Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-22 Thread Alan Altmark
On Friday, 04/22/2016 at 04:50 GMT, Offer Baruch wrote: > If you make sure you have NATIVE NONE and keep track of your grants (just > like PORTBASED) there is no real security concern... > The guest is only allowed the vlans you grant it (just like PORTBASED) and > he cant send any untagged fra

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-22 Thread Offer Baruch
So, If you make sure you have NATIVE NONE and keep track of your grants (just like PORTBASED) there is no real security concern... The guest is only allowed the vlans you grant it (just like PORTBASED) and he cant send any untagged frames. I would rather manage a USERBASED VSWITCH with trunks over

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-22 Thread Alan Altmark
On Friday, 04/22/2016 at 07:07 GMT, Offer Baruch wrote: > Can you please explain what is the problem with linux working in trunk mode? > What security problem are you talking about? An untrusted server should not be on a trunk port. Ever. A trunk can also carry untagged frames, and those fra

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-22 Thread Offer Baruch
Alan, Can you please explain what is the problem with linux working in trunk mode? What security problem are you talking about? Thanks Offer Baruch On Apr 22, 2016 8:00 AM, "Alan Altmark" wrote: > On Friday, 04/22/2016 at 02:41 GMT, Grzegorz Powiedziuk > wrote: > > > > 3. Less common, useful in

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Alan Altmark
On Friday, 04/22/2016 at 02:41 GMT, Grzegorz Powiedziuk wrote: > > 3. Less common, useful in some cases - OSA is plugged into "trunk" port on > real switch and in general same as (2). But, when you do grant, you can say > that this specific grant should act as "porttype trunk" (and you specify

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Grzegorz Powiedziuk
2016-04-21 16:29 GMT-04:00 Mark Post : > >>> On 4/21/2016 at 03:38 PM, Grzegorz Powiedziuk > wrote: > -snip- > > I believe Mark said that having linux to handle vlan tagging is hard. > > > > But what you are trying to do is different. In your case, vswitch is > > removing/adding vlan tags from/to

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Mark Post
>>> On 4/21/2016 at 04:38 PM, Alan Altmark wrote: > On Thursday, 04/21/2016 at 07:39 GMT, Grzegorz Powiedziuk > wrote: >> I believe Mark said that having linux to handle vlan tagging is hard. > > There is nothing difficult about getting Linux to perform VLAN tagging. > The question is not one

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Alan Altmark
On Thursday, 04/21/2016 at 07:39 GMT, Grzegorz Powiedziuk wrote: > I believe Mark said that having linux to handle vlan tagging is hard. There is nothing difficult about getting Linux to perform VLAN tagging. The question is not one of capability, but of network security management. > In your

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Mark Post
>>> On 4/21/2016 at 03:38 PM, Grzegorz Powiedziuk >>> wrote: -snip- > I believe Mark said that having linux to handle vlan tagging is hard. > > But what you are trying to do is different. In your case, vswitch is > removing/adding vlan tags from/to frames on the fly. If Grzegorz is correct in

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Grzegorz Powiedziuk
2016-04-21 14:52 GMT-04:00 Dave Myers : > Since Mark has told us that what we're attempting to do is not supported > by the RAM system...I'll close this thread and thank you all for your > feedback. > > I do have one last question for Alan. > > In this statement does the VLAN AWARE specify TRUNKIN

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Alan Altmark
On Thursday, 04/21/2016 at 06:59 GMT, Dave Myers wrote: > I do have one last question for Alan. > > In this statement does the VLAN AWARE specify TRUNKING to the uplink OSA ? > If not what is the difference between what we coded VLAN 229 and VLAN AWARE? > > DEFINE VSWITCH VSW1 RDEV 400.P1 VL

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-21 Thread Dave Myers
difference between what we coded VLAN 229 and VLAN AWARE? DEFINE VSWITCH VSW1 RDEV 400.P1 VLAN AWARE NATIVE NONE Thanks, Dave From: Dave Myers Sent: Wednesday, April 20, 2016 10:37 PM To: 'linux-390@VM.MARIST.EDU' Subject: RE: Install not working for SLES11 SP4 thru TRUNKE

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Mark Post
>>> On 4/20/2016 at 10:28 PM, Dave Myers wrote: > VLAN def in system config is: > define vswitch vsw1 rdev 400.p1 vlan 229 It's been a while since I played with this stuff, but one thing I know for sure: If the Linux guest has to be aware of which VLAN(s) it's supposed to be seeing, that is n

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Marcy Cortes
Not sure why I was unreadable but Alan covered me and more Marcy -Original Message- From: Alan Altmark [alan_altm...@us.ibm.com] Sent: Wednesday, April 20, 2016 10:56 PM Central Standard Time To: LINUX-390@VM.MARIST.EDU Subject: Re: [LINUX-390] Install no

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Alan Altmark
On Thursday, 04/21/2016 at 02:29 GMT, Dave Myers wrote: > VLAN def in system config is: > define vswitch vsw1 rdev 400.p1 vlan 229 Gaaack! Please use DEFINE VSWITCH VSW1 RDEV 400.P1 VLAN AWARE NATIVE NONE Have your switch admin verify that o The port 400.P1 is plugged into is conf

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Dave Myers
Hi all, I appreciate your help..please keep suggestions coming. Marcy, the last post from you was not readable on the list. Thanks, Dave From: Dave Myers Sent: Wednesday, April 20, 2016 9:29 PM To: 'linux-390@VM.MARIST.EDU' Subject: RE: Install not working for SLES11 SP4 thru TRUNK

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Marcy Cortes
mputer Solutions | www.siriuscom.com<http://www.siriuscom.com/> 10100 Reunion Place, Suite 500, San Antonio, TX 78216 From: Dave Myers Sent: Wednesday, April 20, 2016 8:56 PM To: 'linux-390@VM.MARIST.EDU' Subject: RE: Install not working for SLES11 SP4 thru TRUNKED VSWITCH The de

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Dave Myers
iuscom.com<http://www.siriuscom.com/> 10100 Reunion Place, Suite 500, San Antonio, TX 78216 From: Dave Myers Sent: Wednesday, April 20, 2016 8:56 PM To: 'linux-390@VM.MARIST.EDU' Subject: RE: Install not working for SLES11 SP4 thru TRUNKED VSWITCH The define VSWITCH and the COU

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Alan Altmark
On Thursday, 04/21/2016 at 01:56 GMT, Dave Myers wrote: > The define VSWITCH and the COUPLE both produce no errors. That part looks good. > Yes. We are using this VLAN for some z/OS interfaces, so it is not new. > > The SLES11SP4 EXEC does not show any errors. > The only message we get, after a

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Dave Myers
The define VSWITCH and the COUPLE both produce no errors. That part looks good. Yes. We are using this VLAN for some z/OS interfaces, so it is not new. The SLES11SP4 EXEC does not show any errors. The only message we get, after a 1-2 minute hang in the SLES11SP4 EXEC is: " unable to find ... repo

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Marcy Cortes
Is anything else on your vswitch working or is this a new set up? We run trunked ports and use the vlan on the grant statement with SP4 so that isn't an issue. What messages are you getting?Did you get your default route right? -Original Message- From: Linux on 390 Port [mailto:L

Re: Install not working for SLES11 SP4 thru TRUNKED VSWITCH

2016-04-20 Thread Scott Rohling
What happens when you 'CP COUPLE nicaddress TO SYSTEM vswitchname' from this guests console? If there's an error it may help troubleshoot.. You need to ensure you're connected to the VSWITCH -- does CP Q VSWITCH vswitchname DETAILS show this guest connected? Scott Rohling On Wed, Apr 20, 2016