Re: problems with carp and vlans

2006-04-21 Thread Lars Weste
OTECTED]>, misc@openbsd.org > Betreff: Re: problems with carp and vlans > Datum: Thu, 20 Apr 2006 18:07:40 +0200 > > On Thu, Apr 20, 2006 at 05:42:20PM +0200, Otto Moerbeek wrote: > > > > On Thu, 20 Apr 2006, Lars Weste wrote: > > > > > Hi, > > > &

Re: problems with carp and vlans

2006-04-20 Thread Marco Pfatschbacher
On Thu, Apr 20, 2006 at 05:42:20PM +0200, Otto Moerbeek wrote: > > On Thu, 20 Apr 2006, Lars Weste wrote: > > > Hi, > > > > yes, i am running 3.8 -stable, and the backup has a higher advbase than > > err, for preemption to work, the advskew should be higher on the backup. > At least, that is w

Re: problems with carp and vlans

2006-04-20 Thread Otto Moerbeek
terfaces, or whether there is some new feature, that will do the trick. > > lars > > > --- Urspr|ngliche Nachricht --- > > Von: Marco Pfatschbacher <[EMAIL PROTECTED]> > > An: Lars Weste <[EMAIL PROTECTED]> > > Kopie: misc@openbsd.org > > Betreff

Re: problems with carp and vlans

2006-04-20 Thread Lars Weste
isc@openbsd.org > Betreff: Re: problems with carp and vlans > Datum: Thu, 20 Apr 2006 15:01:30 +0200 > > Hi, > > did you remember to configure the backup machine > with a higher advskew / advbase? > Are you running -stable? > > I'm not aware of any other problems

Re: problems with carp and vlans

2006-04-20 Thread Marco Pfatschbacher
Hi, did you remember to configure the backup machine with a higher advskew / advbase? Are you running -stable? I'm not aware of any other problems in 3.8 that might cause this. On Wed, Apr 19, 2006 at 08:59:01AM +0200, Lars Weste wrote: > Hi, > > I have some problems with carp

Re: Keep carp interfaces in sync, WAS: problems with carp and vlans

2006-04-20 Thread Lars Weste
Hi, >> with scrub in all set at the firewall, will openbsd handle icmp packets >> of type unreach code needfrag automatically, because of the statefulness? >> as far as i know, icmp packtes like port/host/network unreachable are >> allowed by the keep state statements, does this also apply for

Re: Keep carp interfaces in sync, WAS: problems with carp and vlans

2006-04-20 Thread Lars Weste
Hi, >> hostname.carp2 >> !ifconfig bge0 up >> !ifconfig vlan0 create >> !ifconfig vlan0 vlan 3 vlandev bge0 up >> vhid 1 carpdev vlan0 192.168.0.1 192.168.1.255 netmask 255.255.254.0 > I use the seperate hostname.if files instead of loading raw ifconfig > commands. /etc/netstart does start physic

Re: Keep carp interfaces in sync, WAS: problems with carp and vlans

2006-04-19 Thread Jon Simola
On 4/19/06, Lars Weste <[EMAIL PROTECTED]> wrote: > hostname.carp2 > !ifconfig bge0 up > !ifconfig vlan0 create > !ifconfig vlan0 vlan 3 vlandev bge0 up > vhid 1 carpdev vlan0 192.168.0.1 192.168.1.255 netmask 255.255.254.0 I use the seperate hostname.if files instead of loading raw ifconfig comm

Re: Keep carp interfaces in sync, WAS: problems with carp and vlans

2006-04-19 Thread Lars Weste
> > Try a 3.9 kernel and 3.9 ifconfig binary and see what happens > i'm using 3.9-current from the snapshots right now to great effect > > Lars Weste [EMAIL PROTECTED] wrote: > > Hi, > > > > I have some problems with carp and vlans, at least I

problems with carp and vlans

2006-04-19 Thread Lars Weste
Hi, I have some problems with carp and vlans, at least I think so. I found this: http://archives.neohapsis.com/archives/openbsd/cvs/2005-04/0996.html so my assumption may be wrong, as I use openbsd 3.8. I have four physical interfaces in my two firewalls, one for pfsync, one to the Internet