FreeBSD console weirdness when booting from usb stick

2009-12-05 Thread Sebastiaan van Erk

Hi,

I'm booting FreeBSD 8 from an USB stick, but when I do so, the console 
no longer works. They USB keyboard seems to do nothing, and during the 
boot process when the daemons are starting it seems like there is 
another keyboard attached on which the ENTER key is stuck. That is, 
while the daemons are starting the texts like Starting sshd... are 
interspaced with a bunch of blank lines, and after that, the screen 
fills with repeated copies of the login prompt. I cannot type anything. 
When I add or remove my keyboard it shows on the console as a bright 
white log line, which immediately scrolls off the screen again. Same 
when I remove it again.


When I boot from the hard disks, this does not happen. The USB stick 
contains exactly the same stuff as the hard drives, since I cloned the 
hard drive with a dump/restore.


Does anybody have a clue what's going on?

Regards,
Sebastiaan
Copyright (c) 1992-2009 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 8.0-RELEASE #1: Sat Nov 28 10:07:51 CET 2009
r...@piglet.home.sebster.com:/usr/obj/usr/src/sys/PIGLET
Timecounter i8254 frequency 1193182 Hz quality 0
CPU: Genuine Intel(R) CPU N270   @ 1.60GHz (1596.01-MHz 686-class CPU)
  Origin = GenuineIntel  Id = 0x106c2  Stepping = 2
  
Features=0xbfe9fbffFPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE
  Features2=0x40c39dSSE3,DTES64,MON,DS_CPL,EST,TM2,SSSE3,xTPR,PDCM,b22
  AMD Features=0x10NX
  AMD Features2=0x1LAHF
  TSC: P-state invariant
real memory  = 2147483648 (2048 MB)
avail memory = 2080657408 (1984 MB)
MPTable: IntelCalistoga   
WARNING: Non-uniform processors.
WARNING: Using suboptimal topology.
ioapic0: Assuming intbase of 0
ioapic0 Version 2.0 irqs 0-23 on motherboard
kbd1 at kbdmux0
pcib0: MPTable Host-PCI bridge pcibus 0 on motherboard
pci0: PCI bus on pcib0
vgapci0: VGA-compatible display port 0xbc80-0xbc87 mem 
0xfe88-0xfe8f,0xd000-0xdfff,0xfe84-0xfe87 irq 16 at 
device 2.0 on pci0
agp0: Intel 945GME SVGA controller on vgapci0
agp0: detected 7932k stolen memory
agp0: aperture size is 256M
vgapci1: VGA-compatible display mem 0xfe78-0xfe7f at device 2.1 on 
pci0
pci0: multimedia, HDA at device 27.0 (no driver attached)
pcib1: MPTable PCI-PCI bridge irq 16 at device 28.0 on pci0
pci1: PCI bus on pcib1
em0: Intel(R) PRO/1000 Network Connection 6.9.14 port 0xcc80-0xcc9f mem 
0xfe9e-0xfe9f,0xfe9dc000-0xfe9d irq 16 at device 0.0 on pci1
em0: Using MSIX interrupts
em0: [ITHREAD]
em0: [ITHREAD]
em0: [ITHREAD]
em0: Ethernet address: 40:61:86:4a:c2:75
pcib2: MPTable PCI-PCI bridge irq 17 at device 28.1 on pci0
pci2: PCI bus on pcib2
em1: Intel(R) PRO/1000 Network Connection 6.9.14 port 0xdc80-0xdc9f mem 
0xfeae-0xfeaf,0xfeadc000-0xfead irq 17 at device 0.0 on pci2
em1: Using MSIX interrupts
em1: [ITHREAD]
em1: [ITHREAD]
em1: [ITHREAD]
em1: Ethernet address: 40:61:86:4a:c2:76
uhci0: Intel 82801G (ICH7) USB controller USB-A port 0xbc00-0xbc1f irq 23 at 
device 29.0 on pci0
uhci0: [ITHREAD]
uhci0: LegSup = 0x0f30
usbus0: Intel 82801G (ICH7) USB controller USB-A on uhci0
uhci1: Intel 82801G (ICH7) USB controller USB-B port 0xb880-0xb89f irq 19 at 
device 29.1 on pci0
uhci1: [ITHREAD]
uhci1: LegSup = 0x0f30
usbus1: Intel 82801G (ICH7) USB controller USB-B on uhci1
uhci2: Intel 82801G (ICH7) USB controller USB-C port 0xb800-0xb81f irq 18 at 
device 29.2 on pci0
uhci2: [ITHREAD]
uhci2: LegSup = 0x0f30
usbus2: Intel 82801G (ICH7) USB controller USB-C on uhci2
uhci3: Intel 82801G (ICH7) USB controller USB-D port 0xb480-0xb49f irq 16 at 
device 29.3 on pci0
uhci3: [ITHREAD]
uhci3: LegSup = 0x0f30
usbus3: Intel 82801G (ICH7) USB controller USB-D on uhci3
ehci0: Intel 82801GB/R (ICH7) USB 2.0 controller mem 0xfe837c00-0xfe837fff 
irq 23 at device 29.7 on pci0
ehci0: [ITHREAD]
usbus4: waiting for BIOS to give up control
usbus4: EHCI version 1.0
usbus4: Intel 82801GB/R (ICH7) USB 2.0 controller on ehci0
pcib3: MPTable PCI-PCI bridge at device 30.0 on pci0
pci3: PCI bus on pcib3
rl0: RealTek 8139 10/100BaseTX port 0xec00-0xecff mem 0xfebffc00-0xfebffcff 
irq 16 at device 0.0 on pci3
miibus0: MII bus on rl0
rlphy0: RealTek internal media interface PHY 0 on miibus0
rlphy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
rl0: Ethernet address: 00:50:fc:44:23:0e
rl0: [ITHREAD]
isab0: PCI-ISA bridge at device 31.0 on pci0
isa0: ISA bus on isab0
atapci0: Intel ICH7M SATA150 controller port 
0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xffa0-0xffaf at device 31.2 on pci0
ata0: ATA channel 0 on atapci0
ata0: [ITHREAD]
ata1: ATA channel 1 on atapci0
ata1: [ITHREAD]
pci0: serial bus, SMBus at device 31.3 (no driver attached)
cpu0 on motherboard
est0: Enhanced SpeedStep Frequency Control on cpu0
est: CPU supports 

FreeBSD as USB joystick

2009-05-22 Thread Sebastiaan van Erk

Hi,

I'm wondering if I can turn my FreeBSD into a (very expensive ;-)) joystick.

That is, I have a PS2 and want to be able to control it via my laptop. 
This would amount to connecting a USB cable between my PS2 and my 
laptop, and getting the PS2 to detect it as a joystick with the right 
identifier string, and being able to send button presses etc via my 
laptop to the PS2.


Does anybody have any starting points as to how I can achieve this?

Regards,
Sebastiaan

P.S.: For those of you who must know, I want to interface my electronic 
drum module (Roland TD-9KS) with the Rockband game. The idea is to use a 
cheap midi card and convert the incoming notes into joystick button 
presses :)


smime.p7s
Description: S/MIME Cryptographic Signature


Re: FreeBSD as USB joystick

2009-05-22 Thread Sebastiaan van Erk

Hi,

Wojciech Puchar wrote:


That is, I have a PS2 and want to be able to control it via my laptop. 
This would amount to connecting a USB cable between my PS2 and my 
laptop, and getting the PS2 to detect it as a joystick with the right 
identifier string, and being able to send button presses etc via my 
laptop to the PS2.


PC USB controllers has only host mode, not device mode, so the answer is 
no.


Ok, that's a clear answer. Are there any alternatives? For example a PCI 
expansion card that does USB device mode and is programmable? Might be 
difficult to get working under FreeBSD though maybe?


Regards,
Sebastiaan


smime.p7s
Description: S/MIME Cryptographic Signature


Re: CARP bridge

2009-05-01 Thread Sebastiaan van Erk

Hi,

Nikos Vassiliadis wrote:

Sebastiaan van Erk wrote:


Thanks for the suggestion. I tried it, but unfortunately the carp 
device never leaves the INIT state when I put the ip on the bridge. 
:-( I did find some similar problem here:


http://www.freebsd.org/cgi/query-pr.cgi?pr=125816


I just noticed that. On -CURRENT carp tells you that's
not supported:
bridge0: carp is not supported for this interface type

OTOH why do you even have to use the VIP from the remote
side of the bridge?

The only reason I can think of, for doing  such a thing,
is to get *all* traffic from the remote location through
a single redundant router, the one with the VIP. Is this
the case?


It is indeed a single redundant router, though the traffic from the 
other side of the bridge (the OpenVPN clients) generally don't need to 
be routed redudantantly. The OpenVPN clients use OpenVPN's redundancy 
(multiple remote xxx.xxx.xxx.xxx lines), and thus use the 
non-redundant IP address of the OpenVPN client they're connected to as 
gateway (which is fine, because if the server dies OpenVPN connects to a 
different server anyway)...


So I don't really *NEED* the CARP ip address over the bridge (the static 
arp works, so I have a working solution, albeit an ugly one; an ARP 
request generates a reply from every member of the redundant cluster).


I guess it's just not a supported configuration yet and it's not my 
stupidity (in this case anyway ;-)) that's the problem.



Nikos


Regards,
Sebastiaan


smime.p7s
Description: S/MIME Cryptographic Signature


CARP bridge

2009-04-29 Thread Sebastiaan van Erk

Hi,

I have a bridged OpenVPN setup where the OpenVPN tap0 driver is bridged 
(via bridge0) to the physical em1 interface, which has a VIP via a carp1 
interface:


em1: flags=8943UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST metric 0 
mtu 1500

options=98VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM
ether 00:0c:29:61:2a:55
inet 10.0.80.77 netmask 0xff00 broadcast 10.0.80.255
media: Ethernet autoselect (1000baseTX full-duplex)
status: active
bridge0: flags=8843UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST metric 0 mtu 
1500

ether 9a:6a:9f:b2:65:da
id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
maxage 20 holdcnt 6 proto rstp maxaddr 100 timeout 1200
root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
member: tap0 flags=143LEARNING,DISCOVER,AUTOEDGE,AUTOPTP
ifmaxaddr 0 port 11 priority 128 path cost 200
member: em1 flags=143LEARNING,DISCOVER,AUTOEDGE,AUTOPTP
ifmaxaddr 0 port 2 priority 128 path cost 2
tap0: flags=8943UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST metric 
0 mtu 1500

ether 00:bd:48:03:00:00
Opened by PID 24616
carp1: flags=49UP,LOOPBACK,RUNNING metric 0 mtu 1500
inet 10.0.80.74 netmask 0xff00
carp: MASTER vhid 2 advbase 1 advskew 0


The problem I have is that when I ping the VIP from a VPN client (on 
tap0), the server receives arp requests for the VIP on tap0, but it does 
not respond to them:


# tcpdump -i tap0 -ln
11:29:13.637048 arp who-has 10.0.80.74 tell 10.0.80.6

Is there any way to get the server to respond to arp requests on tap0 
for the VIP?


This is all on FreeBSD 7.1 with OpenVPN 2.0.6 (both client and server).

Regards,
Sebastiaan



smime.p7s
Description: S/MIME Cryptographic Signature


Re: CARP bridge

2009-04-29 Thread Sebastiaan van Erk

Hi,

Julien Cigar wrote:

On Wed, 2009-04-29 at 11:37 +0200, Sebastiaan van Erk wrote:

Hi,

I have a bridged OpenVPN setup where the OpenVPN tap0 driver is bridged 
(via bridge0) to the physical em1 interface, which has a VIP via a carp1 
interface:


em1: flags=8943UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST metric 0 
mtu 1500

options=98VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM
ether 00:0c:29:61:2a:55
inet 10.0.80.77 netmask 0xff00 broadcast 10.0.80.255
media: Ethernet autoselect (1000baseTX full-duplex)
status: active
bridge0: flags=8843UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST metric 0 mtu 
1500

ether 9a:6a:9f:b2:65:da
id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
maxage 20 holdcnt 6 proto rstp maxaddr 100 timeout 1200
root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
member: tap0 flags=143LEARNING,DISCOVER,AUTOEDGE,AUTOPTP
ifmaxaddr 0 port 11 priority 128 path cost 200
member: em1 flags=143LEARNING,DISCOVER,AUTOEDGE,AUTOPTP
ifmaxaddr 0 port 2 priority 128 path cost 2
tap0: flags=8943UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST metric 
0 mtu 1500

ether 00:bd:48:03:00:00
Opened by PID 24616
carp1: flags=49UP,LOOPBACK,RUNNING metric 0 mtu 1500
inet 10.0.80.74 netmask 0xff00
carp: MASTER vhid 2 advbase 1 advskew 0


The problem I have is that when I ping the VIP from a VPN client (on 
tap0), the server receives arp requests for the VIP on tap0, but it does 
not respond to them:


# tcpdump -i tap0 -ln
11:29:13.637048 arp who-has 10.0.80.74 tell 10.0.80.6

Is there any way to get the server to respond to arp requests on tap0 
for the VIP?




Maybe you've to do ARP Proxy on one side ? Try to add an ARP entry in
the ARP table with arp (arp -s 1.2.3.4 MAC foo) ..


Thanks for the suggestion.

Ok, static arp works: that is, if I take the carp1 mac address and add 
it to the arp table using:


 arp -s 10.0.80.74 00:00:5e:00:01:02 pub

The ping starts to work. I'm still a bit confused why I have to do this 
though, because I can ping the non-shared IP 10.0.80.77 from the VPN 
client (via tap0) without any static arp, and I can ping the shared VIP 
(10.0.80.74) from clients on the physical network (em1) as well without 
any static arp. It's only when the ping it has to cross the bridge that 
it's an issue.


Regards,
Sebastiaan



smime.p7s
Description: S/MIME Cryptographic Signature


Re: CARP bridge

2009-04-29 Thread Sebastiaan van Erk

Hi,

Nikos Vassiliadis wrote:

Sebastiaan van Erk wrote:

Julien Cigar wrote:


Maybe you've to do ARP Proxy on one side ? Try to add an ARP entry in
the ARP table with arp (arp -s 1.2.3.4 MAC foo) ..


Thanks for the suggestion.

Ok, static arp works: that is, if I take the carp1 mac address and add 
it to the arp table using:


 arp -s 10.0.80.74 00:00:5e:00:01:02 pub

The ping starts to work. I'm still a bit confused why I have to do 
this though, because I can ping the non-shared IP 10.0.80.77 from the 
VPN client (via tap0) without any static arp, and I can ping the 
shared VIP (10.0.80.74) from clients on the physical network (em1) as 
well without any static arp. It's only when the ping it has to cross 
the bridge that it's an issue.


Does it make any difference if you set the IP address on the bridge0
iface and not on the physical one?

I recall that the recommended setup is to use IP addresses on
the bridge interface and leave the members of the bridge IPless.

Nikos


Thanks for the suggestion. I tried it, but unfortunately the carp device 
never leaves the INIT state when I put the ip on the bridge. :-( I did 
find some similar problem here:


http://www.freebsd.org/cgi/query-pr.cgi?pr=125816

Regards,
Sebastiaan


smime.p7s
Description: S/MIME Cryptographic Signature


esxi and freebsd vlans

2009-04-20 Thread Sebastiaan van Erk

Hi,

I ran into the ESXi limit of 4 NICs per VM, so I figured I would work 
around this using FreeBSD's vlan devices.


I made 2 test installs with the following interface configuration:

test1:
ifconfig em0 inet 10.10.10.1 netmask 255.255.255.0
ifconfig vlan create
ifconfig vlan0 inet 192.168.1.1 netmask 255.255.255.0 vlan 22 vlandev em0

test2:
ifconfig em0 inet 10.10.10.2 netmask 255.255.255.0
ifconfig vlan create
ifconfig vlan0 inet 192.168.1.2 netmask 255.255.255.0 vlan 22 vlandev em0

I can ping the other machine using the 10.10.10.x IP address no problem, 
but the 192.168.1.x addresses don't work. I've tried setting the vlan id 
on the vSwitch to none and to 22, but in neither of the two cases does 
it work.


Does anybody have FreeBSD vlan's working on ESXi or know how to get it 
working?


Many thanks,
Sebastiaan van Erk


smime.p7s
Description: S/MIME Cryptographic Signature


Re: esxi and freebsd vlans

2009-04-20 Thread Sebastiaan van Erk

Hi,

Thanks for your response! :-)

Michael K. Smith - Adhost wrote:

Hello Sebastian:


Hi,

I ran into the ESXi limit of 4 NICs per VM, so I figured I would work 
around this using FreeBSD's vlan devices.


I made 2 test installs with the following interface configuration:

test1:
ifconfig em0 inet 10.10.10.1 netmask 255.255.255.0
ifconfig vlan create
ifconfig vlan0 inet 192.168.1.1 netmask 255.255.255.0 vlan 22 vlandev
em0

test2:
ifconfig em0 inet 10.10.10.2 netmask 255.255.255.0
ifconfig vlan create
ifconfig vlan0 inet 192.168.1.2 netmask 255.255.255.0 vlan 22 vlandev
em0

I can ping the other machine using the 10.10.10.x IP address no problem,

but the 192.168.1.x addresses don't work. I've tried setting the vlan id

on the vSwitch to none and to 22, but in neither of the two cases does 
it work.



[Michael K. Smith - Adhost] 


You will need to make sure the switchport facing your server is set to
802.1Q trunk and has VLAN 22 allowed.  The IP address on em0 itself is
untagged so it will work regardless of the port settings on the
switch. VLAN 22 has the 4-byte header attached so the other side has to
recognize the tag.


Just to clarify, both VM's are on a single ESXi server on a virtual 
switch, so no network hardware is involved. It is possible to configure 
the virtual switch to be on no vlan and on a specific vlan, but in both 
cases it didn't work. I'll see if I there are more settings I can change 
on the virtual switch.



Regards,

Mike


Regards,
Sebastiaan


smime.p7s
Description: S/MIME Cryptographic Signature


Re: esxi and freebsd vlans

2009-04-20 Thread Sebastiaan van Erk

Hi,

Michael K. Smith - Adhost wrote:

Hello Sebastian:


Hi,

I ran into the ESXi limit of 4 NICs per VM, so I figured I would work 
around this using FreeBSD's vlan devices.


I made 2 test installs with the following interface configuration:

test1:
ifconfig em0 inet 10.10.10.1 netmask 255.255.255.0
ifconfig vlan create
ifconfig vlan0 inet 192.168.1.1 netmask 255.255.255.0 vlan 22 vlandev
em0

test2:
ifconfig em0 inet 10.10.10.2 netmask 255.255.255.0
ifconfig vlan create
ifconfig vlan0 inet 192.168.1.2 netmask 255.255.255.0 vlan 22 vlandev
em0

I can ping the other machine using the 10.10.10.x IP address no problem,

but the 192.168.1.x addresses don't work. I've tried setting the vlan id

on the vSwitch to none and to 22, but in neither of the two cases does 
it work.



[Michael K. Smith - Adhost] 


You will need to make sure the switchport facing your server is set to
802.1Q trunk and has VLAN 22 allowed.  The IP address on em0 itself is
untagged so it will work regardless of the port settings on the
switch. VLAN 22 has the 4-byte header attached so the other side has to
recognize the tag.


Your reply inspired me to google 802.1Q and ESXi, and I found a document 
describing different VLAN solutions on ESXi 
(http://www.vmware.com/pdf/esx3_vlan_wp.pdf). In this document it says 
that to make guest tagging work I have to set the VLAN ID of the port 
group on the virtual switch to 4095. After I did this, the above 
configuration works.



Regards,

Mike


Regards,
Sebastiaan


smime.p7s
Description: S/MIME Cryptographic Signature


Re: Problem setting up PPTP server

2006-11-10 Thread Sebastiaan van Erk

Hi,

I solved the problem, and I'll post the resolution for reference 
purposes. There were two configuration issues:


1) To enable MPPE encryption the encryption option on the bundle should 
be DISABLED, since MPPE lives in the compression layer and not the 
encryption layer; thus by commenting the set bundle enable encryption 
and set bundle enable crypt-reqd lines, this problem was solved.


2) Since the client (a linux ppp client) had the option 
require-mppe-128 enabled, the server got a config request for 128 bit 
MPPE stateless, but then rejected it. The reason for this was the set 
ccp enable mppc line, which should have read set ccp yes mppc since 
otherwise the accept flag is disabled.


Finally, I have not found a way to force MPPE encryption on the *server* 
side. There seems to be no equivalent to require-mppe-128 or set 
bundle enable comp-reqd or something like that in mpd. Does anybody 
know a way to require MPPE in mpd?


Regards,
Sebastiaan

Sebastiaan van Erk wrote:

Hi,

I'm trying to set up mpd (3.18) on a FreeBSD server to allow windows and
linux clients to connect. Currently I've only been trying to make the
linux connection succeed (Ubuntu with ppp-2.4.4), but I get the
following output from linux pppd:

CHAP authentication succeeded
sent [CCP ConfReq id=0x1 mppe +H -M +S -L -D -C]
rcvd [IPCP ConfReq id=0x1 addr 10.0.0.1 compress VJ 0f 00]
sent [IPCP TermAck id=0x1]
rcvd [CCP ConfReq id=0x1 mppe +H -M +S -L -D -C]
sent [CCP ConfAck id=0x1 mppe +H -M +S -L -D -C]
rcvd [CCP ConfRej id=0x1 mppe +H -M +S -L -D -C]
MPPE required but peer refused
sent [LCP TermReq id=0x2 MPPE required but peer refused]
rcvd [LCP TermAck id=0x4]
Connection terminated.

