LINUX.ORG.RU

Сообщения petav

 

SATA hard resetting link

Диск sda подключен к контроллеру «Silicon Image, Inc. SiI 3132 Serial ATA Raid II Controller» в момент записи на диск он отваливается.

Диагностика:
Информация lspci по RAID bus controller

02:00.0 RAID bus controller: Silicon Image, Inc. SiI 3132 Serial ATA Raid II Controller (rev 01)
	Subsystem: Silicon Image, Inc. Device 7132
	Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
	Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
	Latency: 0, Cache Line Size: 64 bytes
	Interrupt: pin A routed to IRQ 16
	Region 0: Memory at f7d84000 (64-bit, non-prefetchable) [size=128]
	Region 2: Memory at f7d80000 (64-bit, non-prefetchable) [size=16K]
	Region 4: I/O ports at e000 [size=128]
	Expansion ROM at f7d00000 [disabled] [size=512K]
	Capabilities: [54] Power Management version 2
		Flags: PMEClk- DSI+ D1+ D2+ AuxCurrent=0mA PME(D0-,D1-,D2-,D3hot-,D3cold-)
		Status: D0 NoSoftRst- PME-Enable- DSel=0 DScale=1 PME-
	Capabilities: [5c] MSI: Enable- Count=1/1 Maskable- 64bit+
		Address: 0000000000000000  Data: 0000
	Capabilities: [70] Express (v1) Legacy Endpoint, MSI 00
		DevCap:	MaxPayload 1024 bytes, PhantFunc 0, Latency L0s <64ns, L1 <1us
			ExtTag- AttnBtn- AttnInd- PwrInd- RBE- FLReset-
		DevCtl:	Report errors: Correctable- Non-Fatal- Fatal- Unsupported-
			RlxdOrd- ExtTag- PhantFunc- AuxPwr- NoSnoop-
			MaxPayload 128 bytes, MaxReadReq 4096 bytes
		DevSta:	CorrErr- UncorrErr+ FatalErr- UnsuppReq+ AuxPwr- TransPend-
		LnkCap:	Port #0, Speed 2.5GT/s, Width x1, ASPM L0s, Latency L0 unlimited, L1 unlimited
			ClockPM- Surprise- LLActRep- BwNot-
		LnkCtl:	ASPM Disabled; RCB 64 bytes Disabled- Retrain- CommClk+
			ExtSynch- ClockPM- AutWidDis- BWInt- AutBWInt-
		LnkSta:	Speed 2.5GT/s, Width x1, TrErr- Train- SlotClk+ DLActive- BWMgmt- ABWMgmt-
	Capabilities: [100 v1] Advanced Error Reporting
		UESta:	DLP- SDES- TLP- FCP- CmpltTO- CmpltAbrt- UnxCmplt- RxOF- MalfTLP- ECRC- UnsupReq+ ACSViol-
		UEMsk:	DLP- SDES- TLP- FCP- CmpltTO- CmpltAbrt- UnxCmplt- RxOF- MalfTLP- ECRC- UnsupReq- ACSViol-
		UESvrt:	DLP+ SDES- TLP- FCP+ CmpltTO- CmpltAbrt- UnxCmplt- RxOF+ MalfTLP+ ECRC- UnsupReq- ACSViol-
		CESta:	RxErr- BadTLP- BadDLLP- Rollover- Timeout- NonFatalErr-
		CEMsk:	RxErr- BadTLP- BadDLLP- Rollover- Timeout- NonFatalErr-
		AERCap:	First Error Pointer: 14, GenCap+ CGenEn- ChkCap+ ChkEn-
	Kernel driver in use: sata_sil24

Информация о том как система «сбрасывает» диск
hard resetting link

Jul 29 01:04:48 bacula kernel: [28716.231729] ata2: exception Emask 0x10 SAct 0x0 SErr 0x10000 action 0xe frozen
Jul 29 01:04:48 bacula kernel: [28716.233751] ata2: SError: { PHYRdyChg }
Jul 29 01:04:48 bacula kernel: [28716.235755] ata2: hard resetting link
Jul 29 01:04:51 bacula kernel: [28718.917945] ata2: SATA link up 1.5 Gbps (SStatus 113 SControl 310)
Jul 29 01:04:51 bacula kernel: [28719.046239] ata2.00: configured for UDMA/33
Jul 29 01:04:51 bacula kernel: [28719.046248] ata2: EH complete
Jul 29 01:05:20 bacula kernel: [28748.279258] ata2: exception Emask 0x10 SAct 0x0 SErr 0x10000 action 0xe frozen
Jul 29 01:05:20 bacula kernel: [28748.281283] ata2: SError: { PHYRdyChg }
Jul 29 01:05:20 bacula kernel: [28748.283288] ata2: hard resetting link
Jul 29 01:05:22 bacula kernel: [28750.580883] ata2: COMRESET failed (errno=-19)
Jul 29 01:05:22 bacula kernel: [28750.582860] ata2: reset failed (errno=-19), retrying in 8 secs
Jul 29 01:05:30 bacula kernel: [28758.278685] ata2: hard resetting link
Jul 29 01:05:32 bacula kernel: [28760.458082] ata2: SATA link up 1.5 Gbps (SStatus 113 SControl 310)
Jul 29 01:05:32 bacula kernel: [28760.570380] ata2.00: configured for UDMA/33
Jul 29 01:05:32 bacula kernel: [28760.570389] ata2: EH complete
Jul 29 01:05:38 bacula kernel: [28766.813705] ata2: exception Emask 0x10 SAct 0x0 SErr 0x10000 action 0xe frozen
Jul 29 01:05:38 bacula kernel: [28766.815706] ata2: SError: { PHYRdyChg }
Jul 29 01:05:38 bacula kernel: [28766.817689] ata2: hard resetting link
Jul 29 01:05:40 bacula kernel: [28768.011906] ata2: COMRESET failed (errno=-19)
Jul 29 01:05:40 bacula kernel: [28768.013861] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:05:48 bacula kernel: [28776.813394] ata2: hard resetting link
Jul 29 01:05:50 bacula kernel: [28777.977059] ata2: COMRESET failed (errno=-19)
Jul 29 01:05:50 bacula kernel: [28777.978978] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:05:58 bacula kernel: [28786.810510] ata2: hard resetting link
Jul 29 01:06:00 bacula kernel: [28788.438070] ata2: COMRESET failed (errno=-19)
Jul 29 01:06:00 bacula kernel: [28788.439950] ata2: reset failed (errno=-19), retrying in 34 secs
Jul 29 01:06:33 bacula kernel: [28821.800519] ata2: hard resetting link
Jul 29 01:06:35 bacula kernel: [28823.332106] ata2: COMRESET failed (errno=-19)
Jul 29 01:06:35 bacula kernel: [28823.333955] ata2: reset failed, giving up
Jul 29 01:06:35 bacula kernel: [28823.335766] ata2.00: disabled
Jul 29 01:06:35 bacula kernel: [28823.335775] ata2: exception Emask 0x10 SAct 0x0 SErr 0x50000 action 0xe frozen t4
Jul 29 01:06:35 bacula kernel: [28823.337625] ata2: SError: { PHYRdyChg CommWake }
Jul 29 01:06:35 bacula kernel: [28823.339448] ata2: hard resetting link
Jul 29 01:06:37 bacula kernel: [28825.651448] ata2: COMRESET failed (errno=-19)
Jul 29 01:06:37 bacula kernel: [28825.653254] ata2: reset failed (errno=-19), retrying in 8 secs
Jul 29 01:06:45 bacula kernel: [28833.333251] ata2: hard resetting link
Jul 29 01:06:47 bacula kernel: [28834.960789] ata2: COMRESET failed (errno=-19)
Jul 29 01:06:47 bacula kernel: [28834.962553] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:06:55 bacula kernel: [28843.330397] ata2: hard resetting link
Jul 29 01:06:56 bacula kernel: [28844.334107] ata2: COMRESET failed (errno=-19)
Jul 29 01:06:56 bacula kernel: [28844.335834] ata2: reset failed (errno=-19), retrying in 34 secs
Jul 29 01:07:30 bacula kernel: [28878.320406] ata2: hard resetting link
Jul 29 01:07:31 bacula kernel: [28879.819973] ata2: COMRESET failed (errno=-19)
Jul 29 01:07:31 bacula kernel: [28879.821664] ata2: reset failed, giving up
Jul 29 01:07:31 bacula kernel: [28879.823334] ata2: exception Emask 0x10 SAct 0x0 SErr 0x50000 action 0xe frozen t3
Jul 29 01:07:31 bacula kernel: [28879.825029] ata2: SError: { PHYRdyChg CommWake }
Jul 29 01:07:31 bacula kernel: [28879.826737] ata2: hard resetting link
Jul 29 01:07:33 bacula kernel: [28880.987639] ata2: COMRESET failed (errno=-19)
Jul 29 01:07:33 bacula kernel: [28880.989314] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:07:41 bacula kernel: [28889.821095] ata2: hard resetting link
Jul 29 01:07:44 bacula kernel: [28892.496350] ata2: COMRESET failed (errno=-32)
Jul 29 01:07:44 bacula kernel: [28892.497991] ata2: reset failed (errno=-32), retrying in 8 secs
Jul 29 01:07:51 bacula kernel: [28899.818266] ata2: hard resetting link
Jul 29 01:07:52 bacula kernel: [28900.726007] ata2: COMRESET failed (errno=-19)
Jul 29 01:07:52 bacula kernel: [28900.727618] ata2: reset failed (errno=-19), retrying in 35 secs
Jul 29 01:08:26 bacula kernel: [28934.808272] ata2: hard resetting link
Jul 29 01:08:28 bacula kernel: [28936.211843] ata2: COMRESET failed (errno=-19)
Jul 29 01:08:28 bacula kernel: [28936.213422] ata2: reset failed, giving up
Jul 29 01:08:28 bacula kernel: [28936.214974] ata2: exception Emask 0x10 SAct 0x0 SErr 0x50000 action 0xe frozen t2
Jul 29 01:08:28 bacula kernel: [28936.216591] ata2: SError: { PHYRdyChg CommWake }
Jul 29 01:08:28 bacula kernel: [28936.218185] ata2: hard resetting link
Jul 29 01:08:29 bacula kernel: [28937.411524] ata2: COMRESET failed (errno=-19)
Jul 29 01:08:29 bacula kernel: [28937.413099] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:08:38 bacula kernel: [28946.213007] ata2: hard resetting link
Jul 29 01:08:41 bacula kernel: [28949.120180] ata2: COMRESET failed (errno=-19)
Jul 29 01:08:41 bacula kernel: [28949.121724] ata2: reset failed (errno=-19), retrying in 8 secs
Jul 29 01:08:48 bacula kernel: [28956.210158] ata2: hard resetting link
Jul 29 01:08:49 bacula kernel: [28957.773711] ata2: COMRESET failed (errno=-19)
Jul 29 01:08:49 bacula kernel: [28957.775253] ata2: reset failed (errno=-19), retrying in 34 secs
Jul 29 01:09:23 bacula kernel: [28991.200166] ata2: hard resetting link
Jul 29 01:09:24 bacula kernel: [28992.043922] ata2: COMRESET failed (errno=-19)
Jul 29 01:09:24 bacula kernel: [28992.045424] ata2: reset failed, giving up
Jul 29 01:09:24 bacula kernel: [28992.046910] ata2: exception Emask 0x10 SAct 0x0 SErr 0x50000 action 0xe frozen t1
Jul 29 01:09:24 bacula kernel: [28992.048425] ata2: SError: { PHYRdyChg CommWake }
Jul 29 01:09:24 bacula kernel: [28992.049952] ata2: hard resetting link
Jul 29 01:09:25 bacula kernel: [28993.211561] ata2: COMRESET failed (errno=-19)
Jul 29 01:09:25 bacula kernel: [28993.213058] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:09:34 bacula kernel: [29002.045068] ata2: hard resetting link
Jul 29 01:09:35 bacula kernel: [29003.672602] ata2: COMRESET failed (errno=-19)
Jul 29 01:09:35 bacula kernel: [29003.674065] ata2: reset failed (errno=-19), retrying in 9 secs
Jul 29 01:09:44 bacula kernel: [29012.042220] ata2: hard resetting link
Jul 29 01:09:45 bacula kernel: [29013.045931] ata2: COMRESET failed (errno=-19)
Jul 29 01:09:45 bacula kernel: [29013.047352] ata2: reset failed (errno=-19), retrying in 34 secs
Jul 29 01:10:19 bacula kernel: [29047.032223] ata2: hard resetting link
Jul 29 01:10:20 bacula kernel: [29047.939961] ata2: COMRESET failed (errno=-19)
Jul 29 01:10:20 bacula kernel: [29047.941350] ata2: reset failed, giving up
Jul 29 01:10:20 bacula kernel: [29047.942706] ata2: EH pending after 5 tries, giving up
Jul 29 01:10:20 bacula kernel: [29047.944099] ata2: EH complete
Jul 29 01:10:20 bacula kernel: [29047.944113] ata2.00: detaching (SCSI 2:0:0:0)
Jul 29 01:10:20 bacula kernel: [29047.945018] sd 2:0:0:0: [sda] Synchronizing SCSI cache
Jul 29 01:10:20 bacula kernel: [29047.945060] sd 2:0:0:0: [sda]  Result: hostbyte=DID_BAD_TARGET driverbyte=DRIVER_OK
Jul 29 01:10:20 bacula kernel: [29047.945065] sd 2:0:0:0: [sda] Stopping disk
Jul 29 01:10:20 bacula kernel: [29047.945073] sd 2:0:0:0: [sda] START_STOP FAILED
Jul 29 01:10:20 bacula kernel: [29047.945076] sd 2:0:0:0: [sda]  Result: hostbyte=DID_BAD_TARGET driverbyte=DRIVER_OK

Система считает что на файловая структура содержит ошибки
Remounting filesystem read-only

Jul 29 04:00:00 bacula kernel: [39225.515551] EXT4-fs error (device sda1): ext4_find_entry:932: inode #2: comm bacula-fd: reading directory lblock 0
Jul 29 04:00:00 bacula kernel: [39225.528285] quiet_error: 35 callbacks suppressed
Jul 29 04:00:00 bacula kernel: [39225.528291] Buffer I/O error on device sda1, logical block 30441472
Jul 29 04:00:00 bacula kernel: [39225.529738] lost page write due to I/O error on sda1
Jul 29 04:00:00 bacula kernel: [39225.529742] JBD2: I/O error detected when updating journal superblock for sda1-8.
Jul 29 04:00:00 bacula kernel: [39225.531217] Aborting journal on device sda1-8.
Jul 29 04:00:00 bacula kernel: [39225.532677] Buffer I/O error on device sda1, logical block 30441472
Jul 29 04:00:00 bacula kernel: [39225.534109] lost page write due to I/O error on sda1
Jul 29 04:00:00 bacula kernel: [39225.535014] JBD2: I/O error detected when updating journal superblock for sda1-8.
Jul 29 04:00:00 bacula kernel: [39225.536531] journal commit I/O error
Jul 29 04:00:00 bacula kernel: [39225.537952] EXT4-fs error (device sda1): ext4_journal_start_sb:327: Detected aborted journal
Jul 29 04:00:00 bacula kernel: [39225.539426] EXT4-fs (sda1): Remounting filesystem read-only

По факту диска уже нет /dev/sda уже нет.

# smartctl -a /dev/sda
smartctl 5.41 2011-06-09 r3365 [x86_64-linux-3.2.0-4-amd64] (local build)
Copyright (C) 2002-11 by Bruce Allen, http://smartmontools.sourceforge.net

Smartctl open device: /dev/sda failed: No such device

Но его можно найти

echo "- - -" >/sys/class/scsi_host/host2/scan
Jul 29 10:03:34 bacula kernel: [61033.006707] sd 2:0:0:0: [sda] 488397168 512-byte logical blocks: (250 GB/232 GiB)
Jul 29 10:03:34 bacula kernel: [61033.006760] sd 2:0:0:0: [sda] Write Protect is off
Jul 29 10:03:34 bacula kernel: [61033.006763] sd 2:0:0:0: [sda] Mode Sense: 00 3a 00 00
Jul 29 10:03:34 bacula kernel: [61033.006785] sd 2:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
Jul 29 10:03:34 bacula kernel: [61033.007290] sd 2:0:0:0: Attached scsi generic sg0 type 0
Jul 29 10:03:34 bacula kernel: [61033.027146]  sda: sda1
Jul 29 10:03:34 bacula kernel: [61033.027376] sd 2:0:0:0: [sda] Attached SCSI disk
Jul 29 10:03:35 bacula kernel: [61034.578778] EXT4-fs (sda1): warning: mounting fs with errors, running e2fsck is recommended
Jul 29 10:03:35 bacula kernel: [61034.579301] EXT4-fs (sda1): recovery complete
Jul 29 10:03:35 bacula kernel: [61034.579304] EXT4-fs (sda1): mounted filesystem with ordered data mode. Opts: (null)

И посмотреть SMART

=== START OF INFORMATION SECTION ===
Model Family:     Seagate Barracuda 7200.10
Device Model:     ST3250310AS
Serial Number:    9RY17X2G
Firmware Version: 3.AAC
User Capacity:    250,059,350,016 bytes [250 GB]
Sector Size:      512 bytes logical/physical
Device is:        In smartctl database [for details use: -P show]
ATA Version is:   7
ATA Standard is:  Exact ATA specification draft version not indicated
Local Time is:    Sat Jul 29 10:07:17 2017 MSK
SMART support is: Available - device has SMART capability.
SMART support is: Enabled


SMART Attributes Data Structure revision number: 10
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME          FLAG     VALUE WORST THRESH TYPE      UPDATED  WHEN_FAILED RAW_VALUE
  1 Raw_Read_Error_Rate     0x000f   110   082   006    Pre-fail  Always       -       208897990
  3 Spin_Up_Time            0x0003   099   097   000    Pre-fail  Always       -       0
  4 Start_Stop_Count        0x0032   099   099   020    Old_age   Always       -       2032
  5 Reallocated_Sector_Ct   0x0033   100   100   036    Pre-fail  Always       -       0
  7 Seek_Error_Rate         0x000f   090   060   030    Pre-fail  Always       -       145392
  9 Power_On_Hours          0x0032   046   046   000    Old_age   Always       -       47552
 10 Spin_Retry_Count        0x0013   100   100   097    Pre-fail  Always       -       0
 12 Power_Cycle_Count       0x0032   099   099   020    Old_age   Always       -       2036
187 Reported_Uncorrect      0x0032   100   100   000    Old_age   Always       -       0
189 High_Fly_Writes         0x003a   078   078   000    Old_age   Always       -       22
190 Airflow_Temperature_Cel 0x0022   057   047   045    Old_age   Always       -       43 (Min/Max 42/44)
194 Temperature_Celsius     0x0022   043   053   000    Old_age   Always       -       43 (0 14 0 0)
195 Hardware_ECC_Recovered  0x001a   056   049   000    Old_age   Always       -       139832161
197 Current_Pending_Sector  0x0012   100   100   000    Old_age   Always       -       0
198 Offline_Uncorrectable   0x0010   100   100   000    Old_age   Offline      -       0
199 UDMA_CRC_Error_Count    0x003e   200   161   000    Old_age   Always       -       159614
200 Multi_Zone_Error_Rate   0x0000   100   253   000    Old_age   Offline      -       0
202 Data_Address_Mark_Errs  0x0032   100   253   000    Old_age   Always       -       0

 phyrdychg,

petav
()

Puppet. Вызвать module из-за пределов environments

На каждой площадке свою окружение (хосты и модули):

root@puppet:/etc/puppet# tree environments -L 1
environments
├── area1
├── area2
├── area3
└── area4
А есть, к примеру zabbixagent и bacula-fd он одинаков для всех площадок:
root@puppet:/etc/puppet# tree modules -L 1
modules
├── apt
├── bacula-fd
├── chocolatey
├── stdlib
└── zabbixagent
Задача: В окружениях areaX использовать модуль из /etc/puppet/modules (так сказать «Общий»). Возможно. Что конфигурировать? Как вызывать в манифестах?

 environments,

petav
()

Ippon. Nut. No supported devices found

Ippon Back Power Pro LCD 400/500/600/700/800

Jul 18 15:49:57 pbx kernel: [170053.223696] usb 2-2: new low-speed USB device number 3 using ohci-pci
Jul 18 15:49:57 pbx kernel: [170053.442343] usb 2-2: New USB device found, idVendor=06da, idProduct=ffff
Jul 18 15:49:57 pbx kernel: [170053.442357] usb 2-2: New USB device strings: Mfr=1, Product=2, SerialNumber=4
Jul 18 15:49:57 pbx kernel: [170053.442364] usb 2-2: Product: Offline UPS
Jul 18 15:49:57 pbx kernel: [170053.442370] usb 2-2: Manufacturer: PPC
Jul 18 15:49:57 pbx kernel: [170053.442374] usb 2-2: SerialNumber: 000000000   
Jul 18 15:49:57 pbx kernel: [170053.495382] hid-generic 0003:06DA:FFFF.0002: hiddev0,hidraw0: USB HID v1.00 Device [PPC Offline UPS] on usb-0000:00:02.0-2/input0
#cat /etc/nut/ups.conf
[Ippon]
driver = blazer_usb
port = auto
#port = /dev/ttyS0
#port = /dev/usb/hiddev0
desc = "Back Power Pro LCD 400/500/600/700/800"
ondelay=1
offdelay=60
# upsdrvctl start
Network UPS Tools - UPS driver controller 2.7.2
Network UPS Tools - Megatec/Q1 protocol USB driver 0.11 (2.7.2)
No supported devices found. Please check your device availability with 'lsusb'
and make sure you have an up-to-date version of NUT. If this does not help,
try running the driver with at least 'subdriver', 'vendorid' and 'productid'
options specified. Please refer to the man page for details about these options
(man 8 blazer_usb).

Driver failed to start (exit status=1)

 ,

petav
()

zabbix snmpv2 failed

zabbix говорит

 23549:20170713:062500.637 SNMP agent item "ifOutMulticastPkts.5" on host "router1.tech.com" failed: another network error, wait for 15 seconds
Прямая команда успешна
# snmpget -v2c -c public router1.tech.com ifOutMulticastPkts.5
IF-MIB::ifOutMulticastPkts.5 = Counter32: 0

Шаблон zabbix

 ,

petav
()

Asterisk провизия аппарата с несколькими учетными данными

Как бы все просто, в users.conf вяжем MAC аппарата c учеткой

[121](phones)
username=121
secret=qdfsdfsdwrsdf86
callerid=121 <121>
autoprov=yes
profile=YealinkT21PE2
macaddress=001565E36E4C
и если такой аппарат обратится за провизией, asterisk отдаст ему файл настройки.
#!version:1.0.0.1

### This file is the exported MAC-all.cfg.
account.1.enable = 1
account.1.password = qdfsdfsdwrsdf86
account.1.label = 
account.1.user_name = 115
созданный из шаблона
#!version:1.0.0.1

### This file is the exported MAC-all.cfg.
account.1.enable = 1
account.1.password = ${SECRET}
account.1.label = ${LABEL}
account.1.user_name = ${USERNAME}
А если платформа является радиобазой, то у нее есть много трубок
account.X.enable = 1
Какие тут варианты?!

 , provision

petav
()

Звонок в сеть со своего source

На компьютере три интерфейса:
eth0:

# ifconfig eth0 |grep "inet addr"
          inet addr:192.168.1.38  Bcast:192.168.1.255  Mask:255.255.255.0
tun0:
# ifconfig tun0 |grep "inet addr"
          inet addr:172.16.238.1  P-t-P:172.16.238.2  Mask:255.255.255.255
tun1:
# ifconfig tun1 |grep "inet addr"
          inet addr:172.16.206.127  P-t-P:172.16.206.127  Mask:255.255.255.255

За интерфейсом tun1 есть сети:

  • 192.168.206.0/24
  • 172.16.206.0/24

Задача при выходе трафика через локальные интерфейсы:

  • 192.168.1.38
  • 172.16.238.1

включать натацию трафика.

Я вот так это вижу:

iptables -t nat -D POSTROUTING -s 172.16.206.0/24 -d 172.16.238.0/24  -j SNAT --to-source 172.16.238.1
iptables -t nat -D POSTROUTING -s 172.16.206.0/24 -d 192.168.1.0/24  -j SNAT --to-source 192.168.1.38
iptables -t nat -D POSTROUTING -s 192.168.206.0/24 -d 172.16.238.0/24  -j SNAT --to-source 172.16.238.1
iptables -t nat -D POSTROUTING -s 192.168.206.0/24 -d 192.168.1.0/24  -j SNAT --to-source 192.168.1.38
Верно или есть что-то более локаничное?

 ,

petav
()

Микротик медленно пробрасывает 443 порт

Дано:

  • роутер ASUS
  • Скрость подключения к интернет 2Mb/s
  • Внешний порт 443 TCP проброшен на локальный порт компьтера 1195 TCP
  • По порту 443 tun openvpn туннель

iperf говорит про VPN туннель:

[  5] local 172.16.3.1 port 5001 connected with 172.16.3.4 port 47046
[  5]  0.0-12.9 sec  2.62 MBytes  1.70 Mbits/sec
[  5] local 172.16.3.1 port 5001 connected with 172.16.3.4 port 47049
[  5]  0.0-12.5 sec  2.50 MBytes  1.68 Mbits/sec
Нареканий нет (есть, но это к ширине канала в интернет, трафик не вмещается)

Меняем Asus на Mikrotik RB951Ui-2HnD и получаем скорсоть в VPN туннеле:

[  3] local 172.16.3.4 port 48122 connected with 172.16.3.1  port 5001
[ ID] Interval       Transfer     Bandwidth
[  3]  0.0-11.7 sec   896 KBytes   629 Kbits/sec

 , ,

petav
()

Debug puppet проблемы

При (вроде) верной настройке сервера и клиента, свой манифест хост клиента не видит. Получает каталог но он пустой, всегда не ставит пакеты mc, ntp, screen.

puppetmaster

# puppet  --version
3.8.4
# uname -a
Linux puppet 3.2.0-4-amd64 #1 SMP Debian 3.2.68-1+deb7u6 x86_64 GNU/Linux
# cat /etc/puppet/environments/souz/manifest/souz.pp

node 'souz' {

  $base_packages = [ 'mc', 'ntp', 'screen']
  package { $base_packages:
    ensure => present,
  }

}

puppet

# puppet  --version
3.8.7
# uname -a
Linux souz 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux

# cat /etc/puppet/puppet.conf
[main]
    # The Puppet log directory.
    # The default value is '$vardir/log'.
    logdir = /var/log/puppet

    # Where Puppet PID files are kept.
    # The default value is '$vardir/run'.
    rundir = /var/run/puppet

    # Where SSL certificates are kept.
    # The default value is '$confdir/ssl'.
    ssldir = $vardir/ssl
    pluginsync = true

[agent]
    # The file in which puppetd stores a list of the classes
    # associated with the retrieved configuratiion.  Can be loaded in
    # the separate ``puppet`` executable using the ``--loadclasses``
    # option.
    # The default value is '$confdir/classes.txt'.
    classfile = $vardir/classes.txt

    # Where puppetd caches the local configuration.  An
    # extension indicating the cache format is added automatically.
    # The default value is '$confdir/localconfig'.
    localconfig = $vardir/localconfig
    server=puppet.local
    report=true
    environment=souz

Запускает puppet agent

# puppet agent --verbose --test
Info: Retrieving pluginfacts
Info: Retrieving plugin
Info: Loading facts
Info: Caching catalog for souz
Info: Applying configuration version '1499021530'
Notice: Finished catalog run in 0.14 seconds
/var/log/syslog сказал
Jul  2 21:52:10 puppet puppet-master[30373]: Compiled catalog for souz in environment souz in 0.05 seconds
Jul  2 21:52:10 puppet puppet-master[30373]: (//souz/Puppet) Finished catalog run in 0.14 seconds
/var/log/puppet/masterhttp
[2017-07-02 21:52:05] 77.183.123.133 - - [02/Jul/2017:21:52:05 MSK] "GET /souz/node/souz?fail_on_404=true&transaction_uuid=33c7019b-2b88-4881-bce8-afda1179be7c HTTP/1.1" 200 4029
[2017-07-02 21:52:05] - -> /souz/node/souz?fail_on_404=true&transaction_uuid=33c7019b-2b88-4881-bce8-afda1179be7c
[2017-07-02 21:52:05] 77.183.123.133 - - [02/Jul/2017:21:52:05 MSK] "GET /souz/file_metadatas/pluginfacts?recurse=true&checksum_type=md5&links=manage&ignore=.svn&ignore=CVS&ignore=.git HTTP/1.1" 200 298
[2017-07-02 21:52:05] - -> /souz/file_metadatas/pluginfacts?recurse=true&checksum_type=md5&links=manage&ignore=.svn&ignore=CVS&ignore=.git
[2017-07-02 21:52:06] 77.183.123.133 - - [02/Jul/2017:21:52:06 MSK] "GET /souz/file_metadatas/plugins?recurse=true&checksum_type=md5&links=manage&ignore=.svn&ignore=CVS&ignore=.git HTTP/1.1" 200 32765
[2017-07-02 21:52:06] - -> /souz/file_metadatas/plugins?recurse=true&checksum_type=md5&links=manage&ignore=.svn&ignore=CVS&ignore=.git
[2017-07-02 21:52:10] 77.183.123.133 - - [02/Jul/2017:21:52:10 MSK] "POST /souz/catalog/souz HTTP/1.1" 200 566
[2017-07-02 21:52:10] - -> /souz/catalog/souzr
[2017-07-02 21:52:10] 77.183.123.133 - - [02/Jul/2017:21:52:10 MSK] "PUT /souz/report/souz HTTP/1.1" 200 22
[2017-07-02 21:52:10] - -> /souz/report/souz

 

petav
()

Goip host Unspecified status OK

При включени питания GoIP4 вижу

GOIP41/GOIP41             192.168.2.34                             D  No         No          A  5060     OK (7 ms)                                    
GOIP42/GOIP42             192.168.2.34                             D  No         No          A  5060     OK (8 ms)                                    
GOIP43/GOIP43             192.168.2.34                             D  No         No          A  5060     OK (8 ms)                                    
GOIP44/GOIP44             192.168.2.34                             D  No         No          A  5060     OK (211 ms)
После пары секунд уже так
GOIP41/GOIP41             (Unspecified)                            D  No         No          A  0        OK (7 ms)                                    
GOIP42/GOIP42             (Unspecified)                            D  No         No          A  0        OK (8 ms)                                    
GOIP43/GOIP43             (Unspecified)                            D  No         No          A  0        OK (8 ms)                                    
GOIP44/GOIP44             (Unspecified)                            D  No         No          A  0        OK (211 ms) 
Пока сам разбираюсь, кто сталкивался, черкните, от чего такое!

 ,

petav
()

Mysql AS

call2responsible.sql

SELECT IFNULL(
  (SELECT u.phone_crm_extension AS phone
    FROM vtiger_account AS acc
    LEFT JOIN vtiger_crmentity AS e ON e.crmid = acc.accountid
    LEFT JOIN vtiger_users AS u ON u.id = e.smownerid
    WHERE
     (acc.phone =7930
      OR acc.otherphone =7930
      OR acc.fax =7930)
      AND e.deleted = 0
      GROUP BY phone
      LIMIT 1),
  IFNULL(
    (SELECT u.phone_crm_extension AS phone
      FROM vtiger_contactdetails AS cd
      LEFT JOIN vtiger_crmentity AS e ON e.crmid = cd.contactid
      LEFT JOIN vtiger_users AS u ON u.id = e.smownerid
      WHERE
       (cd.phone =7930
        OR cd.mobile =7930
        OR cd.fax =7930)
        AND e.deleted =0
        GROUP BY phone
        LIMIT 1),
        IFNULL(
          (SELECT u.phone_crm_extension AS phone
            FROM vtiger_leadaddress
            AS la
            LEFT JOIN vtiger_crmentity AS e ON e.crmid = la.leadaddressid
            LEFT JOIN vtiger_users AS u ON u.id = e.smownerid WHERE(
              la.phone =7930
              OR la.mobile =7930
              OR la.fax =7930)
            AND e.deleted =0 GROUP BY phone
            LIMIT 1),
          '103'
         )
      )
);
Выдает
# mysql -u root -p'573351' vtigercrm < call2responsible.sql
IFNULL(
  (SELECT u.phone_crm_extension AS 'phone'
    FROM vtiger_account AS acc
    LEFT JOIN vtiger_crmentity AS e ON e.crmid = acc.accountid
    LEFT JOIN vtiger_users AS u ON u.id = e.smownerid
    WHERE
     (acc.phone =7930
      OR acc.other
199
а ожидается
phone
199
или просто
199
что бы к bash не прибегать. Подскажите?

 ,

petav
()

Pointing Alfresco Repository to a NAS vs SAN

Машинка с Alfresco крутится, система зарекомендовала себя пользуемся. Кончается место в репозитории. Стоит задача подмонтировать к /opt/alfresco-community/alf_data большее пространство и перенести туда данные:

alf_data
├── contentstore
├── contentstore.deleted
├── keystore
├── oouser
├── postgresql
├── solr4
└── solr4Backup
Там postgresql! Вопрос SAN|NAS, samba, iscsi, nfs что по лучше будет?

 , ,

petav
()

Годно ли ceph для HA вирт. машин?

Задача:

  • Сократить время простоя CRM 1C из-за отказа оборудования. Производить «прозрачно: (допускается выключение сервиса и загрузка в другом месте) обслуживание оборудования.

Решение:

  • Виртуализация
  • HA на уровне виртуальной машины

Технологии и оборудование:

  • Гипервизора виртуализации KVM (основной, резервный) - 2шт;
  • Массив для данных на каждом гипервизоре - mdadm, raid10, sas rpm 15000 4шт;
  • Распределенная файловая система ceph, прямой link bound (1Gb/s x 4) между узлами KVM;
  • Менеджер кластера (pacemaker + что-то еще в связке )

Годно? или DRBD? или на СХД потратиться?

 , ,

petav
()

Активировать Gnome VNC используя ssh

Имею Gnome

Linux debian 3.16.0-4-amd64 #1 SMP Debian 3.16.43-2 (2017-04-30) x86_64 GNU/Linux
PRETTY_NAME="Debian GNU/Linux 8 (jessie)"
NAME="Debian GNU/Linux"
VERSION_ID="8"
VERSION="8 (jessie)"
ID=debian
HOME_URL="http://www.debian.org/"
SUPPORT_URL="http://www.debian.org/support"
BUG_REPORT_URL="https://bugs.debian.org/
Требуется актвировать удаленное управление VNC. В наличии SSH. Где конфиг поправить?

 ,

petav
()

puppet групповых политик

Дано:

  • Несколько компьютеров Windows XP
  • Puppet

Необходимо:
С помощью puppet реплицировать преднастронные групповые политики на всех агентов.

Что для это уже есть?

 ,

petav
()

1С по протоколу RDP на linux

Кто нибудь экспериментирвал с этим: Сервер терминалов для 1С по протоколу RDP на linux: рекомендации по настройке с учетом опыта реальной эксплуатации? Что с пробросом принтеров? Что со скоростью отрисовки. Стоит ли? База файловая!

 , xordxrdp,

petav
()

tap не ходит трафик

Стартуем ovpn сервер

tls-server
daemon ovpn1
proto udp
port 1195
dev tap
comp-lzo
ca /usr/share/easy-rsa/keys/ca.crt
cert /usr/share/easy-rsa/keys/ovpn1.crt
key /usr/share/easy-rsa/keys/ovpn1.key
dh /usr/share/easy-rsa/keys/dh2048.pem
status /var/log/openvpn/ovpn1.log
log /var/log/openvpn/ovpn1.log
management 127.0.0.1 6001
script-security 2
up /etc/openvpn/braddif.sh
down /etc/openvpn/brdelif.sh
В итоге ovpn итерфейс в добаился в мост
# brctl show
bridge name     bridge id               STP enabled     interfaces
br0             8000.ee1b119301a1       no              tap0

Посылаю broadcast на tap0

 ping -b 192.168.0.255 -I tap0
ping: Warning: source address might be selected on device other than tap0.
PING 192.168.0.255 (192.168.0.255) from 192.168.206.200 tap0: 56(84) bytes of data.
From 192.168.206.200 icmp_seq=1 Destination Host Unreachable
From 192.168.206.200 icmp_seq=2 Destination Host Unreachable
From 192.168.206.200 icmp_seq=3 Destination Host Unreachable
From 192.168.206.200 icmp_seq=4 Destination Host Unreachable
From 192.168.206.200 icmp_seq=5 Destination Host Unreachable

Клиент Не вижу ниодного пакета на tap0

tcpdump -i tap0
Так же не вижу запросы DHCP клиента на интерфейсе сервера. Киньте мысль как диагностировать проблему.

 ,

petav
()

Не долго живет tap

При поднятии туннеля (--up=script.sh), загоняю интерфейс tap в существующий мост br0 скриптом:

#!/bin/sh

ifconfig $dev up
ip link set up dev $dev
brctl addif br0 $dev
ip link set up dev br0
Созданный интерфейс tap0 живет пару минут, потом entered disabled и туннель падает, вслед за интерфейсом:
May 28 16:56:05 pbx kernel: [537315.276478] device tap0 entered promiscuous mode
May 28 16:56:05 pbx kernel: [537315.276786] br0: port 1(tap0) entered forwarding state
May 28 16:56:05 pbx kernel: [537315.276836] br0: port 1(tap0) entered forwarding state
May 28 16:56:06 pbx kernel: [537316.274317] br0: port 1(tap0) entered forwarding state
May 28 16:56:09 pbx ntpd[10881]: Listen normally on 36 tap0 fe80::443e:3bff:fe23:4bd8 UDP 123
May 28 16:56:09 pbx ntpd[10881]: peers refreshed
May 28 16:58:05 pbx kernel: [537434.766200] br0: port 1(tap0) entered disabled state
May 28 16:58:05 pbx kernel: [537434.766457] device tap0 left promiscuous mode
May 28 16:58:05 pbx kernel: [537434.766508] br0: port 1(tap0) entered disabled state
May 28 16:58:07 pbx ntpd[10881]: Deleting interface #36 tap0, fe80::443e:3bff:fe23:4bd8#123, interface stats: received=0, sent=0, dropped=0, active_time=118 secs

На мосту br0 висит только DHCP. На tap0 пока нет соединений. brctl setfd br0 0 сделано.

 ,

petav
()

Пересобрать hash

Имеется hash

  $phone={
    '100' => { 'pass'    => "qwrsdf86",
               'mac'     => "00:15:65:e0:68:47",
               'profile' => "YealinkT21PE2",
             },
    '101' => { 'pass'    => "qwrsdf86",
               'mac'     => "00:15:65:e0:68:48",
               'profile' => "YealinkT21PE2",
             },
    '102' => { 'pass'    => "qwrsdf86",
               'mac'     => "00:15:65:e0:68:49",
               'profile' => "YealinkT21PE2",
             },
  }

Требуется поллучить такой вид
$vpn_name_key=["001565e06847", "001565e06848", "001565e06849"]

Пытаюсь пересобрат hash в array такой конструкцией

$vpn_name_key=[]
$phone.each |$index, $value| {
    $linemac = regsubst($value['mac'], ':', '', 'G')
    $vpn_name_key = $vpn_name_key + [$linemac]
  }
не собирается. Прошу подсказку

 

petav
()

replace string

Переменная:

  $phone={
    '100' => { 'pass'    => "123",
               'mac'     => "00:15:65:e0:68:47",
               'profile' => "YealinkT21PE2",
             },
    '101' => { 'pass'    => "123",
               'mac'     => "00:15:65:e0:68:47",
               'profile' => "YealinkT21PE2",
             },
    '102' => { 'pass'    => "123",
               'mac'     => "00:15:65:e0:68:47",
               'profile' => "YealinkT21PE2",
             },
  }

Шаблон:

<% @users.each do |val| -%>
[<%= val[0] %>](phones)
username=<%= val[0] %>
secret=<%= val[1]["pass"] %>
callerid=<%= val[0] %> <<%= val[0] %>>
autoprov=yes
profile=<%= val[1]["profile"] %>
macaddress=<%= val[1]["mac"] %>

<% end -%>

Задача у переменной
<%= val[1][«mac»] %>
убрать ":". т.е надо что бы
было 00:15:65:e0:68:47, стало 001565e06847

 

petav
()

Архитектура кода

Хочется передать переменную $psql при инициализации класса postgresql и использовать ее в postgresql::config

     3 node 'server.local' {

     30   $psql = {
     31     'db'     => 'dbname',
     32     'user'   => 'username',
     33     'passwd' => 'userpasswd',
     34   }

     38   class {'postgresql':}

     58 }
      1 class postgresql  {
      2 
      3   class { 'postgresql::install': }
      4   class { 'postgresql::service': }
      5   class { 'postgresql::config': }
      6 
      7 }
      1 class postgresql::config (
      2   $psql_db = 'dbname',
      3   $psql_user = 'username',
      4   $psql_passwd = 'userpasswd'
      5 ) {

     49 }

 

petav
()

RSS подписка на новые темы