You can subscribe to this list here.
2006 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
(2) |
Nov
(1) |
Dec
(20) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2007 |
Jan
(91) |
Feb
(111) |
Mar
(226) |
Apr
(65) |
May
(197) |
Jun
(202) |
Jul
(92) |
Aug
(87) |
Sep
(120) |
Oct
(133) |
Nov
(89) |
Dec
(155) |
2008 |
Jan
(251) |
Feb
(136) |
Mar
(174) |
Apr
(149) |
May
(56) |
Jun
(32) |
Jul
(36) |
Aug
(171) |
Sep
(245) |
Oct
(244) |
Nov
(218) |
Dec
(272) |
2009 |
Jan
(113) |
Feb
(119) |
Mar
(192) |
Apr
(117) |
May
(93) |
Jun
(46) |
Jul
(80) |
Aug
(54) |
Sep
(109) |
Oct
(70) |
Nov
(145) |
Dec
(110) |
2010 |
Jan
(137) |
Feb
(87) |
Mar
(45) |
Apr
(157) |
May
(58) |
Jun
(99) |
Jul
(188) |
Aug
(136) |
Sep
(101) |
Oct
(100) |
Nov
(61) |
Dec
(60) |
2011 |
Jan
(84) |
Feb
(43) |
Mar
(70) |
Apr
(17) |
May
(69) |
Jun
(28) |
Jul
(43) |
Aug
(21) |
Sep
(151) |
Oct
(120) |
Nov
(84) |
Dec
(101) |
2012 |
Jan
(119) |
Feb
(82) |
Mar
(70) |
Apr
(115) |
May
(66) |
Jun
(131) |
Jul
(70) |
Aug
(65) |
Sep
(66) |
Oct
(86) |
Nov
(197) |
Dec
(81) |
2013 |
Jan
(65) |
Feb
(48) |
Mar
(32) |
Apr
(68) |
May
(98) |
Jun
(59) |
Jul
(41) |
Aug
(52) |
Sep
(42) |
Oct
(37) |
Nov
(10) |
Dec
(27) |
2014 |
Jan
(61) |
Feb
(34) |
Mar
(30) |
Apr
(52) |
May
(45) |
Jun
(40) |
Jul
(28) |
Aug
(9) |
Sep
(39) |
Oct
(69) |
Nov
(55) |
Dec
(19) |
2015 |
Jan
(13) |
Feb
(21) |
Mar
(5) |
Apr
(14) |
May
(30) |
Jun
(51) |
Jul
(31) |
Aug
(12) |
Sep
(29) |
Oct
(15) |
Nov
(24) |
Dec
(16) |
2016 |
Jan
(62) |
Feb
(76) |
Mar
(30) |
Apr
(43) |
May
(46) |
Jun
(62) |
Jul
(21) |
Aug
(49) |
Sep
(67) |
Oct
(27) |
Nov
(26) |
Dec
(38) |
2017 |
Jan
(7) |
Feb
(12) |
Mar
(69) |
Apr
(59) |
May
(54) |
Jun
(40) |
Jul
(76) |
Aug
(82) |
Sep
(92) |
Oct
(51) |
Nov
(32) |
Dec
(30) |
2018 |
Jan
(22) |
Feb
(25) |
Mar
(34) |
Apr
(35) |
May
(37) |
Jun
(21) |
Jul
(69) |
Aug
(55) |
Sep
(17) |
Oct
(67) |
Nov
(9) |
Dec
(5) |
2019 |
Jan
(19) |
Feb
(12) |
Mar
(15) |
Apr
(19) |
May
|
Jun
(27) |
Jul
(27) |
Aug
(25) |
Sep
(25) |
Oct
(27) |
Nov
(10) |
Dec
(14) |
2020 |
Jan
(22) |
Feb
(20) |
Mar
(36) |
Apr
(40) |
May
(52) |
Jun
(35) |
Jul
(21) |
Aug
(32) |
Sep
(71) |
Oct
(27) |
Nov
(11) |
Dec
(16) |
2021 |
Jan
(16) |
Feb
(21) |
Mar
(21) |
Apr
(27) |
May
(17) |
Jun
|
Jul
(2) |
Aug
(22) |
Sep
(23) |
Oct
(7) |
Nov
(11) |
Dec
(28) |
2022 |
Jan
(23) |
Feb
(18) |
Mar
(9) |
Apr
(15) |
May
(15) |
Jun
(7) |
Jul
(8) |
Aug
(15) |
Sep
(1) |
Oct
|
Nov
(11) |
Dec
(10) |
2023 |
Jan
(14) |
Feb
(10) |
Mar
(11) |
Apr
(13) |
May
(2) |
Jun
(30) |
Jul
(1) |
Aug
(15) |
Sep
(13) |
Oct
(3) |
Nov
(25) |
Dec
(5) |
2024 |
Jan
(3) |
Feb
(10) |
Mar
(9) |
Apr
|
May
(1) |
Jun
(15) |
Jul
(7) |
Aug
(10) |
Sep
(3) |
Oct
(8) |
Nov
(6) |
Dec
(15) |
2025 |
Jan
(3) |
Feb
(1) |
Mar
(7) |
Apr
(5) |
May
(13) |
Jun
(16) |
Jul
(1) |
Aug
(6) |
Sep
|
Oct
|
Nov
|
Dec
|
From: Lonnie A. <li...@lo...> - 2021-08-14 16:03:32
|
Announcing AstLinux Pre-Release: astlinux-1.4-5218-214c68 Key new features: -- 2.5G ethernet support for Intel i225 (igc) and Realtek RTL8125 (r8125) NICs -- '13se' version now uses Asterisk 13.38.3, "Security Fixes Only" version for Asterisk 13 ** The AstLinux Team is regularly upgrading packages containing security and bug fixes as well as adding new features of our own. -- Linux Kernel 4.19.200 (version bump), security and bug fixes -- ixgbe, enable the Intel 10-Gigabit Ethernet Network Driver -- igc, backport from linux-5.4.136, Intel i225 2.5-Gigabit Ethernet Network Driver -- r8125, version 9.005.06, Realtek RTL8125 2.5-Gigabit Ethernet Network Driver -- libcurl (curl) version bump to 7.78.0, several security fixes -- prosody, version bump to 0.11.10, security fix: CVE-2021-37601 -- acme-client, version bump to 2.9.0 -- Monit, version bump to 5.28.1 -- Asterisk 13.38.3 ('13se' version bump) Latest Asterisk 13.x "Security Fixes Only" version, built --without-pjproject -- Asterisk 13.38.3 (version bump) and 16.20.0 (version bump) New Asterisk 16 applications: WaitForCondition, Reload, StoreDTMF -- Complete Pre-Release ChangeLog: https://s3.amazonaws.com/beta.astlinux-project/astlinux-changelog/ChangeLog.txt The "AstLinux Pre-Release ChangeLog" and "Pre-Release Repository URL" entries can be found under the "Development" tab of the AstLinux Project web site ... AstLinux Project -> Development https://www.astlinux-project.org/dev.html AstLinux Team |
From: Lonnie A. <li...@lo...> - 2021-08-14 15:51:20
|
Hey Michael, Looking forward to hearing how acme-dns works for you. AstLinux's acme-client (acme.sh) has a plugin for acme-dns, usage: --dns dns_acmedns The acme-dns author "Joona Hoikkala" wrote an EFF article [1] "Securing the Automation of ACME DNS Challenge Validation" BTW, I would use the acme-dns Github page [2] for info rather then the nethserver wiki article you referenced. Lonnie [1] https://www.eff.org/deeplinks/2018/02/technical-deep-dive-securing-automation-acme-dns-challenge-validation [2] https://github.com/joohoi/acme-dns/ > On Aug 13, 2021, at 10:33 PM, Michael Knill <mic...@ip...> wrote: > > Actually decided that I will give acme-dns a try: https://wiki.nethserver.org/doku.php?id=userguide:let_s_encrypt_acme-dns > Will report how I go. > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply to: AstLinux List <ast...@li...> > Date: Saturday, 14 August 2021 at 12:29 pm > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Securing DNS API Keys when using ACME > > Hi Group > > I'm looking to move away from Wildcard SSL and move back to ACME Lets Encrypt to ensure a unique cert for all our systems. The reason is that we have built our new Mobile Softphone solution which is heavily reliant heavily on TLS for provisioning and SIP. > > As such, I want to set this up but I am concerned that if one of our systems was compromised (we have quite a few now), this will allow an attacker to do bad stuff to our DNS (currently GoDaddy). I understand that some DNS providers may be able to restrict what you can do with the API but just wondering if anyone has any better ideas? > > Regards > > Michael Knill > Managing Director > > D: +61 2 6189 1360 > P: +61 2 6140 4656 > E: mic...@ip... > W: ipcsolutions.com.au > > <image001.png> > Smarter Business Communications > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-08-14 03:33:36
|
Actually decided that I will give acme-dns a try: https://wiki.nethserver.org/doku.php?id=userguide:let_s_encrypt_acme-dns Will report how I go. Regards Michael Knill From: Michael Knill <mic...@ip...> Reply to: AstLinux List <ast...@li...> Date: Saturday, 14 August 2021 at 12:29 pm To: AstLinux List <ast...@li...> Subject: [Astlinux-users] Securing DNS API Keys when using ACME Hi Group I'm looking to move away from Wildcard SSL and move back to ACME Lets Encrypt to ensure a unique cert for all our systems. The reason is that we have built our new Mobile Softphone solution which is heavily reliant heavily on TLS for provisioning and SIP. As such, I want to set this up but I am concerned that if one of our systems was compromised (we have quite a few now), this will allow an attacker to do bad stuff to our DNS (currently GoDaddy). I understand that some DNS providers may be able to restrict what you can do with the API but just wondering if anyone has any better ideas? Regards Michael Knill Managing Director D: +61 2 6189 1360 P: +61 2 6140 4656 E: mic...@ip...<mailto:mic...@ip...> W: ipcsolutions.com.au<https://ipcsolutions.com.au/> [IPC Solutions] Smarter Business Communications |
From: Michael K. <mic...@ip...> - 2021-08-14 02:28:21
|
Hi Group I'm looking to move away from Wildcard SSL and move back to ACME Lets Encrypt to ensure a unique cert for all our systems. The reason is that we have built our new Mobile Softphone solution which is heavily reliant heavily on TLS for provisioning and SIP. As such, I want to set this up but I am concerned that if one of our systems was compromised (we have quite a few now), this will allow an attacker to do bad stuff to our DNS (currently GoDaddy). I understand that some DNS providers may be able to restrict what you can do with the API but just wondering if anyone has any better ideas? Regards Michael Knill Managing Director D: +61 2 6189 1360 P: +61 2 6140 4656 E: mic...@ip...<mailto:mic...@ip...> W: ipcsolutions.com.au<https://ipcsolutions.com.au/> [IPC Solutions] Smarter Business Communications |
From: Lonnie A. <li...@lo...> - 2021-07-13 12:40:34
|
Announcing AstLinux Release: 1.4.3 More Info: AstLinux Project https://www.astlinux-project.org/ AstLinux 1.4.3 Highlights: * Asterisk Versions: 13.29.2, 13.38.2, 16.19.0 * Linux Kernel 4.19.196, security and bug fixes * RUNNIX, version bump to runnix-0.6.4 * OpenSSL, version bump to 1.1.1k, security fixes * OpenVPN, version bump to 2.4.11 * WireGuard VPN, module 1.0.20210606 (version bump), tools 1.0.20210424 (version bump) * libcurl (curl) version bump to 7.77.0 * libxml2, version bump to 2.9.12 * LibreTLS, new package, version 3.3.3p1, a port of libtls from LibreSSL to OpenSSL * chrony, version bump to 4.1 * Monit, version bump to 5.28.0 * msmtp, version bump to 1.8.15, switch TLS support to libtls (LibreTLS via OpenSSL) * prosody, major version bump to 0.11.9 * vnStat, version bump to 2.7 * zabbix, version bump to 4.0.31 * phoneprov-tools, add support for `@CID_NUM@` and `@CID_NUM1@` to `@CID_NUM6@` template variables. * Package upgrades providing important security and bug fixes Full ChangeLog: https://raw.githubusercontent.com/astlinux-project/astlinux/1.4.3/docs/ChangeLog.txt All users are encouraged to upgrade, read the ChangeLog for the details. AstLinux Team |
From: Lonnie A. <li...@lo...> - 2021-07-02 16:41:34
|
Announcing AstLinux Pre-Release: astlinux-1.4-5177-b91b86 Release Candidate1 pre-1.4.3, please report any issues, ASAP. ** The AstLinux Team is regularly upgrading packages containing security and bug fixes as well as adding new features of our own. -- Linux Kernel 4.19.196 (version bump), security and bug fixes. Reverts many @umn.edu unsuitable commits. -- initrd, check for ASTURW /etc/inittab and copy it forward so the linuxrc's /sbin/init can use it. Note: AstLinux 1.3.10 through 1.4.2 ignored any user edits to the /etc/inittab file, rather it always used the default /etc/inittab file (the default is what most users want anyway). Now edits to the /etc/inittab file are honored again, as they were before AstLinux 1.3.10. -- RUNNIX, version bump to runnix-0.6.4, with Linux Kernel 4.19.196, e2fsprogs 1.46.2 -- OpenSSL, version bump to 1.1.1k, security fixes: CVE-2021-3449, CVE-2021-3450 -- WireGuard VPN, module 1.0.20210606 (version bump), tools 1.0.20210424 (version bump) -- OpenVPN, version bump to 2.4.11, security fix: CVE-2020-15078 -- libcurl (curl) version bump to 7.77.0, security fixes: CVE-2021-22876, CVE-2021-22890, CVE-2021-22897, CVE-2021-22898, CVE-2021-22901 -- libxml2, version bump to 2.9.12, security fix: CVE-2021-3541, plus "an awful lot of serious bug fixes" -- LibreTLS, new package, version 3.3.3p1, a port of libtls from LibreSSL to OpenSSL -- chrony, version bump to 4.1 -- Monit, version bump to 5.28.0 -- vnStat, version bump to 2.7 -- prosody, major version bump to 0.11.9 Security fixes: CVE-2021-32917, CVE-2021-32918, CVE-2021-32919, CVE-2021-32920, CVE-2021-32921 -- Asterisk 13.29.2 ('13se' no change) Older than latest Asterisk 13.x version but more tested, built --without-pjproject -- Asterisk 13.38.2 (no change) and 16.19.0 (version bump) -- Complete Pre-Release ChangeLog: https://s3.amazonaws.com/beta.astlinux-project/astlinux-changelog/ChangeLog.txt The "AstLinux Pre-Release ChangeLog" and "Pre-Release Repository URL" entries can be found under the "Development" tab of the AstLinux Project web site ... AstLinux Project -> Development https://www.astlinux-project.org/dev.html AstLinux Team |
From: Lonnie A. <li...@lo...> - 2021-05-24 02:11:12
|
Yes, but test for sure. Lonnie > On May 23, 2021, at 8:37 PM, Michael Knill <mic...@ip...> wrote: > > You mentioned to not do 'ip link set dev wg0 down && ip link set dev wg0' up as that will cause problems only a reboot can fix. > But its ok to do: > ip link set dev eth0 down > sleep 4 > ip link set dev eth0 up > ? > > Just confirming. > > Regards > Michael Knill > > On 24/5/21, 11:30 am, "Lonnie Abelbeck" <li...@lo...> wrote: > >> Ah so it was just wg0 that you cant do this for? > > There is only wg0 for the standard WG configuration. > > Not sure what you are asking. > > Lonnie > > >> On May 23, 2021, at 8:25 PM, Michael Knill <mic...@ip...> wrote: >> >> Ah so it was just wg0 that you cant do this for? >> >> Regards >> Michael Knill >> >> On 24/5/21, 9:31 am, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> >>> On May 23, 2021, at 5:42 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Just thinking about it, I don't think I ever tried a Reload as I thought a Restart would effectively do the same thing. Interesting that it appears to not be the case. >> >> "Restart" always works, destroys wg0 and builds it again, restarts the firewall, etc., but effects active WG tunnels and some may stall for 20 seconds during the process. >> >> "Reload" is optimized to not effect active WG tunnels and only apply add/remove/edits to the peers. Very quick. >> >> >>> PS is there anything I can do to restart a NIC e.g. drop link and bring up again? I have had some issues with Wireguard when behind a firewall that this fixes, albeit possibly breaking other things? >>> Note the problem is actually the firewall not Wireguard and dropping the link clears the firewall translation table so it then works. >> >> Example: toggle "eth0" link >> -- >> ip link set dev eth0 down >> sleep 4 >> ip link set dev eth0 up >> -- >> Test to make sure it works as expected. >> >> In AstLinux pulling the network cable and re-inserting it should always work, the above should do the same from inside. >> >> >> Lonnie >> >> >> >>> Regards >>> Michael Knill >>> >>> On 24/5/21, 7:42 am, "Michael Knill" <mic...@ip...> wrote: >>> >>> Thanks Lonnie. I will test this next time >>> >>> Regards >>> Michael Knill >>> >>> On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> Hi Michael, >>> >>> There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. >>> >>> A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. >>> >>> Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: >>> -- >>> service wireguard reload >>> -- >>> >>> Again, NEVER do: >>> -- >>> service network restart >>> -- and/or -- >>> ip link set dev wg0 down && ip link set dev wg0 up >>> -- >>> as that will cause problems only a reboot can fix. >>> >>> >>> Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. >>> >>> >>> Lonnie >>> >>> [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html >>> >>> >>> >>> >>>> On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Hmm same problem again with two of my sites. >>>> Only one of the two Wireguard VPN's are down. I have tried the following: >>>> arno-iptables-firewall restart >>>> service network restart >>>> pppoe-restart >>>> ip link set dev wg0 down & ip link set dev wg0 up >>>> >>>> All to no avail. Any other ideas before I reboot? >>>> PS there is no failover configured for this site so I don't think MTU is the issue. >>>> >>>> Regards >>>> Michael Knill >>>> >>>> On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: >>>> >>>> Thanks. Guess I will need to test it out. >>>> >>>> Regards >>>> Michael Knill >>>> >>>> On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>>> >>>> While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. >>>> >>>> It would be good to know what the precise answer is. >>>> >>>> Lonnie >>>> >>>> >>>>> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >>>>> >>>>> Thanks Lonnie. >>>>> >>>>> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >>>>> Ultimately it would be the same eventually but there would be a migration period. >>>>> >>>>> Regards >>>>> Michael Knill >>>>> >>>>> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>>>> >>>>> I haven't seen any issues with a WG MTU of 1340, yet anyway. >>>>> >>>>> Lonnie >>>>> >>>>> >>>>>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>>>>> >>>>>> Thanks Lonnie >>>>>> >>>>>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>>>>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>>>>> >>>>>> Regards >>>>>> Michael Knill >>>>>> >>>>>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>>>>> >>>>>> Hi Michael, >>>>>> >>>>>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>>>>> >>>>>> I don't recall later WireGuard versions having any fixes for what you are describing. >>>>>> >>>>>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>>>>> >>>>>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>>>>> >>>>>> Lonnie >>>>>> >>>>>> >>>>>> >>>>>> >>>>>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>>>>> >>>>>>> Hi Group >>>>>>> >>>>>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>>>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>>>>> Any ideas? >>>>>>> >>>>>>> Regards >>>>>>> Michael Knill >>>>>>> _______________________________________________ >>>>>>> Astlinux-users mailing list >>>>>>> Ast...@li... >>>>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>>>> >>>>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>>> >>>>>> >>>>>> >>>>>> _______________________________________________ >>>>>> Astlinux-users mailing list >>>>>> Ast...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>>> >>>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>>> >>>>>> >>>>>> _______________________________________________ >>>>>> Astlinux-users mailing list >>>>>> Ast...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>>> >>>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>> >>>>> >>>>> >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>> >>>>> >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-24 01:38:03
|
You mentioned to not do 'ip link set dev wg0 down && ip link set dev wg0' up as that will cause problems only a reboot can fix. But its ok to do: ip link set dev eth0 down sleep 4 ip link set dev eth0 up ? Just confirming. Regards Michael Knill On 24/5/21, 11:30 am, "Lonnie Abelbeck" <li...@lo...> wrote: > Ah so it was just wg0 that you cant do this for? There is only wg0 for the standard WG configuration. Not sure what you are asking. Lonnie > On May 23, 2021, at 8:25 PM, Michael Knill <mic...@ip...> wrote: > > Ah so it was just wg0 that you cant do this for? > > Regards > Michael Knill > > On 24/5/21, 9:31 am, "Lonnie Abelbeck" <li...@lo...> wrote: > > >> On May 23, 2021, at 5:42 PM, Michael Knill <mic...@ip...> wrote: >> >> Just thinking about it, I don't think I ever tried a Reload as I thought a Restart would effectively do the same thing. Interesting that it appears to not be the case. > > "Restart" always works, destroys wg0 and builds it again, restarts the firewall, etc., but effects active WG tunnels and some may stall for 20 seconds during the process. > > "Reload" is optimized to not effect active WG tunnels and only apply add/remove/edits to the peers. Very quick. > > >> PS is there anything I can do to restart a NIC e.g. drop link and bring up again? I have had some issues with Wireguard when behind a firewall that this fixes, albeit possibly breaking other things? >> Note the problem is actually the firewall not Wireguard and dropping the link clears the firewall translation table so it then works. > > Example: toggle "eth0" link > -- > ip link set dev eth0 down > sleep 4 > ip link set dev eth0 up > -- > Test to make sure it works as expected. > > In AstLinux pulling the network cable and re-inserting it should always work, the above should do the same from inside. > > > Lonnie > > > >> Regards >> Michael Knill >> >> On 24/5/21, 7:42 am, "Michael Knill" <mic...@ip...> wrote: >> >> Thanks Lonnie. I will test this next time >> >> Regards >> Michael Knill >> >> On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> Hi Michael, >> >> There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. >> >> A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. >> >> Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: >> -- >> service wireguard reload >> -- >> >> Again, NEVER do: >> -- >> service network restart >> -- and/or -- >> ip link set dev wg0 down && ip link set dev wg0 up >> -- >> as that will cause problems only a reboot can fix. >> >> >> Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. >> >> >> Lonnie >> >> [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html >> >> >> >> >>> On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Hmm same problem again with two of my sites. >>> Only one of the two Wireguard VPN's are down. I have tried the following: >>> arno-iptables-firewall restart >>> service network restart >>> pppoe-restart >>> ip link set dev wg0 down & ip link set dev wg0 up >>> >>> All to no avail. Any other ideas before I reboot? >>> PS there is no failover configured for this site so I don't think MTU is the issue. >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: >>> >>> Thanks. Guess I will need to test it out. >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. >>> >>> It would be good to know what the precise answer is. >>> >>> Lonnie >>> >>> >>>> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Thanks Lonnie. >>>> >>>> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >>>> Ultimately it would be the same eventually but there would be a migration period. >>>> >>>> Regards >>>> Michael Knill >>>> >>>> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>>> >>>> I haven't seen any issues with a WG MTU of 1340, yet anyway. >>>> >>>> Lonnie >>>> >>>> >>>>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>>>> >>>>> Thanks Lonnie >>>>> >>>>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>>>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>>>> >>>>> Regards >>>>> Michael Knill >>>>> >>>>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>>>> >>>>> Hi Michael, >>>>> >>>>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>>>> >>>>> I don't recall later WireGuard versions having any fixes for what you are describing. >>>>> >>>>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>>>> >>>>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>>>> >>>>> Lonnie >>>>> >>>>> >>>>> >>>>> >>>>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>>>> >>>>>> Hi Group >>>>>> >>>>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>>>> Any ideas? >>>>>> >>>>>> Regards >>>>>> Michael Knill >>>>>> _______________________________________________ >>>>>> Astlinux-users mailing list >>>>>> Ast...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>>> >>>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>> >>>>> >>>>> >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>> >>>>> >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2021-05-24 01:29:59
|
> Ah so it was just wg0 that you cant do this for? There is only wg0 for the standard WG configuration. Not sure what you are asking. Lonnie > On May 23, 2021, at 8:25 PM, Michael Knill <mic...@ip...> wrote: > > Ah so it was just wg0 that you cant do this for? > > Regards > Michael Knill > > On 24/5/21, 9:31 am, "Lonnie Abelbeck" <li...@lo...> wrote: > > >> On May 23, 2021, at 5:42 PM, Michael Knill <mic...@ip...> wrote: >> >> Just thinking about it, I don't think I ever tried a Reload as I thought a Restart would effectively do the same thing. Interesting that it appears to not be the case. > > "Restart" always works, destroys wg0 and builds it again, restarts the firewall, etc., but effects active WG tunnels and some may stall for 20 seconds during the process. > > "Reload" is optimized to not effect active WG tunnels and only apply add/remove/edits to the peers. Very quick. > > >> PS is there anything I can do to restart a NIC e.g. drop link and bring up again? I have had some issues with Wireguard when behind a firewall that this fixes, albeit possibly breaking other things? >> Note the problem is actually the firewall not Wireguard and dropping the link clears the firewall translation table so it then works. > > Example: toggle "eth0" link > -- > ip link set dev eth0 down > sleep 4 > ip link set dev eth0 up > -- > Test to make sure it works as expected. > > In AstLinux pulling the network cable and re-inserting it should always work, the above should do the same from inside. > > > Lonnie > > > >> Regards >> Michael Knill >> >> On 24/5/21, 7:42 am, "Michael Knill" <mic...@ip...> wrote: >> >> Thanks Lonnie. I will test this next time >> >> Regards >> Michael Knill >> >> On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> Hi Michael, >> >> There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. >> >> A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. >> >> Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: >> -- >> service wireguard reload >> -- >> >> Again, NEVER do: >> -- >> service network restart >> -- and/or -- >> ip link set dev wg0 down && ip link set dev wg0 up >> -- >> as that will cause problems only a reboot can fix. >> >> >> Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. >> >> >> Lonnie >> >> [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html >> >> >> >> >>> On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Hmm same problem again with two of my sites. >>> Only one of the two Wireguard VPN's are down. I have tried the following: >>> arno-iptables-firewall restart >>> service network restart >>> pppoe-restart >>> ip link set dev wg0 down & ip link set dev wg0 up >>> >>> All to no avail. Any other ideas before I reboot? >>> PS there is no failover configured for this site so I don't think MTU is the issue. >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: >>> >>> Thanks. Guess I will need to test it out. >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. >>> >>> It would be good to know what the precise answer is. >>> >>> Lonnie >>> >>> >>>> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Thanks Lonnie. >>>> >>>> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >>>> Ultimately it would be the same eventually but there would be a migration period. >>>> >>>> Regards >>>> Michael Knill >>>> >>>> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>>> >>>> I haven't seen any issues with a WG MTU of 1340, yet anyway. >>>> >>>> Lonnie >>>> >>>> >>>>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>>>> >>>>> Thanks Lonnie >>>>> >>>>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>>>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>>>> >>>>> Regards >>>>> Michael Knill >>>>> >>>>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>>>> >>>>> Hi Michael, >>>>> >>>>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>>>> >>>>> I don't recall later WireGuard versions having any fixes for what you are describing. >>>>> >>>>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>>>> >>>>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>>>> >>>>> Lonnie >>>>> >>>>> >>>>> >>>>> >>>>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>>>> >>>>>> Hi Group >>>>>> >>>>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>>>> Any ideas? >>>>>> >>>>>> Regards >>>>>> Michael Knill >>>>>> _______________________________________________ >>>>>> Astlinux-users mailing list >>>>>> Ast...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>>> >>>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>> >>>>> >>>>> >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>>> >>>>> >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-24 01:25:22
|
Ah so it was just wg0 that you cant do this for? Regards Michael Knill On 24/5/21, 9:31 am, "Lonnie Abelbeck" <li...@lo...> wrote: > On May 23, 2021, at 5:42 PM, Michael Knill <mic...@ip...> wrote: > > Just thinking about it, I don't think I ever tried a Reload as I thought a Restart would effectively do the same thing. Interesting that it appears to not be the case. "Restart" always works, destroys wg0 and builds it again, restarts the firewall, etc., but effects active WG tunnels and some may stall for 20 seconds during the process. "Reload" is optimized to not effect active WG tunnels and only apply add/remove/edits to the peers. Very quick. > PS is there anything I can do to restart a NIC e.g. drop link and bring up again? I have had some issues with Wireguard when behind a firewall that this fixes, albeit possibly breaking other things? > Note the problem is actually the firewall not Wireguard and dropping the link clears the firewall translation table so it then works. Example: toggle "eth0" link -- ip link set dev eth0 down sleep 4 ip link set dev eth0 up -- Test to make sure it works as expected. In AstLinux pulling the network cable and re-inserting it should always work, the above should do the same from inside. Lonnie > Regards > Michael Knill > > On 24/5/21, 7:42 am, "Michael Knill" <mic...@ip...> wrote: > > Thanks Lonnie. I will test this next time > > Regards > Michael Knill > > On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > Hi Michael, > > There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. > > A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. > > Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: > -- > service wireguard reload > -- > > Again, NEVER do: > -- > service network restart > -- and/or -- > ip link set dev wg0 down && ip link set dev wg0 up > -- > as that will cause problems only a reboot can fix. > > > Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. > > > Lonnie > > [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html > > > > >> On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: >> >> Hmm same problem again with two of my sites. >> Only one of the two Wireguard VPN's are down. I have tried the following: >> arno-iptables-firewall restart >> service network restart >> pppoe-restart >> ip link set dev wg0 down & ip link set dev wg0 up >> >> All to no avail. Any other ideas before I reboot? >> PS there is no failover configured for this site so I don't think MTU is the issue. >> >> Regards >> Michael Knill >> >> On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: >> >> Thanks. Guess I will need to test it out. >> >> Regards >> Michael Knill >> >> On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. >> >> It would be good to know what the precise answer is. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie. >>> >>> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >>> Ultimately it would be the same eventually but there would be a migration period. >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> I haven't seen any issues with a WG MTU of 1340, yet anyway. >>> >>> Lonnie >>> >>> >>>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Thanks Lonnie >>>> >>>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>>> >>>> Regards >>>> Michael Knill >>>> >>>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>>> >>>> Hi Michael, >>>> >>>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>>> >>>> I don't recall later WireGuard versions having any fixes for what you are describing. >>>> >>>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>>> >>>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>>> >>>> Lonnie >>>> >>>> >>>> >>>> >>>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>>> >>>>> Hi Group >>>>> >>>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>>> Any ideas? >>>>> >>>>> Regards >>>>> Michael Knill >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2021-05-23 23:31:06
|
> On May 23, 2021, at 5:42 PM, Michael Knill <mic...@ip...> wrote: > > Just thinking about it, I don't think I ever tried a Reload as I thought a Restart would effectively do the same thing. Interesting that it appears to not be the case. "Restart" always works, destroys wg0 and builds it again, restarts the firewall, etc., but effects active WG tunnels and some may stall for 20 seconds during the process. "Reload" is optimized to not effect active WG tunnels and only apply add/remove/edits to the peers. Very quick. > PS is there anything I can do to restart a NIC e.g. drop link and bring up again? I have had some issues with Wireguard when behind a firewall that this fixes, albeit possibly breaking other things? > Note the problem is actually the firewall not Wireguard and dropping the link clears the firewall translation table so it then works. Example: toggle "eth0" link -- ip link set dev eth0 down sleep 4 ip link set dev eth0 up -- Test to make sure it works as expected. In AstLinux pulling the network cable and re-inserting it should always work, the above should do the same from inside. Lonnie > Regards > Michael Knill > > On 24/5/21, 7:42 am, "Michael Knill" <mic...@ip...> wrote: > > Thanks Lonnie. I will test this next time > > Regards > Michael Knill > > On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > Hi Michael, > > There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. > > A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. > > Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: > -- > service wireguard reload > -- > > Again, NEVER do: > -- > service network restart > -- and/or -- > ip link set dev wg0 down && ip link set dev wg0 up > -- > as that will cause problems only a reboot can fix. > > > Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. > > > Lonnie > > [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html > > > > >> On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: >> >> Hmm same problem again with two of my sites. >> Only one of the two Wireguard VPN's are down. I have tried the following: >> arno-iptables-firewall restart >> service network restart >> pppoe-restart >> ip link set dev wg0 down & ip link set dev wg0 up >> >> All to no avail. Any other ideas before I reboot? >> PS there is no failover configured for this site so I don't think MTU is the issue. >> >> Regards >> Michael Knill >> >> On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: >> >> Thanks. Guess I will need to test it out. >> >> Regards >> Michael Knill >> >> On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. >> >> It would be good to know what the precise answer is. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie. >>> >>> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >>> Ultimately it would be the same eventually but there would be a migration period. >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> I haven't seen any issues with a WG MTU of 1340, yet anyway. >>> >>> Lonnie >>> >>> >>>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Thanks Lonnie >>>> >>>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>>> >>>> Regards >>>> Michael Knill >>>> >>>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>>> >>>> Hi Michael, >>>> >>>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>>> >>>> I don't recall later WireGuard versions having any fixes for what you are describing. >>>> >>>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>>> >>>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>>> >>>> Lonnie >>>> >>>> >>>> >>>> >>>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>>> >>>>> Hi Group >>>>> >>>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>>> Any ideas? >>>>> >>>>> Regards >>>>> Michael Knill >>>>> _______________________________________________ >>>>> Astlinux-users mailing list >>>>> Ast...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>>> >>>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>>> >>>> >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-23 22:43:05
|
Just thinking about it, I don't think I ever tried a Reload as I thought a Restart would effectively do the same thing. Interesting that it appears to not be the case. PS is there anything I can do to restart a NIC e.g. drop link and bring up again? I have had some issues with Wireguard when behind a firewall that this fixes, albeit possibly breaking other things? Note the problem is actually the firewall not Wireguard and dropping the link clears the firewall translation table so it then works. Regards Michael Knill On 24/5/21, 7:42 am, "Michael Knill" <mic...@ip...> wrote: Thanks Lonnie. I will test this next time Regards Michael Knill On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: Hi Michael, There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: -- service wireguard reload -- Again, NEVER do: -- service network restart -- and/or -- ip link set dev wg0 down && ip link set dev wg0 up -- as that will cause problems only a reboot can fix. Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. Lonnie [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html > On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: > > Hmm same problem again with two of my sites. > Only one of the two Wireguard VPN's are down. I have tried the following: > arno-iptables-firewall restart > service network restart > pppoe-restart > ip link set dev wg0 down & ip link set dev wg0 up > > All to no avail. Any other ideas before I reboot? > PS there is no failover configured for this site so I don't think MTU is the issue. > > Regards > Michael Knill > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: > > Thanks. Guess I will need to test it out. > > Regards > Michael Knill > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. > > It would be good to know what the precise answer is. > > Lonnie > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >> >> Thanks Lonnie. >> >> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >> Ultimately it would be the same eventually but there would be a migration period. >> >> Regards >> Michael Knill >> >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> I haven't seen any issues with a WG MTU of 1340, yet anyway. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie >>> >>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> Hi Michael, >>> >>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>> >>> I don't recall later WireGuard versions having any fixes for what you are describing. >>> >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>> >>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>> >>> Lonnie >>> >>> >>> >>> >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Hi Group >>>> >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>> Any ideas? >>>> >>>> Regards >>>> Michael Knill >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-23 21:42:16
|
Thanks Lonnie. I will test this next time Regards Michael Knill On 23/5/21, 10:29 pm, "Lonnie Abelbeck" <li...@lo...> wrote: Hi Michael, There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: -- service wireguard reload -- Again, NEVER do: -- service network restart -- and/or -- ip link set dev wg0 down && ip link set dev wg0 up -- as that will cause problems only a reboot can fix. Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. Lonnie [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html > On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: > > Hmm same problem again with two of my sites. > Only one of the two Wireguard VPN's are down. I have tried the following: > arno-iptables-firewall restart > service network restart > pppoe-restart > ip link set dev wg0 down & ip link set dev wg0 up > > All to no avail. Any other ideas before I reboot? > PS there is no failover configured for this site so I don't think MTU is the issue. > > Regards > Michael Knill > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: > > Thanks. Guess I will need to test it out. > > Regards > Michael Knill > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. > > It would be good to know what the precise answer is. > > Lonnie > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >> >> Thanks Lonnie. >> >> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >> Ultimately it would be the same eventually but there would be a migration period. >> >> Regards >> Michael Knill >> >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> I haven't seen any issues with a WG MTU of 1340, yet anyway. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie >>> >>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> Hi Michael, >>> >>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>> >>> I don't recall later WireGuard versions having any fixes for what you are describing. >>> >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>> >>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>> >>> Lonnie >>> >>> >>> >>> >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Hi Group >>>> >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>> Any ideas? >>>> >>>> Regards >>>> Michael Knill >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2021-05-23 12:28:48
|
Hi Michael, There is a discussion over on the WireGuard mailing list [1], with a similar situation as you describe. A reporter suggests the equivalent of AstLinux "Reload WireGuard VPN" (not Restart) fixes things. Though it would seem a DNS endpoint was changing and causing loss of WG connection in the [1] discussion. Not exactly the same as you describe. Bottom line, to answer your question, it is always "safe" to issue "Reload WireGuard VPN" via the web interface and not disrupt any active WG connections. Or from the command line: -- service wireguard reload -- Again, NEVER do: -- service network restart -- and/or -- ip link set dev wg0 down && ip link set dev wg0 up -- as that will cause problems only a reboot can fix. Back to your issue, I would take David Kerr's advice and add "PersistentKeepalive = 25" to the troublesome peer and see if that makes a difference. Lonnie [1] https://lists.zx2c4.com/pipermail/wireguard/2021-May/006761.html > On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: > > Hmm same problem again with two of my sites. > Only one of the two Wireguard VPN's are down. I have tried the following: > arno-iptables-firewall restart > service network restart > pppoe-restart > ip link set dev wg0 down & ip link set dev wg0 up > > All to no avail. Any other ideas before I reboot? > PS there is no failover configured for this site so I don't think MTU is the issue. > > Regards > Michael Knill > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: > > Thanks. Guess I will need to test it out. > > Regards > Michael Knill > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. > > It would be good to know what the precise answer is. > > Lonnie > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >> >> Thanks Lonnie. >> >> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >> Ultimately it would be the same eventually but there would be a migration period. >> >> Regards >> Michael Knill >> >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> I haven't seen any issues with a WG MTU of 1340, yet anyway. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie >>> >>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> Hi Michael, >>> >>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>> >>> I don't recall later WireGuard versions having any fixes for what you are describing. >>> >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>> >>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>> >>> Lonnie >>> >>> >>> >>> >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Hi Group >>>> >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>> Any ideas? >>>> >>>> Regards >>>> Michael Knill >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-19 22:04:21
|
Ah ok. Pity! Regards Michael Knill On 19/5/21, 7:32 am, "Lonnie Abelbeck" <li...@lo...> wrote: reboot You should not do a "service network restart" Lonnie > On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: > > Hmm same problem again with two of my sites. > Only one of the two Wireguard VPN's are down. I have tried the following: > arno-iptables-firewall restart > service network restart > pppoe-restart > ip link set dev wg0 down & ip link set dev wg0 up > > All to no avail. Any other ideas before I reboot? > PS there is no failover configured for this site so I don't think MTU is the issue. > > Regards > Michael Knill > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: > > Thanks. Guess I will need to test it out. > > Regards > Michael Knill > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. > > It would be good to know what the precise answer is. > > Lonnie > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >> >> Thanks Lonnie. >> >> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >> Ultimately it would be the same eventually but there would be a migration period. >> >> Regards >> Michael Knill >> >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> I haven't seen any issues with a WG MTU of 1340, yet anyway. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie >>> >>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> Hi Michael, >>> >>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>> >>> I don't recall later WireGuard versions having any fixes for what you are describing. >>> >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>> >>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>> >>> Lonnie >>> >>> >>> >>> >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Hi Group >>>> >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>> Any ideas? >>>> >>>> Regards >>>> Michael Knill >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-19 22:03:46
|
Thanks David Yes I have seen this and I am setting the keepalive when doing an upgrade. This one is directly connected though. Regards Michael Knill From: David Kerr <da...@ke...> Reply to: AstLinux List <ast...@li...> Date: Wednesday, 19 May 2021 at 7:42 am To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Wireguard VPN disconnection I've had some recent problems with wireguard disconnecting (or not reconnecting) from a remote system behind NAT. I discovered that setting PersistentKeepalive to something other than zero (I set to 25) helped. I did it at both ends, but might only have been required for the system behind the NAT. David On Tue, May 18, 2021 at 5:32 PM Lonnie Abelbeck <li...@lo...<mailto:li...@lo...>> wrote: reboot You should not do a "service network restart" Lonnie > On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...<mailto:mic...@ip...>> wrote: > > Hmm same problem again with two of my sites. > Only one of the two Wireguard VPN's are down. I have tried the following: > arno-iptables-firewall restart > service network restart > pppoe-restart > ip link set dev wg0 down & ip link set dev wg0 up > > All to no avail. Any other ideas before I reboot? > PS there is no failover configured for this site so I don't think MTU is the issue. > > Regards > Michael Knill > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...<mailto:mic...@ip...>> wrote: > > Thanks. Guess I will need to test it out. > > Regards > Michael Knill > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...<mailto:li...@lo...>> wrote: > > While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. > > It would be good to know what the precise answer is. > > Lonnie > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...<mailto:mic...@ip...>> wrote: >> >> Thanks Lonnie. >> >> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >> Ultimately it would be the same eventually but there would be a migration period. >> >> Regards >> Michael Knill >> >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...<mailto:li...@lo...>> wrote: >> >> I haven't seen any issues with a WG MTU of 1340, yet anyway. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...<mailto:mic...@ip...>> wrote: >>> >>> Thanks Lonnie >>> >>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...<mailto:li...@lo...>> wrote: >>> >>> Hi Michael, >>> >>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>> >>> I don't recall later WireGuard versions having any fixes for what you are describing. >>> >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>> >>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>> >>> Lonnie >>> >>> >>> >>> >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...<mailto:mic...@ip...>> wrote: >>>> >>>> Hi Group >>>> >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>> Any ideas? >>>> >>>> Regards >>>> Michael Knill >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li...<mailto:Ast...@li...> >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li...<mailto:Ast...@li...> >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li...<mailto:Ast...@li...> >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li...<mailto:Ast...@li...> >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li...<mailto:Ast...@li...> >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li...<mailto:Ast...@li...> > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li...<mailto:Ast...@li...> > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li...<mailto:Ast...@li...> > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. _______________________________________________ Astlinux-users mailing list Ast...@li...<mailto:Ast...@li...> https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr...<mailto:pa...@kr...>. |
From: David K. <da...@ke...> - 2021-05-18 21:41:47
|
I've had some recent problems with wireguard disconnecting (or not reconnecting) from a remote system behind NAT. I discovered that setting PersistentKeepalive to something other than zero (I set to 25) helped. I did it at both ends, but might only have been required for the system behind the NAT. David On Tue, May 18, 2021 at 5:32 PM Lonnie Abelbeck <li...@lo...> wrote: > reboot > > You should not do a "service network restart" > > Lonnie > > > > On May 18, 2021, at 4:27 PM, Michael Knill < > mic...@ip...> wrote: > > > > Hmm same problem again with two of my sites. > > Only one of the two Wireguard VPN's are down. I have tried the following: > > arno-iptables-firewall restart > > service network restart > > pppoe-restart > > ip link set dev wg0 down & ip link set dev wg0 up > > > > All to no avail. Any other ideas before I reboot? > > PS there is no failover configured for this site so I don't think MTU is > the issue. > > > > Regards > > Michael Knill > > > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> > wrote: > > > > Thanks. Guess I will need to test it out. > > > > Regards > > Michael Knill > > > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> > wrote: > > > > While playing with the WG MTU, it seemed to work with only > setting one end and the tunnel used the smallest, but I played it safe and > set everything to 1340. > > > > It would be good to know what the precise answer is. > > > > Lonnie > > > > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill < > mic...@ip...> wrote: > >> > >> Thanks Lonnie. > >> > >> PS I was just thinking (dangerous I know). I would need to set it on > both ends so do you think there would there be any issues with different > MTU's at each end? > >> Ultimately it would be the same eventually but there would be a > migration period. > >> > >> Regards > >> Michael Knill > >> > >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> > wrote: > >> > >> I haven't seen any issues with a WG MTU of 1340, yet anyway. > >> > >> Lonnie > >> > >> > >>> On Mar 19, 2021, at 9:29 PM, Michael Knill < > mic...@ip...> wrote: > >>> > >>> Thanks Lonnie > >>> > >>> Hmm that may have something to do with it. Might also be when it fails > over to 4G. > >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 > for all my systems should be fine. What do you think? > >>> > >>> Regards > >>> Michael Knill > >>> > >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> > wrote: > >>> > >>> Hi Michael, > >>> > >>> I have not experienced anything like that, WireGuard connectivity is > rock solid for me. > >>> > >>> I don't recall later WireGuard versions having any fixes for what you > are describing. > >>> > >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have > a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to > 1412 (1500-8-80) or lower to test. > >>> > >>> I'm testing a 4G-LTE/5G fixed wireless internet service from > T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU > to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the > CGNAT or else it hangs. > >>> > >>> Lonnie > >>> > >>> > >>> > >>> > >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill < > mic...@ip...> wrote: > >>>> > >>>> Hi Group > >>>> > >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all > my systems connect via Wireguard VPN to both my softswitches. > >>>> Its generally all pretty stable but occasionally one of the VPN’s > will be disconnected and I have tried everything I can think of to bring it > back up but only a reboot has managed to do so at this stage. > >>>> Any ideas? > >>>> > >>>> Regards > >>>> Michael Knill > >>>> _______________________________________________ > >>>> Astlinux-users mailing list > >>>> Ast...@li... > >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users > >>>> > >>>> Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > >>> > >>> > >>> > >>> _______________________________________________ > >>> Astlinux-users mailing list > >>> Ast...@li... > >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users > >>> > >>> Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > >>> > >>> > >>> _______________________________________________ > >>> Astlinux-users mailing list > >>> Ast...@li... > >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users > >>> > >>> Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > >> > >> > >> > >> _______________________________________________ > >> Astlinux-users mailing list > >> Ast...@li... > >> https://lists.sourceforge.net/lists/listinfo/astlinux-users > >> > >> Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > >> > >> > >> _______________________________________________ > >> Astlinux-users mailing list > >> Ast...@li... > >> https://lists.sourceforge.net/lists/listinfo/astlinux-users > >> > >> Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > > > > > > > > _______________________________________________ > > Astlinux-users mailing list > > Ast...@li... > > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > > > Donations to support AstLinux are graciously accepted via PayPal > to pa...@kr.... > > > > > > _______________________________________________ > > Astlinux-users mailing list > > Ast...@li... > > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > > > Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > > > > > > _______________________________________________ > > Astlinux-users mailing list > > Ast...@li... > > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > > > Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2021-05-18 21:32:12
|
reboot You should not do a "service network restart" Lonnie > On May 18, 2021, at 4:27 PM, Michael Knill <mic...@ip...> wrote: > > Hmm same problem again with two of my sites. > Only one of the two Wireguard VPN's are down. I have tried the following: > arno-iptables-firewall restart > service network restart > pppoe-restart > ip link set dev wg0 down & ip link set dev wg0 up > > All to no avail. Any other ideas before I reboot? > PS there is no failover configured for this site so I don't think MTU is the issue. > > Regards > Michael Knill > > On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: > > Thanks. Guess I will need to test it out. > > Regards > Michael Knill > > On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. > > It would be good to know what the precise answer is. > > Lonnie > > >> On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: >> >> Thanks Lonnie. >> >> PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? >> Ultimately it would be the same eventually but there would be a migration period. >> >> Regards >> Michael Knill >> >> On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> I haven't seen any issues with a WG MTU of 1340, yet anyway. >> >> Lonnie >> >> >>> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Thanks Lonnie >>> >>> Hmm that may have something to do with it. Might also be when it fails over to 4G. >>> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >>> >>> Regards >>> Michael Knill >>> >>> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >>> >>> Hi Michael, >>> >>> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >>> >>> I don't recall later WireGuard versions having any fixes for what you are describing. >>> >>> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >>> >>> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >>> >>> Lonnie >>> >>> >>> >>> >>>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>>> >>>> Hi Group >>>> >>>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>>> Any ideas? >>>> >>>> Regards >>>> Michael Knill >>>> _______________________________________________ >>>> Astlinux-users mailing list >>>> Ast...@li... >>>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>>> >>>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >>> >>> >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2021-05-18 21:27:59
|
Hmm same problem again with two of my sites. Only one of the two Wireguard VPN's are down. I have tried the following: arno-iptables-firewall restart service network restart pppoe-restart ip link set dev wg0 down & ip link set dev wg0 up All to no avail. Any other ideas before I reboot? PS there is no failover configured for this site so I don't think MTU is the issue. Regards Michael Knill On 20/3/21, 2:09 pm, "Michael Knill" <mic...@ip...> wrote: Thanks. Guess I will need to test it out. Regards Michael Knill On 20/3/21, 2:03 pm, "Lonnie Abelbeck" <li...@lo...> wrote: While playing with the WG MTU, it seemed to work with only setting one end and the tunnel used the smallest, but I played it safe and set everything to 1340. It would be good to know what the precise answer is. Lonnie > On Mar 19, 2021, at 9:57 PM, Michael Knill <mic...@ip...> wrote: > > Thanks Lonnie. > > PS I was just thinking (dangerous I know). I would need to set it on both ends so do you think there would there be any issues with different MTU's at each end? > Ultimately it would be the same eventually but there would be a migration period. > > Regards > Michael Knill > > On 20/3/21, 1:41 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > I haven't seen any issues with a WG MTU of 1340, yet anyway. > > Lonnie > > >> On Mar 19, 2021, at 9:29 PM, Michael Knill <mic...@ip...> wrote: >> >> Thanks Lonnie >> >> Hmm that may have something to do with it. Might also be when it fails over to 4G. >> As most of my VPN's carry voice only, I think a standard MTU of 1340 for all my systems should be fine. What do you think? >> >> Regards >> Michael Knill >> >> On 20/3/21, 10:40 am, "Lonnie Abelbeck" <li...@lo...> wrote: >> >> Hi Michael, >> >> I have not experienced anything like that, WireGuard connectivity is rock solid for me. >> >> I don't recall later WireGuard versions having any fixes for what you are describing. >> >> Just guessing, the standard MTU for WG is 1420 (1500-80), if you have a PPPoE connection with a MTU of 1492 you might try setting the WG MTU to 1412 (1500-8-80) or lower to test. >> >> I'm testing a 4G-LTE/5G fixed wireless internet service from T-Mobile, they use Carrier Grade NAT (CGNAT) for IPv4 which lowers the MTU to 1420 (just like WG) so WG needs a MTU setting of 1340 to work over the CGNAT or else it hangs. >> >> Lonnie >> >> >> >> >>> On Mar 19, 2021, at 3:42 PM, Michael Knill <mic...@ip...> wrote: >>> >>> Hi Group >>> >>> Not sure if anyone else is experiencing this. I'm on 1.3.10 and all my systems connect via Wireguard VPN to both my softswitches. >>> Its generally all pretty stable but occasionally one of the VPN’s will be disconnected and I have tried everything I can think of to bring it back up but only a reboot has managed to do so at this stage. >>> Any ideas? >>> >>> Regards >>> Michael Knill >>> _______________________________________________ >>> Astlinux-users mailing list >>> Ast...@li... >>> https://lists.sourceforge.net/lists/listinfo/astlinux-users >>> >>> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... >> >> >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2021-05-16 15:22:05
|
Announcing AstLinux Pre-Release: astlinux-1.4-5135-88bba6 ** Request for Testing This pre-release includes a major version bump of prosody (XMPP), from 0.10.3 to 0.11.9. The 0.11.9 version includes Denial-of-Service security fixes. If you are using XMPP in your setup, please consider testing this pre-release. Particularly with using XMPP 'pubsub' with Asterisk. Please report any issues (or successes) with this change. ** The AstLinux Team is regularly upgrading packages containing security and bug fixes as well as adding new features of our own. -- Linux Kernel 4.19.190 (version bump), security and bug fixes -- initrd, check for ASTURW /etc/inittab and copy it forward so the linuxrc's /sbin/init can use it. Note: AstLinux 1.3.10 through 1.4.2 ignored any user edits to the /etc/inittab file, rather it always used the default /etc/inittab file (the default is what most users want anyway). Now edits to the /etc/inittab file are honored again, as they were before AstLinux 1.3.10. -- OpenSSL, version bump to 1.1.1k, security fixes: CVE-2021-3449, CVE-2021-3450 -- WireGuard VPN, module 1.0.20210424 (version bump), tools 1.0.20210424 (version bump) -- OpenVPN, version bump to 2.4.11, security fix: CVE-2020-15078 -- libcurl (curl) version bump to 7.76.1, security fixes: CVE-2021-22876, CVE-2021-22890 -- libxml2, version bump to 2.9.12, security fix: CVE-2021-3541, plus "an awful lot of serious bug fixes" -- Monit, version bump to 5.28.0 -- prosody, major version bump to 0.11.9 Security fixes: CVE-2021-32917, CVE-2021-32918, CVE-2021-32919, CVE-2021-32920, CVE-2021-32921 -- Asterisk 13.29.2 ('13se' no change) Older than latest Asterisk 13.x version but more tested, built --without-pjproject -- Asterisk 13.38.2 (no change) and 16.18.0 (version bump) -- Complete Pre-Release ChangeLog: https://s3.amazonaws.com/beta.astlinux-project/astlinux-changelog/ChangeLog.txt The "AstLinux Pre-Release ChangeLog" and "Pre-Release Repository URL" entries can be found under the "Development" tab of the AstLinux Project web site ... AstLinux Project -> Development https://www.astlinux-project.org/dev.html AstLinux Team |
From: Michael K. <li...@mk...> - 2021-05-03 08:37:42
|
> Am 03.05.2021 um 10:35 schrieb Michael Keuter <li...@mk...>: > > > >> Am 23.04.2021 um 08:52 schrieb nedi <ne...@gm...>: >> >> >> Hi Michael, >> can be this CTI with SIP Phone, I use it for one Customer with Astlinux and snom, but this CTI have SIP Client to. >> >> https://www.phonesuite.de/hlp/de/client/topics/sip_softphone.htm >> >> Regards Nedi > > Yes, the "Phonesuite CTI Client" can be used for CTI (TAPI) via the Asterisk Manager Interface (AMI) and it has an integrated softphone which works fine with Asterisk. There are 2 versions of the client: > > https://www.phonesuite.de/de/produkte/client/functions.htm > > I'm not sure, if the BLF keys in the client work without the (optional) Phonesuite CTI server. There is a separate license for "Präsenz-Management". To be sure I would call the programmer (he speaks German). > > https://www.phonesuite.de/de/kontakt.htm If you only need CTI without the softphone you can use TAPI for Asterisk (it is also much cheaper): https://www.phonesuite.de/de/produkte/ast_tsp/phonesuite_tapi_for_asterisk.htm Michael http://www.mksolutions.info |
From: Michael K. <li...@mk...> - 2021-05-03 08:35:28
|
> Am 23.04.2021 um 08:52 schrieb nedi <ne...@gm...>: > > > Hi Michael, > can be this CTI with SIP Phone, I use it for one Customer with Astlinux and snom, but this CTI have SIP Client to. > > https://www.phonesuite.de/hlp/de/client/topics/sip_softphone.htm > > Regards Nedi Yes, the "Phonesuite CTI Client" can be used for CTI (TAPI) via the Asterisk Manager Interface (AMI) and it has an integrated softphone which works fine with Asterisk. There are 2 versions of the client: https://www.phonesuite.de/de/produkte/client/functions.htm I'm not sure, if the BLF keys in the client work without the (optional) Phonesuite CTI server. There is a separate license for "Präsenz-Management". To be sure I would call the programmer (he speaks German). https://www.phonesuite.de/de/kontakt.htm Michael http://www.mksolutions.info |
From: nedi <ne...@gm...> - 2021-05-02 17:42:32
|
<html><head></head><body dir="auto" style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><meta http-equiv="Content-Type" content="text/html; charset=us-ascii" class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class=""> Hi Michael, <div class="">can be this CTI with SIP Phone, I use it for one Customer with Astlinux and snom, but this CTI have SIP Client to.</div><div class=""><br class=""></div><div class=""><a href="https://www.phonesuite.de/hlp/de/client/topics/sip_softphone.htm" class="">https://www.phonesuite.de/hlp/de/client/topics/sip_softphone.htm</a></div><div class=""><br class=""></div><div class="">Regards Nedi</div></div></div></body></html> |
From: nedi <ne...@gm...> - 2021-04-26 07:34:05
|
Hi Michael, do you know how to make working BFL trough OpenVPN, and I can’t Provisioning trough OpenVPN. can be I have some Routing issue? Regards Nedi > Am 25.04.2021 um 11:31 schrieb Michael Keuter <li...@mk...>: > > > >> Am 23.04.2021 um 08:53 schrieb nedi <ne...@gm...>: >> >> >> Hi Michael, >> can be this CTI with SIP Phone, I use it for one Customer with Astlinux and snom, but this CTI have SIP Client to. >> >> https://www.phonesuite.de/hlp/de/client/topics/sip_softphone.htm >> >> Regards Nedi > > Yes, the "Phonesuite CTI Client" can be used for CTI (TAPI) via the Asterisk Manager Interface (AMI) and it has an integrated softphone which works fine with Asterisk. There are 2 versions of the client: > > https://www.phonesuite.de/de/produkte/client/functions.htm > > I'm not sure, if the BLF keys in the client work without the (optional) Phonesuite CTI server. There is a separate license for "Präsenz-Management". To be sure I would call the programmer (he speaks German). > > https://www.phonesuite.de/de/kontakt.htm > > Michael > > http://www.mksolutions.info > > > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <li...@mk...> - 2021-04-25 09:31:36
|
> Am 23.04.2021 um 08:53 schrieb nedi <ne...@gm...>: > > > Hi Michael, > can be this CTI with SIP Phone, I use it for one Customer with Astlinux and snom, but this CTI have SIP Client to. > > https://www.phonesuite.de/hlp/de/client/topics/sip_softphone.htm > > Regards Nedi Yes, the "Phonesuite CTI Client" can be used for CTI (TAPI) via the Asterisk Manager Interface (AMI) and it has an integrated softphone which works fine with Asterisk. There are 2 versions of the client: https://www.phonesuite.de/de/produkte/client/functions.htm I'm not sure, if the BLF keys in the client work without the (optional) Phonesuite CTI server. There is a separate license for "Präsenz-Management". To be sure I would call the programmer (he speaks German). https://www.phonesuite.de/de/kontakt.htm Michael http://www.mksolutions.info |