Re: bgpd, announce to ibgp from 2 routers, prefixes only show up from 1

2021-11-13 Thread Remi Locherer
On Sat, Nov 13, 2021 at 12:11:08AM +, Stuart Henderson wrote: > I have a pair of -current routers running bgpd (let's call them rtr-a > and rtr-b) on a subnet which also has some vpn gateways and firewalls. > > These routers provide a carp address which the vpn gateways are using > as default

Re: OSPF and CARP interfaces

2020-12-22 Thread Remi Locherer
On Tue, Dec 22, 2020 at 02:04:27PM +0100, open...@kene.nu wrote: > Hello, > I am seeing what I deem to be unexpected behavior with ospfd and depending > on carp interfaces. > Running 6.8 with latest patches applied on all three routers. > > # uname -a > OpenBSD extfw1.lab.kambi.com 6.8

Re: bgpd config advice needed

2020-08-25 Thread Remi Locherer
On Tue, Aug 25, 2020 at 07:11:12AM -, Stuart Henderson wrote: > On 2020-08-24, Claudio Jeker wrote: > > On Mon, Aug 24, 2020 at 04:36:10PM +, Laura Smith wrote: > >> *>  N 2001:db8:::/29   2001:db8::::1    100   100 > >> 64512 65500 i > >> *   N 2001:db8:::/29 

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-11 Thread Remi Locherer
On Tue, Aug 11, 2020 at 02:07:32PM -0400, Winfred Harrelson wrote: > I know others are using the new aggr(4) interface but I am having a > problem with trying to use it on some new servers I have recently > gotten. Hoping I could get some help from someone here since my > searches have not been

Re: OSPF seems to stops processing updates

2020-04-13 Thread Remi Locherer
gt; > > > Thanks > > > > Richard > > > > > > > > On Mon, 13 Apr 2020, 14:39 Stuart Henderson, wrote: > > > > On 2020-04-13, Claudio Jeker wrote: > > > On Mon, Apr 13, 2020 at 02:08:31PM +0200,

Re: OSPF seems to stops processing updates

2020-04-13 Thread Remi Locherer
On Mon, Apr 13, 2020 at 12:05:10PM +0100, Richard Chivers wrote: > Thanks. Please see my comments below. > > On Mon, 13 Apr 2020, 10:18 Remi Locherer, wrote: > > > Hi Richard, > > > > On Mon, Apr 13, 2020 at 08:38:31AM +0100, Richard Chivers wrote: > > &

Re: OSPF seems to stops processing updates

2020-04-13 Thread Remi Locherer
forgot to add misc@ ... On Mon, Apr 13, 2020 at 11:18:17AM +0200, Remi Locherer wrote: > Hi Richard, > > On Mon, Apr 13, 2020 at 08:38:31AM +0100, Richard Chivers wrote: > > We have been having a strange issue, whereby OSPF stops updating properly. > > > > We can s

Re: ospfd in 6.6 when dying doesn't recover database before adj timer expires

2020-04-05 Thread Remi Locherer
Hi Tobias, On Fri, Apr 03, 2020 at 08:39:30AM +, Tobias Urdin wrote: > Hello, > > > We've seen a issue where if you perform a ospfctl reload and have a faulty > configuration for example a interface > > that doesn't exist it dies (which is fair in itself) but the seq num for the >

Re: Low throughput with 1 GigE interface

2020-01-30 Thread Remi Locherer
On January 30, 2020 4:17:16 PM UTC, Ian Darwin wrote: >Peter wrote: > >> chi# iperf -c beta.internal.centroid.eu >> >> Client connecting to beta.internal.centroid.eu, TCP port 5001 >> TCP window size: 17.0 KByte (default) >>

Re: Problems with route installation to fib from OSPF

2019-11-23 Thread Remi Locherer
00 > 10.10.10.10/32 192.168.98.204 UGS    0    0 -    40 > em0  > fw1# > fw1#  > > fw1# uptime && ospfctl show rib  >  1:41PM  up 15 days,  3:11, 1 user, load averages: 0.00, 0.00, 0.00 > Destination  Nexthop   Path Type 

Re: Problems with route installation to fib from OSPF

2019-11-05 Thread Remi Locherer
On Thu, Oct 24, 2019 at 02:09:09PM +0200, Joao Alves wrote: > Hi Remi, > > I've installed a lab with OpenBSD6.6 VM's to see if would happen in the > newer version. > > I was able to reproduce it again, but in slightly different manner. > > First of all, you need to have BGP running in FW's

Re: Problems with route installation to fib from OSPF

2019-10-24 Thread Remi Locherer
Hi Joao, I'll try to reproduce. It might take some time. Remi On Thu, Oct 24, 2019 at 02:09:09PM +0200, Joao Alves wrote: > Hi Remi, > > I've installed a lab with OpenBSD6.6 VM's to see if would happen in the > newer version. > > I was able to reproduce it again, but in slightly different

Re: Strong Host Model in OpenBSD network stack

2019-10-17 Thread Remi Locherer
On Thu, Oct 17, 2019 at 10:33:41PM -0600, Theo de Raadt wrote: > > Setting net.inet.ip.check_interface=1 on FreeBSD stopped any ICMP Echo > > replies immediately. > > > > On NetBSD I set net.inet.ip.checkinterface=1 and it showed the same > > behaviour like FreeBSD. No replies anymore, whenever

Re: Problems with route installation to fib from OSPF

2019-10-15 Thread Remi Locherer
Hi João, On Thu, Oct 10, 2019 at 03:01:30PM +0200, Joao Alves wrote: > Hello OpenBSD team, > > > We are facing an issue with OSPF related routes and would like to > request your help as it seems to be a OSPF to FIB route replication issue. > > This happened already once in a different

Re: openbgpd; strip private ASNs from bgp updates

2019-03-31 Thread Remi Locherer
On Sun, Mar 31, 2019 at 01:09:06PM +0200, Claudio Jeker wrote: > On Fri, Mar 29, 2019 at 08:36:26AM +0100, open...@kene.nu wrote: > > I forgot to add to my previous email. One thing that could be useful > > in this case is to mimic the Cisco option "neighbor x.x.x.x > > remove-private-as" which

Re: OpenOSPFD (6.4) "depend on" feature forces "type 1"

2019-01-15 Thread Remi Locherer
Hi Igor On Thu, Jan 10, 2019 at 11:31:00PM +0100, Sebastian Benoit wrote: > Remi Locherer(remi.loche...@relo.ch) on 2019.01.10 21:18:58 +0100: > > On Fri, Jan 11, 2019 at 12:06:09AM +0700, Igor Podlesny wrote: > > > On Thu, 10 Jan 2019 at 21:11, Remi Locherer wrote: > &g

Re: Ignore MTU on OSPFD

2019-01-14 Thread Remi Locherer
On Mon, Jan 14, 2019 at 03:08:32PM -0500, Henry Bonath wrote: > Is it possible to set to ignore MTU on OpenOSPFD? No, this is not supported. > > For example on Cisco IOS I can add the command "ip ospf mtu-ignore" > > I am having some issues if the MTU is mismatched and some neighbors will be >

Re: OpenOSPFD (6.4) "depend on" feature forces "type 1"

2019-01-10 Thread Remi Locherer
On Fri, Jan 11, 2019 at 12:06:09AM +0700, Igor Podlesny wrote: > On Thu, 10 Jan 2019 at 21:11, Remi Locherer wrote: > [...] > > I can reproduce it. Interestingly it only sends out the wrong type when > > the "depend on" interfac (carp1 in your example) is

Re: OpenOSPFD (6.4) "depend on" feature forces "type 1"

2019-01-10 Thread Remi Locherer
On Thu, Jan 10, 2019 at 03:06:59PM +0700, Igor Podlesny wrote: > On Thu, 10 Jan 2019 at 01:21, Remi Locherer wrote: > [...] > > > > It is not intended. I'll look into it. I can reproduce it. Interestingly it only sends out the wrong type when the "depend on" int

Re: OpenOSPFD (6.4) "depend on" feature forces "type 1"

2019-01-09 Thread Remi Locherer
On Wed, Jan 09, 2019 at 10:47:21PM +0700, Igor Podlesny wrote: > Hi! > > My tests show that OpenOSPFD "depend on" feature forces "type 1" > overriding explicitly specified "type 2". For example this statement > can be used: > > redistribute 0.0.0.0/0 set { type 2 } depend on carp1 > > (or

Re: ospfd fib and kernel fib

2018-10-23 Thread Remi Locherer
On Tue, Oct 23, 2018 at 01:14:52PM +0200, open...@kene.nu wrote: > Hello, > On Mon, Oct 22, 2018 at 4:24 PM Remi Locherer wrote: > > > > On Mon, Oct 22, 2018 at 08:48:28AM +0200, open...@kene.nu wrote: > > > Hello, > > > > > > I am having t

Re: ospfd fib and kernel fib

2018-10-22 Thread Remi Locherer
On Mon, Oct 22, 2018 at 08:48:28AM +0200, open...@kene.nu wrote: > Hello, > > I am having trouble with ospfd not updating the kernel fib as it > should (I think). This is in my lab environment on vagrant. > > host# uname -a > OpenBSD host 6.4 GENERIC.MP#329 amd64 > host# ospfctl sh rib | grep

Re: Ospf adding new interface

2018-09-28 Thread Remi Locherer
Hi Simon On Fri, Sep 28, 2018 at 10:22:42PM +0200, Simen Stavdal wrote: > Hi all, > > On 6.3, using both octeon and amd64. > > While ospfd is running, I would like to add another interface (let’s say a > loopback if). After adding the loopback if to ospf as passive I reload > with ospfctl, but

Re: alien OSPF route

2018-09-14 Thread Remi Locherer
On Fri, Sep 14, 2018 at 03:48:36PM +0200, Marko Cupać wrote: > On Fri, 14 Sep 2018 15:27:30 +0200 > Remi Locherer wrote: > > > Did you save the console output and daemon log from the restart? > > Can you share it? > > I restarted ospfd again with rcctl, cons

Re: alien OSPF route

2018-09-14 Thread Remi Locherer
On Fri, Sep 14, 2018 at 10:07:35AM +0200, Marko Cupać wrote: > On Thu, 13 Sep 2018 21:13:11 +0200 > Remi Locherer wrote: > > > On Thu, Sep 13, 2018 at 05:21:37PM +0200, Marko Cupać wrote: > > > Hi, > > > > > > I saw this in my log for the first time, a

Re: alien OSPF route

2018-09-13 Thread Remi Locherer
On Thu, Sep 13, 2018 at 05:21:37PM +0200, Marko Cupać wrote: > Hi, > > I saw this in my log for the first time, after adding 'no redistribute > default': > > ospfd[10921]: alien OSPF route 10.30.1.47/32 > > My ospfd.conf is quite minimal: > > router-priority 0 > router-id IP.ADD.RE.SS > no

Re: 4k display on integrated Intel graphics?

2018-06-30 Thread Remi Locherer
On Fri, Jun 29, 2018 at 11:04:12PM +0200, Maximilian Pichler wrote: > On Fri, Jun 29, 2018 at 9:49 PM, Bryan Vyhmeister > wrote: > > It should work fine because the USB-C ports have DisplayPort signaling > > built-in and I would not expect any issues. > > > >

Re: OpenBSD-based network switch with >16 GigE ports.

2018-04-10 Thread Remi Locherer
On Sat, Apr 07, 2018 at 12:01:54AM +0200, Karel Gardas wrote: > > > Hello, > > I'm looking to buy a new switch for house network. Ideally I'd like to setup > everything here on OpenBSD, but I'm not lucky > to find any OpenBSD-based switch. I need just GigE ports, at least 18-20. > Preferably

Re: OSPF over gif on top of IPsec transport -current

2018-03-13 Thread Remi Locherer
On 2018-03-13 07:28, David Gwynne wrote: On 11 Mar 2018, at 05:30, Atanas Vladimirov <vl...@bsdbg.net> wrote: On 2018-03-10 00:01, Remi Locherer wrote: With below diff the setup works as expected: tcpdump shows OSPF hellos on gif0 and ospfd sees the neighbour. I don't think it's the c

Re: OSPF over gif on top of IPsec transport -current

2018-03-09 Thread Remi Locherer
On Fri, Mar 09, 2018 at 06:13:10PM +0100, Remi Locherer wrote: > On Sun, Mar 04, 2018 at 01:08:21PM +0200, Atanas Vladimirov wrote: > > Hi, > > > > I can't make OSPF to work on gif over IPsec. > > With tcpdump on gif I see the OSPFv2-hello only from localhost: >

Re: OSPF over gif on top of IPsec transport -current

2018-03-09 Thread Remi Locherer
On Sun, Mar 04, 2018 at 01:08:21PM +0200, Atanas Vladimirov wrote: > Hi, > > I can't make OSPF to work on gif over IPsec. > With tcpdump on gif I see the OSPFv2-hello only from localhost: > > # R1 > [ns]~$ tcpdump -nei gif0 > tcpdump: listening on gif0, link-type LOOP > 23:19:29.181685

Re: touchpad input driver: testing needed

2017-08-03 Thread Remi Locherer
On Thu, Aug 03, 2017 at 10:48:12PM +0200, Ulf Brosziewski wrote: > Sorry, I should have been more explicit in my message: Not all > hardware and driver setups are supported yet. Your touchpad is > a HID device, a "Windows Precision Touchpad". Up to now, the > hardware driver (imt(4)) hasn't

Re: touchpad input driver: testing needed

2017-08-03 Thread Remi Locherer
On Mon, Jul 31, 2017 at 11:02:28PM +0200, Ulf Brosziewski wrote: > for you. As always, a dmesg would be appreciated. The output of > # wsconsctl | grep 'mouse' > could also be of interest here (you must run it as root). This is from a Dell XPS 13 9343. The mouse pointer moves into the wrong

Re: Read sysctl from file

2017-07-21 Thread Remi Locherer
On Thu, Jul 20, 2017 at 06:14:03PM -0700, Lyndon Nerenberg wrote: > > > On Jul 20, 2017, at 6:35 AM, BARDOU Pierre wrote: > > > > Hello, > > > > Is there a way to make sysctl re-read its conf file, or even another file, > > like sysctl -p does on linux systems ? > >

"groups in groups" with pf tables

2017-06-05 Thread Remi Locherer
Hi, With other firewall products I like to use groups that contain groups. In pf I like working with tables. Tables can be negated and rules with tables are faster than ones with long lists. I tried to use something like this: $ cat pf-examples.conf host_a1 =

Re: ipsec ... again

2017-04-19 Thread Remi Locherer
On Tue, Apr 18, 2017 at 01:35:58PM +0200, Markus Rosjat wrote: > Hi there, > > since my attempt with ikev2 failed I thought I go back to ikev1 but it seems > since the last time I used it something has changed with that too. > > I simply try to set up a site to site tunnel with a PSK > > here

Re: dig/nslookup limitations - can only do NSLOOKUPs using port 53

2017-01-15 Thread Remi Locherer
On Mon, Jan 16, 2017 at 06:58:59AM +0100, Sebastien Marie wrote: > On Mon, Jan 16, 2017 at 03:37:11PM +1100, Damian McGuckin wrote: > > On Mon, 16 Jan 2017, Stuart Henderson wrote: > > > [...] > > > > > > Prior to the change to make -p an error, but after the dns pledge was > > > added, -p was

Re: radicale and httpd

2017-01-14 Thread Remi Locherer
On Sat, Jan 14, 2017 at 11:06:29AM +, Stuart Henderson wrote: > On 2017-01-13, Jan Lambertz wrote: > > Hi, > > > > having Problems for some time now with the webserver in python2/3 and > > radicale, i tried to get it working with httpd. > > > > installed flup. python

Re: rsyslog does not produce log on OpenBSD 6.0

2016-12-17 Thread Remi Locherer
On December 17, 2016 12:07:18 PM GMT+01:00, Federico Donati wrote: >Hi all, > >I've a problem with an OpenBSD 6.0 box with rsyslog. > >I need to send every local logs to a remote server and I can't use >syslogd, because it does not send the hostname of the server (the one

Re: OSPFD over IPSEC

2016-11-14 Thread Remi Locherer
On Mon, Nov 14, 2016 at 04:50:21PM +, Comète wrote: > 14 novembre 2016 14:50 "Remi Locherer" <remi.loche...@relo.ch> a écrit: > > On > 2016-11-14 12:48, Comète wrote: > > > >> Hi, > >> I'm trying to run OSPFD over > IPSEC with OpenBS

Re: OSPFD over IPSEC

2016-11-14 Thread Remi Locherer
On 2016-11-14 12:48, Comète wrote: Hi, I'm trying to run OSPFD over IPSEC with OpenBSD 6.0 stable, so I first start looking at http://undeadly.org/cgi?action=article=20131105075303 Now that etherip has it's own interface in 6.0, I tried to replace gif with etherip like this: On one host:

Re: Routes to downed interfaces

2016-10-31 Thread Remi Locherer
On Sun, Oct 30, 2016 at 12:36:12PM +0100, Jasper Siepkes wrote: > Hi all, > > I've got a question about how OpenBSD deals with routes and interfaces > that are considerd 'down'. I've noticed that when an interface in > OpenBSD is down the route to that interface will remain in the routing >

Re: axen(4) usb ethernet problems

2016-10-14 Thread Remi Locherer
On Thu, Oct 13, 2016 at 05:40:18PM -0700, Ilya Kaliman wrote: > Hi! > > I have a "Plugable USB 3.0 ethernet adapter" with ASIX AX88179 > chipset. The device is successfully recognized by axen(4) driver but > behaves strangely. When I plug in the ethernet cable the ifconfig > axen0 status says

Re: starting ssh-agent on ssh login

2016-10-08 Thread Remi Locherer
On Sat, Oct 08, 2016 at 04:44:16PM -0400, Predrag Punosevac wrote: > I just want to give an update to this thread. I got lots of replays off > the list as well but not the answer I was looking for > > For now Iexperimented with the single > > eval `ssh-agent -t 60` > > in my .profile file

Re: starting ssh-agent on ssh login

2016-10-08 Thread Remi Locherer
On Sat, Oct 08, 2016 at 09:41:41AM -0400, Predrag Punosevac wrote: > "soko.tica" wrote: > > > Hi Predrag, > > > > I am not sure that I am getting your question right, but for starting ssh > > agent on my lap, I simply uncomment (or create?) the following in my > > .xinitrc

Re: Looking for DMVPN implementation

2016-10-02 Thread Remi Locherer
On Sat, Oct 01, 2016 at 10:44:02PM +, Jens Sauer wrote: > Hi OpenBSD community, > > i'm looking for an OpenSource implementation of DMVPN (Dynamic Multipoint > Virtual private network). > > Currently i just found the draft (from 2013) : > https://tools.ietf.org/html/draft-detienne-dmvpn-00

Re: Logging/backup .ksh_history

2016-08-08 Thread Remi Locherer
On Mon, Aug 08, 2016 at 11:22:33AM +0200, Kamil Cholewiński wrote: > On Mon, 08 Aug 2016, Francois Pussault wrote: > >> > >> From: Craig Skinner > >> Sent: Mon Aug 08 09:49:11 CEST 2016 > >> To:

Re: SSH key encryption when using FDE

2016-08-01 Thread Remi Locherer
On Mon, Aug 01, 2016 at 07:10:21PM -0300, Hugo Osvaldo Barrera wrote: > Hi, > > I've always used password-protected ssh keys, with ssh-agent, and in > recent year, I've been using full disk encryption as well. > I'm wondering if there's some redundancy here, and if using FDE > nullifies the need

Re: internet connection issues

2016-06-23 Thread Remi Locherer
On Wed, Jun 22, 2016 at 03:05:56PM -0400, Sonic wrote: > Have a client whose Internet connection is less then reliable. It's > cable service and the cable company always claims there is nothing > wrong on their end. Of course the service is intermittent and by the > time the onsite clerk calls the

Re: dhclient.conf and hostname.if

2016-05-06 Thread Remi Locherer
On Fri, May 06, 2016 at 06:21:00AM -0600, Duncan Patton a Campbell wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Fri, 06 May 2016 12:06:58 +0100 > Mark Carroll wrote: > > > On 06 May 2016, Duncan Patton a. Campbell wrote: > > > > > Is there any similar tag to

Re: Dualbooting with GRUB in a UEFI environment

2016-03-02 Thread Remi Locherer
On Mon, Feb 29, 2016 at 11:19:57AM -0600, joshua stein wrote: > On Mon, 29 Feb 2016 at 15:19:24 +0100, Noth wrote: > > Hi misc@, > > > > I just cracked this and it doesn't seem to be well documented so I thought > > I'd stick it here. > > > > My setup is a VAIO laptop dualbooting Ubuntu 16.04

Re: can't run multiple instances of httpd, flags not visible in processes

2016-01-28 Thread Remi Locherer
On Thu, Jan 28, 2016 at 06:52:18PM +0100, Ingo Schwarze wrote: > Hi, > > Antoine Jacoutot wrote on Thu, Jan 28, 2016 at 10:41:52AM +0100: > > > As mentioned in another thread already: > > # ln -s /etc/rc.d/mydaemon /etc/rc.d/mydaemon2 > > Then use mydaemon2_flags ... in rc.conf.local. > > This

Dell XPS 9343 and OpenBSD

2016-01-14 Thread Remi Locherer
Hi, I read tedu@'s post about OpenBSD on laptops and thought a little report about running -current on Dell XPS 13 might be interest. http://www.tedunangst.com/flak/post/openbsd-laptops I'm running -current on this and use it daily. o Graphics: Works ok with the modsetting driver (now

problem mounting ext4 filesystem

2016-01-05 Thread Remi Locherer
Hi, I tried to mount an ext4 filesystem on OpenBSD which was created on CentOS7. I get this: remi@mistral:~% doas mount -t ext2fs /dev/sd0m /mnt mount_ext2fs: /dev/sd0m on /mnt: specified device does not match mounted device remi@mistral:~% dmesg | grep incomp ext2fs: unsupported incompat

Re: audio codec RealTek ALC3263

2015-09-20 Thread Remi Locherer
On Sun, Sep 20, 2015 at 08:17:59AM +0200, Remi Locherer wrote: > On Sat, Sep 19, 2015 at 07:26:56PM -0400, Bryan Steele wrote: > > On Sat, Sep 19, 2015 at 06:44:13PM -0400, Bryan Steele wrote: > > > On Sat, Sep 19, 2015 at 02:38:02PM +0200, Remi Locherer wrote: > > > &g

Re: audio codec RealTek ALC3263

2015-09-20 Thread Remi Locherer
On Sun, Sep 20, 2015 at 05:45:08PM +0200, Alexandre Ratchov wrote: > On Sat, Sep 19, 2015 at 10:59:53PM +0200, Remi Locherer wrote: > > azalia0 at pci0 dev 3 function 0 "Intel Core 5G HD Audio" rev 0x09: msi > > azalia_reset: resetting > > azalia_reset: reset counter

Re: audio codec RealTek ALC3263

2015-09-19 Thread Remi Locherer
On Sat, Sep 19, 2015 at 08:31:24PM +, Alexey Suslikov wrote: > Remi Locherer relo.ch> writes: > > > My Dell XPS 13 has a RealTek ALC3263 codec (according to the BIOS). In > > dmesg only the following shows up: > > > > azalia0 at pci0 dev 3 function 0 "

Re: Can't ping IPv6

2015-09-15 Thread Remi Locherer
On Tue, Sep 15, 2015 at 10:01:03PM +0100, Mark Carroll wrote: > I have a fairly vanilla OpenBSD 5.7 installation on > a machine for which my provider told me, > > Net : 5.28.62.155, 2001:41c9:1:41c::155 > > My pf.conf is simple; it still has the, > block return# block stateless traffic >

hp dl360 gen9

2015-07-17 Thread Remi Locherer
Hi, I'm just starting to use hp dl360 gen9 servers with OpenBSD. With a few tweaks in the bios most stuff works fine: System Options o Processor Options - Hyperthreading - disable # HT does not help on a OpenBSD firewall - Core disable - 4 # That way the other cores can run at

Re: Firewall: Where is the bottleneck?

2014-10-29 Thread Remi Locherer
On Tue, Oct 28, 2014 at 10:13:54PM +0100, jum...@yahoo.de wrote: Hi Andy, sorry for the delay, but a lot of more important work were between your mail and this answer ;). You can set a simple prio on a rule like; pass proto tcp from $left to $right set prio (1,4) With PRIQ I mean the

Re: 5.6 arrived

2014-10-29 Thread Remi Locherer
On Wed, Oct 29, 2014 at 04:54:26PM +0100, Harald Dunkel wrote: Hi Oliver, On 10/28/14 14:23, Oliver Peter wrote: If the difference between release and snapshot is too confusing for you, you should probably just stay with release. If you need releases on time you should order a CD set

Re: Firewall cluster.

2014-07-08 Thread Remi Locherer
On Mon, Jul 07, 2014 at 08:44:43PM +0200, Mxher wrote: Hello again, I'm doing few more tests and now I'm wondering if this is possible to disallow CARP to have some resources on serverA and others on serverB? Have you set the sysctl net.inet.carp.preempt=1? Here is my tests (advbase=1

Re: problem with IPSec between OpenBSD 5.5 and Cisco 2901

2014-06-18 Thread Remi Locherer
On Tue, Jun 17, 2014 at 05:34:27PM +0200, Sebastian Reitenbach wrote: Hi, I'm trying to establish an IPSec tunnel between an OpenBSD 5.5 (amd64) box and a Cisco 2901, the whole day, but doesn't seem to get it to work. I think I have something wrong with the crypto transforms for phase two,

Re: Find last month abbreviation

2014-04-18 Thread Remi Locherer
On Fri, Apr 18, 2014 at 04:06:18PM +0200, Ingo Schwarze wrote: Hi, lilit-aibolit wrote on Fri, Apr 18, 2014 at 03:24:36PM +0300: $ date --date=last month +%b Mar Time for a little shell golfing? Look, i'll play it nice and even add two blanks for readability. $ date -j +%b

Re: smokeping errors on OpenBSD 5.4

2014-04-06 Thread Remi Locherer
On Sat, Apr 05, 2014 at 10:37:40PM +0200, Thorleif Wiik [BCIX] wrote: Hey all, just tried to run smokeping on OpenBSD 5.4, but I have the following error after installing it with pkg_add smokeping # smokeping --help Can't load

USB Ethernet ASIX AX88179 not attaching to axen

2014-03-27 Thread Remi Locherer
I tried an Edimax USB Ethernet adapter on my -current system. It attaches as ugen1 but not as axen0: ugen1 at uhub3 port 2 ASIX Elec. Corp. AX88179 rev 2.10/1.00 addr 3 According to axen(4) this device should be supported. But config does not find axen. Is this becaus usb is handled differently

Re: dhclient

2014-01-31 Thread Remi Locherer
Quoting Holger Glaess gla...@glaessixs.de: Am 30.01.2014 13:10, schrieb Giancarlo Razzolini: Em 29-01-2014 18:13, Holger Glaess escreveu: hi i try to setup and multipath configuration with 2 line provider 1 cable with dhcp(client) 1 with pppoe just dynamic ips. the pppoe config create

Re: unbound dnssec revisited

2013-12-30 Thread Remi Locherer
On Mon, Dec 30, 2013 at 03:22:34PM -0500, Ted Unangst wrote: On Mon, Dec 30, 2013 at 12:10, Chris Smith wrote: I've been working on using dnssec with the unbound package and viewing some of the threads here on the list regarding this. Enabling autotrust and the validator module in

Re: spdy support on base nginx

2013-09-08 Thread Remi Locherer
On Sun, Sep 08, 2013 at 11:21:58AM -0600, Alvaro Mantilla Gimenez wrote: Hi, Do nginx from base installation (5.3) support SPDY? I didn't found any reference in man pages and/or ports. The SPDY module was added to base nginx on July 1 2013 [1] but disabled later [2]. [1]

Re: IPSec tunnel doesn't work after CARP fail over (no fast fail over).

2013-07-22 Thread Remi Locherer
Hi On Mon, Jul 22, 2013 at 12:56:38PM +0100, Andy wrote: Hi, I hope this is helpful to someone else and maybe a dev could add this solution (or an improvement thereof) into the code as standard. - I found an issue with IPSec and OpenBSD with CARP during fail-over, whereby a fail over

Re: current snapshot: pc powered down for high cpu temp

2013-07-19 Thread Remi Locherer
On Thu, Jul 18, 2013 at 06:08:17PM +0200, Riccardo Mottola wrote: Hi, I upgraded to a currents snapshot today (I was using one of July 9 previously). Now if I power on my laptop, it will boot, get about to the loign prompt, say my CPU temperature is 5296C and starts a shut down.

Re: OpenSMTPd error after upgrading to -current

2013-02-03 Thread Remi Locherer
On Sun, Feb 03, 2013 at 10:19:02PM +0100, Frank Brodbeck wrote: Hi, I upgraded yesterday to the latest snapshot and have a problem with my smtpd.conf which I can't resolve: /etc/mail/smtpd.conf:12: error: invalid url: smtps+auth://mail.split-brain.de The corresponding line is: #

Re: nfs_server=YES in /etc/rc.conf.local does not work

2012-10-28 Thread Remi Locherer
The problem is that they are still visible to the search function. Well, at least the spanish one was. In this case maybe the search stuff should only return original pages, not the translated ones. maybe this patch helps. remi Index: robots.txt

Re: problem setting inet6 route

2012-09-04 Thread Remi Locherer
On Sat, Sep 01, 2012 at 01:29:02PM -0700, Philip Guenther wrote: On Fri, Aug 31, 2012 at 7:52 AM, Remi Locherer remi.loche...@relo.ch wrote: On Fri, Aug 31, 2012 at 09:47:39AM -0400, Simon Perreault wrote: Le 2012-08-31 03:19, Remi Locherer a ?crit : I rented a server from Hetzner where I

Re: problem setting inet6 route

2012-09-01 Thread Remi Locherer
On Fri, Aug 31, 2012 at 09:01:44PM +0200, Joakim Aronius wrote: * Remi Locherer (remi.loche...@relo.ch) wrote: Hi I rented a server from Hetzner where I installed OpenBSD 5.1. Hetzner also provides IPv6 but somehow with a strange setup. I got something like the following from them

problem setting inet6 route

2012-08-31 Thread Remi Locherer
Hi I rented a server from Hetzner where I installed OpenBSD 5.1. Hetzner also provides IPv6 but somehow with a strange setup. I got something like the following from them: Gateway Address: 2001:db8:1:1110::1/64 Subnet I can use: 2001:db8:1:/64 If I now assign for example

Re: problem setting inet6 route

2012-08-31 Thread Remi Locherer
On Fri, Aug 31, 2012 at 09:22:06AM +, Stuart Henderson wrote: On 2012-08-31, Remi Locherer remi.loche...@relo.ch wrote: I rented a server from Hetzner where I installed OpenBSD 5.1. Hetzner also provides IPv6 but somehow with a strange setup. I got something like the following from

Re: problem setting inet6 route

2012-08-31 Thread Remi Locherer
On Fri, Aug 31, 2012 at 04:27:50PM +0200, Claudio Jeker wrote: On Fri, Aug 31, 2012 at 09:22:06AM +, Stuart Henderson wrote: On 2012-08-31, Remi Locherer remi.loche...@relo.ch wrote: I rented a server from Hetzner where I installed OpenBSD 5.1. Hetzner also provides IPv6 but somehow

Re: problem setting inet6 route

2012-08-31 Thread Remi Locherer
On Fri, Aug 31, 2012 at 09:47:39AM -0400, Simon Perreault wrote: (I rearranged your email: provider info at the top, your actions at the bottom.) Le 2012-08-31 03:19, Remi Locherer a ?crit : I rented a server from Hetzner where I installed OpenBSD 5.1. Hetzner also provides IPv6 but somehow

Re: softraid questions

2012-08-20 Thread Remi Locherer
Hi chris On Mon, Aug 20, 2012 at 07:53:25AM -0600, Chris Lobkowicz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Pardon the noise, but I'm wondering if softraid supports nested raid types? Specifically, I'm looking to do a raid 0+1 over 4 drives. A mirror of stripes. wd1 wd2

Re: softraid questions

2012-08-20 Thread Remi Locherer
On Mon, Aug 20, 2012 at 04:02:19PM +0200, Remi Locherer wrote: Hi chris On Mon, Aug 20, 2012 at 07:53:25AM -0600, Chris Lobkowicz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Pardon the noise, but I'm wondering if softraid supports nested raid types? Specifically, I'm

Re: Suspect fragmented packets.

2012-08-05 Thread Remi Locherer
On Mon, Aug 06, 2012 at 12:54:48AM +0930, David Walker wrote: Daniel Melameth daniel () melameth ! com wrote: When using pppoe(4), MSS can be a problem. I recommend you read the MTU/MSS ISSUES section of the man page and see if that resolves your issue. I have read and tried. As far as

Re: ipsec + mtu configuration

2012-07-17 Thread Remi Locherer
Is there nobody with a config that allows pmtu discovery with ipsec? On Fri, Jul 06, 2012 at 04:49:31PM +0200, Remi Locherer wrote: Hi misc@ We got notice from a customer who connects to us through an ipsec tunnel that loading websites on our site is really slow. On our site we use OpenBSD

ipsec + mtu configuration

2012-07-06 Thread Remi Locherer
Hi misc@ We got notice from a customer who connects to us through an ipsec tunnel that loading websites on our site is really slow. On our site we use OpenBSD 5.0 i386 as ipsec gateway. On the other site of the VPN is a Linux StrongSwan gateway. Our analysis showed that our webserver starts

acceleration for softraid crypto

2011-09-10 Thread Remi Locherer
Hi I'm running OpenBSD 4.9 on an Atom based system. On that system one disk is encrypted using softraid. When I do dd if=/dev/zero of=/dev/rsd0c bs=1m (sd0 is the encrypted softraid device) systat shows a speed of ~ 9200K and 90% sys cpu usage. To speed up the encryption I'm looking at the

Re: OpenLDAP

2011-01-10 Thread Remi Locherer
Hi Friedich It's in current: http://marc.info/?l=openbsd-portsm=129440451210138w=2 Regards, Remi On 01/11/2011 12:56 AM, Friedrich Locke wrote: Hi folks, is there plan for openbsd support openldap with recent version(s) of bdb ? Thanks in advance, Gustavo.