Mixing if_ipsec in 11.1 with old policy based IPSEC

2018-03-07 Thread Muenz, Michael
Hi list, I'm trying to get some docs and examples about the new if_ipsec code. For what I read now, it seems to be a bit tricky* running legacy policy based IPSEC in combination with on route based IPSEC with Strongswan. Is it possible to mix them for bigger sites running e.g. one Azure VPN an

TCP Retransmission meet some problem.

2018-03-07 Thread cameled yang
Hello, everyone. Recently, I work with a eCos project, It's network stack using freebsd version(Not sure Exactly version, SDK is provide by others). Everything work fine before I meet a problem. When local http server return packet to borwser, sometimes retransmission happened. But rarely in rese

Re: why not enable tcp_pmtud_blackhole_detect in default

2018-03-07 Thread Kevin Bowling
Cheng, We run this in production at Limelight Networks (i.e toward a broad spectrum of Internet hosts) and must to deal with some uncommon network topology. There are currently some limitations as you point out. Like you say the signaling is not perfect and we do often clamp MSS unnecessarily. T

why not enable tcp_pmtud_blackhole_detect in default

2018-03-07 Thread Cui, Cheng
Dear all, Reading through the tcp blackhole detection code (support RFC 4821) in FreeBSD including the recent bug fixes, I am wondering why is it still not enabled in default? Given the fact that this implementation was a merge from xnu, and the xnu has enabled it in default, do we have a plan