All of lore.kernel.org
 help / color / mirror / Atom feed
From: Roberto Nibali <ratz@tac.ch>
To: Netfilter-devel <netfilter-devel@lists.netfilter.org>
Subject: TCP window tracking patch status query for further design considerations
Date: Mon, 07 Oct 2002 17:56:14 +0200	[thread overview]
Message-ID: <3DA1AE9E.6030106@tac.ch> (raw)

Hello guys,

Is/Are there any news about the possibly impaired functionality of the TCP 
window tracking patch? I recall the thread about the mailinglist problems where 
Harald concluded that it was this patch that caused headaches to several people 
trying to send emails to the netfilter lists. Has the problem been investigated 
any further or is the status still unclear?

Unfortunately we depend on it because we do not use netfilter in a 'Intranet <-> 
Internet' way but in a 'multiple zones -> multiple zones' way. We do not have 
any trusted zones and without the TCP window tracking patch for example someone 
sending a RST can delete ESTABLISHED entries from the conntrack table. This is 
not an issue if you come from a trusted network like your Intranet for example, 
but it sure takes all the fun away if you have different customers on each NIC.

You can test things very efficiently with sendip (example to flush entries):
./sendip <dst> -p tcp -is <src> -ts <sport> -td <dport> -tfr 1

Without this patch, netfilter is completely useless to us. Could someone please 
give me a status report of this patch? What about a possible inclusion into 
mainstream kernel (this question is important to our management to create 
appropriate SLAs)?

TIA and best regards,
Roberto Nibali, ratz

PS.: FYI, I'm running and testing the stuff with the latest iptables, kernel 
2.4.20-pre8 and latest pom. I've not applied other patches yet.
-- 
echo '[q]sa[ln0=aln256%Pln256/snlbx]sb3135071790101768542287578439snlbxq' | dc

             reply	other threads:[~2002-10-07 15:56 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-07 15:56 Roberto Nibali [this message]
2002-10-08 10:17 ` TCP window tracking patch status query for further design considerations Jozsef Kadlecsik
2002-10-08 12:08   ` Roberto Nibali
2002-10-08 13:55   ` Roberto Nibali
2002-10-08 22:16     ` Jozsef Kadlecsik
2002-10-08 22:22       ` Roberto Nibali
2002-10-09 13:20         ` Roberto Nibali
2002-10-08 14:55   ` Roberto Nibali
2002-10-08 22:32     ` Jozsef Kadlecsik
2002-10-08 23:15       ` Roberto Nibali

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3DA1AE9E.6030106@tac.ch \
    --to=ratz@tac.ch \
    --cc=netfilter-devel@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.