Simple networking question

2005-10-05 Thread Talmage
Is there anyway of making a pppoe0 interface part of a bridge? I'm trying to setup a stealth ethernet bridge that does packet filtering, and also want it to act as a pppoe client. Kory T

squid mime-type blocking

2005-10-05 Thread Florian
Hi When I try to allow only a few mime-types, I only get an access denied Is there a way ? Thanks a lot There's my config: acl auth_param basic program /usr/local/squid/bin/ncsa_auth /etc/squid/squid_passwd acl manager proto cache_object acl localhost src 127.0.0.1/255.255.255.255 acl all

Re: OpenBSD on Nokia IP3300?

2005-10-05 Thread Simon Slaytor
Not an IP330 but I am currently running 3.6 on an IP120. Install was done on a surrogate PC and the hard drive transfered over to the 120 after install. Whilst the AMD processors aren't the most spritely my little 120 is running a 3DES VPN with PSK between it and a Checkpoint NG box and

Por favor, confirme su pedido de suscripción a espadaverdad

2005-10-05 Thread Yahoo! Grupos
Hola misc@openbsd.org, Hemos recibido su pedido de unirse al grupo espadaverdadde Yahoo! Grupos, un servicio de comunidades gratuito y simple. Esta peticisn caducara en 7 dmas. PARA HACERSE MIEMBRO DEL GRUPO: 1) Vaya al sitio de Yahoo! Grupos haciendo clic en:

problems with new macppc snapshot

2005-10-05 Thread Antoine Jacoutot
Hi... I've just upgraded my Powerbook G4 to the latest macppc snapshot and now I have a problem booting. Under openfirwware, I type the following : boot hd:,ofwboot /bsd It starts fine (as it always did for the last 10 months), the kernel gets loaded _but_ it looks like it does not find the

resize a partition

2005-10-05 Thread Abel Talaverón Estevez
Hi all, How could I resize an OpenBSD partition? I have a /var partition of 20 GB and I want to have it of about 1 GB and I don't know how to do it. thanks a lot -- Abel Talaversn Estevez Ingeniero Superior de Telecomunicaciones Analista de Proyectos OpenWired Caballero 87 - Bajos 08029 -

Re: OpenBSD and KDE printing

2005-10-05 Thread Rico
Daniel Martini wrote: Check this post: http://marc.theaimsgroup.com/?l=openbsd-miscm=112422708302678w=2 Hi Daniel The post solved the issue! Thanks a lot! I found that it is possible to get CUPS (partial) working with this: In home-directory .kde/share/config/kdeprintrc [General]

Re: nat vpn pptp issues

2005-10-05 Thread James Wright
frickin, discussed here: http://www.undeadly.org/cgi?action=articlesid=20041009000521 though the frickin sourceforge page does not appear to be functional you can still download the tarball. Only supports one pptp server.

Re: resize a partition

2005-10-05 Thread Vjacheslav V. Borisov
How could I resize an OpenBSD partition? I have a /var partition of 20 GB and I want to have it of about 1 GB and I don't know how to do it. You cannot shrink partition, but you can create another one. You can copy /var contents to another partition with enough free space using cp: cp

Re: squid mime-type blocking

2005-10-05 Thread Gleydson Soares
When I try to allow only a few mime-types, I only get an access denied Is there a way ? yes http_access deny !allowed_mime http_reply_access deny !allowed_mime

Re: squid mime-type blocking

2005-10-05 Thread Florian Sander
When I try to allow only a few mime-types, I only get an access denied Is there a way ? yes http_access deny !allowed_mime http_reply_access deny !allowed_mime no, I get the same error :-(

xorg with Nvidia Go5600 at 1600x1200

2005-10-05 Thread stefan hoffmann
hi, is there anybody out there who has a running setup of xorg for a Nvidia Go5600 with a screen resolution of 1600x1200x32 and can give me some hints? As far as i can see, the nv generic driver is not capable of this mode. btw, i'd like to get my Vaio PCG-GRT796SP to run X. -- ste5an -- --

linksys WMP11 oversized packet received issue

2005-10-05 Thread edgar mortiz
im planning to build a AP using Openbsd i currently have a Linksys WMP11 Card, i was able to manage setting it up but i get a lot of the following message, that eventually kills wifi connection and so does the rest of the wired network. (please see below) wi0: oversized packet received

Re: linksys WMP11 oversized packet received issue

2005-10-05 Thread Melameth, Daniel D.
edgar mortiz wrote: im planning to build a AP using Openbsd i currently have a Linksys WMP11 Card, i was able to manage setting it up but i get a lot of the following message, that eventually kills wifi connection and so does the rest of the wired network. (please see below) wi0: oversized

Re: Webmail recommendations?

2005-10-05 Thread Ray Lai
On Tue, Oct 04, 2005 at 01:20:24PM -0500, Bob Bostwick (Lists) wrote: Not sure if it will run on OBSD or not (haven't had time to try yet...), but hands down Zimbra is the best looking web interface out there - including Exchange OWA. http://www.zimbra.com/ Egads, it's 150 MB! Just for

Re: Webmail recommendations?

