Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable [SOLVED]

2017-09-01 Thread Graham Menhennitt
On 31/08/2017 22:27, Andrey V. Elsukov wrote: On 31.08.2017 15:10, Graham Menhennitt wrote: On 10-Stable, the interface is re1. The output of 'ifconfig re1 | grep options' is: options=8209b nd6

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-09-01 Thread Ian Smith
On Thu, 31 Aug 2017 15:27:47 +0300, Andrey V. Elsukov wrote: > On 31.08.2017 15:10, Graham Menhennitt wrote: > > On 10-Stable, the interface is re1. The output of 'ifconfig re1 | grep > > options' is: > > options=8209b > >

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-08-31 Thread Andrey V. Elsukov
On 31.08.2017 15:10, Graham Menhennitt wrote: > On 10-Stable, the interface is re1. The output of 'ifconfig re1 | grep > options' is: > options=8209b > > nd6 options=29 > > On

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-08-31 Thread Graham Menhennitt
On 31/08/2017 20:03, Andrey V. Elsukov wrote: On 31.08.2017 13:01, Andrey V. Elsukov wrote: Does anybody please have any ideas on this, please? Can you show the output of `ifconfig igb1 | grep flags` on stable/10 and stable/11? Sorry, I wanted to write `ifconfig igb1 | grep options`.

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-08-31 Thread Andrey V. Elsukov
On 31.08.2017 13:01, Andrey V. Elsukov wrote: >> Does anybody please have any ideas on this, please? > > Can you show the output of `ifconfig igb1 | grep flags` on stable/10 and > stable/11? Sorry, I wanted to write `ifconfig igb1 | grep options`. -- WBR, Andrey V. Elsukov signature.asc

Re: ipfw kernel NAT performance much worse in 11-Stable than 10-Stable

2017-08-31 Thread Andrey V. Elsukov
On 29.08.2017 12:33, Graham Menhennitt wrote: > However, the performance on the 11-Stable box is much worse. For file > transfers I get about 1/10th the speed. Incoming TLS connections often > fail to establish. Looking (from outside the box) at the interface in > Wireshark shows lots of packets