Hello Mark: We have done some digging into this. What you are actually seeing is the server detecting "bad" checksums on its own outbound packets. Under FreeBSD, our code uses the Berkely Packet Filter to read packets, hence we end up seeing our own outbound messages. With CSUM offloading, virtually all outbound packets will not have CSUMs at the point the filter sees them. While the log messages are probably annoying, there are no communication issues or packets being lost. We are close to our next releases, 4.3.4 and 4.1-ESV-R13, due out in March 2016. Given their proximity, we'll have to consider any potential solutions for our next release, 4.4.0. If you have any further thoughts on the matter, please let us know. Thank you for taking the time to report the issue and for your interest in our software. Sincerely, Thomas Markwalder ISC Software Engineering