Re: ICMP attacks against TCP and PMTUD

2012-01-13 Thread Andre Oppermann
On 12.01.2012 18:55, Nikolay Denev wrote: Hello, A web server that I administer running Nginx and FreeBSD-7.3-STABLE was recently under a ICMP attack that generated a large amount of outgoing TCP traffic. With some tcpdump and netflow analysis it was evident that the attachers are using ICMP ho

Re: Processes' FIBs

2012-01-13 Thread Kostik Belousov
On Thu, Jan 12, 2012 at 10:44:51PM -0800, Julian Elischer wrote: > On 1/12/12 6:04 AM, Oliver Fromme wrote: > >Bjoern A. Zeeb wrote: > > > On 11. Jan 2012, at 15:06 , Oliver Fromme wrote: > > > > I'm currently looking at the source code of ps, but adding > > > > a field for the FIB isn't as

Re: ICMP attacks against TCP and PMTUD

2012-01-13 Thread Nikolay Denev
On Jan 13, 2012, at 11:47 AM, Andre Oppermann wrote: > On 12.01.2012 18:55, Nikolay Denev wrote: >> Hello, >> >> A web server that I administer running Nginx and FreeBSD-7.3-STABLE was >> recently >> under a ICMP attack that generated a large amount of outgoing TCP traffic. >> With some tcpdump

Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread Vladislav V. Prodan
Tell me, what a performance in pps a network card RTL8111/8168B? Can I somehow increase it? Experimentally, since it begins to fall off 80Kpps: ( Jan 13 18:12:49 XXX kernel: re0: watchdog timeout Jan 13 18:12:49 XXX kernel: re0: link state changed to DOWN Jan 13 18:12:53 XXX kernel: re0: link st

Re: Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread Vladislav V. Prodan
14.01.2012 0:15, YongHyeon PYUN wrote: > On Fri, Jan 13, 2012 at 11:17:45PM +0200, Vladislav V. Prodan wrote: >> >> Tell me, what a performance in pps a network card RTL8111/8168B? >> Can I somehow increase it? >> Experimentally, since it begins to fall off 80Kpps: ( >> > > RX performance number w

Re: Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread YongHyeon PYUN
On Fri, Jan 13, 2012 at 11:17:45PM +0200, Vladislav V. Prodan wrote: > > Tell me, what a performance in pps a network card RTL8111/8168B? > Can I somehow increase it? > Experimentally, since it begins to fall off 80Kpps: ( > RX performance number will show much better than that but TX is major b

Bad interaction between 82599 hardware RSC and VLANs

2012-01-13 Thread Andrew Boyer
Hello Jack, I'm seeing an issue on 82599 controllers. When hardware RSC is used, large VLAN packets arrive without the VP bit set, even though the vtag in the descriptor is correct. It totally kills the receive performance. Turning off hardware RSC in the driver (falling back to software LRO)

Re: Bad interaction between 82599 hardware RSC and VLANs

2012-01-13 Thread Jack Vogel
Hey Andrew, Not heard of this before, but I'll check around. Jack On Fri, Jan 13, 2012 at 3:01 PM, Andrew Boyer wrote: > Hello Jack, > I'm seeing an issue on 82599 controllers. When hardware RSC is used, > large VLAN packets arrive without the VP bit set, even though the vtag in > the descrip

Re: Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread Luigi Rizzo
On Sat, Jan 14, 2012 at 12:35:31AM +0200, Vladislav V. Prodan wrote: > 14.01.2012 0:15, YongHyeon PYUN wrote: > > On Fri, Jan 13, 2012 at 11:17:45PM +0200, Vladislav V. Prodan wrote: > >> > >> Tell me, what a performance in pps a network card RTL8111/8168B? > >> Can I somehow increase it? > >> Expe

Re: Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread YongHyeon PYUN
On Sat, Jan 14, 2012 at 12:35:31AM +0200, Vladislav V. Prodan wrote: > 14.01.2012 0:15, YongHyeon PYUN wrote: > > On Fri, Jan 13, 2012 at 11:17:45PM +0200, Vladislav V. Prodan wrote: > >> > >> Tell me, what a performance in pps a network card RTL8111/8168B? > >> Can I somehow increase it? > >> Expe

Re: Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread Vladislav V. Prodan
14.01.2012 1:27, YongHyeon PYUN wrote: > On Sat, Jan 14, 2012 at 12:35:31AM +0200, Vladislav V. Prodan wrote: >> 14.01.2012 0:15, YongHyeon PYUN wrote: >>> On Fri, Jan 13, 2012 at 11:17:45PM +0200, Vladislav V. Prodan wrote: Tell me, what a performance in pps a network card RTL8111/8168B?

Re: Lack of performance re0 (RTL8111/8168B)

2012-01-13 Thread YongHyeon PYUN
On Sat, Jan 14, 2012 at 01:42:07AM +0200, Vladislav V. Prodan wrote: > 14.01.2012 1:27, YongHyeon PYUN wrote: > > On Sat, Jan 14, 2012 at 12:35:31AM +0200, Vladislav V. Prodan wrote: > >> 14.01.2012 0:15, YongHyeon PYUN wrote: > >>> On Fri, Jan 13, 2012 at 11:17:45PM +0200, Vladislav V. Prodan wrot

Re: openbgpds not talking each other since 8.2-STABLE upgrade

2012-01-13 Thread Hiroki Sato
Doug Barton wrote in <4f0ce268.1000...@freebsd.org>: do> On 01/03/2012 13:03, Hiroki Sato wrote: do> > Okay, thank you for your report. I will take some time to fix do> > TCP_MD5SIG support in openbgpd and inform you when another patch is do> > ready. do> do> Any news on this? Not trying to