Okay vielen Dank schonmal für die Tipps. Ich kann die Abfragen aus der Arbeit zwar erst morgen machen aber ich hab mal den tcpdump auf der Synology angeschaut, wo ja der Internetzugriff funktioniert.
sh-4.3# tcpdump -c 40 -vvveni eth0 port 80 or port 443 tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes 00:21:56.396056 9c:c7:a6:5d:31:61 > 00:11:32:27:22:07, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 52, id 43590, offset 0, flags [DF], proto TCP (6), length 60) 80.187.97.XX.21866 > 192.168.178.27.80: Flags [S], cksum 0xacdb (correct), seq 1390797432, win 14600, options [mss 1452,sackOK,TS val 1780107326 ecr 0,nop,wscale 9], length 0 00:21:56.396168 00:11:32:27:22:07 > 9c:c7:a6:5d:31:61, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6), length 60) 192.168.178.27.80 > 80.187.97.XX.21866: Flags [S.], cksum 0x24e0 (incorrect -> 0x95d4), seq 4138085154, ack 1390797433, win 14480, options [mss 1460,sackOK,TS val 2094466 ecr 1780107326,nop,wscale 4], length 0 00:21:56.420057 9c:c7:a6:5d:31:61 > 00:11:32:27:22:07, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 52, id 43591, offset 0, flags [DF], proto TCP (6), length 52) 80.187.97.XX.21866 > 192.168.178.27.80: Flags [.], cksum 0xfcf8 (correct), seq 1, ack 1, win 29, options [nop,nop,TS val 1780107350 ecr 2094466], length 0 00:21:56.420810 9c:c7:a6:5d:31:61 > 00:11:32:27:22:07, ethertype IPv4 (0x0800), length 449: (tos 0x0, ttl 52, id 43592, offset 0, flags [DF], proto TCP (6), length 435) 80.187.97.XX.21866 > 192.168.178.27.80: Flags [P.], cksum 0xae37 (correct), seq 1:384, ack 1, win 29, options [nop,nop,TS val 1780107351 ecr 2094466], length 383 00:21:56.420853 00:11:32:27:22:07 > 9c:c7:a6:5d:31:61, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 64, id 56999, offset 0, flags [DF], proto TCP (6), length 52) 192.168.178.27.80 > 80.187.97.XX.21866: Flags [.], cksum 0x24d8 (incorrect -> 0xf7c7), seq 1, ack 384, win 972, options [nop,nop,TS val 2094468 ecr 1780107351], length 0 00:21:56.422813 00:11:32:27:22:07 > 9c:c7:a6:5d:31:61, ethertype IPv4 (0x0800), length 1094: (tos 0x0, ttl 64, id 57000, offset 0, flags [DF], proto TCP (6), length 1080) 192.168.178.27.80 > 80.187.97.XX.21866: Flags [P.], cksum 0x28dc (incorrect -> 0x5904), seq 1:1029, ack 384, win 972, options [nop,nop,TS val 2094469 ecr 1780107351], length 1028 00:21:56.448292 9c:c7:a6:5d:31:61 > 00:11:32:27:22:07, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 52, id 43593, offset 0, flags [DF], proto TCP (6), length 52)
Sieht bei den mss gleich aus, nur das hier der Handshake klappt.