Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Cedric Blancher <blancher@cartel-securite.fr>
To: Antony Stone <Antony@Soft-Solutions.co.uk>
Cc: netfilter@lists.netfilter.org
Subject: Re: ICMP conntrack
Date: 18 Oct 2002 12:54:10 +0200	[thread overview]
Message-ID: <1034938450.8912.29.camel@elendil> (raw)
In-Reply-To: <200210180952.g9I9qEL27957@vulcan.rissington.net>

Le ven 18/10/2002 à 11:52, Antony Stone a écrit :
> Although I agree with what you've said here, it's not really relevant
> to the  original poster's question, because in these cases you'll
> still never see an ICMP entry in the connection tracking table.  
> Because the ICMP packets are RELATED to the original connection, it's
> the original packet which you'll see in the conntrack table - the ICMP
> replies simply get through because of their
> relationship to the original packet.

True ;)

> > So, for ICMP requests, you have some kind of conntrack, based on ICMP
> > sequence number. For ICMP errors, conntrack tries to associate them to
> > an existing entry.
> ICMP sequence number ???   What's that ?

cbr@elendil:~$ ping thor
PING thor (192.168.10.50): 56 data bytes
64 bytes from 192.168.10.50: icmp_seq=0 ttl=255 time=0.3 ms
64 bytes from 192.168.10.50: icmp_seq=1 ttl=255 time=0.3 ms
64 bytes from 192.168.10.50: icmp_seq=2 ttl=255 time=0.2 ms
64 bytes from 192.168.10.50: icmp_seq=3 ttl=255 time=0.3 ms
64 bytes from 192.168.10.50: icmp_seq=4 ttl=255 time=0.3 ms

			     ^^^^^^^^^^
				This

Just spy an ICMP request/reply stuff such as ping with ethereal and look
at sequence number field. It aims to associate received reply to the
good sent request.

-- 
Cédric Blancher  <blancher@cartel-securite.fr>
Consultant en sécurité des systèmes et réseaux  - Cartel Sécurité
Tél: +33 (0)1 44 06 97 87 - Fax: +33 (0)1 44 06 97 99
PGP KeyID:157E98EE  FingerPrint:FA62226DA9E72FA8AECAA240008B480E157E98EE


  parent reply	other threads:[~2002-10-18 10:54 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-17 23:27 Rules not taking effect Tib
2002-10-17 23:35 ` Antony Stone
2002-10-18  0:32   ` Rules not taking effect - 2nd try Tib
2002-10-18  2:51     ` ICMP conntrack Vincent Lim
2002-10-18  8:28       ` Antony Stone
2002-10-18  9:05         ` Cedric Blancher
2002-10-18  9:52           ` Antony Stone
2002-10-18 10:07             ` Vincent Lim
2002-10-18 10:22               ` Antony Stone
2002-10-18 10:54             ` Cedric Blancher [this message]
2002-10-18  8:25     ` Rules not taking effect - 2nd try Antony Stone
2002-10-18  9:35       ` Tib

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1034938450.8912.29.camel@elendil \
    --to=blancher@cartel-securite.fr \
    --cc=Antony@Soft-Solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox