All of lore.kernel.org
 help / color / mirror / Atom feed
* question on flags
@ 2006-01-29  0:31 Leonardo Rodrigues Magalhães
  2006-01-29  2:18 ` Jorge Davila
  0 siblings, 1 reply; 2+ messages in thread
From: Leonardo Rodrigues Magalhães @ 2006-01-29  0:31 UTC (permalink / raw)
  To: netfilter ML


    Hello People,

    In normal situations, which would be the flags for SYN packets and 
FIN packets of a tcp stream ?? I'm thinking of, in some few ports, log 
the beggining of the connection (SYN) and the end of the connection 
(FIN). I also know I should treat RST packets, because in problems 
situations i will never see FIN.

    So, can you point me what tcp-flag combinations to look for ?

    Thanks for the answers and for the attention.

-- 


	Atenciosamente / Sincerily,
	Leonardo Rodrigues
	Solutti Tecnologia
	http://www.solutti.com.br

	Minha armadilha de SPAM, NÃO mandem email
	gertrudes@solutti.com.br
	My SPAMTRAP, do not email it






^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: question on flags
  2006-01-29  0:31 question on flags Leonardo Rodrigues Magalhães
@ 2006-01-29  2:18 ` Jorge Davila
  0 siblings, 0 replies; 2+ messages in thread
From: Jorge Davila @ 2006-01-29  2:18 UTC (permalink / raw)
  To: Leonardo Rodrigues Magalhães; +Cc: netfilter ML

You can find a good explanation an examples here:

http://iptables-tutorial.frozentux.net/iptables-tutorial.html

Jorge Dávila.

El sáb, 28-01-2006 a las 21:31 -0300, Leonardo Rodrigues Magalhães
escribió:
>     Hello People,
> 
>     In normal situations, which would be the flags for SYN packets and 
> FIN packets of a tcp stream ?? I'm thinking of, in some few ports, log 
> the beggining of the connection (SYN) and the end of the connection 
> (FIN). I also know I should treat RST packets, because in problems 
> situations i will never see FIN.
> 
>     So, can you point me what tcp-flag combinations to look for ?
> 
>     Thanks for the answers and for the attention.
> 
-- 
-----------------------------------------------------------------
Jorge Isaac Davila Lopez
-
sitio web: http://www.nicaraguaopensource.com/
correo-e: davila@cablenet.com.ni
-----------------------------------------------------------------




^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-01-29  2:18 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-01-29  0:31 question on flags Leonardo Rodrigues Magalhães
2006-01-29  2:18 ` Jorge Davila

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.