* Firewall Sending Resets(was Troubleshooting Netfilter Firewall (performance issues))
@ 2005-11-04 21:39 Harrison, James
2005-11-04 22:01 ` Jozsef Kadlecsik
0 siblings, 1 reply; 4+ messages in thread
From: Harrison, James @ 2005-11-04 21:39 UTC (permalink / raw)
To: netfilter
List,
We have determined, that during large(50-100MB) file transfers the
firewall is spuriously sending a tcp reset to both server and client.
The same file (which is a compressed format to begin with) when zipped
will copy just fine.
Why does the firewall feel the need to pull down the connection? The
reset(based on TTL counts) is being sent from the primary internal
interface.
This is devil-linux 1.2.6 i686 SMP (2.4.31)
Thanks
--
James Harrison RHCE
Manager, Information Security - American Color
PH: 615-377-7426
FX: 615-377-0325
AIM: harrijh1
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Firewall Sending Resets(was Troubleshooting Netfilter Firewall (performance issues))
2005-11-04 21:39 Firewall Sending Resets(was Troubleshooting Netfilter Firewall (performance issues)) Harrison, James
@ 2005-11-04 22:01 ` Jozsef Kadlecsik
2005-11-04 22:16 ` Harrison, James
0 siblings, 1 reply; 4+ messages in thread
From: Jozsef Kadlecsik @ 2005-11-04 22:01 UTC (permalink / raw)
To: Harrison, James; +Cc: netfilter
On Fri, 4 Nov 2005, Harrison, James wrote:
> We have determined, that during large(50-100MB) file transfers the
> firewall is spuriously sending a tcp reset to both server and client.
[...]
netfilter sends RST if it was configured to do so by using the REJECT
target.
No vanilla netfilter sends RST to client and server, in any setup.
Best regards,
Jozsef
-
E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
H-1525 Budapest 114, POB. 49, Hungary
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: Firewall Sending Resets(was Troubleshooting Netfilter Firewall (performance issues))
2005-11-04 22:01 ` Jozsef Kadlecsik
@ 2005-11-04 22:16 ` Harrison, James
2005-11-05 16:25 ` Jozsef Kadlecsik
0 siblings, 1 reply; 4+ messages in thread
From: Harrison, James @ 2005-11-04 22:16 UTC (permalink / raw)
To: Jozsef Kadlecsik; +Cc: netfilter
On Fri, 2005-11-04 at 23:01 +0100, Jozsef Kadlecsik wrote:
> On Fri, 4 Nov 2005, Harrison, James wrote:
>
> > We have determined, that during large(50-100MB) file transfers the
> > firewall is spuriously sending a tcp reset to both server and client.
> [...]
>
> netfilter sends RST if it was configured to do so by using the REJECT
> target.
>
> No vanilla netfilter sends RST to client and server, in any setup.
>
> Best regards,
> Jozsef
> -
> E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
> PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
> Address : KFKI Research Institute for Particle and Nuclear Physics
> H-1525 Budapest 114, POB. 49, Hungary
I understand, but the file transfer is initiated, begins, and can and
will run for a period of time, then out of the blue it fires the RST.
Why?
--
James Harrison RHCE
Manager, Information Security
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Firewall Sending Resets(was Troubleshooting Netfilter Firewall (performance issues))
2005-11-04 22:16 ` Harrison, James
@ 2005-11-05 16:25 ` Jozsef Kadlecsik
0 siblings, 0 replies; 4+ messages in thread
From: Jozsef Kadlecsik @ 2005-11-05 16:25 UTC (permalink / raw)
To: Harrison, James; +Cc: netfilter
On Fri, 4 Nov 2005, Harrison, James wrote:
> > netfilter sends RST if it was configured to do so by using the REJECT
> > target.
> >
> > No vanilla netfilter sends RST to client and server, in any setup.
>
> I understand, but the file transfer is initiated, begins, and can and
> will run for a period of time, then out of the blue it fires the RST.
Are you sure the firewall creates the RST segments?
> Why?
Dunno. You should capture the full traffic by tcpdump so that one could
analyze it. Without such a proof nothing much can be said. Also, one would
require the list of netfilter patches (from patch-o-matic or others)
applied on top of kernel 2.4.31 in devil-linux.
Best regards,
Jozsef
-
E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
H-1525 Budapest 114, POB. 49, Hungary
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2005-11-05 16:25 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-11-04 21:39 Firewall Sending Resets(was Troubleshooting Netfilter Firewall (performance issues)) Harrison, James
2005-11-04 22:01 ` Jozsef Kadlecsik
2005-11-04 22:16 ` Harrison, James
2005-11-05 16:25 ` Jozsef Kadlecsik
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox