Oddities with connmark

2018-09-16 Thread Алексей Болдырев
Actually, there is a suricata with the following rules: #pass tls any any -> any any (pcre: "/play.google.com/i"; tls_sni;nfq_set_mark:0x8/0x; sid:2466;) #pass tls any any -> any any (pcre: "/google.com/i"; tls_sni;nfq_set_mark:0x8/0x; sid:2465;) #pass tls any any -> any any (pcr

Packet corrupts to guest system system from host kernel 4.16.x

2018-04-05 Thread Алексей Болдырев
Why, when using the 4.16 kernel on the host system, is there such a strange behavior of virtual machines? What is the problem? He rolled back to 4.9.c - the problem was gone. tcpdump on router: tcpdump: listening on vlan-00110013, link-type EN10MB (Ethernet), capture size 262144 bytes 23:59:08.

MPLS-TP From Linux

2018-01-19 Thread Алексей Болдырев
Please tell me if the MPLS-TP implementation in Linux is being implemented? RFC: https://tools.ietf.org/html/rfc5654

Multicast MPLS is Linux

2017-12-16 Thread Алексей Болдырев
Tell me please, when in linux is planned the realization of multicast MPLS? Etnernet Tipe: 0c8848

Module compile error

2017-12-10 Thread Алексей Болдырев
CC [M] drivers/net/ethernet/intel/ixgbe/ixgbe_main.o In file included from ./include/net/vxlan.h:6:0, from drivers/net/ethernet/intel/ixgbe/ixgbe_main.c:60: ./include/net/dst_metadata.h: In function ‘skb_vpls_info’: ./include/net/dst_metadata.h:36:9: error: implicit declaration o

David Lamparter

2017-12-07 Thread Алексей Болдырев
And what happened to him?

VPLS Support

2017-12-05 Thread Алексей Болдырев
Hello, when will VPLS be implemented in Linux? August 15, 2017 were patches from ekoinoks, which in Linux added support for VPLS. But, these patches for some reason did not pass. Also, for some reason, the author of these patches has no activity on, for two months. I think so, if activity does n

VPLS in Linux

2017-10-31 Thread Алексей Болдырев
When will support for VPLS appear in Linux? 08/21/2017 David Lamparter has already sent these patches, but they are not in the kernel for some reason, not populi. Such question, when all the same these patches will get to a kernel? Here is a link to this email: https://www.mail-archive.com/net

VPLS in Linux

2017-10-13 Thread Алексей Болдырев
There was a message with patches of VPLS in the Linux kernel. But they somehow did not fall into the next. What about the development of the Linux subsystem in Linux?

https://www.spinics.net/lists/kernel/ non work

2017-08-15 Thread Алексей Болдырев
Forbidden You don't have permission to access /lists/kernel/ on this server. Apache/2.4.6 (CentOS) Server at www.spinics.net Port 443

iproute2 invalid argument mpls labels

2017-08-15 Thread Алексей Болдырев
I updated the kernel 4.12.6. When the mote is hung on the route more than 8 mpls of marks through iproute2, I get the following: root@ne-vlezay80:~# ip route add 10.10.10.0/24 encap mpls 50/60/70/80/90/100/110/120/130 dev lo RTNETLINK answers: Invalid argument root@ne-vlezay80:~# ip route add 1

Linux MPLS traceroute failure

2017-08-12 Thread Алексей Болдырев
Testing MPLS from Linux kernel 4.12. The trace route is duplicete pe-p hop. This is not visible MPLS label on traceroute. root@ne-vlezay80:~# traceroute -e 10.10.10.4 traceroute to 10.10.10.4 (10.10.10.4), 30 hops max, 60 byte packets 1 10.5.5.1 (10.5.5.1) 0.028 ms 0.005 ms 0.006 ms 2 10.4

Re: MPLS Pseudowire (RFC3985) linux kernel support and development

2017-07-06 Thread Алексей Болдырев
As I understand it, the patch will be available in the linux kernel or as a separate application based on tap? 06.07.2017, 16:21, "Vincent JARDIN" : > Le 06/07/2017 à 11:13, Алексей Болдырев a écrit : >>  Is there any plan for developing mpls pseudowire dliver for linux.

MPLS Pseudowire (RFC3985) linux kernel support and development

2017-07-06 Thread Алексей Болдырев
Is there any plan for developing mpls pseudowire dliver for linux. And also, is it possible to write a driver for MPLS pseudowire on the basis of tun / tap?

veth: проблемы со скоростью

2017-06-10 Thread Алексей Болдырев
Короче, имеем ядро 4.11.4. При передаче данных через veth, мы получаем скорость примерно такую: root@containers:~# iperf3 -c 10.194.1.3 Connecting to host 10.194.1.3, port 5201 [ 4] local 10.194.1.2 port 55640 connected to 10.194.1.3 port 5201 [ ID] Interval Transfer Bandwidth

BUG: Bad page state in process Compositor pfn:c03e2

2017-06-09 Thread Алексей Болдырев
[ 1621.875870] BUG: Bad page state in process Compositor pfn:c03e2 [ 1621.875876] page:ea000300f880 count:-1 mapcount:0 mapping: (null) index:0x0 [ 1621.875878] flags: 0x100() [ 1621.875881] raw: 0100 [ 1621.875882] ra

Re: Maximum MPLS labels on Linux network stack

2017-05-03 Thread Алексей Болдырев
As I understand it, it's enough to just set the variable in the source #define FLOW_MAX_MPLS_LABELS 3 on #define FLOW_MAX_MPLS_LABELS 7 Or is there somehow still pitfalls? 04.05.2017, 00:22, "Joe Stringer" : > On 3 May 2017 at 14:19, Алексей Болдырев > wrote: >>  Is i

Re: Maximum MPLS labels on Linux network stack

2017-05-03 Thread Алексей Болдырев
Is it possible to increase this limit in OpenVswitch? 03.05.2017, 23:21, "Joe Stringer" : > On 3 May 2017 at 11:14, David Ahern wrote: >>  On 5/3/17 11:33 AM, Алексей Болдырев wrote: >>>  I watched one forum, there is listed in the properties of one lic

Maximum MPLS labels on Linux network stack

2017-05-03 Thread Алексей Болдырев
I watched one forum, there is listed in the properties of one license for Cisco, it says: Layer 3 VPN • Multi-VRF CE (VRF-lite); requires IP Services Feature license • MPLS VPN; requires Advanced IP Feature license • 26 VRFs • 8192 MPLS labels Especially interested in the figure 8192 MPLS Label

Low speed MPLS to virtio-net

2017-04-26 Thread Алексей Болдырев
Started MPLS on the branch - Everything was fine. When I tried to run MPLS on a real network of virtual machines, there were problems with the speed: root@containers:~# iperf3 -c 10.194.10.2 -B 10.194.10.1 -Z Connecting to host 10.194.10.2, port 5201 [ 4] local 10.194.10.1 port 49533 conne

Re: Bug and configuration MPLS error?

2017-04-26 Thread Алексей Болдырев
26.04.2017, 05:23, "David Ahern" : > On 4/25/17 11:28 AM, Алексей Болдырев wrote: >>  226 sysctl -w net.mpls.conf.lo.input=1 >>  227 sysctl -w net.mpls.platform_labels=1048575 >>  228 ip link add veth0 type veth peer name veth1 >>  229 ip link add veth2 typ

Bug and configuration MPLS error?

2017-04-25 Thread Алексей Болдырев
Короче, вот конфиг MPLS на одном из дистрибутивов: In short, here's the MPLS configuration on one of the distributions: 226 sysctl -w net.mpls.conf.lo.input=1 227 sysctl -w net.mpls.platform_labels=1048575 228 ip link add veth0 type veth peer name veth1 229 ip link add veth2 type veth peer name vet