pf + ftp throughput

Darrin Chandler dwchandler at
Sun Jun 18 20:57:06 UTC 2006

On Fri, Jun 16, 2006 at 02:31:07PM -0500, J.D. Bronson wrote:
> for a trial, I am going to fire up a drive loaded with OpenBSD 3.9 
> and PF and see if there is anything better/worse with the same pf.conf 
> file.

I've been playing at home, trying to reproduce this behavior (sparc64,
OpenBSD). I haven't done so yet, but I don't have the best test cases. I
tried with a 12M file across the 'net, and what looked like the same
issue went away, so it was just fluctuations on the net. I tried the
same file from the firewall itself to a client, and times are virtually
identical. What I really need is two local clients going through the
firewall. If I get that going I'll let you know what I find.

FWIW, I Googled pretty heavily for this and didn't turn up much. I found
one mailing list message from years ago describing *exactly* the same
problem. Unfortunately I didn't see any followups or further problem

Are you also doing nat/rdr on this box? Have you run tcpdump on the
pflog interface to make sure you're matching the rules you think? I'd
like to track this down, so please feel free to send me any info you
think pertains to this.

Darrin Chandler            |  Phoenix BSD Users Group
dwchandler at   |  |

More information about the freebsd-questions mailing list