Re: flaky network connection after 6.1 upgrade

2017-04-20 Thread Stefan Sperling
On Wed, Apr 19, 2017 at 10:08:01AM +0200, Stefan Sperling wrote: > On Tue, Apr 18, 2017 at 11:29:22PM -0500, Colton Lewis wrote: > > > Can you show me a dmesg please, specifically the lines which are > > > related to your wifi card? > > > athn0 at pci6 dev 0 functi

Re: flaky network connection after 6.1 upgrade

2017-04-18 Thread Stefan Sperling
On Tue, Apr 18, 2017 at 01:15:38AM -0500, Colton Lewis wrote: > I tried channels 2, 5, and 10 with no better luck. > > Could you explain what made you think interference? > My computer and AP have been in their current spots for months with no > issue, and no new sources of come around > to the

Re: iwm0: could send power command (error 35), cd0 SENSE KEY: Not Ready

2017-04-17 Thread Stefan Sperling
On Mon, Apr 17, 2017 at 12:15:58AM +0200, Christoph R. Murauer wrote: > Hello ! > > I installed OpenBSD 6.1-current on a ThinkPad w541 (last 2 dmesgs are > below) without problems. iwm works without problems and from time to > time I see the message > > cd0(ahci0:5:0): Check Condition (error

Re: flaky network connection after 6.1 upgrade

2017-04-17 Thread Stefan Sperling
On Sun, Apr 16, 2017 at 05:31:58PM -0500, Colton Lewis wrote: > Stephan, > > > I would guess you are running into some issue with 802.11n support which > > was added to this driver in 6.1. You should be able to restore the previous > > behaviour with: ifconfig athn0 mode 11g > > Your hunch was

Re: flaky network connection after 6.1 upgrade

2017-04-16 Thread Stefan Sperling
On Sat, Apr 15, 2017 at 10:06:44PM -0500, Colton Lewis wrote: > After upgrading to 6.1, I have been unable to maintain an internet > connection for more than a few seconds at a time. > > The machine in question uses an Atheros AR9281 for a wifi connection. > All other machines on that wifi

Re: Free firmware for AR9285

2017-04-13 Thread Stefan Sperling
On Thu, Apr 13, 2017 at 11:08:56AM +0200, Stefan Sperling wrote: > On Wed, Apr 12, 2017 at 06:14:36PM -0400, thinkpad-e535-user wrote: > > I'm wondering why does Atheros AR9285 need binary firmware on OpenBSD? > > According to this wikipedia article [1] it works on Linux and FreeBS

Re: Free firmware for AR9285

2017-04-13 Thread Stefan Sperling
On Wed, Apr 12, 2017 at 06:14:36PM -0400, thinkpad-e535-user wrote: > I'm wondering why does Atheros AR9285 need binary firmware on OpenBSD? > According to this wikipedia article [1] it works on Linux and FreeBSD > with some free firmware. Is that in theory possible for OpenBSD to use > it too? >

Re: OpenBSD as a non-routing access point

2017-04-12 Thread Stefan Sperling
On Tue, Apr 11, 2017 at 08:04:45PM -0500, Jordon wrote: >/ets/hostname.athn0 > media autoselect mode 11n media opt host ap chan 1 Is there actual whitespace between 'media' and 'opt' and between 'host' and 'ap' in your config file? Or is this a copy/paste error? It should look like this:

Re: Adding default IPv6 route fails on 6.1

2017-04-12 Thread Stefan Sperling
On Wed, Apr 12, 2017 at 01:20:20AM +0200, Sterling Archer wrote: > Hello everyone. > > After upgrading to 6.1 about an hour ago, I noticed that I didn't have an > IPv6 connection > anymore. > > I use dhcpcd over a pppoe session, which worked fine in 6.0-stable. The > problem seems to > be a

Re: Driver support for WLE600vx/802.11ac

2017-04-12 Thread Stefan Sperling
On Tue, Apr 11, 2017 at 08:34:34PM -0400, Nathan Van Ymeren wrote: > Hello, > > I am putting together a PCengines machine, and I need some clarification > about support in OpenBSD for the WLE600vx wifi card. This card claims to > support 802.11a/b/g/n/ac and uses the Qualcomm Atheros QCA9882

Re: OpenBSD as a non-routing access point

2017-04-09 Thread Stefan Sperling
On Sat, Apr 08, 2017 at 09:43:29AM -0500, Jordon wrote: > > > On Apr 8, 2017, at 3:38 AM, Stefan Sperling <s...@stsp.name> wrote: > > > > On Fri, Apr 07, 2017 at 05:06:22PM -0500, Jordon wrote: > >> My new wifi adapter finally arrived today (AR9271) so I

Re: OpenBSD as a non-routing access point

2017-04-08 Thread Stefan Sperling
On Fri, Apr 07, 2017 at 05:06:22PM -0500, Jordon wrote: > My new wifi adapter finally arrived today (AR9271) so I want to give hostap a > try with its new 802.11n support. > Am I on the right track? No. AR9271 is a USB device, and unfortunately there are bugs in the driver that prevent hostap

Re: WPA2 dhcp fails on iwi after 3/1/17 security fix (#018)

2017-03-29 Thread Stefan Sperling
On Wed, Mar 29, 2017 at 04:10:15PM +0200, Stefan Sperling wrote: > New diff which fixes another problem where the iwi(4) firmware won't > receive data frames which are protected with RTS frames. This diff > makes iwi(4) work against WPA2 11n athn(4) hostap. Committed. This fix will

Re: WPA2 dhcp fails on iwi after 3/1/17 security fix (#018)

2017-03-29 Thread Stefan Sperling
On Wed, Mar 29, 2017 at 12:22:32PM +0200, Stefan Sperling wrote: > On Wed, Mar 29, 2017 at 10:50:07AM +0200, Stefan Sperling wrote: > > iwi(4) is being stupid and does not forward state changes to the > > net80211 stack. It is a wonder this driver even works at all. > > Pleas

Re: ALIX2C1 as an AP

2017-03-29 Thread Stefan Sperling
On Wed, Mar 29, 2017 at 02:28:18PM +0200, Jan Stary wrote: > Another card shows up as fxp(4) which is Intel EtherExpress. That is not a wifi device. It is Ethernet. > Another is ath(4). It works, but e.g. the ipad reports > "suboptimal performance" and suggests a wifi that can do 802.11n/ac >

Re: WPA2 dhcp fails on iwi after 3/1/17 security fix (#018)

2017-03-29 Thread Stefan Sperling
On Wed, Mar 29, 2017 at 10:50:07AM +0200, Stefan Sperling wrote: > iwi(4) is being stupid and does not forward state changes to the > net80211 stack. It is a wonder this driver even works at all. Please ignore the previous diff. I misunderstood how iwi(4) implements state transitions. It is

Re: WPA2 dhcp fails on iwi after 3/1/17 security fix (#018)

2017-03-29 Thread Stefan Sperling
On Tue, Mar 28, 2017 at 11:22:17PM -0500, bg2...@jamesjerkinscomputer.com wrote: > I follow i386 stable and after applying the WPA1/WPA2 MITM fix to 6.0 (#018) > I can no longer obtain an IP address via dhclient when WPA2 is in use. This > happens with both PSK and enterprise modes (via

Re: Encryption

2017-03-24 Thread Stefan Sperling
On Fri, Mar 24, 2017 at 08:46:09AM -0700, Ken wrote: > I've read things that allude to a lack of support... > > "Much like support for RAID-5, support for encrypted filesystems is > experimental." - Absolute OpenBSD 2nd Edition (2013), page 166. > > But a better source than this slowly aging

Re: 802.11n hostap - latency and timeouts

2017-03-22 Thread Stefan Sperling
On Wed, Mar 22, 2017 at 02:42:19PM +, Kevin Chadwick wrote: > In case it is of any help to anyone. I tried 11n on a ar9271 a few weeks > ago and also an ar2133. Both would give athn0: device timeouts but the usb > ar9271 needed a ifconfig down up to recover whereas the card recovered by >

Re: 802.11n hostap - latency and timeouts

2017-03-20 Thread Stefan Sperling
On Sun, Mar 19, 2017 at 03:14:05PM +, Tom Murphy wrote: > Hi, > > I'm running my athn(4) device in hostap mode. I noticed, when it's set to > 802.11n, I get higher latency (pinging the OpenBSD AP) and disconnections > every few minutes. The Wifi clients are Linux-based (Android and Debian).

Re: Fw: Re: AP using AR9287 working yesterday, broken today.. How to diagnose? **THINK I FOUND A BUG**

2017-03-05 Thread Stefan Sperling
On Sat, Mar 04, 2017 at 08:22:55PM -0500, tec...@protonmail.com wrote: > Ok, I solved the issue. It's a strange one. I noticed that the AP > always uses channel 2, but when I set a channel explicitly within the > hostname.athn0 config then everything would work. So I tried leaving > the channel

Re: Speed tests on 11n / 11g and on different channels with the latest 6.1 snapshot from yesterday. Patterns can be observed.

2017-03-05 Thread Stefan Sperling
On Sat, Mar 04, 2017 at 11:16:28PM -0500, tec...@protonmail.com wrote: > Hi, > > I have performed some speed tests with my AP (AR9287) using both 11g and 11n. > I am on the latest 6.1 snapshot from yestrerday. Thanks for taking the time to test! > For comparison sake, I have included tests on

Re: AP using AR9287 working yesterday, broken today.. How to diagnose?

2017-03-05 Thread Stefan Sperling
On Sat, Mar 04, 2017 at 07:18:18PM -0500, tec...@protonmail.com wrote: > Hi, > > Apologies - missed the important bits! > > > > # ifconfig -a It is unwise to run this command as root if you intend to paste its output in a public forum. As root the output

Re: AP using AR9287 working yesterday, broken today.. How to diagnose?

2017-03-04 Thread Stefan Sperling
On Sat, Mar 04, 2017 at 03:43:16PM -0500, tec...@protonmail.com wrote: > Hello, > > My access point uses an Atheros AR9287 and I'm failing to figure out why it's > not working right. My other wireless devices can see the access point but get > immediately disconnected from it. > > Last night I

Re: AP using AR9287 working yesterday, broken today.. How to diagnose?

2017-03-04 Thread Stefan Sperling
On Sat, Mar 04, 2017 at 11:38:20PM +0200, Mihai Popescu wrote: > > add athn0 > > If i recall correctly, from some discussion on misc@, you cannot use a > wireless interface in a bridge ( athn0 or all, I'm not sure). But > maybe I say something wrong, search the archive. > You can bridge wifi to

Re: softraid & GPT configuration.

2017-03-03 Thread Stefan Sperling
On Fri, Mar 03, 2017 at 01:27:20PM +0100, Eric Huiban wrote: > Hello, > > I should have miss something in the man pages with softraid and bioctl. But > i want to form a RAID 1 between two 3TB harddisk (2.7TiB) and it is acting > like 2TiB MBR disks with OpenBSD 6.0. > > fdisk -ig sd1 is OK. Did

Re: Can OpenBSD do mixed b/g/n mode in hostap?

2017-02-07 Thread Stefan Sperling
On Tue, Feb 07, 2017 at 08:16:10PM +, Tom Murphy wrote: > Hi Stefan, > > I upgraded my kernel to 24 January 2017 and every once in a while I get: > > athn0: device timeout > > I've gotten 3 of these in 12 days. Running: > > ifconfig athn0 down; sh /etc/netstart athn0 > > fixes

Re: getting data from degraded RAID 1 boot disk

2017-02-01 Thread Stefan Sperling
On Wed, Feb 01, 2017 at 08:32:44AM -0500, Jiri B wrote: > On Wed, Feb 01, 2017 at 01:33:54PM +0100, Stefan Sperling wrote: > > On Wed, Feb 01, 2017 at 04:12:26AM -0500, Jiri B wrote: > > > Should have kernel automatically create 'sd4' for degraded RAID 1 > > > but it d

Re: getting data from degraded RAID 1 boot disk

2017-02-01 Thread Stefan Sperling
On Wed, Feb 01, 2017 at 04:12:26AM -0500, Jiri B wrote: > Should have kernel automatically create 'sd4' for degraded RAID 1 > but it does not? I believe it will auto assemble if the disk is present at boot time. But not when you hotplug the disk.

Re: getting data from degraded RAID 1 boot disk

2017-01-31 Thread Stefan Sperling
On Tue, Jan 31, 2017 at 05:23:10PM -0500, Jiri B wrote: > I have a disk which used to be boot disk of a degraded RAID 1 (softraid). > The second disk is totally gone. > > I don't want to use this disk as RAID 1 disk anymore, just to get data > from it. > > I'm asking because when I plugged the

Re: inw0 on Lenovo X230

2017-01-30 Thread Stefan Sperling
On Mon, Jan 30, 2017 at 12:36:31PM +0100, b.gr...@sdnet.info wrote: > This is the line : > nwid Prod_Wifi chan 6 bssid 4a:d9:e7:cd:a9:ad -38dBm 54M > privacy,short_preamble,short_slottime,wpa1 This line says that your AP uses WPA1. In -current WPA1 is disabled by default:

Re: inw0 on Lenovo X230

2017-01-30 Thread Stefan Sperling
On Mon, Jan 30, 2017 at 12:10:56PM +0100, b.gr...@sdnet.info wrote: > Le 30.01.2017 11:58, Stefan Sperling a écrit : > > PLease show the output of 'ifconfig iwn0 scan', in particular the > > entire line which shows the AP you wish to connect to. > > This the ouptut of

Re: inw0 on Lenovo X230

2017-01-30 Thread Stefan Sperling
On Mon, Jan 30, 2017 at 11:59:46AM +0100, b.gr...@sdnet.info wrote: > Hello all, > > I follow current on a Lenovo X230. And i have issue with my internal wifi > card that was work like a charmed few weeks ago. > > I updated this laptop today.The lastest update before was at least 4 weeks > ago.

Re: Installer feature suggestion for the "Which disk is your root disk?" question: If a softraid has been set up, use it as default option suggestion

2017-01-26 Thread Stefan Sperling
On Thu, Jan 26, 2017 at 04:14:34PM +, Christian Weisgerber wrote: > On 2017-01-26, Stefan Sperling <s...@stsp.name> wrote: > > >> Summary: > >> I suggest that, for the "Which disk is your root disk?"'s question in the > >> installer, a logic s

Re: Installer feature suggestion for the "Which disk is your root disk?" question: If a softraid has been set up, use it as default option suggestion

2017-01-26 Thread Stefan Sperling
On Thu, Jan 26, 2017 at 04:59:57PM +0800, Tinker wrote: > Hi, > > Summary: > I suggest that, for the "Which disk is your root disk?"'s question in the > installer, a logic should be added so that if a softraid has been set up, > then it should be used as default option (rather than the name of

Re: Can OpenBSD do mixed b/g/n mode in hostap?

2017-01-25 Thread Stefan Sperling
On Tue, Jan 24, 2017 at 09:00:26PM +, Tom Murphy wrote: > Hi Stefan, > > I've done some more testing. I managed to get 802.11n working in > hostap mode for a while but then it crashed (not a kernel panic but the > driver dropped into ddb mode). Not sure if these help: > > ddb{0}> trace >

Re: athn0: device timeout (AR9271 USB 2.0 Wifi-key as hostap)

2017-01-25 Thread Stefan Sperling
On Tue, Jan 24, 2017 at 03:10:34PM -0500, mabi wrote: > Hi Stefan > Thanks for your input. It looks like the g2k16 modifications to the athn code > from awolk@ did not make it into the 6.0 release. So there is still hope for > 6.1 ;-) There was a rabbit hole this diff by Adam fell into. I don't

Re: apmd

2017-01-24 Thread Stefan Sperling
On Tue, Jan 24, 2017 at 11:52:56AM -0600, Jordon wrote: > > OpenBSD 6.0 (GENERIC.MP) #1992: Tue Jul 26 12:52:55 MDT 2016 > >dera...@i386.openbsd.org:/usr/src/sys/arch/i386/compile/GENERIC.MP > > cpu0: Intel(R) Core(TM) i5-6600 CPU @ 3.30GHz ("GenuineIntel" 686-class) > 3.30 GHz > > > A

Re: athn0: device timeout (AR9271 USB 2.0 Wifi-key as hostap)

2017-01-23 Thread Stefan Sperling
On Mon, Jan 23, 2017 at 11:19:31PM +0100, Stefan Sperling wrote: > On Mon, Jan 23, 2017 at 04:27:32PM -0500, mabi wrote: > > Hi, > > I have an Atheros AR9271 Wifi USB 2.0 key on my OpenBSD 6.0 firewall in > > order to use as an access point. Unfortunately it hap

Re: athn0: device timeout (AR9271 USB 2.0 Wifi-key as hostap)

2017-01-23 Thread Stefan Sperling
On Mon, Jan 23, 2017 at 04:27:32PM -0500, mabi wrote: > Hi, > I have an Atheros AR9271 Wifi USB 2.0 key on my OpenBSD 6.0 firewall in order > to use as an access point. Unfortunately it happens nearly every day that the > athn0 device times out, kernel log: > > athn0: device timeout > > and

Re: Can OpenBSD do mixed b/g/n mode in hostap?

2017-01-15 Thread Stefan Sperling
On Sun, Jan 15, 2017 at 01:53:41PM +, Tom Murphy wrote: > Hi, > > I was wondering if OpenBSD had a way to do mixed b/g/n mode with hostap? > Recently 802.11n support was added for athn(4). I have 4 802.11n devices, > but 1 device which only does 802.11g. If I use 'mode 11n' or even -mode, >

Re: Can I run OpenBSD on an ASUS RT-AC88U?

2017-01-09 Thread Stefan Sperling
On Sun, Jan 08, 2017 at 04:38:43PM +, Andreas Thulin wrote: > Hi! > > Aplogies in advance if this post comes out as tremendously stupid - I'm not > very experienced. No worries. > I bought an ASUS RT-AC88U wireless router. Performance is great, but I lack > the configurability I'm used to

Re: Non-free firmware without asking the user

2017-01-09 Thread Stefan Sperling
On Mon, Jan 09, 2017 at 01:39:41AM +0100, Martin Hanson wrote: > On Sun, 8 Jan 2017, Stefan Sperling wrote: > > >> The above policy applies to the base system code. > >> It does not apply to ports and packages of third party software, i.e. > >> anything > &

Re: Non-free firmware without asking the user

2017-01-07 Thread Stefan Sperling
On Sun, Jan 08, 2017 at 12:02:21AM +0100, Martin Hanson wrote: > On policy page it clearly says: "OpenBSD strives to provide code that can > be freely used, copied, modified, and distributed by anyone and for any > purpose." > > This is MISGUIDING! Where is this secret firmware code which was

Re: Non-free firmware without asking the user

2017-01-07 Thread Stefan Sperling
On Sat, Jan 07, 2017 at 10:16:39AM -0500, Kenneth Gober wrote: > The difference is, closed source firmware runs on the device itself > and if it's buggy, generally the most it will do is make the device > appear to be non-functional or unreliable. If a PCI device has unrestricted DMA access, as

Re: Non-free firmware without asking the user

2017-01-07 Thread Stefan Sperling
On Sat, Jan 07, 2017 at 12:22:55AM +0100, Martin Hanson wrote: > I have misunderstood the purpose and use of the term "free" of OpenBSD > then. > > "OpenBSD strives to provide code that can be freely used, copied, modified, > and distributed by anyone and for any purpose", apparently there exists

Re: iwn problem on Thinkpad T410

2017-01-06 Thread Stefan Sperling
On Fri, Jan 06, 2017 at 12:06:24PM -0500, Donald Allen wrote: > I just installed current from the most recent snapshot on a Thinkpad T410. > Wireless networking doesn't work. During the install, I had an ethernet > cable plugged in and configured the em0 interface (I use static ip > addresses), so

Re: PC Engines APU2xx wireless card for router?

2017-01-02 Thread Stefan Sperling
On Sat, Dec 31, 2016 at 11:13:53AM -0700, Steve Williams wrote: > The PC Engines website lists a WLE200NX which google reveals is a Atheros > AR9280 Wireless Mini PCIe 2.4/5 Ghz Dual Band card. > > According to athn.4, it should be supported and operate as a base station > (router). > > Is this

Re: Hardware recommendations for compact 1U firewall

2016-12-16 Thread Stefan Sperling
On Sat, Dec 17, 2016 at 01:08:50PM +1100, Damian McGuckin wrote: > Assuming traffic going between say 'vr0' and 'vr1', will it a Net5501 > board sustain 100Mbps? I doubt it would. One limiting factor being the number of packets per second. At some point the packets-per-second rate will trigger

Re: Encrypted data partition

2016-12-15 Thread Stefan Sperling
On Thu, Dec 15, 2016 at 07:24:24AM +0100, Carsten Kunze wrote: > So it would really be great to have an up-to-date EncFS... This might be a good opportunity for you to give ports development a go ;-) http://www.openbsd.org/faq/ports/index.html

Re: Too small default root partition

2016-12-12 Thread Stefan Sperling
On Mon, Dec 12, 2016 at 11:26:31AM +0100, Walter Alejandro Iglesias wrote: > It seems the size picked by the partitioner at install time for / isn't > large enough (I choose the defaults except I enlarged /var to run a web > server). > > > OpenBSD 6.0-current (GENERIC.MP) #25: Fri Dec 9

802.11n MIMO support in -current

2016-12-10 Thread Stefan Sperling
The net80211 stack and iwm(4) driver now support MIMO in -current. In my own testing, things work just fine. But I have gotten used to breaking other people's wifi without being aware of it. So please test -current and let me know about any regressions. Because iwm(4) devices have 2 antennas MCS

Re: One of the CARP interfaces stopped sending ARP replies on OpenBSD 6.0

2016-12-06 Thread Stefan Sperling
On Tue, Dec 06, 2016 at 01:48:27PM +0100, Rafał Błaszczyk wrote: > One of CARP interfaces stopped responding on ARP requests on CARP IP - it's > carp1 > > running on physical dev vio1 which is also running pfsync on top. > What I've already checked: > > - ifconfig down and up on carp1 does not

Re: PCI Express wireless adapter supported under OpenBSD

2016-11-30 Thread Stefan Sperling
On Wed, Nov 30, 2016 at 12:07:55PM +, C. L. Martinez wrote: > Ok, I have found a good candidate: TP-LINK TL-WDN4800. According to TP-Link's > webpage uses an Atheros AR9380 chip. But, under athn(4) OpenBSD's man page, > this chip doesn't appears for OpenBSD 6.0 ... but it appears under

Re: PCI Express wireless adapter supported under OpenBSD

2016-11-30 Thread Stefan Sperling
On Wed, Nov 30, 2016 at 01:22:11PM +0100, Stephane HUC "CIOTBSD" wrote: > Better use: > > - TP-Link TL-WDN3200 - run(4) > - TP-Link TL-WN723N v3 - urtwn(4) > - TP-Link TL-WN725N v2 - urtwn(4) <= i've this, and run correctly! (usb > dongle) > - TP-Link TL-WN727N v3 - run(4) > - TP-Link TL-WN821N

Re: PCI Express wireless adapter supported under OpenBSD

2016-11-30 Thread Stefan Sperling
On Wed, Nov 30, 2016 at 10:12:32AM +, C. L. Martinez wrote: > I have discoverd that Asus AC88 AC3100 uses BCM4366 chip, but if I am not > wrong this chip is not supported under OpenBSD, is it right? Indeed, BCM4366 won't work. There are many Atheros AR9280 devices on sites such as ebay. And

Re: PCI Express wireless adapter supported under OpenBSD

2016-11-30 Thread Stefan Sperling
On Wed, Nov 30, 2016 at 09:00:58AM +, Zé Loff wrote: > From (at least) iwn(4) and iwm(4): > > 802.11n operation is currently limited to data rates MCS 0 to MCS 7 > > Which means you'll get at most 150Mbps with a 40 MHz channel under > perfect conditions. Well, given the lack of 40Mhz

Re: PCI Express wireless adapter supported under OpenBSD

2016-11-30 Thread Stefan Sperling
On Wed, Nov 30, 2016 at 08:09:24AM +, C. L. Martinez wrote: > Hi all, > > I would like to install OpenBSD on a HP Microserver Gen8 to act as a > firewall and hostap. I am searching what components I need and I have a doubt > about what wireless interface I need to buy to use it as a hostap

Re: acer swift 7, atheros qca6174 wireless and intel hd 615 video

2016-11-28 Thread Stefan Sperling
On Mon, Nov 28, 2016 at 11:09:12AM -0600, Peter Miller wrote: > As for the wifi, I don't see support for the atheros 6174 chipest in > the man pages, and I don't know if anyone is working on it. As of now > it is "unknown product" in the dmesg. If it is not soldered in, I > would be willing to

Re: Recommendation for firewall appliance running of and OpenBSD

2016-11-24 Thread Stefan Sperling
On Fri, Nov 25, 2016 at 04:15:23AM +0800, Tito Mari Francis H. Escaño wrote: > Hi everyone, > Can somebody please recommend me a firewall appliance that can run OpenBSD and > pf, and can be upgradeable to the latest version? It would be a great plus if > the appliance can also be configured as

Re: Why not use malloc S by default?

2016-11-23 Thread Stefan Sperling
On Tue, Nov 22, 2016 at 10:18:32PM +0100, Benjamin Baier wrote: > On Tue, 22 Nov 2016 19:44:48 +0100 > "minek van" wrote: > > > So why isn't "S" enabled by default? It is the "most secure" solution for > > the > > malloc settings, no? > > Or are there still programs that

Re: strange behaviour with route-to, default route, and ping -I

2016-11-21 Thread Stefan Sperling
On Mon, Nov 21, 2016 at 10:43:17AM -0500, Kenneth Gober wrote: > I get the impression that route-to is applied when a packet enters the > router, > e.g. as part of a "pass in" rule, and that it is used to forcibly direct the > packet to a particular interface for "pass out" rather than relying on

Re: softraid(4) full-disk encryption on SSD

2016-11-16 Thread Stefan Sperling
On Wed, Nov 16, 2016 at 10:23:39AM -0500, Jiri B wrote: > On Wed, Nov 16, 2016 at 09:14:51AM -0600, Ax0n wrote: > > I just purchased a SanDisk SSD for my daily-driver laptop which has been > > running -CURRENT well. I'm considering going with FDE and a fresh snapshot > > install, adding my

Re: Broadcom Wifi Chip Datasheets

2016-11-16 Thread Stefan Sperling
On Tue, Nov 15, 2016 at 10:08:02PM -0800, Chris Cappuccio wrote: > https://twitter.com/marcan42/status/798720961562361857 > > "Cypress bought Broadcom's WiFi business and apparently published all their > formerly unobtainium datasheets": > >

Re: Laptop Recommendations?

2016-11-12 Thread Stefan Sperling
On Fri, Nov 11, 2016 at 08:03:04PM -0600, jordon wrote: > WiFi Just Works! > iwm0 at pci2 dev 0 function 0 "Intel Dual Band Wireless AC 8260" rev 0x3a, > msi Uhmm, you probably wanna be running -current with this one. Then wifi should work even better ;-)

Re: Laptop Recommendations?

2016-11-11 Thread Stefan Sperling
On Fri, Nov 11, 2016 at 12:20:47PM +0100, Robert wrote: > On Fri, 11 Nov 2016 10:21:54 +0100 > harry666t wrote: > > > On 11 November 2016 at 03:25, Brian wrote: > > > Thinkpads are used often by folks wanting to get that penguin OS going > > > also.

Re: Slow wifi

2016-11-10 Thread Stefan Sperling
On Thu, Nov 10, 2016 at 03:22:45PM -0500, Donald Allen wrote: > (FreeBSD doesn't seem to know about iwm yet). After waiting a bit, I > will again try installing -current on a USB drive to see if the > package problems have been resolved. Please do. If it's still broken in -current I'd like to

Re: Slow wifi

2016-11-10 Thread Stefan Sperling
On Thu, Nov 10, 2016 at 10:24:50PM +0200, George Pediaditis wrote: > i currently use stable. I updated my system a week ago. How stable is current? > I use my laptop for programming (java) and im a bit skeptical about > running current. Generally, -current is fine. But if you don't follow our

Re: Slow wifi

2016-11-10 Thread Stefan Sperling
On Thu, Nov 10, 2016 at 09:17:38PM +0200, George Pediaditis wrote: > hello > Im having trouble with wifi. I cant download faster than 523.94kBit/s > Im using the iwm0 driver. Please try -current. This problem should be fixed there.

Re: Laptop Recommendations?

2016-11-10 Thread Stefan Sperling
On Wed, Nov 09, 2016 at 11:47:52PM -0600, Nathan Koch wrote: > Greetings Fair BSD Wizards, > I am new to the lists. I am currently shopping for a new Xmas present for > myself and am looking for a laptop that's portable and lightweight. > Preferably fast, cheap (close to free), light, and

Re: low bandwidth results with IPSEC enabled between two PC Engines APU2C2

2016-11-10 Thread Stefan Sperling
On Thu, Nov 10, 2016 at 10:42:13AM +, Comète wrote: > Now, I can ask the question differently: > > If I don't want the connection to be > reset every half gigabyte, should I better choose isakmpd ? Yes, that is worth trying as a workaround if you don't have clients that require IKEv2. If you

Re: low bandwidth results with IPSEC enabled between two PC Engines APU2C2

2016-11-10 Thread Stefan Sperling
On Thu, Nov 10, 2016 at 09:00:07AM +, Comète wrote: > Oh, should I understand that IKEv2 is unusable on production ? This question is counter-productive because it demotivates volunteers. Developers may help you out of kindness, or they may help you indirectly because the problem affects

Re: npppd troubles

2016-11-04 Thread Stefan Sperling
On Thu, Nov 03, 2016 at 06:48:56PM -0400, Marina Brown wrote: > On 11/03/2016 03:36 PM, Stefan Sperling wrote: > > On Thu, Nov 03, 2016 at 03:17:40PM -0400, Marina Brown wrote: > >> Hi All: > >> > >> I have been trying to create an nppp connection across my prop

Re: npppd troubles

2016-11-03 Thread Stefan Sperling
On Thu, Nov 03, 2016 at 03:17:40PM -0400, Marina Brown wrote: > Hi All: > > I have been trying to create an nppp connection across my property - > about 100M for one of my friends who lives here. He wants less security > than i like behind my firewall. I have not been able to get OpenBSD to >

Re: vmd: /dev/vmm: Operation not supported by device

2016-10-31 Thread Stefan Sperling
On Mon, Oct 31, 2016 at 05:56:12PM +0800, johnw wrote: > Hi, I know my cpu (Intel E8400) support vt-x/vt-d, but when I run vmd, > > vmd: /dev/vmm: Operation not supported by device > Is this cpu support to run vmd? > vmm0 at mainbus0: VMX It seems the current implementation only supports a CPU

Re: softraid crypto performance on Sun Fire T1000

2016-10-29 Thread Stefan Sperling
On Sat, Oct 29, 2016 at 07:53:06PM +0200, Stefan Sperling wrote: > > Are you sure that LDOM was indeed using softraid crypto? > > Yes. Uhm, but the dd command wasn't :-) (the guest's root disk is sd2, not sd0...) Now our numbers align much better: # dd if=/dev/rsd2c of=/dev/null

Re: softraid crypto performance on Sun Fire T1000

2016-10-29 Thread Stefan Sperling
On Sat, Oct 29, 2016 at 07:39:29PM +0200, Jonathan Schleifer wrote: > > I have the 1GHz version with 4 cores (32 threads). > > Ok, so same per-core speed, so single-threaded performance should be the same. > (Btw, you have 8 cores, not 4. 8 cores @ 4 threads each.) > > > Otherwise it's probably

Re: softraid crypto performance on Sun Fire T1000

2016-10-29 Thread Stefan Sperling
On Sat, Oct 29, 2016 at 06:57:00PM +0200, Jonathan Schleifer wrote: > Oh, wow, these are *much* better than what I get. Which CPU do you have? I > have 6x 1 GHz (meaning 24 threads). Are you running 6.0? > > Thank you for these numbers, they make me much more hopeful about this > machine. I

Re: softraid crypto performance on Sun Fire T1000

2016-10-29 Thread Stefan Sperling
On Sat, Oct 29, 2016 at 06:08:37PM +0200, Jonathan Schleifer wrote: > Hm, my main problem seems to be that whenever I decrypt something from the > disk, all other 23 cores seem to get stalled. > > So, would you recommend doing the following then: > > * Have a partition for the main system on a

Re: softraid crypto performance on Sun Fire T1000

2016-10-29 Thread Stefan Sperling
On Sat, Oct 29, 2016 at 05:12:51PM +0200, Jonathan Schleifer wrote: > Another thing I noticed: > > When running dd if=/dev/zero of=foo bs=65536, my SSH connection gets extremely > laggy. If I open 4 more in parallel, all go down to KB/s of writes, and SSH > becomes unusable. Now unusable as in

Re: How should vmm hosts access the internet?

2016-10-13 Thread Stefan Sperling
On Thu, Oct 13, 2016 at 02:23:20PM +0100, Edd Barrett wrote: > Hi, > > Since vmm is now enabled, I thought I would have a play. > > So far so good, but I've not managed to get the host on the internet > yet. > > If I set up a vmm VM on my laptop, we have on the host: > > * iwn0 providing

Re: An AR9280 as an Access Point

2016-10-12 Thread Stefan Sperling
On Wed, Oct 12, 2016 at 05:01:52PM -0400, mabi wrote: > I am using an Atheros AR9281 in a Soekris box with OpenBSD 5.9 as access > point and I am quite disappointed with it. Often I get disconnected from the > access point and all I can see on the OpenBSD side is tons of timeout > messages in

Re: An AR9280 as an Access Point

2016-10-12 Thread Stefan Sperling
On Tue, Oct 11, 2016 at 06:04:55PM +0200, physkets wrote: > Hello! > > I'd asked a related question on the OpenBSD subreddit, and someone > pointed me here. Hope this is appropriate. > https://www.reddit.com/r/openbsd/comments/56lzhu/which_wifi_card_to_make_an_access_point > > Does anyone know

Re: ral(4) problems on current/i396 ALIX

2016-10-05 Thread Stefan Sperling
On Tue, Sep 20, 2016 at 11:53:41AM +0200, Stefan Sperling wrote: > On Tue, Sep 20, 2016 at 10:46:54AM +0200, Jan Stary wrote: > > This is ALIX 2C1, just upgraded to current/i386 (dmesg below). > > It serves as a wifi AP using ral(4). The console gets spammed with > > >

Re: Looking for a way to deal with unwanted HTTP requests using mod_perl

2016-09-30 Thread Stefan Sperling
On Fri, Sep 30, 2016 at 09:46:35AM -0500, Chris Bennett wrote: > On Fri, Sep 30, 2016 at 04:19:58PM +0200, Stefan Sperling wrote: > > On Fri, Sep 30, 2016 at 09:13:43AM -0500, Chris Bennett wrote: > > > Can I redirect to the same server? > > > > I don't see why tha

Re: Looking for a way to deal with unwanted HTTP requests using mod_perl

2016-09-30 Thread Stefan Sperling
On Fri, Sep 30, 2016 at 09:13:43AM -0500, Chris Bennett wrote: > Can I redirect to the same server? I don't see why that shouldn't work. Put your actual web service on some port on 127.0.0.1 and have relayd send the filtered traffic there.

Re: Looking for a way to deal with unwanted HTTP requests using mod_perl

2016-09-30 Thread Stefan Sperling
On Wed, Sep 28, 2016 at 12:20:38PM -0500, Chris Bennett wrote: > I am not sure what is appropriate, given netiqette and practicality for > my server. I am sick of thousands of identical requests in my error log, > plus I want to be able to look over my logs easily to find any real > problems. > >

Re: FDE on BeagleBone Black

2016-09-28 Thread Stefan Sperling
On Wed, Sep 28, 2016 at 06:48:35AM +0200, L.R. D.S. wrote: > Hi, > I'm thinking of buying a new toy board like BeagleBone Black to test the > armv7 port. > It's already possible to do full disk encryption on these boards? I don't think the armv7 bootloader has softraid support at present. You

Re: openiked + rc.conf.local

2016-09-26 Thread Stefan Sperling
On Mon, Sep 26, 2016 at 02:17:35PM +0200, Infoomatic wrote: > also, the already running endpoint did not receive any packets. Nobody on this list can run ifconfig, route, and tcpdump on *your* box to figure out where you're losing packets...

Re: openiked + rc.conf.local

2016-09-26 Thread Stefan Sperling
On Mon, Sep 26, 2016 at 01:56:20PM +0200, Infoomatic wrote: > ipsec=YES in rc.conf.local does not change anything, and appending > "ikelifetime 60" to iked.conf neither. ipsec=YES and /etc/ipsec.conf are for use with isakmpd. iked does not use ipsec.conf. > I am quite sure this is just a minor

Re: ral(4) problems on current/i396 ALIX

2016-09-20 Thread Stefan Sperling
On Tue, Sep 20, 2016 at 10:46:54AM +0200, Jan Stary wrote: > This is ALIX 2C1, just upgraded to current/i386 (dmesg below). > It serves as a wifi AP using ral(4). The console gets spammed with > > ral0: sending data frame failed 0x02faaafa > > This used to work fine since 5.9/i386. This

Re: iwm(4) problems on Dell Latitude E5570

2016-09-16 Thread Stefan Sperling
On Fri, Sep 16, 2016 at 10:35:14AM +0200, Jan Stary wrote: > This is current/amd64 on Dell Latitude E5570 (dmesg below). > I am having problems with the iwm(4) wifi. > > iwm0 at pci1 dev 0 function 0 "Intel Dual Band Wireless AC 8260" rev 0x3a, msi > iwm0: hw rev 0x200, fw ver 16.242414.0,

Re: Routing 10-40 Mpps on OpenBSD

2016-09-12 Thread Stefan Sperling
On Sun, Sep 11, 2016 at 05:46:48PM +, K K wrote: > Chelsio NIcs: Chelsio T540-CR (although not sure there is an OpenBSD driver) There is no driver for these cards. There used to be a work-in-progress driver but it was never finished and hence deleted one year ago. CVSROOT:/cvs Module

Re: Ralink 802.11n Mini PCI

2016-09-05 Thread Stefan Sperling
On Mon, Sep 05, 2016 at 12:15:28PM -0500, Patrick Dohman wrote: > Hello > > Hoping to determine what modern Mini PCI 802.11n adapters are supported by the > RT2800 chipset. In -current, the ral(4) driver supports RT3900E chipsets (with RT5390 and RT5392 MACs). These are more recent so perhaps

Re: Recommendation about an Alfa usb wireless adapter to use it as HostAP

2016-09-02 Thread Stefan Sperling
On Fri, Sep 02, 2016 at 10:41:31AM +0200, David Coppa wrote: > The Alfa AWUS036NHA it's based on the Atheros AR9271 chipset and > should be supported by athn(4). But hostap is broken in the USB athn(4) driver so it's useless as AP. Unless you wish to be hacking wifi drivers, if you want a happy

Re: Installer overwrites partition table

2016-08-24 Thread Stefan Sperling
On Wed, Aug 24, 2016 at 01:15:29PM +0200, Bertram Scharpf wrote: > Hi, > > first of all, I am an experienced OS installer and I did a > heck of partitioning in my life. Now I had some unused disk > space and I found it a good idea to install OpenBSD. > > The installers partitioning tool didn't

Re: ispec - PSK - issues

2016-08-19 Thread Stefan Sperling
On Thu, Aug 18, 2016 at 07:57:40PM +, Justin Mayes wrote: > Hello all - > > I was also recently trying to do a simple ipsec/l2tp vpn. I found that it > works fine for everything except my android 5.1.1 device. This problem and a workaround were already discussed here:

Re: athn0: device timeout with AR9271

2016-07-26 Thread Stefan Sperling
On Tue, Jul 26, 2016 at 07:57:46PM +, ML mail wrote: > Should I upgrade to -CURRENT? Yes!

Re: athn0: device timeout with AR9271

2016-07-25 Thread Stefan Sperling
On Mon, Jul 25, 2016 at 09:57:38AM +, ML mail wrote: > Hi, > > I installed a USB Wifi card on my OpenBSD 5.8 firewall as AP and from time to > time there are timeouts which prevents any access to it anymore until I > either plug out and in the Wifi dongle again or reboot. > Please upgrade

Re: iwm performance

2016-07-25 Thread Stefan Sperling
On Sun, Jul 24, 2016 at 05:54:21PM +0200, Andreas Bartelt wrote: > On 07/24/16 15:28, Stefan Sperling wrote: > >On Sun, Jul 24, 2016 at 01:09:26PM +0200, Andreas Bartelt wrote: > >>However, the wireless link via iwm(4) is currently almost unusable. > >>Overall

<    1   2   3   4   5   6   7   8   9   10   >