Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Luis Miguel Cruz <luismi@b2bi.es>
To: netfilter@lists.netfilter.org
Subject: Re: unclean rule
Date: Fri, 11 Jun 2004 15:09:43 +0200	[thread overview]
Message-ID: <40C9AF17.9010805@b2bi.es> (raw)
In-Reply-To: <20040611144930.70596784.grisha@unixro.net>

Yes, I have it.
But  I want to know why is the reason of the unclean module to drop ftp 
packets for this client :P

My rules are:
$IPT -A SEGURIDAD -m unclean -j LOG --log-prefix "Paquete Unclean: " 
--log-ip-options --log-tcp-options --log-tcp-sequence
$IPT -A SEGURIDAD -m unclean -j DROP


Raileanu Grigore wrote:

> On Fri, 11 Jun 2004 13:35:42 +0200
> Luis Miguel Cruz <luismi@b2bi.es> wrote:
> 
> 
>>I asked it because I remember that in the past this module have a lot of 
>>problems, I like to know if those problems are solved now.
>>
>>I have a problem with a client, he can´t do a ftp to our servers :P
>>The traffic match unclean rule:
>>
>>iptables -A SEGURIDAD -m unclean -j DROP
>>
>>All traffic must across SEGURIDAD chain, I only have problems with ftp 
>>service and this client, the rest of the services runs perfectly for him.
>>
>>What can be wrong? the client´s adsl router? :P
>>
>>
>>Raileanu Grigore wrote:
>>
>>
>>>On Fri, 11 Jun 2004 13:07:37 +0200
>>>Luis Miguel Cruz <luismi@b2bi.es> wrote:
>>>
>>>
>>>
>>>>Is safe to use unclean module?
>>>>
>>>>--
>>>>Luis Miguel Cruz
>>>>
>>>>
>>>
>>>
>>>Yes, you can discard without any problems unclean packets.
>>>
>>
>>
> 
> Try to add in your firewall logging rules, and you can see, which packets are rejected by firewall.
> 


  reply	other threads:[~2004-06-11 13:09 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-06-11 11:07 unclean rule Luis Miguel Cruz
2004-06-11 11:26 ` Raileanu Grigore
2004-06-11 11:35   ` Luis Miguel Cruz
2004-06-11 11:49     ` Raileanu Grigore
2004-06-11 13:09       ` Luis Miguel Cruz [this message]
     [not found] <MAIL-SRV-02XBt7hJpu00020353@mail-srv-02.lsinter.net>
2004-06-11 12:07 ` Luis Miguel Cruz

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=40C9AF17.9010805@b2bi.es \
    --to=luismi@b2bi.es \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox