APF & Traceroute Issue
I'm having a problem with traceroutes when APF is running. Here's a trace with apf running, notice the dropped packets:
root@nj [~]# traceroute www.mainarea.com
traceroute to mainarea.com (67.18.145.58), 30 hops max, 38 byte packets
1 66.45.251.1 (66.45.251.1) 0.374 ms 0.259 ms 0.254 ms
2 66.45.224.238 (66.45.224.238) 0.467 ms 0.454 ms *
3 209.116.198.125 (209.116.198.125) 0.327 ms 0.228 ms 0.222 ms
4 ge4-2-0.MAR2.NYC-NY.us.xo.net (64.1.6.49) 0.712 ms 0.946 ms 0.784 ms
5 * p5-2-0.RAR2.NYC-NY.us.xo.net (65.106.3.49) 1.011 ms 0.817 ms
6 p6-0-0.RAR1.Washington-DC.us.xo.net (65.106.0.2) 5.351 ms 5.410 ms 5.529 ms
7 * p0-0.IR1.Ashburn-VA.us.xo.net (65.106.3.134) 6.472 ms 6.328 ms
8 206.111.0.22.ptr.us.xo.net (206.111.0.22) 6.691 ms 6.725 ms 6.539 ms
9 so0-0-0-2488m.ar1.dal2.gblx.net (67.17.73.30) 49.073 ms * 49.089 ms
10 The-Planet.ge-0-2-1.ar1.DAL2.gblx.net (64.213.176.150) 49.079 ms 49.081 ms 49.070 ms
11 dist-vlan32.dsr3-1.dllstx3.theplanet.com (70.85.127.61) 49.128 ms 49.055 ms 49.228 ms
12 dist-vlan21.dsr1-1.dllstx2.theplanet.com (70.85.127.67) 49.621 ms 49.639 ms 49.477 ms
13 car1-2-v2.dllstx2.theplanet.com (12.96.160.44) 201.240 ms 207.937 ms 207.725 ms
14 car1-1-v1.dllstx2.layeredtech.com (67.18.144.20) 49.894 ms 49.935 ms 50.120 ms
15 dallas.mainarea.com (67.18.145.58) 50.295 ms 50.182 ms 49.867 ms
traceroute to mainarea.com (67.18.145.58), 30 hops max, 38 byte packets
1 66.45.251.1 (66.45.251.1) 0.374 ms 0.259 ms 0.254 ms
2 66.45.224.238 (66.45.224.238) 0.467 ms 0.454 ms *
3 209.116.198.125 (209.116.198.125) 0.327 ms 0.228 ms 0.222 ms
4 ge4-2-0.MAR2.NYC-NY.us.xo.net (64.1.6.49) 0.712 ms 0.946 ms 0.784 ms
5 * p5-2-0.RAR2.NYC-NY.us.xo.net (65.106.3.49) 1.011 ms 0.817 ms
6 p6-0-0.RAR1.Washington-DC.us.xo.net (65.106.0.2) 5.351 ms 5.410 ms 5.529 ms
7 * p0-0.IR1.Ashburn-VA.us.xo.net (65.106.3.134) 6.472 ms 6.328 ms
8 206.111.0.22.ptr.us.xo.net (206.111.0.22) 6.691 ms 6.725 ms 6.539 ms
9 so0-0-0-2488m.ar1.dal2.gblx.net (67.17.73.30) 49.073 ms * 49.089 ms
10 The-Planet.ge-0-2-1.ar1.DAL2.gblx.net (64.213.176.150) 49.079 ms 49.081 ms 49.070 ms
11 dist-vlan32.dsr3-1.dllstx3.theplanet.com (70.85.127.61) 49.128 ms 49.055 ms 49.228 ms
12 dist-vlan21.dsr1-1.dllstx2.theplanet.com (70.85.127.67) 49.621 ms 49.639 ms 49.477 ms
13 car1-2-v2.dllstx2.theplanet.com (12.96.160.44) 201.240 ms 207.937 ms 207.725 ms
14 car1-1-v1.dllstx2.layeredtech.com (67.18.144.20) 49.894 ms 49.935 ms 50.120 ms
15 dallas.mainarea.com (67.18.145.58) 50.295 ms 50.182 ms 49.867 ms
root@nj [~]# traceroute www.mainarea.com
traceroute to mainarea.com (67.18.145.58), 30 hops max, 38 byte packets
1 66.45.251.1 (66.45.251.1) 0.328 ms 0.240 ms 0.236 ms
2 66.45.224.238 (66.45.224.238) 6.541 ms 11.395 ms 3.521 ms
3 209.116.198.125 (209.116.198.125) 0.267 ms 0.165 ms 0.176 ms
4 ge4-2-0.MAR2.NYC-NY.us.xo.net (64.1.6.49) 0.747 ms 0.661 ms 0.664 ms
5 p5-2-0.RAR2.NYC-NY.us.xo.net (65.106.3.49) 0.944 ms 0.891 ms 0.947 ms
6 p6-0-0.RAR1.Washington-DC.us.xo.net (65.106.0.2) 5.413 ms 5.382 ms 5.358 ms
7 p0-0.IR1.Ashburn-VA.us.xo.net (65.106.3.134) 6.259 ms 6.338 ms 6.379 ms
8 206.111.0.22.ptr.us.xo.net (206.111.0.22) 6.561 ms 6.421 ms 6.614 ms
9 so0-0-0-2488m.ar1.dal2.gblx.net (67.17.73.30) 49.175 ms 49.119 ms 49.151 ms
10 The-Planet.ge-0-2-1.ar1.DAL2.gblx.net (64.213.176.150) 49.105 ms 48.979 ms 49.007 ms
11 dist-vlan32.dsr3-1.dllstx3.theplanet.com (70.85.127.61) 49.158 ms 49.136 ms 49.254 ms
12 dist-vlan21.dsr1-1.dllstx2.theplanet.com (70.85.127.67) 49.627 ms 49.567 ms 49.525 ms
13 car1-2-v2.dllstx2.theplanet.com (12.96.160.44) 49.600 ms 49.615 ms 49.710 ms
14 car1-1-v1.dllstx2.layeredtech.com (67.18.144.20) 51.173 ms 50.834 ms 50.170 ms
15 dallas.mainarea.com (67.18.145.58) 50.133 ms 50.008 ms 49.864 ms
traceroute to mainarea.com (67.18.145.58), 30 hops max, 38 byte packets
1 66.45.251.1 (66.45.251.1) 0.328 ms 0.240 ms 0.236 ms
2 66.45.224.238 (66.45.224.238) 6.541 ms 11.395 ms 3.521 ms
3 209.116.198.125 (209.116.198.125) 0.267 ms 0.165 ms 0.176 ms
4 ge4-2-0.MAR2.NYC-NY.us.xo.net (64.1.6.49) 0.747 ms 0.661 ms 0.664 ms
5 p5-2-0.RAR2.NYC-NY.us.xo.net (65.106.3.49) 0.944 ms 0.891 ms 0.947 ms
6 p6-0-0.RAR1.Washington-DC.us.xo.net (65.106.0.2) 5.413 ms 5.382 ms 5.358 ms
7 p0-0.IR1.Ashburn-VA.us.xo.net (65.106.3.134) 6.259 ms 6.338 ms 6.379 ms
8 206.111.0.22.ptr.us.xo.net (206.111.0.22) 6.561 ms 6.421 ms 6.614 ms
9 so0-0-0-2488m.ar1.dal2.gblx.net (67.17.73.30) 49.175 ms 49.119 ms 49.151 ms
10 The-Planet.ge-0-2-1.ar1.DAL2.gblx.net (64.213.176.150) 49.105 ms 48.979 ms 49.007 ms
11 dist-vlan32.dsr3-1.dllstx3.theplanet.com (70.85.127.61) 49.158 ms 49.136 ms 49.254 ms
12 dist-vlan21.dsr1-1.dllstx2.theplanet.com (70.85.127.67) 49.627 ms 49.567 ms 49.525 ms
13 car1-2-v2.dllstx2.theplanet.com (12.96.160.44) 49.600 ms 49.615 ms 49.710 ms
14 car1-1-v1.dllstx2.layeredtech.com (67.18.144.20) 51.173 ms 50.834 ms 50.170 ms
15 dallas.mainarea.com (67.18.145.58) 50.133 ms 50.008 ms 49.864 ms
- Matt