keep state and mac address

This is a discussion on keep state and mac address within the IPFilter forums, part of the System Security and Security Related category; Does anyone know if the mac address is used in the keep state part of a tcp connection? I have ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-22-2005
Atoms for Peace
 
Posts: n/a
Default keep state and mac address

Does anyone know if the mac address is used in the keep state part of a tcp connection?

I have a rule on a Solaris 10 box using ipfilter 4.0.2 (comes with sol10) that looks like this:

block in log all
block out log all
pass in quick on hme0 log proto tcp from any to MYIP port = 22 keep state

That's it. I can connect from one host on the network but not from another. When I watch ipmon from the good host I see a keep state entry being created. From the other host I do not. I instead see the pass on the K-S rule for the S packet, but the SA packet is being blocked by the block out entry. ipfilter did not establish an entry in the state table.

The only difference I can see between the two hosts is when watching snoop. From the good host, I see the SRC mac address of the gateway router/switch. But when I snoop the bad host, I see a mac address that I have not yet found on my network. (I don't run the network gear so this will take time) So I get a packet with a SRC MAC not of the default gateway.

The state table has 5 entries in it (not full), I've flushed and restarted many times, ipstat -io shows just the 3 rules, and nothing else seems unusual.

Anyone know if the mac address matters or have other ideas to check?

Thanks!

Jim


__________________________________________________ ________________
Switch to Netscape Internet Service.
As low as $9.95 a month -- Sign up today at http://isp.netscape.com/register

Netscape. Just the Net You Need.

New! Netscape Toolbar for Internet Explorer
Search from anywhere on the Web and block those annoying pop-ups.
Download now at http://channels.netscape.com/ns/search/install.jsp
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:38 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0