On 11/26/2016 12:42 PM, Andrew David Wong wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

A strange networking problem just started in the past day or so:

Every few hours, around 2/3 of my VMs will suddenly lose network
access. I can still ping websites from sys-net and sys-firewall,
and some VMs still have normal network access, even though all of
them are using the same sys-firewall. (Other devices on my LAN are
also fine.)

The weird part is, if I create a new, additional "sys-firewall1"
ProxyVM and switch over one of the non-working VMs to it
*without restarting* the non-working VM, network access gets
successfully restored. So, the problem must be in sys-firewall
or the AppVMs, I think.

I've tried basing sys-firewall on fedora-24 and fedora-24-minimal
with the same results. Also double-checked NetVM assignments
and firewall rules, of course.

Any ideas for logs or tools I should check to find out what's
failing, or where it's failing?

- -----------------------------------------------------------------

I can't imagine what caused this problem to suddenly start,
except maybe a dom0 or template update, so here are the packages
I've updated in dom0 recently as part of normal qubes-dom0-update:

libsndfile
sudo
bind99-libs
bind99-license
ghostscript-core
hswdata
perf
ntfs-3g
ntfsprogs
perl
perl-libs
perl-macros

And here are the packages I've updated in my fedora-24 template
(again, as normal updates):

libicu
libidn2
gnome-abrt
gnome-software
libdmapsharing
libmetalink
lz4
lz4-r131
rpm
rpm-build-libs
rpm-libs
rpm-plugin-selinux
rpm-plugin-systemd-inhibit
rpm-python
rpm-python3

Any ideas?

- -- Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org

Check out this thread: https://groups.google.com/d/msgid/qubes-users/3aa66b77-9a06-83d8-d965-6583ef10d2a9%40gmail.com

Author claims its dependent on running Qubes in a VM, but the symptoms are about the same and the trigger is a switch to fedora 24.

My own problem with fedora 24 is that the minimal template seems incapable of acting as a simple Qubes firewall. No time to troubleshoot it.

You may want to switch to debian for your service VMs... Versions 8 and 9 are working well for me.

Chris

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/a3872bce-42ed-8fef-0a0f-fec31e294ee6%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to