Cannot access a couple websites

Carl Hattingh carl.hattingh at gmail.com
Thu Aug 25 09:43:14 UTC 2016


On Thu, Aug 25, 2016 at 7:10 PM, Kristof Provost wrote:

> On 24 Aug 2016, at 16:02, Carl Hattingh wrote:
>
>> We are experiencing a issue which has me rather stumped.  We are using
>> Freebsd 10.3-RELEASE-p7 under Hyper-V 2012 R2 as a firewall (pf), and are
>> unable to browse to www.amazon.com and outlook.office365.com under
>> certain
>> circumstances.
>>
>> <snip>
>
>>
>> Has anyone got any ideas on what this could be?  We'd be grateful for any
>> assistance.
>>
>> You’re going to have to make a network capture between the gateway and
> the NTU device.
> Ideally not from the gateway itself (because that might hide checksum
> issues).
>
> Regards,
> Kristof
>

Thanks for the replies.  I finally managed to track down the issue, and it
was scrub after all.

I had "scrub all no-df reassemble tcp" and it was the "reassemble tcp"
command that was causing the issue.
I have now changed it to "scrub all no-df random-id".

I had tested completely commenting out the scrub command earlier to no
avail, but clearly wasn't thorough enough in killing states between tests.


More information about the freebsd-net mailing list