TCP conection problems IBM VM -> FreeBSD

I have the following setup:

IBM VM mainframe <-> [Internet] <->  fbsd 6.2 router   <-> fbsd 4.10 smtp box
    "vm"                             ""       ""

When vm attempts to make a TCP connection (e.g., on port 25) to I see the following traffic on the router:

22:46:27.015389 IP > S 27523124:27523124(0) win 8192 <mss 1420,wscale 0,nop,nop,nop,timestamp 1888741492 0>
22:46:27.015523 IP > S 1745147473:1745147473(0) ack 3530628660 win 57344 <mss 1460>
22:46:27.056277 IP > R 3530628660:3530628660(0) win 0

I.e., the vm box appears to dislike the SYNACK from, and
sends an RST.  One might ask if it is the fault of vm or of

If I switch on "pf", the kernel packet filter, on, using
pfctl -e, with an empty /etc/pf.conf, the router discards the SYNACK
from  I realize that an empty /etc/pf.conf means that a
set of implicit rules are enabled, including some sanitize rules.

This leads me to believing that somehow sends a bad
SYNACK reply to vm.  But is perfectly capable of
accepting TCP connections from lots of machines out there, and the
router leavs the SYNACKs alone except when vm is on the receiving end.

I have stared at tcpdumps in order to try to understand what might be
wrong, unsuccessfully.  I have not found out how to make pf on be so kind as to log the reason for that it throws away
the SYNACK.  And I don't have access to nor knowledge to of the vm
system to get any information on why it dislikes the SYNACK.

Making tcp connections in the other direction ( -> vm)
works flawlessly.

I have tried enabling and disabling rfc1323 on, without
any change wrt this issue.

My questions:

  How can I debug this further?

  Was there a tcp bug in 4.10 that might be causing the observed
  behaviour?  (Is it fixed in 4.11?)

(I might be upgrading to a much more recent FreeBSD
version at some point, but I'd rather not hurry up with it since this
machine runs a lot of things.  Understanding this problem is important
in any case.)


