From: Dale Mellor <dale@rdmp.org>
To: Payam Chychi <pchychi@gmail.com>
Cc: Leonardo Rodrigues <leolistas@solutti.com.br>, netfilter@vger.kernel.org
Subject: Re: How to stop kernel TCP responses on a port
Date: Fri, 05 Sep 2014 06:41:52 +0100 [thread overview]
Message-ID: <1409895712.16431.7.camel@l3> (raw)
In-Reply-To: <CBD8736BE6044AE0B06076D69855AF85@gmail.com>
[-- Attachment #1: Type: text/plain, Size: 1844 bytes --]
> > > On 04/09/14 12:17, Dale Mellor wrote:
> > > I want to do TCP with raw sockets. How can I filter away the
> > > kernel's
> > > RST/ACK/SYN response messages when I want to do this myself?
> >
> >
> > On Thu, 2014-09-04 at 13:16 -0300, Leonardo Rodrigues wrote:
> > you'll probably need to tweak the kernel itself for that. If you
> > wanna do all the 'dirty work', why not use UDP instead of TCP ??
> >
> >
> > On Thursday, September 4, 2014 at 9:27 PM, Dale Mellor wrote:
> > I need to tunnel TCP (specifically telnet) through a space link to a
> > spacecraft in orbit (don't worry, security exists in the link
> > layer).
> > But of course I need the SYN/ACKs to come from the spacecraft itself
> > (rather than the ground-station PC) so I know when I can send
> > commands
> > up. I'm going to try to use the iptables' QUEUE target and a
> > user-space
> > packet filter, thinking that if I reject the incoming SYN it will be
> > dropped without further ado, and then I can synthesize a response
> > later
> > with a raw socket.
> >
> >
> > Any thoughts people may have on this would likely be useful.
>
>
On Thu, 2014-09-04 at 22:06 -0700, Payam Chychi wrote:
Why would the syn-ack come from the ground pc and not the space station?
Are you proxying this? If so, there are other ways todo this ...
I thought this list had rules about not top-posting?
Anyway, the point is I don't want the syn-ack to come from the ground,
but the Linux kernel insists on sending it. That's what I want to
filter out, or otherwise stop.
In case I haven't been clear, the PC is the gateway to the spacecraft;
effectively, it _is_ the proxy. When a telnet client (on the ground)
connects to the gateway (on the ground), the gateway is responding to
the SYN when I don't want it to.
Dale
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
next prev parent reply other threads:[~2014-09-05 5:41 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-04 15:17 How to stop kernel TCP responses on a port Dale Mellor
2014-09-04 16:16 ` Leonardo Rodrigues
2014-09-05 4:27 ` Dale Mellor
[not found] ` <CBD8736BE6044AE0B06076D69855AF85@gmail.com>
2014-09-05 5:41 ` Dale Mellor [this message]
2014-09-08 3:11 ` Brad Campbell
2014-09-09 13:49 ` Dale Mellor
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1409895712.16431.7.camel@l3 \
--to=dale@rdmp.org \
--cc=leolistas@solutti.com.br \
--cc=netfilter@vger.kernel.org \
--cc=pchychi@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.