Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Dharmendra.T" <dharmu@nsecure.net>
To: Juergen Stohr <stohr@lpr.e-technik.tu-muenchen.de>
Cc: netfilter@lists.netfilter.org
Subject: Re: bug? blocked packets get shadowed to internal network
Date: 04 Sep 2003 12:23:42 +0530	[thread overview]
Message-ID: <1062658448.2760.12.camel@india.nsecure.net> (raw)
In-Reply-To: <20030814113448.A21598@rcs.ei.tum.de>

[-- Attachment #1: Type: text/plain, Size: 1697 bytes --]

hi,

When I saw your logs it is sending a rst packet to destination. Are you
running any ids inside your network? 


Regards
Dharmendra.T
dharmu@nsecure.net


On Thu, 2003-08-14 at 15:04, Juergen Stohr wrote:

    Hi to all,
    
    we are using a firewall with RedHat kernel 2.4.20-19.7. The firewall is 
    configured to block every packet with DPT 199 into our network. When doing
    a "telnet server.in.our.network 199" from outside, the firewall correctly 
    drops that packet, logging
    
    IN=eth1 OUT=eth0 SRC=xxx.xxx.11.231 DST=xxx.xxx.151.184 LEN=44 TOS=0x00 PREC=0x00 TTL=252 ID=12615 DF PROTO=TCP SPT=34869 DPT=199 WINDOW=8760 RES=0x00 SYN URGP=0
    
    to syslog. The external interface is eth1, internal is eth0.
    However, at the same time, the firewall generates a packet, which is droped
    by the output chain of the firewall. It fakes the SRC and DST and wants to send
    that packet to the internal server:
    
    IN= OUT=eth0 SRC=xxx.xxx.151.184 DST=xxx.xxx.11.231 LEN=40 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=TCP SPT=199 DPT=34869 WINDOW=0 RES=0x00 ACK RST URGP=0
    
    When setting the output chain to accept policy, the above packet is delivered
    xxx.xxx.151.184!
    
    How can we prohibit those packets to be generated? Kernel RH 2.4.18-x didn't
    show that behaviour.
    
    Please CC me as I'm not subscribed.
    
    regards,
    	juergen
    
    

-- 

This message is intended for the addressee only. It may contain
privileged or Confidential information. If you have received this
message in error,please notify the sender and destroy the message
immediately.Unauthorised use or reproduction of this message is strictly
prohibited.

[-- Attachment #2: Type: text/html, Size: 3616 bytes --]

  parent reply	other threads:[~2003-09-04  6:53 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-08-14  9:34 bug? blocked packets get shadowed to internal network Juergen Stohr
2003-08-19 15:30 ` Arnt Karlsen
2003-09-04  6:53 ` Dharmendra.T [this message]
  -- strict thread matches above, loose matches on Subject: below --
2003-08-14 11:11 Juergen Stohr
2003-08-14 11:39 Juergen Stohr
2003-08-14 11:47 ` Chris Wilson
2003-08-14 13:50 Juergen Stohr
     [not found] <Pine.LNX.4.44.0308141501421.31438-100000@localhost>
     [not found] ` <Pine.LNX.4.44.0308141506450.31438-100000@localhost>
2003-08-14 15:07   ` Juergen Stohr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1062658448.2760.12.camel@india.nsecure.net \
    --to=dharmu@nsecure.net \
    --cc=netfilter@lists.netfilter.org \
    --cc=stohr@lpr.e-technik.tu-muenchen.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox