problems with synproxy on 5.3-stable

Andy Hilker ah at crypta.net
Wed Feb 9 05:10:58 PST 2005


Hi,

i have migrated from ipfilter to pf and have problems with synproxy.
First: many thanks for importing pf to freebsd :)

pf protects only localhost with multiple IPs and jails. There is
only 1 outside interface.

When i use "keep state" everything works normally. If using synproxy
a few people having problems accessing pop3 and http on my server.
Requests are incomplete or corrupt (for example get requests in
httpd-access.log). But it seems that this problem occurs only for
a few people.

Is there any way to "count" or monitor the activity of synproxy to
see how much clients are blocked? 
Any ideas why synproxy does not work at this "few peoples"?

Thanks in advance and best regards,
Andy



More information about the freebsd-pf mailing list