mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Tony Gale <gale@syntax.dera.gov.uk>
To: Jussi Hamalainen <count@theblah.org>
Cc: linux-kernel@vger.kernel.org
Subject: RE: ipchains blocking port 65535
Date: Wed, 17 Jan 2001 14:50:10 -0000 (GMT)	[thread overview]
Message-ID: <XFMail.20010117145010.gale@syntax.dera.gov.uk> (raw)
In-Reply-To: <Pine.LNX.4.30.0101171530150.20661-100000@shodan.irccrew.org>


It looks like this is due to the odd way in which ipchains handles
fragments. Try:

echo 1 > /proc/sys/net/ipv4/ip_always_defrag

-tony


On 17-Jan-2001 Jussi Hamalainen wrote:
> There seems to be a bug in ipchains. Matching port 65535 seems to
> always fail. If I set the chain policy to REJECT or DENY and then
> add a rule that accepts TCP to/from ports 0:65535, packets going to
> port 65535 will still be caught by the kernel. Is there a fix for
> this? It's driving me nuts. The firewall box is a 486 with 3 NICs
> and
> is running kernel 2.2.18 vanilla.
> 
> Here is a piece of the kernel log:
> 
> Jan 17 15:13:03 galileo kernel: Packet log: forward REJECT eth0
> PROTO=6 213.173.130.69:65535 xxx.xxx.xxx.xxx:65535 L=44 S=0x00
> I=16815 F=0x00B6 T=56 (#25)
> Jan 17 15:15:03 galileo kernel: Packet log: forward REJECT eth0
> PROTO=6 213.173.130.69:65535 xxx.xxx.xxx.xxx:65535 L=44 S=0x00
> I=19969 F=0x00B6 T=56 (#25)
> Jan 17 15:17:03 galileo kernel: Packet log: forward REJECT eth0
> PROTO=6 213.173.130.69:65535 xxx.xxx.xxx.xxx:65535 L=44 S=0x00
> I=21869 F=0x00B6 T=56 (#25)
> 
> And here a piece of my forward chain:
> 
> ACCEPT     tcp  ------  anywhere              myhomenet/27
> any ->   1024:65535
> ACCEPT     udp  ------  anywhere              myhomenet/27
> any ->   1024:65535
> 
> -- 
> -=[ Count Zero / TBH - Jussi Hämäläinen - email count@theblah.org
> ]=-
> 
> -
> To unsubscribe from this list: send the line "unsubscribe
> linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> Please read the FAQ at http://www.tux.org/lkml/

---
E-Mail: Tony Gale <gale@syntax.dera.gov.uk>
Never trust anybody whose arm is bigger than your leg.

The views expressed above are entirely those of the writer
and do not represent the views, policy or understanding of
any other person or official body.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
Please read the FAQ at http://www.tux.org/lkml/

  reply	other threads:[~2001-01-17 14:53 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-01-17 13:40 Jussi Hamalainen
2001-01-17 14:50 ` Tony Gale [this message]
2001-01-17 17:12   ` Jussi Hamalainen
2001-01-17 17:15     ` IP defrag (was RE: ipchains blocking port 65535) Tony Gale
2001-01-17 17:35       ` Andi Kleen
2001-01-17 17:44         ` Tony Gale
2001-01-17 18:01           ` Andi Kleen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=XFMail.20010117145010.gale@syntax.dera.gov.uk \
    --to=gale@syntax.dera.gov.uk \
    --cc=count@theblah.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®