Kernel 2.6.21.7 ipv6 module filtering bypass
"Darren Lissimore" <[email protected]> Thu, 24 Jan 2008 11:28:27 -0800
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
--===============0310028468==
Content-Type: multipart/alternative;
boundary="----=_Part_26857_15212347.1201202907092"
------=_Part_26857_15212347.1201202907092
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hey All;
I've got a curious problem.
I'm using a 2.6.21.7 kernel on a transparent bridge. With the following
ebtables rules;
ebtables -t filter -A OUTPUT -p IPv6 -j DROP
ebtables -t nat -A POSTROUTING -p IPv6 -j DROP
If I then modprobe the kernel's ipv6 module, the following trace is
observed going out both ports:
10:54:04.548138 IP6 (hlim 1, next-header: Options (0), length: 36) :: >
ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast
listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea
to_ex { }]
10:54:04.859729 IP6 (hlim 1, next-header: Options (0), length: 36) :: >
ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast
listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea
to_ex { }]
10:54:04.888188 IP6 (hlim 255, next-header: ICMPv6 (58), length: 24) :: >
ff02::1:ff04:63ea: [icmp6 sum ok] ICMP6, neighbor solicitation, length 24,
who has fe80::280:66ff:fe04:63ea
10:54:05.888334 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16)
fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router
solicitation, length 16
source link-address option (1), length 8 (1): 00:01:29:D4:BD:8B
0x0000: 0080 6604 63ea
10:54:09.888345 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16)
fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router
solicitation, length 16
source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C
0x0000: 0080 6604 63ea
10:54:13.888495 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16)
fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router
solicitation, length 16
source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C
0x0000: 0080 6604 63ea
Is there any way to prevent these ipv6 packets being generated and
by-passing the filtering ?
Darren
------=_Part_26857_15212347.1201202907092
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hey All;<br><br>I've got a curious problem. <br>I'm using a <a href="http://2.6.21.7">2.6.21.7</a> kernel on a transparent bridge. With the following ebtables rules;<br><br> ebtables -t filter -A OUTPUT -p IPv6 -j DROP
<br> ebtables -t nat -A POSTROUTING -p IPv6 -j DROP<br><br><br>If I then modprobe the kernel's ipv6 module, the following trace is observed going out both ports:<br><br><br>10:54:04.548138 IP6 (hlim 1, next-header: Options (0), length: 36) :: > ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea to_ex { }]
<br>10:54:04.859729 IP6 (hlim 1, next-header: Options (0), length: 36) :: > ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea to_ex { }]
<br>10:54:04.888188 IP6 (hlim 255, next-header: ICMPv6 (58), length: 24) :: > ff02::1:ff04:63ea: [icmp6 sum ok] ICMP6, neighbor solicitation, length 24, who has fe80::280:66ff:fe04:63ea<br>10:54:05.888334 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16) fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router solicitation, length 16
<br> source link-address option (1), length 8 (1): 00:01:29:D4:BD:8B<br> 0x0000: 0080 6604 63ea<br>10:54:09.888345 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16) fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router solicitation, length 16
<br> source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C<br> 0x0000: 0080 6604 63ea<br>10:54:13.888495 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16) fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router solicitation, length 16
<br> source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C<br> 0x0000: 0080 6604 63ea<br><br>Is there any way to prevent these ipv6 packets being generated and by-passing the filtering ?<br>
<br>Darren<br>
------=_Part_26857_15212347.1201202907092--
--===============0310028468==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
--===============0310028468==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Ebtables-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/ebtables-user
--===============0310028468==--