Loading dummynet via loader.conf doesn't work

2010-06-02 Thread Dmitry Pryanishnikov
Hello! In RELENG_6 loading dummynet.ko from /boot/loader.conf dummynet_load=YES works correctly. However in fresh RELENG_8 it results in strange behaviour: loader shows /boot/kernel/dummynet.ko getting loaded, then adds loading required module 'dummynet'. However 'lsmod' from loader and

Queue size maximum too low [Was: ipfw versions - /usr/src/sbin]

2006-10-09 Thread Dmitry Pryanishnikov
Hello! On Fri, 6 Oct 2006, Andrey V. Elsukov wrote: the 100 need to be changed to 10,000 to allow for a bigger queue according to the customer that wants to use ipfw + dummynet for testing gigE thruput I think this is not good idea. This limit will be checked later in kernel, and if you'll

Re: Getting kern/82724 (ipfw defaultroute/setnexthop) committed

2006-04-20 Thread Dmitry Pryanishnikov
Hello! On Thu, 20 Apr 2006, Ari Suutari wrote: I have now been running two firewalls with patch included in kern/82724 since the pr was created (since june, 2005). Works ok, not a single panic or other problem. I also think that both 'setnexthop' and 'defaultroute' are very useful missing

Re: Still ARP Spoof question.

2006-04-15 Thread Dmitry Pryanishnikov
Hello! On Sat, 15 Apr 2006, hshh wrote: So, is it no way to defend arp spoof attack by FreeBSD? It has always worked for me to simply set up static ARP entries using arp -S hostname ether_addr At least, under RELENG_4 this prevents IP = MAC pair from being overwritten. I believe that it

Re: IPFW1-2 regression: in/out/via any ignored

2006-03-29 Thread Dmitry Pryanishnikov
Hello! On Thu, 23 Mar 2006, Luigi Rizzo wrote: For locally generated packets i admit 'recv any' may be of some use, and this is unsupported. There are probably workaround such as 'src-ip me' Oops! How can one know that feature which is documented from the beginning, which worked in ipfw1 -