From owner-freebsd-net@FreeBSD.ORG Sat Oct 22 20:51:52 2005 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6FE7A16A449 for ; Sat, 22 Oct 2005 20:51:52 +0000 (GMT) (envelope-from mgrooms@shrew.net) Received: from shrew.net (shrew.net [200.46.204.197]) by mx1.FreeBSD.org (Postfix) with ESMTP id C63FF43D45 for ; Sat, 22 Oct 2005 20:51:51 +0000 (GMT) (envelope-from mgrooms@shrew.net) Received: from hole.shrew.net (66-90-165-114.dyn.grandenetworks.net [66.90.165.114]) by shrew.net (Postfix) with ESMTP id D8B38981CDD; Sat, 22 Oct 2005 18:46:07 +0000 (GMT) Received: from [10.22.200.21] ([10.22.200.21]) by hole.shrew.net (8.13.4/8.13.4) with ESMTP id j9MIk7Y0077455; Sat, 22 Oct 2005 13:46:07 -0500 (CDT) (envelope-from mgrooms@shrew.net) Message-ID: <435A88EF.6010706@shrew.net> Date: Sat, 22 Oct 2005 13:46:07 -0500 From: Matthew Grooms User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206) X-Accept-Language: en-us, en MIME-Version: 1.0 To: volker@vwsoft.com References: <435A85F7.3000909@shrew.net> In-Reply-To: <435A85F7.3000909@shrew.net> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-2.0 (hole.shrew.net [66.90.165.114]); Sat, 22 Oct 2005 13:46:07 -0500 (CDT) X-Spam-Status: No, score=-2.8 required=5.0 tests=ALL_TRUSTED,AWL autolearn=ham version=3.0.4 X-Spam-Checker-Version: SpamAssassin 3.0.4 (2005-06-05) on hole.shrew.net Cc: freebsd-net@freebsd.org Subject: Re: IPSec tcp session stalling ( me too ) ... X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 22 Oct 2005 20:51:52 -0000 Matthew Grooms wrote: > Volker, > > ipfw is enabled. I use purely IPSEC so I would agree that GRE isn't the > problem. This behavior is 100% reproducible for me. If traffic is > forwarded from the host providing the ESP protection or if the Sorry, this should have read ... > problem. This behavior is 100% reproducible for me. If traffic is > originating from the host providing the ESP protection or if the > firewall package is disabled, the problem goes away. > -Matthew