Has anyone experienced problems with AFS servers (particularly writes) when
using IP Filter?

Problem: write access to AFS volumes abominably slow, 15 minutes for a
simple  16-meg file.

This problem seems to be present when using "keep state". If I trim the
"keep state" entries from my ruleset and make it a completely stateless
firewall otherwise all the same, it works fine and writes are very quick.

I put log statements on all block in lines to make sure I wasn't
inadvertantly blocking some important IP, and nothing appeared.  I tested
that my log statements were working by doing pings and nmaps from
non-listed hosts and seeing entries appear.

OS: Solaris 8
Compiler: SunStudio 11
Pfil 2.1.11 file PFILEDEBUG line removed from Makefile
IPFilter 4.1.13


Reply via email to