Siwei,

I met the another issue like the ipfilter which can't be enabled at once.
When I tried to enable stmf (COMSTAR) service, 
it ran into the "maintenance status",
there is one warning "svc-stmf: unable to load config" in the log.
But when I rebooted my system, the service of STMF is ok again.

It's very like the issue which I met the issuse for the ipfilter service.
So I think maybe the cause is for Xen on OpenSolaris,
because my OpenSolaris is running as the Xen dom0.

-Hejun


> Siwei,
> 
> When I rebooted my system, this issue for ipfilter
> can't be represented.
> But before I tried the ipfilter, I spent many time on
> installation of Xen and 
> Linux domU.
> Maybe the Xen affect the ipfilter service.
> I think your suggestion is the cause for this issue.
> I will test it when I install new OpenSolaris
> system.
> 
> Thanks
> 
> -Hejun
> 
> > <div id="jive-html-wrapper-div">
> > Hejun,<br><br>You may run into <a
> >
> href="http://bugs.opensolaris.org/bugdatabase/view_bug
> 
> > .do?bug_id=6893162"> 6893162</a>, I think you
> could
> > try out by enlarging the sleep duration in script
> > /lib/svc/share/ipf_include.sh:<br>
> > <br>service_check_state()<br>{<br>       
> > #<br>        # Make sure we&#39;re done with
> ongoing
> > state transition<br>        #<br>        while [
> > &quot;`svcprop -p restarter/next_state $1`&quot;
> !=
> > &quot;$SMF_NONE&quot; ]; do<br>
> >                 sleep 1<br>       
> > done<br><br>        [ &quot;`svcprop -p
> > restarter/state $1`&quot; = &quot;$2&quot; ]
> > &amp;&amp; return 0 || return
> > 1<br>}<br><br><br>-Siwei<br><br><div
> > class="gmail_quote">On Tue, Jan 19, 2010 at 10:02
> AM,
> > Hejun Xu <span dir="ltr">&lt;<a
> >
> href="mailto:xuhe...@gmail.com";>xuhe...@gmail.com</a>&
> 
> > gt;</span> wrote:<br>
> > <blockquote class="gmail_quote" style="margin: 0pt
> > 0pt 0pt 0.8ex; border-left: 1px solid rgb(204,
> 204,
> > 204); padding-left: 1ex;">I find the pfil is
> removed
> > from OpenSolaris 0906.<br>
> > &quot;pfil&quot; is one ipfilter module in Solaris
> > 10.<br>
> > <br>
> > Another friend sugguest me maybe the cause is my
> slow
> > CPU make the ipfilter service timeout.<br>
> > <br>
> > But I installed OpenSolaris 0906 on HP DL145G2
> > server, there is one AMD Opteron 2GHz CPU and 2GB
> > physical Memory.<br>
> > <br>
> > And there is no GUI assistant to help me config
> the
> > ipfilter on OpenSolaris.<br>
> > <br>
> > -Hejun<br>
> > <br>
> > <br>
> > &gt;<br>
> > &gt;<br>
> > &gt;  try if following steps work for you.<br>
> > &gt;  <br>
> > &gt; 0,#svcs -a|egrep &quot;pfil|ipf&quot;<br>
> > &gt; ????         svc:/network/pfil:default<br>
> > &gt; ????          
> svc:/network/ipfilter:default<br>
> > &gt;<br>
> > &gt; 1,#ifconfig -a<br>
> > &gt;<br>
> > &gt;   bge0:...<br>
> > &gt;<br>
> > &gt; 2,#vi /etc/ipf/pfil.ap<br>
> > &gt;  (uncomment bge #)<br>
> > &gt;  #...<br>
> > &gt;  bge    -1      0       pfil<br>
> > &gt;  #...<br>
> > &gt;<br>
> > &gt; 3,#vi  /etc/ipf/ipf.conf<br>
> > &gt;  block oracle in bge<br>
> > &gt;  pass sun in bge<br>
> > &gt;<br>
> > &gt; 4,#svcadm enable
> svc:/network/pfil:default<br>
> > &gt;   #svcadm enable
> > svc:/network/ipfilter:default<br>
> > &gt;<br>
> > &gt; 5,#svcs pfil<br>
> > &gt;   #svcs ipfilter<br>
> > &gt;<br>
> > &gt; 6,#ipfstat -ionh<br>
> > &gt;<br>
> > &gt;<br>
> > &gt; reference:<br>
> > &gt; <a
> >
> href="http://docs.sun.com/app/docs/doc/816-4554/gdwvu?
> 
> > a=view"
> >
> target="_blank">http://docs.sun.com/app/docs/doc/816-4
> 
> > 554/gdwvu?a=view</a><br>
> > &gt; <a
> >
> href="http://blogs.sun.com/tonyn/entry/firewall_config
> 
> > uratio"
> >
> target="_blank">http://blogs.sun.com/tonyn/entry/firew
> 
> > all_configuratio</a><br>
> > &gt; n_in_opensolaris_2009<br>
> > &gt;<br>
> > &gt;<br>
> > &gt;<br>
> > &gt; &gt; Date: Thu, 14 Jan 2010 23:05:23
> -0800<br>
> > &gt; &gt; From: <a
> >
> href="mailto:xuhe...@gmail.com";>xuhe...@gmail.com</a><
> 
> > br>
> > &gt; &gt; To: <a
> >
> href="mailto:ug-bjo...@opensolaris.org";>ug-bjo...@open
> 
> > solaris.org</a><br>
> > &gt; &gt; Subject: [ug-bjosug] To make the
> ipfilter
> > available<br>
> > &gt; must reboot the system?<br>
> > <div class="im">&gt; &gt;<br>
> > &gt; &gt; Dear all,<br>
> > &gt; &gt;<br>
> > &gt; &gt; I tried to enable the firewall on my
> > OpenSolaris<br>
> > &gt; 0906.<br>
> > &gt; &gt; I followed the guide to do the belew
> > step:<br>
> > &gt; &gt;<br>
> > &gt; &gt; $ svcadm enable network/ipfilter<br>
> > &gt; &gt; $ svccfg -s network/ipfilter:default
> > setprop<br>
> > &gt; firewall_config_default/policy = astring:
> > allow<br>
> > &gt; &gt; $ svcadm refresh network/ipfilter<br>
> > &gt; &gt;<br>
> > &gt; &gt; but the ipfilter is always in
> maintenance
> > stage.<br>
> > &gt; &gt;<br>
> > &gt; &gt; I had to reboot my system,then the
> ipfilter
> > is<br>
> > &gt; online.<br>
> > &gt; &gt;<br>
> > &gt; &gt; I don&#39;t know whether there is a
> > bug.<br>
> > &gt; &gt;<br>
> > &gt; &gt; -Hejun<br>
> > &gt; &gt; --<br>
> > &gt; &gt; This message posted from <a
> > href="http://opensolaris.org";
> > target="_blank">opensolaris.org</a><br>
> > &gt;<br>
> > </div>&gt;
> >
> ______________________________________________________
> 
> > <br>
> > &gt; __________<br>
> > &gt; Hotmail: Powerful Free email with security
> > by<br>
> > &gt; Microsoft.<br>
> > &gt; <a
> >
> href="http://clk.atdmt.com/GBL/go/196390710/direct/01/
> 
> > "
> >
> target="_blank">http://clk.atdmt.com/GBL/go/196390710/
> 
> > direct/01/</a><br>
> > <div><div></div><div class="h5">--<br>
> > This message posted from <a
> > href="http://opensolaris.org";
> > target="_blank">opensolaris.org</a><br>
> >
> _______________________________________________<br>
> > networking-discuss mailing list<br>
> > <a
> >
> href="mailto:networking-discuss@opensolaris.org";>netwo
> 
> >
> rking-disc...@opensolaris.org</a></div></div></blockqu
> 
> > ote></div><br>
> > 
> >
> </div>_______________________________________________
> > networking-discuss mailing list
> > networking-discuss@opensolaris.org
-- 
This message posted from opensolaris.org
_______________________________________________
networking-discuss mailing list
networking-discuss@opensolaris.org

Reply via email to