Re: [Shorewall-users] Weird TCP problem

2008-09-10 Thread Wolfgang Hotwagner
i had a similar problem and i solved it by turning off the tcp_window_scaling(/proc/sys/net/ipv4/tcp_window_scaling). our linux-server was not able to communicate to some servers. i tried to turn off the tcp_window_scaling on our linux-server and then it works. try to turn off the window-scaling on

Re: [Shorewall-users] Weird TCP problem

2008-09-07 Thread Tom Eastep
Does this problem only occur with SSH or do you see it happening with other applications? When running tcpdump did you look at all traffic on the server or only the traffic you were interested in? -Tom Gordon Messmer wrote: Tom Eastep wrote: It doesn't "run shorewall" -- Shorewall is used t

Re: [Shorewall-users] Weird TCP problem

2008-09-07 Thread Gordon Messmer
Tom Eastep wrote: > > It doesn't "run shorewall" -- Shorewall is used to configure Netfilter > on the box; once 'shorewall start' is finished, there is no Shorewall > code running there at all. I know, I understand how it works. I just didn't phrase that very well, and I apologize. If you we

Re: [Shorewall-users] Weird TCP problem

2008-09-05 Thread Tom Eastep
Gordon Messmer wrote: Tom Eastep wrote: This is all fascinating but I can't, in my worse nightmares, think that this has anything to do with Shorewall. I'm having a hard time with that, too, except that I can only reproduce the problem from inside that office LAN, which uses the Linux router

Re: [Shorewall-users] Weird TCP problem

2008-09-05 Thread Gordon Messmer
Tom Eastep wrote: > > This is all fascinating but I can't, in my worse nightmares, think that > this has anything to do with Shorewall. I'm having a hard time with that, too, except that I can only reproduce the problem from inside that office LAN, which uses the Linux router running shorewall

Re: [Shorewall-users] Weird TCP problem

2008-09-05 Thread Tom Eastep
Gordon Messmer wrote: Both of those appear to indicate that the server in the colo facility is receiving the SYN packets. What possible reasons are there that it would not reply with SYN+ACK? This is all fascinating but I can't, in my worse nightmares, think that this has anything to do wit

[Shorewall-users] Weird TCP problem

2008-09-05 Thread Gordon Messmer
Last week, I started seeing very strange behavior in one of the networks that I manage. The office LAN uses a Linux firewall (running shorewall) which masquerades their workstations over their DSL connection. There are probably ~75 workstations in the office LAN. Their mail server is in a coll