Kernel 2.6.21.7 ipv6 module filtering bypass

"Darren Lissimore" <[email protected]> Thu, 24 Jan 2008 11:28:27 -0800
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
--===============0310028468==
Content-Type: multipart/alternative; 
	boundary="----=_Part_26857_15212347.1201202907092"

------=_Part_26857_15212347.1201202907092
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Hey All;

I've got a curious problem.
I'm using a  2.6.21.7 kernel on a transparent bridge.  With the following
ebtables rules;

   ebtables -t filter -A OUTPUT -p IPv6 -j DROP
   ebtables -t nat -A POSTROUTING -p IPv6 -j DROP


If I then modprobe the  kernel's ipv6 module,  the following trace is
observed going out both ports:


10:54:04.548138 IP6 (hlim 1, next-header: Options (0), length: 36) :: >
ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast
listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea
to_ex { }]
10:54:04.859729 IP6 (hlim 1, next-header: Options (0), length: 36) :: >
ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast
listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea
to_ex { }]
10:54:04.888188 IP6 (hlim 255, next-header: ICMPv6 (58), length: 24) :: >
ff02::1:ff04:63ea: [icmp6 sum ok] ICMP6, neighbor solicitation, length 24,
who has fe80::280:66ff:fe04:63ea
10:54:05.888334 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16)
fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router
solicitation, length 16
          source link-address option (1), length 8 (1): 00:01:29:D4:BD:8B
            0x0000:  0080 6604 63ea
10:54:09.888345 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16)
fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router
solicitation, length 16
          source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C
            0x0000:  0080 6604 63ea
10:54:13.888495 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16)
fe80::280:66ff:fe04:63ea > ff02::2: [icmp6 sum ok] ICMP6, router
solicitation, length 16
          source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C
            0x0000:  0080 6604 63ea

Is there any way to prevent these ipv6 packets being generated and
by-passing the filtering ?

Darren

------=_Part_26857_15212347.1201202907092
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Hey All;<br><br>I&#39;ve got a curious problem. <br>I&#39;m using a&nbsp; <a href="http://2.6.21.7">2.6.21.7</a> kernel on a transparent bridge.&nbsp; With the following ebtables rules;<br><br>&nbsp;&nbsp; ebtables -t filter -A OUTPUT -p IPv6 -j DROP
<br>&nbsp;&nbsp; ebtables -t nat -A POSTROUTING -p IPv6 -j DROP<br><br><br>If I then modprobe the&nbsp; kernel&#39;s ipv6 module,&nbsp; the following trace is observed going out both ports:<br><br><br>10:54:04.548138 IP6 (hlim 1, next-header: Options (0), length: 36) :: &gt; ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea to_ex { }]
<br>10:54:04.859729 IP6 (hlim 1, next-header: Options (0), length: 36) :: &gt; ff02::16: HBH (rtalert: 0x0000) (padn)[icmp6 sum ok] ICMP6, multicast listener report v2, length 28, 1 group record(s) [gaddr ff02::1:ff04:63ea to_ex { }]
<br>10:54:04.888188 IP6 (hlim 255, next-header: ICMPv6 (58), length: 24) :: &gt; ff02::1:ff04:63ea: [icmp6 sum ok] ICMP6, neighbor solicitation, length 24, who has fe80::280:66ff:fe04:63ea<br>10:54:05.888334 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16) fe80::280:66ff:fe04:63ea &gt; ff02::2: [icmp6 sum ok] ICMP6, router solicitation, length 16
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source link-address option (1), length 8 (1): 00:01:29:D4:BD:8B<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0000:&nbsp; 0080 6604 63ea<br>10:54:09.888345 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16) fe80::280:66ff:fe04:63ea &gt; ff02::2: [icmp6 sum ok] ICMP6, router solicitation, length 16
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0000:&nbsp; 0080 6604 63ea<br>10:54:13.888495 IP6 (hlim 255, next-header: ICMPv6 (58), length: 16) fe80::280:66ff:fe04:63ea &gt; ff02::2: [icmp6 sum ok] ICMP6, router solicitation, length 16
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source link-address option (1), length 8 (1): 00:01:29:D4:BD:8C<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0000:&nbsp; 0080 6604 63ea<br><br>Is there any way to prevent these ipv6 packets being generated and by-passing the filtering ?<br>
<br>Darren<br>

------=_Part_26857_15212347.1201202907092--


--===============0310028468==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
--===============0310028468==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ebtables-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/ebtables-user

--===============0310028468==--