Re: Racoon(ipsec-tools) enters sbwait state or 100% CPU utilization quite often on RELENG_1_2

2007-08-18 Thread George V. Neville-Neil
At Sat, 18 Aug 2007 15:58:16 -0400, Scott Ullrich wrote: > Thanks for the very detailed response. We have worked around the > problem for now with a simple shell script that looks for racoon > falling over and simply restarting it. > > Does anyone know if this is fixed in 7-CURRENT? If so we ca

Re: problems with networking...

2007-08-18 Thread Bill Moran
"Michael Hawkins" <[EMAIL PROTECTED]> wrote: > > Sorry if this is sorta n00bish, but I have a problem that Google hasn't > answered for me yet... > I have a moderately-sized network that I am trying to run, with about 70 or > so machines on it. The DHCP server (running FreeBSD 6.2, IPv4 address: >

problems with networking...

2007-08-18 Thread Michael Hawkins
Sorry if this is sorta n00bish, but I have a problem that Google hasn't answered for me yet... I have a moderately-sized network that I am trying to run, with about 70 or so machines on it. The DHCP server (running FreeBSD 6.2, IPv4 address: 10.11.12.254, Subnet is 10.11.12.0/24) acts as a gateway

Re: Racoon(ipsec-tools) enters sbwait state or 100% CPU utilization quite often on RELENG_1_2

2007-08-18 Thread Scott Ullrich
On 8/18/07, VANHULLEBUS Yvan <[EMAIL PROTECTED]> wrote: [snip] > It really looks like an old "known" (well, at least known by me...) > problem with PFKey interface: it is quite impossible to set up more > than 50-100 tunnels on a standard FreeBSD (and probably any other KAME > based stack), because

Re: Failover default route?

2007-08-18 Thread Bruce M. Simpson
Tuc at T-B-O-H.NET wrote: In my case, as always, its a bit "special". I have 2 OPENVPN tunnels, which I sent over different transits to the same end host. On that host, I do my NAT. SO, without getting into all sorts of hot/heavy things, is there a simple program to install to ping someth

Re: Failover default route?

2007-08-18 Thread Bill Moran
"Tuc at T-B-O-H.NET" <[EMAIL PROTECTED]> wrote: > > Hi, > > I know its been talked about before, did 1/2 an > hour of Google... > > In my case, as always, its a bit "special". I have > 2 OPENVPN tunnels, which I sent over different transits to > the same end host. On that host, I do

Failover default route?

2007-08-18 Thread Tuc at T-B-O-H.NET
Hi, I know its been talked about before, did 1/2 an hour of Google... In my case, as always, its a bit "special". I have 2 OPENVPN tunnels, which I sent over different transits to the same end host. On that host, I do my NAT. SO, without getting into all sorts of hot/heavy things

Re: pf rdr statement & ipsec processing interaction

2007-08-18 Thread Eric Masson
Eric Masson <[EMAIL PROTECTED]> writes: Hello, > So outgoing l2tp packets should be esp transformed, right ? I've been able to reproduce the problem on a -current box (sources from yesterday), should I file a PR ? Regards Éric Masson -- C'est vrai peut t'on renconter quelqu'un sur internet?

Re: Racoon(ipsec-tools) enters sbwait state or 100% CPU utilization quite often on RELENG_1_2

2007-08-18 Thread VANHULLEBUS Yvan
On Fri, Aug 17, 2007 at 04:53:56PM -0400, Scott Ullrich wrote: > Hello! Hi. > We are trying to track down a problem that involves a large number of > ipsec tunnels (in this case 80). Frequently racoon (ipsec-tools > 0.7rc1 and also 0.6) will deadlock into the sbwait state or will enter > a 100%