Re: ipfilter vs nintendo DS

This is a discussion on Re: ipfilter vs nintendo DS within the IPFilter forums, part of the System Security and Security Related category; --0-1349544151-1170078339=:84770 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit > > pass in ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-29-2007
David Hough running ipfilt
 
Posts: n/a
Default Re: ipfilter vs nintendo DS

--0-1349544151-1170078339=:84770
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit

> > pass in log quick proto tcp from any port =3D 80 to 10.0.2.0/24 port >
> > 1023 group
> > 100
> > pass out log quick proto tcp from any port =3D 80 to 10.0.2.0/24 port >=

>
> > 1023 group 151
> > pass in log quick proto tcp from 10.0.2.0/24 port > 1023 to any port =3D=

>
> > 80 group
> > 101
> > pass out log quick proto tcp from 10.0.2.0/24 port > 1023 to any port =

> =3D
> > 80 group 150

>
> This is normal HTTP traffic. I suspect if you add keep state to the last =
> two
> rules you shouldn't need the first two.


There were already normal rules in place:

pass in quick proto tcp from 10.0.2.0/24 to any port = 80 flags S keep state group 101
pass out quick proto tcp from 10.0.2.0/24 to any port = 80 flags S keep state group 150
pass out quick proto tcp from 10.0.2.0/24 to any port = 80 flags S keep state group 151


That sufficed for all normal http connections. The nintendo connection
failed because the website it was contacting responded with flags AS e.g.:

#27/01/2007 22:52:42.230327 dmfe1 @100:19 b 209.67.106.140,80 -> 10.0.2.90,4854 PR tcp len 20 44 -AS IN

So I infer that nintendo's external websites act a little oddly too.
Putting on a keep state rule for that connection didn't work, because then
I would get something like

#27/01/2007 23:07:49.089695 dmfe0 @101:32 b 10.0.2.90,4646 -> 209.67.106.140,80 PR tcp len 20 110 -AP IN

So I came to the conclusion that nintendo didn't have the same ideas about
TCP state as ipfilter. It's probably not worth debugging much further since
several colleges seem to have already tried and given up - but I thought
I would check with the list to see if anybody else had tried to get it to work
with ipfilter.




--0-1349544151-1170078339=:84770
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: 8bit

&gt; &gt; pass in log quick proto tcp from any port =3D 80 to 10.0.2.0/24 port &gt;<br>&gt; &gt; 1023 group<br>&gt; &gt; 100<br>&gt; &gt; pass out log quick proto tcp from any port =3D 80 to 10.0.2.0/24 port &gt;=<br>&gt;<br>&gt; &gt; 1023 group 151<br>&gt; &gt; pass in log quick proto tcp from 10.0.2.0/24 port &gt; 1023 to any port =3D=<br>&gt;<br>&gt; &gt; 80 group<br>&gt; &gt; 101<br>&gt; &gt; pass out log quick proto tcp from&nbsp; 10.0.2.0/24 port &gt; 1023 to any port =<br>&gt; =3D<br>&gt; &gt; 80 group 150<br>&gt;<br>&gt; This is normal HTTP traffic. I suspect if you add keep state to the last =<br>&gt; two<br>&gt; rules you shouldn't need the first two.<br>&nbsp;<br>There were already normal rules in place:<br>&nbsp;<br>pass in&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; quick proto tcp from 10.0.2.0/24 to any port = 80 flags S keep state group 101<br>pass out&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ;&nbsp;&nbsp; quick proto tcp from
10.0.2.0/24 to any port = 80 flags S keep state group 150 <br>pass out&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp ;&nbsp;&nbsp; quick proto tcp from 10.0.2.0/24 to any port = 80 flags S keep state group 151 <br>&nbsp;<br><br>That sufficed for all normal http connections.&nbsp;&nbsp;&nbsp; The nintendo connection<br>failed because the website it was contacting responded with flags AS e.g.:<br>&nbsp;<br>#27/01/2007 22:52:42.230327 dmfe1 @100:19 b 209.67.106.140,80 -&gt; 10.0.2.90,4854 PR tcp len 20 44 -AS IN<br>&nbsp;<br>So I infer that nintendo's external websites act a little oddly too.<br>Putting on a keep state rule for that connection didn't work, because then<br>I would get something like<br>&nbsp;<br>#27/01/2007 23:07:49.089695 dmfe0 @101:32 b 10.0.2.90,4646 -&gt; 209.67.106.140,80 PR tcp len 20 110 -AP IN<br>&nbsp;<br>So I came to the conclusion that nintendo didn't have the same ideas about<br>TCP state as ipfilter.&nbsp;&nbsp;&nbsp;&nbsp; It's probably not worth
debugging much further since<br>several colleges seem to have already tried and given up - but I thought<br>I would check with the list to see if anybody else had tried to get it to work<br>with ipfilter.<br><br><br><br>
--0-1349544151-1170078339=:84770--
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:49 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0