PF divert-packet reinjection

2020-11-24 Thread Szél Gábor
Dear @misc We test OpenBSD with Suricata in IPS mode. IPS mode requires PF divert-packet. simple rule to divert: pass in log quick on $_if proto tcp from ! to any divert-packet port 700 At first look everything is good! The packet goes to suricata, suricata check packet, if packet is

Re: PF divert-packet reinjection

2020-11-24 Thread Stuart Henderson
On 2020-11-23, Szél Gábor wrote: > Dear @misc > > We test OpenBSD with Suricata in IPS mode. > IPS mode requires PF divert-packet. > > simple rule to divert: > pass in log quick on $_if proto tcp from ! to any > divert-packet port 700 > > At first look everything is good! > The packet goes

Redistribution between ospfd and ripd

2020-11-24 Thread Jason Tubnor
Hi, We are planning for migration from ripd to ospf, however both protocols will need to work together as the migration rolls through. I was looking at the 'redistribute rtlabel' option, even after digging into the code, it is unclear how this would work to bring other dynamic routes on the same

Re: OpenBSD + Firebird Server

2020-11-24 Thread Jeremy Evans
On Tue, Nov 24, 2020 at 9:27 PM Radek wrote: > Hi, > is it possible to install Firebird Server in OpenBSD? I can't find any > info about that anywhere. > Thanks! Assuming you mean the SQL database, when last I looked into this years ago, Firebird required pthread_condattr_setpshared and

Re: Advice on using intrusion detection

2020-11-24 Thread Aaron Mason
On Sun, Nov 22, 2020 at 1:14 AM Nick Holland wrote: > > On 2020-11-20 17:15, Erik Lauritsen wrote: > > Is it recommended to run some kind of intrusion detection on an > > OpenBSD router/firewall? > > > > I suspect that any kind of system like Snort or Suricata will give a > > lot of false

OpenBSD + Firebird Server

2020-11-24 Thread Radek
Hi, is it possible to install Firebird Server in OpenBSD? I can't find any info about that anywhere. Thanks! -- Radek