Re: ipfw jail keyword broken in 11.3 by jail_getid changes

2019-08-01 Thread Ari Suutari via freebsd-stable
Hi, I tested your change and can confirm that it fixes the issue.     Ari S. On 1.8.2019 21.19, Kyle Evans wrote: On Thu, Aug 1, 2019 at 8:43 AM Kyle Evans wrote: On Thu, Aug 1, 2019 at 1:38 AM Ari Suutari via freebsd-stable wrote: Hi, We have a lot of servers using jails and ipfw rules

ipfw jail keyword broken in 11.3 by jail_getid changes

2019-07-31 Thread Ari Suutari via freebsd-stable
Hi, We have a lot of servers using jails and ipfw rules with numeric jail ids to limit acess between them (something like 'allow tcp from from me to me 8086 jail 1 keep-state'). This has been working very well for ages. Yesterday, we upgraded first of these servers to 11.3. During boot there are

Re: Carp seems completely broken on 8.2-RC2 and 8.2-PRERELEASE

2011-01-17 Thread Ari Suutari
Hi, On 16.1.2011 14:41, Paul Schenkeveld wrote: This is the kernel config for test1 and test2: include GENERIC device carp Could this be the cause ? In 8.2 it is no longer necessary to build custom kernel as carp can be loaded as module. I have carp running on two

Re: carp0 interface goes down on 6.2-PRERELEASE

2006-10-13 Thread Ari Suutari
Hi, Tom Judge wrote: Ari Suutari wrote: Ari Suutari wrote: I have now tested with real hardware (ethernet is fxp0) and under VmWare (ethernet is lnc0). Same problem on both. I'll have to correct this. Carp works with fxp0. Problem is only under vmware, which makes me

Re: carp0 interface goes down on 6.2-PRERELEASE

2006-10-13 Thread Ari Suutari
Hi, Ari Suutari wrote: I have now tested with real hardware (ethernet is fxp0) and under VmWare (ethernet is lnc0). Same problem on both. I'll have to correct this. Carp works with fxp0. Problem is only under vmware, which makes me more and more suspect th

Re: carp0 interface goes down on 6.2-PRERELEASE

2006-10-13 Thread Ari Suutari
Eugene Grosbein wrote: On Thu, Oct 12, 2006 at 02:44:32PM +0300, Ari Suutari wrote: I have seen similar problems when the carp multicast (224.0.0.18) traffic was not allowed to be transmitted to the network due to a firewall configuration problem. Firewall wasn't enabled at

Re: carp0 interface goes down on 6.2-PRERELEASE

2006-10-12 Thread Ari Suutari
Hi, Marko Lerota wrote: I meant: Maybe first they have to talk to each other and say: "OK, I will be the master first, and you wait. And if I don't send you any more sync packets, then you should be in charge :)" I have been using freevrrpd for quite a long time now and I thi

Re: carp0 interface goes down on 6.2-PRERELEASE

2006-10-12 Thread Ari Suutari
Hi, Vivek Khera wrote: On Oct 12, 2006, at 1:20 PM, Marko Lerota wrote: I think the interface didn't get sync from other carp interface, so it doesn't know that he is the MASTER or BACKUP, and because of that goes into the INIT state. Shouldn't it then move to MASTER since the other server

Re: carp0 interface goes down on 6.2-PRERELEASE

2006-10-12 Thread Ari Suutari
Hi, Tom Judge wrote: I have seen similar problems when the carp multicast (224.0.0.18) traffic was not allowed to be transmitted to the network due to a firewall configuration problem. Firewall wasn't enabled at this point, I wanted to keep things as simple as possible during

carp0 interface goes down on 6.2-PRERELEASE

2006-10-12 Thread Ari Suutari
Hi, I started experimenting with carp, in order to replace freevrrpd stuff we are currently using. I'm running quite recent version of RELENG_6 (compiled this week). I was able to configure carp ok, but for some odd reason the interface goes down by itself shortly after it has been configured.

SCSI hang when running under Ms Virtual Server 2005

2005-02-22 Thread Ari Suutari
Hi, I have tried to run both FreeBSD 4.10 and 5.3 under Microsoft's Virtual Server 2005. Both boot and work ok when virtual IDE disk is used. However, when trying to use SCSI disk (which seems to emulate an adaptec aic 7870 scsi adapter, so FreeBSD uses ahc driver) results in system hang after mach

Re: natd same_ports

2004-11-21 Thread Ari Suutari
Hi, Would please the maintainer or a core member check the natd.c source for the processing and correct defaults of natds' -same_ports option? I took a look at natd.c and the same_ports seems to be defined in source, it sets libalias options PKT_ALIAS_SAME_PORTS, nothing else. It relies o

Re: Adaptect raid performance with FreeBSD

2004-01-15 Thread Ari Suutari
Hi, On Wednesday 14 January 2004 15:42, Karl Pielorz wrote: > --On 14 January 2004 15:27 +0200 Ari Suutari <[EMAIL PROTECTED]> wrote: > > Hi, > > > > On Wednesday 14 January 2004 15:20, Karl Pielorz wrote: > >> > So, I get only about 25MB/s. Shouldn'

Re: Adaptect raid performance with FreeBSD

2004-01-14 Thread Ari Suutari
Hi, From: "ict technician" <[EMAIL PROTECTED]> > > Where's the other CPU? > What's da0 - send dmesg output The other CPU is sure active, at least when I look at things with top. da0 is another pair of disks, but older ones. I don't expect them to perform that well. Here is dmesg:

Re: Adaptect raid performance with FreeBSD

2004-01-14 Thread Ari Suutari
Hi, > riker# dd if=riker-bin.068 of=/dev/null bs=1m count=1000 > 1000+0 records in > 1000+0 records out > 1048576000 bytes transferred in 4.869752 secs (215324315 bytes/sec) I'm afraid that reading from file might give too good results since you might be getting data from filesystem cache

Re: IPsec/gif VPN tunnel packets on wrong NIC in ipfw? SOLUTION ANDQUESTIONS

2002-11-26 Thread Ari Suutari
Hi, On Tuesday 26 November 2002 15:19, Greg Panula wrote: > > # allow private traffic between location to flow > allow ip from 10... to 192.168... out via int.nic > allow ip from 192.168... to 10... in via int.nic > > Granted the ruleset above assumes you are *not* using gif tunnels, just > ipsec