Linux Netfilter discussions
 help / color / mirror / Atom feed
* Ping in ESTABLISHED
@ 2008-12-06 18:25 Gilad Benjamini
  2008-12-07 10:56 ` Christoph Paasch
  0 siblings, 1 reply; 4+ messages in thread
From: Gilad Benjamini @ 2008-12-06 18:25 UTC (permalink / raw)
  To: netfilter

I have a situation where a continuous ping, expected to create a new
connection each time, turns into a single connection in ESTABLISHED state

Here are the details:
- iptables runs on a bridge
- The bridge connects eth1 and eth2
- The iptables rules (minimized for the sake of this post)
    -A FORWARD -p icmp -m physdev  --physdev-in eth1 --physdev-is-bridged -j
ACCEPT
    -A FORWARD -p icmp -m state --state ESTABLISHED -j ACCEPT
    -A FORWARD -p icmp -m state --state NEW -j ACCEPT
    -A FORWARD -j ACCEPT
- A machine located on the eth2 network constantly sends a ping to a machine
located in eth1 network
- "iptables -L -v" shows the counters growing on rules #1 and #3. This is
expected.
- However, at some point, the counters start increasing on rule #2, and stop
increasing on rule #3. This can happen after 200 pings, 400, or even 3000 in
one overnight test.

Any idea what's going on ?



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2008-12-07 17:10 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-12-06 18:25 Ping in ESTABLISHED Gilad Benjamini
2008-12-07 10:56 ` Christoph Paasch
2008-12-07 16:42   ` Gilad Benjamini
2008-12-07 17:10     ` Christoph Paasch

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox