Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-02-04 Thread Jeremy Porter
On 2/4/2015 10:44 AM, Vinícius Zavam wrote:


 vinicius.zavam@egypcio:~ % ssh -6 -l noc -p 22085
 2001:::::
 Last login: Wed Jan 28 16:26:47 2015 from
 2001:::::fb5d
 export: Command not found.
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(1) id
 uid=2000(noc) gid=65534(nobody) groups=65534(nobody),1999(admins)
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(2) su -
 su: Sorry
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(3) sudo su -
 Shared object libutil.so.8 not found, required by sudo
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(4) pkg info
 The package management tool is not yet installed on your system.
 Do you want to fetch and install it now? [y/N]:
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(5) ls -1 /var/db/pkg
 bsdinstaller-2.0.2012.1207
 gettext-0.18.1.1
 iperf-2.0.5 # shouldn't be here, I think; I've deinstalled it
 long time ago.
 libiconv-1.14
 libpcap-1.2.1
 lua-5.1.5_4
 mtr-nox11-0.82
 nmap-6.01
 openssl-1.0.1_10
 pcre-8.30_2
 pkg-config-0.25_1
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(6) nmap --version

 Nmap version 6.47 ( http://nmap.org )
 Platform: amd64-portbld-freebsd10.0
 Compiled with: liblua-5.2.3 openssl-1.0.1g-freebsd
 libpcre-8.35 libpcap-1.4.0 nmap-libdnet-1.12 ipv6
 Compiled without:
 Available nsock engines: kqueue poll select
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(7) mtr --version
 mtr 0.85
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(8) iperf
 iperf: Command not found.
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(9) whereis iperf
 whereis: Command not found.

 PS: a quick test scan with nmap was okay. mtr-nox11 is also in
 good shape.


 -- 
 Vinícius Zavam


 https://redmine.pfsense.org/issues/4344


 -- 
 Vinícius Zavam


 solved?
 https://redmine.pfsense.org/issues/4344#note-3 (it worked here).
 thanks to PiBa-NL, ##pfsense@freenode.

 it smells like... packages issues, I think.

Freebsd pkg is not supported as an official way to install packages on
2.2.  Version 2.2 uses PBI packages for official packages.
That said, if you install pkg, it will run, and install packages, but it
might overwrite system libraries or official packages, rendering your
system in an unsupportable state.

___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-02-04 Thread Vinícius Zavam
2015-01-29 18:29 GMT-03:00 Vinícius Zavam egyp...@googlemail.com:



 2015-01-29 10:56 GMT-03:00 Vinícius Zavam egyp...@googlemail.com:



 2015-01-29 10:24 GMT-03:00 Vinícius Zavam egyp...@googlemail.com:



 2015-01-28 6:41 GMT-03:00 WolfSec-Support supp...@wolfsec.ch:


 2015-01-27 22:13 GMT+01:00 Chris Buechler c...@pfsense.com:

  we have general problems with v2.2
 
  I tried to update 13 devices, and only some worked fine (1 ALIX),
  and one virtual machine (afterwards crashes see below)
 
  Most we had problems, e.g:
  - looping packet installations without ending - reboot is not
 solving it

 In what circumstance?


 after launching the amd64 based pfsense to make an upgrade from 2.1.5
 to v.2.2 via webgui,
 it installs the upgrade, and then reinstalls all packages

 this never ends

 also a reboot will not solve this / brake package installation loop


 +1

 same thing is happening in here. (didn't reboot)
 from 2.1.5 to 2.2; amd64 too. uptime after upgrade? 17 Hours 56 Minutes
 34 Seconds...

  Intel X5550 Issue under VMware ESXi 5.1
 
  - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

 There has to be some difference between this and the other outside of
 the CPU. Some configuration difference, or something. What are you
 using on these that you aren't on the others?


 all use same packages and same plattform, and same sevices:

 packages:
 - squid
 - lightsquid
 - open-vm-tools
 - cron
 - autoconfigbackup


 nmap, mtr-nox11, sudo, suricata


 other vm's with only:
 packages:
 - open-vm-tools
 - cron
 - autoconfigbackup

 have same issue

 I tested also on different hosts (3x same HP DL 380 G6 with same CPU's)


 just one; physical machine...

 same issue

 also I thried without any package:
 - crashes

 services used:
 - DNS Forwarder
 - OpenVPN
 - Firewall for sure ;)
 - HA
 - Limiters


 firewall [LOL], dhcpv4 (+nat, +vlan), dhcpv6 (+vlan), radvd,
 openvpn, dns forwarder.

 all worked fine under v2.1.5




 The only crashing scenario I've found in release is limiters+HA as
 noted in the upgrade guide.
 https://doc.pfsense.org/index.php/Upgrade_Guide



 uh, may have ignored that fact - yes - limiters  HA

 well, question:
 - disabling the limiters would solve this issue in meantime ?
 - or do I have to delete all limiters

 but:
 on other CPU under VMware ESX5.1 I have release 2.2 WITH HA AND
 limiters up and running without problems

 strange

 so, would help If you anser upper questions - I will do some test here

 Many thanks for the helpinng hint

 Best regards
 Stephan


 system logs? http://pastebin.com/8ni6F2Tb

 PS: suricata is *NOT* working :)


 --
 Vinícius Zavam


 almost forgot to mention! SSH (with rsa keys) is working, but...

 vinicius.zavam@egypcio:~ % ssh -6 -l noc -p 22085 2001:::::
 Last login: Wed Jan 28 16:26:47 2015 from 2001:::::fb5d
 export: Command not found.
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(1) id
 uid=2000(noc) gid=65534(nobody) groups=65534(nobody),1999(admins)
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(2) su -
 su: Sorry
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(3) sudo su -
 Shared object libutil.so.8 not found, required by sudo
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(4) pkg info
 The package management tool is not yet installed on your system.
 Do you want to fetch and install it now? [y/N]:
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(5) ls -1 /var/db/pkg
 bsdinstaller-2.0.2012.1207
 gettext-0.18.1.1
 iperf-2.0.5 # shouldn't be here, I think; I've deinstalled it long time
 ago.
 libiconv-1.14
 libpcap-1.2.1
 lua-5.1.5_4
 mtr-nox11-0.82
 nmap-6.01
 openssl-1.0.1_10
 pcre-8.30_2
 pkg-config-0.25_1
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(6) nmap --version

 Nmap version 6.47 ( http://nmap.org )
 Platform: amd64-portbld-freebsd10.0
 Compiled with: liblua-5.2.3 openssl-1.0.1g-freebsd libpcre-8.35
 libpcap-1.4.0 nmap-libdnet-1.12 ipv6
 Compiled without:
 Available nsock engines: kqueue poll select
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(7) mtr --version
 mtr 0.85
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(8) iperf
 iperf: Command not found.
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(9) whereis iperf
 whereis: Command not found.

 PS: a quick test scan with nmap was okay. mtr-nox11 is also in good shape.


 --
 Vinícius Zavam


 https://redmine.pfsense.org/issues/4344


 --
 Vinícius Zavam


solved?
https://redmine.pfsense.org/issues/4344#note-3 (it worked here).
thanks to PiBa-NL, ##pfsense@freenode.

it smells like... packages issues, I think.


