From: Tony Gale <gale@syntax.dera.gov.uk>
To: Jussi Hamalainen <count@theblah.org>
Cc: linux-kernel@vger.kernel.org
Subject: RE: ipchains blocking port 65535
Date: Wed, 17 Jan 2001 14:50:10 -0000 (GMT) [thread overview]
Message-ID: <XFMail.20010117145010.gale@syntax.dera.gov.uk> (raw)
In-Reply-To: <Pine.LNX.4.30.0101171530150.20661-100000@shodan.irccrew.org>
It looks like this is due to the odd way in which ipchains handles
fragments. Try:
echo 1 > /proc/sys/net/ipv4/ip_always_defrag
-tony
On 17-Jan-2001 Jussi Hamalainen wrote:
> There seems to be a bug in ipchains. Matching port 65535 seems to
> always fail. If I set the chain policy to REJECT or DENY and then
> add a rule that accepts TCP to/from ports 0:65535, packets going to
> port 65535 will still be caught by the kernel. Is there a fix for
> this? It's driving me nuts. The firewall box is a 486 with 3 NICs
> and
> is running kernel 2.2.18 vanilla.
>
> Here is a piece of the kernel log:
>
> Jan 17 15:13:03 galileo kernel: Packet log: forward REJECT eth0
> PROTO=6 213.173.130.69:65535 xxx.xxx.xxx.xxx:65535 L=44 S=0x00
> I=16815 F=0x00B6 T=56 (#25)
> Jan 17 15:15:03 galileo kernel: Packet log: forward REJECT eth0
> PROTO=6 213.173.130.69:65535 xxx.xxx.xxx.xxx:65535 L=44 S=0x00
> I=19969 F=0x00B6 T=56 (#25)
> Jan 17 15:17:03 galileo kernel: Packet log: forward REJECT eth0
> PROTO=6 213.173.130.69:65535 xxx.xxx.xxx.xxx:65535 L=44 S=0x00
> I=21869 F=0x00B6 T=56 (#25)
>
> And here a piece of my forward chain:
>
> ACCEPT tcp ------ anywhere myhomenet/27
> any -> 1024:65535
> ACCEPT udp ------ anywhere myhomenet/27
> any -> 1024:65535
>
> --
> -=[ Count Zero / TBH - Jussi Hämäläinen - email count@theblah.org
> ]=-
>
> -
> To unsubscribe from this list: send the line "unsubscribe
> linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> Please read the FAQ at http://www.tux.org/lkml/
---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
Never trust anybody whose arm is bigger than your leg.
The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/
next prev parent reply other threads:[~2001-01-17 14:53 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-01-17 13:40 Jussi Hamalainen
2001-01-17 14:50 ` Tony Gale [this message]
2001-01-17 17:12 ` Jussi Hamalainen
2001-01-17 17:15 ` IP defrag (was RE: ipchains blocking port 65535) Tony Gale
2001-01-17 17:35 ` Andi Kleen
2001-01-17 17:44 ` Tony Gale
2001-01-17 18:01 ` Andi Kleen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=XFMail.20010117145010.gale@syntax.dera.gov.uk \
--to=gale@syntax.dera.gov.uk \
--cc=count@theblah.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®