Upcoming FreeBSD releases...
Hi, I`m trying to make little schedule for upgrading and wanted to know when approximate will be new FreeBSD releases... How I understand in few weeks must be FreeBSD 5.5 release, but I can`t find schedule for upcoming 5.5 version... Or it is delayed? Or in few weeks will be maybe sooner 6.0 version of FreeBSD? Only information what I can find: http://www.freebsd.org/releng/index.html#schedule But I`m not sure what is status, maybe somebody can coment... thanx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Virtual network device for jail...
Hi, Can somebody maybe suggest me how to make some virtual network device for jail ip aliases? How I understand if I have one network card, I can`t use nat, etc... thnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Re: Virtual network device for jail...
I tryed to put in rc.conf: cloned_interfaces=lo1 I think that is something that I wanted, only can somebody point me to some manual about that, what realy is cloned and how to do it manualy at cli. tnx, Casper Casper wrote: Hi, Can somebody maybe suggest me how to make some virtual network device for jail ip aliases? How I understand if I have one network card, I can`t use nat, etc... thnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED] ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Jail error ln operation not permitted
Hi, I have setup 2 jails in FreeBSD 5.4 when they start, abouth have some error for /dev/log... like that: #jail /jail/mail/ mail 127.0.0.2 /bin/sh /etc/rc Loading configuration files. mail Setting hostname: mail. ln: /dev/log: Operation not permitted Starting syslogd. ... Abouth jails seems to work ok, but I can`t debug them from logs or somewhere, where is problem... what is that? tnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Re: Jail error ln operation not permitted
I don`t know what this script doing... :) I don`t know what to try reproduce by myself... ln /dev/log ? Casper Bernhard Fischer wrote: On Tuesday 28 June 2005 19:24, Casper wrote: Hi, I have setup 2 jails in FreeBSD 5.4 when they start, abouth have some error for /dev/log... like that: #jail /jail/mail/ mail 127.0.0.2 /bin/sh /etc/rc Loading configuration files. mail Setting hostname: mail. ln: /dev/log: Operation not permitted Starting syslogd. ... Abouth jails seems to work ok, but I can`t debug them from logs or somewhere, where is problem... what is that? tnx, Casper Try creating the link from outside the jail. Regards, bh ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Ata 1 master failure
Hi, I just got new acer server where I installed FreeBSD: FreeBSD www.ass.lv 5.4-RELEASE-p4 FreeBSD 5.4-RELEASE-p4 #2: Wed Jul 13 00:57:45 and after reboot I got in dmesg: ad0: 190782MB SAMSUNG SP2014N/VC100-30 [387621/16/63] at ata0-master UDMA100 ata1-master: FAILURE - ATA_IDENTIFY status=7fREADY,DMA_READY,DSC,DRQ,CORRECTABLE,INDEX,ERROR error=7fUNCORRECTABLE,MEDIA_CHANGED,NID_NOT_FOUND,MEDIA_CHANGE_REQEST,ABORTED,NO_MEDIA,ILLEGAL_LENGTH LBA=0 ata1-master: FAILURE - ATA_IDENTIFY status=7fREADY,DMA_READY,DSC,DRQ,CORRECTABLE,INDEX,ERROR error=7fUNCORRECTABLE,MEDIA_CHANGED,NID_NOT_FOUND,MEDIA_CHANGE_REQEST,ABORTED,NO_MEDIA,ILLEGAL_LENGTH LBA=0 ata1-master: FAILURE - ATA_IDENTIFY timed out ata1-master: FAILURE - ATA_IDENTIFY timed out acd0: DVDROM DVD-ROM DVD-16X6S/DSR2 at ata1-slave PIO4 ad4: 190782MB WDC WD2000JD-22HBB0/08.02D08 [387621/16/63] at ata2-master SATA150 ad6: 190782MB WDC WD2000JD-22HBB0/08.02D08 [387621/16/63] at ata3-master SATA150 So how I understand I have some problem with some failure... Google didn`t help match. So my question is does it is some sw problem or hw? Maybe somebody can say how to debug it? tnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
FreeBSD 5.x raid...
Hi, I have web server with one ata system disk and two sata disks for www stuff... I wanted to make that all www stuff is on one sata disk and mirror (backups) it to second disk if first sata brakes... So I have little experience with vinum (one samba server vinum raid5 working ok without problem) so I wanted to make on www server with vinum raid1... But something not working: dmesg: ad4: 190782MB WDC WD2000JD-22HBB0/08.02D08 [387621/16/63] at ata2-master SATA150 ad6: 190782MB WDC WD2000JD-22HBB0/08.02D08 [387621/16/63] at ata3-master SATA150 #cat www.vinum drive a device /dev/ad4c drive b device /dev/ad6c volume www plex org raid1 512k sd length 165g drive a sd length 165g drive b [EMAIL PROTECTED] vinum create -f www.vinum 4: plex org raid1 512k ** 4 Invalid plex organization: Invalid argument 5: sd length 165g drive a ** 5 Unnamed sd is not associated with a plex: Invalid argument 6: sd length 165g drive b ** 6 Unnamed sd is not associated with a plex: Invalid argument 2 drives: D a State: up /dev/ad4c A: 190782/190782 MB (100 %) D b State: up /dev/ad6c A: 190782/190782 MB (100 %) 1 volumes: V www State: down Plexes: 0 Size: 0 B 0 plexes: 0 subdisks: What is problem? Casper P.S. I have googled problem and found: http://lists.freebsd.org/pipermail/freebsd-questions/2005-May/088698.html there ppl is saying that they don`t like in 5.x vinum, any better sugestion? I have no coplains about vinum raid5 on 5.3 samba server, it works good.. :) ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Re: FreeBSD 5.x raid...
David Kelly wrote: On Thu, Jul 14, 2005 at 03:55:38PM +0200, FreeBSD questions mailing list wrote: 'plex org raid1 512k' is invalid you should use: 'plex org concat' Uh, he wants all data on one SATA drive and a mirror on the other. Therefore he does not want to concat but to mirror. The man page examples often complicatate things by concating some drives then mirroring the concated. Yep, thanx, I have changed: drive a device /dev/ad4c drive b device /dev/ad6c volume www plex org mirror sd length 165g drive a sd length 165g drive b but: vinum create -f www.vinum 4: plex org mirror ** 4 Invalid plex organization: Invalid argument 5: sd length 165g drive a ** 5 Unnamed sd is not associated with a plex: Invalid argument 6: sd length 165g drive b ** 6 Unnamed sd is not associated with a plex: Invalid argument 2 drives: D a State: up /dev/ad4c A: 190782/190782 MB (100%) D b State: up /dev/ad6c A: 190782/190782 MB (100%) 1 volumes: V www State: down Plexes: 0 Size: 0 B 0 plexes: 0 subdisks: Vinum is flaky on 5.x, while gvinum works pretty good. Others have suggested the future is brighter with the RAID functions in GEOM but I'm not yet ready to experiment with my 300G gvinum slice. I never quite figured out the manual method of configuring [g]vinum. The SIMPLIFIED CONFIGURATION section of the manual got me running. I think this how he would want to do it. There isn't a gvinum man page. Gvinum (GEOM vinum) lacks complete vinum functionality but I don't know what. First, I don't think its wise to use partition c. Use sysinstall to create the single largest partition possible and it'll be on d. Partition c has special meaning and many times its used because the device driver fakes a disk label with c when a real disk label is missing. If the driver is always able to fake a correct and identical label then you are fine, but its better to write a real one on disk. Creating a gvinum mirror is as simple as this: # gvinum mirror -v /dev/ad4d /dev/ad6d Might need: # gvinum start Then edit /etc/rc.d./vinum and add the g to this line thusly: start_cmd=gvinum start Your new slice will probably be /dev/gvinum/vinum0, so edit /etc/fstab appropriately. The slice should be ready for newfs, and then mounting. Be sure to add this to /etc/rc.conf: start_vinum=YES ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Re: FreeBSD 5.x raid...
I can`t find gvinum man on my 5.4 and in google too :) I`m thinking for my server better tool is gmirror? Casper David Kelly wrote: On Thu, Jul 14, 2005 at 09:49:07AM -0500, David Kelly wrote: Uh, he wants all data on one SATA drive and a mirror on the other. Therefore he does not want to concat but to mirror. The man page examples often complicatate things by concating some drives then mirroring the concated. Speaking to the archives something that slipped by me is that normally one creates two concat style plexes and _then_ mirrors the plexes. This way the plex can be edited on a running system, drives substituted. The simplified version of [g]vinum mirror command automagically creates a configuration as described above even when only 2 drives are involved. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Delete files in directory...
Hi, Sorry, simple, stupid q. How to make that what come in directory /usr/files/ for example are erased? Or only put in cron after while do rm /usr/files/*? tnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
jail networking
Hi, I have problem with setuping network to jail... I have #uname -a FreeBSD gam.zuze.lv 5.4-RELEASE-p5 FreeBSD Wed Jul 20 19:52:44 EEST 2005 and installed jail on it... sysctl: net.inet.ip.forwarding: 1 security.jail.set_hostname_allowed: 1 security.jail.socket_unixiproute_only: 1 security.jail.sysvipc_allowed: 0 security.jail.getfsstatroot_only: 1 security.jail.allow_raw_sockets: 1 security.jail.chflags_allowed: 0 security.jail.jailed: 0 from host ping: # ping www.google.lv PING www.l.google.com (216.239.59.104): 56 data bytes 64 bytes from 216.239.59.104: icmp_seq=0 ttl=245 time=64.608 ms 64 bytes from 216.239.59.104: icmp_seq=1 ttl=245 time=65.198 ms 2 packets transmitted, 2 packets received, 0% packet loss from jail: jail# ping www.google.lv PING www.l.google.com (216.239.59.99): 56 data bytes ^C --- www.l.google.com ping statistics --- 3 packets transmitted, 0 packets received, 100% packet loss but traceroute from jail show every second packet: 4 latnet.to.lattelekom.lv (195.13.173.221) 4.324 ms * 4.810 ms 5 * so-4-0-0-war1.lnt.cw.net (166.63.222.101) 54.223 ms * 6 so-7-0-0-zcr2.lnt.cw.net (166.63.222.42) 72.205 ms * 54.778 ms 7 * 195.66.226.125 (195.66.226.125) 90.496 ms * 8 216.239.46.173 (216.239.46.173) 54.711 ms * 54.204 ms 9 * 216.239.49.254 (216.239.49.254) 64.939 ms * 10 216.239.49.121 (216.239.49.121) 67.530 ms * 216.239.49.114 (216.239.49.114) 68.128 ms 11 * 216.239.59.103 (216.239.59.103) 64.615 ms * From jail I can ping router and local network ips... My pf.conf: ext_if=rl0 int_if=rl1 internal_net=172.22.1.0/24 external_addr=xx.xx.xx.xx table foo { 10.0.0.0/8, 127.0.0.0/8, 172.22.0.0/24, 192.168.0.0/24 } set loginterface $ext_if set block-policy return scrub in all nat on $ext_if from $internal_net to any - ($ext_if) pass in all pass out all pass in on $ext_if proto tcp from any to $ext_if port 22 keep state pass out on $ext_if proto { tcp, udp } all keep state pass in on $ext_if proto { tcp, udp } from any to foo port 80 keep state pass out on $ext_if from 192.168.0.0/24 to any keep state queue developers pass out on $ext_if from 192.168.1.0/24 to any keep state queue marketing There is some manual about jail networking? I don`t understand why not working jail network if I can ping router from jail, routes ok and traceroute strange packets... tnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Re: jail networking
I played little more: jail# ping www.google.lv PING www.l.google.com (216.239.59.104): 56 data bytes ^C --- www.l.google.com ping statistics --- 4 packets transmitted, 0 packets received, 100% packet loss jail# ping 216.239.59.104 PING 216.239.59.104 (216.239.59.104): 56 data bytes 64 bytes from 216.239.59.104: icmp_seq=0 ttl=245 time=64.629 ms 64 bytes from 216.239.59.104: icmp_seq=1 ttl=245 time=63.744 ms ^C --- 216.239.59.104 ping statistics --- 2 packets transmitted, 2 packets received, 0% packet loss With host ping not working, and seems that dns is working ok, becouse it resolving ip and with ip network working... :) Anybody can say what is the problem? :) Casper Casper wrote: Hi, I have problem with setuping network to jail... I have #uname -a FreeBSD gam.zuze.lv 5.4-RELEASE-p5 FreeBSD Wed Jul 20 19:52:44 EEST 2005 and installed jail on it... sysctl: net.inet.ip.forwarding: 1 security.jail.set_hostname_allowed: 1 security.jail.socket_unixiproute_only: 1 security.jail.sysvipc_allowed: 0 security.jail.getfsstatroot_only: 1 security.jail.allow_raw_sockets: 1 security.jail.chflags_allowed: 0 security.jail.jailed: 0 from host ping: # ping www.google.lv PING www.l.google.com (216.239.59.104): 56 data bytes 64 bytes from 216.239.59.104: icmp_seq=0 ttl=245 time=64.608 ms 64 bytes from 216.239.59.104: icmp_seq=1 ttl=245 time=65.198 ms 2 packets transmitted, 2 packets received, 0% packet loss from jail: jail# ping www.google.lv PING www.l.google.com (216.239.59.99): 56 data bytes ^C --- www.l.google.com ping statistics --- 3 packets transmitted, 0 packets received, 100% packet loss but traceroute from jail show every second packet: 4 latnet.to.lattelekom.lv (195.13.173.221) 4.324 ms * 4.810 ms 5 * so-4-0-0-war1.lnt.cw.net (166.63.222.101) 54.223 ms * 6 so-7-0-0-zcr2.lnt.cw.net (166.63.222.42) 72.205 ms * 54.778 ms 7 * 195.66.226.125 (195.66.226.125) 90.496 ms * 8 216.239.46.173 (216.239.46.173) 54.711 ms * 54.204 ms 9 * 216.239.49.254 (216.239.49.254) 64.939 ms * 10 216.239.49.121 (216.239.49.121) 67.530 ms * 216.239.49.114 (216.239.49.114) 68.128 ms 11 * 216.239.59.103 (216.239.59.103) 64.615 ms * From jail I can ping router and local network ips... My pf.conf: ext_if=rl0 int_if=rl1 internal_net=172.22.1.0/24 external_addr=xx.xx.xx.xx table foo { 10.0.0.0/8, 127.0.0.0/8, 172.22.0.0/24, 192.168.0.0/24 } set loginterface $ext_if set block-policy return scrub in all nat on $ext_if from $internal_net to any - ($ext_if) pass in all pass out all pass in on $ext_if proto tcp from any to $ext_if port 22 keep state pass out on $ext_if proto { tcp, udp } all keep state pass in on $ext_if proto { tcp, udp } from any to foo port 80 keep state pass out on $ext_if from 192.168.0.0/24 to any keep state queue developers pass out on $ext_if from 192.168.1.0/24 to any keep state queue marketing There is some manual about jail networking? I don`t understand why not working jail network if I can ping router from jail, routes ok and traceroute strange packets... tnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED] ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
gmirror synchronization...
Hi, I have setuped two disks for mirror: #gmirror label -v -b round-robin www-mirror /dev/ad6 #gmirror insert www-mirror /dev/ad4 after reboot it not mounting nad synchronizing ~ 1% in minute... #gmirror list Geom name: www-mirror State: DEGRADED Components: 2 Balance: round-robin Slice: 4096 Flags: NONE GenID: 0 SyncID: 1 ID: 2896798894 Providers: 1. Name: mirror/www-mirror Mediasize: 200049647104 (186G) Sectorsize: 512 Mode: r1w0e0 Consumers: 1. Name: ad6 Mediasize: 200049647616 (186G) Sectorsize: 512 Mode: r1w1e1 State: ACTIVE Priority: 0 Flags: NONE GenID: 0 SyncID: 1 ID: 1503457719 2. Name: ad4 Mediasize: 200049647616 (186G) Sectorsize: 512 Mode: r1w1e1 State: SYNCHRONIZING Priority: 0 Flags: DIRTY, SYNCHRONIZING GenID: 0 SyncID: 1 Synchronized: 3% ID: 564911442 Why so long if there is only ~7mb on disk yet... How to properly start and mount after reboot it? tnx, C. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Fbsd 5.4rc3 sshd in jail won`t start
Hi, I setup jail in 5.4rc3 with all last updates. I have problem that jail won`t start sshd.: # jls JID IP Address Hostname Path 1 192.168.10.1mail /jail/mail # ps ax | grep J 432 ?? SsJ0:00.01 /usr/sbin/syslogd -ss 484 ?? SsJ0:00.01 /usr/sbin/cron -s I have configured rc.conf in jail to start sshd at boot and sshd_config that it listen only 192.168.10.1 ip. # jexec 1 /usr/sbin/sshd PRNG is not seeded I readed that there must be in kernel device random, what I have. But I don`t have in jail dev directory rand* or smth. I have readed many times many Jail how to, but could not understand why jail won`t start sshd. Can somebody help? thanks, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
FreeBSd 6.1 hylafax and Acorp modem...
Hi, I tryed to setup hylafax fax server with Acorp internal modem with conexant-RH56D-PCI chip set. I installed from ports hylafax and try to setup it: fax# faxsetup Setup program for HylaFAX (tm) 4.2.5. Created for i386-unknown-freebsd6.1 on Wed Mar 15 17:04:26 UTC 2006. Checking system for proper client configuration. Checking system for proper server configuration. Warning: /bin/vgetty does not exist or is not an executable program! The file: /bin/vgetty does not exist or this file is not an executable program. The HylaFAX software optionally uses this program and the fact that it does not exist on the system is not a fatal error. If the program resides in a different location and you do not want to install a symbolic link for /bin/vgetty that points to your program then you must reconfigure and rebuild HylaFAX from source code. Warning: /bin/egetty does not exist or is not an executable program! The file: /bin/egetty does not exist or this file is not an executable program. The HylaFAX software optionally uses this program and the fact that it does not exist on the system is not a fatal error. If the program resides in a different location and you do not want to install a symbolic link for /bin/egetty that points to your program then you must reconfigure and rebuild HylaFAX from source code. Warning: Font metric information files were not found! The font metric information file for the Courier font was not found in the /usr/local/lib/afm path. This means that client HylaFAX applications that use this information to format ASCII text for submission as fax will use incorrect information and generate potentially illegible facsimile. If font metric information is present on your system in a directory other than /usr/local/lib/afm then you can setup a symbolic link to the appropriate directory or you can specify the appropriate pathname in the configuration file /usr/local/lib/fax/hyla.conf with a line of the form: FontPath: someplace_unexpected If you do not have the font metric information files loaded on your system system you can obtain them by public FTP from the place where you obtained the HylaFAX software or from the master FTP site at ftp.sgi.com. FATAL ERROR: /usr/local/bin/gs does not exist or is not an executable program! The file: /usr/local/bin/gs does not exist or this file is not an executable program. The HylaFAX software expects this program to exist and be in this location. If the program resides in a different location then you must either reconfigure and rebuild HylaFAX or override the default pathnames in the distributed software through one of the HylaFAX configuration files (consult the HylaFAX documentation). So one problem, by default it has not in dependency list getty and ghostscript... I tried to install mgetty and found that there is no /dev/cuaa1. I`m in dead end with this modem? tnx, Casper ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
Re: FreeBSd 6.1 hylafax and Acorp modem...
Thnx, Company already bought it :/ I try to get mwavem pkg to test it. In ports I found why I not find pkg: [EMAIL PROTECTED] /usr/ports/comms/mwavem]# make === mwavem-fbsd-1.2_2 is marked as broken: Does not compile (bad C code). *** Error code 1 Stop in /usr/ports/comms/mwavem. How I understand mwavem is not supported for 6.1. Mikhail Goriachev wrote: Casper wrote: Hi, I tryed to setup hylafax fax server with Acorp internal modem with conexant-RH56D-PCI chip set. [...] I`m in dead end with this modem? Hi, Conexant chips are winmodems. As far as I'm concerned they're a no go. For instance, Lucent LTs are supported through ports. I recommend finding real hardware-based internal modem or anything external with RS232 connection. http://www.freebsd.org/doc/en_US.ISO8859-1/books/faq/compatibility-networking.html#SUPPORT-WINMODEM Cheers, Mikhail. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
6.1 missing device cuaa ?
Hi, I wanted to setup hylafax and find problem, that there is no device cuaa... %uname -a FreeBSD Test 6.1-RELEASE FreeBSD 6.1-RELEASE #0: Sun May 7 04:32:43 UTC 2006 [EMAIL PROTECTED]:/usr/obj/usr/src/sys/GENERIC i386 %ls /dev/cua* /dev/cuad0 /dev/cuad0.init /dev/cuad0.lock In my older computer: FreeBSD sadkis.lv 5.4-RELEASE-p7 FreeBSD 5.4-RELEASE-p7 #0: Fri Sep 9 12:47:55 EEST 2005 [EMAIL PROTECTED]:/usr/src/sys/i386/compile/SADKIS i386 [EMAIL PROTECTED] ls /dev/cua* /dev/cuaa0 /dev/cuaia0 /dev/cuala0 /dev/cuaa1 /dev/cuaia1 /dev/cuala1 Is device name changed? tnx, K. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]
FreeBSD 5.4 router with pf nat, bug?
Hi, I have 5.4-RELEASE-p6 test router and I wanted to do all routing/fw with pf, to learn more pf... I have added to kernel options: device pf device pflog device pfsync options ALTQ Setuped jails with 172.22.x.x address and local network I have 192.168.x.x addreses... ifconfig rl0 is real ip and maped jails... rl1 is internal network... /etc/pf.conf now looks like: - ext_if=rl0 int_if=rl1 set state-policy if-bound set loginterface $ext_if scrub reassemble tcp fragment reassemble nat on $ext_if from 172.1.1.1/8 to any - ($ext_if) nat on $ext_if from 192.168.1.1/8 to any - $ext_if rdr on $ext_if proto tcp from any to 159.148.155.14 port 8080 - 172.22.1.2 port www antispoof log quick for $ext_if inet antispoof log quick for $int_if inet block in log quick on $ext_if inet from any to ! ($ext_if) pass quick on lo0 all pass in on $ext_if inet proto tcp from any to ($ext_if) port ssh flags S/SA synproxy state --- The problem is when I make conection from jail or internal network, any conection http, ping, etc first package goes trought and got reply, second no... like: # traceroute www.ass.lv traceroute to www.ass.lv (195.13.160.54), 64 hops max, 40 byte packets 1 my_router (my_router) 0.166 ms 0.143 ms 0.130 ms 2 * next_router (next_router) 1.274 ms * 3 titan-v12-gw.latnet.lv (159.148.13.150) 1.970 ms * 1.992 ms 4 * 80.232.230.89 (80.232.230.89) 2.205 ms * From my_router all working ok: 1 next_router (next_router) 1.331 ms 0.962 ms 1.037 ms 2 titan-v12-gw.latnet.lv (159.148.13.150) 1.287 ms 0.757 ms 1.660 ms 3 80.232.230.89 (80.232.230.89) 1.218 ms 2.233 ms 1.352 ms So only nat`ed packages every second get lost... with tcpdump and pf loging all shows that nothing is blocking them... Any idea what is going on or how to test where is problem? tnx, K. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to [EMAIL PROTECTED]