Networking Forums

Networking Forums > Computer Networking > Linux Networking > why is this an invalid packet

Reply
Thread Tools Display Modes

why is this an invalid packet

 
 
H. S.
Guest
Posts: n/a

 
      01-25-2005, 11:07 PM

I am logging the dropped invalid packets by my iptables script. I get
quite a bit in my log file (a few lines every hour):

Jan 25 15:24:29 red kernel: Invalid Outgoing IN= OUT=eth0
SRC=192.168.0.2 DST=194.109.137.218 LEN=52 TOS=0x00 PREC=0x00 TTL=64
ID=306 DF PROTO=TCP SPT=44797 DPT=80 WINDOW=25884 RES=0x00 ACK PSH FIN
URGP=0

How can I determine why this packet was determined to be invalide. The
rule to check invalid state comes after the rules allowing lo traffic
and allowing packtes related to realplayer.

Thanks,
->HS


--
Please remove the underscores ( the '_' symbols) from my email address
to obtain the correct one. Apologies, but the fudging is to remove spam.
 
Reply With Quote
 
 
 
 
Jose Maria Lopez Hernandez
Guest
Posts: n/a

 
      01-26-2005, 12:23 PM
H. S. wrote:
>
> I am logging the dropped invalid packets by my iptables script. I get
> quite a bit in my log file (a few lines every hour):
>
> Jan 25 15:24:29 red kernel: Invalid Outgoing IN= OUT=eth0
> SRC=192.168.0.2 DST=194.109.137.218 LEN=52 TOS=0x00 PREC=0x00 TTL=64
> ID=306 DF PROTO=TCP SPT=44797 DPT=80 WINDOW=25884 RES=0x00 ACK PSH FIN
> URGP=0
>
> How can I determine why this packet was determined to be invalide. The
> rule to check invalid state comes after the rules allowing lo traffic
> and allowing packtes related to realplayer.
>
> Thanks,
> ->HS


It could be because of the combination of TCP flags. Maybe your
firewall it's denying it.

Regards.

--

Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
(E-Mail Removed)
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
-- Jack Kerouac, "On the Road"
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
why TCP packet marked as INVALID? rhendry Linux Networking 0 05-11-2008 06:52 PM
How to Distinguish between a reset packet and a normal packet sairam Linux Networking 4 03-27-2007 04:03 AM
Receiver sensitivity- Packet Detection v/s Packet capture Vinay Wireless Internet 1 10-14-2005 01:50 AM
Invalid WEP Al Broadband Hardware 0 04-06-2004 10:57 PM
WEP Invalid - Please Help CJ Broadband Hardware 4 02-17-2004 02:06 AM



1 2 3 4 5 6 7 8 9 10 11