***amdprophet has joined #arpnetworks [00:21]
..... (idle for 22mn)
amdprophet has quit IRC (Remote host closed the connection)
amdprophet has joined #arpnetworks
...... (idle for 27mn)
LT has joined #arpnetworks [01:11]
......................... (idle for 2h4mn)
amdprophet has quit IRC (Quit: amdprophet) [03:15]
.................... (idle for 1h37mn)
cedwardsCESSMASTER: excuse me? [04:52]
...... (idle for 28mn)
***ziyourenxiang has joined #arpnetworks [05:20]
....... (idle for 34mn)
vtoms has joined #arpnetworks [05:54]
heavysixer has joined #arpnetworks
ChanServ sets mode: +o heavysixer
.... (idle for 17mn)
schmir has quit IRC (Remote host closed the connection) [06:19]
............. (idle for 1h1mn)
cedwardsgood morning [07:20]
aemmorning cedwards :) [07:21]
cedwardsso I'm getting a crash-course in PF this morning. not sure I understand all the rules, but they appear to be working
(_much_ more experience with iptables)
RandalSchwartzpf rocks [07:24]
cedwardsI'm learning that. definitely seems less complicated than all the --foo and --bar options of iptables syntax.
one of the rules I've found suggested, and applied is: 'scrub in all'. I'm not 100% on what it does. Can you explain?
RandalSchwartzit reassembles partial packets
so that firewall rules can inspect full items
some attacks use partial packets to bypass deep inspection rules
cedwardsohh, so instead of packets being reassembled at each end-client, pf will reassemble it before filtering and passing it along? [07:30]
RandalSchwartzyes [07:30]
cedwardsthat's nice
how about this one: antispoof quick for {lo,em0}
best I understand is it's supposed to protect against spoofed addresses
RandalSchwartzkeeps a packet from passing if it shows up on the "wrong" interface
for example, an external packet crafted to look like it has your "internal" address
like from
cedwardsshould that be applied to all interfaces? just lo? just private interfaces? [07:31]
RandalSchwartzso that your firewall passes it as if it had show up locally
it doesn't hurt to apply it to all
no wait
it also filters non-routables too, I think
or maybe that's a different rule
on the inside, you don't want to filter those, if you have a vpn set up
cedwardsI have this rule applied to allow ping/monitoring from ARP nagios: pass in quick on em0 proto icmp from to $ext_ip keep state [07:32]
RandalSchwartzthe pf faq is pretty easy reading - http://www.openbsd.org/faq/pf/ [07:33]
cedwardsYeah. I've been in and out of that and a half-dozen other Google results.
I think the basic rule syntax makes sense. I still haven't quite grokked 'flags S/SA synproxy state' though
aemhehe cedwards its fun you mention it because I was just working on my pf.conf last night too [07:34]
RandalSchwartzsome of that is just magical fairy dust to me
"apply this here, because the faq says so"
and remember this command:
pfctl -vf /etc/pf.conf; sleep 10; pfctl -d
so that when you make a change, you see what it is
and if it works, hit ^C
if your ^C didn't work, wait 10 seconds :)
that keeps you from getting locked out
cedwardsmagical fairy dust reminds me of a theory I heard about how Ubuntu always "just worked".
Mark Shuttleworth brought back magical space dust from his trip to orbit with the Russians, and sprinkled it into the Ubuntu kernel :)
mike-burnsUbuntu works? [07:36]
cedwardsmike-burns: so they say [07:36]
aemyeah, Ubuntu works?
always breaks for me
mike-burnsI must have run out of magical space dust when I tried Ubuntu. [07:37]
RandalSchwartzubunutu acts as a nice shiny object to keep the beginner open source people away from us. :) [07:37]
cedwardscedwards imagines users as lolcats, swatting away at the shiny object. [07:38]
RandalSchwartzyou mean they're not? :) [07:39]
mike-burnsTo be fair, we're not the target audience of Ubuntu. [07:39]
cedwardsI try to go easy on them. I use to be a pretty heavy Ubuntu user. [07:39]
mike-burnsIt might work perfectly fine for people who don't do any programming, admining, etc. [07:40]
RandalSchwartzoooh. I was reading the FAQ, found ":0" [07:42]
cedwardsdoes anyone know what ARP is using to host these VPS'? [07:43]
RandalSchwartzI was trying to figure out how to ensure my outbound vpn traffic would come from my "main" address, instead of randomly all over my addresses. :)
there it is
cedwards - linux qemu I think
it says on the vps page
it's amazing how much goodness can exist inside a linux virtual box. :)
cedwardsRandalSchwartz: right, I know its kvm/qemu on linux, but I'm wondering what Distro they host from. [07:44]
RandalSchwartzask up_the_irons when he comes in [07:44]
mike-burnsI think it's, ironically, Ubuntu. [07:45]
RandalSchwartzthere - nat on $ext_if from !($ext_if) to ($ext_if) -> ($ext_if:0)
that's the nat rule I was looking for for my vpns
without the :0, it was round-robin'ing my /28
***fink has joined #arpnetworks [07:47]
cedwardsmike-burns: hey, as long as it works. [07:49]
mike-burnsYeah I'm not complaining. [07:49]
....... (idle for 32mn)
cedwardswell RHEL6 beta is fail for me. I'm going to try kvm/qemu hosting on a different platform here at work.
tempted to try FreeBSD as the host
it is always surprising the amount of random connection (attempts) you see when you watch firewall logs. [08:27]
RandalSchwartzyeah - steve gibson calls that the "background radiation" of the internet [08:28]
aemcedwards: on your arp vps? [08:29]
just had an attempt for example to 3306.
aemwow [08:30]
cedwardsno you may not connect to my non-existant mysql server, thank you. [08:30]
aemare you running ident? [08:31]
cedwards..no ? [08:31]
aemmaybe I should turn it off
cedwardsI'm actually not sure I know what ident is.. [08:35]
aemident daemon, it removes the ~ from your ident on IRC [08:36]
cedwardsohh. uhm, not that I know of.
I use irssi+bitlbee+screen over ssh. I actually do have a freenode cloak, which might be part of it.
nothing else fancy going on.
aemyou would know hehe, the only reason I was asking was because I was considering running mine in a jail
you have to load it in rc.conf
cedwardsmy irssi/bitlbee setup is in a jail and I know I'm not running ident in there.
in fact, I have three lines in that jail rc.conf. hostname, sshd_enable, bitlbee_enable.
aemcedwards: do you use ez jail? [08:39]
cedwardsaem: oh, absolutely
ezjail-admin is akin to go-go-gadget! :)
aemhehe cool, I must change my securelevel first to set it up ;-/ [08:41]
cedwardswhich, I still think someone needs to write a utility with that name. [08:41]
aemdon't wanna reboot
yes go-go-gadget is a must
cedwardshow fun would that be? go-go-gadget install package. [08:42]
aemi would prefer it to do .conf files for me :) [08:43]
cedwardsgo-go-gadget do .conf files for aem.
aemthank you!!! [08:44]
cedwardsgo-go-gadget change securelevel. done [08:44]
aemhehe [08:47]
cedwardsI should probably set securelevel when I'm done configuring everything too.
haven't bothered in the past, but I know it's a good idea
aemyeah set it to 2 [08:50]
***schmir has joined #arpnetworks
schmir has quit IRC (Ping timeout: 276 seconds)
cedwardsinteresting on the topic of securelevel - http://patchlog.com/general/freebsd-securelevel-setup/ [08:58]
***ziyourenxiang has quit IRC (Quit: ziyourenxiang) [09:08]
cedwardsok. time to deploy some jails. can anyone comment on doing zfs based jails? [09:14]
finkis your root on zfs?
is your root on zfs?
is your root on zfs?
is your root on zfs?
***fink has quit IRC (Quit: fink) [09:16]
***LT has quit IRC (Quit: Leaving)
fink has joined #arpnetworks
.... (idle for 16mn)
cedwardswhat is port 445? is that the windows "virus port" as I so often hear it described? [09:35]
..... (idle for 23mn)
bob^^445 is used for netbios
(smb stuff over tcp iirc)
(file and printer sharing at the most basic level!)
mike-burnsAccording to /etc/services it's: microsoft-ds 445/tcp [09:59]
cedwardsmy firewall keeps blocking 445 connections from
must be that internet radiation RandalSchwartz was talking about
bob^^OrgName: Colo4Dallas LP
sounds like you've made a new virus-infected friend :)
cedwardsyay me [10:08]
***toddf has quit IRC (Ping timeout: 276 seconds) [10:09]
toddf has joined #arpnetworks
ChanServ sets mode: +o toddf
finkcedwards: yea mine too [10:23]
cedwardsI just installed 8.0 on:
hw.model: Intel(R) Xeon(R) CPU X7350 @ 2.93GHz
hw.ncpu: 16
take that buildworld!
bob^^:D [10:31]
cedwardsmake -j16 buildworld almost seems obscene, but I'd love to see how fast it goes :) [10:31]
bob^^i think my biggest box is
hw.model: Intel(R) Xeon(R) CPU E5540 @ 2.53GHz
hw.ncpu: 16
and it's pretty damn fast :)
cedwards-jX on buildworld & buildkernel is safe, right? [10:32]
bob^^yup, should be fine
i think i did a -j16 on this, no probs
cedwardsI've seen conflicting random-internet-opinions on the matter [10:32]
bob^^yeah, i've had problems in the past
but not since 5.x releases
tbh, if it doesn't like it it normally crashes out of the build
cedwardsI'd really like there to be a setting someplace where I could hardcode the -j# [10:33]
bob^^if it builds ok, then it works fine
you can
cedwardsI've done that in Linux plenty of times, but never found any solid documentation on doing the same in FreeBSD [10:33]
finkcedwards: make.conf [10:34]
cedwardsMAKEOPTS=-j# ? [10:34]
spot on
finkbut anywya you don't want it for installkernel, right? [10:34]
cedwardsfink: right. i heard you don't want that for install{kernel,world}. [10:34]
bob^^oh, wait a second too - someone sent me a cool little script for watching the progress of a buildworld last week
i'll see if i can find it

that ^^
i think you need the port 'window' installed
cedwardsdoes it give you a progressbar or something? [10:36]
bob^^i've not tried ti yet
but some friends recommended it highly (and they are very very knowledgeable so i trust em!)
cedwardsas soon as this csup standard-supfile finishes I'll give it a spin [10:36]
bob^^just remmeber to install misc/window [10:37]
cedwardsbob^^: you know, you never hear someone say "(and they are 1337 script kiddies, so I don't trust em!)" :) [10:37]
bob^^i think, from reading the script, you get a little window showing the usual output, then a seperate couple of windows showing how long is left
hah, true :)
fellow ops in #freebsd on quakenet :)
not that that probably helps much either :D
cedwardsi know them from <insert random irc network here>! [10:38]
mike-burnsI thought `window' came with FreeBSD. [10:39]
cedwardsonly reputable people use irc, so you _know_ they are trustworthy :)
mike-burns: can't seem to find it on my box
mike-burnsThough I think I learned this when they removed it for 8.0, so.
Oh well.
cedwardsthis is the first I've heard of it [10:40]
DaCadid they also replace it with tmux? [10:41]
finkcedwards: as both an avid irc user and a fellow of ill repute, i take issue with your statement [10:41]
mike-burnsThe commit message for misc/window is "Add window(1) from the base system. This follows OpenBSD whom removed
this yesterday and we would like to follow suit."
DaCayes, OpenBSD removed it to replace it with tmux [10:41]
mike-burnsYeah. [10:42]
cedwardsfink: did I forget my sarcasm font? :) [10:43]
bob^^lol :) [10:43]
cedwardsI keep hearing about tmux over screen. should I be using tmux? [10:43]
bob^^i hear a lot of good things about tmux [10:43]
mike-burnsI tried tmux but went back to screen simply because I know the keybindings.
But tmux was nice when I tried it.
bob^^yeah, that's the only thing that stops me moving to tmux i think
after 10 years of screen, i'm kind of hard-coded to the keybindings
i guess you can change them in tmux though
DaCaguess what, they are configurable :) [10:44]
bob^^i'm lazy, wht can i say :) [10:45]
***nbari|away is now known as nbari [10:45]
nbarihi all, are there backups of the vps ?
some snapshots or something like that ?
mike-burnsThere are not. We recommend http://www.tarsnap.com/ [10:47]
bob^^tarsnap is excellent [10:47]
nbariand what happend if the master host fails ?
all data is loss ?
cedwardsI hear good things about tarsnap too. s3 storage if I'm not mistaken? [10:50]
seems to work really very well cedwards
not really using it properly in anger just yet, but so far, so good
well priced too once you get to grips with the pricing :)
nbarisorry if this is offtopic but seem to be here smart guys, any idea on how to configure multiple VPN's using the same PEER IP but diferent preshared keys ? [10:54]
cedwardsbob^^: I've been using s3 to store pictures of my kids long-term. _very_ affordable.
.15/g/mo roughly comes out to, if my math is correct, 30G before $5/mo charge.
bob^^yeah, it's good
in theory it should be pretty reliable too ;)
i'm going to use it to mirror my home server (which already has raid1 on a 3ware card)
was using rsync.net but although it's a superb service, it's a bit on the expensive side
.... (idle for 16mn)
cedwardsso I'm running this worldwatch script. not really showing a percentage or remaining value (yet?) though. [11:12]
looks like it shows % and time remaining on subsequent passes. First time has to gather data I guess. [11:25]
***nbari is now known as nbari|away [11:30]
...... (idle for 28mn)
cedwardsI must have something wrong with my ccache config. It keeps failing.
anyone else care to share their setup?
RandalSchwartzwhat is ccache? [11:58]
cedwardshttp://ccache.samba.org/ [11:58]
RandalSchwartzahh. samba
oh - compiler stuff
cedwardscompiler cache for c, c++
I've been using it on my local machines for some time, but my VPSs and a new install I just did are choking on it.
trying to figure out what has changed about my config, or what I'm missing
***aem has quit IRC (Remote host closed the connection) [12:05]
aem has joined #arpnetworks
aem has quit IRC (Client Quit)
aem has joined #arpnetworks
amdprophet has joined #arpnetworks
visinin has joined #arpnetworks
......... (idle for 43mn)
baklava has quit IRC (Ping timeout: 260 seconds) [13:03]
visinin has quit IRC (Quit: out for a bit)
baklava has joined #arpnetworks
baklava has quit IRC (Changing host)
baklava has joined #arpnetworks
..... (idle for 21mn)
cedwardsso I've been digging into ccache for the last hour. I cannot make it work on amd64 (buildworld), but it works every item on 32bit. [13:30]
......... (idle for 42mn)
***amdprophet has quit IRC (Ping timeout: 268 seconds) [14:12]
...... (idle for 27mn)
infraredi just ordered an engagement ring
dxtrinfrared: Damn
That's not a good sign
my 2nd time around
dxtrHaha, waT?
infraredyah [14:40]
dxtrI'm still at my first girlfriend whatsoever :D [14:40]
infraredwell you sound young then :P [14:40]
dxtrYeah, I'm 19. Been with her for three years [14:41]
infraredyeah you're young
i'm 32
dxtrHaha [14:41]
infraredi first got married at 22
had my daughter at 23
dxtrSo basically you've got a daughter the same age as my parents? :P
Kind of
she's 7
dxtrJust trying to make you feel old :D [14:42]
finkmath ftw [14:42]
infraredmy son is 6 [14:43]
dxtrYou even got TWO kids!? Damn. My parens are like 40 - not married :D
parents ffs
infraredinfrared sends dxtr the Typing for Dummies e-book [14:43]
..... (idle for 21mn)
finkheh [15:04]
***vtoms has quit IRC (Remote host closed the connection)
fink has quit IRC (Quit: fink)
........ (idle for 38mn)
amdprophet has joined #arpnetworks [15:42]
................. (idle for 1h24mn)
fink has joined #arpnetworks [17:06]
..... (idle for 22mn)
trapdoor has joined #arpnetworks [17:28]
............ (idle for 57mn)
trapdoor has quit IRC (Quit: Leaving) [18:25]
aem has quit IRC (Remote host closed the connection) [18:38]
st3ff4n has joined #arpnetworks [18:48]
.......................... (idle for 2h8mn)
fink has quit IRC (Read error: Connection reset by peer)
fink has joined #arpnetworks
fink has quit IRC (Client Quit)
.......... (idle for 49mn)
awyeah has quit IRC (Read error: Connection reset by peer)
awyeah has joined #arpnetworks
Guest56287 has quit IRC (Quit: ZNC - http://znc.sourceforge.net)
phlux has joined #arpnetworks
phlux is now known as Guest79362
.......................... (idle for 2h5mn)
amdprophet has quit IRC (Read error: Connection reset by peer)
amdprophet has joined #arpnetworks

