Re: I have $300

2005-11-30 Thread Ian
Awesome - good deal. I have a Netra X1 running openbsd and it's rock solid. Good luck, -Ian On 11/30/05, Bob Ababurko <[EMAIL PROTECTED]> wrote: > > > I totally appreciate everybodies comments and I have in fact decided to > pass over the embedded solution. We just picked up a Sun Netra T105 >

Tables and filter blocks not working as expected...

2005-11-30 Thread Forrest Aldrich
I've a few geoip orientated tables for which I want to block certain traffic. I'm able to match the addresses via pfctl, though the connections from these IP spaces are still getting through, and I'm puzzled. I rdr inbound connections to an RFC addressed server. All mail and web are workin

Re: PF will not redirect to internal boxes

2005-11-30 Thread Jason Dixon
On Nov 30, 2005, at 1:05 PM, Elijah Savage wrote: Anthony Oteri wrote: I was just having this problem last night and just found the solution in the pf faq you may want to look here. http://www.openbsd.org/faq/pf/rdr.html#reflect The bottom of this page describes 3 seperate approaches for

Re: PF will not redirect to internal boxes

2005-11-30 Thread Elijah Savage
It is working but confused as to why it seems that the flags were causing an issue nothing was wrong with the config or the install as I thought. After reading the FAQ again and again and picking up Jacek 2nd edition book and dusting it off I am wondering why I had to this as it seems all that

Re: I have $300

2005-11-30 Thread Bob Ababurko
I totally appreciate everybodies comments and I have in fact decided to pass over the embedded solution. We just picked up a Sun Netra T105 (440Mhz, 512MB)on ebay. It was about $135 shipped and have two onboard NIC's. I have always like Sun hardware and it works well with OpenBSD, it is some o

Re: PF will not redirect to internal boxes

2005-11-30 Thread Elijah Savage
Anthony Oteri wrote: I was just having this problem last night and just found the solution in the pf faq you may want to look here. http://www.openbsd.org/faq/pf/rdr.html#reflect The bottom of this page describes 3 seperate approaches for doing what you want to do. On 11/30/05, Elijah Sav

Re: PF will not redirect to internal boxes

2005-11-30 Thread Jason Dixon
On Nov 30, 2005, at 10:31 AM, Elijah Savage wrote: I am trying to redirect web and mail service to a internal server on the local lan this is my entire pf.conf below and I just can't figure out for the life of me why this does not work. I did a fresh install from 3.6 to 3.8 on a sparc 20 an

RE: PF will not redirect to internal boxes

2005-11-30 Thread Fisher, James L.
Two possible issues: (1) pf will not redirect to another machine on the same interface. Therefore, in your case, any 192.168.11/24 box attempting to connect to the public IP address of the mail server will NOT get redirected back to the private IP address of the mail server because the source and

Re: PF will not redirect to internal boxes

2005-11-30 Thread Anthony Oteri
I was just having this problem last night and just found the solution in the pf faq you may want to look here. http://www.openbsd.org/faq/pf/rdr.html#reflect The bottom of this page describes 3 seperate approaches for doing what you want to do. On 11/30/05, Elijah Savage <[EMAIL PROTECTED]>

Re: PF will not redirect to internal boxes

2005-11-30 Thread Peter N. M. Hansteen
Elijah Savage <[EMAIL PROTECTED]> writes: > Peter I actually have not seen your tutorial I'm a bit relieved it was not my fault (however unlikely). Under any circumstances in my tute I try to stress ruleset keeping the rules as readable as possible as a way to keeping the configuration maintain

Re: PF will not redirect to internal boxes

2005-11-30 Thread Peter N. M. Hansteen
Elijah Savage <[EMAIL PROTECTED]> writes: > #pass traffic from the net to internal host > pass in on $ext_if proto tcp from any to $www_mail port 25 flags S/SA > synproxy state > pass in on $ext_if proto tcp from any to $www_mail port $web_ports flags S/SA > synproxy state hm. looks like you ma

Re: PF will not redirect to internal boxes

2005-11-30 Thread Elijah Savage
Peter N. M. Hansteen wrote: Elijah Savage <[EMAIL PROTECTED]> writes: #pass traffic from the net to internal host pass in on $ext_if proto tcp from any to $www_mail port 25 flags S/SA synproxy state pass in on $ext_if proto tcp from any to $www_mail port $web_ports flags S/SA synproxy stat

PF will not redirect to internal boxes

2005-11-30 Thread Elijah Savage
I am trying to redirect web and mail service to a internal server on the local lan this is my entire pf.conf below and I just can't figure out for the life of me why this does not work. I did a fresh install from 3.6 to 3.8 on a sparc 20 and I am starting to believe something did not go right w

Re: rdr process order

2005-11-30 Thread ed
On Wed, 30 Nov 2005 11:13:52 +0100 Adrian Rudin <[EMAIL PROTECTED]> wrote: > #1 > rdr pass on $lan_if proto { tcp } from $lan_nets to \ > 212.212.212.212 -> 192.168.2.10 > > #2 > rdr pass on $lan_if proto tcp from any to any port www -> \ > 127.0.0.1 port 3128 > > I want the us

Re: spamd vs the sober worm

2005-11-30 Thread Travis H.
It looks like you forgot to sort before you uniq. Most uniq programs I've worked with require the data to be sorted first; they just store the last line in memory for comparisons. Since you've got to run sort anyway, you can use the -u flag. -- http://www.lightconsulting.com/~travis/ -><- "We al

Re: rdr process order

2005-11-30 Thread Adrian Rudin
No $lan_if is correct. Because 192.168.2.10 is a webserver in my dmz and the dns server resolves the url to 212.212.212.212 for the outside world and i use the same dns for my internal network (192.168.1.0/24). The browser in the internal network now connects to the webserver with 212.212.212.2

Re: rdr process order

2005-11-30 Thread Daniel Hartmeier
On Wed, Nov 30, 2005 at 11:13:52AM +0100, Adrian Rudin wrote: > I have a question concering redirection. > These two rdr's are in my pf.conf: > > #1 > rdr pass on $lan_if proto { tcp } from $lan_nets to \ > 212.212.212.212 -> 192.168.2.10 You probably want 'on $ext_if' in this rule, not

rdr process order

2005-11-30 Thread Adrian Rudin
Hello, I have a question concering redirection. These two rdr's are in my pf.conf: #1 rdr pass on $lan_if proto { tcp } from $lan_nets to \ 212.212.212.212 -> 192.168.2.10 #2 rdr pass on $lan_if proto tcp from any to any port www -> \ 127.0.0.1 port 3128 I want the usual web tr