<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0">
  <channel>
  <title>bit.listserv.openbsd-pf Google Group</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf</link>
  <description>Discussion of OpenBSD Packet Filter.</description>
  <language>en</language>
  <item>
  <title>Re: pf is blocking too much connections?</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/d9ecc1d54dae7c04/4e6c774e991f630c?show_docid=4e6c774e991f630c</link>
  <description>
  The statistics don&#39;t really show us much of anything by themselves. &lt;br&gt; What are the actual error messages? What does your rule set say? Do &lt;br&gt; you have meaningful log data (pflog or otherwise)? That&#39;s the kind of &lt;br&gt; information we would need to help you debug, diagnose and fix. &lt;br&gt; One random thought - does your rule set include such things as limits
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/d9ecc1d54dae7c04/4e6c774e991f630c?show_docid=4e6c774e991f630c</guid>
  <author>
  pe...@bsdly.net
  (Peter N. M. Hansteen)
  </author>
  <pubDate>Sat, 14 Nov 2009 21:02:24 UT
</pubDate>
  </item>
  <item>
  <title>Re: pf is blocking too much connections?</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/d9ecc1d54dae7c04/b212bcd0982bef48?show_docid=b212bcd0982bef48</link>
  <description>
  Looking at these stats, I would guess that you are running with the &lt;br&gt; default limit of states, 10,000. You have nearly 10,000 in your state &lt;br&gt; table now, and every time you get to the limit, new connections fail &lt;br&gt; (the &#39;memory&#39; counter: 13.7/s). &lt;br&gt; You can check with pfctl -sm, and change the limit with &#39;set limit
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/d9ecc1d54dae7c04/b212bcd0982bef48?show_docid=b212bcd0982bef48</guid>
  <author>
  mcbr...@openbsd.org
  (Ryan McBride)
  </author>
  <pubDate>Sat, 14 Nov 2009 12:08:51 UT
</pubDate>
  </item>
  <item>
  <title>pf is blocking too much connections?</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/d9ecc1d54dae7c04/3eff0d1a3d32f6a1?show_docid=3eff0d1a3d32f6a1</link>
  <description>
  Hi, &lt;br&gt; I have a openbsd pf firewall protecting a web server, I have noticed that &lt;br&gt; some pages gives me errors when browsing through my site (sometimes it works &lt;br&gt; sometimes not), then I looked at pf and saw that is blocking a lot of &lt;br&gt; connectyions, how do I know which connections is blocking? &lt;br&gt; Status: Enabled for 202 days 23:34:57 Debug: Urgent
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/d9ecc1d54dae7c04/3eff0d1a3d32f6a1?show_docid=3eff0d1a3d32f6a1</guid>
  <author>
  ventas_en_e...@terra.es
  (LeiV)
  </author>
  <pubDate>Sat, 14 Nov 2009 11:38:57 UT
</pubDate>
  </item>
  <item>
  <title>Filter on specific TTL value?</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/87c777a6a13848e6/b30b839abe2ed88b?show_docid=b30b839abe2ed88b</link>
  <description>
  Hi, &lt;br&gt; Is it possible to filter on a specific TTL value? Long story short: &lt;br&gt; there are rogue packets being generated somewhere in our network&#39;s core, &lt;br&gt; and I can reliably identify them with a combination of IP TOS, TCP flags &lt;br&gt; and TTL value. I&#39;d like to filter them out with pf if at all possible. &lt;br&gt; Cheers
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/87c777a6a13848e6/b30b839abe2ed88b?show_docid=b30b839abe2ed88b</guid>
  <author>
  ian.ch...@sers.ox.ac.uk
  (Ian Chard)
  </author>
  <pubDate>Thu, 12 Nov 2009 14:34:40 UT
</pubDate>
  </item>
  <item>
  <title>Re: CBQ download limits failed...</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e1376e77510210e4/12ccb683d39bfca6?show_docid=12ccb683d39bfca6</link>
  <description>
  On Wed, 11 Nov 2009 17:26:06 +0100 &lt;br&gt; Limiting incoming bandwidth on the external interface doesn&#39;t work. &lt;br&gt; You can have some success if you queue traffic to your lan on the &lt;br&gt; internal interface. &lt;br&gt; Have a look at the pf faq &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.openbsd.org/faq/pf/queueing.html&quot;&gt;[link]&lt;/a&gt; , &lt;br&gt; especially the examples. &lt;br&gt; - Robert
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e1376e77510210e4/12ccb683d39bfca6?show_docid=12ccb683d39bfca6</guid>
  <author>
  rob...@openbsd.pap.st
  (Robert)
  </author>
  <pubDate>Thu, 12 Nov 2009 08:04:37 UT
</pubDate>
  </item>
  <item>
  <title>Re: CBQ download limits failed...</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e1376e77510210e4/f2aacd7188b314eb?show_docid=f2aacd7188b314eb</link>
  <description>
  HI, &lt;br&gt; (...) &lt;br&gt; (...) &lt;br&gt; You defined altq rule and queue for nomy2 on $ext_if2 but the pass rule &lt;br&gt; is on $int_if. &lt;br&gt; Add a &#39;pass out&#39; rule on $ext_if2 to assign packets in &#39;nomy2&#39; queue and &lt;br&gt; modify your &#39;pass in on $int_if&#39; rule. &lt;br&gt; Laurent
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e1376e77510210e4/f2aacd7188b314eb?show_docid=f2aacd7188b314eb</guid>
  <author>
  f...@free.fr
  (Laurent Cheylus)
  </author>
  <pubDate>Thu, 12 Nov 2009 00:09:43 UT
</pubDate>
  </item>
  <item>
  <title>CBQ download limits failed...</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e1376e77510210e4/a848e20455aa9e86?show_docid=a848e20455aa9e86</link>
  <description>
  Hi all, &lt;br&gt; I&#39;m trying to implement queue using PF in OpenBSD box. The pf.conf looks &lt;br&gt; like: &lt;br&gt; ext_if1=&amp;quot;fxp0&amp;quot; &lt;br&gt; ext_gw1=&amp;quot;217.126.43.2&amp;quot; &lt;br&gt; ext_if2=&amp;quot;bge1&amp;quot; &lt;br&gt; ext_gw2=&amp;quot;192.168.10.1&amp;quot; &lt;br&gt; lesmes=&amp;quot;192.168.0.121&amp;quot; &lt;br&gt; alejandro=&amp;quot;192.168.0.51&amp;quot; &lt;br&gt; xevi=&amp;quot;192.168.0.124&amp;quot; &lt;br&gt; santi=&amp;quot;192.168.0.49&amp;quot; &lt;br&gt; dominis = &amp;quot;{&amp;quot; $lesmes $alejandro $xevi $santi &amp;quot;}&amp;quot;
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e1376e77510210e4/a848e20455aa9e86?show_docid=a848e20455aa9e86</guid>
  <author>
  jordi.esp...@opengea.org
  (Jordi Espasa Clofent)
  </author>
  <pubDate>Wed, 11 Nov 2009 16:59:58 UT
</pubDate>
  </item>
  <item>
  <title>RE: Trace packets through PF</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/3de44abe4db5252a/cd9ad1f8a32467a6?show_docid=cd9ad1f8a32467a6</link>
  <description>
  Hello Elliott: &lt;br&gt; You can look at the state tables with &#39;pfctl -s state&#39;. It&#39;s not packet &lt;br&gt; based but, rather, flow based. That will show you whether or not you &lt;br&gt; have state all the way through your PF box. If you believe it&#39;s being &lt;br&gt; blocked, use &#39;block in log&#39; in /etc/pf.conf and then &#39;tcpdump -n -e -ttt
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/3de44abe4db5252a/cd9ad1f8a32467a6?show_docid=cd9ad1f8a32467a6</guid>
  <author>
  mksm...@adhost.com
  (Michael K. Smith - Adhost)
  </author>
  <pubDate>Tue, 10 Nov 2009 19:38:45 UT
</pubDate>
  </item>
  <item>
  <title>Trace packets through PF</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/3de44abe4db5252a/dd1e3b6319ada829?show_docid=dd1e3b6319ada829</link>
  <description>
  Hi all, &lt;br&gt; Is there a general way to watch a packet&#39;s progress through PF and see &lt;br&gt; when and where it&#39;s stopped? Something akin to &amp;quot;packet-tracer&amp;quot; on &lt;br&gt; Cisco maybe? &lt;br&gt; Thanks in advance! &lt;br&gt; -elliott-
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/3de44abe4db5252a/dd1e3b6319ada829?show_docid=dd1e3b6319ada829</guid>
  <author>
  elli...@mywedding.com
  (Elliott Barrere)
  </author>
  <pubDate>Tue, 10 Nov 2009 19:05:20 UT
</pubDate>
  </item>
  <item>
  <title>Re: german t-com´s vdsl</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/9853cbfe2ac0b189?show_docid=9853cbfe2ac0b189</link>
  <description>
  Am 07.11.2009 um 07:08 schrieb Tobias Wigand: &lt;br&gt; Did you have a look at XORP &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.openbsd.org/4.3_packages/sparc64/xorp-1.4p1.tgz-long.html&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; ? &lt;br&gt; So, your linux box is not involved in none-IPTV traffic via VDSL? &lt;br&gt; Axel &lt;br&gt; --- &lt;br&gt; axel....@chaos1.de PGP-Key:29E99DD6 +49 151 2300 9283 computing @ &lt;br&gt; chaos claudius
