#arpnetworks 2009-11-16,Mon

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)

WhoWhatWhen
***d^_^b has quit IRC (Remote closed the connection)
d^_^b has joined #arpnetworks
[00:11]
............ (idle for 55mn)
mhoran_ has joined #arpnetworks
ChanServ sets mode: +o mhoran_
mhoran has quit IRC (Read error: 54 (Connection reset by peer))
[01:06]
.................... (idle for 1h39mn)
ballen has quit IRC (Read error: 60 (Operation timed out)) [02:45]
............................................. (idle for 3h44mn)
toddfjeev: you seem to miss the point, after being whitelisted, if you regularly communicate with a mail server, no delays
aka for people you communicate regularly with, a one time delay seems acceptable, to cut mail flow by up to 80%
[06:29]
***mhoran_ is now known as mhoran [06:33]
vxpdepeer the innanet [06:47]
............ (idle for 58mn)
***sentabi_ has joined #arpnetworks [07:45]
.... (idle for 17mn)
djnaff has joined #arpnetworks [08:02]
.......... (idle for 47mn)
sentabi__ has joined #arpnetworks [08:49]
sentabi_ has quit IRC (Read error: 110 (Connection timed out)) [08:59]
.... (idle for 17mn)
djnaffany one know how many ipv4 addresses come in the topic package [09:16]
mhoran1
All packages include a /30, which is essentially one IP.
[09:22]
djnaffhow much for extra 3 [09:29]
jeevtoddf, i'd show some interest
i need to try it first.
[09:35]
***ballen has joined #arpnetworks
ChanServ sets mode: +o ballen
[09:35]
coili thought a /31 was one ip
and a /30 is 4
[09:35]
vxpmore like /32 [09:35]
coilwell /31 being a 2
but one useable
[09:35]
ballenballen doesn't wanna work [09:38]
toddfmhoran: just use v6, pleanty of extras there *grin* [09:40]
mhoranYep.
coil: /32 is 1 IP, /31 2, /30 4. However, /30 has two usable, one for the router, one for you.
/32 and /31 cannot properly be used in routing.
up_the_irons does proper CIDR routing, so that requires a /30 per customer.
(The other two IPs are reserved, the first for network, last for broadcast.)
[09:40]
djnaffso how much for extra ones :) [09:48]
jeevdjnaff, dont take my word for it. my assumption would be $1-$2/each/month, probably 1
you should wit a moment for up_the_irons to come by
or maybe send an email to sales, maybe he has that going to his cell phone
[09:48]
ballen5 IPs (/29 subnet, $4) [09:49]
jeevahh, it saays on his website too haha [09:49]
ballenor 13 IPs (/28 subnet, $8)
I believe up_the_irons only sells IP's in CIDR blocks
not individually
[09:49]
***ballen is now known as ballen|away [09:53]
djnaffty [09:55]
***cablehead has joined #arpnetworks
ChanServ sets mode: +o cablehead
[10:02]
..... (idle for 22mn)
ballen|away is now known as ballen
visinin has joined #arpnetworks
[10:24]
...... (idle for 28mn)
djnaff has quit IRC ("Naff_script · "Don't force it, get a larger hammer"") [10:54]
..... (idle for 24mn)
soysamurai has joined #arpnetworks [11:18]
........ (idle for 35mn)
up_the_ironsballen: you're right, IPs are only sold in CIDR blocks; no funky diving out individual IPs from a large net and then firewalling off what you "shouldn't" see [11:53]
ballenya [11:53]
up_the_ironsmhoran: you could actually do a /31 with static ARP entries (since no broadcast address exists)
but I imagine I'd get tired of explaining that
[11:54]
toddfyou could route individual IP's once the initial block is allocated
as long as they set the netmask to all 1's no further config required
[11:55]
up_the_ironstoddf: sroute: I find your spam fighting techniques interesting [11:56]
toddfjust don't borrow 1and1 hosting's insane cisco based networking scheme `ip subnet zero' stuff
a client of mine has a colo there
[11:56]
up_the_ironstoddf: but this would require customers to share a VLAN, no?
toddf: ip subnet zero, LOL
yeah that's funky stuff
[11:57]
toddfDestination Gateway Flags Refs Use Mtu Prio Iface
default 10.255.255.1 UGS 158 677002749 - 8 nfe0
10.255/16 link#1 UCLS 1 0 - 8 nfe0
10.255.255.1 00:00:0c:07:ac:00 UHLc 6 0 - 8 nfe0
then add aliases on nfe0 as netmask of all 1's
!route add -llinfo -iface -net 10.255.0.0/16 10.255.255.1 -ifp nfe0
[11:57]
ballenisn't that special [11:58]
jeevtoddf, i'd like to try your spamd shit [11:58]
toddfthats a fun line to add to your hostname.nfe0 file [11:58]
jeevbut spamd is spamassassin, no? :D [11:58]
ballenno
not in OpenBSd
[11:58]
toddfjeev: spamd is the name of a daemon spamassassin runs, but /usr/libexec/spamd on OpenBSD is quite different [11:58]
mhoranOpenBSD spamd. [11:58]
jeevah yea i use freebsd. [11:58]
up_the_ironstoddf: sroute: regarding spam fighting, any blog posts I can read? I use dspam currently, and it works quite well, but I'm always into finding better techniques. and dspam only works for my user (I've trained it), and I find asking customers to train theirs is futile [11:59]
toddfup_the_irons: I use dspam myself, behind openbsd's spamd [11:59]
up_the_ironstoddf: gotcha [11:59]
toddfI guess I'll reformat the spamd man page myself, since the openbsd webserver took a hit and is just serving static pages for a bit
(hardware hit for those with active imaginations)
[11:59]
jeevah
thought my papasmurf worked
[12:00]
toddfhahaha
thats so 90s
smurfing
[12:01]
mhoranGreylisting is definitely an interesting technique, but I've never been able to get it to work well.
I just don't get enough volume.
[12:01]
jeev:D [12:01]
mhoranGUess I just need to become more popular! [12:01]
jeevi would love to greylist [12:01]
toddfI have one customer who went from 900k mails an hour to 100k mails an hour or less [12:01]
jeevtoddf, is there a spamd for freebsd [12:02]
mhoranIncoming mail at work runs through SA before delivery, and that does a pretty decent job.
jeev: Yes.
As well as pf, of course.
[12:02]
jeevmy postfix setup with rbl's and shit are awesome [12:02]
toddfjeev: I have no idea, it would work with pf, easily, because of tables .. [12:02]
mhoranjeev: /usr/ports/mail/spamd [12:03]
mike-burnsSA is pretty decent but I hate the dependencies. [12:03]
mhoranYup. I already needed perl for other things, so ...
Hm. If I get rid of all my friends, I could ditch perl. But with no friends, I could never use spamd ...
I don't see how I could win this one.
[12:03]
mike-burnsAs a long-time friend of yours I vote that you ditch Perl. [12:04]
toddf$insert_your_favorite_cmdline_http_to_stdou_app http://todd.fries.net/pub/spamd.cat8 | less
s/stdou/stdout/
[12:05]
mhoranAh, that worked much better. :) [12:07]
jeevsa's deps suck
especially when upgraindg perl;l
upgrading perl
[12:07]
mike-burnsSo with spamd, greylisting means that the first 10 seconds of a message delivery is stuttered?
How does a sender go from whitelisted to blacklisted?
(e.g. how do I mark sometihng as spam?)
[12:08]
mhoranIt's more than that. [12:09]
toddfby re-connecting
after 26 mins
from the same ip
from the same sender
to the same recipient
[12:09]
mhoranWell there we go. Saved me some typing! [12:10]
toddfthen the next connection bypasses spamd altogether and hits the mta directly [12:10]
mhoranMy secondary MX runs spamd, which helps a lot.
mike-burns: As does yours.
[12:10]
mike-burnsmhoran: News to me!
So spamd means that first-time senders will have a 26-minute delay on delivery?
[12:10]
mhoranYes. [12:11]
toddffirst time IP's
there's a huge difference
[12:11]
mike-burnsIndeed. [12:11]
mhoranTypically you purge the whitelist, too, which means if they don't mail you after some period of time, they get greylisted again. [12:11]
toddfsome postfix greylisting does it per sender address and per recipient as well [12:11]
mhoranSo that's my problem -- people don't mail me often enough to keep them whitelisting.
s/whitelisting/whitelisted.
[12:11]
toddfI have a list of manual over-rides, that never see spamd [12:11]
mike-burnsWell that purging doesn't make sense; if someone is whitelisted they should be whitelisted. [12:12]
toddfip renumbering [12:12]
mike-burnsOh sure. [12:12]
toddfyou can always change the default from 31 days to 1024 days
if anybody wants to play with stuttering hit any tcp port on 208.79.89.90
[12:12]
vxphttp://www.skytopia.com/project/fractal/mandelbulb.html [12:14]
mike-burnsPretty. [12:15]
toddfhttp://undeadly.org/cgi?action=article&sid=20090717041621
there's one person's adventure documented with spamd
[12:15]
mike-burnsspamd makes sense on a busy server, but less sense on my personal VPS. [12:17]
ballenI'm using Postgrey on my VPS
and no other spam filtering
catches almost everything
much better then just using dspam alone
[12:18]
jeevpostgrey sounds like it's for postfix
;D
[12:19]
ballenindeed
but really it could be used with any mta
[12:19]
........ (idle for 39mn)
***soysamurai has quit IRC () [12:58]
soysamurai has joined #arpnetworks [13:12]
........ (idle for 35mn)
toddfballen: depends entirely on what you're using the `personal' VPS for
ballen: I'm using mine as an extension/backup/whatever makes sense .. of Free Daemon Hosting .. kindof like a slowly allocated cloud but not as expensive (if I had 1 system up for 1 month at amazon, for example, it'd be over $100)
[13:47]
up_the_ironsamazon's way expensive [13:49]
jeevnot if you get it for free [13:54]
.... (idle for 17mn)
***soysamurai has quit IRC () [14:11]
....... (idle for 30mn)
toddfjeev: how would I get a vm at amazon for free??? [14:41]
.... (idle for 18mn)
jeevhey, i said not if you get it for free, i didn't say that i do
;)
[14:59]
..... (idle for 22mn)
***ballen is now known as ballen|away [15:21]
....... (idle for 30mn)
ballen|away is now known as ballen [15:51]
................... (idle for 1h31mn)
ballen is now known as ballen|away [17:22]
............ (idle for 57mn)
cablehead has quit IRC ("Leaving.") [18:19]
.......... (idle for 47mn)
ballen|away is now known as ballen
sbp_ has joined #arpnetworks
[19:06]
sbp_sup [19:12]
ballenhi [19:12]
***sentabi__ has quit IRC () [19:22]
...... (idle for 25mn)
heavysixer has quit IRC () [19:47]
sbp_hows things [19:52]
mhoranExcellent. [20:01]
sbp_right on [20:03]
***cablehead has joined #arpnetworks
ChanServ sets mode: +o cablehead
cablehead has quit IRC (Client Quit)
[20:09]
......... (idle for 41mn)
jeevwhy couldn't everyghint just remain 800x600
so we wouldn't have to worry about formatting
[20:51]
sbp_why would you want a shity screen resolution
or am i just missing it
[20:51]
jeevtired of html struggles
;D
[20:53]
sbp_:) [20:53]
jeevmaybe you'd be interested.. [20:57]
sbp_what you mean [20:58]
jeevi need to get a hold of some people who want palin to become president
and just beat them
[21:02]
sbp_haha
ill vote for you
but i dont even know who palin is
[21:02]
jeevsarah palin, the moron ex governor of alaska
the one americans say "we can relate, vote for her!"
hahaahaha oh my god
i need to stop caring about the public
[21:03]
sbp_ahh [21:05]
***heavysixer has joined #arpnetworks
ChanServ sets mode: +o heavysixer
[21:12]
ballen is now known as ballen|away [21:21]
jeevmy little cousin is friends with the kid from two and a half men, i asked him to get me charlie sheen's email address so i can email him about his 9/11 thingies he speaks out about [21:28]
........... (idle for 52mn)
***ballen|away is now known as ballen [22:20]
.................... (idle for 1h39mn)
obsidieth has quit IRC (lindbohm.freenode.net irc.freenode.net)
coil has quit IRC (lindbohm.freenode.net irc.freenode.net)
[23:59]

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)