Re: info about cpu in dmesg

2024-06-15 Thread Hrvoje Popovski
On 15.6.2024. 7:54, Rob Schmersel wrote: > On Fri, 14 Jun 2024 22:20:55 +0200 > Hrvoje Popovski wrote: > >> Hi all, >> >> I have question about cpu output in dmesg. >> I have Fujitsu RX2530m4 with 8 core Intel(R) Xeon(R) Gold 6134 and in >> dmesg I'

info about cpu in dmesg

2024-06-14 Thread Hrvoje Popovski
Hi all, I have question about cpu output in dmesg. I have Fujitsu RX2530m4 with 8 core Intel(R) Xeon(R) Gold 6134 and in dmesg I've noticed that core are 0,4,5,7,18,19,21,22 without HT cpu0: smt 0, core 0, package 0 cpu1: smt 0, core 4, package 0 cpu2: smt 0, core 5, package 0 cpu3: smt 0, core 7

Re: Recommendations for 2.5G NIC

2024-06-05 Thread Hrvoje Popovski
On 6.6.2024. 6:08, s...@skolma.com wrote: > > > On Thursday, June 6th, 2024 at 1:08 PM, Martin wrote: > >> >> >> I am about to upgrade a network from 1G to 2.5G and a couple >> of boxes needs new NICs. >> > mee too. > >> Any recommendations for NICs with good driver support on OpenBSD? >> >> I

Serial console on vmware esxi 8

2024-05-29 Thread Hrvoje Popovski
Hi all, this could be useful information to those who are using openbsd on vmware. while testing jan@ vmx LRO diffs, openbsd machine panic. I've sent him few screenshots and those screenshots are awful. Good thing is that vmware have virtual serial port https://docs.vmware.com/en/VMware-vSphere/8

Re: [7.5/amd64] ipsec + npppd + sasyncd + carp - doesn't pick up the VPN session at switchover

2024-05-29 Thread Hrvoje Popovski
On 29.5.2024. 12:48, Radek wrote: > Thank you, that explains everything. > Does wireguard support replication? Will it work properly in my CARP setup? > Hi, I have wg listen on carp interface for redundancy and it's working without admins or clients needs to do anything when primary carp firewa

Re: ixl driver very poor network performance

2024-04-17 Thread Hrvoje Popovski
On 16.4.2024. 20:22, Szél Gábor wrote: > Dear @misc! > > We have several more complex networks where openbsd is the router. > > Structure of the network: > > * OpenBSD redundant routers > - two OpenBSD > - CARP > - pfsync > - LACP trunks for LAN (2x 10Gbit)  (1 side switch #1,

Re: Dell PERC H745

2024-04-01 Thread Hrvoje Popovski
On 29.3.2024. 9:06, Kapetanakis Giannis wrote: > > On 28/03/2024 20:17, Stuart Henderson wrote: >> On 2024-03-28, Hrvoje Popovski wrote: >>> On 28.3.2024. 11:01, Kapetanakis Giannis wrote: >>>> I'm looking for a new server to replace our firewall/routing. &g

Re: Dell PERC H745

2024-03-28 Thread Hrvoje Popovski
On 28.3.2024. 17:40, Hrvoje Popovski wrote: > On 28.3.2024. 11:01, Kapetanakis Giannis wrote: >> I'm looking for a new server to replace our firewall/routing. >> >> Would like to ask if PERC H745 is supported. >> >> mfi(4) lists >>    -   Dell

Re: Dell PERC H745

2024-03-28 Thread Hrvoje Popovski
On 28.3.2024. 11:01, Kapetanakis Giannis wrote: > I'm looking for a new server to replace our firewall/routing. > > Would like to ask if PERC H745 is supported. > > mfi(4) lists >    -   Dell PERC 5/e, PERC 5/i, PERC 6/e, PERC 6/i, PERC H310, PERC >    H700, PERC H800 > > Is

Re: When IPSec destination 0.0.0.0/0, I cannot ping directly connected Interfaces

2024-03-12 Thread Hrvoje Popovski
On 12.3.2024. 17:11, Samuel Jayden wrote: > Dear Misc, > > I have an OpenBSD device with two interfaces: vport10 with an IP address of > 192.168.83.1/24 and vport20 with an IP address of 192.168.85.1/24. I have > configured IPSec to route all traffic from these two vport interfaces to > another po

Dell BOSS-S1 adapter or HBA330 non-raid

2024-02-23 Thread Hrvoje Popovski
Hi all, did anyone installed and boot successfully OpenBSD on Dell BOSS-S1 adapter or HBA330 non-raid controller ? I've got Dell R740xd in lab and of course for storage controllers there are BOSS-S1 and HBA330. :) OpenBSD can be installed on these controllers but unfortunately it panic at boot. I

Re: cvs revert specific commit

2024-01-18 Thread Hrvoje Popovski
On 19.1.2024. 0:14, Christian Weisgerber wrote: > Hrvoje Popovski: > >> I would like to revert only if_em.c rev. 1.369, but would like to leave >> TSO stuff if_em.c rev. 1.370 and if_em.h rev 1.81. >> >> is this somehow possible? > > $ cd /sys/dev/pci >

cvs revert specific commit

2024-01-18 Thread Hrvoje Popovski
Hi all, I sorry for beginners questions regarding cvs revert stuff. https://cvsweb.openbsd.org/src/sys/dev/pci/if_em.c https://cvsweb.openbsd.org/src/sys/dev/pci/if_em.h I would like to revert only if_em.c rev. 1.369, but would like to leave TSO stuff if_em.c rev. 1.370 and if_em.h rev 1.81. is

Re: upgrade to latest snapshot failing

2023-11-17 Thread Hrvoje Popovski
On 17.11.2023. 20:05, Stuart Henderson wrote: > On 2023-11-17, Sonic wrote: >> Following -current: >> OpenBSD 7.4-current (GENERIC.MP) #1447: Wed Nov 15 09:56:54 MST 2023 >> Upgrade via "sysupgrade -s" now failing with: >> init: single user shell terminated, restarting >> init: single user shell t

Re: pf logging in ascii and send to remote syslog

2023-11-11 Thread Hrvoje Popovski
On 11.11.2023. 12:13, Stuart Henderson wrote: > On 2023-11-11, Peter N. M. Hansteen wrote: >> On Fri, Nov 10, 2023 at 08:23:54PM +0100, Hrvoje Popovski wrote: >>> what would be best way to log pf logs in ascii and sent it to remote >>> syslog ? I'm aware of p

pf logging in ascii and send to remote syslog

2023-11-10 Thread Hrvoje Popovski
Hi all, what would be best way to log pf logs in ascii and sent it to remote syslog ? I'm aware of pflow but I need ascii pf logs on remote syslog server. I remember that it was on https://www.openbsd.org/faq/pf/logging.html and that that section was removed. Old version is on https://www.dragonf

Re: Greedy match of traffic in iked between site and hub

2023-10-15 Thread Hrvoje Popovski
On 15.10.2023. 18:56, Stuart Henderson wrote: > On 2023-10-15, rea...@catastrophe.net wrote: >> What is a better way to configure iked on site-obsd so that it does not >> encapsulate local traffic on the 10.89.2.0/24 network? Obviously my >> understanding is incorrect, so any help is appreciated.

Re: 7.4 and hostname.pfsync7

2023-10-15 Thread Hrvoje Popovski
On 15.10.2023. 6:51, Harald Dunkel wrote: > Hi folks, > > I learned that pfsync has been rewritten for 7.4 and that > > up > syncdev em7 > > doesn't work anymore. What about > > up syncdev em7 > > (one line), as suggested in the current pfsync(4)? > > > Regards > Harri > could

Re: OpenBSD 7.2 fw stack trace on Dell R740

2023-09-28 Thread Hrvoje Popovski
On 26.9.2023. 9:24, Joerg Streckfuss wrote: > > Hi Stuart, > > Am 25.09.23 um 19:08 schrieb Stuart Henderson: >> That might possibly be the one fixed by 7.2 errata 008, so if you don't >> already have that you at least want to syspatch. > > That was my guess as well. However, the systems were pa

Re: Stacked MTUs

2023-09-07 Thread Hrvoje Popovski
On 7.9.2023. 18:45, Lyndon Nerenberg (VE7TFX/VE6BBM) wrote: > I'm setting up jumbograms on a couple of vlans stacked > on an aggr and I need a sanithy check that I'm doing > this right. > > The switches use a hardware MTU of 9192. We want an IP > MTU of 9000 for the vlans. I'm assuming this will

Re: Route based IPsec

2023-05-27 Thread Hrvoje Popovski
On 27.5.2023. 9:24, Valdrin MUJA wrote: > Hello, > > I need Route based IPsec solution to set up between a firewall device and > my OpenBSD firewall. > However, I am a little confused about this: > I created more than one enc device, I did policy based routing with PF but no > results. I gue

Re: supermicro 5019D-FTN4 server with AMD EPYC 3251 SoC Processor

2023-04-27 Thread Hrvoje Popovski
On 30.6.2021. 15:34, Denis Fondras wrote: > Le Tue, Jun 29, 2021 at 07:46:55PM +0200, EdaSky a écrit : >> Good day everyone >> >> Does anyone use supermicro 5019D-FTN4 server with AMD EPYC 3251 SoC >> Processor? >> >> https://www.supermicro.com/Aplus/system/Embedded/AS-5019D-FTN4.cfm >> >> Experien

Re: ixl not seeing SFP+ modules ?

2023-04-14 Thread Hrvoje Popovski
On 14.4.2023. 19:36, Laura Smith wrote: > I have an ixl card (ixl0 at pci1 dev 0 function 0 "Intel X710 SFP+" rev 0x02: > port 3, FW 6.0.48442 API 1.7, msix, 4 queues) on OpenBSD that doesn't seem to > be seeing any of my SFP+ modules. > > > The modules are all MSA coded and from different manu

Re: Hardware RAID on Poweredge Servers

2023-03-30 Thread Hrvoje Popovski
On 30.3.2023. 18:33, Kihaguru Gathura wrote: > Hello, > > Is hardware RAID on Poweredge servers (T340, PERC H330 in particular) > generally stable enough for production or is it safer to stick with OpenBSD > softraid? > Hi, not sure if there is big differences between H330 and H330 mini but H33

Re: Using veb instead of bridge at vpls section

2023-03-20 Thread Hrvoje Popovski
On 20.3.2023. 20:05, Valdrin MUJA wrote: > Hello folks, > > I have successfully configured the VPLS by following the instruction on > https://pawa.lt/posts/2018/01/vpls-with-openbsd/. > Everything worked like a charm. > > But when I tried to use veb(4) instead of bridge(4) , I got 'Device Busy'

Re: Selecting a 10G NIC

2023-02-17 Thread Hrvoje Popovski
On 17.2.2023. 18:29, Nicolas Goy wrote: > I know this question has been answered multiple times, but I wonder if > things changed with 7.2. > > Which NIC would provide the best performance with 10G physical layer > with open bsd? > > I have choice between intel e810, x710, x550, x520, broadcom >

Re: Performance optimizing OpenBSD 7.2

2023-02-15 Thread Hrvoje Popovski
On 15.2.2023. 10:28, Gábor LENCSE wrote: > In OpenBSD, the packet forwarding happens single threaded, so the > performance of your system does not benefit much from the 4 cores. Hi, actually if forwarding is single threaded of not, depends of what nic do you have in box. ix,mcx,bnxt,igc,vmx and

Re: Intel nic on Dell R710: failed to allocate interrupt slot for PIC msix

2023-01-26 Thread Hrvoje Popovski
On 25.1.2023. 12:24, Joerg Streckfuss wrote: > > Dear List, > > we have problems with Intel nics of type Intel X710 (10 GbE) on a Dell > R740. In total we have three nics with four ports each. With the uprade > to OpenBSD 6.8 we lost two ports (ixl11 and ixl12). Now we upraded > iteratively to Op

Re: do i need to move to veb?

2023-01-23 Thread Hrvoje Popovski
On 23.1.2023. 16:24, kasak wrote: > > 22.01.2023 14:49, David Gwynne пишет: >> On Sat, Jan 21, 2023 at 03:41:56PM +0300, kasak wrote: >>> Hello misc! >>> >>> I'm using bridge for integrating remote clients to my network with this >>> simple config: >>> >>> $ cat /etc/hostname.bridge0 >>> add vethe

Re: veb(4) with multiple vlan(4)'s

2023-01-22 Thread Hrvoje Popovski
On 22.1.2023. 12:45, David Gwynne wrote: >> hostname.veb1 > description "LAN" > >> link1 > you don't want to enable link1 unless you want pf to filter traffic on > the veb ports, and then you have to be careful to avoid having pf see > the packet again on the vport1 interface. > ah, yes, yes tha

Re: veb(4) with multiple vlan(4)'s

2023-01-22 Thread Hrvoje Popovski
On 22.1.2023. 3:27, Scott Colby wrote: > Hello, > > I am trying to set up a router with a fresh install of OpenBSD 7.2, > and I'm having a hard time grokking how to use veb. > > I have organized my network into 4 subnets: > > - DHCP "WAN" > - 192.168.0.0/24 "LAN" > - 192.168.2.0/24 "IOT" > - 192

Re: bridge(4) question new network setup

2023-01-20 Thread Hrvoje Popovski
On 20.1.2023. 20:09, patrick keshishian wrote: > Hello, > > I am trying get a new ISP setup working. The Router is > causing some pain. There is a /28 public block assigned. > The DSL router can't be configured in transparent bridge > mode (they say). It holds on to one of the /28 addresses. >

Re: BiDi sfp in ix

2023-01-11 Thread Hrvoje Popovski
On 9.1.2023. 15:21, Hrvoje Popovski wrote: > On 5.1.2023. 18:43, Hrvoje Popovski wrote: >> On 4.1.2023. 14:20, Ivo Chutkin wrote: >>> On 2.1.2023 г. 16:58 ч., Hrvoje Popovski wrote: >>>> On 28.12.2022. 20:21, Stuart Henderson wrote: >>>>> On 2022

Re: BiDi sfp in ix

2023-01-09 Thread Hrvoje Popovski
On 9.1.2023. 15:21, Hrvoje Popovski wrote: > On 5.1.2023. 18:43, Hrvoje Popovski wrote: >> On 4.1.2023. 14:20, Ivo Chutkin wrote: >>> On 2.1.2023 г. 16:58 ч., Hrvoje Popovski wrote: >>>> On 28.12.2022. 20:21, Stuart Henderson wrote: >>>>> On 2022

Re: BiDi sfp in ix

2023-01-09 Thread Hrvoje Popovski
On 9.1.2023. 16:39, Boyd Stephens wrote: > Hrvoje, > > I may be inquiring about an item that you have already provided but > would it be possible for you to supply a copy of your hostname.ix0 > config file.  I have been unable to locate this bit of info while > perusing this particular thread. >

Re: BiDi sfp in ix

2023-01-09 Thread Hrvoje Popovski
On 5.1.2023. 18:43, Hrvoje Popovski wrote: > On 4.1.2023. 14:20, Ivo Chutkin wrote: >> On 2.1.2023 г. 16:58 ч., Hrvoje Popovski wrote: >>> On 28.12.2022. 20:21, Stuart Henderson wrote: >>>> On 2022-12-28, Hrvoje Popovski wrote: >>>>> Hi all, >>&

Re: BiDi sfp in ix

2023-01-05 Thread Hrvoje Popovski
On 4.1.2023. 14:20, Ivo Chutkin wrote: > On 2.1.2023 г. 16:58 ч., Hrvoje Popovski wrote: >> On 28.12.2022. 20:21, Stuart Henderson wrote: >>> On 2022-12-28, Hrvoje Popovski wrote: >>>> Hi all, >>>> >>>> I don't have much experience wi

Re: BiDi sfp in ix

2023-01-02 Thread Hrvoje Popovski
On 28.12.2022. 20:21, Stuart Henderson wrote: > On 2022-12-28, Hrvoje Popovski wrote: >> Hi all, >> >> I don't have much experience with BiDi sfp, so I'm asking you guys, >> should openbsd ix work with 1G BiDi sfp. > > should do, yes. > > in

BiDi sfp in ix

2022-12-28 Thread Hrvoje Popovski
Hi all, I don't have much experience with BiDi sfp, so I'm asking you guys, should openbsd ix work with 1G BiDi sfp. Thank you. ix0 at pci5 dev 0 function 0 "Intel X552 SFP+" rev 0x00, msix, 4 queues, ix1 at pci5 dev 0 function 1 "Intel X552 SFP+" rev 0x00, msix, 4 queues, ifconfig ix0 media

Re: poor routing/nat performance

2022-12-19 Thread Hrvoje Popovski
On 19.12.2022. 17:35, David Hajes wrote: > hi guys, > > I have simple PcEngines APU2 router running latest OpenBSD stable. > > em0 is WAN (bridge to CaTV modem with 1Gbps/100Mbps connectivity with normal > ether connectivity with DHCP...no special stuff like PPPoE) > > em1-3 is in vether/bridge

Re: Stretch/L2VPN between two datacenters

2022-12-16 Thread Hrvoje Popovski
On 16.12.2022. 11:33, Lars Bonnesen wrote: > We are about to migrate VM's from one datacenter to another and the VMware > L2VPN we are using for this is simply not stable for some reason that we > cannot figure out why. > > I have used GRE-tunneling before on a software router that I actually > ca

Solidrun - Bedrock

2022-12-01 Thread Hrvoje Popovski
Hi all, I know that this box is new and can't be bought yet, only get for evaluation but maybe someone have dmesg? :) It looks very interesting to me. https://www.solid-run.com/fanless-computers/industrial-embedded-computers/bedrock-v3000-basic/ https://www.servethehome.com/solidrun-bedrock-pc-

Re: Does OpenBSD support Receive Side Scaling (also called: multi-queue receiving)

2022-10-15 Thread Hrvoje Popovski
On 15.10.2022. 9:39, Stuart Henderson wrote: > On 2022-10-14, Gabor LENCSE wrote: >> Dear All, >> >> I am a researcher and I would like to benchmark the stateful NAT64 >> performance of OpenBSD PF. >> >> I use a 32-core server as DUT (Device Under Test). When I use Linux for >> benchmarking othe

Re: AMD EPYC

2022-09-28 Thread Hrvoje Popovski
On 28.9.2022. 10:05, Kapetanakis Giannis wrote: > Hi, > > Looking for upgrading our firewall/router and thinking about switching from > Xeon to EPYC (73F3 - 16C @ 3.5 GHz). > > Anyone running on EPYC? Any problems? > > Alternative would be something like dual Intel Xeon Gold 5315Y - 8C @ 3.20 >

softnet em weirdness

2022-08-16 Thread Hrvoje Popovski
Hi all, I'm testing forwarding over em with plain with snapshot em0 at pci7 dev 0 function 0 "Intel 82576" rev 0x01: msi, em1 at pci7 dev 0 function 1 "Intel 82576" rev 0x01: msi, em2 at pci8 dev 0 function 0 "Intel I210" rev 0x03: msi, em3 at pci9 dev 0 function 0 "Intel I210" rev 0x03: msi, em4

Re: Fanless amd64 sytem recommendations

2022-08-09 Thread Hrvoje Popovski
On 8.8.2022. 14:16, Rachel Roch wrote: > My personal preference are Deciso boxes > (https://www.deciso.com/product-catalog/dec600/) > > They come with OpenSense but  you can plug in a USB serial cable and install > OpenBSD with zero issues. > Hi, I would recommend to go with at least 4 cores

Re: Latest -current boots very slow in VM

2022-07-01 Thread Hrvoje Popovski
On 2.7.2022. 0:11, Mischa wrote: > Hi All, > > Just updated one of my -current test VMs to the snapshot of June 30. > The boot process takes extremely long. As soon as it's booting: Hi, update to latest snaphost and console output will be fast again :) OpenBSD 7.1-current (GENERIC.MP) #599: Fri

Re: Cron running at 99% CPU for seemingly no reason

2022-05-15 Thread Hrvoje Popovski
On 15.5.2022. 16:56, Todd C. Miller wrote: > On Sun, 15 May 2022 16:02:03 +0200, Hrvoje Popovski wrote: > >> I know how to rebuild cron >> >> cd /usr/src/usr.sbin/cron/ >> make obj && make depend && make && make install >> >> but

Re: Cron running at 99% CPU for seemingly no reason

2022-05-15 Thread Hrvoje Popovski
On 15.5.2022. 15:38, Todd C. Miller wrote: > On Sun, 15 May 2022 14:29:28 +0200, Hrvoje Popovski wrote: > >> I'm seeing same as Stephan on few servers in lab. >> I've killed cron and did ktrace -i cron. Is this ok? >> In attachment you can find kdump -f ktrac

Re: Cron running at 99% CPU for seemingly no reason

2022-05-15 Thread Hrvoje Popovski
On 15.5.2022. 14:39, Hrvoje Popovski wrote: > On 15.5.2022. 14:29, Hrvoje Popovski wrote: >> On 15.5.2022. 12:32, Claudio Jeker wrote: >>> Also for cron, please attach ktrace to the cron process for a few seconds >>> and look at the kdump of that. Most probably it

Re: Cron running at 99% CPU for seemingly no reason

2022-05-15 Thread Hrvoje Popovski
On 15.5.2022. 12:32, Claudio Jeker wrote: > Also for cron, please attach ktrace to the cron process for a few seconds > and look at the kdump of that. Most probably it is constantly woken up for > some reasons. Hi, I'm seeing same as Stephan on few servers in lab. I've killed cron and did ktrace

Re: dmesg - cpu, smt, core, package

2022-02-10 Thread Hrvoje Popovski
On 10.2.2022. 20:03, Mihai Popescu wrote: >> you mean gaps because HT is disabled ? > > I think they are disabled from the factory, cores that are not 100% > functional, i.e defects. > There is one line for a family, the luckiest ones have the maximum > number of cores and $$$, the rest are lower

Re: dmesg - cpu, smt, core, package

2022-02-10 Thread Hrvoje Popovski
On 10.2.2022. 16:38, Todd C. Miller wrote: > On Thu, 10 Feb 2022 08:46:37 +, Stuart Henderson wrote: > >> The numbers come from what's reported by the relevant CPUID instruction, >> the only one actually used by OpenBSD is smt to disable all but one >> thread in a core, otherwise they're just

Re: dmesg - cpu, smt, core, package

2022-02-09 Thread Hrvoje Popovski
On 9.2.2022. 19:04, Kapetanakis Giannis wrote: > On 09/02/2022 19:48, Mihai Popescu wrote: >> $ dmesg | grep smt >> cpu0: smt 0, core 0, package 0 >> cpu1: smt 1, core 0, package 0 >> cpu2: smt 0, core 1, package 0 >> cpu3: smt 1, core 1, package 0 >> >> for >> >> AMD A8-5500B APU with Radeon(tm) H

dmesg - cpu, smt, core, package

2022-02-08 Thread Hrvoje Popovski
Hi all, in one supermicro box in dmesg i'm seeing this smc24# dmesg | grep smt cpu0: smt 0, core 0, package 0 cpu1: smt 0, core 1, package 0 cpu2: smt 0, core 2, package 0 cpu3: smt 0, core 3, package 0 cpu4: smt 0, core 4, package 0 cpu5: smt 0, core 5, package 0 cpu6: smt 0, core 8, package 0 c

Re: apu2e4 intermittent network freeze

2022-01-31 Thread Hrvoje Popovski
On 31.1.2022. 17:03, Amarendra Godbole wrote: > [...] > > Thanks for your response(s). A few releases ago I did have a bridge, > but realized it causes an overall throughput drop rather than using > individual interfaces directly. I should have clarified -- even though > both interfaces are on the

Re: apu2e4 intermittent network freeze

2022-01-31 Thread Hrvoje Popovski
On 31.1.2022. 13:44, Łukasz Moskała wrote: > W dniu 31.01.2022 o 02:44, Amarendra Godbole pisze: >> My home network has a PC Engines apu2e4 running OpenBSD 7.0, acting as >> a firewall/router, dhcp server, and DNS server. A Ruckus wifi AP >> receives a fixed DHCP address from apu2e4. All devices co

Re: CPU recommendation

2021-11-30 Thread Hrvoje Popovski
On 29.11.2021. 15:55, Barbaros Bilek wrote: > Hello @misc, > > I’m network administrator at a Hotel. We have nearly ~=1600 users > concurrently. > I’m trying to figure out which hardware covers my pc based OpenBSD firewall. > Disk : 1 TB SSD > RAM : 16 GB > Ethernet : Intel i211AT > But what about

Re: rpki-client and BLACKHOLE routes

2021-11-15 Thread Hrvoje Popovski
On 23.6.2021. 12:09, Claudio Jeker wrote: > On Wed, Jun 23, 2021 at 11:40:25AM +0200, Hrvoje Popovski wrote: >> Hi all, >> >> fist of all, thank you for rpki-client, it's so easy to use it and to >> get the job done. >> I'm playing with rpki-client

Re: Exoscale VPS panic on boot, 10-25 snapshot

2021-10-25 Thread Hrvoje Popovski
On 26.10.2021. 1:16, Ashlen wrote: > Here is as much information as I could get. After upgrading to a > snapshot earlier today (October 25th), the Exoscale VPS panics on boot. > I use this VPS to self-host synapse (a Matrix homeserver, for > messaging). > > I can't copy and paste from the web cons

Re: ipsec with default route and routing of internal networks

2021-10-05 Thread Hrvoje Popovski
On 14.9.2021. 13:12, Hrvoje Popovski wrote: > On 13.9.2021. 15:52, Stuart Henderson wrote: >> On 2021-09-13, Hrvoje Popovski wrote: >>> On 13.9.2021. 14:08, Tom Smyth wrote: >>>> Can you do  an exception for the ranges ...  so internet - private ips >

Re: ipsec with default route and routing of internal networks

2021-09-14 Thread Hrvoje Popovski
On 13.9.2021. 15:52, Stuart Henderson wrote: > On 2021-09-13, Hrvoje Popovski wrote: >> On 13.9.2021. 14:08, Tom Smyth wrote: >>> Can you do  an exception for the ranges ...  so internet - private ips >>> you dont want over the tunnel) >>> >>> ike e

Re: ipsec with default route and routing of internal networks

2021-09-13 Thread Hrvoje Popovski
On 13.9.2021. 14:08, Tom Smyth wrote: > Can you do  an exception for the ranges ...  so internet - private ips > you dont want over the tunnel) > > ike esp from 10.90.0.0/24 to any encrypt   > and  > >  10.90.0.0/24 to   NOT  [networks you dont want > o

Re: ipsec with default route and routing of internal networks

2021-09-13 Thread Hrvoje Popovski
Hi, On 13.9.2021. 12:58, Tom Smyth wrote: > Hi Hrvoje,  > > is 10.90.0.0/24 local to your firewall, and if I > understand your rule, > ike esp from 10.90.0.0/24  to any    you are saying   > encrypt all traffic comming from 10.90.0.0/24

ipsec with default route and routing of internal networks

2021-09-13 Thread Hrvoje Popovski
Hi all, I have a firewall that routes few internal networks, 10.90/24, 10.91/24, 10.92/24. And i have some static routes to other firewalls, but i don't think that is relevant to this problem. For network 10.90/24 i have ipsec tunnel, and i need to push any traffic from that network to the intern

supermicro bmc and openbsd efi install

2021-08-20 Thread Hrvoje Popovski
Hi all, In supermicro server i only have one m2 nvme disk. Because of that i need to enable efi boot to make that disk bootable ... I can mount install.img over bmc as HD image, but boot from that "virtual disk" won't start... is there any way to install openbsd efi image on supermicro server ove

Re: Resolved - Was: Performance tuning PF.

2021-07-27 Thread Hrvoje Popovski
On 27.7.2021. 17:36, Christopher Sean Hilton wrote: > On Sat, Jul 24, 2021 at 10:24:28AM -, Stuart Henderson wrote: >> On 2021-07-23, Christopher Sean Hilton wrote: >>> On Fri, Jul 23, 2021 at 11:19:35AM -0400, Chris Hilton wrote: > > [ ...snip... ] > >>> >>> Answering my own question, it lo

Re: OpenBSD 6.9 on Hetzner cloud server

2021-07-23 Thread Hrvoje Popovski
On 22.7.2021. 16:33, Matthias Schmidt wrote: > Hi, > > * Hrvoje Popovski wrote: >> Hi all, >> >> I'm thinking of getting Hetzner cloud server and install OpenBSD stable >> on it... >> >> Does anyone have experience with it? Is it complicated

OpenBSD 6.9 on Hetzner cloud server

2021-07-22 Thread Hrvoje Popovski
Hi all, I'm thinking of getting Hetzner cloud server and install OpenBSD stable on it... Does anyone have experience with it? Is it complicated to install OpenBSD on it? And of course, is it stable? Thank you

Re: rpki-client and BLACKHOLE routes

2021-06-24 Thread Hrvoje Popovski
On 23.6.2021. 12:09, Claudio Jeker wrote: > On Wed, Jun 23, 2021 at 11:40:25AM +0200, Hrvoje Popovski wrote: >> Hi all, >> >> fist of all, thank you for rpki-client, it's so easy to use it and to >> get the job done. >> I'm playing with rpki-client

rpki-client and BLACKHOLE routes

2021-06-23 Thread Hrvoje Popovski
Hi all, fist of all, thank you for rpki-client, it's so easy to use it and to get the job done. I'm playing with rpki-client and denying ovs invalid statement and I've seen that with default ovs config statement (deny from ebgp ovs invalid) BLACKHOLE routes are blocked/invalid. What is the right

Re: gnome, gdm problem on lenovo e14 gen2

2021-05-05 Thread Hrvoje Popovski
On 4.5.2021. 13:58, Nam Nguyen wrote: > Hrvoje Popovski writes: > >> Problem is that when i should get login screen, gdm to ask me for user >> and password, i'm getting blank grey screen .. >> >> after moving through terminals with ctrl-alt fX, from time to

gnome, gdm problem on lenovo e14 gen2

2021-05-03 Thread Hrvoje Popovski
Hi all, I've installed a snapshot on e14gen2 and the installation went smooth. Gnome was installed and configured based on /usr/local/share/doc/pkg-readmes/gnome. Problem is that when i should get login screen, gdm to ask me for user and password, i'm getting blank grey screen .. after moving thr

Re: OpenBSD on Dell PE R6515

2021-04-12 Thread Hrvoje Popovski
On 12.4.2021. 20:04, Joerg Streckfuss wrote: > > Hello folks, > > in the past we used Dell servers like PE 1850, PE 2850, PE R730 and PE > R740. We had good experiences running Openbsd on these systems. These > models are all Intel based but for another project i'm considering > giving AMD a chan

Re: Small/Mini 10Gbe Router Recommendation

2021-04-08 Thread Hrvoje Popovski
On 8.4.2021. 22:16, Daniel Melameth wrote: > On Thu, Apr 8, 2021 at 1:52 PM Hrvoje Popovski wrote: >> On 8.4.2021. 20:56, Daniel Melameth wrote: >>> On Thu, Apr 8, 2021 at 3:57 AM Stuart Henderson >>> wrote: >>>> On 2021-04-07, Daniel Melameth wrote

Re: Small/Mini 10Gbe Router Recommendation

2021-04-08 Thread Hrvoje Popovski
On 8.4.2021. 20:56, Daniel Melameth wrote: > On Thu, Apr 8, 2021 at 3:57 AM Stuart Henderson wrote: >> On 2021-04-07, Daniel Melameth wrote: >>> Looking to finally part with my legacy OpenBSD router and upgrade to >>> something that can push more than 2Gbps out of a single port. Since >>> my swi

Re: OT: Dell EMC switches

2021-04-08 Thread Hrvoje Popovski
On 8.4.2021. 20:58, Ivo Chutkin wrote: > Hello everyone, > > Does anyone have experience with Dell EMS switches? > > Namely S4100 series, S4128F-ON or S4188F-ON. > > Are they robust and reliable? > > I need to replace number of Extreme Networks X650. 10G ports are loaded > nearly 80% all the ti

Re: pf firewall bridge0 vether0 blocks DHCP for bridge interfaces connected to Windows

2021-03-10 Thread Hrvoje Popovski
On 10.3.2021. 20:40, da...@hajes.org wrote: > Hi, > > I did set up OpenBSD router/firewall on PC Engines APU4d4 box. > > First interface is WAN that connects to Internet. > > Remaining three interfaces are bridged with bridge0 via vether0. > > firewall doesn't block LAN/bridge traffic on vether

Re: 10Gbit network work only 1Gbit

2021-02-26 Thread Hrvoje Popovski
On 26.2.2021. 9:00, csszep wrote: > Hi! > > I miss something , or veb(4) ifconfig bits not yet commited ? > > OpenBSD 6.9-beta (GENERIC.MP) #358: Wed Feb 24 17:11:53 MST 2021 > dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP > > > ifconfig veb0 create > ifconfig: SIOCI

Re: 10Gbit network work only 1Gbit

2021-02-25 Thread Hrvoje Popovski
On 12.11.2019. 10:54, Szél Gábor wrote: > Dear Hrvoje, Theo, > > Thank you for your answers! > > answers to the questions: > -  who is parent interface for carp?  -> vlan  ( carp10 interface parent > vlan10 -> vlan10 interface  parent -> trunk0 ) > - why vlan interfaces don't have ip address ? ->

Re: Switching from trunk(4) to aggr(4)

2020-12-14 Thread Hrvoje Popovski
On 13.12.2020. 23:40, Daniel Jakots wrote: > I just tried > # ifconfig aggr0 debug > # dmesg > > # ifconfig aggr0 down > # ifconfig aggr0 up > # ifconfig aggr0 # checked the debug flag was still there > # dmesg > > > I also looked at /var/log/message to be save, but nothing relevant. Hi, maybe

Re: Intl I350 Network Card Not Found

2020-09-17 Thread Hrvoje Popovski
On 17.9.2020. 20:39, Brandon Woodford wrote: > Hello, > > I've been trying to fix an issue with my Intel I350-T4 PCI Network card not > being reported to the OpenBSD 6.7 system during boot. Looking through dmesg, > I was not able to find any reference to the card or the em interface name > tha

Re: openconnect

2020-09-03 Thread Hrvoje Popovski
On 1.9.2020. 15:22, Stuart Henderson wrote: > On 2020-09-01, Hrvoje Popovski wrote: >> Hi all, >> >> does anyone use an openconnect server on openbsd and have guidelines on >> how to configure it? i see that an openconnect server can use radius, so >> it's

openconnect

2020-09-01 Thread Hrvoje Popovski
Hi all, does anyone use an openconnect server on openbsd and have guidelines on how to configure it? i see that an openconnect server can use radius, so it's interesting to me. Which client do you use to connect to the openconnect server? If there is something else that can use radius, i would li

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-17 Thread Hrvoje Popovski
On 17.8.2020. 11:46, Stuart Henderson wrote: > On 2020-08-15, Hrvoje Popovski wrote: >> On 15.8.2020. 0:48, Hrvoje Popovski wrote: >>> On 12.8.2020. 15:18, Winfred Harrelson wrote: >>>> On Tue, Aug 11, 2020 at 07:52:10PM +0100, Tom Smyth wrote: >>>>>

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-15 Thread Hrvoje Popovski
On 15.8.2020. 0:48, Hrvoje Popovski wrote: > On 12.8.2020. 15:18, Winfred Harrelson wrote: >> On Tue, Aug 11, 2020 at 07:52:10PM +0100, Tom Smyth wrote: >>> Hi Winfred, >>> the intel 710 is a complex card, I would suggest that you try updating the >>>

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-14 Thread Hrvoje Popovski
On 12.8.2020. 15:18, Winfred Harrelson wrote: > On Tue, Aug 11, 2020 at 07:52:10PM +0100, Tom Smyth wrote: >> Hi Winfred, >> the intel 710 is a complex card, I would suggest that you try updating the >> firmware on the card, available from intel.com or your card vendor, >> you may have to boot to

Re: IPSec heavy traffic slows down all network traffic

2020-07-18 Thread Hrvoje Popovski
On 17.7.2020. 20:17, jean-yves boisiaud wrote: > hello, > > Last week, I upgraded a couple of firewalls using carp/pfsync and sasyncd > from 6.0 to 6.7 (yes, big jump !). > > I also applied all the 6.7 published patches. > > When some heavy traffic takes one of the IPSec tunnel, I noticed that :

Re: supermicro - A2SDV-8C-LN8F

2020-07-13 Thread Hrvoje Popovski
On 11.7.2020. 11:13, mlopenb...@xiphosura.co.uk wrote: > On Sat, 11 Jul 2020 00:13:34 +0200 > Hrvoje Popovski wrote: > >> Hi all, >> >> does anyone have experience or dmesg of this motherboard >> https://www.supermicro.com/en/products/motherboard/A2SDV-8C-

supermicro - A2SDV-8C-LN8F

2020-07-10 Thread Hrvoje Popovski
Hi all, does anyone have experience or dmesg of this motherboard https://www.supermicro.com/en/products/motherboard/A2SDV-8C-LN8F is it stable? i'm most interested in network performance and network cards. in motherboard manual i couldn't find what "Quad LAN with Intel® C3000 SoC" means ? is it

Re: strongSwan cannot install IPsec policies on OpenBSD

2020-02-21 Thread Hrvoje Popovski
On 20.2.2020. 18:47, Peter Müller wrote: > Hello openbsd-misc, > > is anybody out there running strongSwan as an IPsec client for a net-to-net > connection > on an OpenBSD machine? > > If so, I would be very grateful to know which steps are necessary in order to > successfully > route traffic t

Re: Brand new server - bad adventures

2020-01-22 Thread Hrvoje Popovski
On 22.1.2020. 21:30, Özgür Kazancci wrote: > Hello everyone! Greetings to misc people! > > Got a brand new dedicated server with a hardware: Intel Xeon-E 2274G - > 64GB DDR4 ECC 2666MHz - 2x SSD NVMe 960GB > and installed "brand new" OpenBSD 6.6 on it. (I'm managing it remotely > via KVM/IPMI) H

Re: small aggr problem ( on current )

2019-12-19 Thread Hrvoje Popovski
On 15.12.2019. 23:01, Hrvoje Popovski wrote: > On 15.12.2019. 12:45, Holger Glaess wrote: >> hi >> >> >>   runing version >> >> >> /etc 16>dmesg | more >> Copyright (c) 1982, 1986, 1989, 1991, 1993 >>     The Regents of the Universit

Re: small aggr problem ( on current )

2019-12-15 Thread Hrvoje Popovski
On 15.12.2019. 12:45, Holger Glaess wrote: > hi > > >   runing version > > > /etc 16>dmesg | more > Copyright (c) 1982, 1986, 1989, 1991, 1993 >     The Regents of the University of California.  All rights reserved. > Copyright (c) 1995-2019 OpenBSD. All rights reserved. > https://www.OpenB

Re: issues configuring vlan on top of aggr device

2019-12-03 Thread Hrvoje Popovski
On 3.12.2019. 15:11, Pedro Caetano wrote: > Hi again, > > I'm sorry, but since the boxes do not (yet) have working networking it > is not easy for me to get the text output. > I'm attaching a few pictures with the requested output. > > https://picpaste.me/images/2019/12/03/cat_hostname.vl3800_hos

Re: issues configuring vlan on top of aggr device

2019-12-03 Thread Hrvoje Popovski
aggr0 interface. > > I'd appreciate any help on this topic. > can you send ifconfig aggr0 and ifconfig vlan3800 ? > This configuration is working on -current with em(4) nics. > > > Best regards, > Pedro Caetano > > A terça, 3/12/2019, 12:01, Hrvoje Popovski <

Re: issues configuring vlan on top of aggr device

2019-12-03 Thread Hrvoje Popovski
On 3.12.2019. 12:21, Pedro Caetano wrote: > Hi misc@ > > I'm running openbsd 6.6 with latest patches running on a pair of hp dl 360 > gen6 servers. > > I'm attempting to configure an aggr0 device towards a cat 3650. > > The aggr0 associates successfully with the switch, but I'm unable to run > v

Re: 10Gbit network work only 1Gbit

2019-11-13 Thread Hrvoje Popovski
ipsec established over em0, pf disabled 8.10Gbps forwarding over ix0 and ix1, ipsec established over em0, pf enabled, 8 TCP streams 5.25Gbps > On 13.11.19 12:52, Hrvoje Popovski wrote: >> On 13.11.2019. 10:59, Hrvoje Popovski wrote: >>> On 12.11.2019. 10:54, Szél Gábor wrote: >

Re: 10Gbit network work only 1Gbit

2019-11-13 Thread Hrvoje Popovski
On 13.11.2019. 10:59, Hrvoje Popovski wrote: > On 12.11.2019. 10:54, Szél Gábor wrote: >> Dear Hrvoje, Theo, >> >> Thank you for your answers! >> >> answers to the questions: >> -  who is parent interface for carp?  -> vlan  ( carp10 interface parent >&

Re: 10Gbit network work only 1Gbit

2019-11-13 Thread Hrvoje Popovski
On 12.11.2019. 10:54, Szél Gábor wrote: > Dear Hrvoje, Theo, > > Thank you for your answers! > > answers to the questions: > -  who is parent interface for carp?  -> vlan  ( carp10 interface parent > vlan10 -> vlan10 interface  parent -> trunk0 ) > - why vlan interfaces don't have ip address ? ->

  1   2   3   >