Пересобрал ядрышко - один хрен. Запускал с текущими настройками:
cat /etc/pf.conf
set limit states 128000
set optimization aggressive
nat pass on re0 from 10.0.0.0/21 to !10.0.0.0/21 -> 109.200.132.2
# cat /etc/rc.firewall
#!/bin/sh -
f='/sbin/ipfw'
${f} add 100 allow ip from any to any
# cat /etc/rc.conf
# -- sysinstall generated deltas -- # Fri Sep 3 12:45:54 2010
# Created: Fri Sep 3 12:45:54 2010
# Enable network daemons for user convenience.
# Please make all changes to this file, not to /etc/defaults/rc.conf.
# This file now contains just the overrides from /etc/defaults/rc.conf.
inetd_enable="YES"
keymap="ua.koi8-u"
sshd_enable="YES"
ifconfig_re0="inet 109.200.132.2/30"
#ifconfig_re0="DHCP"
ifconfig_em0="inet 10.0.0.4 netmask 255.255.248.0"
ifconfig_em0_alias0="inet 194.28.36.2/22"
ifconfig_em0_alias1="inet 80.245.118.176 netmask 255.255.255.0"
hostname="satelit1.lan"
defaultrouter="109.200.132.1"
firewall_enable="YES"
gateway_enable="YES"
fsck_y_enable="YES"
background_fsck="NO"
mpd_enable="YES"
#
pf_enable="YES"
pf_rules="/etc/pf.conf"
pflog_enable="YES"
pflog_logfile="/var/log/pf.log"
ipcad_enable="YES"
radiusd_enable="YES"
noserver_enable="YES"
nol2auth_enable="YES"
static_routes="blackhole1 blackhole2 blackhole3 "
route_blackhole1="-net 80.245.118.0/28 127.0.0.1 -blackhole"
route_blackhole2="-net 80.245.118.240/28 127.0.0.1 -blackhole"
route_blackhole3="-net 194.28.36.0/22 127.0.0.1 -blackhole"
#zabbix_agentd_enable="YES"
]# cat /usr/local/etc/ipcad.conf
capture-ports disable;
interface divert port 1 netflow-disable;
interface divert port 2 netflow-disable;
rsh enable at 10.0.0.4;
rsh root@10.0.0.4 admin;
rsh root@тут ИП базы admin;
rsh enable at 127.0.0.1;
rsh root@127.0.0.1 admin;
rsh ttl = 6;
rsh timeout = 30;
dumpfile = ipcad.dump;
chroot = /tmp;
memory_limit = 50m;
# cat mpd5/mpd.conf
startup:
set user admin ПАРОЛЬ
set console self 127.0.0.1 5005
set console open
set web self 0.0.0.0 5006
set web open
default:
load pppoe_server
pppoe_server:
create bundle template B
set ipcp ranges 10.0.0.4/32 127.0.0.2/32
set ipcp dns 10.0.0.2 80.245.112.10
set ccp yes mppc
set mppc yes e40
set mppc yes e56
set mppc yes e128
set mppc yes stateless
set ecp disable dese-bis dese-old
set iface enable tcpmssfix
set link mtu 1492
set link mru 1492
create link template common pppoe
set link enable multilink
set link action bundle B
set link disable chap pap eap
set link enable pap
# set link no pap chap
# set link enable chap
load radius
set pppoe service "*"
create link template em0 common
set link max-children 1500
set pppoe iface em0
set link enable incoming
radius:
set radius server localhost ПАРОЛЬ 1812 1813
set radius retries 3
set radius timeout 3
set radius me 127.0.0.1
set auth acct-update 45
set auth enable radius-auth
set auth enable radius-acct
set radius enable message-authentic
Вроди все конфиги от которых хоть чтото зависит выложил, теперь то что получил
10.110.1.167 - адресс машины с которой проверяю соединение
# tcpdump -i re0 | grep 10.110.1.167
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on re0, link-type EN10MB (Ethernet), capture size 96 bytes
10:49:04.987034 IP 10.110.1.167.14756 > hb-in-f99.1e100.net.http: Flags [S], seq 1372387838, win 8192, options [mss 1440,nop,wscale 2,nop,nop,sackOK], length 0
10:49:08.566680 IP 10.110.1.167.14754 > yandex.ru.http: Flags [S], seq 2080143888, win 65535, options [mss 1440,nop,nop,sackOK], length 0
10:49:10.768252 IP 10.110.1.167.14757 > 195.82.146.122.http: Flags [S], seq 2827513081, win 8192, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0
10:49:10.977238 IP 10.110.1.167.14756 > hb-in-f99.1e100.net.http: Flags [S], seq 1372387838, win 8192, options [mss 1440,nop,nop,sackOK], length 0
10:49:11.007094 IP 10.110.1.167.14758 > hb-in-f104.1e100.net.http: Flags [S], seq 2626601888, win 8192, options [mss 1440,nop,wscale 2,nop,nop,sackOK], length 0
10:49:13.766979 IP 10.110.1.167.14757 > 195.82.146.122.http: Flags [S], seq 2827513081, win 8192, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0
10:49:13.910027 IP 10.110.1.167.14759 > hb-in-f99.1e100.net.http: Flags [S], seq 2079545663, win 8192, options [mss 1440,nop,wscale 2,nop,nop,sackOK], length 0
10:49:13.996831 IP 10.110.1.167.14758 > hb-in-f104.1e100.net.http: Flags [S], seq 2626601888, win 8192, options [mss 1440,nop,wscale 2,nop,nop,sackOK], length 0
10:49:16.906508 IP 10.110.1.167.14759 > hb-in-f99.1e100.net.http: Flags [S], seq 2079545663, win 8192, options [mss 1440,nop,wscale 2,nop,nop,sackOK], length 0
^C
^C256 packets captured
621 packets received by filter
0 packets dropped by kernel
# kldstat
Id Refs Address Size Name
1 21 0xffffffff80100000 7b1728 kernel
2 1 0xffffffff80a22000 1c02 ng_socket.ko
3 8 0xffffffff80a24000 8d44 netgraph.ko
4 1 0xffffffff80a2d000 18b6 ng_mppc.ko
5 1 0xffffffff80a2f000 282 rc4.ko
6 1 0xffffffff80a30000 153e ng_ether.ko
7 1 0xffffffff80a32000 323e ng_pppoe.ko
8 1 0xffffffff80a36000 abe ng_tee.ko
9 1 0xffffffff80a37000 13c6 ng_iface.ko
10 1 0xffffffff80a39000 463e ng_ppp.ko
11 1 0xffffffff80a3e000 a42 ng_tcpmss.ko
При сборке ядра добавлял следующие параметры
options IPFIREWALL
options IPDIVERT
options IPFIREWALL_FORWARD
options DUMMYNET
options SCHED_ULE
options ALTQ # включает подсистему ALTQ
options ALTQ_CBQ # Class Bases Queuing (CBQ)
options ALTQ_RED # Random Early Detection (RED)
options ALTQ_RIO # RED In/Out
options ALTQ_HFSC # Hierarchical Packet Scheduler (HFSC)
options ALTQ_PRIQ # Priority Queuing (PRIQ)
options ALTQ_NOPCC # Required for SMP build
options ALTQ_CDNR
options ALTQ_DEBUG
device pf
device pflog
device pfsync
device miibus # MII bus suppor
uname -a
FreeBSD satelit1.lan 8.1-RELEASE FreeBSD 8.1-RELEASE #0: Sat Sep 11 10:20:55 EEST 2010 root@satelit1.lan:/usr/src/sys/amd64/compile/SATELIT amd64
Проверка интернета на сателите:
# ping ya.ru
PING ya.ru (77.88.21.3): 56 data bytes
64 bytes from 77.88.21.3: icmp_seq=0 ttl=57 time=45.125 ms
64 bytes from 77.88.21.3: icmp_seq=1 ttl=57 time=45.607 ms
64 bytes from 77.88.21.3: icmp_seq=2 ttl=57 time=45.395 ms
64 bytes from 77.88.21.3: icmp_seq=3 ttl=57 time=44.891 ms
64 bytes from 77.88.21.3: icmp_seq=4 ttl=57 time=44.941 ms
^C
--- ya.ru ping statistics ---
5 packets transmitted, 5 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 44.891/45.192/45.607/0.273 ms
Где еще можно искать я просто в замешательстве???