Re: IPSec session stalls

2005-10-25 Thread Jeremie Le Hen
> Not sure: what you described in your first mail also looks like a > "basic" fragmentation problem, which can be easily solved by > decreasing MTU on traffic endpoints (you can also play with TCPMSS on > one gate, but this will only solve TCP problems...). > > The pf interaction may only be a sid

Re: IPSec session stalls

2005-10-21 Thread VANHULLEBUS Yvan
On Thu, Oct 20, 2005 at 11:47:27PM +0100, Volker wrote: > hmm, I hate replying to myself :-) [rules] > I guess as all works fine while pf is disabled this is an pf issue, right? Not sure: what you described in your first mail also looks like a "basic" fragmentation problem, which can be easi

Re: IPSec session stalls

2005-10-20 Thread Volker
hmm, I hate replying to myself I've just checked another thing: When disabling pf on both IPSec endpoints (even large) file transfer works fine. I'm using pf and altq with cbq. Removing the pf 'scrub' rules didn't solve it. In the firewall I'll let gif traffic pass with rules like: pass qu

IPSec session stalls

2005-10-20 Thread Volker
Hi! A few days ago I've managed to setup two IPSec tunnels (3 machines involved) between FreeBSD 5.4R hosts. While I do not fully understand all the options and knobs of IPSec, it was easy to setup (thanks to the handbook guys!). As the tunnels work properly in the first place, there's one issue