pf icmp redirect question

2014-05-30 Thread Marko Cupać
Hi, let's say for example I have web server on internal network, and I have redirected tcp port 80 from firewall to it: pass in on $ext_if inet proto tcp from any to $pub_web port 80 \ rdr-to $priv_web Assuming that $pub_web ip address is used exclusively for web server access, and no other

Re: 5.5 pf priority

2014-05-30 Thread Henning Brauer
* Paco Esteban p...@onna.be [2014-05-29 12:11]: On Thu, 29 May 2014, Marko Cupać wrote: On Wed, 28 May 2014 21:40:58 +0200 Henning Brauer lists-open...@bsws.de wrote: I'm pretty damn sure I added reset prio if queueing is on thing. yes, in IF_ENQUEUE - hfsc_enqueue

Re: pf icmp redirect question

2014-05-30 Thread Sebastian Benoit
Marko Cupa??(marko.cu...@mimar.rs) on 2014.05.30 11:32:14 +0200: Hi, let's say for example I have web server on internal network, and I have redirected tcp port 80 from firewall to it: pass in on $ext_if inet proto tcp from any to $pub_web port 80 \ rdr-to $priv_web From the wording

encrypted vnd Fwd: CVS: cvs.openbsd.org: src

2014-05-30 Thread Ted Unangst
If you are using encrypted vnd (vnconfig -k or -K) you will want to begin planning your migration strategy. -- Forwarded message -- From: Ted Unangst t...@cvs.openbsd.org Date: Fri 2014/05/30 10:14 -06:00 Subject: CVS: cvs.openbsd.org: src To: source-chan...@cvs.openbsd.org

Re: encrypted vnd Fwd: CVS: cvs.openbsd.org: src

2014-05-30 Thread Robert
On Fri, 30 May 2014 12:19:35 -0400 Ted Unangst t...@tedunangst.com wrote: WARNING: Encrypted vnd is insecure. Migrate your data to softraid before 5.7. Will 5.6 softraid support block sizes other than 512 byte? marc.info/?l=openbsd-miscm=139524543706370 kind regards, Robert

Re: 5.5 pf priority

2014-05-30 Thread Giancarlo Razzolini
Em 30-05-2014 08:43, Henning Brauer escreveu: * Paco Esteban p...@onna.be [2014-05-29 12:11]: On Thu, 29 May 2014, Marko Cupać wrote: On Wed, 28 May 2014 21:40:58 +0200 Henning Brauer lists-open...@bsws.de wrote: I'm pretty damn sure I added reset prio if queueing is on thing. yes, in

Re: pf icmp redirect question

2014-05-30 Thread System Administrator
On 30 May 2014 at 13:56, Sebastian Benoit wrote: Marko Cupa??(marko.cu...@mimar.rs) on 2014.05.30 11:32:14 +0200: Hi, let's say for example I have web server on internal network, and I have redirected tcp port 80 from firewall to it: pass in on $ext_if inet proto tcp from any to

Re: encrypted vnd Fwd: CVS: cvs.openbsd.org: src

2014-05-30 Thread Chris Cappuccio
Robert [info...@die-optimisten.net] wrote: On Fri, 30 May 2014 12:19:35 -0400 Ted Unangst t...@tedunangst.com wrote: WARNING: Encrypted vnd is insecure. Migrate your data to softraid before 5.7. Will 5.6 softraid support block sizes other than 512 byte?

Re: 5.5 pf priority

2014-05-30 Thread Adam Thompson
On 2014-05-30 12:41, Giancarlo Razzolini wrote: From my experience, if you have an asymmetric link, where your download rate is bigger than your upload rate, you can see benefits in putting hfsc in front of it. And, the most benefit seems to be on the upload side. There are some factors

Re: 5.5 pf priority

2014-05-30 Thread Adam Thompson
My apologies, I have no idea why roundcube decided to format the plain-text version of my last message that way. -Adam

Re: pf icmp redirect question

2014-05-30 Thread André Lucas
On 30 May 2014 19:13, System Administrator ad...@bitwise.net wrote: On 30 May 2014 at 13:56, Sebastian Benoit wrote: Marko Cupa??(marko.cu...@mimar.rs) on 2014.05.30 11:32:14 +0200: Assuming that $pub_web ip address is used exclusively for web server access, and no other ports are

Re: encrypted vnd Fwd: CVS: cvs.openbsd.org: src

2014-05-30 Thread Robert
On Fri, 30 May 2014 11:14:40 -0700 Chris Cappuccio ch...@nmedia.net wrote: Robert [info...@die-optimisten.net] wrote: On Fri, 30 May 2014 12:19:35 -0400 Ted Unangst t...@tedunangst.com wrote: WARNING: Encrypted vnd is insecure. Migrate your data to softraid before 5.7. Will 5.6

Re: encrypted vnd Fwd: CVS: cvs.openbsd.org: src

2014-05-30 Thread Theo de Raadt
Robert [info...@die-optimisten.net] wrote: On Fri, 30 May 2014 12:19:35 -0400 Ted Unangst t...@tedunangst.com wrote: WARNING: Encrypted vnd is insecure. Migrate your data to softraid before 5.7. Will 5.6 softraid support block sizes other than 512 byte?

Linux Foundation to fund OpenSSL

2014-05-30 Thread AHLSENGIRARD, EDWARD F CTR USAF AFSOC AFSOC A6/A6OK
This just in: http://www.theinquirer.net/inquirer/news/2347534/linux-foundation-thro\ ws-money-at-openssl-staffing-post-heartbleed -- Ed Ahlsen-Girard, Contractor (Application Management Services) AFSOC/A6OK email: edward.ahlsen-girard@hurlburt.af.mil 850-884-2414 DSN: 312-579-2414

Re: 5.5 pf priority

2014-05-30 Thread sven falempin
On Fri, May 30, 2014 at 2:15 PM, Adam Thompson athom...@athompso.net wrote: On 2014-05-30 12:41, Giancarlo Razzolini wrote: From my experience, if you have an asymmetric link, where your download rate is bigger than your upload rate, you can see benefits in putting hfsc in front of it.

Re: 5.5 pf priority

2014-05-30 Thread Adam Thompson
On 14-05-30 05:07 PM, sven falempin wrote: Just curious. Because TCP got flow and congestion control it should be possible to reduce the input bandwith of tcp connection even without controlling the previous hop ??? Yes, but consider a router with 3 interfaces: WAN, LAN1 and LAN2. Let us

Re: hibernate fails to restore on i386

2014-05-30 Thread Mike Larkin
On Thu, May 29, 2014 at 11:51:07PM -0400, Josh Grosse wrote: I use ZZZ rarely, so I have no clue when the regression -- if it is a regression -- began. Clue sticks welcome, as well a guidance for producing more useful diagnostics. Symptom: ZZZ apparently saves and shuts down. On reboot,

Re: encrypted vnd Fwd: CVS: cvs.openbsd.org: src

2014-05-30 Thread Jonathan Thornburg
In message http://marc.info/?l=openbsd-miscm=140146687910205w=1, Ted Unangst wrote: If you are using encrypted vnd (vnconfig -k or -K) you will want to begin planning your migration strategy. [[...]] WARNING: Encrypted vnd is insecure. Migrate your data to softraid before 5.7. Once this