Re: pf and tap interfaces

2021-10-31 Thread tech-lists
On Sun, Oct 31, 2021 at 10:13:06AM -0600, Theo de Raadt wrote: you are asking a freebsd question on an openbsd mailing list. come on You may have missed my response to Sebastian: In-Reply-To: On Sun, Oct 31, 2021 at 03:59:40PM +, tech-lists wrote: [...] All I'm really aski

Re: pf and tap interfaces

2021-10-31 Thread tech-lists
On Sun, Oct 31, 2021 at 09:33:54AM -0600, Theo de Raadt wrote: tech-lists wrote: I'm asking this here because I'm trying to do this with FreeBSD but their pf has diverged a lot from OpenBSD's that is incorrect history. It is hard to see how 'absolutely minimal maintai

Re: pf and tap interfaces

2021-10-31 Thread tech-lists
Hi, On Sun, Oct 31, 2021 at 04:23:58PM +0100, Sebastian Benoit wrote: Maybe you could describe a bit more what you are trying to do. I'm trying to protect, with pf, a freebsd host running bhyve guests. The guests use tap interfaces. They are in the same network as the host (but with different

pf and tap interfaces

2021-10-31 Thread tech-lists
Hello misc@ Generically, can OpenBSD [7.0] apply rules to *just* the ethernet interface, ignoring the bridge and tap interfaces? Can it do this natively or is a VLAN required as well? Or something else? I'm asking this here because I'm trying to do this with FreeBSD but their pf has diverged a

really pleased with openbsd68/rpi4 8GB installation/performance

2021-01-09 Thread tech-lists
Thank you to everyone who helped make openbsd work on the rpi4. Although I won't be needing xorg/x11 on this particular machine, I tried installing it anyway out of curiosity and was surprised how easy it was to get it all working. I thought firefox might bog it down but no. Very smooth. Instal

Re: msdos partition is too small in arm64/miniroot68.img

2021-01-07 Thread tech-lists
On Thu, Jan 07, 2021 at 09:55:28AM -0700, Theo de Raadt wrote: tech-lists wrote: On Wed, Jan 06, 2021 at 09:25:01AM -0700, Theo de Raadt wrote: >The miniroot is 33MB because it contains many install firmwares, and >it is 97% full. > >I suggest you find another way of installing. &

Re: msdos partition is too small in arm64/miniroot68.img

2021-01-07 Thread tech-lists
On Thu, Jan 07, 2021 at 02:20:54PM +, a...@sdf.org wrote: On Thu, Jan 07, 2021 at 01:01:53PM +, tech-lists wrote: On Wed, Jan 06, 2021 at 09:01:19PM +, a...@sdf.org wrote: [...method...] thanks for that, I'll let you know how I get on. I think your problem with spontaneous cr

Re: msdos partition is too small in arm64/miniroot68.img

2021-01-07 Thread tech-lists
On Wed, Jan 06, 2021 at 09:01:19PM +, a...@sdf.org wrote: [...method...] thanks for that, I'll let you know how I get on. I think your problem with spontaneous crashes might be down to swapfile, sdcard is unsuitable for this. I've had good results with arm64/freebsd-current/swapfile on usb3

Re: msdos partition is too small in arm64/miniroot68.img

2021-01-07 Thread tech-lists
On Wed, Jan 06, 2021 at 09:25:01AM -0700, Theo de Raadt wrote: The miniroot is 33MB because it contains many install firmwares, and it is 97% full. I suggest you find another way of installing. Is there a technical (or some other reason I'm not seeing) why miniroot68.fs has been made as small

msdos partition is too small in arm64/miniroot68.img

2021-01-06 Thread tech-lists
Hi, I'm trying to install openbsd 6.8 on a raspberry pi 4/8GB. The files I need to add to the msdos partition are, in total, too large to fit (the partition is only 4MB) Is there some method of increasing the msdos partition size of the miniroot.fs image? I'd be doing this from either a freebs

Re: the whole greylisting, spam filtering thing

2017-09-29 Thread tech-lists
On Fri, Sep 29, 2017 at 03:06:29PM +0200, Markus Rosjat wrote: So my question is, is there some source that you could use to train these kind of tools (like a database that you could connect to for training conntent ) or is every one here, that uses these tools, lucky enough to have a shit load

ipv4/ipv6 dual-stack configuration on OpenBSD6.0

2017-09-12 Thread tech-lists
Hello misc@, I'm trying to find an *authoritative* walkthrough configuring an OpenBSD-6.0 amd64 machine that currently runs fine as an ipv4 router for my pppoe vdsl connection. The ipv4 network is a public /29. No NAT of any description runs on this machine. There's two NICs, re0 which connec

Re: pppoe via switch

2016-10-01 Thread tech-lists
On 01/10/2016 14:58, Eric Huiban wrote: And my last sentence is where you'll get "problems" with your ISP ! It will append if you're leaking undue ethernet packets to the PPPoE gateway : any broadcast or anything unknown to your dumb switch will be submitted to your ISP's good will. So... don't m

Re: pppoe via switch

2016-10-01 Thread tech-lists
On 30/09/2016 16:49, tech-lists wrote: Hello misc@ If I had this arrangement: openbsd re0 --- unmanaged gigabit switch --- vdsl modem offering PPPoE can I expect pppoe0 on the openbsd box to be able to communicate with the modem and bring the line up? It seems the answer to this is YES. Not

pppoe via switch

2016-09-30 Thread tech-lists
Hello misc@ If I had this arrangement: openbsd re0 --- unmanaged gigabit switch --- vdsl modem offering PPPoE can I expect pppoe0 on the openbsd box to be able to communicate with the modem and bring the line up? Currently I have this arrangement, which works well: openbsd re0 --- vdsl mode

Re: PPPoE and VDSL2 with a real /29

2016-09-29 Thread tech-lists
On 29/09/2016 02:28, Joe Holden wrote: You can achieve full sized frames via pppoe in that case, mtu 1508 on the re interface facing the modem, mtu 1500 in the pppoe config. Will negate the need for nasty scrubbing which doesn't always prevent problems anyway. awesome, now set as per the man p

Re: PPPoE and VDSL2 with a real /29

2016-09-28 Thread tech-lists
Hi, thanks for replying On 28/09/2016 15:20, Stuart Henderson wrote: No baby jumbos with rl(4) so you are stuck with 1492 MTU, so you need PF so you can do "scrub (max-mss 1440)" as described in pppoe(4)'s "MTU/MSS ISSUES" section. I was mistaken. These are re not rl. How does this alter thin

PPPoE and VDSL2 with a real /29

2016-09-28 Thread tech-lists
Hello misc@ Hoping someone can help me please. I have a bit of a chicken and egg situation with regard to routing real IPs through a PPPoE connection in that I know some of the terms but my understanding is limited on others. I've read around pppoe on freebsd and openbsd and openbsd seems to m