Networking Forums

Networking Forums > Computer Networking > Linux Networking > Non-deterministic non-matching in Connection Tracking

Reply
Thread Tools Display Modes

Non-deterministic non-matching in Connection Tracking

 
 
Cameron Kerr
Guest
Posts: n/a

 
      07-10-2004, 11:27 PM
Kernel 2.6.7 compiled for k7, as provided by Debian Testing.

This machine is located in a Co-lo, so kernel experimentation is not
really much of an option.

I have a firewall that I have set up that limits INPUT and OUTPUT (no
FORWARD, it doesn't route).

The rules work fine, and traffic works as expected. However, I see log
messages from the kernel about packets that are being dropped. They are
from friendly sources, and not particular to any service (currently seen
with SSH, POP, and WWW).

The only pattern that I have been able to discern is that all the
packets are TCP, and have at least the ACK flag set, often also FIN and
to a lesser degree PSH, and that these are all going on the OUTPUT
chain (ie, in reply to the client). This would seem to indicate that
the problem lies in the IPTables connection tracking module.

I'm at a loss to explain any rational reason for this, except for a bug.
Has anyone met this odd behaivour?

--
Cameron Kerr
(E-Mail Removed) : http://humbledown.org/
Empowered by Perl!
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem with SCPS & connection tracking Washington Ratso Linux Networking 4 02-11-2011 08:14 PM
DNATing without connection tracking - is it possible? Chris Dew Linux Networking 9 01-26-2009 11:47 AM
PPTPD connection tracking markvr Linux Networking 9 11-30-2006 03:39 PM
IPv6 connection tracking newsposter@carceri.dk Linux Networking 0 09-10-2006 09:45 AM
Tracking Network Connection Activity? garytn9988 Windows Networking 0 08-20-2005 03:51 PM



1 2 3 4 5 6 7 8 9 10 11