From owner-freebsd-net@FreeBSD.ORG Mon Dec 5 14:41:15 2005 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1FE3316A41F for ; Mon, 5 Dec 2005 14:41:15 +0000 (GMT) (envelope-from spadge@fromley.net) Received: from mta09-winn.ispmail.ntl.com (mta09-winn.ispmail.ntl.com [81.103.221.49]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1F34243D76 for ; Mon, 5 Dec 2005 14:41:10 +0000 (GMT) (envelope-from spadge@fromley.net) Received: from aamta12-winn.ispmail.ntl.com ([81.103.221.35]) by mta09-winn.ispmail.ntl.com with ESMTP id <20051205144109.DUXU8609.mta09-winn.ispmail.ntl.com@aamta12-winn.ispmail.ntl.com>; Mon, 5 Dec 2005 14:41:09 +0000 Received: from tobermory.home ([82.18.8.27]) by aamta12-winn.ispmail.ntl.com with ESMTP id <20051205144109.JALC18425.aamta12-winn.ispmail.ntl.com@tobermory.home>; Mon, 5 Dec 2005 14:41:09 +0000 Received: from [192.168.124.185] (unknown [192.168.124.185]) by tobermory.home (Postfix) with ESMTP id 4FAEFA6C99; Mon, 5 Dec 2005 14:41:06 +0000 (GMT) Message-ID: <4394518C.1030104@fromley.net> Date: Mon, 05 Dec 2005 14:41:16 +0000 From: Spadge User-Agent: Mozilla Thunderbird 1.0.6 (Windows/20050716) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Alvaro Saurin References: <79336124-B4D5-43A3-88D2-9FE0D4A4D120@dcs.gla.ac.uk> In-Reply-To: <79336124-B4D5-43A3-88D2-9FE0D4A4D120@dcs.gla.ac.uk> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-net@freebsd.org Subject: Re: Dummynet and fragments X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 05 Dec 2005 14:41:15 -0000 Alvaro Saurin wrote: > The problem comes here: if I 'ping' between these two machines, > everything is fine, but if I 'ping' with a packet size of, ie, 2000, no > packets arrive at the receiver. Does it have to do with fragmented > packets? Do I have to include any other rule for dealing with fragments? 65100 0 0 deny log logamount 5000 ip from any to any frag Does this not effectively kill all frags? Are your unreceived packets showing up in the log? And if not, are you sure that it's BSD4 that's losing them, and not ubuntu3? Here's how my firewall handles frags: # Allow IP fragments to pass through /sbin/ipfw add pass all from any to any frag You may also want to set up something similar to handle ICMP. I've not used dummynet pipes in ages, I wonder if setting a larger queue would help with my disconnect problems, or whether I really do just need to give up and reinstall the entire OS. -- Spadge "Intoccabile" www.fromley.com