Re: Problems with pf+nat+some websites

2005-08-24 Thread Guido Tschakert
Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454 to the route. Also take a look at pppoe(4)

Re: Problems with pf+nat+some websites

2005-08-24 Thread Nick Holland
Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454 to the route. Also

Re: Problems with pf+nat+some websites

2005-08-24 Thread Guido Tschakert
Nick Holland wrote: Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454

Re: Problems with pf+nat+some websites

2005-08-24 Thread Jonathan Schleifer
Guido Tschakert [EMAIL PROTECTED] wrote: BTW. this morning I tried the suggestions from Jonathan and it didn't work :-( This is normal. I thought you use the OpenBSD Box for PPPoE and NAT directly, not through another router, which is a hardware box. I noticed in the past that hardware

Re: Problems with pf+nat+some websites

2005-08-24 Thread Steve Williams
Nick Holland wrote: Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding

Re: Problems with pf+nat+some websites

2005-08-24 Thread Matty
On Wed, 24 Aug 2005, Nick Holland wrote: Guido Tschakert wrote: Jonathan Schleifer wrote: I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf

Re: Problems with pf+nat+some websites

2005-08-24 Thread Bryan Irvine
nice try, but i Don't use pppoe. We have a DSL-Router from our providewr and as I mentioned before, we had no Problems with the cisco-router doing the firewall job (Nat). so, yes you DO use PPPoE. Not necessarily, it could be in bridged mode. --Bryan

Re: Problems with pf+nat+some websites

2005-08-23 Thread Guido Tschakert
Guido Tschakert wrote: Ok, after digging in the archives I found the thread pf reassemble tcp problem in latest snapshot? and it seems there is no real solution for this problem in OpenBSD/pf. provocation on I found that somewhat poor, because with Cisco IOS and Linux iptables this problem

Re: Problems with pf+nat+some websites

2005-08-23 Thread Jonathan Schleifer
I don't see where you set the MTU/MSS? Are you sure you have set them somewhere else? eBay is known to have problems with bad/wrong MTU/MSS. Try adding scrub out on $ext_if max-mss 1414 to your pf.conf and adding -mtu 1454 to the route. Also take a look at pppoe(4) [*NOT* pppoe(8)!], section