Re: OOW: IPFilter 4.1.8 and pfil 2.1.6 running on Solaris 8

This is a discussion on Re: OOW: IPFilter 4.1.8 and pfil 2.1.6 running on Solaris 8 within the IPFilter forums, part of the System Security and Security Related category; Laurent Blume wrote: > It's not reproduceable per se, but it happens all the time. I'm going to &...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-15-2006
Laurent Blume
 
Posts: n/a
Default Re: OOW: IPFilter 4.1.8 and pfil 2.1.6 running on Solaris 8

Laurent Blume wrote:
> It's not reproduceable per se, but it happens all the time. I'm going to
> get a snoop on both sides this afternoon, and send that direct to you.
> Thanks Darren!


Hmmm, actually, it's now also blocking packets without the OOW flag:

May 15 14:34:39 osiris ipmon[182]: [ID 702911 local0.notice]
14:34:39.042517 e1000g0 @0:17 b 144.204.65.4,44422 -> 144.204.16.1,3128
PR tcp len 20 48 -S IN

I don't get it?

Oh, note that not *all* those connections are blocked, only a fraction.
Since this is a proxy, there's a lot of traffic getting in, and most of
it is working. Sometimes, though, the users get a "Connection refused";
and a retry is enough.

Also, the calling party is also blocking packets (IPF 3.4.33 there):
May 15 14:37:22 onera ipmon[25422]: [ID 702911 local0.notice]
14:37:22.328907 ce0 @200:4 b 144.204.16.1,3128 -> 144.204.65.4,51954 PR
tcp len 20 1500 -AP IN

But the rule blocking them is really a block, and my guess is that the
'keep state' does not work properly because the re are packets already
dropped on the other side.

Hmmm, am I clear there? I'm kinda lost myself with those drops, I've
read and re-read again the rules, they look ok to me. And they work --
most of the time.

Laurent
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:52 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0