ipfw + nat проблема

Проблемы установки, настройки и работы Правильной Операционной Системы

Модератор: terminus

Правила форума
Убедительная просьба юзать теги [cоde] при оформлении листингов.
Сообщения не оформленные должным образом имеют все шансы быть незамеченными.
freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 11:49:27

обьясние мне, почему ядро вываливаеться в dump при пинге ip внешней карточки, корорая смотрин та прова!

даже когда страндарный natd настроен в rc.conf типа

Код: Выделить всё

natd_enable="YES"
natd_interface="rl0"
:cz2:
ядро пересобрано с опциями

Код: Выделить всё

options         IPFIREWALL              
options         IPFIREWALL_VERBOSE       
options         IPFIREWALL_VERBOSE_LIMIT=5 
options         IPFIREWALL_FORWARD      
options         IPDIVERT                 
options         DUMMYNET                
options         IPFIREWALL_DEFAULT_TO_ACCEPT  
да кстате, просто держиш natd то инет не рвёт но когда запускаеш связку nat в ipfw + vpn [mpd5] типа

Код: Выделить всё

${FwCMD} add divert natd ip from ${NetIn}/${NetMask} to any out via ${LanOut}
${FwCMD} add divert natd ip from any to ${IpOut} in via ${LanOut}
при пинге нормально, но со страницами лажа!

вечером доберусь до сервака выложу ошибку!


P.S. сервак раньше держал на asplinux. таких проблем не наблюдалось



freebsd-7.0

Хостинговая компания Host-Food.ru
Хостинг HostFood.ru
 

Услуги хостинговой компании Host-Food.ru

Хостинг HostFood.ru

Тарифы на хостинг в России, от 12 рублей: https://www.host-food.ru/tariffs/hosting/
Тарифы на виртуальные сервера (VPS/VDS/KVM) в РФ, от 189 руб.: https://www.host-food.ru/tariffs/virtualny-server-vps/
Выделенные сервера, Россия, Москва, от 2000 рублей (HP Proliant G5, Intel Xeon E5430 (2.66GHz, Quad-Core, 12Mb), 8Gb RAM, 2x300Gb SAS HDD, P400i, 512Mb, BBU):
https://www.host-food.ru/tariffs/vydelennyi-server-ds/
Недорогие домены в популярных зонах: https://www.host-food.ru/domains/

Аватара пользователя
zingel
beastie
Сообщения: 6204
Зарегистрирован: 2007-10-30 3:56:49
Откуда: Moscow
Контактная информация:

Re: ipfw + nat проблема

Непрочитанное сообщение zingel » 2009-02-16 11:54:43

ядро вываливаеться в dump при пинге ip внешней карточки
Чего делает? Я понимаю, что речь о fatal trap?
сервак раньше держал на asplinux
отвратительно....

p.s. Логи ошибки +

Код: Выделить всё

 dmesg -a
Z301171463546 - можно пожертвовать мне денег

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 15:33:33

dmesg -a

Код: Выделить всё

Copyright (c) 1992-2008 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
	The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 7.0-RELEASE #2: Fri Jan  2 17:46:59 EET 2009
    root@fenix.ua:/usr/src/sys/i386/compile/main_kernell
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) Celeron(R) CPU 1.70GHz (1713.23-MHz 686-class CPU)
  Origin = "GenuineIntel"  Id = 0xf13  Stepping = 3
  Features=0x3febfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM>
real memory  = 1073676288 (1023 MB)
avail memory = 1041272832 (993 MB)
ACPI APIC Table: <AMIINT INTEL845>
ioapic0 <Version 2.0> irqs 0-23 on motherboard
acpi0: <AMIINT INTEL845> on motherboard
acpi0: [ITHREAD]
acpi0: Power Button (fixed)
Timecounter "ACPI-fast" frequency 3579545 Hz quality 1000
acpi_timer0: <24-bit timer at 3.579545MHz> port 0x808-0x80b on acpi0
cpu0: <ACPI CPU> on acpi0
p4tcc0: <CPU Frequency Thermal Control> on cpu0
acpi_button0: <Power Button> on acpi0
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
agp0: <Intel 82845 host to AGP bridge> on hostb0
pcib1: <PCI-PCI bridge> at device 1.0 on pci0
pci1: <PCI bus> on pcib1
vgapci0: <VGA-compatible display> mem 0xde000000-0xdeffffff,0xd0000000-0xd7ffffff irq 16 at device 0.0 on pci1
uhci0: <Intel 82801DB (ICH4) USB controller USB-A> port 0xe400-0xe41f irq 16 at device 29.0 on pci0
uhci0: [GIANT-LOCKED]
uhci0: [ITHREAD]
usb0: <Intel 82801DB (ICH4) USB controller USB-A> on uhci0
usb0: USB revision 1.0
uhub0: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb0
uhub0: 2 ports with 2 removable, self powered
uhci1: <Intel 82801DB (ICH4) USB controller USB-B> port 0xe800-0xe81f irq 19 at device 29.1 on pci0
uhci1: [GIANT-LOCKED]
uhci1: [ITHREAD]
usb1: <Intel 82801DB (ICH4) USB controller USB-B> on uhci1
usb1: USB revision 1.0
uhub1: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb1
uhub1: 2 ports with 2 removable, self powered
uhci2: <Intel 82801DB (ICH4) USB controller USB-C> port 0xec00-0xec1f irq 18 at device 29.2 on pci0
uhci2: [GIANT-LOCKED]
uhci2: [ITHREAD]
usb2: <Intel 82801DB (ICH4) USB controller USB-C> on uhci2
usb2: USB revision 1.0
uhub2: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb2
uhub2: 2 ports with 2 removable, self powered
ehci0: <Intel 82801DB/L/M (ICH4) USB 2.0 controller> mem 0xdffffc00-0xdfffffff irq 23 at device 29.7 on pci0
ehci0: [GIANT-LOCKED]
ehci0: [ITHREAD]
usb3: EHCI version 1.0
usb3: companion controllers, 2 ports each: usb0 usb1 usb2
usb3: <Intel 82801DB/L/M (ICH4) USB 2.0 controller> on ehci0
usb3: USB revision 2.0
uhub3: <Intel EHCI root hub, class 9/0, rev 2.00/1.00, addr 1> on usb3
uhub3: 6 ports with 6 removable, self powered
pcib2: <ACPI PCI-PCI bridge> at device 30.0 on pci0
pci3: <ACPI PCI bus> on pcib2
dc0: <ADMtek AN985 10/100BaseTX> port 0xcc00-0xccff mem 0xdfeffc00-0xdfefffff irq 18 at device 5.0 on pci3
miibus0: <MII bus> on dc0
ukphy0: <Generic IEEE 802.3u media interface> PHY 1 on miibus0
ukphy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
dc0: Ethernet address: 00:00:e8:77:04:f3
dc0: [ITHREAD]
ral0: <Ralink Technology RT2561S> mem 0xdfef0000-0xdfef7fff irq 16 at device 7.0 on pci3
ral0: MAC/BBP RT2561C, RF RT2527
ral0: Ethernet address: 00:0e:2e:b3:fa:93
ral0: [ITHREAD]
rl0: <RealTek 8139 10/100BaseTX> port 0xc800-0xc8ff mem 0xdfeffb00-0xdfeffbff irq 17 at device 10.0 on pci3
miibus1: <MII bus> on rl0
rlphy0: <RealTek internal media interface> PHY 0 on miibus1
rlphy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
rl0: Ethernet address: 00:0b:6a:50:8e:41
rl0: [ITHREAD]
isab0: <PCI-ISA bridge> at device 31.0 on pci0
isa0: <ISA bus> on isab0
atapci0: <Intel ICH4 UDMA100 controller> port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xfc00-0xfc0f at device 31.1 on pci0
ata0: <ATA channel 0> on atapci0
ata0: [ITHREAD]
ata1: <ATA channel 1> on atapci0
ata1: [ITHREAD]
pcm0: <Intel ICH4 (82801DB)> port 0xe000-0xe0ff,0xdc00-0xdc3f mem 0xdffffa00-0xdffffbff,0xdffff900-0xdffff9ff irq 17 at device 31.5 on pci0
pcm0: [ITHREAD]
pcm0: <C-Media Electronics CMI9739 AC97 Codec>
atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
kbd0 at atkbd0
atkbd0: [GIANT-LOCKED]
atkbd0: [ITHREAD]
orm0: <ISA Option ROM> at iomem 0xc0000-0xcb7ff pnpid ORM0000 on isa0
sc0: <System console> at flags 0x100 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
ppc0: <Parallel port> at port 0x378-0x37f irq 7 on isa0
ppc0: SMC-like chipset (ECP/EPP/PS2/NIBBLE) in COMPATIBLE mode
ppc0: FIFO with 16/16/9 bytes threshold
ppbus0: <Parallel port bus> on ppc0
ppbus0: [ITHREAD]
ppc0: [GIANT-LOCKED]
ppc0: [ITHREAD]
ums0: <vendor 0x1241 product 0x1177, class 0/0, rev 1.10/2.70, addr 2> on uhub0
ums0: 3 buttons and Z dir.
Timecounter "TSC" frequency 1713234156 Hz quality 800
Timecounters tick every 1.000 msec
ipfw2 (+ipv6) initialized, divert enabled, rule-based forwarding enabled, default to accept, logging limited to 100 packets/entry by default
ad0: 286168MB <SAMSUNG HD300LD WK100-12> at ata0-master UDMA100
acd0: CDRW <CRW-5232AS/1.02> at ata1-master UDMA33
Trying to mount root from ufs:/dev/ad0s1a
WARNING: / was not properly dismounted
/: mount pending error: blocks 20 files 13
Loading configuration files.
kernel dumps on /dev/ad0s1b
Entropy harvesting:
 interrupts
 ethernet
 point_to_point
 kickstart
.
swapon: adding /dev/ad0s1b as swap device
Starting file system checks:
/dev/ad0s1a: UNREF FILE I=47328  OWNER=root MODE=100644
/dev/ad0s1a: SIZE=5 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=47329  OWNER=root MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=48157  OWNER=root MODE=140666
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=95539  OWNER=mysql MODE=100660
/dev/ad0s1a: SIZE=4 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118257  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118298  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118313  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118878  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118972  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=119160  OWNER=root MODE=100644
/dev/ad0s1a: SIZE=4 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=119257  OWNER=flowtools MODE=100644
/dev/ad0s1a: SIZE=5 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=2049026  OWNER=mysql MODE=140777
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=2050210  OWNER=www MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=2050211  OWNER=www MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 10:58 2009  (CLEARED)
/dev/ad0s1a: FREE BLK COUNT(S) WRONG IN SUPERBLK (SALVAGED)
/dev/ad0s1a: SUMMARY INFORMATION BAD (SALVAGED)
/dev/ad0s1a: BLK(S) MISSING IN BIT MAPS (SALVAGED)
/dev/ad0s1a: 12364 files, 363557 used, 9553762 free (7066 frags, 1193337 blocks, 0.1% fragmentation)
/dev/ad0s1d: UNREF FILE I=1391413  OWNER=squid MODE=100640
/dev/ad0s1d: SIZE=64944 MTIME=Feb 16 01:15 2009  (CLEARED)
/dev/ad0s1d: FREE BLK COUNT(S) WRONG IN SUPERBLK (SALVAGED)
/dev/ad0s1d: SUMMARY INFORMATION BAD (SALVAGED)
/dev/ad0s1d: BLK(S) MISSING IN BIT MAPS (SALVAGED)
/dev/ad0s1d: 288654 files, 1473372 used, 18361306 free (33562 frags, 2290968 blocks, 0.2% fragmentation)
/dev/ad0s1e: SUMMARY BLK COUNT(S) WRONG IN SUPERBLK (SALVAGED)
/dev/ad0s1e: 2 files, 2 used, 111136972 free (20 frags, 13892119 blocks, 0.0% fragmentation)
Setting hostuuid: 14697a81-d416-11dd-865d-000b6a508e41.
Setting hostid: 0x29f55186.
Mounting local file systems:
.
Setting hostname: fenix.ua.
net.inet6.ip6.auto_linklocal: 
1
 -> 
0

net.inet.ip.fw.verbose_limit: 
100
 -> 
10

net.inet.ip.fw.verbose_limit: 
10
 -> 
1000

net.inet.ip.fw.dyn_max: 
4096
 -> 
1000

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4 
	inet6 ::1 prefixlen 128 
	inet 127.0.0.1 netmask 0xff000000 
dc0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 00:00:e8:77:04:f3
	inet 10.0.0.1 netmask 0xfffffc00 broadcast 10.0.3.255
	media: Ethernet autoselect (100baseTX <full-duplex>)
	status: active
ral0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	ether 00:0e:2e:b3:fa:93
	inet 172.20.0.1 netmask 0xfffffc00 broadcast 172.20.3.255
	media: IEEE 802.11 Wireless Ethernet autoselect <hostap> (autoselect <hostap>)
	status: associated
	ssid freebsdap channel 6 (2437 Mhz 11g) bssid 00:0e:2e:b3:fa:93
	authmode OPEN privacy OFF txpower 50 scanvalid 60 bgscan
	bgscanintvl 300 bgscanidle 250 roam:rssi11g 7 roam:rate11g 5
	protmode CTS dtimperiod 1
rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 00:0b:6a:50:8e:41
	inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255
	media: Ethernet autoselect (none)
	status: no carrier
add net default: gateway 192.168.1.1
Additional routing options:
 IP gateway=YES
.
Starting devd.
Starting ums0 moused:
.
hw.acpi.cpu.cx_lowest: 
C1
 -> 
C1

Starting natd.
Loading /lib/libalias_cuseeme.so
Loading /lib/libalias_ftp.so
Loading /lib/libalias_irc.so
Loading /lib/libalias_nbt.so
Loading /lib/libalias_pptp.so
Loading /lib/libalias_skinny.so
Loading /lib/libalias_smedia.so
Feb 16 15:34:13 natd[618]: Aliasing to 192.168.1.2, mtu 1500 bytes
Firewall rules loaded.
net.inet.ip.fw.enable: 
1
 -> 
1

Additional IP options:
.
Mounting NFS file systems:
.
ELF ldconfig path: /lib /usr/lib /usr/lib/compat /usr/local/lib /usr/local/lib/evolution/2.12 /usr/local/lib/mysql /usr/local/lib/nss /usr/local/lib/pth
a.out ldconfig path: /usr/lib/aout /usr/lib/compat/aout
Clearing /tmp (X related).
Creating and/or trimming log files:
.
Starting syslogd.
Checking for core dump on /dev/ad0s1b...
savecore: no dumps found
Initial i386 initialization:
.
Additional ABI support:
 linux
.
Starting named.
Starting rpcbind.
Starting mpd5.
Starting local daemons:
.
Updating motd
.
Mounting late file systems:
.
Starting dhcpd.
Internet Systems Consortium DHCP Server V3.0.5

Copyright 2004-2006 Internet Systems Consortium.

All rights reserved.

For info, please visit http://www.isc.org/sw/dhcp/

Wrote 5 leases to leases file.

Listening on BPF/ral0/00:0e:2e:b3:fa:93/172.20.0/22

Sending on   BPF/ral0/00:0e:2e:b3:fa:93/172.20.0/22

Listening on BPF/dc0/00:00:e8:77:04:f3/10.0.0/22

Sending on   BPF/dc0/00:00:e8:77:04:f3/10.0.0/22

Sending on   Socket/fallback/fallback-net

Starting webmin.
Starting squid.
2009/02/16 15:34:17| aclParseAclLine: WARNING: empty ACL: "/usr/local/etc/squid/user/limited_IP.conf"
2009/02/16 15:34:17| Squid is already running!  Process ID 938
Starting mysql.
Starting radiusd.
Mon Feb 16 15:34:18 2009 : Info: Starting - reading configuration files ...
Starting flow_capture.
Performing sanity check on apache22 configuration:
[Mon Feb 16 15:34:21 2009] [warn] The Alias directive in /usr/local/etc/apache22/Includes/abills_httpd.conf at line 6 will probably never match because it overlaps an earlier Alias.
[Mon Feb 16 15:34:28 2009] [error] (EAI 8)hostname nor servname provided, or not known: Failed to resolve server name for 192.168.1.2 (check DNS) -- or specify an explicit ServerName
Syntax OK
Starting apache22.
[Mon Feb 16 15:34:29 2009] [warn] The Alias directive in /usr/local/etc/apache22/Includes/abills_httpd.conf at line 6 will probably never match because it overlaps an earlier Alias.
[Mon Feb 16 15:34:29 2009] [error] (EAI 8)hostname nor servname provided, or not known: Failed to resolve server name for 192.168.1.2 (check DNS) -- or specify an explicit ServerName
Configuring syscons:
 keymap
 scrnmap
 font8x16
 font8x14
 font8x8
 blanktime
.
Starting sshd.
Starting cron.
Local package initialization:
.
net.inet.ip.fw.verbose_limit: 
1000
 -> 
10

net.inet.ip.fw.verbose_limit: 
10
 -> 
1000

Starting inetd.

Mon Feb 16 15:34:32 EET 2009

Fatal double fault:
eip = 0xc05f6293
esp = 0xe3feffd8
ebp = 0xe3ff0090
cpuid = 0; apic id = 00
panic: double fault
cpuid = 0
Uptime: 9m10s
Physical memory: 1015 MB
Dumping 67 MB: 52 36 20 4
Dump complete
Automatic reboot in 15 seconds - press a key on the console to abort
Rebooting...
Copyright (c) 1992-2008 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
	The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 7.0-RELEASE #2: Fri Jan  2 17:46:59 EET 2009
    root@fenix.ua:/usr/src/sys/i386/compile/main_kernell
Timecounter "i8254" frequency 1193182 Hz quality 0
CPU: Intel(R) Celeron(R) CPU 1.70GHz (1713.23-MHz 686-class CPU)
  Origin = "GenuineIntel"  Id = 0xf13  Stepping = 3
  Features=0x3febfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM>
real memory  = 1073676288 (1023 MB)
avail memory = 1041272832 (993 MB)
ACPI APIC Table: <AMIINT INTEL845>
ioapic0 <Version 2.0> irqs 0-23 on motherboard
acpi0: <AMIINT INTEL845> on motherboard
acpi0: [ITHREAD]
acpi0: Power Button (fixed)
Timecounter "ACPI-fast" frequency 3579545 Hz quality 1000
acpi_timer0: <24-bit timer at 3.579545MHz> port 0x808-0x80b on acpi0
cpu0: <ACPI CPU> on acpi0
p4tcc0: <CPU Frequency Thermal Control> on cpu0
acpi_button0: <Power Button> on acpi0
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
agp0: <Intel 82845 host to AGP bridge> on hostb0
pcib1: <PCI-PCI bridge> at device 1.0 on pci0
pci1: <PCI bus> on pcib1
vgapci0: <VGA-compatible display> mem 0xde000000-0xdeffffff,0xd0000000-0xd7ffffff irq 16 at device 0.0 on pci1
uhci0: <Intel 82801DB (ICH4) USB controller USB-A> port 0xe400-0xe41f irq 16 at device 29.0 on pci0
uhci0: [GIANT-LOCKED]
uhci0: [ITHREAD]
usb0: <Intel 82801DB (ICH4) USB controller USB-A> on uhci0
usb0: USB revision 1.0
uhub0: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb0
uhub0: 2 ports with 2 removable, self powered
uhci1: <Intel 82801DB (ICH4) USB controller USB-B> port 0xe800-0xe81f irq 19 at device 29.1 on pci0
uhci1: [GIANT-LOCKED]
uhci1: [ITHREAD]
usb1: <Intel 82801DB (ICH4) USB controller USB-B> on uhci1
usb1: USB revision 1.0
uhub1: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb1
uhub1: 2 ports with 2 removable, self powered
uhci2: <Intel 82801DB (ICH4) USB controller USB-C> port 0xec00-0xec1f irq 18 at device 29.2 on pci0
uhci2: [GIANT-LOCKED]
uhci2: [ITHREAD]
usb2: <Intel 82801DB (ICH4) USB controller USB-C> on uhci2
usb2: USB revision 1.0
uhub2: <Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1> on usb2
uhub2: 2 ports with 2 removable, self powered
ehci0: <Intel 82801DB/L/M (ICH4) USB 2.0 controller> mem 0xdffffc00-0xdfffffff irq 23 at device 29.7 on pci0
ehci0: [GIANT-LOCKED]
ehci0: [ITHREAD]
usb3: EHCI version 1.0
usb3: companion controllers, 2 ports each: usb0 usb1 usb2
usb3: <Intel 82801DB/L/M (ICH4) USB 2.0 controller> on ehci0
usb3: USB revision 2.0
uhub3: <Intel EHCI root hub, class 9/0, rev 2.00/1.00, addr 1> on usb3
uhub3: 6 ports with 6 removable, self powered
pcib2: <ACPI PCI-PCI bridge> at device 30.0 on pci0
pci3: <ACPI PCI bus> on pcib2
dc0: <ADMtek AN985 10/100BaseTX> port 0xcc00-0xccff mem 0xdfeffc00-0xdfefffff irq 18 at device 5.0 on pci3
miibus0: <MII bus> on dc0
ukphy0: <Generic IEEE 802.3u media interface> PHY 1 on miibus0
ukphy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
dc0: Ethernet address: 00:00:e8:77:04:f3
dc0: [ITHREAD]
ral0: <Ralink Technology RT2561S> mem 0xdfef0000-0xdfef7fff irq 16 at device 7.0 on pci3
ral0: MAC/BBP RT2561C, RF RT2527
ral0: Ethernet address: 00:0e:2e:b3:fa:93
ral0: [ITHREAD]
rl0: <RealTek 8139 10/100BaseTX> port 0xc800-0xc8ff mem 0xdfeffb00-0xdfeffbff irq 17 at device 10.0 on pci3
miibus1: <MII bus> on rl0
rlphy0: <RealTek internal media interface> PHY 0 on miibus1
rlphy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
rl0: Ethernet address: 00:0b:6a:50:8e:41
rl0: [ITHREAD]
isab0: <PCI-ISA bridge> at device 31.0 on pci0
isa0: <ISA bus> on isab0
atapci0: <Intel ICH4 UDMA100 controller> port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xfc00-0xfc0f at device 31.1 on pci0
ata0: <ATA channel 0> on atapci0
ata0: [ITHREAD]
ata1: <ATA channel 1> on atapci0
ata1: [ITHREAD]
pcm0: <Intel ICH4 (82801DB)> port 0xe000-0xe0ff,0xdc00-0xdc3f mem 0xdffffa00-0xdffffbff,0xdffff900-0xdffff9ff irq 17 at device 31.5 on pci0
pcm0: [ITHREAD]
pcm0: <C-Media Electronics CMI9739 AC97 Codec>
atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
kbd0 at atkbd0
atkbd0: [GIANT-LOCKED]
atkbd0: [ITHREAD]
orm0: <ISA Option ROM> at iomem 0xc0000-0xcb7ff pnpid ORM0000 on isa0
sc0: <System console> at flags 0x100 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
ppc0: <Parallel port> at port 0x378-0x37f irq 7 on isa0
ppc0: SMC-like chipset (ECP/EPP/PS2/NIBBLE) in COMPATIBLE mode
ppc0: FIFO with 16/16/9 bytes threshold
ppbus0: <Parallel port bus> on ppc0
ppbus0: [ITHREAD]
ppc0: [GIANT-LOCKED]
ppc0: [ITHREAD]
ums0: <vendor 0x1241 product 0x1177, class 0/0, rev 1.10/2.70, addr 2> on uhub0
ums0: 3 buttons and Z dir.
Timecounter "TSC" frequency 1713233600 Hz quality 800
Timecounters tick every 1.000 msec
ipfw2 (+ipv6) initialized, divert enabled, rule-based forwarding enabled, default to accept, logging limited to 100 packets/entry by default
ad0: 286168MB <SAMSUNG HD300LD WK100-12> at ata0-master UDMA100
acd0: CDRW <CRW-5232AS/1.02> at ata1-master UDMA33
Trying to mount root from ufs:/dev/ad0s1a
WARNING: / was not properly dismounted
/: mount pending error: blocks 40 files 3
Loading configuration files.
kernel dumps on /dev/ad0s1b
Entropy harvesting:
 interrupts
 ethernet
 point_to_point
 kickstart
.
swapon: adding /dev/ad0s1b as swap device
Starting file system checks:
/dev/ad0s1a: INCORRECT BLOCK COUNT I=259521 (16 should be 0) (CORRECTED)
/dev/ad0s1a: UNREF FILE I=48174  OWNER=root MODE=140666
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 15:34 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118878  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 15:34 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=118972  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 15:34 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=119160  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 15:34 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=119257  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 15:34 2009  (CLEARED)
/dev/ad0s1a: UNREF FILE I=119259  OWNER=mysql MODE=100600
/dev/ad0s1a: SIZE=0 MTIME=Feb 16 15:34 2009  (CLEARED)
/dev/ad0s1a: FREE BLK COUNT(S) WRONG IN SUPERBLK (SALVAGED)
/dev/ad0s1a: SUMMARY INFORMATION BAD (SALVAGED)
/dev/ad0s1a: BLK(S) MISSING IN BIT MAPS (SALVAGED)
/dev/ad0s1a: 12373 files, 363560 used, 9553759 free (7079 frags, 1193335 blocks, 0.1% fragmentation)
/dev/ad0s1d: 288654 files, 1473372 used, 18361306 free (33562 frags, 2290968 blocks, 0.2% fragmentation)
/dev/ad0s1e: 2 files, 2 used, 111136972 free (20 frags, 13892119 blocks, 0.0% fragmentation)
Setting hostuuid: 14697a81-d416-11dd-865d-000b6a508e41.
Setting hostid: 0x29f55186.
Mounting local file systems:
.
Setting hostname: fenix.ua.
net.inet6.ip6.auto_linklocal: 
1
 -> 
0

net.inet.ip.fw.verbose_limit: 
100
 -> 
10

net.inet.ip.fw.verbose_limit: 
10
 -> 
1000

net.inet.ip.fw.dyn_max: 
4096
 -> 
1000

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4 
	inet6 ::1 prefixlen 128 
	inet 127.0.0.1 netmask 0xff000000 
dc0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 00:00:e8:77:04:f3
	inet 10.0.0.1 netmask 0xfffffc00 broadcast 10.0.3.255
	media: Ethernet autoselect (100baseTX <full-duplex>)
	status: active
ral0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	ether 00:0e:2e:b3:fa:93
	inet 172.20.0.1 netmask 0xfffffc00 broadcast 172.20.3.255
	media: IEEE 802.11 Wireless Ethernet autoselect <hostap> (autoselect <hostap>)
	status: associated
	ssid freebsdap channel 6 (2437 Mhz 11g) bssid 00:0e:2e:b3:fa:93
	authmode OPEN privacy OFF txpower 50 scanvalid 60 bgscan
	bgscanintvl 300 bgscanidle 250 roam:rssi11g 7 roam:rate11g 5
	protmode CTS dtimperiod 1
rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
	options=8<VLAN_MTU>
	ether 00:0b:6a:50:8e:41
	inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255
	media: Ethernet autoselect (none)
	status: no carrier
add net default: gateway 192.168.1.1
Additional routing options:
 IP gateway=YES
.
Starting devd.
Starting ums0 moused:
.
hw.acpi.cpu.cx_lowest: 
C1
 -> 
C1

Starting natd.
Loading /lib/libalias_cuseeme.so
Loading /lib/libalias_ftp.so
Loading /lib/libalias_irc.so
Loading /lib/libalias_nbt.so
Loading /lib/libalias_pptp.so
Loading /lib/libalias_skinny.so
Loading /lib/libalias_smedia.so
Feb 16 15:44:24 natd[620]: Aliasing to 192.168.1.2, mtu 1500 bytes
Firewall rules loaded.
net.inet.ip.fw.enable: 
1
 -> 
1

Additional IP options:
.
Mounting NFS file systems:
.
ELF ldconfig path: /lib /usr/lib /usr/lib/compat /usr/local/lib /usr/local/lib/evolution/2.12 /usr/local/lib/mysql /usr/local/lib/nss /usr/local/lib/pth
a.out ldconfig path: /usr/lib/aout /usr/lib/compat/aout
Clearing /tmp (X related).
Creating and/or trimming log files:
.
Starting syslogd.
Checking for core dump on /dev/ad0s1b...
savecore: reboot after panic: double fault
savecore: writing core to vmcore.9
rl0: link state changed to UP
Initial i386 initialization:
.
Additional ABI support:
 linux
.
Starting named.
Starting rpcbind.
Starting mpd5.
Starting local daemons:
.
Updating motd
.
Mounting late file systems:
.
Starting dhcpd.
Internet Systems Consortium DHCP Server V3.0.5

Copyright 2004-2006 Internet Systems Consortium.

All rights reserved.

For info, please visit http://www.isc.org/sw/dhcp/

Wrote 5 leases to leases file.

Listening on BPF/ral0/00:0e:2e:b3:fa:93/172.20.0/22

Sending on   BPF/ral0/00:0e:2e:b3:fa:93/172.20.0/22

Listening on BPF/dc0/00:00:e8:77:04:f3/10.0.0/22

Sending on   BPF/dc0/00:00:e8:77:04:f3/10.0.0/22

Sending on   Socket/fallback/fallback-net

Starting webmin.
Starting squid.
2009/02/16 15:44:32| aclParseAclLine: WARNING: empty ACL: "/usr/local/etc/squid/user/limited_IP.conf"
Starting mysql.
Starting radiusd.
Mon Feb 16 15:44:33 2009 : Info: Starting - reading configuration files ...
Starting flow_capture.
Performing sanity check on apache22 configuration:
[Mon Feb 16 15:44:38 2009] [warn] The Alias directive in /usr/local/etc/apache22/Includes/abills_httpd.conf at line 6 will probably never match because it overlaps an earlier Alias.
[Mon Feb 16 15:44:38 2009] [error] (EAI 8)hostname nor servname provided, or not known: Failed to resolve server name for 192.168.1.2 (check DNS) -- or specify an explicit ServerName
Syntax OK
Starting apache22.
[Mon Feb 16 15:44:38 2009] [warn] The Alias directive in /usr/local/etc/apache22/Includes/abills_httpd.conf at line 6 will probably never match because it overlaps an earlier Alias.
[Mon Feb 16 15:44:38 2009] [error] (EAI 8)hostname nor servname provided, or not known: Failed to resolve server name for 192.168.1.2 (check DNS) -- or specify an explicit ServerName
Configuring syscons:
 keymap
 scrnmap
 font8x16
 font8x14
 font8x8
 blanktime
.
Starting sshd.
Starting cron.
Local package initialization:
.
net.inet.ip.fw.verbose_limit: 
1000
 -> 
10

net.inet.ip.fw.verbose_limit: 
10
 -> 
1000

Starting inetd.


фаервол взят с сайта


есть свой скрипт но я решил взять cайта и проверить себя на крыворукость
ipfw_load.sh

Код: Выделить всё



${FwCMD} -f flush

${FwCMD} add check-state
${FwCMD} add allow ip from any to any via lo0
${FwCMD} add deny ip from any to 127.0.0.0/8
${FwCMD} add deny ip from 127.0.0.0/8 to any
${FwCMD} add deny ip from any to 10.0.0.0/8 in via ${LanOut}
${FwCMD} add deny ip from any to 0.0.0.0/8 in via ${LanOut}
${FwCMD} add deny ip from any to 169.254.0.0/16 in via ${LanOut}
${FwCMD} add deny ip from any to 240.0.0.0/4 in via ${LanOut}
${FwCMD} add deny icmp from any to any frag
${FwCMD} add deny log icmp from any to 255.255.255.255 in via ${LanOut}
${FwCMD} add deny log icmp from any to 255.255.255.255 out via ${LanOut}
${FwCMD} add fwd 127.0.0.1,3128 tcp from ${NetIn}/${NetMask} to any 80,443 via ${LanOut}
${FwCMD} add divert natd ip from ${NetIn}/${NetMask} to any out via ${LanOut}
${FwCMD} add divert natd ip from any to any in via ${LanOut}
${FwCMD} add deny ip from 10.0.0.0/8 to any out via ${LanOut}
${FwCMD} add deny ip from 0.0.0.0/8 to any out via ${LanOut}
${FwCMD} add deny ip from 169.254.0.0/16 to any out via ${LanOut}
${FwCMD} add deny ip from 224.0.0.0/4 to any out via ${LanOut}
${FwCMD} add deny ip from 240.0.0.0/4 to any out via ${LanOut}
${FwCMD} add allow ip from ${IpOut} to any out xmit ${LanOut}
${FwCMD} add allow udp from any 53 to any 
${FwCMD} add allow udp from any to any 53
${FwCMD} add allow tcp from any to ${IpOut} 49152-65535 via ${LanOut}
${FwCMD} add allow icmp from any to any icmptypes 0,8,11
${FwCMD} add allow tcp from any to ${IpOut} 80 via ${LanOut}
${FwCMD} add allow gre from any to any via ${LanIn}
${FwCMD} add allow tcp from any to any via ${LanIn}
${FwCMD} add allow tcp from any to me 1723 in 
${FwCMD} add allow tcp from me 1723 to any out
${FwCMD} add allow udp from any to any via ${LanIn}
${FwCMD} add allow icmp from any to any via ${LanIn}
${FwCMD} add allow tcp from any to any via ng/*
${FwCMD} add allow udp from any to any via ng/*
${FwCMD} add deny ip from any to any via ${LanOut}
${FwCMD} add deny ip from any to any via ${LanIn}
rc.conf natd

Код: Выделить всё

natd_enable="YES"
natd_interface="rl0"
natd_flags="-m -u"
+ ето всё сопровождаеться vpn сервером поднятым на mpd5 для клиентов даються адреса типа 172.16.x.x ну и естественно сервен впн в подключении отображаеться 172.16.0.1, но только достаточно выполнить команду ping 172.16.0.1 c клиентской стороны сразу же вываливаеться с такой ошибкой (фото с ошибкой прикрепил)
Вложения
DSC00031 (2) (2).gif

paradox
проходил мимо
Сообщения: 11620
Зарегистрирован: 2008-02-21 18:15:41

Re: ipfw + nat проблема

Непрочитанное сообщение paradox » 2009-02-16 15:43:48

Код: Выделить всё

double fault
обычно проблема в железе
причем что бы ее словить надо еще суметь....

Аватара пользователя
zingel
beastie
Сообщения: 6204
Зарегистрирован: 2007-10-30 3:56:49
Откуда: Moscow
Контактная информация:

Re: ipfw + nat проблема

Непрочитанное сообщение zingel » 2009-02-16 15:58:10

не, тут дело в другом, нужно дебагать и писать pr
Z301171463546 - можно пожертвовать мне денег

paradox
проходил мимо
Сообщения: 11620
Зарегистрирован: 2008-02-21 18:15:41

Re: ipfw + nat проблема

Непрочитанное сообщение paradox » 2009-02-16 16:03:16

можно еще до стеибл попробовать обновить
или 7 1 заинсталлить

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 16:24:32

я решал ету проблему другим способом! закрывал всякий доступ к ip 172.16.0.1 с помошью ipfw но появлялась другая, начинает рвать инет! что посоветуете конкретно? :cz2: уже битых 5 дней колупаюсь!

Аватара пользователя
zingel
beastie
Сообщения: 6204
Зарегистрирован: 2007-10-30 3:56:49
Откуда: Moscow
Контактная информация:

Re: ipfw + nat проблема

Непрочитанное сообщение zingel » 2009-02-16 16:28:55

тоесть паник пропал что ли*? :crazy:
Z301171463546 - можно пожертвовать мне денег

paradox
проходил мимо
Сообщения: 11620
Зарегистрирован: 2008-02-21 18:15:41

Re: ipfw + nat проблема

Непрочитанное сообщение paradox » 2009-02-16 16:30:19

ну вы блин даете (с) ктото

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 16:39:12

zingel писал(а):тоесть паник пропал что ли*? :crazy:
как бы не пропал но не появлялся :st:

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 16:41:53

paradox писал(а):можно еще до стеибл попробовать обновить
или 7 1 заинсталлить

у тебя человечиская инструкция есть?
попробую

Аватара пользователя
zingel
beastie
Сообщения: 6204
Зарегистрирован: 2007-10-30 3:56:49
Откуда: Moscow
Контактная информация:

Re: ipfw + nat проблема

Непрочитанное сообщение zingel » 2009-02-16 16:42:23

ну рассказывай везуньчик, что делал, как делал с чем...
Z301171463546 - можно пожертвовать мне денег

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 17:00:38

zingel писал(а):ну рассказывай везуньчик, что делал, как делал с чем...
ничего особого, кроме как поставил билинг abills пересобирал mpd 5 вытаскивал исходники с сайта, так как в beta версии (которая в портах) были небольшые дырки которые меня не устраивали, и пересобрал яро под свою машину! :st:

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-16 20:24:36

попробую обновить до 7.1 stable посмотрим что из етого получиться! а ошибка в модуле divert!

freebsd_max
рядовой
Сообщения: 11
Зарегистрирован: 2009-02-16 11:07:25

Re: ipfw + nat проблема

Непрочитанное сообщение freebsd_max » 2009-02-18 0:33:04

paradox писал(а):можно еще до стеибл попробовать обновить
или 7 1 заинсталлить

заинсталил, помогло, спасиб :good:

p.s 7.0 релиз не стабилен, взял на зметку


спасибо за ответы но помог только один