Linux Netfilter discussions
 help / color / mirror / Atom feed
* Conntrack helper problems (patch-o-matic-20030107)
@ 2003-02-27 16:16 Robert Allmeroth
  2003-02-27 16:54 ` Justin Piszcz
  2003-02-27 22:35 ` Filip Sneppe (Cronos)
  0 siblings, 2 replies; 4+ messages in thread
From: Robert Allmeroth @ 2003-02-27 16:16 UTC (permalink / raw)
  To: netfilter

hello,

I try to get a kernel 2.4.18 with patch-o-matic-20030107 running.
But i have some problems with the conntrack helpers. They simply
don't work .. *sigh*

i tried ftp, irc and h323. I compiled as module and kernel included,
same result..

normal masqerade works, i can do passive FTP, irc, http, normal stateful
inspection, etc..

i hope anybody can help me..

-------------

here is what i have / see:

FTP conntrack problem:
bash-2.05# cat /proc/net/ip_conntrack
tcp      6 431573 ESTABLISHED src=172.30.255.1 dst=10.20.0.17 sport=1572 dport=21 src=10.20.0.17 dst=10.20.10.197 sport=21
dport=1572 [ASSURED] use=1
EXPECTING: - use=1 proto=6 src=10.20.0.17 dst=10.20.10.197 sport=0 dport=1573

The sport=0 seems wrong to me..

my system:

bash-2.05# iptables -vnL PreStateful
Chain PreStateful (3 references)
 pkts bytes target     prot opt in     out     source               destination

  259 66567 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0
     state RELATED,ESTABLISHED
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
     state INVALID
    0     0 DROP       all  --  eth1   *       0.0.0.0/0            0.0.0.0/0

bash-2.05# iptables -vnL -t nat
Chain PREROUTING (policy ACCEPT 476 packets, 60290 bytes)
 pkts bytes target     prot opt in     out     source               destination

Chain POSTROUTING (policy ACCEPT 3 packets, 447 bytes)
 pkts bytes target     prot opt in     out     source               destination

   24 13346 MASQUERADE  all  --  *      eth1    0.0.0.0/0            0.0.0.0/0

Chain OUTPUT (policy ACCEPT 7 packets, 1028 bytes)
 pkts bytes target     prot opt in     out     source               destination


Already applied: submitted/01_2.4.19
                 submitted/02_2.4.20
                 submitted/ipt_ULOG-mac_len-fix
                 submitted/ipt_multiport-invfix
                 pending/01_ip_conntrack_proto_tcp-lockfix
                 pending/02_newnat-udp-helper
                 pending/03_REJECT-fwspotting-phrack60-fix
                 pending/04_ftp-conntrack-msg-fix
                 pending/05_ECN-tcpchecksum-littleendian-fix
                 base/IPV4OPTSSTRIP
                 base/mport
                 base/psd
                 extra/eggdrop-conntrack
                 extra/h323-conntrack-nat
                 extra/ip_tables-proc
                 extra/mms-conntrack-nat
                 extra/pptp-conntrack-nat
                 extra/quake3-conntrack
                 extra/string

bash-2.05# cat /proc/net/ip_tables_matches
tcpmss
string
unclean
conntrack
state
ttl
length
esp
ah
dscp
ecn
psd
tos
owner
mport
multiport
pkttype
mac
mark
limit
helper
tcp
udp
icmp

bash-2.05# cat /proc/net/ip_tables_targets
TCPMSS
ULOG
IPV4OPTSSTRIP
LOG
REDIRECT
MASQUERADE
MARK
DSCP
ECN
TOS
MIRROR
REJECT
DNAT
SNAT

ERROR

best regards
  Robert

------------------
Epygi Labs DE           |  Herrenstrafle 23
Robert Allmeroth        |  76133 Karlsruhe
Tel: +49 721 20596 43   |  Fax: +49 721 20596 59



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Conntrack helper problems (patch-o-matic-20030107)
  2003-02-27 16:16 Conntrack helper problems (patch-o-matic-20030107) Robert Allmeroth
@ 2003-02-27 16:54 ` Justin Piszcz
  2003-02-27 22:35 ` Filip Sneppe (Cronos)
  1 sibling, 0 replies; 4+ messages in thread
From: Justin Piszcz @ 2003-02-27 16:54 UTC (permalink / raw)
  To: netfilter

I am using 2.4.20 with all 3, working flawless, using netmeeting to talk 
to family memebers from behind nat works great.

Try 2.4.20 + patch-o-matic latest for h323, and make sure your firewall 
rules are setup correctly.

Robert Allmeroth wrote:

>hello,
>
>I try to get a kernel 2.4.18 with patch-o-matic-20030107 running.
>But i have some problems with the conntrack helpers. They simply
>don't work .. *sigh*
>
>i tried ftp, irc and h323. I compiled as module and kernel included,
>same result..
>
>normal masqerade works, i can do passive FTP, irc, http, normal stateful
>inspection, etc..
>
>i hope anybody can help me..
>
>-------------
>
>here is what i have / see:
>
>FTP conntrack problem:
>bash-2.05# cat /proc/net/ip_conntrack
>tcp      6 431573 ESTABLISHED src=172.30.255.1 dst=10.20.0.17 sport=1572 dport=21 src=10.20.0.17 dst=10.20.10.197 sport=21
>dport=1572 [ASSURED] use=1
>EXPECTING: - use=1 proto=6 src=10.20.0.17 dst=10.20.10.197 sport=0 dport=1573
>
>The sport=0 seems wrong to me..
>
>my system:
>
>bash-2.05# iptables -vnL PreStateful
>Chain PreStateful (3 references)
> pkts bytes target     prot opt in     out     source               destination
>
>  259 66567 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0
>     state RELATED,ESTABLISHED
>    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>     state INVALID
>    0     0 DROP       all  --  eth1   *       0.0.0.0/0            0.0.0.0/0
>
>bash-2.05# iptables -vnL -t nat
>Chain PREROUTING (policy ACCEPT 476 packets, 60290 bytes)
> pkts bytes target     prot opt in     out     source               destination
>
>Chain POSTROUTING (policy ACCEPT 3 packets, 447 bytes)
> pkts bytes target     prot opt in     out     source               destination
>
>   24 13346 MASQUERADE  all  --  *      eth1    0.0.0.0/0            0.0.0.0/0
>
>Chain OUTPUT (policy ACCEPT 7 packets, 1028 bytes)
> pkts bytes target     prot opt in     out     source               destination
>
>
>Already applied: submitted/01_2.4.19
>                 submitted/02_2.4.20
>                 submitted/ipt_ULOG-mac_len-fix
>                 submitted/ipt_multiport-invfix
>                 pending/01_ip_conntrack_proto_tcp-lockfix
>                 pending/02_newnat-udp-helper
>                 pending/03_REJECT-fwspotting-phrack60-fix
>                 pending/04_ftp-conntrack-msg-fix
>                 pending/05_ECN-tcpchecksum-littleendian-fix
>                 base/IPV4OPTSSTRIP
>                 base/mport
>                 base/psd
>                 extra/eggdrop-conntrack
>                 extra/h323-conntrack-nat
>                 extra/ip_tables-proc
>                 extra/mms-conntrack-nat
>                 extra/pptp-conntrack-nat
>                 extra/quake3-conntrack
>                 extra/string
>
>bash-2.05# cat /proc/net/ip_tables_matches
>tcpmss
>string
>unclean
>conntrack
>state
>ttl
>length
>esp
>ah
>dscp
>ecn
>psd
>tos
>owner
>mport
>multiport
>pkttype
>mac
>mark
>limit
>helper
>tcp
>udp
>icmp
>
>bash-2.05# cat /proc/net/ip_tables_targets
>TCPMSS
>ULOG
>IPV4OPTSSTRIP
>LOG
>REDIRECT
>MASQUERADE
>MARK
>DSCP
>ECN
>TOS
>MIRROR
>REJECT
>DNAT
>SNAT
>
>ERROR
>
>best regards
>  Robert
>
>------------------
>Epygi Labs DE           |  Herrenstraße 23
>Robert Allmeroth        |  76133 Karlsruhe
>Tel: +49 721 20596 43   |  Fax: +49 721 20596 59
>
>
>
>
>  
>




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Conntrack helper problems (patch-o-matic-20030107)
  2003-02-27 16:16 Conntrack helper problems (patch-o-matic-20030107) Robert Allmeroth
  2003-02-27 16:54 ` Justin Piszcz
@ 2003-02-27 22:35 ` Filip Sneppe (Cronos)
  1 sibling, 0 replies; 4+ messages in thread
From: Filip Sneppe (Cronos) @ 2003-02-27 22:35 UTC (permalink / raw)
  To: Robert Allmeroth; +Cc: netfilter

On Thu, 2003-02-27 at 17:16, Robert Allmeroth wrote:
> 
> here is what i have / see:
> 
> FTP conntrack problem:
> bash-2.05# cat /proc/net/ip_conntrack
> tcp      6 431573 ESTABLISHED src=172.30.255.1 dst=10.20.0.17 sport=1572 dport=21 src=10.20.0.17 dst=10.20.10.197 sport=21
> dport=1572 [ASSURED] use=1
> EXPECTING: - use=1 proto=6 src=10.20.0.17 dst=10.20.10.197 sport=0 dport=1573
> 
> The sport=0 seems wrong to me..
> 
Hi Robert,

It's not necessarily wrong. Basically a conntrack helper 
will tell connection tracking what connection to expect 
based on IP/TCP header and packet payload info from the 
"master" connection.

Often, it will get both IP addresses, plus one port
(destination port is the obvious candidate). With this
info, the expectation will be set up. The other port
is "random" (ie. picked by the client) and can't 
really be predicted. 

When a conntrack helper sets up an expecation, it
fills in the necessary values and also uses a mask
to point out the relevant info.

The sport=0 here basically means "any port" and is
probably the result of the mask being set to 0 for
the sport of the expectation.

About your problem, are all relevant conntrack + nat
modules loaded (check with lsmod) ?

Regards,
Filip



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Conntrack helper problems (patch-o-matic-20030107)
@ 2003-02-27 22:38 Robert Allmeroth
  0 siblings, 0 replies; 4+ messages in thread
From: Robert Allmeroth @ 2003-02-27 22:38 UTC (permalink / raw)
  To: netfilter

rehi :)

> On Thu, 2003-02-27 at 17:16, Robert Allmeroth wrote:
>>
>> here is what i have / see:
>>
>> FTP conntrack problem:
>> bash-2.05# cat /proc/net/ip_conntrack
>> tcp      6 431573 ESTABLISHED src=172.30.255.1 dst=10.20.0.17 sport=1572 dport=21 src=10.20.0.17 dst=10.20.10.197 sport=21
>> dport=1572 [ASSURED] use=1
>> EXPECTING: - use=1 proto=6 src=10.20.0.17 dst=10.20.10.197 sport=0 dport=1573
>>
>> The sport=0 seems wrong to me..
>>
> Hi Robert,

> It's not necessarily wrong. Basically a conntrack helper
> will tell connection tracking what connection to expect
> based on IP/TCP header and packet payload info from the
> "master" connection.

> Often, it will get both IP addresses, plus one port
> (destination port is the obvious candidate). With this
> info, the expectation will be set up. The other port
> is "random" (ie. picked by the client) and can't
> really be predicted.

> When a conntrack helper sets up an expecation, it
> fills in the necessary values and also uses a mask
> to point out the relevant info.

> The sport=0 here basically means "any port" and is
> probably the result of the mask being set to 0 for
> the sport of the expectation.

ok.. got it.. :-)

> About your problem, are all relevant conntrack + nat
> modules loaded (check with lsmod) ?

here it is.. everything not listed in the modules dir is
compiled into the kernel..

bash-2.05# lsmod
Module                  Size  Used by
ip_nat_h323             3872   0  (unused)
ip_conntrack_h323       3632   1  [ip_nat_h323]
ip_nat_irc              3792   0  (unused)
ip_conntrack_irc        4336   1  [ip_nat_irc]
ip_nat_ftp              4896   0  (unused)
ip_conntrack_ftp        5472   1  [ip_nat_ftp]

bash-2.05# ls -al /lib/modules/2.4.18/kernel/net/ipv4/netfilter/               
-rw-------    1 0        0          184508 Jan  1  1970 ip_conntrack_egg.o
-rw-------    1 0        0          190900 Jan  1  1970 ip_conntrack_ftp.o
-rw-------    1 0        0          187412 Jan  1  1970 ip_conntrack_h323.o
-rw-------    1 0        0          187672 Jan  1  1970 ip_conntrack_irc.o
-rw-------    1 0        0          188176 Jan  1  1970 ip_conntrack_mms.o
-rw-------    1 0        0          187912 Jan  1  1970 ip_conntrack_pptp.o
-rw-------    1 0        0          147400 Jan  1  1970 ip_conntrack_proto_gre.o
-rw-------    1 0        0          138068 Jan  1  1970 ip_conntrack_quake3.o
-rw-------    1 0        0          191184 Jan  1  1970 ip_nat_ftp.o
-rw-------    1 0        0          191496 Jan  1  1970 ip_nat_h323.o
-rw-------    1 0        0          188216 Jan  1  1970 ip_nat_irc.o
-rw-------    1 0        0          189364 Jan  1  1970 ip_nat_mms.o
-rw-------    1 0        0          188972 Jan  1  1970 ip_nat_pptp.o
-rw-------    1 0        0          139188 Jan  1  1970 ip_nat_proto_gre.o
-rw-------    1 0        0          139372 Jan  1  1970 ip_nat_quake3.o

--------

i also checked again an old software version with 2.4.18 and iptables-1.2.5 with
everything compiled into the kernel.. in that version everything worked fine.
except h323 and pptp ;-) these two modules are the reason why i do all that :)

we cannot simply go to a kernel version > 2.4.18. Its an embedded system (PPC) with
many self programmed addons.. *sigh*.. 

regards
  Robert




^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-02-27 22:38 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-02-27 16:16 Conntrack helper problems (patch-o-matic-20030107) Robert Allmeroth
2003-02-27 16:54 ` Justin Piszcz
2003-02-27 22:35 ` Filip Sneppe (Cronos)
  -- strict thread matches above, loose matches on Subject: below --
2003-02-27 22:38 Robert Allmeroth

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox