I'm trying CARP load balancing on several switchs and most have behavior
not compatible with CARP balancing both in ip and ip-stealth mode.
Ip-unicast also seem a bad option in my test since all switch I tested that
support mirroring can only mirror to one port (or I didn't see any option
to mirror
The solution seem his explain on this link
Message d'origine
De: Marko Cupać
Envoyé: mercredi 24 juin 2015 07:21
À: misc@openbsd.org
Objet: pf nat and routing question
my setup is actually more complicated, but for purpose of this mail I
Michel Blais
Administrateur réseau
Targo communications
2015-05-14 17:01 GMT-04:00 Claudio Jeker :
> On Thu, May 14, 2015 at 03:31:09PM -0400, Michel Blais wrote:
> > Thanks Claudio for answering
> >
> > I added the option "nexthop qualify via bgp" and now, route
me this option is unsecure.
Michel Blais
Administrateur réseau
Targo communications
2015-05-14 14:44 GMT-04:00 Claudio Jeker :
> On Thu, May 14, 2015 at 02:21:41PM -0400, Michel Blais wrote:
> > Thanks Henning for answering,
> >
> > While using nexthop, I s
he're something else or it seem like a problem
on the carrier side ?
2015-05-10 14:37 GMT-04:00 Henning Brauer :
> * Michel Blais [2015-05-07 17:59]:
> > I have 2 BGP peer from different provider (AS5769 and AS22652). It's
> happen
> > 2 times that I was not abl
I know, I must update but unless it's a know bug and was fix on >= 5.5, I
would really like to understand why this is happening.
I have 2 BGP peer from different provider (AS5769 and AS22652). It's happen
2 times that I was not able to ping my neighbor ($peervid1) at AS5769
connected to em1 but st
I have often use Lanner FW-7535 with OpenBSD and like them a lot. Buy them
from LEI Technologie in Canada for 375$. Lanner product are good stuff,
really professionnal. I also Lanner product for customer PBX, unifi
controler, etc.
2013/10/21 emigrant
> min. 3xNICs: wan, lan, pfsync. Hmm 6xNIC
Intel 64 bit is amd64 compatible.
*De: *Jash Sefferson
*Envoyé: *lundi 1 juillet 2013 00:08
*À: *misc@openbsd.org; s...@openbsd.org
*Répondre à: *Jash Sefferson
*Objet: *OpenBSD Doesn't Support 64-Bit Intel
Hi guys.
Im a civil engineer by day and use OpenBSD at night, but Im trying to do
gets underway.
> On Thu, May 9, 2013 at 3:58 AM, Michel Blais
> wrote:
> > Not sure if it's worth the effort since RSPro are not produced anymore.
> It
> > was replaced by Edgerouter Lite. Dev are already working on this one.
> > http://www.openbsd.or
I never tryed on OpenBSD but mFi from Ubnt is cheap and the software is
compatible with Unix.
*De: *rafaello konfekte
*Envoyé: *jeudi 9 mai 2013 07 h 30 min 18 s EDT
*À: *misc@openbsd.org
*Répondre à: *rafaello konfekte
*Objet: *USB temperature sensors
Could you share your exper
so I'll post it wherever, if you want it.
In fact, if anybody is interested in porting to this, I'll probably
happily buy you
the routerstation "pro" board, too (which FreeBSD also supports).
Please CC me, as I'm not subscribed.
Cordialement / B
For the anchor removed if not persistent, I have already writed about
this. The answer from Henning :
Le 2013-03-13 14:15, Maxim Khitrov a écrit :
On Wed, Mar 13, 2013 at 1:59 PM, Michel Blais wrote:
I think you must specify th
, Maxim Khitrov a écrit :
On Wed, Mar 13, 2013 at 1:59 PM, Michel Blais wrote:
I think you must specify the anchor first. Something like :
pfctl -a ix1 -t admins -T show
That doesn't work. First, it's an unnamed anchor, so I don't think you
can specify it with the -a option.
- Max
Cordialement / Best regards
Michel Blais
Administrateur réseau / Network administrator
Targo Communications
Even a 5501 or Alix would probably be enough for that quantity of user.
If your in north america, you should look lanner fw-7535 that cost less
than a net6501-70. It's a great router and lanner have a really good
customer support, one of the best I have seen.
/etc/pkg.conf to reflect it.
2013/1/9 Michel Blais :
The're 2 package I'm not able to install.
# uname -a
OpenBSD myhostname.mydomain.com 5.2 GENERIC.MP#8 amd64
# pkg_add nano
Can't install libiconv-1.14 becau
The're 2 package I'm not able to install.
# uname -a
OpenBSD myhostname.mydomain.com 5.2 GENERIC.MP#8 amd64
# pkg_add nano
Can't install libiconv-1.14 because of libraries
|library c.65.0 not found
| /usr/lib/libc.so.66.0 (system): bad major
Can't install gettext-0.18.1p3: can't resolve lib
now if it can help but when I saw this, I remebered this thread and
thinked it could be good to share the information if somebody want to
try to port it.
Le 2012-09-19 16:32, Michel Blais a écrit :
I think Stig is in charge of the EdgeOS software developement.
mbre 2012 à 22:36 +, Stuart Henderson a écrit :
> On 2012-12-17, Michel Blais mailto:mic...@targointernet.com>> wrote:
> > # cat /etc/hostname.carp0
> > inet W.X.Y.B W.X.Y.D vhid 1 carpdev em0 \
I'm testing carp for the first time on 5.2 (both) and no mather
what I try, both are master. I see the traffic from carp with
tcpdump on both device. Must be a RTMF error but I already
readed all official doc and some unofficial and still can't find
what wrong.
The config of both device is f
I have one Jetway board in production with 5.0 with intel daughterboard
work fine but it's only 3 intel NIC so would have to use one realtek. I
didn't try realtek NIC with lot of traffic.
I now use Lanner FW-7535 instead. Cost a little more but like them
better and Lanner service is great. Ato
Nothing wrong, I normally use bind so I just didn't think of make each
service listen at different address. Double face palm at myself lol.
Thanks Stuart, that what I will do.
Le 2012-10-30 19:23, Stuart Henderson a écrit :
What's wrong with binding NSD to one IP address for authoritat
Le 2012-10-26 06:48, Martin Pelikan a écrit :
2012/10/25 Michel Blais :
I'm trying to make unbound have less timeout query (I see around1 to 2%
of query timeout using DNS performance test from Silverwolf Software
and was looking at "Unbound : Howto optimise"
and wanted to tr
I'm trying to make unbound have less timeout query (I see around1 to 2%
of query timeout using DNS performance test from Silverwolf Software
and was looking at "Unbound : Howto optimise"
and wanted to try the so-rcvbuf option but enabling it cause a error on
service start.
On BSD change |kern
Le 2012-09-27 10:19, Russell Garrison a écrit :
Definitely OT, but I second the FW-7535. Good gear and Lanner is easy
to work with direct even for small projects.
Same with LEI technologie, the're division in Canada.
Michel Blais
Administrateur réseau / Network
First, it would be better to start a new subject if it's not related to
the original post.
Squid need lot of disk space to be efficient and write a lot on the
disk, same for samba. I would not install those on a compact flash.
Maybe something like a Lanner FW-7535 would be better. Those suppo
I think Stig is in charge of the EdgeOS software developement.
Agreed, but the fact it uses an OS which uses the kernel Linux is
encouraging, though GPL source code is pretty much useless to a
BSD-licensed project from a documentation standpoint. We have
i.e., something I could print for them would be best) them
my system is up to date and that all patches have been applied???
Thank you,
Michel Blais
Administrateur réseau / Network administrator
Targo Communications
Oups, didn't saw that Trd answered. Sorry for the noise.
Le 2012-09-14 13:49, Michel Blais a écrit :
LOL, when I started on OpenBSD, I created a bug report about this. Dev
want it this way, the're must be a reason to it but since it's not
standard, the must also expect question
The invoked shell is the target
This is the traditional behavior of su
Running "su -l" works good.
Why if user ID is == 0 or if there's no -l, the $USER will not be set?
What is the policy?
I've tried this also on OpenBSD 4.9 with same result.
Thanks in advance.
Le 2012-09-13 11:34, Michel Blais a écrit :
Also, is it a pfctl limitation to not be able to use it on anchor
inside a other anchor or I'm missing something ? Exemple, I load a
anchor in main ruleset named A and in A, I load a other anchor named
B. Is there any way to use pfctl on B a
I just encounter a stange biavior with the bi-nat rules. Since we optimize
our firewall script via multiple anchor for our thousand of bi-nat rule, we
don't use the bi-nat rule but instead use the 2 rules in different anchor.
anchor out on $ext_if from {
anchor ou
take advantage of the
hardware acceleration.
Michel Blais
Administrateur réseau / Network administrator
Targo Communications
Le 2012-09-11 09:59, James Shupe a écrit :
Not from within Europe,
Not build in europe but this link was the europe shop so it answer the
original question.
is still mostly relevant.
Great article. Thanks for the link and also for the other tips.
Le 2012-09-11 05:38, Shaka Nkofo a écrit :
I found this shop while looking for parts to build a home router. Has
anyone been through this and can give me links to cheap parts within Europe?
Any advise on the pitfalls of this process is welcome
Le 2012-09-04 13:52, Claudio Jeker a écrit :
On Tue, Sep 04, 2012 at 10:16:41AM -0400, Michel Blais wrote:
I've build a Xeon E3 with Intel i340 ethernet with 82580 chip.
CPU is use up to 24% on the first core, congestion is now at 0.3/s.
I still see drops in net.inet.ip.ifq.drops. 1131
of the rule, is there any doc on how to optimise the order
of the rule order for best performance ? I was also not able to
find anything about this.
Le 2012-08-30 09:57, Michel Blais a écrit :
Le 2012-08-30 08:59, Ryan McBride a écrit :
On Wed, Aug 29, 2012 at 12:54:18PM -0400,
Le 2012-08-30 08:59, Ryan McBride a écrit :
On Wed, Aug 29, 2012 at 12:54:18PM -0400, Michel Blais wrote:
How much can I increase net.inet.ip.ifq.maxlen ?
I'm now at 2048 and still seeing increase in net.inet.ip.ifq.drops.
This morning, it was at 21280 and now at 21328.
A little b
Are those related ?
Le 2012-08-29 17:08, Michel Blais a écrit :
> Oups, sorry. It's OpenBSD 5.0, not 5.1.
> Le 2012-08-29 17:05, Michel Blais a écrit :
>> I have both latency and paquet drop problem on 5.1 on card using
>> em(4). Tryed bo
Oups, sorry. It's OpenBSD 5.0, not 5.1.
Le 2012-08-29 17:05, Michel Blais a écrit :
I have both latency and paquet drop problem on 5.1 on card using
em(4). Tryed both 82571EB and 82546GB. It was worst with 82546GB.
Mailing list subject :
WARNING: mclpools limit reached; inc
rev 1.00/1.00 addr 1
isa0 at ichpcib0
isadma0 at isa0
com0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
nd building new server and now
the congestion have dropped from 3.9 to 0.8.
Something I must specify, I use bi-nat to save public ip address and
have thousand of bi-nat rule divided in some anchors.
Le 2012-08-19 08:21, Stuart Henderson a écrit :
On 2012-08-14, Michel Blais
, 2012 at 9:12 PM, Michel Blais wrote:
seem like I have type the wrong command by mistake using tab to complet the
command. Don't know which command it was but I add a lot of output like this
Faulted ikernel: double fault trap, code=0
kernel: double fault trap, code=0
Faulted in DDB; conti
Hi misc,
seem like I have type the wrong command by mistake using tab to complet
the command. Don't know which command it was but I add a lot of output
like this :
Faulted ikernel: double fault trap, code=0
kernel: double fault trap, code=0
Faulted in DDB; continuing...
--db_more--kernel: t
src-limit 00.0/s
synproxy 00.0/s
Le 2012-08-14 11:39, Michel Blais a écrit :
I juste found how to get the boot dmesg :
# cat
modifier keys, 6 key codes
wskbd1 at ukbd0 mux 1
wskbd1: connecting to wsdisplay0
uhidev1 at uhub1 port 1 configuration 1 interface 1 "Dell DRAC4" rev
1.10/0.00 addr 2
uhidev1: iclass 3/1
ums0 at uhidev1: 3 buttons, Z dir
wsmouse0 at ums0 mux 0
vscsi0 at root
scsibus4 at vscsi0: 256 targets
Hi misc,
I got a little error here with a sysctl value in dmesg :
WARNING: mclpools limit reached; increase kern.maxclusters
The value was at 6144 and I just change it to 9216 (50% more)
The system is also having paquet lost from 1 up to 6% and can have
latency up to 30 ms and changing the val
Le 8 juin 2012 14:01, "Chris Smith" a écrit :
> ... if you really want a firewall you need pfSense.
> Also if you " walk into any security experts convention and claim that
> raw OpenBSD is "a firewall", you will get laughed out of the room for
> lack of clue."
> Guess I've been wrong a
OpenBSD 5.1-beta (GENERIC) #140: Sat Jan 21 00:40:23 MST 2012
I believe it would be an improvement if pfctl refused
to load a ruleset that refers to nonexistent tables.
Michel Blais
Administrateur riseau / Network
ther 2 are the load balancers behind the WAN router.
Looking at reducing it to 2 machines, though.
Hardware capability is my main consideration currently.
I want something adequette for 100Mbps.
Michel Blais
Administrateur riseau / Network administrator
Targo Communications
From pf.conf (5)
The packet is matched. This mechanism is used to provide fine
grained filtering without altering the block/pass state of a
Le 20 avril 2012 20:42, Martin Pelikan a icrit :
> On Tue, Apr 17, 2012 at 10:51:31AM -0400, Michel Blais wrote:
>> rule inside of a in bracket anchors, pf will see no rule using the table
>> and delete it. As a work around, I use persist option.
> I don't kno
I'm using 5.0 and I saw a strange behavior with table and in bracket anchor.
From my test, in bracket anchor can't have tables inside of them and
are using the main ruleset tables but if I create a table only use by
rule inside of a in bracket anchors, pf will see no rule using the table
and d
Thanks Andres for the answer.
Le 2012-04-12 22:30, Andres Perera a C)crit :
On Thu, Apr 12, 2012 at 9:25 PM, Michel Blais wrote:
Just saw something strange with inline anchor rule and macro :
if I set a anchor rule with a macro inside of it and do pfctl -vnf, only the
Just saw something strange with inline anchor rule and macro :
if I set a anchor rule with a macro inside of it and do pfctl -vnf, only
the first value of the macro seem to have the anchor rule following.
Every other value will be without bracket and anchor rules.
Exemple :
in the pf.conf
Thanks a lot. It's working fine.
Le 2012-04-12 18:07, Jeremy Evans a icrit :
On Thu, Apr 12, 2012 at 3:00 PM, Michel Blais wrote:
I've read both pf anchor faq and pf.conf man page for 5.0 and my syntax seem
but I always get a error while trying to use ` in line a
I've read both pf anchor faq and pf.conf man page for 5.0 and my syntax
seem right
but I always get a error while trying to use ` in line anchor. The
anchor line and
closing bracket line both give me the syntax error with pfctl -vnf
I tryed with and without anchor name. Here
Oups, sorry for this. I sended it to the wrong address.
Le 2012-04-10 12:06, Michel Blais a icrit :
1<1 ms<1 ms<1 ms
2 5 ms 2 ms 2 ms
3 5 ms 3 ms 8 ms
4 5 ms 6 ms 4 ms
5 4 ms 5 ms
1<1 ms<1 ms<1 ms
2 5 ms 2 ms 2 ms
3 5 ms 3 ms 8 ms
4 5 ms 6 ms 4 ms
5 4 ms 5 ms 5 ms
6 5 ms 5 ms 4 ms
7 5 ms 4 ms 6 ms 207.253.
Anyone had a look at Qualcomm collaboration summit to kill proprietary
drivers ? I'm supprised I didn't see any mail about this.
Hi Stuart,
You we're right. It's working fine now with pwd.db and passwd was not needed.
Le 4 avril 2012 20:46, Stuart Henderson a icrit :
> On 2012-04-04, Kevin Chadwick wrote:
>> On Wed, 04 Apr 2012 18:08:37 -0400
>> Michel Blais wrote:
18:45, Kevin Chadwick a icrit :
> On Wed, 04 Apr 2012 18:08:37 -0400
> Michel Blais wrote:
>> I have create a chroot with scp and needed library for it but when I try
>> to copy a file with scp, I always get the error "unknown user UID" after
>> succefully en
I have create a chroot with scp and needed library for it but when I try
to copy a file with scp, I always get the error "unknown user UID" after
succefully entering the password. I can't find anything for this error
exept for Linux. There also nothing in authlog, only successful
Also add to search this one when i beggined on openbsd.
I think that in route(8), it should be writen that persistent route must be
add in hostname.if. No where in route(8) there a link to hostname.if(5),
not even in files.
Le 20 janv. 2012 09:57, "Hendrickson, Kenneth" a
icrit :
> Thanks
> --
Check the command line section
Le 20 janv. 2012 09:36, "Hendrickson, Kenneth" a
icrit :
> +--+
> | Firewall |
> | | .
> | vr0dhcpd | | | | | Wir
RB750GL use the sames CPU and ethernet switch as RB450G and Ubiquiti
Routerstation Pro. The big difference is that RB750GL have 2 ethernet
switch instead of 1.
I know that RSPro is support by FreeBSD and if I remeber well, I read on
this list that it could easily be port to OpenBSD.
If one o
ehci0 at pci0 dev 21 function 1 "AMD CS5536 USB" rev 0x02: irq 15
usb0 at ehci0: USB revision 2.0
uhub0 at usb0 "AMD EHCI root hub" rev 2.00/1.00 addr 1
isa0 at glxpcib0
isadma0 at isa0
com0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
com0: console
com1 at isa0 port
I can't really find anything explaning these error except that some said
that you never want it to happen and Henning writing that it could be
ignore in some case. In my case, I think I should ignore it but would
like to understand it just to be sure.
pf: state key linking mismatch! dir=
You could use macro instead of table for port.
2011/12/8 John Tate
> Misc,
> I have sucessfully got an OpenBSD machine to connect via ADSL and forward
> packets, I am gradually upgrading my pf.conf. I am having trouble with this
> configuration (ignore some obvious bugs related to tabl
ild by our self there is a
full set of images ready to put on a USB memory stick or Flash card
Best regards Flashboot team
Michel Blais
Administrateur riseau / Network administrator
Targo Communications
oct. 2011 17:27, "Stuart Henderson" a icrit :
> On 2011/10/21 17:01, Michel Blais wrote:
> > This is for a firewall and main gateway of my network.
> > Is a atom dual core cpu 1.6 Ghz with 2 Go or RAM
> > It have 2 realtek onboard nic but since I wanted Intel NIC, I a
2011/10/21 Michel Blais
> This is for a firewall and main gateway of my network.
> Is a atom dual core cpu 1.6 Ghz with 2 Go or RAM
> It have 2 realtek onboard nic but since I wanted Intel NIC, I added a 3
> intel NIC optional board.
> em0 is use to connect to my ISP fiber li
On Fri, Oct 21, 2011 at 9:46 AM, Michel Blais
> wrote:
> > really look like a sysctl limit, tcpdump give me lot of packets dropped
> > by kernel.
> > I commented every block rule to be sure it was not a rules mistake in pf
> >
> > pfctl -vnf /etc/pf.conf without
se value 2 time x2 :
my actual size :
# sysctl net.bpf.bufsize=8388608
net.bpf.bufsize: 4194304 -> 8388608
# sysctl net.bpf.maxbufsize=16777216
net.bpf.maxbufsize: 8388608 -> 16777216
Still the same. Anything else that could make kernel drop paquets ?
Le 2011-10-21 11:46, Mich
sysctl kern.seminfo.semmni=1024
sysctl kern.seminfo.semmns=4096
sysctl kern.shminfo.shmmax=67018864
sysctl kern.shminfo.shmall=32768
The're now a lot less paquet lost but speed test is as much slow.
Any idea ?
Le 2011-10-21 10:42, Michel Blais a icrit :
> I got a
I got a problem with snapshot (not shure if it's the last),
download is really slow, 0.3 to 1 Mbps per customent.
Also a lot of paquet lost beginning from the openbsd.
The're around 800 to 1000 users on this server.
Bandwith is not a problem but we often saw limitation in number
of paquets be the p
the traffic that is passing throught the default
> queue of pf ?
> Thanks for your ideeas.
Michel Blais
Administrateur rC)seau / Network administrator
Targo Communications
I know cacti can do graph from data and it should be possible to build it on
Le 13 oct. 2011 20:10, "Stefan N" a icrit :
> Hi Erling,
> Thanks. I will try and test it.
> Regards,
> Stefan
> From: Erling Westenvik
> To: Stefan N
> Sent:
> Friday,
What some fear is that some Microsoft OEM partner do a lazy job with a
minimal UEFI interface without the possibility to disable secure boot.
In that case, if secure boot block unsigned os at boot, it would be
impossible to install other os than Windows 8.
I have too often see BIOS missing lot
if I try with no state :
pass out on $ext_if from queue second no state
it won't shape ip added to into the queue, the will be
shaped by the default queue instead.
Any idea ? Should I report a bug ?
Le 2011-09-14 15:20, Michel Blais a icrit :
this follow my previous
The're also proxmox ve that is really nice for virtualisation.
this follow my previous posts with subject : "pf shape download"
that I now solved.
The following test where done on OpenBSD 4.9, 5.0 snapshot of
12/09/2011 & FreeBSD 8.2 (include PF from OpenBSD 4.2 if I
remeber well). All add the same behavior. I didn't test current
(but the snapshot was p
But if I try to shape again by adding it to
second tab, I must restart my download again.
Is it normal or a behaviure ?
Le 2011-09-07 17:25, Michel Blais a icrit :
Hi all,
thanks for your help and tips.
I have do some testing when I add some free time.
I finally got it worki
Simply because I always runned final release for server and gateway. Habit
taken from linux even if some use arch or testing for debian.
I'm new to openbsd and freebsd that i used for some month (maybe even a
year) also seem to recommend final release. Should we really use current for
gateway in p
Hi all,
thanks for your help and tips.
I have do some testing when I add some free time.
I finally got it working by creating the queue on my internal
if (now em1 instead of re1)
altq on $int_if hfsc bandwidth 97Mb qlimit 500 queue { main, second }
queue main on $int_if bandwidth 1Mb qlimi
2011-08-22 18:40, David Newman a icrit :
Did you have any luck getting this working?
On 8/16/11 8:20 AM, Michel Blais wrote:
I'm having a problem to shape download with PF. I have 2 HFSC queue
(main and second) created on my internal NIC. Main is my default
queue. If I
I'm having a problem to shape download with PF. I have 2 HFSC queue
(main and second) created on my internal NIC. Main is my default
queue. If I try to match download traffic to the second queue, it still
go trought the main queue.
The IP I want to download trought the second queue for my te
rev 1.10/3.06 addr 2
uhidev0: iclass 3/1
ukbd0 at uhidev0: 8 modifier keys, 6 key codes
wskbd1 at ukbd0 mux 1
wskbd1: connecting to wsdisplay0
vscsi0 at root
scsibus1 at vscsi0: 256 targets
softraid0 at root
root on wd0a swap on wd0b dump on wd0b
Le 2011-07-31 17:03, Rogier Krieger a icrit :
Do you
nnect 1 NIC again, the
four NIC are still configure when I rebot the system.
Strange. I will try to reproduce it on a other system, I must build a
other one for carp redondancy.
Anyway, thanks
Le 2011-07-27 11:04, Michel Blais a icrit :
I'm new to OpenBSD (exprience with
I'm new to OpenBSD (exprience with Linux and FreeBSD) and I'm trying to
configure a second NIC at boot without result.
The OpenBSD version is 4.9.
This NIC name is re1 so I created the file /etc/hostname.re1 with the
following in :
If use netstart to c
91 matches
Mail list logo