From owner-freebsd-pf@FreeBSD.ORG Mon Feb 13 11:02:39 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D939C16A420 for ; Mon, 13 Feb 2006 11:02:39 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id A4F3C43D49 for ; Mon, 13 Feb 2006 11:02:39 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (peter@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k1DB2dTr067371 for ; Mon, 13 Feb 2006 11:02:39 GMT (envelope-from owner-bugmaster@freebsd.org) Received: (from peter@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k1DB2c6V067365 for freebsd-pf@freebsd.org; Mon, 13 Feb 2006 11:02:38 GMT (envelope-from owner-bugmaster@freebsd.org) Date: Mon, 13 Feb 2006 11:02:38 GMT Message-Id: <200602131102.k1DB2c6V067365@freefall.freebsd.org> X-Authentication-Warning: freefall.freebsd.org: peter set sender to owner-bugmaster@freebsd.org using -f From: FreeBSD bugmaster To: freebsd-pf@FreeBSD.org Cc: Subject: Current problem reports assigned to you X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 13 Feb 2006 11:02:40 -0000 Current FreeBSD problem reports Critical problems Serious problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- o [2005/06/15] kern/82271 pf [pf] cbq scheduler cause bad latency f [2005/07/31] kern/84370 pf [modules] Unload pf.ko cause page fault f [2005/09/13] kern/86072 pf [pf] Packet Filter rule not working prope 3 problems total. Non-critical problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- o [2005/05/15] conf/81042 pf [pf] [patch] /etc/pf.os doesn't match Fre o [2005/12/09] kern/90148 pf [pf] pf_enable="YES" -> Fatal trap 12: pa 2 problems total. From owner-freebsd-pf@FreeBSD.ORG Mon Feb 13 17:44:36 2006 Return-Path: X-Original-To: freebsd-pf@FreeBSD.org Delivered-To: freebsd-pf@FreeBSD.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CFA1C16A420 for ; Mon, 13 Feb 2006 17:44:36 +0000 (GMT) (envelope-from tiagocruz@forumgdh.net) Received: from gdhs.guiadohardware.net (gdhs.guiadohardware.net [64.246.6.25]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1B75943D6E for ; Mon, 13 Feb 2006 17:44:33 +0000 (GMT) (envelope-from tiagocruz@forumgdh.net) Received: (qmail 6311 invoked by uid 15); 13 Feb 2006 17:44:30 -0000 Received: from unknown (HELO tuxkiller.matter.b4br.net) (tiagocruz@forumgdh.net@200.152.202.10) by 0 with SMTP; 13 Feb 2006 17:44:30 -0000 From: Tiago Cruz To: freebsd-pf@FreeBSD.org Content-Type: text/plain Date: Mon, 13 Feb 2006 15:44:31 -0200 Message-Id: <1139852671.6545.53.camel@localhost.localdomain> Mime-Version: 1.0 X-Mailer: Evolution 2.2.3 Content-Transfer-Encoding: 7bit Cc: Subject: Log analyzer X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 13 Feb 2006 17:44:36 -0000 Hello all, I'm testing some log analyzer to PF on my FreeBSD 6.0 box I've tried hatchet, metacortex and pfw the fields always is broken, like: pfw: ---- Date: 000006 rule Time: 4294967295/unkn(8): Proto: report Destination: igm mecacortex: ----------- Time: 2. 916461 rule Interface: 221.7.70.233.2391 Source IP: >... Destination IP: 495619630:495619630(0)... So, I think that have some problem with my machine :-( Somebody can help me? Thank you! -- Tiago Cruz http://linuxrapido.org Linux User #282636 "The box said: Requires MS Windows or better, so I installed Linux" From owner-freebsd-pf@FreeBSD.ORG Tue Feb 14 06:54:24 2006 Return-Path: X-Original-To: freebsd-pf@hub.freebsd.org Delivered-To: freebsd-pf@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B627E16A420; Tue, 14 Feb 2006 06:54:24 +0000 (GMT) (envelope-from linimon@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6EAA943D49; Tue, 14 Feb 2006 06:54:24 +0000 (GMT) (envelope-from linimon@FreeBSD.org) Received: from freefall.freebsd.org (linimon@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k1E6sOeD057240; Tue, 14 Feb 2006 06:54:24 GMT (envelope-from linimon@freefall.freebsd.org) Received: (from linimon@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k1E6sOAU057236; Tue, 14 Feb 2006 06:54:24 GMT (envelope-from linimon) Date: Tue, 14 Feb 2006 06:54:24 GMT From: Mark Linimon Message-Id: <200602140654.k1E6sOAU057236@freefall.freebsd.org> To: linimon@FreeBSD.org, freebsd-i386@FreeBSD.org, freebsd-pf@FreeBSD.org Cc: Subject: Re: kern/92949: [pf] PF + ALTQ problems with latency X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Feb 2006 06:54:24 -0000 Old Synopsis: PF + ALTQ problems with latency New Synopsis: [pf] PF + ALTQ problems with latency Responsible-Changed-From-To: freebsd-i386->freebsd-pf Responsible-Changed-By: linimon Responsible-Changed-When: Tue Feb 14 06:54:04 UTC 2006 Responsible-Changed-Why: This does not sound i386-specific. Over to mailing list. http://www.freebsd.org/cgi/query-pr.cgi?pr=92949 From owner-freebsd-pf@FreeBSD.ORG Tue Feb 14 14:57:35 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BFCFE16A429 for ; Tue, 14 Feb 2006 14:57:35 +0000 (GMT) (envelope-from bill.marquette@gmail.com) Received: from xproxy.gmail.com (xproxy.gmail.com [66.249.82.205]) by mx1.FreeBSD.org (Postfix) with ESMTP id AB85643D78 for ; Tue, 14 Feb 2006 14:57:24 +0000 (GMT) (envelope-from bill.marquette@gmail.com) Received: by xproxy.gmail.com with SMTP id h29so806344wxd for ; Tue, 14 Feb 2006 06:57:24 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=gngXnpaJyDgIBBvU9jqeC6WphQMl/cHUwyhow+xHJ+4e8z9HfFFAfwLoBX3hJ36f2QMXAW3e3kROKICleSvW3pGJlratq5AcIeZb4klBi+eoMMIpUw0gKmPYldDHXsdktmCsgnL7KefrpV9gRiNs87THoRJqqyUHMC57dcI3TrE= Received: by 10.70.109.16 with SMTP id h16mr2374042wxc; Tue, 14 Feb 2006 06:57:24 -0800 (PST) Received: by 10.70.89.8 with HTTP; Tue, 14 Feb 2006 06:57:23 -0800 (PST) Message-ID: <55e8a96c0602140657w161a7490xf094fb9d34801724@mail.gmail.com> Date: Tue, 14 Feb 2006 08:57:23 -0600 From: Bill Marquette To: Mark Linimon In-Reply-To: <200602140654.k1E6sOAU057236@freefall.freebsd.org> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <200602140654.k1E6sOAU057236@freefall.freebsd.org> Cc: freebsd-pf@freebsd.org Subject: Re: kern/92949: [pf] PF + ALTQ problems with latency X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Feb 2006 14:57:35 -0000 On 2/14/06, Mark Linimon wrote: > Old Synopsis: PF + ALTQ problems with latency > New Synopsis: [pf] PF + ALTQ problems with latency > > Responsible-Changed-From-To: freebsd-i386->freebsd-pf > Responsible-Changed-By: linimon > Responsible-Changed-When: Tue Feb 14 06:54:04 UTC 2006 > Responsible-Changed-Why: > This does not sound i386-specific. Over to mailing list. > > http://www.freebsd.org/cgi/query-pr.cgi?pr=3D92949 Looks like a simpler test case for: kern/82271 pf [pf] cbq scheduler cause bad latency I don't think this is scheduler specific either, but I haven't been able to generate what I consider to be a stable test case (it comes and goes in HFSC). --Bill From owner-freebsd-pf@FreeBSD.ORG Tue Feb 14 17:31:32 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 800FC16A426 for ; Tue, 14 Feb 2006 17:31:32 +0000 (GMT) (envelope-from worm@chm.org.ua) Received: from support2.cyfra.ua (support2.cyfra.ua [62.80.160.23]) by mx1.FreeBSD.org (Postfix) with ESMTP id 04F0A43D69 for ; Tue, 14 Feb 2006 17:31:29 +0000 (GMT) (envelope-from worm@chm.org.ua) Received: from localhost ([127.0.0.1]) by support2.cyfra.ua with esmtp (Exim 4.60 (FreeBSD)) (envelope-from ) id 1F941T-0002bg-2G; Tue, 14 Feb 2006 19:31:31 +0200 Message-ID: <43F213F2.3080003@chm.org.ua> Date: Tue, 14 Feb 2006 19:31:30 +0200 From: "Victor V. Melnichenko" User-Agent: Thunderbird 1.5 (X11/20060209) MIME-Version: 1.0 To: freebsd-pf@freebsd.org Content-Type: text/plain; charset=KOI8-R; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Check: ClamAV 0.88/1289 on support2.cyfra.ua at Tue, 14 Feb 2006 19:31:31 +0200 Subject: PF: dynamic rules X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: worm@chm.org.ua List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Feb 2006 17:31:32 -0000 Hi ALL! I have some problem with PF. I have pppoe server based on mpd. What i want: When client connect to the server some rules (e.g. altq ... priq ... etc) must be load and apply to the interface ng0 for example. When client disconnected from server this rules must be delete from rule-table. In IPFW this things works fine... Question: how can i do this in PF? P.S. Sorry, i am new in this mail-list and my english is bad sometimes :( Thanks! -- With Best Regards, Victor V. Melnichenko VVM7-UANIC From owner-freebsd-pf@FreeBSD.ORG Tue Feb 14 17:56:39 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 98FEA16A422 for ; Tue, 14 Feb 2006 17:56:39 +0000 (GMT) (envelope-from sullrich@gmail.com) Received: from zproxy.gmail.com (zproxy.gmail.com [64.233.162.201]) by mx1.FreeBSD.org (Postfix) with ESMTP id 28B3943D48 for ; Tue, 14 Feb 2006 17:56:38 +0000 (GMT) (envelope-from sullrich@gmail.com) Received: by zproxy.gmail.com with SMTP id s18so1371652nze for ; Tue, 14 Feb 2006 09:56:38 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=bpPDTQHYTtp8EizjgliIzVVLkG2qwnSuL7tZoRmp7ODdLrOmGzhnyVC8QIesGhITPrucRzOGAT5aKy3TSdh+OGEkg9S/Ruti+rbFLx6rgBZ4jRDkwjEqxx40e3TJkN6QFm0CvUr8Qwdt8NkL/Dl++gV92tDpZYrargjePNEaPug= Received: by 10.64.180.12 with SMTP id c12mr1936313qbf; Tue, 14 Feb 2006 09:56:38 -0800 (PST) Received: by 10.64.181.12 with HTTP; Tue, 14 Feb 2006 09:56:38 -0800 (PST) Message-ID: Date: Tue, 14 Feb 2006 12:56:38 -0500 From: Scott Ullrich To: worm@chm.org.ua In-Reply-To: <43F213F2.3080003@chm.org.ua> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <43F213F2.3080003@chm.org.ua> Cc: freebsd-pf@freebsd.org Subject: Re: PF: dynamic rules X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Feb 2006 17:56:39 -0000 On 2/14/06, Victor V. Melnichenko wrote: > I have some problem with PF. > I have pppoe server based on mpd. > What i want: > When client connect to the server some rules (e.g. altq ... priq ... > etc) must be load and apply to the interface ng0 for example. When > client disconnected from server this rules must be delete from rule-table= . > In IPFW this things works fine... > > Question: how can i do this in PF? You're best bet is to link into ppp-linkup (generally in /usr/local/sbin/) which MPD invokes after a session is nailed up. =20 You could easily tie in you're custom ALTQ rules with this script. Hope this helps! Scott From owner-freebsd-pf@FreeBSD.ORG Tue Feb 14 18:03:03 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2A96E16A420 for ; Tue, 14 Feb 2006 18:03:03 +0000 (GMT) (envelope-from freebsd-listen@fabiankeil.de) Received: from smtprelay01.ispgateway.de (smtprelay01.ispgateway.de [80.67.18.13]) by mx1.FreeBSD.org (Postfix) with ESMTP id 58F0043D45 for ; Tue, 14 Feb 2006 18:03:02 +0000 (GMT) (envelope-from freebsd-listen@fabiankeil.de) Received: (qmail 10345 invoked from network); 14 Feb 2006 18:03:00 -0000 Received: from unknown (HELO localhost) ([pbs]775067@[217.50.129.240]) (envelope-sender ) by smtprelay01.ispgateway.de (qmail-ldap-1.03) with SMTP for ; 14 Feb 2006 18:03:00 -0000 Date: Tue, 14 Feb 2006 19:03:01 +0100 From: Fabian Keil To: worm@chm.org.ua Message-ID: <20060214190301.42c80744@localhost> In-Reply-To: <43F213F2.3080003@chm.org.ua> References: <43F213F2.3080003@chm.org.ua> X-Mailer: Sylpheed-Claws 2.0.0 (GTK+ 2.8.6; i386-portbld-freebsd6.0) X-PGP-KEY-URL: http://www.fabiankeil.de/gpg-keys/freebsd-listen-2006-08-19.asc Mime-Version: 1.0 Content-Type: multipart/signed; boundary=Sig_dWKIRreDVZwawRfk85Hkyyy; protocol="application/pgp-signature"; micalg=PGP-SHA1 Cc: freebsd-pf@freebsd.org Subject: Re: PF: dynamic rules X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Feb 2006 18:03:03 -0000 --Sig_dWKIRreDVZwawRfk85Hkyyy Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable "Victor V. Melnichenko" wrote: > I have some problem with PF. > I have pppoe server based on mpd. > What i want: > When client connect to the server some rules (e.g. altq ... priq ...=20 > etc) must be load and apply to the interface ng0 for example. When=20 > client disconnected from server this rules must be delete from > rule-table. In IPFW this things works fine... >=20 > Question: how can i do this in PF? Looks like a job for authpf. Fabian --=20 http://www.fabiankeil.de/ --Sig_dWKIRreDVZwawRfk85Hkyyy Content-Type: application/pgp-signature; name=signature.asc Content-Disposition: attachment; filename=signature.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFD8htdjV8GA4rMKUQRAnjvAKDZxiuKE2rrI4vFNG6Ky7FniA0VVgCg0RZ8 d4SdCrsNgHDDu/DVY86VxaI= =DON6 -----END PGP SIGNATURE----- --Sig_dWKIRreDVZwawRfk85Hkyyy-- From owner-freebsd-pf@FreeBSD.ORG Tue Feb 14 19:41:04 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1C9DF16A426 for ; Tue, 14 Feb 2006 19:41:04 +0000 (GMT) (envelope-from freebsd-listen@fabiankeil.de) Received: from smtprelay01.ispgateway.de (smtprelay01.ispgateway.de [80.67.18.13]) by mx1.FreeBSD.org (Postfix) with ESMTP id 411F643D49 for ; Tue, 14 Feb 2006 19:41:02 +0000 (GMT) (envelope-from freebsd-listen@fabiankeil.de) Received: (qmail 4126 invoked from network); 14 Feb 2006 19:41:01 -0000 Received: from unknown (HELO localhost) ([pbs]775067@[217.50.129.240]) (envelope-sender ) by smtprelay01.ispgateway.de (qmail-ldap-1.03) with SMTP for ; 14 Feb 2006 19:41:01 -0000 Date: Tue, 14 Feb 2006 20:40:59 +0100 From: Fabian Keil To: Fabian Keil Message-ID: <20060214204059.0b950519@localhost> In-Reply-To: <20060214190301.42c80744@localhost> References: <43F213F2.3080003@chm.org.ua> <20060214190301.42c80744@localhost> X-Mailer: Sylpheed-Claws 2.0.0 (GTK+ 2.8.6; i386-portbld-freebsd6.0) X-PGP-KEY-URL: http://www.fabiankeil.de/gpg-keys/freebsd-listen-2006-08-19.asc Mime-Version: 1.0 Content-Type: multipart/signed; boundary="Sig_3jsqY5hKVnIjfIwRbDjGM/B"; protocol="application/pgp-signature"; micalg=PGP-SHA1 Cc: freebsd-pf@freebsd.org Subject: Re: PF: dynamic rules X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 14 Feb 2006 19:41:04 -0000 --Sig_3jsqY5hKVnIjfIwRbDjGM/B Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable Fabian Keil wrote: > "Victor V. Melnichenko" wrote: >=20 > > I have some problem with PF. > > I have pppoe server based on mpd. > > What i want: > > When client connect to the server some rules (e.g. altq ... > > priq ... etc) must be load and apply to the interface ng0 for > > example. When client disconnected from server this rules must be > > delete from rule-table. In IPFW this things works fine... > >=20 > > Question: how can i do this in PF? >=20 > Looks like a job for authpf. After reading Scott's answer it rather looks like I misunderstood the question. Fabian --=20 http://www.fabiankeil.de/ --Sig_3jsqY5hKVnIjfIwRbDjGM/B Content-Type: application/pgp-signature; name=signature.asc Content-Disposition: attachment; filename=signature.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFD8jJUjV8GA4rMKUQRAm+JAJ4loO61R3uQWYyvZy3gG09FNpZgEQCgjBxE V0bInrdBWbuXWAgE4PmUBxI= =KLIh -----END PGP SIGNATURE----- --Sig_3jsqY5hKVnIjfIwRbDjGM/B-- From owner-freebsd-pf@FreeBSD.ORG Wed Feb 15 02:20:10 2006 Return-Path: X-Original-To: freebsd-pf@hub.freebsd.org Delivered-To: freebsd-pf@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7A8FC16A420 for ; Wed, 15 Feb 2006 02:20:10 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0B0BE43D69 for ; Wed, 15 Feb 2006 02:20:06 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k1F2K6eR078791 for ; Wed, 15 Feb 2006 02:20:06 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k1F2K6VJ078790; Wed, 15 Feb 2006 02:20:06 GMT (envelope-from gnats) Date: Wed, 15 Feb 2006 02:20:06 GMT Message-Id: <200602150220.k1F2K6VJ078790@freefall.freebsd.org> To: freebsd-pf@FreeBSD.org From: linimon@lonesome.com (Mark Linimon) Cc: Subject: Re: kern/92949: [pf] PF + ALTQ problems with latency] X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Mark Linimon List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Feb 2006 02:20:10 -0000 The following reply was made to PR kern/92949; it has been noted by GNATS. From: linimon@lonesome.com (Mark Linimon) To: bug-followup@FreeBSD.org Cc: Subject: Re: kern/92949: [pf] PF + ALTQ problems with latency] Date: Tue, 14 Feb 2006 20:15:29 -0600 ----- Forwarded message from Bill Marquette ----- Looks like a simpler test case for: kern/82271 pf [pf] cbq scheduler cause bad latency I don't think this is scheduler specific either, but I haven't been able to generate what I consider to be a stable test case (it comes and goes in HFSC). --Bill From owner-freebsd-pf@FreeBSD.ORG Wed Feb 15 16:31:24 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EAB0F16A420 for ; Wed, 15 Feb 2006 16:31:24 +0000 (GMT) (envelope-from veldy@veldy.net) Received: from fuggle.veldy.net (fuggle.veldy.net [209.240.64.129]) by mx1.FreeBSD.org (Postfix) with ESMTP id E9E3E43D5C for ; Wed, 15 Feb 2006 16:31:23 +0000 (GMT) (envelope-from veldy@veldy.net) Received: from localhost (localhost [127.0.0.1]) by fuggle.veldy.net (Postfix) with ESMTP id 95C7DC23E for ; Wed, 15 Feb 2006 10:31:22 -0600 (CST) Received: from fuggle.veldy.net ([127.0.0.1]) by localhost (fuggle.veldy.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 14113-03 for ; Wed, 15 Feb 2006 10:31:15 -0600 (CST) Received: from [127.0.0.1] (localhost [127.0.0.1]) by fuggle.veldy.net (Postfix) with ESMTP id F1608C0D7 for ; Wed, 15 Feb 2006 10:31:14 -0600 (CST) Message-ID: <43F35750.7020701@veldy.net> Date: Wed, 15 Feb 2006 10:31:12 -0600 From: "Thomas T. Veldhouse" User-Agent: Mozilla Thunderbird 1.0.6 (Windows/20050716) X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-pf@freebsd.org Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: amavisd-new at veldy.net Subject: PF --> IPTABLES Conversion? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Feb 2006 16:31:25 -0000 Does anybody know if there is a conversion tool to convert PF scripts over to IPTables scripts? I have a firewall that is working nicely using PF and FreeBSD, but I have a machine that I need to setup for a friend that has a similar configuration, but will be running Linux. Rather than learn IPTables outright, I was hoping that there might be a scripting utility to help get me 90% of the way. Thanks in advance, Tom Veldhouse From owner-freebsd-pf@FreeBSD.ORG Wed Feb 15 18:42:46 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A852016A420 for ; Wed, 15 Feb 2006 18:42:46 +0000 (GMT) (envelope-from max@love2party.net) Received: from moutng.kundenserver.de (moutng.kundenserver.de [212.227.126.171]) by mx1.FreeBSD.org (Postfix) with ESMTP id 13A9043D46 for ; Wed, 15 Feb 2006 18:42:45 +0000 (GMT) (envelope-from max@love2party.net) Received: from [84.163.217.163] (helo=amd64.laiers.local) by mrelayeu.kundenserver.de (node=mrelayeu1) with ESMTP (Nemesis), id 0MKwpI-1F9Rbu0Kmm-00071H; Wed, 15 Feb 2006 19:42:42 +0100 From: Max Laier Organization: FreeBSD To: freebsd-pf@freebsd.org Date: Wed, 15 Feb 2006 19:43:15 +0100 User-Agent: KMail/1.9.1 References: <43F35750.7020701@veldy.net> In-Reply-To: <43F35750.7020701@veldy.net> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart1685083.cRogFo07ui"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: <200602151943.22224.max@love2party.net> X-Provags-ID: kundenserver.de abuse@kundenserver.de login:61c499deaeeba3ba5be80f48ecc83056 Cc: Subject: Re: PF --> IPTABLES Conversion? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Feb 2006 18:42:46 -0000 --nextPart1685083.cRogFo07ui Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline On Wednesday 15 February 2006 17:31, Thomas T. Veldhouse wrote: > Does anybody know if there is a conversion tool to convert PF scripts > over to IPTables scripts? I have a firewall that is working nicely > using PF and FreeBSD, but I have a machine that I need to setup for a > friend that has a similar configuration, but will be running Linux. > Rather than learn IPTables outright, I was hoping that there might be a > scripting utility to help get me 90% of the way. You could give http://www.fwbuilder.org/ a try. It used to have import/exp= ort=20 of some kind. I can't comment on quality nor recent versions, so this is=20 just a data point. Best yet, convert your friend to FreeBSD! =2D-=20 /"\ Best regards, | mlaier@freebsd.org \ / Max Laier | ICQ #67774661 X http://pf4freebsd.love2party.net/ | mlaier@EFnet / \ ASCII Ribbon Campaign | Against HTML Mail and News --nextPart1685083.cRogFo07ui Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQBD83ZKXyyEoT62BG0RAvasAJ9e25Cm8A6k/HrcoMTL98BLhZ1pIwCdGzCR CDqTwq1MM2qXS5M6PDxx4z8= =gMav -----END PGP SIGNATURE----- --nextPart1685083.cRogFo07ui-- From owner-freebsd-pf@FreeBSD.ORG Thu Feb 16 13:20:23 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1EAF716A420 for ; Thu, 16 Feb 2006 13:20:23 +0000 (GMT) (envelope-from peter@bgnett.no) Received: from vs3.bgnett.no (vs3.bgnett.no [194.54.96.185]) by mx1.FreeBSD.org (Postfix) with ESMTP id DCC1C43D70 for ; Thu, 16 Feb 2006 13:20:18 +0000 (GMT) (envelope-from peter@bgnett.no) Received: from amidala.datadok.no (amidala.datadok.no [194.54.103.98]) by vs3.bgnett.no (8.12.9p2/8.12.9) with ESMTP id k1GDK40E055741 for ; Thu, 16 Feb 2006 14:20:05 +0100 (CET) (envelope-from peter@bgnett.no) To: freebsd-pf@freebsd.org References: <43F35750.7020701@veldy.net> From: peter@bgnett.no (Peter N. M. Hansteen) Date: Thu, 16 Feb 2006 14:17:47 +0100 In-Reply-To: <43F35750.7020701@veldy.net> (Thomas T. Veldhouse's message of "Wed, 15 Feb 2006 10:31:12 -0600") Message-ID: <86accr7890.fsf@amidala.datadok.no> User-Agent: Gnus/5.1007 (Gnus v5.10.7) XEmacs/21.4.19 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-bgnett.no-virusscanner: Found to be clean X-bgnett.no-SpamScore: s X-Envelope-To: freebsd-pf@freebsd.org Subject: Re: PF --> IPTABLES Conversion? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Feb 2006 13:20:23 -0000 "Thomas T. Veldhouse" writes: > Does anybody know if there is a conversion tool to convert PF scripts > over to IPTables scripts? I had originally decided it was best to keep my mouth shut about IPTables in public, but, well, frankly the cover of the March 2006 Linux Journal really sums it all up for me. Cover bottom left tempts prospective readers with what appears to be a very useful article: "Perl script your way to firewall security" > I have a firewall that is working nicely using PF and FreeBSD, but I > have a machine that I need to setup for a friend that has a similar > configuration, but will be running Linux. Rather than learn IPTables > outright, I was hoping that there might be a scripting utility to help > get me 90% of the way. In my limited experience, if you've gotten used to PF, the only thing you will gain by going to IPTables is a catalogue of profound reasons to hate IPTables and the people who force you to use the thing. If you are used to IPTables, going to PF you will initally refuse to believe that firewall adminning can be that pleasant. Recovering IPTables sufferers tend to quintuple-check their working PF rulesets in disbelief and still end up with rule sets which are way too complicated for their needs. But if there is no way around it, Max' suggestion that fwbuilder is likely to be useful is about as good advice as you can get. Mind you, with IPTables the need for a point'n'click front end to your rule set is a lot bigger than if you stay with PF. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales" 20:11:56 delilah spamd[26905]: 146.151.48.74: disconnected after 36099 seconds. From owner-freebsd-pf@FreeBSD.ORG Sat Feb 18 20:32:13 2006 Return-Path: X-Original-To: freebsd-pf@hub.freebsd.org Delivered-To: freebsd-pf@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EA12516A420; Sat, 18 Feb 2006 20:32:13 +0000 (GMT) (envelope-from linimon@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 9381443D49; Sat, 18 Feb 2006 20:32:13 +0000 (GMT) (envelope-from linimon@FreeBSD.org) Received: from freefall.freebsd.org (linimon@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k1IKWD8d038650; Sat, 18 Feb 2006 20:32:13 GMT (envelope-from linimon@freefall.freebsd.org) Received: (from linimon@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k1IKWDsi038646; Sat, 18 Feb 2006 20:32:13 GMT (envelope-from linimon) Date: Sat, 18 Feb 2006 20:32:13 GMT From: Mark Linimon Message-Id: <200602182032.k1IKWDsi038646@freefall.freebsd.org> To: linimon@FreeBSD.org, gnats-admin@FreeBSD.org, freebsd-pf@FreeBSD.org Cc: Subject: Re: sparc64/93530: Incorrect checksums when using pf's route-to on sparc64 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 18 Feb 2006 20:32:14 -0000 Synopsis: Incorrect checksums when using pf's route-to on sparc64 Responsible-Changed-From-To: gnats-admin->freebsd-pf Responsible-Changed-By: linimon Responsible-Changed-When: Sat Feb 18 20:31:45 UTC 2006 Responsible-Changed-Why: Over to maintainer(s). http://www.freebsd.org/cgi/query-pr.cgi?pr=93530