CARP balancing switchs compatibility

2015-09-18 Thread Michel Blais
I'm trying CARP load balancing on several switchs and most have behavior not compatible with CARP balancing both in ip and ip-stealth mode. Ip-unicast also seem a bad option in my test since all switch I tested that support mirroring can only mirror to one port (or I didn't see any option to

Re: pf nat and routing question

2015-06-24 Thread Michel Blais
The solution seem his explain on this link ‎http://www.openbsd.org/faq/pf/rdr.html#reflect   Message d'origine   De: Marko Cupać Envoyé: mercredi 24 juin 2015 07:21 À: misc@openbsd.org Objet: pf nat and routing question Hi, my setup is actually more complicated, but for purpose of this mail I

Re: OpenBGPD 5.4 - No route received when neighbor from a AS is down

2015-05-15 Thread Michel Blais
Blais Administrateur réseau Targo communications 2015-05-14 17:01 GMT-04:00 Claudio Jeker cje...@diehard.n-r-g.com: On Thu, May 14, 2015 at 03:31:09PM -0400, Michel Blais wrote: Thanks Claudio for answering I added the option nexthop qualify via bgp and now, route are now valid. I found

Re: OpenBGPD 5.4 - No route received when neighbor from a AS is down

2015-05-14 Thread Michel Blais
else or it seem like a problem on the carrier side ? 2015-05-10 14:37 GMT-04:00 Henning Brauer hb-open...@ml.bsws.de: * Michel Blais mic...@targointernet.com [2015-05-07 17:59]: I have 2 BGP peer from different provider (AS5769 and AS22652). It's happen 2 times that I was not able to ping my

Re: OpenBGPD 5.4 - No route received when neighbor from a AS is down

2015-05-14 Thread Michel Blais
. --- Cordialement, Michel Blais Administrateur réseau Targo communications 2015-05-14 14:44 GMT-04:00 Claudio Jeker cje...@diehard.n-r-g.com: On Thu, May 14, 2015 at 02:21:41PM -0400, Michel Blais wrote: Thanks Henning for answering, While using nexthop, I see $peerfibn1 as the variable ip

OpenBGPD 5.4 - No route received when neighbor from a AS is down

2015-05-07 Thread Michel Blais
I know, I must update but unless it's a know bug and was fix on = 5.5, I would really like to understand why this is happening. I have 2 BGP peer from different provider (AS5769 and AS22652). It's happen 2 times that I was not able to ping my neighbor ($peervid1) at AS5769 connected to em1 but

Re: Lanner or Soekris?

2013-10-21 Thread Michel Blais
I have often use Lanner FW-7535 with OpenBSD and like them a lot. Buy them from LEI Technologie in Canada for 375$. Lanner product are good stuff, really professionnal. I also Lanner product for customer PBX, unifi controler, etc. 2013/10/21 emigrant emig...@gmail.com min. 3xNICs: wan, lan,

Re: OpenBSD Doesn't Support 64-Bit Intel

2013-06-30 Thread Michel Blais
Intel 64 bit is amd64 compatible. *De: *Jash Sefferson *Envoyé: *lundi 1 juillet 2013 00:08 *À: *misc@openbsd.org; s...@openbsd.org *Répondre à: *Jash Sefferson *Objet: *OpenBSD Doesn't Support 64-Bit Intel Hi guys. I’m a civil engineer by day and use OpenBSD at night, but I’m trying to do

Re: Hardware to donate: Ubiquiti routerstation

2013-05-12 Thread Michel Blais
gets underway. On Thu, May 9, 2013 at 3:58 AM, Michel Blais mic...@targointernet.com wrote: Not sure if it's worth the effort since RSPro are not produced anymore. It was replaced by Edgerouter Lite. Dev are already working on this one. http://www.openbsd.org/octeon.html Le 2013-05-08

Re: USB temperature sensors

2013-05-09 Thread Michel Blais
I never tryed on OpenBSD but mFi from Ubnt is cheap and the software is compatible with Unix. Michel *De: *rafaello konfekte *Envoyé: *jeudi 9 mai 2013 07 h 30 min 18 s EDT *À: *misc@openbsd.org *Répondre à: *rafaello konfekte *Objet: *USB temperature sensors Hello, Could you share your

Re: Hardware to donate: Ubiquiti routerstation

2013-05-08 Thread Michel Blais
it wherever, if you want it. In fact, if anybody is interested in porting to this, I'll probably happily buy you the routerstation pro board, too (which FreeBSD also supports). Please CC me, as I'm not subscribed. Thanks, -- Kate -- Cordialement / Best regards Michel Blais Administrateur réseau

Re: pf: inline anchor rules in not enough to keep tables in memory?

2013-03-13 Thread Michel Blais
. Is this by design? - Max -- Cordialement / Best regards Michel Blais Administrateur réseau / Network administrator Targo Communications www.targo.ca 514-448-0773

Re: pf: inline anchor rules in not enough to keep tables in memory?

2013-03-13 Thread Michel Blais
, Maxim Khitrov a écrit : On Wed, Mar 13, 2013 at 1:59 PM, Michel Blais mic...@targointernet.com wrote: I think you must specify the anchor first. Something like : pfctl -a ix1 -t admins -T show That doesn't work. First, it's an unnamed anchor, so I don't think you can specify it with the -a option

Re: pf: inline anchor rules in not enough to keep tables in memory?

2013-03-13 Thread Michel Blais
For the anchor removed if not persistent, I have already writed about this. The answer from Henning : http://marc.info/?l=openbsd-miscm=133467818116146w=2 Le 2013-03-13 14:15, Maxim Khitrov a écrit : On Wed, Mar 13, 2013 at 1:59 PM, Michel Blais mic...@targointernet.com wrote: I think you

Re: Soekris net6501-70 as a router+firewall

2013-02-15 Thread Michel Blais
Even a 5501 or Alix would probably be enough for that quantity of user. If your in north america, you should look lanner fw-7535 that cost less than a net6501-70. It's a great router and lanner have a really good customer support, one of the best I have seen. Michel

Bad major libc.so.66.0 while trying to install via pkg_add

2013-01-09 Thread Michel Blais
Hi, The're 2 package I'm not able to install. # uname -a OpenBSD myhostname.mydomain.com 5.2 GENERIC.MP#8 amd64 # pkg_add nano Can't install libiconv-1.14 because of libraries |library c.65.0 not found | /usr/lib/libc.so.66.0 (system): bad major Can't install gettext-0.18.1p3: can't resolve

Re: Bad major libc.so.66.0 while trying to install via pkg_add

2013-01-09 Thread Michel Blais
PKG_PATH or /etc/pkg.conf to reflect it. See http://www.openbsd.org/faq/faq15.html#NoFun 2013/1/9 Michel Blais mic...@targointernet.com: Hi, The're 2 package I'm not able to install. # uname -a OpenBSD myhostname.mydomain.com 5.2 GENERIC.MP#8 amd64 # pkg_add nano Can't install libiconv-1.14

Re: Ubiquiti EdgeMax

2013-01-08 Thread Michel Blais
help but when I saw this, I remebered this thread and thinked it could be good to share the information if somebody want to try to port it. Michel Le 2012-09-19 16:32, Michel Blais a écrit : I think Stig is in charge of the EdgeOS software developement. http://www.linkedin.com/in/stigt

Re: carp both master

2012-12-18 Thread Michel Blais
22:36 +, Stuart Henderson a écrit : On 2012-12-17, Michel Blais mic...@targointernet.com mailto:mic...@targointernet.com wrote: # cat /etc/hostname.carp0 inet W.X.Y.B 255.255.255.248 W.X.Y.D vhid 1 carpdev em0

carp both master

2012-12-17 Thread Michel Blais
Hi, I'm testing carp for the first time on 5.2 (both) and no mather what I try, both are master. I see the traffic from carp with tcpdump on both device. Must be a RTMF error but I already readed all official doc and some unofficial and still can't find what wrong. The config of both device is

Re: Hardware hunting

2012-11-15 Thread Michel Blais
I have one Jetway board in production with 5.0 with intel daughterboard work fine but it's only 3 intel NIC so would have to use one realtek. I didn't try realtek NIC with lot of traffic. I now use Lanner FW-7535 instead. Cost a little more but like them better and Lanner service is great.

Re: unbound performance

2012-11-06 Thread Michel Blais
Nothing wrong, I normally use bind so I just didn't think of make each service listen at different address. Double face palm at myself lol. Thanks Stuart, that what I will do. Michel Le 2012-10-30 19:23, Stuart Henderson a écrit : What's wrong with binding NSD to one IP address for

Re: unbound performance

2012-10-26 Thread Michel Blais
Le 2012-10-26 06:48, Martin Pelikan a écrit : 2012/10/25 Michel Blais mic...@targointernet.com: Hi, I'm trying to make unbound have less timeout query (I see around1 to 2% of query timeout using DNS performance test from Silverwolf Software and was looking at Unbound : Howto optimise

unbound performance

2012-10-25 Thread Michel Blais
Hi, I'm trying to make unbound have less timeout query (I see around1 to 2% of query timeout using DNS performance test from Silverwolf Software and was looking at Unbound : Howto optimise and wanted to try the so-rcvbuf option but enabling it cause a error on service start. On BSD change

Re: happy alix user ?

2012-09-27 Thread Michel Blais
First, it would be better to start a new subject if it's not related to the original post. Squid need lot of disk space to be efficient and write a lot on the disk, same for samba. I would not install those on a compact flash. Maybe something like a Lanner FW-7535 would be better. Those

Re: happy alix user ?

2012-09-27 Thread Michel Blais
2012-09-27 10:19, Russell Garrison a écrit : Definitely OT, but I second the FW-7535. Good gear and Lanner is easy to work with direct even for small projects. Same with LEI technologie, the're division in Canada. -- Michel Blais Administrateur réseau / Network administrator Targo

Re: Ubiquiti EdgeMax

2012-09-19 Thread Michel Blais
I think Stig is in charge of the EdgeOS software developement. http://www.linkedin.com/in/stigt Michel Agreed, but the fact it uses an OS which uses the kernel Linux is encouraging, though GPL source code is pretty much useless to a BSD-licensed project from a documentation standpoint. We

Re: How to PROVE your system is up to date?

2012-09-18 Thread Michel Blais
could print for them would be best) them my system is up to date and that all patches have been applied??? Thank you, Ed -- Michel Blais Administrateur réseau / Network administrator Targo Communications www.targo.ca 514-448-0773

Re: su and passwd

2012-09-14 Thread Michel Blais
. This is the traditional behavior of su Running su -l works good. Why if user ID is == 0 or if there's no -l, the $USER will not be set? What is the policy? I've tried this also on OpenBSD 4.9 with same result. Thanks in advance. Alessandro. -- Michel Blais Administrateur réseau / Network

Re: su and passwd

2012-09-14 Thread Michel Blais
Oups, didn't saw that Trd answered. Sorry for the noise. Le 2012-09-14 13:49, Michel Blais a écrit : LOL, when I started on OpenBSD, I created a bug report about this. Dev want it this way, the're must be a reason to it but since it's not standard, the must also expect question like

bi-nat biavior and anchor limitation

2012-09-13 Thread Michel Blais
Hi, I just encounter a stange biavior with the bi-nat rules. Since we optimize our firewall script via multiple anchor for our thousand of bi-nat rule, we don't use the bi-nat rule but instead use the 2 rules in different anchor. Exemple: anchor out on $ext_if from 192.168.0.0/16 { anchor

Re: bi-nat biavior and anchor limitation

2012-09-13 Thread Michel Blais
Le 2012-09-13 11:34, Michel Blais a écrit : Also, is it a pfctl limitation to not be able to use it on anchor inside a other anchor or I'm missing something ? Exemple, I load a anchor in main ruleset named A and in A, I load a other anchor named B. Is there any way to use pfctl on B anchor

Re: pfsense and or OpenBSD Home router.

2012-09-12 Thread Michel Blais
Le 2012-09-11 09:59, James Shupe a écrit : Not from within Europe, Not build in europe but this link was the europe shop so it answer the original question. Michel

Re: Ubiquiti EdgeMax

2012-09-12 Thread Michel Blais
acceleration. -- Michel Blais Administrateur réseau / Network administrator Targo Communications www.targo.ca 514-448-0773

Re: pfsense and or OpenBSD Home router.

2012-09-11 Thread Michel Blais
Le 2012-09-11 05:38, Shaka Nkofo a écrit : http://store.netgate.com/Desktop-Kits-C82.aspx I found this shop while looking for parts to build a home router. Has anyone been through this and can give me links to cheap parts within Europe? Any advise on the pitfalls of this process is welcome

Re: net.inet.ip.ifq.maxlen

2012-09-11 Thread Michel Blais
http://www.undeadly.org/cgi?action=articlesid=20060927091645 is still mostly relevant. Great article. Thanks for the link and also for the other tips. Michel

Re: net.inet.ip.ifq.maxlen

2012-09-07 Thread Michel Blais
Le 2012-09-04 13:52, Claudio Jeker a écrit : On Tue, Sep 04, 2012 at 10:16:41AM -0400, Michel Blais wrote: I've build a Xeon E3 with Intel i340 ethernet with 82580 chip. CPU is use up to 24% on the first core, congestion is now at 0.3/s. I still see drops in net.inet.ip.ifq.drops. 1131 drops

Re: net.inet.ip.ifq.maxlen

2012-09-04 Thread Michel Blais
doc on how to optimise the order of the rule order for best performance ? I was also not able to find anything about this. Thanks Michel Le 2012-08-30 09:57, Michel Blais a écrit : Le 2012-08-30 08:59, Ryan McBride a écrit : On Wed, Aug 29, 2012 at 12:54:18PM -0400, Michel Blais wrote: How

Re: net.inet.ip.ifq.maxlen

2012-08-30 Thread Michel Blais
Le 2012-08-30 08:59, Ryan McBride a écrit : On Wed, Aug 29, 2012 at 12:54:18PM -0400, Michel Blais wrote: How much can I increase net.inet.ip.ifq.maxlen ? I'm now at 2048 and still seeing increase in net.inet.ip.ifq.drops. This morning, it was at 21280 and now at 21328. A little bit

net.inet.ip.ifq.maxlen was WARNING: mclpools limit reached; increase kern.maxclusters and paquet lost

2012-08-29 Thread Michel Blais
server and now the congestion have dropped from 3.9 to 0.8. Something I must specify, I use bi-nat to save public ip address and have thousand of bi-nat rule divided in some anchors. Thanks Michel Le 2012-08-19 08:21, Stuart Henderson a écrit : On 2012-08-14, Michel Blais mic

Re: High RTT/Latency pings post 5.0

2012-08-29 Thread Michel Blais
exception 16 fdc0 at isa0 port 0x3f0/6 irq 6 drq 2 mtrr: Pentium Pro MTRR support vscsi0 at root scsibus1 at vscsi0: 256 targets softraid0 at root scsibus2 at softraid0: 256 targets root on wd0a swap on wd0b dump on wd0b ~ -- Michel Blais Administrateur réseau / Network administrator Targo

Re: High RTT/Latency pings post 5.0

2012-08-29 Thread Michel Blais
Oups, sorry. It's OpenBSD 5.0, not 5.1. Le 2012-08-29 17:05, Michel Blais a écrit : I have both latency and paquet drop problem on 5.1 on card using em(4). Tryed both 82571EB and 82546GB. It was worst with 82546GB. Mailing list subject : WARNING: mclpools limit reached; increase

Re: High RTT/Latency pings post 5.0

2012-08-29 Thread Michel Blais
17:08, Michel Blais a écrit : Oups, sorry. It's OpenBSD 5.0, not 5.1. Le 2012-08-29 17:05, Michel Blais a écrit : I have both latency and paquet drop problem on 5.1 on card using em(4). Tryed both 82571EB and 82546GB. It was worst with 82546GB. Mailing list subject : WARNING: mclpools limit

Re: broken system with unknow command

2012-08-15 Thread Michel Blais
, 2012 at 9:12 PM, Michel Blais mic...@targointernet.com wrote: seem like I have type the wrong command by mistake using tab to complet the command. Don't know which command it was but I add a lot of output like this : Faulted ikernel: double fault trap, code=0 kernel: double fault trap, code=0

WARNING: mclpools limit reached; increase kern.maxclusters and paquet lost

2012-08-14 Thread Michel Blais
Hi misc, I got a little error here with a sysctl value in dmesg : WARNING: mclpools limit reached; increase kern.maxclusters The value was at 6144 and I just change it to 9216 (50% more) The system is also having paquet lost from 1 up to 6% and can have latency up to 30 ms and changing the

Re: WARNING: mclpools limit reached; increase kern.maxclusters and paquet lost

2012-08-14 Thread Michel Blais
(0e0e83aa73b049f0.a) swap on sd1b dump on sd1b WARNING: / was not properly unmounted Le 2012-08-14 11:31, Michel Blais a écrit : Hi misc, I got a little error here with a sysctl value in dmesg : WARNING: mclpools limit reached; increase kern.maxclusters The value was at 6144 and I just change

Re: WARNING: mclpools limit reached; increase kern.maxclusters and paquet lost

2012-08-14 Thread Michel Blais
0.1/s state-limit00.0/s src-limit 00.0/s synproxy 00.0/s Le 2012-08-14 11:39, Michel Blais a écrit : I juste found how to get the boot dmesg : # cat /var/run/dmesg.boot

broken system with unknow command

2012-08-14 Thread Michel Blais
Hi misc, seem like I have type the wrong command by mistake using tab to complet the command. Don't know which command it was but I add a lot of output like this : Faulted ikernel: double fault trap, code=0 kernel: double fault trap, code=0 Faulted in DDB; continuing... --db_more--kernel:

Re: OpenBSD is just an OS, not a firewall...

2012-06-08 Thread Michel Blais
Lmfao Le 8 juin 2012 14:01, Chris Smith obsd_m...@chrissmith.org a écrit : ... if you really want a firewall you need pfSense. Also if you walk into any security experts convention and claim that raw OpenBSD is a firewall, you will get laughed out of the room for lack of clue. Guess I've

Re: nonexistent tables in pf.conf

2012-05-30 Thread Michel Blais
5.1-beta (GENERIC) #140: Sat Jan 21 00:40:23 MST 2012 dera...@i386.openbsd.org:/usr/src/sys/arch/i386/compile/GENERIC I believe it would be an improvement if pfctl refused to load a ruleset that refers to nonexistent tables. Jan -- Michel Blais Administrateur riseau / Network

Re: HW upgrade options, opinions please?

2012-05-23 Thread Michel Blais
are the load balancers behind the WAN router. Looking at reducing it to 2 machines, though. Hardware capability is my main consideration currently. I want something adequette for 100Mbps. -- Michel Blais Administrateur riseau / Network administrator Targo Communications www.targo.ca 514-448-0773

Re: PF match word

2012-04-24 Thread Michel Blais
From pf.conf (5) http://www.openbsd.org/cgi-bin/man.cgi?query=pf.confapropos=0sektion=0manpath=OpenBSD+Currentarch=i386format=html match The packet is matched. This mechanism is used to provide fine grained filtering without altering the block/pass state of a

Re: tables behavior with in bracket anchor

2012-04-21 Thread Michel Blais
, Martin Pelikan martin.peli...@gmail.com a icrit : On Tue, Apr 17, 2012 at 10:51:31AM -0400, Michel Blais wrote: rule inside of a in bracket anchors, pf will see no rule using the table and delete it. As a work around, I use persist option. I don't know if things have changed in the pfctl parser

tables behavior with in bracket anchor

2012-04-17 Thread Michel Blais
I'm using 5.0 and I saw a strange behavior with table and in bracket anchor. From my test, in bracket anchor can't have tables inside of them and are using the main ruleset tables but if I create a table only use by rule inside of a in bracket anchors, pf will see no rule using the table and

in line anchor syntax error

2012-04-12 Thread Michel Blais
Hi, I've read both pf anchor faq and pf.conf man page for 5.0 and my syntax seem right but I always get a error while trying to use ` in line anchor. The anchor line and closing bracket line both give me the syntax error with pfctl -vnf /etc/pf.conf I tryed with and without anchor name.

Re: in line anchor syntax error

2012-04-12 Thread Michel Blais
. Jeremy -- Michel Blais Administrateur riseau / Network administrator Targo Communications www.targo.ca 514-448-0773

pf anchor strange bihavior

2012-04-12 Thread Michel Blais
Just saw something strange with inline anchor rule and macro : if I set a anchor rule with a macro inside of it and do pfctl -vnf, only the first value of the macro seem to have the anchor rule following. Every other value will be without bracket and anchor rules. Exemple : in the pf.conf

Re: pf anchor strange bihavior

2012-04-12 Thread Michel Blais
Great. Thanks Andres for the answer. Michel Le 2012-04-12 22:30, Andres Perera a C)crit : On Thu, Apr 12, 2012 at 9:25 PM, Michel Blaismic...@targointernet.com wrote: Just saw something strange with inline anchor rule and macro : if I set a anchor rule with a macro inside of it and do

sims vid traceroute

2012-04-10 Thread Michel Blais
11 ms1 ms1 ms 10.5.14.1 2 5 ms 2 ms 2 ms 10.5.0.21 3 5 ms 3 ms 8 ms 10.5.4.253 4 5 ms 6 ms 4 ms 10.5.2.161 5 4 ms 5 ms 5 ms 10.5.2.129 6 5 ms 5 ms 4 ms 216.113.24.85 7 5 ms 4 ms 6 ms

Re: sims vid traceroute

2012-04-10 Thread Michel Blais
Oups, sorry for this. I sended it to the wrong address. Le 2012-04-10 12:06, Michel Blais a icrit : 11 ms1 ms1 ms 10.5.14.1 2 5 ms 2 ms 2 ms 10.5.0.21 3 5 ms 3 ms 8 ms 10.5.4.253 4 5 ms 6 ms 4 ms 10.5.2.161 5 4 ms 5 ms 5 ms

Qualcomm collaboration summit

2012-04-09 Thread Michel Blais
Anyone had a look at Qualcomm collaboration summit to kill proprietary drivers ? I'm supprised I didn't see any mail about this. http://www.scribd.com/doc/87328384/Linux-Collaboaration-Summit-Qualcomm Michel

chroot scp

2012-04-04 Thread Michel Blais
Hi, I have create a chroot with scp and needed library for it but when I try to copy a file with scp, I always get the error unknown user UID after succefully entering the password. I can't find anything for this error exept for Linux. There also nothing in authlog, only successful

Re: chroot scp

2012-04-04 Thread Michel Blais
, Kevin Chadwick ma1l1i...@yahoo.co.uk a icrit : On Wed, 04 Apr 2012 18:08:37 -0400 Michel Blais wrote: I have create a chroot with scp and needed library for it but when I try to copy a file with scp, I always get the error unknown user UID after succefully entering the password. I can't find

Re: chroot scp

2012-04-04 Thread Michel Blais
Hi Stuart, You we're right. It's working fine now with pwd.db and passwd was not needed. Thanks Michel Le 4 avril 2012 20:46, Stuart Henderson s...@spacehopper.org a icrit : On 2012-04-04, Kevin Chadwick ma1l1i...@yahoo.co.uk wrote: On Wed, 04 Apr 2012 18:08:37 -0400 Michel Blais wrote: I

Re: Add Route at Boot Time

2012-01-20 Thread Michel Blais
http://www.openbsd.org/cgi-bin/man.cgi?query=hostname.ifsektion=5 Check the command line section Le 20 janv. 2012 09:36, Hendrickson, Kenneth khend...@harris.com a icrit : +--+ | Firewall | | | .33.34.35.97 | vr0dhcpd | | | |

Re: Add Route at Boot Time

2012-01-20 Thread Michel Blais
Also add to search this one when i beggined on openbsd. I think that in route(8), it should be writen that persistent route must be add in hostname.if. No where in route(8) there a link to hostname.if(5), not even in files. Le 20 janv. 2012 09:57, Hendrickson, Kenneth khend...@harris.com a icrit

Re: MIPS-BE_architecture_(RouterBoard_RB_750_GL)

2012-01-15 Thread Michel Blais
RB750GL use the sames CPU and ethernet switch as RB450G and Ubiquiti Routerstation Pro. The big difference is that RB750GL have 2 ethernet switch instead of 1. I know that RSPro is support by FreeBSD and if I remeber well, I read on this list that it could easily be port to OpenBSD. If one

Re: Problems with outgoing loadbalancing with pppoe(4)

2011-12-28 Thread Michel Blais
) -- Michel Blais Administrateur riseau / Network administrator Targo Communications www.targo.ca 514-448-0773 pckbc0: using irq 1 for kbd slot wskbd0 at pckbd0: console keyboard pcppi0 at isa0 port 0x61 spkr0 at pcppi0 nsclpcsio0 at isa0 port 0x2e/2: NSC PC87366 rev 9: GPIO VLM TMS gpio1 at nsclpcsio0

pf state key linking mismatch

2011-12-27 Thread Michel Blais
Hi, I can't really find anything explaning these error except that some said that you never want it to happen and Henning writing that it could be ignore in some case. In my case, I think I should ignore it but would like to understand it just to be sure. pf: state key linking mismatch!

Re: OpenBSD PF tables

2011-12-08 Thread Michel Blais
You could use macro instead of table for port. Michel 2011/12/8 John Tate j...@johntate.org Misc, I have sucessfully got an OpenBSD machine to connect via ADSL and forward packets, I am gradually upgrading my pf.conf. I am having trouble with this configuration (ignore some obvious bugs

Re: Flashboot for OpenBSD 5.0 is now available

2011-11-03 Thread Michel Blais
self there is a full set of images ready to put on a USB memory stick or Flash card media. Best regards Flashboot team -- Michel Blais Administrateur riseau / Network administrator Targo Communications www.targo.ca 514-448-0773

slow download

2011-10-21 Thread Michel Blais
I got a problem with snapshot (not shure if it's the last), download is really slow, 0.3 to 1 Mbps per customent. Also a lot of paquet lost beginning from the openbsd. The're around 800 to 1000 users on this server. Bandwith is not a problem but we often saw limitation in number of paquets be the

Re: slow download - sysctl limit ?

2011-10-21 Thread Michel Blais
net.inet.ip.porthilast=65535 sysctl kern.seminfo.semmni=1024 sysctl kern.seminfo.semmns=4096 sysctl kern.shminfo.shmmax=67018864 sysctl kern.shminfo.shmall=32768 The're now a lot less paquet lost but speed test is as much slow. Any idea ? Thanks Michel Le 2011-10-21 10:42, Michel Blais a icrit : I

Re: slow download - packets dropped by kernel

2011-10-21 Thread Michel Blais
x2 : my actual size : # sysctl net.bpf.bufsize=8388608 net.bpf.bufsize: 4194304 - 8388608 # sysctl net.bpf.maxbufsize=16777216 net.bpf.maxbufsize: 8388608 - 16777216 Still the same. Anything else that could make kernel drop paquets ? Thanks Le 2011-10-21 11:46, Michel Blais a icrit : really

Re: slow download - sysctl limit ?

2011-10-21 Thread Michel Blais
21, 2011 at 9:46 AM, Michel Blais mic...@targointernet.com wrote: really look like a sysctl limit, tcpdump give me lot of packets dropped by kernel. I commented every block rule to be sure it was not a rules mistake in pf pfctl -vnf /etc/pf.conf without tables and macro set limit states

Re: slow download

2011-10-21 Thread Michel Blais
2011/10/21 Michel Blais mic...@targointernet.com This is for a firewall and main gateway of my network. Is a atom dual core cpu 1.6 Ghz with 2 Go or RAM It have 2 realtek onboard nic but since I wanted Intel NIC, I added a 3 intel NIC optional board. em0 is use to connect to my ISP fiber

Re: slow download

2011-10-21 Thread Michel Blais
oct. 2011 17:27, Stuart Henderson s...@spacehopper.org a icrit : On 2011/10/21 17:01, Michel Blais wrote: This is for a firewall and main gateway of my network. Is a atom dual core cpu 1.6 Ghz with 2 Go or RAM It have 2 realtek onboard nic but since I wanted Intel NIC, I added a 3 intel NIC

Re: Traffic through default pf queue

2011-10-17 Thread Michel Blais
? Thanks for your ideeas. -- Michel Blais Administrateur rC)seau / Network administrator Targo Communications www.targo.ca 514-448-0773

Re: Need suggestion about Firewall Reporter for OpenBSD PF

2011-10-13 Thread Michel Blais
I know cacti can do graph from data and it should be possible to build it on openbsd. Le 13 oct. 2011 20:10, Stefan N stefanbsd...@yahoo.com a icrit : Hi Erling, Thanks. I will try and test it. Regards, Stefan From: Erling Westenvik

Re: UEFI BIOS

2011-10-02 Thread Michel Blais
What some fear is that some Microsoft OEM partner do a lazy job with a minimal UEFI interface without the possibility to disable secure boot. In that case, if secure boot block unsigned os at boot, it would be impossible to install other os than Windows 8. I have too often see BIOS missing

Re: pf behaviors

2011-09-26 Thread Michel Blais
. if I try with no state : pass out on $ext_if from second queue second no state it won't shape ip added to second into the queue, the will be shaped by the default queue instead. Any idea ? Should I report a bug ? Michel Le 2011-09-14 15:20, Michel Blais a icrit : Hi, this follow my previous posts

Re: Are there any virtualization solutions for OpenBSD? (!important: no package from ports!)

2011-09-20 Thread Michel Blais
The're also proxmox ve that is really nice for virtualisation. http://pve.proxmox.com/wiki/Main_Page

pf behaviors

2011-09-14 Thread Michel Blais
Hi, this follow my previous posts with subject : pf shape download that I now solved. The following test where done on OpenBSD 4.9, 5.0 snapshot of 12/09/2011 FreeBSD 8.2 (include PF from OpenBSD 4.2 if I remeber well). All add the same behavior. I didn't test current (but the snapshot was

Re: pf shape download

2011-09-08 Thread Michel Blais
pfctl -k 10.254.200.2 But if I try to shape 10.254.200.2 again by adding it to second tab, I must restart my download again. Is it normal or a behaviure ? Le 2011-09-07 17:25, Michel Blais a icrit : Hi all, thanks for your help and tips. I have do some testing when I add some free time. I finally

Re: pf shape download

2011-09-07 Thread Michel Blais
Hi all, thanks for your help and tips. I have do some testing when I add some free time. I finally got it working by creating the queue on my internal if (now em1 instead of re1) altq on $int_if hfsc bandwidth 97Mb qlimit 500 queue { main, second } queue main on $int_if bandwidth 1Mb

Re: Why aren't you running -current?

2011-09-07 Thread Michel Blais
Simply because I always runned final release for server and gateway. Habit taken from linux even if some use arch or testing for debian. I'm new to openbsd and freebsd that i used for some month (maybe even a year) also seem to recommend final release. Should we really use current for gateway in

Re: pf shape download

2011-08-23 Thread Michel Blais
luck getting this working? Thanks! dn On 8/16/11 8:20 AM, Michel Blais wrote: Hi, I'm having a problem to shape download with PF. I have 2 HFSC queue (main and second) created on my internal NIC. Main is my default queue. If I try to match download traffic to the second queue, it still go

pf shape download

2011-08-16 Thread Michel Blais
Hi, I'm having a problem to shape download with PF. I have 2 HFSC queue (main and second) created on my internal NIC. Main is my default queue. If I try to match download traffic to the second queue, it still go trought the main queue. The IP I want to download trought the second queue for my

Re: second NIC not configure at boot

2011-08-09 Thread Michel Blais
Hi Rogier, I didn't do anything usefull, plug re1 and reboot and it started working fine so that why I write play a little with because I didn't know what had changed when it begin to work again. The output of dmesg was also not include because I really didn't think it was hardware related so it

second NIC not configure at boot

2011-07-27 Thread Michel Blais
Hi, I'm new to OpenBSD (exprience with Linux and FreeBSD) and I'm trying to configure a second NIC at boot without result. The OpenBSD version is 4.9. This NIC name is re1 so I created the file /etc/hostname.re1 with the following in : inet 10.8.1.1 255.255.255.0 10.8.1.255 If use netstart to

Re: second NIC not configure at boot

2011-07-27 Thread Michel Blais
1 NIC again, the four NIC are still configure when I rebot the system. Strange. I will try to reproduce it on a other system, I must build a other one for carp redondancy. Anyway, thanks Michel Le 2011-07-27 11:04, Michel Blais a icrit : Hi, I'm new to OpenBSD (exprience with Linux