public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [Problem] Linux 2.4.5-ac17 ipt_unclean 'fixes'
@ 2001-07-14 22:00 J Troy Piper
  2001-07-14 22:50 ` Josh McKinney
  2001-07-16 10:28 ` Rusty Russell
  0 siblings, 2 replies; 4+ messages in thread
From: J Troy Piper @ 2001-07-14 22:00 UTC (permalink / raw)
  To: linux-kernel; +Cc: Alan Cox, rusty


[-- Attachment #0: Type: message/rfc822, Size: 1011 bytes --]


Alan, 

I apologise for having taken so long to write this (I have known about 
this problem since 2.4.5ac17 and have not had a chance to document til 
today) but there seems to be a problem with the ipt_unclean fixes by Rusty 
Russell.  ANY incoming packets from any interface (ppp0 and eth0) are 
marked as 'unclean' with some variation on the following syslog entry:

Jul  8 23:16:04 paranoia kernel: ipt_unclean: TCP option 3 at 37 too long
Jul  8 23:16:05 paranoia kernel: ipt_unclean: TCP option 3 at 37 too long
Jul  8 23:16:16 paranoia kernel: ipt_unclean: TCP option 3 at 37 too long
Jul  8 23:16:18 paranoia kernel: ipt_unclean: TCP option 3 at 37 too long

and thus are blocked by my 'unclean packet dropping' firewall (iptables).

I haven't seen any mention of this on the list, nor have I seen any more 
ipt_unclean patches to address this problem, so here's your heads-up 
(albeit a bit late).

Thanks,

J Troy Piper
jtp@dok.org

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2001-07-16 22:10 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-07-14 22:00 [Problem] Linux 2.4.5-ac17 ipt_unclean 'fixes' J Troy Piper
2001-07-14 22:50 ` Josh McKinney
2001-07-16 10:28 ` Rusty Russell
2001-07-16 22:09   ` J Troy Piper

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox