On Tue, 6 Jul 2004 13:36:41 -0700 Stephen Hemminger <shemminger@osdl.org> wrote: > > Ok, this is a possibility. And why it breaks is that if the ACK > > for the SYN+ACK comes back, the SYN+ACK sender can only assume > > that the window scale was accepted. > > > > Stephen, do you have a trace showing exactly this? > > No, I don't have a br0ken firewall here. I can get out fine. > When I setup with same kernel as packages.gentoo.org, it works fine as well. Therefore we do not know which of the following two it really is: 1) window scale option being stripped from SYN+ACK 2) non-zero window option being patched into a zero window scale option The trace Bert Hubert will get with Alessandro will give us the information we need. - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html