From: "Domenico Gargano" <d.gargano@planetek.it>
To: netfilter@lists.netfilter.org
Subject: Refused SYN packets for 15min.
Date: Wed, 25 Feb 2004 17:33:05 +0100 [thread overview]
Message-ID: <403CDC51.16545.1D46DD2@localhost> (raw)
Hi all,
I've got a strange problem on my fw, here's my lan:
Fw with 3 eth
eth0: external router
eth1: internal LAN
eth2: DMZ
During the day, sometimes happens that the fw stop accepting incoming SYN packet
(and I can't establish a new connection) for 15 min. mantainig instead the
ESTABLISHED connection.
I've disabled syn-floodin protection in kernel, I've tried flushing rules, raised kernel
buffers, looked inside /proc/net/ip_conntrack finding nothing strange.
My client coming from Internet can't see my website, or a LAN client can't connect to
internet or DMZ.
During this "ban" time (15 min.) it seems I can't do nothing restoring connections.
Also it seems that my fw "ban" not all the net, but some client.
Any ideas?
Thanks
my sys: rh9, kernel 2.4.20-30.9 (latest official patch)
my hw: 2cpu PIII Xeon + 1,5gb RAM
--
~~~~ Domenico Gargano [Network Administrator] ~~~~
Planetek Italia s.r.l. :tel:+39 080 5343750
Via Massaua, 12 - I-70123 BARI :fax:+39 080 5340280
~~~ email: gargano@planetek.it ~~~ www.planetek.it ~~~
reply other threads:[~2004-02-25 16:33 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=403CDC51.16545.1D46DD2@localhost \
--to=d.gargano@planetek.it \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.