Re: IPFilter on Solaris

Phil Dibowitz <[email protected]>
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <[email protected]>
salamond wrote:
> Hi, All.
> 
> After adding "keep frags" to the end of current rule, actually all my rules,
> the problem is solved.
> 
> The weird part is with 3.4.32, it works without "keep frags".
> Never mind. Problem solved.
> 
> And if anyone else ever encounter connection hangs while the exact
> rule should have pass it.
> Add "keep frags" to your rules, it may work for you too.

This makes sense. I'm guessing you, or the remote host, don't have Path MTU
Discovery disabled. Alternatively, something in the middle is disregarding
the DF bit... but yes, it's pretty much required to always have keep frags
enabled.

-- 
Phil Dibowitz                             [email protected]
Open Source software and tech docs        Insanity Palace of Metallica
http://www.phildev.net/                   http://www.ipom.com/

"Never write it in C if you can do it in 'awk';
 Never do it in 'awk' if 'sed' can handle it;
 Never use 'sed' when 'tr' can do the job;
 Never invoke 'tr' when 'cat' is sufficient;
 Avoid using 'cat' whenever possible" -- Taylor's Laws of Programming
signature.asc (application/pgp-signature, 260 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkooOm0ACgkQN5XoxaHnMrvd2ACdFDejxx6N5OEZSSxoBw70oEet
/GAAnR3pE0Is9bGzF7rkYBHU36yW6aUq
=gPM6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.