Solaris 10 05/09 Update 7 - Zone shutdown issue

I have just clean installed several servers with solaris 10 update 7 (both sparc and x64, no other software installed) and I am getting the following svc error messages whenever I shutdown a zone.
Aug 19 18:26:22 svc.startd[25328]: svc:/network/ipsec/policy:default: Method "/usr/sbin/ipsecconf -F" failed with exit status 1.
Aug 19 18:26:22 svc.startd[25328]: svc:/network/ipsec/policy:default: Method "/usr/sbin/ipsecconf -F" failed with exit status 1.
Aug 19 18:26:22 svc.startd[25328]: svc:/network/ipsec/policy:default: Method "/usr/sbin/ipsecconf -F" failed with exit status 1.
Aug 19 18:26:23 svc.startd[25328]: network/ipsec/policy:default failed: transitioned to maintenance (see 'svcs -xv' for details)
The log file for svc:/network/ipsec/policy:default shows the following error.
+[ Aug 19 18:26:22 Stopping because service disabled. ]+
+[ Aug 19 18:26:22 Executing stop method ("/usr/sbin/ipsecconf -F") ]+
ipsecconf: (loading pf_policy) socket:: Permission denied
ipsecconf: unable to open policy socket: Permission denied
+[ Aug 19 18:26:22 Method "stop" exited with status 1 ]+
The errors occur in both sparse and whole root zones with a shared ip-type (does not occur in exclusive ip-type). The zonecfg is shown below.
set zonepath=/export/zones/rdo23wok
set autoboot=false
set ip-type=shared
add inherit-pkg-dir
set dir=/lib
end
add inherit-pkg-dir
set dir=/platform
end
add inherit-pkg-dir
set dir=/sbin
end
add inherit-pkg-dir
set dir=/usr
end
add net
set address=xxx.xxx.xxx.xxx/xx
set physical=bge0
end
Looking at the release notes for 05/09 update 7 it mentions that "IP security (IPsec) is now managed by the following Solaris Management Facility (SMF) services" which seems to fit with the error I am getting.
Although I can prevent the error messages by disabling the service in each zone with svcadm it is a bit annoying and would like to have a better solution. Does anyone know how I can prevent this service from being enabled when I create a new zone?
Thanks
Jools
Edited by: joolshomer on Aug 19, 2009 10:57 AM

I have just clean installed several servers with solaris 10 update 7 (both sparc and x64, no other software installed) and I am getting the following svc error messages whenever I shutdown a zone.
Aug 19 18:26:22 svc.startd[25328]: svc:/network/ipsec/policy:default: Method "/usr/sbin/ipsecconf -F" failed with exit status 1.
Aug 19 18:26:22 svc.startd[25328]: svc:/network/ipsec/policy:default: Method "/usr/sbin/ipsecconf -F" failed with exit status 1.
Aug 19 18:26:22 svc.startd[25328]: svc:/network/ipsec/policy:default: Method "/usr/sbin/ipsecconf -F" failed with exit status 1.
Aug 19 18:26:23 svc.startd[25328]: network/ipsec/policy:default failed: transitioned to maintenance (see 'svcs -xv' for details)
The log file for svc:/network/ipsec/policy:default shows the following error.
+[ Aug 19 18:26:22 Stopping because service disabled. ]+
+[ Aug 19 18:26:22 Executing stop method ("/usr/sbin/ipsecconf -F") ]+
ipsecconf: (loading pf_policy) socket:: Permission denied
ipsecconf: unable to open policy socket: Permission denied
+[ Aug 19 18:26:22 Method "stop" exited with status 1 ]+
The errors occur in both sparse and whole root zones with a shared ip-type (does not occur in exclusive ip-type). The zonecfg is shown below.
set zonepath=/export/zones/rdo23wok
set autoboot=false
set ip-type=shared
add inherit-pkg-dir
set dir=/lib
end
add inherit-pkg-dir
set dir=/platform
end
add inherit-pkg-dir
set dir=/sbin
end
add inherit-pkg-dir
set dir=/usr
end
add net
set address=xxx.xxx.xxx.xxx/xx
set physical=bge0
end
Looking at the release notes for 05/09 update 7 it mentions that "IP security (IPsec) is now managed by the following Solaris Management Facility (SMF) services" which seems to fit with the error I am getting.
Although I can prevent the error messages by disabling the service in each zone with svcadm it is a bit annoying and would like to have a better solution. Does anyone know how I can prevent this service from being enabled when I create a new zone?
Thanks
Jools
Edited by: joolshomer on Aug 19, 2009 10:57 AM

Similar Messages

  • 'Install Updates and Shutdown' option not appearing for Windows 8.1 users

    Windows 8.1 users are reporting, and I have verified, that they are not being prompted to install Windows updates while shutting down, even though the updates are downloaded.  Here are the relevant Windows Update gpo's from a sample Group Policy Result
    for a typical user on one of our Windows 8.1 workstations:
    (Note: The "Specify intranet Microsoft update service location" is the last policy in the updates section, and the value specified there is not relevant to this question.)
    These same settings when applied to Windows XP workstations used to prompt users to install updates at shutdown.  That is, the default shutdown option was "Install Updates and Shutdown".  That was a great workflow because all client workstations
    were shut down every night and the user didn't have to worry about updates installing while they were using the workstation.  All client workstations are now running Windows 8.1 Pro and the only way updates are getting installed is by manually pulling
    up the Windows Update dialog and initiating updates from there.  That is even worse than automatic updates that install during business hours.
    I do notice that
    a notification that updates are available appears in the login screen, but one can not take action upon it from there, and most users don't know how to find the update screen once they sign in; and
    once updating is begun, then the Install Updates and Shutdown option becomes a default - but by that point its rather cosmetic: that is the only option (to configure the partially installed updates during shutdown) and there is nothing
    that could be done to NOT do that at that point. 
    Is anyone having similar issues?  As far as I can tell right now, there is no ability to actually switch the user's default option to
    Install Updates and Shutdown in the same way as in previous Windows editions even though the GPO is identical.

    Hi,
    >>Is anyone having similar issues?  As far as I can tell right now, there is no ability to actually switch the user's default option to
    Install Updates and Shutdown in the same way as in previous Windows editions even though the GPO is identical.
    Regarding this point, the following blog may provide a good explanation.
    Minimizing restarts after automatic updating in Windows Update
    http://blogs.msdn.com/b/b8/archive/2011/11/14/minimizing-restarts-after-automatic-updating-in-windows-update.aspx
    Best regards,
    Frank Shen

  • Macbook pro shutdown issue

    Macbook pro shutdown issue when I push the power button it immediately goes into sleep mode

    Hello Marrio22,
    Thank you for the question.  With OS X Mavericks, the power button has new functionality:
    OS X Mavericks updates the power button behavior on Mac computers. 
    Using the Power Button to Sleep & Wake
    Tap the power button in Mavericks to put your Mac to sleep or to wake it up:
    Tap the power button once to put your Mac to sleep.
    Tap the power button again to wake your Mac.
    Press the power button for less than a half a second to sleep or wake your Mac. This duration is similar to pressing the Space bar or Return key to wake your Mac. The power button works this way across all Macs using OS X Mavericks, including both notebook and desktop computers.
    Accessing the Shut Down Dialog
    Press and hold the power button for 1.5 seconds, to bring up additional options:
    Forcing the Mac to Turn Off
    Hold down the power button for 5 seconds to force the computer to turn off. Important: You may lose unsaved documents if you force the computer to turn off this way. Use this method of turning off your Mac only if it has become unresponsive for an extended period of time. Normally you should shut down the computer by selecting Shut Down from the Apple menu, or from the shut down dialog pictured above.
    OS X Mavericks: Using the power button
    http://support.apple.com/kb/HT5869
    Thank you for using Apple Support Communities.
    Best,
    Sheila M.

  • Urgent help needed; Database shutdown issues.

    Urgent help needed; Database shutdown issues.
    Hi all,
    I am trying to shutdown my SAP database and am facing the issues below, can someone please suggest how I can go about resolving this issue and restart the database?
    SQL> shutdown immediate
    ORA-24324: service handle not initialized
    ORA-24323: value not allowed
    ORA-01089: immediate shutdown in progress - no operations are permitted
    SQL> shutdown abort
    ORA-01031: insufficient privileges
    Thanks and regards,
    Iqbal

    Hi,
    check SAP Note 700548 - FAQ: Oracle authorizations
    also check Note 834917 - Oracle Database 10g: New database role SAPCONN
    regards,
    kaushal

  • Will the new 10.6.8 update fix SATA3 issues related with 2011 MacBook Pros?

    Will the new 10.6.8 update fix SATA3 issues related with 2011 MacBook Pros?

    It is against TOU to speculate on these message board.  Suggest you post your question on the Mac Rumors site.
    As I already stated, there is no 10.6.8 update.  If there was, it would be listed in Software Update.

  • SMC doesn't work in any solaris 10 whole-root zones

    All
    Are you aware of SUN not designing whole-root zones to work with Solaris Management Console?
    None of my solaris 10 whole-root zones/containers will run Solaris Management Console. Very, very frustrating!
    Anyone have a trick to get around this crazy design??
    Thank you!
    SB

    Thanks for your help!
    Yes, i see all font types.
    But maybe i havn't explained my problem good enough:
    I have a FLA-File which works great in Flash CS3: everything – even on different computers – is okay!
    The same FLA-File on the same computer in Flash CS6: the font-rendering is broken!
    In CS6 there seems to be a difference between textfields made via ActionScript and textfields on the stage: see the attached file in my first post.

  • I heard that there was a problem with Apple being vulnerable to Hackers. Has anyone seen an update for this issue? My IPad received the update last night but I have not seen anything for Safari.

    I heard that there was a problem with Apple being vulnerable to Hackers. Has anyone seen an update for this issue? My IPad received the update last night but I have not seen anything for Safari.

    Mac OS X 10.9.2 was released today for this issue and others. Earlier versions are not affected.
    See this Apple article - http://support.apple.com/kb/HT6114
    You can use the Mac app store to do the update or download it directly from here - http://support.apple.com/kb/DL1725
    Best of luck.

  • Oracle 11.2.0.3 upgrade running on Solaris 10 using zfs/zones

    Hello,
    We currently run solaris 10 using zfs/zones.
    We have a global zone and several sparse root zones.
    The oracle upgrade (from 10.2.0.4 to 11.2.0.3) prerequiste check is reporting the following warnings:
    OS kernel parameter "tcp_smallest_anon_port" plus 3 other warnings for tcp_largest_anon_port and for the udp ports as well
    This requires that we use ndd to change the values for these ports in the global zone.
    These changes will affect all of the sparse root zones and not just the one we are upgrading Oracle in.
    Will this pose any problems or is safe to make these port changes in the global zone.
    Thanks
    Kevin

    I would recommend you log an SR with Support
    Srini

  • SL3000 + FC-SCSI connection to Solaris 10 x86, Update 6 won't configure

    Hi all,
    A summary:
    1. New SL3000 installed and configured
    2. SL3000 is connected/zoned into FC switches presenting itself over FC-SCSI port to Solaris 10 x86 update 6 (fully patched) hosts
    3. Appears on fabric like so:
    Jul  4 18:48:05 storehost fctl: [ID 517869 kern.warning] WARNING: fp(2)::N_x Port with D_ID=620200, PWWN=500104f000ae7688 reappeared in fabric
    Jul  4 18:48:05 storehost scsi: [ID 243001 kern.info]         Target 0x620200: Nonzero peripheral qualifier: Device type=0x8 Peripheral qual=0x14. Attempts to cfgadm -c configure:
    [root@storehost:/] $ cfgadm -c configure c4::500104f000ae7688
    cfgadm: Library error: failed to create device node: 500104f000ae7688: Invalid argument
    Ports on FC switch suggest thousands of "invalid transmitted word" errors per hour - and this is just the SCSI-FC robot control port!
    Tried:
    a) Reboots
    b) luxadm probe
    c) cfgadm -c configure -o force_update blah
    d) checking zoning over and over
    e) entire library reboot
    f) entire switch reboot
    Thoughts/comments/what could be going wrong?
    Thanks all.
    z

    hi,guys:
    did you check you type of connecting of library?
     is it point to point or fc_loop ?
    so you need to change fc_loop for fc_swithc 。
    best regards

  • Folio Producer fails to update older published issues

    A client wants me to update an advertisement in several past issues including issues published in January and February 2012.
    I updated the article in the folio and go to the Folio Producer to update the published issue, but either immediately get a failed attempt or it will process up to 20% before failing. I have tried publishing multiple times and it constantly fails.
    Has anyone else come across this problem?
    Why can't I update?

    What do you see when you click the 'Failed' link. There should be an error message there.
    // James Roche
    // [email protected]<mailto:[email protected]>
    // I was born lucky

  • How do I get the updates that refernce "Install this update to resolve issues in Windows." installed automatically?

    On Intune, I'm not certain what to tick off that will install the updates on Windows 7 that reference at the beginning of it's description line... "Install this update to resolve issues in Windows."  The only way that I can get this to prompt
    for install is to manually run Microsoft Update.  Equally odd is that when you run MU locally, these updates are detected and referenced as optional -- for example, 17 optional updates are available.  But when you click on that link to review
    these available updates, in the right pane detail for each update they are referenced as recommended.

    Yes, I know this is an old post, but I’m trying to clean them up. Did you solve this problem, if so what was the solution?
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • HT6114 Does the 10.9.2 update fix the issue on 2011 macs where projectors with HDMI are not recognized via thunderbolt adapter?

    Hi Mac,
    Does the 10.9.2 update fix the issue on 2011 macs where projectors with HDMI are not recognized via thunderbolt adapter?
    Thanks in advance,
    Ricardo Arguelles

    Sordidloam wrote:
    So to be clear, this issue occurs on any input with the Denon Receiver.  Occurs from both HDMI out and MiniDisplay Port out.  Goes away when we reinstall the OS and update it to 10.9.2.  Comes back as soon as we update to 10.9.3.
    Cheers
    MLE
    Have you been able to use the Mac Mini directly attached to the plasma/LCD/projector with out going through the Denon AVR? Even with 10.9.3 installed?
    I have a Pioneer AVR and I have the Mac attached via a HDMI to HDMI and all is working for me. Can your Denon do some upscaling? Some AVR, like my VSX-53 can change the scaling of the input video. Meaning if I still had my Apple TV 2 which outputs 720P only, can be upscaled in my AVR to 1080i or 1080P or even 24fps. Heck, I could even plug in an old style Red, White, Yellow cable and upscale it to 1080P and output it HDMI.
    I am wondering if your Denon is able to do that and it might be set wrong. Check the owners manual for such settings. Even the plasma/LCD/project could be doing the upscaling too. So check that too.
    KOT

  • Time Zone Alias issue

    Hi Everyone,
    After upgrading the Agentry server 6.0.44 we started seeing the Time Zone Alias issue. Earlier we saw the issue but we have done changes to agentry.ini based on the note1886697 and it got fixed. But after upgrade we are the seeing the same.
    Usefull links for the above issue
    Set Up Time Zone Alias in Agentry.ini Configuration File - SAP Mobility - SCN Wiki
    can any one help me?
    Regards,
    Gupta
    Tags edited by: Michael Appleby

    Hi Stepen,
    Yes it has Java or SQL system connection last as per the note 1886697.
    This issue was resolved earlier after implementing as per the note, we got new agentry server version 6.0.44 after installing it again the issue got arrised.
    Regards,
    Gupta

  • After the IOS 7.1 update I have issue with Game Center, I'm not been able to  load the  games. The apps don't seems to be able to connect to game centre. How to resolve the issue?

    After the IOS 7.1 update I have issue with Game Center, I'm not been able to  load the  games. The apps don't seems to be able to connect to game centre. How to resolve the issue?

    Try reset iPad
    Hold down the Sleep/Wake button and the Home button at the same time for at least ten seconds, until the Apple logo appears
    Note: Data will not be affected.

  • Sir since update of ios 8.1.2 i got serious battery problem on 3g 4.30 hrs my battery gets low and sometimes serious net probelms please give an update for this issue its not alone me my friends too getting many problem lcommonly battery problem

    sir since update of ios 8.1.2 i got serious battery problem on 3g 4.30 hrs my battery gets low and sometimes serious net probelms please give an update for this issue its not alone me my friends too getting many problem commonly battery problem please can this be resolved
    its not related to any hardware because last year april i got replacement new phone from apple and i maintained it well...!

    Probably apps running in the background are causing this, sometimes Mail get's stuck connecting to the mail server, or some social media app like Facebook can also be a reason for prolonged background activity.
    Try to reset the phone by holding the sleep and home button for about 10sec, until the Apple logo comes back again. You will not lose any data by resetting, but it can cure some glitches.
    If this does not help, setting it up as new device would be the next step:
    How to erase your iOS device and then set it up as a new device or restore it from backups
    Also take a look at these tips to prolong the battery life again:
    http://www.overthought.org/blog/2014/the-ultimate-guide-to-solving-ios-battery-d rain

Maybe you are looking for

  • Upgrade to 10.6.8 fails!

    I just switched from PC to Mac and have tried several times, on several different connections, to download and install the 10.6.8 on my brand new MacBook Pro. I either get download failures or invalid checksums. I have repaired permissions, performed

  • Bridge CS4 is messing up half the files when saved

    Basically, my wife is uses Bridge CS4 to edit her photos and a a little bit ago, she acquired a Canon 7D.  Ever since then, around half the images after editing are literally, half messed up (see picture).  I figured it was because her iMac was slowi

  • Ipod touch not connecting to itunes 8.1, tried everything

    Hi, I was just wondering if someone could help me please? After going from forum to forum, post to post for days now, I really need someones help. I have an Ipod touch 2nd generation, and I recently updated to itunes 8.1, a few days later I plugged i

  • Final cut will not capture

    i have tiger on my Powerbook g4, just put it on and my capturing will not show signes of capturing footage from my camera.... the sound waves dont even show up on the side. what could be wrong with the final cut after loading Tiger?

  • Printing checks in APP

    Hi all i am able to run the app. customer is getting posted with the payment. i am not able to see the print cheks in the spool , after selecting the job and clicking the spool it says no list exits. so where is the problem. have i given the correct