Re: OpenBSD 7.3 ixl SIOCSIFMEDIA: Operation not supported

2023-06-28 Thread Rachel Roch
28 Jun 2023, 19:35 by z...@philomathiclife.com: > On 6/28/23 14:03, Rachel Roch wrote: > >> Running "doas ifconfig ixl3 media 10GbaseLR" gives me "SIOCSIFMEDIA: >> Operation not supported" and I'm not sure why. >> > > I don't have time to re-test this now, but I will when I do. I have an >

Re: OpenBSD 7.3 ixl SIOCSIFMEDIA: Operation not supported

2023-06-28 Thread Zack Newman
On 6/28/23 14:03, Rachel Roch wrote: Running "doas ifconfig ixl3 media 10GbaseLR" gives me "SIOCSIFMEDIA: Operation not supported" and I'm not sure why. I don't have time to re-test this now, but I will when I do. I have an Intel X710-DA2 flashed with the most recent firmware-the same firmware

OpenBSD 7.3 and some old IA32 CPUs

2023-06-28 Thread Anton Borisov
Hi all, here's sysctl extracts from Rise iDragon, IDT WinChip C6/2A running OpenBSD 7.3. All seems quite stable. P.S. Although Rise CPU is detected dmesg shows only generic info about it: cpu0: RiseRiseRise (586-class) 201 MHz, 05-02-01 cpu0: FPU,TSC,MMX compare it with IDT's CPU: cpu0: IDT

Re: access rdomain0 localhost from rdomainN

2023-06-28 Thread Stuart Henderson
On 2023/06/28 10:37, Zack Newman wrote: > On 2023-05-15, Stuart Henderson wrote: > > pass out quick on rdomain 2 to 127.0.0.1 nat-to 127.0.0.1 rtable 0 > > Not sure what the proper etiquette is here-in particular if I should > start a new thread seeing how this reply is over a month late-so feel

Re: access rdomain0 localhost from rdomainN

2023-06-28 Thread Zack Newman
On 2023-05-15, Stuart Henderson wrote: pass out quick on rdomain 2 to 127.0.0.1 nat-to 127.0.0.1 rtable 0 Not sure what the proper etiquette is here-in particular if I should start a new thread seeing how this reply is over a month late-so feel free to yell at me. What is the purpose of the

relayd: pfe_route: failed to add gateway 22 Invalid argument

2023-06-28 Thread Joerg Streckfuss
Hello, I'm trying to use the relayd router function to add host routes to the routing table with a route label for further processing by bgpd. The host ist directly connected to the firewall. relayd.conf: table { 2001:::::4 } router "service_v6" { route

Re: IP6 redirects through relayd no longer working reliably

2023-06-28 Thread Markus Wernig
Just for the record: The problem was caused by a malfunctioning upstream gateway, which did no longer respond properly to neighbor solicitation requests. The SYN ACK from the server was dropped because the firewall had already removed the state created by the SYN. On 6/23/23 22:51, Markus

OpenBSD 7.3 ixl SIOCSIFMEDIA: Operation not supported

2023-06-28 Thread Rachel Roch
Running "doas ifconfig ixl3 media 10GbaseLR" gives me "SIOCSIFMEDIA: Operation not supported" and I'm not sure why. I'm also not sure why "ifconfig ixl sff" shows no transceiver data even if there are FlexOptix transiceivers in two of the slots and I have confirmed that the card in question is

Re: IPsec over PPPoE

2023-06-28 Thread Stuart Henderson
On 2023-06-28, Stefan Sperling wrote: > Flow source/destination IPs must exactly match packets leaving the box. > > So you will either need to put the private IP as the from "src" of the > flow (which can be annoying if it changes at run-time, you need to adjust > and reload flows somehow when

Re: IPsec over PPPoE

2023-06-28 Thread Stuart Henderson
On 2023-06-28, Jiri Navratil wrote: > Hello, > > I'm trying to build Site-to-site VPN based on "Configuring an IKEv2 Server" > in https://www.openbsd.org/faq/faq17.html > > I see in iked -dv output to terminal (I replaced some parts with dots) > > spi=0x4905: > established peer

Re: IPsec over PPPoE

2023-06-28 Thread Stefan Sperling
On Wed, Jun 28, 2023 at 09:53:38AM +0200, Jiri Navratil wrote: > 3) The sites I'm configuring are both using PPPoE. One have VLAN and I > see external statical IPv4 on PPPoE, but other site uses NAT 1:1, so I > see private IPv4 on PPPoE, but I have to access it over allocated > external IPv4. I'm

Re: IPsec over PPPoE

2023-06-28 Thread Janne Johansson
> > 5) There is note in FAQ, that Native WireGuard support is also > available. As both IPsec and WireGuard are new to me, may wg(4) be an > option? > Yes, it should be a good option for site2site tunnels. -- May the most significant bit of your life be positive.

IPsec over PPPoE

2023-06-28 Thread Jiri Navratil
Hello, I'm trying to build Site-to-site VPN based on "Configuring an IKEv2 Server" in https://www.openbsd.org/faq/faq17.html I see in iked -dv output to terminal (I replaced some parts with dots) spi=0x4905: established peer ...:4500[FQDN/.] local