Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: PF and stalled connections

From: Abdul Rehman Gani <abdulg(at)eastcoast.co.za>
Date: Mon Dec 30 2002 - 14:34:10 EST

On Monday 30 December 2002 15:55, Abdul Rehman Gani wrote:
> Hi,
>
> I have just upgraded a working OBSD 2.9 + IPF firewall to OBSD 3.2 and PF.

I have tried the following:-

Installed 3.2 from CD - this is a complete install, only the config files were saved on another server, then restored to this server.

Config files saved were: pf.conf, hostname.fxp[01], tinydns and dnscache data files and relevant portion of rc.local

Rebuilt a kernel with NMBCLUSTERS=8192

Disabled the audio system (irq 10 conflict with fxp1)

Changed the NIC config from media autoselect to media 100baseTX mediaopt full-duplex

Do you need help?X

Rebooted (obviously)

Further observations:-

The stalls are connection based, ie. during a stall of one ssh session, I can still use another ssh session, to the same host or to another through the host, or even check pop mail on a server out side the firewall.

>From the firewall, two ping started, one to an internal host and another to an
external host will result in lost packets to the internal host.

A netstat -di shows zero collisions, error and drops on all interfaces

pfctl -s i:-

Status: Enabled for 0 days 03:12:35 Debug: Misc

State Table                          Total             Rate
  current entries                     1649
  searches                         2876881          249.0/s
  inserts                           112980            9.8/s
  removals                          111331            9.6/s
Counters
  match                             113708            9.8/s
  bad-offset                             0            0.0/s
  fragment                               3            0.0/s
  short                                  0            0.0/s
  normalize                              1            0.0/s
  memory                                 0            0.0/s

I do not have a limit set for states or fragments in pf.conf - what is the default?

Do you need more help?X

What can people suggest? Any other diagnostics/debugs that I can use to obtain more info?

Thanks,

Abdul

-- 
http://www.eastcoast.co.za
Tel: +27-31-566-8080
Fax: +27-31-566-8010
Email: support@eastcoast.co.za
Received on Mon Dec 30 14:25:41 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:32:12 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library