2005-10-05 Thread Jason Dixon
On Oct 5, 2005, at 10:38 AM, Ray Lai wrote: On Tue, Oct 04, 2005 at 01:20:24PM -0500, Bob Bostwick (Lists) wrote: Not sure if it will run on OBSD or not (haven't had time to try yet...), but hands down Zimbra is the best looking web interface out there - including Exchange OWA.

Re: problems with new macppc snapshot

2005-10-05 Thread Theo de Raadt
I've just upgraded my Powerbook G4 to the latest macppc snapshot and now I have a problem booting. Under openfirwware, I type the following : boot hd:,ofwboot /bsd It starts fine (as it always did for the last 10 months), the kernel gets loaded _but_ it looks like it does not find the

altq traffic limitations

2005-10-05 Thread Chris Smith
Regarding the altq implementation in pf: Is altq effective with all types of protocols/traffic, such as ah, esp, gre, etc.? Thanks. Chris

Re: Load Balancing

2005-10-05 Thread Chris Smith
On Tuesday 04 October 2005 01:54 am, Manpreet Singh Nehra wrote: #NAT Rules #Local Lan to Internet nat on $ext_if1 from $lan_net to any - ($ext_if1) nat on $ext_if2 from $lan_net to any

Re: Load Balancing

2005-10-05 Thread Chris Smith
On Wednesday 05 October 2005 01:03 pm, Chris Smith wrote: nat on !($int_if) from $lan_net to any - gateway_addresses \ round-robin sticky-address Ooops...I think that () around $int_if will not work. Should read: nat on !$int_if from $lan_net to any - gateway_addresses \

Re: Load Balancing

2005-10-05 Thread Stuart Henderson
nat on !($int_if) from $lan_net to any - gateway_addresses \ round-robin sticky-address That changes the source address on the packets, but doesn't affect where they're sent. Without reply-to/route-to, the route taken by an outgoing packet is dependent only on the destination address,

Re: PPTP client

2005-10-05 Thread Waldemar Brodkorb
Hi, Otto Moerbeek wrote, On Fri, 30 Sep 2005, Peter Bako wrote: I have a situation where I need to connect an OpenBSD box to a MS Windows PPTP server (yep, I know it is not secure, but in this case I have no choice in the matter). After looking around the net I found myself at

Re: PPTP client

2005-10-05 Thread Okan Demirmen
On Fri 2005.09.30 at 14:51 -0700, Peter Bako wrote: I have a situation where I need to connect an OpenBSD box to a MS Windows PPTP server (yep, I know it is not secure, but in this case I have no choice in the matter). After looking around the net I found myself at

After upgrading the source tree the kernel building process fails!

2005-10-05 Thread João Salvatti
Hi all, I upgraded my OpenBSD 3.7 system's source code running this command: cvs -q up -rOPENBSD_3_7 -Pd Ok, everything worked fine, the source files were updated. Following the instructions contained in http://www.openbsd.org/anoncvs.html, there says that before compiling a new kernel I should

Re: squid mime-type blocking

2005-10-05 Thread Joe S
Florian wrote: Hi When I try to allow only a few mime-types, I only get an access denied Is there a way ? Are you telling squid to re-read it's configuration? # squid -k reconfigure -joe

Re: squid mime-type blocking

2005-10-05 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Gleydson Soares wrote: http_access deny !allowed_mime http_reply_access deny !allowed_mime - From the Squid configuration file: acl aclname req_mime_type mime-type1 ... # regex match agains the mime type of the request generated # by

Re: squid mime-type blocking

2005-10-05 Thread Andrew Rucker Jones
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 So, since his ACLs were all for req_mime_type, adding the line You suggested doesn't solve the problem. I would venture to say that the -i may be causing problems, since it's not listed as an option to req_mime_type. Uncommenting the

Re: WLAN (Linksys WPC111) + WEP

2005-10-05 Thread Nikolaus Hiebaum
ifconfig wi0 192.168.200.2 255.255.255.0 nwid scyld nwkey BACE8A21EA According to the ifconfig man page, The key can either be a string, a series of hexadecimal digits (preceded by `0x'), or a set of keys... So I would try that. Unfortunately, that didn't help. -- Beste Gr|_e / Best

sparc64 needed in Brazil

2005-10-05 Thread Pedro Martelletto
Hi, I wonder if there's any OpenBSD user in Brazil who would be willing to donate a sparc64 box to help on my development efforts? I work in the kernel, and having access to such an architecture would be great. The look-out is currently for people in Brazil only, since our customs tends to

Re: BGP session clear by remote end when MD5 is configure AND the session was initiate from OpenBSD side failed and do not recover.

2005-10-05 Thread Daniel Ouellet
More on this with test results, example, setup use, and more details. The short of it is that bgpd will not establish an MD5 connection as slave ever! So, if you do get an MD5 session in normal operation, it may well not stay stable at all depending of bgp flap and who will try to become

Problems with your account !!!

2005-10-05 Thread e-gold
[IMAGE]Dear E-gold user. The Company E-gold ltd. in common with the personal security service informs you, that very serious vulnerability has been found recently in software products from Misrosoft. Since our server uses platform WinNT, our server is also subject to vulnerability,

Re: altq traffic limitations

2005-10-05 Thread jared r r spiegel
On Wed, Oct 05, 2005 at 12:07:01PM -0400, Chris Smith wrote: Regarding the altq implementation in pf: Is altq effective with all types of protocols/traffic, such as ah, esp, gre, etc.? ? altq is as effective as your understanding of it and your implementation. being that it is

Using PF, route-to with prejudice ;-)

2005-10-05 Thread Dave Harrison
Hi all, I have two links, a rather costly one, and a cheap high bandwidth one. I prefer to use the cheap one whenever possible, but if it goes down I want to fail over onto the expensive one. This rule (from the PF FAQ) will let me round-robin my outgoing connections : pass in on $int_if

Re: xorg with Nvidia Go5600 at 1600x1200

2005-10-05 Thread pirge
nv will do 1600x1200 - I run a geforce 2 go (dell inspiron 8100) with openbsd 3.7 generic at that resolution. Need to see your xorg.conf and xorg log Reading the nv man page I'm not sure it supports the Go5600..? On 06/10/05, stefan hoffmann [EMAIL PROTECTED] wrote: hi, is there anybody out

Re: Using PF, route-to with prejudice ;-)

2005-10-05 Thread Melameth, Daniel D.
Dave Harrison wrote: I have two links, a rather costly one, and a cheap high bandwidth one. I prefer to use the cheap one whenever possible, but if it goes down I want to fail over onto the expensive one. This rule (from the PF FAQ) will let me round-robin my outgoing connections : pass

Re: Ipsec vpn tunnel x509 phase 2 does not start.

2005-10-05 Thread jared r r spiegel
On Wed, Oct 05, 2005 at 01:20:57AM +, [EMAIL PROTECTED] wrote: Having trouble brining up a tunnel. a nice compromise between debug output and too much info, i've found thus far is: -dDA=0 -D2=50 -D5=50 -D7=50 -D8=40 -D9=30 Though never seems to move on to phase 2 see snip 2 ...

SK-9821 v2 cards, TX consuming massive CPU time, RX affected

2005-10-05 Thread Michael Blodgett
I'm working on increasing the performance of our firewalls, we picked up two of the newer v2 syskonnect cards for testing, I was getting pretty low performance from the bridge so I started testing things using a card as an endpoint. I was using Iperf to generate packets, but to make sure it

Re: Webmail recommendations?

2005-10-05 Thread Roy Morris
Jason Dixon wrote: On Oct 5, 2005, at 10:38 AM, Ray Lai wrote: On Tue, Oct 04, 2005 at 01:20:24PM -0500, Bob Bostwick (Lists) wrote: Not sure if it will run on OBSD or not (haven't had time to try yet...), but hands down Zimbra is the best looking web interface out

Re: detect if a flag-day has happened in the meanwhile

2005-10-05 Thread STeve Andre'
On Sunday 02 October 2005 20:41, Han Boetes wrote: Hi, I am wondering if there is a good way to check if a flag-day has passed if you have both the new and old kernel. How can I check that? # Han Um, given that a flag day is a code change, the only way I know of is to 1) subscribe to the

Fwd: ntop

2005-10-05 Thread Jernej Vodopivec
Forgot to cc: -- Forwarded message -- From: Jernej Vodopivec [EMAIL PROTECTED] Date: Oct 2, 2005 8:36 PM Subject: Re: ntop To: Brian A. Seklecki [EMAIL PROTECTED] I think he wants to compile version 3.1 - in ports tree there is version 1.1. Are there any plans yes about

Re: detect if a flag-day has happened in the meanwhile

2005-10-05 Thread knitti
On 10/3/05, Han Boetes [EMAIL PROTECTED] wrote: But this is not for me. This is to automate a sysadmin task. So I'd like to automate detecting a ``flag day.'' I know you stated you want to compare the binaries. But somewhere the new kernel has to be built, so you check the cvs output for a /M

Patch to log all chmod +s/4000 on binaries owned by root.

2005-10-05 Thread ober
I wanted the ability to log to my logging server anytime a binary, owned by root, was modified via sys_chmod to set the SETUID bit. I find it of use. Please feel free to send constructive feedback, and keep your flames. As my /dev/null is starting to get pretty full.

Re: detect if a flag-day has happened in the meanwhile

2005-10-05 Thread Antti Nykänen
Hi, On 2005-10-06 at 04:17, knitti wrote: On 10/3/05, Han Boetes [EMAIL PROTECTED] wrote: But this is not for me. This is to automate a sysadmin task. So I'd like to automate detecting a ``flag day.'' I know you stated you want to compare the binaries. But somewhere the new kernel has to