Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "gerald" <gerald@palmerhouse.net>
To: netfilter@vger.kernel.org
Subject: conntrackd will not accept connection records into kernel table from another machine
Date: Mon, 06 Mar 2017 11:15:04 -0600	[thread overview]
Message-ID: <2602-58bd9900-3-1184bca@164654059> (raw)

https://bugzilla.netfilter.org/show_bug.cgi?id=1123

OS localhost 4.9.8-1-ARCH #1 SMP PREEMPT Mon Feb 6 12:59:40 CET 2017 x86_64 GNU/Linux

conntrackd version 1.4.4
conntrackd gives an error for each remote connction it attempts to add to the local table:
[Thu Feb 16 17:56:27 2017] (pid=1312) [ERROR] inject-add2: Invalid argument
Thu Feb 16 17:56:27 2017 icmp     1 src=192.168.0.15 dst=67.36.196.10 type=8 code=0 id=5486 [UNREPLIED]
[Thu Feb 16 17:56:27 2017] (pid=1312) [ERROR] inject-upd1: Invalid argument
Thu Feb 16 17:56:27 2017 icmp     1 src=192.168.0.15 dst=67.36.196.10 type=8 code=0 id=5486



when
DisableExternalCache On

conntrackd WILL add to external table when the external cache is enabled
but errors with the cache is disabled

with the external cache disabled
entries DO NOT appear in conntrack -L
entries DO NOT appear in conntrackd -e
entries DO NOT appear in conntrackd -i
failures show in conntrackd -s


conntrackd.conf:
Sync {
    Mode FTFW {
        DisableExternalCache On
        CommitTimeout 1800
        PurgeTimeout 5
    }

    UDP {
        IPv4_address 192.168.0.31
        IPv4_Destination_Address 192.168.0.30
        Port 3780
        Interface ens8
        SndSocketBuffer 24985600
        RcvSocketBuffer 24985600
        Checksum on
    }
}

General {
    Nice -20
    HashSize 32768
    HashLimit 131072
    LogFile on
    Syslog on
    LockFile /var/lock/conntrack.lock
    UNIX {
        Path /var/run/conntrackd.ctl
        Backlog 20
    }
    NetlinkBufferSize 2097152
    NetlinkBufferSizeMaxGrowth 8388608
    Filter From Userspace {
        Protocol Accept {
            TCP
            UDP
            ICMP # This requires a Linux kernel >= 2.6.31
        }
        Address Ignore {
            IPv4_address 127.0.0.1 # loopback
            IPv4_address 192.168.0.30
            IPv4_address 192.168.0.31
        }
    }
}

conntrack -c
works and adds entries to the local table when executed

perhaps related to:
http://www.linuxquestions.org/questions/showthread.php?p=5547189#post5547189

             reply	other threads:[~2017-03-06 17:15 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-03-06 17:15 gerald [this message]
2017-03-09 20:32 ` conntrackd will not accept connection records into kernel table from another machine Pablo Neira Ayuso
2017-03-10  9:59   ` Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2602-58bd9900-3-1184bca@164654059 \
    --to=gerald@palmerhouse.net \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox