Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-12-2008, 01:10 PM
Andrew Gideon
 
Posts: n/a
iptables restart, existing sessions, and ESTABLISHED,RELATED rules


I've noticed a problem when I restart iptables (ie. for the loading of a
change to rules). But it's not a complete problem, which is even weirder
than the problem itself.

I've an early rule "-m state --state ESTABLISHED,RELATED -j ACCEPT" to
permit inbound traffic that's a response to outbound. Pretty
conventional. One example of how this gets used is when I ssh out.

What is odd is what occurs when I've an SSH session open at the time I
restart iptables. Some inbound packets on the SSH session are rejected,
obviously not matching the above ESTABLISHED,RELATED. But not all!

I noticed this when I was running MythTV over port forwarding. It had
been working fine. After the restart of iptables, display of a video was
jittery. I then looked into the log and saw a lot of rejected inbound
SSH packets. But obviously not all were being rejected as the video
*was* playing, if badly.

Restarting the SSH session solved the problem.

So why are *some* of the packets failing to match on
ESTABLISHED,RELATED? I could understand none or all, but some?

And is there a way to reload iptables rules w/o losing the connection
session information that causes this? Or is there perhaps a way to
recreate the session information (ie. something which adds a TCP circuit
to the database even if there's no SYN packet seen perhaps?)?

Thanks...
Andrew
Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:56 AM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
Remortgages | Broadband | Mortgages | Online Advertising | Mortgage Calculator



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115