Unix Technical Forum

scrub reassemble tcp and nat causes problems with some sites

This is a discussion on scrub reassemble tcp and nat causes problems with some sites within the lucky.openbsd.misc forums, part of the OpenBSD category; --> Hi! I'm running OpenBSD 3.9 GENERIC as a NAT router. If I add the "reassemble tcp" option to my ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.misc

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:50 AM
Walter Haidinger
 
Posts: n/a
Default scrub reassemble tcp and nat causes problems with some sites

Hi!

I'm running OpenBSD 3.9 GENERIC as a NAT router.

If I add the "reassemble tcp" option to my scrub rule in pf.conf,
I have trouble connecting to some sites, particulary ebay (ebay.de,
ebay.at and ebay.com as well as e.g. kaufen.ebay.de) and
some other few sites, from a machine behind the NAT router.

Connects time out or have long delays if the site responds at all.
If connecting directly from OpenBSD, using lynx or squid running on
the router, there is no problem.

If I omit "reassemble tcp" everything works fine, i.e. with:
scrub all no-df fragment reassemble random-id

I've never noticed the problem before because I was running the
squid proxy on the router. Now I've moved it to a different machine
which is NATted too. Please note that it is not a squid issue
as timeouts occur regardless of proxy use if on a NATted machine.

Unfortunately I cannot determine why only some sites have troubles
and that's why I seeking advice here on howto further diagnose
the problem.

Any hints are appreciated!

Regards,
Walter

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:34 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com