-- 
Vinícius Zavam
profiles.google.com/egypcio
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-29 Thread Vinícius Zavam
2015-01-28 6:41 GMT-03:00 WolfSec-Support supp...@wolfsec.ch:


 2015-01-27 22:13 GMT+01:00 Chris Buechler c...@pfsense.com:

  we have general problems with v2.2
 
  I tried to update 13 devices, and only some worked fine (1 ALIX),
  and one virtual machine (afterwards crashes see below)
 
  Most we had problems, e.g:
  - looping packet installations without ending - reboot is not solving it

 In what circumstance?


 after launching the amd64 based pfsense to make an upgrade from 2.1.5 to
 v.2.2 via webgui,
 it installs the upgrade, and then reinstalls all packages

 this never ends

 also a reboot will not solve this / brake package installation loop


+1

same thing is happening in here. (didn't reboot)
from 2.1.5 to 2.2; amd64 too. uptime after upgrade? 17 Hours 56 Minutes 34
Seconds...

 Intel X5550 Issue under VMware ESXi 5.1
 
  - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

 There has to be some difference between this and the other outside of
 the CPU. Some configuration difference, or something. What are you
 using on these that you aren't on the others?


 all use same packages and same plattform, and same sevices:

 packages:
 - squid
 - lightsquid
 - open-vm-tools
 - cron
 - autoconfigbackup


nmap, mtr-nox11, sudo, suricata


 other vm's with only:
 packages:
 - open-vm-tools
 - cron
 - autoconfigbackup

 have same issue

 I tested also on different hosts (3x same HP DL 380 G6 with same CPU's)


just one; physical machine...

same issue

 also I thried without any package:
 - crashes

 services used:
 - DNS Forwarder
 - OpenVPN
 - Firewall for sure ;)
 - HA
 - Limiters


firewall [LOL], dhcpv4 (+nat, +vlan), dhcpv6 (+vlan), radvd,
openvpn, dns forwarder.

all worked fine under v2.1.5




 The only crashing scenario I've found in release is limiters+HA as
 noted in the upgrade guide.
 https://doc.pfsense.org/index.php/Upgrade_Guide



 uh, may have ignored that fact - yes - limiters  HA

 well, question:
 - disabling the limiters would solve this issue in meantime ?
 - or do I have to delete all limiters

 but:
 on other CPU under VMware ESX5.1 I have release 2.2 WITH HA AND limiters
 up and running without problems

 strange

 so, would help If you anser upper questions - I will do some test here

 Many thanks for the helpinng hint

 Best regards
 Stephan


system logs? http://pastebin.com/8ni6F2Tb

PS: suricata is *NOT* working :)


-- 
Vinícius Zavam
profiles.google.com/egypcio
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-29 Thread Vinícius Zavam
2015-01-29 10:24 GMT-03:00 Vinícius Zavam egyp...@googlemail.com:



 2015-01-28 6:41 GMT-03:00 WolfSec-Support supp...@wolfsec.ch:


 2015-01-27 22:13 GMT+01:00 Chris Buechler c...@pfsense.com:

  we have general problems with v2.2
 
  I tried to update 13 devices, and only some worked fine (1 ALIX),
  and one virtual machine (afterwards crashes see below)
 
  Most we had problems, e.g:
  - looping packet installations without ending - reboot is not solving
 it

 In what circumstance?


 after launching the amd64 based pfsense to make an upgrade from 2.1.5 to
 v.2.2 via webgui,
 it installs the upgrade, and then reinstalls all packages

 this never ends

 also a reboot will not solve this / brake package installation loop


 +1

 same thing is happening in here. (didn't reboot)
 from 2.1.5 to 2.2; amd64 too. uptime after upgrade? 17 Hours 56 Minutes 34
 Seconds...

