<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[SSH session disconnect, fragmenteg packets blocked.]]></title><description><![CDATA[<p dir="auto">Hello.</p>
<p dir="auto">My eth interface configured with some vlans on it and pfsense routes between this vlans.<br />
Everything works except SSH session between my pc and catalysts managment interface in another vlan.<br />
I can connect to device but after 20-30 seconds session dies.</p>
<p dir="auto">in attach picture with firewall log, there is blocked TCP:PA packed from my pc to this device.</p>
<p dir="auto">My version is<br />
2.0-RC1 (i386)<br />
built on Fri Mar 25 20:35:06 EDT 2011<br />
<img src="/public/_imported_attachments_/1/pfsense-screen.png" alt="pfsense-screen.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/pfsense-screen.png_thumb" alt="pfsense-screen.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/32266/ssh-session-disconnect-fragmenteg-packets-blocked</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 04:06:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/32266.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 31 Mar 2011 20:45:39 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 22 Jul 2011 13:15:42 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for these incredible pointers guys! I've been experiencing MANY problems with this in the past months. Never was able to figure it out. It actually only occurred for all IPv6 traffic between two VLANs on my network being connected via pfSense. Since IPv6 traffic is prioritized over IPv4 traffic, when connecting using DNS or NETBIOS names instead of an explicit IPv4 address, it would always cause trouble. It wasn't just one protocol, it was with every protocol and every type of traffic (i.e. RDP, filesharing over NETBIOS, streaming audo, SSH sessions). Very irritating. Strange that it didn't occur with IPv4 traffic though. Switching the setting at System -&gt; Advanced -&gt; Firewall/NAT -&gt; Firewall Optimization Options to conservative solved it all. And increased memory usage? Its still at 5% of the 4GB of RAM the machine is equipped with, just like it was before  :)</p>
<p dir="auto">Thanks!!</p>
]]></description><link>https://forum.netgate.com/post/288283</link><guid isPermaLink="true">https://forum.netgate.com/post/288283</guid><dc:creator><![CDATA[MrKoen]]></dc:creator><pubDate>Fri, 22 Jul 2011 13:15:42 GMT</pubDate></item><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 01 Apr 2011 20:17:45 GMT]]></title><description><![CDATA[<p dir="auto">My opinion is that SSH should work without troubles and in default configuration.</p>
<p dir="auto">It works everywhere, it's standard I think, so why not here?<br />
I was ready to switch to another solution for routing and firewalling….......<br />
But because I'm curios and like pfsence delay for 3-4 days is nothing.  8)</p>
]]></description><link>https://forum.netgate.com/post/273214</link><guid isPermaLink="true">https://forum.netgate.com/post/273214</guid><dc:creator><![CDATA[d_mito]]></dc:creator><pubDate>Fri, 01 Apr 2011 20:17:45 GMT</pubDate></item><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 01 Apr 2011 20:04:28 GMT]]></title><description><![CDATA[<p dir="auto">I'm not familiar with the specifics behind the firewall optimization options, or why normal works for some and others have to use conservative. Perhaps it has to do with the way your ssh client or server is configured.</p>
<p dir="auto">Personally I use conservative optimization because I have no shortage of RAM, and as a voip user I don't want to risk having the firewall drop any calls (or games, etc).</p>
]]></description><link>https://forum.netgate.com/post/273212</link><guid isPermaLink="true">https://forum.netgate.com/post/273212</guid><dc:creator><![CDATA[clarknova]]></dc:creator><pubDate>Fri, 01 Apr 2011 20:04:28 GMT</pubDate></item><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 01 Apr 2011 20:01:24 GMT]]></title><description><![CDATA[<p dir="auto">HAH  :)</p>
<p dir="auto">It's working now!<br />
Thanks a lot for your help…</p>
<p dir="auto">Only strange why it's doing this in normal behavior???  And only to routed packets<br />
SSH to any interface of pfsense is working well.</p>
<p dir="auto">Anyway thank you!</p>
]]></description><link>https://forum.netgate.com/post/273211</link><guid isPermaLink="true">https://forum.netgate.com/post/273211</guid><dc:creator><![CDATA[d_mito]]></dc:creator><pubDate>Fri, 01 Apr 2011 20:01:24 GMT</pubDate></item><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 01 Apr 2011 19:38:01 GMT]]></title><description><![CDATA[<p dir="auto">Try Conservative optimization, and maybe turn on the first option on that page.</p>
]]></description><link>https://forum.netgate.com/post/273208</link><guid isPermaLink="true">https://forum.netgate.com/post/273208</guid><dc:creator><![CDATA[clarknova]]></dc:creator><pubDate>Fri, 01 Apr 2011 19:38:01 GMT</pubDate></item><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 01 Apr 2011 18:53:40 GMT]]></title><description><![CDATA[<p dir="auto">Already changed this values:</p>
<p dir="auto">Disable Firewall Scrub<br />
Hardware Checksum Offloading<br />
Hardware TCP Segmentation Offloading</p>
<p dir="auto">But it doesn't help. Sometimes instead TCP:PA, blocked TCP:R<br />
and the same result, I can login do something and my session is broken.</p>
<p dir="auto">Anything else that can help????</p>
]]></description><link>https://forum.netgate.com/post/273205</link><guid isPermaLink="true">https://forum.netgate.com/post/273205</guid><dc:creator><![CDATA[d_mito]]></dc:creator><pubDate>Fri, 01 Apr 2011 18:53:40 GMT</pubDate></item><item><title><![CDATA[Reply to SSH session disconnect, fragmenteg packets blocked. on Fri, 01 Apr 2011 17:44:48 GMT]]></title><description><![CDATA[<p dir="auto">If it were me I would try changing some of the options on the System: Advanced: Firewall and NAT page.</p>
]]></description><link>https://forum.netgate.com/post/273195</link><guid isPermaLink="true">https://forum.netgate.com/post/273195</guid><dc:creator><![CDATA[clarknova]]></dc:creator><pubDate>Fri, 01 Apr 2011 17:44:48 GMT</pubDate></item></channel></rss>