Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 26 Oct 2007 02:10:18 +0400
From:      Anton Yuzhaninov <citrin@citrin.ru>
To:        freebsd-net@freebsd.org
Subject:   Re: RELENG_7: can't connect to Solaris
Message-ID:  <4721144A.5000407@citrin.ru>
In-Reply-To: <20071025125732.Q27636@niwun.pair.com>
References:  <47206EE2.6030606@citrin.ru>	<3171D7CB-2E63-4FAF-92A9-3907D44AB845@fnop.net>	<4720B3C5.9070806@citrin.ru> <20071025125732.Q27636@niwun.pair.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 25.10.2007 20:59, Mike Silbersack wrote:
> 
> On Thu, 25 Oct 2007, Anton Yuzhaninov wrote:
> 
>>> As silby@ already pointed out to me, try changing TCP_MAX_WINSHIFT in 
>>> src/sys/netinet/tcp.h to 4.
>>>
>>
>> With TCP_MAX_WINSHIFT 4 it works.
> 
> I have a fix for this already in HEAD, I'll merge it to releng_7 tonight.
> 
>> But from other host with RELENG_7 tcp to Solaris work fine with 
>> unmodified kernel:
> 
> Is there a firewall in one path, but not the other?
> 

Yes problem was in firewall, not Solaris/FreeBSD tcp stacks.

On Solaris was used ipfilter 3.4.18, and after 3.4.18 was fixed several bugs, which can cause such problems.
Probably this:

4.1.17 - Released 20 January 2007
....
fix tracking TCP window scaling in the state code

Or some other.

ipfilter rules (with keep state) permit tcp traffic from freebsd7 host, but really some packets was blocked.

Thanks.

-- 
WBR,
  Anton Yuzhaninov



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4721144A.5000407>