Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.samba.org
Subject: Re: TCP delay, solved
Date: Fri, 14 Jun 2002 10:16:11 +0100	[thread overview]
Message-ID: <200206140919.KAA11256@slate.rockstone.co.uk> (raw)
In-Reply-To: <002101c2137b$e44d6de0$638317d2@pacific.net.au>

On Friday 14 June 2002 9:17 am, David Luyer wrote:

> Ah.  I missed the start of the discussion.  You're blocking ident
> lookups on your customers, and it's causing them to have problems
> accessing some sites and services?
>
> Easy solution:
>
>   deny (connection reset) rather than drop the connections

Yes, that's the "hole in my firewall" I referred to.   By sending back RST to 
packets coming in on TCP port 113, I'm telling people there's a firewall 
there.   All other ports send back nothing, and I don't want this one to 
stand out as being different....

> Hard solution:
>
>   transproxy ident

Explain please ?

>   and return a cryptographic hash representing
>   the actual client online on the IP which the ident request is
>   for

Sounds more than most situations would need.   Why bother to send back 
something actually related to the user (yes, I know this is what Ident's 
expecting, but it's not necessary) ?   So long as Ident responds with 
*something* (such as 'no-user') then the remote server will be happy and talk 
to you without a timeout.

The problem is making sure this only happens in response to an outgoing 
packet (ie the Ident request gets treated as RELATED to the initial 
connection), rather than providing an Ident daemon which answers any request 
which comes in (eg port scan).

 

Antony.


  parent reply	other threads:[~2002-06-14  9:16 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20020612154553.GI10747@hack.home.theunixman.com>
2002-06-12 16:33 ` TCP delay, solved Nathan Cassano
2002-06-12 20:02   ` Antony Stone
2002-06-13  9:59     ` Juri Haberland
2002-06-13 12:05       ` Antony Stone
2002-06-14  7:15         ` David Luyer
2002-06-14  7:55           ` Antony Stone
2002-06-14  8:17             ` David Luyer
2002-06-14  8:25               ` David Luyer
2002-06-14  9:18                 ` Antony Stone
2002-06-14 20:29                   ` Joe Patterson
2002-06-15  1:21                     ` Joe Patterson
2002-06-14  9:16               ` Antony Stone [this message]
2002-06-14 17:28                 ` Tony Earnshaw

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200206140919.KAA11256@slate.rockstone.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.samba.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox