Yes i did see the article:
Patching the host kernel is sufficient to block attacks from guests to the host. On the other hand, in order to protect the guest kernel from a malicious userspace, updates are also needed to the guest kernel and, depending on the processor architecture, to QEMU.
So...
Its seems that the problem has impact on containers, not directly full virtualization machines Read this: Source: https://meltdownattack.com/meltdown.pdf
https://spectreattack.com/
many hosting or cloud providers do not have an abstraction layer for virtual memory. In such environments...
Must a attacker not first have access to your network and has special rights ? Until what level do a firewall protect against Meltdown and Spectre ? What about Snort IDS , OSSEC systems ? Just some thoughts. :rolleyes:
I am running Proxmox V 3.1-12/93bf03d4
And lately i get error:
Message from syslogd: kernel:BUG: soft lockup - CPU#6 stuck for 67s! [kswapd0:140]
At that moment i cant login to the Gui of proxmox. And need to do a reboot.
What can be the problem ? And how to diagnose this ?
Any Advise ? Is...
I have a problem that one of the OpenVZ containers wont be able to backup
any more ? Here is the output off the backup job:
What can this be ? I niticed --> failed: interrupted by signal
INFO: starting new backup job: vzdump 3106 --remove 0 --mode stop --compress lzo --storage Storage --node...
This was about restoring a KVM right ? I believe as a work around it did made next steps ...
Copy /etc/pve/nodes/host235/qemu-server your_KVM_number.conf
Example 100.config to location /etc/pve/nodes/host235/qemu-server
Little while ago i did this. I believe it give a write error. You must...
This time ... a clean installation only Debian ... maybe i better post this at OpenVPN forum ..
I did a clean install of Debian ... Then i installed
OpenVPN on top of this machine.... Nothing complicated just a base setup ...
And really strange problem is still there !!!??? Max 2mbps ...
Here a update of test result.
I did install successfully openVPN on top of the Proxmox host.
I did turn off the Shoreline Firewall. As you can see a tun0 OpenVPN interface.
I can connect all works fine. But again the speed is MAX 2 Mbps !!????
So i connect to the OpenVPN interface at IP...
I use KVM.(untangle ISO install) If i bridge i need to set a mac address at my provider. I like to keep it routed.
But i believe if i install OpenVPN direct on top of the Proxmox box, then its direct linked. (Main adress Proxmox server)
From there i will do some speed test.
I am still testing...
Can you tell me how your Proxmox network looks like ? Its very strange that i have this performance.
While all others service work fine on this box. Like port 80 Apache ftp ssh smtp good connection speed. 100 mbps
I use port UDP 1194 for OpenVZ. Don't think SSL TCP 443 needs to be open because...
Thnx for your reply. Over here i did some testing. Direct vpn traffic routed to the KVM box. Same result.
Also did route all traffic thru the tunnel to test internet speed from openVPN client. Still not good.
Turned off the firewall still to slow.
Next approach, will install a openVPN server...
Holmes thank you for you reply,
I have a I7 core X980 24GB RAM, so that must be enough power :-)
Maybe i know what the problem can be. Looking to all my components
used in my server.
I also use Shorewall firewall on top of Proxmox.
virtio drivers for open VPN. The openVPN server is running
in...
Using ptpp VPN and OpenVPN in a KVM Slow speed. Other protocols full speed ? Port 22 SSH Apache 80 full
speed download.
Using virtio network drivers als did test realtek and Intel E 1000.
Max speed is like 1.68 Mb download. If i use in the same VM SSH download i have full speed ? Like 20 Mb...
INFO: trying to get global lock - waiting... ERROR: can't aquire lock '/var/run/vzdump.lock' - got timeout Problem with disk layout ? Free PE / Size 0 / 0 Proxmox 3.1-21 give me problems with backups. In version 2x never had those issues ? vgdisplay --- Volume group --- VG Name...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.