Re: dhcrelay Can't find free bpf: No such file or directory

2013-01-08 Thread Loïc BLOT
if i'm not mistaken, it's Berkeley Packet Filter. I must do the same issue for dhcpd when i use many vlan interfaces and PF :) -- Cordialement, Loïc BLOT, UNIX systems, security and network expert http://www.unix-experience.fr Le mardi 08 janvier 2013 à 20:39 +0100, Ulrich Drolshagen a

Re: Disk accesses freeze for a lot of seconds

2013-01-06 Thread Loïc BLOT
I got same problem with squid when squid exit normally (/etc/rc.d/squid stop), when mass squid disk cache is written, there is a one min freeze on the server. (OpenBSD 5.2). The problem was also here under OpenBSD 5.1. CPU is also OK (10% of a big xeon quad). But for me softdeps aren't activated.

NMAP problem with PF

2013-01-04 Thread Loïc Blot
Hello, since OpenBSD 5.2 i have a problem with NMAP: Starting Nmap 6.01 ( http://nmap.org ) at 2013-01-04 11:47 CET route_dst_generic: Failed to obtain system routes: getsysroutes_dnet: sysroutes_dnet_find_interfaces() failed If i disable PF the problem isn't present. Do you have an idea ?

Re: NMAP problem with PF

2013-01-04 Thread Loïc BLOT
Hello, It's a simple nmap : Nmap -p 1688 a.b.c.d -PN Loic Blot Le 4 janv. 2013 à 12:14, Peter N. M. Hansteen pe...@bsdly.net a écrit : On Fri, Jan 04, 2013 at 12:09:10PM +0100, Lo?c Blot wrote: Hello, since OpenBSD 5.2 i have a problem with NMAP: Starting Nmap 6.01 ( http://nmap.org ) at

Re: NMAP problem with PF

2013-01-04 Thread Loïc Blot
Hmmm strange but with -- Best regards, Loïc BLOT, Engineering UNIX Systems, Security and Networks http://www.unix-experience.fr Le vendredi 04 janvier 2013 à 13:04 +0100, Loïc BLOT a écrit : Hello, It's a simple nmap : Nmap -p 1688 a.b.c.d -PN Loic Blot Le 4 janv. 2013 à

Re: NMAP problem with PF

2013-01-04 Thread Loïc Blot
Strange but with nmap -sT -p port server -PN it works. -- Best regards, Loïc BLOT, Engineering UNIX Systems, Security and Networks http://www.unix-experience.fr Le vendredi 04 janvier 2013 à 13:04 +0100, Loïc BLOT a écrit : Hello, It's a simple nmap : Nmap -p 1688 a.b.c.d -PN

High uptime load values but not high load

2013-01-03 Thread Loïc Blot
Hello, Since this morning is get a high uptime value for server load, but the server does nothing. It's our CARP backup gateway for our clients, and it stays in backup mode since few month. The CPU does nothing special, the gateway is waiting failover, the memory isn't used (3G/16G Ram), and disk

Re: High uptime load values but not high load

2013-01-03 Thread Loïc Blot
Thanks for your answer, it's sendmail which is waiting disk and forks himself... strange because i don't use sendmail, even if it was default activated -- Best regards, Loïc BLOT, Engineering UNIX Systems, Security and Networks http://www.unix-experience.fr Le jeudi 03 janvier 2013 à

Re: Running OpenBSD on Raspberry Pi

2012-12-31 Thread Loïc BLOT
It's a shame not to port OpenBSD on a Raspberry PI. I would like to a make a cheap firewall router box at home with this. The network card and the CPU is as better as an ISP box but it's more flexible. That's the cheapest solution for homing firewall, and we can add an USB wireless tool to get

Re: Various system freeze

2012-12-29 Thread Loïc BLOT
Hello, i got this problem with squid in the past. My problem was squid freeze all system when i restart him for 5 minutes when it's high loaded. The only solution i got at this moment was to kill -9 squid on restart, no freeze occurs. After those events, i try a new approach, i saw squid and

mistake on FAQ FR

2012-12-29 Thread Loïc BLOT
Hello, there is a little mistake on french FAQ here: http://www.openbsd.org/faq/fr/faq14.html We read: Vous utilisez le système et finissez par avoir pus de 504Mo de données dessus. and we must read Vous utilisez le système et finissez par avoir plus de 504Mo de données dessus. Have a nice

Re: carp both master

2012-12-17 Thread Loïc BLOT
You need one common VHID for each virtual IP, Stuart said all fixes you need. CARP protocol identify nodes by VHID. -- Cordialement, Loïc BLOT, UNIX systems, security and network expert http://www.unix-experience.fr Le lundi 17 décembre 2012 à 22:36 +, Stuart Henderson a écrit : On

OSPF + BGP routing loop

2012-12-12 Thread Loïc Blot
Hello to OpenBSD Community. I am testing OSPF + BGP dynamic routing. I'm happy to see OSPF learn BGP learnt routes natively. I have a problem with my default route. As you see Pala1 (one of the two main router) learn default route from 14.14.14.1 (which is my simulated backbone router). OSPF

Re: Hunning HA over multiple ARCH's

2012-12-04 Thread Loïc BLOT
Hi Joel, You can mix several architectures, that's not a problem for firewall and routers, IP is OS arch independant. The thing you must consider is packet processing. Some architectures are fast to process for packets than other (with equivalent perfs on paper). If you doesn't need low latency,

Re: No route to host

2012-11-27 Thread Loïc BLOT
Here is my rules (without macro table definitions which are before, sensible rules are hidden, but are in the same template as shown rules and same place) ## ## Options ## set skip on lo0 set block-policy drop set limit { states 5, frags 2, src-nodes 4, table-entries 60 } ##

No route to host

2012-11-26 Thread Loïc BLOT
Hello to OpenBSD users, i have a little problem, i think it's linked with PF, but i have no proofs. System is OpenBSD 5.1 but OpenBSD 5.2 get the same things (with different card, 5.1 uses bnx and 5.2 use em) I have a router with squid proxy, named and isc-dhcpd. The problem is, sometimes i get

Re: Support for BCM5720

2012-11-24 Thread Loïc BLOT
Hello all, Thanks stuart for this link, if we add this the card is recognized by the kernel, but does'nt work. You must import more source code from FreeBSD 9.3RC3 because PHY is not properly recognized. Moreover some other code paths aren't followed when you add only the mii code, because you

Support for BCM5720

2012-11-23 Thread Loïc Blot
Hi all, i have bought 2 new dell R320 serveurs to replace my old dell 1650 servers (7 years old). The problem is network card (unfortunately the machines will be routers/gateways). I tried to backport FreeBSD 9.1 RC3 driver, which works, but not totally succesful (card recognized, link negotiation

<    1   2