All of lore.kernel.org
 help / color / mirror / Atom feed
From: Harald Welte <laforge@netfilter.org>
To: Wouter Vanwalleghem <wouter@belnet.be>
Cc: netfilter@lists.netfilter.org
Subject: Re: Unable to stop tunnel from being "connection-tracked"
Date: Fri, 3 Oct 2003 12:15:39 +0200	[thread overview]
Message-ID: <20031003101539.GR5758@sunbeam.de.gnumonks.org> (raw)
In-Reply-To: <1065093009.24289.193.camel@wouter.fw.belnet.be>

[-- Attachment #1: Type: text/plain, Size: 2078 bytes --]

On Thu, Oct 02, 2003 at 01:10:09PM +0200, Wouter Vanwalleghem wrote:
> hi all,
> 
> I have setup a 6-in-4 tunnel which is giving me head-aches.
> FYI, I use kernel 2.4.21 and iptables 1.2.8.
> 
> As soon as I start using the tunnel the output of "cat
> /proc/net/ip_conntrack" shows a protocol 41 connection between my
> firewall and the IPv4 PoP of the tunnelbroker. 
> OK so far. 

yup.  That's how it is on my 6to4 tunnel gateway, too.

> Thing is that the tunnel "dies" as soon as the connection has
> disappeared from the connection tracking table.
> 
> After some research I followed a suggestion to keep the tunnel from
> being connection tracked.

impossible with stock iptables. 

> However, the following iptables rules do not prevent the tunnel from
> popping up in the connection tracking table:
> 
> 
> #####------------ IPv6 tunnel to SixXS-----
> iptables -A INPUT -p 41 -s tunnelserver.concepts-ict.net -j ACCEPT
> iptables -A OUTPUT -p 41 -d tunnelserver.concepts-ict.net -j ACCEPT
> iptables -A INPUT -p icmp --icmp-type echo-request -s
> tunnelserver.concepts-ict.net -j ACCEPT
> iptables -t nat -A POSTROUTING --protocol ! 41 -s 192.168.100.0/24 -o
> ppp0 -j MASQUERADE

Why should this prevent connection tracking from tracking the tunnel?
Connection tracking always tracks all packets, as described in the docs.

It's just a quesion on whether you want to use the information provided
by conntrack or not.  And this totally depends on your ruleset.

> Anybody have a clue?

This has to be somehow related to your local setup/configuration.  I am
running 6to4 tunnels on a lot of firewalls without any problems.

> kind regards,
> Wouter

-- 
- Harald Welte <laforge@netfilter.org>             http://www.netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

      parent reply	other threads:[~2003-10-03 10:15 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-10-02 11:10 Unable to stop tunnel from being "connection-tracked" Wouter Vanwalleghem
2003-10-02 13:52 ` Ramin Dousti
2003-10-02 19:35   ` Wouter Vanwalleghem
2003-10-03 10:16     ` Harald Welte
2003-10-03 19:43     ` Ramin Dousti
2003-10-03 20:02       ` Wouter Vanwalleghem
2003-10-03 10:15 ` Harald Welte [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20031003101539.GR5758@sunbeam.de.gnumonks.org \
    --to=laforge@netfilter.org \
    --cc=netfilter@lists.netfilter.org \
    --cc=wouter@belnet.be \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.