Re: Problems with pf+nat+some websites

2005-08-24 Thread Bryan Irvine
> > nice try, but i Don't use pppoe. > > We have a DSL-Router from our providewr and as I mentioned before, we > > had no Problems with the cisco-router doing the firewall job (Nat). > > so, yes you DO use PPPoE. Not necessarily, it could be in bridged mode. --Bryan

Re: Problems with pf+nat+some websites

2005-08-24 Thread Matty
On Wed, 24 Aug 2005, Nick Holland wrote: Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf an

Re: Problems with pf+nat+some websites

2005-08-24 Thread Steve Williams
Nick Holland wrote: Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu

Re: Problems with pf+nat+some websites

2005-08-24 Thread Jonathan Schleifer
Guido Tschakert <[EMAIL PROTECTED]> wrote: > BTW. this morning I tried the suggestions from Jonathan and it didn't > work :-( This is normal. I thought you use the OpenBSD Box for PPPoE and NAT directly, not through another router, which is a hardware box. I noticed in the past that hardware ro

Re: Problems with pf+nat+some websites

2005-08-24 Thread Guido Tschakert
Nick Holland wrote: Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454 t

Re: Problems with pf+nat+some websites

2005-08-24 Thread Nick Holland
Guido Tschakert wrote: > Jonathan Schleifer wrote: >> I don't see where you set the MTU/MSS? Are you sure you have set them >> somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. >> Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding >> -mtu 1454 to the route.

Re: Problems with pf+nat+some websites

2005-08-24 Thread Guido Tschakert
Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454 to the route. Also take a look at pppoe(4) [*NOT

Re: Problems with pf+nat+some websites

2005-08-23 Thread Jonathan Schleifer
I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454 to the route. Also take a look at pppoe(4) [*NOT* pppoe(8)!], section MTU/MS

Re: Problems with pf+nat+some websites

2005-08-23 Thread Guido Tschakert
Guido Tschakert wrote: Ok, after digging in the archives I found the thread pf reassemble tcp problem in latest snapshot? and it seems there is no real solution for this problem in OpenBSD/pf. I found that somewhat poor, because with Cisco IOS and Linux iptables this problem doesn't exist and

Problems with pf+nat+some websites

2005-08-23 Thread Guido Tschakert
Hello, I have problems to load some websites (e.g. www.hit.de, www.lidl.de, www.ebay.de, www.ebay.com). They are very slow if they show up. I have this problem since this morning, when I changed our old cisco router with our new OpenBSD Firewall. Other sites load normal. Here is the network