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/9853cbfe2ac0b189?show_docid=9853cbfe2ac0b189</guid>
  <author>
  axel....@chaos1.de
  (Axel Rau)
  </author>
  <pubDate>Sat, 07 Nov 2009 13:25:47 UT
</pubDate>
  </item>
  <item>
  <title>Re: german t-com´s vdsl</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/cc1a8277705abe35?show_docid=cc1a8277705abe35</link>
  <description>
  Hi, &lt;br&gt; Yes I had but there was no IGMP Proxy functionality. It was on the TODO &lt;br&gt; list though. &lt;br&gt; It just does Multicast Routing / IGMP proxying, announces the few nets &lt;br&gt; that have to be routed via Vlan8 dynamically and firewalls itself with &lt;br&gt; user unfriendly IPTables ;) &lt;br&gt; On a sidenote, I would order the cheapest IPTV VDSL offer. The others
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/cc1a8277705abe35?show_docid=cc1a8277705abe35</guid>
  <author>
  li...@underscore.de
  (Tobias Wigand)
  </author>
  <pubDate>Sat, 07 Nov 2009 13:09:43 UT
</pubDate>
  </item>
  <item>
  <title>Re: german t-com´s vdsl</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/39d461d9ff7896a2?show_docid=39d461d9ff7896a2</link>
  <description>
  Assuming the same technical infrastructure is used for that offer: yes. &lt;br&gt; I have always found the guys at the onlinekosten.de forum to be very &lt;br&gt; helpful, maybe you can ask there to know for sure. &lt;br&gt; Never tried that. &lt;br&gt; Anyway the HowTo is outdated and does not work anymore for IPTV. Vlan8 &lt;br&gt; is used for Multicast now and the required IGMP version is v3 there.
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/39d461d9ff7896a2?show_docid=39d461d9ff7896a2</guid>
  <author>
  li...@underscore.de
  (Tobias Wigand)
  </author>
  <pubDate>Sat, 07 Nov 2009 06:48:05 UT
</pubDate>
  </item>
  <item>
  <title>Re: german t-com´s vdsl</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/a57aeeaea9318db8?show_docid=a57aeeaea9318db8</link>
  <description>
  Am 22.01.2008 um 09:12 schrieb Tobias Wigand: &lt;br&gt; 2 questions come into mind: &lt;br&gt; - Does the new IP-only (w/o IPTV) offer (started in Sep-2009 by German &lt;br&gt; Telekom) &lt;br&gt; still requires the vlan setup? &lt;br&gt; - How does the vlan setup interferes with a carp/pfsync configuration? &lt;br&gt; Axel &lt;br&gt; --- &lt;br&gt; axel....@chaos1.de PGP-Key:29E99DD6 +49 151 2300 9283 computing @
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/e82b1b9b705f4947/a57aeeaea9318db8?show_docid=a57aeeaea9318db8</guid>
  <author>
  axel....@chaos1.de
  (Axel Rau)
  </author>
  <pubDate>Thu, 05 Nov 2009 10:06:51 UT
</pubDate>
  </item>
  <item>
  <title>Virgin Hate: Virgin Forced Clips</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/68cd29165c5867b6/6a7b89e437a0733e?show_docid=6a7b89e437a0733e</link>
  <description>
  ============================== ============================== ============= &lt;br&gt; ========= My sister lose her virginity with me (video) &lt;br&gt; ========= &lt;br&gt; VVVVVVVVVVVVVVVVVVVVVVVVVVVVVV VVVVVVVVVVVVVVVVVVVVVVVVVVVVVV VVVVVVVVVVVV &lt;br&gt; ========= ENTER HERE: &lt;br&gt; ========= &lt;br&gt; ========= &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://movie33.biz/video/us3n&quot;&gt;[link]&lt;/a&gt;
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/68cd29165c5867b6/6a7b89e437a0733e?show_docid=6a7b89e437a0733e</guid>
  <author>
  woodsonpec...@gmail.com
  (peck Woodson)
  </author>
  <pubDate>Tue, 03 Nov 2009 12:35:00 UT
</pubDate>
  </item>
  <item>
  <title>Re: syntax error while using scrub with OpenBSD 4.6</title>
  <link>http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/f2ea40655a8ed2af/4ab8b73b72fc6054?show_docid=4ab8b73b72fc6054</link>
  <description>
  &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.openbsd.org/faq/upgrade46.html#newPF&quot;&gt;[link]&lt;/a&gt;
  </description>
  <guid isPermaLink="true">http://groups.google.com.au/group/bit.listserv.openbsd-pf/browse_thread/thread/f2ea40655a8ed2af/4ab8b73b72fc6054?show_docid=4ab8b73b72fc6054</guid>
  <author>
  stephan.ricka...@startek.ch
  (Stephan A. Rickauer)
  </author>
  <pubDate>Wed, 28 Oct 2009 13:07:12 UT
</pubDate>
  </item>
  </channel>
</rss>
