From owner-freebsd-net@FreeBSD.ORG Fri May 14 21:04:25 2010 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B33E81065673 for ; Fri, 14 May 2010 21:04:25 +0000 (UTC) (envelope-from pyunyh@gmail.com) Received: from mail-px0-f182.google.com (mail-px0-f182.google.com [209.85.212.182]) by mx1.freebsd.org (Postfix) with ESMTP id 813CF8FC1B for ; Fri, 14 May 2010 21:04:25 +0000 (UTC) Received: by pxi7 with SMTP id 7so100221pxi.13 for ; Fri, 14 May 2010 14:04:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:received:from:date:to:cc :subject:message-id:reply-to:references:mime-version:content-type :content-disposition:in-reply-to:user-agent; bh=qpVI4/QPopGrTzn3/oct4wWSRmXDCNB9J44cvaxnYJA=; b=s40NImRFy+PJz+Ycn4yF20Zgxn96y+H0+y4pmslDXd4iiFzu+G30KlpdmOme9XcLzr M9w8hh0vhW04uxuMJK1vs/D7acIESIMhGNvBHv1P6X2PoFpJSw3OLF5kSM7FUgb3mVtW elvMbb0WRhlWjAnpFuXdeffTddLPfVxE3jKTM= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=from:date:to:cc:subject:message-id:reply-to:references:mime-version :content-type:content-disposition:in-reply-to:user-agent; b=vz6VtUzCjeG3o/ecQMDwYE78NlxnFrRnH8LNv9nn+5GyoTbotlNKaxIBcmWoIGXPWF f5Cawdp4m6ezwBXTu7tuadAMROoMnspfbQhf+wqrpi8XzSKgD03Vea9wx57ruCPnceNx fgE1adTAFyZndeKs2Vemzpha95PPJUOnYnbHE= Received: by 10.140.248.16 with SMTP id v16mr1113280rvh.230.1273871065003; Fri, 14 May 2010 14:04:25 -0700 (PDT) Received: from pyunyh@gmail.com ([174.35.1.224]) by mx.google.com with ESMTPS id b10sm2353274rvn.3.2010.05.14.14.04.23 (version=TLSv1/SSLv3 cipher=RC4-MD5); Fri, 14 May 2010 14:04:24 -0700 (PDT) Received: by pyunyh@gmail.com (sSMTP sendmail emulation); Fri, 14 May 2010 14:03:42 -0700 From: Pyun YongHyeon Date: Fri, 14 May 2010 14:03:42 -0700 To: list@cykotix.com Message-ID: <20100514210342.GD24686@michelle.cdnetworks.com> References: <20100514145612.14566x4tj40yhyos@webmail.lahni.com> <20100514192239.GC24686@michelle.cdnetworks.com> <20100514155638.21116k5xymc7cb8c@webmail.lahni.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20100514155638.21116k5xymc7cb8c@webmail.lahni.com> User-Agent: Mutt/1.4.2.3i Cc: freebsd-net@freebsd.org Subject: Re: Packet Loss on FW1 but not FW2 (CARP + PF on FBSD8) X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: pyunyh@gmail.com List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 14 May 2010 21:04:25 -0000 On Fri, May 14, 2010 at 03:56:38PM -0400, list@cykotix.com wrote: > Quoting Pyun YongHyeon : > > >On Fri, May 14, 2010 at 02:56:12PM -0400, list@cykotix.com wrote: > >>Hello, > >> > >>I recently just purchased 2 Soekris5501 with identical 120gb 2.5" WD > >>Scorpio HDDs. I'm using them for network failover, using CARP, PF and > >>pfSync on FreeBSD 8-STABLE. > >> > >>The short version of my problem: > >> > >>I setup FW2 first, imaged its hard drive to FW1. I changed the > >>necessary configs to update the IPs and ensure FW1 was carp MASTER. > >>Using a known working port on the switch, I continue to get 70% packet > >>loss on FW1 on vr0 (vr0 - extif, vr1 - intif, vr2 - pfsync). If I > >>flip FW1 and FW2, the packet loss follows FW1. I took FW1 home, > >>plugged it into my home network on vr0 and it works fine with 0% > >>packet loss so the interface seems fine. I also took the IP bound to > >>vr0 on FW1 and bound it to vr0 on FW2 and the ISP isn't the problem. > >> > > > >Show me the output of "sysctl dev.vr.0.stats=1" and "netstat -ndI vr0". > > soekris1# sysctl dev.vr.0.stats=1 > dev.vr.0.stats: -1 -> -1 > Please check the output of console. It would have printed some MAC counters maintained in driver. > soekris1# netstat -ndI vr0 > Name Mtu Network Address Ipkts Ierrs Opkts > Oerrs Coll Drop > vr0 1500 00:00:24:cc:cb:94 17491 0 14993 > 0 0 0 > vr0 1500 98.xxx.xxx.56 98.xxx.xxx.59 992 - 9374 > - - - > No Ierrs, so MAC counters would be more helpful here. > > soekris2# sysctl dev.vr.0.stats=1 > dev.vr.0.stats: -1 -> -1 > > soekris2# netstat -ndI vr0 > Name Mtu Network Address Ipkts Ierrs Opkts > Oerrs Coll Drop > vr0 1500 00:00:24:ca:40:60 575909 0 588703 > 0 0 0 > vr0 1500 98.xxx.xxx.56 98.xxx.xxx.60 10029 - 53106 > - - - > > > Let me know if you need any other information! Thanks! > > Patrick