Re: pf half-open tcp in state table

2018-02-10 Thread Matthieu Herrb
On Fri, Feb 09, 2018 at 11:11:18AM +0100, Matthieu Herrb wrote: > Hi, > > I've recently setup a new pair of OpenBSD 6.2 pf firewalls (with carp) > in my lab, and that's not performing very well. > > tcp-based NFS v3 and v4 traffic (between Linux clients and a NetApp > server) through it is strugg

pf half-open tcp in state table

2018-02-09 Thread Matthieu Herrb
Hi, I've recently setup a new pair of OpenBSD 6.2 pf firewalls (with carp) in my lab, and that's not performing very well. tcp-based NFS v3 and v4 traffic (between Linux clients and a NetApp server) through it is struggling, and some SSH or HTTPS transfers are stalling, with their states disapear