Networking Forums

Networking Forums > Computer Networking > Linux Networking > iptables restart, existing sessions, and ESTABLISHED,RELATED rules

Reply
Thread Tools Display Modes

iptables restart, existing sessions, and ESTABLISHED,RELATED rules

 
 
Andrew Gideon
Guest
Posts: n/a

 
      07-12-2008, 01:10 PM

I've noticed a problem when I restart iptables (ie. for the loading of a
change to rules). But it's not a complete problem, which is even weirder
than the problem itself.

I've an early rule "-m state --state ESTABLISHED,RELATED -j ACCEPT" to
permit inbound traffic that's a response to outbound. Pretty
conventional. One example of how this gets used is when I ssh out.

What is odd is what occurs when I've an SSH session open at the time I
restart iptables. Some inbound packets on the SSH session are rejected,
obviously not matching the above ESTABLISHED,RELATED. But not all!

I noticed this when I was running MythTV over port forwarding. It had
been working fine. After the restart of iptables, display of a video was
jittery. I then looked into the log and saw a lot of rejected inbound
SSH packets. But obviously not all were being rejected as the video
*was* playing, if badly.

Restarting the SSH session solved the problem.

So why are *some* of the packets failing to match on
ESTABLISHED,RELATED? I could understand none or all, but some?

And is there a way to reload iptables rules w/o losing the connection
session information that causes this? Or is there perhaps a way to
recreate the session information (ie. something which adds a TCP circuit
to the database even if there's no SYN packet seen perhaps?)?

Thanks...
Andrew
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPTABLES and RELATED states Andrew Townsend Linux Networking 3 07-27-2005 05:20 PM
Looking for iptables applications code (iptables.c) to run some rules to forward packets tvnaidu@yahoo.com Linux Networking 2 01-17-2005 05:01 PM
How net use sessions are established =?Utf-8?B?Sm9uYXMgSGFtbWFyYmFjaw==?= Windows Networking 0 11-16-2004 12:58 PM
iptables: ESTABLISHED,RELATED but some ACK or RST rejected Emmanuel CHANTREAU Linux Networking 1 09-17-2003 08:47 PM
iptables blocks 'established' packets ? Tom Van Overbeke Linux Networking 0 07-01-2003 01:35 PM



1 2 3 4 5 6 7 8 9 10 11