Buildworld on flacky hardware

2011-03-12 Thread Erik Norgaard
Hi: I previously wrote about buildworld failure, it turns out to be flacky hardware. Since then I have tried to reboot on every failure and start building againg. It compiles fine for a 3-5 hours, then fails at different places. It seems that a new make buildworld does not pickup from where

Buildworld fail

2011-03-08 Thread Erik Norgaard
Hi: I'm trying to upgrade to 8.2, just updated source, cleaned up any leftovers from previous build, but make buildworld fails. I have, alpha# uname -a FreeBSD alpha 8.1-STABLE FreeBSD 8.1-STABLE #0: Sat Oct 2 20:34:13 CEST 2010 root@alpha:/usr/local/obj/usr/local/src/sys/GENERIC i386

Re: Buildworld fail

2011-03-08 Thread Erik Norgaard
On 08/03/2011 12:21, Damien Fleuriot wrote: Contents of your make.conf ? You never know... LOADER_TFTP_SUPPORT= YES #SUP_UPDATE= #SUP=/usr/bin/csup #SUPFLAGS= -g -L 2 SUPHOST=cvsup.uk.FreeBSD.org SUPFILE=/usr/local/src/standard-supfile PORTSSUPFILE=

Re: Buildworld fail

2011-03-08 Thread Erik Norgaard
On 08/03/2011 12:22, Robert Bonomi wrote: Something -- just what is unknown -- triggered an *INTERNAL*COMPILER*ERROR* doing a 'makedep'. Dig through the mailing-list archives for the last week or two. There was another report of the compiler choking. As I recall, there was a follow- up to

Re: Buildworld fail

2011-03-08 Thread Erik Norgaard
On 08/03/2011 12:49, Damien Fleuriot wrote: Can you try with the release tag RELENG_8_2 ? I just nuked src and obj and did a fresh checkout of RELENG_8_2, but the problem persist :( -- stage 1.1: legacy release compatibility

Re: Buildworld fail

2011-03-08 Thread Erik Norgaard
On 08/03/2011 15:52, Greg Larkin wrote: A segfault might be indicative of hardware problems, you may want to check your ram chips ? Reference: http://www.bitwizard.nl/sig11/ Hi, thanks. Did a clean up again, reboot, fsck, reboot again and now it's building. Probably time for an upgrade,

Re: Buildworld fail

2011-03-08 Thread Erik Norgaard
On 08/03/2011 21:16, Michael J. Kearney wrote: Would anyone agree that it us possible the hardware console... logging in from a remote terminal has corrected my own segfaults on substandard hardware... Depends on the hardware I guess. I am building everything remotely. I do know however

Re: can't use godaddy SSL cert

2010-11-28 Thread Erik Norgaard
On 28/11/10 18.51, bluethundr wrote: Yes the hostname is in the CN of the cert file. So I agree that -h is not the issue. :) [r...@vircent03:~]#ldapsearch -h ldap -b dc=summitnjhome,dc=com -Z -D cn=Manager,dc=summitnjhome,dc=com (objectclass=sudoRole) -W Maybe I didn't make myself clear: the

Re: can't use godaddy SSL cert

2010-11-25 Thread Erik Norgaard
On 25/11/10 17.26, bluethundr wrote: I have setup the certificate chain in my slapd.conf like so: [r...@lbsd2:/usr/home/bluethundr]#grep -i tls /usr/local/etc/openldap/slapd.conf## TLS options for slapd TLSCipherSuite HIGH:MEDIUM:+SSLv2 TLSCertificateFile

Re: TLS enabled LDAP, clients fail to connect

2010-11-22 Thread Erik Norgaard
On 21/11/10 23.20, bluethundr wrote: I am attempting to setup SSL/TLS support on my openLDAP 2.4 server on FreeBSD. ... [r...@virtcent08:/etc/openldap/cacerts]#openssl s_client -connect ldap.summitnjhome.com:389 -showcerts -CAfile gd_bundle.crt CONNECTED(0003) 3156:error:140790E5:SSL

OT: Racoon error reference

2010-10-22 Thread Erik Norgaard
Hi: I am trying to set up racoon, but have a number of error messages that I have no reference to their meaning or solution, like ERROR: Cannot record event: event queue overflow ERROR: no policy found ERROR: failed to get proposal from responder ERROR: unknown Informational exchange received

Re: OT: Racoon error reference

2010-10-22 Thread Erik Norgaard
On 22/10/10 12.32, Erik Norgaard wrote: ERROR: Cannot record event: event queue overflow ERROR: no policy found ERROR: failed to get proposal from responder ERROR: unknown Informational exchange received and: ERROR: policy found, but no IPsec requried Erik

Re: WiFi HotSpot

2010-10-18 Thread Erik Norgaard
On 18/10/10 21.53, Maile Halatuituia wrote: Anybody have a hint how to implement software as an internet hotspot. OpenBSD based. This is usually a question of: - providing an interface that is reasonable user friendly for users to authenticate against, some sort of web interface, apache and

IPSec/racoon key time to live

2010-10-14 Thread Erik Norgaard
Hi: I'm up against configuring a number of different systems with host-host IPSec AH-only. The systems use different versions of racoon. Questions: - Must the key lifetime be the same in both ends? - Can key lifetime be configured per host-host connection? Thanks, Erik -- Erik Nørgaard

Re: Open Mail Relay

2010-08-15 Thread Erik Norgaard
On 15/08/10 13.57, pe...@vfemail.net wrote: Assume, as Mr. Bonomi suggests, that some bad guy has installed some type of additional mailer on the machine or another machine that's allowed to relay mail. How would I go about locating that other mailer? If the messages are indeed relayed

Re: fetchmail ssl certificate verification problem in FreeBSD 8.1

2010-08-15 Thread Erik Norgaard
On 15/08/10 21.38, Dan Strick wrote: I can get rid of the message by removing the ssl option from the user line but then fetchmail would not even try to use ssl. Why would the old fetchmail be better able to verify the server's ssl certificate? Has openssl changed? Where is the openssl

Re: Open Mail Relay

2010-08-14 Thread Erik Norgaard
On 14/08/10 15.29, pe...@vfemail.net wrote: I have a machine running FreeBSD, sendmail and majordomo. I have someone who is on one of those majordomo lists complaining that they are receiving spam from me. The complainer says I have an open mail relay that I need to fix. When somebody

Re: ssh under attack - sessions in accepted state hogging CPU

2010-08-10 Thread Erik Norgaard
On 10/08/10 05.13, Matt Emmerton wrote: I'm in the middle of dealing with a SSH brute force attack that is relentless. I'm working on getting sshguard+ipfw in place to deal with it, but in the meantime, my box is getting pegged because sshd is accepting some connections which are getting stuck

Re: Wifi AP behind FreeBSD

2010-07-28 Thread Erik Norgaard
On 28/07/10 19.48, DadAN wrote: I wanna just ask if I really need setup nat? Because I think that it will by enought with nat by wifi router (dlink) connected to second nic ? And setup routing between nic's? In that setup, what you're looking for is bridging, take a look here:

Re: Wifi AP behind FreeBSD

2010-07-28 Thread Erik Norgaard
On 28/07/10 22.43, Maile Halatuituia wrote: If you will have a BSD Box you do not need to have that Dlink Router. Co's DHCP, Router can handle by the FreeBSD in addition to Hotspot Login. Lots and lots of manual for that on the Google. As I understand OP the DLink is required for the DSL

Re: Wifi AP behind FreeBSD

2010-07-28 Thread Erik Norgaard
On 28/07/10 19.48, DadAN wrote: Hello, I wanna just ask if I really need setup nat? Because I think that it will by enought with nat by wifi router (dlink) connected to second nic ? And setup routing between nic's? Sorry, I think I misread or misunderstood your question in my previous reply.

Re: ipnat.conf - map and rdr won't work!

2010-07-23 Thread Erik Norgaard
On 23/07/10 18.58, alexus wrote: i just did jail on public ip where i dont need to use ipnat, so obviously that works fine no problem not really what i wanted though but as a temporary fix its fine... With all respect, I think you should start liking this solution, because for all I

Re: Help with setting up a mail server

2010-07-20 Thread Erik Norgaard
On 20/07/10 15.26, Aryeh M. Friedman wrote: I am a consultant and was retained by my client to setup qmail or exim on a VPS running 8.0-STABLE (i386). After setting up the DNS (A record and MX record) we have been unable to send or receive mail. The client has/had a working script for

Re: ipnat.conf - map and rdr won't work!

2010-07-20 Thread Erik Norgaard
On 20/07/10 18.02, alexus wrote: On Mon, Jul 19, 2010 at 12:38 PM, Erik Norgaardnorga...@locolomo.org wrote: On 19/07/10 16.46, alexus wrote: Can't help you more, really, you need to investigate where packets are dropped, tcpdump is a great tool and the man-page is excelent, can't explain it

Re: ipnat.conf - map and rdr won't work!

2010-07-20 Thread Erik Norgaard
On 20/07/10 18.37, alexus wrote: You are running 2 different firewalls at the same time. comment out firewall_enable=YES firewall_type=open and reboot your system. do you know that for a fact or you just guessing?? because first of all it worked before just fine with 2 firewalls second i

Re: ipnat.conf - map and rdr won't work!

2010-07-20 Thread Erik Norgaard
On 20/07/10 20.07, alexus wrote: On Tue, Jul 20, 2010 at 12:57 PM, Erik Norgaardnorga...@locolomo.org wrote: plan b is to run natd, but i'd rather run ipnat especially that ipnat used to work before no problem! Maybe move away from what used to work and towards what is working :) Whichever

Re: ipnat.conf - map and rdr won't work!

2010-07-20 Thread Erik Norgaard
On 20/07/10 20.43, alexus wrote: On Tue, Jul 20, 2010 at 2:16 PM, Aizaaiz...@comclark.com wrote: Just because 2 firewalls at same time didn't blow up in your face before, sure don't mean they are working correctly. Thats one bad assumption to base debugging on. i never had any problem

Re: ipnat.conf - map and rdr won't work!

2010-07-19 Thread Erik Norgaard
On 19/07/10 16.46, alexus wrote: Use tcpdump, you should see if your rdr/map rules work as expected. Also, pfctl -ss and similar. i don't know how to use tcpdump, can you provide exact syntax so i can run it? The man-page is excelent. tried that, unfortunately not really sure what am i

Re: ipnat.conf - map and rdr won't work!

2010-07-17 Thread Erik Norgaard
On 16/07/10 02.56, alexus wrote: su-3.2# cat /etc/ipnat.rules map fxp0 lama -0/32 rdr fxp0 64.52.58.58 port ssh -lama port ssh tcp What's that first rule supposed to do? provides a NAT within jail Just guessing, try to put the rdr rule first. Another thing, the firewall/nat may

Re: ipnat.conf - map and rdr won't work!

2010-07-15 Thread Erik Norgaard
On 15/07/10 21.17, alexus wrote: On Wed, Jul 14, 2010 at 10:32 PM, alexusale...@gmail.com wrote: I can't put my mind around it, before reboot I was able to ssh in from outside to my jail and right now I can't! What did you change? su-3.2# cat /etc/ipnat.rules map fxp0 lama - 0/32 rdr fxp0

Re: iptables equivaelnt

2010-06-22 Thread Erik Norgaard
On 21/06/10 20.06, pete wright wrote: On Jun 21, 2010, at 10:28 AM, Jean-Paul Natola wrote: I'm particuclary trying to implement some type of rate control as we are getting hammered by spam. I'd humbly suggest pf + spamd if you are concerned specifically about stopping spam, both are

Re: LDAP and LDAPS on the same server ?

2010-05-06 Thread Erik Norgaard
On 06/05/10 14.15, Frank Bonnet wrote: It runs nicely but I want to add LDAPS service on the SAME server. Is it possible ? Yes in fact with OpenLDAP you can have ldap, ldaps and ldap TLS with STARTTLS, the latter runs on the standard ldap port. I have generated cert.crt cert.csr cert.key

Re: dhcpd doesn't sent route information

2010-04-24 Thread Erik Norgaard
On 23/04/10 15:14, Onur Aslan wrote: Do you have any idea? Still haven't solved the problem? I just looked over your dhclient.conf: #prepend domain-name-servers 127.0.0.1; prepend domain-name-servers 8.8.8.8, 8.8.8.4; #request subnet-mask, broadcast-address, time-offset, routers, #

ping: sendto: No buffer space available

2010-04-24 Thread Erik Norgaard
Hi! I'm running FreeBSD 8.0. Some times my network just go down without leaving any errors behind, now this morning it went down but didn't cut my ssh connection to the box and I got this error: ping: sendto: No buffer space available From what I have found this relates to protocols like

Re: dhcpd doesn't sent route information

2010-04-24 Thread Erik Norgaard
On 24/04/10 17:41, Peter Boosten wrote: option domain-name-servers ns1.example.com; option domain-name example.com; A fqdn for a name server? That'll give you a chicken and egg problem, don't you think? No, the dhcpd server resolves the address and sends the ip to the clients.

multishell user profile

2010-04-21 Thread Erik Norgaard
Hi: I need to create a user profile that works in different shells, particularly bash, csh and ksh. It seems that these does not read the same files and/or in the same order. So, how do I configure the shell profiles without configuring each shell separately? Also, I can't find information

Re: PXE + sysinstall(8) install.cfg: DHCP Attribute to map install config/policy to system MAC?

2010-04-21 Thread Erik Norgaard
On 21/04/10 21:59, Brian A. Seklecki (CFI NOC) wrote: All: The install.cfg mechanism is pretty wicked. Unfortunately, there doesn't seem to be a really efficient way to provide new clients (or class of clients) an install.cfg without rebuilding an MFSROOT image. Possibly a

Re: hacked?

2010-04-14 Thread Erik Norgaard
On 15/04/10 00:56, Steve Franks wrote: I don't have bsdstats or similar that I'm aware of installed, so this smells bad: Firewall is showing repeated attempts from your FreeBSD machine to connect to port 25 (standard SMTP mail port) on a server in Belgium. This implies something on your system

Syslog to log remote nodes

2010-04-10 Thread Erik Norgaard
Hi: I want my syslog to log remote nodes, in particular my access point and router, which authenticates users against my freeradius server. In /etc/rc.conf I've got: syslogd_flags=-C -a 192.168.0.0/23 -a 172.16.0.0/23 -vv In /etc/syslog.conf I've got first the entries for the system, no

Re: Outdoor wireless - has anyone used Ubiquiti power stations?

2010-04-07 Thread Erik Norgaard
On 07/04/10 22:02, Modulok wrote: List, This might be a little off topic, but it still involves FreeBSD. I figured this list has many a smart folk, so I'd ask here. If I buy two of these Ubiquiti power station 2's, I can set them up to provide a long distance ethernet link to my BSD box right?

Re: SSH root login with keys only

2010-04-05 Thread Erik Norgaard
On 05/04/10 01:35, Marcin Wisnicki wrote: PasswordAuthentication is already disabled (by default). I need to disable ChallengeResponseAuthentication however: /etc/ssh/sshd_config line 131: Directive 'ChallengeResponseAuthentication' is not allowed within a Match block Same thing for

Re: SSH root login with keys only

2010-04-04 Thread Erik Norgaard
On 04/04/10 23:04, Marcin Wisnicki wrote: Is it possible to configure sshd such that both conditions are met: 1. Root will be able to login only by using keys 2. Normal users will still be able to use pam/keyboard-interactive Yes, you can create a Match block with the criteria User, something

OT: Programming perl, BerkeleyDB/MLDBM

2010-03-27 Thread Erik Norgaard
Hi: I have been searching for the appropriate perl mailing list, but no avail. I'm trying to build a database with Berkeley DB and MLDBM for a multi dimensional hash structure, my $hdbm = tie %host, 'MLDBM', -Filename = $dbdir/host.db, -Flags = DB_CREATE|O_RDWR or die Cannot open

Re: The download file is corrupt

2010-03-25 Thread Erik Norgaard
On 25/03/10 07:57, trevor who wrote: Hi guy's, I downloaded the DVD version freeBSD version 8 and went to unpack it and got these messages from winrar. ! D:\FreeBSD\8.0-RELEASE-i386-dvd1.iso.gz: Unexpected end of archive

Re: diskless dhclient

2010-03-22 Thread Erik Norgaard
On 22/03/10 21:35, Mats Lindberg wrote: I've tried to get my freebsd diskless system to get hold of some of the dhcp-options. E.g. my dhcp-server will always be the nfs-server as well. So I was hoping to create the /etc/fstab with the the dhcpd's ip as the nfs server. Thus not needing to have

Re: securing sshd

2010-03-21 Thread Erik Norgaard
On 21/03/10 02:27, Peter wrote: On the same line, portknocking with pf: Port knocking suck: If you have to knock a single time on the secret port you might just have no added security at all, could be that the port scanner first knocked on the secret port then on the ssh port. If you

Re: securing sshd

2010-03-20 Thread Erik Norgaard
On 20/03/10 14:18, Jamie Griffin wrote: I've been reading up on securing sshd after being bombarded with attempted logins. Hi! First step to ssh security is: Don't panic! Take your time to read the logs and understand what's going on. So, you've got bombarded with login attempts, but they

Re: securing sshd

2010-03-20 Thread Erik Norgaard
On 20/03/10 17:14, Jerry wrote: Seriously, disabling password log-ins and using key authentication is extremely secure. Do make sure that you password protect your keys however. In any event, if you laptop or whatever is stolen, you have more than just one problem to contend with anyway. I

Re: securing sshd

2010-03-20 Thread Erik Norgaard
On 20/03/10 18:23, Jamie Griffin wrote: The reason I went with that decision is because I only expect to be logging in to the server from two locations: at home or from a computer at my university In that case, the best thing you can do is figure out the IP ranges of either location.

Re: bruteforce protection howto

2010-03-20 Thread Erik Norgaard
On 20/03/10 23:17, Vadkan Jozsef wrote: What's the best method to ban that ip [what is bruteforcig a server] what was logged on the logger? I need to ban the ip on the router pc. Take your time to think about if this is indeed the right solution. 1st: You need to decide which is the right

FreeBSD and vmware

2010-03-17 Thread Erik Norgaard
Hi: I have a dual boot Windows/FreeBSD which I use for work, I just tried today to create a virtual machine with vmware on windows to start up the installed FreeBSD. This works except for three problems: - The disk device is renamed, I suppose I can just dublicate the entries in the fstab,

Re: FreeBSD and vmware

2010-03-17 Thread Erik Norgaard
On 17/03/10 21:40, Steve Polyack wrote: On 03/17/10 16:34, Erik Norgaard wrote: - I can't see the network devices from vmware Do you mean you can't see a NIC from within FreeBSD on top of VMware? You will have to choose Other (64-bit) for the OS type and/or choose the e1000/Intel1000 device

Re: Generating a random hostname

2010-03-17 Thread Erik Norgaard
On 17/03/10 23:06, Peter Steele wrote: Is there any facility in FreeBSD for generating a random hostname? We have a template with a fixed hostname that has to be changed after the template is closed. It would be useful to have a hostname generated randomly. uuidgen? this command may be used

Re: Generating a random hostname

2010-03-17 Thread Erik Norgaard
On 17/03/10 23:06, Peter Steele wrote: Is there any facility in FreeBSD for generating a random hostname? We have a template with a fixed hostname that has to be changed after the template is closed. It would be useful to have a hostname generated randomly. uuidgen may do the job for you,

Berkeley DB upgrade

2010-03-13 Thread Erik Norgaard
Hi: I want to upgrade my BerkeleyDB, I have some 500MB in BDB 43. - What is the latest stable version? - Is there any way of determining if datafiles are compatible across versions? - Is there any tool for migrating between versions? Thanks, Erik -- Erik Nørgaard Ph:

Re: [OT] ssh security

2010-03-09 Thread Erik Norgaard
On 10/03/10 07:16, per...@pluto.rain.com wrote: but logic tends to tell me that is I have no prior knowledge about the person I am about to talk to, anybody (MIM) could pretend to be that person. True. Cryptography by it self does not solve the identity problem. The pre-shared information

Re: Thousands of ssh probes

2010-03-08 Thread Erik Norgaard
On 08/03/10 18:56, Jason Garrett wrote: Much better, restrict the client access to certain ranges of IPs. The different registries publish ip ranges assigned per country and you can create a list blocking countries you are certain not to visit, you can use my script:

Re: Thousands of ssh probes

2010-03-07 Thread Erik Norgaard
On 07/03/10 21:41, dacoder wrote: has anybody suggested having sshd listen on a high port? Any number will do, think about it: a. The attacker doesn't really care which host is compromised any will do, and better yet someones home box as it is more difficult to trace him. In that case he

Re: Thousands of ssh probes

2010-03-05 Thread Erik Norgaard
On 05/03/10 13:54, John wrote: My nightly security logs have thousands upon thousands of ssh probes in them. One day, over 6500. This is enough that I can actually feel it in my network performance. Other than changing ssh to a non-standard port - is there a way to deal with these? Every

static build of usr.bin/host fails to link

2010-02-24 Thread Erik Norgaard
Hi: I am trying to build a custom crunch file for pxeboot/jumpstart. I have taken the make files from rescue as a template adding the extras I need. But I have problem linking usr.bin/host in the crunch file, I can't figure out what libraries to link with and include with CRUNCH_LIBS+= on

Re: Sysinstall Post-install System Management

2010-02-19 Thread Erik Norgaard
On 19/02/10 20:42, Programmer In Training wrote: Any clues or alternate ways of getting this done? IIRC you first need to load the linux and linprocfs kernel modules and mount linproc. BR, Erik -- Erik Nørgaard Ph: +34.666334818/+34.915211157 http://www.locolomo.org

Re: Cleaning up after attack?

2010-02-15 Thread Erik Norgaard
On 15/02/10 11:13, Dr. Jennifer Nussbaum wrote: Hi. I have an up-to-date FreeBSD 7.2 box that has been compromised. Someone aparently got in to an account with certain admin priveleges and has been sending spam. I disabled the account, shut off my MTA and used pf to block all traffic to port

Re: custom kernel

2010-02-14 Thread Erik Norgaard
On 14/02/10 02:16, Derek Funk wrote: My kernel is basiclly is the generic kernel just with some added options and removed devices i don't have. I have built and installed many times after installation. I play around with this machine a lot and just want to be able to have my kernel installed at

Re: custom kernel

2010-02-13 Thread Erik Norgaard
On 13/02/10 04:08, Derek Funk wrote: I am trying to find how to install a custom kernel at installation. I have found an option in sysinstall to select a kernel. How do I add my own to the options so I can select it? I think the standard procedure is to install the generic kernel at

How to run cron scripts (310.locate) in chrooted env.

2010-02-09 Thread Erik Norgaard
Hi: I have a setup with diskless clients mounting /var/diskless/FreeBSD read-only as root file system. How do I configure cron/locate.rc to run on the server such that the locate database is relative to the root for the diskless systems? I could do a chroot and run it within this

How to set loader password

2010-02-06 Thread Erik Norgaard
Hi: I was looking in /boot/loader.rc and found these lines: \ Tests for password -- executes autoboot first if a password was defined check-password OK, great, so: How do I set this password? What does it protect? Didn't find documentation in loader(8) and no man-page for loader.rc. Thanks,

Howto run privileged commands on login/logout

2010-02-06 Thread Erik Norgaard
Hi: I'm playing around with diskless operation. I'd like to be able to run privileged commands when a user logins or logs out: - on login, nfs mount the user's home directory (ok, not critical, I can mount /home) - on logout a system reboot to clean up any temporary files left from the

specifying nfs root in loader.conf with vfs.root.mountfrom

2010-02-05 Thread Erik Norgaard
Hi: OK, I know I'm not doing this the easy way, don't try to convince me about other ways :) I'm doing PXE boot diskless, fetching the GENERIC kernel with TFTP. Problem is that since the kernel is fetched with tftp, there is no nfs root file system mounted when kernel finish loading.

Re: adduser and single-user groups

2010-01-27 Thread Erik Norgaard
On 27/01/10 19.05, John wrote: Could someone point me in the direction of enlightenment with regard to the value add of the group per user approach that adduser uses? Is that a FreeBSD thing, or a *BSD thing, or a unix-like-universe thing, or what? Many systems do this AFAIK. IIRC, the point

Re: pf rules

2010-01-24 Thread Erik Norgaard
Doug Hardie wrote: 1. pf allows short cuts, but these also makes it more difficult to debug. I'd separate NAT from filtering, Ok. I guess you want some white space between them? Here it is with the white space and comments: ext_if=dc0 table blackhole persist file /etc/blackhole

Re: automating network configuration

2010-01-24 Thread Erik Norgaard
Romain Garbage wrote: Hello, I am looking for a way to automate the configuration of my network depending on its topology (don't know if it's the good word) : I would like to check the wired interface to see if a cable is plugged in (by looking at carrier status), if so, bring up the wired

Re: pf rules

2010-01-23 Thread Erik Norgaard
Doug Hardie wrote: This is quite interesting. I can't figure out the rules on my system. Maybe try to simplify, clean up and structure your rules :) Here is the pf.conf file with all comments removed: table blackhole persist file /etc/blackhole table spamd persist table spamd-white

Re: pf rules

2010-01-22 Thread Erik Norgaard
kalin m wrote: tcp_in = { www, https } ftp_in = { ftp } udp = { domain, ntp } ping = echoreq set skip on lo scrub in antispoof for eth0 inet block in all pass out all keep state pass proto udp to any port $udp pass inet proto icmp all icmp-type $ping keep state pass in inet proto tcp to any

Re: pf rules

2010-01-22 Thread Erik Norgaard
Doug Hardie wrote: On 22 January 2010, at 01:45, Erik Norgaard wrote: To debug pf rules: - always add direction to the rule, pass or block, add interface to all rules except default policy, keep state on all pass rules - group your rules per direction, then per interface - add log to all

Re: /etc/hosts.deniedssh

2010-01-18 Thread Erik Norgaard
David Southwell wrote: Examples from hosts.deniedssh I seem to be on the receiving end of a concerted series of unsuccessful break in attacks on one of our systems. One small part of the attack has resulted in over 2000 entries in our hosts.deniedssh file in less than 1 hour. I would be

Re: denying spam hosts ssh access - good idea?

2010-01-12 Thread Erik Norgaard
Anton Shterenlikht wrote: I'm thinking of denying ssh access to host from which I get brute force ssh attacks. This is a returning topic, search the archives. Anyway, the returning answer: - why not let your firewall do the blocking? If your blocking is IP based that's the place to block.

Re: denying spam hosts ssh access - good idea?

2010-01-12 Thread Erik Norgaard
Anton Shterenlikht wrote: - why not let your firewall do the blocking? If your blocking is IP based that's the place to block. I'm already under the University firewall. Only port 22 is let through. But even that filles my logs. What I meant was that if you want to block IPs or ranges of

System crashes under heavy disk i/o

2009-12-17 Thread Erik Norgaard
Hi: I have had this problem for a while, both on 7.x and now with 8.0: I have a: FreeBSD 8.0-RELEASE-p1 #0: Fri Dec 11 11:53:19 CET 2009 norga...@localhost:/usr/local/obj/usr/local/src/sys/GENERIC Timecounter i8254 frequency 1193182 Hz quality 0 CPU: VIA Nehemiah (800.04-MHz 686-class CPU)

Re: System crashes under heavy disk i/o

2009-12-17 Thread Erik Norgaard
Chuck Swiger wrote: Hi-- On Dec 17, 2009, at 1:26 PM, Erik Norgaard wrote: FreeBSD 8.0-RELEASE-p1 #0: Fri Dec 11 11:53:19 CET 2009 norga...@localhost:/usr/local/obj/usr/local/src/sys/GENERIC Timecounter i8254 frequency 1193182 Hz quality 0 CPU: VIA Nehemiah (800.04-MHz 686-class CPU

Re: System crashes under heavy disk i/o

2009-12-17 Thread Erik Norgaard
Mel Flynn wrote: Turn down operating mode via atacontrol. If using dump(8) use the cache feature and/or do the backup from live disk, so no other services are running and disk isn't accessed other then by dump. Thanks, is there a way to set UDMA mode at boot? BR, Erik -- Erik Nørgaard Ph:

Re: Why is sendmail is part of the system and not a package?

2009-10-29 Thread Erik Norgaard
pete wright wrote: On Tue, Oct 27, 2009 at 7:14 PM, Frank Shute fr...@shute.org.uk wrote: FreeBSD: ? I can't think of a good reason why FreeBSD should get rid of it. Saying that, it would be neat if it was taken out of base and replaced with something minimal that could cope with the demands

Re: Why is sendmail is part of the system and not a package?

2009-10-29 Thread Erik Norgaard
Giorgos Keramidas wrote: So Sendmail is a pretty heavy-weight program, but it also supports a lot of features. Which was the point, if the only process in base that requires some way to dump output other than send to syslog, is cron, then Sendmail is disproportionate solution for the

Re: Why is sendmail is part of the system and not a package?

2009-10-29 Thread Erik Norgaard
Ruben de Groot wrote: On Thu, Oct 29, 2009 at 06:55:20PM +0100, Erik Norgaard typed: Giorgos Keramidas wrote: I don't argue for a replacement but for the elimination. Install a port if you need an MTA, you're happy with that way for so many other standard services. Isn't this going a little

Re: Why is sendmail is part of the system and not a package?

2009-10-27 Thread Erik Norgaard
Jonathan McKeown wrote: Just as a matter of interest, if you want to rip sendmail out of the base system, which MTA would you like to replace it with? Or are you suggesting the system ship with no way to handle mail? This thread moving of topic from OP, but it is always fair to debate what

Re: Wifi Router and FreeeBSD - need some hints..

2009-10-25 Thread Erik Norgaard
herbert langhans wrote: Hi Daemons, I need some basic information about Wifi routers - very little I know about it. There is my FreeBSD-server (the other one is Linux) and some clients are connected with a LAN-switch. Now I want to add a Wifi Router to the network. I am not sure if I can set

packet filter keep state doesn't

2009-10-23 Thread Erik Norgaard
Hi: I have a setup like this: LAN SRV CLIENT --- FBSD --- GW/DSL Internet Now, I'd like my client to connect to the DSL box to manage it, so I have create the following rules in my pf.conf: pass in log quick on $FBSD_LAN inet proto tcp from CLIENT to GW

Re: Whic mail server?

2009-09-27 Thread Erik Norgaard
Aflatoon Aflatooni wrote: Hi, I am running a server that is acting as the mail server for only internal users (about 50 users). Currently we are running Sendmail, but reading on other discussions I noticed that qmail and other programs are suggested. I am wondering if qmail is thought to be

Re: LDAP server gone - impossible to login locally!

2009-09-22 Thread Erik Norgaard
Daniel O'Connor wrote: On Tue, 22 Sep 2009, O. Hartmann wrote: I run into trouble with FreeBSD and LDAP on a regular basis! Sometimes it is necessary to log in onto a bunch of servers with no LDAP service responding, due to service, crash, eletrically disconnetion, whatever. The problem is: I

Re: What should be backed up?

2009-08-24 Thread Erik Norgaard
Jeffrey Goldberg wrote: This is one of the several reasons that I use rsync (via rsnapshot). At each increment, it backs up the minimum that is need. With the cost of having a complete backup which duplicates what you would find in a reinstall, you have a complete system. For binaries,

Re: What should be backed up?

2009-08-24 Thread Erik Norgaard
John Almberg wrote: If you have any databases or ldap service, then you want to add those as well, but it is recommended to dump these rather than backup the files themselves. I'm learning a lot from this thread. Thanks for all the suggestions. The paragraph above raises one more

Re: Continuous backup of critical system files

2009-08-24 Thread Erik Norgaard
Maxim Khitrov wrote: I'm setting up a firewall using FreeBSD 7.2 and thought that it may not be a bad idea to have a continuous backup for important files like pf and dnsmasq configurations. By continuous I mean some script that would be triggered every few minutes from cron to automatically

Re: What should be backed up?

2009-08-22 Thread Erik Norgaard
Jeffrey Goldberg wrote: On Aug 21, 2009, at 2:33 PM, John Almberg wrote: I am currently using rsnapshot to back up these directories on a FreeBSD 7.2 webserver: /etc /usr/home /usr/local /var/cron Here is my exclude list from my rsnapshot.conf exclude /var/log exclude

Re: Recovering files after a crash

2009-08-20 Thread Erik Norgaard
Roland Smith wrote: On Wed, Aug 19, 2009 at 09:59:32AM +0200, Erik Norgaard wrote: Thanks, I couldn't decipher these GEOM_LABEL messages, nice to know that I can stop worrying. But for future incidents, the second question remains: 1. How do I best protect my system from disk errors in case

Re: Recovering files after a crash

2009-08-19 Thread Erik Norgaard
Roland Smith wrote: On Tue, Aug 18, 2009 at 09:30:15AM +0200, Erik Norgaard wrote: The problem is that I have no idea which files were affected. So, now some questions: First, how do I determine which files were corrupted? And how do I recover these files? From what you have shown

Re: freebsd

2009-08-19 Thread Erik Norgaard
BONGANI MANGANYE wrote: I know freebsd is free but i would like to know how much will I pay if I need additional package like updates and other useful software,and can you tell how secure it is how protected i will be if i use freebsd FreeBSD is free, and any updates are free. Third party

Recovering files after a crash

2009-08-18 Thread Erik Norgaard
Hi: I woke op to a crash this morning after a powerfailure, and now dmesg shows this: WARNING: / was not properly dismounted GEOM_LABEL: Label ufsid/442f8ac1c0db9af2 removed. GEOM_LABEL: Label for provider ad6s1a is ufsid/442f8ac1c0db9af2. GEOM_LABEL: Label ufsid/442f8ac5a7fa5dda removed.

Re: please help to uninstall FreeBSD!!!

2009-08-10 Thread Erik Norgaard
Raisa Brokhshtut wrote: My old desktop has FreeBSD that I have never used. One of the friends of my son installed it long ago, but no one used that PC since then. Now I want to get rid of this program and to install Windows. Every time when I boot this PC it prompts for a user login which I

Re: Building home router: 192.168.0.x to access internet

2009-08-09 Thread Erik Norgaard
Nerius Landys wrote: First, my choise of internal network IP addresses is 192.168.0.x. My router machine's IP address will be 192.168.0.254 (that's the interface facing the internal network). The IP addresses of the machines behind the router will start at 192.168.0.2 and go up. I'm wondering

Re: Physically securing FreeBSD workstations /boot/boot2

2009-08-06 Thread Erik Norgaard
Nerius Landys wrote: Hi. I am attempting to secure some workstations in such a way that a user would not be able gain full control of the computer (only user access). However, they are able to see and touch the physical workstation. I assume that users cannot tingle with the hardware, take it

Re: How to find real CPU temperature?

2009-08-05 Thread Erik Norgaard
Unga wrote: Hi all I'm running FreeBSD 7.2 on Intel P4 computer. The lmmon -i shows 21C and when go to BIOS shows 65C! BIOS reading seems to be correct as the CPU heat pipe is very hot to the extent cannot touch. How do I read the real BIOS temperature readings when FreeBSD is running to

  1   2   3   4   5   6   7   8   >