From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 11:01:50 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2608D16A431 for ; Mon, 15 Aug 2005 11:01:50 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id C8D8743D49 for ; Mon, 15 Aug 2005 11:01:49 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (peter@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.3/8.13.3) with ESMTP id j7FB1nbG007500 for ; Mon, 15 Aug 2005 11:01:49 GMT (envelope-from owner-bugmaster@freebsd.org) Received: (from peter@localhost) by freefall.freebsd.org (8.13.3/8.13.1/Submit) id j7FB1nbo007494 for freebsd-ipfw@freebsd.org; Mon, 15 Aug 2005 11:01:49 GMT (envelope-from owner-bugmaster@freebsd.org) Date: Mon, 15 Aug 2005 11:01:49 GMT Message-Id: <200508151101.j7FB1nbo007494@freefall.freebsd.org> X-Authentication-Warning: freefall.freebsd.org: peter set sender to owner-bugmaster@freebsd.org using -f From: FreeBSD bugmaster To: freebsd-ipfw@FreeBSD.org Cc: Subject: Current problem reports assigned to you X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 11:01:50 -0000 Current FreeBSD problem reports Critical problems Serious problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- o [2003/04/22] kern/51274 ipfw ipfw2 create dynamic rules with parent nu f [2003/04/24] kern/51341 ipfw ipfw rule 'deny icmp from any to any icmp o [2003/12/11] kern/60154 ipfw ipfw core (crash) o [2004/03/03] kern/63724 ipfw IPFW2 Queues dont t work o [2004/11/13] kern/73910 ipfw [ipfw] serious bug on forwarding of packe o [2004/11/19] kern/74104 ipfw ipfw2/1 conflict not detected or reported f [2004/12/25] kern/75483 ipfw ipfw count does not count o [2005/05/11] bin/80913 ipfw /sbin/ipfw2 silently discards MAC addr ar 8 problems total. Non-critical problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- o [2004/10/29] kern/73276 ipfw ipfw2 vulnerability (parser error) o [2005/02/01] kern/76971 ipfw ipfw antispoof incorrectly blocks broadca o [2005/05/05] kern/80642 ipfw [patch] IPFW small patch - new RULE OPTIO o [2005/06/28] kern/82724 ipfw [patch] Add setnexthop and defaultroute f 4 problems total. From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 11:02:27 2005 Return-Path: X-Original-To: ipfw@freebsd.org Delivered-To: freebsd-ipfw@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 874C716A44B for ; Mon, 15 Aug 2005 11:02:27 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id D651943D48 for ; Mon, 15 Aug 2005 11:02:26 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (peter@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.3/8.13.3) with ESMTP id j7FB2QlR008059 for ; Mon, 15 Aug 2005 11:02:26 GMT (envelope-from owner-bugmaster@freebsd.org) Received: (from peter@localhost) by freefall.freebsd.org (8.13.3/8.13.1/Submit) id j7FB2PBs008053 for ipfw@freebsd.org; Mon, 15 Aug 2005 11:02:25 GMT (envelope-from owner-bugmaster@freebsd.org) Date: Mon, 15 Aug 2005 11:02:25 GMT Message-Id: <200508151102.j7FB2PBs008053@freefall.freebsd.org> X-Authentication-Warning: freefall.freebsd.org: peter set sender to owner-bugmaster@freebsd.org using -f From: FreeBSD bugmaster To: ipfw@FreeBSD.org Cc: Subject: Current problem reports assigned to you X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 11:02:27 -0000 Current FreeBSD problem reports Critical problems Serious problems Non-critical problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- a [2001/04/13] kern/26534 ipfw Add an option to ipfw to log gid/uid of w o [2002/12/10] kern/46159 ipfw ipfw dynamic rules lifetime feature o [2003/02/11] kern/48172 ipfw ipfw does not log size and flags o [2003/03/10] kern/49086 ipfw [patch] Make ipfw2 log to different syslo o [2003/04/09] bin/50749 ipfw ipfw2 incorrectly parses ports and port r o [2003/08/26] kern/55984 ipfw [patch] time based firewalling support fo o [2003/12/30] kern/60719 ipfw ipfw: Headerless fragments generate cryp o [2004/08/03] kern/69963 ipfw ipfw: install_state warning about already o [2004/09/04] kern/71366 ipfw "ipfw fwd" sometimes rewrites destination 9 problems total. From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 12:38:36 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3D9C116A41F for ; Mon, 15 Aug 2005 12:38:36 +0000 (GMT) (envelope-from unixtools@hotmail.com) Received: from hotmail.com (bay106-f14.bay106.hotmail.com [65.54.161.24]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0B99843D46 for ; Mon, 15 Aug 2005 12:38:36 +0000 (GMT) (envelope-from unixtools@hotmail.com) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Mon, 15 Aug 2005 05:38:35 -0700 Message-ID: Received: from 65.54.161.200 by by106fd.bay106.hotmail.msn.com with HTTP; Mon, 15 Aug 2005 12:38:35 GMT X-Originating-IP: [203.199.109.161] X-Originating-Email: [unixtools@hotmail.com] X-Sender: unixtools@hotmail.com In-Reply-To: <392845895.20050812183732@spaingsm.com> From: "Sunil Sunder Raj" To: vladone@spaingsm.com, freebsd-ipfw@freebsd.org Date: Mon, 15 Aug 2005 12:38:35 +0000 Mime-Version: 1.0 Content-Type: text/plain; format=flowed X-OriginalArrivalTime: 15 Aug 2005 12:38:35.0813 (UTC) FILETIME=[4107E550:01C5A196] Cc: Subject: RE: traffic shaping with dummynet and priorize questions X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 12:38:36 -0000 Hi, Check the ipfw "weight" keyword. You need to assign weights to each server. Depending upon the weight servers are prioritized inside a pipe. -Sunil Sunder Raj >From: vladone >Reply-To: vladone >To: freebsd-ipfw@freebsd.org >Subject: traffic shaping with dummynet and priorize questions >Date: Fri, 12 Aug 2005 18:37:32 +0300 > >Hi! >I want to build some traffic shaping. I want to have clients with >128kbs/s and 256kbits/s. So i make two pipe: >ipfw pipe 1 config bw 128kbits/s mask dst-ip 0xffffff >ipfw pipe 1 config bw 256kbits/s mask dst-ip 0xffffff >With this any host in my network receive the maximum bandwith for that >pipe according with their account. > >My question: >If network is very busy, total bandwith is not sufficient for all >and obviously not reach 128kbits/s, i want to priorize traffic. users >with hight bandwith are priorized against users with low bandwith. > >How i can make this? > > >_______________________________________________ >freebsd-ipfw@freebsd.org mailing list >http://lists.freebsd.org/mailman/listinfo/freebsd-ipfw >To unsubscribe, send any mail to "freebsd-ipfw-unsubscribe@freebsd.org" From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 18:04:04 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5D63716A41F for ; Mon, 15 Aug 2005 18:04:04 +0000 (GMT) (envelope-from vladone@spaingsm.com) Received: from mail.spaingsm.com (llwb135.servidoresdns.net [217.76.137.82]) by mx1.FreeBSD.org (Postfix) with ESMTP id 33AEC43D49 for ; Mon, 15 Aug 2005 18:04:01 +0000 (GMT) (envelope-from vladone@spaingsm.com) Received: from SERVEREL (unknown [85.120.13.218]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.spaingsm.com (Postfix) with ESMTP id 9C9B724C790 for ; Mon, 15 Aug 2005 19:50:24 +0200 (CEST) Date: Mon, 15 Aug 2005 21:03:37 +0300 From: vladone X-Mailer: The Bat! (v3.0.1.33) Professional X-Priority: 3 (Normal) Message-ID: <488322206.20050815210337@spaingsm.com> To: freebsd-ipfw@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Subject: very curious situation X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: vladone List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 18:04:04 -0000 Hi! I want to block illegal acces to server with mac address. For testing i write this rules: ipfw add 100 deny mac any xx:xx:xx:xx:ab:12 in via $lif ipfw add 100 deny mac any