All of lore.kernel.org
 help / color / mirror / Atom feed
* Bug with Fedora's 2.6.23.9-85 kernel (at least) and ESTABLISHED and SACK
@ 2008-01-28  5:14 Zan Lynx
  2008-01-28  9:53 ` Jan Engelhardt
  2008-01-28 13:38 ` Krzysztof Oledzki
  0 siblings, 2 replies; 6+ messages in thread
From: Zan Lynx @ 2008-01-28  5:14 UTC (permalink / raw)
  To: netfilter-devel

Please CC me on any replies as I am not subscribed.

I was downloading a new Google Earth when I noticed a LOT of max-size 
dropped packets in my firewall log.  I only allow RELATED,ESTABLISHED 
sessions into my firewall.

tcpdump showed that every time Google sent a packet to satisfy the 
missing data identified by SACK, that packet was rejected.  So it must 
have been missing the ESTABLISHED rule.

I fixed the problem by adding an ALLOW source port 80 rule for the 
Google download site IP.

This makes me wonder how often this has happened and I haven't noticed 
it.  Is this a known bug or something new?

BTW, your netfilter Bugzilla is dead or at least 404 missing.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2008-01-28 21:06 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-01-28  5:14 Bug with Fedora's 2.6.23.9-85 kernel (at least) and ESTABLISHED and SACK Zan Lynx
2008-01-28  9:53 ` Jan Engelhardt
2008-01-28 17:07   ` Zan Lynx
2008-01-28 13:38 ` Krzysztof Oledzki
2008-01-28 17:06   ` Zan Lynx
2008-01-28 21:06     ` Krzysztof Oledzki

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.