Linux Netfilter discussions
 help / color / mirror / Atom feed
* Possible conntrack problem
@ 2006-06-02 18:46 zottmann
  2006-06-03 22:04 ` Djalma Fadel Junior
  0 siblings, 1 reply; 6+ messages in thread
From: zottmann @ 2006-06-02 18:46 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Mail message body --]
[-- Type: text/plain, Size: 487 bytes --]

Hi !! 

We are seeing a lot of packets being blocked at our firewall, coming from 
our webserver, port 80, going to the several hosts at the Internet, at high 
ports, with both SET and ACK set. 

It seems that these packets are answers from our webserver to connections 
estabilished to it, and, for some reason, their state is not being kept. 

How can I track this problem? 

We are using iptables 1.3.1, kernel 2.6.11.12, in a Fedora Core 3 machine. 

Thanks in advance, 
Carlos. 




^ permalink raw reply	[flat|nested] 6+ messages in thread
* Re: Possible conntrack problem
@ 2006-06-03 18:53 zottmann
  0 siblings, 0 replies; 6+ messages in thread
From: zottmann @ 2006-06-03 18:53 UTC (permalink / raw)
  To: justin, Sietse van Zanen; +Cc: netfilter

[-- Attachment #1: Mail message body --]
[-- Type: text/plain, Size: 1803 bytes --]

Hi !! 

Thank you both for your answers!! 

We are not getting any reports regarding problems with our webserver, but 
surely these logs are weird. 

We are going to try ip_conntrack_tcp_be_liberal and see what happens. By the 
way, what does it really means? 

Regards, 
Carlos. 


Em (14:15:13), Justin Schoeman escreveu: 


>Can also try: 
> 
>echo "1" > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_be_liberal 
> 
>Seems to help if there is a PIX between your clients and servers... 
> 
>-justin 
> 
>Sietse van Zanen wrote: 
>> This usually happens with clients behaving badly or misconfigured 
servers. 
>Very unlikely (I would say less 1% chance) to be a netfilter issue. 
>> If you don't get any reports about you webserver being unreachable or 
>unusable, all is working exactly as it should. 
>> 
>> If people do have problems with your webserver, check the configuration 
of 
>the server and clients. 
>> 
>> -Sietse 
>> 
>> ________________________________ 
>> 
>> From: netfilter-bounces@lists.netfilter.org on behalf of 
>zottmann@ig.com.br 
>> Sent: Thu 01-Jun-06 13:56 
>> To: netfilter@lists.netfilter.org 
>> Subject: Possible conntrack problem 
>> 
>> 
>> 
>> Hi !! 
>> 
>> I am having a problem that I think may be related to conntrack. 
>> 
>> I am getting dropped packets in the firewall coming from our web server, 
>> source port 80, and going to external machines on high ports, with both 
>ACK 
>> and SEQ numbers set. 
>> 
>> It seems to me that these packets are answers from our webserver to 
>> connections estabilished with it, but, for some reason, the connection 
>> information is being lost (maybe due to timeout?). 
>> 
>> How can I track this? Has anyone gone through something like it? 
>> 
>> Thanks in advance, 
>> Carlos. 
>> 
>> 
>> 
>> 
>> 
> 
>---------- 



^ permalink raw reply	[flat|nested] 6+ messages in thread
* Possible conntrack problem
@ 2006-06-01 11:56 zottmann
  2006-06-01 12:04 ` Sietse van Zanen
  0 siblings, 1 reply; 6+ messages in thread
From: zottmann @ 2006-06-01 11:56 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Mail message body --]
[-- Type: text/plain, Size: 540 bytes --]

Hi !! 

I am having a problem that I think may be related to conntrack. 

I am getting dropped packets in the firewall coming from our web server, 
source port 80, and going to external machines on high ports, with both ACK 
and SEQ numbers set. 

It seems to me that these packets are answers from our webserver to 
connections estabilished with it, but, for some reason, the connection 
information is being lost (maybe due to timeout?). 

How can I track this? Has anyone gone through something like it? 

Thanks in advance, 
Carlos. 



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2006-06-03 22:04 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-06-02 18:46 Possible conntrack problem zottmann
2006-06-03 22:04 ` Djalma Fadel Junior
  -- strict thread matches above, loose matches on Subject: below --
2006-06-03 18:53 zottmann
2006-06-01 11:56 zottmann
2006-06-01 12:04 ` Sietse van Zanen
2006-06-01 12:15   ` Justin Schoeman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox