Re: a trick

2004-03-10 Thread Damien Miller
On Tue, 9 Mar 2004, Claudio Jeker wrote: The best sollution is to have a full view (with no default route) via bgp and use no-route. So you get a auto-update bogon filter. It is more accurate than those lists because it is live and knows about the not announced but IANA allocated blocks. How

Re: a trick

2004-03-10 Thread Claudio Jeker
On Wed, Mar 10, 2004 at 06:43:33PM +1100, Damien Miller wrote: On Tue, 9 Mar 2004, Claudio Jeker wrote: The best sollution is to have a full view (with no default route) via bgp and use no-route. So you get a auto-update bogon filter. It is more accurate than those lists because it is

Re: a trick

2004-03-10 Thread Henning Brauer
* Damien Miller [EMAIL PROTECTED] [2004-03-10 09:37]: Abusers use BGP to advertise reachability to those blocks in the first place well, it's mostly a myth that you can simply advertise something in bgp. There's basically no such thing as unfiltered bgp left. if such bogons are advertized

Re: pfctl: Cannot allocate memory

2004-03-10 Thread Cedric Berger
Greg Wooledge wrote: Cedric Berger ([EMAIL PROTECTED]) wrote: Here is the problem I think: 40MB of kernel memory for routing table entries... It might be PF table stuff..., not sure yet. Do you reload your ban table very often? Whenever I notice a new IP address that needs my attention.

Re: example pf.conf

2004-03-10 Thread Curt Micol, PPC
You can also try: https://www.solarflux.org/pf // Asenchi On Tue, 9 Mar 2004 13:06:23 -0800 Gary [EMAIL PROTECTED] wrote: I've been searching for some examples of pf.conf but all I can find are examples for a gateway/firewall with emphasis towards NAT. I need to set up packet filter on a stand

Re: pfauth like system for modifying pf tables

2004-03-10 Thread Armin Wolfermann
* Russell Fulton [EMAIL PROTECTED] [10.03.2004 05:10]: In mid January I asked if anyone had written a daemon to allow one to modify pf tables from another system (eg an authentication system where people are logging in). Someone replied off list and now I that I really need the

RE : ftp on dmz

2004-03-10 Thread borrut
Hi, I've just finished to set up a glftpd behing my magic OpenBSD box. Like you I had problems with the ftp-data ports (cannot list but connected to the ftp). All I've done was correct according to this: http://www.openbsdjournal.org/howto/pfftp.html I suggest you two things: 1/ test ftp-data

Re: example pf.conf

2004-03-10 Thread Per-Olov Sjöholm
Gary said: I've been searching for some examples of pf.conf but all I can find are examples for a gateway/firewall with emphasis towards NAT. I need to set up packet filter on a stand alone (single NIC) OpenBSD 3.4 box which will run ssh, httpd, dns, smtp, pop3. Please can anyone point me

pf plans, please am I on track?

2004-03-10 Thread Dr. David Johnson
Hi this is David, please know I posted this today on OpenBSD.org misc list - I hope this is not considered 'cross-posting' if I tell you that first, so as to warn you so you don't bother with answering me on both lists. *** I really need help, pf gurus! I'm ok with setting up hosts on an