All of lore.kernel.org
 help / color / mirror / Atom feed
* ssh connections stalling
@ 2009-10-22 18:45 Carl Michal
  2009-10-22 20:24 ` Karl Hiramoto
  2009-10-23  8:05 ` Mart Frauenlob
  0 siblings, 2 replies; 19+ messages in thread
From: Carl Michal @ 2009-10-22 18:45 UTC (permalink / raw)
  To: netfilter

I'm having some troubles with what should be a very simple firewall to 
simply protect a local machine.  When the firewall is enabled, ssh and scp 
connections will sometimes hang indefinitely.  I've tried configuring the 
firewall (which blocks all incoming requests to ports 0:1023 except ssh 
and icmp) with several different tools: firehol, ufw and lutelwall.  If 
the firewall is turned off, the problem disappears.  With lutelwall there 
is an option to create a non-stateful firewall - if that is done, the 
problem also disappears.

My syslog does show dropped packets that appear to be the cause of the 
problem.  From tcpdumps at both ends of the connection it looks like the 
problem happens if large packets are sent out from behind the firewall and 
then arrive in pieces at the other end with a piece missing.  ack 
packets coming back in are dropped, and the connection never recovers.

Any help in diagnosing this would be much appreciated.

Carl






^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2009-10-26  4:37 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-10-22 18:45 ssh connections stalling Carl Michal
2009-10-22 20:24 ` Karl Hiramoto
2009-10-22 20:36   ` Carl Michal
2009-10-23  7:10     ` Rob Sterenborg
2009-10-23 10:29     ` Karl Hiramoto
2009-10-22 23:31   ` Carl Michal
2009-10-23  8:05 ` Mart Frauenlob
2009-10-23 17:32   ` Carl Michal
2009-10-23 18:10     ` Jozsef Kadlecsik
2009-10-23 18:49       ` Carl Michal
2009-10-23 19:57       ` Carl Michal
2009-10-23 21:42         ` Jozsef Kadlecsik
2009-10-23 22:22           ` Carl Michal
2009-10-23 23:58             ` Steven Kath
2009-10-24  6:44             ` Carl Michal
2009-10-24  7:21               ` Payam Chychi
2009-10-24 17:24               ` Jozsef Kadlecsik
2009-10-24 20:58                 ` Carl Michal
2009-10-26  4:37                 ` Carl Michal

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.