All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ray Leach <raymondl@knowledgefactory.co.za>
To: Netfilter Mailing List <netfilter@lists.netfilter.org>
Subject: Re: netfilter resets TCP conversation that was DNATed from the local machine to another
Date: 30 Jun 2003 16:44:00 +0200	[thread overview]
Message-ID: <1056984240.1473.18.camel@raylinux.internal> (raw)
In-Reply-To: <20030630142908.GA29083@cannon.eng.us.uu.net>

[-- Attachment #1: Type: text/plain, Size: 1498 bytes --]

This is an IE browser problem.
Normal browsers don't send RST after the connection has ended.

On Mon, 2003-06-30 at 16:29, Ramin Dousti wrote:
> On Sun, Jun 29, 2003 at 07:22:13PM -0700, Michael wrote:
> 
> > What would you like me to confirm? That it's broken? It is broken. That 
> > the RST sending port is not the same as the initiating SYN port? It is 
> > not; it's low, just above 1024, so I assumed it to be 
> > netfilter-generated, whereas the Squid port was in the 30000 range. That 
> > my rule set isn't sending it? "I have no reject-with-tcp-reset lines in 
> > my tables." Don't know what else you could mean.
> 
> What I mean is this:
> 
> squid:		ip1:port1
> webserver:	ip2:80
> 
> Then what you say is:
> 
> packet1:	ip1:port1 -> ip2:80    (SYN)
> packet2:	ip2:80    -> ip1:port1 (SYN ACK)
> packet3:	ip1:port2 -> ip2:80    (RST)
> 
> What I'm saying is that the third packet should not be able to tear down
> the connection between ip1:port1 <-> ip2:80  just because the ports are
> different. The TCP stack on ip2 should discard this RST packet...
> 
> Again, my question:
> do you see any other packets between ip1:port1 <-> ip2:port2 after the RST
> packet?
> 
> Ramin
> 
> 
> 
-- 
--
Raymond Leach <raymondl@knowledgefactory.co.za>
Network Support Specialist
http://www.knowledgefactory.co.za
"lynx -source http://www.rchq.co.za/raymondl.asc | gpg --import"
Key fingerprint = 7209 A695 9EE0 E971 A9AD  00EE 8757 EE47 F06F FB28
--

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2003-06-30 14:44 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-06-28  3:50 netfilter resets TCP conversation that was DNATed from the local machine to another Michael
2003-06-29 21:55 ` Arnt Karlsen
2003-06-30  2:01 ` Ramin Dousti
2003-06-30  2:22   ` Michael
2003-06-30  5:12     ` Alistair Tonner
2003-06-30 14:29     ` Ramin Dousti
2003-06-30 14:44       ` Ray Leach [this message]
2003-06-30 14:52         ` Ramin Dousti
2003-06-30 20:07       ` Michael
2003-07-01  6:00         ` Alistair Tonner
2003-07-01 14:34           ` Ramin Dousti
2003-07-01 16:24           ` Michael
     [not found]             ` <200307020206.13952.Alistair@nerdnet.ca>
2003-07-02 21:39               ` Michael

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1056984240.1473.18.camel@raylinux.internal \
    --to=raymondl@knowledgefactory.co.za \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.