Lots of weird PF behavior on 7.2-STABLE

2009-12-14 Thread Linda Messerschmidt
Hi all, I have a PF machine that is giving fits. I see a lot of weird behavior. 1) TCP connections (mainly port 80) sometimes take 3 seconds to get started instead of being virtually instant. 2) Sometimes HTTP connections just stop responding. (Client program times out waiting for response.) 3)

RE: PF Transparent Bridge Firewall + CARP

2009-12-14 Thread Kevin
> -Original Message- > From: Kevin [mailto:k...@kevinkevin.com] > I have what I would consider not a standard firewall scenario that > requires a second, redundant PF firewall. My first / main firewall is > pf + transparent bridging with no internal network / ip addresses. I realize tha

PF Transparent Bridge Firewall + CARP

2009-12-14 Thread Kevin
Hello, I have what I would consider not a standard firewall scenario that requires a second, redundant PF firewall. My first / main firewall is pf + transparent bridging with no internal network / ip addresses. I would like to implement a second failover firewall w/ CARP and have a pretty good i

Re: IPv6, PF problem

2009-12-14 Thread Max Laier
On Saturday 12 December 2009 22:11:28 Aaron Stellman wrote: > Hello there, > > > What does "pfctl -vvsr" give you for the rule? It should include the > > number of addresses assigned to the interface in the braces - e.g. "... > > (bge0:4) ..." > > @8 pass in on bge0 proto tcp from any to (bge0:

Current problem reports assigned to freebsd-pf@FreeBSD.org

2009-12-14 Thread FreeBSD bugmaster
Note: to view an individual PR, use: http://www.freebsd.org/cgi/query-pr.cgi?pr=(number). The following is a listing of current problems submitted by FreeBSD users. These represent problem reports covering all versions including experimental development code and obsolete releases. S Tracker