View Single Post

   
  #3 (permalink)  
Old 02-16-2008, 08:11 AM
ngolo
 
Posts: n/a
Default Re: Bridging pf firewall not reliable

> Try to find another network card, or another machine.


So far I have had hang problem with at least two different hardwares:
- hme (100Mbit sun U10 network card driver)
- vge (1Gb Zyxel in a i86 pc )

How many network card shall I blind test before to find the good one !

Anybody with experience of pf bridging with steady trafic and no hangs
due to wrong overflow exception dealing ?

> The problem lies not with pf, but with flaky hardware.


On this I must say that I find pf not very good at bridging firewall:

I have this state table / window scaling problem I find hard to settle.
If the fist packets of tcp transaction -where tcpwindow scaling is
negociated- are not passing through the exact same rule, each end might
have a different value for the window scaling bit and trafic ceases.

On the other end, in bridging pf rules I am not sure on how to be sure
that both directions of the same tcp transaction passe trough the exact
same rule and state table.

Onother problem is with bridge and spanning tree, which is not working
as expected with my cisco gear, but this might be a cisco problem...

Many thanks

François
----
n@d.c where n=t, d=eig, c=ch
Reply With Quote