Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Spam User <spam@the-force.net>
To: netfilter@lists.netfilter.org
Subject: RE: stop accepting new connections on port 80
Date: Wed, 7 Dec 2005 14:18:12 -0800 (PST)	[thread overview]
Message-ID: <20051207140828.H66917@uberwoo.hedgpeth.com> (raw)
In-Reply-To: <FAC4E024BF776842876169173CE2F01313B3C4@mailbox.vikus.com>



On Wed, 7 Dec 2005, Derick Anderson wrote:

>
>> -----Original Message-----
>> From: netfilter-bounces@lists.netfilter.org
>> [mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of Spam User
>> Sent: Wednesday, December 07, 2005 3:39 PM
>> To: netfilter@lists.netfilter.org
>> Subject: stop accepting new connections on port 80
>>
>> Hi,
>>
>> I've been trying to figure out how to get iptables to stop
>> accepting new connections on port 80 while letting the
>> existing connections finish up what they're doing.
>>
>> I thought it would be as easy as removing the rule that
>> allows new connections and leaving the rule that allowed
>> related and established connections, but when I remove the
>> rule that allows new connections, all connections stop working.
>
> [snip]
>
> I don't know exactly how you're determining the above: is it a long
> download that gets killed? HTTP opens at least (and usually only) one
> connection per page so the problem may be that the connection is already
> closed even though the page is still being viewed. Unless you are
> downloading something it's not likely your connection will last much
> longer than four or five seconds on a heavily graphical page with
> broadband.


I had sort of thought about this, but then I thought thats what the 
related and established rules took care of.

I suppose it it would be more helpful if the end goal was known.. to be 
more specific, I should have included that we use PHP sessions and what 
I'd like to do is keep the session open until all the currently open PHP 
sessions are closed (serve active session, don't accept new connections).

I was hoping that the connection tracking would be associated to the 
sessions (not by session id or anything, but by the relationship of the 
established connections from the caller), so if user a looked at page X 
then 10 seconds later looked at page y, netfilter would know because that 
client had had established connections - I suppose I can see the flaws in 
that logic though.  I thought that the callers connection info being in a 
time_wait state would possibly mean something to iptables.

I know this isnt an apache/php list, but maybe thats where I should be 
headed?  Something like sending apache a usr1 signal, but instead of 
accepting new connections with the new config, just don't accept new 
connections until the daemon is restarted.

In any case, thanks for your speedy response.

>
> Your rules look ok at first glance so I would recommend some time with
> Ethereal and a long download from the web server. Download a big file
> once with your default rules and see what happens. Then delete the file
> and download it again, this time running your kill-new-connections
> script and see if the file transfer gets knocked immediately.
>
>> Thanks,
>>
>> Mike
>
> Derick Anderson
>
>


  reply	other threads:[~2005-12-07 22:18 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-12-07 21:58 stop accepting new connections on port 80 Derick Anderson
2005-12-07 22:18 ` Spam User [this message]
  -- strict thread matches above, loose matches on Subject: below --
2005-12-08 13:50 Derick Anderson
2005-12-07 20:38 Spam User
2005-12-09 18:42 ` Bill Hance
2005-12-09 19:08   ` R. DuFresne
2006-01-03  7:12   ` Jan Engelhardt
2005-12-14 20:33 ` Nick Drage

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20051207140828.H66917@uberwoo.hedgpeth.com \
    --to=spam@the-force.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox