View Single Post
  #2   (View Single Post)  
Old 23rd June 2011
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,983
Default

Quote:
Originally Posted by magnesik View Post
Is it possible to filter packets by lenght?
The only "length" filtration that is possible is the max-mss option of scrub. Please refer to pf.conf(5)for the description and syntax.
Quote:
During uploading files on machine connected to router with firewall listed above by http (port 80), internet on it is frozen. Any other service doesnt work or works very very slowly.
I'd look to your queuing rules. I've never used HFSC queuing, so I can't comment on your rules, but the symptom you describe is indicative of incorrect traffic shaping.
Quote:
I suspect them (huge ACKs) as my problem.
Don't suspect. Know. Use tcpdump(8).
Reply With Quote