tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: IPv6 TCP sessions hangs when using PF keep state

Darren Reed <> writes:

> On 7/01/2013 12:43 AM, Greg Troxel wrote:
>> It very dimly rings a bell.  I think I saw a problem where ipfilter did
>> range checks on sequence numbers, but this depended on seeing window
>> scaling options.
>> So I would use ipfstat -inh6 (and -onh6) and find the blocked packets,
>> and add log statements, and also dump your state entries.  It wouldn't
>> surprise me if there's a bug.
> I don't mean to dis you, but recommending the use of ipfstat to someone
> that is using pf won't help.

Indeed, a fair point.   But surely there is some pfstat equivalent.

(FWIW, I am successfully using ipfilter on IPv6, from netbsd-5.)

Attachment: pgpW2Yr7TJ4Cs.pgp
Description: PGP signature

Home | Main Index | Thread Index | Old Index