* question on flags
@ 2006-01-29 0:31 Leonardo Rodrigues Magalhães
2006-01-29 2:18 ` Jorge Davila
0 siblings, 1 reply; 2+ messages in thread
From: Leonardo Rodrigues Magalhães @ 2006-01-29 0:31 UTC (permalink / raw)
To: netfilter ML
Hello People,
In normal situations, which would be the flags for SYN packets and
FIN packets of a tcp stream ?? I'm thinking of, in some few ports, log
the beggining of the connection (SYN) and the end of the connection
(FIN). I also know I should treat RST packets, because in problems
situations i will never see FIN.
So, can you point me what tcp-flag combinations to look for ?
Thanks for the answers and for the attention.
--
Atenciosamente / Sincerily,
Leonardo Rodrigues
Solutti Tecnologia
http://www.solutti.com.br
Minha armadilha de SPAM, NÃO mandem email
gertrudes@solutti.com.br
My SPAMTRAP, do not email it
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: question on flags
2006-01-29 0:31 question on flags Leonardo Rodrigues Magalhães
@ 2006-01-29 2:18 ` Jorge Davila
0 siblings, 0 replies; 2+ messages in thread
From: Jorge Davila @ 2006-01-29 2:18 UTC (permalink / raw)
To: Leonardo Rodrigues Magalhães; +Cc: netfilter ML
You can find a good explanation an examples here:
http://iptables-tutorial.frozentux.net/iptables-tutorial.html
Jorge Dávila.
El sáb, 28-01-2006 a las 21:31 -0300, Leonardo Rodrigues Magalhães
escribió:
> Hello People,
>
> In normal situations, which would be the flags for SYN packets and
> FIN packets of a tcp stream ?? I'm thinking of, in some few ports, log
> the beggining of the connection (SYN) and the end of the connection
> (FIN). I also know I should treat RST packets, because in problems
> situations i will never see FIN.
>
> So, can you point me what tcp-flag combinations to look for ?
>
> Thanks for the answers and for the attention.
>
--
-----------------------------------------------------------------
Jorge Isaac Davila Lopez
-
sitio web: http://www.nicaraguaopensource.com/
correo-e: davila@cablenet.com.ni
-----------------------------------------------------------------
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2006-01-29 2:18 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-01-29 0:31 question on flags Leonardo Rodrigues Magalhães
2006-01-29 2:18 ` Jorge Davila
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.