Re[2]: PF - Removing Server from Pool when Service is Down

2006-12-13 Thread Charles Sprickman
On Wed, 13 Dec 2006, Sylwester S. Biernacki wrote: On Wednesday, December 13, 2006, at 15:59:02, Karl O. Pinc wrote: OpenBSD has ifstated, which is pretty simple to configure state engine. it's true, but it's unusable here - if machine get 100% cpu load it won't put down their interface.

PFSense?

2006-01-01 Thread Charles Sprickman
Hello all, I've been spending part of my day here toying with pfsense (http://www.pfsense.org) while I figure out why OpenBSD past 3.5 panics on boot on my old hardware... It looks very interesting so far. I do wish that they'd based it on OpenBSD instead of FreeBSD. It's basically a very

RE: ATT CallVantage VoIP and pf?

2005-11-28 Thread Charles Sprickman
On Mon, 28 Nov 2005, MH wrote: Mmm... Make sure the adapter is supported under OpenBSD, or however you plan to 'rig' it.. VoIP is SIP/port 5060. Keep in mind 5060 is just the SIP signalling port. If you're looking to match for altq, you really should be interested in the RTP streams,

Re: PF and VoIP

2005-10-30 Thread Charles Sprickman
On Sun, 30 Oct 2005 [EMAIL PROTECTED] wrote: So, with this rules, the ATA receive calls, and I speak and my contrapart listen me, but I can't hear him. Any idea? Anybody can talk on VoIP behind NAT? I've had the same problem myself. My pf.conf was just like yours, but I had to configure my

Re: CARP and switches

2005-10-08 Thread Charles Sprickman
On Sat, 1 Oct 2005, Ryan McBride wrote: On Fri, Sep 30, 2005 at 04:40:26PM +0200, Henning Brauer wrote: * Charles Sprickman [EMAIL PROTECTED] [2005-09-29 22:51]: The design seems to assume that one MAC address can only exist on one port at a time, correct? no, not at all. There have been so

tftp through pf w/nat

2005-10-06 Thread Charles Sprickman
Hi, Is it possible, given the nasty way that tftp works to get natted clients to talk to an outside tftp server? In this case the tftp clients are a handful of cisco phones that want to periodically pull down their configs. A failed request looks like this: (tcpdump of phone asking for

CARP and switches

2005-09-29 Thread Charles Sprickman
generally have been using ipf on FBSD as a simple host firewall, so I'm not up to speed on the neat stuff. Thanks, Charles ___ Charles Sprickman NetEng/SysAdmin Bway.net - New York's Best Internet - www.bway.net [EMAIL PROTECTED] - 212.655.9344

Re: Using state and routing inbound traffic

2005-08-05 Thread Charles Sprickman
On Fri, 5 Aug 2005, Karl O. Pinc wrote: Au-contrar (sp), if there's a big fat ftp download filling the pipe I want to drop some of it's packets to favor, for example, VOIP traffic. But when there's no VOIP traffic I want ftp to be able to (almost) fill the pipe. So, I start dropping packets