Re: pf and rpi

2014-10-07 Thread Zoran Kolic
Why are you trying to change the security level to -1? If you want to load a kernel module, you need simply to do so before the system is running at securelevel 1 during the boot process. Exactelly! I was wondering if it was possible to just load the module and pfctl/npfctl latter. With help

Re: pf and rpi

2014-10-06 Thread Thor Lancelot Simon
On Sat, Oct 04, 2014 at 05:03:41AM +0200, Zoran Kolic wrote: I'm afraid it does not work like that. Last win is firewall's internal. Having not used npf ever, I might say that final word makes it stop further checking. At the moment I stranded myself on securelevel. For some reason I just

Re: pf and rpi

2014-10-04 Thread Christos Zoulas
In article 20141004041529.gb...@deimos.ergonaut.org, Malcolm Herbert m...@mjch.net wrote: -=-=-=-=-=- On Sat, Oct 04, 2014 at 02:47:52AM +0200, Rhialto wrote: |On Fri 03 Oct 2014 at 16:25:58 +0200, Zoran Kolic wrote: | On freebsd I use ipfw, with rules that first one wins. On pf I know | that

Re: pf and rpi

2014-10-03 Thread Rhialto
On Fri 03 Oct 2014 at 16:25:58 +0200, Zoran Kolic wrote: On freebsd I use ipfw, with rules that first one wins. On pf I know that the last one wins. Cannot be so sure reading npf howto. My bet is that the last wins too. I've never understood the reason for last one wins. That seems like

Re: pf and rpi

2014-10-03 Thread Malcolm Herbert
On Sat, Oct 04, 2014 at 02:47:52AM +0200, Rhialto wrote: |On Fri 03 Oct 2014 at 16:25:58 +0200, Zoran Kolic wrote: | On freebsd I use ipfw, with rules that first one wins. On pf I know | that the last one wins. Cannot be so sure reading npf howto. My bet | is that the last wins too. | |I've never

Re: pf and rpi

2014-10-02 Thread Zoran Kolic
Is the serial port not working with netbsd? With Raspbian I often use a FTDI cable to access the system over the serial port. I put rpi behind the closet. I see this as a proof of the concept. Aside my previous idea (pfctl; shutdown -r +10), I got answer: sleep sometime; pfctl -d My biggest

Re: pf on rpi

2014-10-02 Thread Zoran Kolic
Just after I made a decission what to do, I stopped on the very first step: # modload pf modload: Operation not permitted So, I have not pf module loaded at all. How could I solve this issue? 7.99.1 on rpi. Best regards Zoran

Re: pf and rpi

2014-10-02 Thread David Lord
On 2 Oct 2014 at 21:20, Christian Koch wrote: On Thu, Oct 02, 2014 at 04:06:22PM +0200, Zoran Kolic wrote: I put rpi behind the closet. I see this as a proof of the concept. Aside my previous idea (pfctl; shutdown -r +10), I got answer: sleep sometime; pfctl -d My biggest puzzle is

pf and rpi

2014-10-01 Thread Zoran Kolic
I intent to load pf firewall on rpi and not stay locked out of the node. The only comminication is via ssh. My plan is to try out rules and, for every safety, reboot the node to state without pf. Like this: # modload pf # pfctl -f /etc/pf.conf; shutdown -r +10 If I make permanent move to pf=YES

Re: pf and rpi

2014-10-01 Thread J. Lewis Muir
On 10/1/14 9:57 AM, Zoran Kolic wrote: I intent to load pf firewall on rpi and not stay locked out of the node. The only comminication is via ssh. Hi, Zoran. You're right about putting pf=YES in /etc/rc.conf; I would not do that until I was confident my configuration was right. Does rpi mean

Re: pf and rpi

2014-10-01 Thread uhel
On Wed, 1 Oct 2014 16:57:14 +0200 Zoran Kolic zko...@sbb.rs wrote: If I make permanent move to pf=YES and make a mistake, I would have to install from the scratch. Is the serial port not working with netbsd? With Raspbian I often use a FTDI cable to access the system over the serial port.