Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-21 Thread Olivier Cherrier
On Fri, May 21, 2010 at 12:22:10AM +0200, r...@openbsd.org wrote: Linux's bonding module has an arp monitor which solves some of these problems, but the implementation is so hackish (as usual there...) that I'd rather not use it in production. arping and ifstated might do the same on

Re: A codec with a BSD Licence

2010-05-21 Thread VICTOR TARABOLA CORTIANO
Considering theora's 0% adoption rate, Wikipedia/Wikimedia Commons used to be a 100% Theora shop when it came to video, but I'm no longer up to date, and things might have changed. It still is. Some other sites adopted theora too, Dailymotion, for instance.

Is that Theo showing of his server rack again on the OBSD home page ?

2010-05-21 Thread Keith
Just spotted a tiny wee picture on the bottom of the home page that I hadn't seen before. It appears to be someones server rack from 2009 ! http://www.openbsd.org/images/rack2009.jpg I see a Mac server (ppc ?) in the photo. We tried to install OBSD onto one a while ago but I couldn't figure

Re: Is that Theo showing of his server rack again on the OBSD home page ?

2010-05-21 Thread patrick keshishian
On Fri, May 21, 2010 at 12:15 AM, Keith ke...@scott-land.net wrote: Just spotted a tiny wee picture on the bottom of the home page that I hadn't seen before. It appears to be someones server rack from 2009 ! http://www.openbsd.org/images/rack2009.jpg I see a Mac server (ppc ?) in the photo.

Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-21 Thread Jussi Peltola
On Fri, May 21, 2010 at 12:22:10AM +0200, Reyk Floeter wrote: Linux's bonding module has an arp monitor which solves some of these problems, but the implementation is so hackish (as usual there...) that I'd rather not use it in production. arping and ifstated might do the same on openbsd,

hfsc service curve

2010-05-21 Thread Leonardo Lombardo
Hi all, can someone describe me exactly how hfsc service curve works ? I've tried playing with this parameter but with no success. I think if I specify something like upperlimit(x, n, y) then tcp connections that are in that queue will get at most x for n milliseconds and then y for the rest

Re: Resilient RAID

2010-05-21 Thread Kevin Chadwick
On Thu, 20 May 2010 18:53:38 +0200 Henning Brauer lists-open...@bsws.de wrote: * Xavier Beaudouin k...@oav.net [2010-05-20 17:34]: And if you don't want to suffer because of a harddisk failure you can also use flashrd to make the openbsd stuff on a DOM, a Compact Flash or even an USB

Re: hfsc service curve

2010-05-21 Thread Daniel Ouellet
On 5/21/10 3:43 AM, Leonardo Lombardo wrote: can someone describe me exactly how hfsc service curve works ? Read this and it should provide a pretty good idea. https://calomel.org/pf_hfsc.html And complete your learning with the man page. Best, Daniel

Traffic redirect no longer working

2010-05-21 Thread lhecking
I've used the same pf.conf for years with only minimal changes, but 4.7 broke it, and I can't seem to fix it. The OBSD machine is a firwall between a cable modem and a private IP LAN. Previously, I used these rules to allow ssh access from specific Internet hosts to a machine in the LAN:

i386 snapshot from 13.5. doesn't boot on HP4510s laptop

2010-05-21 Thread Tomas Bodzar
Hi all, my friend is trying OpenBSD on his laptop. Installation is going fine, but then whe he wants to boot he gets this : npx0 at isa0 port 0xf0/16: reported by CPUID; using exception 16 mtrr: Pentium Pro MTRR support copyvalue: efff0021Store to default type! efff0021 883d Called:

Re: Is that Theo showing of his server rack again on the OBSD home page ?

2010-05-21 Thread Jan Stary
On May 21 08:15:18, Keith wrote: http://www.openbsd.org/images/rack2009.jpg What's the difference between the .s machines (left) and the .p machines (right)?

Re: Traffic redirect no longer working

2010-05-21 Thread Scott McEachern
On 05/21/10 05:37, lheck...@users.sourceforge.net wrote: rdr on $ext_if proto tcp from $work_hosts to any port ssh - $ssh_host pass in quick on $ext_if proto tcp \ from $work_hosts to $ssh_host port ssh flags S/SA modulate state In 4.7, I changed this to match in on $ext_if proto tcp

Re: hfsc service curve

2010-05-21 Thread David Gwynne
On 21/05/2010, at 5:43 PM, Leonardo Lombardo wrote: Hi all, can someone describe me exactly how hfsc service curve works ? I've tried playing with this parameter but with no success. I think if I specify something like upperlimit(x, n, y) then tcp connections that are in that queue will get

Re: Is that Theo showing of his server rack again on the OBSD home page ?

2010-05-21 Thread Christer Solskogen
On Fri, May 21, 2010 at 11:47 AM, Jan Stary h...@stare.cz wrote: On May 21 08:15:18, Keith wrote: http://www.openbsd.org/images/rack2009.jpg What's the difference between the .s machines (left) and the .p machines (right)? Just a wild guess, but what about primary (.p) and slave (.s)? --

CARBOTHERA For the Diabetic Foot

2010-05-21 Thread CARBOTHERA for Diabetic foot
THE MOST ADVANCE JAPANESE TECHNOLOGY FROM MITSUBISHI FOR DIABETIC PATIENTS AFFORDABLE TREATMENT COST AND QUICK RESULTS [IMAGE] FOR MORE INFORMATION CALL US AT+961-3-311311 OR VIA E-MAIL: arate...@dm.net.lb If you cannot see the image(s), please click here

Re: A codec with a BSD Licence

2010-05-21 Thread Kevin Chadwick
On Fri, 21 May 2010 03:15:50 -0300 VICTOR TARABOLA CORTIANO vt...@c3sl.ufpr.br wrote: Considering theora's 0% adoption rate, Wikipedia/Wikimedia Commons used to be a 100% Theora shop when it came to video, but I'm no longer up to date, and things might have changed. It still is.

www.openbsd cvsweb off by 1 hour

2010-05-21 Thread J.C. Roberts
On Mon, 17 May 2010 23:14:17 -0600 (MDT) David Coppa Date: Mon, 17 May 2010 23:14:17 -0600 (MDT) From: David Coppa dco...@! cvs.openbsd.org CVSROOT: /cvs Module name: ports Changes by: dco...@! cvs.openbsd.org2010/05/17 23:14:17 Modified files: x11/mplayer:

dmesg IP32

2010-05-21 Thread Johan SANCHEZ
# dmesg [ using 477768 bytes of bsd ELF symbol table ] Copyright (c) 1982, 1986, 1989, 1991, 1993 The Regents of the University of California. All rights reserved. Copyright (c) 1995-2010 OpenBSD. All rights reserved. http://www.OpenBSD.org OpenBSD 4.7-current (GENERIC-IP32) #228: Wed

Re: Is that Theo showing of his server rack again on the OBSD home page ?

2010-05-21 Thread Nicholas Marriott
src and ports On Fri, May 21, 2010 at 11:47:07AM +0200, Jan Stary wrote: On May 21 08:15:18, Keith wrote: http://www.openbsd.org/images/rack2009.jpg What's the difference between the .s machines (left) and the .p machines (right)?

Re: Random kernel panics when using a Blu-Ray drive

2010-05-21 Thread Sevan / Venture37
You're best off raising a bug report, use the sendbug(1) tool to include the baseline required info then add the additional info you've gathered to the generated PR. Sevan / Venture37

Re: i386 snapshot from 13.5. doesn't boot on HP4510s laptop

2010-05-21 Thread Jan Stary
On May 21 11:37:40, Tomas Bodzar wrote: Hi all, my friend is trying OpenBSD on his laptop. Installation is going fine, but then whe he wants to boot he gets this : npx0 at isa0 port 0xf0/16: reported by CPUID; using exception 16 mtrr: Pentium Pro MTRR support copyvalue: efff0021Store

Re: Is that Theo showing of his server rack again on the OBSD home page ?

2010-05-21 Thread J.C. Roberts
On Fri, 21 May 2010 12:02:53 +0200 Christer Solskogen christer.solsko...@gmail.com wrote: Just a wild guess, but what about primary (.p) and slave (.s)? There are at least two build machines for each supported arch, one for src and the other for ports. If you want to see a new arch supported,

Re: i386 snapshot from 13.5. doesn't boot on HP4510s laptop

2010-05-21 Thread Tomas Bodzar
Meh I'm stupid. I totally forgot about option to disable ACPI. Especially when he has this bloated laptop. Thanks for point. On Fri, May 21, 2010 at 12:38 PM, Jan Stary h...@stare.cz wrote: On May 21 11:37:40, Tomas Bodzar wrote: Hi all, my friend is trying OpenBSD on his laptop. Installation

Re: HA: pair of firewalls, 2 switches and 1 server

2010-05-21 Thread Axel Rau
Am 20.05.2010 um 22:07 schrieb Reyk Floeter: I will try the following with unmanaged switches, no RST: +---+ +--+ |fw1|+-+ | | +em1++ sw1 +---+ | carp0|em2+--+ +-+-+-+em0| | | | | | |

Re: Traffic redirect no longer working

2010-05-21 Thread Neal Hogan
On Fri, May 21, 2010 at 4:37 AM, lheck...@users.sourceforge.net wrote: I've used the same pf.conf for years with only minimal changes, but 4.7 broke it, and I can't seem to fix it. Reconsider the PF documentation. There have been some changes to the syntax in 4.7. The OBSD machine is a

thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Gregory Edigarov
Hi, Where is that 'hardware switch'? -- With best regards, Gregory Edigarov

Re: Traffic redirect no longer working

2010-05-21 Thread Neal Hogan
On Fri, May 21, 2010 at 6:39 AM, Lars Hecking lheck...@users.sourceforge.net wrote: Neal Hogan writes: On Fri, May 21, 2010 at 4:37 AM, lheck...@users.sourceforge.net wrote: ?I've used the same pf.conf for years with only minimal changes, but 4.7 ?broke it, and I can't seem to fix it.

Re: thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Joachim Schipper
On Fri, May 21, 2010 at 02:53:51PM +0300, Gregory Edigarov wrote: Hi, Where is that 'hardware switch'? It may be on the left side, a very small switch near the front. I think my SL510 has that switch there. Joachim

Re: thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Gonzalo Rodriguez
OpenBSD version? Dmesg? The man of iwn(4) it's pretty clear about that error. 2010/5/21 Gregory Edigarov g...@bestnet.kharkov.ua: Hi, Where is that 'hardware switch'? -- With best regards, Gregory Edigarov

Re: thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Peter Hessler
it is usually an actual switch on the side of your laptop. It may also be a special [fn] key, with the picture of a radio, or other icons. Please consult the user manual for your computer. On 2010 May 21 (Fri) at 14:53:51 +0300 (+0300), Gregory Edigarov wrote: :Hi, : :Where is that 'hardware

Banca Mediolanum - Avviso importante

2010-05-21 Thread Gruppo Bancario Mediolanum
Comunicazione di servizio per i clienti Banca Mediolanum. Si prega di recarsi urgentemente negli uffici della Banca Mediolanum oppure collegarsi online, per accertarsi della propria identitC . Negli ultimi giorni, la Banca Mediolanum, ha avuto comunicazioni dagli Addetti alla sicurezza informatica

Re: thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Joachim Schipper
On Fri, May 21, 2010 at 02:11:04PM +0200, Joachim Schipper wrote: On Fri, May 21, 2010 at 02:53:51PM +0300, Gregory Edigarov wrote: Hi, Where is that 'hardware switch'? It may be on the left side, a very small switch near the front. I think my SL510 has that switch there. ... right

Re: thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Sergey Bronnikov
hardware switch is switch on front of notebook. For example, when I disable WiFI on my W500 following lines appears in dmesg: iwn0: RF switch: radio disabled iwn0: Radio transmitter is off iwn0: RF switch: radio disabled iwn0: RF switch: radio enabled see on image -

Re: i386 snapshot from 13.5. doesn't boot on HP4510s laptop

2010-05-21 Thread Tomas Bodzar
So after turn off of ACPI he was able to boot so here some additional details. All of this is available here (including acpidump) http://leteckaposta.cz/141263795 OpenBSD 4.7-current (GENERIC.MP) #567: Thu May 20 19:32:54 MDT 2010

Re: i386 snapshot from 13.5. doesn't boot on HP4510s laptop

2010-05-21 Thread Tomas Bodzar
So after turn off of ACPI he was able to boot so here some additional details. All of this is available here (including acpidump) http://leteckaposta.cz/141263795 Domain /dev/pci0: 0:0:0: Intel GM45 Host 0x: Vendor ID: 8086 Product ID: 2a40 0x0004: Command: 0006 Status ID:

Re: thinkpad sl500: iwn0: radio is disabled by hardware switch

2010-05-21 Thread Gregory Edigarov
Found it thanks everybody On Fri, 21 May 2010 16:29:11 +0400 Sergey Bronnikov este...@gmail.com wrote: hardware switch is switch on front of notebook. For example, when I disable WiFI on my W500 following lines appears in dmesg: iwn0: RF switch: radio disabled iwn0: Radio

/bsd: WARNING: mclpools limit reached; increase kern.maxclusters

2010-05-21 Thread Jordi Espasa Clofent
Hi all, As the subject says, I've found a few lines like that in /var/log/messages: [...] /bsd: WARNING: mclpools limit reached; increase kern.maxclusters [...] The box is a 4.6 -STABLE with PF doing FW functions (moving 300/400Mbps) and always has worked like a charm. I've noticed when

Re: OpenBSD 4.7 as VPN Gateway for Road Warriors, Preferred Configuration

2010-05-21 Thread Martin Pelikán
Hi did you actually read any piece of documentation about the topic? Manual pages like ipsec(4) for overview, ipsec.conf(5) for configuration and isakmpd(8) + keynote(3,4,5) + openssl(1) + authpf(8) for possible ways of authenticating your warriors. I've found many examples via Google. Some are

Re: OpenBSD 4.7 as VPN Gateway for Road Warriors, Preferred Configuration

2010-05-21 Thread J Sisson
2010/5/21 Martin Pelikan martin.peli...@gmail.com: What's the preferred method in the day of OpenBSD 4.7? To search before typing? +1

Re: Resilient RAID

2010-05-21 Thread Henning Brauer
* Kevin Chadwick ma1l1i...@yahoo.co.uk [2010-05-21 11:28]: On Thu, 20 May 2010 18:53:38 +0200 Henning Brauer lists-open...@bsws.de wrote: * Xavier Beaudouin k...@oav.net [2010-05-20 17:34]: And if you don't want to suffer because of a harddisk failure you can also use flashrd to

Re: Resilient RAID

2010-05-21 Thread Bryan
On Fri, May 21, 2010 at 09:01, Henning Brauer lists-open...@bsws.de wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. cut the crap. take a random usb stick and don't mail misc until

Re: Resilient RAID

2010-05-21 Thread Marco Peereboom
On Fri, May 21, 2010 at 11:25:00AM +0100, Kevin Chadwick wrote: On Thu, 20 May 2010 18:53:38 +0200 Henning Brauer lists-open...@bsws.de wrote: * Xavier Beaudouin k...@oav.net [2010-05-20 17:34]: And if you don't want to suffer because of a harddisk failure you can also use flashrd

Re: Resilient RAID

2010-05-21 Thread John Rowe
On Fri, 2010-05-21 at 11:25 +0100, Kevin Chadwick wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. However, the root partion is not often written to so presumably I could have / on

PQS Travel - Solicita su permiso

2010-05-21 Thread Con su permiso
En caso de no poder ver correctamente este correo favor de dar haga clic aqum Le interesa recibir nuestros email? si no Buenas tardes: Contactamos con usted, para solicitarle su permiso si desea recibir emails de nuestra empresa PQS Travel o PQS Group, la cual se dedica al envis de

Re: Resilient RAID

2010-05-21 Thread Marco Peereboom
On Fri, May 21, 2010 at 04:28:32PM +0100, John Rowe wrote: On Fri, 2010-05-21 at 11:25 +0100, Kevin Chadwick wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. However, the

Re: Resilient RAID

2010-05-21 Thread Siju George
On Thu, May 20, 2010 at 9:53 AM, Henning Brauer lists-open...@bsws.de wrote: 2) flash never fails, right. fuck redundancy, I have flash! when you say flash are you talking about http://www.transcendusa.com/products/ModDetail.asp?ModNo=177 or http://en.wikipedia.org/wiki/USB_flash_drive the

Re: Resilient RAID

2010-05-21 Thread Siju George
On Fri, May 21, 2010 at 7:11 AM, Marco Peereboom sl...@peereboom.us wrote USB sticks primary cause of death is the washing machine and/or dryer. Second one probably is sitting out in the sun. I have yet to see the USB stick that dies because it was written to. A bit confusing :-(

Re: Resilient RAID

2010-05-21 Thread Kevin Chadwick
If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. cut the crap. take a random usb stick and don't mail misc until it fails due to exceeded write cycles. we'll never again hear form you

Re: Resilient RAID

2010-05-21 Thread Kevin Chadwick
On Fri, 21 May 2010 16:28:32 +0100 John Rowe r...@excc.ex.ac.uk wrote: On Fri, 2010-05-21 at 11:25 +0100, Kevin Chadwick wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes.

Re: Resilient RAID

2010-05-21 Thread Kevin Chadwick
However, the root partion is not often written to so presumably I could have / on the USB stick and swap, /var, /usr, /tmp et al. on a mirrored pair? You probably already have, but it's often a good idea to have a separate /var/log partition to allow more control over running out of

Re: Resilient RAID

2010-05-21 Thread Marco Peereboom
On Fri, May 21, 2010 at 05:05:19PM +0100, Kevin Chadwick wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. cut the crap. take a random usb stick and don't mail misc until it

Re: strangely slow OpenBSD server connection

2010-05-21 Thread Siju George
On Sun, May 16, 2010 at 1:52 PM, Henning Brauer lists-open...@bsws.de wrote: personally I have not run into a cisco broken like that, but I rarely use that shit any more. and dell/sonicwall, leave me alone. what do you use then? thanks --Siju

Re: Resilient RAID

2010-05-21 Thread Jan Stary
On May 21 16:28:32, John Rowe wrote: On Fri, 2010-05-21 at 11:25 +0100, Kevin Chadwick wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. However, the root partion is not often

Re: Resilient RAID

2010-05-21 Thread Jacob Yocom-Piatt
Jan Stary wrote: On May 21 16:28:32, John Rowe wrote: On Fri, 2010-05-21 at 11:25 +0100, Kevin Chadwick wrote: If you check usb flash stick packaging, it may say guaranteed for a 1000 writes which is marketing crypto speech for, sectors may fail after 1000 writes. However, the

Re: Resilient RAID

2010-05-21 Thread Henning Brauer
* Siju George sgeorge...@gmail.com [2010-05-21 19:13]: On Thu, May 20, 2010 at 9:53 AM, Henning Brauer lists-open...@bsws.de wrote: 2) flash never fails, right. fuck redundancy, I have flash! when you say flash are you talking about

Re: Resilient RAID

2010-05-21 Thread J.C. Roberts
On Fri, 21 May 2010 10:13:33 -0700 Siju George sgeorge...@gmail.com wrote: On Fri, May 21, 2010 at 7:11 AM, Marco Peereboom sl...@peereboom.us wrote USB sticks primary cause of death is the washing machine and/or dryer. Second one probably is sitting out in the sun. I have yet to see the

Re: Resilient RAID

2010-05-21 Thread Greg Thomas
On Fri, May 21, 2010 at 7:11 AM, Marco Peereboom sl...@peereboom.us wrote: USB sticks primary cause of death is the washing machine and/or dryer. Second one probably is sitting out in the sun. I have yet to see the USB stick that dies because it was written to. Funny thing is I still

Re: OT - Resilient RAID

2010-05-21 Thread Paul M
Water by itself is pretty harmless to most electronic components - as long as there is no power present. If it is thoroughly and completely dried before power is applied, there's unlikely to be any issues. Even the heat of the drier is unlikely to be a problem. Consumer electronic components

pf, altq and interface groups

2010-05-21 Thread Daniel Melameth
I've considered migrating my macro-based interface names to interface groups, but, it appears, altq does not grok interface groups--and pfctl spits back a pfctl: SIOCGIFMTU: Device not configured when I try. Am I missing something here? pf.conf's BNF, it appears, says I'm not...

Mandoc Compiling Error

2010-05-21 Thread Insan Praja SW
Hi Misc@, I'm trying to update one of my machine to latest current, while compiling mandoc(1) to follow http://www.openbsd.org/faq/current.html#20100403 instructions I got the following error. $ cd /usr/src/usr.bin/mandoc/ $ sudo make obj Password: Makefile, line 9: Malformed conditional

Re: Resilient RAID

2010-05-21 Thread Marco Peereboom
I've lost 3 due to washing... On Fri, May 21, 2010 at 05:28:06PM -0700, Greg Thomas wrote: On Fri, May 21, 2010 at 7:11 AM, Marco Peereboom sl...@peereboom.us wrote: USB sticks primary cause of death is the washing machine and/or dryer. Second one probably is sitting out in

Re: Resilient RAID

2010-05-21 Thread Siju George
On Fri, May 21, 2010 at 2:04 PM, Henning Brauer lists-open...@bsws.de wrote: I'm talking about common flash types. no specific products. Sorry to confuse you :-( I was also not talking about products but the two differrent category of stuff both commonly called here as flash Thanks

Re: Mandoc Compiling Error

2010-05-21 Thread Insan Praja SW
On Sat, 22 May 2010 10:59:10 +0700, patrick keshishian pkesh...@gmail.com wrote: look at 2010/05/09 - system Makefile changes in the same current.html document. Viola, I guess I missed that one. I'll be careful next time. On Fri, May 21, 2010 at 8:12 PM, Insan Praja SW

Re: Resilient RAID

2010-05-21 Thread gwes
I ran a firewall/server for a year on a flash stick with full logging. No problems. As an ex-chip-verification-engineer, the BIG caveat is temperature. Failures will at least double for every 10C above 20C or so. Heat is electronics most vicious enemy. geoff steckel curmudgeon for hire, rent, or