On 1/25/2015 10:33 AM, Robin Helgelin wrote: > Hi, > > I’m investigating a setup with the returning data from a DNAT rule is going > extremely slow. > > Example rule looks like this: > DNAT net $DMZ_MAIL:22 tcp 9022 - > pu.bl.ic.ip > > interfaces > net eth0 detect tcpflags,nosmurfs > loc eth1 detect routeback > > masq > eth0 192.168.60.0/24 pu.bl.ic.ip > > params: > DMZ_MAIL=loc:192.168.60.2 > > > Using SCP copying files to the server gives as full speed as my internet > permits. Receiving files throttles the traffic at around 2-3KB/s.
Might we see the output of 'shorewall dump' collected as described at http://www.shorewall.org/support.htm#guidelines? Thanks, -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ New Year. New Location. New Benefits. New Data Center in Ashburn, VA. GigeNET is offering a free month of service with a new server in Ashburn. Choose from 2 high performing configs, both with 100TB of bandwidth. Higher redundancy.Lower latency.Increased capacity.Completely compliant. http://p.sf.net/sfu/gigenet
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
