Re: PF keep state does'nt like Mandriva2007
Could be sliding windows, selective ack (SACK), MTU/MTU Disc/MSS issues, any of the RFC extensions. Check sysctl on linux v.s. scrub on OpenBSD ~BAS On Mon, 29 Jan 2007, Marco Peereboom wrote: Nobody likes Mandriva. On Sun, Jan 28, 2007 at 07:56:04PM -0800, Reza Muhammad wrote: Dear Lists. I have one bridge PF machine for packet queue and prio, and few new install Mandriva2007 (linux kernel) that couldn not browse the web (the other protocol work OK) if the rules keep state in PF machine is activated. but the others hosts (WinXP, BSD, Mac, Others Linux) work fine. Why PF (OpenBSD-3.9) doesnt like Mandriva2007 Plese help regards Reza Never Miss an Email Stay connected with Yahoo! Mail on your mobile. Get started! http://mobile.yahoo.com/services?promote=mail l8* -lava (Brian A. Seklecki - Pittsburgh, PA, USA) http://www.spiritual-machines.org/ Guilty? Yeah. But he knows it. I mean, you're guilty. You just don't know it. So who's really in jail? ~James Maynard Keenan
Re: PF keep state does'nt like Mandriva2007
On 2007/01/28 19:56, Reza Muhammad wrote: and few new install Mandriva2007 (linux kernel) that couldn not browse the web (the other protocol work OK) if the rules keep state in PF machine is activated. use 'flags S/SA keep state'
Re: PF keep state does'nt like Mandriva2007
--- Stuart Henderson [EMAIL PROTECTED] wrote: On 2007/01/28 19:56, Reza Muhammad wrote: and few new install Mandriva2007 (linux kernel) that couldn not browse the web (the other protocol work OK) if the rules keep state in PF machine is activated. use 'flags S/SA keep state' thanks for nice replay.. but it still doesnt work. I believe that problem in mandriva2007 hosts rather than PF. regards reza Reza Need a quick answer? Get one in minutes from people who know. Ask your question on www.Answers.yahoo.com
Re: PF keep state does'nt like Mandriva2007
and few new install Mandriva2007 (linux kernel) that couldn not browse the web (the other protocol work OK) if the rules keep state in PF machine is activated. use 'flags S/SA keep state' thanks for nice replay.. but it still doesnt work. I believe that problem in mandriva2007 hosts rather than PF. Send a tcpdump of a failing connection, from start to finish (i.e. include the SYN packet).
Re: PF keep state does'nt like Mandriva2007
Nobody likes Mandriva. On Sun, Jan 28, 2007 at 07:56:04PM -0800, Reza Muhammad wrote: Dear Lists. I have one bridge PF machine for packet queue and prio, and few new install Mandriva2007 (linux kernel) that couldn not browse the web (the other protocol work OK) if the rules keep state in PF machine is activated. but the others hosts (WinXP, BSD, Mac, Others Linux) work fine. Why PF (OpenBSD-3.9) doesnt like Mandriva2007 Plese help regards Reza Never Miss an Email Stay connected with Yahoo! Mail on your mobile. Get started! http://mobile.yahoo.com/services?promote=mail
PF keep state does'nt like Mandriva2007
Dear Lists. I have one bridge PF machine for packet queue and prio, and few new install Mandriva2007 (linux kernel) that couldn not browse the web (the other protocol work OK) if the rules keep state in PF machine is activated. but the others hosts (WinXP, BSD, Mac, Others Linux) work fine. Why PF (OpenBSD-3.9) doesnt like Mandriva2007 Plese help regards Reza Never Miss an Email Stay connected with Yahoo! Mail on your mobile. Get started! http://mobile.yahoo.com/services?promote=mail
Re: PF keep state does'nt like Mandriva2007
On 1/28/07, Reza Muhammad [EMAIL PROTECTED] wrote: Snip Why PF (OpenBSD-3.9) doesnt like Mandriva2007 Plese help because you have Mandriva configured wrong.