Re: Dropped inbound packets from stateful allow rule

"Paul B. Henson" <[email protected]> Mon, 19 Apr 2010 18:37:01 -0700 (PDT)
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <2087_1271727530_4BCD05A9_2087_2638_1_Pine.GSO.4.55.1004191834230.28895@loogie.intranet.csupomona.edu>
On Mon, 19 Apr 2010, [iso-8859-2] Saša Nedvědický wrote:

> do you see just log entries for blocked packet?
> or were you able to identify a particular host having problem to reconnect?

It's multiple hosts.

> what I see in log are just single instances of blocked SYN packet,
> which does not render a problem to host to connect to server.

In this case, an NFS client logs that the server is unresponsive, and hangs
for 2-3 minutes before the NFS connection starts to work again.

> 	6531894 IPF blocks TCP SYN packets for connections in TIME_WAIT state

According to that bug report, packets blocked for this scenario would be
logged with OOW, which doesn't appear in my logs for the packets in
question, so I don't think this is applicable.

Thanks though...

-- 
Paul B. Henson  |  (909) 979-6361  |  http://www.csupomona.edu/~henson/
Operating Systems and Network Analyst  |  [email protected]
California State Polytechnic University  |  Pomona CA 91768