netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Help with invalid packets.
@ 2012-03-19 15:39 Micheal Wolfskill
  2012-03-19 15:58 ` Gáspár Lajos
  2012-03-19 17:01 ` Maarten Vanraes
  0 siblings, 2 replies; 3+ messages in thread
From: Micheal Wolfskill @ 2012-03-19 15:39 UTC (permalink / raw)
  To: netfilter


I have this rule:
 
 $IPT  -A INPUT -i ${PUB_IF} -m state --state INVALID -j DROP
 
 The problem is its matching legitimate packets of visitors (including me) that navigate my site... As i can see in the logs.
 

 Its not affecting the normal viewing of my site.. but I wish to know 
why it is matching these packets as Iam sure it should not. 
 
 Here is the log entry in syslogd
 
 
 Mar 16 15:29:36  kernel: Invalid  IN =eth0 OUT=
 MAC=00:16:3e:44:bf:02:00:11:92:8b:ff:c4:08:00 SRC=xxx.xxxx.xxxx.xxxxx DST=xxxx.xxxx.xxxx.xxxx LEN=40
 TOS=0x00 PREC=0x00 TTL=47 ID=0 DF PROTO=TCP SPT=6367 DPT=80 WINDOW=0 RES=0x00 RST URGP=0

Thanks

Mike 		 	   		  

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Help with invalid packets.
  2012-03-19 15:39 Help with invalid packets Micheal Wolfskill
@ 2012-03-19 15:58 ` Gáspár Lajos
  2012-03-19 17:01 ` Maarten Vanraes
  1 sibling, 0 replies; 3+ messages in thread
From: Gáspár Lajos @ 2012-03-19 15:58 UTC (permalink / raw)
  To: Micheal Wolfskill; +Cc: netfilter

Hi,

202-03-19 16:39 keltezéssel, Micheal Wolfskill írta:
> Its not affecting the normal viewing of my site.. but I wish to know
> why it is matching these packets as Iam sure it should not.
Don't be so sure! :D

AFAIK iptables/netfilter uses a different state machine than the TCP 
stack in the kernel...

http://userpages.umbc.edu/~jeehye/cmsc491b/lectures/tcpstate/sld001.htm
http://www.lug.or.kr/docs/iptables-tutorial/chunkyhtml/c4219.htm

On this page: 
http://www.lug.or.kr/docs/iptables-tutorial/chunkyhtml/x4436.htm

"If the connection is reset by a RST packet, the state is changed to 
CLOSE. This means that the connection per default has 10 seconds before 
the whole connection is definitely closed down. RST packets are not 
acknowledged in any sense, and will break the connection directly."

Maybe that is the source of your problem. Or there may be some timing 
issues (lifetime of a connection, etc.)

Swifty

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Help with invalid packets.
  2012-03-19 15:39 Help with invalid packets Micheal Wolfskill
  2012-03-19 15:58 ` Gáspár Lajos
@ 2012-03-19 17:01 ` Maarten Vanraes
  1 sibling, 0 replies; 3+ messages in thread
From: Maarten Vanraes @ 2012-03-19 17:01 UTC (permalink / raw)
  To: netfilter; +Cc: Micheal Wolfskill

these days, i often have this problem with L3 switches

the problem is asynchronous routing, because the L3 switch decides to route my 
packet directly to the endbox, bypassing the firewall. this happens with 
clients who don't use VLANs on the firewall, but use ip aliasing directly.

Regards,

Op maandag 19 maart 2012 16:39:37 schreef Micheal Wolfskill:
> I have this rule:
> 
>  $IPT  -A INPUT -i ${PUB_IF} -m state --state INVALID -j DROP
> 
>  The problem is its matching legitimate packets of visitors (including me)
> that navigate my site... As i can see in the logs.
> 
> 
>  Its not affecting the normal viewing of my site.. but I wish to know
> why it is matching these packets as Iam sure it should not.
> 
>  Here is the log entry in syslogd
> 
> 
>  Mar 16 15:29:36  kernel: Invalid  IN =eth0 OUT=
>  MAC=00:16:3e:44:bf:02:00:11:92:8b:ff:c4:08:00 SRC=xxx.xxxx.xxxx.xxxxx
> DST=xxxx.xxxx.xxxx.xxxx LEN=40 TOS=0x00 PREC=0x00 TTL=47 ID=0 DF PROTO=TCP
> SPT=6367 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
> 
> Thanks
> 
> Mike 		 	   		  --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2012-03-19 17:01 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-03-19 15:39 Help with invalid packets Micheal Wolfskill
2012-03-19 15:58 ` Gáspár Lajos
2012-03-19 17:01 ` Maarten Vanraes

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).