Re: pf altq and cbq borrowing

2006-12-12 Thread Lawrence Horvath
On 12/12/06, Matt Hamilton <[EMAIL PROTECTED]> wrote: Hi All, Something I just noticed on 3.9 with our firewall that I'm hoping someone can explain, as it looks like a bug to me. Our simplified config for queueing is: altq on $ext_if cbq bandwidth 8Mb queue { colo, bmex, deflt } queue bme

Re: looking for (custom) dial-in

2006-12-28 Thread Lawrence Horvath
May i ask why? I'm sure google could tell you quite a few dial-up company's in the country's you would like On 12/28/06, Peter Philipp <[EMAIL PROTECTED]> wrote: Hi misc@, I know OpenBSD isn't a telco nor an internet service provider, but perhaps someone out there has a spare POTS line where

Re: pf+altq

2007-01-17 Thread Lawrence Horvath
Try defining q_pri with a bandwidth, you might even be able to set it as: queue q_pri bandwidth 0% priority 7 cbq(borrow) This way it wouldnt reserve any bandwidth but it shouldnt cause issues with the bandwidth math either. If you get that working, please let me know. On 1/17/07, sonjaya <[E

rc.conf.local

2007-01-19 Thread Lawrence Horvath
when using rc.conf.local do you need to add #!/bin/sh - at the top of the file, or just start inserting lines? thanks -- -Lawrence -Student ID 1028219 -CCNA

altq hfsc

2007-01-23 Thread Lawrence Horvath
I was looking at the pf.conf(5) page for my altq/hfsc config and had some trouble understanding the exact workings of hfsc queues, the pf.conf man page has limited info on there workings. Also when i was looking at pf(4) it noted altq(9) which didnt seem to exist, is that an old listing in the pf(

Re: Idea for additionnal funding

2007-01-23 Thread Lawrence Horvath
I could be wrong, but the original question said nothing about "non-profit" the way i read the first question as simply as, why cant OpenBSD(a for-profit entity) do advertising, via a search page for google(a for-profit entity, as far as i know), and get paid for it. Nothing non-profit required, s

altq with hfsc

2007-01-23 Thread Lawrence Horvath
Im trying to implement hfsc altq on a firewall i have running, i currently have the linkshare option working properly with only the bandwidth assigned to the queue not a full service curve. I would like to implement upperlimit however i don't quite understand how the delay works, i understand how

Re: apache security

2007-01-23 Thread Lawrence Horvath
I had an idea but not sure if its possible, section off and chroot each site into a folder of its own, not sure if thats possible to chroot each site to a diff dir or not, i think apache only allows you to chroot the process Maybe use permissions, diff user on each site, chmod to disallow writing

Re: Virtualisation on OpenBSD?

2007-01-24 Thread Lawrence Horvath
qemu is your best bet, its not quite as fast as vmware but it runs on OpenBSD, and supports several archs, it has a nice pkg and everything vmware could run on OpenBSD if you have linux compatibility turned on i think On 1/24/07, John Tate <[EMAIL PROTECTED]> wrote: Is there any software that

Re: JOB OFFER

2007-01-24 Thread Lawrence Horvath
I get a number of spams that make it though the misc list, not many but at least a few, i use gmail and wasn't sure if its safe to classify them as spam of if i should just delete them, i was concerned that in classifying them as spam it could count negative toward the list server? thanks On 1/2

multi queu

2007-01-24 Thread Lawrence Horvath
usually its only possible to queue once going out an interface, as far as i know, is it possible to use a loopback interface to run traffic through muliple queues? internet--->em0 (queue)--->lo2 (queue)->em1--->lan -- -Lawrence -Student ID 1028219 -CCNA

Re: multi queu

2007-01-24 Thread Lawrence Horvath
one queue, and i dont want to have to set up multiple firewalls, id rather have everything in one nice pf.conf, im gonna do carp later On 1/24/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/01/24 06:45, Lawrence Horvath wrote: > usually its only possible to queue once goi

Re: Virtualisation on OpenBSD?

2007-01-24 Thread Lawrence Horvath
I tried looking for source but was unable, vmware is a closed source as far as i can tell(please correct me if im wrong, as i like to get hold of the source) when i was looking for it online you have to download the binarys, and you have to email in for a serial number to use it, they also have hi

Re: multi queu

2007-01-24 Thread Lawrence Horvath
work ok, and the loopback queue will still keep anyone from going over the 10 meg link, and allow certain over all prioritization. its kinda strange i know, but i think it will work On 1/24/07, Bill Marquette <[EMAIL PROTECTED]> wrote: On 1/24/07, Lawrence Horvath <[EMAIL PROTECTE

Re: altq hfsc issue

2007-01-29 Thread Lawrence Horvath
i believe if you do not specify the realtime in the qd queue it assumes 100% this creating a math issue, try giving qd a realtime limit On 1/22/07, Piotr Lukawski <[EMAIL PROTECTED]> wrote: Dear misc@openbsd.org, I wanted to share bandwidth 512Kb between 4 users with guaranted bandwidth 20Kb

rsa remote auth

2007-02-07 Thread Lawrence Horvath
I am trying to get my openbsd 4.0 box to allow remote ssh logins using an rsa key, i added the key into my ~/.ssh/authorized_keys file, and set permissions on ~/.ssh and ~/.ssh/authorized_keys to 0600 i added the rsa of its self, for testing, however i cant seem to get an ssh session to authenti

Re: rsa remote auth

2007-02-07 Thread Lawrence Horvath
On 2/7/07, Darren Spruell <[EMAIL PROTECTED]> wrote: On 2/7/07, Lawrence Horvath <[EMAIL PROTECTED]> wrote: > I am trying to get my openbsd 4.0 box to allow remote ssh logins using > an rsa key, > > i added the key into my ~/.ssh/authorized_keys file, and set > permi

Re: rsa remote auth

2007-02-07 Thread Lawrence Horvath
Ahh ok there we go, It was a permissions issue on ~/ i had read and write set for group, changed it to 0700, its now working On 2/7/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/02/07 06:49, Lawrence Horvath wrote: > and made sure of the file permissions > ~/.ssh is 0

Re: altq+HFSC

2007-02-11 Thread Lawrence Horvath
As far as I know there is no specific altq list, just use the main misc list. Please make sure to post to the list and not to people privately thank you On 2/11/07, Ralf Braga <[EMAIL PROTECTED]> wrote: Hi Lawrence and Atren, I'm with one few dificults for configure altq+pf+hfsc, Need bala

Re: is there [EMAIL PROTECTED] archive?

2007-02-18 Thread Lawrence Horvath
I agree with scorch, how do we find out what hardware is working best and most used with OpenBSD. Even we you cant release the dmesg reports, what about a statistics page, something along the lines of, x amount of x mobos is used with OpenBSD, and other hardware as well. would that be possible?

Re: monitoring traffic/bandwidth on a bridge

2007-02-26 Thread Lawrence Horvath
Check out bandwidthd, i dont think its in ports or pkgs, however it does an excellent job, gives per IP graphs and total bandwidth used. never tried it on a bridge thou On 22/02/07, Ross Davis <[EMAIL PROTECTED]> wrote: I am running OpenBSD 4.0 and have a bridge set up between two interfaces: f

passing to inside interface

2007-03-20 Thread Lawrence Horvath
this is on OpenBSD 4.0 Generic I have the below rule set in my pf.conf, i am having the following problem, i need to be able to log into the firewall with ssh from outside, and nothing should be able to hit the firewall from inside, not even ping from outside i can hit the shadow server, ssh, pi

Re: passing to inside interface

2007-03-20 Thread Lawrence Horvath
On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/03/20 04:41, Lawrence Horvath wrote: > I have the below rule set in my pf.conf, i am having the following > problem, i need to be able to log into the firewall with ssh from > outside, and nothing should be able to h

Re: passing to inside interface

2007-03-20 Thread Lawrence Horvath
192.168.25.100 to any pass in on xl0 inet from any to 192.168.25.201 pass in on xl1 inet from 192.168.25.201 to any pass in on xl0 inet from any to 192.168.25.252 pass in on xl1 inet from 192.168.25.252 to any On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/03/20 06:18, Lawrence Horvath

Re: passing to inside interface

2007-03-20 Thread Lawrence Horvath
On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/03/20 09:24, Lawrence Horvath wrote: > is there a way to tag the packets going to pflog, i can see the > packets being blocked with tcpdump on /var/log/pflog, but i would like > to know what rule is blocking them

pps limit with pf

2007-03-24 Thread Lawrence Horvath
is there a way to limit pps with PF? -- -Lawrence -Student ID 1028219 -CCNA

