IKEv1 and IKEv2 coexistence

2023-01-09 Thread jean-yves boisiaud
you for your help. -- Jean-Yves Boisiaud - Alcor Consulting 49, rue du Chemin Vert 49300 Cholet mobile : +33 6 63 71 73 46

Re: IPSec heavy traffic slows down all network traffic

2020-07-30 Thread jean-yves boisiaud
Hello, i replaced the MP kernel with the SP one and made some tests. Perfomances are better, all cpu goes to the kernel and user processes. But it is slow. I will ask to change the hardware, as it is old. jy boisiaud Le mer. 22 juil. 2020 à 08:36, jean-yves boisiaud < jean-yves.boisi...@al

Re: IPSec heavy traffic slows down all network traffic

2020-07-21 Thread jean-yves boisiaud
ok, i'll try with the bsd.sp kernel. thank you for your help. :-( Le dim. 19 juil. 2020 à 07:41, Chris Cappuccio a écrit : > jean-yves boisiaud [jean-yves.boisi...@alcor-consulting.fr] wrote: > > Last week, I upgraded a couple of firewalls using carp/pfsync and sasyncd >

IPSec heavy traffic slows down all network traffic

2020-07-17 Thread jean-yves boisiaud
drm:pid0:connector_bad_edid *WARNING* VGA-1: EDID is invalid: [00] BAD f0 f0 f0 f0 f0 f0 f0 f0 f0 f0 f0 f0 e1 e1 e1 e1 [00] BAD c3 c3 c3 c3 87 87 87 87 0f 0f 0f 0f 1f 1f 1f 1f [00] BAD 3f 3f 3f 3f 7f 7f 7f 7f ff ff ff ff ff ff ff ff [00] BAD ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff [

OpenBSD with root FS mounted read only

2018-11-15 Thread jean-yves boisiaud
? -- Jean-Yves Boisiaud - Alcor Consulting 49, rue du Chemin Vert 49300 Cholet

Re: Problem with installing OpenBSD 6.4 on VirtualBox

2018-11-14 Thread jean-yves boisiaud
hello, I upgraded VirtualBox from 5.1 to 5.2 and ... it works ! as the solution was so easy, i feel confused... thanks for your help. Le mar. 13 nov. 2018 à 22:07, jean-yves boisiaud < jean-yves.boisi...@alcor-consulting.fr> a écrit : > hello Dumitru, > > thanks for your ans

Re: Problem with installing OpenBSD 6.4 on VirtualBox

2018-11-13 Thread jean-yves boisiaud
hello Dumitru, thanks for your answer. Le mar. 13 nov. 2018 à 21:50, Dumitru Moldovan a écrit : > On Tue, 13 Nov 2018 20:51:09 +0100, jean-yves boisiaud < > jean-yves.boisi...@alcor-consulting.fr> wrote: > > > I 'm trying to install OpenBSD 6.4 on VirtualBox 5.

Problem with installing OpenBSD 6.4 on VirtualBox

2018-11-13 Thread jean-yves boisiaud
nbus0 pckbc0 at isa0 port 0x60/5 irq 1 irq 12 I used the last install64.iso file. I also tried with install64.fs, same problem. How could I install obsd 6.4 ? Thank you for your help. -- Jean-Yves Boisiaud - Alcor Consulting 49, rue du Chemin Vert 49300 Cholet - France mobile : +33 6 63 71 73 46

problem with an etherip interface (arp replies do not come back)

2017-02-14 Thread jean-yves boisiaud
Is it the same problem that http://openbsd-archive.7691.n7.nabble.com/bridge-fails-to-broadcast-ARP-from-gif-tunnel-td283960.html ? Thank you for your help. -- Jean-Yves Boisiaud - Alcor Consulting 24, rue de la Glycine 49250 Saint Remy la Varenne mobile : +33 6 63 71 73 46 <+33%206%2063%2071%

Re: etherip problem

2017-02-06 Thread jean-yves boisiaud
etherip0 and bridge0 were not up. I added the up keyword into /etc/hostname.bridge0 and /etc/hostname.etherip0. Thanks to Pierre. Now, I can see traffic crossing the etherip tunnel. But ARP is still not fully working. I investigate... 2017-02-03 15:11 GMT+01:00 jean-yves boisiaud < j

etherip problem

2017-02-03 Thread jean-yves boisiaud
t 6 proto rstp designated: id 00:00:00:00:00:00 priority 0 etherip0 flags=3 port 6 ifpriority 0 ifcost 0 vmx1 flags=3 port 2 ifpriority 0 ifcost 0 Addresses (max cache: 100, timeout: 240): -- Jean-Yves Boisiaud - Alcor Consulting 24, rue de la Glyci

Re: Restricted shell and ssh problem

2016-08-25 Thread jean-yves boisiaud
found the probleM. I Forgot to set ForwardAgent in the 1st ssh command. Sorry. 2016-08-25 18:45 GMT+02:00 jean-yves boisiaud < jean-yves.boisi...@alcor-consulting.fr>: > Hello, > > I am running openbsd 5.7 and openssh 6.8. > > I set a restricted shell (rksh) to run only

Restricted shell and ssh problem

2016-08-25 Thread jean-yves boisiaud
authentication. How could I use agent authentication with ssh when I am in a restricted shell ? ​Thanks for your help.​ -- Jean-Yves Boisiaud - Alcor Consulting 24, rue de la Glycine 49250 Saint Remy la Varenne mobile : +33 6 63 71 73 46 fixe : +33 9 72 41 19 35

Re: Incoming packets arrives on an interface and outgoing packets takes another interface

2015-09-10 Thread jean-yves boisiaud
I will try. Thanks for your help. 2015-09-09 23:16 GMT+02:00 Giancarlo Razzolini : > Em 09-09-2015 07:11, jean-yves boisiaud escreveu: > > I resolved the problem with the reply-to pf directive. > If you enable multipath and add the default gateways, you can use a > reply-to fo

Re: Incoming packets arrives on an interface and outgoing packets takes another interface

2015-09-09 Thread jean-yves boisiaud
; On Wed, 9 Sep 2015 12:11:38 +0200 > jean-yves boisiaud wrote: > > > I resolved the problem with the reply-to pf directive. > > Hi, > > I'm struggling with the same problem as well. Could you please share > relevant part of your ruleset? > > Thank you in ad

Re: Incoming packets arrives on an interface and outgoing packets takes another interface

2015-09-09 Thread jean-yves boisiaud
I resolved the problem with the reply-to pf directive. Thanks to P. Lamaiziere 2015-09-08 12:16 GMT+02:00 jean-yves boisiaud < jean-yves.boisi...@alcor-consulting.fr>: > hello, > > I'm using OBSD 5.7 as a firewall with carp and pfsync, more ipsec VPN used > with

Incoming packets arrives on an interface and outgoing packets takes another interface

2015-09-08 Thread jean-yves boisiaud
anges. How could I resolve this routing problem ? Thanks for your help. -- Jean-Yves Boisiaud - Alcor Consulting 24, rue de la Glycine 49250 Saint Remy la Varenne

Re: IPSec and Cisco peers

2015-04-11 Thread jean-yves boisiaud
erg wrote: >> What I finally did was simply to enable DPD by default in isakmpd.conf >> (you want to have it always on anyways). > > Note that you can have an isakmpd.conf with only needed settings, and > continue to configure sessions with ipsecctl/ipsec.conf. > --

Re: IPSec and Cisco peers

2015-04-07 Thread jean-yves boisiaud
de. > - Use packet-tracer from the cisco device, it's really helpful in these > situations. > - Verify every little bit of configuration on both sides so that they are > exactly the same. > > Alexander Salmin > > > On 2015-04-07 16:28:00, jean-yves boisiaud wr

IPSec and Cisco peers

2015-04-07 Thread jean-yves boisiaud
in my configuration ? ike dynamic esp from 192.168.36.0/24 to 10.0.0.0/8 \ local X peer Y \ main auth hmac-md5 enc 3des group grp2 lifetime 28800 \ quick auth hmac-sha1 enc 3des group grp2 lifetime 28800 \ srcid "X" dstid "Y" \ psk "z" -- Jean-Yves Boisiaud - Alc

netflow + carp + nat problem

2014-11-10 Thread jean-yves boisiaud
, tcpdump shows there is traffic for these missing packets. The missing packets are using a carp interface and are natted. The IP used for the nat is an alias, not the main IP address of the carp interface. Do you know if there a problem with netflow + carp alias + nat ? -- Jean-Yves Boisiaud

netflow + carp + nat question

2014-11-07 Thread jean-yves boisiaud
for these missing packets. The missing packets are using a carp interface and are natted. The IP used for the nat is an alias, not the main IP address of the carp interface. Do you know if there a problem with netflow + carp alias + nat ? -- Jean-Yves Boisiaud - Alcor Consulting 24, rue de la

enc and IPSec question

2009-04-27 Thread Jean-Yves Boisiaud
Hello, I configured an IPSec tunnel with ipssecctl and ipsec.conf. The default interface of the gateway is 219.17.10.1. The other gateway runs Checkpoint. Here is a part of my ipsec.conf : ike active esp from 192.168.36.0/24 to 10.128.203.0/24 \ peer 161.144.27.32 \ main auth h

Re: problem booting on other partition than hd0a

2008-02-07 Thread Jean-Yves Boisiaud
Alexander Hall wrote: Jean-Yves Boisiaud wrote: Hello, I'm using OpenBSD with a Soekris NET4801. To make my job easy and more secure to upgrade software, I have several targets to keep up to date. All partitions are always read only. I prepare an image for all of them, and send th

Re: problem booting on other partition than hd0a

2008-02-07 Thread Jean-Yves Boisiaud
Julian Leyh wrote: On 13:36 Wed 06 Feb , Jean-Yves Boisiaud wrote: I change the /etc/boot.conf, which now is : set tty com0 stty com0 19200 set timeout 5 boot hd0b:/bsd try "set device hd0b" instead of the last line... I tried : set device hd0b set image /bsd It's the same.

problem booting on other partition than hd0a

2008-02-06 Thread Jean-Yves Boisiaud
Hello, I'm using OpenBSD with a Soekris NET4801. To make my job easy and more secure to upgrade software, I would like to have 2 root partitions on the label, one is active at a time and the other will filled with the upgrade by dd. I compiled a kernel with, in NET4801 config file, the line :

problem with Intel quad adapters PRO/1000MT

2008-01-16 Thread Jean-Yves Boisiaud
hello, I'm running OBSD 4.2 on a Axiomtek NA-1531. It's a network appliance with 3 Intel 100 MB fxp adapters, an Intel PRO/1000CT and an Intel quad PRO/1000MT. The problem is with the PRO/1000MT. Other interfaces works fine. Network traffic on quad 1000MT is slow, very slow, and the followin

Re: Device modification time on /dev

2007-05-16 Thread Jean-Yves Boisiaud
Same as if you specify -i 1024. I don't know if anything will change in that regard between now and 4.2, but that's the way it is now. (yes, I did discover this change on remote kit, but I already had good remote console access available so it didn't involve 4 hours travel to fix :-) Don't bother

Re: Device modification time on /dev

2007-05-16 Thread Jean-Yves Boisiaud
Stuart Henderson wrote: On 2007/05/16 11:33, Jean-Yves Boisiaud wrote: I want to limit write accesses on the compact flash, so I mounted / read only, with the noatime option. /var is mounted in RAM. Do you know that you need more than fstab(5) changes to mount / RO? Yes, I could create a mfs

Device modification time on /dev

2007-05-16 Thread Jean-Yves Boisiaud
Hello, I use OBSD on a Soekris target, which uses a compact flash. I want to limit write accesses on the compact flash, so I mounted / read only, with the noatime option. /var is mounted in RAM. Then, I ran mtree as a simple IDS. I saw that some devices had their modification time updated, f

problem booting Supermicro PDSMA

2007-02-22 Thread Jean-Yves Boisiaud
hello, We've just bought a Supermicro PDSMA motherboard and we would like to install OBSD 4.0. Specific hardware is a SATA II RAID controler, an Areca 1110. North bridge : Mukilteo E7230 South bridge : ICH7R 2 GB lan controlers on the motherboard, an Intel PRO/1000MT and a 1000PT. Here is t

what happened to union fs ?

2006-03-09 Thread Jean-Yves Boisiaud
hello, in OBSD 3.8, union filesystem (mount_union(8)) has been removed. http://www.openbsd.org/plus38.html does not say nothing about that. Will union fs be back ? If not, why ? Thanks J-Yves