* Help with invalid packets.
@ 2012-03-19 15:39 Micheal Wolfskill
2012-03-19 15:58 ` Gáspár Lajos
2012-03-19 17:01 ` Maarten Vanraes
0 siblings, 2 replies; 3+ messages in thread
From: Micheal Wolfskill @ 2012-03-19 15:39 UTC (permalink / raw)
To: netfilter
I have this rule:
$IPT -A INPUT -i ${PUB_IF} -m state --state INVALID -j DROP
The problem is its matching legitimate packets of visitors (including me) that navigate my site... As i can see in the logs.
Its not affecting the normal viewing of my site.. but I wish to know
why it is matching these packets as Iam sure it should not.
Here is the log entry in syslogd
Mar 16 15:29:36 kernel: Invalid IN =eth0 OUT=
MAC=00:16:3e:44:bf:02:00:11:92:8b:ff:c4:08:00 SRC=xxx.xxxx.xxxx.xxxxx DST=xxxx.xxxx.xxxx.xxxx LEN=40
TOS=0x00 PREC=0x00 TTL=47 ID=0 DF PROTO=TCP SPT=6367 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
Thanks
Mike
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Help with invalid packets.
2012-03-19 15:39 Help with invalid packets Micheal Wolfskill
@ 2012-03-19 15:58 ` Gáspár Lajos
2012-03-19 17:01 ` Maarten Vanraes
1 sibling, 0 replies; 3+ messages in thread
From: Gáspár Lajos @ 2012-03-19 15:58 UTC (permalink / raw)
To: Micheal Wolfskill; +Cc: netfilter
Hi,
202-03-19 16:39 keltezéssel, Micheal Wolfskill írta:
> Its not affecting the normal viewing of my site.. but I wish to know
> why it is matching these packets as Iam sure it should not.
Don't be so sure! :D
AFAIK iptables/netfilter uses a different state machine than the TCP
stack in the kernel...
http://userpages.umbc.edu/~jeehye/cmsc491b/lectures/tcpstate/sld001.htm
http://www.lug.or.kr/docs/iptables-tutorial/chunkyhtml/c4219.htm
On this page:
http://www.lug.or.kr/docs/iptables-tutorial/chunkyhtml/x4436.htm
"If the connection is reset by a RST packet, the state is changed to
CLOSE. This means that the connection per default has 10 seconds before
the whole connection is definitely closed down. RST packets are not
acknowledged in any sense, and will break the connection directly."
Maybe that is the source of your problem. Or there may be some timing
issues (lifetime of a connection, etc.)
Swifty
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Help with invalid packets.
2012-03-19 15:39 Help with invalid packets Micheal Wolfskill
2012-03-19 15:58 ` Gáspár Lajos
@ 2012-03-19 17:01 ` Maarten Vanraes
1 sibling, 0 replies; 3+ messages in thread
From: Maarten Vanraes @ 2012-03-19 17:01 UTC (permalink / raw)
To: netfilter; +Cc: Micheal Wolfskill
these days, i often have this problem with L3 switches
the problem is asynchronous routing, because the L3 switch decides to route my
packet directly to the endbox, bypassing the firewall. this happens with
clients who don't use VLANs on the firewall, but use ip aliasing directly.
Regards,
Op maandag 19 maart 2012 16:39:37 schreef Micheal Wolfskill:
> I have this rule:
>
> $IPT -A INPUT -i ${PUB_IF} -m state --state INVALID -j DROP
>
> The problem is its matching legitimate packets of visitors (including me)
> that navigate my site... As i can see in the logs.
>
>
> Its not affecting the normal viewing of my site.. but I wish to know
> why it is matching these packets as Iam sure it should not.
>
> Here is the log entry in syslogd
>
>
> Mar 16 15:29:36 kernel: Invalid IN =eth0 OUT=
> MAC=00:16:3e:44:bf:02:00:11:92:8b:ff:c4:08:00 SRC=xxx.xxxx.xxxx.xxxxx
> DST=xxxx.xxxx.xxxx.xxxx LEN=40 TOS=0x00 PREC=0x00 TTL=47 ID=0 DF PROTO=TCP
> SPT=6367 DPT=80 WINDOW=0 RES=0x00 RST URGP=0
>
> Thanks
>
> Mike --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2012-03-19 17:01 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-03-19 15:39 Help with invalid packets Micheal Wolfskill
2012-03-19 15:58 ` Gáspár Lajos
2012-03-19 17:01 ` Maarten Vanraes
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).