Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Michael Schwartzkopff <misch@multinet.de>
To: netfilter@vger.kernel.org
Subject: Problem with conntrackd: TCP RST sent on NAT connections
Date: Fri, 20 Feb 2009 13:34:34 +0100	[thread overview]
Message-ID: <200902201334.34830.misch@multinet.de> (raw)

Hi,

I have a strange problem here. I set up a testbed like in the on on the 
website, except that I have NAT im my scenario.

When I test a SSH connection everything goes fine.

When I download a file via HTTP the first failover works, but the failback 
breaks the connection and the download stops. Tracing the connection show that 
during the failback the HTTP Server sends a package to the virtual NAT address 
of my firewall and the firewall send a TCP RST back and thus stops the 
connection.

Of course I tried first to sync the connection table and after that set up my 
virtual addresses, but it seems that it does not help.

A similar problem was described from Abhijit Menon-Sen on Oct, 30th 2007 on 
the nf-failover mailing list. But I did not find any solution there.

My system:
debian lenny.
Kernel 2.6.26-1-686
conntrackd version 0.9.6-4

Mode: FTFW, heartbeat as HA solution.

My firewall does allow everything. The only rule is the NAT rule that translats 
all packets comming from internal to the virtual external address.

Any idea what could be wrong? How could I trace the problem further? Thanks 
for any help.

-- 
Dr. Michael Schwartzkopff
MultiNET Services GmbH
Addresse: Bretonischer Ring 7; 85630 Grasbrunn; Germany
Tel: +49 - 89 - 45 69 11 0
Fax: +49 - 89 - 45 69 11 21
mob: +49 - 174 - 343 28 75

mail: misch@multinet.de
web: www.multinet.de

Sitz der Gesellschaft: 85630 Grasbrunn
Registergericht: Amtsgericht München HRB 114375
Geschäftsführer: Günter Jurgeneit, Hubert Martens

---

PGP Fingerprint: F919 3919 FF12 ED5A 2801 DEA6 AA77 57A4 EDD8 979B
Skype: misch42

             reply	other threads:[~2009-02-20 12:34 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-02-20 12:34 Michael Schwartzkopff [this message]
2009-02-20 16:49 ` Problem with conntrackd: TCP RST sent on NAT connections Pablo Neira Ayuso
  -- strict thread matches above, loose matches on Subject: below --
2009-02-23 20:34 Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200902201334.34830.misch@multinet.de \
    --to=misch@multinet.de \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox