NTP timeout question

2014-03-07 Thread Jeff Simmons
Is there a way to make ntpd ignore these alarms, or perhaps set them to a time less than fifty minutes (average)? -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any

Re: Single process needing a lot of memory

2013-12-13 Thread Jeff Simmons
need more than 640k RAM! -- Bill Gates, 1981 -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right? -- My Life

Re: Single process needing a lot of memory

2013-12-13 Thread Jeff Simmons
On Friday, December 13, 2013 01:23:15 pm Ted Unangst wrote: On Fri, Dec 13, 2013 at 12:33, Jeff Simmons wrote: Nobody will ever need more than 640k RAM! -- Bill Gates, 1981 I realize this is often quoted in jest, but I've taken to setting the record straight because I think the truth

Quick question on PFS in ipsec

2013-09-11 Thread Jeff Simmons
connection? I'm especially interested in OpenBSD - Cisco tunnels. -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right

Non-standard ipsec behavior

2012-12-02 Thread Jeff Simmons
isakmpd from rc.conf.local. Not a big deal, just seems a kinda funky way to do things. -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing

Re: Non-standard ipsec behavior

2012-12-02 Thread Jeff Simmons
On Sunday, December 02, 2012 10:08:37 pm Otto Moerbeek wrote: On Sun, Dec 02, 2012 at 07:19:34PM -0800, Jeff Simmons wrote: On several of the boxes that I admin, starting ipsec on boot in the normal way, i.e. from rc.conf.local, doesn't work. The problem 'seems' to be that ipsec is looking

Replacement for an outbound pf redirect

2012-08-20 Thread Jeff Simmons
missing something simple, but is there an easy way to do this? -- Jeff Simmons j...@j-simmons.net Simmons Consulting - Network Engineering, Administration, Security

Enforcing symmetric routing

2012-07-30 Thread Jeff Simmons
haven't found anything for connections to the router itself. -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security

Re: Enforcing symmetric routing

2012-07-30 Thread Jeff Simmons
On Monday, July 30, 2012 03:38:58 pm you wrote: On 2012-07-30, Jeff Simmons jsimm...@goblin.punk.net wrote: Given a machine with two interfaces to the internet, is there a way to enforce symmectric routing (i.e. if1 and if2 with if1 as the default route, can connections to if2 be somehow

3ware Escalade 8006-2LP support?

2012-05-27 Thread Jeff Simmons
distributions support for the 8006 was flaky due to 3ware's lack of cooperation. Am I correct in assuming that this is the reason for the install hang?, and is there anything that can be done to get an install on this particular setup? Thanks for any help. -- Jeff Simmons

Failover VPN tunnels

2012-03-12 Thread Jeff Simmons
to 'manually' insert/remove SAs and flows via ipsecctl. Does anyone have any thoughts as to which approach is preferable and the relative merits of each? -- Jeff Simmons jsimm...@goblin.punk.net

mcl pool problem

2010-09-15 Thread Jeff Simmons
exception 16 fdc0 at isa0 port 0x3f0/6 irq 6 drq 2 mtrr: Pentium Pro MTRR support vscsi0 at root scsibus1 at vscsi0: 256 targets softraid0 at root root on wd0a swap on wd0b dump on wd0b -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network

Re: IPSEC bringing down networking 1.1

2010-01-09 Thread Jeff Simmons
On Saturday 09 January 2010 08:57, Toni Mueller wrote: Hi, On Tue, 05.01.2010 at 12:44:49 -0800, Jeff Simmons jsimm...@goblin.punk.net wrote: fw:$ netstat -nr tip: netstat -rnf encap results elided Encap: Source Port Destination Port Proto SA(Address/Proto/Type/Direction

Re: IPSEC bringing down networking 1.1

2010-01-09 Thread Jeff Simmons
Apologies for the previous empty message. On Saturday 09 January 2010 08:57, Toni Mueller wrote: Hi, On Tue, 05.01.2010 at 12:44:49 -0800, Jeff Simmons jsimm...@goblin.punk.net wrote: results elided Encap: Source Port Destination Port Proto SA(Address/Proto/Type/Direction) expected

IPSEC bringing down networking 1.1

2010-01-05 Thread Jeff Simmons
, and then this shows up. Any ideas as to what could be causing this? -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right? -- My Life

IPSEC bringing down networking

2010-01-02 Thread Jeff Simmons
MTRR support softraid0 at root root on wd0a swap on wd0b dump on wd0b -- Jeff Simmons jsimm...@goblin.punk.net Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right? -- My

Re: httpdump?

2008-11-22 Thread Jeff Simmons
On Saturday 22 November 2008 18:19, you wrote: On Thu, Nov 20, 2008 at 9:48 AM, Jeff Simmons [EMAIL PROTECTED] wrote: I need, at a minimum, which virtual server at a particular IP address is being accessed, and the contents of any GET commands (methods). If there's a way to get this via

Re: httpdump?

2008-11-20 Thread Jeff Simmons
On Wednesday 19 November 2008 20:48, John Jackson wrote: On Wed, Nov 19, 2008 at 08:18:00PM -0800, Jeff Simmons wrote: I need, at a minimum, which virtual server at a particular IP address is being accessed, and the contents of any GET commands (methods). If there's a way to get this via

httpdump?

2008-11-19 Thread Jeff Simmons
Anyone know of a text-based program that will dump http protocol packets? Like tcpdump, but for http. -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're

Re: httpdump?

2008-11-19 Thread Jeff Simmons
80? Jeff Simmons wrote: Anyone know of a text-based program that will dump http protocol packets? Like tcpdump, but for http. -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any

Spamd - whitelisting round robin mail servers?

2008-09-03 Thread Jeff Simmons
they are all out of date, and the link to the cvs list is broken. Anyone know of any uptodate compilations? -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're

Re: Spamd - whitelisting round robin mail servers?

2008-09-03 Thread Jeff Simmons
servers are doing this, and who they all are. There's spam blacklists all over the place, and a lot of people are doing greylisting nowadays. Isn't anybody collating these guys? On Wednesday 03 September 2008 20:57, Marco S Hyman wrote: Jeff Simmons writes: all out of date, and the link

Can't read authpf rules with pfctl

2007-10-21 Thread Jeff Simmons
-a '*' -sr firewall:~#pfctl -a '*' -sr anchor * all { pfctl: DIOCGETRULES: Invalid argument } Am I misreading the man page in assuming that both of these commands should return the block line that the authme login set up, or is something else going on? -- Jeff Simmons

isakmpd vs. Cisco 3002

2007-10-15 Thread Jeff Simmons
to notification type NO_PROPOSAL_CHOSEN -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right? -- My Life With The Thrill Kill Kult

Re: Cisco 3002 VPN client to OpenBSD?

2007-10-05 Thread Jeff Simmons
OS can USE one of our proprietary tunnels. Etc. I know that native OpenBSD tools (ipsecctl, isakmpd) work fine with the Cisco 3005 concentrator, I'm running several. I've got a 3002 loaner coming, I'll post the results. -- Jeff Simmons [EMAIL PROTECTED

Cisco 3002 VPN client to OpenBSD?

2007-10-03 Thread Jeff Simmons
-password and user-password entries for connections to the 3000. Most of the rest of the configuration is pretty standard, if old (3des, sha1). I'd rather find out before we buy one. Thanks! -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering

ipsec.conf - format of key specification

2007-09-13 Thread Jeff Simmons
specifies a 'hexadecimal string'. The same thing happens if the key is entered into a file and the 'authkey file' directive is used. Any help would be appreciated. -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security

Flags for WD driver

2007-05-14 Thread Jeff Simmons
Is there any documentation on the exact functions of the flags that can be passed to WD via config? I haven't found any, and I'm not a good enough C programmer to tease them out of the source. -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network

Re: Flags for WD driver

2007-05-14 Thread Jeff Simmons
On Monday 14 May 2007 11:57, Ted Unangst wrote: On 5/14/07, Jeff Simmons [EMAIL PROTECTED] wrote: Is there any documentation on the exact functions of the flags that can be passed to WD via config? I haven't found any, and I'm not a good enough C programmer to tease them out of the source

Preferred hardware vendors

2007-02-22 Thread Jeff Simmons
for the development of OpenBSD (or both)? A company I can feel good about dealing with? -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security By these actions SRL became the first to operate intentionally lethal

Redundant web servers

2007-01-18 Thread Jeff Simmons
to be a 'standard' way of doing this. Does anyone have any recommendations? -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security Delirium: There must be a word for it ... the thing that lets you know that time

Forcing a password change on first login

2006-10-04 Thread Jeff Simmons
for a user, a password expire time is NOT set, even with passwordtime set in login.conf. Is there a way to change this behavior without modifying the source? Thanks! -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration

Preventing password reuse

2006-07-03 Thread Jeff Simmons
. -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right? --My Life With The Thrill Kill Kult

Re: Preventing password reuse

2006-07-03 Thread Jeff Simmons
). A trigger on a password change could easily tell if the new password hashes out to one on record and records a hash of the hash if not. DS -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any

Re: Preventing password reuse

2006-07-03 Thread Jeff Simmons
On Monday 03 July 2006 17:51, STeve Andre' wrote: On Monday 03 July 2006 17:37, Jeff Simmons wrote: A client is setting up a password policy, and would like to prevent users from reusing a password for a period of time (four changes ninety days apart). Is there a way to do this, either

Re: Preventing password reuse

2006-07-03 Thread Jeff Simmons
should rather have worried about our customers ... being stupid. Ross Anderson, Security Engineering On Monday 03 July 2006 20:25, L. V. Lammert wrote: On Mon, 3 Jul 2006, STeve Andre' wrote: On Monday 03 July 2006 17:37, Jeff Simmons wrote: I can't resist pointing out

Apache mod_webkit

2006-04-16 Thread Jeff Simmons
AppServer. Any assistance greatly appreciated. -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting - Network Engineering, Administration, Security You guys, I don't hear any noise. Are you sure you're doing it right? --My Life With The Thrill Kill Kult

Problems with 4 port ethernet cards

2005-12-16 Thread Jeff Simmons
netmask effd ttymask pctr: user-level cycle counter enabled dkcsum: wd0 matches BIOS drive 0x80 wd1: no disk label dkcsum: wd1 matches BIOS drive 0x81 root on wd0a rootdev=0x0 rrootdev=0x300 rawdev=0x302 -- Jeff Simmons [EMAIL PROTECTED] Simmons Consulting

Recommendations for pop3s daemon?

2005-06-15 Thread Jeff Simmons
Finding myself in need of a POP3S daemon, I headed over to the ports tree to get the old standar UW, and noticed that there are several of the little devils hiding out in there. Anyone have any recommendations? Favorites? Pros and cons? Reasons to use something other than UW? Any information

ipsecadm problem in 3.7?

2005-06-13 Thread Jeff Simmons
I'm running several OpenBSD VPN gateways using 3.6, and I'm trying to add a 3.7 box into the mix. I've been using rc.vpn and manual keying. But when I tried to fire up the new VPN, the networks never could connect, and the gateway machines lost contact with each other (no ping, no shh, etc.)