Re: Dropped inbound packets from stateful allow rule
"Paul B. Henson" <[email protected]> Mon, 19 Apr 2010 18:37:01 -0700 (PDT)
| Newsgroups | gmane.comp.security.firewalls.ipfilter |
|---|---|
| Message-ID | <2087_1271727530_4BCD05A9_2087_2638_1_Pine.GSO.4.55.1004191834230.28895@loogie.intranet.csupomona.edu> |
On Mon, 19 Apr 2010, [iso-8859-2] Saša Nedvědický wrote: > do you see just log entries for blocked packet? > or were you able to identify a particular host having problem to reconnect? It's multiple hosts. > what I see in log are just single instances of blocked SYN packet, > which does not render a problem to host to connect to server. In this case, an NFS client logs that the server is unresponsive, and hangs for 2-3 minutes before the NFS connection starts to work again. > 6531894 IPF blocks TCP SYN packets for connections in TIME_WAIT state According to that bug report, packets blocked for this scenario would be logged with OOW, which doesn't appear in my logs for the packets in question, so I don't think this is applicable. Thanks though... -- Paul B. Henson | (909) 979-6361 | http://www.csupomona.edu/~henson/ Operating Systems and Network Analyst | [email protected] California State Polytechnic University | Pomona CA 91768