With the normal 24.7.3 kernel, I can confirm the "pf: ICMP error message too short (ip6)" messages - which go away with the no-sa kernel.I can also confirm the "pf: loose state match" notices with both kernels.
I just went back to OPNsense 24.1 (imported config from 24.7) and, with debug logging turned on,... taddahhh... I also see same 'pf: loose state match' notices.
Thanks, good to know.
Maybe it's a different (but somehow related) issue that did not surface in the same way until now.
Do you also see the performance degredation/FW hits?
Quote from: rkube on September 08, 2024, 07:49:31 pmThe MTU I have set is (unfortunately) not the problem, as I am only testing between two local VLANs (MTU==1500) that are routed/filtered via opnsense. I could try jumbo frames, maybe it can get even worse ;-)Yet you show results from a iperf3 test run against an internet IP?
The MTU I have set is (unfortunately) not the problem, as I am only testing between two local VLANs (MTU==1500) that are routed/filtered via opnsense. I could try jumbo frames, maybe it can get even worse ;-)
So there are alo VLANs and LAGGs in the mix? Maybe netmap and suricata as well?
Is there anything else that could be done? I am very open to suggestions.
Today I DOWNgraded it to a 6.XX firmware that I still had - 'poof' - all issues seem to be gone. I will continue to