From owner-freebsd-net Thu Feb 13 23:34: 7 2003 Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D154837B401 for ; Thu, 13 Feb 2003 23:34:05 -0800 (PST) Received: from mail.econolodgetulsa.com (mail.econolodgetulsa.com [198.78.66.163]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2F90943FDD for ; Thu, 13 Feb 2003 23:34:05 -0800 (PST) (envelope-from user@mail.econolodgetulsa.com) Received: from mail (user@mail [198.78.66.163]) by mail.econolodgetulsa.com (8.12.3/8.12.3) with ESMTP id h1E7YAdR046378 for ; Thu, 13 Feb 2003 23:34:10 -0800 (PST) (envelope-from user@mail.econolodgetulsa.com) Date: Thu, 13 Feb 2003 23:34:10 -0800 (PST) From: Josh Brooks To: freebsd-net@freebsd.org Subject: IPFW2 and count rules ... broken ? Message-ID: <20030213232855.O42678-100000@mail.econolodgetulsa.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-net@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hello, I have recently upgraded to ipfw2 running on 4.7-RELEASE. It seems to be working fine. However, my count rules ... aren't working well at all. I have clear and correct testing that shows that many count rules do not increment at all when traffic is clearly flowing. For instance: count ip from 10.10.10.10 to any and count ip from any to 10.10.10.10 If you insert those rules and then hit a web page on 10.10.10.10, you can hit that page lot and not have the counter for rule 1 increment at all. I set a ping job pinging it for a while, and it incremented then ... but http traffic will not increment it. No, this is not a proxy or caching issue - I was trying pages and links that had never been used on my local computer before. So does anyone know of any problems with count rules in ipfw2 ? To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message