Re: pps limit with pf

2007-03-24 Thread Lawrence Horvath
qlimit and bandwidth knobs. you're sure you need to control packet rate, not data rate? CK On 3/24/07, Lawrence Horvath <[EMAIL PROTECTED]> wrote: > is there a way to limit pps with PF? > > > > -- > -Lawrence > -Student ID 1028219 > -CCNA > > -- GDB has a

Re: couple of questions

2007-05-06 Thread Lawrence Horvath
Yes, I do believe that you can create a bridge and include the wireless device in the bridge, and this should work as you need it to. if anyone knows different please let me know. On 06/05/07, Paolo Supino <[EMAIL PROTECTED]> wrote: Hi Maxime I know that OpenBSD supports IPSEC very well (ha

authpf wrong shell warning

2007-05-14 Thread Lawrence Horvath
I am trying to set up authpf. I created all the files however i would like to be able to login and then start authpf instead of having a separate user for authpf. when ever i try to start authpf after loging in with ssh i get the below error May 14 22:03:31 freemon authpf: wrong shell for user la

ftpd passive port range

2007-05-24 Thread Lawrence Horvath
I am trying to confine my ftp to a smaller port range by editing net.inet.ip.porthifirst=49152 net.inet.ip.porthilast=65535 is there anything else that uses these variables other than ftpd? and would it be possible to force ftpd into using port 20 as its passive port? this is on 4.0 generic --

Re: ftpd passive port range

2007-05-24 Thread Lawrence Horvath
well i figure if active ftp can work many connectsion off one data port why cant passive ftp i see no problems with it, after all, all the control connections terminate on one port why cant the data On 24/05/07, Darren Spruell <[EMAIL PROTECTED]> wrote: On 5/24/07, Lawrence Horvath &

Reclaim mounted space

2007-06-03 Thread Lawrence Horvath
I have just changed from 1 harddrive into having a root, and a home harddrive. its now working but i had several gigs in the old home that i would like to clear off, how can i clear the old home dir with out unmounting the new home -- -Lawrence

Re: Reclaim mounted space

2007-06-03 Thread Lawrence Horvath
Well my old set up was to have just one harddrive, so my old home is part of the root drive, and since my root drive is in use as root, how would i mount just that part of it? On 03/06/07, Darrin Chandler <[EMAIL PROTECTED]> wrote: On Sun, Jun 03, 2007 at 09:10:34AM -0700, Lawrence H

Re: Reclaim mounted space

2007-06-03 Thread Lawrence Horvath
me mountpoint. DS > On 03/06/07, Darrin Chandler <[EMAIL PROTECTED]> wrote: > > On Sun, Jun 03, 2007 at 09:10:34AM -0700, Lawrence Horvath wrote: > > > I have just changed from 1 harddrive into having a root, and a home > > > harddrive. > > > its now working but

type 2 or 3 pcmcia wireless card

2007-06-03 Thread Lawrence Horvath
I am working with a ThinkPad 365X that i am installing obsd on and would like wireless access on. it supports 2 type II or 1 type III PCMCIA, I wanted a ral card however those only appear to come at the lowest as a CB which i dont believe my thinkpad will support. Any suggestions on a card i coul

Re: type 2 or 3 pcmcia wireless card

2007-06-04 Thread Lawrence Horvath
It does not have any built in USB ports, so unless i can find a typeII or III usb card i got no usb On 04/06/07, Reyk Floeter <[EMAIL PROTECTED]> wrote: On Sun, Jun 03, 2007 at 09:46:44PM -0700, Lawrence Horvath wrote: > I am working with a ThinkPad 365X that i am installing obsd

Re: type 2 or 3 pcmcia wireless card

2007-06-04 Thread Lawrence Horvath
I purchased the orinoco, well see how that goes, thanks for the comment On 04/06/07, Lawrence Horvath <[EMAIL PROTECTED]> wrote: It does not have any built in USB ports, so unless i can find a typeII or III usb card i got no usb On 04/06/07, Reyk Floeter <[EMAIL PROTECTED]> wro

T1 pci card

2007-06-10 Thread Lawrence Horvath
I am looking for a Data T1 card to put in an OBSD firewall/router looking for suggestions on a quality card for under 1000 that OBSD supports reasonably well. digium offers the Wildcard TE120P for about 600 but i was unsure of support where could i find out if such a card is supported with out a

Re: T1 pci card

2007-06-10 Thread Lawrence Horvath
looks like im going sangoma, already emailed sales@ thanks for the input, glad to know someone has one up and working On 10/06/07, Bryan Vyhmeister <[EMAIL PROTECTED]> wrote: On Jun 10, 2007, at 4:15 PM, Lawrence Horvath wrote: > I am looking for a Data T1 card to put in an OBSD

nat trouble accessing web

2007-06-25 Thread Lawrence Horvath
Im having some trouble accessing certain sites from my laptop going through a obsd router doing nat I have 2 tested configurations Laptop--->Cisco1721[doing nat]--->internet > msn.com and Laptop--->Cisco1721--(gre0)>Openbsd[doing nat]--->internet > msn.com in the first setup

Re: nat trouble accessing web

2007-06-26 Thread Lawrence Horvath
I resolved this at least for now by setting no-df on my scrub, im still investigating the mtu On 26/06/07, Daniel Melameth <[EMAIL PROTECTED]> wrote: Sounds like a possible MTU issue... Liberal use of tcpdump should help in diagnosing the problem. On 6/25/07, Lawrence Horvath &

classify scp and ssh

2007-07-07 Thread Lawrence Horvath
Is there a way using pf to distinguish between ssh shell logins, and scp file transfers? -- -Lawrence

Re: Options for 1U server with watchdog?

2007-09-07 Thread Lawrence Horvath
If power is a suspect why not get a UPS, it sounds like even a small one would do, and it would probly work out better than buying a new server? On 07/09/2007, K K <[EMAIL PROTECTED]> wrote: > I am looking for recommendations for a new rackmount server with a > watchdog(4) device fully supported

rate limiting an interface

2006-06-15 Thread Lawrence Horvath
3.9 GENERIC#617 i386 Wanted to know what are the possible ways to rate limit an ethernet interface, if queues in pf will do this, or is any other way, i have a 2meg colo connection and dont wnat to go over it or ill get charged, and the ISP wont cap it, so i have to cap myself. Thanks -- -Lawren

Re: rate limiting an interface

2006-06-15 Thread Lawrence Horvath
On 6/15/06, John R. Shannon <[EMAIL PROTECTED]> wrote: Lawrence Horvath wrote: > 3.9 GENERIC#617 i386 > > Wanted to know what are the possible ways to rate limit an ethernet > interface, if queues in pf will do this, or is any other way, i have a > 2meg colo connection and

Re: rate limiting an interface

2006-06-15 Thread Lawrence Horvath
On 6/15/06, John R. Shannon <[EMAIL PROTECTED]> wrote: Lawrence Horvath wrote: > On 6/15/06, John R. Shannon <[EMAIL PROTECTED]> wrote: >> Lawrence Horvath wrote: >> > 3.9 GENERIC#617 i386 >> > >> > Wanted to know what are the possible ways to rat

turning on PF

2006-06-18 Thread Lawrence Horvath
Im having alittle trouble with my queues in PF i have the following in my pf.conf altq on tl0 cbq bandwidth 100Kb queue {all} queue all bandwidth 100% {default} pass out on tl0 from any to any queue all pass in on tl0 from any to any however i get the following: $ sudo pfctl -e pfctl: pf alre

Re: turning on PF

2006-06-19 Thread Lawrence Horvath
On 6/19/06, Alexander Hall <[EMAIL PROTECTED]> wrote: Lawrence Horvath wrote: > Im having alittle trouble with my queues in PF i have the following in > my pf.conf > > > altq on tl0 cbq bandwidth 100Kb queue {all} > queue all bandwidth 100% {default} > pass out on tl

Re: T1 and DSL failover? redundancy?

2006-06-21 Thread Lawrence Horvath
You can use SNMP to monitor the wan interface on almost all routers, (I know personally about the cisco), so you might set something up that monitors taht, or you could using a dynamic routing protcocal, even rip would do, just something interactive between OBSD firewall and the router, the router

Re: T1 and DSL failover? redundancy?

2006-06-22 Thread Lawrence Horvath
On 6/22/06, L. V. Lammert <[EMAIL PROTECTED]> wrote: At 11:13 PM 6/21/2006 -0700, Lawrence Horvath wrote: >You can use SNMP to monitor the wan interface on almost all routers, >(I know personally about the cisco), so you might set something up >that monitors taht, or you could

Mixing queues in pf

2006-06-29 Thread Lawrence Horvath
Is it possible to mix queue types with pf, for instance all http traffic is sent to a hfsc queue while all ssh traffic is sent to a priq queue, or could you have a master priq queue and child cbq queues under it? thanks -- -Lawrence

binding ftpd

2006-07-02 Thread Lawrence Horvath
Is there any way at all to bind ftpd to a single ip, i would like to keep ftpd running on one ip of my server while i setup and play with proftpd on another ip, the man page for ftpd says nothing about being able to bind but is there any other way, Jerry Rig it if you will. Thanks -- -Lawrence

X not found

2006-07-04 Thread Lawrence Horvath
I have been getting the following error, and wasnt sure if i have to totally install X or can i just install a minimal lib set to get the error to stop, at this time I do not have any parts of X installed. # make ===> qemu-0.8.0p3 uses X11, but /usr/X11R6 not found. Thanks -- -Lawrence

Re: X not found

2006-07-05 Thread Lawrence Horvath
client, then you'll need to install the requisite libs. You'll save yourself a lot of time and headache if you just install the X set. On 7/4/06, Lawrence Horvath <[EMAIL PROTECTED]> wrote: > I have been getting the following error, and wasnt sure if i have to > totally insta

Re: X not found

2006-07-05 Thread Lawrence Horvath
so how do you install that, i was thinking it would just be # pkg_add /home/music/xbase39.tgz Can't resolve /home/music/xbase39.tgz but that didnt work, how do you install that package? On 7/5/06, Joachim Schipper <[EMAIL PROTECTED]> wrote: On Wed, Jul 05, 2006 at 12:03:35AM -070

testing max tcp connections

2006-07-10 Thread Lawrence Horvath
Im using a OpenBSD 3.9 server and a FreeBSD 6.1 server on either end of a firewall to test throughput and max open connections of the firewall, i tested throughput with netstrain(d) but im unsure how to test the max open connections, anyone recommend a program? or script? to test the max number of

Re: Code to execute a command on another tty

2006-07-25 Thread Lawrence Horvath
As long as the permissions are correct you can just redirect, you just need to know what tty your piping to, i used who to check, and you have to be an equal or higher user, my example was done as the same user on both sides, like so: ttyp1: $ echo hello world > /dev/ttyp0 $ ttyp0 $ hello world

Re: Code to execute a command on another tty

2006-07-25 Thread Lawrence Horvath
ere an equivelant here or do > > I need to make my own? On 7/25/06, Lawrence Horvath <[EMAIL PROTECTED]> wrote: > As long as the permissions are correct you can just redirect, you just > need to know what tty your piping to, i used who to check, and you > have to be an equal or hi

pf queue monitoring

2006-08-21 Thread Lawrence Horvath
Is there a way to monitor how much traffic is passing through a queue in bps? Im using 'pfctl -s queue -v' but it seems to only show a running total of packets and bits that have passed through it, and i want to be able to see it in bps anyone know of a way to do this? # uname -a OpenBSD localhos

pf queue skipping

2006-08-23 Thread Lawrence Horvath
I have the following config for my pf.conf and i noticed that nothing shows in the queues for incomming: ##BEGIN_QUEUES## altq on tl0 cbq bandwidth 3000Kb qlimit 200 queue { traffic_out, traffic_in } queue traffic_out bandwidth 1500Kb qlimit 200 cbq { \ other_out, ssh_out, ftp_data_out,

Re: pf queue skipping

2006-08-23 Thread Lawrence Horvath
Yes it says its only "useful" for outbound, that doesnt mean that it shoudnt still try to queue inbound, which it does sorta do as per my pfctl -vvs queue, however it skips on parent queue for some reason On 8/23/06, Jason Dixon <[EMAIL PROTECTED]> wrote: On Aug 23, 2006, at 6

Re: Oldest Server you run

2006-10-12 Thread Lawrence Horvath
$ sysctl hw hw.machine=i386 hw.model=Intel Pentium III ("GenuineIntel" 686-class, 512KB L2 cache) hw.ncpu=2 hw.byteorder=1234 hw.physmem=268001280 hw.usermem=267599872 hw.pagesize=4096 hw.disknames=sd0,sd1,sd2,cd0,fd0 hw.diskcount=5 hw.cpuspeed=449 On 10/12/06, Falk Husemann <[EMAIL PROTECTED]>

Re: Is there a "deluser" equivalent in OpenBSD?

2006-10-28 Thread Lawrence Horvath
On 10/28/06, Leonardo Rodrigues <[EMAIL PROTECTED]> wrote: Hello everyone, So, I'm trying to set up a samba server, and looking into the smb.conf, there's this command "deluser" that I can't find a "similar" one on OpenBSD to replace it. I need a tool that is able to delete a user from a group,