From: "Tyler J. Wagner" <tyler@tolaris.com>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter@vger.kernel.org
Subject: Re: DisableExternalCache on conntrackd 0.9.14 not syncing to kernel
Date: Wed, 03 Aug 2011 15:15:18 +0100 [thread overview]
Message-ID: <4E3957F6.2050105@tolaris.com> (raw)
In-Reply-To: <4E385AE3.6020801@netfilter.org>
Thank you for your help, Pablo. My comments below.
On 2011-08-02 21:15, Pablo Neira Ayuso wrote:
> You want to inject your flow-state information inmediately, right? In
> that case, you can to explicitly set DisableExternalCache On. Removing
> the DisableExternalCache clause from the config file defaults to off (as
> it shows your config file).
Correct, that's what I want. I'll try the "On" argument instead. The
manual states to use the "Off" argument, albeit in an unclear example:
http://conntrack-tools.netfilter.org/manual.html
Can someone correct it?
> Active/active with asymmetric routing for stateful firewalls is poor
> design for stateful firewalls. I don't recommend it to you. Please read:
> http://1984.lsi.us.es/~pablo/docs/intcomp09.pdf.
I read that white paper. It made fine reading on a recent flight. Thank you.
What I want is not true active/active asymmetric routing. IE, I don't
need state information to propagate ahead of user traffic (thus adding
latency). I just want active/backup, but where both the active and the
backup have each others' state tables in the kernel. This way, if an
asymmetric loop does occur (due to stale ARP data), the traffic will
pass the firewall. If the state data has propagated by that time, of course.
> There are few differences between 0.9.14 and 1.0.0, but I suggest you to
> upgrade to 1.0.0 since you'll benefit from several fixes of minor bugs
> that happened during that period.
I'll attempt to use or repackage 1.0.0 for Ubuntu lucid. If so, I'll
publish it in my PPA. Thanks.
Regards,
Tyler
--
"No one can terrorize a whole nation, unless we are all his accomplices."
-- Edward R. Murrow
prev parent reply other threads:[~2011-08-03 14:15 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-07-28 15:22 DisableExternalCache on conntrackd 0.9.14 not syncing to kernel Tyler J. Wagner
2011-08-02 20:15 ` Pablo Neira Ayuso
2011-08-03 14:15 ` Tyler J. Wagner [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4E3957F6.2050105@tolaris.com \
--to=tyler@tolaris.com \
--cc=netfilter@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox