Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What causes mismatching states in connections?

    Scheduled Pinned Locked Moved Firewalling
    1 Posts 1 Posters 124 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • senseivitaS
      senseivita
      last edited by

      I'm trying to fix my email. I reinstalled a firewall but since then I'm unable to make it work again.

      In pfTop I get mismatched SYN_SENT:ESTABLISHED/ESTABLISHED:SYN_SENT states, unless I log in to the remote firewall, from where I can use telnet to test successfully. The only difference is that the connection instead of being natted, originates right at the other end of the tunnels. Speaking of tunnels, plural; this is an ECMP link/route between the firewalls (FRR/OSPF), thus I thought it could be routing but I ruled out everything already. I even scavenged the live config file for lingering conflicting settings from the protocol switching (directly addressable WireGuard interfaces keep around that data even though they no longer show it when flipped to OpenVPN or another thing)

      pftop.png

      I moved then to MTU/MSS, but I already found the perfect value for each of the overheads OpenVPN, GRE6 over GIF, and WireGuard has, played with them at the interface-, protocol-, and system level (System/Advanced/Firewall & NAT), so either I haven't actually found the value(s) or that ain't it.

      Any ideas what could it be?
      Thanks.

      Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.