From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
To: netfilter@vger.kernel.org
Cc: Jan Engelhardt <jengelh@medozas.de>,
"Dennis J." <dennisml@conversis.de>,
pablo@netfilter.org
Subject: Re: Synflood filtering and Conntrack
Date: Thu, 29 Jul 2010 14:34:33 +0200 [thread overview]
Message-ID: <4C517559.2030702@plouf.fr.eu.org> (raw)
In-Reply-To: <4C516687.6060602@chello.at>
Mart Frauenlob a écrit :
> On 29.07.2010 13:21, Jan Engelhardt wrote:
>>
>> # iptables -I INPUT -p tcp --dport 23 -j DROP
>> # conntrack -E& telnet localhost 23
>> [1] 6949
>> Trying ::1...
>> telnet: connect to address ::1: Connection refused
>
> refused? on DROP?
> my nc does show a timeout.
That's the IPv6 connection attempt. The Telnet server does not appear to
listen on IPv6, so the connection is refused.
>> Trying 127.0.0.1...
>> [NEW] tcp 6 120 SYN_SENT src=127.0.0.1 dst=127.0.0.1
>> sport=59734 dport=23 [UNREPLIED] src=127.0.0.1 dst=127.0.0.1 sport=23
>> dport=59734
>>
>> ...seconds later...
>> # conntrack -L | grep =23
>> conntrack v0.9.14 (conntrack-tools): 12 flow entries have been shown.
>> tcp 6 97 SYN_SENT src=127.0.0.1 dst=127.0.0.1 sport=59734
>> dport=23 packets=1 bytes=60 [UNREPLIED] src=127.0.0.1 dst=127.0.0.1
>> sport=23 dport=59734 packets=0 bytes=0 mark=0 secmark=0 use=2
>>
>> 2 minutes it is.
That's because it is a locally generated connection, so the conntrack
confirm takes place after POSTROUTING. Even though the packet is dropped
in INPUT after it is looped back, the conntrack entry is already
confirmed. Now try again with the DROP rule in OUTPUT, or from a remote
host.
> oh, well exactly what I did.
Probably not exactly.
next prev parent reply other threads:[~2010-07-29 12:34 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-07-27 22:29 Synflood filtering and Conntrack Dennis J.
2010-07-28 5:24 ` Mart Frauenlob
2010-07-28 6:11 ` Jan Engelhardt
2010-07-28 13:30 ` Pascal Hambourg
2010-07-28 14:10 ` Jan Engelhardt
2010-07-28 14:27 ` Pascal Hambourg
2010-07-29 11:11 ` Mart Frauenlob
2010-07-29 11:21 ` Jan Engelhardt
2010-07-29 11:31 ` Mart Frauenlob
2010-07-29 12:34 ` Pascal Hambourg [this message]
2010-07-29 12:49 ` Jan Engelhardt
2010-07-29 13:16 ` Pascal Hambourg
2010-07-29 15:50 ` Jozsef Kadlecsik
2010-07-29 17:14 ` Gáspár Lajos
2010-07-29 17:52 ` Jozsef Kadlecsik
2010-07-29 22:18 ` Mart Frauenlob
2010-07-29 23:19 ` Pascal Hambourg
2010-07-30 10:32 ` Jozsef Kadlecsik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4C517559.2030702@plouf.fr.eu.org \
--to=pascal.mail@plouf.fr.eu.org \
--cc=dennisml@conversis.de \
--cc=jengelh@medozas.de \
--cc=netfilter@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox