On Sat, Jan 12, 2002 at 09:20:53PM +0100, Bart De Schuymer wrote:
> I am experiencing this oops too. And with a size of around 5000 I get about > 50% packet loss. > Doing a ping xxx.xxx.xxx.xxx -s 20000 from a host through the bridge to > another host also oopses the bridge box. Hmm. I see no such troubles with 0.0.6. Can you reproduce this with 0.0.6? > Lennert: > in net/ipv4/netfilter/ip_conntrack_standalone.c the function ip_refrag() is > registered onto NF_IP_POST_ROUTING with priority NF_IP_PRI_LAST. > So: this function will try to fragment stuff on the bridge POST_ROUTING > hook. Is this healthy? Yes. In fact, packets passed to NF_HOOK and friends are only unfragmented ones (iff connection tracking is loaded). Makes it easier to filter them and such. > Also: is it healthy that connection tracking defragments the ip packets on > the bridge PREROUTING hook? Doesn't this give problems if the bridge/router > box has to bridge those frames (instead of route them)? It only happens on IP packets. And if it is done on IP packets, it's undone again as soon as the packet passes POST_ROUTING. Right? cheers, Lennert _______________________________________________ Bridge mailing list [EMAIL PROTECTED] http://www.math.leidenuniv.nl/mailman/listinfo/bridge
