From owner-freebsd-pf@FreeBSD.ORG Tue May 3 06:29:33 2011 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 4DA58106566C; Tue, 3 May 2011 06:29:33 +0000 (UTC) (envelope-from snabb@epipe.com) Received: from tiktik.epipe.com (tiktik.epipe.com [IPv6:2001:1828:0:3::2]) by mx1.freebsd.org (Postfix) with ESMTP id 0AB538FC19; Tue, 3 May 2011 06:29:32 +0000 (UTC) Received: from tiktik.epipe.com (tiktik.epipe.com [IPv6:2001:1828:0:3::2]) by tiktik.epipe.com (8.14.4/8.14.4) with ESMTP id p436TT0K022213 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 3 May 2011 06:29:30 GMT (envelope-from snabb@epipe.com) X-DKIM: Sendmail DKIM Filter v2.8.3 tiktik.epipe.com p436TT0K022213 DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=epipe.com; s=default; t=1304404170; x=1305008970; bh=uz5U/CRUnb5x4xoCMzRhNwlsTr1SkMKxm+/BIfct7rc=; h=Date:From:To:cc:Subject:In-Reply-To:Message-ID:References: MIME-Version:Content-Type; b=aQM90aRv08ZtDD1p7KCqj7HcAUj05Wtta4CVhMs7bp8S3hIQRtGgIFH4mUz+uoBpy bHpK7w1kKyY5iugl/WyTg/8WDw6WkF8bA8S5+D0I2OSXWxG/OiYQFL9IzT18kHfQgT drmK1HQUxCitPlV0o/MNDBFTOeBcxp6kSfuRroVU= Date: Tue, 3 May 2011 06:29:29 +0000 (UTC) From: Janne Snabb To: Vlad Galu In-Reply-To: Message-ID: References: <20110503015854.GA31444@icarus.home.lan> <20110503060106.GA36331@icarus.home.lan> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.2.7 (tiktik.epipe.com [IPv6:2001:1828:0:3::2]); Tue, 03 May 2011 06:29:30 +0000 (UTC) Cc: freebsd-stable@freebsd.org, Jeremy Chadwick , freebsd-pf@freebsd.org Subject: Re: RELENG_8 pf stack issue (state count spiraling out of control) X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 03 May 2011 06:29:33 -0000 On Tue, 3 May 2011, Vlad Galu wrote: > Disabling scrubbing altogether seems like a good next step. I used to get all kinds of strange problems when I tried scrubbing on FreeBSD 8.1. Especially with IPv6 traffic. After I disabled scrubbing altogether I have had zero problems. The IP & TCP stacks behind this particular pf are good ones anyway, so scrubbing was useless anyway. My belief is that scrubbing is just broken, but I do not have any hard facts about it. I did not bother wasting my time trying to debug it after I noticed that the pf code has not been updated from the upstream for quite a while. The first thing would be to get on the same level with the upstream in case the problem is fixed there. However, I do not want to touch OpenBSD code for personal reasons. -- Janne Snabb / EPIPE Communications snabb@epipe.com - http://epipe.com/