Transparent pf firewall with load balance support

2005-07-21 Thread Vinicius Pavanelli Vianna
Hi, Just a little question that came up when designing a firewall system here, can a transparent bridge with pf do load balance to internal server even if the ifaces don't have any IP adresses? I have two ways to develop this firewall, or a transparent bridge on the switch to router link, or an "f

CARP/PFSYNC over USB is possible?

2005-08-29 Thread Vinicius Pavanelli Vianna
I'm currently using an OpenBSD 3.7 as a firewall for my network, since this machines is a 1U rack I can't add an extra ethernet card to it, so I was looking for an alternative solution to use redundancy, since there are plenty of usb ports free can i use an usb-to-usb link over two OpenBSD to do th

PF performance question

2005-09-17 Thread Vinicius Pavanelli Vianna
Hi, I'm using OpenBSD 3.7 with pf and bridge enabled for a transparent proxy, and I'm having some packet loss somewhere in this bridge, since netstat -ni doesn't give me any ierrors i'm beginning to check PF setup, this machine has about 30k packets/s, my question is: how can i see if pf is ok wit

Re: PF performance question

2005-09-19 Thread Vinicius Pavanelli Vianna
Hi, Thanks for the held Jared, I tried to disable pf (pfctl -d) and it continues to loss packets, i changed the rules to use state on all and raised the limit on it to about 300.000, so i think this is not a problem, and since pfctl -d didn't resolve the packet lost i begin to suspect something on

Re: PF performance question

2005-09-19 Thread Vinicius Pavanelli Vianna
is negotiating properly. It might >be half duplex instead of full or something flakey etc. Check the >output of ifconfig. > >Joe > >On 9/19/05, Vinicius Pavanelli Vianna <[EMAIL PROTECTED]> wrote: > > >>Hi, >>Thanks for the held Jared, >> >>

Re: PF performance question

2005-09-19 Thread Vinicius Pavanelli Vianna
jared r r spiegel wrote: >On Mon, Sep 19, 2005 at 03:13:33PM -0300, Vinicius Pavanelli Vianna wrote: > > >>I tried to disable pf (pfctl -d) and it continues to loss packets >> >> ><...> > > >>The count on in and out are dif

Re: Max number of states in pf? (100k? 200k? 1M?)

2005-09-22 Thread Vinicius Pavanelli Vianna
Well, I'm running a similar setup, only Xeon 2.4 dual and running with 300k states, the info so far is: State Table Total Rate current entries89976 searches 2049646948754332.6/s inserts