xx:xx:xx:xx:ab:34 in via $lif $lif is private interface on my server. After i apply this rule result is strange. Computer with mac ..ab:12 can make traffic but these with ab:34 no. I have withe hair. P.S. computer with traffic is win98 and without traffic is XP. How he can such something! From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 18:11:29 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 01C2316A41F for ; Mon, 15 Aug 2005 18:11:29 +0000 (GMT) (envelope-from RoKlein@roklein.de) Received: from moutng.kundenserver.de (moutng.kundenserver.de [212.227.126.186]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5B75843D45 for ; Mon, 15 Aug 2005 18:11:28 +0000 (GMT) (envelope-from RoKlein@roklein.de) Received: from p54A92B59.dip0.t-ipconnect.de [84.169.43.89] (helo=[192.168.254.148]) by mrelayeu.kundenserver.de with ESMTP (Nemesis), id 0MKwtQ-1E4jQj0udF-0007Z3; Mon, 15 Aug 2005 20:11:25 +0200 Message-ID: <4300DAC9.1040300@roklein.de> Date: Mon, 15 Aug 2005 20:11:21 +0200 From: Robert Klein User-Agent: Mozilla Thunderbird 1.0.6 (Windows/20050716) X-Accept-Language: de-DE, de, en-us, en MIME-Version: 1.0 To: vladone References: <488322206.20050815210337@spaingsm.com> In-Reply-To: <488322206.20050815210337@spaingsm.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Provags-ID: kundenserver.de abuse@kundenserver.de login:ed18d71deac0f49a40655750752d3db9 Cc: freebsd-ipfw@freebsd.org Subject: Re: very curious situation X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 18:11:29 -0000 vladone wrote: >I want to block illegal acces to server with mac address. >For testing i write this rules: > >ipfw add 100 deny mac any xx:xx:xx:xx:ab:12 in via $lif >ipfw add 100 deny mac any xx:xx:xx:xx:ab:34 in via $lif > >$lif is private interface on my server. > >After i apply this rule result is strange. Computer with mac ..ab:12 >can make traffic but these with ab:34 no. >I have withe hair. > > At a guess, both rules have number 100, so the second one overwrites the first one. Regards, Robert From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 18:37:26 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B469516A41F for ; Mon, 15 Aug 2005 18:37:26 +0000 (GMT) (envelope-from vladone@spaingsm.com) Received: from mail.spaingsm.com (llwb135.servidoresdns.net [217.76.137.82]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5551043D53 for ; Mon, 15 Aug 2005 18:37:26 +0000 (GMT) (envelope-from vladone@spaingsm.com) Received: from SERVEREL (unknown [85.120.13.201]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.spaingsm.com (Postfix) with ESMTP id D968524C790 for ; Mon, 15 Aug 2005 20:23:48 +0200 (CEST) Date: Mon, 15 Aug 2005 21:37:09 +0300 From: vladone X-Mailer: The Bat! (v3.0.1.33) Professional X-Priority: 3 (Normal) Message-ID: <763138219.20050815213709@spaingsm.com> To: freebsd-ipfw@freebsd.org In-Reply-To: <4300DAC9.1040300@roklein.de> References: <488322206.20050815210337@spaingsm.com> <4300DAC9.1040300@roklein.de> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Subject: Re[2]: very curious situation X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: vladone List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 18:37:26 -0000 Not work anyway, this is not a good reason. Filter work with rules with same number. I test to block only win98 computer and i can't. I try to block by ip address and not work. I forgot to specifies that on win98 computer after i try to block, not work messenger, but navigation very well. From owner-freebsd-ipfw@FreeBSD.ORG Mon Aug 15 18:41:58 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E5F9C16A41F for ; Mon, 15 Aug 2005 18:41:58 +0000 (GMT) (envelope-from vladone@spaingsm.com) Received: from mail.spaingsm.com (llwb135.servidoresdns.net [217.76.137.82]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1EB0243D5F for ; Mon, 15 Aug 2005 18:41:56 +0000 (GMT) (envelope-from vladone@spaingsm.com) Received: from SERVEREL (unknown [85.120.13.206]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mail.spaingsm.com (Postfix) with ESMTP id 331DB24C790 for ; Mon, 15 Aug 2005 20:28:19 +0200 (CEST) Date: Mon, 15 Aug 2005 21:41:39 +0300 From: vladone X-Mailer: The Bat! (v3.0.1.33) Professional X-Priority: 3 (Normal) Message-ID: <262462427.20050815214139@spaingsm.com> To: freebsd-ipfw@freebsd.org In-Reply-To: References: <392845895.20050812183732@spaingsm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Subject: Re[2]: traffic shaping with dummynet and priorize questions X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: vladone List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2005 18:41:59 -0000 If i understand corectly, weight is a keyword that config queue. Queue is used to share bandwith on same pipe. In my configuration each computer receive same bandwith on different pipe (dynamicaly created with mask), and i dont know how to use weight keyword in this situation. From owner-freebsd-ipfw@FreeBSD.ORG Sat Aug 20 08:49:31 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AF16416A41F for ; Sat, 20 Aug 2005 08:49:31 +0000 (GMT) (envelope-from david@zebra.uem.mz) Received: from zebra.uem.mz (zebra.uem.mz [196.3.96.67]) by mx1.FreeBSD.org (Postfix) with ESMTP id B7A5143D48 for ; Sat, 20 Aug 2005 08:49:30 +0000 (GMT) (envelope-from david@zebra.uem.mz) Received: from zebra.uem.mz (localhost.uem.mz [127.0.0.1]) by zebra.uem.mz (Postfix) with SMTP id 6BA4F74449 for ; Sat, 20 Aug 2005 10:47:55 +0200 (CAT) From: "david" To: freebsd-ipfw@freebsd.org Date: Sat, 20 Aug 2005 11:47:55 +0300 Message-Id: <20050820084619.M33689@zebra.uem.mz> X-Mailer: CIUEM WebMail 2.40 20040816 X-OriginatingIP: 196.3.96.201 (david) MIME-Version: 1.0 Content-Type: text/plain; charset=windows-1251 X-Mailman-Approved-At: Sat, 20 Aug 2005 14:28:22 +0000 Subject: Help X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 20 Aug 2005 08:49:31 -0000 Hi There, Is there anybody who successeded configuring squid 2.5 on FreeBSD 5.3 with ipfw for transparent proxing of http? If yes, Please help. Thanks, David -- CIUEM WebMail (http://www.ci.uem.mz) From owner-freebsd-ipfw@FreeBSD.ORG Sat Aug 20 23:10:54 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BF09116A41F for ; Sat, 20 Aug 2005 23:10:54 +0000 (GMT) (envelope-from denny@alistair.scapegoats.org) Received: from alistair.scapegoats.org (alistair.scapegoats.org [64.40.92.44]) by mx1.FreeBSD.org (Postfix) with ESMTP id 742F143D45 for ; Sat, 20 Aug 2005 23:10:54 +0000 (GMT) (envelope-from denny@alistair.scapegoats.org) Received: by alistair.scapegoats.org (Postfix, from userid 1001) id 0410C75; Sat, 20 Aug 2005 18:12:38 -0500 (CDT) Date: Sat, 20 Aug 2005 18:12:38 -0500 From: Denny Reiter To: david Message-ID: <20050820231238.GG52648@reiters.org> References: <20050820084619.M33689@zebra.uem.mz> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20050820084619.M33689@zebra.uem.mz> X-Uptime: 6:12PM up 607 days, 13:55, 8 users, load averages: 0.00, 0.00, 0.00 X-PGP-Key: http://pgp.dtype.org:11371/pks/lookup?op=get&search=0x997F9D70 User-Agent: Mutt/1.5.1i X-Virus-Scanned: by amavisd-new at strayneutrino.org Cc: freebsd-ipfw@freebsd.org Subject: Re: Help X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 20 Aug 2005 23:10:54 -0000 On Sat, Aug 20, 2005 at 11:47:55AM +0300, david wrote: > > Hi There, > > Is there anybody who successeded configuring squid 2.5 on FreeBSD 5.3 with > ipfw for transparent proxing of http? If yes, Please help. I have. What do you need? -- Denny Reiter denny@reiters.org So I don't hurt your feelings: happydenny@reiters.org Plagiarism saves time.