-21 Thread Chris Black
I am trying to set up failover default routes. The situation is three OpenBSD machines, client, rtr0 and rtr1. Client has two interfaces, one with a crossover link to rtr0 and one to rtr1. I would like the default route for client to be rtr0 unless rtr0 has failed in some way (unreachable, etc). As

failover default route with ospf

2007-03-02 Thread Chris Black
I have four router/firewalls that are all interconnected (each one to every other with a direct crossover link). Two of these are external-facing and have interfaces connected to the internet and our DMZ. The other two are internal-facing and have connections to our internal networks. I am already

Re: failover default route with ospf (now working, some questions)

2007-03-08 Thread Chris Black
f { auth-type none } } I do plan on putting auth in place once I verify everything is working without it. In addition I hope to collapse all these separate auth-type directives into the global or area portions of the conf file. Any other suggestions? Thanks! Chris Chris Black wrote: >

Re: No Blob without Puffy

2007-03-19 Thread Chris Black
Karel Kulhavy wrote: > On Mon, Mar 19, 2007 at 12:06:31AM +0100, SW wrote: > > I have a feeling that the campaign means "We don't want vendors to require > us to use a blob but we'll ocassionally use them when we have to other way", > while Theo means "I don't want vendors to require us to use a bl

Re: interface order with multiple cards of same type

2007-03-26 Thread Chris Black
Aaron Martinez wrote: > apologies if this has been covered in the past, I searched on this and > couldn't find anything, although i'm sure it's the wording i'm using. > > My question is. I have OBSD 4.0 running on an Asus p3b-F with 6 pci > slots that i'm wanting to use as a router/firewall. I ha

VPNs (was: Re: Long WEP key)

2007-03-30 Thread Chris Black
mail-lists wrote: >> Openvpn > > Unless I'm mistaken Openvpn is not equal to Ipsec > You are not mistaken. Openvpn uses SSL over regular IP packets with its own server/client setup on a dedicated port (1194). IPSec is a different protocol (proto esp rather than tcp or udp). We moved from an isa

Re: [OT] Re: Long WEP key

2007-04-02 Thread Chris Black
Joachim Schipper wrote: > On Mon, Apr 02, 2007 at 10:53:50AM +0800, Lars Hansson wrote: > >> Joachim Schipper wrote: >> >>> All in all, I might choose OpenVPN if it involved end users (lots of >>> NAT, Windows, and other crappy stuff), >>> >> OpenVPN isn't exactly awesome on Windows

Re: monitoring raid with mpi

2007-04-04 Thread Chris Black
Thierry Lacoste wrote: > I installed OpenBSD on a Dell PowerEdge with > a raid1 array controlled by a SAS 5iR controller > thanks to the new mpi driver. > > mpi0 at pci2 dev 8 function 0 "Symbios Logic SAS1068" rev 0x01: irq 5 > scsibus0 at mpi0: 63 targets > sd0 at scsibus0 targ 0 lun 0: SCSI3 0/

Re: carp, ospf can't see carp state

2007-04-08 Thread Chris Black
FranC'ois Rousseau wrote: >> > But how I'm suppose to annonce the route for the right carp interface? >> > Right now my servers can always reach the router because of the CARP >> > interface but the router can't always reach the servers... >> > >> > If I unplug the cable of my CARP interface (bge2

Re: Beep!

2007-04-10 Thread Chris Black
Manuel Ravasio wrote: > Hello list. > > > I'm creating some shell scripts for various administrative purposes, and I'd > really like to add some kind of command at the end of each in order to have > the pc speaker BEEP when the script is over. > I usually use: echo -ne '\a' Best, Chris

Re: carp, 2 router

2007-04-12 Thread Chris Black
FranC'ois Rousseau wrote: > Hi, > > I have a problem to understand how to dynamically change the route > destinate to a carp interface. > > I have 2 routers, both have 3 NIC. > > On each router I have: > 1 Nic for the upstream > 1 Nic for the LAN ( 5 carp, no nat) > 1 Nic for inter-router traffic.

Re: [OFF-TOPIC] MRTG and disk / CPU monitoring

2007-06-15 Thread Chris Black
Rivanor P. Soares wrote: Hi guys, Does anyone around have an working setup of MRTG, monitoring CPU and disk utilization? I have been digging for it on the internet, to OpenBSD, but was not able to find anything "worth". I am expecting to monitor these "devices" using MRTG with SNMP. Any URL or

Re: openbsd and dell PE 860 1u rack server

2007-06-15 Thread Chris Black
/quad channels (internal/external) if more discs were required to be supported. Is the channels (internal/external) ideia sound within SAS RAID world ? No idea. We only use a single local disk in each one and use carp for redundancy between machines. Chris Black

Re: wireless openvpn openbsd

2007-06-15 Thread Chris Black
Reyk Floeter wrote: what is this openvpn thing? http://www.google.com/search?q=openvpn

Re: Intel Core 2 - errata pulled?!?

2007-08-07 Thread Chris Black
Chris Cappuccio wrote: Toni Mueller [EMAIL PROTECTED] wrote: Leaving these aside, I just discovered that the i386 compatibility page does apparently not list _any_ current intel CPUs (eg. "Pentium D"), and the question about whether recent Xeons still classify as Xeon in this list has been ra