All of lore.kernel.org
 help / color / mirror / Atom feed
From: Iulian Topliceanu <iulian.topliceanu@net-m.de>
To: netfilter@lists.netfilter.org
Subject: IPTABLES drops packages for existing rules
Date: Fri, 23 Sep 2005 12:22:35 +0200	[thread overview]
Message-ID: <4333D76B.9030900@net-m.de> (raw)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

I have a Fedora Core 3 on a box with plenty of RAM (1 GB) dual P4 and
so on.

The structure is simple: 3 NICs

eth0 - ouside
eth1 - intranet
eth2 - heartbeat

There are plenty of ACCEPT rules, and in the end a general DENY rule,
to drop everything that didn't match the ACCEPT rules (obviously)

There are plenty of NAT rules as well, portforwading and stuff like.

Now, *sometimes* but just *sometimes*, ICMP and TCP packages are
simply matching the general DENY rule and dropped, though there is a
rule that says that LAN hosts can communicate without restrictions
between them (there are 8 subnets)

So, there are moments when IPTABLES is behaving like that ACCEPT rule
woudn't exist, simply denying packets from a LAN host to another LAN host.

If it matters, most of the denyed packets are ICMPs TYPE 0 (round 10
000 packets / 24 h) and TCP packets on various SQL ports (round 35
packets / 24 h)

No, this woudn't be a PITA if the monitoring system would send alarms
in these moments. Everything seems to happen randomly.

What's the problem? I guess it's an IPTABLES issue not some
ip_conntrack trick.

Thanks for the sugestions,
Iulian Topliceanu
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iD8DBQFDM9dqYBaCkvEor9kRAvvfAKCE/9DETQkpeyleAAAD/2a6lB1KTACfdeyw
SXZzydy/uysrCY86ZQBhjW8=
=8Mvg
-----END PGP SIGNATURE-----



             reply	other threads:[~2005-09-23 10:22 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-09-23 10:22 Iulian Topliceanu [this message]
2005-09-23 13:14 ` IPTABLES drops packages for existing rules /dev/rob0

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4333D76B.9030900@net-m.de \
    --to=iulian.topliceanu@net-m.de \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.