HP ProLiant DL360 G4p

2011-10-31 Thread Hrvoje Popovski
hello everyone, everything is working fine, but after bios update i see some acpi log in dmesg acpicpu0 at acpi0acpi0: unable to load \\_PR_.CPU0._PDC.IST0 acpicpu1 at acpi0### AML PARSE ERROR (0x3cb): Undefined name: SSD6 error evaluating: \\_PR_.CPU6._PDC maybe to put acpidump somewhere?

Re: HP ProLiant DL360 G4p

2011-11-01 Thread Hrvoje Popovski
On 31.10.2011. 19:04, Stuart Henderson wrote: On 2011-10-31, Hrvoje Popovskihrv...@srce.hr wrote: hello everyone, everything is working fine, but after bios update i see some acpi log in dmesg acpicpu0 at acpi0acpi0: unable to load \\_PR_.CPU0._PDC.IST0 acpicpu1 at acpi0### AML PARSE ERROR

random nat, ftp clients and 425: Securiy: Bad IP connecting

2012-02-27 Thread Hrvoje Popovski
hello everyone, i'm having problem with ftp communication. when ftp client behind openbsd 5.0 firewall connects to ftp server or servers they see 425: Securiy: Bad IP connecting. openbsd has random nat with pool of /27 public addresess and inside hosts connect through that pool. when

Re: random nat, ftp clients and 425: Securiy: Bad IP connecting

2012-03-01 Thread Hrvoje Popovski
On 28.2.2012. 14:23, Stuart Henderson wrote: There is no such option in ftp-proxy. What _might_ work is to run one ftp-proxy per IP (30 in your case) and use random on the divert-to. 5 minutes later I just tried it, and it does not work... divert-to does not support random like rdr-to does.

OpenBSD5.0-beta - 19-Jul-2011 - Dell R510 Perc H700

2011-07-20 Thread Hrvoje Popovski
hello everyone, i was able to install 4.9-current on dell r510 with Perc H700 and everything went well. today i tried to install openbsd5.0-beta and boot process stoped at scsibus3 at softradi0: 256 targets. screenshot http://imageshack.us/f/856/86075191.jpg/ i can normaly boot 4.9 and

Re: OpenBSD5.0-beta - 19-Jul-2011 - Dell R510 Perc H700

2011-07-21 Thread Hrvoje Popovski
On 20.7.2011. 22:17, Marco Peereboom wrote: I committed a workaround for this. Try a kernel from cvs. I'll be working on a permanent fix. it seems to work from cvs thank you ... # dmesg OpenBSD 5.0-beta (GENERIC.MP) #0: Thu Jul 21 10:09:02 CEST 2011

Intel 10GbE SFP+ (82599) and vlan

2011-04-13 Thread Hrvoje Popovski
hello eveyone, problem is that when i enable vlan on ix interface i can't ping other side. servers are identical and cross connected with twinax SFP+ cable. tried thru switches with other ix interface but same result. card is dual 10GbE intel SFP+ SR, but i'm not sure is it X520-D2 or

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-14 Thread Hrvoje Popovski
On 14.4.2011 2:03, Kapetanakis Giannis wrote: Try to do ifconfig ix1 up (up in /etc/hostname.ix1) I've seen vlans not coming up until I do this on parent interface, although they appear active in ifconfig. Giannis hi, tried with hostname.ix1 and hostname.vlan123 but it's not working

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-14 Thread Hrvoje Popovski
On 14.4.2011 10:47, Hrvoje Popovski wrote: On 14.4.2011 2:03, Kapetanakis Giannis wrote: Try to do ifconfig ix1 up (up in /etc/hostname.ix1) I've seen vlans not coming up until I do this on parent interface, although they appear active in ifconfig. Giannis hi, tried with hostname.ix1

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-14 Thread Hrvoje Popovski
On 14.4.2011 18:37, Stuart Henderson wrote: On 2011-04-13, Hrvoje Popovskihrv...@srce.hr wrote: problem is that when i enable vlan on ix interface i can't ping other side. 01:20:38.556705 802.1Q vid 0 pri 0 802.1Q vid 123 pri 0 arp who-has 10.3.3.2 tell 10.3.3.1 your config is OK,

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-14 Thread Hrvoje Popovski
On 14.4.2011 18:18, Kapetanakis Giannis wrote: I'm not sure what you're trying to do, but i'm trying to understand why vlans aren't working on ix interface i need vlans on ix0 (interface connected to switch) for lan's and ix1 (interface directly connected to other openbsd server) for ospf

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-14 Thread Hrvoje Popovski
On 14.4.2011 20:28, Hrvoje Popovski wrote: On 14.4.2011 18:37, Stuart Henderson wrote: On 2011-04-13, Hrvoje Popovskihrv...@srce.hr wrote: problem is that when i enable vlan on ix interface i can't ping other side. 01:20:38.556705 802.1Q vid 0 pri 0 802.1Q vid 123 pri 0 arp who-has 10.3.3.2

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-14 Thread Hrvoje Popovski
On 14.4.2011 23:34, Stuart Henderson wrote: On 2011-04-14, Hrvoje Popovskihrv...@srce.hr wrote: On 14.4.2011 18:37, Stuart Henderson wrote: On 2011-04-13, Hrvoje Popovskihrv...@srce.hr wrote: problem is that when i enable vlan on ix interface i can't ping other side. 01:20:38.556705

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-15 Thread Hrvoje Popovski
On 15.4.2011 12:49, Reyk Floeter wrote: On Thu, Apr 14, 2011 at 04:37:31PM +, Stuart Henderson wrote: 01:20:38.556705 802.1Q vid 0 pri 0 802.1Q vid 123 pri 0 arp who-has 10.3.3.2 tell 10.3.3.1 your config is OK, something is broken there. I guess this will make it function but it's not a

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-16 Thread Hrvoje Popovski
On 15.4.2011 12:49, Reyk Floeter wrote: On Thu, Apr 14, 2011 at 04:37:31PM +, Stuart Henderson wrote: 01:20:38.556705 802.1Q vid 0 pri 0 802.1Q vid 123 pri 0 arp who-has 10.3.3.2 tell 10.3.3.1 your config is OK, something is broken there. I guess this will make it function but it's not a

Re: Intel 10GbE SFP+ (82599) and vlan

2011-04-18 Thread Hrvoje Popovski
On 15.4.2011 12:49, Reyk Floeter wrote: On Thu, Apr 14, 2011 at 04:37:31PM +, Stuart Henderson wrote: 01:20:38.556705 802.1Q vid 0 pri 0 802.1Q vid 123 pri 0 arp who-has 10.3.3.2 tell 10.3.3.1 your config is OK, something is broken there. I guess this will make it function but it's not a

bnx - BCM5716 - jumbo frames

2011-05-01 Thread Hrvoje Popovski
Hello, is somehow possible to enable jumbo frames on BCM5716? I have applied patch from Jonathan Gray -- http://marc.info/?l=openbsd-techm=130409059829496w=2 in hope that maybe jumbo frames would work, but it didn't ... Is jumbo frames somehow realated to brgphy? # ifconfig bnx1 mtu 9000

Re: Hardware (firewall) recommendation

2012-05-10 Thread Hrvoje Popovski
On 10.5.2012 3:28, Predrag Punosevac wrote: Dear All, I am resurrecting this thread which I followed carefully because I need some hardware advice for the firewall machine which is going to serve our new scientific computing laboratory. Initially behind this firewall, we will have only two

Re: multiple instances of ftp-proxy ?

2012-06-12 Thread Hrvoje Popovski
On 12.6.2012. 12:32, Илья Шипицин wrote: Hello! is anybody running multiple instances of ftp-proxy in reverse mode? I'd afraid of anchor ftp-proxy/*, ftp-proxy doesn't allow to specify anchor, also, many instances of ftp-proxy can break each others anchors. can somebody provide me with

Re: Performance with network card at 10Gb

2012-07-03 Thread Hrvoje Popovski
On 2.7.2012. 9:17, Massimo Pignoloni wrote: hi i have performance problem with an intel X520 DA2. I use this networ at 10Gb to do the backup of some virtual Xen machine. The two Xen server using the same network card and using iperf with them, the value is approximately 5-6 Gb/s. The

Re: [5.1] pflow(4) flow with starttime *after* endtime

2012-07-27 Thread Hrvoje Popovski
On 26.7.2012. 18:31, Patrick Lamaiziere wrote: Hello, We have just noticed that pflow (v5) sometime (but often) uses a StartTime value which is later than the EndTime. So the duration is interpreted 4294966.29600 secondes. This confuses our collector (nfsen). (wireshark) pdu

Re: IPSEC VPN performance

2012-09-28 Thread Hrvoje Popovski
Hi, On 28.9.2012 22:09, Jim Miller wrote: So using another Mac w/ 1Gb ethernet adapter to a Linux box w/ 1Gb eth I was able to achieve approx. 600Mbps performance through the test setup (via iperf and my dd method). 600Mbps via ipsec between two Intel E31220 ?

*** Error 1 in /usr/src/sys/arch/amd64/compile/GENERIC.MP (Makefile:816 'copy.o')

2012-11-03 Thread Hrvoje Popovski
Hello, last few days I want to update the lastest current from cvs (ftp5.eu.openbsd.org or anoncvs.spacehopper.org) and I allways had this error. cc -D_LOCORE -x assembler-with-cpp -mcmodel=kernel -mno-red-zone -mno-sse2 -mno-sse -mno-3dnow -mno-mmx -msoft-float -fno-omit-frame-pointer

ladvd - very cool

2012-11-25 Thread Hrvoje Popovski
after instaling ladvd, in ifconfig i've got description from lldp this is so cool ... # ifconfig ix ix0: flags=28b43UP,BROADCAST,RUNNING,PROMISC,ALLMULTI,SIMPLEX,MULTICAST,NOINET6 mtu 1500 lladdr 90:e2:ba:19:29:a8 description: connected to Srce1 (1:14) priority: 0

Re: IP accounting

2013-01-25 Thread Hrvoje Popovski
On 25.1.2013. 13:48, Kapetanakis Giannis wrote: Hi, I'd like to implement IP accounting in one of my OB routers. What I want to do is to log each new connection that creates a state, ideally in a database. In another Linux router I have (and want to replace with OB) I use ulogd userspace

Re: ospfd loopback advertisment failure (adjacency fail?)

2013-04-13 Thread Hrvoje Popovski
On 13.4.2013. 17:29, Stuart Henderson wrote: ospfd doesn't support point-to-point on ethernet interfaces, you will need to remove this from cisco config for now. might not be too hard to add though.. (as in, I have a diff which builds, but I have no idea if it works ;-) could you post

Re: pflow collection and analysis

2013-05-01 Thread Hrvoje Popovski
On 1.5.2013. 19:11, Jan Stary wrote: I just started using plfow(4) on the router/firewall of my small home network. What do people recommend for collection and analysis tools? So far, I am aware of packages for flow-tools, flowd, and softflowd. Thanks Jan If you

Re: ospfd loopback advertisment failure (adjacency fail?)

2013-05-21 Thread Hrvoje Popovski
it next week. In gmane.os.openbsd.misc, I wrote: On 2013-04-13, Hrvoje Popovski hrv...@srce.hr wrote: On 13.4.2013. 17:29, Stuart Henderson wrote: ospfd doesn't support point-to-point on ethernet interfaces, you will need to remove this from cisco config for now. might not be too hard to add

Re: ospfd loopback advertisment failure (adjacency fail?)

2013-05-23 Thread Hrvoje Popovski
On 21.5.2013. 23:23, Claudio Jeker wrote: Hi, sorry for delay, we are in the middle of the network migration from cisco to extreme and i thought when everything calms down to test it with cisco and extreme equipment. I'm planning to test it next week. I found some issues with the diff

bgpd 4byte AS ext-community neighbour-as

2013-05-31 Thread Hrvoje Popovski
Hello, We @srce have small IX and we filter bgpd updates with communities. Our conifg is simple and works great: match from any set community 12345:65000 deny to { group rsip4, group rsip6 } community 12345:65000 deny to { group rsip4, group rsip6 } community 0:12345 allow to { group rsip4,

Re: bgpd 4byte AS ext-community neighbour-as

2013-05-31 Thread Hrvoje Popovski
On 31.5.2013. 16:50, Hrvoje Popovski wrote: Hello, We @srce have small IX and we filter bgpd updates with communities. Our conifg is simple and works great: match from any set community 12345:65000 deny to { group rsip4, group rsip6 } community 12345:65000 deny to { group rsip4, group

Re: 5.4 CDs received

2013-10-31 Thread Hrvoje Popovski
On 31.10.2013. 11:30, Laurent CARON wrote: Hi, Just received my CDs in Paris. Thanks And in Croatia. Thank you

IBM x3250 M5 boot stopped at acpiec0

2013-11-07 Thread Hrvoje Popovski
Hello, I will be having this box for a month or two to test it as OpenBSD firewall. This is the first time I have my hands on IBM server and there are so many options in BIOS/UEFI that confuse me :). With default install of 5.4-current boot is stopped at acpiec0 at acpi0. when I disable acpiec

Re: IBM x3250 M5 boot stopped at acpiec0

2013-11-08 Thread Hrvoje Popovski
On 7.11.2013. 19:12, Hrvoje Popovski wrote: Hello, I will be having this box for a month or two to test it as OpenBSD firewall. This is the first time I have my hands on IBM server and there are so many options in BIOS/UEFI that confuse me :). With default install of 5.4-current boot

Re: 10G with Intel card - GBIC options

2013-11-29 Thread Hrvoje Popovski
On 29.11.2013. 17:08, Andy wrote: PS; I hope you have reeaaaly fast servers.. NB; ALTQ is currently 32bit so you cannot queue faster than 4 and a bit gig, unless you go for Hennings new queueing system which I'm still yet to do when I actually find time.. Hi, I'm not sure if new queueing

BCM5719/20 or I350

2014-01-05 Thread Hrvoje Popovski
Hello, I need to upgrade my OpenBSD firewalls and have chance to buy HP DL360p G8 or Supermicro 5017R-WRF. Which card is better or more stable for firewalling BCM5719/20 or Intel I350? I see that I350 doesn't support VLAN_HWTAGGING nor TX CSUM's and it seems that is quite different from older em

Re: BCM5719/20 or I350

2014-01-06 Thread Hrvoje Popovski
On 5.1.2014. 17:10, mxb wrote: I have I350 on several machines and haven’t seen any problems. Do you have vlans or trunk on I350? Could you share some numbers like bps or pps? Tnx for info.

Re: 10G with Intel card - GBIC options

2014-01-07 Thread Hrvoje Popovski
On 2.12.2013. 10:05, Andy wrote: Hmm surprised by that! Henning, could you please confirm for us if the 32bit bandwidth limit was lifted in the new queuing subsystem, or if it is just still in place whilst dual-running the new and the old? I guess considering Hrvoje's findings the limit

Re: BCM5719/20 or I350

2014-01-07 Thread Hrvoje Popovski
On 7.1.2014. 13:27, mxb wrote: This is a pair of CARP-nodes (2x Dell R620 ). Nodes are connected with cross-over, trunk to trunk (trunk of 2x I350 per node). No vlans. tcpbench from the base; PF used a lot, but with pass quick on trunk0 keep state”: Conn: 1 Mbps: 926.569 Peak

Re: Promiscuous IPFIX sensor for flow collection/analysis

2014-03-02 Thread Hrvoje Popovski
On 2.3.2014. 18:58, Chris Jones wrote: Good morning folks, I'm looking for advice on a freely available IPFIX probe/sensor for flow export of our company's corporate firewall (Juniper SRX) traffic. An unfortunate limitation of these firewalls is that J-Flow (Juniper's version of Netflow) is

Re: Promiscuous IPFIX sensor for flow collection/analysis

2014-03-02 Thread Hrvoje Popovski
On 2.3.2014. 21:04, Hrvoje Popovski wrote: On 2.3.2014. 18:58, Chris Jones wrote: Good morning folks, I'm looking for advice on a freely available IPFIX probe/sensor for flow export of our company's corporate firewall (Juniper SRX) traffic. An unfortunate limitation of these firewalls

Re: Problems with PPPoE, VLAN, 5.5 (amd64)

2014-05-02 Thread Hrvoje Popovski
On 2.5.2014. 14:54, thors...@bonck.net wrote: Under 5.4-stable, following configuration sets up a working connection for me: /etc/hostname.pppoe0: inet 0.0.0.0 255.255.255.255 NONE \ pppoedev vlan10 authproto pap \ authname 'XXX' authkey 'YYY' up dest 0.0.0.1

Re: ftp-proxy and multiple nat-to addresses

2014-06-11 Thread Hrvoje Popovski
On 11.6.2014. 14:29, Marko Cupać wrote: Hi, I have pf setup which includes NAT and ftp-proxy for accessing FTP servers on the Internet, and it works fine. I would like to add multiple addresses to NAT pool, instead of just one as in current setup, but I am not sure if this is going to

Re: Firewall: Where is the bottleneck?

2014-11-04 Thread Hrvoje Popovski
On 4.11.2014. 21:48, jum...@yahoo.de wrote: Hi Remi, Thanks for your answer. nestat -m is ok, see. 203 mbufs in use: 193 mbufs allocated to data 2 mbufs allocated to packet headers 8 mbufs allocated to socket names and addresses 190/658/6144 mbuf 2048 byte clusters in use

Dell R630 high interrupts on acpi0

2014-12-14 Thread Hrvoje Popovski
Hi all, I have got two new Dell R630 and have current on them from Sun Dec 14 15:07:17. Installation went great and very fast. The problem is that I see around 11k interrupts on acpi0. First I thought that problem is similar to this thread http://marc.info/?l=openbsd-miscm=140551906923931w=2

Re: Dell R630 high interrupts on acpi0

2014-12-16 Thread Hrvoje Popovski
On 16.12.2014. 6:16, Jonathan Matthew wrote: On Sun, Dec 14, 2014 at 06:22:37PM +0100, Hrvoje Popovski wrote: Hi all, I have got two new Dell R630 and have current on them from Sun Dec 14 15:07:17. Installation went great and very fast. The problem is that I see around 11k interrupts on acpi0

Re: Dell R630 high interrupts on acpi0

2014-12-16 Thread Hrvoje Popovski
On 16.12.2014. 6:16, Jonathan Matthew wrote: We just got some r630s too, so I spent some time last week figuring out what's going on here. Something in the AML wants to talk to the intel MEI device. Normally this works, but on the new generation of dell machines (we've seen it on r630s and

Re: Dell R630 high interrupts on acpi0

2014-12-19 Thread Hrvoje Popovski
On 17.12.2014. 6:34, Philip Guenther wrote: Uh, ACPI *requires* that C1 exist. The halt instruction is defined as entering C1, so not having C1 would mean your CPU lacks a basic manadatory ia32 instruction. Hopefully the BIOS docs explain that you're just disabling deep C-states or something

Dell R630 freezes

2014-12-23 Thread Hrvoje Popovski
Hi all, I have Dell R630 with PERC H330 RAID controller and 2 LITEON IT ECT-60 SSD disks. When doing make build, box freezes almost any time. With kern.bufcachepercent=80 make build finishes but then sometimes i can't reboot it from ssh, only reset it from idrac console. Same problem can be

Re: sudo nohup tcpdump at startup

2015-02-04 Thread Hrvoje Popovski
On 3.2.2015. 5:16, Ted Unangst wrote: fRANz wrote: On Thu, Jan 29, 2015 at 10:54 PM, Christopher Barry christopher.r.ba...@gmail.com wrote: what happens if you source /etc/rc.local instead? as in: [ -f /etc/rc.local ] . /etc/rc.local Hi Christopher, I'm sorry, same behaviour: some

Re: sudo nohup tcpdump at startup

2015-02-04 Thread Hrvoje Popovski
On 4.2.2015. 15:13, Todd C. Miller wrote: On Wed, 04 Feb 2015 15:06:41 +0100, Hrvoje Popovski wrote: is there any problem to just put this in crontab? @reboot /usr/sbin/tcpdump -lnqttti pflog0 2 error.log | /usr/bin/logger -t pf -p local2.info You should not try to run the command

Re: Trying to restart pppoe0: Device busy

2015-02-08 Thread Hrvoje Popovski
On 8.2.2015. 22:17, Maximilian Pichler wrote: Hi, I'm trying to restart the pppoe0 interface, so as to renegotiate a new connection to the ISP, but am getting the following error. $ sudo sh /etc/netstart pppoe0 ifconfig: SIOCSSARAMS(SPPPIOSXAUTH): Device busy route: writing to

Re: Dell R630 with PERC H730

2015-03-26 Thread Hrvoje Popovski
On 26.3.2015. 11:40, Or Elimelech wrote: Hello Misc I am trying to install OpenBSD 5.6 on the above machine. 1. While using Lifecycle controller and deploy OS I get weird disk layout with MSDos partition which cannot be removed. 2. While trying to init the raid myself through the raid

Re: Dell R630 with PERC H730

2015-03-26 Thread Hrvoje Popovski
On 26.3.2015. 12:40, Or Elimelech wrote: Is this for sure will solve the problem? Is it a known issue? well, dell r630 is really new hardware and there was few issues with h330 and h730 at the beginning of 2015 you could try current just to see will you be able to install openbsd on

Re: OpenBGPd Route Server

2015-04-15 Thread Hrvoje Popovski
On 15.4.2015. 19:45, Mike Hammett wrote: What do you have $my_ip4_net and $my_ip6_net set to? I assume the IPv4 and IPv6 blocks that the IX is using? yes, that's IX network..

Re: OpenBGPd Route Server

2015-04-15 Thread Hrvoje Popovski
On 15.4.2015. 5:23, Mike Hammett wrote: With the decline of OpenBGPd's popularity among IXPs, it's difficult to track down examples of how IXPs are configuring their servers. I saw a couple presentations in the 2010 - 2011 timeframe with new things that were coming for 32 bit communities

Re: netstat doubles packet count on output

2015-05-20 Thread Hrvoje Popovski
On 20.5.2015. 10:30, Martin Pieuchot wrote: On 19/05/15(Tue) 22:14, Hrvoje Popovski wrote: Hi all, today i have update test box from cvs and it seems that netstat doubles packet count on output. anyone else sees the same thing? Yep, I introduced a regression during the if_output

netstat doubles packet count on output

2015-05-19 Thread Hrvoje Popovski
Hi all, today i have update test box from cvs and it seems that netstat doubles packet count on output. anyone else sees the same thing? pf disabled box on ix1 generate traffic box on ix0 receive same amount of traffic as in total in packets kern.pool_debug=0 net.inet.ip.forwarding=1

Re: ix(4) X710-DA4

2015-06-12 Thread Hrvoje Popovski
On 19.2.2015. 13:08, Jonathan Gray wrote: On Thu, Feb 19, 2015 at 10:11:36AM +0200, Or Elimelech wrote: Hi, I???m purchasing 2 new firewalls and I wonder if the ix(4) driver supports X710-DA4 Have anyone tried this in production? Thanks Someone needs to port Intel's ixl/i40e driver

Re: Intel C61X / C22X Chipset Support

2015-07-31 Thread Hrvoje Popovski
On 31.7.2015. 19:42, Joe Crivello wrote: Awesome! Thanks so much. So C22X gets detected as an Intel 8 series chipset then (which makes sense). We are initially thinking about using a couple of Super Micro 5018D-MR servers with Intel X520 cards as routers, so the lack of onboard Ethernet

Re: Possible fix for i217 problem

2015-08-04 Thread Hrvoje Popovski
On 4.8.2015. 23:47, Stuart Henderson wrote: On 2015/08/04 22:40, Stefan Fritsch wrote: someone mentioned to me the i217-LM problems that were reported on misc end of May. It is possible that the patch below helps. This fixes my Dell poweredge T20: em0 at pci0 dev 25 function 0 Intel

Re: Dell FX2 or Huawei E9000 dmesg(s), anyone?

2015-07-17 Thread Hrvoje Popovski
On 16.7.2015. 1:46, Hrvoje Popovski wrote: On 13.7.2015. 7:52, OpenBSD user wrote: Would anyone care to share amd64 dmesg(s) from Dell FX2 or Huawei E9000? Would be truly grateful! next week i will get access to dell fc630. i'm quite sure that fc630 have dual port QLogic 577xx/578xx 10

Re: Dell FX2 or Huawei E9000 dmesg(s), anyone?

2015-07-15 Thread Hrvoje Popovski
On 13.7.2015. 7:52, OpenBSD user wrote: Would anyone care to share amd64 dmesg(s) from Dell FX2 or Huawei E9000? Would be truly grateful! next week i will get access to dell fc630. i'm quite sure that fc630 have dual port QLogic 577xx/578xx 10 GbE BCM57810 card which is not supported in

unlocking em - unable to fill any rx descriptors

2015-10-07 Thread Hrvoje Popovski
Hi all, i have fairly simple setup with receiver connected to em2 and sender connected to em3. Both em are Intel I350. Setup is without pf with these sysctls: kern.pool_debug=1 net.inet.ip.forwarding=1 net.inet.ip.ifq.maxlen=8192 ddb.console=1 with if_em.c revisions 1.307 and 1.306 i can

netstat statistics bridge interface

2015-08-26 Thread Hrvoje Popovski
Hi all, i have configured bridge interface with em2 and em3. Generator is connected on em3 and receiver is connected on em2. I'm generating 1,48Mpps on em3 and getting around 400kpps on box connected to em2 and that is fine but counters in netstat seems doubled on total in packets and total out

Re: netstat statistics bridge interface

2015-08-27 Thread Hrvoje Popovski
On 27.8.2015. 2:06, Hrvoje Popovski wrote: Hi all, i have configured bridge interface with em2 and em3. Generator is connected on em3 and receiver is connected on em2. I'm generating 1,48Mpps on em3 and getting around 400kpps on box connected to em2 and that is fine but counters

kernel compile error

2015-09-11 Thread Hrvoje Popovski
cvs update from half an hour ago ... log: cc -Werror -Wall -Wimplicit-function-declaration -Wno-main -Wno-uninitialized -Wframe-larger-than=2047 -mcmodel=kernel -mno-red-zone -mno-sse2 -mno-sse -mno-3dnow -mno-mmx -msoft-float -fno-omit-frame-pointer -fno-builtin-printf -fno-builtin-snprintf

Re: kernel compile error

2015-09-11 Thread Hrvoje Popovski
On 11.9.2015. 12:11, Paul de Weerd wrote: > Did you update config(8) before building? > > http://www.openbsd.org/faq/current.html#20150911 > > Cheers, > > Paul 'WEiRD' de Weerd > yes, yes ... thank you ... now it's compile perfectly > On Fri, Sep 11, 2015

kernel compile error

2015-12-28 Thread Hrvoje Popovski
Hi, after fetching source from cvs at 23:40 CET i'm getting this error whilte comliling kernel. cc -Werror -Wall -Wimplicit-function-declaration -Wno-main -Wno-uninitialized -Wframe-larger-than=2047 -mcmode l=kernel -mno-red-zone -mno-sse2 -mno-sse -mno-3dnow -mno-mmx -msoft-float

Re: kernel compile error

2015-12-28 Thread Hrvoje Popovski
On 28.12.2015. 23:44, Hrvoje Popovski wrote: > Hi, > > after fetching source from cvs at 23:40 CET i'm getting this error > whilte comliling kernel. > > > > cc -Werror -Wall -Wimplicit-function-declaration -Wno-main > -Wno-uninitialized -Wframe-larger-than=2047

Re: Xeon-D 10GE nics

2016-06-06 Thread Hrvoje Popovski
On 14.4.2016. 9:29, Jonathan Gray wrote: > On Tue, Apr 12, 2016 at 01:15:49PM +, Stuart Henderson wrote: >> Does anyone know if the 10GE NICs on Xeon-D SoCs work on OpenBSD yet? >> e.g. "Dual 10G SFP+ from D-1500 SoC" on Supermicro SYS-5018D-FN8T. >> > > The windows driver has: > > 0x10a6

Re: recommendations for 10GBase Ethernet on OpenBSD

2016-04-08 Thread Hrvoje Popovski
On 8.4.2016. 16:22, Steiner Peter wrote: > hello, > > i'm looking for recommendations for 10GBase SFP+ network adapters, > anyone has experience with 10G Ethernet on OpenBSD? > > i found dual SFP+ PCIe devices with the following drivers: > ix - Intel 82598/82599/X540 PCI Express 10Gb Ethernet

Re: Xeon-D 10GE nics

2016-05-04 Thread Hrvoje Popovski
On 12.4.2016. 15:15, Stuart Henderson wrote: > Does anyone know if the 10GE NICs on Xeon-D SoCs work on OpenBSD yet? > e.g. "Dual 10G SFP+ from D-1500 SoC" on Supermicro SYS-5018D-FN8T. > Hi, dmesg for https://www.supermicro.nl/products/motherboard/Xeon/D/X10SDV-TP8F.cfm OpenBSD 5.9-current

Re: openbgpd blackhole community

2016-07-25 Thread Hrvoje Popovski
On 21.7.2016. 11:12, Claudio Jeker wrote: > Just use "community BLACKHOLE" instead of 65535:666 and it will work. > thank you guys

openbgpd blackhole community

2016-07-20 Thread Hrvoje Popovski
Hi all, here at CIX we want to implement BLACKHOLE based on https://tools.ietf.org/html/draft-ietf-grow-blackholing presentation https://www.ietf.org/proceedings/94/slides/slides-94-grow-1.pdf Recommendation is to have Blackhole BGP Community: 65535:666, but when configure that community i'm

Re: splassert: yield message on 5 Feb snapshot (amd64)

2017-02-08 Thread Hrvoje Popovski
On 8.2.2017. 17:51, Scott Vanderbilt wrote: > Updated a machine to latest (5 Feb.) snapshot of amd64. I'm now seeing > the following message after booting that I've not recalled seeing before: > >splassert: yield: want 0 have 1 add sysctl kern.splassert=2 ...

Re: Kernel panic after upgrade -CURRENT

2017-01-28 Thread Hrvoje Popovski
On 29.1.2017. 4:13, kayasaman wrote: > Hi, > A very strange issue... > After the previous update of CURRENT I started to have issues with ftpproxy > not loading some directories, an example being shrubbery.net rancid directory. > Today I attempted an upgrade to see if that might kick things into

Re: Routing 10-40 Mpps on OpenBSD

2016-09-11 Thread Hrvoje Popovski
On 11.9.2016. 19:17, K wrote: > All, > > This message is a call for people who are interested to benchmark commodity > hardware with the goal of pushing as much PPS as possible through OpenBSD. > The initial target is to reach 10 Mpps at 64 bytes (or more precisely 84 > bytes with interpacket

Re: Hardware recommendations for compact 1U firewall

2016-12-15 Thread Hrvoje Popovski
On 15.12.2016. 12:30, Stuart Henderson wrote: > If you want to cut down on weight+noise at the expense of more cost > and a less powerful cpu, maybe APU2 in a 1U case or something like > supermicro SYS-5018A-FTN4. has anyone dmesg from SYS-5018A-FTN4 box? i'm interesting in intel qat thank you

Re: Hardware recommendations for compact 1U firewall

2016-12-15 Thread Hrvoje Popovski
On 15.12.2016. 20:45, Bryan Vyhmeister wrote: > There is no support for Intel QAT (sometimes called Quick Assist) in > OpenBSD and that's not likely to change anytime soon. Some support is > supposedly coming to FreeBSD (by way of pfSense and some commerical > sponsorship or something) but I have

Re: Hardware recommendations for compact 1U firewall

2016-12-22 Thread Hrvoje Popovski
On 22.12.2016. 2:17, Predrag Punosevac wrote: > As promissed in one of my earlier e-mails. OpenBSD 6.0 dmesg for > SYS-5018A-FTN4 thank you ...

Van Jacobson network channels

2017-04-03 Thread Hrvoje Popovski
Hi all, i'm reading some networking stuff and I saw Van Jacobson presentation about net channels concept. For me, as user that doesn't know net internals, this presentation seems quite reasonable. Beside that it's about linux network stack, what net gurus think about VJ net channels ?

Re: Gbit performance parameters

2017-07-13 Thread Hrvoje Popovski
On 13.7.2017. 0:26, Per-Olov Sjöholm wrote: > I increased net.inet.ip.ifq.maxlen in steps of 256… I had to increase the > net.inet.ip.ifq.maxlen 9 times to 2309 for the net.inet.ip.ifq.drops to stop > increasing. At a maxlen of 2309 the drops stopped completley. But all values > of

Re: OpenBSD-based ISP

2017-08-16 Thread Hrvoje Popovski
On 16.8.2017. 19:55, Juan Guillermo Narvaez wrote: > Hello everyone! > > I'm relative new using OpenBSD, I have just 4 years using this OS for dhcp > servers. > Today I have the mission of implement this OS in a cablemodem headend, in > my first try I get negative results with this rules: > >

Re: OpenBSD-based ISP

2017-08-17 Thread Hrvoje Popovski
On 17.8.2017. 17:13, Chris Cappuccio wrote: > Juan Guillermo Narvaez [guille...@nrvz.net] wrote: >> # sysctl | grep ifq >> net.inet.ip.ifq.len=0 >> net.inet.ip.ifq.maxlen=1024 >> net.inet.ip.ifq.drops=46068291 >> net.inet6.ip6.ifq.len=0 >> net.inet6.ip6.ifq.maxlen=256 >> net.inet6.ip6.ifq.drops=0

ipsec.conf

2017-05-26 Thread Hrvoje Popovski
Hi all, i having ipsec.conf like this: ike esp from 10.200.136.0/21 to any \ local 10.64.135.246 peer 10.4.57.68 \ main auth hmac-sha1 enc aes group modp1024 \ quick auth hmac-sha1 enc aes group modp1024 \ psk b9278b3051cd17674305833971c22b11514eac51 and with

solidrun marvell macchiatobin

2017-05-31 Thread Hrvoje Popovski
Hi arm gurus, does openbsd support solid-run marvell armada family boards? primary this little cute firewall :) https://www.solid-run.com/marvell-armada-family/armada-8040-community-board/ if there are any interest in this box i'm willing to donate it for development ..

Re: isakmpd listen address

2017-05-25 Thread Hrvoje Popovski
On 25.5.2017. 20:46, mabi wrote: > Hello, > I can't seem to find an option in isakmpd in order to have it listen only on > one interface or IP address respectively. Is there an option for that I am > not aware of? I just saw the -p option but that's for the port number. > Thanks, > M. > Hi,

Re: solidrun marvell macchiatobin

2017-05-31 Thread Hrvoje Popovski
On 31.5.2017. 23:17, Patrick Wildt wrote: > Are you following my Twitter or what? ;) I just posted a picture > of that board, arrived on the doorsteps today. I'll be having a > look. perfect box for MP firewall :)

Re: SoC Intel Xeon D-1518 & D-1548

2017-09-10 Thread Hrvoje Popovski
On 10.9.2017. 0:46, Daniel Ouellet wrote: > Hi, > > Is there anyone that know of have one of the Intel Xeon D-1548 SoC that > works on OpenBSD? > > I know the D-1518 does, I find the DMESG in the archive, but I can't > find anything at all on the D-1548. > > Any clue. > > Here is the D-1518 >

Re: ping -R causes panic

2017-10-01 Thread Hrvoje Popovski
On 20.9.2017. 23:29, Kapetanakis Giannis wrote: > On 20/09/17 19:25, Visa Hankala wrote: >> On Wed, Sep 20, 2017 at 02:26:56PM +0300, Kapetanakis Giannis wrote: >>> I got this panic today after ping -R >>> I don't run pfsync >>> >>> # ping -R www.google.com >>> panic: kernel diagnostic assertion

Re: OpenBSD-based ISP

2017-08-17 Thread Hrvoje Popovski
f you see some performance improvement? > On Thu, Aug 17, 2017 at 3:46 PM, Hrvoje Popovski <hrv...@srce.hr> wrote: > >> On 17.8.2017. 17:13, Chris Cappuccio wrote: >>> Juan Guillermo Narvaez [guille...@nrvz.net] wrote: >>>> # sysctl | grep ifq >>>

Re: OpenBSD-based ISP

2017-08-17 Thread Hrvoje Popovski
them set skip on { lo bge1 vlan123 vlan124 } > On Thu, Aug 17, 2017 at 4:45 PM, Hrvoje Popovski <hrv...@srce.hr> wrote: > >> On 17.8.2017. 21:23, Juan Guillermo Narvaez wrote: >>> This is the dmesg.boot. >> >> nice box with nice cpu and inter

Re: VLAN configuration problem on 6.1 ("no route to host" on other than own IP)

2017-11-06 Thread Hrvoje Popovski
On 6.11.2017. 17:47, Andre Ruppert wrote: > Hello @misc, > > perhaps I'm stupid, but I don't see my fault in a vlan network > configuration: > > I got a OpenBSD 6.1 gateway box, connected to several switches. > > On em0 I habe to serve two networks: > 172.16.210.0  (direct em0 - no vlan) >

Re: 6.3-current kernel panic: aml_die aml_parse:4194 on PowerEdge

2018-05-16 Thread Hrvoje Popovski
On 2.5.2018. 11:28, Jan Vlach wrote: > R440 WAS( Re: Dell PowerEdge R430/R440 support) > Reply-To: > In-Reply-To: <20180425150215.gh20...@diehard.n-r-g.com> > > Hello misc@ > > > the Dell PowerEdge R440 server arrived for testing and it panics on boot > to installed system. Installer works

Re: 6.3-current kernel panic: aml_die aml_parse:4194 on PowerEdge

2018-05-02 Thread Hrvoje Popovski
On 2.5.2018. 19:06, Mike Larkin wrote: > On Wed, May 02, 2018 at 06:51:51PM +0200, Jan Vlach wrote: >>> Last time I checked, we don't support LoadTable. >>> >>> -ml >>> >> >> Thank you Mike for your reply. I have no clue about ACPI. Is this a new >> way how vendors extend ACPI? Is there generally

cpu's in dmesg

2018-08-22 Thread Hrvoje Popovski
Hi all, in today's snapshot i see some strange dmesg cpu output. it feels like cosmetic stuff only but i'm not sure ... cpu1: Intel(R) Xeon(R) Gold 6134 CPU @ 3.20GHz, 3192.49 MHz cpu1:

acpidump and bsd.rd

2018-03-19 Thread Hrvoje Popovski
Hi all, does it make sense to add acpidump to bsd.rd ? I've tried to install snapshot on Dell R640 and installation went well but booting stops with this error: http://kosjenka.srce.hr/~hrvoje/zaprocvat/r640-01.jpg i also noticed this ahci2 log while booting

Re: Performance impact of PF on APU2

2018-10-04 Thread Hrvoje Popovski
On 4.10.2018. 5:58, Benjamin Petit wrote: > Ok so I compared 6.3-release, 6.3-release+syspatches(=stable?) and the latest > snapshot from October 2. > > I measured iperf3 throughput between A and B, like this: > PC A <---> APU2 <---> PC B > > pf rules are the one shipped by default in 6.3: > >

Re: OpenBSD 6.4-stable + current "freezes" after 4h

2019-01-14 Thread Hrvoje Popovski
On 14.1.2019. 10:02, Marco Prause wrote: > splassert: bstp_notify_rtage: want 2 have 0 > splassert: bstp_notify_rtage: want 2 have 0 > splassert: bstp_notify_rtage: want 2 have 0 > splassert: bstp_notify_rtage: want 2 have 0 > splassert: bstp_notify_rtage: want 2 have 0 > splassert:

  1   2   3   >