All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Taylor, Grant" <gtaylor@riverviewtech.net>
To: netfilter@lists.netfilter.org
Subject: Re: matching the first packet of a connection
Date: Wed, 04 May 2005 14:37:49 -0500	[thread overview]
Message-ID: <4279248D.9090903@riverviewtech.net> (raw)
In-Reply-To: <1115220105.26791.25.camel@localhost.localdomain>

> I'm trying to match the first packet of a connection : for a TCP
> connection I want to match the first SYN packet received by the firewall
> and ignore the possible reemission, in fact I want to accept them.
> 
> Is this possible ?
> 
> I've try to use the conntrack module but I was not successful.

Question:  Are you wanting to just silently DROP the first connection attempt and force people to try to reconnect via retransmission of the SYN packet?  If that is the case you will want to do something out side of the connection tracking match extensions that exist because (as far as I know and understand) they all deal within a given connection.  You are really wanting to break / prevent one connection attempt and then allow the subsequent ones.  Or at least that's how I understand what you have written.  I have a feeling that you will be playing with the recent or set match extensions where you add a connection attempt to a recent list or set list while dropping the first connection attempt packet.  Subsequent connection attempt packets can then be matched against the recent list or set list to see if there has been a connection attempt dropped and if so accept the present connection
  attempt.

If you give me more to work with I might be able to come up with a rule set to help you out.



Grant. . . .


  parent reply	other threads:[~2005-05-04 19:37 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-05-04 15:21 matching the first packet of a connection Eric Leblond
2005-05-04 17:43 ` George Alexandru Dragoi
2005-05-04 18:50   ` Eric Leblond
2005-05-04 17:57 ` Thomas Jones
2005-05-04 18:11   ` Daniel Lopes
2005-05-04 18:34     ` Jason Opperisano
2005-05-04 19:37 ` Taylor, Grant [this message]
2005-05-04 21:21   ` Eric Leblond
2005-05-04 21:36     ` Taylor, Grant
2005-05-05  7:53     ` Taylor, Grant
2005-05-04 21:30   ` Eric Leblond

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4279248D.9090903@riverviewtech.net \
    --to=gtaylor@riverviewtech.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.