<?xml version="1.0"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>eRacks Forums: Last 35 Posts</title>
<link>http://forums.eracks.net/</link>
<description>eRacks Forums: Last 35 Posts</description>
<language>en</language>
<pubDate>Mon, 08 Sep 2008 12:07:29 +0000</pubDate>

<item>
<title>sean on "Can't map mbuf"</title>
<link>http://forums.eracks.net/topic.php?id=24&#038;page#post-122</link>
<pubDate>Wed, 13 Aug 2008 03:39:00 +0000</pubDate>
<dc:creator>sean</dc:creator>
<guid isPermaLink="false">122@http://forums.eracks.net/</guid>
<description>&#60;p&#62;the realtek cards, in my experience, are garbage. you might try upgrading to the latest version of obsd and see if the bug in the driver has been fixed, but I would just swap it out with another vendor's gige card.
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "replacing exchange server"</title>
<link>http://forums.eracks.net/topic.php?id=27&#038;page#post-121</link>
<pubDate>Sat, 29 Mar 2008 01:27:36 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">121@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Randy,&#60;/p&#62;
&#60;p&#62;In order to better answer your question, we need a clearer picture of your network, including the network diagram, and what changes you'd like to make, specifically, and how our server fits in to your network, and where and what it is used for.&#60;/p&#62;
&#60;p&#62;(Even an ascii-art network diagram is OK.)&#60;/p&#62;
&#60;p&#62;Also note although we will certainly do our best to help you out, we are not your MS Exchange and OWA (Outlook Web Access) providers, certainly (We are an Open-Source shop) - so configuration of those would be best asked of your Windows service provider (Or move away from Windows altogether :).&#60;/p&#62;
&#60;p&#62;Let us know,&#60;br /&#62;
Joe
&#60;/p&#62;</description>
</item>
<item>
<title>randyg on "replacing exchange server"</title>
<link>http://forums.eracks.net/topic.php?id=27&#038;page#post-120</link>
<pubDate>Thu, 27 Mar 2008 20:24:23 +0000</pubDate>
<dc:creator>randyg</dc:creator>
<guid isPermaLink="false">120@http://forums.eracks.net/</guid>
<description>&#60;p&#62;we are currently replacing our exchange server with a new server.This exchange service   will run on the new server and the primary domain server will stay the same. Can you please provide me with the instructions to change the owa config as well as the the smtp out.Also there is a spam filter between the firewall and the servers.all pop info is going to the spam filter first .      &#60;/p&#62;
&#60;p&#62;Thank you&#60;br /&#62;
          randy grijalva    El Cortez hotal
&#60;/p&#62;</description>
</item>
<item>
<title>MaxeRacks on "Links to some projects!"</title>
<link>http://forums.eracks.net/topic.php?id=26&#038;page#post-119</link>
<pubDate>Fri, 18 Jan 2008 18:06:24 +0000</pubDate>
<dc:creator>MaxeRacks</dc:creator>
<guid isPermaLink="false">119@http://forums.eracks.net/</guid>
<description>&#60;p&#62;64 Studio - a great open source pro-audio software package&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://64studio.com/&#34; rel=&#34;nofollow&#34;&#62;http://64studio.com/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;Ubuntu Studio - Another great open source pro-audio software package, very clean looking. &#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://ubuntustudio.org/&#34; rel=&#34;nofollow&#34;&#62;http://ubuntustudio.org/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;and their forum&#60;br /&#62;
&#60;a href=&#34;http://64studio.com/forum/11&#34; rel=&#34;nofollow&#34;&#62;http://64studio.com/forum/11&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;LMMS - a Linux Multimedia studio setup&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://lmms.sourceforge.net/&#34; rel=&#34;nofollow&#34;&#62;http://lmms.sourceforge.net/&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "I need a rule, but I don't know what..."</title>
<link>http://forums.eracks.net/topic.php?id=25&#038;page#post-118</link>
<pubDate>Tue, 11 Dec 2007 17:23:52 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">118@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Thanks for the reply. The typo on the ext_if should be $ext_if, sorry about that. using synproxy is because I saw it on another site, I assume I don't need it with my version of OpenBSD. The tags are because one other guy told me to do it that way, and I know you said it doesn't need to be like that. I can modify my rules to show rdr pass, eliminate the tags and... which pass out rules to get rid of? I am guessing all except pass out on $ext_if inet from self to any (should I get rid of modulate state also?&#60;/p&#62;
&#60;p&#62;the big question....&#60;/p&#62;
&#60;p&#62;will my RDR Filtered SMTP work? I really need the mail up.
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "I need a rule, but I don't know what..."</title>
<link>http://forums.eracks.net/topic.php?id=25&#038;page#post-117</link>
<pubDate>Tue, 11 Dec 2007 17:02:51 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">117@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Firstly, you shouldn't type in your rules, which is of course very error-prone - use ftp and/or scp, a pastebin, etc.&#60;/p&#62;
&#60;p&#62;Please also include the results of your &#34;ifconfig -A&#34; command. (redirect it to a file and ftp that as well).&#60;/p&#62;
&#60;p&#62;This rule is not proper syntax and will not compile:&#60;br /&#62;
&#38;gt; # RDR ATI&#60;br /&#62;
&#38;gt; on $ext_if inet proto tcp from any to (ext_if:0) tag OK_RDR_ATI -&#38;gt; 172.20.255.82&#60;/p&#62;
&#60;p&#62;I see other suspicious syntax errors which look like they may have been typos introduced by the manual copy.&#60;/p&#62;
&#60;p&#62;Why are you not using the pass feature in your translation rules? (&#34;rdr pass&#34; feature, etc)?  This would completely eliminate the need for all the tagging, and most of the pass out rules.&#60;/p&#62;
&#60;p&#62;Why are you using synproxy?
&#60;/p&#62;</description>
</item>
<item>
<title>admin on "Can't map mbuf"</title>
<link>http://forums.eracks.net/topic.php?id=24&#038;page#post-116</link>
<pubDate>Tue, 11 Dec 2007 16:34:53 +0000</pubDate>
<dc:creator>admin</dc:creator>
<guid isPermaLink="false">116@http://forums.eracks.net/</guid>
<description>&#60;p&#62;This looks like a traffic-volume related error.  We are looking into the issue - let us know if you have any occurrences of this at the 100Mbits/sec speed.
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "I need a rule, but I don't know what..."</title>
<link>http://forums.eracks.net/topic.php?id=25&#038;page#post-115</link>
<pubDate>Mon, 10 Dec 2007 19:57:14 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">115@http://forums.eracks.net/</guid>
<description>&#60;p&#62;ruleset for 172.20.255.1&#60;/p&#62;
&#60;p&#62;#Macros&#60;br /&#62;
ext_if=&#34;re0&#34;&#60;br /&#62;
int_if=&#34;re1&#34;&#60;br /&#62;
# ----&#60;br /&#62;
table &#38;lt;badnets&#38;gt; persist const { \&#60;br /&#62;
0/8 10/8 127/8 172.16/12 192.168/16 192.254/16 \&#60;br /&#62;
$ext_if:0 \&#60;br /&#62;
}&#60;br /&#62;
# ----&#60;br /&#62;
set state-policy if-bound&#60;br /&#62;
set skip on {lo0}&#60;br /&#62;
set block-policy drop&#60;br /&#62;
# ----&#60;br /&#62;
#NAT Rules&#60;br /&#62;
nat on $ext_if inet from ($int_if:network) to any -&#38;gt; ($ext_if:0)&#60;br /&#62;
# RDR ATI&#60;br /&#62;
 on $ext_if inet proto tcp from any to (ext_if:0) tag OK_RDR_ATI -&#38;gt; 172.20.255.82&#60;br /&#62;
#RDR CIS&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) tag OK_RDR -&#38;gt; 172.20.115.10&#60;br /&#62;
#RDR EXTS&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 3389 tag OK_RDR -&#38;gt; 172.20.255.127&#60;br /&#62;
#RDR Filtered_SMTP&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port { 25 } tag OK_RDR -&#38;gt; 172.20.1.3&#60;br /&#62;
#RDR FMT GreatPlains&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 3391 tag OK_RDR -&#38;gt; 172.20.255.27&#60;br /&#62;
# RDR GreatPlains&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to (#ext_if:0) tag OK_RDR -&#38;gt; 172.20.255.27&#60;br /&#62;
# RDR CIS_Telnet&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 23 tag OK_RDR -&#38;gt; 172.20.115.10&#60;br /&#62;
# RDR HTTP out of DNS server&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 80 tag OK_RDR -&#38;gt; 172.20.99.6&#60;br /&#62;
#RDR HTTPS_OWS&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 443 tag OK_RDR -&#38;gt; 172.20.255.188&#60;br /&#62;
#RDR INFOGENESIS_IN&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) tag OK_RDR_IG -&#38;gt; 172.20.99.200&#60;br /&#62;
# RDR LVSC_IN&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) tag OK_RDR_SC -&#38;gt; 172.20.10.100&#60;br /&#62;
# RDR POP3 ---- 127 is dead&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 110 tag OK_RDR -&#38;gt; 172.20.255.127&#60;br /&#62;
# RDR RDP&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 3389 tag OK_RDR -&#38;gt; 172.20.99.1&#60;br /&#62;
# RDR SAFLOK_IN&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) tag OK_RDR_SAFLOK -&#38;gt; 172.20.6.5&#60;br /&#62;
#&#60;br /&#62;
# ----&#60;br /&#62;
# Filter Rules&#60;br /&#62;
block log all&#60;br /&#62;
pass out log quick on $ext_if inet from self to any modulate state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $ext_if inet tagged OKPKTS keep state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $int_if inet from ($int_if:network) to any tag OKPKTS modulate state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR_ATI flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR_IG flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR_SC flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR_SAFLOK flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR_ATI&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR keep state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR_IG keep state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR_SC keep state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR_SAFLOK keep state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp from any to ($ext_if:0) port { ssh https } flags S/SA keep state #Allow admin of the firewall&#60;br /&#62;
# End of ruleset
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "I need a rule, but I don't know what..."</title>
<link>http://forums.eracks.net/topic.php?id=25&#038;page#post-114</link>
<pubDate>Mon, 10 Dec 2007 19:56:33 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">114@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Here are my rules. I had to type them out because I created them by modifying the pf.conf file, I didn't use pfw because it reports an old ruleset!!!!!&#60;/p&#62;
&#60;p&#62;ruleset for 172.20.1.1&#60;/p&#62;
&#60;p&#62;#Macros&#60;br /&#62;
ext_if=&#34;re0&#34;&#60;br /&#62;
int_if=&#34;re1&#34;&#60;br /&#62;
# ----&#60;br /&#62;
table &#38;lt;badnets&#38;gt; persist const { \&#60;br /&#62;
0/8 10/8 127/8 172.16/12 192.168/16 192.254/16 \&#60;br /&#62;
$ext_if:0 \&#60;br /&#62;
}&#60;br /&#62;
# ----&#60;br /&#62;
set state-policy if-bound&#60;br /&#62;
set skip on {lo0}&#60;br /&#62;
set block-policy drop&#60;br /&#62;
# ----&#60;br /&#62;
# NAT Rules&#60;br /&#62;
nat on $ext_if inet from ($int_if:network) to any -&#38;gt; ($ext_if:0)&#60;br /&#62;
#&#60;br /&#62;
# RDR ATI_IN&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) tag OK_RDR_ATI -&#38;gt; 172.20.231.41&#60;br /&#62;
# RDR Filtered HTTP&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 80 tag OK_RDR -&#38;gt; 172.20.99.6&#60;br /&#62;
# RDR Filtered SMTP&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 25 tag OK_RDR -&#38;gt; 172.20.1.3&#60;br /&#62;
# RDR FTP&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 21 tag OK_RDR -&#38;gt; 172.20.99.6&#60;br /&#62;
# RDR HTTPS_Synxis&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port 443 tag OK_RDR -&#38;gt; 172.20.255.189&#60;br /&#62;
RDR TCPIP 20_UDP&#60;br /&#62;
rdr on $ext_if inet proto tcp from any to ($ext_if:0) port { 20 21 22 23 } tag OK_RDR_UDP -&#38;gt; 172.20.255.187&#60;br /&#62;
# ----&#60;br /&#62;
# Filter Rules&#60;br /&#62;
block log all&#60;br /&#62;
pass out log quick on $ext_if inet from self to any modulate state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $ext_if inet tagged OKPKTS keep state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $int_if inet from ($int_if:network) to any tag OKPKTS modulate state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR_ATI flags S/SA synproxy state&#60;br /&#62;
#&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp tagged OK_RDR_UDP keep state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR keep state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR_ATI keep state&#60;br /&#62;
#&#60;br /&#62;
pass out log quick on $int_if inet proto tcp tagged OK_RDR_UDP keep state&#60;br /&#62;
# Allow admin of the firewall&#60;br /&#62;
pass in log quick on $ext_if inet proto tcp from any to ($ext_if:0) port {ssh https } flags S/SA keep state&#60;br /&#62;
# ----&#60;br /&#62;
# End of Ruleset
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "I need a rule, but I don't know what..."</title>
<link>http://forums.eracks.net/topic.php?id=25&#038;page#post-113</link>
<pubDate>Mon, 10 Dec 2007 19:53:28 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">113@http://forums.eracks.net/</guid>
<description>&#60;p&#62;So we have the twinguard set up:&#60;/p&#62;
&#60;p&#62;Twin1&#60;br /&#62;
re0: 24.120.60.58&#60;br /&#62;
re1: 172.20.1.1&#60;/p&#62;
&#60;p&#62;Some computers have the re1 address of 172.20.1.1 as their gateway. those people do not work to get internet access, however I can still access network drives. I cannot ping the fw.&#60;/p&#62;
&#60;p&#62;Twin2&#60;br /&#62;
re0: 24.120.60.59&#60;br /&#62;
re1: 172.20.255.1&#60;/p&#62;
&#60;p&#62;Many of our servers and other PCs have the re1 address of 172.20.255.1 as their gateway. those computers DO work. I can ping 255.1. &#60;/p&#62;
&#60;p&#62;My LAN does has one subnet. /16&#60;/p&#62;
&#60;p&#62;We have two IPs assigned from our ISP. We use all static, there is no DHCP.  It just had a different rule set. The rules were pulled from two watchguard fireboxes which we replaced with the Open BSD ones.&#60;/p&#62;
&#60;p&#62;The default gateway for some machines is set to 255.1, but not all. The remaining machines use the default gateway of 1.1. The 255.1 works, but not the 1.1 to get to the Internet.&#60;/p&#62;
&#60;p&#62;We also have a spam filter that sits at 172.20.1.3, and it does not appear to be working. I have set a rule to do rdr of incoming on port 25 to the spam filter, I think that's how it's already config'd.It has not received incoming mail since I switched over this morning. I suspect it also is using 1.1 as the default gateway.&#60;/p&#62;
&#60;p&#62;So... in short.... what am I missing here? I need to be able to get those who have 172.20.1.1 set as their default gateway get to the Internet? My guess is something that needs to pass to the other gateway in order to get out?? Maybe??
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "Can't map mbuf"</title>
<link>http://forums.eracks.net/topic.php?id=24&#038;page#post-112</link>
<pubDate>Fri, 07 Dec 2007 17:52:21 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">112@http://forums.eracks.net/</guid>
<description>&#60;p&#62;I thought I got my firewall going, and then I still get an error in blue seemingly randomly, which says: re1: can't map mbuf (error 22). It will make the firewall inoperable and I have to reboot it. &#60;/p&#62;
&#60;p&#62;I asked another forum regarding this error, and nobody has much of a fix except that it seems to be related to the Realtek gigabit NIC. One guy set his back down to 100 base T and it worked okay. I have done the same to both NICs, and no troubles yet, however I am concerned about this error when I put it on my network.&#60;/p&#62;
&#60;p&#62;Any experience with this error? Is there anywhere I can look in the system to try and resolve it?
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "kernel oopses with ipw3945 driver v1.2.0"</title>
<link>http://forums.eracks.net/topic.php?id=23&#038;page#post-111</link>
<pubDate>Wed, 05 Dec 2007 18:13:56 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">111@http://forums.eracks.net/</guid>
<description>&#60;p&#62;I guess we should point out to our FreeBSD and *BSD laptop and tablet users that this fix is for Linux only, but that if the BSD-based drivers are based on the Linux drivers, as they often are (although more often the other way around!), that the fact the bug is fixed in Linux means that it may soon propagate over to the BSD-based drivers as well, soon.
&#60;/p&#62;</description>
</item>
<item>
<title>james on "kernel oopses with ipw3945 driver v1.2.0"</title>
<link>http://forums.eracks.net/topic.php?id=23&#038;page#post-110</link>
<pubDate>Wed, 05 Dec 2007 07:39:39 +0000</pubDate>
<dc:creator>james</dc:creator>
<guid isPermaLink="false">110@http://forums.eracks.net/</guid>
<description>&#60;p&#62;It should be independent of the OS (if you're using v1.2.0 of the driver, you'll suffer from the bug no matter which version of the kernel you use.)
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "kernel oopses with ipw3945 driver v1.2.0"</title>
<link>http://forums.eracks.net/topic.php?id=23&#038;page#post-109</link>
<pubDate>Wed, 05 Dec 2007 01:38:39 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">109@http://forums.eracks.net/</guid>
<description>&#60;p&#62;What OS and version?
&#60;/p&#62;</description>
</item>
<item>
<title>james on "kernel oopses with ipw3945 driver v1.2.0"</title>
<link>http://forums.eracks.net/topic.php?id=23&#038;page#post-108</link>
<pubDate>Tue, 04 Dec 2007 23:54:06 +0000</pubDate>
<dc:creator>james</dc:creator>
<guid isPermaLink="false">108@http://forums.eracks.net/</guid>
<description>&#60;p&#62;If you're using the Intel ipw3945 driver version 1.2.0 or below, this likely applies to you.  I was running into a pretty serious issue with my laptop, where the ipw3945 driver (with version 2.6.23.1 of the Linux kernel) caused random kernel oopses every now and then.  I was starting to suspect a hardware issue, but googling around revealed that this was actually a known bug in 1.2.0 (the version I had installed), and that it has been fixed since 1.2.1.&#60;/p&#62;
&#60;p&#62;If you suspect you have this same problem, it can be fixed by installing v1.2.1 or newer.&#60;/p&#62;
&#60;p&#62;James
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "Toshiba Tablet FreeBSD 6.2 install"</title>
<link>http://forums.eracks.net/topic.php?id=19&#038;page#post-107</link>
<pubDate>Wed, 21 Nov 2007 20:06:52 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">107@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Texas Instruments (TI) is vendor 104c, and those devices are 803a, 803b, and 803c.&#60;/p&#62;
&#60;p&#62;According to: &#60;a href=&#34;http://www.pcidatabase.com/vendor_details.php?id=308,&#34; rel=&#34;nofollow&#34;&#62;http://www.pcidatabase.com/vendor_details.php?id=308,&#60;/a&#62;&#60;br /&#62;
the 803c appears to be an SD controller.&#60;/p&#62;
&#60;p&#62;Further searching/googling around for &#34;104c 803c BSD&#34; (or FreeBSD or linux, too) reveals further enlightening info on this, and the starting point for further searches..&#60;/p&#62;
&#60;p&#62;Here's some partial success on Ubuntu Feisty (one release old):&#60;br /&#62;
&#60;a href=&#34;http://ubuntuforums.org/showthread.php?t=459987&#34; rel=&#34;nofollow&#34;&#62;http://ubuntuforums.org/showthread.php?t=459987&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;BTW, to boot from a live Ubuntu Gutsy CD, simply download a CDImage for your platform (i386 first or x86-64 second choice) from &#60;a href=&#34;http://ubuntu.com&#34; rel=&#34;nofollow&#34;&#62;http://ubuntu.com&#60;/a&#62; and burn it to a blank CD!&#60;/p&#62;
&#60;p&#62;For that matter, they'll even mail you one for free, as I recall..
&#60;/p&#62;</description>
</item>
<item>
<title>Alan on "Toshiba Tablet FreeBSD 6.2 install"</title>
<link>http://forums.eracks.net/topic.php?id=19&#038;page#post-106</link>
<pubDate>Wed, 21 Nov 2007 18:21:51 +0000</pubDate>
<dc:creator>Alan</dc:creator>
<guid isPermaLink="false">106@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Is it one of the none[012] devices listed in pciconf?
&#60;/p&#62;</description>
</item>
<item>
<title>Alan on "Toshiba Tablet FreeBSD 6.2 install"</title>
<link>http://forums.eracks.net/topic.php?id=19&#038;page#post-105</link>
<pubDate>Wed, 21 Nov 2007 18:19:49 +0000</pubDate>
<dc:creator>Alan</dc:creator>
<guid isPermaLink="false">105@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Hi. I'm afraid I'm completely ignorant about Linux.  Where can I get a bootable Ubuntu CD?  Do they sell these shrinkwrapped, like at Fry's or Computer Center?&#60;/p&#62;
&#60;p&#62;Meanwhile, here is output from pciconf -lv:&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#60;br /&#62;
&#60;a href=&#34;mailto:hostb0@pci0:0:0:&#34;&#62;hostb0@pci0:0:0:&#60;/a&#62;        class=0x060000 card=0x00011179 chip=0x27a08086 rev=0x03 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    class    = bridge&#60;br /&#62;
    subclass = HOST-PCI&#60;br /&#62;
&#60;a href=&#34;mailto:agp0@pci0:2:0:&#34;&#62;agp0@pci0:2:0:&#60;/a&#62;  class=0x030000 card=0x00011179 chip=0x27a28086 rev=0x03 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    class    = display&#60;br /&#62;
    subclass = VGA&#60;br /&#62;
&#60;a href=&#34;mailto:none0@pci0:2:1:&#34;&#62;none0@pci0:2:1:&#60;/a&#62; class=0x038000 card=0x00011179 chip=0x27a68086 rev=0x03 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    class    = display&#60;br /&#62;
&#60;a href=&#34;mailto:pcm0@pci0:27:0:&#34;&#62;pcm0@pci0:27:0:&#60;/a&#62; class=0x040300 card=0x00011179 chip=0x27d88086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) High Definition Audio'&#60;br /&#62;
    class    = multimedia&#60;br /&#62;
&#60;a href=&#34;mailto:pcib1@pci0:28:0:&#34;&#62;pcib1@pci0:28:0:&#60;/a&#62;        class=0x060400 card=0x00000040 chip=0x27d08086 rev=0x02 hdr=0x01&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) PCI Express Root Port'&#60;br /&#62;
    class    = bridge&#60;br /&#62;
    subclass = PCI-PCI&#60;br /&#62;
&#60;a href=&#34;mailto:pcib2@pci0:28:2:&#34;&#62;pcib2@pci0:28:2:&#60;/a&#62;        class=0x060400 card=0x00000040 chip=0x27d48086 rev=0x02 hdr=0x01&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) PCI Express Root Port'&#60;br /&#62;
    class    = bridge&#60;br /&#62;
    subclass = PCI-PCI&#60;br /&#62;
&#60;a href=&#34;mailto:uhci0@pci0:29:0:&#34;&#62;uhci0@pci0:29:0:&#60;/a&#62;        class=0x0c0300 card=0x00011179 chip=0x27c88086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) USB Universal Host Controller'&#60;br /&#62;
    class    = serial bus&#60;br /&#62;
    subclass = USB&#60;br /&#62;
&#60;a href=&#34;mailto:uhci1@pci0:29:1:&#34;&#62;uhci1@pci0:29:1:&#60;/a&#62;        class=0x0c0300 card=0x00011179 chip=0x27c98086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) USB Universal Host Controller'&#60;br /&#62;
    class    = serial bus&#60;br /&#62;
    subclass = USB&#60;br /&#62;
&#60;a href=&#34;mailto:uhci2@pci0:29:2:&#34;&#62;uhci2@pci0:29:2:&#60;/a&#62;        class=0x0c0300 card=0x00011179 chip=0x27ca8086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) USB Universal Host Controller'&#60;br /&#62;
    class    = serial bus&#60;br /&#62;
    subclass = USB&#60;br /&#62;
&#60;a href=&#34;mailto:uhci3@pci0:29:3:&#34;&#62;uhci3@pci0:29:3:&#60;/a&#62;        class=0x0c0300 card=0x00011179 chip=0x27cb8086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) USB Universal Host Controller'&#60;br /&#62;
    class    = serial bus&#60;br /&#62;
    subclass = USB&#60;br /&#62;
&#60;a href=&#34;mailto:ehci0@pci0:29:7:&#34;&#62;ehci0@pci0:29:7:&#60;/a&#62;        class=0x0c0320 card=0x00011179 chip=0x27cc8086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) USB 2.0 Enhanced Host Controller'&#60;br /&#62;
    class    = serial bus&#60;br /&#62;
    subclass = USB&#60;br /&#62;
&#60;a href=&#34;mailto:pcib3@pci0:30:0:&#34;&#62;pcib3@pci0:30:0:&#60;/a&#62;        class=0x060401 card=0x00000050 chip=0x24488086 rev=0xe2 hdr=0x01&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801BAM/CAM/DBM (ICH2-M/3-M/4-M) Hub Interface to PCI Bridge'&#60;br /&#62;
    class    = bridge&#60;br /&#62;
    subclass = PCI-PCI&#60;br /&#62;
&#60;a href=&#34;mailto:isab0@pci0:31:0:&#34;&#62;isab0@pci0:31:0:&#60;/a&#62;        class=0x060100 card=0x00011179 chip=0x27b98086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801GBM (ICH7-M) LPC Interface Controller'&#60;br /&#62;
    class    = bridge&#60;br /&#62;
    subclass = PCI-ISA&#60;br /&#62;
&#60;a href=&#34;mailto:atapci0@pci0:31:1:&#34;&#62;atapci0@pci0:31:1:&#60;/a&#62;      class=0x01018a card=0x00011179 chip=0x27df8086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801G (ICH7 Family) Ultra ATA Storage Controller'&#60;br /&#62;
    class    = mass storage&#60;br /&#62;
    subclass = ATA&#60;br /&#62;
&#60;a href=&#34;mailto:atapci1@pci0:31:2:&#34;&#62;atapci1@pci0:31:2:&#60;/a&#62;      class=0x010601 card=0x0f001179 chip=0x27c58086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    device   = '82801GB Mobile I/O Controller Hub SATA cc=AHCI'&#60;br /&#62;
    class    = mass storage&#60;br /&#62;
&#60;a href=&#34;mailto:em0@pci1:0:0:&#34;&#62;em0@pci1:0:0:&#60;/a&#62;   class=0x020000 card=0x00011179 chip=0x109a8086 rev=0x00 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    class    = network&#60;br /&#62;
    subclass = ethernet&#60;br /&#62;
&#60;a href=&#34;mailto:wpi0@pci2:0:0:&#34;&#62;wpi0@pci2:0:0:&#60;/a&#62;  class=0x028000 card=0x10408086 chip=0x42228086 rev=0x02 hdr=0x00&#60;br /&#62;
    vendor   = 'Intel Corporation'&#60;br /&#62;
    class    = network&#60;br /&#62;
&#60;a href=&#34;mailto:cbb0@pci3:11:0:&#34;&#62;cbb0@pci3:11:0:&#60;/a&#62; class=0x060700 card=0x00011179 chip=0x8039104c rev=0x00 hdr=0x02&#60;br /&#62;
    vendor   = 'Texas Instruments (TI)'&#60;br /&#62;
    class    = bridge&#60;br /&#62;
    subclass = PCI-CardBus&#60;br /&#62;
&#60;a href=&#34;mailto:fwohci0@pci3:11:1:&#34;&#62;fwohci0@pci3:11:1:&#60;/a&#62;      class=0x0c0010 card=0x00011179 chip=0x803a104c rev=0x00 hdr=0x00&#60;br /&#62;
    vendor   = 'Texas Instruments (TI)'&#60;br /&#62;
    class    = serial bus&#60;br /&#62;
    subclass = FireWire&#60;br /&#62;
&#60;a href=&#34;mailto:none1@pci3:11:2:&#34;&#62;none1@pci3:11:2:&#60;/a&#62;        class=0x018000 card=0x00011179 chip=0x803b104c rev=0x00 hdr=0x00&#60;br /&#62;
    vendor   = 'Texas Instruments (TI)'&#60;br /&#62;
    class    = mass storage&#60;br /&#62;
&#60;a href=&#34;mailto:none2@pci3:11:3:&#34;&#62;none2@pci3:11:3:&#60;/a&#62;        class=0x080501 card=0x00011179 chip=0x803c104c rev=0x00 hdr=0x00&#60;br /&#62;
    vendor   = 'Texas Instruments (TI)'&#60;br /&#62;
    class    = base peripheral&#60;br /&#62;
&#60;/code&#62;&#60;/p&#62;
&#60;p&#62;And here is output from pcitweak -l:&#60;/p&#62;
&#60;p&#62;&#60;code&#62;&#60;br /&#62;
PCI: Probing config type using method 1&#60;br /&#62;
PCI: Config type is 1&#60;br /&#62;
PCI: PCI scan (all values are in hex)&#60;br /&#62;
PCI: 00:00:0: chip 8086,27a0 card 1179,0001 rev 03 class 06,00,00 hdr 00&#60;br /&#62;
PCI: 00:02:0: chip 8086,27a2 card 1179,0001 rev 03 class 03,00,00 hdr 80&#60;br /&#62;
PCI: 00:02:1: chip 8086,27a6 card 1179,0001 rev 03 class 03,80,00 hdr 80&#60;br /&#62;
PCI: 00:1b:0: chip 8086,27d8 card 1179,0001 rev 02 class 04,03,00 hdr 00&#60;br /&#62;
PCI: 00:1c:0: chip 8086,27d0 card 0000,0000 rev 02 class 06,04,00 hdr 81&#60;br /&#62;
PCI: 00:1c:2: chip 8086,27d4 card 0000,0000 rev 02 class 06,04,00 hdr 81&#60;br /&#62;
PCI: 00:1d:0: chip 8086,27c8 card 1179,0001 rev 02 class 0c,03,00 hdr 80&#60;br /&#62;
PCI: 00:1d:1: chip 8086,27c9 card 1179,0001 rev 02 class 0c,03,00 hdr 00&#60;br /&#62;
PCI: 00:1d:2: chip 8086,27ca card 1179,0001 rev 02 class 0c,03,00 hdr 00&#60;br /&#62;
PCI: 00:1d:3: chip 8086,27cb card 1179,0001 rev 02 class 0c,03,00 hdr 00&#60;br /&#62;
PCI: 00:1d:7: chip 8086,27cc card 1179,0001 rev 02 class 0c,03,20 hdr 00&#60;br /&#62;
PCI: 00:1e:0: chip 8086,2448 card 0000,0000 rev e2 class 06,04,01 hdr 01&#60;br /&#62;
PCI: 00:1f:0: chip 8086,27b9 card 1179,0001 rev 02 class 06,01,00 hdr 80&#60;br /&#62;
PCI: 00:1f:1: chip 8086,27df card 1179,0001 rev 02 class 01,01,8a hdr 00&#60;br /&#62;
PCI: 00:1f:2: chip 8086,27c5 card 1179,0f00 rev 02 class 01,06,01 hdr 00&#60;br /&#62;
PCI: 01:00:0: chip 8086,109a card 1179,0001 rev 00 class 02,00,00 hdr 00&#60;br /&#62;
PCI: 02:00:0: chip 8086,4222 card 8086,1040 rev 02 class 02,80,00 hdr 00&#60;br /&#62;
PCI: 03:0b:0: chip 104c,8039 card fffc,ffff rev 00 class 06,07,00 hdr 82&#60;br /&#62;
PCI: 03:0b:1: chip 104c,803a card 1179,0001 rev 00 class 0c,00,10 hdr 80&#60;br /&#62;
PCI: 03:0b:2: chip 104c,803b card 1179,0001 rev 00 class 01,80,00 hdr 80&#60;br /&#62;
PCI: 03:0b:3: chip 104c,803c card 1179,0001 rev 00 class 08,05,01 hdr 80&#60;br /&#62;
PCI: End of PCI scan&#60;br /&#62;
&#60;/code&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "Toshiba Tablet FreeBSD 6.2 install"</title>
<link>http://forums.eracks.net/topic.php?id=19&#038;page#post-104</link>
<pubDate>Wed, 21 Nov 2007 17:40:48 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">104@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Hmm...  I don't see the SD/MMC card in the dmesg you send.&#60;/p&#62;
&#60;p&#62;Two things we can do, next:&#60;/p&#62;
&#60;p&#62;1) List the PCI bus details with &#34;pciconf -lv&#34; and/or pcitweak, and look for the SD/MMC card or the 'unknown' entries&#60;/p&#62;
&#60;p&#62;2) Boot up from a Ubuntu Gutsy Gibbon Live CD, and read the dmesg (and post it here!), and see if it possibly is recognized and works under Gutsy.
&#60;/p&#62;</description>
</item>
<item>
<title>Alan on "Change BSD/Linux terminology @ login screen"</title>
<link>http://forums.eracks.net/topic.php?id=20&#038;page#post-103</link>
<pubDate>Wed, 21 Nov 2007 08:20:50 +0000</pubDate>
<dc:creator>Alan</dc:creator>
<guid isPermaLink="false">103@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Try editing the /etc/gettytab file.  I'm running FreeBSD, not OpenBSD but I suspect it's the same.  If you can't figure out the gettytab file, you can run the command &#34;man 5 gettytab&#34;.
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "Setting PFW Rules"</title>
<link>http://forums.eracks.net/topic.php?id=22&#038;page#post-102</link>
<pubDate>Sat, 17 Nov 2007 22:17:58 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">102@http://forums.eracks.net/</guid>
<description>&#60;p&#62;You need the &#34;-&#38;gt;&#34; to set the destination - &#60;/p&#62;
&#60;p&#62;Assuming the following macros:&#60;/p&#62;
&#60;p&#62;external_ip = 208.57.255.188&#60;br /&#62;
internal_ip = 208.57.255.188&#60;/p&#62;
&#60;p&#62;And assuming that the old fw rule you show above intends to redirect both 5632 and 5631 to the new internal IP (rather than remap 5632 to 5631), the rdr rule would be something like:&#60;/p&#62;
&#60;p&#62;rdr on $ext_if proto tcp from any to $external_ip port { 5632 5631 } -&#38;gt; $internal_ip&#60;/p&#62;
&#60;p&#62;And if you wanted to remap 5632 to 5631, it would be something like:&#60;/p&#62;
&#60;p&#62;rdr on $ext_if proto tcp from any to $external_ip port 5632 -&#38;gt; $internal_ip port 5631&#60;/p&#62;
&#60;p&#62;ANd if you want to declare a filter rule to pass the traffic related to this NAT rule, just add 'pass', thusly:&#60;/p&#62;
&#60;p&#62;rdr pass on $ext_if proto tcp from any to $external_ip port { 5632 5631 } -&#38;gt; $internal_ip&#60;/p&#62;
&#60;p&#62;We rarely/seldom need to use tags except for the most esoteric/complex setups, which it does not sound like you need.&#60;/p&#62;
&#60;p&#62;Also, pfw does indeed handle rdr rules - not sure why you think it doesn't!&#60;/p&#62;
&#60;p&#62;Here's the pfw page, see 'nat rules':&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.allard.nu/pfw&#34; rel=&#34;nofollow&#34;&#62;http://www.allard.nu/pfw&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;And here's a screenshot showing an rdr rule - it's near the bottom of the list:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.allard.nu/pfw/pics/nat1.png&#34; rel=&#34;nofollow&#34;&#62;http://www.allard.nu/pfw/pics/nat1.png&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "Setting PFW Rules"</title>
<link>http://forums.eracks.net/topic.php?id=22&#038;page#post-101</link>
<pubDate>Fri, 16 Nov 2007 18:57:39 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">101@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Thanks for the reply. I have been reading a lot of the manual, and I have a better understanding of what is going on. I also found another good resource:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://home.nuug.no/~peter/pf/&#34; rel=&#34;nofollow&#34;&#62;http://home.nuug.no/~peter/pf/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;But, none of them deal specifically with pfw. And, bumping around in it, it seems to not have the &#34;rdr&#34; command, which I apparently need.&#60;/p&#62;
&#60;p&#62;There are rules on my current fw that allow incoming connections to internal IPs. They look something like: Incoming from Any to 208.57.255.188 -&#38;gt; 172.20.255.82 port tcp:5632 tcp:5631.&#60;/p&#62;
&#60;p&#62;These rules are set because our hotel system talks to an external server that sends reservation information. After doing some research, I think my rule should look like:&#60;/p&#62;
&#60;p&#62;rdr on $ext_if inet proto tcp from any to ($ext_if:0) port { 5632 5631 }&#60;/p&#62;
&#60;p&#62;THEN from what I understand I need to tag them, and then the pass rules will evaluate them.&#60;/p&#62;
&#60;p&#62;tag OPERAOWS -&#38;gt; 172.20.255.82&#60;br /&#62;
#OPERAOWS is what I want to use because Opera is our hotel system.&#60;/p&#62;
&#60;p&#62;THEN the pass rule can evaluate it:&#60;/p&#62;
&#60;p&#62;pass in on $ext_if inet proto tcp tagged OKPKTS synproxy state&#60;/p&#62;
&#60;p&#62;So am I completely off? I appreciate you taking the time to help. I am really trying to learn.
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "Setting PFW Rules"</title>
<link>http://forums.eracks.net/topic.php?id=22&#038;page#post-100</link>
<pubDate>Fri, 16 Nov 2007 17:52:10 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">100@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Ken,&#60;/p&#62;
&#60;p&#62;1) As a rule, you want to apply your incoming filter rules to the external interface.  Unless you want to restrict or filter the outbound traffic from your internal LAN users, you usually want to just pass all outbound traffic on the internal interface.&#60;/p&#62;
&#60;p&#62;2) You can put the port number in both the source/dest matching expression (&#34;Pass in on $ext_if from any to $mail_server port 25&#34;), or in the destination expression (the part after the &#34;-&#38;gt;&#34;), which will remap the port.&#60;/p&#62;
&#60;p&#62;Question 1 is covered in the &#34;PACKET FILTERING&#34; section of the pf.conf maunal, and question 2 is covered in the &#34;TRANSLATION&#34; section.&#60;/p&#62;
&#60;p&#62;See also the FILTERING EXAMPLES and TRANSLATION EXAMPLES sections for handy cut/pasteable examples for common usage scenarios.&#60;/p&#62;
&#60;p&#62;Many of your questions show that you could really benefit from close scrutiny of the manuals -&#60;br /&#62;
Remember the &#34;man pf.conf&#34; and &#34;man pfctl&#34; commands are your friend.&#60;/p&#62;
&#60;p&#62;Here is a great &#34;Getting started&#34; guide for pf:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://home.nyc.rr.com/computertaijutsu/pf.html&#34; rel=&#34;nofollow&#34;&#62;http://home.nyc.rr.com/computertaijutsu/pf.html&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;And here is a great OpenBSD example for SOHO use:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.openbsd.org/faq/pf/example1.html&#34; rel=&#34;nofollow&#34;&#62;http://www.openbsd.org/faq/pf/example1.html&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "Setting PFW Rules"</title>
<link>http://forums.eracks.net/topic.php?id=22&#038;page#post-99</link>
<pubDate>Thu, 08 Nov 2007 15:43:27 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">99@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Well after reading about PF, I answered a few of my own questions.&#60;/p&#62;
&#60;p&#62;ext_if is a macro for my interfaces.&#60;/p&#62;
&#60;p&#62;&#34;Any&#34; will work as a valid source/destination according to the literature.&#60;/p&#62;
&#60;p&#62;It said a protocol will be assumed based on the transmission if I don't specify&#60;/p&#62;
&#60;p&#62;Family address is inet for IPv4, inet6 for IPv6&#60;br /&#62;
_____________________________________________________________&#60;/p&#62;
&#60;p&#62;But I still have questions!!&#60;/p&#62;
&#60;p&#62;1. I have specified my external interface in my macro. When do I need to specify my internal interface?&#60;/p&#62;
&#60;p&#62;2.  If I need to put in a port number, what makes it dependent upon whether I put it in the source or destination section?&#60;/p&#62;
&#60;p&#62;Thanks.
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "Setting PFW Rules"</title>
<link>http://forums.eracks.net/topic.php?id=22&#038;page#post-98</link>
<pubDate>Fri, 02 Nov 2007 00:39:39 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">98@http://forums.eracks.net/</guid>
<description>&#60;p&#62;# ruleset automatically generated by pfw&#60;br /&#62;
#&#60;/p&#62;
&#60;p&#62;ext_if = &#34;re0&#34; 	# External interface&#60;br /&#62;
int_if = &#34;re1&#34; 	# Internal interface&#60;/p&#62;
&#60;p&#62;block log all # Default block rule&#60;br /&#62;
pass in on re0 all # Allow everything on localhost&#60;/p&#62;
&#60;p&#62;# Antispoof rules&#60;br /&#62;
antispoof for $ext_if&#60;/p&#62;
&#60;p&#62;# General rules&#60;br /&#62;
pass in log on $ext_if inet proto tcp from any to $ext_if port { ssh https } keep state # Allow administration of the firewall&#60;/p&#62;
&#60;p&#62;# Network Rules&#60;br /&#62;
pass in log on $ext_if from ipsec_users to 172.20.0.0 # Any in&#60;br /&#62;
pass out log on $ext_if from 172.20.0.0 to ipsec_users # Any out&#60;br /&#62;
pass in on $ext_if proto tcp from any to 172.20.255.108 port 5190 # AOL in&#60;br /&#62;
pass out log on $ext_if proto tcp from 172.20.255.108 to any port 5190 # AOL out&#60;br /&#62;
pass in on $ext_if from any to 172.20.255.108 port 5190 # AOL in&#60;br /&#62;
pass out log on $ext_if proto tcp from 172.20.1.110 port 80 to any # Filtered-HTTP&#60;br /&#62;
pass in on $ext_if proto tcp from any to 172.20.255.108 port 25 # Filtered-SMTP in&#60;br /&#62;
pass out log on $ext_if proto tcp from 172.20.255.108 port 25 to any # Filtered-SMTP out&#60;br /&#62;
pass in log on $ext_if proto FTP from 208.57.255.187 port 21 to 172.20.99.6 # FTP in&#60;br /&#62;
pass out log on $ext_if proto FTP from 172.20.99.6 to any port 21 # FTP out&#60;br /&#62;
pass in log on $ext_if proto tcp from 208.57.255.187 port 443 to 172.20.255.189 # HTTPS_Synxis in
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "Setting PFW Rules"</title>
<link>http://forums.eracks.net/topic.php?id=22&#038;page#post-97</link>
<pubDate>Fri, 02 Nov 2007 00:37:34 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">97@http://forums.eracks.net/</guid>
<description>&#60;p&#62;So, I am getting into this pfw now, and I have some questions about setting these rules. &#60;/p&#62;
&#60;p&#62;1. I assume &#34;interface&#34; means my network card. Part of the basic configuration involved setting a macro, where ext_if was set as the lo0. If I am translating this right, does the ext_if stand for the network interface lo0? In my case, my net adapters are re0 and re1. If so, why do I set the interface to $ext_if instead of just using the re0?&#60;/p&#62;
&#60;p&#62;And what does the $ mean?&#60;/p&#62;
&#60;p&#62;2. Does the syntax &#34;any&#34; work as a source or destination?&#60;/p&#62;
&#60;p&#62;3. If I need to put in a port number, what makes it dependent upon whether I put it in the source or destination section?&#60;/p&#62;
&#60;p&#62;4. Is a protocol always necessary? &#60;/p&#62;
&#60;p&#62;5. What does the Family Address represent? What does inet mean and when should I use it?&#60;/p&#62;
&#60;p&#62;6 What would be the rule if I wanted to block incoming pings? &#60;/p&#62;
&#60;p&#62;In the next post, I will show you what I have. I know there are errors, but perhaps I could get some pointers?&#60;/p&#62;
&#60;p&#62;Thanks!!!
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-96</link>
<pubDate>Tue, 23 Oct 2007 19:56:58 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">96@http://forums.eracks.net/</guid>
<description>&#60;p&#62;... and everything on the LAN, both the 172.20.255 and the 172.20.1 have the same netmasks.
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-95</link>
<pubDate>Tue, 23 Oct 2007 19:55:42 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">95@http://forums.eracks.net/</guid>
<description>&#60;p&#62;So I will change the broadcast back to 172.20.255.255
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-94</link>
<pubDate>Tue, 23 Oct 2007 19:51:58 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">94@http://forums.eracks.net/</guid>
<description>&#60;p&#62;I changed it because I thought I read somewhere that the broadcast would just be what that adapter was seen at for identification. I changed it in the hostname.re0 file, and rebooted. &#60;/p&#62;
&#60;p&#62;It had the unresponsive behavior regardless of the broadcast ID, however.
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-93</link>
<pubDate>Tue, 23 Oct 2007 19:48:34 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">93@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Right - if you set the IP and netmask, it will set the broadcast for you.&#60;/p&#62;
&#60;p&#62;But remember, this netmask (a /16) should match all the other systems on the same LAN!
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-92</link>
<pubDate>Tue, 23 Oct 2007 19:44:52 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">92@http://forums.eracks.net/</guid>
<description>&#60;p&#62;When I type in ifconfig re0, it told me my broadcast was 172.20.255.255
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-91</link>
<pubDate>Tue, 23 Oct 2007 18:59:47 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">91@http://forums.eracks.net/</guid>
<description>&#60;p&#62;Your broadcast address is always the inverse of your netmask applied to your IP - in other words, if you have a /24, with a netmask of 255.255.255.0, and an IP of 1.2.3.4, your broadcast address should be 1.2.3.255 - the same IP with a /16 (a netmask of 255.255.0.0) would have a broadcast address of 1.2.255.255.&#60;/p&#62;
&#60;p&#62;- Machines on the same network, but with mismatched netmasks, may not communicate correctly even though they appear to be on the same network.  Especially with hubs and switches involved, which can get confused more easily because of this.&#60;/p&#62;
&#60;p&#62;- incorrectly configured broadcast addresses can cause strange and unpredictable responses, and interact poorly with routers, filters, hubs, switches, firewalls, and other networking hardware.
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-90</link>
<pubDate>Tue, 23 Oct 2007 18:17:12 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">90@http://forums.eracks.net/</guid>
<description>&#60;p&#62;It is broadcasting the same as the IP: 172.20.255.16.&#60;/p&#62;
&#60;p&#62;I think that the problem is on our network however. I pulled it off our network and connected my PC directly to it, and it worked fine. My &#34;uneducated&#34; guess is that our current FW saw something being transmitted by the Twinguard fw and locked it up. I don't really know how, and there's nothing in the logs, but still when it was taken off the network it behaved fine. &#60;/p&#62;
&#60;p&#62;My concern is when I get this thing back on the network and take the other firewalls off, will it do it again? &#60;/p&#62;
&#60;p&#62;Well, either way it works to this point. Next I will have questions about setting up rules on pfw
&#60;/p&#62;</description>
</item>
<item>
<title>joe on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-89</link>
<pubDate>Tue, 23 Oct 2007 00:15:07 +0000</pubDate>
<dc:creator>joe</dc:creator>
<guid isPermaLink="false">89@http://forums.eracks.net/</guid>
<description>&#60;p&#62;What is your broadcast address?
&#60;/p&#62;</description>
</item>
<item>
<title>kenneth2k1 on "What's the process for running this pfw"</title>
<link>http://forums.eracks.net/topic.php?id=12&#038;page#post-88</link>
<pubDate>Mon, 22 Oct 2007 21:53:47 +0000</pubDate>
<dc:creator>kenneth2k1</dc:creator>
<guid isPermaLink="false">88@http://forums.eracks.net/</guid>
<description>&#60;p&#62;As I stated before, I am plugged into only one NIC - re0. That's it. &#60;/p&#62;
&#60;p&#62;Also, the settings that I input were from your cookbook, and if you see anything in there that looks bad, I will gladly change it. &#60;/p&#62;
&#60;p&#62;I have the current firewall monitor up, and it gives me a bandwidth meter. At it's highest point, sending traffic was at 400kbps and receiving traffic was at about 700kbps. That isn't that much traffic at all.
&#60;/p&#62;</description>
</item>

</channel>
</rss>
