Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Reverend Deuce
Okay guys, I posted that long message about Firefox/etc on Windows Vista a couple of days ago. After I re-read my post and looked at the tcpdump output, and chatting with a friend of mine who also runs several OBSD firewalls at his company which exhibited the same EXACT problem when my Vista

Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Stuart Henderson
On 2006/11/28 14:32, Reverend Deuce wrote: Okay guys, I posted that long message about Firefox/etc on Windows Vista a couple of days ago. this would be easier if you just posted pf.conf rather than non-linear snippets; however.. a) there is a default block policy I didn't notice you posting

Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Stuart Henderson
On 2006/11/28 18:07, Michael Lockhart wrote: Set net.inet.tcp.rfc1323=0 in /etc/sysctl.conf and that should resolve the issue. that's not a fix though, it just avoids the conditions which cause the problem to occur. better to ensure the ruleset is completely sane. if so, then test cases need to

Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-27 Thread Claudio Jeker
On Sun, Nov 26, 2006 at 09:19:25PM -0600, Reverend Deuce wrote: (This is very long email because it's a very complicated problem... I've included some tcpdump logs below to assist...) SNIP Here are some tcpdumps from the master FW during connection attempts with a browser: Opera 9:

Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-27 Thread Christian M. Bernard
Hi there I had the exact same strange (kind of) problem. All clients could connect to my (own OpenBSD) web server, only my main PC (sorry linux gentoo machine) could not. The packets match what you show below. It stops because the initial http) packet does't arrive at your VistaPC. [Fire up

Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-27 Thread Christian Ruediger Bahls
[2006-11-27 10:43] Claudio Jeker [EMAIL PROTECTED] wrote: Both Firefox and Opera use a wscale of 8 whereas IE uses a wscale of 2. In my opinion this sounds like the typical problem where states are not created on the initial SYN packet. sounds like a window scaling problem as described in:

Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-26 Thread Reverend Deuce
(This is very long email because it's a very complicated problem... I've included some tcpdump logs below to assist...) The last week and days I've been working with the RTM version of Vista obtained through my MSDN license. This is the gold version of Windows Vista, BTW. It's done. It's been

Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-26 Thread Bill Maas
I'm not sure if this will be of any help, but at least the Firefox issue sounds like FF is able to connect, but never receives any return traffic. I've had that with misconfigured netmasks I believe. Does Vista use some sort of net group or certificate based access scheme (e.g. if it's not a Vista