Re: FreeBSD, IPFW and the SIP/VoIP NAT problem

2017-09-26 Thread Graham Menhennitt
On 26/09/2017 10:35 PM, O. Hartmann wrote: Hello, trying to build a FreeBSD based router/PBX (Asterisk 13) appliance, I ran into several problems. My questions might have a "noobish" character, so my apology, my experiences with IPFW are not as thorough as they should be. ... The FreeBSD

Re: IPFW NAT behaviour different on 10-Stable versus 11-Stable [SOLVED]

2017-09-02 Thread Graham Menhennitt
On 02/09/2017 20:46, Ian Smith wrote: On Sat, 2 Sep 2017 11:44:51 +1000, Graham Menhennitt wrote: > I have a problem that seems to be a difference between ipfw/NAT > behaviour in 10-Stable versus 11-Stable. I have two servers: one running > 10-Stable and one running 11-Stable.

IPFW NAT behaviour different on 10-Stable versus 11-Stable

2017-09-01 Thread Graham Menhennitt
I have a problem that seems to be a difference between ipfw/NAT behaviour in 10-Stable versus 11-Stable. I have two servers: one running 10-Stable and one running 11-Stable. I'm using the same rule set on both (see below). It works correctly on 10-Stable but not on 11. The problem is seen on

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable [SOLVED]

2017-09-01 Thread Graham Menhennitt
On 31/08/2017 22:27, Andrey V. Elsukov wrote: On 31.08.2017 15:10, Graham Menhennitt wrote: On 10-Stable, the interface is re1. The output of 'ifconfig re1 | grep options' is: options=8209b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,WOL_MAGIC,LINKSTATE> nd6 options=29<P

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-08-31 Thread Graham Menhennitt
On 31/08/2017 20:03, Andrey V. Elsukov wrote: On 31.08.2017 13:01, Andrey V. Elsukov wrote: Does anybody please have any ideas on this, please? Can you show the output of `ifconfig igb1 | grep flags` on stable/10 and stable/11? Sorry, I wanted to write `ifconfig igb1 | grep options`.

ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-08-29 Thread Graham Menhennitt
I have two machines of similar CPU power that I use as routers. One is running 11-Stable as of a week ago and the other is 10-Stable from around the same time. They both run roughly the same IPFW rules (the syntax has changed slightly to run on the newer version). I've been using the 10-Stable

SIP registrations getting through firewall

2016-05-24 Thread Graham Menhennitt
Hello IPFW list, I'm running IPFW on FreeBSD 10-Stable. I thought I'd blocked any bad things coming in from the outside world. However, I'm seeing SIP registration attempts logged by Asterisk and I don't understand how they're getting through. A sample log message is: chan_sip.c: Registration

Re: connecting a PS4 via IPFW

2015-11-27 Thread Graham Menhennitt
; > Wed, Nov 25, 2015 at 04:00:12PM +1100, Graham Menhennitt: >> Hello IPFWers, >> >> I have a box running FreeBSD 10-stable that I use as a >> router/firewall/NAT. It runs IPFW and uses kernel NAT. My son is nagging >> me about playing multi-player online games on h

connecting a PS4 via IPFW

2015-11-24 Thread Graham Menhennitt
Hello IPFWers, I have a box running FreeBSD 10-stable that I use as a router/firewall/NAT. It runs IPFW and uses kernel NAT. My son is nagging me about playing multi-player online games on his Sony PS4. >From what I've read, I could enable UPnP. But I've tried compiling the net/miniupnpd port