Search results

  1. J

    What do I need to do to disable IPv6?

    @wbumiller - Ah, nice catch on "disable"! I must have looked at it 20 times... Considering the message log errors, its likely a better option to firewall the v6 instead of maintaining modifications across system upgrades. Thanks for your time
  2. J

    What do I need to do to disable IPv6?

    @wbumiller I have tried `ipv6.disable=1` but it does not seem to work. This the boot line from same machine above: # cat /proc/cmdline BOOT_IMAGE=/boot/vmlinuz-4.4.98-6-pve root=/dev/mapper/pve-root ro ipv6.disble=1 vga=791 fsck.mode=force pti=on I have made both the boot line modification as...
  3. J

    What do I need to do to disable IPv6?

    Unfortunately, that answer won't survive a security audit. I need to prove that the listening services bound to ipv6 interfaces are properly firewalled. I do not know much about ipv6 but these services appear wide open. Am I misundestanding? # ip6tables -nvL Chain INPUT (policy ACCEPT 0...
  4. J

    What do I need to do to disable IPv6?

    I'll never use IPv6 and want to disable it completely. I don't like having rpcbind or ssh running on both v4 and v6. I've tried disabling using sysctl but getting errors in the logs from pve-firewall: iptables_restore_cmdlist: Try `ip6tables-restore -h' or 'ip6tables-restore --help' for...
  5. J

    Why is /dev full on my LXC container?

    Looks like something using shared memory perhaps? # find /dev/ -type f /dev/shm/qb-pve2-event-1542-19201-26-data /dev/shm/qb-pve2-event-1542-19201-26-header /dev/shm/qb-pve2-response-1542-19201-26-data /dev/shm/qb-pve2-response-1542-19201-26-header /dev/shm/qb-pve2-request-1542-19201-26-data...
  6. J

    Why is /dev full on my LXC container?

    New to containers, so maybe overlooking something - why is /dev at 100% on my container? After a reboot it was fine. 5 days uptime: $ df -mh Filesystem Size Used Avail Use% Mounted on /dev/mapper/pve-vm--700--disk--1 50G 25G 22G 54% / none...
  7. J

    cannot connecto to (https) enterprise.proxmox.com/

    Tried the commands suggested on host below, still not working. Is there some way to debug the pvesubscription command to see what it's doing? host .28 # pvesubscription get checktime: 1521789242 key: pve2c-xxxxxxxxxx nextduedate: 2018-02-18 productname: Proxmox VE Community Subscription 2...
  8. J

    cannot connecto to (https) enterprise.proxmox.com/

    This seems to connect via curl OK on all three hosts. We purchased our licenseses thorugh Symmcom.com (not shop.maurer-it.com) if it matters. $ curl https://shop.maurer-it.com <!DOCTYPE html> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=utf-8" />...
  9. J

    cannot connecto to (https) enterprise.proxmox.com/

    output of pveversion -v below. curl output: # curl https://enterprise.proxmox.com <html> <head><title>Index of /</title></head> <body bgcolor="white"> <h1>Index of /</h1><hr><pre><a href="../">../</a> <a href="debian/">debian/</a>...
  10. J

    cannot connecto to (https) enterprise.proxmox.com/

    UPDATE: I checked with our license purchasing person and the subscriptions for these hosts have been renewed through 2019-02-19. Something is stil amiss here. We do have an edge firewall filter of some kind. I can connect to https://enterprise.proxmox.com using curl from these hosts, so port...
  11. J

    cannot connecto to (https) enterprise.proxmox.com/

    Yes, this machine has susbscription. Actually have three Proxmox hosts (with subs.) in this subnet having the same issue for a few days now.
  12. J

    cannot connecto to (https) enterprise.proxmox.com/

    pveupdate fails to run command 'apt-get update' failed: exit code 100 running aptitude update produces an error connecting to https://enterprise.proxmox.com/ Is this a known issue? Thank you # aptitude update Hit http://security.debian.org jessie/updates InRelease Ign http://ftp.us.debian.org...
  13. J

    How can I expose a NIC to a container?

    ok so I found this posting: https://forum.proxmox.com/threads/lxc-676-feature-request-physical-nic-assignment-for-lxc-containers-in-proxmox-4-0.23068/ (note eth1 below used to be eth3. Seems it moved to eth1 after a reboot or something?) I shutdown container 700 and added these lines to my...
  14. J

    How can I expose a NIC to a container?

    I have an IDS system I've containerized. eth0 is on vmbr0 while eth3 is an interface running from a SPAN session of a Cisco switch. I've tried creating a new bridge (vmbr100) and added eth3 to it. This allows the container to see UDP traffic from the SPAN session but none of the TCP traffic...
  15. J

    How to convert bare metal FS to LXC Container?

    yes, thanks UPDATE: just tried it on a second host today and it worked perfectly. I mounted the bare metal root fs on /mnt/ssd and then mounted the container rootfs via pct. Commands below if anyone is wondering how to do it. pct mount 700 cd /var/lib/lxc/700/rootfs/ rsync -av /mnt/ssd/ ...
  16. J

    How to convert bare metal FS to LXC Container?

    `pct mount` is exactly what I needed. Thanks for the explanation.
  17. J

    How to convert bare metal FS to LXC Container?

    Thanks. Is there a way to boot the container from ISO ? I like to boot the target with an acquiesced filesystem before doing a sync. Usually there is an option under Hardware > Add > CDROM for this but that doesn't exist for a container.
  18. J

    How to convert bare metal FS to LXC Container?

    I'm just trying out containers in Proxmox 4.4. I have a 1U bare metal I'd like to convert to a container. I've done this with KVM by booting the VM with a cdrom and then using rsync to copy files over from a hard disk/usb stick onto the VM filesystem. I don't see a cdrom boot option for LXC...
  19. J

    I created a new bridge but it's not up after boot

    I created a bridge (vmbr3) yesterday and rebooted my proxmox hypervisor but vmbr3 is not coming up at boot and the VM using this bridge is failing to start automatically. I can `ifup vmbr3` and start the VM by hand, but I'd like to know what's not working correctly. My /etc/network/interfaces...