From owner-freebsd-net@FreeBSD.ORG Sat Mar 4 14:51:45 2006 Return-Path: X-Original-To: net@freebsd.org Delivered-To: freebsd-net@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F37B516A420 for ; Sat, 4 Mar 2006 14:51:44 +0000 (GMT) (envelope-from pieter@thedarkside.nl) Received: from mail.thelostparadise.com (129pc197.sshunet.nl [145.97.197.129]) by mx1.FreeBSD.org (Postfix) with ESMTP id ECA4D43D45 for ; Sat, 4 Mar 2006 14:51:38 +0000 (GMT) (envelope-from pieter@thedarkside.nl) Received: from [195.16.84.92] (edinburgh.thelostparadise.com [195.16.84.92]) by mail.thelostparadise.com (8.13.1/8.13.1) with ESMTP id k24EpXD6099601 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sat, 4 Mar 2006 15:51:34 +0100 (CET) (envelope-from pieter@thedarkside.nl) Message-ID: <4409A975.1080108@thedarkside.nl> Date: Sat, 04 Mar 2006 15:51:33 +0100 From: Pieter de Boer User-Agent: Thunderbird 1.5 (X11/20060118) MIME-Version: 1.0 To: Adam McDougall References: <20060304142802.GA63144@egr.msu.edu> In-Reply-To: <20060304142802.GA63144@egr.msu.edu> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: net@freebsd.org Subject: Re: PR kern/93849 IP checksum broken by pf no-df over bridge X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 04 Mar 2006 14:51:45 -0000 Adam McDougall wrote: > Could someone possibly take a look at this and let me know if it > looks 'broken' or if I might be doing something wrong? I am in > a crunch to choose a firewall solution within a few weeks and it > would help me to know if this issue can be solved. FreeBSD/pf > seemed an appropriate solution so far, especially since it has > CARP, pfsync, (and altq which im not using (yet?)). You could try compiling pf using CFLAGS=-O instead of -O2. This fixed a checksum problem I had. That probably was an entirely different issue, but perhaps it does help.. -- Pieter