From: "Domenico Gargano" <d.gargano@planetek.it>
To: linux-kernel@vger.kernel.org
Subject: weird blocked sync packets on win machines
Date: Thu, 11 Nov 2004 16:00:20 +0100 [thread overview]
Message-ID: <41938C94.24206.17593FE@localhost> (raw)
Hi all,
strange things happen on my linuxbox, I've got a firewall box running
fedora 2 with 5 net
adapters. All my private machines (192.168.30.) connect to internet and to
my DMZ
through the linuxbox.
During the day usually happens that my firewall stop forwarding SYN
packets, allowing
instead all other packets (ex. ACK) and all other protocols. This means
that I cannot
establish only new connections (prevoiously opened ones just work fine).
All my eth stop forwarding for 15 minutes, all the new traffic is totally
blocked (from/to
LAN, DMZ, INTERNET).
The really weird thing is that this happen only on windows machines, and
during this
block-time, if I close all IE windows and then I re-open IE, all
connections start again to
work (without waiting 15 minutes), this trick works only if my IE is using
squiq proxy
running on a server located in DMZ.
I've upgraded the kernel from 2.4.22 to all new releases since 2.6.8 but
nothing has
changed, I've changed all net adapters and fine-tuning kernel parameters
(like disable
syn-protect or increase nr. connections and decrease timeout values).
All tests are done with tcpdump.
Can someone please suggest me some way to find a solution? I'm not only
looking for
the right solution, but also some method to study this weird problem.
Thanks
pls put me in CC when replying.
--
~~~ Domenico Gargano [Senior Network Manager] ~~~
Planetek Italia s.r.l. :tel:+39 080 5343750
Via Massaua, 12 - I-70123 BARI :fax:+39 080 5340280
~~ email: d.gargano@planetek.it ~~~ www.planetek.it ~~
reply other threads:[~2004-11-11 15:01 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=41938C94.24206.17593FE@localhost \
--to=d.gargano@planetek.it \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox