Re: Can't get carp to fail over all interfaces with pfsync

2009-11-10 Thread Mikel Lindsaar
On Tue, Nov 10, 2009 at 7:25 PM, Otto Moerbeek o...@drijf.net wrote: On Tue, Nov 10, 2009 at 06:36:24PM +1100, Mikel Lindsaar wrote: Shouldn't you run different vhid ID of carp on different carp instance. Here you have Carp0 and carp 1 both running with vhid 1, so how will the system

Re: Can't get carp to fail over all interfaces with pfsync

2009-11-10 Thread Mikel Lindsaar
On Tue, Nov 10, 2009 at 8:09 PM, Camiel Dobbelaar c...@sentia.nl wrote: To clarify, CARP is working in terms of redundancy, what does not seem to be working is the preempting of the primary firewall interfaces by the backup firewall should _one_ of the primary interfaces be taken off line

Can't get carp to fail over all interfaces with pfsync

2009-11-09 Thread Mikel Lindsaar
Hi list, So googled, went through http://www.openbsd.org/faq/pf/carp.html a few times as well as the archives including one large thread which seemed to deal with this exact issue, but the solution was setting the VHID to the same on all carp interfaces (which I have already tried), and I can't

Re: Can't get carp to fail over all interfaces with pfsync

2009-11-09 Thread Mikel Lindsaar
On Tue, Nov 10, 2009 at 5:37 PM, Daniel Ouellet dan...@presscom.net wrote: FW1 hostname.if files are: $ cat /etc/hostname.carp0 inet 192.168.167.54 255.255.255.248 192.168.167.55 vhid 1 advskew 0 pass password $ cat /etc/hostname.carp1 inet 192.168.110.254 255.255.255.224

HP DL360 Fan Control

2009-09-26 Thread Mikel Lindsaar
I am looking at working out how to control the fans in a HP DL360. Right now, the fans start low, but if the room gets warm, they go to high (Boeing 747) volume, and the only way to put them back down to low, is a reboot, PITA. It looks like the HP website mentions OS specific system health

Re: HP DL360 Fan Control

2009-09-26 Thread Mikel Lindsaar
You could start here: http://people.freebsd.org/~jcagle/#ilo You could try to fiddle with the Web-based iLO (configure the 3rd ethernet port in the setup) and connect with a web browser... I'll check that out, but from memory, couldn't find that setting last time I looked. BTW, HP

On 4.4, ls /path/tabtab apparently hanging disk subsystem

2009-05-03 Thread Mikel Lindsaar
Hi all, I have two HP DL380 G3 servers with two 36Gb SAS drives on it in a hardware RAID 1 mirror using the inbuilt raid controller. When I do an ls /path/filetabtab to get a possible match list, the server disk subsystem hangs. If I do ls /dev/tabtab it always hangs, keyboard does not respond,

spamd handling multiple sending servers

2009-03-23 Thread Mikel Lindsaar
Hi all, New user to spamd, love it. In getting our low traffic email server running, the first thing I noticed while following the logs that sites like gmail et al will retry a message from a different host. Sometimes gmail will send once, try again very soon again from the same host and then

heartbeating Carp ?

2009-02-24 Thread Mikel Lindsaar
Hi all, I have a pair of firewalls using carp between them in front of some servers. Works really nice. Today, however, I got an edge case on the firewalls. Firewall one was not accessible, and I couldn't access any firewall behind it. Getting into firewall 2 directly, I found that firewall 1

Re: [OT] soekris4801: CF and hard disk ?

2008-11-25 Thread Mikel Lindsaar
On Wed, Nov 26, 2008 at 8:27 AM, jul [EMAIL PROTECTED] wrote: is it possible to have both Compact Flash and Hard disk in this soekris at the same time? Yes. Here is my dmesg for a net5501 I don't recall doing anything special. But I do think I installed OpenBSD on the sandisk first, then

Re: PF and the old SIP issue

2008-11-19 Thread Mikel Lindsaar
On Thu, Nov 20, 2008 at 1:44 AM, marrandy [EMAIL PROTECTED]wrote: On Wednesday 19 November 2008 09:07:31 you wrote: OpenBSD PF firewall consisting of ext, DMZ, internal/private interfaces. VOIP server sitting in the DMZ. Multiple (pick any number, 5, 10, 100) SIP phones in the private

Re: Multipath to CISCO

2008-11-05 Thread Mikel Lindsaar
On Wed, Nov 5, 2008 at 2:11 PM, Jussi Peltola [EMAIL PROTECTED] wrote: The other option I believe would be using PF to round robin the packets on both destinations using route-to rules. Would this work? Why wouldn't it? Not that I can think of, I guess that is why I am emailing the list

Re: Multipath to CISCO

2008-11-05 Thread Mikel Lindsaar
On Thu, Nov 6, 2008 at 5:45 AM, andrew fresh [EMAIL PROTECTED] wrote: On Wed, Nov 05, 2008 at 09:40:02AM +, Stuart Henderson wrote: On 2008-11-05, Mikel Lindsaar [EMAIL PROTECTED] wrote: The other option I believe would be using PF to round robin the packets on both destinations

Multipath to CISCO

2008-11-04 Thread Mikel Lindsaar
Hi all, I am trying to get 4mb/s of IAX2 voice traffic to a single VOIP provider using an IAX2 trunk down here in Australia. One of the options we have is getting a 4mb SHDSL connection with an ISP. The ISP usually want to install a CISCO 1841 with two WIC1-SHDSL cards at a lease rate of $2,400

Re: newbie network segment routing query

2008-11-04 Thread Mikel Lindsaar
On Wed, Nov 5, 2008 at 3:16 AM, John . [EMAIL PROTECTED] wrote: fxp0 to the speedtouch fxp1 for a network that I want to be unfiltered, in other words, real IPs (wired) fxp2 the top usable real IP - this I want to nat behind, it is for wireless fxp3 is unused. Is this a DMZ for fxp1? I

Re: Sensor data and RAID notifications help wanted

2008-11-02 Thread Mikel Lindsaar
On Sun, Nov 2, 2008 at 3:28 PM, Mikel Lindsaar [EMAIL PROTECTED] wrote: 2008/11/2 Constantine A. Murenin [EMAIL PROTECTED]: Have you tried enabling ipmi (boot -c enable ipmi quit)? It is disabled mostly due to some problems with IBM servers, AFAIK... Thank you very much! This handled

Re: OpenBSD 4.4 released, Nov 1. Enjoy!

2008-11-01 Thread Mikel Lindsaar
On Sat, Nov 1, 2008 at 6:11 PM, my mail [EMAIL PROTECTED] wrote: --- On Fri, 10/31/08, Theo de Raadt [EMAIL PROTECTED] wrote: We are pleased to announce the official release of OpenBSD 4.4. Thanks again for your work Theo et all...

Sensor data and RAID notifications help wanted

2008-11-01 Thread Mikel Lindsaar
. If anyone is interested, please email me on or off list. Your choice. Mikel Lindsaar

Re: Sensor data and RAID notifications help wanted

2008-11-01 Thread Mikel Lindsaar
2008/11/2 Constantine A. Murenin [EMAIL PROTECTED]: Have you tried enabling ipmi (boot -c enable ipmi quit)? It is disabled mostly due to some problems with IBM servers, AFAIK... Thank you very much! This handled it! Mikel

How to debug IPSec and PF problem

2008-10-29 Thread Mikel Lindsaar
Hi all, I've got a VPN running between two networks. Works fine for basically everything and very easy to setup, kudos to the guys that worked on ipsecctl and isakmpd. I have one problem though that I am trying to debug. Network looks like this: 192.168.11.250# Asterisk1 |

Re: How to debug IPSec and PF problem

2008-10-29 Thread Mikel Lindsaar
On Wed, Oct 29, 2008 at 8:06 PM, Christoph Leser [EMAIL PROTECTED] wrote: On Wed, 29 Oct 2008 17:01:21 +1100, Mikel Lindsaar wrote: I've got a VPN running between two networks. Works fine for basically If so why would traffic from one LAN host at the 192.168.4. end be any different

Management of HP Proliant DL and BL Series

2008-10-29 Thread Mikel Lindsaar
I've got a few (10) HP DL and BL servers running OpenBSD. These are spread out over several sites and run our firewalls and monitoring servers. Trying to find the best way to monitor them for drive, psu failures etc. Has anyone had any success along this line? Looking at the various sites, the

Re: Shutdown with the power button

2008-10-17 Thread Mikel Lindsaar
On Thu, Oct 16, 2008 at 11:54 PM, [EMAIL PROTECTED] wrote: On Thu, Oct 16, 2008 at 11:30:02PM +1100, Mikel Lindsaar wrote: Hmm... here is the dmesg then any ideas? looks like you're missing an acpibtn (man acpibtn). Thanks Peter, that is the case and it looks like the why on the problem

Shutdown with the power button

2008-10-16 Thread Mikel Lindsaar
Hi list, Wondering if anyone knows how (or if it is possible) to be able to gracefully power down an OpenBSD box by hitting the power button on the server. Useful when you need someone to power down a system (like in a power failure situation) but there is no console attached. FreeBSD and linux

Re: Shutdown with the power button

2008-10-16 Thread Mikel Lindsaar
On Thu, Oct 16, 2008 at 11:22 PM, Gregory Edigarov [EMAIL PROTECTED] wrote: Mikel Lindsaar wrote: Wondering if anyone knows how (or if it is possible) to be able to gracefully power down an OpenBSD box by hitting the power button on the server. Mine does clean shutdown on power button just

PF rule evaluation

2008-08-24 Thread Mikel Lindsaar
Hello list, I have purchased and read the book of PF (good book by the way) as well as the man pages, and I have a question that I have not been able to find a definitive answer on: Does PF only evaluate every packet against the ruleset once on all interfaces, or does it evaluate once for each

Re: PF rule evaluation

2008-08-24 Thread Mikel Lindsaar
On Mon, Aug 25, 2008 at 11:33 AM, Aaron Stellman [EMAIL PROTECTED] wrote: On Mon, Aug 25, 2008 at 11:05:38AM +1000, Mikel Lindsaar wrote: I have purchased and read the book of PF (good book by the way) as well as the man pages, and I have a question that I have not been able to find

4.3 Install HP BL10eG2 Blade - panic: revarp failed, error=51

2008-05-01 Thread Mikel Lindsaar
I had OpenBSD 4.2 Running on these blades, installed via PXE fine. Seems though, in running the 4.3 pxeboot and kernel, it dies on trying to send RARP packets out? Anyone have some ideas on how to get this to install? Boot sequence and then DMESG attached (with PS and TRACE) at the end.

Re: [SOLVED] 4.3 Install HP BL10eG2 Blade - panic: revarp failed, error=51

2008-05-01 Thread Mikel Lindsaar
On Thu, May 1, 2008 at 8:32 PM, Stuart Henderson [EMAIL PROTECTED] wrote: On 2008-05-01, Mikel Lindsaar [EMAIL PROTECTED] wrote: I had OpenBSD 4.2 Running on these blades, installed via PXE fine. Seems though, in running the 4.3 pxeboot and kernel, it dies on trying to send RARP packets

Re: Apache VirtualHost permissions

2008-04-17 Thread Mikel Lindsaar
On Fri, Apr 18, 2008 at 7:37 AM, David Newman [EMAIL PROTECTED] wrote: but I'm confused about the 'chown nobody:www' part. I don't get how users would be able to upload files with those permissions. Depends. If they are uploading via a web interface, then you need your web server to be able

Re: 4.3 song and lyrics and commentary

2008-04-12 Thread Mikel Lindsaar
On Sat, Apr 12, 2008 at 4:03 PM, Pau [EMAIL PROTECTED] wrote: are the pictures real?? Isn't it amazing what you can do with some free time and some photo editing tools? Mikel

Re: carp and STP and layer2 security

2008-04-11 Thread Mikel Lindsaar
On Fri, Apr 11, 2008 at 10:04 PM, Henning Brauer [EMAIL PROTECTED] wrote: i have finally taken the time to quickly write up what you need to do on your switches when using carp and/or STP. comments welcome. http://bulabula.org/carp-and-stp-meet-switch-security.html Short and sharp, thanks.

4.2 still has X tree dependency?

2008-03-30 Thread Mikel Lindsaar
I am running 4.1 on several servers, one thing I found was the surprise on needing the X package to install some of the non x-windows ports due to dependencies within that tree. I think it was for the graphics libraries, either way, I installed the x packages and all is well. But I remember

PCI ADSL Card on OpenBSD

2008-01-26 Thread Mikel Lindsaar
I have been googling around and found various answers, but some of them conflict and so I wanted to ask the list: What PCI ADSL card do you use in your OpenBSD box? The use case will be a rack mounted firewall (thus the wish for a PCI card to sit inside the server) handling an ADSL connection

Best way to automate administration of multiple servers

2007-11-14 Thread Mikel Lindsaar
Hello all, I've been googling around for some answers and I thought I would ask the list as well. In the past I have used different compters for different tasks. I would have many different installs of OpenBSD on many different platforms. However, i am moving some stuff into a data center and

OK... I broke something - can't load library 'libpcre.so.1.0'

2007-11-06 Thread Mikel Lindsaar
Hello list :) I was getting ImageMagick working with Rails on OpenBSD and was running into problems. In the process of installing it, somehow I nuked the libpcre library. I went into /usr/ports/devel/pcre/ and did a make clean, make, make install. However I am still getting the error. I tried

TLS/FTP via OpenBSD NAT

2007-10-12 Thread Mikel Lindsaar
Hello all, I have a few OpenBSD servers faithfully running NAT in various spots. One of these firewalls is doing VERY simple NAT on an interface, almost a cut and past from the PF pages (only really the IP addresses got changed). However, the client wants to be able to connect to an FTP server