From owner-freebsd-net@FreeBSD.ORG Sat Jul 12 12:53:08 2003 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 487B137B401 for ; Sat, 12 Jul 2003 12:53:08 -0700 (PDT) Received: from mandarin.fruitsalad.org (pc117.net160.koping.net [81.16.160.117]) by mx1.FreeBSD.org (Postfix) with ESMTP id E6AD643F3F for ; Sat, 12 Jul 2003 12:53:05 -0700 (PDT) (envelope-from mdouhan@fruitsalad.org) Received: from [192.168.15.240] (helo=192.168.15.240) by mandarin.fruitsalad.org with esmtp (Exim 4.14) id 19bQQb-0003v1-3X; Sat, 12 Jul 2003 21:53:05 +0200 From: Matt Douhan To: rmkml Date: Sat, 12 Jul 2003 21:53:10 +0200 User-Agent: KMail/1.5.2 References: <200307122110.37349.mdouhan@fruitsalad.org> <3F106215.8E73129D@wanadoo.fr> In-Reply-To: <3F106215.8E73129D@wanadoo.fr> MIME-Version: 1.0 Content-Type: Text/Plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Content-Description: clearsigned data Content-Disposition: inline Message-Id: <200307122153.17101.mdouhan@fruitsalad.org> cc: freebsd-net@freebsd.org Subject: Re: very strange problem X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 12 Jul 2003 19:53:08 -0000 =2D----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sorry for topposting but I will try and answer the requests one by one, I c= an=20 only do FW1 today, and fw2 on monday, but here goes > > possible send tcpump record pb ? > (example: tcpdump -ns 0 -i externalintf_fw1 -w all1.tcpdump > and tcpdump -ns 0 -i externalintf_fw2 -w all2.tcpdump) dump is pretty large so I did not want to email it, please download it from http://www.fruitsalad.org/people/mdouhan/fw1.tar.gz > > possible send ipf -V (on two fw) ? 7:47pm mdouhan @ [firewall1] ~ > sudo ipf -V ipf: IP Filter: v3.4.31 (336) Kernel: IP Filter: v3.4.31 Running: yes Log Flags: 0 =3D none set Default: pass all, Logging: available Active list: 0 > > possible send ipfstat -nhio (on two fw) ? > 7:49pm mdouhan @ [firewall1] ~ > sudo ipfstat -nhio 2073551 @1 pass out quick on fxp0 from any to any keep state 1038 @1 pass in quick on fxp0 proto icmp from any to any 1802016 @2 pass in quick on fxp0 from 192.168.254.242/32 to 192.168.15.250/= 32 1255 @3 pass in quick on fxp0 from 192.168.254.250/32 to 192.168.15.249/32 372304 @4 block in log quick on fxp0 from any to any > possible send ipnat -slv (on two fw) ? fw1 is not running NAT, will sedn this on monday when I get to fw2 > > possible send netstat -ni ? > 7:50pm mdouhan @ [firewall1] ~ > netstat -ni Name Mtu Network Address Ipkts Ierrs Opkts Oerrs = =20 Coll fxp0 1500 00:02:b3:cc:20:6e 45474907 0 46776572 0 = =20 0 fxp0 1500 192.168.254 192.168.254.1 612 - 673 - = =20 =2D - fxp0 1500 fe80:1::202:b fe80:1::202:b3ff: 0 - 0 - = =20 =2D - fxp1 1500 00:02:b3:cc:1b:3f 47307566 3 45127446 0 = =20 0 fxp1 1500 192.168.15 192.168.15.254 184152 - 40018 - = =20 =2D - fxp1 1500 fe80:2::202:b fe80:2::202:b3ff: 0 - 0 - = =20 =2D - lp0* 1500 0 0 0 0 = =20 0 lo0 16384 528 0 528 0 = =20 0 lo0 16384 ::1/128 ::1 0 - 0 - = =20 =2D - lo0 16384 fe80:4::1/64 fe80:4::1 0 - 0 - = =20 =2D - lo0 16384 127 127.0.0.1 528 - 528 - = =20 =2D - > possible send ifconfig -a ? > 7:50pm mdouhan @ [firewall1] ~ > ifconfig -a fxp0: flags=3D8843 mtu 1500 options=3D3 inet 192.168.254.1 netmask 0xffffff00 broadcast 192.168.254.255 inet6 fe80::202:b3ff:fecc:206e%fxp0 prefixlen 64 scopeid 0x1 ether 00:02:b3:cc:20:6e media: Ethernet autoselect (100baseTX ) status: active fxp1: flags=3D8843 mtu 1500 options=3D3 inet 192.168.15.254 netmask 0xffffff00 broadcast 192.168.15.255 inet6 fe80::202:b3ff:fecc:1b3f%fxp1 prefixlen 64 scopeid 0x2 ether 00:02:b3:cc:1b:3f media: Ethernet autoselect (100baseTX ) status: active lp0: flags=3D8810 mtu 1500 lo0: flags=3D8049 mtu 16384 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4 inet 127.0.0.1 netmask 0xff000000 > possible dmesg ? > 7:51pm mdouhan @ [firewall1] ~ > dmesg Copyright (c) 1992-2003 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. =46reeBSD 5.1-CURRENT #2: Wed Jul 2 15:40:03 GMT 2003 root@firewall1.internal.hasta.se:/usr/obj/usr/src/sys/FIREWALL1 Preloaded elf kernel "/boot/kernel/kernel" at 0xc052a000. Preloaded elf module "/boot/kernel/acpi.ko" at 0xc052a1cc. Timecounter "i8254" frequency 1193182 Hz Timecounter "TSC" frequency 1799806528 Hz CPU: Intel(R) Celeron(R) CPU 1.80GHz (1799.81-MHz 686-class CPU) Origin =3D "GenuineIntel" Id =3D 0xf13 Stepping =3D 3 =20 =46eatures=3D0x3febfbff real memory =3D 536805376 (511 MB) avail memory =3D 515776512 (491 MB) Pentium Pro MTRR support enabled npx0: on motherboard npx0: INT 16 interface acpi0: on motherboard pcibios: BIOS version 2.10 Using $PIR table, 11 entries at 0xc00fdeb0 acpi0: power button is handled as a fixed feature programming model. Timecounter "ACPI-fast" frequency 3579545 Hz acpi_timer0: <24-bit timer at 3.579545MHz> port 0x4008-0x400b on acpi0 acpi_cpu0: on acpi0 acpi_cpu1: on acpi0 acpi_tz0: on acpi0 acpi_button0: on acpi0 pcib0: port 0xcf8-0xcff on acpi0 pci0: on pcib0 pcib0: slot 29 INTA is routed to irq 12 pcib0: slot 29 INTB is routed to irq 11 pcib0: slot 29 INTC is routed to irq 12 pcib0: slot 29 INTD is routed to irq 10 pcib0: slot 31 INTB is routed to irq 11 pcib0: slot 31 INTB is routed to irq 11 agp0: mem 0xe0000000-0xe3ffffff at device = 0.0=20 on pci0 pcib1: at device 1.0 on pci0 pci1: on pcib1 pcib0: slot 1 INTA is routed to irq 12 pcib1: slot 0 INTA is routed to irq 12 pci1: at device 0.0 (no driver attached) uhci0: port 0xd800-0xd81f irq 1= 2=20 at device 29.0 on pci0 usb0: on uhci0 usb0: USB revision 1.0 uhub0: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub0: 2 ports with 2 removable, self powered uhci1: port 0xd000-0xd01f irq 1= 1=20 at device 29.1 on pci0 usb1: on uhci1 usb1: USB revision 1.0 uhub1: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub1: 2 ports with 2 removable, self powered uhci2: port 0xd400-0xd41f irq 1= 2=20 at device 29.2 on pci0 usb2: on uhci2 usb2: USB revision 1.0 uhub2: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub2: 2 ports with 2 removable, self powered pci0: at device 29.7 (no driver attached) pcib2: at device 30.0 on pci0 pci2: on pcib2 pcib2: slot 7 INTA is routed to irq 11 pcib2: slot 9 INTA is routed to irq 10 fxp0: port 0xc000-0xc03f= =20 mem 0xe9000000-0xe901ffff,0xe9041000-0xe9041fff irq 11 at device 7.0 on pci2 fxp0: Ethernet address 00:02:b3:cc:20:6e miibus0: on fxp0 inphy0: on miibus0 inphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto fxp1: port 0xc400-0xc43f= =20 mem 0xe9020000-0xe903ffff,0xe9040000-0xe9040fff irq 10 at device 9.0 on pci2 fxp1: Ethernet address 00:02:b3:cc:1b:3f miibus1: on fxp1 inphy1: on miibus1 inphy1: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto isab0: at device 31.0 on pci0 isa0: on isab0 atapci0: port=20 0xf000-0xf00f,0-0x3,0-0x7,0-0x3,0-0x7 at device 31.1 on pci0 ata0: at 0x1f0 irq 14 on atapci0 ata1: at 0x170 irq 15 on atapci0 pci0: at device 31.3 (no driver attached) pci0: at device 31.5 (no driver attached) fdc0: port=20 0x3f7,0x3f0-0x3f5 irq 6 drq 2 on acpi0 fdc0: FIFO enabled, 8 bytes threshold fd0: <1440-KB 3.5" drive> on fdc0 drive 0 sio0 port 0x3f8-0x3ff irq 4 on acpi0 sio0: type 16550A sio1 port 0x2f8-0x2ff irq 3 on acpi0 sio1: type 16550A ppc0 port 0x778-0x77b,0x378-0x37f irq 7 on acpi0 ppc0: Generic chipset (NIBBLE-only) in COMPATIBLE mode ppbus0: on ppc0 plip0: on ppbus0 lpt0: on ppbus0 lpt0: Interrupt-driven port ppi0: on ppbus0 orm0: