Linux Netfilter discussions
 help / color / mirror / Atom feed
* Iptables find invalid packets
@ 2008-07-21 12:20 Dimitri GOURDON
  2008-07-21 12:58 ` Bernhard Bock
  2008-07-21 13:06 ` Vladislav Kurz
  0 siblings, 2 replies; 10+ messages in thread
From: Dimitri GOURDON @ 2008-07-21 12:20 UTC (permalink / raw)
  To: netfilter

Hi all,

I've setup LVS on a box using Keepalived (and Iptables) to load balance 
traffic between 2 web servers. I have a problem :

A lot of TCP packets with FIN or RST flags (all I think) from clients 
are dropped by Iptables as state INVALID. The consequence is that I have 
a lot of connection in FIN_WAIT state (shown by netstat) on the 2 web 
servers...

I have reproduced this on my lab...

I have sniff packets with tcpdump to see flags, ACK number,... I've 
found nothing bad.

I have tried to accept these packets with Iptables and then, all my 
connections are terminated in a normal way (only 1-2 connection(s) stay 
in FIN_WAIT on web servers).

I know I can play with TCP timeout to reduce this behavior, but I'll 
prefer correct the problem. I don't understand why these packets are 
invalid if when I accept them, the connections end normaly...

Google is NOT my friend on this issue.

Is someone can help me ???

Dimitri Gourdon
Linux Web Administrator
Itool systems

PS : Sorry for my poor english !

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2008-07-21 16:02 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-07-21 12:20 Iptables find invalid packets Dimitri GOURDON
2008-07-21 12:58 ` Bernhard Bock
2008-07-21 13:23   ` Dimitri GOURDON
     [not found]   ` <48849E47.30901@itool.com>
2008-07-21 14:39     ` Bernhard Bock
2008-07-21 15:01       ` Dimitri GOURDON
2008-07-21 15:44       ` Dimitri GOURDON
2008-07-21 16:02         ` Bernhard Bock
2008-07-21 13:06 ` Vladislav Kurz
     [not found]   ` <48849F8F.70103@itool.com>
2008-07-21 14:49     ` Vladislav Kurz
     [not found]       ` <4884A414.10408@itool.com>
2008-07-21 15:11         ` Vladislav Kurz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox