01:57:15 i've not heard of any recent problems.. 01:57:49 illumos had a bug briefly where it was issuing the wrong LBAs (obviously not a good thing) but that's been fixed for a while 04:01:49 [illumos-gate] 15510 Update tzdata to 2023b -- Andy Fiddaman 07:19:17 Does illumos have an equivalent of GNU excvpe ? 07:19:43 execvpe 08:42:32 paulf no, but there is a WIP change to add it at https://code.illumos.org/c/illumos-gate/+/2066 08:42:33 → CODE REVIEW 2066: 7125 Provide execvpe (NEW) | https://www.illumos.org/issues/7125 17:38:32 tzdata 2023c is likely to come out soon (Lebanon again). 17:39:17 Do they have a ETA on d? 17:43:09 17:43:35 Good thing this is early in the SmartOS release cycle (plus a Lebanon update *hopefully* wont' require manifest changes). 18:27:36 hi! 18:27:42 thanks for illumos! 18:28:16 I have a single IP and want to run an ftp server in a zone.  I need to use NAT. 18:28:30 the "rdr" directive in the man page has something that looks like 18:28:36 "port" port range port 18:28:41 what exactly does that mean 18:29:15 rdr e1000g0 from any to 144.76.69.252 port 65001-65100 -> 10.0.5.81 18:29:29 rdr e1000g0 from any to 144.76.69.252 port 65001:65100 -> 10.0.581 18:29:36 rdr e1000g0 from any to 144.76.69.252 port 65001 range 65100 -> 10.0.5.81 18:29:44 rdr e1000g0 from any to 144.76.69.252 port 65001 ... 65100 -> 10.0.5.81 18:30:00 don't work ... can anyone tell me what I should type? 18:46:14 hello hightower2, you're new here 18:46:38 do you know anything about ipnat.conf?  -- I need to redirect a block of ports 18:46:46 alternatively, do you need help? 18:47:02 I know everything, except, of course, for the things I don't know 18:50:31 os10000: according to the manpage you should be using the ':' in your port range. 18:50:38 "man ipnat.conf" 18:51:09 thanks, I'll try again 18:51:33 [6:28:36 PM] "port" port range port 18:51:33 [6:28:41 PM] what exactly does that mean 18:51:38 syntax error error at ":", line 16 18:52:07 000011  #       cmd-masq-service 18:52:08 000012          rdr e1000g0 from any to 144.76.69.252 port = 80 -> 10.0.17.217 port 80 tcp 18:52:08 000013          rdr e1000g0 from any to 144.76.69.252 port = 443 -> 10.0.17.217 port 443 tcp 18:52:09 000014          rdr e1000g0 from any to 144.76.69.252 port = 1194 -> 10.0.9.243 port 1194 tcp 18:52:09 000015          rdr e1000g0 from any to 144.76.69.252 port = 21 -> 10.0.5.81 port 21 tcp 18:52:10 000016          rdr e1000g0 from any to 144.76.69.252 port 65001:65100 -> 10.0.5.81 18:52:10 000017          rdr e1000g0 from any to 144.76.69.252 port = 2022 -> 10.0.5.81 port 22 tcp 18:52:11 000018  # 18:52:19 maybe rdr does not allow ranges 18:52:23 I'll read the man page again 18:53:16 redir ::= "rdr" ifname rlhs "->" ip [ "," ip ] rdrport rdroptions . 18:53:19 yeah, I don't see an example of a rdr with a port range in the man page. I don't know. 18:53:34 the rlhs could be 18:53:41 rlhs ::= ipmask dport | fromto . 18:53:42 a fromto 18:53:51 fromto ::= "from" object "to" object . 18:54:09 oh.... yeah, that might use a hyphen?! 18:54:17 I have "from any to ***" 18:54:23 the *** is an object 18:54:33 object :: = addr [ port-comp | port-range ] . 18:54:46 I would need an address, which I have ... 18:54:59 followed by a "port-range" 18:55:07 port-range :: = "port" port-num range port-num . 18:55:12 now that is the thing which puzzles me 18:55:20 rdr e1000g0 from any to 144.76.69.252 port 65001:65100 -> 10.0.5.81 18:55:29 I start on "port" alright 18:55:39 I have a number following it (65001) 18:55:52 then comes the >>>>range<<<<< whatever that is 18:56:00 followed by another port number 18:56:06 I think I was wrong. I think it's a hyphen, not a colon. 18:56:47 rdr e1000g0 from any to 144.76.69.252/32 port = www -> 10.0.17.217 port 80 tcp 18:56:48 rdr e1000g0 from any to 144.76.69.252/32 port = https -> 10.0.17.217 port 443 tcp 18:56:48 rdr e1000g0 from any to 144.76.69.252/32 port = openvpn -> 10.0.9.243 port 1194 tcp 18:56:49 rdr e1000g0 from any to 144.76.69.252/32 port = ftp -> 10.0.5.81 port 21 tcp 18:56:49 syntax error error at "-", line 16 18:56:59 000014          rdr e1000g0 from any to 144.76.69.252 port = 1194 -> 10.0.9.243 port 1194 tcp 18:57:00 000015          rdr e1000g0 from any to 144.76.69.252 port = 21 -> 10.0.5.81 port 21 tcp 18:57:00 000016          rdr e1000g0 from any to 144.76.69.252 port 65001-65100 -> 10.0.5.81 18:57:01 000017          rdr e1000g0 from any to 144.76.69.252 port = 2022 -> 10.0.5.81 port 22 tcp 18:57:01 000018  # 18:57:04 stop pasting the lines that work. 18:57:09 sorry 18:57:44 let me see if I have a zone I can use to test this. 18:57:52 oh thanks! 19:09:04 The grammar in the man page is slightly broken. There's no definition for "portnum" but it gets used... 19:09:19 ok ... 19:10:34 when I logged onto this IRC channel, I got a message where to find the illumos source code 19:10:48 https://github.com/illumos/illumos-gate/blob/master/usr/src/cmd/ipf/examples/ftp-proxy 19:11:02 I thought I could look at the BNF grammar, but found a bunch of examples first 19:11:12 maybe I can do without forwarding a range entirely 19:11:54 but I have another 12 hosts to do and I fear I will need a portrange before I'm done with all of them.  FTP might not be my only problem that needs a range 19:11:58 that's probably only going to grab the single port from /etc/services if I had to guess. 19:12:13 there's a builtin proxy 19:12:35 and ... it would be nice to understand what I'm doing ... when it's security relevant 19:12:55 I mean... you're using regular FTP... 19:12:57 clearly I'm not understanding something correctly 19:13:20 ok, that's an oxymoron ... using "ftp" and "security" in the same sentence 19:13:52 I'm trying to confine that thing to a zone without other services 19:14:22 oh, there is a "ftp proxy" in there... hmmm. 19:15:12 but it's a map rather than a redir. 19:15:33 I've been nerd-sniped into complete confusion now. 19:15:33 I couldn't get it to work, so I tried mapping 21 + a range 19:16:17 the proftpd allows itself to be restricted to a range and it has a masquerade command if I were to get the range to work 19:16:30 currently the proftpd is configured as a standard ftp server 19:16:43 from the parent zone it can be reached and used just fine 19:16:46 I have to tap out. I need to get back to work and I'm not any closer to helping you solve this. 19:16:55 many thanks for your time 19:16:57 have a good day 19:51:52 nahamu: The FTP proxy is, I believe, for users _inside_ a cone NAT that are trying to use "active" FTP instead of passive FTP (which is what everybody should use now) 19:51:58 where the FTP server is expected to connect _back_ to you 19:57:12 that sounds right 19:57:19 I suspect active ftp is a thing few people remember really these days 20:04:16 * nomad hides the sftp server he's required to maintain for $job[1] 20:04:41 sftp != ftp. 20:05:03 and especially != active ftp 20:05:04 yeah, but still.... 20:05:17 * nomad isn't thrilled to have any kind of FTP thing 20:06:20 SFTP is basically fine 20:06:31 it's just SSH 20:23:21 jclulow, as long as you don't mind account management for $random_contact.