Re: [DISCUSS] Moving to OpenVPN as the remote access VPN provider

2021-06-10 Thread Kristaps Cudars
OpenVPN is SSL/TLS VPN and it has no support for IPSec. OpenVPN should coexist with Strongswan. OpenVPN is ment for vpn client connective many to one. Strongswan is meant for P2P connectivity. On 2021/06/10 08:39:14, Rudraksh MK wrote: > Hey! > > I’m personally a strong proponent of Wireguard

Re: IPV6 in Isolated/VPC networks

2021-07-13 Thread Kristaps Cudars
Hi, I would like to argue that implementer dynamic routing protocol and associated security problems/challenges with it to have IPv6 route inserted in L3 router/s is not a good goal. In my opinion dynamic routing on VR would be interesting to scale availability of service across several datace

Re: RE: IPV6 in Isolated/VPC networks

2021-07-14 Thread Kristaps Cudars
Pony Mail is blocking me :( Hi, Elaborating on my previous email. In my opinion SLAAC (StateLess Address Auto Configuration) is not good candidate for VR as it was created for situations of connecting million devices with less amount of effort and no micromanagement needed. One example that com

Re: IPV6 in Isolated/VPC networks

2021-07-14 Thread Kristaps Cudars
Hi Alex, No BGP or NAT66 on VR. Route insert in to L3 handled or list acquired from ACS api. On Wed, 14 Jul 2021 at 19:05, Hean Seng wrote: > Yes, sorry for that, can use NAT 6 also .I mentiioned DHCP6 , and you > can point the gateway to /48 gw, and this does not need any BGP. Maintain >

Re: RE: IPV6 in Isolated/VPC networks

2021-07-15 Thread Kristaps Cudars
t may not allow you larger email and > doc/attachments. If there are any documents you want to share, can you say > put them on Google docs and share the link with dev list? Thanks. > > > Regards. > > ________ > From: Kristaps Cudars > Sent: Wedn

Re: IPV6 in Isolated/VPC networks

2021-07-15 Thread Kristaps Cudars
Hi Wido, Can you explain why “DHCPv6 as much as possible as that's not really the intended use-case” it’s not intended use-case? On 2021/07/15 09:31:26, Wido den Hollander wrote: > > > Op 14-07-2021 om 16:44 schreef Hean Seng: > > Hi > > > > I replied in another thread, i think do not need

Re: IPV6 in Isolated/VPC networks

2021-07-15 Thread Kristaps Cudars
Hi Hean, You still need to create route on L3 SW that will point /64 VM On 2021/07/15 10:39:13, Hean Seng wrote: > Or explain like this : > > 1) Cloudstack generate list of /64 subnet from /48 that Network admin > assigned to Cloudstack > 2) Cloudsack allocated the subnet (that generated from

Re: IPV6 in Isolated/VPC networks

2021-07-15 Thread Kristaps Cudars
Hi Wido, What is benefit of using Route Advertisement on internal VR networks? In drawing VR is in VPC mode how it will work for isolated network where external link/ip is not assigned initially? On 2021/07/15 14:47:24, Wido den Hollander wrote: > But you still need routing. See the attache

Re: IPV6 in Isolated/VPC networks

2021-07-15 Thread Kristaps Cudars
uter Advertisements with SLAAC is much better supported in Operating > Systems then DHCPv6 is. > > Wido > > > > > Thanks > > Alex > > > > > > > > > > -Original Message- > > From: Kristaps Cudars > > Sent: 13 July 2

Re: IPV6 in Isolated/VPC networks

2021-07-15 Thread Kristaps Cudars
Hi Wido, DHCPv6 is not an option? It enables feature parity between IPv4 and IPv6 in context of VR. Or there are some advantages in RA and SLAAC? On 2021/07/15 15:10:38, Wido den Hollander wrote: > > > Op 15-07-2021 om 17:05 schreef Kristaps Cudars: > > Hi Wido, > >

Re: IPV6 in Isolated/VPC networks

2021-07-16 Thread Kristaps Cudars
Hi Wido, Your proposal is to sacrifice ability to reassign IPv6 to instance, have internal domain prefix, and list/db in ACS what IPv6 has been assigned to what instance and go with RA and SLAAC. For route signaling to switch use BGP/OSPFv3 or manual pre-creation. Option with RA and managed fl

Re: IPV6 in Isolated/VPC networks

2021-07-19 Thread Kristaps Cudars
. On 2021/07/19 09:05:54, Wido den Hollander wrote: > > > Op 16-07-2021 om 21:46 schreef Kristaps Cudars: > > Hi Wido, > > > > Your proposal is to sacrifice ability to reassign IPv6 to instance, have > > internal domain prefix, and list/db in ACS what IPv6

Re: IPV6 in Isolated/VPC networks

2021-07-19 Thread Kristaps Cudars
Hi Wido, In context of size I would recommend sticking with RIPE guidelines. https://www.ripe.net/publications/docs/ripe-690 Reminder: /56 256 LAN segments /48 65,536 LAN segments Maybe it will sound counter intuitive but I’m also not excited about OSPFv3 or BGP on VR. As in our case it

Re: windows vm start error

2021-07-30 Thread Kristaps Cudars
Hello, Usually it indicates that installation media/iso is corrupted. Its polite toon to ask such questions in users mailing list. On 2021/07/30 10:37:20, "technologyrss.mail" wrote: > *Hi,* > > I install windows 10 vm but can't access. I see some error. > > What is issue? Please help me. >

Re: windows vm start error

2021-07-30 Thread Kristaps Cudars
10:50:41, "technologyrss.mail" wrote: > when windows installation done, > then I remove iso and reboot vm then I see this error. > > *--** > **Alamin* > > On 7/30/2021 4:46 PM, Kristaps Cudars wrote: > > Hello, > > > > Usually it indicates

Re: windows vm start error

2021-07-30 Thread Kristaps Cudars
_dvd_KVM\123.iso Oscdimg.exe -u2 -bC:\ \expandedSetup\boot\etfsboot.com -h C:\ \expandedSetup C:\ \Win7.iso On Fri, 30 Jul 2021 at 14:08, technologyrss.mail < technologyrss.m...@gmail.com> wrote: > *yes some is ok.* > > but how can I check > > iso contain correct drivers for h

Re: IPV6 in Isolated/VPC networks

2021-08-12 Thread Kristaps Cudars
gt; /64 network > > And voila all done! I create a domain record that points to my guest > VM IPv6 address a test webserver on > http://ipv6-isolated-ntwk-demo.yadav.cloud/ > > (Note: I'll get rid of the tunnel and request a new /48 block after a few > days, sharing

Re: IPV6 in Isolated/VPC networks

2021-08-17 Thread Kristaps Cudars
Hi Wei, Published this month’s RFC 9099 and explains in different words/perspective what has been written by Alex, Rohit and Wido. https://www.rfc-editor.org/rfc/rfc9099.html On 2021/08/17 09:20:21, Wei ZHOU wrote: > Hi Wido, > > (cc to Rohit and Alex) > > It is a good suggestion to use F

Re: IPV6 in Isolated/VPC networks

2021-09-08 Thread Kristaps Cudars
@cloudstack.apache.org > Subject: Re: IPV6 in Isolated/VPC networks > > Thanks Kristaps, Wido, Rohit and Alex for your replies. > > I am fine with not having stateful dhcpv6 and privacy extension/temporary > address in phase 1. If community decides not to do eventually , it

Asking this in dev as there are many fixes for volumes/snapshots on 4.15.2 and 4.16.0

2021-09-17 Thread Kristaps Cudars
4.15.1/Vmware When you create reoccurring volume snapshot task, instead of transferring only that volume all volumes that are associated with VM are transferred to secondary storage. Way how we find this is that we have some VM with 8~TB disks that should not be backed up and our secondary sto