From owner-freebsd-questions@freebsd.org Sat Apr 18 17:52:06 2020 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id A0CF82A8A0E for ; Sat, 18 Apr 2020 17:52:06 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: from mail-qk1-x731.google.com (mail-qk1-x731.google.com [IPv6:2607:f8b0:4864:20::731]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 494LBY3ry6z4cXW for ; Sat, 18 Apr 2020 17:52:05 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: by mail-qk1-x731.google.com with SMTP id 20so6066257qkl.10 for ; Sat, 18 Apr 2020 10:52:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tenebras-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=FJ4VpEGvVK0/dg73/1zpqevMkszSxo+M0E4IGoM+lOo=; b=YIuXNwDfd5A/qr3/L1AaWhQz1N/BifONc4+8Wbmuw5LHSaZ4VqwnFVfVExVtKF0TYK 8Z4nUF4PN55/8aMU0o3zVRoTzPk1gs0tlyQYhwWm/1SEbGUlmGc4Mtt18hnrgvUs1XxY PZH+zAIwkuJeZlgBxth8/9UIdMeqZp2k67YyK5v6wYmNqWBhJG8q0hq0yyjc18Dx9mFe a2WSLXKvefwfkKTjuosdSOSWsWAKZVWayieijibc7FlZEKz7+1y9CwgT7mCR6swW15AA iRgwCKmpN5cEU9JJOPl1+/Juod1I5rrh2lQhbIDj/tYNFf107uB8LwnKsyEdUNnfGUOx dvNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=FJ4VpEGvVK0/dg73/1zpqevMkszSxo+M0E4IGoM+lOo=; b=NwLFKvtj1bMGTt6FFgQGwyWoLc0qoJjLV3AZKjvYBFyUIyimlYl1WegDUkm7qjS8H9 laVKzegr5q3OQe9UL52VISFS+r7XI9qBX3Y0Ydz6KbT+blACavsyO2+Z00amT1Qapt87 kJcplxpCG/20UQnBJ2LRiyiRtHzX5XMV2yOw5TKivTbYYLH/gartuE2byG+fof2at2oy QqFtuIg3efT2s555NObFgEzafb3zpB6a6yQ+G7m9W5bVf9HlZoq0R0lK7HEtGNhjz7u9 2dwvCsQqkDPhsn/XdcjHzWzGEA59o+uNFvST3K/6ipB0Fgqef4q+l/Ns91Mr8c4wmkYV xSsg== X-Gm-Message-State: AGi0Pua6nVfQVi3B5ICPh18PkC0bZSfXmt5WrkfUH5x+j3bt8hvY9Owi wEIlxKRQcgHzkzYylSTyTQj0G/ymdw5m8Zj8aVTSHi6hxc0= X-Google-Smtp-Source: APiQypJ1bl+knYF+PF46LN8oObs4eaQhzXchWJElc0LlQnKWjlpZrUWe1EROXOGs+QQHgHBFZfGWYNSRbsFmTf/3O38= X-Received: by 2002:a37:c0d:: with SMTP id 13mr8844688qkm.25.1587232324179; Sat, 18 Apr 2020 10:52:04 -0700 (PDT) MIME-Version: 1.0 References: <0e61aeb7-03ff-6016-3f23-1b00630b4af6@tundraware.com> In-Reply-To: <0e61aeb7-03ff-6016-3f23-1b00630b4af6@tundraware.com> From: Michael Sierchio Date: Sat, 18 Apr 2020 10:51:28 -0700 Message-ID: Subject: Re: Changes To nat-ing Behaviour? To: Tim Daneliuk Cc: FreeBSD Mailing List X-Rspamd-Queue-Id: 494LBY3ry6z4cXW X-Spamd-Bar: --- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=tenebras-com.20150623.gappssmtp.com header.s=20150623 header.b=YIuXNwDf; dmarc=none; spf=none (mx1.freebsd.org: domain of kudzu@tenebras.com has no SPF policy when checking 2607:f8b0:4864:20::731) smtp.mailfrom=kudzu@tenebras.com X-Spamd-Result: default: False [-3.29 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; R_DKIM_ALLOW(-0.20)[tenebras-com.20150623.gappssmtp.com:s=20150623]; FROM_HAS_DN(0.00)[]; IP_SCORE(-1.99)[ip: (-9.13), ipnet: 2607:f8b0::/32(-0.33), asn: 15169(-0.43), country: US(-0.05)]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-questions@freebsd.org]; DMARC_NA(0.00)[tenebras.com]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; TO_MATCH_ENVRCPT_SOME(0.00)[]; TO_DN_ALL(0.00)[]; DKIM_TRACE(0.00)[tenebras-com.20150623.gappssmtp.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[1.3.7.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.4.6.8.4.0.b.8.f.7.0.6.2.list.dnswl.org : 127.0.5.0]; R_SPF_NA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; SUBJECT_ENDS_QUESTION(1.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; RCVD_COUNT_TWO(0.00)[2]; RCVD_TLS_ALL(0.00)[] Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.29 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 18 Apr 2020 17:52:06 -0000 Showing your ruleset would allow us to comment meaningfully. On Sat, Apr 18, 2020 at 10:19 AM Tim Daneliuk wrote= : > I recently upgraded a FBSD 11.3 machine to -STABLE as of a few weeks ago. > > This machine acts as a firewall and nats between the outside world > and an internal nonroutable network. > > Configuration is stable and has not changed in years. > > Today I noted that speeds on the LAN side are about half of what is > available > going out to the internet. > > I eliminated cables, interfaces, and switches and confirmed that - even i= f > I plug a machine directly into the FBSD nat box, I get half the speed tha= t > box gets out to the net. > > I'm at a loss since I've changed nothing in the config. > > Ideas would be most appreciated. > > TIA, > -- > > -------------------------------------------------------------------------= --- > Tim Daneliuk tundra@tundraware.com > PGP Key: http://www.tundraware.com/PGP/ > > _______________________________________________ > freebsd-questions@freebsd.org mailing list > https://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to " > freebsd-questions-unsubscribe@freebsd.org" > --=20 "Well," Brahm=C4=81 said, "even after ten thousand explanations, a fool is = no wiser, but an intelligent person requires only two thousand five hundred." - The Mah=C4=81bh=C4=81rata