  Intel X5550 Issue under VMware ESXi 5.1
 
  - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

 There has to be some difference between this and the other outside of
 the CPU. Some configuration difference, or something. What are you
 using on these that you aren't on the others?


 all use same packages and same plattform, and same sevices:

 packages:
 - squid
 - lightsquid
 - open-vm-tools
 - cron
 - autoconfigbackup


 nmap, mtr-nox11, sudo, suricata


 other vm's with only:
 packages:
 - open-vm-tools
 - cron
 - autoconfigbackup

 have same issue

 I tested also on different hosts (3x same HP DL 380 G6 with same CPU's)


 just one; physical machine...

 same issue

 also I thried without any package:
 - crashes

 services used:
 - DNS Forwarder
 - OpenVPN
 - Firewall for sure ;)
 - HA
 - Limiters


 firewall [LOL], dhcpv4 (+nat, +vlan), dhcpv6 (+vlan), radvd,
 openvpn, dns forwarder.

 all worked fine under v2.1.5




 The only crashing scenario I've found in release is limiters+HA as
 noted in the upgrade guide.
 https://doc.pfsense.org/index.php/Upgrade_Guide



 uh, may have ignored that fact - yes - limiters  HA

 well, question:
 - disabling the limiters would solve this issue in meantime ?
 - or do I have to delete all limiters

 but:
 on other CPU under VMware ESX5.1 I have release 2.2 WITH HA AND limiters
 up and running without problems

 strange

 so, would help If you anser upper questions - I will do some test here

 Many thanks for the helpinng hint

 Best regards
 Stephan


 system logs? http://pastebin.com/8ni6F2Tb

 PS: suricata is *NOT* working :)


 --
 Vinícius Zavam


almost forgot to mention! SSH (with rsa keys) is working, but...

vinicius.zavam@egypcio:~ % ssh -6 -l noc -p 22085 2001:::::
Last login: Wed Jan 28 16:26:47 2015 from 2001:::::fb5d
export: Command not found.
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(1) id
uid=2000(noc) gid=65534(nobody) groups=65534(nobody),1999(admins)
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(2) su -
su: Sorry
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(3) sudo su -
Shared object libutil.so.8 not found, required by sudo
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(4) pkg info
The package management tool is not yet installed on your system.
Do you want to fetch and install it now? [y/N]:
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(5) ls -1 /var/db/pkg
bsdinstaller-2.0.2012.1207
gettext-0.18.1.1
iperf-2.0.5 # shouldn't be here, I think; I've deinstalled it long time ago.
libiconv-1.14
libpcap-1.2.1
lua-5.1.5_4
mtr-nox11-0.82
nmap-6.01
openssl-1.0.1_10
pcre-8.30_2
pkg-config-0.25_1
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(6) nmap --version

Nmap version 6.47 ( http://nmap.org )
Platform: amd64-portbld-freebsd10.0
Compiled with: liblua-5.2.3 openssl-1.0.1g-freebsd libpcre-8.35
libpcap-1.4.0 nmap-libdnet-1.12 ipv6
Compiled without:
Available nsock engines: kqueue poll select
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(7) mtr --version
mtr 0.85
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(8) iperf
iperf: Command not found.
[2.2-RELEASE][n...@hostname.dn.tld]/home/noc(9) whereis iperf
whereis: Command not found.

PS: a quick test scan with nmap was okay. mtr-nox11 is also in good shape.


-- 
Vinícius Zavam
profiles.google.com/egypcio
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-29 Thread Vinícius Zavam
2015-01-29 10:56 GMT-03:00 Vinícius Zavam egyp...@googlemail.com:



 2015-01-29 10:24 GMT-03:00 Vinícius Zavam egyp...@googlemail.com:



 2015-01-28 6:41 GMT-03:00 WolfSec-Support supp...@wolfsec.ch:


 2015-01-27 22:13 GMT+01:00 Chris Buechler c...@pfsense.com:

  we have general problems with v2.2
 
  I tried to update 13 devices, and only some worked fine (1 ALIX),
  and one virtual machine (afterwards crashes see below)
 
  Most we had problems, e.g:
  - looping packet installations without ending - reboot is not solving
 it

 In what circumstance?


 after launching the amd64 based pfsense to make an upgrade from 2.1.5 to
 v.2.2 via webgui,
 it installs the upgrade, and then reinstalls all packages

 this never ends

 also a reboot will not solve this / brake package installation loop


 +1

 same thing is happening in here. (didn't reboot)
 from 2.1.5 to 2.2; amd64 too. uptime after upgrade? 17 Hours 56 Minutes
 34 Seconds...

  Intel X5550 Issue under VMware ESXi 5.1
 
  - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

 There has to be some difference between this and the other outside of
 the CPU. Some configuration difference, or something. What are you
 using on these that you aren't on the others?


 all use same packages and same plattform, and same sevices:

 packages:
 - squid
 - lightsquid
 - open-vm-tools
 - cron
 - autoconfigbackup


 nmap, mtr-nox11, sudo, suricata


 other vm's with only:
 packages:
 - open-vm-tools
 - cron
 - autoconfigbackup

 have same issue

 I tested also on different hosts (3x same HP DL 380 G6 with same CPU's)


 just one; physical machine...

 same issue

 also I thried without any package:
 - crashes

 services used:
 - DNS Forwarder
 - OpenVPN
 - Firewall for sure ;)
 - HA
 - Limiters


 firewall [LOL], dhcpv4 (+nat, +vlan), dhcpv6 (+vlan), radvd,
 openvpn, dns forwarder.

 all worked fine under v2.1.5




 The only crashing scenario I've found in release is limiters+HA as
 noted in the upgrade guide.
 https://doc.pfsense.org/index.php/Upgrade_Guide



 uh, may have ignored that fact - yes - limiters  HA

 well, question:
 - disabling the limiters would solve this issue in meantime ?
 - or do I have to delete all limiters

 but:
 on other CPU under VMware ESX5.1 I have release 2.2 WITH HA AND limiters
 up and running without problems

 strange

 so, would help If you anser upper questions - I will do some test here

 Many thanks for the helpinng hint

 Best regards
 Stephan


 system logs? http://pastebin.com/8ni6F2Tb

 PS: suricata is *NOT* working :)


 --
 Vinícius Zavam


 almost forgot to mention! SSH (with rsa keys) is working, but...

 vinicius.zavam@egypcio:~ % ssh -6 -l noc -p 22085 2001:::::
 Last login: Wed Jan 28 16:26:47 2015 from 2001:::::fb5d
 export: Command not found.
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(1) id
 uid=2000(noc) gid=65534(nobody) groups=65534(nobody),1999(admins)
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(2) su -
 su: Sorry
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(3) sudo su -
 Shared object libutil.so.8 not found, required by sudo
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(4) pkg info
 The package management tool is not yet installed on your system.
 Do you want to fetch and install it now? [y/N]:
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(5) ls -1 /var/db/pkg
 bsdinstaller-2.0.2012.1207
 gettext-0.18.1.1
 iperf-2.0.5 # shouldn't be here, I think; I've deinstalled it long time
 ago.
 libiconv-1.14
 libpcap-1.2.1
 lua-5.1.5_4
 mtr-nox11-0.82
 nmap-6.01
 openssl-1.0.1_10
 pcre-8.30_2
 pkg-config-0.25_1
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(6) nmap --version

 Nmap version 6.47 ( http://nmap.org )
 Platform: amd64-portbld-freebsd10.0
 Compiled with: liblua-5.2.3 openssl-1.0.1g-freebsd libpcre-8.35
 libpcap-1.4.0 nmap-libdnet-1.12 ipv6
 Compiled without:
 Available nsock engines: kqueue poll select
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(7) mtr --version
 mtr 0.85
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(8) iperf
 iperf: Command not found.
 [2.2-RELEASE][n...@hostname.dn.tld]/home/noc(9) whereis iperf
 whereis: Command not found.

 PS: a quick test scan with nmap was okay. mtr-nox11 is also in good shape.


 --
 Vinícius Zavam


https://redmine.pfsense.org/issues/4344


-- 
Vinícius Zavam
profiles.google.com/egypcio
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-28 Thread WolfSec-Support
2015-01-27 22:13 GMT+01:00 Chris Buechler c...@pfsense.com:

  we have general problems with v2.2
 
  I tried to update 13 devices, and only some worked fine (1 ALIX),
  and one virtual machine (afterwards crashes see below)
 
  Most we had problems, e.g:
  - looping packet installations without ending - reboot is not solving it

 In what circumstance?


after launching the amd64 based pfsense to make an upgrade from 2.1.5 to
v.2.2 via webgui,
it installs the upgrade, and then reinstalls all packages

this never ends

also a reboot will not solve this / brake package installation loop



  Intel X5550 Issue under VMware ESXi 5.1
 
  - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

 There has to be some difference between this and the other outside of
 the CPU. Some configuration difference, or something. What are you
 using on these that you aren't on the others?


all use same packages and same plattform, and same sevices:

packages:
- squid
- lightsquid
- open-vm-tools
- cron
- autoconfigbackup

other vm's with only:
packages:
- open-vm-tools
- cron
- autoconfigbackup

have same issue

I tested also on different hosts (3x same HP DL 380 G6 with same CPU's)

same issue

also I thried without any package:
- crashes

services used:
- DNS Forwarder
- OpenVPN
- Firewall for sure ;)
- HA
- Limiters

all worked fine under v2.1.5




 The only crashing scenario I've found in release is limiters+HA as
 noted in the upgrade guide.
 https://doc.pfsense.org/index.php/Upgrade_Guide



uh, may have ignored that fact - yes - limiters  HA

well, question:
- disabling the limiters would solve this issue in meantime ?
- or do I have to delete all limiters

but:
on other CPU under VMware ESX5.1 I have release 2.2 WITH HA AND limiters up
and running without problems

strange

so, would help If you anser upper questions - I will do some test here

Many thanks for the helpinng hint

Best regards
Stephan
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-28 Thread Bob Gustafson
On a plain vanilla Alix 3port board with 2.1.5 previously installed, my 
autoupdate installed Asterisk (my only package) with no problems.


I have only lightly tested things though - perhaps problems will pop up.

FWIW

Bob G

On 01/28/2015 03:41 AM, WolfSec-Support wrote:


2015-01-27 22:13 GMT+01:00 Chris Buechler c...@pfsense.com 
mailto:c...@pfsense.com:


 we have general problems with v2.2

 I tried to update 13 devices, and only some worked fine (1 ALIX),
 and one virtual machine (afterwards crashes see below)

 Most we had problems, e.g:
 - looping packet installations without ending - reboot is not
solving it

In what circumstance?


after launching the amd64 based pfsense to make an upgrade from 2.1.5 
to v.2.2 via webgui,

it installs the upgrade, and then reinstalls all packages

this never ends

also a reboot will not solve this / brake package installation loop


 Intel X5550 Issue under VMware ESXi 5.1

 - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

There has to be some difference between this and the other outside of
the CPU. Some configuration difference, or something. What are you
using on these that you aren't on the others?


all use same packages and same plattform, and same sevices:

packages:
- squid
- lightsquid
- open-vm-tools
- cron
- autoconfigbackup

other vm's with only:
packages:
- open-vm-tools
- cron
- autoconfigbackup

have same issue

I tested also on different hosts (3x same HP DL 380 G6 with same CPU's)

same issue

also I thried without any package:
- crashes

services used:
- DNS Forwarder
- OpenVPN
- Firewall for sure ;)
- HA
- Limiters

all worked fine under v2.1.5


The only crashing scenario I've found in release is limiters+HA as
noted in the upgrade guide.
https://doc.pfsense.org/index.php/Upgrade_Guide



uh, may have ignored that fact - yes - limiters  HA

well, question:
- disabling the limiters would solve this issue in meantime ?
- or do I have to delete all limiters

but:
on other CPU under VMware ESX5.1 I have release 2.2 WITH HA AND 
limiters up and running without problems


strange

so, would help If you anser upper questions - I will do some test here

Many thanks for the helpinng hint

Best regards
Stephan




___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

[pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-27 Thread WolfSec-Support
hello all,


we have general problems with v2.2

I tried to update 13 devices, and only some worked fine (1 ALIX),
and one virtual machine (afterwards crashes see below)

Most we had problems, e.g:
- looping packet installations without ending - reboot is not solving it
- packets cron / squid / lightsquid / some open-vm-tools

- build of new SSH keys will be not confirmed on nanobsd installations -
ssh is not working any more afterwards (all ALIX platforms)


and mayor issue:


Intel X5550 Issue under VMware ESXi 5.1

- crashes on ALL machines which run under VMware ESXi 5.1 on CPU:
- - CPU: Intel(R) Xeon(R) CPU   X5550  @ 2.67GHz (2665.58-MHz
K8-class CPU)
- - Origin = GenuineIntel  Id = 0x106a4  Family = 6  Model = 1a  Stepping
= 4

(HP DL380 G6 Servers)

Others under same ESXi5.1 Build with other CPUs work fine

System crashes while booting, or if it has to handle workload.
3 of 4 boot and crash.
1 works - if it has to handle workload, e.g. vpn tunnel, it crashs

so, ALL VM installations on this CPU crash :-((

Basis on all installations was Release 2.1.5

Do have more of you had similar problems ?


Is planned to make a 2.1.6 to solve the open security issues ?
v2.2 under new FreeBSD platform seems not to working stable here.

May more are interested in a stable v2.1.x until v2.2. works fine on all
platforms

comments are welcome,


Best Regards,
Stephan
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-27 Thread Chris Buechler
On Tue, Jan 27, 2015 at 4:07 AM, WolfSec-Support supp...@wolfsec.ch wrote:
 hello all,


 we have general problems with v2.2

 I tried to update 13 devices, and only some worked fine (1 ALIX),
 and one virtual machine (afterwards crashes see below)

 Most we had problems, e.g:
 - looping packet installations without ending - reboot is not solving it

In what circumstance?


 Intel X5550 Issue under VMware ESXi 5.1

 - crashes on ALL machines which run under VMware ESXi 5.1 on CPU:

There has to be some difference between this and the other outside of
the CPU. Some configuration difference, or something. What are you
using on these that you aren't on the others?

The only crashing scenario I've found in release is limiters+HA as
noted in the upgrade guide.
https://doc.pfsense.org/index.php/Upgrade_Guide
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-27 Thread Dr. Peter Voigt
On Tue, 27 Jan 2015 11:07:00 +0100
WolfSec-Support supp...@wolfsec.ch wrote:

 hello all,
 
 
 we have general problems with v2.2
 
 I tried to update 13 devices, and only some worked fine (1 ALIX),
 and one virtual machine (afterwards crashes see below)
 
 Most we had problems, e.g:
 - looping packet installations without ending - reboot is not solving
 it
 - packets cron / squid / lightsquid / some open-vm-tools
 
 - build of new SSH keys will be not confirmed on nanobsd
 installations - ssh is not working any more afterwards (all ALIX
 platforms)
 

Well, I have just successfully upgraded two machines:

https://forum.pfsense.org/index.php?topic=87565.0

One of them is an Alix as well but I have no SSH issues. On the other
hand there is at least one reported SSH issue in the forum:

https://forum.pfsense.org/index.php?topic=87548.0

Regards,
Peter
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-27 Thread Compdoc
 Do have more of you had similar problems ?

I upgraded one firewall and everything works fine except that I use the squid 
and  HAVP packages together, but HAVP is broken. Running commands like clamd 
and freshclam don't work. 
I don't know how to file a bug report so I created a topic in the forums, and 
others have the same problem. Also, in the irc support channel, people are 
having odd problems like yours. Might be best to wait on upgrades.
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold