Post by Stefan Behne » Fri, 13 Jul 2001 17:19:20


I found that the tcp connections (HTTP, FTP, ...) are terribly slow on
my system. No other computer in our network has that problem (neither
under NT nor Linux) and my computer doesn't show it under NT4 either.

My 100TX is receiving a 3/4K per second using Mozilla, Lynx, wget, ...
while bing says it does between 500K and 1M depending on the network
LAN-Samba is a pain, too...

I'm the only one running SuSE (7.2), so I might consider it a problem
with the configuration, but these low rates persist when changing the
kernel (SuSE 2.4.4, orig. 2.4.4/.6)

I tryed ethereal to see if there's any bizarre traffic on the net, but I
didn't find anything not belonging to the connections. RX-errors are not
that high either...

I'm not using ipchains/tables in the kernel, so there shouldn't be any
packet filtering.

Any ideas, anybody?

Thanks in advance!!
Stefan :)

Just in case, this is my configuration:

Host bridge: Intel Corporation 440BX/ZX - 82443BX/ZX (rev 03)

PCI bridge: Digital Equipment Corporation DECchip 21152 (rev 03)

  Ethernet controller: 3Com Corporation 3c905B 100BaseTX [Cyclone] (rev 24)
         Subsystem: Dell Computer Corporation 3C905B Fast Etherlink XL
         Flags: bus master, medium devsel, latency 64, IRQ 11
         I/O ports at dc00 [size=128]
         Memory at ff000000 (32-bit, non-prefetchable) [size=128]
         Expansion ROM at fb000000 [disabled] [size=128K]


1. PPTP via ipchains and SuSE 7.2 with 2.4.x kernel


I successfully set up a VPN server (SuSE 7.2) and client (Win2k) using pptp.
Everything works fine unless i put the client behind an ipchains-firewall
(SuSE 7.2).
I tried to configure the firewall to just do the masquerading for the VPN
client with a small script - so everything should be masqueraded. Although
VPN fails to work.

On the server in /var/log/messages I see the VPN client initiating a
connection. The server tries to send an LCP-packet (for authentication
This packet doesn't seem to reach the client cause the client terminates the
connection telling me that the VPN Server dosen't respond.

My questions now are:
-- there was a patch for older kernels to solve my problem - is this
implemented in the new 2.4.x kernel(s)? If yes, is it activated by default?
-- I found a solution for iptables but just for one client - is there a
solution with ipchains?
-- how can I forward LCP to my client?
-- is there a possibility to use SuSEfirewall to do the job with the
forwarding of the vpn necsessary packets?

Thanks in advance,

