From: Patrick McHardy <kaber@trash.net>
To: Sven Riedel <sr@securenet.de>
Cc: netfilter@vger.kernel.org,
Netfilter Developer Mailing List
<netfilter-devel@vger.kernel.org>
Subject: Re: Transfer stalls with NAT under 2.6.24.3
Date: Wed, 26 Mar 2008 16:47:47 +0100 [thread overview]
Message-ID: <47EA7023.3000405@trash.net> (raw)
In-Reply-To: <47EA2399.1080201@securenet.de>
Sven Riedel wrote:
> Patrick McHardy wrote:
>> Sven Riedel wrote:
>>> Is this issue known/is there a patch available or would further
>>> information be needed to help debug the problem?
>>
>> 2.6.24.3 includes a patches that was supposed to fix problems
>> with connections in TIME_WAIT state. Does 2.6.24.2 work better
>> for you?
>
> The firewall system in question is currently productive. I _might_ be
> able to try the other kernel tomorrow morning. Once I am able to try it
> I'll let you know.
>
>>
>> Please enable conntrack logging for TCP by executing:
>>
>> echo 6 >/proc/sys/net/netfilter/nf_conntrack_log_invalid
>>
>> and check whether you get any messages in the ring buffer.
>
> Yep, lots ;)
>
> In the following 100.100.100.100 is the external machine and
> 200.200.200.200 is the NAT IP-Address on the firewall. A 5MB file was
> transferred via scp to 100.100.100.100 from the internal network.
>
> The output during a "clean" run, with an empty conntrack table and no
> stalls:
> nf_ct_tcp: ACK is over the upper bound (ACKed data not seen yet) IN= OUT=
> SRC=100.100.100.100 DST=200.200.200.200 LEN=64 TOS=0x00 PREC=0x00 TTL=56
> ID=42121
> ...
>
> During a run with stalls:
>
> nf_ct_tcp: ACK is over the upper bound (ACKed data not seen yet) IN= OUT=
> SRC=100.100.100.100 DST=200.200.200.200 LEN=80 TOS=0x00 PREC=0x00 TTL=56
> ID=44105
> DF PROTO=TCP SPT=22 DPT=35858 SEQ=4160349927 ACK=596614326 WINDOW=49248
> RES=0x00 ACK URGP=0 OPT
> (0101080A4558793C1B13CE350101051A491E8751491E8CA9491E7B71491E81F9491E40A9491E5B61)
>
>
> ^^^^ Transfer stalled here for ~10 seconds.
>
>
> printk: 22 messages suppressed.
> nf_ct_tcp: ACK is over the upper bound (ACKed data not seen yet) IN= OUT=
> SRC=100.100.100.100 DST=200.200.200.200 LEN=72 TOS=0x00 PREC=0x00 TTL=56
> ID=44113
Thanks, can you send a binary tcpdump (... -w file) of a connection
that triggers these messages please?
next prev parent reply other threads:[~2008-03-26 15:47 UTC|newest]
Thread overview: 116+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-03-26 8:47 Transfer stalls with NAT under 2.6.24.3 Sven Riedel
2008-03-26 9:24 ` Patrick McHardy
2008-03-26 10:21 ` Sven Riedel
2008-03-26 15:47 ` Patrick McHardy [this message]
2008-03-26 18:45 ` Jozsef Kadlecsik
2008-03-26 19:16 ` Krzysztof Oledzki
2008-03-31 6:53 ` Sven Riedel
2008-07-04 14:54 ` TCP connection stalls under 2.6.24.7 Thomas Jarosch
2008-07-04 20:58 ` Jozsef Kadlecsik
2008-07-04 21:04 ` Jozsef Kadlecsik
2008-07-07 9:18 ` Thomas Jarosch
2008-07-07 13:18 ` Thomas Jarosch
2008-07-10 13:17 ` Jozsef Kadlecsik
2008-07-10 14:12 ` Thomas Jarosch
2008-07-10 21:21 ` Jozsef Kadlecsik
2008-07-11 14:33 ` Thomas Jarosch
2008-07-15 11:47 ` Thomas Jarosch
2008-07-15 16:10 ` Thomas Jarosch
2008-07-15 18:30 ` Dâniel Fraga
2008-07-31 4:47 ` Dâniel Fraga
2008-07-31 7:39 ` Ilpo Järvinen
2008-08-02 12:24 ` Dâniel Fraga
2008-07-15 20:17 ` Ilpo Järvinen
2008-07-16 8:07 ` Thomas Jarosch
2008-07-16 9:03 ` Thomas Jarosch
2008-07-17 13:55 ` Ilpo Järvinen
2008-07-17 15:15 ` Thomas Jarosch
2008-07-17 15:53 ` Ilpo Järvinen
2008-07-18 9:14 ` Thomas Jarosch
2008-07-18 13:55 ` Ilpo Järvinen
2008-07-18 14:02 ` Thomas Jarosch
2008-07-19 7:35 ` Ilpo Järvinen
2008-07-25 10:00 ` Ilpo Järvinen
2008-07-25 13:00 ` Thomas Jarosch
2008-07-25 14:06 ` Ilpo Järvinen
2008-07-25 15:34 ` Thomas Jarosch
2008-07-31 7:39 ` Thomas Jarosch
2008-07-31 12:44 ` Dâniel Fraga
2008-07-31 13:47 ` Thomas Jarosch
2008-07-31 14:11 ` Dâniel Fraga
2008-08-06 18:53 ` Dâniel Fraga
2008-08-07 6:54 ` Ilpo Järvinen
2008-08-07 11:50 ` Denys Fedoryshchenko
2008-08-07 12:11 ` Thomas Jarosch
2008-08-07 12:14 ` Ilpo Järvinen
2008-08-07 12:23 ` Denys Fedoryshchenko
2008-08-08 9:56 ` Ilpo Järvinen
2008-08-08 10:32 ` Denys Fedoryshchenko
2008-08-07 11:33 ` [PATCH] tcp FRTO: in-order-only "TCP proxy" fragility workaround Ilpo Järvinen
2008-08-08 4:42 ` Bill Fink
2008-08-08 10:32 ` Ilpo Järvinen
2008-08-11 21:44 ` David Miller
2008-08-12 7:46 ` Thomas Jarosch
2008-08-12 8:18 ` David Miller
2008-08-12 17:43 ` Dâniel Fraga
2008-08-12 17:52 ` Ilpo Järvinen
2008-08-13 17:53 ` Dâniel Fraga
2008-08-13 18:34 ` Ilpo Järvinen
2008-08-15 4:34 ` Dâniel Fraga
2008-08-15 7:06 ` Ilpo Järvinen
2008-08-15 21:35 ` Dâniel Fraga
2008-08-15 22:06 ` Ilpo Järvinen
2008-08-15 23:57 ` Dâniel Fraga
2008-08-16 2:15 ` Dâniel Fraga
2008-08-16 7:10 ` Ilpo Järvinen
2008-08-16 19:18 ` Ilpo Järvinen
2008-08-17 0:36 ` Dâniel Fraga
2008-08-19 10:38 ` Ilpo Järvinen
2008-08-20 0:34 ` Dâniel Fraga
2008-08-20 7:57 ` Ilpo Järvinen
2008-08-20 12:37 ` Ilpo Järvinen
2008-08-22 21:32 ` Dâniel Fraga
2008-08-22 21:37 ` David Miller
2008-08-23 14:14 ` Dâniel Fraga
2008-08-23 14:38 ` Ilpo Järvinen
2008-08-24 19:38 ` Dâniel Fraga
2008-08-26 14:10 ` Ilpo Järvinen
2008-08-26 14:32 ` Ilpo Järvinen
2008-08-26 17:18 ` Dâniel Fraga
2008-08-26 20:40 ` Ilpo Järvinen
2008-08-26 21:17 ` Dâniel Fraga
2008-08-27 10:22 ` Ilpo Järvinen
2008-08-27 19:51 ` Dâniel Fraga
2008-08-27 20:32 ` Ilpo Järvinen
2008-08-27 20:50 ` Dâniel Fraga
2008-08-27 21:25 ` Ilpo Järvinen
2008-08-27 21:42 ` Dâniel Fraga
2008-08-27 22:24 ` Dâniel Fraga
2008-08-28 21:49 ` Dâniel Fraga
2008-08-29 13:07 ` Ilpo Järvinen
2008-08-29 17:41 ` Dâniel Fraga
2008-09-01 7:11 ` Ilpo Järvinen
2008-08-30 6:56 ` Dâniel Fraga
2008-09-01 7:11 ` Ilpo Järvinen
2008-09-07 8:17 ` Dâniel Fraga
2008-09-08 10:27 ` Ilpo Järvinen
2008-09-08 20:20 ` Dâniel Fraga
2008-09-11 13:44 ` Ilpo Järvinen
2008-09-11 17:30 ` Dâniel Fraga
2008-09-12 10:16 ` Ilpo Järvinen
2008-09-13 23:31 ` Dâniel Fraga
2008-09-16 12:10 ` Ilpo Järvinen
2008-09-16 14:24 ` Dâniel Fraga
2008-09-17 10:23 ` Ilpo Järvinen
2008-09-18 20:35 ` Dâniel Fraga
2008-09-18 21:04 ` Ilpo Järvinen
2008-09-21 3:02 ` Dâniel Fraga
2008-09-22 4:23 ` Dâniel Fraga
2008-09-22 11:22 ` Ilpo Järvinen
2008-09-22 16:13 ` Dâniel Fraga
2008-09-15 19:42 ` Dâniel Fraga
2008-09-11 18:12 ` Dâniel Fraga
2008-08-15 21:59 ` Dâniel Fraga
2008-08-13 8:00 ` Thomas Jarosch
2008-08-22 21:18 ` Ilpo Järvinen
2008-08-11 21:41 ` David Miller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=47EA7023.3000405@trash.net \
--to=kaber@trash.net \
--cc=netfilter-devel@vger.kernel.org \
--cc=netfilter@vger.kernel.org \
--cc=sr@securenet.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.