Linux Netfilter discussions
 help / color / mirror / Atom feed
* sequence numbers in conntrack
@ 2010-01-09 21:12 Nemeth Denes
  2010-01-10  4:10 ` vishesh
  0 siblings, 1 reply; 4+ messages in thread
From: Nemeth Denes @ 2010-01-09 21:12 UTC (permalink / raw)
  To: netfilter

Hello,

Could someone help me to explain what does the conntack module do
in TCP connection negotiation in the following three cases: (host N is
behind the NAT and host P is on the other side of the NAT)

A:
P sends a SYN to H and H replies with an SYN-ACK with an invalid
sequence number (If this passes normally through is it possible to
filter it out?)

B:
P sends a SYN to H and H replies with non SYN-ACK (3-way-handshake)
or SYN (TCP simultaneous open) package

C: If the "--random" option is given to the postrouting chain, what happens
if the clients use up all the ports?

Many thanks,
Denes Nemeth



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-01-10 11:03 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-01-09 21:12 sequence numbers in conntrack Nemeth Denes
2010-01-10  4:10 ` vishesh
2010-01-10 10:06   ` Nemeth Denes
2010-01-10 11:03     ` Nemeth Denes

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox