Loosing TCP/IPv4 connections with jails+pf on 10.0-RELEASE

Jean-Sébastien Pédron dumbbell at FreeBSD.org
Thu Feb 13 16:09:59 UTC 2014


On 13.02.2014 16:38, Gleb Smirnoff wrote:
> Can you please try attached patch?

Yes, thank you, I'll rebuild it right now.

FWIW, the problem appeared again a few days ago. We stopped pf and
unloaded/reloaded the pf module to see if this fixed the problem. That
was yesterday and today we have no connection loss. We'll see how it
goes for the next few days.

> J> IPv6 connections are NOT affected: they work perfectly.
> 
> That's really strange. Are they running stateless via pf?

Our jails have their own IPv6 so those connections don't go through pf.
We just need pf for IPv4 because we have only one public address.

-- 
Jean-Sébastien Pédron

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 899 bytes
Desc: OpenPGP digital signature
URL: <http://lists.freebsd.org/pipermail/freebsd-net/attachments/20140213/d76c4be5/attachment.sig>


More information about the freebsd-net mailing list