autofs and ssh fail over ipsec tunnel
by David A. De Graaf
I use an ipsec tunnel to connect my LAN (192.168.2.h) in North
Carolina to my son's LAN (192.168.1.h) in Maryland. We each have a
primary machine that manages the ipsec tunnel and several secondary
machines. Static routing tables direct traffic for the remote LAN to
the local primary machine and thence through the tunnel.
Cross-referenced DNS tables effectively join the two LANs as one.
We expect all the usual network tools (autofs/nfs, ssh, rsync, etc.)
to work thru the tunnel.
Recently we've noticed that autofs/nfs and ssh don't work between
a secondary machine and any remote machine.
Autofs/nfs and ssh work perfectly between the primaries.
Ping works perfectly between all machines, primary or secondary.
For autofs the key subfunction seems to be rpcinfo.
From the primary (datium) to the remote primary (octopus)
'rpcinfo -p name' yields good data:
# rpcinfo -p octopus
program vers proto port service
100000 4 tcp 111 portmapper
100000 3 tcp 111 portmapper
100000 2 tcp 111 portmapper
100000 4 udp 111 portmapper
100000 3 udp 111 portmapper
100000 2 udp 111 portmapper
100005 1 udp 20048 mountd
100005 1 tcp 20048 mountd
100005 2 udp 20048 mountd
100005 2 tcp 20048 mountd
100005 3 udp 20048 mountd
100005 3 tcp 20048 mountd
100024 1 udp 35631 status
100024 1 tcp 58519 status
100003 3 tcp 2049 nfs
100003 4 tcp 2049 nfs
100227 3 tcp 2049 nfs_acl
100021 1 udp 47742 nlockmgr
100021 3 udp 47742 nlockmgr
100021 4 udp 47742 nlockmgr
100021 1 tcp 35983 nlockmgr
100021 3 tcp 35983 nlockmgr
100021 4 tcp 35983 nlockmgr
But from a secondary to the remote primary it fails:
# rpcinfo -p octopus
octopus: RPC: Port mapper failure - Unable to receive: errno 113 (No
route to host)
Similarly, for ssh the basic test seems to be telnet <name> 22.
From primary to primary it works correctly:
# telnet octopus 22
Trying 192.168.1.2...
Connected to octopus.
Escape character is '^]'.
SSH-2.0-OpenSSH_7.4
But from a secondary to the remote primary, it fails:
# telnet octopus 22
Trying 192.168.1.2...
telnet: connect to address 192.168.1.2: No route to host
In both failures the complaint is "No route to host", but clearly
there is a route to the host, because ping works:
# ping octopus
PING octopus.dino.lan (192.168.1.2) 56(84) bytes of data.
64 bytes from 192.168.1.2 (192.168.1.2): icmp_seq=1 ttl=63 time=107 ms
From router.datix.lan (192.168.2.1): icmp_seq=2 Redirect Host(New
nexthop: datium.datix.lan (192.168.2.2))
64 bytes from 192.168.1.2 (192.168.1.2): icmp_seq=2 ttl=63 time=45.1 ms
From router.datix.lan (192.168.2.1): icmp_seq=3 Redirect Host(New
nexthop: datium.datix.lan (192.168.2.2))
64 bytes from 192.168.1.2 (192.168.1.2): icmp_seq=3 ttl=63 time=85.2 ms
From router.datix.lan (192.168.2.1): icmp_seq=4 Redirect Host(New
nexthop: datium.datix.lan (192.168.2.2))
64 bytes from 192.168.1.2 (192.168.1.2): icmp_seq=4 ttl=63 time=80.4 ms
^C
--- octopus.dino.lan ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3002ms
rtt min/avg/max/mdev = 45.154/79.682/107.905/22.475 ms
Each LAN has a router that connects to the internet.
All LAN machines use the router's IP for the default gateway.
In the router is a static route that sends packets destined for the
remote LAN back to the primary machine that handles the ipsec tunnel.
What's the problem here? Why is ping more clever in finding the
route?
Any advice or insight gratefully received.
--
David A. De Graaf DATIX, Inc. Hendersonville, NC
dad(a)datix.us www.datix.us
6 years, 6 months
Upgrade from f19
by Eyal Lebedinsky
[resend, never saw the first one]
I have a server running f19 (don't ask). It is heavily customised so I prefer
to not do a fresh install of f26 and reconfigure everything.
I am reading the upgrade guide at
https://fedoraproject.org/wiki/Upgrading?rd=Upgrade
which says (Upgrading from End of life releases).
"If you have Fedora 20 or earlier, you will have to perform at least
part of the upgrade with bare yum. You can either use that method to upgrade to Fedora 21 or later"
My plan is to do this
f19 -> f21 (yum)
following https://fedoraproject.org/wiki/Upgrading_Fedora_using_package_manager
f21 -> f26 (DNF system upgrade)
I suspect that attempting to go directly to f26 may be a bridge too far.
I will check and clean the system before/after each step.
Beyond the listed "common problems", is there any reason to not follow this path?
Is there a better way?
TIA
--
Eyal Lebedinsky (fedora(a)eyal.emu.id.au)
6 years, 6 months
vi
by Patrick Dupre
Hello,
How can I keep stored the commands of vi from call to call?
cf.
1,$s/ //
I would like to have it back next time that I edit other file.
Thank.
===========================================================================
Patrick DUPRÉ | | email: pdupre(a)gmx.com
Laboratoire de Physico-Chimie de l'Atmosphère | |
Université du Littoral-Côte d'Opale | |
Tel. (33)-(0)3 28 23 76 12 | | Fax: 03 28 65 82 44
189A, avenue Maurice Schumann | | 59140 Dunkerque, France
===========================================================================
6 years, 6 months
Anyone using kodi?
by Tom Horsley
I'm just installed kodi on my new Intel NUC, and
while it mostly works, it believes that the timezone
is UTC. I even modified the custom systemd service
to add an Environment definition setting TZ, and it
continues to display UTC time on the screen.
(This is on fedora 26).
The kodi timezone setting is always disabled even
in Expert settings mode, so I can't set it directly
in kodi.
I'd hate to think I'd have to change the hardware
clock to store localtime like windows :-).
6 years, 6 months
F27 Beta install issue for existing RAID1
by dwoody5654@gmail.com
I used F27 beta 1.3 to test if it would work a my computer with an existing
RAID1.
As it got to the install screen there was an error 'Device is already in tree'.
There are three reports on bugzilla about RAID issues but it does not seem like
they are related to the error message I am getting.
This same error message also happens on F25 and F26.
F24 works.
The is new documentation for F26 and it no longer references this type of
problem. The old documentation for F26 refers to the three reports in bugzilla.
Have I missed a work around?
Should I post this the the devel list or some other list?
I have a MSI MB (A78M-E35) with 4gig memory.
Thanks,
David
6 years, 6 months
what is an administrator?
by Tom Horsley
In anaconda, in the create user screen, there is a checkbox
for making a user an "administrator".
Once you get past anaconda, there is no "administrator"
checkbox in any of the user configuration tools I
can find.
So what does it mean to make a user an "administrator"?
How do you go about adding that after you are way past
anaconda?
Do I add some sudoer info? Is there a group that needs
to be added to that user? What is an administrator?
6 years, 6 months
Urgent: f24: dvb_usb_rtl28xxu not tuning "Leadtek Winfast DTV2000 DS
PLUS TV"
by Eyal Lebedinsky
[this is a repost of an item I have on the linux-media list]
I have just upgraded to f24. I am now using the standard dvb_usb_rtl28xxu fe
which logs messages suggesting all is well (I get the /dev/dvb/adapter? etc.)
but I get no channels tuned when I run mythfrontend or scandvb.
Is anyone using this combination?
Is this the correct way to use this frontend?
I also built the media tree from source but ended up with the same failure.
BTW:
Until f22 I was using the out of kernel driver from
https://github.com/jaredquinn/DVB-Realtek-RTL2832U.git
but I now get a compile error. I fixed the compile but at load time I see
an error:
Sep 18 17:38:30 e7 kernel: dvbdev: DVB: registering new adapter (Leaktek WinFast DTV2000DS PLUS)
Sep 18 17:38:30 e7 kernel: ------------[ cut here ]------------
Sep 18 17:38:30 e7 kernel: WARNING: CPU: 1 PID: 607 at drivers/usb/core/hcd.c:1587 usb_hcd_map_urb_for_dma+0x37f/0x570
Sep 18 17:38:30 e7 kernel: transfer buffer not dma capable
Sep 18 17:38:30 e7 systemd: Listening on Load/Save RF Kill Switch Status /dev/rfkill Watch.
Sep 18 17:38:30 e7 kernel: Modules linked in: kvm snd_hwdep snd_seq btusb btrtl irqbypass btbcm snd_seq_device pl2303 dvb_usb_rtl2832u(OE+) btintel crct10dif_pclmul ie31200_edac crc32_pclmul joydev snd
_pcm bluetooth ghash_clmulni_intel dvb_usb dvb_core intel_cstate intel_uncore snd_timer snd mei_me rfkill intel_rapl_perf i2c_i801 soundcore mei edac_core shpchp lpc_ich parport_pc nuvoton_cir rc_core
parport tpm_tis tpm_tis_core tpm i915 e1000e i2c_algo_bit drm_kms_helper mvsas ptp libsas pps_core crc32c_intel drm scsi_transport_sas video
Sep 18 17:38:30 e7 kernel: CPU: 1 PID: 607 Comm: systemd-udevd Tainted: G OE 4.11.12-100.fc24.x86_64 #1
Sep 18 17:38:30 e7 kernel: Hardware name: /DH77KC, BIOS KCH7710H.86A.0100.2012.0906.1136 09/06/2012
Sep 18 17:38:30 e7 kernel: Call Trace:
Sep 18 17:38:30 e7 kernel: dump_stack+0x63/0x86
Sep 18 17:38:30 e7 kernel: __warn+0xcb/0xf0
Sep 18 17:38:30 e7 kernel: warn_slowpath_fmt+0x5a/0x80
Sep 18 17:38:30 e7 kernel: usb_hcd_map_urb_for_dma+0x37f/0x570
Sep 18 17:38:30 e7 kernel: usb_hcd_submit_urb+0x34e/0xb90
Sep 18 17:38:30 e7 kernel: ? __rmqueue+0x91/0x760
Sep 18 17:38:30 e7 kernel: usb_submit_urb+0x2f4/0x560
Sep 18 17:38:30 e7 kernel: ? get_page_from_freelist+0xb80/0xbf0
Sep 18 17:38:30 e7 kernel: usb_start_wait_urb+0x6e/0x170
Sep 18 17:38:30 e7 kernel: usb_control_msg+0xdc/0x120
Sep 18 17:38:30 e7 kernel: read_usb_sys_char_bytes+0xd1/0x1a0 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: ? dvb_usb_fe_sleep+0x60/0x60 [dvb_usb]
Sep 18 17:38:30 e7 kernel: read_usb_sys_int_bytes+0x3b/0x90 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: read_usb_sys_register.isra.4+0x4d/0x80 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: usb_init_setting+0x45/0x400 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: rtl2832u_fe_attach+0x96/0xd70 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: rtl2832u_frontend_attach+0x15/0x30 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: dvb_usb_adapter_frontend_init+0xdf/0x190 [dvb_usb]
Sep 18 17:38:30 e7 kernel: dvb_usb_device_init+0x4ca/0x630 [dvb_usb]
Sep 18 17:38:30 e7 kernel: rtl2832u_usb_probe+0x115/0x180 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: usb_probe_interface+0x159/0x2d0
Sep 18 17:38:30 e7 kernel: driver_probe_device+0x2bb/0x460
Sep 18 17:38:30 e7 kernel: __driver_attach+0xdf/0xf0
Sep 18 17:38:30 e7 kernel: ? driver_probe_device+0x460/0x460
Sep 18 17:38:30 e7 kernel: bus_for_each_dev+0x6c/0xc0
Sep 18 17:38:30 e7 kernel: driver_attach+0x1e/0x20
Sep 18 17:38:30 e7 kernel: bus_add_driver+0x170/0x270
Sep 18 17:38:30 e7 kernel: driver_register+0x60/0xe0
Sep 18 17:38:30 e7 kernel: usb_register_driver+0x81/0x140
Sep 18 17:38:30 e7 kernel: ? 0xffffffffc0718000
Sep 18 17:38:30 e7 kernel: rtl2832u_usb_module_init+0x3b/0x1000 [dvb_usb_rtl2832u]
Sep 18 17:38:30 e7 kernel: ? 0xffffffffc0718000
Sep 18 17:38:30 e7 kernel: do_one_initcall+0x52/0x1a0
Sep 18 17:38:30 e7 kernel: ? __vunmap+0x81/0xd0
Sep 18 17:38:30 e7 kernel: ? kfree+0x154/0x170
Sep 18 17:38:30 e7 kernel: ? kmem_cache_alloc_trace+0x159/0x1b0
Sep 18 17:38:30 e7 kernel: ? do_init_module+0x27/0x1f8
Sep 18 17:38:30 e7 kernel: do_init_module+0x5f/0x1f8
Sep 18 17:38:30 e7 kernel: load_module+0x27cc/0x2be0
Sep 18 17:38:30 e7 kernel: SYSC_finit_module+0xdf/0x110
Sep 18 17:38:30 e7 kernel: ? SYSC_finit_module+0xdf/0x110
Sep 18 17:38:30 e7 kernel: SyS_finit_module+0xe/0x10
Sep 18 17:38:30 e7 kernel: do_syscall_64+0x67/0x180
Sep 18 17:38:30 e7 kernel: entry_SYSCALL64_slow_path+0x25/0x25
Sep 18 17:38:30 e7 kernel: RIP: 0033:0x7f3ad1de3219
Sep 18 17:38:30 e7 kernel: RSP: 002b:00007ffc71e7cd38 EFLAGS: 00000246 ORIG_RAX: 0000000000000139
Sep 18 17:38:30 e7 kernel: RAX: ffffffffffffffda RBX: 000000f0fdd83bc0 RCX: 00007f3ad1de3219
Sep 18 17:38:30 e7 kernel: RDX: 0000000000000000 RSI: 000000f0fdd85520 RDI: 0000000000000007
Sep 18 17:38:30 e7 kernel: RBP: 000000f0fdd85520 R08: 0000000000000000 R09: 0000000000000012
Sep 18 17:38:30 e7 kernel: R10: 0000000000000007 R11: 0000000000000246 R12: 0000000000000000
Sep 18 17:38:30 e7 kernel: R13: 000000f0fdd852d0 R14: 0000000000020000 R15: 000000f0fd6eaf2a
Sep 18 17:38:30 e7 kernel: ---[ end trace 5cace06731689a9a ]---
Sep 18 17:38:30 e7 kernel: dvb-usb: no frontend was attached by 'Leaktek WinFast DTV2000DS PLUS'
TIA
--
Eyal Lebedinsky (fedora(a)eyal.emu.id.au)
6 years, 6 months
No login screen after update FC26 from 4.11 kernel to 4.12.*
by Ambrogio
Hi all,
I have a very big problem with my new Fedora 26 installed on a Dell
Inspiron 15 7000 Gaming.
It was Ok for months until last update to kernel 4.12
With this kernel nouveau modules crashes.
If I boot with last 4.11.11-300 Kernel it is ok.
I filled this bug on bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1488305
I would like to know if someone else has this bug, or if someone else
has Fedora working on similar laptop.
From lspci I have this graphic card
00:02.0 VGA compatible controller: Intel Corporation Device 591b (rev 04)
01:00.0 VGA compatible controller: NVIDIA Corporation GP107M [GeForce GTX 1050 Ti Mobile] (rev a1)
I'm also not able to use nvidia drivers from rpmfusion, but at the moment I'm still using nouveau to see if it's will work better.
I found also this bug https://bugzilla.redhat.com/show_bug.cgi?id=1482220 that I think can be similar to mine, and related to kernel 4.12
Regards
Ambrogio
6 years, 6 months
No wayland on Intel HD graphics?
by Tom Horsley
I was installing fedora 26 workstation on a little Intel NUC
system last night (specifically model NUC5CPYH). It uses
"Intel HD Graphics" and anaconda worked fine, but once I
booted f26 from hard disk, the screen just went gray and
stayed there.
When I installed xdm and switched the login from gdm to
xdm, I was able to get a login prompt and run gnome
(I'm pretty sure in X since I'm guessing xdm probably
doesn't know how to start wayland).
Is this a known bug? Should I report it against
some component (which one?)
6 years, 6 months
DNF undo
by ogio spam
Hi all,
I have a lot of problems with my fedora 26 installed on a Dell laptop
model Inspiron 15 7000 gaming.
I use KDE so I installed the KDE version for fedora.
I stopped upgrade kernel because it won't work with the new 4.12
So I start with 4.11.11
It was ok until today.
I run dnf update, checked that nothing related to the kernel 4.12 was
updated, and confirmed all.
Now it boot in init 5 but no graphics displayed after the fedora logo.
I was able to switch to the second console and issued an init 3
After that I logged with my user, and startx was ok.
I had some other problems related to Network Manager (my card is not
seen), and so on.
So I would like to undo the upgrade.
There is a possibility to do it?
Regards
Ambrogio
6 years, 6 months