From owner-freebsd-stable@FreeBSD.ORG Wed Dec 13 20:39:52 2006 Return-Path: X-Original-To: freebsd-stable@freebsd.org Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 3B34B16A516 for ; Wed, 13 Dec 2006 20:39:52 +0000 (UTC) (envelope-from spork@bway.net) Received: from xena.bway.net (xena.bway.net [216.220.96.26]) by mx1.FreeBSD.org (Postfix) with ESMTP id D5B3043CA3 for ; Wed, 13 Dec 2006 20:38:20 +0000 (GMT) (envelope-from spork@bway.net) Received: (qmail 74948 invoked by uid 0); 13 Dec 2006 20:39:51 -0000 Received: from unknown (HELO office-dhcp-32.bway.net) (spork@bway.net@216.220.107.32) by smtp.bway.net with (DHE-RSA-AES256-SHA encrypted) SMTP; 13 Dec 2006 20:39:51 -0000 Date: Wed, 13 Dec 2006 15:31:44 -0500 (EST) From: Charles Sprickman To: Pete French In-Reply-To: Message-ID: <20061213152911.L95481@sporker.bway.net> References: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Cc: freebsd-stable@freebsd.org Subject: Re: pf killing NFS X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 13 Dec 2006 20:39:52 -0000 On Wed, 13 Dec 2006, Pete French wrote: >> I'm running a 6.2-RC1 box (cvsup'd today) that has two broadcom nics. One >> is an internal network (nfs) and the other is external. > ... >> Doing something like "ls /usr/ports" will just hang until interrupted. >> Using tcp for nfs makes it workable, but very slow. > > Oddly enough I hit precisely this problem last night - with a cvsup from a > few days ago. I have tried adding the 'no-df' flag to the scrub rules, but this > did not help much. What I ended up doing was this: I pulled the "scrub in all" line and replaced it with a "scrub in on bge0". I don't really care about scrubbing on the internal network. All works as expected now. Glad to have the bad checksum error explained, that had me thinking I'd be visiting the co-lo to track down a flakey cable. :) Charles > scrub in on bge0 proto tcp fragment reassemble random-id > > so that I am not scrubbing UDP traffic. this works fine. > > -pete. >