I don't understand why the linux client sends a TermAck on IPCP without
getting a TermReq first, but apart from that mpd seems to be failing to
negotiate MPPE even though I configured both the linux client and mpd to
allow ONLY mppe-128, i.e., in my mpd.conf I have the following:

   # Microsoft Point to Point Encryption
   set bundle enable compression
   set ccp enable mppc
   set ccp enable mpp-e128
   set ccp yes mpp-stateless
   set ccp no mpp-e40

The linux client is requesting exactly that: MPPE 128 bit stateless as
can been seen from the mpd log:

[pptp0] CCP: rec'd Configure Request #1 link 0 (Req-Sent)
  MPPC
0x0140: MPPE, 128 bit, stateless

Am I doing something obviously wrong? Does anybody know how to fix this
problem? Any advice is welcome!

Thanks in advance,
Sebastiaan

P.S.: I have attached the mpd.conf, mpd.links, mpd.log and ppp.log files
for completeness.




startup:
  
default:

  load client0

client0:
  new -i ng0 pptp0 pptp
  set ipcp ranges 10.0.0.1/32 10.0.0.128/32
  load pptp_common

pptp_common:
  set iface disable on-demand
  set iface enable proxy-arp
  set iface idle 0
  set iface enable tcpmssfix
  set link yes acfcomp protocomp
  set link disable pap
  set link enable chap
  set link no chap-md5
  set link mtu 1460
  set link keep-alive 10 60
  set ipcp dns 192.168.1.10 192.168.1.1
  set ipcp nbns 10.0.0.1

  # Microsoft Point to Point Encryption
  set bundle enable compression
  set ccp enable mppc
  set ccp enable mpp-e128
  set ccp yes mpp-stateless
  set ccp no mpp-e40

  # Require encryption or drop connection
  set bundle enable encryption
  set bundle enable crypt-reqd


  



pptp:
set link type pptp
set pptp self 192.168.1.10
set pptp enable incoming
set pptp disable originate


  



___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to [EMAIL PROTECTED]

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to [EMAIL PROTECTED]


Problem setting up PPTP server

2006-11-09 Thread Sebastiaan van Erk

Hi,

I'm trying to set up mpd (3.18) on a FreeBSD server to allow windows and
linux clients to connect. Currently I've only been trying to make the
linux connection succeed (Ubuntu with ppp-2.4.4), but I get the
following output from linux pppd:

CHAP authentication succeeded
sent [CCP ConfReq id=0x1 mppe +H -M +S -L -D -C]
rcvd [IPCP ConfReq id=0x1 addr 10.0.0.1 compress VJ 0f 00]
sent [IPCP TermAck id=0x1]
rcvd [CCP ConfReq id=0x1 mppe +H -M +S -L -D -C]
sent [CCP ConfAck id=0x1 mppe +H -M +S -L -D -C]
rcvd [CCP ConfRej id=0x1 mppe +H -M +S -L -D -C]
MPPE required but peer refused
sent [LCP TermReq id=0x2 MPPE required but peer refused]
rcvd [LCP TermAck id=0x4]
Connection terminated.

I don't understand why the linux client sends a TermAck on IPCP without
getting a TermReq first, but apart from that mpd seems to be failing to
negotiate MPPE even though I configured both the linux client and mpd to
allow ONLY mppe-128, i.e., in my mpd.conf I have the following:

   # Microsoft Point to Point Encryption
   set bundle enable compression
   set ccp enable mppc
   set ccp enable mpp-e128
   set ccp yes mpp-stateless
   set ccp no mpp-e40

The linux client is requesting exactly that: MPPE 128 bit stateless as
can been seen from the mpd log:

[pptp0] CCP: rec'd Configure Request #1 link 0 (Req-Sent)
  MPPC
0x0140: MPPE, 128 bit, stateless

Am I doing something obviously wrong? Does anybody know how to fix this
problem? Any advice is welcome!

Thanks in advance,
Sebastiaan

P.S.: I have attached the mpd.conf, mpd.links, mpd.log and ppp.log files
for completeness.


startup:
  
default:
  load client0

client0:
  new -i ng0 pptp0 pptp
  set ipcp ranges 10.0.0.1/32 10.0.0.128/32
  load pptp_common

pptp_common:
  set iface disable on-demand
  set iface enable proxy-arp
  set iface idle 0
  set iface enable tcpmssfix
  set link yes acfcomp protocomp
  set link disable pap
  set link enable chap
  set link no chap-md5
  set link mtu 1460
  set link keep-alive 10 60
  set ipcp dns 192.168.1.10 192.168.1.1
  set ipcp nbns 10.0.0.1

  # Microsoft Point to Point Encryption
  set bundle enable compression
  set ccp enable mppc
  set ccp enable mpp-e128
  set ccp yes mpp-stateless
  set ccp no mpp-e40

  # Require encryption or drop connection
  set bundle enable encryption
  set bundle enable crypt-reqd


pptp:
set link type pptp
set pptp self 192.168.1.10
set pptp enable incoming
set pptp disable originate


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to [EMAIL PROTECTED]

Re: XFree86, Anti-aliasing, Truetype, Freetype

2002-11-05 Thread erk!
On Tue, 5 Nov 2002 06:29:17 -0800 (PST)
Scott I. Remick [EMAIL PROTECTED] wrote:

 Yes... I have tried choosing one of the TTF fonts that only appeared
 once I added the Fontpath line in XF86Config which pointed to the TTF
 folder. I have done this in both OO and Moz. In Moz I can see the font
 visibly change to a non-AA version of it. In OO it is AA but the
 quality of the AA job is poor.

For all your fonts to appear, you will need to add the directories to
XF86Config.  I.E.

FontPath /usr/X11R6/lib/X11/fonts/TTF

 Please excuse my ignorance here, but are Moz or OO gtk apps?

I couldn't tell you about OO, but for mozilla (and it's little brother,
phoenix), it uses gtk for font handling.  once you get all the font
paths added to XF86Config, install gdkxft, and as root, you should just
need to run 'gdkxft_sysinstall'.
there are a few options/modifiers for it, as well, so you might check
out it's manpage once it's installed.
 
 What's the significance of the fact that TT fonts don't appear when I
 have the line in XftConfig but not XF86Config like the handbook says I
 should do? Is this the sign of a problem which is playing a role here?

Well, the predominant problem is that for *any* fonts to be useable in
x-windows, the fontpath for each must exist in XF86Config.  You
shouldn't need to edit XftConfig by hand at all, from my experience. 
Gdkxft creates/edits an XftConfig file for you, anyway, so any changes
you've made prior to configuring it, would likely be overwritten.

On my current system, i've even got shadowed TTF fonts on my terminals
(which looks quite nice, i might add!).  Try out the stuff I mentioned,
and if it doesn't work, toss my an email and i'll try to get you up and
running  a bit more.  So far, it basically sounds like you've got
anti-aliasing for most regular apps working OK, but not gtk apps.  Like
I said, OO is just kinda wonky with font handling (imo).  You might try
installing a small port that doesn't use gtk to see if you notice any
noticeable changes between the three.  

- erk

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: XFree86, Anti-aliasing, Truetype, Freetype

2002-11-04 Thread erk!
On Mon, 4 Nov 2002 14:07:43 -0800 (PST)
Scott I. Remick [EMAIL PROTECTED] wrote:

 I'm close but not quite there yet, so I need some more help...
 
 FreeBSD 4.7-REL, Xfree86 4.2.0, Enlightenment 0.16.5, OpenOffice
 1.0.1, recent Mozilla nightly, Freetype 1.3.1, Freetype2 2.1.2
 
 I have Truetype fonts working, and they're even anti-aliased in OO,
 but they look like crap (certainly not like on a Windoze system).

a few more specifics here *might* be somewhat helpful.  you mention
mozilla, so are you getting not-so-purdy fonts just in mozilla, just in
gtk apps, just in openoffice, or all-around?  are you actually selecting
the truetype fonts
to be used on said apps?  this is relatively important, because while
you may be using truetype fonts, anti-aliasing may not actually be
working for you.  for instance, to have anti-aliased fonts with gtk12
ports, you need to install and configure gdkxft.

concerning openoffice, though, it doesn't handle microsoft-based fonts
very well, from what i've noticed, even on windows systems.  it seems to
me that this is a problem with openoffice (at least when dealing with
the .doc format voodoo), not your configuration.  lemme guess..odd
craggy bits here and there, and badly spaced type (i.e. the letters on
some words look disjointed, sometimes letters look crammed too close to
one another, sometimes too far apart?)  this was my experience with
openoffice under x-windows and ms windows.  same thing for staroffice.

also, if this extends to mozilla, there have been some recent
discussions regarding messed up fonts.  you might take a look back in
the recent mailing list archives.  

- erk, who tossed out *office, and went with abiword.  all is good once
again.

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: Window/File Manager

2002-11-03 Thread erk!
On 03 Nov 2002 21:55:37 -0600
Ryan Sommers [EMAIL PROTECTED] wrote:

 What are your favorite ultra-light WM's and/or FMs? I'm just looking
 for something that does the job, looking nice would be an added
 benefit but I doubt I'll have a high color depth to play with anyway.

without a doubt, blackbox.  i like fluxbox, and on my desktop system, i
use waimea..but blackbox is more minimal than either, and has *zero*
dependencies.  even though it's minimal, it can also be configured to be
really nice looking, which counts for a lot (to me, anyway).  

if you want *really* minimal, and don't care much about appearances,
i've heard that ratpoison is more than adequate :
i've never used it myself, but if you just want a really plain x
session, and the ability to view multiple terminals simultaneously, it
should be fine.

- erk

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: Max Email Users

2002-10-29 Thread erk!
On Tue, 29 Oct 2002 09:28:08 -0500
Anthony Abby [EMAIL PROTECTED] wrote:

 Well that depends on exactly how your users are using the mail server.
  If all they're doing is accessing it via smtp/pop then the answer
  would be GOBS of users.  Sorry for that highly technical answer, but
  I honestly don't know how many users a 600mhz PIII will support, but
  I know it's hundreds at the very least.  I ran mailing lists with
  over 100k total subscribers on an old Cyrix MIII based Linux box that
  had no problem keeping up with the load.

just to add to this, i've even heard of people running *bsd on a 486,
and still being able to handle hundreds of users.  in particular, i read
about a firewall box running openbsd awhile back that received hundreds
of hack attempts over a week-long period, and never skipped a beat.  the
same appears to be true for mail servers, too.

- erk

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: root-tail question

2002-10-28 Thread erk!
On Mon, 28 Oct 2002 06:53:39 -0600
Bryan Cassidy [EMAIL PROTECTED] wrote:

 I don't know if this is the appropriate mailing list but it should be
 pretty simple for someone to answer so. I just installed root-tail
 from the ports and when I root-tail -f /var/log/message and it prints
 the output from /var/log/messages on the top left of the window and
 the text is kinda small. I was wondering 3 things. First I would like
 to know how do I change the font size, second how could I make it go
 to the bottom left but not all the way down so it would cover the
 toolbar of fluxbox. I dont want it to cover the toolbar. Third is if
 anyone uses root-tail could you post what options you use when you
 load root-tail?

read it's manpage for a full list of options and whatnot.  

it's default position is to be in the top left, but you can change this
with some experimentation.  it's a little difficult to get it set to
where you want it, but once you figure out what you're doing, it's a
piece of cake.  you can change the font size even more easily.

anyway, read its docu.  it's very straightforward and covers all your
questions in detail.

also to note: it doesn't cover the toolbar.  afaik, it always stays
behind everything.

