IPFW with NAT (breakage with vlanhwtag enabled) Re: IPFW with NAT : Problems with duplicate packets on FreeBSD 10.3-RC3

2016-04-09 Thread Dr Josef Karthauser
> On 8 Apr 2016, at 10:03, Dr Josef Karthauser wrote: > >> On 8 Apr 2016, at 06:51, Ian Smith > > wrote: >> >> On Thu, 7 Apr 2016 17:08:38 +0100, Dr Josef Karthauser wrote: >> >>> Looks like the first packet is being

Re: IPFW with NAT : Problems with duplicate packets on FreeBSD 10.3-RC3

2016-04-08 Thread Dr Josef Karthauser
> On 8 Apr 2016, at 06:51, Ian Smith wrote: > > On Thu, 7 Apr 2016 17:08:38 +0100, Dr Josef Karthauser wrote: > > [ AppleMail msgs fail to quote properly in pine, so a partial quote: ] > >> Looks like the first packet is being retransmitted, which means that >> the nat

Re: IPFW with NAT : Problems with duplicate packets on FreeBSD 10.3-RC3

2016-04-07 Thread Ian Smith
On Thu, 7 Apr 2016 17:08:38 +0100, Dr Josef Karthauser wrote: [ AppleMail msgs fail to quote properly in pine, so a partial quote: ] > Looks like the first packet is being retransmitted, which means that > the nat is probably misconfigured and the TCP connection is broken in > some strange

Re: IPFW with NAT : Problems with duplicate packets on FreeBSD 10.3-RC3

2016-04-07 Thread Dr Josef Karthauser
> On 8 Apr 2016, at 00:11, Dr Josef Karthauser wrote: > >> On 7 Apr 2016, at 17:08, Dr Josef Karthauser > > wrote: >> >> Looks like the first packet is being retransmitted, which means that the nat >> is probably

Re: IPFW with NAT : Problems with duplicate packets on FreeBSD 10.3-RC3

2016-04-07 Thread Dr Josef Karthauser
> On 7 Apr 2016, at 17:08, Dr Josef Karthauser wrote: > > Looks like the first packet is being retransmitted, which means that the nat > is probably misconfigured and the TCP connection is broken in some strange > way. > > Does anyone have a clue as to where to look? The

IPFW with NAT : Problems with duplicate packets on FreeBSD 10.3-RC3

2016-04-07 Thread Dr Josef Karthauser
I’m scratching my head with an IPFW / NAT configuration; could someone please throw me a bone? I’ve got a jail, and I’m NATing using IPFW to connect it to the outside world. In particular I’m forwarding port 8080 from the host’s public address to the jail’s private address. When I pull an