All of lore.kernel.org
 help / color / mirror / Atom feed
* iptables icmp protocol match bug.
@ 2003-07-31 19:47 Peteris Krumins
  2003-07-31 21:52 ` Patrick McHardy
  0 siblings, 1 reply; 8+ messages in thread
From: Peteris Krumins @ 2003-07-31 19:47 UTC (permalink / raw)
  To: netfilter-devel

Hello,

 A quick bug report:

 iptables -A INPUT -p icmp --icmp-type 255 -i lo -j REJECT

 this rule also denies icmp ping and i think anything else of icmp.

 Works for me at least on 2.4.22-pre6 and patch-o-matic-20030714
 havent tried w/ newer versions.
 
 Does not work on base 2.4.20 and iptables 1.2.7a

proof:
--
z@xor:/[1032]# iptables -A INPUT -p icmp --icmp-type 255 -i lo -j REJECT
z@xor:/[1033]# ping localhost -c 5
PING localhost (127.0.0.1): 56 octets data

--- localhost ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss

z@xor:/[1034]# iptables -D INPUT -p icmp --icmp-type 255 -i lo -j REJECT
z@xor:/[1035]# ping localhost -c 5
PING localhost (127.0.0.1): 56 octets data
64 octets from 127.0.0.1: icmp_seq=0 ttl=128 time=0.3 ms
64 octets from 127.0.0.1: icmp_seq=1 ttl=128 time=0.3 ms
^C


P.Krumins







netfilter-devel@lists.netfilter.org

^ permalink raw reply	[flat|nested] 8+ messages in thread
* iptables icmp protocol match bug.
@ 2003-07-31 20:26 Peteris Krumins
  0 siblings, 0 replies; 8+ messages in thread
From: Peteris Krumins @ 2003-07-31 20:26 UTC (permalink / raw)
  To: netfilter

Hello,

 A quick bug report:
 (sorry for crossposting to devel and user list, but i am interested
 if anyone else can reproduce)

 iptables -A INPUT -p icmp --icmp-type 255 -i lo -j REJECT

 this rule also denies icmp ping and i think anything else of icmp.

 Works for me at least on 2.4.22-pre6 and patch-o-matic-20030714
 havent tried w/ newer versions.
 
 Does not work on base 2.4.20 and iptables 1.2.7a

proof:
--
z@xor:/[1032]# iptables -A INPUT -p icmp --icmp-type 255 -i lo -j REJECT
z@xor:/[1033]# ping localhost -c 5
PING localhost (127.0.0.1): 56 octets data

--- localhost ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss

z@xor:/[1034]# iptables -D INPUT -p icmp --icmp-type 255 -i lo -j REJECT
z@xor:/[1035]# ping localhost -c 5
PING localhost (127.0.0.1): 56 octets data
64 octets from 127.0.0.1: icmp_seq=0 ttl=128 time=0.3 ms
64 octets from 127.0.0.1: icmp_seq=1 ttl=128 time=0.3 ms
^C


P.Krumins







netfilter-devel@lists.netfilter.org



^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2003-08-04 20:50 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-07-31 19:47 iptables icmp protocol match bug Peteris Krumins
2003-07-31 21:52 ` Patrick McHardy
2003-07-31 22:17   ` Re[2]: " Peteris Krumins
2003-07-31 22:39     ` Patrick McHardy
2003-07-31 23:57       ` Henrik Nordstrom
2003-08-02 16:05   ` Harald Welte
2003-08-04 20:50     ` Patrick McHardy
  -- strict thread matches above, loose matches on Subject: below --
2003-07-31 20:26 Peteris Krumins

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.