- erk!

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: DHCP

2002-10-28 Thread erk!
On Mon, 28 Oct 2002 23:58:04 -0500
Mike Stacy [EMAIL PROTECTED] wrote:

 I'm new to FreeBSD, what I'm trying to do is install the latest
 version of FreeBSD onto my box using my dsl line which is networked
 through my WinXP box(DHCP). Now when I'm installing I say DHCP : YES
 in Options, then after everything else is set I go into Installation
 Media, select FTP , then I select the server ftp.freebsd.org, then it
 wants to know where my dsl line is that's the  part I can't figure
 out, can someone tell me what to do..

when you start the install, don't select 'standard install' first. 
scroll down to 'configure', and under that menu should be one called
'networking'.  from there, it's pretty straightforward.  it will first
ask you if you want to configure things via ipv6..select 'no' on that
one, at which point it will ask if you want to detect settings via DHCP.
select 'yes' on that, and you're good to go.

it actually won't matter whether or not your main line is through your
winxp box.  freebsd will detect settings via dhcp regardless of whether
or not it's there.

- erk

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: limewire and fluxbox?

2002-10-28 Thread erk!
On Mon, 28 Oct 2002 17:18:32 -0700
Mike Johnston [EMAIL PROTECTED] wrote:

 I'm wondering if anyone else has noticed that limewire displays very
 poorly on fluxbox..
 to the point that you can't resize the window as it's tiny??? you see
 a small square and can't see limewire.. 
 
 does this make any sense? It's kinda hard to describe.

the little box is intended to be a little quick launch sort of thing. 
unfortunately, when you try to minimize fluxbox, it will also go back to
this, instead of docking itself into the taskbar.  really, really lame,
imo.  i think you can just double-click on the box, and it should pop-up
the main window.

- erk

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: divxplayer

2002-10-28 Thread erk!
On Tue, 29 Oct 2002 1:40:34 -0500
Steve Wingate [EMAIL PROTECTED] wrote:

 rehash doesn't re-read rc.conf AFAIK

i'm pretty sure it does..i could be wrong, though, but i seem to recall
it working fine when i added 'linux_enable=YES' awhile back. 

- erk

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: Netiquette (was Re: linux compatibility in 4.7)

2002-10-26 Thread erk!
On Sat, 26 Oct 2002 01:12:37 -0500
Charles Pelletier [EMAIL PROTECTED] wrote:
 
 9.  Put your response in the correct place (after the text to which it
 replies). It's very difficult to read a thread of responses where
 each reply comes before the text to which it replies.

just to note, the only reason i'd mentioned that is because i was told,
numerous times, that this is how things are preferred here.  it made
sense, to an extent, particularly for those using clients like pine.  on
usenet, it's as above, but when i'd first joined the lists (6+ months
ago), i received several emails telling me not to.

in any case, the one error on my part isn't the point.  the point is, 25
quotes lines with what amounts to a me too response is just
rediculous.  sorry if that ruffles anyone's feathers, but last i
checked, nobody particularly appreciated those types of mails.

to the original person i was replying to, however: i did not mean for my
message to be interpreted as saying *you* are rude, as a person..merely
that those kinds of posts are needlessly full of unnecessary junk, which
is annoying due to slower download times to receive mail, readability,
etc, ad nauseam.  yes, i made a mistake on the top/bottom quoting thing:
i hadn't seen the line that mr. pelletier brought up, and again, i was
only going by what i was told numerous times before.

i'd also like to give thanks to the multiple copies of each email i was
sent, particularly from daleco, who felt his/her point was so
important to express to me, i needed to read it no less than 4 times.

- erk!

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Netiquette (was Re: linux compatibility in 4.7)

2002-10-25 Thread erk!
in the future, PLEASE trim the text you're quoting, and put your reply
above the quote.  we shouldn't have to scroll through 20 rows of text,
including the entirety of the original post, just to see your reply. 
cutting out the MSN ad would've been nice, too.

i don't even use a console-only mail reader anymore, and i still find
this to be incredibly rude.

a good rule of thumb: if the text you're quoting is larger than your
reply, rethink it or don't post it.

- erk

 Dear John,
 
 I'm not sure, but my guess is that linux_base-6.1_3 isn't necessary
 and got installed by some form of minor bug.

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: random reboots

2002-10-22 Thread erk!
i've actually had this problem also..however, it turned out to be a BIOS
issue.  i don't recall the specific setting name that i had to change,
but there should be some kind of performance toggle or speed toggle
between normal and turbo.  switching it back to normal stopped the
spontaneous reboots for me.  dunno if this will help you in any way, but
it's as much a possibility as anything, i suppose.

- erik

On Mon, 21 Oct 2002 23:19:15 -0600
RichardH [EMAIL PROTECTED] wrote:

 We are experiencing random reboots on 4.7. Have seen other postings in
 here regarding this issue so it does not appear to be hardware related
 but have not seen a definitive answer to what is going on. No core
 dumps, etc. Please respond if you are having same problem. We are
 doing 4.7 on a test server running AMD 400 CPU and would like to
 goto 4.7 on production servers but with random reboots this is not
 feasible. As I said this has come up on questions before but still
 has not been fully addressed. Running newest Apache, MySQL, PHP, Perl,
 just can't up to 4.7 yet (was rebooting before any of the previous
 were upped,Apache, etc.) 4.6 was totally stable . Rebooting probs
 started after upping to 4.7 FBSD and are totally random. Thanks for
 any input.

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: Athlon XP motherboards that work well with FreeBSD

2002-10-10 Thread erk

I'll give a good nod to my current board, a Soyo SY-K7V Dragon Plus! VIA
KT266A 100/133 FSB.  It has onboard sound and LAN, but both are well
supported, and can be put aside with a simple change under BIOS.  It was
a really good option for me, initially, because when I built this box, I
was somewhat low on cash.  The onboard stuff saved me a few $$$ early
on, though i've since upgraded the sound card to a Soundblaster Live
5.1.  It also has onboard RAID, and supports up to 3GB of PC2100
DDR-SDRAM.  Very, very smooth little board, even with just 256MB.  I
haven't made use of the RAID yet, but from what I understand, it works
just fine.

Both the processor and mobo have come down quite a bit in price since I
bought it, so you could probably get them cheaply from a place like
newegg.com or directron.com...assuming you want something in the 1+ghz
range.

- erik

On Thu, 10 Oct 2002 15:43:36 -0700
Corey Holcomb-Hockin [EMAIL PROTECTED] wrote:

 I've been having trouble with my a7a-133.  I had trouble with XFree86,
 
 and with a tv card.   I'd like to know some motherboards that work
 well with FreeBSD?

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



qt30 png_write_chunk errors during make

2002-10-08 Thread erk


I'm just finishing up installing FreeBSD on a 3rd machine here at my
apartment, but i'm noticing a slight problem with qt30.  any time i try
to build a port that relies on qt30, the build breaks with a series of
messages seemingly related to png.  this is trimmed down considerably,
but a small portion of those messages includes:


/usr/ports/x11-toolkits/qt30/work/qt-x11-free-3.0.5/tools/qvfb/qanimati
onwriter.cpp(.gnu.linkonce.t.writePNG__19QAnimationWriterMNGRC6QImage+0
x184): undefined reference to 'png_write_image'

the other messages are essentially the same, with undefined reference
to 'png_write_image' periodically changing to things like
png_write_chunk.  i apologize for not posting the entire set of
errors, but they're on the other machine, and typing the entire string
of errors would take quite some time (there are approximately 12-15).

i've had this problem on all 3 boxen when trying to build qt or related
ports, but somehow worked around it each time..i just can't recall how. 
I had assumed it would be fixed by now, but searching the archives and
google didn't really turn up much, so i'm thinking this may be a unique
problem i'm having.  the system in question is a PIII 500mhz running
4.6.2-RELEASE, and the one i'm currently on (where it eventually worked)
is an AMD Athlon XP 1500+ running 4.6.2-RELEASE.  i don't think i made
any significant changes to any Makefile's, so i'm wondering why it
eventually succeeded before (and why it isn't now).  the ports i'm
trying to make are krss, cdbakeoven, qt, arts, and audacity.  on the
system that building qt eventually succeeded, i recall trying several of
the ports in different sequences, like doing arts first, then trying
kdelibs first, etc.  i've tried the same thing on the pIII but nothing
has worked thus far.

should i possibly take this over to ports-?

- erik



To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: 4.7

2002-10-03 Thread erk

glad to see someone posted about this.  i was kind of anxious for this
release, but more stability is infinitely preferable to a
quick-and-dirty release.  

i'd also second a vote for some kind of notification/updates on the main
page.  this is the first info i've seen about any of it, and i'm sure
there are a good number of other people wondering what's going on.  at
the least, it might lower the number of people checking the ftp sites
for iso images.

- erik

On Thu, 3 Oct 2002 01:02:01 -0700
Adam Weinberger [EMAIL PROTECTED] wrote:

 patience ::)
 
 the RE team has chosen to release 4.7 after the original date in
 exchange for greater confidence in the stability of the release.
 there will likely be another release candidate before 4.7 is official.
 
 i imagine it would simplify things to provide at least some sort of
 recognition on the webpage that 4.7 is indeed delayed. while a target
 date easily may not be feasible, a notice of acknowledgement of the
 delay and a note keeping users abreast of what is involved in the
 delay and what is currently being tested would be a welcome addition.

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message



Re: atapi cd-r/cd-rw drives?

2002-09-18 Thread erk

On Wed, 18 Sep 2002 07:48:16 -0400
Brian T. Schellenberger [EMAIL PROTECTED] wrote:

 
 
 
 On Wednesday 18 September 2002 07:18 am, erk wrote:
 | searches on google haven't turned up much, other than linux-oriented
 | changes.  most of them note something about scsi-adapter emulation,
 | though.. does freebsd have support for something like this,
 
 Yes, only very recently.

how recent? as in, implemented, but relatively stable, or implemented, but still in 
need of heavy tinkering to be considered useable?  just kinda curious about that one.

 You couldnt but SCSI emulation is a lot more complex than that, so it 
 wouldn't do anything USEFUL.

kind of figured that.  there was some mention of it on koncd's site, regarding 
configuring things for linux, but i tend to take any info that appears to be 
linux-centric with a grain of salt.

 What on earth do you mean by that?  That sounds like a major slander 
 against burncd which works just great from what I've seen.  I prefer
 it to cdrecord myself; it's more readable and compact IMHO.

it isn't intended as slander..based on the limited amount of info i've run across 
about burncd, i could've sworn i saw a few things mentioning it as having a lack of 
widespread cd-r drive support.  perhaps i'm mistaken, but research time is a little 
limited at the moment.

to elaborate a bit, i've got a dj gig tomorrow and i'm unsure of whether or not i'll 
have access to turntables.  for that reason, i figured i'd
burn a couple discs of mp3's that i have of some of my vinyl releases, just in case. 

- erik

To Unsubscribe: send mail to [EMAIL PROTECTED]
with unsubscribe freebsd-questions in the body of the message